Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 01
- Ran by SYSTEM on 30-07-2013 12:06:46
- Running from H:\
- Windows 7 Home Premium (X64) OS Language: English(US)
- Internet Explorer Version 8
- Boot Mode: Recovery
- The current controlset is ControlSet001
- [b]ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.[/b]
- ==================== Registry (Whitelisted) ==================
- HKLM\...\Run: [ASUS WebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-15] ()
- HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-05-02] (Alcor Micro Corp.)
- HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2085160 2010-03-04] (Synaptics Incorporated)
- HKLM\...\Run: [RunDLLEntry] - C:\Windows\system32\RunDLL32.exe [45568 2009-07-13] (Microsoft Corporation)
- HKLM\...\Run: [Setwallpaper] - c:\programdata\SetWallpaper.cmd [x]
- HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1680976 2010-10-28] (Logitech, Inc.)
- HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [296960 2009-07-13] (Microsoft Corporation)
- Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
- HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
- HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
- HKLM-x32\...\Run: [Boingo Wi-Fi] - C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-08-26] ()
- HKLM-x32\...\Run: [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [6806144 2010-06-24] (ASUS)
- HKLM-x32\...\Run: [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS)
- HKLM-x32\...\Run: [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
- HKLM-x32\...\Run: [VolPanel] - C:\Program Files (x86)\Creative\SB Audigy\Volume Panel\VolPanlu.exe [237693 2008-12-29] (Creative Technology Ltd)
- HKLM-x32\...\Run: [UpdReg] - C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
- HKLM-x32\...\Run: [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-04-26] ()
- HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [919008 2012-07-11] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [38872 2012-07-31] (Adobe Systems Incorporated)
- HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-12] (Microsoft Corporation)
- HKLM-x32\...\Run: [amd_dc_opt] - C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-21] (AMD)
- HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-26] (Apple Inc.)
- HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421736 2011-11-12] (Apple Inc.)
- HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-23] (Apple Inc.)
- HKLM-x32\...\Run: [MobileBroadband] - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [279552 2011-07-13] (Vodafone)
- HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] - C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
- HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-28] (Advanced Micro Devices, Inc.)
- HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-07-29] (Avira Operations GmbH & Co. KG)
- HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
- HKU\Lau Chee Keong\...\Run: [Steam] - "D:\Program Files\Steam\steam.exe" -silent [x]
- HKU\Lau Chee Keong\...\Run: [igndlm.exe] - C:\Program Files (x86)\Download Manager\DLM.exe [1103216 2009-10-27] (IGN Entertainment)
- HKU\Lau Chee Keong\...\Run: [ISUSPM] - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe [222128 2007-03-28] (Macrovision Corporation)
- HKU\Lau Chee Keong\...\Run: [Spotify Web Helper] - C:\Users\Lau Chee Keong\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-06-18] (Spotify Ltd)
- HKU\Lau Chee Keong\...\Run: [Facebook Update] - C:\Users\Lau Chee Keong\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-09-03] (Facebook Inc.)
- HKU\Lau Chee Keong\...\Run: [Akamai NetSession Interface] - "C:\Users\Lau Chee Keong\AppData\Local\Akamai\netsession_win.exe" [x]
- ==================== Services (Whitelisted) =================
- S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-07-29] (Avira Operations GmbH & Co. KG)
- S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-07-29] (Avira Operations GmbH & Co. KG)
- S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [589368 2013-07-29] (Avira Operations GmbH & Co. KG)
- S2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
- S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2011-02-15] (Autodesk)
- S2 HotspotShieldService; C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [271408 2011-01-07] ()
- S3 HssTrayService; C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE [57640 2011-01-07] ()
- S2 HssWd; C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe [326704 2010-10-15] ()
- S2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
- S2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
- S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2012-12-18] ()
- S3 DAUpdaterSvc; d:\program files\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]
- S2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [x]
- S2 VMAuthdService; G:\VMWare\vmware-authd.exe [x]
- ==================== Drivers (Whitelisted) ====================
- S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-07-29] (Avira Operations GmbH & Co. KG)
- S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-07-29] (Avira Operations GmbH & Co. KG)
- S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-07-29] (Avira Operations GmbH & Co. KG)
- S0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2012-03-13] (Bytemobile, Inc.)
- S2 cpuz135; C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2010-11-08] (CPUID)
- S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [213504 2011-07-11] (Huawei Technologies Co., Ltd.)
- S1 HWiNFO32; C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS [30080 2011-09-21] (REALiX(tm))
- S1 HWiNFO32; C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS [30080 2011-09-21] (REALiX(tm))
- S3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
- S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1806400 2009-06-05] ()
- S0 sptd; C:\Windows\System32\Drivers\sptd.sys [871408 2011-02-06] (Duplex Secure Ltd.)
- S1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2012-03-13] (Bytemobile, Inc.)
- S1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2012-03-13] (Bytemobile, Inc.)
- S2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-08-06] ()
- S3 tmlwf;
- S3 tmwfp;
- ========================== Drivers MD5 =======================
- C:\Windows\system32\DRIVERS\1394ohci.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ACPI.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\acpipmi.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit
- C:\Windows\system32\drivers\afd.sys B9384E03479D2506BC924C16A3DB87BC
- C:\Windows\system32\DRIVERS\agp440.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\aksdf.sys BC569A6C209D94F6643EE35710AEC1F6
- C:\Windows\system32\DRIVERS\aliide.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\amdide.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\atikmdag.sys 79CC9BE187E3144E1B58A54B842475E7
- C:\Windows\System32\DRIVERS\atikmpag.sys 07561D3B7FD99F6E186C49C2D0628E38
- C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\amdsata.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\amdxata.sys ==> MD5 is legit
- C:\Windows\System32\drivers\AmUStor.SYS 9C7F164B49CADC658D1B3C575782F346
- C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit
- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961
- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys 4C016FD76ED5C05E84CA8CAB77993961
- C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\atapi.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\athrx.sys F8633CDD09647A64EE8DB550630427FF
- C:\Windows\System32\drivers\AtihdW76.sys ED3A041014FBBFDC23D6C04F9C7A5D79
- C:\Windows\System32\drivers\AtiHdmi.sys D481083348138B4933ACFE95812DB71C
- C:\Windows\System32\DRIVERS\atikmdag.sys 79CC9BE187E3144E1B58A54B842475E7
- C:\Windows\System32\DRIVERS\avgntflt.sys 09E6069EF94B345061B4BD3CEBD974C8
- C:\Windows\System32\DRIVERS\avipbb.sys 488486DAD09A5B6C6DBB8B990A8B2307
- C:\Windows\System32\DRIVERS\avkmgr.sys 490FA25161BF3E51993EB724ECF0ACEB
- C:\Windows\system32\DRIVERS\bxvbda.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
- C:\Windows\System32\drivers\BMLoad.sys 8B1E76B5F86DF4396D77AB09787F6D37
- C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\BthEnum.sys CF98190A94F62E405C8CB255018B2315
- C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF
- C:\Windows\System32\Drivers\BTHport.sys A51FA9D0E85D5ADABEF72E67F386309C
- C:\Windows\System32\Drivers\BTHUSB.sys F740B9A16B2C06700F2130E19986BF3B
- C:\Windows\System32\drivers\btusbflt.sys D3466F77C2C49C6E393BA5FBA963A33E
- C:\Windows\System32\drivers\btwaudio.sys A72A9101F9730DB7332714E566614E4D
- C:\Windows\System32\drivers\btwavdt.sys 5CEEC634B617525F2B6AD29F871033F7
- C:\Windows\System32\DRIVERS\btwl2cap.sys 6149301DC3F81D6F9667A3FBAC410975
- C:\Windows\System32\DRIVERS\btwrchid.sys 2AF5604D28BEF77B7CF4B9D232FE7CD3
- C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit
- C:\Windows\System32\CLFS.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\cmdide.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\cng.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit
- C:\Windows\system32\drivers\cpuz135_x64.sys 262969A3FAB32B9E17E63E2D17A57744
- C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\dfsc.sys 3F1DC527070ACB87E40AFE46EF6DA749
- C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit
- C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit
- C:\Windows\System32\drivers\dxgkrnl.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\evbda.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\errdev.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ew_hwusbdev.sys 86F7951BBCEE4A86E79A97306BD14318
- C:\Windows\System32\DRIVERS\ew_usbenumfilter.sys 55E0EDA185869F7EA67EA97FD0655B39
- C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit
- C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
- C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legit
- C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
- C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\fssfltr.sys 2BF3B36B96D015AF666B6AA63AE2E38F
- C:\Windows\System32\Drivers\Fs_Rec.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\fvevol.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\GEARAspiWDM.sys ==> MD5 is legit
- C:\Windows\system32\drivers\hardlock.sys D8BF3C594BD17A37960362E6C6739B90
- C:\Windows\system32\drivers\hcmon.sys ADB4348DA1345877B04E22203AFC8993
- C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
- C:\Windows\System32\drivers\HdAudio.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\HECIx64.sys B6AC71AAA2B10848F57FC49D55A651AF
- C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\HpSAMD.sys ==> MD5 is legit
- C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ew_jucdcacm.sys 30516686A4ACA616AE8728BC0CB65E51
- C:\Windows\System32\DRIVERS\ew_jubusenum.sys E1EE74AC69C88C8379898D97E34A8852
- C:\Windows\System32\DRIVERS\ew_juextctrl.sys D13B215259D8362DC1C6F8F645DF7BA9
- C:\Windows\System32\DRIVERS\ew_juwwanecm.sys 6AF9654CEDC83CB533771C9FFC6B27B0
- C:\Windows\System32\DRIVERS\ewusbmdm.sys 6C921D120A5212CB94FA2520847774C4
- C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS 160BAB05A99FCF8FD77153371644546F
- C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS 160BAB05A99FCF8FD77153371644546F
- C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\iaStor.sys BBB3B6DF1ABB0FE35802EDE85CC1C011
- C:\Windows\system32\DRIVERS\iaStorV.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit
- C:\Windows\System32\drivers\RTKVHD64.sys B88E24BD77A0CE2CFFEE2FACF1151BE0
- C:\Windows\system32\DRIVERS\intelide.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\IPMIDrv.sys ==> MD5 is legit
- C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
- C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\isapnp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\msiscsi.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\kbfiltr.sys E63EF8C3271D014F14E2469CE75FECB4
- C:\Windows\System32\Drivers\ksecdd.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\ksecpkg.sys ==> MD5 is legit
- C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\L1C62x64.sys 9DDC68B87A9B837736A2B193EE14A4A5
- C:\Windows\System32\DRIVERS\LHidFilt.Sys 24E09882BA51B9830AE029888A3AAF18
- C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\LMouFilt.Sys 2F94325D8C10E2B715F3D753C2422AAC
- C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit
- C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit
- C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
- C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\mpio.sys ==> MD5 is legit
- C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
- C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\mrxsmb.sys B7F3D2C40BDF8FFB73EBFB19C77734E2
- C:\Windows\System32\DRIVERS\mrxsmb10.sys 86C6F88B5168CE21CF8D69D0B3FF5D19
- C:\Windows\System32\DRIVERS\mrxsmb20.sys B081069251C8E9F42CB8769D07148F9C
- C:\Windows\System32\DRIVERS\msahci.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\msdsm.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
- C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\msisadrv.sys ==> MD5 is legit
- C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
- C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
- C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit
- C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ATK64AMD.sys 032D35C996F21D19A205A7C8F0B76F3C
- C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
- C:\Windows\System32\drivers\ndis.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\netaapl64.sys 6F4607E2333FE21E9E3FF8133A88B35B
- C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
- C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Ntfs.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\nvraid.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\nvstor.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\nv_agp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\ohci1394.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\parport.sys ==> MD5 is legit
- C:\Windows\System32\drivers\partmgr.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\pci.sys ==> MD5 is legit
- C:\Windows\System32\drivers\pciide.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit
- C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
- C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit
- C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\rdpbus.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
- C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
- C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\RDPWD.sys ==> MD5 is legit
- C:\Windows\System32\drivers\rdyboost.sys E5DC9BA9E439D6DBDD79F8CAACB5BF01
- C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932
- C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sbp2port.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\serenum.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\serial.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sffdisk.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sffp_mmc.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sffp_sd.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\SiSG664.sys 1BC348CF6BAA90EC8E533EF6E6A69933
- C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\snp2uvc.sys 7AEC460DBDD193680F0E77724E40E7B6
- C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\sptd.sys 88E5162E58C8919CC873F5D8946197CF
- C:\Windows\System32\DRIVERS\srv.sys 148D50904D2A0DF29A19778715EB35BB
- C:\Windows\System32\DRIVERS\srv2.sys CE2189FE31D36678AC9EB7DDEE08EC96
- C:\Windows\System32\DRIVERS\srvnet.sys CB69EDEB069A49577592835659CD0E46
- C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\serscan.sys DECACB6921DED1A38642642685D77DAC
- C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\SynTP.sys 01A658167619075BAAD31C96074C0B38
- C:\Windows\System32\DRIVERS\taphss.sys F33FDC72298DF4BF9813A55D21F4EB31
- C:\Windows\System32\drivers\tcpip.sys 90A2D722CF64D911879D6C4A4F802A4D
- C:\Windows\System32\DRIVERS\tcpip.sys 90A2D722CF64D911879D6C4A4F802A4D
- C:\Windows\system32\drivers\tcpipBM.sys FBA939B917976B2C37F1B235DFCD4876
- C:\Windows\system32\drivers\tcpipBM.sys FBA939B917976B2C37F1B235DFCD4876
- C:\Windows\System32\drivers\tcpipreg.sys ==> MD5 is legit
- C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
- C:\Windows\System32\drivers\tdtcp.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\tssecsrv.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\TurboB.sys C45A3E051C65106A28982CAED125F855
- C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\uliagpkx.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\usbaapl64.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\usbccgp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\usbcir.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\usbehci.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\usbhub.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\usbohci.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\usbprint.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\USBSTOR.SYS ==> MD5 is legit
- C:\Windows\system32\DRIVERS\usbuhci.sys ==> MD5 is legit
- C:\Windows\System32\Drivers\usbvideo.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vdrvroot.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
- C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\vhdmp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\viaide.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vmci.sys 87FC1DD880E8CAC4FAEBB84AF61A87C4
- C:\Windows\system32\drivers\VMkbd.sys 3A717D3E29C107351347B478A9D0043F
- C:\Windows\System32\DRIVERS\vmnetadapter.sys B259C31378BC855AFD1B53F59311C251
- C:\Windows\System32\DRIVERS\vmnetbridge.sys DEC4CE720FFEDA939CF1BA315CFBD993
- C:\Windows\system32\drivers\vmnetuserif.sys B6A3766C3E99FB1F6663C6B4B7C3F3A1
- C:\Windows\System32\Drivers\vmusb.sys 415B167695C4B5960A13098622EF3D80
- C:\Windows\system32\drivers\vmx86.sys E53CAD9B1FA901CA2046501EE88F9CEF
- C:\Windows\System32\DRIVERS\vodafone_K3805-z_dc_enum.sys 1E4D31FEC921300C5F262C52F5FCC666
- C:\Windows\System32\DRIVERS\volmgr.sys ==> MD5 is legit
- C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\volsnap.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\vwifimp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit
- C:\Windows\System32\drivers\Wdf01000.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\wimfltr.sys 52DED146E4797E6CCF94799E8E22BB2A
- C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
- C:\Windows\SysWow64\drivers\wimmount.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\WinUsb.sys ==> MD5 is legit
- C:\Windows\system32\DRIVERS\wmiacpi.sys ==> MD5 is legit
- C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\WSDPrint.sys 8D918B1DB190A4D9B1753A66FA8C96E8
- C:\Windows\System32\DRIVERS\WSDScan.sys 4A2A5C50DD1A63577D3ACA94269FBC7F
- C:\Windows\System32\drivers\WudfPf.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\WUDFRd.sys ==> MD5 is legit
- C:\Windows\System32\DRIVERS\xnacc.sys 4A5CE13408945E525503B5F73D29B9C5
- ==================== NetSvcs (Whitelisted) ===================
- ==================== One Month Created Files and Folders ========
- 2013-07-30 12:06 - 2013-07-30 12:06 - 00000000 ____D C:\FRST
- 2013-07-30 00:00 - 2013-07-30 00:00 - 00042193 _____ C:\Windows\System32\config\mybackup
- 2013-07-30 00:00 - 2013-07-30 00:00 - 00000000 ____D C:\Windows\System32\config\backup
- 2013-07-29 18:48 - 2013-07-29 18:48 - 00266568 _____ C:\Windows\Minidump\073013-27580-01.dmp
- 2013-07-29 03:17 - 2013-07-29 03:17 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Red Alert 3
- 2013-07-29 02:47 - 2013-07-29 02:47 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Red Alert 3 Uprising
- 2013-07-29 02:44 - 2013-07-29 02:46 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Red Alert 3 Uprising
- 2013-07-29 00:51 - 2013-07-29 00:51 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Avira
- 2013-07-29 00:47 - 2013-07-29 00:47 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
- 2013-07-29 00:47 - 2013-07-29 00:47 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00001996 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\ProgramData\Avira
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\ProgramData\APN
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\Program Files (x86)\Avira
- 2013-07-29 00:46 - 2013-07-29 00:28 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys
- 2013-07-29 00:46 - 2013-07-29 00:28 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys
- 2013-07-29 00:46 - 2013-07-29 00:28 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avkmgr.sys
- 2013-07-25 03:26 - 2013-07-25 03:26 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Local\BIT.TRIP RUNNER
- 2013-07-24 05:35 - 2013-07-24 05:35 - 00826112 _____ C:\Windows\Minidump\072413-30404-01.dmp
- 2013-07-24 05:35 - 2013-07-24 05:35 - 00000000 _____ C:\Windows\SysWOW64\cd.dat
- 2013-07-24 05:17 - 2013-07-24 05:17 - 01189624 _____ (AMD Inc.) C:\Users\Lau Chee Keong\Downloads\catalyst_mobility_64-bit_util(2).exe
- 2013-07-24 04:17 - 2013-07-24 04:17 - 00002453 _____ C:\Users\Public\Desktop\SeaTools for Windows.lnk
- 2013-07-24 04:17 - 2013-07-24 04:17 - 00000000 ____D C:\Program Files (x86)\Seagate
- 2013-07-24 04:15 - 2013-07-24 04:15 - 21700280 _____ C:\Users\Lau Chee Keong\Downloads\SeaToolsforWindowsSetup-1208.exe
- 2013-07-12 19:38 - 2013-07-12 19:38 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Gaslamp Games
- 2013-07-09 22:36 - 2013-07-21 07:39 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Larian Studios
- 2013-07-05 21:37 - 2013-07-05 21:37 - 00000000 ____D C:\DA5
- 2013-07-04 01:18 - 2013-07-04 01:19 - 15562212 _____ C:\Users\Lau Chee Keong\Downloads\microstran-student-2013.exe
- 2013-07-02 19:38 - 2013-07-02 19:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 8
- 2013-07-02 06:13 - 2013-07-02 06:31 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\PineappleSmashCrew
- 2013-07-02 06:12 - 2013-07-02 06:12 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Quest3D
- 2013-06-30 00:41 - 2013-06-30 00:44 - 00000000 ____D C:\Void Destroyer
- ==================== One Month Modified Files and Folders =======
- 2013-07-30 00:35 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
- 2013-07-30 00:00 - 2013-07-30 00:00 - 00042193 _____ C:\Windows\System32\config\mybackup
- 2013-07-30 00:00 - 2013-07-30 00:00 - 00000000 ____D C:\Windows\System32\config\backup
- 2013-07-29 22:19 - 2009-07-13 23:44 - 00000000 ___RD C:\Users\Public\Recorded TV
- 2013-07-29 18:48 - 2013-07-29 18:48 - 00266568 _____ C:\Windows\Minidump\073013-27580-01.dmp
- 2013-07-29 18:48 - 2010-10-24 01:22 - 00000000 ____D C:\Windows\Minidump
- 2013-07-29 18:48 - 2010-10-23 17:32 - 00000000 ____D C:\users\Lau Chee Keong
- 2013-07-29 18:47 - 2010-10-24 01:22 - 157000016 _____ C:\Windows\MEMORY.DMP
- 2013-07-29 03:17 - 2013-07-29 03:17 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Red Alert 3
- 2013-07-29 02:47 - 2013-07-29 02:47 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Red Alert 3 Uprising
- 2013-07-29 02:46 - 2013-07-29 02:44 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Red Alert 3 Uprising
- 2013-07-29 01:45 - 2010-08-26 12:40 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
- 2013-07-29 01:26 - 2009-07-13 20:45 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2013-07-29 01:26 - 2009-07-13 20:45 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2013-07-29 01:22 - 2010-08-26 12:22 - 02069532 _____ C:\Windows\WindowsUpdate.log
- 2013-07-29 01:19 - 2012-02-17 07:20 - 00000000 ____D C:\ProgramData\VMware
- 2013-07-29 01:19 - 2010-10-25 05:16 - 00045056 _____ C:\Windows\System32\acovcnt.exe
- 2013-07-29 01:19 - 2010-08-26 12:47 - 00115074 _____ C:\Windows\PFRO.log
- 2013-07-29 01:19 - 2010-08-26 12:40 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
- 2013-07-29 01:19 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
- 2013-07-29 01:19 - 2009-07-13 20:51 - 00198659 _____ C:\Windows\setupact.log
- 2013-07-29 01:17 - 2013-03-16 00:18 - 00000824 _____ C:\Windows\System32\Drivers\etc\tmvsthfud.bin
- 2013-07-29 01:17 - 2010-08-26 12:44 - 00000824 _____ C:\Windows\System32\Drivers\etc\tmvsthfss.bin
- 2013-07-29 01:15 - 2010-08-26 12:57 - 00002402 _____ C:\Windows\System32\AutoRunFilter.ini
- 2013-07-29 01:15 - 2010-08-26 12:57 - 00001790 _____ C:\Windows\System32\ServiceFilter.ini
- 2013-07-29 00:51 - 2013-07-29 00:51 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Avira
- 2013-07-29 00:51 - 2012-09-03 19:46 - 00000964 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-163196908-2427133349-738422901-1001UA.job
- 2013-07-29 00:47 - 2013-07-29 00:47 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
- 2013-07-29 00:47 - 2013-07-29 00:47 - 00000000 ____D C:\Program Files (x86)\AskPartnerNetwork
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00083672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00001996 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\ProgramData\Avira
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\ProgramData\APN
- 2013-07-29 00:46 - 2013-07-29 00:46 - 00000000 ____D C:\Program Files (x86)\Avira
- 2013-07-29 00:28 - 2013-07-29 00:46 - 00130016 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys
- 2013-07-29 00:28 - 2013-07-29 00:46 - 00100712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys
- 2013-07-29 00:28 - 2013-07-29 00:46 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avkmgr.sys
- 2013-07-28 21:51 - 2012-09-03 19:46 - 00000942 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-163196908-2427133349-738422901-1001Core.job
- 2013-07-27 18:57 - 2010-10-24 01:03 - 00034167 _____ C:\Windows\TMFilter.log
- 2013-07-26 02:56 - 2012-02-17 07:25 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Local\VMware
- 2013-07-25 23:04 - 2009-07-13 21:32 - 00000000 ____D C:\Windows\System32\FxsTmp
- 2013-07-25 22:59 - 2012-02-17 07:25 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\VMware
- 2013-07-25 03:26 - 2013-07-25 03:26 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Local\BIT.TRIP RUNNER
- 2013-07-25 03:26 - 2010-08-26 12:55 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\System32\OpenAL32.dll
- 2013-07-25 03:26 - 2010-08-26 12:55 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
- 2013-07-24 05:35 - 2013-07-24 05:35 - 00826112 _____ C:\Windows\Minidump\072413-30404-01.dmp
- 2013-07-24 05:35 - 2013-07-24 05:35 - 00000000 _____ C:\Windows\SysWOW64\cd.dat
- 2013-07-24 05:17 - 2013-07-24 05:17 - 01189624 _____ (AMD Inc.) C:\Users\Lau Chee Keong\Downloads\catalyst_mobility_64-bit_util(2).exe
- 2013-07-24 04:17 - 2013-07-24 04:17 - 00002453 _____ C:\Users\Public\Desktop\SeaTools for Windows.lnk
- 2013-07-24 04:17 - 2013-07-24 04:17 - 00000000 ____D C:\Program Files (x86)\Seagate
- 2013-07-24 04:15 - 2013-07-24 04:15 - 21700280 _____ C:\Users\Lau Chee Keong\Downloads\SeaToolsforWindowsSetup-1208.exe
- 2013-07-23 04:49 - 2010-10-23 17:33 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Local\VirtualStore
- 2013-07-22 02:30 - 2013-03-31 03:44 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Local\GOG.com
- 2013-07-22 02:30 - 2013-03-31 03:44 - 00000000 ____D C:\Program Files (x86)\GOG.com
- 2013-07-21 17:33 - 2012-04-14 04:52 - 00000000 ____D C:\Users\Public\Documents\Virtual PC
- 2013-07-21 07:39 - 2013-07-09 22:36 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Larian Studios
- 2013-07-21 06:56 - 2010-11-03 05:10 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\my games
- 2013-07-21 06:55 - 2010-10-23 17:36 - 00980111 _____ C:\Windows\DirectX.log
- 2013-07-20 18:16 - 2011-03-05 06:52 - 00000000 ____D C:\ProgramData\Stardock
- 2013-07-17 17:41 - 2012-05-20 03:18 - 00000000 ____D C:\Windows\System32\Service
- 2013-07-15 18:40 - 2010-08-26 12:40 - 00003908 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
- 2013-07-15 18:40 - 2010-08-26 12:40 - 00003656 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
- 2013-07-14 19:28 - 2009-07-13 21:13 - 00787066 _____ C:\Windows\System32\PerfStringBackup.INI
- 2013-07-12 19:38 - 2013-07-12 19:38 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\Gaslamp Games
- 2013-07-09 01:01 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\System32\NDF
- 2013-07-05 21:37 - 2013-07-05 21:37 - 00000000 ____D C:\DA5
- 2013-07-04 01:19 - 2013-07-04 01:18 - 15562212 _____ C:\Users\Lau Chee Keong\Downloads\microstran-student-2013.exe
- 2013-07-04 01:19 - 2012-08-30 06:11 - 00000000 ____D C:\Mswin
- 2013-07-03 05:20 - 2012-04-05 18:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
- 2013-07-02 19:38 - 2013-07-02 19:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 8
- 2013-07-02 06:31 - 2013-07-02 06:13 - 00000000 ____D C:\Users\Lau Chee Keong\Documents\PineappleSmashCrew
- 2013-07-02 06:12 - 2013-07-02 06:12 - 00000000 ____D C:\Users\Lau Chee Keong\AppData\Roaming\Quest3D
- 2013-06-30 00:44 - 2013-06-30 00:41 - 00000000 ____D C:\Void Destroyer
- Files to move or delete:
- ====================
- C:\ProgramData\hash.dat
- ==================== Known DLLs (Whitelisted) ================
- ==================== Bamital & volsnap Check =================
- C:\Windows\System32\winlogon.exe => MD5 is legit
- C:\Windows\System32\wininit.exe => MD5 is legit
- C:\Windows\SysWOW64\wininit.exe => MD5 is legit
- C:\Windows\explorer.exe => MD5 is legit
- C:\Windows\SysWOW64\explorer.exe => MD5 is legit
- C:\Windows\System32\svchost.exe => MD5 is legit
- C:\Windows\SysWOW64\svchost.exe => MD5 is legit
- C:\Windows\System32\services.exe => MD5 is legit
- C:\Windows\System32\User32.dll => MD5 is legit
- C:\Windows\SysWOW64\User32.dll => MD5 is legit
- C:\Windows\System32\userinit.exe => MD5 is legit
- C:\Windows\SysWOW64\userinit.exe => MD5 is legit
- C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
- ==================== EXE ASSOCIATION =====================
- HKLM\...\.exe: exefile => OK
- HKLM\...\exefile\DefaultIcon: %1 => OK
- HKLM\...\exefile\open\command: "%1" %* => OK
- ==================== Restore Points =========================
- Restore point made on: 2013-07-29 02:25:36
- Restore point made on: 2013-07-29 02:43:47
- ==================== BCD ================================
- Windows Boot Manager
- --------------------
- identifier {bootmgr}
- device boot
- description Windows Boot Manager
- locale en-US
- inherit {globalsettings}
- default {default}
- resumeobject {8cb2d9b0-7c05-11de-842e-b4611d44fefa}
- displayorder {default}
- toolsdisplayorder {memdiag}
- timeout 30
- Windows Boot Loader
- -------------------
- identifier {572bcd56-ffa7-11d9-aae0-0007e994107d}
- device ramdisk=[\Device\HarddiskVolume1]\winre.wim,{ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
- path \windows\system32\boot\winload.exe
- description Windows Recovery Environment
- osdevice ramdisk=[\Device\HarddiskVolume1]\winre.wim,{ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
- systemroot \windows
- nx OptIn
- detecthal Yes
- winpe Yes
- Windows Boot Loader
- -------------------
- identifier {default}
- device boot
- path \Windows\system32\winload.exe
- description Windows 7
- locale en-US
- inherit {bootloadersettings}
- recoverysequence {current}
- recoveryenabled Yes
- osdevice boot
- systemroot \Windows
- resumeobject {8cb2d9b0-7c05-11de-842e-b4611d44fefa}
- nx OptIn
- Windows Boot Loader
- -------------------
- identifier {current}
- device ramdisk=[C:]\Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\Winre.wim,{8cb2d9b5-7c05-11de-842e-b4611d44fefa}
- path \windows\system32\winload.exe
- description Windows Recovery Environment
- inherit {bootloadersettings}
- osdevice ramdisk=[C:]\Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\Winre.wim,{8cb2d9b5-7c05-11de-842e-b4611d44fefa}
- systemroot \windows
- nx OptIn
- winpe Yes
- Resume from Hibernate
- ---------------------
- identifier {8cb2d9b0-7c05-11de-842e-b4611d44fefa}
- device boot
- path \Windows\system32\winresume.exe
- description Windows Resume Application
- locale en-US
- inherit {resumeloadersettings}
- filedevice partition=C:
- filepath \hiberfil.sys
- debugoptionenabled No
- Windows Memory Tester
- ---------------------
- identifier {memdiag}
- device partition=C:
- path \boot\memtest.exe
- description Windows Memory Diagnostic
- locale en-US
- inherit {globalsettings}
- badmemoryaccess Yes
- EMS Settings
- ------------
- identifier {emssettings}
- bootems Yes
- Debugger Settings
- -----------------
- identifier {dbgsettings}
- debugtype Serial
- debugport 1
- baudrate 115200
- RAM Defects
- -----------
- identifier {badmemory}
- Global Settings
- ---------------
- identifier {globalsettings}
- inherit {dbgsettings}
- {emssettings}
- {badmemory}
- Boot Loader Settings
- --------------------
- identifier {bootloadersettings}
- inherit {globalsettings}
- {hypervisorsettings}
- Hypervisor Settings
- -------------------
- identifier {hypervisorsettings}
- hypervisordebugtype Serial
- hypervisordebugport 1
- hypervisorbaudrate 115200
- Resume Loader Settings
- ----------------------
- identifier {resumeloadersettings}
- inherit {globalsettings}
- Device options
- --------------
- identifier {8cb2d9b5-7c05-11de-842e-b4611d44fefa}
- description Ramdisk Options
- ramdisksdidevice partition=C:
- ramdisksdipath \Recovery\8cb2d9b4-7c05-11de-842e-b4611d44fefa\boot.sdi
- Device options
- --------------
- identifier {ad6c7bc8-fa0f-11da-8ddf-0013200354d8}
- description Ramdisk Device Options
- ramdisksdidevice partition=\Device\HarddiskVolume1
- ramdisksdipath \boot.sdi
- ==================== Memory info ===========================
- Percentage of memory in use: 16%
- Total physical RAM: 4020.55 MB
- Available physical RAM: 3352.84 MB
- Total Pagefile: 4018.7 MB
- Available Pagefile: 3351.4 MB
- Total Virtual: 8192 MB
- Available Virtual: 8191.85 MB
- ==================== Drives ================================
- Drive c: (OS) (Fixed) (Total:116.44 GB) (Free:15.46 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)]
- Drive d: (SDATA1) (Fixed) (Total:232.87 GB) (Free:25.4 GB) NTFS (Disk=1 Partition=1)
- Drive e: (DATA) (Fixed) (Total:329.79 GB) (Free:11.05 GB) NTFS (Disk=0 Partition=3)
- Drive f: (SDATA2) (Fixed) (Total:232.89 GB) (Free:57.09 GB) NTFS (Disk=1 Partition=2)
- Drive h: () (Removable) (Total:3.78 GB) (Free:3.78 GB) FAT (Disk=2 Partition=1)
- Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: E0C5913D)
- Partition 1: (Not Active) - (Size=20 GB) - (Type=1C)
- Partition 2: (Active) - (Size=116 GB) - (Type=07 NTFS)
- Partition 3: (Not Active) - (Size=330 GB) - (Type=OF Extended)
- ========================================================
- Disk: 1 (Size: 466 GB) (Disk ID: BBC58B91)
- Partition 1: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
- Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)
- ========================================================
- Disk: 2 (Size: 4 GB) (Disk ID: 0FAE83BF)
- Partition 1: (Not Active) - (Size=4 GB) - (Type=06)
- LastRegBack: 2013-07-22 20:56
- ==================== End Of Log ============================
Advertisement
Add Comment
Please, Sign In to add comment