1.
thank you for such a fast reply... im sorry but i dont get from work late during the day, so i will update this thread later in the evening hours... ive decided to repair the infected computer but discontinue its use on any online payment use, or access any personal accounts. thanks for those links, they really helped in making my decision.
2.
20:45:34.0601 5088 TDSS rootkit removing tool 2.7.17.0 Feb 29 2012 14:02:24
20:45:35.0099 5088 ============================================================
20:45:35.0099 5088 Current date / time: 2012/03/01 20:45:35.0099
20:45:35.0099 5088 SystemInfo:
20:45:35.0099 5088
20:45:35.0100 5088 OS Version: 6.1.7600 ServicePack: 0.0
20:45:35.0100 5088 Product type: Workstation
20:45:35.0100 5088 ComputerName: DAVE-PC
20:45:35.0100 5088 UserName: dave
20:45:35.0100 5088 Windows directory: C:\Windows
20:45:35.0100 5088 System windows directory: C:\Windows
20:45:35.0100 5088 Processor architecture: Intel x86
20:45:35.0100 5088 Number of processors: 4
20:45:35.0100 5088 Page size: 0x1000
20:45:35.0100 5088 Boot type: Normal boot
20:45:35.0100 5088 ============================================================
20:45:36.0327 5088 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x540BE, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050
20:45:36.0329 5088 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:45:36.0353 5088 \Device\Harddisk0\DR0:
20:45:36.0353 5088 MBR used
20:45:36.0353 5088 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:45:36.0353 5088 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x57513000
20:45:36.0353 5088 \Device\Harddisk1\DR1:
20:45:36.0354 5088 MBR used
20:45:36.0354 5088 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x747059C1
20:45:36.0391 5088 Initialize success
20:45:36.0391 5088 ============================================================
20:46:00.0955 1296 ============================================================
20:46:00.0955 1296 Scan started
20:46:00.0955 1296 Mode: Manual; SigCheck; TDLFS;
20:46:00.0955 1296 ============================================================
20:46:03.0106 1296 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
20:46:03.0189 1296 1394ohci - ok
20:46:03.0231 1296 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
20:46:03.0246 1296 ACPI - ok
20:46:03.0273 1296 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
20:46:03.0323 1296 AcpiPmi - ok
20:46:03.0442 1296 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
20:46:03.0461 1296 adp94xx - ok
20:46:03.0491 1296 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
20:46:03.0507 1296 adpahci - ok
20:46:03.0541 1296 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
20:46:03.0553 1296 adpu320 - ok
20:46:03.0616 1296 AFD (9db8a27a008ab72213051eab90c6babb) C:\Windows\system32\drivers\afd.sys
20:46:03.0622 1296 Suspicious file (Forged): C:\Windows\system32\drivers\afd.sys. Real md5: 9db8a27a008ab72213051eab90c6babb, Fake md5: ddc040fdb01ef1712a6b13e52afb104c
20:46:03.0623 1296 AFD ( Virus.Win32.ZAccess.k ) - infected
20:46:03.0623 1296 AFD - detected Virus.Win32.ZAccess.k (0)
20:46:03.0644 1296 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
20:46:03.0655 1296 agp440 - ok
20:46:03.0696 1296 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
20:46:03.0708 1296 aic78xx - ok
20:46:03.0749 1296 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
20:46:03.0758 1296 aliide - ok
20:46:03.0775 1296 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
20:46:03.0785 1296 amdagp - ok
20:46:03.0859 1296 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
20:46:03.0876 1296 amdide - ok
20:46:03.0888 1296 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
20:46:03.0911 1296 AmdK8 - ok
20:46:03.0926 1296 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
20:46:03.0953 1296 AmdPPM - ok
20:46:03.0986 1296 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys
20:46:03.0997 1296 amdsata - ok
20:46:04.0027 1296 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
20:46:04.0040 1296 amdsbs - ok
20:46:04.0071 1296 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys
20:46:04.0081 1296 amdxata - ok
20:46:04.0131 1296 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
20:46:04.0240 1296 AppID - ok
20:46:04.0285 1296 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
20:46:04.0296 1296 arc - ok
20:46:04.0329 1296 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
20:46:04.0340 1296 arcsas - ok
20:46:04.0383 1296 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
20:46:04.0531 1296 AsyncMac - ok
20:46:04.0550 1296 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
20:46:04.0559 1296 atapi - ok
20:46:04.0657 1296 AVGIDSDriver (f6878b90a8a9795116bce335238e65af) C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys
20:46:05.0744 1296 AVGIDSDriver - ok
20:46:05.0779 1296 AVGIDSEH (19a08a6728a6e02099d64268218cd799) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys
20:46:05.0791 1296 AVGIDSEH - ok
20:46:05.0807 1296 AVGIDSFilter (f8927ab1dd086edeff2924a64dc89869) C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys
20:46:05.0818 1296 AVGIDSFilter - ok
20:46:05.0859 1296 AVGIDSShim (dadca567891033dcf2ec4a3f9da46ae4) C:\Windows\system32\DRIVERS\AVGIDSShim.Sys
20:46:05.0870 1296 AVGIDSShim - ok
20:46:05.0898 1296 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\Windows\system32\DRIVERS\avgldx86.sys
20:46:05.0913 1296 Avgldx86 - ok
20:46:05.0951 1296 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\Windows\system32\DRIVERS\avgmfx86.sys
20:46:05.0965 1296 Avgmfx86 - ok
20:46:05.0999 1296 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\Windows\system32\DRIVERS\avgrkx86.sys
20:46:06.0012 1296 Avgrkx86 - ok
20:46:06.0038 1296 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\Windows\system32\DRIVERS\avgtdix.sys
20:46:06.0053 1296 Avgtdix - ok
20:46:06.0114 1296 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
20:46:06.0170 1296 b06bdrv - ok
20:46:06.0203 1296 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
20:46:06.0234 1296 b57nd60x - ok
20:46:06.0276 1296 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
20:46:06.0312 1296 Beep - ok
20:46:06.0327 1296 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
20:46:06.0339 1296 blbdrive - ok
20:46:06.0395 1296 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
20:46:06.0421 1296 bowser - ok
20:46:06.0436 1296 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:46:06.0458 1296 BrFiltLo - ok
20:46:06.0470 1296 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:46:06.0491 1296 BrFiltUp - ok
20:46:06.0514 1296 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
20:46:06.0542 1296 Brserid - ok
20:46:06.0562 1296 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
20:46:06.0584 1296 BrSerWdm - ok
20:46:06.0597 1296 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
20:46:06.0610 1296 BrUsbMdm - ok
20:46:06.0634 1296 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
20:46:06.0661 1296 BrUsbSer - ok
20:46:06.0716 1296 BTCFilterService (4813df77ede536a52e3737971f910baa) C:\Windows\system32\DRIVERS\motfilt.sys
20:46:06.0759 1296 BTCFilterService - ok
20:46:06.0774 1296 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
20:46:06.0802 1296 BTHMODEM - ok
20:46:06.0832 1296 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
20:46:06.0858 1296 cdfs - ok
20:46:06.0902 1296 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
20:46:06.0921 1296 cdrom - ok
20:46:06.0955 1296 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
20:46:06.0969 1296 circlass - ok
20:46:07.0014 1296 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
20:46:07.0028 1296 CLFS - ok
20:46:07.0044 1296 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
20:46:07.0055 1296 CmBatt - ok
20:46:07.0064 1296 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
20:46:07.0074 1296 cmdide - ok
20:46:07.0097 1296 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
20:46:07.0126 1296 CNG - ok
20:46:07.0146 1296 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
20:46:07.0155 1296 Compbatt - ok
20:46:07.0183 1296 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
20:46:07.0209 1296 CompositeBus - ok
20:46:07.0262 1296 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
20:46:07.0279 1296 crcdisk - ok
20:46:07.0302 1296 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
20:46:07.0326 1296 CSC - ok
20:46:07.0406 1296 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
20:46:07.0440 1296 DfsC - ok
20:46:07.0459 1296 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
20:46:07.0496 1296 discache - ok
20:46:07.0508 1296 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
20:46:07.0518 1296 Disk - ok
20:46:07.0548 1296 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
20:46:07.0570 1296 drmkaud - ok
20:46:07.0619 1296 DXGKrnl (c94b6c3cc628179cb9b9061c19888b99) C:\Windows\System32\drivers\dxgkrnl.sys
20:46:07.0638 1296 DXGKrnl - ok
20:46:07.0726 1296 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
20:46:07.0819 1296 ebdrv - ok
20:46:07.0882 1296 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
20:46:07.0900 1296 elxstor - ok
20:46:07.0916 1296 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
20:46:07.0934 1296 ErrDev - ok
20:46:07.0968 1296 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
20:46:07.0994 1296 exfat - ok
20:46:08.0014 1296 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
20:46:08.0047 1296 fastfat - ok
20:46:08.0063 1296 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
20:46:08.0076 1296 fdc - ok
20:46:08.0093 1296 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
20:46:08.0103 1296 FileInfo - ok
20:46:08.0124 1296 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
20:46:08.0149 1296 Filetrace - ok
20:46:08.0190 1296 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
20:46:08.0214 1296 flpydisk - ok
20:46:08.0237 1296 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
20:46:08.0249 1296 FltMgr - ok
20:46:08.0276 1296 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
20:46:08.0286 1296 FsDepends - ok
20:46:08.0293 1296 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
20:46:08.0303 1296 Fs_Rec - ok
20:46:08.0325 1296 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
20:46:08.0339 1296 fvevol - ok
20:46:08.0361 1296 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
20:46:08.0372 1296 gagp30kx - ok
20:46:08.0430 1296 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:46:08.0436 1296 GEARAspiWDM - ok
20:46:08.0565 1296 hcw72ADFilter (da1f19058c5420959cc59888f4e608eb) C:\Windows\system32\DRIVERS\hcw72ADFilter.sys
20:46:08.0588 1296 hcw72ADFilter - ok
20:46:08.0628 1296 hcw72ATV (6ca0bd5e8a841145fec608565c3a1c80) C:\Windows\system32\DRIVERS\hcw72ATV.sys
20:46:08.0667 1296 hcw72ATV - ok
20:46:08.0744 1296 hcw72DTV (2c1571c8a0bc1101081631dbf4efcf1e) C:\Windows\system32\DRIVERS\hcw72DTV.sys
20:46:08.0795 1296 hcw72DTV - ok
20:46:08.0803 1296 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
20:46:08.0823 1296 hcw85cir - ok
20:46:08.0846 1296 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
20:46:08.0871 1296 HdAudAddService - ok
20:46:08.0891 1296 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
20:46:08.0913 1296 HDAudBus - ok
20:46:08.0929 1296 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
20:46:08.0942 1296 HidBatt - ok
20:46:08.0981 1296 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
20:46:09.0008 1296 HidBth - ok
20:46:09.0033 1296 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
20:46:09.0047 1296 HidIr - ok
20:46:09.0076 1296 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
20:46:09.0088 1296 HidUsb - ok
20:46:09.0123 1296 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
20:46:09.0134 1296 HpSAMD - ok
20:46:09.0164 1296 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
20:46:09.0203 1296 HTTP - ok
20:46:09.0217 1296 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
20:46:09.0226 1296 hwpolicy - ok
20:46:09.0249 1296 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
20:46:09.0262 1296 i8042prt - ok
20:46:09.0297 1296 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys
20:46:09.0311 1296 iaStorV - ok
20:46:09.0420 1296 igfx (ad626f6964f4d364d226c39e06872dd3) C:\Windows\system32\DRIVERS\igdkmd32.sys
20:46:09.0551 1296 igfx - ok
20:46:09.0576 1296 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
20:46:09.0586 1296 iirsp - ok
20:46:09.0639 1296 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
20:46:09.0648 1296 intelide - ok
20:46:09.0673 1296 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
20:46:09.0690 1296 intelppm - ok
20:46:09.0749 1296 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:46:09.0784 1296 IpFilterDriver - ok
20:46:09.0806 1296 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
20:46:09.0820 1296 IPMIDRV - ok
20:46:09.0841 1296 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
20:46:09.0868 1296 IPNAT - ok
20:46:09.0897 1296 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
20:46:09.0940 1296 IRENUM - ok
20:46:09.0955 1296 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
20:46:09.0966 1296 isapnp - ok
20:46:09.0982 1296 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
20:46:09.0995 1296 iScsiPrt - ok
20:46:10.0034 1296 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
20:46:10.0044 1296 kbdclass - ok
20:46:10.0064 1296 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
20:46:10.0076 1296 kbdhid - ok
20:46:10.0122 1296 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
20:46:10.0133 1296 KSecDD - ok
20:46:10.0152 1296 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
20:46:10.0162 1296 KSecPkg - ok
20:46:10.0197 1296 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
20:46:10.0235 1296 lltdio - ok
20:46:10.0280 1296 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
20:46:10.0291 1296 LSI_FC - ok
20:46:10.0322 1296 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
20:46:10.0333 1296 LSI_SAS - ok
20:46:10.0363 1296 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:46:10.0374 1296 LSI_SAS2 - ok
20:46:10.0409 1296 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:46:10.0420 1296 LSI_SCSI - ok
20:46:10.0465 1296 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
20:46:10.0502 1296 luafv - ok
20:46:10.0571 1296 LVUSBSta (a730fc8671a60666d6e877c544dd7cd4) C:\Windows\system32\DRIVERS\LVUSBSta.sys
20:46:10.0601 1296 LVUSBSta - ok
20:46:10.0662 1296 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
20:46:10.0673 1296 megasas - ok
20:46:10.0713 1296 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
20:46:10.0727 1296 MegaSR - ok
20:46:10.0775 1296 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
20:46:10.0810 1296 Modem - ok
20:46:10.0876 1296 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
20:46:10.0895 1296 monitor - ok
20:46:10.0935 1296 motandroidusb (0a43169e115b5e9346a4ba1effcb04cb) C:\Windows\system32\Drivers\motoandroid.sys
20:46:10.0975 1296 motandroidusb - ok
20:46:11.0017 1296 motccgp (f4ea1193a52c8fe4b8a135e210abe546) C:\Windows\system32\DRIVERS\motccgp.sys
20:46:11.0063 1296 motccgp - ok
20:46:11.0096 1296 motccgpfl (b812da6605caf02641312f1f65c75419) C:\Windows\system32\DRIVERS\motccgpfl.sys
20:46:11.0114 1296 motccgpfl - ok
20:46:11.0149 1296 motmodem (69814acd50a9d6d28296050ef6215d46) C:\Windows\system32\DRIVERS\motmodem.sys
20:46:11.0189 1296 motmodem - ok
20:46:11.0198 1296 MotoSwitchService (fd8c2cef7ad8b23c6714103d621fac1f) C:\Windows\system32\DRIVERS\motswch.sys
20:46:11.0229 1296 MotoSwitchService - ok
20:46:11.0246 1296 Motousbnet (ddc489d40b49f443787e7ffa75373522) C:\Windows\system32\DRIVERS\Motousbnet.sys
20:46:11.0274 1296 Motousbnet - ok
20:46:11.0296 1296 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
20:46:11.0305 1296 mouclass - ok
20:46:11.0323 1296 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
20:46:11.0336 1296 mouhid - ok
20:46:11.0352 1296 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
20:46:11.0363 1296 mountmgr - ok
20:46:11.0381 1296 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
20:46:11.0393 1296 mpio - ok
20:46:11.0402 1296 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
20:46:11.0428 1296 mpsdrv - ok
20:46:11.0456 1296 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
20:46:11.0472 1296 MRxDAV - ok
20:46:11.0480 1296 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys
20:46:11.0566 1296 mrxsmb - ok
20:46:11.0584 1296 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:46:11.0612 1296 mrxsmb10 - ok
20:46:11.0624 1296 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:46:11.0651 1296 mrxsmb20 - ok
20:46:11.0662 1296 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
20:46:11.0673 1296 msahci - ok
20:46:11.0696 1296 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
20:46:11.0708 1296 msdsm - ok
20:46:11.0761 1296 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
20:46:11.0785 1296 Msfs - ok
20:46:11.0800 1296 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
20:46:11.0832 1296 mshidkmdf - ok
20:46:11.0850 1296 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
20:46:11.0859 1296 msisadrv - ok
20:46:11.0881 1296 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
20:46:11.0906 1296 MSKSSRV - ok
20:46:11.0921 1296 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
20:46:11.0946 1296 MSPCLOCK - ok
20:46:11.0955 1296 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
20:46:11.0981 1296 MSPQM - ok
20:46:12.0000 1296 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
20:46:12.0011 1296 MsRPC - ok
20:46:12.0029 1296 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
20:46:12.0038 1296 mssmbios - ok
20:46:12.0045 1296 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
20:46:12.0076 1296 MSTEE - ok
20:46:12.0090 1296 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
20:46:12.0102 1296 MTConfig - ok
20:46:12.0152 1296 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\Windows\system32\DRIVERS\ASACPI.sys
20:46:12.0183 1296 MTsensor - ok
20:46:12.0202 1296 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
20:46:12.0212 1296 Mup - ok
20:46:12.0235 1296 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
20:46:12.0262 1296 NativeWifiP - ok
20:46:12.0298 1296 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
20:46:12.0319 1296 NDIS - ok
20:46:12.0340 1296 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
20:46:12.0365 1296 NdisCap - ok
20:46:12.0392 1296 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
20:46:12.0416 1296 NdisTapi - ok
20:46:12.0429 1296 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
20:46:12.0455 1296 Ndisuio - ok
20:46:12.0471 1296 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
20:46:12.0498 1296 NdisWan - ok
20:46:12.0512 1296 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
20:46:12.0538 1296 NDProxy - ok
20:46:12.0545 1296 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
20:46:12.0571 1296 NetBIOS - ok
20:46:12.0587 1296 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
20:46:12.0614 1296 NetBT - ok
20:46:12.0658 1296 netr28 (652881f65b35564575255a0e05e23c55) C:\Windows\system32\DRIVERS\netr28.sys
20:46:12.0689 1296 netr28 - ok
20:46:12.0720 1296 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
20:46:12.0730 1296 nfrd960 - ok
20:46:12.0757 1296 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
20:46:12.0783 1296 Npfs - ok
20:46:12.0831 1296 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
20:46:12.0868 1296 nsiproxy - ok
20:46:12.0908 1296 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
20:46:12.0952 1296 Ntfs - ok
20:46:12.0960 1296 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
20:46:12.0985 1296 Null - ok
20:46:13.0252 1296 nvlddmkm (f452e6ad3eda2852f44be492e283c40f) C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:46:13.0414 1296 nvlddmkm - ok
20:46:13.0447 1296 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys
20:46:13.0459 1296 nvraid - ok
20:46:13.0477 1296 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys
20:46:13.0489 1296 nvstor - ok
20:46:13.0550 1296 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
20:46:13.0561 1296 nv_agp - ok
20:46:13.0580 1296 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
20:46:13.0604 1296 ohci1394 - ok
20:46:13.0629 1296 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
20:46:13.0641 1296 Parport - ok
20:46:13.0656 1296 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
20:46:13.0665 1296 partmgr - ok
20:46:13.0682 1296 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
20:46:13.0694 1296 Parvdm - ok
20:46:13.0709 1296 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
20:46:13.0720 1296 pci - ok
20:46:13.0757 1296 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
20:46:13.0766 1296 pciide - ok
20:46:13.0785 1296 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
20:46:13.0797 1296 pcmcia - ok
20:46:13.0817 1296 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
20:46:13.0827 1296 pcw - ok
20:46:13.0847 1296 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
20:46:13.0885 1296 PEAUTH - ok
20:46:13.0976 1296 PID_0928 (5bd2c6d982481d548107c602e7ccfbbc) C:\Windows\system32\DRIVERS\LV561AV.SYS
20:46:13.0988 1296 PID_0928 - ok
20:46:14.0022 1296 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
20:46:14.0053 1296 PptpMiniport - ok
20:46:14.0068 1296 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
20:46:14.0081 1296 Processor - ok
20:46:14.0101 1296 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
20:46:14.0126 1296 Psched - ok
20:46:14.0186 1296 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
20:46:14.0233 1296 ql2300 - ok
20:46:14.0248 1296 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
20:46:14.0259 1296 ql40xx - ok
20:46:14.0277 1296 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
20:46:14.0292 1296 QWAVEdrv - ok
20:46:14.0305 1296 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
20:46:14.0331 1296 RasAcd - ok
20:46:14.0352 1296 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
20:46:14.0378 1296 RasAgileVpn - ok
20:46:14.0402 1296 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
20:46:14.0430 1296 Rasl2tp - ok
20:46:14.0459 1296 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
20:46:14.0495 1296 RasPppoe - ok
20:46:14.0508 1296 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
20:46:14.0546 1296 RasSstp - ok
20:46:14.0570 1296 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
20:46:14.0597 1296 rdbss - ok
20:46:14.0609 1296 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
20:46:14.0622 1296 rdpbus - ok
20:46:14.0635 1296 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
20:46:14.0667 1296 RDPCDD - ok
20:46:14.0701 1296 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
20:46:14.0755 1296 RDPDR - ok
20:46:14.0792 1296 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
20:46:14.0817 1296 RDPENCDD - ok
20:46:14.0835 1296 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
20:46:14.0862 1296 RDPREFMP - ok
20:46:14.0887 1296 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
20:46:14.0914 1296 RDPWD - ok
20:46:14.0939 1296 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
20:46:14.0952 1296 rdyboost - ok
20:46:15.0004 1296 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
20:46:15.0040 1296 rspndr - ok
20:46:15.0074 1296 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\Windows\system32\DRIVERS\Rt86win7.sys
20:46:15.0088 1296 RTL8167 - ok
20:46:15.0100 1296 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
20:46:15.0121 1296 s3cap - ok
20:46:15.0183 1296 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
20:46:15.0194 1296 sbp2port - ok
20:46:15.0229 1296 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
20:46:15.0271 1296 scfilter - ok
20:46:15.0327 1296 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
20:46:15.0358 1296 secdrv - ok
20:46:15.0379 1296 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
20:46:15.0391 1296 Serenum - ok
20:46:15.0399 1296 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
20:46:15.0423 1296 Serial - ok
20:46:15.0439 1296 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
20:46:15.0452 1296 sermouse - ok
20:46:15.0495 1296 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
20:46:15.0517 1296 sffdisk - ok
20:46:15.0535 1296 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
20:46:15.0561 1296 sffp_mmc - ok
20:46:15.0581 1296 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
20:46:15.0598 1296 sffp_sd - ok
20:46:15.0618 1296 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
20:46:15.0630 1296 sfloppy - ok
20:46:15.0665 1296 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
20:46:15.0682 1296 sisagp - ok
20:46:15.0709 1296 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:46:15.0719 1296 SiSRaid2 - ok
20:46:15.0733 1296 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
20:46:15.0744 1296 SiSRaid4 - ok
20:46:15.0777 1296 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
20:46:15.0802 1296 Smb - ok
20:46:15.0842 1296 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
20:46:15.0851 1296 spldr - ok
20:46:15.0879 1296 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys
20:46:15.0907 1296 srv - ok
20:46:15.0930 1296 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys
20:46:15.0958 1296 srv2 - ok
20:46:15.0973 1296 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys
20:46:15.0998 1296 srvnet - ok
20:46:16.0020 1296 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
20:46:16.0030 1296 stexstor - ok
20:46:16.0051 1296 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
20:46:16.0060 1296 storflt - ok
20:46:16.0068 1296 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
20:46:16.0078 1296 storvsc - ok
20:46:16.0090 1296 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
20:46:16.0099 1296 swenum - ok
20:46:16.0168 1296 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys
20:46:16.0212 1296 Tcpip - ok
20:46:16.0234 1296 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys
20:46:16.0261 1296 TCPIP6 - ok
20:46:16.0281 1296 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
20:46:16.0315 1296 tcpipreg - ok
20:46:16.0332 1296 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
20:46:16.0358 1296 TDPIPE - ok
20:46:16.0379 1296 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
20:46:16.0403 1296 TDTCP - ok
20:46:16.0423 1296 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
20:46:16.0449 1296 tdx - ok
20:46:16.0467 1296 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
20:46:16.0488 1296 TermDD - ok
20:46:16.0555 1296 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
20:46:16.0580 1296 tssecsrv - ok
20:46:16.0608 1296 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
20:46:16.0634 1296 tunnel - ok
20:46:16.0669 1296 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
20:46:16.0679 1296 uagp35 - ok
20:46:16.0710 1296 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
20:46:16.0738 1296 udfs - ok
20:46:16.0777 1296 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
20:46:16.0788 1296 uliagpkx - ok
20:46:16.0814 1296 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
20:46:16.0827 1296 umbus - ok
20:46:16.0907 1296 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
20:46:16.0929 1296 UmPass - ok
20:46:16.0968 1296 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
20:46:17.0006 1296 USBAAPL - ok
20:46:17.0057 1296 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys
20:46:17.0079 1296 usbaudio - ok
20:46:17.0087 1296 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
20:46:17.0101 1296 usbccgp - ok
20:46:17.0128 1296 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
20:46:17.0151 1296 usbcir - ok
20:46:17.0158 1296 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
20:46:17.0221 1296 usbehci - ok
20:46:17.0243 1296 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
20:46:17.0259 1296 usbhub - ok
20:46:17.0274 1296 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
20:46:17.0286 1296 usbohci - ok
20:46:17.0306 1296 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
20:46:17.0320 1296 usbprint - ok
20:46:17.0359 1296 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
20:46:17.0373 1296 usbscan - ok
20:46:17.0388 1296 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:46:17.0401 1296 USBSTOR - ok
20:46:17.0424 1296 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
20:46:17.0442 1296 usbuhci - ok
20:46:17.0466 1296 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
20:46:17.0476 1296 vdrvroot - ok
20:46:17.0495 1296 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
20:46:17.0508 1296 vga - ok
20:46:17.0516 1296 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
20:46:17.0542 1296 VgaSave - ok
20:46:17.0565 1296 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
20:46:17.0577 1296 vhdmp - ok
20:46:17.0595 1296 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
20:46:17.0605 1296 viaagp - ok
20:46:17.0628 1296 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
20:46:17.0654 1296 ViaC7 - ok
20:46:17.0667 1296 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
20:46:17.0677 1296 viaide - ok
20:46:17.0697 1296 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
20:46:17.0710 1296 vmbus - ok
20:46:17.0727 1296 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
20:46:17.0740 1296 VMBusHID - ok
20:46:17.0797 1296 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
20:46:17.0807 1296 volmgr - ok
20:46:17.0828 1296 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
20:46:17.0842 1296 volmgrx - ok
20:46:17.0863 1296 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
20:46:17.0876 1296 volsnap - ok
20:46:17.0903 1296 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
20:46:17.0915 1296 vsmraid - ok
20:46:17.0950 1296 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys
20:46:17.0976 1296 vwifibus - ok
20:46:17.0993 1296 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys
20:46:18.0008 1296 vwififlt - ok
20:46:18.0025 1296 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys
20:46:18.0040 1296 vwifimp - ok
20:46:18.0065 1296 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
20:46:18.0078 1296 WacomPen - ok
20:46:18.0103 1296 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
20:46:18.0136 1296 WANARP - ok
20:46:18.0139 1296 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
20:46:18.0164 1296 Wanarpv6 - ok
20:46:18.0198 1296 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
20:46:18.0208 1296 Wd - ok
20:46:18.0235 1296 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
20:46:18.0251 1296 Wdf01000 - ok
20:46:18.0298 1296 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
20:46:18.0323 1296 WfpLwf - ok
20:46:18.0336 1296 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
20:46:18.0346 1296 WIMMount - ok
20:46:18.0434 1296 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
20:46:18.0463 1296 WinUsb - ok
20:46:18.0511 1296 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
20:46:18.0540 1296 WmiAcpi - ok
20:46:18.0565 1296 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
20:46:18.0591 1296 ws2ifsl - ok
20:46:18.0625 1296 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
20:46:18.0650 1296 WudfPf - ok
20:46:18.0672 1296 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
20:46:18.0704 1296 WUDFRd - ok
20:46:18.0775 1296 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
20:46:18.0853 1296 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
20:46:18.0853 1296 \Device\Harddisk0\DR0 - detected TDSS File System (1)
20:46:18.0858 1296 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR1
20:46:19.0149 1296 \Device\Harddisk1\DR1 - ok
20:46:19.0153 1296 Boot (0x1200) (6af5a51ae321d2dde022567547ce3edf) \Device\Harddisk0\DR0\Partition0
20:46:19.0154 1296 \Device\Harddisk0\DR0\Partition0 - ok
20:46:19.0183 1296 Boot (0x1200) (112b36e8a5b45b79622a752f02d15fcb) \Device\Harddisk0\DR0\Partition1
20:46:19.0184 1296 \Device\Harddisk0\DR0\Partition1 - ok
20:46:19.0187 1296 Boot (0x1200) (28d1b3f2a46ee167d2f9f66a26c92689) \Device\Harddisk1\DR1\Partition0
20:46:19.0189 1296 \Device\Harddisk1\DR1\Partition0 - ok
20:46:19.0190 1296 ============================================================
20:46:19.0190 1296 Scan finished
20:46:19.0190 1296 ============================================================
20:46:19.0203 0616 Detected object count: 2
20:46:19.0203 0616 Actual detected object count: 2
20:47:00.0280 0616 AFD ( Virus.Win32.ZAccess.k ) - skipped by user
20:47:00.0280 0616 AFD ( Virus.Win32.ZAccess.k ) - User select action: Skip
20:47:00.0280 0616 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
20:47:00.0280 0616 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
20:48:30.0437 3380 Deinitialize success
3.
Farbar Service Scanner Version: 01-03-2012
Ran by dave (administrator) on 01-03-2012 at 20:49:13
Running from "C:\Installation\Virus Programs"
Microsoft Windows 7 Ultimate (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.
IE proxy is enabled.
ProxyServer: http=127.0.0.1:63253
Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.
MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.
bfe Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
Windows Update:
============
File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll
[2009-07-13 17:53] - [2009-07-13 19:15] - 0565760 ____A (Microsoft Corporation) 5CD996CECF45CBC3E8D109C86B82D69E
C:\Windows\system32\bfe.dll
[2009-07-13 17:54] - [2009-07-13 19:14] - 0493568 ____A (Microsoft Corporation) 85AC71C045CEB054ED48A7841AAE0C11
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll
[2009-07-13 17:23] - [2009-07-13 19:16] - 0125952 ____A (Microsoft Corporation) 5FD90ABDBFAEE85986802622CBB03446
C:\Windows\system32\vssvc.exe
[2009-07-13 17:24] - [2009-07-13 19:14] - 1025536 ____A (Microsoft Corporation) 7EA2BCD94D9CFAF4C556F5CC94532A6C
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll
[2009-07-13 18:15] - [2009-07-13 19:16] - 1912832 ____A (Microsoft Corporation) A33408CC036F9C08142B11BE5E93F0A1
C:\Windows\system32\qmgr.dll
[2009-07-13 17:30] - [2009-07-13 19:16] - 0589312 ____A (Microsoft Corporation) 53F476476F55A27F580661BDE09C4EC4
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
4.
OTL logfile created on: 3/1/2012 8:51:15 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Installation\Virus Programs
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 66.28% Memory free
7.00 Gb Paging File | 5.45 Gb Available in Paging File | 77.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.54 Gb Total Space | 346.04 Gb Free Space | 49.54% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS
Computer Name: DAVE-PC | User Name: dave | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/03/01 20:50:10 | 000,584,704 | ---- | M] (OldTimer Tools) -- C:\Installation\Virus Programs\OTL.exe
PRC - [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/02/09 22:13:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/02/09 21:02:27 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012/02/09 21:02:07 | 000,857,408 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012/01/24 17:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/11/28 01:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/12 05:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/10/10 05:23:34 | 000,973,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe
PRC - [2011/09/27 20:09:49 | 000,246,600 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
PRC - [2011/09/08 19:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 05:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/07/07 15:11:30 | 000,087,368 | ---- | M] (Nero AG) -- C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe
PRC - [2011/04/26 14:23:02 | 000,223,088 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
PRC - [2011/04/26 14:22:44 | 000,681,840 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
PRC - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
PRC - [2010/03/29 18:28:20 | 000,083,456 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\Program Files\WinTV\WinTV7\WinTVTray.exe
PRC - [2010/03/29 18:13:26 | 000,602,624 | ---- | M] (Hauppauge Computer Works) -- C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe
PRC - [2010/03/29 18:13:00 | 000,310,272 | ---- | M] (Hauppauge Computer Works) -- C:\Program Files\WinTV\TVServer\CaptureGenUSB.exe
PRC - [2010/03/19 14:03:26 | 000,117,344 | ---- | M] (Hauppauge Computer Works) -- C:\Program Files\WinTV\Ir.exe
PRC - [2009/07/13 19:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (No Company Name) ========== MOD - [2012/02/21 21:08:16 | 001,911,768 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/11/18 13:59:45 | 008,527,008 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/04/26 14:22:44 | 000,681,840 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
MOD - [2010/03/29 18:28:10 | 000,022,528 | ---- | M] () -- C:\Program Files\WinTV\TVServer\HauppaugeTVServerps.dll
MOD - [2009/07/13 22:43:04 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll
MOD - [2009/07/13 22:42:57 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll
MOD - [2009/07/13 22:42:40 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll
MOD - [2009/07/13 22:42:36 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll
MOD - [2009/07/13 22:42:30 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll
MOD - [2009/07/13 19:15:51 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2009/07/13 19:15:51 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\system32\mswsock.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (yukonwxp)
SRV - File not found [Auto | Stopped] -- -- (WUSB54Gv4SVC)
SRV - File not found [Auto | Stopped] -- -- (wmi)
SRV - File not found [Auto | Stopped] -- -- (WmaCDriverV32)
SRV - File not found [Auto | Stopped] -- -- (UpdateCenterService)
SRV - File not found [Auto | Stopped] -- -- (ufdsvc)
SRV - File not found [Auto | Stopped] -- -- (U81xmdfl)
SRV - File not found [Auto | Stopped] -- -- (tosrfnds)
SRV - File not found [Auto | Stopped] -- -- (tosrfcom)
SRV - File not found [Auto | Stopped] -- -- (tavsvc)
SRV - File not found [Auto | Stopped] -- -- (szserver)
SRV - File not found [Auto | Stopped] -- -- (syslogd)
SRV - File not found [Auto | Stopped] -- -- (srvdpi)
SRV - File not found [Auto | Stopped] -- -- (SPFDRV)
SRV - File not found [Auto | Stopped] -- -- (speakerphone)
SRV - File not found [Auto | Stopped] -- -- (SerTVOutCtlr)
SRV - File not found [Auto | Stopped] -- -- (se45obex)
SRV - File not found [Auto | Stopped] -- -- (sbhooksvc)
SRV - File not found [Auto | Stopped] -- -- (s616mdm)
SRV - File not found [Auto | Stopped] -- -- (RMSvc)
SRV - File not found [Auto | Stopped] -- -- (raysat3_4_6_18server)
SRV - File not found [Auto | Stopped] -- -- (ql2100)
SRV - File not found [Auto | Stopped] -- -- (purgeieservice)
SRV - File not found [Auto | Stopped] -- -- (pcandis5)
SRV - File not found [Auto | Stopped] -- -- (omniusbl)
SRV - File not found [Auto | Stopped] -- -- (merakcontrol)
SRV - File not found [Auto | Stopped] -- -- (lxct_device)
SRV - File not found [Auto | Stopped] -- -- (LwUsbHid)
SRV - File not found [Auto | Stopped] -- -- (kpfwsvc)
SRV - File not found [Auto | Stopped] -- -- (klblmain)
SRV - File not found [Auto | Stopped] -- -- (iksysflt)
SRV - File not found [Auto | Stopped] -- -- (haspnt)
SRV - File not found [Auto | Stopped] -- -- (genmcmn)
SRV - File not found [Auto | Stopped] -- -- (GBFSHook)
SRV - File not found [Auto | Stopped] -- -- (framework)
SRV - File not found [Auto | Stopped] -- -- (elservice)
SRV - File not found [Auto | Stopped] -- -- (EKECioCtl)
SRV - File not found [Auto | Stopped] -- -- (Dell1100_FUService)
SRV - File not found [Auto | Stopped] -- -- (dbustrcm)
SRV - File not found [Auto | Stopped] -- -- (dbmang)
SRV - File not found [Auto | Stopped] -- -- (dbmanagerscheduler)
SRV - File not found [Auto | Stopped] -- -- (cwafreportscheduler)
SRV - File not found [Auto | Stopped] -- -- (cwafeventrouter)
SRV - File not found [Auto | Stopped] -- -- (cqmgserv)
SRV - File not found [Auto | Stopped] -- -- (cimnotify)
SRV - File not found [Auto | Stopped] -- -- (cfosspeeds)
SRV - File not found [Auto | Stopped] -- -- (cdrbsdrv)
SRV - File not found [Auto | Stopped] -- -- (CAMFLT)
SRV - File not found [Auto | Stopped] -- -- (bb-run)
SRV - File not found [Auto | Stopped] -- -- (ATMsg)
SRV - File not found [Auto | Stopped] -- -- (ANC)
SRV - File not found [Auto | Stopped] -- -- (aeclienthostservice)
SRV - File not found [Auto | Stopped] -- -- ({6080a529-897e-4629-a488-aba0c29b635e})
SRV - [2012/02/09 22:13:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/12 05:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/09/27 20:09:49 | 000,246,600 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/09/01 08:17:00 | 001,025,352 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2011/08/02 05:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011/07/07 15:11:30 | 000,087,368 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe -- (DeviceMonitorService)
SRV - [2011/04/26 14:23:02 | 000,223,088 | ---- | M] () [Auto | Running] -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService)
SRV - [2010/03/29 18:13:26 | 000,602,624 | ---- | M] (Hauppauge Computer Works) [Auto | Running] -- C:\Program Files\WinTV\TVServer\HauppaugeTVServer.exe -- (HauppaugeTVServer)
SRV - [2009/07/13 19:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 19:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
========== Driver Services (SafeList) ========== DRV - [2012/02/09 22:13:00 | 010,816,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/10/07 05:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 05:21:28 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 05:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 05:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 00:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 00:14:14 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 00:14:12 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/07/11 00:14:12 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/04/04 13:55:38 | 000,020,480 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgp.sys -- (motccgp)
DRV - [2011/03/31 13:53:22 | 000,024,064 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2010/04/01 13:31:50 | 000,023,424 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet)
DRV - [2010/01/11 09:16:26 | 001,220,224 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hcw72DTV.sys -- (hcw72DTV)
DRV - [2010/01/11 09:10:30 | 001,217,920 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hcw72ATV.sys -- (hcw72ATV)
DRV - [2010/01/11 09:08:50 | 000,028,928 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hcw72ADFilter.sys -- (hcw72ADFilter)
DRV - [2009/07/13 19:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 19:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 19:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 17:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/13 17:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 17:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 17:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/10 12:01:06 | 000,025,856 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motoandroid.sys -- (motandroidusb)
DRV - [2009/01/29 16:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2009/01/29 16:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService)
DRV - [2007/11/02 14:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService)
DRV - [2005/01/31 10:20:04 | 000,211,712 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LV561AV.SYS -- (PID_0928) Logitech QuickCam Express(PID_0928)
DRV - [2005/01/31 10:12:46 | 000,022,016 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2004/08/13 09:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56646
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:56646
IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehpIE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 56 A4 A7 80 10 AF CC 01 [binary data]
IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKU\..\SearchScopes,DefaultScope = {0B900095-FD52-447B-805A-F882C91124A9}
IE - HKU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\..\SearchScopes\{0B900095-FD52-447B-805A-F882C91124A9}: "URL" =
http://search.avg.com/route/?d=4e015c2f&v=7.7.26.1&i=23&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=usIE - HKU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" =
http://isearch.avg.com/search?cid={C66AC164-B402-4D29-B5C8-3055F263A218}&mid=&lang=en&ds=AVG&pr=fr&d=&v=8.0.0.34&sap=dsp&q={searchTerms}IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*
IE - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:63253
========== FireFox ========== FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX OVS Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\dave\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010/12/22 19:20:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010/12/22 19:20:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/01/31 19:26:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011/09/16 08:21:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/21 21:08:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/15 22:15:59 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{B6C6713F-7DDA-46D5-8568-A19CD05F634C}: C:\Users\dave\AppData\Local\{B6C6713F-7DDA-46D5-8568-A19CD05F634C} [2011/06/20 18:46:59 | 000,000,000 | ---D | M]
[2010/09/10 16:53:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dave\AppData\Roaming\Mozilla\Extensions
[2012/02/15 22:19:00 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dave\AppData\Roaming\Mozilla\Firefox\Profiles\z3rqwx71.default\extensions
[2012/02/15 22:18:55 | 000,000,000 | ---D | M] (DVDVideoSoftTB Community Toolbar) -- C:\Users\dave\AppData\Roaming\Mozilla\Firefox\Profiles\z3rqwx71.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2011/12/26 17:33:14 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\dave\AppData\Roaming\Mozilla\Firefox\Profiles\z3rqwx71.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/05/15 22:16:27 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\dave\AppData\Roaming\Mozilla\Firefox\Profiles\z3rqwx71.default\extensions\engine@conduit.com
[2011/09/27 20:09:48 | 000,003,674 | ---- | M] () -- C:\Users\dave\AppData\Roaming\Mozilla\Firefox\Profiles\z3rqwx71.default\searchplugins\avg-secure-search.xml
[2011/11/27 07:03:56 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/01/31 19:26:20 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4
() (No name found) -- C:\USERS\DAVE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Z3RQWX71.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
[2012/02/21 21:08:16 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/08/25 13:55:45 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/14 07:57:49 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/14 07:57:49 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QCDriverInstaller] C:\Program Files\Common Files\Logitech\QCDriver3\Lqdsw.exe (Logitech Inc.)
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlkc] C:\Users\dave\AppData\Local\Temp\cmd.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlotc] C:\Users\dave\AppData\Local\Temp\hexdump.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlpsc] C:\Users\dave\AppData\Local\Temp\taskmgr.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlqc] C:\Users\dave\AppData\Local\Temp\win.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [LvlciejlqW] C:\Users\dave\AppData\Local\Temp\drweb.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [LvlciejlqZ] C:\Users\dave\AppData\Local\Temp\msmgm.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlrxc] C:\Users\dave\AppData\Local\Temp\spoolsv.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [LvlciejlsPc] C:\Users\dave\AppData\Local\Temp\nvsvc32.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlsxf] C:\Users\dave\AppData\Local\Temp\ktvmutnr.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [Lvlciejlupc] C:\Users\dave\AppData\Local\Temp\sysedit.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [LvlciejlZM] C:\Users\dave\AppData\Local\Temp\ij65h.exe File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [WebCamRT.exe] File not found
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..\Run: [ZortamMp3MediaStudio] C:\Program Files\Zortam Mp3 Media Studio\zmmspro.exe File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O8 - Extra context menu item: Download with Mipony - C:\Program Files\MiPony\Browser\IEContext.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4901C0FD-75B4-45C5-9A63-7040FBC94EDE}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C00EA25D-0200-4776-A720-B4304DE736D0}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/12/15 01:01:46 | 000,000,113 | ---- | M] () - E:\Autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-2712488530-1322185873-1327626398-1000..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE - (WinZip Computing LP)
MsConfig - StartUpReg:
DivX Download Manager - hkey= - key= - C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
MsConfig - StartUpReg:
DivXUpdate - hkey= - key= - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - State: "startup" - 2
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D09AD51C-61A5-A3EF-5ED9-A01186D757C5} - Internet Explorer
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.avis - C:\Windows\System32\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\Windows\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.I420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: dbmang - File not found
NetSvcs: syslogd - File not found
NetSvcs: Dell1100_FUService - File not found
NetSvcs: ANC - File not found
NetSvcs: klblmain - File not found
NetSvcs: lxct_device - File not found
NetSvcs: SerTVOutCtlr - File not found
NetSvcs: framework - File not found
NetSvcs: CAMFLT - File not found
NetSvcs: cimnotify - File not found
NetSvcs: cdrbsdrv - File not found
NetSvcs: dbustrcm - File not found
NetSvcs: GBFSHook - File not found
NetSvcs: bb-run - File not found
NetSvcs: raysat3_4_6_18server - File not found
NetSvcs: srvdpi - File not found
NetSvcs: pcandis5 - File not found
NetSvcs: purgeieservice - File not found
NetSvcs: omniusbl - File not found
NetSvcs: WmaCDriverV32 - File not found
NetSvcs: cwafeventrouter - File not found
NetSvcs: szserver - File not found
NetSvcs: iksysflt - File not found
NetSvcs: ql2100 - File not found
NetSvcs: speakerphone - File not found
NetSvcs: tosrfnds - File not found
NetSvcs: LwUsbHid - File not found
NetSvcs: genmcmn - File not found
NetSvcs: wmi - File not found
NetSvcs: merakcontrol - File not found
NetSvcs: elservice - File not found
NetSvcs: sbhooksvc - File not found
NetSvcs: aeclienthostservice - File not found
NetSvcs: RMSvc - File not found
NetSvcs: haspnt - File not found
NetSvcs: {6080a529-897e-4629-a488-aba0c29b635e} - File not found
NetSvcs: tosrfcom - File not found
NetSvcs: ntservice1 - File not found
NetSvcs: UpdateCenterService - File not found
NetSvcs: ufdsvc - File not found
NetSvcs: ATMsg - File not found
NetSvcs: dbmanagerscheduler - File not found
NetSvcs: EKECioCtl - File not found
NetSvcs: cfosspeeds - File not found
NetSvcs: U81xmdfl - File not found
NetSvcs: yukonwxp - File not found
NetSvcs: cqmgserv - File not found
NetSvcs: se45obex - File not found
NetSvcs: tavsvc - File not found
NetSvcs: cwafreportscheduler - File not found
NetSvcs: kpfwsvc - File not found
NetSvcs: SPFDRV - File not found
NetSvcs: WUSB54Gv4SVC - File not found
NetSvcs: s616mdm - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
========== Files/Folders - Created Within 30 Days ========== [2012/02/29 19:43:43 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/02/21 21:17:21 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\NVIDIA
[2012/02/21 21:16:05 | 019,443,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012/02/21 21:16:05 | 017,543,488 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012/02/21 21:16:05 | 010,816,832 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012/02/21 21:16:05 | 005,892,928 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012/02/21 21:16:05 | 002,517,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012/02/21 21:16:05 | 002,437,440 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012/02/21 21:16:05 | 001,000,256 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2012/02/21 21:16:05 | 000,881,984 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2012/02/21 21:16:05 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2012/02/17 14:31:14 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\Apple Computer
[2012/02/17 08:19:55 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\Media Player Classic
[2012/02/15 23:34:07 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\DivX
[2012/02/15 22:54:10 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\AVG2012
[2012/02/15 22:42:52 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\Malwarebytes
[2012/02/15 22:39:18 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\Macromedia
[2012/02/15 22:39:18 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Roaming\Adobe
[2012/02/03 14:05:08 | 000,000,000 | ---D | C] -- C:\Users\dave\AppData\Local\CrossLoop
[2012/02/02 21:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Moglue Builder
[2012/02/01 20:43:29 | 000,000,000 | ---D | C] -- C:\Winx
========== Files - Modified Within 30 Days ========== [2012/03/01 20:46:29 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 20:46:29 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 20:45:04 | 090,531,853 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2012/03/01 20:41:24 | 000,000,000 | -HS- | M] () -- C:\Windows\System32\dds_trash_log.cmd
[2012/03/01 20:41:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/01 20:41:20 | 2817,875,968 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/29 19:43:40 | 324,243,706 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/29 19:24:50 | 000,000,000 | ---- | M] () -- C:\Users\dave\defogger_reenable
[2012/02/25 17:00:11 | 000,169,484 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm
[2012/02/24 13:34:33 | 000,093,184 | ---- | M] () -- C:\Users\dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/15 22:53:58 | 000,000,362 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/02/15 22:44:07 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 22:13:00 | 019,443,520 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012/02/09 22:13:00 | 017,543,488 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012/02/09 22:13:00 | 015,009,600 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2012/02/09 22:13:00 | 010,816,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012/02/09 22:13:00 | 005,892,928 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012/02/09 22:13:00 | 002,517,312 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012/02/09 22:13:00 | 002,437,440 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012/02/09 22:13:00 | 002,301,248 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
[2012/02/09 22:13:00 | 001,000,256 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2012/02/09 22:13:00 | 000,881,984 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvgenco32.dll
[2012/02/09 22:13:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\System32\OpenCL.dll
[2012/02/09 22:13:00 | 000,008,772 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2012/02/09 21:02:06 | 003,881,792 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcpl.dll
[2012/02/09 21:00:44 | 002,719,040 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvsvc.dll
[2012/02/09 21:00:26 | 000,108,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvmctray.dll
[2012/02/09 21:00:26 | 000,062,272 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvshext.dll
[2012/02/04 07:51:17 | 000,615,122 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/04 07:51:17 | 000,103,496 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/03 18:38:00 | 000,001,994 | ---- | M] () -- C:\Users\dave\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/03 12:40:20 | 000,000,000 | -H-- | M] () -- C:\Users\dave\Documents\Default.rdp
[2012/02/02 21:17:52 | 000,001,091 | ---- | M] () -- C:\Users\Public\Desktop\Moglue Builder.lnk
========== Files Created - No Company Name ========== [2012/02/29 19:43:40 | 324,243,706 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/02/29 19:24:50 | 000,000,000 | ---- | C] () -- C:\Users\dave\defogger_reenable
[2012/02/15 22:44:07 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/05 15:06:06 | 000,000,000 | -HS- | C] () -- C:\Windows\System32\dds_trash_log.cmd
[2012/02/03 12:40:20 | 000,000,000 | -H-- | C] () -- C:\Users\dave\Documents\Default.rdp
[2012/02/02 21:17:52 | 000,001,091 | ---- | C] () -- C:\Users\Public\Desktop\Moglue Builder.lnk
[2012/01/09 23:04:27 | 000,001,388 | -HS- | C] () -- C:\Users\dave\AppData\Local\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2012/01/09 23:04:27 | 000,001,388 | -HS- | C] () -- C:\ProgramData\21juy61aha1224gursi88rlkuu5mp68jeb6v60s3u11qst
[2011/12/30 15:02:11 | 000,001,258 | -HS- | C] () -- C:\Users\dave\AppData\Local\510alf85j208rl31w5ddh7h067038j78y0568
[2011/12/30 15:02:11 | 000,001,258 | -HS- | C] () -- C:\ProgramData\510alf85j208rl31w5ddh7h067038j78y0568
[2011/12/26 23:17:59 | 000,001,602 | -HS- | C] () -- C:\Users\dave\AppData\Local\v5sidvgcsw364rjv
[2011/12/26 23:17:59 | 000,001,602 | -HS- | C] () -- C:\ProgramData\v5sidvgcsw364rjv
[2011/12/14 00:14:22 | 000,001,428 | -HS- | C] () -- C:\Users\dave\AppData\Local\373333b5c671e602x768x2lfo8c5
[2011/12/14 00:14:22 | 000,001,428 | -HS- | C] () -- C:\ProgramData\373333b5c671e602x768x2lfo8c5
[2011/09/23 08:58:02 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/09/23 08:58:01 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/09/23 08:58:01 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/09/23 08:58:01 | 000,080,896 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/08/04 23:04:24 | 000,004,254 | -HS- | C] () -- C:\Users\dave\AppData\Local\75pg32uc86hns2rqtr4c
[2011/08/04 23:04:24 | 000,001,594 | -HS- | C] () -- C:\ProgramData\75pg32uc86hns2rqtr4c
[2011/07/23 13:36:45 | 000,011,630 | ---- | C] () -- C:\Users\dave\AppData\Local\15ho16v480qtjopuusb031qp2362v1q
[2011/07/23 13:36:45 | 000,001,202 | -HS- | C] () -- C:\ProgramData\15ho16v480qtjopuusb031qp2362v1q
[2011/06/27 19:23:44 | 000,001,076 | -HS- | C] () -- C:\ProgramData\s72yyrm12762
[2011/06/20 18:47:00 | 000,000,120 | ---- | C] () -- C:\Users\dave\AppData\Local\Ndazeribecid.dat
[2011/06/20 18:47:00 | 000,000,000 | ---- | C] () -- C:\Users\dave\AppData\Local\Yjozoxiyalogujag.bin
[2011/06/20 18:45:32 | 000,011,902 | -HS- | C] () -- C:\ProgramData\0q5iqr748w574vw7220xkngbul7571d42p55l34k2m2
[2011/06/10 23:14:43 | 000,001,410 | -HS- | C] () -- C:\Users\dave\AppData\Local\hsxwqk4es7wxe43q32mkfjs22vh5nr11s54nd7rbj3
[2011/06/10 23:14:43 | 000,001,410 | -HS- | C] () -- C:\ProgramData\hsxwqk4es7wxe43q32mkfjs22vh5nr11s54nd7rbj3
[2011/06/10 20:41:34 | 000,093,184 | ---- | C] () -- C:\Users\dave\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/10 20:36:33 | 000,000,362 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/02/25 10:34:47 | 000,000,241 | ---- | C] () -- C:\Windows\QSync.INI
[2011/02/25 10:33:47 | 000,000,792 | ---- | C] () -- C:\Windows\_delis32.ini
[2010/12/28 21:13:47 | 000,000,017 | ---- | C] () -- C:\Users\dave\AppData\Local\resmon.resmoncfg
[2010/11/27 15:56:48 | 000,001,456 | ---- | C] () -- C:\Users\dave\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/11/26 21:07:31 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/11/26 18:54:29 | 000,034,706 | ---- | C] () -- C:\Windows\Irremote.ini
[2010/11/26 18:54:14 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010/11/26 18:54:14 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/11/26 18:53:46 | 000,142,337 | ---- | C] () -- C:\Windows\System32\Wait.exe
[2010/11/26 18:53:08 | 000,003,540 | ---- | C] () -- C:\Windows\HCWPNP.INI
[2010/08/07 17:13:38 | 000,043,640 | ---- | C] () -- C:\Windows\PhotoModelerPro5.ini
========== Custom Scans ========== < "%WinDir%\$NtUninstallKB*$." /30 > < C:\Program Files\Common Files\ComObjects\*.* /s > < %systemroot%\*. /mp /s > < %systemroot%\*. /rp /s > < %systemroot%\system32\*.dll /lockedfiles > < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav > < %systemroot%\system32\drivers\*.sys /90 >[2011/12/10 15:24:06 | 000,020,464 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\system32\drivers\mbam.sys
[2012/02/09 22:13:00 | 010,816,832 | ---- | M] (NVIDIA Corporation) -- C:\Windows\system32\drivers\nvlddmkm.sys
< %SYSTEMDRIVE%\*.exe > < MD5 for: ATAPI.SYS >[2009/07/13 19:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/13 19:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_f64b9c35a3a5be81\atapi.sys
[2009/07/13 19:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_dd0e7e3d82dd640d\atapi.sys
< MD5 for: EXPLORER.EXE >[2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\explorer.exe
[2009/07/13 19:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/30 23:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\SoftwareDistribution\Download\b23c9e49177e4877c3c32ef3b38f35ad\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2009/08/02 23:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\SoftwareDistribution\Download\c1f17c80c3b916714e96cf873d95fd6d\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/02 23:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\SoftwareDistribution\Download\c1f17c80c3b916714e96cf873d95fd6d\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 00:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\SoftwareDistribution\Download\b23c9e49177e4877c3c32ef3b38f35ad\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
< MD5 for: TDX.SYS >[2009/07/13 17:12:11 | 000,074,240 | ---- | M] (Microsoft Corporation) MD5=CB39E896A2A83702D1737BFD402B3542 -- C:\Windows\System32\drivers\tdx.sys
[2009/07/13 17:12:11 | 000,074,240 | ---- | M] (Microsoft Corporation) MD5=CB39E896A2A83702D1737BFD402B3542 -- C:\Windows\winsxs\x86_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.1.7600.16385_none_ea141e6f3d693e28\tdx.sys
< MD5 for: VOLSNAP.SYS >[2009/07/13 19:19:10 | 000,245,328 | ---- | M] (Microsoft Corporation) MD5=58DF9D2481A56EDDE167E51B334D44FD -- C:\Windows\System32\drivers\volsnap.sys
[2009/07/13 19:19:10 | 000,245,328 | ---- | M] (Microsoft Corporation) MD5=58DF9D2481A56EDDE167E51B334D44FD -- C:\Windows\System32\DriverStore\FileRepository\volume.inf_x86_neutral_29364d30156a24ca\volsnap.sys
[2009/07/13 19:19:10 | 000,245,328 | ---- | M] (Microsoft Corporation) MD5=58DF9D2481A56EDDE167E51B334D44FD -- C:\Windows\winsxs\x86_volume.inf_31bf3856ad364e35_6.1.7600.16385_none_158d0da45d68903e\volsnap.sys
< MD5 for: WININIT.EXE >[2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\System32\wininit.exe
[2009/07/13 19:14:45 | 000,096,256 | ---- | M] (Microsoft Corporation) MD5=B5C5DCAD3899512020D135600129D665 -- C:\Windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.1.7600.16385_none_30c90ef265a43c13\wininit.exe
< MD5 for: WINLOGON.EXE >[2009/10/28 00:17:59 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD -- C:\Windows\SoftwareDistribution\Download\b23c9e49177e4877c3c32ef3b38f35ad\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/27 23:52:08 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 -- C:\Windows\SoftwareDistribution\Download\b23c9e49177e4877c3c32ef3b38f35ad\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2012/01/13 14:53:20 | 000,182,856 | ---- | M] () MD5=63EEC8A8B221AB79045E776E5F592868 -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/07/13 19:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\System32\winlogon.exe
[2009/07/13 19:14:45 | 000,285,696 | ---- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
< hklm\software\clients\startmenuinternet|command /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/09/01 21:04:07 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
< hklm\software\clients\startmenuinternet|command /64 /rs >HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/02/21 21:08:16 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/02/21 21:08:16 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/09/01 21:04:07 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/09/01 21:04:07 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: iexplore.exe
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========[C:\Windows\$NtUninstallKB12706$] -> Error: Cannot create file handle -> Unknown point type
========== Alternate Data Streams ========== @Alternate Data Stream - 1152 bytes -> C:\Users\dave\AppData\Local\FnRnIVbr0A4UL:qPnN3uy48w37plvjHYoR2L1wC
< End of report >
OTL Extras logfile created on: 3/1/2012 8:51:15 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = C:\Installation\Virus Programs
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 66.28% Memory free
7.00 Gb Paging File | 5.45 Gb Available in Paging File | 77.91% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.54 Gb Total Space | 346.04 Gb Free Space | 49.54% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS
Computer Name: DAVE-PC | User Name: dave | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ========== ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BDC796-3451-4F81-B91D-E98F7ADA76C2}" = TurboTax 2010 WinPerTaxSupport
"{1D76A52C-87A6-4AB0-A7B0-08C8D5DF1D75}" = Motorola Mobile Drivers Installation 5.2.0
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java 7
"{27263813-8BDE-4CD2-84D3-02536743428A}_is1" = Attribute Changer 6.20
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java SE Development Kit 7
"{332B1B33-D0EE-4A0A-AB2F-12BF56BCE1C3}" = FaceGen Modeller 3.1
"{350FB27C-CF62-4EF3-AF9D-70FF313FE221}" = iTunes
"{3782EC09-4000-475E-8A59-9CABD6F03B4C}" = TurboTax 2010 WinPerFedFormset
"{378397D6-FD32-4092-A854-6A75CB7EDA46}" = MOTOROLA MEDIA LINK
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
"{4F2FCCCF-29F3-44B9-886F-6D16F8417522}" = TurboTax 2010 wrapper
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6084D038-3401-4C9D-A216-86E6EEA25AFB}" = ZBrush3
"{6E637484-7ED6-4AA5-BEDC-FD821F64D372}_is1" = Moyea Video4Web Converter version 2.3.0.8
"{82B0940F-A8ED-4F74-935A-CF6AF8530769}" = FaceGen Modeller 3.4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{A525E00B-6609-442E-9DCD-64453C233E8D}" = TurboTax 2010 WinPerReleaseEngine
"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 295.73
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.7.11
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BFCA7375-81A2-44F8-BFC1-0DC5A3D23405}" = TurboTax 2010 wutiper
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DD362256-A7A2-4524-9457-213DDC2AFC2A}" = Adobe After Effects 7.0
"{E7E84E23-C5C0-4B15-B13A-C63149E59C98}" = AVG 2012
"{EB900AF8-CC61-4E15-871B-98D1EA3E8025}" = QuickTime
"{FCB64554-BF51-495E-B13A-2B1F0A430B6C}_is1" = Moglue Builder version 1.0.1
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.65
"Adobe After Effects 7.0" = Adobe After Effects 7.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Anime Studio Pro_is1" = Anime Studio Pro 5.5
"Any Video Converter_is1" = Any Video Converter 3.1.7
"ASP700_is1" = Anime Studio Pro 7.0
"AVG" = AVG 2012
"AviSynth" = AviSynth 2.5
"CINEMA 4D Release 10" = CINEMA 4D Release 10
"DivX Setup.divx.com" = DivX Setup
"ffdshow_is1" = ffdshow v1.1.3949 [2011-07-25]
"Free Audio Converter_is1" = Free Audio Converter version 2.2.11
"Free Audio Dub_is1" = Free Audio Dub version 1.7.9.908
"Free DVD Video Converter_is1" = Free DVD Video Converter version 1.5
"Free Video Dub_is1" = Free Video Dub version 1.8
"Free Video to iPod Converter_is1" = Free Video to iPod Converter version 4.0
"GonVisor_is1" = GonVisor 1.72
"Hauppauge WinTV 7" = Hauppauge WinTV 7
"Hauppauge WinTV Infrared Remote" = Hauppauge WinTV Infrared Remote
"IsoBuster_is1" = IsoBuster 2.8
"JDownloader" = JDownloader
"KLiteCodecPack_is1" = K-Lite Codec Pack 7.7.0 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"MiPony" = MiPony 1.5.3
"MotoHelper" = MotoHelper 2.0.51 Driver 5.2.0
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"MP3 Folder Structure Maker0.9" = MP3 Folder Structure Maker
"Mp3tag" = Mp3tag v2.49
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"Photo To Color Sketch_is1" = Photo To Color Sketch 6.51
"PhotoModeler Pro 5" = PhotoModeler Pro 5
"Power Sound Editor Free" = Power Sound Editor Free
"Swiff Player_is1" = Swiff Player 1.7
"TurboTax 2010" = TurboTax 2010
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.11
"WinZip" = WinZip
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-2712488530-1322185873-1327626398-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = WebEx
"UnityWebPlayer" = Unity Web Player
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 2/15/2012 8:49:18 PM | Computer Name = dave-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
Error - 2/17/2012 9:55:02 AM | Computer Name = dave-PC | Source = RasClient | ID = 20227
Description =
Error - 2/17/2012 2:45:20 PM | Computer Name = dave-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
Error - 2/21/2012 11:20:12 PM | Computer Name = dave-PC | Source = Windows Backup | ID = 4104
Description =
Error - 2/24/2012 12:09:51 PM | Computer Name = dave-PC | Source = Application Hang | ID = 1002
Description = The program firefox.exe version 10.0.2.4428 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 38c Start
Time: 01ccf30e5dcceed2 Termination Time: 60000 Application Path: C:\Program Files\Mozilla
Firefox\firefox.exe Report Id: b995487b-5f01-11e1-8fc1-00248cebeeb5
Error - 2/24/2012 1:32:16 PM | Computer Name = dave-PC | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program files\spybot
- search & destroy\DelZip179.dll" on line 8. The value "*" of attribute "language"
in element "assemblyIdentity" is invalid.
Error - 2/25/2012 10:51:44 PM | Computer Name = dave-PC | Source = SDWinSec.exe | ID = 0
Description =
Error - 2/27/2012 11:32:35 PM | Computer Name = dave-PC | Source = Windows Backup | ID = 4104
Description =
Error - 2/28/2012 11:19:05 PM | Computer Name = dave-PC | Source = SDWinSec.exe | ID = 0
Description =
Error - 2/29/2012 9:55:28 PM | Computer Name = dave-PC | Source = SDWinSec.exe | ID = 0
Description =
[ Media Center Events ]
Error - 11/29/2010 12:43:42 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 10:43:42 PM - Error connecting to the internet. 10:43:42 PM - Unable
to contact server..
Error - 11/29/2010 12:43:59 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 10:43:47 PM - Error connecting to the internet. 10:43:47 PM - Unable
to contact server..
Error - 11/29/2010 11:37:34 PM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 9:37:34 PM - Error connecting to the internet. 9:37:34 PM - Unable
to contact server..
Error - 11/29/2010 11:37:52 PM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 9:37:39 PM - Error connecting to the internet. 9:37:39 PM - Unable
to contact server..
Error - 12/1/2010 11:26:42 PM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 9:26:42 PM - Error connecting to the internet. 9:26:42 PM - Unable
to contact server..
Error - 12/1/2010 11:27:00 PM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 9:26:47 PM - Error connecting to the internet. 9:26:47 PM - Unable
to contact server..
Error - 12/2/2010 12:27:04 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 10:27:04 PM - Error connecting to the internet. 10:27:04 PM - Unable
to contact server..
Error - 12/2/2010 12:27:15 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 10:27:09 PM - Error connecting to the internet. 10:27:09 PM - Unable
to contact server..
Error - 12/2/2010 1:27:20 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 11:27:20 PM - Error connecting to the internet. 11:27:20 PM - Unable
to contact server..
Error - 12/2/2010 1:27:32 AM | Computer Name = dave-PC | Source = MCUpdate | ID = 0
Description = 11:27:25 PM - Error connecting to the internet. 11:27:25 PM - Unable
to contact server..
[ System Events ]
Error - 3/1/2012 10:41:24 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The SE26bus service terminated with the following error: %%126
Error - 3/1/2012 10:41:24 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Nsynas32 service terminated with the following error: %%126
Error - 3/1/2012 10:41:28 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Agnwifi service terminated with the following error: %%126
Error - 3/1/2012 10:41:28 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The NPPTNT service terminated with the following error: %%126
Error - 3/1/2012 10:41:28 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The L8042pr2 service terminated with the following error: %%126
Error - 3/1/2012 10:41:28 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Uiusys service terminated with the following error: %%126
Error - 3/1/2012 10:41:28 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Aha154x service terminated with the following error: %%126
Error - 3/1/2012 10:41:30 PM | Computer Name = dave-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 3/1/2012 10:42:26 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Regmon701 service terminated with the following error: %%5
Error - 3/1/2012 10:57:25 PM | Computer Name = dave-PC | Source = Service Control Manager | ID = 7023
Description = The Vxsvc service terminated with the following error: %%5
< End of report >
5.
computer is running fine... ive had two warnings of that crypt trojan horse only...