Jump to content

Freezing or extremely slow at start up - possible infection or ?


Recommended Posts

Hi,

I opened a help request in the PC section and AdvancedSetup recommended posting here (see post http://forums.malwarebytes.org/index.php?showtopic=126900).

Initially my computer was freezing or hanging after start up. I couldn't click on any programs or bring up the task manager. It started out happening infrequently when I would first start the computer. It would boot up normally but when I tried to start a program it would freeze and the only thing I could do was power off and restart. Now it will boot in normal mode but it takes a very long time before I can click on anything. When I boot in safe mode, everything appears to be okay. Recently, I can't print certain messages from Outlook it will freeze. I can't upgrade to the newest version of Dell DataSafe Local Back up since KIS continues to block it. I ran both Malwarebytes and KIS but nothing was found. I'm not tech savvy but could KIS be the problem? I installed it when I first got the computer but didn't know how to set any of the parameters.

I have the following:

Windows 7 Professional

OS - 64-bit

Processor - Intel Core i7-2600CPU @ 3.40GHz

Installed memory - 8GB

Programs installed:

Malwarebytes Pro

KIS 2012

Spywareblaster

Any help would be greatly appreciated. Thank you!

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 10.0.9200.16576

Run by Joan at 17:04:03 on 2013-05-27

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8174.6348 [GMT -10:00]

.

AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}

SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe

C:\Windows\system32\nvvsvc.exe

C:\Windows\system32\WLANExt.exe

C:\Windows\System32\spoolsv.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\System32\svchost.exe -k NetworkService

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe

C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe

C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe

C:\Windows\System32\svchost.exe -k HPZ12

C:\Program Files (x86)\Secunia\PSI\PSIA.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Windows\system32\svchost.exe -k imgsvc

C:\Windows\System32\svchost.exe -k secsvcs

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\Windows\System32\rundll32.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe

C:\ProgramData\Clickfree\cfagent.exe

C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\System32\WUDFHost.exe

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\System32\svchost.exe -k LocalServicePeerNet

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

C:\Windows\system32\svchost.exe -k SDRSVC

C:\Program Files (x86)\Nero\Update\NASvc.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe

C:\Windows\system32\taskeng.exe

C:\Windows\system32\taskhost.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://google.com/

BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll

BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll

BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll

BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -

uRun: [ClickfreeMonitor] c:\programdata\Clickfree\cfagent.exe

uRun: [Google Update] "C:\Users\Joan\AppData\Local\Google\Update\GoogleUpdate.exe" /c

mRun: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe"

mRun: [updReg] C:\Windows\UpdReg.EXE

mRun: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r

mRun: [shwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

mRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

mRun: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe

mRun: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

dRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe

uPolicies-Explorer: NoDrives = dword:0

mPolicies-Explorer: NoDriveTypeAutoRun = dword:60

mPolicies-Explorer: NoDrives = dword:0

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

IE: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm

IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll

IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - <orphaned>

IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll

.

INFO: HKCU has more than 50 listed domains.

If you wish to scan all of them, select the 'Force scan all domains' option.

.

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab

DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab

DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab

TCP: NameServer = 24.25.227.55 209.18.47.61 24.25.227.53

TCP: Interfaces\{BC9B2C09-33F7-4C59-84D0-F2DADAB64F16} : DHCPNameServer = 24.25.227.55 209.18.47.61 24.25.227.53

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

SSODL: WebCheck - <orphaned>

SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: IEVkbdBHO Class: {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll

x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

x64-BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL

x64-BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} -

x64-BHO: FilterBHO Class: {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll

x64-Run: [RunDLLEntry_THXCfg] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\THXCfg64.dll,RunDLLEntry THXCfg64

x64-Run: [RunDLLEntry_EptMon] C:\Windows\System32\RunDLL32.exe C:\Windows\System32\EptMon64.dll,RunDLLEntry EptMon64

x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s

x64-Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup

x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll

x64-IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\ievkbd.dll

x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

x64-IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x64\klwtbbho.dll

x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

x64-DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_07-windows-i586.cab

x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL

x64-Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - <orphaned>

x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>

x64-Notify: klogon - C:\Windows\System32\klogon.dll

x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\5uuc71d5.default-1344114154362\

FF - prefs.js: browser.startup.homepage - google.com

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll

FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrlui.dll

FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

FF - plugin: C:\Users\Joan\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll

FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll

FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

.

============= SERVICES / DRIVERS ===============

.

R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2011-8-29 55856]

R1 kl2;kl2;C:\Windows\System32\drivers\kl2.sys [2011-3-4 11864]

R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\System32\drivers\klim6.sys [2011-3-10 29488]

R2 AVP;Kaspersky Anti-Virus Service;C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [2011-4-24 206448]

R2 BBSvc;BingBar Service;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [2012-6-11 193616]

R2 FibUacService;FibUacService;C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe [2012-12-20 37192]

R2 FullImagingService;FullImagingService;C:\ProgramData\Clickfree\FullImagingBackup\FullImagingService.exe [2012-12-20 201544]

R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-8-29 13336]

R2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-8-23 13672]

R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-11-25 687400]

R2 NOBU;Dell DataSafe Online;C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe [2010-8-25 2823000]

R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2011-4-18 993848]

R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2011-8-29 1692480]

R3 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [2012-6-11 240208]

R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-8-29 317440]

R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2011-8-29 406056]

R3 klmouflt;Kaspersky Lab KLMOUFLT;C:\Windows\System32\drivers\klmouflt.sys [2009-11-2 22544]

R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2010-8-31 17976]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-10 418376]

S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-10 701512]

S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-20 71168]

S3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2011-8-29 158976]

S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-1-31 25928]

S3 netvsc;netvsc;C:\Windows\System32\drivers\netvsc60.sys [2010-11-20 168448]

S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 SynthVid;SynthVid;C:\Windows\System32\drivers\VMBusVideoM.sys [2010-11-20 22528]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2011-9-4 1255736]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2013-05-24 21:45:42 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{43D1A9EC-4FB8-4CA6-9E7B-BB6C78F7BA17}\mpengine.dll

2013-05-22 21:45:52 262552 ----a-w- C:\Program Files (x86)\Mozilla Firefox\browser\components\browsercomps.dll

2013-05-22 20:34:06 -------- d-----w- C:\ProgramData\PC-Doctor for Windows

2013-05-22 20:32:32 -------- d-----w- C:\Program Files\My Dell

2013-05-22 20:20:04 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys

2013-05-22 20:20:04 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys

2013-05-22 20:20:04 144384 ----a-w- C:\Windows\System32\cdd.dll

2013-05-22 20:20:03 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll

2013-05-22 20:20:03 3153920 ----a-w- C:\Windows\System32\win32k.sys

2013-05-22 20:20:03 230400 ----a-w- C:\Windows\System32\wwansvc.dll

2013-05-22 20:19:53 1930752 ----a-w- C:\Windows\System32\authui.dll

2013-05-22 20:19:47 70144 ----a-w- C:\Windows\System32\appinfo.dll

2013-05-22 20:19:47 1796096 ----a-w- C:\Windows\SysWow64\authui.dll

2013-05-22 20:19:47 111448 ----a-w- C:\Windows\System32\consent.exe

2013-05-11 10:37:28 209472 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll

2013-05-09 05:51:15 -------- d-----w- C:\Users\Joan\AppData\Local\Dell Edoc Viewer

.

==================== Find3M ====================

.

2013-05-22 21:41:11 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-05-22 21:41:11 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-05-02 12:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe

2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll

2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll

2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys

2013-04-05 06:52:14 2242048 ----a-w- C:\Windows\System32\wininet.dll

2013-04-05 06:50:36 3958784 ----a-w- C:\Windows\System32\jscript9.dll

2013-04-05 06:50:31 67072 ----a-w- C:\Windows\System32\iesetup.dll

2013-04-05 06:50:31 136704 ----a-w- C:\Windows\System32\iesysprep.dll

2013-04-05 05:28:24 1767424 ----a-w- C:\Windows\SysWow64\wininet.dll

2013-04-05 05:26:26 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll

2013-04-05 05:26:21 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll

2013-04-05 05:26:21 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll

2013-04-05 04:43:00 2706432 ----a-w- C:\Windows\System32\mshtml.tlb

2013-04-05 04:29:45 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb

2013-04-05 03:51:11 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe

2013-04-05 03:38:25 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe

2013-04-05 00:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll

2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll

2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe

2013-03-17 08:48:17 861088 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll

2013-03-17 08:48:17 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

.

============= FINISH: 17:04:26.30 ===============

attach.txt

Link to post
Share on other sites

  • Replies 54
  • Created
  • Last Reply

Top Posters In This Topic

Hello bluelit.

I will be helping you. Please follow my guidance and do not run tools or fixes nor do changes on your own.

Going forward, please just only Copy & Paste all log contents directly into main-body of reply box.

Use 1 reply per each log as needed. IF you hit some log that is way too huge, then you may attach.

Please do a backup of any documents/personal files that you cannot afford to lose.

Malware cleanups can sometimes be unpredictable. So do a backup to Offline media as a precaution.

Please do the following.

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Disconnect any external storage drives from the computer.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

OR If you have the Windows o.s. DVD, then To enter System Recovery Options, by using Windows installation disc:

  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:


    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Command Prompt i_arrow-l.gif

[*]Select Command Prompt

Now, Plug the flashdrive with FRST tool into the PC.

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.

[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Link to post
Share on other sites

Hi, I'm getting the following message when I entered in the command window: j:\frst64.exe

FRST64.exe

There is no disk n the drive. Please insert a disk into drive\Device\Harddisk3\DR3

I'm not sure what I did wrong. I have a 64bit-OS so I downloaded Farbar Recovery Scan Tool x64.

Link to post
Share on other sites

Did you save FRST64.exe to a clean/new USB flash drive?

Did you plug in that flash-drive -after- you got to the Command prompt?

Normally the flash drive would be drive e

Is that what you tried? e:\frst64.exe

if drive E is not the flash-USB drive, try f:\frst64.exe

C drive is the HDD

D drive is typically the optical drive (CD/DVD)

so one starts with drive E or up for the USB-flash drive

Link to post
Share on other sites

Given that you are really truly at the Command prompt......give this a try

in the command window, type in

explorer.exe

and press Enter

Hopefully you will see Windows Explorer. and if so, drill down thru My Computer

You should be able to see the drive letter for the USB-drive

IF so, use that drive letter as the prefix

as in x:\frst64.exe

Link to post
Share on other sites

Wish I knew how to take a snapshot of the command prompt but I don't know how. So I'll describe what I saw.

Administrator: X:\windows\system32\cmd.exe

Black screen: Microsoft Windows [Version 6.1.7601]

x:\windows\system32>explorer.exe

'explorer.exe' is not recognized as an internal or external command, operable program or batch file.

Link to post
Share on other sites

It's weird that X is showing as your drive letter for Windows. Where do you have Windows installed??

Normally (in most cases) it should be on drive C

Try this in the Command prompt. Type in

x:\windows\explorer.exe

and press Enter

Hoping now that Windows Explorer will show.

Whether it does or not, also type in the command prompt

path

and press Enter

Write down and report back the result of the PATH command displayed.

Link to post
Share on other sites

I checked and Windows is installed on drive C. I got the same message as above when I typed in x:\windows\explorer.exe. When I typed in the command prompt path into X:\windows\system32\path, I got this message:

PATH=X:\windows\system32;X:\windows;X:\windows\system32\Wbem

Link to post
Share on other sites

I'd like for you to restart the system into normal Windows.

Insert the USB-flash with FRST64

Then start Windows Explorer .....press Windows-key+R key for the RUN option

type in

explorer.exe

when Windows Explorer is loaded, view and tell me what drive letter is the Windows folder on

& what is the drive letter for the USB drive

Did you recently re-install or repair Windows?

any idea why the Path is so messed-up, showing drive X .... when it should show C

by-the-way, is that the complete & entire Path (the one you reported above) ??

Link to post
Share on other sites

Restarted into normal Windows. Inserted USB-flash with FRST64. Then started Windows Explorer, typed in explorer.exe.

Windows folder: Drive C

USB drive: Drive E

I DID NOT re-install or repair Windows. Also, PATH=X:\windows\system32;X:\windows;X:\windows\System32\Wbem is the complete path.

Can you please look at this link and see if it makes sense to you:

http://answers.microsoft.com/en-us/windows/forum/windows_7-system/windows-7-32-bit-command-prompt/748e2c81-fe54-4e79-900f-cf19493a7d62?msgId=da6dec7c-92c0-41c1-b278-20012fea0d8c

Link to post
Share on other sites

The link to MS Answers is not one of yours. But did you recently seek help on Answers?

For this next, you need to be in normal Windows.

Do & run this batch run:

We Need to Run a Batch Script

  1. Press the Windows-key on keyboard.
  2. In the 10-16-2011%204-33-46%20PM.png box, type notepad and press Enter.
  3. Highlight the contents of the following codebox, and copy and paste that text into NOTEPAD.
    C:
    pushd\windows\system32
    path C:\windows\system32;C:\windows;C:\windows\System32\Wbem;
    exit


  4. Select File -> Save AS.
  5. Press the Desktop button on the left side of the save dialog.
  6. In the 10-16-2011%204-37-58%20PM.png box, type in Fix.bat.
  7. Press 10-16-2011%204-36-39%20PM.png.
  8. Close Notepad.
  9. Right click 10-16-2011%204-34-34%20PM.png on your desktop, and choose 10-16-2011%204-40-48%20PM.png.
  10. Press Yes if prompted by User Account Control.

NOTE: that fix.bat will run very quickly in the Command prompt and then it will Close itself.

Now, we need to retry the run of FRST64

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Disconnect any external storage drives from the computer.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

OR If you have the Windows o.s. DVD, then To enter System Recovery Options, by using Windows installation disc:

  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:


    • Startup Repair
    • System Restore
    • Windows Complete PC Restore
    • Windows Memory Diagnostic Tool
    • Command Prompt i_arrow-l.gif

[*]Select Command Prompt

Now, Plug the flashdrive with FRST tool into the PC.

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.

[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Edited by Maurice Naggar
Link to post
Share on other sites

Sorry, I was just curious so I googled the path and that was the link I gave you. I couldn't boot into normal windows so I'm in safe mode with networking.

Here's the log! :)

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-05-2013

Ran by SYSTEM on 28-05-2013 15:55:06

Running from J:\

Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Recovery

The current controlset is ControlSet001

ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RunDLLEntry_THXCfg] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)

HKLM\...\Run: [RunDLLEntry_EptMon] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64 [21504 2009-10-15] (Creative Technology Ltd.)

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)

HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()

Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab ZAO)

HKLM-x32\...\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [206448 2012-10-30] (Kaspersky Lab ZAO)

HKLM-x32\...\Run: [updReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)

HKLM-x32\...\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r [963584 2009-12-01] (Creative Technology Ltd)

HKLM-x32\...\Run: [shwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)

HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)

HKLM-x32\...\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)

HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)

HKLM-x32\...\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)

HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576

2013-04-04] (Adobe Systems Incorporated)

HKU\Joan\...\Run: [ClickfreeMonitor] c:\programdata\Clickfree\cfagent.exe [354632 2013-01-31] (Storage Appliance Corp.)

HKU\Joan\...\Run: [Google Update] "C:\Users\Joan\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-09-06] (Google Inc.)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk

ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)

SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %Systemroot%\system32\webcheck.dll (Microsoft Corporation)

==================== Services (Whitelisted) =================

S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-30] (Kaspersky Lab ZAO)

S2 FibUacService; C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe [37192 2013-01-31] (Storage Appliance Corp.)

S2 FullImagingService; C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe [201544 2013-01-31] ()

S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04]

(Malwarebytes Corporation)

S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)

S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [993848 2011-04-19] (Secunia)

==================== Drivers (Whitelisted) ====================

S0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2011-03-04] (Kaspersky Lab ZAO)

S1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2011-03-04] (Kaspersky Lab ZAO)

S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [637272 2012-10-30] (Kaspersky Lab)

S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29488 2011-03-10] (Kaspersky Lab ZAO)

S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-03] (Kaspersky Lab)

S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-05-28 20:43 - 2013-05-28 20:43 - 00000095 ____A C:\Users\Joan\Desktop\Fix.bat

2013-05-28 11:34 - 2013-05-28 18:53 - 00001466 ____A C:\Windows\setupact.log

2013-05-28 11:34 - 2013-05-28 11:34 - 00000000 ____A C:\Windows\setuperr.log

2013-05-28 09:24 - 2013-05-28 09:24 - 00000000 ____D C:\FRST

2013-05-27 22:04 - 2013-05-27 22:04 - 00020871 ____A C:\Users\Joan\Desktop\attach.txt

2013-05-27 22:04 - 2013-05-27 22:04 - 00020311 ____A C:\Users\Joan\Desktop\dds.txt

2013-05-27 21:56 - 2013-05-27 21:56 - 00688992 ____R (Swearware) C:\Users\Joan\Desktop\dds.com

2013-05-27 14:10 - 2013-05-27 14:10 - 00791393 ____A (Lars Hederer ) C:\Users\Joan\Downloads\erunt-setup.exe

2013-05-27 13:08 - 2013-05-28 20:48 - 00076594 ____A C:\Windows\WindowsUpdate.log

2013-05-26 20:22 - 2013-05-26 20:22 - 00019075 ____A C:\Users\Joan\Downloads\Resultminitoolbox.txt

2013-05-26 20:21 - 2013-05-26 20:21 - 00019075 ____A C:\Users\Joan\Downloads\Result.txt

2013-05-26 20:19 - 2013-05-26 20:19 - 00760723 ____A (Farbar) C:\Users\Joan\Downloads\MiniToolBox.exe

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\My Documents\TurboTax

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\Documents\TurboTax

2013-05-22 16:46 - 2013-05-28 19:51 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-22 16:46 - 2013-05-28 18:53 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-22 16:46 - 2013-05-24 16:51 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-05-22 16:46 - 2013-05-24 16:51 - 00002185 ____A C:\ProgramData\Desktop\Google Chrome.lnk

2013-05-22 16:46 - 2013-05-22 16:46 - 00000000 ____D C:\Program Files (x86)\Google

2013-05-22 15:32 - 2013-05-22 15:34 - 00000000 ____D C:\Program Files\My Dell

2013-05-22 15:27 - 2013-04-05 01:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-05-22 15:27 - 2013-04-05 01:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-05-22 15:27 - 2013-04-05 01:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2013-05-22 15:27 - 2013-04-05 01:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2013-05-22 15:27 - 2013-04-05 00:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2013-05-22 15:27 - 2013-04-05 00:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2013-05-22 15:27 - 2013-04-04 23:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-05-22 15:27 - 2013-04-04 23:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2013-05-22 15:27 - 2013-04-04 22:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2013-05-22 15:27 - 2013-04-04 22:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2013-05-22 15:20 - 2013-04-10 01:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys

2013-05-22 15:20 - 2013-04-10 01:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys

2013-05-22 15:20 - 2013-04-09 22:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-05-22 15:20 - 2013-03-19 00:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll

2013-05-22 15:20 - 2013-03-19 00:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll

2013-05-22 15:20 - 2011-02-03 06:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

2013-05-22 15:19 - 2013-02-27 01:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe

2013-05-22 15:19 - 2013-02-27 00:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll

2013-05-22 15:19 - 2013-02-27 00:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll

2013-05-22 15:19 - 2013-02-27 00:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll

2013-05-22 15:19 - 2013-02-27 00:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll

2013-05-22 15:19 - 2013-02-26 23:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll

2013-05-22 15:19 - 2013-02-26 23:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll

2013-05-22 15:19 - 2013-02-26 23:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\AppData\Local\Dell Edoc Viewer

2013-05-06 12:56 - 2013-05-06 12:58 - 145649814 ____A C:\Users\Joan\Downloads\1080??? Aaron Yan - ????? The Moment MV(???_????????_??).mp4

2013-05-02 01:35 - 2013-05-02 01:35 - 02347384 ____A (ESET) C:\Users\Joan\Downloads\esetsmartinstaller_enu.exe

2013-04-29 17:26 - 2013-04-29 17:26 - 00085629 ____A C:\Users\Joan\Desktop\Ep16mail-attachment.googleusercontent.com

One Month Modified Files and Folders =======

2013-05-28 20:48 - 2013-05-27 13:08 - 00076594 ____A C:\Windows\WindowsUpdate.log

2013-05-28 20:43 - 2013-05-28 20:43 - 00000095 ____A C:\Users\Joan\Desktop\Fix.bat

2013-05-28 20:41 - 2011-12-29 17:28 - 00271360 ____A C:\Users\Joan\My Documents\Outlook archive folders backup.pst

2013-05-28 20:41 - 2011-12-29 17:28 - 00271360 ____A C:\Users\Joan\Documents\Outlook archive folders backup.pst

2013-05-28 20:41 - 2011-09-07 14:46 - 00000000 ____D C:\Users\Joan\My Documents\Outlook Files

2013-05-28 20:41 - 2011-09-07 14:46 - 00000000 ____D C:\Users\Joan\Documents\Outlook Files

2013-05-28 20:19 - 2012-09-06 15:54 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000UA.job

2013-05-28 20:19 - 2012-09-06 15:54 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000Core.job

2013-05-28 20:06 - 2011-09-02 15:59 - 00000000 ____D C:\ProgramData\Kaspersky Lab

2013-05-28 20:06 - 2011-09-02 15:59 - 00000000 ____D C:\ProgramData\Application Data\Kaspersky Lab

2013-05-28 19:55 - 2012-09-27 18:29 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-05-28 19:51 - 2013-05-22 16:46 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-28 19:50 - 2009-07-14 00:13 - 00779266 ____A C:\Windows\System32\PerfStringBackup.INI

2013-05-28 19:00 - 2009-07-13 23:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-05-28 19:00 - 2009-07-13 23:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-

9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-05-28 18:53 - 2013-05-28 11:34 - 00001466 ____A C:\Windows\setupact.log

2013-05-28 18:53 - 2013-05-22 16:46 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\Local Settings\SoftThinks

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\SoftThinks

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\AppData\Local\SoftThinks

2013-05-28 18:53 - 2011-08-29 21:46 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup

2013-05-28 18:53 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-05-28 11:34 - 2013-05-28 11:34 - 00000000 ____A C:\Windows\setuperr.log

2013-05-28 09:24 - 2013-05-28 09:24 - 00000000 ____D C:\FRST

2013-05-27 22:04 - 2013-05-27 22:04 - 00020871 ____A C:\Users\Joan\Desktop\attach.txt

2013-05-27 22:04 - 2013-05-27 22:04 - 00020311 ____A C:\Users\Joan\Desktop\dds.txt

2013-05-27 21:56 - 2013-05-27 21:56 - 00688992 ____R (Swearware) C:\Users\Joan\Desktop\dds.com

2013-05-27 16:34 - 2011-11-30 12:38 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster

2013-05-27 14:10 - 2013-05-27 14:10 - 00791393 ____A (Lars Hederer ) C:\Users\Joan\Downloads\erunt-setup.exe

2013-05-26 20:22 - 2013-05-26 20:22 - 00019075 ____A C:\Users\Joan\Downloads\Resultminitoolbox.txt

2013-05-26 20:21 - 2013-05-26 20:21 - 00019075 ____A C:\Users\Joan\Downloads\Result.txt

2013-05-26 20:19 - 2013-05-26 20:19 - 00760723 ____A (Farbar) C:\Users\Joan\Downloads\MiniToolBox.exe

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\My Documents\TurboTax

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\Documents\TurboTax

2013-05-24 16:51 - 2013-05-22 16:46 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-05-24 16:51 - 2013-05-22 16:46 - 00002185 ____A C:\ProgramData\Desktop\Google Chrome.lnk

2013-05-23 13:34 - 2012-08-05 22:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2013-05-23 01:55 - 2011-02-10 09:25 - 00000000 ____D C:\Windows\panther

2013-05-22 21:42 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache

2013-05-22 16:46 - 2013-05-22 16:46 - 00000000 ____D C:\Program Files (x86)\Google

2013-05-22 16:45 - 2013-04-12 00:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-05-22 16:45 - 2012-12-04 02:16 - 00001153 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk

2013-05-22 16:45 - 2012-12-04 02:16 - 00001153 ____A C:\ProgramData\Desktop\Mozilla Firefox.lnk

2013-05-22 16:41 - 2012-09-27 18:29 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-05-22 16:41 - 2012-09-27 18:29 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-05-22 15:49 - 2011-09-02 14:05 - 00000000 ___RD C:\Users\Joan\Virtual Machines

2013-05-22 15:48 - 2009-07-13 23:45 - 00470888 ____A C:\Windows\System32\FNTCACHE.DAT

2013-05-22 15:38 - 2011-09-06 23:49 - 00000000 ____D C:\Program Files\Microsoft Lync

2013-05-22 15:38 - 2011-09-06 23:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Lync

2013-05-22 15:36 - 2011-09-06 23:54 - 00000000 ____D C:\ProgramData\Microsoft Help

2013-05-22 15:36 - 2011-09-06 23:54 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help

2013-05-22 15:34 - 2013-05-22 15:32 - 00000000 ____D C:\Program Files\My Dell

2013-05-22 15:34 - 2011-09-04 21:04 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

2013-05-22 15:34 - 2011-08-29 21:57 - 00000000 ____D C:\Program Files\Dell Support Center

2013-05-22 15:32 - 2011-09-05 19:00 - 00000000 ____D C:\ProgramData\PCDr

2013-05-22 15:32 - 2011-09-05 19:00 - 00000000 ____D C:\ProgramData\Application Data\PCDr

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\AppData\Local\Dell Edoc Viewer

2013-05-06 12:58 - 2013-05-06 12:56 - 145649814 ____A C:\Users\Joan\Downloads\1080??? Aaron Yan - ????? The Moment MV(???_????????_??).mp4

2013-05-04 03:01 - 2011-09-04 22:22 - 00000784 ____A C:\Users\Public\Desktop\CCleaner.lnk

2013-05-04 03:01 - 2011-09-04 22:22 - 00000784 ____A C:\ProgramData\Desktop\CCleaner.lnk

2013-05-04 03:01 - 2011-09-04 22:22 - 00000000 ____D C:\Program Files\CCleaner

2013-05-02 12:01 - 2012-06-17 21:43 - 00000000 ____D C:\Program Files (x86)\Boilsoft

2013-05-02 07:06 - 2010-11-20 22:27 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe

2013-05-02 03:01 - 2012-05-10 02:24 - 00000000 ____D C:\Windows\pss

2013-05-02 01:35 - 2013-05-02 01:35 - 02347384 ____A (ESET) C:\Users\Joan\Downloads\esetsmartinstaller_enu.exe

2013-04-29 17:26 - 2013-04-29 17:26 - 00085629 ____A C:\Users\Joan\Desktop\Ep16mail-attachment.googleusercontent.com

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-05-10 14:18:01

Restore point made on: 2013-05-22 15:18:29

Restore point made on: 2013-05-22 15:25:45

Restore point made on: 2013-05-28 11:44:01

==================== Memory info ===========================

Percentage of memory in use: 10%

Total physical RAM: 8174.45 MB

Available physical RAM: 7356.7 MB

Total Pagefile: 8172.64 MB

Available Pagefile: 7353.03 MB

Total Virtual: 8192 MB

Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:1380.98 GB) (Free:1319.05 GB) NTFS (Disk=0 Partition=3)

Drive e: (RECOVERY) (Fixed) (Total:16.25 GB) (Free:7.51 GB) NTFS (Disk=0 Partition=2) ==>[system with boot components (obtained from reading drive)]

Drive j: () (Removable) (Total:3.75 GB) (Free:3.75 GB) FAT32 (Disk=5 Partition=1)

Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================

Disk: 0 (MBR Code: Windows Vista) (Size: 1397 GB) (Disk ID: 32E6C325)

Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)

Partition 2: (Active) - (Size=16 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=-716210962432) - (Type=07 NTFS)

Link to post
Share on other sites

I was finally able to boot in normal Windows. I wasn't sure if I copied/pasted the entire log in safe mode so I'm copying/pasting it again.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-05-2013

Ran by SYSTEM on 28-05-2013 15:55:06

Running from J:\

Windows 7 Professional Service Pack 1 (X64) OS Language: English(US)

Internet Explorer Version 9

Boot Mode: Recovery

The current controlset is ControlSet001

ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RunDLLEntry_THXCfg] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64 [17920 2009-10-15] (Creative Technology Ltd.)

HKLM\...\Run: [RunDLLEntry_EptMon] C:\Windows\system32\RunDLL32.exe C:\Windows\system32\EptMon64.dll,RunDLLEntry EptMon64 [21504 2009-10-15] (Creative Technology Ltd.)

HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [10920552 2010-06-22] (Realtek Semiconductor)

HKLM\...\Run: [DellStage] "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup [483424 2012-02-01] ()

Winlogon\Notify\klogon: %SystemRoot%\System32\klogon.dll (Kaspersky Lab ZAO)

HKLM-x32\...\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [206448 2012-10-30] (Kaspersky Lab ZAO)

HKLM-x32\...\Run: [updReg] C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)

HKLM-x32\...\Run: [THX Audio Control Panel] "C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" /r [963584 2009-12-01] (Creative Technology Ltd)

HKLM-x32\...\Run: [shwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)

HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)

HKLM-x32\...\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)

HKLM-x32\...\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)

HKLM-x32\...\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices [91520 2010-03-13] (Microsoft Corporation)

HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated)

HKU\Joan\...\Run: [ClickfreeMonitor] c:\programdata\Clickfree\cfagent.exe [354632 2013-01-31] (Storage Appliance Corp.)

HKU\Joan\...\Run: [Google Update] "C:\Users\Joan\AppData\Local\Google\Update\GoogleUpdate.exe" /c [136176 2012-09-06] (Google Inc.)

Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk

ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)

SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %Systemroot%\system32\webcheck.dll (Microsoft Corporation)

==================== Services (Whitelisted) =================

S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe [206448 2012-10-30] (Kaspersky Lab ZAO)

S2 FibUacService; C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe [37192 2013-01-31] (Storage Appliance Corp.)

S2 FullImagingService; C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe [201544 2013-01-31] ()

S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)

S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)

S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [993848 2011-04-19] (Secunia)

==================== Drivers (Whitelisted) ====================

S0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [460888 2011-03-04] (Kaspersky Lab ZAO)

S1 kl2; C:\Windows\System32\DRIVERS\kl2.sys [11864 2011-03-04] (Kaspersky Lab ZAO)

S1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [637272 2012-10-30] (Kaspersky Lab)

S1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29488 2011-03-10] (Kaspersky Lab ZAO)

S3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [22544 2009-11-03] (Kaspersky Lab)

S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2013-05-28 20:43 - 2013-05-28 20:43 - 00000095 ____A C:\Users\Joan\Desktop\Fix.bat

2013-05-28 11:34 - 2013-05-28 18:53 - 00001466 ____A C:\Windows\setupact.log

2013-05-28 11:34 - 2013-05-28 11:34 - 00000000 ____A C:\Windows\setuperr.log

2013-05-28 09:24 - 2013-05-28 09:24 - 00000000 ____D C:\FRST

2013-05-27 22:04 - 2013-05-27 22:04 - 00020871 ____A C:\Users\Joan\Desktop\attach.txt

2013-05-27 22:04 - 2013-05-27 22:04 - 00020311 ____A C:\Users\Joan\Desktop\dds.txt

2013-05-27 21:56 - 2013-05-27 21:56 - 00688992 ____R (Swearware) C:\Users\Joan\Desktop\dds.com

2013-05-27 14:10 - 2013-05-27 14:10 - 00791393 ____A (Lars Hederer ) C:\Users\Joan\Downloads\erunt-setup.exe

2013-05-27 13:08 - 2013-05-28 20:48 - 00076594 ____A C:\Windows\WindowsUpdate.log

2013-05-26 20:22 - 2013-05-26 20:22 - 00019075 ____A C:\Users\Joan\Downloads\Resultminitoolbox.txt

2013-05-26 20:21 - 2013-05-26 20:21 - 00019075 ____A C:\Users\Joan\Downloads\Result.txt

2013-05-26 20:19 - 2013-05-26 20:19 - 00760723 ____A (Farbar) C:\Users\Joan\Downloads\MiniToolBox.exe

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\My Documents\TurboTax

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\Documents\TurboTax

2013-05-22 16:46 - 2013-05-28 19:51 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-22 16:46 - 2013-05-28 18:53 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-22 16:46 - 2013-05-24 16:51 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-05-22 16:46 - 2013-05-24 16:51 - 00002185 ____A C:\ProgramData\Desktop\Google Chrome.lnk

2013-05-22 16:46 - 2013-05-22 16:46 - 00000000 ____D C:\Program Files (x86)\Google

2013-05-22 15:32 - 2013-05-22 15:34 - 00000000 ____D C:\Program Files\My Dell

2013-05-22 15:27 - 2013-04-05 01:52 - 02242048 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll

2013-05-22 15:27 - 2013-04-05 01:52 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll

2013-05-22 15:27 - 2013-04-05 01:52 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe

2013-05-22 15:27 - 2013-04-05 01:50 - 19231232 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 15404032 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll

2013-05-22 15:27 - 2013-04-05 01:50 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll

2013-05-22 15:27 - 2013-04-05 00:28 - 01767424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2013-05-22 15:27 - 2013-04-05 00:28 - 01130496 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 14323712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2013-05-22 15:27 - 2013-04-05 00:26 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2013-05-22 15:27 - 2013-04-04 23:43 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb

2013-05-22 15:27 - 2013-04-04 23:29 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2013-05-22 15:27 - 2013-04-04 22:51 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe

2013-05-22 15:27 - 2013-04-04 22:38 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe

2013-05-22 15:20 - 2013-04-10 01:01 - 00983400 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys

2013-05-22 15:20 - 2013-04-10 01:01 - 00265064 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\dxgmms1.sys

2013-05-22 15:20 - 2013-04-09 22:30 - 03153920 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys

2013-05-22 15:20 - 2013-03-19 00:53 - 00230400 ____A (Microsoft Corporation) C:\Windows\System32\wwansvc.dll

2013-05-22 15:20 - 2013-03-19 00:53 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\wwanprotdim.dll

2013-05-22 15:20 - 2011-02-03 06:25 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\cdd.dll

2013-05-22 15:19 - 2013-02-27 01:02 - 00111448 ____A (Microsoft Corporation) C:\Windows\System32\consent.exe

2013-05-22 15:19 - 2013-02-27 00:52 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll

2013-05-22 15:19 - 2013-02-27 00:52 - 00197120 ____A (Microsoft Corporation) C:\Windows\System32\shdocvw.dll

2013-05-22 15:19 - 2013-02-27 00:48 - 01930752 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll

2013-05-22 15:19 - 2013-02-27 00:47 - 00070144 ____A (Microsoft Corporation) C:\Windows\System32\appinfo.dll

2013-05-22 15:19 - 2013-02-26 23:55 - 12872704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll

2013-05-22 15:19 - 2013-02-26 23:55 - 00180224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll

2013-05-22 15:19 - 2013-02-26 23:49 - 01796096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\AppData\Local\Dell Edoc Viewer

2013-05-06 12:56 - 2013-05-06 12:58 - 145649814 ____A C:\Users\Joan\Downloads\1080??? Aaron Yan - ????? The Moment MV(???_????????_??).mp4

2013-05-02 01:35 - 2013-05-02 01:35 - 02347384 ____A (ESET) C:\Users\Joan\Downloads\esetsmartinstaller_enu.exe

2013-04-29 17:26 - 2013-04-29 17:26 - 00085629 ____A C:\Users\Joan\Desktop\Ep16mail-attachment.googleusercontent.com

==================== One Month Modified Files and Folders =======

2013-05-28 20:48 - 2013-05-27 13:08 - 00076594 ____A C:\Windows\WindowsUpdate.log

2013-05-28 20:43 - 2013-05-28 20:43 - 00000095 ____A C:\Users\Joan\Desktop\Fix.bat

2013-05-28 20:41 - 2011-12-29 17:28 - 00271360 ____A C:\Users\Joan\My Documents\Outlook archive folders backup.pst

2013-05-28 20:41 - 2011-12-29 17:28 - 00271360 ____A C:\Users\Joan\Documents\Outlook archive folders backup.pst

2013-05-28 20:41 - 2011-09-07 14:46 - 00000000 ____D C:\Users\Joan\My Documents\Outlook Files

2013-05-28 20:41 - 2011-09-07 14:46 - 00000000 ____D C:\Users\Joan\Documents\Outlook Files

2013-05-28 20:19 - 2012-09-06 15:54 - 00000904 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000UA.job

2013-05-28 20:19 - 2012-09-06 15:54 - 00000852 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000Core.job

2013-05-28 20:06 - 2011-09-02 15:59 - 00000000 ____D C:\ProgramData\Kaspersky Lab

2013-05-28 20:06 - 2011-09-02 15:59 - 00000000 ____D C:\ProgramData\Application Data\Kaspersky Lab

2013-05-28 19:55 - 2012-09-27 18:29 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job

2013-05-28 19:51 - 2013-05-22 16:46 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2013-05-28 19:50 - 2009-07-14 00:13 - 00779266 ____A C:\Windows\System32\PerfStringBackup.INI

2013-05-28 19:00 - 2009-07-13 23:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2013-05-28 19:00 - 2009-07-13 23:45 - 00021312 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2013-05-28 18:53 - 2013-05-28 11:34 - 00001466 ____A C:\Windows\setupact.log

2013-05-28 18:53 - 2013-05-22 16:46 - 00000890 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\Local Settings\SoftThinks

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\SoftThinks

2013-05-28 18:53 - 2011-09-02 14:02 - 00000000 ____D C:\Users\Joan\AppData\Local\SoftThinks

2013-05-28 18:53 - 2011-08-29 21:46 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup

2013-05-28 18:53 - 2009-07-14 00:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT

2013-05-28 11:34 - 2013-05-28 11:34 - 00000000 ____A C:\Windows\setuperr.log

2013-05-28 09:24 - 2013-05-28 09:24 - 00000000 ____D C:\FRST

2013-05-27 22:04 - 2013-05-27 22:04 - 00020871 ____A C:\Users\Joan\Desktop\attach.txt

2013-05-27 22:04 - 2013-05-27 22:04 - 00020311 ____A C:\Users\Joan\Desktop\dds.txt

2013-05-27 21:56 - 2013-05-27 21:56 - 00688992 ____R (Swearware) C:\Users\Joan\Desktop\dds.com

2013-05-27 16:34 - 2011-11-30 12:38 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster

2013-05-27 14:10 - 2013-05-27 14:10 - 00791393 ____A (Lars Hederer ) C:\Users\Joan\Downloads\erunt-setup.exe

2013-05-26 20:22 - 2013-05-26 20:22 - 00019075 ____A C:\Users\Joan\Downloads\Resultminitoolbox.txt

2013-05-26 20:21 - 2013-05-26 20:21 - 00019075 ____A C:\Users\Joan\Downloads\Result.txt

2013-05-26 20:19 - 2013-05-26 20:19 - 00760723 ____A (Farbar) C:\Users\Joan\Downloads\MiniToolBox.exe

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\My Documents\TurboTax

2013-05-25 13:40 - 2013-05-25 13:40 - 00000000 ____D C:\Users\Joan\Documents\TurboTax

2013-05-24 16:51 - 2013-05-22 16:46 - 00002185 ____A C:\Users\Public\Desktop\Google Chrome.lnk

2013-05-24 16:51 - 2013-05-22 16:46 - 00002185 ____A C:\ProgramData\Desktop\Google Chrome.lnk

2013-05-23 13:34 - 2012-08-05 22:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2013-05-23 01:55 - 2011-02-10 09:25 - 00000000 ____D C:\Windows\panther

2013-05-22 21:42 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache

2013-05-22 16:46 - 2013-05-22 16:46 - 00000000 ____D C:\Program Files (x86)\Google

2013-05-22 16:45 - 2013-04-12 00:19 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox

2013-05-22 16:45 - 2012-12-04 02:16 - 00001153 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk

2013-05-22 16:45 - 2012-12-04 02:16 - 00001153 ____A C:\ProgramData\Desktop\Mozilla Firefox.lnk

2013-05-22 16:41 - 2012-09-27 18:29 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2013-05-22 16:41 - 2012-09-27 18:29 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2013-05-22 15:49 - 2011-09-02 14:05 - 00000000 ___RD C:\Users\Joan\Virtual Machines

2013-05-22 15:48 - 2009-07-13 23:45 - 00470888 ____A C:\Windows\System32\FNTCACHE.DAT

2013-05-22 15:38 - 2011-09-06 23:49 - 00000000 ____D C:\Program Files\Microsoft Lync

2013-05-22 15:38 - 2011-09-06 23:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Lync

2013-05-22 15:36 - 2011-09-06 23:54 - 00000000 ____D C:\ProgramData\Microsoft Help

2013-05-22 15:36 - 2011-09-06 23:54 - 00000000 ____D C:\ProgramData\Application Data\Microsoft Help

2013-05-22 15:34 - 2013-05-22 15:32 - 00000000 ____D C:\Program Files\My Dell

2013-05-22 15:34 - 2011-09-04 21:04 - 75016696 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe

2013-05-22 15:34 - 2011-08-29 21:57 - 00000000 ____D C:\Program Files\Dell Support Center

2013-05-22 15:32 - 2011-09-05 19:00 - 00000000 ____D C:\ProgramData\PCDr

2013-05-22 15:32 - 2011-09-05 19:00 - 00000000 ____D C:\ProgramData\Application Data\PCDr

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\Local Settings\Application Data\Dell Edoc Viewer

2013-05-09 00:51 - 2013-05-09 00:51 - 00000000 ____D C:\Users\Joan\AppData\Local\Dell Edoc Viewer

2013-05-06 12:58 - 2013-05-06 12:56 - 145649814 ____A C:\Users\Joan\Downloads\1080??? Aaron Yan - ????? The Moment MV(???_????????_??).mp4

2013-05-04 03:01 - 2011-09-04 22:22 - 00000784 ____A C:\Users\Public\Desktop\CCleaner.lnk

2013-05-04 03:01 - 2011-09-04 22:22 - 00000784 ____A C:\ProgramData\Desktop\CCleaner.lnk

2013-05-04 03:01 - 2011-09-04 22:22 - 00000000 ____D C:\Program Files\CCleaner

2013-05-02 12:01 - 2012-06-17 21:43 - 00000000 ____D C:\Program Files (x86)\Boilsoft

2013-05-02 07:06 - 2010-11-20 22:27 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe

2013-05-02 03:01 - 2012-05-10 02:24 - 00000000 ____D C:\Windows\pss

2013-05-02 01:35 - 2013-05-02 01:35 - 02347384 ____A (ESET) C:\Users\Joan\Downloads\esetsmartinstaller_enu.exe

2013-04-29 17:26 - 2013-04-29 17:26 - 00085629 ____A C:\Users\Joan\Desktop\Ep16mail-attachment.googleusercontent.com

==================== Known DLLs (Whitelisted) ================

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit

C:\Windows\System32\wininit.exe => MD5 is legit

C:\Windows\SysWOW64\wininit.exe => MD5 is legit

C:\Windows\explorer.exe => MD5 is legit

C:\Windows\SysWOW64\explorer.exe => MD5 is legit

C:\Windows\System32\svchost.exe => MD5 is legit

C:\Windows\SysWOW64\svchost.exe => MD5 is legit

C:\Windows\System32\services.exe => MD5 is legit

C:\Windows\System32\User32.dll => MD5 is legit

C:\Windows\SysWOW64\User32.dll => MD5 is legit

C:\Windows\System32\userinit.exe => MD5 is legit

C:\Windows\SysWOW64\userinit.exe => MD5 is legit

C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK

HKLM\...\exefile\DefaultIcon: %1 => OK

HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-05-10 14:18:01

Restore point made on: 2013-05-22 15:18:29

Restore point made on: 2013-05-22 15:25:45

Restore point made on: 2013-05-28 11:44:01

==================== Memory info ===========================

Percentage of memory in use: 10%

Total physical RAM: 8174.45 MB

Available physical RAM: 7356.7 MB

Total Pagefile: 8172.64 MB

Available Pagefile: 7353.03 MB

Total Virtual: 8192 MB

Available Virtual: 8191.86 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:1380.98 GB) (Free:1319.05 GB) NTFS (Disk=0 Partition=3)

Drive e: (RECOVERY) (Fixed) (Total:16.25 GB) (Free:7.51 GB) NTFS (Disk=0 Partition=2) ==>[system with boot components (obtained from reading drive)]

Drive j: () (Removable) (Total:3.75 GB) (Free:3.75 GB) FAT32 (Disk=5 Partition=1)

Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================

Disk: 0 (MBR Code: Windows Vista) (Size: 1397 GB) (Disk ID: 32E6C325)

Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)

Partition 2: (Active) - (Size=16 GB) - (Type=07 NTFS)

Partition 3: (Not Active) - (Size=-716210962432) - (Type=07 NTFS)

========================================================

Disk: 5 (Size: 4 GB) (Disk ID: 003E5D74)

Partition 1: (Active) - (Size=4 GB) - (Type=0B)

Last Boot: 2013-05-24 20:09

==================== End Of Log ============================

Link to post
Share on other sites

Please carefully follow this procedure

Please download the attached fixlist.txt and SAVE / copy it to your flashdrive.

NOTICE: This script was written specifically for this user, for use on this particular system. Running this on another machine may cause damage to your operating system

On Vista or Windows 7/8: Now please enter System Recovery Options. (as you did before)

Run FRST64 or FRST (which ever one you're using) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Task 2

Make sure to have removed the USB-flash drive.

Now then, Restart Windows into normal mode.

Delete any prior copy (if any) of mbar.exe

1. Download Malwarebytes Anti-Rootkit from http://www.malwarebytes.org/products/mbar/

2. Unzip the contents to a folder in a convenient location.

3. Open the folder where the contents were unzipped and run mbar.exe

IF your Windows is Windows 8 or 7 or Vista, do a RIGHT-Click on mbar.exe and select Run As Administrator and allow to run.

If your Windows is XP, double-click to start.

4. Follow the instructions in the wizard to update and allow the program to scan your computer for threats.

5. Click on the Cleanup button to remove any threats and reboot if prompted to do so.

6. Wait while the system shuts down and the cleanup process is performed.

7. Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.

Fixlist.txt

Edited by Maurice Naggar
Link to post
Share on other sites

Finished the first task.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-05-2013

Ran by SYSTEM at 2013-05-28 17:50:36 Run:1

Running from E:\

Boot Mode: Recovery

==============================================

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdReg => Value deleted successfully.

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => Value deleted successfully.

HKEY_USERS\Joan\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update => Value deleted successfully.

C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk => Moved successfully.

C:\Program Files (x86)\Secunia\PSI\psi_tray.exe => Moved successfully.

==== End of Fixlog ====

However, when I tried to run mbar.exe, I got this message:

mbar.exe - System Error

The program can't start because QtGui4.dll is missing from your computer. Try reinstalling the program to fix this problem.

Link to post
Share on other sites

Let's put aside mbar.

Please proceed with the following, and do as much as possible.

Step 1

Disable CD-ROM Emulation Software:

Please download the following tool DeFogger to your desktop.

◦Double click DeFogger to run the tool.

◦The application window will appear

◦Click the Disable button to disable your CD Emulation drivers.

◦Click Yes to continue

◦A 'Finished!' message will appear

◦Click OK

◦DeFogger will now ask to reboot the machine - click OK

◦IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

◦Do not re-enable these drivers until otherwise instructed.

Step 2

1. Go >> Here << and download ERUNT

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)

2. Install ERUNT by following the prompts

(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)

3. Start ERUNT

(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)

4. Choose a location for the backup

(the default location is C:\WINDOWS\ERDNT which is acceptable).

5. Make sure that at least the first two check boxes are ticked

6. Press OK

7. Press YES to create the folder.

Step 3

To show all files:

  • Press Windows-key +R key on your keyboard to get RUN option.
  • Type in
    explorer.exe

    and press Enter to start Windows Explorer.

  • From the menu options, Select Tools, then Folder Options.
  • Next click the View tab.
  • Locate and uncheck Hide file extensions for known file types.
  • Locate and uncheck Hide protected operating system files (Recommended).
  • Locate and click Show hidden files and folders and drives.
  • Click Apply > OK.

Step 4

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Please download AdwCleaner © Xplode from >>here<< and save it on your Desktop.

If your are running Windows XP, double click adwcleaner.exe to start it.

Otherwise, Right-click on adwcleaner.exe and select Run As Administrator to launch the application.

Now click on the Search tab.

Please post the contents of the log-file created in your next post.

Note: The log can also be located at C:\AdwCleaner[XX].txt where XX Denotes the number of times the application has been ran, so in this should be something like R1.

Step 5

Please read carefully and follow these steps.

  • Download TDSSKiller and save it to your Desktop.
  • Double-Click on TDSSKiller.exe to run the application, then on Start Scan.
    If running Vista or Windows 7, do a RIGHT-Click and select Run as Administrator to start TDSSKILLER.exe.
  • If an infected file is detected, the default action will be Cure, click on Continue.
    TDSSKillerMal-1.png
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    TDSSKillerCompleted.png
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Step 6

  • Download & SAVE to your Desktop >> Tigzy's RogueKillerfrom here << or
    >> from here <<
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
    For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on Scan button at upper right of screen.
  • Wait until the Status box shows "Scan Finished"
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller

Do NOT click any FIX buttons !

Step 7

RE-Enable your antivirus program. excl.png

Then copy/paste the following into your post (in order):

  • the contents of C:\AdwCleaner[R1].txt;
  • the contents of TDSSKILLER log;
  • the contents of RKReport log;

Be sure to do a Preview prior to pressing Submit because all reports may not fit into 1 single reply. You may have to do more than 1 reply.

Do not use the attachment feature to place any of your reports. Always put them in-line inside the body of reply.

Link to post
Share on other sites

Hi Maurice,

Here's the requested logs:

1. C:\AdwCleaner[R1].txt

# AdwCleaner v2.301 - Logfile created 05/29/2013 at 07:04:54

# Updated 16/05/2013 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : Joan - JA

# Boot Mode : Normal

# Running from : C:\Users\Joan\Desktop\adwcleaner.exe

# Option [search]

***** [services] *****

***** [Files / Folders] *****

Folder Found : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\ymm6qbpn.default\extensions\wtxpcom@mybrowserbar.com

***** [Registry] *****

Key Found : HKCU\Software\YahooPartnerToolbar

Key Found : HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD

Key Found : HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD

***** [internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\5uuc71d5.default-1344114154362\prefs.js

[OK] File is clean.

File : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\ymm6qbpn.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R42].txt - [1272 octets] - [29/05/2013 07:04:54]

########## EOF - C:\AdwCleaner[R42].txt - [1333 octets] ##########

2. TDSSKILLER log

07:09:02.0797 4424 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

07:09:03.0575 4424 ============================================================

07:09:03.0575 4424 Current date / time: 2013/05/29 07:09:03.0575

07:09:03.0575 4424 SystemInfo:

07:09:03.0575 4424

07:09:03.0575 4424 OS Version: 6.1.7601 ServicePack: 1.0

07:09:03.0575 4424 Product type: Workstation

07:09:03.0576 4424 ComputerName: JA

07:09:03.0576 4424 UserName: Joan

07:09:03.0576 4424 Windows directory: C:\Windows

07:09:03.0576 4424 System windows directory: C:\Windows

07:09:03.0576 4424 Running under WOW64

07:09:03.0576 4424 Processor architecture: Intel x64

07:09:03.0576 4424 Number of processors: 8

07:09:03.0576 4424 Page size: 0x1000

07:09:03.0576 4424 Boot type: Normal boot

07:09:03.0576 4424 ============================================================

07:09:03.0967 4424 Drive \Device\Harddisk0\DR0 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

07:09:03.0980 4424 ============================================================

07:09:03.0980 4424 \Device\Harddisk0\DR0:

07:09:03.0981 4424 MBR partitions:

07:09:03.0981 4424 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x207F000

07:09:03.0981 4424 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2093000, BlocksNum 0xAC9F4000

07:09:03.0981 4424 ============================================================

07:09:04.0010 4424 C: <-> \Device\Harddisk0\DR0\Partition2

07:09:04.0010 4424 ============================================================

07:09:04.0010 4424 Initialize success

07:09:04.0010 4424 ============================================================

07:09:24.0301 2288 ============================================================

07:09:24.0301 2288 Scan started

07:09:24.0301 2288 Mode: Manual;

07:09:24.0301 2288 ============================================================

07:09:24.0488 2288 ================ Scan system memory ========================

07:09:24.0488 2288 System memory - ok

07:09:24.0488 2288 ================ Scan services =============================

07:09:24.0613 2288 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys

07:09:24.0613 2288 1394ohci - ok

07:09:24.0644 2288 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys

07:09:24.0644 2288 ACPI - ok

07:09:24.0660 2288 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys

07:09:24.0660 2288 AcpiPmi - ok

07:09:24.0722 2288 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

07:09:24.0738 2288 AdobeARMservice - ok

07:09:24.0831 2288 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

07:09:24.0831 2288 AdobeFlashPlayerUpdateSvc - ok

07:09:24.0863 2288 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys

07:09:24.0863 2288 adp94xx - ok

07:09:24.0878 2288 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys

07:09:24.0878 2288 adpahci - ok

07:09:24.0894 2288 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys

07:09:24.0894 2288 adpu320 - ok

07:09:24.0925 2288 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll

07:09:24.0925 2288 AeLookupSvc - ok

07:09:24.0972 2288 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys

07:09:24.0972 2288 AFD - ok

07:09:24.0987 2288 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys

07:09:24.0987 2288 agp440 - ok

07:09:25.0003 2288 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe

07:09:25.0019 2288 ALG - ok

07:09:25.0019 2288 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys

07:09:25.0019 2288 aliide - ok

07:09:25.0034 2288 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys

07:09:25.0034 2288 amdide - ok

07:09:25.0050 2288 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys

07:09:25.0050 2288 AmdK8 - ok

07:09:25.0050 2288 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys

07:09:25.0065 2288 AmdPPM - ok

07:09:25.0065 2288 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys

07:09:25.0081 2288 amdsata - ok

07:09:25.0081 2288 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys

07:09:25.0097 2288 amdsbs - ok

07:09:25.0097 2288 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys

07:09:25.0097 2288 amdxata - ok

07:09:25.0112 2288 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys

07:09:25.0112 2288 AppID - ok

07:09:25.0128 2288 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll

07:09:25.0128 2288 AppIDSvc - ok

07:09:25.0159 2288 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll

07:09:25.0159 2288 Appinfo - ok

07:09:25.0190 2288 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll

07:09:25.0190 2288 AppMgmt - ok

07:09:25.0206 2288 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys

07:09:25.0206 2288 arc - ok

07:09:25.0221 2288 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys

07:09:25.0221 2288 arcsas - ok

07:09:25.0299 2288 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

07:09:25.0331 2288 aspnet_state - ok

07:09:25.0346 2288 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys

07:09:25.0346 2288 AsyncMac - ok

07:09:25.0377 2288 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys

07:09:25.0377 2288 atapi - ok

07:09:25.0393 2288 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

07:09:25.0409 2288 AudioEndpointBuilder - ok

07:09:25.0424 2288 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll

07:09:25.0424 2288 AudioSrv - ok

07:09:25.0518 2288 [ 6C9D5BADC8F83D410A278717C2EEA6F6 ] AVP C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

07:09:25.0518 2288 AVP - ok

07:09:25.0533 2288 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll

07:09:25.0533 2288 AxInstSV - ok

07:09:25.0549 2288 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys

07:09:25.0565 2288 b06bdrv - ok

07:09:25.0580 2288 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys

07:09:25.0580 2288 b57nd60a - ok

07:09:25.0674 2288 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe

07:09:25.0689 2288 BBSvc - ok

07:09:25.0721 2288 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe

07:09:25.0721 2288 BBUpdate - ok

07:09:25.0799 2288 [ 8B5D16D20774FC3727F44E161BE2C0AC ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys

07:09:25.0830 2288 BCM43XX - ok

07:09:25.0845 2288 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll

07:09:25.0845 2288 BDESVC - ok

07:09:25.0845 2288 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys

07:09:25.0861 2288 Beep - ok

07:09:25.0892 2288 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll

07:09:25.0892 2288 BFE - ok

07:09:25.0923 2288 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll

07:09:25.0939 2288 BITS - ok

07:09:25.0955 2288 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys

07:09:25.0955 2288 blbdrive - ok

07:09:25.0970 2288 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys

07:09:25.0986 2288 bowser - ok

07:09:25.0986 2288 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys

07:09:25.0986 2288 BrFiltLo - ok

07:09:26.0001 2288 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys

07:09:26.0001 2288 BrFiltUp - ok

07:09:26.0033 2288 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys

07:09:26.0033 2288 BridgeMP - ok

07:09:26.0064 2288 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll

07:09:26.0064 2288 Browser - ok

07:09:26.0095 2288 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys

07:09:26.0095 2288 Brserid - ok

07:09:26.0111 2288 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys

07:09:26.0111 2288 BrSerWdm - ok

07:09:26.0111 2288 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys

07:09:26.0111 2288 BrUsbMdm - ok

07:09:26.0126 2288 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys

07:09:26.0126 2288 BrUsbSer - ok

07:09:26.0142 2288 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys

07:09:26.0142 2288 BTHMODEM - ok

07:09:26.0157 2288 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll

07:09:26.0157 2288 bthserv - ok

07:09:26.0173 2288 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys

07:09:26.0173 2288 cdfs - ok

07:09:26.0204 2288 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys

07:09:26.0204 2288 cdrom - ok

07:09:26.0220 2288 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll

07:09:26.0220 2288 CertPropSvc - ok

07:09:26.0235 2288 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys

07:09:26.0235 2288 circlass - ok

07:09:26.0251 2288 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys

07:09:26.0251 2288 CLFS - ok

07:09:26.0298 2288 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

07:09:26.0313 2288 clr_optimization_v2.0.50727_32 - ok

07:09:26.0345 2288 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe

07:09:26.0345 2288 clr_optimization_v2.0.50727_64 - ok

07:09:26.0391 2288 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

07:09:26.0391 2288 clr_optimization_v4.0.30319_32 - ok

07:09:26.0407 2288 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

07:09:26.0423 2288 clr_optimization_v4.0.30319_64 - ok

07:09:26.0438 2288 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys

07:09:26.0438 2288 CmBatt - ok

07:09:26.0454 2288 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys

07:09:26.0454 2288 cmdide - ok

07:09:26.0485 2288 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys

07:09:26.0485 2288 CNG - ok

07:09:26.0501 2288 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys

07:09:26.0516 2288 Compbatt - ok

07:09:26.0532 2288 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys

07:09:26.0532 2288 CompositeBus - ok

07:09:26.0547 2288 COMSysApp - ok

07:09:26.0563 2288 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys

07:09:26.0563 2288 crcdisk - ok

07:09:26.0594 2288 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll

07:09:26.0594 2288 CryptSvc - ok

07:09:26.0625 2288 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys

07:09:26.0641 2288 CSC - ok

07:09:26.0657 2288 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll

07:09:26.0672 2288 CscService - ok

07:09:26.0703 2288 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll

07:09:26.0703 2288 DcomLaunch - ok

07:09:26.0735 2288 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll

07:09:26.0735 2288 defragsvc - ok

07:09:26.0750 2288 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys

07:09:26.0750 2288 DfsC - ok

07:09:26.0766 2288 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll

07:09:26.0781 2288 Dhcp - ok

07:09:26.0781 2288 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys

07:09:26.0781 2288 discache - ok

07:09:26.0797 2288 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys

07:09:26.0813 2288 Disk - ok

07:09:26.0828 2288 [ 5DB085A8A6600BE6401F2B24EECB5415 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys

07:09:26.0844 2288 dmvsc - ok

07:09:26.0859 2288 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll

07:09:26.0875 2288 Dnscache - ok

07:09:26.0875 2288 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll

07:09:26.0891 2288 dot3svc - ok

07:09:26.0922 2288 [ B42ED0320C6E41102FDE0005154849BB ] dot4 C:\Windows\system32\DRIVERS\Dot4.sys

07:09:26.0922 2288 dot4 - ok

07:09:26.0922 2288 [ E9F5969233C5D89F3C35E3A66A52A361 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys

07:09:26.0937 2288 Dot4Print - ok

07:09:26.0953 2288 [ FD05A02B0370BC3000F402E543CA5814 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys

07:09:26.0953 2288 dot4usb - ok

07:09:26.0953 2288 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll

07:09:26.0969 2288 DPS - ok

07:09:26.0984 2288 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys

07:09:26.0984 2288 drmkaud - ok

07:09:27.0031 2288 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys

07:09:27.0047 2288 DXGKrnl - ok

07:09:27.0062 2288 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll

07:09:27.0062 2288 EapHost - ok

07:09:27.0125 2288 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys

07:09:27.0187 2288 ebdrv - ok

07:09:27.0218 2288 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe

07:09:27.0234 2288 EFS - ok

07:09:27.0281 2288 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe

07:09:27.0281 2288 ehRecvr - ok

07:09:27.0296 2288 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe

07:09:27.0296 2288 ehSched - ok

07:09:27.0327 2288 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys

07:09:27.0327 2288 elxstor - ok

07:09:27.0327 2288 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys

07:09:27.0327 2288 ErrDev - ok

07:09:27.0359 2288 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll

07:09:27.0359 2288 EventSystem - ok

07:09:27.0374 2288 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys

07:09:27.0390 2288 exfat - ok

07:09:27.0405 2288 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys

07:09:27.0405 2288 fastfat - ok

07:09:27.0421 2288 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe

07:09:27.0437 2288 Fax - ok

07:09:27.0437 2288 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys

07:09:27.0437 2288 fdc - ok

07:09:27.0452 2288 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll

07:09:27.0452 2288 fdPHost - ok

07:09:27.0452 2288 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll

07:09:27.0468 2288 FDResPub - ok

07:09:27.0561 2288 [ 72BA777BFB3E77DE87B1F491B50C7B21 ] FibUacService C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe

07:09:27.0561 2288 FibUacService - ok

07:09:27.0577 2288 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys

07:09:27.0593 2288 FileInfo - ok

07:09:27.0593 2288 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys

07:09:27.0608 2288 Filetrace - ok

07:09:27.0639 2288 [ 8669BE94F63944E4F899C3950B520241 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

07:09:27.0639 2288 FLEXnet Licensing Service - ok

07:09:27.0655 2288 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys

07:09:27.0671 2288 flpydisk - ok

07:09:27.0686 2288 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys

07:09:27.0686 2288 FltMgr - ok

07:09:27.0717 2288 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll

07:09:27.0749 2288 FontCache - ok

07:09:27.0795 2288 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

07:09:27.0795 2288 FontCache3.0.0.0 - ok

07:09:27.0811 2288 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys

07:09:27.0811 2288 FsDepends - ok

07:09:27.0827 2288 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys

07:09:27.0827 2288 Fs_Rec - ok

07:09:27.0873 2288 [ 3D35EFFE5F7A2F4176CE361E23E59A62 ] FullImagingService C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe

07:09:27.0873 2288 FullImagingService - ok

07:09:27.0905 2288 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys

07:09:27.0905 2288 fvevol - ok

07:09:27.0920 2288 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys

07:09:27.0920 2288 gagp30kx - ok

07:09:27.0967 2288 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll

07:09:27.0967 2288 gpsvc - ok

07:09:28.0045 2288 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

07:09:28.0045 2288 gupdate - ok

07:09:28.0061 2288 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

07:09:28.0061 2288 gupdatem - ok

07:09:28.0076 2288 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys

07:09:28.0076 2288 hcw85cir - ok

07:09:28.0107 2288 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys

07:09:28.0107 2288 HDAudBus - ok

07:09:28.0123 2288 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys

07:09:28.0123 2288 HidBatt - ok

07:09:28.0139 2288 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys

07:09:28.0139 2288 HidBth - ok

07:09:28.0170 2288 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys

07:09:28.0170 2288 HidIr - ok

07:09:28.0185 2288 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll

07:09:28.0185 2288 hidserv - ok

07:09:28.0201 2288 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys

07:09:28.0201 2288 HidUsb - ok

07:09:28.0217 2288 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll

07:09:28.0217 2288 hkmsvc - ok

07:09:28.0232 2288 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll

07:09:28.0232 2288 HomeGroupListener - ok

07:09:28.0263 2288 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll

07:09:28.0263 2288 HomeGroupProvider - ok

07:09:28.0279 2288 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys

07:09:28.0279 2288 HpSAMD - ok

07:09:28.0310 2288 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys

07:09:28.0326 2288 HTTP - ok

07:09:28.0341 2288 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys

07:09:28.0341 2288 hwpolicy - ok

07:09:28.0357 2288 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys

07:09:28.0357 2288 i8042prt - ok

07:09:28.0388 2288 [ F7CE9BE72EDAC499B713ECA6DAE5D26F ] iaStor C:\Windows\system32\drivers\iaStor.sys

07:09:28.0388 2288 iaStor - ok

07:09:28.0419 2288 [ B25F192EA1F84A316EB7C19EFCCCF33D ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

07:09:28.0435 2288 IAStorDataMgrSvc - ok

07:09:28.0451 2288 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys

07:09:28.0451 2288 iaStorV - ok

07:09:28.0513 2288 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe

07:09:28.0513 2288 idsvc - ok

07:09:28.0529 2288 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys

07:09:28.0529 2288 iirsp - ok

07:09:28.0560 2288 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll

07:09:28.0560 2288 IKEEXT - ok

07:09:28.0591 2288 [ DD587A55390ED2295BCE6D36AD567DA9 ] Impcd C:\Windows\system32\drivers\Impcd.sys

07:09:28.0591 2288 Impcd - ok

07:09:28.0653 2288 [ 235362D403D9D677514649D88DB31914 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys

07:09:28.0669 2288 IntcAzAudAddService - ok

07:09:28.0700 2288 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys

07:09:28.0700 2288 IntcDAud - ok

07:09:28.0700 2288 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys

07:09:28.0716 2288 intelide - ok

07:09:28.0716 2288 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys

07:09:28.0731 2288 intelppm - ok

07:09:28.0809 2288 [ D9DA7B3117BF5EFF921C0CDED4D58050 ] IntuitUpdateServiceV4 C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

07:09:28.0809 2288 IntuitUpdateServiceV4 - ok

07:09:28.0841 2288 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll

07:09:28.0841 2288 IPBusEnum - ok

07:09:28.0872 2288 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys

07:09:28.0872 2288 IpFilterDriver - ok

07:09:28.0919 2288 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll

07:09:28.0919 2288 iphlpsvc - ok

07:09:28.0950 2288 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys

07:09:28.0950 2288 IPMIDRV - ok

07:09:28.0950 2288 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys

07:09:28.0965 2288 IPNAT - ok

07:09:28.0965 2288 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys

07:09:28.0981 2288 IRENUM - ok

07:09:28.0997 2288 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys

07:09:28.0997 2288 isapnp - ok

07:09:29.0012 2288 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys

07:09:29.0012 2288 iScsiPrt - ok

07:09:29.0028 2288 [ 12E27942DBB7C91880163634B0D8A776 ] k57nd60a C:\Windows\system32\DRIVERS\k57nd60a.sys

07:09:29.0043 2288 k57nd60a - ok

07:09:29.0059 2288 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys

07:09:29.0059 2288 kbdclass - ok

07:09:29.0075 2288 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys

07:09:29.0075 2288 kbdhid - ok

07:09:29.0090 2288 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe

07:09:29.0090 2288 KeyIso - ok

07:09:29.0121 2288 [ E656FE10D6D27794AFA08136685A69E8 ] KL1 C:\Windows\system32\DRIVERS\kl1.sys

07:09:29.0137 2288 KL1 - ok

07:09:29.0153 2288 [ D865DD8B0448E3F963D68C04C532858F ] kl2 C:\Windows\system32\DRIVERS\kl2.sys

07:09:29.0153 2288 kl2 - ok

07:09:29.0184 2288 [ 8490798365236B6C8E54DEDD27A42D07 ] KLIF C:\Windows\system32\DRIVERS\klif.sys

07:09:29.0184 2288 KLIF - ok

07:09:29.0199 2288 [ 89FB5A33D7171B6D84F5EB721D5055E1 ] KLIM6 C:\Windows\system32\DRIVERS\klim6.sys

07:09:29.0199 2288 KLIM6 - ok

07:09:29.0215 2288 [ 9468D07E91BA136D82415F5DFC1FE168 ] klmouflt C:\Windows\system32\DRIVERS\klmouflt.sys

07:09:29.0215 2288 klmouflt - ok

07:09:29.0246 2288 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys

07:09:29.0246 2288 KSecDD - ok

07:09:29.0262 2288 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys

07:09:29.0262 2288 KSecPkg - ok

07:09:29.0262 2288 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys

07:09:29.0262 2288 ksthunk - ok

07:09:29.0293 2288 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll

07:09:29.0293 2288 KtmRm - ok

07:09:29.0324 2288 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll

07:09:29.0340 2288 LanmanServer - ok

07:09:29.0355 2288 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll

07:09:29.0355 2288 LanmanWorkstation - ok

07:09:29.0371 2288 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys

07:09:29.0371 2288 lltdio - ok

07:09:29.0402 2288 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll

07:09:29.0402 2288 lltdsvc - ok

07:09:29.0418 2288 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll

07:09:29.0418 2288 lmhosts - ok

07:09:29.0433 2288 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys

07:09:29.0433 2288 LSI_FC - ok

07:09:29.0449 2288 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys

07:09:29.0449 2288 LSI_SAS - ok

07:09:29.0465 2288 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys

07:09:29.0465 2288 LSI_SAS2 - ok

07:09:29.0480 2288 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys

07:09:29.0480 2288 LSI_SCSI - ok

07:09:29.0496 2288 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys

07:09:29.0511 2288 luafv - ok

07:09:29.0543 2288 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys

07:09:29.0543 2288 MBAMProtector - ok

07:09:29.0605 2288 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

07:09:29.0605 2288 MBAMScheduler - ok

07:09:29.0652 2288 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

07:09:29.0652 2288 MBAMService - ok

07:09:29.0667 2288 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll

07:09:29.0667 2288 Mcx2Svc - ok

07:09:29.0683 2288 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys

07:09:29.0683 2288 megasas - ok

07:09:29.0699 2288 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys

07:09:29.0699 2288 MegaSR - ok

07:09:29.0745 2288 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys

07:09:29.0745 2288 MEIx64 - ok

07:09:29.0808 2288 Microsoft SharePoint Workspace Audit Service - ok

07:09:29.0839 2288 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll

07:09:29.0839 2288 MMCSS - ok

07:09:29.0839 2288 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys

07:09:29.0839 2288 Modem - ok

07:09:29.0870 2288 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys

07:09:29.0870 2288 monitor - ok

07:09:29.0901 2288 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys

07:09:29.0901 2288 mouclass - ok

07:09:29.0933 2288 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys

07:09:29.0933 2288 mouhid - ok

07:09:29.0948 2288 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys

07:09:29.0948 2288 mountmgr - ok

07:09:30.0026 2288 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

07:09:30.0026 2288 MozillaMaintenance - ok

07:09:30.0026 2288 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys

07:09:30.0042 2288 mpio - ok

07:09:30.0042 2288 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys

07:09:30.0057 2288 mpsdrv - ok

07:09:30.0073 2288 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll

07:09:30.0089 2288 MpsSvc - ok

07:09:30.0104 2288 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys

07:09:30.0104 2288 MRxDAV - ok

07:09:30.0120 2288 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys

07:09:30.0120 2288 mrxsmb - ok

07:09:30.0151 2288 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys

07:09:30.0151 2288 mrxsmb10 - ok

07:09:30.0167 2288 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys

07:09:30.0167 2288 mrxsmb20 - ok

07:09:30.0198 2288 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys

07:09:30.0198 2288 msahci - ok

07:09:30.0213 2288 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys

07:09:30.0213 2288 msdsm - ok

07:09:30.0229 2288 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe

07:09:30.0229 2288 MSDTC - ok

07:09:30.0245 2288 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys

07:09:30.0245 2288 Msfs - ok

07:09:30.0260 2288 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys

07:09:30.0260 2288 mshidkmdf - ok

07:09:30.0276 2288 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys

07:09:30.0276 2288 msisadrv - ok

07:09:30.0307 2288 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll

07:09:30.0307 2288 MSiSCSI - ok

07:09:30.0307 2288 msiserver - ok

07:09:30.0323 2288 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys

07:09:30.0323 2288 MSKSSRV - ok

07:09:30.0323 2288 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys

07:09:30.0338 2288 MSPCLOCK - ok

07:09:30.0338 2288 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys

07:09:30.0338 2288 MSPQM - ok

07:09:30.0354 2288 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys

07:09:30.0354 2288 MsRPC - ok

07:09:30.0369 2288 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys

07:09:30.0369 2288 mssmbios - ok

07:09:30.0385 2288 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys

07:09:30.0385 2288 MSTEE - ok

07:09:30.0401 2288 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys

07:09:30.0401 2288 MTConfig - ok

07:09:30.0401 2288 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys

07:09:30.0401 2288 Mup - ok

07:09:30.0432 2288 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll

07:09:30.0447 2288 napagent - ok

07:09:30.0479 2288 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys

07:09:30.0479 2288 NativeWifiP - ok

07:09:30.0572 2288 [ 934BB0D23A25C8C136570800A5A149B6 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe

07:09:30.0572 2288 NAUpdate - ok

07:09:30.0619 2288 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys

07:09:30.0635 2288 NDIS - ok

07:09:30.0650 2288 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys

07:09:30.0650 2288 NdisCap - ok

07:09:30.0666 2288 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys

07:09:30.0666 2288 NdisTapi - ok

07:09:30.0681 2288 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys

07:09:30.0681 2288 Ndisuio - ok

07:09:30.0697 2288 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys

07:09:30.0697 2288 NdisWan - ok

07:09:30.0713 2288 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys

07:09:30.0713 2288 NDProxy - ok

07:09:30.0728 2288 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys

07:09:30.0728 2288 NetBIOS - ok

07:09:30.0744 2288 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys

07:09:30.0744 2288 NetBT - ok

07:09:30.0759 2288 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe

07:09:30.0759 2288 Netlogon - ok

07:09:30.0791 2288 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll

07:09:30.0791 2288 Netman - ok

07:09:30.0822 2288 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

07:09:30.0822 2288 NetMsmqActivator - ok

07:09:30.0837 2288 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

07:09:30.0837 2288 NetPipeActivator - ok

07:09:30.0853 2288 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll

07:09:30.0869 2288 netprofm - ok

07:09:30.0869 2288 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

07:09:30.0869 2288 NetTcpActivator - ok

07:09:30.0869 2288 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

07:09:30.0869 2288 NetTcpPortSharing - ok

07:09:30.0915 2288 [ 73CE12B8BDD747B0063CB0A7EF44CEA7 ] netvsc C:\Windows\system32\DRIVERS\netvsc60.sys

07:09:30.0931 2288 netvsc - ok

07:09:30.0947 2288 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys

07:09:30.0947 2288 nfrd960 - ok

07:09:30.0962 2288 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll

07:09:30.0962 2288 NlaSvc - ok

07:09:31.0040 2288 [ B9B72FAAAA41D59B73B88FE3DD737ED1 ] NOBU C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe

07:09:31.0103 2288 NOBU - ok

07:09:31.0118 2288 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys

07:09:31.0118 2288 Npfs - ok

07:09:31.0118 2288 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll

07:09:31.0134 2288 nsi - ok

07:09:31.0134 2288 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys

07:09:31.0134 2288 nsiproxy - ok

07:09:31.0196 2288 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys

07:09:31.0227 2288 Ntfs - ok

07:09:31.0243 2288 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys

07:09:31.0243 2288 Null - ok

07:09:31.0274 2288 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys

07:09:31.0274 2288 NVHDA - ok

07:09:31.0461 2288 [ 64B046CA14B8EE7ED6D21CFA326B3363 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys

07:09:31.0508 2288 nvlddmkm - ok

07:09:31.0555 2288 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys

07:09:31.0555 2288 nvraid - ok

07:09:31.0571 2288 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys

07:09:31.0571 2288 nvstor - ok

07:09:31.0602 2288 [ 77B013AE58952C6E9DC982D7803311C5 ] NVSvc C:\Windows\system32\nvvsvc.exe

07:09:31.0617 2288 NVSvc - ok

07:09:31.0649 2288 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys

07:09:31.0649 2288 nv_agp - ok

07:09:31.0664 2288 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys

07:09:31.0664 2288 ohci1394 - ok

07:09:31.0711 2288 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE

07:09:31.0711 2288 ose - ok

07:09:31.0836 2288 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

07:09:31.0851 2288 osppsvc - ok

07:09:31.0883 2288 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll

07:09:31.0883 2288 p2pimsvc - ok

07:09:31.0898 2288 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll

07:09:31.0898 2288 p2psvc - ok

07:09:31.0914 2288 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys

07:09:31.0914 2288 Parport - ok

07:09:31.0945 2288 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys

07:09:31.0945 2288 partmgr - ok

07:09:31.0961 2288 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll

07:09:31.0961 2288 PcaSvc - ok

07:09:31.0976 2288 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys

07:09:31.0976 2288 pci - ok

07:09:31.0992 2288 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys

07:09:31.0992 2288 pciide - ok

07:09:32.0023 2288 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys

07:09:32.0023 2288 pcmcia - ok

07:09:32.0039 2288 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys

07:09:32.0039 2288 pcw - ok

07:09:32.0054 2288 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys

07:09:32.0070 2288 PEAUTH - ok

07:09:32.0101 2288 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll

07:09:32.0132 2288 PeerDistSvc - ok

07:09:32.0195 2288 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe

07:09:32.0195 2288 PerfHost - ok

07:09:32.0226 2288 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll

07:09:32.0257 2288 pla - ok

07:09:32.0319 2288 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll

07:09:32.0319 2288 PlugPlay - ok

07:09:32.0366 2288 [ 64CA1485214340CACC315FFDFDED73EF ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll

07:09:32.0366 2288 Pml Driver HPZ12 - ok

07:09:32.0382 2288 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll

07:09:32.0382 2288 PNRPAutoReg - ok

07:09:32.0397 2288 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll

07:09:32.0397 2288 PNRPsvc - ok

07:09:32.0429 2288 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll

07:09:32.0429 2288 PolicyAgent - ok

07:09:32.0444 2288 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll

07:09:32.0460 2288 Power - ok

07:09:32.0475 2288 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys

07:09:32.0491 2288 PptpMiniport - ok

07:09:32.0491 2288 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys

07:09:32.0507 2288 Processor - ok

07:09:32.0538 2288 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll

07:09:32.0538 2288 ProfSvc - ok

07:09:32.0553 2288 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe

07:09:32.0553 2288 ProtectedStorage - ok

07:09:32.0569 2288 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys

07:09:32.0569 2288 Psched - ok

07:09:32.0585 2288 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys

07:09:32.0585 2288 PSI - ok

07:09:32.0616 2288 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys

07:09:32.0616 2288 PxHlpa64 - ok

07:09:32.0678 2288 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys

07:09:32.0709 2288 ql2300 - ok

07:09:32.0709 2288 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys

07:09:32.0725 2288 ql40xx - ok

07:09:32.0741 2288 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll

07:09:32.0741 2288 QWAVE - ok

07:09:32.0756 2288 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys

07:09:32.0756 2288 QWAVEdrv - ok

07:09:32.0756 2288 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys

07:09:32.0756 2288 RasAcd - ok

07:09:32.0772 2288 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys

07:09:32.0772 2288 RasAgileVpn - ok

07:09:32.0787 2288 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll

07:09:32.0787 2288 RasAuto - ok

07:09:32.0803 2288 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys

07:09:32.0803 2288 Rasl2tp - ok

07:09:32.0819 2288 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll

07:09:32.0834 2288 RasMan - ok

07:09:32.0834 2288 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys

07:09:32.0834 2288 RasPppoe - ok

07:09:32.0850 2288 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys

07:09:32.0850 2288 RasSstp - ok

07:09:32.0865 2288 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys

07:09:32.0865 2288 rdbss - ok

07:09:32.0881 2288 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys

07:09:32.0881 2288 rdpbus - ok

07:09:32.0912 2288 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys

07:09:32.0912 2288 RDPCDD - ok

07:09:32.0943 2288 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys

07:09:32.0943 2288 RDPDR - ok

07:09:32.0959 2288 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys

07:09:32.0975 2288 RDPENCDD - ok

07:09:32.0975 2288 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys

07:09:32.0975 2288 RDPREFMP - ok

07:09:33.0006 2288 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys

07:09:33.0006 2288 RDPWD - ok

07:09:33.0037 2288 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys

07:09:33.0037 2288 rdyboost - ok

07:09:33.0053 2288 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll

07:09:33.0068 2288 RemoteAccess - ok

07:09:33.0068 2288 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll

07:09:33.0068 2288 RemoteRegistry - ok

07:09:33.0177 2288 [ 3C957189B31C34D3AD21967B12B6AED7 ] RoxMediaDB12OEM C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

07:09:33.0177 2288 RoxMediaDB12OEM - ok

07:09:33.0209 2288 [ 2B73088CC2CA757A172B425C9398E5BC ] RoxWatch12 C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

07:09:33.0209 2288 RoxWatch12 - ok

07:09:33.0224 2288 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll

07:09:33.0224 2288 RpcEptMapper - ok

07:09:33.0240 2288 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe

07:09:33.0240 2288 RpcLocator - ok

07:09:33.0255 2288 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll

07:09:33.0271 2288 RpcSs - ok

07:09:33.0271 2288 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys

07:09:33.0271 2288 rspndr - ok

07:09:33.0287 2288 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys

07:09:33.0287 2288 s3cap - ok

07:09:33.0302 2288 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe

07:09:33.0302 2288 SamSs - ok

07:09:33.0318 2288 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys

07:09:33.0318 2288 sbp2port - ok

07:09:33.0333 2288 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll

07:09:33.0333 2288 SCardSvr - ok

07:09:33.0349 2288 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys

07:09:33.0349 2288 scfilter - ok

07:09:33.0380 2288 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll

07:09:33.0411 2288 Schedule - ok

07:09:33.0411 2288 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll

07:09:33.0427 2288 SCPolicySvc - ok

07:09:33.0427 2288 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll

07:09:33.0427 2288 SDRSVC - ok

07:09:33.0443 2288 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys

07:09:33.0458 2288 secdrv - ok

07:09:33.0458 2288 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll

07:09:33.0458 2288 seclogon - ok

07:09:33.0505 2288 [ 2D0599DD0124764FC939C59985C860DE ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe

07:09:33.0521 2288 Secunia PSI Agent - ok

07:09:33.0536 2288 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll

07:09:33.0536 2288 SENS - ok

07:09:33.0552 2288 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll

07:09:33.0552 2288 SensrSvc - ok

07:09:33.0567 2288 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys

07:09:33.0567 2288 Serenum - ok

07:09:33.0583 2288 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys

07:09:33.0583 2288 Serial - ok

07:09:33.0599 2288 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys

07:09:33.0599 2288 sermouse - ok

07:09:33.0614 2288 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll

07:09:33.0630 2288 SessionEnv - ok

07:09:33.0630 2288 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys

07:09:33.0630 2288 sffdisk - ok

07:09:33.0630 2288 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys

07:09:33.0630 2288 sffp_mmc - ok

07:09:33.0645 2288 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys

07:09:33.0645 2288 sffp_sd - ok

07:09:33.0645 2288 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys

07:09:33.0645 2288 sfloppy - ok

07:09:33.0723 2288 [ 1968E6EBBEECF61D5F7D8603467E2AD0 ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

07:09:33.0739 2288 SftService - ok

07:09:33.0786 2288 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll

07:09:33.0786 2288 SharedAccess - ok

07:09:33.0801 2288 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll

07:09:33.0817 2288 ShellHWDetection - ok

07:09:33.0817 2288 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys

07:09:33.0817 2288 SiSRaid2 - ok

07:09:33.0833 2288 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys

07:09:33.0833 2288 SiSRaid4 - ok

07:09:33.0833 2288 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys

07:09:33.0848 2288 Smb - ok

07:09:33.0879 2288 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe

07:09:33.0879 2288 SNMPTRAP - ok

07:09:33.0895 2288 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys

07:09:33.0895 2288 spldr - ok

07:09:33.0926 2288 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe

07:09:33.0942 2288 Spooler - ok

07:09:33.0989 2288 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe

07:09:34.0067 2288 sppsvc - ok

07:09:34.0082 2288 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll

07:09:34.0098 2288 sppuinotify - ok

07:09:34.0113 2288 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys

07:09:34.0113 2288 srv - ok

07:09:34.0145 2288 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys

07:09:34.0145 2288 srv2 - ok

07:09:34.0160 2288 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys

07:09:34.0160 2288 srvnet - ok

07:09:34.0176 2288 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll

07:09:34.0191 2288 SSDPSRV - ok

07:09:34.0191 2288 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll

07:09:34.0191 2288 SstpSvc - ok

07:09:34.0207 2288 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys

07:09:34.0207 2288 stexstor - ok

07:09:34.0223 2288 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll

07:09:34.0238 2288 stisvc - ok

07:09:34.0269 2288 [ 7731F46EC0D687A931CBA063E8F90EF0 ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

07:09:34.0269 2288 stllssvr - ok

07:09:34.0285 2288 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll

07:09:34.0285 2288 StorSvc - ok

07:09:34.0301 2288 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys

07:09:34.0316 2288 storvsc - ok

07:09:34.0316 2288 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys

07:09:34.0316 2288 swenum - ok

07:09:34.0332 2288 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll

07:09:34.0347 2288 swprv - ok

07:09:34.0363 2288 [ 4CDD7DF58730D23BA9CB5829A6E2ECEA ] SynthVid C:\Windows\system32\DRIVERS\VMBusVideoM.sys

07:09:34.0363 2288 SynthVid - ok

07:09:34.0394 2288 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll

07:09:34.0441 2288 SysMain - ok

07:09:34.0457 2288 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll

07:09:34.0472 2288 TabletInputService - ok

07:09:34.0472 2288 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll

07:09:34.0488 2288 TapiSrv - ok

07:09:34.0488 2288 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll

07:09:34.0488 2288 TBS - ok

07:09:34.0535 2288 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys

07:09:34.0597 2288 Tcpip - ok

07:09:34.0628 2288 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys

07:09:34.0644 2288 TCPIP6 - ok

07:09:34.0691 2288 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys

07:09:34.0691 2288 tcpipreg - ok

07:09:34.0706 2288 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys

07:09:34.0706 2288 TDPIPE - ok

07:09:34.0722 2288 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys

07:09:34.0737 2288 TDTCP - ok

07:09:34.0753 2288 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys

07:09:34.0753 2288 tdx - ok

07:09:34.0769 2288 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys

07:09:34.0769 2288 TermDD - ok

07:09:34.0784 2288 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll

07:09:34.0800 2288 TermService - ok

07:09:34.0800 2288 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll

07:09:34.0800 2288 Themes - ok

07:09:34.0847 2288 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll

07:09:34.0847 2288 THREADORDER - ok

07:09:34.0862 2288 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll

07:09:34.0878 2288 TrkWks - ok

07:09:34.0909 2288 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe

07:09:34.0909 2288 TrustedInstaller - ok

07:09:34.0925 2288 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys

07:09:34.0925 2288 tssecsrv - ok

07:09:34.0940 2288 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys

07:09:34.0940 2288 TsUsbFlt - ok

07:09:34.0956 2288 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys

07:09:34.0956 2288 TsUsbGD - ok

07:09:34.0971 2288 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys

07:09:34.0971 2288 tunnel - ok

07:09:34.0987 2288 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys

07:09:34.0987 2288 uagp35 - ok

07:09:35.0003 2288 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys

07:09:35.0018 2288 udfs - ok

07:09:35.0034 2288 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe

07:09:35.0034 2288 UI0Detect - ok

07:09:35.0049 2288 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys

07:09:35.0049 2288 uliagpkx - ok

07:09:35.0081 2288 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys

07:09:35.0081 2288 umbus - ok

07:09:35.0096 2288 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys

07:09:35.0096 2288 UmPass - ok

07:09:35.0127 2288 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll

07:09:35.0127 2288 UmRdpService - ok

07:09:35.0143 2288 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll

07:09:35.0143 2288 upnphost - ok

07:09:35.0174 2288 [ 19AD7990C0B67E48DAC5B26F99628223 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys

07:09:35.0174 2288 usbccgp - ok

07:09:35.0190 2288 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys

07:09:35.0190 2288 usbcir - ok

07:09:35.0190 2288 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys

07:09:35.0205 2288 usbehci - ok

07:09:35.0221 2288 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys

07:09:35.0221 2288 usbhub - ok

07:09:35.0237 2288 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys

07:09:35.0237 2288 usbohci - ok

07:09:35.0252 2288 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys

07:09:35.0252 2288 usbprint - ok

07:09:35.0252 2288 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS

07:09:35.0268 2288 USBSTOR - ok

07:09:35.0283 2288 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys

07:09:35.0283 2288 usbuhci - ok

07:09:35.0299 2288 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll

07:09:35.0299 2288 UxSms - ok

07:09:35.0315 2288 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe

07:09:35.0315 2288 VaultSvc - ok

07:09:35.0330 2288 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys

07:09:35.0330 2288 vdrvroot - ok

07:09:35.0346 2288 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe

07:09:35.0361 2288 vds - ok

07:09:35.0361 2288 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys

07:09:35.0361 2288 vga - ok

07:09:35.0361 2288 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys

07:09:35.0361 2288 VgaSave - ok

07:09:35.0377 2288 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys

07:09:35.0393 2288 vhdmp - ok

07:09:35.0408 2288 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys

07:09:35.0408 2288 viaide - ok

07:09:35.0424 2288 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys

07:09:35.0424 2288 VMBusHID - ok

07:09:35.0439 2288 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys

07:09:35.0439 2288 volmgr - ok

07:09:35.0455 2288 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys

07:09:35.0471 2288 volmgrx - ok

07:09:35.0486 2288 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys

07:09:35.0486 2288 volsnap - ok

07:09:35.0502 2288 [ B4A73CA4EF9A02B9738CEA9AD5FE5917 ] vpcbus C:\Windows\system32\DRIVERS\vpchbus.sys

07:09:35.0502 2288 vpcbus - ok

07:09:35.0549 2288 [ E675FB2B48C54F09895482E2253B289C ] vpcnfltr C:\Windows\system32\DRIVERS\vpcnfltr.sys

07:09:35.0549 2288 vpcnfltr - ok

07:09:35.0564 2288 [ 5FB42082B0D19A0268705F1DD343DF20 ] vpcusb C:\Windows\system32\DRIVERS\vpcusb.sys

