Alikhan #1 Posted May 21, 2012 I recently installed Kaspersky and a user there said I have a suspicious driver running (dlhynz)with virtually no info on it apart from one link where they deleted it. Please help me..DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421Run by Shazia Begum at 22:42:47 on 2012-05-21Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4008.2445 [GMT 1:00].AV: Kaspersky Internet Security *Enabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}SP: Kaspersky Internet Security *Enabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}FW: Kaspersky Internet Security *Enabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}.============== Running Processes ===============.C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Program Files (x86)\IdeaCom\IDCMgr\IdcSrv.exeC:\Windows\system32\svchost.exe -k RPCSSC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\SYSTEM32\WISPTIS.EXEC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\system32\WLANExt.exeC:\Windows\system32\conhost.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeC:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exeC:\Program Files (x86)\Acer\Registration\GREGsvc.exeC:\Program Files\Acer\Acer Updater\UpdaterService.exeC:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter.exeC:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter64.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXEC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exeC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Windows\system32\WUDFHost.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskhost.exeC:\Program Files (x86)\TouchSettings\TouchPortalOBR.exeC:\Program Files\Realtek\Audio\HDA\RAVCpl64.exeC:\Program Files\Acer\Acer PowerSaver\PowerSaverTray.exeC:\Windows\System32\igfxtray.exeC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files (x86)\MicroNEXT\Common\RaUI.exeC:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXEC:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exeC:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exeC:\Windows\system32\wbem\unsecapp.exeC:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exeC:\Program Files (x86)\Common Files\Java\Java Update\jusched.exeC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonationC:\Program Files (x86)\IdeaCom\IDCMgr\IdcMgr.exeC:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\system32\taskeng.exeC:\Windows\SYSTEM32\WISPTIS.EXEC:\Program Files\Common Files\microsoft shared\ink\TabTip.exeC:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exeC:\Windows\system32\SearchIndexer.exeC:\Program Files\Freedom Scientific\JAWS\13.0\fsATProxy.exeC:\Windows\system32\SearchProtocolHost.exeC:\Windows\system32\SearchFilterHost.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtblfs.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exeC:\Windows\system32\sppsvc.exeC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exeC:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\SysWOW64\cmd.exeC:\Windows\system32\conhost.exeC:\Windows\SysWOW64\cscript.exe.============== Pseudo HJT Report ===============.uStart Page = about:blankmStart Page = hxxp://acer.msn.comBHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dllBHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dllBHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLLBHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLLBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllBHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunmRun: [YouCam Mirage] "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"mRun: [YouCam Tray] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /smRun: [ideaCom Calibration] C:\Program Files (x86)\IdeaCom\IDCMgr\StartUT.exe calibration_checkmRun: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exemRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServicesmRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraydRunOnce: [isMyWinLockerReboot] msiexec.exe /qn /x{voidguid}StartupFolder: C:\Users\SHAZIA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXEStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICRON~1.LNK - C:\Program Files (x86)\MicroNEXT\Common\RaUI.exemPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)mPolicies-system: EnableLUA = 0 (0x0)mPolicies-system: EnableUIADesktopToggle = 0 (0x0)mPolicies-system: PromptOnSecureDesktop = 0 (0x0)IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htmIE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000IE: Free YouTube Download - C:\Users\Shazia Begum\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htmIE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dllIE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dllIE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dllIE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dllIE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dllDPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cabTCP: DhcpNameServer = 192.168.0.1TCP: Interfaces\{4FCA798A-112F-40E2-8BCC-02391F1CB669} : DhcpNameServer = 192.168.0.1TCP: Interfaces\{B887273F-390E-48B5-AC65-A19E4D9A682A} : NameServer = 8.26.56.26,156.154.70.22TCP: Interfaces\{B887273F-390E-48B5-AC65-A19E4D9A682A} : DhcpNameServer = 192.168.0.1TCP: Interfaces\{D9DA8EA3-8033-4A15-9A19-E500C47C0069} : NameServer = 8.26.56.26,156.154.70.22Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLLHandler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dllSEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLLBHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO-X64: AcroIEHelperStub - No FileBHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dllBHO-X64: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dllBHO-X64: IEVkbdBHO - No FileBHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLLBHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dllBHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~4\Office14\URLREDIR.DLLBHO-X64: URLRedirectionBHO - No FileBHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dllBHO-X64: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dllBHO-X64: link filter bho - No FilemRun-x64: [YouCam Mirage] "C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe"mRun-x64: [YouCam Tray] "C:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe" /smRun-x64: [ideaCom Calibration] C:\Program Files (x86)\IdeaCom\IDCMgr\StartUT.exe calibration_checkmRun-x64: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exemRun-x64: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServicesmRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"mRun-x64: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttraySEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~4\Office14\GROOVEEX.DLL.============= SERVICES / DRIVERS ===============.R1 kl2;kl2;C:\Windows\system32\DRIVERS\kl2.sys --> C:\Windows\system32\DRIVERS\kl2.sys [?]R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys --> C:\Windows\system32\DRIVERS\klim6.sys [?]R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 202296]R2 Freedom Scientific Kernel Manager;Freedom Scientific Kernel Manager;\??\C:\Windows\system32\fsKMgr.dll --> C:\Windows\system32\fsKMgr.dll [?]R2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2011-5-30 36456]R2 IdcSrv;IDCSRV Service;C:\Program Files (x86)\IdeaCom\IDCMgr\IdcSrv.exe [2011-9-29 252928]R2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2011-7-9 244624]R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-21 654408]R2 RalinkRegistryWriter;Ralink Registry Writer;C:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter.exe [2012-1-29 75040]R2 RalinkRegistryWriter64;Ralink Registry Writer 64;C:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter64.exe [2012-1-29 210720]R2 Sentinel64;Sentinel64;C:\Windows\system32\Drivers\Sentinel64.sys --> C:\Windows\system32\Drivers\Sentinel64.sys [?]R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-9-29 2656280]R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\system32\DRIVERS\clwvd.sys --> C:\Windows\system32\DRIVERS\clwvd.sys [?]R3 fsvidmir_service;fsvidmir_service;C:\Windows\system32\DRIVERS\fsvidmir.sys --> C:\Windows\system32\DRIVERS\fsvidmir.sys [?]R3 IdcFltr;HID Touch Screen Driver;C:\Windows\system32\DRIVERS\idcfltr.sys --> C:\Windows\system32\DRIVERS\idcfltr.sys [?]R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\system32\DRIVERS\klmouflt.sys --> C:\Windows\system32\DRIVERS\klmouflt.sys [?]R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]R3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;C:\Windows\system32\DRIVERS\SNTUSB64.SYS --> C:\Windows\system32\DRIVERS\SNTUSB64.SYS [?]R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-5 257696]S3 cphs;Intel® Content Protection HECI Service;C:\Windows\SysWOW64\IntelCpHeciSvc.exe [2012-2-14 276248]S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]S3 JTVNCProxy_13.0;JTVNCProxy_13.0;C:\Program Files\Freedom Scientific\JAWS\13.0\JTVNCProxy.exe [2011-12-8 19736]S3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;C:\Windows\System32\drivers\libusb0.sys [2011-5-25 21504]S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-6-12 31125880]S3 nmwcdnsux64;Nokia USB Flashing Phone Parent;C:\Windows\system32\drivers\nmwcdnsux64.sys --> C:\Windows\system32\drivers\nmwcdnsux64.sys [?]S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]S3 PowerBrl;powerBraille System Driver;\??\C:\Windows\system32\Drivers\powerbrl.sys --> C:\Windows\system32\Drivers\powerbrl.sys [?]S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184].=============== Created Last 30 ================.2012-05-21 19:24:05 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys2012-05-21 19:24:05 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware2012-05-21 18:53:19 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{57C86BFE-0534-405D-8638-8F39654264F2}2012-05-21 18:52:42 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{E7083BA7-FA3B-49D2-A87E-B4A9BF641EE0}2012-05-21 15:29:43 -------- d-----w- C:\ProgramData\Kaspersky Lab2012-05-21 15:29:43 -------- d-----w- C:\Program Files (x86)\Kaspersky Lab2012-05-21 12:50:00 22 --sha-w- C:\Windows\90C7D912BE2316.sys2012-05-21 12:50:00 22 --sha-w- C:\Users\Shazia Begum\AppData\Roaming\Windows1569_SettingsRepository.bin2012-05-21 12:49:59 0 ----a-w- C:\Users\Shazia Begum\AppData\Local\jv16PT_temp.tmp2012-05-21 12:35:29 -------- d-----w- C:\Windows\System32\wbem\repository2012-05-21 12:07:07 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{0EB40C44-90BE-430E-86E2-EF28ACEC36E2}2012-05-20 18:49:51 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{D02485CA-6F16-4E61-AB9A-BA8617F5039D}2012-05-20 18:49:40 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{E6369319-159C-4FF5-AE36-6DB64B1D6DBD}2012-05-20 12:38:22 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{46E0ED2D-418B-4057-B52B-4E4FB97C77CF}2012-05-19 18:17:37 224048 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys2012-05-19 18:17:29 130864 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys2012-05-19 18:00:26 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{33BCE367-C430-47BE-930C-393277B7AE59}2012-05-19 18:00:16 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{054B05E5-E4EF-4D7D-9E5D-30B201532DDC}2012-05-18 14:43:15 -------- d-----w- C:\Program Files\HitmanPro2012-05-18 11:42:20 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{FFF1E625-EBA9-447E-B8A2-B7D329343671}2012-05-13 19:20:21 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{4B01BD36-E283-4C44-8C4B-75A555DFEDB5}2012-05-13 09:55:26 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{D98DAD07-1DD0-4B13-AE01-E6ABFEA35DB8}2012-05-11 15:49:35 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{812E8F69-007E-4CFA-B038-687BB8F843B2}2012-05-09 19:39:01 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{AF18BB63-3C51-4194-ABAB-FDD9FE5A9EBE}2012-05-09 19:29:35 -------- d-----w- C:\Program Files (x86)\BYOND42012-05-08 21:31:08 -------- d-----w- C:\Users\Shazia Begum\AppData\Roaming\ESET2012-05-08 21:31:08 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\ESET2012-05-08 21:20:26 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys2012-05-08 21:20:25 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe2012-05-08 21:20:25 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe2012-05-08 21:20:25 3146240 ----a-w- C:\Windows\System32\win32k.sys2012-05-08 21:20:24 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe2012-05-08 21:20:21 1544704 ----a-w- C:\Windows\System32\DWrite.dll2012-05-08 21:20:21 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll2012-05-08 21:20:14 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys2012-05-08 21:19:33 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll2012-05-08 21:19:33 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL2012-05-08 21:19:33 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll2012-05-08 21:19:33 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll2012-05-08 21:19:33 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll2012-05-08 14:55:50 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{C53092E2-E7A1-4CBE-974C-4BE097AA3D42}2012-05-04 17:54:13 73 ----a-w- C:\Windows\SysWow64\ssprs.dll2012-04-28 19:57:27 -------- d-----w- C:\Users\Shazia Begum\AppData\Roaming\EurekaLog2012-04-28 18:38:48 -------- d-----w- C:\Users\Shazia Begum\AppData\Roaming\Paoc2012-04-28 18:38:48 -------- d-----w- C:\Users\Shazia Begum\AppData\Roaming\Ekynl2012-04-25 18:48:07 -------- d-----w- C:\Users\Shazia Begum\VirtualBox VMs2012-04-25 18:47:34 -------- d-----w- C:\Users\Shazia Begum\.VirtualBox2012-04-24 19:16:00 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{7E60ED7B-A83B-409F-B448-772748B70A65}2012-04-24 16:30:15 -------- d-----w- C:\Windows\SysWow64\Adobe2012-04-24 14:45:45 -------- d-----w- C:\Program Files (x86)\uTorrent2012-04-22 20:35:48 200976 ----a-w- C:\Windows\SysWow64\drivers\tmcomm.sys2012-04-22 12:14:13 -------- d-----w- C:\Users\Shazia Begum\AppData\Local\{3D07BD89-15B8-4B11-9E69-4E045022822D}.==================== Find3M ====================.2012-05-05 16:29:16 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl2012-05-05 16:29:16 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe2012-05-05 16:29:08 8769696 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe2012-04-12 17:12:56 147248 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys2012-04-09 12:17:01 1700352 ------w- C:\Windows\SysWow64\gdiplus.dll2012-03-18 15:16:15 472808 ------w- C:\Windows\SysWow64\deployJava1.dll2012-03-01 06:46:16 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys2012-03-01 06:38:27 220672 ----a-w- C:\Windows\System32\wintrust.dll2012-03-01 06:33:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll2012-03-01 06:28:47 5120 ----a-w- C:\Windows\System32\wmi.dll2012-03-01 05:37:41 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll2012-03-01 05:33:23 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll2012-03-01 05:29:16 5120 ----a-w- C:\Windows\SysWow64\wmi.dll2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb2012-02-23 08:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe.============= FINISH: 22:43:49.15 ===============.UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.IF REQUESTED, ZIP IT UP & ATTACH IT.DDS (Ver_2011-08-26.01).Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2Install Date: 29/01/2012 14:11:20System Uptime: 21/05/2012 22:39:15 (0 hours ago).Motherboard: Acer | | Aspire Z1801Processor: Intel® Pentium® CPU G620 @ 2.60GHz | CPU 1 | 2600/100mhz.==== Disk Partitions =========================.C: is FIXED (NTFS) - 455 GiB total, 392.625 GiB free.D: is FIXED (NTFS) - 455 GiB total, 454.298 GiB free.E: is CDROM ()F: is RemovableG: is Removable.==== Disabled Device Manager Items =============.==== System Restore Points ===================.RP134: 09/05/2012 19:53:36 - Installed Anti-SpywareRP135: 15/05/2012 23:03:25 - Installed AVG 2012RP136: 15/05/2012 23:03:52 - Installed AVG 2012RP137: 19/05/2012 19:16:59 - Installed Oracle VM VirtualBox 4.1.14RP138: 19/05/2012 20:43:48 - Removed Oracle VM VirtualBox 4.1.14RP140: 21/05/2012 12:26:44 - Revo Uninstaller Pro's restore point - AVG 2012RP141: 21/05/2012 12:29:45 - Revo Uninstaller Pro's restore point - AVG 2012RP142: 21/05/2012 12:30:15 - Removed AVG 2012RP143: 21/05/2012 12:34:32 - Removed AVG 2012RP144: 21/05/2012 13:28:42 - Revo Uninstaller Pro's restore point - Kaspersky Internet Security 2012RP145: 21/05/2012 13:32:16 - Revo Uninstaller Pro's restore point - Kaspersky Internet Security 2012RP146: 21/05/2012 13:56:29 - Revo Uninstaller Pro's restore point - jv16 PowerTools 2012.==== Installed Programs ======================.???? ??? Windows Live???? Windows Live????? Windows Live?????? ??????? ?? Windows Live???????? ?????????? Windows Live?????????? Windows Live??????????? ?? Windows LiveAcer eRecovery ManagementAcer GamesAcer PowerSaverAcer RegistrationAcer ScreenSaverAcer UpdaterAdobe Reader X (10.1.3) MUIAdobe Shockwave Player 11.6Agatha Christie - Death on the NileµTorrentBejeweled 2 DeluxeBuild Your Own Net Dream (remove only)Chuzzle DeluxeCisco EAP-FAST ModuleCisco LEAP ModuleCisco PEAP ModuleCrazy Chicken Kart 2CyberLink YouCamD3DX10Definition Update for Microsoft Office 2010 (KB982726) 32-Bit EditionFATEFinal Drive: NitroFotogalerija Windows LiveFree YouTube Download version 3.1.22.319Freedom Scientific OcrFreedom Scientific OmniPageFreedom Scientific Synthesizer EloquenceGaleria de Fotografias do Windows LiveGaleria fotografii uslugi Windows LiveGaleria fotogràfica del Windows LiveGalerie de photos Windows LiveGalerie foto Windows LiveGalería fotográfica de Windows LiveGoogle ChromeHotkey UtilityIdeaCom Touch Screen 3.3.0000.26Identity CardInsaniquarium DeluxeIntel® Control CenterIntel® Management Engine ComponentsIntel® Processor GraphicsJava Auto UpdaterJava 6 Update 31Jewel Match 3Jewel Quest SolitaireJohn Deere Drive GreenJunk Mail filter updateK-Lite Codec Pack 8.2.0 (Basic)Kaspersky Internet Security 2012Malwarebytes Anti-Malware version 1.61.0.1400Mesh RuntimeMicroNEXT MicroNEXT USB WirelessMicrosoft Office 2010 Service Pack 1 (SP1)Microsoft Office Access MUI (English) 2010Microsoft Office Access Setup Metadata MUI (English) 2010Microsoft Office Excel MUI (English) 2010Microsoft Office Groove MUI (English) 2010Microsoft Office InfoPath MUI (English) 2010Microsoft Office OneNote MUI (English) 2010Microsoft Office Outlook ConnectorMicrosoft Office Outlook MUI (English) 2010Microsoft Office PowerPoint MUI (English) 2010Microsoft Office Professional Plus 2010Microsoft Office Proof (English) 2010Microsoft Office Proof (French) 2010Microsoft Office Proof (Spanish) 2010Microsoft Office Proofing (English) 2010Microsoft Office Publisher MUI (English) 2010Microsoft Office Shared MUI (English) 2010Microsoft Office Shared Setup Metadata MUI (English) 2010Microsoft Office Word MUI (English) 2010Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bitMicrosoft SQL Server 2005 Compact Edition [ENU]Microsoft Visual C++ 2005 RedistributableMicrosoft Visual C++ 2008 Redistributable - x86 9.0.30729.17Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219MSVCRTMSVCRT_amd64MSXML 4.0 SP2 (KB954430)MSXML 4.0 SP2 (KB973688)Mystery of Mortlake MansionPenguins!Plants vs. Zombies - Game of the YearPoczta uslugi Windows LivePodstawowe programy Windows LivePolar BowlerPošta Windows LiveRaccolta foto di Windows LiveRealNetworks - Microsoft Visual C++ 2008 RuntimeRealPlayerRealtek Ethernet Controller DriverRealtek High Definition Audio DriverRealUpgrade 1.1S?????? f?t???af??? t?? Windows LiveSecurity Update for Microsoft .NET Framework 4 Client Profile (KB2518870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2553091)Security Update for Microsoft Office 2010 (KB2553096)Security Update for Microsoft Office 2010 (KB2553371) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2589320) 32-Bit EditionSecurity Update for Microsoft Office 2010 (KB2598039) 32-Bit EditionSecurity Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit EditionSecurity Update for Microsoft SharePoint Workspace 2010 (KB2566445)Security Update for Microsoft Visio Viewer 2010 (KB2597981) 32-Bit EditionSentinel System Driver Installer 7.5.0Slingo DeluxeSopCast 3.4.8swMSMTorchlightTouchSettingsUpdate for Microsoft .NET Framework 4 Client Profile (KB2468871)Update for Microsoft .NET Framework 4 Client Profile (KB2533523)Update for Microsoft .NET Framework 4 Client Profile (KB2600217)Update for Microsoft Office 2010 (KB2494150)Update for Microsoft Office 2010 (KB2553065)Update for Microsoft Office 2010 (KB2553092)Update for Microsoft Office 2010 (KB2553181) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2553267) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2553270) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2553310) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2553385) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2566458)Update for Microsoft Office 2010 (KB2596964) 32-Bit EditionUpdate for Microsoft Office 2010 (KB2597091) 32-Bit EditionUpdate for Microsoft OneNote 2010 (KB2553290) 32-Bit EditionUpdate for Microsoft OneNote 2010 (KB2589345) 32-Bit EditionUpdate for Microsoft Outlook 2010 (KB2553248) 32-Bit EditionUpdate for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit EditionUpdate Installer for WildTangent Games AppVeetle TVVirtual Villagers 4 - The Tree of LifeVisual Studio 2008 x64 RedistributablesWedding DashWildTangent Games App (Acer Games)Windows LiveWindows Live ???Windows Live ????Windows Live Argazki GaleriaWindows Live Communications PlatformWindows Live EssentialsWindows Live FotótárWindows Live FotogalerieWindows Live FotogalleriWindows Live FotogalériaWindows Live Fotograf GalerisiWindows Live Galeria de FotosWindows Live Galerija fotografijaWindows Live InstallerWindows Live MailWindows Live MeshWindows Live MessengerWindows Live Movie MakerWindows Live Photo CommonWindows Live Photo GalleryWindows Live PIMT PlatformWindows Live SOXEWindows Live SOXE DefinitionsWindows Live Temel ParçalarWindows Live UX PlatformWindows Live UX Platform Language PackWindows Live WriterWindows Live Writer ResourcesWindows Liven asennustyökaluWindows Liven sähköpostiWindows Liven valokuvavalikoimaZuma Deluxe.==== Event Viewer Messages From Past Week ========.21/05/2012 22:39:36, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: dlhynz raeehd21/05/2012 22:39:33, Error: Service Control Manager [7023] - The Windows Defender service terminated with the following error: The specified module could not be found.21/05/2012 16:15:05, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.21/05/2012 16:15:05, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.21/05/2012 16:14:50, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}21/05/2012 16:14:50, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}21/05/2012 16:14:42, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.21/05/2012 16:14:42, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.21/05/2012 14:02:47, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff960000ea9a2, 0xfffff880029051f0, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 052112-23290-01.21/05/2012 13:38:24, Error: Service Control Manager [7030] - The ESET Uninstaller Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.21/05/2012 13:37:32, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}21/05/2012 13:37:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}21/05/2012 13:37:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}21/05/2012 13:37:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}21/05/2012 13:37:30, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}21/05/2012 13:37:25, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}21/05/2012 13:37:10, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache dlhynz NetBIOS NetBT nsiproxy Psched raeehd rdbss SASDIFSV SASKUTIL spldr tdx vwififlt Wanarpv6 WfpLwf ws2ifsl21/05/2012 13:37:10, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.21/05/2012 13:37:10, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:10, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:10, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:10, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:09, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.21/05/2012 13:37:09, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.21/05/2012 13:37:09, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.21/05/2012 13:37:09, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.21/05/2012 13:37:09, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.19/05/2012 20:36:14, Error: bowser [8003] - The master browser has received a server announcement from the computer DON-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{E6C779D3-9F68-4B58-8319-702DB6A4DD7A}. The master browser is stopping or an election is being forced..==== End Of File ===========================Malwarebytes Anti-Malware (PRO) 1.61.0.1400www.malwarebytes.orgDatabase version: v2012.05.21.04Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421Shazia Begum :: SHAZIABEGUM-PC [administrator]Protection: Enabled21/05/2012 22:45:00mbam-log-2012-05-21 (22-45-00).txtScan type: Quick scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 210867Time elapsed: 2 minute(s), 2 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end) Share this post Link to post Share on other sites
D-FRED-BROWN #2 Posted May 21, 2012 Hello All821 and welcome to Malwarebytes! I am D-FRED-BROWN and I will be helping you. Please print or save this topic: it will make it easier for you to follow the instructions and complete all of the necessary steps.-------------Please download to your Desktop:TDSSKiller.zip from here and extract it (right click on it => "Extract here").>>> TDSSKiller: Double-click on TDSSKiller.exe to run the application.Click on the Start Scan button and wait for the scan and disinfection process to be over.If an infected file is detected, the default action will be Cure, click on Continue If a suspicious file is detected, the default action will be Skip, click on Continue If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.In your next reply, please include the following (you may need to use two posts to get it all in):TDSSKiller_log.txthow the PC is running now?-------------Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:http://www.bleepingc...to-use-combofix* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Please go here to see a list of programs that should be disabled.**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall** Please include the C:\ComboFix.txt in your next reply for further review.Also, please let me know if any problems still remain.-------------Please download Security Check by screen317 from here or here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document.-------------In your next reply, please include:TDSSKiller logfileC:\ComboFix.txtSecurity Check checkup.txtHow is your computer running now? Share this post Link to post Share on other sites
Alikhan #3 Posted May 22, 2012 Computer is running alittle better now. There is still some slowdown and connection to random survey sites.11:35:43.0354 0988 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:1611:35:43.0529 0988 ============================================================11:35:43.0529 0988 Current date / time: 2012/05/22 11:35:43.052911:35:43.0529 0988 SystemInfo:11:35:43.0529 0988 11:35:43.0529 0988 OS Version: 6.1.7601 ServicePack: 1.011:35:43.0529 0988 Product type: Workstation11:35:43.0529 0988 ComputerName: SHAZIABEGUM-PC11:35:43.0529 0988 UserName: Shazia Begum11:35:43.0529 0988 Windows directory: C:\Windows11:35:43.0529 0988 System windows directory: C:\Windows11:35:43.0529 0988 Running under WOW6411:35:43.0529 0988 Processor architecture: Intel x6411:35:43.0529 0988 Number of processors: 211:35:43.0529 0988 Page size: 0x100011:35:43.0529 0988 Boot type: Normal boot11:35:43.0529 0988 ============================================================11:35:44.0595 0988 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x0000004011:35:44.0610 0988 ============================================================11:35:44.0610 0988 \Device\Harddisk0\DR0:11:35:44.0610 0988 MBR partitions:11:35:44.0610 0988 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2AF8800, BlocksNum 0x3200011:35:44.0610 0988 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2B2A800, BlocksNum 0x38DEC80011:35:44.0610 0988 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3B917000, BlocksNum 0x38DEF5B011:35:44.0610 0988 ============================================================11:35:44.0626 0988 C: <-> \Device\Harddisk0\DR0\Partition111:35:44.0673 0988 D: <-> \Device\Harddisk0\DR0\Partition211:35:44.0673 0988 ============================================================11:35:44.0673 0988 Initialize success11:35:44.0673 0988 ============================================================11:35:46.0034 4996 ============================================================11:35:46.0034 4996 Scan started11:35:46.0034 4996 Mode: Manual; 11:35:46.0034 4996 ============================================================11:35:46.0939 4996 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys11:35:46.0939 4996 1394ohci - ok11:35:46.0970 4996 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys11:35:46.0970 4996 ACPI - ok11:35:46.0986 4996 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys11:35:46.0986 4996 AcpiPmi - ok11:35:47.0111 4996 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe11:35:47.0111 4996 AdobeARMservice - ok11:35:47.0204 4996 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe11:35:47.0204 4996 AdobeFlashPlayerUpdateSvc - ok11:35:47.0251 4996 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys11:35:47.0267 4996 adp94xx - ok11:35:47.0298 4996 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys11:35:47.0298 4996 adpahci - ok11:35:47.0329 4996 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys11:35:47.0329 4996 adpu320 - ok11:35:47.0360 4996 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll11:35:47.0360 4996 AeLookupSvc - ok11:35:47.0407 4996 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys11:35:47.0423 4996 AFD - ok11:35:47.0438 4996 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys11:35:47.0438 4996 agp440 - ok11:35:47.0454 4996 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe11:35:47.0454 4996 ALG - ok11:35:47.0485 4996 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys11:35:47.0485 4996 aliide - ok11:35:47.0501 4996 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys11:35:47.0501 4996 amdide - ok11:35:47.0516 4996 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys11:35:47.0532 4996 AmdK8 - ok11:35:47.0547 4996 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys11:35:47.0547 4996 AmdPPM - ok11:35:47.0579 4996 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys11:35:47.0579 4996 amdsata - ok11:35:47.0594 4996 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys11:35:47.0610 4996 amdsbs - ok11:35:47.0610 4996 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys11:35:47.0610 4996 amdxata - ok11:35:47.0625 4996 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys11:35:47.0625 4996 AppID - ok11:35:47.0641 4996 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll11:35:47.0641 4996 AppIDSvc - ok11:35:47.0657 4996 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll11:35:47.0657 4996 Appinfo - ok11:35:47.0672 4996 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys11:35:47.0672 4996 arc - ok11:35:47.0688 4996 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys11:35:47.0688 4996 arcsas - ok11:35:47.0735 4996 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys11:35:47.0735 4996 AsyncMac - ok11:35:47.0750 4996 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys11:35:47.0750 4996 atapi - ok11:35:47.0781 4996 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll11:35:47.0781 4996 AudioEndpointBuilder - ok11:35:47.0797 4996 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll11:35:47.0797 4996 AudioSrv - ok11:35:47.0937 4996 AVP (2718dc27571bd1e37813f5759d2dc118) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe11:35:47.0937 4996 AVP - ok11:35:47.0969 4996 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll11:35:47.0984 4996 AxInstSV - ok11:35:48.0015 4996 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys11:35:48.0031 4996 b06bdrv - ok11:35:48.0062 4996 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys11:35:48.0062 4996 b57nd60a - ok11:35:48.0093 4996 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll11:35:48.0093 4996 BDESVC - ok11:35:48.0109 4996 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys11:35:48.0109 4996 Beep - ok11:35:48.0156 4996 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll11:35:48.0171 4996 BFE - ok11:35:48.0234 4996 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll11:35:48.0249 4996 BITS - ok11:35:48.0281 4996 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys11:35:48.0281 4996 blbdrive - ok11:35:48.0296 4996 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys11:35:48.0296 4996 bowser - ok11:35:48.0312 4996 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys11:35:48.0312 4996 BrFiltLo - ok11:35:48.0327 4996 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys11:35:48.0327 4996 BrFiltUp - ok11:35:48.0359 4996 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys11:35:48.0359 4996 BridgeMP - ok11:35:48.0374 4996 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll11:35:48.0374 4996 Browser - ok11:35:48.0390 4996 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys11:35:48.0390 4996 Brserid - ok11:35:48.0405 4996 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys11:35:48.0405 4996 BrSerWdm - ok11:35:48.0421 4996 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys11:35:48.0421 4996 BrUsbMdm - ok11:35:48.0437 4996 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys11:35:48.0437 4996 BrUsbSer - ok11:35:48.0452 4996 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys11:35:48.0452 4996 BTHMODEM - ok11:35:48.0483 4996 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll11:35:48.0483 4996 bthserv - ok11:35:48.0515 4996 catchme - ok11:35:48.0530 4996 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys11:35:48.0530 4996 cdfs - ok11:35:48.0561 4996 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys11:35:48.0561 4996 cdrom - ok11:35:48.0593 4996 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll11:35:48.0593 4996 CertPropSvc - ok11:35:48.0624 4996 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys11:35:48.0624 4996 circlass - ok11:35:48.0655 4996 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys11:35:48.0671 4996 CLFS - ok11:35:48.0725 4996 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe11:35:48.0726 4996 clr_optimization_v2.0.50727_32 - ok11:35:48.0765 4996 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe11:35:48.0767 4996 clr_optimization_v2.0.50727_64 - ok11:35:48.0811 4996 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe11:35:48.0812 4996 clr_optimization_v4.0.30319_32 - ok11:35:48.0827 4996 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe11:35:48.0828 4996 clr_optimization_v4.0.30319_64 - ok11:35:48.0877 4996 clwvd (e13a438f9e51dd034730678e33b73290) C:\Windows\system32\DRIVERS\clwvd.sys11:35:48.0878 4996 clwvd - ok11:35:48.0898 4996 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys11:35:48.0900 4996 CmBatt - ok11:35:48.0905 4996 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys11:35:48.0907 4996 cmdide - ok11:35:48.0961 4996 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys11:35:48.0965 4996 CNG - ok11:35:48.0975 4996 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys11:35:48.0977 4996 Compbatt - ok11:35:49.0006 4996 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys11:35:49.0007 4996 CompositeBus - ok11:35:49.0020 4996 COMSysApp - ok11:35:49.0115 4996 cphs (df3e8c2c443d3618260dff5705ce2df5) C:\Windows\SysWow64\IntelCpHeciSvc.exe11:35:49.0117 4996 cphs - ok11:35:49.0125 4996 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys11:35:49.0212 4996 crcdisk - ok11:35:49.0244 4996 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll11:35:49.0245 4996 CryptSvc - ok11:35:49.0290 4996 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll11:35:49.0294 4996 DcomLaunch - ok11:35:49.0317 4996 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll11:35:49.0321 4996 defragsvc - ok11:35:49.0341 4996 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys11:35:49.0342 4996 DfsC - ok11:35:49.0362 4996 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll11:35:49.0366 4996 Dhcp - ok11:35:49.0380 4996 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys11:35:49.0381 4996 discache - ok11:35:49.0421 4996 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys11:35:49.0422 4996 Disk - ok11:35:49.0428 4996 dlhynz - ok11:35:49.0450 4996 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll11:35:49.0453 4996 Dnscache - ok11:35:49.0478 4996 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll11:35:49.0481 4996 dot3svc - ok11:35:49.0490 4996 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll11:35:49.0492 4996 DPS - ok11:35:49.0531 4996 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys11:35:49.0533 4996 drmkaud - ok11:35:49.0599 4996 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys11:35:49.0604 4996 DXGKrnl - ok11:35:49.0650 4996 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll11:35:49.0652 4996 EapHost - ok11:35:49.0776 4996 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys11:35:49.0837 4996 ebdrv - ok11:35:49.0925 4996 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe11:35:49.0927 4996 EFS - ok11:35:50.0007 4996 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe11:35:50.0011 4996 ehRecvr - ok11:35:50.0030 4996 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe11:35:50.0031 4996 ehSched - ok11:35:50.0073 4996 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys11:35:50.0087 4996 elxstor - ok11:35:50.0113 4996 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys11:35:50.0114 4996 ErrDev - ok11:35:50.0167 4996 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll11:35:50.0170 4996 EventSystem - ok11:35:50.0196 4996 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys11:35:50.0199 4996 exfat - ok11:35:50.0215 4996 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys11:35:50.0218 4996 fastfat - ok11:35:50.0273 4996 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe11:35:50.0295 4996 Fax - ok11:35:50.0310 4996 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys11:35:50.0311 4996 fdc - ok11:35:50.0318 4996 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll11:35:50.0320 4996 fdPHost - ok11:35:50.0334 4996 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll11:35:50.0336 4996 FDResPub - ok11:35:50.0344 4996 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys11:35:50.0345 4996 FileInfo - ok11:35:50.0353 4996 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys11:35:50.0355 4996 Filetrace - ok11:35:50.0365 4996 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys11:35:50.0367 4996 flpydisk - ok11:35:50.0387 4996 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys11:35:50.0390 4996 FltMgr - ok11:35:50.0450 4996 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll11:35:50.0468 4996 FontCache - ok11:35:50.0527 4996 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe11:35:50.0528 4996 FontCache3.0.0.0 - ok11:35:50.0563 4996 Freedom Scientific Kernel Manager (575d36a0b7fa467367af92d10d04f4b5) C:\Windows\system32\fsKMgr.dll11:35:50.0563 4996 Freedom Scientific Kernel Manager - ok11:35:50.0589 4996 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys11:35:50.0591 4996 FsDepends - ok11:35:50.0621 4996 fsvidmir_service (4c93b7ce0df37059517f3c75ae59daae) C:\Windows\system32\DRIVERS\fsvidmir.sys11:35:50.0622 4996 fsvidmir_service - ok11:35:50.0654 4996 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys11:35:50.0654 4996 Fs_Rec - ok11:35:50.0666 4996 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys11:35:50.0668 4996 fvevol - ok11:35:50.0698 4996 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys11:35:50.0700 4996 gagp30kx - ok11:35:50.0759 4996 GamesAppService (c403c5db49a0f9aaf4f2128edc0106d8) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe11:35:50.0760 4996 GamesAppService - ok11:35:50.0801 4996 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll11:35:50.0819 4996 gpsvc - ok11:35:50.0875 4996 GREGService (c9b2d1d3f86fd3673ef847def73b6f9e) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe11:35:50.0876 4996 GREGService - ok11:35:50.0884 4996 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys11:35:50.0885 4996 hcw85cir - ok11:35:50.0918 4996 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys11:35:50.0922 4996 HdAudAddService - ok11:35:50.0940 4996 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys11:35:50.0942 4996 HDAudBus - ok11:35:50.0954 4996 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys11:35:50.0955 4996 HidBatt - ok11:35:50.0976 4996 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys11:35:50.0978 4996 HidBth - ok11:35:50.0989 4996 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys11:35:50.0990 4996 HidIr - ok11:35:51.0001 4996 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll11:35:51.0003 4996 hidserv - ok11:35:51.0028 4996 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys11:35:51.0029 4996 HidUsb - ok11:35:51.0048 4996 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll11:35:51.0050 4996 hkmsvc - ok11:35:51.0086 4996 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll11:35:51.0090 4996 HomeGroupListener - ok11:35:51.0118 4996 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll11:35:51.0120 4996 HomeGroupProvider - ok11:35:51.0134 4996 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys11:35:51.0136 4996 HpSAMD - ok11:35:51.0194 4996 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys11:35:51.0213 4996 HTTP - ok11:35:51.0256 4996 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys11:35:51.0256 4996 hwpolicy - ok11:35:51.0282 4996 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys11:35:51.0284 4996 i8042prt - ok11:35:51.0335 4996 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys11:35:51.0340 4996 iaStorV - ok11:35:51.0386 4996 IdcFltr (83c749c7d723cfc852b7430044affd4f) C:\Windows\system32\DRIVERS\idcfltr.sys11:35:51.0387 4996 IdcFltr - ok11:35:51.0468 4996 IdcSrv (c9811ea9d8e6e2b6cb76a435ad8ac4f8) C:\Program Files (x86)\IdeaCom\IDCMgr\IdcSrv.exe11:35:51.0471 4996 IdcSrv - ok11:35:51.0544 4996 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe11:35:51.0549 4996 idsvc - ok11:35:51.0961 4996 igfx (276ee9cdab16c50e1df0e4cefa882f5f) C:\Windows\system32\DRIVERS\igdkmd64.sys11:35:52.0182 4996 igfx - ok11:35:52.0267 4996 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys11:35:52.0268 4996 iirsp - ok11:35:52.0331 4996 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll11:35:52.0347 4996 IKEEXT - ok11:35:52.0514 4996 IntcAzAudAddService (0b21b66574e5478fa10cca2d36694c2d) C:\Windows\system32\drivers\RTKVHD64.sys11:35:52.0554 4996 IntcAzAudAddService - ok11:35:52.0593 4996 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys11:35:52.0594 4996 intelide - ok11:35:52.0614 4996 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys11:35:52.0615 4996 intelppm - ok11:35:52.0627 4996 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll11:35:52.0630 4996 IPBusEnum - ok11:35:52.0655 4996 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys11:35:52.0657 4996 IpFilterDriver - ok11:35:52.0703 4996 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll11:35:52.0713 4996 iphlpsvc - ok11:35:52.0734 4996 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys11:35:52.0736 4996 IPMIDRV - ok11:35:52.0753 4996 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys11:35:52.0755 4996 IPNAT - ok11:35:52.0770 4996 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys11:35:52.0771 4996 IRENUM - ok11:35:52.0797 4996 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys11:35:52.0799 4996 isapnp - ok11:35:52.0826 4996 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys11:35:52.0830 4996 iScsiPrt - ok11:35:52.0935 4996 JTVNCProxy_13.0 (2ce0c9a1dfec2e57151983815d6e5c25) C:\Program Files\Freedom Scientific\JAWS\13.0\JTVNCProxy.exe11:35:52.0936 4996 JTVNCProxy_13.0 - ok11:35:52.0957 4996 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys11:35:52.0958 4996 kbdclass - ok11:35:52.0976 4996 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys11:35:52.0977 4996 kbdhid - ok11:35:53.0004 4996 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe11:35:53.0005 4996 KeyIso - ok11:35:53.0053 4996 KL1 (e656fe10d6d27794afa08136685a69e8) C:\Windows\system32\DRIVERS\kl1.sys11:35:53.0059 4996 KL1 - ok11:35:53.0100 4996 kl2 (d865dd8b0448e3f963d68c04c532858f) C:\Windows\system32\DRIVERS\kl2.sys11:35:53.0101 4996 kl2 - ok11:35:53.0163 4996 KLIF (c7d4f357c482dd37e2b05f34093b7b0c) C:\Windows\system32\DRIVERS\klif.sys11:35:53.0195 4996 KLIF - ok11:35:53.0220 4996 KLIM6 (89fb5a33d7171b6d84f5eb721d5055e1) C:\Windows\system32\DRIVERS\klim6.sys11:35:53.0221 4996 KLIM6 - ok11:35:53.0241 4996 klmouflt (9468d07e91ba136d82415f5dfc1fe168) C:\Windows\system32\DRIVERS\klmouflt.sys11:35:53.0242 4996 klmouflt - ok11:35:53.0262 4996 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys11:35:53.0264 4996 KSecDD - ok11:35:53.0285 4996 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys11:35:53.0287 4996 KSecPkg - ok11:35:53.0300 4996 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys11:35:53.0301 4996 ksthunk - ok11:35:53.0374 4996 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll11:35:53.0379 4996 KtmRm - ok11:35:53.0404 4996 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll11:35:53.0408 4996 LanmanServer - ok11:35:53.0428 4996 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll11:35:53.0431 4996 LanmanWorkstation - ok11:35:53.0459 4996 libusb0 (acec35f181075b20a5ef4a71958b13df) C:\Windows\system32\drivers\libusb0.sys11:35:53.0460 4996 libusb0 - ok11:35:53.0533 4996 Live Updater Service (b705c7097f9a0ec941d02dce7c7d426c) C:\Program Files\Acer\Acer Updater\UpdaterService.exe11:35:53.0535 4996 Live Updater Service - ok11:35:53.0560 4996 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys11:35:53.0561 4996 lltdio - ok11:35:53.0593 4996 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll11:35:53.0593 4996 lltdsvc - ok11:35:53.0608 4996 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll11:35:53.0608 4996 lmhosts - ok11:35:53.0686 4996 LMS (e7859ba062db5e23c6dd34ad66b09f50) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe11:35:53.0686 4996 LMS - ok11:35:53.0717 4996 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys11:35:53.0733 4996 LSI_FC - ok11:35:53.0749 4996 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys11:35:53.0749 4996 LSI_SAS - ok11:35:53.0764 4996 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys11:35:53.0764 4996 LSI_SAS2 - ok11:35:53.0780 4996 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys11:35:53.0780 4996 LSI_SCSI - ok11:35:53.0795 4996 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys11:35:53.0811 4996 luafv - ok11:35:53.0842 4996 MBAMProtector (dbc08862a71459e74f7538b432c114cc) C:\Windows\system32\drivers\mbam.sys11:35:53.0842 4996 MBAMProtector - ok11:35:53.0889 4996 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe11:35:53.0889 4996 MBAMService - ok11:35:53.0920 4996 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll11:35:53.0920 4996 Mcx2Svc - ok11:35:53.0936 4996 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys11:35:53.0936 4996 megasas - ok11:35:53.0967 4996 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys11:35:53.0967 4996 MegaSR - ok11:35:54.0014 4996 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys11:35:54.0014 4996 MEIx64 - ok11:35:54.0076 4996 Microsoft SharePoint Workspace Audit Service - ok11:35:54.0092 4996 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll11:35:54.0092 4996 MMCSS - ok11:35:54.0107 4996 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys11:35:54.0107 4996 Modem - ok11:35:54.0139 4996 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys11:35:54.0139 4996 monitor - ok11:35:54.0170 4996 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys11:35:54.0170 4996 mouclass - ok11:35:54.0185 4996 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys11:35:54.0185 4996 mouhid - ok11:35:54.0295 4996 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys11:35:54.0341 4996 mountmgr - ok11:35:54.0451 4996 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys11:35:54.0466 4996 mpio - ok11:35:54.0482 4996 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys11:35:54.0482 4996 mpsdrv - ok11:35:54.0513 4996 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll11:35:54.0529 4996 MpsSvc - ok11:35:54.0544 4996 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys11:35:54.0544 4996 MRxDAV - ok11:35:54.0591 4996 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys11:35:54.0591 4996 mrxsmb - ok11:35:54.0607 4996 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys11:35:54.0607 4996 mrxsmb10 - ok11:35:54.0622 4996 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys11:35:54.0622 4996 mrxsmb20 - ok11:35:54.0638 4996 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys11:35:54.0638 4996 msahci - ok11:35:54.0669 4996 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys11:35:54.0669 4996 msdsm - ok11:35:54.0685 4996 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe11:35:54.0685 4996 MSDTC - ok11:35:54.0716 4996 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys11:35:54.0716 4996 Msfs - ok11:35:54.0716 4996 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys11:35:54.0716 4996 mshidkmdf - ok11:35:54.0731 4996 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys11:35:54.0731 4996 msisadrv - ok11:35:54.0763 4996 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll11:35:54.0763 4996 MSiSCSI - ok11:35:54.0778 4996 msiserver - ok11:35:54.0794 4996 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys11:35:54.0794 4996 MSKSSRV - ok11:35:54.0794 4996 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys11:35:54.0794 4996 MSPCLOCK - ok11:35:54.0809 4996 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys11:35:54.0809 4996 MSPQM - ok11:35:54.0841 4996 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys11:35:54.0841 4996 MsRPC - ok11:35:54.0856 4996 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys11:35:54.0856 4996 mssmbios - ok11:35:54.0856 4996 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys11:35:54.0856 4996 MSTEE - ok11:35:54.0903 4996 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys11:35:54.0934 4996 MTConfig - ok11:35:54.0981 4996 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys11:35:54.0981 4996 Mup - ok11:35:55.0028 4996 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll11:35:55.0028 4996 napagent - ok11:35:55.0075 4996 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys11:35:55.0090 4996 NativeWifiP - ok11:35:55.0121 4996 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys11:35:55.0137 4996 NDIS - ok11:35:55.0137 4996 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys11:35:55.0137 4996 NdisCap - ok11:35:55.0153 4996 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys11:35:55.0168 4996 NdisTapi - ok11:35:55.0168 4996 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys11:35:55.0168 4996 Ndisuio - ok11:35:55.0184 4996 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys11:35:55.0184 4996 NdisWan - ok11:35:55.0199 4996 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys11:35:55.0199 4996 NDProxy - ok11:35:55.0215 4996 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys11:35:55.0215 4996 NetBIOS - ok11:35:55.0231 4996 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys11:35:55.0231 4996 NetBT - ok11:35:55.0246 4996 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe11:35:55.0246 4996 Netlogon - ok11:35:55.0277 4996 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll11:35:55.0277 4996 Netman - ok11:35:55.0293 4996 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll11:35:55.0309 4996 netprofm - ok11:35:55.0371 4996 netr28ux (eed1fbde98cf5f6d5c0c5b27ab1f68ec) C:\Windows\system32\DRIVERS\netr28ux.sys11:35:55.0387 4996 netr28ux - ok11:35:55.0434 4996 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe11:35:55.0434 4996 NetTcpPortSharing - ok11:35:55.0465 4996 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys11:35:55.0465 4996 nfrd960 - ok11:35:55.0496 4996 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll11:35:55.0496 4996 NlaSvc - ok11:35:55.0527 4996 nmwcdnsux64 (9573223e205907247ae6d948e3453770) C:\Windows\system32\drivers\nmwcdnsux64.sys11:35:55.0527 4996 nmwcdnsux64 - ok11:35:55.0543 4996 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys11:35:55.0543 4996 Npfs - ok11:35:55.0543 4996 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll11:35:55.0543 4996 nsi - ok11:35:55.0558 4996 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys11:35:55.0558 4996 nsiproxy - ok11:35:55.0652 4996 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys11:35:55.0652 4996 Ntfs - ok11:35:55.0714 4996 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys11:35:55.0714 4996 Null - ok11:35:55.0761 4996 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys11:35:55.0761 4996 nvraid - ok11:35:55.0792 4996 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys11:35:55.0792 4996 nvstor - ok11:35:55.0824 4996 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys11:35:55.0824 4996 nv_agp - ok11:35:55.0839 4996 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys11:35:55.0839 4996 ohci1394 - ok11:35:55.0933 4996 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE11:35:55.0933 4996 ose - ok11:35:56.0151 4996 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE11:35:56.0182 4996 osppsvc - ok11:35:56.0245 4996 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll11:35:56.0260 4996 p2pimsvc - ok11:35:56.0276 4996 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll11:35:56.0292 4996 p2psvc - ok11:35:56.0323 4996 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys11:35:56.0323 4996 Parport - ok11:35:56.0354 4996 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys11:35:56.0354 4996 partmgr - ok11:35:56.0370 4996 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll11:35:56.0385 4996 PcaSvc - ok11:35:56.0401 4996 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys11:35:56.0401 4996 pci - ok11:35:56.0401 4996 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys11:35:56.0416 4996 pciide - ok11:35:56.0432 4996 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys11:35:56.0432 4996 pcmcia - ok11:35:56.0448 4996 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys11:35:56.0448 4996 pcw - ok11:35:56.0494 4996 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys11:35:56.0526 4996 PEAUTH - ok11:35:56.0572 4996 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe11:35:56.0572 4996 PerfHost - ok11:35:56.0650 4996 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll11:35:56.0666 4996 pla - ok11:35:56.0713 4996 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll11:35:56.0713 4996 PlugPlay - ok11:35:56.0713 4996 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll11:35:56.0728 4996 PNRPAutoReg - ok11:35:56.0744 4996 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll11:35:56.0744 4996 PNRPsvc - ok11:35:56.0791 4996 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll11:35:56.0806 4996 PolicyAgent - ok11:35:56.0838 4996 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll11:35:56.0853 4996 Power - ok11:35:56.0916 4996 PowerBrl (c6b37e8e347bf175027ec0ba0daf06b9) C:\Windows\system32\Drivers\powerbrl.sys11:35:56.0916 4996 PowerBrl - ok11:35:56.0962 4996 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys11:35:56.0962 4996 PptpMiniport - ok11:35:56.0978 4996 PQAWRwa - ok11:35:56.0994 4996 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys11:35:56.0994 4996 Processor - ok11:35:57.0025 4996 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll11:35:57.0025 4996 ProfSvc - ok11:35:57.0040 4996 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe11:35:57.0040 4996 ProtectedStorage - ok11:35:57.0056 4996 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys11:35:57.0056 4996 Psched - ok11:35:57.0150 4996 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys11:35:57.0181 4996 ql2300 - ok11:35:57.0274 4996 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys11:35:57.0274 4996 ql40xx - ok11:35:57.0306 4996 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll11:35:57.0306 4996 QWAVE - ok11:35:57.0321 4996 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys11:35:57.0321 4996 QWAVEdrv - ok11:35:57.0337 4996 raeehd - ok11:35:57.0400 4996 RalinkRegistryWriter (81bebbffe45855b7faf204c517fbeef1) C:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter.exe11:35:57.0400 4996 RalinkRegistryWriter - ok11:35:57.0420 4996 RalinkRegistryWriter64 (0878786c69b92e2a239b94f96f2aa963) C:\Program Files (x86)\MicroNEXT\Common\RalinkRegistryWriter64.exe11:35:57.0430 4996 RalinkRegistryWriter64 - ok11:35:57.0440 4996 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys11:35:57.0440 4996 RasAcd - ok11:35:57.0470 4996 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys11:35:57.0470 4996 RasAgileVpn - ok11:35:57.0486 4996 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll11:35:57.0486 4996 RasAuto - ok11:35:57.0501 4996 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys11:35:57.0501 4996 Rasl2tp - ok11:35:57.0532 4996 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll11:35:57.0548 4996 RasMan - ok11:35:57.0579 4996 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys11:35:57.0579 4996 RasPppoe - ok11:35:57.0595 4996 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys11:35:57.0595 4996 RasSstp - ok11:35:57.0626 4996 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys11:35:57.0626 4996 rdbss - ok11:35:57.0642 4996 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys11:35:57.0642 4996 rdpbus - ok11:35:57.0642 4996 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys11:35:57.0642 4996 RDPCDD - ok11:35:57.0673 4996 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys11:35:57.0673 4996 RDPENCDD - ok11:35:57.0688 4996 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys11:35:57.0688 4996 RDPREFMP - ok11:35:57.0704 4996 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys11:35:57.0704 4996 RDPWD - ok11:35:57.0735 4996 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys11:35:57.0735 4996 rdyboost - ok11:35:57.0751 4996 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll11:35:57.0766 4996 RemoteAccess - ok11:35:57.0782 4996 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll11:35:57.0782 4996 RemoteRegistry - ok11:35:57.0798 4996 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll11:35:57.0798 4996 RpcEptMapper - ok11:35:57.0813 4996 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe11:35:57.0813 4996 RpcLocator - ok11:35:57.0844 4996 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll11:35:57.0860 4996 RpcSs - ok11:35:57.0876 4996 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys11:35:57.0876 4996 rspndr - ok11:35:57.0922 4996 RTL8167 (afc12dfa4c7b089673ad67402ca19edb) C:\Windows\system32\DRIVERS\Rt64win7.sys11:35:57.0938 4996 RTL8167 - ok11:35:57.0954 4996 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe11:35:57.0954 4996 SamSs - ok11:35:57.0969 4996 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys11:35:57.0969 4996 sbp2port - ok11:35:58.0000 4996 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll11:35:58.0000 4996 SCardSvr - ok11:35:58.0016 4996 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys11:35:58.0016 4996 scfilter - ok11:35:58.0078 4996 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll11:35:58.0094 4996 Schedule - ok11:35:58.0110 4996 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll11:35:58.0110 4996 SCPolicySvc - ok11:35:58.0125 4996 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll11:35:58.0141 4996 SDRSVC - ok11:35:58.0172 4996 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys11:35:58.0172 4996 secdrv - ok11:35:58.0188 4996 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll11:35:58.0188 4996 seclogon - ok11:35:58.0203 4996 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll11:35:58.0203 4996 SENS - ok11:35:58.0219 4996 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll11:35:58.0219 4996 SensrSvc - ok11:35:58.0234 4996 Sentinel64 (255476b54c82a89416efdf09fd62f107) C:\Windows\System32\Drivers\Sentinel64.sys11:35:58.0234 4996 Sentinel64 - ok11:35:58.0250 4996 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys11:35:58.0250 4996 Serenum - ok11:35:58.0281 4996 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys11:35:58.0281 4996 Serial - ok11:35:58.0312 4996 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys11:35:58.0312 4996 sermouse - ok11:35:58.0328 4996 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll11:35:58.0328 4996 SessionEnv - ok11:35:58.0344 4996 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys11:35:58.0344 4996 sffdisk - ok11:35:58.0344 4996 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys11:35:58.0344 4996 sffp_mmc - ok11:35:58.0359 4996 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys11:35:58.0359 4996 sffp_sd - ok11:35:58.0375 4996 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys11:35:58.0375 4996 sfloppy - ok11:35:58.0422 4996 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll11:35:58.0422 4996 SharedAccess - ok11:35:58.0453 4996 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll11:35:58.0453 4996 ShellHWDetection - ok11:35:58.0468 4996 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys11:35:58.0468 4996 SiSRaid2 - ok11:35:58.0484 4996 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys11:35:58.0484 4996 SiSRaid4 - ok11:35:58.0500 4996 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys11:35:58.0515 4996 Smb - ok11:35:58.0531 4996 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe11:35:58.0531 4996 SNMPTRAP - ok11:35:58.0562 4996 SNTUSB64 (b3d47be53a032eb8cd0a9b77d946dc19) C:\Windows\system32\DRIVERS\SNTUSB64.SYS11:35:58.0562 4996 SNTUSB64 - ok11:35:58.0593 4996 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys11:35:58.0593 4996 spldr - ok11:35:58.0624 4996 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe11:35:58.0624 4996 Spooler - ok11:35:58.0780 4996 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe11:35:58.0827 4996 sppsvc - ok11:35:58.0905 4996 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll11:35:58.0905 4996 sppuinotify - ok11:35:58.0952 4996 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys11:35:58.0952 4996 srv - ok11:35:58.0983 4996 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys11:35:58.0999 4996 srv2 - ok11:35:59.0046 4996 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys11:35:59.0046 4996 srvnet - ok11:35:59.0061 4996 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll11:35:59.0061 4996 SSDPSRV - ok11:35:59.0077 4996 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll11:35:59.0077 4996 SstpSvc - ok11:35:59.0108 4996 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys11:35:59.0108 4996 stexstor - ok11:35:59.0155 4996 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll11:35:59.0170 4996 stisvc - ok11:35:59.0186 4996 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys11:35:59.0186 4996 swenum - ok11:35:59.0233 