Solved Search engine redirect malware

yeahisgood

Posts: 79   +0
I am getting a search engine redirect. Recently, I removed some trojan viruses using MSE and Malwarebytes. However, when I restarted Windows I got a .dll error window pop up for xtlbj.dll.

I would appreciate any help you could provide.
 
You've been to this forum before so you should know what the deal is...

Please, complete all steps listed here: https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
 
Broni,

Thanks once again


Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.08.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: OWNER-PC [administrator]
9/10/2012 7:53:51 AM
mbam-log-2012-09-10 (07-53-51).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 230789
Time elapsed: 5 minute(s), 39 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.09.08.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: OWNER-PC [administrator]
9/10/2012 7:53:51 AM
mbam-log-2012-09-10 (07-53-51).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 230789
Time elapsed: 5 minute(s), 39 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.6.2
Run by Owner at 8:48:04 on 2012-09-10
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.3110 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\Elantech\ETDCtrlHelper.exe
C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Windows\Samsung\PanelMgr\caller64.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
C:\Program Files (x86)\Secunia\PSI\PSIA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Secunia\PSI\sua.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\notepad.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D9Y5HIRG\8gf9qkq5.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Microsoft Security Client\MpCmdRun.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\DllHost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.siccode.com/
mStart Page = hxxp://samsung.msn.com
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: W2PBrowser Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
uRun: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [nerlex] rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track
uRun: [Deployment] rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW
mRun: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} - hxxps://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
TCP: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
TCP: Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859} : DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
TCP: Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859}\D4169726163686737373 : DhcpNameServer = 167.206.245.129 167.206.245.130
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
BHO-X64: HP Print Enhancer - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: W2PBrowser Class: {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
BHO-X64: W2PBrowser Browser Helper - No File
BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
BHO-X64: URLRedirectionBHO - No File
BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
BHO-X64: HP Smart BHO Class - No File
TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
mRun-x64: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe
AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.brc -
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
R1 SABI;SAMSUNG Kernel Driver For Windows 7;\??\C:\Windows\system32\Drivers\SABI.sys --> C:\Windows\system32\Drivers\SABI.sys [?]
R1 VWiFiFlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-8-31 408576]
R2 HssWd;Hotspot Shield Monitoring Service;C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS --> C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-12-22 1997416]
R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2012-6-27 1326176]
R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-6-27 681056]
R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-22 2655768]
R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-8-31 911872]
R3 bpenum;bpenum;C:\Windows\system32\DRIVERS\bpenum.sys --> C:\Windows\system32\DRIVERS\bpenum.sys [?]
R3 bpmp;Intel(R) Centrino(R) WiMAX 6050 Series;C:\Windows\system32\DRIVERS\bpmp.sys --> C:\Windows\system32\DRIVERS\bpmp.sys [?]
R3 bpusb;bpusb;C:\Windows\system32\Drivers\bpusb.sys --> C:\Windows\system32\Drivers\bpusb.sys [?]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
R3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
S2 CLKMSVC10_38F51D56;CyberLink Product - 2010/12/22 19:14:12;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-8-24 246256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-18 136176]
S2 hshld;Hotspot Shield Service;C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-3-26 542040]
S2 jjvop;jjvop;C:\Users\Owner\AppData\Roaming\clmioni1.bat [2012-9-8 87]
S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-8-19 8192]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 250568]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-18 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-6-13 113120]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-2 340240]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 Samsung UPD Service;Samsung UPD Service;"C:\Windows\System32\SUPDSvc.exe" --> C:\Windows\System32\SUPDSvc.exe [?]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-10-8 150016]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-09-10 12:47:00 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C3AE019-23CD-47BB-B44C-DDA3E0EEC535}\mpengine.dll
2012-09-09 01:45:08 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-09-08 21:51:42 87 ---h--w- C:\Users\Owner\AppData\Roaming\clmioni1.bat
2012-09-08 21:45:32 110592 ----a-w- C:\ProgramData\2jFf5J64.exe_
2012-09-08 21:45:32 110592 ----a-w- C:\ProgramData\2jFf5J64.exe
2012-09-08 02:21:05 -------- d-----w- C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
2012-09-08 02:21:01 416768 ----a-w- C:\Users\Owner\AppData\Roaming\nerlex.dll
2012-09-08 02:20:07 90 ---h--w- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
2012-09-06 20:16:40 916456 ----a-w- C:\Windows\System32\deployJava1.dll
2012-09-06 20:16:40 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
2012-09-06 20:16:33 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2012-09-04 21:59:01 -------- d-----w- C:\Users\Owner\AppData\Roaming\pdfforge
2012-09-04 21:28:26 177640 ----a-w- C:\Windows\System32\drivers\ssadmdm.sys
2012-09-04 21:28:26 16872 ----a-w- C:\Windows\System32\drivers\ssadmdfl.sys
2012-09-04 21:28:26 157672 ----a-w- C:\Windows\System32\drivers\ssadbus.sys
2012-09-04 21:28:26 13800 ----a-w- C:\Windows\System32\drivers\ssadwhnt.sys
2012-09-04 21:28:26 13800 ----a-w- C:\Windows\System32\drivers\ssadwh.sys
2012-09-04 21:28:26 13288 ----a-w- C:\Windows\System32\drivers\ssadcmnt.sys
2012-09-04 21:28:26 13288 ----a-w- C:\Windows\System32\drivers\ssadcm.sys
2012-08-29 14:00:28 60864 ----a-w- C:\Users\Owner\g2mdlhlpx.exe
2012-08-24 11:44:50 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-08-24 11:44:50 366592 ----a-w- C:\Windows\System32\qdvd.dll
2012-08-24 01:38:28 5563840 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f126a2711cd819803\skydrivesetup.exe
2012-08-24 01:38:28 -------- d-----w- C:\Program Files (x86)\Microsoft SkyDrive
2012-08-24 01:38:27 -------- d-----r- C:\Users\Owner\SkyDrive
2012-08-24 01:38:18 -------- d-----w- C:\ProgramData\Microsoft SkyDrive
2012-08-24 01:01:41 751104 ----a-w- C:\Windows\System32\win32spl.dll
2012-08-24 01:01:41 67072 ----a-w- C:\Windows\splwow64.exe
2012-08-24 01:01:41 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2012-08-24 01:01:41 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
2012-08-24 01:01:36 503808 ----a-w- C:\Windows\System32\srcore.dll
2012-08-24 01:01:36 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2012-08-24 01:01:33 59392 ----a-w- C:\Windows\System32\browcli.dll
2012-08-24 01:01:33 136704 ----a-w- C:\Windows\System32\browser.dll
2012-08-24 01:01:32 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
2012-08-24 01:00:53 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-08-24 01:00:52 956928 ----a-w- C:\Windows\System32\localspl.dll
2012-08-24 00:57:49 -------- d-----w- C:\Users\Owner\AppData\Local\Secunia PSI
2012-08-24 00:57:11 -------- d-----w- C:\Program Files (x86)\Secunia
2012-08-24 00:53:49 -------- d-----w- C:\Program Files (x86)\FileHippo.com
2012-08-24 00:39:52 -------- d-----w- C:\Program Files\WOT
2012-08-24 00:39:52 -------- d-----w- C:\Program Files (x86)\WOT
2012-08-23 21:28:23 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2012-08-23 21:28:16 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2012-08-23 16:01:09 -------- d-----w- C:\Program Files (x86)\ESET
2012-08-23 04:50:32 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-08-23 04:50:32 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-22 19:32:44 -------- d-----w- C:\$RECYCLE.BIN
2012-08-22 14:58:27 -------- d-----w- C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
2012-08-16 19:45:50 -------- d-----w- C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
2012-08-16 19:45:37 -------- d-----w- C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
2012-08-16 19:41:33 -------- d-----w- C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
2012-08-16 19:41:24 -------- d-----w- C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
2012-08-16 19:37:26 -------- d-----w- C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
2012-08-16 19:37:14 -------- d-----w- C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
2012-08-16 19:32:27 -------- d-----w- C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
2012-08-16 19:32:16 -------- d-----w- C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
2012-08-16 19:28:37 -------- d-----w- C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
2012-08-16 19:20:58 -------- d-----w- C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
2012-08-16 19:20:46 -------- d-----w- C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
2012-08-15 17:51:28 -------- d-----w- C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
2012-08-15 17:51:15 -------- d-----w- C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
2012-08-14 15:03:42 -------- d-----w- C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
2012-08-14 15:03:18 -------- d-----w- C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
2012-08-14 14:46:32 -------- d-----w- C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
2012-08-14 14:42:40 -------- d-----w- C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
2012-08-14 14:42:12 -------- d-----w- C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
2012-08-14 14:32:49 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0E999AD8-2F3C-4985-9FFC-7E1842C661EF}\gapaengine.dll
2012-08-14 14:30:17 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-08-14 14:30:15 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-08-14 11:23:22 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
2012-08-13 21:37:08 -------- d-----w- C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
2012-08-13 21:36:52 -------- d-----w- C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
2012-08-13 18:28:26 -------- d-----w- C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
2012-08-13 18:28:12 -------- d-----w- C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
2012-08-13 14:40:38 -------- d-----w- C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
2012-08-13 14:39:34 -------- d-----w- C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
2012-08-13 10:35:18 -------- d-----w- C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
2012-08-13 10:33:25 -------- d-----w- C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
2012-08-12 10:38:12 -------- d-----w- C:\Users\Owner\AppData\Local\{E727C9E2-E3DE-49F2-9DC0-AF9EC23EB817}
2012-08-12 03:26:15 -------- d-----w- C:\Users\Owner\AppData\Local\{D458277E-8667-4B04-9785-D180139CFE5C}
.
==================== Find3M ====================
.
2012-09-08 21:51:29 210051234 ----a-w- C:\Users\Owner\AppData\Roaming\jjvop.exe
2012-08-31 18:52:38 73416 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-31 18:52:38 696520 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-08-23 21:28:11 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-07-28 07:09:02 57792 ----a-w- C:\Windows\SysWow64\sirenacm.dll
2012-07-26 23:08:06 862664 ----a-w- C:\Windows\SysWow64\msvcr110.dll
2012-07-26 23:08:06 534480 ----a-w- C:\Windows\SysWow64\msvcp110.dll
2012-07-26 23:08:06 251864 ----a-w- C:\Windows\SysWow64\vccorlib110.dll
2012-07-26 23:08:06 153536 ----a-w- C:\Windows\SysWow64\atl110.dll
2012-07-26 23:08:06 115656 ----a-w- C:\Windows\SysWow64\vcomp110.dll
2012-07-26 19:22:10 828872 ----a-w- C:\Windows\System32\msvcr110.dll
2012-07-26 19:22:10 661448 ----a-w- C:\Windows\System32\msvcp110.dll
2012-07-26 19:22:10 354264 ----a-w- C:\Windows\System32\vccorlib110.dll
2012-07-26 19:22:10 177096 ----a-w- C:\Windows\System32\atl110.dll
2012-07-26 19:22:10 124360 ----a-w- C:\Windows\System32\vcomp110.dll
2012-07-17 19:14:44 253184 ----a-w- C:\Windows\System32\LIVESSP.DLL
2012-07-17 18:49:00 209648 ----a-w- C:\Windows\SysWow64\LIVESSP.DLL
2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2012-06-25 20:04:24 1394248 ----a-w- C:\Windows\SysWow64\msxml4.dll
.
============= FINISH: 8:48:50.16 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 7/15/2011 2:22:35 AM
System Uptime: 9/9/2012 10:14:58 PM (10 hours ago)
.
Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | RC512
Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz | CPU 1 | 780/100mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 272 GiB total, 120.273 GiB free.
D: is FIXED (NTFS) - 406 GiB total, 132.365 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: Officejet 4500 G510n-z
Device ID: ROOT\IMAGE\0001
Manufacturer: HP
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\IMAGE\0001
Service: StillCam
.
Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
Description: Officejet 4500 G510n-z
Device ID: ROOT\MULTIFUNCTION\0000
Manufacturer: HP
Name: Officejet 4500 G510n-z
PNP Device ID: ROOT\MULTIFUNCTION\0000
Service:
.
Class GUID:
Description:
Device ID: ROOT\NET\0000
Manufacturer:
Name:
PNP Device ID: ROOT\NET\0000
Service:
.
==== System Restore Points ===================
.
RP183: 8/30/2012 9:56:13 PM - Windows Update
RP184: 9/2/2012 7:44:38 PM - Windows Backup
RP185: 9/3/2012 10:58:15 PM - Windows Update
RP186: 9/6/2012 4:15:59 PM - Installed Java 7 Update 7 (64-bit)
RP187: 9/7/2012 2:17:20 AM - Windows Update
RP188: 9/10/2012 12:45:48 AM - Windows Backup
.
==== Installed Programs ======================
.
???? Windows Live
????? Windows Live
???????? ?????????? Windows Live
?????????? (????????????? ??????)
4500_G510nz_Help
4500G510nz
4500G510nz_Software_Min
ActiveState Komodo Edit 6.1.2
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.4)
Agatha Christie - Death on the Nile
Audacity 1.3.14 (Unicode)
„Windows Live Essentials“
„Windows Live Mail“
„Windows Live Messenger“
BatteryLifeExtender
Bejeweled 2 Deluxe
BufferChm
Build-a-lot
CamStudio OSS Desktop Recorder
ChargeableUSB
Chuzzle Deluxe
CyberLink Media Suite
CyberLink MediaShow
CyberLink Power2Go
CyberLink PowerDirector
CyberLink PowerDVD 10
CyberLink YouCam
D3DX10
Destinations
DeviceDiscovery
Diner Dash 2 Restaurant Rescue
DocMgr
DocProc
Easy Display Manager
Easy Migration
Easy Network Manager
Easy SpeedUp Manager
EasyBatteryManager
EasyFileShare
ESET Online Scanner v3
Farm Frenzy
Fast Start
Fax
FileHippo.com Update Checker
FileZilla Client 3.5.3
Google Chrome
Google Earth
Google Update Helper
GPBaseService2
Hewlett-Packard ACLM.NET v1.1.0.0
Hotspot Shield 2.52
HP Officejet 6500 E710n-z Help
HP Product Detection
HP Update
HPProductAssistant
HPSSupply
Insaniquarium Deluxe
Intel(R) Control Center
Intel(R) Management Engine Components
Intel(R) Processor Graphics
Intel(R) Rapid Storage Technology
Intel(R) Wireless Display
IrfanView (remove only)
Java 7 Update 6
Java Auto Updater
Java(TM) 6 Update 33
John Deere Drive Green
Junk Mail filter update
Malwarebytes Anti-Malware version 1.62.0.1300
MarketResearch
Microsoft Office 2010
Microsoft SkyDrive
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft_VC80_CRT_x86
Microsoft_VC90_CRT_x86
Movie Color Enhancer
Mozilla Firefox 14.0.1 (x86 en-US)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
MSVCRT110
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB2721691)
Multimedia POP
Norton Online Backup
Peggle
Penguins!
Photo Common
Plants vs. Zombies
Poczta uslugi Windows Live
Podstawowe programy Windows Live
Polar Golfer
Pošta Windows Live
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Renesas Electronics USB 3.0 Host Controller Driver
Samsung AnyWeb Print
Samsung Recovery Solution 5
Samsung Support Center 1.0
Samsung Universal Print Driver
Samsung Universal Scan Driver
Samsung Update Plus
Scan
Secunia PSI (3.0.0.2004)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Skype™ 5.10
SmartWebPrinting
SolutionCenter
Status
Toolbox
TrayApp
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
User Guide
VC80CRTRedist - 8.0.50727.6195
Visual Studio 2008 x64 Redistributables
VLC media player 2.0.2
Vuze
WebReg
WildTangent Games
WildTangent ORB Game Console
Windows Live
Windows Live ??
Windows Live ?? ???
Windows Live ???
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Mail
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live Pošta
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Liven peruspaketti
Windows Liven sähköposti
Zuma Deluxe
.
==== Event Viewer Messages From Past Week ========
.
9/9/2012 6:16:34 AM, Error: Schannel [36887] - The following fatal alert was received: 80.
9/8/2012 9:59:58 PM, Error: Service Control Manager [7003] - The Hotspot Shield Service service depends the following service: taphss. This service might not be installed.
9/8/2012 5:51:44 PM, Error: Service Control Manager [7030] - The jjvop service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
9/8/2012 10:00:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the jjvop service to connect.
9/7/2012 8:38:46 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer JOHN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{DEAA0459-FD77-4007-B31D-7998BC471859}. The master browser is stopping or an election is being forced.
9/5/2012 11:04:02 PM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
9/10/2012 3:31:01 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
9/10/2012 3:25:08 AM, Error: volsnap [35] - The shadow copies of volume D: were aborted because the shadow copy storage failed to grow.
.
==== End Of File ===========================
 
Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.

=================================

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

==============================

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
 
20:51:31.0237 6396 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
20:51:31.0547 6396 ============================================================
20:51:31.0547 6396 Current date / time: 2012/09/10 20:51:31.0547
20:51:31.0547 6396 SystemInfo:
20:51:31.0547 6396
20:51:31.0547 6396 OS Version: 6.1.7601 ServicePack: 1.0
20:51:31.0547 6396 Product type: Workstation
20:51:31.0547 6396 ComputerName: OWNER-PC
20:51:31.0547 6396 UserName: Owner
20:51:31.0547 6396 Windows directory: C:\Windows
20:51:31.0547 6396 System windows directory: C:\Windows
20:51:31.0547 6396 Running under WOW64
20:51:31.0547 6396 Processor architecture: Intel x64
20:51:31.0547 6396 Number of processors: 8
20:51:31.0547 6396 Page size: 0x1000
20:51:31.0547 6396 Boot type: Normal boot
20:51:31.0547 6396 ============================================================
20:51:33.0197 6396 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:51:33.0212 6396 ============================================================
20:51:33.0212 6396 \Device\Harddisk0\DR0:
20:51:33.0228 6396 MBR partitions:
20:51:33.0228 6396 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:51:33.0228 6396 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x22000000
20:51:33.0243 6396 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x22033000, BlocksNum 0x32CAE800
20:51:33.0243 6396 ============================================================
20:51:33.0306 6396 C: <-> \Device\Harddisk0\DR0\Partition2
20:51:33.0415 6396 D: <-> \Device\Harddisk0\DR0\Partition3
20:51:33.0446 6396 ============================================================
20:51:33.0446 6396 Initialize success
20:51:33.0446 6396 ============================================================
20:52:12.0146 4916 ============================================================
20:52:12.0146 4916 Scan started
20:52:12.0146 4916 Mode: Manual;
20:52:12.0146 4916 ============================================================
20:52:13.0236 4916 ================ Scan system memory ========================
20:52:13.0236 4916 System memory - ok
20:52:13.0236 4916 ================ Scan services =============================
20:52:13.0496 4916 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:52:13.0506 4916 1394ohci - ok
20:52:13.0586 4916 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:52:13.0586 4916 ACPI - ok
20:52:13.0636 4916 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:52:13.0646 4916 AcpiPmi - ok
20:52:13.0916 4916 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:52:14.0116 4916 AdobeARMservice - ok
20:52:14.0296 4916 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:52:14.0296 4916 AdobeFlashPlayerUpdateSvc - ok
20:52:14.0346 4916 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
20:52:14.0356 4916 adp94xx - ok
20:52:14.0376 4916 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
20:52:14.0396 4916 adpahci - ok
20:52:14.0436 4916 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
20:52:14.0436 4916 adpu320 - ok
20:52:14.0476 4916 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:52:14.0476 4916 AeLookupSvc - ok
20:52:14.0556 4916 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:52:14.0566 4916 AFD - ok
20:52:14.0616 4916 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:52:14.0616 4916 agp440 - ok
20:52:14.0646 4916 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
20:52:14.0646 4916 ALG - ok
20:52:14.0696 4916 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
20:52:14.0696 4916 aliide - ok
20:52:14.0716 4916 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
20:52:14.0716 4916 amdide - ok
20:52:14.0746 4916 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
20:52:14.0746 4916 AmdK8 - ok
20:52:14.0776 4916 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
20:52:14.0776 4916 AmdPPM - ok
20:52:14.0806 4916 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
20:52:14.0816 4916 amdsata - ok
20:52:14.0846 4916 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
20:52:14.0856 4916 amdsbs - ok
20:52:14.0876 4916 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
20:52:14.0876 4916 amdxata - ok
20:52:14.0906 4916 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
20:52:14.0906 4916 AppID - ok
20:52:14.0936 4916 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:52:14.0936 4916 AppIDSvc - ok
20:52:14.0976 4916 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
20:52:14.0976 4916 Appinfo - ok
20:52:15.0026 4916 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
20:52:15.0026 4916 arc - ok
20:52:15.0046 4916 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
20:52:15.0046 4916 arcsas - ok
20:52:15.0076 4916 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
20:52:15.0076 4916 AsyncMac - ok
20:52:15.0136 4916 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
20:52:15.0136 4916 atapi - ok
20:52:15.0196 4916 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:52:15.0206 4916 AudioEndpointBuilder - ok
20:52:15.0226 4916 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
20:52:15.0226 4916 AudioSrv - ok
20:52:15.0276 4916 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:52:15.0286 4916 AxInstSV - ok
20:52:15.0326 4916 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
20:52:15.0346 4916 b06bdrv - ok
20:52:15.0366 4916 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
20:52:15.0376 4916 b57nd60a - ok
20:52:15.0406 4916 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
20:52:15.0406 4916 BDESVC - ok
20:52:15.0446 4916 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
20:52:15.0446 4916 Beep - ok
20:52:15.0540 4916 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
20:52:15.0556 4916 BFE - ok
20:52:15.0654 4916 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
20:52:15.0714 4916 BITS - ok
20:52:15.0754 4916 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
20:52:15.0754 4916 blbdrive - ok
20:52:15.0814 4916 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:52:15.0814 4916 bowser - ok
20:52:15.0854 4916 [ F46DD257FAD7D2D097EF32E72220A06C ] bpenum C:\Windows\system32\DRIVERS\bpenum.sys
20:52:15.0854 4916 bpenum - ok
20:52:15.0894 4916 [ E82060AED0F28ED8909F2B07FA276185 ] bpmp C:\Windows\system32\DRIVERS\bpmp.sys
20:52:15.0904 4916 bpmp - ok
20:52:15.0924 4916 [ FC6313A5A45C1AE53D0491F0057D5A4D ] bpusb C:\Windows\system32\Drivers\bpusb.sys
20:52:15.0924 4916 bpusb - ok
20:52:15.0934 4916 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:52:15.0944 4916 BrFiltLo - ok
20:52:15.0974 4916 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:52:15.0974 4916 BrFiltUp - ok
20:52:16.0004 4916 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
20:52:16.0004 4916 BridgeMP - ok
20:52:16.0044 4916 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
20:52:16.0044 4916 Browser - ok
20:52:16.0084 4916 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\system32\Drivers\Brserid.sys
20:52:16.0094 4916 Brserid - ok
20:52:16.0124 4916 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
20:52:16.0124 4916 BrSerWdm - ok
20:52:16.0134 4916 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
20:52:16.0154 4916 BrUsbMdm - ok
20:52:16.0164 4916 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\Drivers\BrUsbSer.sys
20:52:16.0164 4916 BrUsbSer - ok
20:52:16.0184 4916 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
20:52:16.0194 4916 BTHMODEM - ok
20:52:16.0224 4916 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
20:52:16.0234 4916 bthserv - ok
20:52:16.0284 4916 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:52:16.0284 4916 cdfs - ok
20:52:16.0334 4916 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
20:52:16.0344 4916 cdrom - ok
20:52:16.0364 4916 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
20:52:16.0364 4916 CertPropSvc - ok
20:52:16.0404 4916 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
20:52:16.0404 4916 circlass - ok
20:52:16.0474 4916 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
20:52:16.0484 4916 CLFS - ok
20:52:16.0624 4916 [ FE1C81A049E5C5D67C4AB7C31C899F6F ] CLKMSVC10_38F51D56 C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
20:52:16.0634 4916 CLKMSVC10_38F51D56 - ok
20:52:16.0704 4916 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:52:16.0704 4916 clr_optimization_v2.0.50727_32 - ok
20:52:16.0764 4916 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:52:16.0764 4916 clr_optimization_v2.0.50727_64 - ok
20:52:16.0894 4916 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:52:16.0914 4916 clr_optimization_v4.0.30319_32 - ok
20:52:16.0974 4916 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:52:16.0974 4916 clr_optimization_v4.0.30319_64 - ok
20:52:17.0024 4916 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
20:52:17.0024 4916 clwvd - ok
20:52:17.0054 4916 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
20:52:17.0054 4916 CmBatt - ok
20:52:17.0114 4916 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
20:52:17.0114 4916 cmdide - ok
20:52:17.0214 4916 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
20:52:17.0224 4916 CNG - ok
20:52:17.0254 4916 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
20:52:17.0264 4916 Compbatt - ok
20:52:17.0304 4916 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
20:52:17.0304 4916 CompositeBus - ok
20:52:17.0314 4916 COMSysApp - ok
20:52:17.0334 4916 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
20:52:17.0334 4916 crcdisk - ok
20:52:17.0384 4916 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:52:17.0394 4916 CryptSvc - ok
20:52:17.0454 4916 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:52:17.0464 4916 DcomLaunch - ok
20:52:17.0514 4916 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
20:52:17.0514 4916 defragsvc - ok
20:52:17.0564 4916 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
20:52:17.0564 4916 DfsC - ok
20:52:17.0604 4916 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
20:52:17.0614 4916 Dhcp - ok
20:52:17.0644 4916 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
20:52:17.0644 4916 discache - ok
20:52:17.0654 4916 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
20:52:17.0664 4916 Disk - ok
20:52:17.0744 4916 [ C4AEBBEB530706B45B7916161A1F525D ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
20:52:17.0864 4916 DMAgent - ok
20:52:17.0914 4916 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:52:17.0924 4916 Dnscache - ok
20:52:17.0964 4916 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
20:52:17.0974 4916 dot3svc - ok
20:52:18.0004 4916 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
20:52:18.0014 4916 DPS - ok
20:52:18.0034 4916 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:52:18.0044 4916 drmkaud - ok
20:52:18.0124 4916 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:52:18.0144 4916 DXGKrnl - ok
20:52:18.0184 4916 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
20:52:18.0194 4916 EapHost - ok
20:52:18.0284 4916 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
20:52:18.0364 4916 ebdrv - ok
20:52:18.0414 4916 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
20:52:18.0424 4916 EFS - ok
20:52:18.0534 4916 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
20:52:18.0554 4916 ehRecvr - ok
20:52:18.0574 4916 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
20:52:18.0574 4916 ehSched - ok
20:52:18.0624 4916 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
20:52:18.0634 4916 elxstor - ok
20:52:18.0674 4916 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
20:52:18.0674 4916 ErrDev - ok
20:52:18.0714 4916 [ 9D8739A2A2173C9D27C499A3FC6EDA3F ] ETD C:\Windows\system32\DRIVERS\ETD.sys
20:52:18.0714 4916 ETD - ok
20:52:18.0764 4916 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
20:52:18.0774 4916 EventSystem - ok
20:52:18.0874 4916 [ F8F610093E1D7FDFA477FC34D15D5C60 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
20:52:18.0904 4916 EvtEng - ok
20:52:18.0924 4916 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
20:52:18.0934 4916 exfat - ok
20:52:18.0954 4916 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:52:18.0964 4916 fastfat - ok
20:52:19.0024 4916 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
20:52:19.0034 4916 Fax - ok
20:52:19.0054 4916 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
20:52:19.0054 4916 fdc - ok
20:52:19.0094 4916 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
20:52:19.0104 4916 fdPHost - ok
20:52:19.0134 4916 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
20:52:19.0134 4916 FDResPub - ok
20:52:19.0184 4916 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:52:19.0194 4916 FileInfo - ok
20:52:19.0204 4916 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:52:19.0204 4916 Filetrace - ok
20:52:19.0234 4916 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
20:52:19.0234 4916 flpydisk - ok
20:52:19.0284 4916 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:52:19.0294 4916 FltMgr - ok
20:52:19.0364 4916 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
20:52:19.0384 4916 FontCache - ok
20:52:19.0444 4916 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:52:19.0444 4916 FontCache3.0.0.0 - ok
20:52:19.0474 4916 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:52:19.0474 4916 FsDepends - ok
20:52:19.0524 4916 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:52:19.0534 4916 Fs_Rec - ok
20:52:19.0574 4916 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:52:19.0594 4916 fvevol - ok
20:52:19.0624 4916 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
20:52:19.0624 4916 gagp30kx - ok
20:52:19.0684 4916 [ 521A469CAF61F00E1DE081CC2099C1D6 ] GameConsoleService C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
20:52:19.0694 4916 GameConsoleService - ok
20:52:19.0754 4916 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
20:52:19.0764 4916 gpsvc - ok
20:52:19.0864 4916 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:52:19.0864 4916 gupdate - ok
20:52:19.0884 4916 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:52:19.0894 4916 gupdatem - ok
20:52:19.0914 4916 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
20:52:19.0914 4916 hcw85cir - ok
20:52:19.0974 4916 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:52:19.0984 4916 HdAudAddService - ok
20:52:19.0994 4916 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
20:52:20.0004 4916 HDAudBus - ok
20:52:20.0034 4916 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
20:52:20.0034 4916 HidBatt - ok
20:52:20.0054 4916 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
20:52:20.0054 4916 HidBth - ok
20:52:20.0084 4916 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
20:52:20.0084 4916 HidIr - ok
20:52:20.0114 4916 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
20:52:20.0124 4916 hidserv - ok
20:52:20.0144 4916 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
20:52:20.0144 4916 HidUsb - ok
20:52:20.0184 4916 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:52:20.0194 4916 hkmsvc - ok
20:52:20.0234 4916 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:52:20.0244 4916 HomeGroupListener - ok
20:52:20.0284 4916 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:52:20.0294 4916 HomeGroupProvider - ok
20:52:20.0444 4916 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
20:52:20.0454 4916 hpqcxs08 - ok
20:52:20.0554 4916 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
20:52:20.0554 4916 hpqddsvc - ok
20:52:20.0584 4916 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:52:20.0584 4916 HpSAMD - ok
20:52:20.0654 4916 [ F37882F128EFACEFE353E0BAE2766909 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
20:52:20.0664 4916 HPSLPSVC - ok
20:52:20.0744 4916 [ 575546EE9A39DD5CB3B4E34A146A8A3E ] hshld C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
20:52:20.0754 4916 hshld - ok
20:52:20.0844 4916 [ 2CFEA9C337B699ACA38487E8A7438F35 ] HssSrv C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
20:52:20.0844 4916 HssSrv - ok
20:52:20.0864 4916 [ 4EFB7FC2A11DB10AB6205206D60C432B ] HssTrayService C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
20:52:20.0864 4916 HssTrayService - ok
20:52:20.0874 4916 HssWd - ok
20:52:20.0934 4916 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:52:20.0944 4916 HTTP - ok
20:52:20.0984 4916 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:52:20.0984 4916 hwpolicy - ok
20:52:21.0034 4916 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
20:52:21.0034 4916 i8042prt - ok
20:52:21.0084 4916 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
20:52:21.0094 4916 iaStor - ok
20:52:21.0144 4916 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:52:21.0154 4916 iaStorV - ok
20:52:21.0224 4916 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:52:21.0244 4916 idsvc - ok
20:52:21.0510 4916 [ 0AC9E321D604BE48A0D72B69BA484BDC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
20:52:21.0744 4916 igfx - ok
20:52:21.0775 4916 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
20:52:21.0790 4916 iirsp - ok
20:52:21.0837 4916 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
20:52:21.0853 4916 IKEEXT - ok
20:52:21.0931 4916 [ A0C2C3D4C03C4FB896CFC53873784178 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:52:21.0962 4916 IntcAzAudAddService - ok
20:52:21.0993 4916 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
20:52:21.0993 4916 IntcDAud - ok
20:52:22.0024 4916 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
20:52:22.0024 4916 intelide - ok
20:52:22.0040 4916 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
20:52:22.0040 4916 intelppm - ok
20:52:22.0071 4916 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
20:52:22.0071 4916 IPBusEnum - ok
20:52:22.0102 4916 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:52:22.0118 4916 IpFilterDriver - ok
20:52:22.0180 4916 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:52:22.0196 4916 iphlpsvc - ok
20:52:22.0243 4916 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
20:52:22.0243 4916 IPMIDRV - ok
20:52:22.0274 4916 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:52:22.0274 4916 IPNAT - ok
20:52:22.0290 4916 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:52:22.0290 4916 IRENUM - ok
20:52:22.0321 4916 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:52:22.0321 4916 isapnp - ok
20:52:22.0368 4916 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
20:52:22.0383 4916 iScsiPrt - ok
20:52:22.0508 4916 [ 7989686A8333CCBD12044D3D40A27B3F ] jjvop C:\Users\Owner\AppData\Roaming\clmioni1.bat
20:52:22.0555 4916 jjvop - ok
20:52:22.0586 4916 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
20:52:22.0602 4916 kbdclass - ok
20:52:22.0633 4916 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
20:52:22.0633 4916 kbdhid - ok
20:52:22.0664 4916 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
20:52:22.0664 4916 KeyIso - ok
20:52:22.0664 4916 KMService - ok
20:52:22.0711 4916 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:52:22.0711 4916 KSecDD - ok
20:52:22.0758 4916 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:52:22.0758 4916 KSecPkg - ok
20:52:22.0789 4916 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:52:22.0789 4916 ksthunk - ok
20:52:22.0820 4916 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
20:52:22.0836 4916 KtmRm - ok
20:52:22.0898 4916 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
20:52:22.0898 4916 LanmanServer - ok
20:52:22.0945 4916 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:52:22.0960 4916 LanmanWorkstation - ok
20:52:22.0992 4916 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:52:22.0992 4916 lltdio - ok
20:52:23.0007 4916 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:52:23.0023 4916 lltdsvc - ok
20:52:23.0038 4916 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:52:23.0038 4916 lmhosts - ok
20:52:23.0116 4916 [ 926EBA26A8B49D1597751CED06B50862 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
20:52:23.0132 4916 LMS - ok
20:52:23.0163 4916 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
20:52:23.0179 4916 LSI_FC - ok
20:52:23.0194 4916 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
20:52:23.0194 4916 LSI_SAS - ok
20:52:23.0210 4916 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:52:23.0226 4916 LSI_SAS2 - ok
20:52:23.0241 4916 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:52:23.0257 4916 LSI_SCSI - ok
20:52:23.0288 4916 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
20:52:23.0288 4916 luafv - ok
20:52:23.0319 4916 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
20:52:23.0335 4916 Mcx2Svc - ok
20:52:23.0335 4916 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
20:52:23.0350 4916 megasas - ok
20:52:23.0366 4916 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
20:52:23.0382 4916 MegaSR - ok
20:52:23.0428 4916 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
20:52:23.0428 4916 MEIx64 - ok
20:52:23.0538 4916 Microsoft SharePoint Workspace Audit Service - ok
20:52:23.0584 4916 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
20:52:23.0584 4916 MMCSS - ok
20:52:23.0616 4916 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
20:52:23.0616 4916 Modem - ok
20:52:23.0662 4916 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
20:52:23.0662 4916 monitor - ok
20:52:23.0678 4916 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
20:52:23.0694 4916 mouclass - ok
20:52:23.0709 4916 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
20:52:23.0709 4916 mouhid - ok
20:52:23.0740 4916 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:52:23.0740 4916 mountmgr - ok
20:52:23.0850 4916 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:52:23.0850 4916 MozillaMaintenance - ok
20:52:23.0881 4916 [ 94C66EDEDCDB6A126880472F9A704D8E ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
20:52:23.0896 4916 MpFilter - ok
20:52:23.0928 4916 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
20:52:23.0928 4916 mpio - ok
20:52:23.0974 4916 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:52:23.0974 4916 mpsdrv - ok
20:52:24.0068 4916 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:52:24.0084 4916 MpsSvc - ok
20:52:24.0130 4916 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:52:24.0130 4916 MRxDAV - ok
20:52:24.0177 4916 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:52:24.0177 4916 mrxsmb - ok
20:52:24.0208 4916 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:52:24.0208 4916 mrxsmb10 - ok
20:52:24.0286 4916 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:52:24.0286 4916 mrxsmb20 - ok
20:52:24.0333 4916 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
20:52:24.0333 4916 msahci - ok
20:52:24.0380 4916 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
20:52:24.0380 4916 msdsm - ok
20:52:24.0411 4916 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
20:52:24.0411 4916 MSDTC - ok
20:52:24.0458 4916 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:52:24.0458 4916 Msfs - ok
20:52:24.0489 4916 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:52:24.0489 4916 mshidkmdf - ok
20:52:24.0520 4916 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:52:24.0536 4916 msisadrv - ok
20:52:24.0552 4916 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:52:24.0552 4916 MSiSCSI - ok
20:52:24.0567 4916 msiserver - ok
20:52:24.0583 4916 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:52:24.0583 4916 MSKSSRV - ok
20:52:24.0645 4916 [ 59FAAF2C83C8169EA20F9E335E418907 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
20:52:24.0645 4916 MsMpSvc - ok
20:52:24.0676 4916 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:52:24.0676 4916 MSPCLOCK - ok
20:52:24.0692 4916 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:52:24.0692 4916 MSPQM - ok
20:52:24.0739 4916 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:52:24.0754 4916 MsRPC - ok
20:52:24.0786 4916 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
20:52:24.0801 4916 mssmbios - ok
20:52:24.0817 4916 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:52:24.0817 4916 MSTEE - ok
20:52:24.0832 4916 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
20:52:24.0832 4916 MTConfig - ok
20:52:24.0864 4916 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
20:52:24.0864 4916 Mup - ok
20:52:24.0895 4916 [ F6EA50DBC391F04CA49427010657CCB3 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
20:52:24.0910 4916 MyWiFiDHCPDNS - ok
20:52:24.0957 4916 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
20:52:24.0957 4916 napagent - ok
20:52:25.0004 4916 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:52:25.0004 4916 NativeWifiP - ok
20:52:25.0066 4916 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
20:52:25.0082 4916 NDIS - ok
20:52:25.0113 4916 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:52:25.0113 4916 NdisCap - ok
20:52:25.0160 4916 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:52:25.0160 4916 NdisTapi - ok
20:52:25.0207 4916 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:52:25.0207 4916 Ndisuio - ok
20:52:25.0254 4916 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:52:25.0254 4916 NdisWan - ok
20:52:25.0300 4916 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:52:25.0300 4916 NDProxy - ok
20:52:25.0347 4916 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
20:52:25.0347 4916 Net Driver HPZ12 - ok
20:52:25.0394 4916 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:52:25.0394 4916 NetBIOS - ok
20:52:25.0425 4916 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:52:25.0441 4916 NetBT - ok
20:52:25.0441 4916 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
20:52:25.0456 4916 Netlogon - ok
20:52:25.0488 4916 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
20:52:25.0503 4916 Netman - ok
20:52:25.0519 4916 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
20:52:25.0534 4916 netprofm - ok
20:52:25.0566 4916 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:52:25.0566 4916 NetTcpPortSharing - ok
20:52:25.0768 4916 [ 30933BB56FB611D0252BAD488ADFB533 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
20:52:25.0940 4916 NETwNs64 - ok
20:52:25.0971 4916 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
20:52:25.0987 4916 nfrd960 - ok
20:52:26.0018 4916 [ 91B4E0273D2F6C24EF845F2B41311289 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
20:52:26.0018 4916 NisDrv - ok
20:52:26.0065 4916 [ 10A43829A9E606AF3EEF25A1C1665923 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
20:52:26.0080 4916 NisSrv - ok
20:52:26.0127 4916 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
20:52:26.0127 4916 NlaSvc - ok
20:52:26.0252 4916 [ 5839A8027D6D324A7CD494051A96628C ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
20:52:26.0299 4916 NOBU - ok
20:52:26.0314 4916 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:52:26.0330 4916 Npfs - ok
20:52:26.0346 4916 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
20:52:26.0346 4916 nsi - ok
20:52:26.0361 4916 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:52:26.0361 4916 nsiproxy - ok
20:52:26.0439 4916 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:52:26.0470 4916 Ntfs - ok
20:52:26.0502 4916 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
20:52:26.0502 4916 Null - ok
20:52:26.0548 4916 [ 786DB821BFD57C0551DBBE4F75384A7D ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
20:52:26.0548 4916 nusb3hub - ok
20:52:26.0580 4916 [ DAA8005CAF745042BB427A1ED7433354 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
20:52:26.0580 4916 nusb3xhc - ok
20:52:26.0892 4916 [ 35AFE139F5CAAE2C54AC3DAF2F0DA525 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:52:27.0110 4916 nvlddmkm - ok
20:52:27.0157 4916 [ 07A4DF15E49F0875B633C39CBEFAE4EC ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
20:52:27.0172 4916 nvpciflt - ok
20:52:27.0250 4916 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:52:27.0250 4916 nvraid - ok
20:52:27.0282 4916 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:52:27.0297 4916 nvstor - ok
20:52:27.0344 4916 [ BBA0F7E4E545CD8C5BEA5BAB815A3A43 ] NVSvc C:\Windows\system32\nvvsvc.exe
20:52:27.0360 4916 NVSvc - ok
20:52:27.0469 4916 [ E4A5158EBD8DE1EA94A4AAEA13232594 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
20:52:27.0500 4916 nvUpdatusService - ok
20:52:27.0547 4916 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:52:27.0547 4916 nv_agp - ok
20:52:27.0609 4916 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
20:52:27.0609 4916 ohci1394 - ok
20:52:27.0703 4916 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:52:27.0703 4916 ose64 - ok
20:52:27.0890 4916 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
20:52:27.0999 4916 osppsvc - ok
20:52:28.0030 4916 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:52:28.0046 4916 p2pimsvc - ok
20:52:28.0062 4916 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
20:52:28.0062 4916 p2psvc - ok
20:52:28.0093 4916 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
20:52:28.0093 4916 Parport - ok
20:52:28.0140 4916 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:52:28.0140 4916 partmgr - ok
20:52:28.0186 4916 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:52:28.0186 4916 PcaSvc - ok
20:52:28.0233 4916 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
20:52:28.0249 4916 pci - ok
20:52:28.0264 4916 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
20:52:28.0264 4916 pciide - ok
20:52:28.0296 4916 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
20:52:28.0296 4916 pcmcia - ok
20:52:28.0327 4916 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
20:52:28.0327 4916 pcw - ok
20:52:28.0358 4916 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:52:28.0374 4916 PEAUTH - ok
20:52:28.0467 4916 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:52:28.0467 4916 PerfHost - ok
20:52:28.0561 4916 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
20:52:28.0592 4916 pla - ok
20:52:28.0639 4916 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:52:28.0639 4916 PlugPlay - ok
20:52:28.0680 4916 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
20:52:28.0680 4916 Pml Driver HPZ12 - ok
20:52:28.0710 4916 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:52:28.0710 4916 PNRPAutoReg - ok
20:52:28.0730 4916 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:52:28.0730 4916 PNRPsvc - ok
20:52:28.0790 4916 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:52:28.0800 4916 PolicyAgent - ok
20:52:28.0830 4916 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
20:52:28.0830 4916 Power - ok
20:52:28.0890 4916 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
20:52:28.0890 4916 PptpMiniport - ok
20:52:28.0930 4916 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
20:52:28.0930 4916 Processor - ok
20:52:28.0970 4916 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
20:52:28.0970 4916 ProfSvc - ok
20:52:28.0980 4916 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:52:28.0980 4916 ProtectedStorage - ok
20:52:29.0040 4916 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:52:29.0040 4916 Psched - ok
20:52:29.0100 4916 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
20:52:29.0120 4916 PSI - ok
20:52:29.0200 4916 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
20:52:29.0230 4916 ql2300 - ok
20:52:29.0260 4916 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
20:52:29.0260 4916 ql40xx - ok
20:52:29.0290 4916 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
20:52:29.0300 4916 QWAVE - ok
20:52:29.0320 4916 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:52:29.0330 4916 QWAVEdrv - ok
20:52:29.0340 4916 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:52:29.0340 4916 RasAcd - ok
20:52:29.0370 4916 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
20:52:29.0370 4916 RasAgileVpn - ok
20:52:29.0400 4916 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
20:52:29.0410 4916 RasAuto - ok
20:52:29.0460 4916 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
20:52:29.0470 4916 Rasl2tp - ok
20:52:29.0490 4916 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
20:52:29.0500 4916 RasMan - ok
20:52:29.0530 4916 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:52:29.0530 4916 RasPppoe - ok
20:52:29.0550 4916 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
20:52:29.0550 4916 RasSstp - ok
20:52:29.0610 4916 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:52:29.0620 4916 rdbss - ok
20:52:29.0640 4916 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
20:52:29.0640 4916 rdpbus - ok
20:52:29.0670 4916 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
20:52:29.0670 4916 RDPCDD - ok
20:52:29.0690 4916 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
20:52:29.0690 4916 RDPENCDD - ok
20:52:29.0710 4916 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
20:52:29.0710 4916 RDPREFMP - ok
20:52:29.0760 4916 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
20:52:29.0760 4916 RDPWD - ok
20:52:29.0830 4916 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:52:29.0840 4916 rdyboost - ok
20:52:29.0950 4916 [ 9276F4D4109FC349925D28E00E533146 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
20:52:29.0970 4916 RegSrvc - ok
20:52:29.0990 4916 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:52:30.0000 4916 RemoteAccess - ok
20:52:30.0020 4916 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:52:30.0030 4916 RemoteRegistry - ok
20:52:30.0130 4916 [ F12A68ED55053940CADD59CA5E3468DD ] RichVideo C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
20:52:30.0310 4916 RichVideo - ok
20:52:30.0330 4916 RimUsb - ok
20:52:30.0370 4916 [ 4AAFFFA67AC4DFA3D9985D78573887E2 ] RimVSerPort C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
20:52:30.0370 4916 RimVSerPort - ok
20:52:30.0400 4916 [ 388D3DD1A6457280F3BADBA9F3ACD6B1 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys
20:52:30.0410 4916 ROOTMODEM - ok
20:52:30.0440 4916 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:52:30.0440 4916 RpcEptMapper - ok
20:52:30.0490 4916 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
20:52:30.0500 4916 RpcLocator - ok
20:52:30.0550 4916 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
20:52:30.0560 4916 RpcSs - ok
20:52:30.0580 4916 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:52:30.0580 4916 rspndr - ok
20:52:30.0620 4916 [ BFE0EF0C4C15820698F50AD73AF5E35F ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
20:52:30.0630 4916 RTL8167 - ok
20:52:30.0710 4916 [ 62DB6CC4B0818F1B5F3441241B098F12 ] SABI C:\Windows\system32\Drivers\SABI.sys
20:52:30.0710 4916 SABI - ok
20:52:30.0730 4916 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
20:52:30.0730 4916 SamSs - ok
20:52:30.0780 4916 [ D641337B75B9A9D5AE10687AA1097755 ] Samsung UPD Service C:\Windows\System32\SUPDSvc.exe
 
20:52:30.0790 4916 Samsung UPD Service - ok
20:52:30.0840 4916 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:52:30.0840 4916 sbp2port - ok
20:52:30.0880 4916 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:52:30.0890 4916 SCardSvr - ok
20:52:30.0930 4916 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:52:30.0930 4916 scfilter - ok
20:52:31.0000 4916 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
20:52:31.0020 4916 Schedule - ok
20:52:31.0060 4916 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
20:52:31.0070 4916 SCPolicySvc - ok
20:52:31.0100 4916 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
20:52:31.0110 4916 SDRSVC - ok
20:52:31.0160 4916 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:52:31.0160 4916 secdrv - ok
20:52:31.0180 4916 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
20:52:31.0180 4916 seclogon - ok
20:52:31.0270 4916 [ F70A51EB03EE7046784EF62EFCE9528E ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
20:52:31.0770 4916 Secunia PSI Agent - ok
20:52:31.0830 4916 [ AD56CEB08EEB517332355FDE9E5939C8 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
20:52:31.0980 4916 Secunia Update Agent - ok
20:52:32.0010 4916 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
20:52:32.0010 4916 SENS - ok
20:52:32.0020 4916 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:52:32.0030 4916 SensrSvc - ok
20:52:32.0050 4916 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
20:52:32.0060 4916 Serenum - ok
20:52:32.0080 4916 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
20:52:32.0080 4916 Serial - ok
20:52:32.0110 4916 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
20:52:32.0120 4916 sermouse - ok
20:52:32.0170 4916 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
20:52:32.0180 4916 SessionEnv - ok
20:52:32.0220 4916 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
20:52:32.0220 4916 sffdisk - ok
20:52:32.0240 4916 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
20:52:32.0240 4916 sffp_mmc - ok
20:52:32.0260 4916 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
20:52:32.0260 4916 sffp_sd - ok
20:52:32.0290 4916 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
20:52:32.0290 4916 sfloppy - ok
20:52:32.0370 4916 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:52:32.0380 4916 SharedAccess - ok
20:52:32.0440 4916 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:52:32.0450 4916 ShellHWDetection - ok
20:52:32.0490 4916 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:52:32.0490 4916 SiSRaid2 - ok
20:52:32.0520 4916 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
20:52:32.0520 4916 SiSRaid4 - ok
20:52:32.0610 4916 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:52:32.0610 4916 SkypeUpdate - ok
20:52:32.0630 4916 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
20:52:32.0630 4916 Smb - ok
20:52:32.0680 4916 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:52:32.0690 4916 SNMPTRAP - ok
20:52:32.0720 4916 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
20:52:32.0720 4916 spldr - ok
20:52:32.0780 4916 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
20:52:32.0790 4916 Spooler - ok
20:52:32.0900 4916 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
20:52:33.0000 4916 sppsvc - ok
20:52:33.0040 4916 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
20:52:33.0040 4916 sppuinotify - ok
20:52:33.0130 4916 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
20:52:33.0140 4916 srv - ok
20:52:33.0170 4916 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:52:33.0180 4916 srv2 - ok
20:52:33.0220 4916 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:52:33.0230 4916 srvnet - ok
20:52:33.0270 4916 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
20:52:33.0270 4916 ssadbus - ok
20:52:33.0300 4916 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
20:52:33.0320 4916 ssadmdfl - ok
20:52:33.0360 4916 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
20:52:33.0360 4916 ssadmdm - ok
20:52:33.0390 4916 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:52:33.0400 4916 SSDPSRV - ok
20:52:33.0420 4916 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:52:33.0420 4916 SstpSvc - ok
20:52:33.0450 4916 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
20:52:33.0460 4916 stexstor - ok
20:52:33.0510 4916 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
20:52:33.0510 4916 StillCam - ok
20:52:33.0570 4916 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
20:52:33.0580 4916 stisvc - ok
20:52:33.0620 4916 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
20:52:33.0620 4916 swenum - ok
20:52:33.0650 4916 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
20:52:33.0670 4916 swprv - ok
20:52:33.0750 4916 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
20:52:33.0780 4916 SysMain - ok
20:52:33.0820 4916 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:52:33.0830 4916 TabletInputService - ok
20:52:33.0850 4916 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:52:33.0860 4916 TapiSrv - ok
20:52:33.0890 4916 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
20:52:33.0900 4916 TBS - ok
20:52:33.0970 4916 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:52:34.0010 4916 Tcpip - ok
20:52:34.0050 4916 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:52:34.0070 4916 TCPIP6 - ok
20:52:34.0150 4916 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:52:34.0150 4916 tcpipreg - ok
20:52:34.0190 4916 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
20:52:34.0190 4916 TDPIPE - ok
20:52:34.0220 4916 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
20:52:34.0230 4916 TDTCP - ok
20:52:34.0280 4916 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:52:34.0290 4916 tdx - ok
20:52:34.0330 4916 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
20:52:34.0340 4916 TermDD - ok
20:52:34.0400 4916 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
20:52:34.0420 4916 TermService - ok
20:52:34.0450 4916 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
20:52:34.0460 4916 Themes - ok
20:52:34.0490 4916 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
20:52:34.0490 4916 THREADORDER - ok
20:52:34.0520 4916 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
20:52:34.0520 4916 TrkWks - ok
20:52:34.0590 4916 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:52:34.0600 4916 TrustedInstaller - ok
20:52:34.0640 4916 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
20:52:34.0650 4916 tssecsrv - ok
20:52:34.0700 4916 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:52:34.0700 4916 TsUsbFlt - ok
20:52:34.0750 4916 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:52:34.0760 4916 tunnel - ok
20:52:34.0780 4916 [ 48743B69EA47C020A792D8649F753F44 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys
20:52:34.0810 4916 TurboB - ok
20:52:34.0860 4916 [ 759F59E3EA3802FF23F93DCDB6FE9171 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe
20:52:34.0970 4916 TurboBoost - ok
20:52:35.0000 4916 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
20:52:35.0000 4916 uagp35 - ok
20:52:35.0040 4916 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:52:35.0050 4916 udfs - ok
20:52:35.0090 4916 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:52:35.0090 4916 UI0Detect - ok
20:52:35.0150 4916 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:52:35.0150 4916 uliagpkx - ok
20:52:35.0170 4916 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
20:52:35.0180 4916 umbus - ok
20:52:35.0200 4916 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
20:52:35.0210 4916 UmPass - ok
20:52:35.0330 4916 [ FDF92EC84FECEE834FB10A2A0A19BCDA ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
20:52:35.0420 4916 UNS - ok
20:52:35.0460 4916 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
20:52:35.0480 4916 upnphost - ok
20:52:35.0510 4916 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
20:52:35.0520 4916 usbccgp - ok
20:52:35.0540 4916 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
20:52:35.0540 4916 usbcir - ok
20:52:35.0590 4916 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
20:52:35.0600 4916 usbehci - ok
20:52:35.0630 4916 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
20:52:35.0640 4916 usbhub - ok
20:52:35.0680 4916 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
20:52:35.0680 4916 usbohci - ok
20:52:35.0730 4916 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
20:52:35.0730 4916 usbprint - ok
20:52:35.0790 4916 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
20:52:35.0800 4916 usbscan - ok
20:52:35.0830 4916 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:52:35.0840 4916 USBSTOR - ok
20:52:35.0870 4916 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
20:52:35.0880 4916 usbuhci - ok
20:52:35.0930 4916 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
20:52:35.0930 4916 usbvideo - ok
20:52:36.0030 4916 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
20:52:36.0030 4916 usb_rndisx - ok
20:52:36.0060 4916 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
20:52:36.0060 4916 UxSms - ok
20:52:36.0080 4916 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
20:52:36.0080 4916 VaultSvc - ok
20:52:36.0140 4916 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:52:36.0140 4916 vdrvroot - ok
20:52:36.0190 4916 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
20:52:36.0200 4916 vds - ok
20:52:36.0220 4916 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
20:52:36.0230 4916 vga - ok
20:52:36.0250 4916 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
20:52:36.0260 4916 VgaSave - ok
20:52:36.0300 4916 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
20:52:36.0310 4916 vhdmp - ok
20:52:36.0350 4916 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
20:52:36.0350 4916 viaide - ok
20:52:36.0380 4916 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:52:36.0390 4916 volmgr - ok
20:52:36.0510 4916 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:52:36.0520 4916 volmgrx - ok
20:52:36.0590 4916 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:52:36.0590 4916 volsnap - ok
20:52:36.0640 4916 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
20:52:36.0640 4916 vsmraid - ok
20:52:36.0730 4916 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
20:52:36.0770 4916 VSS - ok
20:52:36.0810 4916 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
20:52:36.0810 4916 vwifibus - ok
20:52:36.0840 4916 [ 6A3D66263414FF0D6FA754C646612F3F ] VWiFiFlt C:\Windows\system32\DRIVERS\vwififlt.sys
20:52:36.0850 4916 VWiFiFlt - ok
20:52:36.0870 4916 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
20:52:36.0880 4916 vwifimp - ok
20:52:36.0920 4916 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
20:52:36.0930 4916 W32Time - ok
20:52:36.0950 4916 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
20:52:36.0950 4916 WacomPen - ok
20:52:37.0000 4916 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
20:52:37.0000 4916 WANARP - ok
20:52:37.0010 4916 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
20:52:37.0020 4916 Wanarpv6 - ok
20:52:37.0110 4916 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
20:52:37.0140 4916 WatAdminSvc - ok
20:52:37.0220 4916 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
20:52:37.0260 4916 wbengine - ok
20:52:37.0290 4916 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:52:37.0290 4916 WbioSrvc - ok
20:52:37.0340 4916 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:52:37.0350 4916 wcncsvc - ok
20:52:37.0390 4916 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:52:37.0390 4916 WcsPlugInService - ok
20:52:37.0410 4916 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
20:52:37.0420 4916 Wd - ok
20:52:37.0440 4916 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:52:37.0450 4916 Wdf01000 - ok
20:52:37.0470 4916 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:52:37.0480 4916 WdiServiceHost - ok
20:52:37.0500 4916 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:52:37.0500 4916 WdiSystemHost - ok
20:52:37.0540 4916 [ 94DC2BF6CBAAA95E369C3756D3115A76 ] wdkmd C:\Windows\system32\DRIVERS\WDKMD.sys
20:52:37.0540 4916 wdkmd - ok
20:52:37.0590 4916 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
20:52:37.0590 4916 WebClient - ok
20:52:37.0620 4916 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
20:52:37.0630 4916 Wecsvc - ok
20:52:37.0650 4916 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:52:37.0650 4916 wercplsupport - ok
20:52:37.0670 4916 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
20:52:37.0670 4916 WerSvc - ok
20:52:37.0700 4916 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
20:52:37.0700 4916 WfpLwf - ok
20:52:37.0770 4916 [ F3C522691316A24328A7B58B0A86028D ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
20:52:38.0120 4916 WiMAXAppSrv - ok
20:52:38.0140 4916 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:52:38.0140 4916 WIMMount - ok
20:52:38.0180 4916 WinDefend - ok
20:52:38.0190 4916 WinHttpAutoProxySvc - ok
20:52:38.0260 4916 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:52:38.0260 4916 Winmgmt - ok
20:52:38.0350 4916 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
20:52:38.0390 4916 WinRM - ok
20:52:38.0500 4916 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
20:52:38.0520 4916 WinUsb - ok
20:52:38.0580 4916 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
20:52:38.0600 4916 Wlansvc - ok
20:52:38.0760 4916 [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:52:38.0800 4916 wlidsvc - ok
20:52:38.0830 4916 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
20:52:38.0830 4916 WmiAcpi - ok
20:52:38.0860 4916 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:52:38.0860 4916 wmiApSrv - ok
20:52:38.0890 4916 WMPNetworkSvc - ok
20:52:38.0920 4916 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:52:38.0920 4916 WPCSvc - ok
20:52:38.0970 4916 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:52:38.0970 4916 WPDBusEnum - ok
20:52:39.0000 4916 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:52:39.0000 4916 ws2ifsl - ok
20:52:39.0040 4916 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
20:52:39.0040 4916 wscsvc - ok
20:52:39.0050 4916 WSearch - ok
20:52:39.0190 4916 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
20:52:39.0220 4916 wuauserv - ok
20:52:39.0260 4916 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:52:39.0270 4916 WudfPf - ok
20:52:39.0300 4916 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
20:52:39.0310 4916 WUDFRd - ok
20:52:39.0350 4916 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:52:39.0360 4916 wudfsvc - ok
20:52:39.0390 4916 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
20:52:39.0400 4916 WwanSvc - ok
20:52:39.0440 4916 ================ Scan global ===============================
20:52:39.0490 4916 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:52:39.0520 4916 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
20:52:39.0540 4916 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
20:52:39.0570 4916 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:52:39.0620 4916 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:52:39.0630 4916 [Global] - ok
20:52:39.0630 4916 ================ Scan MBR ==================================
20:52:39.0640 4916 [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
20:52:40.0030 4916 \Device\Harddisk0\DR0 - ok
20:52:40.0030 4916 ================ Scan VBR ==================================
20:52:40.0030 4916 [ A483171DE81038D1E1C33057DB820660 ] \Device\Harddisk0\DR0\Partition1
20:52:40.0040 4916 \Device\Harddisk0\DR0\Partition1 - ok
20:52:40.0040 4916 [ 0A881E2FF187E7B678BF204EAC000D06 ] \Device\Harddisk0\DR0\Partition2
20:52:40.0050 4916 \Device\Harddisk0\DR0\Partition2 - ok
20:52:40.0070 4916 [ DE3DD32D182E74A1C4F39C7887F217E6 ] \Device\Harddisk0\DR0\Partition3
20:52:40.0070 4916 \Device\Harddisk0\DR0\Partition3 - ok
20:52:40.0080 4916 ============================================================
20:52:40.0080 4916 Scan finished
20:52:40.0080 4916 ============================================================
20:52:40.0090 11356 Detected object count: 0
20:52:40.0100 11356 Actual detected object count: 0
20:58:59.0417 7980 Deinitialize success
 
RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: https://www.techspot.com/downloads/5562-roguekiller.html
Blog: http://tigzyrk.blogspot.com
Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Owner [Admin rights]
Mode : Scan -- Date : 09/10/2012 21:04:25
¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH][DLL] rundll32.exe -- C:\Windows\SysWOW64\rundll32.exe : -> KILLED [TermProc]
[SUSP PATH][DLL] rundll32.exe -- C:\Windows\SysWOW64\rundll32.exe : -> KILLED [TermProc]
¤¤¤ Registry Entries : 17 ¤¤¤
[RUN][BLACKLIST DLL] HKCU\[...]\Run : nerlex (rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
[RUN][BLACKLIST DLL] HKCU\[...]\Run : Deployment (rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW) -> FOUND
[RUN][BLACKLIST DLL] HKLM\[...]\Run : nerlex ("C:\Windows\System32\rundll32.exe" "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
[RUN][BLACKLIST DLL] HKLM\[...]\Run : xtlbj (rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject) -> FOUND
[RUN][BLACKLIST DLL] HKUS\S-1-5-21-2503403413-1387520261-2031820482-1001[...]\Run : nerlex (rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
[RUN][BLACKLIST DLL] HKUS\S-1-5-21-2503403413-1387520261-2031820482-1001[...]\Run : Deployment (rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW) -> FOUND
[RUN][SUSP PATH] HKLM\[...]\Wow6432Node\Run : mvcf2zo (C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe) -> FOUND
[STARTUP][SUSP PATH] Best Buy pc app.lnk @Default : C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe -> FOUND
[STARTUP][SUSP PATH] Best Buy pc app.lnk @Default User : C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe -> FOUND
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
[HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
[HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowUser (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\n.) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\U --> FOUND
[ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\L --> FOUND
¤¤¤ Driver : [NOT LOADED] ¤¤¤
¤¤¤ Infection : ZeroAccess ¤¤¤
¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts
127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS547575A9E384 +++++
--- User ---
[MBR] bcc0df5a8459b470502c749dd4091510
[BSP] 96066b6721740e60f329fee07cf89bf2 : KIWI Image system MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 278528 Mo
2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 570632192 | Size: 416094 Mo
3 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1422792704 | Size: 20680 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
 
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-10 21:19:35
-----------------------------
21:19:35.498 OS Version: Windows x64 6.1.7601 Service Pack 1
21:19:35.498 Number of processors: 8 586 0x2A07
21:19:35.508 ComputerName: OWNER-PC UserName: Owner
21:19:37.548 Initialize success
21:20:21.371 AVAST engine defs: 12091001
21:20:45.052 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
21:20:45.068 Disk 0 Vendor: Hitachi_ JE4O Size: 715404MB BusType: 3
21:20:45.099 Disk 0 MBR read successfully
21:20:45.115 Disk 0 MBR scan
21:20:45.130 Disk 0 unknown MBR code
21:20:45.146 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
21:20:45.239 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 278528 MB offset 206848
21:20:45.286 Disk 0 Partition - 00 0F Extended LBA 416094 MB offset 570632192
21:20:45.333 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 20680 MB offset 1422792704
21:20:45.427 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 416093 MB offset 570634240
21:20:45.536 Disk 0 scanning C:\Windows\system32\drivers
21:21:06.752 Service scanning
21:22:05.564 Modules scanning
21:22:06.094 Disk 0 trace - called modules:
21:22:06.125 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
21:22:06.141 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007e10790]
21:22:06.141 3 CLASSPNP.SYS[fffff88001b6943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005fb7050]
21:22:07.373 AVAST engine scan C:\Windows
21:22:14.518 AVAST engine scan C:\Windows\system32
21:27:06.071 AVAST engine scan C:\Windows\system32\drivers
21:27:29.128 AVAST engine scan C:\Users\Owner
21:27:49.569 File: C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll **INFECTED** Win32:Tracur-IL [Trj]
21:43:23.627 File: C:\Users\Owner\Desktop\RK_Quarantine\faplygb.dll.vir **INFECTED** Win32:Tracur-IL [Trj]
22:00:58.792 AVAST engine scan C:\ProgramData
22:01:03.129 File: C:\ProgramData\2jFf5J64.exe **INFECTED** Win32:Ransom-QF [Trj]
22:01:05.360 File: C:\ProgramData\2jFf5J64.exe_ **INFECTED** Win32:Ransom-QF [Trj]
22:06:14.711 Scan finished successfully
22:09:16.869 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
22:09:16.947 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
 
For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:

    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Next...

Re-run FRST again.
Type the following in the edit box after "Search:".

services.exe

Click Search button and post the log (Search.txt) it makes in your reply.

I'll expect two logs:
- FRST.txt
- Search.txt
 
Scan result of Farbar Recovery Scan Tool (x64) Version: 08-09-2012
Ran by SYSTEM at 10-09-2012 22:52:56
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet002
==================== Registry (Whitelisted) ===================
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11660904 2010-11-30] (Realtek Semiconductor)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2010-11-01] (Intel(R) Corporation)
HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2588968 2010-11-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-10-08] ()
HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
HKLM\...\Run: [nerlex] "C:\Windows\System32\rundll32.exe" "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track [416768 2012-09-07] ()
HKLM\...\Run: [xtlbj] rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject [x]
HKLM-x32\...\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun [618496 2010-06-07] ()
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe [x]
HKU\Owner\...\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background [306688 2012-03-25] (FileHippo.com)
HKU\Owner\...\Run: [nerlex] rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track [416768 2012-09-07] ()
HKU\Owner\...\Run: [Deployment] rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW [339968 2012-09-08] (Sony Corporation)
Tcpip\Parameters: [DhcpNameServer] 167.206.245.129 167.206.245.130 192.168.1.1
AppInit_DLLs: C:\Windows\System32\nvinitx.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
==================== Services ====================
2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [246256 2010-08-24] (CyberLink)
2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [542040 2012-03-26] ()
3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [77520 2012-03-26] ()
2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [329544 2012-03-26] ()
2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2003-04-18] ()
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-01] ()
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-05-31] (Symantec Corporation)
2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [244904 2009-11-30] ()
2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [1326176 2012-06-26] (Secunia)
2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [681056 2012-06-26] (Secunia)
==================== Drivers =================================
2 jjvop; C:\Users\Owner\AppData\Roaming\clmioni1.bat [87 2012-09-08] ()
3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [x]
==================== NetSvcs (Whitelisted) =================

==================== One Month Created Files and Folders ======================
2012-09-10 18:09 - 2012-09-10 18:09 - 00002503 ____A C:\Users\Owner\Desktop\aswMBR.txt
2012-09-10 18:09 - 2012-09-10 18:09 - 00000512 ____A C:\Users\Owner\Desktop\MBR.dat
2012-09-10 17:19 - 2012-09-10 17:19 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\aswMBR.exe
2012-09-10 17:04 - 2012-09-10 17:04 - 00003673 ____A C:\Users\Owner\Desktop\RKreport[1].txt
2012-09-10 16:59 - 2012-09-10 17:04 - 00000000 ____D C:\Users\Owner\Desktop\RK_Quarantine
2012-09-10 16:59 - 2012-09-10 16:59 - 01378816 ____A C:\Users\Owner\Desktop\RogueKiller.exe
2012-09-10 16:50 - 2012-09-10 16:50 - 02193184 ____A C:\Users\Owner\Desktop\tdsskiller.zip
2012-09-10 16:50 - 2012-08-24 09:28 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
2012-09-10 16:50 - 2010-12-31 21:14 - 00002254 ___RA C:\Users\Owner\Desktop\eula.txt
2012-09-10 12:12 - 2012-09-10 12:12 - 00000016 ____A C:\Users\Owner\AppData\Roaming\lyjsb
2012-09-10 04:49 - 2012-09-10 04:49 - 00029832 ____A C:\Users\Owner\Desktop\DDS.txt
2012-09-10 04:49 - 2012-09-10 04:49 - 00007535 ____A C:\Users\Owner\Desktop\Attach.txt
2012-09-10 04:45 - 2012-09-10 04:45 - 00000000 ____A C:\Users\Owner\Desktop\gmer.log
2012-09-08 13:51 - 2012-09-08 13:51 - 00000087 ____H C:\Users\Owner\AppData\Roaming\clmioni1.bat
2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe_
2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe
2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe_.b
2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe.b
2012-09-08 13:45 - 2012-09-08 13:45 - 00000000 ____A C:\Users\All Users\1VjM2R.dat
2012-09-07 18:21 - 2012-09-10 16:56 - 00006532 ____A C:\Users\Owner\AppData\Local\chromeupdate.crx
2012-09-07 18:21 - 2012-09-07 18:21 - 00416768 ____A C:\Users\Owner\AppData\Roaming\nerlex.dll
2012-09-07 18:21 - 2012-09-07 18:21 - 00000000 ____D C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
2012-09-07 18:20 - 2012-09-07 18:20 - 00090176 ____A C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00086080 ____A C:\Users\Owner\AppData\Roaming\aftr4sb.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00060992 ____A C:\Users\Owner\AppData\Roaming\slr8k5s.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00000090 ____H C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
2012-09-06 12:16 - 2012-09-06 12:16 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-09-06 12:16 - 2012-09-06 12:16 - 00916456 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-09-06 12:16 - 2012-09-06 12:16 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2012-09-06 12:16 - 2012-09-06 12:16 - 00000000 ____D C:\Program Files\Java
2012-09-04 13:59 - 2012-09-04 14:32 - 00000000 ____D C:\Users\Owner\AppData\Roaming\pdfforge
2012-09-04 13:28 - 2011-06-01 21:47 - 00177640 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdm.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00157672 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadbus.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00016872 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdfl.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00013800 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadwhnt.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00013800 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadwh.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00013288 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadcmnt.sys
2012-09-04 13:28 - 2011-06-01 21:47 - 00013288 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadcm.sys
2012-08-29 06:00 - 2012-08-29 06:00 - 00060864 ____A C:\Users\Owner\g2mdlhlpx.exe
2012-08-24 03:46 - 2012-08-24 03:46 - 00265208 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-08-24 03:44 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2012-08-24 03:44 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2012-08-23 17:39 - 2012-08-23 17:39 - 00000000 ____D C:\Program Files\Windows Live
2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ___RD C:\Users\Owner\SkyDrive
2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ____D C:\Users\All Users\Microsoft SkyDrive
2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
2012-08-23 17:37 - 2012-08-23 17:37 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-08-23 17:35 - 2012-08-23 17:35 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2012-08-23 17:06 - 2012-06-28 20:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-08-23 17:06 - 2012-06-28 20:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-08-23 17:06 - 2012-06-28 19:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-08-23 17:06 - 2012-06-28 19:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-08-23 17:06 - 2012-06-28 19:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-08-23 17:06 - 2012-06-28 19:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-08-23 17:06 - 2012-06-28 19:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-08-23 17:06 - 2012-06-28 19:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-08-23 17:06 - 2012-06-28 19:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-08-23 17:06 - 2012-06-28 19:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-08-23 17:06 - 2012-06-28 19:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-08-23 17:06 - 2012-06-28 19:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-08-23 17:06 - 2012-06-28 19:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-08-23 17:06 - 2012-06-28 19:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-08-23 17:06 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-08-23 17:06 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-08-23 17:06 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-08-23 17:06 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-08-23 17:06 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-08-23 17:06 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-08-23 17:06 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-08-23 17:06 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-08-23 17:06 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-08-23 17:06 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-08-23 17:06 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-08-23 17:06 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-08-23 17:06 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-08-23 17:06 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-08-23 17:04 - 2012-08-23 17:04 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-08-23 17:01 - 2012-07-04 14:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-08-23 17:01 - 2012-07-04 14:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-08-23 17:01 - 2012-07-04 14:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-08-23 17:01 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-08-23 17:01 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-08-23 17:01 - 2012-05-05 00:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
2012-08-23 17:01 - 2012-05-04 23:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2012-08-23 17:01 - 2012-02-10 22:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2012-08-23 17:01 - 2012-02-10 22:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
2012-08-23 17:01 - 2012-02-10 22:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
2012-08-23 17:01 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2012-08-23 17:00 - 2012-07-18 10:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-08-23 17:00 - 2012-05-13 21:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
2012-08-23 16:57 - 2012-08-23 16:57 - 00000000 ____D C:\Users\Owner\AppData\Local\Secunia PSI
2012-08-23 16:57 - 2012-08-23 16:57 - 00000000 ____D C:\Program Files (x86)\Secunia
2012-08-23 16:56 - 2012-08-23 16:57 - 03277520 ____A (Secunia) C:\Users\Owner\Downloads\PSISetup.exe
2012-08-23 16:53 - 2012-08-23 16:53 - 00001973 ____A C:\Users\Owner\Desktop\Update Checker.lnk
2012-08-23 16:53 - 2012-08-23 16:53 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
2012-08-23 16:45 - 2012-08-23 16:45 - 00448512 ____A (OldTimer Tools) C:\Users\Owner\Desktop\TFC.exe
2012-08-23 16:39 - 2012-08-23 16:39 - 00000000 ____D C:\Program Files\WOT
2012-08-23 16:39 - 2012-08-23 16:39 - 00000000 ____D C:\Program Files (x86)\WOT
2012-08-23 13:28 - 2012-08-23 13:28 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-08-23 13:28 - 2012-08-23 13:28 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2012-08-23 13:27 - 2012-08-23 13:27 - 00000000 ____D C:\Users\All Users\McAfee
2012-08-23 13:24 - 2012-08-23 13:24 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-08-23 08:01 - 2012-08-23 08:01 - 00000000 ____D C:\Program Files (x86)\ESET
2012-08-22 20:50 - 2012-08-23 16:44 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-22 20:50 - 2012-08-23 16:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-08-22 20:50 - 2012-07-03 09:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-08-22 11:02 - 2012-08-22 11:38 - 00000000 ____D C:\Windows\erdnt
2012-08-22 06:58 - 2012-08-22 06:58 - 00000000 ____D C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
2012-08-16 11:45 - 2012-08-16 11:45 - 00000000 ____D C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
2012-08-16 11:45 - 2012-08-16 11:45 - 00000000 ____D C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
2012-08-16 11:41 - 2012-08-16 11:41 - 00000000 ____D C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
2012-08-16 11:41 - 2012-08-16 11:41 - 00000000 ____D C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
2012-08-16 11:37 - 2012-08-16 11:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
2012-08-16 11:37 - 2012-08-16 11:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
2012-08-16 11:32 - 2012-08-16 11:32 - 00000000 ____D C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
2012-08-16 11:32 - 2012-08-16 11:32 - 00000000 ____D C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
2012-08-16 11:28 - 2012-08-16 11:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
2012-08-16 11:20 - 2012-08-16 11:21 - 00000000 ____D C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
2012-08-16 11:20 - 2012-08-16 11:20 - 00000000 ____D C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
2012-08-15 09:51 - 2012-08-15 09:51 - 00000000 ____D C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
2012-08-15 09:51 - 2012-08-15 09:51 - 00000000 ____D C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
2012-08-14 07:03 - 2012-08-14 07:03 - 00000000 ____D C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
2012-08-14 07:03 - 2012-08-14 07:03 - 00000000 ____D C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
2012-08-14 06:46 - 2012-08-14 06:46 - 00000000 ____D C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
2012-08-14 06:42 - 2012-08-14 06:42 - 00000000 ____D C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
2012-08-14 06:42 - 2012-08-14 06:42 - 00000000 ____D C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
2012-08-14 06:30 - 2012-08-14 06:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
2012-08-14 06:30 - 2012-08-14 06:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
2012-08-14 03:23 - 2012-08-15 05:32 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
2012-08-13 13:37 - 2012-08-13 13:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
2012-08-13 13:36 - 2012-08-13 13:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
2012-08-13 10:41 - 2012-09-08 17:56 - 00000000 ____D C:\Users\Owner\Documents\Anti-virus
2012-08-13 10:28 - 2012-08-13 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
2012-08-13 10:28 - 2012-08-13 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
2012-08-13 06:40 - 2012-08-13 06:40 - 00000000 ____D C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
2012-08-13 06:39 - 2012-08-13 06:40 - 00000000 ____D C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
2012-08-13 02:35 - 2012-08-13 02:35 - 00000000 ____D C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
2012-08-13 02:33 - 2012-08-13 02:35 - 00000000 ____D C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
2012-08-12 02:38 - 2012-08-12 02:38 - 00000000 ____D C:\Users\Owner\AppData\Local\{E727C9E2-E3DE-49F2-9DC0-AF9EC23EB817}
2012-08-11 19:26 - 2012-08-11 19:26 - 00000000 ____D C:\Users\Owner\AppData\Local\{D458277E-8667-4B04-9785-D180139CFE5C}

==================== 3 Months Modified Files ================================
2012-09-10 18:47 - 2010-12-22 18:45 - 01293465 ____A C:\Windows\WindowsUpdate.log
2012-09-10 18:40 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
2012-09-10 18:20 - 2012-04-01 13:32 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2012-09-10 18:09 - 2012-09-10 18:09 - 00002503 ____A C:\Users\Owner\Desktop\aswMBR.txt
2012-09-10 18:09 - 2012-09-10 18:09 - 00000512 ____A C:\Users\Owner\Desktop\MBR.dat
2012-09-10 18:01 - 2012-04-02 04:59 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
2012-09-10 17:52 - 2011-08-18 11:07 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2012-09-10 17:19 - 2012-09-10 17:19 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\aswMBR.exe
2012-09-10 17:04 - 2012-09-10 17:04 - 00003673 ____A C:\Users\Owner\Desktop\RKreport[1].txt
2012-09-10 16:59 - 2012-09-10 16:59 - 01378816 ____A C:\Users\Owner\Desktop\RogueKiller.exe
2012-09-10 16:56 - 2012-09-07 18:21 - 00006532 ____A C:\Users\Owner\AppData\Local\chromeupdate.crx
2012-09-10 16:50 - 2012-09-10 16:50 - 02193184 ____A C:\Users\Owner\Desktop\tdsskiller.zip
2012-09-10 12:12 - 2012-09-10 12:12 - 00000016 ____A C:\Users\Owner\AppData\Roaming\lyjsb
2012-09-10 08:52 - 2011-08-18 11:07 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2012-09-10 04:49 - 2012-09-10 04:49 - 00029832 ____A C:\Users\Owner\Desktop\DDS.txt
2012-09-10 04:49 - 2012-09-10 04:49 - 00007535 ____A C:\Users\Owner\Desktop\Attach.txt
2012-09-10 04:45 - 2012-09-10 04:45 - 00000000 ____A C:\Users\Owner\Desktop\gmer.log
2012-09-10 03:48 - 2012-04-02 04:59 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
2012-09-08 18:07 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-09-08 18:07 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-09-08 18:00 - 2010-12-22 01:56 - 00000050 ____A C:\Windows\System32\SupplicantTest.log
2012-09-08 17:59 - 2010-12-22 03:08 - 00428372 ____A C:\Windows\PFRO.log
2012-09-08 17:59 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-09-08 17:59 - 2009-07-13 20:51 - 00134015 ____A C:\Windows\setupact.log
2012-09-08 13:51 - 2012-09-08 13:51 - 00000087 ____H C:\Users\Owner\AppData\Roaming\clmioni1.bat
2012-09-08 13:51 - 2009-07-13 15:19 - 210051234 ____A (Immediately Display Mobile Erasing llc) C:\Users\Owner\AppData\Roaming\jjvop.exe
2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe_
2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe
2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe_.b
2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe.b
2012-09-08 13:45 - 2012-09-08 13:45 - 00000000 ____A C:\Users\All Users\1VjM2R.dat
2012-09-07 18:21 - 2012-09-07 18:21 - 00416768 ____A C:\Users\Owner\AppData\Roaming\nerlex.dll
2012-09-07 18:20 - 2012-09-07 18:20 - 00090176 ____A C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00086080 ____A C:\Users\Owner\AppData\Roaming\aftr4sb.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00060992 ____A C:\Users\Owner\AppData\Roaming\slr8k5s.dat
2012-09-07 18:20 - 2012-09-07 18:20 - 00000090 ____H C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
2012-09-06 12:16 - 2012-09-06 12:16 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
2012-09-06 12:16 - 2012-09-06 12:16 - 00916456 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
2012-09-06 12:16 - 2012-09-06 12:16 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
2012-09-06 12:16 - 2012-09-06 12:16 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
2012-09-01 12:02 - 2012-04-02 04:59 - 00002453 ____A C:\Users\Owner\Desktop\Google Chrome.lnk
2012-08-31 10:52 - 2012-04-01 13:32 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-08-31 10:52 - 2011-08-19 10:11 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-08-29 06:00 - 2012-08-29 06:00 - 00060864 ____A C:\Users\Owner\g2mdlhlpx.exe
2012-08-29 02:06 - 2012-01-22 07:18 - 00000600 ____A C:\Users\Owner\AppData\Local\PUTTY.RND
2012-08-26 02:34 - 2011-11-19 11:09 - 00011264 ____A C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-24 09:28 - 2012-09-10 16:50 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
2012-08-24 03:46 - 2012-08-24 03:46 - 00265208 ____A C:\Windows\msxml4-KB2721691-enu.LOG
2012-08-23 17:37 - 2012-08-23 17:37 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
2012-08-23 17:14 - 2009-07-13 20:45 - 05043664 ____A C:\Windows\System32\FNTCACHE.DAT
2012-08-23 17:04 - 2012-08-23 17:04 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2012-08-23 17:02 - 2012-02-10 17:49 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2012-08-23 16:57 - 2012-08-23 16:56 - 03277520 ____A (Secunia) C:\Users\Owner\Downloads\PSISetup.exe
2012-08-23 16:53 - 2012-08-23 16:53 - 00001973 ____A C:\Users\Owner\Desktop\Update Checker.lnk
2012-08-23 16:45 - 2012-08-23 16:45 - 00448512 ____A (OldTimer Tools) C:\Users\Owner\Desktop\TFC.exe
2012-08-23 16:44 - 2012-08-22 20:50 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-08-23 13:28 - 2012-08-23 13:28 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2012-08-23 13:28 - 2012-08-23 13:28 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2012-08-23 13:28 - 2012-03-19 07:40 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2012-08-23 13:28 - 2012-03-19 07:40 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2012-08-23 13:28 - 2012-03-19 07:40 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2012-08-23 13:28 - 2011-09-27 10:27 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2012-08-23 13:24 - 2012-08-23 13:24 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
2012-08-22 11:32 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
2012-08-22 10:57 - 2012-01-16 19:35 - 00002086 ____A C:\Windows\epplauncher.mif
2012-08-14 06:30 - 2012-01-16 19:31 - 00743856 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-08-10 13:41 - 2012-08-10 13:41 - 00000218 ____A C:\Windows\Tasks\SidebarExecute.job
2012-08-10 13:20 - 2012-08-10 13:20 - 00000048 ____A C:\Users\Owner\AppData\Local\OWNER-PC.cfg
2012-08-08 21:42 - 2012-01-18 06:24 - 00007596 ____A C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
2012-08-01 12:25 - 2012-08-01 12:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2012-07-27 23:09 - 2012-07-27 23:09 - 00057792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sirenacm.dll
2012-07-26 15:08 - 2012-07-26 15:08 - 00862664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110.dll
2012-07-26 15:08 - 2012-07-26 15:08 - 00534480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110.dll
2012-07-26 15:08 - 2012-07-26 15:08 - 00251864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib110.dll
2012-07-26 15:08 - 2012-07-26 15:08 - 00153536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\atl110.dll
2012-07-26 15:08 - 2012-07-26 15:08 - 00115656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vcomp110.dll
2012-07-26 11:22 - 2012-07-26 11:22 - 00828872 ____A (Microsoft Corporation) C:\Windows\System32\msvcr110.dll
2012-07-26 11:22 - 2012-07-26 11:22 - 00661448 ____A (Microsoft Corporation) C:\Windows\System32\msvcp110.dll
2012-07-26 11:22 - 2012-07-26 11:22 - 00354264 ____A (Microsoft Corporation) C:\Windows\System32\vccorlib110.dll
2012-07-26 11:22 - 2012-07-26 11:22 - 00177096 ____A (Microsoft Corporation) C:\Windows\System32\atl110.dll
2012-07-26 11:22 - 2012-07-26 11:22 - 00124360 ____A (Microsoft Corporation) C:\Windows\System32\vcomp110.dll
2012-07-18 10:15 - 2012-08-23 17:00 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-17 11:14 - 2012-07-17 11:14 - 00253184 ____A (Microsoft Corp.) C:\Windows\System32\LIVESSP.DLL
2012-07-17 10:49 - 2012-07-17 10:49 - 00209648 ____A (Microsoft Corp.) C:\Windows\SysWOW64\LIVESSP.DLL
2012-07-17 06:54 - 2009-07-13 21:08 - 00032578 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-07-04 14:16 - 2012-08-23 17:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
2012-07-04 14:13 - 2012-08-23 17:01 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
2012-07-04 14:13 - 2012-08-23 17:01 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
2012-07-04 13:16 - 2012-08-23 17:01 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
2012-07-04 13:14 - 2012-08-23 17:01 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
2012-07-03 09:46 - 2012-08-22 20:50 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-28 20:55 - 2012-08-23 17:06 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-06-28 20:09 - 2012-08-23 17:06 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-06-28 19:56 - 2012-08-23 17:06 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-06-28 19:49 - 2012-08-23 17:06 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-06-28 19:49 - 2012-08-23 17:06 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-06-28 19:48 - 2012-08-23 17:06 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-06-28 19:47 - 2012-08-23 17:06 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-06-28 19:45 - 2012-08-23 17:06 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-06-28 19:44 - 2012-08-23 17:06 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-06-28 19:43 - 2012-08-23 17:06 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-06-28 19:42 - 2012-08-23 17:06 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-06-28 19:40 - 2012-08-23 17:06 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-06-28 19:39 - 2012-08-23 17:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-06-28 19:35 - 2012-08-23 17:06 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-06-28 16:52 - 2012-08-23 17:06 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-06-28 16:27 - 2012-08-23 17:06 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-06-28 16:16 - 2012-08-23 17:06 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-06-28 16:09 - 2012-08-23 17:06 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-06-28 16:09 - 2012-08-23 17:06 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-06-28 16:08 - 2012-08-23 17:06 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-06-28 16:07 - 2012-08-23 17:06 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-06-28 16:06 - 2012-08-23 17:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-06-28 16:04 - 2012-08-23 17:06 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-06-28 16:04 - 2012-08-23 17:06 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-06-28 16:01 - 2012-08-23 17:06 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-06-28 16:01 - 2012-08-23 17:06 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-06-28 16:00 - 2012-08-23 17:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-06-28 15:57 - 2012-08-23 17:06 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
2012-06-20 21:56 - 2011-08-19 04:51 - 00001053 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-06-20 21:46 - 2012-06-20 21:42 - 16577248 ____A (Mozilla) C:\Users\Owner\Downloads\Firefox Setup 13.0.1.exe

ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62
==================== Known DLLs (Whitelisted) =================

==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2012-08-30 17:56:22
Restore point made on: 2012-09-02 15:44:43
Restore point made on: 2012-09-03 18:58:31
Restore point made on: 2012-09-06 12:16:09
Restore point made on: 2012-09-06 22:17:22
Restore point made on: 2012-09-09 20:45:52
Restore point made on: 2012-09-10 07:19:06
==================== Memory info ===========================
Percentage of memory in use: 12%
Total physical RAM: 6056.29 MB
Available physical RAM: 5293.38 MB
Total Pagefile: 6054.44 MB
Available Pagefile: 5290.05 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
==================== Partitions ============================
1 Drive c: () (Fixed) (Total:272 GB) (Free:119.84 GB) NTFS
2 Drive d: () (Fixed) (Total:406.34 GB) (Free:132.36 GB) NTFS
3 Drive f: (SAMSUNG_REC) (Fixed) (Total:20.2 GB) (Free:0.94 GB) NTFS ==>[System with boot components (obtained from reading drive)]
5 Drive h: () (Removable) (Total:0.94 GB) (Free:0.87 GB) FAT
6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 698 GB 1024 KB
Disk 1 Online 966 MB 0 B
Partitions of Disk 0:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 100 MB 1024 KB
Partition 2 Primary 272 GB 101 MB
Partition 0 Extended 406 GB 272 GB
Partition 4 Logical 406 GB 272 GB
Partition 3 Recovery 20 GB 678 GB
==================================================================================
Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
==================================================================================
Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C NTFS Partition 272 GB Healthy
==================================================================================
Disk: 0
Partition 4
Type : 07
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 D NTFS Partition 406 GB Healthy
==================================================================================
Disk: 0
Partition 3
Type : 27
Hidden: Yes
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 F SAMSUNG_REC NTFS Partition 20 GB Healthy Hidden
==================================================================================
Partitions of Disk 1:
===============
Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 965 MB 700 KB
==================================================================================
Disk: 1
Partition 1
Type : 06
Hidden: No
Active: No
Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 5 H FAT Removable 965 MB Healthy
==================================================================================
Last Boot: 2012-09-06 01:29
==================== End Of Log =============================
 
Farbar Recovery Scan Tool (x64) Version: 08-09-2012
Ran by SYSTEM at 2012-09-10 22:58:48
Running from H:\
================== Search: "services.exe" ===================
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\erdnt\cache64\services.exe
[2012-08-22 11:38] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
====== End Of Search ======
 
Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the UBCD.
Run FRST/FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Next...

Restart normally.

Please download ComboFix from Here, Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  • Double click on combofix.exe & follow the prompts.

  • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
**Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try the following...

Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

Restart computer in safe mode

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

When the scan is done Notepad will open with rKill.txt log.
NOTE. rKill.txt log will also be present on your desktop.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
 

Attachments

  • fixlist.txt
    1.7 KB · Views: 1
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-09-2012
Ran by SYSTEM at 2012-09-10 23:24:11 Run:1
Running from H:\
==============================================
HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
C:\Windows\System32\consrv.dll not found.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nerlex Value deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\xtlbj Value deleted successfully.
C:\Users\Owner\AppData\Roaming\nerlex.dll moved successfully.
C:\Users\Owner\AppData\Roaming\xtlbj.dll not found.
HKEY_LOCAL_MACHINE\software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mvcf2zo Value deleted successfully.
C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe not found.
HKEY_USERS\Owner\Software\Microsoft\Windows\CurrentVersion\Run\\nerlex Value deleted successfully.
jjvop service deleted successfully.
C:\Users\Owner\AppData\Roaming\clmioni1.bat moved successfully.
C:\Users\Owner\AppData\Roaming\lyjsb not found.
C:\Users\All Users\2jFf5J64.exe_ moved successfully.
C:\Users\All Users\2jFf5J64.exe moved successfully.
C:\Users\All Users\2jFf5J64.exe_.b moved successfully.
C:\Users\All Users\2jFf5J64.exe.b moved successfully.
C:\Users\All Users\1VjM2R.dat moved successfully.
C:\Users\Owner\AppData\Roaming\lj1y6nb.dat moved successfully.
C:\Users\Owner\AppData\Roaming\aftr4sb.dat moved successfully.
C:\Users\Owner\AppData\Roaming\slr8k5s.dat moved successfully.
C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat moved successfully.
C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62 moved successfully.
==== End of Fixlog ====
 
ComboFix 12-09-10.04 - Owner 09/10/2012 23:41:54.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.4453 [GMT -4:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll
c:\users\Owner\AppData\Roaming\jjvop.exe
c:\users\Owner\g2mdlhlpx.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-08-11 to 2012-09-11 )))))))))))))))))))))))))))))))
.
.
2012-09-11 06:52 . 2012-09-11 06:52 -------- d-----w- C:\FRST
2012-09-11 03:48 . 2012-09-11 03:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-09-11 03:48 . 2012-09-11 03:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-08 02:21 . 2012-09-08 02:21 -------- d-----w- c:\users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
2012-09-06 20:16 . 2012-09-06 20:16 289768 ----a-w- c:\windows\system32\javaws.exe
2012-09-06 20:16 . 2012-09-06 20:16 916456 ----a-w- c:\windows\system32\deployJava1.dll
2012-09-06 20:16 . 2012-09-06 20:16 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-06 20:16 . 2012-09-06 20:16 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2012-09-06 20:16 . 2012-09-06 20:16 189416 ----a-w- c:\windows\system32\javaw.exe
2012-09-06 20:16 . 2012-09-06 20:16 188904 ----a-w- c:\windows\system32\java.exe
2012-09-06 20:16 . 2012-09-06 20:16 -------- d-----w- c:\program files\Java
2012-09-04 21:59 . 2012-09-04 22:32 -------- d-----w- c:\users\Owner\AppData\Roaming\pdfforge
2012-09-04 21:28 . 2011-06-02 05:47 177640 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2012-09-04 21:28 . 2011-06-02 05:47 16872 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2012-09-04 21:28 . 2011-06-02 05:47 157672 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2012-09-04 21:28 . 2011-06-02 05:47 13800 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2012-09-04 21:28 . 2011-06-02 05:47 13800 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2012-09-04 21:28 . 2011-06-02 05:47 13288 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2012-09-04 21:28 . 2011-06-02 05:47 13288 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2012-08-24 11:44 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-08-24 11:44 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-08-24 01:39 . 2012-08-24 01:39 -------- d-----w- c:\program files\Windows Live
2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----w- c:\program files (x86)\Microsoft SkyDrive
2012-08-24 01:38 . 2012-08-24 01:37 5563840 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\f126a2711cd819803\skydrivesetup.exe
2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----r- c:\users\Owner\SkyDrive
2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----w- c:\programdata\Microsoft SkyDrive
2012-08-24 01:35 . 2012-08-24 01:35 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
2012-08-24 01:01 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-08-24 01:01 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-24 01:01 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2012-08-24 01:01 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-08-24 01:01 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
2012-08-24 01:01 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-08-24 01:01 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-08-24 01:01 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-08-24 01:01 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-08-24 01:01 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-08-24 01:00 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-08-24 01:00 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-08-24 00:57 . 2012-08-24 00:57 -------- d-----w- c:\users\Owner\AppData\Local\Secunia PSI
2012-08-24 00:57 . 2012-08-24 00:57 -------- d-----w- c:\program files (x86)\Secunia
2012-08-24 00:53 . 2012-08-24 00:53 -------- d-----w- c:\program files (x86)\FileHippo.com
2012-08-24 00:39 . 2012-08-24 00:39 -------- d-----w- c:\program files\WOT
2012-08-24 00:39 . 2012-08-24 00:39 -------- d-----w- c:\program files (x86)\WOT
2012-08-23 21:28 . 2012-08-23 21:28 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-08-23 21:28 . 2012-08-23 21:28 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2012-08-23 21:28 . 2012-08-23 21:28 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2012-08-23 21:27 . 2012-08-23 21:27 -------- d-----w- c:\programdata\McAfee
2012-08-23 16:01 . 2012-08-23 16:01 -------- d-----w- c:\program files (x86)\ESET
2012-08-14 11:23 . 2012-08-15 13:32 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-31 18:52 . 2012-04-01 21:32 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-31 18:52 . 2011-08-19 18:11 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-08-24 01:02 . 2012-02-11 01:49 62134624 ----a-w- c:\windows\system32\MRT.exe
2012-08-23 21:28 . 2011-09-27 18:27 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-07-28 07:09 . 2012-07-28 07:09 57792 ----a-w- c:\windows\SysWow64\sirenacm.dll
2012-07-26 23:08 . 2012-07-26 23:08 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
2012-07-26 23:08 . 2012-07-26 23:08 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
2012-07-26 23:08 . 2012-07-26 23:08 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
2012-07-26 23:08 . 2012-07-26 23:08 153536 ----a-w- c:\windows\SysWow64\atl110.dll
2012-07-26 23:08 . 2012-07-26 23:08 115656 ----a-w- c:\windows\SysWow64\vcomp110.dll
2012-07-26 19:22 . 2012-07-26 19:22 828872 ----a-w- c:\windows\system32\msvcr110.dll
2012-07-26 19:22 . 2012-07-26 19:22 661448 ----a-w- c:\windows\system32\msvcp110.dll
2012-07-26 19:22 . 2012-07-26 19:22 354264 ----a-w- c:\windows\system32\vccorlib110.dll
2012-07-26 19:22 . 2012-07-26 19:22 177096 ----a-w- c:\windows\system32\atl110.dll
2012-07-26 19:22 . 2012-07-26 19:22 124360 ----a-w- c:\windows\system32\vcomp110.dll
2012-07-17 19:14 . 2012-07-17 19:14 253184 ----a-w- c:\windows\system32\LIVESSP.DLL
2012-07-17 18:49 . 2012-07-17 18:49 209648 ----a-w- c:\windows\SysWow64\LIVESSP.DLL
2012-07-17 18:37 . 2012-07-17 18:37 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2012-03-26 306688]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2010-06-08 618496]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-6-27 572000]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2010/12/22 19:14;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-08-25 246256]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 136176]
R2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-03-26 542040]
R2 KMService;KMService;c:\windows\system32\srvany.exe [x]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-12-14 1997416]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-31 250568]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 136176]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-08-10 113120]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 340240]
R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-11-08 8500736]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976]
R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe [2010-08-09 166704]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-06-02 157672]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-06-02 16872]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-06-02 177640]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-10-08 150016]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-11 1255736]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2010-12-14 25576]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 13824]
S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-09-01 408576]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2012-03-26 329544]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-06-27 1326176]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-06-27 681056]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-10-08 19192]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-09-01 911872]
S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [2010-05-16 71168]
S3 bpmp;Intel(R) Centrino(R) WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2010-05-16 175104]
S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [2010-05-16 81920]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-11-10 31088]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-12 138024]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-10-11 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-10-11 180736]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-25 409192]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-11-30 42392]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - CLKMDRV10_38F51D56
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 18:52]
.
2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 19:07]
.
2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 19:07]
.
2012-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 07:41]
.
2012-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
- c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 07:41]
.
2012-08-10 c:\windows\Tasks\SidebarExecute.job
- c:\program files\Windows Sidebar\sidebar.exe [2012-02-12 13:25]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-12-07 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-12-07 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-12-07 417304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-11-02 1933584]
"IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.siccode.com/
mStart Page = hxxp://samsung.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} - hxxps://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: network.proxy.type - 0
FF - user.js: general.useragent.extra.brc -
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-Deployment - c:\users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
"value"="?\06\06\09\16\04;ˆ"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-09-10 23:55:16 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-11 03:55
.
Pre-Run: 128,742,363,136 bytes free
Post-Run: 128,954,146,816 bytes free
.
- - End Of File - - 102AC0B7EBC3907078295E033AF09BA1
 
Please note: I am unable to connect to the internet after the combofix. I restarted the computer twice but there are still no connections available. This was posted from another computer.
 
Thanks for getting back to me.

Where do I go to get this restore point?

I went to system restore on the computer and did not see the specified restore point listed. There were two other restore points listed for September 10.
 
Ok. I did the system restore point to 9/10/12 12:45:48 AM. Wifi is working.

There is still a Run DLL window stating:

C:\Users\Owner\AppData\Roaming\xtlbj.dll
The specified module could not be found.
 
We'll take care of it in a moment.

Any other issues?

=======================

Download Malwarebytes' Anti-Malware (MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
Alternate download: http://www.filehippo.com/download_malwarebytes_anti_malware/
NOTE. If you already have MBAM installed, update it before running the scan.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer IF MBAM asks you to do so.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

=========================

Download OTL to your Desktop.
Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
No other issues right now.

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org
Database version: v2012.09.11.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: OWNER-PC [administrator]
9/11/2012 8:16:50 PM
mbam-log-2012-09-11 (20-16-50).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 224981
Time elapsed: 4 minute(s), 9 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\ProgramData\2jFf5J64.exe (Spyware.Zbot) -> Quarantined and deleted successfully.
(end)
 
OTL logfile created on: 9/11/2012 8:27:53 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.91 Gb Total Physical Memory | 3.79 Gb Available Physical Memory | 64.15% Memory free
11.83 Gb Paging File | 9.56 Gb Available in Paging File | 80.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 272.00 Gb Total Space | 120.06 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
Drive D: | 406.34 Gb Total Space | 132.36 Gb Free Space | 32.57% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/11 20:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/06/27 03:25:06 | 001,326,176 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psia.exe
PRC - [2012/06/27 03:25:04 | 000,681,056 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
PRC - [2012/06/27 03:25:04 | 000,572,000 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
PRC - [2012/03/26 17:45:22 | 000,329,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
PRC - [2012/03/26 17:45:18 | 000,363,336 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2011/09/04 12:45:26 | 003,398,736 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
PRC - [2010/12/17 03:28:20 | 000,943,984 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
PRC - [2010/12/14 19:01:16 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2010/12/06 07:44:28 | 007,058,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
PRC - [2010/11/29 01:42:38 | 000,775,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
PRC - [2010/11/17 04:24:54 | 004,387,632 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
PRC - [2010/11/10 04:03:52 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2010/10/06 01:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
PRC - [2010/10/06 01:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2010/06/07 23:15:42 | 000,618,496 | ---- | M] () -- C:\Windows\Samsung\PanelMgr\SSMMgr.exe
PRC - [2010/02/10 10:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe


========== Modules (No Company Name) ==========

MOD - [2012/09/07 22:21:02 | 000,416,768 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
MOD - [2012/08/02 18:13:18 | 001,335,872 | ---- | M] () -- C:\Program Files (x86)\WOT\WOT.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/07/05 06:42:58 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
MOD - [2010/06/07 23:15:42 | 000,618,496 | ---- | M] () -- C:\Windows\Samsung\PanelMgr\SSMMgr.exe
MOD - [2010/05/07 10:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
MOD - [2006/08/11 23:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/11/02 00:49:46 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2010/11/02 00:39:08 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2010/11/02 00:34:14 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2010/10/08 05:24:16 | 000,150,016 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV:64bit: - [2010/08/31 23:00:06 | 000,911,872 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv)
SRV:64bit: - [2010/08/31 22:54:22 | 000,408,576 | ---- | M] (Red Bend Ltd.) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent)
SRV:64bit: - [2010/08/09 15:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/09/08 17:51:42 | 000,000,087 | -H-- | M] () [Auto | Stopped] -- C:\Users\Owner\AppData\Roaming\clmioni1.bat -- (jjvop)
SRV - [2012/08/31 14:52:40 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/08/10 16:18:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/27 03:25:06 | 001,326,176 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
SRV - [2012/06/27 03:25:04 | 000,681,056 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/26 18:45:44 | 000,077,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2012/03/26 18:38:46 | 000,542,040 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012/03/26 17:45:22 | 000,329,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012/03/26 17:45:18 | 000,363,336 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010/12/14 19:01:16 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2010/10/22 14:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/10/06 01:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/10/06 01:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/08/24 23:07:38 | 000,246,256 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe -- (CLKMSVC10_38F51D56)
SRV - [2010/06/01 02:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/16 10:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
DRV:64bit: - [2011/07/20 14:58:22 | 000,044,032 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:64bit: - [2011/06/02 01:47:22 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
DRV:64bit: - [2011/06/02 01:47:22 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
DRV:64bit: - [2011/06/02 01:47:22 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/14 19:01:14 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:64bit: - [2010/11/30 16:02:22 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2010/11/29 01:23:16 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/11/25 15:31:32 | 000,409,192 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/12 18:23:38 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:64bit: - [2010/11/10 04:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/08 14:16:36 | 008,500,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
DRV:64bit: - [2010/10/20 00:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/15 04:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/10/11 18:26:20 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/10/11 18:26:20 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/10/08 05:23:38 | 000,019,192 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
DRV:64bit: - [2010/09/13 05:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/05/16 04:28:36 | 000,175,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpmp.sys -- (bpmp)
DRV:64bit: - [2010/05/16 04:28:28 | 000,081,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpusb.sys -- (bpusb)
DRV:64bit: - [2010/05/16 04:28:26 | 000,071,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpenum.sys -- (bpenum)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
DRV:64bit: - [2009/07/13 20:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/28 02:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3027459


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0




IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.siccode.com/
IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{14E65473-E217-429D-86C4-013FD2B189FF}: "URL" = http://www.bing.com/search?FORM=SMSTDF&PC=MASM&q={searchTerms}&src=IE-SearchBox
IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid=...dd119bca531&lang=en&ds=AVG&pr=pr&d=2012-08-10 17:41:36&v=12.2.0.5&sap=dsp&q={searchTerms}
IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{A54FC709-D0A1-46BD-83FC-8BA859D982A7}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
FF - prefs.js..network.proxy.type: 0


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/06 15:47:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/10 16:18:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/08/23 17:24:42 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/06 15:47:01 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}: C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}\ [2012/09/07 22:21:05 | 000,000,000 | ---D | M]

[2011/08/19 08:51:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2012/09/08 17:46:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\extensions
[1832/11/29 00:30:07 | 000,004,804 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\extensions\zghfslnovh@zghfslnovh.org.xpi
[2012/08/23 21:08:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/08/23 21:08:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/06/09 18:10:27 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
[2012/09/07 22:21:05 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\OWNER\APPDATA\LOCAL\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
[2012/08/10 16:18:54 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/10 17:41:32 | 000,003,749 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/06/14 18:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 18:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.siccode.com/
CHR - default_search_provider: AVG Secure Search (Enabled)
CHR - default_search_provider: search_url = https://isearch.avg.com/search?cid=...d=&lang=&ds=&pr=&d=&v=&sap=dsp&q={searchTerms}
CHR - default_search_provider: suggest_url = http://clients5.google.com/complete...inputEncoding}&outputencoding={outputEncoding}
CHR - homepage: http://www.siccode.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
 
O1 HOSTS File: ([2012/08/22 15:32:39 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O3:64bit: - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [nerlex] C:\Users\Owner\AppData\Roaming\nerlex.dll ()
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [xtlbj] rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject File not found
O4 - HKLM..\Run: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe File not found
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [Deployment] C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll (Sony Corporation)
O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [nerlex] C:\Users\Owner\AppData\Roaming\nerlex.dll ()
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 10.6.2)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 1.7.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.7.0_06)
O16 - DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} https://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab (CertEnrollControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859}: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/11 20:26:35 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/11 20:15:25 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/11 02:52:50 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/10 23:36:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/09/10 20:59:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\RK_Quarantine
[2012/09/07 22:21:05 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
[2012/09/06 16:16:19 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/09/04 17:59:01 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\pdfforge
[2012/09/04 17:28:26 | 000,177,640 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdm.sys
[2012/09/04 17:28:26 | 000,157,672 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadbus.sys
[2012/09/04 17:28:26 | 000,016,872 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdfl.sys
[2012/09/04 17:28:26 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwhnt.sys
[2012/09/04 17:28:26 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys
[2012/09/04 17:28:26 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcmnt.sys
[2012/09/04 17:28:26 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys
[2012/08/23 21:39:47 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2012/08/23 21:38:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SkyDrive
[2012/08/23 21:38:27 | 000,000,000 | R--D | C] -- C:\Users\Owner\SkyDrive
[2012/08/23 21:38:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
[2012/08/23 21:37:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012/08/23 21:35:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2012/08/23 21:05:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/08/23 20:57:49 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Secunia PSI
[2012/08/23 20:57:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
[2012/08/23 20:53:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileHippo.com
[2012/08/23 20:45:35 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\TFC.exe
[2012/08/23 20:39:52 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
[2012/08/23 20:39:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WOT
[2012/08/23 17:28:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/08/23 17:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012/08/23 12:01:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2012/08/23 00:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/23 00:50:32 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/23 00:50:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/22 15:32:44 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/08/22 15:02:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/22 10:58:27 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
[2012/08/16 15:45:50 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
[2012/08/16 15:45:37 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
[2012/08/16 15:41:33 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
[2012/08/16 15:41:24 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
[2012/08/16 15:37:26 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
[2012/08/16 15:37:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
[2012/08/16 15:32:27 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
[2012/08/16 15:32:16 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
[2012/08/16 15:28:37 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
[2012/08/16 15:20:58 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
[2012/08/16 15:20:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
[2012/08/15 13:51:28 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
[2012/08/15 13:51:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
[2012/08/14 11:03:42 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
[2012/08/14 11:03:18 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
[2012/08/14 10:46:32 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
[2012/08/14 10:42:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
[2012/08/14 10:42:12 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
[2012/08/14 10:30:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/14 10:30:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/14 07:23:22 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/08/13 17:37:08 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
[2012/08/13 17:36:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
[2012/08/13 14:41:59 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Anti-virus
[2012/08/13 14:28:26 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
[2012/08/13 14:28:12 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
[2012/08/13 10:40:38 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
[2012/08/13 10:39:34 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
[2012/08/13 06:35:18 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
[2012/08/13 06:33:25 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
[2009/07/13 19:19:28 | 210,051,234 | ---- | C] (Immediately Display Mobile Erasing llc) -- C:\Users\Owner\AppData\Roaming\jjvop.exe

========== Files - Modified Within 30 Days ==========

[2012/09/11 20:36:22 | 000,006,532 | ---- | M] () -- C:\Users\Owner\AppData\Local\chromeupdate.crx
[2012/09/11 20:31:56 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 20:31:56 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/11 20:30:33 | 000,729,880 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/11 20:30:33 | 000,626,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/11 20:30:33 | 000,107,784 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/11 20:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/09/11 20:23:45 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/11 20:23:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/11 20:23:12 | 2055,512,063 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/11 20:20:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/11 20:16:04 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/11 20:15:25 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.65.0.1400.exe
[2012/09/11 20:01:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
[2012/09/11 19:52:04 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/11 19:40:44 | 000,090,176 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
[2012/09/11 19:40:34 | 000,086,080 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\aftr4sb.dat
[2012/09/11 19:40:24 | 000,060,992 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\slr8k5s.dat
[2012/09/10 22:09:16 | 000,000,512 | ---- | M] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/10 20:50:22 | 002,193,184 | ---- | M] () -- C:\Users\Owner\Desktop\tdsskiller.zip
[2012/09/09 07:01:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
[2012/09/08 17:51:42 | 000,000,087 | -H-- | M] () -- C:\Users\Owner\AppData\Roaming\clmioni1.bat
[2012/09/08 17:51:29 | 210,051,234 | ---- | M] (Immediately Display Mobile Erasing llc) -- C:\Users\Owner\AppData\Roaming\jjvop.exe
[2012/09/07 22:21:02 | 000,416,768 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
[2012/09/07 22:20:07 | 000,000,090 | -H-- | M] () -- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
[2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/01 16:02:16 | 000,002,453 | ---- | M] () -- C:\Users\Owner\Desktop\Google Chrome.lnk
[2012/08/29 10:00:29 | 000,060,864 | ---- | M] () -- C:\Users\Owner\g2mdlhlpx.exe
[2012/08/29 06:06:14 | 000,000,600 | ---- | M] () -- C:\Users\Owner\AppData\Local\PUTTY.RND
[2012/08/26 06:34:14 | 000,011,264 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/23 21:37:02 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/08/23 21:14:42 | 005,043,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/23 21:04:41 | 000,001,070 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/23 20:57:19 | 000,001,110 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/08/23 20:53:50 | 000,001,973 | ---- | M] () -- C:\Users\Owner\Desktop\Update Checker.lnk
[2012/08/23 20:45:35 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\TFC.exe
[2012/08/23 17:24:43 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/22 15:32:39 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/08/22 14:57:52 | 000,002,086 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/14 10:30:19 | 000,743,856 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI

========== Files Created - No Company Name ==========

[2012/09/11 19:40:44 | 000,090,176 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
[2012/09/11 19:40:34 | 000,086,080 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\aftr4sb.dat
[2012/09/11 19:40:24 | 000,060,992 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\slr8k5s.dat
[2012/09/10 22:09:16 | 000,000,512 | ---- | C] () -- C:\Users\Owner\Desktop\MBR.dat
[2012/09/10 20:50:20 | 002,193,184 | ---- | C] () -- C:\Users\Owner\Desktop\tdsskiller.zip
[2012/09/08 17:51:42 | 000,000,087 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\clmioni1.bat
[2012/09/07 22:21:05 | 000,006,532 | ---- | C] () -- C:\Users\Owner\AppData\Local\chromeupdate.crx
[2012/09/07 22:21:01 | 000,416,768 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
[2012/09/07 22:20:07 | 000,000,090 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
[2012/08/29 10:00:28 | 000,060,864 | ---- | C] () -- C:\Users\Owner\g2mdlhlpx.exe
[2012/08/23 22:02:18 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2012/08/23 21:38:26 | 000,002,160 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
[2012/08/23 21:37:02 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/08/23 21:04:41 | 000,001,070 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/23 20:57:19 | 000,001,110 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
[2012/08/23 20:57:19 | 000,001,073 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
[2012/08/23 20:53:50 | 000,002,003 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
[2012/08/23 20:53:50 | 000,001,973 | ---- | C] () -- C:\Users\Owner\Desktop\Update Checker.lnk
[2012/08/23 17:24:43 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/23 17:24:42 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/08/23 00:50:37 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/14 10:30:28 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/10 17:20:53 | 000,000,048 | ---- | C] () -- C:\Users\Owner\AppData\Local\OWNER-PC.cfg
[2012/02/06 15:53:41 | 000,207,571 | ---- | C] () -- C:\Windows\hpwins28.dat.temp
[2012/02/06 15:53:41 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat.temp
[2012/02/06 15:39:51 | 000,206,568 | ---- | C] () -- C:\Windows\hpwins28.dat
[2012/01/22 11:18:05 | 000,000,600 | ---- | C] () -- C:\Users\Owner\AppData\Local\PUTTY.RND
[2012/01/18 10:24:09 | 000,007,596 | ---- | C] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2012/01/16 23:31:54 | 000,743,856 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/19 15:09:01 | 000,011,264 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/18 12:34:56 | 000,000,166 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\PLGComp.ini
[2011/08/19 13:48:35 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2011/08/18 14:54:45 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/22 23:21:56 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2010/12/22 23:21:54 | 000,206,952 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2010/12/22 23:21:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2010/12/22 07:36:50 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe
[2010/12/22 06:17:59 | 000,003,154 | ---- | C] () -- C:\Windows\HotFixList.ini
[2010/12/22 06:17:55 | 000,142,704 | ---- | C] () -- C:\Windows\wiainst64.exe
[2010/12/22 06:17:01 | 000,484,656 | ---- | C] () -- C:\Windows\ssndii.exe
[2010/12/22 06:16:42 | 000,258,864 | ---- | C] () -- C:\Windows\SUPDRun.exe
[2010/12/22 05:48:35 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll

========== LOP Check ==========

[2012/01/28 16:24:53 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Audacity
[2012/06/09 19:41:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Azureus
[2012/09/07 13:08:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\FileZilla
[2012/09/11 19:38:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\IrfanView
[2012/03/24 14:05:53 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PDAppFlex
[2012/09/04 18:32:42 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\pdfforge
[2012/03/24 14:24:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/08/19 21:48:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
[2012/07/17 10:54:55 | 000,032,578 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/08/10 17:41:48 | 000,000,218 | ---- | M] () -- C:\Windows\Tasks\SidebarExecute.job

========== Purity Check ==========
< End of report >
 
OTL Extras logfile created on: 9/11/2012 8:27:53 PM - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.91 Gb Total Physical Memory | 3.79 Gb Available Physical Memory | 64.15% Memory free
11.83 Gb Paging File | 9.56 Gb Available in Paging File | 80.81% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 272.00 Gb Total Space | 120.06 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
Drive D: | 406.34 Gb Total Space | 132.36 Gb Free Space | 32.57% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Users\Owner\AppData\Roaming\jjvop.exe" = C:\Users\Owner\AppData\Roaming\jjvop.exe:*:Enabled:jjvop.exe -- (Immediately Display Mobile Erasing llc)
"C:\Users\Owner\AppData\Roaming\jjvop.exe" = C:\Users\Owner\AppData\Roaming\jjvop.exe:*:Enabled:jjvop.exe -- (Immediately Display Mobile Erasing llc)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{478A745B-A9F6-473A-BDE7-36CC8DDBBBBE}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{53B6DF4A-C479-44B2-A315-99C48AF2EA28}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{274A935C-496C-428F-A08F-33FBBFCFD4B1}" = dir=in | app=c:\users\owner\appdata\local\microsoft\skydrive\skydrive.exe |
"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{49AB3915-BD40-46FE-BB2A-880A690CA3E4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{92C806CF-4E28-434C-B89D-1E6852FA4E79}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{D5351119-FDF2-40FE-80C8-1EC0300E9730}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"UDP Query User{93C6D173-F459-4F7E-9363-7B73057D42E1}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit)
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
"{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4BA33BE3-20CF-4972-BD67-B44CEFA52DCB}" = Windows Live MIME IFilter
"{4F26C164-9373-4974-8F43-E0F2176AF937}" = Intel WiMAX Tutorial
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6548B189-BEA4-4041-80E0-AEB60548E046}" = Intel® PROSet/Wireless WiMAX Software
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}" = HP Officejet 4500 G510n-z
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0401-1000-0000000FF1CE}" = الإصدار 64 بت من Microsoft Outlook Hotmail Connector
"{95140000-007A-0402-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector – 64-битова версия
"{95140000-007A-0404-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 位元
"{95140000-007A-0405-1000-0000000FF1CE}" = Doplněk Microsoft Outlook Hotmail Connector (64bitový)
"{95140000-007A-0406-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-0407-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-Bit
"{95140000-007A-0408-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-0409-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-040B-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-bittinen)
"{95140000-007A-040C-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 bits
"{95140000-007A-040D-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-040E-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bites
"{95140000-007A-0410-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector a 64 bit
"{95140000-007A-0412-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64비트
"{95140000-007A-0413-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bits
"{95140000-007A-0414-1000-0000000FF1CE}" = 64-biters Microsoft Outlook Hotmail Connector
"{95140000-007A-0415-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (wersja 64-bitowa)
"{95140000-007A-0416-1000-0000000FF1CE}" = Versão de 64 bits do Microsoft Outlook Hotmail Connector
"{95140000-007A-0418-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-0419-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-разрядная версия)
"{95140000-007A-041A-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64-bitni
"{95140000-007A-041B-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64-bitová verzia
"{95140000-007A-041D-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 bitar
"{95140000-007A-041E-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
"{95140000-007A-041F-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Bağlayıcısı 64 bit
"{95140000-007A-0424-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-bitna različica)
"{95140000-007A-0426-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bitu
"{95140000-007A-0427-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bitai
"{95140000-007A-0804-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 位
"{95140000-007A-0816-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector - versão de 64 bits
"{95140000-007A-081A-1000-0000000FF1CE}" = 64-bitna verzija programa Microsoft Outlook Hotmail Connector
"{95140000-007A-0C0A-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector de 64 bits
"{95140000-007D-0409-1000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{A4DDB2AB-ECCD-4C3A-8633-77D5A1A0E542}" = Network64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{ADDF4B84-5D28-4EAE-8511-EF808C8BC81C}" = HP Officejet 6500 E710n-z Basic Device Software
"{AF162E20-417F-4946-A06D-65734984957F}" = Intel(R) PROSet/Wireless WiFi Software
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.10
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.10
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Intel(R) Turbo Boost Technology Monitor 2.0
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{DCAEC601-735C-41AE-B84F-D792F09FB7D1}" = WOT for Internet Explorer
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64
"{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"Elantech" = ETDWare PS/2-X64 8.0.7.2_WHQL
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"ProInst" = Intel PROSet Wireless
"Shop for HP Supplies" = Shop for HP Supplies
"WinRAR archiver" = WinRAR 4.01 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00D52195-38C5-46A3-9CBC-4104A1CD6608}" = Photo Common
"{012B4B47-5ED6-469C-8CE3-8816248DD7DF}" = Photo Common
"{0159A45D-DB64-454C-8DEE-037702F2FDF0}" = Poczta usługi Windows Live
"{01C62BE2-E4D2-4B53-9584-1A91FB3E153D}" = Photo Common
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{01FB4B77-9211-480E-8439-370C6DB71113}" = Windows Live Writer Resources
"{0509A333-E819-400A-B5B8-1A474D96D58A}" = Windows Live UX Platform Language Pack
"{05B093D6-140B-41EA-BC35-F611800E158D}" = Windows Live Writer Resources
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{09C4F7A1-0AB6-477E-97BB-82FDA39DBD5D}" = Windows Live Mail
"{0ADCA84C-4276-4619-B318-38BC606476B7}" = Windows Liven sähköposti
"{0B32E306-13AA-4EAE-987B-3BD1A1EC0F12}" = Photo Common
"{0B4A75B4-4C0E-4850-8F25-036B92408E1B}" = Windows Live Messenger
"{0B5FDC99-E373-4F0F-938D-42AD090BACC0}" = Windows Live UX Platform Language Pack
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{0FBC0FEF-FAB2-465D-9F78-8AE1D0603559}" = Windows Live Messenger
"{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform
"{130E5108-547F-4482-91EE-F45C784E08C7}" = HP Officejet 6500 E710n-z Help
"{142D8CA7-2C6F-45A7-83E3-099AAFD99133}" = Samsung Update Plus
"{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{15C2E378-C1C9-4FE8-9F27-590726AEC593}" = Windows Live Writer Resources
"{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1789AE05-5298-492C-9A4D-CDD3A98AE6A1}" = Photo Common
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1A2516F6-15CF-45F0-A14C-865742A647C3}" = Windows Live Messenger
"{1B8F8F57-081B-4BEB-83A9-061C142018FF}" = Windows Live Writer Resources
"{1C604122-1DF6-4142-A9E7-C60D6A978D82}" = Photo Common
"{1DC65309-3556-4D72-BC22-0FDD529BE2EB}" = Windows Live Essentials
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"{20068443-0047-49D6-B25E-3322A56D7E2B}" = Windows Live UX Platform Language Pack
"{20FCB655-FF69-4BFF-9300-68C0386A51A6}" = Windows Live UX Platform Language Pack
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
"{269304A7-84ED-429C-8509-7C6AE2F3D085}" = Windows Live Mail
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33
"{26A24AE4-039D-4CA4-87B4-2F83217006FF}" = Java 7 Update 6
"{27F0B692-6793-4631-A416-175A86440A04}" = Windows Live Writer Resources
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform
"{29C1B1BF-BF0C-46B2-A1A5-5ED7EE0C266F}" = Windows Live UX Platform Language Pack
"{2AE414B5-7FE6-49A3-93C8-D864162CDEBC}" = Windows Live UX Platform Language Pack
"{2D416A80-0BB1-4D8B-B770-7BE8F53D5937}" = Windows Live UX Platform Language Pack
"{2D598A54-750B-4120-B8AD-ED938F74932C}" = Windows Live Essentials
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EEB5313-65AB-4C9B-B2FB-F1EDBFD18402}" = Windows Live Writer Resources
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FAFE37E-D796-47B8-BA8F-D09819B12DF6}" = Windows Live Essentials
"{2FBB11ED-EB28-45AC-BACF-4282EA24E8EA}" = Windows Live UX Platform Language Pack
"{318DBE01-1E6B-4243-84B0-210391FE789A}" = Samsung AnyWeb Print
"{3221ABB3-A940-4030-AA86-C0DA75BCD176}" = Windows Live UX Platform Language Pack
"{331ECF61-69AF-4F57-AC35-AFED610231C3}" = Multimedia POP
"{34A9A026-3421-4310-A97A-4D6FCD582275}" = Windows Live UX Platform Language Pack
"{34D42BA7-804F-41CB-A7F5-6C1E5169422F}" = Windows Live UX Platform Language Pack
"{36C704E9-C7FC-44C1-847E-DC9470414709}" = „Windows Live Essentials“
"{37583C76-E48F-4AA4-BD2A-141A0830F799}" = Windows Live 메일
"{377DE7D7-3C49-4D79-B23E-3E466096262E}" = Windows Live Writer Resources
"{38547BC2-D932-4D3D-88DB-B0C33A34B469}" = Windows Live Messenger
"{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
"{3C57F8BF-1ED1-43E7-A174-CA8B2613C8C0}" = Windows Live Writer Resources
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
"{3EAE58C0-7C36-40C3-ACED-0CABF2F46BCF}" = Windows Live Writer Resources
"{3EF3A400-BC02-4345-AF19-297ED2D71DF4}" = Windows Live Messenger
"{400CBE05-CC6E-4AD8-9596-289584AD7232}" = Windows Live Mail
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{41FEC76C-9F4C-4A9A-B872-C605A4E04BBF}" = Photo Common
"{4214AA76-A3A6-41FD-A8ED-DA2A5C533733}" = Windows Live UX Platform Language Pack
"{437F2A1E-1C01-4EC5-BF32-61ED518D3BEB}" = Windows Live Pošta
"{438C2993-99AA-43F7-BA0B-1A13A75E5426}" = Windows Live Writer Resources
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{44E89CCA-BB20-4EA6-80EB-4126E886F83D}" = Windows Live Mail
"{45B29A59-D180-4BFC-A93D-DDD7E65647C8}" = Photo Common
"{45FF1061-E2E3-4EDF-97A3-B87BB2ABBAC0}" = Windows Live Writer Resources
"{46316411-80D8-4F68-8118-696E05FCE199}" = Windows Live Essentials
"{4689F012-C8E3-4F6E-BDEF-13671D53A6DC}" = Windows Live UX Platform Language Pack
"{46B14AF1-EDFA-4088-AB2B-22A8128A1C54}" = Photo Common
"{48ADF615-F7E5-4805-8ABF-4FCB04A2BE58}" = Windows Live Mail
"{491FCC06-244A-471D-974D-D7A59ED70B3F}" = „Windows Live Mail“
"{49400307-EEC4-4C71-94C1-B419194F7290}" = Windows Live Writer Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A331D24-A9E8-484F-835E-1BA7B139689C}" = EasyBatteryManager
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D60765A-2FF1-4848-BDFD-CEA79458F59B}" = Фотографии (общедоступная версия)
"{4DAB6CA2-71C2-4B28-A4D4-5F6E62E44D93}" = Photo Common
"{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE
"{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions
"{5059436D-B480-494A-8F88-5CACFA883F2B}" = Windows Live Essentials
"{510044D7-E70F-41C6-826A-A53C236B6FC5}" = Windows Live Writer Resources
"{53EFA2AB-A58A-45BB-A044-47AC232FF0FE}" = Windows Live UX Platform Language Pack
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{547C128A-691D-4D09-B195-AC5194C07403}" = Windows Live Temel Parçalar
"{54DF8219-0386-4577-B943-3E9807F0663B}" = Windows Live Mail
"{55F84131-D974-4CDA-AD01-C7DDAA3F19F2}" = Windows Live UX Platform Language Pack
"{5724CD7B-8AFC-4DE5-BF65-59272B22B25E}" = Windows Live Essentials
"{57B0AA0C-3B99-435E-9CEC-2EF61CBCEF5F}" = Основные компоненты Windows Live
"{57EC0BAF-E65F-4758-A6AB-586535C870A2}" = Windows Live Essentials
"{5932CF7B-00D6-4B31-A849-554C3C68E0EB}" = Windows Live Essentials
"{5B05FF91-F20C-4832-A8DE-E1912639C17C}" = 4500G510nz
"{5BD54B96-C51E-4CE0-A507-1B606EE4364E}" = Photo Common
"{5CC4C963-F772-4766-BFF2-DE551E205EE9}" = Photo Common
"{5D382E05-9CFA-45A5-962B-8F578E7D3A23}" = Photo Common
"{5D38A14D-8B90-434E-A28F-47A2279C0F40}" = ActiveState Komodo Edit 6.1.2
"{5DBE54E2-C86B-4350-948B-461DC9FF6D20}" = Windows Live Messenger
"{5F00227C-7D06-4CCE-A064-8C98787029FE}" = Windows Live Writer Resources
"{60ADEF86-A867-47A0-9C8E-9B7E2AB3F87C}" = Windows Live Writer Resources
"{618F39BD-9720-47CF-A89C-108AB41B1493}" = Windows Live UX Platform Language Pack
"{62813F65-4D78-43AF-A53C-DFAFA122E065}" = Windows Live Messenger
"{63240270-28DC-4CEB-B796-F3BBA966B1CA}" = Windows Live Messenger
"{63535877-2396-4437-9BF5-C9BE41EE7677}" = Windows Live Essentials
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{67E78A3A-617B-4DD1-975D-7100CF4AC9E6}" = Windows Live 软件包
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{690879A5-18EF-447B-98D6-B699D51008AB}" = 4500_G510nz_Help
"{698ED639-3A26-49EF-B1EF-CD89CB97C778}" = Windows Live Essentials
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6BF29613-DEEF-44BA-93C1-431B9723041C}" = Windows Live Mail
"{6C016AC4-0282-4C82-B12F-3D5910DA7319}" = Samsung AnyWeb Print
"{6DBC903D-396C-4389-9233-AC2DDB200994}" = Windows Live UX Platform Language Pack
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{70243563-AFF3-4B6A-B267-05BA140BFBB2}" = Windows Live Essentials
"{70D4BC7B-BA81-4385-B32E-045CB20C61DB}" = Windows Live Essentials
"{70E5A613-5A04-42D9-B2CF-C99809BB6E0D}" = Windows Live Messenger
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71D1898F-DFAE-4E0F-B57A-97F5F557EA3A}" = Windows Live Messenger
"{72E76708-0A4F-4586-9312-95A0CA8AD3D7}" = Windows Live Messenger
"{749D0B62-5610-4ADE-82E6-399E6B4DAD80}" = Windows Live Writer Resources
"{7541F284-7167-4729-B1C1-0A3F7FC38EF3}" = Windows Live Messenger
"{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer
"{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}" = Fast Start
"{78F35489-621D-4FFD-BCE7-2C7C3897E47C}" = Windows Live
"{7914488D-F56B-464F-B735-F8E972E5E208}" = Photo Common
"{799AF91B-A07A-4E5A-AFCF-EB1E45ADDD0D}" = Windows Live Messenger
"{7A214298-DDD9-470E-895D-A8051ECA0093}" = Windows Live UX Platform Language Pack
"{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
"{7AEEF79F-4278-4510-AAD0-23AD14508217}" = Photo Common
"{7CCDEF0B-C593-49F0-9A8F-C06F00DF2143}" = Photo Common
"{7D212065-7CC7-4BE4-9084-A8C2C687A72F}" = Windows Live Mail
"{7EC2E709-8ACC-48CA-9F67-2534C5C6A859}" = Windows Live Writer Resources
"{7F2B444B-8D7D-4E46-A5D0-A3309B7B587A}" = Windows Live Essentials
"{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}" = Movie Color Enhancer
"{7FF60141-ECA3-46F0-AB83-58FCC64F8935}" = Windows Live Messenger
"{803D4B7D-71CD-46B9-8F89-8BFD73920FAF}" = Windows Live UX Platform Language Pack
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{83519650-D9E7-46E1-BC78-AE5BEC99D5FB}" = Windows Live Mail
"{84BEAA30-1AF1-450B-9DD7-AD38B84004BA}" = Windows Live Messenger
"{85AC15A4-3C6D-4DA5-9DCE-C3396905CF9E}" = Windows Live Writer Resources
"{8698AFE8-285C-44EA-A282-13DBD7039F1C}" = Photo Common
"{86F56921-A690-4FD8-87B6-7BEAC39D2500}" = Photo Common
"{8732818E-CA78-4ACB-B077-22311BF4C0E4}" = Easy Network Manager
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{8BE01561-9570-47E3-8B7F-D6A80005B970}" = Windows Live Essentials
"{8C5935EF-ECAD-4323-99B8-67AB6163D4D2}" = Photo Common
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8E2E1D4E-1F96-4361-9A69-0F513E3A4A25}" = Windows Live Messenger
"{8E5146B4-EC6A-4C5D-82B7-30F825FF1A91}" = Windows Live Writer Resources
"{8F16159F-116C-4EC1-944C-DE491C8FFA4A}" = Windows Live Messenger
"{90B936B2-33E6-4FE8-9A64-08EEB42AF2B1}" = Podstawowe programy Windows Live
"{9268DD4E-72A7-410D-A6EC-DF510C1E4989}" = Windows Live Messenger
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}" = ChargeableUSB
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{954FC3E4-61C1-43BC-AB13-F0CCF145716D}" = Windows Live 程式集
"{97373E60-D071-418A-87F1-A969EEEEBDAC}" = Windows Live Essentials
"{976BD361-BD7C-49D5-8423-3E98DD480E1F}" = Windows Liven peruspaketti
"{98994720-A230-4F45-875C-AD56E28448F1}" = Windows Live Mail
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A3997FD-359F-42B9-9C6F-82B8378BAAD8}" = Windows Live UX Platform Language Pack
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BC2BB12-8EB4-43D9-97D0-FE1BFCD25903}" = Windows Live Messenger
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CC77921-F397-43AE-8CA2-EDD0982BA25A}" = Windows Live Writer Resources
"{9D4E75DB-519C-4A25-B8D1-97FB673E50C5}" = بريد Windows Live
"{A0080F8F-06D3-4409-8148-59D53EE1CF25}" = Windows Live Essentials
"{A013F3E3-5F8E-43E0-BBCE-BA76F69E457B}" = Windows Live Messenger
"{A15FF85A-065C-4138-A934-113FDF8691EA}" = Windows Live Essentials
"{A18C79C7-3D5D-457A-9C89-8B5F78F1FE56}" = Windows Live UX Platform Language Pack
"{A29F0905-84B3-4D7C-8987-0F402BF1E78E}" = Windows Live Mail
"{A35223E2-05BB-44D3-83A3-AF15C7ACD38D}" = Windows Live Writer Resources
"{A399BFB9-2588-4903-B9E2-4F454BC0670D}" = Windows Live Messenger
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A45B1FCC-C091-45F7-90DB-967421945319}" = Windows Live Messenger
"{A4C39979-BBCA-4781-AE37-DDDE679E1F74}" = Windows Live Writer Resources
"{A5163E8D-19B6-4AFD-A43B-9723A1796AE3}" = Windows Live Messenger
"{A59DA39F-305C-44A0-9747-0646A31394CA}" = Windows Live Essentials
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAA96570-FD87-4E07-87C6-7B3FA40A00A9}" = Windows Live Mail
"{AAFCCC4E-587E-4493-9C11-AB75F208CF1B}" = Windows Live Writer Resources
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AD86049C-3D9C-43E1-BE73-643F57D83D50}" = Easy Migration
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{AFDCB551-9506-41FB-ADBD-678321A0E5F6}" = Windows Live Mail
"{AFFBC271-AA8F-4908-BEAE-491B96AC57C4}" = Windows Live Mail
"{B23B230A-F9CD-4B6C-9202-24257A549CBB}" = Windows Live Writer Resources
"{B25D84F2-16D6-42BB-BF24-158C7676D0B6}" = Windows Live Mail
"{B27FA0A3-D80F-41A9-8BAD-C5F2D859AB22}" = Photo Common
"{B2A814DF-B976-438D-92D0-54B53281F27F}" = Windows Live Writer Resources
"{B410D843-920F-41AB-AE7F-F0C67498C113}" = Windows Live UX Platform Language Pack
"{B417B07D-3373-458A-A431-0F7E3742F182}" = Почта Windows Live
"{B6829511-95BB-46FC-9030-957D54B8EFE2}" = Windows Live UX Platform Language Pack
"{B690AA36-1F69-469A-92DC-256688BD2568}" = Windows Live Mail
"{B767B935-0E5F-4FF9-B758-71253603D93E}" = Windows Live Messenger
"{B8292FC1-3D39-43A0-B65B-BADDA11151FB}" = Windows Live Essentials
"{B89EE842-D398-4EAC-A3DF-47280B285DD9}" = Windows Live Mail
"{B997C04C-DEED-4D49-8CEC-0EF040DF20CB}" = Photo Common
"{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform
"{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BD907BBE-3C60-4F5B-96C0-9F9D23890810}" = Photo Common
"{BECFE8E0-4171-4562-8ED4-CBC4594204C9}" = Windows Live UX Platform Language Pack
"{BFC0D53D-3B7F-42FF-9159-3821B593A0B7}" = Windows Live Mail
"{C33EA3F2-015B-48EE-A3ED-AFFDDC19E74A}" = Windows Live Messenger
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C50ECBA4-CD35-47E6-B0A9-D22C8045B1F7}" = Windows Live Messenger
"{C5335524-82F2-4C78-8A86-7B44AD1946FB}" = Windows Live Essentials
"{C60589D9-9881-4ED8-AF7B-1F955542381F}" = Photo Common
"{C782709A-0F72-4BCF-961B-3F40E2619A32}" = Windows Live Mail
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CBB00A31-1E0F-458C-BA15-0BAFF0567772}" = Windows Live Mail
"{CDA04BEC-2F20-4E3C-A0E0-D75C8DE255D8}" = Windows Live Writer Resources
"{D0873221-A48B-4A2F-9D34-5F0C21725CF5}" = Windows Live Mail
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D296620B-C85E-4890-A9B3-197A521B3457}" = Photo Common
"{D436D212-1381-485A-BE46-32E1E2A95D98}" = Windows Live UX Platform Language Pack
"{D48BCCD6-D2E2-42F4-B8E8-D7BC10C568EC}" = Windows Live UX Platform Language Pack
"{D4C1DC3F-F1C4-4DAB-9DF9-73741965AB8E}" = Windows Live Essentials
"{D531FC91-6F4E-49A7-B912-15289D05B6F8}" = Photo Common
"{D555C389-F793-443A-B012-A3D70590CF3D}" = Windows Live Writer Resources
"{D6C0EDA5-7E06-4F01-895D-B08BBE82AC82}" = Windows Live Mail
"{D775D71D-C54B-41AE-97C2-EDEEBCA4FFCF}" = Windows Live Messenger
"{D77A6FED-256C-4E2F-9873-59C92C854A4E}" = Photo Common
"{D969C468-FCB8-4BFF-A480-33C0A6F7EA64}" = Windows Live Mail
"{DB5D7E49-A671-4FCD-9708-3B2BC93DA995}" = Windows Live UX Platform Language Pack
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DC2CB432-D3B9-4F81-8ACB-7775FD5202E5}" = Photo Common
"{DCCC9E33-B234-42D9-9321-F1B961D3568F}" = Windows Live Messenger
"{DDDC459A-9197-40D6-A4A4-83C46A702550}" = „Windows Live Messenger“
"{DE4E45CB-BA8F-4D82-81DA-22E93E522053}" = Photo Common
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{E044491E-D6E6-48C5-A5CC-BBFA96F19246}" = Windows Live Writer Resources
"{E0970F37-1FFF-46D9-B2EB-43F2E1F01814}" = Windows Live Mail
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E13586CB-4E3A-41D3-BE97-2DA9C86CE6E9}" = Windows Live Writer Resources
"{E1B7239A-120F-4676-9B19-D2B028BEBDD1}" = Windows Live Essentials
"{E3B75D04-2C2B-4423-8800-BF8BF345E504}" = Photo Common
"{E51363F9-BA22-4069-A5CB-B17A9EB06BB9}" = Windows Live UX Platform Language Pack
"{E5E19577-2ECC-4C8E-A342-79D160A06097}" = Windows Live UX Platform Language Pack
"{E60D9CA8-14A6-4F56-BA12-D9D8C8004E09}" = Windows Live Messenger
"{E6B296EB-09A3-45A9-8580-949E28622E5B}" = Windows Live Essentials
"{E9CA6D2F-30AF-48DB-8B29-6593AA68D61B}" = Windows Live UX Platform Language Pack
"{E9E878AA-FF39-43EF-BDFE-01C17A0DD490}" = Windows Live Writer Resources
"{EA53D435-3740-4513-A519-484D2BF659FA}" = Windows Live Writer Resources
"{EA76E65F-6679-495A-A8A6-42AD6602ED4C}" = EasyFileShare
"{EAE21C98-7208-46B6-A10F-9317E1AA63F8}" = Windows Live Messenger
"{ECDAE6DC-6198-4102-96A7-29DA1085B79D}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0DA672E-15DB-4413-BE2D-887DD1513607}" = Windows Live Writer
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1CE08B9-2D76-40A3-8BE8-342FC15D62F6}" = Pošta Windows Live
"{F3EECDE9-68D3-404D-A29B-9DFC72FE48F0}" = Windows Live Messenger
"{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center 1.0
"{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel(R) Wireless Display
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
"{F9328515-878F-4AB9-A113-104DD1A1F6EB}" = Photo Common
"{F9E652C8-88D6-4056-B00A-DC3E4529A421}" = Windows Live UX Platform Language Pack
"{FA2056CD-649B-4CB8-B180-61BF1C20E222}" = Photo Common
"{FB76A294-A78A-4356-87C7-31F0278DF4FB}" = Windows Live 필수 패키지
"{FC278470-09B6-4F42-A84A-58BAB03CA422}" = Windows Live Mail
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FDF614F8-710F-4C28-A90F-07A9BC82774D}" = Windows Live UX Platform Language Pack
"{FE58D81E-30CE-4C73-9A52-28E886B62B91}" = Windows Live Writer Resources
"{FECB76C1-1C1D-4A84-8D47-5754C74B5A5E}" = Junk Mail filter update
"{FFD0E594-823B-4E2B-B680-720B3C852588}" = BatteryLifeExtender
"{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger
"8461-7759-5462-8226" = Vuze
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"FileZilla Client" = FileZilla Client 3.5.3
"Game Console - WildGames" = WildTangent ORB Game Console
"HotspotShield" = Hotspot Shield 2.52
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Samsung Universal Print Driver" = Samsung Universal Print Driver
"Samsung Universal Scan Driver" = Samsung Universal Scan Driver
"Secunia PSI" = Secunia PSI (3.0.0.2004)
"VLC media player" = VLC media player 2.0.2
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WT085559" = Diner Dash 2 Restaurant Rescue
"WT085567" = Chuzzle Deluxe
"WT085580" = John Deere Drive Green
"WT085581" = Penguins!
"WT085583" = Polar Golfer
"WT085587" = Agatha Christie - Death on the Nile
"WT085597" = Build-a-lot
"WT085618" = Farm Frenzy
"WT085622" = Insaniquarium Deluxe
"WT085663" = Peggle
"WT085669" = Plants vs. Zombies
"WT089285" = Zuma Deluxe
"WT089286" = Bejeweled 2 Deluxe

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"SkyDriveSetup.exe" = Microsoft SkyDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/24/2012 9:52:32 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Skype.exe, version: 5.8.0.158, time stamp:
0x4f4de709 Faulting module name: Skype.exe, version: 5.8.0.158, time stamp: 0x4f4de709
Exception
code: 0xc0000005 Fault offset: 0x0087e49d Faulting process id: 0x12d4 Faulting application
start time: 0x01cd21bb9501e9cd Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
Faulting
module path: C:\Program Files (x86)\Skype\Phone\Skype.exe Report Id: bc9f6ec6-8e14-11e1-91c6-e811326191eb

Error - 4/25/2012 12:48:29 PM | Computer Name = Owner-PC | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.

Error - 4/27/2012 3:11:53 AM | Computer Name = Owner-PC | Source = Application Hang | ID = 1002
Description = The program MSASCui.exe version 6.1.7600.16385 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 3e0 Start
Time: 01cd244457a13c33 Termination Time: 0 Application Path: C:\Program Files\Windows
Defender\MSASCui.exe Report Id: 3d13f061-9038-11e1-b7e2-e811326191eb

Error - 4/27/2012 7:41:09 PM | Computer Name = Owner-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Application or service 'Windows Live Messenger' could not be shut
down.

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
Description =

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
Description =

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
Description =

Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
Description =

[ System Events ]
Error - 9/11/2012 7:38:58 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2004
Description = %%860 has encountered an error trying to load signatures and will
attempt reverting back to a known-good set of signatures. Signatures Attempted: %%825
Error
Code: 0x80070002 Error description: The system cannot find the file specified. Signature
version: 1.135.819.0;1.135.819.0 Engine version: 1.1.8704.0

Error - 9/11/2012 7:39:06 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7003
Description = The Hotspot Shield Service service depends the following service:
taphss. This service might not be installed.

Error - 9/11/2012 7:39:37 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the jjvop
service to connect.

Error - 9/11/2012 7:43:54 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 11.159.0.0 Update Source: %%815 Update Stage:
%%854 Source Path: Signature Type: %%886 Update Type: %%803 User: NT AUTHORITY\SYSTEM
Current
Engine Version: Previous Engine Version: 2.0.8001.0 Error code: 0x80070002 Error
description: The system cannot find the file specified.

Error - 9/11/2012 7:43:54 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2003
Description = %%860 has encountered an error trying to update the engine. New Engine
Version: Previous Engine Version: 2.0.8001.0 Engine Type: %%886 User: NT AUTHORITY\SYSTEM
Error
Code: 0x80070002 Error description: The system cannot find the file specified.

Error - 9/11/2012 7:43:58 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 1.135.1007.0 Update Source: %%859 Update Stage:
%%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
User:
NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8704.0 Error
code: 0x80070643 Error description: Fatal error during installation.

Error - 9/11/2012 7:44:09 PM | Computer Name = Owner-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138
(Definition 1.135.1007.0).

Error - 9/11/2012 7:56:10 PM | Computer Name = Owner-PC | Source = BROWSER | ID = 8032
Description =

Error - 9/11/2012 8:23:35 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7003
Description = The Hotspot Shield Service service depends the following service:
taphss. This service might not be installed.

Error - 9/11/2012 8:24:09 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the jjvop
service to connect.


< End of report >
 
Back