Ok, the quick launch icons have not reappeared in the lower pane of the screen.
The Desktop however, is now showing 4 new items: 1 folder "SKYNET" and 3 semi transparent files, 2 "desktop.ini" files and 1 "Thumbs.db" file. Possibly hidden files?
Here are the logs from the scans.
OTL logOTL logfile created on: 3/20/2012 9:56:24 PM - Run 2
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Users\hp\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.60 Gb Available Physical Memory | 69.49% Memory free
7.49 Gb Paging File | 6.30 Gb Available in Paging File | 84.12% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.17 Gb Total Space | 39.11 Gb Free Space | 13.71% Space Free | Partition Type: NTFS
Drive D: | 12.91 Gb Total Space | 2.01 Gb Free Space | 15.61% Space Free | Partition Type: NTFS
Computer Name: HP-PC | User Name: hp | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/03/19 05:18:01 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\hp\Desktop\OTL.exe
PRC - [2012/03/19 04:49:03 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/11/15 03:15:02 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\nlssrv32.exe
PRC - [2010/12/20 18:59:25 | 000,181,312 | ---- | M] () -- C:\Program Files (x86)\Photodex\ProShowProducer\scsiaccess.exe
PRC - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2008/10/06 06:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files (x86)\SMINST\BLService.exe
PRC - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) -- C:\Windows\SysWOW64\IoctlSvc.exe
PRC - [2006/09/19 09:07:28 | 000,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Modules (No Company Name) ========== MOD - [2012/03/19 04:49:03 | 001,969,080 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/02/23 23:51:23 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2006/09/19 09:07:28 | 000,827,392 | ---- | M] () -- C:\Windows\vsnpstd3.exe
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2011/05/04 07:55:09 | 000,128,384 | ---- | M] (SUPERAntiSpyware.com) [Disabled | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:
64bit: - [2010/08/19 17:43:24 | 000,386,344 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64) Cyberlink RichVideo64 Service(CRVS)
SRV:
64bit: - [2010/07/16 15:03:58 | 000,030,520 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Windows\SysNative\hpservice.exe -- (hpsrv)
SRV:
64bit: - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\stacsv64.exe -- (STacSV)
SRV:
64bit: - [2009/11/16 09:12:56 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV:
64bit: - [2009/11/16 09:04:30 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV:
64bit: - [2009/08/18 02:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2009/07/13 15:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
SRV:
64bit: - [2008/08/26 19:02:20 | 000,016,896 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Program Files\LSI SoftModem\agr64svc.exe -- (AgereModemAudio)
SRV - [2011/11/15 03:15:02 | 000,066,560 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\nlssrv32.exe -- (nlsX86cc)
SRV - [2011/01/14 14:53:48 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/12/20 18:59:25 | 000,181,312 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Photodex\ProShowProducer\scsiaccess.exe -- (ScsiAccess)
SRV - [2010/03/23 14:53:06 | 000,247,808 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\STacSV64.exe -- (STacSV)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/04 13:00:56 | 000,025,704 | R--- | M] (Amazon.com) [Disabled | Stopped] -- C:\Program Files (x86)\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe -- (ADVService)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 11:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/03/02 18:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_960c1f056a541068\AESTSr64.exe -- (AESTFilters)
SRV - [2008/10/06 06:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/09/24 16:08:26 | 000,296,320 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe -- (TVCapSvc) TV Background Capture Service (TVBCS)
SRV - [2008/09/24 16:08:26 | 000,116,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe -- (TVSched) TV Task Scheduler (TVTS)
SRV - [2006/12/19 10:30:26 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Auto | Running] -- C:\Windows\SysWOW64\IoctlSvc.exe -- (PLFlash DeviceIoControl Service)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2011/12/19 16:41:32 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:
64bit: - [2011/12/19 16:41:32 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:
64bit: - [2011/12/19 16:41:32 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:
64bit: - [2011/08/15 14:51:40 | 000,079,232 | ---- | M] (Fengtao Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dvdfab.sys -- (dvdfab)
DRV:
64bit: - [2011/07/12 11:55:18 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:
64bit: - [2011/07/12 11:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:
64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011/02/10 07:36:12 | 000,848,384 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtl8192cu.sys -- (RTL8192cu)
DRV:
64bit: - [2010/11/20 03:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 03:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/11/20 03:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2010/11/20 01:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/08/26 17:40:56 | 000,186,056 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\C771VSP.sys -- (C771VSP)
DRV:
64bit: - [2010/08/26 17:40:56 | 000,071,752 | ---- | M] (DEVGURU Co., LTD.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\C771BUS.sys -- (C771BUS)
DRV:
64bit: - [2010/07/16 15:04:04 | 000,030,008 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\hpdskflt.sys -- (hpdskflt)
DRV:
64bit: - [2010/07/16 15:03:48 | 000,043,320 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Accelerometer.sys -- (Accelerometer)
DRV:
64bit: - [2010/05/27 22:32:56 | 000,320,560 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2010/04/11 22:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:
64bit: - [2010/03/23 14:53:06 | 000,505,344 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:
64bit: - [2009/11/16 09:07:10 | 000,044,944 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:
64bit: - [2009/11/16 09:07:04 | 000,169,080 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:
64bit: - [2009/11/16 09:03:42 | 000,136,584 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:
64bit: - [2009/11/16 08:56:16 | 000,145,336 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:
64bit: - [2009/11/10 21:48:22 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin)
DRV:
64bit: - [2009/11/04 02:58:42 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (HID)
DRV:
64bit: - [2009/10/09 02:41:02 | 001,394,176 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:
64bit: - [2009/09/02 03:09:34 | 000,221,696 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009/08/18 03:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2009/07/13 15:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 15:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 15:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2009/07/13 15:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/19 08:10:40 | 000,033,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:
