This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Infection, Unknown Virus [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello:
I was referred to this forum from another post that I have in "Whatthetech". It is in the Internet and browsers section. My original problem is that my computer did an automatic update and downloaded Internet Explorer 10 and it won't start. As soon as I open it it comes up with an error message that "Internet Explorer has stopped working", I click on the message boxes to close them and they keep coming back and IE 10 never finishes loading. I did notice that if I start the computer in Safe Mode IE 10 will work ok, and if I uninstall IE10 update and go back to IE8, it will work properly. What Ive tried so far is: Reset browser many times, disabling add-ons, deleating history, running virus scans {Avast and Kaspersky}, I tried to do a clean boot but my computer wouldn't respond correctly (I could not disable my virus scanner {Avast or Kaspersky} in Services and Start Up and save the changes they kept coming back check marked, therefore keeping the Load Start Up Items in General tab from being cleared {I also tried to do a clean boot as Administrator with no success}), tried using Internet Explorer Performance Troubleshooter, turned on compatibility view, tried to turn off Internet Explorer in Turn Off Windows Features and turn it back on, uninstalled IE10 as an update and re-downloaded it, and tried all of the above in an new Administrator account with no success. Also for about 2-3 mounths People in my e-mail address book are getting random e-mails that I didn't send,and I've been getting numerous undeliverable e-mails if that is of any help. I am running Windows 7 Home Premium 64 Bit, Intel processor (2.20 GHz), 4GB ram. I did a scan with OTL.exe. and here are the results:
OTL.txt
OTL logfile created on: 6/3/2013 5:18:08 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Lynn\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.12 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 69.72% Memory free
6.25 Gb Paging File | 5.10 Gb Available in Paging File | 81.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 340.58 Gb Free Space | 73.14% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 29.33 Gb Free Space | 78.71% Space Free | Partition Type: NTFS
Drive N: | 111.76 Gb Total Space | 47.00 Gb Free Space | 42.05% Space Free | Partition Type: FAT32

Computer Name: LYNNS-DESKTOP | User Name: Lynn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Lynn\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
PRC - C:\Program Files (x86)\WebCake\WebCakeDesktop.Updater.exe (WebCake LLC)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtGui4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtCore4.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\localization_manager.dll ()
MOD - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\dblite.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (vToolbarUpdater15.2.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe (AVG Secure Search)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Motorola Device Manager) – C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe (Motorola Mobility LLC)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (DeviceMonitorService) – C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe (Nero AG)
SRV - (PST Service) – C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe (Motorola)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CSObjectsSrv) – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe (Infowatch)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CTDevice_Srv) – C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe (Creative Technology Ltd)
SRV - (MSCSPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (FETNDIS) – C:\Windows\SysNative\drivers\fetn62a.sys (VIA Technologies, Inc. )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (ntcdrdrv) – C:\Windows\SysNative\drivers\ntcdrdrv.sys (NoteBurn Software)
DRV:64bit: - (WsAudio_DeviceS(5) – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV:64bit: - (WsAudio_DeviceS(4) – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV:64bit: - (WsAudio_DeviceS(3) – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV:64bit: - (WsAudio_DeviceS(2) – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV:64bit: - (WsAudio_DeviceS(1) – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (CSCrySec) – C:\Windows\SysNative\drivers\CSCrySec.sys (Infowatch)
DRV:64bit: - (CSVirtualDiskDrv) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys (Infowatch)
DRV:64bit: - (KLBG) – C:\Windows\SysNative\drivers\klbg.sys (Kaspersky Lab)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab)
DRV:64bit: - (kl1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (WUSB54GCv3) – C:\Windows\SysNative\drivers\WUSB54GCv3.sys (Ralink Technology Corp.)
DRV:64bit: - (S3GIGP) – C:\Windows\SysNative\drivers\VTGKModeDX64.sys (S3 Graphics Co., Ltd.)
DRV:64bit: - (Pnp680r) – C:\Windows\SysNative\drivers\PnP680r.sys (Silicon Image, Inc)
DRV - (gdrv) – C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (GVTDrv64) – C:\Windows\GVTDrv64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\..\SearchScopes,DefaultScope = {44816E91-C68A-2FF3-3D8F-8970062E5600}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{44816E91-C68A-2FF3-3D8F-8970062E5600}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={EE2ACA…mp;d=2013-06-02 07:57:19&v;=15.2.0.5&pid;=safeguard&sg;=1&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*;


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files (x86)\RelevantKnowledge [2013/05/26 21:18:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Update (Enabled) = C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (WebCake) - {2A5A2A90-3B30-4E6E-A955-2F232C6EF517} - C:\Program Files (x86)\WebCake\WebCakeIEClient.dll (WebCake LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O3 - HKLM\..\Toolbar: (AVG SafeGuard toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\15.2.0.5\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC569A9F-6DB5-4ACB-BB2B-C1C281E3D477}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\kloehk.dll (Kaspersky Lab)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\sbhook64.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\sbhook.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/06/14 09:53:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/06/14 22:38:57 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - N:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2002/10/28 13:03:12 | 000,000,000 | RH-D | M] - N:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 60 Days ==========

[2013/06/03 17:06:45 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/02 08:15:39 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:58:26 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\AVG SafeGuard toolbar
[2013/06/02 07:58:11 | 000,000,000 | —D | C] – C:\ProgramData\AVG SafeGuard toolbar
[2013/06/02 07:57:34 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/02 07:57:14 | 000,045,856 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/02 07:57:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2013/06/02 07:56:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG SafeGuard toolbar
[2013/06/02 07:56:27 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SmartPCFix
[2013/06/02 07:56:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFix
[2013/06/02 07:56:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartPCFix
[2013/06/02 07:56:06 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/06/02 07:56:04 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\WebCake
[2013/06/02 07:56:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebCake
[2013/05/30 22:26:12 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\Akamai
[2013/05/27 19:29:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEUDINIT.EXE
[2013/05/26 19:16:32 | 000,085,048 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSCrySec.sys
[2013/05/26 19:16:32 | 000,066,104 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys
[2013/05/26 19:14:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InfoWatch
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/05/26 19:13:40 | 000,353,296 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 18:41:34 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2013/05/26 17:37:02 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/26 17:37:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/26 17:37:00 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/26 17:37:00 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/26 17:36:35 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/26 17:36:35 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/26 17:36:33 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/26 07:56:20 | 000,000,000 | -H-D | C] – C:\TMRescueDisk
[2013/05/26 07:43:09 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2013/05/26 07:42:09 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2013/05/26 07:29:26 | 000,000,000 | –SD | C] – C:\Windows\SysWow64\Microsoft
[2013/05/26 07:26:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/05/24 14:01:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiseFixer
[2013/05/24 14:01:16 | 000,000,000 | —D | C] – C:\Program Files\WiseFixer
[2013/05/10 18:20:35 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/05/06 18:15:59 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\Malwarebytes
[2013/05/06 18:15:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/06 18:15:41 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/05/06 18:15:40 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/05/06 18:15:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/05/06 18:15:11 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\Programs
[2013/05/03 12:55:25 | 000,000,000 | —D | C] – C:\Windows\pss
[2013/04/20 16:47:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/04/20 06:45:56 | 000,263,584 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/04/20 06:45:50 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/04/20 06:45:49 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/04/20 06:45:49 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/04/11 05:21:02 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2013/04/10 01:49:41 | 003,717,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2013/04/10 01:49:39 | 003,217,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2013/04/10 01:49:37 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2013/04/10 01:49:37 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2013/04/10 01:49:37 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2013/04/10 01:49:36 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2013/04/10 01:48:21 | 005,550,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/04/10 01:48:17 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/04/10 01:48:16 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/04/10 01:48:15 | 000,112,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\smss.exe
[2013/04/10 01:48:14 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2013/04/10 01:48:14 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apisetschema.dll
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files - Modified Within 60 Days ==========

[2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/03 17:01:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/03 16:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/03 09:43:29 | 000,000,374 | —- | M] () – C:\Windows\tasks\SmartPCFix Task.job
[2013/06/03 09:40:24 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/03 09:40:24 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/03 09:37:20 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/03 09:37:20 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/03 09:37:20 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/03 09:32:58 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/03 09:32:53 | 2516,230,144 | -HS- | M] () – C:\hiberfil.sys
[2013/06/03 08:01:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/06/02 08:15:39 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:38 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 08:15:37 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:57:45 | 000,002,364 | —- | M] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/02 07:57:34 | 000,002,366 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/02 07:56:37 | 000,045,856 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/02 07:56:15 | 000,001,031 | —- | M] () – C:\Users\Public\Desktop\SmartPCFix.lnk
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagwrn.xml
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2013/05/27 21:54:12 | 000,004,954 | —- | M] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/27 20:45:01 | 000,001,437 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/05/26 20:12:21 | 000,300,240 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/26 19:45:03 | 000,153,053 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:45:03 | 000,107,384 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 19:13:40 | 000,353,296 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 17:27:03 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/05/26 07:41:48 | 000,000,036 | —- | M] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[2013/05/06 18:15:43 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/03 12:33:48 | 000,000,344 | —- | M] () – C:\Windows\lgfwup.ini
[2013/04/28 19:13:23 | 000,024,657 | —- | M] () – C:\Users\Lynn\Desktop\HPDV6119.odt
[2013/04/24 08:32:37 | 000,691,592 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/04/24 08:32:36 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/20 06:45:44 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/04/20 06:45:41 | 000,263,584 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/04/20 06:45:41 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/04/20 06:45:40 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/04/20 06:45:40 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/04/20 06:45:39 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/04/11 05:20:52 | 481,142,442 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/04/10 02:01:54 | 000,265,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/02 08:15:38 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:37 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 07:57:33 | 000,002,366 | —- | C] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/02 07:57:33 | 000,002,364 | —- | C] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/02 07:56:28 | 000,000,904 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/02 07:56:28 | 000,000,374 | —- | C] () – C:\Windows\tasks\SmartPCFix Task.job
[2013/06/02 07:56:25 | 000,000,852 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/06/02 07:56:15 | 000,001,031 | —- | C] () – C:\Users\Public\Desktop\SmartPCFix.lnk
[2013/05/27 21:54:13 | 000,004,954 | —- | C] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/26 19:17:08 | 000,153,053 | —- | C] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:17:08 | 000,107,384 | —- | C] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 07:41:48 | 000,000,036 | —- | C] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[2013/05/06 18:15:43 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/28 18:17:40 | 000,024,657 | —- | C] () – C:\Users\Lynn\Desktop\HPDV6119.odt
[2013/04/11 05:20:52 | 481,142,442 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/08/14 21:41:01 | 000,000,877 | —- | C] () – C:\Users\Lynn\recStudio.ini
[2012/03/09 00:27:52 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2012/03/06 22:41:39 | 000,030,528 | —- | C] () – C:\Windows\GVTDrv64.sys
[2012/03/04 14:40:33 | 000,000,288 | —- | C] () – C:\Users\Lynn\AppData\Roaming\.backup.dm
[2012/01/23 23:31:05 | 000,007,605 | —- | C] () – C:\Users\Lynn\AppData\Local\resmon.resmoncfg
[2011/12/06 22:53:34 | 000,153,600 | —- | C] () – C:\Windows\SysWow64\WS_ATLMovie.dll
[2011/07/31 20:48:40 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat
[2011/07/31 20:48:40 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat
[2011/07/31 20:26:53 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2011/06/16 11:07:59 | 000,000,344 | —- | C] () – C:\Windows\lgfwup.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/02/24 13:06:59 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Audacity
[2012/01/16 14:07:27 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Canon
[2011/12/06 21:46:49 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\ConverterLite
[2012/01/30 23:36:33 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Kernel for Windows Data Recovery
[2013/05/26 21:18:20 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\MotoCast
[2012/11/28 23:02:38 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola
[2012/11/28 23:03:48 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola Mobility
[2011/07/05 18:38:06 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\OpenOffice.org
[2013/06/02 07:56:54 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\SmartPCFix
[2013/06/03 09:07:16 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\WebCake

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/06/03 09:43:24 | 000,173,184 | —- | M] () MD5=92E04FCB222C6642033A27791C4F3A02 – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: IEXPLORE.EXE >
[2011/11/05 01:28:03 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=0377589BF14A6E5667B730D6D6DB59B4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_0fae4f323e42a646\iexplore.exe
[2013/03/04 00:49:09 | 000,672,928 | —- | M] (Microsoft Corporation) MD5=050A612C1CE0C7095CAD64EA32C570DB – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_1a42c5438bf82907\iexplore.exe
[2012/10/27 01:02:44 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=06A8334D76DCF0DFFA738A512BDCD5F7 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_19d8942672c321c5\iexplore.exe
[2012/02/28 01:42:27 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=09F6A10AB424E2DE445153065FA076BF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_19d2eba472c68c00\iexplore.exe
[2012/06/27 03:05:59 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=156169FAD6DEACEEF4BAFFEE8A662C4F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_0f81e75a3e642ff5\iexplore.exe
[2013/02/28 12:18:24 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=19025A34D3EAD0FA9634B504194D214D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_19db96ea72c06af1\iexplore.exe
[2012/04/20 01:08:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=27019747D97AB5CEFB97677DBB5CF577 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_1a11a2ba7297e4ee\iexplore.exe
[2011/04/22 16:15:52 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=281C23EC5BCB1853A5D571F1A6E52FB1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_101e7c5957724e1d\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2011/12/16 04:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_19eb591872b56d75\iexplore.exe
[2011/08/20 00:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_19d3ea0872c5a830\iexplore.exe
[2011/11/05 01:34:31 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=441C397A9ECF07747920F7F5E40B419B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_0fef13a357968bc7\iexplore.exe
[2012/12/20 09:27:39 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=45C1FCF818565D44531007526CDEF7EF – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_1a9b45378bb57c2d\iexplore.exe
[2012/04/20 00:53:37 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=4866404D6657D6E50619CCAF56B17D27 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_1a3bf0cd8bfcb2df\iexplore.exe
[2012/08/24 13:15:32 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=4ADB84297505A1627DEEA18529BF4B16 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_1a05d46a72a0e4af\iexplore.exe
[2012/10/27 01:56:51 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=4CDF8DE0C9F0A245B7348FDD2866F176 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_100f8919577e2f69\iexplore.exe
[2012/06/27 03:06:52 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=5421E66F9F91F221B9B88AAE11B0CFE7 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_101a571f57761651\iexplore.exe
[2012/06/27 02:05:29 | 000,672,856 | —- | M] (Microsoft Corporation) MD5=555D62228092C7F87B9930F85F833297 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17051_none_19d691ac72c4f1f0\iexplore.exe
[2013/03/02 01:06:58 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=58D926F3B2113BF849162C9C26FE21DC – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_19d1c74872c7a039\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_1a0bc6f6729d1c7b\iexplore.exe
[2012/02/28 02:38:39 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=69073D126F71A4F0FFF1DEE5082A0052 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16968_none_0f7e41523e65ca05\iexplore.exe
[2011/06/21 02:14:22 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=6B2383EDA3956983E3219A62D8408DAB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_0fe16ab757a12871\iexplore.exe
[2011/06/21 01:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_1a3615098c01ea6c\iexplore.exe
[2012/10/27 01:37:44 | 000,696,400 | —- | M] (Microsoft Corporation) MD5=7BF529AEFBAD8946747A1D592BCD31AB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17153_none_0f83e9d43e625fca\iexplore.exe
[2012/08/24 14:10:19 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=85275D3D81C23C8A8D3C915888D11C66 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17115_none_0fb12a183e4022b4\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/02/28 01:44:39 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8AFD61FB2D96C8229B7D8604F62FA692 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1a67307d8bdc431b\iexplore.exe
[2011/11/05 00:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_1a02f98472a36841\iexplore.exe
[2012/06/27 02:11:42 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=9B80D4B1CAD7C4160D9B2D65D468E336 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21245_none_1a6f01718bd6d84c\iexplore.exe
[2011/06/21 01:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_19f459cc72ad545d\iexplore.exe
[2011/12/16 04:45:57 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=A3F56CED7B94A30BE8954387F0E2B5D2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_0f96aec63e54ab7a\iexplore.exe
[2011/11/05 00:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_1a43bdf58bf74dc2\iexplore.exe
[2013/02/28 13:29:52 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=A976A480AA8FE1AE85B33F543D51752B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_0ff5e9ff5791ff16\iexplore.exe
[2013/06/02 08:15:38 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/06/02 08:15:38 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2011/08/20 01:46:07 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=AC1CC7CD5CBE60EFF105BB3C0DC199C5 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_0f7f3fb63e64e635\iexplore.exe
[2013/03/02 01:50:08 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=AFB0FE34A9B7F1B7A70276B9C1A78114 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17267_none_0f7d1cf63e66de3e\iexplore.exe
[2013/03/04 01:42:51 | 000,696,464 | —- | M] (Microsoft Corporation) MD5=B1B17B56E0F9AE84A1F75E757217154E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21484_none_0fee1af15797670c\iexplore.exe
[2011/06/21 02:21:24 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=B38DE184AC135A4B0AE7D286476FA33F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_0f9faf7a3e4c9262\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2011/12/16 04:42:35 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=C152529FD67ABB61F0609EF5A299794C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_104895c75752f56b\iexplore.exe
[2011/12/16 05:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_1a9d40198bb3b766\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2011/08/20 01:42:38 | 000,696,576 | —- | M] (Microsoft Corporation) MD5=C66C8BF791F9DB974022506265518EE0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_102322ab576fcd64\iexplore.exe
[2012/08/24 13:10:38 | 000,672,872 | —- | M] (Microsoft Corporation) MD5=C6E8F6DB0FD7B28924D1CBC8AE03ECEE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1a8d72878bc04ef2\iexplore.exe
[2012/10/27 00:57:50 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=CAB945F6B0700D84DE40ED1FA6DB15F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21355_none_1a64336b8bdef164\iexplore.exe
[2013/06/02 08:15:38 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/06/02 08:15:38 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/12/20 09:01:03 | 000,672,832 | —- | M] (Microsoft Corporation) MD5=D1F65F76FA03619706C43CBEF9C1EEC3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_19b1559e72dff6e5\iexplore.exe
[2011/04/22 16:16:25 | 000,696,592 | —- | M] (Microsoft Corporation) MD5=D6F57A9ECB4606076FB9519D1698FCBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_0fb71ca43e3c5a80\iexplore.exe
[2012/04/20 02:26:39 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=D889681C78E7BFE45587398AC42FC2D4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17006_none_0fbcf8683e3722f3\iexplore.exe
[2012/08/24 14:24:56 | 000,696,424 | —- | M] (Microsoft Corporation) MD5=E3C361C85ADECFF3A485E4FE17859E0F – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21313_none_1038c835575f8cf7\iexplore.exe
[2013/02/28 13:21:37 | 000,672,912 | —- | M] (Microsoft Corporation) MD5=E9194413FBF8CF085DD548F489BA44F2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21471_none_1a4a94518bf2c111\iexplore.exe
[2012/02/28 02:56:21 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=EFCA1150F17BCE44357F03BB61A29966 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21158_none_1012862b577b8120\iexplore.exe
[2012/04/20 02:13:05 | 000,696,408 | —- | M] (Microsoft Corporation) MD5=F293ACB373FD8F090E08F183C06E07ED – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21198_none_0fe7467b579bf0e4\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/12/20 10:08:37 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=F44F02FEEB5AC24C37D70BC83A578A7D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21406_none_10469ae55754ba32\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_1a7326ab8bd31018\iexplore.exe
[2013/02/28 12:36:35 | 000,696,480 | —- | M] (Microsoft Corporation) MD5=F9F2279A5EBAFB343CDB79FDC5C408C0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17256_none_0f86ec983e5fa8f6\iexplore.exe
[2011/08/20 00:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_1a77ccfd8bd08f5f\iexplore.exe
[2012/12/20 10:09:06 | 000,696,384 | —- | M] (Microsoft Corporation) MD5=FE004EA8558B9C8BF066483A3EA9FDDB – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.17197_none_0f5cab4c3e7f34ea\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2013/06/02 08:15:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/02 08:15:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/06/02 08:15:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/06/02 08:15:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-1B894AFB.PF >
[2013/06/03 09:44:08 | 000,072,194 | —- | M] () MD5=8F6A2DBFBF3BCB6BB3645ECE73616E91 – C:\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf

< MD5 for: IEXPLORE.EXE-F6A52C86.PF >
[2013/06/03 09:44:08 | 000,225,994 | —- | M] () MD5=AFC003A9BCC33D3655BCE0E8AB73283D – C:\Windows\Prefetch\IEXPLORE.EXE-F6A52C86.pf

< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/12/18 10:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SERVICES.RDB >
[2012/08/13 10:51:02 | 000,178,348 | —- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 – C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb
[2012/08/13 10:51:02 | 000,000,453 | —- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 – C:\Program Files (x86)\OpenOffice.org 3\program\services.rdb
[2012/08/10 15:12:16 | 000,008,060 | —- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B – C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2011/06/14 09:53:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/06/14 09:53:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/10/30 23:11:41 | 000,000,010 | —- | M] () – C:\csb.log
[2013/06/03 09:32:53 | 2516,230,144 | -HS- | M] () – C:\hiberfil.sys
[2011/06/14 09:53:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/05/05 23:42:48 | 000,141,556 | —- | M] () – C:\MGlogs.zip
[2011/06/14 09:53:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/06/03 09:32:55 | 3354,976,256 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/06/16 22:07:34 | 000,630,919 | —- | M] (Axialis Software) – C:\Windows\eyesv1.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/05/27 20:45:01 | 000,000,221 | -HS- | M] () – C:\Users\Lynn\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/06 22:40:37 | 010,264,208 | —- | M] () – C:\Users\Lynn\Desktop\Dell_Multi-Touch-Touchpad_A01_R231754.exe
[2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2011/09/10 01:03:52 | 000,969,504 | —- | M] (Microsoft Corporation) – C:\Users\Lynn\Desktop\Windows7-USB-DVD-tool.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:BC359956

< End of report >

Extras.txt
OTL Extras logfile created on: 6/3/2013 5:18:09 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Lynn\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.12 Gb Total Physical Memory | 2.18 Gb Available Physical Memory | 69.72% Memory free
6.25 Gb Paging File | 5.10 Gb Available in Paging File | 81.58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 340.58 Gb Free Space | 73.14% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 29.33 Gb Free Space | 78.71% Space Free | Partition Type: NTFS
Drive N: | 111.76 Gb Total Space | 47.00 Gb Free Space | 42.05% Space Free | Partition Type: FAT32

Computer Name: LYNNS-DESKTOP | User Name: Lynn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 60 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML.CKOO6KD3EMA7CGNCOOCEWZFMV4] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{016895BE-086B-4F35-A258-8A5C1042D308}" = rport=10243 | protocol=6 | dir=out | app=system |
"{08B414D6-1A26-4B9F-B0CF-6C5B169E4B4D}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{1FD1C237-C31F-40A4-BFC3-2CF6AA5DE591}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BCB25F0-1C53-493D-959A-5480C3D82089}" = lport=137 | protocol=17 | dir=in | app=system |
"{3CF69A0D-4106-46BA-A94C-94E2E4C01799}" = rport=137 | protocol=17 | dir=out | app=system |
"{405B420F-488C-4C33-A752-C29FA0E83847}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4EDF0C71-B529-4BEE-9D22-9E3CFA3B9A20}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4EFC7491-5CBD-4ED9-B4A4-EE2F2BB26AF9}" = lport=445 | protocol=6 | dir=in | app=system |
"{7304ACED-E3BE-4CAA-A350-50337EB5D186}" = lport=2869 | protocol=6 | dir=in | app=system |
"{7B2EE43B-E701-4C3B-B902-E0C44A69BA23}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{82119804-E732-4F89-A934-9EC7ECC6DFCF}" = lport=445 | protocol=6 | dir=in | app=system |
"{82F6B6F4-ECC4-4074-8B5D-163EA489D1F0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{95D711F0-0AE1-4A74-9FDE-B8DDD81FD436}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A1D34D52-5C44-40FC-A2AF-559A276A34C6}" = rport=445 | protocol=6 | dir=out | app=system |
"{A3FB2D79-A948-4E7F-B4DE-89B1D218664E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AD19622A-55A6-4230-8AAE-D7BFDB51B0C4}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B21643DC-82F1-4009-9B3C-91512A6AB237}" = rport=139 | protocol=6 | dir=out | app=system |
"{B53B6D7D-B045-4964-9A45-FEEDAA757E49}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{BA88B1B5-C549-4B42-A594-B2C4D30DFFAE}" = lport=138 | protocol=17 | dir=in | app=system |
"{BB9B89F7-0B3E-4942-9760-1141D1906A16}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BE19EE74-C596-4600-A9D1-385A81E07D95}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DAF95B79-26A4-4A14-AE43-3CEFF788EB77}" = lport=139 | protocol=6 | dir=in | app=system |
"{DDFF371F-E349-4755-BF9F-16C8B1FA0F48}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F527C31B-0276-423A-A653-52E596CFEF73}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FDA2F69E-4852-4C66-A89C-95539D13545B}" = rport=138 | protocol=17 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01820AB8-9E98-4E33-9935-49D50D73357C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{0491692C-F90A-42DD-BF62-793EB15E4B13}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{04B08927-C9A8-400E-B24D-B25E3B6D94A2}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{05216365-4DF2-4AA7-A410-4FBDB3593A4B}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{069E263A-559A-46BF-A18A-6662BDF600C5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |
"{078E82A5-B70E-4354-B076-38AD23992261}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{10BD49D2-04C1-4C39-AE88-BA68F0865581}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{129C0D5E-CDD4-439B-A2E9-5DDC0E3F34A7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |
"{130BF112-A77F-4D67-AB7E-B98423DA09B7}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{15A103C4-4BF3-49C0-877F-596DAE7C6C86}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{1D678F0E-1B51-43DB-99AA-9ADE6AB6F8B5}" = dir=out | app=c:\program files (x86)\motorola mobility\motocast\motocast.exe |
"{1D9E73FA-9535-4319-9FFC-24781CC3ECFB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{21264FDC-1CA5-4E5F-9C2A-3CEFFCD064B1}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{230CCA4B-E960-4476-BF02-684EA0E40390}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{235DB1F8-1DFF-4FDB-A098-49C00C0B4C7E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |
"{26AE9331-61A9-44C8-B03C-E17FFF63FA08}" = dir=in | app=c:\program files (x86)\motorola mobility\motocast\motocast.exe |
"{32C3580B-59AB-4E17-ADBC-48FC9F8BA8C7}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{37961DD0-A5FE-40CA-844D-D57337664934}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3E2C5F43-B4DF-4102-952B-30E986ABCE91}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |
"{5BC05727-32F0-4001-BF16-CF8754549A4A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |
"{67828D47-641E-4DCF-A4D9-48FC0B2CC8F0}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{73151AE3-E036-4098-95D8-675773E70173}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposfx08.exe |
"{75025B4E-2112-4D6F-AF53-8D578E1FC38D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{77AEE534-BE90-41D5-8FE4-75B81F642009}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqnrs08.exe |
"{799C068E-5E97-4415-B977-1CAA765A2320}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{79E34724-1295-443C-8E09-8AED19A53504}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |
"{7A23591B-283E-4417-99D9-9F47413F3DF0}" = protocol=17 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |
"{7B305976-BB9E-41F7-A988-3F7BA5705CC1}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{7DB919BE-B309-4915-8805-541083AE1F8D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxm08.exe |
"{816A7099-036B-4EF4-83EC-C366126C1731}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{847A8247-37BE-4688-A799-5A74E5D6DDA2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{886E32EB-5FFE-4512-AB0E-64ECF30ED8BA}" = protocol=6 | dir=in | app=c:\program files (x86)\relevantknowledge\rlvknlg.exe |
"{8ABC3C20-AE14-4F79-BD07-11150D9AB515}" = dir=in | app=c:\users\lynn\appdata\local\temp\7zs5c5a\setup\hpznui40.exe |
"{8C7CE714-5C24-403B-9946-9784314733AE}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{8D8AF1CA-29FB-44DB-9F62-15EB481296EB}" = dir=in | app=c:\program files (x86)\motorola mobility\motocast\bin\motocast-thumbnailer.exe |
"{98A88773-9B71-4BEE-B37C-2991BE642B58}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |
"{A22D9070-7770-4405-A816-A2B7F9F90CDD}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{A7D57924-CFB4-4479-90F5-7E44EEE540BD}" = dir=in | app=c:\program files (x86)\motorola media link\lite\mml.exe |
"{ACD82559-C89B-4E56-A271-61153082E8DE}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{AEB8F3AB-6B58-491B-921C-0D0E8FEAB84E}" = protocol=6 | dir=out | app=system |
"{B73C3685-687E-475B-BEBC-CDE82EBE2D70}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BF62AE63-574F-4509-B2F4-B5161970061E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{CB28ECF1-1A2F-42A5-9A79-DF6E8CA99479}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{CEE47A9F-08F6-4E49-90AF-6B7D4F2686A3}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D1D5E270-A695-4F63-A6BF-2BECC2BF4723}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{D43F0A55-86DA-4EAB-AC6C-F647A9F3F8E9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |
"{D4F95CFE-58DC-4EEB-81F9-66B401EFFAEB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpofxs08.exe |
"{DC9A500B-4EBC-45A0-9019-8E8E202542D2}" = dir=out | app=c:\program files (x86)\motorola mobility\motocast\bin\motocast-thumbnailer.exe |
"{DF3B5441-F9EC-456B-A46A-59C216A977F5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |
"{E56C6B2A-7315-410B-8BD4-9E0A27DDD2E5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqfxt08.exe |
"{F012830C-BA37-4995-B605-CDE25CEF20E7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{F09D7981-5B00-4F12-8930-342CED48B5B8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpzwiz01.exe |
"{F434CFB7-8583-41BB-925C-4EBAD31AD61C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |
"{F89F5566-06AD-4F18-90E6-645F14E86A73}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{FACB3E4B-C481-4F6E-9DA7-A0C310502812}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FBE3CFEE-8D22-436B-98F6-7387FD787769}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |
"{FEAFBE41-99D6-4DF0-827D-D55D6F4CACAB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC3
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX870_series" = Canon MX870 series MP Drivers
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{988329F4-A1A1-4D51-803C-EF2725A97627}" = HP Photosmart All-In-One Driver Software 13.0 Rel. 2
"{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}" = WebCake 3.00
"{C5A22A98-AC82-4404-BFB0-1E9F654EB176}" = Motorola Mobile Drivers Installation 6.0.0
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"Chrome9HC" = VIA Chrome9 HC IGP Family Display
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"NoteBurner_is1" = NoteBurner 2.35
"Shop for HP Supplies" = Shop for HP Supplies
"VN_VUIns_Rhine_VIA" = VIA Rhine Family Fast Ethernet Adapter

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG Power Tools
"{20EFC9AA-BBC1-4DFD-81FF-99654F71CBF8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{28DB8373-C1BB-444F-A427-A55585A12ED7}" = Motorola Device Manager
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{3577E42B-3347-4EB8-BFDA-D36E8ED3C519}" = Windows 7 USB/DVD Download Tool
"{378397D6-FD32-4092-A854-6A75CB7EDA46}" = MOTOROLA MEDIA LINK
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = LG CyberLink Power2Go
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{5401CEE8-3C2D-4835-A802-213306537FF4}" = MotoCast
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{685B0843-6C8D-4E42-B60D-2B86B45526E0}" = PS_AIO_02_Software_Min
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{86604C06-DA30-425E-AECE-47304FE81C45}" = Creative Software Update
"{94F8D42D-BB31-4858-9705-7D756D8D9655}" = PS_AIO_02_Software
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{AC76BA86-7AD7-5670-0000-A00000000003}" = Korean Fonts Support For Adobe Reader X
"{ADD5DB49-72CF-11D8-9D75-000129760D75}" = LG CyberLink PowerBackup
"{B28635AB-1DF3-4F07-BFEA-975D911B549B}" = hpphotosmartdisclabelplugin
"{B4B2096B-B13E-408E-8985-BD07463D5487}" = PS_AIO_02_ProductContext
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint
"{c600ab3d-8b64-41df-bf36-b3d87ce0706b}" = C7200_Help
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D9D8F2CF-FE2D-4644-9762-01F916FE90A9}" = HPPhotoSmartDiscLabel_PaperLabel
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{DEAD13D3-BC70-4AAE-AEF9-BE6297E106D1}" = Motorola Device Software Update
"{EE5926BD-9590-48A3-AB1E-C1C49575823D}" = C7200
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"7-zip" = 7-zip v9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Aimersoft DRM Media Converter_is1" = Aimersoft DRM Media Converter(Build 1.4.7.2)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
"AudioShell_is1" = AudioShell 1.3.5
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"Canon_IJ_Network_Scan_UTILITY" = Canon IJ Network Scan Utility
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenu" = Canon Utilities Solution Menu
"Creative Media Lite" = Creative Media Lite
"DDR - FAT Recovery(Demo)" = DDR - FAT Recovery(Demo) [removed]
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG Power Tools
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = LG CyberLink Power2Go
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint
"InstallShield_{CCD663AE-610D-4BDF-AAB0-E914B044527D}" = OpenMG Secure Module 4.7.00
"InstallWIX_{1A59064A-12A9-469F-99F6-04BF118DBCFF}" = Kaspersky PURE
"Kernel for Windows Data Recovery_is1" = Kernel for Windows Data Recovery ver 11.01.01
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MP Navigator EX 3.1" = Canon MP Navigator EX 3.1
"ophcrack" = ophcrack 3.4.0
"SmartPCFix_is1" = SmartPCFix 2.03
"SystemRequirementsLab" = System Requirements Lab
"UBCD4Win_is1" = UBCD4Win 3.60
"Windows Password Recovery Bootdisk_is1" = Windows Password Recovery Bootdisk 4.0
"ZENStoneUG" = Creative ZEN Stone User's Guide

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/27/2013 6:45:30 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xd74 Faulting application start time: 0x01ce5b2be2a6f970 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 213ccb2b-c71f-11e2-ad7b-001d7d3cc9a6

Error - 5/27/2013 6:45:32 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xe18 Faulting application start time: 0x01ce5b2be4b046cc Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 22ee059d-c71f-11e2-ad7b-001d7d3cc9a6

Error - 5/27/2013 6:49:25 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xc7c Faulting application start time: 0x01ce5b2c6e12523c Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: ad68f36d-c71f-11e2-ad7b-001d7d3cc9a6

Error - 5/27/2013 6:49:31 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0x87c Faulting application start time: 0x01ce5b2c72c6ca87 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: b1048957-c71f-11e2-ad7b-001d7d3cc9a6

Error - 5/27/2013 7:56:03 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xbb0 Faulting application start time: 0x01ce5b35bcf26825 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: fc8bafde-c728-11e2-a63a-001d7d3cc9a6

Error - 5/27/2013 7:56:10 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xd54 Faulting application start time: 0x01ce5b35c23351a0 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 007cf753-c729-11e2-a63a-001d7d3cc9a6

Error - 6/1/2013 5:37:35 PM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: FlashUtil64_11_7_700_169_ActiveX.exe, version:
11.7.700.169, time stamp: 0x5155fbd9 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x00000000000532d0
Faulting
process id: 0xf2c Faulting application start time: 0x01ce5f1037e2a91e Faulting application
path: C:\Windows\System32\Macromed\Flash\FlashUtil64_11_7_700_169_ActiveX.exe Faulting
module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 787b5200-cb03-11e2-8d34-001d7d3cc9a6

Error - 6/3/2013 9:29:23 AM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xbf0 Faulting application start time: 0x01ce605e57946796 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 9a0151a3-cc51-11e2-af78-001d7d3cc9a6

Error - 6/3/2013 9:29:32 AM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0x1f0 Faulting application start time: 0x01ce605e616ad778 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: 9fad590a-cc51-11e2-af78-001d7d3cc9a6

Error - 6/3/2013 9:44:01 AM | Computer Name = Lynns-desktop | Source = Application Error | ID = 1000
Description = Faulting application name: IEXPLORE.EXE, version: 10.0.9200.16576,
time stamp: 0x515e30fe Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,
time stamp: 0x50b83c8a Exception code: 0xc0000002 Fault offset: 0x0000c41f Faulting
process id: 0xd74 Faulting application start time: 0x01ce6060660a5870 Faulting application
path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE Faulting module path:
C:\Windows\syswow64\KERNELBASE.dll Report Id: a571a344-cc53-11e2-a477-001d7d3cc9a6

[ Media Center Events ]
Error - 1/17/2012 3:22:35 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 2:22:28 AM - Error connecting to the internet. 2:22:28 AM - Unable
to contact server..

Error - 1/17/2012 4:52:13 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 3:52:13 AM - Error connecting to the internet. 3:52:13 AM - Unable
to contact server..

Error - 1/17/2012 4:52:28 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 3:52:18 AM - Error connecting to the internet. 3:52:18 AM - Unable
to contact server..

Error - 1/17/2012 5:52:56 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 4:52:56 AM - Error connecting to the internet. 4:52:56 AM - Unable
to contact server..

Error - 1/17/2012 5:53:11 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 4:53:01 AM - Error connecting to the internet. 4:53:01 AM - Unable
to contact server..

Error - 1/17/2012 6:53:30 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 5:53:30 AM - Error connecting to the internet. 5:53:30 AM - Unable
to contact server..

Error - 1/17/2012 6:53:42 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 5:53:35 AM - Error connecting to the internet. 5:53:35 AM - Unable
to contact server..

Error - 1/17/2012 7:58:40 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 6:58:39 AM - Error connecting to the internet. 6:58:39 AM - Unable
to contact server..

Error - 1/17/2012 7:58:49 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 6:58:45 AM - Error connecting to the internet. 6:58:45 AM - Unable
to contact server..

Error - 2/9/2012 4:24:26 AM | Computer Name = Lynns-desktop | Source = MCUpdate | ID = 0
Description = 3:23:27 AM - Failed to retrieve Directory (Error: The operation has
timed out)

[ System Events ]
Error - 5/29/2012 9:28:53 PM | Computer Name = Lynns-desktop | Source = Service Control Manager | ID = 7000
Description = The PortableVBoxDRV service failed to start due to the following error:
%%3

Error - 5/29/2012 9:28:53 PM | Computer Name = Lynns-desktop | Source = Service Control Manager | ID = 7000
Description = The PortableVBoxUSBMon service failed to start due to the following
error: %%3


< End of report >
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.


Please uninstall the following programs:

WebCake 3.00
SmartPCFix 2.03



Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.




Please read and follow these instructions carefully. We do not want it to fix anything yet (if found), we need to see a report first.

Download TDSSKiller.exe and save it to your desktop
  • Execute TDSSKiller.exe by doubleclicking on it.
  • Press Start Scan
  • If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
  • Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

Please post the contents of that log in your next reply.





Scan with aswMBR


Please download aswMBR.exe to your desktop.

  • Double-click the aswMBR.exe to run it
  • When prompted with The application can use the Avast! Free Antivirus for scanning >> select No
  • Now click on the Scan button to start scan
  • On completion of the scan click Save Log, save it to your desktop and post the contents in your next reply
Note: There will also be a file on your desktop named MBR.dat(or similir) do not delete this for now it is a actual backup of the MBR(master boot record).
Hi: I performed the three tasks you gave to do from your reply to me. Below are the results. ADWCleaner.txt: # AdwCleaner v2.302 - Logfile created 06/06/2013 at 22:25:32 # Updated 06/06/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Lynn - LYNNS-DESKTOP # Boot Mode : Normal # Running from : C:\Users\Lynn\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : RelevantKnowledge ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Program Files (x86)\RelevantKnowledge Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge Folder Deleted : C:\ProgramData\Tarma Installer ***** [Registry] ***** Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A5A2A90-3B30-4E6E-A955-2F232C6EF517} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D425283-D487-4337-BAB6-AB8354A81457} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\YahooPartnerToolbar Key Deleted : HKCU\Software\Zugo Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\Software\AVG Security Toolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\S Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\Software\Freeze.com Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Tarma Installer Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{9D425283-D487-4337-BAB6-AB8354A81457}] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{9D425283-D487-4337-BAB6-AB8354A81457}] ***** [Internet Browsers] ***** -\\ Internet Explorer v10.0.9200.16576 [OK] Registry is clean. -\\ Google Chrome v27.0.1453.110 File : C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [6597 octets] - [06/06/2013 22:25:32] ########## EOF - C:\AdwCleaner[S1].txt - [6657 octets] ########## TDSSKiller.txt: 22:34:53.0091 0416 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 22:34:53.0521 0416 ============================================================ 22:34:53.0521 0416 Current date / time: 2013/06/06 22:34:53.0521 22:34:53.0521 0416 SystemInfo: 22:34:53.0521 0416 22:34:53.0521 0416 OS Version: 6.1.7601 ServicePack: 1.0 22:34:53.0521 0416 Product type: Workstation 22:34:53.0521 0416 ComputerName: LYNNS-DESKTOP 22:34:53.0522 0416 UserName: Lynn 22:34:53.0522 0416 Windows directory: C:\Windows 22:34:53.0522 0416 System windows directory: C:\Windows 22:34:53.0522 0416 Running under WOW64 22:34:53.0522 0416 Processor architecture: Intel x64 22:34:53.0522 0416 Number of processors: 2 22:34:53.0522 0416 Page size: 0x1000 22:34:53.0522 0416 Boot type: Normal boot 22:34:53.0522 0416 ============================================================ 22:34:55.0482 0416 Drive \Device\Harddisk2\DR2 - Size: 0x7470AFDE00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xFC59, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040 22:34:55.0482 0416 Drive \Device\Harddisk0\DR0 - Size: 0x9515A5E00 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:34:55.0497 0416 Drive \Device\Harddisk4\DR4 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 22:34:55.0500 0416 ============================================================ 22:34:55.0500 0416 \Device\Harddisk2\DR2: 22:34:55.0500 0416 MBR partitions: 22:34:55.0500 0416 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A352000 22:34:55.0500 0416 \Device\Harddisk0\DR0: 22:34:55.0500 0416 MBR partitions: 22:34:55.0500 0416 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1 22:34:55.0500 0416 \Device\Harddisk4\DR4: 22:34:55.0501 0416 MBR partitions: 22:34:55.0501 0416 \Device\Harddisk4\DR4\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0xDF93782 22:34:55.0501 0416 ============================================================ 22:34:55.0564 0416 C: <-> \Device\Harddisk2\DR2\Partition1 22:34:55.0588 0416 D: <-> \Device\Harddisk0\DR0\Partition1 22:34:55.0589 0416 N: <-> \Device\Harddisk4\DR4\Partition1 22:34:55.0590 0416 ============================================================ 22:34:55.0590 0416 Initialize success 22:34:55.0590 0416 ============================================================ 22:34:59.0276 0760 ============================================================ 22:34:59.0276 0760 Scan started 22:34:59.0276 0760 Mode: Manual; 22:34:59.0276 0760 ============================================================ 22:35:00.0552 0760 ================ Scan system memory ======================== 22:35:00.0552 0760 System memory - ok 22:35:00.0552 0760 ================ Scan services ============================= 22:35:00.0724 0760 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 22:35:00.0740 0760 1394ohci - ok 22:35:00.0786 0760 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys 22:35:00.0786 0760 ACPI - ok 22:35:00.0833 0760 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 22:35:00.0833 0760 AcpiPmi - ok 22:35:00.0974 0760 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 22:35:00.0974 0760 AdobeARMservice - ok 22:35:01.0083 0760 [ 479901C99FA62D1C3261B7ACB1228DAD ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:35:01.0083 0760 AdobeFlashPlayerUpdateSvc - ok 22:35:01.0145 0760 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 22:35:01.0161 0760 adp94xx - ok 22:35:01.0192 0760 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 22:35:01.0208 0760 adpahci - ok 22:35:01.0239 0760 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 22:35:01.0239 0760 adpu320 - ok 22:35:01.0286 0760 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 22:35:01.0286 0760 AeLookupSvc - ok 22:35:01.0348 0760 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys 22:35:01.0348 0760 AFD - ok 22:35:01.0410 0760 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys 22:35:01.0410 0760 agp440 - ok 22:35:01.0426 0760 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe 22:35:01.0442 0760 ALG - ok 22:35:01.0473 0760 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys 22:35:01.0473 0760 aliide - ok 22:35:01.0629 0760 ALSysIO - ok 22:35:01.0660 0760 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys 22:35:01.0660 0760 amdide - ok 22:35:01.0691 0760 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 22:35:01.0691 0760 AmdK8 - ok 22:35:01.0722 0760 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 22:35:01.0722 0760 AmdPPM - ok 22:35:01.0769 0760 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys 22:35:01.0769 0760 amdsata - ok 22:35:01.0800 0760 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 22:35:01.0816 0760 amdsbs - ok 22:35:01.0832 0760 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys 22:35:01.0832 0760 amdxata - ok 22:35:01.0878 0760 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys 22:35:01.0878 0760 AppID - ok 22:35:01.0910 0760 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll 22:35:01.0910 0760 AppIDSvc - ok 22:35:01.0956 0760 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll 22:35:01.0956 0760 Appinfo - ok 22:35:02.0050 0760 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 22:35:02.0066 0760 Apple Mobile Device - ok 22:35:02.0081 0760 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys 22:35:02.0081 0760 arc - ok 22:35:02.0097 0760 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 22:35:02.0112 0760 arcsas - ok 22:35:02.0144 0760 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 22:35:02.0144 0760 AsyncMac - ok 22:35:02.0175 0760 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys 22:35:02.0175 0760 atapi - ok 22:35:02.0237 0760 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 22:35:02.0253 0760 AudioEndpointBuilder - ok 22:35:02.0268 0760 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll 22:35:02.0284 0760 AudioSrv - ok 22:35:02.0315 0760 [ CA0D66B63DBD2A22D0AC9B758D67B8E8 ] avgtp C:\Windows\system32\drivers\avgtpx64.sys 22:35:02.0315 0760 avgtp - ok 22:35:02.0378 0760 [ A2B790F9A751F24F17967F9A5574186D ] AVP C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe 22:35:02.0378 0760 AVP - ok 22:35:02.0424 0760 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll 22:35:02.0424 0760 AxInstSV - ok 22:35:02.0456 0760 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys 22:35:02.0471 0760 b06bdrv - ok 22:35:02.0518 0760 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys 22:35:02.0518 0760 b57nd60a - ok 22:35:02.0565 0760 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll 22:35:02.0565 0760 BDESVC - ok 22:35:02.0596 0760 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys 22:35:02.0596 0760 Beep - ok 22:35:02.0658 0760 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll 22:35:02.0674 0760 BFE - ok 22:35:02.0721 0760 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll 22:35:02.0736 0760 BITS - ok 22:35:02.0752 0760 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 22:35:02.0752 0760 blbdrive - ok 22:35:02.0846 0760 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 22:35:02.0846 0760 Bonjour Service - ok 22:35:02.0892 0760 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 22:35:02.0892 0760 bowser - ok 22:35:02.0908 0760 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 22:35:02.0924 0760 BrFiltLo - ok 22:35:02.0939 0760 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 22:35:02.0939 0760 BrFiltUp - ok 22:35:02.0986 0760 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll 22:35:02.0986 0760 Browser - ok 22:35:03.0017 0760 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys 22:35:03.0017 0760 Brserid - ok 22:35:03.0048 0760 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 22:35:03.0048 0760 BrSerWdm - ok 22:35:03.0080 0760 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 22:35:03.0080 0760 BrUsbMdm - ok 22:35:03.0095 0760 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 22:35:03.0095 0760 BrUsbSer - ok 22:35:03.0126 0760 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 22:35:03.0126 0760 BTHMODEM - ok 22:35:03.0158 0760 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll 22:35:03.0173 0760 bthserv - ok 22:35:03.0189 0760 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 22:35:03.0189 0760 cdfs - ok 22:35:03.0236 0760 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 22:35:03.0251 0760 cdrom - ok 22:35:03.0298 0760 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll 22:35:03.0298 0760 CertPropSvc - ok 22:35:03.0329 0760 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys 22:35:03.0329 0760 circlass - ok 22:35:03.0376 0760 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys 22:35:03.0392 0760 CLFS - ok 22:35:03.0485 0760 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:35:03.0485 0760 clr_optimization_v2.0.50727_32 - ok 22:35:03.0563 0760 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 22:35:03.0563 0760 clr_optimization_v2.0.50727_64 - ok 22:35:03.0626 0760 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 22:35:03.0626 0760 clr_optimization_v4.0.30319_32 - ok 22:35:03.0672 0760 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 22:35:03.0672 0760 clr_optimization_v4.0.30319_64 - ok 22:35:03.0688 0760 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 22:35:03.0688 0760 CmBatt - ok 22:35:03.0719 0760 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys 22:35:03.0735 0760 cmdide - ok 22:35:03.0766 0760 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys 22:35:03.0782 0760 CNG - ok 22:35:03.0797 0760 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 22:35:03.0797 0760 Compbatt - ok 22:35:03.0828 0760 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 22:35:03.0828 0760 CompositeBus - ok 22:35:03.0844 0760 COMSysApp - ok 22:35:03.0875 0760 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 22:35:03.0875 0760 crcdisk - ok 22:35:03.0922 0760 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll 22:35:03.0922 0760 CryptSvc - ok 22:35:03.0969 0760 [ AB1201F8DE199E764DA9A32ABF71049C ] CSCrySec C:\Windows\system32\DRIVERS\CSCrySec.sys 22:35:03.0969 0760 CSCrySec - ok 22:35:04.0078 0760 [ 6E5B42219F1FE4A3D087D9D501E343D5 ] CSObjectsSrv C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe 22:35:04.0078 0760 CSObjectsSrv - ok 22:35:04.0109 0760 [ A6EED705BB510FA6B0F9F097165A3395 ] CSVirtualDiskDrv C:\Windows\system32\DRIVERS\CSVirtualDiskDrv.sys 22:35:04.0109 0760 CSVirtualDiskDrv - ok 22:35:04.0203 0760 [ A5BEA0E5C297F5F3835638A87E512FBA ] CTDevice_Srv C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe 22:35:04.0218 0760 CTDevice_Srv - ok 22:35:04.0265 0760 [ 7AF9DAC504FBD047CBC3E64AE52C92BF ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys 22:35:04.0265 0760 dc3d - ok 22:35:04.0312 0760 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll 22:35:04.0328 0760 DcomLaunch - ok 22:35:04.0359 0760 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll 22:35:04.0374 0760 defragsvc - ok 22:35:04.0421 0760 [ 59D90B6A7FBC4CC712DD7C5868618480 ] DeviceMonitorService C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe 22:35:04.0437 0760 DeviceMonitorService - ok 22:35:04.0484 0760 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 22:35:04.0484 0760 DfsC - ok 22:35:04.0530 0760 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll 22:35:04.0546 0760 Dhcp - ok 22:35:04.0593 0760 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys 22:35:04.0593 0760 discache - ok 22:35:04.0608 0760 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys 22:35:04.0624 0760 Disk - ok 22:35:04.0640 0760 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll 22:35:04.0640 0760 Dnscache - ok 22:35:04.0686 0760 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll 22:35:04.0686 0760 dot3svc - ok 22:35:04.0749 0760 [ B42ED0320C6E41102FDE0005154849BB ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 22:35:04.0749 0760 Dot4 - ok 22:35:04.0796 0760 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 22:35:04.0796 0760 Dot4Print - ok 22:35:04.0811 0760 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 22:35:04.0811 0760 dot4usb - ok 22:35:04.0858 0760 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll 22:35:04.0858 0760 DPS - ok 22:35:04.0905 0760 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 22:35:04.0905 0760 drmkaud - ok 22:35:04.0952 0760 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 22:35:04.0967 0760 DXGKrnl - ok 22:35:05.0014 0760 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll 22:35:05.0014 0760 EapHost - ok 22:35:05.0123 0760 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys 22:35:05.0186 0760 ebdrv - ok 22:35:05.0232 0760 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe 22:35:05.0232 0760 EFS - ok 22:35:05.0326 0760 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 22:35:05.0342 0760 ehRecvr - ok 22:35:05.0388 0760 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe 22:35:05.0388 0760 ehSched - ok 22:35:05.0420 0760 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 22:35:05.0435 0760 elxstor - ok 22:35:05.0482 0760 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys 22:35:05.0482 0760 ErrDev - ok 22:35:05.0529 0760 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll 22:35:05.0544 0760 EventSystem - ok 22:35:05.0576 0760 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys 22:35:05.0576 0760 exfat - ok 22:35:05.0607 0760 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys 22:35:05.0607 0760 fastfat - ok 22:35:05.0778 0760 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe 22:35:05.0778 0760 Fax - ok 22:35:05.0810 0760 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys 22:35:05.0810 0760 fdc - ok 22:35:05.0825 0760 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll 22:35:05.0825 0760 fdPHost - ok 22:35:05.0856 0760 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll 22:35:05.0856 0760 FDResPub - ok 22:35:05.0903 0760 [ A091AE21892170AFEEDACF8EA2595567 ] FETNDIS C:\Windows\system32\DRIVERS\fetn62a.sys 22:35:05.0903 0760 FETNDIS - ok 22:35:05.0919 0760 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 22:35:05.0919 0760 FileInfo - ok 22:35:05.0934 0760 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 22:35:05.0934 0760 Filetrace - ok 22:35:05.0950 0760 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 22:35:05.0966 0760 flpydisk - ok 22:35:05.0997 0760 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 22:35:05.0997 0760 FltMgr - ok 22:35:06.0059 0760 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll 22:35:06.0075 0760 FontCache - ok 22:35:06.0137 0760 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:35:06.0137 0760 FontCache3.0.0.0 - ok 22:35:06.0153 0760 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 22:35:06.0153 0760 FsDepends - ok 22:35:06.0184 0760 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 22:35:06.0200 0760 Fs_Rec - ok 22:35:06.0231 0760 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 22:35:06.0231 0760 fvevol - ok 22:35:06.0262 0760 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 22:35:06.0262 0760 gagp30kx - ok 22:35:06.0309 0760 [ 5EA3B256225D79A4B07A2CAC6276B23D ] gdrv C:\Windows\gdrv.sys 22:35:06.0309 0760 gdrv - ok 22:35:06.0356 0760 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 22:35:06.0356 0760 GEARAspiWDM - ok 22:35:06.0418 0760 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll 22:35:06.0434 0760 gpsvc - ok 22:35:06.0465 0760 [ 8126331FBD4ED29EB3B356F9C905064D ] GVTDrv64 C:\Windows\GVTDrv64.sys 22:35:06.0465 0760 GVTDrv64 - ok 22:35:06.0496 0760 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 22:35:06.0496 0760 hcw85cir - ok 22:35:06.0543 0760 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 22:35:06.0558 0760 HdAudAddService - ok 22:35:06.0590 0760 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 22:35:06.0605 0760 HDAudBus - ok 22:35:06.0621 0760 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 22:35:06.0621 0760 HidBatt - ok 22:35:06.0652 0760 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 22:35:06.0652 0760 HidBth - ok 22:35:06.0684 0760 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 22:35:06.0689 0760 HidIr - ok 22:35:06.0728 0760 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll 22:35:06.0738 0760 hidserv - ok 22:35:06.0763 0760 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 22:35:06.0766 0760 HidUsb - ok 22:35:06.0809 0760 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll 22:35:06.0815 0760 hkmsvc - ok 22:35:06.0862 0760 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll 22:35:06.0868 0760 HomeGroupListener - ok 22:35:06.0905 0760 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 22:35:06.0912 0760 HomeGroupProvider - ok 22:35:07.0006 0760 [ 1DAE5C46D42B02A6D5862E1482EFB390 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 22:35:07.0015 0760 hpqcxs08 - ok 22:35:07.0035 0760 [ 99E8EEF42FE2F4AF29B08C3355DD7685 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 22:35:07.0042 0760 hpqddsvc - ok 22:35:07.0081 0760 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 22:35:07.0085 0760 HpSAMD - ok 22:35:07.0159 0760 [ F37882F128EFACEFE353E0BAE2766909 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL 22:35:07.0177 0760 HPSLPSVC - ok 22:35:07.0247 0760 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys 22:35:07.0258 0760 HTTP - ok 22:35:07.0296 0760 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 22:35:07.0298 0760 hwpolicy - ok 22:35:07.0331 0760 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 22:35:07.0334 0760 i8042prt - ok 22:35:07.0391 0760 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 22:35:07.0400 0760 iaStorV - ok 22:35:07.0499 0760 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 22:35:07.0505 0760 IDriverT - ok 22:35:07.0581 0760 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 22:35:07.0594 0760 idsvc - ok 22:35:07.0641 0760 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 22:35:07.0646 0760 iirsp - ok 22:35:07.0678 0760 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll 22:35:07.0690 0760 IKEEXT - ok 22:35:07.0719 0760 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys 22:35:07.0722 0760 intelide - ok 22:35:07.0747 0760 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 22:35:07.0751 0760 intelppm - ok 22:35:07.0788 0760 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll 22:35:07.0793 0760 IPBusEnum - ok 22:35:07.0839 0760 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:35:07.0842 0760 IpFilterDriver - ok 22:35:07.0894 0760 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 22:35:07.0904 0760 iphlpsvc - ok 22:35:07.0943 0760 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 22:35:07.0946 0760 IPMIDRV - ok 22:35:07.0968 0760 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 22:35:07.0973 0760 IPNAT - ok 22:35:08.0015 0760 [ 4472C8825B5E41D8697D5962F47AB1C9 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 22:35:08.0030 0760 iPod Service - ok 22:35:08.0062 0760 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 22:35:08.0062 0760 IRENUM - ok 22:35:08.0108 0760 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys 22:35:08.0108 0760 isapnp - ok 22:35:08.0155 0760 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 22:35:08.0155 0760 iScsiPrt - ok 22:35:08.0186 0760 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 22:35:08.0186 0760 kbdclass - ok 22:35:08.0218 0760 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 22:35:08.0233 0760 kbdhid - ok 22:35:08.0249 0760 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe 22:35:08.0249 0760 KeyIso - ok 22:35:08.0296 0760 [ DB449F50E5141458EB58E64FFAC4863F ] kl1 C:\Windows\system32\DRIVERS\kl1.sys 22:35:08.0296 0760 kl1 - ok 22:35:08.0327 0760 [ 87200A8AFE40532BAA4D2B24A7BA0EEA ] KLBG C:\Windows\system32\DRIVERS\klbg.sys 22:35:08.0327 0760 KLBG - ok 22:35:08.0374 0760 [ 34D49307217B20E5A845B7DB50CDD4FA ] KLIF C:\Windows\system32\DRIVERS\klif.sys 22:35:08.0389 0760 KLIF - ok 22:35:08.0420 0760 [ 630F22545379437737CF4172F09FE449 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys 22:35:08.0420 0760 KLIM6 - ok 22:35:08.0436 0760 [ 786791291939ABB11F6D0F040DA23912 ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys 22:35:08.0436 0760 klmouflt - ok 22:35:08.0467 0760 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 22:35:08.0467 0760 KSecDD - ok 22:35:08.0498 0760 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 22:35:08.0498 0760 KSecPkg - ok 22:35:08.0545 0760 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 22:35:08.0561 0760 ksthunk - ok 22:35:08.0608 0760 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll 22:35:08.0608 0760 KtmRm - ok 22:35:08.0670 0760 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll 22:35:08.0670 0760 LanmanServer - ok 22:35:08.0732 0760 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 22:35:08.0732 0760 LanmanWorkstation - ok 22:35:08.0764 0760 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 22:35:08.0779 0760 lltdio - ok 22:35:08.0826 0760 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll 22:35:08.0842 0760 lltdsvc - ok 22:35:08.0857 0760 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll 22:35:08.0857 0760 lmhosts - ok 22:35:08.0904 0760 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 22:35:08.0904 0760 LSI_FC - ok 22:35:08.0920 0760 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 22:35:08.0920 0760 LSI_SAS - ok 22:35:08.0935 0760 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 22:35:08.0951 0760 LSI_SAS2 - ok 22:35:08.0966 0760 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 22:35:08.0982 0760 LSI_SCSI - ok 22:35:09.0013 0760 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys 22:35:09.0013 0760 luafv - ok 22:35:09.0029 0760 MarkFun_NT - ok 22:35:09.0076 0760 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 22:35:09.0091 0760 Mcx2Svc - ok 22:35:09.0107 0760 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 22:35:09.0107 0760 megasas - ok 22:35:09.0138 0760 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 22:35:09.0138 0760 MegaSR - ok 22:35:09.0169 0760 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll 22:35:09.0169 0760 MMCSS - ok 22:35:09.0200 0760 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys 22:35:09.0200 0760 Modem - ok 22:35:09.0247 0760 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys 22:35:09.0247 0760 monitor - ok 22:35:09.0325 0760 [ FDF0D78147DA8B2A93FE42D9A14C1B0B ] Motorola Device Manager C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe 22:35:09.0341 0760 Motorola Device Manager - ok 22:35:09.0372 0760 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 22:35:09.0388 0760 mouclass - ok 22:35:09.0403 0760 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 22:35:09.0403 0760 mouhid - ok 22:35:09.0450 0760 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 22:35:09.0450 0760 mountmgr - ok 22:35:09.0497 0760 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys 22:35:09.0497 0760 mpio - ok 22:35:09.0528 0760 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 22:35:09.0528 0760 mpsdrv - ok 22:35:09.0590 0760 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll 22:35:09.0606 0760 MpsSvc - ok 22:35:09.0668 0760 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 22:35:09.0668 0760 MRxDAV - ok 22:35:09.0715 0760 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 22:35:09.0715 0760 mrxsmb - ok 22:35:09.0746 0760 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:35:09.0746 0760 mrxsmb10 - ok 22:35:09.0778 0760 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:35:09.0778 0760 mrxsmb20 - ok 22:35:09.0809 0760 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys 22:35:09.0809 0760 msahci - ok 22:35:09.0887 0760 [ 8E46A7BAC823DD82D4FB2A34C3DF4C1D ] MSCSPTISRV C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe 22:35:09.0902 0760 MSCSPTISRV - ok 22:35:09.0934 0760 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys 22:35:09.0949 0760 msdsm - ok 22:35:09.0965 0760 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe 22:35:09.0980 0760 MSDTC - ok 22:35:10.0043 0760 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys 22:35:10.0043 0760 Msfs - ok 22:35:10.0058 0760 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 22:35:10.0058 0760 mshidkmdf - ok 22:35:10.0105 0760 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 22:35:10.0105 0760 msisadrv - ok 22:35:10.0168 0760 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 22:35:10.0168 0760 MSiSCSI - ok 22:35:10.0183 0760 msiserver - ok 22:35:10.0230 0760 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 22:35:10.0230 0760 MSKSSRV - ok 22:35:10.0261 0760 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 22:35:10.0261 0760 MSPCLOCK - ok 22:35:10.0277 0760 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 22:35:10.0277 0760 MSPQM - ok 22:35:10.0324 0760 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 22:35:10.0339 0760 MsRPC - ok 22:35:10.0370 0760 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 22:35:10.0370 0760 mssmbios - ok 22:35:10.0386 0760 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 22:35:10.0386 0760 MSTEE - ok 22:35:10.0433 0760 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 22:35:10.0433 0760 MTConfig - ok 22:35:10.0464 0760 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys 22:35:10.0480 0760 Mup - ok 22:35:10.0511 0760 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll 22:35:10.0526 0760 napagent - ok 22:35:10.0573 0760 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 22:35:10.0589 0760 NativeWifiP - ok 22:35:10.0636 0760 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys 22:35:10.0651 0760 NDIS - ok 22:35:10.0682 0760 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 22:35:10.0682 0760 NdisCap - ok 22:35:10.0714 0760 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 22:35:10.0714 0760 NdisTapi - ok 22:35:10.0760 0760 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 22:35:10.0760 0760 Ndisuio - ok 22:35:10.0807 0760 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 22:35:10.0807 0760 NdisWan - ok 22:35:10.0854 0760 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 22:35:10.0854 0760 NDProxy - ok 22:35:10.0901 0760 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 22:35:10.0901 0760 Net Driver HPZ12 - ok 22:35:10.0916 0760 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 22:35:10.0916 0760 NetBIOS - ok 22:35:10.0963 0760 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 22:35:10.0979 0760 NetBT - ok 22:35:10.0994 0760 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe 22:35:10.0994 0760 Netlogon - ok 22:35:11.0041 0760 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll 22:35:11.0057 0760 Netman - ok 22:35:11.0088 0760 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll 22:35:11.0104 0760 netprofm - ok 22:35:11.0135 0760 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 22:35:11.0150 0760 NetTcpPortSharing - ok 22:35:11.0166 0760 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 22:35:11.0166 0760 nfrd960 - ok 22:35:11.0197 0760 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll 22:35:11.0213 0760 NlaSvc - ok 22:35:11.0228 0760 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys 22:35:11.0228 0760 Npfs - ok 22:35:11.0275 0760 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll 22:35:11.0275 0760 nsi - ok 22:35:11.0291 0760 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 22:35:11.0291 0760 nsiproxy - ok 22:35:11.0322 0760 [ 9338574167490C5D571FA85E858A5FED ] ntcdrdrv C:\Windows\system32\DRIVERS\ntcdrdrv.sys 22:35:11.0322 0760 ntcdrdrv - ok 22:35:11.0400 0760 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 22:35:11.0431 0760 Ntfs - ok 22:35:11.0462 0760 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys 22:35:11.0462 0760 Null - ok 22:35:11.0509 0760 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys 22:35:11.0525 0760 nvraid - ok 22:35:11.0572 0760 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys 22:35:11.0587 0760 nvstor - ok 22:35:11.0618 0760 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 22:35:11.0634 0760 nv_agp - ok 22:35:11.0665 0760 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 22:35:11.0681 0760 ohci1394 - ok 22:35:11.0728 0760 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 22:35:11.0728 0760 p2pimsvc - ok 22:35:11.0774 0760 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll 22:35:11.0790 0760 p2psvc - ok 22:35:11.0806 0760 [ 753A8F339F231D2B857E2CCD51A6E6CA ] PACSPTISVR C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe 22:35:11.0821 0760 PACSPTISVR - ok 22:35:11.0852 0760 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys 22:35:11.0852 0760 Parport - ok 22:35:11.0899 0760 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys 22:35:11.0899 0760 partmgr - ok 22:35:11.0915 0760 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll 22:35:11.0930 0760 PcaSvc - ok 22:35:11.0946 0760 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys 22:35:11.0946 0760 pci - ok 22:35:11.0962 0760 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys 22:35:11.0962 0760 pciide - ok 22:35:12.0024 0760 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 22:35:12.0024 0760 pcmcia - ok 22:35:12.0055 0760 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys 22:35:12.0055 0760 pcw - ok 22:35:12.0086 0760 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys 22:35:12.0086 0760 PEAUTH - ok 22:35:12.0383 0760 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe 22:35:12.0414 0760 PerfHost - ok 22:35:12.0508 0760 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll 22:35:12.0539 0760 pla - ok 22:35:12.0586 0760 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 22:35:12.0601 0760 PlugPlay - ok 22:35:12.0648 0760 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 22:35:12.0648 0760 Pml Driver HPZ12 - ok 22:35:12.0695 0760 [ 53C96271F1F6DB9F4983FCA85F2DFB52 ] Pnp680r C:\Windows\system32\DRIVERS\pnp680r.sys 22:35:12.0710 0760 Pnp680r - ok 22:35:12.0742 0760 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 22:35:12.0742 0760 PNRPAutoReg - ok 22:35:12.0773 0760 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 22:35:12.0788 0760 PNRPsvc - ok 22:35:12.0835 0760 [ 4F0878FD62D5F7444C5F1C4C66D9D293 ] Point64 C:\Windows\system32\DRIVERS\point64.sys 22:35:12.0835 0760 Point64 - ok 22:35:12.0866 0760 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 22:35:12.0882 0760 PolicyAgent - ok 22:35:12.0929 0760 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll 22:35:12.0944 0760 Power - ok 22:35:12.0960 0760 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 22:35:12.0960 0760 PptpMiniport - ok 22:35:13.0007 0760 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys 22:35:13.0038 0760 Processor - ok 22:35:13.0054 0760 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll 22:35:13.0054 0760 ProfSvc - ok 22:35:13.0069 0760 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe 22:35:13.0085 0760 ProtectedStorage - ok 22:35:13.0132 0760 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys 22:35:13.0147 0760 Psched - ok 22:35:13.0225 0760 [ EA735BF6DF13A857A83C99BF27A422AD ] PST Service C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe 22:35:13.0241 0760 PST Service - ok 22:35:13.0350 0760 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 22:35:13.0412 0760 ql2300 - ok 22:35:13.0444 0760 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 22:35:13.0459 0760 ql40xx - ok 22:35:13.0506 0760 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll 22:35:13.0522 0760 QWAVE - ok 22:35:13.0537 0760 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 22:35:13.0537 0760 QWAVEdrv - ok 22:35:13.0568 0760 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 22:35:13.0568 0760 RasAcd - ok 22:35:13.0615 0760 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 22:35:13.0615 0760 RasAgileVpn - ok 22:35:13.0631 0760 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll 22:35:13.0631 0760 RasAuto - ok 22:35:13.0678 0760 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 22:35:13.0693 0760 Rasl2tp - ok 22:35:13.0740 0760 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll 22:35:13.0756 0760 RasMan - ok 22:35:13.0771 0760 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 22:35:13.0787 0760 RasPppoe - ok 22:35:13.0802 0760 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 22:35:13.0802 0760 RasSstp - ok 22:35:13.0865 0760 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 22:35:13.0865 0760 rdbss - ok 22:35:13.0880 0760 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 22:35:13.0896 0760 rdpbus - ok 22:35:13.0943 0760 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 22:35:13.0943 0760 RDPCDD - ok 22:35:13.0974 0760 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 22:35:13.0990 0760 RDPENCDD - ok 22:35:13.0990 0760 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 22:35:14.0005 0760 RDPREFMP - ok 22:35:14.0052 0760 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 22:35:14.0068 0760 RDPWD - ok 22:35:14.0114 0760 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 22:35:14.0114 0760 rdyboost - ok 22:35:14.0161 0760 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll 22:35:14.0161 0760 RemoteAccess - ok 22:35:14.0224 0760 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll 22:35:14.0224 0760 RemoteRegistry - ok 22:35:14.0270 0760 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 22:35:14.0270 0760 RpcEptMapper - ok 22:35:14.0317 0760 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe 22:35:14.0333 0760 RpcLocator - ok 22:35:14.0364 0760 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll 22:35:14.0380 0760 RpcSs - ok 22:35:14.0380 0760 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 22:35:14.0395 0760 rspndr - ok 22:35:14.0458 0760 [ EC7A66F88756F2D3124B73D68CF5E268 ] S3GIGP C:\Windows\system32\DRIVERS\VTGKModeDX64.sys 22:35:14.0489 0760 S3GIGP - ok 22:35:14.0504 0760 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe 22:35:14.0504 0760 SamSs - ok 22:35:14.0551 0760 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 22:35:14.0582 0760 sbp2port - ok 22:35:14.0614 0760 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll 22:35:14.0629 0760 SCardSvr - ok 22:35:14.0676 0760 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 22:35:14.0676 0760 scfilter - ok 22:35:14.0738 0760 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll 22:35:14.0770 0760 Schedule - ok 22:35:14.0801 0760 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll 22:35:14.0816 0760 SCPolicySvc - ok 22:35:14.0926 0760 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll 22:35:14.0926 0760 SDRSVC - ok 22:35:14.0972 0760 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 22:35:15.0004 0760 secdrv - ok 22:35:15.0050 0760 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll 22:35:15.0050 0760 seclogon - ok 22:35:15.0082 0760 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll 22:35:15.0082 0760 SENS - ok 22:35:15.0128 0760 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll 22:35:15.0144 0760 SensrSvc - ok 22:35:15.0175 0760 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 22:35:15.0175 0760 Serenum - ok 22:35:15.0206 0760 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys 22:35:15.0206 0760 Serial - ok 22:35:15.0238 0760 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 22:35:15.0238 0760 sermouse - ok 22:35:15.0316 0760 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll 22:35:15.0316 0760 SessionEnv - ok 22:35:15.0362 0760 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 22:35:15.0362 0760 sffdisk - ok 22:35:15.0394 0760 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 22:35:15.0394 0760 sffp_mmc - ok 22:35:15.0409 0760 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 22:35:15.0409 0760 sffp_sd - ok 22:35:15.0425 0760 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 22:35:15.0440 0760 sfloppy - ok 22:35:15.0503 0760 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll 22:35:15.0503 0760 SharedAccess - ok 22:35:15.0550 0760 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll 22:35:15.0565 0760 ShellHWDetection - ok 22:35:15.0581 0760 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 22:35:15.0581 0760 SiSRaid2 - ok 22:35:15.0612 0760 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 22:35:15.0612 0760 SiSRaid4 - ok 22:35:15.0628 0760 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys 22:35:15.0628 0760 Smb - ok 22:35:15.0706 0760 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe 22:35:15.0706 0760 SNMPTRAP - ok 22:35:15.0721 0760 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys 22:35:15.0721 0760 spldr - ok 22:35:15.0799 0760 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe 22:35:15.0815 0760 Spooler - ok 22:35:16.0330 0760 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe 22:35:16.0376 0760 sppsvc - ok 22:35:16.0392 0760 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll 22:35:16.0408 0760 sppuinotify - ok 22:35:16.0454 0760 [ E3E6C96B0EF4492C3C8FD0DEEF4E35A1 ] SPTISRV C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe 22:35:16.0454 0760 SPTISRV - ok 22:35:16.0501 0760 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys 22:35:16.0501 0760 srv - ok 22:35:16.0532 0760 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 22:35:16.0532 0760 srv2 - ok 22:35:16.0564 0760 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 22:35:16.0564 0760 srvnet - ok 22:35:16.0626 0760 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 22:35:16.0626 0760 SSDPSRV - ok 22:35:16.0671 0760 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll 22:35:16.0677 0760 SstpSvc - ok 22:35:16.0718 0760 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 22:35:16.0725 0760 stexstor - ok 22:35:16.0774 0760 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll 22:35:16.0819 0760 stisvc - ok 22:35:16.0858 0760 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys 22:35:16.0860 0760 swenum - ok 22:35:16.0883 0760 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll 22:35:16.0895 0760 swprv - ok 22:35:16.0988 0760 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll 22:35:17.0021 0760 SysMain - ok 22:35:17.0126 0760 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll 22:35:17.0137 0760 TabletInputService - ok 22:35:17.0219 0760 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll 22:35:17.0238 0760 TapiSrv - ok 22:35:17.0251 0760 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll 22:35:17.0270 0760 TBS - ok 22:35:17.0351 0760 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 22:35:17.0411 0760 Tcpip - ok 22:35:17.0453 0760 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 22:35:17.0467 0760 TCPIP6 - ok 22:35:17.0494 0760 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 22:35:17.0496 0760 tcpipreg - ok 22:35:17.0541 0760 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 22:35:17.0545 0760 TDPIPE - ok 22:35:17.0561 0760 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 22:35:17.0563 0760 TDTCP - ok 22:35:17.0610 0760 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 22:35:17.0614 0760 tdx - ok 22:35:17.0645 0760 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys 22:35:17.0645 0760 TermDD - ok 22:35:17.0692 0760 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll 22:35:17.0707 0760 TermService - ok 22:35:17.0723 0760 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll 22:35:17.0738 0760 Themes - ok 22:35:17.0738 0760 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll 22:35:17.0754 0760 THREADORDER - ok 22:35:17.0770 0760 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll 22:35:17.0770 0760 TrkWks - ok 22:35:17.0848 0760 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 22:35:17.0848 0760 TrustedInstaller - ok 22:35:17.0910 0760 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 22:35:17.0926 0760 tssecsrv - ok 22:35:17.0972 0760 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 22:35:17.0972 0760 TsUsbFlt - ok 22:35:18.0050 0760 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 22:35:18.0050 0760 tunnel - ok 22:35:18.0066 0760 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 22:35:18.0082 0760 uagp35 - ok 22:35:18.0144 0760 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 22:35:18.0160 0760 udfs - ok 22:35:18.0222 0760 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe 22:35:18.0238 0760 UI0Detect - ok 22:35:18.0269 0760 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 22:35:18.0284 0760 uliagpkx - ok 22:35:18.0331 0760 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys 22:35:18.0347 0760 umbus - ok 22:35:18.0362 0760 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 22:35:18.0362 0760 UmPass - ok 22:35:18.0425 0760 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll 22:35:18.0440 0760 upnphost - ok 22:35:18.0456 0760 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 22:35:18.0456 0760 usbccgp - ok 22:35:18.0503 0760 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys 22:35:18.0503 0760 usbcir - ok 22:35:18.0518 0760 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 22:35:18.0518 0760 usbehci - ok 22:35:18.0550 0760 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 22:35:18.0550 0760 usbhub - ok 22:35:18.0581 0760 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys 22:35:18.0581 0760 usbohci - ok 22:35:18.0596 0760 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 22:35:18.0612 0760 usbprint - ok 22:35:18.0643 0760 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 22:35:18.0659 0760 usbscan - ok 22:35:18.0659 0760 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:35:18.0674 0760 USBSTOR - ok 22:35:18.0690 0760 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 22:35:18.0690 0760 usbuhci - ok 22:35:18.0706 0760 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll 22:35:18.0706 0760 UxSms - ok 22:35:18.0721 0760 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe 22:35:18.0721 0760 VaultSvc - ok 22:35:18.0737 0760 VBoxDRV - ok 22:35:18.0737 0760 VBoxUSBMon - ok 22:35:18.0784 0760 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 22:35:18.0784 0760 vdrvroot - ok 22:35:18.0846 0760 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe 22:35:18.0862 0760 vds - ok 22:35:18.0908 0760 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 22:35:18.0924 0760 vga - ok 22:35:18.0940 0760 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys 22:35:18.0940 0760 VgaSave - ok 22:35:18.0986 0760 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 22:35:19.0002 0760 vhdmp - ok 22:35:19.0033 0760 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys 22:35:19.0033 0760 viaide - ok 22:35:19.0096 0760 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys 22:35:19.0096 0760 volmgr - ok 22:35:19.0174 0760 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 22:35:19.0174 0760 volmgrx - ok 22:35:19.0205 0760 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys 22:35:19.0220 0760 volsnap - ok 22:35:19.0267 0760 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 22:35:19.0267 0760 vsmraid - ok 22:35:19.0345 0760 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe 22:35:19.0392 0760 VSS - ok 22:35:19.0486 0760 [ F1E8C5167F849D1089D8108C50E6FF11 ] vToolbarUpdater15.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe 22:35:19.0501 0760 vToolbarUpdater15.2.0 - ok 22:35:19.0564 0760 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 22:35:19.0610 0760 vwifibus - ok 22:35:19.0642 0760 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll 22:35:19.0657 0760 W32Time - ok 22:35:19.0688 0760 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 22:35:19.0704 0760 WacomPen - ok 22:35:19.0735 0760 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 22:35:19.0735 0760 WANARP - ok 22:35:19.0751 0760 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 22:35:19.0751 0760 Wanarpv6 - ok 22:35:19.0798 0760 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 22:35:19.0829 0760 WatAdminSvc - ok 22:35:19.0922 0760 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe 22:35:19.0969 0760 wbengine - ok 22:35:19.0985 0760 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 22:35:20.0000 0760 WbioSrvc - ok 22:35:20.0047 0760 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll 22:35:20.0063 0760 wcncsvc - ok 22:35:20.0078 0760 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 22:35:20.0094 0760 WcsPlugInService - ok 22:35:20.0110 0760 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys 22:35:20.0125 0760 Wd - ok 22:35:20.0156 0760 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 22:35:20.0172 0760 Wdf01000 - ok 22:35:20.0203 0760 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll 22:35:20.0250 0760 WdiServiceHost - ok 22:35:20.0250 0760 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll 22:35:20.0250 0760 WdiSystemHost - ok 22:35:20.0297 0760 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll 22:35:20.0312 0760 WebClient - ok 22:35:20.0328 0760 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll 22:35:20.0344 0760 Wecsvc - ok 22:35:20.0375 0760 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll 22:35:20.0390 0760 wercplsupport - ok 22:35:20.0422 0760 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll 22:35:20.0422 0760 WerSvc - ok 22:35:20.0453 0760 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 22:35:20.0453 0760 WfpLwf - ok 22:35:20.0484 0760 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 22:35:20.0484 0760 WIMMount - ok 22:35:20.0515 0760 WinDefend - ok 22:35:20.0546 0760 WinHttpAutoProxySvc - ok 22:35:20.0640 0760 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 22:35:20.0640 0760 Winmgmt - ok 22:35:20.0718 0760 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll 22:35:20.0780 0760 WinRM - ok 22:35:20.0858 0760 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 22:35:20.0890 0760 WinUsb - ok 22:35:20.0952 0760 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll 22:35:20.0968 0760 Wlansvc - ok 22:35:21.0014 0760 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 22:35:21.0030 0760 WmiAcpi - ok 22:35:21.0061 0760 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 22:35:21.0061 0760 wmiApSrv - ok 22:35:21.0092 0760 WMPNetworkSvc - ok 22:35:21.0108 0760 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 22:35:21.0139 0760 WPCSvc - ok 22:35:21.0186 0760 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 22:35:21.0186 0760 WPDBusEnum - ok 22:35:21.0217 0760 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 22:35:21.0233 0760 ws2ifsl - ok 22:35:21.0280 0760 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(1) C:\Windows\system32\drivers\WsAudio_DeviceS(1).sys 22:35:21.0280 0760 WsAudio_DeviceS(1) - ok 22:35:21.0295 0760 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(2) C:\Windows\system32\drivers\WsAudio_DeviceS(2).sys 22:35:21.0295 0760 WsAudio_DeviceS(2) - ok 22:35:21.0311 0760 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(3) C:\Windows\system32\drivers\WsAudio_DeviceS(3).sys 22:35:21.0311 0760 WsAudio_DeviceS(3) - ok 22:35:21.0326 0760 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(4) C:\Windows\system32\drivers\WsAudio_DeviceS(4).sys 22:35:21.0326 0760 WsAudio_DeviceS(4) - ok 22:35:21.0342 0760 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(5) C:\Windows\system32\drivers\WsAudio_DeviceS(5).sys 22:35:21.0342 0760 WsAudio_DeviceS(5) - ok 22:35:21.0389 0760 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll 22:35:21.0404 0760 wscsvc - ok 22:35:21.0420 0760 WSearch - ok 22:35:21.0514 0760 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 22:35:21.0623 0760 wuauserv - ok 22:35:21.0670 0760 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 22:35:21.0685 0760 WudfPf - ok 22:35:21.0716 0760 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 22:35:21.0732 0760 WUDFRd - ok 22:35:21.0748 0760 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 22:35:21.0763 0760 wudfsvc - ok 22:35:21.0794 0760 [ C088056DFBA2B3A6955EA596EE5CC507 ] WUSB54GCv3 C:\Windows\system32\DRIVERS\WUSB54GCv3.sys 22:35:21.0810 0760 WUSB54GCv3 - ok 22:35:21.0857 0760 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll 22:35:21.0872 0760 WwanSvc - ok 22:35:21.0888 0760 ================ Scan global =============================== 22:35:21.0935 0760 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll 22:35:21.0997 0760 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:35:22.0013 0760 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll 22:35:22.0060 0760 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll 22:35:22.0122 0760 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe 22:35:22.0122 0760 [Global] - ok 22:35:22.0122 0760 ================ Scan MBR ================================== 22:35:22.0153 0760 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2 22:35:22.0153 0760 \Device\Harddisk2\DR2 - ok 22:35:22.0169 0760 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 22:35:22.0309 0760 \Device\Harddisk0\DR0 - ok 22:35:22.0325 0760 [ 8464D19686910A2E5D0E5C28C70A95AB ] \Device\Harddisk4\DR4 22:35:22.0325 0760 \Device\Harddisk4\DR4 - ok 22:35:22.0325 0760 ================ Scan VBR ================================== 22:35:22.0340 0760 [ CF4C219419516A2CBBBFA0D24A5D2B0F ] \Device\Harddisk2\DR2\Partition1 22:35:22.0418 0760 \Device\Harddisk2\DR2\Partition1 - ok 22:35:22.0434 0760 [ 1768631EC8686518061AF8BE16797E64 ] \Device\Harddisk0\DR0\Partition1 22:35:22.0434 0760 \Device\Harddisk0\DR0\Partition1 - ok 22:35:22.0450 0760 [ B5E1ABF7003AEEE0FC84285CC6154DE9 ] \Device\Harddisk4\DR4\Partition1 22:35:22.0450 0760 \Device\Harddisk4\DR4\Partition1 - ok 22:35:22.0450 0760 ============================================================ 22:35:22.0450 0760 Scan finished 22:35:22.0450 0760 ============================================================ 22:35:22.0465 3216 Detected object count: 0 22:35:22.0465 3216 Actual detected object count: 0 22:35:42.0290 1272 Deinitialize success aswMBR.txt: aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-06-06 22:38:30 —————————– 22:38:30.207 OS Version: Windows x64 6.1.7601 Service Pack 1 22:38:30.207 Number of processors: 2 586 0xF0D 22:38:30.222 ComputerName: LYNNS-DESKTOP UserName: Lynn 22:38:32.094 Initialize success 22:38:51.313 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 22:38:51.313 Disk 0 Vendor: WDC_WD400BB-00JHC0 05.01C05 Size: 38165MB BusType: 3 22:38:51.313 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-4 22:38:51.329 Disk 1 Vendor: IOMEGA_ZIP_250 41.S Size: 38165MB BusType: 2 22:38:51.329 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP2T0L0-0 22:38:51.329 Disk 2 Vendor: WDC_WD5000AADS-00S9B0 01.00A01 Size: 476938MB BusType: 3 22:38:51.531 Disk 2 MBR read successfully 22:38:51.531 Disk 2 MBR scan 22:38:51.531 Disk 2 Windows 7 default MBR code 22:38:51.547 Disk 2 Partition 1 00 07 HPFS/NTFS NTFS 476836 MB offset 206848 22:38:51.563 Disk 2 scanning C:\Windows\system32\drivers 22:38:58.558 Service scanning 22:39:13.733 Modules scanning 22:39:13.734 Disk 2 trace - called modules: 22:39:13.753 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys 22:39:13.753 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0xfffffa8003567060] 22:39:13.753 3 CLASSPNP.SYS[fffff8800145143f] -> nt!IofCallDriver -> [0xfffffa80033e5520] 22:39:13.753 5 ACPI.sys[fffff88000e0b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-0[0xfffffa80033ca060] 22:39:13.753 Scan finished successfully 22:40:21.210 Disk 2 MBR has been saved successfully to "C:\Users\Lynn\Desktop\MBR.dat" 22:40:21.218 The log file has been saved successfully to "C:\Users\Lynn\Desktop\aswMBR.txt"
Please create a new OTL log and post it up. also tell me if something changed with the behaviour of the computer.
Hi,
I tried to use Internet Explorer 10 again and it still does not work, so nothing we did so far has helped. Below is the second log for OTL. Thank you

OTL:

OTL logfile created on: 6/7/2013 5:36:04 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Lynn\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.12 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 59.22% Memory free
6.25 Gb Paging File | 4.83 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 339.41 Gb Free Space | 72.89% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 29.33 Gb Free Space | 78.71% Space Free | Partition Type: NTFS
Drive N: | 111.76 Gb Total Space | 47.00 Gb Free Space | 42.05% Space Free | Partition Type: FAT32

Computer Name: LYNNS-DESKTOP | User Name: Lynn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
PRC - [2013/06/02 07:56:37 | 001,015,984 | —- | M] (AVG Secure Search) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
PRC - [2010/10/01 22:06:36 | 000,348,760 | —- | M] (Kaspersky Lab) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/29 01:27:38 | 000,393,168 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
MOD - [2013/05/29 01:27:35 | 004,051,408 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
MOD - [2013/05/29 01:26:36 | 001,597,392 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll
MOD - [2010/10/01 22:05:46 | 008,972,888 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtGui4.dll
MOD - [2010/10/01 22:05:42 | 002,456,152 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtCore4.dll
MOD - [2010/10/01 21:07:46 | 000,733,184 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\localization_manager.dll
MOD - [2009/10/30 20:32:30 | 000,410,496 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\dblite.dll


========== Services (SafeList) ==========

SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/06/02 07:56:37 | 001,015,984 | —- | M] (AVG Secure Search) [Auto | Running] – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe – (vToolbarUpdater15.2.0)
SRV - [2013/04/24 08:32:38 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/25 15:45:52 | 000,121,144 | —- | M] (Motorola Mobility LLC) [Disabled | Stopped] – C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe – (Motorola Device Manager)
SRV - [2012/12/18 10:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/09/07 22:36:46 | 000,087,992 | —- | M] (Nero AG) [Disabled | Stopped] – C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe – (DeviceMonitorService)
SRV - [2011/09/02 16:06:38 | 000,065,657 | —- | M] (Motorola) [Disabled | Stopped] – C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe – (PST Service)
SRV - [2010/10/22 13:08:18 | 001,039,360 | —- | M] (Hewlett-Packard Co.) [Auto | Running] – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL – (HPSLPSVC)
SRV - [2010/10/01 22:06:36 | 000,348,760 | —- | M] (Kaspersky Lab) [Auto | Running] – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe – (AVP)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/21 17:34:38 | 000,743,992 | —- | M] (Infowatch) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe – (CSObjectsSrv)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/04/02 02:15:40 | 000,061,440 | —- | M] (Creative Technology Ltd) [Disabled | Stopped] – C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe – (CTDevice_Srv)
SRV - [2006/12/14 03:21:20 | 000,045,056 | —- | M] (Sony Corporation) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV)
SRV - [2006/12/14 03:02:08 | 000,069,632 | —- | M] (Sony Corporation) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV)
SRV - [2006/12/14 02:46:16 | 000,057,344 | —- | M] () [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/02 07:56:37 | 000,045,856 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtpx64.sys – (avgtp)
DRV:64bit: - [2013/05/26 19:13:40 | 000,353,296 | —- | M] (Kaspersky Lab) [File_System | System | Running] – C:\Windows\SysNative\drivers\klif.sys – (KLIF)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/08/01 16:59:06 | 000,045,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011/05/18 09:08:32 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011/04/08 06:53:50 | 000,057,968 | —- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\fetn62a.sys – (FETNDIS)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/06 12:29:18 | 000,025,680 | —- | M] (NoteBurn Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ntcdrdrv.sys – (ntcdrdrv)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2009/12/14 12:44:24 | 000,085,048 | —- | M] (Infowatch) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\CSCrySec.sys – (CSCrySec)
DRV:64bit: - [2009/12/14 12:44:24 | 000,066,104 | —- | M] (Infowatch) [Kernel | System | Running] – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys – (CSVirtualDiskDrv)
DRV:64bit: - [2009/10/14 21:18:38 | 000,040,464 | —- | M] (Kaspersky Lab) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\klbg.sys – (KLBG)
DRV:64bit: - [2009/10/02 19:39:32 | 000,021,008 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\klmouflt.sys – (klmouflt)
DRV:64bit: - [2009/09/14 14:46:42 | 000,027,152 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\klim6.sys – (KLIM6)
DRV:64bit: - [2009/09/01 15:29:56 | 000,157,712 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\kl1.sys – (kl1)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/12/04 13:17:16 | 000,797,184 | —- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WUSB54GCv3.sys – (WUSB54GCv3)
DRV:64bit: - [2008/10/17 02:11:56 | 001,023,488 | —- | M] (S3 Graphics Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VTGKModeDX64.sys – (S3GIGP)
DRV:64bit: - [2007/07/24 03:53:04 | 000,125,992 | —- | M] (Silicon Image, Inc) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PnP680r.sys – (Pnp680r)
DRV - [2012/10/30 23:10:34 | 000,022,336 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\gdrv.sys – (gdrv)
DRV - [2012/03/06 22:41:39 | 000,030,528 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\GVTDrv64.sys – (GVTDrv64)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{44816E91-C68A-2FF3-3D8F-8970062E5600}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*;


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files (x86)\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Update (Enabled) = C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC569A9F-6DB5-4ACB-BB2B-C1C281E3D477}: DhcpNameServer = 75.75.76.76 75.75.75.75
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\kloehk.dll (Kaspersky Lab)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\sbhook64.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\sbhook.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/06/14 09:53:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/06/14 22:38:57 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - N:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2002/10/28 13:03:12 | 000,000,000 | RH-D | M] - N:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/06 22:36:17 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Lynn\Desktop\aswMBR.exe
[2013/06/06 22:34:11 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Lynn\Desktop\tdsskiller.exe
[2013/06/03 17:06:45 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/02 08:15:39 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:58:26 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\AVG SafeGuard toolbar
[2013/06/02 07:58:11 | 000,000,000 | —D | C] – C:\ProgramData\AVG SafeGuard toolbar
[2013/06/02 07:57:34 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/02 07:57:14 | 000,045,856 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/02 07:57:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2013/06/02 07:56:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG SafeGuard toolbar
[2013/06/02 07:56:27 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SmartPCFix
[2013/06/02 07:56:06 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/05/30 22:26:12 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\Akamai
[2013/05/27 19:29:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEUDINIT.EXE
[2013/05/26 19:16:32 | 000,085,048 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSCrySec.sys
[2013/05/26 19:16:32 | 000,066,104 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys
[2013/05/26 19:14:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InfoWatch
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/05/26 19:13:40 | 000,353,296 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 18:41:34 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2013/05/26 17:37:02 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/26 17:37:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/26 17:37:00 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/26 17:37:00 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/26 17:36:35 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/26 17:36:35 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/26 17:36:33 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/26 07:56:20 | 000,000,000 | -H-D | C] – C:\TMRescueDisk
[2013/05/26 07:43:09 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2013/05/26 07:42:09 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2013/05/26 07:29:26 | 000,000,000 | –SD | C] – C:\Windows\SysWow64\Microsoft
[2013/05/26 07:26:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/05/24 14:01:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiseFixer
[2013/05/24 14:01:16 | 000,000,000 | —D | C] – C:\Program Files\WiseFixer
[2013/05/10 18:20:35 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/07 17:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/07 17:01:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/07 08:01:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/06/06 22:40:21 | 000,000,512 | —- | M] () – C:\Users\Lynn\Desktop\MBR.dat
[2013/06/06 22:38:06 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Lynn\Desktop\aswMBR.exe
[2013/06/06 22:36:49 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 22:36:49 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 22:34:18 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Lynn\Desktop\tdsskiller.exe
[2013/06/06 22:33:46 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/06 22:33:46 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/06 22:33:46 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/06 22:29:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/06 22:29:19 | 2516,230,144 | -HS- | M] () – C:\hiberfil.sys
[2013/06/06 22:26:15 | 000,000,121 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/06/06 22:24:35 | 000,640,135 | —- | M] () – C:\Users\Lynn\Desktop\adwcleaner.exe
[2013/06/06 07:06:20 | 000,002,366 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/06 07:06:19 | 000,002,364 | —- | M] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/02 08:15:39 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:38 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 08:15:37 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:56:37 | 000,045,856 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagwrn.xml
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2013/05/27 21:54:12 | 000,004,954 | —- | M] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/27 20:45:01 | 000,001,437 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/05/26 20:12:21 | 000,300,240 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/26 19:45:03 | 000,153,053 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:45:03 | 000,107,384 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 19:13:40 | 000,353,296 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 17:27:03 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/05/26 07:41:48 | 000,000,036 | —- | M] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/06 22:40:21 | 000,000,512 | —- | C] () – C:\Users\Lynn\Desktop\MBR.dat
[2013/06/06 22:25:55 | 000,000,121 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/06/06 22:24:28 | 000,640,135 | —- | C] () – C:\Users\Lynn\Desktop\adwcleaner.exe
[2013/06/02 08:15:38 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:37 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 07:57:33 | 000,002,366 | —- | C] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/02 07:57:33 | 000,002,364 | —- | C] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/02 07:56:28 | 000,000,904 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/02 07:56:25 | 000,000,852 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/05/27 21:54:13 | 000,004,954 | —- | C] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/26 19:17:08 | 000,153,053 | —- | C] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:17:08 | 000,107,384 | —- | C] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 07:41:48 | 000,000,036 | —- | C] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[2012/08/14 21:41:01 | 000,000,877 | —- | C] () – C:\Users\Lynn\recStudio.ini
[2012/03/09 00:27:52 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2012/03/06 22:41:39 | 000,030,528 | —- | C] () – C:\Windows\GVTDrv64.sys
[2012/03/04 14:40:33 | 000,000,288 | —- | C] () – C:\Users\Lynn\AppData\Roaming\.backup.dm
[2012/01/23 23:31:05 | 000,007,605 | —- | C] () – C:\Users\Lynn\AppData\Local\resmon.resmoncfg
[2011/12/06 22:53:34 | 000,153,600 | —- | C] () – C:\Windows\SysWow64\WS_ATLMovie.dll
[2011/07/31 20:48:40 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat
[2011/07/31 20:48:40 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat
[2011/07/31 20:26:53 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2011/06/16 11:07:59 | 000,000,344 | —- | C] () – C:\Windows\lgfwup.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/02/24 13:06:59 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Audacity
[2012/01/16 14:07:27 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Canon
[2011/12/06 21:46:49 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\ConverterLite
[2012/01/30 23:36:33 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Kernel for Windows Data Recovery
[2013/05/26 21:18:20 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\MotoCast
[2012/11/28 23:02:38 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola
[2012/11/28 23:03:48 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola Mobility
[2011/07/05 18:38:06 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\OpenOffice.org
[2013/06/02 07:56:54 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\SmartPCFix

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:BC359956

< End of report >
Hi,
I tried to use Internet Explorer 10 again and it still does not work, so nothing we did so far has helped. Below is the second log for OTL. Thank you

OTL:

OTL logfile created on: 6/7/2013 5:36:04 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Lynn\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16576)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.12 Gb Total Physical Memory | 1.85 Gb Available Physical Memory | 59.22% Memory free
6.25 Gb Paging File | 4.83 Gb Available in Paging File | 77.25% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 339.41 Gb Free Space | 72.89% Space Free | Partition Type: NTFS
Drive D: | 37.26 Gb Total Space | 29.33 Gb Free Space | 78.71% Space Free | Partition Type: NTFS
Drive N: | 111.76 Gb Total Space | 47.00 Gb Free Space | 42.05% Space Free | Partition Type: FAT32

Computer Name: LYNNS-DESKTOP | User Name: Lynn | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
PRC - [2013/06/02 07:56:37 | 001,015,984 | —- | M] (AVG Secure Search) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
PRC - [2010/10/01 22:06:36 | 000,348,760 | —- | M] (Kaspersky Lab) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/29 01:27:38 | 000,393,168 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
MOD - [2013/05/29 01:27:35 | 004,051,408 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
MOD - [2013/05/29 01:26:36 | 001,597,392 | —- | M] () – C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll
MOD - [2010/10/01 22:05:46 | 008,972,888 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtGui4.dll
MOD - [2010/10/01 22:05:42 | 002,456,152 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\QtCore4.dll
MOD - [2010/10/01 21:07:46 | 000,733,184 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\localization_manager.dll
MOD - [2009/10/30 20:32:30 | 000,410,496 | —- | M] () – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\dblite.dll


========== Services (SafeList) ==========

SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/06/02 07:56:37 | 001,015,984 | —- | M] (AVG Secure Search) [Auto | Running] – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe – (vToolbarUpdater15.2.0)
SRV - [2013/04/24 08:32:38 | 000,256,904 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/25 15:45:52 | 000,121,144 | —- | M] (Motorola Mobility LLC) [Disabled | Stopped] – C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe – (Motorola Device Manager)
SRV - [2012/12/18 10:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/09/07 22:36:46 | 000,087,992 | —- | M] (Nero AG) [Disabled | Stopped] – C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe – (DeviceMonitorService)
SRV - [2011/09/02 16:06:38 | 000,065,657 | —- | M] (Motorola) [Disabled | Stopped] – C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe – (PST Service)
SRV - [2010/10/22 13:08:18 | 001,039,360 | —- | M] (Hewlett-Packard Co.) [Auto | Running] – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL – (HPSLPSVC)
SRV - [2010/10/01 22:06:36 | 000,348,760 | —- | M] (Kaspersky Lab) [Auto | Running] – C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe – (AVP)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/12/21 17:34:38 | 000,743,992 | —- | M] (Infowatch) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe – (CSObjectsSrv)
SRV - [2009/06/10 17:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/04/02 02:15:40 | 000,061,440 | —- | M] (Creative Technology Ltd) [Disabled | Stopped] – C:\Program Files (x86)\Creative\Shared Files\CTDevSrv.exe – (CTDevice_Srv)
SRV - [2006/12/14 03:21:20 | 000,045,056 | —- | M] (Sony Corporation) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV)
SRV - [2006/12/14 03:02:08 | 000,069,632 | —- | M] (Sony Corporation) [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV)
SRV - [2006/12/14 02:46:16 | 000,057,344 | —- | M] () [Disabled | Stopped] – C:\Program Files (x86)\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/02 07:56:37 | 000,045,856 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtpx64.sys – (avgtp)
DRV:64bit: - [2013/05/26 19:13:40 | 000,353,296 | —- | M] (Kaspersky Lab) [File_System | System | Running] – C:\Windows\SysNative\drivers\klif.sys – (KLIF)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/08/01 16:59:06 | 000,045,416 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2011/05/18 09:08:32 | 000,047,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\dc3d.sys – (dc3d)
DRV:64bit: - [2011/04/08 06:53:50 | 000,057,968 | —- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\fetn62a.sys – (FETNDIS)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/01/06 12:29:18 | 000,025,680 | —- | M] (NoteBurn Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\ntcdrdrv.sys – (ntcdrdrv)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys – (WsAudio_DeviceS(5)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys – (WsAudio_DeviceS(4)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys – (WsAudio_DeviceS(3)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys – (WsAudio_DeviceS(2)
DRV:64bit: - [2010/12/24 16:27:44 | 000,029,288 | —- | M] (Wondershare) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys – (WsAudio_DeviceS(1)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2009/12/14 12:44:24 | 000,085,048 | —- | M] (Infowatch) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\CSCrySec.sys – (CSCrySec)
DRV:64bit: - [2009/12/14 12:44:24 | 000,066,104 | —- | M] (Infowatch) [Kernel | System | Running] – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys – (CSVirtualDiskDrv)
DRV:64bit: - [2009/10/14 21:18:38 | 000,040,464 | —- | M] (Kaspersky Lab) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\klbg.sys – (KLBG)
DRV:64bit: - [2009/10/02 19:39:32 | 000,021,008 | —- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\klmouflt.sys – (klmouflt)
DRV:64bit: - [2009/09/14 14:46:42 | 000,027,152 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\klim6.sys – (KLIM6)
DRV:64bit: - [2009/09/01 15:29:56 | 000,157,712 | —- | M] (Kaspersky Lab) [Kernel | System | Running] – C:\Windows\SysNative\drivers\kl1.sys – (kl1)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/12/04 13:17:16 | 000,797,184 | —- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\WUSB54GCv3.sys – (WUSB54GCv3)
DRV:64bit: - [2008/10/17 02:11:56 | 001,023,488 | —- | M] (S3 Graphics Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\VTGKModeDX64.sys – (S3GIGP)
DRV:64bit: - [2007/07/24 03:53:04 | 000,125,992 | —- | M] (Silicon Image, Inc) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PnP680r.sys – (Pnp680r)
DRV - [2012/10/30 23:10:34 | 000,022,336 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\gdrv.sys – (gdrv)
DRV - [2012/03/06 22:41:39 | 000,030,528 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\GVTDrv64.sys – (GVTDrv64)
DRV - [2009/07/13 21:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{44816E91-C68A-2FF3-3D8F-8970062E5600}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*;


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files (x86)\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/07/31 20:54:50 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Lynn\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Update (Enabled) = C:\Users\Lynn\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Users\Lynn\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe (Kaspersky Lab)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm ()
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll (Kaspersky Lab)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC569A9F-6DB5-4ACB-BB2B-C1C281E3D477}: DhcpNameServer = 75.75.76.76 75.75.75.75
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\kloehk.dll (Kaspersky Lab)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\x64\sbhook64.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\mzvkbd3.dll (Kaspersky Lab)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE\sbhook.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/06/14 09:53:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2011/06/14 22:38:57 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2002/10/17 09:56:50 | 000,000,036 | RH– | M] () - N:\autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2002/10/28 13:03:12 | 000,000,000 | RH-D | M] - N:\autorun – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/06 22:36:17 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Lynn\Desktop\aswMBR.exe
[2013/06/06 22:34:11 | 002,237,968 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Lynn\Desktop\tdsskiller.exe
[2013/06/03 17:06:45 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/02 08:15:39 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:58:26 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\AVG SafeGuard toolbar
[2013/06/02 07:58:11 | 000,000,000 | —D | C] – C:\ProgramData\AVG SafeGuard toolbar
[2013/06/02 07:57:34 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/06/02 07:57:14 | 000,045,856 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/02 07:57:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2013/06/02 07:56:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG SafeGuard toolbar
[2013/06/02 07:56:27 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SmartPCFix
[2013/06/02 07:56:06 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/05/30 22:26:12 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Local\Akamai
[2013/05/27 19:29:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEUDINIT.EXE
[2013/05/26 19:16:32 | 000,085,048 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSCrySec.sys
[2013/05/26 19:16:32 | 000,066,104 | —- | C] (Infowatch) – C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys
[2013/05/26 19:14:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\InfoWatch
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky PURE
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/05/26 19:14:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/05/26 19:13:40 | 000,353,296 | —- | C] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 18:41:34 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2013/05/26 17:37:02 | 001,930,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/05/26 17:37:01 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/26 17:37:00 | 001,796,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/05/26 17:37:00 | 000,111,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/26 17:36:35 | 000,265,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2013/05/26 17:36:35 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2013/05/26 17:36:33 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wwanprotdim.dll
[2013/05/26 07:56:20 | 000,000,000 | -H-D | C] – C:\TMRescueDisk
[2013/05/26 07:43:09 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2013/05/26 07:42:09 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2013/05/26 07:29:26 | 000,000,000 | –SD | C] – C:\Windows\SysWow64\Microsoft
[2013/05/26 07:26:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/05/24 14:01:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WiseFixer
[2013/05/24 14:01:16 | 000,000,000 | —D | C] – C:\Program Files\WiseFixer
[2013/05/10 18:20:35 | 000,000,000 | —D | C] – C:\Users\Lynn\AppData\Roaming\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/05/10 18:20:27 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/07 17:25:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/07 17:01:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/07 08:01:01 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/06/06 22:40:21 | 000,000,512 | —- | M] () – C:\Users\Lynn\Desktop\MBR.dat
[2013/06/06 22:38:06 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Lynn\Desktop\aswMBR.exe
[2013/06/06 22:36:49 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 22:36:49 | 000,013,456 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/06 22:34:18 | 002,237,968 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Lynn\Desktop\tdsskiller.exe
[2013/06/06 22:33:46 | 000,726,444 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/06 22:33:46 | 000,624,162 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/06 22:33:46 | 000,106,538 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/06 22:29:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/06 22:29:19 | 2516,230,144 | -HS- | M] () – C:\hiberfil.sys
[2013/06/06 22:26:15 | 000,000,121 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/06/06 22:24:35 | 000,640,135 | —- | M] () – C:\Users\Lynn\Desktop\adwcleaner.exe
[2013/06/06 07:06:20 | 000,002,366 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/06 07:06:19 | 000,002,364 | —- | M] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/03 17:06:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Lynn\Desktop\OTL.exe
[2013/06/02 08:15:39 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/02 08:15:38 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/02 08:15:38 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/02 08:15:38 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/02 08:15:38 | 000,690,688 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/02 08:15:38 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/02 08:15:38 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/02 08:15:38 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/02 08:15:38 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/02 08:15:38 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/02 08:15:38 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/02 08:15:38 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/02 08:15:38 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/02 08:15:38 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/02 08:15:38 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/02 08:15:38 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/02 08:15:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/02 08:15:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/02 08:15:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/02 08:15:38 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/02 08:15:38 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/02 08:15:38 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/02 08:15:38 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/02 08:15:38 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/02 08:15:38 | 000,089,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/02 08:15:38 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/02 08:15:38 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/02 08:15:38 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/02 08:15:38 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/02 08:15:38 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/02 08:15:38 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/02 08:15:38 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/02 08:15:38 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/02 08:15:38 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/02 08:15:38 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:38 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/02 08:15:38 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/02 08:15:37 | 003,958,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/02 08:15:37 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/02 08:15:37 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/02 08:15:37 | 000,855,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/02 08:15:37 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/02 08:15:37 | 000,603,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/02 08:15:37 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/02 08:15:37 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/02 08:15:37 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/02 08:15:37 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/02 08:15:37 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/02 08:15:37 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/02 08:15:37 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/02 08:15:37 | 000,136,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/02 08:15:37 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/02 08:15:37 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/02 08:15:37 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/02 08:15:37 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/02 08:15:37 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/02 08:15:37 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/02 08:15:37 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/02 08:15:37 | 000,067,072 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/02 08:15:37 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/02 08:15:37 | 000,051,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/02 08:15:37 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/02 08:15:37 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/02 08:15:37 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/02 08:15:37 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/02 08:15:37 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 08:15:37 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/02 08:15:37 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/02 07:56:37 | 000,045,856 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagwrn.xml
[2013/05/27 21:55:21 | 000,001,908 | —- | M] () – C:\Windows\diagerr.xml
[2013/05/27 21:54:12 | 000,004,954 | —- | M] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/27 20:45:01 | 000,001,437 | —- | M] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/05/26 20:12:21 | 000,300,240 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/05/26 19:45:03 | 000,153,053 | —- | M] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:45:03 | 000,107,384 | —- | M] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 19:13:40 | 000,353,296 | —- | M] (Kaspersky Lab) – C:\Windows\SysNative\drivers\klif.sys
[2013/05/26 17:27:03 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/05/26 07:41:48 | 000,000,036 | —- | M] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[1 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/06 22:40:21 | 000,000,512 | —- | C] () – C:\Users\Lynn\Desktop\MBR.dat
[2013/06/06 22:25:55 | 000,000,121 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/06/06 22:24:28 | 000,640,135 | —- | C] () – C:\Users\Lynn\Desktop\adwcleaner.exe
[2013/06/02 08:15:38 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/02 08:15:37 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/02 07:57:33 | 000,002,366 | —- | C] () – C:\Users\Lynn\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/06/02 07:57:33 | 000,002,364 | —- | C] () – C:\Users\Lynn\Desktop\Google Chrome.lnk
[2013/06/02 07:56:28 | 000,000,904 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job
[2013/06/02 07:56:25 | 000,000,852 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job
[2013/05/27 21:54:13 | 000,004,954 | —- | C] () – C:\Users\Lynn\Desktop\Windows Compatibility Report.htm
[2013/05/26 19:17:08 | 000,153,053 | —- | C] () – C:\Windows\SysNative\drivers\klin.dat
[2013/05/26 19:17:08 | 000,107,384 | —- | C] () – C:\Windows\SysNative\drivers\klick.dat
[2013/05/26 07:41:48 | 000,000,036 | —- | C] () – C:\Users\Lynn\AppData\Local\housecall.guid.cache
[2012/08/14 21:41:01 | 000,000,877 | —- | C] () – C:\Users\Lynn\recStudio.ini
[2012/03/09 00:27:52 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat.temp
[2012/03/06 22:41:39 | 000,030,528 | —- | C] () – C:\Windows\GVTDrv64.sys
[2012/03/04 14:40:33 | 000,000,288 | —- | C] () – C:\Users\Lynn\AppData\Roaming\.backup.dm
[2012/01/23 23:31:05 | 000,007,605 | —- | C] () – C:\Users\Lynn\AppData\Local\resmon.resmoncfg
[2011/12/06 22:53:34 | 000,153,600 | —- | C] () – C:\Windows\SysWow64\WS_ATLMovie.dll
[2011/07/31 20:48:40 | 000,211,070 | —- | C] () – C:\Windows\hpoins21.dat
[2011/07/31 20:48:40 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat
[2011/07/31 20:26:53 | 000,005,474 | —- | C] () – C:\Windows\hpomdl21.dat.temp
[2011/06/16 11:07:59 | 000,000,344 | —- | C] () – C:\Windows\lgfwup.ini

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/02/24 13:06:59 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Audacity
[2012/01/16 14:07:27 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Canon
[2011/12/06 21:46:49 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\ConverterLite
[2012/01/30 23:36:33 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Kernel for Windows Data Recovery
[2013/05/26 21:18:20 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\MotoCast
[2012/11/28 23:02:38 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola
[2012/11/28 23:03:48 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\Motorola Mobility
[2011/07/05 18:38:06 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\OpenOffice.org
[2013/06/02 07:56:54 | 000,000,000 | —D | M] – C:\Users\Lynn\AppData\Roaming\SmartPCFix

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:BC359956

< End of report >
Combofix


Combofix should only be run when adviced by a team member!