4996 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll11:35:59.0248 4996 swprv - ok11:35:59.0311 4996 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll11:35:59.0342 4996 SysMain - ok11:35:59.0373 4996 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll11:35:59.0373 4996 TabletInputService - ok11:35:59.0404 4996 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll11:35:59.0404 4996 TapiSrv - ok11:35:59.0420 4996 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll11:35:59.0436 4996 TBS - ok11:35:59.0638 4996 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys11:35:59.0654 4996 Tcpip - ok11:35:59.0763 4996 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys11:35:59.0763 4996 TCPIP6 - ok11:35:59.0794 4996 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys11:35:59.0810 4996 tcpipreg - ok11:35:59.0810 4996 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys11:35:59.0826 4996 TDPIPE - ok11:35:59.0826 4996 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys11:35:59.0826 4996 TDTCP - ok11:35:59.0857 4996 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys11:35:59.0857 4996 tdx - ok11:35:59.0857 4996 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys11:35:59.0872 4996 TermDD - ok11:35:59.0904 4996 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll11:35:59.0904 4996 TermService - ok11:35:59.0919 4996 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll11:35:59.0919 4996 Themes - ok11:35:59.0935 4996 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll11:35:59.0935 4996 THREADORDER - ok11:35:59.0950 4996 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll11:35:59.0950 4996 TrkWks - ok11:35:59.0997 4996 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe11:35:59.0997 4996 TrustedInstaller - ok11:36:00.0013 4996 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys11:36:00.0013 4996 tssecsrv - ok11:36:00.0044 4996 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys11:36:00.0044 4996 TsUsbFlt - ok11:36:00.0060 4996 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys11:36:00.0060 4996 TsUsbGD - ok11:36:00.0091 4996 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys11:36:00.0106 4996 tunnel - ok11:36:00.0122 4996 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys11:36:00.0122 4996 uagp35 - ok11:36:00.0153 4996 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys11:36:00.0153 4996 udfs - ok11:36:00.0169 4996 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe11:36:00.0169 4996 UI0Detect - ok11:36:00.0184 4996 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys11:36:00.0184 4996 uliagpkx - ok11:36:00.0200 4996 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys11:36:00.0200 4996 umbus - ok11:36:00.0200 4996 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys11:36:00.0216 4996 UmPass - ok11:36:00.0387 4996 UNS (e91f8afbd7fb96c94b266579d6bfa77a) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe11:36:00.0403 4996 UNS - ok11:36:00.0481 4996 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll11:36:00.0481 4996 upnphost - ok11:36:00.0512 4996 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys11:36:00.0512 4996 usbccgp - ok11:36:00.0543 4996 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys11:36:00.0543 4996 usbcir - ok11:36:00.0559 4996 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys11:36:00.0559 4996 usbehci - ok11:36:00.0590 4996 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys11:36:00.0590 4996 usbhub - ok11:36:00.0621 4996 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys11:36:00.0621 4996 usbohci - ok11:36:00.0637 4996 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys11:36:00.0637 4996 usbprint - ok11:36:00.0684 4996 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys11:36:00.0684 4996 usbscan - ok11:36:00.0699 4996 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS11:36:00.0699 4996 USBSTOR - ok11:36:00.0715 4996 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys11:36:00.0715 4996 usbuhci - ok11:36:00.0746 4996 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys11:36:00.0746 4996 usbvideo - ok11:36:00.0762 4996 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll11:36:00.0762 4996 UxSms - ok11:36:00.0793 4996 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe11:36:00.0793 4996 VaultSvc - ok11:36:00.0824 4996 VBoxNetAdp (e705a3a384e7569fa2f1a3a29bdc5240) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys11:36:00.0824 4996 VBoxNetAdp - ok11:36:00.0855 4996 VBoxNetFlt - ok11:36:00.0871 4996 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys11:36:00.0871 4996 vdrvroot - ok11:36:00.0918 4996 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe11:36:00.0933 4996 vds - ok11:36:00.0964 4996 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys11:36:00.0964 4996 vga - ok11:36:00.0980 4996 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys11:36:00.0980 4996 VgaSave - ok11:36:01.0011 4996 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys11:36:01.0011 4996 vhdmp - ok11:36:01.0027 4996 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys11:36:01.0027 4996 viaide - ok11:36:01.0042 4996 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys11:36:01.0042 4996 volmgr - ok11:36:01.0058 4996 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys11:36:01.0074 4996 volmgrx - ok11:36:01.0105 4996 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys11:36:01.0120 4996 volsnap - ok11:36:01.0136 4996 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys11:36:01.0136 4996 vsmraid - ok11:36:01.0214 4996 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe11:36:01.0230 4996 VSS - ok11:36:01.0308 4996 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys11:36:01.0308 4996 vwifibus - ok11:36:01.0323 4996 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys11:36:01.0323 4996 vwififlt - ok11:36:01.0339 4996 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys11:36:01.0354 4996 vwifimp - ok11:36:01.0386 4996 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll11:36:01.0386 4996 W32Time - ok11:36:01.0401 4996 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys11:36:01.0417 4996 WacomPen - ok11:36:01.0432 4996 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys11:36:01.0432 4996 WANARP - ok11:36:01.0432 4996 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys11:36:01.0432 4996 Wanarpv6 - ok11:36:01.0526 4996 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe11:36:01.0542 4996 WatAdminSvc - ok11:36:01.0604 4996 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe11:36:01.0635 4996 wbengine - ok11:36:01.0729 4996 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll11:36:01.0729 4996 WbioSrvc - ok11:36:01.0760 4996 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll11:36:01.0760 4996 wcncsvc - ok11:36:01.0776 4996 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll11:36:01.0776 4996 WcsPlugInService - ok11:36:01.0791 4996 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys11:36:01.0791 4996 Wd - ok11:36:01.0838 4996 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys11:36:01.0854 4996 Wdf01000 - ok11:36:01.0869 4996 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll11:36:01.0869 4996 WdiServiceHost - ok11:36:01.0869 4996 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll11:36:01.0869 4996 WdiSystemHost - ok11:36:01.0900 4996 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll11:36:01.0900 4996 WebClient - ok11:36:01.0932 4996 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll11:36:01.0932 4996 Wecsvc - ok11:36:01.0947 4996 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll11:36:01.0947 4996 wercplsupport - ok11:36:01.0978 4996 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll11:36:01.0978 4996 WerSvc - ok11:36:01.0978 4996 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys11:36:01.0994 4996 WfpLwf - ok11:36:01.0994 4996 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys11:36:02.0010 4996 WIMMount - ok11:36:02.0056 4996 WinDefend - ok11:36:02.0056 4996 WinHttpAutoProxySvc - ok11:36:02.0103 4996 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll11:36:02.0103 4996 Winmgmt - ok11:36:02.0181 4996 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll11:36:02.0212 4996 WinRM - ok11:36:02.0306 4996 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys11:36:02.0306 4996 WinUsb - ok11:36:02.0353 4996 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll11:36:02.0368 4996 Wlansvc - ok11:36:02.0431 4996 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe11:36:02.0431 4996 wlcrasvc - ok11:36:02.0571 4996 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE11:36:02.0587 4996 wlidsvc - ok11:36:02.0649 4996 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys11:36:02.0649 4996 WmiAcpi - ok11:36:02.0680 4996 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe11:36:02.0680 4996 wmiApSrv - ok11:36:02.0727 4996 WMPNetworkSvc - ok11:36:02.0743 4996 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll11:36:02.0743 4996 WPCSvc - ok11:36:02.0758 4996 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll11:36:02.0758 4996 WPDBusEnum - ok11:36:02.0774 4996 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys11:36:02.0774 4996 ws2ifsl - ok11:36:02.0790 4996 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll11:36:02.0790 4996 wscsvc - ok11:36:02.0790 4996 WSearch - ok11:36:02.0883 4996 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll11:36:02.0930 4996 wuauserv - ok11:36:02.0977 4996 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys11:36:02.0977 4996 WudfPf - ok11:36:02.0992 4996 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys11:36:02.0992 4996 WUDFRd - ok11:36:03.0008 4996 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll11:36:03.0008 4996 wudfsvc - ok11:36:03.0039 4996 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll11:36:03.0039 4996 WwanSvc - ok11:36:03.0102 4996 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR011:36:03.0273 4996 \Device\Harddisk0\DR0 - ok11:36:03.0273 4996 Boot (0x1200) (6c29d0304f608a862d981236945ca2a6) \Device\Harddisk0\DR0\Partition011:36:03.0273 4996 \Device\Harddisk0\DR0\Partition0 - ok11:36:03.0289 4996 Boot (0x1200) (b8de73dd3ab05971da83d44cc7a6392c) \Device\Harddisk0\DR0\Partition111:36:03.0289 4996 \Device\Harddisk0\DR0\Partition1 - ok11:36:03.0304 4996 Boot (0x1200) (7cae826f03fe553e82ac8fa17b109f35) \Device\Harddisk0\DR0\Partition211:36:03.0304 4996 \Device\Harddisk0\DR0\Partition2 - ok11:36:03.0304 4996 ============================================================11:36:03.0304 4996 Scan finished11:36:03.0304 4996 ============================================================11:36:03.0320 4868 Detected object count: 011:36:03.0320 4868 Actual detected object count: 011:36:05.0301 0536 Deinitialize success Share this post Link to post Share on other sites
Alikhan #4 Posted May 22, 2012 ComboFix 12-05-22.01 - Shazia Begum 22/05/2012 11:19:43.3.2 - x64Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4008.2468 [GMT 1:00]Running from: c:\users\Shazia Begum\Desktop\ComboFix.exeAV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\programdata\ntuser.datc:\windows\SysWow64\ssprs.dll..((((((((((((((((((((((((( Files Created from 2012-04-22 to 2012-05-22 )))))))))))))))))))))))))))))))..2012-05-22 10:24 . 2012-05-22 10:24 -------- d-----w- c:\users\Public\AppData\Local\temp2012-05-22 10:24 . 2012-05-22 10:24 -------- d-----w- c:\users\Default\AppData\Local\temp2012-05-21 19:24 . 2012-05-21 19:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware2012-05-21 19:24 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys2012-05-21 15:29 . 2012-05-22 10:26 -------- d-----w- c:\programdata\Kaspersky Lab2012-05-21 15:29 . 2012-05-21 15:29 -------- d-----w- c:\program files (x86)\Kaspersky Lab2012-05-21 12:50 . 2012-05-21 12:50 22 --sha-w- c:\windows\90C7D912BE2316.sys2012-05-21 12:50 . 2012-05-21 12:50 22 --sha-w- c:\users\Shazia Begum\AppData\Roaming\Windows1569_SettingsRepository.bin2012-05-21 12:49 . 2012-05-21 12:49 0 ----a-w- c:\users\Shazia Begum\AppData\Local\jv16PT_temp.tmp2012-05-21 12:35 . 2012-05-22 10:24 -------- d-----w- c:\windows\system32\wbem\repository2012-05-19 18:17 . 2012-04-12 17:12 224048 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys2012-05-19 18:17 . 2012-04-12 17:12 130864 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys2012-05-18 14:43 . 2012-05-18 14:43 -------- d-----w- c:\program files\HitmanPro2012-05-09 19:29 . 2012-05-09 19:29 -------- d-----w- c:\program files (x86)\BYOND42012-05-09 14:41 . 2012-05-09 14:41 -------- d-----w- c:\program files\Microsoft Silverlight2012-05-09 14:41 . 2012-05-09 14:41 -------- d-----w- c:\program files (x86)\Microsoft Silverlight2012-05-08 21:31 . 2012-05-08 21:31 -------- d-----w- c:\users\Shazia Begum\AppData\Local\ESET2012-05-08 21:20 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys2012-05-08 21:20 . 2012-03-31 06:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe2012-05-08 21:20 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe2012-05-08 21:20 . 2012-03-31 03:10 3146240 ----a-w- c:\windows\system32\win32k.sys2012-05-08 21:20 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe2012-05-08 21:20 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll2012-05-08 21:20 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll2012-05-08 21:20 . 2012-03-30 11:35 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys2012-05-08 21:19 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL2012-05-08 21:19 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll2012-05-08 21:19 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll2012-05-08 21:19 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll2012-05-08 21:19 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll2012-04-28 19:57 . 2012-05-18 16:02 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\EurekaLog2012-04-28 18:38 . 2012-05-21 12:57 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\Paoc2012-04-28 18:38 . 2012-04-28 19:22 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\Ekynl2012-04-25 18:48 . 2012-05-19 19:38 -------- d-----w- c:\users\Shazia Begum\VirtualBox VMs2012-04-25 18:47 . 2012-05-19 19:43 -------- d-----w- c:\users\Shazia Begum\.VirtualBox2012-04-25 18:46 . 2012-05-19 19:44 -------- dc----w- c:\windows\system32\DRVSTORE2012-04-24 16:30 . 2012-05-12 12:44 -------- d-----w- c:\windows\SysWow64\Adobe2012-04-24 14:45 . 2012-04-24 14:45 -------- d-----w- c:\program files (x86)\uTorrent2012-04-22 20:35 . 2011-06-21 04:09 200976 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2012-05-05 16:29 . 2012-04-05 11:37 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe2012-05-05 16:29 . 2011-07-09 08:17 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-05-05 16:29 . 2012-04-17 20:29 8769696 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe2012-04-12 17:12 . 2012-04-12 17:12 147248 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys2012-04-09 12:17 . 2012-04-09 12:17 1700352 ------w- c:\windows\SysWow64\gdiplus.dll2012-03-20 02:51 . 2012-04-06 10:20 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E993DC25-C93B-4BB9-8366-626753F1FEA6}\mpengine.dll2012-03-18 15:16 . 2012-02-01 19:58 472808 ------w- c:\windows\SysWow64\deployJava1.dll2012-03-01 06:46 . 2012-04-11 11:19 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys2012-03-01 06:38 . 2012-04-11 11:19 220672 ----a-w- c:\windows\system32\wintrust.dll2012-03-01 06:33 . 2012-04-11 11:19 81408 ----a-w- c:\windows\system32\imagehlp.dll2012-03-01 06:28 . 2012-04-11 11:19 5120 ----a-w- c:\windows\system32\wmi.dll2012-03-01 05:37 . 2012-04-11 11:19 172544 ----a-w- c:\windows\SysWow64\wintrust.dll2012-03-01 05:33 . 2012-04-11 11:19 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll2012-03-01 05:29 . 2012-04-11 11:19 5120 ----a-w- c:\windows\SysWow64\wmi.dll2012-02-28 06:56 . 2012-04-11 11:23 2311168 ----a-w- c:\windows\system32\jscript9.dll2012-02-28 06:49 . 2012-04-11 11:22 1390080 ----a-w- c:\windows\system32\wininet.dll2012-02-28 06:48 . 2012-04-11 11:23 1493504 ----a-w- c:\windows\system32\inetcpl.cpl2012-02-28 06:42 . 2012-04-11 11:23 2382848 ----a-w- c:\windows\system32\mshtml.tlb2012-02-28 01:18 . 2012-04-11 11:23 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll2012-02-28 01:11 . 2012-04-11 11:23 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl2012-02-28 01:11 . 2012-04-11 11:23 1127424 ----a-w- c:\windows\SysWow64\wininet.dll2012-02-28 01:03 . 2012-04-11 11:23 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb2012-02-23 08:18 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584].[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2011-05-11 136488]"YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCamTray.exe" [2011-09-23 165160]"IdeaCom Calibration"="c:\program files (x86)\IdeaCom\IDCMgr\StartUT.exe" [2010-03-18 270848]"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2011-06-10 627304]"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]"avp"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296].[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216].c:\users\Shazia Begum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712].c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MicroNEXT Wireless Utility.lnk - c:\program files (x86)\MicroNEXT\Common\RaUI.exe [2012-1-29 1828128].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]"aux"=wdmaud.drv.[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]@="".[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]"DisableMonitoring"=dword:00000001.R0 dlhynz;dlhynz; [x]R0 raeehd;raeehd; [x]R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-02-14 276248]R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]R3 JTVNCProxy_13.0;JTVNCProxy_13.0;c:\program files\Freedom Scientific\JAWS\13.0\JTVNCProxy.exe [2011-12-08 19736]R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-12-20 29184]R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]R3 PowerBrl;powerBraille System Driver;c:\windows\system32\Drivers\powerbrl.sys [x]R3 PQAWRwa;PQAWRwa;c:\windows\SysWOW64\PQAWDrv.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]S2 Freedom Scientific Kernel Manager;Freedom Scientific Kernel Manager;c:\windows\system32\fsKMgr.dll [x]S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2011-05-30 36456]S2 IdcSrv;IDCSRV Service;c:\program files (x86)\IdeaCom\IDCMgr\IdcSrv.exe [2011-01-06 252928]S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\MicroNEXT\Common\RalinkRegistryWriter64.exe [2008-09-05 210720]S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [x]S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]S3 fsvidmir_service;fsvidmir_service;c:\windows\system32\DRIVERS\fsvidmir.sys [x]S3 IdcFltr;HID Touch Screen Driver;c:\windows\system32\DRIVERS\idcfltr.sys [x]S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]S3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;c:\windows\system32\DRIVERS\SNTUSB64.SYS [x]S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]..Contents of the 'Scheduled Tasks' folder.2012-05-21 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:29].2012-05-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-781961419-1968162369-1216944339-1000Core.job- c:\users\Shazia Begum\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-29 14:37].2012-05-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-781961419-1968162369-1216944339-1000UA.job- c:\users\Shazia Begum\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-29 14:37]..--------- x86-64 -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"TouchORB"="c:\program files (x86)\TouchSettings\TouchPortalOBR.exe" [2010-05-06 153416]"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-23 11725928]"Acer PowerSaver"="c:\program files\Acer\Acer PowerSaver\PowerSaverTray.exe" [2011-09-06 545680]"JAWS"="c:\program files\Freedom Scientific\JAWS\13.0\jfw.exe" [2011-12-08 6834968]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-14 170264]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-14 398616]"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-14 440600].[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]"LoadAppInit_DLLs"=0x1.------- Supplementary Scan -------.uStart Page = about:blankuLocal Page = c:\windows\system32\blank.htmmStart Page = hxxp://acer.msn.commLocal Page = c:\windows\SysWOW64\blank.htmIE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htmIE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000IE: Free YouTube Download - c:\users\Shazia Begum\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htmIE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105TCP: DhcpNameServer = 192.168.0.1TCP: Interfaces\{B887273F-390E-48B5-AC65-A19E4D9A682A}: NameServer = 8.26.56.26,156.154.70.22TCP: Interfaces\{D9DA8EA3-8033-4A15-9A19-E500C47C0069}: NameServer = 8.26.56.26,156.154.70.22.- - - - ORPHANS REMOVED - - - -.Toolbar-Locked - (no file)WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)...--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.11".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]@Denied: (A) (Everyone)"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]@Denied: (A) (Everyone).[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]"Key"="ActionsPane3""Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Other Running Processes ------------------------.c:\program files (x86)\MicroNEXT\Common\RalinkRegistryWriter.exec:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exec:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe.**************************************************************************.Completion time: 2012-05-22 11:29:01 - machine was rebootedComboFix-quarantined-files.txt 2012-05-22 10:29.Pre-Run: 421,397,352,448 bytes freePost-Run: 421,076,725,760 bytes free.- - End Of File - - 70D7A26EFC8950CB93E1E105C96533A9 Results of screen317's Security Check version 0.99.34 Windows 7 x64 (UAC is disabled!) Internet Explorer 9 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Kaspersky Internet Security 2012 WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes Anti-Malware version 1.61.0.1400 Java 6 Update 31 Java version out of date! Adobe Reader X (10.1.3) ```````````````````````````````` Process Check: objlist.exe by Laurent Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Kaspersky Lab Kaspersky Internet Security 2012 avp.exe Kaspersky Lab Kaspersky Internet Security 2012 x64 klwtblfs.exe ``````````End of Log```````````` Share this post Link to post Share on other sites
D-FRED-BROWN #5 Posted May 22, 2012 Looking better!Let's see if we can take care of some suspicious files :Please do the following:1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.3. Open notepad and copy/paste the text in the quotebox below into it:KILLALL::File::c:\users\Shazia Begum\AppData\Local\jv16PT_temp.tmpC:\Windows\System32\Drivers\dlhynz.sysC:\Windows\System32\Drivers\raeehd.sysc:\windows\90C7D912BE2316.sysc:\users\Shazia Begum\AppData\Roaming\Windows1569_SettingsRepository.binDriver::dlhynzraeehd90C7D912BE2316Reboot::Save this as CFScript.txt, in the same location as ComboFix.exeRefering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I shall require in your next reply.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Please include the newly-created C:\ComboFix.txt in your next reply, and let me know how things are running now Share this post Link to post Share on other sites
Alikhan #6 Posted May 22, 2012 ComboFix 12-05-22.02 - Shazia Begum 22/05/2012 19:19:01.4.2 - x64Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4008.2278 [GMT 1:00]Running from: c:\users\Shazia Begum\Desktop\ComboFix.exeCommand switches used :: c:\users\Shazia Begum\Desktop\CFScript.txtAV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}.FILE ::"c:\users\Shazia Begum\AppData\Local\jv16PT_temp.tmp""c:\users\Shazia Begum\AppData\Roaming\Windows1569_SettingsRepository.bin""c:\windows\90C7D912BE2316.sys""c:\windows\System32\Drivers\dlhynz.sys""c:\windows\System32\Drivers\raeehd.sys"..((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))..c:\users\Shazia Begum\AppData\Local\jv16PT_temp.tmpc:\users\Shazia Begum\AppData\Roaming\Windows1569_SettingsRepository.binc:\windows\90C7D912BE2316.sysc:\windows\SysWow64\ssprs.dll..((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))..-------\Legacy_DLHYNZ-------\Legacy_RAEEHD-------\Service_dlhynz-------\Service_raeehd..((((((((((((((((((((((((( Files Created from 2012-04-22 to 2012-05-22 )))))))))))))))))))))))))))))))..2012-05-22 18:23 . 2012-05-22 18:23 -------- d-----w- c:\users\Public\AppData\Local\temp2012-05-22 18:23 . 2012-05-22 18:23 -------- d-----w- c:\users\Default\AppData\Local\temp2012-05-22 12:44 . 2012-05-22 12:44 -------- d-----w- c:\windows\en2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\pt-pt2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\ar2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\bg2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\cs2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\da2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\de2012-05-22 12:40 . 2012-05-22 12:40 -------- d-----w- c:\windows\el2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\es2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\fi2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\fr2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\he2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\hr2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\hu2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\it2012-05-22 12:39 . 2012-05-22 12:39 -------- d-----w- c:\windows\nl2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\no2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\pl2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\pt-br2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\ro2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\ru2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\sk2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\sl2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\sv2012-05-22 12:38 . 2012-05-22 12:38 -------- d-----w- c:\windows\th2012-05-22 12:37 . 2012-05-22 12:37 -------- d-----w- c:\windows\tr2012-05-22 12:37 . 2012-05-22 12:37 -------- d-----w- c:\windows\zh-tw2012-05-22 12:37 . 2012-05-22 12:37 -------- d-----w- c:\windows\ca2012-05-22 12:37 . 2012-05-22 12:37 -------- d-----w- c:\windows\eu2012-05-22 12:11 . 2012-05-22 12:11 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\fbccaeef1cd381302\MeshBetaRemover.exe2012-05-22 12:11 . 2012-05-22 12:11 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\fb7eb4db1cd381301\DSETUP.dll2012-05-22 12:11 . 2012-05-22 12:11 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\fb7eb4db1cd381301\DXSETUP.exe2012-05-22 12:11 . 2012-05-22 12:11 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\fb7eb4db1cd381301\dsetup32.dll2012-05-21 19:24 . 2012-05-21 19:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware2012-05-21 19:24 . 2012-04-04 14:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys2012-05-21 15:29 . 2012-05-22 19:40 -------- d-----w- c:\programdata\Kaspersky Lab2012-05-21 15:29 . 2012-05-21 15:29 -------- d-----w- c:\program files (x86)\Kaspersky Lab2012-05-21 12:35 . 2012-05-22 18:24 -------- d-----w- c:\windows\system32\wbem\repository2012-05-19 18:17 . 2012-04-12 17:12 224048 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys2012-05-19 18:17 . 2012-04-12 17:12 130864 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys2012-05-18 14:43 . 2012-05-18 14:43 -------- d-----w- c:\program files\HitmanPro2012-05-09 19:29 . 2012-05-09 19:29 -------- d-----w- c:\program files (x86)\BYOND42012-05-09 14:41 . 2012-05-09 14:41 -------- d-----w- c:\program files\Microsoft Silverlight2012-05-09 14:41 . 2012-05-09 14:41 -------- d-----w- c:\program files (x86)\Microsoft Silverlight2012-05-08 21:31 . 2012-05-08 21:31 -------- d-----w- c:\users\Shazia Begum\AppData\Local\ESET2012-05-08 21:20 . 2012-03-17 07:58 75120 ----a-w- c:\windows\system32\drivers\partmgr.sys2012-05-08 21:20 . 2012-03-31 06:05 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe2012-05-08 21:20 . 2012-03-31 04:39 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe2012-05-08 21:20 . 2012-03-31 03:10 3146240 ----a-w- c:\windows\system32\win32k.sys2012-05-08 21:20 . 2012-03-31 04:39 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe2012-05-08 21:20 . 2012-03-03 06:35 1544704 ----a-w- c:\windows\system32\DWrite.dll2012-05-08 21:20 . 2012-03-03 05:31 1077248 ----a-w- c:\windows\SysWow64\DWrite.dll2012-05-08 21:20 . 2012-03-30 11:35 1918320 ----a-w- c:\windows\system32\drivers\tcpip.sys2012-05-08 21:19 . 2012-03-31 05:42 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL2012-05-08 21:19 . 2012-03-31 05:40 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll2012-05-08 21:19 . 2012-03-31 05:40 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll2012-05-08 21:19 . 2012-03-31 05:40 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll2012-05-08 21:19 . 2012-03-31 04:29 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll2012-04-28 19:57 . 2012-05-18 16:02 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\EurekaLog2012-04-28 18:38 . 2012-05-21 12:57 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\Paoc2012-04-28 18:38 . 2012-04-28 19:22 -------- d-----w- c:\users\Shazia Begum\AppData\Roaming\Ekynl2012-04-25 18:48 . 2012-05-19 19:38 -------- d-----w- c:\users\Shazia Begum\VirtualBox VMs2012-04-25 18:47 . 2012-05-19 19:43 -------- d-----w- c:\users\Shazia Begum\.VirtualBox2012-04-25 18:46 . 2012-05-19 19:44 -------- dc----w- c:\windows\system32\DRVSTORE2012-04-24 16:30 . 2012-05-12 12:44 -------- d-----w- c:\windows\SysWow64\Adobe2012-04-24 14:45 . 2012-04-24 14:45 -------- d-----w- c:\program files (x86)\uTorrent2012-04-22 20:35 . 2011-06-21 04:09 200976 ----a-w- c:\windows\SysWow64\drivers\tmcomm.sys...(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2012-05-05 16:29 . 2012-04-05 11:37 419488 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe2012-05-05 16:29 . 2011-07-09 08:17 70304 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl2012-05-05 16:29 . 2012-04-17 20:29 8769696 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe2012-04-12 17:12 . 2012-04-12 17:12 147248 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys2012-04-09 12:17 . 2012-04-09 12:17 1700352 ------w- c:\windows\SysWow64\gdiplus.dll2012-03-20 02:51 . 2012-04-06 10:20 8669240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E993DC25-C93B-4BB9-8366-626753F1FEA6}\mpengine.dll2012-03-18 15:16 . 2012-02-01 19:58 472808 ------w- c:\windows\SysWow64\deployJava1.dll2012-03-08 17:50 . 2012-03-08 17:50 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll2012-03-08 17:37 . 2012-03-08 17:37 302448 ----a-w- c:\windows\WLXPGSS.SCR2012-03-01 06:46 . 2012-04-11 11:19 23408 ----a-w- c:\windows\system32\drivers\fs_rec.sys2012-03-01 06:38 . 2012-04-11 11:19 220672 ----a-w- c:\windows\system32\wintrust.dll2012-03-01 06:33 . 2012-04-11 11:19 81408 ----a-w- c:\windows\system32\imagehlp.dll2012-03-01 06:28 . 2012-04-11 11:19 5120 ----a-w- c:\windows\system32\wmi.dll2012-03-01 05:37 . 2012-04-11 11:19 172544 ----a-w- c:\windows\SysWow64\wintrust.dll2012-03-01 05:33 . 2012-04-11 11:19 159232 ----a-w- c:\windows\SysWow64\imagehlp.dll2012-03-01 05:29 . 2012-04-11 11:19 5120 ----a-w- c:\windows\SysWow64\wmi.dll2012-02-28 06:56 . 2012-04-11 11:23 2311168 ----a-w- c:\windows\system32\jscript9.dll2012-02-28 06:49 . 2012-04-11 11:22 1390080 ----a-w- c:\windows\system32\wininet.dll2012-02-28 06:48 . 2012-04-11 11:23 1493504 ----a-w- c:\windows\system32\inetcpl.cpl2012-02-28 06:42 . 2012-04-11 11:23 2382848 ----a-w- c:\windows\system32\mshtml.tlb2012-02-28 01:18 . 2012-04-11 11:23 1799168 ----a-w- c:\windows\SysWow64\jscript9.dll2012-02-28 01:11 . 2012-04-11 11:23 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl2012-02-28 01:11 . 2012-04-11 11:23 1127424 ----a-w- c:\windows\SysWow64\wininet.dll2012-02-28 01:03 . 2012-04-11 11:23 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb2012-02-23 08:18 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe..((((((((((((((((((((((((((((( SnapShot@2012-05-22_10.25.27 ))))))))))))))))))))))))))))))))))))))))).- 2009-07-14 04:54 . 2012-05-20 11:44 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2009-07-14 04:54 . 2012-05-22 18:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2009-07-14 04:54 . 2012-05-22 18:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat- 2009-07-14 04:54 . 2012-05-20 11:44 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat+ 2009-07-14 04:54 . 2012-05-22 18:24 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat- 2009-07-14 04:54 . 2012-05-20 11:44 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat+ 2010-11-21 03:09 . 2012-05-22 10:26 70578 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin- 2011-09-29 06:54 . 2012-05-21 15:19 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat+ 2011-09-29 06:54 . 2012-05-22 18:28 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat- 2011-09-29 06:54 . 2012-05-21 15:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat+ 2011-09-29 06:54 . 2012-05-22 18:28 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat- 2009-07-14 04:54 . 2012-05-21 15:19 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat+ 2009-07-14 04:54 . 2012-05-22 18:28 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat+ 2012-05-22 12:21 . 2012-05-22 12:21 23552 c:\windows\Installer\645154.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\64514f.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 60416 c:\windows\Installer\645149.msp+ 2012-05-22 12:21 . 2012-05-22 12:21 29184 c:\windows\Installer\6450e8.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 67072 c:\windows\Installer\6450e2.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\64506d.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\645068.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645063.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\64505e.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645059.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645054.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\64504f.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\64504a.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645045.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645040.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\64503b.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645036.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645031.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\64502c.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645027.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645022.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\64501d.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645018.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645013.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\64500e.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\645009.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\645004.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fff.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644ffa.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644ff5.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644ff0.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644feb.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fe6.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fe1.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fdc.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fd7.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fd2.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fcd.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fc8.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fc3.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fbe.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fb9.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fb4.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644faf.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644faa.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644fa5.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644fa0.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f9b.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 29696 c:\windows\Installer\644f96.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f91.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f8c.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f87.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f82.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f7d.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f78.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f73.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f6e.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f69.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f64.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 23552 c:\windows\Installer\644f5d.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 29696 c:\windows\Installer\644f58.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 61440 c:\windows\Installer\644f41.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 60928 c:\windows\Installer\644f25.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 61952 c:\windows\Installer\644f09.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 62464 c:\windows\Installer\644eed.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 60928 c:\windows\Installer\644ed1.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 62464 c:\windows\Installer\644eb5.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 63488 c:\windows\Installer\644e97.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 65024 c:\windows\Installer\644e7b.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 61440 c:\windows\Installer\644e5f.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 61440 c:\windows\Installer\644e43.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 60416 c:\windows\Installer\644e27.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 61952 c:\windows\Installer\644e0b.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 66048 c:\windows\Installer\644def.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 61952 c:\windows\Installer\644dd3.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 64512 c:\windows\Installer\644db7.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 60928 c:\windows\Installer\644d9b.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 66048 c:\windows\Installer\644d7f.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 65024 c:\windows\Installer\644d63.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 65536 c:\windows\Installer\644d47.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 62464 c:\windows\Installer\644d2b.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 62464 c:\windows\Installer\644d0f.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 61440 c:\windows\Installer\644cf3.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 60928 c:\windows\Installer\644cd7.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 60928 c:\windows\Installer\644cbb.msp+ 2012-05-22 12:19 . 2012-05-22 12:19 60928 c:\windows\Installer\644c9f.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 58880 c:\windows\Installer\644c83.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 61952 c:\windows\Installer\644c67.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 60928 c:\windows\Installer\644c4b.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 29696 c:\windows\Installer\644929.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 71680 c:\windows\Installer\644923.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 29184 c:\windows\Installer\6448ed.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 67584 c:\windows\Installer\6448e7.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 30208 c:\windows\Installer\6448b1.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 70144 c:\windows\Installer\6448ab.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 30208 c:\windows\Installer\644875.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 69632 c:\windows\Installer\64486f.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 29696 c:\windows\Installer\644839.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 68608 c:\windows\Installer\644833.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 30208 c:\windows\Installer\6447fd.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 71168 c:\windows\Installer\6447f7.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 30720 c:\windows\Installer\6447c1.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 73728 c:\windows\Installer\6447bb.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 30208 c:\windows\Installer\644785.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 71680 c:\windows\Installer\64477f.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 30208 c:\windows\Installer\644749.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 69632 c:\windows\Installer\644743.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 29184 c:\windows\Installer\64470d.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 71680 c:\windows\Installer\644707.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 28672 c:\windows\Installer\6446d1.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 64512 c:\windows\Installer\6446cb.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 30208 c:\windows\Installer\644695.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 70144 c:\windows\Installer\64468f.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 30208 c:\windows\Installer\644659.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 72192 c:\windows\Installer\644653.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 29184 c:\windows\Installer\64461d.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 70656 c:\windows\Installer\644617.msi+ 2012-05-22 12:14 . 2012-05-22 12:14 29696 c:\windows\Installer\6445e1.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 69120 c:\windows\Installer\6445db.msi+ 2012-05-22 12:14 . 2012-05-22 12:14 29696 c:\windows\Installer\6445a5.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 67584 c:\windows\Installer\64459f.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 29696 c:\windows\Installer\644569.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 71168 c:\windows\Installer\644563.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 29184 c:\windows\Installer\64452d.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 69632 c:\windows\Installer\644527.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 29696 c:\windows\Installer\6444f1.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 70656 c:\windows\Installer\6444eb.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 30208 c:\windows\Installer\6444b5.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 71680 c:\windows\Installer\6444af.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 29696 c:\windows\Installer\644479.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 70144 c:\windows\Installer\644473.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 29184 c:\windows\Installer\64443d.msp+ 2011-07-09 07:50 . 2011-07-09 07:50 69632 c:\windows\Installer\644437.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 29696 c:\windows\Installer\644401.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 68608 c:\windows\Installer\6443fb.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 29184 c:\windows\Installer\6443c5.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 67072 c:\windows\Installer\6443bf.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 29184 c:\windows\Installer\644389.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 69120 c:\windows\Installer\644383.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 28672 c:\windows\Installer\64434d.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 56832 c:\windows\Installer\644347.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 30208 c:\windows\Installer\644311.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 71168 c:\windows\Installer\64430b.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 29184 c:\windows\Installer\6442d4.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 70656 c:\windows\Installer\6442ce.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 39936 c:\windows\Installer\644235.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 74240 c:\windows\Installer\644230.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 26112 c:\windows\Installer\644227.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 80395 c:\windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe- 2012-02-19 19:01 . 2012-02-19 19:01 80395 c:\windows\Installer\{E5B21F11-6933-4E0B-A25C-7963E3C07D11}\MsblIco.Exe+ 2012-05-22 12:56 . 2012-05-22 12:56 61440 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\46c90378e984963ce2acf8b3fd7703ed\WindowsLiveWriter.ni.exe+ 2012-05-22 12:56 . 2012-05-22 12:56 80896 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b139a1cda26d066860aaa83ff1f0ff91\WindowsLive.Writer.Passport.ni.dll+ 2012-05-22 18:24 . 2012-05-22 18:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat- 2012-05-22 10:24 . 2012-05-22 10:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat+ 2012-05-22 18:24 . 2012-05-22 18:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat- 2012-05-22 10:24 . 2012-05-22 10:24 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat- 2009-07-14 02:36 . 2012-05-22 10:18 630928 c:\windows\system32\perfh009.dat+ 2009-07-14 02:36 . 2012-05-22 18:29 630928 c:\windows\system32\perfh009.dat- 2009-07-14 02:36 . 2012-05-22 10:18 111052 c:\windows\system32\perfc009.dat+ 2009-07-14 02:36 . 2012-05-22 18:29 111052 c:\windows\system32\perfc009.dat+ 2011-07-09 07:51 . 2011-07-09 07:51 153600 c:\windows\Installer\645144.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 509952 c:\windows\Installer\64512d.msp+ 2012-05-22 12:21 . 2012-05-22 12:21 635904 c:\windows\Installer\645123.msp+ 2012-05-22 12:21 . 2012-05-22 12:21 468480 c:\windows\Installer\645104.msp+ 2012-05-22 12:21 . 2012-05-22 12:21 625664 c:\windows\Installer\6450f5.msp+ 2012-05-22 12:20 . 2012-05-22 12:20 205824 c:\windows\Installer\644f53.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 775168 c:\windows\Installer\644f4a.msi+ 2011-07-09 07:53 . 2011-07-09 07:53 167424 c:\windows\Installer\644f3c.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 152064 c:\windows\Installer\644f20.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 167936 c:\windows\Installer\644f04.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 160768 c:\windows\Installer\644ee8.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 158208 c:\windows\Installer\644ecc.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 174080 c:\windows\Installer\644eb0.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 176128 c:\windows\Installer\644e92.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 170496 c:\windows\Installer\644e76.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 160256 c:\windows\Installer\644e5a.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 168960 c:\windows\Installer\644e3e.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 147968 c:\windows\Installer\644e22.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 161792 c:\windows\Installer\644e06.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 168448 c:\windows\Installer\644dea.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 164864 c:\windows\Installer\644dce.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 166912 c:\windows\Installer\644db2.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 159232 c:\windows\Installer\644d96.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 169984 c:\windows\Installer\644d7a.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 166912 c:\windows\Installer\644d5e.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 168448 c:\windows\Installer\644d42.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 166912 c:\windows\Installer\644d26.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 161792 c:\windows\Installer\644d0a.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 161792 c:\windows\Installer\644cee.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 157696 c:\windows\Installer\644cd2.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 154112 c:\windows\Installer\644cb6.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 158208 c:\windows\Installer\644c9a.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 115712 c:\windows\Installer\644c7e.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 165888 c:\windows\Installer\644c62.msi+ 2011-07-09 07:52 . 2011-07-09 07:52 164352 c:\windows\Installer\644c46.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 514048 c:\windows\Installer\644be7.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665088 c:\windows\Installer\644bdd.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 518144 c:\windows\Installer\644bd2.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665600 c:\windows\Installer\644bc8.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 517120 c:\windows\Installer\644bbd.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 668672 c:\windows\Installer\644bb3.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 516096 c:\windows\Installer\644ba8.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 666112 c:\windows\Installer\644b9e.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 513024 c:\windows\Installer\644b93.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 664064 c:\windows\Installer\644b89.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 516096 c:\windows\Installer\644b7e.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 666624 c:\windows\Installer\644b74.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 522240 c:\windows\Installer\644b69.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 671232 c:\windows\Installer\644b5f.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 514560 c:\windows\Installer\644b54.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665600 c:\windows\Installer\644b4a.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 515584 c:\windows\Installer\644b3f.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 666112 c:\windows\Installer\644b35.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 515584 c:\windows\Installer\644b2a.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665600 c:\windows\Installer\644b20.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 512000 c:\windows\Installer\644b15.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665088 c:\windows\Installer\644b0b.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 516608 c:\windows\Installer\644b00.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 666112 c:\windows\Installer\644af6.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 517120 c:\windows\Installer\644aeb.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 667648 c:\windows\Installer\644ae1.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 513024 c:\windows\Installer\644ad6.msp+ 2012-05-22 12:18 . 2012-05-22 12:18 665088 c:\windows\Installer\644acc.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 513024 c:\windows\Installer\644ac1.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 665088 c:\windows\Installer\644ab7.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 511488 c:\windows\Installer\644aac.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 664064 c:\windows\Installer\644aa2.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 517632 c:\windows\Installer\644a97.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 667136 c:\windows\Installer\644a8d.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 514560 c:\windows\Installer\644a82.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 665088 c:\windows\Installer\644a76.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 516096 c:\windows\Installer\644a6b.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 665600 c:\windows\Installer\644a61.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 517120 c:\windows\Installer\644a56.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 669184 c:\windows\Installer\644a4c.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 517632 c:\windows\Installer\644a41.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 667136 c:\windows\Installer\644a37.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 515072 c:\windows\Installer\644a2c.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 665600 c:\windows\Installer\644a22.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 510976 c:\windows\Installer\644a17.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 664576 c:\windows\Installer\644a0b.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 509440 c:\windows\Installer\644a00.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 667136 c:\windows\Installer\6449f6.msp+ 2012-05-22 12:17 . 2012-05-22 12:17 513024 c:\windows\Installer\6449eb.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 665600 c:\windows\Installer\6449e1.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 501760 c:\windows\Installer\6449d6.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 663040 c:\windows\Installer\6449cc.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 515072 c:\windows\Installer\6449c1.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 665600 c:\windows\Installer\6449b7.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 513536 c:\windows\Installer\6449ac.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 664576 c:\windows\Installer\6449a0.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 469504 c:\windows\Installer\644945.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 630272 c:\windows\Installer\644936.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 469504 c:\windows\Installer\644909.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 630784 c:\windows\Installer\6448fa.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 471040 c:\windows\Installer\6448cd.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 631808 c:\windows\Installer\6448be.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 470016 c:\windows\Installer\644891.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 631808 c:\windows\Installer\644882.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 468992 c:\windows\Installer\644855.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 628736 c:\windows\Installer\644846.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 470016 c:\windows\Installer\644819.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 630784 c:\windows\Installer\64480a.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 472064 c:\windows\Installer\6447dd.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 635392 c:\windows\Installer\6447ce.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 469504 c:\windows\Installer\6447a1.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 630784 c:\windows\Installer\644792.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 469504 c:\windows\Installer\644765.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 629760 c:\windows\Installer\644756.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 469504 c:\windows\Installer\644729.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 631296 c:\windows\Installer\64471a.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 468480 c:\windows\Installer\6446ed.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 628224 c:\windows\Installer\6446de.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 469504 c:\windows\Installer\6446b1.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 630784 c:\windows\Installer\6446a2.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 470528 c:\windows\Installer\644675.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 633344 c:\windows\Installer\644666.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 468992 c:\windows\Installer\644639.msp+ 2012-05-22 12:15 . 2012-05-22 12:15 630784 c:\windows\Installer\64462a.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 468992 c:\windows\Installer\6445fd.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 630272 c:\windows\Installer\6445ee.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 468992 c:\windows\Installer\6445c1.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 628224 c:\windows\Installer\6445b2.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 470528 c:\windows\Installer\644585.msp+ 2012-05-22 12:14 . 2012-05-22 12:14 632832 c:\windows\Installer\644576.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 468992 c:\windows\Installer\644549.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 630272 c:\windows\Installer\64453a.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 469504 c:\windows\Installer\64450d.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 630784 c:\windows\Installer\6444fe.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 471040 c:\windows\Installer\6444d1.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 633856 c:\windows\Installer\6444c2.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 469504 c:\windows\Installer\644495.msp+ 2012-05-22 12:13 . 2012-05-22 12:13 632832 c:\windows\Installer\644486.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 469504 c:\windows\Installer\644459.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 630272 c:\windows\Installer\64444a.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 468992 c:\windows\Installer\64441d.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 627712 c:\windows\Installer\64440e.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 469504 c:\windows\Installer\6443e1.msp+ 2012-05-22 12:12 . 2012-05-22 12:12 628736 c:\windows\Installer\6443d2.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 469504 c:\windows\Installer\6443a5.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 628736 c:\windows\Installer\644396.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 467968 c:\windows\Installer\644369.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 624640 c:\windows\Installer\64435a.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 469504 c:\windows\Installer\64432d.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 629248 c:\windows\Installer\64431e.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 468992 c:\windows\Installer\6442f1.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 629248 c:\windows\Installer\6442e2.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 715264 c:\windows\Installer\64425d.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 136704 c:\windows\Installer\64423f.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 429056 c:\windows\Installer\64423a.msi+ 2012-05-22 12:56 . 2012-05-22 12:56 634368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\7efc478aa653514837fa2d9f74abc242\WindowsLiveLocal.WriterPlugin.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 665600 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c38f725098b88c724d07b0a63f7d9a4d\WindowsLive.Writer.Interop.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 326144 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\befcde61587ee64fa3cbb00a2a49eb4c\WindowsLive.Writer.SpellChecker.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 871424 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\aba4c14578df5a2a2bdb905526071b80\WindowsLive.Writer.BlogClient.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 119296 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a9f7a39a31fa323327626c240f2bcebd\WindowsLive.Writer.FileDestinations.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 328192 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8d3d296f70fd964569a1981dfbf9ac8a\WindowsLive.Writer.Mshtml.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 146432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7868ce7aef400105ccd415151a24053e\WindowsLive.Writer.Instrumentation.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 156672 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\68e3097a2465cdbc3d61b919c309ce0a\WindowsLive.Writer.HtmlParser.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 122368 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\608f6c85c4d0ef4e5d4f2e91a1e9fc5e\WindowsLive.Writer.Extensibility.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 374272 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\315bb426fe9c648562b1ead5e3cd989d\WindowsLive.Writer.Interop.Mshtml.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 101376 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0eb76e19a15d656f3adde39c356e517a\WindowsLive.Writer.Api.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 780800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0a9d8902040b30058cf7c6b7f704742e\WindowsLive.Writer.Controls.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 174080 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\09da25dea37a498b6f3b894b20fe456c\WindowsLive.Writer.BrowserControl.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 891392 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\0252d2ef3f2e54b65ce297115c7a9adb\WindowsLive.Writer.HtmlEditor.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\4ae7969274514f9b8e90ae2e278f6048\WindowsLive.Client.ni.dll+ 2012-01-29 19:59 . 2012-05-22 19:40 2000000 c:\windows\system32\HJSMEM\HJSMEM1.DAT- 2012-01-29 19:59 . 2012-05-22 10:13 2000000 c:\windows\system32\HJSMEM\HJSMEM1.DAT+ 2012-05-22 12:21 . 2012-05-22 12:21 2631168 c:\windows\Installer\645158.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2146304 c:\windows\Installer\64513e.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4250112 c:\windows\Installer\645133.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 4175360 c:\windows\Installer\645128.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 3410944 c:\windows\Installer\64511e.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 5124096 c:\windows\Installer\645118.msp+ 2012-02-19 19:15 . 2012-02-19 19:15 6661632 c:\windows\Installer\64510e.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1070592 c:\windows\Installer\6450fa.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1492992 c:\windows\Installer\6450ed.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\6450dd.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2632704 c:\windows\Installer\6450d9.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\6450d5.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\6450d1.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2632704 c:\windows\Installer\6450cd.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\6450c9.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2634240 c:\windows\Installer\6450c5.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450c1.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2632704 c:\windows\Installer\6450bd.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450b9.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2632704 c:\windows\Installer\6450b5.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450b1.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\6450ad.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450a9.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450a5.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\6450a1.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\64509d.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\645099.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633216 c:\windows\Installer\645095.msi+ 2012-05-22 12:21 . 2012-05-22 12:21 2633728 c:\windows\Installer\645091.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633728 c:\windows\Installer\64508d.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633216 c:\windows\Installer\645089.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2632704 c:\windows\Installer\645085.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633216 c:\windows\Installer\645081.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633216 c:\windows\Installer\64507d.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2632192 c:\windows\Installer\645079.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633216 c:\windows\Installer\645075.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2633216 c:\windows\Installer\645071.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2148352 c:\windows\Installer\644f36.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 4287488 c:\windows\Installer\644f2b.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2147328 c:\windows\Installer\644f1a.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4243968 c:\windows\Installer\644f0f.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2150912 c:\windows\Installer\644efe.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4282368 c:\windows\Installer\644ef3.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2149888 c:\windows\Installer\644ee2.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4268032 c:\windows\Installer\644ed7.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2146816 c:\windows\Installer\644ec6.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4260352 c:\windows\Installer\644ebb.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2150400 c:\windows\Installer\644eaa.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4297216 c:\windows\Installer\644e9f.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2152448 c:\windows\Installer\644e8c.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4307456 c:\windows\Installer\644e81.msi+ 2012-05-22 12:20 . 2012-05-22 12:20 2148864 c:\windows\Installer\644e70.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4283392 c:\windows\Installer\644e65.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2148864 c:\windows\Installer\644e54.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4268032 c:\windows\Installer\644e49.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2149888 c:\windows\Installer\644e38.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 4293632 c:\windows\Installer\644e2d.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2147840 c:\windows\Installer\644e1c.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4230656 c:\windows\Installer\644e11.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2148864 c:\windows\Installer\644e00.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4271104 c:\windows\Installer\644df5.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2149376 c:\windows\Installer\644de4.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4278272 c:\windows\Installer\644dd9.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2148352 c:\windows\Installer\644dc8.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4275712 c:\windows\Installer\644dbd.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2146816 c:\windows\Installer\644dac.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4278272 c:\windows\Installer\644da1.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2146816 c:\windows\Installer\644d90.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4259328 c:\windows\Installer\644d85.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2150912 c:\windows\Installer\644d74.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4282368 c:\windows\Installer\644d69.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2147328 c:\windows\Installer\644d58.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4274176 c:\windows\Installer\644d4d.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2150400 c:\windows\Installer\644d3c.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4281344 c:\windows\Installer\644d31.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2150400 c:\windows\Installer\644d20.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4271616 c:\windows\Installer\644d15.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2148864 c:\windows\Installer\644d04.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4271104 c:\windows\Installer\644cf9.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2149376 c:\windows\Installer\644ce8.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4265984 c:\windows\Installer\644cdd.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2147328 c:\windows\Installer\644ccc.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4261376 c:\windows\Installer\644cc1.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2145280 c:\windows\Installer\644cb0.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4246016 c:\windows\Installer\644ca5.msi+ 2012-05-22 12:19 . 2012-05-22 12:19 2147328 c:\windows\Installer\644c94.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4263424 c:\windows\Installer\644c89.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 2141696 c:\windows\Installer\644c78.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4144640 c:\windows\Installer\644c6d.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 2149376 c:\windows\Installer\644c5c.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4284416 c:\windows\Installer\644c51.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 2148352 c:\windows\Installer\644c40.msp+ 2011-07-09 07:52 . 2011-07-09 07:52 4273664 c:\windows\Installer\644c35.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 3734016 c:\windows\Installer\644c2f.msp+ 2011-07-09 07:53 . 2011-07-09 07:53 5923328 c:\windows\Installer\644be2.msi+ 2011-07-09 07:53 . 2011-07-09 07:53 5109760 c:\windows\Installer\644bd8.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 4169216 c:\windows\Installer\644bcd.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 5915648 c:\windows\Installer\644bb8.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 5202432 c:\windows\Installer\644bae.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 7407616 c:\windows\Installer\644ba3.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 6635008 c:\windows\Installer\644b99.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 4201984 c:\windows\Installer\644b8e.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 3419136 c:\windows\Installer\644b84.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 9250816 c:\windows\Installer\644b79.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 8424448 c:\windows\Installer\644b6f.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 5693952 c:\windows\Installer\644b64.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 4951552 c:\windows\Installer\644b5a.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 6767616 c:\windows\Installer\644b4f.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 5947392 c:\windows\Installer\644b45.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5425664 c:\windows\Installer\644b3a.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4747776 c:\windows\Installer\644b30.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6484480 c:\windows\Installer\644b25.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5652992 c:\windows\Installer\644b1b.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 9312768 c:\windows\Installer\644b10.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 8612864 c:\windows\Installer\644b06.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5084160 c:\windows\Installer\644afb.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4322304 c:\windows\Installer\644af1.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5364736 c:\windows\Installer\644ae6.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4645888 c:\windows\Installer\644adc.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6628864 c:\windows\Installer\644ad1.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5819392 c:\windows\Installer\644ac7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6219776 c:\windows\Installer\644abc.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5416448 c:\windows\Installer\644ab2.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4184064 c:\windows\Installer\644aa7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 3415040 c:\windows\Installer\644a9d.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 7579648 c:\windows\Installer\644a92.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6774784 c:\windows\Installer\644a88.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5812224 c:\windows\Installer\644a7b.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5011456 c:\windows\Installer\644a71.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 5616640 c:\windows\Installer\644a66.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4918272 c:\windows\Installer\644a5c.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6745088 c:\windows\Installer\644a51.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 6001664 c:\windows\Installer\644a47.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4824576 c:\windows\Installer\644a3c.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4079104 c:\windows\Installer\644a32.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 5384704 c:\windows\Installer\644a27.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 4652032 c:\windows\Installer\644a1d.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 6957568 c:\windows\Installer\644a10.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 6179328 c:\windows\Installer\644a06.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 4169216 c:\windows\Installer\6449fb.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 3509760 c:\windows\Installer\6449f1.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 5568512 c:\windows\Installer\6449e6.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 4805120 c:\windows\Installer\6449dc.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 3957760 c:\windows\Installer\6449d1.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 3406336 c:\windows\Installer\6449c7.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 6159872 c:\windows\Installer\6449bc.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 5335552 c:\windows\Installer\6449b2.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 7898112 c:\windows\Installer\6449a5.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 8030720 c:\windows\Installer\64499a.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 2957312 c:\windows\Installer\644995.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 8313856 c:\windows\Installer\64497b.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5868544 c:\windows\Installer\644976.msp+ 2012-05-22 12:16 . 2012-05-22 12:16 5126656 c:\windows\Installer\644959.msp+ 2012-02-19 19:04 . 2012-02-19 19:04 6696448 c:\windows\Installer\64494f.msi+ 2011-07-09 07:53 . 2011-07-09 07:53 1075200 c:\windows\Installer\64493b.msi+ 2011-07-09 07:53 . 2011-07-09 07:53 1528832 c:\windows\Installer\64492e.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5126656 c:\windows\Installer\64491d.msp+ 2012-02-19 19:03 . 2012-02-19 19:03 6653440 c:\windows\Installer\644913.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1076224 c:\windows\Installer\6448ff.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1531392 c:\windows\Installer\6448f2.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5128704 c:\windows\Installer\6448e1.msp+ 2012-02-19 19:03 . 2012-02-19 19:03 6685184 c:\windows\Installer\6448d7.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1082880 c:\windows\Installer\6448c3.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1559040 c:\windows\Installer\6448b6.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5129216 c:\windows\Installer\6448a5.msp+ 2012-02-19 19:03 . 2012-02-19 19:03 6683648 c:\windows\Installer\64489b.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1078272 c:\windows\Installer\644887.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1522176 c:\windows\Installer\64487a.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5125632 c:\windows\Installer\644869.msp+ 2012-02-19 19:03 . 2012-02-19 19:03 6676992 c:\windows\Installer\64485f.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1072128 c:\windows\Installer\64484b.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1512448 c:\windows\Installer\64483e.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5129728 c:\windows\Installer\64482d.msp+ 2012-02-19 19:03 . 2012-02-19 19:03 6713856 c:\windows\Installer\644823.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1077760 c:\windows\Installer\64480f.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1509888 c:\windows\Installer\644802.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5132288 c:\windows\Installer\6447f1.msp+ 2012-02-19 19:02 . 2012-02-19 19:02 6729728 c:\windows\Installer\6447e7.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1090560 c:\windows\Installer\6447d3.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1590784 c:\windows\Installer\6447c6.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5126656 c:\windows\Installer\6447b5.msp+ 2012-02-19 19:02 . 2012-02-19 19:02 6697984 c:\windows\Installer\6447ab.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1076224 c:\windows\Installer\644797.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1523200 c:\windows\Installer\64478a.msi+ 2012-05-22 12:16 . 2012-05-22 12:16 5127168 c:\windows\Installer\644779.msp+ 2012-02-19 19:02 . 2012-02-19 19:02 6676480 c:\windows\Installer\64476f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1073664 c:\windows\Installer\64475b.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 1522176 c:\windows\Installer\64474e.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 5127680 c:\windows\Installer\64473d.msp+ 2012-02-19 19:01 . 2012-02-19 19:01 6704640 c:\windows\Installer\644733.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1077248 c:\windows\Installer\64471f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1530880 c:\windows\Installer\644712.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 5125120 c:\windows\Installer\644701.msp+ 2012-02-19 19:01 . 2012-02-19 19:01 6633984 c:\windows\Installer\6446f7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1074176 c:\windows\Installer\6446e3.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1518080 c:\windows\Installer\6446d6.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 5128192 c:\windows\Installer\6446c5.msp+ 2012-02-19 19:00 . 2012-02-19 19:00 6678528 c:\windows\Installer\6446bb.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1074688 c:\windows\Installer\6446a7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1516544 c:\windows\Installer\64469a.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 5130240 c:\windows\Installer\644689.msp+ 2012-02-19 19:00 . 2012-02-19 19:00 6705152 c:\windows\Installer\64467f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1080832 c:\windows\Installer\64466b.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1534976 c:\windows\Installer\64465e.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 5126656 c:\windows\Installer\64464d.msp+ 2012-02-19 18:59 . 2012-02-19 18:59 6697984 c:\windows\Installer\644643.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1074176 c:\windows\Installer\64462f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1532416 c:\windows\Installer\644622.msi+ 2012-05-22 12:15 . 2012-05-22 12:15 4302336 c:\windows\Installer\644611.msp+ 2012-02-19 18:59 . 2012-02-19 18:59 5864960 c:\windows\Installer\644607.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1073664 c:\windows\Installer\6445f3.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1524736 c:\windows\Installer\6445e6.msi+ 2012-05-22 12:14 . 2012-05-22 12:14 5125632 c:\windows\Installer\6445d5.msp+ 2012-02-19 18:59 . 2012-02-19 18:59 6668800 c:\windows\Installer\6445cb.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1073152 c:\windows\Installer\6445b7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1502208 c:\windows\Installer\6445aa.msi+ 2012-05-22 12:14 . 2012-05-22 12:14 5129728 c:\windows\Installer\644599.msp+ 2012-02-19 18:59 . 2012-02-19 18:59 6699008 c:\windows\Installer\64458f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1080320 c:\windows\Installer\64457b.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1529344 c:\windows\Installer\64456e.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 5126656 c:\windows\Installer\64455d.msp+ 2012-02-19 18:58 . 2012-02-19 18:58 6682624 c:\windows\Installer\644553.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1073664 c:\windows\Installer\64453f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1526784 c:\windows\Installer\644532.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 5128192 c:\windows\Installer\644521.msp+ 2012-02-19 18:58 . 2012-02-19 18:58 6693888 c:\windows\Installer\644517.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1075712 c:\windows\Installer\644503.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1525760 c:\windows\Installer\6444f6.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 5129728 c:\windows\Installer\6444e5.msp+ 2012-02-19 18:58 . 2012-02-19 18:58 6693888 c:\windows\Installer\6444db.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1096704 c:\windows\Installer\6444c7.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1569280 c:\windows\Installer\6444ba.msi+ 2012-05-22 12:13 . 2012-05-22 12:13 5128192 c:\windows\Installer\6444a9.msp+ 2012-02-19 18:57 . 2012-02-19 18:57 6683136 c:\windows\Installer\64449f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1074176 c:\windows\Installer\64448b.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1526784 c:\windows\Installer\64447e.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 5127168 c:\windows\Installer\64446d.msp+ 2012-02-19 18:57 . 2012-02-19 18:57 6679552 c:\windows\Installer\644463.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1072640 c:\windows\Installer\64444f.msi+ 2011-07-09 07:50 . 2011-07-09 07:50 1517568 c:\windows\Installer\644442.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 5125632 c:\windows\Installer\644431.msp+ 2012-02-19 18:57 . 2012-02-19 18:57 6674432 c:\windows\Installer\644427.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1072640 c:\windows\Installer\644413.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1515008 c:\windows\Installer\644406.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 5125120 c:\windows\Installer\6443f5.msp+ 2012-02-19 18:57 . 2012-02-19 18:57 6654464 c:\windows\Installer\6443eb.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1088512 c:\windows\Installer\6443d7.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1576960 c:\windows\Installer\6443ca.msi+ 2012-05-22 12:12 . 2012-05-22 12:12 5126144 c:\windows\Installer\6443b9.msp+ 2012-02-19 18:56 . 2012-02-19 18:56 6669312 c:\windows\Installer\6443af.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1072640 c:\windows\Installer\64439b.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1519616 c:\windows\Installer\64438e.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 5120000 c:\windows\Installer\64437d.msp+ 2012-02-19 18:56 . 2012-02-19 18:56 6533120 c:\windows\Installer\644373.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1057792 c:\windows\Installer\64435f.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1470464 c:\windows\Installer\644352.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 5126656 c:\windows\Installer\644341.msp+ 2012-02-19 18:56 . 2012-02-19 18:56 6697984 c:\windows\Installer\644337.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1076736 c:\windows\Installer\644323.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1516544 c:\windows\Installer\644316.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 5126144 c:\windows\Installer\644305.msp+ 2012-02-19 18:55 . 2012-02-19 18:55 6688256 c:\windows\Installer\6442fb.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1074688 c:\windows\Installer\6442e7.msi+ 2011-07-09 07:51 . 2011-07-09 07:51 1519104 c:\windows\Installer\6442d9.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 5535744 c:\windows\Installer\6442c8.msp+ 2012-05-22 12:11 . 2012-05-22 12:11 3312128 c:\windows\Installer\6442ae.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 8332288 c:\windows\Installer\644292.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 2932224 c:\windows\Installer\64428a.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 7710720 c:\windows\Installer\644276.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 4426240 c:\windows\Installer\644271.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 9433088 c:\windows\Installer\644262.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 2310656 c:\windows\Installer\644255.msi+ 2012-05-22 12:11 . 2012-05-22 12:11 1139712 c:\windows\Installer\644250.msp+ 2011-07-09 07:49 . 2011-07-09 07:49 4004864 c:\windows\Installer\644244.msi+ 2012-05-22 12:56 . 2012-05-22 12:56 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f719bb2b6393ad8db17a8ce6a00405a4\WindowsLive.Writer.PostEditor.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ef19d35486d93991481aea9dff55239c\WindowsLive.Writer.ApplicationFramework.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bceb30d0438bc12bbae3b68083e0fb40\WindowsLive.Writer.Localization.ni.dll+ 2012-05-22 12:56 . 2012-05-22 12:56 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1969e87f7777f3f03f75182ee5294c67\WindowsLive.Writer.CoreServices.ni.dll+ 2011-07-09 07:51 . 2011-07-09 07:51 11846656 c:\windows\Installer\644c26.msi+ 2012-05-22 12:18 . 2012-05-22 12:18 14624256 c:\windows\Installer\644c1e.msp+ 2011-07-09 07:51 . 2011-07-09 07:51 34193408 c:\windows\Installer\644bf3.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 13157888 c:\windows\Installer\644bc3.msi+ 2011-07-09 07:49 . 2011-07-09 07:49 13850624 c:\windows\Installer\64495f.msi+ 2012-02-19 18:55 . 2012-02-19 18:55 22647296 c:\windows\Installer\6442b5.msi.-- Snapshot reset to current date --.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shownREGEDIT4.[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584].[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]"YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2011-05-11 136488]"YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCamTray.exe" [2011-09-23 165160]"IdeaCom Calibration"="c:\program files (x86)\IdeaCom\IDCMgr\StartUT.exe" [2010-03-18 270848]"Hotkey Utility"="c:\program files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2011-06-10 627304]"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]"avp"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296].[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 73216].c:\users\Shazia Begum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712].c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\MicroNEXT Wireless Utility.lnk - c:\program files (x86)\MicroNEXT\Common\RaUI.exe [2012-1-29 1828128].[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]"ConsentPromptBehaviorAdmin"= 0 (0x0)"ConsentPromptBehaviorUser"= 3 (0x3)"EnableLUA"= 0 (0x0)"EnableUIADesktopToggle"= 0 (0x0)"PromptOnSecureDesktop"= 0 (0x0).[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]"aux"=wdmaud.drv.[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]@="".[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]"DisableMonitoring"=dword:00000001.R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]R3 cphs;Intel® Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-02-14 276248]R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]R3 JTVNCProxy_13.0;JTVNCProxy_13.0;c:\program files\Freedom Scientific\JAWS\13.0\JTVNCProxy.exe [2011-12-08 19736]R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.4.0;c:\windows\system32\drivers\libusb0.sys [2011-12-20 29184]R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [x]R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]R3 PowerBrl;powerBraille System Driver;c:\windows\system32\Drivers\powerbrl.sys [x]R3 PQAWRwa;PQAWRwa;c:\windows\SysWOW64\PQAWDrv.sys [x]R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x]S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x]S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]S2 Freedom Scientific Kernel Manager;Freedom Scientific Kernel Manager;c:\windows\system32\fsKMgr.dll [x]S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2011-05-30 36456]S2 IdcSrv;IDCSRV Service;c:\program files (x86)\IdeaCom\IDCMgr\IdcSrv.exe [2011-01-06 252928]S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-04-22 244624]S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\MicroNEXT\Common\RalinkRegistryWriter64.exe [2008-09-05 210720]S2 Sentinel64;Sentinel64;c:\windows\System32\Drivers\Sentinel64.sys [x]S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [x]S3 fsvidmir_service;fsvidmir_service;c:\windows\system32\DRIVERS\fsvidmir.sys [x]S3 IdcFltr;HID Touch Screen Driver;c:\windows\system32\DRIVERS\idcfltr.sys [x]S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x]S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [x]S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]S3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;c:\windows\system32\DRIVERS\SNTUSB64.SYS [x]S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]..Contents of the 'Scheduled Tasks' folder.2012-05-22 c:\windows\Tasks\Adobe Flash Player Updater.job- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 16:29].2012-05-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-781961419-1968162369-1216944339-1000Core.job- c:\users\Shazia Begum\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-29 14:37].2012-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-781961419-1968162369-1216944339-1000UA.job- c:\users\Shazia Begum\AppData\Local\Google\Update\GoogleUpdate.exe [2012-01-29 14:37]..--------- x86-64 -----------..[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"TouchORB"="c:\program files (x86)\TouchSettings\TouchPortalOBR.exe" [2010-05-06 153416]"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-23 11725928]"Acer PowerSaver"="c:\program files\Acer\Acer PowerSaver\PowerSaverTray.exe" [2011-09-06 545680]"JAWS"="c:\program files\Freedom Scientific\JAWS\13.0\jfw.exe" [2011-12-08 6834968]"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-02-14 170264]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-02-14 398616]"Persistence"="c:\windows\system32\igfxpers.exe" [2012-02-14 440600]"combofix"="c:\combofix\CF32613.3XE" [2010-11-21 345088].------- Supplementary Scan -------.uStart Page = about:blankuLocal Page = c:\windows\system32\blank.htmmStart Page = about:blankmLocal Page = c:\windows\SysWOW64\blank.htmIE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htmIE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office14\EXCEL.EXE/3000IE: Free YouTube Download - c:\users\Shazia Begum\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htmIE: Se&nd to OneNote - c:\progra~2\MICROS~4\Office14\ONBttnIE.dll/105TCP: DhcpNameServer = 192.168.0.1TCP: Interfaces\{B887273F-390E-48B5-AC65-A19E4D9A682A}: NameServer = 8.26.56.26,156.154.70.22TCP: Interfaces\{D9DA8EA3-8033-4A15-9A19-E500C47C0069}: NameServer = 8.26.56.26,156.154.70.22.- - - - ORPHANS REMOVED - - - -.Toolbar-Locked - (no file)WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)...--------------------- LOCKED REGISTRY KEYS ---------------------.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]@Denied: (A 2) (Everyone)@="FlashBroker""LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]"Enabled"=dword:00000001.[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Shockwave Flash Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]@="0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]@="ShockwaveFlash.ShockwaveFlash.11".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="ShockwaveFlash.ShockwaveFlash".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]@Denied: (A 2) (Everyone)@="Macromedia Flash Factory Object".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx""ThreadingModel"="Apartment".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]@="FlashFactory.FlashFactory.1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]@="{D27CDB6B-AE6D-11cf-96B8-444553540000}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]@="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]@="FlashFactory.FlashFactory".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]@Denied: (A 2) (Everyone)@="IFlashBroker4".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]@="{00020424-0000-0000-C000-000000000046}".[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}""Version"="1.0".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]@Denied: (A) (Everyone)"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}".[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]@Denied: (A) (Everyone).[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]"Key"="ActionsPane3""Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd".[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]@Denied: (Full) (Everyone).------------------------ Other Running Processes ------------------------.c:\program files (x86)\MicroNEXT\Common\RalinkRegistryWriter.exec:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exec:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exec:\users\Shazia Begum\AppData\Local\Google\Chrome\Application\chrome.exe.**************************************************************************.Completion time: 2012-05-22 20:42:54 - machine was rebootedComboFix-quarantined-files.txt 2012-05-22 19:42ComboFix2.txt 2012-05-22 10:29.Pre-Run: 422,480,089,088 bytes freePost-Run: 422,434,344,960 bytes free.- - End Of File - - CB70B3F7ADD1266921BA8AAC2F49CD13 Share this post Link to post Share on other sites
D-FRED-BROWN #7 Posted May 22, 2012 Before we move on to the next step, how are things running now? Are you still getting the random survey sites? Please let me know . Share this post Link to post Share on other sites
Alikhan #8 Posted May 22, 2012 Yes, there are still some survery sites as well as another rogue which malwarebytes deleted today. Strange thing is malwarebytes doesn't save the logs. Also it is running quiet slower than before the infection. Share this post Link to post Share on other sites
D-FRED-BROWN #9 Posted May 22, 2012 Go ahead and run a Full Scan with Malwarebytes. Please Launch Malwarebytes' Anti-Malware.Please click Check for Updates to see if any updates are found. If so, please allow MBAM to download and install them.Once the program has loaded, select Perform full scan, then click Scan.When the scan is complete, click OK, then Show Results to view the results.Be sure that everything is checked, and click Remove Selected.When completed, a log will open in Notepad. Please save it to a location you will remember. Copy and Paste that log into your next reply.Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.Click OK for either of the prompts and let MBAM proceed with the disinfection process.If asked to restart the computer, please do so immediately. Share this post Link to post Share on other sites
Alikhan #10 Posted May 23, 2012 Malwarebytes Anti-Malware (PRO) 1.61.0.1400www.malwarebytes.orgDatabase version: v2012.05.23.04Windows 7 Service Pack 1 x64 NTFSInternet Explorer 9.0.8112.16421Shazia Begum :: SHAZIABEGUM-PC [administrator]Protection: Enabled23/05/2012 12:55:05mbam-log-2012-05-23 (12-55-05).txtScan type: Full scanScan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUMScan options disabled: P2PObjects scanned: 319841Time elapsed: 27 minute(s), 35 second(s)Memory Processes Detected: 0(No malicious items detected)Memory Modules Detected: 0(No malicious items detected)Registry Keys Detected: 0(No malicious items detected)Registry Values Detected: 0(No malicious items detected)Registry Data Items Detected: 0(No malicious items detected)Folders Detected: 0(No malicious items detected)Files Detected: 0(No malicious items detected)(end) Share this post Link to post Share on other sites
D-FRED-BROWN #11 Posted May 23, 2012 Let's use Kaspersky Virus Removal Tool to take a deeper look at what may be causing the problems .Please click here to download AVP Tool by Kaspersky.Save it to your desktop.Double click the setup file to run it.Click Next to continue.It will by default install it to your desktop folder. Click Next.It will then open a box. There will be a tab that says "Autoscan"Under Autoscan, make sure these are checked.System MemoryHidden startup ObjectsDisk Boot Sectors.My Computer.Also any other drives (Removable that you may have) After that click on Recommended to the right of Security level then choose settings then click on the tab that says Additional then under Rootkit scan choose Deep scan then choose OK.Then,Click on Start Scan at the to right hand corner.It will automatically Neutralize any objects found.If some objects are left un-neutralized then click the button that says Neutralize allIf it says it cannot be Neutralized, choose the Delete option when prompted.After that is done click on the Reports button at the bottom and save it to file name it Kas.Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report. It will be at the very top under Detected Please post those results in your next reply. How are things running now? Share this post Link to post Share on other sites
Alikhan #12 Posted May 23, 2012 Kaspersky found nothing. The computer is fine now, thanks for the help. Share this post Link to post Share on other sites
D-FRED-BROWN #13 Posted May 23, 2012 That is good news! Let's run an online scan to verify that there's no traces left that we may have missed:Please run a free online scan with the ESET Online ScannerNote: You will need to use Internet Explorer for this scan.Tick the box next to YES, I accept the Terms of Use.Click StartWhen asked, allow the ActiveX control to installClick StartMake sure that the options Remove found threats is Unchecked and the option Scan unwanted applications is checkedClick Scan Wait for the scan to finishUse Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txtCopy and paste that log as a reply to this topicPlease post that log in your next reply, and let me know how things go . Share this post Link to post Share on other sites
Alikhan #14 Posted May 24, 2012 Found nothing. Comp is all fine.ESETSmartInstaller@High as CAB hook log:OnlineScanner64.ocx - registred OKOnlineScanner.ocx - registred OK# version=7# iexplore.exe=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)# OnlineScanner.ocx=1.0.0.6583# api_version=3.0.2# EOSSerial=9b6a79c961480144a70784f8bea0ed10# end=finished# remove_checked=true# archives_checked=false# unwanted_checked=true# unsafe_checked=false# antistealth_checked=true# utc_time=2012-05-24 12:17:51# local_time=2012-05-24 01:17:51 (+0000, GMT Daylight Time)# country="United Kingdom"# lang=1033# osver=6.1.7601 NT Service Pack 1# compatibility_mode=1280 16777215 100 0 244436 244436 0 0# compatibility_mode=5893 16776574 100 94 3885018 90323669 0 0# compatibility_mode=8192 67108863 100 0 48138 48138 0 0# scanned=122758# found=0# cleaned=0# scan_time=3252 Share this post Link to post Share on other sites
D-FRED-BROWN #15 Posted May 24, 2012 Looking much better ,Before we move on, let's update some of your programs.Program updates are a crucial step in preventing malware, as outdated applications are often used by the cybercriminals to gain a foothold on your system.First,I see you have User Accounts Control (UAC) disabled. This is an important security feature which helps prevent malware and other unwanted software from being installed on your computer.I strongly suggest you keep it enabled. See this link for instructions on how to enable it: http://windows.microsoft.com/en-US/windows-vista/Turn-User-Account-Control-on-or-off -----------Java is out of date and older versions contain vulnerabilities. Please update to the newest version.Download the newest version from here http://www.oracle.com/technetwork/java/javase/downloads/index.html.It's important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.Go to Start > Control Panel and open Add or Remove Programs.Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). They will have this icon next to them: Select each in turn and click Remove.Once old versions are gone, please install the newest version.-----------Let me know how the program updates go, as failed updates may be a sign of additional malware. Share this post Link to post Share on other sites
Alikhan #16 Posted May 24, 2012 I've removed Java completely since I do not need it. I'm leaving UAC disabled because it bugs me with my games/software etc because it gets annoying. Share this post Link to post Share on other sites
D-FRED-BROWN #17 Posted May 24, 2012 Sounds good. Unless there are any further issues, I will now provide you with some suggestions for security software.First, let's remove ComboFix:The following will implement some cleanup procedures as well as reset System Restore points:Click Start > Run and copy/paste the following bolded text into the Run box and click OK:ComboFix /Uninstall -------------Please consider using these ideas to help secure your computer. While there is no way to guarantee safety when you use a computer, these steps will make it much less likely that you will need to endure another infection. While we really like to help people, we would rather help you protect yourself so that you won't need that help in the future. Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates or get into the habit of checking Windows Update regularly. They usually have security updates every month. You can set Windows to notify you of Updates so that you can choose, but only do this if you believe you are able to understand which ones are needed. This is a crucial security measure.It is really dangerous to go online without an antivirus. Without one, you are extremely likely to get infected and the consequences could be even worse next time. All of the following are excellent free antiviruses. Be sure to only install one.avast!.AntiVirAVGPlease consider installing and running some of the following programs; they are either free or have free versions of commercial programs:Spybot-Search & DestroyA tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features if you don't have the resident part of another anti-spyware program running.SpywareBlasterA tutorial on using SpywareBlaster to prevent malware from ever installing on your computer may be found here.SpywareGuardA tutorial on using SpywareGuard for real-time protection against spyware and hijackers may be found here.Please, consider maintaining a firewall with HIPS (Host Intrusion Prevention Systems). Firewalls are extremely important and are the first part of your computer's defense. HIPS stops malware by monitoring its behavior and it's very important, too. A firewall is a software program or piece of hardware that helps screen out hackers, viruses, and worms that try to reach your computer over the Internet.If you are using the Windows Firewall please note that it doesn't monitor or block outbound traffic and is therefore less effective than other free alternatives.These firewalls are good and do have free versions available Outpost Firewall Free Online Armor FirewallA tutorial on understanding and using firewalls may be found here.If you use Internet Explorer, it is a good idea to use IE-Spyad for ZonedOut which provides protections against malicious websites. (Requires 2 downloads)Please keep these programs up-to-date and run them whenever you suspect a problem to prevent malware problems. A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall and scanning anti-spyware program at a time. Passive protectors, like SpywareBlaster and IE-Spyad can be run with any of them. Note that there are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:http://www.spywarewarrior.com/rogue_anti-spyware.htmA similar category of programs is now called "scareware." Scareware programs are active infections that will pop-up on your computer and tell you that you are infected. If you look closely, it will usually have a name that looks like it might be legitimate, but it is NOT one of the programs you installed. It tells you to click and install it right away. If you click on any part of it, including the 'X' to close it, you may actually help it infect your computer further. Keeping protection updated and running resident protection can help prevent these infections. If it happens anyway, get offline as quickly as you can. Pull the internet connection cable or shut down the computer if you have to. Contact someone to help by using another computer if possible. These programs are also sometimes called 'rogues', but they are different than the older version of rogues mentioned above.Please consider using an alternate browser. Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScripts, can make it even more secure. Opera is another good option.If you are interested, Firefox may be downloaded from hereOpera is available here: http://www.opera.com/download/For much more useful information, please also read Tony Klein's excellent article: How did I get infected in the first placeHopefully these steps will help to keep you error free. If you run into more difficulty, we will certainly do what we can to help. Share this post Link to post Share on other sites
Alikhan #18 Posted May 24, 2012 Thanks computer is fine now. I'm happy with Kaspersky firewall. Share this post Link to post Share on other sites
D-FRED-BROWN #19 Posted May 24, 2012 Glad to hear things are well! If you have any other questions or concerns, don't hesitate to ask. Otherwise, I will have this thread closed. You can still reach me by private message here on the site if you need anything. Kind regards,-DFB Share this post Link to post Share on other sites
LDTate #20 Posted May 30, 2012 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Share this post Link to post Share on other sites