07:09:35.0564 2288 vpcusb - ok

07:09:35.0580 2288 [ 30D4243726A15A14F5C5E45898D14394 ] vpcvmm C:\Windows\system32\drivers\vpcvmm.sys

07:09:35.0580 2288 vpcvmm - ok

07:09:35.0611 2288 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys

07:09:35.0611 2288 vsmraid - ok

07:09:35.0642 2288 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe

07:09:35.0673 2288 VSS - ok

07:09:35.0689 2288 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys

07:09:35.0689 2288 vwifibus - ok

07:09:35.0705 2288 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys

07:09:35.0705 2288 vwififlt - ok

07:09:35.0736 2288 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys

07:09:35.0736 2288 vwifimp - ok

07:09:35.0767 2288 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll

07:09:35.0767 2288 W32Time - ok

07:09:35.0783 2288 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys

07:09:35.0798 2288 WacomPen - ok

07:09:35.0814 2288 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys

07:09:35.0814 2288 WANARP - ok

07:09:35.0814 2288 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys

07:09:35.0814 2288 Wanarpv6 - ok

07:09:35.0876 2288 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe

07:09:35.0907 2288 WatAdminSvc - ok

07:09:35.0939 2288 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe

07:09:36.0063 2288 wbengine - ok

07:09:36.0079 2288 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll

07:09:36.0079 2288 WbioSrvc - ok

07:09:36.0095 2288 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll

07:09:36.0110 2288 wcncsvc - ok

07:09:36.0126 2288 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll

07:09:36.0126 2288 WcsPlugInService - ok

07:09:36.0141 2288 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys

07:09:36.0141 2288 Wd - ok

07:09:36.0173 2288 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys

07:09:36.0188 2288 Wdf01000 - ok

07:09:36.0188 2288 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll

07:09:36.0188 2288 WdiServiceHost - ok

07:09:36.0204 2288 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll

07:09:36.0204 2288 WdiSystemHost - ok

07:09:36.0219 2288 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll

07:09:36.0219 2288 WebClient - ok

07:09:36.0235 2288 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll

07:09:36.0235 2288 Wecsvc - ok

07:09:36.0251 2288 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll

07:09:36.0251 2288 wercplsupport - ok

07:09:36.0251 2288 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll

07:09:36.0266 2288 WerSvc - ok

07:09:36.0266 2288 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys

07:09:36.0282 2288 WfpLwf - ok

07:09:36.0313 2288 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys

07:09:36.0313 2288 WimFltr - ok

07:09:36.0329 2288 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys

07:09:36.0329 2288 WIMMount - ok

07:09:36.0344 2288 WinDefend - ok

07:09:36.0344 2288 WinHttpAutoProxySvc - ok

07:09:36.0391 2288 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll

07:09:36.0391 2288 Winmgmt - ok

07:09:36.0453 2288 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll

07:09:36.0500 2288 WinRM - ok

07:09:36.0531 2288 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys

07:09:36.0531 2288 WinUsb - ok

07:09:36.0563 2288 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll

07:09:36.0578 2288 Wlansvc - ok

07:09:36.0625 2288 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

07:09:36.0625 2288 wlcrasvc - ok

07:09:36.0687 2288 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

07:09:36.0703 2288 wlidsvc - ok

07:09:36.0719 2288 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys

07:09:36.0719 2288 WmiAcpi - ok

07:09:36.0734 2288 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe

07:09:36.0734 2288 wmiApSrv - ok

07:09:36.0750 2288 WMPNetworkSvc - ok

07:09:36.0781 2288 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll

07:09:36.0781 2288 WPCSvc - ok

07:09:36.0797 2288 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll

07:09:36.0812 2288 WPDBusEnum - ok

07:09:36.0812 2288 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys

07:09:36.0828 2288 ws2ifsl - ok

07:09:36.0843 2288 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll

07:09:36.0843 2288 wscsvc - ok

07:09:36.0843 2288 WSearch - ok

07:09:36.0906 2288 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll

07:09:36.0968 2288 wuauserv - ok

07:09:36.0999 2288 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys

07:09:36.0999 2288 WudfPf - ok

07:09:37.0046 2288 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys

07:09:37.0046 2288 WUDFRd - ok

07:09:37.0062 2288 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll

07:09:37.0062 2288 wudfsvc - ok

07:09:37.0077 2288 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll

07:09:37.0093 2288 WwanSvc - ok

07:09:37.0093 2288 ================ Scan global ===============================

07:09:37.0124 2288 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll

07:09:37.0155 2288 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll

07:09:37.0171 2288 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll

07:09:37.0187 2288 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll

07:09:37.0218 2288 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe

07:09:37.0218 2288 [Global] - ok

07:09:37.0218 2288 ================ Scan MBR ==================================

07:09:37.0233 2288 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0

07:09:37.0452 2288 \Device\Harddisk0\DR0 - ok

07:09:37.0452 2288 ================ Scan VBR ==================================

07:09:37.0452 2288 [ 3EF44B4224E77397F86AF12F22EB6E9D ] \Device\Harddisk0\DR0\Partition1

07:09:37.0467 2288 \Device\Harddisk0\DR0\Partition1 - ok

07:09:37.0467 2288 [ 40FC1DE1D6D80EA803BC1D3BA05320DA ] \Device\Harddisk0\DR0\Partition2

07:09:37.0467 2288 \Device\Harddisk0\DR0\Partition2 - ok

07:09:37.0467 2288 ============================================================

07:09:37.0467 2288 Scan finished

07:09:37.0467 2288 ============================================================

07:09:37.0483 2152 Detected object count: 0

07:09:37.0483 2152 Actual detected object count: 0

3. RKReport log

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy

mail : tigzyRK<at>gmail<dot>com

Feedback : http://www.geekstogo...13-roguekiller/

Website : http://tigzy.geeksto...roguekiller.php

Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User : Joan [Admin rights]

Mode : Scan -- Date : 05/29/2013 07:16:35

| ARK || FAK || MBR |

¤¤¤ Bad processes : 3 ¤¤¤

[sUSP PATH] FibUac.exe -- C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe [7] -> KILLED [TermProc]

[sUSP PATH] FullImagingService.exe -- C:\ProgramData\Clickfree\FullImagingBackup\FullImagingService.exe [7] -> KILLED [TermProc]

[sUSP PATH] cfagent.exe -- C:\ProgramData\Clickfree\cfagent.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 7 ¤¤¤

[RUN][sUSP PATH] HKCU\[...]\Run : ClickfreeMonitor (c:\programdata\Clickfree\cfagent.exe) [7] -> FOUND

[RUN][sUSP PATH] HKUS\S-1-5-21-2212834863-2338292145-3760869027-1000[...]\Run : ClickfreeMonitor (c:\programdata\Clickfree\cfagent.exe) [7] -> FOUND

[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND

[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND

[HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND

[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST31500341AS +++++

--- User ---

[MBR] 0d8761bb3318134530243c1e87e01abe

[bSP] a5ae6594aa5e9b3b40e8e95e9a3b62ad : Windows Vista MBR Code

Partition table:

0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo

1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 16638 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 34156544 | Size: 1414120 Mo

User = LL1 ... OK!

User = LL2 ... OK!

Finished : << RKreport[1]_S_05292013_02d0716.txt >>

RKreport[1]_S_05292013_02d0716.txt

Link to post
Share on other sites

You will want to print out or copy these instructions to Notepad for offline reference!

These steps are for member Bluelit only. If you are a casual viewer, do NOT try this on your system!

If you are not Bluelit and have a similar problem, do NOT post here; start your own topic

Do not run or start any other programs while these utilities and tools are in use!

Do NOT run any other tools on your own or do any fixes other than what is listed here.

If you have questions, please ask before you do something on your own.

But it is important that you get going on these following steps.

=

Close any of your open programs while you run these tools.

On most all of the following programs and tools, you will need to do a right-click on the program link or shortcut or desktop icon (as appropriate) and then select "Run as Administrator". Please remember that as you go along and use these tools, each in turn.

  • Disable your anti-virus program, How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs
  • Please disconnect any USB or external storage drives from the computer before you run this scan! i_arrow-l.gif
  • For Vista or Windows 7 / 8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.
    For Windows XP, double-click to start.
  • Wait until Prescan finishes. i_arrow-l.gif
  • On the RogueKiller console, click the Registry tab.
    Put a check next to all of these and uncheck the rest: (if found)
    [RUN][sUSP PATH] HKCU\[...]\Run : ClickfreeMonitor (c:\programdata\Clickfree\cfagent.exe) [7] -> FOUND
    [RUN][sUSP PATH] HKUS\S-1-5-21-2212834863-2338292145-3760869027-1000[...]\Run : ClickfreeMonitor (c:\programdata\Clickfree\cfagent.exe) [7] -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
    [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND

    UN-check any -other - lines shown on your screen that are not listed in the above list.
  • Then click on Delete on the right hand column under Options.
  • When done, logoff & Restart the system.
  • The log will be found as RKreport
    Copy & Paste the contents into next reply.

Task 2

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Please download Rkill by Grinler and save it to your desktop.

Link 2
Link 3
Link 4
Double-click on the Rkill desktop icon to run the tool.
If using Vista or Windows 7, right-click on it and Run As Administrator.
A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
If not, delete the file, then download and use the one provided in Link 2.
If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
If the tool does not run from any of the links provided, please let me know.
If your antivirus program gives a prompt message, respond positive to allow RKILL to run.
If a malware-rogue gives a message regarding RKILL, proceed forward to running RKILL

IF you still have a problem running RKILL, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.

When all done, rkill.txt log file will be on your desktop. Copy & Paste contents of Rkill.txt into a reply.

More Information about Rkill can be found at this link: http://www.bleepingcomputer.com/forums/topic308364.html

Task 3

  • Close any open documents/programs & all internet browsers you have running.
  • Please start AdwCleaner
  • Click on Delete button.
  • Confirm each time with OK.
  • Your computer will be rebooted automatically. A text file will open after the restart. Please post the content of that logfile in your reply.
  • Note: You can find the logfile at C:\AdwCleaner[s1]

Task 4

Close any open work documents, if any, saving your work.

Make sure to close any other programs that you started before.

Please download Junkware Removal Tool by Thisisu to your Desktop.

  • Please close your security software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or 7 or 8, right-mouse click JRT.exe and select Run as administrator.
  • The tool will open and display information and disclaimer in a Command prompt window.
  • I'd suggest you close all internet browsers at this point.
  • Press a key on keyboard to start scanning your system.
  • Please be very patient as this will take several minutes to complete, depending on your system's specifications.
  • There are approximatly 12 phases or so in this tool. You will see each phase listed in the Command prompt window.
  • On completion, a log (JRT.txt) is saved to your Desktop and will automatically open. And the command prompt will have been closed.
  • Please post the contents of JRT.txt into a new reply.
  • Re-enable your security software.

Task 5

If you have a prior copy of Combofix, delete it now

Download Combofix from any of the links below, and SAVE it to your Desktop.

Link 1

Link 2

**Note: It is important that it is saved directly to your Desktop and not run straight away from download **

Turn OFF your antivirus, otherwise it will interfere. How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Have infinite patience during the run & scan by Combofix. It has many phases: some 50+ stages

It will display it's "stage" within the Command prompt window. Do NOT panic if it seems slow to change ! It has lots of work.

You may notice the desktop icons disappear. Do NOT panic, as that is expected behavior.

Combofix my take as little as 10 minutes and perhaps as much as 30-40 minutes. Time taken will depend on speed of your system and how much there is to scan & how much it needs to clean.

If this is on a notebook system, make sure first the notebook is connected to wall-power (AC power)or a UPS system

Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.

Right- click on Combo-Fix.exe on your Desktop cf-icon.jpg and select "Run as Administrator".

  • A window may open with a warning or prompts. Accept the EULA and follow the prompts during the start phase of Combofix.
    When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.

A caution - Do not run Combofix more than once.

Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.

The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled.

If this occurs, please reboot to restore the desktop.

A file will be created at => C:\Combofix.txt.

Notes:

[1] IF after Combofix reboot you get the message

Illegal operation attempted on registry key that has been marked for deletion

....please reboot the computer, this should resolve the problem. You may have reboot the pc a second time if needed.

[2] Do not mouseclick combofix's window nor run any program while Combofix is running.

That may cause it to stall.

[3]When all done, IF Combofix did not do a Restart...then ... I need for you to Restart the system fresh :excl:

Reply & Copy & Paste contents of the C:\Combofix.txt log

and tell me, How is the system now icon_question.gif

Re-enable your antivirus program.

Link to post
Share on other sites

I think the system is better at startup. :unsure:

Task 1: RogueKiller log

Waited until Prescan was finished. Opened registry but nothing was found in the registry so I couldn't delete anything and generate a log.

Task 2: RKill log

Rkill 2.5.0 by Lawrence Abrams (Grinler)

http://www.bleepingcomputer.com/

Copyright 2008-2013 BleepingComputer.com

More Information about Rkill can be found at this link:

http://www.bleepingc...opic308364.html

Program started at: 05/29/2013 07:56:56 AM in x64 mode.

Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 05/29/2013 07:57:46 AM

Execution time: 0 hours(s), 0 minute(s), and 50 seconds(s)

Task 3: AdwCleaner log

# AdwCleaner v2.301 - Logfile created 05/29/2013 at 07:59:38

# Updated 16/05/2013 by Xplode

# Operating system : Windows 7 Professional Service Pack 1 (64 bits)

# User : Joan - JA

# Boot Mode : Normal

# Running from : C:\Users\Joan\Desktop\adwcleaner.exe

# Option [Delete]

***** [services] *****

***** [Files / Folders] *****

Deleted on reboot : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\ymm6qbpn.default\extensions\wtxpcom@mybrowserbar.com

***** [Registry] *****

Key Deleted : HKCU\Software\YahooPartnerToolbar

Key Deleted : HKLM\Software\Classes\Installer\Features\90C64EA18BA25EE488BF80DCF07F2FFD

Key Deleted : HKLM\Software\Classes\Installer\Products\90C64EA18BA25EE488BF80DCF07F2FFD

***** [internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16576

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\5uuc71d5.default-1344114154362\prefs.js

[OK] File is clean.

File : C:\Users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\ymm6qbpn.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.94

File : C:\Users\Joan\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R42].txt - [1403 octets] - [29/05/2013 07:04:54]

AdwCleaner[s13].txt - [1344 octets] - [29/05/2013 07:59:38]

########## EOF - C:\AdwCleaner[s13].txt - [1405 octets] ##########

Task 4: Junkware Removal Tool log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Junkware Removal Tool (JRT) by Thisisu

Version: 4.9.4 (05.06.2013:1)

OS: Windows 7 Professional x64

Ran by Joan on Wed 05/29/2013 at 8:06:47.99

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{38F71C59-C7FA-47B6-B98D-BEF53B45CEF8}

~~~ Files

~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{2637EE58-115F-400C-8242-70A47161F2BD}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{31A3FBBE-1D85-4D95-A03D-6D63F8580D0F}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{333B8A62-D0FF-40D3-9C19-323013575F97}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{457F728C-1743-4AE7-9875-0E1205FE0BE9}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{47C4228C-3E9D-4FD6-A02A-E506C0181D44}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{4E3B7F0C-34DF-4594-9190-CDB26CCEB817}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{5D6793AC-EFA2-4C7B-9AD4-8F2FBD621CEB}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{61F331BC-EAD2-481C-8160-85AF796645E7}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{626364E3-67FB-45A6-A0AE-0371F2EA3062}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{8656C4E5-25B4-418F-A53A-EC2ED0A839DB}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{8BAB6519-7441-4B13-8895-4DE4E8EF97B3}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{A981C4F8-032A-4F06-B78F-38D871380E00}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{AED5D18C-677E-4ECF-A704-201CC36CC4BF}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{CB5854C7-62AA-4880-956E-28512FE1CFBC}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{D1C646E2-4C40-4723-B55D-3B390445B623}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{DA9D84CB-4F70-4511-BB1A-EB9A963B334C}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{E20A636F-CE44-4816-A8FF-63E8E106DED7}

Successfully deleted: [Empty Folder] C:\Users\Joan\appdata\local\{FD62977B-1A09-4792-88D7-172FDF1293AD}

~~~ FireFox

Failed to delete: [Folder] C:\Users\Joan\AppData\Roaming\mozilla\firefox\profiles\ymm6qbpn.default\extensions\wtxpcom@mybrowserbar.com

Successfully deleted the following from C:\Users\Joan\AppData\Roaming\mozilla\firefox\profiles\5uuc71d5.default-1344114154362\prefs.js

user_pref("extensions.fctlite.defaultRule", "t;;uri;;.;;ct;;torrent;;C1;;;;Download%20torrent%20anywhere;;0001;;@@@f;;uri;;\\.flv|\\.mp4|\\.f4v|\\.hlv|videoback;;content-lengt

Emptied folder: C:\Users\Joan\AppData\Roaming\mozilla\firefox\profiles\ymm6qbpn.default\minidumps [26 files]

Emptied folder: C:\Users\Joan\AppData\Roaming\mozilla\firefox\profiles\5uuc71d5.default-1344114154362\minidumps [355 files]

~~~ Event Viewer Logs were cleared

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Scan was completed on Wed 05/29/2013 at 8:09:50.97

End of JRT log

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Task 5: Combofix log

ComboFix 13-05-29.01 - Joan 05/29/2013 8:20.2.8 - x64

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8174.6154 [GMT -10:00]

Running from: c:\users\Joan\Desktop\ComboFix.exe

AV: Kaspersky Internet Security *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984}

FW: Kaspersky Internet Security *Disabled* {1691B380-548E-1A7A-BE85-9A42CE15AEFF}

SP: Kaspersky Internet Security *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\programdata\PCDr\6261\AddOnDownloaded\1b0b3c38-2b97-4f8d-954b-06296209b73d.dll

c:\programdata\PCDr\6261\AddOnDownloaded\1e512ef2-01fb-49fb-b09b-71de0eac4612.dll

c:\programdata\PCDr\6261\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll

c:\programdata\PCDr\6261\AddOnDownloaded\2eccd5d6-e118-4f76-97b6-ba56fb6c597a.dll

c:\programdata\PCDr\6261\AddOnDownloaded\3e0b29b2-9809-4050-abfc-ef8aff73ceab.dll

c:\programdata\PCDr\6261\AddOnDownloaded\5f2ce3e8-3c56-40bb-86d6-a1a41867000b.dll

c:\programdata\PCDr\6261\AddOnDownloaded\7b6e388f-35d0-44f8-aa2c-20538273473f.dll

c:\programdata\PCDr\6261\AddOnDownloaded\97cd9b9c-9747-469a-acfa-cfbf8aed528a.dll

c:\programdata\PCDr\6261\AddOnDownloaded\b69d9551-76e9-4872-95f8-075916f82d74.dll

c:\programdata\PCDr\6261\AddOnDownloaded\bea3f575-677a-4c92-89ca-7be8480c11a9.dll

.

.

((((((((((((((((((((((((( Files Created from 2013-04-28 to 2013-05-29 )))))))))))))))))))))))))))))))

.

.

2013-05-29 18:11 . 2013-05-29 18:11 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C1F4915-5080-4472-95AB-C1D2CA0E86A1}\offreg.dll

2013-05-29 18:06 . 2013-05-29 18:06 -------- d-----w- c:\windows\ERUNT

2013-05-29 18:06 . 2013-05-29 18:06 -------- d-----w- C:\JRT

2013-05-29 17:59 . 2013-05-29 17:59 175 ----a-w- c:\windows\DeleteOnReboot.bat

2013-05-29 16:52 . 2013-05-29 16:52 -------- d-----w- c:\program files (x86)\ERUNT

2013-05-28 16:44 . 2013-05-13 06:37 9460464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C1F4915-5080-4472-95AB-C1D2CA0E86A1}\mpengine.dll

2013-05-28 14:24 . 2013-05-28 14:24 -------- d-----w- C:\FRST

2013-05-22 21:46 . 2013-05-22 21:46 -------- d-----w- c:\program files (x86)\Google

2013-05-22 21:45 . 2013-05-11 22:27 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll

2013-05-22 20:34 . 2013-05-22 20:34 -------- d-----w- c:\programdata\PC-Doctor for Windows

2013-05-22 20:32 . 2013-05-22 20:34 -------- d-----w- c:\program files\My Dell

2013-05-22 20:20 . 2013-04-10 06:01 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys

2013-05-22 20:20 . 2013-04-10 06:01 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys

2013-05-22 20:20 . 2011-02-03 11:25 144384 ----a-w- c:\windows\system32\cdd.dll

2013-05-22 20:20 . 2013-04-10 03:30 3153920 ----a-w- c:\windows\system32\win32k.sys

2013-05-22 20:20 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll

2013-05-22 20:20 . 2013-03-19 05:53 230400 ----a-w- c:\windows\system32\wwansvc.dll

2013-05-22 20:19 . 2013-02-27 05:52 14172672 ----a-w- c:\windows\system32\shell32.dll

2013-05-22 20:19 . 2013-02-27 05:48 1930752 ----a-w- c:\windows\system32\authui.dll

2013-05-22 20:19 . 2013-02-27 05:52 197120 ----a-w- c:\windows\system32\shdocvw.dll

2013-05-22 20:19 . 2013-02-27 06:02 111448 ----a-w- c:\windows\system32\consent.exe

2013-05-22 20:19 . 2013-02-27 05:47 70144 ----a-w- c:\windows\system32\appinfo.dll

2013-05-22 20:19 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\SysWow64\authui.dll

2013-05-11 10:37 . 2013-05-11 10:37 209472 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\nppdf32.dll

2013-05-09 05:51 . 2013-05-09 05:51 -------- d-----w- c:\users\Joan\AppData\Local\Dell Edoc Viewer

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2013-05-22 21:41 . 2012-09-27 23:29 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl

2013-05-22 21:41 . 2012-09-27 23:29 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe

2013-05-22 20:34 . 2011-09-05 02:04 75016696 ----a-w- c:\windows\system32\MRT.exe

2013-05-08 18:15 . 2012-11-02 20:00 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll

2013-05-02 12:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe

2013-04-13 05:49 . 2013-05-22 20:20 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll

2013-04-13 05:49 . 2013-05-22 20:20 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll

2013-04-13 05:49 . 2013-05-22 20:20 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll

2013-04-13 05:49 . 2013-05-22 20:20 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll

2013-04-13 04:45 . 2013-05-22 20:20 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll

2013-04-13 04:45 . 2013-05-22 20:20 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll

2013-04-12 14:45 . 2013-04-23 17:55 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys

2013-04-05 00:50 . 2012-01-31 23:11 25928 ----a-w- c:\windows\system32\drivers\mbam.sys

2013-03-19 06:04 . 2013-04-10 16:12 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe

2013-03-19 05:46 . 2013-04-10 16:12 43520 ----a-w- c:\windows\system32\csrsrv.dll

2013-03-19 05:04 . 2013-04-10 16:12 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04 . 2013-04-10 16:12 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47 . 2013-04-10 16:12 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll

2013-03-19 03:06 . 2013-04-10 16:12 112640 ----a-w- c:\windows\system32\smss.exe

2013-03-17 08:48 . 2012-06-14 07:29 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll

2013-03-17 08:48 . 2011-08-30 02:41 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll

2013-03-13 18:46 . 2013-03-13 18:46 97280 ----a-w- c:\windows\system32\mshtmled.dll

2013-03-13 18:46 . 2013-03-13 18:46 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe

2013-03-13 18:46 . 2013-03-13 18:46 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll

2013-03-13 18:46 . 2013-03-13 18:46 81408 ----a-w- c:\windows\system32\icardie.dll

2013-03-13 18:46 . 2013-03-13 18:46 77312 ----a-w- c:\windows\system32\tdc.ocx

2013-03-13 18:46 . 2013-03-13 18:46 762368 ----a-w- c:\windows\system32\ieapfltr.dll

2013-03-13 18:46 . 2013-03-13 18:46 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe

2013-03-13 18:46 . 2013-03-13 18:46 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll

2013-03-13 18:46 . 2013-03-13 18:46 62976 ----a-w- c:\windows\system32\pngfilt.dll

2013-03-13 18:46 . 2013-03-13 18:46 61952 ----a-w- c:\windows\SysWow64\tdc.ocx

2013-03-13 18:46 . 2013-03-13 18:46 599552 ----a-w- c:\windows\system32\vbscript.dll

2013-03-13 18:46 . 2013-03-13 18:46 523264 ----a-w- c:\windows\SysWow64\vbscript.dll

2013-03-13 18:46 . 2013-03-13 18:46 52224 ----a-w- c:\windows\system32\msfeedsbs.dll

2013-03-13 18:46 . 2013-03-13 18:46 51200 ----a-w- c:\windows\system32\imgutil.dll

2013-03-13 18:46 . 2013-03-13 18:46 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll

2013-03-13 18:46 . 2013-03-13 18:46 48640 ----a-w- c:\windows\system32\mshtmler.dll

2013-03-13 18:46 . 2013-03-13 18:46 452096 ----a-w- c:\windows\system32\dxtmsft.dll

2013-03-13 18:46 . 2013-03-13 18:46 441856 ----a-w- c:\windows\system32\html.iec

2013-03-13 18:46 . 2013-03-13 18:46 38400 ----a-w- c:\windows\SysWow64\imgutil.dll

2013-03-13 18:46 . 2013-03-13 18:46 361984 ----a-w- c:\windows\SysWow64\html.iec

2013-03-13 18:46 . 2013-03-13 18:46 281600 ----a-w- c:\windows\system32\dxtrans.dll

2013-03-13 18:46 . 2013-03-13 18:46 27648 ----a-w- c:\windows\system32\licmgr10.dll

2013-03-13 18:46 . 2013-03-13 18:46 270848 ----a-w- c:\windows\system32\iedkcs32.dll

2013-03-13 18:46 . 2013-03-13 18:46 247296 ----a-w- c:\windows\system32\webcheck.dll

2013-03-13 18:46 . 2013-03-13 18:46 235008 ----a-w- c:\windows\system32\url.dll

2013-03-13 18:46 . 2013-03-13 18:46 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll

2013-03-13 18:46 . 2013-03-13 18:46 226304 ----a-w- c:\windows\system32\elshyph.dll

2013-03-13 18:46 . 2013-03-13 18:46 216064 ----a-w- c:\windows\system32\msls31.dll

2013-03-13 18:46 . 2013-03-13 18:46 197120 ----a-w- c:\windows\system32\msrating.dll

2013-03-13 18:46 . 2013-03-13 18:46 185344 ----a-w- c:\windows\SysWow64\elshyph.dll

2013-03-13 18:46 . 2013-03-13 18:46 173568 ----a-w- c:\windows\system32\ieUnatt.exe

2013-03-13 18:46 . 2013-03-13 18:46 167424 ----a-w- c:\windows\system32\iexpress.exe

2013-03-13 18:46 . 2013-03-13 18:46 158720 ----a-w- c:\windows\SysWow64\msls31.dll

2013-03-13 18:46 . 2013-03-13 18:46 1509376 ----a-w- c:\windows\system32\inetcpl.cpl

2013-03-13 18:46 . 2013-03-13 18:46 150528 ----a-w- c:\windows\SysWow64\iexpress.exe

2013-03-13 18:46 . 2013-03-13 18:46 149504 ----a-w- c:\windows\system32\occache.dll

2013-03-13 18:46 . 2013-03-13 18:46 144896 ----a-w- c:\windows\system32\wextract.exe

2013-03-13 18:46 . 2013-03-13 18:46 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl

2013-03-13 18:46 . 2013-03-13 18:46 1400416 ----a-w- c:\windows\system32\ieapfltr.dat

2013-03-13 18:46 . 2013-03-13 18:46 138752 ----a-w- c:\windows\SysWow64\wextract.exe

2013-03-13 18:46 . 2013-03-13 18:46 13824 ----a-w- c:\windows\system32\mshta.exe

2013-03-13 18:46 . 2013-03-13 18:46 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe

2013-03-13 18:46 . 2013-03-13 18:46 136192 ----a-w- c:\windows\system32\iepeers.dll

2013-03-13 18:46 . 2013-03-13 18:46 135680 ----a-w- c:\windows\system32\IEAdvpack.dll

2013-03-13 18:46 . 2013-03-13 18:46 12800 ----a-w- c:\windows\SysWow64\mshta.exe

2013-03-13 18:46 . 2013-03-13 18:46 12800 ----a-w- c:\windows\system32\msfeedssync.exe

2013-03-13 18:46 . 2013-03-13 18:46 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll

2013-03-13 18:46 . 2013-03-13 18:46 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe

2013-03-13 18:46 . 2013-03-13 18:46 102912 ----a-w- c:\windows\system32\inseng.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ClickfreeMonitor"="c:\programdata\Clickfree\cfagent.exe" [2013-01-31 354632]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2012-10-30 206448]

"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]

"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2010-03-10 237568]

"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]

"IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-13 283160]

"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]

"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-14 91520]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

.

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 FibUacService;FibUacService;c:\programdata\Clickfree\FullImagingBackup\FibUac.exe [2013-01-31 37192]

R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 71168]

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [2010-02-27 158976]

R3 netvsc;netvsc;c:\windows\system32\DRIVERS\netvsc60.sys [2010-11-21 168448]

R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys [2010-11-21 22528]

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-09-05 1255736]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]

S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11864]

S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-11 29488]

S2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe [2012-06-12 193616]

S2 FullImagingService;FullImagingService;c:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe [2013-01-31 201544]

S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-13 13336]

S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-08-23 13672]

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-05 418376]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-05 701512]

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2011-11-26 687400]

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE [x]

S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2011-04-19 993848]

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2011-07-08 1692480]

S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe [2012-06-12 240208]

S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-16 317440]

S3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2010-06-08 406056]

S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-03 22544]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-05 25928]

S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 17976]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]

2013-05-24 21:51 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe

.

Contents of the 'Scheduled Tasks' folder

.

2013-05-29 c:\windows\Tasks\Adobe Flash Player Updater.job

- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-27 21:41]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22 21:46]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-05-22 21:46]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000Core.job

- c:\users\Joan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-06 20:54]

.

2013-05-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2212834863-2338292145-3760869027-1000UA.job

- c:\users\Joan\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-06 20:54]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RunDLLEntry_THXCfg"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920]

"RunDLLEntry_EptMon"="c:\windows\system32\EptMon64.dll" [2009-10-15 21504]

"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552]

"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824]

.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService

FontCache

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

uStart Page = hxxp://google.com/

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: Add to Anti-Banner - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ie_banner_deny.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000

IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105

Trusted Zone: secunia.com.

TCP: DhcpNameServer = 24.25.227.55 209.18.47.61 24.25.227.53

FF - ProfilePath - c:\users\Joan\AppData\Roaming\Mozilla\Firefox\Profiles\5uuc71d5.default-1344114154362\

FF - prefs.js: browser.startup.homepage - google.com

.

- - - - ORPHANS REMOVED - - - -

.

Toolbar-Locked - (no file)

Wow6432Node-HKU-Default-Run-Skype - c:\program files (x86)\Skype\Phone\Skype.exe

.

.

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.11"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]

@Denied: (A 2) (Everyone)

@="IFlashBroker5"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\DbgagD\1*]

"value"="?\07\00\16\14\0a7?"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

Completion time: 2013-05-29 08:26:19

ComboFix-quarantined-files.txt 2013-05-29 18:26

.

Pre-Run: 1,416,026,648,576 bytes free

Post-Run: 1,415,714,824,192 bytes free

.

- - End Of File - - 18A73EF8CD5ED392EB7D6CCF3B8F6FD2

Link to post
Share on other sites

Save and close any work documents, close any apps that you started.

Temporarily turn off (disable) your antivirus program

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Start your MBAM MalwareBytes' Anti-Malware.

Click the Settings Tab and then the General Settings sub-tab. Make sure all option lines have a checkmark.

Then click the Scanner settings sub-tab in second row of tabs. Make sure all option lines have a checkmark.

If you have the PRO license, then do this too: Click the Protection tab. Make sure all option lines have a checkmark.

Next, Click the Update tab. Press the "Check for Updates" button.

If prompted for a Restart, do that.

When done, click the Scanner tab.

Do a Full Scan. i_arrow-l.gif

When the scan is complete, click OK, then Show Results to view the results.

Make sure that everything is checked, and click Remove Selected.

When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

When all done, Copy & paste the MBAM scan log into a new reply.

Tell me, How is the system ?

Re-enable your antivirus program.

Download Security Check by screen317 from >>here<<.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

Here's my MBAM Full Scan log:

Malwarebytes Anti-Malware (PRO) 1.75.0.1300

www.malwarebytes.org

Database version: v2013.05.29.07

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 10.0.9200.16576

Joan :: JA [administrator]

Protection: Enabled

5/29/2013 11:44:24 AM

mbam-log-2013-05-29 (11-44-24).txt

Scan type: Full scan (C:\|D:\|F:\|G:\|H:\|I:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P

Scan options disabled:

Objects scanned: 380229

Time elapsed: 33 minute(s), 33 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

When I double clicked on SecurityCheck.exe, I got the following message:

C:\Users\Joan\Desktop\SecurityCheck.exe

Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.

Tried rebooting 5 times and I had to shutdown manually 3 out of the 5 times since it would freeze.

Link to post
Share on other sites

Kaspersky is detecting Security Check as malware and has quarantined it. The computer rebooted and there was a black screen with a message in a box: Windows - Bad Image Exception Processing Message 0x000007b Parameters 0x000007FEF missed the rest of the message since it booted. After the Welcome, I got a blue screen. I had to manually shutdown. Restarted computer this time it booted okay. Got a message:

Kaspersky Microsoft Windows Troubleshooting

The wizard searches for damaged and irregular settings caused by such things as malware activity and incorrect functioning system utilities.

  • Search for problems caused by malware activity
  • Roll back changes

Link to post
Share on other sites

No, the Kaspersky is giving a false positive regarding securitycheck.

Close / exit the Kaspersky wizard.

Go ahead and delete securitycheck.exe ..... we will do without it. Kaspersky I.S, looks to be way too sensitive on scripts running.

Let's proceed with these tasks.

Task 1

Download TFC by OldTimer and SAVE it to your desktop

  • Double-click TFC.exe to run it. (Note: If you are running on Vista or Windows 7, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.

Task 2

Turn OFF your Kaspersky antivirus so that it does not interfere. !!!

Download and Save McAfee Stinger to your Desktop

http://www.mcafee.com/us/downloads/free-tools/stinger.aspx

Close all browsers before starting. Disable your antivirus program and anti-malware,if any.

How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

On Windows 7 & Vista systems, Right Click stinger-icon.gif and select Run as Administrator.

On XP, double-click to start it.

The GUI interface will look like this

stinger2.png

The C drive is the default for scanning.

Press the Preferences button. In the top right-block "On virus detection", click Rename

In the bottom block "Heuristic network check for suspicious files" select High

Click the Scan Now button.

When done, use the File menu and select Save report to file

Stinger.txt is the log report and will be saved to your Desktop. I will need a copy of that log.

RE-Enable your anti-virus program.

Stinger is a standalone utility used to detect and remove specific malware. It is not a full scan for all types of malware or viruses.

It is not intended as virus protection.

Task 3

Download, & save & then run the MS Safety scanner

http://www.microsoft.com/security/scanner/en-us/default.aspx

Let me know the result.

Note: The Microsoft Safety Scanner expires 10 days after being downloaded. To rerun a scan with the latest anti-malware definitions, download and run the Microsoft Safety Scanner again.

Note: Any data files that are infected may only be cleaned by deleting the file entirely, which means there is a potential for data loss.

The safety scanner log should be called msert.txt

It should be located in the same folder as where you had msert.exe

If not there, then look for it under c:\windows

When all done, re-enable your Kaspersky.

Link to post
Share on other sites

Task 1: Ran TFC.exe. When done had to reboot manually.

Task 2: Ran McAfee Stinger. I'm not sure if I ran it correctly. I couldn't find the File menu to Save report to file. So I saved the log.

Quick Scan Report File

Virus Scan Information

McAfee® Labs Stinger™ Version 11.0.0.319 built on May 29 2013 at 12:43:03

Copyright© 2013, McAfee Inc. All rights Reserved.

Virus data file v1000.0 created on May 29, 2013

Ready to scan for 6244 Viruses, Trojans and variants.

Scan initiated on Wednesday, May 29, 2013 20:07:08

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe

C:\Program Files (x86)\Secunia\PSI\PSIA.exe

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\ProgramData\Clickfree\cfagent.exe

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

C:\Program Files (x86)\Nero\Update\NASvc.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe

Rootkit scan result : Not Scanned.

\\?\Volume{64a1e444-d2c0-11e0-9fb0-806e6f6e6963}\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf

\\?\Volume{64a1e444-d2c0-11e0-9fb0-806e6f6e6963}\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001

\\?\Volume{64a1e444-d2c0-11e0-9fb0-806e6f6e6963}\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002

C:\$Extend\$RmMetadata\$TxfLog\$TxfLog.blf

C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000001

C:\$Extend\$RmMetadata\$TxfLog\$TxfLogContainer00000000000000000002

C:\$RECYCLE.BIN\S-1-5-21-2212834863-2338292145-3760869027-1000\DESKTOP.INI

C:\AdwCleaner[R42].txt

C:\AdwCleaner[s13].txt

C:\ComboFix.txt

C:\DELL.SDR

C:\PROGRAM FILES (X86)\ADOBE\READER 11.0\READER\ACRORD32.EXE

C:\PROGRAM FILES (X86)\ADOBE\READER 11.0\READER\READER_SL.EXE

C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE AIR\VERSIONS\1.0\ADOBE AIR.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ADOBE\ARM\1.0\ADOBEARM.EXE

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Common Files\Intuit\Database Providers\SQL Server Compact Edition 4.0\System.Data.SqlServerCe.dll

C:\Program Files (x86)\Common Files\Intuit\Database Providers\SQL Server Compact Edition 4.0\x86\sqlceme40.dll

C:\Program Files (x86)\Common Files\Intuit\Database Providers\SQL Server Compact Edition 4.0\x86\sqlceqp40.dll

C:\Program Files (x86)\Common Files\Intuit\Database Providers\SQL Server Compact Edition 4.0\x86\sqlcese40.dll

C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe

C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe

C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\EQUATION\MTEXTRA.TTF

C:\PROGRAM FILES (X86)\COMMON FILES\MICROSOFT SHARED\OFFICE14\CULTURES\OFFICE.ODF

C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\msoshext.dll

C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE

C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\HOMEPERMITSCONFIG12OEM.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\HOMEPERMITSCONFIG13.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\RCSL.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\RSL.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\SONICHTTPCLIENT12OEM.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\SONICHTTPCLIENT13.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\SONICLICENSEMANAGER12OEM.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\SONICLICENSEMANAGER13.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\DLLSHARED\SQLITE352.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\OEM\12.0\DLLSHARED\CPSCOMMONTOOLS12OEM.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\OEM\12.0\DLLSHARED\LAYOUTDLL12OEM.DLL

C:\PROGRAM FILES (X86)\COMMON FILES\ROXIO SHARED\OEM\12.0\DLLSHARED\ROXIPPEMC12.DLL

C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe

C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\COMPONENTS\DSUPDATE\DSUPD.EXE

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\COMPONENTS\DSUPDATE\SCHEDULECONFIG.XML

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\COMPONENTS\SCHEDULER\ST_LOG.INI

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\COMPONENTS\SCHEDULER\ST_LOG.INI\ST_LOG.INI

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSCheduler.dll

C:\Program Files (x86)\Dell DataSafe Local Backup\COMPONENTS\SCHEDULER\STSERVICE.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STSERVICE.EXE.20130529195130_1.log

C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STSERVICE.EXE.20130529195130_1.log\STSERVICE.EXE.20130529195130_1.log

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\DELL.CONFIG.XML

C:\Program Files (x86)\Dell DataSafe Local Backup\DsProtectionIndex.dll

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\LOCALE\DATASAFE.LGG

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\LOCALE\DATASAFE.LGG\DATASAFE.LGG

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\LOCALE\LGG_TAGS.INI

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\LOCALE\LGG_TAGS.INI\LGG_TAGS.INI

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\RPLAUNCH.EXE

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\RPLAUNCH.INI

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\RPLAUNCHER.EXE

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\SCHEDULERCONFIG.XML

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\SCHEDULERCONFIG.XML\SCHEDULERCONFIG.XML

C:\Program Files (x86)\Dell DataSafe Local Backup\SDSSmartRepairTools.dll

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\SETMUILANGUAGE.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\SftBRCC.dll

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\SFTSERVICE.DAT

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE.20130529195124_1.log

C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE.20130529195124_1.log\sftservice.EXE.20130529195124_1.log

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\ST_LOG.INI

C:\Program Files (x86)\Dell DataSafe Local Backup\STUICore.dll

C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\TOASTER.EXE.CONFIG

C:\PROGRAM FILES (X86)\DELL DATASAFE LOCAL BACKUP\TOASTERLOG.20130529123650.LOG

C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLog.20130529195137.log

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\LIBMMD.DLL

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\LIBUMAJIN.DLL

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\QTCORE4.DLL

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\QTGUI4.DLL

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\STAGE_PRIMARY.EXE

C:\PROGRAM FILES (X86)\DELL STAGE\DELL STAGE\START.UMJ

C:\PROGRAM FILES (X86)\DELL\DELL DATASAFE ONLINE\BUENG.DLL

C:\PROGRAM FILES (X86)\DELL\DELL DATASAFE ONLINE\NOBUAGENT.EXE

C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe

C:\PROGRAM FILES (X86)\DELL\VIDEOSTAGE\MUITRANSFER\STMTENVRES.DLL

c:\Program Files (x86)\Dell\VideoStage\VideoStage.exe

C:\PROGRAM FILES (X86)\DESKTOP.INI

C:\PROGRAM FILES (X86)\DESKTOP.INI\DESKTOP.INI

C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.94\Installer\chrmstp.exe

C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.21.145\GOOGLECRASHHANDLER64.EXE

C:\PROGRAM FILES (X86)\GOOGLE\UPDATE\1.3.21.145\GOOPDATE.DLL

C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorCommon.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgr.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

C:\PROGRAM FILES (X86)\INTEL\INTEL® RAPID STORAGE TECHNOLOGY\IASTORICON.EXE.CONFIG

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorUIHelper.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorUtil.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IntelVisualDesign.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\ISDI.dll

C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll

C:\Program Files (x86)\K-Lite Codec Pack\Icaros\IcarosThumbnailProvider.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\acassembler.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ahids.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\am_facade.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\ANTI_PHISHING_HTTP_FILTER.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\antispam.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\aphishex.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\appcat.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\arj.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\AVP.PRG

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avpgui.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avpinit.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avpmain.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avs.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\avzkrnl.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\basegui.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\bl.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\buffer.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\cab.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\cbi.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\CF_RESPONSE_PROVIDER.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\CKAHComm.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ckahrule.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\CKAHStat.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\CKAHUM.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\CLLDR.DLL

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\CONFIG.ESM

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\crpthlpr.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\CryptoStaticProvider.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\diffs.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\dmap.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\dtreg.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\dummy.tmp

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\DumpWriter.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\eka_meta.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\EKASYSWATCH.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\esmgr.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\excludemanager.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\EXTLprtc.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FFREGISTRARAB.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\filemap.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\format_recognizer.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\fsdrvplg.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\fssync.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\FTPPRTC.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\hashmd5.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\hips.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\http_protocoller_pipeline.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\httpanlz.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\httpscan.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ichecker.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\ICQPRTC.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\icudt40.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\icuuc40.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ievkbd.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imageformats\qgif4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imapprtc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\imc.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\IRCPRTC.DLL

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\JBRPRTC.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klifpp.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klscav.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\klwtbbho.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\KLWTBFFR.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ksn_client.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ksn_facade.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\KSN_STATISTICS.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ksnhelper.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\lha.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\lic.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\localization_manager.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\mailmsg.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\mc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\mdb.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\memmon.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\minizip.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\MMPPRTC.DLL

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\MSNPRTC.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\msoe.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\msvcp100.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\msvcr100.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ndetect.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\netwatch.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\nfio.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\nntpprtc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\oas.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ods.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\packed_io.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\params.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\pdm2rt.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\PLUGINS.CFG

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\pop3prtc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\prloader.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ProcessMonitor.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\procmon.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\propmap.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\proxydet.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\prremote.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\prseqio.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\prutil.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\pxstub.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\qb.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtCore4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtDeclarative4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtGui4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtNetwork4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtScript4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\QtSql4.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\rar.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\regmap.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\report.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\reportdb.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\sandbox.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\sc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\schedule.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\scrchpg.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\service.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\sfdb.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\SKIN\LOC\EN\AV.LOC

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\smtpprtc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\stat.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\storage.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\SWPRAGUEPLUGIN.DLL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\thpimpl.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ThreatsManager.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\timer.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\tm.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\trafmon2.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\transport_provider.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\uniarc.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\Updater.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\urlflt.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\ushata.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\vercheck.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\volenum.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\wdiskio.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\webnetstat.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\winreg.ppl

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\wmihlpr.ppl

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\X64\WMI64.EXE

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\X64\WMIHLPR.PPL

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\expsrv.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\mfc42.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\msvbvm50.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\msvbvm60.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\msvcp60.dll

C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\x86\msvcr80.dll

C:\PROGRAM FILES (X86)\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2012\YHOPRTC.DLL

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\LANGUAGES\ENGLISH.LNG

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\LANGUAGES\ENGLISH.LNG\ENGLISH.LNG

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAM.DLL

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAM.EXE

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMCORE.DLL

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMGUI.EXE

C:\PROGRAM FILES (X86)\MALWAREBYTES' ANTI-MALWARE\MBAMNET.DLL

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Microsoft Lync\communicator.exe

C:\Program Files (x86)\Microsoft Lync\OCHelper.dll

C:\PROGRAM FILES (X86)\MICROSOFT LYNC\OCIMPORT.DLL

C:\PROGRAM FILES (X86)\MICROSOFT LYNC\PSOM.DLL

C:\PROGRAM FILES (X86)\MICROSOFT LYNC\UC.DLL

C:\PROGRAM FILES (X86)\MICROSOFT LYNC\UCCAPI.DLL

C:\Program Files (x86)\Microsoft Lync\UcMapi.exe

C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\1033\GROOVEINTLRESOURCE.DLL

C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe

C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE

C:\PROGRAM FILES (X86)\MICROSOFT OFFICE\OFFICE14\GROOVEEX.DLL

C:\Program Files (x86)\Microsoft Office\Office14\msohevi.dll

C:\Program Files (x86)\Microsoft Office\Office14\OLKFSTUB.DLL

C:\Program Files (x86)\Microsoft Office\Office14\ONENOTE.EXE

C:\Program Files (x86)\Microsoft Office\Office14\ONFILTER.DLL

C:\Program Files (x86)\Microsoft Office\Office14\outlook.exe

C:\Program Files (x86)\Microsoft Office\Office14\VISSHE.DLL

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll

C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe

C:\Program Files (x86)\Mozilla Firefox\AccessibleMarshal.dll

C:\Program Files (x86)\Mozilla Firefox\application.ini

C:\Program Files (x86)\Mozilla Firefox\breakpadinjector.dll

C:\Program Files (x86)\Mozilla Firefox\crashreporter.exe

C:\Program Files (x86)\Mozilla Firefox\crashreporter.ini

C:\Program Files (x86)\Mozilla Firefox\dependentlibs.list

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\Mozilla Firefox\freebl3.chk

C:\Program Files (x86)\Mozilla Firefox\freebl3.dll

C:\Program Files (x86)\Mozilla Firefox\gkmedias.dll

C:\Program Files (x86)\Mozilla Firefox\install.log

C:\Program Files (x86)\Mozilla Firefox\install.log\install.log

C:\Program Files (x86)\Mozilla Firefox\libEGL.dll

C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll

C:\Program Files (x86)\Mozilla Firefox\maintenanceservice.exe

C:\Program Files (x86)\Mozilla Firefox\maintenanceservice_installer.exe

C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll

C:\Program Files (x86)\Mozilla Firefox\mozglue.dll

C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll

C:\Program Files (x86)\Mozilla Firefox\nspr4.dll

C:\Program Files (x86)\Mozilla Firefox\nss3.dll

C:\Program Files (x86)\Mozilla Firefox\nssckbi.dll

C:\Program Files (x86)\Mozilla Firefox\nssdbm3.chk

C:\Program Files (x86)\Mozilla Firefox\nssdbm3.dll

C:\Program Files (x86)\Mozilla Firefox\nssutil3.dll

C:\Program Files (x86)\Mozilla Firefox\omni.ja

C:\Program Files (x86)\Mozilla Firefox\platform.ini

C:\Program Files (x86)\Mozilla Firefox\plc4.dll

C:\Program Files (x86)\Mozilla Firefox\plds4.dll

C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

C:\Program Files (x86)\Mozilla Firefox\plugin-hang-ui.exe

C:\Program Files (x86)\Mozilla Firefox\Plugins\nppdf32.dll

C:\Program Files (x86)\Mozilla Firefox\precomplete

C:\Program Files (x86)\Mozilla Firefox\removed-files

C:\Program Files (x86)\Mozilla Firefox\smime3.dll

C:\Program Files (x86)\Mozilla Firefox\softokn3.chk

C:\Program Files (x86)\Mozilla Firefox\softokn3.dll

C:\Program Files (x86)\Mozilla Firefox\ssl3.dll

C:\Program Files (x86)\Mozilla Firefox\update-settings.ini

C:\Program Files (x86)\Mozilla Firefox\updater.exe

C:\Program Files (x86)\Mozilla Firefox\updater.ini

C:\Program Files (x86)\Mozilla Firefox\webapp-uninstaller.exe

C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe

C:\Program Files (x86)\Mozilla Firefox\xpcom.dll

C:\Program Files (x86)\Mozilla Firefox\xul.dll

C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe

C:\PROGRAM FILES (X86)\MULTIMEDIA CARD READER(9106)\SHWICONXP.INI

C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe

C:\Program Files (x86)\Nero\Update\en-US\NASvc.exe.mui

C:\Program Files (x86)\Nero\Update\NASvc.exe

C:\Program Files (x86)\Nero\Update\NASvcPS.dll

C:\PROGRAM FILES (X86)\ROXIO\OEM\ROXIO BURN\AS_STORAGE_W32.DLL

C:\PROGRAM FILES (X86)\ROXIO\OEM\ROXIO BURN\ROXIOBURNLAUNCHER.EXE

C:\PROGRAM FILES (X86)\ROXIO\OEM\ROXIO BURN\STORAGEPCONFIG.DCF

C:\Program Files (x86)\Secunia\PSI\PSIA.exe

C:\PROGRAM FILES (X86)\SECUNIA\PSI\PSIALOG.TXT

C:\Program Files (x86)\stinger\lockdown.dll

C:\Program Files (x86)\stinger\mfehida.dll

C:\Program Files (x86)\stinger\mferkda.dll

C:\PROGRAM FILES (X86)\VIIKIIDESKTOPPLUGIN\ICONS\APP16.PNG

C:\PROGRAM FILES (X86)\VIIKIIDESKTOPPLUGIN\META-INF\AIR\APPLICATION.XML

C:\PROGRAM FILES (X86)\VIIKIIDESKTOPPLUGIN\VIIKIIDESKTOPPLUGIN.EXE

C:\PROGRAM FILES (X86)\VIIKIIDESKTOPPLUGIN\VIIKIIPLUGIN.SWF

C:\PROGRAM FILES (X86)\VIIKIIDESKTOPPLUGIN\VIIKIIPLUGIN.SWF\VIIKIIPLUGIN.SWF

C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

C:\Program Files (x86)\Windows Live\Mesh\MOE.exe

C:\PROGRAM FILES (X86)\WINDOWS LIVE\MESSENGER\EN\MSGSLANG.DLL.MUI

C:\PROGRAM FILES (X86)\WINDOWS LIVE\MESSENGER\MSGSLANG.DLL

C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe

C:\Program Files (x86)\Windows Live\Photo Gallery\PhotoViewerShim.dll

C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\OFFICE14\CULTURES\OFFICE.ODF

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WLIDCREDPROV.DLL

C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WLIDNSP.DLL

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WLIDSVCM.EXE

C:\Program Files\Microsoft Lync\UcMapi64.exe

C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE14\1033\GROOVEINTLRESOURCE.DLL

C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE14\GROOVEEX.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVTRAY.EXE

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVUI.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVUIR.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDAPIX.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDBAT.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDPLCY.DLL

C:\PROGRAM FILES\NVIDIA CORPORATION\DISPLAY\NVXDSYNC.EXE

C:\PROGRAM FILES\WINDOWS LIVE\MESH\EN\WLREMOTESERVICERESOURCE.DLL.MUI

C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

C:\PROGRAM FILES\WINDOWS LIVE\MESH\WLREMOTESERVICERESOURCE.DLL

C:\ProgramData\Clickfree\cfagent.exe

C:\ProgramData\Clickfree\FullImagingBackup\BackupRestoreUtilDLL.dll

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\BACKUPSETTINGS.XML

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\BACKUPTIME.INI

C:\ProgramData\Clickfree\FullImagingBackup\CommObjects.dll

C:\ProgramData\Clickfree\FullImagingBackup\ConfigurationSettings.dll

C:\ProgramData\Clickfree\FullImagingBackup\CSH_Devutil.dll

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\DEVICE.INI

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\FIBREMINDER.EXE

C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\FIBUACLOG.TXT

C:\ProgramData\Clickfree\FullImagingBackup\FSMonitor.log

C:\ProgramData\Clickfree\FullImagingBackup\FSMONITORDB\FSMonitorDB.db

C:\ProgramData\Clickfree\FullImagingBackup\FSMONITORDB\FSMonitorDB.db-shm

C:\ProgramData\Clickfree\FullImagingBackup\FSMONITORDB\FSMonitorDB.db-wal

C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\FULLIMAGINGSERVICE.EXE.CONFIG

C:\ProgramData\Clickfree\FullImagingBackup\FullImagingService.log

C:\ProgramData\Clickfree\FullImagingBackup\IPCDuplexServicesLibrary.dll

C:\ProgramData\Clickfree\FullImagingBackup\LogWriterDLL.dll

C:\ProgramData\Clickfree\FullImagingBackup\RemoteRepositoryComponents.dll

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\SACDEVICE.DLL

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\SACDEVICE_X64.DLL

C:\ProgramData\Clickfree\FullImagingBackup\SchedulerDLL.dll

C:\PROGRAMDATA\CLICKFREE\FULLIMAGINGBACKUP\SOFTWARE.CONFIG

C:\ProgramData\Clickfree\FullImagingBackup\System.Data.SQLite.dll

C:\ProgramData\Clickfree\FullImagingBackup\VssClient.log

C:\ProgramData\Clickfree\FullImagingBackup\VssClient.log\VssClient.log

C:\ProgramData\Clickfree\FullImagingBackup\VssClientDll.dll

C:\ProgramData\Clickfree\FullImagingBackup\WCFServerLib.dll

Continuation of McAfee Stinger Log next post.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.