Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Posted 24 February 2013 - 07:07 PM
Posted 28 February 2013 - 10:13 AM
Greetings chaknik and
to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.
My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.
If you would allow me to call you by your first name I would prefer to do that. ![]()
===================================================
Ground Rules:
button but use the
button instead.
button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
===================================================
Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.
Thank you for your patience thus far. Please allow me some time to review the information you have provided and I will reply as soon as possible.
Posted 28 February 2013 - 12:44 PM
Hi Roy,
Let's get some fresh information about the state of your computer. Please describe the issues you are currently experiencing and complete the following.
===================================================
DDS by sUBs
--------------------
iconPlease note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Posted 28 February 2013 - 01:05 PM
Hi Gary, thanks for your time and effort. I tried many, many times before I was able to get to bleepingcomputer. IE keeps timing out...'Internet Explorer cannot display the webpage'. This happened well over a dozen times. Just now when I clicked the above link for DDS.com, the same thing..'IE cannot....'. I still haven't been able to download the file, but I'll try some more.
Posted 28 February 2013 - 01:55 PM
I was finally able to download DDS.com and ran it. Here is the DDS.txt:
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.13.2
Run by Froy at 12:19:16 on 2013-02-28
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2492 [GMT -6:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AT&T\AT&T Communication Manager\attcm_AppStart.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\EzDesk.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Sierra Wireless Inc\IERA\IERA.exe
C:\Program Files\Java\jre7\bin\jqs.exe
c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesApp32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=Gfo9sFi-kJw7P1yLaLnhKlvnjBo
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - c:\program files\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
uRun: [attcm.exe] c:\program files\at&t\at&t communication manager\attcm.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; FDM)" -"http://pbskids.org/barney/children/games/imagination_game.html"
mRun: [ISUSScheduler] "c:\progra~1\common~1\instal~1\update~1\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTDVDDET] "c:\program files\creative\sound blaster x-fi\dvdaudio\CTDVDDET.EXE"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [attcm_AppStart.exe] "c:\program files\at&t\at&t communication manager\attcm_AppStart.exe"
StartupFolder: c:\docume~1\froy\startm~1\programs\startup\ezware~1.lnk - c:\windows\EzDesk.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:255
uPolicies-Explorer: HideSCABattery = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:255
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {43E3F87D-DE7F-4087-BD4F-0DC854981158} - hxxp://download.microsoft.com/download/7/3/8/7384c441-3721-41ee-ae15-b678888f00dd/clearadj.CAB
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1344814358031
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.0.1
TCP: Interfaces\{1563FF0C-236E-48E3-B70B-5C8DCCBB6108} : NameServer = 68.94.156.1,68.94.157.1
TCP: Interfaces\{2602BA14-2982-417F-8B77-F4730EB189A0} : DHCPNameServer = 192.168.0.1
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: SecurityProviders = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, msansspc.dll
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 98.139.183.24 www.yahoo.com
Hosts: 67.195.160.76 m.yahoo.com
Hosts: 209.191.93.53 yahoo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\froy\application data\mozilla\firefox\profiles\ae57pzsf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-amonetizetest1-chromesbox-en-us&tb_uuid=20120811143732468&tb_oid=15-08-2012&tb_mrud=15-08-2012
FF - prefs.js: browser.startup.homepage - hxxp://wwwyahoo.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&invocationType=tb50-ff-amonetizetest1-ab-en-us&tb_uuid=20120811143732468&tb_oid=15-08-2012&tb_mrud=15-08-2012&query=
FF - component: c:\documents and settings\froy\application data\mozilla\firefox\profiles\ae57pzsf.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\MailUtil.dll
FF - plugin: c:\documents and settings\froy\local settings\application data\google\update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_13.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_6_602_171.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - ExtSQL: !HIDDEN! 2009-11-16 18:05; {20a82645-c095-46ed-80e3-08825760534b}; c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 IERA;Sierra Wireless Error Reporting Agent;c:\program files\sierra wireless inc\iera\IERA.exe [2011-10-19 167280]
R2 TuneUp.UtilitiesSvc;AVG PC TuneUp Service;c:\program files\avg\avg pc tuneup\TuneUpUtilitiesService32.exe [2012-8-23 1532280]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\avg\avg pc tuneup\TuneUpUtilitiesDriver32.sys [2012-7-4 10088]
S3 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-8-11 116608]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2004-10-29 32000]
S3 swg3kser00;Sierra Wireless QMI USB Device for Legacy Serial Communication;c:\windows\system32\drivers\swg3kser00.sys [2011-10-19 215552]
S3 swivsp;AC8xx Virtual Serial Port;c:\windows\system32\drivers\swivspnt.sys [2007-3-26 20352]
S3 swiwdmbx;Sierra Wireless USB Bus Service;c:\windows\system32\drivers\swiwdmbx.sys [2011-10-19 83968]
S3 SWNC8U12;Sierra Wireless MUX NDIS Driver (UMTS12);c:\windows\system32\drivers\swnc8u12.sys [2007-11-4 101632]
S3 SWNC8UA3;Sierra Wireless MUX NDIS Driver (UMTSA3);c:\windows\system32\drivers\swnc8ua3.sys [2011-10-19 208128]
S3 swumx12;Sierra Wireless USB MUX Driver (UMTS12);c:\windows\system32\drivers\swumx12.sys [2007-11-4 73600]
S3 VWan2k;BroadJump PPPoE Adapter;c:\windows\system32\drivers\VWAN2K.sys [2008-3-13 29228]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]
S4 SwiCardDetectSvc;Sierra Wireless Card Detection Service;c:\program files\sierra wireless inc\common\SwiCardDetect.exe [2011-5-20 238960]
.
=============== Created Last 30 ================
.
2013-02-27 17:53:36 -------- d-----w- c:\documents and settings\froy\local settings\application data\exec
2013-02-25 22:28:38 -------- d-----w- c:\documents and settings\froy\local settings\application data\Avg2013
2013-02-24 21:02:21 -------- d-----w- c:\program files\EMET
2013-02-24 19:35:45 -------- d-----w- c:\documents and settings\froy\local settings\application data\attcm_AppStart
2013-02-23 23:10:25 -------- d-----w- c:\program files\AT&T
2013-02-23 21:10:59 -------- d-----w- c:\program files\common files\Research In Motion
2013-02-15 22:31:23 186432 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2013-02-15 22:31:23 186432 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2013-02-10 21:24:00 143872 ----a-w- c:\windows\system32\javacpl.cpl
2013-02-10 21:23:56 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2013-02-27 22:59:39 71024 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-27 22:59:39 691568 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-10 21:23:44 861088 ----a-w- c:\windows\system32\npdeployJava1.dll
2013-02-10 21:23:44 782240 ----a-w- c:\windows\system32\deployJava1.dll
2013-01-26 03:55:44 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:19:45 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37:01 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49:10 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49:10 1292288 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16:29 916480 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16:28 43520 ------w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16:28 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40:59 385024 ------w- c:\windows\system32\html.iec
2012-12-16 12:23:59 290560 ----a-w- c:\windows\system32\atmfd.dll
2012-12-14 22:49:28 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2006-05-03 17:06:54 163328 --sha-r- c:\windows\system32\flvDX.dll
2007-02-21 18:47:16 31232 --sha-r- c:\windows\system32\msfDX.dll
2008-03-16 20:30:52 216064 --sha-r- c:\windows\system32\nbDX.dll
2010-01-07 05:00:00 107520 --sha-r- c:\windows\system32\TAKDSDecoder.dll
.
============= FINISH: 12:19:30.40 ===============
Not exactly sure about how to zip and attach the attach.txt but I'll try this. Didn't work. How do I attach a zipped file?
Posted 28 February 2013 - 04:02 PM
H Roy,
Thanks for the information. As far as the Attach.txt file you can copy and paste the contents in your reply.
Please do this for me.
===================================================
AdwCleaner by Xplode - Delete Adware
-------------------
===================================================
Junkware Removal Tool by thisisu
-------------------
===================================================
SystemLook by jpshortstuff
--------------------
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
Download Mirror #3 For 64-bit users
:dir c:\documents and settings\froy\local settings\application data\exec /s
===================================================
Farbar's MiniToolBox
--------------------
Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
===================================================
Things I would like to see in your next reply. Please be sure to copy and paste the information rather than send an attachment. ![]()
Posted 28 February 2013 - 05:59 PM
<p>The Attach.txt:<br />
.<br />
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.<br />
IF REQUESTED, ZIP IT UP & ATTACH IT<br />
.<br />
DDS (Ver_2012-11-20.01)<br />
.<br />
Microsoft Windows XP Home Edition<br />
Boot Device: \Device\HarddiskVolume2<br />
Install Date: 9/18/2007 2:36:51 PM<br />
System Uptime: 2/28/2013 7:28:54 AM (5 hours ago)<br />
.<br />
Motherboard: Dell Inc. | | 0CT017<br />
Processor: Intel® Core2 CPU 6420 @ 2.13GHz | Microprocessor | 2127/1066mhz<br />
.<br />
==== Disk Partitions =========================<br />
.<br />
C: is FIXED (NTFS) - 295 GiB total, 207.235 GiB free.<br />
D: is CDROM ()<br />
E: is CDROM ()<br />
F: is Removable<br />
G: is Removable<br />
H: is Removable<br />
I: is Removable<br />
.<br />
==== Disabled Device Manager Items =============<br />
.<br />
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}<br />
Description: 1394 Net Adapter<br />
Device ID: V1394\NIC1394\8071EEE5D100<br />
Manufacturer: Microsoft<br />
Name: 1394 Net Adapter<br />
PNP Device ID: V1394\NIC1394\8071EEE5D100<br />
Service: NIC1394<br />
.<br />
==== System Restore Points ===================<br />
.<br />
RP59: 11/30/2012 12:26:34 PM - System Checkpoint<br />
RP60: 12/16/2012 3:20:29 PM - System Checkpoint<br />
RP61: 12/16/2012 6:07:07 PM - Software Distribution Service 3.0<br />
RP62: 12/20/2012 11:55:22 AM - System Checkpoint<br />
RP63: 12/22/2012 1:31:17 AM - Software Distribution Service 3.0<br />
RP64: 12/23/2012 8:59:48 AM - System Checkpoint<br />
RP65: 1/13/2013 3:09:24 PM - Software Distribution Service 3.0<br />
RP66: 1/14/2013 3:38:23 PM - System Checkpoint<br />
RP67: 1/14/2013 5:15:59 PM - Software Distribution Service 3.0<br />
RP68: 1/20/2013 3:32:54 PM - System Checkpoint<br />
RP69: 2/2/2013 12:36:38 PM - System Checkpoint<br />
RP70: 2/3/2013 12:37:44 PM - System Checkpoint<br />
RP71: 2/6/2013 5:05:07 PM - System Checkpoint<br />
RP72: 2/7/2013 5:51:19 PM - System Checkpoint<br />
RP73: 2/8/2013 6:15:31 PM - System Checkpoint<br />
RP74: 2/9/2013 6:58:12 PM - System Checkpoint<br />
RP75: 2/10/2013 3:23:35 PM - Removed Java 7 Update 9<br />
RP76: 2/16/2013 7:44:06 PM - System Checkpoint<br />
RP77: 2/23/2013 9:05:00 AM - System Checkpoint<br />
RP78: 2/23/2013 3:04:05 PM - Software Distribution Service 3.0<br />
RP79: 2/23/2013 3:10:53 PM - Removed AT&T Communication Manager<br />
RP80: 2/23/2013 3:11:10 PM - Drivers Installation<br />
RP81: 2/23/2013 4:53:36 PM - Restore Operation<br />
RP82: 2/23/2013 5:00:43 PM - Restore Operation<br />
RP83: 2/23/2013 5:02:55 PM - Restore Operation<br />
RP84: 2/23/2013 5:06:32 PM - Removed AT&T Communication Manager<br />
RP85: 2/24/2013 3:02:21 PM - Installed EMET<br />
RP86: 2/24/2013 4:54:43 PM - Restore Operation<br />
RP87: 2/25/2013 4:27:51 PM - Removed AVG 2013<br />
RP88: 2/25/2013 4:28:45 PM - Removed AVG 2013<br />
RP89: 2/26/2013 5:31:04 PM - System Checkpoint<br />
RP90: 2/27/2013 5:47:45 PM - System Checkpoint<br />
RP91: 2/28/2013 10:40:53 AM - Removed Ad-Aware<br />
.<br />
==== Installed Programs ======================<br />
.<br />
Adobe AIR<br />
Adobe Flash Player 11 ActiveX<br />
Adobe Flash Player 11 Plugin<br />
Adobe Reader X (10.1.6)<br />
Adobe Shockwave Player 11.6<br />
Advanced Decoder Patch<br />
AnalogX NetStat Live<br />
AnalogX Vocal Remover (WinAmp)<br />
Any Video Converter 3.4.2<br />
AT&T Communication Manager<br />
Audio Conversion Wizard 1.68.1<br />
AutoPlay Media Studio 5.0 Professional Trial<br />
AVG PC TuneUp<br />
AVG PC TuneUp Language Pack (en-US)<br />
BitMeter<br />
BroadJump PPPoE<br />
Canon MP Navigator EX 1.0<br />
Canon MP610 series<br />
Canon MP610 series User Registration<br />
Canon My Printer<br />
Canon Utilities Easy-PhotoPrint EX<br />
Canon Utilities Solution Menu<br />
CCleaner<br />
CDDRV_Installer<br />
CoffeeCup Free HTML Editor<br />
Creative MediaSource<br />
Dell CinePlayer<br />
Dell Driver Download Manager<br />
Dell Driver Reset Tool<br />
Dell Resource CD<br />
Dell Support Center<br />
Dell System Restore<br />
DellSupport<br />
DivX Setup<br />
Documentation & Support Launcher<br />
Doom 3<br />
EMET<br />
FormatFactory 2.95<br />
Free Easy Burner V 5.1<br />
FreeCell Plus<br />
Frhed 1.7.1<br />
Games, Music, & Photos Launcher<br />
GIMP 2.6.11<br />
Google Chrome<br />
GoToAssist 8.0.0.514<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)<br />
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)<br />
Hotfix for Windows Internet Explorer 7 (KB947864)<br />
Hotfix for Windows XP (KB2756822)<br />
Hotfix for Windows XP (KB2779562)<br />
ImgBurn<br />
Indeo® Software<br />
Info Center 1.0.0.7<br />
Inkscape 0.48.2<br />
Intel® Matrix Storage Manager<br />
Intel® PRO Network Connections<br />
Internet Explorer (Enable DEP)<br />
Internet Service Offers Launcher<br />
Java 7 Update 13<br />
Java Auto Updater<br />
KhalSetup<br />
Macromedia Dreamweaver 4<br />
Macromedia Extension Manager<br />
Malwarebytes Anti-Malware version 1.70.0.1100<br />
MediaProSoft Free FLV Video Converter 5.2.3<br />
Microsoft .NET Framework 1.1<br />
Microsoft .NET Framework 1.1 Security Update (KB2698023)<br />
Microsoft .NET Framework 1.1 Security Update (KB2742597)<br />
Microsoft .NET Framework 1.1 Security Update (KB979906)<br />
Microsoft .NET Framework 2.0 Service Pack 2<br />
Microsoft .NET Framework 3.0 Service Pack 2<br />
Microsoft .NET Framework 3.5 SP1<br />
Microsoft Automated Troubleshooting Services Shim<br />
Microsoft Compression Client Pack 1.0 for Windows XP<br />
Microsoft Expedia Streets & Trips 2000<br />
Microsoft Fix it Center<br />
Microsoft Internationalized Domain Names Mitigation APIs<br />
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5<br />
Microsoft National Language Support Downlevel APIs<br />
Microsoft Office Excel MUI (English) 2007<br />
Microsoft Office Home and Student 2007<br />
Microsoft Office OneNote MUI (English) 2007<br />
Microsoft Office PowerPoint MUI (English) 2007<br />
Microsoft Office Proof (English) 2007<br />
Microsoft Office Proof (French) 2007<br />
Microsoft Office Proof (Spanish) 2007<br />
Microsoft Office Proofing (English) 2007<br />
Microsoft Office Shared MUI (English) 2007<br />
Microsoft Office Shared Setup Metadata MUI (English) 2007<br />
Microsoft Office Word MUI (English) 2007<br />
Microsoft Plus! Digital Media Edition Installer<br />
Microsoft Plus! Photo Story 2 LE<br />
Microsoft Software Update for Web Folders (English) 12<br />
Microsoft User-Mode Driver Framework Feature Pack 1.0<br />
Microsoft VC9 runtime libraries<br />
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053<br />
Microsoft Visual C++ 2005 Redistributable<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17<br />
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148<br />
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219<br />
Microsoft Works 2000<br />
Microsoft Works 2000 Setup Launcher<br />
Mozilla Firefox (3.6.28)<br />
MSXML 4.0 SP2 (KB936181)<br />
MSXML 4.0 SP2 (KB954430)<br />
MSXML 4.0 SP2 (KB973688)<br />
Nokia Connectivity Adapter Cable DKU-5<br />
NVIDIA Drivers<br />
Paint Shop Pro 7<br />
PowerDVD 5.9<br />
Prism Video File Converter<br />
Quake III Arena<br />
QualxServ Service Agreement<br />
QuickTime Alternative 1.81<br />
RegScrubXP 3.25<br />
Revo Uninstaller 1.93<br />
Riva FLV Encoder 2.0<br />
Roxio Creator Audio<br />
Roxio Creator Copy<br />
Roxio Creator Data<br />
Roxio Creator DE<br />
Roxio Creator Tools<br />
ScanSoft OmniPage SE 4<br />
Security Update for 2007 Microsoft Office System (KB951550)<br />
Security Update for 2007 Microsoft Office System (KB951944)<br />
Security Update for 2007 Microsoft Office System (KB960003)<br />
Security Update for CAPICOM (KB931906)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)<br />
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)<br />
Security Update for Microsoft Office Excel 2007 (KB959997)<br />
Security Update for Microsoft Office OneNote 2007 (KB950130)<br />
Security Update for Microsoft Office PowerPoint 2007 (KB951338)<br />
Security Update for Microsoft Office system 2007 (KB954326)<br />
Security Update for Microsoft Office system 2007 (KB956828)<br />
Security Update for Microsoft Office Word 2007 (KB956358)<br />
Security Update for Visio 2007 (KB947590)<br />
Security Update for Windows Internet Explorer 7 (KB2544521)<br />
Security Update for Windows Internet Explorer 7 (KB2722913)<br />
Security Update for Windows Internet Explorer 7 (KB938127)<br />
Security Update for Windows Internet Explorer 7 (KB942615)<br />
Security Update for Windows Internet Explorer 7 (KB944533)<br />
Security Update for Windows Internet Explorer 7 (KB950759)<br />
Security Update for Windows Internet Explorer 7 (KB953838)<br />
Security Update for Windows Internet Explorer 7 (KB956390)<br />
Security Update for Windows Internet Explorer 7 (KB958215)<br />
Security Update for Windows Internet Explorer 7 (KB960714)<br />
Security Update for Windows Internet Explorer 7 (KB961260)<br />
Security Update for Windows Internet Explorer 7 (KB963027)<br />
Security Update for Windows Internet Explorer 7 (KB972260)<br />
Security Update for Windows Internet Explorer 8 (KB2510531)<br />
Security Update for Windows Internet Explorer 8 (KB2544521)<br />
Security Update for Windows Internet Explorer 8 (KB2618444)<br />
Security Update for Windows Internet Explorer 8 (KB2722913)<br />
Security Update for Windows Internet Explorer 8 (KB2744842)<br />
Security Update for Windows Internet Explorer 8 (KB2761465)<br />
Security Update for Windows Internet Explorer 8 (KB2792100)<br />
Security Update for Windows Internet Explorer 8 (KB2797052)<br />
Security Update for Windows Internet Explorer 8 (KB2799329)<br />
Security Update for Windows Internet Explorer 8 (KB982381)<br />
Security Update for Windows Media Player (KB911564)<br />
Security Update for Windows XP (KB2510581)<br />
Security Update for Windows XP (KB2655992)<br />
Security Update for Windows XP (KB2691442)<br />
Security Update for Windows XP (KB2698365)<br />
Security Update for Windows XP (KB2705219)<br />
Security Update for Windows XP (KB2707511)<br />
Security Update for Windows XP (KB2712808)<br />
Security Update for Windows XP (KB2719985)<br />
Security Update for Windows XP (KB2723135)<br />
Security Update for Windows XP (KB2724197)<br />
Security Update for Windows XP (KB2727528)<br />
Security Update for Windows XP (KB2731847)<br />
Security Update for Windows XP (KB2753842-v2)<br />
Security Update for Windows XP (KB2757638)<br />
Security Update for Windows XP (KB2758857)<br />
Security Update for Windows XP (KB2761226)<br />
Security Update for Windows XP (KB2770660)<br />
Security Update for Windows XP (KB2778344)<br />
Security Update for Windows XP (KB2779030)<br />
Security Update for Windows XP (KB2780091)<br />
Security Update for Windows XP (KB2799494)<br />
Security Update for Windows XP (KB2802968)<br />
Serif WebPlus 10<br />
SetPoint<br />
SmartDraw 6<br />
Sonic Activation Module<br />
Sound Blaster X-Fi<br />
Stykz for Windows 1.0.2<br />
SUPER © v2012.build.52 (July 7, 2012) version v2012.build.52<br />
SUPERAntiSpyware<br />
swMSM<br />
Synfig Studio<br />
System Requirements Lab<br />
Tweak UI<br />
Update for 2007 Microsoft Office System (KB967642)<br />
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)<br />
Update for Office 2007 (KB932080)<br />
Update for Office 2007 (KB934391)<br />
Update for Windows Internet Explorer 8 (KB2598845)<br />
Update for Windows XP (KB2661254-v2)<br />
Update for Windows XP (KB2718704)<br />
Update for Windows XP (KB2736233)<br />
Update for Windows XP (KB2749655)<br />
VC80CRTRedist - 8.0.50727.6195<br />
VCDEasy<br />
VideoPad Video Editor<br />
VLC media player 1.1.11<br />
WatchWAN v1.0 Pre-Release<br />
WebFldrs XP<br />
WIDCOMM Bluetooth Software<br />
Winamp (remove only)<br />
Windows Internet Explorer 7<br />
Windows Internet Explorer 8<br />
Windows Media Encoder 9 Series SDK<br />
Windows Media Format 11 runtime<br />
Windows Media Player 10<br />
Windows Media Player 11<br />
Windows XP Service Pack 3<br />
WinPcap 3.1 beta4<br />
Xilisoft Video Converter Ultimate<br />
.<br />
==== Event Viewer Messages From Past Week ========<br />
.<br />
2/26/2013 3:55:02 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk4\D.<br />
2/25/2013 1:15:01 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AVGIDSDriver AVGIDSShim Avgldx86 Fips intelppm SASDIFSV SASKUTIL<br />
2/25/2013 1:15:01 PM, error: Service Control Manager [7001] - The AVGIDSAgent service depends on the AVGIDSDriver service which failed to start because of the following error: A device attached to the system is not functioning.<br />
2/25/2013 1:14:15 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}<br />
2/24/2013 4:56:04 PM, error: Dhcp [1002] - The IP address lease 10.34.46.171 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.72.146.253 (The DHCP Server sent a DHCPNACK message).<br />
2/24/2013 4:37:59 PM, error: Dhcp [1002] - The IP address lease 10.46.35.188 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.34.46.253 (The DHCP Server sent a DHCPNACK message).<br />
2/24/2013 4:13:24 PM, error: Dhcp [1002] - The IP address lease 10.46.35.188 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.46.35.253 (The DHCP Server sent a DHCPNACK message).<br />
2/24/2013 3:57:39 PM, error: Dhcp [1002] - The IP address lease 10.120.174.243 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.46.35.253 (The DHCP Server sent a DHCPNACK message).<br />
2/24/2013 3:37:58 PM, error: Dhcp [1002] - The IP address lease 10.185.188.208 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.120.174.253 (The DHCP Server sent a DHCPNACK message).<br />
2/24/2013 3:21:57 PM, error: NetDDE [206] - Listen failed: 15:<br />
2/24/2013 2:59:15 PM, error: Dhcp [1002] - The IP address lease 10.34.248.11 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.185.188.253 (The DHCP Server sent a DHCPNACK message).<br />
2/23/2013 5:06:59 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.<br />
2/23/2013 5:04:42 PM, error: Service Control Manager [7001] - The Telephony service depends on the Plug and Play service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.<br />
2/23/2013 5:04:42 PM, error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: The dependency service or group failed to start.<br />
2/23/2013 5:04:39 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}<br />
2/23/2013 5:02:47 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for FailureActions with the following error: Access is denied.<br />
2/23/2013 5:02:47 PM, error: Service Control Manager [7001] - The Windows Audio service depends on the Plug and Play service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.<br />
2/23/2013 5:02:47 PM, error: Service Control Manager [7001] - The Logical Disk Manager service depends on the Plug and Play service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.<br />
2/23/2013 5:02:35 PM, error: Print [19] - Sharing printer failed + 1722, Printer Auto Canon MP610 series Printer on DBTOA000 share name AutoCanon.<br />
2/23/2013 4:28:03 PM, error: Dhcp [1002] - The IP address lease 10.120.6.141 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.34.248.253 (The DHCP Server sent a DHCPNACK message).<br />
2/23/2013 4:07:32 PM, error: Dhcp [1002] - The IP address lease 10.243.27.208 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.120.6.253 (The DHCP Server sent a DHCPNACK message).<br />
2/23/2013 3:14:16 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.<br />
2/23/2013 3:12:16 PM, error: Dhcp [1002] - The IP address lease 10.243.27.208 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.243.27.253 (The DHCP Server sent a DHCPNACK message).<br />
2/23/2013 2:58:51 PM, error: Dhcp [1002] - The IP address lease 10.88.78.21 for the Network Card with network address 00A0D5FFFFAE has been denied by the DHCP server 10.243.27.253 (The DHCP Server sent a DHCPNACK message).<br />
2/23/2013 11:08:17 AM, error: NetDDE [206] - Listen failed: 23: The ncb_lana_num member did not specify a valid network number.<br />
.<br />
==== End Of File ===========================<br />
<br />
<br />
AdwCleaner[Ss1].txt:<br />
<br />
# AdwCleaner v2.113 - Logfile created 02/28/2013 at 15:48:14<br />
# Updated 23/02/2013 by Xplode<br />
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)<br />
# User : Froy - RAS<br />
# Boot Mode : Normal<br />
# Running from : C:\Documents and Settings\Froy\Desktop\BleepingComputer\AdwCleaner.exe<br />
# Option [Delete]<br />
<br />
<br />
<br />
***** [Services] *****<br />
<br />
<br />
<br />
***** [Files / Folders] *****<br />
<br />
<br />
Deleted on reboot : C:\Program Files\Common Files\AVG Secure Search<br />
File Deleted : C:\Documents and Settings\Froy\Application Data\Mozilla\Firefox\Profiles\ae57pzsf.default\searchplugins\Askcom.xml<br />
File Deleted : C:\Program Files\Mozilla Firefox\.autoreg<br />
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml<br />
Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Secure Search<br />
Folder Deleted : C:\Documents and Settings\Froy\Application Data\AVG Secure Search<br />
Folder Deleted : C:\Documents and Settings\Froy\Application Data\Mozilla\Firefox\Profiles\ae57pzsf.default\extensions\staged<br />
Folder Deleted : C:\Program Files\AVG Secure Search<br />
<br />
<br />
***** [Registry] *****<br />
<br />
<br />
Key Deleted : HKCU\Software\AVG Secure Search<br />
Key Deleted : HKCU\Software\Conduit<br />
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}<br />
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}<br />
Key Deleted : HKLM\Software\AVG Secure Search<br />
Key Deleted : HKLM\Software\AVG Security Toolbar<br />
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}<br />
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}<br />
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE<br />
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL<br />
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI<br />
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1<br />
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj<br />
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1<br />
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}<br />
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}<br />
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}<br />
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}<br />
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}<br />
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}<br />
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}<br />
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}<br />
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}<br />
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol<br />
Key Deleted : HKLM\SOFTWARE\Classes\S<br />
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi<br />
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1<br />
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}<br />
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}<br />
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}<br />
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE<br />
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1<br />
Key Deleted : HKLM\Software\Conduit<br />
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}<br />
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}<br />
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}<br />
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin<br />
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]<br />
<br />
<br />
***** [Internet Browsers] *****<br />
<br />
<br />
-\\ Internet Explorer v8.0.6001.18702<br />
<br />
<br />
[OK] Registry is clean.<br />
<br />
<br />
-\\ Mozilla Firefox v3.6.28 (en-US)<br />
<br />
<br />
File : C:\Documents and Settings\Froy\Application Data\Mozilla\Firefox\Profiles\ae57pzsf.default\prefs.js<br />
<br />
<br />
C:\Documents and Settings\Froy\Application Data\Mozilla\Firefox\Profiles\ae57pzsf.default\user.js ... Deleted !<br />
<br />
<br />
Deleted : user_pref("aol_toolbar.buttons.layout", "aol_mail_5496;facebook_40839;youtube_40850;mapquest_40872;t[...]<br />
Deleted : user_pref("aol_toolbar.default.homepage.check", false);<br />
Deleted : user_pref("aol_toolbar.default.homepage.url", "hxxp://www.aol.com/?mtmhp=hyplogusaolp00000019");<br />
Deleted : user_pref("aol_toolbar.default.search.check", true);<br />
Deleted : user_pref("aol_toolbar.default.search.label", "AOL Search");<br />
Deleted : user_pref("aol_toolbar.default.search.url", "hxxp://search.aol.com/search/search?query={searchTerms}[...]<br />
Deleted : user_pref("aol_toolbar.firsttime.showwindow", false);<br />
Deleted : user_pref("aol_toolbar.guid", "{A6F8C14E-BF15-C2D9-1A7E-CCE423884DE2}");<br />
Deleted : user_pref("aol_toolbar.install.homepage", "hxxp://www.aol.com/?mtmhp={mtmhp}");<br />
Deleted : user_pref("aol_toolbar.install.lastTbVersion", "5.74.1.7990");<br />
Deleted : user_pref("aol_toolbar.install.lid", "hyplognew00000010");<br />
Deleted : user_pref("aol_toolbar.install.mtmhp", "hyplogusaolp00000019");<br />
Deleted : user_pref("aol_toolbar.install.ncid", "");<br />
Deleted : user_pref("aol_toolbar.metrics.activestampdate", "28");<br />
Deleted : user_pref("aol_toolbar.metrics.activestampmonth", "1");<br />
Deleted : user_pref("aol_toolbar.metrics.activestampyear", "2013");<br />
Deleted : user_pref("aol_toolbar.metrics.originalDate", "15");<br />
Deleted : user_pref("aol_toolbar.metrics.originalHours", "2");<br />
Deleted : user_pref("aol_toolbar.metrics.originalMinutes", "16");<br />
Deleted : user_pref("aol_toolbar.metrics.originalMonth", "8");<br />
Deleted : user_pref("aol_toolbar.metrics.originalSeconds", "7");<br />
Deleted : user_pref("aol_toolbar.metrics.originalYear", "2012");<br />
Deleted : user_pref("aol_toolbar.relatednews.enabled", false);<br />
Deleted : user_pref("aol_toolbar.remote.publish.xml", "1362070327601");<br />
Deleted : user_pref("aol_toolbar.rtw.active", false);<br />
Deleted : user_pref("aol_toolbar.search.button", true);<br />
Deleted : user_pref("aol_toolbar.search.cid", "15-08-2012");<br />
Deleted : user_pref("aol_toolbar.search.instd", "20120811143732468");<br />
Deleted : user_pref("aol_toolbar.search.oid", "15-08-2012");<br />
Deleted : user_pref("aol_toolbar.search.populateoncomplete", false);<br />
Deleted : user_pref("aol_toolbar.search.savehistory", false);<br />
Deleted : user_pref("aol_toolbar.search.searchtype", "web");<br />
Deleted : user_pref("aol_toolbar.search.source", "tb50-ff-amonetizetest1");<br />
Deleted : user_pref("aol_toolbar.skin.custom", false);<br />
Deleted : user_pref("aol_toolbar.surf.date", "6");<br />
Deleted : user_pref("aol_toolbar.surf.lastDate", "28");<br />
Deleted : user_pref("aol_toolbar.surf.lastMonth", "1");<br />
Deleted : user_pref("aol_toolbar.surf.lastYear", "2013");<br />
Deleted : user_pref("aol_toolbar.surf.month", "115");<br />
Deleted : user_pref("aol_toolbar.surf.prevMonth", "102");<br />
Deleted : user_pref("aol_toolbar.surf.total", "340");<br />
Deleted : user_pref("aol_toolbar.surf.week", "7");<br />
Deleted : user_pref("aol_toolbar.surf.year", "216");<br />
Deleted : user_pref("aol_toolbar.ticker.active", false);<br />
Deleted : user_pref("aol_toolbar.upgrade.showwindow", false);<br />
Deleted : user_pref("aol_toolbar.weather.degc", "8");<br />
Deleted : user_pref("aol_toolbar.weather.degf", "47");<br />
Deleted : user_pref("aol_toolbar.weather.image", "chrome://aoltoolbar/skin/weather/34.png");<br />
Deleted : user_pref("aol_toolbar.weather.metric", true);<br />
Deleted : user_pref("aol_toolbar.weather.tooltip", "New York , NY : Mostly Sunny");<br />
Deleted : user_pref("aol_toolbar.weather.update", "1362070328750");<br />
Deleted : user_pref("aol_toolbar.weather.zipcode", "10065");<br />
Deleted : user_pref("browser.search.defaultengine", "Ask.com");<br />
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.aol.com/search/search?query={searchTerms}&invo[...]<br />
Deleted : user_pref("browser.search.order.1", "Ask.com");<br />
Deleted : user_pref("keyword.URL", "hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=843&invocatio[...]<br />
<br />
<br />
-\\ Google Chrome v24.0.1312.57<br />
<br />
<br />
File : C:\Documents and Settings\Froy\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences<br />
<br />
<br />
Deleted [l.49] : icon_url = "hxxps://isearch.avg.com/favicon.ico",<br />
Deleted [l.52] : keyword = "isearch.avg.com",<br />
Deleted [l.55] : search_url = "hxxps://isearch.avg.com/search?cid={D29A36C4-FE10-4CDF-AB21-C2799BCF1E0B}&mid=&[...]<br />
<br />
<br />
*************************<br />
<br />
<br />
AdwCleaner[S1].txt - [9644 octets] - [28/02/2013 15:48:14]<br />
<br />
<br />
########## EOF - C:\AdwCleaner[S1].txt - [9704 octets] ##########<br />
<br />
<br />
JRT.txt:<br />
<br />
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br />
Junkware Removal Tool (JRT) by Thisisu<br />
Version: 4.6.6 (02.27.2013:1)<br />
OS: Microsoft Windows XP x86<br />
Ran by Froy on Thu 02/28/2013 at 15:57:00.96<br />
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br />
<br />
<br />
<br />
<br />
<br />
<br />
~~~ Services<br />
<br />
<br />
<br />
<br />
<br />
~~~ Registry Values<br />
<br />
<br />
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName<br />
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL<br />
<br />
<br />
<br />
<br />
<br />
~~~ Registry Keys<br />
<br />
<br />
Successfully deleted: [Registry Key] hkey_local_machine\software\systweak<br />
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{443789b7-f39c-4b5c-9287-da72d38f4fe6}<br />
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{443789b7-f39c-4b5c-9287-da72d38f4fe6}<br />
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{6a1806cd-94d4-4689-ba73-e35ea1ea9990}<br />
<br />
<br />
<br />
<br />
<br />
~~~ Files<br />
<br />
<br />
Successfully deleted: [File] "C:\WINDOWS\system32\roboot.exe"<br />
<br />
<br />
<br />
<br />
<br />
~~~ Folders<br />
<br />
<br />
<br />
<br />
<br />
~~~ FireFox<br />
<br />
<br />
Successfully deleted: [Folder] C:\Documents and Settings\Froy\Application Data\mozilla\firefox\profiles\ae57pzsf.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br />
Scan was completed on Thu 02/28/2013 at 16:02:16.54<br />
End of JRT log<br />
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<br />
<br />
SystemLook.txt:<br />
SystemLook 30.07.11 by jpshortstuff<br />
Log created at 16:38 on 28/02/2013 by Froy<br />
Administrator - Elevation successful<br />
<br />
========== dir ==========<br />
<br />
c:\documents and settings\froy\local settings\application data\exec - Parameters: "/s"<br />
<br />
---Files---<br />
None found.<br />
<br />
No folders found.<br />
<br />
-= EOF =-<br />
</p>
<p> </p>
<p>I don't see any improvement with IE. I clicked the 'Home' button and IE timed out. Tried to get back to this post and IE timed out again. Once I got here, I clicked the 'Edit' button to add this comment, IE timed out again. I just have to keep clicking refresh page, repair network connection, Network Diagnostics for WindowsXP. I've even restarted the machine and come back to the same problem. I have noticed some strange things like some of my 'Services' properties have change, internet disabled. Don't know what's doing that.</p> I don't know if it's my browser or what but this online editor doesn't always load the same. Has a different look and missing some of the font property options-just a sidenote.
Edited by chaknik, 28 February 2013 - 06:28 PM.
Posted 28 February 2013 - 07:00 PM
Posted 28 February 2013 - 07:31 PM
I've tried twice to post Result.txt but both times the server timed out. I'll try again.
MiniToolBox by Farbar Version:10-01-2013
Ran by Froy (administrator) on 28-02-2013 at 16:40:33
Running from "C:\Documents and Settings\Froy\Desktop\BleepingComputer"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= FF Proxy Settings: ==============================
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
========================= Hosts content: =================================
98.139.183.24 www.yahoo.com
67.195.160.76 m.yahoo.com
209.191.93.53 yahoo.com
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
There are 15275 more lines starting with "127.0.0.1"
========================= IP Configuration: ================================
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
popd
# End of interface IP configuration
Windows IP Configuration
Server: UnKnown
Address: 127.0.0.1
Ping request could not find host google.com. Please check the name and try again.
Server: UnKnown
Address: 127.0.0.1
Pinging yahoo.com [209.191.93.53] with 32 bytes of data:
Destination host unreachable.
Destination host unreachable.
Ping statistics for 209.191.93.53:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 23 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 24 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 25 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 26 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 27 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (02/28/2013 01:34:06 PM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/28/2013 01:23:18 PM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/28/2013 11:10:05 AM) (Source: Application Hang) (User: )
Description: Fault bucket 1180947459.
Error: (02/28/2013 11:09:57 AM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/28/2013 07:41:18 AM) (Source: Application Hang) (User: )
Description: Hanging application mbam.exe, version 1.70.0.9, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/27/2013 03:07:42 PM) (Source: Application Hang) (User: )
Description: Hanging application mbam.exe, version 1.70.0.9, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/26/2013 04:00:21 PM) (Source: Application Hang) (User: )
Description: Hanging application explorer.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/26/2013 03:56:37 PM) (Source: Application Hang) (User: )
Description: Hanging application explorer.exe, version 6.0.2900.5512, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/24/2013 02:52:06 PM) (Source: Application Hang) (User: )
Description: Hanging application attcm.exe, version 9.1.177.7, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (02/23/2013 06:24:22 PM) (Source: Application Hang) (User: )
Description: Hanging application mbam.exe, version 1.70.0.9, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
System errors:
=============
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1068
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Telephony service depends on the Plug and Play service which failed to start because of the following error:
%%1058
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1068
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Telephony service depends on the Plug and Play service which failed to start because of the following error:
%%1058
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1068
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Telephony service depends on the Plug and Play service which failed to start because of the following error:
%%1058
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1068
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Telephony service depends on the Plug and Play service which failed to start because of the following error:
%%1058
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1068
Error: (02/28/2013 04:43:08 PM) (Source: Service Control Manager) (User: )
Description: The Telephony service depends on the Plug and Play service which failed to start because of the following error:
%%1058
Microsoft Office Sessions:
=========================
**** End of log ****
Posted 28 February 2013 - 08:30 PM
Are you experiencing this will all web browsers or just Internet Explorer?
Posted 28 February 2013 - 08:53 PM
Firefox also, I have Chrome but haven't used it, don't like it. I'll have to sign off for now. Have other pressing matters. Will get back tomorrow. Thanks, Roy
Posted 28 February 2013 - 09:52 PM
Hi Roy,
Please run this program. You can download it onto a USB device and transfer it to your computer.
===================================================
Run TDSSKiller by Kaspersky on Vista/7
--------------------



-- If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to these instructions. In some cases it may be necessary to redownload TDSSKiller and randomly rename it before downloading and saving to the computer or to perform the scan in "safe mode".
===================================================
Things I would like to see in your next reply. Please be sure to copy and paste the information rather than send an attachment. ![]()
Posted 01 March 2013 - 11:56 AM
Well, I ran the TDSSKiller.exe (run as adminstrator) failed to initialize, wouldn't run. Changed name to td.com(no option to run as administrator), ran the program, it found no problems but there was the word 'Report' at the top right of the window. I clicked it and a text file called 'report' opened. I highlighted all the text and tried to copy but it wouldn't copy. So, sorry to say, I've come back empty handed.????? There was no TDSSKiller....log.txt generated, even after I rebooted.
Posted 01 March 2013 - 11:59 AM
Posted 01 March 2013 - 12:34 PM
Yes, it was there. Sorry again. Everytime I click a link or try to get back to this page, it takes several attempts....always timing out. I kinda lose sight of where I am at times.
10:36:25.0187 2208 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
10:36:25.0187 2208 ============================================================
10:36:25.0187 2208 Current date / time: 2013/03/01 10:36:25.0187
10:36:25.0187 2208 SystemInfo:
10:36:25.0187 2208
10:36:25.0187 2208 OS Version: 5.1.2600 ServicePack: 3.0
10:36:25.0187 2208 Product type: Workstation
10:36:25.0187 2208 ComputerName: RAS
10:36:25.0187 2208 UserName: Froy
10:36:25.0187 2208 Windows directory: C:\WINDOWS
10:36:25.0187 2208 System windows directory: C:\WINDOWS
10:36:25.0187 2208 Processor architecture: Intel x86
10:36:25.0187 2208 Number of processors: 2
10:36:25.0187 2208 Page size: 0x1000
10:36:25.0187 2208 Boot type: Normal boot
10:36:25.0187 2208 ============================================================
10:36:25.0562 2208 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:36:25.0609 2208 ============================================================
10:36:25.0609 2208 \Device\Harddisk0\DR0:
10:36:25.0609 2208 MBR partitions:
10:36:25.0609 2208 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x24E107F2
10:36:25.0609 2208 ============================================================
10:36:25.0640 2208 C: <-> \Device\Harddisk0\DR0\Partition1
10:36:25.0640 2208 ============================================================
10:36:25.0640 2208 Initialize success
10:36:25.0640 2208 ============================================================
10:36:36.0046 2232 ============================================================
10:36:36.0046 2232 Scan started
10:36:36.0046 2232 Mode: Manual;
10:36:36.0046 2232 ============================================================
10:36:36.0171 2232 ================ Scan system memory ========================
10:36:36.0187 2232 System memory - ok
10:36:36.0187 2232 ================ Scan services =============================
10:36:36.0218 2232 [ 01E81C84AD1D0ACC61CF3CFD06632210 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
10:36:36.0218 2232 !SASCORE - ok
10:36:36.0328 2232 [ 914A9709FC3BF419AD2F85547F2A4832 ] 61883 C:\WINDOWS\system32\DRIVERS\61883.sys
10:36:36.0328 2232 61883 - ok
10:36:36.0328 2232 Abiosdsk - ok
10:36:36.0343 2232 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:36:36.0343 2232 abp480n5 - ok
10:36:36.0375 2232 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:36:36.0375 2232 ACPI - ok
10:36:36.0406 2232 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
10:36:36.0406 2232 ACPIEC - ok
10:36:36.0484 2232 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
10:36:36.0484 2232 AdobeFlashPlayerUpdateSvc - ok
10:36:36.0531 2232 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:36:36.0546 2232 adpu160m - ok
10:36:36.0562 2232 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
10:36:36.0562 2232 aec - ok
10:36:36.0609 2232 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
10:36:36.0625 2232 AFD - ok
10:36:36.0640 2232 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
10:36:36.0656 2232 agp440 - ok
10:36:36.0703 2232 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:36:36.0703 2232 agpCPQ - ok
10:36:36.0703 2232 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:36:36.0703 2232 Aha154x - ok
10:36:36.0718 2232 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:36:36.0718 2232 aic78u2 - ok
10:36:36.0718 2232 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:36:36.0718 2232 aic78xx - ok
10:36:36.0750 2232 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
10:36:36.0750 2232 Alerter - ok
10:36:36.0781 2232 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
10:36:36.0781 2232 ALG - ok
10:36:36.0796 2232 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
10:36:36.0796 2232 AliIde - ok
10:36:36.0812 2232 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:36:36.0812 2232 alim1541 - ok
10:36:36.0828 2232 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:36:36.0828 2232 amdagp - ok
10:36:36.0828 2232 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
10:36:36.0828 2232 amsint - ok
10:36:36.0859 2232 AppMgmt - ok
10:36:36.0875 2232 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:36:36.0875 2232 Arp1394 - ok
10:36:36.0890 2232 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
10:36:36.0890 2232 asc - ok
10:36:36.0906 2232 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:36:36.0906 2232 asc3350p - ok
10:36:36.0906 2232 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:36:36.0906 2232 asc3550 - ok
10:36:36.0937 2232 [ 5B01AF89D16D562825C4DB4530F20CBB ] ASPI32 C:\WINDOWS\system32\drivers\aspi32.sys
10:36:36.0937 2232 ASPI32 - ok
10:36:37.0062 2232 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
10:36:37.0062 2232 aspnet_state - ok
10:36:37.0078 2232 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:36:37.0078 2232 AsyncMac - ok
10:36:37.0109 2232 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
10:36:37.0109 2232 atapi - ok
10:36:37.0109 2232 Atdisk - ok
10:36:37.0125 2232 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:36:37.0125 2232 Atmarpc - ok
10:36:37.0156 2232 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
10:36:37.0156 2232 AudioSrv - ok
10:36:37.0171 2232 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
10:36:37.0171 2232 audstub - ok
10:36:37.0187 2232 [ F8E6956A614F15A0860474C5E2A7DE6B ] Avc C:\WINDOWS\system32\DRIVERS\avc.sys
10:36:37.0187 2232 Avc - ok
10:36:37.0203 2232 [ CAE7B6E4D7EB17829C526153D19B9C95 ] avgtp C:\WINDOWS\system32\drivers\avgtpx86.sys
10:36:37.0218 2232 avgtp - ok
10:36:37.0250 2232 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
10:36:37.0250 2232 Beep - ok
10:36:37.0296 2232 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
10:36:37.0468 2232 BITS - ok
10:36:37.0500 2232 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
10:36:37.0515 2232 Browser - ok
10:36:37.0546 2232 [ 0F249BE872F618AABA8D641E81AA3D21 ] btaudio C:\WINDOWS\system32\drivers\btaudio.sys
10:36:37.0546 2232 btaudio - ok
10:36:37.0578 2232 [ 07F0A66CFA550B13AD0674AE09E3CBA0 ] BTDriver C:\WINDOWS\system32\DRIVERS\btport.sys
10:36:37.0578 2232 BTDriver - ok
10:36:37.0625 2232 [ ADE37AB15C958F5DB2F85431CCA8763A ] BTKRNL C:\WINDOWS\system32\DRIVERS\btkrnl.sys
10:36:37.0640 2232 BTKRNL - ok
10:36:37.0718 2232 [ B7822EA8D11717D1FE27295EAFF3E2CE ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
10:36:37.0734 2232 btwdins - ok
10:36:37.0765 2232 [ B1D350F3F13CF340FCE93912D2BA1EBF ] BTWDNDIS C:\WINDOWS\system32\DRIVERS\btwdndis.sys
10:36:37.0765 2232 BTWDNDIS - ok
10:36:37.0781 2232 [ 6BEB0ADAA3D2B80E6515EEC5D03B7540 ] btwhid C:\WINDOWS\system32\DRIVERS\btwhid.sys
10:36:37.0781 2232 btwhid - ok
10:36:37.0812 2232 [ E206EC370646E42DC862FD995869D31D ] btwmodem C:\WINDOWS\system32\DRIVERS\btwmodem.sys
10:36:37.0812 2232 btwmodem - ok
10:36:37.0843 2232 [ A01FD9851406DE0870C23759E2F7B6EA ] BTWUSB C:\WINDOWS\system32\Drivers\btwusb.sys
10:36:37.0843 2232 BTWUSB - ok
10:36:37.0890 2232 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:36:37.0906 2232 cbidf - ok
10:36:37.0906 2232 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
10:36:37.0906 2232 cbidf2k - ok
10:36:37.0921 2232 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:36:37.0921 2232 CCDECODE - ok
10:36:37.0937 2232 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:36:37.0937 2232 cd20xrnt - ok
10:36:37.0968 2232 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
10:36:37.0968 2232 Cdaudio - ok
10:36:38.0015 2232 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
10:36:38.0015 2232 Cdfs - ok
10:36:38.0015 2232 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:36:38.0015 2232 Cdrom - ok
10:36:38.0015 2232 Changer - ok
10:36:38.0062 2232 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
10:36:38.0062 2232 CiSvc - ok
10:36:38.0078 2232 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
10:36:38.0078 2232 ClipSrv - ok
10:36:38.0093 2232 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:36:38.0093 2232 clr_optimization_v2.0.50727_32 - ok
10:36:38.0125 2232 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:36:38.0125 2232 CmdIde - ok
10:36:38.0125 2232 COMSysApp - ok
10:36:38.0140 2232 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:36:38.0140 2232 Cpqarray - ok
10:36:38.0156 2232 [ 3C8B6609712F4FF78E521F6DCFC4032B ] Creative Service for CDROM Access C:\WINDOWS\system32\CTsvcCDA.exe
10:36:38.0171 2232 Creative Service for CDROM Access - ok
10:36:38.0171 2232 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
10:36:38.0171 2232 CryptSvc - ok
10:36:38.0234 2232 [ 8A9C65CE4FE6E8CB24CE06BA28D951A0 ] ctac32k C:\WINDOWS\system32\drivers\ctac32k.sys
10:36:38.0234 2232 ctac32k - ok
10:36:38.0250 2232 [ 47236971DFB3E03690B98E41665D0924 ] ctaud2k C:\WINDOWS\system32\drivers\ctaud2k.sys
10:36:38.0250 2232 ctaud2k - ok
10:36:38.0312 2232 [ 5A0EEB00B02FC78605AA9D3590B24978 ] ctdvda2k C:\WINDOWS\system32\drivers\ctdvda2k.sys
10:36:38.0312 2232 ctdvda2k - ok
10:36:38.0312 2232 [ 2381CF056C15271F6B8DAB50FF82CF3A ] ctprxy2k C:\WINDOWS\system32\drivers\ctprxy2k.sys
10:36:38.0312 2232 ctprxy2k - ok
10:36:38.0343 2232 [ DA1C530DE86C85A701138B30FB145AF3 ] ctsfm2k C:\WINDOWS\system32\drivers\ctsfm2k.sys
10:36:38.0343 2232 ctsfm2k - ok
10:36:38.0375 2232 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:36:38.0375 2232 dac2w2k - ok
10:36:38.0390 2232 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:36:38.0390 2232 dac960nt - ok
10:36:38.0437 2232 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
10:36:38.0437 2232 DcomLaunch - ok
10:36:38.0484 2232 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
10:36:38.0484 2232 Dhcp - ok
10:36:38.0500 2232 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
10:36:38.0500 2232 Disk - ok
10:36:38.0500 2232 dmadmin - ok
10:36:38.0546 2232 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
10:36:38.0578 2232 dmboot - ok
10:36:38.0578 2232 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
10:36:38.0578 2232 dmio - ok
10:36:38.0593 2232 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
10:36:38.0593 2232 dmload - ok
10:36:38.0609 2232 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
10:36:38.0625 2232 dmserver - ok
10:36:38.0640 2232 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
10:36:38.0640 2232 DMusic - ok
10:36:38.0671 2232 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
10:36:38.0671 2232 Dnscache - ok
10:36:38.0718 2232 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
10:36:38.0718 2232 Dot3svc - ok
10:36:38.0718 2232 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:36:38.0734 2232 dpti2o - ok
10:36:38.0734 2232 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
10:36:38.0734 2232 drmkaud - ok
10:36:38.0765 2232 [ 245F62A2AA67F4A61F10174BF1017327 ] DSBrokerService C:\Program Files\DellSupport\brkrsvc.exe
10:36:38.0765 2232 DSBrokerService - ok
10:36:38.0796 2232 [ 413F2D5F9D802688242C23B38F767ECB ] DSproct C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
10:36:38.0796 2232 DSproct - ok
10:36:38.0796 2232 [ DFEABB7CFFFADEA4A912AB95BDC3177A ] dsunidrv C:\WINDOWS\system32\DRIVERS\dsunidrv.sys
10:36:38.0796 2232 dsunidrv - ok
10:36:38.0812 2232 [ 3FCA03CBCA11269F973B70FA483C88EF ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
10:36:38.0812 2232 E100B - ok
10:36:38.0843 2232 [ 00192F0C612591D585594E9467E6CA8B ] e1express C:\WINDOWS\system32\DRIVERS\e1e5132.sys
10:36:38.0843 2232 e1express - ok
10:36:38.0875 2232 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
10:36:38.0875 2232 EapHost - ok
10:36:38.0906 2232 [ 661CF27263F3E0B553BE050A42D357DB ] emupia C:\WINDOWS\system32\drivers\emupia2k.sys
10:36:38.0906 2232 emupia - ok
10:36:38.0937 2232 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
10:36:38.0937 2232 ERSvc - ok
10:36:38.0968 2232 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
10:36:38.0968 2232 Eventlog - ok
10:36:39.0031 2232 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\Es.dll
10:36:39.0031 2232 EventSystem - ok
10:36:39.0046 2232 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
10:36:39.0046 2232 Fastfat - ok
10:36:39.0093 2232 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
10:36:39.0093 2232 FastUserSwitchingCompatibility - ok
10:36:39.0125 2232 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
10:36:39.0125 2232 Fdc - ok
10:36:39.0156 2232 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
10:36:39.0156 2232 Fips - ok
10:36:39.0171 2232 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:36:39.0171 2232 Flpydisk - ok
10:36:39.0203 2232 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
10:36:39.0203 2232 FltMgr - ok
10:36:39.0296 2232 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
10:36:39.0296 2232 FontCache3.0.0.0 - ok
10:36:39.0312 2232 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:36:39.0312 2232 Fs_Rec - ok
10:36:39.0312 2232 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:36:39.0328 2232 Ftdisk - ok
10:36:39.0390 2232 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
10:36:39.0390 2232 GoToAssist - ok
10:36:39.0421 2232 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:36:39.0421 2232 Gpc - ok
10:36:39.0484 2232 [ 862D4185D43128FEF7818711F8F30436 ] ha20x2k C:\WINDOWS\system32\drivers\ha20x2k.sys
10:36:39.0500 2232 ha20x2k - ok
10:36:39.0578 2232 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:36:39.0593 2232 helpsvc - ok
10:36:39.0609 2232 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
10:36:39.0609 2232 HidServ - ok
10:36:39.0625 2232 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:36:39.0625 2232 HidUsb - ok
10:36:39.0656 2232 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
10:36:39.0671 2232 hkmsvc - ok
10:36:39.0718 2232 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
10:36:39.0718 2232 hpn - ok
10:36:39.0718 2232 HSF_DPV - ok
10:36:39.0765 2232 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
10:36:39.0765 2232 HTTP - ok
10:36:39.0796 2232 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
10:36:39.0796 2232 HTTPFilter - ok
10:36:39.0828 2232 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
10:36:39.0828 2232 i2omgmt - ok
10:36:39.0843 2232 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:36:39.0843 2232 i2omp - ok
10:36:39.0843 2232 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:36:39.0859 2232 i8042prt - ok
10:36:39.0937 2232 [ B122BE74E283A2BC7FEBC180BFD2EFD5 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
10:36:39.0937 2232 IAANTMON - ok
10:36:39.0984 2232 [ 019CF5F31C67030841233C545A0E217A ] iaStor C:\WINDOWS\system32\drivers\iaStor.sys
10:36:39.0984 2232 iaStor - ok
10:36:40.0093 2232 [ 6F95324909B502E2651442C1548AB12F ] IDriverT C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
10:36:40.0093 2232 IDriverT - ok
10:36:40.0156 2232 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:36:40.0156 2232 idsvc - ok
10:36:40.0218 2232 [ CC8DBB39941DFED9DC34C463F0ED7660 ] IERA C:\Program Files\Sierra Wireless Inc\IERA\IERA.exe
10:36:40.0234 2232 IERA - ok
10:36:40.0265 2232 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
10:36:40.0265 2232 Imapi - ok
10:36:40.0312 2232 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
10:36:40.0312 2232 ImapiService - ok
10:36:40.0343 2232 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:36:40.0343 2232 ini910u - ok
10:36:40.0359 2232 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
10:36:40.0359 2232 IntelIde - ok
10:36:40.0390 2232 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:36:40.0390 2232 intelppm - ok
10:36:40.0406 2232 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
10:36:40.0406 2232 Ip6Fw - ok
10:36:40.0421 2232 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:36:40.0421 2232 IpFilterDriver - ok
10:36:40.0421 2232 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:36:40.0421 2232 IpInIp - ok
10:36:40.0437 2232 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:36:40.0453 2232 IpNat - ok
10:36:40.0468 2232 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:36:40.0468 2232 IPSec - ok
10:36:40.0500 2232 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
10:36:40.0500 2232 IRENUM - ok
10:36:40.0531 2232 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:36:40.0531 2232 isapnp - ok
10:36:40.0640 2232 [ CC54FD59486BEF7CE70275FAC2FD9D34 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
10:36:40.0640 2232 JavaQuickStarterService - ok
10:36:40.0656 2232 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:36:40.0671 2232 Kbdclass - ok
10:36:40.0671 2232 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:36:40.0671 2232 kbdhid - ok
10:36:40.0671 2232 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
10:36:40.0687 2232 kmixer - ok
10:36:40.0703 2232 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
10:36:40.0703 2232 KSecDD - ok
10:36:40.0765 2232 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
10:36:40.0765 2232 LanmanServer - ok
10:36:40.0828 2232 [ A8888A5327621856C0CEC4E385F69309 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
10:36:40.0828 2232 LanmanWorkstation - ok
10:36:40.0828 2232 Lavasoft Kernexplorer - ok
10:36:40.0828 2232 lbrtfdc - ok
10:36:40.0921 2232 [ D27DD0015DCECF445F229020D263392A ] LBTServ C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
10:36:40.0921 2232 LBTServ - ok
10:36:40.0968 2232 [ 597D79382C154CEDB638A65012925A23 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
10:36:40.0968 2232 LHidFilt - ok
10:36:40.0984 2232 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
10:36:40.0984 2232 LmHosts - ok
10:36:41.0015 2232 [ 9EAD053D28182BD6ACB19D5F58202194 ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
10:36:41.0015 2232 LMouFilt - ok
10:36:41.0093 2232 [ DDF15A42E27E8EFE27B18FD403151A86 ] MatSvc C:\Program Files\Microsoft Fix it Center\Matsvc.exe
10:36:41.0093 2232 MatSvc - ok
10:36:41.0125 2232 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
10:36:41.0125 2232 Messenger - ok
10:36:41.0156 2232 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
10:36:41.0156 2232 mnmdd - ok
10:36:41.0171 2232 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
10:36:41.0171 2232 mnmsrvc - ok
10:36:41.0187 2232 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
10:36:41.0187 2232 Modem - ok
10:36:41.0203 2232 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys
10:36:41.0203 2232 MODEMCSA - ok
10:36:41.0218 2232 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:36:41.0218 2232 Mouclass - ok
10:36:41.0218 2232 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:36:41.0218 2232 mouhid - ok
10:36:41.0250 2232 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
10:36:41.0250 2232 MountMgr - ok
10:36:41.0281 2232 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:36:41.0281 2232 mraid35x - ok
10:36:41.0296 2232 MREMP50 - ok
10:36:41.0296 2232 MREMP50a64 - ok
10:36:41.0296 2232 MRESP50 - ok
10:36:41.0296 2232 MRESP50a64 - ok
10:36:41.0296 2232 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:36:41.0312 2232 MRxDAV - ok
10:36:41.0375 2232 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:36:41.0375 2232 MRxSmb - ok
10:36:41.0375 2232 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
10:36:41.0390 2232 MSDTC - ok
10:36:41.0406 2232 [ 1477849772712BAC69C144DCF2C9CE81 ] MSDV C:\WINDOWS\system32\DRIVERS\msdv.sys
10:36:41.0406 2232 MSDV - ok
10:36:41.0421 2232 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
10:36:41.0421 2232 Msfs - ok
10:36:41.0421 2232 MSIServer - ok
10:36:41.0453 2232 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:36:41.0453 2232 MSKSSRV - ok
10:36:41.0453 2232 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:36:41.0453 2232 MSPCLOCK - ok
10:36:41.0468 2232 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
10:36:41.0468 2232 MSPQM - ok
10:36:41.0484 2232 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:36:41.0484 2232 mssmbios - ok
10:36:41.0531 2232 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
10:36:41.0531 2232 MSTEE - ok
10:36:41.0531 2232 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
10:36:41.0531 2232 Mup - ok
10:36:41.0546 2232 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:36:41.0562 2232 NABTSFEC - ok
10:36:41.0593 2232 [ 1E59AAED42A5E3A5ED86EC403F9C0776 ] NAL C:\WINDOWS\system32\Drivers\iqvw32.sys
10:36:41.0609 2232 NAL - ok
10:36:41.0625 2232 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
10:36:41.0640 2232 napagent - ok
10:36:41.0671 2232 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
10:36:41.0671 2232 NDIS - ok
10:36:41.0687 2232 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:36:41.0687 2232 NdisIP - ok
10:36:41.0718 2232 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:36:41.0718 2232 NdisTapi - ok
10:36:41.0750 2232 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:36:41.0750 2232 Ndisuio - ok
10:36:41.0765 2232 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:36:41.0765 2232 NdisWan - ok
10:36:41.0812 2232 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
10:36:41.0812 2232 NDProxy - ok
10:36:41.0812 2232 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
10:36:41.0812 2232 NetBIOS - ok
10:36:41.0828 2232 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
10:36:41.0828 2232 NetBT - ok
10:36:41.0859 2232 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
10:36:41.0859 2232 NetDDE - ok
10:36:41.0875 2232 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
10:36:41.0875 2232 NetDDEdsdm - ok
10:36:41.0906 2232 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
10:36:41.0906 2232 Netlogon - ok
10:36:41.0921 2232 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
10:36:41.0921 2232 Netman - ok
10:36:41.0953 2232 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:36:41.0953 2232 NetTcpPortSharing - ok
10:36:41.0968 2232 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:36:41.0968 2232 NIC1394 - ok
10:36:42.0015 2232 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
10:36:42.0031 2232 Nla - ok
10:36:42.0062 2232 [ 1E421A6BCF2203CC61B821ADA9DE878B ] nm C:\WINDOWS\system32\DRIVERS\NMnt.sys
10:36:42.0062 2232 nm - ok
10:36:42.0078 2232 [ 05F6BE0427ECB1D4F0985217F30F49F2 ] NPF C:\WINDOWS\system32\drivers\npf.sys
10:36:42.0078 2232 NPF - ok
10:36:42.0078 2232 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
10:36:42.0078 2232 Npfs - ok
10:36:42.0125 2232 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
10:36:42.0171 2232 Ntfs - ok
10:36:42.0171 2232 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
10:36:42.0171 2232 NtLmSsp - ok
10:36:42.0218 2232 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
10:36:42.0234 2232 NtmsSvc - ok
10:36:42.0265 2232 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
10:36:42.0265 2232 Null - ok
10:36:42.0468 2232 [ 81B2932BDD8686D70AFD87FD13BC183D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:36:42.0656 2232 nv - ok
10:36:42.0687 2232 [ E0DFD64A91F5173A554A872BB9B3F4B3 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
10:36:42.0687 2232 NVSvc - ok
10:36:42.0718 2232 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:36:42.0734 2232 NwlnkFlt - ok
10:36:42.0734 2232 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:36:42.0734 2232 NwlnkFwd - ok
10:36:42.0843 2232 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
10:36:42.0843 2232 odserv - ok
10:36:42.0859 2232 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:36:42.0859 2232 ohci1394 - ok
10:36:42.0875 2232 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:36:42.0875 2232 ose - ok
10:36:42.0906 2232 [ 99F877A7BB6FEB5AF1184EAFE937C208 ] ossrv C:\WINDOWS\system32\drivers\ctoss2k.sys
10:36:42.0906 2232 ossrv - ok
10:36:42.0937 2232 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
10:36:42.0937 2232 Parport - ok
10:36:42.0953 2232 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
10:36:42.0953 2232 PartMgr - ok
10:36:42.0984 2232 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
10:36:42.0984 2232 ParVdm - ok
10:36:43.0000 2232 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
10:36:43.0000 2232 PCI - ok
10:36:43.0015 2232 PCIDump - ok
10:36:43.0046 2232 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
10:36:43.0046 2232 PCIIde - ok
10:36:43.0062 2232 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
10:36:43.0062 2232 Pcmcia - ok
10:36:43.0078 2232 [ 7E0F42201E8948315998FCDB0D97F519 ] PCTINDIS5 C:\WINDOWS\system32\PCTINDIS5.SYS
10:36:43.0078 2232 PCTINDIS5 - ok
10:36:43.0078 2232 PDCOMP - ok
10:36:43.0093 2232 PDFRAME - ok
10:36:43.0093 2232 PDRELI - ok
10:36:43.0093 2232 PDRFRAME - ok
10:36:43.0093 2232 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
10:36:43.0093 2232 perc2 - ok
10:36:43.0109 2232 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:36:43.0109 2232 perc2hib - ok
10:36:43.0140 2232 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
10:36:43.0140 2232 PlugPlay - ok
10:36:43.0156 2232 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
10:36:43.0156 2232 PolicyAgent - ok
10:36:43.0156 2232 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:36:43.0156 2232 PptpMiniport - ok
10:36:43.0171 2232 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
10:36:43.0171 2232 ProtectedStorage - ok
10:36:43.0171 2232 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:36:43.0171 2232 Ptilink - ok
10:36:43.0187 2232 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
10:36:43.0187 2232 PxHelp20 - ok
10:36:43.0203 2232 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:36:43.0203 2232 ql1080 - ok
10:36:43.0234 2232 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:36:43.0234 2232 Ql10wnt - ok
10:36:43.0234 2232 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:36:43.0234 2232 ql12160 - ok
10:36:43.0265 2232 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:36:43.0265 2232 ql1240 - ok
10:36:43.0265 2232 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:36:43.0265 2232 ql1280 - ok
10:36:43.0281 2232 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:36:43.0281 2232 RasAcd - ok
10:36:43.0312 2232 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:36:43.0312 2232 RasAuto - ok
10:36:43.0343 2232 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:36:43.0343 2232 Rasl2tp - ok
10:36:43.0390 2232 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
10:36:43.0390 2232 RasMan - ok
10:36:43.0406 2232 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:36:43.0406 2232 RasPppoe - ok
10:36:43.0406 2232 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
10:36:43.0406 2232 Raspti - ok
10:36:43.0421 2232 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:36:43.0421 2232 Rdbss - ok
10:36:43.0421 2232 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:36:43.0421 2232 RDPCDD - ok
10:36:43.0453 2232 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:36:43.0453 2232 rdpdr - ok
10:36:43.0484 2232 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
10:36:43.0484 2232 RDPWD - ok
10:36:43.0531 2232 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
10:36:43.0531 2232 RDSessMgr - ok
10:36:43.0546 2232 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
10:36:43.0546 2232 redbook - ok
10:36:43.0578 2232 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:36:43.0593 2232 RemoteAccess - ok
10:36:43.0609 2232 [ 2C4FB2E9F039287767C384E46EE91030 ] RimVSerPort C:\WINDOWS\system32\DRIVERS\RimSerial.sys
10:36:43.0609 2232 RimVSerPort - ok
10:36:43.0625 2232 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys
10:36:43.0625 2232 ROOTMODEM - ok
10:36:43.0703 2232 [ D131B07080C7CCB6EE2CC1494D6F58B4 ] rpcapd C:\Program Files\WinPcap\rpcapd.exe
10:36:43.0703 2232 rpcapd - ok
10:36:43.0718 2232 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
10:36:43.0718 2232 RpcLocator - ok
10:36:43.0750 2232 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:36:43.0750 2232 RpcSs - ok
10:36:43.0781 2232 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
10:36:43.0781 2232 RSVP - ok
10:36:43.0828 2232 SABProcEnum - ok
10:36:43.0843 2232 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
10:36:43.0843 2232 SamSs - ok
10:36:43.0875 2232 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
10:36:43.0875 2232 SASDIFSV - ok
10:36:43.0906 2232 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
10:36:43.0906 2232 SASKUTIL - ok
10:36:43.0906 2232 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
10:36:43.0921 2232 SCardSvr - ok
10:36:43.0968 2232 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:36:43.0984 2232 Schedule - ok
10:36:44.0015 2232 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:36:44.0015 2232 Secdrv - ok
10:36:44.0031 2232 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
10:36:44.0031 2232 seclogon - ok
10:36:44.0062 2232 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
10:36:44.0062 2232 SENS - ok
10:36:44.0078 2232 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
10:36:44.0078 2232 serenum - ok
10:36:44.0078 2232 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
10:36:44.0093 2232 Serial - ok
10:36:44.0109 2232 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
10:36:44.0109 2232 Sfloppy - ok
10:36:44.0156 2232 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
10:36:44.0156 2232 SharedAccess - ok
10:36:44.0203 2232 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:36:44.0203 2232 ShellHWDetection - ok
10:36:44.0203 2232 Simbad - ok
10:36:44.0234 2232 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:36:44.0234 2232 sisagp - ok
10:36:44.0234 2232 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:36:44.0234 2232 SLIP - ok
10:36:44.0328 2232 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:36:44.0328 2232 Sparrow - ok
10:36:44.0343 2232 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
10:36:44.0359 2232 splitter - ok
10:36:44.0406 2232 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
10:36:44.0406 2232 Spooler - ok
10:36:44.0453 2232 sprtsvc_dellsupportcenter - ok
10:36:44.0468 2232 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
10:36:44.0468 2232 sr - ok
10:36:44.0500 2232 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
10:36:44.0500 2232 srservice - ok
10:36:44.0546 2232 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:36:44.0546 2232 Srv - ok
10:36:44.0546 2232 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:36:44.0562 2232 SSDPSRV - ok
10:36:44.0562 2232 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
10:36:44.0562 2232 stisvc - ok
10:36:44.0578 2232 stllssvr - ok
10:36:44.0609 2232 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:36:44.0609 2232 streamip - ok
10:36:44.0625 2232 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
10:36:44.0625 2232 swenum - ok
10:36:44.0656 2232 [ FDBD13CE3B3FC298E7FBB98B026F1ECB ] swg3kser00 C:\WINDOWS\system32\DRIVERS\swg3kser00.sys
10:36:44.0656 2232 swg3kser00 - ok
10:36:44.0703 2232 [ 1BD6EE93178F01E58ECA846DA0C69F14 ] SwiCardDetectSvc C:\Program Files\Sierra Wireless Inc\Common\SwiCardDetect.exe
10:36:44.0703 2232 SwiCardDetectSvc - ok
10:36:44.0734 2232 [ 5230AAB3A00B0A1B89580D8ED85B5BFA ] swivsp C:\WINDOWS\system32\DRIVERS\swivspnt.sys
10:36:44.0750 2232 swivsp - ok
10:36:44.0765 2232 [ C61566BE5B8DA87F1B2BD3D9EC08592D ] swiwdmbx C:\WINDOWS\system32\DRIVERS\swiwdmbx.sys
10:36:44.0765 2232 swiwdmbx - ok
10:36:44.0781 2232 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
10:36:44.0781 2232 swmidi - ok
10:36:44.0828 2232 [ 4748C3FBD786AA84852F0ACC416C932A ] SWNC8U12 C:\WINDOWS\system32\DRIVERS\swnc8u12.sys
10:36:44.0828 2232 SWNC8U12 - ok
10:36:44.0859 2232 [ 1D394F1585793AC2A9738028FF97FBE3 ] SWNC8UA3 C:\WINDOWS\system32\DRIVERS\swnc8ua3.sys
10:36:44.0859 2232 SWNC8UA3 - ok
10:36:44.0859 2232 SwPrv - ok
10:36:44.0890 2232 [ 574A712E3015A7E092756DB3D1982107 ] swumx12 C:\WINDOWS\system32\DRIVERS\swumx12.sys
10:36:44.0890 2232 swumx12 - ok
10:36:44.0890 2232 SWUMX20 - ok
10:36:44.0906 2232 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
10:36:44.0921 2232 symc810 - ok
10:36:44.0921 2232 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:36:44.0921 2232 symc8xx - ok
10:36:44.0921 2232 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:36:44.0921 2232 sym_hi - ok
10:36:44.0921 2232 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:36:44.0921 2232 sym_u3 - ok
10:36:44.0921 2232 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
10:36:44.0937 2232 sysaudio - ok
10:36:44.0984 2232 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
10:36:44.0984 2232 SysmonLog - ok
10:36:45.0015 2232 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:36:45.0015 2232 TapiSrv - ok
10:36:45.0062 2232 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:36:45.0078 2232 Tcpip - ok
10:36:45.0093 2232 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
10:36:45.0093 2232 TDPIPE - ok
10:36:45.0109 2232 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
10:36:45.0109 2232 TDTCP - ok
10:36:45.0140 2232 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
10:36:45.0140 2232 TermDD - ok
10:36:45.0171 2232 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
10:36:45.0171 2232 TermService - ok
10:36:45.0203 2232 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
10:36:45.0203 2232 Themes - ok
10:36:45.0234 2232 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
10:36:45.0234 2232 TosIde - ok
10:36:45.0265 2232 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
10:36:45.0265 2232 TrkWks - ok
10:36:45.0421 2232 [ 9DF6AD6FC51A802808621CBFB2A88453 ] TuneUp.UtilitiesSvc C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesService32.exe
10:36:45.0453 2232 TuneUp.UtilitiesSvc - ok
10:36:45.0468 2232 [ 94C4CD2D19B8C4137A46261F229FEC24 ] TuneUpUtilitiesDrv C:\Program Files\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver32.sys
10:36:45.0468 2232 TuneUpUtilitiesDrv - ok
10:36:45.0500 2232 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
10:36:45.0500 2232 Udfs - ok
10:36:45.0531 2232 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
10:36:45.0531 2232 ultra - ok
10:36:45.0578 2232 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
10:36:45.0578 2232 Update - ok
10:36:45.0609 2232 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
10:36:45.0609 2232 upnphost - ok
10:36:45.0640 2232 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
10:36:45.0640 2232 UPS - ok
10:36:45.0671 2232 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:36:45.0671 2232 usbccgp - ok
10:36:45.0687 2232 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:36:45.0687 2232 usbehci - ok
10:36:45.0734 2232 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:36:45.0734 2232 usbhub - ok
10:36:45.0750 2232 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:36:45.0750 2232 usbprint - ok
10:36:45.0765 2232 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:36:45.0765 2232 usbscan - ok
10:36:45.0781 2232 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:36:45.0781 2232 USBSTOR - ok
10:36:45.0781 2232 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:36:45.0796 2232 usbuhci - ok
10:36:45.0796 2232 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
10:36:45.0796 2232 VgaSave - ok
10:36:45.0796 2232 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:36:45.0796 2232 viaagp - ok
10:36:45.0828 2232 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
10:36:45.0828 2232 ViaIde - ok
10:36:45.0843 2232 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
10:36:45.0859 2232 VolSnap - ok
10:36:45.0859 2232 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
10:36:45.0875 2232 VSS - ok
10:36:45.0937 2232 [ 3AD1E72748978D8B0B3B674741E4C3E2 ] vToolbarUpdater14.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
10:36:45.0984 2232 vToolbarUpdater14.2.0 - ok
10:36:46.0015 2232 [ 96D9503DF68CD4DCFEE9F44903DB5BB0 ] VWan2k C:\WINDOWS\system32\DRIVERS\VWan2k.SYS
10:36:46.0015 2232 VWan2k - ok
10:36:46.0046 2232 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll
10:36:46.0046 2232 w32time - ok
10:36:46.0062 2232 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:36:46.0062 2232 Wanarp - ok
10:36:46.0109 2232 [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
10:36:46.0109 2232 Wdf01000 - ok
10:36:46.0125 2232 WDICA - ok
10:36:46.0140 2232 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
10:36:46.0140 2232 wdmaud - ok
10:36:46.0140 2232 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:36:46.0140 2232 WebClient - ok
10:36:46.0234 2232 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:36:46.0234 2232 winmgmt - ok
10:36:46.0265 2232 [ 051B1BDECD6DEE18C771B5D5EC7F044D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
10:36:46.0265 2232 WmdmPmSN - ok
10:36:46.0296 2232 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:36:46.0296 2232 WmiApSrv - ok
10:36:46.0390 2232 [ 6BAB4DC65515A098505F8B3D01FB6FE5 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
10:36:46.0421 2232 WMPNetworkSvc - ok
10:36:46.0437 2232 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
10:36:46.0437 2232 WS2IFSL - ok
10:36:46.0468 2232 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
10:36:46.0484 2232 wscsvc - ok
10:36:46.0500 2232 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:36:46.0500 2232 WSTCODEC - ok
10:36:46.0500 2232 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
10:36:46.0515 2232 wuauserv - ok
10:36:46.0531 2232 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:36:46.0531 2232 WudfPf - ok
10:36:46.0546 2232 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:36:46.0546 2232 WudfRd - ok
10:36:46.0562 2232 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
10:36:46.0562 2232 WudfSvc - ok
10:36:46.0609 2232 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
10:36:46.0625 2232 WZCSVC - ok
10:36:46.0656 2232 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
10:36:46.0671 2232 xmlprov - ok
10:36:46.0671 2232 ================ Scan global ===============================
10:36:46.0703 2232 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
10:36:46.0750 2232 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:36:46.0765 2232 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:36:46.0781 2232 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
10:36:46.0781 2232 [Global] - ok
10:36:46.0781 2232 ================ Scan MBR ==================================
10:36:46.0796 2232 [ 91722E6BC3A2B40FF00222DCA4A3DB3E ] \Device\Harddisk0\DR0
10:36:46.0968 2232 \Device\Harddisk0\DR0 - ok
10:36:46.0968 2232 ================ Scan VBR ==================================
10:36:46.0984 2232 [ 417163F24DFAD9C717ACCDB5E9AE3CEF ] \Device\Harddisk0\DR0\Partition1
10:36:46.0984 2232 \Device\Harddisk0\DR0\Partition1 - ok
10:36:46.0984 2232 ============================================================
10:36:46.0984 2232 Scan finished
10:36:46.0984 2232 ============================================================
10:36:46.0984 2224 Detected object count: 0
10:36:46.0984 2224 Actual detected object count: 0
10:38:43.0234 2204 Deinitialize success
0 members, 0 guests, 0 anonymous users