64bit: - [2009/06/10 10:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 10:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 10:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 10:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2009/05/09 01:14:20 | 000,015,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr)
DRV:
64bit: - [2009/02/13 11:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:
64bit: - [2008/11/21 22:05:22 | 001,253,376 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2008/07/21 00:53:04 | 000,145,496 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\jmcr.sys -- (JMCR)
DRV:
64bit: - [2008/06/27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:
64bit: - [2008/05/28 15:54:18 | 000,026,168 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:
64bit: - [2008/04/27 23:25:06 | 000,016,400 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV:
64bit: - [2008/03/14 13:56:26 | 000,133,120 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cm_net.sys -- (cm_net)
DRV:
64bit: - [2008/03/14 13:36:22 | 000,118,272 | ---- | M] (C-motech Co.,Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cm_ser.sys -- (cm_ser)
DRV:
64bit: - [2008/01/24 03:24:24 | 000,060,928 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\enecir.sys -- (enecir)
DRV:
64bit: - [2007/06/18 14:13:12 | 000,018,432 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV:
64bit: - [2007/03/27 18:18:58 | 010,550,272 | ---- | M] (Sonix Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\snpstd3.sys -- (SNPSTD3) USB PC Camera (SNPSTD3)
DRV - [2009/07/13 15:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2008/09/26 00:36:34 | 000,027,632 | ---- | M] (Cyberlink Corp.) [Kernel | Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl -- ({55662437-DA8C-40c0-AADA-2C816A897A49})
DRV - [2004/04/01 16:30:46 | 000,010,368 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\pfc.sys -- (pfc)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...avilion&pf=cnnbIE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...avilion&pf=cnnbIE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {67D7FE62-DD38-48E0-9480-A7D12163F62C}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE:
64bit: - HKLM\..\SearchScopes\{67D7FE62-DD38-48E0-9480-A7D12163F62C}: "URL" =
http://search.live.c...ms}&FORM=HPNTDFIE:
64bit: - HKLM\..\SearchScopes\{ED905251-EDB7-4CA0-AF39-1551C50BCE24}: "URL" =
http://www.ask.com/w...}&l=dis&o=ushplIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {67D7FE62-DD38-48E0-9480-A7D12163F62C}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{67D7FE62-DD38-48E0-9480-A7D12163F62C}: "URL" =
http://search.live.c...ms}&FORM=HPNTDFIE - HKLM\..\SearchScopes\{ED905251-EDB7-4CA0-AF39-1551C50BCE24}: "URL" =
http://www.ask.com/w...}&l=dis&o=ushpl IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...avilion&pf=cnnbIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://mail.google....l/?shva=1#inboxIE - HKCU\..\SearchScopes,DefaultScope = {67D7FE62-DD38-48E0-9480-A7D12163F62C}
IE - HKCU\..\SearchScopes\{67D7FE62-DD38-48E0-9480-A7D12163F62C}: "URL" =
http://www.bing.com/...rc=IE-SearchBoxIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {5c8bfb7c-9a54-11dc-8314-0800200c9a66}:3.6.7
FF - prefs.js..keyword.URL: "
http://www.google.co...ient&gfns=1&q="FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/19 04:49:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/13 14:10:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2009/12/15 23:35:02 | 000,000,000 | ---D | M]
[2010/01/23 22:11:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hp\AppData\Roaming\mozilla\Extensions
[2010/01/23 22:11:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hp\AppData\Roaming\mozilla\Extensions\
[email protected][2012/03/10 21:55:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hp\AppData\Roaming\mozilla\Firefox\Profiles\q2l386qa.default\extensions
[2011/01/07 00:02:12 | 000,000,000 | ---D | M] (Aero Fox XL) -- C:\Users\hp\AppData\Roaming\mozilla\Firefox\Profiles\q2l386qa.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
[2011/12/26 22:50:23 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\hp\AppData\Roaming\mozilla\Firefox\Profiles\q2l386qa.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/09/19 09:47:49 | 000,000,000 | ---D | M] (vShare Plugin) -- C:\Users\hp\AppData\Roaming\mozilla\Firefox\Profiles\q2l386qa.default\extensions\vshare@toolbar
[2011/01/07 00:02:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\hp\AppData\Roaming\mozilla\Firefox\Profiles\q2l386qa.default\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}\chrome\win\mozapps\extensions
[2012/03/19 04:49:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) -- C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\HP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q2L386QA.DEFAULT\EXTENSIONS\{03D3EFE3-332D-4D5C-B69E-565437649F0E}.XPI
() (No name found) -- C:\USERS\HP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q2L386QA.DEFAULT\EXTENSIONS\{C45C406E-AB73-11D8-BE73-000A95BE3B12}.XPI
() (No name found) -- C:\USERS\HP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q2L386QA.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/03/19 04:49:03 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/01/06 22:32:36 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/01/06 22:32:36 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/12/13 15:09:04 | 000,001,349 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 0.0.0.0 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:
64bit: - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe ()
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [DVDFab Passkey] C:\Program Files (x86)\DVDFab Passkey\DVDFabPasskey.exe (Fengtao Software Inc.)
O4 - Startup: C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.14.235.234 67.238.98.162
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72AEDFB1-6F8C-4282-BE96-99B83EA1CA03}: DhcpNameServer = 207.14.235.234 67.238.98.162
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Users\hp\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\hp\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{15e787e8-8fad-11e0-911e-08863b0231c1}\Shell - "" = AutoRun
O33 - MountPoints2\{15e787e8-8fad-11e0-911e-08863b0231c1}\Shell\AutoRun\command - "" = I:\Launcher.exe
O33 - MountPoints2\{253d8245-e514-11de-b22d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{253d8245-e514-11de-b22d-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Launcher.exe
O33 - MountPoints2\{7f2db9e1-4263-11e1-9801-00235a3d2af5}\Shell - "" = AutoRun
O33 - MountPoints2\{7f2db9e1-4263-11e1-9801-00235a3d2af5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\TL-Bootstrap.exe
O33 - MountPoints2\{7f2dbba2-4263-11e1-9801-00235a3d2af5}\Shell - "" = AutoRun
O33 - MountPoints2\{7f2dbba2-4263-11e1-9801-00235a3d2af5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\TL-Bootstrap.exe
O33 - MountPoints2\{a73b1988-3131-11e1-9f2d-00235a3d2af5}\Shell - "" = AutoRun
O33 - MountPoints2\{a73b1988-3131-11e1-9f2d-00235a3d2af5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\TL-Bootstrap.exe
O33 - MountPoints2\{b9d353df-2466-11e1-aeba-00235a3d2af5}\Shell - "" = AutoRun
O33 - MountPoints2\{b9d353df-2466-11e1-aeba-00235a3d2af5}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\TL-Bootstrap.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\AUTORUN.EXE
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/03/20 21:46:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/03/20 21:44:20 | 002,063,920 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\hp\Desktop\tdsskiller.exe
[2012/03/19 22:05:17 | 000,000,000 | ---D | C] -- C:\Users\hp\Desktop\RK_Quarantine
[2012/03/19 05:17:45 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Users\hp\Desktop\OTL.exe
[2012/03/11 09:21:57 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
[2012/03/11 05:14:43 | 000,029,288 | ---- | C] (Wondershare) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys
[2012/03/11 05:13:35 | 000,029,288 | ---- | C] (Wondershare) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys
[2012/03/11 05:12:14 | 000,029,288 | ---- | C] (Wondershare) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys
[2012/03/11 05:12:12 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Local\Aimersoft
[2012/03/11 05:12:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Aimersoft
[2012/03/11 05:12:06 | 000,892,928 | ---- | C] (Free Software Foundation) -- C:\Windows\SysWow64\iconv.dll
[2012/03/11 05:12:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Aimersoft
[2012/03/11 03:57:37 | 000,000,000 | ---D | C] -- C:\Users\hp\Desktop\100GOPRO
[2012/03/08 22:46:03 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Local\Adobe
[2012/03/08 05:06:52 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Local\Apple Computer
[2012/02/23 23:51:20 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2012/02/23 02:06:23 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Roaming\Alien Skin
[2012/02/23 02:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Alien Skin
[2012/02/23 02:00:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Alien Skin
[2012/02/23 02:00:05 | 000,000,000 | ---D | C] -- C:\Program Files\Alien Skin
[2012/02/22 18:34:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Image Trends Inc
[2012/02/22 18:24:52 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Roaming\onOne Software
[2012/02/22 18:09:28 | 000,066,560 | ---- | C] (Nalpeiron Ltd.) -- C:\Windows\SysWow64\nlssrv32.exe
[2012/02/22 18:09:27 | 000,066,560 | ---- | C] (Nalpeiron Ltd.) -- C:\Windows\SysNative\nlssrv32.exe
[2012/02/22 18:09:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onOne Software
[2012/02/22 18:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\onOne Software
[2012/02/22 18:09:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\onOne Software
[2012/02/22 18:09:10 | 000,000,000 | ---D | C] -- C:\ProgramData\onOne Software
[2012/02/22 18:07:37 | 000,000,000 | ---D | C] -- C:\Users\hp\Documents\Photoshop Plugins
[2012/02/22 17:32:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Trends Inc
[2012/02/22 17:32:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Image Trends Inc
[2012/02/22 17:21:47 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Roaming\Nik Software
[2012/02/22 17:16:57 | 000,000,000 | ---D | C] -- C:\Windows\MSSecurityNS
[2012/02/22 17:14:32 | 000,000,000 | ---D | C] -- C:\Windows\MSSecurityNi
[2012/02/22 17:10:22 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Local\Nik Software
[2012/02/22 17:10:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Nik Software
[2012/02/22 17:10:05 | 000,000,000 | ---D | C] -- C:\Program Files\Nik Software
[2012/02/21 04:26:45 | 000,000,000 | ---D | C] -- C:\Users\hp\AppData\Roaming\OpenOffice.org
[2012/02/20 05:05:48 | 000,000,000 | --SD | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.3
[2012/02/20 05:04:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenOffice.org 3
========== Files - Modified Within 30 Days ========== [2012/03/20 21:56:08 | 000,011,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 21:56:08 | 000,011,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/20 21:53:08 | 000,782,154 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/20 21:53:08 | 000,662,722 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/03/20 21:53:08 | 000,121,558 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/03/20 21:48:52 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/20 21:48:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/20 21:48:23 | 3018,190,848 | -HS- | M] () -- C:\hiberfil.sys
[2012/03/20 21:44:54 | 002,063,920 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\hp\Desktop\tdsskiller.exe
[2012/03/20 21:03:01 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/19 05:18:01 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Users\hp\Desktop\OTL.exe
[2012/03/17 12:00:36 | 3524,504,479 | ---- | M] () -- C:\Users\hp\Desktop\Archer.zip
[2012/03/16 02:10:00 | 000,023,552 | ---- | M] () -- C:\Users\hp\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/12 05:18:35 | 015,583,491 | ---- | M] () -- C:\Users\hp\Desktop\Disposable-War.mp3
[2012/03/11 07:51:43 | 000,776,434 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/26 22:42:06 | 009,368,052 | ---- | M] () -- C:\Users\hp\Documents\Jims Story.odt
[2012/02/24 08:18:39 | 000,001,652 | ---- | M] () -- C:\Users\hp\AppData\Roaming\wklnhst.dat
[2012/02/23 23:49:19 | 005,176,136 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/21 04:27:08 | 000,001,235 | ---- | M] () -- C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
========== Files Created - No Company Name ========== [2012/03/19 22:06:55 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012/03/19 22:06:51 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/19 22:06:49 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2012/03/19 22:06:49 | 000,001,147 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2012/03/19 22:06:47 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/03/19 22:06:40 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/03/19 22:06:40 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/03/19 22:06:40 | 000,002,041 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition 3.0.lnk
[2012/03/19 22:06:40 | 000,002,007 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition 1.5.lnk
[2012/03/19 22:06:40 | 000,001,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012/03/19 22:06:40 | 000,001,505 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Pixel Bender Toolkit 2.lnk
[2012/03/19 22:06:40 | 000,001,353 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012/03/19 22:06:40 | 000,001,262 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012/03/19 22:06:40 | 000,001,207 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012/03/19 22:06:40 | 000,001,194 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CS5.lnk
[2012/03/19 22:06:40 | 000,001,169 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012/03/19 22:06:40 | 000,001,090 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CS5.lnk
[2012/03/19 22:06:40 | 000,000,916 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk
[2012/03/17 11:49:14 | 3524,504,479 | ---- | C] () -- C:\Users\hp\Desktop\Archer.zip
[2012/03/12 05:18:34 | 015,583,491 | ---- | C] () -- C:\Users\hp\Desktop\Disposable-War.mp3
[2012/03/11 05:12:06 | 000,675,840 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.ax
[2012/03/11 05:12:06 | 000,496,640 | ---- | C] () -- C:\Windows\SysWow64\xvid.ax
[2012/03/07 21:49:53 | 000,776,434 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/21 04:40:22 | 009,368,052 | ---- | C] () -- C:\Users\hp\Documents\Jims Story.odt
[2012/02/21 04:27:08 | 000,001,235 | ---- | C] () -- C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/12/09 12:32:57 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2011/12/09 12:32:57 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/12/09 12:32:57 | 000,074,752 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/12/09 03:00:24 | 000,326,144 | ---- | C] () -- C:\Windows\SysWow64\Viveza2FC32.dll
[2011/12/07 14:47:26 | 000,326,144 | ---- | C] () -- C:\Windows\SysWow64\HDREfexProFC32.dll
[2011/12/01 14:59:04 | 000,326,144 | ---- | C] () -- C:\Windows\SysWow64\SilverEfexPro2FC32.dll
[2011/11/22 12:16:04 | 000,326,144 | ---- | C] () -- C:\Windows\SysWow64\ColorEfexPro4FC32.dll
[2011/09/21 21:12:41 | 000,012,343 | ---- | C] () -- C:\Users\hp\AppData\Local\tmpIMG_0003_navi.JPG
[2011/09/21 21:12:32 | 001,220,628 | ---- | C] () -- C:\Users\hp\AppData\Local\tmpIMG_0003.0
[2011/09/21 21:12:32 | 000,786,639 | ---- | C] () -- C:\Users\hp\AppData\Local\tmpIMG_0003.JPG
[2011/06/04 15:34:39 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2010/08/09 00:03:49 | 000,001,652 | ---- | C] () -- C:\Users\hp\AppData\Roaming\wklnhst.dat
[2010/07/14 23:30:36 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
========== LOP Check ========== [2012/03/20 21:48:42 | 000,032,616 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== < End of report >
TDSSKILLER LOG22:01:58.0581 2160 TDSS rootkit removing tool 2.7.20.0 Mar 9 2012 17:10:43
22:02:00.0606 2160 ============================================================
22:02:00.0606 2160 Current date / time: 2012/03/20 22:02:00.0606
22:02:00.0606 2160 SystemInfo:
22:02:00.0606 2160
22:02:00.0606 2160 OS Version: 6.1.7601 ServicePack: 1.0
22:02:00.0606 2160 Product type: Workstation
22:02:00.0606 2160 ComputerName: HP-PC
22:02:00.0606 2160 UserName: hp
22:02:00.0606 2160 Windows directory: C:\Windows
22:02:00.0606 2160 System windows directory: C:\Windows
22:02:00.0606 2160 Running under WOW64
22:02:00.0606 2160 Processor architecture: Intel x64
22:02:00.0606 2160 Number of processors: 2
22:02:00.0606 2160 Page size: 0x1000
22:02:00.0606 2160 Boot type: Normal boot
22:02:00.0606 2160 ============================================================
22:02:01.0949 2160 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:02:01.0955 2160 \Device\Harddisk0\DR0:
22:02:01.0955 2160 MBR used
22:02:01.0955 2160 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x23A59000
22:02:01.0955 2160 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x23A59800, BlocksNum 0x19D02B0
22:02:02.0052 2160 Initialize success
22:02:02.0052 2160 ============================================================
22:02:40.0424 3788 ============================================================
22:02:40.0424 3788 Scan started
22:02:40.0424 3788 Mode: Manual; SigCheck; TDLFS;
22:02:40.0424 3788 ============================================================
22:02:41.0017 3788 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
22:02:41.0145 3788 1394ohci - ok
22:02:41.0203 3788 Accelerometer (3e2427d4966c7606097341e55ab4e105) C:\Windows\system32\DRIVERS\Accelerometer.sys
22:02:41.0267 3788 Accelerometer - ok
22:02:41.0428 3788 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
22:02:41.0447 3788 ACPI - ok
22:02:41.0513 3788 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
22:02:41.0571 3788 AcpiPmi - ok
22:02:41.0769 3788 adfs (2f0683fd2df1d92e891caca14b45a8c1) C:\Windows\system32\drivers\adfs.sys
22:02:41.0780 3788 adfs - ok
22:02:41.0879 3788 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
22:02:41.0934 3788 adp94xx - ok
22:02:41.0983 3788 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
22:02:42.0034 3788 adpahci - ok
22:02:42.0190 3788 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
22:02:42.0207 3788 adpu320 - ok
22:02:42.0329 3788 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
22:02:42.0392 3788 AFD - ok
22:02:42.0602 3788 AgereSoftModem (70e15cda25e151dfc60636ef73f5a7be) C:\Windows\system32\DRIVERS\agrsm64.sys
22:02:42.0668 3788 AgereSoftModem - ok
22:02:42.0872 3788 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
22:02:42.0884 3788 agp440 - ok
22:02:42.0924 3788 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
22:02:42.0935 3788 aliide - ok
22:02:42.0981 3788 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
22:02:42.0992 3788 amdide - ok
22:02:43.0077 3788 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
22:02:43.0128 3788 AmdK8 - ok
22:02:43.0299 3788 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
22:02:43.0354 3788 AmdPPM - ok
22:02:43.0444 3788 amdsata (6ec6d772eae38dc17c14aed9b178d24b) C:\Windows\system32\drivers\amdsata.sys
22:02:43.0456 3788 amdsata - ok
22:02:43.0487 3788 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
22:02:43.0519 3788 amdsbs - ok
22:02:43.0667 3788 amdxata (1142a21db581a84ea5597b03a26ebaa0) C:\Windows\system32\drivers\amdxata.sys
22:02:43.0695 3788 amdxata - ok
22:02:43.0768 3788 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
22:02:43.0828 3788 AppID - ok
22:02:44.0021 3788 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
22:02:44.0050 3788 arc - ok
22:02:44.0070 3788 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
22:02:44.0085 3788 arcsas - ok
22:02:44.0135 3788 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
22:02:44.0219 3788 AsyncMac - ok
22:02:44.0369 3788 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
22:02:44.0380 3788 atapi - ok
22:02:44.0484 3788 athr (8c56e93749ba53a4b645963d3439e01e) C:\Windows\system32\DRIVERS\athrx.sys
22:02:44.0543 3788 athr - ok
22:02:44.0850 3788 atikmdag (52bd95caa9cae8977fe043e9ad6d2d0e) C:\Windows\system32\DRIVERS\atikmdag.sys
22:02:45.0105 3788 atikmdag - ok
22:02:45.0296 3788 AtiPcie (db0d3de15edc96e7529fc0d3f7760894) C:\Windows\system32\DRIVERS\AtiPcie.sys
22:02:45.0305 3788 AtiPcie - ok
22:02:45.0407 3788 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
22:02:45.0452 3788 b06bdrv - ok
22:02:45.0628 3788 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
22:02:45.0685 3788 b57nd60a - ok
22:02:45.0729 3788 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
22:02:45.0804 3788 Beep - ok
22:02:46.0036 3788 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
22:02:46.0082 3788 blbdrive - ok
22:02:46.0166 3788 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
22:02:46.0217 3788 bowser - ok
22:02:46.0386 3788 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:02:46.0432 3788 BrFiltLo - ok
22:02:46.0459 3788 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:02:46.0479 3788 BrFiltUp - ok
22:02:46.0513 3788 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
22:02:46.0584 3788 Brserid - ok
22:02:46.0608 3788 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
22:02:46.0659 3788 BrSerWdm - ok
22:02:46.0870 3788 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:02:46.0924 3788 BrUsbMdm - ok
22:02:46.0952 3788 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
22:02:46.0984 3788 BrUsbSer - ok
22:02:47.0024 3788 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
22:02:47.0079 3788 BTHMODEM - ok
22:02:47.0294 3788 C771BUS (00729a4d11a86dfdb3b300d70df0f0b1) C:\Windows\system32\DRIVERS\C771BUS.sys
22:02:47.0305 3788 C771BUS - ok
22:02:47.0379 3788 C771VSP (5a8c764aa501f1df15121b0b0b2d3fcb) C:\Windows\system32\DRIVERS\C771VSP.sys
22:02:47.0408 3788 C771VSP - ok
22:02:47.0479 3788 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
22:02:47.0542 3788 cdfs - ok
22:02:47.0727 3788 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
22:02:47.0779 3788 cdrom - ok
22:02:47.0866 3788 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
22:02:47.0908 3788 circlass - ok
22:02:48.0053 3788 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
22:02:48.0105 3788 CLFS - ok
22:02:48.0205 3788 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
22:02:48.0237 3788 CmBatt - ok
22:02:48.0289 3788 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
22:02:48.0300 3788 cmdide - ok
22:02:48.0465 3788 cm_net (f749e9cabb1572649715ec69bd68ca4e) C:\Windows\system32\DRIVERS\cm_net.sys
22:02:48.0508 3788 cm_net - ok
22:02:48.0544 3788 cm_ser (e9e160fed596d6555de17bc7a78aa424) C:\Windows\system32\DRIVERS\cm_ser.sys
22:02:48.0612 3788 cm_ser - ok
22:02:48.0659 3788 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
22:02:48.0720 3788 CNG - ok
22:02:48.0877 3788 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
22:02:48.0913 3788 Compbatt - ok
22:02:48.0966 3788 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
22:02:49.0020 3788 CompositeBus - ok
22:02:49.0069 3788 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
22:02:49.0082 3788 crcdisk - ok
22:02:49.0292 3788 dc3d (db0459afd124ce5ccb649e33f95d715f) C:\Windows\system32\DRIVERS\dc3d.sys
22:02:49.0357 3788 dc3d - ok
22:02:49.0545 3788 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
22:02:49.0609 3788 DfsC - ok
22:02:49.0673 3788 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
22:02:49.0764 3788 discache - ok
22:02:49.0952 3788 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
22:02:49.0981 3788 Disk - ok
22:02:50.0055 3788 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
22:02:50.0094 3788 drmkaud - ok
22:02:50.0178 3788 dvdfab (eee504899a0cc781f09cf003ca897771) C:\Windows\system32\drivers\dvdfab.sys
22:02:50.0191 3788 dvdfab - ok
22:02:50.0379 3788 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
22:02:50.0407 3788 DXGKrnl - ok
22:02:50.0570 3788 eamon (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
22:02:50.0599 3788 eamon - ok
22:02:50.0718 3788 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
22:02:50.0876 3788 ebdrv - ok
22:02:51.0041 3788 ehdrv (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
22:02:51.0052 3788 ehdrv - ok
22:02:51.0148 3788 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
22:02:51.0173 3788 elxstor - ok
22:02:51.0344 3788 enecir (3a70dc8951b995c73a22b9a23210833e) C:\Windows\system32\DRIVERS\enecir.sys
22:02:51.0376 3788 enecir - ok
22:02:51.0425 3788 epfw (99698ff43533c0fdc75967d48001c25f) C:\Windows\system32\DRIVERS\epfw.sys
22:02:51.0455 3788 epfw - ok
22:02:51.0475 3788 Epfwndis (be1f150790123e1077cf95990394339d) C:\Windows\system32\DRIVERS\Epfwndis.sys
22:02:51.0485 3788 Epfwndis - ok
22:02:51.0644 3788 epfwwfp (6eb1d07c86913ad53ec5afa67b9453fd) C:\Windows\system32\DRIVERS\epfwwfp.sys
22:02:51.0670 3788 epfwwfp - ok
22:02:51.0723 3788 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
22:02:51.0790 3788 ErrDev - ok
22:02:51.0974 3788 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
22:02:52.0069 3788 exfat - ok
22:02:52.0095 3788 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
22:02:52.0187 3788 fastfat - ok
22:02:52.0233 3788 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
22:02:52.0299 3788 fdc - ok
22:02:52.0463 3788 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
22:02:52.0492 3788 FileInfo - ok
22:02:52.0509 3788 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
22:02:52.0596 3788 Filetrace - ok
22:02:52.0656 3788 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
22:02:52.0688 3788 flpydisk - ok
22:02:52.0907 3788 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
22:02:52.0957 3788 FltMgr - ok
22:02:53.0025 3788 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
22:02:53.0054 3788 FsDepends - ok
22:02:53.0070 3788 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
22:02:53.0098 3788 Fs_Rec - ok
22:02:53.0157 3788 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
22:02:53.0208 3788 fvevol - ok
22:02:53.0402 3788 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:02:53.0461 3788 gagp30kx - ok
22:02:53.0541 3788 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
22:02:53.0552 3788 GEARAspiWDM - ok
22:02:53.0804 3788 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
22:02:53.0844 3788 hcw85cir - ok
22:02:53.0925 3788 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
22:02:53.0968 3788 HdAudAddService - ok
22:02:54.0019 3788 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
22:02:54.0058 3788 HDAudBus - ok
22:02:54.0199 3788 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
22:02:54.0246 3788 HidBatt - ok
22:02:54.0267 3788 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
22:02:54.0327 3788 HidBth - ok
22:02:54.0365 3788 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
22:02:54.0436 3788 HidIr - ok
22:02:54.0630 3788 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
22:02:54.0673 3788 HidUsb - ok
22:02:54.0731 3788 hpdskflt (ccbe758967cc0f53f5ba3b271653c4e6) C:\Windows\system32\DRIVERS\hpdskflt.sys
22:02:54.0742 3788 hpdskflt - ok
22:02:54.0800 3788 HpqKbFiltr (0ecc54fd34d6a089c300846b011e81d6) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
22:02:54.0834 3788 HpqKbFiltr - ok
22:02:55.0051 3788 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
22:02:55.0063 3788 HpSAMD - ok
22:02:55.0157 3788 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
22:02:55.0236 3788 HTTP - ok
22:02:55.0382 3788 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
22:02:55.0409 3788 hwpolicy - ok
22:02:55.0457 3788 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
22:02:55.0490 3788 i8042prt - ok
22:02:55.0567 3788 iaStorV (3df4395a7cf8b7a72a5f4606366b8c2d) C:\Windows\system32\drivers\iaStorV.sys
22:02:55.0589 3788 iaStorV - ok
22:02:55.0651 3788 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
22:02:55.0664 3788 iirsp - ok
22:02:55.0818 3788 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
22:02:55.0829 3788 intelide - ok
22:02:55.0866 3788 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
22:02:55.0919 3788 intelppm - ok
22:02:55.0968 3788 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:02:56.0024 3788 IpFilterDriver - ok
22:02:56.0073 3788 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
22:02:56.0089 3788 IPMIDRV - ok
22:02:56.0251 3788 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
22:02:56.0338 3788 IPNAT - ok
22:02:56.0406 3788 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
22:02:56.0455 3788 IRENUM - ok
22:02:56.0629 3788 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
22:02:56.0640 3788 isapnp - ok
22:02:56.0691 3788 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
22:02:56.0709 3788 iScsiPrt - ok
22:02:56.0760 3788 JMCR (15371306d1adbbf35e475c8da516a956) C:\Windows\system32\DRIVERS\jmcr.sys
22:02:56.0803 3788 JMCR - ok
22:02:56.0870 3788 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
22:02:56.0881 3788 kbdclass - ok
22:02:57.0049 3788 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
22:02:57.0082 3788 kbdhid - ok
22:02:57.0141 3788 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
22:02:57.0156 3788 KSecDD - ok
22:02:57.0208 3788 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
22:02:57.0224 3788 KSecPkg - ok
22:02:57.0285 3788 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
22:02:57.0366 3788 ksthunk - ok
22:02:57.0580 3788 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
22:02:57.0661 3788 lltdio - ok
22:02:57.0721 3788 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:02:57.0751 3788 LSI_FC - ok
22:02:57.0770 3788 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:02:57.0800 3788 LSI_SAS - ok
22:02:57.0824 3788 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:02:57.0853 3788 LSI_SAS2 - ok
22:02:58.0007 3788 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:02:58.0037 3788 LSI_SCSI - ok
22:02:58.0074 3788 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
22:02:58.0143 3788 luafv - ok
22:02:58.0296 3788 Maplom - ok
22:02:58.0308 3788 MaplomL - ok
22:02:58.0360 3788 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
22:02:58.0403 3788 megasas - ok
22:02:58.0435 3788 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
22:02:58.0472 3788 MegaSR - ok
22:02:58.0508 3788 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
22:02:58.0553 3788 Modem - ok
22:02:58.0616 3788 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
22:02:58.0657 3788 monitor - ok
22:02:58.0829 3788 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
22:02:58.0841 3788 mouclass - ok
22:02:58.0910 3788 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
22:02:58.0926 3788 mouhid - ok
22:02:58.0973 3788 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
22:02:59.0003 3788 mountmgr - ok
22:02:59.0059 3788 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
22:02:59.0073 3788 mpio - ok
22:02:59.0232 3788 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
22:02:59.0314 3788 mpsdrv - ok
22:02:59.0357 3788 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
22:02:59.0398 3788 MRxDAV - ok
22:02:59.0461 3788 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:02:59.0495 3788 mrxsmb - ok
22:02:59.0711 3788 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:02:59.0754 3788 mrxsmb10 - ok
22:02:59.0811 3788 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:02:59.0826 3788 mrxsmb20 - ok
22:02:59.0881 3788 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
22:02:59.0892 3788 msahci - ok
22:02:59.0944 3788 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
22:02:59.0974 3788 msdsm - ok
22:03:00.0045 3788 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
22:03:00.0089 3788 Msfs - ok
22:03:00.0204 3788 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
22:03:00.0283 3788 mshidkmdf - ok
22:03:00.0322 3788 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
22:03:00.0350 3788 msisadrv - ok
22:03:00.0387 3788 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
22:03:00.0431 3788 MSKSSRV - ok
22:03:00.0486 3788 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
22:03:00.0567 3788 MSPCLOCK - ok
22:03:00.0760 3788 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
22:03:00.0847 3788 MSPQM - ok
22:03:00.0896 3788 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
22:03:00.0916 3788 MsRPC - ok
22:03:00.0967 3788 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
22:03:00.0978 3788 mssmbios - ok
22:03:01.0000 3788 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
22:03:01.0063 3788 MSTEE - ok
22:03:01.0214 3788 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
22:03:01.0253 3788 MTConfig - ok
22:03:01.0291 3788 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
22:03:01.0320 3788 Mup - ok
22:03:01.0363 3788 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
22:03:01.0444 3788 NativeWifiP - ok
22:03:01.0640 3788 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
22:03:01.0675 3788 NDIS - ok
22:03:01.0828 3788 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
22:03:01.0901 3788 NdisCap - ok
22:03:01.0947 3788 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
22:03:02.0015 3788 NdisTapi - ok
22:03:02.0057 3788 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
22:03:02.0117 3788 Ndisuio - ok
22:03:02.0274 3788 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
22:03:02.0336 3788 NdisWan - ok
22:03:02.0390 3788 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
22:03:02.0485 3788 NDProxy - ok
22:03:02.0561 3788 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
22:03:02.0638 3788 NetBIOS - ok
22:03:02.0787 3788 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
22:03:02.0863 3788 NetBT - ok
22:03:02.0973 3788 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
22:03:03.0017 3788 nfrd960 - ok
22:03:03.0209 3788 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
22:03:03.0287 3788 Npfs - ok
22:03:03.0318 3788 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
22:03:03.0377 3788 nsiproxy - ok
22:03:03.0466 3788 Ntfs (05d78aa5cb5f3f5c31160bdb955d0b7c) C:\Windows\system32\drivers\Ntfs.sys
22:03:03.0537 3788 Ntfs - ok
22:03:03.0669 3788 NuidFltr (d4012918d3a3847b44b888d56bc095d6) C:\Windows\system32\DRIVERS\NuidFltr.sys
22:03:03.0680 3788 NuidFltr - ok
22:03:03.0733 3788 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
22:03:03.0820 3788 Null - ok
22:03:03.0888 3788 nvraid (5d9fd91f3d38dc9da01e3cb5fa89cd48) C:\Windows\system32\drivers\nvraid.sys
22:03:03.0904 3788 nvraid - ok
22:03:04.0034 3788 nvstor (f7cd50fe7139f07e77da8ac8033d1832) C:\Windows\system32\drivers\nvstor.sys
22:03:04.0048 3788 nvstor - ok
22:03:04.0112 3788 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
22:03:04.0125 3788 nv_agp - ok
22:03:04.0199 3788 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
22:03:04.0252 3788 ohci1394 - ok
22:03:04.0436 3788 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
22:03:04.0486 3788 Parport - ok
22:03:04.0535 3788 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
22:03:04.0564 3788 partmgr - ok
22:03:04.0619 3788 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
22:03:04.0635 3788 pci - ok
22:03:04.0692 3788 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
22:03:04.0703 3788 pciide - ok
22:03:04.0732 3788 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
22:03:04.0764 3788 pcmcia - ok
22:03:04.0914 3788 pcouffin (af7ce12c4f3dc8cb2b07685c916bbcfe) C:\Windows\system32\Drivers\pcouffin.sys
22:03:04.0952 3788 pcouffin - ok
22:03:04.0994 3788 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
22:03:05.0023 3788 pcw - ok
22:03:05.0184 3788 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
22:03:05.0256 3788 PEAUTH - ok
22:03:05.0408 3788 pfc - ok
22:03:05.0498 3788 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
22:03:05.0559 3788 PptpMiniport - ok
22:03:05.0613 3788 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
22:03:05.0663 3788 Processor - ok
22:03:05.0850 3788 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
22:03:05.0910 3788 Psched - ok
22:03:06.0003 3788 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
22:03:06.0055 3788 ql2300 - ok
22:03:06.0207 3788 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
22:03:06.0221 3788 ql40xx - ok
22:03:06.0249 3788 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
22:03:06.0308 3788 QWAVEdrv - ok
22:03:06.0334 3788 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
22:03:06.0412 3788 RasAcd - ok
22:03:06.0492 3788 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:03:06.0560 3788 RasAgileVpn - ok
22:03:06.0720 3788 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:03:06.0818 3788 Rasl2tp - ok
22:03:06.0903 3788 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
22:03:06.0966 3788 RasPppoe - ok
22:03:06.0996 3788 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
22:03:07.0056 3788 RasSstp - ok
22:03:07.0221 3788 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
22:03:07.0283 3788 rdbss - ok
22:03:07.0334 3788 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
22:03:07.0383 3788 rdpbus - ok
22:03:07.0406 3788 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:03:07.0470 3788 RDPCDD - ok
22:03:07.0657 3788 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
22:03:07.0719 3788 RDPENCDD - ok
22:03:07.0733 3788 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
22:03:07.0776 3788 RDPREFMP - ok
22:03:07.0821 3788 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
22:03:07.0882 3788 RDPWD - ok
22:03:07.0946 3788 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
22:03:07.0964 3788 rdyboost - ok
22:03:08.0192 3788 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
22:03:08.0275 3788 rspndr - ok
22:03:08.0350 3788 RTL8169 (170a66dfaaa22358e08d6f4b38c8f3df) C:\Windows\system32\DRIVERS\Rtlh64.sys
22:03:08.0402 3788 RTL8169 - ok
22:03:08.0494 3788 RTL8192cu (665ba29357882a8c5980b15b3a0123a4) C:\Windows\system32\DRIVERS\RTL8192cu.sys
22:03:08.0540 3788 RTL8192cu - ok
22:03:08.0616 3788 SASDIFSV (b2a29cc6c019fe738c39037c6218444c) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
22:03:08.0625 3788 SASDIFSV - ok
22:03:08.0655 3788 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
22:03:08.0664 3788 SASKUTIL - ok
22:03:08.0815 3788 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
22:03:08.0844 3788 sbp2port - ok
22:03:08.0931 3788 SCDEmu (6ce6f98ea3d07a9c2ce3cd0a5a86352d) C:\Windows\system32\drivers\SCDEmu.sys
22:03:08.0943 3788 SCDEmu - ok
22:03:08.0990 3788 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
22:03:09.0069 3788 scfilter - ok
22:03:09.0322 3788 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
22:03:09.0405 3788 secdrv - ok
22:03:09.0447 3788 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
22:03:09.0494 3788 Serenum - ok
22:03:09.0528 3788 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
22:03:09.0616 3788 Serial - ok
22:03:09.0659 3788 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
22:03:09.0674 3788 sermouse - ok
22:03:09.0838 3788 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
22:03:09.0892 3788 sffdisk - ok
22:03:09.0922 3788 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
22:03:09.0957 3788 sffp_mmc - ok
22:03:09.0967 3788 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
22:03:09.0992 3788 sffp_sd - ok
22:03:10.0035 3788 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
22:03:10.0083 3788 sfloppy - ok
22:03:10.0284 3788 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:03:10.0328 3788 SiSRaid2 - ok
22:03:10.0347 3788 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
22:03:10.0377 3788 SiSRaid4 - ok
22:03:10.0421 3788 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
22:03:10.0467 3788 Smb - ok
22:03:10.0907 3788 SNPSTD3 (37d91c6385bb1104d67925fc43800ed0) C:\Windows\system32\DRIVERS\snpstd3.sys
22:03:11.0350 3788 SNPSTD3 - ok
22:03:11.0510 3788 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
22:03:11.0537 3788 spldr - ok
22:03:11.0601 3788 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
22:03:11.0644 3788 srv - ok
22:03:11.0687 3788 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
22:03:11.0727 3788 srv2 - ok
22:03:11.0883 3788 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
22:03:11.0918 3788 srvnet - ok
22:03:11.0976 3788 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
22:03:11.0989 3788 stexstor - ok
22:03:12.0061 3788 STHDA (dffbc024dfc7bb05b2129e05cbc7a201) C:\Windows\system32\DRIVERS\stwrt64.sys
22:03:12.0104 3788 STHDA - ok
22:03:12.0311 3788 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
22:03:12.0322 3788 swenum - ok
22:03:12.0439 3788 SynTP (3a706a967295e16511e40842b1a2761d) C:\Windows\system32\DRIVERS\SynTP.sys
22:03:12.0455 3788 SynTP - ok
22:03:12.0646 3788 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
22:03:12.0709 3788 Tcpip - ok
22:03:12.0879 3788 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
22:03:12.0924 3788 TCPIP6 - ok
22:03:13.0079 3788 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
22:03:13.0122 3788 tcpipreg - ok
22:03:13.0193 3788 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
22:03:13.0274 3788 TDPIPE - ok
22:03:13.0305 3788 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
22:03:13.0361 3788 TDTCP - ok
22:03:13.0489 3788 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
22:03:13.0574 3788 tdx - ok
22:03:13.0643 3788 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
22:03:13.0655 3788 TermDD - ok
22:03:13.0731 3788 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:03:13.0791 3788 tssecsrv - ok
22:03:13.0952 3788 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
22:03:13.0984 3788 TsUsbFlt - ok
22:03:14.0070 3788 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
22:03:14.0129 3788 tunnel - ok
22:03:14.0184 3788 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
22:03:14.0213 3788 uagp35 - ok
22:03:14.0359 3788 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
22:03:14.0423 3788 udfs - ok
22:03:14.0511 3788 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
22:03:14.0522 3788 uliagpkx - ok
22:03:14.0585 3788 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
22:03:14.0615 3788 umbus - ok
22:03:14.0759 3788 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
22:03:14.0813 3788 UmPass - ok
22:03:14.0917 3788 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
22:03:14.0960 3788 USBAAPL64 - ok
22:03:15.0135 3788 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
22:03:15.0194 3788 usbaudio - ok
22:03:15.0303 3788 usbccgp (481dff26b4dca8f4cbac1f7dce1d6829) C:\Windows\system32\drivers\usbccgp.sys
22:03:15.0407 3788 usbccgp - ok
22:03:15.0581 3788 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
22:03:15.0660 3788 usbcir - ok
22:03:15.0791 3788 usbehci (74ee782b1d9c241efe425565854c661c) C:\Windows\system32\drivers\usbehci.sys
22:03:15.0843 3788 usbehci - ok
22:03:15.0897 3788 usbfilter (8fec71666aba7114f9cab9e56065ec80) C:\Windows\system32\DRIVERS\usbfilter.sys
22:03:15.0907 3788 usbfilter - ok
22:03:15.0939 3788 usbhub (dc96bd9ccb8403251bcf25047573558e) C:\Windows\system32\drivers\usbhub.sys
22:03:15.0979 3788 usbhub - ok
22:03:16.0007 3788 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\drivers\usbohci.sys
22:03:16.0061 3788 usbohci - ok
22:03:16.0196 3788 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
22:03:16.0249 3788 usbprint - ok
22:03:16.0330 3788 USBSTOR (d76510cfa0fc09023077f22c2f979d86) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:03:16.0364 3788 USBSTOR - ok
22:03:16.0408 3788 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\drivers\usbuhci.sys
22:03:16.0444 3788 usbuhci - ok
22:03:16.0581 3788 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
22:03:16.0601 3788 usbvideo - ok
22:03:16.0647 3788 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
22:03:16.0659 3788 vdrvroot - ok
22:03:16.0728 3788 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
22:03:16.0747 3788 vga - ok
22:03:16.0774 3788 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
22:03:16.0850 3788 VgaSave - ok
22:03:16.0959 3788 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
22:03:16.0992 3788 vhdmp - ok
22:03:17.0056 3788 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
22:03:17.0067 3788 viaide - ok
22:03:17.0118 3788 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
22:03:17.0131 3788 volmgr - ok
22:03:17.0192 3788 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
22:03:17.0213 3788 volmgrx - ok
22:03:17.0368 3788 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
22:03:17.0411 3788 volsnap - ok
22:03:17.0482 3788 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
22:03:17.0513 3788 vsmraid - ok
22:03:17.0539 3788 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
22:03:17.0591 3788 vwifibus - ok
22:03:17.0734 3788 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
22:03:17.0778 3788 vwififlt - ok
22:03:17.0826 3788 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
22:03:17.0863 3788 vwifimp - ok
22:03:17.0887 3788 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
22:03:17.0903 3788 WacomPen - ok
22:03:18.0048 3788 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
22:03:18.0129 3788 WANARP - ok
22:03:18.0134 3788 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
22:03:18.0177 3788 Wanarpv6 - ok
22:03:18.0304 3788 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
22:03:18.0316 3788 Wd - ok
22:03:18.0444 3788 WDC_SAM (a3d04ebf5227886029b4532f20d026f7) C:\Windows\system32\DRIVERS\wdcsam64.sys
22:03:18.0457 3788 WDC_SAM - ok
22:03:18.0494 3788 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
22:03:18.0522 3788 Wdf01000 - ok
22:03:18.0727 3788 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
22:03:18.0810 3788 WfpLwf - ok
22:03:18.0836 3788 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
22:03:18.0866 3788 WIMMount - ok
22:03:18.0959 3788 WinUSB (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUSB.sys
22:03:18.0980 3788 WinUSB - ok
22:03:19.0179 3788 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
22:03:19.0210 3788 WmiAcpi - ok
22:03:19.0287 3788 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
22:03:19.0371 3788 ws2ifsl - ok
22:03:19.0476 3788 WsAudio_DeviceS(1) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(1).sys
22:03:19.0486 3788 WsAudio_DeviceS(1) - ok
22:03:19.0563 3788 WsAudio_DeviceS(2) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(2).sys
22:03:19.0572 3788 WsAudio_DeviceS(2) - ok
22:03:19.0606 3788 WsAudio_DeviceS(3) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(3).sys
22:03:19.0629 3788 WsAudio_DeviceS(3) - ok
22:03:19.0701 3788 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
22:03:19.0783 3788 WudfPf - ok
22:03:19.0948 3788 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:03:20.0022 3788 WUDFRd - ok
22:03:20.0181 3788 {55662437-DA8C-40c0-AADA-2C816A897A49} (15cc7077d2dc28776cd430ecabbffd66) C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl
22:03:20.0191 3788 {55662437-DA8C-40c0-AADA-2C816A897A49} - ok
22:03:20.0244 3788 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:03:20.0278 3788 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - infected
22:03:20.0278 3788 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.b (0)
22:03:20.0336 3788 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
22:03:20.0336 3788 \Device\Harddisk0\DR0 - detected TDSS File System (1)
22:03:20.0371 3788 Boot (0x1200) (5efce210fec595c2dfa1de05d3d97f7f) \Device\Harddisk0\DR0\Partition0
22:03:20.0372 3788 \Device\Harddisk0\DR0\Partition0 - ok
22:03:20.0397 3788 Boot (0x1200) (e6ffe6111a92557139dd1d9815cd62bf) \Device\Harddisk0\DR0\Partition1
22:03:20.0399 3788 \Device\Harddisk0\DR0\Partition1 - ok
22:03:20.0399 3788 ============================================================
22:03:20.0399 3788 Scan finished
22:03:20.0399 3788 ============================================================
22:03:20.0417 0884 Detected object count: 2
22:03:20.0417 0884 Actual detected object count: 2
22:05:13.0967 0884 \Device\Harddisk0\DR0\# - copied to quarantine
22:05:13.0970 0884 \Device\Harddisk0\DR0 - copied to quarantine
22:05:14.0037 0884 \Device\Harddisk0\DR0\TDLFS\mbr - copied to quarantine
22:05:14.0041 0884 \Device\Harddisk0\DR0\TDLFS\vbr - copied to quarantine
22:05:14.0046 0884 \Device\Harddisk0\DR0\TDLFS\bid - copied to quarantine
22:05:14.0050 0884 \Device\Harddisk0\DR0\TDLFS\affid - copied to quarantine
22:05:14.0055 0884 \Device\Harddisk0\DR0\TDLFS\boot - copied to quarantine
22:05:14.0060 0884 \Device\Harddisk0\DR0\TDLFS\cmd32 - copied to quarantine
22:05:18.0700 0884 \Device\Harddisk0\DR0\TDLFS\cmd64 - copied to quarantine
22:05:19.0242 0884 \Device\Harddisk0\DR0\TDLFS\dbg32 - copied to quarantine
22:05:19.0247 0884 \Device\Harddisk0\DR0\TDLFS\dbg64 - copied to quarantine
22:05:19.0732 0884 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
22:05:20.0248 0884 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
22:05:20.0759 0884 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
22:05:21.0303 0884 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
22:05:21.0826 0884 \Device\Harddisk0\DR0\TDLFS\subid - copied to quarantine
22:05:21.0830 0884 \Device\Harddisk0\DR0\TDLFS\info - copied to quarantine
22:05:21.0835 0884 \Device\Harddisk0\DR0\TDLFS\mainfb.script - copied to quarantine
22:05:21.0878 0884 \Device\Harddisk0\DR0\TDLFS\com64 - copied to quarantine
22:05:21.0898 0884 \Device\Harddisk0\DR0\TDLFS\bbr232 - copied to quarantine
22:05:21.0961 0884 \Device\Harddisk0\DR0\TDLFS\serf332 - copied to quarantine
22:05:22.0032 0884 \Device\Harddisk0\DR0\TDLFS\serf364 - copied to quarantine
22:05:22.0053 0884 \Device\Harddisk0\DR0\TDLFS\bbr264 - copied to quarantine
22:05:22.0059 0884 \Device\Harddisk0\DR0\TDLFS\main - copied to quarantine
22:05:22.0064 0884 \Device\Harddisk0\DR0\TDLFS\serf_conf - copied to quarantine
22:05:22.0110 0884 \Device\Harddisk0\DR0\TDLFS\bbr_conf - copied to quarantine
22:05:22.0168 0884 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - will be cured on reboot
22:05:22.0176 0884 \Device\Harddisk0\DR0 - ok
22:05:23.0102 0884 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.b ) - User select action: Cure
22:05:23.0102 0884 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
22:05:23.0102 0884 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
22:05:48.0505 3452 Deinitialize success