Re-ran TDDSKiller. Log is below.
Ran the OTL fix. Log is below. After reboot Michelle's desktop shortcuts re-appeared. The desktop background was none... used to be Bliss so I changed that back manually.
Ran the OTL quick scan. Log is below.
Michelle's Start Menu still appears unusual.
- The pinned Internet Explorer shortcut is now Internet Explorer (No Add-ons)
- There are several shortcuts/folders missing. i.e. My Documents, My Recent Documents, My Pictures, My Music, My Computer, My Network Places, Control Panel, Set Program Access and Defaults, Printers and Faxes, Help and Support, Search, Run
17:22:32.0328 3632 TDSS rootkit removing tool 2.7.42.0 Jun 25 2012 21:18:44
17:22:32.0750 3632 ============================================================
17:22:32.0750 3632 Current date / time: 2012/06/28 17:22:32.0750
17:22:32.0750 3632 SystemInfo:
17:22:32.0750 3632
17:22:32.0750 3632 OS Version: 5.1.2600 ServicePack: 3.0
17:22:32.0750 3632 Product type: Workstation
17:22:32.0750 3632 ComputerName: HOMEPC3
17:22:32.0750 3632 UserName: Michelle
17:22:32.0750 3632 Windows directory: C:\WINDOWS
17:22:32.0750 3632 System windows directory: C:\WINDOWS
17:22:32.0750 3632 Processor architecture: Intel x86
17:22:32.0750 3632 Number of processors: 1
17:22:32.0750 3632 Page size: 0x1000
17:22:32.0750 3632 Boot type: Normal boot
17:22:32.0750 3632 ============================================================
17:22:34.0765 3632 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
17:22:34.0828 3632 Drive \Device\Harddisk1\DR1 - Size: 0x9516AE000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
17:22:34.0828 3632 ============================================================
17:22:34.0828 3632 \Device\Harddisk0\DR0:
17:22:34.0828 3632 MBR partitions:
17:22:34.0828 3632 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x950A5C1
17:22:34.0828 3632 \Device\Harddisk1\DR1:
17:22:34.0828 3632 MBR partitions:
17:22:34.0828 3632 \Device\Harddisk1\DR1\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x4A89182
17:22:34.0828 3632 ============================================================
17:22:34.0859 3632 C: <-> \Device\Harddisk0\DR0\Partition0
17:22:34.0859 3632 E: <-> \Device\Harddisk1\DR1\Partition0
17:22:34.0859 3632 ============================================================
17:22:34.0859 3632 Initialize success
17:22:34.0859 3632 ============================================================
17:22:48.0843 0576 ============================================================
17:22:48.0843 0576 Scan started
17:22:48.0843 0576 Mode: Manual; SigCheck; TDLFS;
17:22:48.0843 0576 ============================================================
17:22:49.0281 0576 Abiosdsk - ok
17:22:49.0312 0576 abp480n5 - ok
17:22:49.0312 0576 ac97intc - ok
17:22:49.0390 0576 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:22:50.0656 0576 ACPI - ok
17:22:50.0687 0576 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:22:50.0906 0576 ACPIEC - ok
17:22:50.0937 0576 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\System32\DRIVERS\adpu160m.sys
17:22:51.0171 0576 adpu160m - ok
17:22:51.0203 0576 adpu320 (0ea9b1f0c6c90a509c8603775366adb7) C:\WINDOWS\System32\DRIVERS\adpu320.sys
17:22:51.0234 0576 adpu320 ( UnsignedFile.Multi.Generic ) - warning
17:22:51.0234 0576 adpu320 - detected UnsignedFile.Multi.Generic (1)
17:22:51.0281 0576 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
17:22:51.0343 0576 aeaudio - ok
17:22:51.0406 0576 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:22:51.0593 0576 aec - ok
17:22:51.0640 0576 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:22:51.0718 0576 AFD - ok
17:22:51.0718 0576 Aha154x - ok
17:22:51.0781 0576 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\System32\DRIVERS\aic78u2.sys
17:22:51.0984 0576 aic78u2 - ok
17:22:52.0015 0576 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\System32\DRIVERS\aic78xx.sys
17:22:52.0234 0576 aic78xx - ok
17:22:52.0281 0576 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
17:22:52.0468 0576 Alerter - ok
17:22:52.0500 0576 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
17:22:52.0687 0576 ALG - ok
17:22:52.0703 0576 AliIde - ok
17:22:52.0718 0576 amsint - ok
17:22:52.0843 0576 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:22:52.0875 0576 Apple Mobile Device - ok
17:22:52.0937 0576 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
17:22:53.0125 0576 AppMgmt - ok
17:22:53.0140 0576 asc - ok
17:22:53.0156 0576 asc3350p - ok
17:22:53.0171 0576 asc3550 - ok
17:22:53.0312 0576 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
17:22:53.0328 0576 aspnet_state - ok
17:22:53.0359 0576 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:22:53.0578 0576 AsyncMac - ok
17:22:53.0625 0576 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:22:53.0828 0576 atapi - ok
17:22:53.0843 0576 Atdisk - ok
17:22:53.0875 0576 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:22:54.0078 0576 Atmarpc - ok
17:22:54.0125 0576 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
17:22:54.0312 0576 AudioSrv - ok
17:22:54.0359 0576 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:22:54.0546 0576 audstub - ok
17:22:54.0609 0576 bcm4sbxp (068523d2cd260069b19ad68adea0d739) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
17:22:54.0640 0576 bcm4sbxp - ok
17:22:54.0671 0576 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:22:54.0875 0576 Beep - ok
17:22:54.0937 0576 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
17:22:55.0203 0576 BITS - ok
17:22:55.0296 0576 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
17:22:55.0328 0576 Bonjour Service - ok
17:22:55.0375 0576 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
17:22:55.0562 0576 Browser - ok
17:22:55.0703 0576 catchme - ok
17:22:55.0750 0576 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:22:55.0953 0576 cbidf2k - ok
17:22:56.0031 0576 CCALib8 (20f89e232173985a455bc9a5f70d1166) C:\Program Files\Canon\CAL\CALMAIN.exe
17:22:56.0062 0576 CCALib8 ( UnsignedFile.Multi.Generic ) - warning
17:22:56.0062 0576 CCALib8 - detected UnsignedFile.Multi.Generic (1)
17:22:56.0125 0576 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
17:22:56.0296 0576 CCDECODE - ok
17:22:56.0312 0576 cd20xrnt - ok
17:22:56.0359 0576 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:22:56.0578 0576 Cdaudio - ok
17:22:56.0625 0576 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:22:56.0812 0576 Cdfs - ok
17:22:56.0859 0576 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:22:57.0046 0576 Cdrom - ok
17:22:57.0062 0576 Changer - ok
17:22:57.0109 0576 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
17:22:57.0296 0576 CiSvc - ok
17:22:57.0328 0576 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
17:22:57.0515 0576 ClipSrv - ok
17:22:57.0656 0576 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:22:57.0687 0576 clr_optimization_v2.0.50727_32 - ok
17:22:57.0703 0576 CmdIde - ok
17:22:57.0718 0576 COMSysApp - ok
17:22:57.0734 0576 Cpqarray - ok
17:22:57.0796 0576 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
17:22:57.0984 0576 CryptSvc - ok
17:22:58.0000 0576 dac2w2k - ok
17:22:58.0015 0576 dac960nt - ok
17:22:58.0078 0576 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
17:22:58.0187 0576 DcomLaunch - ok
17:22:58.0234 0576 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
17:22:58.0421 0576 Dhcp - ok
17:22:58.0453 0576 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:22:58.0625 0576 Disk - ok
17:22:58.0625 0576 dmadmin - ok
17:22:58.0703 0576 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
17:22:58.0937 0576 dmboot - ok
17:22:59.0000 0576 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
17:22:59.0203 0576 dmio - ok
17:22:59.0218 0576 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:22:59.0406 0576 dmload - ok
17:22:59.0500 0576 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
17:22:59.0671 0576 dmserver - ok
17:22:59.0718 0576 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:22:59.0890 0576 DMusic - ok
17:22:59.0984 0576 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
17:23:00.0062 0576 Dnscache - ok
17:23:00.0109 0576 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
17:23:00.0281 0576 Dot3svc - ok
17:23:00.0312 0576 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\System32\DRIVERS\dpti2o.sys
17:23:00.0531 0576 dpti2o - ok
17:23:00.0562 0576 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:23:00.0734 0576 drmkaud - ok
17:23:00.0781 0576 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
17:23:00.0984 0576 E100B - ok
17:23:01.0031 0576 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
17:23:01.0218 0576 EapHost - ok
17:23:01.0250 0576 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
17:23:01.0437 0576 ERSvc - ok
17:23:01.0484 0576 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
17:23:01.0531 0576 Eventlog - ok
17:23:01.0578 0576 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\System32\es.dll
17:23:01.0625 0576 EventSystem - ok
17:23:01.0687 0576 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:23:01.0859 0576 Fastfat - ok
17:23:01.0906 0576 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
17:23:02.0000 0576 FastUserSwitchingCompatibility - ok
17:23:02.0046 0576 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
17:23:02.0234 0576 Fdc - ok
17:23:02.0265 0576 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
17:23:02.0437 0576 Fips - ok
17:23:02.0468 0576 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
17:23:02.0640 0576 Flpydisk - ok
17:23:02.0687 0576 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:23:02.0890 0576 FltMgr - ok
17:23:03.0062 0576 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
17:23:03.0078 0576 FontCache3.0.0.0 - ok
17:23:03.0125 0576 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:23:03.0343 0576 Fs_Rec - ok
17:23:03.0375 0576 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:23:03.0609 0576 Ftdisk - ok
17:23:03.0656 0576 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
17:23:03.0656 0576 GearAspiWDM - ok
17:23:03.0750 0576 getPlus® Helper (35a1f815962f3552066c6be4c969d297) C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
17:23:03.0750 0576 getPlus® Helper - ok
17:23:03.0796 0576 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:23:03.0968 0576 Gpc - ok
17:23:04.0015 0576 grmnusb (6003bc70f1a8307262bd3c941bda0b7e) C:\WINDOWS\system32\drivers\grmnusb.sys
17:23:04.0062 0576 grmnusb - ok
17:23:04.0140 0576 gupdate1c95c931cacec94 (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe
17:23:04.0156 0576 gupdate1c95c931cacec94 - ok
17:23:04.0171 0576 gupdatem (626a24ed1228580b9518c01930936df9) C:\Program Files\Google\Update\GoogleUpdate.exe
17:23:04.0187 0576 gupdatem - ok
17:23:04.0234 0576 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
17:23:04.0265 0576 gusvc - ok
17:23:04.0328 0576 Halt (b636fb5126d7851789a681fb738a2a15) c:\program files\soccerwinners\halt\halt.exe
17:23:04.0343 0576 Halt ( UnsignedFile.Multi.Generic ) - warning
17:23:04.0343 0576 Halt - detected UnsignedFile.Multi.Generic (1)
17:23:04.0359 0576 HaltMonitor (8d287028886cfb7fb6770a9ff39b2c2e) c:\program files\soccerwinners\halt\haltmonitor.exe
17:23:04.0390 0576 HaltMonitor ( UnsignedFile.Multi.Generic ) - warning
17:23:04.0390 0576 HaltMonitor - detected UnsignedFile.Multi.Generic (1)
17:23:04.0468 0576 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
17:23:04.0656 0576 helpsvc - ok
17:23:04.0671 0576 HidServ - ok
17:23:04.0718 0576 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
17:23:04.0890 0576 HidUsb - ok
17:23:04.0937 0576 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
17:23:05.0109 0576 hkmsvc - ok
17:23:05.0125 0576 hpn - ok
17:23:05.0187 0576 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:23:05.0250 0576 HTTP - ok
17:23:05.0281 0576 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
17:23:05.0453 0576 HTTPFilter - ok
17:23:05.0468 0576 i2omgmt - ok
17:23:05.0484 0576 i2omp - ok
17:23:05.0515 0576 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:23:05.0718 0576 i8042prt - ok
17:23:05.0750 0576 i81x (06b7ef73ba5f302eecc294cdf7e19702) C:\WINDOWS\system32\DRIVERS\i81xnt5.sys
17:23:05.0906 0576 i81x - ok
17:23:05.0953 0576 iAimFP0 (7b5b44efe5eb9dadfb8ee29700885d23) C:\WINDOWS\system32\DRIVERS\wADV01nt.sys
17:23:06.0109 0576 iAimFP0 - ok
17:23:06.0140 0576 iAimFP1 (eb1f6bab6c22ede0ba551b527475f7e9) C:\WINDOWS\system32\DRIVERS\wADV02NT.sys
17:23:06.0296 0576 iAimFP1 - ok
17:23:06.0328 0576 iAimFP2 (03ce989d846c1aa81145cb22fcb86d06) C:\WINDOWS\system32\DRIVERS\wADV05NT.sys
17:23:06.0468 0576 iAimFP2 - ok
17:23:06.0500 0576 iAimFP3 (525849b4469de021d5d61b4db9be3a9d) C:\WINDOWS\system32\DRIVERS\wSiINTxx.sys
17:23:06.0640 0576 iAimFP3 - ok
17:23:06.0671 0576 iAimFP4 (589c2bcdb5bd602bf7b63d210407ef8c) C:\WINDOWS\system32\DRIVERS\wVchNTxx.sys
17:23:06.0828 0576 iAimFP4 - ok
17:23:06.0859 0576 iAimTV0 (d83bdd5c059667a2f647a6be5703a4d2) C:\WINDOWS\system32\DRIVERS\wATV01nt.sys
17:23:07.0015 0576 iAimTV0 - ok
17:23:07.0046 0576 iAimTV1 (ed968d23354daa0d7c621580c012a1f6) C:\WINDOWS\system32\DRIVERS\wATV02NT.sys
17:23:07.0187 0576 iAimTV1 - ok
17:23:07.0203 0576 iAimTV2 - ok
17:23:07.0250 0576 iAimTV3 (d738273f218a224c1ddac04203f27a84) C:\WINDOWS\system32\DRIVERS\wATV04nt.sys
17:23:07.0390 0576 iAimTV3 - ok
17:23:07.0437 0576 iAimTV4 (0052d118995cbab152daabe6106d1442) C:\WINDOWS\system32\DRIVERS\wCh7xxNT.sys
17:23:07.0562 0576 iAimTV4 - ok
17:23:07.0609 0576 ialm (a79029861cb69cd3cf4eab9ebfee32dd) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
17:23:07.0812 0576 ialm - ok
17:23:07.0937 0576 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
17:23:07.0968 0576 IDriverT ( UnsignedFile.Multi.Generic ) - warning
17:23:07.0968 0576 IDriverT - detected UnsignedFile.Multi.Generic (1)
17:23:08.0140 0576 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:23:08.0218 0576 idsvc - ok
17:23:08.0250 0576 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\IMAPI.SYS
17:23:08.0437 0576 Imapi - ok
17:23:08.0500 0576 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
17:23:08.0656 0576 ImapiService - ok
17:23:08.0687 0576 ini910u - ok
17:23:08.0734 0576 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\System32\DRIVERS\intelide.sys
17:23:08.0906 0576 IntelIde - ok
17:23:08.0937 0576 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
17:23:09.0093 0576 intelppm - ok
17:23:09.0156 0576 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:23:09.0312 0576 ip6fw - ok
17:23:09.0375 0576 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:23:09.0578 0576 IpFilterDriver - ok
17:23:09.0625 0576 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:23:09.0781 0576 IpInIp - ok
17:23:09.0828 0576 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:23:10.0015 0576 IpNat - ok
17:23:10.0140 0576 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
17:23:10.0218 0576 iPod Service - ok
17:23:10.0250 0576 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:23:10.0437 0576 IPSec - ok
17:23:10.0500 0576 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:23:10.0671 0576 IRENUM - ok
17:23:10.0718 0576 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:23:10.0906 0576 isapnp - ok
17:23:11.0093 0576 JavaQuickStarterService (9dba73c2f1e76ec4cb837e67c5743596) C:\Program Files\Java\jre6\bin\jqs.exe
17:23:11.0140 0576 JavaQuickStarterService - ok
17:23:11.0187 0576 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:23:11.0359 0576 Kbdclass - ok
17:23:11.0406 0576 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:23:11.0578 0576 kmixer - ok
17:23:11.0625 0576 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:23:11.0703 0576 KSecDD - ok
17:23:11.0750 0576 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
17:23:11.0812 0576 lanmanserver - ok
17:23:11.0859 0576 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
17:23:11.0921 0576 lanmanworkstation - ok
17:23:11.0937 0576 lbrtfdc - ok
17:23:12.0015 0576 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
17:23:12.0187 0576 LmHosts - ok
17:23:12.0218 0576 LVUSBSta (c5efbd05a5195402121711a6ebbb271f) C:\WINDOWS\system32\drivers\lvusbsta.sys
17:23:12.0296 0576 LVUSBSta - ok
17:23:12.0437 0576 MDM (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
17:23:12.0484 0576 MDM - ok
17:23:12.0562 0576 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
17:23:12.0734 0576 Messenger - ok
17:23:12.0765 0576 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:23:13.0000 0576 mnmdd - ok
17:23:13.0031 0576 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\System32\mnmsrvc.exe
17:23:13.0203 0576 mnmsrvc - ok
17:23:13.0250 0576 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
17:23:13.0437 0576 Modem - ok
17:23:13.0468 0576 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:23:13.0640 0576 Mouclass - ok
17:23:13.0687 0576 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
17:23:13.0890 0576 mouhid - ok
17:23:13.0937 0576 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:23:14.0093 0576 MountMgr - ok
17:23:14.0140 0576 MpFilter (d993bea500e7382dc4e760bf4f35efcb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
17:23:14.0171 0576 MpFilter - ok
17:23:14.0359 0576 MpKsl3e251709 (a69630d039c38018689190234f866d77) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{19B62B28-0556-4437-A4FA-3BB0D682AE47}\MpKsl3e251709.sys
17:23:14.0375 0576 MpKsl3e251709 - ok
17:23:14.0390 0576 mraid35x - ok
17:23:14.0453 0576 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:23:14.0640 0576 MRxDAV - ok
17:23:14.0703 0576 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:23:14.0796 0576 MRxSmb - ok
17:23:14.0828 0576 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\System32\msdtc.exe
17:23:15.0015 0576 MSDTC - ok
17:23:15.0078 0576 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:23:15.0250 0576 Msfs - ok
17:23:15.0265 0576 MSIServer - ok
17:23:15.0312 0576 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:23:15.0484 0576 MSKSSRV - ok
17:23:15.0578 0576 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) c:\Program Files\Microsoft Security Client\MsMpEng.exe
17:23:15.0609 0576 MsMpSvc - ok
17:23:15.0640 0576 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:23:15.0796 0576 MSPCLOCK - ok
17:23:15.0843 0576 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:23:16.0015 0576 MSPQM - ok
17:23:16.0062 0576 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:23:16.0218 0576 mssmbios - ok
17:23:16.0250 0576 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
17:23:16.0421 0576 MSTEE - ok
17:23:16.0468 0576 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:23:16.0500 0576 Mup - ok
17:23:16.0546 0576 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
17:23:16.0734 0576 NABTSFEC - ok
17:23:16.0796 0576 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
17:23:16.0984 0576 napagent - ok
17:23:17.0046 0576 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:23:17.0234 0576 NDIS - ok
17:23:17.0281 0576 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
17:23:17.0453 0576 NdisIP - ok
17:23:17.0500 0576 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:23:17.0546 0576 NdisTapi - ok
17:23:17.0609 0576 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:23:17.0781 0576 Ndisuio - ok
17:23:17.0812 0576 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:23:18.0015 0576 NdisWan - ok
17:23:18.0062 0576 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:23:18.0109 0576 NDProxy - ok
17:23:18.0156 0576 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:23:18.0328 0576 NetBIOS - ok
17:23:18.0375 0576 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:23:18.0546 0576 NetBT - ok
17:23:18.0593 0576 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
17:23:18.0765 0576 NetDDE - ok
17:23:18.0781 0576 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
17:23:18.0937 0576 NetDDEdsdm - ok
17:23:18.0984 0576 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
17:23:19.0187 0576 Netlogon - ok
17:23:19.0234 0576 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
17:23:19.0406 0576 Netman - ok
17:23:19.0546 0576 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:23:19.0562 0576 NetTcpPortSharing - ok
17:23:19.0609 0576 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
17:23:19.0656 0576 Nla - ok
17:23:19.0687 0576 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:23:19.0859 0576 Npfs - ok
17:23:19.0921 0576 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:23:20.0140 0576 Ntfs - ok
17:23:20.0187 0576 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\System32\lsass.exe
17:23:20.0343 0576 NtLmSsp - ok
17:23:20.0406 0576 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
17:23:20.0609 0576 NtmsSvc - ok
17:23:20.0640 0576 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:23:20.0843 0576 Null - ok
17:23:20.0890 0576 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:23:21.0078 0576 NwlnkFlt - ok
17:23:21.0109 0576 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:23:21.0296 0576 NwlnkFwd - ok
17:23:21.0406 0576 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:23:21.0437 0576 ose - ok
17:23:21.0531 0576 P3 (c90018bafdc7098619a4a95b046b30f3) C:\WINDOWS\system32\DRIVERS\p3.sys
17:23:21.0703 0576 P3 - ok
17:23:21.0750 0576 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
17:23:21.0937 0576 Parport - ok
17:23:21.0984 0576 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:23:22.0171 0576 PartMgr - ok
17:23:22.0218 0576 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
17:23:22.0437 0576 ParVdm - ok
17:23:22.0484 0576 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
17:23:22.0671 0576 PCI - ok
17:23:22.0687 0576 PCIDump - ok
17:23:22.0734 0576 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:23:22.0921 0576 PCIIde - ok
17:23:22.0968 0576 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:23:23.0156 0576 Pcmcia - ok
17:23:23.0171 0576 PDCOMP - ok
17:23:23.0187 0576 PDFRAME - ok
17:23:23.0203 0576 PDRELI - ok
17:23:23.0218 0576 PDRFRAME - ok
17:23:23.0265 0576 pepifilter (2a3efd6c3f116675d149da5e36a010a4) C:\WINDOWS\system32\DRIVERS\lv302af.sys
17:23:23.0296 0576 pepifilter - ok
17:23:23.0312 0576 perc2 - ok
17:23:23.0328 0576 perc2hib - ok
17:23:23.0437 0576 PID_08A0 (cebefeae6156f4fee41f56be89ea9c96) C:\WINDOWS\system32\DRIVERS\LV302AV.SYS
17:23:23.0562 0576 PID_08A0 - ok
17:23:23.0625 0576 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
17:23:23.0671 0576 PlugPlay - ok
17:23:23.0718 0576 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
17:23:23.0859 0576 PolicyAgent - ok
17:23:23.0906 0576 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:23:24.0109 0576 PptpMiniport - ok
17:23:24.0140 0576 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
17:23:24.0312 0576 Processor - ok
17:23:24.0328 0576 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
17:23:24.0484 0576 ProtectedStorage - ok
17:23:24.0546 0576 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:23:24.0734 0576 PSched - ok
17:23:24.0781 0576 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:23:25.0000 0576 Ptilink - ok
17:23:25.0015 0576 ql1080 - ok
17:23:25.0031 0576 Ql10wnt - ok
17:23:25.0031 0576 ql12160 - ok
17:23:25.0046 0576 ql1240 - ok
17:23:25.0062 0576 ql1280 - ok
17:23:25.0109 0576 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:23:25.0296 0576 RasAcd - ok
17:23:25.0343 0576 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
17:23:25.0515 0576 RasAuto - ok
17:23:25.0562 0576 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:23:25.0750 0576 Rasl2tp - ok
17:23:25.0796 0576 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
17:23:25.0984 0576 RasMan - ok
17:23:26.0046 0576 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:23:26.0234 0576 RasPppoe - ok
17:23:26.0296 0576 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:23:26.0500 0576 Raspti - ok
17:23:26.0531 0576 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:23:26.0703 0576 Rdbss - ok
17:23:26.0750 0576 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:23:26.0937 0576 RDPCDD - ok
17:23:26.0984 0576 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
17:23:27.0171 0576 rdpdr - ok
17:23:27.0234 0576 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
17:23:27.0296 0576 RDPWD - ok
17:23:27.0343 0576 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
17:23:27.0531 0576 RDSessMgr - ok
17:23:27.0578 0576 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:23:27.0765 0576 redbook - ok
17:23:27.0812 0576 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
17:23:27.0984 0576 RemoteAccess - ok
17:23:28.0062 0576 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
17:23:28.0250 0576 RemoteRegistry - ok
17:23:28.0296 0576 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\System32\locator.exe
17:23:28.0468 0576 RpcLocator - ok
17:23:28.0531 0576 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
17:23:28.0578 0576 RpcSs - ok
17:23:28.0640 0576 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\System32\rsvp.exe
17:23:28.0859 0576 RSVP - ok
17:23:28.0906 0576 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
17:23:29.0062 0576 SamSs - ok
17:23:29.0109 0576 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
17:23:29.0296 0576 SCardSvr - ok
17:23:29.0328 0576 SCDEmu (91f8ecfe09ae8ad46a3ef012d32b14bc) C:\WINDOWS\system32\drivers\SCDEmu.sys
17:23:29.0328 0576 SCDEmu ( UnsignedFile.Multi.Generic ) - warning
17:23:29.0328 0576 SCDEmu - detected UnsignedFile.Multi.Generic (1)
17:23:29.0375 0576 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
17:23:29.0562 0576 Schedule - ok
17:23:29.0625 0576 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:23:29.0781 0576 Secdrv - ok
17:23:29.0828 0576 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
17:23:30.0000 0576 seclogon - ok
17:23:30.0031 0576 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
17:23:30.0203 0576 SENS - ok
17:23:30.0234 0576 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:23:30.0406 0576 serenum - ok
17:23:30.0453 0576 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
17:23:30.0640 0576 Serial - ok
17:23:30.0687 0576 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:23:30.0859 0576 Sfloppy - ok
17:23:30.0921 0576 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
17:23:31.0140 0576 SharedAccess - ok
17:23:31.0187 0576 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
17:23:31.0234 0576 ShellHWDetection - ok
17:23:31.0250 0576 Simbad - ok
17:23:31.0296 0576 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
17:23:31.0468 0576 SLIP - ok
17:23:31.0546 0576 smwdm (70b8dd8707dbf6142530c106365df67d) C:\WINDOWS\system32\drivers\smwdm.sys
17:23:31.0609 0576 smwdm - ok
17:23:31.0625 0576 Sparrow - ok
17:23:31.0671 0576 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:23:31.0843 0576 splitter - ok
17:23:31.0890 0576 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
17:23:31.0953 0576 Spooler - ok
17:23:32.0031 0576 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
17:23:32.0218 0576 sr - ok
17:23:32.0265 0576 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
17:23:32.0437 0576 srservice - ok
17:23:32.0500 0576 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:23:32.0609 0576 Srv - ok
17:23:32.0625 0576 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
17:23:32.0828 0576 SSDPSRV - ok
17:23:32.0859 0576 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
17:23:33.0078 0576 stisvc - ok
17:23:33.0140 0576 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
17:23:33.0312 0576 streamip - ok
17:23:33.0343 0576 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:23:33.0515 0576 swenum - ok
17:23:33.0546 0576 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:23:33.0718 0576 swmidi - ok
17:23:33.0718 0576 SwPrv - ok
17:23:33.0765 0576 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\System32\DRIVERS\symc810.sys
17:23:33.0984 0576 symc810 - ok
17:23:34.0015 0576 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\System32\DRIVERS\symc8xx.sys
17:23:34.0218 0576 symc8xx - ok
17:23:34.0250 0576 Symmpi (f2b7e8416f508368ac6730e2ae1c614f) C:\WINDOWS\System32\DRIVERS\symmpi.sys
17:23:34.0281 0576 Symmpi ( UnsignedFile.Multi.Generic ) - warning
17:23:34.0281 0576 Symmpi - detected UnsignedFile.Multi.Generic (1)
17:23:34.0312 0576 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\System32\DRIVERS\sym_hi.sys
17:23:34.0500 0576 sym_hi - ok
17:23:34.0531 0576 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\System32\DRIVERS\sym_u3.sys
17:23:34.0734 0576 sym_u3 - ok
17:23:34.0765 0576 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:23:34.0937 0576 sysaudio - ok
17:23:34.0984 0576 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
17:23:35.0187 0576 SysmonLog - ok
17:23:35.0281 0576 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
17:23:35.0468 0576 TapiSrv - ok
17:23:35.0531 0576 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:23:35.0609 0576 Tcpip - ok
17:23:35.0687 0576 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:23:35.0859 0576 TDPIPE - ok
17:23:35.0890 0576 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:23:36.0062 0576 TDTCP - ok
17:23:36.0109 0576 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:23:36.0296 0576 TermDD - ok
17:23:36.0359 0576 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
17:23:36.0546 0576 TermService - ok
17:23:36.0593 0576 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
17:23:36.0609 0576 Themes - ok
17:23:36.0656 0576 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\System32\tlntsvr.exe
17:23:36.0843 0576 TlntSvr - ok
17:23:36.0859 0576 TosIde - ok
17:23:36.0906 0576 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
17:23:37.0078 0576 TrkWks - ok
17:23:37.0140 0576 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:23:37.0328 0576 Udfs - ok
17:23:37.0328 0576 ultra - ok
17:23:37.0390 0576 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:23:37.0609 0576 Update - ok
17:23:37.0671 0576 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
17:23:37.0843 0576 upnphost - ok
17:23:37.0875 0576 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
17:23:38.0046 0576 UPS - ok
17:23:38.0093 0576 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\WINDOWS\system32\Drivers\usbaapl.sys
17:23:38.0156 0576 USBAAPL - ok
17:23:38.0187 0576 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
17:23:38.0390 0576 usbaudio - ok
17:23:38.0421 0576 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
17:23:38.0593 0576 usbccgp - ok
17:23:38.0625 0576 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:23:38.0796 0576 usbehci - ok
17:23:38.0828 0576 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:23:39.0000 0576 usbhub - ok
17:23:39.0046 0576 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
17:23:39.0218 0576 usbprint - ok
17:23:39.0250 0576 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:23:39.0421 0576 usbscan - ok
17:23:39.0484 0576 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:23:39.0656 0576 USBSTOR - ok
17:23:39.0687 0576 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
17:23:39.0859 0576 usbuhci - ok
17:23:39.0890 0576 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:23:40.0031 0576 VgaSave - ok
17:23:40.0078 0576 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\System32\DRIVERS\viaide.sys
17:23:40.0234 0576 ViaIde - ok
17:23:40.0296 0576 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
17:23:40.0468 0576 VolSnap - ok
17:23:40.0531 0576 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
17:23:40.0781 0576 VSS - ok
17:23:40.0843 0576 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
17:23:41.0015 0576 W32Time - ok
17:23:41.0062 0576 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:23:41.0234 0576 Wanarp - ok
17:23:41.0250 0576 WDICA - ok
17:23:41.0296 0576 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:23:41.0484 0576 wdmaud - ok
17:23:41.0562 0576 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
17:23:41.0750 0576 WebClient - ok
17:23:41.0859 0576 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
17:23:42.0031 0576 winmgmt - ok
17:23:42.0187 0576 WLSetupSvc (94a85e956a065e23e0010a6a7826243b) C:\Program Files\Windows Live\installer\WLSetupSvc.exe
17:23:42.0234 0576 WLSetupSvc - ok
17:23:42.0281 0576 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
17:23:42.0343 0576 WmdmPmSN - ok
17:23:42.0437 0576 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
17:23:42.0500 0576 Wmi - ok
17:23:42.0609 0576 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\System32\wbem\wmiapsrv.exe
17:23:42.0781 0576 WmiApSrv - ok
17:23:42.0890 0576 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
17:23:43.0000 0576 WMPNetworkSvc - ok
17:23:43.0109 0576 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:23:43.0328 0576 WS2IFSL - ok
17:23:43.0359 0576 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
17:23:43.0546 0576 wscsvc - ok
17:23:43.0609 0576 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
17:23:43.0781 0576 WSTCODEC - ok
17:23:43.0812 0576 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
17:23:43.0984 0576 wuauserv - ok
17:23:44.0031 0576 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:23:44.0093 0576 WudfPf - ok
17:23:44.0125 0576 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
17:23:44.0156 0576 WudfSvc - ok
17:23:44.0234 0576 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
17:23:44.0468 0576 WZCSVC - ok
17:23:44.0531 0576 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
17:23:44.0718 0576 xmlprov - ok
17:23:44.0781 0576 {6080A529-897E-4629-A488-ABA0C29B635E} (3ee36328e860fbf102b54608a055c6be) C:\WINDOWS\system32\drivers\ialmsbw.sys
17:23:44.0828 0576 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
17:23:44.0875 0576 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (17f39a1916733ed228eb46ad67c35426) C:\WINDOWS\system32\drivers\ialmkchw.sys
17:23:44.0921 0576 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
17:23:44.0937 0576 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:23:45.0453 0576 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
17:23:45.0453 0576 \Device\Harddisk0\DR0 - detected TDSS File System (1)
17:23:45.0484 0576 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
17:23:46.0000 0576 \Device\Harddisk1\DR1 - ok
17:23:46.0015 0576 Boot (0x1200) (94470a9ba795b89879bcc4d6b282b276) \Device\Harddisk0\DR0\Partition0
17:23:46.0015 0576 \Device\Harddisk0\DR0\Partition0 - ok
17:23:46.0031 0576 Boot (0x1200) (4cadfca791ca63a414e0790bf27b2f15) \Device\Harddisk1\DR1\Partition0
17:23:46.0031 0576 \Device\Harddisk1\DR1\Partition0 - ok
17:23:46.0031 0576 ============================================================
17:23:46.0031 0576 Scan finished
17:23:46.0031 0576 ============================================================
17:23:46.0140 2816 Detected object count: 8
17:23:46.0140 2816 Actual detected object count: 8
17:24:24.0437 2816 adpu320 ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0437 2816 adpu320 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0437 2816 CCALib8 ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0437 2816 CCALib8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0437 2816 Halt ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0437 2816 Halt ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0437 2816 HaltMonitor ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0437 2816 HaltMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0453 2816 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0453 2816 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0453 2816 SCDEmu ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0453 2816 SCDEmu ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0453 2816 Symmpi ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:24.0453 2816 Symmpi ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:24.0468 2816 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
17:24:24.0468 2816 \Device\Harddisk0\DR0\TDLFS\rsrc.dat - copied to quarantine
17:24:24.0484 2816 \Device\Harddisk0\DR0\TDLFS\bckfg.tmp - copied to quarantine
17:24:24.0593 2816 \Device\Harddisk0\DR0\TDLFS\tdlcmd.dll - copied to quarantine
17:24:24.0593 2816 \Device\Harddisk0\DR0\TDLFS - deleted
17:24:24.0593 2816 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
All processes killed
========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-2527309032-1139936588-3641913080-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-2527309032-1139936588-3641913080-1007\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-21-2527309032-1139936588-3641913080-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDesktop deleted successfully.
C:\Documents and Settings\Michelle\Application Data\Microsoft\Internet Explorer\Quick Launch\Data_Recovery.lnk moved successfully.
C:\Documents and Settings\Michelle\Desktop\Data_Recovery.lnk moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Michelle\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Michelle\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Matthew and Caleb
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 406898 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 24684 bytes
User: Michelle
->Temp folder emptied: 116795 bytes
->Temporary Internet Files folder emptied: 14274841 bytes
->Java cache emptied: 616485 bytes
->Flash cache emptied: 103830 bytes
User: NetworkService
->Temp folder emptied: 8782 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes
User: Rick
->Temp folder emptied: 653 bytes
->Temporary Internet Files folder emptied: 10270580 bytes
->Java cache emptied: 274990 bytes
->Google Chrome cache emptied: 557424 bytes
->Flash cache emptied: 388781 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 129728 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 22599 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 26.00 mb
Error creating restore point.
OTL by OldTimer - Version 3.2.50.0 log created on 06282012_172510
Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1A3B.tmp not found!
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1A41.tmp not found!
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1A88.tmp not found!
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1A8E.tmp not found!
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1AC4.tmp not found!
File\Folder C:\Documents and Settings\Michelle\Local Settings\Temp\~DF1ACA.tmp not found!
C:\Documents and Settings\Michelle\Local Settings\Temporary Internet Files\Content.IE5\S8RH1F5S\fastbutton[1].htm moved successfully.
C:\Documents and Settings\Michelle\Local Settings\Temporary Internet Files\Content.IE5\NMS2E5Q5\page__st__15__gopid__2172221[1].txt moved successfully.
C:\Documents and Settings\Michelle\Local Settings\Temporary Internet Files\Content.IE5\NMS2E5Q5\search[1].htm moved successfully.
C:\Documents and Settings\Michelle\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
Registry entries deleted on Reboot...
OTL logfile created on: 6/28/2012 5:32:15 PM - Run 5
OTL by OldTimer - Version 3.2.50.0 Folder = C:\Documents and Settings\Michelle\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.49 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 64.29% Memory free
2.09 Gb Paging File | 1.70 Gb Available in Paging File | 81.44% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 10.84 Gb Free Space | 14.55% Space Free | Partition Type: NTFS
Drive E: | 37.26 Gb Total Space | 3.58 Gb Free Space | 9.60% Space Free | Partition Type: FAT32
Computer Name: HOMEPC3 | User Name: Michelle | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/06/20 19:25:28 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michelle\Desktop\OTL.exe
PRC - [2012/05/15 10:06:46 | 000,325,448 | ---- | M] (Smilebox, Inc.) -- C:\Documents and Settings\Michelle\Application Data\Smilebox\SmileboxTray.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2011/09/19 14:50:22 | 000,993,280 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2008/05/06 18:50:40 | 002,500,096 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\SFlyStudio.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ========== MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/11/03 09:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2011/08/31 16:44:40 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2011/08/31 16:44:38 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2008/05/06 18:50:40 | 002,500,096 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\SFlyStudio.exe
MOD - [2008/05/06 18:47:32 | 000,217,600 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmslideshow.dll
MOD - [2008/05/06 18:46:28 | 000,069,632 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmopengl.dll
MOD - [2008/05/06 18:46:22 | 000,196,096 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmphotomgr.dll
MOD - [2008/05/06 18:46:06 | 000,896,000 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmwindowing.dll
MOD - [2008/05/06 18:44:44 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmdirectx.dll
MOD - [2008/05/06 18:44:38 | 000,124,416 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmimgmgr.dll
MOD - [2008/05/06 18:44:28 | 000,598,016 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmpersist.dll
MOD - [2008/05/06 18:44:10 | 000,060,928 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmbrowser.dll
MOD - [2008/05/06 18:43:54 | 000,125,952 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmimglib.dll
MOD - [2008/05/06 18:43:50 | 000,094,208 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmexiftags.dll
MOD - [2008/05/06 18:43:42 | 000,429,568 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmcommon.dll
MOD - [2008/05/06 18:43:06 | 000,065,024 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmthreading.dll
MOD - [2008/05/06 18:42:52 | 003,146,240 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\mmlangres.dll
MOD - [2008/05/05 18:58:16 | 000,383,818 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\sqlite3.dll
MOD - [2008/05/05 18:57:52 | 000,151,552 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\Studio\Bin\libexpat.dll
MOD - [2008/04/13 18:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2007/09/16 19:07:27 | 000,051,716 | ---- | M] () -- C:\WINDOWS\system32\pdf995mon.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009/03/03 14:53:08 | 000,033,176 | ---- | M] (NOS Microsystems Ltd.) [Disabled | Stopped] -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus® Helper) getPlus®
SRV - [2007/10/01 15:39:06 | 000,045,056 | ---- | M] ( ) [Disabled | Stopped] -- c:\Program Files\Soccerwinners\Halt\Halt.exe -- (Halt)
SRV - [2007/10/01 15:39:06 | 000,020,480 | ---- | M] ( ) [Disabled | Stopped] -- c:\Program Files\Soccerwinners\Halt\HaltMonitor.exe -- (HaltMonitor)
SRV - [2006/03/30 09:15:44 | 000,096,341 | ---- | M] (Canon Inc.) [Disabled | Stopped] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\DRIVERS\wATV03nt.sys -- (iAimTV2)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Rick\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\ac97intc.sys -- (ac97intc) Intel® 82801 Audio Driver Install Service (WDM)
DRV - [2012/06/27 20:37:03 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{19B62B28-0556-4437-A4FA-3BB0D682AE47}\MpKsl3e251709.sys -- (MpKsl3e251709)
DRV - [2006/05/20 04:15:25 | 000,030,588 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2005/05/27 03:46:22 | 000,913,280 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LV302AV.SYS -- (PID_08A0) QuickCam IM(PID_08A0)
DRV - [2005/05/27 03:38:00 | 000,007,136 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lv302af.sys -- (pepifilter)
DRV - [2005/05/27 03:31:28 | 000,022,016 | R--- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2004/08/03 23:29:49 | 000,019,455 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wvchntxx.sys -- (iAimFP4)
DRV - [2004/08/03 23:29:47 | 000,012,063 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wsiintxx.sys -- (iAimFP3)
DRV - [2004/08/03 23:29:45 | 000,023,615 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wch7xxnt.sys -- (iAimTV4)
DRV - [2004/08/03 23:29:43 | 000,033,599 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv04nt.sys -- (iAimTV3)
DRV - [2004/08/03 23:29:42 | 000,019,551 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv02nt.sys -- (iAimTV1)
DRV - [2004/08/03 23:29:41 | 000,029,311 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\watv01nt.sys -- (iAimTV0)
DRV - [2004/08/03 23:29:37 | 000,012,415 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv01nt.sys -- (iAimFP0)
DRV - [2004/08/03 23:29:37 | 000,012,127 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv02nt.sys -- (iAimFP1)
DRV - [2004/08/03 23:29:37 | 000,011,775 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wadv05nt.sys -- (iAimFP2)
DRV - [2004/08/03 23:29:36 | 000,161,020 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2003/05/15 18:09:32 | 000,043,136 | R--- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2002/04/04 00:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (Symmpi)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://go.compaq.com...DT/0409/bl8.aspIE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.c...ferrer:source?}IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.co...g}&sourceid=ie7 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\..\SearchScopes,DefaultScope = {993686DF-984A-47D9-83CF-F544570F72F3}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRCIE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.co...g}&sourceid=ie7IE - HKCU\..\SearchScopes\{993686DF-984A-47D9-83CF-F544570F72F3}: "URL" =
http://www.google.ca...1I7GPEA_enCA304IE - HKCU\..\SearchScopes\{A586AAFC-3D30-49C0-B007-B18586008F31}: "URL" =
http://search.yahoo....ei=utf-8&fr=ie8IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.condui...4&ctid=CT340574IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Documents and Settings\Michelle\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: C:\Documents and Settings\Michelle\Application Data\nprhapengine.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Michelle\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
O1 HOSTS File: ([2012/06/28 17:25:12 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ShutterflyStudio] C:\Documents and Settings\Michelle\Desktop\Studio\BIN\SFlyStudio.exe ()
O4 - HKCU..\Run: [SmileboxTray] C:\Documents and Settings\Michelle\Application Data\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found
O4 - Startup: C:\Documents and Settings\Michelle\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0}
https://securedoc.sa...wer.com/qp2.cab (QuickPlace Class)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF}
http://download.micr...20/pmupd806.exe (MSN Money Charting)
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC}
http://upload.facebo...otoUploader.cab (Facebook Photo Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1179431535093 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.mi...b?1180668558656 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A}
http://web1.shutterf...ds/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809}
http://www.walmartph...veX_Control.cab (Photo Upload Plugin Class)
O16 - DPF: {C42B23DF-334C-4AD0-9AB4-91FF53D04239} file:///C:/Documents%20and%20Settings/Michelle/Application%20Data/Smilebox/OzDesktopImporter.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} Reg Error: Key error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD}
http://www.walmartph...pv2.0.0.12.cab? (Photo Upload Plugin Class)
O16 - DPF: {F8FC1530-0608-11DF-2008-0800200C9A66}
https://access.rcsd....ies/instweb.cab (CSD ActiveX Installer)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.222 208.67.220.220 65.87.230.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1DEE6D3E-36FF-49A0-A898-A6C153E5FD93}: DhcpNameServer = 208.67.222.222 208.67.220.220 65.87.230.4
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll File not found
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/12/21 06:18:12 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/06/28 17:25:39 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/06/28 17:22:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michelle\Desktop\tdsskiller
[2012/06/27 20:36:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michelle\Desktop\RK_Quarantine
[2012/06/27 20:36:46 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Michelle\Desktop\OTL.exe
[2012/06/27 20:30:05 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/06/26 19:58:23 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/06/26 17:53:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/06/26 17:53:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/06/26 17:53:27 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/06/26 17:53:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/06/26 17:52:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/06/23 16:56:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/23 16:56:00 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/06/18 21:19:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michelle\My Documents\Copy of K4J Get Moving Games
[2012/06/18 20:29:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Michelle\Start Menu\Programs\Data Recovery
[2012/06/18 20:26:00 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Michelle\Recent
[2012/06/06 12:14:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2012/06/03 20:17:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2012/06/03 20:16:23 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/06/03 20:12:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2012/06/03 20:11:43 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/06/03 20:02:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\QuickTime
[2012/06/03 20:02:17 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
========== Files - Modified Within 30 Days ========== [2012/06/28 17:29:42 | 000,001,158 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/06/28 17:29:34 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/28 17:29:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/06/28 17:29:23 | 1601,753,088 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/28 17:25:12 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/06/28 17:07:00 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/27 20:42:56 | 000,000,384 | ---- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/06/27 20:37:06 | 000,468,718 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/06/27 20:37:06 | 000,079,142 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/06/27 20:36:00 | 000,000,308 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\google.url
[2012/06/27 20:35:46 | 000,000,428 | ---- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8194FAB8-47E9-45C7-824B-B5F660D581C0}.job
[2012/06/26 17:36:37 | 001,535,488 | ---- | M] () -- C:\Documents and Settings\Michelle\Desktop\RogueKiller.exe
[2012/06/25 18:32:23 | 000,000,005 | ---- | M] () -- C:\test.bat
[2012/06/23 13:45:26 | 000,000,244 | ---- | M] () -- C:\sqmnoopt18.sqm
[2012/06/23 13:45:26 | 000,000,232 | ---- | M] () -- C:\sqmdata17.sqm
[2012/06/20 19:25:28 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Michelle\Desktop\OTL.exe
[2012/06/13 05:17:05 | 000,356,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/06/12 21:06:23 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/06/06 12:14:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/06/03 20:17:24 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/05/31 13:28:02 | 000,149,361 | ---- | M] () -- C:\Documents and Settings\Michelle\My Documents\shiki
========== Files Created - No Company Name ========== [2012/06/27 20:36:46 | 001,535,488 | ---- | C] () -- C:\Documents and Settings\Michelle\Desktop\RogueKiller.exe
[2012/06/27 20:35:39 | 000,000,308 | ---- | C] () -- C:\Documents and Settings\Michelle\Desktop\google.url
[2012/06/26 17:53:27 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/06/26 17:53:27 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/06/26 17:53:27 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/06/26 17:53:27 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/06/26 17:53:27 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/06/25 18:32:05 | 000,000,005 | ---- | C] () -- C:\test.bat
[2012/06/23 13:45:26 | 000,000,244 | ---- | C] () -- C:\sqmnoopt18.sqm
[2012/06/23 13:45:26 | 000,000,232 | ---- | C] () -- C:\sqmdata17.sqm
[2012/06/22 20:50:01 | 000,001,846 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN Explorer.lnk
[2012/06/22 20:50:01 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/06/22 20:50:01 | 000,001,605 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2012/06/22 20:50:00 | 000,002,387 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Money 2003.lnk
[2012/06/22 20:49:58 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2012/06/22 20:49:58 | 000,001,830 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012/06/21 21:54:35 | 1601,753,088 | -HS- | C] () -- C:\hiberfil.sys
[2012/06/03 20:17:24 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2012/06/03 19:51:04 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/05/31 13:28:00 | 000,149,361 | ---- | C] () -- C:\Documents and Settings\Michelle\My Documents\shiki
[2011/09/15 22:04:01 | 000,000,129 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2011/04/02 17:25:14 | 000,080,808 | ---- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/09/04 14:50:41 | 000,001,664 | -H-- | C] () -- C:\WINDOWS\lsrslt.ini
========== LOP Check ========== [2007/06/24 18:00:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/05/21 20:56:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\GARMIN
[2010/04/07 16:48:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
[2009/02/08 23:23:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\muvee Technologies
[2012/05/27 16:20:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\pdf995
[2007/07/09 18:40:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
[2010/12/28 23:05:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2008/09/10 21:55:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Aim
[2007/11/06 21:35:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Canon
[2011/04/12 15:47:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Cisco
[2009/08/31 19:38:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/21 12:17:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Facebook
[2010/05/21 20:56:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\GARMIN
[2010/04/19 10:34:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\LEGO Company
[2007/07/02 20:55:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Shutterfly
[2012/06/23 21:50:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Smilebox
[2009/07/11 22:06:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Template
[2009/11/19 16:46:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Michelle\Application Data\Unity
[2012/06/27 20:35:46 | 000,000,428 | ---- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8194FAB8-47E9-45C7-824B-B5F660D581C0}.job
========== Purity Check ========== < End of report >