Link 1
Link 2


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.
Here is the log for ComboFix. Thank you. ComboFix: ComboFix 13-06-08.02 - Lynn 06/09/2013 8:00.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3200.1920 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Kaspersky PURE *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky PURE *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky PURE *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . N:\autorun.inf . . ((((((((((((((((((((((((( Files Created from 2013-05-09 to 2013-06-09 ))))))))))))))))))))))))))))))) . . 2013-06-07 09:02 . 2013-05-14 05:48 9460464 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{813EEEAE-7FF5-4B4B-BF96-FBE7678BAE6F}\mpengine.dll 2013-06-07 02:25 . 2013-06-07 02:26 121 —-a-w- c:\windows\DeleteOnReboot.bat 2013-06-02 11:58 . 2013-06-02 11:58 ——– d—–w- c:\users\Lynn\AppData\Local\AVG SafeGuard toolbar 2013-06-02 11:58 . 2013-06-02 11:58 ——– d—–w- c:\programdata\AVG SafeGuard toolbar 2013-06-02 11:57 . 2013-06-02 11:56 45856 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-06-02 11:57 . 2013-06-07 02:25 ——– d—–w- c:\program files (x86)\Common Files\AVG Secure Search 2013-06-02 11:56 . 2013-06-02 11:57 ——– d—–w- c:\program files (x86)\AVG SafeGuard toolbar 2013-06-02 11:56 . 2013-06-02 11:56 ——– d—–w- c:\users\Lynn\AppData\Roaming\SmartPCFix 2013-06-02 11:56 . 2013-06-02 11:56 ——– d–h–w- c:\programdata\Common Files 2013-05-31 02:26 . 2013-05-31 02:26 ——– d—–w- c:\users\Lynn\AppData\Local\Akamai 2013-05-30 02:54 . 2013-05-30 02:54 ——– d—–w- c:\users\LAB\AppData\Local\Apple 2013-05-29 13:17 . 2013-05-29 13:17 ——– d—–w- c:\users\LAB\AppData\Local\Adobe 2013-05-27 23:29 . 2013-02-17 05:40 28672 —-a-w- c:\windows\system32\IEUDINIT.EXE 2013-05-26 23:16 . 2009-12-14 16:44 85048 —-a-w- c:\windows\system32\drivers\CSCrySec.sys 2013-05-26 23:16 . 2009-12-14 16:44 66104 —-a-w- c:\windows\system32\drivers\CSVirtualDiskDrv.sys 2013-05-26 23:14 . 2013-05-26 23:14 ——– d—–w- c:\program files (x86)\Common Files\InfoWatch 2013-05-26 23:14 . 2013-06-09 11:48 ——– d—–w- c:\programdata\Kaspersky Lab 2013-05-26 23:14 . 2013-05-26 23:14 ——– d—–w- c:\program files (x86)\Kaspersky Lab 2013-05-26 23:13 . 2013-05-26 23:13 353296 —-a-w- c:\windows\system32\drivers\klif.sys 2013-05-26 22:41 . 2013-05-26 22:41 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files 2013-05-26 21:37 . 2013-02-27 05:52 14172672 —-a-w- c:\windows\system32\shell32.dll 2013-05-26 21:37 . 2013-02-27 05:48 1930752 —-a-w- c:\windows\system32\authui.dll 2013-05-26 21:37 . 2013-02-27 05:52 197120 —-a-w- c:\windows\system32\shdocvw.dll 2013-05-26 21:37 . 2013-02-27 06:02 111448 —-a-w- c:\windows\system32\consent.exe 2013-05-26 21:37 . 2013-02-27 05:47 70144 —-a-w- c:\windows\system32\appinfo.dll 2013-05-26 21:37 . 2013-02-27 04:49 1796096 —-a-w- c:\windows\SysWow64\authui.dll 2013-05-26 21:36 . 2013-04-10 06:01 265064 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-05-26 21:36 . 2013-04-10 06:01 983400 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-05-26 21:36 . 2011-02-03 11:25 144384 —-a-w- c:\windows\system32\cdd.dll 2013-05-26 21:36 . 2013-03-19 05:53 48640 —-a-w- c:\windows\system32\wwanprotdim.dll 2013-05-26 21:36 . 2013-03-19 05:53 230400 —-a-w- c:\windows\system32\wwansvc.dll 2013-05-26 21:36 . 2013-04-10 03:30 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-05-26 11:56 . 2013-05-26 11:56 ——– d—–w- C:\TMRescueDisk 2013-05-26 11:43 . 2013-05-27 00:08 ——– d—–w- c:\programdata\Trend Micro 2013-05-26 11:42 . 2013-05-26 11:43 ——– d—–w- c:\program files\Trend Micro 2013-05-26 11:29 . 2013-05-26 11:29 ——– d-s—w- c:\windows\SysWow64\Microsoft 2013-05-26 11:26 . 2013-05-26 12:09 ——– d—–w- c:\program files (x86)\Trend Micro 2013-05-24 18:01 . 2013-05-27 00:08 ——– d—–w- c:\program files\WiseFixer 2013-05-10 22:20 . 2013-05-10 22:20 ——– d—–w- c:\users\Lynn\AppData\Roaming\SUPERAntiSpyware.com 2013-05-10 22:20 . 2013-05-12 19:02 ——– d—–w- c:\program files\SUPERAntiSpyware 2013-05-10 22:20 . 2013-05-10 22:20 ——– d—–w- c:\programdata\SUPERAntiSpyware.com . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-27 00:03 . 2011-06-17 07:45 75016696 —-a-w- c:\windows\system32\MRT.exe 2013-05-02 06:06 . 2011-06-16 04:24 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-04-24 12:32 . 2012-03-31 16:03 691592 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-04-24 12:32 . 2011-11-06 19:42 71048 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-20 10:45 . 2013-04-20 10:45 95648 —-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-04-20 10:45 . 2012-10-24 03:16 866720 —-a-w- c:\windows\SysWow64\npdeployJava1.dll 2013-04-20 10:45 . 2011-07-05 22:35 788896 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-04-13 05:49 . 2013-05-26 21:36 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-26 21:36 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-26 21:36 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-26 21:36 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-26 21:36 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-26 21:36 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-23 20:15 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-04 18:50 . 2013-05-06 22:15 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-03-19 06:04 . 2013-04-10 05:48 5550424 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 05:46 . 2013-04-10 05:48 43520 —-a-w- c:\windows\system32\csrsrv.dll 2013-03-19 05:04 . 2013-04-10 05:48 3968856 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-10 05:48 3913560 —-a-w- c:\windows\SysWow64\ntoskrnl.exe 2013-03-19 04:47 . 2013-04-10 05:48 6656 —-a-w- c:\windows\SysWow64\apisetschema.dll 2013-03-19 03:06 . 2013-04-10 05:48 112640 —-a-w- c:\windows\system32\smss.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon] @="{dd230880-495a-11d1-b064-008048ec2fc5}" [HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}] 2010-10-02 02:05 129624 —-a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\shellex.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\avp.exe" [2010-10-02 348760] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~2\KASPER~1\KASPER~1\sbhook.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 VBoxDRV;PortableVBoxDRV;j:\portable-virtualbox\app64\drivers\VBoxDrv\VBoxDrv.sys;j:\portable-virtualbox\app64\drivers\VBoxDrv\VBoxDrv.sys [x] R2 VBoxUSBMon;PortableVBoxUSBMon;j:\portable-virtualbox\app64\drivers\USB\filter\VBoxUSBMon.sys;j:\portable-virtualbox\app64\drivers\USB\filter\VBoxUSBMon.sys [x] R3 ALSysIO;ALSysIO;c:\users\Lynn\AppData\Local\Temp\ALSysIO64.sys;c:\users\Lynn\AppData\Local\Temp\ALSysIO64.sys [x] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] R3 GVTDrv64;GVTDrv64;c:\windows\GVTDrv64.sys;c:\windows\GVTDrv64.sys [x] R3 MarkFun_NT;MarkFun_NT;c:\program files (x86)\Gigabyte\ET5\markfun.a64;c:\program files (x86)\Gigabyte\ET5\markfun.a64 [x] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 CSObjectsSrv;CryptoStorage control service;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe;c:\program files (x86)\Common Files\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe [x] R4 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [x] R4 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [x] R4 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [x] R4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [x] S0 CSCrySec;InfoWatch Encrypt Sector Library driver;c:\windows\system32\DRIVERS\CSCrySec.sys;c:\windows\SYSNATIVE\DRIVERS\CSCrySec.sys [x] S0 KLBG;Kaspersky Lab Boot Guard Driver;c:\windows\system32\DRIVERS\klbg.sys;c:\windows\SYSNATIVE\DRIVERS\klbg.sys [x] S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ntcdrdrv.sys [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x] S1 CSVirtualDiskDrv;InfoWatch Virtual Disk driver;c:\windows\system32\DRIVERS\CSVirtualDiskDrv.sys;c:\windows\SYSNATIVE\DRIVERS\CSVirtualDiskDrv.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(1).sys [x] S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(2).sys [x] S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(3).sys [x] S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(4).sys [x] S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys;c:\windows\SYSNATIVE\drivers\WsAudio_DeviceS(5).sys [x] S3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\DRIVERS\WUSB54GCv3.sys;c:\windows\SYSNATIVE\DRIVERS\WUSB54GCv3.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-06-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-31 12:32] . 2013-06-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001Core.job - c:\users\Lynn\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-02 11:56] . 2013-06-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3764578106-988534880-3039420071-1001UA.job - c:\users\Lynn\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-02 11:56] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\KAVOverlayIcon] @="{dd230880-495a-11d1-b064-008048ec2fc5}" [HKEY_CLASSES_ROOT\CLSID\{dd230880-495a-11d1-b064-008048ec2fc5}] 2010-10-02 02:06 170584 —-a-w- c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\x64\ShellEx.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://xfinity.comcast.net/ mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local;192.168.*.*; IE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky PURE\ie_banner_deny.htm TCP: DhcpNameServer = 75.75.76.76 75.75.75.75 . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run- - (no file) AddRemove-Kernel for Windows Data Recovery_is1 - h:\downloads\Recovery soft\Kernel\Kernel for Windows Data Recovery\unins000.exe AddRemove-ophcrack - h:\ophcrack\uninst.exe AddRemove-UBCD4Win_is1 - h:\downloads\ubcd4win\UBCD4Win\unins000.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\MarkFun_NT] "ImagePath"="\??\c:\program files (x86)\Gigabyte\ET5\markfun.a64" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_169_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_169.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-06-09 08:14:29 ComboFix-quarantined-files.txt 2013-06-09 12:14 . Pre-Run: 368,525,058,048 bytes free Post-Run: 377,741,488,128 bytes free . - - End Of File - - FC713BD90A2CA52238B405A058676F01 8F558EB6672622401DA993E1E865C861
Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.
Hi: I tried to download ESET and it gave me a message that since I am not using Internet Explorer (I'm using Google Chrome because Internet Explorer is not working). It's asking me to download the "ESET Smart Installer". Is it OK to do this or will it mess up some results of the scan for my computer? Please let me know if it is OK to download the installer. Thank You.
Hi: Here are the results of the ESET scan. C:\MGtools\Process.exe Win32/PrcView application C:\Program Files (x86)\ophcrack\ophcrack.exe a variant of Win32/PSWTool.ophCrack.A application C:\Program Files (x86)\ophcrack\ophcrack_nogui.exe a variant of Win32/PSWTool.ophCrack.A application C:\Program Files (x86)\ophcrack\pwdump\lsremora.dll Win32/PSWTool.PWDump6 application C:\Program Files (x86)\ophcrack\pwdump\pwdump6_setup.exe Win32/PSWTool.PWDump6 application C:\System Volume Information\_restore{39D6AD0D-1030-4672-8AD9-422605D103D0}\RP15\A0000449.exe Win32/PrcView application C:\Users\Lynn\Downloads\DVD Buring\cbsidlm-tr1_10a-Burn_DVD__CD__Fliperac-SEO-75374673.exe Win32/DownloadAdmin.G application C:\Users\Lynn\Downloads\DVD Buring\cbsidlm-tr1_10a-Burn_DVD__CD__Fliperac-SEO-75374673A.exe Win32/DownloadAdmin.G application C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5\ApnIC[1].0 a variant of Win32/Bundled.Toolbar.Ask application C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\ApnIC[1].0 a variant of Win32/Bundled.Toolbar.Ask application C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5\ApnIC[1].0 a variant of Win32/Bundled.Toolbar.Ask application C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\ApnIC[1].0 a variant of Win32/Bundled.Toolbar.Ask application D:\Documents and Settings\Lynn Brown\Local Settings\Temp\AskSLib.dll a variant of Win32/Bundled.Toolbar.Ask application D:\Documents and Settings\Lynn Brown\Local Settings\Temporary Internet Files\Content.IE5\DB27R07N\avira_free_antivirus_en[1].exe a variant of Win32/Bundled.Toolbar.Ask application D:\Program Files\Avira\AntiVir Desktop\apnic.dll a variant of Win32/Bundled.Toolbar.Ask application D:\Program Files\Avira\AntiVir Desktop\apntoolbarinstaller.exe a variant of Win32/Bundled.Toolbar.Ask application D:\WINDOWS\Temp\AskSLib.dll a variant of Win32/Bundled.Toolbar.Ask application N:\Downloads\avira\avira_free_antivirus_en.exe a variant of Win32/Bundled.Toolbar.Ask application N:\Downloads\ubcd4win\UBCD4WinV360.exe Win32/PrcView application N:\Downloads\ubcd4win\UBCD4Win\plugin\Cleanup Tools\SDFix\SDFix.exe Win32/PrcView application N:\Downloads\ubcd4win\UBCD4Win\BartPE\PROGRAMS\sdfix\SDFix.exe Win32/PrcView application N:\Downloads\Password\ophcrack\ophcrack-win32-installer-3.5.0.exe multiple threats N:\Downloads\Cleaning Tools\New sys cleaner\setup.exe a variant of Win32/AirAdInstaller.A application N:\Dot's ASUS\cbsidlm-tr1_10a-Burn_DVD__CD__Fliperac-SEO-75374673.exe Win32/DownloadAdmin.G application N:\Dot's ASUS\cbsidlm-tr1_10a-Burn_DVD__CD__Fliperac-SEO-75374673A.exe Win32/DownloadAdmin.G application Thank You.
The files listed aren´t malware but contain security risks.
It would be safer to delete them immediately. Your choice.


SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
I deleated the items from ESET as you told me to do. I also did the scan with Security Check as you requested, below are the results.
Security Check=

Results of screen317's Security Check version 0.99.64
Windows 7 Service Pack 1 x64
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
Kaspersky PURE
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 21
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
Kaspersky Lab Kaspersky PURE avp.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
Your system is all clean now! :)



Uninstall our tools.
Please follow these steps in order:

  • In the case we used Defogger to turn off your CD emulation software. You can start it again and use the Enable button.
  • In the case we used Combofix. Rename the combofix.exe to uninstall.exe and run it one last time. You shall be noted that Combofix has been removed.
  • In any case please download delfix to your desktop.
    • Close all other programms and start delfix.
    • Please check all the boxes and run the tool.
    • delfix will now delete all found traces of our removal process
  • If there is still something left please delete it manualy.



Reading Material
How to protect yourself

  • System Updates
    Beeing up to date is very important. Please be sure to activate automatic updates in your control panel.
    Windows XP | Windows Vista |
    Windows 7 | windows 8
  • Protection
    What you need is one (not more) good virus scanner with backgroud protection. Additionally I recommend a special malwarescanner that you run from time to time.
    Personally I am using the avast! Antivirus Free Edition and Malwarebytes Anti-Malware. They offer you good protection for free use. But please remember: You get only the full protection if you use the payed versions of your security software.
  • Up to date Software
    Stay up to date with all the programs you use. Some of those really have to have an eye on are: your browser(s) including add-ons and plug-ins, Java, Flash Player, your virus scanner, and basically every software you use often. These link may help you to check:
    • Secunia Online Software Inspector - Checks if your software has updates available.
    • Filehippo Update Checkere - This tool also scans your computer for outdated software.
    • Mozilla: Check your plugins - The webpage will tell you if you have outdated plugins in your Firefox browser.
  • Backups
    There are chances for an emergency every day. So be prepared. Back up your data on a regular basis. If you burn it to DVDs from time to time, use a cloud-drive or a professional network backup system is your choice.
  • Brains
    It's no joke! You really need one of those things. :) It is very important not just to click anywhere it is colored or flashing while you surfing on the web. Do not click an OK button on any popping window without reading what it says. While installing software always choose the custom mode, read what those windows says and uncheck adware that will be installed along the software you want.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI