This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

win32.bagle.gen and Win32.downloader.gen [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

This pc has some really bad maleware infections, including rootkits which are a real pain to remove I have tried all sorts of different maleware removal tools and programs, i probably deleted 90% of the infection files, but the root kit infections i think still remain. I ended my whole process with cleaning the computer with ESET online scanner and it still managed to find 6 maleware infections, even after using several other programs before it.

I just can't seen to get rid of this Win32.Bagle. and Win32.downloader.gen. I know how these viruses and worms work, they install diffferent application and other potentual harmful malicious items into your computer, they also change many registery values.

This is the process i undertook.


Step #1

http://malwaretips.com/blogs/win32-downloader-gen-trojan/

I followed this entire tutorial and used each and every program stated here. Found infections.

Step #2, used other software and ran a scan with Nortan Power eraser, cureit, and Superantispyware, finally ending with a scan of ESET online scanner which still managed to find 6 infections 4 of which got deleted but 2 more remains, so the computer is still not free of infections apparently,

Here are the logs i managed to save.

Rouge Killer:

RogueKiller V8.6.1 [Jun 19 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Ashley [Admin rights]
Mode : Remove – Date : 06/19/2013 14:07:13
| ARK || FAK || MBR |

¤¤¤ Bad processes : 1 ¤¤¤
[SVCHOST] svchost.exe – C:\Users\Ashley\Desktop\mbam-chameleon-1.62.1.1000\svchost.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 93 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB2731 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD5003 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB9844 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD6190 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB3645 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD2761 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB1290 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD7504 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB1140 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD4004 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB4392 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD4325 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB2038 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD9560 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB9797 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD164 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB9148 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD6184 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB7400 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD3306 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB6368 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD4707 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB9181 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD6260 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB2537 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD7311 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB5245 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD8945 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingB7285 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKCU\[…]\RunOnce : SpybotDeletingD7299 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB2731 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD5003 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB9844 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD6190 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB3645 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD2761 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB1290 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD7504 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB1140 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD4004 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB4392 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD4325 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB2038 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD9560 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB9797 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD164 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB9148 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD6184 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB7400 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD3306 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB6368 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD4707 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB9181 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD6260 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB2537 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD7311 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB5245 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD8945 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingB7285 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKUS\S-1-5-21-2238972994-1161546085-716596809-1000\[…]\RunOnce : SpybotDeletingD7299 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> [0x2] The system cannot find the file specified.
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA5931 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC797 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA9959 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC548 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA674 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC4034 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA4107 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC1295 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA4490 (command.com /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC458 (cmd.exe /c del "C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA1938 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC8834 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\ChromeModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA1653 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC7624 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\CltMngSvc.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA8478 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC2255 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\FirefoxModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA4486 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC4511 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\InternetExplorerModule.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA9908 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC9228 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcp100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA4933 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC1948 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\msvcr100.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA5565 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC6853 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\rep.dat" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA4269 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC4502 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPHook32.dll" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA175 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC7269 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\SPRunner.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingA3064 (command.com /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : SpybotDeletingC6280 (cmd.exe /c del "C:\Users\Ashley\AppData\Roaming\SearchProtect\bin\uninstall.exe" [x][x]) -> DELETED
[RUN][SUSP PATH] HKLM\[…]\Wow6432Node\[…]\RunOnce : 1 (C:\Users\Ashley\Desktop\mbam-chameleon-1.62.1.1000\mbam-chameleon.exe /r /p [7]) -> DELETED
[HJ DESK] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 1 ¤¤¤
[Ashley][SUSP PATH] _uninst_.lnk : C:\Users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_.lnk @C:\Users\Ashley\AppData\Local\Temp\_uninst_.bat [-][x] -> DELETED

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600AAJS-08PSA0 ATA Device +++++
— User —
[MBR] 4120842d563b0cc4ddc5d217b50e3583
[BSP] 3b160d394e77b4479d456c19bfd011ed : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 152525 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_D_06192013_140713.txt >>
RKreport[0]_S_06192013_140517.txt



Junk Ware Removal

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Ultimate x64
Ran by [removed] on Wed 06/19/2013 at 15:50:24.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{83F6DC1D-7C93-4103-AB25-77DFE4F247A2}



~~~ Files



~~~ Folders



~~~ Chrome

Successfully deleted: [Registry Key] hkey_current_user\software\policies\google\chrome\extensioninstallforcelist



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 06/19/2013 at 15:51:32.57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ADW Cleaner

# AdwCleaner v2.303 - Logfile created 06/19/2013 at 15:45:22
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Ultimate Service Pack 1 (64 bits)
# User : Ashley - ASHLEY-PC
# Boot Mode : Safe mode with networking
# Running from : C:\Users\Ashley\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nemfjadlboooiffmcelkafilagddogim
File Deleted : C:\Users\Ashley\Desktop\HDVidCodec.lnk
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\HDvidCodec.com
Folder Deleted : C:\Program Files (x86)\Iminent
Folder Deleted : C:\Program Files (x86)\InternetHelper3.1
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Folder Deleted : C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nemfjadlboooiffmcelkafilagddogim
Folder Deleted : C:\Users\Ashley\AppData\Local\Temp\Iminent
Folder Deleted : C:\Users\Ashley\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Ashley\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ashley\AppData\LocalLow\InternetHelper3.1
Folder Deleted : C:\Users\Ashley\AppData\Roaming\Iminent
Folder Deleted : C:\Users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HDvidCodec.com

***** [Registry] *****

Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\InternetHelper3.1
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\nemfjadlboooiffmcelkafilagddogim
Key Deleted : HKCU\Software\Iminent
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07CBF788-1359-421B-A4E3-5A8D041B90A3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKCU\Software\d28cdde234ed43
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3289663
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\InfoAtoms
Key Deleted : HKLM\Software\InternetHelper3.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_nonsearch_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_nonsearch_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6CE83F03-4DFD-4070-A0A7-C46C82E20971}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{07CBF788-1359-421B-A4E3-5A8D041B90A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{6CE83F03-4DFD-4070-A0A7-C46C82E20971}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\d28cdde234ed43
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kpkbnefaikfaeadgidhpoanckoiaheli
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\nemfjadlboooiffmcelkafilagddogim
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16FC43A2-49FA-45D5-AE4A-037309B744A2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{595EEFCC-BAE8-477A-A65D-E2953279D4AB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07CBF788-1359-421B-A4E3-5A8D041B90A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\InternetHelper3.1 Toolbar
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Tarma Installer
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{07CBF788-1359-421B-A4E3-5A8D041B90A3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{07CBF788-1359-421B-A4E3-5A8D041B90A3}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{07CBF788-1359-421B-A4E3-5A8D041B90A3}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16611

[OK] Registry is clean.

-\\ Google Chrome v27.0.1453.110

File : C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.37] : icon_url = "hxxp://search.conduit.com/fav.ico",
Deleted [l.40] : keyword = "search.conduit.com",
Deleted [l.44] : search_url = "hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN24[…]
Deleted [l.45] : suggest_url = "hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}&CUI=U[…]
Deleted [l.2422] : homepage = "hxxp://search.conduit.com/?ctid=CT3289663&SearchSource=48&CUI=UN24470857261048732&UM[…]
Deleted [l.2896] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3289663&SearchSource=48&CUI[…]

File : C:\Users\Chuck\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [18367 octets] - [19/06/2013 15:45:22]

########## EOF - C:\AdwCleaner[S1].txt - [18428 octets] ##########


TTDS Killer For Rootkit Entries

13:34:06.0840 2580 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:34:07.0379 2580 ============================================================
13:34:07.0379 2580 Current date / time: 2013/06/19 13:34:07.0379
13:34:07.0379 2580 SystemInfo:
13:34:07.0379 2580
13:34:07.0380 2580 OS Version: 6.1.7601 ServicePack: 1.0
13:34:07.0380 2580 Product type: Workstation
13:34:07.0380 2580 ComputerName: ASHLEY-PC
13:34:07.0380 2580 UserName: Ashley
13:34:07.0380 2580 Windows directory: C:\Windows
13:34:07.0380 2580 System windows directory: C:\Windows
13:34:07.0380 2580 Running under WOW64
13:34:07.0380 2580 Processor architecture: Intel x64
13:34:07.0380 2580 Number of processors: 4
13:34:07.0380 2580 Page size: 0x1000
13:34:07.0380 2580 Boot type: Safe boot with network
13:34:07.0380 2580 ============================================================
13:34:08.0446 2580 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:34:08.0486 2580 ============================================================
13:34:08.0486 2580 \Device\Harddisk0\DR0:
13:34:08.0486 2580 MBR partitions:
13:34:08.0486 2580 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:34:08.0486 2580 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x129E6800
13:34:08.0486 2580 ============================================================
13:34:08.0503 2580 C: <-> \Device\Harddisk0\DR0\Partition2
13:34:08.0503 2580 ============================================================
13:34:08.0503 2580 Initialize success
13:34:08.0503 2580 ============================================================
13:36:52.0573 2908 ============================================================
13:36:52.0573 2908 Scan started
13:36:52.0573 2908 Mode: Manual; TDLFS;
13:36:52.0573 2908 ============================================================
13:36:52.0894 2908 ================ Scan system memory ========================
13:36:52.0894 2908 System memory - ok
13:36:52.0894 2908 ================ Scan services =============================
13:36:53.0040 2908 [ ABDCD326E1DD1C62509ED94C278A7453 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
13:36:53.0041 2908 !SASCORE - ok
13:36:53.0189 2908 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
13:36:53.0191 2908 1394ohci - ok
13:36:53.0229 2908 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
13:36:53.0232 2908 ACPI - ok
13:36:53.0253 2908 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
13:36:53.0253 2908 AcpiPmi - ok
13:36:53.0355 2908 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:36:53.0357 2908 AdobeARMservice - ok
13:36:53.0409 2908 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
13:36:53.0413 2908 adp94xx - ok
13:36:53.0447 2908 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
13:36:53.0450 2908 adpahci - ok
13:36:53.0470 2908 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
13:36:53.0471 2908 adpu320 - ok
13:36:53.0493 2908 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:36:53.0493 2908 AeLookupSvc - ok
13:36:53.0542 2908 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
13:36:53.0547 2908 AFD - ok
13:36:53.0575 2908 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:36:53.0576 2908 agp440 - ok
13:36:53.0589 2908 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
13:36:53.0590 2908 ALG - ok
13:36:53.0607 2908 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
13:36:53.0607 2908 aliide - ok
13:36:53.0617 2908 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
13:36:53.0618 2908 amdide - ok
13:36:53.0647 2908 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
13:36:53.0647 2908 AmdK8 - ok
13:36:53.0650 2908 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
13:36:53.0650 2908 AmdPPM - ok
13:36:53.0678 2908 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
13:36:53.0678 2908 amdsata - ok
13:36:53.0702 2908 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
13:36:53.0704 2908 amdsbs - ok
13:36:53.0718 2908 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
13:36:53.0719 2908 amdxata - ok
13:36:53.0774 2908 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
13:36:53.0774 2908 AppID - ok
13:36:53.0794 2908 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:36:53.0794 2908 AppIDSvc - ok
13:36:53.0840 2908 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
13:36:53.0841 2908 Appinfo - ok
13:36:53.0880 2908 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
13:36:53.0882 2908 AppMgmt - ok
13:36:53.0899 2908 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
13:36:53.0899 2908 arc - ok
13:36:53.0916 2908 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
13:36:53.0916 2908 arcsas - ok
13:36:54.0007 2908 [ 31E2470E61D5A390405BA41C279D8446 ] asComSvc C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
13:36:54.0029 2908 asComSvc - ok
13:36:54.0075 2908 [ 0466B91EE5767A769E9F8EDB8EF94DDB ] asHmComSvc C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
13:36:54.0098 2908 asHmComSvc - ok
13:36:54.0169 2908 [ FEF9DD9EA587F8886ADE43C1BEFBDAFE ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
13:36:54.0170 2908 AsIO - ok
13:36:54.0202 2908 [ AD8947D621FDCA48F1F39F4624B60AA1 ] AsSysCtrlService C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
13:36:54.0204 2908 AsSysCtrlService - ok
13:36:54.0214 2908 [ 1392B92179B07B672720763D9B1028A5 ] AsUpIO C:\Windows\syswow64\drivers\AsUpIO.sys
13:36:54.0215 2908 AsUpIO - ok
13:36:54.0249 2908 [ 55B8384F53CF6405A7729F1CECEB0FA0 ] AsusFanControlService C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe
13:36:54.0253 2908 AsusFanControlService - ok
13:36:54.0276 2908 [ A5E4CDB420540095D1293C874B5F89AA ] ASUSFILTER C:\Windows\syswow64\drivers\ASUSFILTER.sys
13:36:54.0276 2908 ASUSFILTER - ok
13:36:54.0317 2908 [ 0BAEFD3F648C6E7AB52990DD9565E4E2 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
13:36:54.0317 2908 aswFsBlk - ok
13:36:54.0351 2908 [ 7A62C389380F6FF3FA952D511D8790B8 ] aswFW C:\Windows\system32\drivers\aswFW.sys
13:36:54.0352 2908 aswFW - ok
13:36:54.0401 2908 [ 890918D53B80B474CFAFB48995B85AF3 ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
13:36:54.0401 2908 aswKbd - ok
13:36:54.0440 2908 [ FA562F34ED6633C66170B09182B4C049 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
13:36:54.0440 2908 aswMonFlt - ok
13:36:54.0452 2908 [ 518B8D447A1975AB46DA093A2E743256 ] aswNdis C:\Windows\system32\DRIVERS\aswNdis.sys
13:36:54.0453 2908 aswNdis - ok
13:36:54.0469 2908 [ 94CCA87794454E1824D59B092B9F70C4 ] aswNdis2 C:\Windows\system32\drivers\aswNdis2.sys
13:36:54.0472 2908 aswNdis2 - ok
13:36:54.0494 2908 [ 64E2BAB4096C13D2342BC4661C967E07 ] aswRdr C:\Windows\System32\Drivers\aswrdr2.sys
13:36:54.0494 2908 aswRdr - ok
13:36:54.0500 2908 [ 5573AA70993A2BB81525B1C704B88763 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
13:36:54.0501 2908 aswRvrt - ok
13:36:54.0533 2908 [ 10ED1CAB84AA65983C41A11F60294C9B ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
13:36:54.0557 2908 aswSnx - ok
13:36:54.0569 2908 [ 00E5253353717D3CA12A0F5A6F9991EC ] aswSP C:\Windows\system32\drivers\aswSP.sys
13:36:54.0572 2908 aswSP - ok
13:36:54.0586 2908 [ 29DD8E458A84171202AA4979364C30C0 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
13:36:54.0586 2908 aswTdi - ok
13:36:54.0615 2908 [ 6359B99C955DB9F40B653159A0EED261 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
13:36:54.0617 2908 aswVmm - ok
13:36:54.0640 2908 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:36:54.0640 2908 AsyncMac - ok
13:36:54.0661 2908 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
13:36:54.0662 2908 atapi - ok
13:36:54.0738 2908 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:36:54.0744 2908 AudioEndpointBuilder - ok
13:36:54.0763 2908 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
13:36:54.0766 2908 AudioSrv - ok
13:36:54.0818 2908 [ 28D6701C710AD7BA3CB95E75F8F1A9AA ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
13:36:54.0819 2908 avast! Antivirus - ok
13:36:54.0865 2908 [ C2009C6A452BD07B30D773349589B762 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
13:36:54.0868 2908 avast! Firewall - ok
13:36:54.0919 2908 [ CA0D66B63DBD2A22D0AC9B758D67B8E8 ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
13:36:54.0919 2908 avgtp - ok
13:36:54.0992 2908 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:36:54.0993 2908 AxInstSV - ok
13:36:55.0029 2908 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
13:36:55.0033 2908 b06bdrv - ok
13:36:55.0071 2908 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
13:36:55.0073 2908 b57nd60a - ok
13:36:55.0109 2908 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
13:36:55.0109 2908 BDESVC - ok
13:36:55.0117 2908 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
13:36:55.0118 2908 Beep - ok
13:36:55.0195 2908 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
13:36:55.0202 2908 BFE - ok
13:36:55.0226 2908 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
13:36:55.0248 2908 BITS - ok
13:36:55.0273 2908 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
13:36:55.0273 2908 blbdrive - ok
13:36:55.0304 2908 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:36:55.0305 2908 bowser - ok
13:36:55.0325 2908 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:36:55.0325 2908 BrFiltLo - ok
13:36:55.0327 2908 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:36:55.0327 2908 BrFiltUp - ok
13:36:55.0351 2908 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
13:36:55.0352 2908 Browser - ok
13:36:55.0370 2908 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
13:36:55.0372 2908 Brserid - ok
13:36:55.0375 2908 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
13:36:55.0375 2908 BrSerWdm - ok
13:36:55.0377 2908 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
13:36:55.0377 2908 BrUsbMdm - ok
13:36:55.0380 2908 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
13:36:55.0380 2908 BrUsbSer - ok
13:36:55.0383 2908 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:36:55.0383 2908 BTHMODEM - ok
13:36:55.0421 2908 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
13:36:55.0422 2908 bthserv - ok
13:36:55.0452 2908 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:36:55.0452 2908 cdfs - ok
13:36:55.0492 2908 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:36:55.0493 2908 cdrom - ok
13:36:55.0546 2908 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
13:36:55.0547 2908 CertPropSvc - ok
13:36:55.0561 2908 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
13:36:55.0562 2908 circlass - ok
13:36:55.0588 2908 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
13:36:55.0592 2908 CLFS - ok
13:36:55.0639 2908 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:36:55.0641 2908 clr_optimization_v2.0.50727_32 - ok
13:36:55.0698 2908 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:36:55.0700 2908 clr_optimization_v2.0.50727_64 - ok
13:36:55.0764 2908 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:36:55.0826 2908 clr_optimization_v4.0.30319_32 - ok
13:36:55.0860 2908 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:36:55.0863 2908 clr_optimization_v4.0.30319_64 - ok
13:36:55.0897 2908 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
13:36:55.0897 2908 CmBatt - ok
13:36:55.0922 2908 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:36:55.0922 2908 cmdide - ok
13:36:55.0973 2908 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
13:36:55.0977 2908 CNG - ok
13:36:55.0995 2908 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
13:36:55.0995 2908 Compbatt - ok
13:36:56.0026 2908 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
13:36:56.0026 2908 CompositeBus - ok
13:36:56.0045 2908 COMSysApp - ok
13:36:56.0056 2908 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
13:36:56.0056 2908 crcdisk - ok
13:36:56.0123 2908 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:36:56.0124 2908 CryptSvc - ok
13:36:56.0183 2908 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
13:36:56.0188 2908 CSC - ok
13:36:56.0248 2908 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
13:36:56.0254 2908 CscService - ok
13:36:56.0334 2908 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
13:36:56.0340 2908 DcomLaunch - ok
13:36:56.0379 2908 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
13:36:56.0381 2908 defragsvc - ok
13:36:56.0450 2908 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:36:56.0451 2908 DfsC - ok
13:36:56.0568 2908 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
13:36:56.0571 2908 Dhcp - ok
13:36:56.0593 2908 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
13:36:56.0593 2908 discache - ok
13:36:56.0639 2908 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
13:36:56.0639 2908 Disk - ok
13:36:56.0718 2908 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:36:56.0732 2908 Dnscache - ok
13:36:56.0830 2908 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
13:36:56.0832 2908 dot3svc - ok
13:36:56.0879 2908 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
13:36:56.0880 2908 DPS - ok
13:36:56.0919 2908 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:36:56.0920 2908 drmkaud - ok
13:36:56.0961 2908 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:36:56.0983 2908 DXGKrnl - ok
13:36:57.0013 2908 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
13:36:57.0014 2908 EapHost - ok
13:36:57.0082 2908 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
13:36:57.0140 2908 ebdrv - ok
13:36:57.0182 2908 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
13:36:57.0183 2908 EFS - ok
13:36:57.0234 2908 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:36:57.0247 2908 ehRecvr - ok
13:36:57.0274 2908 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
13:36:57.0275 2908 ehSched - ok
13:36:57.0300 2908 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
13:36:57.0304 2908 elxstor - ok
13:36:57.0336 2908 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
13:36:57.0336 2908 ErrDev - ok
13:36:57.0371 2908 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
13:36:57.0374 2908 EventSystem - ok
13:36:57.0379 2908 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
13:36:57.0380 2908 exfat - ok
13:36:57.0399 2908 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:36:57.0400 2908 fastfat - ok
13:36:57.0476 2908 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
13:36:57.0482 2908 Fax - ok
13:36:57.0485 2908 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:36:57.0486 2908 fdc - ok
13:36:57.0519 2908 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
13:36:57.0519 2908 fdPHost - ok
13:36:57.0522 2908 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
13:36:57.0522 2908 FDResPub - ok
13:36:57.0538 2908 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:36:57.0538 2908 FileInfo - ok
13:36:57.0552 2908 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:36:57.0552 2908 Filetrace - ok
13:36:57.0568 2908 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:36:57.0568 2908 flpydisk - ok
13:36:57.0630 2908 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:36:57.0632 2908 FltMgr - ok
13:36:57.0712 2908 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
13:36:57.0735 2908 FontCache - ok
13:36:57.0804 2908 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:36:57.0805 2908 FontCache3.0.0.0 - ok
13:36:57.0820 2908 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:36:57.0821 2908 FsDepends - ok
13:36:57.0868 2908 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:36:57.0869 2908 Fs_Rec - ok
13:36:57.0902 2908 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:36:57.0903 2908 fvevol - ok
13:36:57.0932 2908 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
13:36:57.0933 2908 gagp30kx - ok
13:36:57.0996 2908 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
13:36:58.0008 2908 gpsvc - ok
13:36:58.0188 2908 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:36:58.0189 2908 gupdate - ok
13:36:58.0206 2908 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:36:58.0206 2908 gupdatem - ok
13:36:58.0220 2908 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
13:36:58.0221 2908 hcw85cir - ok
13:36:58.0265 2908 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:36:58.0268 2908 HdAudAddService - ok
13:36:58.0317 2908 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
13:36:58.0318 2908 HDAudBus - ok
13:36:58.0333 2908 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
13:36:58.0333 2908 HidBatt - ok
13:36:58.0340 2908 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
13:36:58.0341 2908 HidBth - ok
13:36:58.0344 2908 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
13:36:58.0344 2908 HidIr - ok
13:36:58.0367 2908 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
13:36:58.0368 2908 hidserv - ok
13:36:58.0405 2908 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
13:36:58.0405 2908 HidUsb - ok
13:36:58.0458 2908 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:36:58.0459 2908 hkmsvc - ok
13:36:58.0512 2908 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:36:58.0514 2908 HomeGroupListener - ok
13:36:58.0560 2908 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:36:58.0561 2908 HomeGroupProvider - ok
13:36:58.0597 2908 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
13:36:58.0598 2908 HpSAMD - ok
13:36:58.0669 2908 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:36:58.0676 2908 HTTP - ok
13:36:58.0725 2908 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:36:58.0725 2908 hwpolicy - ok
13:36:58.0769 2908 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
13:36:58.0770 2908 i8042prt - ok
13:36:58.0803 2908 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
13:36:58.0807 2908 iaStorV - ok
13:36:58.0862 2908 [ 90D95B25F8413F937A2E155F196D892C ] ICCS C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
13:36:58.0864 2908 ICCS - ok
13:36:58.0900 2908 [ C1010ADD3DDAE1196ED21057AF7B2AAE ] ICCWDT C:\Windows\system32\DRIVERS\ICCWDT.sys
13:36:58.0901 2908 ICCWDT - ok
13:36:58.0975 2908 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:36:58.0988 2908 idsvc - ok
13:36:59.0019 2908 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
13:36:59.0019 2908 iirsp - ok
13:36:59.0057 2908 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
13:36:59.0070 2908 IKEEXT - ok
13:36:59.0181 2908 [ 9CC645EB9697AA4F2D5A39835C80A0A2 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
13:36:59.0257 2908 IntcAzAudAddService - ok
13:36:59.0325 2908 [ B353F1834FCD36D77BE3F74992C147D4 ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
13:36:59.0337 2908 Intel® Capability Licensing Service Interface - ok
13:36:59.0355 2908 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
13:36:59.0356 2908 intelide - ok
13:36:59.0392 2908 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:36:59.0392 2908 intelppm - ok
13:36:59.0423 2908 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:36:59.0424 2908 IPBusEnum - ok
13:36:59.0465 2908 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:36:59.0466 2908 IpFilterDriver - ok
13:36:59.0527 2908 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:36:59.0533 2908 iphlpsvc - ok
13:36:59.0563 2908 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
13:36:59.0563 2908 IPMIDRV - ok
13:36:59.0578 2908 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:36:59.0578 2908 IPNAT - ok
13:36:59.0601 2908 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:36:59.0602 2908 IRENUM - ok
13:36:59.0629 2908 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:36:59.0629 2908 isapnp - ok
13:36:59.0663 2908 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
13:36:59.0666 2908 iScsiPrt - ok
13:36:59.0698 2908 [ D596D915CF091DA1F8CE4BD38BB5D509 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
13:36:59.0698 2908 iusb3hcs - ok
13:36:59.0736 2908 [ 023896E23B61543A15A230EED996D911 ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
13:36:59.0737 2908 iusb3hub - ok
13:36:59.0781 2908 [ 7FAEC13F1ADD619F4B5B2D2CBF841E8E ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
13:36:59.0783 2908 iusb3xhc - ok
13:36:59.0843 2908 [ 5B7DE9D87B9D2713BDD6A53678DC2A49 ] jhi_service C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
13:36:59.0845 2908 jhi_service - ok
13:36:59.0863 2908 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
13:36:59.0863 2908 kbdclass - ok
13:36:59.0895 2908 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
13:36:59.0896 2908 kbdhid - ok
13:36:59.0907 2908 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
13:36:59.0907 2908 KeyIso - ok
13:36:59.0958 2908 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:36:59.0958 2908 KSecDD - ok
13:37:00.0013 2908 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:37:00.0014 2908 KSecPkg - ok
13:37:00.0037 2908 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:37:00.0037 2908 ksthunk - ok
13:37:00.0073 2908 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
13:37:00.0076 2908 KtmRm - ok
13:37:00.0145 2908 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
13:37:00.0148 2908 LanmanServer - ok
13:37:00.0195 2908 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:37:00.0196 2908 LanmanWorkstation - ok
13:37:00.0222 2908 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:37:00.0222 2908 lltdio - ok
13:37:00.0251 2908 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:37:00.0254 2908 lltdsvc - ok
13:37:00.0272 2908 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:37:00.0273 2908 lmhosts - ok
13:37:00.0317 2908 [ E70FD0D2C95F559A17321D831875593D ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
13:37:00.0320 2908 LMS - ok
13:37:00.0352 2908 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
13:37:00.0352 2908 LSI_FC - ok
13:37:00.0356 2908 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
13:37:00.0356 2908 LSI_SAS - ok
13:37:00.0371 2908 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:37:00.0371 2908 LSI_SAS2 - ok
13:37:00.0392 2908 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:37:00.0392 2908 LSI_SCSI - ok
13:37:00.0431 2908 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
13:37:00.0432 2908 luafv - ok
13:37:00.0482 2908 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:37:00.0483 2908 Mcx2Svc - ok
13:37:00.0495 2908 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
13:37:00.0496 2908 megasas - ok
13:37:00.0514 2908 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
13:37:00.0517 2908 MegaSR - ok
13:37:00.0535 2908 [ 772A1DEEDFDBC244183B5C805D1B7D85 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
13:37:00.0535 2908 MEIx64 - ok
13:37:00.0567 2908 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
13:37:00.0567 2908 MMCSS - ok
13:37:00.0581 2908 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
13:37:00.0581 2908 Modem - ok
13:37:00.0612 2908 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:37:00.0613 2908 monitor - ok
13:37:00.0644 2908 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys
13:37:00.0645 2908 mouclass - ok
13:37:00.0657 2908 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:37:00.0658 2908 mouhid - ok
13:37:00.0709 2908 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:37:00.0709 2908 mountmgr - ok
13:37:00.0735 2908 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
13:37:00.0737 2908 mpio - ok
13:37:00.0764 2908 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:37:00.0765 2908 mpsdrv - ok
13:37:00.0823 2908 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
13:37:00.0836 2908 MpsSvc - ok
13:37:00.0892 2908 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:37:00.0893 2908 MRxDAV - ok
13:37:00.0945 2908 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:37:00.0946 2908 mrxsmb - ok
13:37:00.0963 2908 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:37:00.0965 2908 mrxsmb10 - ok
13:37:01.0008 2908 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:37:01.0008 2908 mrxsmb20 - ok
13:37:01.0053 2908 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
13:37:01.0053 2908 msahci - ok
13:37:01.0082 2908 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:37:01.0083 2908 msdsm - ok
13:37:01.0101 2908 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
13:37:01.0102 2908 MSDTC - ok
13:37:01.0123 2908 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:37:01.0123 2908 Msfs - ok
13:37:01.0135 2908 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:37:01.0136 2908 mshidkmdf - ok
13:37:01.0150 2908 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:37:01.0151 2908 msisadrv - ok
13:37:01.0191 2908 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:37:01.0192 2908 MSiSCSI - ok
13:37:01.0194 2908 msiserver - ok
13:37:01.0224 2908 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:37:01.0224 2908 MSKSSRV - ok
13:37:01.0242 2908 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:37:01.0242 2908 MSPCLOCK - ok
13:37:01.0247 2908 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:37:01.0247 2908 MSPQM - ok
13:37:01.0302 2908 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:37:01.0305 2908 MsRPC - ok
13:37:01.0316 2908 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
13:37:01.0317 2908 mssmbios - ok
13:37:01.0333 2908 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:37:01.0333 2908 MSTEE - ok
13:37:01.0339 2908 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
13:37:01.0339 2908 MTConfig - ok
13:37:01.0360 2908 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
13:37:01.0361 2908 Mup - ok
13:37:01.0412 2908 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
13:37:01.0417 2908 napagent - ok
13:37:01.0452 2908 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:37:01.0455 2908 NativeWifiP - ok
13:37:01.0528 2908 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:37:01.0541 2908 NDIS - ok
13:37:01.0559 2908 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:37:01.0559 2908 NdisCap - ok
13:37:01.0573 2908 [ 270B10B8BD822DD4673781E0A1935DFB ] ndisrd C:\Windows\system32\DRIVERS\ndisrd.sys
13:37:01.0574 2908 ndisrd - ok
13:37:01.0596 2908 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:37:01.0597 2908 NdisTapi - ok
13:37:01.0642 2908 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:37:01.0642 2908 Ndisuio - ok
13:37:01.0696 2908 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:37:01.0697 2908 NdisWan - ok
13:37:01.0744 2908 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:37:01.0744 2908 NDProxy - ok
13:37:01.0754 2908 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:37:01.0755 2908 NetBIOS - ok
13:37:01.0834 2908 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:37:01.0836 2908 NetBT - ok
13:37:01.0838 2908 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
13:37:01.0839 2908 Netlogon - ok
13:37:01.0872 2908 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
13:37:01.0875 2908 Netman - ok
13:37:01.0882 2908 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
13:37:01.0893 2908 netprofm - ok
13:37:01.0926 2908 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:37:01.0928 2908 NetTcpPortSharing - ok
13:37:01.0944 2908 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
13:37:01.0944 2908 nfrd960 - ok
13:37:01.0996 2908 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:37:01.0999 2908 NlaSvc - ok
13:37:02.0010 2908 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:37:02.0010 2908 Npfs - ok
13:37:02.0030 2908 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
13:37:02.0030 2908 nsi - ok
13:37:02.0041 2908 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:37:02.0041 2908 nsiproxy - ok
13:37:02.0088 2908 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:37:02.0119 2908 Ntfs - ok
13:37:02.0141 2908 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
13:37:02.0142 2908 Null - ok
13:37:02.0356 2908 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:37:02.0566 2908 nvlddmkm - ok
13:37:02.0617 2908 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:37:02.0618 2908 nvraid - ok
13:37:02.0653 2908 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:37:02.0654 2908 nvstor - ok
13:37:02.0727 2908 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe
13:37:02.0749 2908 nvsvc - ok
13:37:02.0812 2908 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
13:37:02.0836 2908 nvUpdatusService - ok
13:37:02.0872 2908 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:37:02.0872 2908 nv_agp - ok
13:37:02.0898 2908 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:37:02.0899 2908 ohci1394 - ok
13:37:02.0943 2908 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:37:02.0946 2908 p2pimsvc - ok
13:37:02.0973 2908 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
13:37:02.0978 2908 p2psvc - ok
13:37:03.0016 2908 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
13:37:03.0017 2908 Parport - ok
13:37:03.0085 2908 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:37:03.0086 2908 partmgr - ok
13:37:03.0122 2908 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:37:03.0127 2908 PcaSvc - ok
13:37:03.0151 2908 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
13:37:03.0153 2908 pci - ok
13:37:03.0159 2908 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
13:37:03.0160 2908 pciide - ok
13:37:03.0176 2908 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
13:37:03.0178 2908 pcmcia - ok
13:37:03.0195 2908 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
13:37:03.0196 2908 pcw - ok
13:37:03.0225 2908 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:37:03.0231 2908 PEAUTH - ok
13:37:03.0275 2908 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
13:37:03.0297 2908 PeerDistSvc - ok
13:37:03.0360 2908 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:37:03.0360 2908 PerfHost - ok
13:37:03.0439 2908 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
13:37:03.0462 2908 pla - ok
13:37:03.0490 2908 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:37:03.0494 2908 PlugPlay - ok
13:37:03.0516 2908 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:37:03.0516 2908 PNRPAutoReg - ok
13:37:03.0535 2908 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:37:03.0536 2908 PNRPsvc - ok
13:37:03.0580 2908 [ 34A8FAE065249F85A67A3215FF5ECB34 ] Point64 C:\Windows\system32\DRIVERS\point64.sys
13:37:03.0580 2908 Point64 - ok
13:37:03.0636 2908 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:37:03.0641 2908 PolicyAgent - ok
13:37:03.0667 2908 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
13:37:03.0669 2908 Power - ok
13:37:03.0734 2908 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:37:03.0734 2908 PptpMiniport - ok
13:37:03.0754 2908 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
13:37:03.0755 2908 Processor - ok
13:37:03.0811 2908 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
13:37:03.0813 2908 ProfSvc - ok
13:37:03.0823 2908 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:37:03.0824 2908 ProtectedStorage - ok
13:37:03.0888 2908 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:37:03.0888 2908 Psched - ok
13:37:03.0933 2908 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
13:37:03.0965 2908 ql2300 - ok
13:37:03.0973 2908 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
13:37:03.0974 2908 ql40xx - ok
13:37:04.0003 2908 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
13:37:04.0005 2908 QWAVE - ok
13:37:04.0012 2908 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:37:04.0013 2908 QWAVEdrv - ok
13:37:04.0026 2908 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:37:04.0026 2908 RasAcd - ok
13:37:04.0061 2908 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:37:04.0062 2908 RasAgileVpn - ok
13:37:04.0079 2908 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
13:37:04.0080 2908 RasAuto - ok
13:37:04.0131 2908 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:37:04.0131 2908 Rasl2tp - ok
13:37:04.0183 2908 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
13:37:04.0186 2908 RasMan - ok
13:37:04.0199 2908 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:37:04.0200 2908 RasPppoe - ok
13:37:04.0226 2908 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:37:04.0227 2908 RasSstp - ok
13:37:04.0276 2908 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:37:04.0279 2908 rdbss - ok
13:37:04.0289 2908 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
13:37:04.0290 2908 rdpbus - ok
13:37:04.0297 2908 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:37:04.0297 2908 RDPCDD - ok
13:37:04.0346 2908 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
13:37:04.0347 2908 RDPDR - ok
13:37:04.0369 2908 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:37:04.0369 2908 RDPENCDD - ok
13:37:04.0381 2908 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
13:37:04.0381 2908 RDPREFMP - ok
13:37:04.0415 2908 [ 70CBA1A0C98600A2AA1863479B35CB90 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:37:04.0415 2908 RdpVideoMiniport - ok
13:37:04.0461 2908 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:37:04.0463 2908 RDPWD - ok
13:37:04.0526 2908 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:37:04.0527 2908 rdyboost - ok
13:37:04.0550 2908 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:37:04.0551 2908 RemoteAccess - ok
13:37:04.0579 2908 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:37:04.0580 2908 RemoteRegistry - ok
13:37:04.0608 2908 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:37:04.0609 2908 RpcEptMapper - ok
13:37:04.0636 2908 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
13:37:04.0637 2908 RpcLocator - ok
13:37:04.0700 2908 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
13:37:04.0702 2908 RpcSs - ok
13:37:04.0719 2908 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:37:04.0720 2908 rspndr - ok
13:37:04.0773 2908 [ 3713DACCA1025B05A6343104112708D9 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
13:37:04.0775 2908 RTL8167 - ok
13:37:04.0802 2908 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
13:37:04.0803 2908 s3cap - ok
13:37:04.0815 2908 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
13:37:04.0815 2908 SamSs - ok
13:37:04.0924 2908 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
13:37:04.0925 2908 SASDIFSV - ok
13:37:04.0936 2908 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
13:37:04.0937 2908 SASKUTIL - ok
13:37:04.0959 2908 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:37:04.0959 2908 sbp2port - ok
13:37:05.0093 2908 [ 794D4B48DFB6E999537C7C3947863463 ] SBSDWSCService C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
13:37:05.0099 2908 SBSDWSCService - ok
13:37:05.0120 2908 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:37:05.0122 2908 SCardSvr - ok
13:37:05.0170 2908 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:37:05.0171 2908 scfilter - ok
13:37:05.0213 2908 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
13:37:05.0237 2908 Schedule - ok
13:37:05.0295 2908 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
13:37:05.0296 2908 SCPolicySvc - ok
13:37:05.0350 2908 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:37:05.0352 2908 SDRSVC - ok
13:37:05.0380 2908 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:37:05.0381 2908 secdrv - ok
13:37:05.0431 2908 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
13:37:05.0432 2908 seclogon - ok
13:37:05.0453 2908 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
13:37:05.0454 2908 SENS - ok
13:37:05.0460 2908 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:37:05.0461 2908 SensrSvc - ok
13:37:05.0482 2908 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
13:37:05.0482 2908 Serenum - ok
13:37:05.0496 2908 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
13:37:05.0496 2908 Serial - ok
13:37:05.0511 2908 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
13:37:05.0511 2908 sermouse - ok
13:37:05.0563 2908 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
13:37:05.0564 2908 SessionEnv - ok
13:37:05.0587 2908 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:37:05.0588 2908 sffdisk - ok
13:37:05.0597 2908 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:37:05.0598 2908 sffp_mmc - ok
13:37:05.0607 2908 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:37:05.0608 2908 sffp_sd - ok
13:37:05.0624 2908 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
13:37:05.0624 2908 sfloppy - ok
13:37:05.0649 2908 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:37:05.0652 2908 SharedAccess - ok
13:37:05.0701 2908 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:37:05.0704 2908 ShellHWDetection - ok
13:37:05.0721 2908 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:37:05.0721 2908 SiSRaid2 - ok
13:37:05.0735 2908 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
13:37:05.0736 2908 SiSRaid4 - ok
13:37:05.0763 2908 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:37:05.0764 2908 Smb - ok
13:37:05.0796 2908 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:37:05.0797 2908 SNMPTRAP - ok
13:37:05.0861 2908 [ 0FFE35F0B0CD5A324BBE22F02569AE3B ] speedfan C:\Windows\syswow64\speedfan.sys
13:37:05.0861 2908 speedfan - ok
13:37:05.0873 2908 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
13:37:05.0873 2908 spldr - ok
13:37:05.0902 2908 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
13:37:05.0907 2908 Spooler - ok
13:37:06.0019 2908 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
13:37:06.0092 2908 sppsvc - ok
13:37:06.0106 2908 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
13:37:06.0107 2908 sppuinotify - ok
13:37:06.0166 2908 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
13:37:06.0170 2908 srv - ok
13:37:06.0188 2908 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:37:06.0191 2908 srv2 - ok
13:37:06.0244 2908 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:37:06.0245 2908 srvnet - ok
13:37:06.0290 2908 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:37:06.0292 2908 SSDPSRV - ok
13:37:06.0305 2908 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:37:06.0306 2908 SstpSvc - ok
13:37:06.0341 2908 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
13:37:06.0345 2908 Stereo Service - ok
13:37:06.0368 2908 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
13:37:06.0368 2908 stexstor - ok
13:37:06.0448 2908 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
13:37:06.0454 2908 stisvc - ok
13:37:06.0489 2908 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
13:37:06.0489 2908 storflt - ok
13:37:06.0515 2908 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
13:37:06.0516 2908 storvsc - ok
13:37:06.0542 2908 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
13:37:06.0543 2908 swenum - ok
13:37:06.0570 2908 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
13:37:06.0575 2908 swprv - ok
13:37:06.0585 2908 Synth3dVsc - ok
13:37:06.0716 2908 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
13:37:06.0748 2908 SysMain - ok
13:37:06.0797 2908 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:37:06.0798 2908 TabletInputService - ok
13:37:06.0855 2908 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:37:06.0858 2908 TapiSrv - ok
13:37:06.0867 2908 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
13:37:06.0868 2908 TBS - ok
13:37:06.0944 2908 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:37:06.0977 2908 Tcpip - ok
13:37:07.0029 2908 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
13:37:07.0035 2908 TCPIP6 - ok
13:37:07.0087 2908 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:37:07.0088 2908 tcpipreg - ok
13:37:07.0119 2908 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:37:07.0119 2908 TDPIPE - ok
13:37:07.0139 2908 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:37:07.0139 2908 TDTCP - ok
13:37:07.0208 2908 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:37:07.0209 2908 tdx - ok
13:37:07.0231 2908 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
13:37:07.0232 2908 TermDD - ok
13:37:07.0292 2908 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
13:37:07.0305 2908 TermService - ok
13:37:07.0322 2908 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
13:37:07.0323 2908 Themes - ok
13:37:07.0349 2908 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
13:37:07.0350 2908 THREADORDER - ok
13:37:07.0359 2908 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
13:37:07.0360 2908 TrkWks - ok
13:37:07.0430 2908 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:37:07.0432 2908 TrustedInstaller - ok
13:37:07.0477 2908 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:37:07.0477 2908 tssecsrv - ok
13:37:07.0519 2908 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
13:37:07.0520 2908 TsUsbFlt - ok
13:37:07.0522 2908 tsusbhub - ok
13:37:07.0586 2908 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:37:07.0586 2908 tunnel - ok
13:37:07.0596 2908 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
13:37:07.0596 2908 uagp35 - ok
13:37:07.0646 2908 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:37:07.0649 2908 udfs - ok
13:37:07.0676 2908 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:37:07.0677 2908 UI0Detect - ok
13:37:07.0696 2908 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:37:07.0696 2908 uliagpkx - ok
13:37:07.0729 2908 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
13:37:07.0730 2908 umbus - ok
13:37:07.0741 2908 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
13:37:07.0741 2908 UmPass - ok
13:37:07.0794 2908 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
13:37:07.0796 2908 UmRdpService - ok
13:37:07.0892 2908 [ C485FB802F6C4A306B8F89BA087E5CA2 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
13:37:07.0897 2908 UNS - ok
13:37:07.0915 2908 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
13:37:07.0918 2908 upnphost - ok
13:37:07.0944 2908 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:37:07.0945 2908 usbccgp - ok
13:37:08.0027 2908 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:37:08.0028 2908 usbcir - ok
13:37:08.0049 2908 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
13:37:08.0050 2908 usbehci - ok
13:37:08.0082 2908 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:37:08.0085 2908 usbhub - ok
13:37:08.0116 2908 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:37:08.0117 2908 usbohci - ok
13:37:08.0160 2908 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:37:08.0160 2908 usbprint - ok
13:37:08.0207 2908 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:37:08.0207 2908 usbscan - ok
13:37:08.0219 2908 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:37:08.0219 2908 USBSTOR - ok
13:37:08.0234 2908 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
13:37:08.0234 2908 usbuhci - ok
13:37:08.0258 2908 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
13:37:08.0259 2908 UxSms - ok
13:37:08.0273 2908 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
13:37:08.0273 2908 VaultSvc - ok
13:37:08.0299 2908 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
13:37:08.0299 2908 vdrvroot - ok
13:37:08.0359 2908 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
13:37:08.0364 2908 vds - ok
13:37:08.0383 2908 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:37:08.0383 2908 vga - ok
13:37:08.0400 2908 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
13:37:08.0401 2908 VgaSave - ok
13:37:08.0403 2908 VGPU - ok
13:37:08.0440 2908 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
13:37:08.0441 2908 vhdmp - ok
13:37:08.0473 2908 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
13:37:08.0473 2908 viaide - ok
13:37:08.0504 2908 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
13:37:08.0506 2908 vmbus - ok
13:37:08.0525 2908 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
13:37:08.0525 2908 VMBusHID - ok
13:37:08.0543 2908 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:37:08.0543 2908 volmgr - ok
13:37:08.0602 2908 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:37:08.0605 2908 volmgrx - ok
13:37:08.0632 2908 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:37:08.0635 2908 volsnap - ok
13:37:08.0651 2908 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
13:37:08.0652 2908 vsmraid - ok
13:37:08.0726 2908 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
13:37:08.0760 2908 VSS - ok
13:37:08.0901 2908 [ F1E8C5167F849D1089D8108C50E6FF11 ] vToolbarUpdater15.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
13:37:08.0926 2908 vToolbarUpdater15.2.0 - ok
13:37:08.0986 2908 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
13:37:08.0986 2908 vwifibus - ok
13:37:09.0017 2908 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
13:37:09.0021 2908 W32Time - ok
13:37:09.0043 2908 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
13:37:09.0043 2908 WacomPen - ok
13:37:09.0124 2908 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
13:37:09.0124 2908 WANARP - ok
13:37:09.0134 2908 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:37:09.0134 2908 Wanarpv6 - ok
13:37:09.0213 2908 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
13:37:09.0235 2908 WatAdminSvc - ok
13:37:09.0355 2908 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
13:37:09.0378 2908 wbengine - ok
13:37:09.0464 2908 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
13:37:09.0466 2908 WbioSrvc - ok
13:37:09.0518 2908 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:37:09.0522 2908 wcncsvc - ok
13:37:09.0535 2908 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:37:09.0536 2908 WcsPlugInService - ok
13:37:09.0560 2908 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
13:37:09.0560 2908 Wd - ok
13:37:09.0593 2908 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:37:09.0606 2908 Wdf01000 - ok
13:37:09.0676 2908 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:37:09.0677 2908 WdiServiceHost - ok
13:37:09.0680 2908 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:37:09.0681 2908 WdiSystemHost - ok
13:37:09.0727 2908 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
13:37:09.0730 2908 WebClient - ok
13:37:09.0739 2908 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:37:09.0742 2908 Wecsvc - ok
13:37:09.0757 2908 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:37:09.0758 2908 wercplsupport - ok
13:37:09.0784 2908 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
13:37:09.0785 2908 WerSvc - ok
13:37:09.0798 2908 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
13:37:09.0798 2908 WfpLwf - ok
13:37:09.0807 2908 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
13:37:09.0807 2908 WIMMount - ok
13:37:09.0819 2908 WinDefend - ok
13:37:09.0832 2908 WinHttpAutoProxySvc - ok
13:37:09.0886 2908 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:37:09.0889 2908 Winmgmt - ok
13:37:09.0970 2908 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
13:37:10.0035 2908 WinRM - ok
13:37:10.0071 2908 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
13:37:10.0072 2908 WinUsb - ok
13:37:10.0109 2908 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
13:37:10.0122 2908 Wlansvc - ok
13:37:10.0163 2908 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:37:10.0163 2908 WmiAcpi - ok
13:37:10.0192 2908 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:37:10.0194 2908 wmiApSrv - ok
13:37:10.0211 2908 WMPNetworkSvc - ok
13:37:10.0241 2908 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:37:10.0241 2908 WPCSvc - ok
13:37:10.0287 2908 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:37:10.0289 2908 WPDBusEnum - ok
13:37:10.0310 2908 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:37:10.0310 2908 ws2ifsl - ok
13:37:10.0354 2908 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
13:37:10.0355 2908 wscsvc - ok
13:37:10.0357 2908 WSearch - ok
13:37:10.0423 2908 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
13:37:10.0464 2908 wuauserv - ok
13:37:10.0513 2908 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
13:37:10.0513 2908 WudfPf - ok
13:37:10.0540 2908 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:37:10.0542 2908 WUDFRd - ok
13:37:10.0586 2908 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:37:10.0588 2908 wudfsvc - ok
13:37:10.0612 2908 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
13:37:10.0615 2908 WwanSvc - ok
13:37:10.0623 2908 ================ Scan global ===============================
13:37:10.0644 2908 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
13:37:10.0693 2908 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
13:37:10.0698 2908 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
13:37:10.0724 2908 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
13:37:10.0749 2908 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
13:37:10.0752 2908 [Global] - ok
13:37:10.0755 2908 ================ Scan MBR ==================================
13:37:10.0765 2908 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:37:11.0071 2908 \Device\Harddisk0\DR0 - ok
13:37:11.0071 2908 ================ Scan VBR ==================================
13:37:11.0073 2908 [ AF25421FB2D4DA95532F5668D6C62FE2 ] \Device\Harddisk0\DR0\Partition1
13:37:11.0074 2908 \Device\Harddisk0\DR0\Partition1 - ok
13:37:11.0110 2908 [ 9C793764C0080746B8C669D1917CEE7E ] \Device\Harddisk0\DR0\Partition2
13:37:11.0111 2908 \Device\Harddisk0\DR0\Partition2 - ok
13:37:11.0111 2908 ============================================================
13:37:11.0111 2908 Scan finished
13:37:11.0111 2908 ============================================================
13:37:11.0116 2900 Detected object count: 0
13:37:11.0116 2900 Actual detected object count: 0
13:37:31.0054 2576 Deinitialize success


ESET online Scanner

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=ab4e995ade338246932d4e8e510ca46e
# engine=14113
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-19 11:53:22
# local_time=2013-06-19 04:53:22 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=772 16777214 83 94 526871 147477874 0 0
# compatibility_mode=5893 16776573 100 94 0 123229452 0 0
# scanned=131134
# found=8
# cleaned=5
# scan_time=2584
sh=A9CBC88E9D722E875D317EF4ADB1318C83E9A9BA ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WebCakeBHO4.zip"
sh=89AAF5CED0599281F5AE40AFC190565B87529D56 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinDownloadergen9.zip"
sh=56503AE5B01E5D7D9B1F40D25A3622FAC4C2F657 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip"
sh=A9CBC88E9D722E875D317EF4ADB1318C83E9A9BA ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WebCakeBHO4.zip"
sh=89AAF5CED0599281F5AE40AFC190565B87529D56 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WinDownloadergen9.zip"
sh=56503AE5B01E5D7D9B1F40D25A3622FAC4C2F657 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\YontooPagerage2.zip"
sh=667B5AEBC1D7DDA9306FA3F96B82B9CBEAF158F0 ft=1 fh=2ef010c205350c9d vn="Win32/Adware.1ClickDownload.Y application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Ashley\Downloads\codec_pack_58553_ch.exe"
sh=D170A42F90107EC8C0788A68E9941601CFF16FC6 ft=1 fh=7b456f3f819a6c92 vn="Win32/Adware.1ClickDownload.AI application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Ashley\Downloads\The_Vampire_Diaries_S04E22_HDTV_x264-LOL_[eztv].exe"


Logs i don't have because some of them i didn't save:

MALWAREBYTES CHAMELEON
Malwarebytes Anti-Malware
HITMANPRO
EMSISOFT EMERGENCY KIT
Nortan Power Erasor
CureIT



Here is my DDS log so you can anylise this machine further.

DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 10.0.9200.16611
Run by [removed] at 17:42:54 on 2013-06-19
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8126.6744 [GMT -7:00]
.
AV: avast! Internet Security *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Internet Security *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\explorer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
mWinlogon: Userinit = userinit.exe,
BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: GetSavin 5.0: {913E5B85-561D-4532-B8CA-B08D28F2C80F} -
BHO: {C4401D0E-088C-4AD4-B14A-8D6B1181A5E4} -
BHO: SelectionLinks: {D9C8D61C-A7E4-4CA2-8427-CCAF098EB352} -
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [uTorrent] "C:\Users\Ashley\AppData\Roaming\uTorrent\uTorrent.exe"
uRunOnce: [SpybotDeletingB5561] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll"
uRunOnce: [SpybotDeletingD1548] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll"
uRunOnce: [SpybotDeletingB1995] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll"
uRunOnce: [SpybotDeletingD3513] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll"
uRunOnce: [SpybotDeletingB8330] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll"
uRunOnce: [SpybotDeletingD9520] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll"
uRunOnce: [SpybotDeletingB3943] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\msvcp100.dll"
uRunOnce: [SpybotDeletingD7287] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\msvcp100.dll"
uRunOnce: [SpybotDeletingB6869] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\msvcr100.dll"
uRunOnce: [SpybotDeletingD2720] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\msvcr100.dll"
uRunOnce: [SpybotDeletingB4736] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll"
uRunOnce: [SpybotDeletingD5223] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll"
uRunOnce: [SpybotDeletingB6395] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe"
uRunOnce: [SpybotDeletingD939] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe"
uRunOnce: [SpybotDeletingB8549] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\uninstall.exe"
uRunOnce: [SpybotDeletingD5153] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\uninstall.exe"
uRunOnce: [DeleteOnReboot] C:\Windows\DeleteOnReboot.bat
uRunOnce: [Report] C:\AdwCleaner[S1].txt
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
mRun: [USB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
mRun: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
mRun: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRunOnce: [SpybotDeletingA9695] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll"
mRunOnce: [SpybotDeletingC4026] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\ChromeModule.dll"
mRunOnce: [SpybotDeletingA2039] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll"
mRunOnce: [SpybotDeletingC4787] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\FirefoxModule.dll"
mRunOnce: [SpybotDeletingA5435] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll"
mRunOnce: [SpybotDeletingC232] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\InternetExplorerModule.dll"
mRunOnce: [SpybotDeletingA3451] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\msvcp100.dll"
mRunOnce: [SpybotDeletingC851] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\msvcp100.dll"
mRunOnce: [SpybotDeletingA4585] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\msvcr100.dll"
mRunOnce: [SpybotDeletingC4716] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\msvcr100.dll"
mRunOnce: [SpybotDeletingA9025] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll"
mRunOnce: [SpybotDeletingC9896] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\SPHook32.dll"
mRunOnce: [SpybotDeletingA3819] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe"
mRunOnce: [SpybotDeletingC7782] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\SPRunner.exe"
mRunOnce: [SpybotDeletingA100] command.com /c del "C:\Program Files (x86)\SearchProtect\bin\uninstall.exe"
mRunOnce: [SpybotDeletingC4163] cmd.exe /c del "C:\Program Files (x86)\SearchProtect\bin\uninstall.exe"
mRunOnce: [SpybotSnD] "C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.0.1 205.171.2.65
TCP: Interfaces\{03EA97B4-FE79-4431-946A-69738F82AE95} : DHCPNameServer = 192.168.0.1 [removed]
SSODL: WebCheck -
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-SSODL: WebCheck -
.
============= SERVICES / DRIVERS ===============
.
R0 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2013-4-19 22600]
R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\System32\drivers\aswNdis.sys [2013-4-19 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\System32\drivers\aswNdis2.sys [2013-4-19 270824]
R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2013-4-7 19264]
R1 aswFW;avast! TDI Firewall driver;C:\Windows\System32\drivers\aswFW.sys [2013-4-19 131232]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2013-6-14 45856]
R1 ndisrd;WinpkFilter LightWeight Filter;C:\Windows\System32\drivers\ndisrd.sys [2013-4-7 32400]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2013-5-23 143120]
R3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);C:\Windows\System32\drivers\ICCWDT.sys [2012-5-17 26136]
R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2013-4-7 357184]
R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2013-4-7 789824]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2013-4-7 726160]
S0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-4-19 65336]
S0 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-4-19 189936]
S1 A2DDA;A2 Direct Disk Access Support Driver;C:\Users\Ashley\Desktop\EmsisoftEmergencyKit\Run\a2ddax64.sys [2013-6-19 26176]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-4-19 1025808]
S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-4-19 378432]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-4-19 33400]
S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-4-19 80816]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-6-12 46808]
S2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-6-12 137960]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2013-6-19 32000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-4-7 20992]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-4-30 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-4-11 1255736]
S4 asComSvc;ASUS Com Service;C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [2012-6-1 920736]
S4 asHmComSvc;ASUS HM Com Service;C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [2012-6-1 951936]
S4 AsSysCtrlService;ASUS System Control Service;C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [2013-4-7 149120]
S4 AsusFanControlService;AsusFanControlService;C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [2013-4-7 324608]
S4 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [2013-4-7 160768]
S4 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-6-19 634632]
S4 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2013-4-7 166720]
S4 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2013-4-15 1153368]
S4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-1-18 383264]
S4 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2013-4-7 365376]
S4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe –> C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [?]
.
=============== Created Last 30 ================
.
2013-06-19 23:06:28 ——– d—–w- C:\Program Files (x86)\ESET
2013-06-19 22:59:23 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6529BE4F-3264-4969-851A-9EDFDABA821A}\offreg.dll
2013-06-19 22:53:57 ——– d—–w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-19 22:50:22 ——– d—–w- C:\Windows\ERUNT
2013-06-19 22:50:13 ——– d—–w- C:\JRT
2013-06-19 22:45:29 173 —-a-w- C:\Windows\DeleteOnReboot.bat
2013-06-19 21:19:53 32000 —-a-w- C:\Windows\System32\drivers\hitmanpro37.sys
2013-06-19 21:10:09 ——– d—–w- C:\Program Files\HitmanPro
2013-06-19 21:08:45 ——– d—–w- C:\ProgramData\HitmanPro
2013-06-19 19:04:13 ——– d—–w- C:\Users\Ashley\Doctor Web
2013-06-19 08:15:26 ——– d—–w- C:\Users\Ashley\AppData\Roaming\SUPERAntiSpyware.com
2013-06-19 08:15:20 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2013-06-19 08:15:20 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2013-06-19 07:14:45 ——– d—–w- C:\Users\Ashley\AppData\Local\NPE
2013-06-19 03:09:14 ——– d—–w- C:\Users\Ashley\AppData\Local\ElevatedDiagnostics
2013-06-19 02:59:56 ——– d—–w- C:\ProgramData\Kaspersky Lab
2013-06-19 00:27:07 ——– d—–w- C:\Users\Ashley\AppData\Local\CRE
2013-06-18 09:43:57 9552976 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6529BE4F-3264-4969-851A-9EDFDABA821A}\mpengine.dll
2013-06-14 22:26:47 ——– d—–w- C:\Windows\System32\appmgmt
2013-06-14 22:20:27 ——– d—–w- C:\Program Files\MPC-HC
2013-06-14 22:19:10 ——– d—–w- C:\Program Files (x86)\MyPC Backup
2013-06-14 22:17:50 33958 —-a-w- C:\ProgramData\uninstaller.exe
2013-06-14 22:17:42 ——– d—–w- C:\Users\Ashley\AppData\Local\AVG SafeGuard toolbar
2013-06-14 22:17:19 ——– d—–w- C:\ProgramData\AVG SafeGuard toolbar
2013-06-14 22:17:06 45856 —-a-w- C:\Windows\System32\drivers\avgtpx64.sys
2013-06-14 22:16:59 ——– d—–w- C:\Program Files (x86)\AVG SafeGuard toolbar
2013-06-12 21:27:23 1910632 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-12 21:23:29 751104 —-a-w- C:\Windows\System32\win32spl.dll
2013-06-12 21:23:29 492544 —-a-w- C:\Windows\SysWow64\win32spl.dll
2013-06-12 21:23:08 30720 —-a-w- C:\Windows\System32\cryptdlg.dll
2013-06-12 21:23:08 24576 —-a-w- C:\Windows\SysWow64\cryptdlg.dll
2013-06-05 15:03:35 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-26 02:59:04 ——– d—–w- C:\Users\Ashley\AppData\Roaming\DVDFab9
2013-05-26 02:58:50 ——– d—–w- C:\Program Files (x86)\DVDFab 9
2013-05-22 15:21:06 4325376 —-a-w- C:\ProgramData\ReadOnlyInstaller.msi
.
==================== Find3M ====================
.
2013-06-08 12:28:46 2706432 —-a-w- C:\Windows\System32\mshtml.tlb
2013-06-08 11:13:19 2706432 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-06-05 15:03:35 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-17 01:25:57 1767936 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-05-17 01:25:27 2877440 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-05-17 01:25:26 61440 —-a-w- C:\Windows\SysWow64\iesetup.dll
2013-05-17 01:25:26 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2013-05-17 00:59:03 2241024 —-a-w- C:\Windows\System32\wininet.dll
2013-05-17 00:58:10 3958784 —-a-w- C:\Windows\System32\jscript9.dll
2013-05-17 00:58:08 67072 —-a-w- C:\Windows\System32\iesetup.dll
2013-05-17 00:58:08 136704 —-a-w- C:\Windows\System32\iesysprep.dll
2013-05-14 12:23:25 89600 —-a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-05-14 08:40:13 71680 —-a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-05-13 05:51:01 184320 —-a-w- C:\Windows\System32\cryptsvc.dll
2013-05-13 05:51:00 1464320 —-a-w- C:\Windows\System32\crypt32.dll
2013-05-13 05:51:00 139776 —-a-w- C:\Windows\System32\cryptnet.dll
2013-05-13 05:50:40 52224 —-a-w- C:\Windows\System32\certenc.dll
2013-05-13 04:45:55 140288 —-a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-05-13 04:45:55 1160192 —-a-w- C:\Windows\SysWow64\crypt32.dll
2013-05-13 04:45:55 103936 —-a-w- C:\Windows\SysWow64\cryptnet.dll
2013-05-13 03:43:55 1192448 —-a-w- C:\Windows\System32\certutil.exe
2013-05-13 03:08:10 903168 —-a-w- C:\Windows\SysWow64\certutil.exe
2013-05-13 03:08:06 43008 —-a-w- C:\Windows\SysWow64\certenc.dll
2013-05-09 08:59:07 72016 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-05-09 08:59:07 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-05-09 08:59:07 189936 —-a-w- C:\Windows\System32\drivers\aswVmm.sys
2013-05-09 08:59:07 1025808 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-05-09 08:59:06 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-05-09 08:59:06 270824 —-a-w- C:\Windows\System32\drivers\aswNdis2.sys
2013-05-09 08:59:06 22600 —-a-w- C:\Windows\System32\drivers\aswKbd.sys
2013-05-09 08:59:06 131232 —-a-w- C:\Windows\System32\drivers\aswFW.sys
2013-05-09 08:58:37 41664 —-a-w- C:\Windows\avastSS.scr
2013-05-02 09:06:08 278800 ——w- C:\Windows\System32\MpSigStub.exe
2013-05-01 10:06:36 175616 —-a-w- C:\Windows\System32\msclmd.dll
2013-05-01 10:06:36 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll
2013-04-25 23:30:32 1505280 —-a-w- C:\Windows\SysWow64\d3d11.dll
2013-04-17 07:02:06 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-04-17 06:24:46 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll
2013-04-13 05:49:23 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 —-a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 —-a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 —-a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 —-a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 —-a-w- C:\Windows\System32\win32k.sys
2013-04-07 22:44:36 16896 —-a-w- C:\Windows\AsTaskSched.dll
2013-04-04 21:50:32 25928 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-04 12:36:01 866720 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-04-04 12:35:52 788896 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-03-31 22:52:16 1887232 —-a-w- C:\Windows\System32\d3d11.dll
2013-03-23 01:09:28 354656 —-a-w- C:\Windows\SysWow64\DivXControlPanelApplet.cpl
.
============= FINISH: 17:43:10.32 ===============


GMER LOG


GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-19 18:17:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-1 WDC_WD1600AAJS-08PSA0 rev.05.06H05 149.05GB
Running: gmer.exe; Driver: C:\Users\Ashley\AppData\Local\Temp\uxdiqpod.sys


—- Kernel code sections - GMER 2.1 —-

INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80001da4000 45 bytes [00, 00, 16, 02, 4E, 74, 66, …]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff80001da402f 29 bytes [00, 01, 00, 06, 00, 00, 00, …]

—- User code sections - GMER 2.1 —-

.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007726f991 7 bytes {MOV EDX, 0xc2ce28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007726fbd5 7 bytes {MOV EDX, 0xc2ce68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007726fc05 7 bytes {MOV EDX, 0xc2cda8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007726fc1d 7 bytes {MOV EDX, 0xc2cd28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007726fc35 7 bytes {MOV EDX, 0xc2cf28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007726fc65 7 bytes {MOV EDX, 0xc2cf68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007726fce5 7 bytes {MOV EDX, 0xc2cee8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007726fcfd 7 bytes {MOV EDX, 0xc2cea8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007726fd49 7 bytes {MOV EDX, 0xc2cc68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007726fe41 7 bytes {MOV EDX, 0xc2cca8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077270099 7 bytes {MOV EDX, 0xc2cc28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000772710a5 7 bytes {MOV EDX, 0xc2cde8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007727111d 7 bytes {MOV EDX, 0xc2cd68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077271321 7 bytes {MOV EDX, 0xc2cce8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007726f991 7 bytes {MOV EDX, 0xef2628; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007726fbd5 7 bytes {MOV EDX, 0xef2668; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007726fc05 7 bytes {MOV EDX, 0xef25a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007726fc1d 7 bytes {MOV EDX, 0xef2528; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007726fc35 7 bytes {MOV EDX, 0xef2728; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007726fc65 7 bytes {MOV EDX, 0xef2768; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007726fce5 7 bytes {MOV EDX, 0xef26e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007726fcfd 7 bytes {MOV EDX, 0xef26a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007726fd49 7 bytes {MOV EDX, 0xef2468; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007726fe41 7 bytes {MOV EDX, 0xef24a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077270099 7 bytes {MOV EDX, 0xef2428; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000772710a5 7 bytes {MOV EDX, 0xef25e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007727111d 7 bytes {MOV EDX, 0xef2568; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077271321 7 bytes {MOV EDX, 0xef24e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1252] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007726f991 7 bytes {MOV EDX, 0x20fa28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007726fbd5 7 bytes {MOV EDX, 0x20fa68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007726fc05 7 bytes {MOV EDX, 0x20f9a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007726fc1d 7 bytes {MOV EDX, 0x20f928; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007726fc35 7 bytes {MOV EDX, 0x20fb28; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007726fc65 7 bytes {MOV EDX, 0x20fb68; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007726fce5 7 bytes {MOV EDX, 0x20fae8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007726fcfd 7 bytes {MOV EDX, 0x20faa8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007726fd49 7 bytes {MOV EDX, 0x20f868; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007726fe41 7 bytes {MOV EDX, 0x20f8a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077270099 7 bytes {MOV EDX, 0x20f828; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000772710a5 7 bytes {MOV EDX, 0x20f9e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007727111d 7 bytes {MOV EDX, 0x20f968; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077271321 7 bytes {MOV EDX, 0x20f8e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007726f991 7 bytes {MOV EDX, 0xaa6228; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007726fbd5 7 bytes {MOV EDX, 0xaa6268; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007726fc05 7 bytes {MOV EDX, 0xaa61a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007726fc1d 7 bytes {MOV EDX, 0xaa6128; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007726fc35 7 bytes {MOV EDX, 0xaa6328; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007726fc65 7 bytes {MOV EDX, 0xaa6368; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007726fce5 7 bytes {MOV EDX, 0xaa62e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007726fcfd 7 bytes {MOV EDX, 0xaa62a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007726fd49 7 bytes {MOV EDX, 0xaa6068; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007726fe41 7 bytes {MOV EDX, 0xaa60a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077270099 7 bytes {MOV EDX, 0xaa6028; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000772710a5 7 bytes {MOV EDX, 0xaa61e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007727111d 7 bytes {MOV EDX, 0xaa6168; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077271321 7 bytes {MOV EDX, 0xaa60e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007726f991 7 bytes {MOV EDX, 0x8cd628; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007726fbd5 7 bytes {MOV EDX, 0x8cd668; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007726fc05 7 bytes {MOV EDX, 0x8cd5a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007726fc1d 7 bytes {MOV EDX, 0x8cd528; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007726fc35 7 bytes {MOV EDX, 0x8cd728; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007726fc65 7 bytes {MOV EDX, 0x8cd768; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007726fce5 7 bytes {MOV EDX, 0x8cd6e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007726fcfd 7 bytes {MOV EDX, 0x8cd6a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007726fd49 7 bytes {MOV EDX, 0x8cd468; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007726fe41 7 bytes {MOV EDX, 0x8cd4a8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077270099 7 bytes {MOV EDX, 0x8cd428; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000772710a5 7 bytes {MOV EDX, 0x8cd5e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007727111d 7 bytes {MOV EDX, 0x8cd568; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077271321 7 bytes {MOV EDX, 0x8cd4e8; JMP RDX}
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076891465 2 bytes [89, 76]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2404] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000768914bb 2 bytes [89, 76]
.text … * 2

—- EOF - GMER 2.1 —-



Thats it, that should be enough logs for you to really find the root of the issue that still remains for that nasty W32.bagel.gen.
Hi there,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.



Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-***.txt . Please attach that to your next reply.
I did the scan, but no maleware was found with that software, as i told you before i already ran that software before so it probably picked up what was last scene, but the very last scan i ran was ESET online scanner and that still manage to find the Win32.bagel.gen.
I am not sure what you are trying to ask. Are you asking what software i used, well i used both, anti maleware rootkit and malewarebytes. The software that you just told me to run was the "Anti-malware Rootkit" yes.
Combofix


Combofix should only be run when adviced by a team member!


Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.
ComboFix 13-06-20.01 - Ashley 06/20/2013 16:27:36.1.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8126.6303 [GMT -7:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47} SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\ReadOnlyInstaller.msi c:\programdata\uninstaller.exe c:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2013-05-20 to 2013-06-20 ))))))))))))))))))))))))))))))) . . 2013-06-19 23:06 . 2013-06-19 23:06 ——– d—–w- c:\program files (x86)\ESET 2013-06-19 22:53 . 2013-06-20 17:18 ——– d—–w- c:\programdata\Malwarebytes' Anti-Malware (portable) 2013-06-19 22:50 . 2013-06-19 22:50 ——– d—–w- c:\windows\ERUNT 2013-06-19 22:50 . 2013-06-19 22:50 ——– d—–w- C:\JRT 2013-06-19 22:45 . 2013-06-19 22:45 173 —-a-w- c:\windows\DeleteOnReboot.bat 2013-06-19 21:19 . 2013-06-19 21:19 32000 —-a-w- c:\windows\system32\drivers\hitmanpro37.sys 2013-06-19 21:10 . 2013-06-19 21:10 ——– d—–w- c:\program files\HitmanPro 2013-06-19 21:08 . 2013-06-19 21:18 ——– d—–w- c:\programdata\HitmanPro 2013-06-19 19:04 . 2013-06-19 19:53 ——– d—–w- c:\users\Ashley\Doctor Web 2013-06-19 08:15 . 2013-06-19 08:15 ——– d—–w- c:\users\Ashley\AppData\Roaming\SUPERAntiSpyware.com 2013-06-19 08:15 . 2013-06-19 08:15 ——– d—–w- c:\program files\SUPERAntiSpyware 2013-06-19 08:15 . 2013-06-19 08:15 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2013-06-19 07:14 . 2013-06-19 19:03 ——– d—–w- c:\users\Ashley\AppData\Local\NPE 2013-06-19 03:09 . 2013-06-19 03:09 ——– d—–w- c:\users\Ashley\AppData\Local\ElevatedDiagnostics 2013-06-19 02:59 . 2013-06-19 02:59 ——– d—–w- c:\programdata\Kaspersky Lab 2013-06-19 00:27 . 2013-06-19 00:27 ——– d—–w- c:\users\Ashley\AppData\Local\CRE 2013-06-18 09:43 . 2013-06-12 03:08 9552976 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6529BE4F-3264-4969-851A-9EDFDABA821A}\mpengine.dll 2013-06-18 04:42 . 2013-06-18 04:42 ——– d—–w- c:\users\Chuck\AppData\Local\AVG SafeGuard toolbar 2013-06-14 22:26 . 2013-06-14 22:26 ——– d—–w- c:\windows\system32\appmgmt 2013-06-14 22:21 . 2013-06-14 22:21 ——– d—–w- c:\users\Ashley\AppData\Roaming\Media Player Classic 2013-06-14 22:20 . 2013-06-14 22:20 ——– d—–w- c:\program files\MPC-HC 2013-06-14 22:19 . 2013-06-14 22:28 ——– d—–w- c:\program files (x86)\MyPC Backup 2013-06-14 22:17 . 2013-06-14 22:17 ——– d—–w- c:\users\Ashley\AppData\Local\AVG SafeGuard toolbar 2013-06-14 22:17 . 2013-06-14 22:17 ——– d—–w- c:\programdata\AVG SafeGuard toolbar 2013-06-14 22:17 . 2013-06-14 22:16 45856 —-a-w- c:\windows\system32\drivers\avgtpx64.sys 2013-06-14 22:16 . 2013-06-14 22:16 ——– d—–w- c:\program files (x86)\AVG SafeGuard toolbar 2013-06-12 21:27 . 2013-05-08 06:39 1910632 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-06-12 21:23 . 2013-04-26 05:51 751104 —-a-w- c:\windows\system32\win32spl.dll 2013-06-12 21:23 . 2013-04-26 04:55 492544 —-a-w- c:\windows\SysWow64\win32spl.dll 2013-06-12 21:23 . 2013-05-10 05:49 30720 —-a-w- c:\windows\system32\cryptdlg.dll 2013-06-12 21:23 . 2013-05-10 03:20 24576 —-a-w- c:\windows\SysWow64\cryptdlg.dll 2013-06-05 15:06 . 2013-06-05 15:06 97280 —-a-w- c:\windows\system32\mshtmled.dll 2013-06-05 15:03 . 2013-06-05 15:03 9728 —ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-26 02:59 . 2013-05-26 02:59 ——– d—–w- c:\users\Ashley\AppData\Roaming\DVDFab9 2013-05-26 02:58 . 2013-05-26 02:59 ——– d—–w- c:\program files (x86)\DVDFab 9 2013-05-23 03:16 . 2013-05-23 03:16 ——– d—–w- c:\users\Daniel-Kristi . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-13 00:23 . 2013-05-17 10:00 75825640 —-a-w- c:\windows\system32\MRT.exe 2013-05-09 08:59 . 2013-04-19 08:42 378432 —-a-w- c:\windows\system32\drivers\aswSP.sys 2013-05-09 08:59 . 2013-04-19 08:42 72016 —-a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-05-09 08:59 . 2013-04-19 08:42 64288 —-a-w- c:\windows\system32\drivers\aswTdi.sys 2013-05-09 08:59 . 2013-04-19 08:42 189936 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-05-09 08:59 . 2013-04-19 08:42 1025808 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-05-09 08:59 . 2013-04-19 08:42 65336 —-a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-05-09 08:59 . 2013-04-19 08:42 33400 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-05-09 08:59 . 2013-04-19 08:42 270824 —-a-w- c:\windows\system32\drivers\aswNdis2.sys 2013-05-09 08:59 . 2013-04-19 08:42 131232 —-a-w- c:\windows\system32\drivers\aswFW.sys 2013-05-09 08:59 . 2013-04-19 08:42 22600 —-a-w- c:\windows\system32\drivers\aswKbd.sys 2013-05-09 08:59 . 2013-04-19 08:42 80816 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-05-09 08:58 . 2013-04-19 08:40 41664 —-a-w- c:\windows\avastSS.scr 2013-05-09 08:58 . 2013-04-19 08:42 287840 —-a-w- c:\windows\system32\aswBoot.exe 2013-05-02 09:06 . 2013-04-07 22:27 278800 ——w- c:\windows\system32\MpSigStub.exe 2013-05-01 10:06 . 2009-07-14 02:36 175616 —-a-w- c:\windows\system32\msclmd.dll 2013-05-01 10:06 . 2009-07-14 02:36 152576 —-a-w- c:\windows\SysWow64\msclmd.dll 2013-04-29 10:33 . 2013-04-29 10:33 737072 —-a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll 2013-04-29 10:23 . 2013-04-29 10:23 2876528 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll 2013-04-29 10:23 . 2013-04-29 10:23 42776 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll 2013-04-29 10:23 . 2013-04-29 10:23 539984 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2013-04-13 05:49 . 2013-05-15 18:23 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-05-15 18:23 308736 —-a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-05-15 18:23 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-05-15 18:23 111104 —-a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-05-15 18:23 474624 —-a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-15 18:23 2176512 —-a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-04-23 21:07 1656680 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-15 18:24 265064 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-15 18:24 983400 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-15 18:24 3153920 —-a-w- c:\windows\system32\win32k.sys 2013-04-07 22:44 . 2013-04-07 22:44 16896 —-a-w- c:\windows\AsTaskSched.dll 2013-04-04 21:50 . 2013-04-16 05:19 25928 —-a-w- c:\windows\system32\drivers\mbam.sys 2013-04-04 12:36 . 2013-04-08 01:01 866720 —-a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-04-04 12:35 . 2013-04-08 01:01 788896 —-a-w- c:\windows\SysWow64\deployJava1.dll 2013-03-23 01:09 . 2013-03-23 01:09 354656 —-a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2013-05-15 5622512] "uTorrent"="c:\users\Ashley\AppData\Roaming\uTorrent\uTorrent.exe" [2013-05-17 394616] "GoogleChromeAutoLaunch_E21A55733DE47A9C91846541BA1A406D"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2013-05-29 825808] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IMSS"="c:\program files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe" [2012-07-19 133440] "USB3MON"="c:\program files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-20 291648] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2011-08-04 1637496] "IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2011-09-27 439440] "DivXMediaServer"="c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" [2013-04-15 450560] "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2013-02-13 1263952] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot] @="" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys;c:\windows\SYSNATIVE\drivers\hitmanpro37.sys [x] R3 ICCS;Intel® Integrated Clock Controller Service - Intel® ICCS;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [x] S0 aswKbd;aswKbd; [x] S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys;c:\windows\SYSNATIVE\DRIVERS\aswNdis.sys [x] S0 aswNdis2;avast! Firewall Core Firewall Service; [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 A2DDA;A2 Direct Disk Access Support Driver;c:\users\Ashley\Desktop\EmsisoftEmergencyKit\Run\a2ddax64.sys;c:\users\Ashley\Desktop\EmsisoftEmergencyKit\Run\a2ddax64.sys [x] S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x] S1 aswFW;avast! TDI Firewall driver; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x] S1 ndisrd;WinpkFilter LightWeight Filter;c:\windows\system32\DRIVERS\ndisrd.sys;c:\windows\SYSNATIVE\DRIVERS\ndisrd.sys [x] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [x] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [x] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [x] S2 asComSvc;ASUS Com Service;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe;c:\program files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [x] S2 asHmComSvc;ASUS HM Com Service;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe;c:\program files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [x] S2 AsusFanControlService;AsusFanControlService;c:\program files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe;c:\program files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe;c:\program files\AVAST Software\Avast\afwServ.exe [x] S2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x] S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [x] S3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x] S3 ICCWDT;Intel® Watchdog Timer Driver (Intel® WDT);c:\windows\system32\DRIVERS\ICCWDT.sys;c:\windows\SYSNATIVE\DRIVERS\ICCWDT.sys [x] S3 iusb3hub;Intel® USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 Point64;Microsoft Mouse and Keyboard Center Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - A2DDA *NewlyCreated* - SASDIFSV *NewlyCreated* - SASKUTIL . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-05 17:21 1165776 —-a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-11 01:11] . 2013-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-11 01:11] . 2013-06-19 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 0aa04f95-1c27-420b-a47c-f650cb3bcea9.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21] . 2013-06-19 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 3f0d5762-0827-4121-a22d-8ae50d6a7fa7.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2013-05-23 20:21] . . ——— X64 Entries ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 —-a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2012-06-12 6548112] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2011-07-19 2780776] . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.0.1 [removed] . - - - - ORPHANS REMOVED - - - - . BHO-{913E5B85-561D-4532-B8CA-B08D28F2C80F} - c:\users\Ashley\AppData\Local\getsavin\ie\getsavin_1365641401.dll BHO-{C4401D0E-088C-4AD4-B14A-8D6B1181A5E4} - (no file) BHO-{D9C8D61C-A7E4-4CA2-8427-CCAF098EB352} - c:\program files (x86)\OApps\SelectionLinks.dll Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-sl-cb - c:\program files (x86)\OApps\sl-cb_uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-06-20 16:33:07 ComboFix-quarantined-files.txt 2013-06-20 23:33 . Pre-Run: 4,234,588,160 bytes free Post-Run: 3,880,914,944 bytes free . - - End Of File - - 8A37B6226B3E15671505A40E3A627EE9 A36C5E4F47E84449FF07ED3517B43A31
Welll my ESET online scanner is not picking up anything any more for some reason so i guess all those software i ran must of cleaned pretty much everything out, but if their is any known traces, registry's what so ever, let me know and we can use OTL or combofix to fix the issues, also if their is any change to proxy settings which i think their is and other stuff like audio, video. Prior to running all these tests, it had lots of audio issues, video issues, and the internet kept rerouting even using wikipedia.
Sorry, netiher malware nor malicious modifications to see in here.
Let´s clean up here and submit you to the general pc helpf forum to get further assistance.


Scan with adwCleaner


Please download AdwCleaner to your desktop.


  • Run adwcleaner.exe.
  • Hit delete.
  • When the run is finished, it will open up a text file.
  • Please post its contents within your next reply.
  • You´ll find the log file at C:\AdwCleaner[S1].txt also.

SecurityCheck

Please download SecurityCheck: LINK1 LINK2

  • Save it to your desktop, start it and follow the instructions in the window.
  • After the scan finished the (checkup.txt) will open. Copy its content to your thread.
Results of screen317's Security Check version 0.99.67
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Internet Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 21
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Reader 10.1.7 Adobe Reader out of Date!
Google Chrome 27.0.1453.110
Google Chrome 27.0.1453.94
````````Process Check: objlist.exe by Laurent````````
AVAST Software Avast AvastSvc.exe
AVAST Software Avast afwServ.exe
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````



For the most part i think this machine might be clean, but you can't be to careful with win32.bagel.gen or a win32.downloader.gen as they can have root kits and repopulate them selfs on the pc, infecting it further, so i want to be sure this machine is clean. I have done everything i could do to the best of my abilitiy
Let´s see if we can find something a little bit deeper:


Download and run OTL

  • Download OTL by OldTimer and save it to your desktop.
  • Double click on the OTL.exe icon on your desktop. If you are using Vista, please right-click and select run as administrator
  • Click the "Scan All Users" checkbox.


    Note: If you are using a Windows 64bit machine, please make sure the checkbox next to Include 64Bit Scans is checked. It will be checked by default.

  • Push the [external image: Posted Image] button.
  • It will now begin to scan, please be paitent while it scans.
  • Two reports will open once it's done.
  • Please copy and paste them in your next reply:
  • OTL.txt <– Will be opened
  • Extras.txt <– Will be minimized

I wanted to mention that all of the video's i play on the pc are pix-elated and skipping for some reason and this was never the case before, is this because the tools we been running? I just tested it out and im actually not in safe mode any more.

My sister tends to use alot of software to download music, video's and such so thats why it didn't come to know surprise as to whys the pc got infected. But i after deeply looking into these logs, you think its clean? After all the work i did on it, i got rid of most of the infections i think, but their could be still some root kit entries floating around some where, i just want to be completely sure. I am honestly tired of cleaning this machine, i have to do it almost like nearly every other week, i can try comodo security as a firewall, maybe that might stop alot of the outgoing and ingoing infections, only problem with that software is its not very user friendly.





OTL logfile created on: 6/21/2013 9:46:52 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ashley\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.94 Gb Total Physical Memory | 5.98 Gb Available Physical Memory | 75.34% Memory free
15.87 Gb Paging File | 13.82 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 148.95 Gb Total Space | 2.34 Gb Free Space | 1.57% Space Free | Partition Type: NTFS

Computer Name: ASHLEY-PC | User Name: Ashley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/21 09:45:17 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Ashley\Downloads\OTL.exe
PRC - [2013/05/28 22:27:40 | 000,825,808 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/05/10 00:57:22 | 000,065,640 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/05/09 01:58:30 | 004,858,968 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 01:58:30 | 000,046,808 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/05/09 01:58:27 | 000,137,960 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2013/02/26 00:32:22 | 001,260,320 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/02/12 19:37:16 | 001,263,952 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2013/01/18 08:14:20 | 000,383,264 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/08/08 18:17:52 | 003,101,056 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetSvcHelp.exe
PRC - [2012/08/07 13:42:12 | 001,504,640 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
PRC - [2012/08/01 16:39:04 | 001,112,064 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe
PRC - [2012/07/23 16:34:28 | 001,190,400 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\PowerControlHelp.exe
PRC - [2012/07/18 19:00:54 | 000,365,376 | R— | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/07/18 19:00:52 | 000,277,824 | R— | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/07/18 19:00:28 | 000,166,720 | R— | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
PRC - [2012/06/01 02:42:18 | 000,951,936 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
PRC - [2012/06/01 02:42:18 | 000,920,736 | R— | M] () – C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
PRC - [2012/05/20 09:26:26 | 000,291,648 | R— | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
PRC - [2012/05/18 01:15:32 | 000,324,608 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe
PRC - [2012/05/03 12:17:36 | 001,256,576 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe
PRC - [2012/03/13 12:34:12 | 002,935,424 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
PRC - [2012/02/16 23:26:00 | 000,149,120 | R— | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
PRC - [2012/02/02 15:20:32 | 000,889,984 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\NetiCtrlTray.exe
PRC - [2011/09/27 11:44:20 | 000,439,440 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
PRC - [2011/09/08 21:29:12 | 001,112,704 | —- | M] (ASUSTeK Computer Inc.) – C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
PRC - [2011/08/04 14:44:24 | 000,593,032 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE
PRC - [2011/08/04 14:41:44 | 001,637,496 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE


========== Modules (No Company Name) ==========

MOD - [2013/05/28 22:27:38 | 000,393,168 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
MOD - [2013/05/28 22:27:35 | 004,051,408 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll
MOD - [2013/05/28 22:26:40 | 000,599,504 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\libglesv2.dll
MOD - [2013/05/28 22:26:39 | 000,124,368 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\libegl.dll
MOD - [2013/05/28 22:26:36 | 001,597,392 | —- | M] () – C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll
MOD - [2013/02/12 19:38:06 | 000,100,688 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2013/02/12 19:37:16 | 001,263,952 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2012/08/08 16:45:52 | 000,786,432 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\func.dll
MOD - [2012/07/31 15:21:32 | 000,152,064 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\gep.dll
MOD - [2012/07/25 09:56:42 | 001,124,864 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\Network iControl.dll
MOD - [2012/07/05 12:05:48 | 000,253,952 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\pngio.dll
MOD - [2012/06/19 12:56:22 | 001,305,600 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\MyLogo\MyLogo.dll
MOD - [2012/05/28 21:27:04 | 001,622,528 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll
MOD - [2012/05/25 10:33:10 | 000,883,712 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll
MOD - [2012/05/17 03:57:12 | 000,043,520 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\HookKey32.dll
MOD - [2012/03/21 12:07:44 | 000,972,288 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll
MOD - [2012/02/10 11:29:44 | 001,047,040 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Probe_II\ProbeII.dll
MOD - [2011/10/14 20:03:22 | 000,885,248 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll
MOD - [2011/09/19 20:18:20 | 001,243,136 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll
MOD - [2011/07/21 09:06:44 | 000,846,848 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll
MOD - [2011/07/12 19:14:52 | 000,147,456 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll
MOD - [2010/10/05 08:22:50 | 000,253,952 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll
MOD - [2010/10/05 08:22:50 | 000,253,952 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Network iControl\NetSvcHelp\pngio.dll
MOD - [2010/10/05 08:22:50 | 000,208,896 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll
MOD - [2010/08/22 19:17:40 | 000,662,016 | R— | M] () – C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMLib.dll
MOD - [2009/08/12 20:15:52 | 000,253,952 | —- | M] () – C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/05/23 13:12:02 | 000,143,120 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2013/05/09 01:58:30 | 000,046,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/05/09 01:58:27 | 000,137,960 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2012/06/19 19:10:34 | 000,634,632 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\iCLS Client\HeciServer.exe – (Intel®
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [2009/07/13 18:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV - [2013/05/10 00:57:22 | 000,065,640 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2013/02/26 00:32:22 | 001,260,320 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe – (nvUpdatusService)
SRV - [2013/01/18 08:14:20 | 000,383,264 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2012/07/18 19:00:54 | 000,365,376 | R— | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS)
SRV - [2012/07/18 19:00:52 | 000,277,824 | R— | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS)
SRV - [2012/07/18 19:00:28 | 000,166,720 | R— | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe – (jhi_service)
SRV - [2012/06/01 02:42:18 | 000,951,936 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe – (asHmComSvc)
SRV - [2012/06/01 02:42:18 | 000,920,736 | R— | M] () [Auto | Running] – C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe – (asComSvc)
SRV - [2012/05/18 01:15:32 | 000,324,608 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files (x86)\ASUS\AsusFanControlService\1.01.08\AsusFanControlService.exe – (AsusFanControlService)
SRV - [2012/02/16 23:26:00 | 000,149,120 | R— | M] (ASUSTeK Computer Inc.) [Auto | Running] – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe – (AsSysCtrlService)
SRV - [2011/05/27 11:07:36 | 000,160,768 | —- | M] (Intel Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe – (ICCS)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/19 14:19:53 | 000,032,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hitmanpro37.sys – (hitmanpro37)
DRV:64bit: - [2013/06/14 15:16:45 | 000,045,856 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avgtpx64.sys – (avgtp)
DRV:64bit: - [2013/05/09 01:59:07 | 001,025,808 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/05/09 01:59:07 | 000,378,432 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/05/09 01:59:07 | 000,189,936 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/05/09 01:59:07 | 000,072,016 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/05/09 01:59:07 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/05/09 01:59:07 | 000,064,288 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/05/09 01:59:06 | 000,270,824 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2013/05/09 01:59:06 | 000,131,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2013/05/09 01:59:06 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/05/09 01:59:06 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/05/09 01:59:06 | 000,022,600 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2013/03/06 15:11:21 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2013/01/29 18:15:04 | 000,050,800 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\point64.sys – (Point64)
DRV:64bit: - [2012/07/02 00:16:02 | 000,062,784 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:64bit: - [2012/06/12 07:00:48 | 000,726,160 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2012/05/30 20:06:14 | 000,032,400 | R— | M] (NT Kernel Resources) [Kernel | System | Running] – C:\Windows\SysNative\drivers\ndisrd.sys – (ndisrd)
DRV:64bit: - [2012/05/20 09:25:32 | 000,789,824 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\iusb3xhc.sys – (iusb3xhc)
DRV:64bit: - [2012/05/20 09:25:32 | 000,357,184 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\iusb3hub.sys – (iusb3hub)
DRV:64bit: - [2012/05/20 09:25:32 | 000,019,264 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iusb3hcs.sys – (iusb3hcs)
DRV:64bit: - [2012/05/17 03:57:06 | 000,026,136 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ICCWDT.sys – (ICCWDT)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/22 09:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 14:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/03/10 23:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 23:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 06:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 04:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 04:03:42 | 000,020,992 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV - [2013/06/19 22:35:50 | 000,026,176 | —- | M] (Emsisoft GmbH) [File_System | System | Running] – C:\Users\Ashley\Desktop\EmsisoftEmergencyKit\Run\a2ddax64.sys – (A2DDA)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2238972994-1161546085-716596809-1001\..\SearchScopes,DefaultScope =


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Plus Web Player Plug-In,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013/05/19 10:40:45 | 000,000,000 | —D | M]

[2013/04/18 23:58:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
[2013/04/18 23:58:27 | 000,000,000 | —D | M] (No name found) – C:\Users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\searchplugins
[2013/04/08 10:11:52 | 000,216,492 | —- | M] () (No name found) – C:\Users\Ashley\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\[removed]
[2013/04/10 18:03:51 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla FireFox\extensions

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…289663&UM=2
CHR - default_search_provider: suggest_url = http://suggest.search.conduit.com/CSuggest…048732&UM=2
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\PepperFlash\11.7.700.225\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility for IJ (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Java Deployment Toolkit 7.0.210.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.172_0\

O1 HOSTS File: ([2013/06/20 16:31:39 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (GetSavin 5.0) - {913E5B85-561D-4532-B8CA-B08D28F2C80F} - C:\Users\Ashley\AppData\Local\getsavin\ie\getsavin_1365641401.dll File not found
O2 - BHO: (no name) - {C4401D0E-088C-4AD4-B14A-8D6B1181A5E4} - No CLSID value found.
O2 - BHO: (SelectionLinks) - {D9C8D61C-A7E4-4CA2-8427-CCAF098EB352} - C:\Program Files (x86)\OApps\SelectionLinks.dll File not found
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [USB3MON] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Intel Corporation)
O4 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000..\Run: [GoogleChromeAutoLaunch_E21A55733DE47A9C91846541BA1A406D] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000..\Run: [uTorrent] C:\Users\Ashley\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKU\S-1-5-21-2238972994-1161546085-716596809-1001..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2238972994-1161546085-716596809-1001..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2238972994-1161546085-716596809-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2238972994-1161546085-716596809-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{03EA97B4-FE79-4431-946A-69738F82AE95}: DhcpNameServer = 192.168.0.1 [removed]
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/20 23:06:26 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/06/20 16:33:08 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/06/20 16:26:33 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/06/20 16:26:33 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/06/20 16:26:33 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/06/20 15:20:27 | 000,000,000 | —D | C] – C:\Qoobox
[2013/06/20 15:20:11 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/06/19 16:06:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/06/19 16:06:24 | 002,347,384 | —- | C] (ESET) – C:\Users\Ashley\Desktop\esetsmartinstaller_enu.exe
[2013/06/19 15:53:57 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/06/19 15:52:55 | 000,000,000 | —D | C] – C:\Users\Ashley\Desktop\mbar-1.06.0.1003
[2013/06/19 15:50:22 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/06/19 15:50:13 | 000,000,000 | —D | C] – C:\JRT
[2013/06/19 14:49:12 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Ashley\Desktop\JRT.exe
[2013/06/19 14:37:19 | 000,000,000 | —D | C] – C:\Users\Ashley\Desktop\EmsisoftEmergencyKit
[2013/06/19 14:10:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2013/06/19 14:10:09 | 000,000,000 | —D | C] – C:\Program Files\HitmanPro
[2013/06/19 14:08:45 | 000,000,000 | —D | C] – C:\ProgramData\HitmanPro
[2013/06/19 14:01:52 | 000,000,000 | —D | C] – C:\Users\Ashley\Desktop\RK_Quarantine
[2013/06/19 13:52:03 | 000,000,000 | —D | C] – C:\Users\Ashley\Desktop\mbam-chameleon-1.62.1.1000
[2013/06/19 12:04:13 | 000,000,000 | —D | C] – C:\Users\Ashley\Doctor Web
[2013/06/19 01:15:26 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Roaming\SUPERAntiSpyware.com
[2013/06/19 01:15:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/06/19 01:15:20 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/06/19 01:15:20 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/06/19 00:14:45 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Local\NPE
[2013/06/18 20:09:14 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Local\ElevatedDiagnostics
[2013/06/18 19:59:56 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2013/06/18 19:12:06 | 000,000,000 | —D | C] – C:\Users\Ashley\Documents\Virus Clean up Tools
[2013/06/18 17:58:26 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/18 17:58:25 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/18 17:27:07 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Local\CRE
[2013/06/14 15:26:47 | 000,000,000 | —D | C] – C:\Windows\SysNative\appmgmt
[2013/06/14 15:21:06 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Roaming\Media Player Classic
[2013/06/14 15:20:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
[2013/06/14 15:20:27 | 000,000,000 | —D | C] – C:\Program Files\MPC-HC
[2013/06/14 15:19:10 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyPC Backup
[2013/06/14 15:17:42 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Local\AVG SafeGuard toolbar
[2013/06/14 15:17:19 | 000,000,000 | —D | C] – C:\ProgramData\AVG SafeGuard toolbar
[2013/06/14 15:17:06 | 000,045,856 | —- | C] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/14 15:16:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG SafeGuard toolbar
[2013/06/12 17:22:51 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/12 17:22:51 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/12 17:22:51 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/12 17:22:51 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/12 17:22:51 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/12 17:22:51 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/12 17:22:51 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/12 17:22:51 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/12 17:22:51 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/12 17:22:49 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/12 17:22:49 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/12 17:22:49 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/12 17:22:48 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/12 14:23:29 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/12 14:23:29 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/12 14:23:08 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/12 14:23:08 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/12 14:22:54 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/12 14:22:49 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/12 14:22:49 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/12 14:22:49 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/12 14:22:49 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/12 14:22:49 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/12 14:22:49 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/12 14:22:44 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/12 14:22:44 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/06/05 08:06:04 | 001,509,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/05 08:06:04 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/05 08:06:04 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/05 08:06:04 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/05 08:06:04 | 001,054,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/05 08:06:04 | 000,905,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/05 08:06:04 | 000,762,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/05 08:06:04 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/05 08:06:04 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/05 08:06:04 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/05 08:06:04 | 000,452,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/05 08:06:04 | 000,441,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/05 08:06:04 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/05 08:06:04 | 000,281,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/05 08:06:04 | 000,235,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/05 08:06:04 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/05 08:06:04 | 000,226,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/05 08:06:04 | 000,216,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/05 08:06:04 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/05 08:06:04 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/05 08:06:04 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/05 08:06:04 | 000,167,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/05 08:06:04 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/05 08:06:04 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/05 08:06:04 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/05 08:06:04 | 000,144,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/05 08:06:04 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/05 08:06:04 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/05 08:06:04 | 000,136,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/05 08:06:04 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/05 08:06:04 | 000,125,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/05 08:06:04 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/05 08:06:04 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/05 08:06:04 | 000,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/05 08:06:04 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/05 08:06:04 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/05 08:06:04 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/05 08:06:04 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/05 08:06:04 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/05 08:06:04 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/05 08:06:04 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/05 08:06:04 | 000,069,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/05 08:06:04 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/05 08:06:04 | 000,061,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/05 08:06:04 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/05 08:06:04 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/05 08:06:04 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/05 08:06:04 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/05 08:06:04 | 000,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/05 08:06:04 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/05 08:06:04 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/05 08:06:04 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/05 08:06:04 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/05 08:03:35 | 003,928,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/06/05 08:03:35 | 002,776,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/06/05 08:03:35 | 002,565,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/06/05 08:03:35 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/06/05 08:03:35 | 001,682,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/06/05 08:03:35 | 001,643,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/06/05 08:03:35 | 001,238,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/06/05 08:03:35 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/06/05 08:03:35 | 000,648,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/06/05 08:03:35 | 000,522,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/06/05 08:03:35 | 000,465,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/06/05 08:03:35 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/06/05 08:03:35 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/06/05 08:03:35 | 000,363,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/06/05 08:03:35 | 000,333,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/06/05 08:03:35 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/06/05 08:03:35 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/06/05 08:03:35 | 000,221,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/06/05 08:03:35 | 000,194,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/06/05 08:03:35 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/06/05 08:03:35 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/05 08:03:35 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/05 08:03:35 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/05 08:03:35 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/05/25 20:10:17 | 000,000,000 | —D | C] – C:\Users\Ashley\Documents\DVDFab 9.0.2.8 Final (cracked exe ChVL) [ChingLiu]
[2013/05/25 19:59:04 | 000,000,000 | —D | C] – C:\Users\Ashley\Documents\DVDFab9
[2013/05/25 19:59:04 | 000,000,000 | —D | C] – C:\Users\Ashley\AppData\Roaming\DVDFab9
[2013/05/25 19:59:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9
[2013/05/25 19:58:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDFab 9
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/21 09:21:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/21 03:21:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/20 23:16:05 | 000,726,316 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/20 23:16:05 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/06/20 23:16:05 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/06/20 23:14:16 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 23:14:16 | 000,017,168 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 23:05:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/20 23:05:21 | 2095,321,087 | -HS- | M] () – C:\hiberfil.sys
[2013/06/20 16:31:39 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/06/20 15:21:22 | 000,002,075 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2013/06/19 17:42:16 | 000,001,087 | —- | M] () – C:\Users\Ashley\Desktop\Continue Zip Opener Installation.lnk
[2013/06/19 16:05:39 | 002,347,384 | —- | M] (ESET) – C:\Users\Ashley\Desktop\esetsmartinstaller_enu.exe
[2013/06/19 15:45:40 | 000,000,173 | —- | M] () – C:\Windows\DeleteOnReboot.bat
[2013/06/19 14:48:54 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Ashley\Desktop\JRT.exe
[2013/06/19 14:46:56 | 000,648,201 | —- | M] () – C:\Users\Ashley\Desktop\adwcleaner.exe
[2013/06/19 14:45:13 | 013,169,742 | —- | M] () – C:\Users\Ashley\Desktop\mbar-1.06.0.1003.zip
[2013/06/19 14:36:50 | 187,341,895 | —- | M] () – C:\Users\Ashley\Desktop\EmsisoftEmergencyKit.zip
[2013/06/19 14:19:53 | 000,032,000 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro37.sys
[2013/06/19 14:17:23 | 000,003,110 | —- | M] () – C:\Windows\SysNative\.crusader
[2013/06/19 14:10:10 | 000,001,893 | —- | M] () – C:\Users\Public\Desktop\HitmanPro.lnk
[2013/06/19 13:51:38 | 001,440,846 | —- | M] () – C:\Users\Ashley\Desktop\mbam-chameleon-1.62.1.1000.zip
[2013/06/19 13:26:57 | 000,000,512 | —- | M] () – C:\Users\Ashley\Desktop\MBR.dat
[2013/06/19 01:15:33 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 3f0d5762-0827-4121-a22d-8ae50d6a7fa7.job
[2013/06/19 01:15:33 | 000,000,512 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0aa04f95-1c27-420b-a47c-f650cb3bcea9.job
[2013/06/19 01:15:23 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/06/14 15:20:30 | 000,001,712 | —- | M] () – C:\Users\Public\Desktop\MPC-HC x64.lnk
[2013/06/14 15:16:45 | 000,045,856 | —- | M] (AVG Technologies) – C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/06/13 23:40:38 | 1475,360,768 | —- | M] () – C:\Users\Ashley\Documents\Aftershock.2012.WEBDLRiP.avi
[2013/06/12 14:13:46 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/06/08 07:06:58 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/08 04:40:02 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/05 10:22:05 | 000,002,183 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/06/05 08:06:04 | 001,509,376 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/06/05 08:06:04 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/06/05 08:06:04 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2013/06/05 08:06:04 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2013/06/05 08:06:04 | 001,054,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\MsSpellCheckingFacility.exe
[2013/06/05 08:06:04 | 000,905,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmlmedia.dll
[2013/06/05 08:06:04 | 000,762,368 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2013/06/05 08:06:04 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmlmedia.dll
[2013/06/05 08:06:04 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2013/06/05 08:06:04 | 000,599,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/06/05 08:06:04 | 000,452,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2013/06/05 08:06:04 | 000,441,856 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2013/06/05 08:06:04 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2013/06/05 08:06:04 | 000,281,600 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2013/06/05 08:06:04 | 000,235,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/06/05 08:06:04 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/06/05 08:06:04 | 000,226,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\elshyph.dll
[2013/06/05 08:06:04 | 000,216,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2013/06/05 08:06:04 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2013/06/05 08:06:04 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\elshyph.dll
[2013/06/05 08:06:04 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/06/05 08:06:04 | 000,167,424 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2013/06/05 08:06:04 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2013/06/05 08:06:04 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2013/06/05 08:06:04 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2013/06/05 08:06:04 | 000,144,896 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2013/06/05 08:06:04 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2013/06/05 08:06:04 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/06/05 08:06:04 | 000,136,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2013/06/05 08:06:04 | 000,135,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2013/06/05 08:06:04 | 000,125,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2013/06/05 08:06:04 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2013/06/05 08:06:04 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2013/06/05 08:06:04 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2013/06/05 08:06:04 | 000,097,280 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/06/05 08:06:04 | 000,092,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2013/06/05 08:06:04 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2013/06/05 08:06:04 | 000,081,408 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2013/06/05 08:06:04 | 000,079,872 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/06/05 08:06:04 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2013/06/05 08:06:04 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2013/06/05 08:06:04 | 000,069,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2013/06/05 08:06:04 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2013/06/05 08:06:04 | 000,061,952 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2013/06/05 08:06:04 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2013/06/05 08:06:04 | 000,051,200 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2013/06/05 08:06:04 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2013/06/05 08:06:04 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2013/06/05 08:06:04 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2013/06/05 08:06:04 | 000,025,185 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/05 08:06:04 | 000,025,185 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2013/06/05 08:06:04 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2013/06/05 08:06:04 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2013/06/05 08:06:04 | 000,012,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2013/06/05 08:06:04 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2013/06/05 08:03:35 | 003,928,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2013/06/05 08:03:35 | 002,776,576 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msmpeg2vdec.dll
[2013/06/05 08:03:35 | 002,565,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2013/06/05 08:03:35 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msmpeg2vdec.dll
[2013/06/05 08:03:35 | 001,682,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2013/06/05 08:03:35 | 001,643,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/06/05 08:03:35 | 001,238,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2013/06/05 08:03:35 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2013/06/05 08:03:35 | 000,648,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2013/06/05 08:03:35 | 000,522,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/06/05 08:03:35 | 000,465,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2013/06/05 08:03:35 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2013/06/05 08:03:35 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/06/05 08:03:35 | 000,363,008 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2013/06/05 08:03:35 | 000,333,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2013/06/05 08:03:35 | 000,296,960 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2013/06/05 08:03:35 | 000,245,248 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2013/06/05 08:03:35 | 000,221,184 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2013/06/05 08:03:35 | 000,194,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2013/06/05 08:03:35 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2013/06/05 08:03:35 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/05 08:03:35 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/05 08:03:35 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-version-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/06/05 08:03:35 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/06/05 08:03:35 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/05/25 19:59:01 | 000,001,019 | —- | M] () – C:\Users\Ashley\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 9.lnk
[2013/05/25 19:59:01 | 000,000,995 | —- | M] () – C:\Users\Ashley\Desktop\DVDFab 9.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/20 16:26:33 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/06/20 16:26:33 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/06/20 16:26:33 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/06/20 16:26:33 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/06/20 16:26:33 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/06/20 04:31:34 | 000,004,161 | —- | C] () – C:\Full Metal Panic! The Second Raid.lnk
[2013/06/20 04:31:12 | 000,005,128 | —- | C] () – C:\Full Metal Panic.lnk
[2013/06/19 17:42:16 | 000,001,087 | —- | C] () – C:\Users\Ashley\Desktop\Continue Zip Opener Installation.lnk
[2013/06/19 15:45:29 | 000,000,173 | —- | C] () – C:\Windows\DeleteOnReboot.bat
[2013/06/19 14:48:22 | 000,648,201 | —- | C] () – C:\Users\Ashley\Desktop\adwcleaner.exe
[2013/06/19 14:46:43 | 013,169,742 | —- | C] () – C:\Users\Ashley\Desktop\mbar-1.06.0.1003.zip
[2013/06/19 14:37:15 | 187,341,895 | —- | C] () – C:\Users\Ashley\Desktop\EmsisoftEmergencyKit.zip
[2013/06/19 14:19:53 | 000,032,000 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro37.sys
[2013/06/19 14:17:23 | 000,003,110 | —- | C] () – C:\Windows\SysNative\.crusader
[2013/06/19 14:10:10 | 000,001,893 | —- | C] () – C:\Users\Public\Desktop\HitmanPro.lnk
[2013/06/19 13:51:59 | 001,440,846 | —- | C] () – C:\Users\Ashley\Desktop\mbam-chameleon-1.62.1.1000.zip
[2013/06/19 13:26:57 | 000,000,512 | —- | C] () – C:\Users\Ashley\Desktop\MBR.dat
[2013/06/19 01:15:33 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 3f0d5762-0827-4121-a22d-8ae50d6a7fa7.job
[2013/06/19 01:15:33 | 000,000,512 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0aa04f95-1c27-420b-a47c-f650cb3bcea9.job
[2013/06/19 01:15:23 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/06/14 15:20:30 | 000,001,712 | —- | C] () – C:\Users\Public\Desktop\MPC-HC x64.lnk
[2013/06/13 19:14:56 | 1475,360,768 | —- | C] () – C:\Users\Ashley\Documents\Aftershock.2012.WEBDLRiP.avi
[2013/06/05 08:06:04 | 000,025,185 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2013/06/05 08:06:04 | 000,025,185 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2013/05/25 19:59:01 | 000,001,019 | —- | C] () – C:\Users\Ashley\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab 9.lnk
[2013/05/25 19:59:01 | 000,000,995 | —- | C] () – C:\Users\Ashley\Desktop\DVDFab 9.lnk
[2013/04/15 22:07:32 | 000,079,360 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2013/04/07 15:57:20 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2013/04/07 15:57:15 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2013/04/07 15:02:00 | 000,056,769 | —- | C] () – C:\Windows\Ascd_log.ini
[2013/04/07 14:59:11 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2013/04/07 14:59:07 | 000,000,628 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2012/06/19 18:52:42 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/26 22:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 21:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >





OTL Extras logfile created on: 6/21/2013 9:46:52 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ashley\Downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.94 Gb Total Physical Memory | 5.98 Gb Available Physical Memory | 75.34% Memory free
15.87 Gb Paging File | 13.82 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 148.95 Gb Total Space | 2.34 Gb Free Space | 1.57% Space Free | Partition Type: NTFS

Computer Name: ASHLEY-PC | User Name: Ashley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2238972994-1161546085-716596809-1000\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1E60873E-4609-4E9E-BBA6-6052A2518996}" = protocol=17 | dir=in | app=c:\users\ashley\appdata\roaming\utorrent\utorrent.exe |
"{7739199D-A3A7-4DF3-9735-3E206E8052DC}" = protocol=6 | dir=in | app=c:\users\ashley\appdata\roaming\utorrent\utorrent.exe |
"{A6F00266-C518-44D0-AB6C-74C56EB7AE8D}" = protocol=6 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |
"{D2F4A876-8ACB-41D4-8AAD-35D2AA1927C7}" = protocol=17 | dir=in | app=c:\program files (x86)\asus\ai suite ii\ai suite ii.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX510_series" = Canon MX510 series MP Drivers
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{24F93B56-61F5-415F-85B9-AA444DA34AFC}" = Microsoft Mouse and Keyboard Center
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = MPC-HC 1.6.7.7114 (9eb64ec) (64-bit)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{977D1ABF-4089-4CA7-BA33-CC75808B7ACE}" = Intel® Trusted Connect Service Client
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"HitmanPro37" = HitmanPro 3.7
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Mouse and Keyboard Center" = Microsoft Mouse and Keyboard Center
"WinRAR archiver" = WinRAR 4.20 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{240C3DDD-C5E9-4029-9DF7-95650D040CF2}" = Intel® USB 3.0 eXtensible Host Controller Driver
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{34D3688E-A737-44C5-9E2A-FF73618728E1}" = AI Suite II
"{3FD0C489-0F02-481a-A3E1-9754CD396761}" = Intel® Watchdog Timer Driver (Intel® WDT)
"{49BE9B8A-E858-4533-A74A-64306C13DB59}" = ASUS Product Register Program
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.7) MUI
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C1CC26DF-148A-4F68-BE42-EE5214686A71}" = LucidWizard
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"avast" = avast! Internet Security
"AVG SafeGuard toolbar" = AVG SafeGuard toolbar
"Canon MX510 series On-screen Manual" = Canon MX510 series On-screen Manual
"Canon_IJ_Network_Scanner_Selector_EX" = Canon IJ Network Scanner Selector EX
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"DivX Setup" = DivX Setup
"DVDFab 8_is1" = DVDFab 8.0.7.3 (29/01/2011)
"DVDFab 9_is1" = DVDFab 9.0.4.0 (15/05/2013)
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"ESET Online Scanner" = ESET Online Scanner v3
"ffdshow_is1" = ffdshow v1.2.4422 [2012-04-09]
"FormatFactory" = FormatFactory 3.0.1
"Google Chrome" = Google Chrome
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"MP Navigator EX 5.1" = Canon MP Navigator EX 5.1
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"sl-cb" = SelectionLinks
"Speed Dial Utility" = Canon Speed Dial Utility
"SpeedFan" = SpeedFan (remove only)
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/20/2013 7:25:19 PM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Canon\Solution
Menu EX\MFC80U.DLL". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/20/2013 7:25:48 PM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Ashley\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 6/20/2013 7:50:56 PM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 6/20/2013 7:51:09 PM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 6/21/2013 2:06:41 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Canon\Solution
Menu EX\MFC80U.DLL". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/21/2013 2:06:43 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Canon\Solution
Menu EX\MFC80U.DLL". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/21/2013 2:07:08 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Canon\Solution
Menu EX\MFC80U.DLL". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/21/2013 2:07:08 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files (x86)\Canon\Solution
Menu EX\MFC80U.DLL". Dependent Assembly Microsoft.VC80.MFCLOC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"
could not be found. Please use sxstrace.exe for detailed diagnosis.

Error - 6/21/2013 3:30:19 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "c:\program files (x86)\ESET\eset
online scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 6/21/2013 3:30:35 AM | Computer Name = Ashley-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 6/20/2013 6:26:49 PM | Computer Name = Ashley-PC | Source = DCOM | ID = 10005
Description =

Error - 6/20/2013 6:27:02 PM | Computer Name = Ashley-PC | Source = DCOM | ID = 10005
Description =

Error - 6/20/2013 6:27:16 PM | Computer Name = Ashley-PC | Source = DCOM | ID = 10005
Description =

Error - 6/20/2013 6:27:16 PM | Computer Name = Ashley-PC | Source = DCOM | ID = 10005
Description =

Error - 6/20/2013 6:33:17 PM | Computer Name = Ashley-PC | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the eventlog service.

Error - 6/20/2013 7:30:03 PM | Computer Name = Ashley-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 6/20/2013 7:31:18 PM | Computer Name = Ashley-PC | Source = Application Popup | ID = 1060
Description = \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility
with this system. Please contact your software vendor for a compatible version
of the driver.

Error - 6/20/2013 7:31:41 PM | Computer Name = Ashley-PC | Source = Service Control Manager | ID = 7030
Description = The PEVSystemStart service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 6/21/2013 2:06:49 AM | Computer Name = Ashley-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the SBSD
Security Center Service service to connect.

Error - 6/21/2013 2:06:49 AM | Computer Name = Ashley-PC | Source = Service Control Manager | ID = 7000
Description = The SBSD Security Center Service service failed to start due to the
following error: %%1053


< End of report >
Yes I´m still here but due to timezone differences we aren´t online at the same time always. I cannot see malware within the logs - but the one and only way to be 100% sure ist to format the hard disk and reinstall windows from scratch. If your sister is crapping the computer, why not restrict her user account? Don´t allow her installing any software, block peer to pper software´s ports, etc. I´m currently reviewing the OTL log, that may take some time. Think about reinstalling and reply what you want to do meanwhile.
I am kind of surprised you didn't mention anything bout updating adobe flash player or java or did you just assume that i was going to do that. The best i can do i use avast security and block any sites that she visits after she visits them unless you have a better option to staying further protected from maleware I am pretty sure she got some of her infections from movieurls.com which is a site she visits very often. WoT picked it up as being in the red zone.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI