WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Changed the default search settings. Deleted the yahoo one. Keeps happening as soon as you reopen a window. Please help. Downloaded Malwarebytes Anti-Malware. Nothing is helping.

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*****************************************************************
SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!


Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
*********************************************
Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall Mbamicontw5 Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Download DDS from HERE or HERE and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall DDS

1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by Kimberley Davis at 21:26:23 on 2012-08-25
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.343 [GMT -6:00]
.
AV: avast! Internet Security *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Kimberley Davis\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kimberley Davis\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kimberley Davis\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kimberley Davis\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Kimberley Davis\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.babylon.com/?affID=109935&tt=010712_2&babsrc=HP_ss&mntrId=983a0d90000000000000001111be41ca
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\kimberley davis\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: []
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 9.0\acrobat\Acrotray.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.6.0.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{D3562BE4-94E7-4E6F-99F8-581C998A89D5} : DhcpNameServer = 209.18.47.61 209.18.47.62
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: LMIinit - LMIinit.dll
AppInit_DLLs: acaptuser32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\kimberley davis\application data\mozilla\firefox\profiles\xghrpk7x.default\
.
============= SERVICES / DRIVERS ===============
.
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2012-5-3 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2012-5-3 202928]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2012-5-3 113776]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-5-3 18544]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-5-3 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-5-3 355632]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-5-3 21256]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-5-3 44808]
R2 avast! Firewall;avast! Firewall;c:\program files\avast software\avast\afwServ.exe [2012-5-3 133912]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2012-1-31 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-9-16 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2012-5-2 47640]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-25 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-25 22344]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-9 113120]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== Created Last 30 ================
.
2012-08-26 01:08:54 -------- d-----w- c:\documents and settings\kimberley davis\application data\Malwarebytes
2012-08-26 01:08:40 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-08-26 01:08:38 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-26 01:08:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-26 00:50:26 -------- d-----w- c:\documents and settings\kimberley davis\application data\SUPERAntiSpyware.com
2012-08-26 00:50:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-08-26 00:50:13 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2012-08-25 14:26:29 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-08-25 14:26:29 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-25 14:24:16 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-08-24 22:30:49 -------- d-----w- c:\documents and settings\kimberley davis\application data\com.w3i.intune
2012-08-24 22:30:04 -------- d-----w- c:\program files\W3i
2012-08-24 22:30:04 -------- d-----w- c:\documents and settings\all users\application data\W3i
2012-08-24 22:30:03 -------- d-----w- c:\documents and settings\all users\application data\Tarma Installer
2012-08-24 22:29:46 -------- d-----w- c:\program files\Free Offers from Freeze.com
2012-08-24 22:29:45 -------- d-----w- c:\program files\Chrome
2012-08-24 22:29:44 -------- d-----w- c:\documents and settings\all users\application data\WeCareReminder
2012-07-27 20:51:30 184248 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
.
==================== Find3M ====================
.
2012-08-21 09:13:15 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13:14 202928 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-08-21 09:13:14 18544 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-08-21 09:13:13 113776 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-08-21 09:12:33 41224 ----a-w- c:\windows\avastSS.scr
2012-07-27 01:53:13 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 01:53:12 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49:33 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49:32 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05:43 385024 ------w- c:\windows\system32\html.iec
2012-06-05 15:50:25 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:08 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 21:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 21:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 21:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 21:19:34 15384 -c--a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 21:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
.
============= FINISH: 21:27:13.07 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/2/2012 4:23:32 PM
System Uptime: 8/25/2012 9:18:36 PM (0 hours ago)
.
Motherboard: Dell Inc. | | 0U7077
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz | Microprocessor | 3192/800mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 279 GiB total, 199.517 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP51: 5/28/2012 6:44:30 PM - System Checkpoint
RP52: 5/29/2012 7:21:31 PM - System Checkpoint
RP53: 5/31/2012 7:23:32 AM - System Checkpoint
RP54: 6/1/2012 7:24:46 AM - System Checkpoint
RP55: 6/2/2012 7:39:39 AM - System Checkpoint
RP56: 6/3/2012 8:18:52 AM - System Checkpoint
RP57: 6/4/2012 8:49:37 AM - System Checkpoint
RP58: 6/4/2012 8:14:49 PM - Software Distribution Service 3.0
RP59: 6/6/2012 7:19:50 AM - System Checkpoint
RP60: 6/7/2012 7:57:29 AM - System Checkpoint
RP61: 6/8/2012 8:18:21 AM - System Checkpoint
RP62: 6/9/2012 8:28:50 AM - System Checkpoint
RP63: 6/10/2012 9:04:17 AM - System Checkpoint
RP64: 6/11/2012 9:34:16 AM - System Checkpoint
RP65: 6/12/2012 10:11:10 AM - System Checkpoint
RP66: 6/13/2012 12:48:41 PM - System Checkpoint
RP67: 6/13/2012 8:56:34 PM - Software Distribution Service 3.0
RP68: 6/15/2012 8:24:05 AM - System Checkpoint
RP69: 6/15/2012 12:02:04 PM - Removed Java(TM) 6 Update 32
RP70: 6/15/2012 12:02:43 PM - Installed Java(TM) 7 Update 5
RP71: 6/15/2012 12:03:23 PM - Installed JavaFX 2.1.1
RP72: 6/15/2012 12:22:58 PM - Installed Windows 7 Upgrade Advisor
RP73: 6/15/2012 12:40:51 PM - Removed Windows 7 Upgrade Advisor
RP74: 6/16/2012 1:23:06 PM - System Checkpoint
RP75: 6/17/2012 1:50:11 PM - System Checkpoint
RP76: 6/18/2012 2:58:50 PM - System Checkpoint
RP77: 6/19/2012 3:45:10 PM - System Checkpoint
RP78: 6/20/2012 7:47:16 PM - System Checkpoint
RP79: 6/22/2012 7:20:57 AM - System Checkpoint
RP80: 6/22/2012 1:06:09 PM - Removed Java(TM) 7 Update 5
RP81: 6/22/2012 1:07:34 PM - Installed Java(TM) 7 Update 5
RP82: 6/23/2012 1:45:16 PM - System Checkpoint
RP83: 6/24/2012 1:47:38 PM - System Checkpoint
RP84: 6/25/2012 3:01:25 PM - System Checkpoint
RP85: 6/26/2012 3:37:45 PM - System Checkpoint
RP86: 6/27/2012 5:24:19 PM - System Checkpoint
RP87: 6/28/2012 5:31:53 PM - System Checkpoint
RP88: 6/29/2012 6:01:00 PM - System Checkpoint
RP89: 6/30/2012 6:39:40 PM - System Checkpoint
RP90: 7/1/2012 8:17:04 AM - System Checkpoint
RP91: 7/2/2012 8:25:41 AM - System Checkpoint
RP92: 7/3/2012 9:29:27 AM - System Checkpoint
RP93: 7/4/2012 9:32:26 AM - System Checkpoint
RP94: 7/5/2012 9:48:50 AM - System Checkpoint
RP95: 7/6/2012 9:58:14 AM - System Checkpoint
RP96: 7/7/2012 10:16:31 AM - System Checkpoint
RP97: 7/8/2012 11:42:28 AM - System Checkpoint
RP98: 7/9/2012 12:27:20 PM - System Checkpoint
RP99: 7/10/2012 12:38:40 PM - System Checkpoint
RP100: 7/11/2012 1:05:37 PM - System Checkpoint
RP101: 7/11/2012 7:39:18 PM - Removed BabylonObjectInstaller
RP102: 7/11/2012 9:51:56 PM - Software Distribution Service 3.0
RP103: 7/13/2012 7:16:27 AM - System Checkpoint
RP104: 7/14/2012 7:52:09 AM - System Checkpoint
RP105: 7/15/2012 8:50:44 AM - System Checkpoint
RP106: 7/16/2012 11:13:56 AM - System Checkpoint
RP107: 7/17/2012 12:01:55 PM - System Checkpoint
RP108: 7/18/2012 12:45:14 PM - System Checkpoint
RP109: 7/19/2012 2:04:27 PM - System Checkpoint
RP110: 7/20/2012 2:40:11 PM - System Checkpoint
RP111: 7/21/2012 4:45:37 PM - System Checkpoint
RP112: 7/22/2012 5:02:25 PM - System Checkpoint
RP113: 7/23/2012 5:13:27 PM - System Checkpoint
RP114: 7/24/2012 5:41:22 PM - System Checkpoint
RP115: 7/25/2012 6:05:02 PM - System Checkpoint
RP116: 7/26/2012 6:38:47 PM - System Checkpoint
RP117: 7/27/2012 7:08:40 PM - System Checkpoint
RP118: 7/28/2012 7:30:11 PM - System Checkpoint
RP119: 7/30/2012 8:00:25 AM - System Checkpoint
RP120: 7/31/2012 8:37:05 AM - System Checkpoint
RP121: 8/1/2012 8:48:11 AM - System Checkpoint
RP122: 8/2/2012 9:46:55 AM - System Checkpoint
RP123: 8/3/2012 9:51:30 AM - System Checkpoint
RP124: 8/4/2012 10:46:13 AM - System Checkpoint
RP125: 8/5/2012 11:15:36 AM - System Checkpoint
RP126: 8/6/2012 12:36:27 PM - System Checkpoint
RP127: 8/7/2012 1:28:39 PM - System Checkpoint
RP128: 8/8/2012 1:47:56 PM - System Checkpoint
RP129: 8/9/2012 2:03:35 PM - System Checkpoint
RP130: 8/10/2012 3:11:36 PM - System Checkpoint
RP131: 8/11/2012 3:44:06 PM - System Checkpoint
RP132: 8/12/2012 3:58:41 PM - System Checkpoint
RP133: 8/13/2012 4:23:45 PM - System Checkpoint
RP134: 8/14/2012 5:12:06 PM - System Checkpoint
RP135: 8/15/2012 5:17:36 PM - System Checkpoint
RP136: 8/15/2012 8:12:44 PM - Software Distribution Service 3.0
RP137: 8/20/2012 2:57:07 PM - System Checkpoint
RP138: 8/21/2012 3:21:06 PM - System Checkpoint
RP139: 8/22/2012 5:42:33 PM - System Checkpoint
RP140: 8/24/2012 7:14:39 AM - System Checkpoint
RP141: 8/24/2012 4:33:39 PM - Removed inTuneMP3
RP142: 8/24/2012 4:39:49 PM - Removed SavetheChildren Reminder by We-Care.com v4.1.18.4
RP143: 8/25/2012 8:23:04 AM - Restore Operation
.
==== Installed Programs ======================
.
Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
Adobe Acrobat 9.5.1 - CPSID_83708
Adobe AIR
Adobe Community Help
Adobe Creative Suite 5 Design Premium
Adobe Flash Player 11 ActiveX
Adobe Media Player
Adobe Reader X (10.1.4)
Adobe Shockwave Player 11.6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Display Driver
avast! Internet Security
Bonjour
Compatibility Pack for the 2007 Office system
Google Chrome
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
iTunes
Java Auto Updater
Java(TM) 7 Update 5
JavaFX 2.1.1
LogMeIn
Malwarebytes Anti-Malware version 1.62.0.1300
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox 13.0.1 (x86 en-US)
Mozilla Maintenance Service
OGA Notifier 2.0.0048.0
PDF Settings CS5
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544521)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2675157)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
SUPERAntiSpyware
swMSM
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2718704)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
.
==== Event Viewer Messages From Past Week ========
.
8/25/2012 9:19:53 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
8/25/2012 9:19:11 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
.
==== End Of File ===========================


Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.25.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Kimberley Davis :: OWNER-756206CFD [administrator]

Protection: Enabled

8/25/2012 7:12:49 PM
mbam-log-2012-08-25 (19-12-49).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 337976
Time elapsed: 2 hour(s), 2 minute(s), 46 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCU\SOFTWARE\CROSSRIDER (Adware.GamePlayLab) -> Quarantined and deleted successfully.

Registry Values Detected: 1
HKCU\Software\Crossrider|215AppVerifier (Adware.GamePlayLab) -> Data: 83d5334eed57948909e0f20258c8c889 -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 7
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP101\A0034588.dll (PUP.GamePlayLabs) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP101\A0034589.exe (PUP.GamePlayLabs) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP101\A0034592.exe (PUP.GamePlayLabs) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP101\A0034593.exe (PUP.GamePlayLabs) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041791.exe (PUP.BundleOffers.IIQ) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041821.exe (PUP.GamePlayLabs) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP143\A0042315.exe (PUP.BundleOffers.IIQ) -> Quarantined and deleted successfully.

(end)

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
I will still need to see the SAS log.

Please download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall AswMBR_Scan

Click the "Scan" button to start scan

Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall AswMBR_SaveLog

On completion of the scan click save log, save it to your desktop and post in your next reply
*******************************************************************************
Download Combofix from any of the links below, and save it to your DESKTOP.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.

  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall NSIS_disclaimer_ENG

Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall NSIS_extraction

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall RcAuto1

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall Whatnext

Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/25/2012 at 07:00 PM

Application Version : 5.5.1012

Core Rules Database Version : 9124
Trace Rules Database Version: 6936

Scan type : Quick Scan
Total Scan Time : 00:05:10

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 497
Memory threats detected : 0
Registry items scanned : 28897
Registry threats detected : 0
File items scanned : 7004
File threats detected : 176

Adware.Tracking Cookie
C:\Documents and Settings\Kimberley Davis\Cookies\P2F9030D.txt [ /atdmt.com ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.c1.atdmt.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.evite.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.ru4.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.steelhousemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.px.steelhousemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.overture.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.legolas-media.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.yieldmanager.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.apmebf.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.azjmp.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.azjmp.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.linksynergy.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.linksynergy.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.linksynergy.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.linksynergy.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.specificclick.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.fastclick.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.accounts.google.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.accounts.google.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.amazon-adsystem.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.amazon-adsystem.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
accounts.youtube.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
base.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adserver.adtechus.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adbrite.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.dmtracker.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.burstnet.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.questionmarket.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.questionmarket.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.questionmarket.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.apmebf.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.mediaplex.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.mediaplex.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.microsoftwlsearchcrm.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atdmt.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.c.atdmt.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.c.atdmt.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
accounts.google.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
accounts.google.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
imp.bid.ace.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
wstat.wibiya.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.zedo.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.mm.chitika.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
server.iad.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
server.iad.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
server.iad.liveperson.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.statcounter.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tribalfusion.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adbrite.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.casalemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.ar.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.advertising.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.media6degrees.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.realmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.realmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.realmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
network.realmedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.tacoda.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.at.atwola.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.revsci.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.statcounter.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.collective-media.net [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.adbrite.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\KIMBERLEY DAVIS\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]




ComboFix 12-08-25.04 - Kimberley Davis 08/26/2012 18:09:51.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.301 [GMT -6:00]
Running from: c:\documents and settings\Kimberley Davis\Desktop\ComboFix.exe
AV: avast! Internet Security *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: avast! Internet Security *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-27 to 2012-08-27 )))))))))))))))))))))))))))))))
.
.
2012-08-26 01:08 . 2012-08-26 01:08 -------- d-----w- c:\documents and settings\Kimberley Davis\Application Data\Malwarebytes
2012-08-26 01:08 . 2012-08-26 01:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-26 01:08 . 2012-08-26 01:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-26 01:08 . 2012-07-03 19:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-26 00:50 . 2012-08-26 00:50 -------- d-----w- c:\documents and settings\Kimberley Davis\Application Data\SUPERAntiSpyware.com
2012-08-26 00:50 . 2012-08-26 00:50 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-08-26 00:50 . 2012-08-26 00:50 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-25 14:26 . 2012-08-25 14:26 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-25 14:24 . 2012-08-25 14:24 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-08-24 22:30 . 2012-08-24 22:30 -------- d-----w- c:\documents and settings\Kimberley Davis\Application Data\com.w3i.intune
2012-08-24 22:30 . 2012-08-24 22:30 -------- d-----w- c:\program files\W3i
2012-08-24 22:30 . 2012-08-24 22:30 -------- d-----w- c:\documents and settings\All Users\Application Data\W3i
2012-08-24 22:30 . 2012-08-25 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Tarma Installer
2012-08-24 22:29 . 2012-08-25 14:24 -------- d-----w- c:\program files\Free Offers from Freeze.com
2012-08-24 22:29 . 2012-08-24 22:29 -------- d-----w- c:\program files\Chrome
2012-08-24 22:29 . 2012-08-25 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\WeCareReminder
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-21 09:13 . 2012-05-03 19:12 355632 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2012-05-03 19:11 729752 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2012-05-03 19:11 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2012-05-03 19:11 202928 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2012-08-21 09:13 . 2012-05-03 19:11 35928 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2012-05-03 19:11 18544 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-08-21 09:13 . 2012-05-03 19:11 97608 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-08-21 09:13 . 2012-05-03 19:11 89624 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-08-21 09:13 . 2012-05-03 19:12 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:13 . 2012-05-03 19:12 113776 ----a-w- c:\windows\system32\drivers\aswFW.sys
2012-08-21 09:13 . 2012-05-03 19:11 25256 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-08-21 09:12 . 2012-05-03 19:11 41224 ----a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2012-05-03 19:11 227648 ----a-w- c:\windows\system32\aswBoot.exe
2012-07-27 01:53 . 2012-05-03 15:39 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-27 01:53 . 2012-05-03 15:39 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2012-05-02 22:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2008-04-14 12:00 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-06-05 15:50 . 2008-04-14 12:00 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2008-04-14 12:00 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 21:19 . 2009-08-07 01:24 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 21:19 . 2012-05-02 22:19 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 21:19 . 2012-05-02 22:19 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 21:19 . 2012-05-02 22:19 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 21:19 . 2009-08-07 01:24 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 21:19 . 2012-05-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 21:19 . 2012-05-02 22:19 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 21:19 . 2009-08-07 01:24 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 21:19 . 2009-08-07 01:24 15384 -c--a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 21:19 . 2008-04-14 12:00 97304 -c--a-w- c:\windows\system32\cdm.dll
2012-06-02 21:19 . 2009-08-07 01:24 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 21:19 . 2012-05-02 22:19 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 21:19 . 2012-05-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2008-04-14 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-06-14 22:20 . 2012-07-09 16:34 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-09-16 63048]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2012-05-03 273528]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-03-27 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-03-26 640440]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-02-01 03:30 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\acaptuser32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [5/3/2012 1:11 PM 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [5/3/2012 1:11 PM 202928]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [5/3/2012 1:12 PM 113776]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [5/3/2012 1:11 PM 18544]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [5/3/2012 1:11 PM 729752]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5/3/2012 1:12 PM 355632]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 10:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 3:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 5:38 PM 116608]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/3/2012 1:12 PM 21256]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [5/3/2012 1:11 PM 133912]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [1/31/2012 9:30 PM 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [9/16/2011 2:10 PM 12856]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/25/2012 7:08 PM 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/25/2012 7:08 PM 22344]
S0 cerc6;cerc6; [x]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [7/9/2012 10:34 AM 113120]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-07 c:\windows\Tasks\AdobeAAMUpdater-1.0-OWNER-756206CFD-Kimberley Davis.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-05-18 09:44]
.
2012-08-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57]
.
2012-08-26 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-06-30 09:12]
.
2012-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-789336058-1606980848-1003Core.job
- c:\documents and settings\Kimberley Davis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-05-03 17:08]
.
2012-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-789336058-1606980848-1003UA.job
- c:\documents and settings\Kimberley Davis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-05-03 17:08]
.
2012-08-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-789336058-1606980848-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 19:40]
.
2012-08-23 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-789336058-1606980848-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 19:40]
.
2012-08-26 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 3a139577-44e8-4c81-a5c9-58263fc5fd1f.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-08-26 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 54e0d0c8-69bc-4366-8e13-260f3e83b9c9.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.babylon.com/?affID=109935&tt=010712_2&babsrc=HP_ss&mntrId=983a0d90000000000000001111be41ca
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert link target to existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\documents and settings\Kimberley Davis\Application Data\Mozilla\Firefox\Profiles\xghrpk7x.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-26 18:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\avast! sandbox
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1180)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2012-08-26 18:26:38
ComboFix-quarantined-files.txt 2012-08-27 00:26
.
Pre-Run: 213,943,115,776 bytes free
Post-Run: 214,041,485,312 bytes free
.
- - End Of File - - 73B88540D8E549D529C3A9584CDF66A2





aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-26 17:44:41
-----------------------------
17:44:41.468 OS Version: Windows 5.1.2600 Service Pack 3
17:44:41.468 Number of processors: 2 586 0x304
17:44:41.468 ComputerName: OWNER-756206CFD UserName: Kimberley Davis
17:44:43.953 Initialize success
17:44:44.234 AVAST engine defs: 12082601
17:44:52.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
17:44:52.937 Disk 0 Vendor: ST3300822AS 3.AHH Size: 286168MB BusType: 3
17:44:52.953 Disk 0 MBR read successfully
17:44:52.953 Disk 0 MBR scan
17:44:53.015 Disk 0 Windows XP default MBR code
17:44:53.015 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 286157 MB offset 63
17:44:53.015 Disk 0 scanning sectors +586051200
17:44:53.093 Disk 0 scanning C:\WINDOWS\system32\drivers
17:45:02.578 Service scanning
17:45:15.109 Modules scanning
17:45:21.734 Disk 0 trace - called modules:
17:45:21.765 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll intelide.sys PCIIDEX.SYS
17:45:21.765 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x867c6ab8]
17:45:21.765 3 CLASSPNP.SYS[f78a4fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x86796d98]
17:45:22.343 AVAST engine scan C:\WINDOWS
17:45:30.531 AVAST engine scan C:\WINDOWS\system32
17:47:21.828 AVAST engine scan C:\WINDOWS\system32\drivers
17:47:34.812 AVAST engine scan C:\Documents and Settings\Kimberley Davis
17:54:42.953 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Kimberley Davis\Desktop\MBR.dat"
17:54:42.953 The log file has been saved successfully to "C:\Documents and Settings\Kimberley Davis\Desktop\aswMBR.txt"




descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
***********************************************
SysProt Antirootkit

Download
SysProt Antirootkit from the link below (you will find it at the bottom
of the page under attachments, or you can get it from one of the
mirrors).

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select the following items.

    • Process << Selected
    • Kernel Modules << Selected
    • SSDT << Selected
    • Kernel Hooks << Selected
    • IRP Hooks << NOT Selected
    • Ports << NOT Selected
    • Hidden Files << Selected

  • At the bottom of the page

    • Hidden Objects Only << Selected

  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Results of screen317's Security Check version 0.99.46
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
avast! Internet Security
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
SUPERAntiSpyware
Malwarebytes Anti-Malware version 1.62.0.1300
JavaFX 2.1.1
Java(TM) 7 Update 5
Java version out of Date!
Adobe Reader X (10.1.4)
Mozilla Firefox 13.0.1 Firefox out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
AVAST Software Avast afwServ.exe
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 0%
````````````````````End of Log``````````````````````




SysProt AntiRootkit v1.0.1.0
by swatkat

******************************************************************************************
******************************************************************************************

No Hidden Processes found

******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: EE966000
Module End: EE97E000
Hidden: Yes

Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
Service Name: ---
Module Base: F7D9E000
Module End: F7DA0000
Hidden: Yes

Module Name: \??\C:\DOCUME~1\KIMBER~1\LOCALS~1\Temp\aswMBR.sys
Service Name: aswMBR
Module Base: EC4CA000
Module End: EC4D6000
Hidden: Yes

Module Name: \??\C:\WINDOWS\system32\Drivers\PROCEXP113.SYS
Service Name: ---
Module Base: F7DC8000
Module End: F7DCA000
Hidden: Yes

Module Name: \??\C:\DOCUME~1\KIMBER~1\LOCALS~1\Temp\catchme.sys
Service Name: catchme
Module Base: F7BBC000
Module End: F7BC4000
Hidden: Yes

******************************************************************************************
******************************************************************************************
SSDT:
Function Name: ZwAddBootEntry
Address: EE9BC708
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwAllocateVirtualMemory
Address: EEA677C8
Driver Base: EEA5B000
Driver End: EEAB0000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS

Function Name: ZwAssignProcessToJobObject
Address: EE9BD11C
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwClose
Address: EE9FE401
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateEvent
Address: EE9C7F28
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateEventPair
Address: EE9C7F74
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateIoCompletion
Address: EE9C80F6
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateKey
Address: EE9FDDB5
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateMutant
Address: EE9C7E96
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateSection
Address: EE9C7FB8
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateSemaphore
Address: EE9C7EDE
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateThread
Address: EE9BD310
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwCreateTimer
Address: EE9C80B0
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwDebugActiveProcess
Address: EE9BDA9C
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwDeleteBootEntry
Address: EE9BC756
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwDeleteKey
Address: EE9FEAC7
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwDeleteValueKey
Address: EE9FED7D
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwDuplicateObject
Address: EE9C10E4
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwEnumerateKey
Address: EE9FE932
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwEnumerateValueKey
Address: EE9FE79D
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwFreeVirtualMemory
Address: EEA678AC
Driver Base: EEA5B000
Driver End: EEAB0000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS

Function Name: ZwLoadDriver
Address: EE9BC3BE
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwModifyBootEntry
Address: EE9BC7A4
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwNotifyChangeKey
Address: EE9C1456
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwNotifyChangeMultipleKeys
Address: EE9BE464
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenEvent
Address: EE9C7F52
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenEventPair
Address: EE9C7F96
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenIoCompletion
Address: EE9C811A
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenKey
Address: EE9FE111
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenMutant
Address: EE9C7EBC
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenProcess
Address: EE9C0C5A
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenSection
Address: EE9C803A
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenSemaphore
Address: EE9C7F06
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenThread
Address: EE9C0E8C
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwOpenTimer
Address: EE9C80D4
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwProtectVirtualMemory
Address: EEA67A2C
Driver Base: EEA5B000
Driver End: EEAB0000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS

Function Name: ZwQueryKey
Address: EE9FE618
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwQueryObject
Address: EE9BE330
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwQueryValueKey
Address: EE9FE46A
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwQueueApcThread
Address: EE9BDEDA
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwRenameKey
Address: EEA7330E
Driver Base: EEA5B000
Driver End: EEAB0000
Driver Name: \SystemRoot\System32\Drivers\aswSP.SYS

Function Name: ZwRestoreKey
Address: EE9FD428
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetBootEntryOrder
Address: EE9BC7F2
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetBootOptions
Address: EE9BC840
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetContextThread
Address: EE9BD91C
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetSystemInformation
Address: EE9BC448
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetSystemPowerState
Address: EE9BC5F8
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSetValueKey
Address: EE9FEBCE
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwShutdownSystem
Address: EE9BC59E
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSuspendProcess
Address: EE9BDBFE
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSuspendThread
Address: EE9BDD5A
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwSystemDebugControl
Address: EE9BC668
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwTerminateProcess
Address: EEB55640
Driver Base: EEB4B000
Driver End: EEB6D000
Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

Function Name: ZwTerminateThread
Address: EE9BD794
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwVdmControl
Address: EE9BC88E
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

Function Name: ZwWriteVirtualMemory
Address: EE9BD160
Driver Base: EE9A6000
Driver End: EEA5B000
Driver Name: \SystemRoot\System32\Drivers\aswSnx.SYS

******************************************************************************************
******************************************************************************************
Kernel Hooks:
Hooked Function: ZwCreateProcessEx
At Address: 8058B7F4
Jump To: EEA7F96A
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS

Hooked Function: PsGetThreadWin32Thread
At Address: 804E6BFC
Jump To: F5806135
Module Name: _unknown_

Hooked Function: PsGetProcessWin32Process
At Address: 804E6BFC
Jump To: F5806135
Module Name: _unknown_

Hooked Function: PsGetCurrentProcessSessionId
At Address: 804EA47C
Jump To: 72CF044B
Module Name: _unknown_

Hooked Function: ObMakeTemporaryObject
At Address: 805E0536
Jump To: EEA7C806
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS

Hooked Function: ObInsertObject
At Address: 8056DA64
Jump To: EEA7E320
Module Name: C:\WINDOWS\System32\Drivers\aswSP.SYS

******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\Documents and Settings\Kimberley Davis\Application Data\Adobe\Flash Player\APSPrivateData2\0\2836e5ca\R6Uz1DHckRR4BcuLJ8DtKrlEk2s=\SbJVsrWvzia9YuK1nMdjYe_4dEcE=\QzI1NkRENkMtMkM2OS0zOEVCLUJEMEMtQzg0NkUxOTI4NjlD\QUIyQTFCMTktRkMzNC0zOEQ1LUIzNEMtMTEyN0Q3OT
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\Application Data\Adobe\Flash Player\APSPrivateData2\0\2836e5ca\R6Uz1DHckRR4BcuLJ8DtKrlEk2s=\SnOZTw83Phaj__bdvATTqdO2KRTc=\MDk4QjUxNEQtRUUzRS0zRTMyLUI2NEYtQzc0MTlBQkM0OEU5\NjBGNkEyMkQtQ0QwOS0zNEU4LTgyMTMtMkYxQjQ0RD
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\CS5\Extracted Files\Adobe Creative Suite 5 Design Premium\Creative Suite 5 Design Premium - Ctete.pdf
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\CS5\Extracted Files\Adobe Creative Suite 5 Web Premium\Creative Suite 5 Web Premium - Ctete.pdf
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\CS5\Extracted Files\Magyar\Hasznos eszközök\Betutípusok
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\CS5\Extracted Files\Türkçe\Sekerlemeler
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\CS5\Extracted Files\Ceský
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\InDesign5\Extracted Files\Adobe Creative Suite 5 Design Premium\Creative Suite 5 Design Premium - Ctete.pdf
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\InDesign5\Extracted Files\Adobe Creative Suite 5 Web Premium\Creative Suite 5 Web Premium - Ctete.pdf
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\InDesign5\Extracted Files\Magyar\Hasznos eszközök\Betutípusok
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\InDesign5\Extracted Files\Türkçe\Sekerlemeler
Status: Hidden

Object: C:\Documents and Settings\Kimberley Davis\My Documents\InDesign5\Extracted Files\Ceský
Status: Hidden

Object: C:\Qoobox\BackEnv\AppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cache.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Cookies.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Desktop.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Favorites.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\History.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Music.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\NetHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Personal.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Pictures.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Programs.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Recent.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SendTo.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SetPath.bat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\StartUp.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\SysPath.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\Templates.folder.dat
Status: Access denied

Object: C:\Qoobox\BackEnv\VikPev00
Status: Access denied

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Are you still getting the redirects?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetAcceptTerms
•Click the Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetStart button.
•Accept any security warnings from your browser.
•Check Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetListThreats
•Push Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetBack button.
•Push Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
I didn't click "delete files" box when I clicked on "Scan Archives". Do I have to repeat the entire scan or can I go directly to the file name and delete it?

C:\Documents and Settings\Kimberley Davis\My Documents\mozilla-firefox.exe a variant of Win32/InstallCore.X application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034576.dll Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034577.dll Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034578.dll a variant of Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034579.dll Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034581.exe probably a variant of Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP113\A0037217.exe a variant of Win32/InstallCore.X application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041784.dll a variant of Win32/Adware.Yontoo.A application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041786.dll a variant of Win32/Adware.Yontoo.B application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041796.exe Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041806.exe Win32/Toolbar.Babylon application
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041822.exe Win32/Toolbar.Babylon application

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Please run it again and click "delete files"

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Here are the results of the second scan.


C:\Documents and Settings\Kimberley Davis\My Documents\mozilla-firefox.exe a variant of Win32/InstallCore.X application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034576.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034577.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034578.dll a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034579.dll Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP100\A0034581.exe probably a variant of Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP113\A0037217.exe a variant of Win32/InstallCore.X application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041784.dll a variant of Win32/Adware.Yontoo.A application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041786.dll a variant of Win32/Adware.Yontoo.B application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041796.exe Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041806.exe Win32/Toolbar.Babylon application cleaned by deleting - quarantined
C:\System Volume Information\_restore{46591F97-3E36-4675-81C5-F2AC518C2937}\RP142\A0041822.exe Win32/Toolbar.Babylon application cleaned by deleting - quarantined

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
That looks good. How's your computer working now? Any other issues before we do a cleanup?

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
It is still happening. It's also very slow today and sometimes when I double click on an icon to open something it doesn't work the first and I have to do it again. Very uncharacteristic. What do I do next?

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
It is still happening.

You're still being re-directed?


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

  • If an infected file is detected, the default action will be Cure, click on Continue.

  • If a suspicious file is detected, the default action will be Skip, click on Continue.

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
*********************************************************************

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
I cant send the logs "its telling me the message is too long" What should I do?

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
kdavis wrote:
I cant send the logs "its telling me the message is too long" What should I do?

Please split them up into two or more posts. Or you could upload them to File Dropper and send me the link.

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
18:00:11.0968 3228 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
18:00:12.0875 3228 ============================================================
18:00:12.0875 3228 Current date / time: 2012/08/29 18:00:12.0875
18:00:12.0875 3228 SystemInfo:
18:00:12.0875 3228
18:00:12.0875 3228 OS Version: 5.1.2600 ServicePack: 3.0
18:00:12.0875 3228 Product type: Workstation
18:00:12.0875 3228 ComputerName: OWNER-756206CFD
18:00:12.0875 3228 UserName: Kimberley Davis
18:00:12.0875 3228 Windows directory: C:\WINDOWS
18:00:12.0875 3228 System windows directory: C:\WINDOWS
18:00:12.0875 3228 Processor architecture: Intel x86
18:00:12.0875 3228 Number of processors: 2
18:00:12.0875 3228 Page size: 0x1000
18:00:12.0875 3228 Boot type: Normal boot
18:00:12.0875 3228 ============================================================
18:00:14.0203 3228 Drive \Device\Harddisk0\DR0 - Size: 0x45DD826000 (279.46 Gb), SectorSize: 0x200, Cylinders: 0x8E81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:00:14.0359 3228 ============================================================
18:00:14.0359 3228 \Device\Harddisk0\DR0:
18:00:14.0359 3228 MBR partitions:
18:00:14.0359 3228 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x22EE6E41
18:00:14.0359 3228 ============================================================
18:00:14.0390 3228 C: <-> \Device\Harddisk0\DR0\Partition1
18:00:14.0390 3228 ============================================================
18:00:14.0390 3228 Initialize success
18:00:14.0390 3228 ============================================================
18:00:42.0250 0700 ============================================================
18:00:42.0250 0700 Scan started
18:00:42.0250 0700 Mode: Manual;
18:00:42.0250 0700 ============================================================
18:00:42.0437 0700 ================ Scan system memory ========================
18:00:42.0453 0700 System memory - ok
18:00:42.0453 0700 ================ Scan services =============================
18:00:42.0578 0700 [ C0393EB99A6C72C6BEF9BFC4A72B33A6 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
18:00:42.0578 0700 !SASCORE - ok
18:00:42.0687 0700 [ 0352A73CD6B1782EA3ED7A03A8268F55 ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
18:00:42.0687 0700 Aavmker4 - ok
18:00:42.0703 0700 Abiosdsk - ok
18:00:42.0703 0700 abp480n5 - ok
18:00:42.0750 0700 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:00:42.0750 0700 ACPI - ok
18:00:42.0781 0700 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
18:00:42.0781 0700 ACPIEC - ok
18:00:42.0796 0700 adpu160m - ok
18:00:42.0828 0700 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
18:00:42.0828 0700 aec - ok
18:00:42.0890 0700 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
18:00:42.0890 0700 AFD - ok
18:00:42.0890 0700 Aha154x - ok
18:00:42.0906 0700 aic78u2 - ok
18:00:42.0906 0700 aic78xx - ok
18:00:42.0953 0700 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
18:00:42.0953 0700 Alerter - ok
18:00:42.0968 0700 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
18:00:42.0968 0700 ALG - ok
18:00:42.0968 0700 AliIde - ok
18:00:42.0984 0700 amsint - ok
18:00:43.0062 0700 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:00:43.0062 0700 Apple Mobile Device - ok
18:00:43.0093 0700 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
18:00:43.0281 0700 AppMgmt - ok
18:00:43.0281 0700 asc - ok
18:00:43.0296 0700 asc3350p - ok
18:00:43.0296 0700 asc3550 - ok
18:00:43.0406 0700 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
18:00:43.0406 0700 aspnet_state - ok
18:00:43.0421 0700 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:00:43.0421 0700 aswFsBlk - ok
18:00:43.0453 0700 [ 09678587C5C70F91720631EF048B4744 ] aswFW C:\WINDOWS\system32\drivers\aswFW.sys
18:00:43.0453 0700 aswFW - ok
18:00:43.0484 0700 [ 31E0D16EB06D09A248AFF20C76F9091B ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
18:00:43.0484 0700 aswKbd - ok
18:00:43.0500 0700 [ 2B9B1DF809E965EF63402CBBA6DB50AE ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
18:00:43.0500 0700 aswMon2 - ok
18:00:43.0500 0700 [ 7B948E3657BEA62E437BC46CA6EF6012 ] aswNdis C:\WINDOWS\system32\DRIVERS\aswNdis.sys
18:00:43.0515 0700 aswNdis - ok
18:00:43.0515 0700 [ C6E5E1E0FB3827B2359F4D394ECAA070 ] aswNdis2 C:\WINDOWS\system32\drivers\aswNdis2.sys
18:00:43.0515 0700 aswNdis2 - ok
18:00:43.0531 0700 [ B7D5E4486BA658ED08624D8084ABB830 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
18:00:43.0531 0700 AswRdr - ok
18:00:43.0546 0700 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
18:00:43.0562 0700 aswSnx - ok
18:00:43.0593 0700 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
18:00:43.0593 0700 aswSP - ok
18:00:43.0609 0700 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
18:00:43.0609 0700 aswTdi - ok
18:00:43.0640 0700 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:00:43.0640 0700 AsyncMac - ok
18:00:43.0656 0700 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
18:00:43.0656 0700 atapi - ok
18:00:43.0671 0700 Atdisk - ok
18:00:43.0718 0700 [ 4DEAA162480367B232F3EE3A6D34084B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
18:00:43.0718 0700 Ati HotKey Poller - ok
18:00:43.0781 0700 [ F0D0B0CDEC0BE32D775F404CAC2604BF ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:00:43.0812 0700 ati2mtag - ok
18:00:43.0812 0700 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:00:43.0828 0700 Atmarpc - ok
18:00:43.0843 0700 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
18:00:43.0843 0700 AudioSrv - ok
18:00:43.0875 0700 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
18:00:43.0875 0700 audstub - ok
18:00:43.0953 0700 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:00:43.0953 0700 avast! Antivirus - ok
18:00:44.0000 0700 [ DD4C61CB3CDBC8B0A7D2107C6944DC71 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
18:00:44.0000 0700 avast! Firewall - ok
18:00:44.0062 0700 [ 4826FCF97C47B361A2E2F68CD487A19E ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys
18:00:44.0062 0700 b57w2k - ok
18:00:44.0109 0700 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
18:00:44.0109 0700 Beep - ok
18:00:44.0140 0700 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
18:00:44.0156 0700 BITS - ok
18:00:44.0218 0700 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
18:00:44.0218 0700 Bonjour Service - ok
18:00:44.0265 0700 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
18:00:44.0265 0700 Browser - ok
18:00:44.0359 0700 catchme - ok
18:00:44.0390 0700 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
18:00:44.0390 0700 cbidf2k - ok
18:00:44.0406 0700 cd20xrnt - ok
18:00:44.0437 0700 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
18:00:44.0437 0700 Cdaudio - ok
18:00:44.0468 0700 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
18:00:44.0484 0700 Cdfs - ok
18:00:44.0531 0700 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:00:44.0531 0700 Cdrom - ok
18:00:44.0531 0700 cerc6 - ok
18:00:44.0546 0700 Changer - ok
18:00:44.0562 0700 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
18:00:44.0562 0700 CiSvc - ok
18:00:44.0562 0700 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
18:00:44.0562 0700 ClipSrv - ok
18:00:44.0593 0700 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:00:44.0625 0700 clr_optimization_v2.0.50727_32 - ok
18:00:44.0703 0700 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:00:44.0703 0700 clr_optimization_v4.0.30319_32 - ok
18:00:44.0703 0700 CmdIde - ok
18:00:44.0718 0700 COMSysApp - ok
18:00:44.0734 0700 Cpqarray - ok
18:00:44.0765 0700 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
18:00:44.0765 0700 CryptSvc - ok
18:00:44.0765 0700 dac2w2k - ok
18:00:44.0781 0700 dac960nt - ok
18:00:44.0828 0700 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
18:00:44.0843 0700 DcomLaunch - ok
18:00:44.0906 0700 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
18:00:44.0906 0700 Dhcp - ok
18:00:44.0921 0700 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
18:00:44.0921 0700 Disk - ok
18:00:44.0937 0700 dmadmin - ok
18:00:44.0984 0700 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
18:00:45.0015 0700 dmboot - ok
18:00:45.0046 0700 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
18:00:45.0046 0700 dmio - ok
18:00:45.0078 0700 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
18:00:45.0078 0700 dmload - ok
18:00:45.0109 0700 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
18:00:45.0109 0700 dmserver - ok
18:00:45.0156 0700 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
18:00:45.0156 0700 DMusic - ok
18:00:45.0203 0700 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
18:00:45.0203 0700 Dnscache - ok
18:00:45.0234 0700 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
18:00:45.0250 0700 Dot3svc - ok
18:00:45.0250 0700 dpti2o - ok
18:00:45.0281 0700 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
18:00:45.0281 0700 drmkaud - ok
18:00:45.0328 0700 [ 049177996E5E33B5FAF40CAD2B82098C ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys
18:00:45.0328 0700 drvmcdb - ok
18:00:45.0328 0700 [ 2F4134D073F972575C174E3D621F0107 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys
18:00:45.0328 0700 drvnddm - ok
18:00:45.0375 0700 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
18:00:45.0375 0700 EapHost - ok
18:00:45.0421 0700 [ 6E883BF518296A40959131C2304AF714 ] EL90XBC C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
18:00:45.0421 0700 EL90XBC - ok
18:00:45.0421 0700 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
18:00:45.0437 0700 ERSvc - ok
18:00:45.0468 0700 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
18:00:45.0484 0700 Eventlog - ok
18:00:45.0515 0700 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
18:00:45.0515 0700 EventSystem - ok
18:00:45.0562 0700 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
18:00:45.0562 0700 Fastfat - ok
18:00:45.0593 0700 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
18:00:45.0640 0700 FastUserSwitchingCompatibility - ok
18:00:45.0671 0700 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
18:00:45.0671 0700 Fdc - ok
18:00:45.0703 0700 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
18:00:45.0703 0700 Fips - ok
18:00:45.0765 0700 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:00:45.0796 0700 FLEXnet Licensing Service - ok
18:00:45.0843 0700 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:00:45.0843 0700 Flpydisk - ok
18:00:45.0890 0700 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:00:45.0890 0700 FltMgr - ok
18:00:45.0953 0700 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:00:45.0953 0700 FontCache3.0.0.0 - ok
18:00:45.0953 0700 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:00:45.0953 0700 Fs_Rec - ok
18:00:45.0984 0700 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:00:45.0984 0700 Ftdisk - ok
18:00:46.0015 0700 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
18:00:46.0031 0700 GEARAspiWDM - ok
18:00:46.0046 0700 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:00:46.0046 0700 Gpc - ok
18:00:46.0140 0700 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:00:46.0140 0700 helpsvc - ok
18:00:46.0156 0700 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
18:00:46.0171 0700 HidServ - ok
18:00:46.0187 0700 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:00:46.0187 0700 HidUsb - ok
18:00:46.0218 0700 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
18:00:46.0218 0700 hkmsvc - ok
18:00:46.0234 0700 hpn - ok
18:00:46.0265 0700 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
18:00:46.0281 0700 HTTP - ok
18:00:46.0312 0700 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
18:00:46.0328 0700 HTTPFilter - ok
18:00:46.0328 0700 i2omgmt - ok
18:00:46.0343 0700 i2omp - ok
18:00:46.0375 0700 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:00:46.0375 0700 i8042prt - ok
18:00:46.0453 0700 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:00:46.0468 0700 idsvc - ok
18:00:46.0500 0700 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
18:00:46.0500 0700 Imapi - ok
18:00:46.0546 0700 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
18:00:46.0562 0700 ImapiService - ok
18:00:46.0562 0700 ini910u - ok
18:00:46.0593 0700 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
18:00:46.0593 0700 IntelIde - ok
18:00:46.0640 0700 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:00:46.0640 0700 intelppm - ok
18:00:46.0656 0700 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:00:46.0671 0700 Ip6Fw - ok
18:00:46.0703 0700 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:00:46.0703 0700 IpFilterDriver - ok
18:00:46.0734 0700 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:00:46.0734 0700 IpInIp - ok
18:00:46.0765 0700 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:00:46.0765 0700 IpNat - ok
18:00:46.0812 0700 [ 57EDB35EA2FECA88F8B17C0C095C9A56 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
18:00:46.0828 0700 iPod Service - ok
18:00:46.0875 0700 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:00:46.0875 0700 IPSec - ok
18:00:46.0906 0700 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
18:00:46.0906 0700 IRENUM - ok
18:00:46.0953 0700 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:00:46.0953 0700 isapnp - ok
18:00:47.0031 0700 [ C2C1660DDCC9BD67EB98D6D5F91C107F ] JavaQuickStarterService C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
18:00:47.0031 0700 JavaQuickStarterService - ok
18:00:47.0078 0700 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:00:47.0078 0700 Kbdclass - ok
18:00:47.0125 0700 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:00:47.0125 0700 kbdhid - ok
18:00:47.0140 0700 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
18:00:47.0156 0700 kmixer - ok
18:00:47.0187 0700 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
18:00:47.0187 0700 KSecDD - ok
18:00:47.0203 0700 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
18:00:47.0218 0700 LanmanServer - ok
18:00:47.0234 0700 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
18:00:47.0250 0700 lanmanworkstation - ok
18:00:47.0265 0700 lbrtfdc - ok
18:00:47.0312 0700 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
18:00:47.0312 0700 LmHosts - ok
18:00:47.0390 0700 [ 2375E7E01635FBCCDE2F796A9E078E07 ] LMIGuardianSvc C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
18:00:47.0406 0700 LMIGuardianSvc - ok
18:00:47.0437 0700 [ 4F69FAAABB7DB0D43E327C0B6AAB40FC ] LMIInfo C:\Program Files\LogMeIn\x86\RaInfo.sys
18:00:47.0437 0700 LMIInfo - ok
18:00:47.0453 0700 [ B9C127273EABA403311854A8DCB6D0AA ] LMIMaint C:\Program Files\LogMeIn\x86\RaMaint.exe
18:00:47.0468 0700 LMIMaint - ok
18:00:47.0500 0700 [ 4477689E2D8AE6B78BA34C9AF4CC1ED1 ] lmimirr C:\WINDOWS\system32\DRIVERS\lmimirr.sys
18:00:47.0500 0700 lmimirr - ok
18:00:47.0500 0700 LMIRfsClientNP - ok
18:00:47.0531 0700 [ 3FAA563DDF853320F90259D455A01D79 ] LMIRfsDriver C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
18:00:47.0531 0700 LMIRfsDriver - ok
18:00:47.0562 0700 [ 432618FA75B61059D2C57D6A7E55147A ] LogMeIn C:\Program Files\LogMeIn\x86\LogMeIn.exe
18:00:47.0578 0700 LogMeIn - ok
18:00:47.0593 0700 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
18:00:47.0593 0700 MBAMProtector - ok
18:00:47.0656 0700 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:00:47.0656 0700 MBAMService - ok
18:00:47.0718 0700 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
18:00:47.0718 0700 MDM - ok
18:00:47.0750 0700 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
18:00:47.0750 0700 Messenger - ok
18:00:47.0781 0700 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
18:00:47.0781 0700 mnmdd - ok
18:00:47.0812 0700 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
18:00:47.0828 0700 mnmsrvc - ok
18:00:47.0843 0700 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
18:00:47.0843 0700 Modem - ok
18:00:47.0859 0700 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:00:47.0859 0700 Mouclass - ok
18:00:47.0890 0700 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:00:47.0890 0700 mouhid - ok
18:00:47.0921 0700 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
18:00:47.0921 0700 MountMgr - ok
18:00:48.0015 0700 [ 15D5398EED42C2504BB3D4FC875C15D1 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:00:48.0031 0700 MozillaMaintenance - ok
18:00:48.0046 0700 mraid35x - ok
18:00:48.0062 0700 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:00:48.0078 0700 MRxDAV - ok
18:00:48.0125 0700 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:00:48.0125 0700 MRxSmb - ok
18:00:48.0171 0700 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
18:00:48.0171 0700 MSDTC - ok
18:00:48.0187 0700 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
18:00:48.0187 0700 Msfs - ok
18:00:48.0187 0700 MSIServer - ok
18:00:48.0218 0700 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:00:48.0218 0700 MSKSSRV - ok
18:00:48.0265 0700 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:00:48.0265 0700 MSPCLOCK - ok
18:00:48.0281 0700 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
18:00:48.0281 0700 MSPQM - ok
18:00:48.0343 0700 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:00:48.0343 0700 mssmbios - ok
18:00:48.0359 0700 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
18:00:48.0375 0700 Mup - ok
18:00:48.0406 0700 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
18:00:48.0421 0700 napagent - ok
18:00:48.0453 0700 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
18:00:48.0453 0700 NDIS - ok
18:00:48.0468 0700 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:00:48.0468 0700 NdisTapi - ok
18:00:48.0500 0700 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:00:48.0515 0700 Ndisuio - ok
18:00:48.0531 0700 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:00:48.0531 0700 NdisWan - ok
18:00:48.0593 0700 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
18:00:48.0593 0700 NDProxy - ok
18:00:48.0593 0700 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
18:00:48.0609 0700 NetBIOS - ok
18:00:48.0625 0700 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
18:00:48.0625 0700 NetBT - ok
18:00:48.0656 0700 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
18:00:48.0656 0700 NetDDE - ok
18:00:48.0671 0700 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
18:00:48.0671 0700 NetDDEdsdm - ok
18:00:48.0703 0700 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
18:00:48.0718 0700 Netlogon - ok
18:00:48.0734 0700 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
18:00:48.0750 0700 Netman - ok
18:00:48.0781 0700 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:00:48.0781 0700 NetTcpPortSharing - ok
18:00:48.0812 0700 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
18:00:48.0828 0700 Nla - ok
18:00:48.0828 0700 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
18:00:48.0843 0700 Npfs - ok
18:00:48.0875 0700 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
18:00:48.0890 0700 Ntfs - ok
18:00:48.0906 0700 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
18:00:48.0906 0700 NtLmSsp - ok
18:00:48.0937 0700 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
18:00:48.0968 0700 NtmsSvc - ok
18:00:49.0031 0700 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
18:00:49.0109 0700 NuidFltr - ok
18:00:49.0171 0700 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
18:00:49.0187 0700 Null - ok
18:00:49.0234 0700 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:00:49.0265 0700 NwlnkFlt - ok
18:00:49.0265 0700 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:00:49.0265 0700 NwlnkFwd - ok
18:00:49.0312 0700 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:00:49.0312 0700 ose - ok
18:00:49.0328 0700 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
18:00:49.0328 0700 Parport - ok
18:00:49.0343 0700 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
18:00:49.0343 0700 PartMgr - ok
18:00:49.0375 0700 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
18:00:49.0390 0700 ParVdm - ok
18:00:49.0390 0700 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
18:00:49.0390 0700 PCI - ok
18:00:49.0390 0700 PCIDump - ok
18:00:49.0406 0700 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
18:00:49.0406 0700 PCIIde - ok
18:00:49.0453 0700 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
18:00:49.0453 0700 Pcmcia - ok
18:00:49.0468 0700 PDCOMP - ok
18:00:49.0468 0700 PDFRAME - ok
18:00:49.0468 0700 PDRELI - ok
18:00:49.0484 0700 PDRFRAME - ok
18:00:49.0484 0700 perc2 - ok
18:00:49.0500 0700 perc2hib - ok
18:00:49.0531 0700 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
18:00:49.0546 0700 PlugPlay - ok
18:00:49.0562 0700 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
18:00:49.0578 0700 PolicyAgent - ok
18:00:49.0578 0700 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:00:49.0578 0700 PptpMiniport - ok
18:00:49.0593 0700 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
18:00:49.0593 0700 ProtectedStorage - ok
18:00:49.0625 0700 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
18:00:49.0640 0700 PSched - ok
18:00:49.0687 0700 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:00:49.0687 0700 Ptilink - ok
18:00:49.0703 0700 [ B5DFB86A6CAEAE9B2BF3DEDB43BE6393 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:00:49.0703 0700 PxHelp20 - ok
18:00:49.0718 0700 ql1080 - ok
18:00:49.0718 0700 Ql10wnt - ok
18:00:49.0718 0700 ql12160 - ok
18:00:49.0734 0700 ql1240 - ok
18:00:49.0734 0700 ql1280 - ok
18:00:49.0796 0700 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:00:49.0796 0700 RasAcd - ok
18:00:49.0828 0700 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
18:00:49.0843 0700 RasAuto - ok
18:00:49.0859 0700 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:00:49.0859 0700 Rasl2tp - ok
18:00:49.0890 0700 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
18:00:49.0906 0700 RasMan - ok
18:00:49.0906 0700 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:00:49.0921 0700 RasPppoe - ok
18:00:49.0921 0700 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
18:00:49.0921 0700 Raspti - ok
18:00:49.0937 0700 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:00:49.0937 0700 Rdbss - ok
18:00:49.0953 0700 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:00:49.0953 0700 RDPCDD - ok
18:00:49.0984 0700 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:00:49.0984 0700 rdpdr - ok
18:00:50.0031 0700 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
18:00:50.0046 0700 RDPWD - ok
18:00:50.0078 0700 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
18:00:50.0093 0700 RDSessMgr - ok
18:00:50.0140 0700 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
18:00:50.0140 0700 redbook - ok
18:00:50.0171 0700 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
18:00:50.0171 0700 RemoteAccess - ok
18:00:50.0203 0700 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
18:00:50.0218 0700 RemoteRegistry - ok
18:00:50.0234 0700 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
18:00:50.0234 0700 RpcLocator - ok
18:00:50.0265 0700 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
18:00:50.0281 0700 RpcSs - ok
18:00:50.0312 0700 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
18:00:50.0343 0700 RSVP - ok
18:00:50.0375 0700 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
18:00:50.0375 0700 SamSs - ok
18:00:50.0390 0700 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
18:00:50.0390 0700 SASDIFSV - ok
18:00:50.0406 0700 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
18:00:50.0421 0700 SASKUTIL - ok
18:00:50.0437 0700 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
18:00:50.0453 0700 SCardSvr - ok
18:00:50.0484 0700 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
18:00:50.0500 0700 Schedule - ok
18:00:50.0515 0700 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:00:50.0515 0700 Secdrv - ok
18:00:50.0546 0700 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
18:00:50.0546 0700 seclogon - ok
18:00:50.0593 0700 [ B9C7617C1E8AB6FDFF75D3C8DAFCB4C8 ] senfilt C:\WINDOWS\system32\drivers\senfilt.sys
18:00:50.0671 0700 senfilt - ok
18:00:50.0703 0700 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
18:00:50.0718 0700 SENS - ok
18:00:50.0750 0700 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
18:00:50.0750 0700 serenum - ok
18:00:50.0750 0700 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
18:00:50.0765 0700 Serial - ok
18:00:50.0812 0700 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
18:00:50.0812 0700 Sfloppy - ok
18:00:50.0828 0700 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
18:00:50.0843 0700 SharedAccess - ok
18:00:50.0875 0700 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
18:00:50.0875 0700 ShellHWDetection - ok
18:00:50.0890 0700 Simbad - ok
18:00:50.0968 0700 [ 86C4D93B7B7818D066C52FDB03C6C921 ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
18:00:50.0968 0700 smwdm - ok
18:00:50.0984 0700 Sparrow - ok
18:00:51.0015 0700 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
18:00:51.0015 0700 splitter - ok
18:00:51.0062 0700 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
18:00:51.0062 0700 Spooler - ok
18:00:51.0109 0700 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
18:00:51.0109 0700 sr - ok
18:00:51.0140 0700 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
18:00:51.0156 0700 srservice - ok
18:00:51.0171 0700 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
18:00:51.0187 0700 Srv - ok
18:00:51.0203 0700 [ 7C0C9BDCA2D351FF3B4F9B69F99AA995 ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys
18:00:51.0203 0700 sscdbhk5 - ok
18:00:51.0234 0700 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
18:00:51.0234 0700 SSDPSRV - ok
18:00:51.0250 0700 [ 31726706D54894D5059F7471111A87BB ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys
18:00:51.0265 0700 ssrtln - ok
18:00:51.0296 0700 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
18:00:51.0312 0700 stisvc - ok
18:00:51.0343 0700 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
18:00:51.0343 0700 swenum - ok
18:00:51.0484 0700 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:00:51.0484 0700 SwitchBoard - ok
18:00:51.0515 0700 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
18:00:51.0531 0700 swmidi - ok
18:00:51.0531 0700 SwPrv - ok
18:00:51.0531 0700 symc810 - ok
18:00:51.0546 0700 symc8xx - ok
18:00:51.0546 0700 sym_hi - ok
18:00:51.0562 0700 sym_u3 - ok
18:00:51.0578 0700 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
18:00:51.0593 0700 sysaudio - ok
18:00:51.0609 0700 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
18:00:51.0625 0700 SysmonLog - ok
18:00:51.0640 0700 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
18:00:51.0656 0700 TapiSrv - ok
18:00:51.0703 0700 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:00:51.0703 0700 Tcpip - ok
18:00:51.0734 0700 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
18:00:51.0750 0700 TDPIPE - ok
18:00:51.0765 0700 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
18:00:51.0765 0700 TDTCP - ok
18:00:51.0796 0700 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
18:00:51.0812 0700 TermDD - ok
18:00:51.0828 0700 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
18:00:51.0843 0700 TermService - ok
18:00:51.0921 0700 [ B0D311F33C5B4A5858E4E6C965A79267 ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys
18:00:51.0921 0700 tfsnboio - ok
18:00:51.0921 0700 [ 250F74FCE5D1ECCB29AD9ABEB55F35D8 ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys
18:00:51.0937 0700 tfsncofs - ok
18:00:51.0937 0700 [ E23291934C59E1741BA83582E7A209C0 ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys
18:00:51.0937 0700 tfsndrct - ok
18:00:51.0968 0700 [ 0D863D020633025F1E4AD3E0E325D503 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys
18:00:51.0968 0700 tfsndres - ok
18:00:51.0984 0700 [ E3E10696663E35062851A376299198BD ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys
18:00:51.0984 0700 tfsnifs - ok
18:00:51.0984 0700 [ 00CC366BDCBD8A9A1C95C1C59900DD9B ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys
18:00:51.0984 0700 tfsnopio - ok
18:00:52.0000 0700 [ 84A91D08F49831E8C24E4D25DDEFAE87 ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys
18:00:52.0000 0700 tfsnpool - ok
18:00:52.0000 0700 [ 55B761C6E2D4FCEDAC3B46B6C0724830 ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys
18:00:52.0015 0700 tfsnudf - ok
18:00:52.0015 0700 [ 64C6E8C217E30EE595120C66F6E783BA ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys
18:00:52.0015 0700 tfsnudfa - ok
18:00:52.0046 0700 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
18:00:52.0062 0700 Themes - ok
18:00:52.0109 0700 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
18:00:52.0109 0700 TlntSvr - ok
18:00:52.0125 0700 TosIde - ok
18:00:52.0140 0700 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
18:00:52.0156 0700 TrkWks - ok
18:00:52.0171 0700 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
18:00:52.0171 0700 Udfs - ok
18:00:52.0187 0700 ultra - ok
18:00:52.0234 0700 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
18:00:52.0234 0700 Update - ok
18:00:52.0265 0700 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
18:00:52.0281 0700 upnphost - ok
18:00:52.0296 0700 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
18:00:52.0312 0700 UPS - ok
18:00:52.0343 0700 [ EAFE1E00739AFE6C51487A050E772E17 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
18:00:52.0343 0700 USBAAPL - ok
18:00:52.0375 0700 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:00:52.0375 0700 usbccgp - ok
18:00:52.0406 0700 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:00:52.0406 0700 usbehci - ok
18:00:52.0421 0700 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:00:52.0421 0700 usbhub - ok
18:00:52.0453 0700 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:00:52.0453 0700 usbscan - ok
18:00:52.0484 0700 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:00:52.0484 0700 USBSTOR - ok
18:00:52.0515 0700 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:00:52.0515 0700 usbuhci - ok
18:00:52.0531 0700 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
18:00:52.0531 0700 VgaSave - ok
18:00:52.0531 0700 ViaIde - ok
18:00:52.0562 0700 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
18:00:52.0578 0700 VolSnap - ok
18:00:52.0625 0700 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
18:00:52.0656 0700 VSS - ok
18:00:52.0703 0700 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
18:00:52.0703 0700 W32Time - ok
18:00:52.0750 0700 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:00:52.0750 0700 Wanarp - ok
18:00:52.0796 0700 [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
18:00:52.0812 0700 Wdf01000 - ok
18:00:52.0812 0700 WDICA - ok
18:00:52.0843 0700 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
18:00:52.0843 0700 wdmaud - ok
18:00:52.0890 0700 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
18:00:52.0890 0700 WebClient - ok
18:00:52.0968 0700 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
18:00:52.0968 0700 winmgmt - ok
18:00:53.0046 0700 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll
18:00:53.0093 0700 WinRM - ok
18:00:53.0125 0700 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
18:00:53.0140 0700 WmdmPmSN - ok
18:00:53.0171 0700 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
18:00:53.0187 0700 Wmi - ok
18:00:53.0218 0700 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
18:00:53.0218 0700 WmiApSrv - ok
18:00:53.0296 0700 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
18:00:53.0312 0700 WMPNetworkSvc - ok
18:00:53.0343 0700 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:00:53.0406 0700 WPFFontCache_v0400 - ok
18:00:53.0437 0700 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:00:53.0437 0700 WS2IFSL - ok
18:00:53.0468 0700 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
18:00:53.0484 0700 wscsvc - ok
18:00:53.0500 0700 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
18:00:53.0515 0700 wuauserv - ok
18:00:53.0546 0700 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:00:53.0546 0700 WudfPf - ok
18:00:53.0562 0700 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:00:53.0562 0700 WudfRd - ok
18:00:53.0578 0700 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
18:00:53.0593 0700 WudfSvc - ok
18:00:53.0625 0700 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
18:00:53.0640 0700 WZCSVC - ok
18:00:53.0671 0700 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
18:00:53.0703 0700 xmlprov - ok
18:00:53.0703 0700 ================ Scan global ===============================
18:00:53.0734 0700 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
18:00:53.0781 0700 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:00:53.0812 0700 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:00:53.0828 0700 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
18:00:53.0843 0700 [Global] - ok
18:00:53.0843 0700 ================ Scan MBR ==================================
18:00:53.0859 0700 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
18:00:54.0000 0700 \Device\Harddisk0\DR0 - ok
18:00:54.0000 0700 ================ Scan VBR ==================================
18:00:54.0000 0700 [ 1E1E2C54EFC8162EB8A4BF34083B59B5 ] \Device\Harddisk0\DR0\Partition1
18:00:54.0000 0700 \Device\Harddisk0\DR0\Partition1 - ok
18:00:54.0000 0700 ============================================================
18:00:54.0000 0700 Scan finished
18:00:54.0000 0700 ============================================================
18:00:54.0015 3876 Detected object count: 0
18:00:54.0015 3876 Actual detected object count: 0
18:01:49.0093 0188 =====================================================

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
=======
18:01:49.0093 0188 Scan started
18:01:49.0093 0188 Mode: Manual;
18:01:49.0093 0188 ============================================================
18:01:49.0218 0188 ================ Scan system memory ========================
18:01:49.0218 0188 System memory - ok
18:01:49.0218 0188 ================ Scan services =============================
18:01:49.0328 0188 [ C0393EB99A6C72C6BEF9BFC4A72B33A6 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
18:01:49.0328 0188 !SASCORE - ok
18:01:49.0421 0188 [ 0352A73CD6B1782EA3ED7A03A8268F55 ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
18:01:49.0421 0188 Aavmker4 - ok
18:01:49.0421 0188 Abiosdsk - ok
18:01:49.0437 0188 abp480n5 - ok
18:01:49.0468 0188 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:01:49.0468 0188 ACPI - ok
18:01:49.0500 0188 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
18:01:49.0500 0188 ACPIEC - ok
18:01:49.0515 0188 adpu160m - ok
18:01:49.0546 0188 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
18:01:49.0546 0188 aec - ok
18:01:49.0593 0188 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
18:01:49.0593 0188 AFD - ok
18:01:49.0593 0188 Aha154x - ok
18:01:49.0609 0188 aic78u2 - ok
18:01:49.0609 0188 aic78xx - ok
18:01:49.0640 0188 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
18:01:49.0640 0188 Alerter - ok
18:01:49.0656 0188 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
18:01:49.0671 0188 ALG - ok
18:01:49.0671 0188 AliIde - ok
18:01:49.0671 0188 amsint - ok
18:01:49.0781 0188 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:01:49.0781 0188 Apple Mobile Device - ok
18:01:49.0812 0188 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
18:01:49.0812 0188 AppMgmt - ok
18:01:49.0828 0188 asc - ok
18:01:49.0828 0188 asc3350p - ok
18:01:49.0828 0188 asc3550 - ok
18:01:49.0937 0188 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
18:01:49.0937 0188 aspnet_state - ok
18:01:49.0968 0188 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:01:49.0968 0188 aswFsBlk - ok
18:01:49.0984 0188 [ 09678587C5C70F91720631EF048B4744 ] aswFW C:\WINDOWS\system32\drivers\aswFW.sys
18:01:49.0984 0188 aswFW - ok
18:01:50.0031 0188 [ 31E0D16EB06D09A248AFF20C76F9091B ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
18:01:50.0031 0188 aswKbd - ok
18:01:50.0031 0188 [ 2B9B1DF809E965EF63402CBBA6DB50AE ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
18:01:50.0031 0188 aswMon2 - ok
18:01:50.0062 0188 [ 7B948E3657BEA62E437BC46CA6EF6012 ] aswNdis C:\WINDOWS\system32\DRIVERS\aswNdis.sys
18:01:50.0062 0188 aswNdis - ok
18:01:50.0093 0188 [ C6E5E1E0FB3827B2359F4D394ECAA070 ] aswNdis2 C:\WINDOWS\system32\drivers\aswNdis2.sys
18:01:50.0093 0188 aswNdis2 - ok
18:01:50.0125 0188 [ B7D5E4486BA658ED08624D8084ABB830 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
18:01:50.0125 0188 AswRdr - ok
18:01:50.0156 0188 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
18:01:50.0156 0188 aswSnx - ok
18:01:50.0187 0188 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
18:01:50.0203 0188 aswSP - ok
18:01:50.0234 0188 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
18:01:50.0234 0188 aswTdi - ok
18:01:50.0265 0188 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:01:50.0265 0188 AsyncMac - ok
18:01:50.0296 0188 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
18:01:50.0296 0188 atapi - ok
18:01:50.0296 0188 Atdisk - ok
18:01:50.0359 0188 [ 4DEAA162480367B232F3EE3A6D34084B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
18:01:50.0359 0188 Ati HotKey Poller - ok
18:01:50.0421 0188 [ F0D0B0CDEC0BE32D775F404CAC2604BF ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:01:50.0421 0188 ati2mtag - ok
18:01:50.0421 0188 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:01:50.0437 0188 Atmarpc - ok
18:01:50.0437 0188 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
18:01:50.0437 0188 AudioSrv - ok
18:01:50.0484 0188 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
18:01:50.0484 0188 audstub - ok
18:01:50.0562 0188 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:01:50.0562 0188 avast! Antivirus - ok
18:01:50.0609 0188 [ DD4C61CB3CDBC8B0A7D2107C6944DC71 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
18:01:50.0609 0188 avast! Firewall - ok
18:01:50.0625 0188 [ 4826FCF97C47B361A2E2F68CD487A19E ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys
18:01:50.0625 0188 b57w2k - ok
18:01:50.0671 0188 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
18:01:50.0671 0188 Beep - ok
18:01:50.0718 0188 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
18:01:50.0734 0188 BITS - ok
18:01:50.0781 0188 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
18:01:50.0781 0188 Bonjour Service - ok
18:01:50.0812 0188 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
18:01:50.0812 0188 Browser - ok
18:01:50.0921 0188 catchme - ok
18:01:50.0953 0188 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
18:01:50.0953 0188 cbidf2k - ok
18:01:50.0968 0188 cd20xrnt - ok
18:01:50.0984 0188 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
18:01:50.0984 0188 Cdaudio - ok
18:01:51.0031 0188 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
18:01:51.0031 0188 Cdfs - ok
18:01:51.0078 0188 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:01:51.0078 0188 Cdrom - ok
18:01:51.0093 0188 cerc6 - ok
18:01:51.0093 0188 Changer - ok
18:01:51.0109 0188 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
18:01:51.0109 0188 CiSvc - ok
18:01:51.0125 0188 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
18:01:51.0125 0188 ClipSrv - ok
18:01:51.0156 0188 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:01:51.0156 0188 clr_optimization_v2.0.50727_32 - ok
18:01:51.0218 0188 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:01:51.0218 0188 clr_optimization_v4.0.30319_32 - ok
18:01:51.0234 0188 CmdIde - ok
18:01:51.0234 0188 COMSysApp - ok
18:01:51.0250 0188 Cpqarray - ok
18:01:51.0281 0188 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
18:01:51.0281 0188 CryptSvc - ok
18:01:51.0296 0188 dac2w2k - ok
18:01:51.0296 0188 dac960nt - ok
18:01:51.0359 0188 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
18:01:51.0359 0188 DcomLaunch - ok
18:01:51.0406 0188 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
18:01:51.0406 0188 Dhcp - ok
18:01:51.0421 0188 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
18:01:51.0421 0188 Disk - ok
18:01:51.0421 0188 dmadmin - ok
18:01:51.0484 0188 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
18:01:51.0484 0188 dmboot - ok
18:01:51.0500 0188 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
18:01:51.0500 0188 dmio - ok
18:01:51.0515 0188 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
18:01:51.0515 0188 dmload - ok
18:01:51.0515 0188 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
18:01:51.0531 0188 dmserver - ok
18:01:51.0578 0188 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
18:01:51.0578 0188 DMusic - ok
18:01:51.0609 0188 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
18:01:51.0609 0188 Dnscache - ok
18:01:51.0640 0188 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
18:01:51.0640 0188 Dot3svc - ok
18:01:51.0640 0188 dpti2o - ok
18:01:51.0687 0188 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
18:01:51.0687 0188 drmkaud - ok
18:01:51.0718 0188 [ 049177996E5E33B5FAF40CAD2B82098C ] drvmcdb C:\WINDOWS\system32\drivers\drvmcdb.sys
18:01:51.0734 0188 drvmcdb - ok
18:01:51.0734 0188 [ 2F4134D073F972575C174E3D621F0107 ] drvnddm C:\WINDOWS\system32\drivers\drvnddm.sys
18:01:51.0734 0188 drvnddm - ok
18:01:51.0765 0188 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
18:01:51.0765 0188 EapHost - ok
18:01:51.0796 0188 [ 6E883BF518296A40959131C2304AF714 ] EL90XBC C:\WINDOWS\system32\DRIVERS\el90xbc5.sys
18:01:51.0796 0188 EL90XBC - ok
18:01:51.0812 0188 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
18:01:51.0812 0188 ERSvc - ok
18:01:51.0843 0188 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
18:01:51.0859 0188 Eventlog - ok
18:01:51.0906 0188 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
18:01:51.0906 0188 EventSystem - ok
18:01:51.0937 0188 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
18:01:51.0937 0188 Fastfat - ok
18:01:51.0984 0188 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
18:01:51.0984 0188 FastUserSwitchingCompatibility - ok
18:01:52.0000 0188 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
18:01:52.0000 0188 Fdc - ok
18:01:52.0015 0188 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
18:01:52.0015 0188 Fips - ok
18:01:52.0062 0188 [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:01:52.0062 0188 FLEXnet Licensing Service - ok
18:01:52.0093 0188 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:01:52.0093 0188 Flpydisk - ok
18:01:52.0140 0188 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:01:52.0140 0188 FltMgr - ok
18:01:52.0203 0188 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:01:52.0203 0188 FontCache3.0.0.0 - ok
18:01:52.0203 0188 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:01:52.0218 0188 Fs_Rec - ok
18:01:52.0234 0188 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:01:52.0234 0188 Ftdisk - ok
18:01:52.0265 0188 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
18:01:52.0281 0188 GEARAspiWDM - ok
18:01:52.0281 0188 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:01:52.0281 0188 Gpc - ok
18:01:52.0359 0188 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:01:52.0359 0188 helpsvc - ok
18:01:52.0390 0188 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
18:01:52.0390 0188 HidServ - ok
18:01:52.0421 0188 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:01:52.0421 0188 HidUsb - ok
18:01:52.0453 0188 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
18:01:52.0453 0188 hkmsvc - ok
18:01:52.0453 0188 hpn - ok
18:01:52.0500 0188 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
18:01:52.0500 0188 HTTP - ok
18:01:52.0531 0188 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
18:01:52.0546 0188 HTTPFilter - ok
18:01:52.0546 0188 i2omgmt - ok
18:01:52.0562 0188 i2omp - ok
18:01:52.0593 0188 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:01:52.0593 0188 i8042prt - ok
18:01:52.0656 0188 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:01:52.0656 0188 idsvc - ok
18:01:52.0687 0188 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
18:01:52.0687 0188 Imapi - ok
18:01:52.0734 0188 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
18:01:52.0734 0188 ImapiService - ok
18:01:52.0750 0188 ini910u - ok
18:01:52.0765 0188 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
18:01:52.0765 0188 IntelIde - ok
18:01:52.0812 0188 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:01:52.0812 0188 intelppm - ok
18:01:52.0828 0188 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:01:52.0828 0188 Ip6Fw - ok
18:01:52.0875 0188 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:01:52.0875 0188 IpFilterDriver - ok
18:01:52.0890 0188 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:01:52.0890 0188 IpInIp - ok
18:01:52.0921 0188 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:01:52.0921 0188 IpNat - ok
18:01:52.0984 0188 [ 57EDB35EA2FECA88F8B17C0C095C9A56 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
18:01:52.0984 0188 iPod Service - ok
18:01:53.0031 0188 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:01:53.0031 0188 IPSec - ok
18:01:53.0062 0188 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
18:01:53.0062 0188 IRENUM - ok
18:01:53.0093 0188 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:01:53.0093 0188 isapnp - ok
18:01:53.0156 0188 [ C2C1660DDCC9BD67EB98D6D5F91C107F ] JavaQuickStarterService C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
18:01:53.0171 0188 JavaQuickStarterService - ok
18:01:53.0187 0188 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:01:53.0187 0188 Kbdclass - ok
18:01:53.0218 0188 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:01:53.0218 0188 kbdhid - ok
18:01:53.0250 0188 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
18:01:53.0250 0188 kmixer - ok
18:01:53.0296 0188 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
18:01:53.0296 0188 KSecDD - ok
18:01:53.0328 0188 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
18:01:53.0343 0188 LanmanServer - ok
18:01:53.0375 0188 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
18:01:53.0390 0188 lanmanworkstation - ok
18:01:53.0390 0188 lbrtfdc - ok
18:01:53.0437 0188 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
18:01:53.0453 0188 LmHosts - ok
18:01:53.0531 0188 [ 2375E7E01635FBCCDE2F796A9E078E07 ] LMIGuardianSvc C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
18:01:53.0531 0188 LMIGuardianSvc - ok
18:01:53.0546 0188 [ 4F69FAAABB7DB0D43E327C0B6AAB40FC ] LMIInfo C:\Program Files\LogMeIn\x86\RaInfo.sys
18:01:53.0546 0188 LMIInfo - ok
18:01:53.0562 0188 [ B9C127273EABA403311854A8DCB6D0AA ] LMIMaint C:\Program Files\LogMeIn\x86\RaMaint.exe
18:01:53.0562 0188 LMIMaint - ok
18:01:53.0593 0188 [ 4477689E2D8AE6B78BA34C9AF4CC1ED1 ] lmimirr C:\WINDOWS\system32\DRIVERS\lmimirr.sys
18:01:53.0593 0188 lmimirr - ok
18:01:53.0593 0188 LMIRfsClientNP - ok
18:01:53.0609 0188 [ 3FAA563DDF853320F90259D455A01D79 ] LMIRfsDriver C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
18:01:53.0609 0188 LMIRfsDriver - ok
18:01:53.0640 0188 [ 432618FA75B61059D2C57D6A7E55147A ] LogMeIn C:\Program Files\LogMeIn\x86\LogMeIn.exe
18:01:53.0640 0188 LogMeIn - ok
18:01:53.0671 0188 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
18:01:53.0671 0188 MBAMProtector - ok
18:01:53.0718 0188 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:01:53.0718 0188 MBAMService - ok
18:01:53.0765 0188 [ 11F714F85530A2BD134074DC30E99FCA ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
18:01:53.0765 0188 MDM - ok
18:01:53.0796 0188 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
18:01:53.0796 0188 Messenger - ok
18:01:53.0828 0188 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
18:01:53.0828 0188 mnmdd - ok
18:01:53.0859 0188 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
18:01:53.0875 0188 mnmsrvc - ok
18:01:53.0875 0188 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
18:01:53.0890 0188 Modem - ok
18:01:53.0906 0188 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:01:53.0906 0188 Mouclass - ok
18:01:53.0937 0188 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:01:53.0937 0188 mouhid - ok
18:01:53.0968 0188 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
18:01:53.0968 0188 MountMgr - ok
18:01:54.0046 0188 [ 15D5398EED42C2504BB3D4FC875C15D1 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:01:54.0046 0188 MozillaMaintenance - ok
18:01:54.0046 0188 mraid35x - ok
18:01:54.0078 0188 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:01:54.0078 0188 MRxDAV - ok
18:01:54.0140 0188 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:01:54.0140 0188 MRxSmb - ok
18:01:54.0171 0188 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
18:01:54.0187 0188 MSDTC - ok
18:01:54.0187 0188 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
18:01:54.0203 0188 Msfs - ok
18:01:54.0203 0188 MSIServer - ok
18:01:54.0234 0188 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:01:54.0234 0188 MSKSSRV - ok
18:01:54.0265 0188 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:01:54.0265 0188 MSPCLOCK - ok
18:01:54.0265 0188 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
18:01:54.0265 0188 MSPQM - ok
18:01:54.0296 0188 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:01:54.0296 0188 mssmbios - ok
18:01:54.0343 0188 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
18:01:54.0343 0188 Mup - ok
18:01:54.0359 0188 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
18:01:54.0375 0188 napagent - ok
18:01:54.0390 0188 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
18:01:54.0406 0188 NDIS - ok
18:01:54.0421 0188 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:01:54.0421 0188 NdisTapi - ok
18:01:54.0453 0188 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:01:54.0453 0188 Ndisuio - ok
18:01:54.0484 0188 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:01:54.0484 0188 NdisWan - ok
18:01:54.0531 0188 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
18:01:54.0531 0188 NDProxy - ok
18:01:54.0531 0188 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
18:01:54.0546 0188 NetBIOS - ok
18:01:54.0562 0188 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
18:01:54.0562 0188 NetBT - ok
18:01:54.0593 0188 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
18:01:54.0593 0188 NetDDE - ok
18:01:54.0593 0188 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
18:01:54.0609 0188 NetDDEdsdm - ok
18:01:54.0640 0188 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
18:01:54.0640 0188 Netlogon - ok
18:01:54.0656 0188 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
18:01:54.0671 0188 Netman - ok
18:01:54.0703 0188 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:01:54.0703 0188 NetTcpPortSharing - ok
18:01:54.0734 0188 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
18:01:54.0750 0188 Nla - ok
18:01:54.0750 0188 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
18:01:54.0750 0188 Npfs - ok
18:01:54.0781 0188 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
18:01:54.0781 0188 Ntfs - ok
18:01:54.0796 0188 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
18:01:54.0796 0188 NtLmSsp - ok
18:01:54.0828 0188 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
18:01:54.0843 0188 NtmsSvc - ok
18:01:54.0859 0188 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
18:01:54.0859 0188 NuidFltr - ok
18:01:54.0890 0188 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
18:01:54.0890 0188 Null - ok
18:01:54.0921 0188 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:01:54.0921 0188 NwlnkFlt - ok
18:01:54.0937 0188 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:01:54.0937 0188 NwlnkFwd - ok
18:01:54.0968 0188 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:01:54.0968 0188 ose - ok
18:01:54.0984 0188 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
18:01:54.0984 0188 Parport - ok
18:01:55.0000 0188 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
18:01:55.0000 0188 PartMgr - ok
18:01:55.0046 0188 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
18:01:55.0046 0188 ParVdm - ok
18:01:55.0046 0188 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
18:01:55.0046 0188 PCI - ok
18:01:55.0062 0188 PCIDump - ok
18:01:55.0062 0188 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
18:01:55.0078 0188 PCIIde - ok
18:01:55.0109 0188 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
18:01:55.0109 0188 Pcmcia - ok
18:01:55.0125 0188 PDCOMP - ok
18:01:55.0125 0188 PDFRAME - ok
18:01:55.0140 0188 PDRELI - ok
18:01:55.0140 0188 PDRFRAME - ok
18:01:55.0140 0188 perc2 - ok
18:01:55.0156 0188 perc2hib - ok
18:01:55.0203 0188 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
18:01:55.0203 0188 PlugPlay - ok
18:01:55.0218 0188 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
18:01:55.0218 0188 PolicyAgent - ok
18:01:55.0234 0188 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:01:55.0234 0188 PptpMiniport - ok
18:01:55.0234 0188 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
18:01:55.0250 0188 ProtectedStorage - ok
18:01:55.0250 0188 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
18:01:55.0250 0188 PSched - ok
18:01:55.0265 0188 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:01:55.0265 0188 Ptilink - ok
18:01:55.0312 0188 [ B5DFB86A6CAEAE9B2BF3DEDB43BE6393 ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:01:55.0312 0188 PxHelp20 - ok
18:01:55.0312 0188 ql1080 - ok
18:01:55.0328 0188 Ql10wnt - ok
18:01:55.0328 0188 ql12160 - ok
18:01:55.0328 0188 ql1240 - ok
18:01:55.0343 0188 ql1280 - ok
18:01:55.0375 0188 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:01:55.0375 0188 RasAcd - ok
18:01:55.0406 0188 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
18:01:55.0406 0188 RasAuto - ok
18:01:55.0437 0188 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:01:55.0437 0188 Rasl2tp - ok
18:01:55.0453 0188 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
18:01:55.0468 0188 RasMan - ok
18:01:55.0468 0188 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:01:55.0468 0188 RasPppoe - ok
18:01:55.0484 0188 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
18:01:55.0484 0188 Raspti - ok
18:01:55.0515 0188 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:01:55.0515 0188 Rdbss - ok
18:01:55.0531 0188 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:01:55.0531 0188 RDPCDD - ok
18:01:55.0578 0188 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:01:55.0578 0188 rdpdr - ok
18:01:55.0625 0188 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
18:01:55.0640 0188 RDPWD - ok
18:01:55.0671 0188 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
18:01:55.0671 0188 RDSessMgr - ok
18:01:55.0703 0188 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
18:01:55.0703 0188 redbook - ok
18:01:55.0734 0188 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
18:01:55.0734 0188 RemoteAccess - ok
18:01:55.0765 0188 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
18:01:55.0781 0188 RemoteRegistry - ok
18:01:55.0796 0188 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
18:01:55.0796 0188 RpcLocator - ok
18:01:55.0828 0188 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
18:01:55.0843 0188 RpcSs - ok
18:01:55.0890 0188 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
18:01:55.0890 0188 RSVP - ok
18:01:55.0906 0188 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
18:01:55.0921 0188 SamSs - ok
18:01:55.0937 0188 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
18:01:55.0937 0188 SASDIFSV - ok
18:01:55.0953 0188 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
18:01:55.0953 0188 SASKUTIL - ok
18:01:55.0984 0188 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
18:01:55.0984 0188 SCardSvr - ok
18:01:56.0015 0188 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
18:01:56.0031 0188 Schedule - ok
18:01:56.0062 0188 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:01:56.0062 0188 Secdrv - ok
18:01:56.0078 0188 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
18:01:56.0093 0188 seclogon - ok
18:01:56.0140 0188 [ B9C7617C1E8AB6FDFF75D3C8DAFCB4C8 ] senfilt C:\WINDOWS\system32\drivers\senfilt.sys
18:01:56.0140 0188 senfilt - ok
18:01:56.0171 0188 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
18:01:56.0171 0188 SENS - ok
18:01:56.0187 0188 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
18:01:56.0187 0188 serenum - ok
18:01:56.0187 0188 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
18:01:56.0203 0188 Serial - ok
18:01:56.0234 0188 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
18:01:56.0234 0188 Sfloppy - ok
18:01:56.0265 0188 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
18:01:56.0265 0188 SharedAccess - ok
18:01:56.0281 0188 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
18:01:56.0296 0188 ShellHWDetection - ok
18:01:56.0296 0188 Simbad - ok
18:01:56.0359 0188 [ 86C4D93B7B7818D066C52FDB03C6C921 ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
18:01:56.0375 0188 smwdm - ok
18:01:56.0375 0188 Sparrow - ok
18:01:56.0390 0188 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
18:01:56.0390 0188 splitter - ok
18:01:56.0421 0188 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
18:01:56.0437 0188 Spooler - ok
18:01:56.0468 0188 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
18:01:56.0468 0188 sr - ok
18:01:56.0500 0188 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
18:01:56.0500 0188 srservice - ok
18:01:56.0515 0188 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
18:01:56.0531 0188 Srv - ok
18:01:56.0546 0188 [ 7C0C9BDCA2D351FF3B4F9B69F99AA995 ] sscdbhk5 C:\WINDOWS\system32\drivers\sscdbhk5.sys
18:01:56.0562 0188 sscdbhk5 - ok
18:01:56.0578 0188 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
18:01:56.0578 0188 SSDPSRV - ok
18:01:56.0593 0188 [ 31726706D54894D5059F7471111A87BB ] ssrtln C:\WINDOWS\system32\drivers\ssrtln.sys
18:01:56.0593 0188 ssrtln - ok
18:01:56.0640 0188 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
18:01:56.0640 0188 stisvc - ok
18:01:56.0671 0188 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
18:01:56.0671 0188 swenum - ok
18:01:56.0796 0188 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:01:56.0796 0188 SwitchBoard - ok
18:01:56.0812 0188 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
18:01:56.0812 0188 swmidi - ok
18:01:56.0812 0188 SwPrv - ok
18:01:56.0828 0188 symc810 - ok
18:01:56.0828 0188 symc8xx - ok
18:01:56.0843 0188 sym_hi - ok
18:01:56.0843 0188 sym_u3 - ok
18:01:56.0859 0188 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
18:01:56.0859 0188 sysaudio - ok
18:01:56.0890 0188 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
18:01:56.0906 0188 SysmonLog - ok
18:01:56.0937 0188 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
18:01:56.0937 0188 TapiSrv - ok
18:01:56.0984 0188 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:01:56.0984 0188 Tcpip - ok
18:01:57.0015 0188 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
18:01:57.0015 0188 TDPIPE - ok
18:01:57.0031 0188 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
18:01:57.0031 0188 TDTCP - ok
18:01:57.0078 0188 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
18:01:57.0078 0188 TermDD - ok
18:01:57.0093 0188 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
18:01:57.0093 0188 TermService - ok
18:01:57.0187 0188 [ B0D311F33C5B4A5858E4E6C965A79267 ] tfsnboio C:\WINDOWS\system32\dla\tfsnboio.sys
18:01:57.0187 0188 tfsnboio - ok
18:01:57.0187 0188 [ 250F74FCE5D1ECCB29AD9ABEB55F35D8 ] tfsncofs C:\WINDOWS\system32\dla\tfsncofs.sys
18:01:57.0187 0188 tfsncofs - ok
18:01:57.0203 0188 [ E23291934C59E1741BA83582E7A209C0 ] tfsndrct C:\WINDOWS\system32\dla\tfsndrct.sys
18:01:57.0203 0188 tfsndrct - ok
18:01:57.0218 0188 [ 0D863D020633025F1E4AD3E0E325D503 ] tfsndres C:\WINDOWS\system32\dla\tfsndres.sys
18:01:57.0218 0188 tfsndres - ok
18:01:57.0218 0188 [ E3E10696663E35062851A376299198BD ] tfsnifs C:\WINDOWS\system32\dla\tfsnifs.sys
18:01:57.0218 0188 tfsnifs - ok
18:01:57.0234 0188 [ 00CC366BDCBD8A9A1C95C1C59900DD9B ] tfsnopio C:\WINDOWS\system32\dla\tfsnopio.sys
18:01:57.0234 0188 tfsnopio - ok
18:01:57.0234 0188 [ 84A91D08F49831E8C24E4D25DDEFAE87 ] tfsnpool C:\WINDOWS\system32\dla\tfsnpool.sys
18:01:57.0234 0188 tfsnpool - ok
18:01:57.0250 0188 [ 55B761C6E2D4FCEDAC3B46B6C0724830 ] tfsnudf C:\WINDOWS\system32\dla\tfsnudf.sys
18:01:57.0250 0188 tfsnudf - ok
18:01:57.0250 0188 [ 64C6E8C217E30EE595120C66F6E783BA ] tfsnudfa C:\WINDOWS\system32\dla\tfsnudfa.sys
18:01:57.0265 0188 tfsnudfa - ok
18:01:57.0281 0188 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
18:01:57.0281 0188 Themes - ok
18:01:57.0328 0188 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
18:01:57.0328 0188 TlntSvr - ok
18:01:57.0343 0188 TosIde - ok
18:01:57.0359 0188 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
18:01:57.0359 0188 TrkWks - ok
18:01:57.0390 0188 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
18:01:57.0390 0188 Udfs - ok
18:01:57.0390 0188 ultra - ok
18:01:57.0437 0188 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
18:01:57.0437 0188 Update - ok
18:01:57.0468 0188 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
18:01:57.0468 0188 upnphost - ok
18:01:57.0484 0188 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
18:01:57.0500 0188 UPS - ok
18:01:57.0531 0188 [ EAFE1E00739AFE6C51487A050E772E17 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
18:01:57.0531 0188 USBAAPL - ok
18:01:57.0562 0188 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:01:57.0562 0188 usbccgp - ok
18:01:57.0578 0188 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:01:57.0578 0188 usbehci - ok
18:01:57.0609 0188 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:01:57.0609 0188 usbhub - ok
18:01:57.0625 0188 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:01:57.0625 0188 usbscan - ok
18:01:57.0656 0188 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:01:57.0656 0188 USBSTOR - ok
18:01:57.0703 0188 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:01:57.0703 0188 usbuhci - ok
18:01:57.0703 0188 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
18:01:57.0703 0188 VgaSave - ok
18:01:57.0718 0188 ViaIde - ok
18:01:57.0734 0188 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
18:01:57.0734 0188 VolSnap - ok
18:01:57.0765 0188 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
18:01:57.0781 0188 VSS - ok
18:01:57.0812 0188 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
18:01:57.0828 0188 W32Time - ok
18:01:57.0843 0188 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:01:57.0843 0188 Wanarp - ok
18:01:57.0890 0188 [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
18:01:57.0906 0188 Wdf01000 - ok
18:01:57.0906 0188 WDICA - ok
18:01:57.0937 0188 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
18:01:57.0937 0188 wdmaud - ok
18:01:57.0968 0188 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
18:01:57.0968 0188 WebClient - ok
18:01:58.0046 0188 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
18:01:58.0046 0188 winmgmt - ok
18:01:58.0109 0188 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll
18:01:58.0125 0188 WinRM - ok
18:01:58.0171 0188 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
18:01:58.0171 0188 WmdmPmSN - ok
18:01:58.0218 0188 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
18:01:58.0218 0188 Wmi - ok
18:01:58.0250 0188 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
18:01:58.0250 0188 WmiApSrv - ok
18:01:58.0328 0188 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
18:01:58.0328 0188 WMPNetworkSvc - ok
18:01:58.0390 0188 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:01:58.0390 0188 WPFFontCache_v0400 - ok
18:01:58.0421 0188 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:01:58.0437 0188 WS2IFSL - ok
18:01:58.0453 0188 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
18:01:58.0468 0188 wscsvc - ok
18:01:58.0484 0188 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
18:01:58.0500 0188 wuauserv - ok
18:01:58.0531 0188 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:01:58.0531 0188 WudfPf - ok
18:01:58.0546 0188 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:01:58.0546 0188 WudfRd - ok
18:01:58.0562 0188 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
18:01:58.0578 0188 WudfSvc - ok
18:01:58.0625 0188 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
18:01:58.0640 0188 WZCSVC - ok
18:01:58.0671 0188 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
18:01:58.0671 0188 xmlprov - ok
18:01:58.0687 0188 ================ Scan global ===============================
18:01:58.0750 0188 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
18:01:58.0781 0188 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:01:58.0812 0188 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
18:01:58.0828 0188 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
18:01:58.0843 0188 [Global] - ok
18:01:58.0843 0188 ================ Scan MBR ==================================
18:01:58.0875 0188 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
18:01:59.0000 0188 \Device\Harddisk0\DR0 - ok
18:01:59.0000 0188 ================ Scan VBR ==================================
18:01:59.0000 0188 [ 1E1E2C54EFC8162EB8A4BF34083B59B5 ] \Device\Harddisk0\DR0\Partition1
18:01:59.0015 0188 \Device\Harddisk0\DR0\Partition1 - ok
18:01:59.0015 0188 ============================================================
18:01:59.0015 0188 Scan finished
18:01:59.0015 0188 ============================================================
18:01:59.0015 3776 Detected object count: 0
18:01:59.0015 3776 Actual detected object count: 0

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
RogueKiller V8.0.0 [08/26/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Kimberley Davis [Admin rights]
Mode : Remove -- Date : 08/29/2012 18:10:01

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 2 ¤¤¤
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST3300822AS +++++
--- User ---
[MBR] 927df9f0f2e09d9a21e596fcca539c63
[BSP] 03bddcf5c06e2e78b266736121096d23 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 286157 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt


descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
Save these instructions so you can have access to them while in Safe Mode.

Please click here to download AVP Tool by Kaspersky.

  • Save it to your desktop.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
  • Double click the setup file to run it.
  • Click Next to continue.
  • Accept the License agreement and click on next.
  • It will, by default, install it to your desktop folder. Click Next.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • Hidden Startup Objects
  • System Memory
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)

Leave the rest of the settings as they appear as default.
•Then click on Scan at the to right hand Corner.
•It will automatically Neutralize any objects found.
•If some objects are left un-neutralized then click the button that says Neutralize all
•If it says it cannot be neutralized then choose the delete option when prompted.
•After that is done click on the reports button at the bottom and save it to file name it Kas.
•Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

Note: This tool will self uninstall when you close it so please save the log before closing it.

descriptionGoogle Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall EmptyRe: Google Chrome Icon Directs to "http://yahoo.genieo.com/?v=w3i4" Cannot Uninstall

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum