Solved Computer seems infected

NorGitram

Posts: 112   +0
DDS scan locks up computer and won't finish. I disconnected from net and disabled antivirus.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.12.04.04
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HOME :: DELL-D610 [administrator]
12/4/2013 3:53:08 AM
mbam-log-2013-12-04 (03-53-08).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 232038
Time elapsed: 17 minute(s), 54 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 13
HKCR\CLSID\{33119133-0854-469d-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{13119113-0854-469d-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\PopularScreensavers_7i.SkinLauncher.1 (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\PopularScreensavers_7i.SkinLauncher (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{03119103-0854-469d-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\Interface\{23119123-0854-469D-807A-171568457991} (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\PopularScreensavers_7i.SkinLauncherSettings.1 (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCR\PopularScreensavers_7i.SkinLauncherSettings (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
HKCU\Software\ConduitSearchScopes (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
HKCU\Software\PriceGong (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\CROSSRIDER (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCU\Software\InstalledBrowserExtensions\weDownload (PUP.Optional.WeDownload.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\_VOID (Rootkit.TDSS) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKCU\Software\Crossrider|Verifier (PUP.Optional.CrossRider.A) -> Data: 250551f22fc46bd5c76f01d711e6f088 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PopularScreensavers Search Scope Monitor (PUP.Optional.MindSpark) -> Data: "C:\PROGRA~1\POPULA~2\bar\1.bin\7isrchmn.exe" /m=2 /w /h -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PopularScreensavers_7i Browser Plugin Loader (PUP.Optional.MindSpark) -> Data: C:\PROGRA~1\POPULA~2\bar\1.bin\7ibrmon.exe -> Quarantined and deleted successfully.
Registry Data Items Detected: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 11
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\lib (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\images (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\_VOIDymxgobuqxe (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Conduit\IE (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
Files Detected: 73
C:\Program Files\PopularScreensavers_7i\bar\1.bin\7isknlcr.dll (PUP.Optional.FunWebProducts.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsj34.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\SecondStepInstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsm18.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsq13.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsq2F.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsx34.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Application Data\Conduit\CT3297964\Begin-download_FLV_B2AutoUpdateHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Favorites\_favdata.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\nsprotector.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\abstraction.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\application.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\popupTransparent.xul (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\dialogsApi.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\lib\jquery.min.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\lib\json2.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\bubble.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\bubble.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images\information.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images\x-default-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-LTR.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spbd\images\x-mouseover-RTL.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\main.html (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\SearchProtector.css (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\settings.js (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\images\ok-button.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\images\separation-line.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\ffprotect\Dialogs\spsd\images\warning.png (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\roboot.exe (PUP.Optional.PCPerformer.A) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\weDownload Manager-codedownloader.job (PUP.Optional.WeDownload.A) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\weDownload Manager-enabler.job (PUP.Optional.WeDownload.A) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\weDownload Manager-firefoxinstaller.job (PUP.Optional.WeDownload.A) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\weDownload Manager-updater.job (PUP.Optional.WeDownload.A) -> Quarantined and deleted successfully.
C:\Program Files\PopularScreensavers_7i\bar\1.bin\7iSrchMn.exe (PUP.Optional.MindSpark) -> Quarantined and deleted successfully.
C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibrmon.exe (PUP.Optional.MindSpark) -> Delete on reboot.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\1.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\4489.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\450.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\83.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\a.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\b.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\c.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\d.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\e.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\f.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\g.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\h.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\I.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\j.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\k.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\l.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\m.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\mru.xml (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\n.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\o.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\p.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\q.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\r.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\s.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\t.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\u.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\v.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\w.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\wlu.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\x.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\y.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\HOME\Application Data\PriceGong\Data\z.txt (PUP.Optional.PriceGong.A) -> Quarantined and deleted successfully.
(end)
 
Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

===================================

Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
 
11:28:07.0468 0x0de8 TDSS rootkit removing tool 3.0.0.19 Nov 18 2013 09:27:50
11:28:15.0015 0x0de8 ============================================================
11:28:15.0015 0x0de8 Current date / time: 2013/12/04 11:28:15.0015
11:28:15.0015 0x0de8 SystemInfo:
11:28:15.0015 0x0de8
11:28:15.0031 0x0de8 OS Version: 5.1.2600 ServicePack: 3.0
11:28:15.0031 0x0de8 Product type: Workstation
11:28:15.0031 0x0de8 ComputerName: DELL-D610
11:28:15.0031 0x0de8 UserName: HOME
11:28:15.0031 0x0de8 Windows directory: C:\WINDOWS
11:28:15.0031 0x0de8 System windows directory: C:\WINDOWS
11:28:15.0031 0x0de8 Processor architecture: Intel x86
11:28:15.0031 0x0de8 Number of processors: 1
11:28:15.0031 0x0de8 Page size: 0x1000
11:28:15.0031 0x0de8 Boot type: Normal boot
11:28:15.0031 0x0de8 ============================================================
11:28:21.0796 0x0de8 KLMD registered as C:\WINDOWS\system32\drivers\37985886.sys
11:28:22.0296 0x0de8 System UUID: {A1F4EB8F-5FA7-650B-2A5E-216558DD5DD6}
11:28:23.0484 0x0de8 Drive \Device\Harddisk0\DR0 - Size: 0x950A60000 (37.26 Gb), SectorSize: 0x200, Cylinders: 0x1300, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
11:28:23.0484 0x0de8 ============================================================
11:28:23.0484 0x0de8 \Device\Harddisk0\DR0:
11:28:23.0484 0x0de8 MBR partitions:
11:28:23.0484 0x0de8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1
11:28:23.0484 0x0de8 ============================================================
11:28:23.0531 0x0de8 C: <-> \Device\Harddisk0\DR0\Partition1
11:28:23.0562 0x0de8 ============================================================
11:28:23.0562 0x0de8 Initialize success
11:28:23.0562 0x0de8 ============================================================
11:28:37.0515 0x0d7c ============================================================
11:28:37.0515 0x0d7c Scan started
11:28:37.0515 0x0d7c Mode: Manual;
11:28:37.0515 0x0d7c ============================================================
11:28:37.0515 0x0d7c KSN ping started
11:28:41.0531 0x0d7c KSN ping finished: true
11:28:42.0812 0x0d7c ================ Scan system memory ========================
11:28:42.0812 0x0d7c System memory - ok
11:28:42.0812 0x0d7c ================ Scan services =============================
11:28:43.0015 0x0d7c Abiosdsk - ok
11:28:43.0015 0x0d7c abp480n5 - ok
11:28:43.0078 0x0d7c [ 0F2D66D5F08EBE2F77BB904288DCF6F0, 5969A64B6995DCAF16F9A76BD1235472F76D71DFE629B956221D2C3D73EDF98A ] ac97intc C:\WINDOWS\system32\drivers\ac97intc.sys
11:28:43.0078 0x0d7c ac97intc - ok
11:28:43.0437 0x0d7c [ ADC420616C501B45D26C0FD3EF1E54E4, 29FC41D40A35AC5476E2A673CE5B12684E0CFA12A1AEBEEBE5883FBA5CA68B67 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
11:28:43.0453 0x0d7c ACDaemon - ok
11:28:43.0500 0x0d7c [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:28:43.0500 0x0d7c ACPI - ok
11:28:43.0562 0x0d7c [ 9859C0F6936E723E4892D7141B1327D5, 5E8F6A2FC4DF2E5E92A1D66ECC2810E08B42B64E9CD0DF4AD3F78EA8558B90AF ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
11:28:43.0562 0x0d7c ACPIEC - ok
11:28:43.0718 0x0d7c [ 438F31336B3DC248ABC632F1C8F34A24, 94C1218E7EC2EC6D4870A6FDC118097D7D3A359DA073DCD3A9770F399F830991 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:28:43.0734 0x0d7c AdobeFlashPlayerUpdateSvc - ok
11:28:43.0750 0x0d7c adpu160m - ok
11:28:43.0796 0x0d7c [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
11:28:43.0812 0x0d7c aec - ok
11:28:43.0843 0x0d7c [ FE3EA6E9AFC1A78E6EDCA121E006AFB7, B596ABBAC058D93C505C9DBF8685049C88E4364195A4092DB580D2D44FA8C23C ] Afc C:\WINDOWS\system32\drivers\Afc.sys
11:28:43.0843 0x0d7c Afc - ok
11:28:43.0906 0x0d7c [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
11:28:43.0921 0x0d7c AFD - ok
11:28:43.0968 0x0d7c [ 08FD04AA961BDC77FB983F328334E3D7, A784EC8A9EDB579262366B5A9AB177DB7BEC0A421BDE85431D0AD4959D5AF5E7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
11:28:43.0968 0x0d7c agp440 - ok
11:28:43.0984 0x0d7c Aha154x - ok
11:28:44.0000 0x0d7c aic78u2 - ok
11:28:44.0015 0x0d7c aic78xx - ok
11:28:44.0062 0x0d7c [ A9A3DAA780CA6C9671A19D52456705B4, 67C959144B57AE0BBF1D82DBED197F32CDB06FECD883A80C441A0202FE83FAB4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
11:28:44.0062 0x0d7c Alerter - ok
11:28:44.0125 0x0d7c [ 8C515081584A38AA007909CD02020B3D, A5E13CA10F702928E0DE84C74D0EA8ACCB117FD76FBABC55220C75C4FFD596DC ] ALG C:\WINDOWS\System32\alg.exe
11:28:44.0140 0x0d7c ALG - ok
11:28:44.0156 0x0d7c AliIde - ok
11:28:44.0156 0x0d7c amsint - ok
11:28:44.0234 0x0d7c [ D8849F77C0B66226335A59D26CB4EDC6, 4990031453204C57E36E850252A39B05D6ECDAB9E71A8136FB4900F17E59C9CA ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
11:28:44.0250 0x0d7c AppMgmt - ok
11:28:44.0359 0x0d7c [ 5BAC41911D588E16B8E92335F9FD98D1, 343B64E3C0DD1A2AFAD0D635D1C23F4E665B8EE38D9F1A052CF3B5DE59ACA6B7 ] AR5211 C:\WINDOWS\system32\DRIVERS\ar5211.sys
11:28:44.0421 0x0d7c AR5211 - ok
11:28:44.0500 0x0d7c [ FBE18577F160F0D3CA79234C317729D9, B0C940679F6D539CD4D2602F7BDDE2092DD0655553E16A27B16429F8E3613F8E ] AR5513 C:\WINDOWS\system32\DRIVERS\ar5513.sys
11:28:44.0546 0x0d7c AR5513 - ok
11:28:44.0578 0x0d7c [ B5B8A80875C1DEDEDA8B02765642C32F, AD0C71D73B1B8225351FBF4FFB43001A32B4DAE69504C59970CD2428BB33D4EF ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
11:28:44.0593 0x0d7c Arp1394 - ok
11:28:44.0593 0x0d7c asc - ok
11:28:44.0609 0x0d7c asc3350p - ok
11:28:44.0625 0x0d7c asc3550 - ok
11:28:44.0796 0x0d7c [ 0E5E4957549056E2BF2C49F4F6B601AD, F7F19FDC906B719A3516D30A9B4A2262C8CC5B36B94E3D4195C345EC4610FF2B ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:28:44.0796 0x0d7c aspnet_state - ok
11:28:44.0828 0x0d7c [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:28:44.0828 0x0d7c AsyncMac - ok
11:28:44.0875 0x0d7c [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
11:28:44.0890 0x0d7c atapi - ok
11:28:44.0890 0x0d7c Atdisk - ok
11:28:45.0015 0x0d7c [ 17EA1C7671DDE20E32E7C9FFE842F46E, D2E1AF4E75A7AC6CCFA0040D68A5B76B0A85E31CF6E7127E7766C30A2CF37E77 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
11:28:45.0078 0x0d7c Ati HotKey Poller - ok
11:28:45.0203 0x0d7c [ 8EB17CF829DF300CC885651CFEAF931C, 5CD263BD4539E64F0B73E2D7A84ED94BDBC6EB5212F5A1C39B4368D2D9AE7EF4 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
11:28:45.0296 0x0d7c ati2mtag - ok
11:28:45.0343 0x0d7c atimtag - ok
11:28:45.0390 0x0d7c [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:28:45.0406 0x0d7c Atmarpc - ok
11:28:45.0453 0x0d7c [ DEF7A7882BEC100FE0B2CE2549188F9D, 462C95B63D0A1058291A2DC8CBFCB13D7D74CCD1CA43B613A7EB43D49E3276F8 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
11:28:45.0453 0x0d7c AudioSrv - ok
11:28:45.0515 0x0d7c [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
11:28:45.0515 0x0d7c audstub - ok
11:28:45.0593 0x0d7c [ 3A3A82FFD268BCFB7AE6A48CECF00AD9, 16F076B9816E28541C58FE9695EB883211C284AA025E9F49B19E7DD4E6BDA94D ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys
11:28:45.0609 0x0d7c b57w2k - ok
11:28:45.0765 0x0d7c [ B89BCF0A25AEB3B47030AC83287F894A, DEBA0B00D5E15D1F4AC014D3FD684115E48FE924DF0170F7F4273056DD854778 ] BCM43XX C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
11:28:45.0828 0x0d7c BCM43XX - ok
11:28:45.0921 0x0d7c [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
11:28:45.0921 0x0d7c Beep - ok
11:28:46.0015 0x0d7c [ 574738F61FCA2935F5265DC4E5691314, 3C7CCF064397186C3A3863DD2370AB6414A61B330097DCA4F299CA7BBAA3D1B4 ] BITS C:\WINDOWS\system32\qmgr.dll
11:28:46.0125 0x0d7c BITS - ok
11:28:46.0265 0x0d7c [ F832F1505AD8B83474BD9A5B1B985E01, 205D9F237DD50FDF84F57CC53476B5ADB218A03A8B68B017AFF7CBD0DCAC71C4 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
11:28:46.0312 0x0d7c Bonjour Service - ok
11:28:46.0359 0x0d7c [ CFD4E51402DA9838B5A04AE680AF54A0, 5378F42B195B5832B00A05AD64E00473A45FFB86AC25C57241F26EA82B149FE1 ] Browser C:\WINDOWS\System32\browser.dll
11:28:46.0375 0x0d7c Browser - ok
11:28:46.0406 0x0d7c [ B279426E3C0C344893ED78A613A73BDE, 30B29ED5DCFF0C180B806A5FBC705E1CAF6B0F525298CDA79A77FC2AF6E5AAA7 ] BthEnum C:\WINDOWS\system32\DRIVERS\BthEnum.sys
11:28:46.0421 0x0d7c BthEnum - ok
11:28:46.0453 0x0d7c [ 80602B8746D3738F5886CE3D67EF06B6, 15ABAA8106C42A4453763EEB92B291844580168C934088DB1E22B2065DC238E9 ] BthPan C:\WINDOWS\system32\DRIVERS\bthpan.sys
11:28:46.0468 0x0d7c BthPan - ok
11:28:46.0546 0x0d7c [ 662BFD909447DD9CC15B1A1C366583B4, 2E012304336769C24A6EFB4D975BA3F21289827A5EB4C9A8216E941344348447 ] BTHPORT C:\WINDOWS\system32\Drivers\BTHport.sys
11:28:46.0578 0x0d7c BTHPORT - ok
11:28:46.0625 0x0d7c [ F4C43C66471B87996D95DB7A3A664A37, C7324DBF75376578EC254FD64E2564FEF9A35B58DFE1095389F769F37EA68B21 ] BthServ C:\WINDOWS\System32\bthserv.dll
11:28:46.0640 0x0d7c BthServ - ok
11:28:46.0687 0x0d7c [ 61364CD71EF63B0F038B7E9DF00F1EFA, FB44D02B4379A8AF7DD8B0B22B53888B758903700142BFE45A412709294CE88A ] BTHUSB C:\WINDOWS\system32\Drivers\BTHUSB.sys
11:28:46.0703 0x0d7c BTHUSB - ok
11:28:46.0734 0x0d7c [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
11:28:46.0734 0x0d7c cbidf2k - ok
11:28:46.0750 0x0d7c cd20xrnt - ok
11:28:46.0796 0x0d7c [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
11:28:46.0812 0x0d7c Cdaudio - ok
11:28:46.0828 0x0d7c [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
11:28:46.0843 0x0d7c Cdfs - ok
11:28:46.0875 0x0d7c [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:28:46.0875 0x0d7c Cdrom - ok
11:28:46.0937 0x0d7c [ 84853B3FD012251690570E9E7E43343F, 65CACFA643E52A0C0E6B2D901228A8A0AD4993CAFA3C287E65395F4B7C521089 ] cercsr6 C:\WINDOWS\system32\drivers\cercsr6.sys
11:28:47.0015 0x0d7c cercsr6 - ok
11:28:47.0031 0x0d7c Changer - ok
11:28:47.0093 0x0d7c [ 1CFE720EB8D93A7158A4EBC3AB178BDE, 65D2A9D9A88F38D4AF323134C151BA0F4B3CD0F6A134AF86E7AC9D07319F1726 ] CiSvc C:\WINDOWS\system32\cisvc.exe
11:28:47.0093 0x0d7c CiSvc - ok
11:28:47.0125 0x0d7c [ 34CBE729F38138217F9C80212A2A0C82, A9FD7A758D12E0818A11BEEF1CE772FEFA8373E92EF6C0DA8628CD4572CC9A43 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
11:28:47.0140 0x0d7c ClipSrv - ok
11:28:47.0187 0x0d7c [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:28:47.0218 0x0d7c clr_optimization_v2.0.50727_32 - ok
11:28:47.0250 0x0d7c [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
11:28:47.0265 0x0d7c CmBatt - ok
11:28:47.0265 0x0d7c CmdIde - ok
11:28:47.0296 0x0d7c [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
11:28:47.0296 0x0d7c Compbatt - ok
11:28:47.0312 0x0d7c COMSysApp - ok
11:28:47.0328 0x0d7c Cpqarray - ok
11:28:47.0359 0x0d7c [ 3D4E199942E29207970E04315D02AD3B, 0825960894CF9C86CC8775BDD2A262948A09CA495AA7FE9F210FAF49E7086383 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
11:28:47.0359 0x0d7c CryptSvc - ok
11:28:47.0375 0x0d7c dac2w2k - ok
11:28:47.0390 0x0d7c dac960nt - ok
11:28:47.0468 0x0d7c [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
11:28:47.0562 0x0d7c DcomLaunch - ok
11:28:47.0609 0x0d7c [ 5E38D7684A49CACFB752B046357E0589, F192AD4190BCFB6939A5CBC91648FE63168AF79A5E227A111DEAD6A92E42AB8D ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
11:28:47.0625 0x0d7c Dhcp - ok
11:28:47.0640 0x0d7c [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
11:28:47.0640 0x0d7c Disk - ok
11:28:47.0656 0x0d7c dmadmin - ok
11:28:47.0765 0x0d7c [ D992FE1274BDE0F84AD826ACAE022A41, C82BD6561A14F2932A761F5883A787B99031250EE5E9B7B5714AA045545C9B99 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
11:28:47.0859 0x0d7c dmboot - ok
11:28:47.0921 0x0d7c [ 7C824CF7BBDE77D95C08005717A95F6F, A73CB323B7A6410C3D3F258BF204E716ADF8C84C9E4F6562C57AB73DAED8CCDE ] dmio C:\WINDOWS\system32\drivers\dmio.sys
11:28:47.0937 0x0d7c dmio - ok
11:28:48.0031 0x0d7c [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
11:28:48.0031 0x0d7c dmload - ok
11:28:48.0093 0x0d7c [ 57EDEC2E5F59F0335E92F35184BC8631, 61F6F0DC2D1A6C61D5EF0D5CC4BE0FFC217F1E61FDA3EA9F704709293656600F ] dmserver C:\WINDOWS\System32\dmserver.dll
11:28:48.0109 0x0d7c dmserver - ok
11:28:48.0156 0x0d7c [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
11:28:48.0156 0x0d7c DMusic - ok
11:28:48.0203 0x0d7c [ 5F7E24FA9EAB896051FFB87F840730D2, 356EEFDCD54DECAD0170B34B993E4BF80DD039E2B2922D7A8D09B84031E9FC7A ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
11:28:48.0203 0x0d7c Dnscache - ok
11:28:48.0281 0x0d7c [ 0F0F6E687E5E15579EF4DA8DD6945814, 5C32D88119EB1465B2D719BEE2E05888D1A73454B5E33F2D4928DA710F8BFBA3 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
11:28:48.0296 0x0d7c Dot3svc - ok
11:28:48.0312 0x0d7c dpti2o - ok
11:28:48.0328 0x0d7c [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
11:28:48.0328 0x0d7c drmkaud - ok
11:28:48.0359 0x0d7c [ 2187855A7703ADEF0CEF9EE4285182CC, 8233CC11F637866C0074043835A785EA2B616739B6B1181B143A253CF2508CFD ] EapHost C:\WINDOWS\System32\eapsvc.dll
11:28:48.0359 0x0d7c EapHost - ok
11:28:48.0406 0x0d7c [ 6E883BF518296A40959131C2304AF714, FCBDAB6C9220742821D1A1711D39688889B578E0992F8B41945027DB23E92777 ] EL90XBC C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
11:28:48.0421 0x0d7c EL90XBC - ok
11:28:48.0453 0x0d7c [ BC93B4A066477954555966D77FEC9ECB, 27F5B780175EF46DA102EE33F7F33559C8B40C077EEA4405D579D9507F4B1C23 ] ERSvc C:\WINDOWS\System32\ersvc.dll
11:28:48.0468 0x0d7c ERSvc - ok
11:28:48.0515 0x0d7c [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] Eventlog C:\WINDOWS\system32\services.exe
11:28:48.0531 0x0d7c Eventlog - ok
11:28:48.0609 0x0d7c [ D4991D98F2DB73C60D042F1AEF79EFAE, 58AF949EAEBF4FF3E3314DFB66CE4198BF65F0836B68CD27A6ED319742CCCCD2 ] EventSystem C:\WINDOWS\system32\es.dll
11:28:48.0640 0x0d7c EventSystem - ok
11:28:48.0703 0x0d7c [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
11:28:48.0718 0x0d7c Fastfat - ok
11:28:48.0796 0x0d7c [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
11:28:48.0812 0x0d7c FastUserSwitchingCompatibility - ok
11:28:48.0843 0x0d7c [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
11:28:48.0859 0x0d7c Fdc - ok
11:28:48.0906 0x0d7c [ D45926117EB9FA946A6AF572FBE1CAA3, 4C94EF009D778BE0BDF8F812F026B96F91F641BE30AA2531427A5E63DBD280DA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
11:28:49.0031 0x0d7c Fips - ok
11:28:49.0078 0x0d7c [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:28:49.0078 0x0d7c Flpydisk - ok
11:28:49.0125 0x0d7c [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
11:28:49.0140 0x0d7c FltMgr - ok
11:28:49.0234 0x0d7c [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
11:28:49.0234 0x0d7c FontCache3.0.0.0 - ok
11:28:49.0265 0x0d7c [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:28:49.0265 0x0d7c Fs_Rec - ok
11:28:49.0328 0x0d7c [ 6AC26732762483366C3969C9E4D2259D, FF2C9A23CC17F380093F0BEA955B1925794271C2FEA16B9B7639668E6999BAE3 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:28:49.0343 0x0d7c Ftdisk - ok
11:28:49.0390 0x0d7c [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:28:49.0406 0x0d7c Gpc - ok
11:28:49.0484 0x0d7c [ CA835331825599B938E37525796D3549, 0CF7AEA9456A02FDB5621B4774956839B879098E35BECCFF1FE7140710986BF2 ] GTIPCI21 C:\WINDOWS\system32\DRIVERS\gtipci21.sys
11:28:49.0484 0x0d7c GTIPCI21 - ok
11:28:49.0578 0x0d7c [ 28571F4E281D0DC89A43D49699DB8EB3, A9D072409388A38B5401F3B47D98DCF1F70692489281A3267CAFCDCB3E944C7A ] GWRCB_A00 C:\WINDOWS\system32\DRIVERS\GWRCBA00.sys
11:28:49.0718 0x0d7c GWRCB_A00 - ok
11:28:49.0734 0x0d7c HidServ - ok
11:28:49.0781 0x0d7c [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:28:49.0781 0x0d7c HidUsb - ok
11:28:49.0828 0x0d7c [ 8878BD685E490239777BFE51320B88E9, C5C3ECF6B049B6736E35B39518A8F830B45C45A88FFE8E3A6B7922AD946597E2 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
11:28:49.0843 0x0d7c hkmsvc - ok
11:28:49.0859 0x0d7c hpn - ok
11:28:49.0968 0x0d7c [ 5FABA4775D4C61E55EC669D643FFC71F, EDBC23F6079DC4F4492E3A3381D1DDABA2BDAD05BAF831BB9E92D55AEBEB3FDB ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
11:28:49.0984 0x0d7c HPZid412 - ok
11:28:50.0015 0x0d7c [ A3C43980EE1F1BEAC778B44EA65DBDD4, 404F5248FD7DB0AAF02F214FC6001D743EB61F579D250A87D06F58F9182F5DE4 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
11:28:50.0015 0x0d7c HPZipr12 - ok
11:28:50.0031 0x0d7c [ 2906949BD4E206F2BB0DD1896CE9F66F, F1EAE39571C2264163E1E080ED83225B6CD005FB2BAD0925430E7B1FE0654DAE ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
11:28:50.0031 0x0d7c HPZius12 - ok
11:28:50.0109 0x0d7c [ A84BBBDD125D370593004F6429F8445C, 78292243F4894A3DCB4F90D71DE4AB51C5DEF1252976272C8108E8CAFFEE10F5 ] HSFHWICH C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
11:28:50.0187 0x0d7c HSFHWICH - ok
11:28:50.0359 0x0d7c [ B678FA91CF4A1C19B462D8DB04CD02AB, B1A7BC7519BFF1BBAAFE0A74D2258302C0F1437476DDC7FA9334D83BC4E10586 ] HSF_DPV C:\WINDOWS\system32\DRIVERS\HSF_DPV.SYS
11:28:50.0593 0x0d7c HSF_DPV - ok
11:28:50.0687 0x0d7c [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
11:28:50.0703 0x0d7c HTTP - ok
11:28:50.0734 0x0d7c [ 6100A808600F44D999CEBDEF8841C7A3, 61A75118C327812C60622010985A2E80E79B6FD9030A5732390EE5426E4AF6C9 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
11:28:50.0765 0x0d7c HTTPFilter - ok
11:28:50.0781 0x0d7c i2omgmt - ok
11:28:50.0796 0x0d7c i2omp - ok
11:28:50.0812 0x0d7c [ 4A0B06AA8943C1E332520F7440C0AA30, DB2452390CCFE67E0C5FEB4FD42CA24ABE2DDD40D0B22DD5F5B8F70416863918 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:28:50.0812 0x0d7c i8042prt - ok
11:28:51.0031 0x0d7c [ 643162FBC619E35D3F1A90A095A5BB42, F59C325B9822E740C5E2808791CFDFD3E8CB543557E52794F578566546B9316F ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
11:28:51.0125 0x0d7c ialm - ok
11:28:51.0343 0x0d7c [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:28:51.0484 0x0d7c idsvc - ok
11:28:51.0515 0x0d7c [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
11:28:51.0515 0x0d7c Imapi - ok
11:28:51.0562 0x0d7c [ 30DEAF54A9755BB8546168CFE8A6B5E1, 3936228CD3125C763ABFCB93E86E4B43838202BCC0913A28E84AC0263B43EE0D ] ImapiService C:\WINDOWS\system32\imapi.exe
11:28:51.0578 0x0d7c ImapiService - ok
11:28:51.0609 0x0d7c ini910u - ok
11:28:51.0640 0x0d7c [ B5466A9250342A7AA0CD1FBA13420678, 87E735C4E8924A883AB692D387A83BCBFAE6E165688336AE7AB488F7CA8D339E ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
11:28:51.0640 0x0d7c IntelIde - ok
11:28:51.0671 0x0d7c [ 8C953733D8F36EB2133F5BB58808B66B, 555868F246D73652E998B0B1296476E42FCEDED30D646CC000F31ECE4EBC25E6 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
11:28:51.0671 0x0d7c intelppm - ok
11:28:51.0718 0x0d7c [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
11:28:51.0718 0x0d7c ip6fw - ok
11:28:51.0750 0x0d7c [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:28:51.0765 0x0d7c IpFilterDriver - ok
11:28:51.0781 0x0d7c [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:28:51.0781 0x0d7c IpInIp - ok
11:28:51.0843 0x0d7c [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:28:51.0859 0x0d7c IpNat - ok
11:28:51.0890 0x0d7c [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:28:51.0906 0x0d7c IPSec - ok
11:28:51.0968 0x0d7c [ ACA5E7B54409F9CB5EED97ED0C81120E, 1E22F442EA77596F58D133F1A5887CDC4F3325DD0836D24A665E1D31287ABFF7 ] irda C:\WINDOWS\system32\DRIVERS\irda.sys
11:28:51.0984 0x0d7c irda - ok
11:28:52.0015 0x0d7c [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
11:28:52.0015 0x0d7c IRENUM - ok
11:28:52.0031 0x0d7c [ 49CC4533CE897CB2E93C1E84A818FDE5, F2AC81CDB971F630699616509748DCE133874EFC79B9D6230517B5A4DFBE193D ] Irmon C:\WINDOWS\System32\irmon.dll
11:28:52.0031 0x0d7c Irmon - ok
11:28:52.0062 0x0d7c [ 05A299EC56E52649B1CF2FC52D20F2D7, 2654619DB3E6D6C385B63AB02F87D4241C4F0250CC31383D1B3586917166C2DC ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:28:52.0062 0x0d7c isapnp - ok
11:28:52.0250 0x0d7c [ 9ECF00E19736054E019C532AED8228FC, F5A64A8269EA3655BBD4850298F335C0BD30535258928ED7CE62A32A3363E60B ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
11:28:52.0453 0x0d7c JavaQuickStarterService - ok
11:28:52.0500 0x0d7c [ 463C1EC80CD17420A542B7F36A36F128, E3B11BA26AFEAFB50B0FC168EA07F6049DA6B88BCDDEEE20310602D7FC27A3A7 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:28:52.0500 0x0d7c Kbdclass - ok
11:28:52.0531 0x0d7c [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
11:28:52.0546 0x0d7c kmixer - ok
11:28:52.0625 0x0d7c [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
11:28:52.0625 0x0d7c KSecDD - ok
11:28:52.0671 0x0d7c [ 3A7C3CBE5D96B8AE96CE81F0B22FB527, 0044F03132596A494448CCE5F3D6ECC12617BB4CF6BAE348F79D4DC40ACD6EE0 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
11:28:52.0671 0x0d7c lanmanserver - ok
11:28:52.0718 0x0d7c [ A8888A5327621856C0CEC4E385F69309, B08B63300D824E35E31EEEA2C4C086DFA2C2A964CEDAE512E74D3D88AADAA2C1 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
11:28:52.0750 0x0d7c lanmanworkstation - ok
11:28:52.0765 0x0d7c lbrtfdc - ok
11:28:52.0796 0x0d7c [ A7DB739AE99A796D91580147E919CC59, EDF4E039BA277B0E6D66FEB0B28096E67D682C09DFC18ECECF062D9DCFB75ACF ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
11:28:52.0796 0x0d7c LmHosts - ok
11:28:52.0812 0x0d7c McComponentHostService - ok
11:28:52.0843 0x0d7c [ 3C318B9CD391371BED62126581EE9961, 1254273DE950EF8D5922F26D67B55C9D9082F45CDE168E3DAB20A2E53208DC3A ] mdmxsdk C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
11:28:52.0843 0x0d7c mdmxsdk - ok
11:28:52.0859 0x0d7c [ 986B1FF5814366D71E0AC5755C88F2D3, E6AF051174531C24B38E73987755D366ABEC595476C6D17793E8DCCC73F55340 ] Messenger C:\WINDOWS\System32\msgsvc.dll
11:28:52.0875 0x0d7c Messenger - ok
11:28:52.0906 0x0d7c [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
11:28:52.0921 0x0d7c mnmdd - ok
11:28:53.0000 0x0d7c [ D18F1F0C101D06A1C1ADF26EED16FCDD, BA0837C7780BD8262E143E2935AFA63BE59C3C39EF56CB8608EED0F50AF070D4 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
11:28:53.0015 0x0d7c mnmsrvc - ok
11:28:53.0062 0x0d7c [ DFCBAD3CEC1C5F964962AE10E0BCC8E1, B342CC9EC3729AB1AB4B5E2E99F890C1E0CA649162DE91F6768AB857B719E97B ] Modem C:\WINDOWS\system32\drivers\Modem.sys
11:28:53.0062 0x0d7c Modem - ok
11:28:53.0078 0x0d7c [ 35C9E97194C8CFB8430125F8DBC34D04, 0C0FCE6B0A23FB0ECB92E1663E1C72D2DD5B177D82E04782957690B69530DB39 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:28:53.0078 0x0d7c Mouclass - ok
11:28:53.0125 0x0d7c [ B1C303E17FB9D46E87A98E4BA6769685, 161A45488522055D0F0474ABEDA04DDD0B5DAC2411AF9154B15190BBD66E7153 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:28:53.0125 0x0d7c mouhid - ok
11:28:53.0156 0x0d7c [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
11:28:53.0156 0x0d7c MountMgr - ok
11:28:53.0234 0x0d7c [ FEE0BADED54222E9F1DAE9541212AAB1, 436FD3BFD698576F5F947795462F9E7970F9A6F19C9F066CC63A3B97590DB5E3 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys
11:28:53.0250 0x0d7c MpFilter - ok
11:28:53.0265 0x0d7c mraid35x - ok
11:28:53.0343 0x0d7c [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:28:53.0359 0x0d7c MRxDAV - ok
11:28:53.0453 0x0d7c [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:28:53.0515 0x0d7c MRxSmb - ok
11:28:53.0562 0x0d7c [ A137F1470499A205ABBB9AAFB3B6F2B1, FB4951727543030D9E6ED74149C3FAACE2CA9DA8C1B5F616301B30B858C724E8 ] MSDTC C:\WINDOWS\System32\msdtc.exe
11:28:53.0578 0x0d7c MSDTC - ok
11:28:53.0593 0x0d7c [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
11:28:53.0593 0x0d7c Msfs - ok
11:28:53.0609 0x0d7c MSIServer - ok
11:28:53.0671 0x0d7c [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:28:53.0703 0x0d7c MSKSSRV - ok
11:28:53.0765 0x0d7c [ CFCE43B70CA0CC4DCC8ADB62B792B173, 227F64B151B502D1D67BD6FEBADA3A567CFF2219305459C70BF1B17D1CD5BE3A ] MsMpSvc C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
11:28:53.0765 0x0d7c MsMpSvc - ok
11:28:53.0796 0x0d7c [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:28:53.0796 0x0d7c MSPCLOCK - ok
11:28:53.0812 0x0d7c [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
11:28:53.0812 0x0d7c MSPQM - ok
11:28:53.0859 0x0d7c [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:28:53.0859 0x0d7c mssmbios - ok
11:28:53.0968 0x0d7c [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
11:28:53.0984 0x0d7c Mup - ok
11:28:54.0062 0x0d7c [ 0102140028FAD045756796E1C685D695, 5335B8278418CA200E2772124F0602C3E15A5CAF2D5CC59F6785DFAABF339B09 ] napagent C:\WINDOWS\System32\qagentrt.dll
11:28:54.0109 0x0d7c napagent - ok
11:28:54.0171 0x0d7c [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
11:28:54.0187 0x0d7c NDIS - ok
11:28:54.0250 0x0d7c [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:28:54.0250 0x0d7c NdisTapi - ok
11:28:54.0281 0x0d7c [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:28:54.0281 0x0d7c Ndisuio - ok
11:28:54.0312 0x0d7c [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:28:54.0328 0x0d7c NdisWan - ok
11:28:54.0359 0x0d7c [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
11:28:54.0359 0x0d7c NDProxy - ok
11:28:54.0406 0x0d7c [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
11:28:54.0406 0x0d7c NetBIOS - ok
11:28:54.0453 0x0d7c [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
11:28:54.0468 0x0d7c NetBT - ok
11:28:54.0515 0x0d7c [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDE C:\WINDOWS\system32\netdde.exe
11:28:54.0531 0x0d7c NetDDE - ok
11:28:54.0562 0x0d7c [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
11:28:54.0562 0x0d7c NetDDEdsdm - ok
11:28:54.0625 0x0d7c [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] Netlogon C:\WINDOWS\system32\lsass.exe
11:28:54.0625 0x0d7c Netlogon - ok
11:28:54.0671 0x0d7c [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE, 4E0A67B3CC897E80D4B342FFE8B7B4CC4F6CA2EF2D34C136027A098B2E1C6166 ] Netman C:\WINDOWS\System32\netman.dll
11:28:54.0687 0x0d7c Netman - ok
11:28:54.0750 0x0d7c [ D34612C5D02D026535B3095D620626AE, 1BBCCCBF49EB8807240A77DCB43C25C21682073CC5356594E2C4F53EF36BF657 ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:28:54.0765 0x0d7c NetTcpPortSharing - ok
11:28:54.0812 0x0d7c [ E9E47CFB2D461FA0FC75B7A74C6383EA, 544136F5BFD4DC23D45E90F12FA48B82FD9EAEA9EAF3E0F5F0BD27E23D672C3E ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
11:28:54.0812 0x0d7c NIC1394 - ok
11:28:54.0890 0x0d7c [ 943337D786A56729263071623BBB9DE5, B631B47C869FE4ACF46E4AA272435D9A9CA536E3349E3FFBB8602636FEE7AFD4 ] Nla C:\WINDOWS\System32\mswsock.dll
11:28:54.0921 0x0d7c Nla - ok
11:28:54.0968 0x0d7c [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
11:28:54.0984 0x0d7c Npfs - ok
11:28:55.0046 0x0d7c [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
11:28:55.0125 0x0d7c Ntfs - ok
11:28:55.0140 0x0d7c [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
11:28:55.0156 0x0d7c NtLmSsp - ok
11:28:55.0250 0x0d7c [ 156F64A3345BD23C600655FB4D10BC08, 9611BE411586E068D9297D77102DB3BE48AA67F1BAD6F61A84F83FC3043FA9CD ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
11:28:55.0328 0x0d7c NtmsSvc - ok
11:28:55.0343 0x0d7c [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
11:28:55.0359 0x0d7c Null - ok
11:28:55.0546 0x0d7c [ D50DBFCDF05C7B161DEFCD0FC46E77AE, FAB3EDC5003EAAD84391CC8CFFE45F202FA2CF5635C3A3D354768454FA48D98A ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:28:55.0718 0x0d7c nv - ok
11:28:55.0781 0x0d7c [ 82336D4ABD8CA5F8E870CBFA47C0A5DA, 0B3DDC214AAD4BF68D0C8A74CB6E8627D8943FEB94ED0EA870938401A4B8D15C ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
11:28:55.0796 0x0d7c NVSvc - ok
11:28:55.0843 0x0d7c [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:28:55.0843 0x0d7c NwlnkFlt - ok
11:28:55.0875 0x0d7c [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:28:55.0875 0x0d7c NwlnkFwd - ok
11:28:55.0968 0x0d7c [ CA33832DF41AFB202EE7AEB05145922F, 9DD0089C2E13C7F81214C3B5A4A61276292052F9BBFEA7FCD0F6AA27815D5F95 ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
11:28:55.0984 0x0d7c ohci1394 - ok
11:28:56.0046 0x0d7c [ 1D98907D80461371437A7C898C58C8AE, 1BFEAD2AC3CCA5057F19368D8B2FE53641759772051F0927BE95FDE99B17A4A1 ] omci C:\WINDOWS\system32\DRIVERS\omci.sys
11:28:56.0109 0x0d7c omci - ok
11:28:56.0187 0x0d7c [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
 
11:28:56.0203 0x0d7c ose - ok
11:28:56.0281 0x0d7c [ AB2B07AC4AFD38F574D903EAF9E98A60, 9CB2DDB911407B9B8EA244F5A4C0AFEDCB38DDFBBC1AEAA423BDC8EE0E503729 ] OZSCR C:\WINDOWS\system32\DRIVERS\ozscr.sys
11:28:56.0296 0x0d7c OZSCR - ok
11:28:56.0328 0x0d7c [ C90018BAFDC7098619A4A95B046B30F3, 1826E46F237AD65BA189B83803A46A6C2B29089C1BA146106ADD9F2B04D4A89D ] P3 C:\WINDOWS\system32\DRIVERS\p3.sys
11:28:56.0343 0x0d7c P3 - ok
11:28:56.0375 0x0d7c [ 5575FAF8F97CE5E713D108C2A58D7C7C, 96D4595D19A78CCBE8B325A08780AC077AE5CC99642ACD72FB47AEAE8D344D3B ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
11:28:56.0390 0x0d7c Parport - ok
11:28:56.0406 0x0d7c [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
11:28:56.0421 0x0d7c PartMgr - ok
11:28:56.0453 0x0d7c [ 70E98B3FD8E963A6A46A2E6247E0BEA1, 6771313EC41B3B5BFD398F60706E40BE71617046880CC352DD110B001AFC22A1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
11:28:56.0453 0x0d7c ParVdm - ok
11:28:56.0484 0x0d7c [ A219903CCF74233761D92BEF471A07B1, D4E6C360A1D2FCA4D17C991B834D68BF20F5111DD06B1FAB8B22984804CEC269 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
11:28:56.0484 0x0d7c PCI - ok
11:28:56.0500 0x0d7c PCIDump - ok
11:28:56.0546 0x0d7c [ CCF5F451BB1A5A2A522A76E670000FF0, D63F7E5A39653EC9CCE94B7D84B2D3EBD4F54533BD65701020198724042C9257 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
11:28:56.0546 0x0d7c PCIIde - ok
11:28:56.0578 0x0d7c [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1, 0BA3DB21DC7C641C181E2635B5C9B73965FDCDCD3EBBBE48FCFEC1C8C987F617 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys
11:28:56.0593 0x0d7c Pcmcia - ok
11:28:56.0609 0x0d7c PDCOMP - ok
11:28:56.0609 0x0d7c PDFRAME - ok
11:28:56.0625 0x0d7c PDRELI - ok
11:28:56.0640 0x0d7c PDRFRAME - ok
11:28:56.0640 0x0d7c perc2 - ok
11:28:56.0656 0x0d7c perc2hib - ok
11:28:56.0718 0x0d7c [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] PlugPlay C:\WINDOWS\system32\services.exe
11:28:56.0734 0x0d7c PlugPlay - ok
11:28:56.0765 0x0d7c [ 901C43516504CBE582E4C4193E00876A, AB071D9287AD84B313440AB55D0EF01452D445C009A62E2703D42DF9D37986ED ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe
11:28:56.0765 0x0d7c Pml Driver HPZ12 - ok
11:28:56.0781 0x0d7c [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
11:28:56.0781 0x0d7c PolicyAgent - ok
11:28:56.0828 0x0d7c [ 622FCF264119F7DF127BE353F796B319, 6689D8F62F860178685496EF45520967AFAEFF94CFBCC64CF77074F21577E0A2 ] PopularScreensavers_7iService C:\PROGRA~1\POPULA~2\bar\1.bin\7ibarsvc.exe
11:28:56.0843 0x0d7c PopularScreensavers_7iService - ok
11:28:56.0875 0x0d7c [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:28:56.0875 0x0d7c PptpMiniport - ok
11:28:56.0890 0x0d7c [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
11:28:56.0906 0x0d7c ProtectedStorage - ok
11:28:56.0921 0x0d7c [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
11:28:56.0921 0x0d7c PSched - ok
11:28:56.0968 0x0d7c [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:28:56.0968 0x0d7c Ptilink - ok
11:28:57.0000 0x0d7c [ 6A3FBBBBA5F228B003EF64070F7B3FE4, D228C95EB3841F81271AB76343B4BEF156CCAF8C585E8F4AB2AA4F366ADE0C51 ] Ptserial C:\WINDOWS\system32\DRIVERS\ptserial.sys
11:28:57.0015 0x0d7c Ptserial - ok
11:28:57.0031 0x0d7c ql1080 - ok
11:28:57.0031 0x0d7c Ql10wnt - ok
11:28:57.0046 0x0d7c ql12160 - ok
11:28:57.0046 0x0d7c ql1240 - ok
11:28:57.0062 0x0d7c ql1280 - ok
11:28:57.0093 0x0d7c [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:28:57.0093 0x0d7c RasAcd - ok
11:28:57.0156 0x0d7c [ AD188BE7BDF94E8DF4CA0A55C00A5073, C7D76CB579FAEBCCC2873499441BACDD6BD6668ACF5ED7F31862656E96E2B20C ] RasAuto C:\WINDOWS\System32\rasauto.dll
11:28:57.0156 0x0d7c RasAuto - ok
11:28:57.0218 0x0d7c [ 0207D26DDF796A193CCD9F83047BB5FC, 13613036BCB869FBD7229A0FE25D324710308385D8C35E5D990A40E52BE040DF ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys
11:28:57.0218 0x0d7c Rasirda - ok
11:28:57.0250 0x0d7c [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:28:57.0250 0x0d7c Rasl2tp - ok
11:28:57.0312 0x0d7c [ 76A9A3CBEADD68CC57CDA5E1D7448235, 4AFD048C5D2306AB8DE46F3AA60AC0213333DDA3B09A9E91F7585DB6EB978EC8 ] RasMan C:\WINDOWS\System32\rasmans.dll
11:28:57.0328 0x0d7c RasMan - ok
11:28:57.0343 0x0d7c [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:28:57.0359 0x0d7c RasPppoe - ok
11:28:57.0375 0x0d7c [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
11:28:57.0375 0x0d7c Raspti - ok
11:28:57.0421 0x0d7c [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:28:57.0437 0x0d7c Rdbss - ok
11:28:57.0453 0x0d7c [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:28:57.0453 0x0d7c RDPCDD - ok
11:28:57.0500 0x0d7c [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
11:28:57.0531 0x0d7c rdpdr - ok
11:28:57.0593 0x0d7c [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
11:28:57.0609 0x0d7c RDPWD - ok
11:28:57.0656 0x0d7c [ 3C37BF86641BDA977C3BF8A840F3B7FA, AB9A6E54DBA3F4561CD4837372BECCE0D73943D02E3288F944333039375AC08C ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
11:28:57.0687 0x0d7c RDSessMgr - ok
11:28:57.0734 0x0d7c [ F828DD7E1419B6653894A8F97A0094C5, E6150E1F598BA4CFEDB8FF075BC0D576518C331B864388F1CAE8812EFF106ECF ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
11:28:57.0734 0x0d7c redbook - ok
11:28:57.0812 0x0d7c [ 7E699FF5F59B5D9DE5390E3C34C67CF5, 3FCF0442D80AB181FED4303E570378736AA1F8718C0B8B70F689A1E45200FFE4 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
11:28:57.0812 0x0d7c RemoteAccess - ok
11:28:57.0859 0x0d7c [ 5B19B557B0C188210A56A6B699D90B8F, 0FA880B81AE615206FD1738B83428AAA491D54B24168339DE6E87FDE8C6C14B0 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
11:28:57.0875 0x0d7c RemoteRegistry - ok
11:28:57.0937 0x0d7c [ 851C30DF2807FCFA21E4C681A7D6440E, C2269B8ED4E831664B83F8F3BE33E5A340206A9E07F89CDF6707EAD8F280FBE9 ] RFCOMM C:\WINDOWS\system32\DRIVERS\rfcomm.sys
11:28:57.0937 0x0d7c RFCOMM - ok
11:28:57.0968 0x0d7c [ AAED593F84AFA419BBAE8572AF87CF6A, CC0FFC5A69394C8830DC66320DA01A820BBF41AD7E57D0FC343561DC5EF9A360 ] RpcLocator C:\WINDOWS\system32\locator.exe
11:28:57.0984 0x0d7c RpcLocator - ok
11:28:58.0062 0x0d7c [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] RpcSs C:\WINDOWS\system32\rpcss.dll
11:28:58.0093 0x0d7c RpcSs - ok
11:28:58.0156 0x0d7c [ 471B3F9741D762ABE75E9DEEA4787E47, D9ADE42965EC22AEB4B2AD21D429C3C8232A60AA9853DEFDA7AED86A13FE8623 ] RSVP C:\WINDOWS\system32\rsvp.exe
11:28:58.0187 0x0d7c RSVP - ok
11:28:58.0296 0x0d7c [ EF64988C8E699E2481D1FD45BF472EF0, 216D89FC2556AE1115B353973DBD1E91A43F2D33AD62928349630CA7AFB14B6D ] RT61 C:\WINDOWS\system32\DRIVERS\RT61.sys
11:28:58.0343 0x0d7c RT61 - ok
11:28:58.0390 0x0d7c [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] SamSs C:\WINDOWS\system32\lsass.exe
11:28:58.0406 0x0d7c SamSs - ok
11:28:58.0437 0x0d7c [ 86D007E7A654B9A71D1D7D856B104353, 7B1DE53D637A5FC9619D5D07C48927AFEC89D959207F6F2E2F45DD054EEA04C7 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
11:28:58.0453 0x0d7c SCardSvr - ok
11:28:58.0500 0x0d7c [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA, 0B582F47BD70732BAC48B8B86E5D06CE7F299A20E8177F3F2E6F28217C3FB605 ] Schedule C:\WINDOWS\system32\schedsvc.dll
11:28:58.0531 0x0d7c Schedule - ok
11:28:58.0593 0x0d7c [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:28:58.0593 0x0d7c Secdrv - ok
11:28:58.0640 0x0d7c [ CBE612E2BB6A10E3563336191EDA1250, C331797DC3569F0E715766561DE2562F60B924378842246C35D2B1CF867E9D96 ] seclogon C:\WINDOWS\System32\seclogon.dll
11:28:58.0640 0x0d7c seclogon - ok
11:28:58.0671 0x0d7c [ 7FDD5D0684ECA8C1F68B4D99D124DCD0, 7105B026F966A992430F86C3698ABE15EC73E4772F1A3E362E29FD5247A5DCA6 ] SENS C:\WINDOWS\system32\sens.dll
11:28:58.0671 0x0d7c SENS - ok
11:28:58.0703 0x0d7c [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
11:28:58.0703 0x0d7c serenum - ok
11:28:58.0718 0x0d7c [ CCA207A8896D4C6A0C9CE29A4AE411A7, 5999B39242283CD803319AADCA171CCCC6E2A40FB2FAFA51B1D29F3FF2DD8D6C ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
11:28:58.0734 0x0d7c Serial - ok
11:28:58.0765 0x0d7c [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
11:28:58.0765 0x0d7c Sfloppy - ok
11:28:58.0843 0x0d7c [ 83F41D0D89645D7235C051AB1D9523AC, B681F33EEAA511D6A2DCB9FBAA407B739184C9FF6067C6B7E51F1FC37E9D4DD7 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
11:28:58.0890 0x0d7c SharedAccess - ok
11:28:58.0968 0x0d7c [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
11:28:58.0984 0x0d7c ShellHWDetection - ok
11:28:58.0984 0x0d7c Simbad - ok
11:28:59.0031 0x0d7c [ 707647A1AA0EDB6CBEF61B0C75C28ED3, 0FCACC13B3D0EFE026D447CDE5AA10F37986FB235975E3683F0DC2100D50611F ] SMCIRDA C:\WINDOWS\system32\DRIVERS\smcirda.sys
11:28:59.0046 0x0d7c SMCIRDA - ok
11:28:59.0062 0x0d7c Sparrow - ok
11:28:59.0109 0x0d7c [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
11:28:59.0109 0x0d7c splitter - ok
11:28:59.0156 0x0d7c [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
11:28:59.0171 0x0d7c Spooler - ok
11:28:59.0218 0x0d7c [ 76BB022C2FB6902FD5BDD4F78FC13A5D, 6031CB2344D7277FC703480EB43CF856A0F8F818EA98FF26A2CA532336CD2DFA ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
11:28:59.0234 0x0d7c sr - ok
11:28:59.0281 0x0d7c [ 3805DF0AC4296A34BA4BF93B346CC378, B57A14F1B7B0997E619DDD62B73157AA2399A9852166FB58139CBB358A88F6F3 ] srservice C:\WINDOWS\system32\srsvc.dll
11:28:59.0296 0x0d7c srservice - ok
11:28:59.0375 0x0d7c [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
11:28:59.0406 0x0d7c Srv - ok
11:28:59.0453 0x0d7c [ 0A5679B3714EDAB99E357057EE88FCA6, 01E1A101FFF48402C77E385A78FEF27876E04533B60EB1C18558A737E57E5FA8 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
11:28:59.0453 0x0d7c SSDPSRV - ok
11:28:59.0562 0x0d7c [ 305CC42945A713347F978D78566113F3, 92D95E1DCCAA5E31AADB061EB7B531337975974961211BFB7C542FB799348034 ] STAC97 C:\WINDOWS\system32\drivers\stac97.sys
11:28:59.0593 0x0d7c STAC97 - ok
11:28:59.0656 0x0d7c [ 8BAD69CBAC032D4BBACFCE0306174C30, 2AA0DA710FCBFF38FE8DA91EE02E7A4503269347E61F8D3246FCA3384BBA2305 ] stisvc C:\WINDOWS\system32\wiaservc.dll
11:28:59.0687 0x0d7c stisvc - ok
11:28:59.0734 0x0d7c [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
11:28:59.0734 0x0d7c swenum - ok
11:28:59.0765 0x0d7c [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
11:28:59.0781 0x0d7c swmidi - ok
11:28:59.0796 0x0d7c SwPrv - ok
11:28:59.0812 0x0d7c symc810 - ok
11:28:59.0828 0x0d7c symc8xx - ok
11:28:59.0843 0x0d7c sym_hi - ok
11:28:59.0843 0x0d7c sym_u3 - ok
11:28:59.0921 0x0d7c [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
11:28:59.0937 0x0d7c sysaudio - ok
11:29:00.0000 0x0d7c [ C7ABBC59B43274B1109DF6B24D617051, 4384CA0AA6CE9B603CF7DB775A3C721E46715D5B120B94FB57DEADAADE18535B ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
11:29:00.0015 0x0d7c SysmonLog - ok
11:29:00.0062 0x0d7c [ 3CB78C17BB664637787C9A1C98F79C38, F35C31F6B7F366CB949D1044B357C76DEC9170441C5E559802794F62B72FD255 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
11:29:00.0093 0x0d7c TapiSrv - ok
11:29:00.0187 0x0d7c [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:29:00.0250 0x0d7c Tcpip - ok
11:29:00.0312 0x0d7c [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
11:29:00.0312 0x0d7c TDPIPE - ok
11:29:00.0343 0x0d7c [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
11:29:00.0343 0x0d7c TDTCP - ok
11:29:00.0359 0x0d7c [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
11:29:00.0375 0x0d7c TermDD - ok
11:29:00.0437 0x0d7c [ FF3477C03BE7201C294C35F684B3479F, D6246521539BA4ACD022D26983182F5E323D2EF1EA7C54265A248C43A1CE5202 ] TermService C:\WINDOWS\System32\termsrv.dll
11:29:00.0484 0x0d7c TermService - ok
11:29:00.0531 0x0d7c [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] Themes C:\WINDOWS\System32\shsvcs.dll
11:29:00.0546 0x0d7c Themes - ok
11:29:00.0609 0x0d7c [ DB7205804759FF62C34E3EFD8A4CC76A, 13A4248F528CE98ACA66898E56822E4FC49B11F491FF1F61A687BA601BF0A802 ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
11:29:00.0625 0x0d7c TlntSvr - ok
11:29:00.0640 0x0d7c TosIde - ok
11:29:00.0734 0x0d7c [ 55BCA12F7F523D35CA3CB833C725F54E, 849FB1AE31B143B14B298BBC0D91230693D41DEB95F46516878F53A7F4186C38 ] TrkWks C:\WINDOWS\system32\trkwks.dll
11:29:00.0750 0x0d7c TrkWks - ok
11:29:00.0812 0x0d7c [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
11:29:00.0812 0x0d7c Udfs - ok
11:29:00.0828 0x0d7c UIUSys - ok
11:29:00.0843 0x0d7c ultra - ok
11:29:00.0953 0x0d7c [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
11:29:01.0000 0x0d7c Update - ok
11:29:01.0078 0x0d7c [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91, 7746916DB48E3F5B243B63C066596AD9037A494BF1AD935946DD04AC85D983DF ] upnphost C:\WINDOWS\System32\upnphost.dll
11:29:01.0093 0x0d7c upnphost - ok
11:29:01.0125 0x0d7c [ 05365FB38FCA1E98F7A566AAAF5D1815, 16843048CEEC3DAA3B953A12FF1EE339E86783A08F2A56DA7F94AD9F9717D77D ] UPS C:\WINDOWS\System32\ups.exe
11:29:01.0125 0x0d7c UPS - ok
11:29:01.0203 0x0d7c [ 1DF89C499BF45D878B87EBD4421D462D, 37FE229C128DA2C3380944EDFA8E6117CB4B36D99EEFB2AEB1DD4E0890B49A17 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
11:29:01.0296 0x0d7c USBAAPL - ok
11:29:01.0343 0x0d7c [ 1B611611C28D2DF25BC057D79C6F13FC, B0D86F63E44B40413BBAE6402CC088046CFAE082D41BBC2ED5A916293356B846 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:29:01.0343 0x0d7c usbccgp - ok
11:29:01.0390 0x0d7c [ 4BAC8DF07F1D8434FC640E677A62204E, 76C1351AF6752224BF59DEEE0F8665FE699F3DFD679F5BCD01C7D9383E6402A4 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:29:01.0390 0x0d7c usbehci - ok
11:29:01.0421 0x0d7c [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:29:01.0437 0x0d7c usbhub - ok
11:29:01.0500 0x0d7c [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:29:01.0500 0x0d7c usbprint - ok
11:29:01.0562 0x0d7c [ F8EDE2B6928970DCE3D5614C27D9E7F6, 6E5EBBC8B70C1D593634DAF0C190DEADFDA18C3CBC8F552A76F156F3869EF05B ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:29:01.0562 0x0d7c usbscan - ok
11:29:01.0578 0x0d7c [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:29:01.0593 0x0d7c USBSTOR - ok
11:29:01.0640 0x0d7c [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
11:29:01.0640 0x0d7c usbuhci - ok
11:29:01.0656 0x0d7c [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
11:29:01.0656 0x0d7c VgaSave - ok
11:29:01.0671 0x0d7c ViaIde - ok
11:29:01.0765 0x0d7c [ 09C2FCD4E379E6AB804A58CAA2A3508B, C88052ED4F81032610A3715134D51DCDE58235D356AA30881D2451DF9CC8DBEA ] Vmodem C:\WINDOWS\system32\DRIVERS\vmodem.sys
11:29:01.0843 0x0d7c Vmodem - ok
11:29:01.0875 0x0d7c [ 4C8FCB5CC53AAB716D810740FE59D025, 010EAC43DBED700B73E4FC908FAAF9F6A0168EBBD5D86751E49BC33AAA18BFA4 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
11:29:01.0875 0x0d7c VolSnap - ok
11:29:01.0984 0x0d7c [ 081BC31EDDA73D40DEFD347E580F9144, D5867FEEAD5A71BA0A7B73F5B748427BA69FFF559FFF79BBC01E3777096A0EBA ] Vpctcom C:\WINDOWS\system32\DRIVERS\vpctcom.sys
11:29:02.0031 0x0d7c Vpctcom - ok
11:29:02.0109 0x0d7c [ 7A9DB3A67C333BF0BD42E42B8596854B, D31A9A3B1AAAB373EDD73B674102395212FCB616F829E938B7B2B7BE7D4752C5 ] VSS C:\WINDOWS\System32\vssvc.exe
11:29:02.0156 0x0d7c VSS - ok
11:29:02.0218 0x0d7c [ DB18922F81E90D95E69F45AB8E9FC5C1, 2131A4F608D717D2B657A83809F2B97B4213839AF59625481F13B8CA573789D7 ] Vvoice C:\WINDOWS\system32\DRIVERS\vvoice.sys
11:29:02.0218 0x0d7c Vvoice - ok
11:29:02.0296 0x0d7c [ 54AF4B1D5459500EF0937F6D33B1914F, FA1876888BCB9C72A92369DBED4FF1A8666784523FB41E618FA0919490FCDDB9 ] W32Time C:\WINDOWS\system32\w32time.dll
11:29:02.0312 0x0d7c W32Time - ok
11:29:02.0406 0x0d7c [ 2D78810229A924B8DA2C7656C389E691, 3796C2CD24CF9EB35C80CAEE136971B288026B03340D9CFCDAE9ECA1CCBABFE2 ] W8335PCI C:\WINDOWS\system32\DRIVERS\Mrvw123.sys
11:29:02.0578 0x0d7c W8335PCI - ok
11:29:02.0625 0x0d7c [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:29:02.0625 0x0d7c Wanarp - ok
11:29:02.0640 0x0d7c WDICA - ok
11:29:02.0687 0x0d7c [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
11:29:02.0687 0x0d7c wdmaud - ok
11:29:02.0718 0x0d7c [ 77A354E28153AD2D5E120A5A8687BC06, 8B2D37A4443501C0A8E70BC2079BE27F0A36FD07B561E6F68B40A72EABBC2DFE ] WebClient C:\WINDOWS\System32\webclnt.dll
11:29:02.0750 0x0d7c WebClient - ok
11:29:02.0890 0x0d7c [ 0C5B9CF1BDF998750D9C5EEB5F8C55AC, 897226F3CF628401B71F38228CB429506E5DD1C0C24CF8AC9C969DC594AF9F7D ] winachsf C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
11:29:03.0093 0x0d7c winachsf - ok
11:29:03.0312 0x0d7c [ 2D0E4ED081963804CCC196A0929275B5, E1D75C7D7233D81DFDE13160B0C80138DF8B35230D04FB79B367A52FACF69BF8 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
11:29:03.0328 0x0d7c winmgmt - ok
11:29:03.0359 0x0d7c wltrysvc - ok
11:29:03.0421 0x0d7c [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
11:29:03.0421 0x0d7c WmdmPmSN - ok
11:29:03.0546 0x0d7c [ E76F8807070ED04E7408A86D6D3A6137, BFCF5361B7335760A7AE4B6958DE516A27AC60AA09135A46F0B49F588FAFE3A0 ] Wmi C:\WINDOWS\System32\advapi32.dll
11:29:03.0625 0x0d7c Wmi - ok
11:29:03.0687 0x0d7c [ E0673F1106E62A68D2257E376079F821, 12992F18C9653050B10DC61D12988067933FCFDF02123D3A7EF5DE607A785DDC ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
11:29:03.0718 0x0d7c WmiApSrv - ok
11:29:03.0859 0x0d7c [ F74E3D9A7FA9556C3BBB14D4E5E63D3B, C71FAAC752F6D58BF8556661252DBF8C5DDD090CAE002A2C7E09C9A014526066 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
11:29:03.0984 0x0d7c WMPNetworkSvc - ok
11:29:04.0078 0x0d7c [ 7C278E6408D1DCE642230C0585A854D5, DA46079A04F6E8E3441E4AE454AEAC02B3E935DE29CE7F6D4476F57867FCC12A ] wscsvc C:\WINDOWS\system32\wscsvc.dll
11:29:04.0093 0x0d7c wscsvc - ok
11:29:04.0125 0x0d7c [ 35321FB577CDC98CE3EB3A3EB9E4610A, C9A6F5CF282D8FCB3CDFCC4B306013480E78E1B664E1A60A4E27B161F9FFD4CD ] wuauserv C:\WINDOWS\system32\wuauserv.dll
11:29:04.0140 0x0d7c wuauserv - ok
11:29:04.0187 0x0d7c [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:29:04.0203 0x0d7c WudfPf - ok
11:29:04.0250 0x0d7c [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:29:04.0265 0x0d7c WudfRd - ok
11:29:04.0312 0x0d7c [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
11:29:04.0328 0x0d7c WudfSvc - ok
11:29:04.0437 0x0d7c [ 81DC3F549F44B1C1FFF022DEC9ECF30B, 3D14BFEA539F9CEB16555BD56C5E3C7C8F6692FC62C2789F8AAEA1C042E63940 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
11:29:04.0500 0x0d7c WZCSVC - ok
11:29:04.0562 0x0d7c [ 295D21F14C335B53CB8154E5B1F892B9, 9418477C2E3EA93E93D931A4EDD4500DA568FAD6040204B5201D1080203B0BBC ] xmlprov C:\WINDOWS\System32\xmlprov.dll
11:29:04.0593 0x0d7c xmlprov - ok
11:29:04.0609 0x0d7c _VOIDymxgobuqxe - ok
11:29:04.0718 0x0d7c ================ Scan global ===============================
11:29:04.0765 0x0d7c [ 42F1F4C0AFB08410E5F02D4B13EBB623, 924C30587C51C0D1E1F47991969AF492A644552E15F2480EA991DCB74A3E68D5 ] C:\WINDOWS\system32\basesrv.dll
11:29:04.0812 0x0d7c [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
11:29:04.0859 0x0d7c [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
11:29:04.0890 0x0d7c [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] C:\WINDOWS\system32\services.exe
11:29:04.0890 0x0d7c [ Global ] - ok
11:29:04.0906 0x0d7c ================ Scan MBR ==================================
11:29:04.0953 0x0d7c [ D10F1090C2A1DA838DEE05AA4CA56FBD ] \Device\Harddisk0\DR0
11:29:05.0171 0x0d7c \Device\Harddisk0\DR0 - ok
11:29:05.0171 0x0d7c ================ Scan VBR ==================================
11:29:05.0171 0x0d7c [ 797B559E02A8DDE942BC927A3444C1FF ] \Device\Harddisk0\DR0\Partition1
11:29:05.0171 0x0d7c \Device\Harddisk0\DR0\Partition1 - ok
11:29:05.0171 0x0d7c Waiting for KSN requests completion. In queue: 202
11:29:06.0171 0x0d7c Waiting for KSN requests completion. In queue: 202
11:29:07.0171 0x0d7c Waiting for KSN requests completion. In queue: 202
11:29:08.0281 0x0d7c AV detected via SS1: Microsoft Security Essentials, 3.0.8402.0, enabled, updated
11:29:08.0281 0x0d7c AV detected via SS1: Microsoft Security Essentials, 2.1.6805.0, disabled, updated
11:29:08.0281 0x0d7c Win FW state via NFM: enabled
11:29:10.0796 0x0d7c ============================================================
11:29:10.0796 0x0d7c Scan finished
11:29:10.0828 0x0d7c ============================================================
11:29:10.0843 0x09ac Detected object count: 0
11:29:10.0843 0x09ac Actual detected object count: 0
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please copy and paste it to your reply.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-12-2013 01
Ran by HOME (administrator) on DELL-D610 on 04-12-2013 12:17:09
Running from C:\Documents and Settings\HOME\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(Hewlett-Packard Company) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ATIPTA] - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-01-11] (ATI Technologies, Inc.)
HKLM\...\Run: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2006-09-15] (Intel Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\WINDOWS\system32\WLTRAY.EXE [1392640 2006-11-01] (Dell Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)
HKLM\...\Run: [HP Component Manager] - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [36272 2010-04-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-15] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
MountPoints2: {34e2d166-eaa6-11df-b2e1-000b7d25208b} - F:\MI.exe
HKU\Administrator\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
ShortcutTarget: HP Image Zone Fast Start.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
BootExecute: autocheck autochk * lsdelete
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/
URLSearchHook: HKCU - (No Name) - {0953a3a2-9223-4990-a1c9-efb4d4686ef2} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7iSrcAs.dll (MindSpark)
URLSearchHook: HKCU - (No Name) - {bd8006aa-6e85-4b36-bb42-7f97053d5b70} - No File
SearchScopes: HKLM - DefaultScope {EAB87B7A-B2AC-4345-9929-DD6B830520EA} URL =
SearchScopes: HKLM - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.tb.ask.com/search/GGm...&n=77fd2d5a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {2166D31A-2CB5-47B8-BCA0-D20BA478BD31} URL = http://websearch.ask.com/redirect?c...pn_sauid=5A3E80CF-2B71-4ACF-ADB4-27B8FC90B23C
SearchScopes: HKCU - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.tb.ask.com/search/GGm...&n=77fd2d5a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {BA2C2F9E-D4DD-43A6-B87E-1F2983FC7977} URL = http://tuvaro.com/ws/?source=6912e0...00000000000000b7d25208b&q={searchTerms}&r=894
SearchScopes: HKCU - {EAB87B7A-B2AC-4345-9929-DD6B830520EA} URL = http://search.conduit.com/ResultsEx...4&ctid=CT3299872&CUI=UN13645246185853184&UM=2
BHO: Toolbar BHO - {0709f2cc-d1e6-4b43-9efc-1c0701cb173d} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Search Assistant BHO - {3a6625a2-591b-4e83-ac3f-8c25eea30ac0} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7iSrcAs.dll (MindSpark)
BHO: tuvaro Helper Object - {5CB02877-EFBC-4317-B608-9E24B11BAB40} - C:\Program Files\tuvaro\tuvaro\1.8.22.1\bh\tuvaro.dll No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Tuvaro Toolbar - {6F001652-AF51-45C6-B029-86E0265A1851} - C:\Program Files\tuvaro\tuvaro\1.8.22.1\tuvaroTlbr.dll No File
Toolbar: HKLM - PopularScreensavers - {f339a07f-9578-412d-85e0-b8a80277151a} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - PopularScreensavers - {F339A07F-9578-412D-85E0-B8A80277151A} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
Toolbar: HKCU - No Name - {BD8006AA-6E85-4B36-BB42-7F97053D5B70} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252605597546
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137095143638
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
ShellExecuteHooks: URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll [8462848 2012-06-08] (Microsoft Corporation)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Ask Web Search
FF Homepage: hxxp://home.tb.ask.com/index.jhtml?ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&p2=^ZR^xpt366^YYA^us&si=installldownload
FF Keyword.URL: hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&ind=2013120306&p2=^ZR^xpt366^YYA^us&si=installldownload&searchfor=
FF DefaultSearchEngine: Google
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @popularscreensavers.com/Plugin - C:\Program Files\PopularScreensavers\NPp5Stub.dll (popularscreensavers.com)
FF Plugin: @PopularScreensavers_7i.com/Plugin - C:\Program Files\PopularScreensavers_7i\bar\1.bin\NP7iStub.dll (MindSpark)
FF SearchPlugin: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\ask-web-search.xml
FF SearchPlugin: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\answers.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
FF Extension: weDownload Manager - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com
FF Extension: PopularScreensavers - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\7iffxtbr@PopularScreensavers_7i.com
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Google Toolbar for Firefox - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: Google Settings - C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [7iffxtbr@PopularScreensavers_7i.com] - C:\Program Files\PopularScreensavers_7i\bar\1.bin
FF Extension: PopularScreensavers - C:\Program Files\PopularScreensavers_7i\bar\1.bin
========================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
S2 PopularScreensavers_7iService; C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibarsvc.exe [42504 2013-08-09] (COMPANYVERS_NAME)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [1253376 2006-11-01] (Dell Inc.)
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe" [x]
==================== Drivers (Whitelisted) ====================
S3 ac97intc; C:\Windows\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation)
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [407360 2004-12-22] (D-Link )
S3 AR5513; C:\Windows\System32\DRIVERS\ar5513.sys [358464 2005-09-12] (Atheros Communications, Inc.)
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [604928 2006-11-03] (Broadcom Corporation)
S3 EL90XBC; C:\Windows\System32\DRIVERS\el90xbc5.sys [66591 2001-08-17] (3Com Corporation)
R3 GTIPCI21; C:\Windows\System32\DRIVERS\gtipci21.sys [88192 2006-04-06] (Texas Instruments)
S3 GWRCB_A00; C:\Windows\System32\DRIVERS\GWRCBA00.sys [418368 2004-03-15] (Ashton Digital Corp.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-06-21] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-06-21] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-06-21] (HP)
R3 HSFHWICH; C:\Windows\System32\DRIVERS\HSFHWICH.sys [208384 2005-05-03] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.SYS [1033728 2005-05-03] (Conexant Systems, Inc.)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
S3 OZSCR; C:\Windows\System32\DRIVERS\ozscr.sys [92550 2005-04-21] (O2Micro)
S1 P3; C:\Windows\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation)
S3 Ptserial; C:\Windows\System32\DRIVERS\ptserial.sys [135292 2003-02-24] (PCTEL, INC.)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RT61; C:\Windows\System32\DRIVERS\RT61.sys [483968 2007-07-28] (Ralink Technology, Corp.)
R3 SMCIRDA; C:\Windows\System32\DRIVERS\smcirda.sys [35913 2001-08-17] (SMC)
R3 STAC97; C:\Windows\System32\drivers\stac97.sys [273168 2005-03-10] (SigmaTel, Inc.)
R0 Vmodem; C:\Windows\System32\DRIVERS\vmodem.sys [690973 2003-05-30] (PCTEL, INC.)
R0 Vpctcom; C:\Windows\System32\DRIVERS\vpctcom.sys [477403 2003-05-30] (PCtel, Inc.)
R0 Vvoice; C:\Windows\System32\DRIVERS\vvoice.sys [66111 2003-05-28] (PCtel, Inc.)
S3 W8335PCI; C:\Windows\System32\DRIVERS\Mrvw123.sys [282624 2005-12-29] (Marvell Semiconductor, Inc)
S3 atimtag; System32\DRIVERS\atimtag.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 UIUSys; system32\drivers\UIUSys.sys [x]
U1 WS2IFSL;
U1 _VOIDymxgobuqxe; \systemroot\_VOIDymxgobuqxe\_VOIDd.sys [x]
==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========
2013-12-04 12:17 - 2013-12-04 12:17 - 00016314 _____ C:\Documents and Settings\HOME\Desktop\FRST.txt
2013-12-04 12:17 - 2013-12-04 12:17 - 00000000 ____D C:\FRST
2013-12-04 12:16 - 2013-12-04 12:16 - 01092683 _____ (Farbar) C:\Documents and Settings\HOME\Desktop\FRST.exe
2013-12-04 11:27 - 2013-12-04 11:27 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\tdsskiller
2013-12-04 03:41 - 2013-12-04 03:41 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-04 03:32 - 2013-12-04 03:32 - 00009474 _____ C:\WINDOWS\KB2900986.log
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-12-04 03:31 - 2013-12-04 03:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-12-04 03:30 - 2013-12-04 03:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-12-04 03:28 - 2013-12-04 03:30 - 00011778 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-04 03:26 - 2013-12-04 03:26 - 00688992 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\dds.com
2013-12-04 02:14 - 2013-12-04 12:14 - 00000250 _____ C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2013-12-04 01:55 - 2013-12-04 03:32 - 00018881 _____ C:\WINDOWS\KB2868626.log
2013-12-04 01:55 - 2013-12-04 03:31 - 00017890 _____ C:\WINDOWS\KB2862152.log
2013-12-04 01:54 - 2013-12-04 03:30 - 00017469 _____ C:\WINDOWS\KB2876331.log
2013-12-03 13:14 - 2013-12-04 11:09 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-03 13:14 - 2013-12-03 13:14 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
==================== One Month Modified Files and Folders =======
2013-12-04 12:18 - 2006-01-12 05:01 - 00526818 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-04 12:17 - 2013-12-04 12:17 - 00016314 _____ C:\Documents and Settings\HOME\Desktop\FRST.txt
2013-12-04 12:17 - 2013-12-04 12:17 - 00000000 ____D C:\FRST
2013-12-04 12:16 - 2013-12-04 12:16 - 01092683 _____ (Farbar) C:\Documents and Settings\HOME\Desktop\FRST.exe
2013-12-04 12:14 - 2013-12-04 02:14 - 00000250 _____ C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2013-12-04 12:14 - 2010-05-30 05:33 - 01703359 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-04 12:13 - 2010-05-30 05:42 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-04 12:13 - 2010-05-30 05:42 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-12-04 12:13 - 2006-01-12 10:18 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-04 12:13 - 2002-09-03 14:04 - 00002228 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-04 12:03 - 2010-05-30 05:42 - 00032148 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-04 12:03 - 2006-01-12 10:29 - 00000278 ___SH C:\Documents and Settings\HOME\ntuser.ini
2013-12-04 12:03 - 2006-01-12 10:29 - 00000000 ____D C:\Documents and Settings\HOME
2013-12-04 11:27 - 2013-12-04 11:27 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\tdsskiller
2013-12-04 11:09 - 2013-12-03 13:14 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-04 09:13 - 2013-03-11 15:11 - 00000424 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job
2013-12-04 09:10 - 2010-05-30 09:34 - 00061485 _____ C:\WINDOWS\setupapi.log
2013-12-04 09:10 - 2009-11-13 21:06 - 00000420 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{3AC8987B-6FA2-4503-AB40-BD9C6C5DDA8F}.job
2013-12-04 04:42 - 2013-08-10 08:58 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2719985$
2013-12-04 04:41 - 2013-09-19 17:11 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Conduit
2013-12-04 03:41 - 2013-12-04 03:41 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-12-04 03:32 - 2013-12-04 03:32 - 00009474 _____ C:\WINDOWS\KB2900986.log
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-12-04 03:32 - 2013-12-04 01:55 - 00018881 _____ C:\WINDOWS\KB2868626.log
2013-12-04 03:32 - 2010-05-30 09:53 - 00070588 _____ C:\WINDOWS\updspapi.log
2013-12-04 03:32 - 2010-05-30 09:52 - 01049850 _____ C:\WINDOWS\iis6.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00973804 _____ C:\WINDOWS\FaxSetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00465244 _____ C:\WINDOWS\ocgen.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00444510 _____ C:\WINDOWS\tsoc.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00324776 _____ C:\WINDOWS\comsetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00298250 _____ C:\WINDOWS\msmqinst.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00196658 _____ C:\WINDOWS\ntdtcsetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00170530 _____ C:\WINDOWS\netfxocm.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00066916 _____ C:\WINDOWS\MedCtrOC.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00053871 _____ C:\WINDOWS\ocmsn.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00049099 _____ C:\WINDOWS\tabletoc.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00048750 _____ C:\WINDOWS\msgsocm.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00001374 _____ C:\WINDOWS\imsins.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-12-04 03:31 - 2013-12-04 03:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-12-04 03:31 - 2013-12-04 01:55 - 00017890 _____ C:\WINDOWS\KB2862152.log
2013-12-04 03:30 - 2013-12-04 03:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-12-04 03:30 - 2013-12-04 03:28 - 00011778 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-04 03:30 - 2013-12-04 01:54 - 00017469 _____ C:\WINDOWS\KB2876331.log
2013-12-04 03:26 - 2013-12-04 03:26 - 00688992 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\dds.com
2013-12-04 02:17 - 2013-08-12 06:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-04 02:11 - 2006-01-12 14:14 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-12-03 11:36 - 2008-08-20 10:25 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\OpenOffice.org2
2013-12-03 11:19 - 2013-08-09 20:36 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Systweak
2013-12-03 11:12 - 2009-09-10 10:35 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-12-03 10:56 - 2013-08-10 07:44 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Conduit
2013-12-03 10:53 - 2012-07-03 16:42 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Unity
2013-12-03 10:29 - 2006-01-13 10:07 - 00000000 ____D C:\Program Files\Google
2013-12-03 10:21 - 2007-08-13 10:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Google
2013-12-03 10:21 - 2006-01-13 09:45 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Google
2013-12-03 06:52 - 2009-09-11 09:24 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-03 06:41 - 2010-05-30 09:52 - 00000120 _____ C:\WINDOWS\setupact.log
2013-12-03 06:09 - 2013-08-09 20:33 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\PopularScreensavers_7i
2013-12-03 06:08 - 2006-01-13 08:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-03 05:46 - 2009-09-23 07:20 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-03 05:40 - 2009-09-10 12:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-03 05:40 - 2006-01-12 04:59 - 00230392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-19 04:21 - 2010-05-31 02:55 - 00230048 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Documents and Settings\HOME\Local Settings\Temp\ApnStub.exe
C:\Documents and Settings\HOME\Local Settings\Temp\BackupSetup.exe
C:\Documents and Settings\HOME\Local Settings\Temp\contentDATs.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jna985496082466458090.dll
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u20-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u17-windows-i586-iftw.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\HOME\Local Settings\Temp\mssinstaller.exe
C:\Documents and Settings\HOME\Local Settings\Temp\nsmFA.tmp.tbBegi.dll
C:\Documents and Settings\HOME\Local Settings\Temp\nsqA0.tmp.tbWise.dll
C:\Documents and Settings\HOME\Local Settings\Temp\oi_{0377526B-6C42-4D38-BA65-F20FFAD9F0F9}.exe
C:\Documents and Settings\HOME\Local Settings\Temp\SecurityScan_Release.exe
C:\Documents and Settings\HOME\Local Settings\Temp\setup.exe
C:\Documents and Settings\HOME\Local Settings\Temp\SSUPDATE.EXE
C:\Documents and Settings\HOME\Local Settings\Temp\tbIns2.dll
C:\Documents and Settings\HOME\Local Settings\Temp\uninst.exe
C:\Documents and Settings\HOME\Local Settings\Temp\UNINSTALL.exe
C:\Documents and Settings\HOME\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\HOME\Local Settings\Temp\VSUSetup.exe

==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 04-12-2013 01
Ran by HOME at 2013-12-04 12:18:46
Running from C:\Documents and Settings\HOME\Desktop
Boot Mode: Normal
==========================================================

==================== Security Center ========================
AV: Microsoft Security Essentials (Disabled - Up to date) {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials (Disabled - Up to date) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
==================== Installed Programs ======================
1310 (Version: 43.0.217.000)
1310_Help (Version: 43.0.217.000)
1310Tour (Version: 43.0.217.000)
1310Trb (Version: 43.0.217.000)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.152)
Adobe Reader 9.3.2 (Version: 9.3.2)
AiO_Scan (Version: 43.0.217.000)
AiOSoftware (Version: 43.0.217.000)
Apple Application Support (Version: 1.5.0)
ArcSoft MediaImpression for Kodak (Version: 1.2.24.380)
ASL_Study_Guide
ATI - Software Uninstall Utility (Version: 6.14.10.1010)
ATI Control Panel (Version: 6.14.10.5125)
ATI Display Driver (Version: 8.063.2.1.1-050111a-020427C-Dell)
Bonjour (Version: 2.0.4.0)
Broadcom Gigabit Integrated Controller (Version: 9.02.06)
BufferChm (Version: 43.1.5.000)
C-Major Audio (Version: 42xx)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Conexant D110 MDC V.92 Modem
Copy (Version: 43.1.5.000)
CreativeProjects (Version: 43.1.5.000)
CreativeProjectsTemplates (Version: 43.1.5.000)
CueTour (Version: 43.1.5.000)
Dell Wireless WLAN Card (Version: 4.100.15.8)
Destinations (Version: 43.1.5.000)
Director (Version: 43.1.5.000)
DocProc (Version: 4.0.0.0)
DocumentViewer (Version: 43.0.217.000)
Fax (Version: 43.0.217.000)
GalleryPlayer Images (Version: 1.0)
HP Diagnostic Assistant (Version: 1.0.1.0)
HP Image Zone 4.2 (Version: 4.2)
HP PSC & OfficeJet 4.2
HP Software Update (Version: 2.0.39.20040212)
HP Unload DLL Patch (Version: 1.00.0000)
HPSystemDiagnostics (Version: 1.5.0.0)
InstantShare (Version: 4.0.0.40)
Intel(R) Graphics Media Accelerator Driver for Mobile (Version: 6.14.10.4693)
InterVideo WinDVD
Java 7 Update 25 (Version: 7.0.250)
Java Auto Updater (Version: 2.1.9.5)
Java(TM) 6 Update 7 (Version: 1.6.0.70)
Malwarebytes Anti-Malware version 1.75.0.1300 (Version: 1.75.0.1300)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2572067)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Antimalware (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft Security Client (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 2.1.1116.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Mozilla Firefox (3.5.7) (Version: 3.5.7 (en-US))
Nero 6 Ultra Edition
NVIDIA Windows 2000/XP Display Drivers
O2Micro Smartcard Driver (Version: 2.26.0000)
OGA Notifier 2.0.0048.0 (Version: 2.0.0048.0)
OpenOffice.org 2.4 (Version: 2.4.9310)
Overland (Version: 2.1.5)
PCTEL 2304WT V.9x MDC Modem Drivers
PhotoGallery (Version: 43.1.5.000)
PopularScreensavers Firefox Toolbar
PopularScreensavers Internet Explorer Toolbar
PrintScreen (Version: 43.1.5.000)
ProductContext (Version: 43.0.217.000)
QFolder (Version: 1.00.0000)
QuickProjects (Version: 43.1.5.000)
QuickTime (Version: 7.69.80.9)
Readme (Version: 43.0.217.000)
Scan (Version: 4.1.0.0)
SkinsHP1 (Version: 43.1.5.000)
Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 2.00.0000)
TIPCI (Version: 2.00.0000)
TrayApp (Version: 43.1.5.000)
Unload (Version: 4.0.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows Internet Explorer 8 (KB973874) (Version: 1)
Update for Windows Internet Explorer 8 (KB976662) (Version: 1)
Update for Windows Internet Explorer 8 (KB976749) (Version: 1)
Update for Windows Internet Explorer 8 (KB980182) (Version: 1)
Update for Windows XP (KB2141007) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676-v2) (Version: 2)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB2863058) (Version: 1)
Update for Windows XP (KB951072-v2) (Version: 2)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
WebFldrs XP (Version: 9.50.6513)
WebReg (Version: 43.1.5.000)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Genuine Advantage v1.3.0254.0 (Version: 1.3.0254.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Installer Clean Up (Version: 3.00.00.0000)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3 (Version: 20080414.031525)
Yahoo! Detect
==================== Restore Points =========================
03-12-2013 11:45:59 Software Distribution Service 3.0
03-12-2013 12:19:40 Revo Uninstaller's restore point - Ask Toolbar
03-12-2013 12:19:59 Removed Ask Toolbar.
03-12-2013 12:22:55 Revo Uninstaller's restore point - AVG SafeGuard toolbar
03-12-2013 12:24:33 Revo Uninstaller's restore point - SUPERAntiSpyware
03-12-2013 12:25:45 Revo Uninstaller's restore point - Safari
03-12-2013 12:26:35 Removed Safari
03-12-2013 12:30:05 Revo Uninstaller's restore point - Tuvaro toolbar
03-12-2013 12:31:13 Revo Uninstaller's restore point - Google Toolbar for Internet Explorer
03-12-2013 12:32:29 Revo Uninstaller's restore point - Google Updater
03-12-2013 12:34:18 Revo Uninstaller's restore point - MobileMe Control Panel
03-12-2013 12:34:38 Removed MobileMe Control Panel
03-12-2013 12:35:31 Revo Uninstaller's restore point - MobileMe Control Panel
03-12-2013 12:35:42 Revo Uninstaller's restore point - MobileMe Control Panel
03-12-2013 13:22:21 Revo Uninstaller's restore point - MyPC Backup
03-12-2013 13:25:48 Revo Uninstaller's restore point - CCleaner
03-12-2013 13:26:56 Revo Uninstaller's restore point - RegClean Pro
03-12-2013 16:17:45 Revo Uninstaller's restore point - PitchPerfect Musical Instrument Tuner
03-12-2013 16:21:08 Revo Uninstaller's restore point - Google Photos Screensaver
03-12-2013 16:21:23 Removed Google Photos Screensaver
03-12-2013 16:22:27 Revo Uninstaller's restore point - Google Desktop
03-12-2013 16:24:53 Revo Uninstaller's restore point - TempoPerfect
03-12-2013 16:26:09 Revo Uninstaller's restore point - WavePad Sound Editor
03-12-2013 16:35:04 Revo Uninstaller's restore point - iTunes
03-12-2013 16:38:11 Removed iTunes
03-12-2013 16:50:46 Revo Uninstaller's restore point - weDownload Manager
03-12-2013 16:52:34 Revo Uninstaller's restore point - Unity Web Player
03-12-2013 16:53:43 Revo Uninstaller's restore point - C-Major Audio
03-12-2013 16:54:13 Revo Uninstaller's restore point - Search Protect by conduit
03-12-2013 16:55:42 Revo Uninstaller's restore point - Installl Converter Toolbar for IE
03-12-2013 16:57:46 Revo Uninstaller's restore point - Apple Software Update
03-12-2013 16:58:01 Removed Apple Software Update
03-12-2013 17:02:08 Revo Uninstaller's restore point - Bing Bar
03-12-2013 17:04:28 Removed Bing Bar
03-12-2013 17:10:50 Revo Uninstaller's restore point - Apple Mobile Device Support
03-12-2013 17:11:53 Removed Apple Mobile Device Support
03-12-2013 17:39:10 Software Distribution Service 3.0
03-12-2013 17:42:54 Software Distribution Service 3.0
04-12-2013 08:11:44 Software Distribution Service 3.0
04-12-2013 09:28:15 Software Distribution Service 3.0
==================== Hosts content: ==========================
2002-09-03 13:39 - 2002-09-03 13:39 - 00000734 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\MP Scheduled Scan.job => C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{3AC8987B-6FA2-4503-AB40-BD9C6C5DDA8F}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) =============
2009-09-04 13:54 - 2006-11-01 10:48 - 00757760 _____ () C:\WINDOWS\System32\bcm1xsup.dll
==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\aawservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UploadMgr => ""="Service"
==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================
Application errors:
==================
Error: (12/04/2013 03:16:09 AM) (Source: Application Hang) (User: )
Description: Hanging application rundll32.exe, version 5.1.2600.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (12/04/2013 03:07:48 AM) (Source: Application Hang) (User: )
Description: Hanging application rundll32.exe, version 5.1.2600.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (12/03/2013 10:54:19 AM) (Source: CltMngSvc) (User: )
Description: CltMngSvcShutting down. (Error: 997)
Error: (12/03/2013 05:47:25 AM) (Source: Application Hang) (User: )
Description: Hanging application RegCleanPro.exe, version 6.21.65.2601, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (12/03/2013 05:45:59 AM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (12/03/2013 05:43:04 AM) (Source: crypt32) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The server name or address could not be resolved
Error: (11/03/2013 03:11:41 PM) (Source: .NET Runtime Optimization Service) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131506
Error: (11/03/2013 02:33:39 PM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (11/03/2013 02:27:25 PM) (Source: crypt32) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The server name or address could not be resolved
Error: (10/25/2013 07:30:08 PM) (Source: CltMngSvc) (User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)

System errors:
=============
Error: (12/04/2013 00:13:12 PM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 09:07:56 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 05:10:35 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 05:03:24 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 04:44:48 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
agp440
PCIIde
Error: (12/04/2013 04:43:19 AM) (Source: 0) (User: )
Description: 0xC0000001HarddiskVolume1
Error: (12/04/2013 04:43:19 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 03:34:14 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 02:58:39 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.
Error: (12/04/2013 02:53:43 AM) (Source: SCardSvr) (User: )
Description: WDM Reader driver initialization cannot open reader device: The system cannot find the path specified.

Microsoft Office Sessions:
=========================
Error: (12/04/2013 03:16:09 AM) (Source: Application Hang)(User: )
Description: rundll32.exe5.1.2600.5512hungapp0.0.0.000000000
Error: (12/04/2013 03:07:48 AM) (Source: Application Hang)(User: )
Description: rundll32.exe5.1.2600.5512hungapp0.0.0.000000000
Error: (12/03/2013 10:54:19 AM) (Source: CltMngSvc)(User: )
Description: CltMngSvcShutting down. (Error: 997)
Error: (12/03/2013 05:47:25 AM) (Source: Application Hang)(User: )
Description: RegCleanPro.exe6.21.65.2601hungapp0.0.0.000000000
Error: (12/03/2013 05:45:59 AM) (Source: Application Hang)(User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (12/03/2013 05:43:04 AM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThe server name or address could not be resolved
Error: (11/03/2013 03:11:41 PM) (Source: .NET Runtime Optimization Service)(User: )
Description: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131506
System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
Error: (11/03/2013 02:33:39 PM) (Source: Application Hang)(User: )
Description: iexplore.exe8.0.6001.18702hungapp0.0.0.000000000
Error: (11/03/2013 02:27:25 PM) (Source: crypt32)(User: )
Description: http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtThe server name or address could not be resolved
Error: (10/25/2013 07:30:08 PM) (Source: CltMngSvc)(User: )
Description: CltMngSvcServiceInstall: Fail to Start serviceSearch Protect by Conduit Updater (Error: 1056)

==================== Memory info ===========================
Percentage of memory in use: 49%
Total physical RAM: 1015.36 MB
Available physical RAM: 512.6 MB
Total Pagefile: 2453.86 MB
Available Pagefile: 2021.48 MB
Total Virtual: 2047.88 MB
Available Virtual: 1945.23 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:37.26 GB) (Free:13.35 GB) NTFS ==>[Drive with boot components (Windows XP)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 37 GB) (Disk ID: CC7ACC7A)
Partition 1: (Active) - (Size=37 GB) - (Type=07 NTFS)
==================== End Of Log ============================
 
Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
 

Attachments

  • fixlist.txt
    4 KB · Views: 1
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-12-2013 01
Ran by HOME at 2013-12-04 13:09:02 Run:1
Running from C:\Documents and Settings\HOME\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
MountPoints2: {34e2d166-eaa6-11df-b2e1-000b7d25208b} - F:\MI.exe
URLSearchHook: HKCU - (No Name) - {0953a3a2-9223-4990-a1c9-efb4d4686ef2} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7iSrcAs.dll (MindSpark)
C:\Program Files\PopularScreensavers_7i
URLSearchHook: HKCU - (No Name) - {bd8006aa-6e85-4b36-bb42-7f97053d5b70} - No File
SearchScopes: HKCU - {BA2C2F9E-D4DD-43A6-B87E-1F2983FC7977} URL = http://tuvaro.com/ws/?source=6912e0...00000000000000b7d25208b&q={searchTerms}&r=894
SearchScopes: HKCU - {EAB87B7A-B2AC-4345-9929-DD6B830520EA} URL = http://search.conduit.com/ResultsEx...4&ctid=CT3299872&CUI=UN13645246185853184&UM=2
BHO: Toolbar BHO - {0709f2cc-d1e6-4b43-9efc-1c0701cb173d} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
BHO: Search Assistant BHO - {3a6625a2-591b-4e83-ac3f-8c25eea30ac0} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7iSrcAs.dll (MindSpark)
BHO: tuvaro Helper Object - {5CB02877-EFBC-4317-B608-9E24B11BAB40} - C:\Program Files\tuvaro\tuvaro\1.8.22.1\bh\tuvaro.dll No File
Toolbar: HKLM - Tuvaro Toolbar - {6F001652-AF51-45C6-B029-86E0265A1851} - C:\Program Files\tuvaro\tuvaro\1.8.22.1\tuvaroTlbr.dll No File
Toolbar: HKLM - PopularScreensavers - {f339a07f-9578-412d-85e0-b8a80277151a} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKCU - PopularScreensavers - {F339A07F-9578-412D-85E0-B8A80277151A} - C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibar.dll (MindSpark)
Toolbar: HKCU - No Name - {BD8006AA-6E85-4B36-BB42-7F97053D5B70} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
FF Plugin: @popularscreensavers.com/Plugin - C:\Program Files\PopularScreensavers\NPp5Stub.dll (popularscreensavers.com)
FF Extension: PopularScreensavers - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\7iffxtbr@PopularScreensavers_7i.com
FF HKLM\...\Firefox\Extensions: [7iffxtbr@PopularScreensavers_7i.com] - C:\Program Files\PopularScreensavers_7i\bar\1.bin
FF Extension: PopularScreensavers - C:\Program Files\PopularScreensavers_7i\bar\1.bin
S2 PopularScreensavers_7iService; C:\Program Files\PopularScreensavers_7i\bar\1.bin\7ibarsvc.exe [42504 2013-08-09] (COMPANYVERS_NAME)
U1 _VOIDymxgobuqxe; \systemroot\_VOIDymxgobuqxe\_VOIDd.sys [x]
C:\Documents and Settings\HOME\Local Settings\Temp\ApnStub.exe
C:\Documents and Settings\HOME\Local Settings\Temp\BackupSetup.exe
C:\Documents and Settings\HOME\Local Settings\Temp\contentDATs.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jna985496082466458090.dll
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u20-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u22-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u17-windows-i586-iftw.exe
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\HOME\Local Settings\Temp\mssinstaller.exe
C:\Documents and Settings\HOME\Local Settings\Temp\nsmFA.tmp.tbBegi.dll
C:\Documents and Settings\HOME\Local Settings\Temp\nsqA0.tmp.tbWise.dll
C:\Documents and Settings\HOME\Local Settings\Temp\oi_{0377526B-6C42-4D38-BA65-F20FFAD9F0F9}.exe
C:\Documents and Settings\HOME\Local Settings\Temp\SecurityScan_Release.exe
C:\Documents and Settings\HOME\Local Settings\Temp\setup.exe
C:\Documents and Settings\HOME\Local Settings\Temp\SSUPDATE.EXE
C:\Documents and Settings\HOME\Local Settings\Temp\tbIns2.dll
C:\Documents and Settings\HOME\Local Settings\Temp\uninst.exe
C:\Documents and Settings\HOME\Local Settings\Temp\UNINSTALL.exe
C:\Documents and Settings\HOME\Local Settings\Temp\vcredist_x86.exe
C:\Documents and Settings\HOME\Local Settings\Temp\VSUSetup.exe
*****************
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{34e2d166-eaa6-11df-b2e1-000b7d25208b} => Key deleted successfully.
HKCR\CLSID\{34e2d166-eaa6-11df-b2e1-000b7d25208b} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0953a3a2-9223-4990-a1c9-efb4d4686ef2} => Value deleted successfully.
HKCR\CLSID\{0953a3a2-9223-4990-a1c9-efb4d4686ef2} => Key deleted successfully.
C:\Program Files\PopularScreensavers_7i => Moved successfully.
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{bd8006aa-6e85-4b36-bb42-7f97053d5b70} => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BA2C2F9E-D4DD-43A6-B87E-1F2983FC7977} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{BA2C2F9E-D4DD-43A6-B87E-1F2983FC7977} => Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EAB87B7A-B2AC-4345-9929-DD6B830520EA} => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{EAB87B7A-B2AC-4345-9929-DD6B830520EA} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0709f2cc-d1e6-4b43-9efc-1c0701cb173d} => Key deleted successfully.
HKCR\CLSID\{0709f2cc-d1e6-4b43-9efc-1c0701cb173d} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3a6625a2-591b-4e83-ac3f-8c25eea30ac0} => Key deleted successfully.
HKCR\CLSID\{3a6625a2-591b-4e83-ac3f-8c25eea30ac0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CB02877-EFBC-4317-B608-9E24B11BAB40} => Key deleted successfully.
HKCR\CLSID\{5CB02877-EFBC-4317-B608-9E24B11BAB40} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{6F001652-AF51-45C6-B029-86E0265A1851} => Value deleted successfully.
HKCR\CLSID\{6F001652-AF51-45C6-B029-86E0265A1851} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{f339a07f-9578-412d-85e0-b8a80277151a} => Value deleted successfully.
HKCR\CLSID\{f339a07f-9578-412d-85e0-b8a80277151a} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} => Value deleted successfully.
HKCR\CLSID\{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} => Value deleted successfully.
HKCR\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{F339A07F-9578-412D-85E0-B8A80277151A} => Value deleted successfully.
HKCR\CLSID\{F339A07F-9578-412D-85E0-B8A80277151A} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{BD8006AA-6E85-4B36-BB42-7F97053D5B70} => Value deleted successfully.
HKCR\CLSID\{BD8006AA-6E85-4B36-BB42-7F97053D5B70} => Key not found.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Value deleted successfully.
HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => Key deleted successfully.
HKLM\Software\MozillaPlugins\@popularscreensavers.com/Plugin => Key deleted successfully.
C:\Program Files\PopularScreensavers\NPp5Stub.dll => Moved successfully.
C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\7iffxtbr@PopularScreensavers_7i.com => Moved successfully.
HKLM\Software\Mozilla\Firefox\Extensions\\7iffxtbr@PopularScreensavers_7i.com => Value deleted successfully.
C:\Program Files\PopularScreensavers_7i\bar\1.bin => not found.
PopularScreensavers_7iService => Service deleted successfully.
_VOIDymxgobuqxe => Service deleted successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\ApnStub.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\BackupSetup.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\contentDATs.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jna985496082466458090.dll => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u20-windows-i586-iftw-rv.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u22-windows-i586-iftw-rv.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jre-6u26-windows-i586-iftw-rv.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u17-windows-i586-iftw.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\jre-7u25-windows-i586-iftw.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\mssinstaller.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsmFA.tmp.tbBegi.dll => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\nsqA0.tmp.tbWise.dll => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\oi_{0377526B-6C42-4D38-BA65-F20FFAD9F0F9}.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\SecurityScan_Release.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\setup.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\SSUPDATE.EXE => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\tbIns2.dll => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\uninst.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\UNINSTALL.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\vcredist_x86.exe => Moved successfully.
C:\Documents and Settings\HOME\Local Settings\Temp\VSUSetup.exe => Moved successfully.
==== End of Fixlog ====
 
Good :)

redtarget.gif
Download RogueKiller for 32bit or Roguekiller for 64bit to your Desktop.
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • Wait until the Status box shows Scan Finished
  • Click on Delete.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If more than one log is produced post all logs.
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

redtarget.gif
Create new restore point before proceeding with the next step....
How to: http://www.smartestcomputing.us.com/topic/63983-how-to-create-new-restore-point-all-windows/

Download Malwarebytes Anti-Rootkit (MBAR) from HERE
  • Unzip downloaded file.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder..... mbar-log-xxxxx.txt and system-log.txt
 
System Restore won't start...

RogueKiller V8.7.11 [Dec 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : HOME [Admin rights]
Mode : Scan -- Date : 12/05/2013 04:24:13
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 3 ¤¤¤
[RUN][SUSP PATH] HKUS\.DEFAULT\[...]\Run : SearchProtect (C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe [x]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-18\[...]\Run : SearchProtect (C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe [x]) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) FUJITSU MHV2040AH +++++
--- User ---
[MBR] 160360ebfb19ff3afbdb85c24a35a98a
[BSP] 10396c38056863599fcbdfa1d8d8ab6b : Legit.C MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 38154 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_S_12052013_042413.txt >>


RogueKiller V8.7.11 [Dec 3 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : HOME [Admin rights]
Mode : Remove -- Date : 12/05/2013 04:24:52
| ARK || FAK || MBR |
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 3 ¤¤¤
[RUN][SUSP PATH] HKUS\.DEFAULT\[...]\Run : SearchProtect (C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe [x]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-18\[...]\Run : SearchProtect (C:\WINDOWS\system32\config\systemprofile\Application Data\SearchProtect\bin\cltmng.exe [x]) -> [0x2] The system cannot find the file specified.
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Startup Entries : 0 ¤¤¤
¤¤¤ Web browsers : 0 ¤¤¤
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
¤¤¤ External Hives: ¤¤¤
¤¤¤ Infection : ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) FUJITSU MHV2040AH +++++
--- User ---
[MBR] 160360ebfb19ff3afbdb85c24a35a98a
[BSP] 10396c38056863599fcbdfa1d8d8ab6b : Legit.C MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 38154 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_D_12052013_042452.txt >>
RKreport[0]_S_12052013_042413.txt
 
Malwarebytes Anti-Rootkit BETA 1.07.0.1007
www.malwarebytes.org
Database version: v2013.12.06.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
HOME :: DELL-D610 [administrator]
12/6/2013 4:08:56 AM
mbar-log-2013-12-06 (04-08-56).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 235995
Time elapsed: 32 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1007
(c) Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 1.596000 GHz
Memory total: 1064685568, free: 282656768
=======================================

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1007
(c) Malwarebytes Corporation 2011-2012
OS version: 5.1.2600 Windows XP Service Pack 3 x86
Account is Administrative
Internet Explorer version: 8.0.6001.18702
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 1.596000 GHz
Memory total: 1064685568, free: 308748288
Downloaded database version: v2013.12.06.03
Downloaded database version: v2013.10.11.02
=======================================
Initializing...
------------ Kernel report ------------
12/06/2013 04:08:28
------------ Loaded modules -----------
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
compbatt.sys
\WINDOWS\System32\DRIVERS\BATTC.SYS
PCIIde.sys
\WINDOWS\System32\Drivers\PCIIDEX.SYS
intelide.sys
pcmcia.sys
MountMgr.sys
ftdisk.sys
PartMgr.sys
VolSnap.sys
atapi.sys
cercsr6.sys
\WINDOWS\System32\Drivers\SCSIPORT.SYS
disk.sys
\WINDOWS\System32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
vvoice.sys
vpctcom.sys
vmodem.sys
ohci1394.sys
\WINDOWS\system32\DRIVERS\1394BUS.SYS
Mup.sys
agp440.sys
\SystemRoot\System32\DRIVERS\intelppm.sys
\SystemRoot\System32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\ialmnt5.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\b57xp32.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\gtipci21.sys
\SystemRoot\system32\DRIVERS\SMCLIB.SYS
\SystemRoot\System32\DRIVERS\bcmwl5.sys
\SystemRoot\system32\drivers\stac97.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\HSFHWICH.sys
\SystemRoot\system32\DRIVERS\HSF_DPV.SYS
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\System32\DRIVERS\i8042prt.sys
\SystemRoot\System32\DRIVERS\mouclass.sys
\SystemRoot\System32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\smcirda.sys
\SystemRoot\System32\DRIVERS\irenum.sys
\SystemRoot\System32\DRIVERS\parport.sys
\SystemRoot\System32\DRIVERS\imapi.sys
\SystemRoot\system32\drivers\Afc.sys
\SystemRoot\System32\DRIVERS\cdrom.sys
\SystemRoot\System32\DRIVERS\redbook.sys
\SystemRoot\System32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasirda.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\rasl2tp.sys
\SystemRoot\System32\DRIVERS\ndistapi.sys
\SystemRoot\System32\DRIVERS\ndiswan.sys
\SystemRoot\System32\DRIVERS\raspppoe.sys
\SystemRoot\System32\DRIVERS\raspptp.sys
\SystemRoot\System32\DRIVERS\psched.sys
\SystemRoot\System32\DRIVERS\msgpc.sys
\SystemRoot\System32\DRIVERS\ptilink.sys
\SystemRoot\System32\DRIVERS\raspti.sys
\SystemRoot\System32\DRIVERS\rdpdr.sys
\SystemRoot\System32\DRIVERS\termdd.sys
\SystemRoot\System32\DRIVERS\swenum.sys
\SystemRoot\System32\DRIVERS\update.sys
\SystemRoot\System32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\omci.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\MpFilter.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\DRIVERS\rasacd.sys
\SystemRoot\System32\DRIVERS\ipsec.sys
\SystemRoot\System32\DRIVERS\tcpip.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbios.sys
\SystemRoot\System32\DRIVERS\rdbss.sys
\SystemRoot\System32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ialmdnt5.dll
\SystemRoot\System32\ialmrnt5.dll
\SystemRoot\System32\ialmdev5.DLL
\SystemRoot\System32\ialmdd5.DLL
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\irda.sys
\SystemRoot\System32\DRIVERS\ndisuio.sys
\SystemRoot\System32\DRIVERS\mrxdav.sys
\SystemRoot\System32\Drivers\ParVdm.SYS
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\drivers\kmixer.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff87120ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\
Lower Device Object: 0xffffffff871a5b00
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff87120ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff87141900, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff87120ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff871a5b00, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: CC7ACC7A
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 63 Numsec = 78140097
Partition file system is NTFS
Partition is bootable
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 40007761920 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-62-78120160-78140160)...
Done!
Scan finished
=======================================

Removal queue found; removal started
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_0_63_i.mbam...
Removing C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam...
Removal finished
 
Please download ComboFix from Here, Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    If the connection is not there use restore point you created prior to running Combofix.
  • Double click on combofix.exe & follow the prompts.

  • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
**Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try the following...

Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

Restart computer in safe mode

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

When the scan is done Notepad will open with rKill.txt log.
NOTE. rKill.txt log will also be present on your desktop.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
 
Combofix stalls.....ran rKill then a fresh renamed copy of Combofix still stalls.
Rkill 2.6.3 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/07/2013 02:15:25 AM in x86 mode. (Safe Mode)
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* AFD Networking Support Environment (AFD) is not Running.
Startup Type set to: System
* DHCP Client (Dhcp) is not Running.
Startup Type set to: Automatic
* DNS Client (Dnscache) is not Running.
Startup Type set to: Automatic
* COM+ Event System (EventSystem) is not Running.
Startup Type set to: Manual
* Network Connections (Netman) is not Running.
Startup Type set to: Manual
* Security Center (wscsvc) is not Running.
Startup Type set to: Automatic
* Automatic Updates (wuauserv) is not Running.
Startup Type set to: Automatic
* AFD Networking Support Environment (AFD) is not Running.
Startup Type set to: System
* IPSEC driver (IPSec) is not Running.
Startup Type set to: System
* NetBios over Tcpip (NetBT) is not Running.
Startup Type set to: System
* TCP/IP Protocol Driver (Tcpip) is not Running.
Startup Type set to: System
* helpsvc [Missing Parameters Key]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* HOSTS file entries found:
127.0.0.1 localhost
Program finished at: 12/07/2013 02:17:22 AM
Execution time: 0 hours(s), 1 minute(s), and 57 seconds(s)
 
Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please copy and paste it to your reply.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 08-12-2013 01
Ran by HOME (administrator) on DELL-D610 on 08-12-2013 04:06:51
Running from C:\Documents and Settings\HOME\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(Hewlett-Packard Company) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(ArcSoft Inc.) C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ATIPTA] - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [344064 2005-01-11] (ATI Technologies, Inc.)
HKLM\...\Run: [BluetoothAuthenticationAgent] - rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2006-09-15] (Intel Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\WINDOWS\system32\WLTRAY.EXE [1392640 2006-11-01] (Dell Inc.)
HKLM\...\Run: [HP Software Update] - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [49152 2004-02-12] (Hewlett-Packard Company)
HKLM\...\Run: [HP Component Manager] - C:\Program Files\HP\hpcoretech\hpcmpmgr.exe [241664 2004-05-12] (Hewlett-Packard Company)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [36272 2010-04-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [997920 2011-06-15] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Winlogon\Notify\AtiExtEvent: C:\Windows\system32\Ati2evxx.dll (ATI Technologies Inc.)
HKU\Administrator\...\Run: [MSMSGS] - C:\Program Files\Messenger\msmsgs.exe [ 2008-04-13] (Microsoft Corporation)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
ShortcutTarget: HP Image Zone Fast Start.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
BootExecute: autocheck autochk * lsdelete
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/
SearchScopes: HKLM - DefaultScope {EAB87B7A-B2AC-4345-9929-DD6B830520EA} URL =
SearchScopes: HKLM - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.tb.ask.com/search/GGm...&n=77fd2d5a&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {2166D31A-2CB5-47B8-BCA0-D20BA478BD31} URL = http://websearch.ask.com/redirect?c...pn_sauid=5A3E80CF-2B71-4ACF-ADB4-27B8FC90B23C
SearchScopes: HKCU - {46197f3d-30e7-4905-a14b-02bee3aaeb58} URL = http://search.tb.ask.com/search/GGm...&n=77fd2d5a&psa=&st=sb&searchfor={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - &Address - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252605597546
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137095143638
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default
FF SearchEngineOrder.1: Ask.com
FF SelectedSearchEngine: Ask Web Search
FF Homepage: hxxp://home.tb.ask.com/index.jhtml?ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&p2=^ZR^xpt366^YYA^us&si=installldownload
FF Keyword.URL: hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&ind=2013120306&p2=^ZR^xpt366^YYA^us&si=installldownload&searchfor=
FF DefaultSearchEngine: Google
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @PopularScreensavers_7i.com/Plugin - C:\Program Files\PopularScreensavers_7i\bar\1.bin\NP7iStub.dll No File
FF SearchPlugin: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\ask-web-search.xml
FF SearchPlugin: C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\askcom.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\answers.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
FF Extension: weDownload Manager - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com
FF Extension: Microsoft .NET Framework Assistant - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: Google Toolbar for Firefox - C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: Google Settings - C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
========================== Services (Whitelisted) =================
R2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 helpsvc; C:\Windows\System32\svchost.exe [14336 2008-04-13] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe [11736 2011-04-27] (Microsoft Corporation)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [1253376 2006-11-01] (Dell Inc.)
R2 JavaQuickStarterService; "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf"
S3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe" [x]
S2 PEVSystemStart; "C:\ComboFix\pev.3XE" EXEC /I "C:\ComboFix\HIDEC.3XE" "C:\ComboFix\SWREG.3XE" ACL "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep" /RESET /Q
==================== Drivers (Whitelisted) ====================
S3 ac97intc; C:\Windows\System32\drivers\ac97intc.sys [96256 2001-08-17] (Intel Corporation)
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 AR5211; C:\Windows\System32\DRIVERS\ar5211.sys [407360 2004-12-22] (D-Link )
S3 AR5513; C:\Windows\System32\DRIVERS\ar5513.sys [358464 2005-09-12] (Atheros Communications, Inc.)
R3 BCM43XX; C:\Windows\System32\DRIVERS\bcmwl5.sys [604928 2006-11-03] (Broadcom Corporation)
S3 EL90XBC; C:\Windows\System32\DRIVERS\el90xbc5.sys [66591 2001-08-17] (3Com Corporation)
R3 GTIPCI21; C:\Windows\System32\DRIVERS\gtipci21.sys [88192 2006-04-06] (Texas Instruments)
S3 GWRCB_A00; C:\Windows\System32\DRIVERS\GWRCBA00.sys [418368 2004-03-15] (Ashton Digital Corp.)
S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [51088 2004-06-21] (HP)
S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2004-06-21] (HP)
S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21744 2004-06-21] (HP)
R3 HSFHWICH; C:\Windows\System32\DRIVERS\HSFHWICH.sys [208384 2005-05-03] (Conexant Systems, Inc.)
R3 HSF_DPV; C:\Windows\System32\DRIVERS\HSF_DPV.SYS [1033728 2005-05-03] (Conexant Systems, Inc.)
R1 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [165648 2011-04-18] (Microsoft Corporation)
S3 OZSCR; C:\Windows\System32\DRIVERS\ozscr.sys [92550 2005-04-21] (O2Micro)
S1 P3; C:\Windows\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation)
S3 Ptserial; C:\Windows\System32\DRIVERS\ptserial.sys [135292 2003-02-24] (PCTEL, INC.)
R3 Rasirda; C:\Windows\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
S3 RT61; C:\Windows\System32\DRIVERS\RT61.sys [483968 2007-07-28] (Ralink Technology, Corp.)
R3 SMCIRDA; C:\Windows\System32\DRIVERS\smcirda.sys [35913 2001-08-17] (SMC)
R3 STAC97; C:\Windows\System32\drivers\stac97.sys [273168 2005-03-10] (SigmaTel, Inc.)
R0 Vmodem; C:\Windows\System32\DRIVERS\vmodem.sys [690973 2003-05-30] (PCTEL, INC.)
R0 Vpctcom; C:\Windows\System32\DRIVERS\vpctcom.sys [477403 2003-05-30] (PCtel, Inc.)
R0 Vvoice; C:\Windows\System32\DRIVERS\vvoice.sys [66111 2003-05-28] (PCtel, Inc.)
S3 W8335PCI; C:\Windows\System32\DRIVERS\Mrvw123.sys [282624 2005-12-29] (Marvell Semiconductor, Inc)
S3 atimtag; System32\DRIVERS\atimtag.sys [x]
U5 ScsiPort; C:\Windows\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 UIUSys; system32\drivers\UIUSys.sys [x]
==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========
2013-12-08 04:06 - 2013-12-08 04:07 - 00013742 _____ C:\Documents and Settings\HOME\Desktop\FRST.txt
2013-12-07 02:18 - 2013-12-07 02:21 - 00000000 ___SD C:\RonM
2013-12-07 02:15 - 2013-12-07 02:17 - 00004020 _____ C:\Documents and Settings\HOME\Desktop\Rkill.txt
2013-12-07 01:28 - 2013-12-07 01:28 - 01937144 _____ (Bleeping Computer, LLC) C:\Documents and Settings\HOME\Desktop\rkill.exe
2013-12-07 01:27 - 2013-12-07 01:27 - 05153293 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\RonM.exe
2013-12-07 00:34 - 2013-12-07 00:34 - 00000000 _RSHD C:\cmdcons
2013-12-07 00:34 - 2005-12-02 01:07 - 00000211 _____ C:\Boot.bak
2013-12-07 00:34 - 2004-08-03 23:00 - 00260272 __RSH C:\cmldr
2013-12-07 00:32 - 2013-12-07 00:32 - 00000000 ____D C:\Qoobox
2013-12-07 00:32 - 2011-06-26 00:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-12-07 00:32 - 2010-11-07 11:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-12-07 00:32 - 2009-04-19 22:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-12-07 00:32 - 2000-08-30 18:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-12-07 00:31 - 2013-12-07 00:31 - 00000000 ____D C:\WINDOWS\erdnt
2013-12-06 04:08 - 2013-12-06 04:50 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-12-06 04:08 - 2013-12-06 04:08 - 00105176 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2013-12-06 04:05 - 2013-12-06 04:06 - 00047064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2013-12-06 04:04 - 2013-12-06 04:50 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\mbar
2013-12-05 04:24 - 2013-12-05 04:24 - 00001754 _____ C:\Documents and Settings\HOME\Desktop\RKreport[0]_D_12052013_042452.txt
2013-12-05 04:24 - 2013-12-05 04:24 - 00001666 _____ C:\Documents and Settings\HOME\Desktop\RKreport[0]_S_12052013_042413.txt
2013-12-05 04:17 - 2013-12-05 04:24 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\RK_Quarantine
2013-12-05 04:16 - 2013-12-05 04:17 - 03580416 _____ C:\Documents and Settings\HOME\Desktop\RogueKiller.exe
2013-12-04 12:17 - 2013-12-04 12:17 - 00000000 ____D C:\FRST
2013-12-04 12:16 - 2013-12-08 04:05 - 01060421 _____ (Farbar) C:\Documents and Settings\HOME\Desktop\FRST.exe
2013-12-04 11:27 - 2013-12-04 11:27 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\tdsskiller
2013-12-04 03:41 - 2013-12-04 03:41 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-12-04 03:32 - 2013-12-04 03:32 - 00009474 _____ C:\WINDOWS\KB2900986.log
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-12-04 03:31 - 2013-12-04 03:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-12-04 03:30 - 2013-12-04 03:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-12-04 03:28 - 2013-12-04 03:30 - 00011778 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-04 03:26 - 2013-12-04 03:26 - 00688992 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\dds.com
2013-12-04 02:14 - 2013-12-06 03:57 - 00000250 _____ C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2013-12-04 01:55 - 2013-12-04 03:32 - 00018881 _____ C:\WINDOWS\KB2868626.log
2013-12-04 01:55 - 2013-12-04 03:31 - 00017890 _____ C:\WINDOWS\KB2862152.log
2013-12-04 01:54 - 2013-12-04 03:30 - 00017469 _____ C:\WINDOWS\KB2876331.log
2013-12-03 13:14 - 2013-12-06 04:09 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-03 13:14 - 2013-12-03 13:14 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
==================== One Month Modified Files and Folders =======
2013-12-08 04:07 - 2013-12-08 04:06 - 00013742 _____ C:\Documents and Settings\HOME\Desktop\FRST.txt
2013-12-08 04:05 - 2013-12-04 12:16 - 01060421 _____ (Farbar) C:\Documents and Settings\HOME\Desktop\FRST.exe
2013-12-08 03:55 - 2009-11-13 21:06 - 00000420 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{3AC8987B-6FA2-4503-AB40-BD9C6C5DDA8F}.job
2013-12-08 03:49 - 2010-05-30 05:33 - 01859975 _____ C:\WINDOWS\WindowsUpdate.log
2013-12-08 03:41 - 2013-03-11 15:11 - 00000424 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job
2013-12-08 03:37 - 2010-05-30 05:42 - 00032564 _____ C:\WINDOWS\SchedLgU.Txt
2013-12-08 03:36 - 2002-09-03 14:04 - 00002228 _____ C:\WINDOWS\system32\wpa.dbl
2013-12-08 03:35 - 2010-05-30 05:42 - 00000159 _____ C:\WINDOWS\wiadebug.log
2013-12-08 03:35 - 2010-05-30 05:42 - 00000049 _____ C:\WINDOWS\wiaservc.log
2013-12-08 03:35 - 2006-01-12 10:18 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-12-07 03:30 - 2006-01-12 10:29 - 00000278 ___SH C:\Documents and Settings\HOME\ntuser.ini
2013-12-07 03:30 - 2006-01-12 10:29 - 00000000 ____D C:\Documents and Settings\HOME
2013-12-07 02:21 - 2013-12-07 02:18 - 00000000 ___SD C:\RonM
2013-12-07 02:17 - 2013-12-07 02:15 - 00004020 _____ C:\Documents and Settings\HOME\Desktop\Rkill.txt
2013-12-07 01:28 - 2013-12-07 01:28 - 01937144 _____ (Bleeping Computer, LLC) C:\Documents and Settings\HOME\Desktop\rkill.exe
2013-12-07 01:27 - 2013-12-07 01:27 - 05153293 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\RonM.exe
2013-12-07 00:34 - 2013-12-07 00:34 - 00000000 _RSHD C:\cmdcons
2013-12-07 00:34 - 2006-01-12 04:59 - 00000327 __RSH C:\boot.ini
2013-12-07 00:32 - 2013-12-07 00:32 - 00000000 ____D C:\Qoobox
2013-12-07 00:31 - 2013-12-07 00:31 - 00000000 ____D C:\WINDOWS\erdnt
2013-12-06 04:50 - 2013-12-06 04:08 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-12-06 04:50 - 2013-12-06 04:04 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\mbar
2013-12-06 04:09 - 2013-12-03 13:14 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-12-06 04:08 - 2013-12-06 04:08 - 00105176 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2013-12-06 04:06 - 2013-12-06 04:05 - 00047064 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2013-12-06 04:00 - 2006-01-12 05:01 - 00526818 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-12-06 03:57 - 2013-12-04 02:14 - 00000250 _____ C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2013-12-05 06:39 - 2010-05-29 14:40 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2013-12-05 06:23 - 2006-01-12 10:14 - 00000000 ____D C:\WINDOWS\system32\Restore
2013-12-05 06:17 - 2006-01-12 04:54 - 00000000 ____D C:\WINDOWS\security
2013-12-05 04:24 - 2013-12-05 04:24 - 00001754 _____ C:\Documents and Settings\HOME\Desktop\RKreport[0]_D_12052013_042452.txt
2013-12-05 04:24 - 2013-12-05 04:24 - 00001666 _____ C:\Documents and Settings\HOME\Desktop\RKreport[0]_S_12052013_042413.txt
2013-12-05 04:24 - 2013-12-05 04:17 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\RK_Quarantine
2013-12-05 04:17 - 2013-12-05 04:16 - 03580416 _____ C:\Documents and Settings\HOME\Desktop\RogueKiller.exe
2013-12-04 13:09 - 2013-08-09 20:33 - 00000000 ____D C:\Program Files\PopularScreensavers
2013-12-04 12:17 - 2013-12-04 12:17 - 00000000 ____D C:\FRST
2013-12-04 11:27 - 2013-12-04 11:27 - 00000000 ____D C:\Documents and Settings\HOME\Desktop\tdsskiller
2013-12-04 09:10 - 2010-05-30 09:34 - 00061485 _____ C:\WINDOWS\setupapi.log
2013-12-04 04:42 - 2013-08-10 08:58 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2719985$
2013-12-04 04:41 - 2013-09-19 17:11 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Conduit
2013-12-04 03:41 - 2013-12-04 03:41 - 00000784 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Malwarebytes
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
2013-12-04 03:41 - 2013-12-04 03:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2013-12-04 03:32 - 2013-12-04 03:32 - 00009474 _____ C:\WINDOWS\KB2900986.log
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2900986$
2013-12-04 03:32 - 2013-12-04 03:32 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2868626$
2013-12-04 03:32 - 2013-12-04 01:55 - 00018881 _____ C:\WINDOWS\KB2868626.log
2013-12-04 03:32 - 2010-05-30 09:53 - 00070588 _____ C:\WINDOWS\updspapi.log
2013-12-04 03:32 - 2010-05-30 09:52 - 01049850 _____ C:\WINDOWS\iis6.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00973804 _____ C:\WINDOWS\FaxSetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00465244 _____ C:\WINDOWS\ocgen.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00444510 _____ C:\WINDOWS\tsoc.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00324776 _____ C:\WINDOWS\comsetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00298250 _____ C:\WINDOWS\msmqinst.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00196658 _____ C:\WINDOWS\ntdtcsetup.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00170530 _____ C:\WINDOWS\netfxocm.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00066916 _____ C:\WINDOWS\MedCtrOC.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00053871 _____ C:\WINDOWS\ocmsn.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00049099 _____ C:\WINDOWS\tabletoc.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00048750 _____ C:\WINDOWS\msgsocm.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00001374 _____ C:\WINDOWS\imsins.log
2013-12-04 03:32 - 2010-05-30 09:52 - 00001374 _____ C:\WINDOWS\imsins.BAK
2013-12-04 03:31 - 2013-12-04 03:31 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2862152$
2013-12-04 03:31 - 2013-12-04 01:55 - 00017890 _____ C:\WINDOWS\KB2862152.log
2013-12-04 03:30 - 2013-12-04 03:30 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB2876331$
2013-12-04 03:30 - 2013-12-04 03:28 - 00011778 _____ C:\WINDOWS\KB2888505-IE8.log
2013-12-04 03:30 - 2013-12-04 01:54 - 00017469 _____ C:\WINDOWS\KB2876331.log
2013-12-04 03:26 - 2013-12-04 03:26 - 00688992 ____R (Swearware) C:\Documents and Settings\HOME\Desktop\dds.com
2013-12-04 02:17 - 2013-08-12 06:24 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-12-04 02:11 - 2006-01-12 14:14 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2013-12-03 13:14 - 2013-12-03 13:14 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2013-12-03 11:36 - 2008-08-20 10:25 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\OpenOffice.org2
2013-12-03 11:19 - 2013-08-09 20:36 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\Systweak
2013-12-03 11:12 - 2009-09-10 10:35 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-12-03 10:56 - 2013-08-10 07:44 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Conduit
2013-12-03 10:53 - 2012-07-03 16:42 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Unity
2013-12-03 10:29 - 2006-01-13 10:07 - 00000000 ____D C:\Program Files\Google
2013-12-03 10:21 - 2007-08-13 10:38 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Google
2013-12-03 10:21 - 2006-01-13 09:45 - 00000000 ____D C:\Documents and Settings\HOME\Local Settings\Application Data\Google
2013-12-03 06:52 - 2009-09-11 09:24 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2013-12-03 06:41 - 2010-05-30 09:52 - 00000120 _____ C:\WINDOWS\setupact.log
2013-12-03 06:09 - 2013-08-09 20:33 - 00000000 ____D C:\Documents and Settings\HOME\Application Data\PopularScreensavers_7i
2013-12-03 06:08 - 2006-01-13 08:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-03 05:46 - 2009-09-23 07:20 - 00000000 ____D C:\Program Files\Microsoft Office
2013-12-03 05:40 - 2009-09-10 12:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-03 05:40 - 2006-01-12 04:59 - 00230392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-11-19 04:21 - 2010-05-31 02:55 - 00230048 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
Some content of TEMP:
====================
C:\Documents and Settings\HOME\Local Settings\Temp\ntdll_dump.dll

==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== End Of Log ============================
 
Looks good.

redtarget.gif
Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

redtarget.gif
Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

redtarget.gif
Download OTL to your Desktop.
Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
# AdwCleaner v3.014 - Report created 08/12/2013 at 13:42:55
# Updated 01/12/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : HOME - DELL-D610
# Running from : C:\Documents and Settings\HOME\Desktop\adwcleaner.exe
# Option : Clean
***** [ Services ] *****

***** [ Files / Folders ] *****
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Conduit
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\PopularScreensavers
Folder Deleted : C:\Documents and Settings\HOME\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\HOME\Local Settings\Application Data\iac
Folder Deleted : C:\Documents and Settings\HOME\Application Data\Systweak
Folder Deleted : C:\Documents and Settings\HOME\Application Data\tuvaro
File Deleted : C:\WINDOWS\system32\p5PSSavr.scr
File Deleted : C:\Program Files\Mozilla Firefox\.autoreg
File Deleted : C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\Askcom.xml
File Deleted : C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\searchplugins\ask-web-search.xml
***** [ Shortcuts ] *****

***** [ Registry ] *****
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\&Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3299872
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6FB5B50A-863D-4C0D-8E84-92A59565D087}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C39937A0-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A73204A3-4E2A-4924-95DA-D5DF58717368}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5DB5A94-1E55-4E2E-AA50-49C8C8215D56}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C39937A7-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{B2E5F9A4-0587-4525-8602-E08E32510243}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C39937A5-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5CB02877-EFBC-4317-B608-9E24B11BAB40}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F001652-AF51-45C6-B029-86E0265A1851}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5CB02877-EFBC-4317-B608-9E24B11BAB40}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F001652-AF51-45C6-B029-86E0265A1851}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C39937A9-C59D-4506-A9FC-0A0138192287}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DD55C1D4-CE89-4E93-866E-3F4A4962BD68}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8798BBE7-DDF6-448B-AE0E-83C9E28A5598}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F37BCE7B-6055-418C-A301-E715F36F1E79}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\installedbrowserextensions
Key Deleted : HKCU\Software\SmartBar
Key Deleted : HKCU\Software\WEDLMNGR
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\PopularScreensavers
Key Deleted : HKLM\Software\systweak
***** [ Browsers ] *****
-\\ Internet Explorer v8.0.6001.18702

-\\ Mozilla Firefox v3.5.7 (en-US)
[ File : C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\prefs.js ]
Line Deleted : user_pref("browser.search.order.1", "Ask.com");
Line Deleted : user_pref("browser.search.selectedEngine", "Ask Web Search");
Line Deleted : user_pref("browser.startup.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&p2=^ZR^xpt366^YYA^us&si=installldownload");
Line Deleted : user_pref("extensions.enabledItems", "{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20,{CAFEEFAC-0016-0000-0022[...]
Line Deleted : user_pref("extensions.mywebsearch.prevDefaultEngine", "Google");
Line Deleted : user_pref("extensions.mywebsearch.prevKwdEnabled", true);
Line Deleted : user_pref("extensions.mywebsearch.prevSelectedEngine", "Ask.com");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&p2=^ZR^xpt366^YYA^us&si=installldownload");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.initialized", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.contextKey", "");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.installDate", "2013120306");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.partnerId", "^ZR^xpt366^YYA^us");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.partnerSubId", "installldownload");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.success", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.installation.toolbarId", "580E6C67-07B7-4729-9B85-FFDAD8B9AC83");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.lastActivePing", "1386072563948");
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.defaultSearch", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.homePageEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.keywordEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark._7iMembers_.options.tabEnabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled", true);
Line Deleted : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "popularscreensavers@mindspark.com");
Line Deleted : user_pref("extensions.toolbar.mindspark.lastInstalled", "popularscreensavers@mindspark.com");
Line Deleted : user_pref("keyword.URL", "hxxp://search.tb.ask.com/search/GGmain.jhtml?st=kwd&ptb=580E6C67-07B7-4729-9B85-FFDAD8B9AC83&n=77fdc732&ind=2013120306&p2=^ZR^xpt366^YYA^us&si=installldownload&searchfor=");
*************************
AdwCleaner[R0].txt - [8791 octets] - [08/12/2013 13:41:58]
AdwCleaner[S0].txt - [8908 octets] - [08/12/2013 13:42:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8968 octets] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Microsoft Windows XP x86
Ran by HOME on Sun 12/08/2013 at 13:48:00.51
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values

~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.dynamicbarbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.dynamicbarbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.feedmanager
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.feedmanager.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.htmlpanel
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.htmlpanel.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.multiplebutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.multiplebutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.pseudotransparentplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.pseudotransparentplugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.radiosettings
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.radiosettings.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.scriptbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.scriptbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.thirdpartyinstaller
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.thirdpartyinstaller.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.urlalertbutton
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.urlalertbutton.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.xmlsessionplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\popularscreensavers_7i.xmlsessionplugin.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{17B0B148-1491-4668-AD7D-1F39972E03E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{406463E6-91B4-4BBE-8182-E41FDCA2B2B3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5469582E-6A71-4C2C-AB43-AB183058C88C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{5C0A85B9-3980-475D-AA36-EA2EF138EC04}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6833E938-D47A-4BCA-B7D4-A712CD561127}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{756E61B2-52AE-4D73-8535-F8DF642D72E5}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{7F9BAD37-202C-468D-A046-EBDEF588616D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{96D0C95F-BFE7-430E-A406-D8E2D33FEE48}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A9197738-02A5-46EF-BBF9-FDE251C5A631}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B7C7E5C1-F49C-476A-A7E9-F45E5C85C995}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{BC07C71E-C13B-4E16-B9A4-D954C3F097B6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D952F4A1-8B38-4B62-9E1E-CB74A2917580}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E51062CE-0B63-42A4-934A-C2ABE7B3EE7B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{0797C39C-6FDE-45BA-A89F-FDF91A1432D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{13431DEE-CAD4-403C-BDC2-F36F3F3F0852}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{50CE9C1E-AFA8-494D-98F1-FFEC8965EA0A}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66376EFC-73B3-41CB-8403-C19EA5A60623}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{A1C4DF97-9F5A-4518-A185-B71B3E2EDFA2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{A40F7F79-8927-4A4A-B0FC-D41A8BE8C018}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B956E151-3D90-489F-B109-97D5B4545D36}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{B985332B-07EF-4185-BBFA-805BF2130D59}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{C91E811C-4C64-4705-9C79-6DCF4184CE2C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{2CF52ECC-9E7E-43D7-8F7F-BBFB10C2D36F}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{32416A28-DAA5-4EE2-A5A1-6E9CB952C19D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{46A5C277-35A6-4C87-A0D2-D34D30D5A363}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{679DD02B-BFD7-439D-ADFF-20D7ED92FFD4}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{A5F237F3-1DA6-43AF-8CA5-CFD7BE9259A2}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{BBB1A756-C3A5-42CF-8FA3-BA0BD4C6F386}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{CCEC4CA8-9CE0-48E2-B203-C0239AA97A62}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{EA010B0B-1015-4E3E-B752-CC20A792B34C}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{FD4D02F2-EA24-4809-B0B6-805031110E8C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{17B0B148-1491-4668-AD7D-1F39972E03E5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{406463E6-91B4-4BBE-8182-E41FDCA2B2B3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7F9BAD37-202C-468D-A046-EBDEF588616D}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D952F4A1-8B38-4B62-9E1E-CB74A2917580}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2166D31A-2CB5-47B8-BCA0-D20BA478BD31}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{46197f3d-30e7-4905-a14b-02bee3aaeb58}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B698EA09-AC80-4830-91F5-3CC33877C48B}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{46197f3d-30e7-4905-a14b-02bee3aaeb58}

~~~ Files

~~~ Folders
Successfully deleted: [Folder] "C:\Documents and Settings\HOME\Application Data\popularscreensavers_7i"
Successfully deleted: [Folder] "C:\Documents and Settings\HOME\Local Settings\Application Data\begin-download_flv_b2"
Successfully deleted: [Folder] "C:\Program Files\begin-download_flv_b2"

~~~ FireFox
Successfully deleted: [Folder] C:\Documents and Settings\HOME\Application Data\mozilla\firefox\profiles\aad9qvoq.default\extensions\0c3e9649-324d-4df0-a61e-7ac31aead042@2612bb82-5f8a-49b2-a299-348e707310fc.com


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sun 12/08/2013 at 13:52:42.70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
OTL logfile created on: 12/8/2013 1:56:15 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\HOME\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.36 Mb Total Physical Memory | 547.43 Mb Available Physical Memory | 53.91% Memory free
2.40 Gb Paging File | 2.03 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 14.74 Gb Free Space | 39.55% Space Free | Partition Type: NTFS

Computer Name: DELL-D610 | User Name: HOME | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/12/08 13:55:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HOME\Desktop\OTL.exe
PRC - [2013/08/09 14:37:29 | 000,182,184 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/06/15 14:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/10/27 18:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/08/25 11:27:44 | 000,309,824 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
PRC - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2013/08/10 09:48:58 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2013/08/10 09:48:55 | 000,471,040 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2013/08/10 09:48:52 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2009/10/22 00:15:59 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2009/09/11 09:30:02 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc\3.0.0.0__a53cf5803f4c3827\hpqcprsc.dll
MOD - [2009/09/11 09:30:02 | 000,006,656 | ---- | M] () -- c:\windows\assembly\gac\hpqcprsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqcprsc.resources.dll
MOD - [2009/09/11 09:29:57 | 000,614,400 | ---- | M] () -- c:\windows\assembly\gac\hpqietpz\3.0.0.0__a53cf5803f4c3827\hpqietpz.dll
MOD - [2009/09/11 09:29:31 | 000,032,768 | ---- | M] () -- c:\windows\assembly\gac\hpqisrtb\4.0.0.0__a53cf5803f4c3827\hpqisrtb.dll
MOD - [2009/09/11 09:29:04 | 000,430,080 | ---- | M] () -- c:\windows\assembly\gac\lead.wrapper\13.0.0.66__9cf889f53ea9b907\lead.wrapper.dll
MOD - [2009/09/11 09:29:04 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead.drawing\13.0.0.66__9cf889f53ea9b907\lead.drawing.dll
MOD - [2009/09/11 09:29:04 | 000,081,920 | ---- | M] () -- c:\windows\assembly\gac\lead\13.0.0.66__9cf889f53ea9b907\lead.dll
MOD - [2009/09/11 09:29:04 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\lead.windows.forms\13.0.0.66__9cf889f53ea9b907\lead.windows.forms.dll
MOD - [2009/09/11 09:29:03 | 000,010,240 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqimgr\1.0.0.0__a53cf5803f4c3827\interop.hpqimgr.dll
MOD - [2009/09/11 09:29:02 | 000,368,640 | ---- | M] () -- c:\windows\assembly\gac\hpqtray\3.0.0.0__a53cf5803f4c3827\hpqtray.dll
MOD - [2009/09/11 09:29:02 | 000,249,856 | ---- | M] () -- c:\windows\assembly\gac\hpqtray.resources\3.0.0.0_en_a53cf5803f4c3827\hpqtray.resources.dll
MOD - [2009/09/11 09:29:02 | 000,163,840 | ---- | M] () -- c:\windows\assembly\gac\hpqimgrc\3.0.0.0__a53cf5803f4c3827\hpqimgrc.dll
MOD - [2009/09/11 09:29:02 | 000,045,056 | ---- | M] () -- c:\windows\assembly\gac\hpqthumb\3.0.0.0__a53cf5803f4c3827\hpqthumb.dll
MOD - [2009/09/11 09:29:02 | 000,028,672 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc\3.0.0.0__a53cf5803f4c3827\hpqfmrsc.dll
MOD - [2009/09/11 09:29:02 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqiface\3.0.0.0__a53cf5803f4c3827\hpqiface.dll
MOD - [2009/09/11 09:29:02 | 000,007,168 | ---- | M] () -- c:\windows\assembly\gac\hpqfmrsc.resources\3.0.0.0_en_a53cf5803f4c3827\hpqfmrsc.resources.dll
MOD - [2009/09/11 09:29:01 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqgldlg\3.0.0.0__a53cf5803f4c3827\hpqgldlg.dll
MOD - [2009/09/11 09:29:01 | 000,024,576 | ---- | M] () -- c:\windows\assembly\gac\hpqasset\3.0.0.0__a53cf5803f4c3827\hpqasset.dll
MOD - [2009/09/11 09:27:46 | 000,077,824 | ---- | M] () -- c:\windows\assembly\gac\hpqgskin\3.0.0.0__a53cf5803f4c3827\hpqgskin.dll
MOD - [2009/09/11 09:27:46 | 000,036,864 | ---- | M] () -- c:\windows\assembly\gac\interop.hpqcxm08\3.0.0.0__a53cf5803f4c3827\interop.hpqcxm08.dll
MOD - [2009/09/11 09:27:46 | 000,016,384 | ---- | M] () -- c:\windows\assembly\gac\hpqptfnd\3.0.0.0__a53cf5803f4c3827\hpqptfnd.dll
MOD - [2009/09/11 09:27:45 | 000,557,056 | ---- | M] () -- c:\windows\assembly\gac\hpqcmctl\3.0.0.0__a53cf5803f4c3827\hpqcmctl.dll
MOD - [2009/09/11 09:27:45 | 000,192,512 | ---- | M] () -- c:\windows\assembly\gac\hpqccrsc\3.0.0.0__a53cf5803f4c3827\hpqccrsc.dll
MOD - [2009/09/11 09:27:45 | 000,151,552 | ---- | M] () -- c:\windows\assembly\gac\hpqutils\3.0.0.0__a53cf5803f4c3827\hpqutils.dll
MOD - [2009/09/11 09:24:41 | 000,007,680 | ---- | M] () -- c:\windows\assembly\gac\accessibility\1.0.5000.0__b03f5f7f11d50a3a\accessibility.dll
MOD - [2006/11/01 10:48:18 | 000,757,760 | ---- | M] () -- C:\WINDOWS\system32\bcm1xsup.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\ComboFix\pev.3XE EXEC /I C:\ComboFix\HIDEC.3XE C:\ComboFix\SWREG.3XE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe -- (McComponentHostService)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2013/12/03 13:14:14 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/08/09 14:37:29 | 000,182,184 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2011/04/27 14:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2004/03/18 15:55:48 | 000,065,536 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\atimtag.sys -- (atimtag)
DRV - [2007/07/28 14:10:18 | 000,483,968 | R--- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2006/11/10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2006/11/03 12:34:00 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/05/10 13:00:16 | 000,156,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/04/06 14:49:00 | 000,088,192 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gtipci21.sys -- (GTIPCI21)
DRV - [2005/12/29 12:07:50 | 000,282,624 | R--- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Mrvw123.sys -- (W8335PCI)
DRV - [2005/09/12 19:59:28 | 000,358,464 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5513.sys -- (AR5513)
DRV - [2005/05/03 14:09:28 | 001,033,728 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.SYS -- (HSF_DPV)
DRV - [2005/05/03 14:08:50 | 000,208,384 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH)
DRV - [2005/05/03 14:08:44 | 000,705,408 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/04/21 19:58:38 | 000,092,550 | ---- | M] (O2Micro) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ozscr.sys -- (OZSCR)
DRV - [2005/03/10 15:56:06 | 000,273,168 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\STAC97.sys -- (STAC97)
DRV - [2005/01/11 12:18:22 | 000,800,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/12/22 06:30:00 | 000,407,360 | R--- | M] (D-Link ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2004/03/15 05:57:34 | 000,418,368 | R--- | M] (Ashton Digital Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GWRCBA00.sys -- (GWRCB_A00)
DRV - [2003/05/30 17:45:16 | 000,477,403 | ---- | M] (PCtel, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vpctcom.sys -- (Vpctcom)
DRV - [2003/05/30 16:50:46 | 000,690,973 | ---- | M] (PCTEL, INC.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vmodem.sys -- (Vmodem)
DRV - [2003/05/28 11:08:12 | 000,066,111 | ---- | M] (PCtel, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\vvoice.sys -- (Vvoice)
DRV - [2003/02/24 14:30:02 | 000,135,292 | ---- | M] (PCTEL, INC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ptserial.sys -- (Ptserial)
DRV - [2002/07/19 09:22:08 | 000,017,153 | RH-- | M] (Dell Computer Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\omci.sys -- (omci)
DRV - [2001/08/17 10:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
DRV - [2001/08/17 06:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = www.bing.com [binary data]
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.bing.com/ [binary data]
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&sourceid=ie7&rlz=1I7GGLG_enUS344
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@PopularScreensavers_7i.com/Plugin: C:\Program Files\PopularScreensavers_7i\bar\1.bin\NP7iStub.dll File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/29 08:49:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/08/09 20:33:07 | 000,000,000 | ---D | M]

[2009/11/22 10:24:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HOME\Application Data\Mozilla\Extensions
[2009/09/18 20:26:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HOME\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2013/12/08 13:52:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\extensions
[2011/08/29 13:05:38 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/09/06 19:07:32 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Documents and Settings\HOME\Application Data\Mozilla\Firefox\Profiles\aad9qvoq.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2013/12/03 06:09:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/30 10:08:10 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/10/17 09:58:39 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2007/08/13 16:16:18 | 000,000,000 | ---D | M] (Google Settings) -- C:\Program Files\Mozilla Firefox\extensions\google-cjk@partners.mozilla.com
[2012/12/18 11:21:58 | 000,031,456 | ---- | M] (popularscreensavers.com) -- C:\Program Files\mozilla firefox\plugins\NPp5Stub.dll

O1 HOSTS File: ([2002/09/03 13:39:21 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Co.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252605597546 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137095143638 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C3D27985-B9F8-41A0-AAF1-4667D9ECE4DB}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\HOME\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\HOME\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/09 09:26:21 | 000,000,615 | ---- | M] () - C:\autoAlbum.log -- [ NTFS ]
O32 - AutoRun File - [2006/01/12 10:18:55 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/12/08 13:55:32 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\HOME\Desktop\OTL.exe
[2013/12/08 13:47:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/12/08 13:46:52 | 001,034,531 | ---- | C] (Thisisu) -- C:\Documents and Settings\HOME\Desktop\JRT.exe
[2013/12/08 13:41:34 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2013/12/08 04:05:43 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013/12/07 02:18:59 | 000,000,000 | --SD | C] -- C:\RonM
[2013/12/07 01:28:27 | 001,937,144 | ---- | C] (Bleeping Computer, LLC) -- C:\Documents and Settings\HOME\Desktop\rkill.exe
[2013/12/07 01:27:16 | 005,153,293 | R--- | C] (Swearware) -- C:\Documents and Settings\HOME\Desktop\RonM.exe
[2013/12/07 00:34:27 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2013/12/07 00:32:28 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2013/12/07 00:32:28 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2013/12/07 00:32:28 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2013/12/07 00:32:28 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2013/12/07 00:32:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/12/07 00:31:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\erdnt
[2013/12/06 04:08:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
[2013/12/06 04:08:26 | 000,105,176 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2013/12/06 04:05:08 | 000,047,064 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/12/06 04:04:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HOME\Desktop\mbar
[2013/12/05 04:17:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HOME\Desktop\RK_Quarantine
[2013/12/04 12:17:00 | 000,000,000 | ---D | C] -- C:\FRST
[2013/12/04 12:16:14 | 001,060,421 | ---- | C] (Farbar) -- C:\Documents and Settings\HOME\Desktop\FRST.exe
[2013/12/04 11:27:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HOME\Desktop\tdsskiller
[2013/12/04 03:41:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\HOME\Application Data\Malwarebytes
[2013/12/04 03:41:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/12/04 03:41:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/12/04 03:41:43 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2013/12/04 03:41:43 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/12/04 03:26:33 | 000,688,992 | R--- | C] (Swearware) -- C:\Documents and Settings\HOME\Desktop\dds.com
[29 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/12/08 13:55:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\HOME\Desktop\OTL.exe
[2013/12/08 13:49:38 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/12/08 13:47:19 | 001,034,531 | ---- | M] (Thisisu) -- C:\Documents and Settings\HOME\Desktop\JRT.exe
[2013/12/08 13:44:30 | 000,002,228 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/12/08 13:44:14 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/12/08 13:44:10 | 1064,755,200 | -HS- | M] () -- C:\hiberfil.sys
[2013/12/08 13:40:47 | 001,110,034 | ---- | M] () -- C:\Documents and Settings\HOME\Desktop\adwcleaner.exe
[2013/12/08 04:09:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/12/08 04:05:18 | 001,060,421 | ---- | M] (Farbar) -- C:\Documents and Settings\HOME\Desktop\FRST.exe
[2013/12/08 03:55:55 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{3AC8987B-6FA2-4503-AB40-BD9C6C5DDA8F}.job
[2013/12/07 01:28:34 | 001,937,144 | ---- | M] (Bleeping Computer, LLC) -- C:\Documents and Settings\HOME\Desktop\rkill.exe
[2013/12/07 01:27:36 | 005,153,293 | R--- | M] (Swearware) -- C:\Documents and Settings\HOME\Desktop\RonM.exe
[2013/12/07 00:34:35 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013/12/06 04:08:26 | 000,105,176 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
[2013/12/06 04:06:20 | 000,047,064 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2013/12/06 04:00:58 | 000,445,044 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/12/06 04:00:57 | 000,072,754 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/12/06 03:57:43 | 000,000,250 | ---- | M] () -- C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
[2013/12/05 04:17:12 | 003,580,416 | ---- | M] () -- C:\Documents and Settings\HOME\Desktop\RogueKiller.exe
[2013/12/04 03:41:46 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/12/04 03:32:09 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2013/12/04 03:26:54 | 000,688,992 | R--- | M] (Swearware) -- C:\Documents and Settings\HOME\Desktop\dds.com
[2013/12/03 05:40:24 | 000,230,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[29 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/12/08 13:40:21 | 001,110,034 | ---- | C] () -- C:\Documents and Settings\HOME\Desktop\adwcleaner.exe
[2013/12/07 03:23:09 | 1064,755,200 | -HS- | C] () -- C:\hiberfil.sys
[2013/12/07 00:34:35 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2013/12/07 00:34:32 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2013/12/07 00:32:28 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2013/12/07 00:32:28 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2013/12/07 00:32:28 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2013/12/07 00:32:28 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2013/12/07 00:32:28 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2013/12/05 04:16:58 | 003,580,416 | ---- | C] () -- C:\Documents and Settings\HOME\Desktop\RogueKiller.exe
[2013/12/04 03:41:46 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/12/04 02:14:19 | 000,000,250 | ---- | C] () -- C:\Documents and Settings\HOME\Desktop\Virus and Malware Removal - TechSpot Forums.URL
[2013/12/03 13:14:15 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/03/23 08:49:49 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/10/04 10:53:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HOME\Local Settings\Application Data\{D933C6C2-7F02-4CA5-B3DA-C08E57DC30E5}
[2011/10/04 10:53:23 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\HOME\Local Settings\Application Data\{05E4BA26-224F-4A15-A64D-72AF215B55BD}
[2010/05/30 13:31:16 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\HOME\Local Settings\Application Data\housecall.guid.cache
[2009/09/20 18:00:06 | 000,000,148 | ---- | C] () -- C:\Documents and Settings\HOME\webct_upload_applet.properties
[2009/09/11 15:51:00 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\HOME\Local Settings\Application Data\fusioncache.dat
[2007/08/13 16:18:59 | 000,007,168 | ---- | C] () -- C:\Documents and Settings\HOME\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2009/09/11 09:24:50 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 18:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 06:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 18:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/09/19 16:48:56 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2009/12/30 01:04:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/09/10 10:38:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2013/11/03 15:39:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\HOME\Application Data\.minecraft
[2006/01/13 08:53:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\HOME\Application Data\InterVideo

========== Purity Check ==========


< End of report >
 
OTL Extras logfile created on: 12/8/2013 1:56:15 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\HOME\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1015.36 Mb Total Physical Memory | 547.43 Mb Available Physical Memory | 53.91% Memory free
2.40 Gb Paging File | 2.03 Gb Available in Paging File | 84.88% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 14.74 Gb Free Space | 39.55% Space Free | Partition Type: NTFS

Computer Name: DELL-D610 | User Name: HOME | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"FirstRunDisabled" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service -- (Apple Inc.)
"C:\Program Files\Java\jre7\bin\javaw.exe" = C:\Program Files\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary -- (Oracle Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0E0479F8-180F-4054-B4F7-17EE657F90BF}" = TIPCI
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{21E75254-410E-49C4-8981-2E1A2A2221F2}" = HP Diagnostic Assistant
"{2405665A-16C9-4D3A-B70E-F006220E1472}" = Overland
"{267868CE-6DFF-40F7-9C58-C01119B7B117}" = Fax
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2BBC9458-07CA-4843-848B-5C8146E5EFA8}" = CreativeProjects
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{2F71F2BA-B513-4113-969C-18A84D238E27}" = 1310
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{34A59AC3-6C5C-4A09-A7F5-369A37176C8A}" = AiOSoftware
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3AE681E0-4E8D-453F-950A-48534D3C0724}" = Copy
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{41254D7B-EADF-4078-AE4A-BD73B300EE86}" = Unload
"{457791C5-D702-4143-A7B2-2744BE9573F2}" = HP Software Update
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{595D0DE8-C38A-4432-B851-47DECC1A99BD}" = HP Unload DLL Patch
"{597D73A8-5FDB-4bc1-9893-40B54459F1BC}" = ProductContext
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7C70D3E4-8965-4C28-9B19-B526CD9F1C9F}" = ArcSoft MediaImpression for Kodak
"{7E369B27-13E2-41A5-9879-358EE1C8B5AD}" = Broadcom Gigabit Integrated Controller
"{80413011-029C-4D6B-B3AD-725DDE60B81C}" = 1310Trb
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Graphics Media Accelerator Driver for Mobile
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981FB376-8418-4EA8-BBED-9DE5AA63E7D5}" = SkinsHP1
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CB2512B-3EC4-43DF-8002-46BDAB5EDD1B}" = QuickProjects
"{9EEBF8D5-8712-4D1D-88F4-4CDC2D270BC3}" = PrintScreen
"{A1062847-0846-427A-92A1-BB8251A91E91}" = HP PSC & OfficeJet 4.2
"{A1DCC235-DACC-4E1F-8D11-D630634B4AEF}" = PhotoGallery
"{A2500497-FD32-493e-B8E5-28D6728DBEF5}" = Readme
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A4EA3AB4-E78C-4286-96DF-26035507CE55}" = AiO_Scan
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B32C75F2-7495-4D01-9431-C11E97D66F8C}" = DocProc
"{B3D5D4E0-E965-41C4-ABFD-A7B1AD0663C2}" = Director
"{B45D9FEE-1AF4-46F3-9A83-2545F81547F5}" = CreativeProjectsTemplates
"{B56D5B09-C4FB-4EA0-8EAD-7BC3E2715A2D}" = DocumentViewer
"{BCC992E5-5C81-4066-9B55-03DC10B24D21}" = InstantShare
"{BF018D2F-C788-4AB1-AB95-1280EAB8F13E}" = TrayApp
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E21658D0-8C83-4ADD-937B-6ED07F335ABA}" = 1310Tour
"{E90BEB5B-CFA0-418E-9ABB-4C4A7B0D9483}" = 1310_Help
"{EC8673DA-F96B-497E-B2DB-BC7B029FD680}" = BufferChm
"{F4F47155-5B4D-42AA-97F8-490BC52EA7F3}" = Destinations
"{F65787F3-B356-45EC-8DD0-0E6758EDBCEE}" = WebReg
"{FF26F7EA-BCEE-478C-9A1B-6B4F88717D73}" = CueTour
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ASL_Study_Guide" = ASL_Study_Guide
"ATI Display Driver" = ATI Display Driver
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"GalleryPlayer Images" = GalleryPlayer Images
"HP Photo & Imaging" = HP Image Zone 4.2
"ie8" = Windows Internet Explorer 8
"Installing HSP56 MicroModem Drivers" = PCTEL 2304WT V.9x MDC Modem Drivers
"InstallShield_{0E0479F8-180F-4054-B4F7-17EE657F90BF}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{C5BED10B-42A9-4142-B4C2-008C0FDE27D5}" = O2Micro Smartcard Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PopularScreensavers_7ibar Uninstall Firefox" = PopularScreensavers Firefox Toolbar
"PopularScreensavers_7ibar Uninstall Internet Explorer" = PopularScreensavers Internet Explorer Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"YTdetect" = Yahoo! Detect

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/25/2013 9:30:08 PM | Computer Name = DELL-D610 | Source = CltMngSvc | ID = 1000
Description =

Error - 11/3/2013 4:27:25 PM | Computer Name = DELL-D610 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 11/3/2013 4:33:39 PM | Computer Name = DELL-D610 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/3/2013 5:11:41 PM | Computer Name = DELL-D610 | Source = .NET Runtime Optimization Service | ID = 1101
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Failed to compile: System, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
. Error code = 0x80131506

Error - 12/3/2013 7:43:04 AM | Computer Name = DELL-D610 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved

Error - 12/3/2013 7:45:59 AM | Computer Name = DELL-D610 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/3/2013 7:47:25 AM | Computer Name = DELL-D610 | Source = Application Hang | ID = 1002
Description = Hanging application RegCleanPro.exe, version 6.21.65.2601, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/3/2013 12:54:19 PM | Computer Name = DELL-D610 | Source = CltMngSvc | ID = 1000
Description =

Error - 12/4/2013 5:07:48 AM | Computer Name = DELL-D610 | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/4/2013 5:16:09 AM | Computer Name = DELL-D610 | Source = Application Hang | ID = 1002
Description = Hanging application rundll32.exe, version 5.1.2600.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 12/7/2013 3:31:46 AM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 12/7/2013 3:31:46 AM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD Fips intelppm IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL

Error - 12/7/2013 5:23:18 AM | Computer Name = DELL-D610 | Source = SCardSvr | ID = 602
Description = WDM Reader driver initialization cannot open reader device: The system
cannot find the path specified.

Error - 12/7/2013 5:23:26 AM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 12/8/2013 5:35:44 AM | Computer Name = DELL-D610 | Source = SCardSvr | ID = 602
Description = WDM Reader driver initialization cannot open reader device: The system
cannot find the path specified.

Error - 12/8/2013 5:35:47 AM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 12/8/2013 3:37:39 PM | Computer Name = DELL-D610 | Source = SCardSvr | ID = 602
Description = WDM Reader driver initialization cannot open reader device: The system
cannot find the path specified.

Error - 12/8/2013 3:37:41 PM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2

Error - 12/8/2013 3:44:18 PM | Computer Name = DELL-D610 | Source = SCardSvr | ID = 602
Description = WDM Reader driver initialization cannot open reader device: The system
cannot find the path specified.

Error - 12/8/2013 3:44:20 PM | Computer Name = DELL-D610 | Source = Service Control Manager | ID = 7000
Description = The helpsvc service failed to start due to the following error: %%2


< End of report >
 
redtarget.gif
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
Code:
:OTL
SRV - File not found [Auto | Stopped] -- C:\ComboFix\pev.3XE EXEC /I C:\ComboFix\HIDEC.3XE C:\ComboFix\SWREG.3XE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q -- (PEVSystemStart)
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe -- (McComponentHostService)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\atimtag.sys -- (atimtag)
FF - user.js - File not found
O3 - HKU\S-1-5-21-1275210071-507921405-1060284298-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)


:Services

:Reg

:Files
C:\FRST

:Commands
[purity]
[emptytemp]
[emptyjava]
[emptyflash]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.
Last scans...

redtarget.gif
Download Security Check from here or here and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


redtarget.gif
Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

redtarget.gif
Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.

redtarget.gif
Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
All processes killed
========== OTL ==========
Service PEVSystemStart stopped successfully!
Service PEVSystemStart deleted successfully!
File C:\ComboFix\pev.3XE EXEC /I C:\ComboFix\HIDEC.3XE C:\ComboFix\SWREG.3XE ACL HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_Beep /RESET /Q not found.
Service McComponentHostService stopped successfully!
Service McComponentHostService deleted successfully!
File C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe not found.
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File %SystemRoot%\System32\hidserv.dll not found.
Service WDICA stopped successfully!
Service WDICA deleted successfully!
Service UIUSys stopped successfully!
Service UIUSys deleted successfully!
File system32\drivers\UIUSys.sys not found.
Service PDRFRAME stopped successfully!
Service PDRFRAME deleted successfully!
Service PDRELI stopped successfully!
Service PDRELI deleted successfully!
Service PDFRAME stopped successfully!
Service PDFRAME deleted successfully!
Service PDCOMP stopped successfully!
Service PDCOMP deleted successfully!
Service PCIDump stopped successfully!
Service PCIDump deleted successfully!
Service lbrtfdc stopped successfully!
Service lbrtfdc deleted successfully!
Service i2omgmt stopped successfully!
Service i2omgmt deleted successfully!
Service Changer stopped successfully!
Service Changer deleted successfully!
Service atimtag stopped successfully!
Service atimtag deleted successfully!
File System32\DRIVERS\atimtag.sys not found.
Registry value HKEY_USERS\S-1-5-21-1275210071-507921405-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
File Animation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab not found.
Starting removal of ActiveX control DirectAnimation Java Classes
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\DirectAnimation Java Classes\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\DirectAnimation Java Classes\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\FRST\Quarantine\PopularScreensavers_7i\bar\Settings folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\Message\COMMON folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\Message folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\IE9Mesg folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\History folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\gen1 folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\Cache folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\1.bin\ThirdPartyInstallers folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\1.bin\chrome folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar\1.bin folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i\bar folder moved successfully.
C:\FRST\Quarantine\PopularScreensavers_7i folder moved successfully.
C:\FRST\Quarantine\7iffxtbr@PopularScreensavers_7i.com\chrome folder moved successfully.
C:\FRST\Quarantine\7iffxtbr@PopularScreensavers_7i.com folder moved successfully.
C:\FRST\Quarantine folder moved successfully.
C:\FRST\Logs folder moved successfully.
C:\FRST\Hives\Users\00000002 folder moved successfully.
C:\FRST\Hives\Users\00000001 folder moved successfully.
C:\FRST\Hives\Users folder moved successfully.
C:\FRST\Hives folder moved successfully.
C:\FRST folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 55415 bytes
->Temporary Internet Files folder emptied: 110692 bytes
->Java cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Java cache emptied: 12118713 bytes

User: HOME
->Temp folder emptied: 1220002734 bytes
->Temporary Internet Files folder emptied: 85666723 bytes
->Java cache emptied: 17829213 bytes
->FireFox cache emptied: 23304462 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 523 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 6821075 bytes

User: NetworkService
->Temp folder emptied: 831462 bytes
->Temporary Internet Files folder emptied: 61643568 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 5450930 bytes
%systemroot%\System32 .tmp files removed: 51166737 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 40199624 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 299295099 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 1353469 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,741.00 mb


[EMPTYJAVA]

User: Administrator
->Java cache emptied: 0 bytes

User: All Users

User: Default User
->Java cache emptied: 0 bytes

User: HOME
->Java cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: HOME
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 12082013_234555
Files\Folders moved on Reboot...
File\Folder C:\WINDOWS\temp\TMP0000000138E3164FA8F97D54 not found!
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
 
Results of screen317's Security Check version 0.99.77
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Java 7 Update 25
Java(TM) 6 Update 7
Java version out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (Toolbar.)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials msseces.exe
Windows Defender MSMpEng.exe
Microsoft Security Client Antimalware MsMpEng.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 0%
````````````````````End of Log``````````````````````
 
Farbar Service Scanner Version: 05-12-2013
Ran by HOME (administrator) on 08-12-2013 at 23:58:35
Running from "C:\Documents and Settings\HOME\Desktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.

Windows Firewall:
=============
Firewall Disabled Policy:
==================
"HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\\EnableFirewall" registry value does not exist.

System Restore:
============
System Restore Disabled Policy:
========================

Security Center:
============

Windows Update:
============
Windows Autoupdate Disabled Policy:
============================

Other Services:
==============

File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
Extra List:
=======
Gpc(3) IPSec(5) irda(10) NetBT(6) PSched(7) RFCOMM(9) Tcpip(4)
0x0A0000000500000001000000020000000300000004000000060000000700000008000000090000000A000000
IpSec Tag value is correct.
**** End of log ****
 
Back