ERR [1704] 2011/12/09 16:06:00: SDKController::CheckEngineState -> Engine not loaded MSG [4092] 2011/12/09 18:31:28: Configure new scan with profile: smart MSG [4092] 2011/12/09 18:31:28: -> scanning critical objects MSG [4092] 2011/12/09 18:31:28: -> scanning running processes MSG [4092] 2011/12/09 18:31:28: -> scanning registry MSG [4092] 2011/12/09 18:31:28: -> scanning lsp MSG [4092] 2011/12/09 18:31:28: -> scanning browser hijacks MSG [4092] 2011/12/09 18:31:28: -> scanning cookies MSG [4092] 2011/12/09 18:31:28: -> neutralizing rootkits MSG [4092] 2011/12/09 18:31:28: -> use mild rootkit detection MSG [4092] 2011/12/09 18:31:28: -> use spyware heuristics MSG [4092] 2011/12/09 18:31:28: -> use medium heuristics MSG [4092] 2011/12/09 18:31:28: -> scan only executables MSG [4092] 2011/12/09 18:31:28: -> file size limit = 20480 kB (0 = unlimited) MSG [4092] 2011/12/09 18:31:28: -> validating system critical files ERR [4092] 2011/12/09 18:31:28: SDKController::GetInfectionList -> Not in found infections state MSG [3660] 2011/12/09 18:34:32: Scan was completed in 183 seconds MSG [3660] 2011/12/09 18:34:32: Objects processed: 56090, infections detected: 0 MSG [4092] 2011/12/09 18:34:32: Dumping scan report: >>> Logfile created: 12/9/2011 18:31:28 >>> Ad-Aware version: 9.6.0 >>> Extended engine: 3 >>> Extended engine version: 3.1.2770 >>> User performing scan: Kevin >>> >>> *********************** Definitions database information *********************** >>> Lavasoft definition file: 150.644 >>> Genotype definition file version: 2011/09/21 13:56:01 >>> Extended engine definition file: 11223.0 >>> >>> ******************************** Scan results: ********************************* >>> Scan profile name: Smart Scan (ID: smart) >>> Objects scanned: 56090 >>> Objects detected: 0 >>> >>> >>> Type Detected >>> ========================== >>> Processes.......: 0 >>> Registry entries: 0 >>> Hostfile entries: 0 >>> Files...........: 0 >>> Folders.........: 0 >>> LSPs............: 0 >>> Cookies.........: 0 >>> Browser hijacks.: 0 >>> MRU objects.....: 0 >>> >>> >>> >>> Scan and cleaning complete: Finished correctly after 183 seconds >>> >>> *********************************** Settings *********************************** >>> >>> Scan profile: >>> ID: smart, enabled:1, value: Smart Scan >>> ID: folderstoscan, enabled:1, value: >>> ID: useantivirus, enabled:1, value: true >>> ID: sections, enabled:1 >>> ID: scancriticalareas, enabled:1, value: true >>> ID: scanrunningapps, enabled:1, value: true >>> ID: scanregistry, enabled:1, value: true >>> ID: scanlsp, enabled:1, value: true >>> ID: scanads, enabled:1, value: false >>> ID: scanhostsfile, enabled:1, value: false >>> ID: scanmru, enabled:1, value: false >>> ID: scanbrowserhijacks, enabled:1, value: true >>> ID: scantrackingcookies, enabled:1, value: true >>> ID: closebrowsers, enabled:1, value: false >>> ID: filescanningoptions, enabled:1 >>> ID: archives, enabled:1, value: false >>> ID: onlyexecutables, enabled:1, value: true >>> ID: skiplargerthan, enabled:1, value: 20480 >>> ID: scanrootkits, enabled:1, value: true >>> ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict >>> ID: usespywareheuristics, enabled:1, value: true >>> >>> Scan global: >>> ID: global, enabled:1 >>> ID: addtocontextmenu, enabled:1, value: true >>> ID: playsoundoninfection, enabled:1, value: false >>> ID: soundfile, enabled:0, value: N/A >>> >>> Scheduled scan settings: >>> >>> >>> Update settings: >>> ID: updates, enabled:1 >>> ID: launchthreatworksafterscan, enabled:1, value: silently, domain: normal,off,silently >>> ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: schedules, enabled:1, value: true >>> ID: updatedaily1, enabled:1, value: Daily 1 >>> ID: time, enabled:1, value: Fri Dec 09 12:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily2, enabled:1, value: Daily 2 >>> ID: time, enabled:1, value: Fri Dec 09 18:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily3, enabled:1, value: Daily 3 >>> ID: time, enabled:1, value: Fri Dec 09 00:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily4, enabled:1, value: Daily 4 >>> ID: time, enabled:1, value: Fri Dec 09 06:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updateweekly1, enabled:1, value: Weekly >>> ID: time, enabled:1, value: Fri Dec 09 12:39:00 2011 >>> ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: true >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: true >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> >>> Appearance settings: >>> ID: appearance, enabled:1 >>> ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource >>> ID: showtrayicon, enabled:1, value: false >>> ID: autoentertainmentmode, enabled:1, value: false >>> ID: guimode, enabled:1, value: mode_advanced, domain: mode_advanced,mode_simple >>> ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language >>> >>> Realtime protection settings: >>> ID: realtime, enabled:1 >>> ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant >>> ID: modules, enabled:1 >>> ID: processprotection, enabled:1, value: true >>> ID: onaccessprotection, enabled:1, value: true >>> ID: registryprotection, enabled:1, value: true >>> ID: networkprotection, enabled:1, value: true >>> ID: layers, enabled:1 >>> ID: useantivirus, enabled:1, value: true >>> ID: usespywareheuristics, enabled:1, value: true >>> ID: maintainbackup, enabled:1, value: true >>> >>> >>> ****************************** System