1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Unwanted sounds from computer!

Discussion in 'Virus & Other Malware Removal' started by bjja, Oct 15, 2012.

Thread Status:
Not open for further replies.
Advertisement
  1. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    Hi! It sounds like Commercial audio ads playing through speakers and i can't get rid off it! malware scanners have not been able to detect anything wrong.

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 15:57:02, on 2012-10-15
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v9.00 (9.00.8112.16450)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
    C:\Users\julius\Downloads\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: UserInit=userinit.exe
    O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
    O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
    O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
    O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    O4 - HKLM\..\Run: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
    O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
    O4 - HKLM\..\Run: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
    O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [Spotify] "C:\Users\julius\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Lokal tjänst')
    O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Lokal tjänst')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'Nätverkstjänst')
    O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'Nätverkstjänst')
    O4 - HKUS\S-1-5-21-1628012227-26710139-1449845332-1003\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
    O4 - HKUS\S-1-5-21-1628012227-26710139-1449845332-1003\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
    O4 - Global Startup: NETGEAR WNA3100 Smart Wizard.lnk = ?
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
    O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
    O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
    O23 - Service: Adobe Licensing Console - - C:\Windows\SysWOW64\lnsecsl.exe
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
    O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    O23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
    O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files (x86)\Digidesign\Pro Tools\digiSPTIService.exe
    O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: Tjänsten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Tjänsten Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: vToolbarUpdater12.2.6 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
    O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    O23 - Service: WSWNA3100 - Unknown owner - C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe

    --
    End of file - 11053 bytes
     
  2. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,889
    follow advice here and post the logs those programs make

    is there any reason you haven't updated to SP1 yet

    Please run the MGA Diagnostic Tool and post back the report it creates:
    • Download MGADiag to your desktop.
    • Double-click on MGADiag.exe to launch the program
    • Click "Continue"
    • Ensure that the "Windows" tab is selected (it should be by default).
    • Click the "Copy" button to copy the MGA Diagnostic Report to the Windows clipboard.
    • Paste the MGA Diagnostic Report back here in your next reply.

    Please download and run WVCheck.
    • Double-click WVCheck.exe.
    • As indicated by the prompt, this program can take a while depending on your hard drive space.
    • Once the program is done, copy the contents of the Notepad file as a reply.
     
  3. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    I don't have it? I thought it would install automatically?

    Diagnostic Report (1.9.0027.0):
    -----------------------------------------
    Windows Validation Data-->

    Validation Code: 0
    Cached Online Validation Code: 0x0
    Windows Product Key: *****-*****-H3GDR-BBWQ6-X9D7P
    Windows Product Key Hash: 7V41wMaoxyDLt70perqMVCmvers=
    Windows Product ID: 00426-OEM-9141204-92095
    Windows Product ID Type: 3
    Windows License Type: OEM System Builder
    Windows OS version: 6.1.7600.2.00010100.0.0.001
    ID: {77E6ECF9-978E-41AA-B951-F9AFE6A0CC19}(1)
    Is Admin: Yes
    TestCab: 0x0
    LegitcheckControl ActiveX: N/A, hr = 0x80070002
    Signed By: N/A, hr = 0x80070002
    Product Name: Windows 7 Ultimate
    Architecture: 0x00000009
    Build lab: 7600.win7_gdr.120830-0334
    TTS Error:
    Validation Diagnostic:
    Resolution Status: N/A

    Vista WgaER Data-->
    ThreatID(s): N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002

    Windows XP Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Notifications Data-->
    Cached Result: N/A, hr = 0x80070002
    Version: N/A, hr = 0x80070002
    OGAExec.exe Signed By: N/A, hr = 0x80070002
    OGAAddin.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{77E6ECF9-978E-41AA-B951-F9AFE6A0CC19}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-X9D7P</PKey><PID>00426-OEM-9141204-92095</PID><PIDType>3</PIDType><SID>S-1-5-21-1628012227-26710139-1449845332</SID><SYSTEM><Manufacturer>MSI</Manufacturer><Model>MS-7636</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>V1.10</Version><SMBIOSVersion major="2" minor="6"/><Date>20110126000000.000000+000</Date></BIOS><HWID>3AB83607018400FC</HWID><UserLCID>041D</UserLCID><SystemLCID>041D</SystemLCID><TimeZone>Västeuropa, normaltid(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/><GANotification/></MachineData><Software><Office><Result>109</Result><Products/><Applications/></Office></Software></GenuineResults>

    Spsys.log Content: 0x80070002

    Licensing Data-->
    Programlicenstjänstens version: 6.1.7600.16385

    Namn: Windows(R) 7, Ultimate edition
    Beskrivning: Windows Operating System - Windows(R) 7, OEM_COA_NSLP channel
    Aktiverings-ID: cfb3e52c-d707-4861-af51-11b27ee6169c
    Program-ID: 55c92734-d682-4d71-983e-d6ec3f16059f
    Utökat produkt-ID: 00426-00182-412-092095-02-1053-7600.0000-1862010
    Installations-ID: 005870314462554352422361142325910555732745013640183940
    URL till processorcertifikatet: http://go.microsoft.com/fwlink/?LinkID=88338
    URL till datorcertifikatet: http://go.microsoft.com/fwlink/?LinkID=88339
    URL till användningslicensen: http://go.microsoft.com/fwlink/?LinkID=88341
    URL till produktnyckelcertifikat: http://go.microsoft.com/fwlink/?LinkID=88340
    Ofullständig produktnyckel: X9D7P
    Licenstillstånd: Licensierad
    Återstående antal Windows-omaktiveringar: 3
    Betrodd tid: 2012-10-15 20:05:31

    Windows Activation Technologies-->
    HrOffline: 0x00000000
    HrOnline: 0x00000000
    HealthStatus: 0x0000000000000000
    Event Time Stamp: 10:10:2012 15:44
    ActiveX: Registered, Version: 7.1.7600.16395
    Admin Service: Registered, Version: 7.1.7600.16395
    HealthStatus Bitmask Output:


    HWID Data-->
    HWID Hash Current: PgAAAAIABgABAAEAAAAEAAAAAgABAAEA6GEkk3cWTGdCxgZP4l9E2D4kgJbcijakzp/AfPvOc32cuCu7XF0=

    OEM Activation 1.0 Data-->
    N/A

    OEM Activation 2.0 Data-->
    BIOS valid for OA 2.0: yes, but no SLIC table
    Windows marker version: N/A
    OEMID and OEMTableID Consistent: N/A
    BIOS Information:
    ACPI Table Name OEMID Value OEMTableID Value
    APIC 7636MS A7636100
    FACP 7636MS A7636100
    HPET 7636MS OEMHPET
    MCFG 7636MS OEMMCFG
    OEMB 7636MS A7636100
    SSDT DpgPmm CpuPm







    Windows Validation Check
    Version: 1.9.12.5
    Log Created On: 2006_15-10-2012
    -----------------------

    Windows Information
    -----------------------
    Windows Version: Windows 7
    Windows Mode: Normal
    Systemroot Path: C:\Windows

    WVCheck's Auto Update Check
    -----------------------
    Auto-Update Option: Download updates and install them automatically.
    -----------------------
    Last Success Time for Update Detection: 2012-10-15 12:23:23
    Last Success Time for Update Download: 2012-10-11 16:34:41
    Last Success Time for Update Installation: 2012-10-11 16:34:20


    WVCheck's Registry Check Check
    -----------------------
    Antiwpa: Not Found
    -----------------------
    Chew7Hale: Not Found
    -----------------------


    WVCheck's File Dump
    -----------------------
    C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7601.17514_none_5d778f71b9f4fd55\slwga.dll
    Size: 15360 bytes
    Creation; 9/10/2012 16:55:32
    Modification; 20/11/2010 14:27:26
    MD5; b6d6886149573278cba6abd44c4317f5
    Matched: slwga.dll
    -----------------------
    C:\Windows\SoftwareDistribution\Download\433767575943dacb697ee0558fc08c06\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7601.17514_none_0158f3ee01978c1f\slwga.dll
    Size: 14336 bytes
    Creation; 9/10/2012 16:55:27
    Modification; 20/11/2010 13:21:24
    MD5; 19f75d71e4256f5113d64ce2bb66b838
    Matched: slwga.dll
    -----------------------
    C:\Windows\System32\slwga.dll
    Size: 14336 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 6:38:16
    MD5; 2008845b41d561fb77b77bbe0045099e
    Matched: slwga.dll
    -----------------------
    C:\Windows\SysWOW64\slwga.dll
    Size: 14336 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 6:38:16
    MD5; 2008845b41d561fb77b77bbe0045099e
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16385_none_5b467ba9bd0679bb\slwga.dll
    Size: 14848 bytes
    Creation; 14/7/2009 1:52:11
    Modification; 14/7/2009 3:41:54
    MD5; cc03cf9f24946dcbd70acb3e1b2f05bf
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16723_none_5b856235bcd79403\slwga.dll
    Size: 15360 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 7:15:31
    MD5; b7213e92b270761b88b313b62ba0e13b
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\amd64_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.20862_none_5be2bf06d6168a3a\slwga.dll
    Size: 15360 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 7:9:5
    MD5; 86b7d4d7a87ecb9e6bded44c52c8d5d9
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16385_none_ff27e02604a90885\slwga.dll
    Size: 13824 bytes
    Creation; 14/7/2009 1:36:22
    Modification; 14/7/2009 3:16:15
    MD5; 01fe4bdd0b47a7d8bf34d78d2bc23ddb
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.16723_none_ff66c6b2047a22cd\slwga.dll
    Size: 14336 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 6:38:16
    MD5; 2008845b41d561fb77b77bbe0045099e
    Matched: slwga.dll
    -----------------------
    C:\Windows\winsxs\x86_microsoft-windows-security-spp-wga_31bf3856ad364e35_6.1.7600.20862_none_ffc423831db91904\slwga.dll
    Size: 14336 bytes
    Creation; 8/10/2012 19:51:5
    Modification; 21/12/2010 6:29:6
    MD5; 2332de32759ebcc691850e092b2564a6
    Matched: slwga.dll
    -----------------------


    WVCheck's Dir Dump
    -----------------------
    WVCheck found no known bad directories.


    WVCheck's Missing File Check
    -----------------------
    WVCheck found no missing Windows files.


    WVCheck's MBAM Quarantine Check
    -----------------------
    There were no bad files quarantined by MBAM.


    WVCheck's HOSTS File Check
    -----------------------
    WVCheck found no bad lines in the hosts file.


    WVCheck's MD5 Check
    EXPERIMENTAL!!
    -----------------------
    user32.dll - e8b0ffc209e504cb7e79fc24e6c085f0


    -------- End of File, program close at 2010_15-10-2012 --------
     
  4. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    DDS (Ver_2012-10-14.05) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16421
    Run by julius at 19:59:50 on 2012-10-15
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1053.18.3959.2175 [GMT 2:00]
    .
    AV: AVG Internet Security 2013 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: AVG Internet Security 2013 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
    FW: AVG Internet Security 2013 *Enabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
    .
    ============== Running Processes ===============
    .
    C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\TEMP\mrt79D0.tmp\stdrt.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\Windows\System32\M-AudioTaskBarIcon.exe
    C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
    C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
    C:\Program Files (x86)\NETGEAR\WNA3100\WNA3100.exe
    C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    C:\Program Files (x86)\AVG Secure Search\vprot.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
    C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
    C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
    C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\WUDFHost.exe
    C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    mWinlogon: Userinit = userinit.exe
    BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll
    TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
    TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    uRun: [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
    uRun: [Spotify Web Helper] "C:\Users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
    uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
    uRun: [Spotify] "C:\Users\julius\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
    mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
    mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
    mRun: [vProt] "C:\Program Files (x86)\AVG Secure Search\vprot.exe"
    mRun: [ROC_ROC_NT] "C:\Program Files (x86)\AVG Secure Search\ROC_ROC_NT.exe" / /PROMPT /CMPID=ROC_NT
    mRun: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe
    mRun: [Live Update 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\NETGEA~1.LNK - C:\Program Files (x86)\NETGEAR\WNA3100\WNA3100.exe
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
    TCP: NameServer = 192.168.1.1
    TCP: Interfaces\{D1F4C133-1B5C-4464-9F3C-66602FE55160} : DHCPNameServer = 192.168.1.1
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
    SSODL: WebCheck - <orphaned>
    x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll
    x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
    x64-Run: [M-Audio Taskbar Icon] C:\Windows\System32\M-AudioTaskBarIcon.exe
    x64-Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - <orphaned>
    x64-SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2012-9-21 61792]
    R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2012-9-21 225120]
    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2012-10-5 111456]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2012-9-14 40800]
    R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\System32\drivers\SCMNdisP.sys [2012-10-7 25312]
    R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2011-5-23 50296]
    R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2012-9-13 151904]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2012-10-2 185696]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2012-9-21 200032]
    R1 avgtp;avgtp;C:\Windows\System32\drivers\avgtpx64.sys [2012-10-7 31080]
    R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2012-10-7 283200]
    R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
    R2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG2013\avgfws.exe [2012-10-2 1314720]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [2012-10-2 5783672]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-2 193568]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-10-15 399432]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-10-15 676936]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-10-8 1258856]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-8-30 382312]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-10-7 2533400]
    R2 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2012-10-7 278528]
    R2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-10-7 722528]
    R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;C:\Windows\System32\drivers\bcmwlhigh664.sys [2012-10-7 838136]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2009-9-17 56344]
    R3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;C:\Windows\System32\drivers\MAudioFastTrackPro.sys [2010-12-7 187912]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-10-15 25928]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\System32\drivers\nvhda64v.sys [2012-10-8 189288]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-10-8 676968]
    S2 Adobe Licensing Console;Adobe Licensing Console;C:\Windows\SysWOW64\lnsecsl.exe [2012-10-13 905070]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Tjänsten Google Update (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-7 116648]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-7 250808]
    S3 gupdatem;Tjänsten Google Update (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-10-7 116648]
    S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys [2012-10-8 33592]
    S3 NTIOLib_1_0_4;NTIOLib_1_0_4;C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2012-10-8 14136]
    S3 NTIOLib_1_0_6;NTIOLib_1_0_6;C:\Program Files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys [2011-1-6 11888]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-7-9 52736]
    S3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-10-9 1255736]
    .
    =============== Created Last 30 ================
    .
    2012-10-15 12:31:37 -------- d-----w- C:\Users\julius\AppData\Roaming\Malwarebytes
    2012-10-15 12:31:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-10-15 12:31:32 -------- d-----w- C:\ProgramData\Malwarebytes
    2012-10-15 12:31:32 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-10-14 14:24:23 1713152 ----a-w- C:\Windows\System32\synsoacc.dll
    2012-10-14 14:24:23 -------- d-----w- C:\ProgramData\eLicenser
    2012-10-14 14:24:23 -------- d-----w- C:\Program Files (x86)\Syncrosoft
    2012-10-14 14:24:23 -------- d-----w- C:\Program Files (x86)\eLicenser
    2012-10-14 14:24:21 86016 ----a-w- C:\Windows\SysWow64\SYNSOPOS.exe
    2012-10-14 14:24:21 1277952 ----a-w- C:\Windows\SysWow64\SYNSOACC.dll
    2012-10-14 13:47:29 -------- d-----w- C:\Program Files (x86)\Common Files\reFX
    2012-10-14 13:41:45 2440704 ----a-w- C:\Windows\SysWow64\SYNSOEMU.DLL
    2012-10-14 10:56:33 -------- dc-h--w- C:\ProgramData\{E26B3878-7CEC-469C-B449-5CAA336DF8CD}
    2012-10-14 10:55:48 -------- dc-h--w- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
    2012-10-13 20:25:21 -------- d-----w- C:\Program Files (x86)\Ableton
    2012-10-13 19:48:31 -------- d-----w- C:\Program Files (x86)\VstPlugins
    2012-10-13 19:48:18 1554944 ----a-w- C:\Windows\SysWow64\vorbis.acm
    2012-10-13 19:48:08 -------- d-----w- C:\Program Files (x86)\Outsim
    2012-10-13 19:45:59 -------- d-----w- C:\Program Files (x86)\Image-Line
    2012-10-13 19:45:04 905070 ----a-w- C:\Windows\SysWow64\lnsecsl.exe
    2012-10-13 00:45:10 -------- d-----w- C:\Users\julius\AppData\Local\Apple Computer
    2012-10-13 00:44:49 33240 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
    2012-10-13 00:43:21 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
    2012-10-13 00:43:21 -------- d-----w- C:\Program Files\iTunes
    2012-10-13 00:43:21 -------- d-----w- C:\Program Files\iPod
    2012-10-13 00:43:21 -------- d-----w- C:\Program Files (x86)\iTunes
    2012-10-13 00:42:20 -------- d-----w- C:\Users\julius\AppData\Local\Apple
    2012-10-13 00:41:15 -------- d-----w- C:\Program Files\Bonjour
    2012-10-13 00:41:15 -------- d-----w- C:\Program Files (x86)\Bonjour
    2012-10-11 16:47:10 -------- d-----w- C:\Users\julius\AppData\Local\SKIDROW
    2012-10-11 16:36:16 -------- d-----w- C:\Program Files (x86)\Bethesda Softworks
    2012-10-10 17:30:30 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
    2012-10-10 15:11:34 98304 ----a-w- C:\Windows\System32CmdLineExt.dll
    2012-10-10 14:45:29 -------- d-----w- C:\Program Files (x86)\Steam
    2012-10-10 13:28:58 220160 ----a-w- C:\Windows\System32\wintrust.dll
    2012-10-10 13:28:57 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
    2012-10-10 13:28:55 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-10-10 13:28:55 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-10-10 13:28:45 714752 ----a-w- C:\Windows\System32\kerberos.dll
    2012-10-10 13:28:45 541184 ----a-w- C:\Windows\SysWow64\kerberos.dll
    2012-10-10 13:28:40 182272 ----a-w- C:\Windows\System32\cryptsvc.dll
    2012-10-10 13:28:40 1462784 ----a-w- C:\Windows\System32\crypt32.dll
    2012-10-10 13:28:40 140288 ----a-w- C:\Windows\System32\cryptnet.dll
    2012-10-10 13:28:40 139264 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2012-10-10 13:28:40 1157632 ----a-w- C:\Windows\SysWow64\crypt32.dll
    2012-10-10 13:28:40 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    2012-10-09 20:53:31 -------- d-----w- C:\Program Files (x86)\Common Files\Propellerhead Software
    2012-10-09 13:59:09 -------- d-----w- C:\Games
    2012-10-09 13:56:20 -------- d-----w- C:\Users\julius\AppData\Local\Black_Tree_Gaming
    2012-10-09 13:56:14 -------- d-----w- C:\Program Files\Nexus Mod Manager
    2012-10-09 13:45:18 -------- d-----w- C:\Program Files (x86)\VideoLAN
    2012-10-09 12:52:30 -------- d-----w- C:\ProgramData\DivX
    2012-10-09 12:51:41 -------- d-----w- C:\Users\julius\AppData\Local\MotionDSP
    2012-10-09 12:15:02 -------- d-----w- C:\Windows\SysWow64\Wat
    2012-10-09 12:15:02 -------- d-----w- C:\Windows\System32\Wat
    2012-10-08 23:02:40 367104 ----a-w- C:\Windows\System32\wcncsvc.dll
    2012-10-08 23:02:40 276992 ----a-w- C:\Windows\SysWow64\wcncsvc.dll
    2012-10-08 22:46:23 311808 ----a-w- C:\Windows\System32\msv1_0.dll
    2012-10-08 22:46:23 257024 ----a-w- C:\Windows\SysWow64\msv1_0.dll
    2012-10-08 22:32:26 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
    2012-10-08 22:32:26 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
    2012-10-08 22:32:26 48960 ----a-w- C:\Windows\System32\netfxperf.dll
    2012-10-08 22:32:26 444752 ----a-w- C:\Windows\System32\mscoree.dll
    2012-10-08 22:32:26 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
    2012-10-08 22:32:26 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
    2012-10-08 22:32:26 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
    2012-10-08 22:32:26 1942856 ----a-w- C:\Windows\System32\dfshim.dll
    2012-10-08 22:32:26 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
    2012-10-08 22:32:26 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
    2012-10-08 22:31:15 294912 ----a-w- C:\Windows\System32\browserchoice.exe
    2012-10-08 22:18:59 80896 ----a-w- C:\Windows\System32\imagehlp.dll
    2012-10-08 22:18:59 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
    2012-10-08 22:18:59 5120 ----a-w- C:\Windows\System32\wmi.dll
    2012-10-08 22:18:59 22896 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
    2012-10-08 22:18:59 158720 ----a-w- C:\Windows\SysWow64\imagehlp.dll
    2012-10-08 22:16:35 243712 ----a-w- C:\Windows\System32\drivers\ks.sys
    2012-10-08 20:12:12 9575864 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
    2012-10-08 18:49:28 -------- d-----w- C:\Users\julius\AppData\Local\Skyrim
    2012-10-08 18:32:32 -------- d-----w- C:\Program Files (x86)\Setup Files
    2012-10-08 18:30:39 74344 ----a-w- C:\Windows\System32\RtNicProp64.dll
    2012-10-08 18:30:39 676968 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
    2012-10-08 18:09:30 3487434 ----a-w- C:\Windows\System32\nvcoproc.bin
    2012-10-08 18:09:09 -------- d-----w- C:\temp
    2012-10-08 18:02:24 78680 ----a-w- C:\Windows\System32\XAPOFX1_4.dll
    2012-10-08 18:01:59 5073256 ----a-w- C:\Windows\System32\d3dx9_35.dll
    2012-10-08 17:57:10 -------- d-----w- C:\Program Files (x86)\The Elder Scrolls V Skyrim
    2012-10-08 17:54:49 503808 ----a-w- C:\Windows\System32\srcore.dll
    2012-10-08 17:53:36 1572864 ----a-w- C:\Windows\System32\quartz.dll
    2012-10-08 17:52:59 483840 ----a-w- C:\Windows\System32\StructuredQuery.dll
    2012-10-08 17:51:48 43520 ----a-w- C:\Windows\System32\csrsrv.dll
    2012-10-08 17:50:55 662528 ----a-w- C:\Windows\System32\XpsPrint.dll
    2012-10-08 17:49:36 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll
    2012-10-08 17:48:27 738816 ----a-w- C:\Windows\SysWow64\wmpmde.dll
    2012-10-08 17:47:59 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
    2012-10-08 17:46:57 640896 ----a-w- C:\Windows\System32\winload.efi
    2012-10-08 17:45:46 64512 ----a-w- C:\Windows\SysWow64\devobj.dll
    2012-10-08 17:44:56 723456 ----a-w- C:\Windows\System32\EncDec.dll
    2012-10-08 17:44:56 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
    2012-10-08 17:44:46 1895280 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2012-10-08 17:43:13 -------- d-----w- C:\Users\julius\AppData\Roaming\PACE Anti-Piracy
    2012-10-08 17:43:13 -------- d-----w- C:\Users\julius\AppData\Local\PACE Anti-Piracy
    2012-10-08 17:43:13 -------- d-----w- C:\ProgramData\PACE Anti-Piracy
    2012-10-08 17:43:13 -------- d-----w- C:\Program Files (x86)\Common Files\PACE Anti-Piracy
    2012-10-08 17:39:54 -------- d-----w- C:\Program Files (x86)\MSI
    2012-10-08 17:37:25 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-10-08 17:37:25 1732096 ----a-w- C:\Program Files\Windows Journal\NBDoc.DLL
    2012-10-08 17:37:25 1402880 ----a-w- C:\Program Files\Windows Journal\JNWDRV.dll
    2012-10-08 17:37:25 1393664 ----a-w- C:\Program Files\Windows Journal\JNTFiltr.dll
    2012-10-08 17:37:25 1367552 ----a-w- C:\Program Files\Common Files\Microsoft Shared\ink\journal.dll
    2012-10-08 17:36:18 1425408 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
    2012-10-08 17:36:17 987136 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msado15.dll
    2012-10-08 17:36:02 720896 ----a-w- C:\Windows\System32\odbc32.dll
    2012-10-08 17:36:02 573440 ----a-w- C:\Windows\SysWow64\odbc32.dll
    2012-10-08 17:36:02 495616 ----a-w- C:\Program Files\Common Files\System\ado\msadox.dll
    2012-10-08 17:36:02 466944 ----a-w- C:\Program Files\Common Files\System\ado\msadomd.dll
    2012-10-08 17:36:02 372736 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadox.dll
    2012-10-08 17:36:02 352256 ----a-w- C:\Program Files (x86)\Common Files\System\ado\msadomd.dll
    2012-10-08 17:36:02 258048 ----a-w- C:\Program Files\Common Files\System\msadc\msadco.dll
    2012-10-08 17:36:02 208896 ----a-w- C:\Program Files (x86)\Common Files\System\msadc\msadco.dll
    2012-10-08 17:35:53 1739160 ----a-w- C:\Windows\System32\ntdll.dll
    2012-10-08 17:35:53 1292592 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2012-10-08 17:35:49 9728 ----a-w- C:\Windows\SysWow64\sscore.dll
    2012-10-08 17:35:49 236032 ----a-w- C:\Windows\System32\srvsvc.dll
    2012-10-08 17:35:29 77312 ----a-w- C:\Windows\System32\packager.dll
    2012-10-08 17:35:29 67072 ----a-w- C:\Windows\SysWow64\packager.dll
    2012-10-07 21:01:52 -------- d-----w- C:\Program Files (x86)\ASIO4ALL v2
    2012-10-07 20:04:26 -------- d-----w- C:\Users\julius\AppData\Local\Spotify
    2012-10-07 20:04:01 -------- d-----w- C:\Users\julius\AppData\Roaming\Spotify
    2012-10-07 19:52:09 -------- d-----w- C:\Program Files\Common Files\Native Instruments
    2012-10-07 19:52:09 -------- d-----w- C:\Program Files (x86)\Common Files\Native Instruments
    2012-10-07 19:51:54 -------- d-----w- C:\ProgramData\Native Instruments
    2012-10-07 19:51:54 -------- d-----w- C:\Program Files\Native Instruments
    2012-10-07 19:49:25 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys
    2012-10-07 19:49:19 -------- d-----w- C:\Users\julius\AppData\Roaming\DAEMON Tools Pro
    2012-10-07 19:49:17 -------- d-----w- C:\Program Files (x86)\DAEMON Tools Pro
    2012-10-07 19:48:35 -------- d-----w- C:\ProgramData\DAEMON Tools Pro
    2012-10-07 19:41:06 -------- d-----w- C:\Users\julius\AppData\Roaming\Ableton
    2012-10-07 19:34:40 -------- d-----w- C:\ProgramData\Ableton
    2012-10-07 19:08:23 -------- d-----w- C:\Program Files (x86)\InterLok
    2012-10-07 19:08:17 -------- d-----w- C:\Windows\Downloaded Installations
    2012-10-07 18:56:42 -------- d-----w- C:\Program Files (x86)\uTorrent
    2012-10-07 18:55:48 -------- d-----w- C:\Users\julius\AppData\Roaming\uTorrent
    2012-10-07 18:44:05 -------- d-----w- C:\Program Files\M-Audio
    2012-10-07 18:30:54 -------- d-----w- C:\Users\julius\AppData\Roaming\AVG2013
    2012-10-07 18:30:14 -------- d-----w- C:\Users\julius\AppData\Local\AVG Secure Search
    2012-10-07 18:30:11 -------- d-----w- C:\Users\julius\AppData\Roaming\TuneUp Software
    2012-10-07 18:30:09 -------- d-----w- C:\ProgramData\AVG Secure Search
    2012-10-07 18:30:01 31080 ----a-w- C:\Windows\System32\drivers\avgtpx64.sys
    2012-10-07 18:29:59 -------- d-----w- C:\Program Files (x86)\Common Files\AVG Secure Search
    2012-10-07 18:29:59 -------- d-----w- C:\Program Files (x86)\AVG Secure Search
    2012-10-07 18:28:43 -------- d--h--w- C:\$AVG
    2012-10-07 18:28:43 -------- d-----w- C:\ProgramData\AVG2013
    2012-10-07 18:28:26 139264 ----a-w- C:\Windows\System32\cabview.dll
    2012-10-07 18:28:25 132608 ----a-w- C:\Windows\SysWow64\cabview.dll
    2012-10-07 18:28:24 826368 ----a-w- C:\Windows\SysWow64\rdpcore.dll
    2012-10-07 18:28:24 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
    2012-10-07 18:28:24 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
    2012-10-07 18:28:15 -------- d-----w- C:\Program Files (x86)\AVG
    2012-10-07 18:24:56 -------- d--h--w- C:\ProgramData\Common Files
    2012-10-07 18:24:56 -------- d-----w- C:\Users\julius\AppData\Local\MFAData
    2012-10-07 18:24:56 -------- d-----w- C:\Users\julius\AppData\Local\Avg2013
    2012-10-07 18:24:56 -------- d-----w- C:\ProgramData\MFAData
    2012-10-07 18:24:10 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-10-07 18:24:10 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-10-07 18:23:54 2622464 ----a-w- C:\Windows\System32\wucltux.dll
    2012-10-07 18:23:49 99840 ----a-w- C:\Windows\System32\wudriver.dll
    2012-10-07 18:23:38 36864 ----a-w- C:\Windows\System32\wuapp.exe
    2012-10-07 18:23:38 186752 ----a-w- C:\Windows\System32\wuwebv.dll
    2012-10-07 18:22:16 -------- d-----w- C:\Users\julius\AppData\Local\Google
    2012-10-07 18:22:02 -------- d-----w- C:\Users\julius\AppData\Local\Apps
    2012-10-07 18:22:01 -------- d-----w- C:\Users\julius\AppData\Local\Deployment
    2012-10-07 18:18:26 107624 ----a-w- C:\Windows\System32\RTNUninst64.dll
    2012-10-07 18:17:31 -------- d-----w- C:\Program Files (x86)\Common Files\postureAgent
    2012-10-07 18:17:04 53248 ----a-w- C:\Windows\SysWow64\CSVer.dll
    2012-10-07 18:17:00 -------- d-----w- C:\Intel
    2012-10-07 18:09:39 -------- d-----w- C:\Users\julius\AppData\Roaming\MotionDSP
    2012-10-07 18:08:58 -------- d-----w- C:\Program Files (x86)\vReveal
    2012-10-07 18:07:53 255592 ----a-w- C:\Windows\System32\nvcohda6.dll
    2012-10-07 18:07:52 -------- d-----w- C:\NVIDIA
    2012-10-07 18:07:24 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
    2012-10-07 18:06:53 -------- d-----w- C:\ProgramData\NVIDIA Corporation
    2012-10-07 18:06:52 -------- d-----w- C:\Program Files\NVIDIA Corporation
    2012-10-07 17:54:13 -------- d-----w- C:\Users\julius\AppData\Local\VirtualStore
    2012-10-05 01:26:22 111456 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
    2012-10-02 01:30:38 185696 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
    2012-09-21 01:46:04 200032 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
    2012-09-21 01:46:00 225120 ----a-w- C:\Windows\System32\drivers\avgloga.sys
    2012-09-21 01:45:50 61792 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
    .
    ==================== Find3M ====================
    .
    2012-09-14 01:05:18 40800 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
    2012-09-13 01:11:18 151904 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
    2012-09-04 08:39:32 50296 ----a-w- C:\Windows\System32\drivers\avgfwd6a.sys
    2012-08-31 18:02:20 1656688 ----a-w- C:\Windows\System32\drivers\ntfs.sys
    2012-08-30 18:11:29 5505904 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-08-30 17:18:33 3958128 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-08-30 17:18:33 3902832 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-08-30 16:18:05 891240 ----a-w- C:\Windows\System32\nvvsvc.exe
    2012-08-30 16:18:05 63336 ----a-w- C:\Windows\System32\nvshext.dll
    2012-08-30 16:18:05 2557800 ----a-w- C:\Windows\System32\nvsvcr.dll
    2012-08-30 16:18:05 118120 ----a-w- C:\Windows\System32\nvmctray.dll
    2012-08-30 16:18:01 3266920 ----a-w- C:\Windows\System32\nvsvc64.dll
    2012-08-30 16:17:59 6198120 ----a-w- C:\Windows\System32\nvcpl.dll
    2012-08-30 08:40:14 429416 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
    2012-08-21 11:01:20 125872 ----a-w- C:\Windows\System32\GEARAspi64.dll
    2012-08-21 11:01:20 106928 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
    2012-08-18 15:43:05 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2012-08-18 15:43:05 243200 ----a-w- C:\Windows\System32\wow64.dll
    2012-08-18 15:43:05 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2012-08-18 15:42:31 215040 ----a-w- C:\Windows\System32\winsrv.dll
    2012-08-18 15:40:26 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2012-08-18 15:37:49 425984 ----a-w- C:\Windows\System32\KernelBase.dll
    2012-08-18 15:34:13 338432 ----a-w- C:\Windows\System32\conhost.exe
    2012-08-18 11:22:55 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2012-08-18 11:19:45 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2012-08-18 11:19:22 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2012-08-18 11:17:56 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2012-08-18 11:17:56 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2012-08-18 09:12:09 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2012-08-18 09:12:09 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2012-08-18 09:07:02 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2012-08-18 09:07:02 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2012-08-18 09:07:02 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2012-08-18 09:07:02 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2012-08-02 17:55:04 574464 ----a-w- C:\Windows\System32\d3d10level9.dll
    2012-08-02 17:05:42 490496 ----a-w- C:\Windows\SysWow64\d3d10level9.dll
    2012-07-18 17:31:12 3146752 ----a-w- C:\Windows\System32\win32k.sys
    .
    ============= FINISH: 20:00:37,47 ===============






    NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-10-14.05)
    .
    Microsoft Windows 7 Ultimate
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2012-10-07 19:53:07
    System Uptime: 2012-10-15 19:54:01 (1 hours ago)
    .
    Motherboard: MSI | | H55M-E33(MS-7636)
    Processor: Intel(R) Core(TM) i5 CPU 650 @ 3.20GHz | CPU 1 | 2912/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 466 GiB total, 326,296 GiB free.
    D: is CDROM ()
    E: is Removable
    F: is FIXED (NTFS) - 466 GiB total, 437,625 GiB free.
    G: is CDROM (UDF)
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP22: 2012-10-11 18:30:07 - Windows Update
    RP23: 2012-10-13 02:42:33 - Installed iTunes
    RP24: 2012-10-14 16:24:28 - Installation av enhetsdrivrutinspaket: Steinberg Media Technologies GmbH
    .
    ==== Installed Programs ======================
    .
    Ableton Live 8
    Adobe Flash Player 11 ActiveX
    Apple-programstöd
    Apple Mobile Device Support
    Apple Software Update
    ASIO4ALL
    µTorrent
    AVG 2013
    Bonjour
    DAEMON Tools Pro
    Dark Messiah
    Digidesign Pro Tools M-Powered Demo 7.4
    Digidesign Shared Plug-Ins 7.4
    Dishonored
    eLicenser Control
    FL Studio 10
    Google Chrome
    Google Toolbar for Internet Explorer
    Google Update Helper
    IL Download Manager
    Intel(R) Control Center
    Intel(R) Management Engine Components
    Interlok driver setup x64
    iTunes
    Live 8.2.2
    Live Update 5
    M-Audio FastTrackPro Driver 6.0.7 (x64)
    Malwarebytes Anti-Malware version 1.65.0.1400
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Client Profile Language Pack - SVE
    Microsoft .NET Framework 4 Client Profile SVE Language Pack
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
    Native Instruments Massive
    Native Instruments Service Center
    NETGEAR WNA3100 wireless USB 2.0 adapter
    Nexus Mod Manager
    NVIDIA-uppdatering 1.10.8
    NVIDIA 3D Vision drivrutin 306.23
    NVIDIA 3D Vision drivrutin för styrenhet 306.23
    NVIDIA Display Control Panel
    NVIDIA Grafikdrivrutin 306.23
    NVIDIA HD audiodrivrutin 1.3.18.0
    NVIDIA Install Application
    NVIDIA PhysX
    NVIDIA PhysX systemprogramvara 9.12.0604
    NVIDIA Stereoscopic 3D Driver
    NVIDIA Update Components
    NVIDIAs kontrollpanel 306.23
    Realtek Ethernet Controller Driver
    Realtek High Definition Audio Driver
    reFX Nexus VSTi RTAS v2.2.0
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Spotify
    Steam
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    WinRAR 4.20 (64-bit)
    Visual Studio 2010 x64 Redistributables
    VLC media player 2.0.3
    vReveal
    .
    ==== End Of File ===========================
     
  5. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,889
    ok we will try & sort out SP1 later
    itf you haven't got it and are on automatic updates, it normally menas that an optional vital update is needed

    first though lets try & sort the problem

    Run tdss killer from http://support.kaspersky.com/viruses/solutions?qid=208280684

    let it cure anything it fnds ( except SPTD.SYS or anything detected as UnsignedFile.Multi.Generic, which should be ignored) & then reboot

    post back with its log

    By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder.
    Logs have names like: UtilityName.Version_Date_Time_log.txt.
    E.g. C:\TDSSKiller.2.4.7_23.07.2010_15.31.43_log.txt
     
  6. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    21:08:52.0034 9576 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
    21:08:52.0684 9576 ============================================================
    21:08:52.0684 9576 Current date / time: 2012/10/15 21:08:52.0684
    21:08:52.0684 9576 SystemInfo:
    21:08:52.0684 9576
    21:08:52.0684 9576 OS Version: 6.1.7600 ServicePack: 0.0
    21:08:52.0684 9576 Product type: Workstation
    21:08:52.0684 9576 ComputerName: JULIUS-DATOR
    21:08:52.0684 9576 UserName: julius
    21:08:52.0684 9576 Windows directory: C:\Windows
    21:08:52.0684 9576 System windows directory: C:\Windows
    21:08:52.0684 9576 Running under WOW64
    21:08:52.0684 9576 Processor architecture: Intel x64
    21:08:52.0684 9576 Number of processors: 4
    21:08:52.0684 9576 Page size: 0x1000
    21:08:52.0684 9576 Boot type: Normal boot
    21:08:52.0684 9576 ============================================================
    21:08:53.0874 9576 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    21:08:53.0884 9576 Drive \Device\Harddisk1\DR1 - Size: 0x7470C05E00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    21:08:54.0184 9576 ============================================================
    21:08:54.0184 9576 \Device\Harddisk0\DR0:
    21:08:54.0224 9576 MBR partitions:
    21:08:54.0224 9576 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000
    21:08:54.0224 9576 \Device\Harddisk1\DR1:
    21:08:54.0294 9576 MBR partitions:
    21:08:54.0294 9576 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384C02
    21:08:54.0294 9576 ============================================================
    21:08:54.0314 9576 C: <-> \Device\Harddisk0\DR0\Partition1
    21:08:54.0354 9576 F: <-> \Device\Harddisk1\DR1\Partition1
    21:08:54.0354 9576 ============================================================
    21:08:54.0354 9576 Initialize success
    21:08:54.0354 9576 ============================================================
    21:09:02.0933 10232 ============================================================
    21:09:02.0934 10232 Scan started
    21:09:02.0934 10232 Mode: Manual;
    21:09:02.0934 10232 ============================================================
    21:09:04.0886 10232 ================ Scan system memory ========================
    21:09:04.0886 10232 System memory - ok
    21:09:04.0886 10232 ================ Scan services =============================
    21:09:05.0016 10232 [ 1B00662092F9F9568B995902F0CC40D5 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
    21:09:05.0016 10232 1394ohci - ok
    21:09:05.0036 10232 [ 6F11E88748CDEFD2F76AA215F97DDFE5 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
    21:09:05.0046 10232 ACPI - ok
    21:09:05.0046 10232 [ 63B05A0420CE4BF0E4AF6DCC7CADA254 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
    21:09:05.0046 10232 AcpiPmi - ok
    21:09:05.0312 10232 [ D13DC8B68779ADA1176A52F39EEF10FF ] Adobe Licensing Console C:\Windows\SysWOW64\lnsecsl.exe
    21:09:05.0327 10232 Adobe Licensing Console - ok
    21:09:05.0395 10232 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    21:09:05.0399 10232 AdobeFlashPlayerUpdateSvc - ok
    21:09:05.0427 10232 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
    21:09:05.0434 10232 adp94xx - ok
    21:09:05.0460 10232 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
    21:09:05.0466 10232 adpahci - ok
    21:09:05.0485 10232 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
    21:09:05.0489 10232 adpu320 - ok
    21:09:05.0517 10232 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    21:09:05.0519 10232 AeLookupSvc - ok
    21:09:05.0565 10232 [ DB9D6C6B2CD95A9CA414D045B627422E ] AFD C:\Windows\system32\drivers\afd.sys
    21:09:05.0573 10232 AFD - ok
    21:09:05.0594 10232 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
    21:09:05.0597 10232 agp440 - ok
    21:09:05.0611 10232 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
    21:09:05.0614 10232 ALG - ok
    21:09:05.0628 10232 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
    21:09:05.0629 10232 aliide - ok
    21:09:05.0636 10232 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\DRIVERS\amdide.sys
    21:09:05.0638 10232 amdide - ok
    21:09:05.0643 10232 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
    21:09:05.0645 10232 AmdK8 - ok
    21:09:05.0650 10232 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
    21:09:05.0652 10232 AmdPPM - ok
    21:09:05.0675 10232 [ EC7EBAB00A4D8448BAB68D1E49B4BEB9 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    21:09:05.0677 10232 amdsata - ok
    21:09:05.0704 10232 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
    21:09:05.0708 10232 amdsbs - ok
    21:09:05.0713 10232 [ DB27766102C7BF7E95140A2AA81D042E ] amdxata C:\Windows\system32\drivers\amdxata.sys
    21:09:05.0714 10232 amdxata - ok
    21:09:05.0728 10232 [ 42FD751B27FA0E9C69BB39F39E409594 ] AppID C:\Windows\system32\drivers\appid.sys
    21:09:05.0730 10232 AppID - ok
    21:09:05.0745 10232 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    21:09:05.0747 10232 AppIDSvc - ok
    21:09:05.0752 10232 [ D065BE66822847B7F127D1F90158376E ] Appinfo C:\Windows\System32\appinfo.dll
    21:09:05.0753 10232 Appinfo - ok
    21:09:05.0850 10232 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    21:09:05.0852 10232 Apple Mobile Device - ok
    21:09:05.0895 10232 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
    21:09:05.0899 10232 AppMgmt - ok
    21:09:05.0938 10232 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
    21:09:05.0940 10232 arc - ok
    21:09:05.0952 10232 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
    21:09:05.0954 10232 arcsas - ok
    21:09:05.0988 10232 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    21:09:05.0990 10232 AsyncMac - ok
    21:09:05.0995 10232 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\DRIVERS\atapi.sys
    21:09:05.0996 10232 atapi - ok
    21:09:06.0046 10232 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    21:09:06.0056 10232 AudioEndpointBuilder - ok
    21:09:06.0071 10232 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioSrv C:\Windows\System32\Audiosrv.dll
    21:09:06.0078 10232 AudioSrv - ok
    21:09:06.0122 10232 [ 3D1FFAA3358CA0D8A298DEA8BECFC468 ] Avgfwfd C:\Windows\system32\DRIVERS\avgfwd6a.sys
    21:09:06.0124 10232 Avgfwfd - ok
    21:09:06.0187 10232 [ 2E0DB82F4254FF91E153F331BA9B2D6E ] avgfws C:\Program Files (x86)\AVG\AVG2013\avgfws.exe
    21:09:06.0213 10232 avgfws - ok
    21:09:06.0329 10232 [ B41F0E54105801538D56623271A0AE49 ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    21:09:06.0417 10232 AVGIDSAgent - ok
    21:09:06.0428 10232 [ F1A99DA71E6549D7D944596E15142866 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys
    21:09:06.0430 10232 AVGIDSDriver - ok
    21:09:06.0449 10232 [ E6CB84918C1ABE84AAAF749D2EA4E764 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys
    21:09:06.0450 10232 AVGIDSHA - ok
    21:09:06.0466 10232 [ 5989592A91A17587799792A81E1541D4 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys
    21:09:06.0469 10232 Avgldx64 - ok
    21:09:06.0490 10232 [ 3FC43AA02545FCDDC22817829114DEC8 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys
    21:09:06.0494 10232 Avgloga - ok
    21:09:06.0514 10232 [ EAFF19168F26FA225EB679547B718051 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys
    21:09:06.0516 10232 Avgmfx64 - ok
    21:09:06.0526 10232 [ FE4F444DBE4BBBDFD8FECF49398DEFC7 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys
    21:09:06.0527 10232 Avgrkx64 - ok
    21:09:06.0543 10232 [ 6E634525613D48A1D1657FB21F21F3B2 ] Avgtdia C:\Windows\system32\DRIVERS\avgtdia.sys
    21:09:06.0547 10232 Avgtdia - ok
    21:09:06.0570 10232 [ DE24B2CA078FC6A7EAA53B1DFD3F61CF ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
    21:09:06.0571 10232 avgtp - ok
    21:09:06.0596 10232 [ 0D2EB149AFF89A307E5D82D0A2B78439 ] avgwd C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    21:09:06.0599 10232 avgwd - ok
    21:09:06.0700 10232 [ B20B5FA5CA050E9926E4D1DB81501B32 ] AxInstSV C:\Windows\System32\AxInstSV.dll
    21:09:06.0737 10232 AxInstSV - ok
    21:09:06.0853 10232 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
    21:09:06.0860 10232 b06bdrv - ok
    21:09:06.0891 10232 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
    21:09:06.0896 10232 b57nd60a - ok
    21:09:06.0947 10232 [ E49110A58A32E9450356686A95DD7763 ] BCMH43XX C:\Windows\system32\DRIVERS\bcmwlhigh664.sys
    21:09:06.0954 10232 BCMH43XX - ok
    21:09:06.0996 10232 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
    21:09:07.0039 10232 BDESVC - ok
    21:09:07.0059 10232 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
    21:09:07.0060 10232 Beep - ok
    21:09:07.0098 10232 [ 4992C609A6315671463E30F6512BC022 ] BFE C:\Windows\System32\bfe.dll
    21:09:07.0108 10232 BFE - ok
    21:09:07.0139 10232 [ 7F0C323FE3DA28AA4AA1BDA3F575707F ] BITS C:\Windows\System32\qmgr.dll
    21:09:07.0156 10232 BITS - ok
    21:09:07.0173 10232 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
    21:09:07.0175 10232 blbdrive - ok
    21:09:07.0277 10232 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
    21:09:07.0282 10232 Bonjour Service - ok
    21:09:07.0306 10232 [ 19D20159708E152267E53B66677A4995 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    21:09:07.0308 10232 bowser - ok
    21:09:07.0332 10232 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
    21:09:07.0334 10232 BrFiltLo - ok
    21:09:07.0339 10232 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
    21:09:07.0341 10232 BrFiltUp - ok
    21:09:07.0368 10232 [ 6B054C67AAA87843504E8E3C09102009 ] Browser C:\Windows\System32\browser.dll
    21:09:07.0371 10232 Browser - ok
    21:09:07.0378 10232 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
    21:09:07.0383 10232 Brserid - ok
    21:09:07.0388 10232 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    21:09:07.0390 10232 BrSerWdm - ok
    21:09:07.0394 10232 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    21:09:07.0395 10232 BrUsbMdm - ok
    21:09:07.0399 10232 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
    21:09:07.0400 10232 BrUsbSer - ok
    21:09:07.0404 10232 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
    21:09:07.0406 10232 BTHMODEM - ok
    21:09:07.0442 10232 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
    21:09:07.0443 10232 bthserv - ok
    21:09:07.0466 10232 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    21:09:07.0468 10232 cdfs - ok
    21:09:07.0486 10232 [ 83D2D75E1EFB81B3450C18131443F7DB ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    21:09:07.0488 10232 cdrom - ok
    21:09:07.0509 10232 [ 312E2F82AF11E79906898AC3E3D58A1F ] CertPropSvc C:\Windows\System32\certprop.dll
    21:09:07.0510 10232 CertPropSvc - ok
    21:09:07.0528 10232 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
    21:09:07.0530 10232 circlass - ok
    21:09:07.0546 10232 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
    21:09:07.0550 10232 CLFS - ok
    21:09:07.0625 10232 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    21:09:07.0627 10232 clr_optimization_v2.0.50727_32 - ok
    21:09:07.0679 10232 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    21:09:07.0686 10232 clr_optimization_v2.0.50727_64 - ok
    21:09:07.0747 10232 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    21:09:07.0750 10232 clr_optimization_v4.0.30319_32 - ok
    21:09:07.0775 10232 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    21:09:07.0778 10232 clr_optimization_v4.0.30319_64 - ok
    21:09:07.0814 10232 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
    21:09:07.0816 10232 CmBatt - ok
    21:09:07.0827 10232 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
    21:09:07.0829 10232 cmdide - ok
    21:09:07.0876 10232 [ CA7720B73446FDDEC5C69519C1174C98 ] CNG C:\Windows\system32\Drivers\cng.sys
    21:09:07.0883 10232 CNG - ok
    21:09:07.0887 10232 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
    21:09:07.0889 10232 Compbatt - ok
    21:09:07.0916 10232 [ F26B3A86F6FA87CA360B879581AB4123 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
    21:09:07.0919 10232 CompositeBus - ok
    21:09:07.0937 10232 COMSysApp - ok
    21:09:07.0974 10232 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
    21:09:07.0976 10232 crcdisk - ok
    21:09:08.0008 10232 [ BAF19B633933A9FB4883D27D66C39E9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
    21:09:08.0011 10232 CryptSvc - ok
    21:09:08.0044 10232 [ 4A6173C2279B498CD8F57CAE504564CB ] CSC C:\Windows\system32\drivers\csc.sys
    21:09:08.0072 10232 CSC - ok
    21:09:08.0110 10232 [ 873FBF927C06E5CEE04DEC617502F8FD ] CscService C:\Windows\System32\cscsvc.dll
    21:09:08.0120 10232 CscService - ok
    21:09:08.0157 10232 [ 7266972E86890E2B30C0C322E906B027 ] DcomLaunch C:\Windows\system32\rpcss.dll
    21:09:08.0165 10232 DcomLaunch - ok
    21:09:08.0186 10232 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
    21:09:08.0192 10232 defragsvc - ok
    21:09:08.0211 10232 [ 9C253CE7311CA60FC11C774692A13208 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    21:09:08.0213 10232 DfsC - ok
    21:09:08.0234 10232 [ CE3B9562D997F69B330D181A8875960F ] Dhcp C:\Windows\system32\dhcpcore.dll
    21:09:08.0239 10232 Dhcp - ok
    21:09:08.0270 10232 DigiRefresh - ok
    21:09:08.0302 10232 [ 02983523825AEC64B6C50D7AFD2F694E ] digiSPTIService C:\Program Files (x86)\Digidesign\Pro Tools\digiSPTIService.exe
    21:09:08.0305 10232 digiSPTIService - ok
    21:09:08.0339 10232 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
    21:09:08.0341 10232 discache - ok
    21:09:08.0375 10232 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
    21:09:08.0376 10232 Disk - ok
    21:09:08.0403 10232 [ 85CF424C74A1D5EC33533E1DBFF9920A ] Dnscache C:\Windows\System32\dnsrslvr.dll
    21:09:08.0407 10232 Dnscache - ok
    21:09:08.0426 10232 [ 14452ACDB09B70964C8C21BF80A13ACB ] dot3svc C:\Windows\System32\dot3svc.dll
    21:09:08.0431 10232 dot3svc - ok
    21:09:08.0441 10232 [ 8C2BA6BEA949EE6E68385F5692BAFB94 ] DPS C:\Windows\system32\dps.dll
    21:09:08.0445 10232 DPS - ok
    21:09:08.0490 10232 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    21:09:08.0492 10232 drmkaud - ok
    21:09:08.0536 10232 [ 46571ED73AE84469DCA53081D33CF3C8 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
    21:09:08.0541 10232 dtsoftbus01 - ok
    21:09:08.0564 10232 [ 1633B9ABF52784A1331476397A48CBEF ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    21:09:08.0630 10232 DXGKrnl - ok
    21:09:08.0662 10232 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
    21:09:08.0665 10232 EapHost - ok
    21:09:08.0753 10232 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
    21:09:08.0844 10232 ebdrv - ok
    21:09:08.0882 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] EFS C:\Windows\System32\lsass.exe
    21:09:08.0884 10232 EFS - ok
    21:09:08.0945 10232 [ 47C071994C3F649F23D9CD075AC9304A ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    21:09:08.0955 10232 ehRecvr - ok
    21:09:08.0979 10232 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
    21:09:08.0981 10232 ehSched - ok
    21:09:09.0010 10232 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
    21:09:09.0019 10232 elxstor - ok
    21:09:09.0032 10232 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
    21:09:09.0034 10232 ErrDev - ok
    21:09:09.0067 10232 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
    21:09:09.0073 10232 EventSystem - ok
    21:09:09.0097 10232 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
    21:09:09.0100 10232 exfat - ok
    21:09:09.0118 10232 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
    21:09:09.0122 10232 fastfat - ok
    21:09:09.0143 10232 [ D607B2F1BEE3992AA6C2C92C0A2F0855 ] Fax C:\Windows\system32\fxssvc.exe
    21:09:09.0153 10232 Fax - ok
    21:09:09.0157 10232 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
    21:09:09.0158 10232 fdc - ok
    21:09:09.0176 10232 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
    21:09:09.0177 10232 fdPHost - ok
    21:09:09.0182 10232 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
    21:09:09.0184 10232 FDResPub - ok
    21:09:09.0202 10232 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    21:09:09.0203 10232 FileInfo - ok
    21:09:09.0212 10232 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    21:09:09.0214 10232 Filetrace - ok
    21:09:09.0216 10232 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
    21:09:09.0217 10232 flpydisk - ok
    21:09:09.0236 10232 [ F7866AF72ABBAF84B1FA5AA195378C59 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    21:09:09.0239 10232 FltMgr - ok
    21:09:09.0284 10232 [ BC00505CFDA789ED3BE95D2FF38C4875 ] FontCache C:\Windows\system32\FntCache.dll
    21:09:09.0300 10232 FontCache - ok
    21:09:09.0356 10232 [ 8D89E3131C27FDD6932189CB785E1B7A ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    21:09:09.0357 10232 FontCache3.0.0.0 - ok
    21:09:09.0363 10232 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    21:09:09.0365 10232 FsDepends - ok
    21:09:09.0418 10232 [ D3E3F93D67821A2DB2B3D9FAC2DC2064 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    21:09:09.0464 10232 Fs_Rec - ok
    21:09:09.0578 10232 [ AE87BA80D0EC3B57126ED2CDC15B24ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    21:09:09.0620 10232 fvevol - ok
    21:09:09.0648 10232 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
    21:09:09.0651 10232 gagp30kx - ok
    21:09:09.0679 10232 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    21:09:09.0680 10232 GEARAspiWDM - ok
    21:09:09.0711 10232 [ FE5AB4525BC2EC68B9119A6E5D40128B ] gpsvc C:\Windows\System32\gpsvc.dll
    21:09:09.0726 10232 gpsvc - ok
    21:09:09.0774 10232 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:09:09.0776 10232 gupdate - ok
    21:09:09.0794 10232 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:09:09.0796 10232 gupdatem - ok
    21:09:09.0823 10232 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    21:09:09.0826 10232 gusvc - ok
    21:09:09.0854 10232 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    21:09:09.0856 10232 hcw85cir - ok
    21:09:09.0892 10232 [ 6410F6F415B2A5A9037224C41DA8BF12 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    21:09:09.0897 10232 HdAudAddService - ok
    21:09:09.0922 10232 [ 0A49913402747A0B67DE940FB42CBDBB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
    21:09:09.0925 10232 HDAudBus - ok
    21:09:09.0969 10232 [ B6AC71AAA2B10848F57FC49D55A651AF ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
    21:09:09.0971 10232 HECIx64 - ok
    21:09:09.0975 10232 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
    21:09:09.0977 10232 HidBatt - ok
    21:09:09.0991 10232 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
    21:09:09.0994 10232 HidBth - ok
    21:09:10.0006 10232 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
    21:09:10.0008 10232 HidIr - ok
    21:09:10.0030 10232 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
    21:09:10.0032 10232 hidserv - ok
    21:09:10.0042 10232 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    21:09:10.0044 10232 HidUsb - ok
    21:09:10.0054 10232 [ EFA58EDE58DD74388FFD04CB32681518 ] hkmsvc C:\Windows\system32\kmsvc.dll
    21:09:10.0057 10232 hkmsvc - ok
    21:09:10.0064 10232 [ 046B2673767CA626E2CFB7FDF735E9E8 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    21:09:10.0069 10232 HomeGroupListener - ok
    21:09:10.0098 10232 [ 06A7422224D9865A5613710A089987DF ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    21:09:10.0103 10232 HomeGroupProvider - ok
    21:09:10.0128 10232 [ 0886D440058F203EBA0E1825E4355914 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
    21:09:10.0130 10232 HpSAMD - ok
    21:09:10.0158 10232 [ CEE049CAC4EFA7F4E1E4AD014414A5D4 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    21:09:10.0172 10232 HTTP - ok
    21:09:10.0187 10232 [ F17766A19145F111856378DF337A5D79 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    21:09:10.0188 10232 hwpolicy - ok
    21:09:10.0213 10232 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    21:09:10.0216 10232 i8042prt - ok
    21:09:10.0242 10232 [ B75E45C564E944A2657167D197AB29DA ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    21:09:10.0248 10232 iaStorV - ok
    21:09:10.0290 10232 [ 2F2BE70D3E02B6FA877921AB9516D43C ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    21:09:10.0304 10232 idsvc - ok
    21:09:10.0323 10232 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
    21:09:10.0325 10232 iirsp - ok
    21:09:10.0363 10232 [ C5B4683680DF085B57BC53E5EF34861F ] IKEEXT C:\Windows\System32\ikeext.dll
    21:09:10.0379 10232 IKEEXT - ok
    21:09:10.0494 10232 [ 9CC645EB9697AA4F2D5A39835C80A0A2 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
    21:09:10.0613 10232 IntcAzAudAddService - ok
    21:09:10.0622 10232 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\DRIVERS\intelide.sys
    21:09:10.0623 10232 intelide - ok
    21:09:10.0655 10232 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    21:09:10.0656 10232 intelppm - ok
    21:09:10.0696 10232 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    21:09:10.0698 10232 IPBusEnum - ok
    21:09:10.0714 10232 [ 722DD294DF62483CECAAE6E094B4D695 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:09:10.0716 10232 IpFilterDriver - ok
    21:09:10.0745 10232 [ F8E058D17363EC580E4B7232778B6CB5 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    21:09:10.0752 10232 iphlpsvc - ok
    21:09:10.0756 10232 [ E2B4A4494DB7CB9B89B55CA268C337C5 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
    21:09:10.0757 10232 IPMIDRV - ok
    21:09:10.0761 10232 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    21:09:10.0763 10232 IPNAT - ok
    21:09:10.0810 10232 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
    21:09:10.0821 10232 iPod Service - ok
    21:09:10.0831 10232 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
    21:09:10.0832 10232 IRENUM - ok
    21:09:10.0840 10232 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
    21:09:10.0842 10232 isapnp - ok
    21:09:10.0864 10232 [ FA4D2557DE56D45B0A346F93564BE6E1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
    21:09:10.0868 10232 iScsiPrt - ok
    21:09:10.0883 10232 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
    21:09:10.0885 10232 kbdclass - ok
    21:09:10.0905 10232 [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
    21:09:10.0906 10232 kbdhid - ok
    21:09:10.0923 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] KeyIso C:\Windows\system32\lsass.exe
    21:09:10.0925 10232 KeyIso - ok
    21:09:10.0945 10232 [ 4F4B5FDE429416877DE7143044582EB5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    21:09:10.0947 10232 KSecDD - ok
    21:09:10.0961 10232 [ 6F40465A44ECDC1731BEFAFEC5BDD03C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    21:09:10.0963 10232 KSecPkg - ok
    21:09:10.0973 10232 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    21:09:10.0974 10232 ksthunk - ok
    21:09:11.0002 10232 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
    21:09:11.0009 10232 KtmRm - ok
    21:09:11.0037 10232 [ 81F1D04D4D0E433099365127375FD501 ] LanmanServer C:\Windows\system32\srvsvc.dll
    21:09:11.0041 10232 LanmanServer - ok
    21:09:11.0072 10232 [ 27026EAC8818E8A6C00A1CAD2F11D29A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    21:09:11.0076 10232 LanmanWorkstation - ok
    21:09:11.0110 10232 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    21:09:11.0112 10232 lltdio - ok
    21:09:11.0149 10232 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    21:09:11.0155 10232 lltdsvc - ok
    21:09:11.0169 10232 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
    21:09:11.0171 10232 lmhosts - ok
    21:09:11.0211 10232 [ CE97B09D1BA41802A6FAE3BBED3CC37B ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    21:09:11.0216 10232 LMS - ok
    21:09:11.0255 10232 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
    21:09:11.0257 10232 LSI_FC - ok
    21:09:11.0269 10232 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
    21:09:11.0271 10232 LSI_SAS - ok
    21:09:11.0280 10232 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
    21:09:11.0282 10232 LSI_SAS2 - ok
    21:09:11.0288 10232 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
    21:09:11.0291 10232 LSI_SCSI - ok
    21:09:11.0304 10232 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
    21:09:11.0306 10232 luafv - ok
    21:09:11.0352 10232 [ 066991E50A5CBBEEFB2EC6880069CDB5 ] MAUSBFASTTRACKPRO C:\Windows\system32\DRIVERS\MAudioFastTrackPro.sys
    21:09:11.0355 10232 MAUSBFASTTRACKPRO - ok
    21:09:11.0394 10232 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
    21:09:11.0395 10232 MBAMProtector - ok
    21:09:11.0451 10232 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    21:09:11.0457 10232 MBAMScheduler - ok
    21:09:11.0475 10232 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    21:09:11.0483 10232 MBAMService - ok
    21:09:11.0529 10232 [ F84C8F1000BC11E3B7B23CBD3BAFF111 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    21:09:11.0532 10232 Mcx2Svc - ok
    21:09:11.0545 10232 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
    21:09:11.0546 10232 megasas - ok
    21:09:11.0582 10232 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
    21:09:11.0587 10232 MegaSR - ok
    21:09:11.0630 10232 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
    21:09:11.0633 10232 MMCSS - ok
    21:09:11.0651 10232 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
    21:09:11.0652 10232 Modem - ok
    21:09:11.0674 10232 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    21:09:11.0675 10232 monitor - ok
    21:09:11.0692 10232 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    21:09:11.0694 10232 mouclass - ok
    21:09:11.0698 10232 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    21:09:11.0700 10232 mouhid - ok
    21:09:11.0714 10232 [ 791AF66C4D0E7C90A3646066386FB571 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    21:09:11.0716 10232 mountmgr - ok
    21:09:11.0724 10232 [ 609D1D87649ECC19796F4D76D4C15CEA ] mpio C:\Windows\system32\DRIVERS\mpio.sys
    21:09:11.0728 10232 mpio - ok
    21:09:11.0740 10232 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    21:09:11.0743 10232 mpsdrv - ok
    21:09:11.0763 10232 [ AECAB449567D1846DAD63ECE49E893E3 ] MpsSvc C:\Windows\system32\mpssvc.dll
    21:09:11.0780 10232 MpsSvc - ok
    21:09:11.0792 10232 [ 30524261BB51D96D6FCBAC20C810183C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    21:09:11.0795 10232 MRxDAV - ok
    21:09:11.0811 10232 [ 040D62A9D8AD28922632137ACDD984F2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:09:11.0813 10232 mrxsmb - ok
    21:09:11.0823 10232 [ F0067552F8F9B33D7C59403AB808A3CB ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:09:11.0827 10232 mrxsmb10 - ok
    21:09:11.0906 10232 [ 3C142D31DE9F2F193218A53FE2632051 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:09:11.0909 10232 mrxsmb20 - ok
    21:09:11.0914 10232 [ 5C37497276E3B3A5488B23A326A754B7 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
    21:09:11.0916 10232 msahci - ok
    21:09:11.0922 10232 [ 8D27B597229AED79430FB9DB3BCBFBD0 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
    21:09:11.0926 10232 msdsm - ok
    21:09:11.0943 10232 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
    21:09:11.0946 10232 MSDTC - ok
    21:09:11.0961 10232 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    21:09:11.0961 10232 Msfs - ok
    21:09:11.0979 10232 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    21:09:11.0980 10232 mshidkmdf - ok
    21:09:11.0987 10232 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
    21:09:11.0988 10232 msisadrv - ok
    21:09:12.0015 10232 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    21:09:12.0018 10232 MSiSCSI - ok
    21:09:12.0022 10232 msiserver - ok
    21:09:12.0067 10232 [ 192476C10371DC83243D67432B2CDCBF ] MSI_MSIBIOS_010507 C:\Program Files (x86)\MSI\Live Update 5\msibios64_100507.sys
    21:09:12.0069 10232 MSI_MSIBIOS_010507 - ok
    21:09:12.0105 10232 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    21:09:12.0107 10232 MSKSSRV - ok
    21:09:12.0122 10232 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    21:09:12.0125 10232 MSPCLOCK - ok
    21:09:12.0129 10232 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    21:09:12.0130 10232 MSPQM - ok
    21:09:12.0139 10232 [ 89CB141AA8616D8C6A4610FA26C60964 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    21:09:12.0143 10232 MsRPC - ok
    21:09:12.0160 10232 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
    21:09:12.0161 10232 mssmbios - ok
    21:09:12.0171 10232 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    21:09:12.0172 10232 MSTEE - ok
    21:09:12.0176 10232 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
    21:09:12.0177 10232 MTConfig - ok
    21:09:12.0189 10232 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
    21:09:12.0190 10232 Mup - ok
    21:09:12.0226 10232 [ 4987E079A4530FA737A128BE54B63B12 ] napagent C:\Windows\system32\qagentRT.dll
    21:09:12.0233 10232 napagent - ok
    21:09:12.0269 10232 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    21:09:12.0274 10232 NativeWifiP - ok
    21:09:12.0300 10232 [ CAD515DBD07D082BB317D9928CE8962C ] NDIS C:\Windows\system32\drivers\ndis.sys
    21:09:12.0311 10232 NDIS - ok
    21:09:12.0328 10232 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    21:09:12.0330 10232 NdisCap - ok
    21:09:12.0354 10232 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    21:09:12.0355 10232 NdisTapi - ok
    21:09:12.0362 10232 [ F105BA1E22BF1F2EE8F005D4305E4BEC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    21:09:12.0364 10232 Ndisuio - ok
    21:09:12.0369 10232 [ 557DFAB9CA1FCB036AC77564C010DAD3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    21:09:12.0372 10232 NdisWan - ok
    21:09:12.0379 10232 [ 659B74FB74B86228D6338D643CD3E3CF ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    21:09:12.0381 10232 NDProxy - ok
    21:09:12.0395 10232 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    21:09:12.0396 10232 NetBIOS - ok
    21:09:12.0413 10232 [ 9162B273A44AB9DCE5B44362731D062A ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    21:09:12.0417 10232 NetBT - ok
    21:09:12.0440 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] Netlogon C:\Windows\system32\lsass.exe
    21:09:12.0442 10232 Netlogon - ok
    21:09:12.0469 10232 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
    21:09:12.0478 10232 Netman - ok
    21:09:12.0494 10232 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
    21:09:12.0501 10232 netprofm - ok
    21:09:12.0527 10232 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    21:09:12.0529 10232 NetTcpPortSharing - ok
    21:09:12.0550 10232 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
    21:09:12.0552 10232 nfrd960 - ok
    21:09:12.0561 10232 [ D9A0CE66046D6EFA0C61BAA885CBA0A8 ] NlaSvc C:\Windows\System32\nlasvc.dll
    21:09:12.0566 10232 NlaSvc - ok
    21:09:12.0609 10232 [ C31FA031335EFF434B2D94278E74BCCE ] NPF C:\Windows\system32\DRIVERS\npf.sys
    21:09:12.0611 10232 NPF - ok
    21:09:12.0629 10232 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    21:09:12.0630 10232 Npfs - ok
    21:09:12.0644 10232 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
    21:09:12.0647 10232 nsi - ok
    21:09:12.0653 10232 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    21:09:12.0654 10232 nsiproxy - ok
    21:09:12.0701 10232 [ 184C189D4FC416978550FC599BB4EDDA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    21:09:12.0727 10232 Ntfs - ok
    21:09:12.0772 10232 [ 1B32C54B95121AB1683C7B83B2DB4B96 ] NTIOLib_1_0_4 C:\Program Files (x86)\MSI\Live Update 5\NTIOLib_X64.sys
    21:09:12.0773 10232 NTIOLib_1_0_4 - ok
    21:09:12.0828 10232 [ C02F70960FA934B8DEFA16A03D7F6556 ] NTIOLib_1_0_6 C:\Program Files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys
    21:09:12.0829 10232 NTIOLib_1_0_6 - ok
    21:09:12.0847 10232 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
    21:09:12.0848 10232 Null - ok
    21:09:12.0892 10232 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
    21:09:12.0895 10232 NVHDA - ok
    21:09:13.0104 10232 [ BF7A24A71E1932200D864BC1CE15E596 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
    21:09:13.0310 10232 nvlddmkm - ok
    21:09:13.0348 10232 [ A4D9C9A608A97F59307C2F2600EDC6A4 ] nvraid C:\Windows\system32\drivers\nvraid.sys
    21:09:13.0351 10232 nvraid - ok
    21:09:13.0371 10232 [ 6C1D5F70E7A6A3FD1C90D840EDC048B9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
    21:09:13.0391 10232 nvstor - ok
    21:09:13.0428 10232 [ 43F91595049DE14C4B61D1E76436164F ] nvsvc C:\Windows\system32\nvvsvc.exe
    21:09:13.0438 10232 nvsvc - ok
    21:09:13.0511 10232 [ 322B69422836F97B76F4AA59B47507BA ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    21:09:13.0536 10232 nvUpdatusService - ok
    21:09:13.0556 10232 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
    21:09:13.0559 10232 nv_agp - ok
    21:09:13.0564 10232 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
    21:09:13.0566 10232 ohci1394 - ok
    21:09:13.0589 10232 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    21:09:13.0595 10232 p2pimsvc - ok
    21:09:13.0611 10232 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
    21:09:13.0619 10232 p2psvc - ok
    21:09:13.0648 10232 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
    21:09:13.0650 10232 Parport - ok
    21:09:13.0675 10232 [ 90061B1ACFE8CCAA5345750FFE08D8B8 ] partmgr C:\Windows\system32\drivers\partmgr.sys
    21:09:13.0681 10232 partmgr - ok
    21:09:13.0695 10232 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
    21:09:13.0700 10232 PcaSvc - ok
    21:09:13.0713 10232 [ F36F6504009F2FB0DFD1B17A116AD74B ] pci C:\Windows\system32\DRIVERS\pci.sys
    21:09:13.0716 10232 pci - ok
    21:09:13.0728 10232 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\DRIVERS\pciide.sys
    21:09:13.0729 10232 pciide - ok
    21:09:13.0748 10232 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
    21:09:13.0752 10232 pcmcia - ok
    21:09:13.0762 10232 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
    21:09:13.0763 10232 pcw - ok
    21:09:13.0774 10232 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    21:09:13.0782 10232 PEAUTH - ok
    21:09:13.0851 10232 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
    21:09:13.0875 10232 PeerDistSvc - ok
    21:09:13.0934 10232 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    21:09:13.0936 10232 PerfHost - ok
    21:09:13.0987 10232 [ 557E9A86F65F0DE18C9B6751DFE9D3F1 ] pla C:\Windows\system32\pla.dll
    21:09:14.0013 10232 pla - ok
    21:09:14.0060 10232 [ 98B1721B8718164293B9701B98C52D77 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    21:09:14.0067 10232 PlugPlay - ok
    21:09:14.0083 10232 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    21:09:14.0086 10232 PNRPAutoReg - ok
    21:09:14.0105 10232 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    21:09:14.0109 10232 PNRPsvc - ok
    21:09:14.0136 10232 [ 166EB40D1F5B47E615DE3D0FFFE5F243 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    21:09:14.0143 10232 PolicyAgent - ok
    21:09:14.0171 10232 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
    21:09:14.0175 10232 Power - ok
    21:09:14.0201 10232 [ 27CC19E81BA5E3403C48302127BDA717 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    21:09:14.0203 10232 PptpMiniport - ok
    21:09:14.0220 10232 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
    21:09:14.0222 10232 Processor - ok
    21:09:14.0250 10232 [ 97293447431311C06703368AD0F6C4BE ] ProfSvc C:\Windows\system32\profsvc.dll
    21:09:14.0255 10232 ProfSvc - ok
    21:09:14.0273 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] ProtectedStorage C:\Windows\system32\lsass.exe
    21:09:14.0275 10232 ProtectedStorage - ok
    21:09:14.0289 10232 [ EE992183BD8EAEFD9973F352E587A299 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    21:09:14.0291 10232 Psched - ok
    21:09:14.0348 10232 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
    21:09:14.0379 10232 ql2300 - ok
    21:09:14.0386 10232 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
    21:09:14.0389 10232 ql40xx - ok
    21:09:14.0417 10232 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
    21:09:14.0422 10232 QWAVE - ok
    21:09:14.0434 10232 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    21:09:14.0436 10232 QWAVEdrv - ok
    21:09:14.0456 10232 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    21:09:14.0457 10232 RasAcd - ok
    21:09:14.0478 10232 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    21:09:14.0480 10232 RasAgileVpn - ok
    21:09:14.0491 10232 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
    21:09:14.0495 10232 RasAuto - ok
    21:09:14.0500 10232 [ 87A6E852A22991580D6D39ADC4790463 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:09:14.0503 10232 Rasl2tp - ok
    21:09:14.0534 10232 [ 47394ED3D16D053F5906EFE5AB51CC83 ] RasMan C:\Windows\System32\rasmans.dll
    21:09:14.0540 10232 RasMan - ok
    21:09:14.0550 10232 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    21:09:14.0553 10232 RasPppoe - ok
    21:09:14.0559 10232 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    21:09:14.0562 10232 RasSstp - ok
    21:09:14.0570 10232 [ 3BAC8142102C15D59A87757C1D41DCE5 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    21:09:14.0579 10232 rdbss - ok
    21:09:14.0586 10232 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
    21:09:14.0588 10232 rdpbus - ok
    21:09:14.0608 10232 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:09:14.0609 10232 RDPCDD - ok
    21:09:14.0654 10232 [ 9706B84DBABFC4B4CA46C5A82B14DFA3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
    21:09:14.0676 10232 RDPDR - ok
    21:09:14.0716 10232 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    21:09:14.0733 10232 RDPENCDD - ok
    21:09:14.0763 10232 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
    21:09:14.0765 10232 RDPREFMP - ok
    21:09:14.0794 10232 [ 447DE7E3DEA39D422C1504F245B668B1 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    21:09:14.0798 10232 RDPWD - ok
    21:09:14.0816 10232 [ 634B9A2181D98F15941236886164EC8B ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    21:09:14.0819 10232 rdyboost - ok
    21:09:14.0840 10232 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
    21:09:14.0843 10232 RemoteAccess - ok
    21:09:14.0870 10232 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    21:09:14.0874 10232 RemoteRegistry - ok
    21:09:14.0883 10232 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    21:09:14.0887 10232 RpcEptMapper - ok
    21:09:14.0912 10232 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
    21:09:14.0914 10232 RpcLocator - ok
    21:09:14.0931 10232 [ 7266972E86890E2B30C0C322E906B027 ] RpcSs C:\Windows\system32\rpcss.dll
    21:09:14.0937 10232 RpcSs - ok
    21:09:14.0942 10232 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    21:09:14.0945 10232 rspndr - ok
    21:09:14.0988 10232 [ 39A719875F572241C585A629EE62EB14 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
    21:09:15.0003 10232 RTL8167 - ok
    21:09:15.0028 10232 [ 88AF6E02AB19DF7FD07ECDF9C91E9AF6 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
    21:09:15.0030 10232 s3cap - ok
    21:09:15.0040 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] SamSs C:\Windows\system32\lsass.exe
    21:09:15.0042 10232 SamSs - ok
    21:09:15.0047 10232 [ E3BBB89983DAF5622C1D50CF49F28227 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
    21:09:15.0049 10232 sbp2port - ok
    21:09:15.0064 10232 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
    21:09:15.0069 10232 SCardSvr - ok
    21:09:15.0078 10232 [ C94DA20C7E3BA1DCA269BC8460D98387 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    21:09:15.0080 10232 scfilter - ok
    21:09:15.0202 10232 [ 624D0F5FF99428BB90A5B8A4123E918E ] Schedule C:\Windows\system32\schedsvc.dll
    21:09:15.0226 10232 Schedule - ok
    21:09:15.0246 10232 [ 6011CDF54BB6F4C69F38FACCDAD73D7E ] SCMNdisP C:\Windows\system32\DRIVERS\scmndisp.sys
    21:09:15.0247 10232 SCMNdisP - ok
    21:09:15.0276 10232 [ 312E2F82AF11E79906898AC3E3D58A1F ] SCPolicySvc C:\Windows\System32\certprop.dll
    21:09:15.0276 10232 SCPolicySvc - ok
    21:09:15.0287 10232 [ 765A27C3279CE11D14CB9E4F5869FCA5 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    21:09:15.0290 10232 SDRSVC - ok
    21:09:15.0323 10232 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    21:09:15.0325 10232 secdrv - ok
    21:09:15.0338 10232 [ 463B386EBC70F98DA5DFF85F7E654346 ] seclogon C:\Windows\system32\seclogon.dll
    21:09:15.0341 10232 seclogon - ok
    21:09:15.0350 10232 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
    21:09:15.0353 10232 SENS - ok
    21:09:15.0358 10232 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
    21:09:15.0362 10232 SensrSvc - ok
    21:09:15.0373 10232 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
    21:09:15.0374 10232 Serenum - ok
    21:09:15.0392 10232 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
    21:09:15.0394 10232 Serial - ok
    21:09:15.0409 10232 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
    21:09:15.0410 10232 sermouse - ok
    21:09:15.0427 10232 [ C3BC61CE47FF6F4E88AB8A3B429A36AF ] SessionEnv C:\Windows\system32\sessenv.dll
    21:09:15.0430 10232 SessionEnv - ok
    21:09:15.0433 10232 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
    21:09:15.0435 10232 sffdisk - ok
    21:09:15.0438 10232 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
    21:09:15.0440 10232 sffp_mmc - ok
    21:09:15.0442 10232 [ 5588B8C6193EB1522490C122EB94DFFA ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
    21:09:15.0443 10232 sffp_sd - ok
    21:09:15.0446 10232 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
    21:09:15.0447 10232 sfloppy - ok
    21:09:15.0465 10232 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
    21:09:15.0469 10232 SharedAccess - ok
    21:09:15.0487 10232 [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    21:09:15.0492 10232 ShellHWDetection - ok
    21:09:15.0512 10232 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
    21:09:15.0514 10232 SiSRaid2 - ok
    21:09:15.0518 10232 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
    21:09:15.0520 10232 SiSRaid4 - ok
    21:09:15.0523 10232 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    21:09:15.0525 10232 Smb - ok
    21:09:15.0553 10232 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    21:09:15.0555 10232 SNMPTRAP - ok
    21:09:15.0568 10232 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
    21:09:15.0568 10232 spldr - ok
    21:09:15.0595 10232 [ 567977DC43CC13C4C35ED7084C0B84D5 ] Spooler C:\Windows\System32\spoolsv.exe
    21:09:15.0606 10232 Spooler - ok
    21:09:15.0681 10232 [ 913D843498553A1BC8F8DBAD6358E49F ] sppsvc C:\Windows\system32\sppsvc.exe
    21:09:15.0747 10232 sppsvc - ok
    21:09:15.0766 10232 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
    21:09:15.0769 10232 sppuinotify - ok
    21:09:15.0798 10232 [ 2408C0366D96BCDF63E8F1C78E4A29C5 ] srv C:\Windows\system32\DRIVERS\srv.sys
    21:09:15.0805 10232 srv - ok
    21:09:15.0822 10232 [ 76548F7B818881B47D8D1AE1BE9C11F8 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    21:09:15.0828 10232 srv2 - ok
    21:09:15.0842 10232 [ 0AF6E19D39C70844C5CAA8FB0183C36E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    21:09:15.0845 10232 srvnet - ok
    21:09:15.0863 10232 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    21:09:15.0868 10232 SSDPSRV - ok
    21:09:15.0876 10232 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
    21:09:15.0880 10232 SstpSvc - ok
    21:09:15.0914 10232 Steam Client Service - ok
    21:09:15.0956 10232 [ A766CCAD980235FF34E7F8089D3175A3 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    21:09:15.0963 10232 Stereo Service - ok
    21:09:15.0984 10232 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
    21:09:15.0986 10232 stexstor - ok
    21:09:16.0018 10232 [ 52D0E33B681BD0F33FDC08812FEE4F7D ] stisvc C:\Windows\System32\wiaservc.dll
    21:09:16.0028 10232 stisvc - ok
    21:09:16.0048 10232 [ FFD7A6F15B14234B5B0E5D49E7961895 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
    21:09:16.0049 10232 storflt - ok
    21:09:16.0060 10232 [ 8FCCBEFC5C440B3C23454656E551B09A ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
    21:09:16.0062 10232 storvsc - ok
    21:09:16.0075 10232 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
    21:09:16.0077 10232 swenum - ok
    21:09:16.0092 10232 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
    21:09:16.0101 10232 swprv - ok
    21:09:16.0142 10232 [ 3C1284516A62078FB68F768DE4F1A7BE ] SysMain C:\Windows\system32\sysmain.dll
    21:09:16.0176 10232 SysMain - ok
    21:09:16.0191 10232 [ 238935C3CF2854886DC7CBB2A0E2CC66 ] TabletInputService C:\Windows\System32\TabSvc.dll
    21:09:16.0194 10232 TabletInputService - ok
    21:09:16.0208 10232 [ 884264AC597B690C5707C89723BB8E7B ] TapiSrv C:\Windows\System32\tapisrv.dll
    21:09:16.0214 10232 TapiSrv - ok
    21:09:16.0223 10232 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
    21:09:16.0225 10232 TBS - ok
    21:09:16.0270 10232 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    21:09:16.0304 10232 Tcpip - ok
    21:09:16.0341 10232 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    21:09:16.0351 10232 TCPIP6 - ok
    21:09:16.0378 10232 [ 76D078AF6F587B162D50210F761EB9ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    21:09:16.0379 10232 tcpipreg - ok
    21:09:16.0397 10232 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    21:09:16.0399 10232 TDPIPE - ok
    21:09:16.0426 10232 [ 7518F7BCFD4B308ABC9192BACAF6C970 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    21:09:16.0427 10232 TDTCP - ok
    21:09:16.0455 10232 [ 079125C4B17B01FCAEEBCE0BCB290C0F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    21:09:16.0458 10232 tdx - ok
    21:09:16.0474 10232 [ C448651339196C0E869A355171875522 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
    21:09:16.0477 10232 TermDD - ok
    21:09:16.0508 10232 [ 0F05EC2887BFE197AD82A13287D2F404 ] TermService C:\Windows\System32\termsrv.dll
    21:09:16.0523 10232 TermService - ok
    21:09:16.0541 10232 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
    21:09:16.0544 10232 Themes - ok
    21:09:16.0556 10232 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
    21:09:16.0558 10232 THREADORDER - ok
    21:09:16.0592 10232 [ 2E595C44B1C1160070B1530EDF6DE098 ] Tpkd C:\Windows\system32\drivers\Tpkd.sys
    21:09:16.0594 10232 Tpkd - ok
    21:09:16.0605 10232 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
    21:09:16.0609 10232 TrkWks - ok
    21:09:16.0662 10232 [ 840F7FB849F5887A49BA18C13B2DA920 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    21:09:16.0666 10232 TrustedInstaller - ok
    21:09:16.0685 10232 [ 61B96C26131E37B24E93327A0BD1FB95 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:09:16.0686 10232 tssecsrv - ok
    21:09:16.0715 10232 [ 3836171A2CDF3AF8EF10856DB9835A70 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    21:09:16.0718 10232 tunnel - ok
    21:09:16.0737 10232 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
    21:09:16.0739 10232 uagp35 - ok
    21:09:16.0747 10232 [ D47BAEAD86C65D4F4069D7CE0A4EDCEB ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    21:09:16.0752 10232 udfs - ok
    21:09:16.0770 10232 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
    21:09:16.0772 10232 UI0Detect - ok
    21:09:16.0775 10232 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
    21:09:16.0777 10232 uliagpkx - ok
    21:09:16.0805 10232 [ EAB6C35E62B1B0DB0D1B48B671D3A117 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    21:09:16.0806 10232 umbus - ok
    21:09:16.0820 10232 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
    21:09:16.0821 10232 UmPass - ok
    21:09:16.0840 10232 [ AF0AC98EE5077EB844413EB54287FDE3 ] UmRdpService C:\Windows\System32\umrdp.dll
    21:09:16.0844 10232 UmRdpService - ok
    21:09:16.0914 10232 [ C6C3B5AB7D807C1A97B1E95FED1AB90D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    21:09:16.0991 10232 UNS - ok
    21:09:17.0164 10232 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
    21:09:17.0201 10232 upnphost - ok
    21:09:17.0238 10232 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
    21:09:17.0240 10232 USBAAPL64 - ok
    21:09:17.0266 10232 [ 77B01BC848298223A95D4EC23E1785A1 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
    21:09:17.0269 10232 usbaudio - ok
    21:09:17.0292 10232 [ 7B6A127C93EE590E4D79A5F2A76FE46F ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
    21:09:17.0294 10232 usbccgp - ok
    21:09:17.0324 10232 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
    21:09:17.0327 10232 usbcir - ok
    21:09:17.0342 10232 [ 92969BA5AC44E229C55A332864F79677 ] usbehci C:\Windows\system32\drivers\usbehci.sys
    21:09:17.0344 10232 usbehci - ok
    21:09:17.0364 10232 [ E7DF1CFD28CA86B35EF5ADD0735CEEF3 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
    21:09:17.0370 10232 usbhub - ok
    21:09:17.0382 10232 [ F1BB1E55F1E7A65C5839CCC7B36D773E ] usbohci C:\Windows\system32\drivers\usbohci.sys
    21:09:17.0383 10232 usbohci - ok
    21:09:17.0394 10232 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
    21:09:17.0396 10232 usbprint - ok
    21:09:17.0412 10232 [ F39983647BC1F3E6100778DDFE9DCE29 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
    21:09:17.0415 10232 USBSTOR - ok
    21:09:17.0425 10232 [ BC3070350A491D84B518D7CCA9ABD36F ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
    21:09:17.0427 10232 usbuhci - ok
    21:09:17.0449 10232 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
    21:09:17.0452 10232 UxSms - ok
    21:09:17.0482 10232 [ 156F6159457D0AA7E59B62681B56EB90 ] VaultSvc C:\Windows\system32\lsass.exe
    21:09:17.0484 10232 VaultSvc - ok
    21:09:17.0505 10232 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
    21:09:17.0506 10232 vdrvroot - ok
    21:09:17.0527 10232 [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds C:\Windows\System32\vds.exe
    21:09:17.0537 10232 vds - ok
    21:09:17.0542 10232 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    21:09:17.0543 10232 vga - ok
    21:09:17.0552 10232 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
    21:09:17.0554 10232 VgaSave - ok
    21:09:17.0560 10232 [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
    21:09:17.0565 10232 vhdmp - ok
    21:09:17.0578 10232 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
    21:09:17.0579 10232 viaide - ok
    21:09:17.0611 10232 [ 1501699D7EDA984ABC4155A7DA5738D1 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
    21:09:17.0615 10232 vmbus - ok
    21:09:17.0620 10232 [ AE10C35761889E65A6F7176937C5592C ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
    21:09:17.0622 10232 VMBusHID - ok
    21:09:17.0636 10232 [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
    21:09:17.0638 10232 volmgr - ok
    21:09:17.0657 10232 [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    21:09:17.0662 10232 volmgrx - ok
    21:09:17.0670 10232 [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
    21:09:17.0674 10232 volsnap - ok
    21:09:17.0689 10232 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
    21:09:17.0692 10232 vsmraid - ok
    21:09:17.0749 10232 [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS C:\Windows\system32\vssvc.exe
    21:09:17.0783 10232 VSS - ok
    21:09:17.0837 10232 [ 40DBA03782BCC10685A8C200C5EBDCD0 ] vToolbarUpdater12.2.6 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe
    21:09:17.0847 10232 vToolbarUpdater12.2.6 - ok
    21:09:17.0863 10232 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
    21:09:17.0865 10232 vwifibus - ok
    21:09:17.0898 10232 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    21:09:17.0900 10232 vwififlt - ok
    21:09:17.0912 10232 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
    21:09:17.0918 10232 W32Time - ok
    21:09:17.0937 10232 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
    21:09:17.0938 10232 WacomPen - ok
    21:09:17.0959 10232 [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
    21:09:17.0961 10232 WANARP - ok
    21:09:17.0964 10232 [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    21:09:17.0965 10232 Wanarpv6 - ok
    21:09:18.0021 10232 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
    21:09:18.0047 10232 WatAdminSvc - ok
    21:09:18.0082 10232 [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine C:\Windows\system32\wbengine.exe
    21:09:18.0108 10232 wbengine - ok
    21:09:18.0137 10232 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    21:09:18.0143 10232 WbioSrvc - ok
    21:09:18.0171 10232 [ DD1BAE8EBFC653824D29CCF8C9054D68 ] wcncsvc C:\Windows\System32\wcncsvc.dll
    21:09:18.0179 10232 wcncsvc - ok
    21:09:18.0195 10232 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    21:09:18.0199 10232 WcsPlugInService - ok
    21:09:18.0228 10232 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
    21:09:18.0230 10232 Wd - ok
    21:09:18.0251 10232 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    21:09:18.0260 10232 Wdf01000 - ok
    21:09:18.0272 10232 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
    21:09:18.0276 10232 WdiServiceHost - ok
    21:09:18.0281 10232 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
    21:09:18.0284 10232 WdiSystemHost - ok
    21:09:18.0306 10232 [ 733006127F235BE7C35354EBEE7B9A7B ] WebClient C:\Windows\System32\webclnt.dll
    21:09:18.0312 10232 WebClient - ok
    21:09:18.0328 10232 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
    21:09:18.0334 10232 Wecsvc - ok
    21:09:18.0351 10232 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    21:09:18.0355 10232 wercplsupport - ok
    21:09:18.0374 10232 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
    21:09:18.0377 10232 WerSvc - ok
    21:09:18.0403 10232 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
    21:09:18.0405 10232 WfpLwf - ok
    21:09:18.0420 10232 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    21:09:18.0422 10232 WIMMount - ok
    21:09:18.0440 10232 WinDefend - ok
    21:09:18.0446 10232 WinHttpAutoProxySvc - ok
    21:09:18.0487 10232 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    21:09:18.0491 10232 Winmgmt - ok
    21:09:18.0535 10232 [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM C:\Windows\system32\WsmSvc.dll
    21:09:18.0578 10232 WinRM - ok
    21:09:18.0643 10232 [ 817EAFF5D38674EDD7713B9DFB8E9791 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
    21:09:18.0645 10232 WinUsb - ok
    21:09:18.0674 10232 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
    21:09:18.0699 10232 Wlansvc - ok
    21:09:18.0721 10232 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
    21:09:18.0723 10232 WmiAcpi - ok
    21:09:18.0738 10232 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    21:09:18.0742 10232 wmiApSrv - ok
    21:09:18.0769 10232 WMPNetworkSvc - ok
    21:09:18.0780 10232 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
    21:09:18.0784 10232 WPCSvc - ok
    21:09:18.0802 10232 [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    21:09:18.0807 10232 WPDBusEnum - ok
    21:09:18.0829 10232 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    21:09:18.0831 10232 ws2ifsl - ok
    21:09:18.0858 10232 [ 8F9F3969933C02DA96EB0F84576DB43E ] wscsvc C:\Windows\System32\wscsvc.dll
    21:09:18.0862 10232 wscsvc - ok
    21:09:18.0866 10232 WSearch - ok
    21:09:18.0906 10232 [ 76FBEFAB6677AF9C498116F1AAEA8BDB ] WSWNA3100 C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
    21:09:18.0910 10232 WSWNA3100 - ok
    21:09:18.0976 10232 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    21:09:19.0028 10232 wuauserv - ok
    21:09:19.0041 10232 [ 7CADC74271DD6461C452C271B30BD378 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    21:09:19.0043 10232 WudfPf - ok
    21:09:19.0065 10232 [ 3B197AF0FFF08AA66B6B2241CA538D64 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:09:19.0068 10232 WUDFRd - ok
    21:09:19.0089 10232 [ B551D6637AA0E132C18AC6E504F7B79B ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    21:09:19.0092 10232 wudfsvc - ok
    21:09:19.0104 10232 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
    21:09:19.0109 10232 WwanSvc - ok
    21:09:19.0125 10232 ================ Scan global ===============================
    21:09:19.0146 10232 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
    21:09:19.0174 10232 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
    21:09:19.0185 10232 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
    21:09:19.0207 10232 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
    21:09:19.0242 10232 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
    21:09:19.0249 10232 [Global] - ok
    21:09:19.0249 10232 ================ Scan MBR ==================================
    21:09:19.0262 10232 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    21:09:19.0472 10232 \Device\Harddisk0\DR0 - ok
    21:09:19.0763 10232 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
    21:09:20.0099 10232 \Device\Harddisk1\DR1 - ok
    21:09:20.0100 10232 ================ Scan VBR ==================================
    21:09:20.0101 10232 [ 79DBB7460805E75DBF13C51AD6D89C59 ] \Device\Harddisk0\DR0\Partition1
    21:09:20.0102 10232 \Device\Harddisk0\DR0\Partition1 - ok
    21:09:20.0104 10232 [ 04E21CFA27C4E855075D4E17F3343397 ] \Device\Harddisk1\DR1\Partition1
    21:09:20.0107 10232 \Device\Harddisk1\DR1\Partition1 - ok
    21:09:20.0107 10232 ============================================================
    21:09:20.0107 10232 Scan finished
    21:09:20.0107 10232 ============================================================
    21:09:20.0113 9312 Detected object count: 0
    21:09:20.0113 9312 Actual detected object count: 0
     
  7. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,889
    Delete any existing version of ComboFix you have sitting on your desktop
    Please read and follow all these instructions very carefully
    Do not edit or remove any information or user names etc, otherwise we cannot fix the problem. If you insist on editing out anything then I will close the topic & refuse to offer any help.

    Download ComboFix from Hereto your Desktop.
    As you download it rename it to username123.exe


    **Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer**
    --------------------------------------------------------------------
    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    • Very Important! Temporarily disable your anti-virus and anti-malware real-time protection and any script blocking components of them or your firewall before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results" or stop combofix running at all
    • Click on THIS LINK to see instructions on how to temporarily disable many security programs while running combofix. The list does not cover every program. If yours is not listed and you don't know how to disable it, please ask.
    • Remember to re enable the protection again after combofix has finished
    --------------------------------------------------------------------
    2. Close any open browsers and any other programs you might have running
    Double click on renamed combofix.exe & follow the prompts.​
    If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?"
    Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
    When finished, it will produce a report for you.
    Please post the "C:\ComboFix.txt" for further review


    ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

    Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
    Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.Read HERE why we disable autoruns

    Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version.

    Please tell us if it has cured the problems or if there are any outstanding issues

    *EXTRA NOTES*
    • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
    • If Combofix reboot is due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
    • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

    Post the log in next reply please...
     
  8. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    ComboFix 12-10-15.01 - julius 2012-10-15 23:20:32.1.4 - x64
    Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1053.18.3959.2369 [GMT 2:00]
    Körs från: c:\users\julius\Desktop\username123.exe
    AV: AVG Internet Security 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
    FW: AVG Internet Security 2013 *Disabled* {36AFA1E1-4CDC-7EF8-11EE-C77C3581ABA2}
    SP: AVG Internet Security 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\SysWow64\FlashPlayerInstaller.exe
    c:\windows\SysWow64\Packet.dll
    c:\windows\SysWow64\pthreadVC.dll
    c:\windows\SysWow64\wpcap.dll
    F:\Autorun.inf
    F:\Setup.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivrutiner/Tjänster )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_Adobe Licensing Console
    -------\Service_NPF
    -------\Service_nvsvc
    .
    .
    (((((((((((((((((((((((( Filer skapade från 2012-09-15 till 2012-10-15 ))))))))))))))))))))))))))))))
    .
    .
    2012-10-15 18:05 . 2012-10-15 18:05 -------- d-----w- C:\MGADiagToolOutput
    2012-10-15 12:31 . 2012-10-15 12:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-10-15 12:31 . 2012-09-07 15:04 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-10-14 14:24 . 2012-10-14 14:25 -------- d-----w- c:\program files (x86)\eLicenser
    2012-10-14 14:24 . 2012-10-14 14:24 -------- d-----w- c:\program files (x86)\Syncrosoft
    2012-10-14 14:24 . 2012-05-02 13:33 1713152 ----a-w- c:\windows\system32\synsoacc.dll
    2012-10-14 14:24 . 2012-05-02 13:33 1277952 ----a-w- c:\windows\SysWow64\SYNSOACC.dll
    2012-10-14 14:24 . 2011-12-14 19:21 86016 ----a-w- c:\windows\SysWow64\SYNSOPOS.exe
    2012-10-14 13:47 . 2012-10-14 13:47 -------- d-----w- c:\program files (x86)\Common Files\reFX
    2012-10-14 13:41 . 2010-01-16 21:27 2440704 ----a-w- c:\windows\SysWow64\SYNSOEMU.DLL
    2012-10-13 20:25 . 2012-10-13 20:25 -------- d-----w- c:\program files (x86)\Ableton
    2012-10-13 19:48 . 2012-10-14 13:50 -------- d-----w- c:\program files (x86)\VstPlugins
    2012-10-13 19:48 . 2009-09-15 09:14 1554944 ----a-w- c:\windows\SysWow64\vorbis.acm
    2012-10-13 19:48 . 2012-10-13 19:48 -------- d-----w- c:\program files (x86)\Outsim
    2012-10-13 19:45 . 2012-10-13 19:48 -------- d-----w- c:\program files (x86)\Image-Line
    2012-10-13 19:45 . 2012-10-13 19:45 905070 ----a-w- c:\windows\SysWow64\lnsecsl.exe
    2012-10-13 12:00 . 2012-10-13 12:00 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
    2012-10-13 00:44 . 2012-10-13 00:44 -------- dc----w- c:\windows\system32\DRVSTORE
    2012-10-13 00:44 . 2012-08-21 11:01 33240 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2012-10-13 00:43 . 2012-10-13 00:44 -------- d-----w- c:\program files\iTunes
    2012-10-13 00:43 . 2012-10-13 00:44 -------- d-----w- c:\program files (x86)\iTunes
    2012-10-13 00:43 . 2012-10-13 00:43 -------- d-----w- c:\program files\iPod
    2012-10-13 00:42 . 2012-10-13 00:42 -------- d-----w- c:\program files (x86)\Apple Software Update
    2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files\Common Files\Apple
    2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files\Bonjour
    2012-10-13 00:41 . 2012-10-13 00:41 -------- d-----w- c:\program files (x86)\Bonjour
    2012-10-13 00:40 . 2012-10-13 00:43 -------- d-----w- c:\program files (x86)\Common Files\Apple
    2012-10-11 16:36 . 2012-10-11 16:36 -------- d-----w- c:\program files (x86)\Bethesda Softworks
    2012-10-10 17:30 . 2012-10-10 17:30 -------- d-----w- c:\program files (x86)\Common Files\Steam
    2012-10-10 15:11 . 2012-10-10 15:11 98304 ----a-w- c:\windows\system32CmdLineExt.dll
    2012-10-10 14:46 . 2012-10-10 14:46 -------- d-----w- c:\program files (x86)\Ubisoft
    2012-10-10 14:45 . 2012-10-15 21:27 -------- d-----w- c:\program files (x86)\Steam
    2012-10-10 13:28 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
    2012-10-10 13:28 . 2012-08-24 17:10 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
    2012-10-10 13:28 . 2012-09-14 19:23 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-10-10 13:28 . 2012-09-14 18:30 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2012-10-10 13:28 . 2012-08-11 00:53 714752 ----a-w- c:\windows\system32\kerberos.dll
    2012-10-10 13:28 . 2012-08-10 23:54 541184 ----a-w- c:\windows\SysWow64\kerberos.dll
    2012-10-10 13:28 . 2012-06-02 05:25 182272 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-10-10 13:28 . 2012-06-02 05:25 1462784 ----a-w- c:\windows\system32\crypt32.dll
    2012-10-10 13:28 . 2012-06-02 05:25 140288 ----a-w- c:\windows\system32\cryptnet.dll
    2012-10-10 13:28 . 2012-06-02 04:45 139264 ----a-w- c:\windows\SysWow64\cryptsvc.dll
    2012-10-10 13:28 . 2012-06-02 04:45 1157632 ----a-w- c:\windows\SysWow64\crypt32.dll
    2012-10-10 13:28 . 2012-06-02 04:45 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
    2012-10-09 20:53 . 2012-10-09 20:53 -------- d-----w- c:\program files (x86)\Common Files\Propellerhead Software
    2012-10-09 13:59 . 2012-10-09 13:59 -------- d-----w- C:\Games
    2012-10-09 13:56 . 2012-10-09 13:56 -------- d-----w- c:\program files\Nexus Mod Manager
    2012-10-09 13:45 . 2012-10-09 13:45 -------- d-----w- c:\program files (x86)\VideoLAN
    2012-10-09 12:24 . 2012-10-09 12:24 -------- d-----w- c:\program files (x86)\Microsoft.NET
    2012-10-09 12:15 . 2012-10-09 12:15 -------- d-----w- c:\windows\SysWow64\Wat
    2012-10-09 12:15 . 2012-10-09 12:15 -------- d-----w- c:\windows\system32\Wat
    2012-10-08 23:02 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
    2012-10-08 23:02 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
    2012-10-08 22:46 . 2009-09-10 06:28 311808 ----a-w- c:\windows\system32\msv1_0.dll
    2012-10-08 22:46 . 2009-09-10 05:52 257024 ----a-w- c:\windows\SysWow64\msv1_0.dll
    2012-10-08 22:32 . 2009-11-25 10:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
    2012-10-08 22:32 . 2009-11-25 10:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
    2012-10-08 22:32 . 2009-11-25 10:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
    2012-10-08 22:32 . 2009-11-25 10:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
    2012-10-08 22:32 . 2009-11-25 10:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
    2012-10-08 22:32 . 2009-11-25 10:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
    2012-10-08 22:32 . 2009-11-25 10:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2012-10-08 22:32 . 2009-11-25 10:47 444752 ----a-w- c:\windows\system32\mscoree.dll
    2012-10-08 22:32 . 2009-11-25 10:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
    2012-10-08 22:32 . 2009-11-25 10:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
    2012-10-08 22:31 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
    2012-10-08 22:18 . 2012-03-01 06:54 22896 ----a-w- c:\windows\system32\drivers\fs_rec.sys
    2012-10-08 22:18 . 2012-03-01 06:40 80896 ----a-w- c:\windows\system32\imagehlp.dll
    2012-10-08 22:18 . 2012-03-01 06:35 5120 ----a-w- c:\windows\system32\wmi.dll
    2012-10-08 22:18 . 2012-03-01 05:45 158720 ----a-w- c:\windows\SysWow64\imagehlp.dll
    2012-10-08 22:18 . 2012-03-01 05:40 5120 ----a-w- c:\windows\SysWow64\wmi.dll
    2012-10-08 22:16 . 2010-03-04 04:32 243712 ----a-w- c:\windows\system32\drivers\ks.sys
    2012-10-08 18:32 . 2012-10-08 18:32 -------- d-----w- c:\program files (x86)\Setup Files
    2012-10-08 18:30 . 2012-02-16 11:42 74344 ----a-w- c:\windows\system32\RtNicProp64.dll
    2012-10-08 18:30 . 2012-02-16 11:42 676968 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
    2012-10-08 18:09 . 2012-10-10 17:31 -------- d-----w- c:\users\UpdatusUser
    2012-10-08 18:09 . 2012-08-30 16:18 3487434 ----a-w- c:\windows\system32\nvcoproc.bin
    2012-10-08 18:09 . 2012-10-08 18:09 -------- d-----w- C:\temp
    2012-10-08 18:02 . 2010-02-04 08:01 78680 ----a-w- c:\windows\system32\XAPOFX1_4.dll
    2012-10-08 18:01 . 2007-07-19 16:14 5073256 ----a-w- c:\windows\system32\d3dx9_35.dll
    2012-10-08 17:57 . 2012-10-09 14:33 -------- d-----w- c:\program files (x86)\The Elder Scrolls V Skyrim
    2012-10-08 17:54 . 2012-05-05 08:30 503808 ----a-w- c:\windows\system32\srcore.dll
    2012-10-08 17:53 . 2011-10-26 05:22 1572864 ----a-w- c:\windows\system32\quartz.dll
    2012-10-08 17:52 . 2010-05-05 07:37 483840 ----a-w- c:\windows\system32\StructuredQuery.dll
    2012-10-08 17:51 . 2011-10-26 05:19 43520 ----a-w- c:\windows\system32\csrsrv.dll
    2012-10-08 17:50 . 2011-03-12 12:03 662528 ----a-w- c:\windows\system32\XpsPrint.dll
    2012-10-08 17:49 . 2011-02-19 06:36 46080 ----a-w- c:\windows\system32\atmlib.dll
    2012-10-08 17:48 . 2010-08-21 06:38 1024512 ----a-w- c:\windows\system32\wmpmde.dll
    2012-10-08 17:47 . 2011-08-17 05:32 613888 ----a-w- c:\windows\system32\psisdecd.dll
    2012-10-08 17:46 . 2011-02-05 12:41 556928 ----a-w- c:\windows\system32\winresume.efi
    2012-10-08 17:45 . 2011-05-24 11:21 404992 ----a-w- c:\windows\system32\umpnpmgr.dll
    2012-10-08 17:44 . 2011-10-15 06:25 723456 ----a-w- c:\windows\system32\EncDec.dll
    2012-10-08 17:44 . 2011-10-15 05:48 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
    2012-10-08 17:44 . 2012-03-30 11:09 1895280 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-10-08 17:43 . 2012-10-08 17:43 -------- d-----w- c:\program files (x86)\Common Files\PACE Anti-Piracy
    2012-10-08 17:39 . 2012-10-08 17:39 -------- d-----w- c:\program files (x86)\MSI
    2012-10-08 17:37 . 2012-04-02 05:26 1732096 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
    2012-10-08 17:37 . 2012-04-02 05:24 1367552 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
    2012-10-08 17:37 . 2012-04-02 05:24 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
    2012-10-08 17:37 . 2012-04-02 05:24 1393664 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
    2012-10-08 17:37 . 2012-04-02 04:40 936960 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
    2012-10-08 17:36 . 2012-06-06 05:50 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
    2012-10-08 17:36 . 2012-06-06 05:09 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
    2012-10-08 17:36 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
    2012-10-08 17:36 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
    2012-10-08 17:36 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
    2012-10-08 17:36 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
    2012-10-08 17:36 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
    2012-10-08 17:36 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
    2012-10-08 17:36 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
    2012-10-08 17:36 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
    2012-10-08 17:35 . 2011-11-17 07:14 1739160 ----a-w- c:\windows\system32\ntdll.dll
    2012-10-08 17:35 . 2011-11-17 05:41 1292592 ----a-w- c:\windows\SysWow64\ntdll.dll
    2012-10-08 17:35 . 2010-08-27 06:14 236032 ----a-w- c:\windows\system32\srvsvc.dll
    2012-10-08 17:35 . 2010-08-27 05:46 9728 ----a-w- c:\windows\SysWow64\sscore.dll
    2012-10-08 17:35 . 2011-11-19 15:07 77312 ----a-w- c:\windows\system32\packager.dll
    2012-10-08 17:35 . 2011-11-19 14:06 67072 ----a-w- c:\windows\SysWow64\packager.dll
    2012-10-07 21:01 . 2012-10-07 21:01 -------- d-----w- c:\program files (x86)\ASIO4ALL v2
    2012-10-07 19:52 . 2012-10-14 10:56 -------- d-----w- c:\program files (x86)\Common Files\Native Instruments
    2012-10-07 19:52 . 2012-10-07 19:52 -------- d-----w- c:\program files\Common Files\Native Instruments
    2012-10-07 19:51 . 2012-10-14 10:56 -------- d-----w- c:\program files\Native Instruments
    2012-10-07 19:49 . 2012-10-07 19:49 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
    2012-10-07 19:49 . 2012-10-07 19:49 -------- d-----w- c:\program files (x86)\DAEMON Tools Pro
    2012-10-07 19:08 . 2012-10-07 19:08 -------- d-----w- c:\program files (x86)\InterLok
    2012-10-07 19:08 . 2012-10-07 19:08 -------- d-----w- c:\windows\Downloaded Installations
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-10-08 22:28 . 2012-10-08 22:28 599040 ----a-w- c:\windows\system32\vbscript.dll
    2012-09-14 01:05 . 2012-09-14 01:05 40800 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
    2012-09-13 01:11 . 2012-09-13 01:11 151904 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
    2012-09-04 08:39 . 2011-05-22 23:03 50296 ----a-w- c:\windows\system32\drivers\avgfwd6a.sys
    2012-08-30 19:14 . 2010-07-31 14:46 2725224 ----a-w- c:\windows\system32\nvapi64.dll
    2012-08-30 19:14 . 2010-07-31 14:46 15291752 ----a-w- c:\windows\SysWow64\nvd3dum.dll
    2012-08-30 19:14 . 2010-07-31 14:46 14879080 ----a-w- c:\windows\system32\nvwgf2umx.dll
    2012-08-30 16:18 . 2010-07-31 06:52 63336 ----a-w- c:\windows\system32\nvshext.dll
    2012-08-30 16:18 . 2010-07-31 06:52 118120 ----a-w- c:\windows\system32\nvmctray.dll
    2012-08-30 16:18 . 2010-07-31 06:52 891240 ----a-w- c:\windows\system32\nvvsvc.exe
    2012-08-30 16:18 . 2010-07-31 06:52 2557800 ----a-w- c:\windows\system32\nvsvcr.dll
    2012-08-30 16:18 . 2010-07-31 06:52 3266920 ----a-w- c:\windows\system32\nvsvc64.dll
    2012-08-30 16:17 . 2010-07-31 06:52 6198120 ----a-w- c:\windows\system32\nvcpl.dll
    2012-08-30 08:40 . 2012-08-30 08:40 429416 ----a-w- c:\windows\SysWow64\nvStreaming.exe
    2012-08-21 11:01 . 2012-08-21 11:01 125872 ----a-w- c:\windows\system32\GEARAspi64.dll
    2012-08-21 11:01 . 2012-08-21 11:01 106928 ----a-w- c:\windows\SysWow64\GEARAspi.dll
    2012-08-18 11:19 . 2012-10-10 13:29 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    .
    .
    (((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Not* tomma poster & legitima standardposter visas inte.
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    2012-10-07 18:29 1734240 ----a-w- c:\program files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files (x86)\AVG Secure Search\12.2.5.34\AVG Secure Search_toolbar.dll" [2012-10-07 1734240]
    .
    [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
    [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Pro Agent"="c:\program files (x86)\DAEMON Tools Pro\DTAgent.exe" [2012-04-26 3111744]
    "Spotify Web Helper"="c:\users\julius\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-10-07 1193176]
    "Steam"="c:\program files (x86)\Steam\Steam.exe" [2012-10-10 1353080]
    "Spotify"="c:\users\julius\AppData\Roaming\Spotify\spotify.exe" [2012-10-07 5576408]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "IMSS"="c:\program files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [2010-07-01 112152]
    "AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2012-10-10 3116152]
    "vProt"="c:\program files (x86)\AVG Secure Search\vprot.exe" [2012-10-07 947808]
    "ROC_ROC_NT"="c:\program files (x86)\AVG Secure Search\ROC_ROC_NT.exe" [2012-10-07 856160]
    "DigidesignMMERefresh"="c:\program files (x86)\Digidesign\Drivers\MMERefresh.exe" [2007-10-30 77824]
    "Live Update 5"="c:\program files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe" [2012-01-30 315392]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-27 59280]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-09 421776]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    NETGEAR WNA3100 Smart Wizard.lnk - c:\program files (x86)\NETGEAR\WNA3100\WNA3100.exe [2012-10-7 4562944]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
    "aux2"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~2\AVG\AVG2013\avgrsa.exe /sync /restart
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Tjänsten Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 116648]
    R2 WSWNA3100;WSWNA3100;c:\program files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2010-01-12 278528]
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-08 250808]
    R3 gupdatem;Tjänsten Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 116648]
    R3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files (x86)\MSI\Live Update 5\msibios64_100507.sys [2010-05-10 33592]
    R3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files (x86)\MSI\Live Update 5\NTIOLib_X64.sys [2010-10-22 14136]
    R3 NTIOLib_1_0_6;NTIOLib_1_0_6;c:\program files (x86)\Setup Files\Ms7636v1A0\NTIOLib_X64.sys [2011-01-06 11888]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-07-09 52736]
    R3 WatAdminSvc;Aktiveringsteknologier för Windows-tjänst;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-08 1255736]
    S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2012-09-21 61792]
    S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2012-09-21 225120]
    S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2012-10-05 111456]
    S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2012-09-14 40800]
    S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [2007-01-19 25312]
    S1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6a.sys [2012-09-04 50296]
    S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2012-09-13 151904]
    S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2012-10-02 185696]
    S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2012-09-21 200032]
    S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys [2012-10-07 31080]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-10-07 283200]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
    S2 avgfws;AVG Firewall;c:\program files (x86)\AVG\AVG2013\avgfws.exe [2012-10-02 1314720]
    S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2012-10-02 5783672]
    S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2012-10-02 193568]
    S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-07 399432]
    S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-07 676936]
    S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2012-08-30 1258856]
    S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-08-30 382312]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-07-01 2533400]
    S2 vToolbarUpdater12.2.6;vToolbarUpdater12.2.6;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.6\ToolbarUpdater.exe [2012-10-07 722528]
    S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\DRIVERS\bcmwlhigh664.sys [2009-11-06 838136]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2009-09-17 56344]
    S3 MAUSBFASTTRACKPRO;Service for M-Audio FastTrack Pro;c:\windows\system32\DRIVERS\MAudioFastTrackPro.sys [2010-12-07 187912]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-07 25928]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2012-07-03 189288]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2012-02-16 676968]
    .
    .
    --- Övriga tjänster/drivrutiner i minnet ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Innehåll i mappen 'Schemalagda aktiviteter':
    .
    2012-10-15 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-07 20:12]
    .
    2012-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 18:22]
    .
    2012-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-10-07 18:22]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-06-11 12503184]
    "M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-12-07 798728]
    .
    ------- Extra genomsökning -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.google.com/
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    TCP: DhcpNameServer = 192.168.1.1
    Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\12.2.6\ViProtocol.dll
    .
    .
    --------------------- LÅSTA REGISTERNYCKLAR ---------------------
    .
    [HKEY_USERS\S-1-5-21-1628012227-26710139-1449845332-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    @Allowed: (Read) (RestrictedCode)
    "??"=hex:76,89,ac,2e,0a,55,98,bb,6f,e4,fa,6a,e6,87,bb,62,4f,ff,52,47,36,71,65,
    10,f2,21,b8,79,ab,2d,17,0d,8b,d5,30,78,f2,16,72,8e,b7,19,03,38,33,da,bb,33,\
    "??"=hex:ec,7f,62,96,57,2c,d6,08,cc,a5,1f,55,b4,c4,7c,48
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
    @="?????????????????? v1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
    @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
    @="?????????????????? v2"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
    @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Andra processer som körs ------------------------
    .
    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    c:\program files (x86)\DAEMON Tools Pro\DTShellHlp.exe
    c:\program files (x86)\Common Files\Steam\SteamService.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    c:\program files (x86)\Google\Chrome\Application\chrome.exe
    c:\program files (x86)\Google\Chrome\Application\chrome.exe
    c:\program files (x86)\Google\Chrome\Application\chrome.exe
    c:\program files (x86)\Google\Chrome\Application\chrome.exe
    c:\program files (x86)\Google\Chrome\Application\chrome.exe
    .
    **************************************************************************
    .
    Sluttid: 2012-10-15 23:31:01 - datorn startades om.
    ComboFix-quarantined-files.txt 2012-10-15 21:31
    .
    Före genomsökningen: 350*235*934*720 byte ledigt
    Efter genomsökningen: 349*825*175*552 byte ledigt
    .
    - - End Of File - - EED21AD83F06B355C0DC9964EF7C7F75
     
  9. dvk01

    dvk01 Derek Moderator Malware Specialist

    Joined:
    Dec 14, 2002
    Messages:
    47,889
    when do you get these sounds
    is it only in a particular browser or all the time
     
  10. bjja

    bjja Thread Starter

    Joined:
    Oct 15, 2012
    Messages:
    6
    The sounds come just randomly, even if i don't have any program active.
    It seems That the sound are gone now, gonna check bettet tomorrow
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1072744