Inactive [A] Svchost.exe malware help blue screening

Status
Not open for further replies.

aznsaik0

Posts: 15   +0
Hello, I am having lots of trouble getting ridding of this rootkit/malware. I'm not sure what exactly it is either. Malwarebytes picks up the virus but it wont get rid of it after a restart. I've tried using ComboFix and rkill, but I'm not sure if I did it right. Someone please help!'
35lc0at.png
 
Welcome aboard
yahooo.gif


Please, complete all steps listed here: https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running tools or applying updates other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

===================================================

Never run Combofix on your own.
 
2012/06/07 00:02:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50607, Process: svchost.exe)
2012/06/07 00:02:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50610, Process: svchost.exe)
2012/06/07 00:19:39 -0700JUSTIN-PCJustinMESSAGEStarting protection
2012/06/07 00:19:40 -0700JUSTIN-PCJustinMESSAGEProtection started successfully
2012/06/07 00:19:43 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
2012/06/07 00:19:45 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
2012/06/07 00:20:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 49682, Process: svchost.exe)
2012/06/07 00:20:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 49751, Process: svchost.exe)
2012/06/07 00:26:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50927, Process: svchost.exe)
2012/06/07 00:26:26 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50991, Process: svchost.exe)
2012/06/07 00:26:34 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51009, Process: svchost.exe)
2012/06/07 00:27:22 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51167, Process: svchost.exe)
2012/06/07 00:27:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51179, Process: svchost.exe)
2012/06/07 00:27:46 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 51205, Process: svchost.exe)
2012/06/07 00:27:54 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 51380, Process: svchost.exe)
2012/06/07 00:28:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51426, Process: svchost.exe)
2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51640, Process: svchost.exe)
2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51647, Process: svchost.exe)
2012/06/07 00:29:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51648, Process: svchost.exe)
2012/06/07 00:30:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51777, Process: svchost.exe)
2012/06/07 00:31:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52027, Process: svchost.exe)
2012/06/07 00:31:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52109, Process: svchost.exe)
2012/06/07 00:32:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52247, Process: svchost.exe)
2012/06/07 00:33:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52377, Process: svchost.exe)
2012/06/07 00:33:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52416, Process: svchost.exe)
2012/06/07 00:33:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52469, Process: svchost.exe)
2012/06/07 00:33:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52472, Process: svchost.exe)
2012/06/07 00:34:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52769, Process: svchost.exe)
2012/06/07 00:35:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52785, Process: svchost.exe)
2012/06/07 00:36:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 52873, Process: svchost.exe)
2012/06/07 00:37:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53020, Process: svchost.exe)
2012/06/07 00:38:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53294, Process: svchost.exe)
2012/06/07 00:41:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53848, Process: svchost.exe)
2012/06/07 00:41:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53851, Process: svchost.exe)
2012/06/07 00:41:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53854, Process: svchost.exe)
2012/06/07 00:41:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 53881, Process: svchost.exe)
2012/06/07 00:43:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54367, Process: svchost.exe)
2012/06/07 00:44:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54612, Process: svchost.exe)
2012/06/07 00:44:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 54615, Process: svchost.exe)
2012/06/07 00:46:12 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55128, Process: svchost.exe)
2012/06/07 00:46:28 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55156, Process: svchost.exe)
2012/06/07 00:47:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55371, Process: svchost.exe)
2012/06/07 00:47:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55375, Process: svchost.exe)
2012/06/07 00:47:48 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55508, Process: svchost.exe)
2012/06/07 00:49:17 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55866, Process: svchost.exe)
2012/06/07 00:49:17 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 55869, Process: svchost.exe)
2012/06/07 00:50:13 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56072, Process: svchost.exe)
2012/06/07 00:50:21 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56075, Process: svchost.exe)
2012/06/07 00:50:37 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56078, Process: svchost.exe)
2012/06/07 00:51:09 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56227, Process: svchost.exe)
2012/06/07 00:51:25 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56383, Process: svchost.exe)
2012/06/07 00:51:57 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56414, Process: svchost.exe)
2012/06/07 00:52:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56633, Process: svchost.exe)
2012/06/07 00:52:37 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56666, Process: svchost.exe)
2012/06/07 00:52:53 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56697, Process: svchost.exe)
2012/06/07 00:53:25 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 56867, Process: svchost.exe)
2012/06/07 00:53:33 -0700JUSTIN-PCJustinIP-BLOCK89.108.64.196 (Type: outgoing, Port: 56914, Process: svchost.exe)
2012/06/07 00:54:05 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57034, Process: svchost.exe)
2012/06/07 00:54:21 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57113, Process: svchost.exe)
2012/06/07 00:55:41 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57452, Process: svchost.exe)
2012/06/07 00:56:13 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57609, Process: svchost.exe)
2012/06/07 00:56:21 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 57642, Process: svchost.exe)
2012/06/07 00:56:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57666, Process: svchost.exe)
2012/06/07 00:56:29 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57673, Process: svchost.exe)
2012/06/07 00:57:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57911, Process: svchost.exe)
2012/06/07 00:58:06 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57916, Process: svchost.exe)
2012/06/07 00:58:06 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 57939, Process: svchost.exe)
2012/06/07 01:00:38 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58211, Process: svchost.exe)
2012/06/07 01:00:38 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58215, Process: svchost.exe)
2012/06/07 01:01:10 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58250, Process: svchost.exe)
2012/06/07 01:03:34 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58970, Process: svchost.exe)
2012/06/07 01:03:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 58990, Process: svchost.exe)
2012/06/07 01:04:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59040, Process: svchost.exe)
2012/06/07 01:04:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59074, Process: svchost.exe)
2012/06/07 01:04:30 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59077, Process: svchost.exe)
2012/06/07 01:06:14 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59308, Process: svchost.exe)
2012/06/07 01:07:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59649, Process: svchost.exe)
2012/06/07 01:07:42 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59662, Process: svchost.exe)
2012/06/07 01:07:51 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59676, Process: svchost.exe)
2012/06/07 01:07:51 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59687, Process: svchost.exe)
2012/06/07 01:08:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59761, Process: svchost.exe)
2012/06/07 01:08:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59788, Process: svchost.exe)
2012/06/07 01:08:47 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59878, Process: svchost.exe)
2012/06/07 01:08:47 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 59914, Process: svchost.exe)
2012/06/07 01:10:07 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60214, Process: svchost.exe)
2012/06/07 01:10:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60344, Process: svchost.exe)
2012/06/07 01:11:19 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60438, Process: svchost.exe)
2012/06/07 01:11:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 60484, Process: svchost.exe)
2012/06/07 01:11:27 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 60485, Process: svchost.exe)
2012/06/07 01:12:07 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 60727, Process: svchost.exe)
2012/06/07 01:15:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61280, Process: svchost.exe)
2012/06/07 01:15:35 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61295, Process: svchost.exe)
2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61478, Process: svchost.exe)
2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61482, Process: svchost.exe)
2012/06/07 01:16:23 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61485, Process: svchost.exe)
2012/06/07 01:18:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61802, Process: svchost.exe)
2012/06/07 01:18:31 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61821, Process: svchost.exe)
2012/06/07 01:18:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61831, Process: svchost.exe)
2012/06/07 01:18:39 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61834, Process: svchost.exe)
2012/06/07 01:19:27 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61928, Process: svchost.exe)
2012/06/07 01:19:35 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 61931, Process: svchost.exe)
2012/06/07 01:20:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 61987, Process: svchost.exe)
2012/06/07 01:20:24 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62000, Process: svchost.exe)
2012/06/07 01:20:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62056, Process: svchost.exe)
2012/06/07 01:21:04 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62142, Process: svchost.exe)
2012/06/07 01:21:36 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62305, Process: svchost.exe)
2012/06/07 01:22:16 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62419, Process: svchost.exe)
2012/06/07 01:22:32 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62510, Process: svchost.exe)
2012/06/07 01:22:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62514, Process: svchost.exe)
2012/06/07 01:22:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62522, Process: svchost.exe)
2012/06/07 01:22:48 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62563, Process: svchost.exe)
2012/06/07 01:23:28 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 62737, Process: svchost.exe)
2012/06/07 01:24:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 62965, Process: svchost.exe)
2012/06/07 01:24:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63001, Process: svchost.exe)
2012/06/07 01:24:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63018, Process: svchost.exe)
2012/06/07 01:24:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63024, Process: svchost.exe)
2012/06/07 01:25:44 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63334, Process: svchost.exe)
2012/06/07 01:26:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63446, Process: svchost.exe)
2012/06/07 01:26:32 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 63513, Process: svchost.exe)
2012/06/07 01:26:39 -0700JUSTIN-PCJustinMESSAGEExecuting scheduled update: Daily
2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEScheduled update executed successfully: database updated from version v2012.06.06.05 to version v2012.06.07.02
2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEStarting database refresh
2012/06/07 01:26:44 -0700JUSTIN-PCJustinMESSAGEStopping IP protection
2012/06/07 01:28:18 -0700JUSTIN-PCJustinMESSAGEIP Protection stopped
2012/06/07 01:28:20 -0700JUSTIN-PCJustinMESSAGEDatabase refreshed successfully
2012/06/07 01:28:20 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
2012/06/07 01:28:21 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
2012/06/07 01:29:16 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 64359, Process: svchost.exe)
2012/06/07 01:29:24 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 64438, Process: svchost.exe)
2012/06/07 01:33:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65332, Process: svchost.exe)
2012/06/07 01:33:40 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 65336, Process: svchost.exe)
2012/06/07 01:33:40 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65339, Process: svchost.exe)
2012/06/07 01:34:20 -0700JUSTIN-PCJustinIP-BLOCK78.41.203.118 (Type: outgoing, Port: 65355, Process: svchost.exe)
2012/06/07 01:34:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65358, Process: svchost.exe)
2012/06/07 01:35:08 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 65383, Process: svchost.exe)
2012/06/07 15:23:25 -0700JUSTIN-PCJustinMESSAGEStarting protection
2012/06/07 15:23:27 -0700JUSTIN-PCJustinMESSAGEProtection started successfully
2012/06/07 15:23:30 -0700JUSTIN-PCJustinMESSAGEStarting IP protection
2012/06/07 15:23:31 -0700JUSTIN-PCJustinMESSAGEIP Protection started successfully
2012/06/07 15:27:15 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50356, Process: svchost.exe)
2012/06/07 15:27:23 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 50371, Process: svchost.exe)
2012/06/07 15:36:20 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51104, Process: svchost.exe)
2012/06/07 15:38:04 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51186, Process: svchost.exe)
2012/06/07 15:38:04 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51190, Process: svchost.exe)
2012/06/07 15:38:21 -0700JUSTIN-PCJustinIP-BLOCK206.161.121.6 (Type: outgoing, Port: 51202, Process: svchost.exe)
2012/06/07 15:38:37 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51215, Process: svchost.exe)
2012/06/07 15:39:17 -0700JUSTIN-PCJustinIP-BLOCK173.236.56.93 (Type: outgoing, Port: 51436, Process: svchost.exe)

_______________________________________________________________________________________________________

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 7/14/2011 4:16:56 PM
System Uptime: 6/7/2012 3:20:58 PM (0 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | GA-880GA-UD3H
Processor: AMD Phenom(tm) II X6 1100T Processor | Socket M2 | 3314/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 931 GiB total, 756.89 GiB free.
D: is CDROM ()
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_50071458&REV_04\4&5B6B27D&0&0048
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1033&DEV_0194&SUBSYS_50071458&REV_04\4&5B6B27D&0&0048
Service:
.
==== System Restore Points ===================
.
RP167: 5/28/2012 12:56:37 AM - Scheduled Checkpoint
RP168: 6/5/2012 11:49:10 PM - avast! Free Antivirus Setup
RP169: 6/6/2012 4:35:28 PM - avast! Free Antivirus Setup
RP170: 6/6/2012 5:14:59 PM - avast! Free Antivirus Setup
RP171: 6/6/2012 5:18:29 PM - Removed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
RP172: 6/6/2012 5:19:15 PM - Removed Skype Click to Call
RP173: 6/6/2012 5:20:11 PM - Removed Skype Click to Call
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.1.3)
AIM 7
AOL Messaging Toolbar
Apple Application Support
Apple Software Update
Battlefield 3™
Battlefield: Bad Company 2
Battlelog Web Plugins
Call of Duty(R) - World at War(TM)
Counter-Strike
Counter-Strike: Global Offensive Beta
Counter-Strike: Source
DAEMON Tools Lite
Day of Defeat: Source
DivX Setup
Dota 2
Download Updater (AOL LLC)
EasySaver B9.1214.1
ESN Sonar
EVGA Precision 2.1.2
EVGA Precision X 3.0.2
F.lux
FBDownloader IE Add-on
FrostWire 5.2.9
Garry's Mod
Google Chrome
Java Auto Updater
Java(TM) 6 Update 29
Killing Floor
League of Legends
Left 4 Dead 2
Malwarebytes Anti-Malware version 1.61.0.1400
MapleStory
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Music Rescue
Need For Speed™ World
NVIDIA 3D Vision Controller Driver
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
ooVoo
Origin
Pando Media Booster
PunkBuster Services
QuickTime
Realtek Ethernet Controller Driver
Sanctum
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office Groove 2007 (KB2552997)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Skype™ 5.8
Spybot - Search & Destroy
StarCraft II
Steam
System Requirements Lab CYRI
Update for 2007 Microsoft Office System (KB2284654)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2596560)
VC80CRTRedist - 8.0.50727.6195
VirtualDJ PRO Full
Windows Movie Maker 2.6
WinRAR 4.01 (32-bit)
Zombie Panic Source
.
==== Event Viewer Messages From Past Week ========
.
6/7/2012 3:21:22 PM, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.
6/7/2012 12:16:35 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
6/7/2012 12:16:15 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
6/7/2012 12:09:12 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service VSS with arguments "" in order to run the server: {E579AB5F-1CC4-44B4-BED9-DE0991FF0623}
6/7/2012 12:05:11 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
6/7/2012 12:05:05 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
6/7/2012 12:05:04 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
6/7/2012 12:04:56 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
6/7/2012 12:04:46 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf ws2ifsl
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The Network Connections service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
6/7/2012 12:04:46 AM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
6/6/2012 5:47:30 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff8800cb00fe4, 0xfffff8800ba905c8, 0xfffff8800ba8fe30). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-32120-01.
6/6/2012 5:47:29 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx Wanarpv6 WfpLwf
6/6/2012 5:30:28 PM, Error: Service Control Manager [7038] - The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: Logon failure: the specified account password has expired. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
6/6/2012 5:30:28 PM, Error: Service Control Manager [7000] - The NVIDIA Update Service Daemon service failed to start due to the following error: The service did not start due to a logon failure.
6/6/2012 5:27:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff80002eabf95). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-24835-01.
6/6/2012 5:24:30 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031673fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-25537-01.
6/6/2012 5:12:46 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000000075503, 0x0000000000000002, 0x0000000000000001, 0xfffff80002e69f95). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-24663-01.
6/6/2012 5:10:15 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031813fa, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-26176-01.
6/6/2012 4:25:23 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002e65703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-20170-01.
6/6/2012 3:55:12 PM, Error: Service Control Manager [7023] - The Peer Name Resolution Protocol service terminated with the following error: %%-2140993535
6/6/2012 3:55:12 PM, Error: Service Control Manager [7001] - The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: %%-2140993535
6/6/2012 3:55:12 PM, Error: Microsoft-Windows-PNRPSvc [102] - The Peer Name Resolution Protocol cloud did not start because the creation of the default identity failed with error code: 0x80630801.
6/6/2012 12:43:49 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002eac703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-30934-01.
6/6/2012 12:40:42 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000019 (0x0000000000000003, 0xfffff8000300fbb0, 0xfffff8000300fbb0, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-30763-01.
6/6/2012 11:41:40 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002eaa703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-19094-01.
6/6/2012 11:27:42 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000116 (0xfffffa80095914e0, 0xfffff8801496f1a4, 0xffffffffc000009a, 0x0000000000000004). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060612-17628-01.
6/5/2012 12:14:00 AM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR2.
6/5/2012 11:38:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002ea6703, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 060512-24554-01.
6/4/2012 7:42:25 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
.
==== End Of File ===========================
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Justin at 15:50:08 on 2012-06-07
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.8190.5572 [GMT -7:00]
.
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\AIM\aim.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\oovoo\ooVoo.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
-netsvcs
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Justin\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=APN10379&gct=hp
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: FBDownloader BHO: {553318da-d010-469e-84b1-496563cae1bf} - C:\Program Files (x86)\HTTO Group, Ltd\FBDownloader IE Add-on\FBDownloader.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [ooVoo.exe] C:\program files (x86)\oovoo\oovoo.exe /minimized
mRun: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\Justin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces\{33137353-D12F-4305-9D68-3937A18FD63F} : DhcpNameServer = 10.0.0.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: FBDownloader BHO: {553318DA-D010-469E-84B1-496563CAE1BF} - C:\Program Files (x86)\HTTO Group, Ltd\FBDownloader IE Add-on\FBDownloader.dll
BHO-X64: FBDownloader - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
BHO-X64: AOL Messaging Toolbar Loader - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
mRun-x64: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
Hosts: 127.0.0.1www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-4-3 63928]
R2 ES lite Service;ES lite Service for program management.;C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe [2011-7-14 68136]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-6-6 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-3-18 1262400]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-5-15 382272]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S3 Gun;Gun;C:\Game\SoftnyxGame\GunboundIS\Gun64.sys [2012-5-5 45176]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== File Associations ===============
.
inffile=%SystemRoot%\SysWow64\NOTEPAD.EXE %1
VBEFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-06-07 22:22:1720480----a-w-C:\Windows\svchost.exe
2012-06-07 07:17:46--------d-----w-C:\$RECYCLE.BIN
2012-06-07 07:09:08--------d-----w-C:\ComboFix
2012-06-07 03:49:4898816----a-w-C:\Windows\sed.exe
2012-06-07 03:49:48518144----a-w-C:\Windows\SWREG.exe
2012-06-07 03:49:48256000----a-w-C:\Windows\PEV.exe
2012-06-07 03:49:48208896----a-w-C:\Windows\MBR.exe
2012-06-07 00:53:03--------d-----w-C:\Users\Justin\AppData\Roaming\Malwarebytes
2012-06-07 00:52:58--------d-----w-C:\ProgramData\Malwarebytes
2012-06-07 00:52:5724904----a-w-C:\Windows\System32\drivers\mbam.sys
2012-06-07 00:52:57--------d-----w-C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-07 00:44:35--------d-----w-C:\Program Files (x86)\EVGA Precision X
2012-06-06 07:51:02--------d-----w-C:\ProgramData\Spybot - Search & Destroy
2012-06-06 07:51:02--------d-----w-C:\Program Files (x86)\Spybot - Search & Destroy
2012-06-06 06:49:21--------d-----w-C:\ProgramData\AVAST Software
2012-06-06 06:49:21--------d-----w-C:\Program Files\AVAST Software
2012-05-23 23:50:41--------d-----w-C:\Users\Justin\AppData\Roaming\LolClient2
2012-05-15 09:21:50423744----a-w-C:\Windows\SysWow64\nvStreaming.exe
2012-05-13 21:34:24--------d-----w-C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP
2012-05-12 06:22:55419488----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
.
==================== Find3M ====================
.
2012-06-07 22:21:2125640----a-w-C:\Windows\gdrv.sys
2012-06-03 23:23:40283304----a-w-C:\Windows\SysWow64\PnkBstrB.xtr
2012-06-03 23:23:40283304----a-w-C:\Windows\SysWow64\PnkBstrB.exe
2012-06-03 23:23:23280904----a-w-C:\Windows\SysWow64\PnkBstrB.ex0
2012-05-15 09:29:47889664----a-w-C:\Windows\System32\nvvsvc.exe
2012-05-15 09:29:4663296----a-w-C:\Windows\System32\nvshext.dll
2012-05-15 09:29:46118080----a-w-C:\Windows\System32\nvmctray.dll
2012-05-15 09:29:452621723----a-w-C:\Windows\System32\nvcoproc.bin
2012-05-15 09:29:253149632----a-w-C:\Windows\System32\nvsvc64.dll
2012-05-15 09:28:426151488----a-w-C:\Windows\System32\nvcpl.dll
2012-05-12 06:22:5570304----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-04-18 17:08:0831040----a-w-C:\Windows\System32\nvhdap64.dll
2012-04-18 17:08:03188736----a-w-C:\Windows\System32\drivers\nvhda64v.sys
2012-04-18 17:08:021451840----a-w-C:\Windows\System32\nvhdagenco6420103.dll
.
============= FINISH: 15:50:37.99 ===============
 
Please tell me if I am missing anything

Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.15.02

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Justin :: JUSTIN-PC [administrator]

Protection: Enabled

6/15/2012 12:41:05 PM
mbam-log-2012-06-15 (12-47-39).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 228936
Time elapsed: 1 minute(s), 54 second(s)

Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 4316 -> No action taken.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> No action taken.

(end)
__
 
Your MBAM log says "No action taken".
Re-run it, fix all issues and post new log.
 
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.17.03

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Justin :: JUSTIN-PC [administrator]

Protection: Enabled

6/17/2012 2:48:16 PM
mbam-log-2012-06-17 (14-48-16).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 229306
Time elapsed: 1 minute(s), 39 second(s)

Memory Processes Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> 4472 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.

(end)
 
For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
 
Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
Ran by SYSTEM at 30-06-2012 10:18:45
Running from F:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31072 2008-10-25] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Justin\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4321112 2012-02-29] (AOL Inc.)
HKU\Justin\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-07-14] ()
HKU\Justin\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-03] (Valve Corporation)
HKU\Justin\...\Run: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
HKU\Justin\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\Justin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) ======

2 ES lite Service; "C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE" [68136 2009-08-24] ()
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-18] ()
2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]

========================== Drivers (Whitelisted) =============

1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [279616 2011-11-29] (DT Soft Ltd)
3 gdrv; \??\C:\Windows\gdrv.sys [25640 2012-06-30] (Windows (R) Server 2003 DDK provider)
3 Gun; \??\C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys [45176 2012-05-05] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 catchme; \??\C:\ComboFix\catchme.sys [x]

========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
2012-06-29 01:39 - 2012-06-29 01:39 - 00000000 ____D C:\Users\Justin\Desktop\RGSC
2012-06-29 01:37 - 2012-06-29 01:39 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
2012-06-28 21:38 - 2008-07-12 07:18 - 04992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
2012-06-28 21:38 - 2008-07-12 07:18 - 01942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
2012-06-28 21:38 - 2008-07-12 07:18 - 00540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
2012-06-28 18:55 - 2012-06-28 18:55 - 00000000 ____D C:\Users\Justin\Documents\Rockstar Games
2012-06-24 12:45 - 2012-06-24 12:46 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
2012-06-24 00:10 - 2012-06-24 00:11 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
2012-06-24 00:00 - 2012-06-24 00:01 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
2012-06-22 00:16 - 2012-06-22 00:40 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
2012-06-22 00:02 - 2012-06-22 00:02 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Azureus
2012-06-21 10:52 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 10:52 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-17 13:52 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
2012-06-12 12:34 - 2012-06-12 12:35 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp
2012-06-11 15:19 - 2012-06-11 15:19 - 00284688 ____A C:\Windows\Minidump\061112-15818-01.dmp
2012-06-07 14:38 - 2012-06-07 14:38 - 00302592 ____A C:\Users\Justin\Desktop\gktwy3y7.exe
2012-06-07 00:33 - 2012-06-06 23:17 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20120607-013318.backup
2012-06-07 00:14 - 2012-06-07 00:14 - 00001258 ____A C:\Users\Justin\Desktop\Spybot - Search & Destroy.lnk
2012-06-07 00:10 - 2012-06-07 00:10 - 16409960 ____A (Safer Networking Limited ) C:\Users\Justin\Desktop\spybotsd162.exe
2012-06-06 23:09 - 2012-06-06 23:19 - 00000000 ____D C:\ComboFix
2012-06-06 23:00 - 2012-06-24 00:04 - 00000498 ____A C:\rkill.log
2012-06-06 22:59 - 2012-06-06 23:00 - 01012656 ____A C:\Users\Justin\Desktop\rkill.exe
2012-06-06 22:41 - 2012-06-06 22:41 - 00291488 ____A C:\Windows\Minidump\060612-19094-01.dmp
2012-06-06 22:27 - 2012-06-06 22:27 - 00792912 ____A C:\Windows\Minidump\060612-17628-01.dmp
2012-06-06 19:49 - 2012-06-06 23:09 - 00000000 ____D C:\Qoobox
2012-06-06 19:49 - 2012-06-06 20:01 - 00000000 ____D C:\Windows\ERDNT
2012-06-06 19:49 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-06-06 19:49 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-06-06 19:49 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-06-06 19:49 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-06-06 19:49 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-06-06 19:49 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-06-06 19:49 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-06-06 19:49 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-06-06 19:47 - 2012-06-06 22:43 - 04538022 ____R (Swearware) C:\Users\Justin\Desktop\ComboFix.exe
2012-06-06 16:53 - 2012-06-06 16:53 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Malwarebytes
2012-06-06 16:52 - 2012-06-06 16:52 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Justin\Desktop\mbam-setup-1.61.0.1400.exe
2012-06-06 16:52 - 2012-06-06 16:52 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-06 16:52 - 2012-06-06 16:52 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-06-06 16:52 - 2012-06-06 16:52 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-06-06 16:52 - 2012-04-04 14:56 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-06 16:47 - 2012-06-06 16:47 - 00285616 ____A C:\Windows\Minidump\060612-32120-01.dmp
2012-06-06 16:44 - 2012-06-06 16:44 - 00001088 ____A C:\Users\Justin\Desktop\EVGA Precision X.lnk
2012-06-06 16:44 - 2012-06-06 16:44 - 00000000 ____D C:\Program Files (x86)\EVGA Precision X
2012-06-06 16:36 - 2012-05-15 02:48 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-06-06 16:36 - 2012-05-15 02:48 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
2012-06-06 16:36 - 2012-05-15 02:48 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2012-06-06 16:36 - 2012-04-18 09:08 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-06-06 16:36 - 2012-04-18 09:08 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-06-06 16:27 - 2012-06-06 16:27 - 00285336 ____A C:\Windows\Minidump\060612-24835-01.dmp
2012-06-06 16:24 - 2012-06-06 16:24 - 00287520 ____A C:\Windows\Minidump\060612-25537-01.dmp
2012-06-06 16:12 - 2012-06-06 16:12 - 00284520 ____A C:\Windows\Minidump\060612-24663-01.dmp
2012-06-06 16:10 - 2012-06-06 16:10 - 00292440 ____A C:\Windows\Minidump\060612-26176-01.dmp
2012-06-06 15:36 - 2012-06-06 15:36 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-06-06 15:36 - 2012-03-06 15:15 - 00258520 ____A (AVAST Software) C:\Windows\System32\aswBoot.exe
2012-06-06 15:25 - 2012-06-06 15:25 - 00288728 ____A C:\Windows\Minidump\060612-20170-01.dmp
2012-06-06 00:00 - 2012-06-07 00:29 - 00000273 ____A C:\Windows\wininit.ini
2012-06-05 23:51 - 2012-06-07 00:34 - 00000000 ____D C:\Users\All Users\Spybot - Search & Destroy
2012-06-05 23:51 - 2012-06-07 00:16 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy
2012-06-05 22:49 - 2012-06-06 16:16 - 00000000 ____D C:\Users\All Users\AVAST Software
2012-06-05 22:49 - 2012-06-06 15:35 - 00000000 ____D C:\Program Files\AVAST Software
2012-06-05 22:44 - 2012-06-05 22:48 - 74761776 ____A C:\Users\Justin\Desktop\avast_free_antivirus_setup.exe
2012-06-05 22:38 - 2012-06-05 22:38 - 00285560 ____A C:\Windows\Minidump\060512-24554-01.dmp


============ 3 Months Modified Files ========================
 
Scan result of Farbar Recovery Scan Tool Version: 30-06-2012 04
Ran by SYSTEM at 12-07-2012 21:23:30
Running from F:\
Windows 7 Ultimate (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM-x32\...\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [31072 2008-10-25] (Microsoft Corporation)
HKLM-x32\...\Run: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] ()
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-11-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462408 2012-04-04] (Malwarebytes Corporation)
HKU\Justin\...\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US [4321112 2012-02-29] (AOL Inc.)
HKU\Justin\...\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3077528 2011-07-14] ()
HKU\Justin\...\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent [1242448 2011-08-03] (Valve Corporation)
HKU\Justin\...\Run: [F.lux] "C:\Users\Justin\Local Settings\Apps\F.lux\flux.exe" /noshow [966656 2009-08-28] ()
HKU\Justin\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [17148552 2012-02-29] (Skype Technologies S.A.)
HKU\Justin\...\Run: [Google Update] "C:\Users\Justin\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2011-07-14] (Google Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Startup: C:\Users\Justin\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) ======

2 ES lite Service; "C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE" [68136 2009-08-24] ()
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [654408 2012-04-04] (Malwarebytes Corporation)
2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-02-18] ()
2 WinDefend; C:\Program Files (x86)\Windows Defender\mpsvc.dll [x]

========================== Drivers (Whitelisted) =============

1 dtsoftbus01; C:\Windows\System32\Drivers\dtsoftbus01.sys [279616 2011-11-29] (DT Soft Ltd)
3 gdrv; \??\C:\Windows\gdrv.sys [25640 2012-07-12] (Windows (R) Server 2003 DDK provider)
3 Gun; \??\C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys [45176 2012-05-05] ()
3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-04-04] (Malwarebytes Corporation)
3 catchme; \??\C:\ComboFix\catchme.sys [x]

========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-07-12 11:02 - 2012-07-12 11:02 - 00285376 ____A C:\Windows\Minidump\071212-29016-01.dmp
2012-07-12 10:56 - 2012-07-12 10:56 - 00284584 ____A C:\Windows\Minidump\071212-19890-01.dmp
2012-07-09 22:36 - 2012-07-09 22:36 - 00288464 ____A C:\Windows\Minidump\070912-27424-01.dmp
2012-07-04 17:06 - 2012-07-04 17:06 - 00000278 ____A C:\Users\Justin\Desktop\128kbps.pls
2012-07-02 20:50 - 2012-07-02 20:50 - 00285136 ____A C:\Windows\Minidump\070212-39421-01.dmp
2012-07-02 10:27 - 2012-07-02 10:27 - 00284512 ____A C:\Windows\Minidump\070212-18236-01.dmp
2012-07-01 19:32 - 2012-07-01 19:32 - 00284512 ____A C:\Windows\Minidump\070112-17472-01.dmp
2012-07-01 14:59 - 2012-07-01 14:59 - 00285712 ____A C:\Windows\Minidump\070112-21512-01.dmp
2012-06-30 19:13 - 2012-06-30 19:13 - 00284672 ____A C:\Windows\Minidump\063012-17612-01.dmp
2012-06-30 19:11 - 2012-06-30 19:11 - 00284592 ____A C:\Windows\Minidump\063012-19032-01.dmp
2012-06-30 19:02 - 2012-06-30 19:02 - 00284752 ____A C:\Windows\Minidump\063012-18548-01.dmp
2012-06-30 18:00 - 2012-06-30 18:00 - 00284944 ____A C:\Windows\Minidump\063012-26239-01.dmp
2012-06-30 10:15 - 2012-07-09 22:40 - 00000000 ____D C:\FRST
2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
2012-06-29 01:39 - 2012-06-29 01:39 - 00000000 ____D C:\Users\Justin\Desktop\RGSC
2012-06-29 01:37 - 2012-06-29 01:39 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
2012-06-28 21:38 - 2008-07-12 07:18 - 04992520 ____A (Microsoft Corporation) C:\Windows\System32\D3DX9_39.dll
2012-06-28 21:38 - 2008-07-12 07:18 - 01942552 ____A (Microsoft Corporation) C:\Windows\System32\D3DCompiler_39.dll
2012-06-28 21:38 - 2008-07-12 07:18 - 00540688 ____A (Microsoft Corporation) C:\Windows\System32\d3dx10_39.dll
2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
2012-06-28 18:55 - 2012-06-28 18:55 - 00000000 ____D C:\Users\Justin\Documents\Rockstar Games
2012-06-24 12:45 - 2012-06-24 12:46 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
2012-06-24 00:10 - 2012-06-24 00:11 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
2012-06-24 00:00 - 2012-06-24 00:01 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
2012-06-22 00:16 - 2012-06-22 00:40 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
2012-06-22 00:02 - 2012-06-22 00:02 - 00000000 ____D C:\Users\Justin\AppData\Roaming\Azureus
2012-06-21 10:52 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-21 10:52 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-21 10:52 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-21 10:52 - 2012-06-02 14:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 16:12 - 2012-06-19 16:12 - 00000000 __SHD C:\Windows\SysWOW64\%APPDATA%
2012-06-17 13:52 - 2009-07-13 17:14 - 00020480 ____A (Microsoft Corporation) C:\Windows\svchost.exe
2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
2012-06-12 12:34 - 2012-06-12 12:35 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp

============ 3 Months Modified Files ========================

2012-07-12 15:58 - 2011-07-14 15:35 - 00000237 ____A C:\service.log
2012-07-12 15:58 - 2011-07-14 15:18 - 01190591 ____A C:\Windows\WindowsUpdate.log
2012-07-12 15:16 - 2011-07-14 15:39 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-312835093-3087082948-3825595922-1000UA.job
2012-07-12 15:01 - 2009-07-13 21:13 - 00730448 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-12 15:00 - 2009-07-13 20:45 - 00013424 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-12 15:00 - 2009-07-13 20:45 - 00013424 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-12 14:55 - 2011-07-14 17:07 - 00025640 ____A (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2012-07-12 14:55 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-12 14:55 - 2009-07-13 20:51 - 00088028 ____A C:\Windows\setupact.log
2012-07-12 11:02 - 2012-07-12 11:02 - 00285376 ____A C:\Windows\Minidump\071212-29016-01.dmp
2012-07-12 11:02 - 2011-09-03 21:20 - 534257664 ____A C:\Windows\MEMORY.DMP
2012-07-12 10:56 - 2012-07-12 10:56 - 00284584 ____A C:\Windows\Minidump\071212-19890-01.dmp
2012-07-12 00:16 - 2011-07-14 15:39 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-312835093-3087082948-3825595922-1000Core.job
2012-07-11 18:17 - 2011-07-14 15:40 - 00002364 ____A C:\Users\Justin\Desktop\Google Chrome.lnk
2012-07-09 22:36 - 2012-07-09 22:36 - 00288464 ____A C:\Windows\Minidump\070912-27424-01.dmp
2012-07-04 17:06 - 2012-07-04 17:06 - 00000278 ____A C:\Users\Justin\Desktop\128kbps.pls
2012-07-02 22:15 - 2011-07-14 15:24 - 00288614 ____A C:\Windows\DirectX.log
2012-07-02 20:50 - 2012-07-02 20:50 - 00285136 ____A C:\Windows\Minidump\070212-39421-01.dmp
2012-07-02 10:28 - 2009-07-13 21:08 - 00032630 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-02 10:27 - 2012-07-02 10:27 - 00284512 ____A C:\Windows\Minidump\070212-18236-01.dmp
2012-07-01 19:32 - 2012-07-01 19:32 - 00284512 ____A C:\Windows\Minidump\070112-17472-01.dmp
2012-07-01 14:59 - 2012-07-01 14:59 - 00285712 ____A C:\Windows\Minidump\070112-21512-01.dmp
2012-06-30 19:13 - 2012-06-30 19:13 - 00284672 ____A C:\Windows\Minidump\063012-17612-01.dmp
2012-06-30 19:11 - 2012-06-30 19:11 - 00284592 ____A C:\Windows\Minidump\063012-19032-01.dmp
2012-06-30 19:02 - 2012-06-30 19:02 - 00284752 ____A C:\Windows\Minidump\063012-18548-01.dmp
2012-06-30 18:04 - 2012-06-06 23:00 - 00000545 ____A C:\rkill.log
2012-06-30 18:00 - 2012-06-30 18:00 - 00284944 ____A C:\Windows\Minidump\063012-26239-01.dmp
2012-06-30 09:08 - 2012-06-30 09:08 - 00285816 ____A C:\Windows\Minidump\063012-20748-01.dmp
2012-06-30 08:55 - 2012-06-30 08:55 - 00292736 ____A C:\Windows\Minidump\063012-19172-01.dmp
2012-06-29 01:39 - 2012-06-29 01:37 - 222070843 ____A C:\Users\Justin\Desktop\RGSC.rar
2012-06-29 01:36 - 2012-06-29 01:36 - 00001843 ____A C:\lanoire6-29-2012 2-36-52 AM.log
2012-06-28 19:01 - 2012-06-28 19:01 - 02796287 ____A C:\Users\Justin\Desktop\RGSC_1_1_3_0.rar
2012-06-24 12:46 - 2012-06-24 12:45 - 00000288 ____A C:\Windows\SysWOW64\msexcr.ini
2012-06-24 01:10 - 2012-06-24 01:10 - 00292704 ____A C:\Windows\Minidump\062412-23368-01.dmp
2012-06-24 00:11 - 2012-06-24 00:10 - 00285256 ____A C:\Windows\Minidump\062412-50965-01.dmp
2012-06-24 00:06 - 2012-06-24 00:06 - 00286760 ____A C:\Windows\Minidump\062412-20124-01.dmp
2012-06-24 00:02 - 2012-05-11 22:22 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-06-24 00:02 - 2011-07-18 06:30 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-06-24 00:01 - 2012-06-24 00:00 - 00292736 ____A C:\Windows\Minidump\062412-19312-01.dmp
2012-06-22 00:43 - 2011-12-09 19:44 - 00005632 ____A C:\Users\Justin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-22 00:40 - 2012-06-22 00:16 - 13287340 ____A C:\Users\Justin\Desktop\megamix.mp3
2012-06-19 10:45 - 2011-07-14 17:05 - 00066850 ____A C:\Windows\PFRO.log
2012-06-17 13:10 - 2012-06-17 13:10 - 00000000 ____A C:\Users\Justin\Desktop\gmer.log
2012-06-15 11:31 - 2012-06-15 11:31 - 00291072 ____A C:\Windows\Minidump\061512-19500-01.dmp
2012-06-14 23:33 - 2012-06-14 23:33 - 00287464 ____A C:\Windows\Minidump\061512-18220-01.dmp
2012-06-13 22:37 - 2011-07-14 15:42 - 00001080 ___AH C:\IPH.PH
2012-06-12 12:39 - 2012-06-12 12:39 - 00284752 ____A C:\Windows\Minidump\061212-16270-01.dmp
2012-06-12 12:35 - 2012-06-12 12:34 - 00284752 ____A C:\Windows\Minidump\061212-18673-01.dmp
2012-06-12 12:27 - 2012-06-12 12:27 - 00285536 ____A C:\Windows\Minidump\061212-16941-01.dmp
2012-06-12 12:09 - 2012-06-12 12:09 - 00284592 ____A C:\Windows\Minidump\061212-17097-01.dmp
2012-06-12 11:03 - 2012-06-12 11:03 - 00284672 ____A C:\Windows\Minidump\061212-16707-01.dmp
2012-06-11 15:19 - 2012-06-11 15:19 - 00284688 ____A C:\Windows\Minidump\061112-15818-01.dmp
2012-06-07 14:38 - 2012-06-07 14:38 - 00302592 ____A C:\Users\Justin\Desktop\gktwy3y7.exe
2012-06-07 00:29 - 2012-06-06 00:00 - 00000273 ____A C:\Windows\wininit.ini
2012-06-07 00:14 - 2012-06-07 00:14 - 00001258 ____A C:\Users\Justin\Desktop\Spybot - Search & Destroy.lnk
2012-06-07 00:10 - 2012-06-07 00:10 - 16409960 ____A (Safer Networking Limited ) C:\Users\Justin\Desktop\spybotsd162.exe
2012-06-06 23:17 - 2012-06-07 00:33 - 00000027 ____A C:\Windows\System32\Drivers\etc\hosts.20120607-013318.backup
2012-06-06 23:17 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
2012-06-06 23:00 - 2012-06-06 22:59 - 01012656 ____A C:\Users\Justin\Desktop\rkill.exe
2012-06-06 22:43 - 2012-06-06 19:47 - 04538022 ____R (Swearware) C:\Users\Justin\Desktop\ComboFix.exe
2012-06-06 22:41 - 2012-06-06 22:41 - 00291488 ____A C:\Windows\Minidump\060612-19094-01.dmp
2012-06-06 22:27 - 2012-06-06 22:27 - 00792912 ____A C:\Windows\Minidump\060612-17628-01.dmp
2012-06-06 16:52 - 2012-06-06 16:52 - 10063000 ____A (Malwarebytes Corporation ) C:\Users\Justin\Desktop\mbam-setup-1.61.0.1400.exe
2012-06-06 16:52 - 2012-06-06 16:52 - 00001109 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-06-06 16:47 - 2012-06-06 16:47 - 00285616 ____A C:\Windows\Minidump\060612-32120-01.dmp
2012-06-06 16:44 - 2012-06-06 16:44 - 00001088 ____A C:\Users\Justin\Desktop\EVGA Precision X.lnk
2012-06-06 16:27 - 2012-06-06 16:27 - 00285336 ____A C:\Windows\Minidump\060612-24835-01.dmp
2012-06-06 16:24 - 2012-06-06 16:24 - 00287520 ____A C:\Windows\Minidump\060612-25537-01.dmp
2012-06-06 16:12 - 2012-06-06 16:12 - 00284520 ____A C:\Windows\Minidump\060612-24663-01.dmp
2012-06-06 16:10 - 2012-06-06 16:10 - 00292440 ____A C:\Windows\Minidump\060612-26176-01.dmp
2012-06-06 15:36 - 2012-06-06 15:36 - 00000000 ____A C:\Windows\SysWOW64\config.nt
2012-06-06 15:25 - 2012-06-06 15:25 - 00288728 ____A C:\Windows\Minidump\060612-20170-01.dmp
2012-06-05 22:48 - 2012-06-05 22:44 - 74761776 ____A C:\Users\Justin\Desktop\avast_free_antivirus_setup.exe
2012-06-05 22:38 - 2012-06-05 22:38 - 00285560 ____A C:\Windows\Minidump\060512-24554-01.dmp
2012-06-03 15:23 - 2011-07-14 21:40 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.xtr
2012-06-03 15:23 - 2011-07-14 21:39 - 00283304 ____A C:\Windows\SysWOW64\PnkBstrB.exe
2012-06-03 15:23 - 2011-07-14 21:39 - 00280904 ____A C:\Windows\SysWOW64\PnkBstrB.ex0
2012-06-02 14:19 - 2012-06-21 10:52 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-21 10:52 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-21 10:52 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 14:19 - 2012-06-21 10:52 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-21 10:52 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-21 10:52 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-21 10:52 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-21 10:52 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 14:15 - 2012-06-21 10:52 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-05-15 02:48 - 2012-06-06 16:36 - 25743168 ____A (NVIDIA Corporation) C:\Windows\System32\nvoglv64.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 25248064 ____A (NVIDIA Corporation) C:\Windows\System32\nvcompiler.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 19607872 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 18044224 ____A (NVIDIA Corporation) C:\Windows\System32\nvd3dumx.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 17551680 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 14298944 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvlddmkm.sys
2012-05-15 02:48 - 2012-06-06 16:36 - 08139072 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuda.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 08105280 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 05982528 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 02881856 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 02681664 ____A (NVIDIA Corporation) C:\Windows\System32\nvcuvid.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 02524992 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 02445120 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 02368832 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 00818496 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 00364352 ____A (NVIDIA Corporation) C:\Windows\System32\nvdecodemft.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 00301376 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 00246592 ____A (NVIDIA Corporation) C:\Windows\System32\nvinitx.dll
2012-05-15 02:48 - 2012-06-06 16:36 - 00202048 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2012-05-15 02:48 - 2012-03-18 00:35 - 00949056 ____A (NVIDIA Corporation) C:\Windows\System32\nvumdshimx.dll
2012-05-15 02:48 - 2012-03-18 00:35 - 00068928 ____A (Khronos Group) C:\Windows\System32\OpenCL.dll
2012-05-15 02:48 - 2012-03-18 00:35 - 00061248 ____A (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2012-05-15 02:48 - 2011-10-23 00:16 - 01738048 ____A (NVIDIA Corporation) C:\Windows\System32\nvdispco64.dll
2012-05-15 02:48 - 2011-10-23 00:16 - 01468224 ____A (NVIDIA Corporation) C:\Windows\System32\nvgenco64.dll
2012-05-15 02:48 - 2011-07-14 22:37 - 10194752 ____A (NVIDIA Corporation) C:\Windows\System32\nvwgf2umx.dll
2012-05-15 02:48 - 2011-07-14 18:30 - 15322432 ____A (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2012-05-15 02:48 - 2011-07-14 15:19 - 02741568 ____A (NVIDIA Corporation) C:\Windows\System32\nvapi64.dll
2012-05-15 02:48 - 2011-07-14 15:19 - 00014324 ____A C:\Windows\System32\nvinfo.pb
2012-05-15 01:29 - 2012-03-18 00:36 - 02621723 ____A C:\Windows\System32\nvcoproc.bin
2012-05-15 01:29 - 2011-01-16 16:13 - 03149632 ____A (NVIDIA Corporation) C:\Windows\System32\nvsvc64.dll
2012-05-15 01:29 - 2011-01-16 16:13 - 00889664 ____A (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
2012-05-15 01:29 - 2011-01-16 16:13 - 00118080 ____A (NVIDIA Corporation) C:\Windows\System32\nvmctray.dll
2012-05-15 01:29 - 2011-01-16 16:13 - 00063296 ____A (NVIDIA Corporation) C:\Windows\System32\nvshext.dll
2012-05-15 01:28 - 2011-01-16 16:13 - 06151488 ____A (NVIDIA Corporation) C:\Windows\System32\nvcpl.dll
2012-05-15 01:21 - 2012-05-15 01:21 - 00423744 ____A C:\Windows\SysWOW64\nvStreaming.exe
2012-05-01 17:12 - 2012-05-01 17:12 - 00001219 ____A C:\Users\Justin\Desktop\FrostWire 5.2.9.lnk
2012-04-18 09:08 - 2012-06-06 16:36 - 00188736 ____A (NVIDIA Corporation) C:\Windows\System32\Drivers\nvhda64v.sys
2012-04-18 09:08 - 2012-06-06 16:36 - 00031040 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdap64.dll
2012-04-18 09:08 - 2012-03-18 00:35 - 01451840 ____A (NVIDIA Corporation) C:\Windows\System32\nvhdagenco6420103.dll


========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

========================= Memory info ======================

Percentage of memory in use: 10%
Total physical RAM: 8189.55 MB
Available physical RAM: 7345.01 MB
Total Pagefile: 8187.7 MB
Available Pagefile: 7339.44 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

2 Drive c: () (Fixed) (Total:931.41 GB) (Free:739.83 GB) NTFS
4 Drive f: (KINGSTON) (Removable) (Total:3.73 GB) (Free:3.73 GB) FAT32
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 931 GB 0 B
Disk 1 Online 3826 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 931 GB 101 MB

==================================================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y System Rese NTFS Partition 100 MB Healthy

==================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 931 GB Healthy

==================================================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 3825 MB 568 KB

==================================================================================

Disk: 1
Partition 1
Type : 0B
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F KINGSTON FAT32 Removable 3825 MB Healthy

==================================================================================

==========================================================

Last Boot: 2012-07-08 14:24

======================= End Of Log ==========================
 
Restart normally.

Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
 
16:00:10.0655 3828TDSS rootkit removing tool 2.7.46.0 Jul 16 2012 22:10:11
16:00:11.0137 3828============================================================
16:00:11.0137 3828Current date / time: 2012/07/17 16:00:11.0137
16:00:11.0137 3828SystemInfo:
16:00:11.0137 3828
16:00:11.0137 3828OS Version: 6.1.7600 ServicePack: 0.0
16:00:11.0137 3828Product type: Workstation
16:00:11.0137 3828ComputerName: JUSTIN-PC
16:00:11.0137 3828UserName: Justin
16:00:11.0137 3828Windows directory: C:\Windows
16:00:11.0137 3828System windows directory: C:\Windows
16:00:11.0137 3828Running under WOW64
16:00:11.0137 3828Processor architecture: Intel x64
16:00:11.0137 3828Number of processors: 6
16:00:11.0137 3828Page size: 0x1000
16:00:11.0137 3828Boot type: Normal boot
16:00:11.0137 3828============================================================
16:00:12.0196 3828Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
16:00:12.0199 3828============================================================
16:00:12.0199 3828\Device\Harddisk0\DR0:
16:00:12.0199 3828MBR partitions:
16:00:12.0199 3828\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
16:00:12.0199 3828\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
16:00:12.0199 3828============================================================
16:00:12.0214 3828C: <-> \Device\Harddisk0\DR0\Partition1
16:00:12.0214 3828============================================================
16:00:12.0214 3828Initialize success
16:00:12.0214 3828============================================================
16:00:13.0595 1788============================================================
16:00:13.0595 1788Scan started
16:00:13.0595 1788Mode: Manual;
16:00:13.0595 1788============================================================
16:00:14.0911 17881394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
16:00:14.0913 17881394ohci - ok
16:00:14.0955 1788ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
16:00:14.0958 1788ACPI - ok
16:00:14.0970 1788AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
16:00:14.0970 1788AcpiPmi - ok
16:00:15.0072 1788AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:00:15.0072 1788AdobeARMservice - ok
16:00:15.0175 1788AdobeFlashPlayerUpdateSvc (990dc6edc9f933194d7cd4e65146bc94) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:00:15.0178 1788AdobeFlashPlayerUpdateSvc - ok
16:00:15.0203 1788adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
16:00:15.0208 1788adp94xx - ok
16:00:15.0224 1788adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
16:00:15.0227 1788adpahci - ok
16:00:15.0237 1788adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
16:00:15.0239 1788adpu320 - ok
16:00:15.0260 1788AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
16:00:15.0261 1788AeLookupSvc - ok
16:00:15.0309 1788AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
16:00:15.0314 1788AFD - ok
16:00:15.0326 1788agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
16:00:15.0327 1788agp440 - ok
16:00:15.0340 1788ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
16:00:15.0341 1788ALG - ok
16:00:15.0357 1788aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
16:00:15.0357 1788aliide - ok
16:00:15.0362 1788amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
16:00:15.0363 1788amdide - ok
16:00:15.0372 1788AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
16:00:15.0373 1788AmdK8 - ok
16:00:15.0394 1788AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
16:00:15.0395 1788AmdPPM - ok
16:00:15.0430 1788amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
16:00:15.0431 1788amdsata - ok
16:00:15.0448 1788amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
16:00:15.0450 1788amdsbs - ok
16:00:15.0461 1788amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
16:00:15.0462 1788amdxata - ok
16:00:15.0481 1788AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
16:00:15.0482 1788AppID - ok
16:00:15.0494 1788AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
16:00:15.0494 1788AppIDSvc - ok
16:00:15.0514 1788Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
16:00:15.0515 1788Appinfo - ok
16:00:15.0588 1788Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:00:15.0589 1788Apple Mobile Device - ok
16:00:15.0617 1788AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
16:00:15.0619 1788AppMgmt - ok
16:00:15.0637 1788arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
16:00:15.0638 1788arc - ok
16:00:15.0651 1788arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
16:00:15.0652 1788arcsas - ok
16:00:15.0677 1788AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
16:00:15.0677 1788AsyncMac - ok
16:00:15.0683 1788atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
16:00:15.0684 1788atapi - ok
16:00:15.0709 1788AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
16:00:15.0716 1788AudioEndpointBuilder - ok
16:00:15.0720 1788AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
16:00:15.0723 1788AudioSrv - ok
16:00:15.0745 1788AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
16:00:15.0747 1788AxInstSV - ok
16:00:15.0770 1788b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
16:00:15.0775 1788b06bdrv - ok
16:00:15.0800 1788b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
16:00:15.0802 1788b57nd60a - ok
16:00:15.0817 1788BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
16:00:15.0819 1788BDESVC - ok
16:00:15.0831 1788Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
16:00:15.0831 1788Beep - ok
16:00:15.0872 1788BFE (4992c609a6315671463e30f6512bc022) C:\Windows\System32\bfe.dll
16:00:15.0879 1788BFE - ok
16:00:15.0916 1788BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\system32\qmgr.dll
16:00:15.0924 1788BITS - ok
16:00:15.0956 1788blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
16:00:15.0957 1788blbdrive - ok
16:00:16.0028 1788Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
16:00:16.0032 1788Bonjour Service - ok
16:00:16.0068 1788bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
16:00:16.0069 1788bowser - ok
16:00:16.0082 1788BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
16:00:16.0083 1788BrFiltLo - ok
16:00:16.0094 1788BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
16:00:16.0094 1788BrFiltUp - ok
16:00:16.0155 1788BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
16:00:16.0156 1788BridgeMP - ok
16:00:16.0171 1788Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
16:00:16.0172 1788Browser - ok
16:00:16.0191 1788Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
16:00:16.0194 1788Brserid - ok
16:00:16.0208 1788BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
16:00:16.0208 1788BrSerWdm - ok
16:00:16.0219 1788BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
16:00:16.0219 1788BrUsbMdm - ok
16:00:16.0231 1788BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
16:00:16.0231 1788BrUsbSer - ok
16:00:16.0251 1788BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
16:00:16.0252 1788BTHMODEM - ok
16:00:16.0268 1788bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
16:00:16.0269 1788bthserv - ok
16:00:16.0307 1788catchme - ok
16:00:16.0336 1788cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
16:00:16.0337 1788cdfs - ok
16:00:16.0400 1788cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
16:00:16.0402 1788cdrom - ok
16:00:16.0426 1788CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
16:00:16.0427 1788CertPropSvc - ok
16:00:16.0441 1788circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
16:00:16.0442 1788circlass - ok
16:00:16.0464 1788CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
16:00:16.0468 1788CLFS - ok
16:00:16.0511 1788clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:00:16.0514 1788clr_optimization_v2.0.50727_32 - ok
16:00:16.0566 1788clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:00:16.0569 1788clr_optimization_v2.0.50727_64 - ok
16:00:16.0633 1788clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:00:16.0667 1788clr_optimization_v4.0.30319_32 - ok
16:00:16.0695 1788clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:00:16.0697 1788clr_optimization_v4.0.30319_64 - ok
16:00:16.0716 1788CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
16:00:16.0716 1788CmBatt - ok
16:00:16.0721 1788cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
16:00:16.0721 1788cmdide - ok
16:00:16.0739 1788CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
16:00:16.0743 1788CNG - ok
16:00:16.0746 1788Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
16:00:16.0746 1788Compbatt - ok
16:00:16.0755 1788CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
16:00:16.0756 1788CompositeBus - ok
16:00:16.0767 1788COMSysApp - ok
16:00:16.0784 1788crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
16:00:16.0785 1788crcdisk - ok
16:00:16.0806 1788CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
16:00:16.0808 1788CryptSvc - ok
16:00:16.0831 1788CSC (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
16:00:16.0836 1788CSC - ok
16:00:16.0863 1788CscService (873fbf927c06e5cee04dec617502f8fd) C:\Windows\System32\cscsvc.dll
16:00:16.0869 1788CscService - ok
16:00:16.0899 1788DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
16:00:16.0905 1788DcomLaunch - ok
16:00:16.0927 1788defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
16:00:16.0930 1788defragsvc - ok
16:00:16.0971 1788DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
16:00:16.0972 1788DfsC - ok
16:00:16.0995 1788Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
16:00:16.0998 1788Dhcp - ok
16:00:17.0012 1788discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
16:00:17.0013 1788discache - ok
16:00:17.0037 1788Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
16:00:17.0037 1788Disk - ok
16:00:17.0065 1788Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
16:00:17.0067 1788Dnscache - ok
16:00:17.0098 1788dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
16:00:17.0101 1788dot3svc - ok
16:00:17.0117 1788DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
16:00:17.0119 1788DPS - ok
16:00:17.0152 1788drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
16:00:17.0152 1788drmkaud - ok
16:00:17.0194 1788dtsoftbus01 (400582b09e0bb557d0ec28a945150eeb) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
16:00:17.0195 1788dtsoftbus01 - ok
16:00:17.0245 1788DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
16:00:17.0249 1788DXGKrnl - ok
16:00:17.0264 1788EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
16:00:17.0266 1788EapHost - ok
16:00:17.0346 1788ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
16:00:17.0374 1788ebdrv - ok
16:00:17.0443 1788EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
16:00:17.0444 1788EFS - ok
16:00:17.0503 1788ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
16:00:17.0510 1788ehRecvr - ok
16:00:17.0531 1788ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
16:00:17.0533 1788ehSched - ok
16:00:17.0583 1788elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
16:00:17.0589 1788elxstor - ok
16:00:17.0594 1788ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
16:00:17.0595 1788ErrDev - ok
16:00:17.0659 1788ES lite Service (b8fa96995726d1fa58476e352c02ad82) C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
16:00:17.0660 1788ES lite Service - ok
16:00:17.0694 1788EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
16:00:17.0698 1788EventSystem - ok
16:00:17.0722 1788exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
16:00:17.0724 1788exfat - ok
16:00:17.0742 1788fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
16:00:17.0744 1788fastfat - ok
16:00:17.0772 1788Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
16:00:17.0779 1788Fax - ok
16:00:17.0786 1788fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
16:00:17.0787 1788fdc - ok
16:00:17.0796 1788fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
16:00:17.0796 1788fdPHost - ok
16:00:17.0808 1788FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
16:00:17.0809 1788FDResPub - ok
16:00:17.0819 1788FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
16:00:17.0819 1788FileInfo - ok
16:00:17.0832 1788Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
16:00:17.0833 1788Filetrace - ok
16:00:17.0838 1788flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
16:00:17.0838 1788flpydisk - ok
16:00:17.0929 1788FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
16:00:17.0932 1788FltMgr - ok
16:00:17.0986 1788FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
16:00:17.0996 1788FontCache - ok
16:00:18.0060 1788FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:00:18.0061 1788FontCache3.0.0.0 - ok
16:00:18.0079 1788FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
16:00:18.0080 1788FsDepends - ok
16:00:18.0086 1788Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
16:00:18.0086 1788Fs_Rec - ok
16:00:18.0121 1788fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
16:00:18.0123 1788fvevol - ok
16:00:18.0162 1788gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
16:00:18.0163 1788gagp30kx - ok
16:00:18.0201 1788gdrv (7907e14f9bcf3a4689c9a74a1a873cb6) C:\Windows\gdrv.sys
16:00:18.0201 1788gdrv - ok
16:00:18.0245 1788GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:00:18.0245 1788GEARAspiWDM - ok
16:00:18.0277 1788gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
16:00:18.0284 1788gpsvc - ok
16:00:18.0361 1788Gun (721ce1551f8198714f3cabfe2147939b) C:\Game\SoftnyxGame\GunBoundIS\Gun64.sys
16:00:18.0361 1788Gun - ok
16:00:18.0373 1788hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
16:00:18.0374 1788hcw85cir - ok
16:00:18.0411 1788HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
16:00:18.0414 1788HdAudAddService - ok
16:00:18.0439 1788HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
16:00:18.0441 1788HDAudBus - ok
16:00:18.0448 1788HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
16:00:18.0449 1788HidBatt - ok
16:00:18.0463 1788HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
16:00:18.0465 1788HidBth - ok
16:00:18.0468 1788HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
16:00:18.0469 1788HidIr - ok
16:00:18.0494 1788hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
16:00:18.0495 1788hidserv - ok
16:00:18.0519 1788HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
16:00:18.0520 1788HidUsb - ok
16:00:18.0543 1788hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
16:00:18.0545 1788hkmsvc - ok
16:00:18.0560 1788HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
16:00:18.0563 1788HomeGroupListener - ok
16:00:18.0587 1788HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
16:00:18.0590 1788HomeGroupProvider - ok
16:00:18.0608 1788HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
16:00:18.0609 1788HpSAMD - ok
16:00:18.0638 1788HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
16:00:18.0645 1788HTTP - ok
16:00:18.0661 1788hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
16:00:18.0661 1788hwpolicy - ok
16:00:18.0685 1788i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
16:00:18.0686 1788i8042prt - ok
16:00:18.0718 1788iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
16:00:18.0722 1788iaStorV - ok
16:00:18.0807 1788idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:00:18.0815 1788idsvc - ok
16:00:18.0829 1788iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
16:00:18.0830 1788iirsp - ok
16:00:18.0862 1788IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
16:00:18.0871 1788IKEEXT - ok
16:00:18.0881 1788intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
16:00:18.0881 1788intelide - ok
16:00:18.0908 1788intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
16:00:18.0909 1788intelppm - ok
16:00:18.0924 1788IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
16:00:18.0926 1788IPBusEnum - ok
16:00:18.0948 1788IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:00:18.0949 1788IpFilterDriver - ok
16:00:18.0976 1788iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
16:00:18.0981 1788iphlpsvc - ok
16:00:18.0995 1788IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
16:00:18.0997 1788IPMIDRV - ok
16:00:19.0011 1788IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
16:00:19.0012 1788IPNAT - ok
16:00:19.0105 1788iPod Service (ee4c2a137c7088911a8919effc9812e7) C:\Program Files\iPod\bin\iPodService.exe
16:00:19.0113 1788iPod Service - ok
16:00:19.0126 1788IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
16:00:19.0127 1788IRENUM - ok
16:00:19.0137 1788isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
16:00:19.0138 1788isapnp - ok
16:00:19.0150 1788iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
16:00:19.0152 1788iScsiPrt - ok
16:00:19.0168 1788kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
16:00:19.0169 1788kbdclass - ok
16:00:19.0188 1788kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
16:00:19.0189 1788kbdhid - ok
16:00:19.0207 1788KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
16:00:19.0208 1788KeyIso - ok
16:00:19.0221 1788KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
16:00:19.0221 1788KSecDD - ok
16:00:19.0257 1788KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
16:00:19.0259 1788KSecPkg - ok
16:00:19.0264 1788ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
16:00:19.0265 1788ksthunk - ok
16:00:19.0286 1788KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
16:00:19.0290 1788KtmRm - ok
16:00:19.0343 1788LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\System32\srvsvc.dll
16:00:19.0347 1788LanmanServer - ok
16:00:19.0370 1788LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
16:00:19.0372 1788LanmanWorkstation - ok
16:00:19.0404 1788lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
16:00:19.0405 1788lltdio - ok
16:00:19.0425 1788lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
16:00:19.0428 1788lltdsvc - ok
16:00:19.0442 1788lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
16:00:19.0443 1788lmhosts - ok
16:00:19.0464 1788LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
16:00:19.0465 1788LSI_FC - ok
16:00:19.0478 1788LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
16:00:19.0479 1788LSI_SAS - ok
16:00:19.0492 1788LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
16:00:19.0493 1788LSI_SAS2 - ok
16:00:19.0507 1788LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
16:00:19.0508 1788LSI_SCSI - ok
16:00:19.0532 1788luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
16:00:19.0533 1788luafv - ok
16:00:19.0579 1788MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
16:00:19.0580 1788MBAMProtector - ok
16:00:19.0682 1788MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
16:00:19.0688 1788MBAMService - ok
16:00:19.0706 1788Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
16:00:19.0708 1788Mcx2Svc - ok
16:00:19.0722 1788megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
16:00:19.0723 1788megasas - ok
16:00:19.0741 1788MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
16:00:19.0744 1788MegaSR - ok
16:00:19.0802 1788Microsoft Office Groove Audit Service (7c4c76b39d5525c4a465e0be32528e19) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
16:00:19.0803 1788Microsoft Office Groove Audit Service - ok
16:00:19.0829 1788MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
16:00:19.0831 1788MMCSS - ok
16:00:19.0834 1788Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
16:00:19.0835 1788Modem - ok
16:00:19.0855 1788monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
16:00:19.0855 1788monitor - ok
16:00:19.0877 1788mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
16:00:19.0878 1788mouclass - ok
16:00:19.0900 1788mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
16:00:19.0901 1788mouhid - ok
16:00:19.0915 1788mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
16:00:19.0915 1788mountmgr - ok
16:00:19.0926 1788mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
16:00:19.0927 1788mpio - ok
16:00:19.0937 1788mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
16:00:19.0939 1788mpsdrv - ok
16:00:19.0975 1788MpsSvc (aecab449567d1846dad63ece49e893e3) C:\Windows\system32\mpssvc.dll
16:00:19.0983 1788MpsSvc - ok
16:00:20.0003 1788MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
16:00:20.0004 1788MRxDAV - ok
16:00:20.0035 1788mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
16:00:20.0036 1788mrxsmb - ok
16:00:20.0068 1788mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:00:20.0070 1788mrxsmb10 - ok
16:00:20.0081 1788mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:00:20.0083 1788mrxsmb20 - ok
16:00:20.0100 1788msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
16:00:20.0100 1788msahci - ok
16:00:20.0113 1788msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
16:00:20.0114 1788msdsm - ok
16:00:20.0131 1788MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
16:00:20.0133 1788MSDTC - ok
16:00:20.0143 1788Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
16:00:20.0144 1788Msfs - ok
16:00:20.0152 1788mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
16:00:20.0152 1788mshidkmdf - ok
16:00:20.0155 1788msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
16:00:20.0156 1788msisadrv - ok
16:00:20.0183 1788MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
16:00:20.0186 1788MSiSCSI - ok
16:00:20.0188 1788msiserver - ok
16:00:20.0203 1788MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
16:00:20.0204 1788MSKSSRV - ok
16:00:20.0219 1788MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
16:00:20.0220 1788MSPCLOCK - ok
16:00:20.0233 1788MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
16:00:20.0233 1788MSPQM - ok
16:00:20.0277 1788MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
16:00:20.0280 1788MsRPC - ok
16:00:20.0284 1788mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
16:00:20.0285 1788mssmbios - ok
16:00:20.0288 1788MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
16:00:20.0288 1788MSTEE - ok
16:00:20.0294 1788MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
16:00:20.0295 1788MTConfig - ok
16:00:20.0312 1788Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
16:00:20.0312 1788Mup - ok
16:00:20.0345 1788napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
16:00:20.0350 1788napagent - ok
16:00:20.0376 1788NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
16:00:20.0379 1788NativeWifiP - ok
 
16:00:20.0419 1788NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
16:00:20.0427 1788NDIS - ok
16:00:20.0450 1788NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
16:00:20.0451 1788NdisCap - ok
16:00:20.0469 1788NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
16:00:20.0469 1788NdisTapi - ok
16:00:20.0478 1788Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
16:00:20.0479 1788Ndisuio - ok
16:00:20.0494 1788NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
16:00:20.0496 1788NdisWan - ok
16:00:20.0508 1788NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
16:00:20.0509 1788NDProxy - ok
16:00:20.0512 1788NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
16:00:20.0513 1788NetBIOS - ok
16:00:20.0530 1788NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
16:00:20.0533 1788NetBT - ok
16:00:20.0556 1788Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
16:00:20.0557 1788Netlogon - ok
16:00:20.0585 1788Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
16:00:20.0589 1788Netman - ok
16:00:20.0612 1788netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
16:00:20.0617 1788netprofm - ok
16:00:20.0671 1788NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:00:20.0673 1788NetTcpPortSharing - ok
16:00:20.0692 1788nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
16:00:20.0693 1788nfrd960 - ok
16:00:20.0713 1788NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
16:00:20.0717 1788NlaSvc - ok
16:00:20.0724 1788Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
16:00:20.0725 1788Npfs - ok
16:00:20.0735 1788nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
16:00:20.0737 1788nsi - ok
16:00:20.0745 1788nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
16:00:20.0745 1788nsiproxy - ok
16:00:20.0808 1788Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
16:00:20.0823 1788Ntfs - ok
16:00:20.0895 1788Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
16:00:20.0895 1788Null - ok
16:00:20.0941 1788NVHDA (102806b360d0e6bc6e55bf47ef655d43) C:\Windows\system32\drivers\nvhda64v.sys
16:00:20.0941 1788NVHDA - ok
16:00:21.0300 1788nvlddmkm (ba0b4889c40380a01ecdf84c227a89c9) C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:00:21.0357 1788nvlddmkm - ok
16:00:21.0411 1788nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
16:00:21.0413 1788nvraid - ok
16:00:21.0429 1788nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
16:00:21.0430 1788nvstor - ok
16:00:21.0508 1788NVSvc (06633cf95bea62164c3bfca24bce6b11) C:\Windows\system32\nvvsvc.exe
16:00:21.0516 1788NVSvc - ok
16:00:21.0623 1788nvUpdatusService (53b629ce436b110c5689c2f6439e567b) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
16:00:21.0635 1788nvUpdatusService - ok
16:00:21.0672 1788nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
16:00:21.0674 1788nv_agp - ok
16:00:21.0883 1788odserv (1f0e05dff4f5a833168e49be1256f002) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
16:00:21.0887 1788odserv - ok
16:00:21.0905 1788ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
16:00:21.0906 1788ohci1394 - ok
16:00:21.0941 1788ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:00:21.0943 1788ose - ok
16:00:21.0967 1788p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
16:00:21.0971 1788p2pimsvc - ok
16:00:21.0997 1788p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
16:00:22.0002 1788p2psvc - ok
16:00:22.0017 1788Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
16:00:22.0018 1788Parport - ok
16:00:22.0027 1788partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
16:00:22.0027 1788partmgr - ok
16:00:22.0039 1788PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
16:00:22.0041 1788PcaSvc - ok
16:00:22.0058 1788pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
16:00:22.0060 1788pci - ok
16:00:22.0068 1788pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
16:00:22.0068 1788pciide - ok
16:00:22.0086 1788pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
16:00:22.0089 1788pcmcia - ok
16:00:22.0101 1788pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
16:00:22.0102 1788pcw - ok
16:00:22.0126 1788PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
16:00:22.0132 1788PEAUTH - ok
16:00:22.0167 1788PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
16:00:22.0189 1788PeerDistSvc - ok
16:00:22.0243 1788PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
16:00:22.0245 1788PerfHost - ok
16:00:22.0320 1788pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
16:00:22.0333 1788pla - ok
16:00:22.0380 1788PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
16:00:22.0385 1788PlugPlay - ok
16:00:22.0409 1788PnkBstrA - ok
16:00:22.0429 1788PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
16:00:22.0431 1788PNRPAutoReg - ok
16:00:22.0448 1788PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
16:00:22.0450 1788PNRPsvc - ok
16:00:22.0481 1788PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
16:00:22.0486 1788PolicyAgent - ok
16:00:22.0517 1788Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
16:00:22.0519 1788Power - ok
16:00:22.0564 1788PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
16:00:22.0565 1788PptpMiniport - ok
16:00:22.0574 1788Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
16:00:22.0575 1788Processor - ok
16:00:22.0593 1788ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
16:00:22.0595 1788ProfSvc - ok
16:00:22.0608 1788ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
16:00:22.0608 1788ProtectedStorage - ok
16:00:22.0630 1788Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
16:00:22.0631 1788Psched - ok
16:00:22.0674 1788ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
16:00:22.0688 1788ql2300 - ok
16:00:22.0757 1788ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
16:00:22.0758 1788ql40xx - ok
16:00:22.0783 1788QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
16:00:22.0786 1788QWAVE - ok
16:00:22.0799 1788QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
16:00:22.0800 1788QWAVEdrv - ok
16:00:22.0806 1788RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
16:00:22.0806 1788RasAcd - ok
16:00:22.0828 1788RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
16:00:22.0829 1788RasAgileVpn - ok
16:00:22.0847 1788RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
16:00:22.0849 1788RasAuto - ok
16:00:22.0862 1788Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
16:00:22.0863 1788Rasl2tp - ok
16:00:22.0879 1788RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
16:00:22.0883 1788RasMan - ok
16:00:22.0894 1788RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
16:00:22.0895 1788RasPppoe - ok
16:00:22.0907 1788RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
16:00:22.0908 1788RasSstp - ok
16:00:22.0928 1788rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
16:00:22.0931 1788rdbss - ok
16:00:22.0934 1788rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
16:00:22.0935 1788rdpbus - ok
16:00:22.0948 1788RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
16:00:22.0948 1788RDPCDD - ok
16:00:22.0960 1788RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
16:00:22.0961 1788RDPDR - ok
16:00:22.0984 1788RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
16:00:22.0984 1788RDPENCDD - ok
16:00:22.0999 1788RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
16:00:22.0999 1788RDPREFMP - ok
16:00:23.0014 1788RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
16:00:23.0016 1788RDPWD - ok
16:00:23.0036 1788rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
16:00:23.0038 1788rdyboost - ok
16:00:23.0057 1788RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
16:00:23.0059 1788RemoteAccess - ok
16:00:23.0075 1788RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
16:00:23.0077 1788RemoteRegistry - ok
16:00:23.0090 1788RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
16:00:23.0092 1788RpcEptMapper - ok
16:00:23.0106 1788RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
16:00:23.0107 1788RpcLocator - ok
16:00:23.0134 1788RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
16:00:23.0137 1788RpcSs - ok
16:00:23.0163 1788rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
16:00:23.0164 1788rspndr - ok
16:00:23.0214 1788RTL8167 (6d3c7e7d82d3dc92dc2a8b0df9f20f8a) C:\Windows\system32\DRIVERS\Rt64win7.sys
16:00:23.0215 1788RTL8167 - ok
16:00:23.0229 1788s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
16:00:23.0229 1788s3cap - ok
16:00:23.0239 1788SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
16:00:23.0240 1788SamSs - ok
16:00:23.0252 1788sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
16:00:23.0253 1788sbp2port - ok
16:00:23.0278 1788SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
16:00:23.0281 1788SCardSvr - ok
16:00:23.0289 1788scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
16:00:23.0290 1788scfilter - ok
16:00:23.0339 1788Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
16:00:23.0350 1788Schedule - ok
16:00:23.0372 1788SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
16:00:23.0373 1788SCPolicySvc - ok
16:00:23.0389 1788SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
16:00:23.0392 1788SDRSVC - ok
16:00:23.0417 1788secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
16:00:23.0417 1788secdrv - ok
16:00:23.0425 1788seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
16:00:23.0427 1788seclogon - ok
16:00:23.0438 1788SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
16:00:23.0440 1788SENS - ok
16:00:23.0454 1788SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
16:00:23.0455 1788SensrSvc - ok
16:00:23.0468 1788Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
16:00:23.0468 1788Serenum - ok
16:00:23.0475 1788Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
16:00:23.0476 1788Serial - ok
16:00:23.0496 1788sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
16:00:23.0496 1788sermouse - ok
16:00:23.0516 1788SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
16:00:23.0519 1788SessionEnv - ok
16:00:23.0526 1788sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
16:00:23.0526 1788sffdisk - ok
16:00:23.0528 1788sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
16:00:23.0529 1788sffp_mmc - ok
16:00:23.0532 1788sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
16:00:23.0532 1788sffp_sd - ok
16:00:23.0536 1788sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
16:00:23.0536 1788sfloppy - ok
16:00:23.0570 1788SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
16:00:23.0574 1788SharedAccess - ok
16:00:23.0589 1788ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
16:00:23.0593 1788ShellHWDetection - ok
16:00:23.0615 1788SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
16:00:23.0615 1788SiSRaid2 - ok
16:00:23.0630 1788SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
16:00:23.0631 1788SiSRaid4 - ok
16:00:23.0716 1788SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files (x86)\Skype\Updater\Updater.exe
16:00:23.0718 1788SkypeUpdate - ok
16:00:23.0745 1788Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
16:00:23.0746 1788Smb - ok
16:00:23.0777 1788SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
16:00:23.0779 1788SNMPTRAP - ok
16:00:23.0784 1788spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
16:00:23.0784 1788spldr - ok
16:00:23.0822 1788Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
16:00:23.0828 1788Spooler - ok
16:00:23.0909 1788sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
16:00:23.0941 1788sppsvc - ok
16:00:23.0994 1788sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
16:00:23.0996 1788sppuinotify - ok
16:00:24.0156 1788srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
16:00:24.0160 1788srv - ok
16:00:24.0178 1788srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
16:00:24.0182 1788srv2 - ok
16:00:24.0208 1788srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
16:00:24.0210 1788srvnet - ok
16:00:24.0232 1788SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
16:00:24.0235 1788SSDPSRV - ok
16:00:24.0254 1788SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
16:00:24.0256 1788SstpSvc - ok
16:00:24.0301 1788Steam Client Service - ok
16:00:24.0397 1788Stereo Service (c354621b6b94e10ae7f5cdbe745feb86) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
16:00:24.0401 1788Stereo Service - ok
16:00:24.0424 1788stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
16:00:24.0425 1788stexstor - ok
16:00:24.0457 1788stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
16:00:24.0464 1788stisvc - ok
16:00:24.0482 1788storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
16:00:24.0482 1788storflt - ok
16:00:24.0488 1788storvsc (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
16:00:24.0489 1788storvsc - ok
16:00:24.0498 1788swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
16:00:24.0499 1788swenum - ok
16:00:24.0523 1788swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
16:00:24.0528 1788swprv - ok
16:00:24.0578 1788SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
16:00:24.0595 1788SysMain - ok
16:00:24.0670 1788TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
16:00:24.0673 1788TabletInputService - ok
16:00:24.0696 1788TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
16:00:24.0700 1788TapiSrv - ok
16:00:24.0717 1788TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
16:00:24.0718 1788TBS - ok
16:00:24.0797 1788Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys
16:00:24.0814 1788Tcpip - ok
16:00:24.0884 1788TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys
16:00:24.0891 1788TCPIP6 - ok
16:00:24.0923 1788tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
16:00:24.0924 1788tcpipreg - ok
16:00:24.0931 1788TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
16:00:24.0931 1788TDPIPE - ok
16:00:24.0951 1788TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
16:00:24.0951 1788TDTCP - ok
16:00:24.0966 1788tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
16:00:24.0967 1788tdx - ok
16:00:24.0974 1788TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
16:00:24.0975 1788TermDD - ok
16:00:25.0003 1788TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
16:00:25.0010 1788TermService - ok
16:00:25.0019 1788Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
16:00:25.0020 1788Themes - ok
16:00:25.0046 1788THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
16:00:25.0047 1788THREADORDER - ok
16:00:25.0058 1788TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
16:00:25.0060 1788TrkWks - ok
16:00:25.0089 1788TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
16:00:25.0091 1788TrustedInstaller - ok
16:00:25.0105 1788tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
16:00:25.0106 1788tssecsrv - ok
16:00:25.0126 1788tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
16:00:25.0128 1788tunnel - ok
16:00:25.0140 1788uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
16:00:25.0141 1788uagp35 - ok
16:00:25.0162 1788udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
16:00:25.0165 1788udfs - ok
16:00:25.0179 1788UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
16:00:25.0181 1788UI0Detect - ok
16:00:25.0195 1788uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
16:00:25.0196 1788uliagpkx - ok
16:00:25.0226 1788umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
16:00:25.0227 1788umbus - ok
16:00:25.0236 1788UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
16:00:25.0236 1788UmPass - ok
16:00:25.0261 1788UmRdpService (af0ac98ee5077eb844413eb54287fde3) C:\Windows\System32\umrdp.dll
16:00:25.0264 1788UmRdpService - ok
16:00:25.0286 1788upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
16:00:25.0291 1788upnphost - ok
16:00:25.0331 1788USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
16:00:25.0332 1788USBAAPL64 - ok
16:00:25.0367 1788usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
16:00:25.0368 1788usbccgp - ok
16:00:25.0388 1788usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
16:00:25.0389 1788usbcir - ok
16:00:25.0417 1788usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
16:00:25.0418 1788usbehci - ok
16:00:25.0434 1788usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
16:00:25.0438 1788usbhub - ok
16:00:25.0448 1788usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\DRIVERS\usbohci.sys
16:00:25.0448 1788usbohci - ok
16:00:25.0461 1788usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
16:00:25.0461 1788usbprint - ok
16:00:25.0475 1788USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:00:25.0476 1788USBSTOR - ok
16:00:25.0502 1788usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
16:00:25.0503 1788usbuhci - ok
16:00:25.0513 1788UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
16:00:25.0514 1788UxSms - ok
16:00:25.0525 1788VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
16:00:25.0526 1788VaultSvc - ok
16:00:25.0539 1788vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
16:00:25.0539 1788vdrvroot - ok
16:00:25.0565 1788vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
16:00:25.0571 1788vds - ok
16:00:25.0583 1788vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
16:00:25.0584 1788vga - ok
16:00:25.0599 1788VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
16:00:25.0600 1788VgaSave - ok
16:00:25.0619 1788vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
16:00:25.0622 1788vhdmp - ok
16:00:25.0624 1788viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
16:00:25.0625 1788viaide - ok
16:00:25.0641 1788vmbus (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
16:00:25.0643 1788vmbus - ok
16:00:25.0653 1788VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
16:00:25.0653 1788VMBusHID - ok
16:00:25.0664 1788volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
16:00:25.0664 1788volmgr - ok
16:00:25.0680 1788volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
16:00:25.0683 1788volmgrx - ok
16:00:25.0700 1788volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
16:00:25.0703 1788volsnap - ok
16:00:25.0729 1788vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
16:00:25.0731 1788vsmraid - ok
16:00:25.0780 1788VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
16:00:25.0795 1788VSS - ok
16:00:25.0857 1788vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
16:00:25.0858 1788vwifibus - ok
16:00:25.0874 1788W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
16:00:25.0879 1788W32Time - ok
16:00:25.0891 1788WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
16:00:25.0892 1788WacomPen - ok
16:00:25.0910 1788WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
16:00:25.0911 1788WANARP - ok
16:00:25.0913 1788Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
16:00:25.0914 1788Wanarpv6 - ok
16:00:25.0977 1788WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
16:00:25.0989 1788WatAdminSvc - ok
16:00:26.0030 1788wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
16:00:26.0044 1788wbengine - ok
16:00:26.0073 1788WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
16:00:26.0077 1788WbioSrvc - ok
16:00:26.0107 1788wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
16:00:26.0111 1788wcncsvc - ok
16:00:26.0122 1788WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
16:00:26.0124 1788WcsPlugInService - ok
16:00:26.0137 1788Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
16:00:26.0138 1788Wd - ok
16:00:26.0163 1788Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
16:00:26.0168 1788Wdf01000 - ok
16:00:26.0183 1788WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
16:00:26.0185 1788WdiServiceHost - ok
16:00:26.0187 1788WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
16:00:26.0189 1788WdiSystemHost - ok
16:00:26.0244 1788WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
16:00:26.0247 1788WebClient - ok
16:00:26.0273 1788Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
16:00:26.0276 1788Wecsvc - ok
16:00:26.0292 1788wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
16:00:26.0294 1788wercplsupport - ok
16:00:26.0308 1788WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
16:00:26.0310 1788WerSvc - ok
16:00:26.0323 1788WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
16:00:26.0324 1788WfpLwf - ok
16:00:26.0334 1788WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
16:00:26.0334 1788WIMMount - ok
16:00:26.0361 1788WinDefend - ok
16:00:26.0365 1788WinHttpAutoProxySvc - ok
16:00:26.0413 1788Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
16:00:26.0416 1788Winmgmt - ok
16:00:26.0479 1788WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
16:00:26.0498 1788WinRM - ok
16:00:26.0557 1788WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
16:00:26.0558 1788WinUsb - ok
16:00:26.0601 1788Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
16:00:26.0610 1788Wlansvc - ok
16:00:26.0623 1788WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
16:00:26.0624 1788WmiAcpi - ok
16:00:26.0663 1788wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
16:00:26.0665 1788wmiApSrv - ok
16:00:26.0685 1788WMPNetworkSvc - ok
16:00:26.0696 1788WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
16:00:26.0698 1788WPCSvc - ok
16:00:26.0714 1788WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
16:00:26.0716 1788WPDBusEnum - ok
16:00:26.0729 1788ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
16:00:26.0729 1788ws2ifsl - ok
16:00:26.0753 1788wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\system32\wscsvc.dll
16:00:26.0755 1788wscsvc - ok
16:00:26.0758 1788WSearch - ok
16:00:26.0838 1788wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
16:00:26.0860 1788wuauserv - ok
16:00:26.0900 1788WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
16:00:26.0901 1788WudfPf - ok
16:00:26.0914 1788WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
16:00:26.0916 1788WUDFRd - ok
16:00:26.0926 1788wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
16:00:26.0928 1788wudfsvc - ok
16:00:26.0945 1788WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
16:00:26.0949 1788WwanSvc - ok
16:00:26.0965 1788MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
16:00:26.0984 1788\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
16:00:26.0984 1788\Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
16:00:27.0012 1788Boot (0x1200) (1ca5653cd1d791d37167e8d13011c817) \Device\Harddisk0\DR0\Partition0
16:00:27.0013 1788\Device\Harddisk0\DR0\Partition0 - ok
16:00:27.0023 1788Boot (0x1200) (5ff3be391070404df62dbcb26e4cd7d5) \Device\Harddisk0\DR0\Partition1
16:00:27.0024 1788\Device\Harddisk0\DR0\Partition1 - ok
16:00:27.0024 1788============================================================
16:00:27.0024 1788Scan finished
16:00:27.0024 1788============================================================
16:00:27.0031 3968Detected object count: 1
16:00:27.0031 3968Actual detected object count: 1
16:00:49.0748 3968\Device\Harddisk0\DR0\# - copied to quarantine
16:00:49.0748 3968\Device\Harddisk0\DR0 - copied to quarantine
16:00:50.0027 3968\Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
16:00:50.0029 3968\Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
16:00:50.0035 3968\Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
16:00:50.0039 3968\Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
16:00:50.0040 3968\Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
16:00:50.0040 3968\Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
16:00:50.0041 3968\Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
16:00:50.0042 3968\Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
16:00:50.0043 3968\Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
16:00:50.0044 3968\Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
16:00:50.0044 3968\Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
16:00:50.0045 3968\Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
16:00:50.0050 3968\Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
16:00:50.0140 3968\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
16:00:50.0155 3968\Device\Harddisk0\DR0 - ok
16:00:55.0710 3968\Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
16:01:18.0524 3980Deinitialize success
 
Good :)

Update MBAM, post new log.

Next....

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

======================================

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
 
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.17.15

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Justin :: JUSTIN-PC [administrator]

Protection: Enabled

7/17/2012 5:03:27 PM
mbam-log-2012-07-17 (17-07-19).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239962
Time elapsed: 2 minute(s), 48 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\Justin\AppData\Local\Temp\.exe (Trojan.Agent) -> No action taken.

(end)
 
RogueKiller V7.6.4 [07/17/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.techspot.com/downloads/5562-roguekiller.html
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User: Justin [Admin rights]
Mode: Scan -- Date: 07/17/2012 17:08:25
¤¤¤ Bad processes: 0 ¤¤¤
¤¤¤ Registry Entries: 5 ¤¤¤
[SUSP PATH] RunAsStdUser Task.job @ : C:\Users\Justin\AppData\Local\cheerychickenSA\bin\1.0.7.0\CheeryChickenSA.exe -> FOUND
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver: [NOT LOADED] ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
127.0.0.1www.007guard.com
127.0.0.1007guard.com
127.0.0.1008i.com
127.0.0.1www.008k.com
127.0.0.1008k.com
127.0.0.1www.00hq.com
127.0.0.100hq.com
127.0.0.1010402.com
127.0.0.1www.032439.com
127.0.0.1032439.com
127.0.0.1www.0scan.com
127.0.0.10scan.com
127.0.0.11000gratisproben.com
127.0.0.1www.1000gratisproben.com
127.0.0.11001namen.com
127.0.0.1www.1001namen.com
127.0.0.1www.100888290cs.com
127.0.0.1100888290cs.com
127.0.0.1100sexlinks.com
[...]
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD103SJ ATA Device +++++
--- User ---
[MBR] 78f33fdd9332190a16726ff0f4328421
[BSP] 95d42fcc6c073633fa29b11d35047033 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 953767 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
 
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-07-17 17:09:41
-----------------------------
17:09:41.522 OS Version: Windows x64 6.1.7600
17:09:41.522 Number of processors: 6 586 0xA00
17:09:41.523 ComputerName: JUSTIN-PC UserName: Justin
17:09:42.254 Initialize success
17:10:22.383 AVAST engine defs: 12071701
17:10:30.653 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
17:10:30.654 Disk 0 Vendor: SAMSUNG_HD103SJ 1AJ10001 Size: 953869MB BusType: 3
17:10:30.666 Disk 0 MBR read successfully
17:10:30.667 Disk 0 MBR scan
17:10:30.669 Disk 0 Windows 7 default MBR code
17:10:30.690 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
17:10:30.735 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
17:10:30.774 Disk 0 scanning C:\Windows\system32\drivers
17:10:35.869 Service scanning
17:10:48.078 Modules scanning
17:10:48.082 Disk 0 trace - called modules:
17:10:48.097 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
17:10:48.099 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007b09060]
17:10:48.425 3 CLASSPNP.SYS[fffff8800100143f] -> nt!IofCallDriver -> [0xfffffa800785a580]
17:10:48.428 5 ACPI.sys[fffff88000f21781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800783c060]
17:10:49.190 AVAST engine scan C:\Windows
17:10:51.566 AVAST engine scan C:\Windows\system32
17:12:45.659 AVAST engine scan C:\Windows\system32\drivers
17:12:51.760 AVAST engine scan C:\Users\Justin
17:13:32.097 Disk 0 MBR has been saved successfully to "C:\Users\Justin\Desktop\MBR.dat"
17:13:32.101 The log file has been saved successfully to "C:\Users\Justin\Desktop\aswMBR.txt"
 
Status
Not open for further replies.
Back