Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Serious virus


  • Please log in to reply
14 replies to this topic

#1 jabbb

jabbb

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 06 April 2012 - 08:02 PM

Hi guys long time, but here I am again with my sore ass kicked by some hacker.
Ok so I was browsing some webpages, not worth to mention which ones, and all of a sudden I got this red screen in the background and on top a pop up of ie where it said something about virus and that I should go to homepage instead.
Couldn't get rid of it in any way so I restarted the pc, on log in the first thing that happens is this red screen on the background with the same ie pop up.

I tried to to do something on windows safe mode but no program worked or just didnt find it. For instance f-secure online scanner didn't find any virus.

Anywho I did some sort of factury settings because I'm working on asus notebook and now everything is more or less reinstalled, but I'd like to be sure that the virus is gone for good. Can you guys help me how to do this. Thanks

Jabbb

Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Animal

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:21 AM

Posted 06 April 2012 - 11:13 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)


Please download GMER from here(doesnot work on 64 bit OS)

http://www2.gmer.net/download.php

Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.

GMER will open to the Rootkit/Malware tab and perform an automatic Full Scan when first run. (do not use the computer while the scan is in progress)

If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
Now click the Scan button. If you see a rootkit warning window, click OK.
When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
Click the Copy button and paste the results into your next reply.


Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

#3 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 02:55 AM

Hi narenxp,
Thanks for the prompt reply, unfortunately I do have a 64bit OS. So what should I do about the GMER?

#4 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 03:00 AM

ok here's the TDSSkiller log:
0:51:50.0326 3940 TDSS rootkit removing tool 2.7.26.0 Apr 4 2012 19:52:02
10:51:50.0456 3940 ============================================================
10:51:50.0456 3940 Current date / time: 2012/04/07 10:51:50.0456
10:51:50.0456 3940 SystemInfo:
10:51:50.0456 3940
10:51:50.0456 3940 OS Version: 6.1.7601 ServicePack: 1.0
10:51:50.0456 3940 Product type: Workstation
10:51:50.0456 3940 ComputerName: BEAST-PC
10:51:50.0457 3940 UserName: beast
10:51:50.0457 3940 Windows directory: C:\Windows
10:51:50.0457 3940 System windows directory: C:\Windows
10:51:50.0457 3940 Running under WOW64
10:51:50.0457 3940 Processor architecture: Intel x64
10:51:50.0457 3940 Number of processors: 8
10:51:50.0457 3940 Page size: 0x1000
10:51:50.0457 3940 Boot type: Normal boot
10:51:50.0457 3940 ============================================================
10:51:50.0835 3940 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:51:50.0850 3940 \Device\Harddisk0\DR0:
10:51:50.0850 3940 MBR used
10:51:50.0850 3940 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3200800, BlocksNum 0x186B5000
10:51:50.0881 3940 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B8B6000, BlocksNum 0x1EACF800
10:51:50.0944 3940 Initialize success
10:51:50.0944 3940 ============================================================
10:53:13.0195 5332 ============================================================
10:53:13.0195 5332 Scan started
10:53:13.0195 5332 Mode: Manual; TDLFS;
10:53:13.0195 5332 ============================================================
10:53:13.0912 5332 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
10:53:13.0928 5332 1394ohci - ok
10:53:14.0224 5332 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
10:53:14.0240 5332 ACPI - ok
10:53:14.0536 5332 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
10:53:14.0536 5332 AcpiPmi - ok
10:53:14.0848 5332 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
10:53:14.0864 5332 adp94xx - ok
10:53:15.0160 5332 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
10:53:15.0176 5332 adpahci - ok
10:53:15.0472 5332 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
10:53:15.0488 5332 adpu320 - ok
10:53:15.0691 5332 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
10:53:15.0706 5332 AeLookupSvc - ok
10:53:16.0003 5332 AFD (d31dc7a16dea4a9baf179f3d6fbdb38c) C:\Windows\system32\drivers\afd.sys
10:53:16.0018 5332 AFD - ok
10:53:16.0330 5332 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
10:53:16.0330 5332 agp440 - ok
10:53:16.0627 5332 AiCharger (14370049d8c9912eac7603809a77c378) C:\Windows\system32\DRIVERS\AiCharger.sys
10:53:16.0627 5332 AiCharger - ok
10:53:16.0861 5332 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
10:53:16.0861 5332 ALG - ok
10:53:17.0157 5332 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
10:53:17.0157 5332 aliide - ok
10:53:17.0453 5332 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
10:53:17.0453 5332 amdide - ok
10:53:17.0765 5332 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
10:53:17.0765 5332 AmdK8 - ok
10:53:18.0062 5332 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
10:53:18.0077 5332 AmdPPM - ok
10:53:18.0374 5332 amdsata (6ec6d772eae38dc17c14aed9b178d24b) C:\Windows\system32\drivers\amdsata.sys
10:53:18.0374 5332 amdsata - ok
10:53:18.0686 5332 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
10:53:18.0686 5332 amdsbs - ok
10:53:18.0982 5332 amdxata (1142a21db581a84ea5597b03a26ebaa0) C:\Windows\system32\drivers\amdxata.sys
10:53:18.0982 5332 amdxata - ok
10:53:19.0091 5332 Amsp (e8494519bcb9e3b1b72e5604993a76e3) C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe
10:53:19.0107 5332 Amsp - ok
10:53:19.0419 5332 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
10:53:19.0419 5332 AppID - ok
10:53:19.0637 5332 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
10:53:19.0637 5332 AppIDSvc - ok
10:53:19.0856 5332 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
10:53:19.0856 5332 Appinfo - ok
10:53:20.0168 5332 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
10:53:20.0168 5332 arc - ok
10:53:20.0464 5332 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
10:53:20.0464 5332 arcsas - ok
10:53:20.0542 5332 ASLDRService (18e5c2f937f9deb8c282df66a3761925) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
10:53:20.0558 5332 ASLDRService - ok
10:53:20.0558 5332 ASMMAP64 (4c016fd76ed5c05e84ca8cab77993961) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys
10:53:20.0558 5332 ASMMAP64 - ok
10:53:20.0620 5332 AsusUacSvc (b6ef28ecee73b624d56df30ad562ae8d) C:\Program Files\Asus\Rotation Desktop for G Series\AsusUacSvc.exe
10:53:20.0636 5332 AsusUacSvc - ok
10:53:20.0932 5332 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
10:53:20.0932 5332 AsyncMac - ok
10:53:21.0229 5332 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
10:53:21.0229 5332 atapi - ok
10:53:21.0525 5332 AthBTPort (cbe61b4494165f458bd87e37181ee934) C:\Windows\system32\DRIVERS\btath_flt.sys
10:53:21.0541 5332 AthBTPort - ok
10:53:21.0619 5332 Atheros Bt&Wlan Coex Agent (4c4a576818ea028257c624ae36ff7a03) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
10:53:21.0634 5332 Atheros Bt&Wlan Coex Agent - ok
10:53:21.0650 5332 AtherosSvc (21753130331188c4b474e1d3b396e629) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
10:53:21.0650 5332 AtherosSvc - ok
10:53:22.0009 5332 athr (de8b9c3e0e09d918b394207f34ac16dd) C:\Windows\system32\DRIVERS\athrx.sys
10:53:22.0055 5332 athr - ok
10:53:22.0118 5332 ATKGFNEXSrv (7910158929571214a959d5a6d16dd9c0) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
10:53:22.0133 5332 ATKGFNEXSrv - ok
10:53:22.0165 5332 ATKWMIACPIIO (1f7238a37389ed92e9d8eee975cabd54) C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys
10:53:22.0165 5332 ATKWMIACPIIO - ok
10:53:22.0399 5332 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
10:53:22.0414 5332 AudioEndpointBuilder - ok
10:53:22.0430 5332 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
10:53:22.0445 5332 AudioSrv - ok
10:53:22.0679 5332 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
10:53:22.0679 5332 AxInstSV - ok
10:53:22.0991 5332 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
10:53:23.0007 5332 b06bdrv - ok
10:53:23.0303 5332 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
10:53:23.0319 5332 b57nd60a - ok
10:53:23.0381 5332 BBSvc (93ee7d9c35ae7e9ffda148d7805f1421) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
10:53:23.0381 5332 BBSvc - ok
10:53:23.0600 5332 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
10:53:23.0600 5332 BDESVC - ok
10:53:23.0912 5332 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
10:53:23.0912 5332 Beep - ok
10:53:24.0146 5332 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
10:53:24.0177 5332 BFE - ok
10:53:24.0411 5332 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
10:53:24.0442 5332 BITS - ok
10:53:24.0739 5332 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
10:53:24.0754 5332 blbdrive - ok
10:53:25.0035 5332 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
10:53:25.0051 5332 bowser - ok
10:53:25.0394 5332 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
10:53:25.0394 5332 BrFiltLo - ok
10:53:25.0721 5332 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
10:53:25.0721 5332 BrFiltUp - ok
10:53:25.0987 5332 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
10:53:25.0987 5332 Browser - ok
10:53:26.0330 5332 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
10:53:26.0345 5332 Brserid - ok
10:53:26.0689 5332 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
10:53:26.0689 5332 BrSerWdm - ok
10:53:27.0094 5332 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
10:53:27.0110 5332 BrUsbMdm - ok
10:53:27.0437 5332 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
10:53:27.0437 5332 BrUsbSer - ok
10:53:27.0781 5332 BTATH_A2DP (fe70889a85c57a9268101b2db0474509) C:\Windows\system32\drivers\btath_a2dp.sys
10:53:27.0796 5332 BTATH_A2DP - ok
10:53:28.0139 5332 BTATH_BUS (a83a91d07d1fe6bbe7a9db46ca00434b) C:\Windows\system32\DRIVERS\btath_bus.sys
10:53:28.0139 5332 BTATH_BUS - ok
10:53:28.0467 5332 BTATH_HCRP (c864ff85ee16d61c2bdd5ef76824625f) C:\Windows\system32\DRIVERS\btath_hcrp.sys
10:53:28.0467 5332 BTATH_HCRP - ok
10:53:28.0810 5332 BTATH_LWFLT (0dea505efb5d771826d177ef8b8a208f) C:\Windows\system32\DRIVERS\btath_lwflt.sys
10:53:28.0810 5332 BTATH_LWFLT - ok
10:53:29.0138 5332 BTATH_RCP (724c8088c96efe7a3e63fec21d4681c0) C:\Windows\system32\DRIVERS\btath_rcp.sys
10:53:29.0153 5332 BTATH_RCP - ok
10:53:29.0481 5332 BtFilter (aa0f5afcf077c5246589b32eceeae566) C:\Windows\system32\DRIVERS\btfilter.sys
10:53:29.0481 5332 BtFilter - ok
10:53:29.0793 5332 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
10:53:29.0793 5332 BthEnum - ok
10:53:30.0121 5332 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
10:53:30.0121 5332 BTHMODEM - ok
10:53:30.0448 5332 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
10:53:30.0448 5332 BthPan - ok
10:53:30.0807 5332 BTHPORT (0d25b6d300ba26a5f2c3b2a8e96b158b) C:\Windows\system32\Drivers\BTHport.sys
10:53:30.0823 5332 BTHPORT - ok
10:53:31.0072 5332 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
10:53:31.0088 5332 bthserv - ok
10:53:31.0353 5332 BTHUSB (1f9912f8ec5bfa53432e71e150636a8a) C:\Windows\system32\Drivers\BTHUSB.sys
10:53:31.0369 5332 BTHUSB - ok
10:53:31.0712 5332 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
10:53:31.0712 5332 cdfs - ok
10:53:32.0039 5332 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
10:53:32.0039 5332 cdrom - ok
10:53:32.0258 5332 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
10:53:32.0273 5332 CertPropSvc - ok
10:53:32.0570 5332 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
10:53:32.0570 5332 circlass - ok
10:53:32.0788 5332 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
10:53:32.0804 5332 CLFS - ok
10:53:32.0960 5332 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:53:32.0960 5332 clr_optimization_v2.0.50727_32 - ok
10:53:33.0053 5332 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:53:33.0053 5332 clr_optimization_v2.0.50727_64 - ok
10:53:33.0287 5332 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
10:53:33.0287 5332 CmBatt - ok
10:53:33.0568 5332 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
10:53:33.0584 5332 cmdide - ok
10:53:33.0896 5332 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
10:53:33.0896 5332 CNG - ok
10:53:34.0208 5332 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
10:53:34.0208 5332 Compbatt - ok
10:53:34.0504 5332 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
10:53:34.0504 5332 CompositeBus - ok
10:53:34.0691 5332 COMSysApp - ok
10:53:34.0972 5332 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
10:53:34.0988 5332 crcdisk - ok
10:53:35.0050 5332 Creative ALchemy AL6 Licensing Service (c8bd651e13895b93ed9ec5b4f1df42bc) C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
10:53:35.0050 5332 Creative ALchemy AL6 Licensing Service - ok
10:53:35.0081 5332 Creative Audio Engine Licensing Service (c0ead9f8ab83d41ff07303c75589c2b8) C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
10:53:35.0097 5332 Creative Audio Engine Licensing Service - ok
10:53:35.0331 5332 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
10:53:35.0331 5332 CryptSvc - ok
10:53:35.0565 5332 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
10:53:35.0581 5332 DcomLaunch - ok
10:53:35.0799 5332 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
10:53:35.0815 5332 defragsvc - ok
10:53:36.0095 5332 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
10:53:36.0095 5332 DfsC - ok
10:53:36.0329 5332 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
10:53:36.0345 5332 Dhcp - ok
10:53:36.0626 5332 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
10:53:36.0626 5332 discache - ok
10:53:36.0985 5332 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
10:53:36.0985 5332 Disk - ok
10:53:37.0187 5332 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
10:53:37.0203 5332 Dnscache - ok
10:53:37.0406 5332 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
10:53:37.0406 5332 dot3svc - ok
10:53:37.0593 5332 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
10:53:37.0609 5332 DPS - ok
10:53:37.0889 5332 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
10:53:37.0889 5332 drmkaud - ok
10:53:38.0170 5332 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
10:53:38.0186 5332 DXGKrnl - ok
10:53:38.0373 5332 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
10:53:38.0389 5332 EapHost - ok
10:53:38.0732 5332 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
10:53:38.0919 5332 ebdrv - ok
10:53:39.0122 5332 EFS (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\System32\lsass.exe
10:53:39.0137 5332 EFS - ok
10:53:39.0278 5332 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
10:53:39.0293 5332 ehRecvr - ok
10:53:39.0309 5332 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
10:53:39.0325 5332 ehSched - ok
10:53:39.0574 5332 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
10:53:39.0590 5332 elxstor - ok
10:53:39.0839 5332 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
10:53:39.0839 5332 ErrDev - ok
10:53:40.0073 5332 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
10:53:40.0073 5332 EventSystem - ok
10:53:40.0370 5332 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
10:53:40.0370 5332 exfat - ok
10:53:40.0651 5332 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
10:53:40.0651 5332 fastfat - ok
10:53:40.0869 5332 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
10:53:40.0885 5332 Fax - ok
10:53:41.0165 5332 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
10:53:41.0165 5332 fdc - ok
10:53:41.0384 5332 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
10:53:41.0384 5332 fdPHost - ok
10:53:41.0555 5332 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
10:53:41.0571 5332 FDResPub - ok
10:53:41.0867 5332 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
10:53:41.0867 5332 FileInfo - ok
10:53:42.0148 5332 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
10:53:42.0164 5332 Filetrace - ok
10:53:42.0445 5332 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
10:53:42.0445 5332 flpydisk - ok
10:53:42.0710 5332 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
10:53:42.0725 5332 FltMgr - ok
10:53:43.0022 5332 FLxHCIc (7de8a770487fc4b5e3a168ad97e1d370) C:\Windows\system32\DRIVERS\FLxHCIc.sys
10:53:43.0022 5332 FLxHCIc - ok
10:53:43.0303 5332 FLxHCIh (2d54a3319fc955029e4b371cdc088ff4) C:\Windows\system32\DRIVERS\FLxHCIh.sys
10:53:43.0303 5332 FLxHCIh - ok
10:53:43.0521 5332 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
10:53:43.0552 5332 FontCache - ok
10:53:43.0661 5332 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:53:43.0661 5332 FontCache3.0.0.0 - ok
10:53:43.0880 5332 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
10:53:43.0895 5332 FsDepends - ok
10:53:44.0176 5332 fspad_win764 (3dfa8d4e50d608f8f732014614c84dd2) C:\Windows\system32\DRIVERS\fspad_win764.sys
10:53:44.0176 5332 fspad_win764 - ok
10:53:44.0473 5332 fssfltr (07da62c960ddccc2d35836aeab4fc578) C:\Windows\system32\DRIVERS\fssfltr.sys
10:53:44.0473 5332 fssfltr - ok
10:53:44.0582 5332 fsssvc (28ddeeec44e988657b732cf404d504cb) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
10:53:44.0629 5332 fsssvc - ok
10:53:44.0894 5332 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
10:53:44.0894 5332 Fs_Rec - ok
10:53:45.0190 5332 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
10:53:45.0190 5332 fvevol - ok
10:53:45.0471 5332 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
10:53:45.0471 5332 gagp30kx - ok
10:53:45.0689 5332 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
10:53:45.0721 5332 gpsvc - ok
10:53:45.0783 5332 gupdate (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:53:45.0783 5332 gupdate - ok
10:53:45.0799 5332 gupdatem (8f0de4fef8201e306f9938b0905ac96a) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:53:45.0799 5332 gupdatem - ok
10:53:45.0830 5332 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
10:53:45.0845 5332 gusvc - ok
10:53:46.0189 5332 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
10:53:46.0189 5332 hcw85cir - ok
10:53:46.0516 5332 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
10:53:46.0516 5332 HdAudAddService - ok
10:53:46.0844 5332 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
10:53:46.0844 5332 HDAudBus - ok
10:53:47.0156 5332 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
10:53:47.0156 5332 HidBatt - ok
10:53:47.0452 5332 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
10:53:47.0452 5332 HidBth - ok
10:53:47.0764 5332 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
10:53:47.0764 5332 HidIr - ok
10:53:47.0983 5332 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
10:53:47.0983 5332 hidserv - ok
10:53:48.0310 5332 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
10:53:48.0310 5332 HidUsb - ok
10:53:48.0513 5332 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
10:53:48.0529 5332 hkmsvc - ok
10:53:48.0747 5332 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
10:53:48.0763 5332 HomeGroupListener - ok
10:53:48.0965 5332 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
10:53:48.0981 5332 HomeGroupProvider - ok
10:53:49.0262 5332 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
10:53:49.0262 5332 HpSAMD - ok
10:53:49.0543 5332 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
10:53:49.0574 5332 HTTP - ok
10:53:49.0870 5332 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
10:53:49.0870 5332 hwpolicy - ok
10:53:50.0135 5332 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
10:53:50.0135 5332 i8042prt - ok
10:53:50.0432 5332 iaStor (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\DRIVERS\iaStor.sys
10:53:50.0432 5332 iaStor - ok
10:53:50.0744 5332 iaStorV (3df4395a7cf8b7a72a5f4606366b8c2d) C:\Windows\system32\drivers\iaStorV.sys
10:53:50.0759 5332 iaStorV - ok
10:53:50.0900 5332 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:53:50.0931 5332 idsvc - ok
10:53:51.0181 5332 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
10:53:51.0181 5332 iirsp - ok
10:53:51.0383 5332 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
10:53:51.0430 5332 IKEEXT - ok
10:53:51.0805 5332 IntcAzAudAddService (7d24e44761ee029680bd8da23fab8fb4) C:\Windows\system32\drivers\RTKVHD64.sys
10:53:51.0820 5332 IntcAzAudAddService - ok
10:53:52.0114 5332 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
10:53:52.0116 5332 intelide - ok
10:53:52.0365 5332 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
10:53:52.0381 5332 intelppm - ok
10:53:52.0583 5332 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
10:53:52.0583 5332 IPBusEnum - ok
10:53:52.0880 5332 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:53:52.0880 5332 IpFilterDriver - ok
10:53:53.0093 5332 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
10:53:53.0107 5332 iphlpsvc - ok
10:53:53.0385 5332 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
10:53:53.0385 5332 IPMIDRV - ok
10:53:53.0650 5332 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
10:53:53.0650 5332 IPNAT - ok
10:53:53.0931 5332 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
10:53:53.0931 5332 IRENUM - ok
10:53:54.0212 5332 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
10:53:54.0212 5332 isapnp - ok
10:53:54.0492 5332 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
10:53:54.0492 5332 iScsiPrt - ok
10:53:54.0758 5332 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
10:53:54.0773 5332 kbdclass - ok
10:53:55.0023 5332 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
10:53:55.0038 5332 kbdhid - ok
10:53:55.0350 5332 kbfiltr (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
10:53:55.0350 5332 kbfiltr - ok
10:53:55.0553 5332 KeyIso (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
10:53:55.0553 5332 KeyIso - ok
10:53:55.0850 5332 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
10:53:55.0850 5332 KSecDD - ok
10:53:56.0099 5332 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
10:53:56.0115 5332 KSecPkg - ok
10:53:56.0364 5332 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
10:53:56.0364 5332 ksthunk - ok
10:53:56.0567 5332 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
10:53:56.0583 5332 KtmRm - ok
10:53:56.0864 5332 L1C (033b4aed2c5519072c0d81e00804d003) C:\Windows\system32\DRIVERS\L1C62x64.sys
10:53:56.0864 5332 L1C - ok
10:53:57.0082 5332 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
10:53:57.0098 5332 LanmanServer - ok
10:53:57.0300 5332 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
10:53:57.0316 5332 LanmanWorkstation - ok
10:53:57.0597 5332 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
10:53:57.0597 5332 lltdio - ok
10:53:57.0800 5332 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
10:53:57.0815 5332 lltdsvc - ok
10:53:58.0034 5332 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
10:53:58.0034 5332 lmhosts - ok
10:53:58.0112 5332 LMS (0803906d607a9b83184447b75b60ecc2) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
10:53:58.0127 5332 LMS - ok
10:53:58.0424 5332 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
10:53:58.0424 5332 LSI_FC - ok
10:53:58.0704 5332 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
10:53:58.0720 5332 LSI_SAS - ok
10:53:59.0001 5332 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
10:53:59.0001 5332 LSI_SAS2 - ok
10:53:59.0282 5332 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
10:53:59.0282 5332 LSI_SCSI - ok
10:53:59.0562 5332 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
10:53:59.0562 5332 luafv - ok
10:53:59.0874 5332 MBfilt (8ff2d95cba49b405c5de27039ff0bf35) C:\Windows\system32\drivers\MBfilt64.sys
10:53:59.0890 5332 MBfilt - ok
10:54:00.0093 5332 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
10:54:00.0108 5332 Mcx2Svc - ok
10:54:00.0374 5332 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
10:54:00.0374 5332 megasas - ok
10:54:00.0639 5332 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
10:54:00.0639 5332 MegaSR - ok
10:54:00.0920 5332 MEIx64 (1c6e73fc46b509eff9d0086aa37132df) C:\Windows\system32\DRIVERS\HECIx64.sys
10:54:00.0920 5332 MEIx64 - ok
10:54:01.0138 5332 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
10:54:01.0138 5332 MMCSS - ok
10:54:01.0388 5332 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
10:54:01.0388 5332 Modem - ok
10:54:01.0668 5332 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
10:54:01.0668 5332 monitor - ok
10:54:01.0965 5332 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
10:54:01.0965 5332 mouclass - ok
10:54:02.0261 5332 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
10:54:02.0261 5332 mouhid - ok
10:54:02.0526 5332 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
10:54:02.0542 5332 mountmgr - ok
10:54:02.0792 5332 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
10:54:02.0807 5332 mpio - ok
10:54:03.0072 5332 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
10:54:03.0072 5332 mpsdrv - ok
10:54:03.0291 5332 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
10:54:03.0322 5332 MpsSvc - ok
10:54:03.0587 5332 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
10:54:03.0603 5332 MRxDAV - ok
10:54:03.0868 5332 mrxsmb (c2b4651001a867ff3f8865863b592991) C:\Windows\system32\DRIVERS\mrxsmb.sys
10:54:03.0884 5332 mrxsmb - ok
10:54:04.0149 5332 mrxsmb10 (7e79946afc5f799ab62982282be5ac13) C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:54:04.0149 5332 mrxsmb10 - ok
10:54:04.0430 5332 mrxsmb20 (5fb954100cea2bfec6446fbbecaa3f79) C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:54:04.0430 5332 mrxsmb20 - ok
10:54:04.0695 5332 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
10:54:04.0695 5332 msahci - ok
10:54:04.0960 5332 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
10:54:04.0960 5332 msdsm - ok
10:54:05.0163 5332 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
10:54:05.0163 5332 MSDTC - ok
10:54:05.0428 5332 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
10:54:05.0428 5332 Msfs - ok
10:54:05.0693 5332 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
10:54:05.0693 5332 mshidkmdf - ok
10:54:05.0974 5332 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
10:54:05.0974 5332 msisadrv - ok
10:54:06.0192 5332 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
10:54:06.0192 5332 MSiSCSI - ok
10:54:06.0364 5332 msiserver - ok
10:54:06.0645 5332 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
10:54:06.0645 5332 MSKSSRV - ok
10:54:06.0926 5332 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
10:54:06.0926 5332 MSPCLOCK - ok
10:54:07.0209 5332 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
10:54:07.0211 5332 MSPQM - ok
10:54:07.0479 5332 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
10:54:07.0479 5332 MsRPC - ok
10:54:07.0790 5332 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
10:54:07.0792 5332 mssmbios - ok
10:54:08.0129 5332 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
10:54:08.0133 5332 MSTEE - ok
10:54:08.0386 5332 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
10:54:08.0386 5332 MTConfig - ok
10:54:08.0636 5332 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
10:54:08.0651 5332 Mup - ok
10:54:08.0839 5332 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
10:54:08.0854 5332 napagent - ok
10:54:09.0160 5332 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
10:54:09.0170 5332 NativeWifiP - ok
10:54:09.0530 5332 NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
10:54:09.0608 5332 NDIS - ok
10:54:09.0889 5332 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
10:54:09.0889 5332 NdisCap - ok
10:54:10.0164 5332 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
10:54:10.0166 5332 NdisTapi - ok
10:54:10.0422 5332 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
10:54:10.0438 5332 Ndisuio - ok
10:54:10.0703 5332 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
10:54:10.0703 5332 NdisWan - ok
10:54:10.0984 5332 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
10:54:10.0984 5332 NDProxy - ok
10:54:11.0273 5332 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
10:54:11.0276 5332 NetBIOS - ok
10:54:11.0534 5332 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
10:54:11.0534 5332 NetBT - ok
10:54:11.0737 5332 Netlogon (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
10:54:11.0737 5332 Netlogon - ok
10:54:11.0956 5332 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
10:54:11.0971 5332 Netman - ok
10:54:12.0174 5332 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
10:54:12.0190 5332 netprofm - ok
10:54:12.0314 5332 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:54:12.0314 5332 NetTcpPortSharing - ok
10:54:12.0548 5332 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
10:54:12.0564 5332 nfrd960 - ok
10:54:12.0767 5332 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
10:54:12.0782 5332 NlaSvc - ok
10:54:13.0063 5332 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
10:54:13.0063 5332 Npfs - ok
10:54:13.0266 5332 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
10:54:13.0266 5332 nsi - ok
10:54:13.0516 5332 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
10:54:13.0516 5332 nsiproxy - ok
10:54:13.0828 5332 Ntfs (05d78aa5cb5f3f5c31160bdb955d0b7c) C:\Windows\system32\drivers\Ntfs.sys
10:54:13.0874 5332 Ntfs - ok
10:54:14.0140 5332 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
10:54:14.0140 5332 Null - ok
10:54:14.0436 5332 NVHDA (f2662fdc20518ee8a8eed4f61ba42349) C:\Windows\system32\drivers\nvhda64v.sys
10:54:14.0452 5332 NVHDA - ok
10:54:14.0966 5332 nvlddmkm (b6d7d3ebb1401b04b48f40c3d0ce5b09) C:\Windows\system32\DRIVERS\nvlddmkm.sys
10:54:15.0029 5332 nvlddmkm - ok
10:54:15.0327 5332 nvraid (5d9fd91f3d38dc9da01e3cb5fa89cd48) C:\Windows\system32\drivers\nvraid.sys
10:54:15.0334 5332 nvraid - ok
10:54:15.0609 5332 nvstor (f7cd50fe7139f07e77da8ac8033d1832) C:\Windows\system32\drivers\nvstor.sys
10:54:15.0609 5332 nvstor - ok
10:54:15.0858 5332 NVSvc (1c594d199180864cbea5fa0b0b55287a) C:\Windows\system32\nvvsvc.exe
10:54:15.0890 5332 NVSvc - ok
10:54:16.0170 5332 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
10:54:16.0175 5332 nv_agp - ok
10:54:16.0425 5332 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
10:54:16.0440 5332 ohci1394 - ok
10:54:16.0628 5332 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
10:54:16.0643 5332 p2pimsvc - ok
10:54:16.0846 5332 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
10:54:16.0862 5332 p2psvc - ok
10:54:17.0127 5332 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
10:54:17.0127 5332 Parport - ok
10:54:17.0392 5332 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
10:54:17.0392 5332 partmgr - ok
10:54:17.0470 5332 Partner Service (9665402b7fa59302d520ad845ddfc026) C:\ProgramData\Partner\Partner.exe
10:54:17.0486 5332 Partner Service - ok
10:54:17.0688 5332 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
10:54:17.0704 5332 PcaSvc - ok
10:54:17.0969 5332 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
10:54:17.0985 5332 pci - ok
10:54:18.0266 5332 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
10:54:18.0266 5332 pciide - ok
10:54:18.0515 5332 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
10:54:18.0515 5332 pcmcia - ok
10:54:18.0780 5332 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
10:54:18.0780 5332 pcw - ok
10:54:19.0061 5332 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
10:54:19.0077 5332 PEAUTH - ok
10:54:19.0301 5332 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
10:54:19.0305 5332 PerfHost - ok
10:54:19.0527 5332 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
10:54:19.0574 5332 pla - ok
10:54:19.0793 5332 PlugPlay (b806e50427511bcf4ad8e8239c3e25fa) C:\Windows\system32\umpnpmgr.dll
10:54:19.0808 5332 PlugPlay - ok
10:54:20.0011 5332 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
10:54:20.0011 5332 PNRPAutoReg - ok
10:54:20.0229 5332 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
10:54:20.0229 5332 PNRPsvc - ok
10:54:20.0448 5332 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
10:54:20.0463 5332 PolicyAgent - ok
10:54:20.0697 5332 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
10:54:20.0697 5332 Power - ok
10:54:20.0978 5332 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
10:54:20.0994 5332 PptpMiniport - ok
10:54:21.0243 5332 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
10:54:21.0243 5332 Processor - ok
10:54:21.0462 5332 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
10:54:21.0477 5332 ProfSvc - ok
10:54:21.0665 5332 ProtectedStorage (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
10:54:21.0680 5332 ProtectedStorage - ok
10:54:21.0945 5332 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
10:54:21.0945 5332 Psched - ok
10:54:22.0289 5332 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
10:54:22.0289 5332 PxHlpa64 - ok
10:54:22.0569 5332 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
10:54:22.0616 5332 ql2300 - ok
10:54:22.0897 5332 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
10:54:22.0897 5332 ql40xx - ok
10:54:23.0100 5332 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
10:54:23.0115 5332 QWAVE - ok
10:54:23.0381 5332 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
10:54:23.0381 5332 QWAVEdrv - ok
10:54:23.0630 5332 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
10:54:23.0646 5332 RasAcd - ok
10:54:23.0927 5332 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
10:54:23.0927 5332 RasAgileVpn - ok
10:54:24.0114 5332 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
10:54:24.0129 5332 RasAuto - ok
10:54:24.0395 5332 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
10:54:24.0395 5332 Rasl2tp - ok
10:54:24.0613 5332 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
10:54:24.0629 5332 RasMan - ok
10:54:24.0894 5332 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
10:54:24.0894 5332 RasPppoe - ok
10:54:25.0175 5332 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
10:54:25.0175 5332 RasSstp - ok
10:54:25.0424 5332 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
10:54:25.0424 5332 rdbss - ok
10:54:25.0689 5332 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
10:54:25.0689 5332 rdpbus - ok
10:54:25.0939 5332 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
10:54:25.0955 5332 RDPCDD - ok
10:54:26.0220 5332 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
10:54:26.0220 5332 RDPENCDD - ok
10:54:26.0485 5332 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
10:54:26.0485 5332 RDPREFMP - ok
10:54:26.0766 5332 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
10:54:26.0766 5332 RDPWD - ok
10:54:27.0047 5332 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
10:54:27.0047 5332 rdyboost - ok
10:54:27.0249 5332 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
10:54:27.0249 5332 RemoteAccess - ok
10:54:27.0468 5332 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
10:54:27.0468 5332 RemoteRegistry - ok
10:54:27.0749 5332 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
10:54:27.0749 5332 RFCOMM - ok
10:54:27.0936 5332 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
10:54:27.0951 5332 RpcEptMapper - ok
10:54:28.0154 5332 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
10:54:28.0170 5332 RpcLocator - ok
10:54:28.0373 5332 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
10:54:28.0373 5332 RpcSs - ok
10:54:28.0653 5332 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
10:54:28.0653 5332 rspndr - ok
10:54:28.0950 5332 RSUSBVSTOR (e57fac2cdb73f06586ed2ed310b80932) C:\Windows\system32\Drivers\RtsUVStor.sys
10:54:28.0965 5332 RSUSBVSTOR - ok
10:54:29.0231 5332 RTL8167 (f4c374b1c46de294b573bb43723ac3f6) C:\Windows\system32\DRIVERS\Rt64win7.sys
10:54:29.0246 5332 RTL8167 - ok
10:54:29.0449 5332 SamSs (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
10:54:29.0449 5332 SamSs - ok
10:54:29.0730 5332 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
10:54:29.0730 5332 sbp2port - ok
10:54:29.0933 5332 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
10:54:29.0933 5332 SCardSvr - ok
10:54:30.0198 5332 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
10:54:30.0198 5332 scfilter - ok
10:54:30.0416 5332 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
10:54:30.0463 5332 Schedule - ok
10:54:30.0666 5332 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
10:54:30.0666 5332 SCPolicySvc - ok
10:54:30.0884 5332 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
10:54:30.0884 5332 SDRSVC - ok
10:54:30.0947 5332 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
10:54:30.0962 5332 SeaPort - ok
10:54:31.0227 5332 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
10:54:31.0227 5332 secdrv - ok
10:54:31.0430 5332 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
10:54:31.0430 5332 seclogon - ok
10:54:31.0636 5332 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
10:54:31.0641 5332 SENS - ok
10:54:31.0842 5332 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
10:54:31.0842 5332 SensrSvc - ok
10:54:32.0107 5332 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
10:54:32.0123 5332 Serenum - ok
10:54:32.0386 5332 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
10:54:32.0392 5332 Serial - ok
10:54:32.0646 5332 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
10:54:32.0646 5332 sermouse - ok
10:54:32.0849 5332 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
10:54:32.0865 5332 SessionEnv - ok
10:54:33.0114 5332 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
10:54:33.0114 5332 sffdisk - ok
10:54:33.0374 5332 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
10:54:33.0378 5332 sffp_mmc - ok
10:54:33.0633 5332 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
10:54:33.0633 5332 sffp_sd - ok
10:54:33.0898 5332 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
10:54:33.0914 5332 sfloppy - ok
10:54:34.0117 5332 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
10:54:34.0117 5332 SharedAccess - ok
10:54:34.0351 5332 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
10:54:34.0351 5332 ShellHWDetection - ok
10:54:34.0631 5332 SiSGbeLH (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
10:54:34.0647 5332 SiSGbeLH - ok
10:54:34.0928 5332 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
10:54:34.0928 5332 SiSRaid2 - ok
10:54:35.0177 5332 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
10:54:35.0193 5332 SiSRaid4 - ok
10:54:35.0443 5332 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
10:54:35.0458 5332 Smb - ok
10:54:35.0661 5332 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
10:54:35.0677 5332 SNMPTRAP - ok
10:54:35.0911 5332 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
10:54:35.0926 5332 spldr - ok
10:54:36.0129 5332 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
10:54:36.0145 5332 Spooler - ok
10:54:36.0425 5332 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
10:54:36.0519 5332 sppsvc - ok
10:54:36.0706 5332 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
10:54:36.0722 5332 sppuinotify - ok
10:54:36.0971 5332 srv (65bbf4920148c2ee279055da7228fc7b) C:\Windows\system32\DRIVERS\srv.sys
10:54:36.0987 5332 srv - ok
10:54:37.0283 5332 srv2 (da939f762a1ccc2d77428621ddbd40a7) C:\Windows\system32\DRIVERS\srv2.sys
10:54:37.0283 5332 srv2 - ok
10:54:37.0564 5332 srvnet (3f847c9dc87299516f7dc82fb6572865) C:\Windows\system32\DRIVERS\srvnet.sys
10:54:37.0564 5332 srvnet - ok
10:54:37.0783 5332 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
10:54:37.0783 5332 SSDPSRV - ok
10:54:37.0970 5332 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
10:54:37.0970 5332 SstpSvc - ok
10:54:38.0032 5332 Stereo Service (1d26267eb061652a0419698e7cf06d72) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
10:54:38.0048 5332 Stereo Service - ok
10:54:38.0422 5332 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
10:54:38.0422 5332 stexstor - ok
10:54:38.0641 5332 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
10:54:38.0656 5332 stisvc - ok
10:54:38.0921 5332 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
10:54:38.0921 5332 swenum - ok
10:54:39.0124 5332 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
10:54:39.0140 5332 swprv - ok
10:54:39.0374 5332 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
10:54:39.0405 5332 SysMain - ok
10:54:39.0608 5332 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
10:54:39.0608 5332 TabletInputService - ok
10:54:39.0811 5332 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
10:54:39.0826 5332 TapiSrv - ok
10:54:40.0013 5332 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
10:54:40.0029 5332 TBS - ok
10:54:40.0341 5332 Tcpip (509383e505c973ed7534a06b3d19688d) C:\Windows\system32\drivers\tcpip.sys
10:54:40.0372 5332 Tcpip - ok
10:54:40.0700 5332 TCPIP6 (509383e505c973ed7534a06b3d19688d) C:\Windows\system32\DRIVERS\tcpip.sys
10:54:40.0731 5332 TCPIP6 - ok
10:54:40.0996 5332 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
10:54:40.0996 5332 tcpipreg - ok
10:54:41.0293 5332 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
10:54:41.0293 5332 TDPIPE - ok
10:54:41.0542 5332 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
10:54:41.0558 5332 TDTCP - ok
10:54:41.0839 5332 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
10:54:41.0839 5332 tdx - ok
10:54:42.0119 5332 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
10:54:42.0119 5332 TermDD - ok
10:54:42.0338 5332 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
10:54:42.0353 5332 TermService - ok
10:54:42.0556 5332 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
10:54:42.0572 5332 Themes - ok
10:54:42.0775 5332 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
10:54:42.0775 5332 THREADORDER - ok
10:54:42.0853 5332 TiMiniService (69d76ce06bb629b69165c81d83a4b03e) C:\Program Files\Trend Micro\Titanium\TiMiniService.exe
10:54:42.0853 5332 TiMiniService - ok
10:54:43.0133 5332 tmactmon (73aaffdd2ac3c8814b26c440e5dd9dd4) C:\Windows\system32\DRIVERS\tmactmon.sys
10:54:43.0133 5332 tmactmon - ok
10:54:43.0414 5332 tmcomm (360e61217d4e1e333583d0c721057f70) C:\Windows\system32\DRIVERS\tmcomm.sys
10:54:43.0414 5332 tmcomm - ok
10:54:43.0695 5332 tmevtmgr (699d34eb7c670139ca23a65372bd5743) C:\Windows\system32\DRIVERS\tmevtmgr.sys
10:54:43.0695 5332 tmevtmgr - ok
10:54:43.0991 5332 tmtdi (262198efb734012bfcd17e7479ae4a09) C:\Windows\system32\DRIVERS\tmtdi.sys
10:54:43.0991 5332 tmtdi - ok
10:54:44.0194 5332 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
10:54:44.0210 5332 TrkWks - ok
10:54:44.0288 5332 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
10:54:44.0288 5332 TrustedInstaller - ok
10:54:44.0506 5332 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
10:54:44.0522 5332 tssecsrv - ok
10:54:44.0803 5332 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
10:54:44.0803 5332 TsUsbFlt - ok
10:54:45.0068 5332 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
10:54:45.0068 5332 TsUsbGD - ok
10:54:45.0364 5332 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
10:54:45.0364 5332 tunnel - ok
10:54:45.0629 5332 TurboB (fd24f98d2898be093fe926604be7db99) C:\Windows\system32\DRIVERS\TurboB.sys
10:54:45.0629 5332 TurboB - ok
10:54:45.0707 5332 TurboBoost (600b406a04d90f577fea8a88d7379f08) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
10:54:45.0707 5332 TurboBoost - ok
10:54:45.0973 5332 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
10:54:45.0973 5332 uagp35 - ok
10:54:46.0269 5332 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
10:54:46.0269 5332 udfs - ok
10:54:46.0503 5332 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
10:54:46.0519 5332 UI0Detect - ok
10:54:46.0799 5332 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
10:54:46.0799 5332 uliagpkx - ok
10:54:47.0080 5332 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
10:54:47.0096 5332 umbus - ok
10:54:47.0361 5332 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
10:54:47.0377 5332 UmPass - ok
10:54:47.0517 5332 UNS (eb79c6c91a99930015ef29ae7fa802d1) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
10:54:47.0595 5332 UNS - ok
10:54:47.0798 5332 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
10:54:47.0813 5332 upnphost - ok
10:54:48.0094 5332 usbccgp (481dff26b4dca8f4cbac1f7dce1d6829) C:\Windows\system32\DRIVERS\usbccgp.sys
10:54:48.0110 5332 usbccgp - ok
10:54:48.0375 5332 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
10:54:48.0391 5332 usbcir - ok
10:54:48.0671 5332 usbehci (74ee782b1d9c241efe425565854c661c) C:\Windows\system32\DRIVERS\usbehci.sys
10:54:48.0671 5332 usbehci - ok
10:54:48.0968 5332 usbhub (dc96bd9ccb8403251bcf25047573558e) C:\Windows\system32\DRIVERS\usbhub.sys
10:54:48.0968 5332 usbhub - ok
10:54:49.0249 5332 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\drivers\usbohci.sys
10:54:49.0264 5332 usbohci - ok
10:54:49.0529 5332 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\drivers\usbprint.sys
10:54:49.0545 5332 usbprint - ok
10:54:49.0795 5332 USBSTOR (d76510cfa0fc09023077f22c2f979d86) C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:54:49.0810 5332 USBSTOR - ok
10:54:50.0091 5332 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\drivers\usbuhci.sys
10:54:50.0091 5332 usbuhci - ok
10:54:50.0372 5332 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
10:54:50.0372 5332 usbvideo - ok
10:54:50.0559 5332 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
10:54:50.0575 5332 UxSms - ok
10:54:50.0746 5332 VaultSvc (0793f40b9b8a1bdd266296409dbd91ea) C:\Windows\system32\lsass.exe
10:54:50.0746 5332 VaultSvc - ok
10:54:51.0027 5332 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
10:54:51.0027 5332 vdrvroot - ok
10:54:51.0261 5332 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
10:54:51.0277 5332 vds - ok
10:54:51.0542 5332 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
10:54:51.0557 5332 vga - ok
10:54:51.0807 5332 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
10:54:51.0823 5332 VgaSave - ok
10:54:52.0103 5332 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
10:54:52.0103 5332 vhdmp - ok
10:54:52.0384 5332 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
10:54:52.0384 5332 viaide - ok
10:54:52.0415 5332 VideAceWindowsService (c37ce43fb54066ffb540729c6e6e194e) C:\ExpressGateUtil\VAWinService.exe
10:54:52.0431 5332 VideAceWindowsService - ok
10:54:52.0696 5332 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
10:54:52.0696 5332 volmgr - ok
10:54:52.0961 5332 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
10:54:52.0961 5332 volmgrx - ok
10:54:53.0242 5332 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
10:54:53.0242 5332 volsnap - ok
10:54:53.0523 5332 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
10:54:53.0523 5332 vsmraid - ok
10:54:53.0741 5332 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
10:54:53.0804 5332 VSS - ok
10:54:54.0053 5332 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
10:54:54.0053 5332 vwifibus - ok
10:54:54.0319 5332 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
10:54:54.0319 5332 vwififlt - ok
10:54:54.0537 5332 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
10:54:54.0553 5332 W32Time - ok
10:54:54.0818 5332 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
10:54:54.0818 5332 WacomPen - ok
10:54:55.0083 5332 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:54:55.0099 5332 WANARP - ok
10:54:55.0114 5332 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
10:54:55.0114 5332 Wanarpv6 - ok
10:54:55.0348 5332 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
10:54:55.0411 5332 wbengine - ok
10:54:55.0613 5332 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
10:54:55.0629 5332 WbioSrvc - ok
10:54:55.0832 5332 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
10:54:55.0832 5332 wcncsvc - ok
10:54:56.0035 5332 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
10:54:56.0035 5332 WcsPlugInService - ok
10:54:56.0300 5332 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
10:54:56.0300 5332 Wd - ok
10:54:56.0565 5332 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
10:54:56.0581 5332 Wdf01000 - ok
10:54:56.0768 5332 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
10:54:56.0783 5332 WdiServiceHost - ok
10:54:56.0783 5332 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
10:54:56.0783 5332 WdiSystemHost - ok
10:54:56.0986 5332 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
10:54:57.0002 5332 WebClient - ok
10:54:57.0205 5332 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
10:54:57.0205 5332 Wecsvc - ok
10:54:57.0423 5332 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
10:54:57.0423 5332 wercplsupport - ok
10:54:57.0641 5332 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
10:54:57.0641 5332 WerSvc - ok
10:54:57.0922 5332 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
10:54:57.0922 5332 WfpLwf - ok
10:54:58.0203 5332 WimFltr (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
10:54:58.0203 5332 WimFltr - ok
10:54:58.0484 5332 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
10:54:58.0499 5332 WIMMount - ok
10:54:58.0531 5332 WinDefend - ok
10:54:58.0546 5332 WinHttpAutoProxySvc - ok
10:54:58.0843 5332 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
10:54:58.0843 5332 Winmgmt - ok
10:54:59.0092 5332 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
10:54:59.0139 5332 WinRM - ok
10:54:59.0373 5332 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
10:54:59.0404 5332 Wlansvc - ok
10:54:59.0482 5332 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
10:54:59.0482 5332 wlcrasvc - ok
10:54:59.0607 5332 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
10:54:59.0654 5332 wlidsvc - ok
10:54:59.0919 5332 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
10:54:59.0919 5332 WmiAcpi - ok
10:55:00.0231 5332 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
10:55:00.0247 5332 wmiApSrv - ok
10:55:00.0293 5332 WMPNetworkSvc - ok
10:55:00.0559 5332 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
10:55:00.0559 5332 WPCSvc - ok
10:55:00.0762 5332 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
10:55:00.0762 5332 WPDBusEnum - ok
10:55:01.0058 5332 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
10:55:01.0058 5332 ws2ifsl - ok
10:55:01.0276 5332 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
10:55:01.0276 5332 wscsvc - ok
10:55:01.0464 5332 WSearch - ok
10:55:01.0729 5332 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
10:55:01.0809 5332 wuauserv - ok
10:55:02.0066 5332 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
10:55:02.0066 5332 WudfPf - ok
10:55:02.0362 5332 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
10:55:02.0362 5332 WUDFRd - ok
10:55:02.0581 5332 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
10:55:02.0581 5332 wudfsvc - ok
10:55:02.0783 5332 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
10:55:02.0783 5332 WwanSvc - ok
10:55:02.0830 5332 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
10:55:03.0064 5332 \Device\Harddisk0\DR0 - ok
10:55:03.0080 5332 Boot (0x1200) (4447c909fb67e0547e25328175d0b6c1) \Device\Harddisk0\DR0\Partition0
10:55:03.0080 5332 \Device\Harddisk0\DR0\Partition0 - ok
10:55:03.0111 5332 Boot (0x1200) (100278ad7735ea869f9ae80d08556317) \Device\Harddisk0\DR0\Partition1
10:55:03.0111 5332 \Device\Harddisk0\DR0\Partition1 - ok
10:55:03.0111 5332 ============================================================
10:55:03.0111 5332 Scan finished
10:55:03.0111 5332 ============================================================
10:55:03.0127 5392 Detected object count: 0
10:55:03.0127 5392 Actual detected object count: 0

#5 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 03:07 AM

here's the aswMBR log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-07 11:00:30
-----------------------------
11:00:30.429 OS Version: Windows x64 6.1.7601 Service Pack 1
11:00:30.429 Number of processors: 8 586 0x2A07
11:00:30.429 ComputerName: BEAST-PC UserName: beast
11:00:36.292 Initialize success
11:01:04.899 AVAST engine defs: 12040601
11:01:19.790 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:01:19.806 Disk 0 Vendor: ST950042 0002 Size: 476940MB BusType: 3
11:01:19.821 Disk 0 MBR read successfully
11:01:19.837 Disk 0 MBR scan
11:01:19.837 Disk 0 Windows 7 default MBR code
11:01:19.852 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 25600 MB offset 2048
11:01:19.868 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 200042 MB offset 52430848
11:01:19.884 Disk 0 Partition - 00 0F Extended LBA 251296 MB offset 462116864
11:01:19.915 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 251295 MB offset 462118912
11:01:19.946 Disk 0 scanning C:\Windows\system32\drivers
11:01:26.201 Service scanning
11:01:45.225 Modules scanning
11:01:45.240 Disk 0 trace - called modules:
11:01:45.303 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
11:01:45.638 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800741b790]
11:01:45.646 3 CLASSPNP.SYS[fffff88001b7543f] -> nt!IofCallDriver -> [0xfffffa80071e5b20]
11:01:45.654 5 ACPI.sys[fffff88000fa97a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80071eb050]
11:01:46.290 AVAST engine scan C:\Windows
11:01:48.408 AVAST engine scan C:\Windows\system32
11:03:05.037 AVAST engine scan C:\Windows\system32\drivers
11:03:12.605 AVAST engine scan C:\Users\beast
11:03:49.725 AVAST engine scan C:\ProgramData
11:04:08.191 Scan finished successfully
11:06:08.987 Disk 0 MBR has been saved successfully to "C:\Users\beast\Desktop\MBR.dat"
11:06:09.002 The log file has been saved successfully to "C:\Users\beast\Desktop\aswMBR.txt"

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:21 AM

Posted 07 April 2012 - 04:23 AM

Download

http://www.techspot.com/downloads/4716-malwarebytes-anti-malware.html

Install,update and run a full scan

Click on SHOW results.Select all infections and remove it

Reboot the PC and scan MBAM once in regular mode until you get a clean log

Download

ESET online scanner


Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply


Download

mini toolbox

Checkmark following boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Click Go and post the result.

#7 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 05:14 AM

sorry but "Reboot the PC and scan MBAM once in regular mode until you get a clean log" means that I scan once more with quick scan? or what did you mean by regular mode?

#8 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 05:28 AM

first malwarebytes scan:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.07.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
beast :: BEAST-PC [administrator]

7.4.2012 13:07:18
mbam-log-2012-04-07 (13-07-18).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 345726
Time elapsed: 18 minute(s), 5 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#9 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 05:39 AM

malwarebytes quick scan:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.04.07.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
beast :: BEAST-PC [administrator]

7.4.2012 13:35:11
mbam-log-2012-04-07 (13-35-11).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 190768
Time elapsed: 1 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#10 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 06:24 AM

ESET came back clean with no threats to be found so there was no list to export

#11 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 06:26 AM

my pc doesn't allow me to run mini toolbox, it says it might be harmful to my pc and it gives me only two option "don't run the program" or "delete the program"

#12 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 06:31 AM

my bad...I managed to do the scan and here's the result:

MiniToolBox by Farbar Version: 18-01-2012
Ran by beast (administrator) on 07-04-2012 at 14:27:38
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================



========================= IP Configuration: ================================

Atheros AR9002WB-1NG Wireless Network Adapter = Wireless Network Connection (Connected)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : beast-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : 14-DA-E9-4B-F3-4C
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wireless Network Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Atheros AR9002WB-1NG Wireless Network Adapter
Physical Address. . . . . . . . . : 74-2F-68-3A-90-D5
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::e948:f39e:24d2:f66a%11(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.0.13(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : 7. huhtikuuta 2012 13:29:22
Lease Expires . . . . . . . . . . : 14. huhtikuuta 2012 13:29:27
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DHCPv6 IAID . . . . . . . . . . . : 242495336
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-11-C4-FC-74-2F-68-3A-90-D5
DNS Servers . . . . . . . . . . . : 62.241.198.245
62.241.198.246
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{DD808CA8-E85B-41C1-84DC-42D6B9DF0B4E}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:5ef5:73b8:cc9:2c46:ad4a:1ef3(Preferred)
Link-local IPv6 Address . . . . . : fe80::cc9:2c46:ad4a:1ef3%15(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: resolver1.dnaip.fi
Address: 62.241.198.245

Name: google.com
Addresses: 173.194.32.35
173.194.32.36
173.194.32.37
173.194.32.38
173.194.32.39
173.194.32.40
173.194.32.41
173.194.32.46
173.194.32.32
173.194.32.33
173.194.32.34


Pinging google.com [173.194.32.33] with 32 bytes of data:
Reply from 173.194.32.33: bytes=32 time=15ms TTL=55
Reply from 173.194.32.33: bytes=32 time=16ms TTL=55

Ping statistics for 173.194.32.33:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 15ms, Maximum = 16ms, Average = 15ms
Server: resolver1.dnaip.fi
Address: 62.241.198.245

Name: yahoo.com
Addresses: 209.191.122.70
72.30.38.140
98.139.183.24


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=326ms TTL=48
Reply from 98.139.183.24: bytes=32 time=430ms TTL=47

Ping statistics for 98.139.183.24:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 326ms, Maximum = 430ms, Average = 378ms
Server: resolver1.dnaip.fi
Address: 62.241.198.245

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
12...14 da e9 4b f3 4c ......Realtek PCIe GBE Family Controller
11...74 2f 68 3a 90 d5 ......Atheros AR9002WB-1NG Wireless Network Adapter
1...........................Software Loopback Interface 1
16...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
15...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.13 25
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.0.0 255.255.255.0 On-link 192.168.0.13 281
192.168.0.13 255.255.255.255 On-link 192.168.0.13 281
192.168.0.255 255.255.255.255 On-link 192.168.0.13 281
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.0.13 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.0.13 281
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
15 58 ::/0 On-link
1 306 ::1/128 On-link
15 58 2001::/32 On-link
15 306 2001:0:5ef5:73b8:cc9:2c46:ad4a:1ef3/128
On-link
11 281 fe80::/64 On-link
15 306 fe80::/64 On-link
15 306 fe80::cc9:2c46:ad4a:1ef3/128
On-link
11 281 fe80::e948:f39e:24d2:f66a/128
On-link
1 306 ff00::/8 On-link
15 306 ff00::/8 On-link
11 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/07/2012 02:23:16 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/07/2012 02:23:16 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/07/2012 01:39:12 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/07/2012 01:39:07 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/06/2012 00:38:51 PM) (Source: Google Update) (User: SYSTEM)SYSTEM
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://tools.google.com/service/update2
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.


System errors:
=============
Error: (04/07/2012 11:47:57 AM) (Source: Service Control Manager) (User: )
Description: The ATKWMIACPI Driver_ service failed to start due to the following error:
%%2


Microsoft Office Sessions:
=========================
Error: (04/07/2012 02:23:16 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\beast\Downloads\esetsmartinstaller_enu.exe

Error: (04/07/2012 02:23:16 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\beast\Downloads\esetsmartinstaller_enu.exe

Error: (04/07/2012 01:39:12 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\beast\Downloads\esetsmartinstaller_enu.exe

Error: (04/07/2012 01:39:07 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\beast\Downloads\esetsmartinstaller_enu.exe

Error: (04/06/2012 00:38:51 PM) (Source: Google Update)(User: SYSTEM)SYSTEM
Description: Network Request Error.
Error: 0x80072ee7. Http status code: 0.
Url=https://tools.google.com/service/update2
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.
Trying config: source=auto, wpad=1, script=.
trying CUP:WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying WinHTTP.
Send request returned 0x80072ee7. Http status code 0.
trying CUP:iexplore.
Send request returned 0x80004005. Http status code 0.


=========================== Installed Programs ============================

ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (Version: 15.4.5722.2)
Adobe Flash Player 10 ActiveX (Version: 10.1.85.3)
Adobe Flash Player 10 Plugin (Version: 10.0.32.18)
ASUS AI Recovery (Version: 1.0.23)
ASUS FaceLogon (Version: 1.0.0013)
ASUS Live Update (Version: 3.1.2)
ASUS Power4Gear Hybrid (Version: 1.2.0)
ASUS Splendid Video Enhancement Technology (Version: 1.02.0040)
ASUS USB Charger Plus (Version: 2.0.8)
ASUS WebStorage (Version: 3.0.84.161)
ASUS Virtual Camera (Version: 1.0.25)
AsusScr_G74 Series_ENG (Version: 1.0.0001)
AsusVibe2.0 (Version: 2.0.4.617)
Atheros Client Installation Program (Version: 7.0)
ATK Package (Version: 1.0.0015)
Bing Bar (Version: 7.0.610.0)
Bluetooth Win7 Suite (64) (Version: 7.2.0.65)
Bookworm Deluxe
Cooking Dash
CyberLink LabelPrint (Version: 2.5.1908)
CyberLink Power2Go (Version: 6.1.3602c)
D3DX10 (Version: 15.4.2368.0902)
DirectX 9 Runtime (Version: 1.00.0000)
ExpressGateCloud (Version: 2.6.27.160)
Finger Sensing Pad Driver (Version: 9.1.3.5)
Fresco Logic USB3.0 Host Controller (Version: 3.5.30.0)
Game Park Console (Version: 6.2.1.1)
GameFast.exe (Version: 1.0.0.1)
Google Chrome (Version: 3.0.195.27)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Update Helper (Version: 1.3.21.111)
Governor of Poker
Hotel Dash Suite Success
Intel® Control Center (Version: 1.2.1.1007)
Intel® Management Engine Components (Version: 7.0.0.1118)
Intel® Turbo Boost Technology Monitor 2.0 (Version: 2.1.23.0)
Jewel Quest 3
Junk Mail filter update (Version: 15.4.3502.0922)
Luxor 3
Mahjongg dimensions
Malwarebytes Anti-Malware version 1.60.1.1000 (Version: 1.60.1.1000)
Mesh Runtime (Version: 15.4.5722.2)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (Version: 14.0.4763.1000)
Microsoft Silverlight (Version: 4.0.50401.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
Nuance PDF Reader (Version: 6.00.0041)
NVIDIA 3D Vision Driver 268.37 (Version: 268.37)
NVIDIA Control Panel 268.37 (Version: 268.37)
NVIDIA Graphics Driver 268.37 (Version: 268.37)
NVIDIA HD Audio Driver 1.2.22.1 (Version: 1.2.22.1)
NVIDIA Install Application (Version: 2.265.41.0)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.12.6837)
Plants vs Zombies
Realtek Ethernet Controller Driver (Version: 7.44.421.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.6564)
Realtek USB 2.0 Reader Driver (Version: 6.1.7600.10001)
Rotation Desktop for G Series.exe (Version: 1.0.0.9)
Roxio AACS Certificate (Version: 1.0.0)
Roxio CinePlayer (Version: 5.8)
Roxio CinePlayer (Version: 5.8.58232.1)
syncables desktop SE (Version: 5.5.746.11492)
THX TruStudio (Version: 1.03.01)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Family Safety (Version: 15.4.3555.0308)
Windows Live Fotogalleri (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (Version: 15.4.5722.2)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Liven asennustyökalu (Version: 15.4.3502.0922)
Windows Liven asennustyökalu (Version: 15.4.3555.0308)
Windows Liven sähköposti (Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (Version: 15.4.3502.0922)
WinFlash (Version: 2.32.0)
Wireless Console 3 (Version: 3.0.27)
World of Goo

========================= Memory info: ===================================

Percentage of memory in use: 27%
Total physical RAM: 8169.16 MB
Available physical RAM: 5931.63 MB
Total Pagefile: 16336.53 MB
Available Pagefile: 13725.32 MB
Total Virtual: 4095.88 MB
Available Virtual: 3962.35 MB

========================= Partitions: =====================================

1 Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:156.06 GB) NTFS
2 Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:245.31 GB) NTFS

========================= Users: ========================================

User accounts for \\BEAST-PC

Administrator beast Guest


**** End of log ****

#13 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:21 AM

Posted 07 April 2012 - 06:53 AM

That looks good,PC is clean

Download

TFC


Launch it,it will close all running programs

click on START,it should ask for reboot

Turn off your system restore,restart the PC,create a new restore point

http://windows.microsoft.com/en-US/windows7/Turn-System-Restore-on-or-off

Update your antivirus frequently,do not click on suspicious links

Safe surfing :)

#14 jabbb

jabbb
  • Topic Starter

  • Members
  • 55 posts
  • OFFLINE
  •  
  • Local time:08:21 AM

Posted 07 April 2012 - 07:09 AM

Thanks a million narenxp, you've been so helpfull, I'm greatful for your help.
I'll see you in the future ;)

#15 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:21 AM

Posted 07 April 2012 - 07:11 AM

You're welcome :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users