Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan's quaratined/logged but won't go away?


  • Please log in to reply
17 replies to this topic

#1 xhongxkongx

xhongxkongx

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 20 May 2012 - 11:25 PM

Virus I'm faced with:
1) Trojan.Ransomlock
2) Trojan.Gen
3) Trojan.Zeroaccess.B
4) Suspicious.DLoader

My antivirus software that runs in the back ground is Symantec Endpoint Protection. I also use SuperAntiSpyware and Malwarebytes to scan and remove viruses.

Problem: The "Symantec AntiVirus Dection Results" keeps popping up and alerts me that it has either "log, quarantine, or backup" the viruses I have listed above. It keeps on happening whenever I have my computer turned on. The most frequent one that pops up is Trojan.Ransomlock, then Trojan.Gen. The other two every once in a while. Once the "detection results" box pops up my computer would freeze for a bit (a few minutes) while Symantec does its thing.

I would like to find a solution that ends this problem once and for all.

I appreciate any insightful solution and thank you for your time in advance.

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 21 May 2012 - 12:45 AM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)



Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner


Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 21 May 2012 - 07:34 PM

TDSSKiller Log Below:

12:29:17.0646 4244 TDSS rootkit removing tool 2.7.36.0 May 21 2012 16:40:16
12:29:17.0942 4244 ============================================================
12:29:17.0942 4244 Current date / time: 2012/05/21 12:29:17.0942
12:29:17.0942 4244 SystemInfo:
12:29:17.0942 4244
12:29:17.0942 4244 OS Version: 6.1.7601 ServicePack: 1.0
12:29:17.0942 4244 Product type: Workstation
12:29:17.0942 4244 ComputerName: PC
12:29:17.0942 4244 UserName: Chung Hei Sing
12:29:17.0942 4244 Windows directory: C:\Windows
12:29:17.0942 4244 System windows directory: C:\Windows
12:29:17.0942 4244 Running under WOW64
12:29:17.0942 4244 Processor architecture: Intel x64
12:29:17.0942 4244 Number of processors: 4
12:29:17.0942 4244 Page size: 0x1000
12:29:17.0942 4244 Boot type: Normal boot
12:29:17.0942 4244 ============================================================
12:29:23.0199 4244 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:29:23.0215 4244 ============================================================
12:29:23.0215 4244 \Device\Harddisk0\DR0:
12:29:23.0215 4244 MBR partitions:
12:29:23.0215 4244 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1388000
12:29:23.0215 4244 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x13BA800, BlocksNum 0x24072EC1
12:29:23.0215 4244 ============================================================
12:29:23.0277 4244 C: <-> \Device\Harddisk0\DR0\Partition1
12:29:23.0277 4244 ============================================================
12:29:23.0277 4244 Initialize success
12:29:23.0277 4244 ============================================================
12:29:46.0662 2948 ============================================================
12:29:46.0662 2948 Scan started
12:29:46.0662 2948 Mode: Manual; TDLFS;
12:29:46.0662 2948 ============================================================
12:29:48.0549 2948 !SASCORE (7d9d615201a483d6fa99491c2e655a5a) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
12:29:48.0549 2948 !SASCORE - ok
12:29:49.0423 2948 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
12:29:49.0439 2948 1394ohci - ok
12:29:49.0532 2948 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
12:29:49.0532 2948 ACPI - ok
12:29:49.0579 2948 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
12:29:49.0595 2948 AcpiPmi - ok
12:29:49.0751 2948 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
12:29:49.0751 2948 AdobeARMservice - ok
12:29:49.0953 2948 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:29:50.0000 2948 AdobeFlashPlayerUpdateSvc - ok
12:29:50.0078 2948 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
12:29:50.0109 2948 adp94xx - ok
12:29:50.0156 2948 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
12:29:50.0172 2948 adpahci - ok
12:29:50.0219 2948 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
12:29:50.0234 2948 adpu320 - ok
12:29:50.0281 2948 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
12:29:50.0281 2948 AeLookupSvc - ok
12:29:50.0359 2948 AERTFilters (3ac22a3dfa8a050e35f0e3cd99d0cdf2) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
12:29:50.0359 2948 AERTFilters - ok
12:29:50.0453 2948 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
12:29:50.0468 2948 AFD - ok
12:29:50.0531 2948 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
12:29:50.0546 2948 agp440 - ok
12:29:50.0593 2948 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
12:29:50.0593 2948 ALG - ok
12:29:50.0624 2948 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
12:29:50.0640 2948 aliide - ok
12:29:50.0671 2948 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
12:29:50.0687 2948 amdide - ok
12:29:50.0733 2948 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
12:29:50.0749 2948 AmdK8 - ok
12:29:50.0749 2948 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
12:29:50.0765 2948 AmdPPM - ok
12:29:50.0811 2948 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
12:29:50.0827 2948 amdsata - ok
12:29:50.0889 2948 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
12:29:50.0889 2948 amdsbs - ok
12:29:50.0921 2948 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
12:29:50.0921 2948 amdxata - ok
12:29:50.0983 2948 ApfiltrService (8b522286c8d6a20133d12225b7759596) C:\Windows\system32\DRIVERS\Apfiltr.sys
12:29:50.0983 2948 ApfiltrService - ok
12:29:51.0155 2948 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
12:29:51.0170 2948 AppID - ok
12:29:51.0201 2948 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
12:29:51.0201 2948 AppIDSvc - ok
12:29:51.0248 2948 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
12:29:51.0264 2948 Appinfo - ok
12:29:51.0467 2948 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:29:51.0467 2948 Apple Mobile Device - ok
12:29:51.0513 2948 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
12:29:51.0529 2948 arc - ok
12:29:51.0560 2948 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
12:29:51.0576 2948 arcsas - ok
12:29:51.0763 2948 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
12:29:51.0810 2948 aspnet_state - ok
12:29:51.0857 2948 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
12:29:51.0857 2948 AsyncMac - ok
12:29:51.0903 2948 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
12:29:51.0903 2948 atapi - ok
12:29:52.0013 2948 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
12:29:52.0028 2948 AudioEndpointBuilder - ok
12:29:52.0044 2948 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
12:29:52.0044 2948 AudioSrv - ok
12:29:52.0106 2948 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
12:29:52.0122 2948 AxInstSV - ok
12:29:52.0184 2948 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
12:29:52.0215 2948 b06bdrv - ok
12:29:52.0262 2948 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
12:29:52.0278 2948 b57nd60a - ok
12:29:53.0198 2948 BBSvc (825f81a6f7dd073509db101f0ba6dc59) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
12:29:53.0261 2948 BBSvc - ok
12:29:53.0292 2948 BCM42RLY (e001dd475a7c27ebe5a0db45c11bad71) C:\Windows\system32\drivers\BCM42RLY.sys
12:29:53.0292 2948 BCM42RLY - ok
12:29:53.0573 2948 BCM43XX (37394d3553e220fb732c21e217e1bd8b) C:\Windows\system32\DRIVERS\bcmwl664.sys
12:29:53.0573 2948 BCM43XX - ok
12:29:54.0337 2948 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
12:29:54.0353 2948 BDESVC - ok
12:29:54.0493 2948 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
12:29:54.0493 2948 Beep - ok
12:29:54.0633 2948 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
12:29:54.0633 2948 BFE - ok
12:29:54.0743 2948 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
12:29:54.0774 2948 BITS - ok
12:29:54.0836 2948 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
12:29:54.0836 2948 blbdrive - ok
12:29:55.0039 2948 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
12:29:55.0039 2948 Bonjour Service - ok
12:29:55.0101 2948 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
12:29:55.0101 2948 bowser - ok
12:29:55.0133 2948 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:29:55.0148 2948 BrFiltLo - ok
12:29:55.0179 2948 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:29:55.0195 2948 BrFiltUp - ok
12:29:55.0257 2948 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
12:29:55.0257 2948 Browser - ok
12:29:55.0304 2948 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
12:29:55.0335 2948 Brserid - ok
12:29:55.0351 2948 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
12:29:55.0367 2948 BrSerWdm - ok
12:29:55.0382 2948 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
12:29:55.0398 2948 BrUsbMdm - ok
12:29:55.0429 2948 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
12:29:55.0445 2948 BrUsbSer - ok
12:29:55.0476 2948 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
12:29:55.0476 2948 BTHMODEM - ok
12:29:55.0944 2948 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
12:29:55.0975 2948 bthserv - ok
12:29:56.0193 2948 ccEvtMgr (4ed0778cf4e1c2406db5fd456f2ed746) C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
12:29:56.0193 2948 ccEvtMgr - ok
12:29:56.0240 2948 ccSetMgr (4ed0778cf4e1c2406db5fd456f2ed746) C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
12:29:56.0240 2948 ccSetMgr - ok
12:29:56.0271 2948 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
12:29:56.0303 2948 cdfs - ok
12:29:56.0365 2948 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
12:29:56.0381 2948 cdrom - ok
12:29:56.0427 2948 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
12:29:56.0459 2948 CertPropSvc - ok
12:29:56.0521 2948 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
12:29:56.0537 2948 circlass - ok
12:29:56.0615 2948 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
12:29:56.0615 2948 CLFS - ok
12:29:56.0708 2948 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:29:56.0755 2948 clr_optimization_v2.0.50727_32 - ok
12:29:57.0317 2948 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:29:57.0379 2948 clr_optimization_v2.0.50727_64 - ok
12:29:57.0457 2948 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:29:57.0519 2948 clr_optimization_v4.0.30319_32 - ok
12:29:57.0613 2948 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:29:57.0629 2948 clr_optimization_v4.0.30319_64 - ok
12:29:57.0675 2948 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
12:29:57.0691 2948 CmBatt - ok
12:29:57.0707 2948 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
12:29:57.0738 2948 cmdide - ok
12:29:57.0831 2948 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
12:29:57.0847 2948 CNG - ok
12:29:57.0894 2948 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
12:29:57.0894 2948 Compbatt - ok
12:29:57.0925 2948 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
12:29:57.0925 2948 CompositeBus - ok
12:29:57.0941 2948 COMSysApp - ok
12:29:57.0956 2948 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
12:29:57.0987 2948 crcdisk - ok
12:29:58.0034 2948 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
12:29:58.0050 2948 CryptSvc - ok
12:29:58.0128 2948 CtClsFlt (ed5cf92396a62f4c15110dcdb5e854d9) C:\Windows\system32\DRIVERS\CtClsFlt.sys
12:29:58.0128 2948 CtClsFlt - ok
12:29:58.0237 2948 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
12:29:58.0253 2948 DcomLaunch - ok
12:29:58.0299 2948 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
12:29:58.0346 2948 defragsvc - ok
12:29:58.0409 2948 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
12:29:58.0424 2948 DfsC - ok
12:29:58.0487 2948 dg_ssudbus (388039f99ce8769024ee0438352aca99) C:\Windows\system32\DRIVERS\ssudbus.sys
12:29:58.0518 2948 dg_ssudbus - ok
12:29:58.0611 2948 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
12:29:58.0611 2948 Dhcp - ok
12:29:58.0643 2948 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
12:29:58.0658 2948 discache - ok
12:29:58.0705 2948 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
12:29:58.0705 2948 Disk - ok
12:29:58.0783 2948 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
12:29:58.0783 2948 Dnscache - ok
12:29:58.0955 2948 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe
12:29:58.0955 2948 DockLoginService - ok
12:29:59.0033 2948 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
12:29:59.0064 2948 dot3svc - ok
12:29:59.0111 2948 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
12:29:59.0111 2948 DPS - ok
12:29:59.0142 2948 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
12:29:59.0173 2948 drmkaud - ok
12:29:59.0235 2948 dsNcAdpt (3eef0b3489edbf725564e17c77cabafd) C:\Windows\system32\DRIVERS\dsNcAdpt.sys
12:29:59.0235 2948 dsNcAdpt - ok
12:29:59.0423 2948 dsNcService (bc4851b8cd478b93fcaedb95052a824d) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
12:29:59.0438 2948 dsNcService - ok
12:29:59.0547 2948 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
12:29:59.0563 2948 DXGKrnl - ok
12:29:59.0594 2948 EagleX64 - ok
12:29:59.0657 2948 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
12:29:59.0657 2948 EapHost - ok
12:30:00.0093 2948 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
12:30:00.0218 2948 ebdrv - ok
12:30:00.0437 2948 eeCtrl (0c3f9eff8ddd9f9eb56d754b4620155f) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
12:30:00.0452 2948 eeCtrl - ok
12:30:00.0717 2948 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
12:30:00.0733 2948 EFS - ok
12:30:01.0482 2948 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
12:30:01.0560 2948 ehRecvr - ok
12:30:01.0622 2948 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
12:30:01.0638 2948 ehSched - ok
12:30:01.0778 2948 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
12:30:01.0825 2948 elxstor - ok
12:30:02.0043 2948 EraserUtilRebootDrv (8c0f9b877bc0b7ffd327ef55f9efb642) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
12:30:02.0043 2948 EraserUtilRebootDrv - ok
12:30:02.0121 2948 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
12:30:02.0121 2948 ErrDev - ok
12:30:02.0246 2948 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
12:30:02.0262 2948 EventSystem - ok
12:30:02.0340 2948 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
12:30:02.0355 2948 exfat - ok
12:30:02.0387 2948 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
12:30:02.0402 2948 fastfat - ok
12:30:02.0511 2948 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
12:30:02.0511 2948 Fax - ok
12:30:02.0558 2948 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
12:30:02.0574 2948 fdc - ok
12:30:02.0605 2948 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
12:30:02.0605 2948 fdPHost - ok
12:30:02.0621 2948 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
12:30:02.0636 2948 FDResPub - ok
12:30:02.0699 2948 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
12:30:02.0699 2948 FileInfo - ok
12:30:02.0714 2948 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
12:30:02.0730 2948 Filetrace - ok
12:30:02.0745 2948 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
12:30:02.0761 2948 flpydisk - ok
12:30:03.0291 2948 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
12:30:03.0291 2948 FltMgr - ok
12:30:03.0494 2948 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
12:30:03.0541 2948 FontCache - ok
12:30:03.0650 2948 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:30:03.0666 2948 FontCache3.0.0.0 - ok
12:30:03.0962 2948 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
12:30:03.0962 2948 FsDepends - ok
12:30:04.0025 2948 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
12:30:04.0040 2948 fssfltr - ok
12:30:05.0522 2948 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
12:30:05.0631 2948 fsssvc - ok
12:30:06.0021 2948 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
12:30:06.0021 2948 Fs_Rec - ok
12:30:06.0099 2948 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
12:30:06.0099 2948 fvevol - ok
12:30:06.0209 2948 FwcAgent (024c0e47ac6cf525f558400ae09ca63d) C:\Program Files (x86)\Microsoft Firewall Client 2004\FwcAgent.exe
12:30:06.0209 2948 FwcAgent - ok
12:30:06.0271 2948 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
12:30:06.0271 2948 gagp30kx - ok
12:30:06.0318 2948 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:30:06.0318 2948 GEARAspiWDM - ok
12:30:06.0365 2948 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
12:30:06.0380 2948 GoToAssist - ok
12:30:06.0552 2948 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
12:30:06.0599 2948 gpsvc - ok
12:30:06.0645 2948 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
12:30:06.0661 2948 hcw85cir - ok
12:30:06.0708 2948 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
12:30:06.0708 2948 HDAudBus - ok
12:30:06.0755 2948 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
12:30:06.0770 2948 HECIx64 - ok
12:30:06.0848 2948 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
12:30:06.0848 2948 HidBatt - ok
12:30:07.0394 2948 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
12:30:07.0425 2948 HidBth - ok
12:30:07.0472 2948 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
12:30:07.0488 2948 HidIr - ok
12:30:07.0566 2948 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
12:30:07.0581 2948 hidserv - ok
12:30:07.0644 2948 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
12:30:07.0644 2948 HidUsb - ok
12:30:07.0769 2948 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
12:30:07.0800 2948 hkmsvc - ok
12:30:07.0862 2948 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
12:30:07.0893 2948 HomeGroupListener - ok
12:30:07.0971 2948 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
12:30:07.0987 2948 HomeGroupProvider - ok
12:30:08.0424 2948 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
12:30:08.0439 2948 HpSAMD - ok
12:30:08.0549 2948 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
12:30:08.0549 2948 HTTP - ok
12:30:08.0595 2948 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
12:30:08.0595 2948 hwpolicy - ok
12:30:08.0658 2948 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
12:30:08.0658 2948 i8042prt - ok
12:30:09.0453 2948 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
12:30:09.0516 2948 iaStorV - ok
12:30:09.0687 2948 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:30:09.0719 2948 idsvc - ok
12:30:10.0249 2948 igfx (0372c154226f7074cd150f475a4870a6) C:\Windows\system32\DRIVERS\igdkmd64.sys
12:30:10.0405 2948 igfx - ok
12:30:10.0577 2948 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
12:30:10.0592 2948 iirsp - ok
12:30:10.0717 2948 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
12:30:10.0733 2948 IKEEXT - ok
12:30:10.0764 2948 Impcd (36fdf367a1dabff903e2214023d71368) C:\Windows\system32\DRIVERS\Impcd.sys
12:30:10.0764 2948 Impcd - ok
12:30:10.0967 2948 IntcAzAudAddService (2a7cf87be453241fe0baa1c8651e7aa4) C:\Windows\system32\drivers\RTKVHD64.sys
12:30:10.0982 2948 IntcAzAudAddService - ok
12:30:11.0185 2948 IntcDAud (49072edbc5c2f964917d1b585c90ed0a) C:\Windows\system32\DRIVERS\IntcDAud.sys
12:30:11.0185 2948 IntcDAud - ok
12:30:11.0216 2948 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
12:30:11.0232 2948 intelide - ok
12:30:11.0279 2948 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
12:30:11.0279 2948 intelppm - ok
12:30:11.0325 2948 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
12:30:11.0341 2948 IPBusEnum - ok
12:30:11.0419 2948 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:30:11.0419 2948 IpFilterDriver - ok
12:30:11.0466 2948 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
12:30:11.0466 2948 IPMIDRV - ok
12:30:11.0528 2948 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
12:30:11.0544 2948 IPNAT - ok
12:30:11.0715 2948 iPod Service (50d6ccc6ff5561f9f56946b3e6164fb8) C:\Program Files\iPod\bin\iPodService.exe
12:30:11.0731 2948 iPod Service - ok
12:30:11.0778 2948 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
12:30:11.0793 2948 IRENUM - ok
12:30:11.0825 2948 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
12:30:11.0840 2948 isapnp - ok
12:30:11.0918 2948 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
12:30:11.0949 2948 iScsiPrt - ok
12:30:12.0012 2948 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
12:30:12.0012 2948 kbdclass - ok
12:30:12.0059 2948 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
12:30:12.0074 2948 kbdhid - ok
12:30:12.0137 2948 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
12:30:12.0152 2948 KeyIso - ok
12:30:12.0215 2948 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
12:30:12.0215 2948 KSecDD - ok
12:30:12.0293 2948 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
12:30:12.0293 2948 KSecPkg - ok
12:30:12.0339 2948 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
12:30:12.0339 2948 ksthunk - ok
12:30:13.0400 2948 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
12:30:13.0431 2948 KtmRm - ok
12:30:13.0525 2948 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
12:30:13.0541 2948 LanmanServer - ok
12:30:13.0603 2948 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
12:30:13.0619 2948 LanmanWorkstation - ok
12:30:14.0196 2948 LiveUpdate (010fd2b41e75a98e3a4d23f44405f5c9) C:\PROGRA~2\Symantec\LIVEUP~1\LUCOMS~1.EXE
12:30:14.0289 2948 LiveUpdate - ok
12:30:14.0757 2948 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
12:30:14.0757 2948 lltdio - ok
12:30:14.0835 2948 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
12:30:14.0851 2948 lltdsvc - ok
12:30:14.0851 2948 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
12:30:14.0851 2948 lmhosts - ok
12:30:15.0335 2948 LMS (7485fbcef9136f530953575e2977859d) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
12:30:15.0350 2948 LMS - ok
12:30:15.0397 2948 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
12:30:15.0413 2948 LSI_FC - ok
12:30:15.0444 2948 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
12:30:15.0444 2948 LSI_SAS - ok
12:30:15.0475 2948 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:30:15.0491 2948 LSI_SAS2 - ok
12:30:15.0522 2948 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:30:15.0537 2948 LSI_SCSI - ok
12:30:15.0553 2948 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
12:30:15.0569 2948 luafv - ok
12:30:15.0600 2948 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
12:30:15.0631 2948 Mcx2Svc - ok
12:30:15.0647 2948 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
12:30:15.0647 2948 megasas - ok
12:30:15.0709 2948 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
12:30:15.0725 2948 MegaSR - ok
12:30:15.0818 2948 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
12:30:15.0849 2948 Microsoft Office Groove Audit Service - ok
12:30:15.0990 2948 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:30:15.0990 2948 MMCSS - ok
12:30:16.0021 2948 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
12:30:16.0021 2948 Modem - ok
12:30:16.0099 2948 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
12:30:16.0099 2948 monitor - ok
12:30:16.0146 2948 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
12:30:16.0146 2948 mouclass - ok
12:30:16.0161 2948 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
12:30:16.0177 2948 mouhid - ok
12:30:16.0224 2948 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
12:30:16.0239 2948 mountmgr - ok
12:30:16.0333 2948 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:30:16.0380 2948 MozillaMaintenance - ok
12:30:16.0442 2948 MpFilter (94c66ededcdb6a126880472f9a704d8e) C:\Windows\system32\DRIVERS\MpFilter.sys
12:30:16.0458 2948 MpFilter - ok
12:30:16.0505 2948 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
12:30:16.0520 2948 mpio - ok
12:30:16.0567 2948 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
12:30:16.0583 2948 mpsdrv - ok
12:30:16.0707 2948 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
12:30:16.0739 2948 MpsSvc - ok
12:30:16.0785 2948 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
12:30:16.0801 2948 MRxDAV - ok
12:30:16.0848 2948 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
12:30:16.0848 2948 mrxsmb - ok
12:30:16.0910 2948 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:30:16.0910 2948 mrxsmb10 - ok
12:30:16.0957 2948 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:30:16.0957 2948 mrxsmb20 - ok
12:30:16.0988 2948 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
12:30:16.0988 2948 msahci - ok
12:30:17.0409 2948 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
12:30:17.0425 2948 msdsm - ok
12:30:17.0955 2948 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
12:30:18.0018 2948 MSDTC - ok
12:30:18.0049 2948 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
12:30:18.0065 2948 Msfs - ok
12:30:18.0096 2948 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
12:30:18.0111 2948 mshidkmdf - ok
12:30:18.0189 2948 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
12:30:18.0189 2948 msisadrv - ok
12:30:18.0236 2948 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
12:30:18.0252 2948 MSiSCSI - ok
12:30:18.0252 2948 msiserver - ok
12:30:18.0314 2948 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
12:30:18.0314 2948 MSKSSRV - ok
12:30:18.0486 2948 MsMpSvc (59faaf2c83c8169ea20f9e335e418907) c:\Program Files\Microsoft Security Client\MsMpEng.exe
12:30:18.0486 2948 MsMpSvc - ok
12:30:18.0533 2948 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
12:30:18.0548 2948 MSPCLOCK - ok
12:30:18.0564 2948 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
12:30:18.0579 2948 MSPQM - ok
12:30:18.0642 2948 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
12:30:18.0657 2948 MsRPC - ok
12:30:18.0689 2948 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
12:30:18.0704 2948 mssmbios - ok
12:30:18.0735 2948 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
12:30:18.0735 2948 MSTEE - ok
12:30:18.0845 2948 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
12:30:18.0860 2948 MTConfig - ok
12:30:18.0891 2948 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
12:30:18.0891 2948 Mup - ok
12:30:19.0047 2948 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
12:30:19.0063 2948 napagent - ok
12:30:19.0141 2948 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
12:30:19.0141 2948 NativeWifiP - ok
12:30:19.0437 2948 NAVENG (8043d41f881d6ace40b854ad6e32217f) C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20120519.009\ENG64.SYS
12:30:19.0469 2948 NAVENG - ok
12:30:19.0781 2948 NAVEX15 (9a9ab2fc45d701daed465d14980f1305) C:\PROGRA~3\Symantec\DEFINI~1\VIRUSD~1\20120519.009\EX64.SYS
12:30:19.0827 2948 NAVEX15 - ok
12:30:23.0712 2948 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
12:30:23.0743 2948 NDIS - ok
12:30:23.0946 2948 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
12:30:23.0961 2948 NdisCap - ok
12:30:24.0024 2948 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
12:30:24.0039 2948 NdisTapi - ok
12:30:24.0133 2948 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
12:30:24.0133 2948 Ndisuio - ok
12:30:24.0305 2948 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
12:30:24.0305 2948 NdisWan - ok
12:30:24.0523 2948 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
12:30:24.0523 2948 NDProxy - ok
12:30:24.0585 2948 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
12:30:24.0585 2948 NetBIOS - ok
12:30:24.0710 2948 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
12:30:24.0726 2948 NetBT - ok
12:30:24.0804 2948 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
12:30:24.0804 2948 Netlogon - ok
12:30:24.0897 2948 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
12:30:24.0913 2948 Netman - ok
12:30:25.0100 2948 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:30:25.0147 2948 NetMsmqActivator - ok
12:30:25.0163 2948 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:30:25.0163 2948 NetPipeActivator - ok
12:30:25.0225 2948 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
12:30:25.0241 2948 netprofm - ok
12:30:25.0287 2948 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:30:25.0287 2948 NetTcpActivator - ok
12:30:25.0287 2948 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:30:25.0303 2948 NetTcpPortSharing - ok
12:30:25.0490 2948 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
12:30:25.0490 2948 nfrd960 - ok
12:30:26.0177 2948 NisDrv (91b4e0273d2f6c24ef845f2b41311289) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
12:30:26.0208 2948 NisDrv - ok
12:30:26.0629 2948 NisSrv (10a43829a9e606af3eef25a1c1665923) c:\Program Files\Microsoft Security Client\NisSrv.exe
12:30:26.0723 2948 NisSrv - ok
12:30:26.0801 2948 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
12:30:26.0816 2948 NlaSvc - ok
12:30:26.0863 2948 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
12:30:26.0863 2948 Npfs - ok
12:30:26.0988 2948 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
12:30:27.0003 2948 nsi - ok
12:30:27.0019 2948 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
12:30:27.0019 2948 nsiproxy - ok
12:30:27.0300 2948 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
12:30:27.0362 2948 Ntfs - ok
12:30:27.0737 2948 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
12:30:27.0737 2948 Null - ok
12:30:27.0799 2948 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
12:30:27.0815 2948 nvraid - ok
12:30:27.0861 2948 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
12:30:27.0877 2948 nvstor - ok
12:30:27.0939 2948 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
12:30:27.0955 2948 nv_agp - ok
12:30:28.0189 2948 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:30:28.0236 2948 odserv - ok
12:30:28.0283 2948 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
12:30:28.0298 2948 ohci1394 - ok
12:30:28.0361 2948 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:30:28.0439 2948 ose - ok
12:30:28.0501 2948 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:30:28.0517 2948 p2pimsvc - ok
12:30:28.0563 2948 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
12:30:28.0579 2948 p2psvc - ok
12:30:28.0641 2948 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
12:30:28.0657 2948 Parport - ok
12:30:28.0704 2948 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
12:30:28.0704 2948 partmgr - ok
12:30:28.0782 2948 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
12:30:28.0782 2948 PcaSvc - ok
12:30:28.0891 2948 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
12:30:28.0891 2948 pci - ok
12:30:28.0953 2948 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
12:30:28.0985 2948 pciide - ok
12:30:29.0063 2948 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
12:30:29.0094 2948 pcmcia - ok
12:30:29.0109 2948 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
12:30:29.0109 2948 pcw - ok
12:30:29.0203 2948 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
12:30:29.0219 2948 PEAUTH - ok
12:30:29.0437 2948 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
12:30:29.0468 2948 PerfHost - ok
12:30:31.0481 2948 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
12:30:31.0543 2948 pla - ok
12:30:31.0621 2948 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
12:30:31.0652 2948 PlugPlay - ok
12:30:31.0683 2948 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
12:30:31.0699 2948 PNRPAutoReg - ok
12:30:31.0746 2948 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:30:31.0746 2948 PNRPsvc - ok
12:30:31.0824 2948 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
12:30:31.0839 2948 PolicyAgent - ok
12:30:31.0886 2948 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
12:30:31.0917 2948 Power - ok
12:30:32.0011 2948 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
12:30:32.0011 2948 PptpMiniport - ok
12:30:32.0042 2948 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
12:30:32.0058 2948 Processor - ok
12:30:32.0120 2948 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
12:30:32.0120 2948 ProfSvc - ok
12:30:32.0167 2948 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
12:30:32.0167 2948 ProtectedStorage - ok
12:30:32.0229 2948 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
12:30:32.0245 2948 Psched - ok
12:30:32.0292 2948 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
12:30:32.0292 2948 PxHlpa64 - ok
12:30:32.0448 2948 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
12:30:32.0495 2948 ql2300 - ok
12:30:32.0682 2948 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
12:30:32.0697 2948 ql40xx - ok
12:30:32.0744 2948 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
12:30:32.0760 2948 QWAVE - ok
12:30:32.0760 2948 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
12:30:32.0775 2948 QWAVEdrv - ok
12:30:32.0775 2948 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
12:30:32.0791 2948 RasAcd - ok
12:30:32.0822 2948 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
12:30:32.0822 2948 RasAgileVpn - ok
12:30:32.0900 2948 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
12:30:32.0931 2948 RasAuto - ok
12:30:32.0963 2948 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
12:30:32.0963 2948 Rasl2tp - ok
12:30:33.0025 2948 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
12:30:33.0072 2948 RasMan - ok
12:30:33.0103 2948 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
12:30:33.0119 2948 RasPppoe - ok
12:30:33.0134 2948 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
12:30:33.0134 2948 RasSstp - ok
12:30:33.0197 2948 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
12:30:33.0212 2948 rdbss - ok
12:30:33.0228 2948 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
12:30:33.0259 2948 rdpbus - ok
12:30:33.0275 2948 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
12:30:33.0275 2948 RDPCDD - ok
12:30:33.0290 2948 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
12:30:33.0290 2948 RDPENCDD - ok
12:30:33.0306 2948 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
12:30:33.0306 2948 RDPREFMP - ok
12:30:33.0368 2948 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
12:30:33.0415 2948 RDPWD - ok
12:30:33.0493 2948 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
12:30:33.0493 2948 rdyboost - ok
12:30:33.0571 2948 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
12:30:33.0587 2948 RemoteAccess - ok
12:30:33.0633 2948 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
12:30:33.0665 2948 RemoteRegistry - ok
12:30:33.0711 2948 RimUsb (71b48ddaf5e9c2b40e64de5c405f5aac) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
12:30:33.0743 2948 RimUsb - ok
12:30:33.0774 2948 RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
12:30:33.0774 2948 RimVSerPort - ok
12:30:33.0821 2948 ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\Windows\system32\Drivers\RootMdm.sys
12:30:33.0821 2948 ROOTMODEM - ok
12:30:33.0852 2948 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
12:30:33.0867 2948 RpcEptMapper - ok
12:30:33.0883 2948 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
12:30:33.0899 2948 RpcLocator - ok
12:30:33.0977 2948 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
12:30:33.0992 2948 RpcSs - ok
12:30:34.0023 2948 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
12:30:34.0039 2948 rspndr - ok
12:30:34.0086 2948 RSUSBSTOR (502b316947ea887cddd325d4745eb7d0) C:\Windows\system32\Drivers\RtsUStor.sys
12:30:34.0086 2948 RSUSBSTOR - ok
12:30:34.0148 2948 RTL8167 (3b01789ee4eaee97f5eb46b711387d5e) C:\Windows\system32\DRIVERS\Rt64win7.sys
12:30:34.0148 2948 RTL8167 - ok
12:30:34.0195 2948 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
12:30:34.0195 2948 SamSs - ok
12:30:34.0320 2948 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
12:30:34.0320 2948 SASDIFSV - ok
12:30:34.0320 2948 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
12:30:34.0320 2948 SASKUTIL - ok
12:30:34.0367 2948 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
12:30:34.0398 2948 sbp2port - ok
12:30:34.0445 2948 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
12:30:34.0476 2948 SCardSvr - ok
12:30:34.0523 2948 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
12:30:34.0554 2948 scfilter - ok
12:30:34.0663 2948 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
12:30:34.0694 2948 Schedule - ok
12:30:34.0741 2948 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
12:30:34.0741 2948 SCPolicySvc - ok
12:30:34.0788 2948 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
12:30:34.0819 2948 SDRSVC - ok
12:30:34.0959 2948 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
12:30:34.0959 2948 SeaPort - ok
12:30:35.0037 2948 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
12:30:35.0037 2948 secdrv - ok
12:30:35.0069 2948 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
12:30:35.0100 2948 seclogon - ok
12:30:35.0147 2948 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
12:30:35.0162 2948 SENS - ok
12:30:35.0178 2948 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
12:30:35.0193 2948 SensrSvc - ok
12:30:35.0225 2948 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
12:30:35.0240 2948 Serenum - ok
12:30:35.0303 2948 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
12:30:35.0334 2948 Serial - ok
12:30:35.0365 2948 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
12:30:35.0396 2948 sermouse - ok
12:30:35.0459 2948 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
12:30:35.0490 2948 SessionEnv - ok
12:30:35.0521 2948 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
12:30:35.0537 2948 sffdisk - ok
12:30:35.0552 2948 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
12:30:35.0568 2948 sffp_mmc - ok
12:30:35.0583 2948 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
12:30:35.0599 2948 sffp_sd - ok
12:30:35.0646 2948 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
12:30:35.0661 2948 sfloppy - ok
12:30:35.0755 2948 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
12:30:35.0786 2948 SharedAccess - ok
12:30:35.0849 2948 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
12:30:35.0880 2948 ShellHWDetection - ok
12:30:35.0880 2948 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:30:35.0895 2948 SiSRaid2 - ok
12:30:35.0927 2948 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
12:30:35.0942 2948 SiSRaid4 - ok
12:30:36.0067 2948 SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files (x86)\Skype\Updater\Updater.exe
12:30:36.0067 2948 SkypeUpdate - ok
12:30:36.0098 2948 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
12:30:36.0114 2948 Smb - ok
12:30:36.0426 2948 SmcService (8316eb68c09b53135e717ff464180913) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe
12:30:36.0488 2948 SmcService - ok
12:30:36.0660 2948 SNAC (7baaa607b3d6b9f6180a3f1746bf1a6a) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE
12:30:36.0675 2948 SNAC - ok
12:30:36.0847 2948 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
12:30:36.0863 2948 SNMPTRAP - ok
12:30:36.0925 2948 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
12:30:36.0925 2948 spldr - ok
12:30:37.0003 2948 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
12:30:37.0034 2948 Spooler - ok
12:30:37.0346 2948 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
12:30:37.0362 2948 sppsvc - ok
12:30:37.0518 2948 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
12:30:37.0549 2948 sppuinotify - ok
12:30:37.0674 2948 SRTSP (620df2e4eca4d3b18486a0976b731411) C:\Windows\system32\Drivers\SRTSP64.SYS
12:30:37.0689 2948 SRTSP - ok
12:30:37.0767 2948 SRTSPL (15ae63bfb22579a06d9dfdce3a094aa1) C:\Windows\system32\Drivers\SRTSPL64.SYS
12:30:37.0799 2948 SRTSPL - ok
12:30:37.0845 2948 SRTSPX (9560cf1b6b002b3277b427491f9e6819) C:\Windows\system32\Drivers\SRTSPX64.SYS
12:30:37.0861 2948 SRTSPX - ok
12:30:37.0923 2948 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
12:30:37.0939 2948 srv - ok
12:30:37.0986 2948 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
12:30:37.0986 2948 srv2 - ok
12:30:38.0017 2948 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
12:30:38.0017 2948 srvnet - ok
12:30:38.0064 2948 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
12:30:38.0079 2948 SSDPSRV - ok
12:30:38.0111 2948 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
12:30:38.0111 2948 SstpSvc - ok
12:30:38.0173 2948 ssudmdm (ad42ca614e086bcadbd53fffc404ac24) C:\Windows\system32\DRIVERS\ssudmdm.sys
12:30:38.0189 2948 ssudmdm - ok
12:30:38.0220 2948 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
12:30:38.0235 2948 stexstor - ok
12:30:38.0313 2948 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
12:30:38.0345 2948 stisvc - ok
12:30:38.0376 2948 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
12:30:38.0376 2948 swenum - ok
12:30:38.0438 2948 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
12:30:38.0469 2948 swprv - ok
12:30:38.0766 2948 Symantec AntiVirus (da035c6cd2684e3160b9d0a66176814c) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
12:30:38.0781 2948 Symantec AntiVirus - ok
12:30:38.0969 2948 SymEvent (70c8d165063eb76f1a373b74456d2aab) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
12:30:38.0984 2948 SymEvent - ok
12:30:39.0140 2948 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
12:30:39.0187 2948 SysMain - ok
12:30:39.0343 2948 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
12:30:39.0359 2948 TabletInputService - ok
12:30:39.0421 2948 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
12:30:39.0437 2948 TapiSrv - ok
12:30:39.0468 2948 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
12:30:39.0483 2948 TBS - ok
12:30:39.0702 2948 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
12:30:39.0749 2948 Tcpip - ok
12:30:40.0076 2948 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
12:30:40.0092 2948 TCPIP6 - ok
12:30:40.0201 2948 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
12:30:40.0217 2948 tcpipreg - ok
12:30:40.0232 2948 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
12:30:40.0248 2948 TDPIPE - ok
12:30:40.0279 2948 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
12:30:40.0295 2948 TDTCP - ok
12:30:40.0341 2948 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
12:30:40.0357 2948 tdx - ok
12:30:40.0404 2948 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
12:30:40.0404 2948 TermDD - ok
12:30:40.0497 2948 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
12:30:40.0513 2948 TermService - ok
12:30:40.0560 2948 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
12:30:40.0575 2948 Themes - ok
12:30:40.0591 2948 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:30:40.0607 2948 THREADORDER - ok
12:30:40.0622 2948 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
12:30:40.0638 2948 TrkWks - ok
12:30:40.0731 2948 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
12:30:40.0731 2948 TrustedInstaller - ok
12:30:40.0778 2948 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
12:30:40.0778 2948 tssecsrv - ok
12:30:40.0856 2948 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
12:30:40.0872 2948 TsUsbFlt - ok
12:30:40.0919 2948 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
12:30:40.0934 2948 tunnel - ok
12:30:40.0965 2948 TurboB (825e7a1f48fb8bcfba27c178aab4e275) C:\Windows\system32\DRIVERS\TurboB.sys
12:30:40.0981 2948 TurboB - ok
12:30:41.0075 2948 TurboBoost (b206be1174d5964d49a56bb6c4e0524a) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
12:30:41.0121 2948 TurboBoost - ok
12:30:41.0153 2948 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
12:30:41.0168 2948 uagp35 - ok
12:30:41.0246 2948 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
12:30:41.0262 2948 udfs - ok
12:30:41.0309 2948 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
12:30:41.0340 2948 UI0Detect - ok
12:30:41.0371 2948 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
12:30:41.0387 2948 uliagpkx - ok
12:30:41.0480 2948 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
12:30:41.0480 2948 umbus - ok
12:30:41.0527 2948 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
12:30:41.0527 2948 UmPass - ok
12:30:41.0777 2948 UNS (765f2dd351ba064f657751d8d75e58c0) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
12:30:41.0823 2948 UNS - ok
12:30:41.0995 2948 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
12:30:42.0026 2948 upnphost - ok
12:30:42.0089 2948 USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
12:30:42.0120 2948 USBAAPL64 - ok
12:30:42.0182 2948 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
12:30:42.0198 2948 usbaudio - ok
12:30:42.0245 2948 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
12:30:42.0245 2948 usbccgp - ok
12:30:42.0307 2948 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
12:30:42.0323 2948 usbcir - ok
12:30:42.0338 2948 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
12:30:42.0338 2948 usbehci - ok
12:30:42.0416 2948 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
12:30:42.0432 2948 usbhub - ok
12:30:42.0463 2948 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
12:30:42.0479 2948 usbohci - ok
12:30:42.0510 2948 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
12:30:42.0510 2948 usbprint - ok
12:30:42.0557 2948 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:30:42.0572 2948 USBSTOR - ok
12:30:42.0588 2948 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
12:30:42.0603 2948 usbuhci - ok
12:30:42.0666 2948 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
12:30:42.0666 2948 usbvideo - ok
12:30:42.0697 2948 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
12:30:42.0713 2948 UxSms - ok
12:30:42.0759 2948 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
12:30:42.0759 2948 VaultSvc - ok
12:30:42.0806 2948 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
12:30:42.0822 2948 vdrvroot - ok
12:30:42.0884 2948 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
12:30:42.0915 2948 vds - ok
12:30:42.0962 2948 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
12:30:42.0978 2948 vga - ok
12:30:42.0993 2948 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
12:30:42.0993 2948 VgaSave - ok
12:30:43.0056 2948 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
12:30:43.0071 2948 vhdmp - ok
12:30:43.0118 2948 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
12:30:43.0134 2948 viaide - ok
12:30:43.0181 2948 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
12:30:43.0181 2948 volmgr - ok
12:30:43.0259 2948 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
12:30:43.0259 2948 volmgrx - ok
12:30:43.0321 2948 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
12:30:43.0321 2948 volsnap - ok
12:30:43.0368 2948 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
12:30:43.0384 2948 vsmraid - ok
12:30:43.0555 2948 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
12:30:43.0618 2948 VSS - ok
12:30:43.0774 2948 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
12:30:43.0774 2948 vwifibus - ok
12:30:43.0820 2948 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
12:30:43.0820 2948 vwififlt - ok
12:30:43.0883 2948 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
12:30:43.0945 2948 W32Time - ok
12:30:43.0976 2948 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
12:30:43.0992 2948 WacomPen - ok
12:30:44.0039 2948 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
12:30:44.0039 2948 WANARP - ok
12:30:44.0054 2948 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
12:30:44.0054 2948 Wanarpv6 - ok
12:30:44.0226 2948 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
12:30:44.0257 2948 WatAdminSvc - ok
12:30:44.0413 2948 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
12:30:44.0476 2948 wbengine - ok
12:30:44.0632 2948 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
12:30:44.0663 2948 WbioSrvc - ok
12:30:44.0725 2948 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
12:30:44.0756 2948 wcncsvc - ok
12:30:44.0756 2948 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
12:30:44.0772 2948 WcsPlugInService - ok
12:30:44.0819 2948 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
12:30:44.0834 2948 Wd - ok
12:30:44.0912 2948 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
12:30:44.0912 2948 Wdf01000 - ok
12:30:44.0944 2948 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:30:44.0959 2948 WdiServiceHost - ok
12:30:44.0959 2948 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:30:44.0959 2948 WdiSystemHost - ok
12:30:45.0022 2948 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
12:30:45.0053 2948 WebClient - ok
12:30:45.0100 2948 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
12:30:45.0115 2948 Wecsvc - ok
12:30:45.0146 2948 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
12:30:45.0178 2948 wercplsupport - ok
12:30:45.0193 2948 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
12:30:45.0209 2948 WerSvc - ok
12:30:45.0287 2948 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
12:30:45.0287 2948 WfpLwf - ok
12:30:45.0302 2948 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
12:30:45.0318 2948 WIMMount - ok
12:30:45.0443 2948 WinFLdrv (0ae97898030bc89d64be429a88c33a7f) C:\Windows\syswow64\WinFLdrv.sys
12:30:45.0458 2948 Suspicious file (Hidden): C:\Windows\syswow64\WinFLdrv.sys. md5: 0ae97898030bc89d64be429a88c33a7f
12:30:45.0458 2948 WinFLdrv ( HiddenFile.Multi.Generic ) - warning
12:30:45.0458 2948 WinFLdrv - detected HiddenFile.Multi.Generic (1)
12:30:45.0474 2948 WinHttpAutoProxySvc - ok
12:30:45.0536 2948 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
12:30:45.0536 2948 Winmgmt - ok
12:30:45.0739 2948 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
12:30:45.0786 2948 WinRM - ok
12:30:46.0004 2948 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
12:30:46.0020 2948 WinUsb - ok
12:30:46.0129 2948 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
12:30:46.0145 2948 Wlansvc - ok
12:30:46.0254 2948 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
12:30:46.0270 2948 wlcrasvc - ok
12:30:46.0504 2948 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:30:46.0566 2948 wlidsvc - ok
12:30:46.0660 2948 wltrysvc (13b0a570e1ae451c92da550085d72cf3) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
12:30:46.0660 2948 wltrysvc - ok
12:30:46.0800 2948 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
12:30:46.0816 2948 WmiAcpi - ok
12:30:46.0878 2948 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
12:30:46.0894 2948 wmiApSrv - ok
12:30:46.0956 2948 WMPNetworkSvc - ok
12:30:47.0003 2948 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
12:30:47.0034 2948 WPCSvc - ok
12:30:47.0081 2948 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
12:30:47.0096 2948 WPDBusEnum - ok
12:30:47.0112 2948 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
12:30:47.0128 2948 ws2ifsl - ok
12:30:47.0128 2948 WSearch - ok
12:30:47.0346 2948 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
12:30:47.0408 2948 wuauserv - ok
12:30:47.0627 2948 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
12:30:47.0627 2948 WudfPf - ok
12:30:47.0658 2948 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
12:30:47.0674 2948 WUDFRd - ok
12:30:47.0705 2948 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
12:30:47.0705 2948 wudfsvc - ok
12:30:47.0752 2948 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
12:30:47.0783 2948 WwanSvc - ok
12:30:47.0830 2948 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
12:30:48.0329 2948 \Device\Harddisk0\DR0 - ok
12:30:48.0329 2948 Boot (0x1200) (bcde422f9e17126feff776f65757ce9b) \Device\Harddisk0\DR0\Partition0
12:30:48.0329 2948 \Device\Harddisk0\DR0\Partition0 - ok
12:30:48.0360 2948 Boot (0x1200) (9b5677c7b510331bda27fef1edff7577) \Device\Harddisk0\DR0\Partition1
12:30:48.0360 2948 \Device\Harddisk0\DR0\Partition1 - ok
12:30:48.0360 2948 ============================================================
12:30:48.0360 2948 Scan finished
12:30:48.0360 2948 ============================================================
12:30:48.0376 3416 Detected object count: 1
12:30:48.0376 3416 Actual detected object count: 1
12:31:03.0180 3416 WinFLdrv ( HiddenFile.Multi.Generic ) - skipped by user
12:31:03.0180 3416 WinFLdrv ( HiddenFile.Multi.Generic ) - User select action: Skip
12:31:54.0407 3204 Deinitialize success


-------------------------------------------------------------------------------------------

aswMBR1 log Below: (Please note that I'm not sure if it finished scanning because it stopped after a while but didn't say "finished scan") I can rescan if needed.

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-21 15:07:15
-----------------------------
15:07:15.057 OS Version: Windows x64 6.1.7601 Service Pack 1
15:07:15.057 Number of processors: 4 586 0x2502
15:07:15.057 ComputerName: PC UserName:
15:07:20.642 Initialize success
15:07:32.358 AVAST engine defs: 12052100
15:07:37.209 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
15:07:37.209 Disk 0 Vendor: WDC_WD3200BEVT-75A23T0 01.01A01 Size: 305245MB BusType: 11
15:07:37.240 Disk 0 MBR read successfully
15:07:37.240 Disk 0 MBR scan
15:07:37.256 Disk 0 Windows VISTA default MBR code
15:07:37.287 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
15:07:37.350 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10000 MB offset 206848
15:07:37.412 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 295141 MB offset 20686848
15:07:37.552 Disk 0 scanning C:\Windows\system32\drivers
15:08:39.907 Service scanning
15:11:11.570 Modules scanning
15:11:11.570 Disk 0 trace - called modules:
15:11:11.586 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
15:11:12.101 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004be4060]
15:11:12.101 3 CLASSPNP.SYS[fffff880019b943f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8004932060]
15:11:14.207 AVAST engine scan C:\Windows
15:11:26.297 AVAST engine scan C:\Windows\system32
15:19:47.974 AVAST engine scan C:\Windows\system32\drivers
15:20:33.165 AVAST engine scan C:\Users\Chung Hei Sing
16:33:53.740 AVAST engine scan C:\ProgramData
17:43:39.913 Disk 0 MBR has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\MBR.dat"
17:43:39.913 The log file has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\aswMBR1.txt"

--------------------------------------------------------

Eset Online Scanner is stuck at 91%
The Target file that it is stuck at is: C:\Users\Myusername\AppData\Local\Temp\av4158B.tmp
The Total scan time as of right now is 2:37:20

Should I restart the scan?

Thank you for your help.

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 21 May 2012 - 08:34 PM

Run aswmbr scan in safemode with networking


Download

ESET online scanner


Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply


Download

http://www.techspot.com/downloads/4716-malwarebytes-anti-malware.html

Install,update and run a full scan

Click on SHOW results.Select all infections and remove it

Reboot the PC and scan MBAM once in regular mode until you get a clean log

#5 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 21 May 2012 - 10:59 PM

aswMBR2 below:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-21 22:15:55
-----------------------------
22:15:55.945 OS Version: Windows x64 6.1.7601 Service Pack 1
22:15:55.945 Number of processors: 4 586 0x2502
22:15:55.945 ComputerName: PC UserName:
22:15:57.583 Initialize success
22:16:05.507 AVAST engine defs: 12052100
22:16:08.893 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
22:16:08.893 Disk 0 Vendor: WDC_WD3200BEVT-75A23T0 01.01A01 Size: 305245MB BusType: 11
22:16:08.939 Disk 0 MBR read successfully
22:16:08.939 Disk 0 MBR scan
22:16:08.939 Disk 0 Windows VISTA default MBR code
22:16:08.939 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
22:16:08.955 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10000 MB offset 206848
22:16:08.971 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 295141 MB offset 20686848
22:16:09.002 Disk 0 scanning C:\Windows\system32\drivers
22:16:20.873 Service scanning
22:17:11.580 Modules scanning
22:17:11.588 Disk 0 trace - called modules:
22:17:11.620 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
22:17:11.986 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004b87060]
22:17:11.990 3 CLASSPNP.SYS[fffff8800165143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048fa060]
22:17:13.575 AVAST engine scan C:\Windows
22:17:16.775 AVAST engine scan C:\Windows\system32
22:21:06.360 AVAST engine scan C:\Windows\system32\drivers
22:21:19.172 AVAST engine scan C:\Users\Chung Hei Sing
22:24:12.138 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1143.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:12.729 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1A68.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:12.913 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1FB7.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:13.055 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH28DB.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:13.278 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH2A6F.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:13.588 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3394.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:13.758 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH361.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:13.876 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH38D1.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.010 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3901.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.178 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH39CB.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.307 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3A66.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.443 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH437C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.588 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH520C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.737 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH523A.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:14.896 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH5798.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:15.030 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH64C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:15.195 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6A2D.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:15.331 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6AD8.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:15.567 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6EED.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:15.674 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6F8B.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:16.087 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH81A4.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:16.341 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH8693.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:16.696 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH936E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:16.961 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH9987.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:17.133 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH9EC4.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:17.394 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHAB81.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:17.564 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHB14B.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:17.811 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHB34D.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:17.986 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHC6BD.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:18.198 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHCB9E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:18.370 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHCD06.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:18.509 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHE3CF.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:18.655 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHE4CA.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:24:18.903 File: C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHFCCC.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:41:39.635 AVAST engine scan C:\ProgramData
22:46:52.136 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ1895.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.272 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ1923.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.389 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ19FF.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.479 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ1A1F.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.588 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ1C5D.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.717 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2392.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.765 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2431.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:52.876 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2460.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.026 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2668.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.213 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2688.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.350 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2707.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.477 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2871.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.574 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ292E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.634 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ294E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.693 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2A79.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.764 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2C5E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.847 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2CDC.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:53.965 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2CFC.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.062 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2D4B.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.102 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2D5C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.177 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2E76.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.253 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ2E96.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.343 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ370E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.401 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ3EEC.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.470 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ3F1C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.538 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4100.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.615 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4120.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.681 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4527.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.744 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4547.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.811 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ45B5.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.897 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ45D6.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:54.961 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ47BA.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.018 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ47EA.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.084 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4849.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.152 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4869.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.230 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ48A8.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.289 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ48C8.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.357 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4937.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.468 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ4947.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.539 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ56C0.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.701 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ56D0.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.824 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ582D.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.919 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ5AF6.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:55.988 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ63E4.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.054 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ7AE9.tmp **INFECTED** Win64:Sirefef-C [Drp]
22:46:56.124 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8CB6.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.221 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8CE5.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.283 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8D21.tmp **INFECTED** Win64:Sirefef-C [Drp]
22:46:56.361 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8D54.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.469 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8DB2.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.664 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8F39.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.799 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8F79.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:56.916 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8F7A.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.051 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8F8A.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.124 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8F9B.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.232 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8FBB.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.320 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9029.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.418 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9097.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.484 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9134.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.577 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9144.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.690 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ91B2.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.760 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9240.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.848 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9260.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:57.947 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ92BF.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.016 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ932D.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.102 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ93CA.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.153 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ93FA.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.222 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9458.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.260 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9469.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.363 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ94D7.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.436 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9564.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.486 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9575.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.572 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ95B4.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.632 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9632.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.695 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9681.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.759 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9692.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.828 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ96F0.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:58.919 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ976E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.014 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ98A7.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.081 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ9954.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.170 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQB46F.tmp **INFECTED** Win64:Sirefef-C [Drp]
22:46:59.253 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQB98F.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.331 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQB9EE.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.422 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQC7C1.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.494 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQDE9B.tmp **INFECTED** Win64:Sirefef-C [Drp]
22:46:59.607 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQE0DF.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.708 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQEA6F.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:46:59.774 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQF2C.tmp **INFECTED** Win32:Downloader-LYB [Trj]
22:47:15.202 File: C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer\4FAAFA6B.TMP **INFECTED** Win64:Sirefef-C [Drp]
22:47:15.307 File: C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer\4FB2F62E.TMP **INFECTED** Win64:Sirefef-C [Drp]
22:47:17.460 Scan finished successfully
22:48:01.190 Disk 0 MBR has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\MBR.dat"
22:48:01.195 The log file has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\aswMBR2.txt"


-----------------------------------------------

ESET list of threats:

C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer\4FAAFA6B.TMP Win64/Sirefef.E trojan cleaned by deleting - quarantined
C:\ProgramData\Symantec\Symantec Endpoint Protection\xfer\4FB2F62E.TMP Win64/Sirefef.E trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1143.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1A68.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH1FB7.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH28DB.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH2A6F.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3394.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH361.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH38D1.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3901.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH39CB.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH3A66.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH437C.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH520C.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH523A.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH5798.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH64C.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6A2D.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6AD8.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6EED.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH6F8B.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH81A4.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH8693.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH936E.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH9987.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWH9EC4.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHAB81.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHB14B.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHB34D.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHC6BD.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHCB9E.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHCD06.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHE3CF.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHE4CA.tmp Win32/TrojanClicker.Agent.NPA trojan cleaned by deleting - quarantined
C:\Users\Chung Hei Sing\AppData\Local\Temp\DWHFCCC.tmp a variant of Win32/Kryptik.XNC trojan cleaned by deleting - quarantined
------------------------------------------------

Will now proceed with Malwarebytes scan.

#6 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 23 May 2012 - 10:06 PM

Scanned in Safe Mode w/ Networking twice with Malwarebytes already. It removed some viruses, but it's still coming back. Symantec detection dialogue pops up. Trojan.Ransomlock along with the other three viruses are in that dialogue and it is being quarantined/logged.

Whenever it pops up it freezes my computer for a couple of minutes which really prevents me from getting much work done and delays the progress making it really inefficient.

I deeply appreciate any additional advice.

#7 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 23 May 2012 - 10:20 PM

Scanned in Safe Mode w/ Networking twice with Malwarebytes already.

Reboot to normal mode and run a scan again,If infections reoccur ,post the log here

good luck

#8 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 25 May 2012 - 10:18 PM

It's coming up again, going to scan in safe mode again, will get back to you once it is complete.

Thanks again!

#9 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 26 May 2012 - 10:49 AM

From aswBMR scan:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-26 09:25:51
-----------------------------
09:25:51.297 OS Version: Windows x64 6.1.7601 Service Pack 1
09:25:51.297 Number of processors: 4 586 0x2502
09:25:51.297 ComputerName: PC UserName:
09:25:52.889 Initialize success
09:26:01.874 AVAST engine defs: 12052501
09:26:06.648 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
09:26:06.648 Disk 0 Vendor: WDC_WD3200BEVT-75A23T0 01.01A01 Size: 305245MB BusType: 11
09:26:06.663 Disk 0 MBR read successfully
09:26:06.663 Disk 0 MBR scan
09:26:06.663 Disk 0 Windows VISTA default MBR code
09:26:06.679 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
09:26:06.679 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 10000 MB offset 206848
09:26:06.695 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 295141 MB offset 20686848
09:26:06.726 Disk 0 scanning C:\Windows\system32\drivers
09:26:19.752 Service scanning
09:26:56.162 Modules scanning
09:26:56.162 Disk 0 trace - called modules:
09:26:56.178 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
09:26:56.178 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004b87060]
09:26:56.178 3 CLASSPNP.SYS[fffff8800165143f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80048e9680]
09:26:57.909 AVAST engine scan C:\Windows
09:27:00.967 AVAST engine scan C:\Windows\system32
09:30:40.225 AVAST engine scan C:\Windows\system32\drivers
09:31:00.287 AVAST engine scan C:\Users\Chung Hei Sing
09:52:20.784 AVAST engine scan C:\ProgramData
09:58:10.428 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ52E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
09:58:10.521 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ7AE9.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.584 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8D21.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.708 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQB46F.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.818 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQDE9B.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:29.522 Scan finished successfully
10:00:52.995 Disk 0 MBR has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\MBR.dat"
10:00:52.995 The log file has been saved successfully to "C:\Users\Chung Hei Sing\Desktop\aswMBR3.txt"

I also rescanned it with ESET and TDSSKiller but no threats were found.

Please let me know what I should do next.

Thank you.

#10 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 26 May 2012 - 10:51 AM

Can you post your Malwarebytes log in normal mode?

#11 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 26 May 2012 - 09:27 PM

I also just noticed I have both Microsoft Security Essentials and Symantec Endpoint System enabled in the background. I'm not sure if this may be any problem.

Proceeding with scan now.

#12 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 26 May 2012 - 11:55 PM

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.05.26.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
xhongxkongx :: PC [administrator]

5/26/2012 11:20:17 PM
mbam-log-2012-05-26 (23-20-17).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 378925
Time elapsed: 1 hour(s), 24 minute(s), 1 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#13 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 27 May 2012 - 01:18 AM

09:58:10.428 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ52E.tmp **INFECTED** Win32:Downloader-LYB [Trj]
09:58:10.521 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ7AE9.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.584 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQ8D21.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.708 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQB46F.tmp **INFECTED** Win64:Sirefef-C [Drp]
09:58:10.818 File: C:\ProgramData\Symantec\SRTSP\Quarantine\APQDE9B.tmp **INFECTED** Win64:Sirefef-C [Drp]


The infections shown here are quarantined by symantec.See if you can clear the quarantined items.

What are your current issues?

Edited by narenxp, 27 May 2012 - 01:18 AM.


#14 xhongxkongx

xhongxkongx
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:03:38 AM

Posted 27 May 2012 - 10:14 PM

My issue/problem is that the virus dialogue for Symantec Endpoint keeps on popping up telling it is processing for example: Trojan.ransomlock, and when the status is "pending" meaning it is deciding what to do with the virus or it is quarantining the virus, it lags/freezes my computer for 5minutes. This happens every 15-20min making it hard for me to do any work.

Disabling Symantec Endpoint temporarily solves this problem, but it doesn't complete solve it; therefore I want to find a way to remove/clean the viruses I've mentioned in my original post.

#15 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:38 AM

Posted 28 May 2012 - 04:09 AM

My issue/problem is that the virus dialogue for Symantec Endpoint keeps on popping up telling it is processing for example: Trojan.ransomlock, and when the status is "pending" meaning it is deciding what to do with the virus or it is quarantining the virus

Dont you have an option to remove the quarantined items?

Follow this guide on removing them

http://www.symantec.com/business/support/index?page=content&id=TECH106444




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users