TechSpot

I have the "Malwarebytes has successfully blocked access to malicious IP" problem.

Solved
By muddie
May 31, 2012
  1. About 2 weeks ago, my laptop was infected with the annoying "Congratulations, You've Won" virus and the fan was on constantly+slow performance. I installed Malwarebytes and did full scan which turned up 20 malwares which I deleted.
    After deleting those malwares I don't hear the "Congratulations, You've Won" phrase every time I open a website, but my laptop's fan is still acting up and my computer's feels kind of slow. Furthermore, I constantly get the "malwarebytes has successfull blocked access to "ip"" notification that pops up on the bottom right corner.
    My laptop is HP-DV7 and about 1 year old.
    P.S- This is my first time posting, so if I am missing any info or important details please tell me.

    Thanks
     
  2. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    Welcome aboard [​IMG]

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     
  3. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Hi, Thanks for the reply.

    I am having problems with Step 3 on the list you linked me. I downloaded gmer but when it scans, it ends up with "GMER didn't find any modifications". So it won't produce the log.

    I downloaded the Main Mirror version and turned off all the real time active protection security programs before the scan.
    In the GMER > Rookit/Malware tab, it only has "services" ," Registry", "Files" -"C:/", "ADS" selected. The other ones on the list can't be selected for the scan. Am I missing a step in downloading or using GMER?


    Thanks
     
  4. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Also, I can't seem to download DDS. When I click a DDS download link, it only opens a blank page and nothing is being downloaded.
     
  5. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    If you read our instructions carefully....
    What about Malwarebytes?

    I uploaded DDS for you here: http://www.uploadmb.com/dw.php?id=1338580613
     
  6. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Yes, I have the Malwarebytes logs:


    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Michael :: MICHAEL-HP [administrator]

    Protection: Enabled

    5/28/2012 10:12:15 PM
    mbam-log-2012-05-28 (22-12-15).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 386181
    Time elapsed: 53 minute(s), 32 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 15
    HKCR\CrossriderApp0003491.BHO (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCR\CrossriderApp0003491.BHO.1 (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCR\CrossriderApp0003491.FBApi (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCR\CrossriderApp0003491.FBApi.1 (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCR\CrossriderApp0003491.Sandbox (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCR\CrossriderApp0003491.Sandbox.1 (PUP.CrossFire.Gen) -> Quarantined and deleted successfully.
    HKCU\Software\Cr_Installer\3491 (Adware.GamePlayLab) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKCR\CLSID\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKCR\TypeLib\{44444444-4444-4444-4444-440044344491} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKCR\Interface\{55555555-5555-5555-5555-550055345591} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011341191} (PUP.GamePlayLab) -> Quarantined and deleted successfully.

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 5
    C:\Program Files (x86)\iBryte\playbryte\iBryteDesktop.exe (Adware.IBryte) -> Quarantined and deleted successfully.
    C:\Users\Michael\Downloads\aMSN_Setup (1).exe (Adware.IBryte) -> Quarantined and deleted successfully.
    C:\Users\Michael\Downloads\aMSN_Setup (2).exe (Adware.IBryte) -> Quarantined and deleted successfully.
    C:\Users\Michael\Downloads\aMSN_Setup.exe (Adware.IBryte) -> Quarantined and deleted successfully.
    C:\Program Files (x86)\Vid-Saver\Vid-Saver.dll (PUP.GamePlayLab) -> Quarantined and deleted successfully.

    (end)

    Malwarebytes Anti-Malware (Trial) 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.05.29.05

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Michael :: MICHAEL-HP [administrator]

    Protection: Enabled

    5/29/2012 3:27:02 PM
    mbam-log-2012-05-29 (15-27-02).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 385443
    Time elapsed: 53 minute(s), 23 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  7. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Yeah, I thought it was a bad thing if GMER couldn't produce any logs.
     
  8. muddie

    muddie TS Rookie Topic Starter Posts: 45

    DDS logs:


    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421
    Run by Michael at 17:10:19 on 2012-06-01
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8140.5716 [GMT -4:00]
    .
    AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    c:\Program Files\Microsoft Security Client\MsMpEng.exe
    C:\Windows\system32\atiesrxx.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\IDT\WDM\STacSV64.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\Hpservice.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\atieclxx.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k WbioSvcGroup
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\IDT\WDM\AESTSr64.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Windows\SysWOW64\ezSharedSvcHost.exe
    C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
    C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\IDT\WDM\sttray64.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Windows\System32\StikyNot.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
    C:\Program Files (x86)\CyberLink\Shared files\brs.exe
    C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Michael's File\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Michael's File\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe
    C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
    C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Michael\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uInternet Settings,ProxyOverride = *.local
    mWinlogon: Userinit=userinit.exe,
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - No File
    BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: TrueSuite Website Log On: {8590886e-ec8c-43c1-a32c-e4c2b0b6395b} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
    TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
    uRun: [Google Update] "C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
    mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
    mRun: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
    mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [<NO NAME>]
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [Malwarebytes' Anti-Malware] "C:\Michael's File\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    TCP: Interfaces\{050D4D5E-7233-4EA6-8637-82D260679035} : DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79} : DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79}\1427963747F63627164756 : DhcpNameServer = 8.8.8.8 8.8.4.4
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79}\368656E6769716E676 : DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79}\46C696E6B6 : DhcpNameServer = 192.168.0.1
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79}\5777D257E637563657275646 : DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    TCP: Interfaces\{10AD0EE9-65C5-4A83-BD76-E67D5001EE79}\5777D27657563747 : DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
    BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO-X64: 0x1 - No File
    BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO-X64: HP Print Enhancer - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - No File
    BHO-X64: StartNow Toolbar Helper: {6E13D095-45C3-4271-9475-F3B48227DD9F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
    BHO-X64: StartNowToolbarHelper - No File
    BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO-X64: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
    BHO-X64: TSBHO Class - No File
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    BHO-X64: HP Smart BHO Class - No File
    TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
    TB-X64: StartNow Toolbar: {5911488E-9D1E-40ec-8CBB-06B231CC153F} - C:\Program Files (x86)\StartNow Toolbar\Toolbar32.dll
    TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
    mRun-x64: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun-x64: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
    mRun-x64: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
    mRun-x64: [BDRegion] C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
    mRun-x64: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    mRun-x64: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun-x64: [(Default)]
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [Malwarebytes' Anti-Malware] "C:\Michael's File\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
    IE-X64: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
    SEH-X64: EasyBits ShellExecute Hook: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]
    R2 AESTFilters;Andrea ST Filters Service;C:\Program Files\IDT\WDM\AESTSr64.exe [2011-6-2 89600]
    R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?]
    R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe [2011-4-8 514232]
    R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-2-18 265544]
    R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
    R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
    R2 hpsrv;HP Service;C:\Windows\system32\Hpservice.exe --> C:\Windows\system32\Hpservice.exe [?]
    R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-6-14 26680]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-6-2 13336]
    R2 MBAMService;MBAMService;C:\Michael's File\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-28 654408]
    R2 RoxioNow Service;RoxioNow Service;C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344]
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-6-2 2656280]
    R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe [2012-4-20 265952]
    R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
    R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
    R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
    R3 hpCMSrv;HP Connection Manager 4.0 Service;C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-2-15 1071160]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
    R3 intelkmd;intelkmd;C:\Windows\system32\DRIVERS\igdpmd64.sys --> C:\Windows\system32\DRIVERS\igdpmd64.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 MEIx64;Intel(R) Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
    R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\system32\DRIVERS\RtsPStor.sys --> C:\Windows\system32\DRIVERS\RtsPStor.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
    R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
    S2 CLKMSVC10_38F51D56;CyberLink Product - 2011/06/02 02:04:43;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2011-1-25 241648]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 HP Support Assistant Service;HP Support Assistant Service;"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe" --> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [?]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-21 257696]
    S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]
    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2011-1-5 340240]
    S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\system32\DRIVERS\VSTAZL6.SYS --> C:\Windows\system32\DRIVERS\VSTAZL6.SYS [?]
    S3 SrvHsfV92;SrvHsfV92;C:\Windows\system32\DRIVERS\VSTDPV6.SYS --> C:\Windows\system32\DRIVERS\VSTDPV6.SYS [?]
    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\system32\DRIVERS\VSTCNXT6.SYS --> C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== Created Last 30 ================
    .
    2012-06-01 14:41:158955792----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D2E8E609-7BCB-45C7-A58F-F730FF81AC65}\mpengine.dll
    2012-05-30 21:18:208955792----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-05-29 02:11:19--------d-----w-C:\Users\Michael\AppData\Roaming\Malwarebytes
    2012-05-29 02:11:10--------d-----w-C:\ProgramData\Malwarebytes
    2012-05-29 02:11:0924904----a-w-C:\Windows\System32\drivers\mbam.sys
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
    2012-05-22 01:48:06159744----a-w-C:\Program Files (x86)\Internet Explorer\Plugins\npqtplugin.dll
    2012-05-21 21:45:42--------d-----w-C:\Users\Michael\AppData\Local\Vid-Saver
    2012-05-21 21:45:41--------d-----w-C:\Program Files (x86)\Vid-Saver
    2012-05-21 15:48:1070304----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-05-21 15:48:10419488----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-05-18 13:34:16--------d-----w-C:\Users\Michael\AppData\Roaming\StartNow Toolbar
    2012-05-11 22:12:401544704----a-w-C:\Windows\System32\DWrite.dll
    2012-05-11 22:12:391077248----a-w-C:\Windows\SysWow64\DWrite.dll
    2012-05-11 22:12:385559664----a-w-C:\Windows\System32\ntoskrnl.exe
    2012-05-11 22:12:383146240----a-w-C:\Windows\System32\win32k.sys
    2012-05-11 22:12:373968368----a-w-C:\Windows\SysWow64\ntkrnlpa.exe
    2012-05-11 22:12:373913072----a-w-C:\Windows\SysWow64\ntoskrnl.exe
    2012-05-11 22:12:2275120----a-w-C:\Windows\System32\drivers\partmgr.sys
    2012-05-11 22:12:151918320----a-w-C:\Windows\System32\drivers\tcpip.sys
    2012-05-11 22:12:14936960----a-w-C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-05-11 22:12:141367552----a-w-C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
    2012-05-07 20:07:43--------d-----w-C:\Users\Michael\AppData\Local\Windows Live
    2012-05-07 20:07:42--------d-----w-C:\Users\Michael\AppData\Local\{E7BE3DF1-D458-46C7-A2DD-B31497BAE0AA}
    2012-05-07 20:07:42--------d-----w-C:\Users\Michael\AppData\Local\{20BDDC35-3649-4B33-89C6-89525270CBFA}
    .
    ==================== Find3M ====================
    .
    2012-04-19 00:56:3094208----a-w-C:\Windows\SysWow64\QuickTimeVR.qtx
    2012-04-19 00:56:3069632----a-w-C:\Windows\SysWow64\QuickTime.qts
    2012-03-21 00:44:1298688----a-w-C:\Windows\System32\drivers\NisDrvWFP.sys
    2012-03-21 00:44:12203888----a-w-C:\Windows\System32\drivers\MpFilter.sys
    .
    ============= FINISH: 17:10:37.65 ===============
     
  9. muddie

    muddie TS Rookie Topic Starter Posts: 45

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 6/10/2011 4:00:54 PM
    System Uptime: 6/1/2012 11:33:48 AM (6 hours ago)
    .
    Motherboard: Hewlett-Packard | | 165A
    Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz | CPU1 | 2001/1333mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 684 GiB total, 600.791 GiB free.
    D: is FIXED (NTFS) - 14 GiB total, 1.61 GiB free.
    E: is CDROM ()
    F: is FIXED (FAT32) - 0 GiB total, 0.083 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0157
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0157
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0059
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0059
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0224
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0224
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: DesignJet 5000PS (C6091A)
    Device ID: ROOT\MULTIFUNCTION\0118
    Manufacturer: Hewlett-Packard
    Name: DesignJet 5000PS (C6091A)
    PNP Device ID: ROOT\MULTIFUNCTION\0118
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0020
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0020
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 3600
    Device ID: ROOT\MULTIFUNCTION\0177
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 3600
    PNP Device ID: ROOT\MULTIFUNCTION\0177
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet M1522n MFP
    Device ID: ROOT\MULTIFUNCTION\0079
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet M1522n MFP
    PNP Device ID: ROOT\MULTIFUNCTION\0079
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 9000 Series
    Device ID: ROOT\MULTIFUNCTION\0244
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 9000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0244
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0138
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0138
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0040
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0040
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp color LaserJet 3700
    Device ID: ROOT\MULTIFUNCTION\0203
    Manufacturer: Hewlett-Packard
    Name: hp color LaserJet 3700
    PNP Device ID: ROOT\MULTIFUNCTION\0203
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0099
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0099
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0271
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0271
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0001
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0001
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0158
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0158
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp color LaserJet 4650
    Device ID: ROOT\MULTIFUNCTION\0060
    Manufacturer: Hewlett-Packard
    Name: hp color LaserJet 4650
    PNP Device ID: ROOT\MULTIFUNCTION\0060
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0225
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0225
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0119
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0119
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet M2727nf MFP
    Device ID: ROOT\MULTIFUNCTION\0021
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet M2727nf MFP
    PNP Device ID: ROOT\MULTIFUNCTION\0021
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 600 M602
    Device ID: ROOT\MULTIFUNCTION\0178
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 600 M602
    PNP Device ID: ROOT\MULTIFUNCTION\0178
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0080
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0080
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0245
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0245
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 2605dn
    Device ID: ROOT\MULTIFUNCTION\0139
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 2605dn
    PNP Device ID: ROOT\MULTIFUNCTION\0139
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8100 Series
    Device ID: ROOT\MULTIFUNCTION\0041
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0041
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0204
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0204
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0100
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0100
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P1505n
    Device ID: ROOT\MULTIFUNCTION\0272
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P1505n
    PNP Device ID: ROOT\MULTIFUNCTION\0272
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4515
    Device ID: ROOT\MULTIFUNCTION\0002
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4515
    PNP Device ID: ROOT\MULTIFUNCTION\0002
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0159
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0159
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0061
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0061
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0226
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0226
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1300n
    Device ID: ROOT\MULTIFUNCTION\0120
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1300n
    PNP Device ID: ROOT\MULTIFUNCTION\0120
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2100 Series
    Device ID: ROOT\MULTIFUNCTION\0022
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 2100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0022
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0179
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0179
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 1022n
    Device ID: ROOT\MULTIFUNCTION\0081
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 1022n
    PNP Device ID: ROOT\MULTIFUNCTION\0081
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0246
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0246
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet Professional M1212nf MFP
    Device ID: ROOT\MULTIFUNCTION\0140
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet Professional M1212nf MFP
    PNP Device ID: ROOT\MULTIFUNCTION\0140
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0042
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0042
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2300 series
    Device ID: ROOT\MULTIFUNCTION\0205
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2300 series
    PNP Device ID: ROOT\MULTIFUNCTION\0205
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8100 Series
    Device ID: ROOT\MULTIFUNCTION\0101
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0101
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0003
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0003
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0160
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0160
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0062
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0062
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0227
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0227
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0121
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0121
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0023
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0023
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0180
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0180
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0082
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0082
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0247
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0247
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0141
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0141
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0043
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0043
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0206
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0206
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0102
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0102
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0004
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0004
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8150 Series
    Device ID: ROOT\MULTIFUNCTION\0161
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8150 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0161
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 600 M602
    Device ID: ROOT\MULTIFUNCTION\0063
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 600 M602
    PNP Device ID: ROOT\MULTIFUNCTION\0063
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0228
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0228
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0122
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0122
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0024
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0024
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0181
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0181
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0083
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0083
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0248
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0248
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0142
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0142
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 5200
    Device ID: ROOT\MULTIFUNCTION\0044
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 5200
    PNP Device ID: ROOT\MULTIFUNCTION\0044
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0207
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0207
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0103
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0103
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0005
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0005
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Designjet T610 24in
    Device ID: ROOT\MULTIFUNCTION\0162
    Manufacturer: Hewlett-Packard
    Name: HP Designjet T610 24in
    PNP Device ID: ROOT\MULTIFUNCTION\0162
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0064
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0064
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0229
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0229
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 5100 Series
    Device ID: ROOT\MULTIFUNCTION\0123
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 5100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0123
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0025
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0025
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0182
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0182
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0084
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0084
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0249
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0249
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0143
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0143
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1300n
    Device ID: ROOT\MULTIFUNCTION\0045
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1300n
    PNP Device ID: ROOT\MULTIFUNCTION\0045
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0208
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0208
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0104
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0104
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP5520 Series
    Device ID: ROOT\MULTIFUNCTION\0006
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP5520 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0006
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0163
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0163
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4515
    Device ID: ROOT\MULTIFUNCTION\0065
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4515
    PNP Device ID: ROOT\MULTIFUNCTION\0065
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1300n
    Device ID: ROOT\MULTIFUNCTION\0230
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1300n
    PNP Device ID: ROOT\MULTIFUNCTION\0230
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0124
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0124
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP4005
    Device ID: ROOT\MULTIFUNCTION\0026
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP4005
    PNP Device ID: ROOT\MULTIFUNCTION\0026
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8100 Series
    Device ID: ROOT\MULTIFUNCTION\0183
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0183
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0085
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0085
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0251
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0251
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0144
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0144
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P1505n
    Device ID: ROOT\MULTIFUNCTION\0046
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P1505n
    PNP Device ID: ROOT\MULTIFUNCTION\0046
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4515
    Device ID: ROOT\MULTIFUNCTION\0209
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4515
    PNP Device ID: ROOT\MULTIFUNCTION\0209
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P1505n
    Device ID: ROOT\MULTIFUNCTION\0105
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P1505n
    PNP Device ID: ROOT\MULTIFUNCTION\0105
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2200
    Device ID: ROOT\MULTIFUNCTION\0007
    Manufacturer:
    Name: HP LaserJet 2200
    PNP Device ID: ROOT\MULTIFUNCTION\0007
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0164
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0164
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 3600
    Device ID: ROOT\MULTIFUNCTION\0066
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 3600
    PNP Device ID: ROOT\MULTIFUNCTION\0066
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0231
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0231
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0125
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0125
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0027
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0027
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 2820
    Device ID: ROOT\MULTIFUNCTION\0184
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 2820
    PNP Device ID: ROOT\MULTIFUNCTION\0184
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0086
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0086
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 1022n
    Device ID: ROOT\MULTIFUNCTION\0252
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 1022n
    PNP Device ID: ROOT\MULTIFUNCTION\0252
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0145
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0145
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 5200
    Device ID: ROOT\MULTIFUNCTION\0047
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 5200
    PNP Device ID: ROOT\MULTIFUNCTION\0047
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet M3035 MFP
    Device ID: ROOT\MULTIFUNCTION\0210
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet M3035 MFP
    PNP Device ID: ROOT\MULTIFUNCTION\0210
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0106
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0106
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 600 M602
    Device ID: ROOT\MULTIFUNCTION\0008
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 600 M602
    PNP Device ID: ROOT\MULTIFUNCTION\0008
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2420
    Device ID: ROOT\MULTIFUNCTION\0165
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2420
    PNP Device ID: ROOT\MULTIFUNCTION\0165
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0067
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0067
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0232
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0232
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 6MP
    Device ID: ROOT\MULTIFUNCTION\0126
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 6MP
    PNP Device ID: ROOT\MULTIFUNCTION\0126
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0028
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0028
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2100 Series
    Device ID: ROOT\MULTIFUNCTION\0185
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 2100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0185
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP3525
    Device ID: ROOT\MULTIFUNCTION\0087
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP3525
    PNP Device ID: ROOT\MULTIFUNCTION\0087
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0253
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0253
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0146
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0146
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0048
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0048
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet M3035 MFP
    Device ID: ROOT\MULTIFUNCTION\0212
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet M3035 MFP
    PNP Device ID: ROOT\MULTIFUNCTION\0212
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0107
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0107
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0009
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0009
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0166
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0166
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0068
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0068
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0233
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0233
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: FAX-4750e
    Device ID: ROOT\MULTIFUNCTION\0127
    Manufacturer: Brother
    Name: FAX-4750e
    PNP Device ID: ROOT\MULTIFUNCTION\0127
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0029
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0029
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0186
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0186
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2100 Series
    Device ID: ROOT\MULTIFUNCTION\0088
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 2100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0088
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0254
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0254
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0147
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0147
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0049
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0049
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0213
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0213
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0108
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0108
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0010
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0010
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0167
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0167
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0069
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0069
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0234
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0234
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0128
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0128
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0030
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0030
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0189
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0189
    Service:
     
  10. muddie

    muddie TS Rookie Topic Starter Posts: 45

    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0089
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0089
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0255
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0255
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0148
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0148
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0050
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0050
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 2600n
    Device ID: ROOT\MULTIFUNCTION\0214
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 2600n
    PNP Device ID: ROOT\MULTIFUNCTION\0214
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0109
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0109
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0011
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0011
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0168
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0168
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0070
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0070
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0235
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0235
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0129
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0129
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0031
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0031
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Lexmark E323
    Device ID: ROOT\MULTIFUNCTION\0192
    Manufacturer: Lexmark International
    Name: Lexmark E323
    PNP Device ID: ROOT\MULTIFUNCTION\0192
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0090
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0090
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2420
    Device ID: ROOT\MULTIFUNCTION\0256
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2420
    PNP Device ID: ROOT\MULTIFUNCTION\0256
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0149
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0149
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8000 Series
    Device ID: ROOT\MULTIFUNCTION\0051
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0051
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0215
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0215
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0110
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0110
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0012
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0012
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0169
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0169
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0071
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0071
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0236
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0236
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Laser Printer 5100cn
    Device ID: ROOT\MULTIFUNCTION\0130
    Manufacturer: Dell
    Name: Laser Printer 5100cn
    PNP Device ID: ROOT\MULTIFUNCTION\0130
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0032
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0032
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0193
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0193
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0091
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0091
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0257
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0257
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0150
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0150
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0052
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0052
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0217
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0217
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP2025dn
    Device ID: ROOT\MULTIFUNCTION\0111
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP2025dn
    PNP Device ID: ROOT\MULTIFUNCTION\0111
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 2600n
    Device ID: ROOT\MULTIFUNCTION\0013
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 2600n
    PNP Device ID: ROOT\MULTIFUNCTION\0013
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0170
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0170
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0072
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0072
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0237
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0237
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0131
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0131
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0033
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0033
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0195
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0195
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0092
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0092
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 8000 Series
    Device ID: ROOT\MULTIFUNCTION\0260
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 8000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0260
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 3052
    Device ID: ROOT\MULTIFUNCTION\0151
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 3052
    PNP Device ID: ROOT\MULTIFUNCTION\0151
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP3525
    Device ID: ROOT\MULTIFUNCTION\0053
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP3525
    PNP Device ID: ROOT\MULTIFUNCTION\0053
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0218
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0218
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0112
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0112
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0014
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0014
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0171
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0171
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0073
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0073
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0238
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0238
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0132
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0132
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4515
    Device ID: ROOT\MULTIFUNCTION\0034
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4515
    PNP Device ID: ROOT\MULTIFUNCTION\0034
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0196
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0196
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 4700
    Device ID: ROOT\MULTIFUNCTION\0093
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 4700
    PNP Device ID: ROOT\MULTIFUNCTION\0093
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3005
    Device ID: ROOT\MULTIFUNCTION\0262
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3005
    PNP Device ID: ROOT\MULTIFUNCTION\0262
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet 4700
    Device ID: ROOT\MULTIFUNCTION\0152
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet 4700
    PNP Device ID: ROOT\MULTIFUNCTION\0152
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0054
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0054
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0219
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0219
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0113
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0113
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0015
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0015
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0172
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0172
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0074
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0074
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2420
    Device ID: ROOT\MULTIFUNCTION\0239
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2420
    PNP Device ID: ROOT\MULTIFUNCTION\0239
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0133
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0133
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Designjet Z3200ps 44in Photo
    Device ID: ROOT\MULTIFUNCTION\0035
    Manufacturer: Hewlett-Packard
    Name: HP Designjet Z3200ps 44in Photo
    PNP Device ID: ROOT\MULTIFUNCTION\0035
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0197
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0197
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0094
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0094
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4015
    Device ID: ROOT\MULTIFUNCTION\0263
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4015
    PNP Device ID: ROOT\MULTIFUNCTION\0263
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0153
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0153
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0055
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0055
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2300 series
    Device ID: ROOT\MULTIFUNCTION\0220
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2300 series
    PNP Device ID: ROOT\MULTIFUNCTION\0220
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0114
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0114
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2430
    Device ID: ROOT\MULTIFUNCTION\0016
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2430
    PNP Device ID: ROOT\MULTIFUNCTION\0016
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0173
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0173
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0075
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0075
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0240
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0240
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0134
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0134
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0036
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0036
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0198
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0198
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0095
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0095
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP3525
    Device ID: ROOT\MULTIFUNCTION\0265
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP3525
    PNP Device ID: ROOT\MULTIFUNCTION\0265
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0154
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0154
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0056
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0056
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0221
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0221
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0115
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0115
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 9040
    Device ID: ROOT\MULTIFUNCTION\0017
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 9040
    PNP Device ID: ROOT\MULTIFUNCTION\0017
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0174
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0174
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2015 Series
    Device ID: ROOT\MULTIFUNCTION\0076
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2015 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0076
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0241
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0241
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0135
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0135
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4200
    Device ID: ROOT\MULTIFUNCTION\0037
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4200
    PNP Device ID: ROOT\MULTIFUNCTION\0037
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2300 series
    Device ID: ROOT\MULTIFUNCTION\0199
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2300 series
    PNP Device ID: ROOT\MULTIFUNCTION\0199
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2100 Series
    Device ID: ROOT\MULTIFUNCTION\0096
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 2100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0096
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2300 series
    Device ID: ROOT\MULTIFUNCTION\0266
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2300 series
    PNP Device ID: ROOT\MULTIFUNCTION\0266
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 9050
    Device ID: ROOT\MULTIFUNCTION\0155
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 9050
    PNP Device ID: ROOT\MULTIFUNCTION\0155
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0057
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0057
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0222
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0222
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0116
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0116
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0018
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0018
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4050 Series
    Device ID: ROOT\MULTIFUNCTION\0175
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4050 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0175
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0077
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0077
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0242
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0242
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP Color LaserJet CP2025n
    Device ID: ROOT\MULTIFUNCTION\0136
    Manufacturer: Hewlett-Packard
    Name: HP Color LaserJet CP2025n
    PNP Device ID: ROOT\MULTIFUNCTION\0136
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0038
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0038
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4250
    Device ID: ROOT\MULTIFUNCTION\0201
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4250
    PNP Device ID: ROOT\MULTIFUNCTION\0201
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4000 Series
    Device ID: ROOT\MULTIFUNCTION\0097
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4000 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0097
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 2100 Series
    Device ID: ROOT\MULTIFUNCTION\0267
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 2100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0267
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0156
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0156
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 2420
    Device ID: ROOT\MULTIFUNCTION\0058
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 2420
    PNP Device ID: ROOT\MULTIFUNCTION\0058
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 4100 Series
    Device ID: ROOT\MULTIFUNCTION\0223
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 4100 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0223
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0117
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0117
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0019
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0019
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet CP1025nw
    Device ID: ROOT\MULTIFUNCTION\0176
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet CP1025nw
    PNP Device ID: ROOT\MULTIFUNCTION\0176
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P2055dn
    Device ID: ROOT\MULTIFUNCTION\0078
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P2055dn
    PNP Device ID: ROOT\MULTIFUNCTION\0078
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 4350
    Device ID: ROOT\MULTIFUNCTION\0243
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 4350
    PNP Device ID: ROOT\MULTIFUNCTION\0243
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P3010 Series
    Device ID: ROOT\MULTIFUNCTION\0137
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P3010 Series
    PNP Device ID: ROOT\MULTIFUNCTION\0137
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P1505n
    Device ID: ROOT\MULTIFUNCTION\0039
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P1505n
    PNP Device ID: ROOT\MULTIFUNCTION\0039
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0202
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0202
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet 1022n
    Device ID: ROOT\MULTIFUNCTION\0098
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet 1022n
    PNP Device ID: ROOT\MULTIFUNCTION\0098
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: hp LaserJet 1320 series
    Device ID: ROOT\MULTIFUNCTION\0269
    Manufacturer: Hewlett-Packard
    Name: hp LaserJet 1320 series
    PNP Device ID: ROOT\MULTIFUNCTION\0269
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: HP LaserJet P4014
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: Hewlett-Packard
    Name: HP LaserJet P4014
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:
    .
    ==== System Restore Points ===================
    .
    RP152: 5/15/2012 5:23:15 PM - Windows Update
    RP153: 5/19/2012 4:34:10 PM - Windows Update
    RP154: 5/22/2012 9:59:51 PM - Windows Update
    RP155: 5/26/2012 12:06:42 AM - Windows Update
    RP156: 5/29/2012 2:39:46 PM - Windows Update
    .
    ==== Installed Programs ======================
    .
    Update for Microsoft Office 2007 (KB2508958)
    Adobe Flash Player 11 ActiveX
    Adobe Reader X (10.1.3) MUI
    Adobe Shockwave Player 11.5
    Agatha Christie - Peril at End House
    aMSN 0.98.4
    Apple Application Support
    Apple Software Update
    Bejeweled 2 Deluxe
    Bejeweled 3
    Bing Bar
    BitTorrent
    Blackhawk Striker 2
    Blasterball 3
    Blio
    Bounce Symphony
    BufferChm
    Build-a-lot 2
    Cake Mania
    Catalyst Control Center
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    Catalyst Control Center Localization All
    Catalyst Control Center Profiles Mobile
    CCC Help Chinese Standard
    CCC Help Chinese Traditional
    CCC Help Czech
    CCC Help Danish
    CCC Help Dutch
    CCC Help English
    CCC Help Finnish
    CCC Help French
    CCC Help German
    CCC Help Greek
    CCC Help Hungarian
    CCC Help Italian
    CCC Help Japanese
    CCC Help Korean
    CCC Help Norwegian
    CCC Help Polish
    CCC Help Portuguese
    CCC Help Russian
    CCC Help Spanish
    CCC Help Swedish
    CCC Help Thai
    CCC Help Turkish
    Chuzzle Deluxe
    Coupon Printer for Windows
    CyberLink PowerDVD 10
    CyberLink YouCam
    D110
    D3DX10
    Destinations
    DeviceDiscovery
    Diner Dash 2 Restaurant Rescue
    Dora's World Adventure
    Download Updater (AOL LLC)
    Energy Star Digital Logo
    ESU for Microsoft Windows 7
    Evernote v. 4.2.2
    Farm Frenzy
    FATE - The Traitor Soul
    Google Chrome
    GPBaseService2
    Hewlett-Packard ACLM.NET v1.1.0.0
    HP Connection Manager
    HP Customer Experience Enhancements
    HP Documentation
    HP Games
    HP MovieStore
    HP On Screen Display
    HP Power Manager
    HP Product Detection
    HP Quick Launch
    HP Setup
    HP Setup Manager
    HP SimplePass 2011
    HP Software Framework
    HP Update
    HPAppStudio
    HPDiagnosticAlert
    HPPhotoGadget
    HPProductAssistant
    HPSSupply
    IDT Audio
    Intel(R) Display Audio Driver
    Intel(R) Management Engine Components
    Intel(R) Rapid Storage Technology
    Intel(R) Wireless Display
    Java Auto Updater
    Java(TM) 6 Update 31
    Junk Mail filter update
    Magic Desktop
    Mah Jong Medley
    Malwarebytes Anti-Malware version 1.61.0.1400
    Maple 15
    MarketResearch
    Mesh Runtime
    Microsoft Office 2007 Service Pack 3 (SP3)
    Microsoft Office 2010
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office File Validation Add-In
    Microsoft Office Home and Student 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft WSE 3.0 Runtime
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Mystery P.I. - Stolen in San Francisco
    Namco All-Stars PAC-MAN
    Penguins!
    Plants vs. Zombies - Game of the Year
    PlayReady PC Runtime x86
    Poker Superstars III
    Polar Bowler
    Polar Golfer
    PS_AIO_07_D110_SW_Min
    PX Profile Update
    QuickTime
    QuickTransfer
    Racket v5.1.3
    Realtek Ethernet Controller Driver
    Realtek PCIE Card Reader
    Recovery Manager
    Renesas Electronics USB 3.0 Host Controller Driver
    RoxioNow Player
    Scan
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft Office 2007 suites (KB2596672) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2596880) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597162) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
    Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
    Security Update for Microsoft Office Excel 2007 (KB2597161) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
    Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
    Security Update for Microsoft Office Word 2007 (KB2596917) 32-Bit Edition
    Shop To Win
    Slingo Supreme
    SmartWebPrinting
    SolutionCenter
    StartNow Toolbar
    Status
    Toolbox
    TrayApp
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update Installer for WildTangent Games App
    Vid-Saver
    Virtual Villagers 4 - The Tree of Life
    WebReg
    Wheel of Fortune 2
    WildTangent Games App (HP Games)
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Zuma Deluxe
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/1/2012 9:33:18 AM, Error: Service Control Manager [7000] - The HP Support Assistant Service service failed to start due to the following error: The system cannot find the file specified.
    5/31/2012 11:00:25 PM, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
    5/29/2012 5:00:01 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the hpqwmiex service.
    .
    ==== End Of File ===========================
     
  11. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    Very well :)

    Download Bootkit Remover to your desktop.

    • Unzip downloaded file to your Desktop.
    • Double-click on boot_cleaner.exe to run the program (Vista/7 users,right click on boot_cleaner.exe and click Run As Administrator).
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.

    =========================================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
     
  12. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Bootkit Remover
    (c) 2009 Esage Lab
    www.esagelab.com

    Program version: 1.2.0.1
    OS Version: Microsoft Windows 7 Home Premium Edition Service Pack 1 (build 7601)
    , 64-bit

    System volume is \\.\C:
    \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`0c800000

    Size Device Name MBR Status
    --------------------------------------------
    698 GB \\.\PhysicalDrive0 Controlled by rootkit!

    Boot code on some of your physical disks is hidden by a rootkit.
    To disinfect the master boot sector, use the following command:
    remover.exe fix <device_name>
    To inspect the boot code manually, dump the master boot sector:
    remover.exe dump <device_name> [output_file]


    Done;
    Press any key to quit...
     
  13. muddie

    muddie TS Rookie Topic Starter Posts: 45

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-06-01 19:10:00
    -----------------------------
    19:10:00.532 OS Version: Windows x64 6.1.7601 Service Pack 1
    19:10:00.532 Number of processors: 8 586 0x2A07
    19:10:00.532 ComputerName: MICHAEL-HP UserName: Michael
    19:10:02.023 Initialize success
    19:10:25.428 AVAST engine defs: 12060101
    19:10:42.816 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    19:10:42.820 Disk 0 Vendor: TOSHIBA_ GN00 Size: 715404MB BusType: 3
    19:10:42.838 Disk 0 MBR read successfully
    19:10:42.844 Disk 0 MBR scan
    19:10:42.917 Disk 0 Windows 7 default MBR code
    19:10:42.923 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
    19:10:42.955 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 700270 MB offset 409600
    19:10:42.991 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 14831 MB offset 1434562560
    19:10:43.022 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 102 MB offset 1464936448
    19:10:43.142 Disk 0 scanning C:\Windows\system32\drivers
    19:10:57.010 Service scanning
    19:11:46.273 Modules scanning
    19:11:46.293 Disk 0 trace - called modules:
    19:11:46.647 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
    19:11:46.659 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80083c1790]
    19:11:46.670 3 CLASSPNP.SYS[fffff88001b9643f] -> nt!IofCallDriver -> [0xfffffa80082c2a20]
    19:11:46.682 5 hpdskflt.sys[fffff88001b3d361] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800818f050]
    19:11:49.088 AVAST engine scan C:\Windows
    19:11:51.944 AVAST engine scan C:\Windows\system32
    19:16:20.964 AVAST engine scan C:\Windows\system32\drivers
    19:16:40.336 AVAST engine scan C:\Users\Michael
    19:25:38.541 AVAST engine scan C:\ProgramData
    19:27:10.929 Scan finished successfully
    19:28:29.590 Disk 0 MBR has been saved successfully to "C:\Users\Michael\Desktop\MBR.dat"
    19:28:29.635 The log file has been saved successfully to "C:\Users\Michael\Desktop\aswMBR.txt"
     
  14. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  15. muddie

    muddie TS Rookie Topic Starter Posts: 45

    19:40:57.0089 7956TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
    19:40:57.0319 7956============================================================
    19:40:57.0319 7956Current date / time: 2012/06/01 19:40:57.0319
    19:40:57.0319 7956SystemInfo:
    19:40:57.0319 7956
    19:40:57.0319 7956OS Version: 6.1.7601 ServicePack: 1.0
    19:40:57.0319 7956Product type: Workstation
    19:40:57.0320 7956ComputerName: MICHAEL-HP
    19:40:57.0320 7956UserName: Michael
    19:40:57.0320 7956Windows directory: C:\Windows
    19:40:57.0320 7956System windows directory: C:\Windows
    19:40:57.0320 7956Running under WOW64
    19:40:57.0320 7956Processor architecture: Intel x64
    19:40:57.0320 7956Number of processors: 8
    19:40:57.0320 7956Page size: 0x1000
    19:40:57.0320 7956Boot type: Normal boot
    19:40:57.0320 7956============================================================
    19:40:57.0756 7956Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    19:40:57.0816 7956============================================================
    19:40:57.0816 7956\Device\Harddisk0\DR0:
    19:40:57.0816 7956MBR partitions:
    19:40:57.0816 7956\Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
    19:40:57.0816 7956\Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x557B7000
    19:40:57.0816 7956\Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x5581B000, BlocksNum 0x1CF7800
    19:40:57.0816 7956\Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x57512800, BlocksNum 0x336F0
    19:40:57.0816 7956============================================================
    19:40:57.0843 7956C: <-> \Device\Harddisk0\DR0\Partition1
    19:40:57.0889 7956D: <-> \Device\Harddisk0\DR0\Partition2
    19:40:57.0904 7956F: <-> \Device\Harddisk0\DR0\Partition3
    19:40:57.0904 7956============================================================
    19:40:57.0904 7956Initialize success
    19:40:57.0904 7956============================================================
    19:41:05.0439 6220============================================================
    19:41:05.0439 6220Scan started
    19:41:05.0439 6220Mode: Manual;
    19:41:05.0439 6220============================================================
    19:41:06.0042 62201394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
    19:41:06.0047 62201394ohci - ok
    19:41:06.0115 6220Accelerometer (7a330a42870eb1fa81f88be514d2d566) C:\Windows\system32\DRIVERS\Accelerometer.sys
    19:41:06.0117 6220Accelerometer - ok
    19:41:06.0168 6220ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
    19:41:06.0173 6220ACPI - ok
    19:41:06.0208 6220AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
    19:41:06.0210 6220AcpiPmi - ok
    19:41:06.0341 6220AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    19:41:06.0344 6220AdobeARMservice - ok
    19:41:06.0524 6220AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    19:41:06.0529 6220AdobeFlashPlayerUpdateSvc - ok
    19:41:06.0602 6220adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
    19:41:06.0612 6220adp94xx - ok
    19:41:06.0658 6220adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
    19:41:06.0665 6220adpahci - ok
    19:41:06.0719 6220adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
    19:41:06.0723 6220adpu320 - ok
    19:41:06.0757 6220AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
    19:41:06.0759 6220AeLookupSvc - ok
    19:41:06.0852 6220AESTFilters (a6fb9db8f1a86861d955fd6975977ae0) C:\Program Files\IDT\WDM\AESTSr64.exe
    19:41:06.0855 6220AESTFilters - ok
    19:41:06.0924 6220AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
    19:41:06.0934 6220AFD - ok
    19:41:06.0972 6220agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
    19:41:06.0973 6220agp440 - ok
    19:41:07.0007 6220ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
    19:41:07.0009 6220ALG - ok
    19:41:07.0047 6220aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
    19:41:07.0048 6220aliide - ok
    19:41:07.0091 6220AMD External Events Utility (1b4a3c8e429f1fab998eceea3ce3e0b8) C:\Windows\system32\atiesrxx.exe
    19:41:07.0096 6220AMD External Events Utility - ok
    19:41:07.0119 6220amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
    19:41:07.0121 6220amdide - ok
    19:41:07.0170 6220AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
    19:41:07.0172 6220AmdK8 - ok
    19:41:07.0544 6220amdkmdag (e08cf0ed91fcca0017776cff4a506012) C:\Windows\system32\DRIVERS\atikmdag.sys
    19:41:07.0704 6220amdkmdag - ok
    19:41:07.0836 6220amdkmdap (f072f317e430925c7d88c766db7da86e) C:\Windows\system32\DRIVERS\atikmpag.sys
    19:41:07.0842 6220amdkmdap - ok
    19:41:07.0877 6220AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
    19:41:07.0879 6220AmdPPM - ok
    19:41:07.0937 6220amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
    19:41:07.0939 6220amdsata - ok
    19:41:07.0969 6220amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
    19:41:07.0972 6220amdsbs - ok
    19:41:07.0992 6220amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
    19:41:07.0993 6220amdxata - ok
    19:41:08.0054 6220AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
    19:41:08.0056 6220AppID - ok
    19:41:08.0083 6220AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
    19:41:08.0085 6220AppIDSvc - ok
    19:41:08.0107 6220Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
    19:41:08.0109 6220Appinfo - ok
    19:41:08.0227 6220Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    19:41:08.0230 6220Apple Mobile Device - ok
    19:41:08.0273 6220arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
    19:41:08.0275 6220arc - ok
    19:41:08.0297 6220arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
    19:41:08.0300 6220arcsas - ok
    19:41:08.0327 6220AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    19:41:08.0328 6220AsyncMac - ok
    19:41:08.0460 6220atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
    19:41:08.0461 6220atapi - ok
    19:41:08.0588 6220AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
    19:41:08.0614 6220AudioEndpointBuilder - ok
    19:41:08.0631 6220AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
    19:41:08.0641 6220AudioSrv - ok
    19:41:08.0677 6220AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
    19:41:08.0681 6220AxInstSV - ok
    19:41:08.0759 6220b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
    19:41:08.0764 6220b06bdrv - ok
    19:41:08.0829 6220b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    19:41:08.0834 6220b57nd60a - ok
    19:41:08.0933 6220BBSvc (93ee7d9c35ae7e9ffda148d7805f1421) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
    19:41:08.0937 6220BBSvc - ok
    19:41:09.0028 6220BCM43XX (9e84a931dbee0292e38ed672f6293a99) C:\Windows\system32\DRIVERS\bcmwl664.sys
    19:41:09.0045 6220BCM43XX - ok
    19:41:09.0070 6220BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
    19:41:09.0072 6220BDESVC - ok
    19:41:09.0147 6220Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    19:41:09.0148 6220Beep - ok
    19:41:09.0219 6220BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
    19:41:09.0229 6220BFE - ok
    19:41:09.0281 6220BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
    19:41:09.0295 6220BITS - ok
    19:41:09.0372 6220blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys
    19:41:09.0374 6220blbdrive - ok
    19:41:09.0483 6220Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
    19:41:09.0491 6220Bonjour Service - ok
    19:41:09.0547 6220bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
    19:41:09.0549 6220bowser - ok
    19:41:09.0578 6220BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
    19:41:09.0580 6220BrFiltLo - ok
    19:41:09.0605 6220BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
    19:41:09.0606 6220BrFiltUp - ok
    19:41:09.0645 6220Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
    19:41:09.0648 6220Browser - ok
    19:41:09.0696 6220Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    19:41:09.0701 6220Brserid - ok
    19:41:09.0731 6220BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    19:41:09.0733 6220BrSerWdm - ok
    19:41:09.0793 6220BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    19:41:09.0795 6220BrUsbMdm - ok
    19:41:09.0817 6220BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    19:41:09.0818 6220BrUsbSer - ok
    19:41:09.0843 6220BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
    19:41:09.0845 6220BTHMODEM - ok
    19:41:09.0890 6220bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
    19:41:09.0893 6220bthserv - ok
    19:41:09.0925 6220cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    19:41:09.0927 6220cdfs - ok
    19:41:09.0988 6220cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
    19:41:09.0991 6220cdrom - ok
    19:41:10.0028 6220CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
    19:41:10.0030 6220CertPropSvc - ok
    19:41:10.0066 6220circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
    19:41:10.0068 6220circlass - ok
    19:41:10.0102 6220CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    19:41:10.0110 6220CLFS - ok
    19:41:10.0223 6220CLKMSVC10_38F51D56 (524dc3807cb1746225f9d26add19c319) C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
    19:41:10.0228 6220CLKMSVC10_38F51D56 - ok
    19:41:10.0295 6220clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    19:41:10.0298 6220clr_optimization_v2.0.50727_32 - ok
    19:41:10.0348 6220clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    19:41:10.0351 6220clr_optimization_v2.0.50727_64 - ok
    19:41:10.0422 6220clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    19:41:10.0425 6220clr_optimization_v4.0.30319_32 - ok
    19:41:10.0464 6220clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    19:41:10.0467 6220clr_optimization_v4.0.30319_64 - ok
    19:41:10.0577 6220clwvd (50f92c943f18b070f166d019dfab3d9a) C:\Windows\system32\DRIVERS\clwvd.sys
    19:41:10.0578 6220clwvd - ok
    19:41:10.0621 6220CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
    19:41:10.0622 6220CmBatt - ok
    19:41:10.0653 6220cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
    19:41:10.0654 6220cmdide - ok
    19:41:10.0712 6220CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
    19:41:10.0721 6220CNG - ok
    19:41:10.0754 6220Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
    19:41:10.0755 6220Compbatt - ok
    19:41:10.0781 6220CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
    19:41:10.0782 6220CompositeBus - ok
    19:41:10.0796 6220COMSysApp - ok
    19:41:10.0824 6220crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
    19:41:10.0826 6220crcdisk - ok
    19:41:10.0863 6220CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
    19:41:10.0867 6220CryptSvc - ok
    19:41:10.0920 6220dc3d (7f61fbe259c18666d8ddf862f13a5eb0) C:\Windows\system32\DRIVERS\dc3d.sys
    19:41:10.0922 6220dc3d - ok
    19:41:10.0987 6220DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
    19:41:11.0000 6220DcomLaunch - ok
    19:41:11.0046 6220defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
    19:41:11.0053 6220defragsvc - ok
    19:41:11.0079 6220DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
    19:41:11.0082 6220DfsC - ok
    19:41:11.0125 6220Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
    19:41:11.0132 6220Dhcp - ok
    19:41:11.0162 6220discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    19:41:11.0164 6220discache - ok
    19:41:11.0206 6220Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
    19:41:11.0207 6220Disk - ok
    19:41:11.0241 6220Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
    19:41:11.0246 6220Dnscache - ok
    19:41:11.0289 6220dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
    19:41:11.0295 6220dot3svc - ok
    19:41:11.0345 6220Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
    19:41:11.0348 6220Dot4 - ok
    19:41:11.0373 6220Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys
    19:41:11.0374 6220Dot4Print - ok
    19:41:11.0412 6220dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
    19:41:11.0414 6220dot4usb - ok
    19:41:11.0445 6220DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
    19:41:11.0449 6220DPS - ok
    19:41:11.0491 6220drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    19:41:11.0492 6220drmkaud - ok
    19:41:11.0552 6220DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
    19:41:11.0566 6220DXGKrnl - ok
    19:41:11.0600 6220EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
    19:41:11.0603 6220EapHost - ok
    19:41:11.0759 6220ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
    19:41:11.0789 6220ebdrv - ok
    19:41:11.0883 6220EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
    19:41:11.0887 6220EFS - ok
    19:41:11.0984 6220ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
    19:41:11.0998 6220ehRecvr - ok
    19:41:12.0019 6220ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
    19:41:12.0021 6220ehSched - ok
    19:41:12.0118 6220elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
    19:41:12.0128 6220elxstor - ok
    19:41:12.0160 6220ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
    19:41:12.0161 6220ErrDev - ok
    19:41:12.0218 6220EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
    19:41:12.0226 6220EventSystem - ok
    19:41:12.0353 6220EvtEng (7ee9f35bc1dd0ce1a4976032f9ac5162) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    19:41:12.0370 6220EvtEng - ok
    19:41:12.0477 6220exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    19:41:12.0482 6220exfat - ok
    19:41:12.0496 6220ezSharedSvc - ok
    19:41:12.0525 6220fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    19:41:12.0529 6220fastfat - ok
    19:41:12.0593 6220Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
    19:41:12.0607 6220Fax - ok
    19:41:12.0646 6220fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
    19:41:12.0648 6220fdc - ok
    19:41:12.0689 6220fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
    19:41:12.0691 6220fdPHost - ok
    19:41:12.0700 6220FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
    19:41:12.0703 6220FDResPub - ok
    19:41:12.0745 6220FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    19:41:12.0747 6220FileInfo - ok
    19:41:12.0764 6220Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    19:41:12.0765 6220Filetrace - ok
    19:41:12.0802 6220flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
    19:41:12.0804 6220flpydisk - ok
    19:41:12.0835 6220FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
    19:41:12.0840 6220FltMgr - ok
    19:41:12.0910 6220FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
    19:41:12.0930 6220FontCache - ok
    19:41:13.0006 6220FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    19:41:13.0008 6220FontCache3.0.0.0 - ok
    19:41:13.0105 6220FPLService (2074a85a6b8f84a5a9c60b915b465faf) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    19:41:13.0110 6220FPLService - ok
    19:41:13.0191 6220FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    19:41:13.0193 6220FsDepends - ok
    19:41:13.0221 6220Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
    19:41:13.0223 6220Fs_Rec - ok
    19:41:13.0261 6220fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
    19:41:13.0265 6220fvevol - ok
    19:41:13.0309 6220gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
    19:41:13.0311 6220gagp30kx - ok
    19:41:13.0378 6220GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
    19:41:13.0383 6220GamesAppService - ok
    19:41:13.0419 6220GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    19:41:13.0420 6220GEARAspiWDM - ok
    19:41:13.0489 6220gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
    19:41:13.0505 6220gpsvc - ok
    19:41:13.0549 6220hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    19:41:13.0551 6220hcw85cir - ok
    19:41:13.0624 6220HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
    19:41:13.0631 6220HdAudAddService - ok
    19:41:13.0680 6220HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    19:41:13.0683 6220HDAudBus - ok
    19:41:13.0713 6220HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
    19:41:13.0714 6220HidBatt - ok
    19:41:13.0739 6220HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
    19:41:13.0742 6220HidBth - ok
    19:41:13.0776 6220HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
    19:41:13.0778 6220HidIr - ok
    19:41:13.0818 6220hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
    19:41:13.0821 6220hidserv - ok
    19:41:13.0868 6220HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
    19:41:13.0869 6220HidUsb - ok
    19:41:13.0890 6220hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
    19:41:13.0895 6220hkmsvc - ok
    19:41:13.0919 6220HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
    19:41:13.0926 6220HomeGroupListener - ok
    19:41:13.0966 6220HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
    19:41:13.0973 6220HomeGroupProvider - ok
    19:41:14.0054 6220HP Support Assistant Service - ok
    19:41:14.0137 6220HPAuto (7b8c1b09c11e8db7c4480abd7d17e821) C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    19:41:14.0147 6220HPAuto - ok
    19:41:14.0202 6220HPClientSvc (6a181452d4e240b8ecc7614b9a19bde9) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    19:41:14.0207 6220HPClientSvc - ok
    19:41:14.0300 6220hpCMSrv (e040f0064d39f73bb4995d494f3dcbb8) C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
    19:41:14.0315 6220hpCMSrv - ok
    19:41:14.0510 6220hpdskflt (a4be23c451adeb252cd17a0532cae220) C:\Windows\system32\DRIVERS\hpdskflt.sys
    19:41:14.0512 6220hpdskflt - ok
    19:41:14.0603 6220hpqcxs08 (5da42d24712e00728cea2342a65009b2) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
    19:41:14.0688 6220hpqcxs08 - ok
    19:41:14.0712 6220hpqddsvc (d86a39bf100069444d026d22d9a6e555) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
    19:41:14.0805 6220hpqddsvc - ok
    19:41:14.0897 6220hpqwmiex (ec9739a46f1f83c6e52a7a4697f44a65) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    19:41:14.0904 6220hpqwmiex - ok
    19:41:15.0026 6220HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
    19:41:15.0029 6220HpSAMD - ok
    19:41:15.0135 6220HPSLPSVC (f37882f128efacefe353e0bae2766909) C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
    19:41:15.0200 6220HPSLPSVC - ok
    19:41:15.0238 6220hpsrv (a88a45e82bc54bffb49c63973010226a) C:\Windows\system32\Hpservice.exe
    19:41:15.0239 6220hpsrv - ok
    19:41:15.0312 6220HPWMISVC (171000873eb522e5ea3dd4c4e0b689b2) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    19:41:15.0313 6220HPWMISVC - ok
    19:41:15.0383 6220HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
    19:41:15.0397 6220HTTP - ok
    19:41:15.0416 6220hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
    19:41:15.0417 6220hwpolicy - ok
    19:41:15.0459 6220i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    19:41:15.0461 6220i8042prt - ok
    19:41:15.0512 6220iaStor (d469b77687e12fe43e344806740b624d) C:\Windows\system32\DRIVERS\iaStor.sys
    19:41:15.0518 6220iaStor - ok
    19:41:15.0615 6220IAStorDataMgrSvc (983fc69644ddf0486c8dfea262948d1a) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    19:41:15.0617 6220IAStorDataMgrSvc - ok
    19:41:15.0680 6220iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
    19:41:15.0688 6220iaStorV - ok
    19:41:15.0794 6220idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    19:41:15.0810 6220idsvc - ok
    19:41:15.0855 6220iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
    19:41:15.0857 6220iirsp - ok
    19:41:15.0923 6220IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
    19:41:15.0938 6220IKEEXT - ok
    19:41:15.0987 6220IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
    19:41:15.0991 6220IntcDAud - ok
    19:41:16.0021 6220intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
    19:41:16.0022 6220intelide - ok
    19:41:16.0541 6220intelkmd (efe5a0af39a8e179624117c521f1e012) C:\Windows\system32\DRIVERS\igdpmd64.sys
    19:41:16.0766 6220intelkmd - ok
    19:41:16.0873 6220intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    19:41:16.0875 6220intelppm - ok
    19:41:16.0912 6220IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
    19:41:16.0916 6220IPBusEnum - ok
    19:41:16.0941 6220IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    19:41:16.0943 6220IpFilterDriver - ok
    19:41:16.0978 6220iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
    19:41:16.0986 6220iphlpsvc - ok
    19:41:17.0020 6220IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
    19:41:17.0021 6220IPMIDRV - ok
    19:41:17.0041 6220IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    19:41:17.0042 6220IPNAT - ok
    19:41:17.0162 6220iPod Service (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
    19:41:17.0171 6220iPod Service - ok
    19:41:17.0198 6220IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    19:41:17.0199 6220IRENUM - ok
    19:41:17.0245 6220isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
    19:41:17.0247 6220isapnp - ok
    19:41:17.0282 6220iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
    19:41:17.0287 6220iScsiPrt - ok
    19:41:17.0308 6220kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    19:41:17.0309 6220kbdclass - ok
    19:41:17.0334 6220kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
    19:41:17.0335 6220kbdhid - ok
    19:41:17.0371 6220KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    19:41:17.0373 6220KeyIso - ok
    19:41:17.0389 6220KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
    19:41:17.0392 6220KSecDD - ok
    19:41:17.0431 6220KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
    19:41:17.0433 6220KSecPkg - ok
    19:41:17.0454 6220ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    19:41:17.0455 6220ksthunk - ok
    19:41:17.0498 6220KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
    19:41:17.0506 6220KtmRm - ok
    19:41:17.0552 6220LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
    19:41:17.0559 6220LanmanServer - ok
    19:41:17.0587 6220LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
    19:41:17.0592 6220LanmanWorkstation - ok
    19:41:17.0637 6220lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    19:41:17.0638 6220lltdio - ok
    19:41:17.0677 6220lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
    19:41:17.0684 6220lltdsvc - ok
    19:41:17.0707 6220lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
    19:41:17.0710 6220lmhosts - ok
    19:41:17.0829 6220LMS (d7e0bed3ea21d7bddd410ade51708d90) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    19:41:17.0834 6220LMS - ok
    19:41:17.0885 6220LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
    19:41:17.0888 6220LSI_FC - ok
    19:41:17.0915 6220LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
    19:41:17.0918 6220LSI_SAS - ok
    19:41:17.0947 6220LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
    19:41:17.0949 6220LSI_SAS2 - ok
    19:41:17.0971 6220LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
    19:41:17.0974 6220LSI_SCSI - ok
    19:41:17.0998 6220luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    19:41:18.0001 6220luafv - ok
    19:41:18.0058 6220MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys
    19:41:18.0059 6220MBAMProtector - ok
    19:41:18.0174 6220MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Michael's File\Malwarebytes' Anti-Malware\mbamservice.exe
    19:41:18.0185 6220MBAMService - ok
    19:41:18.0221 6220Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
    19:41:18.0224 6220Mcx2Svc - ok
    19:41:18.0247 6220megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
    19:41:18.0248 6220megasas - ok
    19:41:18.0276 6220MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
    19:41:18.0280 6220MegaSR - ok
    19:41:18.0326 6220MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
    19:41:18.0327 6220MEIx64 - ok
    19:41:18.0355 6220MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    19:41:18.0357 6220MMCSS - ok
    19:41:18.0382 6220Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    19:41:18.0383 6220Modem - ok
    19:41:18.0411 6220monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    19:41:18.0412 6220monitor - ok
    19:41:18.0447 6220mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    19:41:18.0448 6220mouclass - ok
    19:41:18.0496 6220mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    19:41:18.0497 6220mouhid - ok
    19:41:18.0527 6220mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
    19:41:18.0529 6220mountmgr - ok
    19:41:18.0614 6220MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
    19:41:18.0618 6220MpFilter - ok
    19:41:18.0664 6220mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
    19:41:18.0668 6220mpio - ok
    19:41:18.0697 6220mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    19:41:18.0699 6220mpsdrv - ok
    19:41:18.0767 6220MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
    19:41:18.0784 6220MpsSvc - ok
    19:41:18.0809 6220MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
    19:41:18.0811 6220MRxDAV - ok
    19:41:18.0851 6220mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
    19:41:18.0855 6220mrxsmb - ok
    19:41:18.0901 6220mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    19:41:18.0905 6220mrxsmb10 - ok
    19:41:18.0921 6220mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    19:41:18.0923 6220mrxsmb20 - ok
    19:41:18.0947 6220msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
    19:41:18.0948 6220msahci - ok
    19:41:18.0983 6220msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
     
  16. muddie

    muddie TS Rookie Topic Starter Posts: 45

    19:41:18.0987 6220msdsm - ok
    19:41:19.0021 6220MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
    19:41:19.0024 6220MSDTC - ok
    19:41:19.0044 6220Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    19:41:19.0045 6220Msfs - ok
    19:41:19.0060 6220mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    19:41:19.0060 6220mshidkmdf - ok
    19:41:19.0089 6220msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
    19:41:19.0090 6220msisadrv - ok
    19:41:19.0134 6220MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
    19:41:19.0140 6220MSiSCSI - ok
    19:41:19.0146 6220msiserver - ok
    19:41:19.0194 6220MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    19:41:19.0195 6220MSKSSRV - ok
    19:41:19.0265 6220MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
    19:41:19.0265 6220MsMpSvc - ok
    19:41:19.0291 6220MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    19:41:19.0292 6220MSPCLOCK - ok
    19:41:19.0325 6220MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    19:41:19.0326 6220MSPQM - ok
    19:41:19.0354 6220MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
    19:41:19.0360 6220MsRPC - ok
    19:41:19.0392 6220mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
    19:41:19.0393 6220mssmbios - ok
    19:41:19.0417 6220MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    19:41:19.0418 6220MSTEE - ok
    19:41:19.0441 6220MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
    19:41:19.0442 6220MTConfig - ok
    19:41:19.0471 6220Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    19:41:19.0473 6220Mup - ok
    19:41:19.0558 6220MyWiFiDHCPDNS (0cf5580f27918ffd2e165ecafa734103) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    19:41:19.0565 6220MyWiFiDHCPDNS - ok
    19:41:19.0615 6220napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
    19:41:19.0627 6220napagent - ok
    19:41:19.0678 6220NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    19:41:19.0685 6220NativeWifiP - ok
    19:41:19.0754 6220NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
    19:41:19.0766 6220NDIS - ok
    19:41:19.0796 6220NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    19:41:19.0797 6220NdisCap - ok
    19:41:19.0822 6220NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    19:41:19.0823 6220NdisTapi - ok
    19:41:19.0841 6220Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
    19:41:19.0843 6220Ndisuio - ok
    19:41:19.0865 6220NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
    19:41:19.0867 6220NdisWan - ok
    19:41:19.0884 6220NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
    19:41:19.0886 6220NDProxy - ok
    19:41:19.0933 6220Net Driver HPZ12 (2334dc48997ba203b794df3ee70521db) C:\Windows\system32\HPZinw12.dll
    19:41:19.0937 6220Net Driver HPZ12 - ok
    19:41:19.0967 6220NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    19:41:19.0969 6220NetBIOS - ok
    19:41:20.0001 6220NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
    19:41:20.0007 6220NetBT - ok
    19:41:20.0039 6220Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    19:41:20.0042 6220Netlogon - ok
    19:41:20.0101 6220Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
    19:41:20.0112 6220Netman - ok
    19:41:20.0153 6220netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
    19:41:20.0165 6220netprofm - ok
    19:41:20.0243 6220NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    19:41:20.0246 6220NetTcpPortSharing - ok
    19:41:20.0625 6220NETwNs64 (b9c587bdaa61a689883439d5ae6fe7f3) C:\Windows\system32\DRIVERS\NETwNs64.sys
    19:41:20.0788 6220NETwNs64 - ok
    19:41:20.0912 6220nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
    19:41:20.0914 6220nfrd960 - ok
    19:41:20.0970 6220NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
    19:41:20.0973 6220NisDrv - ok
    19:41:21.0063 6220NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
    19:41:21.0068 6220NisSrv - ok
    19:41:21.0122 6220NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
    19:41:21.0131 6220NlaSvc - ok
    19:41:21.0158 6220Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    19:41:21.0159 6220Npfs - ok
    19:41:21.0169 6220nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
    19:41:21.0173 6220nsi - ok
    19:41:21.0186 6220nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    19:41:21.0187 6220nsiproxy - ok
    19:41:21.0278 6220Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
    19:41:21.0303 6220Ntfs - ok
    19:41:21.0401 6220Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    19:41:21.0402 6220Null - ok
    19:41:21.0443 6220nusb3hub (158ad24745bd85ba9be3c51c38f48c32) C:\Windows\system32\DRIVERS\nusb3hub.sys
    19:41:21.0445 6220nusb3hub - ok
    19:41:21.0481 6220nusb3xhc (d40a13b2c0891e218f9523b376955db6) C:\Windows\system32\DRIVERS\nusb3xhc.sys
    19:41:21.0485 6220nusb3xhc - ok
    19:41:21.0548 6220NVENETFD (a85b4f2ef3a7304a5399ef0526423040) C:\Windows\system32\DRIVERS\nvm62x64.sys
    19:41:21.0556 6220NVENETFD - ok
    19:41:21.0618 6220nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
    19:41:21.0622 6220nvraid - ok
    19:41:21.0648 6220nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
    19:41:21.0651 6220nvstor - ok
    19:41:21.0689 6220nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
    19:41:21.0692 6220nv_agp - ok
    19:41:21.0831 6220odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
    19:41:21.0838 6220odserv - ok
    19:41:21.0873 6220ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
    19:41:21.0875 6220ohci1394 - ok
    19:41:21.0934 6220ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    19:41:21.0937 6220ose - ok
    19:41:21.0979 6220p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    19:41:21.0989 6220p2pimsvc - ok
    19:41:22.0016 6220p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
    19:41:22.0024 6220p2psvc - ok
    19:41:22.0047 6220Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
    19:41:22.0049 6220Parport - ok
    19:41:22.0087 6220partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
    19:41:22.0089 6220partmgr - ok
    19:41:22.0128 6220PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
    19:41:22.0135 6220PcaSvc - ok
    19:41:22.0172 6220pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
    19:41:22.0176 6220pci - ok
    19:41:22.0214 6220pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
    19:41:22.0215 6220pciide - ok
    19:41:22.0257 6220pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
    19:41:22.0261 6220pcmcia - ok
    19:41:22.0287 6220pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    19:41:22.0289 6220pcw - ok
    19:41:22.0325 6220PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    19:41:22.0337 6220PEAUTH - ok
    19:41:22.0421 6220PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
    19:41:22.0425 6220PerfHost - ok
    19:41:22.0558 6220pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
    19:41:22.0578 6220pla - ok
    19:41:22.0633 6220PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
    19:41:22.0645 6220PlugPlay - ok
    19:41:22.0705 6220Pml Driver HPZ12 (ac78df349f0e4cfb8b667c0cfff83cce) C:\Windows\system32\HPZipm12.dll
    19:41:22.0709 6220Pml Driver HPZ12 - ok
    19:41:22.0730 6220PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
    19:41:22.0735 6220PNRPAutoReg - ok
    19:41:22.0768 6220PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
    19:41:22.0775 6220PNRPsvc - ok
    19:41:22.0845 6220Point64 (33328fa8a580885ab0065be6db266e9f) C:\Windows\system32\DRIVERS\point64.sys
    19:41:22.0847 6220Point64 - ok
    19:41:22.0898 6220PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
    19:41:22.0909 6220PolicyAgent - ok
    19:41:22.0940 6220Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
    19:41:22.0947 6220Power - ok
    19:41:22.0997 6220PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
    19:41:23.0000 6220PptpMiniport - ok
    19:41:23.0032 6220Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
    19:41:23.0034 6220Processor - ok
    19:41:23.0071 6220ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
    19:41:23.0078 6220ProfSvc - ok
    19:41:23.0117 6220ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    19:41:23.0120 6220ProtectedStorage - ok
    19:41:23.0168 6220Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
    19:41:23.0171 6220Psched - ok
    19:41:23.0271 6220ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
    19:41:23.0292 6220ql2300 - ok
    19:41:23.0405 6220ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
    19:41:23.0408 6220ql40xx - ok
    19:41:23.0444 6220QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
    19:41:23.0452 6220QWAVE - ok
    19:41:23.0503 6220QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    19:41:23.0505 6220QWAVEdrv - ok
    19:41:23.0542 6220RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    19:41:23.0544 6220RasAcd - ok
    19:41:23.0597 6220RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    19:41:23.0599 6220RasAgileVpn - ok
    19:41:23.0655 6220RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
    19:41:23.0661 6220RasAuto - ok
    19:41:23.0689 6220Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
    19:41:23.0692 6220Rasl2tp - ok
    19:41:23.0731 6220RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
    19:41:23.0742 6220RasMan - ok
    19:41:23.0766 6220RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    19:41:23.0769 6220RasPppoe - ok
    19:41:23.0817 6220RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    19:41:23.0820 6220RasSstp - ok
    19:41:23.0853 6220rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
    19:41:23.0860 6220rdbss - ok
    19:41:23.0893 6220rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
    19:41:23.0895 6220rdpbus - ok
    19:41:23.0924 6220RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    19:41:23.0925 6220RDPCDD - ok
    19:41:23.0947 6220RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    19:41:23.0949 6220RDPENCDD - ok
    19:41:23.0959 6220RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    19:41:23.0960 6220RDPREFMP - ok
    19:41:24.0009 6220RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
    19:41:24.0014 6220RDPWD - ok
    19:41:24.0075 6220rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
    19:41:24.0079 6220rdyboost - ok
    19:41:24.0220 6220RegSrvc (aa9fd849c028ccb441a78061b57db734) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    19:41:24.0236 6220RegSrvc - ok
    19:41:24.0262 6220RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
    19:41:24.0265 6220RemoteAccess - ok
    19:41:24.0301 6220RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
    19:41:24.0306 6220RemoteRegistry - ok
    19:41:24.0392 6220RoxioNow Service (085d18c71ab2611a3d61528132b6501e) C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
    19:41:24.0397 6220RoxioNow Service - ok
    19:41:24.0423 6220RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
    19:41:24.0426 6220RpcEptMapper - ok
    19:41:24.0449 6220RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
    19:41:24.0451 6220RpcLocator - ok
    19:41:24.0487 6220RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
    19:41:24.0495 6220RpcSs - ok
    19:41:24.0574 6220RSPCIESTOR (d5c3e1629a3f7f0857d27949252b94ce) C:\Windows\system32\DRIVERS\RtsPStor.sys
    19:41:24.0581 6220RSPCIESTOR - ok
    19:41:24.0617 6220rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    19:41:24.0620 6220rspndr - ok
    19:41:24.0671 6220RTL8167 (ed5873f7dfb2f96d37f13322211b6bdc) C:\Windows\system32\DRIVERS\Rt64win7.sys
    19:41:24.0679 6220RTL8167 - ok
    19:41:24.0717 6220SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    19:41:24.0720 6220SamSs - ok
    19:41:24.0751 6220sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
    19:41:24.0753 6220sbp2port - ok
    19:41:24.0781 6220SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
    19:41:24.0788 6220SCardSvr - ok
    19:41:24.0801 6220scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
    19:41:24.0803 6220scfilter - ok
    19:41:24.0867 6220Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
    19:41:24.0885 6220Schedule - ok
    19:41:24.0906 6220SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
    19:41:24.0908 6220SCPolicySvc - ok
    19:41:24.0940 6220sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\DRIVERS\sdbus.sys
    19:41:24.0942 6220sdbus - ok
    19:41:24.0977 6220SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
    19:41:24.0981 6220SDRSVC - ok
    19:41:25.0066 6220SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
    19:41:25.0072 6220SeaPort - ok
    19:41:25.0118 6220secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    19:41:25.0120 6220secdrv - ok
    19:41:25.0176 6220seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
    19:41:25.0181 6220seclogon - ok
    19:41:25.0198 6220SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
    19:41:25.0203 6220SENS - ok
    19:41:25.0252 6220SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
    19:41:25.0255 6220SensrSvc - ok
    19:41:25.0289 6220Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
    19:41:25.0289 6220Serenum - ok
    19:41:25.0305 6220Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
    19:41:25.0306 6220Serial - ok
    19:41:25.0353 6220sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
    19:41:25.0353 6220sermouse - ok
    19:41:25.0400 6220SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
    19:41:25.0406 6220SessionEnv - ok
    19:41:25.0443 6220sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
    19:41:25.0444 6220sffdisk - ok
    19:41:25.0458 6220sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
    19:41:25.0460 6220sffp_mmc - ok
    19:41:25.0478 6220sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
    19:41:25.0479 6220sffp_sd - ok
    19:41:25.0511 6220sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
    19:41:25.0513 6220sfloppy - ok
    19:41:25.0555 6220SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
    19:41:25.0565 6220SharedAccess - ok
    19:41:25.0604 6220ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
    19:41:25.0616 6220ShellHWDetection - ok
    19:41:25.0651 6220SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
    19:41:25.0653 6220SiSRaid2 - ok
    19:41:25.0683 6220SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
    19:41:25.0685 6220SiSRaid4 - ok
    19:41:25.0730 6220Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    19:41:25.0732 6220Smb - ok
    19:41:25.0780 6220SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
    19:41:25.0785 6220SNMPTRAP - ok
    19:41:25.0804 6220spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    19:41:25.0806 6220spldr - ok
    19:41:25.0851 6220Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
    19:41:25.0865 6220Spooler - ok
    19:41:26.0015 6220sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
    19:41:26.0047 6220sppsvc - ok
    19:41:26.0151 6220sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
    19:41:26.0157 6220sppuinotify - ok
    19:41:26.0228 6220srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
    19:41:26.0236 6220srv - ok
    19:41:26.0270 6220srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
    19:41:26.0276 6220srv2 - ok
    19:41:26.0328 6220SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    19:41:26.0335 6220SrvHsfHDA - ok
    19:41:26.0420 6220SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
    19:41:26.0441 6220SrvHsfV92 - ok
    19:41:26.0583 6220SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
    19:41:26.0595 6220SrvHsfWinac - ok
    19:41:26.0641 6220srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
    19:41:26.0644 6220srvnet - ok
    19:41:26.0688 6220SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
    19:41:26.0694 6220SSDPSRV - ok
    19:41:26.0711 6220SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
    19:41:26.0715 6220SstpSvc - ok
    19:41:26.0826 6220STacSV (86678c2f5081fea3517d78e92230b5ff) C:\Program Files\IDT\WDM\STacSV64.exe
    19:41:26.0831 6220STacSV - ok
    19:41:26.0859 6220stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
    19:41:26.0861 6220stexstor - ok
    19:41:26.0927 6220STHDA (74387b34b43f94e380608888c56a5ccd) C:\Windows\system32\DRIVERS\stwrt64.sys
    19:41:26.0936 6220STHDA - ok
    19:41:26.0998 6220stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
    19:41:27.0011 6220stisvc - ok
    19:41:27.0040 6220swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
    19:41:27.0041 6220swenum - ok
    19:41:27.0087 6220swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
    19:41:27.0096 6220swprv - ok
    19:41:27.0208 6220SynTP (33e6a285daa5134d8ea2247914c86c09) C:\Windows\system32\DRIVERS\SynTP.sys
    19:41:27.0227 6220SynTP - ok
    19:41:27.0390 6220SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
    19:41:27.0413 6220SysMain - ok
    19:41:27.0515 6220TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
    19:41:27.0519 6220TabletInputService - ok
    19:41:27.0552 6220TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
    19:41:27.0560 6220TapiSrv - ok
    19:41:27.0581 6220TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
    19:41:27.0585 6220TBS - ok
    19:41:27.0729 6220Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
    19:41:27.0751 6220Tcpip - ok
    19:41:27.0957 6220TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
    19:41:27.0973 6220TCPIP6 - ok
    19:41:28.0083 6220tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
    19:41:28.0085 6220tcpipreg - ok
    19:41:28.0108 6220TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    19:41:28.0109 6220TDPIPE - ok
    19:41:28.0131 6220TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
    19:41:28.0132 6220TDTCP - ok
    19:41:28.0158 6220tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
    19:41:28.0161 6220tdx - ok
    19:41:28.0208 6220TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
    19:41:28.0210 6220TermDD - ok
    19:41:28.0269 6220TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
    19:41:28.0283 6220TermService - ok
    19:41:28.0298 6220Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
    19:41:28.0300 6220Themes - ok
    19:41:28.0334 6220THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
    19:41:28.0336 6220THREADORDER - ok
    19:41:28.0360 6220TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
    19:41:28.0363 6220TrkWks - ok
    19:41:28.0422 6220TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
    19:41:28.0426 6220TrustedInstaller - ok
    19:41:28.0465 6220tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
    19:41:28.0466 6220tssecsrv - ok
    19:41:28.0496 6220TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
    19:41:28.0498 6220TsUsbFlt - ok
    19:41:28.0526 6220TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
    19:41:28.0527 6220TsUsbGD - ok
    19:41:28.0570 6220tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
    19:41:28.0573 6220tunnel - ok
    19:41:28.0592 6220uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
    19:41:28.0593 6220uagp35 - ok
    19:41:28.0631 6220udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
    19:41:28.0636 6220udfs - ok
    19:41:28.0675 6220UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
    19:41:28.0679 6220UI0Detect - ok
    19:41:28.0716 6220uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
    19:41:28.0717 6220uliagpkx - ok
    19:41:28.0766 6220umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
    19:41:28.0767 6220umbus - ok
    19:41:28.0792 6220UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
    19:41:28.0793 6220UmPass - ok
    19:41:29.0004 6220UNS (a678e5ddd974903dd71f503bdcaca218) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    19:41:29.0024 6220UNS - ok
    19:41:29.0128 6220Updater Service for StartNow Toolbar (87d6b7229afbba2ea523e28c5137c980) C:\Program Files (x86)\StartNow Toolbar\ToolbarUpdaterService.exe
    19:41:29.0235 6220Updater Service for StartNow Toolbar - ok
    19:41:29.0331 6220upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
    19:41:29.0342 6220upnphost - ok
    19:41:29.0414 6220USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
    19:41:29.0416 6220USBAAPL64 - ok
    19:41:29.0456 6220usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
    19:41:29.0458 6220usbccgp - ok
    19:41:29.0490 6220usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
    19:41:29.0493 6220usbcir - ok
    19:41:29.0513 6220usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
    19:41:29.0515 6220usbehci - ok
    19:41:29.0549 6220usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
    19:41:29.0556 6220usbhub - ok
    19:41:29.0583 6220usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
    19:41:29.0584 6220usbohci - ok
    19:41:29.0620 6220usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    19:41:29.0622 6220usbprint - ok
    19:41:29.0661 6220usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
    19:41:29.0663 6220usbscan - ok
    19:41:29.0687 6220USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    19:41:29.0689 6220USBSTOR - ok
    19:41:29.0735 6220usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
    19:41:29.0736 6220usbuhci - ok
    19:41:29.0779 6220usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
    19:41:29.0782 6220usbvideo - ok
    19:41:29.0805 6220UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
    19:41:29.0809 6220UxSms - ok
    19:41:29.0825 6220VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
    19:41:29.0827 6220VaultSvc - ok
    19:41:29.0860 6220vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
    19:41:29.0861 6220vdrvroot - ok
    19:41:29.0903 6220vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
    19:41:29.0915 6220vds - ok
    19:41:29.0953 6220vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    19:41:29.0955 6220vga - ok
    19:41:29.0976 6220VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    19:41:29.0978 6220VgaSave - ok
    19:41:30.0017 6220vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
    19:41:30.0022 6220vhdmp - ok
    19:41:30.0035 6220viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
    19:41:30.0037 6220viaide - ok
    19:41:30.0086 6220volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
    19:41:30.0089 6220volmgr - ok
    19:41:30.0128 6220volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
    19:41:30.0135 6220volmgrx - ok
    19:41:30.0176 6220volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
    19:41:30.0182 6220volsnap - ok
    19:41:30.0219 6220vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
    19:41:30.0223 6220vsmraid - ok
    19:41:30.0315 6220VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
    19:41:30.0342 6220VSS - ok
    19:41:30.0454 6220vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
    19:41:30.0456 6220vwifibus - ok
    19:41:30.0493 6220vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    19:41:30.0495 6220vwififlt - ok
    19:41:30.0531 6220vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
    19:41:30.0533 6220vwifimp - ok
    19:41:30.0575 6220W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
    19:41:30.0587 6220W32Time - ok
    19:41:30.0616 6220WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
    19:41:30.0618 6220WacomPen - ok
    19:41:30.0667 6220WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    19:41:30.0670 6220WANARP - ok
    19:41:30.0677 6220Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
    19:41:30.0679 6220Wanarpv6 - ok
    19:41:30.0778 6220WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
    19:41:30.0796 6220WatAdminSvc - ok
    19:41:30.0895 6220wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
    19:41:30.0917 6220wbengine - ok
    19:41:31.0005 6220WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
    19:41:31.0014 6220WbioSrvc - ok
    19:41:31.0049 6220wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
    19:41:31.0060 6220wcncsvc - ok
    19:41:31.0083 6220WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
    19:41:31.0088 6220WcsPlugInService - ok
    19:41:31.0152 6220Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
    19:41:31.0154 6220Wd - ok
    19:41:31.0202 6220Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    19:41:31.0215 6220Wdf01000 - ok
    19:41:31.0244 6220WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    19:41:31.0248 6220WdiServiceHost - ok
    19:41:31.0251 6220WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
    19:41:31.0254 6220WdiSystemHost - ok
    19:41:31.0296 6220wdkmd (5e1640435dd54d00451156ca5340b109) C:\Windows\system32\DRIVERS\WDKMD.sys
    19:41:31.0299 6220wdkmd - ok
    19:41:31.0332 6220WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
    19:41:31.0340 6220WebClient - ok
    19:41:31.0386 6220Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
    19:41:31.0394 6220Wecsvc - ok
    19:41:31.0421 6220wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
    19:41:31.0427 6220wercplsupport - ok
    19:41:31.0458 6220WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
    19:41:31.0463 6220WerSvc - ok
    19:41:31.0504 6220WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    19:41:31.0505 6220WfpLwf - ok
    19:41:31.0526 6220WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    19:41:31.0528 6220WIMMount - ok
    19:41:31.0559 6220WinDefend - ok
    19:41:31.0569 6220WinHttpAutoProxySvc - ok
    19:41:31.0636 6220Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
    19:41:31.0642 6220Winmgmt - ok
    19:41:31.0751 6220WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
    19:41:31.0787 6220WinRM - ok
    19:41:31.0913 6220WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUSB.sys
    19:41:31.0915 6220WinUsb - ok
    19:41:31.0978 6220Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
    19:41:31.0996 6220Wlansvc - ok
    19:41:32.0065 6220wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    19:41:32.0068 6220wlcrasvc - ok
    19:41:32.0239 6220wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    19:41:32.0259 6220wlidsvc - ok
    19:41:32.0394 6220WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
    19:41:32.0396 6220WmiAcpi - ok
    19:41:32.0453 6220wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
    19:41:32.0459 6220wmiApSrv - ok
    19:41:32.0504 6220WMPNetworkSvc - ok
    19:41:32.0528 6220WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
    19:41:32.0534 6220WPCSvc - ok
    19:41:32.0562 6220WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
    19:41:32.0569 6220WPDBusEnum - ok
    19:41:32.0592 6220ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    19:41:32.0594 6220ws2ifsl - ok
    19:41:32.0613 6220wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
    19:41:32.0619 6220wscsvc - ok
    19:41:32.0625 6220WSearch - ok
    19:41:32.0738 6220wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
    19:41:32.0766 6220wuauserv - ok
    19:41:32.0886 6220WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
    19:41:32.0888 6220WudfPf - ok
    19:41:32.0922 6220WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
    19:41:32.0926 6220WUDFRd - ok
    19:41:32.0957 6220wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
    19:41:32.0963 6220wudfsvc - ok
    19:41:32.0994 6220WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
    19:41:33.0003 6220WwanSvc - ok
    19:41:33.0040 6220MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    19:41:33.0204 6220\Device\Harddisk0\DR0 - ok
    19:41:33.0210 6220Boot (0x1200) (a928b5ddec82a2dec7a51ea377acdd7f) \Device\Harddisk0\DR0\Partition0
    19:41:33.0212 6220\Device\Harddisk0\DR0\Partition0 - ok
    19:41:33.0225 6220Boot (0x1200) (be37cf771f59395cf61b569e79f6d024) \Device\Harddisk0\DR0\Partition1
    19:41:33.0227 6220\Device\Harddisk0\DR0\Partition1 - ok
    19:41:33.0257 6220Boot (0x1200) (167c4ff138097275994dfbd4efc00f7a) \Device\Harddisk0\DR0\Partition2
    19:41:33.0260 6220\Device\Harddisk0\DR0\Partition2 - ok
    19:41:33.0276 6220Boot (0x1200) (9677294e9f758f36dccb28a04f965289) \Device\Harddisk0\DR0\Partition3
    19:41:33.0277 6220\Device\Harddisk0\DR0\Partition3 - ok
    19:41:33.0278 6220============================================================
    19:41:33.0278 6220Scan finished
    19:41:33.0278 6220============================================================
    19:41:33.0300 2432Detected object count: 0
    19:41:33.0300 2432Actual detected object count: 0
     
  17. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    Download the FixTDSS.exe

    Save the file to your Windows desktop.
    Close all running programs.
    If you are running Windows XP, turn off System Restore. How to turn off or turn on Windows XP System Restore
    Double-click the FixTDSS.exe file to start the removal tool.
    Click Start to begin the process, and then allow the tool to run.
    OK any security prompts.
    Restart the computer when prompted by the tool.
    After the computer has started, the tool will inform you of the state of infection (make sure to let me know what it said)
    If you are running Windows XP, re-enable System Restore.
     
  18. muddie

    muddie TS Rookie Topic Starter Posts: 45

    After running FixTDSS and allowing it to restart my computer, it said "No infections were found".

    Does that mean my computer is clean?
     
  19. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    We're not done...

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
    There are 4 different versions. If one of them won't run then download and try to run the other one.
    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    * Rkill.com
    * Rkill.scr
    * Rkill.exe
    • Double-click on the Rkill icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  20. muddie

    muddie TS Rookie Topic Starter Posts: 45

    I'm not sure what script blocking is and I don't know how to disable it. The only 2 computer protection programs I have is Microsoft Security Essentials and Malwarebytes Anti-Malware.
     
  21. muddie

    muddie TS Rookie Topic Starter Posts: 45

    I ran Combofix and it automatically restarted my computer and produced a log after that. But I couldn't open any of my programs and when I click on any desktop icon it says something along the lines of " illegal operation attempted on a registry key ...".
    So I restarted my computer and everything was fine again.
     
  22. muddie

    muddie TS Rookie Topic Starter Posts: 45

    ComboFix 12-06-02.01 - Michael 06/02/2012 0:53.2.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8140.6209 [GMT -4:00]
    Running from: c:\users\Michael\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-05-02 to 2012-06-02 )))))))))))))))))))))))))))))))
    .
    .
    2012-06-02 05:00 . 2012-06-02 05:00--------d-----w-c:\users\Default\AppData\Local\temp
    2012-06-01 14:41 . 2012-05-08 17:028955792----a-w-c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-05-29 02:11 . 2012-05-29 02:11--------d-----w-c:\users\Michael\AppData\Roaming\Malwarebytes
    2012-05-29 02:11 . 2012-05-29 02:11--------d-----w-c:\programdata\Malwarebytes
    2012-05-29 02:11 . 2012-04-04 19:5624904----a-w-c:\windows\system32\drivers\mbam.sys
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin7.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin6.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin5.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin4.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin3.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin2.dll
    2012-05-22 01:48 . 2012-05-22 01:48159744----a-w-c:\program files (x86)\Internet Explorer\Plugins\npqtplugin.dll
    2012-05-22 01:47 . 2012-05-22 01:48--------d-----w-c:\program files (x86)\QuickTime
    2012-05-21 21:45 . 2012-05-21 21:45--------d-----w-c:\users\Michael\AppData\Local\Vid-Saver
    2012-05-21 21:45 . 2012-05-21 21:45--------d-----w-c:\program files (x86)\Vid-Saver
    2012-05-21 15:48 . 2012-05-21 15:4870304----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-05-21 15:48 . 2012-05-21 15:48419488----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
    2012-05-18 13:34 . 2012-05-18 13:34--------d-----w-c:\users\Michael\AppData\Roaming\StartNow Toolbar
    2012-05-11 22:12 . 2012-03-03 06:351544704----a-w-c:\windows\system32\DWrite.dll
    2012-05-11 22:12 . 2012-03-03 05:311077248----a-w-c:\windows\SysWow64\DWrite.dll
    2012-05-11 22:12 . 2012-03-31 06:055559664----a-w-c:\windows\system32\ntoskrnl.exe
    2012-05-11 22:12 . 2012-03-31 03:103146240----a-w-c:\windows\system32\win32k.sys
    2012-05-11 22:12 . 2012-03-31 04:393968368----a-w-c:\windows\SysWow64\ntkrnlpa.exe
    2012-05-11 22:12 . 2012-03-31 04:393913072----a-w-c:\windows\SysWow64\ntoskrnl.exe
    2012-05-11 22:12 . 2012-03-17 07:5875120----a-w-c:\windows\system32\drivers\partmgr.sys
    2012-05-11 22:12 . 2012-03-30 11:351918320----a-w-c:\windows\system32\drivers\tcpip.sys
    2012-05-11 22:12 . 2012-03-31 05:401367552----a-w-c:\program files\Common Files\Microsoft Shared\ink\journal.dll
    2012-05-11 22:12 . 2012-03-31 04:29936960----a-w-c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-05-07 20:07 . 2012-05-07 20:07--------d-----w-c:\users\Michael\AppData\Local\Windows Live
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-04-19 00:56 . 2012-04-19 00:5694208----a-w-c:\windows\SysWow64\QuickTimeVR.qtx
    2012-04-19 00:56 . 2012-04-19 00:5669632----a-w-c:\windows\SysWow64\QuickTime.qts
    2012-03-21 00:44 . 2010-10-25 04:2598688----a-w-c:\windows\system32\drivers\NisDrvWFP.sys
    2012-03-21 00:44 . 2010-10-25 04:25203888----a-w-c:\windows\system32\drivers\MpFilter.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2012-06-02_04.42.29 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2010-11-21 03:09 . 2012-06-02 04:5052526 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-07-14 05:10 . 2012-06-02 04:5039582 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
    + 2011-06-10 20:02 . 2012-06-02 04:5012318 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1837406275-2172662107-3430232410-1000_UserData.bin
    - 2012-06-02 04:42 . 2012-06-02 04:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2012-06-02 05:01 . 2012-06-02 05:012048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2012-06-02 04:42 . 2012-06-02 04:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2012-06-02 05:01 . 2012-06-02 05:012048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-07-14 02:36 . 2012-06-02 04:55626540 c:\windows\system32\perfh009.dat
    - 2009-07-14 02:36 . 2012-06-02 03:37626540 c:\windows\system32\perfh009.dat
    + 2009-07-14 02:36 . 2012-06-02 04:55107784 c:\windows\system32\perfc009.dat
    - 2009-07-14 02:36 . 2012-06-02 03:37107784 c:\windows\system32\perfc009.dat
    - 2009-07-14 05:01 . 2012-06-02 04:41289812 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    + 2009-07-14 05:01 . 2012-06-02 05:00289812 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    - 2011-06-02 09:13 . 2012-06-02 04:412367552 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    + 2011-06-02 09:13 . 2012-06-02 05:002367552 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-13 283160]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-15 336384]
    "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
    "HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-02-15 94264]
    "RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2010-02-03 87336]
    "BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-01-25 75048]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2012-04-04 35736]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
    "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-03-16 61112]
    "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-06-13 336440]
    "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2011-06-14 587320]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
    "Malwarebytes' Anti-Malware"="c:\michael's file\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "EnableShellExecuteHooks"= 1 (0x1)
    .
    [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security PackagesREG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/06/02 02:04;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2011-01-25 241648]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-21 257696]
    R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]
    R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    R3 hpCMSrv;HP Connection Manager 4.0 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-02-15 1071160]
    R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-01-05 340240]
    R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
    R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
    R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x]
    R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x]
    R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
     
  23. muddie

    muddie TS Rookie Topic Starter Posts: 45

    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
    S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
    S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-02-18 265544]
    S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
    S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
    S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
    S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2011-06-14 26680]
    S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-13 13336]
    S2 MBAMService;MBAMService;c:\michael's file\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
    S2 RoxioNow Service;RoxioNow Service;c:\program files (x86)\Roxio\RoxioNow Player\RNowSvc.exe [2010-11-26 399344]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-22 2656280]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
    S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]
    S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [x]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
    S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [x]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
    S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
    S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
    S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
    S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
    S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
    S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
    S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [x]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_38F51D56
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-06-02 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-21 15:48]
    .
    2012-06-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837406275-2172662107-3430232410-1000Core.job
    - c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-28 19:44]
    .
    2012-06-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1837406275-2172662107-3430232410-1000UA.job
    - c:\users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-28 19:44]
    .
    2012-05-29 c:\windows\Tasks\HPCeeScheduleForMICHAEL-HP$.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
    .
    2012-05-10 c:\windows\Tasks\HPCeeScheduleForMichael.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-03-11 1128448]
    "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-01-05 1933584]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
    TCP: DhcpNameServer = 129.97.2.1 129.97.129.10 129.97.2.2
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\windows\SysWOW64\ezSharedSvcHost.exe
    c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
    c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    .
    **************************************************************************
    .
    Completion time: 2012-06-02 01:05:04 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-06-02 05:05
    ComboFix2.txt 2012-06-02 04:46
    .
    Pre-Run: 651,591,139,328 bytes free
    Post-Run: 651,273,859,072 bytes free
    .
    - - End Of File - - 6E17CE5F8C5501B84B972B4EA356A22D
     
  24. Broni

    Broni Malware Annihilator Posts: 47,684   +268

    Combofix log looks good.

    How is computer doing?

    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Under the Custom Scan box paste this in:


    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\tasks\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /I " " /c
    dir /b "%systemroot%\*.exe" | find /I " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    %systemroot%\system32\winlog\*.*
    %systemroot%\system32\Language\*.*
    %systemroot%\system32\Settings\*.*
    %systemroot%\system32\*.quo
    %SYSTEMROOT%\AppPatch\*.exe
    %SYSTEMROOT%\inf\*.exe
    %SYSTEMROOT%\Installer\*.exe
    %systemroot%\system32\config\*.bak2
    %systemroot%\system32\Computers\*.*
    %SystemRoot%\system32\Sound\*.*
    %SystemRoot%\system32\SpecialImg\*.*
    %SystemRoot%\system32\code\*.*
    %SystemRoot%\system32\draft\*.*
    %SystemRoot%\system32\MSSSys\*.*
    %ProgramFiles%\Javascript\*.*
    %systemroot%\pchealth\helpctr\System\*.exe /s
    %systemroot%\Web\*.exe
    %systemroot%\system32\msn\*.*
    %systemroot%\system32\*.tro
    %AppData%\Microsoft\Installer\msupdates\*.*
    %ProgramFiles%\Messenger\*.*
    %systemroot%\system32\systhem32\*.*
    %systemroot%\system\*.exe
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    /md5start
    /md5stop


    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  25. muddie

    muddie TS Rookie Topic Starter Posts: 45

    Well, I haven't seen the Malwarbyte's pop up I mentioned in my first post in a while. But my laptop's fan runs a lot more frequently than it did couple weeks ago (laptop feels really hot sometimes) which makes me think I have other programs running in the background. But there isn't any.
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.