This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't update or load web pages,freezing,shutting down,black screen

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Desription:
Windows Update would not update(error code 8024AFFF), Microsoft Security Essentials would not update today, When I tried to load Mozilla Firefox today an error message box says "couldnt load XPCOM, computer suddenly freezing, shutting down, black screen on reboot, noticed that websites were redirecting, google search page started to redirect to another google search page and text wouldnt show up when typing, all 3 browsers are SO slow (over a minute for a page to load or never), Windows Update icon recently started appearing on toolbar at botton of page, receiving email from contacts with website link leading to a bogus website, many new programs showing up in Programs folder.

Hi-
I have already done the following things:
- I ran the OTL scan and noticed 'scan all users" wasn't checked, so I checked it and ran it again. Then extras.txt file was not created.
- I did a system restore about a week ago (back as far as it would go) to see if that would fix the problems (it did not)
- I ran Spybot and it found 49 items. I closed it because I had no idea what to do, so Im not sure if it quarantined all those items.
- I am running in Safe mode w/ Networking because I cant get any browsers to load a page
-I did scans with system files and folders hidden (not sure if they should show or not)


Are the following programs and files safe (they appear in Hijackthis log):
-FacebookVideoCallSetup_v1.2.205.0 (kids recently downloaded)
-Facebook Updater (always in running processes)
-What are all the "Unknown files in Winsock" (I think all these are new)
-Skype/Skype toolbar (suddenly there are soo many Skype files)
-Google update Service and Google Software Updater (I heard one was legit and one was not)
-what is Google Photos Screensa&ver

My laptop has become useless at this point. The other users mainly play games (Minecraft, Roblox, Terraria and Technic) and that could be how this has happened. Although the fake emails did start installing a program before the pages could be shut down. Thank you in advance for your help. I dont know what i would do without you guys.

OTL Log:
OTL logfile created on: 8/4/2013 1:54:43 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\gogo\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.93 Gb Total Physical Memory | 1.74 Gb Available Physical Memory | 59.48% Memory free
6.08 Gb Paging File | 4.89 Gb Available in Paging File | 80.31% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.17 Gb Total Space | 152.71 Gb Free Space | 53.18% Space Free | Partition Type: NTFS
Drive D: | 10.92 Gb Total Space | 1.81 Gb Free Space | 16.58% Space Free | Partition Type: NTFS

Computer Name: GOGO | User Name: gogo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\gogo\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SMINST\BLService.exe ()
PRC - C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (McAfee SiteAdvisor Service) – c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (BBUpdate) – C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE (Microsoft Corporation.)
SRV - (BBSvc) – C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE (Microsoft Corporation.)
SRV - (EpsonCustomerParticipation) – C:\Program Files\epson\EpsonCustomerParticipation\EPCP.exe (SEIKO EPSON CORPORATION)
SRV - (Recovery Service for Windows) – C:\Program Files\SMINST\BLService.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WcesComm) – C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) – C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
SRV - (EpsonBidirectionalService) – C:\Program Files\Common Files\EPSON\EBAPI\eEBSvc.exe (SEIKO EPSON CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (MBAMSwissArmy) – C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) – C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (aswKbd) – C:\Windows\System32\drivers\aswKbd.sys (AVAST Software)
DRV - (SRS_AE_Service) – C:\Windows\System32\drivers\SRS_AE_i386.sys ()
DRV - (Revoflt) – C:\Windows\System32\drivers\revoflt.sys (VS Revo Group)
DRV - (ssrangdr) – C:\Windows\System32\drivers\ssrangdr.sys (SupportSoft Inc.)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (WSDScan) – C:\Windows\System32\drivers\WSDScan.sys (Microsoft Corporation)
DRV - (CnxtHdAudService) – C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (IntcHdmiAddService) – C:\Windows\System32\drivers\IntcHdmi.sys (Intel® Corporation)
DRV - (WSDPrintDevice) – C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
IE - HKU\S-1-5-21-90010376-98873278-4205430638-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-90010376-98873278-4205430638-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: testpilot%40labs.mozilla.com:1.2.2
FF - prefs.js..extensions.enabledAddons: %7B0545b830-f0aa-4d7e-8820-50a4629a56fe%7D:19.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23.0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Users\gogo\Downloads\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\gogo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\gogo\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\CONFLICT.1\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\gogo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 23.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2010/03/04 15:12:17 | 000,000,000 | —D | M] (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Extensions
[2010/03/04 15:12:17 | 000,000,000 | —D | M] (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/03/29 09:32:17 | 000,000,000 | —D | M] (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\extensions
[2010/03/29 09:32:17 | 000,000,000 | —D | M] (PlaySushi TextLinks) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\extensions\[removed]
[2013/08/01 03:37:09 | 000,000,000 | —D | M] (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions
[2013/08/01 03:37:09 | 000,000,000 | —D | M] (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2013/07/30 00:39:09 | 000,000,000 | —D | M] ("ColorfulTabs") – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}(235)
[2013/06/20 17:53:34 | 000,000,000 | —D | M] (YouTube™ Anywhere Player) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions\{c9d31470-81c6-4e3e-9a37-46eb9237ed3a}
[2013/05/13 22:11:08 | 000,615,445 | —- | M] () (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions\[removed]
[2013/08/01 01:16:50 | 000,824,302 | —- | M] () (No name found) – C:\Users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

========== Chrome ==========

CHR - default_search_provider: Bing (Enabled)
CHR - default_search_provider: search_url = http://www.bing.com/search?setmkt=en-US&q={searchTerms}
CHR - default_search_provider: suggest_url = http://api.bing.com/osjson.aspx?query={sea…uage={language},
CHR - plugin: Shockwave Flash (Disabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: iTunes Application Detector (Disabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Disabled) = C:\Users\gogo\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Facebook Video Calling Plugin (Disabled) = C:\Users\gogo\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: SOE Web Installer (Disabled) = C:\Users\gogo\AppData\Local\Microsoft\Internet Explorer\Downloaded Program Files\CONFLICT.1\npsoe.dll
CHR - plugin: Picasa (Disabled) = C:\Users\gogo\Downloads\Picasa3\npPicasa3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: BIODIGITAL HUMAN = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak\0.9.5_0\
CHR - Extension: Hidden Object Games from Big Fish Games = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cimlkohpcpfkjdpcflnekhaecfhmcmnc\1.1_0\
CHR - Extension: Find your way to Oz = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgmbnhmcbgnenhcjpmgfhneiiamfijel\1.1.0_0\
CHR - Extension: Rush Team = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb\1.0_0\
CHR - Extension: Mahjongg = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop\1.0.0.2_0\
CHR - Extension: Causality Games = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\femoooemgmjaebeodbbikbkmhlafenpl\10_0\
CHR - Extension: Crush the castle series = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\geblmcokaocbfbjebkabgkpofoagfdbd\6.2_0\
CHR - Extension: Planetarium = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp\1.1.2_0\
CHR - Extension: Air Hockey = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gojagedhadegobocpaokaifiacjiolph\2.0.0_0\
CHR - Extension: Cargo Bridge: Armor Games Edition = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlpiaibleklmjieibbnmkignbggodmmj\2.1.1_0\
CHR - Extension: iPiccy Photo Editor = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\imokeandodnlammaoenbgcnbhigjbpjh\1.1_0\
CHR - Extension: Roomstyler 3D planner = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfnniehafojoidolddmhfnpnbiolbppi\2.5_0\
CHR - Extension: Autodesk Homestyler = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb\2.3_0\
CHR - Extension: Cargo Bridge = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\keembkgclppcbilkekfgpobhldjjhpmn\1.5.7_0\
CHR - Extension: Meme Generator = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfcohkjejibbohjcejckhdnkfceagebc\1.0_0\
CHR - Extension: Quick Earth = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\khodocggeplgfhppgagfdpbjkniadmdh\3.6_0\
CHR - Extension: CanvasDraw = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\knfimpamngmggpbamfoomdpebdoleghe\2_0\
CHR - Extension: Little Alchemy = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0\
CHR - Extension: Build with Chrome = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbbbhbjeecagnlfgggogfclkdjamoapf\0.0.0.2_0\
CHR - Extension: Word\u00B2 = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpibnckjjeaabeepofhfmmpjmnomohee\2.5_0\
CHR - Extension: Planner 5D = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcafejemebbngbglfoinpoaannbihjna\1.2.0.4_0\
CHR - Extension: 3D Solar System Web = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdaaepplopehigjgkolniddiadbbkphd\0.50_0\
CHR - Extension: Google Play Books = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.8_0\
CHR - Extension: ROBLOX Outfit Saver Extension = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpaohnjlgfabcooefhihmafmdcbliakf\1.3.5_0\
CHR - Extension: Anatronica - 3D Interactive Anatomy = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nalpooddpdnhjicpjgnhaihnnfnmbpee\1.2.0_0\
CHR - Extension: Cargo Bridge: Xmas level pack = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncdcclndkdgngndhjfccoabooegcgamk\1.0.1_0\
CHR - Extension: BeGone = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk\1.7.2_0\
CHR - Extension: Lumosity = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffmfbhcjemfledhndnpllechagamlfp\1.1_0\
CHR - Extension: Mini Ninjas = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi\1.0.0.19_0\
CHR - Extension: Origami Player = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiomepakkenneiifjocbinkmmampfbdn\2.4_0\
CHR - Extension: Bullet Physics NaCl Test = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgehkhceingafmkkmbeoempaablkkeal\1.0_0\
CHR - Extension: Psykopaint = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\
CHR - Extension: Psykopaint = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\.bak
CHR - Extension: Mysteriez! = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\phhpkfchfjfeicikkkajdojpjkapdpnd\1.0.1_0\
CHR - Extension: Anatomicus - Human Anatomy Atlas = C:\Users\gogo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkgfngehhjplndcgejapgknnjpdgfpag\1.2_0\

O1 HOSTS File: ([2013/04/27 22:49:47 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (SDHelper) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows Mobile-based device management] C:\Windows\WindowsMobile\wmdSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-90010376-98873278-4205430638-1000..\Run: [Facebook Update] C:\Users\gogo\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-90010376-98873278-4205430638-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-90010376-98873278-4205430638-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C922B5CC-8097-4DF3-B14B-264696D80453}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Users\gogo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\gogo\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/04 13:39:57 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/08/04 02:49:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/08/04 02:37:29 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\gogo\Desktop\HiJackThis.exe
[2013/08/04 02:33:35 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/08/04 02:31:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\gogo\Desktop\OTL.exe
[2013/07/30 12:36:48 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox(79)
[2013/07/28 03:48:20 | 000,000,000 | —D | C] – C:\Program Files\Bandizip
[2013/07/28 03:39:23 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2013/07/12 17:28:11 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/07/12 17:28:09 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/07/12 17:28:08 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/07/12 17:28:07 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/07/12 17:28:07 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/07/12 17:28:04 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/07/12 17:28:03 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/07/12 17:28:01 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/07/11 11:44:32 | 001,069,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/07/11 11:44:31 | 001,172,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/07/11 11:44:31 | 001,029,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/07/11 11:44:31 | 000,486,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/07/11 11:44:31 | 000,219,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/07/11 11:44:31 | 000,189,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/07/11 11:44:30 | 000,683,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/07/11 11:44:30 | 000,160,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/07/11 11:22:12 | 002,049,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/07/11 11:17:46 | 000,505,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/07/11 11:17:37 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/07/07 22:26:48 | 000,000,000 | —D | C] – C:\Users\gogo\AppData\Local\ElevatedDiagnostics
[2013/07/07 20:30:42 | 000,000,000 | —D | C] – C:\Users\gogo\.minecraft
[2013/07/07 19:12:15 | 000,000,000 | —D | C] – C:\Users\gogo\AppData\Roaming\.technic
[2013/07/06 00:13:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2011/11/25 17:15:28 | 000,730,192 | —- | C] (How Inc.) – C:\Program Files\Common Files\ZugoInstaller.exe

========== Files - Modified Within 30 Days ==========

[2013/08/04 13:42:05 | 000,640,886 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/04 13:42:05 | 000,119,106 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/04 13:39:57 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/08/04 13:36:32 | 000,000,878 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/04 13:36:07 | 000,000,620 | —- | M] () – C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/08/04 13:35:35 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/04 13:35:05 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/04 13:35:05 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/04 13:34:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/04 13:34:19 | 3149,078,528 | -HS- | M] () – C:\hiberfil.sys
[2013/08/04 02:40:47 | 000,625,664 | —- | M] () – C:\Users\gogo\Desktop\dds.scr
[2013/08/04 02:37:29 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\gogo\Desktop\HiJackThis.exe
[2013/08/04 02:31:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\gogo\Desktop\OTL.exe
[2013/07/11 11:30:35 | 000,310,888 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/07/08 20:52:01 | 000,114,688 | —- | M] () – C:\Users\gogo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/07/07 19:32:53 | 000,000,708 | —- | M] () – C:\Users\gogo\Desktop\Technic Launcher.lnk
[2013/07/07 14:16:28 | 000,001,323 | —- | M] () – C:\Users\gogo\Documents\chores.rtf

========== Files Created - No Company Name ==========

[2013/08/04 13:34:19 | 3149,078,528 | -HS- | C] () – C:\hiberfil.sys
[2013/08/04 02:40:47 | 000,625,664 | —- | C] () – C:\Users\gogo\Desktop\dds.scr
[2013/07/07 19:32:53 | 000,000,708 | —- | C] () – C:\Users\gogo\Desktop\Technic Launcher.lnk
[2013/07/07 13:50:22 | 000,001,323 | —- | C] () – C:\Users\gogo\Documents\chores.rtf
[2013/04/12 00:49:24 | 000,000,036 | —- | C] () – C:\Users\gogo\AppData\Local\housecall.guid.cache
[2013/03/15 23:22:28 | 000,174,664 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/03/15 23:22:28 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2012/11/26 16:39:32 | 000,583,306 | —- | C] () – C:\Users\gogo\AppData\Roaming\technic-launcher.jar
[2012/06/16 16:48:43 | 000,404,256 | —- | C] () – C:\Windows\System32\drivers\SRS_AE_i386.sys
[2012/02/07 15:14:11 | 000,000,094 | —- | C] () – C:\Windows\EART730.ini
[2011/05/22 09:04:02 | 000,011,316 | -HS- | C] () – C:\ProgramData\mssfsi1vlq8g1bx8lmkcbl8
[2011/03/26 19:13:54 | 000,193,536 | —- | C] () – C:\Users\gogo\yeah.MSWMM
[2010/07/21 23:53:12 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/01/30 14:41:15 | 000,000,069 | —- | C] () – C:\Users\gogo\jagex_runescape_preferences2.dat
[2010/01/30 14:40:21 | 000,000,039 | —- | C] () – C:\Users\gogo\jagex_runescape_preferences.dat
[2009/09/28 19:22:45 | 000,003,804 | —- | C] () – C:\Users\gogo\AppData\Roaming\wklnhst.dat
[2009/09/15 17:47:40 | 000,001,356 | —- | C] () – C:\Users\gogo\AppData\Local\d3d9caps.dat
[2009/08/28 18:57:16 | 000,114,688 | —- | C] () – C:\Users\gogo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/27 00:35:33 | 000,000,632 | RHS- | C] () – C:\Users\gogo\ntuser.pol
[2009/08/23 00:36:47 | 000,024,206 | —- | C] () – C:\Users\gogo\AppData\Roaming\UserTile.png
[2009/07/31 11:08:01 | 000,000,284 | —- | C] () – C:\ProgramData\hpqp.ini

========== ZeroAccess Check ==========

[2006/11/02 05:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 10:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/10 23:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/10 23:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/06/26 12:40:39 | 000,000,000 | —D | M] – C:\Users\Daisy\AppData\Roaming\Epson
[2013/02/02 16:44:35 | 000,000,000 | —D | M] – C:\Users\Daisy\AppData\Roaming\IrfanView
[2013/08/01 03:37:08 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\.minecraft
[2013/07/21 18:56:25 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\.technic
[2012/11/26 16:41:56 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\.techniclauncher
[2010/05/09 09:57:11 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Boomzap
[2010/01/20 16:59:13 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013/04/18 23:58:07 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Dropbox
[2010/07/26 14:00:34 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Enlightenus_iWin
[2012/06/16 19:28:58 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Epson
[2010/11/30 15:31:45 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Flood Light Games
[2010/01/24 11:45:29 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\funkitron
[2010/06/26 22:28:49 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Gamelab
[2010/01/24 09:24:02 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\GAMEON
[2010/10/31 00:40:14 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Games
[2011/08/09 13:25:59 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\go
[2010/01/20 22:40:31 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Gold Casual Games
[2011/02/24 13:15:24 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Instant Housecall
[2009/10/23 15:30:27 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\IronCode
[2010/11/20 21:25:41 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Jane s Hotel
[2012/02/08 07:30:44 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Leader Technologies
[2012/02/07 15:40:51 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Leadertech
[2012/11/26 16:39:31 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\logs
[2011/03/11 22:36:33 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Mystery of Mortlake Mansion
[2010/11/15 19:36:07 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\MysteryStudio
[2009/08/23 00:36:47 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\PeerNetworking
[2010/11/13 12:05:38 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\PlayFirst
[2009/09/03 22:21:37 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Playrix Entertainment
[2010/10/17 18:40:52 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\SaveThePuppy
[2009/12/24 14:14:14 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\SBTT
[2009/09/25 21:12:42 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Shape games
[2009/08/19 14:56:27 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\SupportSoft
[2009/09/28 19:22:46 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Template
[2010/11/17 19:07:04 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\Virtual City
[2010/10/14 23:33:03 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\WildTangentv1001
[2009/09/06 09:11:41 | 000,000,000 | —D | M] – C:\Users\gogo\AppData\Roaming\WildTangentv1002
[2013/08/01 03:37:10 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\.minecraft
[2013/07/31 11:52:45 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\.technic
[2013/06/28 20:37:49 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\.techniclauncher
[2012/10/10 00:26:44 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/10/23 22:18:28 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Epson
[2010/01/18 11:39:47 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\funkitron
[2013/01/29 14:52:28 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\IrfanView
[2010/10/15 17:48:12 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Jane s Hotel
[2012/02/07 16:58:11 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Leader Technologies
[2010/03/07 15:13:13 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\LimeWire
[2013/07/05 20:29:11 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\logs
[2013/01/14 16:46:39 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\MoreTerra
[2011/12/25 14:12:14 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Origin
[2010/11/20 08:39:34 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\PlayFirst
[2010/04/30 21:11:34 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Shape games
[2010/05/07 15:57:48 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Template
[2011/11/24 15:25:15 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\Unity
[2009/08/29 07:41:10 | 000,000,000 | —D | M] – C:\Users\Kids\AppData\Roaming\WildTangent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2009/04/20 04:38:00 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/04/20 04:37:59 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/04/20 04:37:59 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\erdnt\cache\explorer.exe
[2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/10 23:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2012/11/13 14:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe
[2009/04/20 04:38:00 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 19:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: EXPLORER.EXE.ATK.KDMP >
[2013/08/01 03:22:18 | 000,070,264 | —- | M] () MD5=55EAD2FF2C9281F02D60F526C16B0E77 – C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.atk.kdmp
[2013/08/01 03:22:18 | 000,070,264 | —- | M] () MD5=55EAD2FF2C9281F02D60F526C16B0E77 – C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.atk.kdmp

< MD5 for: EXPLORER.EXE.MU.DMP >
[2013/08/01 03:22:20 | 000,050,937 | —- | M] () MD5=FDEF4F543999147975097030884C0DA8 – C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.mu.dmp
[2013/08/01 03:22:20 | 000,050,937 | —- | M] () MD5=FDEF4F543999147975097030884C0DA8 – C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.mu.dmp

< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 05:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 05:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui

< MD5 for: EXPLORER.EXE.XML >
[2013/08/01 03:22:20 | 000,001,508 | —- | M] () MD5=04620C0562F4D79C1ED6E4121626A046 – C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.xml
[2013/08/01 03:22:20 | 000,001,508 | —- | M] () MD5=04620C0562F4D79C1ED6E4121626A046 – C:\Users\All Users\Microsoft\Windows\WER\ReportQueue\Report0b51a0f1\Explorer.EXE.xml

< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/08/04 13:36:32 | 000,202,118 | —- | M] () MD5=ED235270D753B8FFDA9AA752DA211CBD – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf

< MD5 for: IEXPLORE.BAT >
[2013/04/21 00:58:12 | 000,029,803 | —- | M] () MD5=E4B95882FB080670179EA3605395889B – C:\JRT\iexplore.bat

< MD5 for: IEXPLORE.EXE >
[2012/05/17 16:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 04:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/04/20 04:41:17 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 19:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2011/09/30 16:49:11 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2009/04/20 04:25:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2009/11/20 23:42:38 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=1B6362BB14FCEB9E76BCF9A953B04788 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18865_none_120f459f2ff7e1f8\iexplore.exe
[2009/07/18 05:16:49 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D5A01AA2DE47C052AF46D7EBCB003A3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16890_none_2d1a75e31d20e59f\iexplore.exe
[2009/07/18 14:39:09 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=1D8163DBFECAEDB9C48C5F55084BC491 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18294_none_2f04b5b11a43dbec\iexplore.exe
[2012/08/24 00:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2010/02/23 08:06:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=25DB705A7DC85C208B3CF2D20F118AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22995_none_127872a6492dd595\iexplore.exe
[2012/05/17 15:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 01:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2011/11/03 00:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/10 23:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2009/08/26 22:23:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=2E48756F12C21F46895036AC089AAD97 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18828_none_123d862d2fd4be39\iexplore.exe
[2013/02/21 21:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\erdnt\cache\iexplore.exe
[2013/02/21 21:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2013/05/28 20:32:47 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=33E62E4EFC2ACA8EC63A8926F26D3889 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20606_none_594dd74504b2f1a8\iexplore.exe
[2012/06/02 02:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2010/01/02 07:58:26 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=3D8DA00B028DEA9517066F1CECBFC4A2 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22973_none_128c11ea491f6b05\iexplore.exe
[2013/04/04 15:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_586ab855ebd8e83a\iexplore.exe
[2013/02/21 21:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2010/05/03 23:32:18 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=48A6109E8DF0365195298CC527B7426A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23019_none_12d2cb5048e98eab\iexplore.exe
[2010/09/07 23:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/07/21 23:04:09 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4B5AEA50CE77FBA4C2D169622DC9B489 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\iexplore.exe
[2011/07/23 04:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2011/12/15 00:36:29 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=54EF418BD99720658CCE24210799BD1A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23286_none_12841eca4925008b\iexplore.exe
[2010/11/01 23:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 19:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2010/05/03 23:00:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5C9B1062EA7A44E8F6BFDE994B68C7AA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18928_none_123d88132fd4bb60\iexplore.exe
[2012/08/24 00:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2013/05/16 16:34:33 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16490_none_585ce78bebe3b826\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2010/06/25 23:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 00:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 16:07:49 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2009/08/27 06:31:08 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7DD482E4A2E3CBB0A72F718C342F5B75 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22918_none_12d1f2e448ea4212\iexplore.exe
[2011/05/28 00:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2009/07/18 05:16:45 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=7FCF4E704A48D95202F3E7A1E1A21412 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.21089_none_2db7bd56362e80c9\iexplore.exe
[2010/01/01 23:40:20 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=88BD42DAE7CFFEB256CA7145A15E4843 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18882_none_11f6a4e9300acdd5\iexplore.exe
[2012/02/21 07:36:09 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 00:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 18:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2009/04/20 04:25:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 00:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2010/02/22 23:39:16 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9F52FBE99C749E3F32C75124F09F1B03 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18904_none_124f26c32fc81e22\iexplore.exe
[2013/02/01 21:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_58f1544304f93bff\iexplore.exe
[2013/05/16 15:27:11 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20600_none_5947d58904b8599e\iexplore.exe
[2011/12/14 23:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19190_none_11e9b0573014e4a8\iexplore.exe
[2009/03/08 14:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/12/17 23:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 01:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2013/04/04 14:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_58e9853504fea3f5\iexplore.exe
[2011/02/21 23:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2009/07/21 14:53:43 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=C33BD196A0301F9B23D9A003D30ED8B0 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\iexplore.exe
[2011/11/02 23:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/10/08 01:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/07 23:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2013/02/01 21:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_58728763ebd38044\iexplore.exe
[2009/11/21 08:05:17 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=E7F8DF50E483D165BB01F367D3519AA7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22956_none_12a4b2a0490c7f28\iexplore.exe
[2012/06/28 16:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2009/07/18 04:55:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=EBEE9E4421F35CD861107DDA0266FBB1 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22475_none_2fa4f48433505a52\iexplore.exe
[2011/05/27 23:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2013/05/28 19:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/28 19:24:32 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=EE12BA876C4190532A4085994BA9B616 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16496_none_5862e947ebde5030\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/25 23:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/04/20 04:41:17 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 19:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe

< MD5 for: IEXPLORE.EXE.LOCAL >
[2011/12/20 13:37:28 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Program Files\Internet Explorer\iexplore.exe.local

< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 05:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2012/02/21 07:36:10 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/02/21 07:36:10 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 14:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-1B894AFB.PF >
[2013/08/04 13:50:51 | 000,151,580 | —- | M] () MD5=A423A36D286FEE90375E69ADF3EABC01 – C:\Windows\Prefetch\IEXPLORE.EXE-1B894AFB.pf

< MD5 for: SERVICES >
[2006/09/18 14:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 14:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.CFG >
[2013/05/10 00:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.DAT >
[2013/04/21 20:04:55 | 000,001,720 | —- | M] () MD5=43C1700D78D89F0B1F6FA88FD132BE1A – C:\JRT\services.dat

< MD5 for: SERVICES.EXE >
[2008/01/20 19:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/10 23:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\erdnt\cache\services.exe
[2009/04/10 23:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/10 23:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 05:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 05:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/01/20 19:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 19:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 14:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 14:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 14:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 05:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 14:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 05:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 14:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SERVICES.SBS >
[2011/03/01 08:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy 2\Includes\Services.sbs

< MD5 for: WINLOGON.EXE >
[2009/04/10 23:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\erdnt\cache\winlogon.exe
[2009/04/10 23:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/10 23:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 19:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 19:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 19:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 05:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2013/08/01 03:05:42 | 000,034,046 | —- | M] () MD5=707444F2C79616E9FD4320ED43E3CA2D – C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf

< MD5 for: WINLOGON.MOF >
[2006/09/18 14:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 14:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2006/09/18 14:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/10 23:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2013/08/04 13:34:19 | 3149,078,528 | -HS- | M] () – C:\hiberfil.sys
[2013/08/04 13:34:17 | 3462,864,896 | -HS- | M] () – C:\pagefile.sys
[2011/11/12 00:56:59 | 000,000,184 | —- | M] () – C:\setup.log

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/10/05 10:20:49 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/05/01 16:33:35 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 2DF8-C431
Directory of C:\
11/02/2006 06:02 AM Documents and Settings [c:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
11/02/2006 06:02 AM Application Data [c:\ProgramData]
11/02/2006 06:02 AM Desktop [c:\Users\Public\Desktop]
11/02/2006 06:02 AM Documents [c:\Users\Public\Documents]
11/02/2006 06:02 AM Favorites [c:\Users\Public\Favorites]
11/02/2006 06:02 AM Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 06:02 AM Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
11/02/2006 06:02 AM All Users [c:\ProgramData]
11/02/2006 06:02 AM Default User [c:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
11/02/2006 06:02 AM Application Data [c:\ProgramData]
11/02/2006 06:02 AM Desktop [c:\Users\Public\Desktop]
11/02/2006 06:02 AM Documents [c:\Users\Public\Documents]
11/02/2006 06:02 AM Favorites [c:\Users\Public\Favorites]
11/02/2006 06:02 AM Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
11/02/2006 06:02 AM Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Daisy
06/26/2012 12:40 PM Application Data [C:\Users\Daisy\AppData\Roaming]
06/26/2012 12:40 PM Cookies [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Cookies]
06/26/2012 12:40 PM Local Settings [C:\Users\Daisy\AppData\Local]
06/26/2012 12:40 PM My Documents [C:\Users\Daisy\Documents]
06/26/2012 12:40 PM NetHood [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/26/2012 12:40 PM PrintHood [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/26/2012 12:40 PM Recent [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Recent]
06/26/2012 12:40 PM SendTo [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\SendTo]
06/26/2012 12:40 PM Start Menu [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Start Menu]
06/26/2012 12:40 PM Templates [C:\Users\Daisy\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Daisy\AppData\Local
06/26/2012 12:40 PM Application Data [C:\Users\Daisy\AppData\Local]
06/26/2012 12:40 PM History [C:\Users\Daisy\AppData\Local\Microsoft\Windows\History]
06/26/2012 12:40 PM Temporary Internet Files [C:\Users\Daisy\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Daisy\Documents
06/26/2012 12:40 PM My Music [C:\Users\Daisy\Music]
06/26/2012 12:40 PM My Pictures [C:\Users\Daisy\Pictures]
06/26/2012 12:40 PM My Videos [C:\Users\Daisy\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
11/02/2006 06:02 AM Application Data [c:\Users\Default\AppData\Roaming]
11/02/2006 06:02 AM Local Settings [c:\Users\Default\AppData\Local]
11/02/2006 06:02 AM My Documents [c:\Users\Default\Documents]
11/02/2006 06:02 AM NetHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/02/2006 06:02 AM PrintHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/02/2006 06:02 AM Recent [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
11/02/2006 06:02 AM SendTo [c:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
11/02/2006 06:02 AM Start Menu [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
11/02/2006 06:02 AM Templates [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
11/02/2006 06:02 AM Application Data [c:\Users\Default\AppData\Local]
11/02/2006 06:02 AM History [c:\Users\Default\AppData\Local\Microsoft\Windows\History]
11/02/2006 06:02 AM Temporary Internet Files [c:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
11/02/2006 06:02 AM My Music [c:\Users\Default\Music]
11/02/2006 06:02 AM My Pictures [c:\Users\Default\Pictures]
11/02/2006 06:02 AM My Videos [c:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\gogo
08/19/2009 02:46 PM Application Data [C:\Users\gogo\AppData\Roaming]
08/19/2009 02:46 PM Cookies [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Cookies]
08/19/2009 02:46 PM Local Settings [C:\Users\gogo\AppData\Local]
08/19/2009 02:46 PM My Documents [C:\Users\gogo\Documents]
08/19/2009 02:46 PM NetHood [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/19/2009 02:46 PM PrintHood [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/19/2009 02:46 PM Recent [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Recent]
08/19/2009 02:46 PM SendTo [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\SendTo]
08/19/2009 02:46 PM Start Menu [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Start Menu]
08/19/2009 02:46 PM Templates [C:\Users\gogo\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\gogo\AppData\Local
08/19/2009 02:46 PM Application Data [C:\Users\gogo\AppData\Local]
08/19/2009 02:46 PM History [C:\Users\gogo\AppData\Local\Microsoft\Windows\History]
08/19/2009 02:46 PM Temporary Internet Files [C:\Users\gogo\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\gogo\Documents
08/19/2009 02:46 PM My Music [C:\Users\gogo\Music]
08/19/2009 02:46 PM My Pictures [C:\Users\gogo\Pictures]
08/19/2009 02:46 PM My Videos [C:\Users\gogo\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Kids
08/27/2009 06:07 PM Application Data [C:\Users\Kids\AppData\Roaming]
08/27/2009 06:07 PM Cookies [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Cookies]
08/27/2009 06:07 PM Local Settings [C:\Users\Kids\AppData\Local]
08/27/2009 06:07 PM My Documents [C:\Users\Kids\Documents]
08/27/2009 06:07 PM NetHood [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/27/2009 06:07 PM PrintHood [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/27/2009 06:07 PM Recent [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Recent]
08/27/2009 06:07 PM SendTo [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\SendTo]
08/27/2009 06:07 PM Start Menu [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Start Menu]
08/27/2009 06:07 PM Templates [C:\Users\Kids\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Kids\AppData\Local
08/27/2009 06:07 PM Application Data [C:\Users\Kids\AppData\Local]
08/27/2009 06:07 PM History [C:\Users\Kids\AppData\Local\Microsoft\Windows\History]
08/27/2009 06:07 PM Temporary Internet Files [C:\Users\Kids\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Kids\Documents
08/27/2009 06:07 PM My Music [C:\Users\Kids\Music]
08/27/2009 06:07 PM My Pictures [C:\Users\Kids\Pictures]
08/27/2009 06:07 PM My Videos [C:\Users\Kids\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
11/02/2006 06:02 AM My Music [c:\Users\Public\Music]
11/02/2006 06:02 AM My Pictures [c:\Users\Public\Pictures]
11/02/2006 06:02 AM My Videos [c:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
04/20/2009 05:29 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
04/20/2009 05:29 AM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
04/20/2009 05:29 AM My Documents [C:\Windows\system32\config\systemprofile\Documents]
04/20/2009 05:29 AM NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/20/2009 05:29 AM PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/20/2009 05:29 AM Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
04/20/2009 05:29 AM SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
04/20/2009 05:29 AM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
04/20/2009 05:29 AM Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
04/20/2009 05:29 AM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
04/20/2009 05:29 AM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
04/20/2009 05:29 AM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\Documents
04/20/2009 05:29 AM My Music [C:\Windows\system32\config\systemprofile\Music]
04/20/2009 05:29 AM My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
04/20/2009 05:29 AM My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
96 Dir(s) 163,416,158,208 bytes free

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/06/26 00:38:10 | 000,000,286 | -HS- | M] () – C:\Users\gogo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/08/04 02:37:29 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\gogo\Desktop\HiJackThis.exe
[2013/08/04 02:31:36 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\gogo\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >
[2011/09/02 14:03:28 | 000,730,192 | —- | M] (How Inc.) – C:\Program Files\Common Files\ZugoInstaller.exe

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-08-04 10:02:26

========== Alternate Data Streams ==========

@Alternate Data Stream - 146 bytes -> C:\ProgramData\Temp:AA6C7C38
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:5C321E34
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:B1FBBD09
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:7757A6D4

< End of report >

——————————————————————————————————————————————————————————–
Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:34:25 PM, on 8/5/2013
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16496)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\gogo\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…ion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SDHelper - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\gogo\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Startup: OneNote Table Of Contents.onetoc2
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: Google Update Service (gupdate1ce11e97cd4f97c) (gupdate1ce11e97cd4f97c) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 9012 bytes
——————————————————————————————————————————————————————————
DDS.txt log:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 22:36:54.21 on Mon 08/05/2013
Internet Explorer: 9.0.8112.16421
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1799 [GMT -7:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Epson Software\Event Manager\EEventManager.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\gogo\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://www.google.com
BHO: SDHelper: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Facebook Update] "c:\users\gogo\appdata\local\facebook\update\FacebookUpdate.exe" /c /nocrashserver
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [EEventManager] "c:\program files\epson software\event manager\EEventManager.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\gogo\appdata\roaming\microsoft\windows\start menu\programs\startup\OneNote Table Of Contents.onetoc2
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
LSP: c:\windows\system32\wpclsp.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\27.0.1453.116\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\gogo\appdata\roaming\mozilla\firefox\profiles\1qnmbpub.default\
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.153\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20513.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\gogo\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\gogo\appdata\local\microsoft\internet explorer\downloaded program files\conflict.1\npsoe.dll
FF - plugin: c:\users\gogo\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\gogo\downloads\picasa3\npPicasa3.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1203133.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_8_800_94.dll
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-15 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-15 174664]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2013-1-20 195296]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2013-2-6 20624]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-2-17 368944]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2013-5-5 37352]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2013-5-10 65640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-17 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-2-17 66336]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2013-5-5 84744]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2009-4-20 365952]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2013-5-13 1103392]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2013-5-13 1369624]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\spybot - search & destroy 2\SDWSCSvc.exe [2013-5-13 168384]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-20 193840]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 112128]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-7-9 765736]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1ce11e97cd4f97c;Google Update Service (gupdate1ce11e97cd4f97c);c:\program files\google\update\GoogleUpdate.exe [2011-10-31 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2013-5-13 256904]
S3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-10-31 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2013-8-4 40776]
S3 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\sitead~1\mcsacore.exe –> c:\progra~1\mcafee\sitead~1\mcsacore.exe [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2013-1-20 117144]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2013-1-20 100328]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2013-1-27 295232]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2013-5-5 27192]
S3 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 SRS_AE_Service;SRS Audio Essentials;c:\windows\system32\drivers\SRS_AE_i386.sys [2012-6-16 404256]
S3 ssrangdr;ssrangdr;c:\windows\system32\drivers\ssrangdr.sys [2009-7-13 2560]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-4-18 754856]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896]
S3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\drivers\WSDScan.sys [2009-9-17 19968]
S4 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]
S4 EpsonCustomerParticipation;EpsonCustomerParticipation;c:\program files\epson\epsoncustomerparticipation\EPCP.exe [2011-3-17 513408]
.
=============== Created Last 30 ================
.
2013-08-04 20:49:24 7143960 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{b6574f63-d203-48ea-b8a6-de8ba1a1c56e}\mpengine.dll
2013-08-04 20:39:57 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-08-04 09:43:18 698504 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{72bb2389-e65f-46ab-ad2c-74f75ea33e4e}\gapaengine.dll
2013-08-04 09:33:35 638328 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-04 09:33:35 37376 —-a-w- c:\windows\system32\cdd.dll
2013-08-01 10:39:52 7068072 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2013-07-30 19:36:48 ——– d—–w- c:\program files\Mozilla Firefox(79)
2013-07-28 10:48:20 ——– d—–w- c:\program files\Bandizip
2013-07-11 18:44:32 1069056 —-a-w- c:\windows\system32\DWrite.dll
2013-07-11 18:44:31 798208 —-a-w- c:\windows\system32\FntCache.dll
2013-07-11 18:44:31 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2013-07-11 18:44:31 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2013-07-11 18:44:31 189952 —-a-w- c:\windows\system32\d3d10core.dll
2013-07-11 18:44:31 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2013-07-11 18:44:31 1029120 —-a-w- c:\windows\system32\d3d10.dll
2013-07-11 18:44:30 683008 —-a-w- c:\windows\system32\d2d1.dll
2013-07-11 18:44:30 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2013-07-11 18:22:12 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-07-11 18:17:46 505344 —-a-w- c:\windows\system32\qedit.dll
2013-07-11 18:17:37 1548288 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-11 18:13:33 936960 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2013-07-11 18:13:31 1218048 —-a-w- c:\program files\windows journal\NBDoc.DLL
2013-07-11 18:13:30 983552 —-a-w- c:\program files\windows journal\JNTFiltr.dll
2013-07-11 18:13:30 964608 —-a-w- c:\program files\windows journal\JNWDRV.dll
2013-07-08 05:26:48 ——– d—–w- c:\users\gogo\appdata\local\ElevatedDiagnostics
2013-07-08 03:30:42 ——– d—–w- c:\users\gogo\.minecraft
2013-07-08 02:12:15 ——– d—–w- c:\users\gogo\appdata\roaming\.technic
.
==================== Find3M ====================
.
2013-07-04 03:55:18 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-04 03:55:12 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-07-04 03:55:12 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-06-18 05:02:25 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-18 05:02:24 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-29 01:50:14 1800704 —-a-w- c:\windows\system32\jscript9.dll
2013-05-29 01:41:52 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2013-05-29 01:41:08 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-05-29 01:37:15 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2013-05-29 01:36:09 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-05-29 01:33:22 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-09-02 21:03:28 730192 —-a-w- c:\program files\common files\ZugoInstaller.exe
.
============= FINISH: 22:37:45.51 ===============
———————————————————————————————————————————————————————————-
Attach.txt log:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 7/31/2009 10:32:58 AM
System Uptime: 8/5/2013 10:12:33 PM (0 hours ago)
.
Motherboard: Wistron | | 360C
Processor: Intel® Core™2 Duo CPU T6500 @ 2.10GHz | CPU | 2100/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 287 GiB total, 151.746 GiB free.
D: is FIXED (NTFS) - 11 GiB total, 1.81 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1361: 7/16/2013 4:15:58 PM - Scheduled Checkpoint
RP1362: 7/16/2013 7:13:29 PM - Windows Update
RP1363: 7/17/2013 4:42:11 PM - Scheduled Checkpoint
RP1364: 7/17/2013 6:00:28 PM - Windows Update
RP1365: 7/17/2013 6:12:36 PM - Windows Update
RP1366: 7/18/2013 9:55:58 AM - Scheduled Checkpoint
RP1367: 7/19/2013 12:00:11 AM - Scheduled Checkpoint
RP1368: 7/20/2013 12:00:10 AM - Scheduled Checkpoint
RP1369: 7/20/2013 2:35:04 PM - Scheduled Checkpoint
RP1370: 7/20/2013 7:17:36 PM - Windows Update
RP1371: 7/22/2013 12:00:11 AM - Scheduled Checkpoint
RP1372: 7/23/2013 7:39:46 AM - Scheduled Checkpoint
RP1373: 7/24/2013 10:27:14 AM - Scheduled Checkpoint
RP1374: 7/24/2013 7:18:39 PM - Windows Update
RP1375: 7/25/2013 9:46:01 AM - Scheduled Checkpoint
RP1376: 7/25/2013 11:27:11 PM - Scheduled Checkpoint
RP1377: 7/27/2013 8:38:09 AM - Scheduled Checkpoint
RP1378: 7/27/2013 7:30:34 PM - Windows Update
RP1379: 7/28/2013 10:19:08 AM - Scheduled Checkpoint
RP1380: 7/29/2013 11:26:28 AM - Scheduled Checkpoint
RP1381: 7/30/2013 12:00:09 AM - Scheduled Checkpoint
RP1382: 7/30/2013 4:37:55 PM - Scheduled Checkpoint
RP1383: 7/31/2013 12:02:29 PM - Scheduled Checkpoint
RP1384: 7/31/2013 12:03:18 PM - Windows Update
RP1385: 7/31/2013 7:20:44 PM - Windows Update
RP1386: 8/1/2013 1:53:08 AM - Removed Skype™ 5.10
RP1387: 8/1/2013 1:55:05 AM - Removed Facebook Video Calling 1.2.0.287
RP1388: 8/1/2013 2:33:34 AM - Windows Update
RP1389: 8/1/2013 3:27:12 AM - Restore Operation
RP1390: 8/4/2013 2:36:12 AM - Windows Update
RP1391: 8/4/2013 2:58:38 AM - OTL Restore Point - 8/4/2013 2:58:38 AM
RP1392: 8/4/2013 3:00:22 AM - Windows Update
RP1393: 8/4/2013 1:56:08 PM - OTL Restore Point - 8/4/2013 1:56:08 PM
RP1394: 8/4/2013 2:36:22 PM - OTL Restore Point - 8/4/2013 2:36:22 PM
RP1395: 8/5/2013 10:28:03 PM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
ActiveCheck component for HP Active Support Library
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.7)
Adobe Shockwave Player
Adobe Shockwave Player 12.0
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Atheros Driver Installation Program
Bandizip
Bing Bar
Bing Rewards Client Installer
Bonjour
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CyberLink DVD Suite
CyberLink PhotoDirector 3
CyberLink YouCam
DFX
Dropbox
EPSON Artisan 730 Series Printer Uninstall
Epson Connect
Epson Customer Participation
Epson Download Navigator
Epson Event Manager
Epson Print CD
EPSON Scan
EpsonNet Print
ESET Online Scanner v3
ESU for Microsoft Vista
Facebook Video Calling 1.2.0.287
FileHippo.com Update Checker
FUJIFILM MyFinePix Studio 2.0
Google Chrome
Google Earth Plug-in
Google Toolbar for Internet Explorer
Google Update Helper
HDAUDIO Soft Data Fax Modem with SmartCP
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.7
HP Help and Support
HP Quick Launch Buttons 6.40 H2
HP Total Care Advisor
HP Total Care Setup
HP Update
HP User Guides 0118
HP Wireless Assistant
HPAsset component for HP Active Support Library
HPNetworkAssistant
Instant Housecall Remote Support
Intel® Graphics Media Accelerator Driver
iTunes
Java 7 Update 25
Java Auto Updater
LabelPrint
LightScribe System Software 1.14.17.1
LTCM Client
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Works
Microsoft WSE 3.0 Runtime
Microsoft XNA Framework Redistributable 4.0
Mozilla Firefox 23.0 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NetWaiting
OGA Notifier 2.0.0048.0
Origin
Picasa 3
Pirate101
Power2Go
PowerDirector
Primo
QuickTime
RAF
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek USB 2.0 Card Reader
Revo Uninstaller Pro 3.0.5
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2832407)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687499) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Skype™ 5.10
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
SpywareBlaster 5.0
swMSM
Synaptics Pointing Device Driver
The Sims™ 3
Unity Web Player
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB2836940)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2836939)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Windows Live ID Sign-in Assistant
Windows Live OneCare safety scanner
Wizard101
.
==== Event Viewer Messages From Past Week ========
.
8/5/2013 10:26:00 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.155.1486.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9700.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
8/5/2013 10:15:48 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
8/5/2013 10:15:04 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
8/5/2013 10:14:03 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: aswSnx
8/5/2013 10:14:02 PM, Error: Service Control Manager [7001] - The Internet Connection Sharing (ICS) service depends on the Remote Access Connection Manager service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
8/5/2013 10:14:02 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
8/5/2013 10:13:58 PM, Error: Microsoft-Windows-TaskScheduler [412] - Task Scheduler service failed to launch tasks triggered by computer startup. Additional Data: Error Value: 2147549183. User Action: restart task scheduler service.
8/4/2013 2:26:49 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
8/4/2013 2:26:49 AM, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/4/2013 2:24:24 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the hpqwmiex service to connect.
8/4/2013 2:24:24 AM, Error: Service Control Manager [7000] - The hpqwmiex service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/4/2013 2:24:24 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service hpqwmiex with arguments "" in order to run the server: {F5539356-2F02-40D4-999E-FA61F45FE12E}
8/4/2013 1:50:56 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user GOGO\gogo SID (S-1-5-21-90010376-98873278-4205430638-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
8/4/2013 1:50:22 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 00265E5FE04C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/1/2013 3:44:42 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service gupdate1ce11e97cd4f97c with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
8/1/2013 3:44:41 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate1ce11e97cd4f97c) service to connect.
8/1/2013 3:44:41 AM, Error: Service Control Manager [7000] - The Google Update Service (gupdate1ce11e97cd4f97c) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/1/2013 3:43:33 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Font Cache Service service to connect.
8/1/2013 3:43:33 AM, Error: Service Control Manager [7000] - The Windows Font Cache Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/1/2013 3:42:29 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
8/1/2013 3:39:52 AM, Error: Microsoft Antimalware [2004] - Microsoft Antimalware has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x80070002 Error description: The system cannot find the file specified. Signature version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0
8/1/2013 3:24:03 AM, Error: cdrom [11] - The driver detected a controller error on \Device\CdRom0.
8/1/2013 2:31:17 AM, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2830290 (Security Update) into Resolved(Resolved) state
8/1/2013 2:30:50 AM, Error: Microsoft-Windows-Servicing [4375] - Windows Servicing failed to complete the process of setting package KB2804580 (Security Update) into Resolved(Resolved) state
8/1/2013 2:20:31 AM, Error: Microsoft Antimalware [2004] - Microsoft Antimalware has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x80070002 Error description: The system cannot find the file specified. Signature version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0
8/1/2013 1:38:14 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user GOGO\Kids SID (S-1-5-21-90010376-98873278-4205430638-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
7/31/2013 6:38:00 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.155.1052.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9700.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/31/2013 6:27:28 PM, Error: Microsoft Antimalware [2004] - Microsoft Antimalware has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures. Signatures Attempted: Current Error Code: 0x80070002 Error description: The system cannot find the file specified. Signature version: 0.0.0.0;0.0.0.0 Engine version: 0.0.0.0
7/31/2013 10:24:16 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.5 for the Network Card with network address 00265E5FE04C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
7/31/2013 1:35:41 PM, Error: EventLog [6008] - The previous system shutdown at 1:33:18 PM on 7/31/2013 was unexpected.
7/30/2013 7:26:19 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.155.1052.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.9700.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/30/2013 12:08:24 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the stisvc service.
7/30/2013 10:19:57 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00265E5FE04C has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================
Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.
  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.




Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi - thank you for responding so quickly. Ok I ran the GMER scan. The first scan stopped and Wouldn't finish so I ran it again. It finished scanning. It won't let me save it. When I push 'save' Nothing happens and no box to name the file comes up. I'm going to leave the computer the way it is with gmer open so it won't have to rescan. Let me know what to do next. Thank you.
I also tried to copy and paste the log but I was unable to open any other programs or documents to paste it to. I closed GMER and the screen went black and laptop froze. I tried Ctrl alt delete and nothing happened. I left it alone for a little bit to see if it would recover but it was still just a black screen. I tried to reboot and it wouldn't shut down. I had to hold the power button for a lot longer than usual to get it to shut down. :wacko: I'll wait for your next instructions before I touch it. Goodnight.
OK, skip the gmer scan.


Scan with Malwarebytes Anti-Rootkit

Please download Malwarebytes Anti-Rootkit from here Malwarebytes : Malwarebytes Anti-Rootkit and save it to your desktop.

Be sure to print out and follow the instructions provided on that same page.

Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.

  • Double click the mbar.zip file to open it, then 'Extract all files'.
  • Double click the mbar folder to open it, then double click mbar.exe to start the tool.
Check for Updates, then Scan your system for malware

If malware is found, do NOT press the Cleanup button yet. Click EXIT.

I'd like to see the log first so I can see what it sees. You'll find the log in that mbar folder as MBAR-log-[date and time]***.txt . Please attach that to your next reply.
:pullhair: :pullhair:

Tried to update Mbam 4-5 times in safe mode, reg mode, and even on another user and it will not update. Update failed: Timeout error.
I also had problems trying to backup with the Vista backup tool. It would not complete. Inserting the 3rd disc would make it freeze and everything on screen would disappear. It shut down and did a system repair. Tried it again and the same thing kept happening.
So today was filled with freezes, shut downs, and incomplete updates.

Oh I tried to load the Whatthetech website on Chrome on another user while in safe mode and this is the error I received:
"The webpage at http://www.whatthetech.com/ might be temporarily down or it may have moved permanently to a new web
address. Error 124 (net::ERR_WINSOCK_UNEXPECTED_WRITTEN_BYTES): Unknown error."

Now what should I do?
Who told you to run Malwarebytes Antimalware or do a system repair? We cannot help you if you don´t follow our instructions. did you try to run Malwarebytes Antirootkit as well?
I'm sorry I meant mbar (malwarebytes antirootkit) , NOT mbam. Everything I spoke about was in reference to malwarebytes antirootkit. Sorry, I'll be more careful. In regards to the system repair, the computer rebooted to it and I thought what I hit was to exit it, but it began to repair. I was afraid to try and stop it or shut it down. I'll be more careful in the future. Is there a reason it won't update or am I doing something wrong? Let me know what to do next.
Scan with TDSS-Killer

Please read and follow these instructions carefully. We do not want it to fix anything yet (if found), we need to see a report first.

Download TDSSKiller.exe and save it to your desktop
  • Execute TDSSKiller.exe by doubleclicking on it.
  • Press Start Scan
  • If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
  • Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

Please post the contents of that log in your next reply.




Scan with aswMBR


Please download aswMBR.exe to your desktop.

  • Double-click the aswMBR.exe to run it
  • When prompted with The application can use the Avast! Free Antivirus for scanning >> select No
  • Now click on the Scan button to start scan
  • On completion of the scan click Save Log, save it to your desktop and post the contents in your next reply
Note: There will also be a file on your desktop named MBR.dat(or similir) do not delete this for now it is a actual backup of the MBR(master boot record).
Hi!

TDSS log

00:19:04.0248 0992 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
00:19:04.0284 0992 ============================================================
00:19:04.0284 0992 Current date / time: 2013/08/11 00:19:04.0284
00:19:04.0284 0992 SystemInfo:
00:19:04.0284 0992
00:19:04.0284 0992 OS Version: 6.0.6002 ServicePack: 2.0
00:19:04.0284 0992 Product type: Workstation
00:19:04.0284 0992 ComputerName: GOGO
00:19:04.0284 0992 UserName: gogo
00:19:04.0284 0992 Windows directory: C:\Windows
00:19:04.0284 0992 System windows directory: C:\Windows
00:19:04.0284 0992 Processor architecture: Intel x86
00:19:04.0284 0992 Number of processors: 2
00:19:04.0284 0992 Page size: 0x1000
00:19:04.0284 0992 Boot type: Normal boot
00:19:04.0284 0992 ============================================================
00:19:06.0574 0992 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x13135, SectorsPerTrack: 0x3F, TracksPerCylinder: 0x7F, Type 'K0', Flags 0x00000050
00:19:06.0595 0992 ============================================================
00:19:06.0595 0992 \Device\Harddisk0\DR0:
00:19:06.0598 0992 MBR partitions:
00:19:06.0598 0992 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x23E55000
00:19:06.0598 0992 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x23E55800, BlocksNum 0x15D7800
00:19:06.0598 0992 ============================================================
00:19:06.0698 0992 C: <-> \Device\Harddisk0\DR0\Partition1
00:19:06.0782 0992 D: <-> \Device\Harddisk0\DR0\Partition2
00:19:06.0782 0992 ============================================================
00:19:06.0782 0992 Initialize success
00:19:06.0782 0992 ============================================================
00:19:10.0646 5404 ============================================================
00:19:10.0647 5404 Scan started
00:19:10.0647 5404 Mode: Manual;
00:19:10.0647 5404 ============================================================
00:19:11.0873 5404 ================ Scan system memory ========================
00:19:11.0874 5404 System memory - ok
00:19:11.0877 5404 ================ Scan services =============================
00:19:12.0574 5404 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
00:19:12.0578 5404 ACPI - ok
00:19:12.0696 5404 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
00:19:12.0698 5404 AdobeARMservice - ok
00:19:12.0857 5404 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
00:19:12.0863 5404 AdobeFlashPlayerUpdateSvc - ok
00:19:12.0903 5404 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
00:19:12.0921 5404 adp94xx - ok
00:19:12.0942 5404 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
00:19:12.0948 5404 adpahci - ok
00:19:12.0956 5404 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
00:19:12.0958 5404 adpu160m - ok
00:19:12.0969 5404 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
00:19:12.0972 5404 adpu320 - ok
00:19:13.0049 5404 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
00:19:13.0050 5404 AeLookupSvc - ok
00:19:13.0127 5404 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
00:19:13.0133 5404 AFD - ok
00:19:13.0178 5404 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
00:19:13.0180 5404 agp440 - ok
00:19:13.0235 5404 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
00:19:13.0251 5404 aic78xx - ok
00:19:13.0272 5404 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
00:19:13.0274 5404 ALG - ok
00:19:13.0285 5404 [ 3D76FDA1A10ACC3DC84728F55C29B6D4 ] aliide C:\Windows\system32\drivers\aliide.sys
00:19:13.0286 5404 aliide - ok
00:19:13.0301 5404 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
00:19:13.0303 5404 amdagp - ok
00:19:13.0310 5404 [ 5B92E7839F5A1FBC1B39DE67758AD6F8 ] amdide C:\Windows\system32\drivers\amdide.sys
00:19:13.0311 5404 amdide - ok
00:19:13.0331 5404 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
00:19:13.0333 5404 AmdK7 - ok
00:19:13.0368 5404 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
00:19:13.0370 5404 AmdK8 - ok
00:19:13.0418 5404 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
00:19:13.0419 5404 Appinfo - ok
00:19:13.0573 5404 [ 4B5AE15E5C73EB4DC8DBEC2788230D41 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
00:19:13.0586 5404 Apple Mobile Device - ok
00:19:13.0639 5404 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
00:19:13.0640 5404 arc - ok
00:19:13.0664 5404 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
00:19:13.0665 5404 arcsas - ok
00:19:13.0775 5404 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
00:19:13.0788 5404 aspnet_state - ok
00:19:13.0810 5404 [ BE1F39FD61852D31B1E99B2DA23A3693 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
00:19:13.0811 5404 aswFsBlk - ok
00:19:13.0857 5404 [ E2FEE0486D68BF85355D3EDA1A24FF68 ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
00:19:13.0858 5404 aswKbd - ok
00:19:13.0946 5404 [ 5A46BB2BEB3FC1385D56EFD8B57FB537 ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
00:19:13.0947 5404 aswMonFlt - ok
00:19:13.0958 5404 [ 52183BC3CAC3DCCCF571CC9C955741AA ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
00:19:13.0959 5404 aswRdr - ok
00:19:14.0009 5404 [ C4FE2A34CC7CBDF93446768CA7AC8180 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
00:19:14.0010 5404 aswRvrt - ok
00:19:14.0098 5404 [ 020CD9DFC85F753C84629D07EB9A16BA ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
00:19:14.0108 5404 aswSnx - ok
00:19:14.0205 5404 [ 2B427BAF48952868ECE8DE6A0AC2E85B ] aswSP C:\Windows\system32\drivers\aswSP.sys
00:19:14.0211 5404 aswSP - ok
00:19:14.0290 5404 [ 636B4D118926A135654118CDBB8B399D ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
00:19:14.0291 5404 aswTdi - ok
00:19:14.0397 5404 [ E81608EF25709525A236F3A3E03855EB ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
00:19:14.0491 5404 aswVmm - ok
00:19:14.0619 5404 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
00:19:14.0644 5404 AsyncMac - ok
00:19:14.0706 5404 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
00:19:14.0707 5404 atapi - ok
00:19:15.0050 5404 [ 8AEFD56986964BBAE02B790971F2ABAF ] athr C:\Windows\system32\DRIVERS\athr.sys
00:19:15.0411 5404 athr - ok
00:19:15.0593 5404 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
00:19:15.0599 5404 AudioEndpointBuilder - ok
00:19:15.0668 5404 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
00:19:15.0674 5404 Audiosrv - ok
00:19:15.0735 5404 [ 87425709A251386064C99B684BF96F72 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
00:19:15.0736 5404 avgntflt - ok
00:19:15.0778 5404 [ D50FBA68163BC498F2C136E0E5BA8E2F ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
00:19:15.0780 5404 avipbb - ok
00:19:15.0865 5404 [ CB8741CD7B126499FED40C9B197F6AC5 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
00:19:15.0867 5404 avkmgr - ok
00:19:16.0105 5404 [ A2494901E7226B356B8C1005C45F1C5F ] BBSvc C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.exe
00:19:16.0111 5404 BBSvc - ok
00:19:16.0184 5404 [ 63B1CBBAE4790B5BAC98F01BF9449722 ] BBUpdate C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe
00:19:16.0189 5404 BBUpdate - ok
00:19:16.0231 5404 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
00:19:16.0232 5404 Beep - ok
00:19:16.0328 5404 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
00:19:16.0333 5404 BFE - ok
00:19:16.0386 5404 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\System32\qmgr.dll
00:19:16.0398 5404 BITS - ok
00:19:16.0428 5404 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
00:19:16.0442 5404 blbdrive - ok
00:19:16.0525 5404 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
00:19:16.0526 5404 Bonjour Service - ok
00:19:16.0565 5404 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
00:19:16.0566 5404 bowser - ok
00:19:16.0612 5404 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
00:19:16.0613 5404 BrFiltLo - ok
00:19:16.0670 5404 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
00:19:16.0686 5404 BrFiltUp - ok
00:19:16.0721 5404 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
00:19:16.0723 5404 Browser - ok
00:19:16.0777 5404 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
00:19:16.0779 5404 Brserid - ok
00:19:16.0796 5404 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
00:19:16.0797 5404 BrSerWdm - ok
00:19:16.0808 5404 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
00:19:16.0810 5404 BrUsbMdm - ok
00:19:16.0824 5404 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
00:19:16.0825 5404 BrUsbSer - ok
00:19:16.0853 5404 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
00:19:16.0854 5404 BTHMODEM - ok
00:19:16.0889 5404 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
00:19:16.0890 5404 cdfs - ok
00:19:16.0934 5404 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
00:19:16.0936 5404 cdrom - ok
00:19:17.0009 5404 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
00:19:17.0011 5404 CertPropSvc - ok
00:19:17.0034 5404 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
00:19:17.0035 5404 circlass - ok
00:19:17.0069 5404 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
00:19:17.0072 5404 CLFS - ok
00:19:17.0132 5404 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
00:19:17.0137 5404 clr_optimization_v2.0.50727_32 - ok
00:19:17.0279 5404 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
00:19:17.0291 5404 clr_optimization_v4.0.30319_32 - ok
00:19:17.0336 5404 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
00:19:17.0337 5404 CmBatt - ok
00:19:17.0347 5404 [ D36372A6EA6805EFBE8884D10772313F ] cmdide C:\Windows\system32\drivers\cmdide.sys
00:19:17.0348 5404 cmdide - ok
00:19:17.0407 5404 [ DDA0CB141150FEF87419926790CD26C8 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT32.sys
00:19:17.0412 5404 CnxtHdAudService - ok
00:19:17.0461 5404 [ 7795F8CEBC284A426B53F541E538695F ] Com4QLBEx C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
00:19:17.0463 5404 Com4QLBEx - ok
00:19:17.0469 5404 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
00:19:17.0470 5404 Compbatt - ok
00:19:17.0478 5404 COMSysApp - ok
00:19:17.0488 5404 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
00:19:17.0489 5404 crcdisk - ok
00:19:17.0511 5404 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
00:19:17.0526 5404 Crusoe - ok
00:19:17.0574 5404 [ 3EDE4C1F9672C972479201544969ADCB ] CryptSvc C:\Windows\system32\cryptsvc.dll
00:19:17.0577 5404 CryptSvc - ok
00:19:17.0649 5404 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
00:19:17.0670 5404 DcomLaunch - ok
00:19:17.0700 5404 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
00:19:17.0702 5404 DfsC - ok
00:19:17.0832 5404 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
00:19:17.0874 5404 DFSR - ok
00:19:17.0948 5404 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
00:19:17.0955 5404 Dhcp - ok
00:19:18.0006 5404 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
00:19:18.0008 5404 disk - ok
00:19:18.0055 5404 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
00:19:18.0058 5404 Dnscache - ok
00:19:18.0142 5404 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
00:19:18.0147 5404 dot3svc - ok
00:19:18.0209 5404 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
00:19:18.0212 5404 DPS - ok
00:19:18.0270 5404 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
00:19:18.0284 5404 drmkaud - ok
00:19:18.0321 5404 [ 5DE0FAEC9E5D1AAE74F8568897891A01 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
00:19:18.0330 5404 DXGKrnl - ok
00:19:18.0381 5404 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
00:19:18.0397 5404 E1G60 - ok
00:19:18.0440 5404 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
00:19:18.0443 5404 EapHost - ok
00:19:18.0488 5404 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
00:19:18.0507 5404 Ecache - ok
00:19:18.0655 5404 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
00:19:18.0661 5404 ehRecvr - ok
00:19:18.0685 5404 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
00:19:18.0688 5404 ehSched - ok
00:19:18.0701 5404 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
00:19:18.0703 5404 ehstart - ok
00:19:18.0759 5404 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
00:19:18.0768 5404 elxstor - ok
00:19:18.0869 5404 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
00:19:18.0880 5404 EMDMgmt - ok
00:19:18.0988 5404 [ ABDD5AD016AFFD34AD40E944CE94BF59 ] EpsonBidirectionalService C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
00:19:18.0990 5404 EpsonBidirectionalService - ok
00:19:19.0155 5404 [ CF5DD6219185B18F7F8D8CE0142FD13F ] EpsonCustomerParticipation C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
00:19:19.0185 5404 EpsonCustomerParticipation - ok
00:19:19.0226 5404 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
00:19:19.0228 5404 ErrDev - ok
00:19:19.0371 5404 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
00:19:19.0423 5404 EventSystem - ok
00:19:19.0487 5404 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
00:19:19.0490 5404 exfat - ok
00:19:19.0537 5404 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
00:19:19.0548 5404 fastfat - ok
00:19:19.0589 5404 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
00:19:19.0590 5404 fdc - ok
00:19:19.0627 5404 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
00:19:19.0628 5404 fdPHost - ok
00:19:19.0645 5404 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
00:19:19.0646 5404 FDResPub - ok
00:19:19.0732 5404 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
00:19:19.0734 5404 FileInfo - ok
00:19:19.0749 5404 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
00:19:19.0751 5404 Filetrace - ok
00:19:19.0765 5404 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
00:19:19.0766 5404 flpydisk - ok
00:19:19.0829 5404 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
00:19:19.0868 5404 FltMgr - ok
00:19:20.0066 5404 [ 119ACA7CADCA75BEA6B38E999443BAA6 ] FontCache C:\Windows\system32\FntCache.dll
00:19:20.0086 5404 FontCache - ok
00:19:20.0160 5404 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
00:19:20.0165 5404 FontCache3.0.0.0 - ok
00:19:20.0230 5404 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
00:19:20.0248 5404 Fs_Rec - ok
00:19:20.0278 5404 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
00:19:20.0295 5404 gagp30kx - ok
00:19:20.0344 5404 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
00:19:20.0345 5404 GEARAspiWDM - ok
00:19:20.0510 5404 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
00:19:20.0544 5404 gpsvc - ok
00:19:20.0683 5404 [ F02A533F517EB38333CB12A9E8963773 ] gupdate1ce11e97cd4f97c C:\Program Files\Google\Update\GoogleUpdate.exe
00:19:20.0684 5404 gupdate1ce11e97cd4f97c - ok
00:19:20.0708 5404 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
00:19:20.0709 5404 gupdatem - ok
00:19:20.0782 5404 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
00:19:20.0784 5404 gusvc - ok
00:19:20.0853 5404 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
00:19:20.0857 5404 HdAudAddService - ok
00:19:20.0894 5404 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
00:19:20.0899 5404 HDAudBus - ok
00:19:20.0918 5404 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
00:19:20.0919 5404 HidBth - ok
00:19:20.0945 5404 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
00:19:20.0946 5404 HidIr - ok
00:19:21.0024 5404 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
00:19:21.0025 5404 hidserv - ok
00:19:21.0095 5404 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
00:19:21.0115 5404 HidUsb - ok
00:19:21.0270 5404 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
00:19:21.0291 5404 hkmsvc - ok
00:19:21.0461 5404 [ A19B0BB5A7EB6DF2DD4A0711D36955EE ] HP Health Check Service c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
00:19:21.0484 5404 HP Health Check Service - ok
00:19:21.0511 5404 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
00:19:21.0513 5404 HpCISSs - ok
00:19:21.0539 5404 [ 35956140E686D53BF676CF0C778880FC ] HpqKbFiltr C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
00:19:21.0540 5404 HpqKbFiltr - ok
00:19:21.0583 5404 [ 1665C7121A026DF10C903DB9BC5E9D43 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
00:19:21.0584 5404 hpqwmiex - ok
00:19:21.0819 5404 [ CC267848CB3508E72762BE65734E764D ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
00:19:21.0883 5404 HSF_DPV - ok
00:19:21.0936 5404 [ A2882945CC4B6E3E4E9E825590438888 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
00:19:21.0977 5404 HSXHWAZL - ok
00:19:22.0081 5404 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
00:19:22.0128 5404 HTTP - ok
00:19:22.0245 5404 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
00:19:22.0246 5404 i2omp - ok
00:19:22.0431 5404 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
00:19:22.0468 5404 i8042prt - ok
00:19:22.0542 5404 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
00:19:22.0547 5404 iaStorV - ok
00:19:22.0683 5404 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
00:19:22.0686 5404 IDriverT - ok
00:19:22.0798 5404 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
00:19:22.0838 5404 idsvc - ok
00:19:23.0875 5404 [ DCE0B53570703CCE580D066F89EF58CD ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
00:19:24.0872 5404 igfx - ok
00:19:24.0915 5404 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
00:19:24.0932 5404 iirsp - ok
00:19:25.0012 5404 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll
00:19:25.0039 5404 IKEEXT - ok
00:19:25.0111 5404 [ C7E7E43CBD34D3B0A0156B51B917DFCC ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys
00:19:25.0114 5404 IntcHdmiAddService - ok
00:19:25.0207 5404 [ DD512A049BD7B4BCE8A83554C5EFF2C1 ] intelide C:\Windows\system32\drivers\intelide.sys
00:19:25.0208 5404 intelide - ok
00:19:25.0277 5404 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
00:19:25.0278 5404 intelppm - ok
00:19:25.0404 5404 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
00:19:25.0408 5404 IPBusEnum - ok
00:19:25.0458 5404 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
00:19:25.0460 5404 IpFilterDriver - ok
00:19:25.0524 5404 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
00:19:25.0547 5404 iphlpsvc - ok
00:19:25.0555 5404 IpInIp - ok
00:19:25.0620 5404 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
00:19:25.0623 5404 IPMIDRV - ok
00:19:25.0661 5404 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
00:19:25.0692 5404 IPNAT - ok
00:19:25.0899 5404 [ 7A3611564FCE7C8BE50B03F58CB3EB7D ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
00:19:25.0927 5404 iPod Service - ok
00:19:25.0978 5404 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
00:19:25.0980 5404 IRENUM - ok
00:19:26.0004 5404 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
00:19:26.0006 5404 isapnp - ok
00:19:26.0083 5404 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
00:19:26.0086 5404 iScsiPrt - ok
00:19:26.0104 5404 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
00:19:26.0105 5404 iteatapi - ok
00:19:26.0180 5404 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
00:19:26.0203 5404 iteraid - ok
00:19:26.0239 5404 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
00:19:26.0240 5404 kbdclass - ok
00:19:26.0333 5404 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
00:19:26.0335 5404 kbdhid - ok
00:19:26.0397 5404 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
00:19:26.0401 5404 KeyIso - ok
00:19:26.0473 5404 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
00:19:26.0482 5404 KSecDD - ok
00:19:26.0550 5404 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
00:19:26.0559 5404 KtmRm - ok
00:19:26.0631 5404 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
00:19:26.0646 5404 LanmanServer - ok
00:19:26.0743 5404 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
00:19:26.0749 5404 LanmanWorkstation - ok
00:19:26.0860 5404 [ ABF90FC5A127F481219B873C1B8DFC1C ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
00:19:26.0862 5404 LightScribeService - ok
00:19:26.0919 5404 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
00:19:26.0921 5404 lltdio - ok
00:19:26.0991 5404 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
00:19:27.0010 5404 lltdsvc - ok
00:19:27.0080 5404 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
00:19:27.0083 5404 lmhosts - ok
00:19:27.0124 5404 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
00:19:27.0159 5404 LSI_FC - ok
00:19:27.0204 5404 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
00:19:27.0206 5404 LSI_SAS - ok
00:19:27.0247 5404 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
00:19:27.0249 5404 LSI_SCSI - ok
00:19:27.0296 5404 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
00:19:27.0298 5404 luafv - ok
00:19:27.0397 5404 [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy C:\Windows\system32\drivers\mbamswissarmy.sys
00:19:27.0399 5404 MBAMSwissArmy - ok
00:19:27.0503 5404 McAfee SiteAdvisor Service - ok
00:19:27.0577 5404 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
00:19:27.0655 5404 Mcx2Svc - ok
00:19:27.0704 5404 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
00:19:27.0706 5404 mdmxsdk - ok
00:19:27.0804 5404 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
00:19:27.0805 5404 megasas - ok
00:19:28.0203 5404 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
00:19:28.0230 5404 MegaSR - ok
00:19:28.0275 5404 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
00:19:28.0279 5404 MMCSS - ok
00:19:28.0321 5404 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
00:19:28.0324 5404 Modem - ok
00:19:28.0377 5404 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
00:19:28.0379 5404 monitor - ok
00:19:28.0419 5404 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
00:19:28.0420 5404 mouclass - ok
00:19:28.0445 5404 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
00:19:28.0446 5404 mouhid - ok
00:19:28.0507 5404 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
00:19:28.0509 5404 MountMgr - ok
00:19:28.0591 5404 [ ADE67764E0E2F3592D4D059B69FD02C0 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
00:19:28.0595 5404 MozillaMaintenance - ok
00:19:28.0667 5404 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
00:19:28.0672 5404 MpFilter - ok
00:19:28.0737 5404 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
00:19:28.0740 5404 mpio - ok
00:19:28.0770 5404 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
00:19:28.0774 5404 mpsdrv - ok
00:19:28.0825 5404 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
00:19:28.0834 5404 MpsSvc - ok
00:19:28.0904 5404 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
00:19:28.0958 5404 Mraid35x - ok
00:19:29.0006 5404 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
00:19:29.0047 5404 MRxDAV - ok
00:19:29.0075 5404 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
00:19:29.0078 5404 mrxsmb - ok
00:19:29.0173 5404 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
00:19:29.0178 5404 mrxsmb10 - ok
00:19:29.0251 5404 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
00:19:29.0271 5404 mrxsmb20 - ok
00:19:29.0359 5404 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
00:19:29.0360 5404 msahci - ok
00:19:29.0446 5404 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
00:19:29.0474 5404 msdsm - ok
00:19:29.0522 5404 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
00:19:29.0554 5404 MSDTC - ok
00:19:29.0601 5404 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
00:19:29.0603 5404 Msfs - ok
00:19:29.0691 5404 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
00:19:29.0692 5404 msisadrv - ok
00:19:29.0768 5404 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
00:19:29.0773 5404 MSiSCSI - ok
00:19:29.0784 5404 msiserver - ok
00:19:29.0887 5404 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
00:19:29.0913 5404 MSKSSRV - ok
00:19:30.0131 5404 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
00:19:30.0132 5404 MsMpSvc - ok
00:19:30.0212 5404 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
00:19:30.0214 5404 MSPCLOCK - ok
00:19:30.0242 5404 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
00:19:30.0244 5404 MSPQM - ok
00:19:30.0306 5404 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
00:19:30.0310 5404 MsRPC - ok
00:19:30.0359 5404 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
00:19:30.0361 5404 mssmbios - ok
00:19:30.0423 5404 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
00:19:30.0425 5404 MSTEE - ok
00:19:30.0470 5404 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
00:19:30.0472 5404 Mup - ok
00:19:30.0589 5404 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
00:19:30.0603 5404 napagent - ok
00:19:30.0679 5404 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
00:19:30.0699 5404 NativeWifiP - ok
00:19:30.0798 5404 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
00:19:30.0826 5404 NDIS - ok
00:19:30.0897 5404 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
00:19:30.0899 5404 NdisTapi - ok
00:19:30.0945 5404 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
00:19:30.0947 5404 Ndisuio - ok
00:19:30.0978 5404 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
00:19:30.0982 5404 NdisWan - ok
00:19:31.0023 5404 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
00:19:31.0048 5404 NDProxy - ok
00:19:31.0087 5404 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
00:19:31.0089 5404 NetBIOS - ok
00:19:31.0232 5404 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
00:19:31.0236 5404 netbt - ok
00:19:31.0264 5404 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
00:19:31.0267 5404 Netlogon - ok
00:19:31.0376 5404 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
00:19:31.0405 5404 Netman - ok
00:19:31.0465 5404 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
00:19:31.0468 5404 NetMsmqActivator - ok
00:19:31.0481 5404 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
00:19:31.0482 5404 NetPipeActivator - ok
00:19:31.0515 5404 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
00:19:31.0520 5404 netprofm - ok
00:19:31.0545 5404 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
00:19:31.0547 5404 NetTcpActivator - ok
00:19:31.0556 5404 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing c:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
00:19:31.0558 5404 NetTcpPortSharing - ok
00:19:31.0942 5404 [ 35D5458D9A1B26B2005ABFFBF4C1C5E7 ] NETw3v32 C:\Windows\system32\DRIVERS\NETw3v32.sys
00:19:32.0084 5404 NETw3v32 - ok
00:19:32.0126 5404 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
00:19:32.0131 5404 nfrd960 - ok
00:19:32.0276 5404 [ 832E098BCA8235436FE2D8AE50AC3718 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
00:19:32.0278 5404 NisDrv - ok
00:19:32.0367 5404 [ E570ECA850F30EB740C2E9699DF3D2BD ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
00:19:32.0370 5404 NisSrv - ok
00:19:32.0455 5404 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
00:19:32.0462 5404 NlaSvc - ok
00:19:32.0516 5404 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
00:19:32.0518 5404 Npfs - ok
00:19:32.0550 5404 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
00:19:32.0554 5404 nsi - ok
00:19:32.0605 5404 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
00:19:32.0607 5404 nsiproxy - ok
00:19:32.0761 5404 [ 2C1121F2B87E9A6B12485DF53CD848C7 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
00:19:32.0811 5404 Ntfs - ok
00:19:32.0848 5404 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
00:19:32.0852 5404 ntrigdigi - ok
00:19:32.0920 5404 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
00:19:32.0922 5404 Null - ok
00:19:32.0965 5404 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
00:19:32.0968 5404 nvraid - ok
00:19:33.0018 5404 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
00:19:33.0020 5404 nvstor - ok
00:19:33.0064 5404 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
00:19:33.0068 5404 nv_agp - ok
00:19:33.0074 5404 NwlnkFlt - ok
00:19:33.0083 5404 NwlnkFwd - ok
00:19:33.0562 5404 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
00:19:33.0680 5404 odserv - ok
00:19:33.0761 5404 [ 790E27C3DB53410B40FF9EF2FD10A1D9 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
00:19:33.0763 5404 ohci1394 - ok
00:19:33.0825 5404 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
00:19:33.0829 5404 ose - ok
00:19:33.0921 5404 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
00:19:33.0952 5404 p2pimsvc - ok
00:19:33.0976 5404 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
00:19:33.0987 5404 p2psvc - ok
00:19:34.0028 5404 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
00:19:34.0048 5404 Parport - ok
00:19:34.0094 5404 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
00:19:34.0096 5404 partmgr - ok
00:19:34.0165 5404 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
00:19:34.0168 5404 Parvdm - ok
00:19:34.0230 5404 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
00:19:34.0234 5404 PcaSvc - ok
00:19:34.0291 5404 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
00:19:34.0294 5404 pci - ok
00:19:34.0363 5404 [ 1D8B3D8DF8EB7FCF2F0AC02F9F947802 ] pciide C:\Windows\system32\drivers\pciide.sys
00:19:34.0364 5404 pciide - ok
00:19:34.0453 5404 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
00:19:34.0479 5404 pcmcia - ok
00:19:34.0604 5404 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
00:19:34.0667 5404 PEAUTH - ok
00:19:34.0958 5404 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
00:19:35.0036 5404 pla - ok
00:19:35.0119 5404 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
00:19:35.0131 5404 PlugPlay - ok
00:19:35.0241 5404 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
00:19:35.0251 5404 PNRPAutoReg - ok
00:19:35.0267 5404 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
00:19:35.0276 5404 PNRPsvc - ok
00:19:35.0322 5404 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
00:19:35.0328 5404 PolicyAgent - ok
00:19:35.0370 5404 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
00:19:35.0372 5404 PptpMiniport - ok
00:19:35.0420 5404 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
00:19:35.0422 5404 Processor - ok
00:19:35.0484 5404 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
00:19:35.0490 5404 ProfSvc - ok
00:19:35.0542 5404 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
00:19:35.0545 5404 ProtectedStorage - ok
00:19:35.0590 5404 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
00:19:35.0591 5404 PSched - ok
00:19:35.0677 5404 [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
00:19:35.0705 5404 PxHelp20 - ok
00:19:35.0952 5404 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
00:19:36.0053 5404 ql2300 - ok
00:19:36.0073 5404 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
00:19:36.0077 5404 ql40xx - ok
00:19:36.0136 5404 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
00:19:36.0164 5404 QWAVE - ok
00:19:36.0215 5404 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
00:19:36.0218 5404 QWAVEdrv - ok
00:19:36.0321 5404 [ 70DBDAB246C18B78E2200D6401D038BE ] RapiMgr C:\Windows\WindowsMobile\rapimgr.dll
00:19:36.0335 5404 RapiMgr - ok
00:19:36.0382 5404 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
00:19:36.0384 5404 RasAcd - ok
00:19:36.0407 5404 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
00:19:36.0414 5404 RasAuto - ok
00:19:36.0434 5404 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
00:19:36.0438 5404 Rasl2tp - ok
00:19:36.0478 5404 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
00:19:36.0499 5404 RasMan - ok
00:19:36.0540 5404 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
00:19:36.0542 5404 RasPppoe - ok
00:19:36.0556 5404 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
00:19:36.0560 5404 RasSstp - ok
00:19:36.0619 5404 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
00:19:36.0625 5404 rdbss - ok
00:19:36.0654 5404 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
00:19:36.0657 5404 RDPCDD - ok
00:19:36.0697 5404 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
00:19:36.0703 5404 rdpdr - ok
00:19:36.0732 5404 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
00:19:36.0734 5404 RDPENCDD - ok
00:19:36.0822 5404 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
00:19:36.0844 5404 RDPWD - ok
00:19:37.0108 5404 [ 0D362785BEF9BDF5A6E1F4628D06716D ] Recovery Service for Windows C:\Program Files\SMINST\BLService.exe
00:19:37.0110 5404 Recovery Service for Windows - ok
00:19:37.0247 5404 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
00:19:37.0278 5404 RemoteAccess - ok
00:19:37.0344 5404 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
00:19:37.0366 5404 RemoteRegistry - ok
00:19:37.0506 5404 [ B9BB8E2093C1615AD6EA55AD96214354 ] Revoflt C:\Windows\system32\DRIVERS\revoflt.sys
00:19:37.0525 5404 Revoflt - ok
00:19:37.0699 5404 [ 805AE1F90C64758D19AAA001CF8CBA12 ] RichVideo C:\Program Files\CyberLink\Shared files\RichVideo.exe
00:19:37.0731 5404 RichVideo - ok
00:19:37.0878 5404 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
00:19:37.0906 5404 RpcLocator - ok
00:19:38.0049 5404 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\System32\rpcss.dll
00:19:38.0060 5404 RpcSs - ok
00:19:38.0098 5404 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
00:19:38.0130 5404 rspndr - ok
00:19:38.0240 5404 [ D6FAE13AFACEF23A6471D23284B8A164 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys
00:19:38.0266 5404 RTL8169 - ok
00:19:38.0331 5404 [ D1FB9A678BD6C2B1129FCB09D5FEB6DD ] RTSTOR C:\Windows\system32\drivers\RTSTOR.SYS
00:19:38.0356 5404 RTSTOR - ok
00:19:38.0398 5404 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
00:19:38.0403 5404 SamSs - ok
00:19:38.0455 5404 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
00:19:38.0487 5404 sbp2port - ok
00:19:38.0573 5404 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
00:19:38.0599 5404 SCardSvr - ok
00:19:38.0772 5404 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
00:19:38.0828 5404 Schedule - ok
00:19:38.0866 5404 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
00:19:38.0867 5404 SCPolicySvc - ok
00:19:38.0971 5404 [ 126EA89BCC413EE45E3004FB0764888F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
00:19:38.0974 5404 sdbus - ok
00:19:39.0059 5404 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
00:19:39.0091 5404 SDRSVC - ok
00:19:39.0890 5404 [ 206387AB881E93A1A6EB89966C8651F1 ] SDScannerService C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
00:19:39.0903 5404 SDScannerService - ok
00:19:40.0264 5404 [ A529CFE32565C0B145578FFB2B32C9A5 ] SDUpdateService C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
00:19:40.0279 5404 SDUpdateService - ok
00:19:40.0366 5404 [ CB63BDB77BB86549FC3303C2F11EDC18 ] SDWSCService C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
00:19:40.0369 5404 SDWSCService - ok
00:19:40.0444 5404 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
00:19:40.0445 5404 secdrv - ok
00:19:40.0509 5404 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
00:19:40.0513 5404 seclogon - ok
00:19:40.0583 5404 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
00:19:40.0587 5404 SENS - ok
00:19:40.0650 5404 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
00:19:40.0673 5404 Serenum - ok
00:19:40.0773 5404 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
00:19:40.0822 5404 Serial - ok
00:19:40.0890 5404 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
00:19:40.0911 5404 sermouse - ok
00:19:40.0969 5404 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
00:19:40.0974 5404 SessionEnv - ok
00:19:41.0050 5404 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
00:19:41.0051 5404 sffdisk - ok
00:19:41.0140 5404 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
00:19:41.0145 5404 sffp_mmc - ok
00:19:41.0225 5404 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
00:19:41.0246 5404 sffp_sd - ok
00:19:41.0283 5404 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
00:19:41.0302 5404 sfloppy - ok
00:19:41.0401 5404 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
00:19:41.0447 5404 SharedAccess - ok
00:19:41.0593 5404 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
00:19:41.0619 5404 ShellHWDetection - ok
00:19:41.0709 5404 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
00:19:41.0742 5404 sisagp - ok
00:19:41.0813 5404 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
00:19:41.0818 5404 SiSRaid2 - ok
00:19:41.0908 5404 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
00:19:41.0910 5404 SiSRaid4 - ok
00:19:42.0270 5404 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
00:19:42.0299 5404 SkypeUpdate - ok
00:19:42.0986 5404 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
00:19:43.0329 5404 slsvc - ok
00:19:43.0410 5404 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
00:19:43.0422 5404 SLUINotify - ok
00:19:43.0511 5404 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
00:19:43.0549 5404 Smb - ok
00:19:43.0604 5404 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
00:19:43.0608 5404 SNMPTRAP - ok
00:19:43.0682 5404 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
00:19:43.0683 5404 spldr - ok
00:19:43.0771 5404 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
00:19:43.0776 5404 Spooler - ok
00:19:44.0213 5404 [ 3EED76A0C1412F52860F7E7EAB5AECCA ] SRS_AE_Service C:\Windows\system32\drivers\SRS_AE_i386.sys
00:19:44.0698 5404 SRS_AE_Service - ok
00:19:44.0877 5404 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
00:19:44.0947 5404 srv - ok
00:19:45.0045 5404 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
00:19:45.0049 5404 srv2 - ok
00:19:45.0125 5404 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
00:19:45.0128 5404 srvnet - ok
00:19:45.0292 5404 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
00:19:45.0298 5404 SSDPSRV - ok
00:19:45.0431 5404 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys
00:19:45.0433 5404 ssmdrv - ok
00:19:45.0532 5404 [ F87737D83B965EFA765117051E3B9D0C ] ssrangdr C:\Windows\system32\DRIVERS\ssrangdr.sys
00:19:45.0566 5404 ssrangdr - ok
00:19:45.0678 5404 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
00:19:45.0727 5404 SstpSvc - ok
00:19:46.0052 5404 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
00:19:46.0264 5404 stisvc - ok
00:19:46.0360 5404 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
00:19:46.0361 5404 swenum - ok
00:19:46.0589 5404 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
00:19:46.0596 5404 swprv - ok
00:19:46.0665 5404 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
00:19:46.0684 5404 Symc8xx - ok
00:19:46.0720 5404 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
00:19:46.0721 5404 Sym_hi - ok
00:19:46.0780 5404 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
00:19:46.0782 5404 Sym_u3 - ok
00:19:46.0913 5404 [ 00B19F27858F56181EDB58B71A7C67A0 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
00:19:46.0916 5404 SynTP - ok
00:19:47.0236 5404 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
00:19:47.0276 5404 SysMain - ok
00:19:47.0372 5404 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
00:19:47.0376 5404 TabletInputService - ok
00:19:47.0455 5404 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
00:19:47.0462 5404 TapiSrv - ok
00:19:47.0598 5404 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
00:19:47.0619 5404 TBS - ok
00:19:47.0844 5404 [ 078218D74C4EFC2CE7E4C6DF22A94F2F ] Tcpip C:\Windows\system32\drivers\tcpip.sys
00:19:47.0855 5404 Tcpip - ok
00:19:48.0095 5404 [ 078218D74C4EFC2CE7E4C6DF22A94F2F ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
00:19:48.0108 5404 Tcpip6 - ok
00:19:48.0192 5404 [ 4C11A1820DDC37FA653913AD680ACCAE ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
00:19:48.0193 5404 tcpipreg - ok
00:19:48.0286 5404 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
00:19:48.0302 5404 TDPIPE - ok
00:19:48.0341 5404 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
00:19:48.0365 5404 TDTCP - ok
00:19:48.0429 5404 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
00:19:48.0470 5404 tdx - ok
00:19:48.0584 5404 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
00:19:48.0585 5404 TermDD - ok
00:19:48.0866 5404 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
00:19:48.0950 5404 TermService - ok
00:19:48.0997 5404 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
00:19:49.0004 5404 Themes - ok
00:19:49.0076 5404 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
00:19:49.0079 5404 THREADORDER - ok
00:19:49.0201 5404 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
00:19:49.0253 5404 TrkWks - ok
00:19:49.0434 5404 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
00:19:49.0435 5404 TrustedInstaller - ok
00:19:49.0519 5404 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
00:19:49.0538 5404 tssecsrv - ok
00:19:49.0637 5404 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
00:19:49.0748 5404 tunmp - ok
00:19:49.0947 5404 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
00:19:49.0990 5404 tunnel - ok
00:19:50.0084 5404 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
00:19:50.0235 5404 uagp35 - ok
00:19:50.0564 5404 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
00:19:50.0768 5404 udfs - ok
00:19:50.0925 5404 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
00:19:50.0950 5404 UI0Detect - ok
00:19:51.0055 5404 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
00:19:51.0082 5404 uliagpkx - ok
00:19:51.0167 5404 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
00:19:51.0203 5404 uliahci - ok
00:19:51.0221 5404 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
00:19:51.0238 5404 UlSata - ok
00:19:51.0299 5404 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
00:19:51.0333 5404 ulsata2 - ok
00:19:51.0377 5404 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
00:19:51.0397 5404 umbus - ok
00:19:51.0519 5404 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
00:19:51.0567 5404 upnphost - ok
00:19:51.0663 5404 [ 1DF89C499BF45D878B87EBD4421D462D ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
00:19:51.0679 5404 USBAAPL - ok
00:19:51.0764 5404 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
00:19:51.0767 5404 usbccgp - ok
00:19:51.0883 5404 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
00:19:51.0903 5404 usbcir - ok
00:19:52.0032 5404 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
00:19:52.0073 5404 usbehci - ok
00:19:52.0298 5404 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
00:19:52.0349 5404 usbhub - ok
00:19:52.0434 5404 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
00:19:52.0484 5404 usbohci - ok
00:19:52.0539 5404 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys
00:19:52.0598 5404 usbprint - ok
00:19:52.0670 5404 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
00:19:52.0692 5404 USBSTOR - ok
00:19:52.0727 5404 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
00:19:52.0750 5404 usbuhci - ok
00:19:52.0877 5404 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
00:19:52.0932 5404 usbvideo - ok
00:19:53.0030 5404 [ 228F444F9AF0D3B9ECA9FC3F4FEB12F2 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
00:19:53.0032 5404 usb_rndisx - ok
00:19:53.0108 5404 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
00:19:53.0113 5404 UxSms - ok
00:19:53.0342 5404 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
00:19:53.0441 5404 vds - ok
00:19:53.0485 5404 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
00:19:53.0487 5404 vga - ok
00:19:53.0556 5404 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
00:19:53.0558 5404 VgaSave - ok
00:19:53.0589 5404 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
00:19:53.0713 5404 viaagp - ok
00:19:53.0773 5404 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
00:19:53.0817 5404 ViaC7 - ok
00:19:53.0855 5404 [ EA1AA6E3ABB3C194FEBA12A46DE8CF2C ] viaide C:\Windows\system32\drivers\viaide.sys
00:19:53.0856 5404 viaide - ok
00:19:53.0945 5404 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
00:19:53.0967 5404 volmgr - ok
00:19:54.0142 5404 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
00:19:54.0309 5404 volmgrx - ok
00:19:54.0497 5404 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
00:19:54.0557 5404 volsnap - ok
00:19:54.0639 5404 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
00:19:54.0673 5404 vsmraid - ok
00:19:55.0152 5404 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
00:19:55.0190 5404 VSS - ok
00:19:55.0446 5404 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
00:19:55.0454 5404 W32Time - ok
00:19:55.0485 5404 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
00:19:55.0507 5404 WacomPen - ok
00:19:55.0544 5404 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
00:19:55.0565 5404 Wanarp - ok
00:19:55.0572 5404 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
00:19:55.0574 5404 Wanarpv6 - ok
00:19:55.0747 5404 [ 779F9C90D3FE9C70B6FFD8EF035F3E83 ] WcesComm C:\Windows\WindowsMobile\wcescomm.dll
00:19:55.0894 5404 WcesComm - ok
00:19:56.0084 5404 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
00:19:56.0116 5404 wcncsvc - ok
00:19:56.0195 5404 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
00:19:56.0221 5404 WcsPlugInService - ok
00:19:56.0281 5404 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
00:19:56.0282 5404 Wd - ok
00:19:56.0539 5404 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
00:19:56.0579 5404 Wdf01000 - ok
00:19:56.0621 5404 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
00:19:56.0626 5404 WdiServiceHost - ok
00:19:56.0644 5404 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
00:19:56.0649 5404 WdiSystemHost - ok
00:19:56.0769 5404 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
00:19:56.0785 5404 WebClient - ok
00:19:56.0892 5404 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
00:19:56.0925 5404 Wecsvc - ok
00:19:57.0013 5404 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
00:19:57.0021 5404 wercplsupport - ok
00:19:57.0111 5404 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
00:19:57.0116 5404 WerSvc - ok
00:19:57.0455 5404 [ 0ACD399F5DB3DF1B58903CF4949AB5A8 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
00:19:57.0558 5404 winachsf - ok
00:19:57.0829 5404 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
00:19:57.0937 5404 WinDefend - ok
00:19:57.0949 5404 WinHttpAutoProxySvc - ok
00:19:58.0102 5404 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
00:19:58.0105 5404 Winmgmt - ok
00:19:58.0179 5404 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
00:19:58.0247 5404 WinRM - ok
00:19:58.0337 5404 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
00:19:58.0369 5404 Wlansvc - ok
00:19:58.0505 5404 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
00:19:58.0535 5404 wlidsvc - ok
00:19:58.0603 5404 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
00:19:58.0605 5404 WmiAcpi - ok
00:19:58.0714 5404 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
00:19:58.0758 5404 wmiApSrv - ok
00:19:58.0986 5404 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
00:19:59.0034 5404 WMPNetworkSvc - ok
00:19:59.0065 5404 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
00:19:59.0107 5404 WPCSvc - ok
00:19:59.0204 5404 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
00:19:59.0209 5404 WPDBusEnum - ok
00:19:59.0387 5404 [ B800EEC15851597405784126C407188C ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
00:19:59.0413 5404 WPFFontCache_v0400 - ok
00:19:59.0471 5404 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
00:19:59.0473 5404 ws2ifsl - ok
00:19:59.0545 5404 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
00:19:59.0550 5404 wscsvc - ok
00:19:59.0625 5404 [ 4422AC5ED8D4C2F0DB63E71D4C069DD7 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
00:19:59.0627 5404 WSDPrintDevice - ok
00:19:59.0669 5404 [ 65D1FF8AAFF4A7D8F787A290E5087816 ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
00:19:59.0671 5404 WSDScan - ok
00:19:59.0678 5404 WSearch - ok
00:19:59.0849 5404 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
00:19:59.0990 5404 wuauserv - ok
00:20:00.0066 5404 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
00:20:00.0068 5404 WudfPf - ok
00:20:00.0119 5404 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
00:20:00.0131 5404 WUDFRd - ok
00:20:00.0192 5404 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
00:20:00.0220 5404 wudfsvc - ok
00:20:00.0275 5404 [ DAB33CFA9DD24251AAA389FF36B64D4B ] XAudio C:\Windows\system32\DRIVERS\xaudio.sys
00:20:00.0276 5404 XAudio - ok
00:20:00.0389 5404 [ CD5F291A1161F15896D1A4D63DAFF5DF ] XAudioService C:\Windows\system32\DRIVERS\xaudio.exe
00:20:00.0394 5404 XAudioService - ok
00:20:00.0560 5404 [ 9EEA6D029FEF5F3016D089B1A603837D ] xnacc C:\Windows\system32\DRIVERS\xnacc.sys
00:20:00.0581 5404 xnacc - ok
00:20:00.0678 5404 [ 7D1F3B131D503EF43EE594B5A2B9B427 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
00:20:00.0683 5404 yukonwlh - ok
00:20:00.0755 5404 ================ Scan global ===============================
00:20:00.0812 5404 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
00:20:00.0928 5404 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
00:20:01.0041 5404 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
00:20:01.0132 5404 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe
00:20:01.0139 5404 [Global] - ok
00:20:01.0139 5404 ================ Scan MBR ==================================
00:20:01.0187 5404 [ 588AE8F0C685C02BA11F30D9CD7E61A0 ] \Device\Harddisk0\DR0
00:20:01.0729 5404 \Device\Harddisk0\DR0 - ok
00:20:01.0730 5404 ================ Scan VBR ==================================
00:20:01.0745 5404 [ 6BFA14D23CEA50F3EC57851D16B87537 ] \Device\Harddisk0\DR0\Partition1
00:20:01.0758 5404 \Device\Harddisk0\DR0\Partition1 - ok
00:20:01.0792 5404 [ 8716D012B86C5BFEDF709070834DD6EA ] \Device\Harddisk0\DR0\Partition2
00:20:01.0794 5404 \Device\Harddisk0\DR0\Partition2 - ok
00:20:01.0799 5404 ============================================================
00:20:01.0799 5404 Scan finished
00:20:01.0799 5404 ============================================================
00:20:01.0816 5420 Detected object count: 0
00:20:01.0816 5420 Actual detected object count: 0

—————————————————————————————————————————————————————————————————————————————————————-
aswMBR log

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-08-11 00:38:51
—————————–
00:38:51.226 OS Version: Windows 6.0.6002 Service Pack 2
00:38:51.226 Number of processors: 2 586 0x170A
00:38:51.227 ComputerName: GOGO UserName: gogo
00:38:53.477 Initialize success
00:39:42.299 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
00:39:42.302 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OCA0G Size: 305245MB BusType: 3
00:39:42.500 Disk 0 MBR read successfully
00:39:42.503 Disk 0 MBR scan
00:39:42.506 Disk 0 unknown MBR code
00:39:42.545 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 294058 MB offset 2048
00:39:42.591 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 11183 MB offset 602232832
00:39:42.632 Disk 0 scanning sectors +625135616
00:39:42.672 Disk 0 scanning C:\Windows\system32\drivers
00:40:13.363 Service scanning
00:40:35.384 Modules scanning
00:40:51.585 Disk 0 trace - called modules:
00:40:51.622 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys
00:40:51.627 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86847ac8]
00:40:51.634 3 CLASSPNP.SYS[832098b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x866aab98]
00:40:51.639 Scan finished successfully
00:41:29.360 Disk 0 MBR has been saved successfully to "C:\Users\gogo\Desktop\MBR.dat"
00:41:29.368 The log file has been saved successfully to "C:\Users\gogo\Desktop\aswMBR.txt"
Combofix

Combofix should only be run when adviced by a team member!

Link


Important - Save the file to your desktop!


  • Deactivate any and all of your antivirus programs /spyware scanners - they can prevent CF from doing its work.
  • Run Combofix.exe

When finished, Combofix creates a log file named C:\Combofix.txt. Please post its content in your next reply.

Note: When receiving an error message containing ""Illegal operation attempted on a registry key that has been marked for deletion" simply restart your computer to fix this.
Hi- Here is the combofix log:


ComboFix 13-08-12.01 - gogo 08/12/2013 22:38:09.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1869 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Spybot - Search and Destroy *Disabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-07-13 to 2013-08-13 )))))))))))))))))))))))))))))))
.
.
2013-08-13 05:48 . 2013-08-13 05:48 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-08-13 05:48 . 2013-08-13 05:48 ——– d—–w- c:\users\Kids\AppData\Local\temp
2013-08-13 05:48 . 2013-08-13 05:49 ——– d—–w- c:\users\gogo\AppData\Local\temp
2013-08-13 05:48 . 2013-08-13 05:48 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-08-13 05:48 . 2013-08-13 05:48 ——– d—–w- c:\users\Daisy\AppData\Local\temp
2013-08-11 07:36 . 2013-06-12 04:18 7068072 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B476184F-E39D-4FF8-AD2D-6C96A628E011}\mpengine.dll
2013-08-06 21:26 . 2013-08-06 21:26 103680 —-a-w- C:\pxldqpog.sys
2013-08-04 20:39 . 2013-08-04 20:39 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2013-08-04 09:43 . 2013-08-04 09:38 698504 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{72BB2389-E65F-46AB-AD2C-74F75EA33E4E}\gapaengine.dll
2013-08-04 09:33 . 2013-04-15 14:20 638328 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-04 09:33 . 2013-04-13 10:56 37376 —-a-w- c:\windows\system32\cdd.dll
2013-08-01 10:39 . 2013-06-12 04:18 7068072 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-07-31 18:52 . 2013-07-31 18:52 ——– d—–w- c:\users\Kids\AppData\Roaming\.technic
2013-07-30 19:36 . 2013-07-30 19:37 ——– d—–w- c:\program files\Mozilla Firefox(79)
2013-07-28 10:48 . 2013-07-28 10:48 ——– d—–w- c:\program files\Bandizip
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-04 03:55 . 2013-07-04 03:55 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-07-04 03:55 . 2012-06-18 20:41 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-07-04 03:55 . 2010-05-15 03:59 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-06-21 02:33 . 2013-05-21 02:29 724464 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2013-06-18 05:02 . 2013-05-14 05:31 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-18 05:02 . 2013-05-14 05:31 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-04 01:50 . 2013-07-11 18:22 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-06-01 04:06 . 2013-07-11 18:17 505344 —-a-w- c:\windows\system32\qedit.dll
2013-05-29 01:50 . 2013-07-13 00:28 1800704 —-a-w- c:\windows\system32\jscript9.dll
2013-05-29 01:41 . 2013-07-13 00:28 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2013-05-29 01:41 . 2013-07-13 00:28 1129472 —-a-w- c:\windows\system32\wininet.dll
2013-05-29 01:37 . 2013-07-13 00:28 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2013-05-29 01:36 . 2013-07-13 00:28 420864 —-a-w- c:\windows\system32\vbscript.dll
2013-05-29 01:33 . 2013-07-13 00:28 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-09-02 21:03 . 2011-11-26 00:15 730192 —-a-w- c:\program files\Common Files\ZugoInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\users\gogo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\users\gogo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-11-13 23:32 129272 —-a-w- c:\users\gogo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-20 39408]
"Facebook Update"="c:\users\gogo\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2013-06-23 138096]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2010-10-12 979328]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 137752]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 172568]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
c:\users\Daisy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2009-2-26 97680]
.
c:\users\gogo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote Table Of Contents.onetoc2 [2011-12-24 3656]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^DFX.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\DFX.lnk
backup=c:\windows\pss\DFX.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^gogo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
path=c:\users\gogo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
backup=c:\windows\pss\Dropbox.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^gogo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\gogo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06 958576 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-10-12 05:56 59280 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-21 02:25 125952 —-a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2008-10-09 14:58 75008 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2008-09-30 23:56 972080 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2008-04-15 21:51 488752 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-13 00:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 17:16 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTCM Client]
2009-08-05 17:36 1596096 —-a-w- c:\program files\LTCM Client\ltcmClient.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2008-09-24 00:21 468264 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-10-25 11:12 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
2012-11-13 21:08 3825176 —-a-w- c:\program files\Spybot - Search & Destroy 2\SDTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 14:32 253816 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-20 16:54 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-04-17 18:05 1049896 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2008-11-15 05:02 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateLBPShortCut]
2008-06-14 01:11 210216 ——w- c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GoShortCut]
2008-06-14 01:11 210216 ——w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePDIRShortCut]
2008-06-14 01:11 210216 ——w- c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePSTShortCut]
2008-10-07 03:42 210216 ——w- c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 —-a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-07-02 07:38 1165776 —-a-w- c:\program files\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-18 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-14 05:02]
.
2013-08-13 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2013-05-14 21:08]
.
2013-06-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-90010376-98873278-4205430638-1000Core.job
- c:\users\gogo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-23 04:59]
.
2013-06-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-90010376-98873278-4205430638-1000UA.job
- c:\users\gogo\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-23 04:59]
.
2013-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-31 18:19]
.
2013-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-31 18:19]
.
2013-08-13 c:\windows\Tasks\HPCeeScheduleForKids.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2009-04-20 18:34]
.
2013-07-03 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2013-05-14 21:07]
.
2013-05-14 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2013-05-14 21:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
LSP: c:\windows\system32\wpclsp.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\gogo\AppData\Roaming\Mozilla\Firefox\Profiles\1qnmbpub.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
Notify-SDWinLogon - SDWinLogon.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 - c:\program files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-08-12 22:49
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3516)
c:\users\gogo\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
.
Completion time: 2013-08-12 22:53:19
ComboFix-quarantined-files.txt 2013-08-13 05:53
.
Pre-Run: 162,792,099,840 bytes free
Post-Run: 164,782,845,952 bytes free
.
- - End Of File - - 08C1E2A4CF90F8AAA7208BFEE12A0ED2
588AE8F0C685C02BA11F30D9CD7E61A0



Thank you.
Hi-I have not been using the computer while we have been fixing this issue, so I'm not sure if there still are any problems. I will get on it and do some things and test it out. I will get back to you later on tonight or tomorrow with an update. Thank you.
:thumbup: Everything seems good so far. I had only a few issues: Microsoft Security Essentials updated just fine and Windows Update completed all but 4 updates. I kept getting error messages on them, an unknown issue it said. I tried to load Firefox, but an error massage saying Firefox "couldnt load XPCOM" came up. It still seems alittle slow, both the internet (could be our mi-fi) and also doing other things on the computer (example: opening the control panel and doing anything in it). When I started it there was a long lag and the screen was black, right before the microsoft pic came up. All the icons on the screen were white and took awhile to load. I didnt notice any of the old browser problems though. Thank You :woot: Whats next?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI