On my work laptop I cannot get on line, IE9 gives the stopped working error and Chrome times out, I cant get on line so I am posting all this from my daughters MacMini. I have read the instruction and hope that all I have listed below is accurate as I am in a bad spot.
this is the error I get from IE9
Files that help describe the problem:
C:\Users\jrybak\AppData\Local\Temp\WER823A.tmp.WERInternalMetadata.xml
C:\Users\jrybak\AppData\Local\Temp\WER9741.tmp.appcompat.txt
C:\Users\jrybak\AppData\Local\Temp\WER9751.tmp.mdmp
Mbam Log
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.02.26.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
jrybak :: RHPROPNB01 [administrator]
2/25/2013 9:22:32 PM
mbam-log-2013-02-25 (21-22-32).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206965
Time elapsed: 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 1.6.0_20
Run by jrybak at 21:28:14 on 2013-02-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8124.6345 [GMT -6:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqscrproj.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\Windows\system32\spool\DRIVERS\x64\3\OPHGLDCS.EXE
C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqScrProxy.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dcute.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Users\jrybak\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Client Security Solution\password_manager.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe
C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig?hl=en&source=iglk
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe
BHO: Fast Search: {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [Google Update] "C:\Users\jrybak\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
StartupFolder: C:\Users\jrybak\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\jrybak\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoWelcomeScreen = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: DisableCAD = dword:1
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {A6616B31-4860-41E2-98E3-CA7649AF172F} - file:///E:/launch.ocx
DPF: {AA299E98-6FB5-409F-99D3-D30D749F4864} - hxxp://managed.jbtech.com/inc/kaxRemote.dll
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.13.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7}\25549435348434F4 : DHCPNameServer = 192.168.1.3 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7}\345435C402D20275942554C4543535 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{AF6BCD99-3C80-422B-B6EA-4B70A928B3E2} : DHCPNameServer = 172.16.206.215 172.16.206.215 8.8.8.8
TCP: Interfaces\{F633A54D-F5B4-49AA-9A6E-DE98A3A32B45} : DHCPNameServer = 192.168.1.1
AppInit_DLLs= acaptuser32.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
LSA: Notification Packages = scecli ACGina C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
x64-Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
x64-Run: [Lenovo dCute] "C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dCute.exe"
x64-Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
x64-Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
x64-Notify: psfus - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 ALvldr;ALvldr;C:\Windows\System32\drivers\ALvldr.sys [2010-1-19 28736]
R0 DzHDD64;DzHDD64;C:\Windows\System32\drivers\DZHDD64.SYS [2010-3-12 29512]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\System32\drivers\ApsHM64.sys [2011-3-29 23664]
R1 dqBridge;dqBridge;C:\Windows\System32\drivers\dqbridge.sys [2010-1-19 57408]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\System32\drivers\smiifx64.sys [2012-4-24 15472]
R2 AMPPALR3;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-3-15 659976]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-4-23 135952]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-18 13336]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2010-11-18 165032]
R2 KjsUpdateService2;AppLife Update Service 2.0;C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe [2011-8-2 12800]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2010-11-18 50536]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2012-4-24 101736]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2010-11-18 74088]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [2010-4-30 6237800]
R2 OKI OPHG DCS Loader;OKI OPHG DCS Loader;C:\Windows\System32\spool\drivers\x64\3\OPHGLDCS.EXE [2011-3-9 20480]
R2 QDLService2kLenovo;Qualcomm Gobi 2000 Download Service (Lenovo);C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [2011-5-23 1688384]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2010-3-12 61952]
R2 ScrProj;Lenovo USB Display Screen Projector;C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqscrproj.exe [2010-1-15 88576]
R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2011-5-30 13128]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2012-4-24 145256]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2012-4-24 142696]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-9-29 12728]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-3-12 2533400]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-6-25 3325232]
R3 AMPPAL;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2012-3-15 198144]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-4-13 35104]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2010-3-12 292864]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2012-2-2 509104]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-3-12 56344]
R3 LenovoRd;LenovoRd;C:\Windows\System32\drivers\LenovoRd.sys [2010-3-12 118016]
R3 lvlddrv;Lenovo DsplyFltDrv Filter Driver;C:\Windows\System32\drivers\lvlddrv.sys [2010-1-19 94784]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-1-22 77824]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-1-22 180224]
R3 qcfilterlno2k;Gobi 2000 USB Composite Device Filter Driver(05C6-9205);C:\Windows\System32\drivers\qcfilterlno2k.sys [2009-12-8 6400]
R3 qcusbnetlno2k;Gobi 2000 USB-NDIS miniport(05C6-9205);C:\Windows\System32\drivers\qcusbnetlno2k.sys [2011-5-23 444416]
R3 qcusbserlno2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9205);C:\Windows\System32\drivers\qcusbserlno2k.sys [2011-5-23 231040]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\drivers\Smb_driver_Intel.sys [2013-1-31 44344]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\System32\drivers\tvti2c.sys [2009-10-8 41536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 5U877;USB Video Device;C:\Windows\System32\drivers\5U877.sys [2010-11-18 163072]
S3 AMPPALP;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2012-3-15 198144]
S3 androidusb;ADB Interface Driver;C:\Windows\System32\drivers\androidusb.sys [2010-4-29 32768]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2011-9-19 54824]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2013-1-31 320576]
S3 dqusb;Driver for dCute_Lenovo;C:\Windows\System32\drivers\dqusb.sys [2009-8-6 29688]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-8-21 1436424]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2010-4-19 22528]
S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2009-9-15 6952960]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2010-3-12 38536]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2010-3-12 1666112]
S3 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2012-4-24 1665088]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-1-31 19456]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-1-31 57856]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-9-29 126392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 UsbFltr;WayTech USB Filter Driver;C:\Windows\System32\drivers\UsbFltr.sys [2007-4-9 12288]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-26 1255736]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile=C:\Windows\System32\notepad.exe "%1"
.
=============== Created Last 30 ================
.
2013-02-25 16:46:55996352----a-w-C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-25 16:46:55768000----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-25 16:40:295553512----a-w-C:\Windows\System32\ntoskrnl.exe
2013-02-25 16:40:263967848----a-w-C:\Windows\SysWow64\ntkrnlpa.exe
2013-02-25 16:40:243913064----a-w-C:\Windows\SysWow64\ntoskrnl.exe
2013-02-25 16:40:173153408----a-w-C:\Windows\System32\win32k.sys
2013-02-25 16:40:09288088----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-02-25 16:40:091913192----a-w-C:\Windows\System32\drivers\tcpip.sys
2013-02-25 16:39:277680----a-w-C:\Windows\SysWow64\instnm.exe
2013-02-25 16:39:275120----a-w-C:\Windows\SysWow64\wow32.dll
2013-02-25 16:39:2725600----a-w-C:\Windows\SysWow64\setup16.exe
2013-02-25 16:39:27215040----a-w-C:\Windows\System32\winsrv.dll
2013-02-25 16:39:272048----a-w-C:\Windows\SysWow64\user.exe
2013-02-25 16:39:2714336----a-w-C:\Windows\SysWow64\ntvdm64.dll
2013-02-24 10:26:109162192----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EE2E3824-54E6-43E2-A4D7-D90871E9E8B7}\mpengine.dll
2013-01-31 18:44:509728----a-w-C:\Windows\System32\Wdfres.dll
2013-01-31 18:44:50785512----a-w-C:\Windows\System32\drivers\Wdf01000.sys
2013-01-31 18:44:5054376----a-w-C:\Windows\System32\drivers\WdfLdr.sys
2013-01-31 18:44:502560----a-w-C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-01-31 18:18:3046080----a-w-C:\Windows\System32\atmlib.dll
2013-01-31 18:18:30367616----a-w-C:\Windows\System32\atmfd.dll
2013-01-31 18:18:3034304----a-w-C:\Windows\SysWow64\atmlib.dll
2013-01-31 18:18:30295424----a-w-C:\Windows\SysWow64\atmfd.dll
2013-01-31 18:17:1087040----a-w-C:\Windows\System32\drivers\WUDFPf.sys
2013-01-31 18:17:10198656----a-w-C:\Windows\System32\drivers\WUDFRd.sys
2013-01-31 18:17:0984992----a-w-C:\Windows\System32\WUDFSvc.dll
2013-01-31 18:17:09194048----a-w-C:\Windows\System32\WUDFPlatform.dll
2013-01-31 18:17:0745056----a-w-C:\Windows\System32\WUDFCoinstaller.dll
2013-01-31 18:17:06744448----a-w-C:\Windows\System32\WUDFx.dll
2013-01-31 18:17:06229888----a-w-C:\Windows\System32\WUDFHost.exe
2013-01-31 17:47:482002432----a-w-C:\Windows\System32\msxml6.dll
2013-01-31 17:44:17458712----a-w-C:\Windows\System32\drivers\cng.sys
2013-01-31 17:44:17340992----a-w-C:\Windows\System32\schannel.dll
2013-01-31 17:44:17247808----a-w-C:\Windows\SysWow64\schannel.dll
2013-01-31 17:44:17154480----a-w-C:\Windows\System32\drivers\ksecpkg.sys
2013-01-31 17:44:171448448----a-w-C:\Windows\System32\lsasrv.dll
2013-01-31 17:44:1596768----a-w-C:\Windows\SysWow64\sspicli.dll
2013-01-31 17:44:1522016----a-w-C:\Windows\SysWow64\secur32.dll
2013-01-31 17:43:48216576----a-w-C:\Windows\System32\ncsi.dll
2013-01-31 17:43:47246272----a-w-C:\Windows\System32\netcorehc.dll
2013-01-31 17:43:47156672----a-w-C:\Windows\SysWow64\ncsi.dll
2013-01-31 17:43:4670656----a-w-C:\Windows\System32\nlaapi.dll
2013-01-31 17:43:46569344----a-w-C:\Windows\System32\iphlpsvc.dll
2013-01-31 17:43:4652224----a-w-C:\Windows\SysWow64\nlaapi.dll
2013-01-31 17:43:4645568----a-w-C:\Windows\System32\drivers\tcpipreg.sys
2013-01-31 17:43:46303104----a-w-C:\Windows\System32\nlasvc.dll
2013-01-31 17:43:4618944----a-w-C:\Windows\SysWow64\netevent.dll
2013-01-31 17:43:4618944----a-w-C:\Windows\System32\netevent.dll
2013-01-31 17:43:46175104----a-w-C:\Windows\SysWow64\netcorehc.dll
2013-01-31 17:42:44307200----a-w-C:\Windows\System32\ncrypt.dll
2013-01-31 17:42:44220160----a-w-C:\Windows\SysWow64\ncrypt.dll
2013-01-31 17:42:37245760----a-w-C:\Windows\System32\OxpsConverter.exe
2013-01-31 17:42:181659760----a-w-C:\Windows\System32\drivers\ntfs.sys
2013-01-31 17:42:13715776----a-w-C:\Windows\System32\kerberos.dll
2013-01-31 17:42:13542208----a-w-C:\Windows\SysWow64\kerberos.dll
2013-01-31 17:42:08800768----a-w-C:\Windows\System32\usp10.dll
2013-01-31 17:42:07626688----a-w-C:\Windows\SysWow64\usp10.dll
2013-01-31 17:41:5555296----a-w-C:\Windows\System32\dhcpcsvc6.dll
2013-01-31 17:41:5544032----a-w-C:\Windows\SysWow64\dhcpcsvc6.dll
2013-01-31 17:41:55226816----a-w-C:\Windows\System32\dhcpcore6.dll
2013-01-31 17:41:55193536----a-w-C:\Windows\SysWow64\dhcpcore6.dll
2013-01-31 17:41:38220160----a-w-C:\Windows\System32\wintrust.dll
2013-01-31 17:41:38172544----a-w-C:\Windows\SysWow64\wintrust.dll
2013-01-31 17:41:32750592----a-w-C:\Windows\System32\win32spl.dll
2013-01-31 17:41:32492032----a-w-C:\Windows\SysWow64\win32spl.dll
2013-01-31 17:41:28478208----a-w-C:\Windows\System32\dpnet.dll
2013-01-31 17:41:28376832----a-w-C:\Windows\SysWow64\dpnet.dll
2013-01-31 17:39:50184320----a-w-C:\Windows\System32\cryptsvc.dll
2013-01-31 17:39:501464320----a-w-C:\Windows\System32\crypt32.dll
2013-01-31 17:39:50140288----a-w-C:\Windows\SysWow64\cryptsvc.dll
2013-01-31 17:39:50140288----a-w-C:\Windows\System32\cryptnet.dll
2013-01-31 17:39:501159680----a-w-C:\Windows\SysWow64\crypt32.dll
2013-01-31 17:39:49103936----a-w-C:\Windows\SysWow64\cryptnet.dll
2013-01-31 17:39:0895744----a-w-C:\Windows\System32\synceng.dll
2013-01-31 17:39:0878336----a-w-C:\Windows\SysWow64\synceng.dll
2013-01-31 17:39:0868608----a-w-C:\Windows\System32\taskhost.exe
2013-01-31 16:48:39--------d-----w-C:\Users\jrybak\AppData\Local\Lenovo
2013-01-31 16:43:3353248----a-r-C:\Users\jrybak\AppData\Roaming\Microsoft\Installer\{0369F866-2CE0-4EB9-B426-88FA122C6E82}\ARPPRODUCTICON.exe
2013-01-31 16:43:3053248----a-r-C:\Users\jrybak\AppData\Roaming\Microsoft\Installer\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}\ARPPRODUCTICON.exe
2013-01-31 16:37:2672048----a-w-C:\Windows\System32\ibmpmctl.exe
2013-01-31 16:37:2660272----a-w-C:\Windows\System32\ibmpmsvc.exe
2013-01-31 16:37:2642824----a-w-C:\Windows\System32\drivers\ibmpmdrv.sys
2013-01-31 16:37:2639792----a-w-C:\Windows\System32\tpinspm.dll
2013-01-31 16:35:45215336----a-w-C:\Windows\System32\SynTPAPI.dll
2013-01-31 16:35:451395760----a-w-C:\Windows\System32\drivers\SynTP.sys
2013-01-31 16:35:45107816----a-w-C:\Windows\SysWow64\SynTPCOM.dll
2013-01-31 16:35:44400168----a-w-C:\Windows\System32\SynCOM.dll
2013-01-31 16:35:44273704----a-w-C:\Windows\System32\SynCtrl.dll
2013-01-31 16:35:44218408----a-w-C:\Windows\SysWow64\SynCtrl.dll
2013-01-31 16:35:44173352----a-w-C:\Windows\SysWow64\SynCOM.dll
2013-01-31 16:35:02--------d-----w-C:\Program Files\Synaptics
2013-01-31 16:33:541721576----a-w-C:\Windows\System32\WdfCoInstaller01009.dll
2013-01-31 16:33:44177976----a-w-C:\Windows\System32\SynTPCo14.dll
2013-01-31 16:33:431048576----a-w-C:\Windows\System32\syndata.bin
2013-01-31 16:33:4244344----a-w-C:\Windows\System32\drivers\Smb_driver_Intel.sys
2013-01-30 03:01:21--------dc----w-C:\Users\jrybak\AppData\Local\MigWiz
2013-01-29 21:26:19--------d-----w-C:\Program Files\Common Files\SPBA
2013-01-29 21:26:17--------d-----w-C:\Program Files (x86)\Common Files\SPBA
2013-01-29 21:26:16--------d-----w-C:\Program Files\ThinkVantage Fingerprint Software
2013-01-28 16:48:4468864----a-w-C:\Windows\System32\drivers\stream.sys
2013-01-28 16:37:34--------d-----w-C:\Program Files (x86)\Cisco
2013-01-28 16:31:53--------d-----w-C:\Program Files\AuthenTec
2013-01-28 16:30:17569152----a-w-C:\Windows\System32\drivers\iaStor.sys
.
==================== Find3M ====================
.
2013-02-23 15:12:52861088----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2013-02-23 15:12:52782240----a-w-C:\Windows\SysWow64\deployJava1.dll
2013-02-12 17:13:1674096----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-12 17:13:16697712----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-17 07:28:58273840------w-C:\Windows\System32\MpSigStub.exe
2013-01-09 01:19:092312704----a-w-C:\Windows\System32\jscript9.dll
2013-01-09 01:12:031392128----a-w-C:\Windows\System32\wininet.dll
2013-01-09 01:11:061494528----a-w-C:\Windows\System32\inetcpl.cpl
2013-01-09 01:07:51173056----a-w-C:\Windows\System32\ieUnatt.exe
2013-01-09 01:07:47599040----a-w-C:\Windows\System32\vbscript.dll
2013-01-09 01:04:422382848----a-w-C:\Windows\System32\mshtml.tlb
2013-01-08 22:11:211800704----a-w-C:\Windows\SysWow64\jscript9.dll
2013-01-08 22:03:201129472----a-w-C:\Windows\SysWow64\wininet.dll
2013-01-08 22:03:121427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2013-01-08 21:59:02142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2013-01-08 21:58:29420864----a-w-C:\Windows\SysWow64\vbscript.dll
2013-01-08 21:56:232382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2013-01-04 04:43:2144032----a-w-C:\Windows\apppatch\acwow64.dll
2012-12-14 22:49:2824176----a-w-C:\Windows\System32\drivers\mbam.sys
2012-12-07 13:20:16441856----a-w-C:\Windows\System32\Wpc.dll
2012-12-07 13:15:312746368----a-w-C:\Windows\System32\gameux.dll
2012-12-07 12:26:17308736----a-w-C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:432576384----a-w-C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:0430720----a-w-C:\Windows\System32\usk.rs
2012-12-07 11:20:0343520----a-w-C:\Windows\System32\csrr.rs
2012-12-07 11:20:0323552----a-w-C:\Windows\System32\oflc.rs
2012-12-07 11:20:0145568----a-w-C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:0144544----a-w-C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:0120480----a-w-C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:0020480----a-w-C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:5920480----a-w-C:\Windows\System32\pegi.rs
2012-12-07 11:19:5846592----a-w-C:\Windows\System32\fpb.rs
2012-12-07 11:19:5740960----a-w-C:\Windows\System32\cob-au.rs
2012-12-07 11:19:5721504----a-w-C:\Windows\System32\grb.rs
2012-12-07 11:19:5715360----a-w-C:\Windows\System32\djctq.rs
2012-12-07 11:19:5655296----a-w-C:\Windows\System32\cero.rs
2012-12-07 11:19:5551712----a-w-C:\Windows\System32\esrb.rs
2012-11-30 05:45:35362496----a-w-C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35243200----a-w-C:\Windows\System32\wow64.dll
2012-11-30 05:45:3513312----a-w-C:\Windows\System32\wow64cpu.dll
2012-11-30 05:43:1216384----a-w-C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07424448----a-w-C:\Windows\System32\KernelBase.dll
2012-11-30 04:53:59274944----a-w-C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48338432----a-w-C:\Windows\System32\conhost.exe
2012-11-30 02:38:596144---ha-w-C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:594608---ha-w-C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:593584---ha-w-C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:593072---ha-w-C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 21:28:28.94 ===============
this is the error I get from IE9
Files that help describe the problem:
C:\Users\jrybak\AppData\Local\Temp\WER823A.tmp.WERInternalMetadata.xml
C:\Users\jrybak\AppData\Local\Temp\WER9741.tmp.appcompat.txt
C:\Users\jrybak\AppData\Local\Temp\WER9751.tmp.mdmp
Mbam Log
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2013.02.26.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
jrybak :: RHPROPNB01 [administrator]
2/25/2013 9:22:32 PM
mbam-log-2013-02-25 (21-22-32).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206965
Time elapsed: 56 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
DDS
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 1.6.0_20
Run by jrybak at 21:28:14 on 2013-02-25
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.8124.6345 [GMT -6:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqscrproj.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlk.exe
C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
C:\Windows\system32\spool\DRIVERS\x64\3\OPHGLDCS.EXE
C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Lenovo\Client Security Solution\tvttcsd.exe
C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqScrProxy.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dcute.exe
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Users\jrybak\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files\ThinkPad\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Lenovo\Client Security Solution\password_manager.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Lenovo\Client Security Solution\password_manager.exe
C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
C:\Windows\system32\svchost.exe -k HsfXAudioService
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig?hl=en&source=iglk
uSearch Bar = Preserve
mWinlogon: Userinit = userinit.exe
BHO: Fast Search: {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: IePasswordManagerHelper Class: {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [Google Update] "C:\Users\jrybak\AppData\Local\Google\Update\GoogleUpdate.exe" /c
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
StartupFolder: C:\Users\jrybak\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\jrybak\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-Explorer: NoWelcomeScreen = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
mPolicies-System: DisableCAD = dword:1
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {A6616B31-4860-41E2-98E3-CA7649AF172F} - file:///E:/launch.ocx
DPF: {AA299E98-6FB5-409F-99D3-D30D749F4864} - hxxp://managed.jbtech.com/inc/kaxRemote.dll
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.3.13.0.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7}\25549435348434F4 : DHCPNameServer = 192.168.1.3 192.168.1.1
TCP: Interfaces\{623E3D4C-4F39-40E3-8056-6A1422205DF7}\345435C402D20275942554C4543535 : DHCPNameServer = 192.168.2.1
TCP: Interfaces\{AF6BCD99-3C80-422B-B6EA-4B70A928B3E2} : DHCPNameServer = 172.16.206.215 172.16.206.215 8.8.8.8
TCP: Interfaces\{F633A54D-F5B4-49AA-9A6E-DE98A3A32B45} : DHCPNameServer = 192.168.1.1
AppInit_DLLs= acaptuser32.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
LSA: Notification Packages = scecli ACGina C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
x64-Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup
x64-Run: [Lenovo dCute] "C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dCute.exe"
x64-Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent
x64-Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
x64-Notify: psfus - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
x64-SSODL: WebCheck - <orphaned>
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 ALvldr;ALvldr;C:\Windows\System32\drivers\ALvldr.sys [2010-1-19 28736]
R0 DzHDD64;DzHDD64;C:\Windows\System32\drivers\DZHDD64.SYS [2010-3-12 29512]
R0 TPDIGIMN;TPDIGIMN;C:\Windows\System32\drivers\ApsHM64.sys [2011-3-29 23664]
R1 dqBridge;dqBridge;C:\Windows\System32\drivers\dqbridge.sys [2010-1-19 57408]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\System32\drivers\smiifx64.sys [2012-4-24 15472]
R2 AMPPALR3;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Service;C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [2012-3-15 659976]
R2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) + High Speed Security Service;C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [2012-4-23 135952]
R2 HsfXAudioService;HsfXAudioService;C:\Windows\System32\svchost.exe -k HsfXAudioService [2009-7-13 27136]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-18 13336]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2010-11-18 165032]
R2 KjsUpdateService2;AppLife Update Service 2.0;C:\Program Files (x86)\Common Files\AppLifeUpdateService2\kjsausvc.exe [2011-8-2 12800]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2010-11-18 50536]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2012-4-24 101736]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2010-11-18 74088]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [2010-4-30 6237800]
R2 OKI OPHG DCS Loader;OKI OPHG DCS Loader;C:\Windows\System32\spool\drivers\x64\3\OPHGLDCS.EXE [2011-3-9 20480]
R2 QDLService2kLenovo;Qualcomm Gobi 2000 Download Service (Lenovo);C:\Program Files (x86)\QUALCOMM\QDLService2k\QDLService2kLenovo.exe [2011-5-23 1688384]
R2 rimspci;rimspci;C:\Windows\System32\drivers\rimspe64.sys [2010-3-12 61952]
R2 ScrProj;Lenovo USB Display Screen Projector;C:\Program Files\Lenovo\ThinkPad USB Port Replicator with Digital Video\dqscrproj.exe [2010-1-15 88576]
R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [2011-5-30 13128]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2012-4-24 145256]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2012-4-24 142696]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-9-29 12728]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-3-12 2533400]
R2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2012-6-25 3325232]
R3 AMPPAL;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Virtual Adapter;C:\Windows\System32\drivers\AmpPal.sys [2012-3-15 198144]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2010-4-13 35104]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\System32\drivers\CAXHWAZL.sys [2010-3-12 292864]
R3 e1kexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver K;C:\Windows\System32\drivers\e1k62x64.sys [2012-2-2 509104]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-3-12 56344]
R3 LenovoRd;LenovoRd;C:\Windows\System32\drivers\LenovoRd.sys [2010-3-12 118016]
R3 lvlddrv;Lenovo DsplyFltDrv Filter Driver;C:\Windows\System32\drivers\lvlddrv.sys [2010-1-19 94784]
R3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-1-22 77824]
R3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-1-22 180224]
R3 qcfilterlno2k;Gobi 2000 USB Composite Device Filter Driver(05C6-9205);C:\Windows\System32\drivers\qcfilterlno2k.sys [2009-12-8 6400]
R3 qcusbnetlno2k;Gobi 2000 USB-NDIS miniport(05C6-9205);C:\Windows\System32\drivers\qcusbnetlno2k.sys [2011-5-23 444416]
R3 qcusbserlno2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9205);C:\Windows\System32\drivers\qcusbserlno2k.sys [2011-5-23 231040]
R3 SmbDrvI;SmbDrvI;C:\Windows\System32\drivers\Smb_driver_Intel.sys [2013-1-31 44344]
R3 TVTI2C;Lenovo SM bus driver;C:\Windows\System32\drivers\tvti2c.sys [2009-10-8 41536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 5U877;USB Video Device;C:\Windows\System32\drivers\5U877.sys [2010-11-18 163072]
S3 AMPPALP;IntelÆ CentrinoÆ Wireless BluetoothÆ + High Speed Protocol;C:\Windows\System32\drivers\AmpPal.sys [2012-3-15 198144]
S3 androidusb;ADB Interface Driver;C:\Windows\System32\drivers\androidusb.sys [2010-4-29 32768]
S3 btusbflt;Bluetooth USB Filter;C:\Windows\System32\drivers\btusbflt.sys [2011-9-19 54824]
S3 cpudrv64;cpudrv64;C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys [2009-12-18 17864]
S3 DozeSvc;Lenovo Doze Mode Service;C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [2013-1-31 320576]
S3 dqusb;Driver for dCute_Lenovo;C:\Windows\System32\drivers\dqusb.sys [2009-8-6 29688]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2010-8-21 1436424]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2010-4-19 22528]
S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2009-9-15 6952960]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]
S3 pmxdrv;pmxdrv;C:\Windows\System32\drivers\pmxdrv.sys [2010-3-12 38536]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2010-3-12 1666112]
S3 PwmEWSvc;Cisco EnergyWise Enabler;C:\Program Files (x86)\ThinkPad\Utilities\PWMEWSVC.exe [2012-4-24 1665088]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-1-31 19456]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-1-31 57856]
S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-9-29 126392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 UsbFltr;WayTech USB Filter Driver;C:\Windows\System32\drivers\UsbFltr.sys [2007-4-9 12288]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-3-26 1255736]
.
=============== File Associations ===============
.
FileExt: .scr: AutoCADScriptFile=C:\Windows\System32\notepad.exe "%1"
.
=============== Created Last 30 ================
.
2013-02-25 16:46:55996352----a-w-C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-25 16:46:55768000----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-25 16:40:295553512----a-w-C:\Windows\System32\ntoskrnl.exe
2013-02-25 16:40:263967848----a-w-C:\Windows\SysWow64\ntkrnlpa.exe
2013-02-25 16:40:243913064----a-w-C:\Windows\SysWow64\ntoskrnl.exe
2013-02-25 16:40:173153408----a-w-C:\Windows\System32\win32k.sys
2013-02-25 16:40:09288088----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-02-25 16:40:091913192----a-w-C:\Windows\System32\drivers\tcpip.sys
2013-02-25 16:39:277680----a-w-C:\Windows\SysWow64\instnm.exe
2013-02-25 16:39:275120----a-w-C:\Windows\SysWow64\wow32.dll
2013-02-25 16:39:2725600----a-w-C:\Windows\SysWow64\setup16.exe
2013-02-25 16:39:27215040----a-w-C:\Windows\System32\winsrv.dll
2013-02-25 16:39:272048----a-w-C:\Windows\SysWow64\user.exe
2013-02-25 16:39:2714336----a-w-C:\Windows\SysWow64\ntvdm64.dll
2013-02-24 10:26:109162192----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EE2E3824-54E6-43E2-A4D7-D90871E9E8B7}\mpengine.dll
2013-01-31 18:44:509728----a-w-C:\Windows\System32\Wdfres.dll
2013-01-31 18:44:50785512----a-w-C:\Windows\System32\drivers\Wdf01000.sys
2013-01-31 18:44:5054376----a-w-C:\Windows\System32\drivers\WdfLdr.sys
2013-01-31 18:44:502560----a-w-C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2013-01-31 18:18:3046080----a-w-C:\Windows\System32\atmlib.dll
2013-01-31 18:18:30367616----a-w-C:\Windows\System32\atmfd.dll
2013-01-31 18:18:3034304----a-w-C:\Windows\SysWow64\atmlib.dll
2013-01-31 18:18:30295424----a-w-C:\Windows\SysWow64\atmfd.dll
2013-01-31 18:17:1087040----a-w-C:\Windows\System32\drivers\WUDFPf.sys
2013-01-31 18:17:10198656----a-w-C:\Windows\System32\drivers\WUDFRd.sys
2013-01-31 18:17:0984992----a-w-C:\Windows\System32\WUDFSvc.dll
2013-01-31 18:17:09194048----a-w-C:\Windows\System32\WUDFPlatform.dll
2013-01-31 18:17:0745056----a-w-C:\Windows\System32\WUDFCoinstaller.dll
2013-01-31 18:17:06744448----a-w-C:\Windows\System32\WUDFx.dll
2013-01-31 18:17:06229888----a-w-C:\Windows\System32\WUDFHost.exe
2013-01-31 17:47:482002432----a-w-C:\Windows\System32\msxml6.dll
2013-01-31 17:44:17458712----a-w-C:\Windows\System32\drivers\cng.sys
2013-01-31 17:44:17340992----a-w-C:\Windows\System32\schannel.dll
2013-01-31 17:44:17247808----a-w-C:\Windows\SysWow64\schannel.dll
2013-01-31 17:44:17154480----a-w-C:\Windows\System32\drivers\ksecpkg.sys
2013-01-31 17:44:171448448----a-w-C:\Windows\System32\lsasrv.dll
2013-01-31 17:44:1596768----a-w-C:\Windows\SysWow64\sspicli.dll
2013-01-31 17:44:1522016----a-w-C:\Windows\SysWow64\secur32.dll
2013-01-31 17:43:48216576----a-w-C:\Windows\System32\ncsi.dll
2013-01-31 17:43:47246272----a-w-C:\Windows\System32\netcorehc.dll
2013-01-31 17:43:47156672----a-w-C:\Windows\SysWow64\ncsi.dll
2013-01-31 17:43:4670656----a-w-C:\Windows\System32\nlaapi.dll
2013-01-31 17:43:46569344----a-w-C:\Windows\System32\iphlpsvc.dll
2013-01-31 17:43:4652224----a-w-C:\Windows\SysWow64\nlaapi.dll
2013-01-31 17:43:4645568----a-w-C:\Windows\System32\drivers\tcpipreg.sys
2013-01-31 17:43:46303104----a-w-C:\Windows\System32\nlasvc.dll
2013-01-31 17:43:4618944----a-w-C:\Windows\SysWow64\netevent.dll
2013-01-31 17:43:4618944----a-w-C:\Windows\System32\netevent.dll
2013-01-31 17:43:46175104----a-w-C:\Windows\SysWow64\netcorehc.dll
2013-01-31 17:42:44307200----a-w-C:\Windows\System32\ncrypt.dll
2013-01-31 17:42:44220160----a-w-C:\Windows\SysWow64\ncrypt.dll
2013-01-31 17:42:37245760----a-w-C:\Windows\System32\OxpsConverter.exe
2013-01-31 17:42:181659760----a-w-C:\Windows\System32\drivers\ntfs.sys
2013-01-31 17:42:13715776----a-w-C:\Windows\System32\kerberos.dll
2013-01-31 17:42:13542208----a-w-C:\Windows\SysWow64\kerberos.dll
2013-01-31 17:42:08800768----a-w-C:\Windows\System32\usp10.dll
2013-01-31 17:42:07626688----a-w-C:\Windows\SysWow64\usp10.dll
2013-01-31 17:41:5555296----a-w-C:\Windows\System32\dhcpcsvc6.dll
2013-01-31 17:41:5544032----a-w-C:\Windows\SysWow64\dhcpcsvc6.dll
2013-01-31 17:41:55226816----a-w-C:\Windows\System32\dhcpcore6.dll
2013-01-31 17:41:55193536----a-w-C:\Windows\SysWow64\dhcpcore6.dll
2013-01-31 17:41:38220160----a-w-C:\Windows\System32\wintrust.dll
2013-01-31 17:41:38172544----a-w-C:\Windows\SysWow64\wintrust.dll
2013-01-31 17:41:32750592----a-w-C:\Windows\System32\win32spl.dll
2013-01-31 17:41:32492032----a-w-C:\Windows\SysWow64\win32spl.dll
2013-01-31 17:41:28478208----a-w-C:\Windows\System32\dpnet.dll
2013-01-31 17:41:28376832----a-w-C:\Windows\SysWow64\dpnet.dll
2013-01-31 17:39:50184320----a-w-C:\Windows\System32\cryptsvc.dll
2013-01-31 17:39:501464320----a-w-C:\Windows\System32\crypt32.dll
2013-01-31 17:39:50140288----a-w-C:\Windows\SysWow64\cryptsvc.dll
2013-01-31 17:39:50140288----a-w-C:\Windows\System32\cryptnet.dll
2013-01-31 17:39:501159680----a-w-C:\Windows\SysWow64\crypt32.dll
2013-01-31 17:39:49103936----a-w-C:\Windows\SysWow64\cryptnet.dll
2013-01-31 17:39:0895744----a-w-C:\Windows\System32\synceng.dll
2013-01-31 17:39:0878336----a-w-C:\Windows\SysWow64\synceng.dll
2013-01-31 17:39:0868608----a-w-C:\Windows\System32\taskhost.exe
2013-01-31 16:48:39--------d-----w-C:\Users\jrybak\AppData\Local\Lenovo
2013-01-31 16:43:3353248----a-r-C:\Users\jrybak\AppData\Roaming\Microsoft\Installer\{0369F866-2CE0-4EB9-B426-88FA122C6E82}\ARPPRODUCTICON.exe
2013-01-31 16:43:3053248----a-r-C:\Users\jrybak\AppData\Roaming\Microsoft\Installer\{6E6E7725-C7BC-4C39-8B3F-14B67331A120}\ARPPRODUCTICON.exe
2013-01-31 16:37:2672048----a-w-C:\Windows\System32\ibmpmctl.exe
2013-01-31 16:37:2660272----a-w-C:\Windows\System32\ibmpmsvc.exe
2013-01-31 16:37:2642824----a-w-C:\Windows\System32\drivers\ibmpmdrv.sys
2013-01-31 16:37:2639792----a-w-C:\Windows\System32\tpinspm.dll
2013-01-31 16:35:45215336----a-w-C:\Windows\System32\SynTPAPI.dll
2013-01-31 16:35:451395760----a-w-C:\Windows\System32\drivers\SynTP.sys
2013-01-31 16:35:45107816----a-w-C:\Windows\SysWow64\SynTPCOM.dll
2013-01-31 16:35:44400168----a-w-C:\Windows\System32\SynCOM.dll
2013-01-31 16:35:44273704----a-w-C:\Windows\System32\SynCtrl.dll
2013-01-31 16:35:44218408----a-w-C:\Windows\SysWow64\SynCtrl.dll
2013-01-31 16:35:44173352----a-w-C:\Windows\SysWow64\SynCOM.dll
2013-01-31 16:35:02--------d-----w-C:\Program Files\Synaptics
2013-01-31 16:33:541721576----a-w-C:\Windows\System32\WdfCoInstaller01009.dll
2013-01-31 16:33:44177976----a-w-C:\Windows\System32\SynTPCo14.dll
2013-01-31 16:33:431048576----a-w-C:\Windows\System32\syndata.bin
2013-01-31 16:33:4244344----a-w-C:\Windows\System32\drivers\Smb_driver_Intel.sys
2013-01-30 03:01:21--------dc----w-C:\Users\jrybak\AppData\Local\MigWiz
2013-01-29 21:26:19--------d-----w-C:\Program Files\Common Files\SPBA
2013-01-29 21:26:17--------d-----w-C:\Program Files (x86)\Common Files\SPBA
2013-01-29 21:26:16--------d-----w-C:\Program Files\ThinkVantage Fingerprint Software
2013-01-28 16:48:4468864----a-w-C:\Windows\System32\drivers\stream.sys
2013-01-28 16:37:34--------d-----w-C:\Program Files (x86)\Cisco
2013-01-28 16:31:53--------d-----w-C:\Program Files\AuthenTec
2013-01-28 16:30:17569152----a-w-C:\Windows\System32\drivers\iaStor.sys
.
==================== Find3M ====================
.
2013-02-23 15:12:52861088----a-w-C:\Windows\SysWow64\npDeployJava1.dll
2013-02-23 15:12:52782240----a-w-C:\Windows\SysWow64\deployJava1.dll
2013-02-12 17:13:1674096----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-12 17:13:16697712----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-17 07:28:58273840------w-C:\Windows\System32\MpSigStub.exe
2013-01-09 01:19:092312704----a-w-C:\Windows\System32\jscript9.dll
2013-01-09 01:12:031392128----a-w-C:\Windows\System32\wininet.dll
2013-01-09 01:11:061494528----a-w-C:\Windows\System32\inetcpl.cpl
2013-01-09 01:07:51173056----a-w-C:\Windows\System32\ieUnatt.exe
2013-01-09 01:07:47599040----a-w-C:\Windows\System32\vbscript.dll
2013-01-09 01:04:422382848----a-w-C:\Windows\System32\mshtml.tlb
2013-01-08 22:11:211800704----a-w-C:\Windows\SysWow64\jscript9.dll
2013-01-08 22:03:201129472----a-w-C:\Windows\SysWow64\wininet.dll
2013-01-08 22:03:121427968----a-w-C:\Windows\SysWow64\inetcpl.cpl
2013-01-08 21:59:02142848----a-w-C:\Windows\SysWow64\ieUnatt.exe
2013-01-08 21:58:29420864----a-w-C:\Windows\SysWow64\vbscript.dll
2013-01-08 21:56:232382848----a-w-C:\Windows\SysWow64\mshtml.tlb
2013-01-04 04:43:2144032----a-w-C:\Windows\apppatch\acwow64.dll
2012-12-14 22:49:2824176----a-w-C:\Windows\System32\drivers\mbam.sys
2012-12-07 13:20:16441856----a-w-C:\Windows\System32\Wpc.dll
2012-12-07 13:15:312746368----a-w-C:\Windows\System32\gameux.dll
2012-12-07 12:26:17308736----a-w-C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:432576384----a-w-C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:0430720----a-w-C:\Windows\System32\usk.rs
2012-12-07 11:20:0343520----a-w-C:\Windows\System32\csrr.rs
2012-12-07 11:20:0323552----a-w-C:\Windows\System32\oflc.rs
2012-12-07 11:20:0145568----a-w-C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:0144544----a-w-C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:0120480----a-w-C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:0020480----a-w-C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:5920480----a-w-C:\Windows\System32\pegi.rs
2012-12-07 11:19:5846592----a-w-C:\Windows\System32\fpb.rs
2012-12-07 11:19:5740960----a-w-C:\Windows\System32\cob-au.rs
2012-12-07 11:19:5721504----a-w-C:\Windows\System32\grb.rs
2012-12-07 11:19:5715360----a-w-C:\Windows\System32\djctq.rs
2012-12-07 11:19:5655296----a-w-C:\Windows\System32\cero.rs
2012-12-07 11:19:5551712----a-w-C:\Windows\System32\esrb.rs
2012-11-30 05:45:35362496----a-w-C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35243200----a-w-C:\Windows\System32\wow64.dll
2012-11-30 05:45:3513312----a-w-C:\Windows\System32\wow64cpu.dll
2012-11-30 05:43:1216384----a-w-C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07424448----a-w-C:\Windows\System32\KernelBase.dll
2012-11-30 04:53:59274944----a-w-C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48338432----a-w-C:\Windows\System32\conhost.exe
2012-11-30 02:38:596144---ha-w-C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:594608---ha-w-C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:593584---ha-w-C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:593072---ha-w-C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 21:28:28.94 ===============