Solved Virus cleanup for Win 7 fake antivirus

jamesc118

Posts: 21   +0
My sister's laptop (Win 7 32bit) got infected by multiple viruses, and after doing what she could to fix it (like running tddskiller), she gave it to me to play with. After doing what I could to fix it (rkill, Malwarebytes, Kaspersky virus removal tool, McAfee), I am asking for help.
The problems it still has are: Windows security center will not run; McAfee firewall will not stay on; browsers redirect to spam sites randomly.
I have tried to follow the five steps, with limited success.

1. Full McAfee scan
2. Full Malwarebyte's scan
3. GMER. I did some other stuff after running this scan, and tried again right before posting this. It gave these errors the second time:
Code:
LoadDriveer("C:\Users\{user}\AppData\Local\Temp\kxldqpow.sys")
error 0xC000010E: An instance of the service is already running.

C:\windows\system32\config\system: The process cannot access he file because it is being used by another process.

C:\Users\{user}\ntuser.dat: The process cannot access he file because it is being used by another process.

GMER hasn't found any system modification.

4. DDS by sUBs. Each time I tried to run this, it froze the computer to the point it had to be reset.

5. Submitting logs:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-01 13:54:56
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Sarah\AppData\Local\Temp\kxldqpow.sys


---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\ec55f942cee4
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\ec55f9b4b4dc
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\ec55f942cee4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\ec55f9b4b4dc (not active ControlSet)

---- Files - GMER 1.0.15 ----

File C:\Users\Sarah\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDX0ZY2S\down[1] 0 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022 0 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\@ 2048 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\bckfg.tmp 845 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\cfg.ini 199 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\keywords 0 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\L 0 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\L\xadqgnnk 187904 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U 0 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\80000000.@ 11264 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB19606$\1902657022\U\80000032.@ 97792 bytes
File C:\Windows\$NtUninstallKB19606$\3069654774 0 bytes

---- EOF - GMER 1.0.15 ----
 
Malwarebyte's log

Whoops, here's the other log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2011.12.24.05

Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Sarah :: WRITER [administrator]

12/31/2011 11:07:57 AM
mbam-log-2011-12-31 (11-07-57).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 264566
Time elapsed: 1 hour(s), 35 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCR\wr (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Detected: 9
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|995.exe (Malware.Packer) -> Data: C:\Program Files\LP\A477\995.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|YgggTXqqjY (Trojan.Dropper.PE4) -> Data: C:\Users\Sarah\AppData\Roaming\dwme.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|5F9.exe (Trojan.Dropper.PE4) -> Data: C:\Users\Sarah\AppData\Roaming\Microsoft\4DB7\5F9.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|995.exe (Malware.Packer) -> Data: C:\Users\Sarah\AppData\Roaming\Microsoft\A477\995.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Backdoor.CycBot) -> Data: C:\Users\Sarah\AppData\Roaming\D6E65\lvvm.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell (Hijack.Shell.Gen) -> Data: explorer.exe,C:\Users\Sarah\AppData\Roaming\78CD6\859A4.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ATI (Trojan.Agent) -> Data: C:\Users\Sarah\AppData\Roaming\csrss.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|jhhTTXwjjUelIrP8234A (Trojan.FakeAlert.CLGen) -> Data: C:\windows\system32\AV Security 2012v121.exe -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupd (Trojan.Agent) -> Data: C:\Users\Sarah\AppData\Local\Temp:winupd.exe -> Quarantined and deleted successfully.

Registry Data Items Detected: 3
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|Load (Spyware.Password) -> Bad: (C:\Users\Sarah\AppData\Roaming\D6E65\lvvm.exe) Good: () -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 22
C:\Users\Sarah\AppData\Local\bhy.exe (Trojan.FakeAV) -> No action taken.
C:\Program Files\LP\A477\995.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\dwme.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\4DB7\5F9.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\A477\995.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\D6E65\lvvm.exe (Spyware.Password) -> Quarantined and deleted successfully.
C:\ProgramData\gfhYdHclcK.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
C:\ProgramData\l6j26BwDtcD5Va.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\ywerrtyerw.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\wmplayer.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\firefox.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\iexplore.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\java.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\78CD6\859A4.exe (Spyware.Password) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\78CD6\B4B4D.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\4DC7\5F9.exe (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\A477\E0AD.tmp (Trojan.Dropper.PE4) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\Microsoft\A477\F8C2.exe (Malware.Packer) -> Quarantined and deleted successfully.
C:\Users\Sarah\Desktop\Privacy Protection.lnk (Malware.Trace) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Local\Temp\wera0.08702821218245271.exe (Exploit.Drop.6) -> Quarantined and deleted successfully.
C:\Users\Sarah\AppData\Roaming\ldr.ini (Malware.Trace) -> Quarantined and deleted successfully.
c:\users\sarah\appdata\local\temp:winupd.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)
 
Welcome aboard
yahooo.gif


Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running tools or applying updates other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

===============================================================

Your MBAM version is outdated.
Update, run new scan and post fresh log.

When done attempt DDS one more time.
 
Nothing new

It didn't come up with anything new... I'll attempt to run DDS again anyway and let you know. In case you want it, here's the mbam log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.09.08

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
Sarah :: WRITER [administrator]

1/9/2012 4:16:52 PM
mbam-log-2012-01-09 (16-16-52).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 281266
Time elapsed: 54 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 
DDS still freezes the computer. DDS says to disable anything that might block scripts... just in case, I have been disabling McAfee before I run DDS. Is there anything else that I should be turning off?
 
Download TDSSKiller and save it to your desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
 
