Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.

Unwanted sounds from computer!

1K views 9 replies 2 participants last post by  bjja 
#1 ·
Hi! It sounds like Commercial audio ads playing through speakers and i can't get rid off it! malware scanners have not been able to detect anything wrong.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:57:02, on 2012-10-15
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Users\julius\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Spotify] "C:\Users\julius\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Lokal tjänst')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Lokal tjänst')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Nätverkstjänst')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Nätverkstjänst')
O4 - HKUS\S-1-5-21-1628012227-26710139-1449845332-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1628012227-26710139-1449845332-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - Global Startup: NETGEAR WNA3100 Smart Wizard.lnk = ?
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
O23 - Service: Adobe Licensing Console - - C:\Windows\SysWOW64\lnsecsl.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files (x86)\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Tjänsten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Tjänsten Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: WSWNA3100 - Unknown owner - C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe

--
End of file - 11053 bytes
 
See less See more
#2 ·
follow advice here and post the logs those programs make

is there any reason you haven't updated to SP1 yet

Please run the MGA Diagnostic Tool and post back the report it creates:
  • Download MGADiag to your desktop.
  • Double-click on MGADiag.exe to launch the program
  • Click "Continue"
  • Ensure that the "Windows" tab is selected (it should be by default).
  • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
  • Paste the MGA Diagnostic Report back here in your next reply.

Please download and run WVCheck.
  • Double-click WVCheck.exe.
  • As indicated by the prompt, this program can take a while depending on your hard drive space.
  • Once the program is done, copy the contents of the Notepad file as a reply.
 
#3 ·
I don't have it? I thought it would install automatically?

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-H3GDR-BBWQ6-X9D7P
Windows Product Key Hash: 7V41wMaoxyDLt70perqMVCmvers=
Windows Product ID: 00426-OEM-9141204-92095
Windows Product ID Type: 3
Windows License Type: OEM System Builder
Windows OS version: 6.1.7600.2.00010100.0.0.001
ID: {77E6ECF9-978E-41AA-B951-F9AFE6A0CC19}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Ultimate
Architecture: 0x00000009
Build lab: 7600.win7_gdr.120830-0334
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{77E6ECF9-978E-41AA-B951-F9AFE6A0CC19}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-X9D7P</PKey><PID>00426-OEM-9141204-92095</PID><PIDType>3</PIDType><SID>S-1-5-21-1628012227-26710139-1449845332</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7636</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V1.10</Version><SMBIOSVersion major="2" minor="6"/><Date>20110126000000.000000+000</Date></BIOS><HWID>3AB83607018400FC</HWID><UserLCID>041D</UserLCID><SystemLCID>041D</SystemLCID><TimeZone>Västeuropa, normaltid(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Programlicenstjänstens version: 6.1.7600.16385

Namn: Windows(R) 7, Ultimate edition
Beskrivning: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
Aktiverings-ID: cfb3e52c-d707-4861-af51-11b27ee6169c
Program-ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Utökat produkt-ID: 00426-00182-412-092095-02-1053-7600.0000-1862010
Installations-ID: 005870314462554352422361142325910555732745013640183940
URL till processorcertifikatet: http://go.microsoft.com/fwlink/?LinkID=88338
URL till datorcertifikatet: http://go.microsoft.com/fwlink/?LinkID=88339
URL till användningslicensen: http://go.microsoft.com/fwlink/?LinkID=88341
URL till produktnyckelcertifikat: http://go.microsoft.com/fwlink/?LinkID=88340
Ofullständig produktnyckel: X9D7P
Licenstillstånd: Licensierad
Återstående antal Windows-omaktiveringar: 3
Betrodd tid: 2012-10-15 20:05:31

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 10:10:2012 15:44
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:

HWID Data-->
HWID Hash Current: PgAAAAIABgABAAEAAAAEAAAAAgABAAEA6GEkk3cWTGdCxgZP4l9E2D4kgJbcijakzp/AfPvOc32cuCu7XF0=

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes, but no SLIC table
Windows marker version: N/A
OEMID and OEMTableID Consistent: N/A
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC 7636MS A7636100
FACP 7636MS A7636100
HPET 7636MS OEMHPET
MCFG 7636MS OEMMCFG
OEMB 7636MS A7636100
SSDT DpgPmm CpuPm

Windows Validation Check
Version: 1.9.12.5
Log Created On: 2006_15-10-2012
-----------------------

Windows Information
-----------------------
Windows Version: Windows 7
Windows Mode: Normal
Systemroot Path: C:\Windows

WVCheck's Auto Update Check
-----------------------
Auto-Update Option: Download updates and install them automatically.
-----------------------
Last Success Time for Update Detection: 2012-10-15 12:23:23
Last Success Time for Update Download: 2012-10-11 16:34:41
Last Success Time for Update Installation: 2012-10-11 16:34:20

WVCheck's Registry Check Check
-----------------------
Antiwpa: Not Found
-----------------------
Chew7Hale: Not Found
-----------------------

WVCheck's File Dump
-----------------------
C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7601.17514_none_5d778f71b9f4fd55\slwga.dll
Size: 15360 bytes
Creation; 9/10/2012 16:55:32
Modification; 20/11/2010 14:27:26
MD5; b6d6886149573278cba6abd44c4317f5
Matched: slwga.dll
-----------------------
C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7601.17514_none_0158f3ee01978c1f\slwga.dll
Size: 14336 bytes
Creation; 9/10/2012 16:55:27
Modification; 20/11/2010 13:21:24
MD5; 19f75d71e4256f5113d64ce2bb66b838
Matched: slwga.dll
-----------------------
C:\Windows\System32\slwga.dll
Size: 14336 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 6:38:16
MD5; 2008845b41d561fb77b77bbe0045099e
Matched: slwga.dll
-----------------------
C:\Windows\SysWOW64\slwga.dll
Size: 14336 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 6:38:16
MD5; 2008845b41d561fb77b77bbe0045099e
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16385_none_5b467ba9bd0679bb\slwga.dll
Size: 14848 bytes
Creation; 14/7/2009 1:52:11
Modification; 14/7/2009 3:41:54
MD5; cc03cf9f24946dcbd70acb3e1b2f05bf
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16723_none_5b856235bcd79403\slwga.dll
Size: 15360 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 7:15:31
MD5; b7213e92b270761b88b313b62ba0e13b
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.20862_none_5be2bf06d6168a3a\slwga.dll
Size: 15360 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 7:9:5
MD5; 86b7d4d7a87ecb9e6bded44c52c8d5d9
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16385_none_ff27e02604a90885\slwga.dll
Size: 13824 bytes
Creation; 14/7/2009 1:36:22
Modification; 14/7/2009 3:16:15
MD5; 01fe4bdd0b47a7d8bf34d78d2bc23ddb
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16723_none_ff66c6b2047a22cd\slwga.dll
Size: 14336 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 6:38:16
MD5; 2008845b41d561fb77b77bbe0045099e
Matched: slwga.dll
-----------------------
C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.20862_none_ffc423831db91904\slwga.dll
Size: 14336 bytes
Creation; 8/10/2012 19:51:5
Modification; 21/12/2010 6:29:6
MD5; 2332de32759ebcc691850e092b2564a6
Matched: slwga.dll
-----------------------

WVCheck's Dir Dump
-----------------------
WVCheck found no known bad directories.

WVCheck's Missing File Check
-----------------------
WVCheck found no missing Windows files.

WVCheck's MBAM Quarantine Check
-----------------------
There were no bad files quarantined by MBAM.

WVCheck's HOSTS File Check
-----------------------
WVCheck found no bad lines in the hosts file.

WVCheck's MD5 Check
EXPERIMENTAL!!
-----------------------
user32.dll - e8b0ffc209e504cb7e79fc24e6c085f0

-------- End of File, program close at 2010_15-10-2012 --------
 
#4 ·
DDS (Ver_2012-10-14.05) - NTFS_AMD64
Internet Explorer: 9.0.8112.16421
Run by julius at 19:59:50 on 2012-10-15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1053.18.3959.2175 [GMT 2:00]
.
AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
.
============== Running Processes ===============
.
C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\TEMP\mrt79D0.tmp\stdrt.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Windows\System32\M-AudioTaskBarIcon.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
C:\Program Files (x86)\NETGEAR\WNA3100\WNA3100.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\AVG Secure Search\vprot.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
uRun: [Spotify Web Helper] "C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [Spotify] "C:\Users\julius\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
mRun: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
mRun: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
mRun: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNA3100\WNA3100.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{D1F4C133-1B5C-4464-9F3C-66602FE55160} : DHCPNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe
x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-9-21 61792]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\System32\drivers\SCMNdisP.sys [2012-10-7 25312]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2011-5-23 50296]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-9-13 151904]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-10-7 31080]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-10-7 283200]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-10-2 1314720]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-10-2 5783672]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-2 193568]
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-15 399432]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-15 676936]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-8 1258856]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-8-30 382312]
R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-7 2533400]
R2 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2012-10-7 278528]
R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-10-7 722528]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-10-7 838136]
R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
R3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;C:\Windows\System32\drivers\MAudioFastTrackPro.sys [2010-12-7 187912]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-15 25928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2012-10-8 189288]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-8 676968]
S2 Adobe Licensing Console;Adobe Licensing Console;C:\Windows\SysWOW64\lnsecsl.exe [2012-10-13 905070]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Tjänsten Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-7 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-7 250808]
S3 gupdatem;Tjänsten Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-7 116648]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2012-10-8 33592]
S3 NTIOLib_1_0_4;NTIOLib_1_0_4;C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2012-10-8 14136]
S3 NTIOLib_1_0_6;NTIOLib_1_0_6;C:\Program Files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys [2011-1-6 11888]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-9 1255736]
.
=============== Created Last 30 ================
.
2012-10-15 12:31:37 -------- d-----w- C:\Users\julius\AppData\Roaming\Malwarebytes
2012-10-15 12:31:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-10-15 12:31:32 -------- d-----w- C:\ProgramData\Malwarebytes
2012-10-15 12:31:32 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-10-14 14:24:23 1713152 ----a-w- C:\Windows\System32\synsoacc.dll
2012-10-14 14:24:23 -------- d-----w- C:\ProgramData\eLicenser
2012-10-14 14:24:23 -------- d-----w- C:\Program Files (x86)\Syncrosoft
2012-10-14 14:24:23 -------- d-----w- C:\Program Files (x86)\eLicenser
2012-10-14 14:24:21 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
2012-10-14 14:24:21 1277952 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
2012-10-14 13:47:29 -------- d-----w- C:\Program Files (x86)\Common Files\reFX
2012-10-14 13:41:45 2440704 ----a-w- C:\Windows\SysWow64\SYNSOEMU.DLL
2012-10-14 10:56:33 -------- dc-h--w- C:\ProgramData\{E26B3878-7CEC-469C-B449-5CAA336DF8CD}
2012-10-14 10:55:48 -------- dc-h--w- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
2012-10-13 20:25:21 -------- d-----w- C:\Program Files (x86)\Ableton
2012-10-13 19:48:31 -------- d-----w- C:\Program Files (x86)\VstPlugins
2012-10-13 19:48:18 1554944 ----a-w- C:\Windows\SysWow64\vorbis.acm
2012-10-13 19:48:08 -------- d-----w- C:\Program Files (x86)\Outsim
2012-10-13 19:45:59 -------- d-----w- C:\Program Files (x86)\Image-Line
2012-10-13 19:45:04 905070 ----a-w- C:\Windows\SysWow64\lnsecsl.exe
2012-10-13 00:45:10 -------- d-----w- C:\Users\julius\AppData\Local\Apple Computer
2012-10-13 00:44:49 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-10-13 00:43:21 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2012-10-13 00:43:21 -------- d-----w- C:\Program Files\iTunes
2012-10-13 00:43:21 -------- d-----w- C:\Program Files\iPod
2012-10-13 00:43:21 -------- d-----w- C:\Program Files (x86)\iTunes
2012-10-13 00:42:20 -------- d-----w- C:\Users\julius\AppData\Local\Apple
2012-10-13 00:41:15 -------- d-----w- C:\Program Files\Bonjour
2012-10-13 00:41:15 -------- d-----w- C:\Program Files (x86)\Bonjour
2012-10-11 16:47:10 -------- d-----w- C:\Users\julius\AppData\Local\SKIDROW
2012-10-11 16:36:16 -------- d-----w- C:\Program Files (x86)\Bethesda Softworks
2012-10-10 17:30:30 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2012-10-10 15:11:34 98304 ----a-w- C:\Windows\System32CmdLineExt.dll
2012-10-10 14:45:29 -------- d-----w- C:\Program Files (x86)\Steam
2012-10-10 13:28:58 220160 ----a-w- C:\Windows\System32\wintrust.dll
2012-10-10 13:28:57 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-10-10 13:28:55 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-10-10 13:28:55 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-10-10 13:28:45 714752 ----a-w- C:\Windows\System32\kerberos.dll
2012-10-10 13:28:45 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll
2012-10-10 13:28:40 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-10-10 13:28:40 1462784 ----a-w- C:\Windows\System32\crypt32.dll
2012-10-10 13:28:40 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-10-10 13:28:40 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-10-10 13:28:40 1157632 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-10-10 13:28:40 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-10-09 20:53:31 -------- d-----w- C:\Program Files (x86)\Common Files\Propellerhead Software
2012-10-09 13:59:09 -------- d-----w- C:\Games
2012-10-09 13:56:20 -------- d-----w- C:\Users\julius\AppData\Local\Black_Tree_Gaming
2012-10-09 13:56:14 -------- d-----w- C:\Program Files\Nexus Mod Manager
2012-10-09 13:45:18 -------- d-----w- C:\Program Files (x86)\VideoLAN
2012-10-09 12:52:30 -------- d-----w- C:\ProgramData\DivX
2012-10-09 12:51:41 -------- d-----w- C:\Users\julius\AppData\Local\MotionDSP
2012-10-09 12:15:02 -------- d-----w- C:\Windows\SysWow64\Wat
2012-10-09 12:15:02 -------- d-----w- C:\Windows\System32\Wat
2012-10-08 23:02:40 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
2012-10-08 23:02:40 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
2012-10-08 22:46:23 311808 ----a-w- C:\Windows\System32\msv1_0.dll
2012-10-08 22:46:23 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
2012-10-08 22:32:26 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2012-10-08 22:32:26 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2012-10-08 22:32:26 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2012-10-08 22:32:26 444752 ----a-w- C:\Windows\System32\mscoree.dll
2012-10-08 22:32:26 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2012-10-08 22:32:26 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2012-10-08 22:32:26 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2012-10-08 22:32:26 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2012-10-08 22:32:26 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2012-10-08 22:32:26 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2012-10-08 22:31:15 294912 ----a-w- C:\Windows\System32\browserchoice.exe
2012-10-08 22:18:59 80896 ----a-w- C:\Windows\System32\imagehlp.dll
2012-10-08 22:18:59 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-10-08 22:18:59 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-10-08 22:18:59 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-10-08 22:18:59 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-10-08 22:16:35 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
2012-10-08 20:12:12 9575864 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-10-08 18:49:28 -------- d-----w- C:\Users\julius\AppData\Local\Skyrim
2012-10-08 18:32:32 -------- d-----w- C:\Program Files (x86)\Setup Files
2012-10-08 18:30:39 74344 ----a-w- C:\Windows\System32\RtNicProp64.dll
2012-10-08 18:30:39 676968 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2012-10-08 18:09:30 3487434 ----a-w- C:\Windows\System32\nvcoproc.bin
2012-10-08 18:09:09 -------- d-----w- C:\temp
2012-10-08 18:02:24 78680 ----a-w- C:\Windows\System32\XAPOFX1_4.dll
2012-10-08 18:01:59 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
2012-10-08 17:57:10 -------- d-----w- C:\Program Files (x86)\The Elder Scrolls V Skyrim
2012-10-08 17:54:49 503808 ----a-w- C:\Windows\System32\srcore.dll
2012-10-08 17:53:36 1572864 ----a-w- C:\Windows\System32\quartz.dll
2012-10-08 17:52:59 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
2012-10-08 17:51:48 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2012-10-08 17:50:55 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
2012-10-08 17:49:36 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
2012-10-08 17:48:27 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
2012-10-08 17:47:59 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2012-10-08 17:46:57 640896 ----a-w- C:\Windows\System32\winload.efi
2012-10-08 17:45:46 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
2012-10-08 17:44:56 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-10-08 17:44:56 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-10-08 17:44:46 1895280 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-10-08 17:43:13 -------- d-----w- C:\Users\julius\AppData\Roaming\PACE Anti-Piracy
2012-10-08 17:43:13 -------- d-----w- C:\Users\julius\AppData\Local\PACE Anti-Piracy
2012-10-08 17:43:13 -------- d-----w- C:\ProgramData\PACE Anti-Piracy
2012-10-08 17:43:13 -------- d-----w- C:\Program Files (x86)\Common Files\PACE Anti-Piracy
2012-10-08 17:39:54 -------- d-----w- C:\Program Files (x86)\MSI
2012-10-08 17:37:25 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-10-08 17:37:25 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-10-08 17:37:25 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
2012-10-08 17:37:25 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
2012-10-08 17:37:25 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
2012-10-08 17:36:18 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2012-10-08 17:36:17 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
2012-10-08 17:36:02 720896 ----a-w- C:\Windows\System32\odbc32.dll
2012-10-08 17:36:02 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
2012-10-08 17:36:02 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
2012-10-08 17:36:02 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
2012-10-08 17:36:02 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
2012-10-08 17:36:02 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
2012-10-08 17:36:02 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
2012-10-08 17:36:02 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
2012-10-08 17:35:53 1739160 ----a-w- C:\Windows\System32\ntdll.dll
2012-10-08 17:35:53 1292592 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-10-08 17:35:49 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
2012-10-08 17:35:49 236032 ----a-w- C:\Windows\System32\srvsvc.dll
2012-10-08 17:35:29 77312 ----a-w- C:\Windows\System32\packager.dll
2012-10-08 17:35:29 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2012-10-07 21:01:52 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
2012-10-07 20:04:26 -------- d-----w- C:\Users\julius\AppData\Local\Spotify
2012-10-07 20:04:01 -------- d-----w- C:\Users\julius\AppData\Roaming\Spotify
2012-10-07 19:52:09 -------- d-----w- C:\Program Files\Common Files\Native Instruments
2012-10-07 19:52:09 -------- d-----w- C:\Program Files (x86)\Common Files\Native Instruments
2012-10-07 19:51:54 -------- d-----w- C:\ProgramData\Native Instruments
2012-10-07 19:51:54 -------- d-----w- C:\Program Files\Native Instruments
2012-10-07 19:49:25 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
2012-10-07 19:49:19 -------- d-----w- C:\Users\julius\AppData\Roaming\DAEMON Tools Pro
2012-10-07 19:49:17 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Pro
2012-10-07 19:48:35 -------- d-----w- C:\ProgramData\DAEMON Tools Pro
2012-10-07 19:41:06 -------- d-----w- C:\Users\julius\AppData\Roaming\Ableton
2012-10-07 19:34:40 -------- d-----w- C:\ProgramData\Ableton
2012-10-07 19:08:23 -------- d-----w- C:\Program Files (x86)\InterLok
2012-10-07 19:08:17 -------- d-----w- C:\Windows\Downloaded Installations
2012-10-07 18:56:42 -------- d-----w- C:\Program Files (x86)\uTorrent
2012-10-07 18:55:48 -------- d-----w- C:\Users\julius\AppData\Roaming\uTorrent
2012-10-07 18:44:05 -------- d-----w- C:\Program Files\M-Audio
2012-10-07 18:30:54 -------- d-----w- C:\Users\julius\AppData\Roaming\AVG2013
2012-10-07 18:30:14 -------- d-----w- C:\Users\julius\AppData\Local\AVG Secure Search
2012-10-07 18:30:11 -------- d-----w- C:\Users\julius\AppData\Roaming\TuneUp Software
2012-10-07 18:30:09 -------- d-----w- C:\ProgramData\AVG Secure Search
2012-10-07 18:30:01 31080 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
2012-10-07 18:29:59 -------- d-----w- C:\Program Files (x86)\Common Files\AVG Secure Search
2012-10-07 18:29:59 -------- d-----w- C:\Program Files (x86)\AVG Secure Search
2012-10-07 18:28:43 -------- d--h--w- C:\$AVG
2012-10-07 18:28:43 -------- d-----w- C:\ProgramData\AVG2013
2012-10-07 18:28:26 139264 ----a-w- C:\Windows\System32\cabview.dll
2012-10-07 18:28:25 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
2012-10-07 18:28:24 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-10-07 18:28:24 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-10-07 18:28:24 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-10-07 18:28:15 -------- d-----w- C:\Program Files (x86)\AVG
2012-10-07 18:24:56 -------- d--h--w- C:\ProgramData\Common Files
2012-10-07 18:24:56 -------- d-----w- C:\Users\julius\AppData\Local\MFAData
2012-10-07 18:24:56 -------- d-----w- C:\Users\julius\AppData\Local\Avg2013
2012-10-07 18:24:56 -------- d-----w- C:\ProgramData\MFAData
2012-10-07 18:24:10 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-07 18:24:10 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-10-07 18:23:54 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-10-07 18:23:49 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-10-07 18:23:38 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-10-07 18:23:38 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-10-07 18:22:16 -------- d-----w- C:\Users\julius\AppData\Local\Google
2012-10-07 18:22:02 -------- d-----w- C:\Users\julius\AppData\Local\Apps
2012-10-07 18:22:01 -------- d-----w- C:\Users\julius\AppData\Local\Deployment
2012-10-07 18:18:26 107624 ----a-w- C:\Windows\System32\RTNUninst64.dll
2012-10-07 18:17:31 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
2012-10-07 18:17:04 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
2012-10-07 18:17:00 -------- d-----w- C:\Intel
2012-10-07 18:09:39 -------- d-----w- C:\Users\julius\AppData\Roaming\MotionDSP
2012-10-07 18:08:58 -------- d-----w- C:\Program Files (x86)\vReveal
2012-10-07 18:07:53 255592 ----a-w- C:\Windows\System32\nvcohda6.dll
2012-10-07 18:07:52 -------- d-----w- C:\NVIDIA
2012-10-07 18:07:24 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2012-10-07 18:06:53 -------- d-----w- C:\ProgramData\NVIDIA Corporation
2012-10-07 18:06:52 -------- d-----w- C:\Program Files\NVIDIA Corporation
2012-10-07 17:54:13 -------- d-----w- C:\Users\julius\AppData\Local\VirtualStore
2012-10-05 01:26:22 111456 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
2012-10-02 01:30:38 185696 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
2012-09-21 01:46:04 200032 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2012-09-21 01:46:00 225120 ----a-w- C:\Windows\System32\drivers\avgloga.sys
2012-09-21 01:45:50 61792 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
.
==================== Find3M ====================
.
2012-09-14 01:05:18 40800 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
2012-09-13 01:11:18 151904 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2012-09-04 08:39:32 50296 ----a-w- C:\Windows\System32\drivers\avgfwd6a.sys
2012-08-31 18:02:20 1656688 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2012-08-30 18:11:29 5505904 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-08-30 17:18:33 3958128 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:18:33 3902832 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-08-30 16:18:05 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
2012-08-30 16:18:05 63336 ----a-w- C:\Windows\System32\nvshext.dll
2012-08-30 16:18:05 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
2012-08-30 16:18:05 118120 ----a-w- C:\Windows\System32\nvmctray.dll
2012-08-30 16:18:01 3266920 ----a-w- C:\Windows\System32\nvsvc64.dll
2012-08-30 16:17:59 6198120 ----a-w- C:\Windows\System32\nvcpl.dll
2012-08-30 08:40:14 429416 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2012-08-21 11:01:20 125872 ----a-w- C:\Windows\System32\GEARAspi64.dll
2012-08-21 11:01:20 106928 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-08-18 15:43:05 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-08-18 15:43:05 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-08-18 15:43:05 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-08-18 15:42:31 215040 ----a-w- C:\Windows\System32\winsrv.dll
2012-08-18 15:40:26 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-08-18 15:37:49 425984 ----a-w- C:\Windows\System32\KernelBase.dll
2012-08-18 15:34:13 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-08-18 11:22:55 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2012-08-18 11:19:45 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-08-18 11:19:22 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2012-08-18 11:17:56 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2012-08-18 11:17:56 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-08-18 09:12:09 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2012-08-18 09:12:09 2048 ----a-w- C:\Windows\SysWow64\user.exe
2012-08-18 09:07:02 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-08-18 09:07:02 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-08-18 09:07:02 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-08-18 09:07:02 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-08-02 17:55:04 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
2012-08-02 17:05:42 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
2012-07-18 17:31:12 3146752 ----a-w- C:\Windows\System32\win32k.sys
.
============= FINISH: 20:00:37,47 ===============

NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-10-14.05)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 2012-10-07 19:53:07
System Uptime: 2012-10-15 19:54:01 (1 hours ago)
.
Motherboard: MSI | | H55M-E33(MS-7636)
Processor: Intel(R) Core(TM) i5 CPU 650 @ 3.20GHz | CPU 1 | 2912/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 466 GiB total, 326,296 GiB free.
D: is CDROM ()
E: is Removable
F: is FIXED (NTFS) - 466 GiB total, 437,625 GiB free.
G: is CDROM (UDF)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP22: 2012-10-11 18:30:07 - Windows Update
RP23: 2012-10-13 02:42:33 - Installed iTunes
RP24: 2012-10-14 16:24:28 - Installation av enhetsdrivrutinspaket: Steinberg Media Technologies GmbH
.
==== Installed Programs ======================
.
Ableton Live 8
Adobe Flash Player 11 ActiveX
Apple-programstöd
Apple Mobile Device Support
Apple Software Update
ASIO4ALL
µTorrent
AVG 2013
Bonjour
DAEMON Tools Pro
Dark Messiah
Digidesign Pro Tools M-Powered Demo 7.4
Digidesign Shared Plug-Ins 7.4
Dishonored
eLicenser Control
FL Studio 10
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
IL Download Manager
Intel(R) Control Center
Intel(R) Management Engine Components
Interlok driver setup x64
iTunes
Live 8.2.2
Live Update 5
M-Audio FastTrackPro Driver 6.0.7 (x64)
Malwarebytes Anti-Malware version 1.65.0.1400
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile Language Pack - SVE
Microsoft .NET Framework 4 Client Profile SVE Language Pack
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Native Instruments Massive
Native Instruments Service Center
NETGEAR WNA3100 wireless USB 2.0 adapter
Nexus Mod Manager
NVIDIA-uppdatering 1.10.8
NVIDIA 3D Vision drivrutin 306.23
NVIDIA 3D Vision drivrutin för styrenhet 306.23
NVIDIA Display Control Panel
NVIDIA Grafikdrivrutin 306.23
NVIDIA HD audiodrivrutin 1.3.18.0
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX systemprogramvara 9.12.0604
NVIDIA Stereoscopic 3D Driver
NVIDIA Update Components
NVIDIAs kontrollpanel 306.23
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
reFX Nexus VSTi RTAS v2.2.0
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Spotify
Steam
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
WinRAR 4.20 (64-bit)
Visual Studio 2010 x64 Redistributables
VLC media player 2.0.3
vReveal
.
==== End Of File ===========================
 
#5 ·
ok we will try & sort out SP1 later
itf you haven't got it and are on automatic updates, it normally menas that an optional vital update is needed

first though lets try & sort the problem

Run tdss killer from http://support.kaspersky.com/viruses/solutions?qid=208280684

let it cure anything it fnds ( except SPTD.SYS or anything detected as UnsignedFile.Multi.Generic, which should be ignored) & then reboot

post back with its log

By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder.
Logs have names like: UtilityName.Version_Date_Time_log.txt.
E.g. C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt
 
#6 ·
21:08:52.0034 9576 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
21:08:52.0684 9576 ============================================================
21:08:52.0684 9576 Current date / time: 2012/10/15 21:08:52.0684
21:08:52.0684 9576 SystemInfo:
21:08:52.0684 9576
21:08:52.0684 9576 OS Version: 6.1.7600 ServicePack: 0.0
21:08:52.0684 9576 Product type: Workstation
21:08:52.0684 9576 ComputerName: JULIUS-DATOR
21:08:52.0684 9576 UserName: julius
21:08:52.0684 9576 Windows directory: C:\Windows
21:08:52.0684 9576 System windows directory: C:\Windows
21:08:52.0684 9576 Running under WOW64
21:08:52.0684 9576 Processor architecture: Intel x64
21:08:52.0684 9576 Number of processors: 4
21:08:52.0684 9576 Page size: 0x1000
21:08:52.0684 9576 Boot type: Normal boot
21:08:52.0684 9576 ============================================================
21:08:53.0874 9576 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:08:53.0884 9576 Drive \Device\Harddisk1\DR1 - Size: 0x7470C05E00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
21:08:54.0184 9576 ============================================================
21:08:54.0184 9576 \Device\Harddisk0\DR0:
21:08:54.0224 9576 MBR partitions:
21:08:54.0224 9576 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000
21:08:54.0224 9576 \Device\Harddisk1\DR1:
21:08:54.0294 9576 MBR partitions:
21:08:54.0294 9576 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384C02
21:08:54.0294 9576 ============================================================
21:08:54.0314 9576 C: <-> \Device\Harddisk0\DR0\Partition1
21:08:54.0354 9576 F: <-> \Device\Harddisk1\DR1\Partition1
21:08:54.0354 9576 ============================================================
21:08:54.0354 9576 Initialize success
21:08:54.0354 9576 ============================================================
21:09:02.0933 10232 ============================================================
21:09:02.0934 10232 Scan started
21:09:02.0934 10232 Mode: Manual;
21:09:02.0934 10232 ============================================================
21:09:04.0886 10232 ================ Scan system memory ========================
21:09:04.0886 10232 System memory - ok
21:09:04.0886 10232 ================ Scan services =============================
21:09:05.0016 10232 [ 1B00662092F9F9568B995902F0CC40D5 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
21:09:05.0016 10232 1394ohci - ok
21:09:05.0036 10232 [ 6F11E88748CDEFD2F76AA215F97DDFE5 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
21:09:05.0046 10232 ACPI - ok
21:09:05.0046 10232 [ 63B05A0420CE4BF0E4AF6DCC7CADA254 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
21:09:05.0046 10232 AcpiPmi - ok
21:09:05.0312 10232 [ D13DC8B68779ADA1176A52F39EEF10FF ] Adobe Licensing Console C:\Windows\SysWOW64\lnsecsl.exe
21:09:05.0327 10232 Adobe Licensing Console - ok
21:09:05.0395 10232 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:09:05.0399 10232 AdobeFlashPlayerUpdateSvc - ok
21:09:05.0427 10232 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
21:09:05.0434 10232 adp94xx - ok
21:09:05.0460 10232 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
21:09:05.0466 10232 adpahci - ok
21:09:05.0485 10232 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
21:09:05.0489 10232 adpu320 - ok
21:09:05.0517 10232 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:09:05.0519 10232 AeLookupSvc - ok
21:09:05.0565 10232 [ DB9D6C6B2CD95A9CA414D045B627422E ] AFD C:\Windows\system32\drivers\afd.sys
21:09:05.0573 10232 AFD - ok
21:09:05.0594 10232 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
21:09:05.0597 10232 agp440 - ok
21:09:05.0611 10232 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
21:09:05.0614 10232 ALG - ok
21:09:05.0628 10232 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
21:09:05.0629 10232 aliide - ok
21:09:05.0636 10232 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\DRIVERS\amdide.sys
21:09:05.0638 10232 amdide - ok
21:09:05.0643 10232 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
21:09:05.0645 10232 AmdK8 - ok
21:09:05.0650 10232 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
21:09:05.0652 10232 AmdPPM - ok
21:09:05.0675 10232 [ EC7EBAB00A4D8448BAB68D1E49B4BEB9 ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:09:05.0677 10232 amdsata - ok
21:09:05.0704 10232 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
21:09:05.0708 10232 amdsbs - ok
21:09:05.0713 10232 [ DB27766102C7BF7E95140A2AA81D042E ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:09:05.0714 10232 amdxata - ok
21:09:05.0728 10232 [ 42FD751B27FA0E9C69BB39F39E409594 ] AppID C:\Windows\system32\drivers\appid.sys
21:09:05.0730 10232 AppID - ok
21:09:05.0745 10232 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:09:05.0747 10232 AppIDSvc - ok
21:09:05.0752 10232 [ D065BE66822847B7F127D1F90158376E ] Appinfo C:\Windows\System32\appinfo.dll
21:09:05.0753 10232 Appinfo - ok
21:09:05.0850 10232 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:09:05.0852 10232 Apple Mobile Device - ok
21:09:05.0895 10232 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
21:09:05.0899 10232 AppMgmt - ok
21:09:05.0938 10232 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
21:09:05.0940 10232 arc - ok
21:09:05.0952 10232 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
21:09:05.0954 10232 arcsas - ok
21:09:05.0988 10232 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:09:05.0990 10232 AsyncMac - ok
21:09:05.0995 10232 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\DRIVERS\atapi.sys
21:09:05.0996 10232 atapi - ok
21:09:06.0046 10232 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:09:06.0056 10232 AudioEndpointBuilder - ok
21:09:06.0071 10232 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioSrv C:\Windows\System32\Audiosrv.dll
21:09:06.0078 10232 AudioSrv - ok
21:09:06.0122 10232 [ 3D1FFAA3358CA0D8A298DEA8BECFC468 ] Avgfwfd C:\Windows\system32\DRIVERS\avgfwd6a.sys
21:09:06.0124 10232 Avgfwfd - ok
21:09:06.0187 10232 [ 2E0DB82F4254FF91E153F331BA9B2D6E ] avgfws C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
21:09:06.0213 10232 avgfws - ok
21:09:06.0329 10232 [ B41F0E54105801538D56623271A0AE49 ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
21:09:06.0417 10232 AVGIDSAgent - ok
21:09:06.0428 10232 [ F1A99DA71E6549D7D944596E15142866 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys
21:09:06.0430 10232 AVGIDSDriver - ok
21:09:06.0449 10232 [ E6CB84918C1ABE84AAAF749D2EA4E764 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys
21:09:06.0450 10232 AVGIDSHA - ok
21:09:06.0466 10232 [ 5989592A91A17587799792A81E1541D4 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys
21:09:06.0469 10232 Avgldx64 - ok
21:09:06.0490 10232 [ 3FC43AA02545FCDDC22817829114DEC8 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys
21:09:06.0494 10232 Avgloga - ok
21:09:06.0514 10232 [ EAFF19168F26FA225EB679547B718051 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys
21:09:06.0516 10232 Avgmfx64 - ok
21:09:06.0526 10232 [ FE4F444DBE4BBBDFD8FECF49398DEFC7 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys
21:09:06.0527 10232 Avgrkx64 - ok
21:09:06.0543 10232 [ 6E634525613D48A1D1657FB21F21F3B2 ] Avgtdia C:\Windows\system32\DRIVERS\avgtdia.sys
21:09:06.0547 10232 Avgtdia - ok
21:09:06.0570 10232 [ DE24B2CA078FC6A7EAA53B1DFD3F61CF ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
21:09:06.0571 10232 avgtp - ok
21:09:06.0596 10232 [ 0D2EB149AFF89A307E5D82D0A2B78439 ] avgwd C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
21:09:06.0599 10232 avgwd - ok
21:09:06.0700 10232 [ B20B5FA5CA050E9926E4D1DB81501B32 ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:09:06.0737 10232 AxInstSV - ok
21:09:06.0853 10232 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
21:09:06.0860 10232 b06bdrv - ok
21:09:06.0891 10232 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
21:09:06.0896 10232 b57nd60a - ok
21:09:06.0947 10232 [ E49110A58A32E9450356686A95DD7763 ] BCMH43XX C:\Windows\system32\DRIVERS\bcmwlhigh664.sys
21:09:06.0954 10232 BCMH43XX - ok
21:09:06.0996 10232 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
21:09:07.0039 10232 BDESVC - ok
21:09:07.0059 10232 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
21:09:07.0060 10232 Beep - ok
21:09:07.0098 10232 [ 4992C609A6315671463E30F6512BC022 ] BFE C:\Windows\System32\bfe.dll
21:09:07.0108 10232 BFE - ok
21:09:07.0139 10232 [ 7F0C323FE3DA28AA4AA1BDA3F575707F ] BITS C:\Windows\System32\qmgr.dll
21:09:07.0156 10232 BITS - ok
21:09:07.0173 10232 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
21:09:07.0175 10232 blbdrive - ok
21:09:07.0277 10232 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:09:07.0282 10232 Bonjour Service - ok
21:09:07.0306 10232 [ 19D20159708E152267E53B66677A4995 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:09:07.0308 10232 bowser - ok
21:09:07.0332 10232 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:09:07.0334 10232 BrFiltLo - ok
21:09:07.0339 10232 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:09:07.0341 10232 BrFiltUp - ok
21:09:07.0368 10232 [ 6B054C67AAA87843504E8E3C09102009 ] Browser C:\Windows\System32\browser.dll
21:09:07.0371 10232 Browser - ok
21:09:07.0378 10232 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
21:09:07.0383 10232 Brserid - ok
21:09:07.0388 10232 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
21:09:07.0390 10232 BrSerWdm - ok
21:09:07.0394 10232 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
21:09:07.0395 10232 BrUsbMdm - ok
21:09:07.0399 10232 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
21:09:07.0400 10232 BrUsbSer - ok
21:09:07.0404 10232 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
21:09:07.0406 10232 BTHMODEM - ok
21:09:07.0442 10232 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
21:09:07.0443 10232 bthserv - ok
21:09:07.0466 10232 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:09:07.0468 10232 cdfs - ok
21:09:07.0486 10232 [ 83D2D75E1EFB81B3450C18131443F7DB ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:09:07.0488 10232 cdrom - ok
21:09:07.0509 10232 [ 312E2F82AF11E79906898AC3E3D58A1F ] CertPropSvc C:\Windows\System32\certprop.dll
21:09:07.0510 10232 CertPropSvc - ok
21:09:07.0528 10232 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
21:09:07.0530 10232 circlass - ok
21:09:07.0546 10232 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
21:09:07.0550 10232 CLFS - ok
21:09:07.0625 10232 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:09:07.0627 10232 clr_optimization_v2.0.50727_32 - ok
21:09:07.0679 10232 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:09:07.0686 10232 clr_optimization_v2.0.50727_64 - ok
21:09:07.0747 10232 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:09:07.0750 10232 clr_optimization_v4.0.30319_32 - ok
21:09:07.0775 10232 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:09:07.0778 10232 clr_optimization_v4.0.30319_64 - ok
21:09:07.0814 10232 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
21:09:07.0816 10232 CmBatt - ok
21:09:07.0827 10232 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
21:09:07.0829 10232 cmdide - ok
21:09:07.0876 10232 [ CA7720B73446FDDEC5C69519C1174C98 ] CNG C:\Windows\system32\Drivers\cng.sys
21:09:07.0883 10232 CNG - ok
21:09:07.0887 10232 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
21:09:07.0889 10232 Compbatt - ok
21:09:07.0916 10232 [ F26B3A86F6FA87CA360B879581AB4123 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
21:09:07.0919 10232 CompositeBus - ok
21:09:07.0937 10232 COMSysApp - ok
21:09:07.0974 10232 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
21:09:07.0976 10232 crcdisk - ok
21:09:08.0008 10232 [ BAF19B633933A9FB4883D27D66C39E9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:09:08.0011 10232 CryptSvc - ok
21:09:08.0044 10232 [ 4A6173C2279B498CD8F57CAE504564CB ] CSC C:\Windows\system32\drivers\csc.sys
21:09:08.0072 10232 CSC - ok
21:09:08.0110 10232 [ 873FBF927C06E5CEE04DEC617502F8FD ] CscService C:\Windows\System32\cscsvc.dll
21:09:08.0120 10232 CscService - ok
21:09:08.0157 10232 [ 7266972E86890E2B30C0C322E906B027 ] DcomLaunch C:\Windows\system32\rpcss.dll
21:09:08.0165 10232 DcomLaunch - ok
21:09:08.0186 10232 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
21:09:08.0192 10232 defragsvc - ok
21:09:08.0211 10232 [ 9C253CE7311CA60FC11C774692A13208 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:09:08.0213 10232 DfsC - ok
21:09:08.0234 10232 [ CE3B9562D997F69B330D181A8875960F ] Dhcp C:\Windows\system32\dhcpcore.dll
21:09:08.0239 10232 Dhcp - ok
21:09:08.0270 10232 DigiRefresh - ok
21:09:08.0302 10232 [ 02983523825AEC64B6C50D7AFD2F694E ] digiSPTIService C:\Program Files (x86)\Digidesign\Pro Tools\digiSPTIService.exe
21:09:08.0305 10232 digiSPTIService - ok
21:09:08.0339 10232 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
21:09:08.0341 10232 discache - ok
21:09:08.0375 10232 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
21:09:08.0376 10232 Disk - ok
21:09:08.0403 10232 [ 85CF424C74A1D5EC33533E1DBFF9920A ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:09:08.0407 10232 Dnscache - ok
21:09:08.0426 10232 [ 14452ACDB09B70964C8C21BF80A13ACB ] dot3svc C:\Windows\System32\dot3svc.dll
21:09:08.0431 10232 dot3svc - ok
21:09:08.0441 10232 [ 8C2BA6BEA949EE6E68385F5692BAFB94 ] DPS C:\Windows\system32\dps.dll
21:09:08.0445 10232 DPS - ok
21:09:08.0490 10232 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:09:08.0492 10232 drmkaud - ok
21:09:08.0536 10232 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
21:09:08.0541 10232 dtsoftbus01 - ok
21:09:08.0564 10232 [ 1633B9ABF52784A1331476397A48CBEF ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:09:08.0630 10232 DXGKrnl - ok
21:09:08.0662 10232 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
21:09:08.0665 10232 EapHost - ok
21:09:08.0753 10232 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
21:09:08.0844 10232 ebdrv - ok
21:09:08.0882 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] EFS C:\Windows\System32\lsass.exe
21:09:08.0884 10232 EFS - ok
21:09:08.0945 10232 [ 47C071994C3F649F23D9CD075AC9304A ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:09:08.0955 10232 ehRecvr - ok
21:09:08.0979 10232 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
21:09:08.0981 10232 ehSched - ok
21:09:09.0010 10232 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
21:09:09.0019 10232 elxstor - ok
21:09:09.0032 10232 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
21:09:09.0034 10232 ErrDev - ok
21:09:09.0067 10232 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
21:09:09.0073 10232 EventSystem - ok
21:09:09.0097 10232 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
21:09:09.0100 10232 exfat - ok
21:09:09.0118 10232 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:09:09.0122 10232 fastfat - ok
21:09:09.0143 10232 [ D607B2F1BEE3992AA6C2C92C0A2F0855 ] Fax C:\Windows\system32\fxssvc.exe
21:09:09.0153 10232 Fax - ok
21:09:09.0157 10232 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
21:09:09.0158 10232 fdc - ok
21:09:09.0176 10232 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
21:09:09.0177 10232 fdPHost - ok
21:09:09.0182 10232 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
21:09:09.0184 10232 FDResPub - ok
21:09:09.0202 10232 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:09:09.0203 10232 FileInfo - ok
21:09:09.0212 10232 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:09:09.0214 10232 Filetrace - ok
21:09:09.0216 10232 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
21:09:09.0217 10232 flpydisk - ok
21:09:09.0236 10232 [ F7866AF72ABBAF84B1FA5AA195378C59 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:09:09.0239 10232 FltMgr - ok
21:09:09.0284 10232 [ BC00505CFDA789ED3BE95D2FF38C4875 ] FontCache C:\Windows\system32\FntCache.dll
21:09:09.0300 10232 FontCache - ok
21:09:09.0356 10232 [ 8D89E3131C27FDD6932189CB785E1B7A ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:09:09.0357 10232 FontCache3.0.0.0 - ok
21:09:09.0363 10232 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:09:09.0365 10232 FsDepends - ok
21:09:09.0418 10232 [ D3E3F93D67821A2DB2B3D9FAC2DC2064 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:09:09.0464 10232 Fs_Rec - ok
21:09:09.0578 10232 [ AE87BA80D0EC3B57126ED2CDC15B24ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:09:09.0620 10232 fvevol - ok
21:09:09.0648 10232 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
21:09:09.0651 10232 gagp30kx - ok
21:09:09.0679 10232 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:09:09.0680 10232 GEARAspiWDM - ok
21:09:09.0711 10232 [ FE5AB4525BC2EC68B9119A6E5D40128B ] gpsvc C:\Windows\System32\gpsvc.dll
21:09:09.0726 10232 gpsvc - ok
21:09:09.0774 10232 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:09:09.0776 10232 gupdate - ok
21:09:09.0794 10232 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:09:09.0796 10232 gupdatem - ok
21:09:09.0823 10232 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
21:09:09.0826 10232 gusvc - ok
21:09:09.0854 10232 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
21:09:09.0856 10232 hcw85cir - ok
21:09:09.0892 10232 [ 6410F6F415B2A5A9037224C41DA8BF12 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:09:09.0897 10232 HdAudAddService - ok
21:09:09.0922 10232 [ 0A49913402747A0B67DE940FB42CBDBB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
21:09:09.0925 10232 HDAudBus - ok
21:09:09.0969 10232 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
21:09:09.0971 10232 HECIx64 - ok
21:09:09.0975 10232 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
21:09:09.0977 10232 HidBatt - ok
21:09:09.0991 10232 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
21:09:09.0994 10232 HidBth - ok
21:09:10.0006 10232 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
21:09:10.0008 10232 HidIr - ok
21:09:10.0030 10232 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
21:09:10.0032 10232 hidserv - ok
21:09:10.0042 10232 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:09:10.0044 10232 HidUsb - ok
21:09:10.0054 10232 [ EFA58EDE58DD74388FFD04CB32681518 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:09:10.0057 10232 hkmsvc - ok
21:09:10.0064 10232 [ 046B2673767CA626E2CFB7FDF735E9E8 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:09:10.0069 10232 HomeGroupListener - ok
21:09:10.0098 10232 [ 06A7422224D9865A5613710A089987DF ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:09:10.0103 10232 HomeGroupProvider - ok
21:09:10.0128 10232 [ 0886D440058F203EBA0E1825E4355914 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
21:09:10.0130 10232 HpSAMD - ok
21:09:10.0158 10232 [ CEE049CAC4EFA7F4E1E4AD014414A5D4 ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:09:10.0172 10232 HTTP - ok
21:09:10.0187 10232 [ F17766A19145F111856378DF337A5D79 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:09:10.0188 10232 hwpolicy - ok
21:09:10.0213 10232 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
21:09:10.0216 10232 i8042prt - ok
21:09:10.0242 10232 [ B75E45C564E944A2657167D197AB29DA ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:09:10.0248 10232 iaStorV - ok
21:09:10.0290 10232 [ 2F2BE70D3E02B6FA877921AB9516D43C ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:09:10.0304 10232 idsvc - ok
21:09:10.0323 10232 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
21:09:10.0325 10232 iirsp - ok
21:09:10.0363 10232 [ C5B4683680DF085B57BC53E5EF34861F ] IKEEXT C:\Windows\System32\ikeext.dll
21:09:10.0379 10232 IKEEXT - ok
21:09:10.0494 10232 [ 9CC645EB9697AA4F2D5A39835C80A0A2 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
21:09:10.0613 10232 IntcAzAudAddService - ok
21:09:10.0622 10232 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\DRIVERS\intelide.sys
21:09:10.0623 10232 intelide - ok
21:09:10.0655 10232 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
21:09:10.0656 10232 intelppm - ok
21:09:10.0696 10232 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:09:10.0698 10232 IPBusEnum - ok
21:09:10.0714 10232 [ 722DD294DF62483CECAAE6E094B4D695 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:09:10.0716 10232 IpFilterDriver - ok
21:09:10.0745 10232 [ F8E058D17363EC580E4B7232778B6CB5 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:09:10.0752 10232 iphlpsvc - ok
21:09:10.0756 10232 [ E2B4A4494DB7CB9B89B55CA268C337C5 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
21:09:10.0757 10232 IPMIDRV - ok
21:09:10.0761 10232 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:09:10.0763 10232 IPNAT - ok
21:09:10.0810 10232 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
21:09:10.0821 10232 iPod Service - ok
21:09:10.0831 10232 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:09:10.0832 10232 IRENUM - ok
21:09:10.0840 10232 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
21:09:10.0842 10232 isapnp - ok
21:09:10.0864 10232 [ FA4D2557DE56D45B0A346F93564BE6E1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
21:09:10.0868 10232 iScsiPrt - ok
21:09:10.0883 10232 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
21:09:10.0885 10232 kbdclass - ok
21:09:10.0905 10232 [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
21:09:10.0906 10232 kbdhid - ok
21:09:10.0923 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] KeyIso C:\Windows\system32\lsass.exe
21:09:10.0925 10232 KeyIso - ok
21:09:10.0945 10232 [ 4F4B5FDE429416877DE7143044582EB5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:09:10.0947 10232 KSecDD - ok
21:09:10.0961 10232 [ 6F40465A44ECDC1731BEFAFEC5BDD03C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:09:10.0963 10232 KSecPkg - ok
21:09:10.0973 10232 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
21:09:10.0974 10232 ksthunk - ok
21:09:11.0002 10232 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
21:09:11.0009 10232 KtmRm - ok
21:09:11.0037 10232 [ 81F1D04D4D0E433099365127375FD501 ] LanmanServer C:\Windows\system32\srvsvc.dll
21:09:11.0041 10232 LanmanServer - ok
21:09:11.0072 10232 [ 27026EAC8818E8A6C00A1CAD2F11D29A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:09:11.0076 10232 LanmanWorkstation - ok
21:09:11.0110 10232 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:09:11.0112 10232 lltdio - ok
21:09:11.0149 10232 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:09:11.0155 10232 lltdsvc - ok
21:09:11.0169 10232 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
21:09:11.0171 10232 lmhosts - ok
21:09:11.0211 10232 [ CE97B09D1BA41802A6FAE3BBED3CC37B ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
21:09:11.0216 10232 LMS - ok
21:09:11.0255 10232 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
21:09:11.0257 10232 LSI_FC - ok
21:09:11.0269 10232 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
21:09:11.0271 10232 LSI_SAS - ok
21:09:11.0280 10232 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:09:11.0282 10232 LSI_SAS2 - ok
21:09:11.0288 10232 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:09:11.0291 10232 LSI_SCSI - ok
21:09:11.0304 10232 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
21:09:11.0306 10232 luafv - ok
21:09:11.0352 10232 [ 066991E50A5CBBEEFB2EC6880069CDB5 ] MAUSBFASTTRACKPRO C:\Windows\system32\DRIVERS\MAudioFastTrackPro.sys
21:09:11.0355 10232 MAUSBFASTTRACKPRO - ok
21:09:11.0394 10232 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
21:09:11.0395 10232 MBAMProtector - ok
21:09:11.0451 10232 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
21:09:11.0457 10232 MBAMScheduler - ok
21:09:11.0475 10232 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:09:11.0483 10232 MBAMService - ok
21:09:11.0529 10232 [ F84C8F1000BC11E3B7B23CBD3BAFF111 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:09:11.0532 10232 Mcx2Svc - ok
21:09:11.0545 10232 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
21:09:11.0546 10232 megasas - ok
21:09:11.0582 10232 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
21:09:11.0587 10232 MegaSR - ok
21:09:11.0630 10232 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
21:09:11.0633 10232 MMCSS - ok
21:09:11.0651 10232 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
21:09:11.0652 10232 Modem - ok
21:09:11.0674 10232 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:09:11.0675 10232 monitor - ok
21:09:11.0692 10232 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:09:11.0694 10232 mouclass - ok
21:09:11.0698 10232 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:09:11.0700 10232 mouhid - ok
21:09:11.0714 10232 [ 791AF66C4D0E7C90A3646066386FB571 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:09:11.0716 10232 mountmgr - ok
21:09:11.0724 10232 [ 609D1D87649ECC19796F4D76D4C15CEA ] mpio C:\Windows\system32\DRIVERS\mpio.sys
21:09:11.0728 10232 mpio - ok
21:09:11.0740 10232 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:09:11.0743 10232 mpsdrv - ok
21:09:11.0763 10232 [ AECAB449567D1846DAD63ECE49E893E3 ] MpsSvc C:\Windows\system32\mpssvc.dll
21:09:11.0780 10232 MpsSvc - ok
21:09:11.0792 10232 [ 30524261BB51D96D6FCBAC20C810183C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:09:11.0795 10232 MRxDAV - ok
21:09:11.0811 10232 [ 040D62A9D8AD28922632137ACDD984F2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:09:11.0813 10232 mrxsmb - ok
21:09:11.0823 10232 [ F0067552F8F9B33D7C59403AB808A3CB ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:09:11.0827 10232 mrxsmb10 - ok
21:09:11.0906 10232 [ 3C142D31DE9F2F193218A53FE2632051 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:09:11.0909 10232 mrxsmb20 - ok
21:09:11.0914 10232 [ 5C37497276E3B3A5488B23A326A754B7 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
21:09:11.0916 10232 msahci - ok
21:09:11.0922 10232 [ 8D27B597229AED79430FB9DB3BCBFBD0 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
21:09:11.0926 10232 msdsm - ok
21:09:11.0943 10232 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
21:09:11.0946 10232 MSDTC - ok
21:09:11.0961 10232 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:09:11.0961 10232 Msfs - ok
21:09:11.0979 10232 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:09:11.0980 10232 mshidkmdf - ok
21:09:11.0987 10232 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
21:09:11.0988 10232 msisadrv - ok
21:09:12.0015 10232 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:09:12.0018 10232 MSiSCSI - ok
21:09:12.0022 10232 msiserver - ok
21:09:12.0067 10232 [ 192476C10371DC83243D67432B2CDCBF ] MSI_MSIBIOS_010507 C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys
21:09:12.0069 10232 MSI_MSIBIOS_010507 - ok
21:09:12.0105 10232 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:09:12.0107 10232 MSKSSRV - ok
21:09:12.0122 10232 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:09:12.0125 10232 MSPCLOCK - ok
21:09:12.0129 10232 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:09:12.0130 10232 MSPQM - ok
21:09:12.0139 10232 [ 89CB141AA8616D8C6A4610FA26C60964 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:09:12.0143 10232 MsRPC - ok
21:09:12.0160 10232 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
21:09:12.0161 10232 mssmbios - ok
21:09:12.0171 10232 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:09:12.0172 10232 MSTEE - ok
21:09:12.0176 10232 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
21:09:12.0177 10232 MTConfig - ok
21:09:12.0189 10232 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
21:09:12.0190 10232 Mup - ok
21:09:12.0226 10232 [ 4987E079A4530FA737A128BE54B63B12 ] napagent C:\Windows\system32\qagentRT.dll
21:09:12.0233 10232 napagent - ok
21:09:12.0269 10232 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:09:12.0274 10232 NativeWifiP - ok
21:09:12.0300 10232 [ CAD515DBD07D082BB317D9928CE8962C ] NDIS C:\Windows\system32\drivers\ndis.sys
21:09:12.0311 10232 NDIS - ok
21:09:12.0328 10232 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:09:12.0330 10232 NdisCap - ok
21:09:12.0354 10232 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:09:12.0355 10232 NdisTapi - ok
21:09:12.0362 10232 [ F105BA1E22BF1F2EE8F005D4305E4BEC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:09:12.0364 10232 Ndisuio - ok
21:09:12.0369 10232 [ 557DFAB9CA1FCB036AC77564C010DAD3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:09:12.0372 10232 NdisWan - ok
21:09:12.0379 10232 [ 659B74FB74B86228D6338D643CD3E3CF ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:09:12.0381 10232 NDProxy - ok
21:09:12.0395 10232 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:09:12.0396 10232 NetBIOS - ok
21:09:12.0413 10232 [ 9162B273A44AB9DCE5B44362731D062A ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:09:12.0417 10232 NetBT - ok
21:09:12.0440 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] Netlogon C:\Windows\system32\lsass.exe
21:09:12.0442 10232 Netlogon - ok
21:09:12.0469 10232 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
21:09:12.0478 10232 Netman - ok
21:09:12.0494 10232 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
21:09:12.0501 10232 netprofm - ok
21:09:12.0527 10232 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:09:12.0529 10232 NetTcpPortSharing - ok
21:09:12.0550 10232 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
21:09:12.0552 10232 nfrd960 - ok
21:09:12.0561 10232 [ D9A0CE66046D6EFA0C61BAA885CBA0A8 ] NlaSvc C:\Windows\System32\nlasvc.dll
21:09:12.0566 10232 NlaSvc - ok
21:09:12.0609 10232 [ C31FA031335EFF434B2D94278E74BCCE ] NPF C:\Windows\system32\DRIVERS\npf.sys
21:09:12.0611 10232 NPF - ok
21:09:12.0629 10232 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:09:12.0630 10232 Npfs - ok
21:09:12.0644 10232 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
21:09:12.0647 10232 nsi - ok
21:09:12.0653 10232 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:09:12.0654 10232 nsiproxy - ok
21:09:12.0701 10232 [ 184C189D4FC416978550FC599BB4EDDA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:09:12.0727 10232 Ntfs - ok
21:09:12.0772 10232 [ 1B32C54B95121AB1683C7B83B2DB4B96 ] NTIOLib_1_0_4 C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys
21:09:12.0773 10232 NTIOLib_1_0_4 - ok
21:09:12.0828 10232 [ C02F70960FA934B8DEFA16A03D7F6556 ] NTIOLib_1_0_6 C:\Program Files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys
21:09:12.0829 10232 NTIOLib_1_0_6 - ok
21:09:12.0847 10232 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
21:09:12.0848 10232 Null - ok
21:09:12.0892 10232 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
21:09:12.0895 10232 NVHDA - ok
21:09:13.0104 10232 [ BF7A24A71E1932200D864BC1CE15E596 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
21:09:13.0310 10232 nvlddmkm - ok
21:09:13.0348 10232 [ A4D9C9A608A97F59307C2F2600EDC6A4 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:09:13.0351 10232 nvraid - ok
21:09:13.0371 10232 [ 6C1D5F70E7A6A3FD1C90D840EDC048B9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:09:13.0391 10232 nvstor - ok
21:09:13.0428 10232 [ 43F91595049DE14C4B61D1E76436164F ] nvsvc C:\Windows\system32\nvvsvc.exe
21:09:13.0438 10232 nvsvc - ok
21:09:13.0511 10232 [ 322B69422836F97B76F4AA59B47507BA ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
21:09:13.0536 10232 nvUpdatusService - ok
21:09:13.0556 10232 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
21:09:13.0559 10232 nv_agp - ok
21:09:13.0564 10232 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
21:09:13.0566 10232 ohci1394 - ok
21:09:13.0589 10232 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:09:13.0595 10232 p2pimsvc - ok
21:09:13.0611 10232 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
21:09:13.0619 10232 p2psvc - ok
21:09:13.0648 10232 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
21:09:13.0650 10232 Parport - ok
21:09:13.0675 10232 [ 90061B1ACFE8CCAA5345750FFE08D8B8 ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:09:13.0681 10232 partmgr - ok
21:09:13.0695 10232 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:09:13.0700 10232 PcaSvc - ok
21:09:13.0713 10232 [ F36F6504009F2FB0DFD1B17A116AD74B ] pci C:\Windows\system32\DRIVERS\pci.sys
21:09:13.0716 10232 pci - ok
21:09:13.0728 10232 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\DRIVERS\pciide.sys
21:09:13.0729 10232 pciide - ok
21:09:13.0748 10232 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
21:09:13.0752 10232 pcmcia - ok
21:09:13.0762 10232 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
21:09:13.0763 10232 pcw - ok
21:09:13.0774 10232 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:09:13.0782 10232 PEAUTH - ok
21:09:13.0851 10232 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:09:13.0875 10232 PeerDistSvc - ok
21:09:13.0934 10232 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
21:09:13.0936 10232 PerfHost - ok
21:09:13.0987 10232 [ 557E9A86F65F0DE18C9B6751DFE9D3F1 ] pla C:\Windows\system32\pla.dll
21:09:14.0013 10232 pla - ok
21:09:14.0060 10232 [ 98B1721B8718164293B9701B98C52D77 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:09:14.0067 10232 PlugPlay - ok
21:09:14.0083 10232 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:09:14.0086 10232 PNRPAutoReg - ok
21:09:14.0105 10232 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:09:14.0109 10232 PNRPsvc - ok
21:09:14.0136 10232 [ 166EB40D1F5B47E615DE3D0FFFE5F243 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:09:14.0143 10232 PolicyAgent - ok
21:09:14.0171 10232 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
21:09:14.0175 10232 Power - ok
21:09:14.0201 10232 [ 27CC19E81BA5E3403C48302127BDA717 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:09:14.0203 10232 PptpMiniport - ok
21:09:14.0220 10232 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
21:09:14.0222 10232 Processor - ok
21:09:14.0250 10232 [ 97293447431311C06703368AD0F6C4BE ] ProfSvc C:\Windows\system32\profsvc.dll
21:09:14.0255 10232 ProfSvc - ok
21:09:14.0273 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:09:14.0275 10232 ProtectedStorage - ok
21:09:14.0289 10232 [ EE992183BD8EAEFD9973F352E587A299 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:09:14.0291 10232 Psched - ok
21:09:14.0348 10232 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
21:09:14.0379 10232 ql2300 - ok
21:09:14.0386 10232 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
21:09:14.0389 10232 ql40xx - ok
21:09:14.0417 10232 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
21:09:14.0422 10232 QWAVE - ok
21:09:14.0434 10232 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:09:14.0436 10232 QWAVEdrv - ok
21:09:14.0456 10232 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:09:14.0457 10232 RasAcd - ok
21:09:14.0478 10232 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:09:14.0480 10232 RasAgileVpn - ok
21:09:14.0491 10232 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
21:09:14.0495 10232 RasAuto - ok
21:09:14.0500 10232 [ 87A6E852A22991580D6D39ADC4790463 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:09:14.0503 10232 Rasl2tp - ok
21:09:14.0534 10232 [ 47394ED3D16D053F5906EFE5AB51CC83 ] RasMan C:\Windows\System32\rasmans.dll
21:09:14.0540 10232 RasMan - ok
21:09:14.0550 10232 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:09:14.0553 10232 RasPppoe - ok
21:09:14.0559 10232 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:09:14.0562 10232 RasSstp - ok
21:09:14.0570 10232 [ 3BAC8142102C15D59A87757C1D41DCE5 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:09:14.0579 10232 rdbss - ok
21:09:14.0586 10232 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
21:09:14.0588 10232 rdpbus - ok
21:09:14.0608 10232 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:09:14.0609 10232 RDPCDD - ok
21:09:14.0654 10232 [ 9706B84DBABFC4B4CA46C5A82B14DFA3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:09:14.0676 10232 RDPDR - ok
21:09:14.0716 10232 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:09:14.0733 10232 RDPENCDD - ok
21:09:14.0763 10232 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
21:09:14.0765 10232 RDPREFMP - ok
21:09:14.0794 10232 [ 447DE7E3DEA39D422C1504F245B668B1 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:09:14.0798 10232 RDPWD - ok
21:09:14.0816 10232 [ 634B9A2181D98F15941236886164EC8B ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:09:14.0819 10232 rdyboost - ok
21:09:14.0840 10232 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
21:09:14.0843 10232 RemoteAccess - ok
21:09:14.0870 10232 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:09:14.0874 10232 RemoteRegistry - ok
21:09:14.0883 10232 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:09:14.0887 10232 RpcEptMapper - ok
21:09:14.0912 10232 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
21:09:14.0914 10232 RpcLocator - ok
21:09:14.0931 10232 [ 7266972E86890E2B30C0C322E906B027 ] RpcSs C:\Windows\system32\rpcss.dll
21:09:14.0937 10232 RpcSs - ok
21:09:14.0942 10232 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:09:14.0945 10232 rspndr - ok
21:09:14.0988 10232 [ 39A719875F572241C585A629EE62EB14 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
21:09:15.0003 10232 RTL8167 - ok
21:09:15.0028 10232 [ 88AF6E02AB19DF7FD07ECDF9C91E9AF6 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
21:09:15.0030 10232 s3cap - ok
21:09:15.0040 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] SamSs C:\Windows\system32\lsass.exe
21:09:15.0042 10232 SamSs - ok
21:09:15.0047 10232 [ E3BBB89983DAF5622C1D50CF49F28227 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
21:09:15.0049 10232 sbp2port - ok
21:09:15.0064 10232 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:09:15.0069 10232 SCardSvr - ok
21:09:15.0078 10232 [ C94DA20C7E3BA1DCA269BC8460D98387 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:09:15.0080 10232 scfilter - ok
21:09:15.0202 10232 [ 624D0F5FF99428BB90A5B8A4123E918E ] Schedule C:\Windows\system32\schedsvc.dll
21:09:15.0226 10232 Schedule - ok
21:09:15.0246 10232 [ 6011CDF54BB6F4C69F38FACCDAD73D7E ] SCMNdisP C:\Windows\system32\DRIVERS\scmndisp.sys
21:09:15.0247 10232 SCMNdisP - ok
21:09:15.0276 10232 [ 312E2F82AF11E79906898AC3E3D58A1F ] SCPolicySvc C:\Windows\System32\certprop.dll
21:09:15.0276 10232 SCPolicySvc - ok
21:09:15.0287 10232 [ 765A27C3279CE11D14CB9E4F5869FCA5 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:09:15.0290 10232 SDRSVC - ok
21:09:15.0323 10232 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:09:15.0325 10232 secdrv - ok
21:09:15.0338 10232 [ 463B386EBC70F98DA5DFF85F7E654346 ] seclogon C:\Windows\system32\seclogon.dll
21:09:15.0341 10232 seclogon - ok
21:09:15.0350 10232 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
21:09:15.0353 10232 SENS - ok
21:09:15.0358 10232 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:09:15.0362 10232 SensrSvc - ok
21:09:15.0373 10232 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
21:09:15.0374 10232 Serenum - ok
21:09:15.0392 10232 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
21:09:15.0394 10232 Serial - ok
21:09:15.0409 10232 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
21:09:15.0410 10232 sermouse - ok
21:09:15.0427 10232 [ C3BC61CE47FF6F4E88AB8A3B429A36AF ] SessionEnv C:\Windows\system32\sessenv.dll
21:09:15.0430 10232 SessionEnv - ok
21:09:15.0433 10232 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
21:09:15.0435 10232 sffdisk - ok
21:09:15.0438 10232 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
21:09:15.0440 10232 sffp_mmc - ok
21:09:15.0442 10232 [ 5588B8C6193EB1522490C122EB94DFFA ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
21:09:15.0443 10232 sffp_sd - ok
21:09:15.0446 10232 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
21:09:15.0447 10232 sfloppy - ok
21:09:15.0465 10232 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:09:15.0469 10232 SharedAccess - ok
21:09:15.0487 10232 [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:09:15.0492 10232 ShellHWDetection - ok
21:09:15.0512 10232 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:09:15.0514 10232 SiSRaid2 - ok
21:09:15.0518 10232 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
21:09:15.0520 10232 SiSRaid4 - ok
21:09:15.0523 10232 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:09:15.0525 10232 Smb - ok
21:09:15.0553 10232 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:09:15.0555 10232 SNMPTRAP - ok
21:09:15.0568 10232 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
21:09:15.0568 10232 spldr - ok
21:09:15.0595 10232 [ 567977DC43CC13C4C35ED7084C0B84D5 ] Spooler C:\Windows\System32\spoolsv.exe
21:09:15.0606 10232 Spooler - ok
21:09:15.0681 10232 [ 913D843498553A1BC8F8DBAD6358E49F ] sppsvc C:\Windows\system32\sppsvc.exe
21:09:15.0747 10232 sppsvc - ok
21:09:15.0766 10232 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
21:09:15.0769 10232 sppuinotify - ok
21:09:15.0798 10232 [ 2408C0366D96BCDF63E8F1C78E4A29C5 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:09:15.0805 10232 srv - ok
21:09:15.0822 10232 [ 76548F7B818881B47D8D1AE1BE9C11F8 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:09:15.0828 10232 srv2 - ok
21:09:15.0842 10232 [ 0AF6E19D39C70844C5CAA8FB0183C36E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:09:15.0845 10232 srvnet - ok
21:09:15.0863 10232 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:09:15.0868 10232 SSDPSRV - ok
21:09:15.0876 10232 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:09:15.0880 10232 SstpSvc - ok
21:09:15.0914 10232 Steam Client Service - ok
21:09:15.0956 10232 [ A766CCAD980235FF34E7F8089D3175A3 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
21:09:15.0963 10232 Stereo Service - ok
21:09:15.0984 10232 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
21:09:15.0986 10232 stexstor - ok
21:09:16.0018 10232 [ 52D0E33B681BD0F33FDC08812FEE4F7D ] stisvc C:\Windows\System32\wiaservc.dll
21:09:16.0028 10232 stisvc - ok
21:09:16.0048 10232 [ FFD7A6F15B14234B5B0E5D49E7961895 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
21:09:16.0049 10232 storflt - ok
21:09:16.0060 10232 [ 8FCCBEFC5C440B3C23454656E551B09A ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
21:09:16.0062 10232 storvsc - ok
21:09:16.0075 10232 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
21:09:16.0077 10232 swenum - ok
21:09:16.0092 10232 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
21:09:16.0101 10232 swprv - ok
21:09:16.0142 10232 [ 3C1284516A62078FB68F768DE4F1A7BE ] SysMain C:\Windows\system32\sysmain.dll
21:09:16.0176 10232 SysMain - ok
21:09:16.0191 10232 [ 238935C3CF2854886DC7CBB2A0E2CC66 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:09:16.0194 10232 TabletInputService - ok
21:09:16.0208 10232 [ 884264AC597B690C5707C89723BB8E7B ] TapiSrv C:\Windows\System32\tapisrv.dll
21:09:16.0214 10232 TapiSrv - ok
21:09:16.0223 10232 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
21:09:16.0225 10232 TBS - ok
21:09:16.0270 10232 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:09:16.0304 10232 Tcpip - ok
21:09:16.0341 10232 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:09:16.0351 10232 TCPIP6 - ok
21:09:16.0378 10232 [ 76D078AF6F587B162D50210F761EB9ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:09:16.0379 10232 tcpipreg - ok
21:09:16.0397 10232 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:09:16.0399 10232 TDPIPE - ok
21:09:16.0426 10232 [ 7518F7BCFD4B308ABC9192BACAF6C970 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:09:16.0427 10232 TDTCP - ok
21:09:16.0455 10232 [ 079125C4B17B01FCAEEBCE0BCB290C0F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:09:16.0458 10232 tdx - ok
21:09:16.0474 10232 [ C448651339196C0E869A355171875522 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
21:09:16.0477 10232 TermDD - ok
21:09:16.0508 10232 [ 0F05EC2887BFE197AD82A13287D2F404 ] TermService C:\Windows\System32\termsrv.dll
21:09:16.0523 10232 TermService - ok
21:09:16.0541 10232 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
21:09:16.0544 10232 Themes - ok
21:09:16.0556 10232 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
21:09:16.0558 10232 THREADORDER - ok
21:09:16.0592 10232 [ 2E595C44B1C1160070B1530EDF6DE098 ] Tpkd C:\Windows\system32\drivers\Tpkd.sys
21:09:16.0594 10232 Tpkd - ok
21:09:16.0605 10232 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
21:09:16.0609 10232 TrkWks - ok
21:09:16.0662 10232 [ 840F7FB849F5887A49BA18C13B2DA920 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:09:16.0666 10232 TrustedInstaller - ok
21:09:16.0685 10232 [ 61B96C26131E37B24E93327A0BD1FB95 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:09:16.0686 10232 tssecsrv - ok
21:09:16.0715 10232 [ 3836171A2CDF3AF8EF10856DB9835A70 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:09:16.0718 10232 tunnel - ok
21:09:16.0737 10232 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
21:09:16.0739 10232 uagp35 - ok
21:09:16.0747 10232 [ D47BAEAD86C65D4F4069D7CE0A4EDCEB ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:09:16.0752 10232 udfs - ok
21:09:16.0770 10232 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:09:16.0772 10232 UI0Detect - ok
21:09:16.0775 10232 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
21:09:16.0777 10232 uliagpkx - ok
21:09:16.0805 10232 [ EAB6C35E62B1B0DB0D1B48B671D3A117 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:09:16.0806 10232 umbus - ok
21:09:16.0820 10232 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
21:09:16.0821 10232 UmPass - ok
21:09:16.0840 10232 [ AF0AC98EE5077EB844413EB54287FDE3 ] UmRdpService C:\Windows\System32\umrdp.dll
21:09:16.0844 10232 UmRdpService - ok
21:09:16.0914 10232 [ C6C3B5AB7D807C1A97B1E95FED1AB90D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
21:09:16.0991 10232 UNS - ok
21:09:17.0164 10232 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
21:09:17.0201 10232 upnphost - ok
21:09:17.0238 10232 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
21:09:17.0240 10232 USBAAPL64 - ok
21:09:17.0266 10232 [ 77B01BC848298223A95D4EC23E1785A1 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
21:09:17.0269 10232 usbaudio - ok
21:09:17.0292 10232 [ 7B6A127C93EE590E4D79A5F2A76FE46F ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
21:09:17.0294 10232 usbccgp - ok
21:09:17.0324 10232 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
21:09:17.0327 10232 usbcir - ok
21:09:17.0342 10232 [ 92969BA5AC44E229C55A332864F79677 ] usbehci C:\Windows\system32\drivers\usbehci.sys
21:09:17.0344 10232 usbehci - ok
21:09:17.0364 10232 [ E7DF1CFD28CA86B35EF5ADD0735CEEF3 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:09:17.0370 10232 usbhub - ok
21:09:17.0382 10232 [ F1BB1E55F1E7A65C5839CCC7B36D773E ] usbohci C:\Windows\system32\drivers\usbohci.sys
21:09:17.0383 10232 usbohci - ok
21:09:17.0394 10232 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:09:17.0396 10232 usbprint - ok
21:09:17.0412 10232 [ F39983647BC1F3E6100778DDFE9DCE29 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
21:09:17.0415 10232 USBSTOR - ok
21:09:17.0425 10232 [ BC3070350A491D84B518D7CCA9ABD36F ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
21:09:17.0427 10232 usbuhci - ok
21:09:17.0449 10232 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
21:09:17.0452 10232 UxSms - ok
21:09:17.0482 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] VaultSvc C:\Windows\system32\lsass.exe
21:09:17.0484 10232 VaultSvc - ok
21:09:17.0505 10232 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
21:09:17.0506 10232 vdrvroot - ok
21:09:17.0527 10232 [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds C:\Windows\System32\vds.exe
21:09:17.0537 10232 vds - ok
21:09:17.0542 10232 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:09:17.0543 10232 vga - ok
21:09:17.0552 10232 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
21:09:17.0554 10232 VgaSave - ok
21:09:17.0560 10232 [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
21:09:17.0565 10232 vhdmp - ok
21:09:17.0578 10232 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
21:09:17.0579 10232 viaide - ok
21:09:17.0611 10232 [ 1501699D7EDA984ABC4155A7DA5738D1 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
21:09:17.0615 10232 vmbus - ok
21:09:17.0620 10232 [ AE10C35761889E65A6F7176937C5592C ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
21:09:17.0622 10232 VMBusHID - ok
21:09:17.0636 10232 [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
21:09:17.0638 10232 volmgr - ok
21:09:17.0657 10232 [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:09:17.0662 10232 volmgrx - ok
21:09:17.0670 10232 [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
21:09:17.0674 10232 volsnap - ok
21:09:17.0689 10232 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
21:09:17.0692 10232 vsmraid - ok
21:09:17.0749 10232 [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS C:\Windows\system32\vssvc.exe
21:09:17.0783 10232 VSS - ok
21:09:17.0837 10232 [ 40DBA03782BCC10685A8C200C5EBDCD0 ] vToolbarUpdater12.2.6 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
21:09:17.0847 10232 vToolbarUpdater12.2.6 - ok
21:09:17.0863 10232 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
21:09:17.0865 10232 vwifibus - ok
21:09:17.0898 10232 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
21:09:17.0900 10232 vwififlt - ok
21:09:17.0912 10232 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
21:09:17.0918 10232 W32Time - ok
21:09:17.0937 10232 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
21:09:17.0938 10232 WacomPen - ok
21:09:17.0959 10232 [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
21:09:17.0961 10232 WANARP - ok
21:09:17.0964 10232 [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:09:17.0965 10232 Wanarpv6 - ok
21:09:18.0021 10232 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
21:09:18.0047 10232 WatAdminSvc - ok
21:09:18.0082 10232 [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine C:\Windows\system32\wbengine.exe
21:09:18.0108 10232 wbengine - ok
21:09:18.0137 10232 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:09:18.0143 10232 WbioSrvc - ok
21:09:18.0171 10232 [ DD1BAE8EBFC653824D29CCF8C9054D68 ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:09:18.0179 10232 wcncsvc - ok
21:09:18.0195 10232 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:09:18.0199 10232 WcsPlugInService - ok
21:09:18.0228 10232 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
21:09:18.0230 10232 Wd - ok
21:09:18.0251 10232 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:09:18.0260 10232 Wdf01000 - ok
21:09:18.0272 10232 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:09:18.0276 10232 WdiServiceHost - ok
21:09:18.0281 10232 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:09:18.0284 10232 WdiSystemHost - ok
21:09:18.0306 10232 [ 733006127F235BE7C35354EBEE7B9A7B ] WebClient C:\Windows\System32\webclnt.dll
21:09:18.0312 10232 WebClient - ok
21:09:18.0328 10232 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:09:18.0334 10232 Wecsvc - ok
21:09:18.0351 10232 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:09:18.0355 10232 wercplsupport - ok
21:09:18.0374 10232 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
21:09:18.0377 10232 WerSvc - ok
21:09:18.0403 10232 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
21:09:18.0405 10232 WfpLwf - ok
21:09:18.0420 10232 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:09:18.0422 10232 WIMMount - ok
21:09:18.0440 10232 WinDefend - ok
21:09:18.0446 10232 WinHttpAutoProxySvc - ok
21:09:18.0487 10232 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:09:18.0491 10232 Winmgmt - ok
21:09:18.0535 10232 [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM C:\Windows\system32\WsmSvc.dll
21:09:18.0578 10232 WinRM - ok
21:09:18.0643 10232 [ 817EAFF5D38674EDD7713B9DFB8E9791 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
21:09:18.0645 10232 WinUsb - ok
21:09:18.0674 10232 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
21:09:18.0699 10232 Wlansvc - ok
21:09:18.0721 10232 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
21:09:18.0723 10232 WmiAcpi - ok
21:09:18.0738 10232 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:09:18.0742 10232 wmiApSrv - ok
21:09:18.0769 10232 WMPNetworkSvc - ok
21:09:18.0780 10232 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:09:18.0784 10232 WPCSvc - ok
21:09:18.0802 10232 [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:09:18.0807 10232 WPDBusEnum - ok
21:09:18.0829 10232 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:09:18.0831 10232 ws2ifsl - ok
21:09:18.0858 10232 [ 8F9F3969933C02DA96EB0F84576DB43E ] wscsvc C:\Windows\System32\wscsvc.dll
21:09:18.0862 10232 wscsvc - ok
21:09:18.0866 10232 WSearch - ok
21:09:18.0906 10232 [ 76FBEFAB6677AF9C498116F1AAEA8BDB ] WSWNA3100 C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
21:09:18.0910 10232 WSWNA3100 - ok
21:09:18.0976 10232 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
21:09:19.0028 10232 wuauserv - ok
21:09:19.0041 10232 [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:09:19.0043 10232 WudfPf - ok
21:09:19.0065 10232 [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:09:19.0068 10232 WUDFRd - ok
21:09:19.0089 10232 [ B551D6637AA0E132C18AC6E504F7B79B ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:09:19.0092 10232 wudfsvc - ok
21:09:19.0104 10232 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
21:09:19.0109 10232 WwanSvc - ok
21:09:19.0125 10232 ================ Scan global ===============================
21:09:19.0146 10232 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
21:09:19.0174 10232 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
21:09:19.0185 10232 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
21:09:19.0207 10232 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
21:09:19.0242 10232 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
21:09:19.0249 10232 [Global] - ok
21:09:19.0249 10232 ================ Scan MBR ==================================
21:09:19.0262 10232 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:09:19.0472 10232 \Device\Harddisk0\DR0 - ok
21:09:19.0763 10232 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
21:09:20.0099 10232 \Device\Harddisk1\DR1 - ok
21:09:20.0100 10232 ================ Scan VBR ==================================
21:09:20.0101 10232 [ 79DBB7460805E75DBF13C51AD6D89C59 ] \Device\Harddisk0\DR0\Partition1
21:09:20.0102 10232 \Device\Harddisk0\DR0\Partition1 - ok
21:09:20.0104 10232 [ 04E21CFA27C4E855075D4E17F3343397 ] \Device\Harddisk1\DR1\Partition1
21:09:20.0107 10232 \Device\Harddisk1\DR1\Partition1 - ok
21:09:20.0107 10232 ============================================================
21:09:20.0107 10232 Scan finished
21:09:20.0107 10232 ============================================================
21:09:20.0113 9312 Detected object count: 0
21:09:20.0113 9312 Actual detected object count: 0
 
#7 ·
Delete any existing version of ComboFix you have sitting on your desktop
Please read and follow all these instructions very carefully
Do not edit or remove any information or user names etc, otherwise we cannot fix the problem. If you insist on editing out anything then I will close the topic & refuse to offer any help.

Download ComboFix from Hereto your Desktop.
As you download it rename it to username123.exe

**Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer**
--------------------------------------------------------------------
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus and anti-malware real-time protection and any script blocking components of them or your firewall before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results" or stop combofix running at all
  • Click on THIS LINK to see instructions on how to temporarily disable many security programs while running combofix. The list does not cover every program. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again after combofix has finished
--------------------------------------------------------------------
2. Close any open browsers and any other programs you might have running
Double click on renamed combofix.exe & follow the prompts.​
If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?"
Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.Read HERE why we disable autoruns

Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.

Please tell us if it has cured the problems or if there are any outstanding issues

*EXTRA NOTES*
  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot is due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Post the log in next reply please...
 
#8 ·
ComboFix 12-10-15.01 - julius 2012-10-15 23:20:32.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1053.18.3959.2369 [GMT 2:00]
Körs från: c:\users\julius\Desktop\username123.exe
AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
FW: AVG Internet Security 2013 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\FlashPlayerInstaller.exe
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\pthreadVC.dll
c:\windows\SysWow64\wpcap.dll
F:\Autorun.inf
F:\Setup.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_Adobe Licensing Console
-------\Service_NPF
-------\Service_nvsvc
.
.
(((((((((((((((((((((((( Filer skapade från 2012-09-15 till 2012-10-15 ))))))))))))))))))))))))))))))
.
.
2012-10-15 18:05 . 2012-10-15 18:05 -------- d-----w- C:\MGADiagToolOutput
2012-10-15 12:31 . 2012-10-15 12:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-15 12:31 . 2012-09-07 15:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-14 14:24 . 2012-10-14 14:25 -------- d-----w- c:\program files (x86)\eLicenser
2012-10-14 14:24 . 2012-10-14 14:24 -------- d-----w- c:\program files (x86)\Syncrosoft
2012-10-14 14:24 . 2012-05-02 13:33 1713152 ----a-w- c:\windows\system32\synsoacc.dll
2012-10-14 14:24 . 2012-05-02 13:33 1277952 ----a-w- c:\windows\SysWow64\SYNSOACC.dll
2012-10-14 14:24 . 2011-12-14 19:21 86016 ----a-w- c:\windows\SysWow64\SYNSOPOS.exe
2012-10-14 13:47 . 2012-10-14 13:47 -------- d-----w- c:\program files (x86)\Common Files\reFX
2012-10-14 13:41 . 2010-01-16 21:27 2440704 ----a-w- c:\windows\SysWow64\SYNSOEMU.DLL
2012-10-13 20:25 . 2012-10-13 20:25 -------- d-----w- c:\program files (x86)\Ableton
2012-10-13 19:48 . 2012-10-14 13:50 -------- d-----w- c:\program files (x86)\VstPlugins
2012-10-13 19:48 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\SysWow64\vorbis.acm
2012-10-13 19:48 . 2012-10-13 19:48 -------- d-----w- c:\program files (x86)\Outsim
2012-10-13 19:45 . 2012-10-13 19:48 -------- d-----w- c:\program files (x86)\Image-Line
2012-10-13 19:45 . 2012-10-13 19:45 905070 ----a-w- c:\windows\SysWow64\lnsecsl.exe
2012-10-13 12:00 . 2012-10-13 12:00 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2012-10-13 00:44 . 2012-10-13 00:44 -------- dc----w- c:\windows\system32\DRVSTORE
2012-10-13 00:44 . 2012-08-21 11:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-13 00:43 . 2012-10-13 00:44 -------- d-----w- c:\program files\iTunes
2012-10-13 00:43 . 2012-10-13 00:44 -------- d-----w- c:\program files (x86)\iTunes
2012-10-13 00:43 . 2012-10-13 00:43 -------- d-----w- c:\program files\iPod
2012-10-13 00:42 . 2012-10-13 00:42 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files\Common Files\Apple
2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files\Bonjour
2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files (x86)\Bonjour
2012-10-13 00:40 . 2012-10-13 00:43 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-10-11 16:36 . 2012-10-11 16:36 -------- d-----w- c:\program files (x86)\Bethesda Softworks
2012-10-10 17:30 . 2012-10-10 17:30 -------- d-----w- c:\program files (x86)\Common Files\Steam
2012-10-10 15:11 . 2012-10-10 15:11 98304 ----a-w- c:\windows\system32CmdLineExt.dll
2012-10-10 14:46 . 2012-10-10 14:46 -------- d-----w- c:\program files (x86)\Ubisoft
2012-10-10 14:45 . 2012-10-15 21:27 -------- d-----w- c:\program files (x86)\Steam
2012-10-10 13:28 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 13:28 . 2012-08-24 17:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-10-10 13:28 . 2012-09-14 19:23 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-10 13:28 . 2012-09-14 18:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-10-10 13:28 . 2012-08-11 00:53 714752 ----a-w- c:\windows\system32\kerberos.dll
2012-10-10 13:28 . 2012-08-10 23:54 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
2012-10-10 13:28 . 2012-06-02 05:25 182272 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 13:28 . 2012-06-02 05:25 1462784 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 13:28 . 2012-06-02 05:25 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 13:28 . 2012-06-02 04:45 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-10 13:28 . 2012-06-02 04:45 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-10-10 13:28 . 2012-06-02 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-09 20:53 . 2012-10-09 20:53 -------- d-----w- c:\program files (x86)\Common Files\Propellerhead Software
2012-10-09 13:59 . 2012-10-09 13:59 -------- d-----w- C:\Games
2012-10-09 13:56 . 2012-10-09 13:56 -------- d-----w- c:\program files\Nexus Mod Manager
2012-10-09 13:45 . 2012-10-09 13:45 -------- d-----w- c:\program files (x86)\VideoLAN
2012-10-09 12:24 . 2012-10-09 12:24 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-10-09 12:15 . 2012-10-09 12:15 -------- d-----w- c:\windows\SysWow64\Wat
2012-10-09 12:15 . 2012-10-09 12:15 -------- d-----w- c:\windows\system32\Wat
2012-10-08 23:02 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
2012-10-08 23:02 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
2012-10-08 22:46 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
2012-10-08 22:46 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
2012-10-08 22:32 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2012-10-08 22:32 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2012-10-08 22:32 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2012-10-08 22:32 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2012-10-08 22:32 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2012-10-08 22:32 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2012-10-08 22:32 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-10-08 22:32 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2012-10-08 22:32 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2012-10-08 22:32 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2012-10-08 22:31 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-10-08 22:18 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-10-08 22:18 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
2012-10-08 22:18 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-10-08 22:18 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
2012-10-08 22:18 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2012-10-08 22:16 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
2012-10-08 18:32 . 2012-10-08 18:32 -------- d-----w- c:\program files (x86)\Setup Files
2012-10-08 18:30 . 2012-02-16 11:42 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-10-08 18:30 . 2012-02-16 11:42 676968 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-10-08 18:09 . 2012-10-10 17:31 -------- d-----w- c:\users\UpdatusUser
2012-10-08 18:09 . 2012-08-30 16:18 3487434 ----a-w- c:\windows\system32\nvcoproc.bin
2012-10-08 18:09 . 2012-10-08 18:09 -------- d-----w- C:\temp
2012-10-08 18:02 . 2010-02-04 08:01 78680 ----a-w- c:\windows\system32\XAPOFX1_4.dll
2012-10-08 18:01 . 2007-07-19 16:14 5073256 ----a-w- c:\windows\system32\d3dx9_35.dll
2012-10-08 17:57 . 2012-10-09 14:33 -------- d-----w- c:\program files (x86)\The Elder Scrolls V Skyrim
2012-10-08 17:54 . 2012-05-05 08:30 503808 ----a-w- c:\windows\system32\srcore.dll
2012-10-08 17:53 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-10-08 17:52 . 2010-05-05 07:37 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
2012-10-08 17:51 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
2012-10-08 17:50 . 2011-03-12 12:03 662528 ----a-w- c:\windows\system32\XpsPrint.dll
2012-10-08 17:49 . 2011-02-19 06:36 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-10-08 17:48 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
2012-10-08 17:47 . 2011-08-17 05:32 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-10-08 17:46 . 2011-02-05 12:41 556928 ----a-w- c:\windows\system32\winresume.efi
2012-10-08 17:45 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-10-08 17:44 . 2011-10-15 06:25 723456 ----a-w- c:\windows\system32\EncDec.dll
2012-10-08 17:44 . 2011-10-15 05:48 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2012-10-08 17:44 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-10-08 17:43 . 2012-10-08 17:43 -------- d-----w- c:\program files (x86)\Common Files\PACE Anti-Piracy
2012-10-08 17:39 . 2012-10-08 17:39 -------- d-----w- c:\program files (x86)\MSI
2012-10-08 17:37 . 2012-04-02 05:26 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2012-10-08 17:37 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2012-10-08 17:37 . 2012-04-02 05:24 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2012-10-08 17:37 . 2012-04-02 05:24 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2012-10-08 17:37 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2012-10-08 17:36 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-10-08 17:36 . 2012-06-06 05:09 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-10-08 17:36 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
2012-10-08 17:36 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
2012-10-08 17:36 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-10-08 17:36 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-10-08 17:36 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
2012-10-08 17:36 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2012-10-08 17:36 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2012-10-08 17:36 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2012-10-08 17:35 . 2011-11-17 07:14 1739160 ----a-w- c:\windows\system32\ntdll.dll
2012-10-08 17:35 . 2011-11-17 05:41 1292592 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-10-08 17:35 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
2012-10-08 17:35 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2012-10-08 17:35 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
2012-10-08 17:35 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-10-07 21:01 . 2012-10-07 21:01 -------- d-----w- c:\program files (x86)\ASIO4ALL v2
2012-10-07 19:52 . 2012-10-14 10:56 -------- d-----w- c:\program files (x86)\Common Files\Native Instruments
2012-10-07 19:52 . 2012-10-07 19:52 -------- d-----w- c:\program files\Common Files\Native Instruments
2012-10-07 19:51 . 2012-10-14 10:56 -------- d-----w- c:\program files\Native Instruments
2012-10-07 19:49 . 2012-10-07 19:49 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-10-07 19:49 . 2012-10-07 19:49 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
2012-10-07 19:08 . 2012-10-07 19:08 -------- d-----w- c:\program files (x86)\InterLok
2012-10-07 19:08 . 2012-10-07 19:08 -------- d-----w- c:\windows\Downloaded Installations
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-08 22:28 . 2012-10-08 22:28 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-09-14 01:05 . 2012-09-14 01:05 40800 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
2012-09-13 01:11 . 2012-09-13 01:11 151904 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2012-09-04 08:39 . 2011-05-22 23:03 50296 ----a-w- c:\windows\system32\drivers\avgfwd6a.sys
2012-08-30 19:14 . 2010-07-31 14:46 2725224 ----a-w- c:\windows\system32\nvapi64.dll
2012-08-30 19:14 . 2010-07-31 14:46 15291752 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2012-08-30 19:14 . 2010-07-31 14:46 14879080 ----a-w- c:\windows\system32\nvwgf2umx.dll
2012-08-30 16:18 . 2010-07-31 06:52 63336 ----a-w- c:\windows\system32\nvshext.dll
2012-08-30 16:18 . 2010-07-31 06:52 118120 ----a-w- c:\windows\system32\nvmctray.dll
2012-08-30 16:18 . 2010-07-31 06:52 891240 ----a-w- c:\windows\system32\nvvsvc.exe
2012-08-30 16:18 . 2010-07-31 06:52 2557800 ----a-w- c:\windows\system32\nvsvcr.dll
2012-08-30 16:18 . 2010-07-31 06:52 3266920 ----a-w- c:\windows\system32\nvsvc64.dll
2012-08-30 16:17 . 2010-07-31 06:52 6198120 ----a-w- c:\windows\system32\nvcpl.dll
2012-08-30 08:40 . 2012-08-30 08:40 429416 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2012-08-21 11:01 . 2012-08-21 11:01 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-08-21 11:01 . 2012-08-21 11:01 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-08-18 11:19 . 2012-10-10 13:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
.
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-10-07 18:29 1734240 ----a-w- c:\program files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-10-07 1734240]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744]
"Spotify Web Helper"="c:\users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-10-07 1193176]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-10-10 1353080]
"Spotify"="c:\users\julius\AppData\Roaming\Spotify\spotify.exe" [2012-10-07 5576408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2010-07-01 112152]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-10-10 3116152]
"vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-10-07 947808]
"ROC_ROC_NT"="c:\program files (x86)\AVG Secure Search\ROC_ROC_NT.exe" [2012-10-07 856160]
"DigidesignMMERefresh"="c:\program files (x86)\Digidesign\Drivers\MMERefresh.exe" [2007-10-30 77824]
"Live Update 5"="c:\program files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe" [2012-01-30 315392]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WNA3100 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNA3100\WNA3100.exe [2012-10-7 4562944]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2013\avgrsa.exe /sync /restart
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Tjänsten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 116648]
R2 WSWNA3100;WSWNA3100;c:\program files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2010-01-12 278528]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808]
R3 gupdatem;Tjänsten Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 116648]
R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
R3 NTIOLib_1_0_6;NTIOLib_1_0_6;c:\program files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys [2011-01-06 11888]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-08 1255736]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-09-21 61792]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-10-05 111456]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [2007-01-19 25312]
S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2012-09-04 50296]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-09-13 151904]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-10-07 31080]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-10-07 283200]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2013\avgfws.exe [2012-10-02 1314720]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-10-02 5783672]
S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-02 193568]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-08-30 1258856]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-08-30 382312]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-07-01 2533400]
S2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-10-07 722528]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2009-11-06 838136]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
S3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;c:\windows\system32\DRIVERS\MAudioFastTrackPro.sys [2010-12-07 187912]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
.
.
--- Övriga tjänster/drivrutiner i minnet ---
.
*NewlyCreated* - WS2IFSL
.
Innehåll i mappen 'Schemalagda aktiviteter':
.
2012-10-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-07 20:12]
.
2012-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 18:22]
.
2012-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 18:22]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-12-07 798728]
.
------- Extra genomsökning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
.
.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------
.
[HKEY_USERS\S-1-5-21-1628012227-26710139-1449845332-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:76,89,ac,2e,0a,55,98,bb,6f,e4,fa,6a,e6,87,bb,62,4f,ff,52,47,36,71,65,
10,f2,21,b8,79,ab,2d,17,0d,8b,d5,30,78,f2,16,72,8e,b7,19,03,38,33,da,bb,33,\
"??"=hex:ec,7f,62,96,57,2c,d6,08,cc,a5,1f,55,b4,c4,7c,48
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andra processer som körs ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
c:\program files (x86)\Common Files\Steam\SteamService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
c:\program files (x86)\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Sluttid: 2012-10-15 23:31:01 - datorn startades om.
ComboFix-quarantined-files.txt 2012-10-15 21:31
.
Före genomsökningen: 350*235*934*720 byte ledigt
Efter genomsökningen: 349*825*175*552 byte ledigt
.
- - End Of File - - EED21AD83F06B355C0DC9964EF7C7F75
 
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top