information ****************************** >>> Computer name: KEVIN-PC >>> Processor name: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz >>> Processor identifier: Intel64 Family 6 Model 23 Stepping 10 >>> Processor speed: ~1995MHZ >>> Raw info: processorarchitecture 9, processortype 8664, processorlevel 6, processor revision 5898, number of processors 2, processor features: [MMX,SSE,SSE2,SSE3] >>> Physical memory available: 2337959936 bytes >>> Physical memory total: 4152360960 bytes >>> Virtual memory available: 1899044864 bytes >>> Virtual memory total: 2147352576 bytes >>> Memory load: 43% >>> Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) >>> Windows startup mode: >>> >>> Running processes: >>> PID: 520 name: C:\Windows\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 552 name: C:\PROGRA~2\AVG\AVG2012\avgrsa.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 584 name: C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 840 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 880 name: C:\Windows\System32\wininit.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 900 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 940 name: C:\Windows\System32\services.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 956 name: C:\Windows\System32\lsass.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 968 name: C:\Windows\System32\lsm.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 388 name: C:\Windows\System32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 744 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 816 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1084 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1112 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1128 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1272 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1292 name: C:\Windows\System32\SLsvc.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1360 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1484 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1668 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1776 name: C:\Windows\System32\spoolsv.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1800 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1412 name: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1472 name: C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1600 name: C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 548 name: C:\Program Files\Bonjour\mDNSResponder.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1808 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1152 name: C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2088 name: C:\Windows\System32\dwm.exe owner: Kevin domain: Kevin-PC >>> PID: 2100 name: C:\Windows\System32\taskeng.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2176 name: C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2188 name: C:\Windows\explorer.exe owner: Kevin domain: Kevin-PC >>> PID: 2216 name: C:\Windows\SysWOW64\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2256 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2368 name: C:\Program Files (x86)\Common Files\Motive\McciCMService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2396 name: C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2408 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2416 name: C:\Program Files (x86)\AVG\AVG2012\avgemca.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2468 name: C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2492 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2600 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 2640 name: C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 2752 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2828 name: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2920 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2976 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 3024 name: C:\Windows\System32\SearchIndexer.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2476 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 2820 name: C:\Windows\System32\drivers\XAudio64.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3016 name: C:\Windows\System32\taskeng.exe owner: Kevin domain: Kevin-PC >>> PID: 3104 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3152 name: C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3528 name: C:\Windows\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3932 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2460 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: Kevin domain: Kevin-PC >>> PID: 1984 name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe owner: Kevin domain: Kevin-PC >>> PID: 1348 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe owner: Kevin domain: Kevin-PC >>> PID: 812 name: C:\Windows\System32\igfxtray.exe owner: Kevin domain: Kevin-PC >>> PID: 3700 name: C:\Windows\System32\hkcmd.exe owner: Kevin domain: Kevin-PC >>> PID: 3516 name: C:\Windows\System32\igfxpers.exe owner: Kevin domain: Kevin-PC >>> PID: 3808 name: C:\Program Files\Windows Sidebar\sidebar.exe owner: Kevin domain: Kevin-PC >>> PID: 1216 name: C:\Windows\ehome\ehtray.exe owner: Kevin domain: Kevin-PC >>> PID: 1416 name: C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe owner: Kevin domain: Kevin-PC >>> PID: 1448 name: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe owner: Kevin domain: Kevin-PC >>> PID: 2504 name: C:\Program Files\Camera Assistant Software for Gateway\traybar.exe owner: Kevin domain: Kevin-PC >>> PID: 4060 name: C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe owner: Kevin domain: Kevin-PC >>> PID: 3668 name: C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe owner: Kevin domain: Kevin-PC >>> PID: 2036 name: C:\Program Files (x86)\AVG\AVG2012\avgtray.exe owner: Kevin domain: Kevin-PC >>> PID: 532 name: C:\Program Files (x86)\AVG Secure Search\vprot.exe owner: Kevin domain: Kevin-PC >>> PID: 3196 name: C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe owner: Kevin domain: Kevin-PC >>> PID: 4076 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: Kevin domain: Kevin-PC >>> PID: 3616 name: C:\Program Files (x86)\iTunes\iTunesHelper.exe owner: Kevin domain: Kevin-PC >>> PID: 3576 name: C:\Program Files\Camera Assistant Software for Gateway\CEC_MAIN.exe owner: Kevin domain: Kevin-PC >>> PID: 4188 name: C:\Windows\System32\igfxsrvc.exe owner: Kevin domain: Kevin-PC >>> PID: 4272 name: C:\Program Files\Windows Media Player\wmpnscfg.exe owner: Kevin domain: Kevin-PC >>> PID: 4380 name: C:\Program Files\iPod\bin\iPodService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 4804 name: C:\Program Files\Windows Media Player\wmpnetwk.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 4176 name: C:\Windows\ehome\ehmsas.exe owner: Kevin domain: Kevin-PC >>> PID: 3128 name: C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe owner: Kevin domain: Kevin-PC >>> PID: 4052 name: C:\Users\Kevin\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe owner: Kevin domain: Kevin-PC >>> PID: 4560 name: C:\Program Files\Windows Sidebar\sidebar.exe owner: Kevin domain: Kevin-PC >>> PID: 4452 name: C:\Program Files\Synaptics\SynTP\SynTPHelper.exe owner: Kevin domain: Kevin-PC >>> PID: 4196 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 4700 name: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe owner: Kevin domain: Kevin-PC >>> PID: 3640 name: C:\Windows\System32\wbem\unsecapp.exe owner: Kevin domain: Kevin-PC >>> PID: 2904 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Kevin domain: Kevin-PC >>> >>> Startup items: >>> Name: WebCheck >>> imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} >>> Name: {8C7461EF-2B13-11d2-BE35-3078302C2030} >>> imagepath: Component Categories cache daemon >>> Name: Camera Assistant Software >>> imagepath: "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe" >>> Name: eRecoveryService >>> Name: RemoteControl >>> imagepath: "C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe" >>> Name: LanguageShortcut >>> imagepath: "C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe" >>> Name: HP Software Update >>> imagepath: C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe >>> Name: AVG_TRAY >>> imagepath: "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" >>> Name: CarboniteSetupLite >>> imagepath: "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900 >>> Name: MaxMenuMgr >>> imagepath: "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" >>> Name: Adobe ARM >>> imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" >>> Name: vProt >>> imagepath: "C:\Program Files (x86)\AVG Secure Search\vprot.exe" >>> Name: DivXUpdate >>> imagepath: "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW >>> Name: APSDaemon >>> imagepath: "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" >>> Name: QuickTime Task >>> imagepath: "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime >>> Name: SunJavaUpdateSched >>> imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" >>> Name: iTunesHelper >>> imagepath: "C:\Program Files (x86)\iTunes\iTunesHelper.exe" >>> Name: >>> Name: >>> imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini >>> Name: >>> location: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk >>> imagepath: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe >>> >>> Bootexecute items: >>> Name: >>> imagepath: autocheck autochk * >>> Name: >>> imagepath: C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart >>> Name: >>> imagepath: lsdelete >>> >>> Running services: >>> Name: AdobeARMservice >>> displayname: Adobe Acrobat Update Service >>> Name: AeLookupSvc >>> displayname: Application Experience >>> Name: Appinfo >>> displayname: Application Information >>> Name: Apple Mobile Device >>> displayname: Apple Mobile Device >>> Name: AudioEndpointBuilder >>> displayname: Windows Audio Endpoint Builder >>> Name: AudioSrv >>> displayname: Windows Audio >>> Name: AVGIDSAgent >>> displayname: AVGIDSAgent >>> Name: avgwd >>> displayname: AVG WatchDog >>> Name: BFE >>> displayname: Base Filtering Engine >>> Name: BITS >>> displayname: Background Intelligent Transfer Service >>> Name: Bonjour Service >>> displayname: Bonjour Service >>> Name: Browser >>> displayname: Computer Browser >>> Name: BthServ >>> displayname: Bluetooth Support Service >>> Name: CryptSvc >>> displayname: Cryptographic Services >>> Name: DcomLaunch >>> displayname: DCOM Server Process Launcher >>> Name: Dhcp >>> displayname: DHCP Client >>> Name: Dnscache >>> displayname: DNS Client >>> Name: DPS >>> displayname: Diagnostic Policy Service >>> Name: EapHost >>> displayname: Extensible Authentication Protocol >>> Name: EMDMgmt >>> displayname: ReadyBoost >>> Name: ETService >>> displayname: Empowering Technology Service >>> Name: Eventlog >>> displayname: Windows Event Log >>> Name: EventSystem >>> displayname: COM+ Event System >>> Name: FDResPub >>> displayname: Function Discovery Resource Publication >>> Name: FontCache >>> displayname: Windows Font Cache Service >>> Name: FreeAgentGoNext Service >>> displayname: Seagate Service >>> Name: gpsvc >>> displayname: Group Policy Client >>> Name: hidserv >>> displayname: Human Interface Device Access >>> Name: hpqcxs08 >>> displayname: hpqcxs08 >>> Name: hpqddsvc >>> displayname: HP CUE DeviceDiscovery Service >>> Name: HsfXAudioService >>> displayname: HsfXAudioService >>> Name: IAANTMON >>> displayname: Intel(R) Matrix Storage Event Monitor >>> Name: IKEEXT >>> displayname: IKE and AuthIP IPsec Keying Modules >>> Name: iphlpsvc >>> displayname: IP Helper >>> Name: iPod Service >>> displayname: iPod Service >>> Name: KeyIso >>> displayname: CNG Key Isolation >>> Name: KtmRm >>> displayname: KtmRm for Distributed Transaction Coordinator >>> Name: LanmanServer >>> displayname: Server >>> Name: LanmanWorkstation >>> displayname: Workstation >>> Name: Lavasoft Ad-Aware Service >>> displayname: Lavasoft Ad-Aware Service >>> Name: lmhosts >>> displayname: TCP/IP NetBIOS Helper >>> Name: McciCMService >>> displayname: McciCMService >>> Name: MMCSS >>> displayname: Multimedia Class Scheduler >>> Name: MpsSvc >>> displayname: Windows Firewall >>> Name: Net Driver HPZ12 >>> displayname: Net Driver HPZ12 >>> Name: Netman >>> displayname: Network Connections >>> Name: netprofm >>> displayname: Network List Service >>> Name: NlaSvc >>> displayname: Network Location Awareness >>> Name: nsi >>> displayname: Network Store Interface Service >>> Name: o2flash >>> displayname: O2Micro Flash Memory Card Service >>> Name: PcaSvc >>> displayname: Program Compatibility Assistant Service >>> Name: PlugPlay >>> displayname: Plug and Play >>> Name: Pml Driver HPZ12 >>> displayname: Pml Driver HPZ12 >>> Name: PolicyAgent >>> displayname: IPsec Policy Agent >>> Name: ProfSvc >>> displayname: User Profile Service >>> Name: RasMan >>> displayname: Remote Access Connection Manager >>> Name: RpcSs >>> displayname: Remote Procedure Call (RPC) >>> Name: SamSs >>> displayname: Security Accounts Manager >>> Name: Schedule >>> displayname: Task Scheduler >>> Name: SeaPort >>> displayname: SeaPort >>> Name: seclogon >>> displayname: Secondary Logon >>> Name: SENS >>> displayname: System Event Notification Service >>> Name: ShellHWDetection >>> displayname: Shell Hardware Detection >>> Name: slsvc >>> displayname: Software Licensing >>> Name: Spooler >>> displayname: Print Spooler >>> Name: SSDPSRV >>> displayname: SSDP Discovery >>> Name: SstpSvc >>> displayname: Secure Socket Tunneling Protocol Service >>> Name: stisvc >>> displayname: Windows Image Acquisition (WIA) >>> Name: SysMain >>> displayname: Superfetch >>> Name: TabletInputService >>> displayname: Tablet PC Input Service >>> Name: TapiSrv >>> displayname: Telephony >>> Name: TermService >>> displayname: Terminal Services >>> Name: Themes >>> displayname: Themes >>> Name: TrkWks >>> displayname: Distributed Link Tracking Client >>> Name: upnphost >>> displayname: UPnP Device Host >>> Name: UxSms >>> displayname: Desktop Window Manager Session Manager >>> Name: vToolbarUpdater >>> displayname: vToolbarUpdater >>> Name: W32Time >>> displayname: Windows Time >>> Name: WdiSystemHost >>> displayname: Diagnostic System Host >>> Name: WebClient >>> displayname: WebClient >>> Name: WerSvc >>> displayname: Windows Error Reporting Service >>> Name: Winmgmt >>> displayname: Windows Management Instrumentation >>> Name: Wlansvc >>> displayname: WLAN AutoConfig >>> Name: wlidsvc >>> displayname: Windows Live ID Sign-in Assistant >>> Name: WMPNetworkSvc >>> displayname: Windows Media Player Network Sharing Service >>> Name: WPDBusEnum >>> displayname: Portable Device Enumerator Service >>> Name: wscsvc >>> displayname: Security Center >>> Name: WSearch >>> displayname: Windows Search >>> Name: wuauserv >>> displayname: Windows Update >>> Name: wudfsvc >>> displayname: Windows Driver Foundation - User-mode Driver Framework >>> Name: XAudioService >>> displayname: XAudioService >>> >>> ERR [4092] 2011/12/09 18:34:32: SDKController::GetInfectionList -> Not in found infections state MSG [4092] 2011/12/09 18:35:20: Configure new scan with profile: full MSG [4092] 2011/12/09 18:35:20: -> scanning critical objects MSG [4092] 2011/12/09 18:35:20: -> scanning running processes MSG [4092] 2011/12/09 18:35:20: -> scanning registry MSG [4092] 2011/12/09 18:35:20: -> scanning lsp MSG [4092] 2011/12/09 18:35:20: -> scanning ads MSG [4092] 2011/12/09 18:35:20: -> scanning hosts file MSG [4092] 2011/12/09 18:35:20: -> scanning mru objects MSG [4092] 2011/12/09 18:35:20: -> scanning browser hijacks MSG [4092] 2011/12/09 18:35:20: -> scanning cookies MSG [4092] 2011/12/09 18:35:20: -> neutralizing rootkits MSG [4092] 2011/12/09 18:35:20: -> use mild rootkit detection MSG [4092] 2011/12/09 18:35:20: -> use spyware heuristics MSG [4092] 2011/12/09 18:35:20: -> use medium heuristics MSG [4092] 2011/12/09 18:35:20: -> scan archives MSG [4092] 2011/12/09 18:35:20: -> file size limit = 20480 kB (0 = unlimited) MSG [4092] 2011/12/09 18:35:20: -> validating system critical files MSG [4092] 2011/12/09 18:35:20: -> scan file/path = C:\ ERR [4092] 2011/12/09 18:35:20: SDKController::GetInfectionList -> Not in found infections state MSG [4092] 2011/12/09 18:46:20: Stopping scan... MSG [3988] 2011/12/09 18:46:21: Scan was requested to stop after 660 seconds MSG [3988] 2011/12/09 18:46:21: Objects processed: 66598, infections detected: 5 MSG [6012] 2011/12/09 18:46:47: Remediating 5 infections MSG [6012] 2011/12/09 18:46:48: Infections quarantined: 5, removed: 0, repaired: 0 MSG [6012] 2011/12/09 18:46:48: Infections ignored by remediation: 0 (0 whitelisted, 0 skipped). MSG [4092] 2011/12/09 18:46:48: Dumping scan report: >>> Logfile created: 12/9/2011 18:35:20 >>> Ad-Aware version: 9.6.0 >>> Extended engine: 3 >>> Extended engine version: 3.1.2770 >>> User performing scan: Kevin >>> >>> *********************** Definitions database information *********************** >>> Lavasoft definition file: 150.644 >>> Genotype definition file version: 2011/09/21 13:56:01 >>> Extended engine definition file: 11223.0 >>> >>> ******************************** Scan results: ********************************* >>> Scan profile name: Full Scan (ID: full) >>> Objects scanned: 66598 >>> Objects detected: 5 >>> >>> >>> Type Detected >>> ========================== >>> Processes.......: 0 >>> Registry entries: 0 >>> Hostfile entries: 0 >>> Files...........: 5 >>> Folders.........: 0 >>> LSPs............: 0 >>> Cookies.........: 0 >>> Browser hijacks.: 0 >>> MRU objects.....: 0 >>> >>> >>> >>> Quarantined items: >>> Description: c:\program files (x86)\common files\spigot\wtxpcom\components\widgitoolbarff.dll Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: d3b24afd9cf164044e5bfcf166773e4f >>> Description: c:\program files (x86)\common files\spigot\wtxpcom\components\widgitoolbarff.dll.5 Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: 3d95e8ec740cb7f73207d79a58d65cd1 >>> Description: c:\program files (x86)\common files\spigot\wtxpcom\components\widgitoolbarff.dll.6 Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: cfc065e048f1a3987228c7d9d1901c44 >>> Description: c:\program files (x86)\common files\spigot\wtxpcom\components\widgitoolbarff.dll.7 Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: d3b24afd9cf164044e5bfcf166773e4f >>> Description: c:\program files (x86)\common files\spigot\wtxpcom\components\widgitoolbarff.dll.8 Family Name: Win32.Trojan.Agent Engine: 1 Clean status: Success Item ID: 0 Family ID: 936 MD5: dade726aa8aae9c4a1cd1ba1925f86fc >>> >>> Scan and cleaning complete: Stopped by request after 660 seconds >>> >>> *********************************** Settings *********************************** >>> >>> Scan profile: >>> ID: full, enabled:1, value: Full Scan >>> ID: folderstoscan, enabled:1, value: C:\ >>> ID: useantivirus, enabled:1, value: true >>> ID: sections, enabled:1 >>> ID: scancriticalareas, enabled:1, value: true >>> ID: scanrunningapps, enabled:1, value: true >>> ID: scanregistry, enabled:1, value: true >>> ID: scanlsp, enabled:1, value: true >>> ID: scanads, enabled:1, value: true >>> ID: scanhostsfile, enabled:1, value: true >>> ID: scanmru, enabled:1, value: true >>> ID: scanbrowserhijacks, enabled:1, value: true >>> ID: scantrackingcookies, enabled:1, value: true >>> ID: closebrowsers, enabled:1, value: false >>> ID: filescanningoptions, enabled:1 >>> ID: archives, enabled:1, value: true >>> ID: onlyexecutables, enabled:1, value: false >>> ID: skiplargerthan, enabled:1, value: 20480 >>> ID: scanrootkits, enabled:1, value: true >>> ID: rootkitlevel, enabled:1, value: mild, domain: medium,mild,strict >>> ID: usespywareheuristics, enabled:1, value: true >>> >>> Scan global: >>> ID: global, enabled:1 >>> ID: addtocontextmenu, enabled:1, value: true >>> ID: playsoundoninfection, enabled:1, value: false >>> ID: soundfile, enabled:0, value: N/A >>> >>> Scheduled scan settings: >>> >>> >>> Update settings: >>> ID: updates, enabled:1 >>> ID: launchthreatworksafterscan, enabled:1, value: silently, domain: normal,off,silently >>> ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall >>> ID: schedules, enabled:1, value: true >>> ID: updatedaily1, enabled:1, value: Daily 1 >>> ID: time, enabled:1, value: Fri Dec 09 12:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily2, enabled:1, value: Daily 2 >>> ID: time, enabled:1, value: Fri Dec 09 18:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily3, enabled:1, value: Daily 3 >>> ID: time, enabled:1, value: Fri Dec 09 00:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updatedaily4, enabled:1, value: Daily 4 >>> ID: time, enabled:1, value: Fri Dec 09 06:39:00 2011 >>> ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: false >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: false >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> ID: updateweekly1, enabled:1, value: Weekly >>> ID: time, enabled:1, value: Fri Dec 09 12:39:00 2011 >>> ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly >>> ID: weekdays, enabled:1 >>> ID: monday, enabled:1, value: true >>> ID: tuesday, enabled:1, value: false >>> ID: wednesday, enabled:1, value: false >>> ID: thursday, enabled:1, value: false >>> ID: friday, enabled:1, value: true >>> ID: saturday, enabled:1, value: false >>> ID: sunday, enabled:1, value: false >>> ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31 >>> ID: scanprofile, enabled:1, value: >>> ID: auto_deal_with_infections, enabled:1, value: false >>> >>> Appearance settings: >>> ID: appearance, enabled:1 >>> ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource >>> ID: showtrayicon, enabled:1, value: false >>> ID: autoentertainmentmode, enabled:1, value: false >>> ID: guimode, enabled:1, value: mode_advanced, domain: mode_advanced,mode_simple >>> ID: language, enabled:1, value: en, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language >>> >>> Realtime protection settings: >>> ID: realtime, enabled:1 >>> ID: infomessages, enabled:1, value: onlyimportant, domain: display,dontnotify,onlyimportant >>> ID: modules, enabled:1 >>> ID: processprotection, enabled:1, value: true >>> ID: onaccessprotection, enabled:1, value: true >>> ID: registryprotection, enabled:1, value: true >>> ID: networkprotection, enabled:1, value: true >>> ID: layers, enabled:1 >>> ID: useantivirus, enabled:1, value: true >>> ID: usespywareheuristics, enabled:1, value: true >>> ID: maintainbackup, enabled:1, value: true >>> >>> >>> ****************************** System information ****************************** >>> Computer name: KEVIN-PC >>> Processor name: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz >>> Processor identifier: Intel64 Family 6 Model 23 Stepping 10 >>> Processor speed: ~1995MHZ >>> Raw info: processorarchitecture 9, processortype 8664, processorlevel 6, processor revision 5898, number of processors 2, processor features: [MMX,SSE,SSE2,SSE3] >>> Physical memory available: 2347761664 bytes >>> Physical memory total: 4152360960 bytes >>> Virtual memory available: 1866387456 bytes >>> Virtual memory total: 2147352576 bytes >>> Memory load: 43% >>> Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) >>> Windows startup mode: >>> >>> Running processes: >>> PID: 520 name: C:\Windows\System32\smss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 552 name: C:\PROGRA~2\AVG\AVG2012\avgrsa.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 584 name: C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 840 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 880 name: C:\Windows\System32\wininit.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 900 name: C:\Windows\System32\csrss.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 940 name: C:\Windows\System32\services.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 956 name: C:\Windows\System32\lsass.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 968 name: C:\Windows\System32\lsm.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 388 name: C:\Windows\System32\winlogon.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 744 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 816 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1084 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1112 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1128 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1272 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1292 name: C:\Windows\System32\SLsvc.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1360 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1484 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 1668 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1776 name: C:\Windows\System32\spoolsv.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1800 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1412 name: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1472 name: C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1600 name: C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 548 name: C:\Program Files\Bonjour\mDNSResponder.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 1808 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 1152 name: C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2088 name: C:\Windows\System32\dwm.exe owner: Kevin domain: Kevin-PC >>> PID: 2100 name: C:\Windows\System32\taskeng.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2176 name: C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2188 name: C:\Windows\explorer.exe owner: Kevin domain: Kevin-PC >>> PID: 2216 name: C:\Windows\SysWOW64\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2256 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2368 name: C:\Program Files (x86)\Common Files\Motive\McciCMService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2396 name: C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2408 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2416 name: C:\Program Files (x86)\AVG\AVG2012\avgemca.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2468 name: C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2492 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2600 name: C:\Windows\System32\svchost.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 2640 name: C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 2752 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 2828 name: C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2920 name: C:\Windows\System32\svchost.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2976 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 3024 name: C:\Windows\System32\SearchIndexer.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2476 name: C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE owner: SYSTEM domain: NT AUTHORITY >>> PID: 2820 name: C:\Windows\System32\drivers\XAudio64.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3016 name: C:\Windows\System32\taskeng.exe owner: Kevin domain: Kevin-PC >>> PID: 3104 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3152 name: C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3528 name: C:\Windows\System32\wbem\unsecapp.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 3932 name: C:\Windows\System32\wbem\WmiPrvSE.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 2460 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe owner: Kevin domain: Kevin-PC >>> PID: 1984 name: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe owner: Kevin domain: Kevin-PC >>> PID: 1348 name: C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe owner: Kevin domain: Kevin-PC >>> PID: 812 name: C:\Windows\System32\igfxtray.exe owner: Kevin domain: Kevin-PC >>> PID: 3700 name: C:\Windows\System32\hkcmd.exe owner: Kevin domain: Kevin-PC >>> PID: 3516 name: C:\Windows\System32\igfxpers.exe owner: Kevin domain: Kevin-PC >>> PID: 3808 name: C:\Program Files\Windows Sidebar\sidebar.exe owner: Kevin domain: Kevin-PC >>> PID: 1216 name: C:\Windows\ehome\ehtray.exe owner: Kevin domain: Kevin-PC >>> PID: 1416 name: C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe owner: Kevin domain: Kevin-PC >>> PID: 1448 name: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe owner: Kevin domain: Kevin-PC >>> PID: 2504 name: C:\Program Files\Camera Assistant Software for Gateway\traybar.exe owner: Kevin domain: Kevin-PC >>> PID: 4060 name: C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe owner: Kevin domain: Kevin-PC >>> PID: 3668 name: C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe owner: Kevin domain: Kevin-PC >>> PID: 2036 name: C:\Program Files (x86)\AVG\AVG2012\avgtray.exe owner: Kevin domain: Kevin-PC >>> PID: 532 name: C:\Program Files (x86)\AVG Secure Search\vprot.exe owner: Kevin domain: Kevin-PC >>> PID: 3196 name: C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe owner: Kevin domain: Kevin-PC >>> PID: 4076 name: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe owner: Kevin domain: Kevin-PC >>> PID: 3616 name: C:\Program Files (x86)\iTunes\iTunesHelper.exe owner: Kevin domain: Kevin-PC >>> PID: 3576 name: C:\Program Files\Camera Assistant Software for Gateway\CEC_MAIN.exe owner: Kevin domain: Kevin-PC >>> PID: 4188 name: C:\Windows\System32\igfxsrvc.exe owner: Kevin domain: Kevin-PC >>> PID: 4272 name: C:\Program Files\Windows Media Player\wmpnscfg.exe owner: Kevin domain: Kevin-PC >>> PID: 4380 name: C:\Program Files\iPod\bin\iPodService.exe owner: SYSTEM domain: NT AUTHORITY >>> PID: 4804 name: C:\Program Files\Windows Media Player\wmpnetwk.exe owner: NETWORK SERVICE domain: NT AUTHORITY >>> PID: 4176 name: C:\Windows\ehome\ehmsas.exe owner: Kevin domain: Kevin-PC >>> PID: 3128 name: C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe owner: Kevin domain: Kevin-PC >>> PID: 4052 name: C:\Users\Kevin\AppData\Local\Google\Update\1.3.21.79\GoogleCrashHandler.exe owner: Kevin domain: Kevin-PC >>> PID: 4560 name: C:\Program Files\Windows Sidebar\sidebar.exe owner: Kevin domain: Kevin-PC >>> PID: 4452 name: C:\Program Files\Synaptics\SynTP\SynTPHelper.exe owner: Kevin domain: Kevin-PC >>> PID: 4196 name: C:\Windows\System32\svchost.exe owner: LOCAL SERVICE domain: NT AUTHORITY >>> PID: 4700 name: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe owner: Kevin domain: Kevin-PC >>> PID: 3640 name: C:\Windows\System32\wbem\unsecapp.exe owner: Kevin domain: Kevin-PC >>> PID: 2904 name: C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-Aware.exe owner: Kevin domain: Kevin-PC >>> >>> Startup items: >>> Name: WebCheck >>> imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED} >>> Name: Camera Assistant Software >>> imagepath: "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe" >>> Name: eRecoveryService >>> Name: RemoteControl >>> imagepath: "C:\Program Files (x86)\CyberLink\PowerDVD\PDVDServ.exe" >>> Name: LanguageShortcut >>> imagepath: "C:\Program Files (x86)\CyberLink\PowerDVD\Language\Language.exe" >>> Name: HP Software Update >>> imagepath: C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe >>> Name: AVG_TRAY >>> imagepath: "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe" >>> Name: CarboniteSetupLite >>> imagepath: "C:\Program Files (x86)\Carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900 >>> Name: MaxMenuMgr >>> imagepath: "C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" >>> Name: Adobe ARM >>> imagepath: "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" >>> Name: vProt >>> imagepath: "C:\Program Files (x86)\AVG Secure Search\vprot.exe" >>> Name: DivXUpdate >>> imagepath: "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW >>> Name: APSDaemon >>> imagepath: "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" >>> Name: QuickTime Task >>> imagepath: "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime >>> Name: SunJavaUpdateSched >>> imagepath: "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" >>> Name: iTunesHelper >>> imagepath: "C:\Program Files (x86)\iTunes\iTunesHelper.exe" >>> Name: >>> Name: {8C7461EF-2B13-11d2-BE35-3078302C2030} >>> imagepath: Component Categories cache daemon >>> Name: >>> imagepath: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini >>> Name: >>> location: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk >>> imagepath: C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe >>> >>> Bootexecute items: >>> Name: >>> imagepath: autocheck autochk * >>> Name: >>> imagepath: C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart >>> Name: >>> imagepath: lsdelete >>> >>> Running services: >>> Name: AdobeARMservice >>> displayname: Adobe Acrobat Update Service >>> Name: AeLookupSvc >>> displayname: Application Experience >>> Name: Appinfo >>> displayname: Application Information >>> Name: Apple Mobile Device >>> displayname: Apple Mobile Device >>> Name: AudioEndpointBuilder >>> displayname: Windows Audio Endpoint Builder >>> Name: AudioSrv >>> displayname: Windows Audio >>> Name: AVGIDSAgent >>> displayname: AVGIDSAgent >>> Name: avgwd >>> displayname: AVG WatchDog >>> Name: BFE >>> displayname: Base Filtering Engine >>> Name: BITS >>> displayname: Background Intelligent Transfer Service >>> Name: Bonjour Service >>> displayname: Bonjour Service >>> Name: Browser >>> displayname: Computer Browser >>> Name: BthServ >>> displayname: Bluetooth Support Service >>> Name: CryptSvc >>> displayname: Cryptographic Services >>> Name: DcomLaunch >>> displayname: DCOM Server Process Launcher >>> Name: Dhcp >>> displayname: DHCP Client >>> Name: Dnscache >>> displayname: DNS Client >>> Name: DPS >>> displayname: Diagnostic Policy Service >>> Name: EapHost >>> displayname: Extensible Authentication Protocol >>> Name: EMDMgmt >>> displayname: ReadyBoost >>> Name: ETService >>> displayname: Empowering Technology Service >>> Name: Eventlog >>> displayname: Windows Event Log >>> Name: EventSystem >>> displayname: COM+ Event System >>> Name: FDResPub >>> displayname: Function Discovery Resource Publication >>> Name: FontCache >>> displayname: Windows Font Cache Service >>> Name: FreeAgentGoNext Service >>> displayname: Seagate Service >>> Name: gpsvc >>> displayname: Group Policy Client >>> Name: hidserv >>> displayname: Human Interface Device Access >>> Name: hpqcxs08 >>> displayname: hpqcxs08 >>> Name: hpqddsvc >>> displayname: HP CUE DeviceDiscovery Service >>> Name: HsfXAudioService >>> displayname: HsfXAudioService >>> Name: IAANTMON >>> displayname: Intel(R) Matrix Storage Event Monitor >>> Name: IKEEXT >>> displayname: IKE and AuthIP IPsec Keying Modules >>> Name: iphlpsvc >>> displayname: IP Helper >>> Name: iPod Service >>> displayname: iPod Service >>> Name: KeyIso >>> displayname: CNG Key Isolation >>> Name: KtmRm >>> displayname: KtmRm for Distributed Transaction Coordinator >>> Name: LanmanServer >>> displayname: Server >>> Name: LanmanWorkstation >>> displayname: Workstation >>> Name: Lavasoft Ad-Aware Service >>> displayname: Lavasoft Ad-Aware Service >>> Name: lmhosts >>> displayname: TCP/IP NetBIOS Helper >>> Name: McciCMService >>> displayname: McciCMService >>> Name: MMCSS >>> displayname: Multimedia Class Scheduler >>> Name: MpsSvc >>> displayname: Windows Firewall >>> Name: Net Driver HPZ12 >>> displayname: Net Driver HPZ12 >>> Name: Netman >>> displayname: Network Connections >>> Name: netprofm >>> displayname: Network List Service >>> Name: NlaSvc >>> displayname: Network Location Awareness >>> Name: nsi >>> displayname: Network Store Interface Service >>> Name: o2flash >>> displayname: O2Micro Flash Memory Card Service >>> Name: PcaSvc >>> displayname: Program Compatibility Assistant Service >>> Name: PlugPlay >>> displayname: Plug and Play >>> Name: Pml Driver HPZ12 >>> displayname: Pml Driver HPZ12 >>> Name: PolicyAgent >>> displayname: IPsec Policy Agent >>> Name: ProfSvc >>> displayname: User Profile Service >>> Name: RasMan >>> displayname: Remote Access Connection Manager >>> Name: RpcSs >>> displayname: Remote Procedure Call (RPC) >>> Name: SamSs >>> displayname: Security Accounts Manager >>> Name: Schedule >>> displayname: Task Scheduler >>> Name: SeaPort >>> displayname: SeaPort >>> Name: seclogon >>> displayname: Secondary Logon >>> Name: SENS >>> displayname: System Event Notification Service >>> Name: ShellHWDetection >>> displayname: Shell Hardware Detection >>> Name: slsvc >>> displayname: Software Licensing >>> Name: Spooler >>> displayname: Print Spooler >>> Name: SSDPSRV >>> displayname: SSDP Discovery >>> Name: SstpSvc >>> displayname: Secure Socket Tunneling Protocol Service >>> Name: stisvc >>> displayname: Windows Image Acquisition (WIA) >>> Name: SysMain >>> displayname: Superfetch >>> Name: TabletInputService >>> displayname: Tablet PC Input Service >>> Name: TapiSrv >>> displayname: Telephony >>> Name: TermService >>> displayname: Terminal Services >>> Name: Themes >>> displayname: Themes >>> Name: TrkWks >>> displayname: Distributed Link Tracking Client >>> Name: upnphost >>> displayname: UPnP Device Host >>> Name: UxSms >>> displayname: Desktop Window Manager Session Manager >>> Name: vToolbarUpdater >>> displayname: vToolbarUpdater >>> Name: W32Time >>> displayname: Windows Time >>> Name: WdiSystemHost >>> displayname: Diagnostic System Host >>> Name: WebClient >>> displayname: WebClient >>> Name: WerSvc >>> displayname: Windows Error Reporting Service >>> Name: Winmgmt >>> displayname: Windows Management Instrumentation >>> Name: Wlansvc >>> displayname: WLAN AutoConfig >>> Name: wlidsvc >>> displayname: Windows Live ID Sign-in Assistant >>> Name: WMPNetworkSvc >>> displayname: Windows Media Player Network Sharing Service >>> Name: WPDBusEnum >>> displayname: Portable Device Enumerator Service >>> Name: wscsvc >>> displayname: Security Center >>> Name: WSearch >>> displayname: Windows Search >>> Name: wuauserv >>> displayname: Windows Update >>> Name: wudfsvc >>> displayname: Windows Driver Foundation - User-mode Driver Framework >>> Name: XAudioService >>> displayname: XAudioService >>> >>>