TechSpot

Search engine redirect malware

Solved
By yeahisgood
Sep 9, 2012
  1. I am getting a search engine redirect. Recently, I removed some trojan viruses using MSE and Malwarebytes. However, when I restarted Windows I got a .dll error window pop up for xtlbj.dll.

    I would appreciate any help you could provide.
     
  2. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    You've been to this forum before so you should know what the deal is...

    Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
     
  3. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Broni,

    Thanks once again


    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org
    Database version: v2012.09.08.09
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Owner :: OWNER-PC [administrator]
    9/10/2012 7:53:51 AM
    mbam-log-2012-09-10 (07-53-51).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 230789
    Time elapsed: 5 minute(s), 39 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org
    Database version: v2012.09.08.09
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Owner :: OWNER-PC [administrator]
    9/10/2012 7:53:51 AM
    mbam-log-2012-09-10 (07-53-51).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 230789
    Time elapsed: 5 minute(s), 39 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 0
    (No malicious items detected)
    (end)
    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.6.2
    Run by Owner at 8:48:04 on 2012-09-10
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.3110 [GMT -4:00]
    .
    AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Program Files\Microsoft Security Client\MsMpEng.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
    C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
    C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Program Files\Elantech\ETDCtrl.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files\Elantech\ETDCtrlHelper.exe
    C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
    C:\Windows\Samsung\PanelMgr\caller64.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
    C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
    C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\srspremiumpanel_64.exe
    C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
    C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k HPService
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Secunia\PSI\sua.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\igfxext.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
    C:\Program Files\Samsung\SamsungFastStart\SmartRestarter.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
    C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
    C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\notepad.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D9Y5HIRG\8gf9qkq5.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Microsoft Security Client\MpCmdRun.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\DllHost.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.siccode.com/
    mStart Page = hxxp://samsung.msn.com
    BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: W2PBrowser Class: {aa609d72-8482-4076-8991-8cdae5b93bcb} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - C:\Program Files (x86)\WOT\WOT.dll
    EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_bho.dll
    uRun: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
    uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    uRun: [nerlex] rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track
    uRun: [Deployment] rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW
    mRun: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableLUA = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {328ECD19-C167-40eb-A0C7-16FE7634105E} - {94BB0C4C-B957-479A-85E4-42F53B89F681} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
    DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
    DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} - hxxps://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
    TCP: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
    TCP: Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859} : DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
    TCP: Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859}\D4169726163686737373 : DhcpNameServer = 167.206.245.129 167.206.245.130
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll
    AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    BHO-X64: HP Print Enhancer - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: W2PBrowser Class: {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll
    BHO-X64: W2PBrowser Browser Helper - No File
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    BHO-X64: WOT Helper: {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
    BHO-X64: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    BHO-X64: HP Smart BHO Class - No File
    TB-X64: WOT: {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll
    EB-X64: {555D4D79-4BD2-4094-A395-CFC534424A05} - No File
    mRun-x64: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
    mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    mRun-x64: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe
    AppInit_DLLs-X64: C:\Windows\SysWOW64\nvinit.dll
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\
    FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
    FF - prefs.js: network.proxy.type - 0
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
    FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
    FF - plugin: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
    FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
    FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: general.useragent.extra.brc -
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
    R0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys --> C:\Windows\system32\DRIVERS\nvpciflt.sys [?]
    R1 SABI;SAMSUNG Kernel Driver For Windows 7;\??\C:\Windows\system32\Drivers\SABI.sys --> C:\Windows\system32\Drivers\SABI.sys [?]
    R1 VWiFiFlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-7-27 63960]
    R2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [2010-8-31 408576]
    R2 HssWd;Hotspot Shield Monitoring Service;C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS --> C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [?]
    R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2010-6-1 2804568]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-12-22 1997416]
    R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2012-6-27 1326176]
    R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-6-27 681056]
    R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys --> C:\Windows\system32\DRIVERS\TurboB.sys [?]
    R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-22 2655768]
    R2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [2010-8-31 911872]
    R3 bpenum;bpenum;C:\Windows\system32\DRIVERS\bpenum.sys --> C:\Windows\system32\DRIVERS\bpenum.sys [?]
    R3 bpmp;Intel(R) Centrino(R) WiMAX 6050 Series;C:\Windows\system32\DRIVERS\bpmp.sys --> C:\Windows\system32\DRIVERS\bpmp.sys [?]
    R3 bpusb;bpusb;C:\Windows\system32\Drivers\bpusb.sys --> C:\Windows\system32\Drivers\bpusb.sys [?]
    R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]
    R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
    R3 MEIx64;Intel(R) Management Engine Interface ;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
    R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys --> C:\Windows\system32\DRIVERS\nusb3hub.sys [?]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys --> C:\Windows\system32\DRIVERS\nusb3xhc.sys [?]
    R3 PSI;PSI;C:\Windows\system32\DRIVERS\psi_mf.sys --> C:\Windows\system32\DRIVERS\psi_mf.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
    R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
    S2 CLKMSVC10_38F51D56;CyberLink Product - 2010/12/22 19:14:12;C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-8-24 246256]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-18 136176]
    S2 hshld;Hotspot Shield Service;C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-3-26 542040]
    S2 jjvop;jjvop;C:\Users\Owner\AppData\Roaming\clmioni1.bat [2012-9-8 87]
    S2 KMService;KMService;C:\Windows\System32\srvany.exe [2011-8-19 8192]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-6-7 160944]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-1 250568]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-8-18 136176]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 51740536]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-6-13 113120]
    S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-2 340240]
    S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
    S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
    S3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-1-9 174440]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S3 Samsung UPD Service;Samsung UPD Service;"C:\Windows\System32\SUPDSvc.exe" --> C:\Windows\System32\SUPDSvc.exe [?]
    S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);C:\Windows\system32\DRIVERS\ssadbus.sys --> C:\Windows\system32\DRIVERS\ssadbus.sys [?]
    S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);C:\Windows\system32\DRIVERS\ssadmdfl.sys --> C:\Windows\system32\DRIVERS\ssadmdfl.sys [?]
    S3 ssadmdm;SAMSUNG Android USB Modem Drivers;C:\Windows\system32\DRIVERS\ssadmdm.sys --> C:\Windows\system32\DRIVERS\ssadmdm.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2010-10-8 150016]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
    .
    =============== Created Last 30 ================
    .
    2012-09-10 12:47:00 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{8C3AE019-23CD-47BB-B44C-DDA3E0EEC535}\mpengine.dll
    2012-09-09 01:45:08 9310152 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-09-08 21:51:42 87 ---h--w- C:\Users\Owner\AppData\Roaming\clmioni1.bat
    2012-09-08 21:45:32 110592 ----a-w- C:\ProgramData\2jFf5J64.exe_
    2012-09-08 21:45:32 110592 ----a-w- C:\ProgramData\2jFf5J64.exe
    2012-09-08 02:21:05 -------- d-----w- C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
    2012-09-08 02:21:01 416768 ----a-w- C:\Users\Owner\AppData\Roaming\nerlex.dll
    2012-09-08 02:20:07 90 ---h--w- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
    2012-09-06 20:16:40 916456 ----a-w- C:\Windows\System32\deployJava1.dll
    2012-09-06 20:16:40 1034216 ----a-w- C:\Windows\System32\npDeployJava1.dll
    2012-09-06 20:16:33 108008 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
    2012-09-04 21:59:01 -------- d-----w- C:\Users\Owner\AppData\Roaming\pdfforge
    2012-09-04 21:28:26 177640 ----a-w- C:\Windows\System32\drivers\ssadmdm.sys
    2012-09-04 21:28:26 16872 ----a-w- C:\Windows\System32\drivers\ssadmdfl.sys
    2012-09-04 21:28:26 157672 ----a-w- C:\Windows\System32\drivers\ssadbus.sys
    2012-09-04 21:28:26 13800 ----a-w- C:\Windows\System32\drivers\ssadwhnt.sys
    2012-09-04 21:28:26 13800 ----a-w- C:\Windows\System32\drivers\ssadwh.sys
    2012-09-04 21:28:26 13288 ----a-w- C:\Windows\System32\drivers\ssadcmnt.sys
    2012-09-04 21:28:26 13288 ----a-w- C:\Windows\System32\drivers\ssadcm.sys
    2012-08-29 14:00:28 60864 ----a-w- C:\Users\Owner\g2mdlhlpx.exe
    2012-08-24 11:44:50 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-08-24 11:44:50 366592 ----a-w- C:\Windows\System32\qdvd.dll
    2012-08-24 01:38:28 5563840 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\f126a2711cd819803\skydrivesetup.exe
    2012-08-24 01:38:28 -------- d-----w- C:\Program Files (x86)\Microsoft SkyDrive
    2012-08-24 01:38:27 -------- d-----r- C:\Users\Owner\SkyDrive
    2012-08-24 01:38:18 -------- d-----w- C:\ProgramData\Microsoft SkyDrive
    2012-08-24 01:01:41 751104 ----a-w- C:\Windows\System32\win32spl.dll
    2012-08-24 01:01:41 67072 ----a-w- C:\Windows\splwow64.exe
    2012-08-24 01:01:41 559104 ----a-w- C:\Windows\System32\spoolsv.exe
    2012-08-24 01:01:41 492032 ----a-w- C:\Windows\SysWow64\win32spl.dll
    2012-08-24 01:01:36 503808 ----a-w- C:\Windows\System32\srcore.dll
    2012-08-24 01:01:36 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
    2012-08-24 01:01:33 59392 ----a-w- C:\Windows\System32\browcli.dll
    2012-08-24 01:01:33 136704 ----a-w- C:\Windows\System32\browser.dll
    2012-08-24 01:01:32 41984 ----a-w- C:\Windows\SysWow64\browcli.dll
    2012-08-24 01:00:53 3148800 ----a-w- C:\Windows\System32\win32k.sys
    2012-08-24 01:00:52 956928 ----a-w- C:\Windows\System32\localspl.dll
    2012-08-24 00:57:49 -------- d-----w- C:\Users\Owner\AppData\Local\Secunia PSI
    2012-08-24 00:57:11 -------- d-----w- C:\Program Files (x86)\Secunia
    2012-08-24 00:53:49 -------- d-----w- C:\Program Files (x86)\FileHippo.com
    2012-08-24 00:39:52 -------- d-----w- C:\Program Files\WOT
    2012-08-24 00:39:52 -------- d-----w- C:\Program Files (x86)\WOT
    2012-08-23 21:28:23 821736 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
    2012-08-23 21:28:16 95208 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
    2012-08-23 16:01:09 -------- d-----w- C:\Program Files (x86)\ESET
    2012-08-23 04:50:32 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-08-23 04:50:32 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-08-22 19:32:44 -------- d-----w- C:\$RECYCLE.BIN
    2012-08-22 14:58:27 -------- d-----w- C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
    2012-08-16 19:45:50 -------- d-----w- C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
    2012-08-16 19:45:37 -------- d-----w- C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
    2012-08-16 19:41:33 -------- d-----w- C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
    2012-08-16 19:41:24 -------- d-----w- C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
    2012-08-16 19:37:26 -------- d-----w- C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
    2012-08-16 19:37:14 -------- d-----w- C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
    2012-08-16 19:32:27 -------- d-----w- C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
    2012-08-16 19:32:16 -------- d-----w- C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
    2012-08-16 19:28:37 -------- d-----w- C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
    2012-08-16 19:20:58 -------- d-----w- C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
    2012-08-16 19:20:46 -------- d-----w- C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
    2012-08-15 17:51:28 -------- d-----w- C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
    2012-08-15 17:51:15 -------- d-----w- C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
    2012-08-14 15:03:42 -------- d-----w- C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
    2012-08-14 15:03:18 -------- d-----w- C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
    2012-08-14 14:46:32 -------- d-----w- C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
    2012-08-14 14:42:40 -------- d-----w- C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
    2012-08-14 14:42:12 -------- d-----w- C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
    2012-08-14 14:32:49 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0E999AD8-2F3C-4985-9FFC-7E1842C661EF}\gapaengine.dll
    2012-08-14 14:30:17 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
    2012-08-14 14:30:15 -------- d-----w- C:\Program Files\Microsoft Security Client
    2012-08-14 11:23:22 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
    2012-08-13 21:37:08 -------- d-----w- C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
    2012-08-13 21:36:52 -------- d-----w- C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
    2012-08-13 18:28:26 -------- d-----w- C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
    2012-08-13 18:28:12 -------- d-----w- C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
    2012-08-13 14:40:38 -------- d-----w- C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
    2012-08-13 14:39:34 -------- d-----w- C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
    2012-08-13 10:35:18 -------- d-----w- C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
    2012-08-13 10:33:25 -------- d-----w- C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
    2012-08-12 10:38:12 -------- d-----w- C:\Users\Owner\AppData\Local\{E727C9E2-E3DE-49F2-9DC0-AF9EC23EB817}
    2012-08-12 03:26:15 -------- d-----w- C:\Users\Owner\AppData\Local\{D458277E-8667-4B04-9785-D180139CFE5C}
    .
    ==================== Find3M ====================
    .
    2012-09-08 21:51:29 210051234 ----a-w- C:\Users\Owner\AppData\Roaming\jjvop.exe
    2012-08-31 18:52:38 73416 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-08-31 18:52:38 696520 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-08-23 21:28:11 746984 ----a-w- C:\Windows\SysWow64\deployJava1.dll
    2012-07-28 07:09:02 57792 ----a-w- C:\Windows\SysWow64\sirenacm.dll
    2012-07-26 23:08:06 862664 ----a-w- C:\Windows\SysWow64\msvcr110.dll
    2012-07-26 23:08:06 534480 ----a-w- C:\Windows\SysWow64\msvcp110.dll
    2012-07-26 23:08:06 251864 ----a-w- C:\Windows\SysWow64\vccorlib110.dll
    2012-07-26 23:08:06 153536 ----a-w- C:\Windows\SysWow64\atl110.dll
    2012-07-26 23:08:06 115656 ----a-w- C:\Windows\SysWow64\vcomp110.dll
    2012-07-26 19:22:10 828872 ----a-w- C:\Windows\System32\msvcr110.dll
    2012-07-26 19:22:10 661448 ----a-w- C:\Windows\System32\msvcp110.dll
    2012-07-26 19:22:10 354264 ----a-w- C:\Windows\System32\vccorlib110.dll
    2012-07-26 19:22:10 177096 ----a-w- C:\Windows\System32\atl110.dll
    2012-07-26 19:22:10 124360 ----a-w- C:\Windows\System32\vcomp110.dll
    2012-07-17 19:14:44 253184 ----a-w- C:\Windows\System32\LIVESSP.DLL
    2012-07-17 18:49:00 209648 ----a-w- C:\Windows\SysWow64\LIVESSP.DLL
    2012-06-29 03:56:34 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2012-06-29 03:49:11 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-06-29 03:48:07 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-06-29 03:43:49 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-06-29 03:39:48 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-06-29 00:16:58 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-06-29 00:09:01 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-06-29 00:08:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-06-29 00:04:43 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-06-29 00:00:45 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-06-25 20:04:24 1394248 ----a-w- C:\Windows\SysWow64\msxml4.dll
    .
    ============= FINISH: 8:48:50.16 ===============
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/15/2011 2:22:35 AM
    System Uptime: 9/9/2012 10:14:58 PM (10 hours ago)
    .
    Motherboard: SAMSUNG ELECTRONICS CO., LTD. | | RC512
    Processor: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz | CPU 1 | 780/100mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 272 GiB total, 120.273 GiB free.
    D: is FIXED (NTFS) - 406 GiB total, 132.365 GiB free.
    E: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
    Description: Officejet 4500 G510n-z
    Device ID: ROOT\IMAGE\0001
    Manufacturer: HP
    Name: Officejet 4500 G510n-z
    PNP Device ID: ROOT\IMAGE\0001
    Service: StillCam
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 4500 G510n-z
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet 4500 G510n-z
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\NET\0000
    Manufacturer:
    Name:
    PNP Device ID: ROOT\NET\0000
    Service:
    .
    ==== System Restore Points ===================
    .
    RP183: 8/30/2012 9:56:13 PM - Windows Update
    RP184: 9/2/2012 7:44:38 PM - Windows Backup
    RP185: 9/3/2012 10:58:15 PM - Windows Update
    RP186: 9/6/2012 4:15:59 PM - Installed Java 7 Update 7 (64-bit)
    RP187: 9/7/2012 2:17:20 AM - Windows Update
    RP188: 9/10/2012 12:45:48 AM - Windows Backup
    .
    ==== Installed Programs ======================
    .
    ???? Windows Live
    ????? Windows Live
    ???????? ?????????? Windows Live
    ?????????? (????????????? ??????)
    4500_G510nz_Help
    4500G510nz
    4500G510nz_Software_Min
    ActiveState Komodo Edit 6.1.2
    Adobe AIR
    Adobe Flash Player 11 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.1.4)
    Agatha Christie - Death on the Nile
    Audacity 1.3.14 (Unicode)
    „Windows Live Essentials“
    „Windows Live Mail“
    „Windows Live Messenger“
    BatteryLifeExtender
    Bejeweled 2 Deluxe
    BufferChm
    Build-a-lot
    CamStudio OSS Desktop Recorder
    ChargeableUSB
    Chuzzle Deluxe
    CyberLink Media Suite
    CyberLink MediaShow
    CyberLink Power2Go
    CyberLink PowerDirector
    CyberLink PowerDVD 10
    CyberLink YouCam
    D3DX10
    Destinations
    DeviceDiscovery
    Diner Dash 2 Restaurant Rescue
    DocMgr
    DocProc
    Easy Display Manager
    Easy Migration
    Easy Network Manager
    Easy SpeedUp Manager
    EasyBatteryManager
    EasyFileShare
    ESET Online Scanner v3
    Farm Frenzy
    Fast Start
    Fax
    FileHippo.com Update Checker
    FileZilla Client 3.5.3
    Google Chrome
    Google Earth
    Google Update Helper
    GPBaseService2
    Hewlett-Packard ACLM.NET v1.1.0.0
    Hotspot Shield 2.52
    HP Officejet 6500 E710n-z Help
    HP Product Detection
    HP Update
    HPProductAssistant
    HPSSupply
    Insaniquarium Deluxe
    Intel(R) Control Center
    Intel(R) Management Engine Components
    Intel(R) Processor Graphics
    Intel(R) Rapid Storage Technology
    Intel(R) Wireless Display
    IrfanView (remove only)
    Java 7 Update 6
    Java Auto Updater
    Java(TM) 6 Update 33
    John Deere Drive Green
    Junk Mail filter update
    Malwarebytes Anti-Malware version 1.62.0.1300
    MarketResearch
    Microsoft Office 2010
    Microsoft SkyDrive
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Microsoft_VC80_CRT_x86
    Microsoft_VC90_CRT_x86
    Movie Color Enhancer
    Mozilla Firefox 14.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSVCRT
    MSVCRT_amd64
    MSVCRT110
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    Multimedia POP
    Norton Online Backup
    Peggle
    Penguins!
    Photo Common
    Plants vs. Zombies
    Poczta uslugi Windows Live
    Podstawowe programy Windows Live
    Polar Golfer
    Pošta Windows Live
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    Renesas Electronics USB 3.0 Host Controller Driver
    Samsung AnyWeb Print
    Samsung Recovery Solution 5
    Samsung Support Center 1.0
    Samsung Universal Print Driver
    Samsung Universal Scan Driver
    Samsung Update Plus
    Scan
    Secunia PSI (3.0.0.2004)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Skype™ 5.10
    SmartWebPrinting
    SolutionCenter
    Status
    Toolbox
    TrayApp
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    User Guide
    VC80CRTRedist - 8.0.50727.6195
    Visual Studio 2008 x64 Redistributables
    VLC media player 2.0.2
    Vuze
    WebReg
    WildTangent Games
    WildTangent ORB Game Console
    Windows Live
    Windows Live ??
    Windows Live ?? ???
    Windows Live ???
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Common
    Windows Live PIMT Platform
    Windows Live Pošta
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Temel Parçalar
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Liven peruspaketti
    Windows Liven sähköposti
    Zuma Deluxe
    .
    ==== Event Viewer Messages From Past Week ========
    .
    9/9/2012 6:16:34 AM, Error: Schannel [36887] - The following fatal alert was received: 80.
    9/8/2012 9:59:58 PM, Error: Service Control Manager [7003] - The Hotspot Shield Service service depends the following service: taphss. This service might not be installed.
    9/8/2012 5:51:44 PM, Error: Service Control Manager [7030] - The jjvop service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
    9/8/2012 10:00:29 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the jjvop service to connect.
    9/7/2012 8:38:46 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer JOHN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{DEAA0459-FD77-4007-B31D-7998BC471859}. The master browser is stopping or an election is being forced.
    9/5/2012 11:04:02 PM, Error: Service Control Manager [7043] - The Windows Update service did not shut down properly after receiving a preshutdown control.
    9/10/2012 3:31:01 AM, Error: VDS Basic Provider [1] - Unexpected failure. Error code: D@01010004
    9/10/2012 3:25:08 AM, Error: volsnap [35] - The shadow copies of volume D: were aborted because the shadow copy storage failed to grow.
    .
    ==== End Of File ===========================
     
  4. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.

    =================================

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    ==============================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  5. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    20:51:31.0237 6396 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
    20:51:31.0547 6396 ============================================================
    20:51:31.0547 6396 Current date / time: 2012/09/10 20:51:31.0547
    20:51:31.0547 6396 SystemInfo:
    20:51:31.0547 6396
    20:51:31.0547 6396 OS Version: 6.1.7601 ServicePack: 1.0
    20:51:31.0547 6396 Product type: Workstation
    20:51:31.0547 6396 ComputerName: OWNER-PC
    20:51:31.0547 6396 UserName: Owner
    20:51:31.0547 6396 Windows directory: C:\Windows
    20:51:31.0547 6396 System windows directory: C:\Windows
    20:51:31.0547 6396 Running under WOW64
    20:51:31.0547 6396 Processor architecture: Intel x64
    20:51:31.0547 6396 Number of processors: 8
    20:51:31.0547 6396 Page size: 0x1000
    20:51:31.0547 6396 Boot type: Normal boot
    20:51:31.0547 6396 ============================================================
    20:51:33.0197 6396 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    20:51:33.0212 6396 ============================================================
    20:51:33.0212 6396 \Device\Harddisk0\DR0:
    20:51:33.0228 6396 MBR partitions:
    20:51:33.0228 6396 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    20:51:33.0228 6396 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x22000000
    20:51:33.0243 6396 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x22033000, BlocksNum 0x32CAE800
    20:51:33.0243 6396 ============================================================
    20:51:33.0306 6396 C: <-> \Device\Harddisk0\DR0\Partition2
    20:51:33.0415 6396 D: <-> \Device\Harddisk0\DR0\Partition3
    20:51:33.0446 6396 ============================================================
    20:51:33.0446 6396 Initialize success
    20:51:33.0446 6396 ============================================================
    20:52:12.0146 4916 ============================================================
    20:52:12.0146 4916 Scan started
    20:52:12.0146 4916 Mode: Manual;
    20:52:12.0146 4916 ============================================================
    20:52:13.0236 4916 ================ Scan system memory ========================
    20:52:13.0236 4916 System memory - ok
    20:52:13.0236 4916 ================ Scan services =============================
    20:52:13.0496 4916 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
    20:52:13.0506 4916 1394ohci - ok
    20:52:13.0586 4916 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
    20:52:13.0586 4916 ACPI - ok
    20:52:13.0636 4916 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
    20:52:13.0646 4916 AcpiPmi - ok
    20:52:13.0916 4916 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    20:52:14.0116 4916 AdobeARMservice - ok
    20:52:14.0296 4916 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    20:52:14.0296 4916 AdobeFlashPlayerUpdateSvc - ok
    20:52:14.0346 4916 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
    20:52:14.0356 4916 adp94xx - ok
    20:52:14.0376 4916 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
    20:52:14.0396 4916 adpahci - ok
    20:52:14.0436 4916 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
    20:52:14.0436 4916 adpu320 - ok
    20:52:14.0476 4916 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    20:52:14.0476 4916 AeLookupSvc - ok
    20:52:14.0556 4916 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
    20:52:14.0566 4916 AFD - ok
    20:52:14.0616 4916 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
    20:52:14.0616 4916 agp440 - ok
    20:52:14.0646 4916 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
    20:52:14.0646 4916 ALG - ok
    20:52:14.0696 4916 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
    20:52:14.0696 4916 aliide - ok
    20:52:14.0716 4916 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
    20:52:14.0716 4916 amdide - ok
    20:52:14.0746 4916 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
    20:52:14.0746 4916 AmdK8 - ok
    20:52:14.0776 4916 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
    20:52:14.0776 4916 AmdPPM - ok
    20:52:14.0806 4916 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    20:52:14.0816 4916 amdsata - ok
    20:52:14.0846 4916 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
    20:52:14.0856 4916 amdsbs - ok
    20:52:14.0876 4916 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    20:52:14.0876 4916 amdxata - ok
    20:52:14.0906 4916 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
    20:52:14.0906 4916 AppID - ok
    20:52:14.0936 4916 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    20:52:14.0936 4916 AppIDSvc - ok
    20:52:14.0976 4916 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
    20:52:14.0976 4916 Appinfo - ok
    20:52:15.0026 4916 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
    20:52:15.0026 4916 arc - ok
    20:52:15.0046 4916 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
    20:52:15.0046 4916 arcsas - ok
    20:52:15.0076 4916 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    20:52:15.0076 4916 AsyncMac - ok
    20:52:15.0136 4916 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
    20:52:15.0136 4916 atapi - ok
    20:52:15.0196 4916 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    20:52:15.0206 4916 AudioEndpointBuilder - ok
    20:52:15.0226 4916 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    20:52:15.0226 4916 AudioSrv - ok
    20:52:15.0276 4916 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
    20:52:15.0286 4916 AxInstSV - ok
    20:52:15.0326 4916 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
    20:52:15.0346 4916 b06bdrv - ok
    20:52:15.0366 4916 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
    20:52:15.0376 4916 b57nd60a - ok
    20:52:15.0406 4916 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
    20:52:15.0406 4916 BDESVC - ok
    20:52:15.0446 4916 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
    20:52:15.0446 4916 Beep - ok
    20:52:15.0540 4916 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
    20:52:15.0556 4916 BFE - ok
    20:52:15.0654 4916 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
    20:52:15.0714 4916 BITS - ok
    20:52:15.0754 4916 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
    20:52:15.0754 4916 blbdrive - ok
    20:52:15.0814 4916 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    20:52:15.0814 4916 bowser - ok
    20:52:15.0854 4916 [ F46DD257FAD7D2D097EF32E72220A06C ] bpenum C:\Windows\system32\DRIVERS\bpenum.sys
    20:52:15.0854 4916 bpenum - ok
    20:52:15.0894 4916 [ E82060AED0F28ED8909F2B07FA276185 ] bpmp C:\Windows\system32\DRIVERS\bpmp.sys
    20:52:15.0904 4916 bpmp - ok
    20:52:15.0924 4916 [ FC6313A5A45C1AE53D0491F0057D5A4D ] bpusb C:\Windows\system32\Drivers\bpusb.sys
    20:52:15.0924 4916 bpusb - ok
    20:52:15.0934 4916 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
    20:52:15.0944 4916 BrFiltLo - ok
    20:52:15.0974 4916 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
    20:52:15.0974 4916 BrFiltUp - ok
    20:52:16.0004 4916 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
    20:52:16.0004 4916 BridgeMP - ok
    20:52:16.0044 4916 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
    20:52:16.0044 4916 Browser - ok
    20:52:16.0084 4916 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\system32\Drivers\Brserid.sys
    20:52:16.0094 4916 Brserid - ok
    20:52:16.0124 4916 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    20:52:16.0124 4916 BrSerWdm - ok
    20:52:16.0134 4916 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    20:52:16.0154 4916 BrUsbMdm - ok
    20:52:16.0164 4916 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\Drivers\BrUsbSer.sys
    20:52:16.0164 4916 BrUsbSer - ok
    20:52:16.0184 4916 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
    20:52:16.0194 4916 BTHMODEM - ok
    20:52:16.0224 4916 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
    20:52:16.0234 4916 bthserv - ok
    20:52:16.0284 4916 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    20:52:16.0284 4916 cdfs - ok
    20:52:16.0334 4916 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    20:52:16.0344 4916 cdrom - ok
    20:52:16.0364 4916 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
    20:52:16.0364 4916 CertPropSvc - ok
    20:52:16.0404 4916 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
    20:52:16.0404 4916 circlass - ok
    20:52:16.0474 4916 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
    20:52:16.0484 4916 CLFS - ok
    20:52:16.0624 4916 [ FE1C81A049E5C5D67C4AB7C31C899F6F ] CLKMSVC10_38F51D56 C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
    20:52:16.0634 4916 CLKMSVC10_38F51D56 - ok
    20:52:16.0704 4916 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    20:52:16.0704 4916 clr_optimization_v2.0.50727_32 - ok
    20:52:16.0764 4916 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    20:52:16.0764 4916 clr_optimization_v2.0.50727_64 - ok
    20:52:16.0894 4916 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    20:52:16.0914 4916 clr_optimization_v4.0.30319_32 - ok
    20:52:16.0974 4916 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    20:52:16.0974 4916 clr_optimization_v4.0.30319_64 - ok
    20:52:17.0024 4916 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
    20:52:17.0024 4916 clwvd - ok
    20:52:17.0054 4916 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
    20:52:17.0054 4916 CmBatt - ok
    20:52:17.0114 4916 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
    20:52:17.0114 4916 cmdide - ok
    20:52:17.0214 4916 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
    20:52:17.0224 4916 CNG - ok
    20:52:17.0254 4916 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
    20:52:17.0264 4916 Compbatt - ok
    20:52:17.0304 4916 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
    20:52:17.0304 4916 CompositeBus - ok
    20:52:17.0314 4916 COMSysApp - ok
    20:52:17.0334 4916 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
    20:52:17.0334 4916 crcdisk - ok
    20:52:17.0384 4916 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
    20:52:17.0394 4916 CryptSvc - ok
    20:52:17.0454 4916 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
    20:52:17.0464 4916 DcomLaunch - ok
    20:52:17.0514 4916 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
    20:52:17.0514 4916 defragsvc - ok
    20:52:17.0564 4916 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    20:52:17.0564 4916 DfsC - ok
    20:52:17.0604 4916 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
    20:52:17.0614 4916 Dhcp - ok
    20:52:17.0644 4916 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
    20:52:17.0644 4916 discache - ok
    20:52:17.0654 4916 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
    20:52:17.0664 4916 Disk - ok
    20:52:17.0744 4916 [ C4AEBBEB530706B45B7916161A1F525D ] DMAgent C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
    20:52:17.0864 4916 DMAgent - ok
    20:52:17.0914 4916 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    20:52:17.0924 4916 Dnscache - ok
    20:52:17.0964 4916 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
    20:52:17.0974 4916 dot3svc - ok
    20:52:18.0004 4916 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
    20:52:18.0014 4916 DPS - ok
    20:52:18.0034 4916 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    20:52:18.0044 4916 drmkaud - ok
    20:52:18.0124 4916 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    20:52:18.0144 4916 DXGKrnl - ok
    20:52:18.0184 4916 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
    20:52:18.0194 4916 EapHost - ok
    20:52:18.0284 4916 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
    20:52:18.0364 4916 ebdrv - ok
    20:52:18.0414 4916 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
    20:52:18.0424 4916 EFS - ok
    20:52:18.0534 4916 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    20:52:18.0554 4916 ehRecvr - ok
    20:52:18.0574 4916 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
    20:52:18.0574 4916 ehSched - ok
    20:52:18.0624 4916 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
    20:52:18.0634 4916 elxstor - ok
    20:52:18.0674 4916 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
    20:52:18.0674 4916 ErrDev - ok
    20:52:18.0714 4916 [ 9D8739A2A2173C9D27C499A3FC6EDA3F ] ETD C:\Windows\system32\DRIVERS\ETD.sys
    20:52:18.0714 4916 ETD - ok
    20:52:18.0764 4916 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
    20:52:18.0774 4916 EventSystem - ok
    20:52:18.0874 4916 [ F8F610093E1D7FDFA477FC34D15D5C60 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    20:52:18.0904 4916 EvtEng - ok
    20:52:18.0924 4916 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
    20:52:18.0934 4916 exfat - ok
    20:52:18.0954 4916 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
    20:52:18.0964 4916 fastfat - ok
    20:52:19.0024 4916 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
    20:52:19.0034 4916 Fax - ok
    20:52:19.0054 4916 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
    20:52:19.0054 4916 fdc - ok
    20:52:19.0094 4916 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
    20:52:19.0104 4916 fdPHost - ok
    20:52:19.0134 4916 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
    20:52:19.0134 4916 FDResPub - ok
    20:52:19.0184 4916 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    20:52:19.0194 4916 FileInfo - ok
    20:52:19.0204 4916 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    20:52:19.0204 4916 Filetrace - ok
    20:52:19.0234 4916 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
    20:52:19.0234 4916 flpydisk - ok
    20:52:19.0284 4916 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    20:52:19.0294 4916 FltMgr - ok
    20:52:19.0364 4916 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
    20:52:19.0384 4916 FontCache - ok
    20:52:19.0444 4916 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    20:52:19.0444 4916 FontCache3.0.0.0 - ok
    20:52:19.0474 4916 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    20:52:19.0474 4916 FsDepends - ok
    20:52:19.0524 4916 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    20:52:19.0534 4916 Fs_Rec - ok
    20:52:19.0574 4916 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    20:52:19.0594 4916 fvevol - ok
    20:52:19.0624 4916 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
    20:52:19.0624 4916 gagp30kx - ok
    20:52:19.0684 4916 [ 521A469CAF61F00E1DE081CC2099C1D6 ] GameConsoleService C:\Program Files (x86)\WildGames\Game Console - WildGames\GameConsoleService.exe
    20:52:19.0694 4916 GameConsoleService - ok
    20:52:19.0754 4916 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
    20:52:19.0764 4916 gpsvc - ok
    20:52:19.0864 4916 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    20:52:19.0864 4916 gupdate - ok
    20:52:19.0884 4916 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    20:52:19.0894 4916 gupdatem - ok
    20:52:19.0914 4916 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    20:52:19.0914 4916 hcw85cir - ok
    20:52:19.0974 4916 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    20:52:19.0984 4916 HdAudAddService - ok
    20:52:19.0994 4916 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
    20:52:20.0004 4916 HDAudBus - ok
    20:52:20.0034 4916 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
    20:52:20.0034 4916 HidBatt - ok
    20:52:20.0054 4916 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
    20:52:20.0054 4916 HidBth - ok
    20:52:20.0084 4916 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
    20:52:20.0084 4916 HidIr - ok
    20:52:20.0114 4916 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
    20:52:20.0124 4916 hidserv - ok
    20:52:20.0144 4916 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    20:52:20.0144 4916 HidUsb - ok
    20:52:20.0184 4916 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
    20:52:20.0194 4916 hkmsvc - ok
    20:52:20.0234 4916 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    20:52:20.0244 4916 HomeGroupListener - ok
    20:52:20.0284 4916 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    20:52:20.0294 4916 HomeGroupProvider - ok
    20:52:20.0444 4916 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
    20:52:20.0454 4916 hpqcxs08 - ok
    20:52:20.0554 4916 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
    20:52:20.0554 4916 hpqddsvc - ok
    20:52:20.0584 4916 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    20:52:20.0584 4916 HpSAMD - ok
    20:52:20.0654 4916 [ F37882F128EFACEFE353E0BAE2766909 ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
    20:52:20.0664 4916 HPSLPSVC - ok
    20:52:20.0744 4916 [ 575546EE9A39DD5CB3B4E34A146A8A3E ] hshld C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
    20:52:20.0754 4916 hshld - ok
    20:52:20.0844 4916 [ 2CFEA9C337B699ACA38487E8A7438F35 ] HssSrv C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
    20:52:20.0844 4916 HssSrv - ok
    20:52:20.0864 4916 [ 4EFB7FC2A11DB10AB6205206D60C432B ] HssTrayService C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
    20:52:20.0864 4916 HssTrayService - ok
    20:52:20.0874 4916 HssWd - ok
    20:52:20.0934 4916 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    20:52:20.0944 4916 HTTP - ok
    20:52:20.0984 4916 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    20:52:20.0984 4916 hwpolicy - ok
    20:52:21.0034 4916 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
    20:52:21.0034 4916 i8042prt - ok
    20:52:21.0084 4916 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    20:52:21.0094 4916 iaStor - ok
    20:52:21.0144 4916 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    20:52:21.0154 4916 iaStorV - ok
    20:52:21.0224 4916 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    20:52:21.0244 4916 idsvc - ok
    20:52:21.0510 4916 [ 0AC9E321D604BE48A0D72B69BA484BDC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    20:52:21.0744 4916 igfx - ok
    20:52:21.0775 4916 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
    20:52:21.0790 4916 iirsp - ok
    20:52:21.0837 4916 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
    20:52:21.0853 4916 IKEEXT - ok
    20:52:21.0931 4916 [ A0C2C3D4C03C4FB896CFC53873784178 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
    20:52:21.0962 4916 IntcAzAudAddService - ok
    20:52:21.0993 4916 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
    20:52:21.0993 4916 IntcDAud - ok
    20:52:22.0024 4916 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
    20:52:22.0024 4916 intelide - ok
    20:52:22.0040 4916 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    20:52:22.0040 4916 intelppm - ok
    20:52:22.0071 4916 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    20:52:22.0071 4916 IPBusEnum - ok
    20:52:22.0102 4916 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    20:52:22.0118 4916 IpFilterDriver - ok
    20:52:22.0180 4916 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    20:52:22.0196 4916 iphlpsvc - ok
    20:52:22.0243 4916 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
    20:52:22.0243 4916 IPMIDRV - ok
    20:52:22.0274 4916 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    20:52:22.0274 4916 IPNAT - ok
    20:52:22.0290 4916 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
    20:52:22.0290 4916 IRENUM - ok
    20:52:22.0321 4916 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    20:52:22.0321 4916 isapnp - ok
    20:52:22.0368 4916 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
    20:52:22.0383 4916 iScsiPrt - ok
    20:52:22.0508 4916 [ 7989686A8333CCBD12044D3D40A27B3F ] jjvop C:\Users\Owner\AppData\Roaming\clmioni1.bat
    20:52:22.0555 4916 jjvop - ok
    20:52:22.0586 4916 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
    20:52:22.0602 4916 kbdclass - ok
    20:52:22.0633 4916 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
    20:52:22.0633 4916 kbdhid - ok
    20:52:22.0664 4916 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
    20:52:22.0664 4916 KeyIso - ok
    20:52:22.0664 4916 KMService - ok
    20:52:22.0711 4916 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    20:52:22.0711 4916 KSecDD - ok
    20:52:22.0758 4916 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    20:52:22.0758 4916 KSecPkg - ok
    20:52:22.0789 4916 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    20:52:22.0789 4916 ksthunk - ok
    20:52:22.0820 4916 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
    20:52:22.0836 4916 KtmRm - ok
    20:52:22.0898 4916 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
    20:52:22.0898 4916 LanmanServer - ok
    20:52:22.0945 4916 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    20:52:22.0960 4916 LanmanWorkstation - ok
    20:52:22.0992 4916 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    20:52:22.0992 4916 lltdio - ok
    20:52:23.0007 4916 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    20:52:23.0023 4916 lltdsvc - ok
    20:52:23.0038 4916 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
    20:52:23.0038 4916 lmhosts - ok
    20:52:23.0116 4916 [ 926EBA26A8B49D1597751CED06B50862 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    20:52:23.0132 4916 LMS - ok
    20:52:23.0163 4916 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
    20:52:23.0179 4916 LSI_FC - ok
    20:52:23.0194 4916 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
    20:52:23.0194 4916 LSI_SAS - ok
    20:52:23.0210 4916 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
    20:52:23.0226 4916 LSI_SAS2 - ok
    20:52:23.0241 4916 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
    20:52:23.0257 4916 LSI_SCSI - ok
    20:52:23.0288 4916 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
    20:52:23.0288 4916 luafv - ok
    20:52:23.0319 4916 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    20:52:23.0335 4916 Mcx2Svc - ok
    20:52:23.0335 4916 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
    20:52:23.0350 4916 megasas - ok
    20:52:23.0366 4916 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
    20:52:23.0382 4916 MegaSR - ok
    20:52:23.0428 4916 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
    20:52:23.0428 4916 MEIx64 - ok
    20:52:23.0538 4916 Microsoft SharePoint Workspace Audit Service - ok
    20:52:23.0584 4916 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
    20:52:23.0584 4916 MMCSS - ok
    20:52:23.0616 4916 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
    20:52:23.0616 4916 Modem - ok
    20:52:23.0662 4916 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    20:52:23.0662 4916 monitor - ok
    20:52:23.0678 4916 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    20:52:23.0694 4916 mouclass - ok
    20:52:23.0709 4916 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    20:52:23.0709 4916 mouhid - ok
    20:52:23.0740 4916 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    20:52:23.0740 4916 mountmgr - ok
    20:52:23.0850 4916 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    20:52:23.0850 4916 MozillaMaintenance - ok
    20:52:23.0881 4916 [ 94C66EDEDCDB6A126880472F9A704D8E ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
    20:52:23.0896 4916 MpFilter - ok
    20:52:23.0928 4916 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
    20:52:23.0928 4916 mpio - ok
    20:52:23.0974 4916 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    20:52:23.0974 4916 mpsdrv - ok
    20:52:24.0068 4916 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
    20:52:24.0084 4916 MpsSvc - ok
    20:52:24.0130 4916 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    20:52:24.0130 4916 MRxDAV - ok
    20:52:24.0177 4916 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    20:52:24.0177 4916 mrxsmb - ok
    20:52:24.0208 4916 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    20:52:24.0208 4916 mrxsmb10 - ok
    20:52:24.0286 4916 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    20:52:24.0286 4916 mrxsmb20 - ok
    20:52:24.0333 4916 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
    20:52:24.0333 4916 msahci - ok
    20:52:24.0380 4916 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    20:52:24.0380 4916 msdsm - ok
    20:52:24.0411 4916 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
    20:52:24.0411 4916 MSDTC - ok
    20:52:24.0458 4916 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    20:52:24.0458 4916 Msfs - ok
    20:52:24.0489 4916 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    20:52:24.0489 4916 mshidkmdf - ok
    20:52:24.0520 4916 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    20:52:24.0536 4916 msisadrv - ok
    20:52:24.0552 4916 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    20:52:24.0552 4916 MSiSCSI - ok
    20:52:24.0567 4916 msiserver - ok
    20:52:24.0583 4916 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    20:52:24.0583 4916 MSKSSRV - ok
    20:52:24.0645 4916 [ 59FAAF2C83C8169EA20F9E335E418907 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
    20:52:24.0645 4916 MsMpSvc - ok
    20:52:24.0676 4916 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    20:52:24.0676 4916 MSPCLOCK - ok
    20:52:24.0692 4916 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    20:52:24.0692 4916 MSPQM - ok
    20:52:24.0739 4916 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    20:52:24.0754 4916 MsRPC - ok
    20:52:24.0786 4916 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
    20:52:24.0801 4916 mssmbios - ok
    20:52:24.0817 4916 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    20:52:24.0817 4916 MSTEE - ok
    20:52:24.0832 4916 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
    20:52:24.0832 4916 MTConfig - ok
    20:52:24.0864 4916 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
    20:52:24.0864 4916 Mup - ok
    20:52:24.0895 4916 [ F6EA50DBC391F04CA49427010657CCB3 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    20:52:24.0910 4916 MyWiFiDHCPDNS - ok
    20:52:24.0957 4916 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
    20:52:24.0957 4916 napagent - ok
    20:52:25.0004 4916 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    20:52:25.0004 4916 NativeWifiP - ok
    20:52:25.0066 4916 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
    20:52:25.0082 4916 NDIS - ok
    20:52:25.0113 4916 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    20:52:25.0113 4916 NdisCap - ok
    20:52:25.0160 4916 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    20:52:25.0160 4916 NdisTapi - ok
    20:52:25.0207 4916 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    20:52:25.0207 4916 Ndisuio - ok
    20:52:25.0254 4916 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    20:52:25.0254 4916 NdisWan - ok
    20:52:25.0300 4916 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    20:52:25.0300 4916 NDProxy - ok
    20:52:25.0347 4916 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
    20:52:25.0347 4916 Net Driver HPZ12 - ok
    20:52:25.0394 4916 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    20:52:25.0394 4916 NetBIOS - ok
    20:52:25.0425 4916 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    20:52:25.0441 4916 NetBT - ok
    20:52:25.0441 4916 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
    20:52:25.0456 4916 Netlogon - ok
    20:52:25.0488 4916 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
    20:52:25.0503 4916 Netman - ok
    20:52:25.0519 4916 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
    20:52:25.0534 4916 netprofm - ok
    20:52:25.0566 4916 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    20:52:25.0566 4916 NetTcpPortSharing - ok
    20:52:25.0768 4916 [ 30933BB56FB611D0252BAD488ADFB533 ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
    20:52:25.0940 4916 NETwNs64 - ok
    20:52:25.0971 4916 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
    20:52:25.0987 4916 nfrd960 - ok
    20:52:26.0018 4916 [ 91B4E0273D2F6C24EF845F2B41311289 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
    20:52:26.0018 4916 NisDrv - ok
    20:52:26.0065 4916 [ 10A43829A9E606AF3EEF25A1C1665923 ] NisSrv C:\Program Files\Microsoft Security Client\NisSrv.exe
    20:52:26.0080 4916 NisSrv - ok
    20:52:26.0127 4916 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
    20:52:26.0127 4916 NlaSvc - ok
    20:52:26.0252 4916 [ 5839A8027D6D324A7CD494051A96628C ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
    20:52:26.0299 4916 NOBU - ok
    20:52:26.0314 4916 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    20:52:26.0330 4916 Npfs - ok
    20:52:26.0346 4916 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
    20:52:26.0346 4916 nsi - ok
    20:52:26.0361 4916 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    20:52:26.0361 4916 nsiproxy - ok
    20:52:26.0439 4916 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    20:52:26.0470 4916 Ntfs - ok
    20:52:26.0502 4916 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
    20:52:26.0502 4916 Null - ok
    20:52:26.0548 4916 [ 786DB821BFD57C0551DBBE4F75384A7D ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
    20:52:26.0548 4916 nusb3hub - ok
    20:52:26.0580 4916 [ DAA8005CAF745042BB427A1ED7433354 ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
    20:52:26.0580 4916 nusb3xhc - ok
    20:52:26.0892 4916 [ 35AFE139F5CAAE2C54AC3DAF2F0DA525 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
    20:52:27.0110 4916 nvlddmkm - ok
    20:52:27.0157 4916 [ 07A4DF15E49F0875B633C39CBEFAE4EC ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
    20:52:27.0172 4916 nvpciflt - ok
    20:52:27.0250 4916 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
    20:52:27.0250 4916 nvraid - ok
    20:52:27.0282 4916 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
    20:52:27.0297 4916 nvstor - ok
    20:52:27.0344 4916 [ BBA0F7E4E545CD8C5BEA5BAB815A3A43 ] NVSvc C:\Windows\system32\nvvsvc.exe
    20:52:27.0360 4916 NVSvc - ok
    20:52:27.0469 4916 [ E4A5158EBD8DE1EA94A4AAEA13232594 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    20:52:27.0500 4916 nvUpdatusService - ok
    20:52:27.0547 4916 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    20:52:27.0547 4916 nv_agp - ok
    20:52:27.0609 4916 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    20:52:27.0609 4916 ohci1394 - ok
    20:52:27.0703 4916 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    20:52:27.0703 4916 ose64 - ok
    20:52:27.0890 4916 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    20:52:27.0999 4916 osppsvc - ok
    20:52:28.0030 4916 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    20:52:28.0046 4916 p2pimsvc - ok
    20:52:28.0062 4916 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
    20:52:28.0062 4916 p2psvc - ok
    20:52:28.0093 4916 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
    20:52:28.0093 4916 Parport - ok
    20:52:28.0140 4916 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
    20:52:28.0140 4916 partmgr - ok
    20:52:28.0186 4916 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
    20:52:28.0186 4916 PcaSvc - ok
    20:52:28.0233 4916 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
    20:52:28.0249 4916 pci - ok
    20:52:28.0264 4916 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
    20:52:28.0264 4916 pciide - ok
    20:52:28.0296 4916 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
    20:52:28.0296 4916 pcmcia - ok
    20:52:28.0327 4916 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
    20:52:28.0327 4916 pcw - ok
    20:52:28.0358 4916 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    20:52:28.0374 4916 PEAUTH - ok
    20:52:28.0467 4916 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    20:52:28.0467 4916 PerfHost - ok
    20:52:28.0561 4916 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
    20:52:28.0592 4916 pla - ok
    20:52:28.0639 4916 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    20:52:28.0639 4916 PlugPlay - ok
    20:52:28.0680 4916 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
    20:52:28.0680 4916 Pml Driver HPZ12 - ok
    20:52:28.0710 4916 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    20:52:28.0710 4916 PNRPAutoReg - ok
    20:52:28.0730 4916 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    20:52:28.0730 4916 PNRPsvc - ok
    20:52:28.0790 4916 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    20:52:28.0800 4916 PolicyAgent - ok
    20:52:28.0830 4916 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
    20:52:28.0830 4916 Power - ok
    20:52:28.0890 4916 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    20:52:28.0890 4916 PptpMiniport - ok
    20:52:28.0930 4916 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
    20:52:28.0930 4916 Processor - ok
    20:52:28.0970 4916 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
    20:52:28.0970 4916 ProfSvc - ok
    20:52:28.0980 4916 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
    20:52:28.0980 4916 ProtectedStorage - ok
    20:52:29.0040 4916 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    20:52:29.0040 4916 Psched - ok
    20:52:29.0100 4916 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
    20:52:29.0120 4916 PSI - ok
    20:52:29.0200 4916 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
    20:52:29.0230 4916 ql2300 - ok
    20:52:29.0260 4916 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
    20:52:29.0260 4916 ql40xx - ok
    20:52:29.0290 4916 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
    20:52:29.0300 4916 QWAVE - ok
    20:52:29.0320 4916 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    20:52:29.0330 4916 QWAVEdrv - ok
    20:52:29.0340 4916 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    20:52:29.0340 4916 RasAcd - ok
    20:52:29.0370 4916 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    20:52:29.0370 4916 RasAgileVpn - ok
    20:52:29.0400 4916 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
    20:52:29.0410 4916 RasAuto - ok
    20:52:29.0460 4916 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    20:52:29.0470 4916 Rasl2tp - ok
    20:52:29.0490 4916 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
    20:52:29.0500 4916 RasMan - ok
    20:52:29.0530 4916 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    20:52:29.0530 4916 RasPppoe - ok
    20:52:29.0550 4916 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    20:52:29.0550 4916 RasSstp - ok
    20:52:29.0610 4916 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    20:52:29.0620 4916 rdbss - ok
    20:52:29.0640 4916 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
    20:52:29.0640 4916 rdpbus - ok
    20:52:29.0670 4916 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    20:52:29.0670 4916 RDPCDD - ok
    20:52:29.0690 4916 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    20:52:29.0690 4916 RDPENCDD - ok
    20:52:29.0710 4916 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
    20:52:29.0710 4916 RDPREFMP - ok
    20:52:29.0760 4916 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    20:52:29.0760 4916 RDPWD - ok
    20:52:29.0830 4916 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    20:52:29.0840 4916 rdyboost - ok
    20:52:29.0950 4916 [ 9276F4D4109FC349925D28E00E533146 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    20:52:29.0970 4916 RegSrvc - ok
    20:52:29.0990 4916 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
    20:52:30.0000 4916 RemoteAccess - ok
    20:52:30.0020 4916 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    20:52:30.0030 4916 RemoteRegistry - ok
    20:52:30.0130 4916 [ F12A68ED55053940CADD59CA5E3468DD ] RichVideo C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
    20:52:30.0310 4916 RichVideo - ok
    20:52:30.0330 4916 RimUsb - ok
    20:52:30.0370 4916 [ 4AAFFFA67AC4DFA3D9985D78573887E2 ] RimVSerPort C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
    20:52:30.0370 4916 RimVSerPort - ok
    20:52:30.0400 4916 [ 388D3DD1A6457280F3BADBA9F3ACD6B1 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys
    20:52:30.0410 4916 ROOTMODEM - ok
    20:52:30.0440 4916 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    20:52:30.0440 4916 RpcEptMapper - ok
    20:52:30.0490 4916 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
    20:52:30.0500 4916 RpcLocator - ok
    20:52:30.0550 4916 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
    20:52:30.0560 4916 RpcSs - ok
    20:52:30.0580 4916 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    20:52:30.0580 4916 rspndr - ok
    20:52:30.0620 4916 [ BFE0EF0C4C15820698F50AD73AF5E35F ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
    20:52:30.0630 4916 RTL8167 - ok
    20:52:30.0710 4916 [ 62DB6CC4B0818F1B5F3441241B098F12 ] SABI C:\Windows\system32\Drivers\SABI.sys
    20:52:30.0710 4916 SABI - ok
    20:52:30.0730 4916 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
    20:52:30.0730 4916 SamSs - ok
    20:52:30.0780 4916 [ D641337B75B9A9D5AE10687AA1097755 ] Samsung UPD Service C:\Windows\System32\SUPDSvc.exe
     
  6. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    20:52:30.0790 4916 Samsung UPD Service - ok
    20:52:30.0840 4916 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    20:52:30.0840 4916 sbp2port - ok
    20:52:30.0880 4916 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
    20:52:30.0890 4916 SCardSvr - ok
    20:52:30.0930 4916 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    20:52:30.0930 4916 scfilter - ok
    20:52:31.0000 4916 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
    20:52:31.0020 4916 Schedule - ok
    20:52:31.0060 4916 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
    20:52:31.0070 4916 SCPolicySvc - ok
    20:52:31.0100 4916 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    20:52:31.0110 4916 SDRSVC - ok
    20:52:31.0160 4916 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    20:52:31.0160 4916 secdrv - ok
    20:52:31.0180 4916 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
    20:52:31.0180 4916 seclogon - ok
    20:52:31.0270 4916 [ F70A51EB03EE7046784EF62EFCE9528E ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    20:52:31.0770 4916 Secunia PSI Agent - ok
    20:52:31.0830 4916 [ AD56CEB08EEB517332355FDE9E5939C8 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
    20:52:31.0980 4916 Secunia Update Agent - ok
    20:52:32.0010 4916 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
    20:52:32.0010 4916 SENS - ok
    20:52:32.0020 4916 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
    20:52:32.0030 4916 SensrSvc - ok
    20:52:32.0050 4916 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
    20:52:32.0060 4916 Serenum - ok
    20:52:32.0080 4916 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
    20:52:32.0080 4916 Serial - ok
    20:52:32.0110 4916 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
    20:52:32.0120 4916 sermouse - ok
    20:52:32.0170 4916 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
    20:52:32.0180 4916 SessionEnv - ok
    20:52:32.0220 4916 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    20:52:32.0220 4916 sffdisk - ok
    20:52:32.0240 4916 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    20:52:32.0240 4916 sffp_mmc - ok
    20:52:32.0260 4916 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    20:52:32.0260 4916 sffp_sd - ok
    20:52:32.0290 4916 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
    20:52:32.0290 4916 sfloppy - ok
    20:52:32.0370 4916 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
    20:52:32.0380 4916 SharedAccess - ok
    20:52:32.0440 4916 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    20:52:32.0450 4916 ShellHWDetection - ok
    20:52:32.0490 4916 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
    20:52:32.0490 4916 SiSRaid2 - ok
    20:52:32.0520 4916 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
    20:52:32.0520 4916 SiSRaid4 - ok
    20:52:32.0610 4916 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    20:52:32.0610 4916 SkypeUpdate - ok
    20:52:32.0630 4916 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    20:52:32.0630 4916 Smb - ok
    20:52:32.0680 4916 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    20:52:32.0690 4916 SNMPTRAP - ok
    20:52:32.0720 4916 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
    20:52:32.0720 4916 spldr - ok
    20:52:32.0780 4916 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
    20:52:32.0790 4916 Spooler - ok
    20:52:32.0900 4916 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
    20:52:33.0000 4916 sppsvc - ok
    20:52:33.0040 4916 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
    20:52:33.0040 4916 sppuinotify - ok
    20:52:33.0130 4916 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
    20:52:33.0140 4916 srv - ok
    20:52:33.0170 4916 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    20:52:33.0180 4916 srv2 - ok
    20:52:33.0220 4916 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    20:52:33.0230 4916 srvnet - ok
    20:52:33.0270 4916 [ 8F8324ED1DE63FFC7B1A02CD2D963C72 ] ssadbus C:\Windows\system32\DRIVERS\ssadbus.sys
    20:52:33.0270 4916 ssadbus - ok
    20:52:33.0300 4916 [ 58221EFCB74167B73667F0024C661CE0 ] ssadmdfl C:\Windows\system32\DRIVERS\ssadmdfl.sys
    20:52:33.0320 4916 ssadmdfl - ok
    20:52:33.0360 4916 [ 4DA7C71BFAC5AD71255B7E4CAB980163 ] ssadmdm C:\Windows\system32\DRIVERS\ssadmdm.sys
    20:52:33.0360 4916 ssadmdm - ok
    20:52:33.0390 4916 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    20:52:33.0400 4916 SSDPSRV - ok
    20:52:33.0420 4916 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
    20:52:33.0420 4916 SstpSvc - ok
    20:52:33.0450 4916 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
    20:52:33.0460 4916 stexstor - ok
    20:52:33.0510 4916 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
    20:52:33.0510 4916 StillCam - ok
    20:52:33.0570 4916 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
    20:52:33.0580 4916 stisvc - ok
    20:52:33.0620 4916 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
    20:52:33.0620 4916 swenum - ok
    20:52:33.0650 4916 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
    20:52:33.0670 4916 swprv - ok
    20:52:33.0750 4916 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
    20:52:33.0780 4916 SysMain - ok
    20:52:33.0820 4916 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
    20:52:33.0830 4916 TabletInputService - ok
    20:52:33.0850 4916 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
    20:52:33.0860 4916 TapiSrv - ok
    20:52:33.0890 4916 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
    20:52:33.0900 4916 TBS - ok
    20:52:33.0970 4916 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    20:52:34.0010 4916 Tcpip - ok
    20:52:34.0050 4916 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    20:52:34.0070 4916 TCPIP6 - ok
    20:52:34.0150 4916 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    20:52:34.0150 4916 tcpipreg - ok
    20:52:34.0190 4916 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    20:52:34.0190 4916 TDPIPE - ok
    20:52:34.0220 4916 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    20:52:34.0230 4916 TDTCP - ok
    20:52:34.0280 4916 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    20:52:34.0290 4916 tdx - ok
    20:52:34.0330 4916 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
    20:52:34.0340 4916 TermDD - ok
    20:52:34.0400 4916 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
    20:52:34.0420 4916 TermService - ok
    20:52:34.0450 4916 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
    20:52:34.0460 4916 Themes - ok
    20:52:34.0490 4916 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
    20:52:34.0490 4916 THREADORDER - ok
    20:52:34.0520 4916 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
    20:52:34.0520 4916 TrkWks - ok
    20:52:34.0590 4916 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    20:52:34.0600 4916 TrustedInstaller - ok
    20:52:34.0640 4916 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    20:52:34.0650 4916 tssecsrv - ok
    20:52:34.0700 4916 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    20:52:34.0700 4916 TsUsbFlt - ok
    20:52:34.0750 4916 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    20:52:34.0760 4916 tunnel - ok
    20:52:34.0780 4916 [ 48743B69EA47C020A792D8649F753F44 ] TurboB C:\Windows\system32\DRIVERS\TurboB.sys
    20:52:34.0810 4916 TurboB - ok
    20:52:34.0860 4916 [ 759F59E3EA3802FF23F93DCDB6FE9171 ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe
    20:52:34.0970 4916 TurboBoost - ok
    20:52:35.0000 4916 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
    20:52:35.0000 4916 uagp35 - ok
    20:52:35.0040 4916 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    20:52:35.0050 4916 udfs - ok
    20:52:35.0090 4916 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
    20:52:35.0090 4916 UI0Detect - ok
    20:52:35.0150 4916 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    20:52:35.0150 4916 uliagpkx - ok
    20:52:35.0170 4916 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
    20:52:35.0180 4916 umbus - ok
    20:52:35.0200 4916 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
    20:52:35.0210 4916 UmPass - ok
    20:52:35.0330 4916 [ FDF92EC84FECEE834FB10A2A0A19BCDA ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    20:52:35.0420 4916 UNS - ok
    20:52:35.0460 4916 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
    20:52:35.0480 4916 upnphost - ok
    20:52:35.0510 4916 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    20:52:35.0520 4916 usbccgp - ok
    20:52:35.0540 4916 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    20:52:35.0540 4916 usbcir - ok
    20:52:35.0590 4916 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
    20:52:35.0600 4916 usbehci - ok
    20:52:35.0630 4916 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
    20:52:35.0640 4916 usbhub - ok
    20:52:35.0680 4916 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    20:52:35.0680 4916 usbohci - ok
    20:52:35.0730 4916 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
    20:52:35.0730 4916 usbprint - ok
    20:52:35.0790 4916 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
    20:52:35.0800 4916 usbscan - ok
    20:52:35.0830 4916 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    20:52:35.0840 4916 USBSTOR - ok
    20:52:35.0870 4916 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
    20:52:35.0880 4916 usbuhci - ok
    20:52:35.0930 4916 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
    20:52:35.0930 4916 usbvideo - ok
    20:52:36.0030 4916 [ 70D05EE263568A742D14E1876DF80532 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
    20:52:36.0030 4916 usb_rndisx - ok
    20:52:36.0060 4916 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
    20:52:36.0060 4916 UxSms - ok
    20:52:36.0080 4916 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
    20:52:36.0080 4916 VaultSvc - ok
    20:52:36.0140 4916 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    20:52:36.0140 4916 vdrvroot - ok
    20:52:36.0190 4916 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
    20:52:36.0200 4916 vds - ok
    20:52:36.0220 4916 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    20:52:36.0230 4916 vga - ok
    20:52:36.0250 4916 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
    20:52:36.0260 4916 VgaSave - ok
    20:52:36.0300 4916 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
    20:52:36.0310 4916 vhdmp - ok
    20:52:36.0350 4916 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
    20:52:36.0350 4916 viaide - ok
    20:52:36.0380 4916 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    20:52:36.0390 4916 volmgr - ok
    20:52:36.0510 4916 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    20:52:36.0520 4916 volmgrx - ok
    20:52:36.0590 4916 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
    20:52:36.0590 4916 volsnap - ok
    20:52:36.0640 4916 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
    20:52:36.0640 4916 vsmraid - ok
    20:52:36.0730 4916 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
    20:52:36.0770 4916 VSS - ok
    20:52:36.0810 4916 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
    20:52:36.0810 4916 vwifibus - ok
    20:52:36.0840 4916 [ 6A3D66263414FF0D6FA754C646612F3F ] VWiFiFlt C:\Windows\system32\DRIVERS\vwififlt.sys
    20:52:36.0850 4916 VWiFiFlt - ok
    20:52:36.0870 4916 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
    20:52:36.0880 4916 vwifimp - ok
    20:52:36.0920 4916 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
    20:52:36.0930 4916 W32Time - ok
    20:52:36.0950 4916 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
    20:52:36.0950 4916 WacomPen - ok
    20:52:37.0000 4916 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
    20:52:37.0000 4916 WANARP - ok
    20:52:37.0010 4916 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    20:52:37.0020 4916 Wanarpv6 - ok
    20:52:37.0110 4916 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
    20:52:37.0140 4916 WatAdminSvc - ok
    20:52:37.0220 4916 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
    20:52:37.0260 4916 wbengine - ok
    20:52:37.0290 4916 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    20:52:37.0290 4916 WbioSrvc - ok
    20:52:37.0340 4916 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
    20:52:37.0350 4916 wcncsvc - ok
    20:52:37.0390 4916 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    20:52:37.0390 4916 WcsPlugInService - ok
    20:52:37.0410 4916 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
    20:52:37.0420 4916 Wd - ok
    20:52:37.0440 4916 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    20:52:37.0450 4916 Wdf01000 - ok
    20:52:37.0470 4916 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
    20:52:37.0480 4916 WdiServiceHost - ok
    20:52:37.0500 4916 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
    20:52:37.0500 4916 WdiSystemHost - ok
    20:52:37.0540 4916 [ 94DC2BF6CBAAA95E369C3756D3115A76 ] wdkmd C:\Windows\system32\DRIVERS\WDKMD.sys
    20:52:37.0540 4916 wdkmd - ok
    20:52:37.0590 4916 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
    20:52:37.0590 4916 WebClient - ok
    20:52:37.0620 4916 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
    20:52:37.0630 4916 Wecsvc - ok
    20:52:37.0650 4916 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    20:52:37.0650 4916 wercplsupport - ok
    20:52:37.0670 4916 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
    20:52:37.0670 4916 WerSvc - ok
    20:52:37.0700 4916 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
    20:52:37.0700 4916 WfpLwf - ok
    20:52:37.0770 4916 [ F3C522691316A24328A7B58B0A86028D ] WiMAXAppSrv C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
    20:52:38.0120 4916 WiMAXAppSrv - ok
    20:52:38.0140 4916 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    20:52:38.0140 4916 WIMMount - ok
    20:52:38.0180 4916 WinDefend - ok
    20:52:38.0190 4916 WinHttpAutoProxySvc - ok
    20:52:38.0260 4916 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    20:52:38.0260 4916 Winmgmt - ok
    20:52:38.0350 4916 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
    20:52:38.0390 4916 WinRM - ok
    20:52:38.0500 4916 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
    20:52:38.0520 4916 WinUsb - ok
    20:52:38.0580 4916 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
    20:52:38.0600 4916 Wlansvc - ok
    20:52:38.0760 4916 [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    20:52:38.0800 4916 wlidsvc - ok
    20:52:38.0830 4916 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    20:52:38.0830 4916 WmiAcpi - ok
    20:52:38.0860 4916 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    20:52:38.0860 4916 wmiApSrv - ok
    20:52:38.0890 4916 WMPNetworkSvc - ok
    20:52:38.0920 4916 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
    20:52:38.0920 4916 WPCSvc - ok
    20:52:38.0970 4916 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    20:52:38.0970 4916 WPDBusEnum - ok
    20:52:39.0000 4916 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    20:52:39.0000 4916 ws2ifsl - ok
    20:52:39.0040 4916 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
    20:52:39.0040 4916 wscsvc - ok
    20:52:39.0050 4916 WSearch - ok
    20:52:39.0190 4916 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    20:52:39.0220 4916 wuauserv - ok
    20:52:39.0260 4916 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    20:52:39.0270 4916 WudfPf - ok
    20:52:39.0300 4916 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    20:52:39.0310 4916 WUDFRd - ok
    20:52:39.0350 4916 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    20:52:39.0360 4916 wudfsvc - ok
    20:52:39.0390 4916 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
    20:52:39.0400 4916 WwanSvc - ok
    20:52:39.0440 4916 ================ Scan global ===============================
    20:52:39.0490 4916 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
    20:52:39.0520 4916 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
    20:52:39.0540 4916 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
    20:52:39.0570 4916 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
    20:52:39.0620 4916 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
    20:52:39.0630 4916 [Global] - ok
    20:52:39.0630 4916 ================ Scan MBR ==================================
    20:52:39.0640 4916 [ 2E5DEBB2116B3417023E0D6562D7ED07 ] \Device\Harddisk0\DR0
    20:52:40.0030 4916 \Device\Harddisk0\DR0 - ok
    20:52:40.0030 4916 ================ Scan VBR ==================================
    20:52:40.0030 4916 [ A483171DE81038D1E1C33057DB820660 ] \Device\Harddisk0\DR0\Partition1
    20:52:40.0040 4916 \Device\Harddisk0\DR0\Partition1 - ok
    20:52:40.0040 4916 [ 0A881E2FF187E7B678BF204EAC000D06 ] \Device\Harddisk0\DR0\Partition2
    20:52:40.0050 4916 \Device\Harddisk0\DR0\Partition2 - ok
    20:52:40.0070 4916 [ DE3DD32D182E74A1C4F39C7887F217E6 ] \Device\Harddisk0\DR0\Partition3
    20:52:40.0070 4916 \Device\Harddisk0\DR0\Partition3 - ok
    20:52:40.0080 4916 ============================================================
    20:52:40.0080 4916 Scan finished
    20:52:40.0080 4916 ============================================================
    20:52:40.0090 11356 Detected object count: 0
    20:52:40.0100 11356 Actual detected object count: 0
    20:58:59.0417 7980 Deinitialize success
     
  7. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    RogueKiller V8.0.2 [08/31/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com
    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Owner [Admin rights]
    Mode : Scan -- Date : 09/10/2012 21:04:25
    ¤¤¤ Bad processes : 2 ¤¤¤
    [SUSP PATH][DLL] rundll32.exe -- C:\Windows\SysWOW64\rundll32.exe : -> KILLED [TermProc]
    [SUSP PATH][DLL] rundll32.exe -- C:\Windows\SysWOW64\rundll32.exe : -> KILLED [TermProc]
    ¤¤¤ Registry Entries : 17 ¤¤¤
    [RUN][BLACKLIST DLL] HKCU\[...]\Run : nerlex (rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
    [RUN][BLACKLIST DLL] HKCU\[...]\Run : Deployment (rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW) -> FOUND
    [RUN][BLACKLIST DLL] HKLM\[...]\Run : nerlex ("C:\Windows\System32\rundll32.exe" "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
    [RUN][BLACKLIST DLL] HKLM\[...]\Run : xtlbj (rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject) -> FOUND
    [RUN][BLACKLIST DLL] HKUS\S-1-5-21-2503403413-1387520261-2031820482-1001[...]\Run : nerlex (rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track) -> FOUND
    [RUN][BLACKLIST DLL] HKUS\S-1-5-21-2503403413-1387520261-2031820482-1001[...]\Run : Deployment (rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW) -> FOUND
    [RUN][SUSP PATH] HKLM\[...]\Wow6432Node\Run : mvcf2zo (C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe) -> FOUND
    [STARTUP][SUSP PATH] Best Buy pc app.lnk @Default : C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe -> FOUND
    [STARTUP][SUSP PATH] Best Buy pc app.lnk @Default User : C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowUser (0) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\n.) -> FOUND
    ¤¤¤ Particular Files / Folders: ¤¤¤
    [ZeroAccess][FOLDER] U : C:\$recycle.bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\U --> FOUND
    [ZeroAccess][FOLDER] L : C:\$recycle.bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62\L --> FOUND
    ¤¤¤ Driver : [NOT LOADED] ¤¤¤
    ¤¤¤ Infection : ZeroAccess ¤¤¤
    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts
    127.0.0.1 localhost

    ¤¤¤ MBR Check: ¤¤¤
    +++++ PhysicalDrive0: Hitachi HTS547575A9E384 +++++
    --- User ---
    [MBR] bcc0df5a8459b470502c749dd4091510
    [BSP] 96066b6721740e60f329fee07cf89bf2 : KIWI Image system MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 278528 Mo
    2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 570632192 | Size: 416094 Mo
    3 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1422792704 | Size: 20680 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!
    Finished : << RKreport[1].txt >>
    RKreport[1].txt
     
  8. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-09-10 21:19:35
    -----------------------------
    21:19:35.498 OS Version: Windows x64 6.1.7601 Service Pack 1
    21:19:35.498 Number of processors: 8 586 0x2A07
    21:19:35.508 ComputerName: OWNER-PC UserName: Owner
    21:19:37.548 Initialize success
    21:20:21.371 AVAST engine defs: 12091001
    21:20:45.052 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    21:20:45.068 Disk 0 Vendor: Hitachi_ JE4O Size: 715404MB BusType: 3
    21:20:45.099 Disk 0 MBR read successfully
    21:20:45.115 Disk 0 MBR scan
    21:20:45.130 Disk 0 unknown MBR code
    21:20:45.146 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
    21:20:45.239 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 278528 MB offset 206848
    21:20:45.286 Disk 0 Partition - 00 0F Extended LBA 416094 MB offset 570632192
    21:20:45.333 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 20680 MB offset 1422792704
    21:20:45.427 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 416093 MB offset 570634240
    21:20:45.536 Disk 0 scanning C:\Windows\system32\drivers
    21:21:06.752 Service scanning
    21:22:05.564 Modules scanning
    21:22:06.094 Disk 0 trace - called modules:
    21:22:06.125 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    21:22:06.141 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007e10790]
    21:22:06.141 3 CLASSPNP.SYS[fffff88001b6943f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8005fb7050]
    21:22:07.373 AVAST engine scan C:\Windows
    21:22:14.518 AVAST engine scan C:\Windows\system32
    21:27:06.071 AVAST engine scan C:\Windows\system32\drivers
    21:27:29.128 AVAST engine scan C:\Users\Owner
    21:27:49.569 File: C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll **INFECTED** Win32:Tracur-IL [Trj]
    21:43:23.627 File: C:\Users\Owner\Desktop\RK_Quarantine\faplygb.dll.vir **INFECTED** Win32:Tracur-IL [Trj]
    22:00:58.792 AVAST engine scan C:\ProgramData
    22:01:03.129 File: C:\ProgramData\2jFf5J64.exe **INFECTED** Win32:Ransom-QF [Trj]
    22:01:05.360 File: C:\ProgramData\2jFf5J64.exe_ **INFECTED** Win32:Ransom-QF [Trj]
    22:06:14.711 Scan finished successfully
    22:09:16.869 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
    22:09:16.947 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
     
  9. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:

      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

    Next...

    Re-run FRST again.
    Type the following in the edit box after "Search:".

    services.exe

    Click Search button and post the log (Search.txt) it makes in your reply.

    I'll expect two logs:
    - FRST.txt
    - Search.txt
     
  10. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Scan result of Farbar Recovery Scan Tool (x64) Version: 08-09-2012
    Ran by SYSTEM at 10-09-2012 22:52:56
    Running from H:\
    Windows 7 Home Premium (X64) OS Language: English(US)
    The current controlset is ControlSet002
    ==================== Registry (Whitelisted) ===================
    HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11660904 2010-11-30] (Realtek Semiconductor)
    HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2010-11-01] (Intel(R) Corporation)
    HKLM\...\Run: [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe [2588968 2010-11-12] (ELAN Microelectronics Corp.)
    HKLM\...\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" [4526 2010-10-08] ()
    HKLM\...\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices [112512 2010-03-13] (Microsoft Corporation)
    HKLM\...\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey [1271168 2012-03-26] (Microsoft Corporation)
    HKLM\...\Run: [nerlex] "C:\Windows\System32\rundll32.exe" "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track [416768 2012-09-07] ()
    HKLM\...\Run: [xtlbj] rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject [x]
    HKLM-x32\...\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun [618496 2010-06-07] ()
    HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-09] (Hewlett-Packard)
    HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe [x]
    HKU\Owner\...\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background [306688 2012-03-25] (FileHippo.com)
    HKU\Owner\...\Run: [nerlex] rundll32.exe "C:\Users\Owner\AppData\Roaming\nerlex.dll",GC_Track [416768 2012-09-07] ()
    HKU\Owner\...\Run: [Deployment] rundll32.exe "C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll",DllRegisterServerW [339968 2012-09-08] (Sony Corporation)
    Tcpip\Parameters: [DhcpNameServer] 167.206.245.129 167.206.245.130 192.168.1.1
    AppInit_DLLs: C:\Windows\System32\nvinitx.dll
    Startup: C:\Users\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
    ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
    Startup: C:\Users\Default\Start Menu\Programs\Startup\Best Buy pc app.lnk
    ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
    Startup: C:\Users\Default User\Start Menu\Programs\Startup\Best Buy pc app.lnk
    ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
    ==================== Services ====================
    2 CLKMSVC10_38F51D56; "C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe" /svc [246256 2010-08-24] (CyberLink)
    2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [542040 2012-03-26] ()
    3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [77520 2012-03-26] ()
    2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [329544 2012-03-26] ()
    2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2003-04-18] ()
    2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [12600 2012-03-26] (Microsoft Corporation)
    3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-01] ()
    3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [291696 2012-03-26] (Microsoft Corporation)
    2 NOBU; "C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE [2804568 2010-05-31] (Symantec Corporation)
    2 RichVideo; "C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe" [244904 2009-11-30] ()
    2 Secunia PSI Agent; "C:\Program Files (x86)\Secunia\PSI\PSIA.exe" --start-service [1326176 2012-06-26] (Secunia)
    2 Secunia Update Agent; "C:\Program Files (x86)\Secunia\PSI\sua.exe" --start-service [681056 2012-06-26] (Secunia)
    ==================== Drivers =================================
    2 jjvop; C:\Users\Owner\AppData\Roaming\clmioni1.bat [87 2012-09-08] ()
    3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [x]
    ==================== NetSvcs (Whitelisted) =================

    ==================== One Month Created Files and Folders ======================
    2012-09-10 18:09 - 2012-09-10 18:09 - 00002503 ____A C:\Users\Owner\Desktop\aswMBR.txt
    2012-09-10 18:09 - 2012-09-10 18:09 - 00000512 ____A C:\Users\Owner\Desktop\MBR.dat
    2012-09-10 17:19 - 2012-09-10 17:19 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\aswMBR.exe
    2012-09-10 17:04 - 2012-09-10 17:04 - 00003673 ____A C:\Users\Owner\Desktop\RKreport[1].txt
    2012-09-10 16:59 - 2012-09-10 17:04 - 00000000 ____D C:\Users\Owner\Desktop\RK_Quarantine
    2012-09-10 16:59 - 2012-09-10 16:59 - 01378816 ____A C:\Users\Owner\Desktop\RogueKiller.exe
    2012-09-10 16:50 - 2012-09-10 16:50 - 02193184 ____A C:\Users\Owner\Desktop\tdsskiller.zip
    2012-09-10 16:50 - 2012-08-24 09:28 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
    2012-09-10 16:50 - 2010-12-31 21:14 - 00002254 ___RA C:\Users\Owner\Desktop\eula.txt
    2012-09-10 12:12 - 2012-09-10 12:12 - 00000016 ____A C:\Users\Owner\AppData\Roaming\lyjsb
    2012-09-10 04:49 - 2012-09-10 04:49 - 00029832 ____A C:\Users\Owner\Desktop\DDS.txt
    2012-09-10 04:49 - 2012-09-10 04:49 - 00007535 ____A C:\Users\Owner\Desktop\Attach.txt
    2012-09-10 04:45 - 2012-09-10 04:45 - 00000000 ____A C:\Users\Owner\Desktop\gmer.log
    2012-09-08 13:51 - 2012-09-08 13:51 - 00000087 ____H C:\Users\Owner\AppData\Roaming\clmioni1.bat
    2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe_
    2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe_.b
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe.b
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000000 ____A C:\Users\All Users\1VjM2R.dat
    2012-09-07 18:21 - 2012-09-10 16:56 - 00006532 ____A C:\Users\Owner\AppData\Local\chromeupdate.crx
    2012-09-07 18:21 - 2012-09-07 18:21 - 00416768 ____A C:\Users\Owner\AppData\Roaming\nerlex.dll
    2012-09-07 18:21 - 2012-09-07 18:21 - 00000000 ____D C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
    2012-09-07 18:20 - 2012-09-07 18:20 - 00090176 ____A C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00086080 ____A C:\Users\Owner\AppData\Roaming\aftr4sb.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00060992 ____A C:\Users\Owner\AppData\Roaming\slr8k5s.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00000090 ____H C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
    2012-09-06 12:16 - 2012-09-06 12:16 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-09-06 12:16 - 2012-09-06 12:16 - 00916456 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-09-06 12:16 - 2012-09-06 12:16 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
    2012-09-06 12:16 - 2012-09-06 12:16 - 00000000 ____D C:\Program Files\Java
    2012-09-04 13:59 - 2012-09-04 14:32 - 00000000 ____D C:\Users\Owner\AppData\Roaming\pdfforge
    2012-09-04 13:28 - 2011-06-01 21:47 - 00177640 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdm.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00157672 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadbus.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00016872 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadmdfl.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00013800 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadwhnt.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00013800 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadwh.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00013288 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadcmnt.sys
    2012-09-04 13:28 - 2011-06-01 21:47 - 00013288 ____A (MCCI Corporation) C:\Windows\System32\Drivers\ssadcm.sys
    2012-08-29 06:00 - 2012-08-29 06:00 - 00060864 ____A C:\Users\Owner\g2mdlhlpx.exe
    2012-08-24 03:46 - 2012-08-24 03:46 - 00265208 ____A C:\Windows\msxml4-KB2721691-enu.LOG
    2012-08-24 03:44 - 2012-05-04 03:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
    2012-08-24 03:44 - 2012-05-04 01:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
    2012-08-23 17:39 - 2012-08-23 17:39 - 00000000 ____D C:\Program Files\Windows Live
    2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ___RD C:\Users\Owner\SkyDrive
    2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ____D C:\Users\All Users\Microsoft SkyDrive
    2012-08-23 17:38 - 2012-08-23 17:38 - 00000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
    2012-08-23 17:37 - 2012-08-23 17:37 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
    2012-08-23 17:35 - 2012-08-23 17:35 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
    2012-08-23 17:06 - 2012-06-28 20:55 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-08-23 17:06 - 2012-06-28 20:09 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-08-23 17:06 - 2012-06-28 19:56 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-08-23 17:06 - 2012-06-28 19:49 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-08-23 17:06 - 2012-06-28 19:49 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-08-23 17:06 - 2012-06-28 19:48 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-08-23 17:06 - 2012-06-28 19:47 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-08-23 17:06 - 2012-06-28 19:45 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-08-23 17:06 - 2012-06-28 19:44 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-08-23 17:06 - 2012-06-28 19:43 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-08-23 17:06 - 2012-06-28 19:42 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-08-23 17:06 - 2012-06-28 19:40 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-08-23 17:06 - 2012-06-28 19:39 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-08-23 17:06 - 2012-06-28 19:35 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-08-23 17:06 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-08-23 17:06 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-08-23 17:06 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-08-23 17:06 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-08-23 17:06 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-08-23 17:06 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-08-23 17:06 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-08-23 17:06 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-08-23 17:06 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-08-23 17:06 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-08-23 17:06 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-08-23 17:06 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-08-23 17:06 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-08-23 17:06 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-08-23 17:04 - 2012-08-23 17:04 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2012-08-23 17:01 - 2012-07-04 14:16 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-08-23 17:01 - 2012-07-04 14:13 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
    2012-08-23 17:01 - 2012-07-04 14:13 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
    2012-08-23 17:01 - 2012-07-04 13:16 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2012-08-23 17:01 - 2012-07-04 13:14 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2012-08-23 17:01 - 2012-05-05 00:36 - 00503808 ____A (Microsoft Corporation) C:\Windows\System32\srcore.dll
    2012-08-23 17:01 - 2012-05-04 23:46 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2012-08-23 17:01 - 2012-02-10 22:43 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
    2012-08-23 17:01 - 2012-02-10 22:36 - 00559104 ____A (Microsoft Corporation) C:\Windows\System32\spoolsv.exe
    2012-08-23 17:01 - 2012-02-10 22:36 - 00067072 ____A (Microsoft Corporation) C:\Windows\splwow64.exe
    2012-08-23 17:01 - 2012-02-10 21:43 - 00492032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
    2012-08-23 17:00 - 2012-07-18 10:15 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-08-23 17:00 - 2012-05-13 21:26 - 00956928 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll
    2012-08-23 16:57 - 2012-08-23 16:57 - 00000000 ____D C:\Users\Owner\AppData\Local\Secunia PSI
    2012-08-23 16:57 - 2012-08-23 16:57 - 00000000 ____D C:\Program Files (x86)\Secunia
    2012-08-23 16:56 - 2012-08-23 16:57 - 03277520 ____A (Secunia) C:\Users\Owner\Downloads\PSISetup.exe
    2012-08-23 16:53 - 2012-08-23 16:53 - 00001973 ____A C:\Users\Owner\Desktop\Update Checker.lnk
    2012-08-23 16:53 - 2012-08-23 16:53 - 00000000 ____D C:\Program Files (x86)\FileHippo.com
    2012-08-23 16:45 - 2012-08-23 16:45 - 00448512 ____A (OldTimer Tools) C:\Users\Owner\Desktop\TFC.exe
    2012-08-23 16:39 - 2012-08-23 16:39 - 00000000 ____D C:\Program Files\WOT
    2012-08-23 16:39 - 2012-08-23 16:39 - 00000000 ____D C:\Program Files (x86)\WOT
    2012-08-23 13:28 - 2012-08-23 13:28 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-08-23 13:28 - 2012-08-23 13:28 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2012-08-23 13:27 - 2012-08-23 13:27 - 00000000 ____D C:\Users\All Users\McAfee
    2012-08-23 13:24 - 2012-08-23 13:24 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
    2012-08-23 08:01 - 2012-08-23 08:01 - 00000000 ____D C:\Program Files (x86)\ESET
    2012-08-22 20:50 - 2012-08-23 16:44 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-22 20:50 - 2012-08-23 16:44 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-08-22 20:50 - 2012-07-03 09:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-08-22 11:02 - 2012-08-22 11:38 - 00000000 ____D C:\Windows\erdnt
    2012-08-22 06:58 - 2012-08-22 06:58 - 00000000 ____D C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
    2012-08-16 11:45 - 2012-08-16 11:45 - 00000000 ____D C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
    2012-08-16 11:45 - 2012-08-16 11:45 - 00000000 ____D C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
    2012-08-16 11:41 - 2012-08-16 11:41 - 00000000 ____D C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
    2012-08-16 11:41 - 2012-08-16 11:41 - 00000000 ____D C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
    2012-08-16 11:37 - 2012-08-16 11:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
    2012-08-16 11:37 - 2012-08-16 11:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
    2012-08-16 11:32 - 2012-08-16 11:32 - 00000000 ____D C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
    2012-08-16 11:32 - 2012-08-16 11:32 - 00000000 ____D C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
    2012-08-16 11:28 - 2012-08-16 11:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
    2012-08-16 11:20 - 2012-08-16 11:21 - 00000000 ____D C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
    2012-08-16 11:20 - 2012-08-16 11:20 - 00000000 ____D C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
    2012-08-15 09:51 - 2012-08-15 09:51 - 00000000 ____D C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
    2012-08-15 09:51 - 2012-08-15 09:51 - 00000000 ____D C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
    2012-08-14 07:03 - 2012-08-14 07:03 - 00000000 ____D C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
    2012-08-14 07:03 - 2012-08-14 07:03 - 00000000 ____D C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
    2012-08-14 06:46 - 2012-08-14 06:46 - 00000000 ____D C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
    2012-08-14 06:42 - 2012-08-14 06:42 - 00000000 ____D C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
    2012-08-14 06:42 - 2012-08-14 06:42 - 00000000 ____D C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
    2012-08-14 06:30 - 2012-08-14 06:30 - 00000000 ____D C:\Program Files\Microsoft Security Client
    2012-08-14 06:30 - 2012-08-14 06:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client
    2012-08-14 03:23 - 2012-08-15 05:32 - 00000000 ___AD C:\Kaspersky Rescue Disk 10.0
    2012-08-13 13:37 - 2012-08-13 13:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
    2012-08-13 13:36 - 2012-08-13 13:37 - 00000000 ____D C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
    2012-08-13 10:41 - 2012-09-08 17:56 - 00000000 ____D C:\Users\Owner\Documents\Anti-virus
    2012-08-13 10:28 - 2012-08-13 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
    2012-08-13 10:28 - 2012-08-13 10:28 - 00000000 ____D C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
    2012-08-13 06:40 - 2012-08-13 06:40 - 00000000 ____D C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
    2012-08-13 06:39 - 2012-08-13 06:40 - 00000000 ____D C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
    2012-08-13 02:35 - 2012-08-13 02:35 - 00000000 ____D C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
    2012-08-13 02:33 - 2012-08-13 02:35 - 00000000 ____D C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
    2012-08-12 02:38 - 2012-08-12 02:38 - 00000000 ____D C:\Users\Owner\AppData\Local\{E727C9E2-E3DE-49F2-9DC0-AF9EC23EB817}
    2012-08-11 19:26 - 2012-08-11 19:26 - 00000000 ____D C:\Users\Owner\AppData\Local\{D458277E-8667-4B04-9785-D180139CFE5C}

    ==================== 3 Months Modified Files ================================
    2012-09-10 18:47 - 2010-12-22 18:45 - 01293465 ____A C:\Windows\WindowsUpdate.log
    2012-09-10 18:40 - 2009-07-13 21:13 - 00729880 ____A C:\Windows\System32\PerfStringBackup.INI
    2012-09-10 18:20 - 2012-04-01 13:32 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
    2012-09-10 18:09 - 2012-09-10 18:09 - 00002503 ____A C:\Users\Owner\Desktop\aswMBR.txt
    2012-09-10 18:09 - 2012-09-10 18:09 - 00000512 ____A C:\Users\Owner\Desktop\MBR.dat
    2012-09-10 18:01 - 2012-04-02 04:59 - 00000908 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
    2012-09-10 17:52 - 2011-08-18 11:07 - 00000896 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2012-09-10 17:19 - 2012-09-10 17:19 - 04731392 ____A (AVAST Software) C:\Users\Owner\Desktop\aswMBR.exe
    2012-09-10 17:04 - 2012-09-10 17:04 - 00003673 ____A C:\Users\Owner\Desktop\RKreport[1].txt
    2012-09-10 16:59 - 2012-09-10 16:59 - 01378816 ____A C:\Users\Owner\Desktop\RogueKiller.exe
    2012-09-10 16:56 - 2012-09-07 18:21 - 00006532 ____A C:\Users\Owner\AppData\Local\chromeupdate.crx
    2012-09-10 16:50 - 2012-09-10 16:50 - 02193184 ____A C:\Users\Owner\Desktop\tdsskiller.zip
    2012-09-10 12:12 - 2012-09-10 12:12 - 00000016 ____A C:\Users\Owner\AppData\Roaming\lyjsb
    2012-09-10 08:52 - 2011-08-18 11:07 - 00000892 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2012-09-10 04:49 - 2012-09-10 04:49 - 00029832 ____A C:\Users\Owner\Desktop\DDS.txt
    2012-09-10 04:49 - 2012-09-10 04:49 - 00007535 ____A C:\Users\Owner\Desktop\Attach.txt
    2012-09-10 04:45 - 2012-09-10 04:45 - 00000000 ____A C:\Users\Owner\Desktop\gmer.log
    2012-09-10 03:48 - 2012-04-02 04:59 - 00000856 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
    2012-09-08 18:07 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2012-09-08 18:07 - 2009-07-13 20:45 - 00014144 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2012-09-08 18:00 - 2010-12-22 01:56 - 00000050 ____A C:\Windows\System32\SupplicantTest.log
    2012-09-08 17:59 - 2010-12-22 03:08 - 00428372 ____A C:\Windows\PFRO.log
    2012-09-08 17:59 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
    2012-09-08 17:59 - 2009-07-13 20:51 - 00134015 ____A C:\Windows\setupact.log
    2012-09-08 13:51 - 2012-09-08 13:51 - 00000087 ____H C:\Users\Owner\AppData\Roaming\clmioni1.bat
    2012-09-08 13:51 - 2009-07-13 15:19 - 210051234 ____A (Immediately Display Mobile Erasing llc) C:\Users\Owner\AppData\Roaming\jjvop.exe
    2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe_
    2012-09-08 13:45 - 2012-09-08 13:45 - 00110592 ____A C:\Users\All Users\2jFf5J64.exe
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe_.b
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000001 ____A C:\Users\All Users\2jFf5J64.exe.b
    2012-09-08 13:45 - 2012-09-08 13:45 - 00000000 ____A C:\Users\All Users\1VjM2R.dat
    2012-09-07 18:21 - 2012-09-07 18:21 - 00416768 ____A C:\Users\Owner\AppData\Roaming\nerlex.dll
    2012-09-07 18:20 - 2012-09-07 18:20 - 00090176 ____A C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00086080 ____A C:\Users\Owner\AppData\Roaming\aftr4sb.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00060992 ____A C:\Users\Owner\AppData\Roaming\slr8k5s.dat
    2012-09-07 18:20 - 2012-09-07 18:20 - 00000090 ____H C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
    2012-09-06 12:16 - 2012-09-06 12:16 - 01034216 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll
    2012-09-06 12:16 - 2012-09-06 12:16 - 00916456 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll
    2012-09-06 12:16 - 2012-09-06 12:16 - 00289768 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00189416 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00188904 ____A (Oracle Corporation) C:\Windows\System32\java.exe
    2012-09-06 12:16 - 2012-09-06 12:16 - 00108008 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll
    2012-09-01 12:02 - 2012-04-02 04:59 - 00002453 ____A C:\Users\Owner\Desktop\Google Chrome.lnk
    2012-08-31 10:52 - 2012-04-01 13:32 - 00696520 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-08-31 10:52 - 2011-08-19 10:11 - 00073416 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-08-29 06:00 - 2012-08-29 06:00 - 00060864 ____A C:\Users\Owner\g2mdlhlpx.exe
    2012-08-29 02:06 - 2012-01-22 07:18 - 00000600 ____A C:\Users\Owner\AppData\Local\PUTTY.RND
    2012-08-26 02:34 - 2011-11-19 11:09 - 00011264 ____A C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    2012-08-24 09:28 - 2012-09-10 16:50 - 02211928 ____A (Kaspersky Lab ZAO) C:\Users\Owner\Desktop\TDSSKiller.exe
    2012-08-24 03:46 - 2012-08-24 03:46 - 00265208 ____A C:\Windows\msxml4-KB2721691-enu.LOG
    2012-08-23 17:37 - 2012-08-23 17:37 - 00002212 ____A C:\Users\Public\Desktop\Google Earth.lnk
    2012-08-23 17:14 - 2009-07-13 20:45 - 05043664 ____A C:\Windows\System32\FNTCACHE.DAT
    2012-08-23 17:04 - 2012-08-23 17:04 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
    2012-08-23 17:02 - 2012-02-10 17:49 - 62134624 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
    2012-08-23 16:57 - 2012-08-23 16:56 - 03277520 ____A (Secunia) C:\Users\Owner\Downloads\PSISetup.exe
    2012-08-23 16:53 - 2012-08-23 16:53 - 00001973 ____A C:\Users\Owner\Desktop\Update Checker.lnk
    2012-08-23 16:45 - 2012-08-23 16:45 - 00448512 ____A (OldTimer Tools) C:\Users\Owner\Desktop\TFC.exe
    2012-08-23 16:44 - 2012-08-22 20:50 - 00001113 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2012-08-23 13:28 - 2012-08-23 13:28 - 00821736 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2012-08-23 13:28 - 2012-08-23 13:28 - 00095208 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
    2012-08-23 13:28 - 2012-03-19 07:40 - 00246760 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
    2012-08-23 13:28 - 2012-03-19 07:40 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
    2012-08-23 13:28 - 2012-03-19 07:40 - 00174056 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
    2012-08-23 13:28 - 2011-09-27 10:27 - 00746984 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2012-08-23 13:24 - 2012-08-23 13:24 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader X.lnk
    2012-08-22 11:32 - 2009-07-13 18:34 - 00000215 ____A C:\Windows\system.ini
    2012-08-22 10:57 - 2012-01-16 19:35 - 00002086 ____A C:\Windows\epplauncher.mif
    2012-08-14 06:30 - 2012-01-16 19:31 - 00743856 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
    2012-08-10 13:41 - 2012-08-10 13:41 - 00000218 ____A C:\Windows\Tasks\SidebarExecute.job
    2012-08-10 13:20 - 2012-08-10 13:20 - 00000048 ____A C:\Users\Owner\AppData\Local\OWNER-PC.cfg
    2012-08-08 21:42 - 2012-01-18 06:24 - 00007596 ____A C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
    2012-08-01 12:25 - 2012-08-01 12:25 - 00000000 ___AH C:\Windows\System32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    2012-07-27 23:09 - 2012-07-27 23:09 - 00057792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sirenacm.dll
    2012-07-26 15:08 - 2012-07-26 15:08 - 00862664 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110.dll
    2012-07-26 15:08 - 2012-07-26 15:08 - 00534480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110.dll
    2012-07-26 15:08 - 2012-07-26 15:08 - 00251864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib110.dll
    2012-07-26 15:08 - 2012-07-26 15:08 - 00153536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\atl110.dll
    2012-07-26 15:08 - 2012-07-26 15:08 - 00115656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vcomp110.dll
    2012-07-26 11:22 - 2012-07-26 11:22 - 00828872 ____A (Microsoft Corporation) C:\Windows\System32\msvcr110.dll
    2012-07-26 11:22 - 2012-07-26 11:22 - 00661448 ____A (Microsoft Corporation) C:\Windows\System32\msvcp110.dll
    2012-07-26 11:22 - 2012-07-26 11:22 - 00354264 ____A (Microsoft Corporation) C:\Windows\System32\vccorlib110.dll
    2012-07-26 11:22 - 2012-07-26 11:22 - 00177096 ____A (Microsoft Corporation) C:\Windows\System32\atl110.dll
    2012-07-26 11:22 - 2012-07-26 11:22 - 00124360 ____A (Microsoft Corporation) C:\Windows\System32\vcomp110.dll
    2012-07-18 10:15 - 2012-08-23 17:00 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
    2012-07-17 11:14 - 2012-07-17 11:14 - 00253184 ____A (Microsoft Corp.) C:\Windows\System32\LIVESSP.DLL
    2012-07-17 10:49 - 2012-07-17 10:49 - 00209648 ____A (Microsoft Corp.) C:\Windows\SysWOW64\LIVESSP.DLL
    2012-07-17 06:54 - 2009-07-13 21:08 - 00032578 ____A C:\Windows\Tasks\SCHEDLGU.TXT
    2012-07-04 14:16 - 2012-08-23 17:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll
    2012-07-04 14:13 - 2012-08-23 17:01 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\browser.dll
    2012-07-04 14:13 - 2012-08-23 17:01 - 00059392 ____A (Microsoft Corporation) C:\Windows\System32\browcli.dll
    2012-07-04 13:16 - 2012-08-23 17:01 - 00057344 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netapi32.dll
    2012-07-04 13:14 - 2012-08-23 17:01 - 00041984 ____A (Microsoft Corporation) C:\Windows\SysWOW64\browcli.dll
    2012-07-03 09:46 - 2012-08-22 20:50 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
    2012-06-28 20:55 - 2012-08-23 17:06 - 17809920 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
    2012-06-28 20:09 - 2012-08-23 17:06 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
    2012-06-28 19:56 - 2012-08-23 17:06 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
    2012-06-28 19:49 - 2012-08-23 17:06 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
    2012-06-28 19:49 - 2012-08-23 17:06 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
    2012-06-28 19:48 - 2012-08-23 17:06 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
    2012-06-28 19:47 - 2012-08-23 17:06 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
    2012-06-28 19:45 - 2012-08-23 17:06 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
    2012-06-28 19:44 - 2012-08-23 17:06 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
    2012-06-28 19:43 - 2012-08-23 17:06 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
    2012-06-28 19:42 - 2012-08-23 17:06 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
    2012-06-28 19:40 - 2012-08-23 17:06 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
    2012-06-28 19:39 - 2012-08-23 17:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
    2012-06-28 19:35 - 2012-08-23 17:06 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
    2012-06-28 16:52 - 2012-08-23 17:06 - 12317184 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2012-06-28 16:27 - 2012-08-23 17:06 - 09737728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2012-06-28 16:16 - 2012-08-23 17:06 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2012-06-28 16:09 - 2012-08-23 17:06 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2012-06-28 16:09 - 2012-08-23 17:06 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2012-06-28 16:08 - 2012-08-23 17:06 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2012-06-28 16:07 - 2012-08-23 17:06 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
    2012-06-28 16:06 - 2012-08-23 17:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2012-06-28 16:04 - 2012-08-23 17:06 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2012-06-28 16:04 - 2012-08-23 17:06 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2012-06-28 16:01 - 2012-08-23 17:06 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2012-06-28 16:01 - 2012-08-23 17:06 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2012-06-28 16:00 - 2012-08-23 17:06 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2012-06-28 15:57 - 2012-08-23 17:06 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2012-06-25 12:04 - 2012-06-25 12:04 - 01394248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml4.dll
    2012-06-20 21:56 - 2011-08-19 04:51 - 00001053 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
    2012-06-20 21:46 - 2012-06-20 21:42 - 16577248 ____A (Mozilla) C:\Users\Owner\Downloads\Firefox Setup 13.0.1.exe

    ZeroAccess:
    C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62
    ==================== Known DLLs (Whitelisted) =================

    ==================== Bamital & volsnap Check =================
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ==================== Restore Points =========================
    Restore point made on: 2012-08-30 17:56:22
    Restore point made on: 2012-09-02 15:44:43
    Restore point made on: 2012-09-03 18:58:31
    Restore point made on: 2012-09-06 12:16:09
    Restore point made on: 2012-09-06 22:17:22
    Restore point made on: 2012-09-09 20:45:52
    Restore point made on: 2012-09-10 07:19:06
    ==================== Memory info ===========================
    Percentage of memory in use: 12%
    Total physical RAM: 6056.29 MB
    Available physical RAM: 5293.38 MB
    Total Pagefile: 6054.44 MB
    Available Pagefile: 5290.05 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.9 MB
    ==================== Partitions ============================
    1 Drive c: () (Fixed) (Total:272 GB) (Free:119.84 GB) NTFS
    2 Drive d: () (Fixed) (Total:406.34 GB) (Free:132.36 GB) NTFS
    3 Drive f: (SAMSUNG_REC) (Fixed) (Total:20.2 GB) (Free:0.94 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    5 Drive h: () (Removable) (Total:0.94 GB) (Free:0.87 GB) FAT
    6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    7 Drive y: (SYSTEM) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 698 GB 1024 KB
    Disk 1 Online 966 MB 0 B
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 100 MB 1024 KB
    Partition 2 Primary 272 GB 101 MB
    Partition 0 Extended 406 GB 272 GB
    Partition 4 Logical 406 GB 272 GB
    Partition 3 Recovery 20 GB 678 GB
    ==================================================================================
    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 Y SYSTEM NTFS Partition 100 MB Healthy
    ==================================================================================
    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 C NTFS Partition 272 GB Healthy
    ==================================================================================
    Disk: 0
    Partition 4
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 D NTFS Partition 406 GB Healthy
    ==================================================================================
    Disk: 0
    Partition 3
    Type : 27
    Hidden: Yes
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 F SAMSUNG_REC NTFS Partition 20 GB Healthy Hidden
    ==================================================================================
    Partitions of Disk 1:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 965 MB 700 KB
    ==================================================================================
    Disk: 1
    Partition 1
    Type : 06
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 5 H FAT Removable 965 MB Healthy
    ==================================================================================
    Last Boot: 2012-09-06 01:29
    ==================== End Of Log =============================
     
  11. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Farbar Recovery Scan Tool (x64) Version: 08-09-2012
    Ran by SYSTEM at 2012-09-10 22:58:48
    Running from H:\
    ================== Search: "services.exe" ===================
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
    C:\Windows\System32\services.exe
    [2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
    C:\Windows\erdnt\cache64\services.exe
    [2012-08-22 11:38] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB
    ====== End Of Search ======
     
     
  12. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the UBCD.
    Run FRST/FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    Next...

    Restart normally.

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     

    Attached Files:

  13. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-09-2012
    Ran by SYSTEM at 2012-09-10 23:24:11 Run:1
    Running from H:\
    ==============================================
    HKEY_LOCAL_MACHINE\System\ControlSet002\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
    C:\Windows\System32\consrv.dll not found.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nerlex Value deleted successfully.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\xtlbj Value deleted successfully.
    C:\Users\Owner\AppData\Roaming\nerlex.dll moved successfully.
    C:\Users\Owner\AppData\Roaming\xtlbj.dll not found.
    HKEY_LOCAL_MACHINE\software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\mvcf2zo Value deleted successfully.
    C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe not found.
    HKEY_USERS\Owner\Software\Microsoft\Windows\CurrentVersion\Run\\nerlex Value deleted successfully.
    jjvop service deleted successfully.
    C:\Users\Owner\AppData\Roaming\clmioni1.bat moved successfully.
    C:\Users\Owner\AppData\Roaming\lyjsb not found.
    C:\Users\All Users\2jFf5J64.exe_ moved successfully.
    C:\Users\All Users\2jFf5J64.exe moved successfully.
    C:\Users\All Users\2jFf5J64.exe_.b moved successfully.
    C:\Users\All Users\2jFf5J64.exe.b moved successfully.
    C:\Users\All Users\1VjM2R.dat moved successfully.
    C:\Users\Owner\AppData\Roaming\lj1y6nb.dat moved successfully.
    C:\Users\Owner\AppData\Roaming\aftr4sb.dat moved successfully.
    C:\Users\Owner\AppData\Roaming\slr8k5s.dat moved successfully.
    C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat moved successfully.
    C:\$Recycle.Bin\S-1-5-21-2503403413-1387520261-2031820482-1001\$a92ef71ff5980a56e36bb9b9fb1c4d62 moved successfully.
    ==== End of Fixlog ====
     
  14. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    ComboFix 12-09-10.04 - Owner 09/10/2012 23:41:54.2.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6056.4453 [GMT -4:00]
    Running from: c:\users\Owner\Desktop\ComboFix.exe
    AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll
    c:\users\Owner\AppData\Roaming\jjvop.exe
    c:\users\Owner\g2mdlhlpx.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-08-11 to 2012-09-11 )))))))))))))))))))))))))))))))
    .
    .
    2012-09-11 06:52 . 2012-09-11 06:52 -------- d-----w- C:\FRST
    2012-09-11 03:48 . 2012-09-11 03:48 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
    2012-09-11 03:48 . 2012-09-11 03:48 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-09-08 02:21 . 2012-09-08 02:21 -------- d-----w- c:\users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
    2012-09-06 20:16 . 2012-09-06 20:16 289768 ----a-w- c:\windows\system32\javaws.exe
    2012-09-06 20:16 . 2012-09-06 20:16 916456 ----a-w- c:\windows\system32\deployJava1.dll
    2012-09-06 20:16 . 2012-09-06 20:16 1034216 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-09-06 20:16 . 2012-09-06 20:16 108008 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
    2012-09-06 20:16 . 2012-09-06 20:16 189416 ----a-w- c:\windows\system32\javaw.exe
    2012-09-06 20:16 . 2012-09-06 20:16 188904 ----a-w- c:\windows\system32\java.exe
    2012-09-06 20:16 . 2012-09-06 20:16 -------- d-----w- c:\program files\Java
    2012-09-04 21:59 . 2012-09-04 22:32 -------- d-----w- c:\users\Owner\AppData\Roaming\pdfforge
    2012-09-04 21:28 . 2011-06-02 05:47 177640 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
    2012-09-04 21:28 . 2011-06-02 05:47 16872 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
    2012-09-04 21:28 . 2011-06-02 05:47 157672 ----a-w- c:\windows\system32\drivers\ssadbus.sys
    2012-09-04 21:28 . 2011-06-02 05:47 13800 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
    2012-09-04 21:28 . 2011-06-02 05:47 13800 ----a-w- c:\windows\system32\drivers\ssadwh.sys
    2012-09-04 21:28 . 2011-06-02 05:47 13288 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
    2012-09-04 21:28 . 2011-06-02 05:47 13288 ----a-w- c:\windows\system32\drivers\ssadcm.sys
    2012-08-24 11:44 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-08-24 11:44 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
    2012-08-24 01:39 . 2012-08-24 01:39 -------- d-----w- c:\program files\Windows Live
    2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----w- c:\program files (x86)\Microsoft SkyDrive
    2012-08-24 01:38 . 2012-08-24 01:37 5563840 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\f126a2711cd819803\skydrivesetup.exe
    2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----r- c:\users\Owner\SkyDrive
    2012-08-24 01:38 . 2012-08-24 01:38 -------- d-----w- c:\programdata\Microsoft SkyDrive
    2012-08-24 01:35 . 2012-08-24 01:35 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
    2012-08-24 01:01 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll
    2012-08-24 01:01 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
    2012-08-24 01:01 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
    2012-08-24 01:01 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
    2012-08-24 01:01 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
    2012-08-24 01:01 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
    2012-08-24 01:01 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
    2012-08-24 01:01 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
    2012-08-24 01:01 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
    2012-08-24 01:01 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
    2012-08-24 01:00 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
    2012-08-24 01:00 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
    2012-08-24 00:57 . 2012-08-24 00:57 -------- d-----w- c:\users\Owner\AppData\Local\Secunia PSI
    2012-08-24 00:57 . 2012-08-24 00:57 -------- d-----w- c:\program files (x86)\Secunia
    2012-08-24 00:53 . 2012-08-24 00:53 -------- d-----w- c:\program files (x86)\FileHippo.com
    2012-08-24 00:39 . 2012-08-24 00:39 -------- d-----w- c:\program files\WOT
    2012-08-24 00:39 . 2012-08-24 00:39 -------- d-----w- c:\program files (x86)\WOT
    2012-08-23 21:28 . 2012-08-23 21:28 -------- d-----w- c:\program files (x86)\Common Files\Java
    2012-08-23 21:28 . 2012-08-23 21:28 821736 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
    2012-08-23 21:28 . 2012-08-23 21:28 95208 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
    2012-08-23 21:27 . 2012-08-23 21:27 -------- d-----w- c:\programdata\McAfee
    2012-08-23 16:01 . 2012-08-23 16:01 -------- d-----w- c:\program files (x86)\ESET
    2012-08-14 11:23 . 2012-08-15 13:32 -------- d---a-w- C:\Kaspersky Rescue Disk 10.0
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-08-31 18:52 . 2012-04-01 21:32 696520 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-08-31 18:52 . 2011-08-19 18:11 73416 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-08-24 01:02 . 2012-02-11 01:49 62134624 ----a-w- c:\windows\system32\MRT.exe
    2012-08-23 21:28 . 2011-09-27 18:27 746984 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2012-07-28 07:09 . 2012-07-28 07:09 57792 ----a-w- c:\windows\SysWow64\sirenacm.dll
    2012-07-26 23:08 . 2012-07-26 23:08 862664 ----a-w- c:\windows\SysWow64\msvcr110.dll
    2012-07-26 23:08 . 2012-07-26 23:08 534480 ----a-w- c:\windows\SysWow64\msvcp110.dll
    2012-07-26 23:08 . 2012-07-26 23:08 251864 ----a-w- c:\windows\SysWow64\vccorlib110.dll
    2012-07-26 23:08 . 2012-07-26 23:08 153536 ----a-w- c:\windows\SysWow64\atl110.dll
    2012-07-26 23:08 . 2012-07-26 23:08 115656 ----a-w- c:\windows\SysWow64\vcomp110.dll
    2012-07-26 19:22 . 2012-07-26 19:22 828872 ----a-w- c:\windows\system32\msvcr110.dll
    2012-07-26 19:22 . 2012-07-26 19:22 661448 ----a-w- c:\windows\system32\msvcp110.dll
    2012-07-26 19:22 . 2012-07-26 19:22 354264 ----a-w- c:\windows\system32\vccorlib110.dll
    2012-07-26 19:22 . 2012-07-26 19:22 177096 ----a-w- c:\windows\system32\atl110.dll
    2012-07-26 19:22 . 2012-07-26 19:22 124360 ----a-w- c:\windows\system32\vcomp110.dll
    2012-07-17 19:14 . 2012-07-17 19:14 253184 ----a-w- c:\windows\system32\LIVESSP.DLL
    2012-07-17 18:49 . 2012-07-17 18:49 209648 ----a-w- c:\windows\SysWow64\LIVESSP.DLL
    2012-07-17 18:37 . 2012-07-17 18:37 19736 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
    @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
    [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
    @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
    [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
    @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
    [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    2012-08-24 01:38 220608 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "FileHippo.com"="c:\program files (x86)\FileHippo.com\UpdateChecker.exe" [2012-03-26 306688]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2010-06-08 618496]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-6-27 572000]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2010-6-24 9216]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux5"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
    @="Service"
    .
    R2 CLKMSVC10_38F51D56;CyberLink Product - 2010/12/22 19:14;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [2010-08-25 246256]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 136176]
    R2 hshld;Hotspot Shield Service;c:\program files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-03-26 542040]
    R2 KMService;KMService;c:\windows\system32\srvany.exe [x]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2010-12-14 1997416]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-06-07 160944]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-31 250568]
    R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 136176]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 51740536]
    R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-08-10 113120]
    R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 340240]
    R3 NETwNs64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-11-08 8500736]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-10 174440]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
    R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976]
    R3 Samsung UPD Service;Samsung UPD Service;c:\windows\System32\SUPDSvc.exe [2010-08-09 166704]
    R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-06-02 157672]
    R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-06-02 16872]
    R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-06-02 177640]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
    R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;c:\program files\Intel\TurboBoost\TurboBoost.exe [2010-10-08 150016]
    R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-11 1255736]
    S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys [2010-12-14 25576]
    S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 13824]
    S1 VWiFiFlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-07-27 63960]
    S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2010-09-01 408576]
    S2 HssWd;Hotspot Shield Monitoring Service;c:\program files (x86)\Hotspot Shield\bin\hsswd.exe [2012-03-26 329544]
    S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-06-27 1326176]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-06-27 681056]
    S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2010-10-08 19192]
    S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-10-06 2655768]
    S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2010-09-01 911872]
    S3 bpenum;bpenum;c:\windows\system32\DRIVERS\bpenum.sys [2010-05-16 71168]
    S3 bpmp;Intel(R) Centrino(R) WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [2010-05-16 175104]
    S3 bpusb;bpusb;c:\windows\system32\Drivers\bpusb.sys [2010-05-16 81920]
    S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-11-10 31088]
    S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-11-12 138024]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-15 317440]
    S3 MEIx64;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
    S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-10-11 80384]
    S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-10-11 180736]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-11-25 409192]
    S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-11-30 42392]
    .
    .
    --- Other Services/Drivers In Memory ---
    .
    *Deregistered* - CLKMDRV10_38F51D56
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 18:52]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 19:07]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-08-18 19:07]
    .
    2012-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 07:41]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
    - c:\users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe [2012-04-02 07:41]
    .
    2012-08-10 c:\windows\Tasks\SidebarExecute.job
    - c:\program files\Windows Sidebar\sidebar.exe [2012-02-12 13:25]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
    @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
    [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
    @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
    [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
    @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
    [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    2012-08-24 01:38 244672 ----a-w- c:\users\Owner\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-12-07 167960]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-12-07 391704]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-12-07 417304]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-11-30 11660904]
    "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-11-02 1933584]
    "IntelTBRunOnce"="wscript.exe" [2009-07-14 168960]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.siccode.com/
    mStart Page = hxxp://samsung.msn.com
    mLocal Page = c:\windows\SysWOW64\blank.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    TCP: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
    DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} - hxxps://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab
    FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\
    FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
    FF - prefs.js: network.proxy.type - 0
    FF - user.js: general.useragent.extra.brc -
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-Deployment - c:\users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll
    HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]
    "value"="?\06\06\09\16\04;ˆ"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
    c:\program files (x86)\CyberLink\Shared files\RichVideo.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    .
    **************************************************************************
    .
    Completion time: 2012-09-10 23:55:16 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-09-11 03:55
    .
    Pre-Run: 128,742,363,136 bytes free
    Post-Run: 128,954,146,816 bytes free
    .
    - - End Of File - - 102AC0B7EBC3907078295E033AF09BA1
     
  15. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Please note: I am unable to connect to the internet after the combofix. I restarted the computer twice but there are still no connections available. This was posted from another computer.
     
  16. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Please use this restore point:
    ...and see if you have your connection back.
     
  17. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Thanks for getting back to me.

    Where do I go to get this restore point?

    I went to system restore on the computer and did not see the specified restore point listed. There were two other restore points listed for September 10.
     
  18. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    Use the earlier one.
     
  19. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    Ok. I did the system restore point to 9/10/12 12:45:48 AM. Wifi is working.

    There is still a Run DLL window stating:

    C:\Users\Owner\AppData\Roaming\xtlbj.dll
    The specified module could not be found.
     
  20. Broni

    Broni Malware Annihilator Posts: 47,048   +256

    We'll take care of it in a moment.

    Any other issues?

    =======================

    Download Malwarebytes' Anti-Malware (MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
    Alternate download: http://www.filehippo.com/download_malwarebytes_anti_malware/
    NOTE. If you already have MBAM installed, update it before running the scan.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer IF MBAM asks you to do so.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    =========================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  21. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    No other issues right now.

    Malwarebytes Anti-Malware 1.65.0.1400
    www.malwarebytes.org
    Database version: v2012.09.11.09
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Owner :: OWNER-PC [administrator]
    9/11/2012 8:16:50 PM
    mbam-log-2012-09-11 (20-16-50).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 224981
    Time elapsed: 4 minute(s), 9 second(s)
    Memory Processes Detected: 0
    (No malicious items detected)
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 1
    C:\ProgramData\2jFf5J64.exe (Spyware.Zbot) -> Quarantined and deleted successfully.
    (end)
     
  22. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    OTL logfile created on: 9/11/2012 8:27:53 PM - Run 1
    OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Owner\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    5.91 Gb Total Physical Memory | 3.79 Gb Available Physical Memory | 64.15% Memory free
    11.83 Gb Paging File | 9.56 Gb Available in Paging File | 80.81% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 272.00 Gb Total Space | 120.06 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
    Drive D: | 406.34 Gb Total Space | 132.36 Gb Free Space | 32.57% Space Free | Partition Type: NTFS

    Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/09/11 20:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
    PRC - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    PRC - [2012/06/27 03:25:06 | 001,326,176 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psia.exe
    PRC - [2012/06/27 03:25:04 | 000,681,056 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\sua.exe
    PRC - [2012/06/27 03:25:04 | 000,572,000 | ---- | M] (Secunia) -- C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    PRC - [2012/03/26 17:45:22 | 000,329,544 | ---- | M] () -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe
    PRC - [2012/03/26 17:45:18 | 000,363,336 | ---- | M] (AnchorFree Inc.) -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
    PRC - [2011/09/04 12:45:26 | 003,398,736 | ---- | M] (SAMSUNG Electronics) -- C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
    PRC - [2010/12/17 03:28:20 | 000,943,984 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
    PRC - [2010/12/14 19:01:16 | 001,997,416 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    PRC - [2010/12/06 07:44:28 | 007,058,800 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Easy Display Manager\WifiManager.exe
    PRC - [2010/11/29 01:42:38 | 000,775,848 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\MovieColorEnhancer.exe
    PRC - [2010/11/17 04:24:54 | 004,387,632 | ---- | M] (SEC) -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
    PRC - [2010/11/10 04:03:52 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    PRC - [2010/10/06 01:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    PRC - [2010/10/06 01:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    PRC - [2010/06/07 23:15:42 | 000,618,496 | ---- | M] () -- C:\Windows\Samsung\PanelMgr\SSMMgr.exe
    PRC - [2010/02/10 10:29:52 | 000,719,360 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe


    ========== Modules (No Company Name) ==========

    MOD - [2012/09/07 22:21:02 | 000,416,768 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
    MOD - [2012/08/02 18:13:18 | 001,335,872 | ---- | M] () -- C:\Program Files (x86)\WOT\WOT.dll
    MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
    MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
    MOD - [2010/07/05 06:42:58 | 000,203,776 | ---- | M] () -- C:\Program Files (x86)\Samsung\Movie Color Enhancer\WinCRT.dll
    MOD - [2010/06/07 23:15:42 | 000,618,496 | ---- | M] () -- C:\Windows\Samsung\PanelMgr\SSMMgr.exe
    MOD - [2010/05/07 10:22:18 | 001,636,864 | ---- | M] () -- C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll
    MOD - [2006/08/11 23:48:40 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
    SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
    SRV:64bit: - [2010/11/02 00:49:46 | 001,515,792 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
    SRV:64bit: - [2010/11/02 00:39:08 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
    SRV:64bit: - [2010/11/02 00:34:14 | 000,836,880 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
    SRV:64bit: - [2010/10/08 05:24:16 | 000,150,016 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
    SRV:64bit: - [2010/08/31 23:00:06 | 000,911,872 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv)
    SRV:64bit: - [2010/08/31 22:54:22 | 000,408,576 | ---- | M] (Red Bend Ltd.) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent)
    SRV:64bit: - [2010/08/09 15:04:12 | 000,166,704 | ---- | M] (Samsung Electronics CO., LTD.) [On_Demand | Stopped] -- C:\Windows\SysNative\SUPDSvc.exe -- (Samsung UPD Service)
    SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV - [2012/09/08 17:51:42 | 000,000,087 | -H-- | M] () [Auto | Stopped] -- C:\Users\Owner\AppData\Roaming\clmioni1.bat -- (jjvop)
    SRV - [2012/08/31 14:52:40 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/08/10 16:18:54 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/07/27 16:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
    SRV - [2012/06/27 03:25:06 | 001,326,176 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\psia.exe -- (Secunia PSI Agent)
    SRV - [2012/06/27 03:25:04 | 000,681,056 | ---- | M] (Secunia) [Auto | Running] -- C:\Program Files (x86)\Secunia\PSI\sua.exe -- (Secunia Update Agent)
    SRV - [2012/06/07 19:12:14 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/03/26 18:45:44 | 000,077,520 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
    SRV - [2012/03/26 18:38:46 | 000,542,040 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe -- (hshld)
    SRV - [2012/03/26 17:45:22 | 000,329,544 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -- (HssWd)
    SRV - [2012/03/26 17:45:18 | 000,363,336 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
    SRV - [2010/12/14 19:01:16 | 001,997,416 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
    SRV - [2010/10/22 14:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
    SRV - [2010/10/06 01:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe -- (UNS)
    SRV - [2010/10/06 01:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
    SRV - [2010/08/24 23:07:38 | 000,246,256 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe -- (CLKMSVC10_38F51D56)
    SRV - [2010/06/01 02:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
    SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2003/04/18 19:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
    DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2011/12/16 10:20:10 | 000,017,976 | ---- | M] (Secunia) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\psi_mf.sys -- (PSI)
    DRV:64bit: - [2011/07/20 14:58:22 | 000,044,032 | ---- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimSerial_AMD64.sys -- (RimVSerPort)
    DRV:64bit: - [2011/06/02 01:47:22 | 000,177,640 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdm.sys -- (ssadmdm)
    DRV:64bit: - [2011/06/02 01:47:22 | 000,157,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadbus.sys -- (ssadbus)
    DRV:64bit: - [2011/06/02 01:47:22 | 000,016,872 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssadmdfl.sys -- (ssadmdfl)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2010/12/14 19:01:14 | 000,025,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
    DRV:64bit: - [2010/11/30 16:02:22 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
    DRV:64bit: - [2010/11/29 01:23:16 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2010/11/25 15:31:32 | 000,409,192 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
    DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2010/11/12 18:23:38 | 000,138,024 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
    DRV:64bit: - [2010/11/10 04:04:14 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
    DRV:64bit: - [2010/11/08 14:16:36 | 008,500,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64)
    DRV:64bit: - [2010/10/20 00:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
    DRV:64bit: - [2010/10/15 04:28:16 | 000,317,440 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
    DRV:64bit: - [2010/10/11 18:26:20 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
    DRV:64bit: - [2010/10/11 18:26:20 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
    DRV:64bit: - [2010/10/08 05:23:38 | 000,019,192 | ---- | M] (Intel(R) Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TurboB.sys -- (TurboB)
    DRV:64bit: - [2010/09/13 05:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
    DRV:64bit: - [2010/05/16 04:28:36 | 000,175,104 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpmp.sys -- (bpmp)
    DRV:64bit: - [2010/05/16 04:28:28 | 000,081,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpusb.sys -- (bpusb)
    DRV:64bit: - [2010/05/16 04:28:26 | 000,071,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpenum.sys -- (bpenum)
    DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
    DRV:64bit: - [2009/07/13 20:10:47 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rootmdm.sys -- (ROOTMODEM)
    DRV:64bit: - [2009/07/13 20:09:50 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
    DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
    DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
    DRV:64bit: - [2009/05/28 02:38:04 | 000,013,824 | ---- | M] (SAMSUNG ELECTRONICS) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SABI.sys -- (SABI)
    DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://samsung.msn.com
    IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
    IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3027459


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0




    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.siccode.com/
    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{14E65473-E217-429D-86C4-013FD2B189FF}: "URL" = http://www.bing.com/search?FORM=SMSTDF&PC=MASM&q={searchTerms}&src=IE-SearchBox
    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = https://isearch.avg.com/search?cid=...dd119bca531&lang=en&ds=AVG&pr=pr&d=2012-08-10 17:41:36&v=12.2.0.5&sap=dsp&q={searchTerms}
    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\SearchScopes\{A54FC709-D0A1-46BD-83FC-8BA859D982A7}: "URL" = http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
    IE - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
    FF - prefs.js..extensions.enabledAddons: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}:6.0.33
    FF - prefs.js..network.proxy.type: 0


    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
    FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.6.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.6.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/06 15:47:01 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/08/10 16:18:54 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/08/23 17:24:42 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/06 15:47:01 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}: C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}\ [2012/09/07 22:21:05 | 000,000,000 | ---D | M]

    [2011/08/19 08:51:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
    [2012/09/08 17:46:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\extensions
    [1832/11/29 00:30:07 | 000,004,804 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\86hcnlmp.default\extensions\zghfslnovh@zghfslnovh.org.xpi
    [2012/08/23 21:08:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2012/08/23 21:08:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
    [2012/06/09 18:10:27 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
    [2012/09/07 22:21:05 | 000,000,000 | ---D | M] (Mozilla Safe Browsing) -- C:\USERS\OWNER\APPDATA\LOCAL\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
    [2012/08/10 16:18:54 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2012/08/10 17:41:32 | 000,003,749 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
    [2012/06/14 18:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/06/14 18:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - homepage: http://www.siccode.com/
    CHR - default_search_provider: AVG Secure Search (Enabled)
    CHR - default_search_provider: search_url = https://isearch.avg.com/search?cid=...d=&lang=&ds=&pr=&d=&v=&sap=dsp&q={searchTerms}
    CHR - default_search_provider: suggest_url = http://clients5.google.com/complete...inputEncoding}&outputencoding={outputEncoding}
    CHR - homepage: http://www.siccode.com/
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
    CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
    CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
    CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
    CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
     
  23. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    O1 HOSTS File: ([2012/08/22 15:32:39 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2 - BHO: (W2PBrowser Class) - {AA609D72-8482-4076-8991-8CDAE5B93BCB} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
    O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files (x86)\WOT\WOT.dll ()
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O3:64bit: - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
    O3:64bit: - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
    O3 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll ()
    O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
    O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IntelTBRunOnce] wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" File not found
    O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel(R) Corporation)
    O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
    O4:64bit: - HKLM..\Run: [nerlex] C:\Users\Owner\AppData\Roaming\nerlex.dll ()
    O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [xtlbj] rundll32.exe "C:\Users\Owner\AppData\Roaming\xtlbj.dll",PVDecodeObject File not found
    O4 - HKLM..\Run: [mvcf2zo] C:\Users\Owner\AppData\Roaming\s1p3jq5g.exe File not found
    O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
    O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [Deployment] C:\Users\Owner\AppData\Local\Diagnostics\Deployment\faplygb.dll (Sony Corporation)
    O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [FileHippo.com] C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (FileHippo.com)
    O4 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001..\Run: [nerlex] C:\Users\Owner\AppData\Roaming\nerlex.dll ()
    O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
    O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk = C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKU\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
    O9 - Extra Button: Samsung AnyWeb Print - {328ECD19-C167-40eb-A0C7-16FE7634105E} - C:\Program Files\Samsung AnyWeb Print\W2PBrowser.dll ()
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 10.6.2)
    O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
    O16 - DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab (Java Plug-in 1.7.0_06)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.7.0_06)
    O16 - DPF: {CB1A2363-BCE7-42B1-A8B2-E530C9F0B0DA} https://secure.digsigtrust.com/ms/IdenTrustCertEnroll.cab (CertEnrollControl Class)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DEAA0459-FD77-4007-B31D-7998BC471859}: DhcpNameServer = 167.206.245.129 167.206.245.130 192.168.1.1
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
    O18 - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll ()
    O20:64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
    O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
    O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
    O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = ComFile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/09/11 20:26:35 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
    [2012/09/11 20:15:25 | 010,524,080 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.65.0.1400.exe
    [2012/09/11 02:52:50 | 000,000,000 | ---D | C] -- C:\FRST
    [2012/09/10 23:36:54 | 000,000,000 | ---D | C] -- C:\Qoobox
    [2012/09/10 20:59:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\RK_Quarantine
    [2012/09/07 22:21:05 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{D48A5C82-F95B-11E1-8270-B8AC6F996F26}
    [2012/09/06 16:16:19 | 000,000,000 | ---D | C] -- C:\Program Files\Java
    [2012/09/04 17:59:01 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\pdfforge
    [2012/09/04 17:28:26 | 000,177,640 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdm.sys
    [2012/09/04 17:28:26 | 000,157,672 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadbus.sys
    [2012/09/04 17:28:26 | 000,016,872 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadmdfl.sys
    [2012/09/04 17:28:26 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwhnt.sys
    [2012/09/04 17:28:26 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys
    [2012/09/04 17:28:26 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcmnt.sys
    [2012/09/04 17:28:26 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys
    [2012/08/23 21:39:47 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
    [2012/08/23 21:38:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SkyDrive
    [2012/08/23 21:38:27 | 000,000,000 | R--D | C] -- C:\Users\Owner\SkyDrive
    [2012/08/23 21:38:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft SkyDrive
    [2012/08/23 21:37:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    [2012/08/23 21:35:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
    [2012/08/23 21:05:55 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
    [2012/08/23 20:57:49 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Secunia PSI
    [2012/08/23 20:57:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Secunia
    [2012/08/23 20:53:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileHippo.com
    [2012/08/23 20:45:35 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\TFC.exe
    [2012/08/23 20:39:52 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
    [2012/08/23 20:39:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WOT
    [2012/08/23 17:28:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
    [2012/08/23 17:27:38 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
    [2012/08/23 12:01:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
    [2012/08/23 00:50:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2012/08/23 00:50:32 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/08/23 00:50:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    [2012/08/22 15:32:44 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
    [2012/08/22 15:02:04 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
    [2012/08/22 10:58:27 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{23E2D15F-877F-4E0A-9068-7728E64CB6FB}
    [2012/08/16 15:45:50 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{6554A463-B686-416D-AE80-4C34BB8A1211}
    [2012/08/16 15:45:37 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{62419E22-A8B3-401D-8019-D8898FB392EE}
    [2012/08/16 15:41:33 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{B505AEBC-C2ED-44AB-B9CB-97FA4D20DBC3}
    [2012/08/16 15:41:24 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{FC35BACC-6C4F-4274-8F77-532F485773F9}
    [2012/08/16 15:37:26 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{018C6B10-3ABD-429B-8D85-A9048B37B756}
    [2012/08/16 15:37:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{D33577DA-02DF-4F1D-AF40-91B6265FAA3B}
    [2012/08/16 15:32:27 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{19FD24CF-8C45-4E36-A019-4B00EC31E717}
    [2012/08/16 15:32:16 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{BD66BFB9-923F-4C18-8EEA-128E2CC075C7}
    [2012/08/16 15:28:37 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1046392E-14FA-4E6F-BA53-439704799308}
    [2012/08/16 15:20:58 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{7D3BEB9E-C3BE-492E-A119-91483A10A490}
    [2012/08/16 15:20:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{89351A59-EF82-4218-BC50-DE97F2046B1D}
    [2012/08/15 13:51:28 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{FEEF43F0-0A08-47A8-B5CA-CDFAFF8B4547}
    [2012/08/15 13:51:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{C30C1636-CD8A-4655-AC25-192B45FA3D84}
    [2012/08/14 11:03:42 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{50635B3E-137B-48CA-B7DA-0EA1E85634B4}
    [2012/08/14 11:03:18 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{2B0369F3-07BF-44BD-A709-129E48E4BF18}
    [2012/08/14 10:46:32 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{92357CE2-F4B4-4A77-96A6-F87CFD2DB9FB}
    [2012/08/14 10:42:40 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1D333F65-AA86-4F75-926D-5E55F73F68D9}
    [2012/08/14 10:42:12 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{F08DC235-3BB4-4A33-84E0-4782C63F344F}
    [2012/08/14 10:30:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
    [2012/08/14 10:30:15 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
    [2012/08/14 07:23:22 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
    [2012/08/13 17:37:08 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{579256FC-33D1-4EDD-82FB-BC3C703BCB37}
    [2012/08/13 17:36:52 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{640DAB74-1BBB-4F34-B908-84F628F84990}
    [2012/08/13 14:41:59 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Anti-virus
    [2012/08/13 14:28:26 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{1711552E-7CA8-46D2-9553-BEE14EAC0097}
    [2012/08/13 14:28:12 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{7B607E49-0F6A-492B-A417-395C94B2FC48}
    [2012/08/13 10:40:38 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{DB087CDE-B094-40D6-89EA-1EF1049501EE}
    [2012/08/13 10:39:34 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{A80D082C-126E-4832-8981-7EA7034EA543}
    [2012/08/13 06:35:18 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{C89E875A-F683-49A7-B7BC-96601D88EBFC}
    [2012/08/13 06:33:25 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\{6BF451D9-0EE4-42B8-A822-23513582F10B}
    [2009/07/13 19:19:28 | 210,051,234 | ---- | C] (Immediately Display Mobile Erasing llc) -- C:\Users\Owner\AppData\Roaming\jjvop.exe

    ========== Files - Modified Within 30 Days ==========

    [2012/09/11 20:36:22 | 000,006,532 | ---- | M] () -- C:\Users\Owner\AppData\Local\chromeupdate.crx
    [2012/09/11 20:31:56 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/09/11 20:31:56 | 000,014,144 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/09/11 20:30:33 | 000,729,880 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/09/11 20:30:33 | 000,626,540 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/09/11 20:30:33 | 000,107,784 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/09/11 20:26:58 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
    [2012/09/11 20:23:45 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/09/11 20:23:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/09/11 20:23:12 | 2055,512,063 | -HS- | M] () -- C:\hiberfil.sys
    [2012/09/11 20:20:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2012/09/11 20:16:04 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/09/11 20:15:25 | 010,524,080 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Owner\Desktop\mbam-setup-1.65.0.1400.exe
    [2012/09/11 20:01:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001UA.job
    [2012/09/11 19:52:04 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/09/11 19:40:44 | 000,090,176 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
    [2012/09/11 19:40:34 | 000,086,080 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\aftr4sb.dat
    [2012/09/11 19:40:24 | 000,060,992 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\slr8k5s.dat
    [2012/09/10 22:09:16 | 000,000,512 | ---- | M] () -- C:\Users\Owner\Desktop\MBR.dat
    [2012/09/10 20:50:22 | 002,193,184 | ---- | M] () -- C:\Users\Owner\Desktop\tdsskiller.zip
    [2012/09/09 07:01:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2503403413-1387520261-2031820482-1001Core.job
    [2012/09/08 17:51:42 | 000,000,087 | -H-- | M] () -- C:\Users\Owner\AppData\Roaming\clmioni1.bat
    [2012/09/08 17:51:29 | 210,051,234 | ---- | M] (Immediately Display Mobile Erasing llc) -- C:\Users\Owner\AppData\Roaming\jjvop.exe
    [2012/09/07 22:21:02 | 000,416,768 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
    [2012/09/07 22:20:07 | 000,000,090 | -H-- | M] () -- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
    [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2012/09/01 16:02:16 | 000,002,453 | ---- | M] () -- C:\Users\Owner\Desktop\Google Chrome.lnk
    [2012/08/29 10:00:29 | 000,060,864 | ---- | M] () -- C:\Users\Owner\g2mdlhlpx.exe
    [2012/08/29 06:06:14 | 000,000,600 | ---- | M] () -- C:\Users\Owner\AppData\Local\PUTTY.RND
    [2012/08/26 06:34:14 | 000,011,264 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2012/08/23 21:37:02 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2012/08/23 21:14:42 | 005,043,664 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2012/08/23 21:04:41 | 000,001,070 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2012/08/23 20:57:19 | 000,001,110 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
    [2012/08/23 20:53:50 | 000,001,973 | ---- | M] () -- C:\Users\Owner\Desktop\Update Checker.lnk
    [2012/08/23 20:45:35 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\TFC.exe
    [2012/08/23 17:24:43 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
    [2012/08/22 15:32:39 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/08/22 14:57:52 | 000,002,086 | ---- | M] () -- C:\Windows\epplauncher.mif
    [2012/08/14 10:30:19 | 000,743,856 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI

    ========== Files Created - No Company Name ==========

    [2012/09/11 19:40:44 | 000,090,176 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\lj1y6nb.dat
    [2012/09/11 19:40:34 | 000,086,080 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\aftr4sb.dat
    [2012/09/11 19:40:24 | 000,060,992 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\slr8k5s.dat
    [2012/09/10 22:09:16 | 000,000,512 | ---- | C] () -- C:\Users\Owner\Desktop\MBR.dat
    [2012/09/10 20:50:20 | 002,193,184 | ---- | C] () -- C:\Users\Owner\Desktop\tdsskiller.zip
    [2012/09/08 17:51:42 | 000,000,087 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\clmioni1.bat
    [2012/09/07 22:21:05 | 000,006,532 | ---- | C] () -- C:\Users\Owner\AppData\Local\chromeupdate.crx
    [2012/09/07 22:21:01 | 000,416,768 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\nerlex.dll
    [2012/09/07 22:20:07 | 000,000,090 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\y2n8nc2c.bat
    [2012/08/29 10:00:28 | 000,060,864 | ---- | C] () -- C:\Users\Owner\g2mdlhlpx.exe
    [2012/08/23 22:02:18 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
    [2012/08/23 21:38:26 | 000,002,160 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
    [2012/08/23 21:37:02 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
    [2012/08/23 21:04:41 | 000,001,070 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
    [2012/08/23 20:57:19 | 000,001,110 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
    [2012/08/23 20:57:19 | 000,001,073 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Secunia PSI.lnk
    [2012/08/23 20:53:50 | 000,002,003 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Update Checker.lnk
    [2012/08/23 20:53:50 | 000,001,973 | ---- | C] () -- C:\Users\Owner\Desktop\Update Checker.lnk
    [2012/08/23 17:24:43 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
    [2012/08/23 17:24:42 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
    [2012/08/23 00:50:37 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2012/08/14 10:30:28 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
    [2012/08/10 17:20:53 | 000,000,048 | ---- | C] () -- C:\Users\Owner\AppData\Local\OWNER-PC.cfg
    [2012/02/06 15:53:41 | 000,207,571 | ---- | C] () -- C:\Windows\hpwins28.dat.temp
    [2012/02/06 15:53:41 | 000,000,418 | ---- | C] () -- C:\Windows\hpwmdl28.dat.temp
    [2012/02/06 15:39:51 | 000,206,568 | ---- | C] () -- C:\Windows\hpwins28.dat
    [2012/01/22 11:18:05 | 000,000,600 | ---- | C] () -- C:\Users\Owner\AppData\Local\PUTTY.RND
    [2012/01/18 10:24:09 | 000,007,596 | ---- | C] () -- C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
    [2012/01/16 23:31:54 | 000,743,856 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2011/11/19 15:09:01 | 000,011,264 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2011/11/18 12:34:56 | 000,000,166 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\PLGComp.ini
    [2011/08/19 13:48:35 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
    [2011/08/18 14:54:45 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
    [2010/12/22 23:21:56 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
    [2010/12/22 23:21:54 | 000,206,952 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
    [2010/12/22 23:21:52 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
    [2010/12/22 07:36:50 | 000,307,200 | ---- | C] () -- C:\Windows\SetDisplayResolution.exe
    [2010/12/22 06:17:59 | 000,003,154 | ---- | C] () -- C:\Windows\HotFixList.ini
    [2010/12/22 06:17:55 | 000,142,704 | ---- | C] () -- C:\Windows\wiainst64.exe
    [2010/12/22 06:17:01 | 000,484,656 | ---- | C] () -- C:\Windows\ssndii.exe
    [2010/12/22 06:16:42 | 000,258,864 | ---- | C] () -- C:\Windows\SUPDRun.exe
    [2010/12/22 05:48:35 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll

    ========== LOP Check ==========

    [2012/01/28 16:24:53 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Audacity
    [2012/06/09 19:41:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Azureus
    [2012/09/07 13:08:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\FileZilla
    [2012/09/11 19:38:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\IrfanView
    [2012/03/24 14:05:53 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PDAppFlex
    [2012/09/04 18:32:42 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\pdfforge
    [2012/03/24 14:24:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
    [2011/08/19 21:48:30 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Windows Live Writer
    [2012/07/17 10:54:55 | 000,032,578 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
    [2012/08/10 17:41:48 | 000,000,218 | ---- | M] () -- C:\Windows\Tasks\SidebarExecute.job

    ========== Purity Check ==========
    < End of report >
     
  24. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    OTL Extras logfile created on: 9/11/2012 8:27:53 PM - Run 1
    OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\Owner\Desktop
    64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    5.91 Gb Total Physical Memory | 3.79 Gb Available Physical Memory | 64.15% Memory free
    11.83 Gb Paging File | 9.56 Gb Available in Paging File | 80.81% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 272.00 Gb Total Space | 120.06 Gb Free Space | 44.14% Space Free | Partition Type: NTFS
    Drive D: | 406.34 Gb Total Space | 132.36 Gb Free Space | 32.57% Space Free | Partition Type: NTFS

    Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Extra Registry (SafeList) ==========


    ========== File Associations ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
    .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

    ========== Shell Spawning ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htafile [open] -- "%1" %*
    htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
    inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
    InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
    InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
    batfile [open] -- "%1" %*
    cmdfile [open] -- "%1" %*
    comfile [open] -- "%1" %*
    cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
    exefile [open] -- "%1" %*
    helpfile [open] -- Reg Error: Key error.
    htafile [open] -- "%1" %*
    piffile [open] -- "%1" %*
    regfile [merge] -- Reg Error: Key error.
    scrfile [config] -- "%1"
    scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
    scrfile [open] -- "%1" /S
    txtfile [edit] -- Reg Error: Key error.
    Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
    Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
    Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
    Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
    Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
    Folder [explore] -- Reg Error: Value error.
    Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

    ========== Security Center Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "cval" = 0
    "FirewallDisableNotify" = 0
    "AntiVirusDisableNotify" = 0
    "UpdatesDisableNotify" = 0

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
    "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
    "AntiVirusOverride" = 0
    "AntiSpywareOverride" = 0
    "FirewallOverride" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    "UpdatesDisableNotify" = 0

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

    ========== System Restore Settings ==========

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
    "DisableSR" = 0

    ========== Firewall Settings ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1
    "DoNotAllowExceptions" = 0

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
    "DisableNotifications" = 0
    "EnableFirewall" = 1

    ========== Authorized Applications List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\Users\Owner\AppData\Roaming\jjvop.exe" = C:\Users\Owner\AppData\Roaming\jjvop.exe:*:Enabled:jjvop.exe -- (Immediately Display Mobile Erasing llc)
    "C:\Users\Owner\AppData\Roaming\jjvop.exe" = C:\Users\Owner\AppData\Roaming\jjvop.exe:*:Enabled:jjvop.exe -- (Immediately Display Mobile Erasing llc)


    ========== Vista Active Open Ports Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
    "{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
    "{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
    "{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
    "{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
    "{478A745B-A9F6-473A-BDE7-36CC8DDBBBBE}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
    "{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
    "{53B6DF4A-C479-44B2-A315-99C48AF2EA28}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
    "{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
    "{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
    "{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
    "{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
    "{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
    "{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
    "{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
    "{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
    "{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
    "{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
    "{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

    ========== Vista Active Application Exception List ==========

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
    "{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
    "{274A935C-496C-428F-A08F-33FBBFCFD4B1}" = dir=in | app=c:\users\owner\appdata\local\microsoft\skydrive\skydrive.exe |
    "{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
    "{49AB3915-BD40-46FE-BB2A-880A690CA3E4}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
    "{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
    "{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
    "{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{92C806CF-4E28-434C-B89D-1E6852FA4E79}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
    "{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
    "{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
    "{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
    "{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
    "{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
    "TCP Query User{D5351119-FDF2-40FE-80C8-1EC0300E9730}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
    "UDP Query User{93C6D173-F459-4F7E-9363-7B73057D42E1}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

    ========== HKEY_LOCAL_MACHINE Uninstall List ==========

    64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
    "{26A24AE4-039D-4CA4-87B4-2F86417007FF}" = Java 7 Update 7 (64-bit)
    "{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel(R) Wireless Display
    "{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
    "{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    "{4BA33BE3-20CF-4972-BD67-B44CEFA52DCB}" = Windows Live MIME IFilter
    "{4F26C164-9373-4974-8F43-E0F2176AF937}" = Intel WiMAX Tutorial
    "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    "{6548B189-BEA4-4041-80E0-AEB60548E046}" = Intel® PROSet/Wireless WiMAX Software
    "{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
    "{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}" = HP Officejet 4500 G510n-z
    "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
    "{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
    "{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
    "{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
    "{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
    "{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
    "{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
    "{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
    "{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
    "{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
    "{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
    "{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
    "{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
    "{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUS_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
    "{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
    "{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
    "{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
    "{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
    "{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
    "{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
    "{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
    "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
    "{95140000-007A-0401-1000-0000000FF1CE}" = الإصدار 64 بت من Microsoft Outlook Hotmail Connector
    "{95140000-007A-0402-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector – 64-битова версия
    "{95140000-007A-0404-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 位元
    "{95140000-007A-0405-1000-0000000FF1CE}" = Doplněk Microsoft Outlook Hotmail Connector (64bitový)
    "{95140000-007A-0406-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-0407-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-Bit
    "{95140000-007A-0408-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-0409-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-040B-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-bittinen)
    "{95140000-007A-040C-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 bits
    "{95140000-007A-040D-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-040E-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bites
    "{95140000-007A-0410-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector a 64 bit
    "{95140000-007A-0412-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64비트
    "{95140000-007A-0413-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bits
    "{95140000-007A-0414-1000-0000000FF1CE}" = 64-biters Microsoft Outlook Hotmail Connector
    "{95140000-007A-0415-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (wersja 64-bitowa)
    "{95140000-007A-0416-1000-0000000FF1CE}" = Versão de 64 bits do Microsoft Outlook Hotmail Connector
    "{95140000-007A-0418-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-0419-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-разрядная версия)
    "{95140000-007A-041A-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64-bitni
    "{95140000-007A-041B-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64-bitová verzia
    "{95140000-007A-041D-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 bitar
    "{95140000-007A-041E-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64-bit
    "{95140000-007A-041F-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Bağlayıcısı 64 bit
    "{95140000-007A-0424-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector (64-bitna različica)
    "{95140000-007A-0426-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bitu
    "{95140000-007A-0427-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector, 64 bitai
    "{95140000-007A-0804-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector 64 位
    "{95140000-007A-0816-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector - versão de 64 bits
    "{95140000-007A-081A-1000-0000000FF1CE}" = 64-bitna verzija programa Microsoft Outlook Hotmail Connector
    "{95140000-007A-0C0A-1000-0000000FF1CE}" = Microsoft Outlook Hotmail Connector de 64 bits
    "{95140000-007D-0409-1000-0000000FF1CE}" = Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit
    "{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
    "{A4DDB2AB-ECCD-4C3A-8633-77D5A1A0E542}" = Network64
    "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
    "{ADDF4B84-5D28-4EAE-8511-EF808C8BC81C}" = HP Officejet 6500 E710n-z Basic Device Software
    "{AF162E20-417F-4946-A06D-65734984957F}" = Intel(R) PROSet/Wireless WiFi Software
    "{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.10
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.10
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus 1.0.11
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
    "{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
    "{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}" = Intel(R) Turbo Boost Technology Monitor 2.0
    "{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
    "{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
    "{DCAEC601-735C-41AE-B84F-D792F09FB7D1}" = WOT for Internet Explorer
    "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
    "{F842F8B0-6942-4930-821F-543E976B2C66}" = MSVCRT110_amd64
    "{FBBC4667-2521-4E78-B1BD-8706F774549B}" = Best Buy pc app
    "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
    "Elantech" = ETDWare PS/2-X64 8.0.7.2_WHQL
    "HP Document Manager" = HP Document Manager 2.0
    "HP Imaging Device Functions" = HP Imaging Device Functions 13.0
    "HP Smart Web Printing" = HP Smart Web Printing 4.5
    "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
    "HPExtendedCapabilities" = HP Customer Participation Program 13.0
    "HPOCR" = OCR Software by I.R.I.S. 13.0
    "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
    "Microsoft Security Client" = Microsoft Security Essentials
    "Office14.PROPLUS" = Microsoft Office Professional Plus 2010
    "ProInst" = Intel PROSet Wireless
    "Shop for HP Supplies" = Shop for HP Supplies
    "WinRAR archiver" = WinRAR 4.01 (64-bit)
     
  25. yeahisgood

    yeahisgood TS Rookie Topic Starter Posts: 74

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "{00D52195-38C5-46A3-9CBC-4104A1CD6608}" = Photo Common
    "{012B4B47-5ED6-469C-8CE3-8816248DD7DF}" = Photo Common
    "{0159A45D-DB64-454C-8DEE-037702F2FDF0}" = Poczta usługi Windows Live
    "{01C62BE2-E4D2-4B53-9584-1A91FB3E153D}" = Photo Common
    "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
    "{01FB4B77-9211-480E-8439-370C6DB71113}" = Windows Live Writer Resources
    "{0509A333-E819-400A-B5B8-1A474D96D58A}" = Windows Live UX Platform Language Pack
    "{05B093D6-140B-41EA-BC35-F611800E158D}" = Windows Live Writer Resources
    "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
    "{09C4F7A1-0AB6-477E-97BB-82FDA39DBD5D}" = Windows Live Mail
    "{0ADCA84C-4276-4619-B318-38BC606476B7}" = Windows Liven sähköposti
    "{0B32E306-13AA-4EAE-987B-3BD1A1EC0F12}" = Photo Common
    "{0B4A75B4-4C0E-4850-8F25-036B92408E1B}" = Windows Live Messenger
    "{0B5FDC99-E373-4F0F-938D-42AD090BACC0}" = Windows Live UX Platform Language Pack
    "{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
    "{0FBC0FEF-FAB2-465D-9F78-8AE1D0603559}" = Windows Live Messenger
    "{1057511B-F8FE-4230-9ED3-AB949A57EE4A}" = Windows Live PIMT Platform
    "{130E5108-547F-4482-91EE-F45C784E08C7}" = HP Officejet 6500 E710n-z Help
    "{142D8CA7-2C6F-45A7-83E3-099AAFD99133}" = Samsung Update Plus
    "{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}" = Samsung Recovery Solution 5
    "{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
    "{15C2E378-C1C9-4FE8-9F27-590726AEC593}" = Windows Live Writer Resources
    "{17283B95-21A8-4996-97DA-547A48DB266F}" = Easy Display Manager
    "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
    "{1789AE05-5298-492C-9A4D-CDD3A98AE6A1}" = Photo Common
    "{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
    "{1A2516F6-15CF-45F0-A14C-865742A647C3}" = Windows Live Messenger
    "{1B8F8F57-081B-4BEB-83A9-061C142018FF}" = Windows Live Writer Resources
    "{1C604122-1DF6-4142-A9E7-C60D6A978D82}" = Photo Common
    "{1DC65309-3556-4D72-BC22-0FDD529BE2EB}" = Windows Live Essentials
    "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
    "{20068443-0047-49D6-B25E-3322A56D7E2B}" = Windows Live UX Platform Language Pack
    "{20FCB655-FF69-4BFF-9300-68C0386A51A6}" = Windows Live UX Platform Language Pack
    "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
    "{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
    "{269304A7-84ED-429C-8509-7C6AE2F3D085}" = Windows Live Mail
    "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33
    "{26A24AE4-039D-4CA4-87B4-2F83217006FF}" = Java 7 Update 6
    "{27F0B692-6793-4631-A416-175A86440A04}" = Windows Live Writer Resources
    "{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
    "{29315CEC-E6CE-4394-84DC-6F862E8D9A52}" = Windows Live UX Platform
    "{29C1B1BF-BF0C-46B2-A1A5-5ED7EE0C266F}" = Windows Live UX Platform Language Pack
    "{2AE414B5-7FE6-49A3-93C8-D864162CDEBC}" = Windows Live UX Platform Language Pack
    "{2D416A80-0BB1-4D8B-B770-7BE8F53D5937}" = Windows Live UX Platform Language Pack
    "{2D598A54-750B-4120-B8AD-ED938F74932C}" = Windows Live Essentials
    "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
    "{2EEB5313-65AB-4C9B-B2FB-F1EDBFD18402}" = Windows Live Writer Resources
    "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
    "{2FAFE37E-D796-47B8-BA8F-D09819B12DF6}" = Windows Live Essentials
    "{2FBB11ED-EB28-45AC-BACF-4282EA24E8EA}" = Windows Live UX Platform Language Pack
    "{318DBE01-1E6B-4243-84B0-210391FE789A}" = Samsung AnyWeb Print
    "{3221ABB3-A940-4030-AA86-C0DA75BCD176}" = Windows Live UX Platform Language Pack
    "{331ECF61-69AF-4F57-AC35-AFED610231C3}" = Multimedia POP
    "{34A9A026-3421-4310-A97A-4D6FCD582275}" = Windows Live UX Platform Language Pack
    "{34D42BA7-804F-41CB-A7F5-6C1E5169422F}" = Windows Live UX Platform Language Pack
    "{36C704E9-C7FC-44C1-847E-DC9470414709}" = „Windows Live Essentials“
    "{37583C76-E48F-4AA4-BD2A-141A0830F799}" = Windows Live 메일
    "{377DE7D7-3C49-4D79-B23E-3E466096262E}" = Windows Live Writer Resources
    "{38547BC2-D932-4D3D-88DB-B0C33A34B469}" = Windows Live Messenger
    "{3A4D5E2D-988D-4ee9-8E7F-3AC200A2B8F5}" = 4500G510nz_Software_Min
    "{3C57F8BF-1ED1-43E7-A174-CA8B2613C8C0}" = Windows Live Writer Resources
    "{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel(R) Rapid Storage Technology
    "{3EAE58C0-7C36-40C3-ACED-0CABF2F46BCF}" = Windows Live Writer Resources
    "{3EF3A400-BC02-4345-AF19-297ED2D71DF4}" = Windows Live Messenger
    "{400CBE05-CC6E-4AD8-9596-289584AD7232}" = Windows Live Mail
    "{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
    "{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "{41FEC76C-9F4C-4A9A-B872-C605A4E04BBF}" = Photo Common
    "{4214AA76-A3A6-41FD-A8ED-DA2A5C533733}" = Windows Live UX Platform Language Pack
    "{437F2A1E-1C01-4EC5-BF32-61ED518D3BEB}" = Windows Live Pošta
    "{438C2993-99AA-43F7-BA0B-1A13A75E5426}" = Windows Live Writer Resources
    "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
    "{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
    "{44E89CCA-BB20-4EA6-80EB-4126E886F83D}" = Windows Live Mail
    "{45B29A59-D180-4BFC-A93D-DDD7E65647C8}" = Photo Common
    "{45FF1061-E2E3-4EDF-97A3-B87BB2ABBAC0}" = Windows Live Writer Resources
    "{46316411-80D8-4F68-8118-696E05FCE199}" = Windows Live Essentials
    "{4689F012-C8E3-4F6E-BDEF-13671D53A6DC}" = Windows Live UX Platform Language Pack
    "{46B14AF1-EDFA-4088-AB2B-22A8128A1C54}" = Photo Common
    "{48ADF615-F7E5-4805-8ABF-4FCB04A2BE58}" = Windows Live Mail
    "{491FCC06-244A-471D-974D-D7A59ED70B3F}" = „Windows Live Mail“
    "{49400307-EEC4-4C71-94C1-B419194F7290}" = Windows Live Writer Resources
    "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
    "{4A331D24-A9E8-484F-835E-1BA7B139689C}" = EasyBatteryManager
    "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
    "{4D60765A-2FF1-4848-BDFD-CEA79458F59B}" = Фотографии (общедоступная версия)
    "{4DAB6CA2-71C2-4B28-A4D4-5F6E62E44D93}" = Photo Common
    "{4F9A382F-4478-4036-905C-F77DF2EA0370}" = Windows Live SOXE
    "{4FA8F084-C42F-45E1-B7E5-E0C8A1083DC5}" = Windows Live SOXE Definitions
    "{5059436D-B480-494A-8F88-5CACFA883F2B}" = Windows Live Essentials
    "{510044D7-E70F-41C6-826A-A53C236B6FC5}" = Windows Live Writer Resources
    "{53EFA2AB-A58A-45BB-A044-47AC232FF0FE}" = Windows Live UX Platform Language Pack
    "{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
    "{547C128A-691D-4D09-B195-AC5194C07403}" = Windows Live Temel Parçalar
    "{54DF8219-0386-4577-B943-3E9807F0663B}" = Windows Live Mail
    "{55F84131-D974-4CDA-AD01-C7DDAA3F19F2}" = Windows Live UX Platform Language Pack
    "{5724CD7B-8AFC-4DE5-BF65-59272B22B25E}" = Windows Live Essentials
    "{57B0AA0C-3B99-435E-9CEC-2EF61CBCEF5F}" = Основные компоненты Windows Live
    "{57EC0BAF-E65F-4758-A6AB-586535C870A2}" = Windows Live Essentials
    "{5932CF7B-00D6-4B31-A849-554C3C68E0EB}" = Windows Live Essentials
    "{5B05FF91-F20C-4832-A8DE-E1912639C17C}" = 4500G510nz
    "{5BD54B96-C51E-4CE0-A507-1B606EE4364E}" = Photo Common
    "{5CC4C963-F772-4766-BFF2-DE551E205EE9}" = Photo Common
    "{5D382E05-9CFA-45A5-962B-8F578E7D3A23}" = Photo Common
    "{5D38A14D-8B90-434E-A28F-47A2279C0F40}" = ActiveState Komodo Edit 6.1.2
    "{5DBE54E2-C86B-4350-948B-461DC9FF6D20}" = Windows Live Messenger
    "{5F00227C-7D06-4CCE-A064-8C98787029FE}" = Windows Live Writer Resources
    "{60ADEF86-A867-47A0-9C8E-9B7E2AB3F87C}" = Windows Live Writer Resources
    "{618F39BD-9720-47CF-A89C-108AB41B1493}" = Windows Live UX Platform Language Pack
    "{62813F65-4D78-43AF-A53C-DFAFA122E065}" = Windows Live Messenger
    "{63240270-28DC-4CEB-B796-F3BBA966B1CA}" = Windows Live Messenger
    "{63535877-2396-4437-9BF5-C9BE41EE7677}" = Windows Live Essentials
    "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
    "{64DF7404-9D46-44AF-AFA1-A2F8D5648C2D}" = Windows Live Photo Common
    "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
    "{67E78A3A-617B-4DD1-975D-7100CF4AC9E6}" = Windows Live 软件包
    "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
    "{690879A5-18EF-447B-98D6-B699D51008AB}" = 4500_G510nz_Help
    "{698ED639-3A26-49EF-B1EF-CD89CB97C778}" = Windows Live Essentials
    "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
    "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
    "{6BF29613-DEEF-44BA-93C1-431B9723041C}" = Windows Live Mail
    "{6C016AC4-0282-4C82-B12F-3D5910DA7319}" = Samsung AnyWeb Print
    "{6DBC903D-396C-4389-9233-AC2DDB200994}" = Windows Live UX Platform Language Pack
    "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
    "{70243563-AFF3-4B6A-B267-05BA140BFBB2}" = Windows Live Essentials
    "{70D4BC7B-BA81-4385-B32E-045CB20C61DB}" = Windows Live Essentials
    "{70E5A613-5A04-42D9-B2CF-C99809BB6E0D}" = Windows Live Messenger
    "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
    "{71D1898F-DFAE-4E0F-B57A-97F5F557EA3A}" = Windows Live Messenger
    "{72E76708-0A4F-4586-9312-95A0CA8AD3D7}" = Windows Live Messenger
    "{749D0B62-5610-4ADE-82E6-399E6B4DAD80}" = Windows Live Writer Resources
    "{7541F284-7167-4729-B1C1-0A3F7FC38EF3}" = Windows Live Messenger
    "{76EE8FE7-1957-4C51-9074-4930A8CFB1AF}" = Windows Live Installer
    "{77F45ECD-FAFC-45A8-8896-CFFB139DAAA3}" = Fast Start
    "{78F35489-621D-4FFD-BCE7-2C7C3897E47C}" = Windows Live
    "{7914488D-F56B-464F-B735-F8E972E5E208}" = Photo Common
    "{799AF91B-A07A-4E5A-AFCF-EB1E45ADDD0D}" = Windows Live Messenger
    "{7A214298-DDD9-470E-895D-A8051ECA0093}" = Windows Live UX Platform Language Pack
    "{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
    "{7AEEF79F-4278-4510-AAD0-23AD14508217}" = Photo Common
    "{7CCDEF0B-C593-49F0-9A8F-C06F00DF2143}" = Photo Common
    "{7D212065-7CC7-4BE4-9084-A8C2C687A72F}" = Windows Live Mail
    "{7EC2E709-8ACC-48CA-9F67-2534C5C6A859}" = Windows Live Writer Resources
    "{7F2B444B-8D7D-4E46-A5D0-A3309B7B587A}" = Windows Live Essentials
    "{7F6F62F0-7884-4CFB-B86C-597A4A6D9C4D}" = Movie Color Enhancer
    "{7FF60141-ECA3-46F0-AB83-58FCC64F8935}" = Windows Live Messenger
    "{803D4B7D-71CD-46B9-8F89-8BFD73920FAF}" = Windows Live UX Platform Language Pack
    "{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
    "{83519650-D9E7-46E1-BC78-AE5BEC99D5FB}" = Windows Live Mail
    "{84BEAA30-1AF1-450B-9DD7-AD38B84004BA}" = Windows Live Messenger
    "{85AC15A4-3C6D-4DA5-9DCE-C3396905CF9E}" = Windows Live Writer Resources
    "{8698AFE8-285C-44EA-A282-13DBD7039F1C}" = Photo Common
    "{86F56921-A690-4FD8-87B6-7BEAC39D2500}" = Photo Common
    "{8732818E-CA78-4ACB-B077-22311BF4C0E4}" = Easy Network Manager
    "{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
    "{8BE01561-9570-47E3-8B7F-D6A80005B970}" = Windows Live Essentials
    "{8C5935EF-ECAD-4323-99B8-67AB6163D4D2}" = Photo Common
    "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
    "{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
    "{8E2E1D4E-1F96-4361-9A69-0F513E3A4A25}" = Windows Live Messenger
    "{8E5146B4-EC6A-4C5D-82B7-30F825FF1A91}" = Windows Live Writer Resources
    "{8F16159F-116C-4EC1-944C-DE491C8FFA4A}" = Windows Live Messenger
    "{90B936B2-33E6-4FE8-9A64-08EEB42AF2B1}" = Podstawowe programy Windows Live
    "{9268DD4E-72A7-410D-A6EC-DF510C1E4989}" = Windows Live Messenger
    "{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
    "{92D50865-FC60-4EA8-BA7A-5581B0D13EFB}" = ChargeableUSB
    "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
    "{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
    "{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
    "{954FC3E4-61C1-43BC-AB13-F0CCF145716D}" = Windows Live 程式集
    "{97373E60-D071-418A-87F1-A969EEEEBDAC}" = Windows Live Essentials
    "{976BD361-BD7C-49D5-8423-3E98DD480E1F}" = Windows Liven peruspaketti
    "{98994720-A230-4F45-875C-AD56E28448F1}" = Windows Live Mail
    "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    "{9A3997FD-359F-42B9-9C6F-82B8378BAAD8}" = Windows Live UX Platform Language Pack
    "{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
    "{9BC2BB12-8EB4-43D9-97D0-FE1BFCD25903}" = Windows Live Messenger
    "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    "{9CC77921-F397-43AE-8CA2-EDD0982BA25A}" = Windows Live Writer Resources
    "{9D4E75DB-519C-4A25-B8D1-97FB673E50C5}" = بريد Windows Live
    "{A0080F8F-06D3-4409-8148-59D53EE1CF25}" = Windows Live Essentials
    "{A013F3E3-5F8E-43E0-BBCE-BA76F69E457B}" = Windows Live Messenger
    "{A15FF85A-065C-4138-A934-113FDF8691EA}" = Windows Live Essentials
    "{A18C79C7-3D5D-457A-9C89-8B5F78F1FE56}" = Windows Live UX Platform Language Pack
    "{A29F0905-84B3-4D7C-8987-0F402BF1E78E}" = Windows Live Mail
    "{A35223E2-05BB-44D3-83A3-AF15C7ACD38D}" = Windows Live Writer Resources
    "{A399BFB9-2588-4903-B9E2-4F454BC0670D}" = Windows Live Messenger
    "{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
    "{A45B1FCC-C091-45F7-90DB-967421945319}" = Windows Live Messenger
    "{A4C39979-BBCA-4781-AE37-DDDE679E1F74}" = Windows Live Writer Resources
    "{A5163E8D-19B6-4AFD-A43B-9723A1796AE3}" = Windows Live Messenger
    "{A59DA39F-305C-44A0-9747-0646A31394CA}" = Windows Live Essentials
    "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
    "{AAA96570-FD87-4E07-87C6-7B3FA40A00A9}" = Windows Live Mail
    "{AAFCCC4E-587E-4493-9C11-AB75F208CF1B}" = Windows Live Writer Resources
    "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
    "{AD86049C-3D9C-43E1-BE73-643F57D83D50}" = Easy Migration
    "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
    "{AFDCB551-9506-41FB-ADBD-678321A0E5F6}" = Windows Live Mail
    "{AFFBC271-AA8F-4908-BEAE-491B96AC57C4}" = Windows Live Mail
    "{B23B230A-F9CD-4B6C-9202-24257A549CBB}" = Windows Live Writer Resources
    "{B25D84F2-16D6-42BB-BF24-158C7676D0B6}" = Windows Live Mail
    "{B27FA0A3-D80F-41A9-8BAD-C5F2D859AB22}" = Photo Common
    "{B2A814DF-B976-438D-92D0-54B53281F27F}" = Windows Live Writer Resources
    "{B410D843-920F-41AB-AE7F-F0C67498C113}" = Windows Live UX Platform Language Pack
    "{B417B07D-3373-458A-A431-0F7E3742F182}" = Почта Windows Live
    "{B6829511-95BB-46FC-9030-957D54B8EFE2}" = Windows Live UX Platform Language Pack
    "{B690AA36-1F69-469A-92DC-256688BD2568}" = Windows Live Mail
    "{B767B935-0E5F-4FF9-B758-71253603D93E}" = Windows Live Messenger
    "{B8292FC1-3D39-43A0-B65B-BADDA11151FB}" = Windows Live Essentials
    "{B89EE842-D398-4EAC-A3DF-47280B285DD9}" = Windows Live Mail
    "{B997C04C-DEED-4D49-8CEC-0EF040DF20CB}" = Photo Common
    "{BA73469B-D8C7-4FE3-B33C-1340D09F0709}" = Windows Live Communications Platform
    "{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}" = User Guide
    "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
    "{BD907BBE-3C60-4F5B-96C0-9F9D23890810}" = Photo Common
    "{BECFE8E0-4171-4562-8ED4-CBC4594204C9}" = Windows Live UX Platform Language Pack
    "{BFC0D53D-3B7F-42FF-9159-3821B593A0B7}" = Windows Live Mail
    "{C33EA3F2-015B-48EE-A3ED-AFFDDC19E74A}" = Windows Live Messenger
    "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
    "{C50ECBA4-CD35-47E6-B0A9-D22C8045B1F7}" = Windows Live Messenger
    "{C5335524-82F2-4C78-8A86-7B44AD1946FB}" = Windows Live Essentials
    "{C60589D9-9881-4ED8-AF7B-1F955542381F}" = Photo Common
    "{C782709A-0F72-4BCF-961B-3F40E2619A32}" = Windows Live Mail
    "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
    "{CBB00A31-1E0F-458C-BA15-0BAFF0567772}" = Windows Live Mail
    "{CDA04BEC-2F20-4E3C-A0E0-D75C8DE255D8}" = Windows Live Writer Resources
    "{D0873221-A48B-4A2F-9D34-5F0C21725CF5}" = Windows Live Mail
    "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
    "{D296620B-C85E-4890-A9B3-197A521B3457}" = Photo Common
    "{D436D212-1381-485A-BE46-32E1E2A95D98}" = Windows Live UX Platform Language Pack
    "{D48BCCD6-D2E2-42F4-B8E8-D7BC10C568EC}" = Windows Live UX Platform Language Pack
    "{D4C1DC3F-F1C4-4DAB-9DF9-73741965AB8E}" = Windows Live Essentials
    "{D531FC91-6F4E-49A7-B912-15289D05B6F8}" = Photo Common
    "{D555C389-F793-443A-B012-A3D70590CF3D}" = Windows Live Writer Resources
    "{D6C0EDA5-7E06-4F01-895D-B08BBE82AC82}" = Windows Live Mail
    "{D775D71D-C54B-41AE-97C2-EDEEBCA4FFCF}" = Windows Live Messenger
    "{D77A6FED-256C-4E2F-9873-59C92C854A4E}" = Photo Common
    "{D969C468-FCB8-4BFF-A480-33C0A6F7EA64}" = Windows Live Mail
    "{DB5D7E49-A671-4FCD-9708-3B2BC93DA995}" = Windows Live UX Platform Language Pack
    "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
    "{DC2CB432-D3B9-4F81-8ACB-7775FD5202E5}" = Photo Common
    "{DCCC9E33-B234-42D9-9321-F1B961D3568F}" = Windows Live Messenger
    "{DDDC459A-9197-40D6-A4A4-83C46A702550}" = „Windows Live Messenger“
    "{DE4E45CB-BA8F-4D82-81DA-22E93E522053}" = Photo Common
    "{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
    "{E044491E-D6E6-48C5-A5CC-BBFA96F19246}" = Windows Live Writer Resources
    "{E0970F37-1FFF-46D9-B2EB-43F2E1F01814}" = Windows Live Mail
    "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
    "{E13586CB-4E3A-41D3-BE97-2DA9C86CE6E9}" = Windows Live Writer Resources
    "{E1B7239A-120F-4676-9B19-D2B028BEBDD1}" = Windows Live Essentials
    "{E3B75D04-2C2B-4423-8800-BF8BF345E504}" = Photo Common
    "{E51363F9-BA22-4069-A5CB-B17A9EB06BB9}" = Windows Live UX Platform Language Pack
    "{E5E19577-2ECC-4C8E-A342-79D160A06097}" = Windows Live UX Platform Language Pack
    "{E60D9CA8-14A6-4F56-BA12-D9D8C8004E09}" = Windows Live Messenger
    "{E6B296EB-09A3-45A9-8580-949E28622E5B}" = Windows Live Essentials
    "{E9CA6D2F-30AF-48DB-8B29-6593AA68D61B}" = Windows Live UX Platform Language Pack
    "{E9E878AA-FF39-43EF-BDFE-01C17A0DD490}" = Windows Live Writer Resources
    "{EA53D435-3740-4513-A519-484D2BF659FA}" = Windows Live Writer Resources
    "{EA76E65F-6679-495A-A8A6-42AD6602ED4C}" = EasyFileShare
    "{EAE21C98-7208-46B6-A10F-9317E1AA63F8}" = Windows Live Messenger
    "{ECDAE6DC-6198-4102-96A7-29DA1085B79D}" = Windows Live Messenger
    "{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
    "{EF367AA4-070B-493C-9575-85BE59D789C9}" = Easy SpeedUp Manager
    "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    "{F0DA672E-15DB-4413-BE2D-887DD1513607}" = Windows Live Writer
    "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
    "{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
    "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
    "{F1CE08B9-2D76-40A3-8BE8-342FC15D62F6}" = Pošta Windows Live
    "{F3EECDE9-68D3-404D-A29B-9DFC72FE48F0}" = Windows Live Messenger
    "{F687E657-F636-44DF-8125-9FEEA2C362F5}" = Samsung Support Center 1.0
    "{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel(R) Wireless Display
    "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center
    "{F9328515-878F-4AB9-A113-104DD1A1F6EB}" = Photo Common
    "{F9E652C8-88D6-4056-B00A-DC3E4529A421}" = Windows Live UX Platform Language Pack
    "{FA2056CD-649B-4CB8-B180-61BF1C20E222}" = Photo Common
    "{FB76A294-A78A-4356-87C7-31F0278DF4FB}" = Windows Live 필수 패키지
    "{FC278470-09B6-4F42-A84A-58BAB03CA422}" = Windows Live Mail
    "{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
    "{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
    "{FDF614F8-710F-4C28-A90F-07A9BC82774D}" = Windows Live UX Platform Language Pack
    "{FE58D81E-30CE-4C73-9A52-28E886B62B91}" = Windows Live Writer Resources
    "{FECB76C1-1C1D-4A84-8D47-5754C74B5A5E}" = Junk Mail filter update
    "{FFD0E594-823B-4E2B-B680-720B3C852588}" = BatteryLifeExtender
    "{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger
    "8461-7759-5462-8226" = Vuze
    "Adobe AIR" = Adobe AIR
    "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
    "Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
    "Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.14 (Unicode)
    "ESET Online Scanner" = ESET Online Scanner v3
    "FileHippo.com" = FileHippo.com Update Checker
    "FileZilla Client" = FileZilla Client 3.5.3
    "Game Console - WildGames" = WildTangent ORB Game Console
    "HotspotShield" = Hotspot Shield 2.52
    "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
    "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite
    "InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
    "InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
    "InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
    "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
    "InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
    "IrfanView" = IrfanView (remove only)
    "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
    "Mozilla Firefox 14.0.1 (x86 en-US)" = Mozilla Firefox 14.0.1 (x86 en-US)
    "MozillaMaintenanceService" = Mozilla Maintenance Service
    "Samsung Universal Print Driver" = Samsung Universal Print Driver
    "Samsung Universal Scan Driver" = Samsung Universal Scan Driver
    "Secunia PSI" = Secunia PSI (3.0.0.2004)
    "VLC media player" = VLC media player 2.0.2
    "WildTangent wildgames Master Uninstall" = WildTangent Games
    "WinLiveSuite" = Windows Live Essentials
    "WT085559" = Diner Dash 2 Restaurant Rescue
    "WT085567" = Chuzzle Deluxe
    "WT085580" = John Deere Drive Green
    "WT085581" = Penguins!
    "WT085583" = Polar Golfer
    "WT085587" = Agatha Christie - Death on the Nile
    "WT085597" = Build-a-lot
    "WT085618" = Farm Frenzy
    "WT085622" = Insaniquarium Deluxe
    "WT085663" = Peggle
    "WT085669" = Plants vs. Zombies
    "WT089285" = Zuma Deluxe
    "WT089286" = Bejeweled 2 Deluxe

    ========== HKEY_USERS Uninstall List ==========

    [HKEY_USERS\S-1-5-21-2503403413-1387520261-2031820482-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
    "Google Chrome" = Google Chrome
    "SkyDriveSetup.exe" = Microsoft SkyDrive

    ========== Last 20 Event Log Errors ==========

    [ Application Events ]
    Error - 4/24/2012 9:52:32 AM | Computer Name = Owner-PC | Source = Application Error | ID = 1000
    Description = Faulting application name: Skype.exe, version: 5.8.0.158, time stamp:
    0x4f4de709 Faulting module name: Skype.exe, version: 5.8.0.158, time stamp: 0x4f4de709
    Exception
    code: 0xc0000005 Fault offset: 0x0087e49d Faulting process id: 0x12d4 Faulting application
    start time: 0x01cd21bb9501e9cd Faulting application path: C:\Program Files (x86)\Skype\Phone\Skype.exe
    Faulting
    module path: C:\Program Files (x86)\Skype\Phone\Skype.exe Report Id: bc9f6ec6-8e14-11e1-91c6-e811326191eb

    Error - 4/25/2012 12:48:29 PM | Computer Name = Owner-PC | Source = SideBySide | ID = 16842824
    Description = Activation context generation failed for "c:\program files\microsoft
    security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
    security client\MSESysprep.dll" on line 10. The element imaging appears as a child
    of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
    this version of Windows.

    Error - 4/27/2012 3:11:53 AM | Computer Name = Owner-PC | Source = Application Hang | ID = 1002
    Description = The program MSASCui.exe version 6.1.7600.16385 stopped interacting
    with Windows and was closed. To see if more information about the problem is available,
    check the problem history in the Action Center control panel. Process ID: 3e0 Start
    Time: 01cd244457a13c33 Termination Time: 0 Application Path: C:\Program Files\Windows
    Defender\MSASCui.exe Report Id: 3d13f061-9038-11e1-b7e2-e811326191eb

    Error - 4/27/2012 7:41:09 PM | Computer Name = Owner-PC | Source = Microsoft-Windows-RestartManager | ID = 10006
    Description = Application or service 'Windows Live Messenger' could not be shut
    down.

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
    Description =

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
    Description =

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
    Description =

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
    Description =

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 10005
    Description =

    Error - 4/27/2012 7:46:20 PM | Computer Name = Owner-PC | Source = MsiInstaller | ID = 1024
    Description =

    [ System Events ]
    Error - 9/11/2012 7:38:58 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2004
    Description = %%860 has encountered an error trying to load signatures and will
    attempt reverting back to a known-good set of signatures. Signatures Attempted: %%825
    Error
    Code: 0x80070002 Error description: The system cannot find the file specified. Signature
    version: 1.135.819.0;1.135.819.0 Engine version: 1.1.8704.0

    Error - 9/11/2012 7:39:06 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7003
    Description = The Hotspot Shield Service service depends the following service:
    taphss. This service might not be installed.

    Error - 9/11/2012 7:39:37 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the jjvop
    service to connect.

    Error - 9/11/2012 7:43:54 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 11.159.0.0 Update Source: %%815 Update Stage:
    %%854 Source Path: Signature Type: %%886 Update Type: %%803 User: NT AUTHORITY\SYSTEM
    Current
    Engine Version: Previous Engine Version: 2.0.8001.0 Error code: 0x80070002 Error
    description: The system cannot find the file specified.

    Error - 9/11/2012 7:43:54 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2003
    Description = %%860 has encountered an error trying to update the engine. New Engine
    Version: Previous Engine Version: 2.0.8001.0 Engine Type: %%886 User: NT AUTHORITY\SYSTEM
    Error
    Code: 0x80070002 Error description: The system cannot find the file specified.

    Error - 9/11/2012 7:43:58 PM | Computer Name = Owner-PC | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures. New Signature
    Version: Previous Signature Version: 1.135.1007.0 Update Source: %%859 Update Stage:
    %%854 Source Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803
    User:
    NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8704.0 Error
    code: 0x80070643 Error description: Fatal error during installation.

    Error - 9/11/2012 7:44:09 PM | Computer Name = Owner-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
    Description = Installation Failure: Windows failed to install the following update
    with error 0x80070643: Definition Update for Microsoft Security Essentials - KB2310138
    (Definition 1.135.1007.0).

    Error - 9/11/2012 7:56:10 PM | Computer Name = Owner-PC | Source = BROWSER | ID = 8032
    Description =

    Error - 9/11/2012 8:23:35 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7003
    Description = The Hotspot Shield Service service depends the following service:
    taphss. This service might not be installed.

    Error - 9/11/2012 8:24:09 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7009
    Description = A timeout was reached (30000 milliseconds) while waiting for the jjvop
    service to connect.


    < End of report >
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.