tddskiller

It came up clean. Here's the report:
11:59:22.0700 4676 TDSS rootkit removing tool 2.7.0.0 Jan 10 2012 09:14:26
11:59:24.0141 4676 ============================================================
11:59:24.0141 4676 Current date / time: 2012/01/10 11:59:24.0141
11:59:24.0141 4676 SystemInfo:
11:59:24.0142 4676
11:59:24.0142 4676 OS Version: 6.1.7600 ServicePack: 0.0
11:59:24.0142 4676 Product type: Workstation
11:59:24.0143 4676 ComputerName: WRITER
11:59:24.0149 4676 UserName: Sarah
11:59:24.0149 4676 Windows directory: C:\windows
11:59:24.0149 4676 System windows directory: C:\windows
11:59:24.0149 4676 Processor architecture: Intel x86
11:59:24.0149 4676 Number of processors: 2
11:59:24.0149 4676 Page size: 0x1000
11:59:24.0149 4676 Boot type: Normal boot
11:59:24.0149 4676 ============================================================
11:59:26.0127 4676 Drive \Device\Harddisk0\DR0 - Size: 0x7745D6000, SectorSize: 0x200, Cylinders: 0xF34, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K', Flags 0x00000050
11:59:26.0138 4676 Initialize success
11:59:45.0929 5920 ============================================================
11:59:45.0929 5920 Scan started
11:59:45.0929 5920 Mode: Manual;
11:59:45.0929 5920 ============================================================
11:59:46.0272 5920 11959207 (186b54479d98e48aee0e9ada4b3c4d31) C:\windows\system32\DRIVERS\11959207.sys
11:59:46.0288 5920 11959207 - ok
11:59:46.0319 5920 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
11:59:46.0350 5920 1394ohci - ok
11:59:46.0381 5920 84347022 (186b54479d98e48aee0e9ada4b3c4d31) C:\windows\system32\DRIVERS\84347022.sys
11:59:46.0381 5920 84347022 - ok
11:59:46.0428 5920 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
11:59:46.0444 5920 ACPI - ok
11:59:46.0459 5920 acpials (79d6b28027c398b728ce7cd0570248b0) C:\windows\system32\DRIVERS\acpials.sys
11:59:46.0490 5920 acpials - ok
11:59:46.0506 5920 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
11:59:46.0537 5920 AcpiPmi - ok
11:59:46.0568 5920 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
11:59:46.0615 5920 adp94xx - ok
11:59:46.0646 5920 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
11:59:46.0678 5920 adpahci - ok
11:59:46.0724 5920 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
11:59:46.0771 5920 adpu320 - ok
11:59:46.0834 5920 AFD (0db7a48388d54d154ebec120461a0fcd) C:\windows\system32\drivers\afd.sys
11:59:46.0834 5920 AFD - ok
11:59:46.0865 5920 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
11:59:46.0896 5920 agp440 - ok
11:59:46.0927 5920 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
11:59:46.0943 5920 aic78xx - ok
11:59:46.0990 5920 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
11:59:47.0021 5920 aliide - ok
11:59:47.0052 5920 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
11:59:47.0083 5920 amdagp - ok
11:59:47.0114 5920 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
11:59:47.0130 5920 amdide - ok
11:59:47.0161 5920 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
11:59:47.0177 5920 AmdK8 - ok
11:59:47.0411 5920 amdkmdag (e55945478d9a7f652741ae88d0c71794) C:\windows\system32\DRIVERS\atikmdag.sys
11:59:47.0972 5920 amdkmdag - ok
11:59:48.0019 5920 amdkmdap (cfb28043a973dba2125451ce0ffcf7d9) C:\windows\system32\DRIVERS\atikmpag.sys
11:59:48.0035 5920 amdkmdap - ok
11:59:48.0066 5920 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
11:59:48.0066 5920 AmdPPM - ok
11:59:48.0113 5920 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\windows\system32\drivers\amdsata.sys
11:59:48.0534 5920 amdsata - ok
11:59:48.0565 5920 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
11:59:48.0581 5920 amdsbs - ok
11:59:48.0612 5920 amdxata (869e67d66be326a5a9159fba8746fa70) C:\windows\system32\drivers\amdxata.sys
11:59:48.0612 5920 amdxata - ok
11:59:48.0643 5920 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
11:59:48.0643 5920 AppID - ok
11:59:48.0690 5920 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
11:59:48.0706 5920 arc - ok
11:59:48.0737 5920 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
11:59:48.0768 5920 arcsas - ok
11:59:48.0784 5920 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
11:59:48.0799 5920 AsyncMac - ok
11:59:48.0830 5920 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
11:59:48.0830 5920 atapi - ok
11:59:48.0862 5920 AthBTPort (882edbafcc227852c9dca23ea48d2e78) C:\windows\system32\DRIVERS\btath_flt.sys
11:59:49.0033 5920 AthBTPort - ok
11:59:49.0142 5920 athr (d3ad5858a58668c65fbf6ea436b3a8ff) C:\windows\system32\DRIVERS\athr.sys
11:59:49.0423 5920 athr - ok
11:59:49.0470 5920 AtiHDAudioService (95b1e9804ca10d096c0383f7c6684950) C:\windows\system32\drivers\AtihdW73.sys
11:59:49.0891 5920 AtiHDAudioService - ok
11:59:49.0954 5920 AX88772B (2c795db1b509279ac18fe9e5635e3313) C:\windows\system32\DRIVERS\ax88772b.sys
11:59:49.0969 5920 AX88772B - ok
11:59:50.0016 5920 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
11:59:50.0047 5920 b06bdrv - ok
11:59:50.0078 5920 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
11:59:50.0110 5920 b57nd60x - ok
11:59:50.0172 5920 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
11:59:50.0188 5920 Beep - ok
11:59:50.0219 5920 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
11:59:50.0250 5920 blbdrive - ok
11:59:50.0281 5920 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\windows\system32\DRIVERS\bowser.sys
11:59:50.0297 5920 bowser - ok
11:59:50.0328 5920 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
11:59:50.0344 5920 BrFiltLo - ok
11:59:50.0375 5920 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
11:59:50.0406 5920 BrFiltUp - ok
11:59:50.0453 5920 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
11:59:50.0468 5920 Brserid - ok
11:59:50.0500 5920 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
11:59:50.0515 5920 BrSerWdm - ok
11:59:50.0546 5920 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
11:59:50.0562 5920 BrUsbMdm - ok
11:59:50.0578 5920 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
11:59:50.0609 5920 BrUsbSer - ok
11:59:50.0640 5920 BST (664e7861a289e1bbf75be2d6b02be40f) C:\windows\system32\DRIVERS\bma150.sys
11:59:50.0858 5920 BST - ok
11:59:50.0890 5920 BTATH_A2DP (d57bc943ed4ef85a51165f408e4c15a7) C:\windows\system32\drivers\btath_a2dp.sys
11:59:51.0139 5920 BTATH_A2DP - ok
11:59:51.0170 5920 BTATH_BUS (f60e0c722442ea91f0c253b7814d8192) C:\windows\system32\DRIVERS\btath_bus.sys
11:59:51.0186 5920 BTATH_BUS - ok
11:59:51.0217 5920 BTATH_HCRP (f31e369db8258b28e3dcf66705aea9e9) C:\windows\system32\DRIVERS\btath_hcrp.sys
11:59:51.0467 5920 BTATH_HCRP - ok
11:59:51.0498 5920 BTATH_LWFLT (6651798266fde23159d961463a63a77d) C:\windows\system32\DRIVERS\btath_lwflt.sys
11:59:51.0701 5920 BTATH_LWFLT - ok
11:59:51.0732 5920 BTATH_RCP (08ef5298df80bc136523bcd2ed8b9c37) C:\windows\system32\DRIVERS\btath_rcp.sys
11:59:51.0935 5920 BTATH_RCP - ok
11:59:51.0982 5920 BtFilter (6c692b2920d0e1b2fdb19329b7d69c6a) C:\windows\system32\DRIVERS\btfilter.sys
11:59:52.0387 5920 BtFilter - ok
11:59:52.0418 5920 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\drivers\BthEnum.sys
11:59:52.0434 5920 BthEnum - ok
11:59:52.0465 5920 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
11:59:52.0496 5920 BTHMODEM - ok
11:59:52.0528 5920 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
11:59:52.0559 5920 BthPan - ok
11:59:52.0590 5920 BTHPORT (88059ff1ded4472acd17eebabd393069) C:\windows\System32\Drivers\BTHport.sys
11:59:52.0762 5920 BTHPORT - ok
11:59:52.0793 5920 BTHUSB (80e6384beec03b8bd45edea29802d657) C:\windows\System32\Drivers\BTHUSB.sys
11:59:53.0198 5920 BTHUSB - ok
11:59:53.0245 5920 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
11:59:53.0276 5920 cdfs - ok
11:59:53.0308 5920 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
11:59:53.0339 5920 cdrom - ok
11:59:53.0370 5920 cfwids (1dcb5209601a70e36c70fe8d197d62cb) C:\windows\system32\drivers\cfwids.sys
11:59:53.0557 5920 cfwids - ok
11:59:53.0588 5920 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
11:59:53.0604 5920 circlass - ok
11:59:53.0635 5920 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
11:59:53.0651 5920 CLFS - ok
11:59:53.0682 5920 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
11:59:53.0698 5920 CmBatt - ok
11:59:53.0744 5920 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
11:59:53.0760 5920 cmdide - ok
11:59:53.0791 5920 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
11:59:53.0807 5920 CNG - ok
11:59:53.0838 5920 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
11:59:53.0854 5920 Compbatt - ok
11:59:53.0869 5920 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
11:59:53.0885 5920 CompositeBus - ok
11:59:54.0010 5920 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
11:59:54.0025 5920 crcdisk - ok
11:59:54.0103 5920 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\windows\system32\Drivers\dfsc.sys
11:59:54.0103 5920 DfsC - ok
11:59:54.0150 5920 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
11:59:54.0150 5920 discache - ok
11:59:54.0181 5920 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
11:59:54.0181 5920 Disk - ok
11:59:54.0244 5920 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
11:59:54.0275 5920 drmkaud - ok
11:59:54.0337 5920 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
11:59:54.0602 5920 DXGKrnl - ok
11:59:54.0743 5920 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
11:59:54.0868 5920 ebdrv - ok
11:59:54.0946 5920 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
11:59:54.0992 5920 elxstor - ok
11:59:55.0024 5920 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
11:59:55.0039 5920 ErrDev - ok
11:59:55.0102 5920 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
11:59:55.0133 5920 exfat - ok
11:59:55.0164 5920 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
11:59:55.0180 5920 fastfat - ok
11:59:55.0226 5920 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
11:59:55.0226 5920 fdc - ok
11:59:55.0289 5920 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
11:59:55.0289 5920 FileInfo - ok
11:59:55.0320 5920 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
11:59:55.0336 5920 Filetrace - ok
11:59:55.0367 5920 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
11:59:55.0382 5920 flpydisk - ok
11:59:55.0414 5920 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
11:59:55.0429 5920 FltMgr - ok
11:59:55.0476 5920 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
11:59:55.0492 5920 FsDepends - ok
11:59:55.0523 5920 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
11:59:55.0538 5920 Fs_Rec - ok
11:59:55.0570 5920 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys
11:59:55.0585 5920 fvevol - ok
11:59:55.0601 5920 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
11:59:55.0632 5920 gagp30kx - ok
11:59:55.0694 5920 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
11:59:55.0726 5920 hcw85cir - ok
11:59:55.0772 5920 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
11:59:55.0788 5920 HdAudAddService - ok
11:59:55.0819 5920 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
11:59:55.0835 5920 HDAudBus - ok
11:59:55.0866 5920 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
11:59:55.0866 5920 HidBatt - ok
11:59:55.0913 5920 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
11:59:55.0928 5920 HidBth - ok
11:59:55.0960 5920 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
11:59:55.0975 5920 HidIr - ok
11:59:56.0022 5920 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
11:59:56.0053 5920 HidUsb - ok
11:59:56.0116 5920 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
11:59:56.0131 5920 HpSAMD - ok
11:59:56.0178 5920 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
11:59:56.0194 5920 HTTP - ok
11:59:56.0225 5920 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
11:59:56.0225 5920 hwpolicy - ok
11:59:56.0272 5920 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
11:59:56.0287 5920 i8042prt - ok
11:59:56.0318 5920 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\windows\system32\drivers\iaStorV.sys
11:59:56.0786 5920 iaStorV - ok
11:59:56.0833 5920 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
11:59:56.0864 5920 iirsp - ok
11:59:57.0020 5920 IntcAzAudAddService (0859200f021ba9c30b270d8397555605) C:\windows\system32\drivers\RTKVHDA.sys
11:59:57.0348 5920 IntcAzAudAddService - ok
11:59:57.0379 5920 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
11:59:57.0379 5920 intelide - ok
11:59:57.0410 5920 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
11:59:57.0442 5920 intelppm - ok
11:59:57.0488 5920 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
11:59:57.0504 5920 IpFilterDriver - ok
11:59:57.0535 5920 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
11:59:57.0551 5920 IPMIDRV - ok
11:59:57.0582 5920 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
11:59:57.0598 5920 IPNAT - ok
11:59:57.0629 5920 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
11:59:57.0644 5920 IRENUM - ok
11:59:57.0660 5920 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
11:59:57.0691 5920 isapnp - ok
11:59:57.0754 5920 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
11:59:57.0785 5920 iScsiPrt - ok
11:59:57.0816 5920 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
11:59:57.0832 5920 kbdclass - ok
11:59:57.0847 5920 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
11:59:57.0863 5920 kbdhid - ok
11:59:57.0910 5920 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
11:59:57.0910 5920 KSecDD - ok
11:59:57.0956 5920 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
11:59:57.0956 5920 KSecPkg - ok
11:59:58.0050 5920 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
11:59:58.0081 5920 lltdio - ok
11:59:58.0144 5920 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
11:59:58.0175 5920 LSI_FC - ok
11:59:58.0206 5920 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
11:59:58.0237 5920 LSI_SAS - ok
11:59:58.0268 5920 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
11:59:58.0300 5920 LSI_SAS2 - ok
11:59:58.0331 5920 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
11:59:58.0346 5920 LSI_SCSI - ok
11:59:58.0393 5920 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
11:59:58.0393 5920 luafv - ok
11:59:58.0424 5920 MBAMSwissArmy - ok
11:59:58.0627 5920 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
11:59:58.0643 5920 megasas - ok
11:59:58.0690 5920 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
11:59:58.0705 5920 MegaSR - ok
11:59:58.0736 5920 mfeapfk (36b47b1e9c537f8f2b4481084b8f7d22) C:\windows\system32\drivers\mfeapfk.sys
11:59:58.0752 5920 mfeapfk - ok
11:59:58.0783 5920 mfeavfk (cde41293db871a75cd99eb0ce781356b) C:\windows\system32\drivers\mfeavfk.sys
11:59:59.0033 5920 mfeavfk - ok
11:59:59.0064 5920 mfeavfk01 - ok
11:59:59.0095 5920 mfebopk (e22385f64bdf0ad81157479496e33c4a) C:\windows\system32\drivers\mfebopk.sys
11:59:59.0111 5920 mfebopk - ok
11:59:59.0173 5920 mfefirek (215666a8a85023ef019b510cbb67f678) C:\windows\system32\drivers\mfefirek.sys
11:59:59.0423 5920 mfefirek - ok
11:59:59.0470 5920 mfehidk (56d330981866a72f061dd16cc5004513) C:\windows\system32\drivers\mfehidk.sys
11:59:59.0485 5920 mfehidk - ok
11:59:59.0516 5920 mfenlfk (b41bacc049cdb916a52b1448bf30d6ab) C:\windows\system32\DRIVERS\mfenlfk.sys
11:59:59.0750 5920 mfenlfk - ok
11:59:59.0782 5920 mferkdet (89b564d63c53fc0c6782ab07eea63acf) C:\windows\system32\drivers\mferkdet.sys
11:59:59.0782 5920 mferkdet - ok
11:59:59.0828 5920 mfewfpk (c2ff7473a60c0fb2df145ab686889653) C:\windows\system32\drivers\mfewfpk.sys
11:59:59.0844 5920 mfewfpk - ok
11:59:59.0891 5920 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
11:59:59.0906 5920 Modem - ok
11:59:59.0938 5920 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
11:59:59.0953 5920 monitor - ok
11:59:59.0984 5920 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
11:59:59.0984 5920 mouclass - ok
12:00:00.0016 5920 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
12:00:00.0031 5920 mouhid - ok
12:00:00.0062 5920 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
12:00:00.0078 5920 mountmgr - ok
12:00:00.0109 5920 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
12:00:00.0140 5920 mpio - ok
12:00:00.0172 5920 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
12:00:00.0187 5920 mpsdrv - ok
12:00:00.0218 5920 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
12:00:00.0250 5920 MRxDAV - ok
12:00:00.0281 5920 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\windows\system32\DRIVERS\mrxsmb.sys
12:00:00.0281 5920 mrxsmb - ok
12:00:00.0328 5920 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\windows\system32\DRIVERS\mrxsmb10.sys
12:00:00.0343 5920 mrxsmb10 - ok
12:00:00.0359 5920 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\windows\system32\DRIVERS\mrxsmb20.sys
12:00:00.0780 5920 mrxsmb20 - ok
12:00:00.0811 5920 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
12:00:00.0811 5920 msahci - ok
12:00:00.0842 5920 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
12:00:00.0874 5920 msdsm - ok
12:00:00.0920 5920 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
12:00:00.0936 5920 Msfs - ok
12:00:00.0967 5920 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
12:00:00.0983 5920 mshidkmdf - ok
12:00:01.0014 5920 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
12:00:01.0014 5920 msisadrv - ok
12:00:01.0061 5920 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
12:00:01.0092 5920 MSKSSRV - ok
12:00:01.0108 5920 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
12:00:01.0139 5920 MSPCLOCK - ok
12:00:01.0170 5920 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
12:00:01.0186 5920 MSPQM - ok
12:00:01.0217 5920 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
12:00:01.0232 5920 MsRPC - ok
12:00:01.0279 5920 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
12:00:01.0279 5920 mssmbios - ok
12:00:01.0310 5920 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
12:00:01.0342 5920 MSTEE - ok
12:00:01.0357 5920 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
12:00:01.0373 5920 MTConfig - ok
12:00:01.0404 5920 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
12:00:01.0420 5920 Mup - ok
12:00:01.0466 5920 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
12:00:01.0498 5920 NativeWifiP - ok
12:00:01.0560 5920 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
12:00:01.0576 5920 NDIS - ok
12:00:01.0607 5920 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
12:00:01.0638 5920 NdisCap - ok
12:00:01.0669 5920 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
12:00:01.0685 5920 NdisTapi - ok
12:00:01.0716 5920 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
12:00:01.0747 5920 Ndisuio - ok
12:00:01.0778 5920 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
12:00:01.0810 5920 NdisWan - ok
12:00:01.0841 5920 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
12:00:01.0856 5920 NDProxy - ok
12:00:01.0888 5920 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
12:00:01.0888 5920 NetBIOS - ok
12:00:01.0934 5920 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
12:00:01.0950 5920 NetBT - ok
12:00:02.0028 5920 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
12:00:02.0044 5920 nfrd960 - ok
12:00:02.0090 5920 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
12:00:02.0090 5920 Npfs - ok
12:00:02.0137 5920 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
12:00:02.0137 5920 nsiproxy - ok
12:00:02.0215 5920 Ntfs (187002ce05693c306f43c873f821381f) C:\windows\system32\drivers\Ntfs.sys
12:00:02.0262 5920 Ntfs - ok
12:00:02.0293 5920 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\drivers\NTIDrvr.sys
12:00:02.0714 5920 NTIDrvr - ok
12:00:02.0746 5920 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
12:00:02.0746 5920 Null - ok
12:00:02.0777 5920 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\windows\system32\drivers\nvraid.sys
12:00:03.0011 5920 nvraid - ok
12:00:03.0042 5920 nvstor (4520b63899e867f354ee012d34e11536) C:\windows\system32\drivers\nvstor.sys
12:00:03.0494 5920 nvstor - ok
12:00:03.0526 5920 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
12:00:03.0541 5920 nv_agp - ok
12:00:03.0557 5920 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
12:00:03.0604 5920 ohci1394 - ok
12:00:03.0650 5920 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
12:00:03.0697 5920 Parport - ok
12:00:03.0728 5920 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
12:00:03.0728 5920 partmgr - ok
12:00:03.0760 5920 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
12:00:03.0775 5920 Parvdm - ok
12:00:03.0838 5920 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
12:00:03.0838 5920 pci - ok
12:00:03.0884 5920 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
12:00:03.0916 5920 pciide - ok
12:00:03.0947 5920 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
12:00:03.0978 5920 pcmcia - ok
12:00:04.0009 5920 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
12:00:04.0009 5920 pcw - ok
12:00:04.0072 5920 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
12:00:04.0118 5920 PEAUTH - ok
12:00:04.0290 5920 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
12:00:04.0306 5920 PptpMiniport - ok
12:00:04.0352 5920 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
12:00:04.0368 5920 Processor - ok
12:00:04.0430 5920 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
12:00:04.0430 5920 Psched - ok
12:00:04.0493 5920 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
12:00:04.0571 5920 ql2300 - ok
12:00:04.0586 5920 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
12:00:04.0602 5920 ql40xx - ok
12:00:04.0649 5920 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
12:00:04.0649 5920 QWAVEdrv - ok
12:00:04.0680 5920 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
12:00:04.0711 5920 RasAcd - ok
12:00:04.0742 5920 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
12:00:04.0758 5920 RasAgileVpn - ok
12:00:04.0805 5920 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
12:00:04.0820 5920 Rasl2tp - ok
12:00:04.0852 5920 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
12:00:04.0883 5920 RasPppoe - ok
12:00:04.0914 5920 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
12:00:04.0930 5920 RasSstp - ok
12:00:04.0976 5920 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
12:00:04.0976 5920 rdbss - ok
12:00:05.0008 5920 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
12:00:05.0023 5920 rdpbus - ok
12:00:05.0054 5920 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
12:00:05.0054 5920 RDPCDD - ok
12:00:05.0117 5920 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
12:00:05.0117 5920 RDPENCDD - ok
12:00:05.0164 5920 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
12:00:05.0164 5920 RDPREFMP - ok
12:00:05.0210 5920 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
12:00:05.0242 5920 RDPWD - ok
12:00:05.0273 5920 rdyboost (65db288f7372b1f632891fc32bf908b7) C:\windows\system32\drivers\rdyboost.sys
12:00:05.0288 5920 rdyboost - ok
12:00:05.0351 5920 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
12:00:05.0366 5920 RFCOMM - ok
12:00:05.0429 5920 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
12:00:05.0460 5920 rspndr - ok
12:00:05.0507 5920 RSUSBSTOR (247b0a8164069cd4fe6f3094c581b13b) C:\windows\system32\Drivers\RtsUStor.sys
12:00:05.0928 5920 RSUSBSTOR - ok
12:00:05.0990 5920 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
12:00:06.0022 5920 sbp2port - ok
12:00:06.0068 5920 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
12:00:06.0084 5920 scfilter - ok
12:00:06.0146 5920 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
12:00:06.0162 5920 secdrv - ok
12:00:06.0224 5920 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
12:00:06.0240 5920 Serenum - ok
12:00:06.0271 5920 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
12:00:06.0302 5920 Serial - ok
12:00:06.0318 5920 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
12:00:06.0334 5920 sermouse - ok
12:00:06.0396 5920 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
12:00:06.0412 5920 sffdisk - ok
12:00:06.0443 5920 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
12:00:06.0474 5920 sffp_mmc - ok
12:00:06.0490 5920 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\windows\system32\DRIVERS\sffp_sd.sys
12:00:06.0692 5920 sffp_sd - ok
12:00:06.0724 5920 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
12:00:06.0755 5920 sfloppy - ok
12:00:06.0802 5920 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
12:00:06.0817 5920 sisagp - ok
12:00:06.0848 5920 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
12:00:06.0864 5920 SiSRaid2 - ok
12:00:06.0895 5920 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
12:00:06.0911 5920 SiSRaid4 - ok
12:00:06.0942 5920 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
12:00:06.0958 5920 Smb - ok
12:00:07.0020 5920 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
12:00:07.0036 5920 spldr - ok
12:00:07.0114 5920 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\windows\system32\DRIVERS\srv.sys
12:00:07.0129 5920 srv - ok
12:00:07.0160 5920 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\windows\system32\DRIVERS\srv2.sys
12:00:07.0457 5920 srv2 - ok
12:00:07.0504 5920 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\windows\system32\DRIVERS\srvnet.sys
12:00:07.0504 5920 srvnet - ok
12:00:07.0566 5920 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
12:00:07.0582 5920 stexstor - ok
12:00:07.0628 5920 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
12:00:07.0644 5920 swenum - ok
12:00:07.0753 5920 Tcpip (56c198ac82efa622dd93e9e43575f79c) C:\windows\system32\drivers\tcpip.sys
12:00:07.0784 5920 Tcpip - ok
12:00:07.0847 5920 TCPIP6 (56c198ac82efa622dd93e9e43575f79c) C:\windows\system32\DRIVERS\tcpip.sys
12:00:07.0878 5920 TCPIP6 - ok
12:00:07.0909 5920 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
12:00:07.0925 5920 tcpipreg - ok
12:00:07.0972 5920 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
12:00:07.0972 5920 TDPIPE - ok
12:00:08.0003 5920 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
12:00:08.0018 5920 TDTCP - ok
12:00:08.0050 5920 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
12:00:08.0050 5920 tdx - ok
12:00:08.0081 5920 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
12:00:08.0096 5920 TermDD - ok
12:00:08.0190 5920 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
12:00:08.0190 5920 tssecsrv - ok
12:00:08.0221 5920 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
12:00:08.0252 5920 tunnel - ok
12:00:08.0284 5920 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
12:00:08.0299 5920 uagp35 - ok
12:00:08.0330 5920 UBHelper (d79c0b9bb011218b93705cbf77fa3e5e) C:\Windows\system32\drivers\UBHelper.sys
12:00:08.0549 5920 UBHelper - ok
12:00:08.0580 5920 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
12:00:08.0611 5920 udfs - ok
12:00:08.0689 5920 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
12:00:08.0720 5920 uliagpkx - ok
12:00:08.0752 5920 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
12:00:08.0783 5920 umbus - ok
12:00:08.0814 5920 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
12:00:08.0814 5920 UmPass - ok
12:00:08.0861 5920 usbccgp (5c233aefb566ee78c1efbc0493fb066a) C:\windows\system32\DRIVERS\usbccgp.sys
12:00:09.0079 5920 usbccgp - ok
12:00:09.0110 5920 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
12:00:09.0126 5920 usbcir - ok
12:00:09.0157 5920 usbehci (5b71019a6aca0116fd21b368f19c0b91) C:\windows\system32\DRIVERS\usbehci.sys
12:00:09.0157 5920 usbehci - ok
12:00:09.0188 5920 usbfilter (56e89c8e05a987a49ffa595428fb9767) C:\windows\system32\DRIVERS\usbfilter.sys
12:00:09.0407 5920 usbfilter - ok
12:00:09.0438 5920 usbhub (5823d3965c2a4f6f785ed1a3b403f3b8) C:\windows\system32\DRIVERS\usbhub.sys
12:00:09.0890 5920 usbhub - ok
12:00:09.0922 5920 usbohci (e753ed6c49da13967ebabf9ea616454a) C:\windows\system32\DRIVERS\usbohci.sys
12:00:10.0327 5920 usbohci - ok
12:00:10.0358 5920 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
12:00:10.0374 5920 usbprint - ok
12:00:10.0405 5920 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\windows\system32\drivers\USBSTOR.SYS
12:00:10.0421 5920 USBSTOR - ok
12:00:10.0452 5920 usbuhci (6a30928a469ce802600e1ea8c0f2f53f) C:\windows\system32\drivers\usbuhci.sys
12:00:10.0873 5920 usbuhci - ok
12:00:10.0904 5920 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\system32\Drivers\usbvideo.sys
12:00:11.0310 5920 usbvideo - ok
12:00:11.0341 5920 ute4nzu5 (524d8d450622db4a7875b111c299a76b) C:\windows\system32\Drivers\ute4nzu5.sys
12:00:11.0528 5920 ute4nzu5 - ok
12:00:11.0591 5920 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
12:00:11.0591 5920 vdrvroot - ok
12:00:11.0638 5920 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
12:00:11.0653 5920 vga - ok
12:00:11.0684 5920 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
12:00:11.0716 5920 VgaSave - ok
12:00:11.0747 5920 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
12:00:11.0778 5920 vhdmp - ok
12:00:11.0825 5920 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
12:00:11.0840 5920 viaagp - ok
12:00:11.0872 5920 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
12:00:11.0887 5920 ViaC7 - ok
12:00:11.0918 5920 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
12:00:11.0934 5920 viaide - ok
12:00:11.0965 5920 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
12:00:11.0981 5920 volmgr - ok
12:00:12.0028 5920 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
12:00:12.0043 5920 volmgrx - ok
12:00:12.0074 5920 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
12:00:12.0090 5920 volsnap - ok
12:00:12.0121 5920 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
12:00:12.0137 5920 vsmraid - ok
12:00:12.0184 5920 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
12:00:12.0199 5920 vwifibus - ok
12:00:12.0230 5920 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
12:00:12.0262 5920 vwififlt - ok
12:00:12.0293 5920 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
12:00:12.0308 5920 vwifimp - ok
12:00:12.0355 5920 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
12:00:12.0371 5920 WacomPen - ok
12:00:12.0418 5920 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
12:00:12.0433 5920 WANARP - ok
12:00:12.0449 5920 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
12:00:12.0449 5920 Wanarpv6 - ok
12:00:12.0542 5920 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
12:00:12.0558 5920 Wd - ok
12:00:12.0605 5920 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
12:00:12.0620 5920 Wdf01000 - ok
12:00:12.0730 5920 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
12:00:12.0745 5920 WfpLwf - ok
12:00:12.0776 5920 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
12:00:12.0792 5920 WIMMount - ok
12:00:12.0948 5920 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
12:00:12.0948 5920 WmiAcpi - ok
12:00:13.0042 5920 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
12:00:13.0057 5920 ws2ifsl - ok
12:00:13.0135 5920 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
12:00:13.0166 5920 WudfPf - ok
12:00:13.0198 5920 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
12:00:13.0213 5920 WUDFRd - ok
12:00:13.0354 5920 MBR (0x1B8) (70e629b51c16b3c007730c6ae57144c9) \Device\Harddisk0\DR0
12:00:23.0166 5920 \Device\Harddisk0\DR0 - ok
12:00:23.0182 5920 Boot (0x1200) (37ec77ac26e6cc5b4b0b0ed8a30e677b) \Device\Harddisk0\DR0\Partition0
12:00:23.0182 5920 \Device\Harddisk0\DR0\Partition0 - ok
12:00:23.0197 5920 ============================================================
12:00:23.0197 5920 Scan finished
12:00:23.0197 5920 ============================================================
12:00:23.0244 5768 Detected object count: 0
12:00:23.0244 5768 Actual detected object count: 0
 
Here's an older log, from when my sister ran tddskiller and it found something:

10:23:20.0416 5568 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
10:23:20.0822 5568 ============================================================
10:23:20.0822 5568 Current date / time: 2011/12/27 10:23:20.0822
10:23:20.0822 5568 SystemInfo:
10:23:20.0822 5568
10:23:20.0822 5568 OS Version: 6.1.7600 ServicePack: 0.0
10:23:20.0822 5568 Product type: Workstation
10:23:20.0822 5568 ComputerName: WRITER
10:23:20.0822 5568 UserName: Sarah
10:23:20.0822 5568 Windows directory: C:\windows
10:23:20.0822 5568 System windows directory: C:\windows
10:23:20.0822 5568 Processor architecture: Intel x86
10:23:20.0822 5568 Number of processors: 2
10:23:20.0822 5568 Page size: 0x1000
10:23:20.0822 5568 Boot type: Normal boot
10:23:20.0822 5568 ============================================================
10:23:25.0533 5568 Initialize success
10:23:29.0885 6020 ============================================================
10:23:29.0885 6020 Scan started
10:23:29.0885 6020 Mode: Manual;
10:23:29.0885 6020 ============================================================
10:23:31.0024 6020 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
10:23:31.0087 6020 1394ohci - ok
10:23:31.0149 6020 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
10:23:31.0149 6020 ACPI - ok
10:23:31.0180 6020 acpials (79d6b28027c398b728ce7cd0570248b0) C:\windows\system32\DRIVERS\acpials.sys
10:23:31.0258 6020 acpials - ok
10:23:31.0289 6020 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
10:23:31.0321 6020 AcpiPmi - ok
10:23:31.0352 6020 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
10:23:31.0477 6020 adp94xx - ok
10:23:31.0508 6020 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
10:23:31.0601 6020 adpahci - ok
10:23:31.0633 6020 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
10:23:31.0711 6020 adpu320 - ok
10:23:31.0804 6020 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys
10:23:31.0820 6020 AFD - ok
10:23:31.0867 6020 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
10:23:31.0898 6020 agp440 - ok
10:23:31.0945 6020 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
10:23:32.0007 6020 aic78xx - ok
10:23:32.0069 6020 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
10:23:32.0116 6020 aliide - ok
10:23:32.0179 6020 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
10:23:32.0210 6020 amdagp - ok
10:23:32.0257 6020 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
10:23:32.0303 6020 amdide - ok
10:23:32.0350 6020 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
10:23:32.0381 6020 AmdK8 - ok
10:23:32.0678 6020 amdkmdag (e55945478d9a7f652741ae88d0c71794) C:\windows\system32\DRIVERS\atikmdag.sys
10:23:32.0990 6020 amdkmdag - ok
10:23:33.0068 6020 amdkmdap (cfb28043a973dba2125451ce0ffcf7d9) C:\windows\system32\DRIVERS\atikmpag.sys
10:23:33.0083 6020 amdkmdap - ok
10:23:33.0130 6020 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
10:23:33.0130 6020 AmdPPM - ok
10:23:33.0177 6020 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
10:23:33.0239 6020 amdsata - ok
10:23:33.0271 6020 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
10:23:33.0349 6020 amdsbs - ok
10:23:33.0411 6020 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
10:23:33.0411 6020 amdxata - ok
10:23:33.0442 6020 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
10:23:33.0505 6020 AppID - ok
10:23:33.0567 6020 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
10:23:33.0645 6020 arc - ok
10:23:33.0707 6020 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
10:23:33.0770 6020 arcsas - ok
10:23:33.0817 6020 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
10:23:33.0879 6020 AsyncMac - ok
10:23:34.0004 6020 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
10:23:34.0004 6020 atapi - ok
10:23:34.0066 6020 AthBTPort (882edbafcc227852c9dca23ea48d2e78) C:\windows\system32\DRIVERS\btath_flt.sys
10:23:34.0113 6020 AthBTPort - ok
10:23:34.0269 6020 athr (d3ad5858a58668c65fbf6ea436b3a8ff) C:\windows\system32\DRIVERS\athr.sys
10:23:34.0363 6020 athr - ok
10:23:34.0425 6020 AtiHDAudioService (95b1e9804ca10d096c0383f7c6684950) C:\windows\system32\drivers\AtihdW73.sys
10:23:34.0487 6020 AtiHDAudioService - ok
10:23:34.0565 6020 AX88772B (2c795db1b509279ac18fe9e5635e3313) C:\windows\system32\DRIVERS\ax88772b.sys
10:23:34.0565 6020 AX88772B - ok
10:23:34.0643 6020 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
10:23:34.0721 6020 b06bdrv - ok
10:23:34.0784 6020 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
10:23:34.0831 6020 b57nd60x - ok
10:23:34.0909 6020 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
10:23:34.0955 6020 Beep - ok
10:23:35.0002 6020 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
10:23:35.0002 6020 blbdrive - ok
10:23:35.0065 6020 bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys
10:23:35.0080 6020 bowser - ok
10:23:35.0111 6020 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
10:23:35.0158 6020 BrFiltLo - ok
10:23:35.0205 6020 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
10:23:35.0252 6020 BrFiltUp - ok
10:23:35.0330 6020 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
10:23:35.0377 6020 Brserid - ok
10:23:35.0439 6020 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
10:23:35.0486 6020 BrSerWdm - ok
10:23:35.0548 6020 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
10:23:35.0595 6020 BrUsbMdm - ok
10:23:35.0657 6020 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
10:23:35.0704 6020 BrUsbSer - ok
10:23:35.0735 6020 BST (664e7861a289e1bbf75be2d6b02be40f) C:\windows\system32\DRIVERS\bma150.sys
10:23:35.0767 6020 BST - ok
10:23:35.0829 6020 BTATH_A2DP (d57bc943ed4ef85a51165f408e4c15a7) C:\windows\system32\drivers\btath_a2dp.sys
10:23:35.0876 6020 BTATH_A2DP - ok
10:23:35.0923 6020 BTATH_BUS (f60e0c722442ea91f0c253b7814d8192) C:\windows\system32\DRIVERS\btath_bus.sys
10:23:35.0923 6020 BTATH_BUS - ok
10:23:35.0985 6020 BTATH_HCRP (f31e369db8258b28e3dcf66705aea9e9) C:\windows\system32\DRIVERS\btath_hcrp.sys
10:23:36.0047 6020 BTATH_HCRP - ok
10:23:36.0125 6020 BTATH_LWFLT (6651798266fde23159d961463a63a77d) C:\windows\system32\DRIVERS\btath_lwflt.sys
10:23:36.0172 6020 BTATH_LWFLT - ok
10:23:36.0219 6020 BTATH_RCP (08ef5298df80bc136523bcd2ed8b9c37) C:\windows\system32\DRIVERS\btath_rcp.sys
10:23:36.0297 6020 BTATH_RCP - ok
10:23:36.0375 6020 BtFilter (6c692b2920d0e1b2fdb19329b7d69c6a) C:\windows\system32\DRIVERS\btfilter.sys
10:23:36.0391 6020 BtFilter - ok
10:23:36.0437 6020 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\DRIVERS\BthEnum.sys
10:23:36.0484 6020 BthEnum - ok
10:23:36.0531 6020 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
10:23:36.0593 6020 BTHMODEM - ok
10:23:36.0656 6020 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
10:23:36.0765 6020 BthPan - ok
10:23:36.0827 6020 BTHPORT (4a34888e13224678dd062466afec4240) C:\windows\system32\Drivers\BTHport.sys
10:23:37.0046 6020 BTHPORT - ok
10:23:37.0108 6020 BTHUSB (fa04c63916fa221dbb91fce153d07a55) C:\windows\system32\Drivers\BTHUSB.sys
10:23:37.0186 6020 BTHUSB - ok
10:23:37.0233 6020 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
10:23:37.0280 6020 cdfs - ok
10:23:37.0327 6020 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
10:23:37.0342 6020 cdrom - ok
10:23:37.0405 6020 cfwids (1dcb5209601a70e36c70fe8d197d62cb) C:\windows\system32\drivers\cfwids.sys
10:23:37.0405 6020 cfwids - ok
10:23:37.0451 6020 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
10:23:37.0483 6020 circlass - ok
10:23:37.0529 6020 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
10:23:37.0545 6020 CLFS - ok
10:23:37.0607 6020 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
10:23:37.0639 6020 CmBatt - ok
10:23:37.0701 6020 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
10:23:37.0763 6020 cmdide - ok
10:23:37.0810 6020 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
10:23:37.0826 6020 CNG - ok
10:23:37.0857 6020 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
10:23:37.0873 6020 Compbatt - ok
10:23:37.0904 6020 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
10:23:37.0951 6020 CompositeBus - ok
10:23:38.0013 6020 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
10:23:38.0044 6020 crcdisk - ok
10:23:38.0169 6020 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys
10:23:38.0169 6020 DfsC - ok
10:23:38.0231 6020 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
10:23:38.0231 6020 discache - ok
10:23:38.0294 6020 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
10:23:38.0309 6020 Disk - ok
10:23:38.0372 6020 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
10:23:38.0419 6020 drmkaud - ok
10:23:38.0512 6020 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
10:23:38.0590 6020 DXGKrnl - ok
10:23:38.0746 6020 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
10:23:38.0902 6020 ebdrv - ok
10:23:38.0996 6020 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
10:23:39.0089 6020 elxstor - ok
10:23:39.0152 6020 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
10:23:39.0183 6020 ErrDev - ok
10:23:39.0261 6020 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
10:23:39.0308 6020 exfat - ok
10:23:39.0355 6020 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
10:23:39.0355 6020 fastfat - ok
10:23:39.0448 6020 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
10:23:39.0464 6020 fdc - ok
10:23:39.0526 6020 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
10:23:39.0542 6020 FileInfo - ok
10:23:39.0573 6020 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
10:23:39.0635 6020 Filetrace - ok
10:23:39.0682 6020 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
10:23:39.0713 6020 flpydisk - ok
10:23:39.0791 6020 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
10:23:39.0807 6020 FltMgr - ok
10:23:39.0869 6020 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
10:23:39.0901 6020 FsDepends - ok
10:23:39.0963 6020 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
10:23:39.0979 6020 Fs_Rec - ok
10:23:40.0103 6020 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys
10:23:40.0119 6020 fvevol - ok
10:23:40.0197 6020 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
10:23:40.0228 6020 gagp30kx - ok
10:23:40.0306 6020 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
10:23:40.0353 6020 hcw85cir - ok
10:23:40.0400 6020 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
10:23:40.0447 6020 HdAudAddService - ok
10:23:40.0509 6020 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
10:23:40.0525 6020 HDAudBus - ok
10:23:40.0587 6020 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
10:23:40.0634 6020 HidBatt - ok
10:23:40.0712 6020 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
10:23:40.0774 6020 HidBth - ok
10:23:40.0868 6020 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
10:23:40.0930 6020 HidIr - ok
10:23:40.0977 6020 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
10:23:40.0977 6020 HidUsb - ok
10:23:41.0055 6020 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
10:23:41.0117 6020 HpSAMD - ok
10:23:41.0180 6020 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
10:23:41.0195 6020 HTTP - ok
10:23:41.0227 6020 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
10:23:41.0242 6020 hwpolicy - ok
10:23:41.0273 6020 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
10:23:41.0336 6020 i8042prt - ok
10:23:41.0507 6020 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
10:23:41.0632 6020 iaStorV - ok
10:23:41.0695 6020 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
10:23:41.0757 6020 iirsp - ok
10:23:41.0960 6020 IntcAzAudAddService (0859200f021ba9c30b270d8397555605) C:\windows\system32\drivers\RTKVHDA.sys
10:23:42.0069 6020 IntcAzAudAddService - ok
10:23:42.0131 6020 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
10:23:42.0194 6020 intelide - ok
10:23:42.0241 6020 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
10:23:42.0287 6020 intelppm - ok
10:23:42.0397 6020 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
10:23:42.0459 6020 IpFilterDriver - ok
10:23:42.0521 6020 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
10:23:42.0568 6020 IPMIDRV - ok
10:23:42.0615 6020 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
10:23:42.0646 6020 IPNAT - ok
10:23:42.0693 6020 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
10:23:42.0740 6020 IRENUM - ok
10:23:42.0787 6020 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
10:23:42.0818 6020 isapnp - ok
10:23:42.0880 6020 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
10:23:42.0927 6020 iScsiPrt - ok
10:23:42.0974 6020 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
10:23:43.0036 6020 kbdclass - ok
10:23:43.0145 6020 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
10:23:43.0192 6020 kbdhid - ok
10:23:43.0379 6020 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
10:23:43.0395 6020 KSecDD - ok
10:23:43.0442 6020 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
10:23:43.0457 6020 KSecPkg - ok
10:23:43.0598 6020 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
10:23:43.0645 6020 lltdio - ok
10:23:43.0723 6020 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
10:23:43.0801 6020 LSI_FC - ok
10:23:43.0816 6020 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
10:23:43.0910 6020 LSI_SAS - ok
10:23:43.0941 6020 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
10:23:44.0019 6020 LSI_SAS2 - ok
10:23:44.0050 6020 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
10:23:44.0113 6020 LSI_SCSI - ok
10:23:44.0159 6020 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
10:23:44.0159 6020 luafv - ok
10:23:44.0456 6020 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
10:23:44.0518 6020 megasas - ok
10:23:44.0565 6020 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
10:23:44.0674 6020 MegaSR - ok
10:23:44.0737 6020 mfeapfk (36b47b1e9c537f8f2b4481084b8f7d22) C:\windows\system32\drivers\mfeapfk.sys
10:23:44.0737 6020 mfeapfk - ok
10:23:44.0799 6020 mfeavfk (cde41293db871a75cd99eb0ce781356b) C:\windows\system32\drivers\mfeavfk.sys
10:23:44.0861 6020 mfeavfk - ok
10:23:44.0893 6020 mfeavfk01 - ok
10:23:44.0971 6020 mfebopk (e22385f64bdf0ad81157479496e33c4a) C:\windows\system32\drivers\mfebopk.sys
10:23:44.0971 6020 mfebopk - ok
10:23:45.0080 6020 mfefirek (215666a8a85023ef019b510cbb67f678) C:\windows\system32\drivers\mfefirek.sys
10:23:45.0158 6020 mfefirek - ok
10:23:45.0236 6020 mfehidk (56d330981866a72f061dd16cc5004513) C:\windows\system32\drivers\mfehidk.sys
10:23:45.0251 6020 mfehidk - ok
10:23:45.0298 6020 mfenlfk (b41bacc049cdb916a52b1448bf30d6ab) C:\windows\system32\DRIVERS\mfenlfk.sys
10:23:45.0298 6020 mfenlfk - ok
10:23:45.0345 6020 mferkdet (89b564d63c53fc0c6782ab07eea63acf) C:\windows\system32\drivers\mferkdet.sys
10:23:45.0392 6020 mferkdet - ok
10:23:45.0454 6020 mfewfpk (c2ff7473a60c0fb2df145ab686889653) C:\windows\system32\drivers\mfewfpk.sys
10:23:45.0485 6020 mfewfpk - ok
10:23:45.0548 6020 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
10:23:45.0579 6020 Modem - ok
10:23:45.0626 6020 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
10:23:45.0626 6020 monitor - ok
10:23:45.0673 6020 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
10:23:45.0673 6020 mouclass - ok
10:23:45.0719 6020 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
10:23:45.0719 6020 mouhid - ok
10:23:45.0782 6020 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
10:23:45.0782 6020 mountmgr - ok
10:23:45.0829 6020 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
10:23:45.0907 6020 mpio - ok
10:23:45.0985 6020 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
10:23:46.0047 6020 mpsdrv - ok
10:23:46.0094 6020 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
10:23:46.0250 6020 MRxDAV - ok
10:23:46.0312 6020 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\windows\system32\DRIVERS\mrxsmb.sys
10:23:46.0312 6020 mrxsmb - ok
10:23:46.0375 6020 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\windows\system32\DRIVERS\mrxsmb10.sys
10:23:46.0390 6020 mrxsmb10 - ok
10:23:46.0437 6020 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\windows\system32\DRIVERS\mrxsmb20.sys
10:23:46.0437 6020 mrxsmb20 - ok
10:23:46.0531 6020 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
10:23:46.0531 6020 msahci - ok
10:23:46.0624 6020 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
10:23:46.0687 6020 msdsm - ok
10:23:46.0780 6020 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
10:23:46.0780 6020 Msfs - ok
10:23:46.0843 6020 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
10:23:46.0874 6020 mshidkmdf - ok
10:23:46.0921 6020 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
10:23:46.0921 6020 msisadrv - ok
10:23:46.0999 6020 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
10:23:47.0030 6020 MSKSSRV - ok
10:23:47.0061 6020 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
10:23:47.0108 6020 MSPCLOCK - ok
10:23:47.0155 6020 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
10:23:47.0186 6020 MSPQM - ok
10:23:47.0233 6020 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
10:23:47.0233 6020 MsRPC - ok
10:23:47.0279 6020 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
10:23:47.0279 6020 mssmbios - ok
10:23:47.0326 6020 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
10:23:47.0357 6020 MSTEE - ok
10:23:47.0404 6020 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
10:23:47.0435 6020 MTConfig - ok
10:23:47.0467 6020 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
10:23:47.0482 6020 Mup - ok
10:23:47.0545 6020 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
10:23:47.0638 6020 NativeWifiP - ok
10:23:47.0701 6020 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
10:23:47.0732 6020 NDIS - ok
10:23:47.0779 6020 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
10:23:47.0810 6020 NdisCap - ok
10:23:47.0857 6020 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
10:23:47.0888 6020 NdisTapi - ok
10:23:47.0966 6020 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
10:23:47.0997 6020 Ndisuio - ok
10:23:48.0044 6020 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
10:23:48.0044 6020 NdisWan - ok
10:23:48.0091 6020 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
10:23:48.0122 6020 NDProxy - ok
10:23:48.0184 6020 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
10:23:48.0184 6020 NetBIOS - ok
10:23:48.0231 6020 NetBT (4e284fbf849021979ce4c3f24ced1edc) C:\windows\system32\DRIVERS\netbt.sys
10:23:48.0247 6020 Suspicious file (Forged): C:\windows\system32\DRIVERS\netbt.sys. Real md5: 4e284fbf849021979ce4c3f24ced1edc, Fake md5: dd52a733bf4ca5af84562a5e2f963b91
10:23:48.0247 6020 NetBT ( Rootkit.Win32.ZAccess.aml ) - infected
10:23:48.0247 6020 NetBT - detected Rootkit.Win32.ZAccess.aml (0)
10:23:48.0356 6020 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
10:23:48.0403 6020 nfrd960 - ok
10:23:48.0481 6020 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
10:23:48.0481 6020 Npfs - ok
10:23:48.0543 6020 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
10:23:48.0543 6020 nsiproxy - ok
10:23:48.0637 6020 Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys
10:23:48.0668 6020 Ntfs - ok
10:23:48.0746 6020 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\drivers\NTIDrvr.sys
10:23:48.0808 6020 NTIDrvr - ok
10:23:48.0902 6020 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
10:23:48.0917 6020 Null - ok
10:23:48.0980 6020 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys
10:23:49.0027 6020 nvraid - ok
10:23:49.0120 6020 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys
10:23:49.0183 6020 nvstor - ok
10:23:49.0245 6020 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
10:23:49.0276 6020 nv_agp - ok
10:23:49.0323 6020 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
10:23:49.0354 6020 ohci1394 - ok
10:23:49.0432 6020 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
10:23:49.0510 6020 Parport - ok
10:23:49.0557 6020 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
10:23:49.0557 6020 partmgr - ok
10:23:49.0619 6020 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
10:23:49.0635 6020 Parvdm - ok
10:23:49.0713 6020 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
10:23:49.0713 6020 pci - ok
10:23:49.0775 6020 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
10:23:49.0822 6020 pciide - ok
10:23:49.0885 6020 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
10:23:49.0931 6020 pcmcia - ok
10:23:49.0978 6020 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
10:23:49.0978 6020 pcw - ok
10:23:50.0056 6020 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
10:23:50.0119 6020 PEAUTH - ok
10:23:50.0290 6020 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
10:23:50.0290 6020 PptpMiniport - ok
10:23:50.0337 6020 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
10:23:50.0368 6020 Processor - ok
10:23:50.0493 6020 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
10:23:50.0493 6020 Psched - ok
10:23:50.0555 6020 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
10:23:50.0680 6020 ql2300 - ok
10:23:50.0743 6020 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
10:23:50.0821 6020 ql40xx - ok
10:23:50.0883 6020 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
10:23:50.0930 6020 QWAVEdrv - ok
10:23:50.0977 6020 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
10:23:51.0023 6020 RasAcd - ok
10:23:51.0086 6020 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
10:23:51.0086 6020 RasAgileVpn - ok
10:23:51.0164 6020 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
10:23:51.0164 6020 Rasl2tp - ok
10:23:51.0226 6020 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
10:23:51.0289 6020 RasPppoe - ok
10:23:51.0335 6020 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
10:23:51.0335 6020 RasSstp - ok
10:23:51.0413 6020 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
10:23:51.0429 6020 rdbss - ok
10:23:51.0476 6020 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
10:23:51.0507 6020 rdpbus - ok
10:23:51.0569 6020 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
10:23:51.0569 6020 RDPCDD - ok
10:23:51.0663 6020 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
10:23:51.0679 6020 RDPENCDD - ok
10:23:51.0741 6020 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
10:23:51.0741 6020 RDPREFMP - ok
10:23:51.0803 6020 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
10:23:51.0881 6020 RDPWD - ok
10:23:51.0944 6020 rdyboost (65db288f7372b1f632891fc32bf908b7) C:\windows\system32\drivers\rdyboost.sys
10:23:51.0959 6020 rdyboost - ok
10:23:52.0037 6020 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
10:23:52.0100 6020 RFCOMM - ok
10:23:52.0209 6020 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
10:23:52.0240 6020 rspndr - ok
10:23:52.0303 6020 RSUSBSTOR (247b0a8164069cd4fe6f3094c581b13b) C:\windows\system32\Drivers\RtsUStor.sys
10:23:52.0303 6020 RSUSBSTOR - ok
10:23:52.0381 6020 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
10:23:52.0459 6020 sbp2port - ok
10:23:52.0552 6020 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
10:23:52.0583 6020 scfilter - ok
10:23:52.0677 6020 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
10:23:52.0755 6020 secdrv - ok
10:23:52.0849 6020 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
10:23:52.0880 6020 Serenum - ok
10:23:52.0927 6020 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
10:23:52.0973 6020 Serial - ok
10:23:53.0036 6020 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
10:23:53.0067 6020 sermouse - ok
10:23:53.0161 6020 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
10:23:53.0192 6020 sffdisk - ok
10:23:53.0239 6020 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
10:23:53.0285 6020 sffp_mmc - ok
10:23:53.0332 6020 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\windows\system32\DRIVERS\sffp_sd.sys
10:23:53.0363 6020 sffp_sd - ok
10:23:53.0410 6020 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
10:23:53.0457 6020 sfloppy - ok
10:23:53.0551 6020 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
10:23:53.0582 6020 sisagp - ok
10:23:53.0629 6020 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
10:23:53.0691 6020 SiSRaid2 - ok
10:23:53.0753 6020 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
10:23:53.0816 6020 SiSRaid4 - ok
10:23:53.0878 6020 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
10:23:53.0941 6020 Smb - ok
10:23:54.0019 6020 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
10:23:54.0019 6020 spldr - ok
10:23:54.0143 6020 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\windows\system32\DRIVERS\srv.sys
10:23:54.0159 6020 srv - ok
10:23:54.0206 6020 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\windows\system32\DRIVERS\srv2.sys
10:23:54.0221 6020 srv2 - ok
10:23:54.0268 6020 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\windows\system32\DRIVERS\srvnet.sys
10:23:54.0268 6020 srvnet - ok
10:23:54.0331 6020 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
10:23:54.0377 6020 stexstor - ok
10:23:54.0455 6020 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
10:23:54.0487 6020 swenum - ok
10:23:54.0627 6020 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\drivers\tcpip.sys
10:23:54.0674 6020 Tcpip - ok
10:23:54.0752 6020 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\DRIVERS\tcpip.sys
10:23:54.0767 6020 TCPIP6 - ok
10:23:54.0830 6020 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
10:23:54.0877 6020 tcpipreg - ok
10:23:54.0939 6020 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
10:23:54.0986 6020 TDPIPE - ok
10:23:55.0033 6020 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
10:23:55.0079 6020 TDTCP - ok
10:23:55.0126 6020 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
10:23:55.0126 6020 tdx - ok
10:23:55.0189 6020 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
10:23:55.0189 6020 TermDD - ok
10:23:55.0345 6020 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
10:23:55.0391 6020 tssecsrv - ok
10:23:55.0454 6020 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
10:23:55.0454 6020 tunnel - ok
10:23:55.0501 6020 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
10:23:55.0547 6020 uagp35 - ok
10:23:55.0594 6020 UBHelper (d79c0b9bb011218b93705cbf77fa3e5e) C:\Windows\system32\drivers\UBHelper.sys
10:23:55.0610 6020 UBHelper - ok
10:23:55.0688 6020 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
10:23:55.0703 6020 udfs - ok
10:23:55.0813 6020 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
10:23:55.0844 6020 uliagpkx - ok
10:23:55.0906 6020 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
10:23:55.0953 6020 umbus - ok
10:23:56.0000 6020 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
10:23:56.0031 6020 UmPass - ok
10:23:56.0078 6020 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys
10:23:56.0109 6020 usbccgp - ok
10:23:56.0156 6020 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
10:23:56.0187 6020 usbcir - ok
10:23:56.0234 6020 usbehci (0eeedd78c2bedac75e8ed1ba8d77878b) C:\windows\system32\DRIVERS\usbehci.sys
10:23:56.0249 6020 usbehci - ok
10:23:56.0296 6020 usbfilter (56e89c8e05a987a49ffa595428fb9767) C:\windows\system32\DRIVERS\usbfilter.sys
10:23:56.0327 6020 usbfilter - ok
10:23:56.0374 6020 usbhub (ba50148445e5b2b3abdba208fc9b6fb5) C:\windows\system32\DRIVERS\usbhub.sys
10:23:56.0452 6020 usbhub - ok
10:23:56.0515 6020 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys
10:23:56.0561 6020 usbohci - ok
10:23:56.0608 6020 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
10:23:56.0655 6020 usbprint - ok
10:23:56.0702 6020 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS
10:23:56.0717 6020 USBSTOR - ok
10:23:56.0780 6020 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys
10:23:56.0827 6020 usbuhci - ok
10:23:56.0889 6020 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\system32\Drivers\usbvideo.sys
10:23:56.0967 6020 usbvideo - ok
10:23:57.0061 6020 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
10:23:57.0061 6020 vdrvroot - ok
10:23:57.0139 6020 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
10:23:57.0170 6020 vga - ok
10:23:57.0217 6020 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
10:23:57.0248 6020 VgaSave - ok
10:23:57.0310 6020 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
10:23:57.0357 6020 vhdmp - ok
10:23:57.0404 6020 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
10:23:57.0435 6020 viaagp - ok
10:23:57.0497 6020 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
10:23:57.0544 6020 ViaC7 - ok
10:23:57.0591 6020 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
10:23:57.0638 6020 viaide - ok
10:23:57.0685 6020 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
10:23:57.0685 6020 volmgr - ok
10:23:57.0747 6020 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
10:23:57.0747 6020 volmgrx - ok
10:23:57.0825 6020 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
10:23:57.0841 6020 volsnap - ok
10:23:57.0887 6020 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
10:23:57.0965 6020 vsmraid - ok
10:23:58.0028 6020 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
10:23:58.0075 6020 vwifibus - ok
10:23:58.0137 6020 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
10:23:58.0137 6020 vwififlt - ok
10:23:58.0184 6020 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
10:23:58.0184 6020 vwifimp - ok
10:23:58.0277 6020 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
10:23:58.0340 6020 WacomPen - ok
10:23:58.0387 6020 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
10:23:58.0433 6020 WANARP - ok
10:23:58.0465 6020 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
10:23:58.0465 6020 Wanarpv6 - ok
10:23:58.0605 6020 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
10:23:58.0652 6020 Wd - ok
10:23:58.0730 6020 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
10:23:58.0745 6020 Wdf01000 - ok
10:23:58.0917 6020 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
10:23:58.0933 6020 WfpLwf - ok
10:23:58.0964 6020 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
10:23:59.0042 6020 WIMMount - ok
10:23:59.0213 6020 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
10:23:59.0213 6020 WmiAcpi - ok
10:23:59.0338 6020 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
10:23:59.0369 6020 ws2ifsl - ok
10:23:59.0447 6020 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
10:23:59.0510 6020 WudfPf - ok
10:23:59.0557 6020 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
10:23:59.0619 6020 WUDFRd - ok
10:23:59.0806 6020 MBR (0x1B8) (70e629b51c16b3c007730c6ae57144c9) \Device\Harddisk0\DR0
10:24:01.0834 6020 \Device\Harddisk0\DR0 - ok
10:24:01.0850 6020 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1
10:24:01.0943 6020 \Device\Harddisk1\DR1 - ok
10:24:01.0959 6020 Boot (0x1200) (37ec77ac26e6cc5b4b0b0ed8a30e677b) \Device\Harddisk0\DR0\Partition0
10:24:01.0975 6020 \Device\Harddisk0\DR0\Partition0 - ok
10:24:01.0990 6020 Boot (0x1200) (050d616d812e9e8f20a0e3db1c54e1a5) \Device\Harddisk1\DR1\Partition0
10:24:01.0990 6020 \Device\Harddisk1\DR1\Partition0 - ok
10:24:02.0006 6020 ============================================================
10:24:02.0006 6020 Scan finished
10:24:02.0006 6020 ============================================================
10:24:02.0053 6012 Detected object count: 1
10:24:02.0053 6012 Actual detected object count: 1
10:25:08.0119 6012 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\windows\system32\drivers\netbt.sys) error 1813
10:25:10.0474 6012 Backup copy found, using it..
10:25:10.0599 6012 C:\windows\system32\DRIVERS\netbt.sys - will be cured on reboot
10:25:12.0861 6012 NetBT ( Rootkit.Win32.ZAccess.aml ) - User select action: Cure
10:25:16.0387 5436 Deinitialize success
 
Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

============================================================

Download Bootkit Remover to your Desktop.

  • Unzip downloaded file to your Desktop.
  • Double-click on boot_cleaner.exe to run the program (Vista/7 users,right click on boot_cleaner.exe and click Run As Administrator).
  • It will show a Black screen with some data on it.
  • Right click on the screen and click Select All.
  • Press CTRL+C
  • Open a Notepad and press CTRL+V
  • Post the output back here.
 
Instructions followed. Here is the aswMBR log:
aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-10 15:39:53
-----------------------------
15:39:53.933 OS Version: Windows 6.1.7600
15:39:53.933 Number of processors: 2 586 0x100
15:39:53.964 ComputerName: WRITER UserName: Sarah
15:39:57.022 Initialize success
15:41:30.365 AVAST engine defs: 12011001
15:41:36.995 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:41:37.011 Disk 0 Vendor: SanDisk_SSD_P4_32GB SSD_8.10 Size: 30533MB BusType: 11
15:41:37.027 Disk 0 MBR read successfully
15:41:37.042 Disk 0 MBR scan
15:41:37.058 Disk 0 unknown MBR code
15:41:37.073 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 100 MB offset 2048
15:41:37.089 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 30431 MB offset 206848
15:41:37.120 Disk 0 scanning sectors +62529536
15:41:37.167 Disk 0 scanning C:\windows\system32\drivers
15:42:02.158 Service scanning
15:42:12.891 Modules scanning
15:42:24.763 Disk 0 trace - called modules:
15:42:24.794 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
15:42:25.355 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x869d5ac8]
15:42:25.371 3 CLASSPNP.SYS[891b859e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x868e1030]
15:42:26.557 AVAST engine scan C:\windows
15:42:31.112 AVAST engine scan C:\windows\system32
15:47:21.132 AVAST engine scan C:\windows\system32\drivers
15:47:44.173 AVAST engine scan C:\Users\Sarah
15:48:52.065 Disk 0 MBR has been saved successfully to "C:\Users\Sarah\Desktop\MBR.dat"
15:48:52.111 The log file has been saved successfully to "C:\Users\Sarah\Desktop\aswMBR.txt"

and here is the boot_cleaner output:

Bootkit Remover
(c) 2009 Esage Lab
www.esagelab.com

Program version: 1.2.0.1
OS Version: Microsoft Windows 7 Home Premium Edition (build 7600), 32-bit

System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`06500000
Boot sector MD5 is: 08c6d97449fb1d8bcab9d003ed787166

Size Device Name MBR Status
--------------------------------------------
29 GB \\.\PhysicalDrive0 Unknown boot code

Unknown boot code has been found on some of your physical disks.
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>

Done;
Press any key to quit...
 
Looks good :)

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  1. Please, never rename Combofix unless instructed.
  2. Close any open browsers.
  3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  4. Double click on combofix.exe & follow the prompts.
  5. When finished, it will produce a report for you.
  6. Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.

**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode (How to...)

2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
 
ComboFix log

Here it is:

ComboFix 12-01-10.02 - Sarah 01/10/2012 16:47:20.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1642.1149 [GMT -6:00]
Running from: c:\users\Sarah\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\LP
c:\windows\$NtUninstallKB19606$
c:\windows\$NtUninstallKB19606$\1902657022\@
c:\windows\$NtUninstallKB19606$\1902657022\bckfg.tmp
c:\windows\$NtUninstallKB19606$\1902657022\cfg.ini
c:\windows\$NtUninstallKB19606$\1902657022\Desktop.ini
c:\windows\$NtUninstallKB19606$\1902657022\keywords
c:\windows\$NtUninstallKB19606$\1902657022\kwrd.dll
c:\windows\$NtUninstallKB19606$\1902657022\L\xadqgnnk
c:\windows\$NtUninstallKB19606$\1902657022\lsflt7.ver
c:\windows\$NtUninstallKB19606$\1902657022\U\00000001.@
c:\windows\$NtUninstallKB19606$\1902657022\U\00000002.@
c:\windows\$NtUninstallKB19606$\1902657022\U\00000004.@
c:\windows\$NtUninstallKB19606$\1902657022\U\80000000.@
c:\windows\$NtUninstallKB19606$\1902657022\U\80000004.@
c:\windows\$NtUninstallKB19606$\1902657022\U\80000032.@
c:\windows\$NtUninstallKB19606$\3069654774
.
.
((((((((((((((((((((((((( Files Created from 2011-12-10 to 2012-01-10 )))))))))))))))))))))))))))))))
.
.
2012-01-10 23:08 . 2012-01-10 23:12 -------- d-----w- c:\users\Sarah\AppData\Local\temp
2012-01-10 23:08 . 2012-01-10 23:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-10 23:08 . 2012-01-10 23:08 -------- d-----w- c:\users\Administer\AppData\Local\temp
2012-01-10 22:43 . 2011-04-25 02:35 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2012-01-10 09:31 . 2012-01-10 09:31 -------- d-----w- c:\windows\system32\Wat
2012-01-09 23:16 . 2011-04-28 03:29 60416 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2012-01-09 23:16 . 2011-04-28 03:29 393216 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-01-09 23:16 . 2011-03-29 03:07 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-01-09 23:16 . 2011-03-29 03:06 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-01-09 23:16 . 2011-03-29 03:06 284160 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-01-09 23:16 . 2011-03-29 03:06 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-01-09 23:16 . 2011-03-29 03:06 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-01-09 23:16 . 2011-03-29 03:06 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-01-09 23:16 . 2011-03-29 03:06 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-01-09 23:15 . 2011-03-11 05:44 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-01-09 23:15 . 2011-03-11 05:44 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-01-09 23:15 . 2011-03-11 05:44 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-01-09 23:15 . 2011-03-11 05:43 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-01-09 23:15 . 2011-03-11 05:39 1686016 ----a-w- c:\windows\system32\esent.dll
2012-01-09 23:15 . 2011-03-11 05:44 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2012-01-09 23:15 . 2011-03-11 05:43 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-01-09 23:15 . 2011-03-11 05:43 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-01-09 23:15 . 2011-03-11 05:37 74240 ----a-w- c:\windows\system32\fsutil.exe
2012-01-03 02:01 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-01-03 02:00 . 2011-02-19 05:33 802304 ----a-w- c:\windows\system32\FntCache.dll
2012-01-03 02:00 . 2011-02-19 05:32 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-01-03 01:09 . 2009-11-25 18:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-01-03 01:09 . 2009-11-25 18:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-01-03 01:09 . 2009-11-25 18:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-01-03 01:09 . 2009-11-25 18:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-01-03 01:09 . 2009-11-25 18:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-01-03 00:56 . 2010-09-14 06:07 276992 ----a-w- c:\windows\system32\wcncsvc.dll
2012-01-02 23:01 . 2011-04-29 02:57 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2012-01-02 23:01 . 2011-04-29 02:57 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-01-02 23:01 . 2011-04-29 02:57 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-01-02 20:39 . 2010-10-16 04:34 573440 ----a-w- c:\windows\system32\odbc32.dll
2012-01-02 20:39 . 2010-10-16 04:33 987136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-01-02 20:39 . 2010-10-16 04:33 372736 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-01-02 20:39 . 2010-10-16 04:33 352256 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-01-02 20:39 . 2010-10-16 04:33 208896 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-01-02 20:39 . 2011-02-18 05:33 31232 ----a-w- c:\windows\system32\prevhost.exe
2012-01-02 20:39 . 2011-04-27 02:33 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-01-02 20:38 . 2011-05-04 04:52 1401856 ----a-w- c:\windows\system32\mssrch.dll
2012-01-02 20:38 . 2011-05-04 04:53 1553920 ----a-w- c:\windows\system32\tquery.dll
2012-01-02 20:38 . 2011-05-04 04:52 428032 ----a-w- c:\windows\system32\SearchIndexer.exe
2012-01-02 20:38 . 2011-05-04 04:52 666624 ----a-w- c:\windows\system32\mssvp.dll
2012-01-02 20:38 . 2011-05-04 04:52 337408 ----a-w- c:\windows\system32\mssph.dll
2012-01-02 20:38 . 2011-05-04 04:52 197120 ----a-w- c:\windows\system32\mssphtb.dll
2012-01-02 20:38 . 2011-05-04 04:52 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2012-01-02 20:38 . 2011-05-04 04:52 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2012-01-02 20:38 . 2011-05-04 04:52 59392 ----a-w- c:\windows\system32\msscntrs.dll
2012-01-02 20:38 . 2011-09-29 15:43 1285488 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-01-02 20:37 . 2011-10-01 04:43 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2012-01-02 20:37 . 2010-12-18 05:29 541184 ----a-w- c:\windows\system32\kerberos.dll
2012-01-02 20:37 . 2011-03-03 05:29 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-01-02 20:37 . 2011-03-03 05:27 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-01-02 20:37 . 2011-11-05 04:30 2048 ----a-w- c:\windows\system32\tzres.dll
2012-01-02 20:36 . 2011-07-09 02:26 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-01-02 20:36 . 2011-05-04 02:43 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-01-02 20:36 . 2011-05-04 02:43 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-01-02 20:36 . 2011-10-15 05:48 534528 ----a-w- c:\windows\system32\EncDec.dll
2012-01-02 20:35 . 2010-03-04 07:33 1619968 ----a-w- c:\program files\Windows Mail\msoe.dll
2012-01-02 20:35 . 2011-10-26 04:42 3957104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-01-02 20:35 . 2011-10-26 04:42 3901808 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-01-02 20:34 . 2011-11-24 04:23 2340352 ----a-w- c:\windows\system32\win32k.sys
2012-01-02 20:33 . 2011-10-26 04:25 38912 ----a-w- c:\windows\system32\csrsrv.dll
2012-01-02 20:33 . 2011-08-17 04:22 75776 ----a-w- c:\windows\system32\psisrndr.ax
2012-01-02 20:33 . 2011-08-17 04:26 465408 ----a-w- c:\windows\system32\psisdecd.dll
2012-01-02 20:33 . 2011-08-17 04:22 204288 ----a-w- c:\windows\system32\MSNP.ax
2012-01-02 20:33 . 2011-08-17 04:22 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-01-02 20:33 . 2011-08-17 04:22 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-01-02 20:33 . 2011-02-12 05:30 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2012-01-02 20:30 . 2010-12-23 05:28 642048 ----a-w- c:\windows\system32\CPFilters.dll
2012-01-02 20:30 . 2010-12-23 05:28 850432 ----a-w- c:\windows\system32\sbe.dll
2012-01-02 20:30 . 2010-12-23 05:24 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2012-01-02 20:30 . 2011-05-03 04:50 740864 ----a-w- c:\windows\system32\inetcomm.dll
2012-01-02 20:30 . 2011-06-15 09:04 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2012-01-02 20:30 . 2011-06-15 09:04 122880 ----a-w- c:\windows\system32\odbccp32.dll
2012-01-02 20:30 . 2011-06-15 09:04 81920 ----a-w- c:\windows\system32\odbccr32.dll
2012-01-02 20:30 . 2011-06-15 09:04 86016 ----a-w- c:\windows\system32\odbccu32.dll
2012-01-02 20:30 . 2011-06-15 09:04 94208 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2012-01-02 20:30 . 2011-06-15 09:04 163840 ----a-w- c:\windows\system32\odbctrac.dll
2012-01-02 20:28 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2012-01-02 20:28 . 2011-03-12 11:31 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2012-01-02 20:28 . 2011-02-26 05:33 2614784 ----a-w- c:\windows\explorer.exe
2012-01-02 20:28 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\system32\mstscax.dll
2012-01-02 20:28 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\system32\mstsc.exe
2012-01-02 20:28 . 2011-05-24 10:35 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-01-02 20:28 . 2011-02-19 03:37 294912 ----a-w- c:\windows\system32\atmfd.dll
2012-01-02 20:28 . 2011-02-19 05:32 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-01-02 20:27 . 2011-08-27 04:43 571904 ----a-w- c:\windows\system32\oleaut32.dll
2012-01-02 20:27 . 2011-08-27 04:43 233472 ----a-w- c:\windows\system32\oleacc.dll
2012-01-02 20:27 . 2011-02-24 05:32 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-01-02 20:27 . 2010-12-21 05:38 204288 ----a-w- c:\windows\system32\upnp.dll
2012-01-02 20:27 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll
2012-01-02 20:27 . 2010-12-21 05:36 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-01-02 20:26 . 2010-12-21 05:38 204800 ----a-w- c:\windows\system32\WebClnt.dll
2012-01-02 20:26 . 2010-12-21 05:38 350720 ----a-w- c:\windows\system32\winhttp.dll
2012-01-02 20:26 . 2010-12-21 05:34 80384 ----a-w- c:\windows\system32\davclnt.dll
2012-01-02 20:26 . 2010-12-21 05:38 51200 ----a-w- c:\windows\system32\wscapi.dll
2012-01-02 20:26 . 2010-12-21 05:38 14336 ----a-w- c:\windows\system32\slwga.dll
2012-01-02 20:26 . 2010-12-21 05:38 73728 ----a-w- c:\windows\system32\wscsvc.dll
2012-01-02 20:26 . 2010-10-27 04:40 1289536 ----a-w- c:\windows\system32\ntdll.dll
2012-01-02 20:26 . 2011-03-11 05:40 1137664 ----a-w- c:\windows\system32\mfc42.dll
2012-01-02 20:26 . 2011-03-11 05:40 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2012-01-02 20:26 . 2011-01-17 05:38 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-01-02 20:25 . 2011-02-23 05:05 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-01-02 20:19 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2012-01-02 20:18 . 2011-04-22 19:36 26496 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2012-01-02 20:17 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-01-02 20:05 . 2012-01-02 20:05 -------- d-----w- c:\users\Sarah\AppData\Local\WindowsUpdate
2012-01-02 19:44 . 2012-01-02 19:44 7168 ----a-w- c:\windows\system32\drivers\ute4nzu5.sys
2012-01-02 19:15 . 2012-01-02 12:32 133208 ----a-w- c:\windows\system32\drivers\11959207.sys
2012-01-02 18:56 . 2012-01-02 18:56 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-01-02 15:48 . 2012-01-02 15:48 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-02 15:44 . 2012-01-02 12:32 133208 ----a-w- c:\windows\system32\drivers\84347022.sys
2012-01-02 02:04 . 2011-12-21 07:24 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-01-01 20:13 . 2012-01-01 20:13 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2012-01-01 20:12 . 2012-01-01 20:12 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-01-01 20:01 . 2012-01-01 20:01 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-12-31 17:05 . 2011-12-31 17:05 -------- d-----w- c:\users\Sarah\AppData\Roaming\Malwarebytes
2011-12-31 17:04 . 2011-12-31 17:04 -------- d-----w- c:\programdata\Malwarebytes
2011-12-31 17:04 . 2011-12-31 17:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-28 00:54 . 2012-01-10 02:45 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2011-12-28 00:54 . 2012-01-10 02:43 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-02 18:52 . 2011-11-05 20:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-02 18:50 . 2011-11-05 03:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-12-27 16:25 . 2009-07-13 23:12 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-11-06 14:27 . 2010-06-24 18:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-18 20:32 . 2011-03-08 11:19 150856 ----a-w- c:\windows\system32\mfevtps.exe
2011-10-15 19:16 . 2011-03-08 11:20 9608 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-10-15 19:16 . 2010-10-14 06:28 87656 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-10-15 19:16 . 2010-10-14 06:28 64880 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-10-15 19:16 . 2010-10-14 06:28 59456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-10-15 19:16 . 2010-10-14 06:28 57600 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-10-15 19:16 . 2010-10-14 06:28 464176 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-15 19:16 . 2010-10-14 06:28 338176 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-10-15 19:16 . 2010-10-14 06:28 180816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-10-15 19:16 . 2010-10-14 06:28 165680 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-10-15 19:16 . 2010-10-14 06:28 121256 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-12-21 07:24 . 2012-01-02 02:04 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-11-06 14:33 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-13 336384]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-01-26 10025576]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2011-01-18 1530472]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-17 1318552]
"ADevCtrl"="c:\program files\Acer\Device Control\ADevCtrl.exe" [2011-02-22 239696]
"AcerRingLauncher"="c:\program files\Acer\TouchApplicationSuite\Acer Ring\AcerRingLauncher.exe" [2011-03-04 15248]
"BackupManagerTray"="c:\program files\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-03-03 377664]
"OOTag"="c:\program files\Acer\OOBEOffer\ootag.exe" [2010-02-23 13856]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2011-02-11 1070160]
"AtherosBtStack"="c:\program files\Bluetooth Suite\BtvStack.exe" [2011-01-07 490656]
"AthBtTray"="c:\program files\Bluetooth Suite\AthBtTray.exe" [2011-01-07 302240]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-02-23 715368]
"xLaunchHIDMon"="c:\program files\HIDMon\HIDMon.exe" [2011-02-11 114688]
"AutoScreenRotationBlocker"="c:\program files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe" [2011-02-21 114768]
.
c:\users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\users\Sarah\AppData\Local\Temp\quickstart.exe [N/A]
_uninst_11959207.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_11959207.bat [N/A]
_uninst_61472742.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_61472742.bat [N/A]
_uninst_84347022.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_84347022.bat [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2011-3-8 723560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-01-31 244624]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 34976]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 258720]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 175776]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 49312]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 141088]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 241824]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 57600]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-09 198904]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-15 87656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-29 197224]
R3 ute4nzu5;AVZ Kernel Driver;c:\windows\system32\Drivers\ute4nzu5.sys [2012-01-02 7168]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-10 1343400]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 11959207;11959207;c:\windows\system32\DRIVERS\11959207.sys [2012-01-02 133208]
S0 84347022;84347022;c:\windows\system32\DRIVERS\84347022.sys [2012-01-02 133208]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 165680]
S1 BST;Bosch Sensortec BMA150 Driver;c:\windows\system32\DRIVERS\bma150.sys [2011-01-10 15936]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 64880]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-12 176128]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
S2 AtherosSvc;AtherosSvc;c:\program files\Bluetooth Suite\adminservice.exe [2011-01-07 56480]
S2 DsiDeviceControlService;Dritek Device Control Service;c:\program files\Acer\Device Control\DeviceCtrlSvc.exe [2011-02-22 66128]
S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2011-02-11 346704]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2011-02-23 739944]
S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 160608]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-10-18 150856]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-03-03 257344]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 SnxUsbDockingKB2267Srv;SnxUsbDockingKB2267 Service;c:\program files\USBKBTool\SnxUsbDockingKB2267Srv.exe [2011-02-04 86016]
S3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys [2009-07-13 7680]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-01-12 7566848]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-01-12 238592]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-11-16 101392]
S3 AX88772B;ASIX AX88772B USB2.0 to Fast Ethernet Adapter;c:\windows\system32\DRIVERS\ax88772b.sys [2010-12-31 81408]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 24736]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 338176]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-11-28 35968]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://acer.msn.com
TCP: DhcpNameServer = 64.251.160.2 64.251.173.40
FF - ProfilePath - c:\users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\thorvlvn.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-34279700.sys
AddRemove-DS4 Default Content 4.0.0.16 - c:\users\Sarah\Documents\DAZ 3D\Studio\My Library\Uninstallers\Remove-DS4 Default Content.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(6084)
c:\program files\Bluetooth Suite\AthCopyHook.dll
c:\program files\Spybot - Search & Destroy\SDHelper.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\system32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Acer\clear.fi\MVP\clear.fiAgent.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Launch Manager\LMworker.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\conhost.exe
c:\program files\Acer\TouchApplicationSuite\Acer Ring\Acer Ring.exe
c:\program files\Acer\Device Control\AdWmiSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
c:\windows\System32\msdtc.exe
c:\windows\system32\sppsvc.exe
c:\windows\ehome\ehsched.exe
c:\windows\eHome\EhTray.exe
c:\program files\Common Files\McAfee\Core\mchost.exe
c:\windows\ehome\ehRecvr.exe
.
**************************************************************************
.
Completion time: 2012-01-10 17:21:53 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-10 23:21
.
Pre-Run: 1,059,504,128 bytes free
Post-Run: 2,373,701,632 bytes free
.
- - End Of File - - 6EFF67499EABDA3CB03541A9E00050D8
 
1. Please open Notepad (Start>All Programs>Accessories>Notepad).

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Code:
File::
c:\windows\system32\DRIVERS\11959207.sys
c:\windows\system32\DRIVERS\84347022.sys

Folder::

Driver::
11959207
84347022

Registry::

ClearJavaCache::


3. Save the above as CFScript.txt

4. Close/disable all anti virus and anti malware programs again, so they do not interfere with the running of ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

CFScript.gif



6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
 
Here it is:

ComboFix 12-01-10.02 - Sarah 01/10/2012 17:42:34.2.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.1642.886 [GMT -6:00]
Running from: c:\users\Sarah\Desktop\ComboFix.exe
Command switches used :: E:\CFScript.txt
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\DRIVERS\11959207.sys"
"c:\windows\system32\DRIVERS\84347022.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_11959207
-------\Legacy_84347022
-------\Service_11959207
-------\Service_84347022
.
.
((((((((((((((((((((((((( Files Created from 2011-12-11 to 2012-01-11 )))))))))))))))))))))))))))))))
.
.
2012-01-11 00:01 . 2012-01-11 00:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-11 00:01 . 2012-01-11 00:01 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-01-11 00:01 . 2012-01-11 00:01 -------- d-----w- c:\users\Administer\AppData\Local\temp
2012-01-10 23:08 . 2012-01-11 01:24 -------- d-----w- c:\users\Sarah\AppData\Local\temp
2012-01-10 22:43 . 2011-04-25 02:35 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2012-01-10 09:31 . 2012-01-10 09:31 -------- d-----w- c:\windows\system32\Wat
2012-01-09 23:16 . 2011-04-28 03:29 60416 ----a-w- c:\windows\system32\drivers\BTHUSB.SYS
2012-01-09 23:16 . 2011-04-28 03:29 393216 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-01-09 23:16 . 2011-03-29 03:07 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-01-09 23:16 . 2011-03-29 03:06 76288 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-01-09 23:16 . 2011-03-29 03:06 284160 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-01-09 23:16 . 2011-03-29 03:06 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-01-09 23:16 . 2011-03-29 03:06 20480 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-01-09 23:16 . 2011-03-29 03:06 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-01-09 23:16 . 2011-03-29 03:06 5888 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-01-09 23:15 . 2011-03-11 05:44 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2012-01-09 23:15 . 2011-03-11 05:44 1210240 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-01-09 23:15 . 2011-03-11 05:44 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2012-01-09 23:15 . 2011-03-11 05:43 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2012-01-09 23:15 . 2011-03-11 05:39 1686016 ----a-w- c:\windows\system32\esent.dll
2012-01-09 23:15 . 2011-03-11 05:44 146304 ----a-w- c:\windows\system32\drivers\storport.sys
2012-01-09 23:15 . 2011-03-11 05:43 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2012-01-09 23:15 . 2011-03-11 05:43 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2012-01-09 23:15 . 2011-03-11 05:37 74240 ----a-w- c:\windows\system32\fsutil.exe
2012-01-03 02:01 . 2011-02-19 05:32 1074176 ----a-w- c:\windows\system32\DWrite.dll
2012-01-03 02:00 . 2011-02-19 05:33 802304 ----a-w- c:\windows\system32\FntCache.dll
2012-01-03 02:00 . 2011-02-19 05:32 739840 ----a-w- c:\windows\system32\d2d1.dll
2012-01-03 01:09 . 2009-11-25 18:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-01-03 01:09 . 2009-11-25 18:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-01-03 01:09 . 2009-11-25 18:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-01-03 01:09 . 2009-11-25 18:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-01-03 01:09 . 2009-11-25 18:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-01-03 00:56 . 2010-09-14 06:07 276992 ----a-w- c:\windows\system32\wcncsvc.dll
2012-01-02 23:01 . 2011-04-29 02:57 311296 ----a-w- c:\windows\system32\drivers\srv.sys
2012-01-02 23:01 . 2011-04-29 02:57 309760 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-01-02 23:01 . 2011-04-29 02:57 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-01-02 20:39 . 2010-10-16 04:34 573440 ----a-w- c:\windows\system32\odbc32.dll
2012-01-02 20:39 . 2010-10-16 04:33 987136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-01-02 20:39 . 2010-10-16 04:33 372736 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-01-02 20:39 . 2010-10-16 04:33 352256 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-01-02 20:39 . 2010-10-16 04:33 208896 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-01-02 20:39 . 2011-02-18 05:33 31232 ----a-w- c:\windows\system32\prevhost.exe
2012-01-02 20:39 . 2011-04-27 02:33 78336 ----a-w- c:\windows\system32\drivers\dfsc.sys
2012-01-02 20:38 . 2011-05-04 04:52 1401856 ----a-w- c:\windows\system32\mssrch.dll
2012-01-02 20:38 . 2011-05-04 04:53 1553920 ----a-w- c:\windows\system32\tquery.dll
2012-01-02 20:38 . 2011-05-04 04:52 428032 ----a-w- c:\windows\system32\SearchIndexer.exe
2012-01-02 20:38 . 2011-05-04 04:52 666624 ----a-w- c:\windows\system32\mssvp.dll
2012-01-02 20:38 . 2011-05-04 04:52 337408 ----a-w- c:\windows\system32\mssph.dll
2012-01-02 20:38 . 2011-05-04 04:52 197120 ----a-w- c:\windows\system32\mssphtb.dll
2012-01-02 20:38 . 2011-05-04 04:52 164352 ----a-w- c:\windows\system32\SearchProtocolHost.exe
2012-01-02 20:38 . 2011-05-04 04:52 86528 ----a-w- c:\windows\system32\SearchFilterHost.exe
2012-01-02 20:38 . 2011-05-04 04:52 59392 ----a-w- c:\windows\system32\msscntrs.dll
2012-01-02 20:38 . 2011-09-29 15:43 1285488 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-01-02 20:37 . 2011-10-01 04:43 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2012-01-02 20:37 . 2010-12-18 05:29 541184 ----a-w- c:\windows\system32\kerberos.dll
2012-01-02 20:37 . 2011-03-03 05:29 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-01-02 20:37 . 2011-03-03 05:27 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-01-02 20:37 . 2011-11-05 04:30 2048 ----a-w- c:\windows\system32\tzres.dll
2012-01-02 20:36 . 2011-07-09 02:26 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2012-01-02 20:36 . 2011-05-04 02:43 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2012-01-02 20:36 . 2011-05-04 02:43 96256 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2012-01-02 20:36 . 2011-10-15 05:48 534528 ----a-w- c:\windows\system32\EncDec.dll
2012-01-02 20:35 . 2010-03-04 07:33 1619968 ----a-w- c:\program files\Windows Mail\msoe.dll
2012-01-02 20:35 . 2011-10-26 04:42 3957104 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-01-02 20:35 . 2011-10-26 04:42 3901808 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-01-02 20:34 . 2011-11-24 04:23 2340352 ----a-w- c:\windows\system32\win32k.sys
2012-01-02 20:33 . 2011-10-26 04:25 38912 ----a-w- c:\windows\system32\csrsrv.dll
2012-01-02 20:33 . 2011-08-17 04:22 75776 ----a-w- c:\windows\system32\psisrndr.ax
2012-01-02 20:33 . 2011-08-17 04:26 465408 ----a-w- c:\windows\system32\psisdecd.dll
2012-01-02 20:33 . 2011-08-17 04:22 204288 ----a-w- c:\windows\system32\MSNP.ax
2012-01-02 20:33 . 2011-08-17 04:22 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
2012-01-02 20:33 . 2011-08-17 04:22 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
2012-01-02 20:33 . 2011-02-12 05:30 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2012-01-02 20:30 . 2010-12-23 05:28 642048 ----a-w- c:\windows\system32\CPFilters.dll
2012-01-02 20:30 . 2010-12-23 05:28 850432 ----a-w- c:\windows\system32\sbe.dll
2012-01-02 20:30 . 2010-12-23 05:24 199680 ----a-w- c:\windows\system32\mpg2splt.ax
2012-01-02 20:30 . 2011-05-03 04:50 740864 ----a-w- c:\windows\system32\inetcomm.dll
2012-01-02 20:30 . 2011-06-15 09:04 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2012-01-02 20:30 . 2011-06-15 09:04 122880 ----a-w- c:\windows\system32\odbccp32.dll
2012-01-02 20:30 . 2011-06-15 09:04 81920 ----a-w- c:\windows\system32\odbccr32.dll
2012-01-02 20:30 . 2011-06-15 09:04 86016 ----a-w- c:\windows\system32\odbccu32.dll
2012-01-02 20:30 . 2011-06-15 09:04 94208 ----a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2012-01-02 20:30 . 2011-06-15 09:04 163840 ----a-w- c:\windows\system32\odbctrac.dll
2012-01-02 20:28 . 2009-09-26 05:58 194488 ----a-w- c:\windows\system32\drivers\fvevol.sys
2012-01-02 20:28 . 2011-03-12 11:31 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2012-01-02 20:28 . 2011-02-26 05:33 2614784 ----a-w- c:\windows\explorer.exe
2012-01-02 20:28 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\system32\mstscax.dll
2012-01-02 20:28 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\system32\mstsc.exe
2012-01-02 20:28 . 2011-05-24 10:35 294912 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-01-02 20:28 . 2011-02-19 03:37 294912 ----a-w- c:\windows\system32\atmfd.dll
2012-01-02 20:28 . 2011-02-19 05:32 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-01-02 20:27 . 2011-08-27 04:43 571904 ----a-w- c:\windows\system32\oleaut32.dll
2012-01-02 20:27 . 2011-08-27 04:43 233472 ----a-w- c:\windows\system32\oleacc.dll
2012-01-02 20:27 . 2011-02-24 05:32 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-01-02 20:27 . 2010-12-21 05:38 204288 ----a-w- c:\windows\system32\upnp.dll
2012-01-02 20:27 . 2010-12-21 05:36 1389568 ----a-w- c:\windows\system32\msxml6.dll
2012-01-02 20:27 . 2010-12-21 05:36 1236992 ----a-w- c:\windows\system32\msxml3.dll
2012-01-02 20:26 . 2010-12-21 05:38 204800 ----a-w- c:\windows\system32\WebClnt.dll
2012-01-02 20:26 . 2010-12-21 05:38 350720 ----a-w- c:\windows\system32\winhttp.dll
2012-01-02 20:26 . 2010-12-21 05:34 80384 ----a-w- c:\windows\system32\davclnt.dll
2012-01-02 20:26 . 2010-12-21 05:38 51200 ----a-w- c:\windows\system32\wscapi.dll
2012-01-02 20:26 . 2010-12-21 05:38 14336 ----a-w- c:\windows\system32\slwga.dll
2012-01-02 20:26 . 2010-12-21 05:38 73728 ----a-w- c:\windows\system32\wscsvc.dll
2012-01-02 20:26 . 2010-10-27 04:40 1289536 ----a-w- c:\windows\system32\ntdll.dll
2012-01-02 20:26 . 2011-03-11 05:40 1137664 ----a-w- c:\windows\system32\mfc42.dll
2012-01-02 20:26 . 2011-03-11 05:40 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2012-01-02 20:26 . 2011-01-17 05:38 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2012-01-02 20:25 . 2011-02-23 05:05 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-01-02 20:19 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe
2012-01-02 20:18 . 2011-04-22 19:36 26496 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2012-01-02 20:17 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-01-02 20:05 . 2012-01-02 20:05 -------- d-----w- c:\users\Sarah\AppData\Local\WindowsUpdate
2012-01-02 19:44 . 2012-01-02 19:44 7168 ----a-w- c:\windows\system32\drivers\ute4nzu5.sys
2012-01-02 19:15 . 2012-01-02 12:32 133208 ----a-w- c:\windows\system32\drivers\11959207.sys
2012-01-02 18:56 . 2012-01-02 18:56 539984 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-01-02 15:48 . 2012-01-02 15:48 -------- d-----w- c:\programdata\Kaspersky Lab
2012-01-02 15:44 . 2012-01-02 12:32 133208 ----a-w- c:\windows\system32\drivers\84347022.sys
2012-01-02 02:04 . 2011-12-21 07:24 121816 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2012-01-01 20:13 . 2012-01-01 20:13 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore-2\Microsoft.MediaCenter.Sports.UI.dll
2012-01-01 20:12 . 2012-01-01 20:12 4283672 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2012-01-01 20:01 . 2012-01-01 20:01 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-12-31 17:05 . 2011-12-31 17:05 -------- d-----w- c:\users\Sarah\AppData\Roaming\Malwarebytes
2011-12-31 17:04 . 2011-12-31 17:04 -------- d-----w- c:\programdata\Malwarebytes
2011-12-31 17:04 . 2011-12-31 17:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-28 00:54 . 2012-01-10 02:45 737072 ----a-w- c:\programdata\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-02 18:52 . 2011-11-05 20:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-02 18:50 . 2011-11-05 03:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-12-27 16:25 . 2009-07-13 23:12 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-11-06 14:27 . 2010-06-24 18:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-18 20:32 . 2011-03-08 11:19 150856 ----a-w- c:\windows\system32\mfevtps.exe
2011-10-15 19:16 . 2011-03-08 11:20 9608 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-10-15 19:16 . 2010-10-14 06:28 87656 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2011-10-15 19:16 . 2010-10-14 06:28 64880 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2011-10-15 19:16 . 2010-10-14 06:28 59456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2011-10-15 19:16 . 2010-10-14 06:28 57600 ----a-w- c:\windows\system32\drivers\cfwids.sys
2011-10-15 19:16 . 2010-10-14 06:28 464176 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-15 19:16 . 2010-10-14 06:28 338176 ----a-w- c:\windows\system32\drivers\mfefirek.sys
2011-10-15 19:16 . 2010-10-14 06:28 180816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-10-15 19:16 . 2010-10-14 06:28 165680 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2011-10-15 19:16 . 2010-10-14 06:28 121256 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-12-21 07:24 . 2012-01-02 02:04 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-14 19:01 . 2011-11-06 14:33 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-13 336384]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-01-26 10025576]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RtHDVBg.exe" [2011-01-18 1530472]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-17 1318552]
"ADevCtrl"="c:\program files\Acer\Device Control\ADevCtrl.exe" [2011-02-22 239696]
"AcerRingLauncher"="c:\program files\Acer\TouchApplicationSuite\Acer Ring\AcerRingLauncher.exe" [2011-03-04 15248]
"BackupManagerTray"="c:\program files\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-03-03 377664]
"OOTag"="c:\program files\Acer\OOBEOffer\ootag.exe" [2010-02-23 13856]
"LManager"="c:\program files\Launch Manager\LManager.exe" [2011-02-11 1070160]
"AtherosBtStack"="c:\program files\Bluetooth Suite\BtvStack.exe" [2011-01-07 490656]
"AthBtTray"="c:\program files\Bluetooth Suite\AthBtTray.exe" [2011-01-07 302240]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"Power Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-02-23 715368]
"xLaunchHIDMon"="c:\program files\HIDMon\HIDMon.exe" [2011-02-11 114688]
"AutoScreenRotationBlocker"="c:\program files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe" [2011-02-21 114768]
.
c:\users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\users\Sarah\AppData\Local\Temp\quickstart.exe [N/A]
_uninst_11959207.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_11959207.bat [N/A]
_uninst_61472742.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_61472742.bat [N/A]
_uninst_84347022.lnk - c:\users\Sarah\AppData\Local\Temp\_uninst_84347022.bat [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Acer VCM.lnk - c:\program files\Acer\Acer VCM\AcerVCM.exe [2011-3-8 723560]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-01-31 244624]
R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 34976]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 258720]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 175776]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 49312]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 141088]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 241824]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2011-10-15 57600]
R3 GamesAppService;GamesAppService;c:\program files\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-09 198904]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2011-10-15 87656]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-29 197224]
R3 ute4nzu5;AVZ Kernel Driver;c:\windows\system32\Drivers\ute4nzu5.sys [2012-01-02 7168]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-10 1343400]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2011-10-15 165680]
S1 BST;Bosch Sensortec BMA150 Driver;c:\windows\system32\DRIVERS\bma150.sys [2011-01-10 15936]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2011-10-15 64880]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-01-12 176128]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
S2 AtherosSvc;AtherosSvc;c:\program files\Bluetooth Suite\adminservice.exe [2011-01-07 56480]
S2 DsiDeviceControlService;Dritek Device Control Service;c:\program files\Acer\Device Control\DeviceCtrlSvc.exe [2011-02-22 66128]
S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2011-02-11 346704]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2011-02-23 739944]
S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-28 214904]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2011-10-18 160608]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2011-10-18 150856]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files\NTI\Acer Backup Manager\IScheduleSvc.exe [2011-03-03 257344]
S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-30 260640]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 SnxUsbDockingKB2267Srv;SnxUsbDockingKB2267 Service;c:\program files\USBKBTool\SnxUsbDockingKB2267Srv.exe [2011-02-04 86016]
S3 acpials;ALS Sensor Filter;c:\windows\system32\DRIVERS\acpials.sys [2009-07-13 7680]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-01-12 7566848]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-01-12 238592]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2010-11-16 101392]
S3 AX88772B;ASIX AX88772B USB2.0 to Fast Ethernet Adapter;c:\windows\system32\DRIVERS\ax88772b.sys [2010-12-31 81408]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 24736]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2011-10-15 338176]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2010-11-28 35968]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://acer.msn.com
TCP: DhcpNameServer = 64.251.160.2 64.251.173.40
FF - ProfilePath - c:\users\Sarah\AppData\Roaming\Mozilla\Firefox\Profiles\thorvlvn.default\
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(4908)
c:\program files\Bluetooth Suite\AthCopyHook.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\windows\system32\WUDFHost.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\McAfee\SystemCore\mfefire.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\System32\msdtc.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\Acer\clear.fi\MVP\clear.fiAgent.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Launch Manager\LMworker.exe
c:\windows\system32\conhost.exe
c:\program files\Acer\TouchApplicationSuite\Acer Ring\Acer Ring.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Acer\Device Control\AdWmiSvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
c:\program files\Common Files\McAfee\Core\mchost.exe
.
**************************************************************************
.
Completion time: 2012-01-10 19:32:05 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-11 01:32
ComboFix2.txt 2012-01-10 23:21
.
Pre-Run: 2,422,906,880 bytes free
Post-Run: 2,465,161,216 bytes free
.
- - End Of File - - 196F79DFB6995071426095DEC4EE209C
 
How is computer doing?

Download OTL to your Desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
Scanning...
As far as I can tell, the redirection problem is gone. The action center can give me security warnings saying that there is no active firewall, spyware, or virus protection enabled, but it can't do anything about it.
McAfee says that the computer is secure.
 
OTL.txt is too long for one post. Here is part 1:

OTL logfile created on: 1/11/2012 3:16:44 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Sarah\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.60 Gb Total Physical Memory | 0.52 Gb Available Physical Memory | 32.28% Memory free
2.09 Gb Paging File | 0.59 Gb Available in Paging File | 28.09% Paging File free
Paging file location(s): C:\pagefile.sys 500 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 29.72 Gb Total Space | 2.26 Gb Free Space | 7.62% Space Free | Partition Type: NTFS

Computer Name: WRITER | User Name: Sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/11 15:14:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sarah\Desktop\OTL.exe
PRC - [2011/12/21 01:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/10/18 14:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2011/10/18 14:28:34 | 000,160,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
PRC - [2011/10/18 14:28:18 | 000,166,288 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\mcafee\systemcore\mcshield.exe
PRC - [2011/09/16 18:38:10 | 001,318,552 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mcafee.com\agent\mcagent.exe
PRC - [2011/07/15 22:31:12 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/03/04 16:50:18 | 003,594,112 | ---- | M] (Acer) -- C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\Acer Ring.exe
PRC - [2011/03/03 16:00:04 | 000,257,344 | ---- | M] (NTI Corporation) -- C:\Program Files\NTI\Acer Backup Manager\IScheduleSvc.exe
PRC - [2011/03/03 15:59:38 | 000,377,664 | ---- | M] (NTI Corporation) -- C:\Program Files\NTI\Acer Backup Manager\BackupManagerTray.exe
PRC - [2011/03/02 19:46:30 | 000,723,560 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\AcerVCM.exe
PRC - [2011/02/25 23:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/22 22:01:10 | 000,715,368 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
PRC - [2011/02/22 22:01:08 | 000,739,944 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
PRC - [2011/02/22 22:01:02 | 000,469,608 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
PRC - [2011/02/21 21:01:17 | 000,066,128 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe
PRC - [2011/02/21 21:01:16 | 000,239,696 | ---- | M] () -- C:\Program Files\Acer\Device Control\ADevCtrl.exe
PRC - [2011/02/21 21:01:16 | 000,106,064 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Acer\Device Control\AdWmiSvc.exe
PRC - [2011/02/21 07:33:32 | 000,114,768 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe
PRC - [2011/02/18 12:46:36 | 000,120,104 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Acer\clear.fi\MVP\clear.fiAgent.exe
PRC - [2011/02/11 06:49:46 | 000,332,368 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LMworker.exe
PRC - [2011/02/11 06:49:44 | 001,070,160 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\LManager.exe
PRC - [2011/02/11 06:49:44 | 000,346,704 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\dsiwmis.exe
PRC - [2011/02/11 03:53:18 | 000,114,688 | ---- | M] () -- C:\Program Files\HIDMon\HIDMON.exe
PRC - [2011/02/04 03:12:38 | 000,086,016 | ---- | M] () -- C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe
PRC - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
PRC - [2011/01/18 00:52:56 | 001,530,472 | ---- | M] (Realtek Semiconductor) -- C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
PRC - [2011/01/12 07:57:14 | 000,393,216 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011/01/12 07:56:44 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011/01/06 21:08:38 | 000,138,400 | ---- | M] (Atheros) -- C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe
PRC - [2011/01/06 21:04:54 | 000,490,656 | ---- | M] (Atheros Commnucations) -- C:\Program Files\Bluetooth Suite\BtvStack.exe
PRC - [2011/01/06 21:04:44 | 000,302,240 | ---- | M] (Atheros Commnucations) -- C:\Program Files\Bluetooth Suite\AthBtTray.exe
PRC - [2011/01/06 21:04:40 | 000,056,480 | ---- | M] (Atheros Commnucations) -- C:\Program Files\Bluetooth Suite\AdminService.exe
PRC - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files\Acer\Registration\GREGsvc.exe
PRC - [2009/07/13 19:14:46 | 000,115,200 | ---- | M] () -- \\?\C:\windows\System32\wbem\WMIADAP.EXE
PRC - [2009/07/13 19:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/13 19:14:41 | 000,354,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\StikyNot.exe
PRC - [2009/07/13 19:14:15 | 000,301,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe


========== Modules (No Company Name) ==========

MOD - [2012/01/10 03:47:57 | 002,295,296 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\6d859463c9e6a7423ddb335211a79dda\System.Core.ni.dll
MOD - [2012/01/10 03:43:45 | 000,368,128 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5672e6b9d976feca51deb06d8dd1df0e\PresentationFramework.Aero.ni.dll
MOD - [2012/01/10 03:43:22 | 014,322,688 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09e39322b47f9b4e8dd2199ff03acb2e\PresentationFramework.ni.dll
MOD - [2012/01/10 03:42:24 | 012,216,320 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2dc021a8311197516e4fa325b292f21\PresentationCore.ni.dll
MOD - [2012/01/10 03:41:46 | 003,325,952 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll
MOD - [2012/01/10 03:41:01 | 012,431,360 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll
MOD - [2012/01/10 03:40:05 | 000,771,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll
MOD - [2012/01/10 03:39:37 | 011,807,744 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5a95ba97100404e2ab26b5a9ab9ef965\System.Web.ni.dll
MOD - [2012/01/10 03:39:08 | 001,586,688 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll
MOD - [2012/01/10 03:38:56 | 005,452,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll
MOD - [2012/01/10 03:38:44 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll
MOD - [2012/01/10 03:38:26 | 007,949,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll
MOD - [2012/01/10 03:38:09 | 011,490,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2012/01/02 12:52:54 | 008,527,008 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/12/21 01:24:51 | 002,124,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/03/04 16:50:56 | 000,008,592 | ---- | M] () -- C:\Program Files\Acer\TouchApplicationSuite\TouchBrowser\TouchBrowserMui.dll
MOD - [2011/03/03 16:00:48 | 000,465,640 | ---- | M] () -- C:\Program Files\NTI\Acer Backup Manager\sqlite3.dll
MOD - [2011/03/03 16:00:26 | 001,081,664 | ---- | M] () -- C:\Program Files\NTI\Acer Backup Manager\ACE.dll
MOD - [2011/02/21 21:01:16 | 000,239,696 | ---- | M] () -- C:\Program Files\Acer\Device Control\ADevCtrl.exe
MOD - [2011/02/21 21:01:16 | 000,057,424 | ---- | M] () -- C:\Program Files\Acer\Device Control\BrandDetection.dll
MOD - [2011/02/11 03:53:18 | 000,114,688 | ---- | M] () -- C:\Program Files\HIDMon\HIDMON.exe


========== Win32 Services (SafeList) ==========

SRV - [2012/01/10 03:00:33 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/10/18 16:59:54 | 000,361,976 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/10/18 14:32:30 | 000,150,856 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/10/18 14:28:34 | 000,160,608 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2011/10/18 14:28:18 | 000,166,288 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/03/03 16:00:04 | 000,257,344 | ---- | M] (NTI Corporation) [Auto | Running] -- C:\Program Files\NTI\Acer Backup Manager\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2011/02/22 22:01:08 | 000,739,944 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe -- (ePowerSvc)
SRV - [2011/02/21 21:01:17 | 000,066,128 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files\Acer\Device Control\DeviceCtrlSvc.exe -- (DsiDeviceControlService)
SRV - [2011/02/11 06:49:44 | 000,346,704 | ---- | M] (Dritek System Inc.) [Auto | Running] -- C:\Program Files\Launch Manager\dsiwmis.exe -- (DsiWMIService)
SRV - [2011/02/04 03:12:38 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\USBKBTool\SnxUsbDockingKB2267Srv.exe -- (SnxUsbDockingKB2267Srv)
SRV - [2011/01/31 15:55:14 | 000,244,624 | ---- | M] (Acer Incorporated) [Auto | Stopped] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Live Updater Service)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Unknown | Stopped] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2011/01/12 07:56:44 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/01/06 21:08:38 | 000,138,400 | ---- | M] (Atheros) [Auto | Running] -- C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe -- (Atheros Bt&Wlan Coex Agent)
SRV - [2011/01/06 21:04:40 | 000,056,480 | ---- | M] (Atheros Commnucations) [Auto | Running] -- C:\Program Files\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010/10/12 11:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/08/09 16:41:46 | 000,198,904 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\McAfee\msc\McAWFwk.exe -- (McAWFwk)
SRV - [2010/01/29 18:52:58 | 000,260,640 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Acer VCM\RS_Service.exe -- (RS_Service)
SRV - [2010/01/08 07:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/07/13 19:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV - [2012/01/02 13:44:49 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ute4nzu5.sys -- (ute4nzu5)
DRV - [2011/10/15 13:16:16 | 000,464,176 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/15 13:16:16 | 000,338,176 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/10/15 13:16:16 | 000,180,816 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/15 13:16:16 | 000,165,680 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/15 13:16:16 | 000,121,256 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/10/15 13:16:16 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/15 13:16:16 | 000,064,880 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/10/15 13:16:16 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/15 13:16:16 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2011/01/12 08:38:26 | 007,566,848 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011/01/12 07:14:58 | 000,238,592 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2011/01/10 06:59:36 | 000,015,936 | ---- | M] (Bosch Sensortec GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\bma150.sys -- (BST)
DRV - [2011/01/06 21:05:14 | 000,241,824 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btfilter.sys -- (BtFilter)
DRV - [2011/01/06 21:05:14 | 000,141,088 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV - [2011/01/06 21:05:14 | 000,049,312 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV - [2011/01/06 21:05:12 | 000,175,776 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV - [2011/01/06 21:05:12 | 000,034,976 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btath_flt.sys -- (AthBTPort)
DRV - [2011/01/06 21:05:10 | 000,258,720 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV - [2011/01/06 21:05:10 | 000,024,736 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btath_bus.sys -- (BTATH_BUS)
DRV - [2010/12/31 01:17:32 | 000,081,408 | ---- | M] (ASIX Electronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ax88772b.sys -- (AX88772B)
DRV - [2010/11/28 13:50:40 | 000,035,968 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2010/11/16 17:04:24 | 000,101,392 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2010/11/09 04:26:46 | 001,884,160 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2010/10/29 02:11:08 | 000,197,224 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2009/07/13 17:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 17:45:20 | 000,007,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\acpials.sys -- (acpials)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3387651535-152678953-4247029933-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-3387651535-152678953-4247029933-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2011/03/08 05:14:55 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files\EpicPlay\npEpicHost.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/01/02 14:15:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/01/11 15:16:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/01 20:04:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/11/10 12:48:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sarah\AppData\Roaming\mozilla\Extensions
[2012/01/02 18:49:53 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/12/21 01:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 13:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2011/12/20 22:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/28 18:26:50 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml.old
[2011/12/20 22:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2012/01/10 19:23:40 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120102204249.dll (McAfee, Inc.)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [AcerRingLauncher] C:\Program Files\Acer\TouchApplicationSuite\Acer Ring\AcerRingLauncher.exe (Acer)
O4 - HKLM..\Run: [ADevCtrl] C:\Program Files\Acer\Device Control\ADevCtrl.exe ()
O4 - HKLM..\Run: [AthBtTray] C:\Program Files\Bluetooth Suite\AthBtTray.exe (Atheros Commnucations)
O4 - HKLM..\Run: [AtherosBtStack] C:\Program Files\Bluetooth Suite\BtvStack.exe (Atheros Commnucations)
O4 - HKLM..\Run: [AutoScreenRotationBlocker] C:\Program Files\Acer\Auto Screen Rotation Blocker\AutoScreenRotationBlocker.exe (Dritek System Inc.)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [OOTag] C:\Program Files\Acer\OOBEOffer\OOTag.exe (Microsoft)
O4 - HKLM..\Run: [Power Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [xLaunchHIDMon] C:\Program Files\HIDMon\HIDMON.exe ()
O4 - HKU\S-1-5-21-3387651535-152678953-4247029933-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3387651535-152678953-4247029933-1000..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = File not found
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_11959207.lnk = File not found
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61472742.lnk = File not found
O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84347022.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3387651535-152678953-4247029933-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3387651535-152678953-4247029933-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.251.160.2 64.251.173.40
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2145E70C-E825-40EC-BADD-4208DF81DA52}: DhcpNameServer = 64.251.160.2 64.251.173.40
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CC6BEF89-113E-44E5-B422-DA5BE152EEB2}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE7CC4F7-0702-46B9-B3BD-3B5633BF7B99}: DhcpNameServer = 64.251.160.2 64.251.173.40
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/11 15:14:38 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Sarah\Desktop\OTL.exe
[2012/01/11 15:14:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/01/11 10:08:34 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Roaming\vlc
[2012/01/10 19:23:45 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/01/10 17:08:09 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Local\temp
[2012/01/10 16:40:08 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2012/01/10 16:40:08 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2012/01/10 16:40:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2012/01/10 16:39:54 | 000,000,000 | ---D | C] -- C:\windows\ERDNT
[2012/01/10 16:30:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/10 16:28:38 | 004,377,322 | R--- | C] (Swearware) -- C:\Users\Sarah\Desktop\ComboFix.exe
[2012/01/10 15:38:00 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Users\Sarah\Desktop\aswMBR.exe
[2012/01/10 03:31:37 | 000,000,000 | ---D | C] -- C:\windows\System32\Wat
[2012/01/06 18:56:14 | 000,000,000 | ---D | C] -- C:\Users\Sarah\Documents\My Barnes & Noble eBooks
[2012/01/02 20:00:18 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Sarah\Desktop\dds.scr
[2012/01/02 18:45:59 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2012/01/02 14:05:36 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Local\WindowsUpdate
[2012/01/02 13:15:14 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\windows\System32\drivers\11959207.sys
[2012/01/02 13:08:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/01/02 09:48:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012/01/02 09:44:51 | 000,133,208 | ---- | C] (Kaspersky Lab ZAO) -- C:\windows\System32\drivers\84347022.sys
[2012/01/01 13:28:34 | 000,000,000 | ---D | C] -- C:\Users\Sarah\Desktop\gmer
[2011/12/31 11:05:28 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Roaming\Malwarebytes
[2011/12/31 11:05:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/12/31 11:04:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/31 11:04:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/12/31 10:26:43 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2011/12/31 10:09:06 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2011/12/26 13:15:47 | 000,000,000 | ---D | C] -- C:\ProgramData\RTMI2
[2011/12/26 13:13:07 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Iceberg Interactive
[2011/12/26 13:04:36 | 000,000,000 | ---D | C] -- C:\Program Files\Iceberg Interactive
[2011/12/14 14:44:05 | 000,000,000 | ---D | C] -- C:\Users\Sarah\AppData\Roaming\gtk-2.0
[2011/12/13 17:47:41 | 000,000,000 | ---D | C] -- C:\Users\Sarah\.thumbnails
[2011/12/13 17:45:39 | 000,000,000 | ---D | C] -- C:\Users\Sarah\.gimp-2.6
[2011/12/13 17:45:38 | 000,000,000 | ---D | C] -- C:\Users\Sarah\Documents\gegl-0.0

========== Files - Modified Within 30 Days ==========

[2012/01/11 15:18:01 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/11 15:18:01 | 000,009,696 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/11 15:17:40 | 000,615,360 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2012/01/11 15:17:40 | 000,103,702 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2012/01/11 15:14:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sarah\Desktop\OTL.exe
[2012/01/11 15:10:11 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2012/01/11 15:09:54 | 000,067,584 | -H-- | M] () -- C:\windows\bootstat.dat
[2012/01/11 15:09:35 | 860,827,648 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/10 19:23:40 | 000,000,027 | ---- | M] () -- C:\windows\System32\drivers\etc\hosts
[2012/01/10 15:48:52 | 000,000,512 | ---- | M] () -- C:\Users\Sarah\Desktop\MBR.dat
[2012/01/10 15:25:22 | 004,377,322 | R--- | M] (Swearware) -- C:\Users\Sarah\Desktop\ComboFix.exe
[2012/01/10 14:35:48 | 000,044,607 | ---- | M] () -- C:\Users\Sarah\Desktop\bootkit_remover.zip
[2012/01/10 14:35:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Sarah\Desktop\aswMBR.exe
[2012/01/10 11:58:46 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Sarah\Desktop\tdsskiller.exe
[2012/01/10 03:33:38 | 000,307,752 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2012/01/02 20:00:44 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Sarah\Desktop\dds.scr
[2012/01/02 13:44:49 | 000,007,168 | ---- | M] () -- C:\windows\System32\drivers\ute4nzu5.sys
[2012/01/02 13:18:38 | 000,001,008 | ---- | M] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_11959207.lnk
[2012/01/02 10:27:59 | 000,000,124 | -HS- | M] () -- C:\windows\0711449drv.spi
[2012/01/02 10:11:02 | 000,001,008 | ---- | M] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61472742.lnk
[2012/01/02 09:48:27 | 000,001,008 | ---- | M] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84347022.lnk
[2012/01/02 06:32:07 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\windows\System32\drivers\84347022.sys
[2012/01/02 06:32:07 | 000,133,208 | ---- | M] (Kaspersky Lab ZAO) -- C:\windows\System32\drivers\11959207.sys
[2012/01/01 20:14:46 | 000,001,411 | ---- | M] () -- C:\Users\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/01/01 20:08:41 | 000,072,822 | ---- | M] () -- C:\windows\System32\ieuinit.inf
[2011/12/31 11:05:08 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/31 11:01:20 | 000,000,150 | ---- | M] () -- C:\Users\Sarah\Desktop\rk-proxy.reg
[2011/12/31 10:57:47 | 000,028,682 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\458v73p75ekmqk3f8msv2l
[2011/12/31 10:57:47 | 000,028,682 | -HS- | M] () -- C:\ProgramData\458v73p75ekmqk3f8msv2l
[2011/12/31 10:09:06 | 000,000,681 | ---- | M] () -- C:\Users\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/12/31 10:01:47 | 000,002,062 | ---- | M] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/12/31 10:01:34 | 000,002,343 | ---- | M] () -- C:\Users\Sarah\Desktop\Spybot - Search & Destroy.lnk
[2011/12/31 10:01:32 | 000,002,099 | ---- | M] () -- C:\Users\Sarah\Desktop\Return to Mysterious Island 2.lnk
[2011/12/30 04:55:48 | 000,027,878 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
[2011/12/30 04:55:48 | 000,027,878 | -HS- | M] () -- C:\ProgramData\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
[2011/12/27 16:34:26 | 000,028,058 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\33tc3173v44sqee43uclq23c54s20c2j
[2011/12/27 16:34:26 | 000,028,058 | -HS- | M] () -- C:\ProgramData\33tc3173v44sqee43uclq23c54s20c2j
[2011/12/23 17:49:35 | 000,002,484 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
[2011/12/14 21:12:11 | 000,002,806 | ---- | M] () -- C:\Users\Sarah\.recently-used.xbel

========== Files Created - No Company Name ==========

[2012/01/10 16:40:08 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2012/01/10 16:40:08 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2012/01/10 16:40:08 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2012/01/10 16:40:08 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2012/01/10 16:40:08 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2012/01/10 15:48:52 | 000,000,512 | ---- | C] () -- C:\Users\Sarah\Desktop\MBR.dat
[2012/01/10 15:38:00 | 000,044,607 | ---- | C] () -- C:\Users\Sarah\Desktop\bootkit_remover.zip
[2012/01/02 13:44:38 | 000,007,168 | ---- | C] () -- C:\windows\System32\drivers\ute4nzu5.sys
[2012/01/02 13:18:38 | 000,001,008 | ---- | C] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_11959207.lnk
[2012/01/02 10:27:59 | 000,000,124 | -HS- | C] () -- C:\windows\0711449drv.spi
[2012/01/02 10:11:02 | 000,001,008 | ---- | C] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61472742.lnk
[2012/01/02 09:48:27 | 000,001,008 | ---- | C] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84347022.lnk
[2012/01/01 20:16:45 | 000,001,409 | ---- | C] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/01/01 20:08:41 | 000,072,822 | ---- | C] () -- C:\windows\System32\ieuinit.inf
[2012/01/01 20:04:35 | 000,001,112 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/12/31 11:05:08 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/31 11:01:20 | 000,000,150 | ---- | C] () -- C:\Users\Sarah\Desktop\rk-proxy.reg
[2011/12/31 10:09:06 | 000,000,681 | ---- | C] () -- C:\Users\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2011/12/31 10:07:09 | 000,028,682 | -HS- | C] () -- C:\Users\Sarah\AppData\Local\458v73p75ekmqk3f8msv2l
[2011/12/31 10:07:09 | 000,028,682 | -HS- | C] () -- C:\ProgramData\458v73p75ekmqk3f8msv2l
[2011/12/29 18:43:33 | 000,027,878 | -HS- | C] () -- C:\Users\Sarah\AppData\Local\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
[2011/12/29 18:43:33 | 000,027,878 | -HS- | C] () -- C:\ProgramData\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
[2011/12/26 21:24:02 | 000,028,058 | -HS- | C] () -- C:\Users\Sarah\AppData\Local\33tc3173v44sqee43uclq23c54s20c2j
[2011/12/26 21:24:02 | 000,028,058 | -HS- | C] () -- C:\ProgramData\33tc3173v44sqee43uclq23c54s20c2j
[2011/12/26 13:13:07 | 000,002,099 | ---- | C] () -- C:\Users\Sarah\Desktop\Return to Mysterious Island 2.lnk
[2011/12/14 21:12:11 | 000,002,806 | ---- | C] () -- C:\Users\Sarah\.recently-used.xbel
[2011/11/17 20:20:18 | 000,000,193 | ---- | C] () -- C:\windows\WORDPAD.INI
[2011/03/26 16:53:45 | 000,001,165 | ---- | C] () -- C:\windows\SYSTEMCD.dat
[2011/03/26 16:53:45 | 000,000,620 | ---- | C] () -- C:\windows\LPCD.dat
[2011/03/26 16:53:45 | 000,000,438 | ---- | C] () -- C:\windows\RCD.dat
[2011/03/26 16:53:45 | 000,000,066 | ---- | C] () -- C:\windows\NAPP.dat
[2011/03/08 05:12:06 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011/03/08 05:08:45 | 000,247,560 | ---- | C] () -- C:\windows\System32\drivers\RTConvEQ.dat
[2011/03/08 05:08:45 | 000,039,672 | ---- | C] () -- C:\windows\System32\drivers\RtPCEE3.DAT
[2011/03/08 05:08:45 | 000,029,494 | ---- | C] () -- C:\windows\System32\drivers\RtPCEE4.DAT
[2011/03/08 05:08:45 | 000,002,084 | ---- | C] () -- C:\windows\System32\drivers\SamSfPa.dat
[2011/03/08 05:08:45 | 000,001,448 | ---- | C] () -- C:\windows\System32\drivers\RtHdatEx.dat
[2011/03/08 05:08:45 | 000,000,520 | ---- | C] () -- C:\windows\System32\drivers\RTEQEX3.dat
[2011/03/08 05:08:45 | 000,000,520 | ---- | C] () -- C:\windows\System32\drivers\RTEQEX2.dat
[2011/03/08 05:08:45 | 000,000,520 | ---- | C] () -- C:\windows\System32\drivers\RTEQEX1.dat
[2011/03/08 05:08:45 | 000,000,520 | ---- | C] () -- C:\windows\System32\drivers\RTEQEX0.dat
[2011/03/08 05:08:45 | 000,000,176 | ---- | C] () -- C:\windows\System32\drivers\RTHDAEQ1.dat
[2011/03/08 05:08:45 | 000,000,024 | ---- | C] () -- C:\windows\System32\drivers\rtkhdaud.dat
[2011/03/08 04:21:39 | 000,003,113 | ---- | C] () -- C:\windows\System32\atipblag.dat
[2011/03/08 04:21:38 | 000,227,587 | ---- | C] () -- C:\windows\System32\atiicdxx.dat
[2011/01/06 20:55:08 | 000,246,804 | ---- | C] () -- C:\windows\System32\drivers\AtherosBt.bin
[2009/07/13 22:57:37 | 000,067,584 | -H-- | C] () -- C:\windows\bootstat.dat
[2009/07/13 22:33:53 | 000,307,752 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2009/07/13 20:05:48 | 000,615,360 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2009/07/13 20:05:48 | 000,291,294 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2009/07/13 20:05:48 | 000,103,702 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2009/07/13 20:05:48 | 000,031,548 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2009/07/13 20:05:05 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2009/07/13 20:04:11 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2009/07/13 17:55:01 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/13 17:51:43 | 000,073,728 | ---- | C] () -- C:\windows\System32\BthpanContextHandler.dll
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\windows\System32\BWContextHandler.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat

========== LOP Check ==========

[2011/12/31 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\78CD6
[2011/11/05 22:46:18 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Acer
[2011/11/06 22:07:07 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\Barnes & Noble
[2011/11/16 12:00:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\bpppnGG5aQH6W7
[2011/11/16 09:58:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\BTXXXqjYCekIVzN
[2011/11/17 20:09:47 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\CG4aQH6sKE9ZYwI
[2011/11/06 22:08:07 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1
[2011/11/17 20:09:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\crzONxA0ciDp
[2011/12/31 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\D6E65
[2011/11/17 12:38:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\DA1ivD2on4m
[2011/12/06 16:21:54 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\DAZ 3D
[2011/11/16 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\delOBtzP0ciDoFp
[2011/11/16 20:28:35 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\gH5sQJ7dE8R9YjV
[2011/12/14 21:11:59 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\gtk-2.0
[2011/11/16 14:54:01 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\GxA0uvSib3n5Q6W
[2011/11/17 21:49:57 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\HUelIBty2F5ERXj
[2011/11/20 13:38:32 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\i0ucS2ibDpaHW7T
[2011/11/17 12:38:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\ksQJdEK8g9YwUlB
[2011/11/04 21:29:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\OpenOffice.org
[2011/11/05 22:49:13 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\PowerCinema
[2011/11/16 14:54:01 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\rKfRL9hTXjCkBzN
[2011/11/16 09:58:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\sddWWK77fR9
[2011/11/05 23:26:59 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\SocialJogger
[2011/11/21 21:34:35 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\SoftGrid Client
[2012/01/06 18:58:16 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\TouchBrowser
[2011/11/21 21:29:07 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\TP
[2011/11/16 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\twwjjUVVel
[2011/11/16 12:00:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\vRL9gTXqjCkVzNx
[2011/11/20 13:33:25 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\VTXqYCekIrOt
[2011/11/20 13:38:53 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\vVrlOBtxPySiDoF
[2011/11/17 21:49:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\yrzNyxASbpaJ8R9
[2011/11/16 09:58:30 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\zjCeekIBrzOyxAv
[2012/01/10 16:44:59 | 000,028,760 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========
 
part two:

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/06/10 15:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2011/03/08 04:23:40 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/01/10 19:32:06 | 000,024,840 | ---- | M] () -- C:\ComboFix.txt
[2009/06/10 15:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2012/01/11 15:09:35 | 860,827,648 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/26 16:14:03 | 000,000,000 | ---- | M] () -- C:\mini-agent.log
[2012/01/11 15:09:48 | 524,288,000 | -HS- | M] () -- C:\pagefile.sys
[2011/12/31 11:02:28 | 000,000,968 | ---- | M] () -- C:\rkill.log
[2011/11/26 12:20:59 | 000,079,996 | ---- | M] () -- C:\TDSSKiller.2.6.21.0_26.11.2011_12.20.21_log.txt
[2011/12/27 10:25:16 | 000,081,594 | ---- | M] () -- C:\TDSSKiller.2.6.21.0_27.12.2011_10.23.20_log.txt
[2012/01/10 12:02:52 | 000,081,076 | ---- | M] () -- C:\TDSSKiller.2.7.0.0_10.01.2012_11.59.22_log.txt

< %systemroot%\Fonts\*.com >
[2009/07/13 22:52:25 | 000,026,040 | ---- | M] () -- C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:52:25 | 000,026,489 | ---- | M] () -- C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:52:25 | 000,029,779 | ---- | M] () -- C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:52:25 | 000,043,318 | ---- | M] () -- C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:31:19 | 000,000,065 | ---- | M] () -- C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 19:15:35 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/13 19:16:19 | 000,029,696 | ---- | M] (Microsoft Corporation) -- C:\windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/23 01:32:56 | 000,301,936 | ---- | M] (Microsoft Corporation) -- C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 22:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/01/01 20:14:46 | 000,000,221 | -HS- | M] () -- C:\Users\Sarah\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2012/01/10 14:35:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Sarah\Desktop\aswMBR.exe
[2011/09/20 03:02:40 | 000,083,968 | ---- | M] (Esage Lab) -- C:\Users\Sarah\Desktop\boot_cleaner.exe
[2012/01/10 15:25:22 | 004,377,322 | R--- | M] (Swearware) -- C:\Users\Sarah\Desktop\ComboFix.exe
[2012/01/11 15:14:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sarah\Desktop\OTL.exe
[2012/01/10 11:58:46 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Sarah\Desktop\tdsskiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 15:20:04 | 000,000,802 | ---- | M] () -- C:\windows\ADDINS\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/03/26 16:12:40 | 000,008,192 | ---- | M] () -- C:\windows\SECURITY\Database\edb.chk
[2011/03/26 16:12:40 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edb.log
[2011/03/26 16:01:16 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00001.jrs
[2011/03/26 16:01:16 | 001,048,576 | ---- | M] () -- C:\windows\SECURITY\Database\edbres00002.jrs
[2011/03/26 16:12:40 | 001,056,768 | ---- | M] () -- C:\windows\SECURITY\Database\tmp.edb

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2011/11/03 23:11:40 | 000,000,402 | -HS- | M] () -- C:\Users\Sarah\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >
[2011/12/27 16:34:26 | 000,028,058 | -HS- | M] () -- C:\ProgramData\33tc3173v44sqee43uclq23c54s20c2j
[2011/12/31 10:57:47 | 000,028,682 | -HS- | M] () -- C:\ProgramData\458v73p75ekmqk3f8msv2l
[2011/03/26 16:42:00 | 000,005,584 | ---- | M] () -- C:\ProgramData\ArcadeDeluxe5.log
[2011/12/30 04:55:48 | 000,027,878 | -HS- | M] () -- C:\ProgramData\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.* >

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >


< End of report >
 
and Extras.txt:
OTL Extras logfile created on: 1/11/2012 3:16:45 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Sarah\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.60 Gb Total Physical Memory | 0.52 Gb Available Physical Memory | 32.28% Memory free
2.09 Gb Paging File | 0.59 Gb Available in Paging File | 28.09% Paging File free
Paging file location(s): C:\pagefile.sys 500 1500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 29.72 Gb Total Space | 2.26 Gb Free Space | 7.62% Space Free | Partition Type: NTFS

Computer Name: WRITER | User Name: Sarah | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.cpl [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.hlp [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.hta [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.inf [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found
.ini [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-3387651535-152678953-4247029933-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"{047F790A-7A2A-4B6A-AD02-38092BA63DAC}" = Acer VCM
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Backup Manager V3
"{101A497C-7EF6-4001-834D-E5FA1C70FEFA}" = Bluetooth Win7 Suite
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1C572D82-7E38-4A13-932A-D651AA95E1E9}" = Acer Touch Application Suite
"{1D894873-0D35-5F79-8F72-6C1BC02AB9CA}" = CCC Help Danish
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2B6492B6-BE53-C890-2B15-6B3C8287DD83}" = CCC Help Russian
"{2C303EE0-A595-3543-A71A-931C7AC40EDE}" = Microsoft Primary Interoperability Assemblies 2005
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Virtual Earth 3D (Beta)
"{2EAC2EBA-EFF8-E786-A685-E59AF35087E4}" = CCC Help Italian
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{342B9C98-5BEE-399B-7263-BC9C4E38A882}" = ccc-core-static
"{3498B743-779F-6429-D119-A07653A1756F}" = CCC Help Korean
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}" = Microsoft XNA Framework Redistributable 3.0
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Acer ePower Management
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{43AAE145-83CF-4C96-9A5E-756CEFCE879F}" = clear.fi Client
"{4441282F-90A4-814A-A183-35DCB091E397}" = CCC Help Greek
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{5456D07D-629A-8D12-BE0D-A95CBC9DEE7E}" = CCC Help Dutch
"{54A168C9-2250-4058-80EB-1F4A4192548A}" = AX88772B Windows 7 Drivers
"{5C52C331-09A1-7F31-5331-CDBABD9960B3}" = Catalyst Control Center InstallProxy
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{63C6C285-7794-EC3A-A99A-B93F2A1C3096}" = Catalyst Control Center Localization All
"{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = SocialJogger
"{67B49EB8-0F0F-5513-0FF9-F120B1EF44B7}" = CCC Help French
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6B5C0E6F-7D11-7972-C276-833010563BE4}" = CCC Help Portuguese
"{6C50AF4D-212B-240A-3F43-D0B1E03DB2D4}" = ccc-utility
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App (Acer Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7166D240-F1EE-4044-B0F3-F6AB1AF8AE72}" = HIDMon
"{74626E9E-F880-8BA1-1211-2B37A0254035}" = CCC Help Spanish
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{8190F7B6-BFCE-4F60-8670-59F1709BFF9F}" = Catalyst Control Center - Branding
"{8AB9CAD9-12CE-9C2D-726C-5A4BD84CABDD}" = CCC Help Turkish
"{8ABCCB06-BE5F-903B-10CA-10D5A96E9A13}" = CCC Help Chinese Standard
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF90DB8-6DED-44A3-B182-244FEC09012F}" = Microsoft Touch Pack for Windows 7
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93DED073-01CE-E238-919E-2ADF059ACE30}" = ATI Catalyst Install Manager
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{965F585D-E44A-8C3E-C68D-B78CF0D8D546}" = CCC Help Hungarian
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9ECA28E4-29DD-3F55-DA48-678E164A2144}" = WMV9/VC-1 Video Playback
"{A001B149-0FFE-C376-BC28-556616F1DF1A}" = CCC Help Finnish
"{A049C53B-A802-36D5-2F46-AC5E5F3D9043}" = CCC Help Thai
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B3D9E321-72EE-9C01-1B58-C9059263953B}" = CCC Help Norwegian
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BD35202B-EF1D-6880-07E3-2AE2C67B6F08}" = Catalyst Control Center Graphics Previews Common
"{BDD4164A-E9DE-AE28-0738-A606514B681A}" = CCC Help English
"{BF32E327-1DFF-47DF-3E84-1E614888AA1E}" = CCC Help Swedish
"{C115CD58-E79D-68C5-FF3F-52D6AFADA051}" = CCC Help Polish
"{C48B4153-D899-BBB0-7FA9-2B0751AC8B4E}" = CCC Help Chinese Traditional
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5774C5C-8FB1-7B91-ED69-66F9C00E72FF}" = CCC Help Japanese
"{DBCB7CAB-5935-A1EB-DC6D-722DA95BDB22}" = CCC Help Czech
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F7AD663E-8A7D-0CBB-14AF-36646F335012}" = CCC Help German
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer Registration" = Acer Registration
"Acer Screensaver" = Acer ScreenSaver
"Acer Welcome Center" = Welcome Center
"ADevCtrl" = Acer Device Control
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AUPEO!" = AUPEO!
"AutoScreenRotationBlocker" = Acer Auto Screen Rotation Blocker
"BN_DesktopReader" = NOOK for PC
"Identity Card" = Identity Card
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Acer Crystal Eye Webcam
"InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}" = Acer Backup Manager
"InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = clear.fi
"InstallShield_{54A168C9-2250-4058-80EB-1F4A4192548A}" = AX88772B Windows 7 Drivers
"InstallShield_{64EF903E-D00A-414C-94A4-FBA368FFCDC9}" = SocialJogger
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"Mozilla Firefox 9.0.1 (x86 en-US)" = Mozilla Firefox 9.0.1 (x86 en-US)
"MSC" = McAfee AntiVirus Plus
"Return to Mysterious Island 2" = Return to Mysterious Island 2
"USBKBTool" = USBKBTool 1.0.3.6
"VLC media player" = VLC media player 1.1.11
"WildTangent acer Master Uninstall" = Acer Games
"WinLiveSuite" = Windows Live Essentials
"WTA-c09c8859-6865-42b8-b1fd-f3a03ffa7c75" = Bookworm Adventures

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3387651535-152678953-4247029933-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/4/2012 10:54:25 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:55:28 AM | Computer Name = Writer | Source = MsiInstaller | ID = 11935
Description =

Error - 1/4/2012 10:55:48 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:56:28 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:56:45 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:57:02 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:57:27 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:58:08 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:58:21 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

Error - 1/4/2012 10:58:39 AM | Computer Name = Writer | Source = System Restore | ID = 8193
Description =

[ Media Center Events ]
Error - 1/2/2012 1:51:12 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 11:50:57 AM - Error connecting to the internet. 11:50:57 AM - Unable
to contact server..

Error - 1/8/2012 11:19:59 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 9:19:59 PM - Error connecting to the internet. 9:19:59 PM - Unable
to contact server..

Error - 1/8/2012 11:21:46 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 9:20:10 PM - Error connecting to the internet. 9:20:10 PM - Unable
to contact server..

Error - 1/9/2012 6:17:06 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 4:17:02 PM - Error connecting to the internet. 4:17:02 PM - Unable
to contact server..

Error - 1/9/2012 6:17:37 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 4:17:14 PM - Error connecting to the internet. 4:17:14 PM - Unable
to contact server..

Error - 1/9/2012 7:17:51 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 5:17:51 PM - Error connecting to the internet. 5:17:51 PM - Unable
to contact server..

Error - 1/9/2012 7:18:02 PM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 5:17:56 PM - Error connecting to the internet. 5:17:56 PM - Unable
to contact server..

Error - 1/10/2012 7:37:51 AM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 5:37:44 AM - Error connecting to the internet. 5:37:44 AM - Unable
to contact server..

Error - 1/10/2012 8:38:04 AM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 6:37:58 AM - Error connecting to the internet. 6:37:58 AM - Unable
to contact server..

Error - 1/10/2012 9:38:13 AM | Computer Name = Writer | Source = MCUpdate | ID = 0
Description = 7:38:09 AM - Error connecting to the internet. 7:38:09 AM - Unable
to contact server..

[ System Events ]
Error - 1/11/2012 5:10:13 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 1/11/2012 5:10:44 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Live
Updater Service service to connect.

Error - 1/11/2012 5:10:44 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7000
Description = The Live Updater Service service failed to start due to the following
error: %%1053

Error - 1/11/2012 5:10:44 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7003
Description = The McAfee Personal Firewall Service service depends the following
service: MpsSvc. This service might not be installed.

Error - 1/11/2012 5:10:52 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 1/11/2012 5:11:06 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the DsiWMIService service.

Error - 1/11/2012 5:13:01 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7003
Description = The McAfee Personal Firewall Service service depends the following
service: MpsSvc. This service might not be installed.

Error - 1/11/2012 5:13:01 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7003
Description = The McAfee Personal Firewall Service service depends the following
service: MpsSvc. This service might not be installed.

Error - 1/11/2012 5:13:49 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7003
Description = The McAfee Personal Firewall Service service depends the following
service: MpsSvc. This service might not be installed.

Error - 1/11/2012 5:13:49 PM | Computer Name = Writer | Source = Service Control Manager | ID = 7003
Description = The McAfee Personal Firewall Service service depends the following
service: MpsSvc. This service might not be installed.


< End of report >
 
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
    O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
    O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = File not found
    O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_11959207.lnk = File not found
    O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_61472742.lnk = File not found
    O4 - Startup: C:\Users\Sarah\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_84347022.lnk = File not found
    [2011/12/31 10:57:47 | 000,028,682 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\458v73p75ekmqk3f8msv2l
    [2011/12/31 10:57:47 | 000,028,682 | -HS- | M] () -- C:\ProgramData\458v73p75ekmqk3f8msv2l
    [2011/12/30 04:55:48 | 000,027,878 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
    [2011/12/30 04:55:48 | 000,027,878 | -HS- | M] () -- C:\ProgramData\sev68fq41yk1qbmnnfrx803860r6kgy265y01qxpow6
    [2011/12/27 16:34:26 | 000,028,058 | -HS- | M] () -- C:\Users\Sarah\AppData\Local\33tc3173v44sqee43uclq23c54s20c2j
    [2011/12/27 16:34:26 | 000,028,058 | -HS- | M] () -- C:\ProgramData\33tc3173v44sqee43uclq23c54s20c2j
    [2012/01/02 10:27:59 | 000,000,124 | -HS- | C] () -- C:\windows\0711449drv.spi
    [2011/12/31 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\78CD6
    [2011/11/16 12:00:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\bpppnGG5aQH6W7
    [2011/11/16 09:58:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\BTXXXqjYCekIVzN
    [2011/11/17 20:09:47 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\CG4aQH6sKE9ZYwI
    [2011/11/17 20:09:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\crzONxA0ciDp
    [2011/12/31 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\D6E65
    [2011/11/17 12:38:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\DA1ivD2on4m
    [2011/12/06 16:21:54 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\DAZ 3D
    [2011/11/16 20:28:34 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\delOBtzP0ciDoFp
    [2011/11/16 20:28:35 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\gH5sQJ7dE8R9YjV
    [2011/11/16 14:54:01 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\GxA0uvSib3n5Q6W
    [2011/11/17 21:49:57 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\HUelIBty2F5ERXj
    [2011/11/20 13:38:32 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\i0ucS2ibDpaHW7T
    [2011/11/17 12:38:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\ksQJdEK8g9YwUlB
    [2011/11/16 14:54:01 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\rKfRL9hTXjCkBzN
    [2011/11/16 09:58:46 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\sddWWK77fR9
    [2011/11/16 09:58:29 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\twwjjUVVel
    [2011/11/16 12:00:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\vRL9gTXqjCkVzNx
    [2011/11/20 13:33:25 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\VTXqYCekIrOt
    [2011/11/20 13:38:53 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\vVrlOBtxPySiDoF
    [2011/11/17 21:49:58 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\yrzNyxASbpaJ8R9
    [2011/11/16 09:58:30 | 000,000,000 | ---D | M] -- C:\Users\Sarah\AppData\Roaming\zjCeekIBrzOyxAv
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

==============================================================

Last scans...

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

2. Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


3. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


4. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
OTL fix log is incorrect.
You clicked on "Scan" button instead of "Fix" button.
Redo.
 
Here is Security Check's checkup.txt:

Results of screen317's Security Check version 0.99.24
Windows 7 x86 (UAC is enabled)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

McAfee AntiVirus Plus
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
Adobe Flash Player 11.1.102.55
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

``````````End of Log````````````
 
Back