This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Infection [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can someone help me please? I don't know whether it's just my Internet connection or my laptop is infected. It's really slow, like, loading a browser takes too long or it just don't load at all.

 

Thank you for your help in advance. :)

Hello xxxerotech, welcome to WhatTheTech's Malware Removal forum!
 
My username is LiquidTension, but you can call me Adam. I will be assisting you with your malware-related problems.
If you would allow me to call you by your first name I would prefer that.  :)
 
======================================================
 
Please read through the points below to ensure this process moves as quickly and efficiently as possible.

  • Please ensure you read through my instructions thoroughly, and carry out each step in the order specified.
  • Please do not post logs using the CODE, QUOTE or ATTACHMENT format. Logs should be posted directly in plain text. If you receive an error whilst posting, please break the log in half and use multiple posts.
  • Please do not run any tools or take any steps other than those I provide for you. Independent efforts may make matters worse, and will affect my ability in ascertaining the current situation and providing the best set of instructions for you.
  • Please backup important files before proceeding with my instructions. Malware removal can be unpredictable.  
  • If you come across any issues whilst following my instructions, please stop and inform me of the issue in as much detail as possible. Please do not hesitate to ask before proceeding.
  • Topics are locked if no response is made after 4 days. Please inform me if you require additional time to complete my instructions.
  • Ensure you are following this topic. Click [external image: etYzdbu.png] at the top of the page. 
     

======================================================
 
Please run the following diagnostic scans so I can ascertain the state of your computer.
 
STEP 1

[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Scan

  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply. 
     

STEP 2
[external image: YARWD1t.png.pagespeed.ce.nvhmVeYDe3.png] TDSSKiller Scan

  • Please download TDSSKiller and save the file to your Desktop.
  • Right-Click TDSSKiller.exe and select [external image: xAVOiBNU.jpg.pagespeed.ic.H5HC6LkiJX.jpg] Run as administrator to run the programme.
  • Click Change parameters. Place a checkmark next to Detect TDLFS file system and Verify file digital signatures.
  • ​Click Start Scan. Do not use the computer during the scan.
  • If objects are found, change the action to skip.
  • Click Continue and close the window.
  • A log will be created and saved to the root directory (usually C:\). Attach the file in your next reply.
     

======================================================
 
STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • FRST.txt
  • Addition.txt
  • TDSSKiller log (attached)

Hi, Adam. Thank you for taking the time to help me out. My name is Ryan.

 

I was only able to run the scan for FRST. As for the TDSSKiller, I got an error message: Invalid access to memory location. I tried to run the TDSSKiller, not as an Administrator, to see if it will work; but I got an erro message: tdsskiller.exe is not a valid Win32 application.

 

Here are the logs for FRST.

 

FRST

 

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01
Ran by [removed] (administrator) on USER-PC on 31-01-2015 19:23:05
Running from C:\Users\[removed]\Downloads
[removed] Platform: Microsoft® Windows Vista™ Home Premium  Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Malwarebytes Corporation) C:\D-drive-96751\Malwarebytes' Anti-Malware\mbamscheduler.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
() C:\Program Files\Smart Bro\AssistantServices.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
() C:\Windows\PLFSetI.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
(cyberlink) C:\Program Files\CyberLink\Shared Files\brs.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(RealNetworks, Inc.) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Smart Bro\UIExec.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Realtek Semiconductor Corp.) C:\Users\user\AppData\Local\temp\RtkBtMnt.exe
() C:\Program Files\Smart Bro\UIMain.exe
() C:\Program Files\Smart Bro\CMUpdater.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Windows\RtHDVCpl.exe [4472832 2007-05-28] (Realtek Semiconductor)
HKLM\…\Run: [Skytel] => C:\Windows\Skytel.exe [1826816 2007-05-28] (Realtek Semiconductor Corp.)
HKLM\…\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2007-10-23] ()
HKLM\…\Run: [RemoteControl8] => C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe [83240 2008-03-21] (Cyberlink Corp.)
HKLM\…\Run: [BDRegion] => C:\Program Files\Cyberlink\Shared Files\brs.exe [91432 2008-03-21] (cyberlink)
HKLM\…\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31072 2008-10-25] (Microsoft Corporation)
HKLM\…\Run: [TkBellExe] => C:\Program Files\Common Files\Real\Update_OB\realsched.exe [202256 2010-09-23] (RealNetworks, Inc.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-04] (Adobe Systems Incorporated)
HKLM\…\Run: [OLPSYNCH] => C:\Program Files\Offline Course Player\OlpSynch.exe
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\…\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\…\Run: [UIExec] => C:\Program Files\SMART BRO\UIExec.exe [139088 2011-04-02] ()
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\…\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\…\Run: [ISUSPM] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [213936 2006-05-17] (Macrovision Corporation)
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\…\Run: [Facebook Update] => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-07-02] (Facebook Inc.)
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\…\RunOnce: [Adobe Speed Launcher] => 1422675461
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
URLSearchHook: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} -  No File
SearchScopes: HKLM -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {22663A6E-F025-42F6-B440-5476F25B04FA} URL = http://ph.search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {8B2BE058-0BDE-464F-B4DF-E3AE0C712653} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo.com/search?fr=mcafee&p;={searchTerms}
BHO: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll No File
Toolbar: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
Tcpip\..\Interfaces\{ADDC55A4-81C7-4A27-9E54-D027BE216942}: [NameServer] 121.1.3.172 121.1.3.89

FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\8m0iqaze.default
FF SearchEngineOrder.1: NationSearch
FF Homepage: about:home
FF NetworkProxy: "no_proxies_on", ""
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Content Upload Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Content Uploader\npUpload.dll No File
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.12.775 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.3.775 -> c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=1.0.0.0 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.775 -> c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-722566208-2681290114-2279458060-1000: @facebook.com/FBPlugin,version=1.0.3 -> C:\Users\user\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll No File
FF Plugin HKU\S-1-5-21-722566208-2681290114-2279458060-1000: @leeuu.com/npgboxruner;version= -> C:\Users\user\AppData\Roaming\gbox\npgboxruner.dll No File
FF Plugin HKU\S-1-5-21-722566208-2681290114-2279458060-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-722566208-2681290114-2279458060-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\user\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF user.js: detected! => C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\8m0iqaze.default\user.js
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOlp32.dll (Element K Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\…\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-04-09]
FF HKLM\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-09-23]
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: No Name - C:\Program Files\McAfee\SiteAdvisor [2009-09-17]

Chrome:
=======
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\27.0.1453.94\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.6.4) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U13) - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U18) - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (RealPlayer™ HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) ) - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Chrome NaCl) - C:\Program Files\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\27.0.1453.94\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll No File
CHR Plugin: (Facebook Plugin) - C:\Users\user\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - D:\itunes\Mozilla Plugins\npitunes.dll No File
CHR Plugin: (RealJukebox NS Plugin) - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (Default Plug-in) - default_plugin No File
CHR Profile: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-01-04]
CHR Extension: (Google Search) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-01-04]
CHR Extension: (SiteAdvisor) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2011-10-30]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2010-09-27]
CHR Extension: (Gmail) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-01-04]
CHR HKLM\…\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\user\AppData\Local\Temp\crxA94C.tmp [Not Found]
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx [Not Found]
CHR HKLM\…\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2010-09-23]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 MBAMScheduler; C:\D-drive-96751\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\D-drive-96751\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 UI Assistant Service; C:\Program Files\Smart Bro\AssistantServices.exe [253264 2011-01-24] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
S2 FreeAgentGoNext Service; D:\Sync\FreeAgentService.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 ampa; C:\Windows\system32\ampa.sys [12728 2011-12-26] () [File not signed]
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [1123328 2007-10-09] (Broadcom Corp.) [File not signed]
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [147912 2013-09-23] (McAfee, Inc.)
S3 massfilter; C:\Windows\System32\drivers\massfilter.sys [9216 2011-03-26] (MBB Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 tapvpn; C:\Windows\System32\DRIVERS\tapvpn.sys [27136 2008-01-24] (The OpenVPN Project) [File not signed]
R3 ZTEusbvoice; C:\Windows\System32\DRIVERS\ZTEusbvoice.sys [107776 2011-03-26] (ZTE Incorporated)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 hwusbfake; system32\DRIVERS\ewusbfake.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-31 19:23 - 2015-01-31 19:24 - 00019844 _____ () C:\Users\user\Downloads\FRST.txt
2015-01-31 19:22 - 2015-01-31 19:23 - 00000000 ___DC () C:\FRST
2015-01-31 00:33 - 2015-01-31 00:36 - 02670708 _____ () C:\Users\user\Downloads\tdsskiller.exe
2015-01-31 00:20 - 2015-01-31 00:27 - 01034935 _____ () C:\Users\user\Downloads\FRST64.exe
2015-01-31 00:16 - 2015-01-31 00:18 - 01121792 _____ (Farbar) C:\Users\user\Downloads\FRST.exe
2015-01-28 22:08 - 2015-01-29 14:35 - 00001365 _____ () C:\Users\user\Desktop\Transcription Exam.txt
2015-01-28 19:42 - 2015-01-28 19:42 - 00000714 _____ () C:\Windows\setupact.log
2015-01-28 19:42 - 2015-01-28 19:42 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-28 19:39 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbvoice.sys
2015-01-28 19:39 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbser6k.sys
2015-01-28 19:39 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbnmea.sys
2015-01-28 19:39 - 2011-03-26 10:37 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbmdm6k.sys
2015-01-28 19:39 - 2011-03-26 10:37 - 00009216 _____ (MBB Incorporated) C:\Windows\system32\Drivers\massfilter.sys
2015-01-28 19:38 - 2015-01-28 19:38 - 00001477 _____ () C:\Users\Public\Desktop\SMART BRO.lnk
2015-01-28 19:38 - 2015-01-28 19:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMART BRO
2015-01-28 08:44 - 2013-07-03 10:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2015-01-28 01:55 - 2012-06-04 23:26 - 00440704 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-01-28 01:55 - 2012-06-02 08:04 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-01-28 01:55 - 2012-06-02 08:03 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-01-28 01:55 - 2011-11-17 00:23 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-01-28 01:55 - 2011-11-17 00:21 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-01-28 01:55 - 2011-11-16 22:12 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-01-28 01:54 - 2013-02-12 09:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2015-01-28 01:48 - 2015-01-28 01:49 - 00691112 _____ (Yahoo! Inc.) C:\Users\user\Downloads\msgr11ph(2).exe
2015-01-28 01:07 - 2015-01-28 01:07 - 00001878 _____ () C:\Users\Public\Desktop\Skype.lnk
2015-01-28 01:07 - 2015-01-28 01:07 - 00000000 ___RD () C:\Program Files\Skype
2015-01-28 01:07 - 2015-01-28 01:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-01-28 01:07 - 2015-01-28 01:07 - 00000000 ____D () C:\Program Files\Common Files\Skype
2015-01-28 00:24 - 2015-01-28 00:56 - 44836968 _____ (Skype Technologies S.A.) C:\Users\user\Downloads\SkypeSetupFull.exe
2015-01-27 22:05 - 2015-01-27 22:06 - 00524288 _____ (Yahoo! Inc.) C:\Users\user\Downloads\msgr11ph(1).exe
2015-01-27 19:10 - 2015-01-27 19:10 - 00000000 ____D () C:\Users\user\AppData\Local\TeamViewer
2015-01-27 19:08 - 2015-01-27 19:08 - 00000756 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-01-27 19:08 - 2015-01-27 19:08 - 00000744 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-01-27 01:07 - 2015-01-27 01:08 - 00639912 _____ (Oracle Corporation) C:\Users\user\Downloads\jxpiinstall.exe
2015-01-27 00:59 - 2015-01-27 01:00 - 00691112 _____ (Yahoo! Inc.) C:\Users\user\Downloads\msgr11ph.exe

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-31 19:20 - 2009-07-14 01:16 - 00000420 ____H () C:\Windows\Tasks\User_Feed_Synchronization-{ADB7C4EF-9010-443B-B014-92A8A5210DCF}.job
2015-01-31 19:18 - 2008-01-21 09:35 - 01647451 _____ () C:\Windows\WindowsUpdate.log
2015-01-31 19:17 - 2011-11-10 03:04 - 00000000 ____D () C:\Program Files\Smart Bro
2015-01-31 19:00 - 2013-07-02 06:55 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000UA.job
2015-01-31 18:49 - 2014-02-11 01:49 - 00000284 _____ () C:\Windows\Tasks\FoxTab.job
2015-01-31 17:50 - 2006-11-02 20:47 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-31 17:50 - 2006-11-02 20:47 - 00003712 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-31 11:32 - 2014-02-03 21:45 - 00000000 ____D () C:\Users\user\AppData\Local\Battle.net
2015-01-31 07:00 - 2013-07-02 06:55 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000Core.job
2015-01-31 00:52 - 2012-05-04 07:42 - 00000000 ____D () C:\Users\user\AppData\Roaming\vlc
2015-01-30 23:50 - 2006-11-02 21:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-30 16:44 - 2009-04-07 01:08 - 00000012 _____ () C:\Windows\bthservsdp.dat
2015-01-30 16:44 - 2006-11-02 21:01 - 00032626 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-30 06:04 - 2011-11-09 23:10 - 00000000 ____D () C:\Users\user\AppData\Roaming\Orbit
2015-01-30 03:46 - 2014-02-05 18:00 - 00000000 ____D () C:\Program Files\Hearthstone
2015-01-29 21:11 - 2014-02-25 21:31 - 00000000 ____D () C:\Users\user\Desktop\FOLDERS
2015-01-29 20:13 - 2006-11-02 18:33 - 00755222 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-29 16:42 - 2006-11-02 20:47 - 00380760 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-29 16:41 - 2012-05-16 09:24 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-29 16:41 - 2006-01-10 04:00 - 00137944 _____ () C:\Windows\PFRO.log
2015-01-29 10:31 - 2009-04-10 13:58 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-29 10:29 - 2009-04-07 00:12 - 00100432 _____ () C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-28 19:38 - 2011-11-11 00:12 - 00000000 ____D () C:\Windows\system32\SupportAppCB
2015-01-28 19:38 - 2009-04-07 01:03 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2015-01-28 09:41 - 2006-01-10 06:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-28 02:15 - 2010-07-01 22:56 - 00000000 ____D () C:\Users\user\AppData\Roaming\Skype
2015-01-28 02:00 - 2014-09-07 07:04 - 00000000 ____D () C:\Users\user\Desktop\start over
2015-01-28 01:08 - 2009-07-15 00:34 - 00000000 ____D () C:\ProgramData\Skype
2015-01-27 19:09 - 2014-08-04 11:04 - 00000000 ____D () C:\Program Files\TeamViewer
2015-01-27 01:09 - 2012-01-26 22:23 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-01-27 01:08 - 2009-04-07 02:13 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-01-19 14:50 - 2013-08-07 19:43 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-19 04:03 - 2012-04-08 02:14 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-01-19 04:03 - 2012-04-08 02:14 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-01-19 03:18 - 2014-07-21 22:26 - 00000000 ____D () C:\Users\user\AppData\Local\Adobe
2015-01-13 19:19 - 2009-04-07 01:35 - 00144896 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-08 23:55 - 2013-08-13 20:28 - 00000000 ____D () C:\Users\user\AppData\Roaming\Azureus

==================== Files in the root of some directories =======

2014-02-11 01:56 - 2014-02-16 15:09 - 0000124 _____ () C:\Users\user\AppData\Roaming\Camdata.ini
2014-02-11 01:56 - 2014-02-16 15:09 - 0000408 _____ () C:\Users\user\AppData\Roaming\CamLayout.ini
2014-02-11 01:56 - 2014-02-16 15:09 - 0000408 _____ () C:\Users\user\AppData\Roaming\CamShapes.ini
2014-02-11 01:56 - 2014-02-16 15:09 - 0004546 _____ () C:\Users\user\AppData\Roaming\CamStudio.cfg
2012-08-12 03:07 - 2012-08-12 03:08 - 0061525 _____ () C:\Users\user\AppData\Roaming\Express.dmp
2012-08-04 19:13 - 2012-09-09 17:19 - 0045194 _____ () C:\Users\user\AppData\Roaming\room_v3.dat
2009-04-09 17:41 - 2009-04-09 17:41 - 0572595 _____ () C:\Users\user\AppData\Roaming\UserTile.png
2014-02-11 01:52 - 2014-02-16 14:55 - 0000096 _____ () C:\Users\user\AppData\Roaming\version2.xml
2014-02-11 01:49 - 2014-02-12 00:49 - 0000087 _____ () C:\Users\user\AppData\Roaming\WB.CFG
2009-04-07 00:12 - 2014-11-11 21:05 - 0006324 _____ () C:\Users\user\AppData\Local\d3d9caps.dat
2009-04-07 01:35 - 2015-01-13 19:19 - 0144896 _____ () C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-07-06 11:39 - 2014-07-06 11:39 - 0000832 _____ () C:\Users\user\AppData\Local\recently-used.xbel
2009-08-14 20:01 - 2009-08-14 20:01 - 0000032 _____ () C:\ProgramData\ezsid.dat
2009-07-18 05:30 - 2009-07-18 05:30 - 0000056 ____H () C:\ProgramData\ezsidmv.dat

Files to move or delete:
====================
C:\ProgramData\ezsid.dat
C:\Users\user\MBR.dat


Some content of TEMP:
====================
C:\Users\user\AppData\Local\temp\RtkBtMnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-31 12:00

==================== End Of Log ============================

 

ADDITION

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-01-2015 01
Ran by [removed] at 2015-01-31 19:24:57
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Crystal Eye Webcam (HKLM\…\{A77255C4-AFCB-44A3-BF0F-2091A71FFD9E}) (Version: 2.0.4 - SuYin)
Acer Crystal Eye Webcam (HKLM\…\{DD1DED37-2486-4F56-8F89-56AA814003F5}) (Version: 2.0.0.14 - Acer Crystal Eye Webcam)
Acrobat.com (HKLM\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1.377 - Adobe Systems Incorporated)
Acrobat.com (Version: 0.0.0 - Adobe Systems Incorporated) Hidden
Adobe AIR (HKLM\…\Adobe AIR) (Version: 1.0.4990 - Adobe Systems Inc.)
Adobe Flash Player 16 ActiveX (HKLM\…\Adobe Flash Player ActiveX) (Version: 16.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM\…\Adobe Flash Player NPAPI) (Version: 16.0.0.257 - Adobe Systems Incorporated)
Adobe Photoshop 7.0 (HKLM\…\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.)
Adobe Reader X (10.1.13) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.13 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.6 (HKLM\…\Adobe Shockwave Player) (Version: 11.6.3.633 - Adobe Systems, Inc.)
AVS Audio Editor 7.2 (HKLM\…\AVS Audio Editor_is1) (Version: 7.2.2.488 - Online Media Technologies Ltd.)
AVS Audio Recorder 4.0 (HKLM\…\AVS Audio Recorder_is1) (Version: 4.0.2.22 - Online Media Technologies Ltd.)
Battle.net (HKLM\…\Battle.net) (Version:  - Blizzard Entertainment)
CBR Reader (HKLM\…\{EDAAC216-AC73-4152-9654-E12FE5A69F5D}_is1) (Version:  - cbrreader.com)
CCleaner (HKLM\…\CCleaner) (Version: 2.29 - Piriform)
CyberLink PowerDVD 8 (HKLM\…\InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}) (Version: 8.0.1531 - CyberLink Corp.)
EPUB File Reader (HKLM\…\{818C5857-5C74-4CAC-9F43-E5597086852D}_is1) (Version:  - )
ESET Online Scanner v3 (HKLM\…\ESET Online Scanner) (Version:  - )
Express Scribe (HKLM\…\Scribe) (Version: 5.63 - NCH Software)
Ezvid (HKLM\…\{F96D619D-99D6-4C9C-A393-0CD22DE1CA66}_is1) (Version: 0978 - Ezvid, inc.)
Facebook Video Calling 3.1.0.521 (HKLM\…\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
FormatFactory 3.2.1.0 (HKLM\…\FormatFactory) (Version: 3.2.1.0 - Free Time)
GIMP 2.8.10 (HKLM\…\GIMP-2_is1) (Version: 2.8.10 - The GIMP Team)
Heroes of the Storm (HKLM\…\Heroes of the Storm) (Version:  - Blizzard Entertainment)
HTML Executable IERuntime (HKLM\…\HTMLExecutableIERuntimeSetup44) (Version: 3.2.2.2 - G.D.G. Software)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version:  - )
Java 7 Update 71 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
K-Lite Codec Pack 3.4.5 Full (HKLM\…\KLiteCodecPack_is1) (Version: 3.45 - )
Lagarith lossless video codec (Remove Only) (HKLM\…\LAGARITH) (Version:  - )
Malwarebytes Anti-Malware version 1.75.0.1300 (HKLM\…\Malwarebytes' Anti-Malware_is1) (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\…\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\…\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (HKLM\…\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 2 (SP2) (HKLM\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM\…\ENTERPRISE) (Version: 12.0.6425.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.4.304.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.60531.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 en-US) (HKLM\…\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Notepad++ (HKLM\…\Notepad++) (Version: 6.5.2 - Notepad++ Team)
Offline Course Player (HKLM\…\{3BC1AB78-2D98-4906-84B5-4230B5420DCC}) (Version: 04.0000.0008 - )
Orbit Downloader (HKLM\…\Orbit_is1) (Version:  - www.orbitdownloader.com)
RealPlayer (HKLM\…\RealPlayer 12.0) (Version:  - RealNetworks)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5423 - Realtek Semiconductor Corp.)
RealUpgrade 1.0 (Version: 1.0.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller 1.93 (HKLM\…\Revo Uninstaller) (Version: 1.93 - VS Revo Group)
Seagate Manager Installer (HKLM\…\InstallShield_{3F5CFC1C-653B-4B22-9153-2BDDF2E03C0E}) (Version: 2.01.0700 - Seagate)
Seagate Manager Installer (Version: 2.01.0700 - Seagate) Hidden
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
SketchUp 2013 (HKLM\…\{B75BC01B-4586-43F8-9349-D250DB98F26F}) (Version: 13.0.4812 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SMART BRO (HKLM\…\{A9E5EDA7-2E6C-49E7-924B-A32B89C24A04}) (Version: 1.0.0.1 - ZTE)
Steam (HKLM\…\Steam) (Version:  - Valve Corporation)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 10 (HKLM\…\TeamViewer) (Version: 10.0.36897 - TeamViewer)
Texas Instruments PCIxx21/x515/xx12 drivers. (HKLM\…\InstallShield_{BE1826A9-7EEE-492A-B3BC-DEF3DFAE37EE}) (Version: 2.00.0002 - Texas Instruments Inc.)
TIPCI (Version: 2.00.0002 - Texas Instruments Inc.) Hidden
Update for 2007 Microsoft Office System (KB967642) (HKLM\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Outlook 2007 Junk Email Filter (kb2279264) (HKLM\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{01D475AB-57B1-44CC-8A8F-3A6B0FA4989F}) (Version:  - Microsoft)
VCRedistSetup (Version: 1.0.0 - Nero AG) Hidden
VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
Vuze (HKLM\…\8461-7759-5462-8226) (Version: 5.0.0.0 - Azureus Software, Inc.)
WinRAR archiver (HKLM\…\WinRAR archiver) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\user\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\user\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{8B9F5BF4-0407-4BB2-9FED-4C0372DABD00}\localserver32 -> C:\Users\user\AppData\Local\Facebook\Video\Skype\FacebookVideoCallingProxy.exe (Skype Limited)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{CBE9C57E-FFA9-4123-8354-AD360D6DD3CC}\InprocServer32 -> C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File

==================== Restore Points  =========================

25-01-2015 05:48:03 Scheduled Checkpoint
27-01-2015 01:56:03 Windows Update
27-01-2015 17:26:59 Scheduled Checkpoint
28-01-2015 09:24:40 Windows Update
28-01-2015 19:34:51 Removed SMART BRO
28-01-2015 19:38:09 Installed SMART BRO
30-01-2015 10:09:50 Scheduled Checkpoint
31-01-2015 12:04:10 Scheduled Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2006-11-02 18:23 - 2013-07-27 07:25 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {04F10F95-38E5-4809-89B3-485DD16453A6} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000UA => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-07-02] (Facebook Inc.)
Task: {19A072B4-E913-440B-9EBF-B1E2483F24BC} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-722566208-2681290114-2279458060-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2010-06-03] (RealNetworks, Inc.)
Task: {1D6F003A-DB6C-495E-A5BD-CA5495097DC4} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-722566208-2681290114-2279458060-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2010-06-03] (RealNetworks, Inc.)
Task: {36D21C62-3FFC-4A86-8530-39B256EF258D} - System32\Tasks\RunAsStdUser Task => C:\Program Files\iWin Games\iWinGames.exe
Task: {3AD49039-5D80-4EE0-8F7A-3CBAFFE231DC} - System32\Tasks\{90E64AA1-0269-4355-9152-08DD78A6C295} => pcalua.exe -a F:\Setup.exe
Task: {3B88AE82-BFBD-46C8-A60A-0AE30FAA3CAF} - System32\Tasks\{812C581E-B475-473E-B0D4-47DAA29064CA} => C:\Program Files\Skype\Phone\Skype.exe [2014-12-11] (Skype Technologies S.A.)
Task: {3ECC3DB9-2A7A-43E6-BDCE-E6C20A228A1B} - System32\Tasks\{1CB9E06F-9A0A-4D0E-923B-B2BA1985C92F} => pcalua.exe -a C:\Windows\system32\ISUSPM.cpl -c Program Updates
Task: {41FCE233-7ADE-4452-B043-F990CA24D085} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000Core => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-07-02] (Facebook Inc.)
Task: {76022DF9-1BEF-4AA8-B602-D0AB1BF92A43} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
Task: {8E20B94C-BA08-40DF-8EF2-A1681CA14DAF} - System32\Tasks\{7004846C-4717-4ECF-889C-BDF113A3126F} => Firefox.exe http://ui.skype.com/ui/0/6.16.0.105/en/abandoninstall?source=lightinstaller&page;=tsInstall
Task: {9C0B4D86-6CE5-4DB9-94D5-2C778866083D} - System32\Tasks\FoxTab => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {B5677960-EB7B-4481-AE4F-69F2F6D5D121} - System32\Tasks\{5C2E9BE7-8CE2-4959-96E1-ED5954D09786} => pcalua.exe -a "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5X91NVXW\frostwire-4.17.2.windows[1].exe" -d C:\Users\user
Task: {D02A5942-EEF0-4D53-B69F-725C601FBF8A} - System32\Tasks\4628 => Wscript.exe C:\Users\user\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
Task: {D12A5607-1BE5-4BB8-BE1B-0959BBD58DD0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-19] (Adobe Systems Incorporated)
Task: {E1CD8D7A-1062-4B6F-836E-CC1E95A72E6A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Signature Update => c:\program files\windows defender\MpCmdRun.exe [2008-01-21] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000Core.job => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-722566208-2681290114-2279458060-1000UA.job => C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FoxTab.job => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\User_Feed_Synchronization-{ADB7C4EF-9010-443B-B014-92A8A5210DCF}.job => C:\Windows\system32\msfeedssync.exe

==================== Loaded Modules (whitelisted) =============

2015-01-28 19:38 - 2011-01-24 20:29 - 00253264 _____ () C:\Program Files\Smart Bro\AssistantServices.exe
2009-04-07 02:09 - 2007-09-20 22:34 - 00129024 _____ () C:\Program Files\WinRAR\rarext.dll
2012-06-18 23:24 - 2012-06-18 23:24 - 00260096 _____ () C:\Program Files\Notepad++\NppShell_05.dll
2009-04-07 00:36 - 2007-08-20 12:10 - 00249856 _____ () C:\Windows\system32\igfxTMM.dll
2009-04-07 02:03 - 2007-10-23 14:56 - 00200704 _____ () C:\Windows\PLFSetI.exe
2015-01-28 19:38 - 2011-04-02 10:44 - 00139088 _____ () C:\Program Files\Smart Bro\UIExec.exe
2015-01-28 19:38 - 2011-05-12 19:06 - 03325776 _____ () C:\Program Files\SMART BRO\UIMain.exe
2006-01-16 19:49 - 2009-04-11 14:28 - 00368640 _____ () C:\Windows\system32\msjetoledb40.dll
2012-05-06 18:20 - 2012-05-06 18:20 - 03449856 _____ () C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\ffdshow\ffdshow.ax
2009-08-11 21:19 - 2009-08-11 21:19 - 00797184 _____ () C:\Program Files\FreeTime\FormatFactory\FFModules\Filters\ac3filter.ax
2015-01-28 19:38 - 2011-05-12 19:38 - 00698208 _____ () C:\Program Files\SMART BRO\CMUpdater.exe
2015-01-28 19:38 - 2011-01-24 20:29 - 00238928 _____ () C:\Program Files\SMART BRO\UICommonDlg.dll
2015-01-28 19:38 - 2011-01-24 20:29 - 00349520 _____ () C:\Program Files\SMART BRO\UISkin.dll
2015-01-28 19:38 - 2011-01-24 20:29 - 00165712 _____ () C:\Program Files\SMART BRO\BIXml.dll
2015-01-28 19:38 - 2011-01-24 20:29 - 00617808 _____ () C:\Program Files\SMART BRO\UpdateAgent.dll
2013-12-21 17:31 - 2015-01-29 10:31 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


========================= Accounts: ==========================

Administrator (S-1-5-21-722566208-2681290114-2279458060-500 - Administrator - Disabled)
Guest (S-1-5-21-722566208-2681290114-2279458060-501 - Limited - Disabled)
user (S-1-5-21-722566208-2681290114-2279458060-1000 - Administrator - Enabled) => C:\Users\user

==================== Faulty Device Manager Devices =============

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: isatap.{ADDC55A4-81C7-4A27-9E54-D027BE216942}
Description: Microsoft ISATAP Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver

Name: Broadcom NetLink (TM) Gigabit Ethernet
Description: Broadcom NetLink (TM) Gigabit Ethernet
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Broadcom
Service: b57nd60x
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/31/2015 07:17:50 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={F0C4C133-6444-44D7-BDC1-0C1B0BA9306B}: The user user-PC\user dialed a connection named SmartBro which has failed. The error code returned on failure is 0.

Error: (01/31/2015 07:05:28 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={F19EB1C1-49FB-4358-9CC7-9448F3106687}: The user user-PC\user dialed a connection named SmartBro which has failed. The error code returned on failure is 0.

Error: (01/31/2015 07:00:12 PM) (Source: Google Update) (EventID: 20) (User: user-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (01/31/2015 04:00:12 PM) (Source: Google Update) (EventID: 20) (User: user-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (01/31/2015 01:00:13 PM) (Source: Google Update) (EventID: 20) (User: user-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=IE, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80

Error: (01/30/2015 11:51:43 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 11:31:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 10:02:38 AM) (Source: Google Update) (EventID: 20) (User: user-PC)
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://www.facebook.com/omaha/update.php
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=FireFox, direct connection.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned

Error: (01/30/2015 08:21:08 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/30/2015 01:36:01 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application plugin-container.exe, version 35.0.1.5500, time stamp 0x54c1f9f3, faulting module mozalloc.dll, version 35.0.1.5500, time stamp 0x54c1f224, exception code 0x80000003, fault offset 0x00001425,
process id 0x11b0, application start time 0xplugin-container.exe0.


System errors:
=============
Error: (01/31/2015 11:33:46 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {C2BFE331-6739-4270-86C9-493D9A04CD38}

Error: (01/31/2015 00:26:42 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.191.3527.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.4.0304.00

    Source Path: 4.4.0304.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (01/31/2015 00:26:42 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.

    New Signature Version:

    Previous Signature Version: 1.191.3527.0

    Update Source: %NT AUTHORITY59

    Update Stage: 4.4.0304.00

    Source Path: 4.4.0304.01

    Signature Type: %NT AUTHORITY602

    Update Type: %NT AUTHORITY604

    User: NT AUTHORITY\SYSTEM

    Current Engine Version: %NT AUTHORITY605

    Previous Engine Version: %NT AUTHORITY606

    Error code: %NT AUTHORITY607

    Error description: %NT AUTHORITY608

Error: (01/30/2015 11:52:55 PM) (Source: DCOM) (EventID: 10000) (User: )
Description: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe -Embedding740{FFF2D28F-E4EE-44D9-8104-8E71556757F6}

Error: (01/30/2015 11:51:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}%%2

Error: (01/30/2015 11:51:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058

Error: (01/30/2015 11:50:59 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 412) (User: NT AUTHORITY)
Description: 2147942402

Error: (01/30/2015 00:03:32 PM) (Source: DCOM) (EventID: 10000) (User: )
Description: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe -Embedding740{FFF2D28F-E4EE-44D9-8104-8E71556757F6}

Error: (01/30/2015 11:31:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}%%2

Error: (01/30/2015 11:31:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Parallel port driver%%1058


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-01-15 21:17:37.165
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-15 21:17:36.771
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-15 21:17:36.388
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-15 21:17:35.959
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:07.818
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:07.417
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:07.011
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:06.608
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:06.197
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-01-11 18:38:05.789
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume1\Windows\System32\drivers\mbamchameleon.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
Percentage of memory in use: 57%
Total physical RAM: 2037.68 MB
Available physical RAM: 860.68 MB
Total Pagefile: 4314.62 MB
Available Pagefile: 3004.34 MB
Total Virtual: 2047.88 MB
Available Virtual: 1901.16 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.05 GB) (Free:19.76 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (SMART BRO modem) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: BE2EBE2E)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End Of Log ============================

Hi Ryan, 
 

As for the TDSSKiller, I got an error message: Invalid access to memory location. I tried to run the TDSSKiller, not as an Administrator, to see if it will work; but I got an erro message: tdsskiller.exe is not a valid Win32 application.

OK, thank you for letting me know. 
 
When did you run ComboFix? 
 
Please consider the following warning, and proceed with the instructions below. 
 

[external image: goGMWSt.gif]P2P Warning

——————————

I see you have peer-to-peer (P2P) file sharing software installed on your computer (Orbit Downloader & Vuze). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infected and infested with malware - worms, backdoor Trojans, IRCBots, and rootkits propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans, and spyware. The best way to reduce the risk of infection is to avoid these types of web sites and not use P2P applications. Please read the following articles for more information.

  • Risks of File-Sharing Technology
  • P2P Software User Advisories
  • More malware is traveling on P2P networks these days
Your P2P software can be removed by following the instructions below.
  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for the aforementioned programme(s), right-click and click Uninstall.
If you choose not to, please refrain from using the programme(s) during this process.

 
STEP 1
[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    URLSearchHook: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} -  No File
    SearchScopes: HKLM -> DefaultScope value is missing.
    SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {22663A6E-F025-42F6-B440-5476F25B04FA} URL = http://ph.search.yah…p={SearchTerms}
    SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo….p={searchTerms}
    BHO: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
    BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File
    Toolbar: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File
    Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File
    FF SearchEngineOrder.1: NationSearch
    CHR HKLM\…\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\user\AppData\Local\Temp\crxA94C.tmp [Not Found]
    2015-01-31 18:49 - 2014-02-11 01:49 - 00000284 _____ () C:\Windows\Tasks\FoxTab.job
    CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
    CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
    CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
    Task: {76022DF9-1BEF-4AA8-B602-D0AB1BF92A43} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION
    Task: {9C0B4D86-6CE5-4DB9-94D5-2C778866083D} - System32\Tasks\FoxTab => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
    Task: {B5677960-EB7B-4481-AE4F-69F2F6D5D121} - System32\Tasks\{5C2E9BE7-8CE2-4959-96E1-ED5954D09786} => pcalua.exe -a "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5X91NVXW\frostwire-4.17.2.windows[1].exe" -d C:\Users\user
    Task: {D02A5942-EEF0-4D53-B69F-725C601FBF8A} - System32\Tasks\4628 => Wscript.exe C:\Users\user\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION
    Task: C:\Windows\Tasks\FoxTab.job => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
    C:\Users\user\AppData\Roaming\FoxTab
    CMD: type C:\ComboFix.txt
    CMD: ipconfig /flushdns
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.
     

STEP 2
[external image: b8zkrsY.png] Browser Reset
 
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.

  • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png] Internet Explorer: Backup Internet Explorer Favourites
  • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg] Firefox: Backup Firefox Bookmarks
  • [external image: U5NwUGc.png] Chrome: Backup Chrome Bookmarks
     

Proceed with the reset once done.

  • [external image: xehzOq95.png.pagespeed.ic.1o1xpAkZbO.png] Internet Explorer: How to reset Internet Explorer settings
  • [external image: xQlf57ne.png.pagespeed.ic.SnwgqhVB9v.jpg] Firefox: Reset Firefox
  • [external image: U5NwUGc.png] Chrome: Chrome - Reset browser settings
     

STEP 3
[external image: iAdP9bf.png] Malwarebytes Anti-Rootkit (MBAR)

  • Please download Malwarebytes Anti-Rootkit and save the file to your Desktop.
  • Double-click MBAR.exe to run the installer.
  • Select a convenient location to extract the contents and click OK. Navigate to the location you selected.
  • Right-Click MBAR.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts to update the programme and scan your computer. 
  • Upon completion, click Cleanup and reboot your computer. 
  • After the reboot, rerun the programme to verify no threats remain. If threats are still detected, click the Cleanup button once more. 
  • Upon completion, two logs (mbar-log.txt and system-log.txt) will be created. Copy the contents of both logs and paste in your next reply. Both logs can be found in the MBAR folder. 
     

STEP 4
[external image: aA7bkRO.png] aswMBR

  • Please download aswMBR and save the file to your Desktop. 
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click aswMBR.exe and select [external image: xAVOiBNU.jpg.pagespeed.ic.H5HC6LkiJX.jpg] Run as administrator to run the programme.
  • Click Yes when prompted to download avast! virus definitions. Wait until AVAST engine defs: ### appears. 
  • If you are prompted to enable the use of "Virtualization Technology", click Yes.
  • Click the AV Scan: drop down box and click C:\.
  • Click Scan. 
  • Upon completion, you will see Scan finished successfully. Click Save log. Save the log to your Desktop. 
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.

Note: Do NOT click Fix or FixMBR.
Note: A file (MBR.dat) will be created on your Desktop. Do NOT click or delete it.
 
 
======================================================
 
STEP 5
[external image: xpfNZP4A.png.pagespeed.ic.bp5cRl1pJg.jpg] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Fixlog.txt
  • Did your browsers reset OK? 
  • mbar-log.txt
  • system-log.txt
  • aswMBR log

I don't remember when was the last time I ran ComboFix.

 

1. Here is the copy of the log for FRST.exe.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-02-2015

Ran by [removed] at 2015-02-03 21:54:43 Run:1

Running from C:\Users\[removed]\Downloads

[removed]

Boot Mode: Normal

 

==============================================

 

Content of fixlist:

*****************

start

CreateRestorePoint:

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

URLSearchHook: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} -  No File

SearchScopes: HKLM -> DefaultScope value is missing.

SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {22663A6E-F025-42F6-B440-5476F25B04FA} URL = http://ph.search.yah…p={SearchTerms}

SearchScopes: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> {DECA3892-BA8F-44b8-A993-A466AD694AE4} URL = http://search.yahoo….p={searchTerms}

BHO: Octh Class -> {000123B4-9B42-4900-B3F7-F4B073EFC214} -> C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} ->  No File

Toolbar: HKU\S-1-5-21-722566208-2681290114-2279458060-1000 -> No Name - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} -  No File

Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File

Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} -  No File

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} -  No File

FF SearchEngineOrder.1: NationSearch

CHR HKLM\…\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\user\AppData\Local\Temp\crxA94C.tmp [Not Found]

2015-01-31 18:49 - 2014-02-11 01:49 - 00000284 _____ () C:\Windows\Tasks\FoxTab.job

CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File

CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File

CustomCLSID: HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File

Task: {76022DF9-1BEF-4AA8-B602-D0AB1BF92A43} - System32\Tasks\0 => Iexplore.exe  <==== ATTENTION

Task: {9C0B4D86-6CE5-4DB9-94D5-2C778866083D} - System32\Tasks\FoxTab => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

Task: {B5677960-EB7B-4481-AE4F-69F2F6D5D121} - System32\Tasks\{5C2E9BE7-8CE2-4959-96E1-ED5954D09786} => pcalua.exe -a "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5X91NVXW\frostwire-4.17.2.windows[1].exe" -d C:\Users\user

Task: {D02A5942-EEF0-4D53-B69F-725C601FBF8A} - System32\Tasks\4628 => Wscript.exe C:\Users\user\AppData\Local\Temp\launchie.vbs //B <==== ATTENTION

Task: C:\Windows\Tasks\FoxTab.job => C:\Users\user\AppData\Roaming\FoxTab\UPDATE~1\UPDATE~1.EXE <==== ATTENTION

C:\Users\user\AppData\Roaming\FoxTab

CMD: type C:\ComboFix.txt

CMD: ipconfig /flushdns

EmptyTemp:

end

*****************

 

Restore point was successfully created.

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.

HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.

HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.

HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} => value deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{22663A6E-F025-42F6-B440-5476F25B04FA}" => Key deleted successfully.

HKCR\CLSID\{22663A6E-F025-42F6-B440-5476F25B04FA} => Key not found.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}" => Key deleted successfully.

HKCR\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4} => Key not found.

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}" => Key deleted successfully.

"HKCR\CLSID\{000123B4-9B42-4900-B3F7-F4B073EFC214}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}" => Key deleted successfully.

HKCR\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => Key not found.

HKU\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} => value deleted successfully.

HKCR\CLSID\{C55BBCD6-41AD-48AD-9953-3609C48EACC7} => Key not found.

"HKCR\PROTOCOLS\Handler\dssrequest" => Key deleted successfully.

HKCR\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => Key not found.

"HKCR\PROTOCOLS\Handler\sacore" => Key deleted successfully.

HKCR\CLSID\{5513F07E-936B-4E52-9B00-067394E91CC5} => Key not found.

"HKCR\PROTOCOLS\Filter\application/x-mfe-ipt" => Key deleted successfully.

HKCR\CLSID\{3EF5086B-5478-4598-A054-786C45D75692} => Key not found.

Firefox SearchEngineOrder.1 deleted successfully.

"HKLM\SOFTWARE\Google\Chrome\Extensions\bejbohlohkkgompgecdcbbglkpjfjgdj" => Key deleted successfully.

C:\Windows\Tasks\FoxTab.job => Moved successfully.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}" => Key deleted successfully.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}" => Key deleted successfully.

"HKU\S-1-5-21-722566208-2681290114-2279458060-1000_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{76022DF9-1BEF-4AA8-B602-D0AB1BF92A43}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{76022DF9-1BEF-4AA8-B602-D0AB1BF92A43}" => Key deleted successfully.

C:\Windows\System32\Tasks\0 => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\0" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9C0B4D86-6CE5-4DB9-94D5-2C778866083D}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C0B4D86-6CE5-4DB9-94D5-2C778866083D}" => Key deleted successfully.

C:\Windows\System32\Tasks\FoxTab => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FoxTab" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5677960-EB7B-4481-AE4F-69F2F6D5D121}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5677960-EB7B-4481-AE4F-69F2F6D5D121}" => Key deleted successfully.

C:\Windows\System32\Tasks\{5C2E9BE7-8CE2-4959-96E1-ED5954D09786} => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5C2E9BE7-8CE2-4959-96E1-ED5954D09786}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D02A5942-EEF0-4D53-B69F-725C601FBF8A}" => Key deleted successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D02A5942-EEF0-4D53-B69F-725C601FBF8A}" => Key deleted successfully.

C:\Windows\System32\Tasks\4628 => Moved successfully.

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4628" => Key deleted successfully.

C:\Windows\Tasks\FoxTab.job not found.

"C:\Users\user\AppData\Roaming\FoxTab" => File/Directory not found.

 

=========  type C:\ComboFix.txt =========

 

The system cannot find the file specified.

 

========= End of CMD: =========

 

 

=========  ipconfig /flushdns =========

 

 

Windows IP Configuration

 

Successfully flushed the DNS Resolver Cache.

 

========= End of CMD: =========

 

EmptyTemp: => Removed 1.3 GB temporary data.

 

 

The system needed a reboot.

 

==== End of Fixlog 22:00:54 ====

 

2. I have successfully reset the browser.

 

3. I ran the MBAR.exe but I got an error message: Non 7z archive.

 

4. Here is the copy of the log for aswMBR.exe

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software

Run date: 2015-02-03 23:43:18

—————————–

23:43:18.635    OS Version: Windows 6.0.6002 Service Pack 2

23:43:18.636    Number of processors: 2 586 0xF0D

23:43:18.639    ComputerName: USER-PC  UserName: user

23:43:23.144    Initialize success

23:43:23.170    VM: initialized successfully

23:43:23.173    VM: Intel CPU virtualization not supported

23:50:52.846    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3

23:50:52.869    Disk 0 Vendor: TOSHIBA_MK1646GSX LB113J Size: 152627MB BusType: 3

23:50:53.151    Disk 0 MBR read successfully

23:50:53.159    Disk 0 MBR scan

23:50:53.165    Disk 0 Windows VISTA default MBR code

23:50:53.182    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS       152623 MB offset 2048

23:50:53.221    Disk 0 scanning sectors +312574642

23:50:53.435    Disk 0 scanning C:\Windows\system32\drivers

23:51:14.152    Service scanning

23:51:33.437    Service MpKsl378ee1a3 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D31DAC76-7FCE-41A8-9BEA-9A0D5BAE2E79}\MpKsl378ee1a3.sys **LOCKED** 32

23:51:49.717    Modules scanning

23:51:49.737    Disk 0 trace - called modules:

23:51:50.244    ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS intelide.sys PCIIDEX.SYS atapi.sys

23:51:50.259    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85dc63b0]

23:51:50.271    3 CLASSPNP.SYS[88da28b3] -> nt!IofCallDriver -> [0x85c92f08]

23:51:50.289    5 acpi.sys[806a06bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0x85cb4030]

23:51:50.302    Disk 0 statistics 71259/0/0 @ 3.69 MB/s

23:51:50.314    Scan finished successfully

23:52:47.735    Disk 0 MBR has been saved successfully to "C:\Users\user\Desktop\MBR.dat"

23:52:47.764    The log file has been saved successfully to "C:\Users\user\Desktop\aswMBR.txt"

 

5. I have done everything except number 3.

Hi Adam,

 

I run the TDSSKiller and there were no objecs found. Here is the log.

 

00:43:31.0012 0x1588  TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04
00:43:45.0908 0x1588  ============================================================
00:43:45.0908 0x1588  Current date / time: 2015/02/06 00:43:45.0908
00:43:45.0908 0x1588  SystemInfo:
00:43:45.0909 0x1588  
00:43:45.0909 0x1588  OS Version: 6.0.6002 ServicePack: 2.0
00:43:45.0909 0x1588  Product type: Workstation
00:43:45.0909 0x1588  ComputerName: USER-PC
00:43:45.0909 0x1588  UserName: user
00:43:45.0910 0x1588  Windows directory: C:\Windows
00:43:45.0910 0x1588  System windows directory: C:\Windows
00:43:45.0910 0x1588  Processor architecture: Intel x86
00:43:45.0910 0x1588  Number of processors: 2
00:43:45.0910 0x1588  Page size: 0x1000
00:43:45.0910 0x1588  Boot type: Normal boot
00:43:45.0910 0x1588  ============================================================
00:43:51.0459 0x1588  KLMD registered as C:\Windows\system32\drivers\58550998.sys
00:43:54.0265 0x1588  System UUID: {1E91A994-F547-1B3D-18D3-1ADA0222D589}
00:44:02.0803 0x1588  Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
00:44:03.0420 0x1588  ============================================================
00:44:03.0420 0x1588  \Device\Harddisk0\DR0:
00:44:03.0428 0x1588  MBR partitions:
00:44:03.0428 0x1588  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A17AB2
00:44:03.0428 0x1588  ============================================================
00:44:03.0770 0x1588  C: <-> \Device\Harddisk0\DR0\Partition1
00:44:04.0061 0x1588  ============================================================
00:44:04.0061 0x1588  Initialize success
00:44:04.0061 0x1588  ============================================================
01:00:57.0536 0x0f34  ============================================================
01:00:57.0536 0x0f34  Scan started
01:00:57.0536 0x0f34  Mode: Manual; SigCheck; TDLFS;
01:00:57.0536 0x0f34  ============================================================
01:00:57.0536 0x0f34  KSN ping started
01:00:59.0462 0x0f34  KSN ping finished: true
01:01:01.0230 0x0f34  ================ Scan system memory ========================
01:01:01.0230 0x0f34  System memory - ok
01:01:01.0231 0x0f34  ================ Scan services =============================
01:01:01.0535 0x0f34  [ 82B296AE1892FE3DBEE00C9CF92F8AC7, 54B22BA63E1DA616B546992141B0C3117BA057283B8F60CB9BECE203661FEBF3 ] ACPI            C:\Windows\system32\drivers\acpi.sys
01:01:01.0861 0x0f34  ACPI - ok
01:01:02.0061 0x0f34  [ 4C72FDD915D62EAEF149BD9C73AB9CF4, 8EA45A1B88DFD819F0ADA3AF36D464E1BF52574269592370E0CC8D0490680E1F ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
01:01:02.0355 0x0f34  AdobeARMservice - ok
01:01:02.0495 0x0f34  [ CB1719E3EA00A0C114A8AD2655F43754, B38D21C4A7A83904CADEBA96A56AA5D1807C412A8E0BEFC889DF20D02941E570 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
01:01:02.0590 0x0f34  AdobeFlashPlayerUpdateSvc - ok
01:01:02.0678 0x0f34  [ 04F0FCAC69C7C71A3AC4EB97FAFC8303, FBBDD38574A1F66A5AA12B82E34FDE60B870180C4B7100C15757539DC869ED4B ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
01:01:02.0766 0x0f34  adp94xx - ok
01:01:02.0829 0x0f34  [ 60505E0041F7751BDBB80F88BF45C2CE, 1DE16042B8ABD7B643189E836DE273832EE743FD66AFBB641E8049C4E0CD04D8 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
01:01:02.0894 0x0f34  adpahci - ok
01:01:02.0934 0x0f34  [ 8A42779B02AEC986EAB64ECFC98F8BD7, B89938EFF4E81FA44197D2D839EBD3340DDE01FBC79605049C088621784C1B91 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
01:01:02.0977 0x0f34  adpu160m - ok
01:01:03.0007 0x0f34  [ 241C9E37F8CE45EF51C3DE27515CA4E5, 1A03E93DD8C1F3640C96124A14A3D0F4E349B06CCA2118CE40B8AE201A4030A7 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
01:01:03.0051 0x0f34  adpu320 - ok
01:01:03.0135 0x0f34  [ 9D1FDA9E086BA64E3C93C9DE32461BCF, 200FD0BFC811EC8993AF9FC78F58823ECC717063F438B627FBCDD6BD7790CAA8 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
01:01:03.0662 0x0f34  AeLookupSvc - ok
01:01:03.0792 0x0f34  [ A201207363AA900ABF1A388468688570, C772D8546BBA93553AFCD553B7CF50C252B1F8B45A4A415014B48308F1D7ECD6 ] AFD             C:\Windows\system32\drivers\afd.sys
01:01:03.0945 0x0f34  AFD - ok
01:01:04.0029 0x0f34  [ 13F9E33747E6B41A3FF305C37DB0D360, 066DD6060B1CF93F85BBAAA52848C801128CD294E8B7EACD912E0EF219DBFBC2 ] agp440          C:\Windows\system32\drivers\agp440.sys
01:01:04.0062 0x0f34  agp440 - ok
01:01:04.0110 0x0f34  [ AE1FDF7BF7BB6C6A70F67699D880592A, B831BF156FC49287A19FC149383D437B1034EA6F42CE9D761EB90ABD0F8D96B1 ] aic78xx         C:\Windows\system32\drivers\djsvs.sys
01:01:04.0147 0x0f34  aic78xx - ok
01:01:04.0191 0x0f34  [ A1545B731579895D8CC44FC0481C1192, 6B0EE833BA39C142D625A03586CCD8F6C9C3136C603CE5DF5BAC1AA3423E3E7F ] ALG             C:\Windows\System32\alg.exe
01:01:04.0380 0x0f34  ALG - ok
01:01:04.0414 0x0f34  [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91, 0EADB6AE21FEDAB55D41F41B638198B556CC2BE2EE57F6C8B40EB044A318319F ] aliide          C:\Windows\system32\drivers\aliide.sys
01:01:04.0447 0x0f34  aliide - ok
01:01:04.0525 0x0f34  [ C47344BC706E5F0B9DCE369516661578, 689C9CDAF6F38227F1C34359CAEB3C7798F318EDFD4B7FE532FBE3C8E4EE3DC8 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
01:01:04.0557 0x0f34  amdagp - ok
01:01:04.0606 0x0f34  [ 9B78A39A4C173FDBC1321E0DD659B34C, 2CA66EB68AD7A317D91C13B8CFD4E8CA985926A610D19595B613F5553B145C7B ] amdide          C:\Windows\system32\drivers\amdide.sys
01:01:04.0636 0x0f34  amdide - ok
01:01:04.0666 0x0f34  [ 18F29B49AD23ECEE3D2A826C725C8D48, 0FA08882301D218E367E63E1966B6406220EE94BAE7E7DAD6E55EB70BF6FED7F ] AmdK7           C:\Windows\system32\drivers\amdk7.sys
01:01:04.0765 0x0f34  AmdK7 - ok
01:01:04.0795 0x0f34  [ 93AE7F7DD54AB986A6F1A1B37BE7442D, ECE0ABA2DECEED94AC678240A4B604F04022F0740F2295CBD07D25F5917E878A ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
01:01:04.0930 0x0f34  AmdK8 - ok
01:01:05.0007 0x0f34  [ 47E6301D245AB061B9853B90A46AE55A, 0E6690018AEE241BE3073570C2FD4C270447024FCB2A518E4D3BB1775777282D ] ampa            C:\Windows\system32\ampa.sys
01:01:05.0427 0x0f34  ampa - detected UnsignedFile.Multi.Generic ( 1 )
01:01:06.0922 0x0f34  Detect skipped due to KSN trusted
01:01:06.0922 0x0f34  ampa - ok
01:01:06.0996 0x0f34  [ C6D704C7F0434DC791AAC37CAC4B6E14, 35CF7D1895F97637E0C678A39F3049B871BCA9526D379C7793ED33B87D2EAC4C ] Appinfo         C:\Windows\System32\appinfo.dll
01:01:07.0088 0x0f34  Appinfo - ok
01:01:07.0179 0x0f34  [ 5D2888182FB46632511ACEE92FDAD522, 2E53231ACAF9B2FB7993DBC1CD15C06D7B0CCE0D08DAFF7B0CC13A2040028A75 ] arc             C:\Windows\system32\drivers\arc.sys
01:01:07.0212 0x0f34  arc - ok
01:01:07.0258 0x0f34  [ 5E2A321BD7C8B3624E41FDEC3E244945, 9D47FF6C823868F2267FEFAB5851D3CD2BC3F619A2D6EFF803EA22DB0509C450 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
01:01:07.0300 0x0f34  arcsas - ok
01:01:07.0473 0x0f34  [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
01:01:07.0504 0x0f34  aspnet_state - ok
01:01:07.0553 0x0f34  [ 53B202ABEE6455406254444303E87BE1, 4C91CA8DD345FEDD74A6AF2C07580717703F979B7DE2532B1D00B9F6896DDE70 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
01:01:07.0660 0x0f34  AsyncMac - ok
01:01:07.0694 0x0f34  [ 1F05B78AB91C9075565A9D8A4B880BC4, 737BE9F9376DAB0CCDFED93EA6D67F0C432367EA63CD772A453485BE769AF3BD ] atapi           C:\Windows\system32\drivers\atapi.sys
01:01:07.0730 0x0f34  atapi - ok
01:01:07.0813 0x0f34  [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
01:01:07.0911 0x0f34  AudioEndpointBuilder - ok
01:01:07.0948 0x0f34  [ 68E2A1A0407A66CF50DA0300852424AB, 5FFDAE4E477C90A855081B5120582810471F67D3E9C343779A7AFB8D684D16F8 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
01:01:08.0029 0x0f34  Audiosrv - ok
01:01:08.0110 0x0f34  [ 502F1C30BD50B32D00CE4DCAECC3D3C7, F1F74D821C0D436C438313B522704F5DCA38A008725B74C2F6659ACAABDB210C ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
01:01:08.0262 0x0f34  b57nd60x - ok
01:01:08.0438 0x0f34  [ E9EA635B8432D68F0005B3F6CEBAB837, 62E9C7AE02836457EB50C816B6BCB671F2918FD5A451415257077A4CC99CA2AB ] BCM43XX         C:\Windows\system32\DRIVERS\bcmwl5.sys
01:01:08.0750 0x0f34  BCM43XX - detected UnsignedFile.Multi.Generic ( 1 )
01:01:11.0091 0x0f34  Detect skipped due to KSN trusted
01:01:11.0092 0x0f34  BCM43XX - ok
01:01:11.0159 0x0f34  [ 67E506B75BD5326A3EC7B70BD014DFB6, 3B07243970CAB4E93A858BEA6E31F56AD0157C42D624F3FEB469E68EEEF65669 ] Beep            C:\Windows\system32\drivers\Beep.sys
01:01:11.0340 0x0f34  Beep - ok
01:01:11.0436 0x0f34  [ C789AF0F724FDA5852FB9A7D3A432381, 4B0F7A3A8F2D45E49630D24F2630B8014BCDB793B9C6E83FD2B2863A54F62BF5 ] BFE             C:\Windows\System32\bfe.dll
01:01:11.0592 0x0f34  BFE - ok
01:01:11.0696 0x0f34  [ 93952506C6D67330367F7E7934B6A02F, 1D9A6B10B9489C1A32F730E22CC399BFF0796E3FCB3BA52BE45ED487CAC59EBD ] BITS            C:\Windows\system32\qmgr.dll
01:01:11.0871 0x0f34  BITS - ok
01:01:11.0925 0x0f34  [ D4DF28447741FD3D953526E33A617397, E7239BA432090F8AC7DF453DB876507CD4419ECA964D289408A1B2B353618693 ] blbdrive        C:\Windows\system32\drivers\blbdrive.sys
01:01:11.0997 0x0f34  blbdrive - ok
01:01:12.0028 0x0f34  [ 74B442B2BE1260B7588C136177CEAC66, CB489B0BDA6833297707499B3B3A166D1CF4CF4C1D734F0222D696B06C680E87 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
01:01:12.0117 0x0f34  bowser - ok
01:01:12.0160 0x0f34  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
01:01:12.0226 0x0f34  BrFiltLo - ok
01:01:12.0247 0x0f34  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
01:01:12.0310 0x0f34  BrFiltUp - ok
01:01:12.0341 0x0f34  [ A3629A0C4226F9E9C72FAAEEBC3AD33C, FB4D2738B64AADA52B95A6CF7ED4CDBFE4DD4BEBCAF1AE9CE64317F97DB38DDF ] Browser         C:\Windows\System32\browser.dll
01:01:12.0445 0x0f34  Browser - ok
01:01:12.0489 0x0f34  [ B304E75CFF293029EDDF094246747113, CB6B219B186C3511A0DE3CDE7F7B8966A9E32D808A952CA8C5B42B3A3A17BFB0 ] Brserid         C:\Windows\system32\drivers\brserid.sys
01:01:12.0743 0x0f34  Brserid - ok
01:01:12.0784 0x0f34  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
01:01:12.0978 0x0f34  BrSerWdm - ok
01:01:13.0005 0x0f34  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
01:01:13.0136 0x0f34  BrUsbMdm - ok
01:01:13.0167 0x0f34  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
01:01:13.0293 0x0f34  BrUsbSer - ok
01:01:13.0355 0x0f34  [ 6D39C954799B63BA866910234CF7D726, 1D807C3410C01C76E5810D626F23C1CCED3C9C5A65F39267B770C494C8D64114 ] BthEnum         C:\Windows\system32\DRIVERS\BthEnum.sys
01:01:13.0458 0x0f34  BthEnum - ok
01:01:13.0514 0x0f34  [ 9A966A8E86D1771911AE34A20D11BFF3, FBD5F621A47A3530B325816E71F0C4BCE5CCE731C57DEBD42ACFC8BCAA258656 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
01:01:13.0571 0x0f34  BTHMODEM - ok
01:01:13.0619 0x0f34  [ 5904EFA25F829BF84EA6FB045134A1D8, 66E4160CC404744576BA6E9DD606B533F42B3D4A3E2FDD457DAA016CC72A81CC ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
01:01:13.0711 0x0f34  BthPan - ok
01:01:13.0806 0x0f34  [ 5A3ABAA2F8EECE7AEFB942773766E3DB, E10A284B8587EC3B033DDBEAAB9CF0FCC698088BEF4F3B1E6DFCBCD177AF126B ] BTHPORT         C:\Windows\system32\Drivers\BTHport.sys
01:01:13.0941 0x0f34  BTHPORT - ok
01:01:13.0989 0x0f34  [ A4C8377FA4A994E07075107DBE2E3DCE, C3CDAA7B83D130100044341C23897CC6C257FA075A8D08B8551F4A28AE8CE6C4 ] BthServ         C:\Windows\System32\bthserv.dll
01:01:14.0061 0x0f34  BthServ - ok
01:01:14.0089 0x0f34  [ 94E2941280E3756A5E0BCB467865C43A, 5A7B30F69D645881717BD78066E62337EB4A081F54E6B5898662C4BEBF59925F ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
01:01:14.0152 0x0f34  BTHUSB - ok
01:01:14.0211 0x0f34  catchme - ok
01:01:14.0261 0x0f34  [ 7ADD03E75BEB9E6DD102C3081D29840A, 0CA14A77CE990B5AA32C0725C22CA190ECBC73B75064DD959CABAD79B8846F1D ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
01:01:14.0350 0x0f34  cdfs - ok
01:01:14.0405 0x0f34  [ 6B4BFFB9BECD728097024276430DB314, 4451EFEAD37B05C8A3CB610B6D72E73B55D3D1E1CC1B17405598C1EDAA93C2D5 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
01:01:14.0645 0x0f34  cdrom - ok
01:01:14.0714 0x0f34  [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] CertPropSvc     C:\Windows\System32\certprop.dll
01:01:14.0800 0x0f34  CertPropSvc - ok
01:01:14.0842 0x0f34  [ E5D4133F37219DBCFE102BC61072589D, 74C7F8C53D9C71CE3C8B33BC0331948571318402B0A8E1AC4552360504092A46 ] circlass        C:\Windows\system32\drivers\circlass.sys
01:01:14.0915 0x0f34  circlass - ok
01:01:14.0973 0x0f34  [ D7659D3B5B92C31E84E53C1431F35132, 6BFE644AD9890A8CEEDCC4B97ADD564AD57202FBC5D21599469E0C4B31BB27C6 ] CLFS            C:\Windows\system32\CLFS.sys
01:01:15.0023 0x0f34  CLFS - ok
01:01:15.0081 0x0f34  [ 8EE772032E2FE80A924F3B8DD5082194, B743DF91563A22CC15D9B44105804B5866A29D3DFC156DBE88DFAFEF903B94C0 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
01:01:15.0116 0x0f34  clr_optimization_v2.0.50727_32 - ok
01:01:15.0186 0x0f34  [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
01:01:15.0237 0x0f34  clr_optimization_v4.0.30319_32 - ok
01:01:15.0294 0x0f34  [ 99AFC3795B58CC478FBBBCDC658FCB56, 0D1B27C42A058C5D56A0157B5ECA9A054254F6B9C8015D0321021A7EFCE10CE2 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
01:01:15.0371 0x0f34  CmBatt - ok
01:01:15.0402 0x0f34  [ 0CA25E686A4928484E9FDABD168AB629, C2CB2333CAB40CDF93219870E66700F957188C86A1B1A004BC4652953091E5C5 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
01:01:15.0431 0x0f34  cmdide - ok
01:01:15.0458 0x0f34  [ 6AFEF0B60FA25DE07C0968983EE4F60A, E4037EF9EDE57A1039AB814EBCE9A8B12C9A084E7FAC6296212ACF2394DD37B6 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
01:01:15.0487 0x0f34  Compbatt - ok
01:01:15.0498 0x0f34  COMSysApp - ok
01:01:15.0518 0x0f34  [ 741E9DFF4F42D2D8477D0FC1DC0DF871, 06EA43D771E3455F943AB624CC00C2259FE5E561164908630755E933EF44A522 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
01:01:15.0549 0x0f34  crcdisk - ok
01:01:15.0575 0x0f34  [ 1F07BECDCA750766A96CDA811BA86410, F4E36F0003184BCB36D59B23AC903421AD8C0A1FD2D6315E06375235ABC9A0AD ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
01:01:15.0655 0x0f34  Crusoe - ok
01:01:15.0740 0x0f34  [ FB27772BEAF8E1D28CCD825C09DA939B, D074A314FB3E6B2248F2DB0A734B98A110F618804449E055B4178BF414826982 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
01:01:15.0803 0x0f34  CryptSvc - ok
01:01:15.0911 0x0f34  [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] DcomLaunch      C:\Windows\system32\rpcss.dll
01:01:16.0040 0x0f34  DcomLaunch - ok
01:01:16.0083 0x0f34  [ 218D8AE46C88E82014F5D73D0236D9B2, D404EE45EFC2557182DDD9C1B7244C10FC5AD3080A57CDFBF2C9D3B890F78852 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
01:01:16.0161 0x0f34  DfsC - ok
01:01:16.0383 0x0f34  [ 2CC3DCFB533A1035B13DCAB6160AB38B, C88C91F662ADE248EEE3B568E70C2BC2D5075B7D9B7D3C63E83D011C5F7812B0 ] DFSR            C:\Windows\system32\DFSR.exe
01:01:16.0787 0x0f34  DFSR - ok
01:01:16.0884 0x0f34  [ 9028559C132146FB75EB7ACF384B086A, 35159D86706441ED94895B4629411B4445FCB4526AFD1F7036EE647931B7A94D ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
01:01:16.0977 0x0f34  Dhcp - ok
01:01:17.0064 0x0f34  [ 5D4AEFC3386920236A548271F8F1AF6A, 11B74D6800EC6F7AAEFB0B6A9F2E8376C7C3B8DB677F03AC3743CB004CA96B08 ] disk            C:\Windows\system32\drivers\disk.sys
01:01:17.0112 0x0f34  disk - ok
01:01:17.0183 0x0f34  [ 30A08728740E71947AE1E073B5CE69B4, 6F313F09E17885A84F546E11215B4B451AAA0FFDF2E7A13211F862FAD18F5C8E ] Dnscache        C:\Windows\System32\dnsrslvr.dll
01:01:17.0271 0x0f34  Dnscache - ok
01:01:17.0330 0x0f34  [ 324FD74686B1EF5E7C19A8AF49E748F6, DC6EB4304555B60DD17E04D20DFE4E279718E4041A9310DE29E678834BB22C5B ] dot3svc         C:\Windows\System32\dot3svc.dll
01:01:17.0404 0x0f34  dot3svc - ok
01:01:17.0471 0x0f34  [ A622E888F8AA2F6B49E9BC466F0E5DEF, 3DED7F22A29AD2F8C927DFA0FD87FDE5ED0BDCAC7260BD9F71D8EA34328C772A ] DPS             C:\Windows\system32\dps.dll
01:01:17.0574 0x0f34  DPS - ok
01:01:17.0629 0x0f34  [ 97FEF831AB90BEE128C9AF390E243F80, A7F4118603E2D5DDDB117EF7C058684EA5B37690EFAB2BEBA570EEF9C36281BE ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
01:01:17.0719 0x0f34  drmkaud - ok
01:01:17.0816 0x0f34  [ C68AC676B0EF30CFBB1080ADCE49EB1F, 62A808F2BB22507B66AE825315BBB655776AFEFD9E7DE33795DD308ACE87F0CD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
01:01:17.0907 0x0f34  DXGKrnl - ok
01:01:17.0953 0x0f34  [ 5425F74AC0C1DBD96A1E04F17D63F94C, AD133CEDCDEA75420C75A91BB4CF7152475D46ED7B7703E3BAE5F9946D610292 ] E1G60           C:\Windows\system32\DRIVERS\E1G60I32.sys
01:01:18.0055 0x0f34  E1G60 - ok
01:01:18.0113 0x0f34  [ C0B95E40D85CD807D614E264248A45B9, 30421DAF1722A225222268CB8BA4FE60CB76C6FD0C9157B0F53FC1368F806A4E ] EapHost         C:\Windows\System32\eapsvc.dll
01:01:18.0192 0x0f34  EapHost - ok
01:01:18.0265 0x0f34  [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371, F3E9CF5D8E9124CB06F08454C5F0E510DE19A92780151FB2F8A58A0905D59B8F ] Ecache          C:\Windows\system32\drivers\ecache.sys
01:01:18.0310 0x0f34  Ecache - ok
01:01:18.0390 0x0f34  [ 9BE3744D295A7701EB425332014F0797, 1A139EE9232581E466591C5EBEF41E4BF1F82D99C1959F1C68C879B240E9F46D ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
01:01:18.0506 0x0f34  ehRecvr - ok
01:01:18.0540 0x0f34  [ AD1870C8E5D6DD340C829E6074BF3C3F, 064D07106A1BBE80294F1913354832F2B67D22274BB4D36C81D2D83C96FE0B88 ] ehSched         C:\Windows\ehome\ehsched.exe
01:01:18.0631 0x0f34  ehSched - ok
01:01:18.0654 0x0f34  [ C27C4EE8926E74AA72EFCAB24C5242C3, F1EBF78CCE9BA76AFD0478BC66B67CA44DEAF3C380369BFCE91BD8F678C8608A ] ehstart         C:\Windows\ehome\ehstart.dll
01:01:18.0714 0x0f34  ehstart - ok
01:01:18.0831 0x0f34  [ 23B62471681A124889978F6295B3F4C6, A90C521F06125B86A26EA625B0E7F811AF7D328E1313165E7AD4A83596A23819 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
01:01:18.0961 0x0f34  elxstor - ok
01:01:19.0078 0x0f34  [ 4E6B23DFC917EA39306B529B773950F4, C4BA77632B4BD46C4C1797F7F57399DB506D3EB6E5A0A36C269A793DAA3445C2 ] EMDMgmt         C:\Windows\system32\emdmgmt.dll
01:01:19.0249 0x0f34  EMDMgmt - ok
01:01:19.0297 0x0f34  [ 3DB974F3935483555D7148663F726C61, C288CFC04213B0340ABEC752C0A7B308B29122B5F51E68387BA1D9E9D7166FDD ] ErrDev          C:\Windows\system32\drivers\errdev.sys
01:01:19.0385 0x0f34  ErrDev - ok
01:01:19.0469 0x0f34  [ 67058C46504BC12D821F38CF99B7B28F, E8D19F305F78BCA1DA8425315F2C77A377CD51E3CC54323DC2FF355120EA097D ] EventSystem     C:\Windows\system32\es.dll
01:01:19.0566 0x0f34  EventSystem - ok
01:01:19.0644 0x0f34  [ 22B408651F9123527BCEE54B4F6C5CAE, 31AF9649333A9496A9224001266D1B68CE2A31B9FB182A755D127FC5492AA6B2 ] exfat           C:\Windows\system32\drivers\exfat.sys
01:01:19.0748 0x0f34  exfat - ok
01:01:19.0795 0x0f34  [ 1E9B9A70D332103C52995E957DC09EF8, 7E709D545D4025A2E9F3489CF2A231040904CB53E3E4EEAC15A22468FAB2A5B3 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
01:01:19.0874 0x0f34  fastfat - ok
01:01:19.0920 0x0f34  [ AFE1E8B9782A0DD7FB46BBD88E43F89A, B4CBE1DC3430F2F3485F49007C71293D5B86E9C405741EA00A67B00A38BE1F8D ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
01:01:20.0003 0x0f34  fdc - ok
01:01:20.0055 0x0f34  [ 6629B5F0E98151F4AFDD87567EA32BA3, 8CC02D5E0639CDF74B2F85DB56D6199E1858F1A58465ED1D8B25C968E986132C ] fdPHost         C:\Windows\system32\fdPHost.dll
01:01:20.0197 0x0f34  fdPHost - ok
01:01:20.0218 0x0f34  [ 89ED56DCE8E47AF40892778A5BD31FD2, 924360875796C3DDDDA8097FDF53F6846B227F7413766F00AEDD981EFD691BF9 ] FDResPub        C:\Windows\system32\fdrespub.dll
01:01:20.0364 0x0f34  FDResPub - ok
01:01:20.0399 0x0f34  [ A8C0139A884861E3AAE9CFE73B208A9F, 3B021D148A2989AAA46AE58E5FED8A2DCA25E9212C2FA7F922880EF5A077E49B ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
01:01:20.0435 0x0f34  FileInfo - ok
01:01:20.0456 0x0f34  [ 0AE429A696AECBC5970E3CF2C62635AE, 1ECC315C099D17835788B68F0DE00EC98DC5AEE8F329D739E0DB90A898F22244 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
01:01:20.0555 0x0f34  Filetrace - ok
01:01:20.0592 0x0f34  [ 85B7CF99D532820495D68D747FDA9EBD, 682D35D219D1AFBE51CF0AB03F2D3E15C940F5AF291C1A611A19F4D279143F3C ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
01:01:20.0670 0x0f34  flpydisk - ok
01:01:20.0749 0x0f34  [ 01334F9EA68E6877C4EF05D3EA8ABB05, 82F8AA6AD2B5077898773D4A5814819EAF0E872FFD95894E06FEDAB6EE92CF99 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
01:01:20.0800 0x0f34  FltMgr - ok
01:01:20.0941 0x0f34  [ 452FEAAB2A8DBB42ED751754CB2594F5, 26926CD9D323C5C757AA47057589949A128367987BE05607827A43ED973356B1 ] FontCache       C:\Windows\system32\FntCache.dll
01:01:21.0126 0x0f34  FontCache - ok
01:01:21.0214 0x0f34  [ C7FBDD1ED42F82BFA35167A5C9803EA3, 372FF71070D5ECE17342466A690737A0622E93C98DBED8172C49B0854F0012B7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
01:01:21.0247 0x0f34  FontCache3.0.0.0 - ok
01:01:21.0282 0x0f34  FreeAgentGoNext Service - ok
01:01:21.0341 0x0f34  [ 65EA8B77B5851854F0C55C43FA51A198, 150BE6C195094DBEAC4FD73CC1C31FF59B77A73944574E244D280EE2DE69DC2F ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
01:01:21.0414 0x0f34  Fs_Rec - ok
01:01:21.0438 0x0f34  [ 34582A6E6573D54A07ECE5FE24A126B5, 5F45DC38F8015AD90616EAD3B57820CCD284938A96B2C4E1FF5FC7BDEE8A848D ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
01:01:21.0477 0x0f34  gagp30kx - ok
01:01:21.0547 0x0f34  [ 8182FF89C65E4D38B2DE4BB0FB18564E, 2ACFA64D48BF7D25641EC5819C8722144284B8A8E071BF297C1881B07EEAFE88 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
01:01:21.0575 0x0f34  GEARAspiWDM - ok
01:01:21.0668 0x0f34  [ CD5D0AEEE35DFD4E986A5AA1500A6E66, DCED5126837292593F1C1B35DF18E3B631D6C0C6D0742B77C7B7742C55A7825F ] gpsvc           C:\Windows\System32\gpsvc.dll
01:01:21.0859 0x0f34  gpsvc - ok
01:01:21.0935 0x0f34  [ CB04C744BE0A61B1D648FAED182C3B59, 61DC0FF94325DAFCCB7B3980A48727EFBF1283FCF753EC16EF04C730525994C0 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
01:01:22.0095 0x0f34  HdAudAddService - ok
01:01:22.0237 0x0f34  [ 062452B7FFD68C8C042A6261FE8DFF4A, DD9873502456D3C058C6177AC223B28C71370E624FA0814C17EA3D93201F2B56 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
01:01:22.0407 0x0f34  HDAudBus - ok
01:01:22.0484 0x0f34  [ 1338520E78D90154ED6BE8F84DE5FCEB, 8531F1C5856983EBDA4C2B70162645ECE72FFFBA9FE7A28BCEDDF2169B7ECF9D ] HidBth          C:\Windows\system32\drivers\hidbth.sys
01:01:22.0616 0x0f34  HidBth - ok
01:01:22.0638 0x0f34  [ FF3160C3A2445128C5A6D9B076DA519E, DC1A70C80CD55F33B3AD5A21E86AF7C3086D8CC2DC6148C058E74A871E0BAD4A ] HidIr           C:\Windows\system32\drivers\hidir.sys
01:01:22.0777 0x0f34  HidIr - ok
01:01:22.0830 0x0f34  [ 84067081F3318162797385E11A8F0582, 11E32E3800CFCA37354388243F88D0239D622891BAC5483518A2BE5D1CA19015 ] hidserv         C:\Windows\System32\hidserv.dll
01:01:22.0888 0x0f34  hidserv - ok
01:01:22.0930 0x0f34  [ CCA4B519B17E23A00B826C55716809CC, 91AD0758A6185B0FBBE383BDB1B457FFB850477AFF8DE040DE9527A97D28EF62 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
01:01:23.0011 0x0f34  HidUsb - ok
01:01:23.0096 0x0f34  [ 156765F692192EA9039A6C4A809312FD, 73400BC5E5C92A2E7834CB8EB33B3D78BF73C875C98B1AD91B0112FBB8DB19E3 ] HipShieldK      C:\Windows\system32\drivers\HipShieldK.sys
01:01:23.0370 0x0f34  HipShieldK - ok
01:01:23.0437 0x0f34  [ D8AD255B37DA92434C26E4876DB7D418, C901EADDD93FC90C8F29F4B6DE808F8E4F486C877FC0AA27DA4ACDE17E28899D ] hkmsvc          C:\Windows\system32\kmsvc.dll
01:01:23.0529 0x0f34  hkmsvc - ok
01:01:23.0559 0x0f34  [ 16EE7B23A009E00D835CDB79574A91A6, 964AFE7D2F7E48C7DE7FDAB48F57ADC4AD44A0B2A9A03071E0E8D334007E5572 ] HpCISSs         C:\Windows\system32\drivers\hpcisss.sys
01:01:23.0590 0x0f34  HpCISSs - ok
01:01:23.0661 0x0f34  [ 46D67209550973257601A533E2AC5785, 3C0D97781947BA8532344AA5D9F3B684761B5B3263A0A294F4593E76EE41DB0C ] HSFHWAZL        C:\Windows\system32\DRIVERS\VSTAZL3.SYS
01:01:23.0809 0x0f34  HSFHWAZL - ok
01:01:23.0909 0x0f34  [ EC36F1D542ED4252390D446BF6D4DFD0, DB55D73726E96D3653C37EEBE628D48466D766A9EC1219ED735D5D8FF2822BE2 ] HSF_DPV         C:\Windows\system32\DRIVERS\VSTDPV3.SYS
01:01:24.0185 0x0f34  HSF_DPV - ok
01:01:24.0282 0x0f34  [ F870AA3E254628EBEAFE754108D664DE, B0444E7D246AA1982094030ACB991690F6A7DD3FB07B1BB6A1BC0F3AA9718A70 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
01:01:24.0434 0x0f34  HTTP - ok
01:01:24.0476 0x0f34  hwdatacard - ok
01:01:24.0515 0x0f34  hwusbdev - ok
01:01:24.0527 0x0f34  hwusbfake - ok
01:01:24.0583 0x0f34  [ C6B032D69650985468160FC9937CF5B4, 4D5A944C70037F35A9DBA4F49F174455FA80ED7EAEDAA143F0A2C0E05AE585D8 ] i2omp           C:\Windows\system32\drivers\i2omp.sys
01:01:24.0626 0x0f34  i2omp - ok
01:01:24.0674 0x0f34  [ 22D56C8184586B7A1F6FA60BE5F5A2BD, D96A2962848C1F59B143BFEC22EC48BD1C5A75D0EBCFD7FB965E66B85FF7D8CA ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
01:01:24.0792 0x0f34  i8042prt - ok
01:01:24.0849 0x0f34  [ 54155EA1B0DF185878E0FC9EC3AC3A14, 344A0793499261D2E4FF2FCCC70501329485F8E299EBC68953D07BA86F0D4729 ] iaStorV         C:\Windows\system32\drivers\iastorv.sys
01:01:24.0950 0x0f34  iaStorV - ok
01:01:25.0113 0x0f34  [ 98477B08E61945F974ED9FDC4CB6BDAB, C7E8F661F6FBF6AB493E950D2E70363496E155B1838CE7B490B981BD840B04FC ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
01:01:25.0334 0x0f34  idsvc - ok
01:01:25.0740 0x0f34  [ 04E385059DA704EC6659DDB1526C4193, 32AAB988AB3ADAFE649C5E32394853C423B424A3A1DCCAA823622CAAD2A9D864 ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
01:01:26.0109 0x0f34  igfx - ok
01:01:26.0165 0x0f34  [ 2D077BF86E843F901D8DB709C95B49A5, 78FF558A881F307858F5C7C74A748B8B2562AF3CAC7EA8639945609001D790CE ] iirsp           C:\Windows\system32\drivers\iirsp.sys
01:01:26.0197 0x0f34  iirsp - ok
01:01:26.0341 0x0f34  [ 9908D8A397B76CD8D31D0D383C5773C9, FFA6996BE9F11A81CB63C849C2400EB44A07706D1EEB7A3502D4110DAC3684A2 ] IKEEXT          C:\Windows\System32\ikeext.dll
01:01:26.0452 0x0f34  IKEEXT - ok
01:01:26.0666 0x0f34  [ 9438FE15DA89C6AACE8A79DB2C6F60C1, 9A298FFE670DBEAC0690AA3C39775AE93A85CAC268EDC445233EB3BF3785B5F0 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
01:01:26.0918 0x0f34  IntcAzAudAddService - ok
01:01:27.0020 0x0f34  [ 83AA759F3189E6370C30DE5DC5590718, 7406FE41EA8FB80052517318CB72E2641E92E579FAFAF5E8DDDFF0BF8DAE773A ] intelide        C:\Windows\system32\drivers\intelide.sys
01:01:27.0086 0x0f34  intelide - ok
01:01:27.0151 0x0f34  [ 224191001E78C89DFA78924C3EA595FF, E4EC9CAAEEEAEB30E13F4A8023AF687F29514667380DDFD638BBFFF1D5FC2563 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
01:01:27.0241 0x0f34  intelppm - ok
01:01:27.0328 0x0f34  [ 9AC218C6E6105477484C6FDBE7D409A4, FF30D09CD2A0F5BBEC309E953370F194B6F26BF4227E627B594AAA48B0F5D3C2 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
01:01:27.0427 0x0f34  IPBusEnum - ok
01:01:27.0487 0x0f34  [ 62C265C38769B864CB25B4BCF62DF6C3, CAF6BCE967104233E216464E4729B0275C3BD426D812F404AB0EE83A7F2063D8 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
01:01:27.0570 0x0f34  IpFilterDriver - ok
01:01:27.0618 0x0f34  [ 1998BD97F950680BB55F55A7244679C2, A4E8BB4C6B2AF4800BD5E0BA8725FD0927F8FB6751AEBF6DD16B59C414CCB9D8 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
01:01:27.0717 0x0f34  iphlpsvc - ok
01:01:27.0732 0x0f34  IpInIp - ok
01:01:27.0764 0x0f34  [ B25AAF203552B7B3491139D582B39AD1, EA9C38F512F40FF12975A6719E6FE4D7EA93A4B2497103E0FDA5A4CD6033C0A6 ] IPMIDRV         C:\Windows\system32\drivers\ipmidrv.sys
01:01:27.0845 0x0f34  IPMIDRV - ok
01:01:27.0894 0x0f34  [ 8793643A67B42CEC66490B2A0CF92D68, 8B1ED1314E4C6623824DD6B9C15A0F7F996F4D243BF0B305421251BE40850907 ] IPNAT           C:\Windows\system32\DRIVERS\ipnat.sys
01:01:27.0994 0x0f34  IPNAT - ok
01:01:28.0060 0x0f34  [ E50A95179211B12946F7E035D60AF560, 69765E2548BA708FF35545EC944DBA1940AD4065AF90E53B97A7792AC231DCF7 ] irda            C:\Windows\system32\DRIVERS\irda.sys
01:01:28.0151 0x0f34  irda - ok
01:01:28.0174 0x0f34  [ 109C0DFB82C3632FBD11949B73AEEAC9, 73B01426100256B7110DF0B74483AF1B62FC209612EEC29A7BF6DC31A7FBEFB6 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
01:01:28.0244 0x0f34  IRENUM - ok
01:01:28.0270 0x0f34  [ CBB0D940221A281BCFEAEA695BD1CDA5, D05D192019524A02FE3FAE6827B98A942FA1AD651BF7AA53530A8A6F4ADFB7EB ] Irmon           C:\Windows\System32\irmon.dll
01:01:28.0404 0x0f34  Irmon - ok
01:01:28.0424 0x0f34  [ 6C70698A3E5C4376C6AB5C7C17FB0614, 10FBCBA5A74AF5D136B152FD4D3DFA2A1F2CEBC3F979D5BA6DB98B3DCB2F7A07 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
01:01:28.0468 0x0f34  isapnp - ok
01:01:28.0544 0x0f34  [ 232FA340531D940AAC623B121A595034, 90C93F04D8A0094EEBD118F10223605B8169DA5F24C466F503CED5C014BD17B1 ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
01:01:28.0589 0x0f34  iScsiPrt - ok
01:01:28.0623 0x0f34  [ BCED60D16156E428F8DF8CF27B0DF150, 4934E9AB8A8A548548F0C63517F2BF4DE84B05E5C9C7C2AA6C1517B8F9C340D4 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
01:01:28.0653 0x0f34  iteatapi - ok
01:01:28.0681 0x0f34  [ 06FA654504A498C30ADCA8BEC4E87E7E, 651BC35A0A3D504573BBAB40DE81929BB18C9FC0CD7944FEAE0E99CD7658EA88 ] iteraid         C:\Windows\system32\drivers\iteraid.sys
01:01:28.0712 0x0f34  iteraid - ok
01:01:28.0740 0x0f34  [ 37605E0A8CF00CBBA538E753E4344C6E, B9A9FFDCE45B0830E277CF322C28ACB49372C16144B0F676B283BE5DAE9A7F30 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
01:01:28.0771 0x0f34  kbdclass - ok
01:01:28.0802 0x0f34  [ 18247836959BA67E3511B62846B9C2E0, 9623FF990A1C11A707C358CC9FDD4306C2992A8C766A50DAFC9534A283AA011D ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
01:01:28.0923 0x0f34  kbdhid - ok
01:01:28.0976 0x0f34  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] KeyIso          C:\Windows\system32\lsass.exe
01:01:29.0075 0x0f34  KeyIso - ok
01:01:29.0135 0x0f34  [ 4A1445EFA932A3BAF5BDB02D7131EE20, 9DD262ED72DF268FE024063788F54124E320D0775D8DC0C5CAD099CD5F655DA2 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
01:01:29.0207 0x0f34  KSecDD - ok
01:01:29.0269 0x0f34  [ 8078F8F8F7A79E2E6B494523A828C585, BB399993166853F0C01B7508649ECD7E7473238267BA8333D0441128FE656347 ] KtmRm           C:\Windows\system32\msdtckrm.dll
01:01:29.0410 0x0f34  KtmRm - ok
01:01:29.0474 0x0f34  [ 43446F197C74EF2030F84B3A4F39D570, 94915BEA9CF2E047AFF058DCE9819836A9BBC07122D2DCC5BD9269F9FA7D7FA8 ] LanmanServer    C:\Windows\System32\srvsvc.dll
01:01:29.0558 0x0f34  LanmanServer - ok
01:01:29.0604 0x0f34  [ 1DB69705B695B987082C8BAEC0C6B34F, D395B272F6B69D4A9FC3CDEFD812EF0DBFECF3C1B1C787C7CC1E1A1B091B8DB3 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
01:01:29.0707 0x0f34  LanmanWorkstation - ok
01:01:29.0749 0x0f34  [ D1C5883087A0C3F1344D9D55A44901F6, 608D67357AFDDD538D2C12C93EB0793ECA4EB3AF2BAB779E881C41F50E4AB911 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
01:01:29.0837 0x0f34  lltdio - ok
01:01:29.0889 0x0f34  [ 2D5A428872F1442631D0959A34ABFF63, E532C6ECFFB936EFF744CA57BDC6394C89E797B6B0822D04F1F3F35D9BDDD4F0 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
01:01:29.0986 0x0f34  lltdsvc - ok
01:01:30.0009 0x0f34  [ 35D40113E4A5B961B6CE5C5857702518, 453097AEF46ED48107395D9A1696AAC259FD6CEA8A655D38C5E246FDDAB81664 ] lmhosts         C:\Windows\System32\lmhsvc.dll
01:01:30.0126 0x0f34  lmhosts - ok
01:01:30.0187 0x0f34  [ C7E15E82879BF3235B559563D4185365, 98C9268ADF6BAEB0522BB84BE6C98D0D6D5EB4BD27BB61412D208232164C8435 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
01:01:30.0222 0x0f34  LSI_FC - ok
01:01:30.0256 0x0f34  [ EE01EBAE8C9BF0FA072E0FF68718920A, 655924440E611278998226299645BC72B3627A8A057286DC8D65A162CFBBE484 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
01:01:30.0290 0x0f34  LSI_SAS - ok
01:01:30.0344 0x0f34  [ 912A04696E9CA30146A62AFA1463DD5C, 1D336D47B9D1C8449F29CDB776C092235E3D70CE53D9440970533E376EB004D3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
01:01:30.0396 0x0f34  LSI_SCSI - ok
01:01:30.0433 0x0f34  [ 8F5C7426567798E62A3B3614965D62CC, 659810257D942C5F4168E1247868CDA990F2324AC9ACAA9A6211F64B7AC9EC6E ] luafv           C:\Windows\system32\drivers\luafv.sys
01:01:30.0520 0x0f34  luafv - ok
01:01:30.0623 0x0f34  [ D1A79F9CF0A0960DF4DAB08BEF847F43, 079ABB3C86B1C3CE38FCFD17523E9B1C7204F8AE61CDC63789B9D80B29EE28FB ] massfilter      C:\Windows\system32\drivers\massfilter.sys
01:01:30.0793 0x0f34  massfilter - ok
01:01:30.0859 0x0f34  [ 4470E3C1E0C3378E4CAB137893C12C3A, CA8E66356F0E671D5454E561E7EAD74DE25DCF53BE452369F96ECACFA8709489 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
01:01:31.0103 0x0f34  MBAMProtector - ok
01:01:31.0275 0x0f34  [ 65085456FD9A74D7F1A999520C299ECB, EA564BC913EF1B8A4CAA9242FC70F525B68CF1F3CA462F63B0B7215B93FE8530 ] MBAMScheduler   C:\D-drive-96751\Malwarebytes' Anti-Malware\mbamscheduler.exe
01:01:31.0337 0x0f34  MBAMScheduler - ok
01:01:31.0429 0x0f34  [ E0D7732F2D2E24B2DB3F67B6750295B8, AA5CA86AF1ACEC900F60339016B3DC55472DB40ADB99186005A7ABE67B7D66FC ] MBAMService     C:\D-drive-96751\Malwarebytes' Anti-Malware\mbamservice.exe
01:01:31.0522 0x0f34  MBAMService - ok
01:01:31.0566 0x0f34  [ AEF9BABB8A506BC4CE0451A64AADED46, D5608A703EA7E97F11ED4D029B4B820440B0C9317DB7D7DC0152253CD723DC07 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
01:01:31.0628 0x0f34  Mcx2Svc - ok
01:01:31.0671 0x0f34  [ 0001CE609D66632FA17B84705F658879, D5F9758BDC2B733307B565A74B33F5581FB425A5A9F32CCFA307DA1569EBD6CD ] megasas         C:\Windows\system32\drivers\megasas.sys
01:01:31.0701 0x0f34  megasas - ok
01:01:31.0754 0x0f34  [ C252F32CD9A49DBFC25ECF26EBD51A99, 47EC8F475AB62A00FAF989CD2C3ABDF2922588F75CC15C83CD99A62EF6400FB0 ] MegaSR          C:\Windows\system32\drivers\megasr.sys
01:01:31.0829 0x0f34  MegaSR - ok
01:01:31.0917 0x0f34  [ 7C4C76B39D5525C4A465E0BE32528E19, B7FE3B2AE7E8A936AFC0572A6C4F23327400EAD16B26B6E1193F1C9C3767B3E1 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
01:01:31.0950 0x0f34  Microsoft Office Groove Audit Service - ok
01:01:31.0991 0x0f34  [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] MMCSS           C:\Windows\system32\mmcss.dll
01:01:32.0063 0x0f34  MMCSS - ok
01:01:32.0084 0x0f34  [ E13B5EA0F51BA5B1512EC671393D09BA, 5B380D1B435D809CA201FD5ED075D42F3C6BA1A4EEDBC4040F7E3329F05A334A ] Modem           C:\Windows\system32\drivers\modem.sys
01:01:32.0164 0x0f34  Modem - ok
01:01:32.0192 0x0f34  [ 0A9BB33B56E294F686ABB7C1E4E2D8A8, 1E8031D51E074FDFB53E98E26DABF313B901C028D01196BFD402EED5D0A89595 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
01:01:32.0314 0x0f34  monitor - ok
01:01:32.0327 0x0f34  [ 5BF6A1326A335C5298477754A506D263, CC7F58E5955A448F6CE28D6D8EB98C7479E11F931B5C733CFE71A29B2E95923D ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
01:01:32.0359 0x0f34  mouclass - ok
01:01:32.0389 0x0f34  [ 93B8D4869E12CFBE663915502900876F, 7464DE60FAAD8793D855F1F86C3C865B3A3EE41C19A3E926D1BE4426E67F5EC2 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
01:01:32.0474 0x0f34  mouhid - ok
01:01:32.0504 0x0f34  [ BDAFC88AA6B92F7842416EA6A48E1600, 2CA8A7BB260016D6B7953980A94C45A3C5D41F7DC7E73EEFB1C18EA144749503 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
01:01:32.0538 0x0f34  MountMgr - ok
01:01:32.0641 0x0f34  [ 345477F02C308B7480702767218C86A2, 98AFB5CF35BD82BA44B8F52CBC5FA3760506ADD7892C2AA1A77E8DF71FC8523F ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
01:01:32.0680 0x0f34  MozillaMaintenance - ok
01:01:32.0776 0x0f34  [ E77DC03DD3C8E5A388BF9EED2A28F3D1, ED0DAA975D1EC35CE036F02596218E15CC6A054167628D12A0A5AD91B841F422 ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
01:01:32.0830 0x0f34  MpFilter - ok
01:01:32.0904 0x0f34  [ 511D011289755DD9F9A7579FB0B064E6, 1FD0D0D5B6E08FE06F7A5D0821BCD859B0F98A6DEA58AAB7FB6C95B64212FFC8 ] mpio            C:\Windows\system32\drivers\mpio.sys
01:01:32.0948 0x0f34  mpio - ok
01:01:33.0164 0x0f34  [ 65C34426C83EFA32D48380A97717997B, CD7EB6BFBB0BE382BA21055460D9A72323F09AF3194A22D8EDB28D5DB3BAE8E7 ] MpKsl4b851088   c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D041F4D6-54FF-4EC0-A3EB-23B7F49F17AE}\MpKsl4b851088.sys
01:01:33.0205 0x0f34  MpKsl4b851088 - ok
01:01:33.0228 0x0f34  [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E, 62055C0DCEB69873B8961AB17DBD002F44319A44CB05EC3A61421A0C6D4736CD ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
01:01:33.0314 0x0f34  mpsdrv - ok
01:01:33.0446 0x0f34  [ 5DE62C6E9108F14F6794060A9BDECAEC, 655E6645CC4A1EDBE5F51F5F80C7B504DD956851E788A6E4E4E08CDCDCE160D9 ] MpsSvc          C:\Windows\system32\mpssvc.dll
01:01:33.0564 0x0f34  MpsSvc - ok
01:01:33.0595 0x0f34  [ 4FBBB70D30FD20EC51F80061703B001E, 72907A0CA5CFF82F40C02A65CD8EFD51D7CFC33BE67DE572D1ACF4FD3B248F0A ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
01:01:33.0626 0x0f34  Mraid35x - ok
01:01:33.0680 0x0f34  [ 82CEA0395524AACFEB58BA1448E8325C, 16E37990A291C848DE35F48EA7E09AE5B258AE589EB08A3FA2C60DC1278DE182 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
01:01:33.0741 0x0f34  MRxDAV - ok
01:01:33.0796 0x0f34  [ 454341E652BDF5E01B0F2140232B073E, EC1DCF18FB95F253D40DC3DFD135F7FFFE6FB558B2A0182C6CD2DDB279AC9991 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
01:01:33.0874 0x0f34  mrxsmb - ok
01:01:33.0946 0x0f34  [ 2A4901AFF069944FA945ED5BBF4DCDE3, 6577BAFC739484BB21805D2C66A2DE048E2E22BBD27EA065813F5D939229492E ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
01:01:34.0034 0x0f34  mrxsmb10 - ok
01:01:34.0062 0x0f34  [ 28B3F1AB44BDD4432C041581412F17D9, 61F8AFABB1BCDF1B9FB5A64F21F896B6B34BB26582DABB9889F92D3863CB89EE ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
01:01:34.0122 0x0f34  mrxsmb20 - ok
01:01:34.0155 0x0f34  [ 28023E86F17001F7CD9B15A5BC9AE07D, FC7EAA592C5F796E3BCD7F7EF261709CD899B33FC8486E594A480F143D0D6320 ] msahci          C:\Windows\system32\drivers\msahci.sys
01:01:34.0186 0x0f34  msahci - ok
01:01:34.0216 0x0f34  [ 4468B0F385A86ECDDAF8D3CA662EC0E7, EAEDC9CDD2EEC5000AF8190A4BE7729282576C3F88E64FDF57F455F5CECC81C9 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
01:01:34.0254 0x0f34  msdsm - ok
01:01:34.0287 0x0f34  [ FD7520CC3A80C5FC8C48852BB24C6DED, C3F3D7A07FAB9AF38A2A00BF0DF6EEE18CA8FE26277BEC9D8ADB793F2CD5EC1F ] MSDTC           C:\Windows\System32\msdtc.exe
01:01:34.0370 0x0f34  MSDTC - ok
01:01:34.0416 0x0f34  [ A9927F4A46B816C92F461ACB90CF8515, 753284F726F9B4D3E7322C75532244CA43714F00717C2019391FB36DEE0738C0 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
01:01:34.0541 0x0f34  Msfs - ok
01:01:34.0578 0x0f34  [ 0F400E306F385C56317357D6DEA56F62, C48FA8193787359902D20D869F5F602CD66D3C5D061A58DDB72F51EED433C4BC ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
01:01:34.0611 0x0f34  msisadrv - ok
01:01:34.0646 0x0f34  [ 85466C0757A23D9A9AECDC0755203CB2, 79141B8DF9D7470466872AF03A85C3D3976512BFDBDB8B92A22225DC8EFD70A6 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
01:01:34.0744 0x0f34  MSiSCSI - ok
01:01:34.0774 0x0f34  msiserver - ok
01:01:34.0824 0x0f34  [ D8C63D34D9C9E56C059E24EC7185CC07, D0CBFB8D57E6D908679DC0488ED659CA35B92626DEA890873E165F051A1AD2AE ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
01:01:34.0909 0x0f34  MSKSSRV - ok
01:01:34.0977 0x0f34  [ B0F49DA36F30922F5DDC3B623B778FCE, EE025AEFA4A2095AFEABFB3A49639DA77D78068A3F5EEDA6C15D34853AFD5609 ] MsMpSvc         c:\Program Files\Microsoft Security Client\MsMpEng.exe
01:01:35.0017 0x0f34  MsMpSvc - ok
01:01:35.0040 0x0f34  [ 1D373C90D62DDB641D50E55B9E78D65E, 1D4897A96EA54D6FAC7916D69B4E88CAE1397C38CC8FAE08554772808476357B ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
01:01:35.0124 0x0f34  MSPCLOCK - ok
01:01:35.0141 0x0f34  [ B572DA05BF4E098D4BBA3A4734FB505B, B7923F204CEADD0F62C2FE4B7CF8C56DAB70F88093B15C5692D0E61490CF4BAA ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
01:01:35.0231 0x0f34  MSPQM - ok
01:01:35.0286 0x0f34  [ B49456D70555DE905C311BCDA6EC6ADB, 8E40586B3A1FAE9996459E0261726C9DD6A8D5F575604868C45604613385C92F ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
01:01:35.0333 0x0f34  MsRPC - ok
01:01:35.0380 0x0f34  [ E384487CB84BE41D09711C30CA79646C, 520391DEE14D4D6C1EA99C7D31DD95D56B44D54CA3CD8E5C9855E9C0A04F026C ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
01:01:35.0412 0x0f34  mssmbios - ok
01:01:35.0442 0x0f34  [ 7199C1EEC1E4993CAF96B8C0A26BD58A, DD02DF8ED7AF5BB88BD2A91F38CE4C52432CB8044BDCBC41C320CD22B10B8A3B ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
01:01:35.0530 0x0f34  MSTEE - ok
01:01:35.0564 0x0f34  [ 6A57B5733D4CB702C8EA4542E836B96C, 080FB0B01E949D24CDD6876125B3A72DA9F88845D8B9A1A425BCA99E7ACF6821 ] Mup             C:\Windows\system32\Drivers\mup.sys
01:01:35.0600 0x0f34  Mup - ok
01:01:35.0673 0x0f34  [ E4EAF0C5C1B41B5C83386CF212CA9584, 5946C3DCE65A0DB164169A1775DFCA544AF4E1895ADF6916BB1653F373F8D9AF ] napagent        C:\Windows\system32\qagentRT.dll
01:01:35.0782 0x0f34  napagent - ok
01:01:35.0837 0x0f34  [ 85C44FDFF9CF7E72A40DCB7EC06A4416, DC37C99C458CA69B33BFD3894187089E947F4F9C01EC2ED024FA8614989E0956 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
01:01:35.0909 0x0f34  NativeWifiP - ok
01:01:36.0011 0x0f34  [ 1357274D1883F68300AEADD15D7BBB42, EE6352CBF0D9D633816F338159CDA27F1A805C3DDC3402D8605B50D8F3CD3300 ] NDIS            C:\Windows\system32\drivers\ndis.sys
01:01:36.0087 0x0f34  NDIS - ok
01:01:36.0138 0x0f34  [ 0E186E90404980569FB449BA7519AE61, DE41791D9D3074007D6DD1D3933E7A2A13E3789D0AD4F029105B58279622FC1B ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
01:01:36.0206 0x0f34  NdisTapi - ok
01:01:36.0229 0x0f34  [ D6973AA34C4D5D76C0430B181C3CD389, 7C303F3D6BFF8B82E39998135B444837091AB1F9EB8F28D013E5EF45DB237EFC ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
01:01:36.0296 0x0f34  Ndisuio - ok
01:01:36.0335 0x0f34  [ 818F648618AE34F729FDB47EC68345C3, 5FC8F9237BD7FCE3C62D5BDDD49DC104BE2BECDC2FA8CDC1DB8F1891CBAA9140 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
01:01:36.0413 0x0f34  NdisWan - ok
01:01:36.0444 0x0f34  [ 71DAB552B41936358F3B541AE5997FB3, 30A8B3E33CBF04FC047254E404C0321F9028F2640036AA8AC1EA0A5E64551684 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
01:01:36.0502 0x0f34  NDProxy - ok
01:01:36.0524 0x0f34  [ BCD093A5A6777CF626434568DC7DBA78, 2A283DD93230361204EA0897864EAF0224CB8C02E025AE2E4237B07A598B3EBD ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
01:01:36.0594 0x0f34  NetBIOS - ok
01:01:36.0645 0x0f34  [ ECD64230A59CBD93C85F1CD1CAB9F3F6, 83650D756C1F2768A2AAAFC7924F2A4316ABAEB1708F4B05803CDDD699B5AB6F ] netbt           C:\Windows\system32\DRIVERS\netbt.sys
01:01:36.0736 0x0f34  netbt - ok
01:01:36.0776 0x0f34  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] Netlogon        C:\Windows\system32\lsass.exe
01:01:36.0815 0x0f34  Netlogon - ok
01:01:36.0888 0x0f34  [ C8052711DAECC48B982434C5116CA401, 417DEB86D157DD3F0B4678410FE27FDD3E8FA04AB03AF398F6C02BF207070B35 ] Netman          C:\Windows\System32\netman.dll
01:01:36.0997 0x0f34  Netman - ok
01:01:37.0046 0x0f34  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
01:01:37.0081 0x0f34  NetMsmqActivator - ok
01:01:37.0109 0x0f34  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
01:01:37.0141 0x0f34  NetPipeActivator - ok
01:01:37.0186 0x0f34  [ 2EF3BBE22E5A5ACD1428EE387A0D0172, 55DB91EDD0339D2434C06445F8A716A48EA90925B0FF7EBF45BB79D4B54B80BF ] netprofm        C:\Windows\System32\netprofm.dll
01:01:37.0299 0x0f34  netprofm - ok
01:01:37.0316 0x0f34  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
01:01:37.0350 0x0f34  NetTcpActivator - ok
01:01:37.0366 0x0f34  [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
01:01:37.0399 0x0f34  NetTcpPortSharing - ok
01:01:37.0444 0x0f34  [ 2E7FB731D4790A1BC6270ACCEFACB36E, EE9A00B694E8A3A5842CDC56C7BA1364317AC8134E046A0059661D057094B1A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
01:01:37.0475 0x0f34  nfrd960 - ok
01:01:37.0527 0x0f34  [ 32FF06EC6D946EF791D98D6C838A3090, 319BDD491CB22D0CCCCE76A2854CF469D7AF046289F9C56CD03AE3D3CBC0275E ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
01:01:37.0565 0x0f34  NisDrv - ok
01:01:37.0625 0x0f34  [ 42D33042371BFB1A7D40834590CAFD30, 53DA3618EC10293B2DF686E291A4EF6ACBBD41D116EC762D54106D201A784E87 ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
01:01:37.0677 0x0f34  NisSrv - ok
01:01:37.0719 0x0f34  [ 2997B15415F9BBE05B5A4C1C85E0C6A2, 5455536515FE740E18E090329FDCC40288724372AD18ACDB2CB4BB9D85CF681E ] NlaSvc          C:\Windows\System32\nlasvc.dll
01:01:37.0817 0x0f34  NlaSvc - ok
01:01:37.0859 0x0f34  [ D36F239D7CCE1931598E8FB90A0DBC26, DF9397411D0CE5A87E3346D4E6E25BEC537A21BCE196CC55FD999CD08FC4A637 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
01:01:37.0916 0x0f34  Npfs - ok
01:01:37.0931 0x0f34  [ 6D8D2E5652FC2442C810C5D8BE784148, 013FF4FA03CA2E066B1946CC09889616B243068BA0FB2E58D4C1435BF66FBC87 ] NSCIRDA         C:\Windows\system32\DRIVERS\nscirda.sys
01:01:38.0019 0x0f34  NSCIRDA - ok
01:01:38.0044 0x0f34  [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD, 15CA178518EB3D457AA4C109D97A8490821590842AE4E9841703B5A55870C8F6 ] nsi             C:\Windows\system32\nsisvc.dll
01:01:38.0116 0x0f34  nsi - ok
01:01:38.0168 0x0f34  [ 609773E344A97410CE4EBF74A8914FCF, 90B9CBD2B62854DD503DE4A910CB987D402368EB99882FE20FFB6DEACD70F2BD ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
01:01:38.0246 0x0f34  nsiproxy - ok
01:01:38.0378 0x0f34  [ 6A4A98CEE84CF9E99564510DDA4BAA47, 18C3D8C0F12761D3B7FC43D9413CF4C4CEBF8CA9BEC521381F40D241B35EA779 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
01:01:38.0521 0x0f34  Ntfs - ok
01:01:38.0573 0x0f34  [ E875C093AEC0C978A90F30C9E0DFBB72, D3A480CD7EF374EFBC1BB831B33B81534774DDDBB0FB338BEE1D444949FD8DE7 ] ntrigdigi       C:\Windows\system32\drivers\ntrigdigi.sys
01:01:38.0699 0x0f34  ntrigdigi - ok
01:01:38.0727 0x0f34  [ C5DBBCDA07D780BDA9B685DF333BB41E, 3652893DFF05469A273C3073D8D0A9D6D6BBDEC7855FEA8EAB768F95BA674108 ] Null            C:\Windows\system32\drivers\Null.sys
01:01:38.0896 0x0f34  Null - ok
01:01:38.0930 0x0f34  [ 2EDF9E7751554B42CBB60116DE727101, 37A0AA78E83DBB5A788F7F067EB71DDF6CCC72A66BB41B209E1A5E2F68F8AF9B ] nvraid          C:\Windows\system32\drivers\nvraid.sys
01:01:38.0967 0x0f34  nvraid - ok
01:01:39.0000 0x0f34  [ ABED0C09758D1D97DB0042DBB2688177, 84B9BF886EF9181915E8AB6D971446BC681E6DE4485DBECD62838EAFA10E7F46 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
01:01:39.0057 0x0f34  nvstor - ok
01:01:39.0107 0x0f34  [ 18BBDF913916B71BD54575BDB6EEAC0B, 5FBA165149AB09E869DCE35622E91CFC964BDD22B31A5E76CF12F1565402B207 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
01:01:39.0142 0x0f34  nv_agp - ok
01:01:39.0153 0x0f34  NwlnkFlt - ok
01:01:39.0168 0x0f34  NwlnkFwd - ok
01:01:39.0304 0x0f34  [ 1F0E05DFF4F5A833168E49BE1256F002, A858267572033C185293B0FD15B2BFDA679D0771A14C0ADF24461B529DBAD8DF ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
01:01:39.0365 0x0f34  odserv - ok
01:01:39.0435 0x0f34  [ 6F310E890D46E246E0E261A63D9B36B4, 7050B0C43CC0DF2DDAD3EB8D2FF9EEE425A627C68654CBB154D55A4B1A47AA08 ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
01:01:39.0508 0x0f34  ohci1394 - ok
01:01:39.0560 0x0f34  [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
01:01:39.0595 0x0f34  ose - ok
01:01:39.0698 0x0f34  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2pimsvc        C:\Windows\system32\p2psvc.dll
01:01:39.0842 0x0f34  p2pimsvc - ok
01:01:39.0895 0x0f34  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] p2psvc          C:\Windows\system32\p2psvc.dll
01:01:39.0994 0x0f34  p2psvc - ok
01:01:40.0054 0x0f34  [ 0FA9B5055484649D63C303FE404E5F4D, ABF357001A5E7B21621560E74FA538E2D899C5111A6AAC784B5B12D9D819C6CD ] Parport         C:\Windows\system32\drivers\parport.sys
01:01:40.0174 0x0f34  Parport - ok
01:01:40.0224 0x0f34  [ 57389FA59A36D96B3EB09D0CB91E9CDC, 05A3E2B155789990517CCFDC57FC3D1E9A596E4F31D86350B8BF0C043DE5EE9B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
01:01:40.0261 0x0f34  partmgr - ok
01:01:40.0287 0x0f34  [ 4F9A6A8A31413180D0FCB279AD5D8112, DCE48BC6E3447403521BB9FBF727E629DEE45B69B8AE8CFEE1A67FECAE3CB9D3 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
01:01:40.0414 0x0f34  Parvdm - ok
01:01:40.0444 0x0f34  [ C6276AD11F4BB49B58AA1ED88537F14A, 409E956AF994640DF8D062E5E41F87A6EE7EEE0335C191B582722A49322357CE ] PcaSvc          C:\Windows\System32\pcasvc.dll
01:01:40.0559 0x0f34  PcaSvc - ok
01:01:40.0610 0x0f34  [ 941DC1D19E7E8620F40BBC206981EFDB, 156142A8B587131D2D47074CBFD0A31F69B3C27A8C74C8C4F29DFE7B53BBA802 ] pci             C:\Windows\system32\drivers\pci.sys
01:01:40.0652 0x0f34  pci - ok
01:01:40.0690 0x0f34  [ FC175F5DDAB666D7F4D17449A547626F, 7D6108213D1AD3F97A3B83E491BCCC7D6F5BC72C32A182BDDE8736851A26C8D2 ] pciide          C:\Windows\system32\drivers\pciide.sys
01:01:40.0719 0x0f34  pciide - ok
01:01:40.0792 0x0f34  [ 3BB2244F343B610C29C98035504C9B75, DA61EC2600199DFA32020D0484E9BBF5E0742E7C8C952370BF6FAF91C914A999 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
01:01:40.0837 0x0f34  pcmcia - ok
01:01:40.0965 0x0f34  [ 6349F6ED9C623B44B52EA3C63C831A92, 9EAA3ABD396870123107D6E1B758F56FDA378BD28B28DB8415AA470D24294F92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
01:01:41.0228 0x0f34  PEAUTH - ok
01:01:41.0480 0x0f34  [ B1689DF169143F57053F795390C99DB3, 887B8C76B34CABC68067C0F27CC4EEF02457A53634C96FE5B0FE9B99453BDBEF ] pla             C:\Windows\system32\pla.dll
01:01:41.0716 0x0f34  pla - ok
01:01:41.0857 0x0f34  [ C5E7F8A996EC0A82D508FD9064A5569E, 416A93816CDF12DD42DEA796D37E6E2000D3172AAAB20D3EAD3B715DACD4B61F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
01:01:41.0952 0x0f34  PlugPlay - ok
01:01:42.0034 0x0f34  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPAutoReg     C:\Windows\system32\p2psvc.dll
01:01:42.0196 0x0f34  PNRPAutoReg - ok
01:01:42.0255 0x0f34  [ 0C8E8E61AD1EB0B250B846712C917506, 8F23657B90BFFCD7273B93EDA2D3768F35C1C5A313F22AE33452BE3B2A550649 ] PNRPsvc         C:\Windows\system32\p2psvc.dll
01:01:42.0357 0x0f34  PNRPsvc - ok
01:01:42.0407 0x0f34  [ D0494460421A03CD5225CCA0059AA146, FC30E90522C63F2A66D89381705712D2CDF07B2E029DF40C2DEBB2353E763E90 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
01:01:42.0553 0x0f34  PolicyAgent - ok
01:01:42.0628 0x0f34  [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1, 6E4B188A4BFDBBCA51347BCCE2873F2D0F858398851B9B5129CB9F36A02E4354 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
01:01:42.0720 0x0f34  PptpMiniport - ok
01:01:42.0747 0x0f34  [ 2027293619DD0F047C584CF2E7DF4FFD, B7C172CCD08D8A30483D27536355ED1E5009B33629355B426470AFBA8542B394 ] Processor       C:\Windows\system32\drivers\processr.sys
01:01:42.0830 0x0f34  Processor - ok
01:01:42.0885 0x0f34  [ 0508FAA222D28835310B7BFCA7A77346, 3AE2340C6E365F137CC00D9560069501DD2724756EA9EBF7A6CDFFC91B43709C ] ProfSvc         C:\Windows\system32\profsvc.dll
01:01:42.0976 0x0f34  ProfSvc - ok
01:01:43.0011 0x0f34  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] ProtectedStorage C:\Windows\system32\lsass.exe
01:01:43.0053 0x0f34  ProtectedStorage - ok
01:01:43.0121 0x0f34  [ 99514FAA8DF93D34B5589187DB3AA0BA, 4DDE5EC0C721B22E1D7D55ED3514B60EA07435C232A3A931BB49C7F486B52C18 ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
01:01:43.0194 0x0f34  PSched - ok
01:01:43.0263 0x0f34  [ E42E3433DBB4CFFE8FDD91EAB29AEA8E, 20ABD8372B242FD356AC143E7EB56F93CFEA4988ED1B0C4434CB64C387D7F66C ] PxHelp20        C:\Windows\system32\Drivers\PxHelp20.sys
01:01:43.0506 0x0f34  PxHelp20 - ok
01:01:43.0662 0x0f34  [ 0A6DB55AFB7820C99AA1F3A1D270F4F6, 8B7D44A7698B95FE34CBBE4FAB2F01EC1F5BA86C2B19672F99767E650E99BF1C ] ql2300          C:\Windows\system32\drivers\ql2300.sys
01:01:43.0791 0x0f34  ql2300 - ok
01:01:43.0868 0x0f34  [ 81A7E5C076E59995D54BC1ED3A16E60B, A2988F065F93C41B3B389BFF3BB3FD69F768C2AF249C2356F315CC92E5C9E128 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
01:01:43.0903 0x0f34  ql40xx - ok
01:01:43.0961 0x0f34  [ E9ECAE663F47E6CB43962D18AB18890F, F1A05320CAED9E745AA36A6DA9B64C48AAEDE888B42B249840CEB31448F7F432 ] QWAVE           C:\Windows\system32\qwave.dll
01:01:44.0043 0x0f34  QWAVE - ok
01:01:44.0078 0x0f34  [ 9F5E0E1926014D17486901C88ECA2DB7, 67CDFB99AB546DCEEF20507EAC07DD52FFB51BFDFE9416ABEDDC1201B60D720E ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
01:01:44.0119 0x0f34  QWAVEdrv - ok
01:01:44.0162 0x0f34  [ 147D7F9C556D259924351FEB0DE606C3, E41EBA5F3098C6CF2BE4C0060A5F4BF161C3677D983B7A0D70ACC12FC3CFEFD7 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
01:01:44.0248 0x0f34  RasAcd - ok
01:01:44.0278 0x0f34  [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F, 6A410ABCCD2211EFF511CDBF22E4152B57D2996336EBE711DFF71904AF232DB2 ] RasAuto         C:\Windows\System32\rasauto.dll
01:01:44.0366 0x0f34  RasAuto - ok
01:01:44.0396 0x0f34  [ A214ADBAF4CB47DD2728859EF31F26B0, A24F37F55E2C018B1B4FA2C568A01AAAAEA1220833ED24A93378386174A70A32 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
01:01:44.0469 0x0f34  Rasl2tp - ok
01:01:44.0538 0x0f34  [ 75D47445D70CA6F9F894B032FBC64FCF, 9112EA5D25F867136858524C7965ACCEDC02675D1E2985B950598D89CCF25E14 ] RasMan          C:\Windows\System32\rasmans.dll
01:01:44.0618 0x0f34  RasMan - ok
01:01:44.0669 0x0f34  [ 509A98DD18AF4375E1FC40BC175F1DEF, CC7C278CA298CE102D871E34C176E73F903D6687D1E8B5AFAB8772C7DE1A60B1 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
01:01:44.0738 0x0f34  RasPppoe - ok
01:01:44.0842 0x0f34  [ 2005F4A1E05FA09389AC85840F0A9E4D, D8A664073FDE82F9AB324347024CDB7043635C84EB11C24C59AB384C52F0FD94 ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
01:01:44.0884 0x0f34  RasSstp - ok
01:01:44.0944 0x0f34  [ B14C9D5B9ADD2F84F70570BBBFAA7935, 3D533767A50554B86C769DF4D8841B3EA680B3807E85EA3533BDA9B649548269 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
01:01:45.0018 0x0f34  rdbss - ok
01:01:45.0050 0x0f34  [ 89E59BE9A564262A3FB6C4F4F1CD9899, 6F948FB0E73495CA60B7B19E758268495EC8A084C475EC59AD7940AA619570BB ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
01:01:45.0136 0x0f34  RDPCDD - ok
01:01:45.0180 0x0f34  [ FBC0BACD9C3D7F6956853F64A66E252D, 7672B10C7039295B152C02C96903E869FF2C0A88A2C3FA89BAE9F1D593B43569 ] rdpdr           C:\Windows\system32\drivers\rdpdr.sys
01:01:45.0269 0x0f34  rdpdr - ok
01:01:45.0285 0x0f34  [ 9D91FE5286F748862ECFFA05F8A0710C, 33F37F1B207151A5564BF051BBF16F35D8C5A0F426CCA078A51F125BF09E487B ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
01:01:45.0355 0x0f34  RDPENCDD - ok
01:01:45.0395 0x0f34  [ 30BFBDFB7F95559EDE971F9DDB9A00BA, 1BDD3FD0ABCF5EA2C4D2618E76AC782894E5A7132700BA4C4226E1F9C7CE547B ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
01:01:45.0478 0x0f34  RDPWD - ok
01:01:45.0545 0x0f34  [ BCDD6B4804D06B1F7EBF29E53A57ECE9, 8A961CCD0A0265E03D9952C733B593B02B5CF64E308D6B420276D2D6B20F86FC ] RemoteAccess    C:\Windows\System32\mprdim.dll
01:01:45.0619 0x0f34  RemoteAccess - ok
01:01:45.0669 0x0f34  [ 9E6894EA18DAFF37B63E1005F83AE4AB, 5D6DF994D297C875D547C7B111A571AA90D582DAECADE18A53F65AD988819E67 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
01:01:45.0764 0x0f34  RemoteRegistry - ok
01:01:45.0858 0x0f34  [ 6482707F9F4DA0ECBAB43B2E0398A101, 7D57FC36577121D7E26A4F2D46DCA8725D55EC9F75B91DF994DB742BC4FB89C2 ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
01:01:45.0926 0x0f34  RFCOMM - ok
01:01:45.0965 0x0f34  [ 5123F83CBC4349D065534EEB6BBDC42B, 92A3F38EA924D83D601BB93E3750F9DBC2DD963FB7ACF2A0E776297E21815225 ] RpcLocator      C:\Windows\system32\locator.exe
01:01:46.0032 0x0f34  RpcLocator - ok
01:01:46.0102 0x0f34  [ 3B5B4D53FEC14F7476CA29A20CC31AC9, EC02A412DA5FDE2C759A4A2C5904579E1CE7C4999CE87145812F354FC8F5E183 ] RpcSs           C:\Windows\system32\rpcss.dll
01:01:46.0214 0x0f34  RpcSs - ok
01:01:46.0261 0x0f34  [ 9C508F4074A39E8B4B31D27198146FAD, 84913471E5A6C297B1EDABE45EF3FE7D2C4410EF04370F615109FD9E2690FFDB ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
01:01:46.0349 0x0f34  rspndr - ok
01:01:46.0388 0x0f34  [ A3E186B4B935905B829219502557314E, 7F58EAC6C12208D792C77014AC9D37AD1A7B2E73863C914F5DA831A72E1D52BB ] SamSs           C:\Windows\system32\lsass.exe
01:01:46.0427 0x0f34  SamSs - ok
01:01:46.0470 0x0f34  [ 3CE8F073A557E172B330109436984E30, CEC281C6076FAA1E34372CF419C6308E73811316606B8D0D9055B7D8952BDC88 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
01:01:46.0503 0x0f34  sbp2port - ok
01:01:46.0555 0x0f34  [ 77B7A11A0C3D78D3386398FBBEA1B632, A3D290AB793BDC2F84C7B963300DFCE81CFE082A0FFF7489E8E5B14714892C00 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
01:01:46.0620 0x0f34  SCardSvr - ok
01:01:46.0713 0x0f34  [ 323AE0BDFD2EB15B668DDA50CC597329, 43AF5B26713D317DB4A5C82A27074B2E2A75A22B4CF9DA597ED93130B951133C ] Schedule        C:\Windows\system32\schedsvc.dll
01:01:46.0866 0x0f34  Schedule - ok
01:01:46.0894 0x0f34  [ 312EC3E37A0A1F2006534913E37B4423, 81B8F462336791D162DAFA8092C1F437638DA3022CA24A2458B9FE183FC18C5D ] SCPolicySvc     C:\Windows\System32\certprop.dll
01:01:46.0949 0x0f34  SCPolicySvc - ok
01:01:47.0003 0x0f34  [ 8F36B54688C31EED4580129040C6A3D3, DC150689CBAEEC94B9DE0CA6A633FAD16CDDDC452521232E0C2A44BAE61E08D9 ] sdbus           C:\Windows\system32\DRIVERS\sdbus.sys
01:01:47.0064 0x0f34  sdbus - ok
01:01:47.0109 0x0f34  [ 716313D9F6B0529D03F726D5AAF6F191, 44FE994A11631C1D99C73026340BACE39973C65A1281D87A61B481C9B5FAB251 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
01:01:47.0228 0x0f34  SDRSVC - ok
01:01:47.0256 0x0f34  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
01:01:47.0383 0x0f34  secdrv - ok
01:01:47.0416 0x0f34  [ FD5199D4D8A521005E4B5EE7FE00FA9B, 0FB7A1D300C72B1ADC423CC57343C17853E5F8ACFE3EA2C42FAC2FF72E502FBE ] seclogon        C:\Windows\system32\seclogon.dll
01:01:47.0497 0x0f34  seclogon - ok
01:01:47.0528 0x0f34  [ A9BBAB5759771E523F55563D6CBE140F, 415BF6F6A1E4C5F98DABF9C2EEAF8CA49730693046E5F94C7655683717EDAD75 ] SENS            C:\Windows\system32\sens.dll
01:01:47.0616 0x0f34  SENS - ok
01:01:47.0642 0x0f34  [ 68E44E331D46F0FB38F0863A84CD1A31, 0778D85B6869CE2610820DC9724360538BFE832426E898AEBC34E53D2AB4322B ] Serenum         C:\Windows\system32\drivers\serenum.sys
01:01:47.0769 0x0f34  Serenum - ok
01:01:47.0825 0x0f34  [ C70D69A918B178D3C3B06339B40C2E1B, 40BEEECA4C797A3355F4B01C57C2763C33028F27826315062320789A496D0810 ] Serial          C:\Windows\system32\drivers\serial.sys
01:01:47.0961 0x0f34  Serial - ok
01:01:48.0000 0x0f34  [ 8AF3D28A879BF75DB53A0EE7A4289624, C870BEBB969DCD9170E64584D1CD329A193D9FC812A45EF3574891110CA68B45 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
01:01:48.0071 0x0f34  sermouse - ok
01:01:48.0137 0x0f34  [ D2193326F729B163125610DBF3E17D57, 82C894E24E2C139C884246A693AD37BBF0A4E9375B7F7A288EF1DB22F89434B9 ] SessionEnv      C:\Windows\system32\sessenv.dll
01:01:48.0218 0x0f34  SessionEnv - ok
01:01:48.0244 0x0f34  [ 3EFA810BDCA87F6ECC24F9832243FE86, E50FEA94DB9851A46A8A71A8C061AC953A9D5B14585382B3F0FFC84931A0A68F ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
01:01:48.0299 0x0f34  sffdisk - ok
01:01:48.0317 0x0f34  [ E95D451F7EA3E583AEC75F3B3EE42DC5, B014BE4F9B0C79ECCE2537D1CF4AAD48ACB4C5AD3DACAC4444F0F465B9689921 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
01:01:48.0400 0x0f34  sffp_mmc - ok
01:01:48.0424 0x0f34  [ 3D0EA348784B7AC9EA9BD9F317980979, 2500CE188C9B71C50E966FA575303AEFE50934E376C530AECEC7C7533C15EF08 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
01:01:48.0493 0x0f34  sffp_sd - ok
01:01:48.0513 0x0f34  [ 46ED8E91793B2E6F848015445A0AC188, 34A97304F23EA153422848F6F1CAF8ADF0944EA781E12F027B6DEAF751A04B5D ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
01:01:48.0647 0x0f34  sfloppy - ok
01:01:48.0715 0x0f34  [ E1499BD0FF76B1B2FBBF1AF339D91165, 9A8F0403467E75880D3070C4D862489A75134383BAF8E7C45F8C5E7DFB0605A5 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
01:01:48.0906 0x0f34  SharedAccess - ok
01:01:48.0981 0x0f34  [ C818C44C201898399BF999BB6B35D4E3, 8887EDF7F9D16F5D055AA4EE3BE22AD238AF15034671F09124921B66B7890915 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
01:01:49.0086 0x0f34  ShellHWDetection - ok
01:01:49.0123 0x0f34  [ 1D76624A09A054F682D746B924E2DBC3, DC903DD466AB8899883253F09477B02E4E93A31C8B279F9F02BD555F1AA083B7 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
01:01:49.0215 0x0f34  sisagp - ok
01:01:49.0263 0x0f34  [ 43CB7AA756C7DB280D01DA9B676CFDE2, 08484CAEA0518C0A4CCCD292D8C803B27FEC453537EE1E4CEE74A7208356A474 ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
01:01:49.0305 0x0f34  SiSRaid2 - ok
01:01:49.0340 0x0f34  [ A99C6C8B0BAA970D8AA59DDC50B57F94, 97AC9DD6DC4F58AC60E819B999BB157663EE7C1739521D16768AA9AC00DAD012 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
01:01:49.0381 0x0f34  SiSRaid4 - ok
01:01:49.0549 0x0f34  [ F6EF225A23D336CA30001E5007644C24, B0A4B1256C1074F1B4F73E3BBA16FD4683D6EEA583DEEF8E11EFD29BA7541F2A ] SkypeUpdate     C:\Program Files\Skype\Updater\Updater.exe
01:01:49.0619 0x0f34  SkypeUpdate - ok
01:01:50.0355 0x0f34  [ 862BB4CBC05D80C5B45BE430E5EF872F, F4961B22C93E472C8C862421AA231CDDA9E40D3958741A1D666357F22CC3143D ] slsvc           C:\Windows\system32\SLsvc.exe
01:01:51.0062 0x0f34  slsvc - ok
01:01:51.0126 0x0f34  [ 6EDC422215CD78AA8A9CDE6B30ABBD35, D8342BC3152859F4F7512E85ABEC61147DBCAB515458644728874E42F639D6CA ] SLUINotify      C:\Windows\system32\SLUINotify.dll
01:01:51.0205 0x0f34  SLUINotify - ok
01:01:51.0281 0x0f34  [ 7B75299A4D201D6A6533603D6914AB04, 172BE3951F06B1991EF70B71EB91786D1EFC4E381C22BCA3A5F622CD59F3227E ] Smb             C:\Windows\system32\DRIVERS\smb.sys
01:01:51.0424 0x0f34  Smb - ok
01:01:51.0486 0x0f34  [ 2A146A055B4401C16EE62D18B8E2A032, D0930FFA53951C92F56E1ECB41374F4C0AA01ECBF99F474513A21EAD579CFE47 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
01:01:51.0543 0x0f34  SNMPTRAP - ok
01:01:51.0595 0x0f34  [ 7AEBDEEF071FE28B0EEF2CDD69102BFF, E03BEE733F4C2A5F39946D4955679A290E22758DFCE4222EE69ABF64FC54EDF7 ] spldr           C:\Windows\system32\drivers\spldr.sys
01:01:51.0633 0x0f34  spldr - ok
01:01:51.0680 0x0f34  [ 524BFBEA40E6E404737CCBC754647A2E, 0F4F06DEFCA6886D4D3BDA5F6FDA467C8F966E511FA757A83BFC5B33D8D33EAA ] Spooler         C:\Windows\System32\spoolsv.exe
01:01:51.0772 0x0f34  Spooler - ok
01:01:51.0933 0x0f34  [ 41987F9FC0E61ADF54F581E15029AD91, A46E718648C2DD3B43FC3798932C966315893A59442A0686CE46C605B9E4641E ] srv             C:\Windows\system32\DRIVERS\srv.sys
01:01:52.0054 0x0f34  srv - ok
01:01:52.0097 0x0f34  [ A5940CA32ED206F90BE9FABDF6E92DE4, 3FA6120BE2380F85C0A7DCAA3D7D158494AA4C5B6587EF9F4135FE9B644B6029 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
01:01:52.0187 0x0f34  srv2 - ok
01:01:52.0256 0x0f34  [ 37AA1D560D5FA486C4B11C2F276ADA61, 53A54A45FE40E82F7BE481EFE5A8B14A5540398946B87AC0B1AB0F8253E2F1D8 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
01:01:52.0334 0x0f34  srvnet - ok
01:01:52.0375 0x0f34  [ 03D50B37234967433A5EA5BA72BC0B62, 7B61D6A4BF5D446A9473D058BC207FB6DA7C2FEFB8083F3B66CAC8907DBD8327 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
01:01:52.0480 0x0f34  SSDPSRV - ok
01:01:52.0536 0x0f34  [ 6F1A32E7B7B30F004D9A20AFADB14944, AA9D874A14CA4779E76701D2B02F4CCA92CD5917435FB4CACA149FCB2D1D4C4C ] SstpSvc         C:\Windows\system32\sstpsvc.dll
01:01:52.0604 0x0f34  SstpSvc - ok
01:01:52.0851 0x0f34  [ 5DE7D67E49B88F5F07F3E53C4B92A352, 6930A598C35646646ED0E91633797EFE139AE6CDD0012335BD1340754A22F997 ] stisvc          C:\Windows\System32\wiaservc.dll
01:01:52.0976 0x0f34  stisvc - ok
01:01:53.0046 0x0f34  [ 7BA58ECF0C0A9A69D44B3DCA62BECF56, 23CC47FA2D6E183D69DB0D3D3F3081A830D94A58FBC0A9A295B3A56C51E9486A ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
01:01:53.0076 0x0f34  swenum - ok
01:01:53.0140 0x0f34  [ F21FD248040681CCA1FB6C9A03AAA93D, 32FE765841A183A1F2C1ACACBBF8CDB11E7D4D4396F9C9F6CFF1B51C9B620ED3 ] swprv           C:\Windows\System32\swprv.dll
01:01:53.0256 0x0f34  swprv - ok
01:01:53.0323 0x0f34  [ 192AA3AC01DF071B541094F251DEED10, 5C6EB56D1C39F3717EB754A1B37C8A618BA4F2107F64048E985D71FA04D1AD05 ] Symc8xx         C:\Windows\system32\drivers\symc8xx.sys
01:01:53.0354 0x0f34  Symc8xx - ok
01:01:53.0388 0x0f34  [ 8C8EB8C76736EBAF3B13B633B2E64125, A6C4845DDED81CCF4947612A4D6E42035136025BCD80812D2FF396927CAADEC5 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
01:01:53.0420 0x0f34  Sym_hi - ok
01:01:53.0449 0x0f34  [ 8072AF52B5FD103BBBA387A1E49F62CB, D336A7D008D145619E79043EBF5D0D455086BA1FEF89612BC2EA11CC363D82B0 ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
01:01:53.0483 0x0f34  Sym_u3 - ok
01:01:53.0578 0x0f34  [ 9A51B04E9886AA4EE90093586B0BA88D, 1666C29FBFA34174B506678C920636519051D03456A6DDCCD6FF708CAE5D9962 ] SysMain         C:\Windows\system32\sysmain.dll
01:01:53.0747 0x0f34  SysMain - ok
01:01:53.0852 0x0f34  [ 2DCA225EAE15F42C0933E998EE0231C3, 67C7913E41854DFA3043426B7D59AA1FBBB9DE01A6E6904E40A696A7C61A5F98 ] TabletInputService C:\Windows\System32\TabSvc.dll
01:01:53.0936 0x0f34  TabletInputService - ok
01:01:54.0001 0x0f34  [ D7673E4B38CE21EE54C59EEEB65E2483, 330D0AD13F5008D8569CE8E5EA0BBD69F54F59FEB54FD903FA18D2849CEC6AF0 ] TapiSrv         C:\Windows\System32\tapisrv.dll
01:01:54.0096 0x0f34  TapiSrv - ok
01:01:54.0172 0x0f34  [ 27A2C318CD28CFB3EB2200FD96AF1E58, E0D841B4D3A042367A60E32F18F497F642BE69253E0539395066D82F809D16BE ] tapvpn          C:\Windows\system32\DRIVERS\tapvpn.sys
01:01:54.0223 0x0f34  tapvpn - detected UnsignedFile.Multi.Generic ( 1 )
01:01:56.0478 0x0f34  Detect skipped due to KSN trusted
01:01:56.0478 0x0f34  tapvpn - ok
01:01:56.0534 0x0f34  [ CB05822CD9CC6C688168E113C603DBE7, 9DB8945BDC702BB13E9DE477F2D3CCA4CE0E9E8CE9B54CE1A25375F2A2C93F0E ] TBS             C:\Windows\System32\tbssvc.dll
01:01:56.0628 0x0f34  TBS - ok
01:01:56.0744 0x0f34  [ 6A10AFCE0B38371064BE41C1FBFD3C6B, 20FDB47DCF54B857B09C2753B49737F5B2D2D9ED7942C4DB0BFDEDC7811D02E1 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
01:01:56.0895 0x0f34  Tcpip - ok
01:01:56.0972 0x0f34  [ 6A10AFCE0B38371064BE41C1FBFD3C6B, 20FDB47DCF54B857B09C2753B49737F5B2D2D9ED7942C4DB0BFDEDC7811D02E1 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
01:01:57.0086 0x0f34  Tcpip6 - ok
01:01:57.0121 0x0f34  [ 9BF343F4C878D6AD6922B2C5A4FEFE0D, D3A8E2BC16A998D28228E7931624AF52C991E1D7959B8679F0867BA8241935D4 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
01:01:57.0204 0x0f34  tcpipreg - ok
01:01:57.0234 0x0f34  [ 5DCF5E267BE67A1AE926F2DF77FBCC56, E00C0A03AEE579B51B39930A72F39F4EFFE7CDA37187B0AE90F4E001AD15473B ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
01:01:57.0314 0x0f34  TDPIPE - ok
01:01:57.0339 0x0f34  [ 389C63E32B3CEFED425B61ED92D3F021, E4718E290678F00995E754AE66F1027D227BFAB9E1A1D2AC8E4EAD27DC50CB17 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
01:01:57.0418 0x0f34  TDTCP - ok
01:01:57.0469 0x0f34  [ 76B06EB8A01FC8624D699E7045303E54, EC30F244B48A35622ED3EE91792F6A1517C5A50770FAB3945E7A945EB7AF28A8 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
01:01:57.0543 0x0f34  tdx - ok
01:01:58.0405 0x0f34  [ C0C121B537DA3AD87481C0502CACE462, E0FC2AC71B60C796DCD03217A510C47425FB7783713FCCC477130E69715D2B8D ] TeamViewer      C:\Program Files\TeamViewer\TeamViewer_Service.exe
01:02:01.0963 0x1018  Object required for P2P: [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV
01:02:02.0118 0x0f34  TeamViewer - ok
01:02:02.0197 0x0f34  [ 3CAD38910468EAB9A6479E2F01DB43C7, 9D18C71EDF39743A0A592BC0873909D2B75B5B177B2672A865D1EEC0BFD2F61C ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
01:02:02.0232 0x0f34  TermDD - ok
01:02:02.0323 0x0f34  [ BB95DA09BEF6E7A131BFF3BA5032090D, BAF6997F8D944F85F0553957677866C7F22E72AA434BA45FFFB6CC41041070DC ] TermService     C:\Windows\System32\termsrv.dll
01:02:02.0492 0x0f34  TermService - ok
01:02:02.0597 0x0f34  [ C818C44C201898399BF999BB6B35D4E3, 8887EDF7F9D16F5D055AA4EE3BE22AD238AF15034671F09124921B66B7890915 ] Themes          C:\Windows\system32\shsvcs.dll
01:02:02.0680 0x0f34  Themes - ok
01:02:02.0786 0x0f34  [ 1076FFCFFAAE8385FD62DFCB25AC4708, 8C5C106FCB018E019DEBA8E1A6AA170CD7A93293F27994F724EBC486238DA0AA ] THREADORDER     C:\Windows\system32\mmcss.dll
01:02:02.0872 0x0f34  THREADORDER - ok
01:02:02.0942 0x0f34  [ 78213F01CE781F93180BEF5EB5B3AD81, D036E406775DAC1DEEEF283D98CEEC3D0A75C178FDAE783A5ED1383F662288AA ] tifm21          C:\Windows\system32\drivers\tifm21.sys
01:02:03.0118 0x0f34  tifm21 - ok
01:02:03.0154 0x0f34  [ EC74E77D0EB004BD3A809B5F8FB8C2CE, 1E4BBC58D0E35D79C764CF1BA73602C5E29A5A2393D40332801D533E445C6667 ] TrkWks          C:\Windows\System32\trkwks.dll
01:02:03.0323 0x0f34  TrkWks - ok
01:02:03.0416 0x0f34  [ 97D9D6A04E3AD9B6C626B9931DB78DBA, 8E42133ED5EE5EEC414A8B11C1035385C6141E445EA9677F947D20768F25A877 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
01:02:03.0471 0x0f34  TrustedInstaller - ok
01:02:03.0509 0x0f34  [ DCF0F056A2E4F52287264F5AB29CF206, D9F770BD65AE4320A8C130DEA1D093AA4E37FCA573BBE6A59D6D045452EA711D ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
01:02:03.0579 0x0f34  tssecsrv - ok
01:02:03.0627 0x0f34  [ CAECC0120AC49E3D2F758B9169872D38, 80DB15ADF5F4FF78D0C7D5081B6C0E8F1E5125872B60D23C19DA8E62C9DAC9A8 ] tunmp           C:\Windows\system32\DRIVERS\tunmp.sys
01:02:03.0685 0x0f34  tunmp - ok
01:02:03.0721 0x0f34  [ 300DB877AC094FEAB0BE7688C3454A9C, 3B36AA191FBE25B1A61150EAA2BDF8BA286DC4C052F6E98B0ED8202135553D8C ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
01:02:03.0773 0x0f34  tunnel - ok
01:02:03.0808 0x0f34  [ 7D33C4DB2CE363C8518D2DFCF533941F, C6A539AD31B0BD9F895E0A537783AA75D5760C8590D83BA832D59A9B090CA0E9 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
01:02:03.0840 0x0f34  uagp35 - ok
01:02:03.0904 0x0f34  [ D9728AF68C4C7693CB100B8441CBDEC6, A2CEE1EE4EF17106349F4E6967F504354801934179FBB3F10B9A4E3C30BC28CE ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
01:02:03.0976 0x0f34  udfs - ok
01:02:04.0139 0x0f34  [ EF3D01DFFAE4AEDB7AD07B75FBE5CC60, 043A802DE59CBA62FD4185DE57D5C84874D226A862E0B845837FD785B3886EF7 ] UI Assistant Service C:\Program Files\Smart Bro\AssistantServices.exe
01:02:04.0182 0x0f34  UI Assistant Service - ok
01:02:04.0228 0x0f34  [ ECEF404F62863755951E09C802C94AD5, 5D92062B3E371F196774EBFE840C78501E55A244DB2A49703C7AC0141C7DABF1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
01:02:04.0315 0x0f34  UI0Detect - ok
01:02:04.0350 0x0f34  [ B0ACFDC9E4AF279E9116C03E014B2B27, 455D30859E381361FF6EE8B01EDC22A2E66CD5EC22CA9F314E88009DB77A8BAF ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
01:02:04.0385 0x0f34  uliagpkx - ok
01:02:04.0419 0x1018  Object send P2P result: true
01:02:04.0429 0x0f34  [ 9224BB254F591DE4CA8D572A5F0D635C, C5E7B24587AC5A28ECA63300307AD95B8A846833340126AE378840A40E53C056 ] uliahci         C:\Windows\system32\drivers\uliahci.sys
01:02:04.0431 0x1018  Object required for P2P: [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394
01:02:04.0479 0x0f34  uliahci - ok
01:02:04.0547 0x0f34  [ 8514D0E5CD0534467C5FC61BE94A569F, A6EFB967044F88335469DB3351587E31CEC659BB6A7D8ED45C68329232C31BB9 ] UlSata          C:\Windows\system32\drivers\ulsata.sys
01:02:04.0591 0x0f34  UlSata - ok
01:02:04.0640 0x0f34  [ 38C3C6E62B157A6BC46594FADA45C62B, 44F87DC955CB4E35E0EB4C8B4E931472B33D97FE000C22370A06AD5EDCEFD0BA ] ulsata2         C:\Windows\system32\drivers\ulsata2.sys
01:02:04.0698 0x0f34  ulsata2 - ok
01:02:04.0844 0x0f34  [ 32CFF9F809AE9AED85464492BF3E32D2, 91AAA47AEF17F373276B01AC8FA823592A0C854541A7A9A3B78F2350DB964EBC ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
01:02:05.0029 0x0f34  umbus - ok
01:02:05.0442 0x0f34  [ 68308183F4AE0BE7BF8ECD07CB297999, 4444233CA3C42BEE50ED47553D4AE5A7C12D8F288D2FA4B2DAE1D9B9FEC1A72D ] upnphost        C:\Windows\System32\upnphost.dll
01:02:05.0619 0x0f34  upnphost - ok
01:02:05.0826 0x0f34  [ CAF811AE4C147FFCD5B51750C7F09142, BD670CF88D8F932AD1C6BA91FB68A7204BC473657C6A057C92AFB84D164D393C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
01:02:06.0113 0x0f34  usbccgp - ok
01:02:06.0156 0x0f34  [ E9476E6C486E76BC4898074768FB7131, D14B8F69A511DC1F990A9C123C18689AFE59659BA8130D248D8D03E9BD2143B6 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
01:02:06.0289 0x0f34  usbcir - ok
01:02:06.0353 0x0f34  [ 79E96C23A97CE7B8F14D310DA2DB0C9B, EB441D3B93965CD927E0C181031AD1082F59F9885BF35CABFDCA08C6C76B0DAF ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
01:02:06.0440 0x0f34  usbehci - ok
01:02:06.0474 0x0f34  [ 4673BBCB006AF60E7ABDDBE7A130BA42, 0B7DED0D887A3530AA5497FDBCB69389486FB9E2B6FAE3163E33713256D575BA ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
01:02:06.0584 0x0f34  usbhub - ok
01:02:06.0613 0x0f34  [ 38DBC7DD6CC5A72011F187425384388B, 456CFCD190035C3033709C8DC0F6DC4352BBF751D57C0C52DD04F8C301FEBACD ] usbohci         C:\Windows\system32\drivers\usbohci.sys
01:02:06.0741 0x0f34  usbohci - ok
01:02:06.0776 0x0f34  [ B51E52ACF758BE00EF3A58EA452FE360, 79E629EC5DE8AB7F31B0EE9AE94C71E8F703FED5C09A816228726974F7790C85 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
01:02:06.0904 0x0f34  usbprint - ok
01:02:06.0969 0x0f34  [ BE3DA31C191BC222D9AD503C5224F2AD, 201FB0FDBF423342202686DC0D8A3221B7798AE04C04A649D3441C257C733CE8 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
01:02:06.0998 0x1018  Object send P2P result: true
01:02:07.0132 0x0f34  USBSTOR - ok
01:02:07.0195 0x0f34  [ 814D653EFC4D48BE3B04A307ECEFF56F, D73D62F51AEFE2F8F2B938B20107C246F2AC2F62ED49112DBD092A5D2E4024B3 ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
01:02:07.0253 0x0f34  usbuhci - ok
01:02:07.0307 0x0f34  [ E67998E8F14CB0627A769F6530BCB352, 60982F168E9BF13954328C728F55F4D3ADDC572CACB65289B0E895A63DAA08C1 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
01:02:07.0410 0x0f34  usbvideo - ok
01:02:07.0471 0x0f34  [ 1509E705F3AC1D474C92454A5C2DD81F, 7F525921A3513224F8B093A16E19B4235B300349A14B0B86EE11B7473BA53337 ] UxSms           C:\Windows\System32\uxsms.dll
01:02:07.0549 0x0f34  UxSms - ok
01:02:07.0635 0x0f34  [ CD88D1B7776DC17A119049742EC07EB4, 6B68B9EDB8C6BCB2644F1F004D5743E928509D12107D996F390A24A72E0AA528 ] vds             C:\Windows\System32\vds.exe
01:02:07.0770 0x0f34  vds - ok
01:02:07.0826 0x0f34  [ 87B06E1F30B749A114F74622D013F8D4, 06C06EF87F7DC668D23B50AA5F419F62474ACF90E325E167491BF290286D6594 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
01:02:07.0918 0x0f34  vga - ok
01:02:07.0940 0x0f34  [ 2E93AC0A1D8C79D019DB6C51F036636C, 8B6F3B4EE90691A22788915AD0F99D8EE617750430A34E7CEB9AB4FB4E581755 ] VgaSave         C:\Windows\System32\drivers\vga.sys
01:02:08.0027 0x0f34  VgaSave - ok
01:02:08.0052 0x0f34  [ 5D7159DEF58A800D5781BA3A879627BC, 499A8E51FDE61AE0D7C1812D1E5B331211A36BD095A4992C629B93DE6D80F4E6 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
01:02:08.0087 0x0f34  viaagp - ok
01:02:08.0127 0x0f34  [ C4F3A691B5BAD343E6249BD8C2D45DEE, 19DE07AD6CD51036FA8A6B8EE82F34D7F5264FF3A12CBE6E52BD036D0303E319 ] ViaC7           C:\Windows\system32\drivers\viac7.sys
01:02:08.0209 0x0f34  ViaC7 - ok
01:02:08.0236 0x0f34  [ AADF5587A4063F52C2C3FED7887426FC, 0A74791A236FDAFCD045CFB79A159245B94F7C2033E0CD830C1B76F0F994E06D ] viaide          C:\Windows\system32\drivers\viaide.sys
01:02:08.0271 0x0f34  viaide - ok
01:02:08.0293 0x0f34  [ 69503668AC66C77C6CD7AF86FBDF8C43, 2CE407674A58313737073F02B9A617460BBA84B36C3A16D98AE5ED45279F5006 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
01:02:08.0328 0x0f34  volmgr - ok
01:02:08.0398 0x0f34  [ 23E41B834759917BFD6B9A0D625D0C28, 9F60992805262F936E8DA33610FDF60A191ECAFC08BBF657C8F9A21833C8EFC5 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
01:02:08.0514 0x0f34  volmgrx - ok
01:02:08.0541 0x0f34  [ 147281C01FCB1DF9252DE2A10D5E7093, DF5DCF6FD472F21863DC10B62F7647420B9686607857D08286B618D585E50219 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
01:02:08.0600 0x0f34  volsnap - ok
01:02:08.0648 0x0f34  [ 587253E09325E6BF226B299774B728A9, C9F46197819C2A095456393C518A9B00B59ECDC54F464D038AA7F8DCCDB93CCF ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
01:02:08.0690 0x0f34  vsmraid - ok
01:02:09.0180 0x0f34  [ DB3D19F850C6EB32BDCB9BC0836ACDDB, D81FF1CDA87A2FE83EFD5B3FE01EFF940952F8BAEE70BEA3B2F6EF30E2121704 ] VSS             C:\Windows\system32\vssvc.exe
01:02:09.0445 0x0f34  VSS - ok
01:02:09.0673 0x0f34  [ 96EA68B9EB310A69C25EBB0282B2B9DE, C76D3427F8A2953CB4D96BBA1523679CBE1BBF7FA821A35D2FBEB3E67AC6A10B ] W32Time         C:\Windows\system32\w32time.dll
01:02:09.0785 0x0f34  W32Time - ok
01:02:09.0854 0x0f34  [ 48DFEE8F1AF7C8235D4E626F0C4FE031, A41D05BC0DA3C476C32E0A4DAF015DF7BADF28A03CE236D5596885FF1772F148 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
01:02:09.0998 0x0f34  WacomPen - ok
01:02:10.0030 0x0f34  [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
01:02:10.0112 0x0f34  Wanarp - ok
01:02:10.0127 0x0f34  [ 55201897378CCA7AF8B5EFD874374A26, 350ADDCEFAA33E301027CFEA8DDE703F6FBD6E53624598CB2E7B671B9E48F7CC ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
01:02:10.0185 0x0f34  Wanarpv6 - ok
01:02:10.0290 0x0f34  [ A3CD60FD826381B49F03832590E069AF, 213C5DB5E5D828264286FD7548527566D6160CCA780BC6853B7B28CECF329674 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
01:02:10.0388 0x0f34  wcncsvc - ok
01:02:10.0426 0x0f34  [ 11BCB7AFCDD7AADACB5746F544D3A9C7, 0370E20FD12ED713F94E5CD76F068F7A7A5E7F42416DD2A8A41249020DA7DA31 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
01:02:10.0515 0x0f34  WcsPlugInService - ok
01:02:10.0581 0x0f34  [ 78FE9542363F297B18C027B2D7E7C07F, 6BC3ED2A48EF41E1EE597FD58271DB12256EC013518663331CD0FBCB3FC415EE ] Wd              C:\Windows\system32\drivers\wd.sys
01:02:10.0618 0x0f34  Wd - ok
01:02:10.0754 0x0f34  [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96, 6A6EFFDB538DE1E201058A00F3E056F1256E92EED943FBFBCE28E54BE751E33D ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
01:02:10.0833 0x0f34  Wdf01000 - ok
01:02:10.0865 0x0f34  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiServiceHost  C:\Windows\system32\wdi.dll
01:02:10.0952 0x0f34  WdiServiceHost - ok
01:02:10.0974 0x0f34  [ ABFC76B48BB6C96E3338D8943C5D93B5, B5B22D445724D58641A53276063A4AA2A98F07B93865C86E94661EB31BD63511 ] WdiSystemHost   C:\Windows\system32\wdi.dll
01:02:11.0050 0x0f34  WdiSystemHost - ok
01:02:11.0181 0x0f34  [ 04C37D8107320312FBAE09926103D5E2, 1C6726A9871CBACB240AFA93E57781515F01758D43693DDA395EA683D97234F0 ] WebClient       C:\Windows\System32\webclnt.dll
01:02:11.0248 0x0f34  WebClient - ok
01:02:11.0320 0x0f34  [ 905214925A88311FCE52F66153DE7610, 5D18C6E835A2EA4108C93D9E6AA976142119860C8FC8ECB2DFA961A241B6E61C ] Wecsvc          C:\Windows\system32\wecsvc.dll
01:02:11.0447 0x0f34  Wecsvc - ok
01:02:11.0483 0x0f34  [ 670FF720071ED741206D69BD995EA453, 4B96F5E3545F69AE9EBC75DC4AB27B87306D656EE526AE39E7EC7E2B6F83F7FD ] wercplsupport   C:\Windows\System32\wercplsupport.dll
01:02:11.0595 0x0f34  wercplsupport - ok
01:02:11.0649 0x0f34  [ 32B88481D3B326DA6DEB07B1D03481E7, 821FBAF147E525ED15EB9391B16A96C6D5464841258B11F277EFB57A3BD50E37 ] WerSvc          C:\Windows\System32\WerSvc.dll
01:02:11.0732 0x0f34  WerSvc - ok
01:02:11.0908 0x0f34  [ 5C7BDCF5864DB00323FE2D90FA26A8A2, E948B6BF8985CFF56FBE99AF7AF78CC3123AE5DAC9A5420ADE3C8B52CA702686 ] winachsf        C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
01:02:12.0039 0x0f34  winachsf - ok
01:02:12.0180 0x0f34  [ 4575AA12561C5648483403541D0D7F2B, 2DBB7904285F16E879E1662C4CC4DFAA420D5EB24DDFC4BAC0B7616F5F44649A ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
01:02:12.0252 0x0f34  WinDefend - ok
01:02:12.0274 0x0f34  WinHttpAutoProxySvc - ok
01:02:12.0583 0x0f34  [ 6B2A1D0E80110E3D04E6863C6E62FD8A, EE8BC7C378993EFE90273764C83119EBF331768CD7B24DE949233C74A51306C2 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
01:02:12.0651 0x0f34  Winmgmt - ok
01:02:12.0738 0x0f34  [ 01874D4689C212460FBABF0ECD7CB7F7, 8FC46BAD704A1E057DC4A8DC7374AAB93A96CC4A46E06FF9C2E06A6D62820469 ] WinRM           C:\Windows\system32\WsmSvc.dll
01:02:12.0913 0x0f34  WinRM - ok
01:02:13.0117 0x0f34  [ C008405E4FEEB069E30DA1D823910234, C392A7B5FEACB7D11A3A231C1AD65D533984E6E7429ECD3BFBF90A27E8DEB157 ] Wlansvc         C:\Windows\System32\wlansvc.dll
01:02:13.0263 0x0f34  Wlansvc - ok
01:02:13.0307 0x0f34  [ 2E7255D172DF0B8283CDFB7B433B864E, 60C786CF0EA4A29B309B9457F0496D5A0AF1F093FC2C5D88078865814B7DBBA3 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
01:02:13.0413 0x0f34  WmiAcpi - ok
01:02:13.0461 0x0f34  [ 43BE3875207DCB62A85C8C49970B66CC, 27169F2E8A30807794407DA8F80611E4287F940AAE2A1F00F547901872FB9703 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
01:02:13.0575 0x0f34  wmiApSrv - ok
01:02:13.0955 0x0f34  [ 3978704576A121A9204F8CC49A301A9B, 936CC13B90A183613BDA4081556C96D48CA415B5F65D61E18CB5F2E51EEBE59F ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
01:02:14.0115 0x0f34  WMPNetworkSvc - ok
01:02:14.0178 0x0f34  [ CFC5A04558F5070CEE3E3A7809F3FF52, 45899E04000E21C4E009BE8B6149F199A5B2E0512C657A525770BF9DBFED7D2B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
01:02:14.0269 0x0f34  WPCSvc - ok
01:02:14.0316 0x0f34  [ 801FBDB89D472B3C467EB112A0FC9246, C24053FA12732089384D3AF06C676FF201D282FC5AD56A42B6EE8BAED4379CB2 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
01:02:14.0416 0x0f34  WPDBusEnum - ok
01:02:14.0486 0x0f34  [ DE9D36F91A4DF3D911626643DEBF11EA, 8029ECE76E29276BFB6ED3387AC560A9A779AAF683A4416E96334FAF7BDBADA0 ] WpdUsb          C:\Windows\system32\DRIVERS\wpdusb.sys
01:02:14.0588 0x0f34  WpdUsb - ok
01:02:14.0743 0x0f34  [ DCF3E3EDF5109EE8BC02FE6E1F045795, 4B8E14B1CFB095982D34DAEC336114F5039D7793080FB787DC95A63B6B945DD0 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
01:02:14.0850 0x0f34  WPFFontCache_v0400 - ok
01:02:14.0919 0x0f34  [ E3A3CB253C0EC2494D4A61F5E43A389C, 10BA8B102E31B961819E524FCA5FA817B588EC77FB26B4E176D0A5CFF11EDF79 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
01:02:15.0006 0x0f34  ws2ifsl - ok
01:02:15.0064 0x0f34  [ 1CA6C40261DDC0425987980D0CD2AAAB, 727C1E3A170316641F832A8D197EDA6D6EE1206E4ED7B741E5A4017B7F2F7B88 ] wscsvc          C:\Windows\system32\wscsvc.dll
01:02:15.0163 0x0f34  wscsvc - ok
01:02:15.0173 0x0f34  WSearch - ok
01:02:15.0394 0x0f34  [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv        C:\Windows\system32\wuaueng.dll
01:02:15.0666 0x0f34  wuauserv - ok
01:02:15.0760 0x0f34  [ AC13CB789D93412106B0FB6C7EB2BCB6, 8F5B0BD0CBBAB182A400F8994D4727BC0C978D749B6429A2D41B412AE97428B6 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
01:02:15.0838 0x0f34  WUDFRd - ok
01:02:15.0877 0x0f34  [ 575A4190D989F64732119E4114045A4F, 373C344B106AFDB1E6125A21DFE28CA6CFC77FA87FE904656A4F209DB2ED69C7 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
01:02:15.0951 0x0f34  wudfsvc - ok
01:02:16.0028 0x0f34  [ 32396B4D2BF707D81C20E5E9022A2055, 7161B0270E39118ABD408F83630211DA5730E10650ECD0B3944D4B15EEAB0F69 ] ZTEusbmdm6k     C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys
01:02:16.0228 0x0f34  ZTEusbmdm6k - ok
01:02:16.0261 0x0f34  [ 32396B4D2BF707D81C20E5E9022A2055, 7161B0270E39118ABD408F83630211DA5730E10650ECD0B3944D4B15EEAB0F69 ] ZTEusbnmea      C:\Windows\system32\DRIVERS\ZTEusbnmea.sys
01:02:16.0365 0x0f34  ZTEusbnmea - ok
01:02:16.0413 0x0f34  [ 32396B4D2BF707D81C20E5E9022A2055, 7161B0270E39118ABD408F83630211DA5730E10650ECD0B3944D4B15EEAB0F69 ] ZTEusbser6k     C:\Windows\system32\DRIVERS\ZTEusbser6k.sys
01:02:16.0520 0x0f34  ZTEusbser6k - ok
01:02:16.0566 0x0f34  [ 32396B4D2BF707D81C20E5E9022A2055, 7161B0270E39118ABD408F83630211DA5730E10650ECD0B3944D4B15EEAB0F69 ] ZTEusbvoice     C:\Windows\system32\DRIVERS\ZTEusbvoice.sys
01:02:16.0672 0x0f34  ZTEusbvoice - ok
01:02:16.0740 0x0f34  {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054} - ok
01:02:16.0741 0x0f34  ================ Scan global ===============================
01:02:16.0787 0x0f34  [ F31EEBC1A1C81FD04005489CC3DCDFE7, 098C35ACFCCE1686C5A6DB6057001CBF8B06A863A0802CB2E9D793F4795F8CEE ] C:\Windows\system32\basesrv.dll
01:02:16.0853 0x0f34  [ 40864DA48A14EBC68A0D6BFD08BA21EB, EF311D4A937ADE53216949CB2E690582883C30B70BFCB89F82433CA2FBF1E24E ] C:\Windows\system32\winsrv.dll
01:02:16.0913 0x0f34  [ 40864DA48A14EBC68A0D6BFD08BA21EB, EF311D4A937ADE53216949CB2E690582883C30B70BFCB89F82433CA2FBF1E24E ] C:\Windows\system32\winsrv.dll
01:02:17.0000 0x0f34  [ D4E6D91C1349B7BFB3599A6ADA56851B, 8748091BF27F05D28D45688E04DD9229A4B2E159209A64F457703F66A8CECE4D ] C:\Windows\system32\services.exe
01:02:17.0025 0x0f34  [ Global ] - ok
01:02:17.0026 0x0f34  ================ Scan MBR ==================================
01:02:17.0038 0x0f34  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
01:02:17.0393 0x0f34  \Device\Harddisk0\DR0 - ok
01:02:17.0394 0x0f34  ================ Scan VBR ==================================
01:02:17.0404 0x0f34  [ 08C2636F36FC80B812F5AE44E556ACB8 ] \Device\Harddisk0\DR0\Partition1
01:02:17.0458 0x0f34  \Device\Harddisk0\DR0\Partition1 - ok
01:02:17.0459 0x0f34  ================ Scan generic autorun ======================
01:02:17.0501 0x0f34  [ 9F5F8F97D5F18AE35F986CE593F7D01B, C612933B52113B5B0935EE845050F4CC9A7FBFCCECE20170D314AEB4C1E3CD7C ] C:\Windows\system32\igfxtray.exe
01:02:17.0754 0x0f34  IgfxTray - ok
01:02:17.0817 0x0f34  [ 55750597BAA561644674C6F673C08302, 602209C1EDD60F73CE2E05A0DF74C66D783B685E74EC569EED6EEB08771C359B ] C:\Windows\system32\hkcmd.exe
01:02:18.0062 0x0f34  HotKeysCmds - ok
01:02:18.0124 0x0f34  [ FF51AA0D606326B9842EA5A3F02060D5, F661EA2647C27BFF7D476FD724A4919C2029DDA75948C5B43E43ADC77130EB16 ] C:\Windows\system32\igfxpers.exe
01:02:18.0362 0x0f34  Persistence - ok
01:02:18.0758 0x0f34  [ C3C40834D72095517D2944ED5910DC67, 5062D6487013D78223AC11FA97C065BA2A7D51F7C8592ED6C89DE13D318630F1 ] C:\Windows\RtHDVCpl.exe
01:02:19.0352 0x0f34  RtHDVCpl - ok
01:02:19.0521 0x0f34  [ 0F31EFC96FFB8B5DEA52B92271944A7B, 1143977D2F6E4E5556DBCF9E8B2B703603DD1F98FD77B3867161FFCA857197E9 ] C:\Windows\Skytel.exe
01:02:19.0829 0x0f34  Skytel - ok
01:02:19.0892 0x0f34  [ 2AC7F8B8BF0D5D327A3A2A00453222C4, F71B6CFA7F4AE2A13C8DDF296631EF26C72E7C0387D88B9701577DAE133EC583 ] C:\Windows\PLFSetI.exe
01:02:19.0943 0x0f34  PLFSetI - detected UnsignedFile.Multi.Generic ( 1 )
01:02:21.0756 0x0f34  Detect skipped due to KSN trusted
01:02:21.0757 0x0f34  PLFSetI - ok
01:02:21.0810 0x0f34  [ 0A80BED61A1729DAB9499BC5A9B515A9, C6AB21181B4377E0204B1D8534D026A5B10EF79B7E37606A5D25A82B356B14DA ] C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
01:02:21.0848 0x0f34  RemoteControl8 - ok
01:02:21.0898 0x0f34  [ 04C40F2EFB9F333E16CE33A2D283829F, 7EE276F1B3B501EA585D99FF06BC8F889668443DE5B0E97C06E87397CE68EF94 ] C:\Program Files\Cyberlink\Shared Files\brs.exe
01:02:21.0927 0x0f34  BDRegion - ok
01:02:22.0008 0x0f34  [ 644795F6985C740F5E36E9336B837D0B, 2531274063468D7F1B1C26EAD5183BAF114AA46C7106F18F260BF49D37EED1B8 ] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
01:02:22.0037 0x0f34  GrooveMonitor - ok
01:02:22.0114 0x0f34  [ 9ACE8ECDB1EBC519F48AA65DE5875573, FE46B6E41E5A74FDA001A3AA24C597B39176C3B71EDFF7D5092D330F0DA5A587 ] C:\Program Files\Common Files\Real\Update_OB\realsched.exe
01:02:22.0159 0x0f34  TkBellExe - ok
01:02:22.0402 0x0f34  [ 07A37CB5C5A01E73FB69F138FAE2DB0E, 9E8B5D78D7EAB8FA35133763EDA91AFE5CDEE275D604F02CDB56FB00A0D5AA0F ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
01:02:22.0508 0x0f34  Adobe ARM - ok
01:02:22.0537 0x0f34  OLPSYNCH - ok
01:02:22.0651 0x0f34  [ 03396637E1E1B4E333D00AED86178918, CF582487E856D01C960392AC658E8D36A92F2B2B4B9AEA9BFC9E6F75FBAD6571 ] c:\Program Files\Microsoft Security Client\msseces.exe
01:02:22.0779 0x0f34  MSC - ok
01:02:22.0885 0x0f34  [ 14D6542607ACD4B2D1DDB1A36E0D8813, 3A270600549E8E7988D5AF3486C0F504269B9573393D87BF87BDB2287BF007B2 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
01:02:22.0935 0x0f34  SunJavaUpdateSched - ok
01:02:22.0999 0x0f34  [ B4EE64488B0A47F3B9598DA6C8913CC7, 8313A0D10AC07BBA079F57C306EB590352DDE37019F674445AEB7DB8F71F8E58 ] C:\Program Files\SMART BRO\UIExec.exe
01:02:23.0031 0x0f34  UIExec - ok
01:02:23.0207 0x0f34  [ 9E35FF7F943AE0FB89192BFE058B7FD4, 54712A4FA296AE28CF834F90B77B2EEB69020E3D5B5CF24674BD8DACA25195B9 ] C:\Program Files\Windows Sidebar\sidebar.exe
01:02:23.0426 0x0f34  Sidebar - ok
01:02:23.0488 0x0f34  [ BF08674925F151BD4537B89A493E3E0C, 6A97562E998A2B90649FF7986313AD33823053FF98BBE163AD39AAA5E01FC545 ] C:\Windows\ehome\ehTray.exe
01:02:23.0555 0x0f34  ehTray.exe - ok
01:02:23.0638 0x0f34  [ 2BAD84B393AF47006D80BA2F03B18029, 72E7A5906E48C6318533D9657D32B29E9AB1D76E25C2C0C6D4C34077561493A2 ] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
01:02:23.0742 0x0f34  ISUSPM - ok
01:02:23.0878 0x0f34  [ 2A3FB4C98F139038E23330D2439DB8A4, DE9253AD362B03FA5D3D4912662398E5C4AC76F7274B83E51C251A6921A5B838 ] C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe
01:02:23.0913 0x0f34  Facebook Update - ok
01:02:23.0921 0x0f34  Adobe Speed Launcher - ok
01:02:23.0925 0x0f34  Waiting for KSN requests completion. In queue: 92
01:02:24.0925 0x0f34  Waiting for KSN requests completion. In queue: 92
01:02:25.0925 0x0f34  Waiting for KSN requests completion. In queue: 92
01:02:26.0400 0x10d4  Object required for P2P: [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost
01:02:26.0966 0x0f34  Waiting for KSN requests completion. In queue: 74
01:02:27.0966 0x0f34  Waiting for KSN requests completion. In queue: 74
01:02:28.0847 0x10d4  Object send P2P result: true
01:02:28.0858 0x10d4  Object required for P2P: [ BF08674925F151BD4537B89A493E3E0C ] C:\Windows\ehome\ehTray.exe
01:02:28.0966 0x0f34  Waiting for KSN requests completion. In queue: 3
01:02:29.0966 0x0f34  Waiting for KSN requests completion. In queue: 3
01:02:30.0966 0x0f34  Waiting for KSN requests completion. In queue: 3
01:02:31.0228 0x10d4  Object send P2P result: true
01:02:32.0089 0x0f34  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x61000 ( enabled : updated )
01:02:32.0143 0x0f34  Win FW state via NFP2: enabled
01:02:33.0566 0x0f34  ============================================================
01:02:33.0566 0x0f34  Scan finished
01:02:33.0566 0x0f34  ============================================================
01:02:33.0594 0x0200  Detected object count: 0
01:02:33.0594 0x0200  Actual detected object count: 0
01:02:54.0468 0x1580  Deinitialize success
 

Hello, 
 
Lets continue checking for malware/adware. 
 
STEP 1
[external image: E3feWj5.png] Junkware Removal Tool (JRT)

  • Please download Junkware Removal Tool and save the file to your Desktop.
  • Create a System Restore Point. For instructions, please refer to the following link (Vista).
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Right-Click JRT.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts and allow the scan to run uninterrupted. 
  • Upon completion, a log (JRT.txt) will open on your desktop.
  • Re-enable your anti-virus software.
  • Copy the contents of JRT.txt and paste in your next reply.
     

STEP 2
[external image: BY4dvz9.png] AdwCleaner

  • Please download AdwCleaner and save the file to your Desktop.
  • Right-Click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts. 
  • Click Scan. 
  • Upon completion, click Report. A log (AdwCleaner[R0].txt) will open. Briefly check the log for anything you know to be legitimate. 
  • Ensure anything you know to be legitimate does not have a checkmark, and click Clean. 
  • Follow the prompts and allow your computer to reboot. 
  • After rebooting, a log (AdwCleaner[S0].txt) will open. Copy the contents of the log and paste in your next reply.

– File and folder backups are made for items removed using this tool. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[R0].txt.
 
 
======================================================

STEP 3
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • JRT.txt
  • AdwCleaner[S0].txt

1. Here is the log from the Junkware Removal Tool:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows Vista (TM) Home Premium x86
Ran by [removed] on 08/02/2015 at  0:28:19.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Program Files\orbitdownloader"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08/02/2015 at  0:33:49.36
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

2. Here is the log from the AdwCleaner:

 

# AdwCleaner v4.110 - Logfile created 08/02/2015 at 01:14:32
# Updated 05/02/2015 by Xplode
# Database : 2015-02-05.2 [Local]
# Operating system : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Username : user - USER-PC
# Running from : C:\Users\user\Downloads\AdwCleaner.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\users\user\AppData\Local\CrashRpt
Folder Deleted : C:\users\user\AppData\Roaming\GrabPro
Folder Deleted : C:\users\user\AppData\Roaming\ProgSense

***** [ Scheduled tasks ] *****

Task Deleted : RunAsStdUser Task

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Download by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Grab video by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Do&wnload selected by Orbit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Down&load all by Orbit
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3F1D494B-0CEF-4468-96C9-386E2E4DEC90}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7854F00C-DC77-477E-A10E-603F48442D3B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A1CCCE0D-AE21-42A2-BE58-8E6109410995}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CD4D7B0F-45C6-4bb2-A1E7-54D1754E7FC5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0880527-DC28-4EBB-BA27-D22102F22A9F}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{BCDDE143-FAE3-4C57-B22B-C4E8678CFDC0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000123B4-9B42-4900-B3F7-F4B073EFC214}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C55BBCD6-41AD-48AD-9953-3609C48EACC7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4250488A-CB24-0893-C066-B1AEA57BCFF2}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\Orbit
Key Deleted : HKCU\Software\ProgSense
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Orbit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Orbit_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Orbit_is1

***** [ Web browsers ] *****

-\\ Internet Explorer v8.0.6001.18943


-\\ Mozilla Firefox v35.0.1 (x86 en-US)


-\\ Google Chrome v


-\\ Chromium v


*************************

AdwCleaner[R0].txt - [3069 bytes] - [08/02/2015 00:38:06]
AdwCleaner[R1].txt - [3128 bytes] - [08/02/2015 00:45:26]
AdwCleaner[R2].txt - [3187 bytes] - [08/02/2015 00:56:56]
AdwCleaner[S0].txt - [3174 bytes] - [08/02/2015 01:14:32]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3233  bytes] ##########
 

Hello, 
 
Those logs are OK. 
Lets continue checking. We may find what we're dealing with is unrelated to malware. 
 
STEP 1
[external image: GfiJrQ9.png] Malwarebytes Anti-Malware (MBAM)

  • Your version of Malwarebytes Anti-Malware is outdated. Download the update on top of your current version. 
  • Open mbam-setup.x.x.xxxx.exe (x represents the version #) and follow the prompts to install the programme. 
  • Open Malwarebytes Anti-Malware and click Update Now.
  • Once updated, click the Settings tab, followed by Detection and Protection and tick Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is checked and click Scan Now.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards. 
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • Click Copy to Clipboard and paste the log in your next reply. 
     

STEP 2
[external image: GzlsbnV.png] ESET Online Scan
Note: This scan may take a long time to complete. Please do not browse the Internet whilst your Anti-Virus is disabled.

  • Please download ESET Online Scan and save the file to your Desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then click Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Place a checkmark next to Enable detection of potentially unwanted applications.
  • Click Advanced settings. Place a checkmark next to:
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Ensure Remove found threats is unchecked.
  • Click Start.
  • Wait for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click [external image: esetListThreats.png]. If no threats were found, skip the next two bullet points. 
  • Click [external image: esetExport.png] and save the file to your Desktop, naming it something such as "MyEsetScan".
  • Push the Back button.
  • Place a checkmark next to [external image: xKN1w2nv.png.pagespeed.ic.JWqIaEgZi7.png] and click [external image: SzOC1p0.png.pagespeed.ce.OWDP45O6oG.png].
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
     

STEP 3
[external image: mlEX1wH.png] RogueKiller

  • Please download RogueKiller (x32) and save the file to your Desktop.
  • Close any running programmes.
  • Right-Click RogueKiller.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Allow the Prescan to complete. Upon completion, a window will open. Click Accept.
  • A browser window may open. Close the browser window.
  • Click [external image: jpgUwzp.png]. Upon completion, click [external image: phPvmc6.png].
  • Close the programme. Do not fix anything!
  • A log (RKreport.txt) will be open. Copy the contents of the log and paste in your next reply.
     

======================================================
 
STEP 4
[external image: pfNZP4A.png] Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • MBAM Scan log
  • ESET Online Scan log
  • RKreport.txt

Hello there. I'm sorry for the late reply. I just started at my new job. Please let me get back to you tomorrow with the logs that you requested. I'm having an internet connection problem right now. It's really slow. I think it's the reason why I can't run MBAM.

 

I’ve downloaded the free version of the Malwarebytes Anti-Malware from the link that you have provided; however, when I run the program, I got an error message: The setup files are corrupted. Please obtain a new copy of the program.

 

I’ve tried it three times, and I still got the same error message.

Hello, 

 

Please do the following, and try redownloading/reinstalling MBAM. 

 

[external image: x6YRrgUC.png.pagespeed.ic.HjgFxjvw2Z.jpg] MBAM Clean

  • Please read the following article on how to run MBAM Clean. 
  • (!) Ensure you follow the correct set of instructions depending on which version you have (Free or Premium).
  • Download and install the latest version of MBAM as per the instructions.  

I'm sorry. I thought I already sent the logs this morning. I was finally able to run all the scans. Here are the logs.

 

MBAM Scan log

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 15/02/2015
Scan Time: 02:10:23
Logfile: mbam.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.02.14.04
Rootkit Database: v2015.02.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows Vista Service Pack 2
CPU: x86
File System: NTFS
User: user

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 358868
Time Elapsed: 1 hr, 7 min, 27 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.Softonic.A, HKU\S-1-5-21-722566208-2681290114-2279458060-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{930F1200-F5F1-4870-BAC6-E233EC8E7023}, Quarantined, [987ac3579eec46f00f1ebd459f646997],
PUP.Optional.Softonic.A, HKU\S-1-5-21-722566208-2681290114-2279458060-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{930F1200-F5F1-4870-BAC6-E233EC8E7023}, Quarantined, [987ac3579eec46f00f1ebd459f646997],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 4
PUP.Optional.IWin.A, C:\ProgramData\iWin Games, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\drm\data, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],

Files: 4
PUP.Optional.Iwin, C:\Users\user\Downloads\chuzzle-setup.exe, Quarantined, [e230a872c7c3ae88d1a0bc746e92b050],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\Flash.ocx, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\FlashPlayerControl.dll, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],
PUP.Optional.IWin.A, C:\ProgramData\iWin Games\opal\opal.ver, Quarantined, [2ee4d347a4e6e94d68986a05a261fd03],

Physical Sectors: 0
(No malicious items detected)


(end)

 

ESET Online Scan log

 

C:\D-drive-96751\movies\ECI\LPO Wave 12\Scribe\express scribe_v5.30.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\LPO Wave 12\Scribe\scribe.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\LPO Wave 12\Scribe\uninst.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Express\edsetup_v5.58.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Express\express.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Express\uninst.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Scribe\essetup_v5.52.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Scribe\scribe.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\movies\ECI\USB FILES\QUESTRONIX\NCH Software\Scribe\uninst.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\NCH Software\Scribe\essetup_v5.52.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\NCH Software\Scribe\scribe.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\D-drive-96751\NCH Software\Scribe\uninst.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\Ask\ApnIC.dll    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\Ask\ApnStub.exe    a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\Ask\ApnToolbarInstaller.exe    a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\Ask\AskPIP_FF_.exe    a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-egypt.exe    a variant of Win32/Hao123.A potentially unwanted application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-japan.exe    a variant of Win32/Hao123.A potentially unwanted application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst-saudi-forf.exe    a variant of Win32/Hao123.D potentially unwanted application
C:\Program Files\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe    a variant of Win32/Hao123.A potentially unwanted application
C:\Program Files\NCH Software\Scribe\scribe.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Program Files\NCH Software\Scribe\scribesetup_v5.63.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Users\user\Desktop\FOLDERS\USB\Scribe\express scribe_v5.30.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\user\Desktop\FOLDERS\USB\Scribe\scribe.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\user\Desktop\FOLDERS\USB\Scribe\uninst.exe    a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\user\Downloads\essetup.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Users\user\Downloads\ezvid.exe    Win32/OpenCandy potentially unsafe application
C:\Users\user\Downloads\ffsetup.exe    a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
C:\Users\user\Downloads\orbitdownload_setup.exe    Win32/OpenCandy potentially unsafe application
C:\Windows\Installer\MSIDFE8.tmp    a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application
 

RKreport.txt

 

RogueKiller V10.2.0.0 [Jan 19 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User : user [Administrator]
Mode : Scan – Date : 02/15/2015  12:21:57

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 13 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | Skytel : Skytel.exe  -> Found
[Hidden.From.SCM] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AFD (\SystemRoot\system32\drivers\afd.sys) -> Found
[PUM.HomePage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.HomePage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : -> Found
[PUM.SearchPage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : -> Found
[PUM.SearchPage] HKEY_USERS\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Internet Explorer\Main | Search Page : -> Found
[PUM.SearchPage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : -> Found
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ADDC55A4-81C7-4A27-9E54-D027BE216942} | NameServer : 121.1.3.172 121.1.3.89 [PHILIPPINES (PH)][PHILIPPINES (PH)]  -> Found
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ADDC55A4-81C7-4A27-9E54-D027BE216942} | NameServer : 121.1.3.172 121.1.3.89 [PHILIPPINES (PH)][PHILIPPINES (PH)]  -> Found
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031A47-3F72-44A7-89C5-5595FE6B30EE} : 1  -> Found
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1  -> Found
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-722566208-2681290114-2279458060-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1       localhost

¤¤¤ Antirootkit : 1 (Driver: Loaded) ¤¤¤
[Filter(Kernel.Filter)] \Driver\atapi @ Unknown : \Driver\cdrom @ \Device\CdRom0 (\SystemRoot\system32\drivers\irenum.sys)

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MK1646GSX ATA Device +++++
— User —
[MBR] 0e4ee1c2cace05251abb4a263513a249
[BSP] 6c03bacf61537fc4e9637227991386e3 : HP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 152623 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 … OK
User = LL2 … OK

+++++ PhysicalDrive1: ZTE MMC Storage USB Device +++++
Error reading User MBR! ([15] The device is not ready. )
Error reading LL1 MBR! NOT VALID!
Error reading LL2 MBR! ([32] The request is not supported. )


============================================
RKreport_SCN_02152015_120644.log

Hello, 
 

I'm sorry. I thought I already sent the logs this morning. I was finally able to run all the scans. Here are the logs.

That's quite alright. 
 
Is your Internet Service Provider (ISP) Smart Broadband Incorporated?
 
Please let me know how the machine is performing after doing the following. Are you still experiencing the issues described in your first post?

[external image: xlK5Hdb.png] Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key [external image: pdKOQKY.png] + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    start
    CreateRestorePoint:
    C:\Program Files\FreeTime\FormatFactory\FFModules\Package\Ask
    C:\Program Files\FreeTime\FormatFactory\FFModules\Package\BaiDu
    C:\Users\user\Downloads\essetup.exe
    C:\Users\user\Downloads\ezvid.exe
    C:\Users\user\Downloads\ffsetup.exe
    C:\Users\user\Downloads\orbitdownload_setup.exe
    C:\Windows\Installer\MSIDFE8.tmp
    EmptyTemp:
    end
  • Click File, Save As and type fixlist.txt as the File Name. 
  • Important: The file must be saved in the same location as FRST.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI