Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malwarebytes found Trojan but can't remove it, Google not working


  • This topic is locked This topic is locked

#1
kaybli

kaybli

    Member

  • Member
  • PipPip
  • 27 posts
I was aware of some kind of malware infection after Google wasn't working properly. I downloaded and ran Malwarebytes Anti-malware which showed two trojans found but after it asked me to restart the system they were still there. Here is the OTL log file:

OTL logfile created on: 3/11/2012 8:15:45 AM - Run 1
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Users\kaybli2\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.91 Gb Total Physical Memory | 3.42 Gb Available Physical Memory | 57.87% Memory free
11.82 Gb Paging File | 9.13 Gb Available in Paging File | 77.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 682.10 Gb Total Space | 515.04 Gb Free Space | 75.51% Space Free | Partition Type: NTFS

Computer Name: KAYBLI2-PC | User Name: kaybli2 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/03/11 08:15:21 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\kaybli2\Desktop\OTL.exe
PRC - [2012/02/16 10:40:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/01/13 14:53:16 | 000,981,680 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2011/11/29 22:17:50 | 000,138,248 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccsvchst.exe
PRC - [2011/02/01 17:24:42 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/02/01 17:24:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/12/25 20:05:54 | 001,716,144 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\Toshiba\widimon\widimon.exe
PRC - [2010/08/16 14:54:50 | 000,034,160 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\Toshiba\Utilities\KeNotify.exe
PRC - [2010/05/20 20:15:00 | 000,110,736 | R--- | M] (InterVideo) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
PRC - [2010/03/11 18:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe


========== Modules (No Company Name) ==========

MOD - [2012/02/19 01:01:48 | 006,271,648 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2012/02/16 10:40:41 | 001,911,768 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/07/01 15:46:14 | 000,828,856 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:64bit: - [2011/06/14 14:31:06 | 000,498,688 | ---- | M] (Red Bend Ltd.) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe -- (DMAgent)
SRV:64bit: - [2011/06/14 14:26:20 | 000,986,112 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe -- (WiMAXAppSrv)
SRV:64bit: - [2011/06/10 01:10:00 | 000,138,152 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2011/06/01 16:38:30 | 001,517,328 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel®
SRV:64bit: - [2011/06/01 16:23:40 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2011/06/01 16:19:58 | 000,844,560 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel®
SRV:64bit: - [2011/05/24 13:58:12 | 000,294,848 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:64bit: - [2011/05/17 18:34:18 | 000,574,896 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2011/04/20 19:16:04 | 000,558,592 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\ThpSrv.exe -- (Thpsrv)
SRV:64bit: - [2010/10/20 18:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/11/29 22:17:50 | 000,138,248 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe -- (NIS)
SRV - [2011/07/11 21:16:06 | 000,057,216 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2011/02/01 17:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2011/02/01 17:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/05/20 20:15:00 | 000,110,736 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/11 18:06:06 | 000,193,824 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/20 21:51:33 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012/02/19 00:29:12 | 000,020,592 | ---- | M] (Compal Electronics, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CeKbFilter.sys -- (CeKbFilter)
DRV:64bit: - [2011/11/23 22:23:47 | 001,092,728 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symefa64.sys -- (SymEFA)
DRV:64bit: - [2011/11/23 21:50:27 | 000,738,936 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2011/11/23 21:50:27 | 000,037,496 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/11/16 23:37:59 | 000,405,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symnets.sys -- (SymNetS)
DRV:64bit: - [2011/11/16 23:17:49 | 000,190,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ironx64.sys -- (SymIRON)
DRV:64bit: - [2011/11/04 19:59:30 | 000,167,048 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\ccsetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2011/06/27 13:55:50 | 012,231,584 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/06/21 19:19:14 | 000,025,496 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:64bit: - [2011/06/21 19:19:12 | 000,034,200 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:64bit: - [2011/06/09 23:28:22 | 000,482,384 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tos_sps64.sys -- (tos_sps64)
DRV:64bit: - [2011/05/19 17:25:10 | 000,182,272 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpmp.sys -- (bpmp) Intel® Centrino®
DRV:64bit: - [2011/05/19 17:25:04 | 000,083,968 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpusb.sys -- (bpusb) Intel® Centrino®
DRV:64bit: - [2011/05/19 17:25:00 | 000,084,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bpenum.sys -- (bpenum) Intel® Centrino®
DRV:64bit: - [2011/05/16 16:03:26 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1305000.091\symds64.sys -- (SymDS)
DRV:64bit: - [2011/05/02 21:45:04 | 000,175,192 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:64bit: - [2011/05/01 18:33:06 | 008,593,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel®
DRV:64bit: - [2011/03/23 21:10:28 | 000,036,992 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\thpdrv.sys -- (Thpdrv)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/10 18:52:34 | 000,181,760 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2011/02/10 18:52:34 | 000,082,432 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2011/02/08 23:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2011/02/03 23:59:06 | 001,413,680 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/01/13 23:58:30 | 000,413,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/01/12 21:51:44 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/19 20:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/10/15 20:28:18 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2010/03/22 14:55:20 | 000,046,192 | ---- | M] (COMPAL ELECTRONIC INC.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LPCFilter.sys -- (LPCFilter)
DRV:64bit: - [2009/07/31 00:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009/07/14 19:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/29 20:16:20 | 000,014,784 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Thpevm.sys -- (Thpevm)
DRV:64bit: - [2009/06/19 23:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2007/04/17 15:51:50 | 000,014,112 | ---- | M] (InterVideo) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\regi.sys -- (regi)
DRV - [2012/03/10 03:42:26 | 002,048,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20120309.034\ex64.sys -- (NAVEX15)
DRV - [2012/03/10 03:42:26 | 000,117,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20120309.034\eng64.sys -- (NAVENG)
DRV - [2012/03/06 17:04:10 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20120309.002\IDSviA64.sys -- (IDSVia64)
DRV - [2012/03/02 14:58:01 | 001,157,240 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20120302.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2012/02/20 20:49:48 | 000,138,360 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/02/18 23:53:32 | 000,482,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}
IE:64bit: - HKLM\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNO
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}
IE - HKLM\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNO

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.toshiba.com/?cid=C001B2Y
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.toshiba.com/?cid=C001B2Y
IE - HKCU\..\SearchScopes,DefaultScope = {93AAE84D-0C7C-430F-9672-CC2EA834E129}
IE - HKCU\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNO
IE - HKCU\..\SearchScopes\{93AAE84D-0C7C-430F-9672-CC2EA834E129}: "URL" = http://www.google.co...1I7TSNO_enUS471
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"

FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFFPlgn\ [2012/02/20 21:14:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\ [2012/03/11 08:01:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/02/21 22:40:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2012/02/18 23:27:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\kaybli2\AppData\Roaming\Mozilla\Extensions
[2012/02/18 23:27:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/16 10:40:42 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/02/16 06:42:53 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/02/16 06:42:53 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.5.0.145\coieplg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelPAN] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [ThpSrv] C:\windows\SysNative\thpsrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\Utilities\HWSetup.exe (TOSHIBA Electronics, Inc.)
O4 - HKLM..\Run: [KeNotify] C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA CORPORATION)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TSleepSrv] C:\Program Files (x86)\Toshiba\TOSHIBA Sleep Utility\TSleepSrv.exe (TOSHIBA)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DD588496-A226-43AB-B83F-E5FC09D5C888}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{6fd45ad1-5da5-11e1-84b3-dc0ea13261e5}\Shell - "" = AutoRun
O33 - MountPoints2\{6fd45ad1-5da5-11e1-84b3-dc0ea13261e5}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/11 08:15:10 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Users\kaybli2\Desktop\OTL.exe
[2012/03/11 07:46:28 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Malwarebytes
[2012/03/11 07:46:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/11 07:46:13 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/03/11 07:46:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/03/11 07:46:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/03/08 21:12:58 | 001,092,728 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\symefa64.sys
[2012/03/08 21:12:58 | 000,738,936 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtsp64.sys
[2012/03/08 21:12:58 | 000,451,192 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\symds64.sys
[2012/03/08 21:12:58 | 000,405,624 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\symnets.sys
[2012/03/08 21:12:58 | 000,190,072 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\ironx64.sys
[2012/03/08 21:12:58 | 000,167,048 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\ccsetx64.sys
[2012/03/08 21:12:58 | 000,037,496 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtspx64.sys
[2012/03/08 21:12:47 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NISx64\1306010.008
[2012/03/04 23:04:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
[2012/03/04 23:04:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BurnAware Free
[2012/03/03 14:43:41 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Apple Computer
[2012/03/03 14:43:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/03/03 14:42:41 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/03/03 14:42:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012/03/03 14:42:41 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/03/03 14:42:41 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/03/03 14:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2012/03/03 14:41:48 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/03/03 14:41:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2012/03/03 14:41:39 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/02/25 01:38:48 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\vlc
[2012/02/23 06:08:48 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Adobe
[2012/02/22 18:36:12 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Apple Computer
[2012/02/21 22:40:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/02/21 22:40:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/02/21 22:40:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/02/21 22:39:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/02/21 22:39:25 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Apple
[2012/02/21 22:39:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/02/21 22:39:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/02/21 04:00:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/02/20 22:36:56 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Best Buy pc app
[2012/02/20 21:51:27 | 000,405,624 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\symnets.sys
[2012/02/20 21:51:26 | 001,092,728 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\symefa64.sys
[2012/02/20 21:51:26 | 000,738,936 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys
[2012/02/20 21:51:26 | 000,451,192 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\symds64.sys
[2012/02/20 21:51:26 | 000,190,072 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\ironx64.sys
[2012/02/20 21:51:26 | 000,167,048 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\ccsetx64.sys
[2012/02/20 21:51:26 | 000,037,496 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys
[2012/02/20 21:51:19 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NISx64\1305000.091
[2012/02/20 21:10:18 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2012/02/20 21:10:18 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2012/02/20 16:51:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/02/19 16:29:52 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\WinRAR
[2012/02/19 16:29:52 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/02/19 16:29:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/02/19 16:29:43 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012/02/19 15:51:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/02/19 15:51:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/02/19 01:17:49 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/02/19 01:03:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation
[2012/02/19 01:03:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel Corporation
[2012/02/19 01:03:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel Corporation
[2012/02/19 00:58:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TOSHIBA Corporation
[2012/02/19 00:57:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Ulead Systems
[2012/02/19 00:57:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel Label@Once
[2012/02/19 00:55:13 | 000,014,112 | ---- | C] (InterVideo) -- C:\windows\SysNative\drivers\regi.sys
[2012/02/19 00:55:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corel
[2012/02/19 00:55:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InterVideo
[2012/02/19 00:54:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Protexis
[2012/02/19 00:54:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Corel
[2012/02/19 00:54:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Corel
[2012/02/19 00:53:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Toshiba Shared
[2012/02/19 00:47:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Best Buy pc app
[2012/02/19 00:47:52 | 000,000,000 | -H-D | C] -- C:\ProgramData\{373A11D3-0B96-4E16-9184-7D0FBE86932F}
[2012/02/19 00:45:03 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/02/19 00:45:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2012/02/19 00:44:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/02/19 00:44:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012/02/19 00:43:59 | 000,175,736 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/02/19 00:43:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/02/19 00:43:59 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/02/19 00:43:41 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NISx64
[2012/02/19 00:43:40 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2012/02/19 00:43:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Internet Security
[2012/02/19 00:43:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2012/02/19 00:43:25 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2012/02/19 00:43:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NortonInstaller
[2012/02/19 00:42:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Best Buy Connect
[2012/02/19 00:41:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Best Buy Connect
[2012/02/19 00:40:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Roaming
[2012/02/19 00:40:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
[2012/02/19 00:39:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2012/02/19 00:39:59 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012/02/19 00:39:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2012/02/19 00:39:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2012/02/19 00:38:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Renesas Electronics
[2012/02/19 00:38:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Downloaded Installations
[2012/02/19 00:38:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JMicron
[2012/02/19 00:37:58 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\SDA
[2012/02/19 00:37:17 | 000,413,800 | ---- | C] (Realtek ) -- C:\windows\SysNative\drivers\Rt64win7.sys
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\tr
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\sv
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\sk
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\ru
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\pt
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\pl
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\no
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\nl
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\it
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\hu
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\fr
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\fi
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\es
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\el
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\de
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\da
[2012/02/19 00:36:24 | 000,000,000 | ---D | C] -- C:\windows\SysNative\cs
[2012/02/19 00:36:11 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012/02/19 00:32:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wave Audio Ltd
[2012/02/19 00:32:43 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\RTCOM
[2012/02/19 00:32:43 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012/02/19 00:32:28 | 002,578,576 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\WavesGUILib.dll
[2012/02/19 00:32:28 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSX64.dll
[2012/02/19 00:32:28 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSWOW64.dll
[2012/02/19 00:32:27 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioEQ.dll
[2012/02/19 00:32:27 | 001,868,944 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioRealtek.dll
[2012/02/19 00:32:27 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEP64A.dll
[2012/02/19 00:32:27 | 000,341,336 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO30.dll
[2012/02/19 00:32:27 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxVolumeSDAPO.dll
[2012/02/19 00:32:27 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO20.dll
[2012/02/19 00:32:27 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DHT64.dll
[2012/02/19 00:32:27 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DAA64.dll
[2012/02/19 00:32:27 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSH64.dll
[2012/02/19 00:32:27 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEED64A.dll
[2012/02/19 00:32:27 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSHP64.dll
[2012/02/19 00:32:27 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEL64A.dll
[2012/02/19 00:32:27 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEG64A.dll
[2012/02/19 00:32:26 | 002,075,712 | ---- | C] (Fortemedia Corporation) -- C:\windows\SysNative\FMAPO64.dll
[2012/02/19 00:32:26 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2012/02/19 00:32:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2012/02/19 00:29:18 | 000,000,000 | ---D | C] -- C:\windows\SoftwareDistribution
[2012/02/19 00:29:14 | 000,020,592 | ---- | C] (Compal Electronics, INC.) -- C:\windows\SysNative\drivers\CeKbFilter.sys
[2012/02/19 00:29:14 | 000,000,000 | ---D | C] -- C:\windows\SysNative\DRVSTORE
[2012/02/19 00:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\xp
[2012/02/19 00:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\win7_64
[2012/02/19 00:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\win7_32
[2012/02/19 00:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\vista64
[2012/02/19 00:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\vista32
[2012/02/19 00:28:50 | 000,295,936 | ---- | C] (COMPAL ELECTRONIC INC.) -- C:\windows\SysNative\HWS_Ctrl.dll
[2012/02/19 00:28:50 | 000,008,192 | ---- | C] (COMPAL ELECTRONIC INC.) -- C:\windows\SysNative\TSBWLS.dll
[2012/02/19 00:28:33 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Microsoft.VC80.MFC
[2012/02/19 00:28:22 | 000,000,000 | ---D | C] -- C:\windows\Downloaded Installations
[2012/02/19 00:26:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2012/02/19 00:26:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2012/02/19 00:23:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2012/02/19 00:23:41 | 000,000,000 | ---D | C] -- C:\Intel
[2012/02/19 00:21:51 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\windows\SysWow64\CSVer.dll
[2012/02/19 00:21:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Intel
[2012/02/19 00:03:31 | 000,000,000 | ---D | C] -- C:\rev
[2012/02/19 00:02:05 | 000,000,000 | ---D | C] -- C:\Music
[2012/02/18 23:51:00 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Desktop\Work
[2012/02/18 23:48:32 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\directx
[2012/02/18 23:46:29 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\CrashDumps
[2012/02/18 23:46:18 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Media Player Classic
[2012/02/18 23:41:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Classic - Home Cinema x64
[2012/02/18 23:41:13 | 000,000,000 | ---D | C] -- C:\Program Files\Media Player Classic - Home Cinema
[2012/02/18 23:38:48 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
[2012/02/18 23:38:46 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\IrfanView
[2012/02/18 23:38:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IrfanView
[2012/02/18 23:27:10 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Mozilla
[2012/02/18 23:27:10 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Mozilla
[2012/02/18 23:27:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/02/18 23:22:10 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Toshiba
[2012/02/18 23:21:23 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Adobe
[2012/02/18 23:21:17 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Google
[2012/02/18 23:21:15 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Google
[2012/02/18 23:20:48 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy
[2012/02/18 23:20:40 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Deployment
[2012/02/18 23:20:40 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Apps
[2012/02/18 23:20:22 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\TOSHIBA
[2012/02/18 23:20:06 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Searches
[2012/02/18 23:20:06 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/02/18 23:20:06 | 000,000,000 | -H-D | C] -- C:\Users\kaybli2\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/02/18 23:19:55 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Identities
[2012/02/18 23:19:53 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Contacts
[2012/02/18 23:19:02 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\VirtualStore
[2012/02/18 22:18:54 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\WinBatch
[2012/02/18 22:18:30 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Intel
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\AppData\Local\Temporary Internet Files
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Templates
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Start Menu
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\SendTo
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Recent
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\PrintHood
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\NetHood
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Documents\My Videos
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Documents\My Pictures
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Documents\My Music
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\My Documents
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Local Settings
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\AppData\Local\History
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Cookies
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\Application Data
[2012/02/18 22:18:20 | 000,000,000 | -HSD | C] -- C:\Users\kaybli2\AppData\Local\Application Data
[2012/02/18 22:18:19 | 000,000,000 | --SD | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Videos
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Saved Games
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Pictures
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Music
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Links
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Favorites
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Downloads
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Documents
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\Desktop
[2012/02/18 22:18:19 | 000,000,000 | R--D | C] -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/02/18 22:18:19 | 000,000,000 | -H-D | C] -- C:\Users\kaybli2\AppData
[2012/02/18 22:18:19 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Temp
[2012/02/18 22:18:19 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\Roaming
[2012/02/18 22:18:19 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Local\Microsoft
[2012/02/18 22:18:19 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Media Center Programs
[2012/02/18 22:18:19 | 000,000,000 | ---D | C] -- C:\Users\kaybli2\AppData\Roaming\Macromedia
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/11 08:15:21 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Users\kaybli2\Desktop\OTL.exe
[2012/03/11 08:08:05 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/11 08:08:05 | 000,025,120 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/11 08:04:25 | 000,726,316 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/03/11 08:04:25 | 000,624,178 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/03/11 08:04:25 | 000,106,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/03/11 08:00:50 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/11 08:00:36 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/03/11 08:00:29 | 463,486,975 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/11 07:55:02 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/11 02:52:00 | 000,013,312 | ---- | M] () -- C:\Users\kaybli2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/06 07:29:28 | 000,000,233 | ---- | M] () -- C:\Users\kaybli2\AppData\Roaming\burnaware.ini
[2012/03/03 14:43:21 | 001,506,428 | ---- | M] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012/02/25 02:08:39 | 000,000,172 | ---- | M] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\isolate.ini
[2012/02/24 19:02:23 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/02/22 18:34:58 | 000,004,782 | ---- | M] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012/02/20 21:51:33 | 000,175,736 | ---- | M] (Symantec Corporation) -- C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/02/20 21:51:33 | 000,007,488 | ---- | M] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/02/20 21:51:33 | 000,000,855 | ---- | M] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/02/20 21:11:58 | 000,275,352 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/02/19 01:16:05 | 000,108,227 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2012/02/19 01:16:05 | 000,108,227 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2012/02/19 01:03:14 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_iwdbus_01009.Wdf
[2012/02/19 00:58:47 | 000,000,040 | -H-- | M] () -- C:\windows\SysNative\ivireg.ivr
[2012/02/19 00:41:23 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_bpusb_01007.Wdf
[2012/02/19 00:41:20 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_bpenum_01007.Wdf
[2012/02/19 00:36:12 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/02/19 00:29:12 | 000,020,592 | ---- | M] (Compal Electronics, INC.) -- C:\windows\SysNative\drivers\CeKbFilter.sys
[2012/02/19 00:27:35 | 000,018,218 | ---- | M] () -- C:\windows\SysNative\results.xml
[2012/02/18 23:27:06 | 000,001,145 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/02/18 23:21:07 | 000,001,452 | ---- | M] () -- C:\Users\kaybli2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/18 23:19:22 | 000,000,013 | RHS- | M] () -- C:\windows\SysNative\drivers\fbd.sys
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/08 21:12:58 | 000,007,496 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symds64.cat
[2012/03/08 21:12:58 | 000,007,468 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\ccsetx64.cat
[2012/03/08 21:12:58 | 000,007,462 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtspx64.cat
[2012/03/08 21:12:58 | 000,007,460 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symefa64.cat
[2012/03/08 21:12:58 | 000,007,458 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symnet64.cat
[2012/03/08 21:12:58 | 000,007,458 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtsp64.cat
[2012/03/08 21:12:58 | 000,007,450 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\iron.cat
[2012/03/08 21:12:58 | 000,003,434 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symefa.inf
[2012/03/08 21:12:58 | 000,002,852 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symds.inf
[2012/03/08 21:12:58 | 000,001,441 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symnet.inf
[2012/03/08 21:12:58 | 000,001,438 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtsp64.inf
[2012/03/08 21:12:58 | 000,001,420 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\srtspx64.inf
[2012/03/08 21:12:58 | 000,000,853 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\ccsetx64.inf
[2012/03/08 21:12:58 | 000,000,772 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\iron.inf
[2012/03/08 21:12:47 | 000,004,782 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\symvtcer.dat
[2012/03/08 21:12:47 | 000,000,172 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1306010.008\isolate.ini
[2012/03/04 23:04:59 | 000,000,233 | ---- | C] () -- C:\Users\kaybli2\AppData\Roaming\burnaware.ini
[2012/02/24 19:02:23 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/02/22 18:34:58 | 001,506,428 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012/02/22 18:34:58 | 000,004,782 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012/02/21 22:39:23 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/02/20 21:51:27 | 000,007,458 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symnet64.cat
[2012/02/20 21:51:27 | 000,001,441 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symnet.inf
[2012/02/20 21:51:26 | 000,007,496 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symds64.cat
[2012/02/20 21:51:26 | 000,007,468 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\ccsetx64.cat
[2012/02/20 21:51:26 | 000,007,462 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtspx64.cat
[2012/02/20 21:51:26 | 000,007,460 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symefa64.cat
[2012/02/20 21:51:26 | 000,007,458 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtsp64.cat
[2012/02/20 21:51:26 | 000,007,450 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\iron.cat
[2012/02/20 21:51:26 | 000,003,434 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symefa.inf
[2012/02/20 21:51:26 | 000,002,852 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symds.inf
[2012/02/20 21:51:26 | 000,001,438 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtsp64.inf
[2012/02/20 21:51:26 | 000,001,420 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\srtspx64.inf
[2012/02/20 21:51:26 | 000,000,853 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\ccsetx64.inf
[2012/02/20 21:51:26 | 000,000,772 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\iron.inf
[2012/02/20 21:51:19 | 000,004,782 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\symvtcer.dat
[2012/02/20 21:51:19 | 000,000,172 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1305000.091\isolate.ini
[2012/02/19 03:29:26 | 000,013,312 | ---- | C] () -- C:\Users\kaybli2\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/19 01:03:14 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_iwdbus_01009.Wdf
[2012/02/19 01:03:06 | 000,002,063 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® WiDi.lnk
[2012/02/19 00:55:15 | 000,000,040 | -H-- | C] () -- C:\windows\SysNative\ivireg.ivr
[2012/02/19 00:44:53 | 000,000,912 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/19 00:44:53 | 000,000,908 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/19 00:43:59 | 000,007,488 | ---- | C] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/02/19 00:43:59 | 000,000,855 | ---- | C] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/02/19 00:41:23 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_bpusb_01007.Wdf
[2012/02/19 00:41:20 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_bpenum_01007.Wdf
[2012/02/19 00:37:17 | 000,074,272 | ---- | C] () -- C:\windows\SysNative\RtNicProp64.dll
[2012/02/19 00:36:12 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/02/19 00:32:29 | 000,012,734 | ---- | C] () -- C:\windows\SysNative\drivers\RTWAVES30.DAT
[2012/02/19 00:32:29 | 000,000,852 | ---- | C] () -- C:\windows\SysNative\drivers\RTKHDRC.dat
[2012/02/19 00:32:29 | 000,000,712 | ---- | C] () -- C:\windows\SysNative\drivers\RTEQEX1.dat
[2012/02/19 00:32:29 | 000,000,712 | ---- | C] () -- C:\windows\SysNative\drivers\RTEQEX0.dat
[2012/02/19 00:32:29 | 000,000,064 | ---- | C] () -- C:\windows\SysNative\drivers\rtkhdaud.dat
[2012/02/19 00:27:35 | 000,018,218 | ---- | C] () -- C:\windows\SysNative\results.xml
[2012/02/19 00:23:51 | 000,008,192 | ---- | C] () -- C:\windows\SysNative\drivers\IntelMEFWVer.dll
[2012/02/19 00:18:18 | 463,486,975 | -HS- | C] () -- C:\hiberfil.sys
[2012/02/18 23:27:06 | 000,001,145 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/02/18 23:27:05 | 000,001,157 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/18 23:21:07 | 000,001,452 | ---- | C] () -- C:\Users\kaybli2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/02/18 23:20:08 | 000,001,458 | ---- | C] () -- C:\Users\kaybli2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/02/18 23:19:22 | 000,000,013 | RHS- | C] () -- C:\windows\SysNative\drivers\fbd.sys
[2012/02/18 22:18:19 | 000,000,290 | ---- | C] () -- C:\Users\kaybli2\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/02/18 22:18:19 | 000,000,272 | ---- | C] () -- C:\Users\kaybli2\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/06/27 13:53:58 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/06/27 13:53:58 | 000,218,304 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/06/27 13:53:58 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/06/27 13:48:58 | 000,056,832 | ---- | C] () -- C:\windows\SysWow64\igdde32.dll
[2011/06/27 13:28:08 | 013,899,776 | ---- | C] () -- C:\windows\SysWow64\ig4icd32.dll
[2011/02/03 23:56:58 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll
[2010/11/09 16:09:58 | 000,028,672 | ---- | C] () -- C:\windows\SysWow64\SPCtl.dll

========== LOP Check ==========

[2012/02/19 03:29:45 | 000,000,000 | ---D | M] -- C:\Users\kaybli2\AppData\Roaming\IrfanView
[2012/02/18 23:22:10 | 000,000,000 | ---D | M] -- C:\Users\kaybli2\AppData\Roaming\Toshiba
[2012/02/18 22:18:54 | 000,000,000 | ---D | M] -- C:\Users\kaybli2\AppData\Roaming\WinBatch
[2009/07/14 01:08:49 | 000,007,626 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

It's also attached.

Attached Files

  • Attached File  OTL.Txt   125.3KB   82 downloads

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there lets see if we can resolve this

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

THEN

Download aswMBR.exe ( 4.1mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#3
kaybli

kaybli

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Thank you so much for your help! You have my greatest gratitude. I promise to give you a $50 donation upon fixing this problem.

Here is the contents of ComboFix.txt:

ComboFix 12-03-10.02 - kaybli2 03/11/2012 11:45:51.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6051.4367 [GMT -4:00]
Running from: c:\users\kaybli2\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Roaming
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
c:\windows\svchost.exe
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-02-11 to 2012-03-11 )))))))))))))))))))))))))))))))
.
.
2012-03-11 15:52 . 2012-03-11 15:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-11 11:46 . 2012-03-11 11:46 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-11 11:46 . 2012-03-11 11:46 -------- d-----w- c:\programdata\Malwarebytes
2012-03-11 11:46 . 2011-12-10 19:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-10 11:30 . 2012-03-10 11:30 6656 ----a-w- c:\programdata\Microsoft\Windows\DRM\DEC0.tmp
2012-03-10 11:30 . 2012-03-10 11:30 6656 ----a-w- c:\programdata\Microsoft\Windows\DRM\DEBF.tmp
2012-03-05 03:04 . 2012-03-05 03:04 -------- d-----w- c:\program files (x86)\BurnAware Free
2012-03-03 18:43 . 2009-05-18 18:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-03-03 18:43 . 2008-04-17 17:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-03-03 18:43 . 2008-04-17 17:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\program files\iTunes
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\program files (x86)\iTunes
2012-02-22 02:40 . 2012-02-22 02:40 -------- d-----w- c:\program files (x86)\QuickTime
2012-02-22 02:39 . 2012-03-03 18:42 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-02-22 02:39 . 2012-03-03 18:42 -------- d-----w- c:\programdata\Apple
2012-02-22 02:39 . 2012-02-22 02:39 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-02-21 08:00 . 2012-02-21 08:00 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-02-21 01:10 . 2012-02-21 01:10 -------- d-----w- c:\windows\SysWow64\Wat
2012-02-21 01:10 . 2012-02-21 01:10 -------- d-----w- c:\windows\system32\Wat
2012-02-20 20:51 . 2012-02-20 20:51 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-02-19 19:51 . 2012-02-19 19:51 -------- d-----w- c:\program files (x86)\VideoLAN
2012-02-19 08:15 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-19 08:15 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-19 08:15 . 2011-09-29 16:29 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-02-19 08:15 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2012-02-19 08:15 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2012-02-19 08:15 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-19 08:15 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-19 08:15 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-19 08:15 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-19 08:15 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-19 08:15 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-19 05:03 . 2011-02-18 00:42 99320 ----a-w- c:\windows\system32\tosWirelessLANIndicatorCP.dll
2012-02-19 05:03 . 2010-03-18 17:36 827728 ----a-w- c:\windows\system32\msvcr100.dll
2012-02-19 05:03 . 2010-03-18 17:36 607568 ----a-w- c:\windows\system32\msvcp100.dll
2012-02-19 05:03 . 2012-02-19 05:03 -------- d-----w- c:\program files (x86)\Common Files\Intel Corporation
2012-02-19 05:03 . 2012-02-19 05:03 -------- d-----w- c:\program files (x86)\Intel Corporation
2012-02-19 04:58 . 2010-10-20 22:41 138656 ----a-w- c:\windows\system32\TODDSrv.exe
2012-02-19 04:58 . 2012-02-19 04:58 -------- d-----w- c:\program files (x86)\TOSHIBA Corporation
2012-02-19 04:55 . 2007-04-17 19:51 14112 ----a-w- c:\windows\system32\drivers\regi.sys
2012-02-19 04:55 . 2012-02-19 04:55 -------- d-----w- c:\program files (x86)\Common Files\InterVideo
2012-02-19 04:54 . 2012-02-19 04:54 -------- d-----w- c:\program files (x86)\Common Files\Protexis
2012-02-19 04:54 . 2012-02-19 04:57 -------- d-----w- c:\program files (x86)\Corel
2012-02-19 04:54 . 2012-02-19 04:54 -------- d-----w- c:\programdata\Corel
2012-02-19 04:53 . 2012-02-19 04:58 -------- d-----w- c:\program files (x86)\Common Files\Toshiba Shared
2012-02-19 04:53 . 2011-06-10 03:28 482384 ----a-w- c:\windows\system32\drivers\tos_sps64.sys
2012-02-19 04:53 . 2009-03-09 23:27 4178264 ----a-w- c:\windows\SysWow64\D3DX9_41.dll
2012-02-19 04:52 . 2011-02-09 03:07 38096 ----a-w- c:\windows\system32\drivers\PGEffect.sys
2012-02-19 04:47 . 2012-02-19 04:47 -------- d-----w- c:\programdata\Best Buy pc app
2012-02-19 04:47 . 2012-02-19 04:47 -------- dc-h--w- c:\programdata\{373A11D3-0B96-4E16-9184-7D0FBE86932F}
2012-02-19 04:45 . 2012-02-19 04:45 -------- d-----w- c:\program files\Google
2012-02-19 04:44 . 2012-02-19 04:45 -------- d-----w- c:\program files (x86)\Google
2012-02-19 04:43 . 2012-02-21 01:51 175736 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2012-02-19 04:43 . 2012-02-21 01:51 -------- d-----w- c:\program files\Symantec
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files\Common Files\Symantec Shared
2012-02-19 04:43 . 2012-03-09 01:12 -------- d-----w- c:\windows\system32\drivers\NISx64
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files (x86)\Norton Internet Security
2012-02-19 04:43 . 2012-02-19 03:21 -------- d-----w- c:\programdata\Norton
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-02-19 04:41 . 2012-02-19 04:42 -------- d-----w- c:\program files (x86)\Best Buy Connect
2012-02-19 04:40 . 2012-02-19 04:40 -------- d-----w- c:\users\Public\Roaming
2012-02-19 04:40 . 2012-02-19 04:40 -------- d-----w- c:\users\Default\Roaming
2012-02-19 04:39 . 2012-02-19 05:03 -------- d-----w- c:\programdata\Intel
2012-02-19 04:39 . 2012-02-19 04:41 -------- d-----w- c:\program files\Intel
2012-02-19 04:39 . 2012-02-19 04:40 -------- d-----w- c:\program files (x86)\Cisco
2012-02-19 04:39 . 2012-02-19 04:39 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\program files (x86)\Renesas Electronics
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\programdata\Downloaded Installations
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\program files (x86)\JMicron
2012-02-19 04:37 . 2012-02-19 04:37 -------- d-----w- c:\windows\SysWow64\SDA
2012-02-19 04:37 . 2011-01-14 03:58 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-02-19 04:37 . 2011-01-14 03:58 413800 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-02-19 04:37 . 2011-01-14 03:58 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2012-02-19 04:32 . 2012-02-19 04:32 -------- d-----w- c:\program files\Common Files\Wave Audio Ltd
2012-02-19 04:29 . 1999-10-13 02:47 24576 ----a-w- c:\windows\SysWow64\TSCI.dll
2012-02-19 04:29 . 1999-10-13 02:45 24576 ----a-w- c:\windows\SysWow64\THCI.dll
2012-02-19 04:29 . 2012-03-03 18:43 -------- dc----w- c:\windows\system32\DRVSTORE
2012-02-19 04:29 . 2012-02-19 04:29 20592 ----a-w- c:\windows\system32\drivers\CeKbFilter.sys
2012-02-19 04:28 . 2012-02-19 04:30 -------- d-----w- c:\programdata\win7_64
2012-02-19 04:28 . 2012-02-19 04:30 -------- d-----w- c:\programdata\win7_32
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\programdata\vista64
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\programdata\vista32
2012-02-19 04:28 . 2011-03-10 20:06 295936 ----a-w- c:\windows\system32\HWS_Ctrl.dll
2012-02-19 04:28 . 2010-03-05 00:44 8192 ----a-w- c:\windows\system32\TSBWLS.dll
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\windows\system32\Microsoft.VC80.MFC
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\windows\Downloaded Installations
2012-02-19 04:26 . 2012-02-19 04:39 -------- d-----w- c:\program files\Common Files\Intel
2012-02-19 04:26 . 2012-02-19 04:26 -------- d-----w- c:\program files (x86)\Common Files\Intel
2012-02-19 04:23 . 2011-01-13 01:51 439320 ----a-w- c:\windows\system32\drivers\iaStor.sys
2012-02-19 04:23 . 2011-02-01 21:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2012-02-19 04:23 . 2012-02-19 04:23 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2012-02-19 04:23 . 2012-02-19 04:25 -------- d-----w- C:\Intel
2012-02-19 04:21 . 2012-02-19 04:26 -------- d-----w- c:\program files (x86)\Intel
2012-02-19 04:21 . 2010-10-04 21:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2012-02-19 04:03 . 2012-02-19 05:24 -------- d-----w- C:\rev
2012-02-19 04:02 . 2012-03-05 03:30 -------- d-----w- C:\Music
2012-02-19 03:41 . 2012-02-19 03:41 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2012-02-19 03:38 . 2012-02-19 03:38 -------- d-----w- c:\program files (x86)\IrfanView
2012-02-19 03:19 . 2012-02-19 03:19 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2012-02-19 02:18 . 2012-02-19 03:20 -------- d-----w- c:\users\kaybli2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-19 05:01 . 2011-08-22 03:19 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-19 03:19 . 2011-03-29 01:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-02-19 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2011-03-10 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-2-25 15776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-06-01 340240]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2011-07-01 828856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20120302.001\BHDrvx64.sys [2012-03-02 1157240]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20120309.002\IDSvia64.sys [2012-03-06 488568]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2011-06-14 498688]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2011-05-24 294848]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2011-06-14 986112]
S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [x]
S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x]
S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [x]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-21 138360]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 04:44]
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 04:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-07-02 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-07-02 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-07-02 416024]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-03-05 11780712]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-02 2189416]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-01 1935120]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-06-10 710560]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\kaybli2\AppData\Roaming\Mozilla\Firefox\Profiles\1rjzlrzq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKLM-Run-TSleepSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
Toolbar-Locked - (no file)
HKLM-Run-(Default) - (no file)
HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\program files (x86)\TOSHIBA\widimon\widimon.exe
c:\\.\globalroot\systemroot\svchost.exe
c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-03-11 11:59:13 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-11 15:59
.
Pre-Run: 552,039,600,128 bytes free
Post-Run: 551,981,527,040 bytes free
.
- - End Of File - - E631BF27C89FDF3C0D50D12AF0D78DDD

Here is the contents of aswMBR.txt:

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-11 12:06:34
-----------------------------
12:06:34.607 OS Version: Windows x64 6.1.7601 Service Pack 1
12:06:34.607 Number of processors: 8 586 0x2A07
12:06:34.607 ComputerName: KAYBLI2-PC UserName: kaybli2
12:07:17.541 Initialize success
12:09:28.051 AVAST engine defs: 12031100
12:10:13.625 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
12:10:13.627 Disk 0 Vendor: TOSHIBA_ GT00 Size: 715404MB BusType: 3
12:10:13.629 Device \Driver\iaStor -> MajorFunction fffffa80085c45c4
12:10:13.631 Disk 0 MBR read successfully
12:10:13.633 Disk 0 MBR scan
12:10:13.636 Disk 0 Windows VISTA default MBR code
12:10:13.669 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
12:10:13.714 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 698469 MB offset 3074048
12:10:13.767 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 15434 MB offset 1433538560
12:10:13.820 Disk 0 scanning C:\windows\system32\drivers
12:10:23.510 Service scanning
12:11:00.792 Modules scanning
12:11:00.804 Disk 0 trace - called modules:
12:11:00.809 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys
12:11:00.813 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007c31060]
12:11:00.817 3 CLASSPNP.SYS[fffff8800182c43f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa8007b84710]
12:11:06.721 AVAST engine scan C:\windows
12:11:12.700 AVAST engine scan C:\windows\system32
12:14:31.934 AVAST engine scan C:\windows\system32\drivers
12:14:44.213 AVAST engine scan C:\Users\kaybli2
12:16:20.283 AVAST engine scan C:\ProgramData
12:17:03.702 File: C:\ProgramData\Microsoft\Windows\DRM\DEBF.tmp **INFECTED** Win32:Malware-gen
12:17:03.744 File: C:\ProgramData\Microsoft\Windows\DRM\DEC0.tmp **INFECTED** Win32:Malware-gen
12:17:37.135 Scan finished successfully
12:18:08.780 Disk 0 MBR has been saved successfully to "C:\Users\kaybli2\Desktop\MBR.dat"
12:18:08.784 The log file has been saved successfully to "C:\Users\kaybli2\Desktop\aswMBR.txt"

Google was working for a little bit then it stopped working again.
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK looks like we need one further run with combofix, on completion of this could you check out Google and let me know if it is functioning properly. Also any other problems you are experiencing

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\ProgramData\Microsoft\Windows\DRM\DEBF.tmp
C:\ProgramData\Microsoft\Windows\DRM\DEC0.tmp
c:\windows\svchost.exe


Save this as CFScript.txt, in the same location as ComboFix.exe
Posted Image

Refering to the picture above, drag CFScript into ComboFix.exeWhen finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • 0

#5
kaybli

kaybli

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I ran ComboFix again the way you instructed me to. Google is working now. Here is the ComboFix log:

ComboFix 12-03-10.02 - kaybli2 03/11/2012 12:42:19.2.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6051.4358 [GMT -4:00]
Running from: c:\users\kaybli2\Desktop\ComboFix.exe
Command switches used :: c:\users\kaybli2\Desktop\CFScript.txt
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\programdata\Microsoft\Windows\DRM\DEBF.tmp"
"c:\programdata\Microsoft\Windows\DRM\DEC0.tmp"
"c:\windows\svchost.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\Microsoft\Windows\DRM\DEBF.tmp
c:\programdata\Microsoft\Windows\DRM\DEC0.tmp
c:\windows\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-02-11 to 2012-03-11 )))))))))))))))))))))))))))))))
.
.
2012-03-11 16:47 . 2012-03-11 16:47 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-11 11:46 . 2012-03-11 11:46 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-03-11 11:46 . 2012-03-11 11:46 -------- d-----w- c:\programdata\Malwarebytes
2012-03-11 11:46 . 2011-12-10 19:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-05 03:04 . 2012-03-05 03:04 -------- d-----w- c:\program files (x86)\BurnAware Free
2012-03-03 18:43 . 2009-05-18 18:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-03-03 18:43 . 2008-04-17 17:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-03-03 18:43 . 2008-04-17 17:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\program files\iTunes
2012-03-03 18:42 . 2012-03-03 18:43 -------- d-----w- c:\program files (x86)\iTunes
2012-02-22 02:40 . 2012-02-22 02:40 -------- d-----w- c:\program files (x86)\QuickTime
2012-02-22 02:39 . 2012-03-03 18:42 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-02-22 02:39 . 2012-03-03 18:42 -------- d-----w- c:\programdata\Apple
2012-02-22 02:39 . 2012-02-22 02:39 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-02-21 08:00 . 2012-02-21 08:00 -------- d-----w- c:\program files (x86)\Microsoft.NET
2012-02-21 01:10 . 2012-02-21 01:10 -------- d-----w- c:\windows\SysWow64\Wat
2012-02-21 01:10 . 2012-02-21 01:10 -------- d-----w- c:\windows\system32\Wat
2012-02-20 20:51 . 2012-02-20 20:51 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-02-19 19:51 . 2012-02-19 19:51 -------- d-----w- c:\program files (x86)\VideoLAN
2012-02-19 08:15 . 2011-12-30 06:26 515584 ----a-w- c:\windows\system32\timedate.cpl
2012-02-19 08:15 . 2011-12-30 05:27 478720 ----a-w- c:\windows\SysWow64\timedate.cpl
2012-02-19 08:15 . 2011-09-29 16:29 1923952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-02-19 08:15 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2012-02-19 08:15 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2012-02-19 08:15 . 2012-01-14 04:06 3145728 ----a-w- c:\windows\system32\win32k.sys
2012-02-19 08:15 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-02-19 08:15 . 2011-08-17 05:25 108032 ----a-w- c:\windows\system32\psisrndr.ax
2012-02-19 08:15 . 2011-08-17 04:24 465408 ----a-w- c:\windows\SysWow64\psisdecd.dll
2012-02-19 08:15 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-02-19 08:15 . 2011-12-28 03:59 498688 ----a-w- c:\windows\system32\drivers\afd.sys
2012-02-19 05:03 . 2011-02-18 00:42 99320 ----a-w- c:\windows\system32\tosWirelessLANIndicatorCP.dll
2012-02-19 05:03 . 2010-03-18 17:36 827728 ----a-w- c:\windows\system32\msvcr100.dll
2012-02-19 05:03 . 2010-03-18 17:36 607568 ----a-w- c:\windows\system32\msvcp100.dll
2012-02-19 05:03 . 2012-02-19 05:03 -------- d-----w- c:\program files (x86)\Common Files\Intel Corporation
2012-02-19 05:03 . 2012-02-19 05:03 -------- d-----w- c:\program files (x86)\Intel Corporation
2012-02-19 04:58 . 2010-10-20 22:41 138656 ----a-w- c:\windows\system32\TODDSrv.exe
2012-02-19 04:58 . 2012-02-19 04:58 -------- d-----w- c:\program files (x86)\TOSHIBA Corporation
2012-02-19 04:55 . 2007-04-17 19:51 14112 ----a-w- c:\windows\system32\drivers\regi.sys
2012-02-19 04:55 . 2012-02-19 04:55 -------- d-----w- c:\program files (x86)\Common Files\InterVideo
2012-02-19 04:54 . 2012-02-19 04:54 -------- d-----w- c:\program files (x86)\Common Files\Protexis
2012-02-19 04:54 . 2012-02-19 04:57 -------- d-----w- c:\program files (x86)\Corel
2012-02-19 04:54 . 2012-02-19 04:54 -------- d-----w- c:\programdata\Corel
2012-02-19 04:53 . 2012-02-19 04:58 -------- d-----w- c:\program files (x86)\Common Files\Toshiba Shared
2012-02-19 04:53 . 2011-06-10 03:28 482384 ----a-w- c:\windows\system32\drivers\tos_sps64.sys
2012-02-19 04:53 . 2009-03-09 23:27 4178264 ----a-w- c:\windows\SysWow64\D3DX9_41.dll
2012-02-19 04:52 . 2011-02-09 03:07 38096 ----a-w- c:\windows\system32\drivers\PGEffect.sys
2012-02-19 04:47 . 2012-02-19 04:47 -------- d-----w- c:\programdata\Best Buy pc app
2012-02-19 04:47 . 2012-02-19 04:47 -------- dc-h--w- c:\programdata\{373A11D3-0B96-4E16-9184-7D0FBE86932F}
2012-02-19 04:45 . 2012-02-19 04:45 -------- d-----w- c:\program files\Google
2012-02-19 04:44 . 2012-02-19 04:45 -------- d-----w- c:\program files (x86)\Google
2012-02-19 04:43 . 2012-02-21 01:51 175736 ----a-w- c:\windows\system32\drivers\SYMEVENT64x86.SYS
2012-02-19 04:43 . 2012-02-21 01:51 -------- d-----w- c:\program files\Symantec
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files\Common Files\Symantec Shared
2012-02-19 04:43 . 2012-03-09 01:12 -------- d-----w- c:\windows\system32\drivers\NISx64
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files (x86)\Norton Internet Security
2012-02-19 04:43 . 2012-02-19 03:21 -------- d-----w- c:\programdata\Norton
2012-02-19 04:43 . 2012-02-19 04:43 -------- d-----w- c:\program files (x86)\NortonInstaller
2012-02-19 04:41 . 2012-02-19 04:42 -------- d-----w- c:\program files (x86)\Best Buy Connect
2012-02-19 04:40 . 2012-02-19 04:40 -------- d-----w- c:\users\Public\Roaming
2012-02-19 04:40 . 2012-02-19 04:40 -------- d-----w- c:\users\Default\Roaming
2012-02-19 04:39 . 2012-02-19 05:03 -------- d-----w- c:\programdata\Intel
2012-02-19 04:39 . 2012-02-19 04:41 -------- d-----w- c:\program files\Intel
2012-02-19 04:39 . 2012-02-19 04:40 -------- d-----w- c:\program files (x86)\Cisco
2012-02-19 04:39 . 2012-02-19 04:39 -------- d-----w- c:\program files (x86)\Common Files\Symantec Shared
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\program files (x86)\Renesas Electronics
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\programdata\Downloaded Installations
2012-02-19 04:38 . 2012-02-19 04:38 -------- d-----w- c:\program files (x86)\JMicron
2012-02-19 04:37 . 2012-02-19 04:37 -------- d-----w- c:\windows\SysWow64\SDA
2012-02-19 04:37 . 2011-01-14 03:58 74272 ----a-w- c:\windows\system32\RtNicProp64.dll
2012-02-19 04:37 . 2011-01-14 03:58 413800 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2012-02-19 04:37 . 2011-01-14 03:58 107552 ----a-w- c:\windows\system32\RTNUninst64.dll
2012-02-19 04:32 . 2012-02-19 04:32 -------- d-----w- c:\program files\Common Files\Wave Audio Ltd
2012-02-19 04:29 . 1999-10-13 02:47 24576 ----a-w- c:\windows\SysWow64\TSCI.dll
2012-02-19 04:29 . 1999-10-13 02:45 24576 ----a-w- c:\windows\SysWow64\THCI.dll
2012-02-19 04:29 . 2012-03-03 18:43 -------- dc----w- c:\windows\system32\DRVSTORE
2012-02-19 04:29 . 2012-02-19 04:29 20592 ----a-w- c:\windows\system32\drivers\CeKbFilter.sys
2012-02-19 04:28 . 2012-02-19 04:30 -------- d-----w- c:\programdata\win7_64
2012-02-19 04:28 . 2012-02-19 04:30 -------- d-----w- c:\programdata\win7_32
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\programdata\vista64
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\programdata\vista32
2012-02-19 04:28 . 2011-03-10 20:06 295936 ----a-w- c:\windows\system32\HWS_Ctrl.dll
2012-02-19 04:28 . 2010-03-05 00:44 8192 ----a-w- c:\windows\system32\TSBWLS.dll
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\windows\system32\Microsoft.VC80.MFC
2012-02-19 04:28 . 2012-02-19 04:28 -------- d-----w- c:\windows\Downloaded Installations
2012-02-19 04:26 . 2012-02-19 04:39 -------- d-----w- c:\program files\Common Files\Intel
2012-02-19 04:26 . 2012-02-19 04:26 -------- d-----w- c:\program files (x86)\Common Files\Intel
2012-02-19 04:23 . 2011-01-13 01:51 439320 ----a-w- c:\windows\system32\drivers\iaStor.sys
2012-02-19 04:23 . 2011-02-01 21:06 8192 ----a-w- c:\windows\system32\drivers\IntelMEFWVer.dll
2012-02-19 04:23 . 2012-02-19 04:23 -------- d-----w- c:\program files (x86)\Common Files\postureAgent
2012-02-19 04:23 . 2012-02-19 04:25 -------- d-----w- C:\Intel
2012-02-19 04:21 . 2012-02-19 04:26 -------- d-----w- c:\program files (x86)\Intel
2012-02-19 04:21 . 2010-10-04 21:02 53248 ----a-w- c:\windows\SysWow64\CSVer.dll
2012-02-19 04:03 . 2012-02-19 05:24 -------- d-----w- C:\rev
2012-02-19 04:02 . 2012-03-05 03:30 -------- d-----w- C:\Music
2012-02-19 03:41 . 2012-02-19 03:41 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2012-02-19 03:38 . 2012-02-19 03:38 -------- d-----w- c:\program files (x86)\IrfanView
2012-02-19 03:19 . 2012-02-19 03:19 13 --sh--r- c:\windows\system32\drivers\fbd.sys
2012-02-19 02:18 . 2012-02-19 03:20 -------- d-----w- c:\users\kaybli2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-19 05:01 . 2011-08-22 03:19 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-19 03:19 . 2011-03-29 01:36 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-11_15.53.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-11 12:05 . 2012-03-11 16:02 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012031120120312\index.dat
- 2012-03-10 11:45 . 2012-03-11 15:38 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2012-03-10 11:45 . 2012-03-11 16:02 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2010-11-21 03:09 . 2012-03-11 16:50 30152 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-03-11 16:50 39180 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2012-02-19 04:41 . 2012-03-11 16:48 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2012-02-19 04:41 . 2012-03-11 15:53 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-02-19 04:41 . 2012-03-11 16:48 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2012-02-19 04:41 . 2012-03-11 15:53 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-11 16:48 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-11 15:53 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-03-11 16:00 . 2012-03-11 16:00 1604 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2012-02-19 03:20 . 2012-03-11 16:50 3146 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3362831547-2038997110-2861792478-1000_UserData.bin
+ 2012-03-11 16:48 . 2012-03-11 16:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2012-03-11 15:52 . 2012-03-11 15:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-03-11 16:48 . 2012-03-11 16:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-03-11 15:52 . 2012-03-11 15:52 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-03-10 11:34 . 2012-03-11 16:49 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2012-03-10 11:34 . 2012-03-11 15:53 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:54 . 2012-03-11 15:53 180224 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-03-11 16:49 180224 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 02:36 . 2012-03-11 16:07 624178 c:\windows\system32\perfh009.dat
- 2009-07-14 02:36 . 2012-03-11 15:41 624178 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2012-03-11 16:07 106522 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2012-03-11 15:41 106522 c:\windows\system32\perfc009.dat
- 2009-07-14 05:01 . 2012-03-11 15:52 236908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-03-11 16:48 236908 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:54 . 2012-03-11 15:53 3162112 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-11 16:40 3162112 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-03-11 16:40 8208384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:54 . 2012-03-11 15:53 8208384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2012-03-11 11:51 . 2012-03-11 15:52 5480856 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
+ 2012-03-11 11:51 . 2012-03-11 16:48 5480856 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
+ 2012-02-21 01:10 . 2012-03-11 16:48 14535136 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3362831547-2038997110-2861792478-1000-8192.dat
- 2012-02-21 01:10 . 2012-03-11 15:52 14535136 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3362831547-2038997110-2861792478-1000-8192.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-02-19 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SVPWUTIL"="c:\program files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe" [2010-11-09 532480]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2011-03-10 423936]
"KeNotify"="c:\program files (x86)\TOSHIBA\Utilities\KeNotify.exe" [2010-08-16 34160]
"ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe [2011-2-25 15776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 136176]
R3 intaud_WaveExtensible;Intel WiDi Audio Device;c:\windows\system32\drivers\intelaud.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2011-06-01 340240]
R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152]
R3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2011-07-01 828856]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS [x]
S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20120302.001\BHDrvx64.sys [2012-03-02 1157240]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20120309.002\IDSvia64.sys [2012-03-06 488568]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 DMAgent;Intel® PROSet/Wireless WiMAX Red Bend Device Management Service;c:\program files\Intel\WiMAX\Bin\DMAgent.exe [2011-06-14 498688]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe [2011-11-30 138248]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [x]
S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2011-05-24 294848]
S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
S2 WiMAXAppSrv;Intel® PROSet/Wireless WiMAX Service;c:\program files\Intel\WiMAX\Bin\AppSrv.exe [2011-06-14 986112]
S3 bpenum;Intel® Centrino® WiMAX Enumerator;c:\windows\system32\DRIVERS\bpenum.sys [x]
S3 bpmp;Intel® Centrino® WiMAX 6050 Series;c:\windows\system32\DRIVERS\bpmp.sys [x]
S3 bpusb;Intel® Centrino® WiMAX 6050 Series Function Driver;c:\windows\system32\Drivers\bpusb.sys [x]
S3 CeKbFilter;CeKbFilter;c:\windows\system32\DRIVERS\CeKbFilter.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-02-21 138360]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 iwdbus;IWD Bus Enumerator;c:\windows\system32\DRIVERS\iwdbus.sys [x]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x]
S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 04:44]
.
2012-03-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-02-19 04:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThpSrv"="c:\windows\system32\thpsrv" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-07-02 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-07-02 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-07-02 416024]
"TPwrMain"="c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE" [BU]
"HSON"="c:\program files (x86)\TOSHIBA\TBS\HSON.exe" [BU]
"TCrdMain"="c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe" [BU]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-03-05 11780712]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-02 2189416]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
"Teco"="c:\program files (x86)\TOSHIBA\TECO\Teco.exe" [BU]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-01 1935120]
"TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2011-06-10 710560]
"TosWaitSrv"="c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe" [BU]
"TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
"TosNC"="c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe" [BU]
"TosReelTimeMonitor"="c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>;*.local
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\kaybli2\AppData\Roaming\Mozilla\Firefox\Profiles\1rjzlrzq.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\19.5.0.145\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\\.\globalroot\systemroot\svchost.exe
c:\program files (x86)\TOSHIBA\widimon\widimon.exe
c:\program files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-03-11 12:55:26 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-11 16:55
ComboFix2.txt 2012-03-11 15:59
.
Pre-Run: 552,553,299,968 bytes free
Post-Run: 552,726,163,456 bytes free
.
- - End Of File - - 4B8D8C97B2315DA06B50CC3774F4BAC1


Are we outta the woods yet?
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Not quite there is one file that refuses to go - there is a new variant doing the rounds at the moment and this may be one of them. So I will need to run a further tool to confirm or deny this, it should only take a few minutes to run



Download the latest version of TDSSKiller from here and save it to your Desktop.


  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    Posted Image
  • Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

    Posted Image
  • Click the Start Scan button.

    Posted Image
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    Posted Image
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

    Posted Image
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
  • 0

#7
kaybli

kaybli

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Google was not working but after the latest restart it is working again.

Here is the log of TDSSKiller. Cure was not working for one of the options so I chose SKIP:

13:10:15.0510 3232 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
13:10:15.0850 3232 ============================================================
13:10:15.0851 3232 Current date / time: 2012/03/11 13:10:15.0850
13:10:15.0851 3232 SystemInfo:
13:10:15.0851 3232
13:10:15.0851 3232 OS Version: 6.1.7601 ServicePack: 1.0
13:10:15.0851 3232 Product type: Workstation
13:10:15.0851 3232 ComputerName: KAYBLI2-PC
13:10:15.0851 3232 UserName: kaybli2
13:10:15.0851 3232 Windows directory: C:\windows
13:10:15.0851 3232 System windows directory: C:\windows
13:10:15.0851 3232 Running under WOW64
13:10:15.0851 3232 Processor architecture: Intel x64
13:10:15.0851 3232 Number of processors: 8
13:10:15.0851 3232 Page size: 0x1000
13:10:15.0851 3232 Boot type: Normal boot
13:10:15.0851 3232 ============================================================
13:10:16.0274 3232 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:10:16.0278 3232 \Device\Harddisk0\DR0:
13:10:16.0278 3232 MBR used
13:10:16.0278 3232 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x55432800
13:10:16.0335 3232 Initialize success
13:10:16.0335 3232 ============================================================
13:11:10.0799 5188 ============================================================
13:11:10.0799 5188 Scan started
13:11:10.0799 5188 Mode: Manual; SigCheck; TDLFS;
13:11:10.0799 5188 ============================================================
13:11:12.0438 5188 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
13:11:12.0519 5188 1394ohci - ok
13:11:12.0619 5188 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
13:11:12.0637 5188 ACPI - ok
13:11:12.0819 5188 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
13:11:12.0906 5188 AcpiPmi - ok
13:11:13.0054 5188 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\drivers\adp94xx.sys
13:11:13.0072 5188 adp94xx - ok
13:11:13.0203 5188 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\drivers\adpahci.sys
13:11:13.0217 5188 adpahci - ok
13:11:13.0338 5188 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\drivers\adpu320.sys
13:11:13.0353 5188 adpu320 - ok
13:11:13.0510 5188 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
13:11:13.0595 5188 AFD - ok
13:11:13.0715 5188 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
13:11:13.0725 5188 agp440 - ok
13:11:13.0849 5188 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
13:11:13.0856 5188 aliide - ok
13:11:14.0060 5188 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
13:11:14.0068 5188 amdide - ok
13:11:14.0148 5188 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\drivers\amdk8.sys
13:11:14.0186 5188 AmdK8 - ok
13:11:14.0231 5188 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\drivers\amdppm.sys
13:11:14.0272 5188 AmdPPM - ok
13:11:14.0522 5188 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
13:11:14.0532 5188 amdsata - ok
13:11:14.0653 5188 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\drivers\amdsbs.sys
13:11:14.0664 5188 amdsbs - ok
13:11:14.0817 5188 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
13:11:14.0825 5188 amdxata - ok
13:11:14.0926 5188 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
13:11:15.0043 5188 AppID - ok
13:11:15.0171 5188 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\drivers\arc.sys
13:11:15.0181 5188 arc - ok
13:11:15.0285 5188 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\drivers\arcsas.sys
13:11:15.0294 5188 arcsas - ok
13:11:15.0396 5188 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
13:11:15.0559 5188 AsyncMac - ok
13:11:15.0701 5188 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
13:11:15.0708 5188 atapi - ok
13:11:15.0896 5188 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\drivers\bxvbda.sys
13:11:15.0944 5188 b06bdrv - ok
13:11:16.0129 5188 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
13:11:16.0162 5188 b57nd60a - ok
13:11:16.0259 5188 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
13:11:16.0315 5188 Beep - ok
13:11:16.0483 5188 BHDrvx64 (6c64fa457c200874faa87d74152e0d84) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20120302.001\BHDrvx64.sys
13:11:16.0532 5188 BHDrvx64 - ok
13:11:16.0626 5188 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\drivers\blbdrive.sys
13:11:16.0651 5188 blbdrive - ok
13:11:16.0767 5188 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
13:11:16.0798 5188 bowser - ok
13:11:16.0915 5188 bpenum (56e4345f392f17d66683225e214840cb) C:\windows\system32\DRIVERS\bpenum.sys
13:11:16.0944 5188 bpenum - ok
13:11:17.0062 5188 bpmp (d50b07c4d7afec4ca6ac8fcb72583c5b) C:\windows\system32\DRIVERS\bpmp.sys
13:11:17.0104 5188 bpmp - ok
13:11:17.0207 5188 bpusb (a85ba55e4fe9cb2f342f281aaf7de810) C:\windows\system32\Drivers\bpusb.sys
13:11:17.0231 5188 bpusb - ok
13:11:17.0419 5188 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\drivers\BrFiltLo.sys
13:11:17.0477 5188 BrFiltLo - ok
13:11:17.0575 5188 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\drivers\BrFiltUp.sys
13:11:17.0590 5188 BrFiltUp - ok
13:11:17.0619 5188 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\windows\system32\DRIVERS\bridge.sys
13:11:17.0694 5188 BridgeMP - ok
13:11:17.0772 5188 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
13:11:17.0826 5188 Brserid - ok
13:11:17.0939 5188 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
13:11:17.0964 5188 BrSerWdm - ok
13:11:18.0095 5188 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
13:11:18.0117 5188 BrUsbMdm - ok
13:11:18.0229 5188 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
13:11:18.0260 5188 BrUsbSer - ok
13:11:18.0374 5188 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\drivers\bthmodem.sys
13:11:18.0397 5188 BTHMODEM - ok
13:11:18.0433 5188 catchme - ok
13:11:18.0584 5188 ccSet_NIS (0e1737a63aec0f6de231bb59836c0a11) C:\windows\system32\drivers\NISx64\1305000.091\ccSetx64.sys
13:11:18.0592 5188 ccSet_NIS - ok
13:11:18.0717 5188 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
13:11:18.0764 5188 cdfs - ok
13:11:18.0866 5188 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\DRIVERS\cdrom.sys
13:11:18.0912 5188 cdrom - ok
13:11:19.0071 5188 CeKbFilter (a965b206921c55f2d1481789d609b711) C:\windows\system32\DRIVERS\CeKbFilter.sys
13:11:19.0078 5188 CeKbFilter - ok
13:11:19.0199 5188 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\drivers\circlass.sys
13:11:19.0235 5188 circlass - ok
13:11:19.0323 5188 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
13:11:19.0338 5188 CLFS - ok
13:11:19.0487 5188 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\drivers\CmBatt.sys
13:11:19.0528 5188 CmBatt - ok
13:11:19.0668 5188 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
13:11:19.0676 5188 cmdide - ok
13:11:19.0739 5188 CNG (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
13:11:19.0785 5188 CNG - ok
13:11:19.0901 5188 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\drivers\compbatt.sys
13:11:19.0911 5188 Compbatt - ok
13:11:20.0053 5188 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
13:11:20.0113 5188 CompositeBus - ok
13:11:20.0301 5188 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\drivers\crcdisk.sys
13:11:20.0310 5188 crcdisk - ok
13:11:20.0551 5188 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
13:11:20.0699 5188 DfsC - ok
13:11:20.0825 5188 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
13:11:20.0868 5188 discache - ok
13:11:20.0995 5188 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\drivers\disk.sys
13:11:21.0004 5188 Disk - ok
13:11:21.0153 5188 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
13:11:21.0170 5188 drmkaud - ok
13:11:21.0249 5188 DXGKrnl (85dbf6ec7bdfa6187f4a1ec8f3145cd0) C:\windows\System32\drivers\dxgkrnl.sys
13:11:21.0270 5188 DXGKrnl - ok
13:11:21.0419 5188 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\drivers\evbda.sys
13:11:21.0508 5188 ebdrv - ok
13:11:21.0593 5188 eeCtrl (0c3f9eff8ddd9f9eb56d754b4620155f) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
13:11:21.0605 5188 eeCtrl - ok
13:11:21.0768 5188 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\drivers\elxstor.sys
13:11:21.0786 5188 elxstor - ok
13:11:21.0886 5188 EraserUtilRebootDrv (8c0f9b877bc0b7ffd327ef55f9efb642) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
13:11:21.0894 5188 EraserUtilRebootDrv - ok
13:11:22.0052 5188 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
13:11:22.0154 5188 ErrDev - ok
13:11:22.0363 5188 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
13:11:22.0414 5188 exfat - ok
13:11:22.0536 5188 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
13:11:22.0612 5188 fastfat - ok
13:11:22.0709 5188 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\drivers\fdc.sys
13:11:22.0747 5188 fdc - ok
13:11:22.0865 5188 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
13:11:22.0877 5188 FileInfo - ok
13:11:22.0910 5188 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
13:11:23.0026 5188 Filetrace - ok
13:11:23.0593 5188 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\drivers\flpydisk.sys
13:11:23.0606 5188 flpydisk - ok
13:11:23.0798 5188 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
13:11:23.0810 5188 FltMgr - ok
13:11:23.0985 5188 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
13:11:23.0995 5188 FsDepends - ok
13:11:24.0045 5188 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
13:11:24.0056 5188 Fs_Rec - ok
13:11:24.0477 5188 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
13:11:24.0492 5188 fvevol - ok
13:11:24.0590 5188 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\drivers\gagp30kx.sys
13:11:24.0599 5188 gagp30kx - ok
13:11:24.0634 5188 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
13:11:24.0640 5188 GEARAspiWDM - ok
13:11:24.0840 5188 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
13:11:24.0875 5188 hcw85cir - ok
13:11:24.0966 5188 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
13:11:24.0992 5188 HdAudAddService - ok
13:11:25.0111 5188 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
13:11:25.0156 5188 HDAudBus - ok
13:11:25.0239 5188 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\drivers\HidBatt.sys
13:11:25.0267 5188 HidBatt - ok
13:11:25.0352 5188 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\drivers\hidbth.sys
13:11:25.0374 5188 HidBth - ok
13:11:25.0453 5188 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\drivers\hidir.sys
13:11:25.0473 5188 HidIr - ok
13:11:25.0654 5188 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\drivers\hidusb.sys
13:11:25.0678 5188 HidUsb - ok
13:11:25.0778 5188 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
13:11:25.0787 5188 HpSAMD - ok
13:11:25.0891 5188 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
13:11:25.0967 5188 HTTP - ok
13:11:26.0047 5188 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
13:11:26.0059 5188 hwpolicy - ok
13:11:26.0174 5188 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
13:11:26.0211 5188 i8042prt - ok
13:11:26.0325 5188 iaStor (d469b77687e12fe43e344806740b624d) C:\windows\system32\DRIVERS\iaStor.sys
13:11:26.0337 5188 iaStor - ok
13:11:26.0453 5188 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
13:11:26.0467 5188 iaStorV - ok
13:11:26.0604 5188 IDSVia64 (18c40c3f368323b203ace403cb430db1) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20120309.002\IDSvia64.sys
13:11:26.0617 5188 IDSVia64 - ok
13:11:27.0051 5188 igfx (93c8115d4baeb1bd047ab0a9b265ee7a) C:\windows\system32\DRIVERS\igdkmd64.sys
13:11:27.0556 5188 igfx - ok
13:11:27.0664 5188 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\drivers\iirsp.sys
13:11:27.0672 5188 iirsp - ok
13:11:27.0787 5188 intaud_WaveExtensible (caddf0927dac63edae48f5c35a61d87d) C:\windows\system32\drivers\intelaud.sys
13:11:27.0795 5188 intaud_WaveExtensible - ok
13:11:27.0993 5188 IntcAzAudAddService (4b2151f04bb466ec1924aa27315e1118) C:\windows\system32\drivers\RTKVHD64.sys
13:11:28.0038 5188 IntcAzAudAddService - ok
13:11:28.0772 5188 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\windows\system32\DRIVERS\IntcDAud.sys
13:11:29.0003 5188 IntcDAud - ok
13:11:29.0098 5188 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
13:11:29.0216 5188 intelide - ok
13:11:29.0392 5188 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
13:11:29.0417 5188 intelppm - ok
13:11:29.0522 5188 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
13:11:29.0554 5188 IpFilterDriver - ok
13:11:29.0565 5188 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
13:11:29.0592 5188 IPMIDRV - ok
13:11:29.0702 5188 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
13:11:29.0759 5188 IPNAT - ok
13:11:29.0868 5188 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
13:11:29.0940 5188 IRENUM - ok
13:11:30.0036 5188 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
13:11:30.0045 5188 isapnp - ok
13:11:30.0079 5188 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
13:11:30.0091 5188 iScsiPrt - ok
13:11:30.0181 5188 iwdbus (716f66336f10885d935b08174dc54242) C:\windows\system32\DRIVERS\iwdbus.sys
13:11:30.0188 5188 iwdbus - ok
13:11:30.0256 5188 JMCR (935301dd8306ceeaef0b84dd6abffdc6) C:\windows\system32\DRIVERS\jmcr.sys
13:11:30.0266 5188 JMCR - ok
13:11:30.0368 5188 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
13:11:30.0376 5188 kbdclass - ok
13:11:30.0448 5188 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
13:11:30.0470 5188 kbdhid - ok
13:11:30.0552 5188 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
13:11:30.0561 5188 KSecDD - ok
13:11:30.0670 5188 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
13:11:30.0680 5188 KSecPkg - ok
13:11:30.0776 5188 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
13:11:30.0819 5188 ksthunk - ok
13:11:30.0936 5188 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
13:11:30.0991 5188 lltdio - ok
13:11:31.0151 5188 LPCFilter (2825a71e7501cb33b3b9f856610c729d) C:\windows\system32\DRIVERS\LPCFilter.sys
13:11:31.0159 5188 LPCFilter - ok
13:11:31.0264 5188 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\drivers\lsi_fc.sys
13:11:31.0278 5188 LSI_FC - ok
13:11:31.0386 5188 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\drivers\lsi_sas.sys
13:11:31.0396 5188 LSI_SAS - ok
13:11:31.0446 5188 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\drivers\lsi_sas2.sys
13:11:31.0455 5188 LSI_SAS2 - ok
13:11:31.0568 5188 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\drivers\lsi_scsi.sys
13:11:31.0580 5188 LSI_SCSI - ok
13:11:31.0697 5188 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
13:11:31.0778 5188 luafv - ok
13:11:31.0871 5188 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\drivers\megasas.sys
13:11:31.0879 5188 megasas - ok
13:11:31.0971 5188 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\drivers\MegaSR.sys
13:11:31.0985 5188 MegaSR - ok
13:11:32.0012 5188 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
13:11:32.0019 5188 MEIx64 - ok
13:11:32.0098 5188 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
13:11:32.0155 5188 Modem - ok
13:11:32.0545 5188 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
13:11:32.0616 5188 monitor - ok
13:11:32.0720 5188 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\drivers\mouclass.sys
13:11:32.0729 5188 mouclass - ok
13:11:32.0822 5188 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\drivers\mouhid.sys
13:11:32.0844 5188 mouhid - ok
13:11:32.0930 5188 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
13:11:32.0939 5188 mountmgr - ok
13:11:32.0955 5188 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
13:11:32.0965 5188 mpio - ok
13:11:33.0041 5188 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
13:11:33.0082 5188 mpsdrv - ok
13:11:33.0164 5188 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
13:11:33.0194 5188 MRxDAV - ok
13:11:33.0278 5188 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
13:11:33.0308 5188 mrxsmb - ok
13:11:33.0406 5188 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
13:11:33.0435 5188 mrxsmb10 - ok
13:11:33.0525 5188 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
13:11:33.0537 5188 mrxsmb20 - ok
13:11:33.0552 5188 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\DRIVERS\msahci.sys
13:11:33.0559 5188 msahci - ok
13:11:33.0642 5188 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
13:11:33.0651 5188 msdsm - ok
13:11:33.0740 5188 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
13:11:33.0773 5188 Msfs - ok
13:11:33.0815 5188 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
13:11:33.0860 5188 mshidkmdf - ok
13:11:34.0003 5188 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
13:11:34.0011 5188 msisadrv - ok
13:11:34.0169 5188 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
13:11:34.0259 5188 MSKSSRV - ok
13:11:34.0356 5188 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
13:11:34.0400 5188 MSPCLOCK - ok
13:11:34.0483 5188 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
13:11:34.0527 5188 MSPQM - ok
13:11:34.0610 5188 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
13:11:34.0625 5188 MsRPC - ok
13:11:34.0633 5188 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
13:11:34.0641 5188 mssmbios - ok
13:11:34.0744 5188 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
13:11:34.0778 5188 MSTEE - ok
13:11:34.0807 5188 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\drivers\MTConfig.sys
13:11:34.0828 5188 MTConfig - ok
13:11:34.0886 5188 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
13:11:34.0896 5188 Mup - ok
13:11:35.0043 5188 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
13:11:35.0077 5188 NativeWifiP - ok
13:11:35.0213 5188 NAVENG (2dbe90210de76be6e1653bb20ec70ec2) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20120309.034\ENG64.SYS
13:11:35.0222 5188 NAVENG - ok
13:11:35.0359 5188 NAVEX15 (346da70e203b8e2c850277713de8f71b) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20120309.034\EX64.SYS
13:11:35.0404 5188 NAVEX15 - ok
13:11:35.0524 5188 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
13:11:35.0550 5188 NDIS - ok
13:11:35.0641 5188 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
13:11:35.0687 5188 NdisCap - ok
13:11:35.0780 5188 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
13:11:35.0831 5188 NdisTapi - ok
13:11:35.0924 5188 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
13:11:35.0973 5188 Ndisuio - ok
13:11:36.0056 5188 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
13:11:36.0143 5188 NdisWan - ok
13:11:36.0240 5188 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
13:11:36.0272 5188 NDProxy - ok
13:11:36.0337 5188 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
13:11:36.0386 5188 NetBIOS - ok
13:11:36.0481 5188 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
13:11:36.0517 5188 NetBT - ok
13:11:36.0897 5188 NETwNs64 (ac69618de5bcce8747c9ab0aae1003c1) C:\windows\system32\DRIVERS\NETwNs64.sys
13:11:37.0219 5188 NETwNs64 - ok
13:11:37.0339 5188 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\drivers\nfrd960.sys
13:11:37.0347 5188 nfrd960 - ok
13:11:37.0438 5188 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
13:11:37.0491 5188 Npfs - ok
13:11:37.0574 5188 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
13:11:37.0619 5188 nsiproxy - ok
13:11:37.0728 5188 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
13:11:37.0769 5188 Ntfs - ok
13:11:37.0855 5188 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
13:11:37.0914 5188 Null - ok
13:11:38.0001 5188 nusb3hub (0ebc9d13cd96c15b1b18d8678a609e4b) C:\windows\system32\DRIVERS\nusb3hub.sys
13:11:38.0034 5188 nusb3hub - ok
13:11:38.0133 5188 nusb3xhc (7bdec000d56d485021d9c1e63c2f81ca) C:\windows\system32\DRIVERS\nusb3xhc.sys
13:11:38.0182 5188 nusb3xhc - ok
13:11:38.0286 5188 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
13:11:38.0296 5188 nvraid - ok
13:11:38.0304 5188 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
13:11:38.0315 5188 nvstor - ok
13:11:38.0390 5188 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
13:11:38.0403 5188 nv_agp - ok
13:11:38.0427 5188 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
13:11:38.0446 5188 ohci1394 - ok
13:11:38.0533 5188 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\drivers\parport.sys
13:11:38.0546 5188 Parport - ok
13:11:38.0566 5188 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
13:11:38.0574 5188 partmgr - ok
13:11:38.0646 5188 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
13:11:38.0657 5188 pci - ok
13:11:38.0676 5188 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys
13:11:38.0683 5188 pciide - ok
13:11:38.0709 5188 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\drivers\pcmcia.sys
13:11:38.0721 5188 pcmcia - ok
13:11:38.0806 5188 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
13:11:38.0814 5188 pcw - ok
13:11:38.0834 5188 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
13:11:38.0889 5188 PEAUTH - ok
13:11:39.0011 5188 PGEffect (91111cebbde8015e822c46120ed9537c) C:\windows\system32\DRIVERS\pgeffect.sys
13:11:39.0019 5188 PGEffect - ok
13:11:39.0137 5188 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
13:11:39.0185 5188 PptpMiniport - ok
13:11:39.0266 5188 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\drivers\processr.sys
13:11:39.0297 5188 Processor - ok
13:11:39.0398 5188 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
13:11:39.0448 5188 Psched - ok
13:11:39.0557 5188 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\drivers\ql2300.sys
13:11:39.0592 5188 ql2300 - ok
13:11:39.0667 5188 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\drivers\ql40xx.sys
13:11:39.0681 5188 ql40xx - ok
13:11:39.0706 5188 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
13:11:39.0740 5188 QWAVEdrv - ok
13:11:39.0843 5188 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
13:11:39.0897 5188 RasAcd - ok
13:11:39.0998 5188 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
13:11:40.0035 5188 RasAgileVpn - ok
13:11:40.0122 5188 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
13:11:40.0174 5188 Rasl2tp - ok
13:11:40.0330 5188 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
13:11:40.0385 5188 RasPppoe - ok
13:11:40.0481 5188 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
13:11:40.0536 5188 RasSstp - ok
13:11:40.0630 5188 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
13:11:40.0673 5188 rdbss - ok
13:11:40.0768 5188 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\drivers\rdpbus.sys
13:11:40.0791 5188 rdpbus - ok
13:11:40.0876 5188 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
13:11:40.0934 5188 RDPCDD - ok
13:11:41.0020 5188 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
13:11:41.0073 5188 RDPENCDD - ok
13:11:41.0158 5188 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
13:11:41.0200 5188 RDPREFMP - ok
13:11:41.0227 5188 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\windows\system32\drivers\RDPWD.sys
13:11:41.0268 5188 RDPWD - ok
13:11:41.0357 5188 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
13:11:41.0370 5188 rdyboost - ok
13:11:41.0454 5188 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\windows\system32\drivers\regi.sys
13:11:41.0462 5188 regi - ok
13:11:41.0578 5188 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
13:11:41.0634 5188 rspndr - ok
13:11:41.0733 5188 RTL8167 (6d3c7e7d82d3dc92dc2a8b0df9f20f8a) C:\windows\system32\DRIVERS\Rt64win7.sys
13:11:41.0747 5188 RTL8167 - ok
13:11:41.0846 5188 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
13:11:41.0857 5188 sbp2port - ok
13:11:41.0897 5188 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
13:11:41.0955 5188 scfilter - ok
13:11:42.0040 5188 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\windows\system32\DRIVERS\sdbus.sys
13:11:42.0065 5188 sdbus - ok
13:11:42.0163 5188 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
13:11:42.0228 5188 secdrv - ok
13:11:42.0352 5188 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\drivers\serenum.sys
13:11:42.0374 5188 Serenum - ok
13:11:42.0487 5188 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\drivers\serial.sys
13:11:42.0532 5188 Serial - ok
13:11:42.0631 5188 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\drivers\sermouse.sys
13:11:42.0681 5188 sermouse - ok
13:11:42.0708 5188 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
13:11:42.0724 5188 sffdisk - ok
13:11:42.0810 5188 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
13:11:42.0839 5188 sffp_mmc - ok
13:11:42.0921 5188 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
13:11:42.0948 5188 sffp_sd - ok
13:11:43.0032 5188 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\drivers\sfloppy.sys
13:11:43.0053 5188 sfloppy - ok
13:11:43.0157 5188 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\drivers\SiSRaid2.sys
13:11:43.0166 5188 SiSRaid2 - ok
13:11:43.0174 5188 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\drivers\sisraid4.sys
13:11:43.0184 5188 SiSRaid4 - ok
13:11:43.0283 5188 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
13:11:43.0326 5188 Smb - ok
13:11:43.0428 5188 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
13:11:43.0436 5188 spldr - ok
13:11:43.0646 5188 SRTSP (4d56f175f76c685a06471800a03219b2) C:\windows\System32\Drivers\NISx64\1305000.091\SRTSP64.SYS
13:11:43.0667 5188 SRTSP - ok
13:11:43.0800 5188 SRTSPX (7b02f64dc80c0ec7300af302ed5d1cb3) C:\windows\system32\drivers\NISx64\1305000.091\SRTSPX64.SYS
13:11:43.0808 5188 SRTSPX - ok
13:11:43.0897 5188 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
13:11:43.0933 5188 srv - ok
13:11:44.0011 5188 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
13:11:44.0040 5188 srv2 - ok
13:11:44.0727 5188 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
13:11:44.0749 5188 srvnet - ok
13:11:44.0867 5188 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\drivers\stexstor.sys
13:11:44.0878 5188 stexstor - ok
13:11:44.0981 5188 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
13:11:44.0989 5188 swenum - ok
13:11:45.0101 5188 SymDS (8b2430762099598da40686f754632efd) C:\windows\system32\drivers\NISx64\1305000.091\SYMDS64.SYS
13:11:45.0120 5188 SymDS - ok
13:11:45.0300 5188 SymEFA (f90c7a190399165d3ab2245048d34786) C:\windows\system32\drivers\NISx64\1305000.091\SYMEFA64.SYS
13:11:45.0326 5188 SymEFA - ok
13:11:45.0417 5188 SymEvent (898bb48c797483420df523b2bbc1ecdb) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
13:11:45.0425 5188 SymEvent - ok
13:11:45.0517 5188 SymIRON (5013a76caaa1d7cf1c55214b490b4e35) C:\windows\system32\drivers\NISx64\1305000.091\Ironx64.SYS
13:11:45.0526 5188 SymIRON - ok
13:11:45.0673 5188 SymNetS (3911bd0e68c010e5438a87706abbe9ab) C:\windows\System32\Drivers\NISx64\1305000.091\SYMNETS.SYS
13:11:45.0687 5188 SymNetS - ok
13:11:45.0804 5188 SynTP (f5b46df59feaa48a442aed7eeb754d4b) C:\windows\system32\DRIVERS\SynTP.sys
13:11:45.0830 5188 SynTP - ok
13:11:45.0963 5188 Tcpip (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
13:11:46.0005 5188 Tcpip - ok
13:11:46.0475 5188 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
13:11:46.0510 5188 TCPIP6 - ok
13:11:46.0606 5188 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
13:11:46.0645 5188 tcpipreg - ok
13:11:46.0738 5188 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys
13:11:46.0745 5188 tdcmdpst - ok
13:11:46.0778 5188 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
13:11:46.0814 5188 TDPIPE - ok
13:11:46.0911 5188 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys
13:11:46.0952 5188 TDTCP - ok
13:11:47.0039 5188 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
13:11:47.0071 5188 tdx - ok
13:11:47.0160 5188 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
13:11:47.0171 5188 TermDD - ok
13:11:47.0273 5188 Thpdrv (7f35ca8296a52c7161088eb1d952e8ed) C:\windows\system32\DRIVERS\thpdrv.sys
13:11:47.0279 5188 Thpdrv - ok
13:11:47.0382 5188 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS
13:11:47.0391 5188 Thpevm - ok
13:11:47.0526 5188 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\windows\system32\DRIVERS\tos_sps64.sys
13:11:47.0544 5188 tos_sps64 - ok
13:11:47.0637 5188 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
13:11:47.0684 5188 tssecsrv - ok
13:11:47.0784 5188 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
13:11:47.0803 5188 TsUsbFlt - ok
13:11:47.0907 5188 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\windows\system32\drivers\TsUsbGD.sys
13:11:47.0935 5188 TsUsbGD - ok
13:11:48.0031 5188 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
13:11:48.0373 5188 tunnel - ok
13:11:48.0494 5188 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS
13:11:48.0501 5188 TVALZ - ok
13:11:48.0564 5188 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys
13:11:48.0571 5188 TVALZFL - ok
13:11:48.0654 5188 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\drivers\uagp35.sys
13:11:48.0664 5188 uagp35 - ok
13:11:48.0730 5188 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
13:11:48.0805 5188 udfs - ok
13:11:48.0907 5188 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
13:11:48.0916 5188 uliagpkx - ok
13:11:49.0022 5188 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\DRIVERS\umbus.sys
13:11:49.0042 5188 umbus - ok
13:11:49.0119 5188 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\drivers\umpass.sys
13:11:49.0137 5188 UmPass - ok
13:11:49.0237 5188 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
13:11:49.0265 5188 usbccgp - ok
13:11:49.0375 5188 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
13:11:49.0402 5188 usbcir - ok
13:11:49.0493 5188 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\DRIVERS\usbehci.sys
13:11:49.0515 5188 usbehci - ok
13:11:49.0603 5188 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\drivers\usbhub.sys
13:11:49.0631 5188 usbhub - ok
13:11:49.0746 5188 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
13:11:49.0814 5188 usbohci - ok
13:11:49.0907 5188 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\drivers\usbprint.sys
13:11:49.0974 5188 usbprint - ok
13:11:50.0075 5188 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
13:11:50.0109 5188 USBSTOR - ok
13:11:50.0194 5188 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
13:11:50.0212 5188 usbuhci - ok
13:11:50.0321 5188 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\windows\system32\Drivers\usbvideo.sys
13:11:50.0336 5188 usbvideo - ok
13:11:50.0422 5188 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
13:11:50.0430 5188 vdrvroot - ok
13:11:50.0527 5188 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
13:11:50.0540 5188 vga - ok
13:11:50.0561 5188 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
13:11:50.0600 5188 VgaSave - ok
13:11:50.0687 5188 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
13:11:50.0699 5188 vhdmp - ok
13:11:50.0768 5188 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
13:11:50.0777 5188 viaide - ok
13:11:50.0800 5188 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
13:11:50.0808 5188 volmgr - ok
13:11:50.0893 5188 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
13:11:50.0907 5188 volmgrx - ok
13:11:50.0998 5188 volsnap (df8126bd41180351a093a3ad2fc8903b) C:\windows\system32\drivers\volsnap.sys
13:11:51.0010 5188 volsnap - ok
13:11:51.0103 5188 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\drivers\vsmraid.sys
13:11:51.0113 5188 vsmraid - ok
13:11:51.0205 5188 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
13:11:51.0232 5188 vwifibus - ok
13:11:51.0322 5188 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
13:11:51.0351 5188 vwififlt - ok
13:11:51.0450 5188 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys
13:11:51.0466 5188 vwifimp - ok
13:11:51.0491 5188 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\drivers\wacompen.sys
13:11:51.0510 5188 WacomPen - ok
13:11:51.0603 5188 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
13:11:51.0645 5188 WANARP - ok
13:11:51.0656 5188 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
13:11:51.0686 5188 Wanarpv6 - ok
13:11:51.0778 5188 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\drivers\wd.sys
13:11:51.0786 5188 Wd - ok
13:11:51.0809 5188 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
13:11:51.0827 5188 Wdf01000 - ok
13:11:51.0930 5188 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
13:11:51.0960 5188 WfpLwf - ok
13:11:52.0041 5188 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
13:11:52.0050 5188 WIMMount - ok
13:11:52.0186 5188 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
13:11:52.0202 5188 WmiAcpi - ok
13:11:52.0358 5188 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
13:11:52.0387 5188 ws2ifsl - ok
13:11:52.0415 5188 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
13:11:52.0466 5188 WudfPf - ok
13:11:52.0554 5188 WUDFRd (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
13:11:52.0595 5188 WUDFRd - ok
13:11:52.0635 5188 MBR (0x1B8) (849e52748aab5959bc8000cb4974bc13) \Device\Harddisk0\DR0
13:11:52.0698 5188 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - infected
13:11:52.0699 5188 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.b (0)
13:11:53.0057 5188 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
13:11:53.0057 5188 \Device\Harddisk0\DR0 - detected TDSS File System (1)
13:11:53.0076 5188 Boot (0x1200) (b5865bc2c1b6137f066dacb716eb8c7d) \Device\Harddisk0\DR0\Partition0
13:11:53.0077 5188 \Device\Harddisk0\DR0\Partition0 - ok
13:11:53.0077 5188 ============================================================
13:11:53.0077 5188 Scan finished
13:11:53.0077 5188 ============================================================
13:11:53.0087 3264 Detected object count: 2
13:11:53.0087 3264 Actual detected object count: 2
13:13:04.0317 3264 \Device\Harddisk0\DR0\# - copied to quarantine
13:13:04.0318 3264 \Device\Harddisk0\DR0 - copied to quarantine
13:13:04.0348 3264 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
13:13:04.0351 3264 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
13:13:04.0355 3264 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
13:13:04.0358 3264 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
13:13:04.0369 3264 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
13:13:04.0376 3264 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
13:13:04.0377 3264 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
13:13:04.0378 3264 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
13:13:04.0380 3264 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
13:13:04.0383 3264 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
13:13:04.0386 3264 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
13:13:04.0388 3264 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
13:13:04.0427 3264 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
13:13:04.0428 3264 \Device\Harddisk0\DR0 - ok
13:13:04.0538 3264 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
13:13:04.0538 3264 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
13:13:04.0539 3264 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
13:13:21.0582 6812 Deinitialize success

Edited by kaybli, 11 March 2012 - 11:23 AM.

  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK that got it - this should be the last run

Re-run TDSSKiller and when it reaches the following part select delete :

\Device\Harddisk0\DR0 ( TDSS File System )

Then re-run MBAM and post the resultant log please with an update on how the computer is behaving
  • 0

#9
kaybli

kaybli

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I ran MBAM and it said no threats detected:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.11.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
kaybli2 :: KAYBLI2-PC [administrator]

3/11/2012 1:40:03 PM
mbam-log-2012-03-11 (13-40-03).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 188231
Time elapsed: 2 minute(s), 55 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


Thank you so much! I sent you 50 bucks (31.91 pounds). Did you receive it?
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Yes, thank you very much.. :thumbsup:

I will remove my tools and the like now, but monitor the system for the next day or so

Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK

    Posted Image
  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. With the exception of aswMBR - just delete that from the desktop

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point
  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create

Now we can purge the infected ones
  • GoStart > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
Posted Image
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

Keep safe :wave:
  • 0

#11
kaybli

kaybli

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
Thank you very much! You are the man!

Posted Image
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
My pleasure - keep safe now ;)
  • 0

#13
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP