This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop running very slow! [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop with Win 7 Home Premium lately runs very slow. I wonder if it was infected. OTL scan was done.

OTL.txt
OTL logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS

Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Google\Drive\googledrivesync.exe (Google)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
PRC - C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe (Google Inc.)
PRC - C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
PRC - C:\Users\Kevin\AppData\Local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
PRC - C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Modules (No Company Name) ==========

MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_elementtree.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32api.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_socket.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32ts.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._gdi_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32com.shell.shell.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._html2.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_multiprocessing.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32profile.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32crypt.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._misc_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pythoncom27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ctypes.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._core_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\PyWinTypes27.dll ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32security.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_ssl.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._windows_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\_hashlib.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._wizard.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32process.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32pdh.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32file.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32inet.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\wx._controls_.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\pyexpat.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\win32event.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\unicodedata.pyd ()
MOD - C:\Users\Kevin\AppData\Local\Temp\_MEI29882\select.pyd ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libglesv2.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\libegl.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll ()
MOD - C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()


========== Services (SafeList) ==========

SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (swi_service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (swi_update) – C:\ProgramData\Sophos\Web Intelligence\swi_update.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (SAVService) – C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (Sophos AutoUpdate Service) – C:\Program Files\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (Sophos Web Control Service) – C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos Limited)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (eRecoveryService) – C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (Acer Inc.)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)


========== Driver Services (SafeList) ==========

DRV - (SAVOnAccess) – C:\Windows\System32\drivers\savonaccess.sys (Sophos Limited)
DRV - (SKMScan) – C:\Windows\System32\drivers\skmscan.sys (Sophos Limited)
DRV - (sdcfilter) – C:\Windows\System32\drivers\sdcfilter.sys (Sophos Limited)
DRV - (SophosBootDriver) – C:\Windows\System32\drivers\SophosBootDriver.sys (Sophos Plc)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (int15) – C:\Acer\Empowering Technology\eRecovery\int15.sys ()
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SEARCH PAGE = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {73546C17-705F-4776-96EF-A483F8695E63}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{73546C17-705F-4776-96EF-A483F8695E63}: "URL" = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)



========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.62\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - Extension: Google Docs = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Unblock Youku = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnfnkhpgegpcingjbfihlkjeighnddk\2.6.7.3_0\
CHR - Extension: Gmail = C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKCU..\Run: [8CB61047070556905AB7FB604CF2473F5483F0D5._service_run] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll (Sophos Limited)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183}: DhcpNameServer = 192.168.2.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\Acer02.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/30 00:00:54 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:12:17 | 000,000,000 | —D | C] – C:\Windows\Panther
[2013/08/29 09:47:12 | 000,000,000 | —D | C] – C:\Windows\System32\MRT
[2013/08/29 09:22:22 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:00:11 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/08/29 07:46:39 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/08/29 07:46:38 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/08/29 07:46:21 | 000,040,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wwanprotdim.dll
[2013/08/29 07:46:14 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cryptdlg.dll
[2013/08/29 07:45:54 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certutil.exe
[2013/08/29 07:45:52 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\certenc.dll
[2013/08/29 07:45:07 | 000,509,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qedit.dll
[2013/08/29 07:45:01 | 002,347,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/08/29 07:44:57 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2013/08/29 07:44:18 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/08/29 07:44:06 | 000,218,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2013/08/29 07:23:36 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2013/08/29 07:22:49 | 000,000,000 | —D | C] – C:\Users\Kevin\AppData\Local\Wajam
[2013/08/29 07:22:17 | 000,000,000 | —D | C] – C:\Program Files\Wajam
[2013/08/29 07:19:34 | 000,894,600 | —- | C] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/30 00:07:19 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[2013/08/29 22:17:51 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:17:50 | 000,010,048 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/29 22:13:22 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/29 22:11:06 | 000,410,200 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/08/29 22:10:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/08/29 09:56:53 | 000,624,178 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/08/29 09:56:53 | 000,106,522 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/08/29 09:22:22 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MsSpellCheckingFacility.exe
[2013/08/29 09:22:22 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\elshyph.dll
[2013/08/29 09:22:21 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2013/08/29 09:22:21 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2013/08/29 09:22:21 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2013/08/29 09:22:21 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2013/08/29 09:22:21 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/08/29 09:22:20 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/08/29 09:22:20 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/08/29 09:22:20 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2013/08/29 09:22:20 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2013/08/29 09:22:20 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/08/29 09:22:20 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/08/29 09:22:20 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2013/08/29 09:22:20 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2013/08/29 09:22:19 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/08/29 09:22:19 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/08/29 09:22:19 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2013/08/29 09:22:19 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2013/08/29 09:22:19 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2013/08/29 09:22:19 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2013/08/29 09:22:19 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2013/08/29 09:22:19 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2013/08/29 09:22:18 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2013/08/29 09:22:18 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/08/29 09:22:18 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmlmedia.dll
[2013/08/29 09:22:18 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/08/29 09:22:18 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/08/29 09:22:18 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2013/08/29 09:22:18 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/08/29 09:22:18 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/08/29 09:22:18 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2013/08/29 09:22:18 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2013/08/29 09:22:18 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2013/08/29 09:22:18 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2013/08/29 09:22:18 | 000,025,185 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 09:22:18 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2013/08/29 09:20:24 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/08/29 09:20:23 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2013/08/29 09:20:23 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msmpeg2vdec.dll
[2013/08/29 09:20:23 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2013/08/29 09:20:23 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2013/08/29 09:20:23 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2013/08/29 09:20:23 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10.dll
[2013/08/29 09:20:23 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10level9.dll
[2013/08/29 09:20:23 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMPhoto.dll
[2013/08/29 09:20:23 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2013/08/29 09:20:23 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxgi.dll
[2013/08/29 09:20:23 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2013/08/29 09:20:23 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10core.dll
[2013/08/29 09:20:23 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/08/29 09:20:23 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2013/08/29 09:20:23 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/08/29 09:20:23 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/08/29 09:20:23 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/08/29 09:20:23 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/08/29 09:20:22 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\Windows\System32\UIAnimation.dll
[2013/08/29 09:18:04 | 001,505,280 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d11.dll
[2013/08/29 08:42:54 | 000,002,133 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/08/07 04:22:04 | 000,238,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/29 09:22:18 | 000,025,185 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2013/08/29 07:22:16 | 000,000,000 | —- | C] () – C:\end
[2013/01/17 00:11:05 | 000,000,142 | —- | C] () – C:\Windows\ODBC.INI
[2013/01/16 22:56:39 | 000,021,316 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2013/01/15 18:41:25 | 000,016,384 | —- | C] () – C:\Windows\System32\LauncheRyAgentUser.exe
[2013/01/15 18:41:25 | 000,016,384 | —- | C] ( ) – C:\Windows\System32\ClearEvent.exe
[2013/01/15 18:38:45 | 000,000,000 | —- | C] () – C:\Windows\SETUP.INI
[2013/01/15 18:04:26 | 000,000,092 | —- | C] () – C:\Windows\CLEANUP.INI

========== ZeroAccess Check ==========

[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 05:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 18:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Acer
[2013/08/29 07:23:36 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\addpcs
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\GetRightToGo
[2013/01/16 22:52:43 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Leadertech
[2013/04/08 19:53:19 | 000,000,000 | —D | M] – C:\Users\Kevin\AppData\Roaming\Thinstall

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 19:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 14:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/25 22:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 05:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/24 22:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 19:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/04/23 20:34:47 | 000,138,668 | —- | M] () MD5=1C6962D48032784C1213726F6304D2D8 – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.ZIP >
[2006/03/06 22:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2013/07/24 19:48:45 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=139C8953AC56A9E559C7DEF07BC45ED7 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20613_none_b1cc6e48e11fccf7\iexplore.exe
[2013/02/21 21:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_b104f0edc83023b1\iexplore.exe
[2013/02/21 21:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_b183bdcce155df6c\iexplore.exe
[2013/07/24 19:42:37 | 000,757,400 | —- | M] (Microsoft Corporation) MD5=57EC630DBD5F0713E77CB3540AB80A8E – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16502_none_b14ca11fc7faf7e5\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_b10dc045c829d512\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/08/29 09:22:21 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_ba6aa26e65e05c0d\iexplore.exe
[2013/01/17 19:57:30 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2013/02/01 21:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_b17dbc10e15b4762\iexplore.exe
[2012/11/16 09:33:24 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=B201AF83DF2E85323E29EB83E4046810 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_b11b910fc81f0526\iexplore.exe
[2012/11/15 20:08:47 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=C0BA71C1B3FB6E3DD432FF3CCAEBDC62 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_b1985d5ae1468e33\iexplore.exe
[2013/02/01 21:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_b0feef31c8358ba7\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_b18b8cdae1507776\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2013/01/17 19:57:31 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/08/29 09:22:22 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_b41defe19d893548\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-38CD2DC9.PF >
[2013/08/29 09:17:11 | 000,019,784 | —- | M] () MD5=BC920AF9249F2D6B6FAB1F03B390DF53 – C:\Windows\Prefetch\IEXPLORE.EXE-38CD2DC9.pf

< MD5 for: SERVICES >
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 14:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.CFG >
[2012/09/23 20:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 03:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 18:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 19:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 21:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 14:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 19:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 13:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 19:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 05:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 05:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/04/17 18:40:24 | 000,009,906 | —- | M] () MD5=F39F9262475CC1DACD8C1A0AE95B9EAC – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf

< MD5 for: WINLOGON.MFL >
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 19:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 13:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2007/01/14 04:28:55 | 000,003,269 | —- | M] () – C:\-20070114.log
[2013/01/15 22:02:23 | 000,004,621 | —- | M] () – C:\-20130115.log
[2007/01/14 04:16:30 | 000,000,166 | —- | M] () – C:\Arcade.log
[2009/06/10 14:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010/11/20 05:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2013/01/16 23:44:04 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009/06/10 14:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2013/08/29 07:22:46 | 000,000,000 | —- | M] () – C:\end
[2013/08/29 22:10:03 | 1200,230,400 | -HS- | M] () – C:\hiberfil.sys
[2013/01/15 21:57:12 | 000,000,379 | —- | M] () – C:\MDR.log
[2013/08/29 22:10:09 | 1600,311,296 | -HS- | M] () – C:\pagefile.sys
[2007/01/14 04:05:26 | 000,000,284 | —- | M] () – C:\RHDSetup.log
[2007/01/14 04:19:44 | 000,000,178 | —- | M] () – C:\setup.log

< %systemroot%\Fonts\*.com >
[2009/07/13 21:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 14:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 18:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 05:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 1099-6666
Directory of C:\
07/13/2009 09:53 PM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/13/2009 09:53 PM All Users [C:\ProgramData]
07/13/2009 09:53 PM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/13/2009 09:53 PM Application Data [C:\ProgramData]
07/13/2009 09:53 PM Desktop [C:\Users\Public\Desktop]
07/13/2009 09:53 PM Documents [C:\Users\Public\Documents]
07/13/2009 09:53 PM Favorites [C:\Users\Public\Favorites]
07/13/2009 09:53 PM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Roaming]
07/13/2009 09:53 PM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/13/2009 09:53 PM Local Settings [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM My Documents [C:\Users\Default\Documents]
07/13/2009 09:53 PM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/13/2009 09:53 PM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/13/2009 09:53 PM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/13/2009 09:53 PM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/13/2009 09:53 PM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/13/2009 09:53 PM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/13/2009 09:53 PM Application Data [C:\Users\Default\AppData\Local]
07/13/2009 09:53 PM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/13/2009 09:53 PM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/13/2009 09:53 PM My Music [C:\Users\Default\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Default\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Kevin
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Roaming]
01/16/2013 10:49 PM Cookies [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Cookies]
01/16/2013 10:49 PM Local Settings [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM My Documents [C:\Users\Kevin\Documents]
01/16/2013 10:49 PM NetHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/16/2013 10:49 PM PrintHood [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/16/2013 10:49 PM Recent [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Recent]
01/16/2013 10:49 PM SendTo [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\SendTo]
01/16/2013 10:49 PM Start Menu [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu]
01/16/2013 10:49 PM Templates [C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\AppData\Local
01/16/2013 10:49 PM Application Data [C:\Users\Kevin\AppData\Local]
01/16/2013 10:49 PM History [C:\Users\Kevin\AppData\Local\Microsoft\Windows\History]
01/16/2013 10:49 PM Temporary Internet Files [C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Kevin\Documents
01/16/2013 10:49 PM My Music [C:\Users\Kevin\Music]
01/16/2013 10:49 PM My Pictures [C:\Users\Kevin\Pictures]
01/16/2013 10:49 PM My Videos [C:\Users\Kevin\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/13/2009 09:53 PM My Music [C:\Users\Public\Music]
07/13/2009 09:53 PM My Pictures [C:\Users\Public\Pictures]
07/13/2009 09:53 PM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
50 Dir(s) 48,410,677,248 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/01/15 21:47:09 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2013/01/17 22:20:12 | 000,000,221 | -HS- | M] () – C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/08/29 07:19:56 | 000,894,600 | —- | M] (CNET Download.com) – C:\Users\Kevin\Desktop\cbsidlm-cbsi134-Temp_File_Cleaner-SEO-10628816.exe
[2013/01/17 22:25:13 | 015,075,864 | —- | M] (Google Inc.) – C:\Users\Kevin\Desktop\GooglePinyinInstaller.exe
[2013/08/30 00:01:03 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Kevin\Desktop\OTL.exe
[1 C:\Users\Kevin\Desktop\*.tmp files -> C:\Users\Kevin\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-08-29 17:00:35

< End of report >

Extras.txt
OTL Extras logfile created on: 8/30/2013 12:05:04 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Kevin\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.49 Gb Total Physical Memory | 0.49 Gb Available Physical Memory | 32.96% Memory free
2.98 Gb Paging File | 1.36 Gb Available in Paging File | 45.72% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 66.72 Gb Total Space | 43.81 Gb Free Space | 65.66% Space Free | Partition Type: NTFS

Computer Name: KEVIN-PC | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{07FB4F3C-16F4-4D73-831F-67A3259320FB}" = rport=10243 | protocol=6 | dir=out | app=system |
"{345EB324-CBAA-41E4-A9EE-36735F67C73D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{37D14B3C-0EB0-469F-8C70-48F4BB1AEE10}" = rport=138 | protocol=17 | dir=out | app=system |
"{3A66E8DD-B83A-4098-94B4-B14BD884AA40}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4814C0A6-9008-4058-8FBC-99E5E22165A0}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{5C9A0760-E75C-476B-910B-3E57905728E0}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5DCB5A67-A8A9-4384-BB41-6FC4B6E99321}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{613DB84B-2025-4AB9-91D1-D88DA95135BE}" = lport=445 | protocol=6 | dir=in | app=system |
"{65E62E7B-3C34-4957-BCDD-3608568C644A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{751880B3-6F3E-489D-BDEE-573AB2B7FE02}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7B551164-2206-4A4E-8407-1F9AF2EAE0CB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7F563466-66C7-41AB-9FAC-5CE99872A8EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{82BAB721-EF91-4C72-97C2-F68DD1ED5EE1}" = lport=2869 | protocol=6 | dir=in | app=system |
"{A73C8847-A1FE-42E4-82BE-2B58E5BFBAE7}" = lport=139 | protocol=6 | dir=in | app=system |
"{B6C48D16-CF82-47EC-96ED-E2283B392844}" = rport=445 | protocol=6 | dir=out | app=system |
"{BCB90625-1467-439C-86E5-32706856A469}" = rport=139 | protocol=6 | dir=out | app=system |
"{DAD893EB-0708-44D7-8C0C-F2FE2CCDA5DA}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13DCD54-A941-4599-97FF-59768EAC3BA0}" = rport=137 | protocol=17 | dir=out | app=system |
"{EAAD9CF1-3C05-4C4A-83C6-07C2250D89FA}" = lport=10243 | protocol=6 | dir=in | app=system |
"{ED381E7D-475B-46F4-BD00-0377D831005A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F6DE7578-F398-4588-9342-0FED7E46C659}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FAF4555C-6C69-4C2F-A5C3-6A9FE0CB38C0}" = lport=138 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0F1EDC1A-65BC-4629-9EC0-0BD77557C5CD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1753D194-856F-4AE0-9369-114E75CB72A6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19CB0346-D080-44C3-8010-00AFB02CAA96}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{229F06F9-0B42-46B1-BBD2-7C9CD1164FCA}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2C2B329B-5E01-4C3E-957C-03FF24040684}" = protocol=6 | dir=out | app=system |
"{564E4D93-0897-4A2C-966A-610B6241AC3C}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{6C9C30B9-77F6-42F1-A841-4DC026B157C1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6F543147-644B-4090-96C4-ACD0801D0D0E}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{9FFA5CC5-281A-497A-86E0-B41EA59E6CB9}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{B0822FCC-36A7-4949-9186-673B39CC08EB}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{B30C257D-FE0F-49C9-AAC7-B5CE9AEE32C6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BC1344E1-91F9-45FD-8187-F6B6710F915D}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{BD4B99DC-67A9-4E59-9F2F-03C2CB3259BA}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BFAFFB66-7EFE-4B5B-88A3-78775A820523}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{C562013B-E0D1-416E-B0BB-BE2A0A3E67C2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CC2E1F5A-2046-4AC7-99F9-B9458960979D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{D0BE4786-D665-44F7-A941-71861382C785}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{DEBD8B02-613F-42D1-82CC-16190AD99C51}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E6F108CE-BA19-496D-BCE3-FCBC82FF2905}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{F9486C25-8BD9-4002-B5ED-4109227DAC4C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = TIPCI
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{C2D4CD4A-AE20-40B3-8726-8ED1C03E8C15}" = Google Drive
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"GooglePinyin2" = 谷歌拼音输入法 2.7
"HDMI" = Intel® Graphics Media Accelerator Driver
"InstallShield_{0409969E-BEFB-44D3-90B9-63BE50FBAE5E}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"LManager" = Launch Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Wajam" = Wajam

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/15/2013 10:35:17 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 2/15/2013 10:35:18 AM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 2/15/2013 10:42:11 AM | Computer Name = Kevin-PC | Source = ESENT | ID = 215
Description = WinMail (2988) WindowsMail0: The backup has been stopped because it
was halted by the client or the connection with the client failed.

Error - 3/4/2013 11:49:55 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: ALMon.exe, version: 3.47.115.344, time
stamp: 0x50efe301 Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7b96f Exception code: 0xc0000005 Fault offset: 0x0003bc21 Faulting process
id: 0x8c4 Faulting application start time: 0x01ce195196b73bef Faulting application
path: C:\Program Files\Sophos\AutoUpdate\ALMon.exe Faulting module path: C:\Windows\system32\ole32.dll
Report
Id: bdcb2667-8547-11e2-a4e2-001636fab2c0

Error - 3/4/2013 11:52:27 PM | Computer Name = Kevin-PC | Source = VSS | ID = 8194
Description =

Error - 3/5/2013 11:34:10 PM | Computer Name = Kevin-PC | Source = .NET Runtime Optimization Service | ID = 1107
Description =

Error - 3/24/2013 6:46:31 PM | Computer Name = Kevin-PC | Source = Application Error | ID = 1000
Description = Faulting application name: googledrivesync.exe, version: 1.7.4018.3496,
time stamp: 0x509418e4 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec49b60 Exception code: 0xc0000005 Fault offset: 0x00052cc7 Faulting
process id: 0x948 Faulting application start time: 0x01ce28d6d4e034e5 Faulting application
path: C:\Program Files\Google\Drive\googledrivesync.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: ab5a1529-94d4-11e2-a07b-001636fab2c0

[ System Events ]
Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.

Error - 4/16/2013 1:03:40 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.6. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.

Error - 4/16/2013 1:48:12 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =

Error - 4/16/2013 4:59:21 PM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.

Error - 4/16/2013 4:59:22 PM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.

Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = Server | ID = 2505
Description = The server could not bind to the transport \Device\NetBT_Tcpip_{7EE4F889-FC71-4682-A73C-8AD7FF413183}
because another computer on the network has the same name. The server could not
start.

Error - 4/17/2013 1:07:53 AM | Computer Name = Kevin-PC | Source = NetBT | ID = 4321
Description = The name "KEVIN-PC :20" could not be registered on the interface
with IP address 192.168.2.4. The computer with the IP address 192.168.2.5 did not
allow the name to be claimed by this computer.

Error - 4/17/2013 2:48:01 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =

Error - 4/18/2013 12:40:17 AM | Computer Name = Kevin-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 6:39:43 PM on ?4/?17/?2013 was unexpected.

Error - 4/18/2013 1:08:41 PM | Computer Name = Kevin-PC | Source = bowser | ID = 8003
Description =


< End of report >
Hi and Welcome!!

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • If you happen to have a flash drive/thumb drive please have that ready in the event that we need to use it.
  • Please be sure to subscribe to the topic if you have not already done so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.


Having said that…. [external image: Posted Image] Let's get going!!
———-

Sorry for any delay. As you can see we are quite busy here and we appreciate your patience. :)
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any antivirus programs during the scan (If you have difficulty properly disabling your protective programs, refer to this link here )
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

[external image: Posted Image] Please download TDSSKiller
  • Double click TDSSKiller.exe
  • Press Start Scan but do nothing else as we are just looking for what is there.
  • If Malicious objects are found, select Skip by changing the Cure dropdown in the upper right.
  • Attach the log in your next reply
  • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
———-
Hi Jeff, thanks for your help!

DDS

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16660
Run by [removed] at 9:03:46 on 2013-09-05
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1526.268 [GMT -7:00]
.
AV: Sophos Anti-Virus *Disabled/Outdated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Sophos Anti-Virus *Disabled/Outdated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe
C:\Program Files\Google\Google Pinyin 2\GooglePinyinService.exe
C:\Program Files\Google\Update\1.3.21.153\GoogleCrashHandler.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\igfxext.exe
C:\Users\Kevin\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\ProgramData\Sophos\AutoUpdate\cache\sophos_autoupdate1.dir\alupdate.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://en.us.acer.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} -
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - c:\program files\wajam\ie\priam_bho.dll
uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [8CB61047070556905AB7FB604CF2473F5483F0D5._service_run] "c:\program files\google\chrome\application\chrome.exe" –type=service
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [LManager] c:\progra~1\launch~1\QtZgAcer.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Sophos AutoUpdate Monitor] c:\program files\sophos\autoupdate\almon.exe
StartupFolder: c:\users\kevin\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183} : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183}\1414D2C4F657E67656 : DHCPNameServer = [removed] [removed] [removed]
TCP: Interfaces\{7EE4F889-FC71-4682-A73C-8AD7FF413183}\247525F657E64686F6573756355796475637 : DHCPNameServer = [removed] [removed] 8.8.8.8
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs= c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\29.0.1547.62\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome
.
============= SERVICES / DRIVERS ===============
.
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
.
=============== Created Last 30 ================
.
2013-08-31 07:54:05 7166848 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{3f2fa4c8-d0b2-42dd-a6a1-2445eb14d8d9}\mpengine.dll
2013-08-31 05:11:26 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll
2013-08-31 05:11:06 1796096 —-a-w- c:\windows\system32\authui.dll
2013-08-31 05:11:06 101720 —-a-w- c:\windows\system32\consent.exe
2013-08-31 05:11:04 47104 —-a-w- c:\windows\system32\appinfo.dll
2013-08-30 05:30:30 1247744 —-a-w- c:\windows\system32\DWrite.dll
2013-08-30 05:12:17 ——– d—–w- c:\windows\Panther
2013-08-29 16:47:12 ——– d—–w- c:\windows\system32\MRT
2013-08-29 16:20:23 9728 —ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-08-29 16:18:04 1505280 —-a-w- c:\windows\system32\d3d11.dll
2013-08-29 14:48:08 1211752 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-08-29 14:47:56 652800 —-a-w- c:\windows\system32\rpcrt4.dll
2013-08-29 14:47:42 175104 —-a-w- c:\windows\system32\wintrust.dll
2013-08-29 14:47:42 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2013-08-29 14:47:42 1166848 —-a-w- c:\windows\system32\crypt32.dll
2013-08-29 14:47:42 103936 —-a-w- c:\windows\system32\cryptnet.dll
2013-08-29 14:46:39 3913664 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-08-29 14:46:38 3968960 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-08-29 14:46:37 1289096 —-a-w- c:\windows\system32\ntdll.dll
2013-08-29 14:46:22 186368 —-a-w- c:\windows\system32\wwansvc.dll
2013-08-29 14:46:21 40960 —-a-w- c:\windows\system32\wwanprotdim.dll
2013-08-29 14:46:14 24576 —-a-w- c:\windows\system32\cryptdlg.dll
2013-08-29 14:46:02 492544 —-a-w- c:\windows\system32\win32spl.dll
2013-08-29 14:45:54 903168 —-a-w- c:\windows\system32\certutil.exe
2013-08-29 14:45:52 43008 —-a-w- c:\windows\system32\certenc.dll
2013-08-29 14:45:13 1293760 —-a-w- c:\windows\system32\drivers\tcpip.sys
2013-08-29 14:45:07 509440 —-a-w- c:\windows\system32\qedit.dll
2013-08-29 14:45:01 2347520 —-a-w- c:\windows\system32\win32k.sys
2013-08-29 14:44:57 1620992 —-a-w- c:\windows\system32\WMVDECOD.DLL
2013-08-29 14:44:25 988672 —-a-w- c:\program files\windows journal\JNTFiltr.dll
2013-08-29 14:44:25 936448 —-a-w- c:\program files\common files\microsoft shared\ink\journal.dll
2013-08-29 14:44:24 969216 —-a-w- c:\program files\windows journal\JNWDRV.dll
2013-08-29 14:44:24 1221632 —-a-w- c:\program files\windows journal\NBDoc.DLL
2013-08-29 14:44:18 2048 —-a-w- c:\windows\system32\tzres.dll
2013-08-29 14:44:06 728424 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-08-29 14:44:06 218984 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-08-29 14:44:04 680960 —-a-w- c:\program files\windows defender\MpSvc.dll
2013-08-29 14:44:04 392704 —-a-w- c:\program files\windows defender\MpClient.dll
2013-08-29 14:44:03 224768 —-a-w- c:\program files\windows defender\MpCommu.dll
2013-08-29 14:43:27 31232 —-a-w- c:\windows\system32\drivers\tssecsrv.sys
2013-08-29 14:23:36 ——– d—–w- c:\users\kevin\appdata\roaming\addpcs
2013-08-29 14:22:49 ——– d—–w- c:\users\kevin\appdata\local\Wajam
2013-08-29 14:22:17 ——– d—–w- c:\program files\Wajam
.
==================== Find3M ====================
.
2013-08-29 16:20:24 4096 —ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-08-07 11:22:04 238872 ——w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 9:07:03.33 ===============

attach

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 1/16/2013 11:30:04 PM
System Uptime: 9/5/2013 8:52:25 AM (1 hours ago)
.
Motherboard: Acer, Inc. | | Prespa1
Processor: Intel® Celeron® M CPU 520 @ 1.60GHz | U2E1 | 1600/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 67 GiB total, 44.188 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP34: 4/22/2013 1:12:04 AM - Windows Update
RP35: 8/29/2013 7:08:12 AM - Windows Update
RP36: 8/29/2013 9:15:52 AM - Windows Update
RP37: 8/30/2013 12:08:55 AM - OTL Restore Point - 8/30/2013 12:08:50 AM
RP38: 8/30/2013 1:08:49 AM - Windows Update
RP39: 8/31/2013 12:51:17 AM - Windows Update
.
==== Installed Programs ======================
.
??????? 2.7
2007 Microsoft Office Suite Service Pack 2 (SP2)
Adobe Flash Player 9 ActiveX
Adobe Reader XI (11.0.03)
Agere Systems HDA Modem
Google Chrome
Google Drive
Google Update Helper
Intel® Graphics Media Accelerator Driver
Launch Manager
LightScribe 1.4.136.1
Microsoft .NET Framework 4 Client Profile
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2758694)
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Sophos Anti-Virus
Sophos AutoUpdate
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TIPCI
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Wajam
.
==== Event Viewer Messages From Past Week ========
.
8/31/2013 12:24:53 AM, Error: Service Control Manager [7034] - The Sophos Anti-Virus service terminated unexpectedly. It has done this 1 time(s).
8/31/2013 12:24:53 AM, Error: SAVOnAccess [37] - Driver threads still active when driver is being shutdown.
8/29/2013 9:45:28 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x8024200d: Security Update for Windows 7 (KB2835361).
8/29/2013 10:17:55 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 (KB2834140).
8/29/2013 10:17:55 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80242016: Cumulative Security Update for Internet Explorer 9 for Windows 7 (KB2862772).
.
==== End Of File ===========================

TDSS

09:16:35.0754 2524 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
09:16:36.0499 2524 ============================================================
09:16:36.0499 2524 Current date / time: 2013/09/05 09:16:36.0499
09:16:36.0500 2524 SystemInfo:
09:16:36.0500 2524
09:16:36.0500 2524 OS Version: 6.1.7601 ServicePack: 1.0
09:16:36.0500 2524 Product type: Workstation
09:16:36.0500 2524 ComputerName: KEVIN-PC
09:16:36.0500 2524 UserName: Kevin
09:16:36.0500 2524 Windows directory: C:\Windows
09:16:36.0500 2524 System windows directory: C:\Windows
09:16:36.0500 2524 Processor architecture: Intel x86
09:16:36.0500 2524 Number of processors: 1
09:16:36.0500 2524 Page size: 0x1000
09:16:36.0500 2524 Boot type: Normal boot
09:16:36.0500 2524 ============================================================
09:16:38.0514 2524 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
09:16:38.0517 2524 ============================================================
09:16:38.0517 2524 \Device\Harddisk0\DR0:
09:16:38.0547 2524 MBR partitions:
09:16:38.0548 2524 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x6, StartLBA 0xF9CA3B, BlocksNum 0x8571C57
09:16:38.0548 2524 ============================================================
09:16:38.0600 2524 C: <-> \Device\Harddisk0\DR0\Partition1
09:16:38.0836 2524 ============================================================
09:16:38.0837 2524 Initialize success
09:16:38.0837 2524 ============================================================
09:16:49.0350 4916 ============================================================
09:16:49.0350 4916 Scan started
09:16:49.0350 4916 Mode: Manual;
09:16:49.0350 4916 ============================================================
09:16:50.0601 4916 ================ Scan system memory ========================
09:16:50.0601 4916 System memory - ok
09:16:50.0606 4916 ================ Scan services =============================
09:16:50.0818 4916 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
09:16:50.0822 4916 1394ohci - ok
09:16:50.0884 4916 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
09:16:50.0900 4916 ACPI - ok
09:16:50.0954 4916 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
09:16:50.0955 4916 AcpiPmi - ok
09:16:51.0076 4916 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
09:16:51.0078 4916 AdobeARMservice - ok
09:16:51.0148 4916 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
09:16:51.0157 4916 adp94xx - ok
09:16:51.0205 4916 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
09:16:51.0212 4916 adpahci - ok
09:16:51.0250 4916 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
09:16:51.0254 4916 adpu320 - ok
09:16:51.0303 4916 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
09:16:51.0305 4916 AeLookupSvc - ok
09:16:51.0362 4916 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
09:16:51.0368 4916 AFD - ok
09:16:51.0423 4916 [ 39E435C90C9C4F780FA0ED05CA3C3A1B ] AgereModemAudio C:\Windows\system32\agrsmsvc.exe
09:16:51.0424 4916 AgereModemAudio - ok
09:16:51.0520 4916 [ 2E3ABAACBF547ABBB5E73A504A56D05A ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
09:16:51.0591 4916 AgereSoftModem - ok
09:16:51.0644 4916 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
09:16:51.0646 4916 agp440 - ok
09:16:51.0700 4916 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
09:16:51.0703 4916 aic78xx - ok
09:16:51.0785 4916 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
09:16:51.0787 4916 ALG - ok
09:16:51.0836 4916 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
09:16:51.0837 4916 aliide - ok
09:16:51.0863 4916 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
09:16:51.0865 4916 amdagp - ok
09:16:51.0918 4916 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
09:16:51.0919 4916 amdide - ok
09:16:51.0958 4916 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
09:16:51.0961 4916 AmdK8 - ok
09:16:51.0978 4916 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
09:16:51.0980 4916 AmdPPM - ok
09:16:52.0044 4916 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
09:16:52.0046 4916 amdsata - ok
09:16:52.0084 4916 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
09:16:52.0088 4916 amdsbs - ok
09:16:52.0124 4916 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
09:16:52.0136 4916 amdxata - ok
09:16:52.0189 4916 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
09:16:52.0191 4916 AppID - ok
09:16:52.0236 4916 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
09:16:52.0238 4916 AppIDSvc - ok
09:16:52.0285 4916 [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo C:\Windows\System32\appinfo.dll
09:16:52.0287 4916 Appinfo - ok
09:16:52.0354 4916 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
09:16:52.0367 4916 arc - ok
09:16:52.0398 4916 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
09:16:52.0401 4916 arcsas - ok
09:16:52.0438 4916 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
09:16:52.0440 4916 AsyncMac - ok
09:16:52.0509 4916 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
09:16:52.0509 4916 atapi - ok
09:16:52.0697 4916 [ B01751CC563AECAC09BBE36AAA21FBEF ] athr C:\Windows\system32\DRIVERS\athr.sys
09:16:52.0743 4916 athr - ok
09:16:52.0835 4916 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
09:16:52.0845 4916 AudioEndpointBuilder - ok
09:16:52.0871 4916 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
09:16:52.0876 4916 Audiosrv - ok
09:16:52.0959 4916 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
09:16:52.0967 4916 AxInstSV - ok
09:16:53.0053 4916 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
09:16:53.0061 4916 b06bdrv - ok
09:16:53.0125 4916 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
09:16:53.0132 4916 b57nd60x - ok
09:16:53.0214 4916 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
09:16:53.0216 4916 BDESVC - ok
09:16:53.0244 4916 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
09:16:53.0245 4916 Beep - ok
09:16:53.0352 4916 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
09:16:53.0362 4916 BFE - ok
09:16:53.0477 4916 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
09:16:53.0501 4916 BITS - ok
09:16:53.0519 4916 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
09:16:53.0521 4916 blbdrive - ok
09:16:53.0565 4916 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
09:16:53.0568 4916 bowser - ok
09:16:53.0596 4916 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
09:16:53.0598 4916 BrFiltLo - ok
09:16:53.0618 4916 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
09:16:53.0619 4916 BrFiltUp - ok
09:16:53.0702 4916 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
09:16:53.0705 4916 Browser - ok
09:16:53.0779 4916 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
09:16:53.0791 4916 Brserid - ok
09:16:53.0827 4916 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
09:16:53.0830 4916 BrSerWdm - ok
09:16:53.0880 4916 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
09:16:53.0882 4916 BrUsbMdm - ok
09:16:53.0895 4916 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
09:16:53.0900 4916 BrUsbSer - ok
09:16:53.0953 4916 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
09:16:53.0955 4916 BTHMODEM - ok
09:16:54.0030 4916 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
09:16:54.0032 4916 bthserv - ok
09:16:54.0083 4916 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
09:16:54.0086 4916 cdfs - ok
09:16:54.0162 4916 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
09:16:54.0169 4916 cdrom - ok
09:16:54.0265 4916 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
09:16:54.0268 4916 CertPropSvc - ok
09:16:54.0318 4916 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
09:16:54.0320 4916 circlass - ok
09:16:54.0382 4916 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
09:16:54.0388 4916 CLFS - ok
09:16:54.0611 4916 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
09:16:54.0644 4916 clr_optimization_v2.0.50727_32 - ok
09:16:54.0948 4916 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
09:16:54.0952 4916 clr_optimization_v4.0.30319_32 - ok
09:16:55.0012 4916 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
09:16:55.0025 4916 CmBatt - ok
09:16:55.0073 4916 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
09:16:55.0074 4916 cmdide - ok
09:16:55.0199 4916 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
09:16:55.0221 4916 CNG - ok
09:16:55.0258 4916 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
09:16:55.0260 4916 Compbatt - ok
09:16:55.0323 4916 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
09:16:55.0325 4916 CompositeBus - ok
09:16:55.0452 4916 COMSysApp - ok
09:16:55.0495 4916 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
09:16:55.0497 4916 crcdisk - ok
09:16:55.0572 4916 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9 ] CryptSvc C:\Windows\system32\cryptsvc.dll
09:16:55.0644 4916 CryptSvc - ok
09:16:55.0720 4916 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
09:16:55.0730 4916 DcomLaunch - ok
09:16:55.0810 4916 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
09:16:55.0817 4916 defragsvc - ok
09:16:55.0868 4916 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
09:16:55.0870 4916 DfsC - ok
09:16:55.0992 4916 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
09:16:56.0012 4916 Dhcp - ok
09:16:56.0072 4916 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
09:16:56.0074 4916 discache - ok
09:16:56.0204 4916 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
09:16:56.0210 4916 Disk - ok
09:16:56.0285 4916 [ 73BAF270D24FE726B9CD7F80BB17A23D ] DKbFltr C:\Windows\system32\DRIVERS\DKbFltr.sys
09:16:56.0287 4916 DKbFltr - ok
09:16:56.0347 4916 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
09:16:56.0351 4916 Dnscache - ok
09:16:56.0433 4916 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
09:16:56.0467 4916 dot3svc - ok
09:16:56.0557 4916 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
09:16:56.0594 4916 DPS - ok
09:16:56.0632 4916 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
09:16:56.0643 4916 drmkaud - ok
09:16:56.0859 4916 [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
09:16:56.0926 4916 DXGKrnl - ok
09:16:57.0007 4916 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
09:16:57.0020 4916 EapHost - ok
09:16:57.0501 4916 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
09:16:57.0617 4916 ebdrv - ok
09:16:57.0669 4916 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
09:16:57.0682 4916 EFS - ok
09:16:57.0928 4916 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
09:16:57.0943 4916 ehRecvr - ok
09:16:57.0989 4916 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
09:16:58.0003 4916 ehSched - ok
09:16:58.0098 4916 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
09:16:58.0108 4916 elxstor - ok
09:16:58.0200 4916 [ 448E6DEFA9DFB76207A529FC0FB64069 ] eRecoveryService C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
09:16:58.0201 4916 eRecoveryService - ok
09:16:58.0250 4916 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
09:16:58.0251 4916 ErrDev - ok
09:16:58.0339 4916 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
09:16:58.0345 4916 EventSystem - ok
09:16:58.0402 4916 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
09:16:58.0406 4916 exfat - ok
09:16:58.0450 4916 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
09:16:58.0454 4916 fastfat - ok
09:16:58.0526 4916 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
09:16:58.0608 4916 Fax - ok
09:16:58.0637 4916 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
09:16:58.0639 4916 fdc - ok
09:16:58.0683 4916 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
09:16:58.0685 4916 fdPHost - ok
09:16:58.0708 4916 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
09:16:58.0710 4916 FDResPub - ok
09:16:58.0736 4916 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
09:16:58.0738 4916 FileInfo - ok
09:16:58.0770 4916 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
09:16:58.0772 4916 Filetrace - ok
09:16:58.0803 4916 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
09:16:58.0805 4916 flpydisk - ok
09:16:58.0855 4916 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
09:16:58.0860 4916 FltMgr - ok
09:16:58.0943 4916 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
09:16:58.0993 4916 FontCache - ok
09:16:59.0070 4916 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
09:16:59.0072 4916 FontCache3.0.0.0 - ok
09:16:59.0111 4916 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
09:16:59.0113 4916 FsDepends - ok
09:16:59.0152 4916 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
09:16:59.0154 4916 Fs_Rec - ok
09:16:59.0216 4916 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
09:16:59.0220 4916 fvevol - ok
09:16:59.0254 4916 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
09:16:59.0256 4916 gagp30kx - ok
09:16:59.0320 4916 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
09:16:59.0369 4916 gpsvc - ok
09:16:59.0447 4916 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
09:16:59.0449 4916 gupdate - ok
09:16:59.0462 4916 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
09:16:59.0465 4916 gupdatem - ok
09:16:59.0500 4916 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
09:16:59.0502 4916 hcw85cir - ok
09:16:59.0568 4916 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
09:16:59.0571 4916 HDAudBus - ok
09:16:59.0590 4916 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
09:16:59.0592 4916 HidBatt - ok
09:16:59.0622 4916 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
09:16:59.0625 4916 HidBth - ok
09:16:59.0668 4916 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
09:16:59.0670 4916 HidIr - ok
09:16:59.0711 4916 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
09:16:59.0716 4916 hidserv - ok
09:16:59.0798 4916 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
09:16:59.0800 4916 HidUsb - ok
09:16:59.0840 4916 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
09:16:59.0844 4916 hkmsvc - ok
09:16:59.0885 4916 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
09:16:59.0891 4916 HomeGroupListener - ok
09:16:59.0980 4916 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
09:16:59.0987 4916 HomeGroupProvider - ok
09:17:00.0034 4916 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
09:17:00.0036 4916 HpSAMD - ok
09:17:00.0096 4916 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
09:17:00.0106 4916 HTTP - ok
09:17:00.0154 4916 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
09:17:00.0155 4916 hwpolicy - ok
09:17:00.0216 4916 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
09:17:00.0219 4916 i8042prt - ok
09:17:00.0291 4916 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
09:17:00.0298 4916 iaStorV - ok
09:17:00.0385 4916 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
09:17:00.0420 4916 idsvc - ok
09:17:00.0630 4916 [ 9467514EA189475A6E7FDC5D7BDE9D3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
09:17:00.0791 4916 igfx - ok
09:17:00.0861 4916 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
09:17:00.0863 4916 iirsp - ok
09:17:00.0921 4916 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
09:17:00.0955 4916 IKEEXT - ok
09:17:00.0994 4916 [ 9D64201C9E5AC8D1F088762BA00FF3AB ] int15 C:\Acer\Empowering Technology\eRecovery\int15.sys
09:17:01.0001 4916 int15 - ok
09:17:01.0116 4916 [ 04BEF1C4AA990E0D5851C7532FC8642C ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
09:17:01.0177 4916 IntcAzAudAddService - ok
09:17:01.0225 4916 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
09:17:01.0227 4916 intelide - ok
09:17:01.0275 4916 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
09:17:01.0277 4916 intelppm - ok
09:17:01.0345 4916 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
09:17:01.0356 4916 IPBusEnum - ok
09:17:01.0395 4916 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
09:17:01.0397 4916 IpFilterDriver - ok
09:17:01.0465 4916 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
09:17:01.0479 4916 iphlpsvc - ok
09:17:01.0521 4916 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
09:17:01.0524 4916 IPMIDRV - ok
09:17:01.0568 4916 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
09:17:01.0576 4916 IPNAT - ok
09:17:01.0626 4916 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
09:17:01.0628 4916 IRENUM - ok
09:17:01.0685 4916 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
09:17:01.0701 4916 isapnp - ok
09:17:01.0753 4916 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
09:17:01.0758 4916 iScsiPrt - ok
09:17:01.0810 4916 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
09:17:01.0812 4916 kbdclass - ok
09:17:01.0857 4916 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
09:17:01.0859 4916 kbdhid - ok
09:17:01.0889 4916 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
09:17:01.0891 4916 KeyIso - ok
09:17:01.0954 4916 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
09:17:01.0959 4916 KSecDD - ok
09:17:02.0005 4916 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
09:17:02.0009 4916 KSecPkg - ok
09:17:02.0053 4916 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
09:17:02.0061 4916 KtmRm - ok
09:17:02.0105 4916 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
09:17:02.0112 4916 LanmanServer - ok
09:17:02.0143 4916 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
09:17:02.0149 4916 LanmanWorkstation - ok
09:17:02.0228 4916 [ 559C9B7800FAC92FC515CD0003D7C631 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
09:17:02.0230 4916 LightScribeService - ok
09:17:02.0284 4916 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
09:17:02.0286 4916 lltdio - ok
09:17:02.0326 4916 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
09:17:02.0332 4916 lltdsvc - ok
09:17:02.0372 4916 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
09:17:02.0388 4916 lmhosts - ok
09:17:02.0440 4916 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
09:17:02.0443 4916 LSI_FC - ok
09:17:02.0474 4916 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
09:17:02.0476 4916 LSI_SAS - ok
09:17:02.0507 4916 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
09:17:02.0510 4916 LSI_SAS2 - ok
09:17:02.0537 4916 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
09:17:02.0539 4916 LSI_SCSI - ok
09:17:02.0565 4916 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
09:17:02.0568 4916 luafv - ok
09:17:02.0610 4916 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
09:17:02.0613 4916 Mcx2Svc - ok
09:17:02.0642 4916 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
09:17:02.0644 4916 megasas - ok
09:17:02.0713 4916 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
09:17:02.0732 4916 MegaSR - ok
09:17:02.0803 4916 [ 7C4C76B39D5525C4A465E0BE32528E19 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
09:17:02.0806 4916 Microsoft Office Groove Audit Service - ok
09:17:02.0842 4916 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
09:17:02.0846 4916 MMCSS - ok
09:17:02.0864 4916 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
09:17:02.0866 4916 Modem - ok
09:17:02.0925 4916 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
09:17:02.0926 4916 monitor - ok
09:17:02.0964 4916 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
09:17:02.0966 4916 mouclass - ok
09:17:03.0008 4916 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
09:17:03.0010 4916 mouhid - ok
09:17:03.0051 4916 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
09:17:03.0054 4916 mountmgr - ok
09:17:03.0076 4916 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
09:17:03.0080 4916 mpio - ok
09:17:03.0109 4916 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
09:17:03.0111 4916 mpsdrv - ok
09:17:03.0172 4916 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
09:17:03.0184 4916 MpsSvc - ok
09:17:03.0235 4916 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
09:17:03.0239 4916 MRxDAV - ok
09:17:03.0282 4916 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
09:17:03.0286 4916 mrxsmb - ok
09:17:03.0315 4916 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
09:17:03.0320 4916 mrxsmb10 - ok
09:17:03.0346 4916 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
09:17:03.0348 4916 mrxsmb20 - ok
09:17:03.0382 4916 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
09:17:03.0384 4916 msahci - ok
09:17:03.0427 4916 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
09:17:03.0431 4916 msdsm - ok
09:17:03.0466 4916 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
09:17:03.0472 4916 MSDTC - ok
09:17:03.0534 4916 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
09:17:03.0536 4916 Msfs - ok
09:17:03.0559 4916 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
09:17:03.0560 4916 mshidkmdf - ok
09:17:03.0595 4916 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
09:17:03.0596 4916 msisadrv - ok
09:17:03.0656 4916 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
09:17:03.0660 4916 MSiSCSI - ok
09:17:03.0678 4916 msiserver - ok
09:17:03.0719 4916 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
09:17:03.0720 4916 MSKSSRV - ok
09:17:03.0760 4916 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
09:17:03.0761 4916 MSPCLOCK - ok
09:17:03.0788 4916 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
09:17:03.0790 4916 MSPQM - ok
09:17:03.0818 4916 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
09:17:03.0822 4916 MsRPC - ok
09:17:03.0872 4916 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
09:17:03.0874 4916 mssmbios - ok
09:17:03.0901 4916 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
09:17:03.0903 4916 MSTEE - ok
09:17:03.0930 4916 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
09:17:03.0932 4916 MTConfig - ok
09:17:03.0961 4916 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
09:17:03.0963 4916 Mup - ok
09:17:04.0015 4916 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
09:17:04.0038 4916 napagent - ok
09:17:04.0097 4916 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
09:17:04.0109 4916 NativeWifiP - ok
09:17:04.0172 4916 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
09:17:04.0218 4916 NDIS - ok
09:17:04.0248 4916 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
09:17:04.0250 4916 NdisCap - ok
09:17:04.0295 4916 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
09:17:04.0296 4916 NdisTapi - ok
09:17:04.0345 4916 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
09:17:04.0347 4916 Ndisuio - ok
09:17:04.0377 4916 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
09:17:04.0380 4916 NdisWan - ok
09:17:04.0425 4916 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
09:17:04.0427 4916 NDProxy - ok
09:17:04.0485 4916 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
09:17:04.0487 4916 NetBIOS - ok
09:17:04.0530 4916 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
09:17:04.0534 4916 NetBT - ok
09:17:04.0553 4916 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
09:17:04.0556 4916 Netlogon - ok
09:17:04.0622 4916 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
09:17:04.0631 4916 Netman - ok
09:17:04.0668 4916 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
09:17:04.0678 4916 netprofm - ok
09:17:04.0705 4916 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
09:17:04.0709 4916 NetTcpPortSharing - ok
09:17:04.0762 4916 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
09:17:04.0764 4916 nfrd960 - ok
09:17:04.0843 4916 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
09:17:04.0869 4916 NlaSvc - ok
09:17:04.0915 4916 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
09:17:04.0943 4916 Npfs - ok
09:17:04.0986 4916 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
09:17:04.0990 4916 nsi - ok
09:17:05.0030 4916 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
09:17:05.0031 4916 nsiproxy - ok
09:17:05.0109 4916 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
09:17:05.0167 4916 Ntfs - ok
09:17:05.0204 4916 [ 7F1C1F78D709C4A54CBB46EDE7E0B48D ] NTIDrvr C:\Windows\system32\DRIVERS\NTIDrvr.sys
09:17:05.0205 4916 NTIDrvr - ok
09:17:05.0246 4916 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
09:17:05.0248 4916 Null - ok
09:17:05.0292 4916 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
09:17:05.0296 4916 nvraid - ok
09:17:05.0344 4916 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
09:17:05.0348 4916 nvstor - ok
09:17:05.0408 4916 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
09:17:05.0413 4916 nv_agp - ok
09:17:05.0516 4916 [ 1F0E05DFF4F5A833168E49BE1256F002 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
09:17:05.0544 4916 odserv - ok
09:17:05.0571 4916 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
09:17:05.0574 4916 ohci1394 - ok
09:17:05.0635 4916 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:17:05.0639 4916 ose - ok
09:17:05.0696 4916 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
09:17:05.0717 4916 p2pimsvc - ok
09:17:05.0765 4916 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
09:17:05.0774 4916 p2psvc - ok
09:17:05.0819 4916 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
09:17:05.0821 4916 Parport - ok
09:17:05.0864 4916 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
09:17:05.0867 4916 partmgr - ok
09:17:05.0896 4916 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
09:17:05.0898 4916 Parvdm - ok
09:17:05.0932 4916 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
09:17:05.0938 4916 PcaSvc - ok
09:17:05.0963 4916 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
09:17:05.0967 4916 pci - ok
09:17:05.0992 4916 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
09:17:05.0994 4916 pciide - ok
09:17:06.0032 4916 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
09:17:06.0036 4916 pcmcia - ok
09:17:06.0071 4916 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
09:17:06.0073 4916 pcw - ok
09:17:06.0118 4916 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
09:17:06.0142 4916 PEAUTH - ok
09:17:06.0255 4916 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
09:17:06.0316 4916 pla - ok
09:17:06.0375 4916 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
09:17:06.0385 4916 PlugPlay - ok
09:17:06.0414 4916 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
09:17:06.0418 4916 PNRPAutoReg - ok
09:17:06.0452 4916 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
09:17:06.0457 4916 PNRPsvc - ok
09:17:06.0500 4916 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
09:17:06.0523 4916 PolicyAgent - ok
09:17:06.0569 4916 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
09:17:06.0574 4916 Power - ok
09:17:06.0612 4916 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
09:17:06.0615 4916 PptpMiniport - ok
09:17:06.0644 4916 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
09:17:06.0646 4916 Processor - ok
09:17:06.0709 4916 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
09:17:06.0715 4916 ProfSvc - ok
09:17:06.0741 4916 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
09:17:06.0743 4916 ProtectedStorage - ok
09:17:06.0787 4916 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
09:17:06.0789 4916 Psched - ok
09:17:06.0874 4916 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
09:17:06.0921 4916 ql2300 - ok
09:17:06.0952 4916 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
09:17:06.0955 4916 ql40xx - ok
09:17:07.0004 4916 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
09:17:07.0011 4916 QWAVE - ok
09:17:07.0038 4916 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
09:17:07.0040 4916 QWAVEdrv - ok
09:17:07.0062 4916 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
09:17:07.0064 4916 RasAcd - ok
09:17:07.0108 4916 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
09:17:07.0110 4916 RasAgileVpn - ok
09:17:07.0165 4916 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
09:17:07.0179 4916 RasAuto - ok
09:17:07.0211 4916 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
09:17:07.0213 4916 Rasl2tp - ok
09:17:07.0266 4916 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
09:17:07.0275 4916 RasMan - ok
09:17:07.0304 4916 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
09:17:07.0307 4916 RasPppoe - ok
09:17:07.0353 4916 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
09:17:07.0356 4916 RasSstp - ok
09:17:07.0398 4916 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
09:17:07.0403 4916 rdbss - ok
09:17:07.0436 4916 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
09:17:07.0438 4916 rdpbus - ok
09:17:07.0475 4916 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
09:17:07.0476 4916 RDPCDD - ok
09:17:07.0515 4916 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
09:17:07.0515 4916 RDPENCDD - ok
09:17:07.0545 4916 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
09:17:07.0546 4916 RDPREFMP - ok
09:17:07.0589 4916 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
09:17:07.0594 4916 RDPWD - ok
09:17:07.0648 4916 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
09:17:07.0652 4916 rdyboost - ok
09:17:07.0692 4916 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
09:17:07.0696 4916 RemoteAccess - ok
09:17:07.0738 4916 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
09:17:07.0744 4916 RemoteRegistry - ok
09:17:07.0803 4916 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
09:17:07.0808 4916 RpcEptMapper - ok
09:17:07.0849 4916 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
09:17:07.0852 4916 RpcLocator - ok
09:17:07.0902 4916 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
09:17:07.0912 4916 RpcSs - ok
09:17:07.0967 4916 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
09:17:07.0970 4916 rspndr - ok
09:17:07.0997 4916 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
09:17:07.0999 4916 SamSs - ok
09:17:08.0118 4916 [ 07310DF9FD1A62790B5A011048D8E121 ] SAVAdminService C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
09:17:08.0122 4916 SAVAdminService - ok
09:17:08.0173 4916 [ 3932A1A0F46728CC00E3D9B389C096B0 ] SAVOnAccess C:\Windows\system32\DRIVERS\savonaccess.sys
09:17:08.0177 4916 SAVOnAccess - ok
09:17:08.0211 4916 [ D31E18B53B0E52C234568BB61EEC7940 ] SAVService C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
09:17:08.0216 4916 SAVService - ok
09:17:08.0263 4916 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
09:17:08.0266 4916 sbp2port - ok
09:17:08.0304 4916 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
09:17:08.0312 4916 SCardSvr - ok
09:17:08.0353 4916 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
09:17:08.0355 4916 scfilter - ok
09:17:08.0429 4916 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
09:17:08.0463 4916 Schedule - ok
09:17:08.0501 4916 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
09:17:08.0502 4916 SCPolicySvc - ok
09:17:08.0553 4916 [ 4F21774E1259A546B992D9EAACDFD778 ] sdcfilter C:\Windows\system32\DRIVERS\sdcfilter.sys
09:17:08.0555 4916 sdcfilter - ok
09:17:08.0595 4916 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
09:17:08.0601 4916 SDRSVC - ok
09:17:08.0660 4916 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
09:17:08.0662 4916 secdrv - ok
09:17:08.0702 4916 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
09:17:08.0707 4916 seclogon - ok
09:17:08.0737 4916 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
09:17:08.0742 4916 SENS - ok
09:17:08.0780 4916 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
09:17:08.0784 4916 SensrSvc - ok
09:17:08.0816 4916 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
09:17:08.0817 4916 Serenum - ok
09:17:08.0871 4916 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
09:17:08.0874 4916 Serial - ok
09:17:08.0914 4916 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
09:17:08.0915 4916 sermouse - ok
09:17:08.0970 4916 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
09:17:08.0976 4916 SessionEnv - ok
09:17:09.0015 4916 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
09:17:09.0017 4916 sffdisk - ok
09:17:09.0033 4916 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
09:17:09.0037 4916 sffp_mmc - ok
09:17:09.0059 4916 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
09:17:09.0060 4916 sffp_sd - ok
09:17:09.0105 4916 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
09:17:09.0107 4916 sfloppy - ok
09:17:09.0163 4916 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
09:17:09.0171 4916 SharedAccess - ok
09:17:09.0206 4916 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
09:17:09.0215 4916 ShellHWDetection - ok
09:17:09.0248 4916 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
09:17:09.0250 4916 sisagp - ok
09:17:09.0286 4916 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
09:17:09.0288 4916 SiSRaid2 - ok
09:17:09.0319 4916 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
09:17:09.0322 4916 SiSRaid4 - ok
09:17:09.0379 4916 [ DA8F2F3BB2B58B0125F9C62412DDC4D9 ] SKMScan C:\Windows\system32\DRIVERS\skmscan.sys
09:17:09.0381 4916 SKMScan - ok
09:17:09.0419 4916 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
09:17:09.0422 4916 Smb - ok
09:17:09.0466 4916 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
09:17:09.0470 4916 SNMPTRAP - ok
09:17:09.0555 4916 [ 89F663C9ACA369C0E327C00D2C220AA9 ] Sophos AutoUpdate Service C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
09:17:09.0567 4916 Sophos AutoUpdate Service - ok
09:17:09.0636 4916 [ BD03374253F79CE7A716A870DC85BD84 ] Sophos Web Control Service C:\Program Files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
09:17:09.0656 4916 Sophos Web Control Service - ok
09:17:09.0681 4916 [ F2B7BD04146B3E6A895A1919E1F5DA89 ] SophosBootDriver C:\Windows\system32\DRIVERS\SophosBootDriver.sys
09:17:09.0683 4916 SophosBootDriver - ok
09:17:09.0721 4916 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
09:17:09.0722 4916 spldr - ok
09:17:09.0767 4916 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
09:17:09.0776 4916 Spooler - ok
09:17:09.0932 4916 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
09:17:10.0036 4916 sppsvc - ok
09:17:10.0132 4916 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
09:17:10.0137 4916 sppuinotify - ok
09:17:10.0191 4916 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
09:17:10.0198 4916 srv - ok
09:17:10.0237 4916 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
09:17:10.0244 4916 srv2 - ok
09:17:10.0278 4916 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
09:17:10.0282 4916 srvnet - ok
09:17:10.0325 4916 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
09:17:10.0332 4916 SSDPSRV - ok
09:17:10.0348 4916 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
09:17:10.0384 4916 SstpSvc - ok
09:17:10.0424 4916 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
09:17:10.0426 4916 stexstor - ok
09:17:10.0480 4916 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
09:17:10.0503 4916 StiSvc - ok
09:17:10.0541 4916 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
09:17:10.0542 4916 swenum - ok
09:17:10.0720 4916 [ FF4057FF51ED100C0003B2FE128C2194 ] swi_service C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
09:17:10.0812 4916 swi_service - ok
09:17:10.0946 4916 [ A06DA209AABD062D5904F16816C818D1 ] swi_update C:\ProgramData\Sophos\Web Intelligence\swi_update.exe
09:17:11.0004 4916 swi_update - ok
09:17:11.0061 4916 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
09:17:11.0071 4916 swprv - ok
09:17:11.0128 4916 [ 2D2C815364A878C7E358D5F549711197 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
09:17:11.0135 4916 SynTP - ok
09:17:11.0214 4916 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
09:17:11.0264 4916 SysMain - ok
09:17:11.0308 4916 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
09:17:11.0313 4916 TabletInputService - ok
09:17:11.0356 4916 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
09:17:11.0365 4916 TapiSrv - ok
09:17:11.0406 4916 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
09:17:11.0410 4916 TBS - ok
09:17:11.0484 4916 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] Tcpip C:\Windows\system32\drivers\tcpip.sys
09:17:11.0537 4916 Tcpip - ok
09:17:11.0606 4916 [ 4E8B9BE71B807B3BAEDB7F4243F85E3C ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
09:17:11.0621 4916 TCPIP6 - ok
09:17:11.0682 4916 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
09:17:11.0691 4916 tcpipreg - ok
09:17:11.0732 4916 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
09:17:11.0734 4916 TDPIPE - ok
09:17:11.0759 4916 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
09:17:11.0761 4916 TDTCP - ok
09:17:11.0797 4916 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
09:17:11.0799 4916 tdx - ok
09:17:11.0839 4916 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
09:17:11.0842 4916 TermDD - ok
09:17:11.0895 4916 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
09:17:11.0919 4916 TermService - ok
09:17:11.0964 4916 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
09:17:11.0969 4916 Themes - ok
09:17:11.0993 4916 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
09:17:11.0995 4916 THREADORDER - ok
09:17:12.0046 4916 [ F779BA4CD37963AB4600C9871B7752A3 ] tifm21 C:\Windows\system32\drivers\tifm21.sys
09:17:12.0050 4916 tifm21 - ok
09:17:12.0094 4916 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
09:17:12.0099 4916 TrkWks - ok
09:17:12.0163 4916 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
09:17:12.0167 4916 TrustedInstaller - ok
09:17:12.0218 4916 [ B37B08F2E5EEB1A37E448E09BACE1101 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
09:17:12.0220 4916 tssecsrv - ok
09:17:12.0268 4916 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
09:17:12.0271 4916 TsUsbFlt - ok
09:17:12.0344 4916 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
09:17:12.0347 4916 tunnel - ok
09:17:12.0393 4916 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
09:17:12.0395 4916 uagp35 - ok
09:17:12.0434 4916 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
09:17:12.0440 4916 udfs - ok
09:17:12.0498 4916 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
09:17:12.0502 4916 UI0Detect - ok
09:17:12.0532 4916 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
09:17:12.0534 4916 uliagpkx - ok
09:17:12.0577 4916 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
09:17:12.0579 4916 umbus - ok
09:17:12.0608 4916 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
09:17:12.0609 4916 UmPass - ok
09:17:12.0665 4916 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
09:17:12.0688 4916 upnphost - ok
09:17:12.0740 4916 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
09:17:12.0743 4916 usbccgp - ok
09:17:12.0783 4916 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
09:17:12.0786 4916 usbcir - ok
09:17:12.0812 4916 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
09:17:12.0815 4916 usbehci - ok
09:17:12.0869 4916 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
09:17:12.0881 4916 usbhub - ok
09:17:12.0910 4916 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
09:17:12.0912 4916 usbohci - ok
09:17:12.0949 4916 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
09:17:12.0951 4916 usbprint - ok
09:17:12.0993 4916 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
09:17:12.0995 4916 USBSTOR - ok
09:17:13.0028 4916 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
09:17:13.0030 4916 usbuhci - ok
09:17:13.0058 4916 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
09:17:13.0062 4916 UxSms - ok
09:17:13.0082 4916 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
09:17:13.0084 4916 VaultSvc - ok
09:17:13.0125 4916 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
09:17:13.0127 4916 vdrvroot - ok
09:17:13.0183 4916 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
09:17:13.0195 4916 vds - ok
09:17:13.0257 4916 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
09:17:13.0259 4916 vga - ok
09:17:13.0285 4916 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
09:17:13.0286 4916 VgaSave - ok
09:17:13.0329 4916 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
09:17:13.0333 4916 vhdmp - ok
09:17:13.0366 4916 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
09:17:13.0368 4916 viaagp - ok
09:17:13.0397 4916 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
09:17:13.0399 4916 ViaC7 - ok
09:17:13.0431 4916 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
09:17:13.0433 4916 viaide - ok
09:17:13.0463 4916 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
09:17:13.0471 4916 volmgr - ok
09:17:13.0511 4916 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
09:17:13.0517 4916 volmgrx - ok
09:17:13.0562 4916 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
09:17:13.0568 4916 volsnap - ok
09:17:13.0610 4916 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
09:17:13.0614 4916 vsmraid - ok
09:17:13.0686 4916 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
09:17:13.0736 4916 VSS - ok
09:17:13.0760 4916 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
09:17:13.0762 4916 vwifibus - ok
09:17:13.0790 4916 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
09:17:13.0792 4916 vwififlt - ok
09:17:13.0844 4916 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
09:17:13.0868 4916 W32Time - ok
09:17:13.0902 4916 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
09:17:13.0904 4916 WacomPen - ok
09:17:13.0960 4916 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
09:17:13.0963 4916 WANARP - ok
09:17:13.0993 4916 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
09:17:13.0995 4916 Wanarpv6 - ok
09:17:14.0096 4916 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
09:17:14.0144 4916 WatAdminSvc - ok
09:17:14.0211 4916 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
09:17:14.0257 4916 wbengine - ok
09:17:14.0295 4916 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
09:17:14.0302 4916 WbioSrvc - ok
09:17:14.0347 4916 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
09:17:14.0356 4916 wcncsvc - ok
09:17:14.0386 4916 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
09:17:14.0393 4916 WcsPlugInService - ok
09:17:14.0436 4916 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
09:17:14.0438 4916 Wd - ok
09:17:14.0504 4916 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
09:17:14.0539 4916 Wdf01000 - ok
09:17:14.0570 4916 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
09:17:14.0576 4916 WdiServiceHost - ok
09:17:14.0602 4916 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
09:17:14.0607 4916 WdiSystemHost - ok
09:17:14.0653 4916 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
09:17:14.0661 4916 WebClient - ok
09:17:14.0709 4916 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
09:17:14.0716 4916 Wecsvc - ok
09:17:14.0749 4916 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
09:17:14.0755 4916 wercplsupport - ok
09:17:14.0799 4916 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
09:17:14.0804 4916 WerSvc - ok
09:17:14.0847 4916 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
09:17:14.0849 4916 WfpLwf - ok
09:17:14.0879 4916 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
09:17:14.0881 4916 WIMMount - ok
09:17:14.0961 4916 [ 082CF481F659FAE0DE51AD060881EB47 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
09:17:14.0992 4916 WinDefend - ok
09:17:15.0019 4916 WinHttpAutoProxySvc - ok
09:17:15.0088 4916 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
09:17:15.0092 4916 Winmgmt - ok
09:17:15.0207 4916 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
09:17:15.0272 4916 WinRM - ok
09:17:15.0386 4916 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
09:17:15.0405 4916 Wlansvc - ok
09:17:15.0458 4916 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
09:17:15.0462 4916 WmiAcpi - ok
09:17:15.0524 4916 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
09:17:15.0540 4916 wmiApSrv - ok
09:17:15.0644 4916 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
09:17:15.0691 4916 WMPNetworkSvc - ok
09:17:15.0737 4916 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
09:17:15.0741 4916 WPCSvc - ok
09:17:15.0782 4916 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
09:17:15.0788 4916 WPDBusEnum - ok
09:17:15.0829 4916 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
09:17:15.0831 4916 ws2ifsl - ok
09:17:15.0858 4916 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
09:17:15.0864 4916 wscsvc - ok
09:17:15.0879 4916 WSearch - ok
09:17:15.0991 4916 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
09:17:16.0079 4916 wuauserv - ok
09:17:16.0120 4916 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
09:17:16.0122 4916 WudfPf - ok
09:17:16.0173 4916 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
09:17:16.0177 4916 WUDFRd - ok
09:17:16.0224 4916 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
09:17:16.0230 4916 wudfsvc - ok
09:17:16.0275 4916 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc C:\Windows\System32\wwansvc.dll
09:17:16.0285 4916 WwanSvc - ok
09:17:16.0355 4916 [ B07C5B7EFDF936FF93D4F540938725BE ] yukonw7 C:\Windows\system32\DRIVERS\yk62x86.sys
09:17:16.0361 4916 yukonw7 - ok
09:17:16.0405 4916 ================ Scan global ===============================
09:17:16.0457 4916 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
09:17:16.0493 4916 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
09:17:16.0521 4916 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
09:17:16.0567 4916 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
09:17:16.0624 4916 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
09:17:16.0629 4916 [Global] - ok
09:17:16.0635 4916 ================ Scan MBR ==================================
09:17:16.0657 4916 [ E90AA6BE22E8268A3764331202F9CFB0 ] \Device\Harddisk0\DR0
09:17:20.0069 4916 \Device\Harddisk0\DR0 - ok
09:17:20.0073 4916 ================ Scan VBR ==================================
09:17:20.0081 4916 [ 4AD9DD57A559207DA0A8CC678316C73C ] \Device\Harddisk0\DR0\Partition1
09:17:20.0091 4916 \Device\Harddisk0\DR0\Partition1 - ok
09:17:20.0096 4916 ============================================================
09:17:20.0096 4916 Scan finished
09:17:20.0096 4916 ============================================================
09:17:20.0117 2908 Detected object count: 0
09:17:20.0117 2908 Actual detected object count: 0

Adwclean

# AdwCleaner v3.002 - Report created 05/09/2013 at 09:19:51
# Updated 01/09/2013 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Kevin - KEVIN-PC
# Running from : C:\Users\Kevin\Desktop\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****

File Found : C:\END
Folder Found C:\Program Files\Wajam
Folder Found C:\Users\Kevin\AppData\Local\Wajam
Folder Found C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Wajam
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Found : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL
Key Found : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Found : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Found : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32
Key Found : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Found : HKLM\Software\Wajam
Product Found : Google Update Helper
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16660


-\\ Google Chrome v29.0.1547.62

[ File : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [2876 octets] - [05/09/2013 09:19:51]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [2936 octets] ##########




I don't know much about anything else, but I am pretty sure "WAJAM" is not what I want.
Hi,

I am pretty sure "WAJAM" is not what I want.

LOL….no not really. :)

[external image: Posted Image] AdwCleaner

Double click on AdwCleaner.exe to run the tool again.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished…
  • This time, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
———-

ComboFix

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
Hi Jeff, I am away from my laptop now and I will go ahead to follow your instruction later. What I noticed after scanning using AdwCleaner initially, a message " Pending. Please select the items you want to remove." was there. But I did not see any item captured in the main panel of the program. I will try one more time with this cleaner.
# AdwCleaner v3.002 - Report created 05/09/2013 at 21:42:50 # Updated 01/09/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (32 bits) # Username : Kevin - KEVIN-PC # Running from : C:\Users\Kevin\Desktop\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files\Wajam Folder Deleted : C:\Users\Kevin\AppData\Local\Wajam Folder Deleted : C:\Users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam File Deleted : C:\END ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Key Deleted : HKLM\SOFTWARE\Classes\AppID\priam_bho.DLL Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_RASMANCS Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}] Key Deleted : HKCU\Software\Wajam Key Deleted : HKLM\Software\Wajam Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Product Deleted : Google Update Helper ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Google Chrome v29.0.1547.62 [ File : C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [3016 octets] - [05/09/2013 09:19:51] AdwCleaner[R1].txt - [3076 octets] - [05/09/2013 21:40:38] AdwCleaner[S0].txt - [3065 octets] - [05/09/2013 21:42:50] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3125 octets] ##########
ComboFix 13-09-06.01 - Kevin 09/05/2013 21:53:50.1.1 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.1526.587 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} SP: Sophos Anti-Virus *Disabled/Updated* {DE9A3984-B0E2-7A61-FD5D-409005EB0337} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Kevin\AppData\Local\Temp\_MEI56042\_ctypes.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\_elementtree.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\_hashlib.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\_multiprocessing.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\_socket.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\_ssl.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\msvcp100.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\msvcr100.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\pyexpat.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\pysqlite2._sqlite.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\python27.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\pythoncom27.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\PyWinTypes27.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\select.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\unicodedata.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32api.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32com.shell.shell.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32crypt.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32event.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32file.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32inet.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32pdh.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32process.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32profile.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32security.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\win32ts.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\windows._cacheinvalidation.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._controls_.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._core_.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._gdi_.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._html2.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._misc_.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._windows_.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wx._wizard.pyd c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxbase294u_net_vc90.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxbase294u_vc90.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxmsw294u_adv_vc90.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxmsw294u_core_vc90.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxmsw294u_html_vc90.dll c:\users\Kevin\AppData\Local\Temp\_MEI56042\wxmsw294u_webview_vc90.dll . . ((((((((((((((((((((((((( Files Created from 2013-08-06 to 2013-09-06 ))))))))))))))))))))))))))))))) . . 2013-09-06 05:03 . 2013-09-06 05:03 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-09-05 16:33 . 2013-08-20 07:47 7166848 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1BFE4A1F-A5DC-4BBD-8C8C-F9486DD35512}\mpengine.dll 2013-09-05 16:19 . 2013-09-06 04:43 ——– d—–w- C:\AdwCleaner 2013-08-31 05:11 . 2013-04-17 07:02 1230336 —-a-w- c:\windows\system32\WindowsCodecs.dll 2013-08-31 05:11 . 2013-02-27 05:05 101720 —-a-w- c:\windows\system32\consent.exe 2013-08-31 05:11 . 2013-02-27 04:49 1796096 —-a-w- c:\windows\system32\authui.dll 2013-08-31 05:11 . 2013-02-27 04:49 47104 —-a-w- c:\windows\system32\appinfo.dll 2013-08-30 05:30 . 2013-04-09 23:34 1247744 —-a-w- c:\windows\system32\DWrite.dll 2013-08-30 05:12 . 2013-08-30 05:12 ——– d—–w- c:\windows\Panther 2013-08-29 16:47 . 2013-08-29 16:50 ——– d—–w- c:\windows\system32\MRT 2013-08-29 16:20 . 2013-08-29 16:20 4096 —ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-08-29 16:18 . 2013-08-29 16:18 1505280 —-a-w- c:\windows\system32\d3d11.dll 2013-08-29 14:48 . 2013-04-12 13:45 1211752 —-a-w- c:\windows\system32\drivers\ntfs.sys 2013-08-29 14:47 . 2013-07-09 04:50 652800 —-a-w- c:\windows\system32\rpcrt4.dll 2013-08-29 14:47 . 2013-07-09 04:52 175104 —-a-w- c:\windows\system32\wintrust.dll 2013-08-29 14:47 . 2013-07-09 04:46 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2013-08-29 14:47 . 2013-07-09 04:46 1166848 —-a-w- c:\windows\system32\crypt32.dll 2013-08-29 14:47 . 2013-07-09 04:46 103936 —-a-w- c:\windows\system32\cryptnet.dll 2013-08-29 14:46 . 2013-07-09 05:03 3913664 —-a-w- c:\windows\system32\ntoskrnl.exe 2013-08-29 14:46 . 2013-07-09 05:03 3968960 —-a-w- c:\windows\system32\ntkrnlpa.exe 2013-08-29 14:46 . 2013-07-09 04:53 1289096 —-a-w- c:\windows\system32\ntdll.dll 2013-08-29 14:46 . 2013-03-19 04:53 186368 —-a-w- c:\windows\system32\wwansvc.dll 2013-08-29 14:46 . 2013-03-19 03:33 40960 —-a-w- c:\windows\system32\wwanprotdim.dll 2013-08-29 14:46 . 2013-05-10 03:20 24576 —-a-w- c:\windows\system32\cryptdlg.dll 2013-08-29 14:46 . 2013-04-26 04:55 492544 —-a-w- c:\windows\system32\win32spl.dll 2013-08-29 14:45 . 2013-05-13 03:08 903168 —-a-w- c:\windows\system32\certutil.exe 2013-08-29 14:45 . 2013-05-13 03:08 43008 —-a-w- c:\windows\system32\certenc.dll 2013-08-29 14:45 . 2013-07-06 05:05 1293760 —-a-w- c:\windows\system32\drivers\tcpip.sys 2013-08-29 14:45 . 2013-06-04 04:53 509440 —-a-w- c:\windows\system32\qedit.dll 2013-08-29 14:45 . 2013-06-05 03:05 2347520 —-a-w- c:\windows\system32\win32k.sys 2013-08-29 14:44 . 2013-07-25 08:57 1620992 —-a-w- c:\windows\system32\WMVDECOD.DLL 2013-08-29 14:44 . 2013-04-10 05:03 936448 —-a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-08-29 14:44 . 2013-04-10 05:03 988672 —-a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-08-29 14:44 . 2013-04-10 05:04 1221632 —-a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-08-29 14:44 . 2013-04-10 05:03 969216 —-a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-08-29 14:44 . 2013-07-19 01:41 2048 —-a-w- c:\windows\system32\tzres.dll 2013-08-29 14:44 . 2013-04-10 05:18 728424 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-08-29 14:44 . 2013-04-10 05:18 218984 —-a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-08-29 14:44 . 2013-05-27 04:57 680960 —-a-w- c:\program files\Windows Defender\MpSvc.dll 2013-08-29 14:44 . 2013-05-27 04:57 392704 —-a-w- c:\program files\Windows Defender\MpClient.dll 2013-08-29 14:44 . 2013-05-27 04:57 224768 —-a-w- c:\program files\Windows Defender\MpCommu.dll 2013-08-29 14:43 . 2013-06-15 03:38 31232 —-a-w- c:\windows\system32\drivers\tssecsrv.sys 2013-08-29 14:23 . 2013-08-29 14:23 ——– d—–w- c:\users\Kevin\AppData\Roaming\addpcs . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-07 11:22 . 2013-01-16 04:50 238872 ——w- c:\windows\system32\MpSigStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2013-06-27 23:11 579024 —-a-w- c:\program files\Google\Drive\googledrivesync32.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2013-06-27 20097696] "8CB61047070556905AB7FB604CF2473F5483F0D5._service_run"="c:\program files\Google\Chrome\Application\chrome.exe" [2013-08-24 829392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104] "RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 4186112] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-01-11 483328] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Sophos AutoUpdate Monitor"="c:\program files\Sophos\AutoUpdate\almon.exe" [2013-02-15 929272] . c:\users\Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE /tsr [2008-10-25 98696] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe 9999 [2007-1-14 528384] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Sophos\SOPHOS~1\sophos_detoured.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200804] Ime File REG_SZ GOOGLEPINYIN2.IME . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService] @="service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus] "DisableMonitoring"=dword:00000001 . R2 swi_update;Sophos Web Intelligence Update;c:\programdata\Sophos\Web Intelligence\swi_update.exe [2013-03-24 1468920] R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2013-01-18 33696] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2013-01-17 1343400] R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2013-01-18 22536] S1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2013-02-15 132424] S1 SKMScan;SKMScan;c:\windows\system32\DRIVERS\skmscan.sys [2013-02-15 33096] S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2013-02-15 217592] S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2013-02-15 159296] S2 Sophos Web Control Service;Sophos Web Control Service;c:\program files\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [2013-01-18 357400] S2 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2013-03-24 2890232] S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-08-29 15:09 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.62\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2013-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-01-17 06:41] . 2013-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-01-17 06:41] . . ——- Supplementary Scan ——- . uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uStart Page = hxxp://en.us.acer.yahoo.com uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 LSP: c:\programdata\Sophos\Web Intelligence\swi_ifslsp.dll TCP: DhcpNameServer = 192.168.2.1 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\windows\system32\agrsmsvc.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Sophos\AutoUpdate\ALsvc.exe c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe c:\program files\Google\Update\1.3.21.153\GoogleCrashHandler.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Google\Update\Install\{A822CF16-1DF5-4F97-B66B-5BCE9B667AC3}\29.0.1547.66_29.0.1547.62_chrome_updater.exe c:\windows\TEMP\CR_780D0.tmp\setup.exe c:\windows\system32\taskhost.exe c:\program files\Google\Google Pinyin 2\GooglePinyinDaemon.exe c:\program files\Google\Google Pinyin 2\GooglePinyinService.exe c:\windows\system32\conhost.exe . ************************************************************************** . Completion time: 2013-09-05 22:17:30 - machine was rebooted ComboFix-quarantined-files.txt 2013-09-06 05:17 . Pre-Run: 47,889,240,064 bytes free Post-Run: 47,476,752,384 bytes free . - - End Of File - - 9B367FBEB463E77E6D11D5DB5AD31899 E90AA6BE22E8268A3764331202F9CFB0
I am not sure what ComboFix removed. What I saw is that now there is an item, hips/regmod-016, captured by my Sophos anti-virus program. It was not there before; this only occurred after ComboFix scan.
Ok thanks.

Seems like maybe Sophos alerted you to something when ComboFix was running. You can read more about it here, but I don't think that this is a problem.

How is your system running other than that though? :)
Let's check to see if anything is in there hiding…

[external image: Posted Image] Please download Malwarebytes Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:

Windows 2000 & Windows XP:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Windows Vista & Win7:
C:\Users\\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
———-

ESET Online Scanner

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI