Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

"FBI" blocked my computer


  • Please log in to reply
32 replies to this topic

#1 monismama

monismama

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 01:51 PM

So I went to get on my computer and all of a sudden it came up with FBI blocked my computer and turned on my webcam and that i need to pay 200 dollars to get it unblocked.
i stuck a piece of tape over my webcam because thats just freaky all in itself lol and i got on my phone and searched it and it stated that it was a malware virus.

i restarted my computer and went into safe mode and i restored my computer to a earlier date. after that i did a malwarebytes quick scan and it found trojan.ransom and removed it.
i am now in the process of doing a full scan.

you think i will be okay now?

and i am a registered user. when i go into chat it tells me to identify by typing /msg NickServ IDENTIFY (password)
when i do that it tells me that my password is incorrect lol
im so lost on that thing.
but any assistance with anything would be helpful.

THANK YOU

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:18 PM

Posted 01 December 2012 - 02:06 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here.If you get crashes in normal mode,run it in safemode with networking

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 02:25 PM

12:21:47.0173 4212 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
12:21:47.0563 4212 ============================================================
12:21:47.0563 4212 Current date / time: 2012/12/01 12:21:47.0563
12:21:47.0563 4212 SystemInfo:
12:21:47.0563 4212
12:21:47.0563 4212 OS Version: 6.1.7600 ServicePack: 0.0
12:21:47.0563 4212 Product type: Workstation
12:21:47.0563 4212 ComputerName: RANDI-PC
12:21:47.0563 4212 UserName: Randi
12:21:47.0563 4212 Windows directory: C:\Windows
12:21:47.0563 4212 System windows directory: C:\Windows
12:21:47.0563 4212 Running under WOW64
12:21:47.0563 4212 Processor architecture: Intel x64
12:21:47.0563 4212 Number of processors: 2
12:21:47.0563 4212 Page size: 0x1000
12:21:47.0563 4212 Boot type: Normal boot
12:21:47.0563 4212 ============================================================
12:21:51.0463 4212 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:21:51.0473 4212 ============================================================
12:21:51.0473 4212 \Device\Harddisk0\DR0:
12:21:51.0473 4212 MBR partitions:
12:21:51.0473 4212 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000
12:21:51.0473 4212 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x236CE2B0
12:21:51.0473 4212 ============================================================
12:21:51.0533 4212 C: <-> \Device\Harddisk0\DR0\Partition2
12:21:51.0533 4212 ============================================================
12:21:51.0533 4212 Initialize success
12:21:51.0533 4212 ============================================================
12:22:23.0783 0240 ============================================================
12:22:23.0783 0240 Scan started
12:22:23.0783 0240 Mode: Manual; TDLFS;
12:22:23.0783 0240 ============================================================
12:22:24.0433 0240 ================ Scan system memory ========================
12:22:24.0433 0240 System memory - ok
12:22:24.0443 0240 ================ Scan services =============================
12:22:25.0003 0240 [ 1B00662092F9F9568B995902F0CC40D5 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
12:22:25.0043 0240 1394ohci - ok
12:22:25.0173 0240 [ 6F11E88748CDEFD2F76AA215F97DDFE5 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
12:22:25.0183 0240 ACPI - ok
12:22:25.0433 0240 [ 63B05A0420CE4BF0E4AF6DCC7CADA254 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
12:22:25.0433 0240 AcpiPmi - ok
12:22:25.0793 0240 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:22:25.0803 0240 AdobeFlashPlayerUpdateSvc - ok
12:22:25.0963 0240 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
12:22:26.0023 0240 adp94xx - ok
12:22:26.0093 0240 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
12:22:26.0103 0240 adpahci - ok
12:22:26.0213 0240 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
12:22:26.0233 0240 adpu320 - ok
12:22:26.0283 0240 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
12:22:26.0283 0240 AeLookupSvc - ok
12:22:26.0433 0240 [ DB9D6C6B2CD95A9CA414D045B627422E ] AFD C:\Windows\system32\drivers\afd.sys
12:22:26.0453 0240 AFD - ok
12:22:26.0523 0240 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
12:22:26.0533 0240 agp440 - ok
12:22:26.0573 0240 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
12:22:26.0583 0240 ALG - ok
12:22:26.0693 0240 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
12:22:26.0693 0240 aliide - ok
12:22:26.0753 0240 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\DRIVERS\amdide.sys
12:22:26.0753 0240 amdide - ok
12:22:26.0843 0240 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
12:22:26.0843 0240 AmdK8 - ok
12:22:26.0863 0240 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
12:22:26.0863 0240 AmdPPM - ok
12:22:26.0933 0240 [ EC7EBAB00A4D8448BAB68D1E49B4BEB9 ] amdsata C:\Windows\system32\drivers\amdsata.sys
12:22:26.0943 0240 amdsata - ok
12:22:26.0973 0240 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
12:22:27.0003 0240 amdsbs - ok
12:22:27.0033 0240 [ DB27766102C7BF7E95140A2AA81D042E ] amdxata C:\Windows\system32\drivers\amdxata.sys
12:22:27.0043 0240 amdxata - ok
12:22:27.0153 0240 [ 42FD751B27FA0E9C69BB39F39E409594 ] AppID C:\Windows\system32\drivers\appid.sys
12:22:27.0153 0240 AppID - ok
12:22:27.0203 0240 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
12:22:27.0203 0240 AppIDSvc - ok
12:22:27.0253 0240 [ D065BE66822847B7F127D1F90158376E ] Appinfo C:\Windows\System32\appinfo.dll
12:22:27.0253 0240 Appinfo - ok
12:22:27.0313 0240 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
12:22:27.0313 0240 arc - ok
12:22:27.0333 0240 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
12:22:27.0343 0240 arcsas - ok
12:22:27.0383 0240 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
12:22:27.0383 0240 AsyncMac - ok
12:22:27.0423 0240 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\DRIVERS\atapi.sys
12:22:27.0433 0240 atapi - ok
12:22:27.0573 0240 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:22:27.0593 0240 AudioEndpointBuilder - ok
12:22:27.0663 0240 [ 07721A77180EDD4D39CCB865BF63C7FD ] AudioSrv C:\Windows\System32\Audiosrv.dll
12:22:27.0673 0240 AudioSrv - ok
12:22:27.0763 0240 [ B20B5FA5CA050E9926E4D1DB81501B32 ] AxInstSV C:\Windows\System32\AxInstSV.dll
12:22:27.0773 0240 AxInstSV - ok
12:22:27.0863 0240 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
12:22:27.0923 0240 b06bdrv - ok
12:22:27.0983 0240 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
12:22:28.0053 0240 b57nd60a - ok
12:22:28.0233 0240 [ 01A24B415926BB5F772DBE12459D97DE ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
12:22:28.0263 0240 BBSvc - ok
12:22:28.0333 0240 [ 785DE7ABDA13309D6065305542829E76 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
12:22:28.0343 0240 BBUpdate - ok
12:22:28.0433 0240 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
12:22:28.0433 0240 BDESVC - ok
12:22:28.0533 0240 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
12:22:28.0543 0240 Beep - ok
12:22:28.0673 0240 [ 4992C609A6315671463E30F6512BC022 ] BFE C:\Windows\System32\bfe.dll
12:22:28.0733 0240 BFE - ok
12:22:28.0883 0240 [ 7F0C323FE3DA28AA4AA1BDA3F575707F ] BITS C:\Windows\System32\qmgr.dll
12:22:28.0923 0240 BITS - ok
12:22:28.0963 0240 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
12:22:28.0963 0240 blbdrive - ok
12:22:29.0083 0240 [ 19D20159708E152267E53B66677A4995 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
12:22:29.0083 0240 bowser - ok
12:22:29.0143 0240 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:22:29.0153 0240 BrFiltLo - ok
12:22:29.0233 0240 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:22:29.0233 0240 BrFiltUp - ok
12:22:29.0273 0240 [ 6B054C67AAA87843504E8E3C09102009 ] Browser C:\Windows\System32\browser.dll
12:22:29.0273 0240 Browser - ok
12:22:29.0333 0240 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
12:22:29.0333 0240 Brserid - ok
12:22:29.0373 0240 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
12:22:29.0383 0240 BrSerWdm - ok
12:22:29.0463 0240 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
12:22:29.0473 0240 BrUsbMdm - ok
12:22:29.0483 0240 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
12:22:29.0483 0240 BrUsbSer - ok
12:22:29.0533 0240 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
12:22:29.0543 0240 BTHMODEM - ok
12:22:29.0623 0240 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
12:22:29.0623 0240 bthserv - ok
12:22:29.0663 0240 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
12:22:29.0673 0240 cdfs - ok
12:22:29.0723 0240 [ 83D2D75E1EFB81B3450C18131443F7DB ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
12:22:29.0723 0240 cdrom - ok
12:22:29.0783 0240 [ 312E2F82AF11E79906898AC3E3D58A1F ] CertPropSvc C:\Windows\System32\certprop.dll
12:22:29.0783 0240 CertPropSvc - ok
12:22:29.0863 0240 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
12:22:29.0863 0240 circlass - ok
12:22:29.0893 0240 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
12:22:29.0903 0240 CLFS - ok
12:22:29.0993 0240 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:22:29.0993 0240 clr_optimization_v2.0.50727_32 - ok
12:22:30.0153 0240 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:22:30.0183 0240 clr_optimization_v2.0.50727_64 - ok
12:22:30.0633 0240 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:22:30.0723 0240 clr_optimization_v4.0.30319_32 - ok
12:22:30.0863 0240 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:22:30.0903 0240 clr_optimization_v4.0.30319_64 - ok
12:22:30.0943 0240 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
12:22:30.0943 0240 CmBatt - ok
12:22:30.0983 0240 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
12:22:30.0983 0240 cmdide - ok
12:22:31.0133 0240 [ CA7720B73446FDDEC5C69519C1174C98 ] CNG C:\Windows\system32\Drivers\cng.sys
12:22:31.0163 0240 CNG - ok
12:22:31.0223 0240 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
12:22:31.0223 0240 Compbatt - ok
12:22:31.0263 0240 [ F26B3A86F6FA87CA360B879581AB4123 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
12:22:31.0273 0240 CompositeBus - ok
12:22:31.0293 0240 COMSysApp - ok
12:22:31.0343 0240 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
12:22:31.0343 0240 crcdisk - ok
12:22:31.0423 0240 [ BAF19B633933A9FB4883D27D66C39E9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
12:22:31.0423 0240 CryptSvc - ok
12:22:31.0483 0240 [ ED5CF92396A62F4C15110DCDB5E854D9 ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
12:22:31.0483 0240 CtClsFlt - ok
12:22:31.0593 0240 [ E6CE7188CC47AE5DAFDAF552D370C52F ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys
12:22:31.0593 0240 dc3d - ok
12:22:31.0713 0240 [ 7266972E86890E2B30C0C322E906B027 ] DcomLaunch C:\Windows\system32\rpcss.dll
12:22:31.0743 0240 DcomLaunch - ok
12:22:31.0823 0240 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
12:22:31.0853 0240 defragsvc - ok
12:22:31.0933 0240 [ 9C253CE7311CA60FC11C774692A13208 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
12:22:31.0933 0240 DfsC - ok
12:22:32.0053 0240 [ CE3B9562D997F69B330D181A8875960F ] Dhcp C:\Windows\system32\dhcpcore.dll
12:22:32.0093 0240 Dhcp - ok
12:22:32.0133 0240 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
12:22:32.0143 0240 discache - ok
12:22:32.0183 0240 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
12:22:32.0183 0240 Disk - ok
12:22:32.0223 0240 [ 85CF424C74A1D5EC33533E1DBFF9920A ] Dnscache C:\Windows\System32\dnsrslvr.dll
12:22:32.0243 0240 Dnscache - ok
12:22:32.0413 0240 [ 0840ABBBDF438691EE65A20040635CBE ] DockLoginService C:\Program Files\Dell\DellDock\DockLogin.exe
12:22:32.0413 0240 DockLoginService - ok
12:22:32.0463 0240 [ 14452ACDB09B70964C8C21BF80A13ACB ] dot3svc C:\Windows\System32\dot3svc.dll
12:22:32.0503 0240 dot3svc - ok
12:22:32.0523 0240 [ 8C2BA6BEA949EE6E68385F5692BAFB94 ] DPS C:\Windows\system32\dps.dll
12:22:32.0523 0240 DPS - ok
12:22:32.0583 0240 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
12:22:32.0583 0240 drmkaud - ok
12:22:32.0823 0240 [ 1633B9ABF52784A1331476397A48CBEF ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
12:22:32.0853 0240 DXGKrnl - ok
12:22:32.0893 0240 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
12:22:32.0903 0240 EapHost - ok
12:22:33.0293 0240 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
12:22:33.0383 0240 ebdrv - ok
12:22:33.0423 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] EFS C:\Windows\System32\lsass.exe
12:22:33.0433 0240 EFS - ok
12:22:33.0563 0240 [ 47C071994C3F649F23D9CD075AC9304A ] ehRecvr C:\Windows\ehome\ehRecvr.exe
12:22:33.0593 0240 ehRecvr - ok
12:22:33.0693 0240 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
12:22:33.0693 0240 ehSched - ok
12:22:33.0853 0240 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
12:22:33.0943 0240 elxstor - ok
12:22:33.0963 0240 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
12:22:33.0973 0240 ErrDev - ok
12:22:34.0043 0240 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
12:22:34.0083 0240 EventSystem - ok
12:22:34.0113 0240 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
12:22:34.0133 0240 exfat - ok
12:22:34.0153 0240 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
12:22:34.0163 0240 fastfat - ok
12:22:34.0293 0240 [ D607B2F1BEE3992AA6C2C92C0A2F0855 ] Fax C:\Windows\system32\fxssvc.exe
12:22:34.0333 0240 Fax - ok
12:22:34.0403 0240 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
12:22:34.0413 0240 fdc - ok
12:22:34.0473 0240 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
12:22:34.0473 0240 fdPHost - ok
12:22:34.0493 0240 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
12:22:34.0493 0240 FDResPub - ok
12:22:34.0543 0240 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
12:22:34.0543 0240 FileInfo - ok
12:22:34.0573 0240 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
12:22:34.0583 0240 Filetrace - ok
12:22:34.0623 0240 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
12:22:34.0633 0240 flpydisk - ok
12:22:34.0713 0240 [ F7866AF72ABBAF84B1FA5AA195378C59 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
12:22:34.0733 0240 FltMgr - ok
12:22:34.0883 0240 [ BC00505CFDA789ED3BE95D2FF38C4875 ] FontCache C:\Windows\system32\FntCache.dll
12:22:34.0933 0240 FontCache - ok
12:22:35.0023 0240 [ 8D89E3131C27FDD6932189CB785E1B7A ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:22:35.0023 0240 FontCache3.0.0.0 - ok
12:22:35.0073 0240 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
12:22:35.0083 0240 FsDepends - ok
12:22:35.0123 0240 [ D3E3F93D67821A2DB2B3D9FAC2DC2064 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
12:22:35.0133 0240 Fs_Rec - ok
12:22:35.0213 0240 [ AE87BA80D0EC3B57126ED2CDC15B24ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
12:22:35.0213 0240 fvevol - ok
12:22:35.0253 0240 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
12:22:35.0263 0240 gagp30kx - ok
12:22:35.0403 0240 [ C1BBCE4B30B45410178EE674C818D10C ] GameConsoleService C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
12:22:35.0453 0240 GameConsoleService - ok
12:22:35.0633 0240 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
12:22:35.0643 0240 GoToAssist - ok
12:22:35.0803 0240 [ FE5AB4525BC2EC68B9119A6E5D40128B ] gpsvc C:\Windows\System32\gpsvc.dll
12:22:35.0873 0240 gpsvc - ok
12:22:35.0923 0240 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
12:22:35.0923 0240 hcw85cir - ok
12:22:35.0993 0240 [ 0A49913402747A0B67DE940FB42CBDBB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
12:22:35.0993 0240 HDAudBus - ok
12:22:36.0033 0240 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
12:22:36.0063 0240 HidBatt - ok
12:22:36.0073 0240 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
12:22:36.0073 0240 HidBth - ok
12:22:36.0113 0240 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
12:22:36.0113 0240 HidIr - ok
12:22:36.0153 0240 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
12:22:36.0153 0240 hidserv - ok
12:22:36.0223 0240 [ B3BF6B5B50006DEF50B66306D99FCF6F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
12:22:36.0223 0240 HidUsb - ok
12:22:36.0293 0240 [ EFA58EDE58DD74388FFD04CB32681518 ] hkmsvc C:\Windows\system32\kmsvc.dll
12:22:36.0353 0240 hkmsvc - ok
12:22:36.0433 0240 [ 046B2673767CA626E2CFB7FDF735E9E8 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:22:36.0433 0240 HomeGroupListener - ok
12:22:36.0493 0240 [ 06A7422224D9865A5613710A089987DF ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:22:36.0513 0240 HomeGroupProvider - ok
12:22:36.0553 0240 [ 0886D440058F203EBA0E1825E4355914 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
12:22:36.0563 0240 HpSAMD - ok
12:22:36.0783 0240 [ CEE049CAC4EFA7F4E1E4AD014414A5D4 ] HTTP C:\Windows\system32\drivers\HTTP.sys
12:22:36.0823 0240 HTTP - ok
12:22:36.0863 0240 [ F17766A19145F111856378DF337A5D79 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
12:22:36.0873 0240 hwpolicy - ok
12:22:36.0923 0240 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
12:22:36.0923 0240 i8042prt - ok
12:22:37.0043 0240 [ 7548066DF68A8A1A56B043359F915F37 ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
12:22:37.0053 0240 IAANTMON - ok
12:22:37.0133 0240 [ 1D004CB1DA6323B1F55CAEF7F94B61D9 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
12:22:37.0133 0240 iaStor - ok
12:22:37.0223 0240 [ B75E45C564E944A2657167D197AB29DA ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
12:22:37.0253 0240 iaStorV - ok
12:22:37.0373 0240 [ 2F2BE70D3E02B6FA877921AB9516D43C ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:22:37.0413 0240 idsvc - ok
12:22:37.0713 0240 [ BABD5F9B2BCC82CE556A0BAF1AE208A7 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
12:22:37.0863 0240 igfx - ok
12:22:37.0923 0240 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
12:22:37.0923 0240 iirsp - ok
12:22:38.0023 0240 [ C5B4683680DF085B57BC53E5EF34861F ] IKEEXT C:\Windows\System32\ikeext.dll
12:22:38.0063 0240 IKEEXT - ok
12:22:38.0113 0240 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\DRIVERS\intelide.sys
12:22:38.0113 0240 intelide - ok
12:22:38.0183 0240 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
12:22:38.0183 0240 intelppm - ok
12:22:38.0233 0240 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
12:22:38.0233 0240 IPBusEnum - ok
12:22:38.0243 0240 [ 722DD294DF62483CECAAE6E094B4D695 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:22:38.0253 0240 IpFilterDriver - ok
12:22:38.0363 0240 [ F8E058D17363EC580E4B7232778B6CB5 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
12:22:38.0423 0240 iphlpsvc - ok
12:22:38.0463 0240 [ E2B4A4494DB7CB9B89B55CA268C337C5 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:22:38.0473 0240 IPMIDRV - ok
12:22:38.0483 0240 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
12:22:38.0483 0240 IPNAT - ok
12:22:38.0523 0240 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
12:22:38.0523 0240 IRENUM - ok
12:22:38.0583 0240 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
12:22:38.0583 0240 isapnp - ok
12:22:38.0643 0240 [ FA4D2557DE56D45B0A346F93564BE6E1 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
12:22:38.0643 0240 iScsiPrt - ok
12:22:38.0713 0240 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
12:22:38.0713 0240 kbdclass - ok
12:22:38.0763 0240 [ 6DEF98F8541E1B5DCEB2C822A11F7323 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
12:22:38.0763 0240 kbdhid - ok
12:22:38.0783 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] KeyIso C:\Windows\system32\lsass.exe
12:22:38.0783 0240 KeyIso - ok
12:22:38.0843 0240 [ 4F4B5FDE429416877DE7143044582EB5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
12:22:38.0863 0240 KSecDD - ok
12:22:38.0933 0240 [ 6F40465A44ECDC1731BEFAFEC5BDD03C ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
12:22:38.0943 0240 KSecPkg - ok
12:22:39.0003 0240 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
12:22:39.0003 0240 ksthunk - ok
12:22:39.0063 0240 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
12:22:39.0093 0240 KtmRm - ok
12:22:39.0173 0240 [ 81F1D04D4D0E433099365127375FD501 ] LanmanServer C:\Windows\system32\srvsvc.dll
12:22:39.0213 0240 LanmanServer - ok
12:22:39.0283 0240 [ 27026EAC8818E8A6C00A1CAD2F11D29A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:22:39.0293 0240 LanmanWorkstation - ok
12:22:39.0373 0240 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
12:22:39.0383 0240 lltdio - ok
12:22:39.0433 0240 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
12:22:39.0443 0240 lltdsvc - ok
12:22:39.0483 0240 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
12:22:39.0483 0240 lmhosts - ok
12:22:39.0543 0240 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
12:22:39.0553 0240 LSI_FC - ok
12:22:39.0563 0240 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
12:22:39.0563 0240 LSI_SAS - ok
12:22:39.0573 0240 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:22:39.0573 0240 LSI_SAS2 - ok
12:22:39.0603 0240 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:22:39.0603 0240 LSI_SCSI - ok
12:22:39.0643 0240 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
12:22:39.0643 0240 luafv - ok
12:22:39.0693 0240 [ F84C8F1000BC11E3B7B23CBD3BAFF111 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
12:22:39.0703 0240 Mcx2Svc - ok
12:22:39.0733 0240 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
12:22:39.0733 0240 megasas - ok
12:22:39.0803 0240 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
12:22:39.0813 0240 MegaSR - ok
12:22:39.0883 0240 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
12:22:39.0883 0240 MMCSS - ok
12:22:39.0913 0240 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
12:22:39.0913 0240 Modem - ok
12:22:39.0963 0240 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
12:22:39.0973 0240 monitor - ok
12:22:40.0033 0240 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
12:22:40.0033 0240 mouclass - ok
12:22:40.0083 0240 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
12:22:40.0083 0240 mouhid - ok
12:22:40.0123 0240 [ 791AF66C4D0E7C90A3646066386FB571 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
12:22:40.0133 0240 mountmgr - ok
12:22:40.0263 0240 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:22:40.0263 0240 MozillaMaintenance - ok
12:22:40.0353 0240 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
12:22:40.0353 0240 MpFilter - ok
12:22:40.0393 0240 [ 609D1D87649ECC19796F4D76D4C15CEA ] mpio C:\Windows\system32\DRIVERS\mpio.sys
12:22:40.0423 0240 mpio - ok
12:22:40.0453 0240 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
12:22:40.0463 0240 mpsdrv - ok
12:22:40.0553 0240 [ AECAB449567D1846DAD63ECE49E893E3 ] MpsSvc C:\Windows\system32\mpssvc.dll
12:22:40.0593 0240 MpsSvc - ok
12:22:40.0663 0240 [ 30524261BB51D96D6FCBAC20C810183C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
12:22:40.0703 0240 MRxDAV - ok
12:22:40.0773 0240 [ 040D62A9D8AD28922632137ACDD984F2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
12:22:40.0783 0240 mrxsmb - ok
12:22:40.0873 0240 [ F0067552F8F9B33D7C59403AB808A3CB ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:22:40.0883 0240 mrxsmb10 - ok
12:22:40.0943 0240 [ 3C142D31DE9F2F193218A53FE2632051 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:22:40.0983 0240 mrxsmb20 - ok
12:22:41.0043 0240 [ BCCF16D5FB1109162380E3E28DC9E4E5 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
12:22:41.0053 0240 msahci - ok
12:22:41.0073 0240 [ 8D27B597229AED79430FB9DB3BCBFBD0 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
12:22:41.0103 0240 msdsm - ok
12:22:41.0113 0240 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
12:22:41.0123 0240 MSDTC - ok
12:22:41.0153 0240 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
12:22:41.0153 0240 Msfs - ok
12:22:41.0213 0240 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
12:22:41.0213 0240 mshidkmdf - ok
12:22:41.0243 0240 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
12:22:41.0253 0240 msisadrv - ok
12:22:41.0283 0240 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
12:22:41.0283 0240 MSiSCSI - ok
12:22:41.0293 0240 msiserver - ok
12:22:41.0333 0240 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
12:22:41.0333 0240 MSKSSRV - ok
12:22:41.0463 0240 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
12:22:41.0463 0240 MsMpSvc - ok
12:22:41.0513 0240 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
12:22:41.0523 0240 MSPCLOCK - ok
12:22:41.0523 0240 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
12:22:41.0533 0240 MSPQM - ok
12:22:41.0563 0240 [ 89CB141AA8616D8C6A4610FA26C60964 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
12:22:41.0573 0240 MsRPC - ok
12:22:41.0593 0240 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
12:22:41.0593 0240 mssmbios - ok
12:22:41.0663 0240 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
12:22:41.0673 0240 MSTEE - ok
12:22:41.0683 0240 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
12:22:41.0693 0240 MTConfig - ok
12:22:41.0743 0240 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
12:22:41.0743 0240 Mup - ok
12:22:41.0793 0240 [ 4987E079A4530FA737A128BE54B63B12 ] napagent C:\Windows\system32\qagentRT.dll
12:22:41.0823 0240 napagent - ok
12:22:41.0913 0240 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
12:22:41.0953 0240 NativeWifiP - ok
12:22:42.0113 0240 [ CAD515DBD07D082BB317D9928CE8962C ] NDIS C:\Windows\system32\drivers\ndis.sys
12:22:42.0143 0240 NDIS - ok
12:22:42.0203 0240 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
12:22:42.0213 0240 NdisCap - ok
12:22:42.0283 0240 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
12:22:42.0283 0240 NdisTapi - ok
12:22:42.0373 0240 [ F105BA1E22BF1F2EE8F005D4305E4BEC ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
12:22:42.0373 0240 Ndisuio - ok
12:22:42.0433 0240 [ 557DFAB9CA1FCB036AC77564C010DAD3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
12:22:42.0433 0240 NdisWan - ok
12:22:42.0463 0240 [ 659B74FB74B86228D6338D643CD3E3CF ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
12:22:42.0463 0240 NDProxy - ok
12:22:42.0533 0240 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
12:22:42.0543 0240 NetBIOS - ok
12:22:42.0603 0240 [ 9162B273A44AB9DCE5B44362731D062A ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
12:22:42.0613 0240 NetBT - ok
12:22:42.0633 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] Netlogon C:\Windows\system32\lsass.exe
12:22:42.0643 0240 Netlogon - ok
12:22:42.0743 0240 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
12:22:42.0773 0240 Netman - ok
12:22:42.0873 0240 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
12:22:42.0893 0240 netprofm - ok
12:22:42.0933 0240 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:22:42.0933 0240 NetTcpPortSharing - ok
12:22:43.0423 0240 [ 4D85A450EDEF10C38882182753A49AAE ] NETw5s64 C:\Windows\system32\DRIVERS\NETw5s64.sys
12:22:43.0603 0240 NETw5s64 - ok
12:22:43.0663 0240 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
12:22:43.0663 0240 nfrd960 - ok
12:22:43.0733 0240 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
12:22:43.0743 0240 NisDrv - ok
12:22:43.0763 0240 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
12:22:43.0763 0240 NisSrv - ok
12:22:43.0843 0240 [ D9A0CE66046D6EFA0C61BAA885CBA0A8 ] NlaSvc C:\Windows\System32\nlasvc.dll
12:22:43.0863 0240 NlaSvc - ok
12:22:43.0893 0240 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
12:22:43.0913 0240 Npfs - ok
12:22:43.0943 0240 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
12:22:43.0943 0240 nsi - ok
12:22:43.0963 0240 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
12:22:43.0963 0240 nsiproxy - ok
12:22:44.0153 0240 [ 184C189D4FC416978550FC599BB4EDDA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
12:22:44.0233 0240 Ntfs - ok
12:22:44.0273 0240 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
12:22:44.0283 0240 Null - ok
12:22:44.0443 0240 [ A4D9C9A608A97F59307C2F2600EDC6A4 ] nvraid C:\Windows\system32\drivers\nvraid.sys
12:22:44.0443 0240 nvraid - ok
12:22:44.0493 0240 [ 6C1D5F70E7A6A3FD1C90D840EDC048B9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
12:22:44.0513 0240 nvstor - ok
12:22:44.0533 0240 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
12:22:44.0553 0240 nv_agp - ok
12:22:44.0723 0240 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:22:44.0743 0240 odserv - ok
12:22:44.0773 0240 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
12:22:44.0773 0240 ohci1394 - ok
12:22:44.0833 0240 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:22:44.0863 0240 ose - ok
12:22:44.0923 0240 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
12:22:44.0933 0240 p2pimsvc - ok
12:22:45.0013 0240 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
12:22:45.0013 0240 p2psvc - ok
12:22:45.0083 0240 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
12:22:45.0083 0240 Parport - ok
12:22:45.0163 0240 [ 90061B1ACFE8CCAA5345750FFE08D8B8 ] partmgr C:\Windows\system32\drivers\partmgr.sys
12:22:45.0173 0240 partmgr - ok
12:22:45.0233 0240 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
12:22:45.0233 0240 PcaSvc - ok
12:22:45.0283 0240 [ F36F6504009F2FB0DFD1B17A116AD74B ] pci C:\Windows\system32\DRIVERS\pci.sys
12:22:45.0283 0240 pci - ok
12:22:45.0313 0240 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\DRIVERS\pciide.sys
12:22:45.0313 0240 pciide - ok
12:22:45.0393 0240 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
12:22:45.0403 0240 pcmcia - ok
12:22:45.0413 0240 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
12:22:45.0413 0240 pcw - ok
12:22:45.0553 0240 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:22:45.0573 0240 PEAUTH - ok
12:22:45.0703 0240 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
12:22:45.0713 0240 PerfHost - ok
12:22:45.0863 0240 [ 557E9A86F65F0DE18C9B6751DFE9D3F1 ] pla C:\Windows\system32\pla.dll
12:22:45.0913 0240 pla - ok
12:22:46.0023 0240 [ 98B1721B8718164293B9701B98C52D77 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:22:46.0043 0240 PlugPlay - ok
12:22:46.0083 0240 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
12:22:46.0093 0240 PNRPAutoReg - ok
12:22:46.0123 0240 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
12:22:46.0133 0240 PNRPsvc - ok
12:22:46.0253 0240 [ 166EB40D1F5B47E615DE3D0FFFE5F243 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:22:46.0303 0240 PolicyAgent - ok
12:22:46.0363 0240 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
12:22:46.0383 0240 Power - ok
12:22:46.0463 0240 [ 27CC19E81BA5E3403C48302127BDA717 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:22:46.0473 0240 PptpMiniport - ok
12:22:46.0493 0240 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
12:22:46.0503 0240 Processor - ok
12:22:46.0553 0240 [ 97293447431311C06703368AD0F6C4BE ] ProfSvc C:\Windows\system32\profsvc.dll
12:22:46.0563 0240 ProfSvc - ok
12:22:46.0583 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:22:46.0583 0240 ProtectedStorage - ok
12:22:46.0623 0240 [ EE992183BD8EAEFD9973F352E587A299 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
12:22:46.0633 0240 Psched - ok
12:22:46.0683 0240 [ 4712CC14E720ECCCC0AA16949D18AAF1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys
12:22:46.0683 0240 PxHlpa64 - ok
12:22:46.0733 0240 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
12:22:46.0763 0240 ql2300 - ok
12:22:46.0833 0240 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
12:22:46.0843 0240 ql40xx - ok
12:22:46.0943 0240 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
12:22:46.0953 0240 QWAVE - ok
12:22:46.0973 0240 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:22:46.0983 0240 QWAVEdrv - ok
12:22:47.0023 0240 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:22:47.0023 0240 RasAcd - ok
12:22:47.0063 0240 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
12:22:47.0063 0240 RasAgileVpn - ok
12:22:47.0103 0240 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
12:22:47.0113 0240 RasAuto - ok
12:22:47.0143 0240 [ 87A6E852A22991580D6D39ADC4790463 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:22:47.0153 0240 Rasl2tp - ok
12:22:47.0163 0240 [ 47394ED3D16D053F5906EFE5AB51CC83 ] RasMan C:\Windows\System32\rasmans.dll
12:22:47.0173 0240 RasMan - ok
12:22:47.0243 0240 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:22:47.0263 0240 RasPppoe - ok
12:22:47.0313 0240 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:22:47.0323 0240 RasSstp - ok
12:22:47.0363 0240 [ 3BAC8142102C15D59A87757C1D41DCE5 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:22:47.0363 0240 rdbss - ok
12:22:47.0383 0240 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
12:22:47.0393 0240 rdpbus - ok
12:22:47.0463 0240 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:22:47.0463 0240 RDPCDD - ok
12:22:47.0483 0240 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:22:47.0483 0240 RDPENCDD - ok
12:22:47.0503 0240 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
12:22:47.0503 0240 RDPREFMP - ok
12:22:47.0543 0240 [ 447DE7E3DEA39D422C1504F245B668B1 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:22:47.0553 0240 RDPWD - ok
12:22:47.0643 0240 [ 634B9A2181D98F15941236886164EC8B ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
12:22:47.0653 0240 rdyboost - ok
12:22:47.0693 0240 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:22:47.0703 0240 RemoteAccess - ok
12:22:47.0823 0240 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:22:47.0853 0240 RemoteRegistry - ok
12:22:47.0863 0240 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
12:22:47.0873 0240 RpcEptMapper - ok
12:22:47.0903 0240 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
12:22:47.0913 0240 RpcLocator - ok
12:22:47.0943 0240 [ 7266972E86890E2B30C0C322E906B027 ] RpcSs C:\Windows\system32\rpcss.dll
12:22:47.0953 0240 RpcSs - ok
12:22:48.0043 0240 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:22:48.0043 0240 rspndr - ok
12:22:48.0123 0240 [ 4A25DC970C58104602ED274DACAFD784 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
12:22:48.0133 0240 RSUSBSTOR - ok
12:22:48.0163 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] SamSs C:\Windows\system32\lsass.exe
12:22:48.0173 0240 SamSs - ok
12:22:48.0213 0240 [ E3BBB89983DAF5622C1D50CF49F28227 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
12:22:48.0213 0240 sbp2port - ok
12:22:48.0263 0240 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:22:48.0283 0240 SCardSvr - ok
12:22:48.0293 0240 [ C94DA20C7E3BA1DCA269BC8460D98387 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
12:22:48.0303 0240 scfilter - ok
12:22:48.0413 0240 [ 624D0F5FF99428BB90A5B8A4123E918E ] Schedule C:\Windows\system32\schedsvc.dll
12:22:48.0443 0240 Schedule - ok
12:22:48.0463 0240 [ 312E2F82AF11E79906898AC3E3D58A1F ] SCPolicySvc C:\Windows\System32\certprop.dll
12:22:48.0473 0240 SCPolicySvc - ok
12:22:48.0503 0240 [ 765A27C3279CE11D14CB9E4F5869FCA5 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:22:48.0513 0240 SDRSVC - ok
12:22:48.0593 0240 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:22:48.0593 0240 secdrv - ok
12:22:48.0623 0240 [ 463B386EBC70F98DA5DFF85F7E654346 ] seclogon C:\Windows\system32\seclogon.dll
12:22:48.0623 0240 seclogon - ok
12:22:48.0653 0240 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
12:22:48.0653 0240 SENS - ok
12:22:48.0673 0240 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
12:22:48.0683 0240 SensrSvc - ok
12:22:48.0743 0240 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:22:48.0743 0240 Serenum - ok
12:22:48.0753 0240 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:22:48.0763 0240 Serial - ok
12:22:48.0773 0240 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
12:22:48.0773 0240 sermouse - ok
12:22:48.0843 0240 [ C3BC61CE47FF6F4E88AB8A3B429A36AF ] SessionEnv C:\Windows\system32\sessenv.dll
12:22:48.0843 0240 SessionEnv - ok
12:22:48.0863 0240 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
12:22:48.0873 0240 sffdisk - ok
12:22:48.0913 0240 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:22:48.0913 0240 sffp_mmc - ok
12:22:48.0933 0240 [ 5588B8C6193EB1522490C122EB94DFFA ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
12:22:48.0943 0240 sffp_sd - ok
12:22:48.0983 0240 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
12:22:48.0993 0240 sfloppy - ok
12:22:49.0193 0240 [ 38F88F0DF46C4D42125EF721ABD7F6B9 ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
12:22:49.0223 0240 SftService - ok
12:22:49.0273 0240 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:22:49.0303 0240 SharedAccess - ok
12:22:49.0343 0240 [ 0298AC45D0EFFFB2DB4BAA7DD186E7BF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:22:49.0373 0240 ShellHWDetection - ok
12:22:49.0403 0240 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:22:49.0403 0240 SiSRaid2 - ok
12:22:49.0433 0240 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
12:22:49.0443 0240 SiSRaid4 - ok
12:22:49.0483 0240 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:22:49.0493 0240 Smb - ok
12:22:49.0573 0240 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:22:49.0573 0240 SNMPTRAP - ok
12:22:49.0613 0240 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
12:22:49.0623 0240 spldr - ok
12:22:49.0703 0240 [ 567977DC43CC13C4C35ED7084C0B84D5 ] Spooler C:\Windows\System32\spoolsv.exe
12:22:49.0743 0240 Spooler - ok
12:22:50.0153 0240 [ 913D843498553A1BC8F8DBAD6358E49F ] sppsvc C:\Windows\system32\sppsvc.exe
12:22:50.0273 0240 sppsvc - ok
12:22:50.0313 0240 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
12:22:50.0313 0240 sppuinotify - ok
12:22:50.0423 0240 [ D630B6F2E8379B6F10DC16E82A426552 ] sprtsvc_DellSupportCenter C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
12:22:50.0433 0240 sprtsvc_DellSupportCenter - ok
12:22:50.0503 0240 [ 2408C0366D96BCDF63E8F1C78E4A29C5 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:22:50.0523 0240 srv - ok
12:22:50.0593 0240 [ 76548F7B818881B47D8D1AE1BE9C11F8 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:22:50.0623 0240 srv2 - ok
12:22:50.0723 0240 [ 0AF6E19D39C70844C5CAA8FB0183C36E ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:22:50.0723 0240 srvnet - ok
12:22:50.0823 0240 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:22:50.0833 0240 SSDPSRV - ok
12:22:50.0893 0240 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:22:50.0903 0240 SstpSvc - ok
12:22:51.0483 0240 [ 444109453A2B87E6C16BCDA5953E81A9 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe
12:22:51.0503 0240 STacSV - ok
12:22:51.0553 0240 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
12:22:51.0553 0240 stexstor - ok
12:22:51.0693 0240 [ 02E784FA49032F84964DB90A3ED81890 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
12:22:51.0733 0240 STHDA - ok
12:22:51.0913 0240 [ 52D0E33B681BD0F33FDC08812FEE4F7D ] stisvc C:\Windows\System32\wiaservc.dll
12:22:52.0013 0240 stisvc - ok
12:22:52.0073 0240 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
12:22:52.0073 0240 swenum - ok
12:22:52.0223 0240 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
12:22:52.0283 0240 swprv - ok
12:22:52.0393 0240 [ 3178B56219E0E4FB5F95299E49B83B44 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
12:22:52.0403 0240 SynTP - ok
12:22:52.0653 0240 [ 3C1284516A62078FB68F768DE4F1A7BE ] SysMain C:\Windows\system32\sysmain.dll
12:22:52.0713 0240 SysMain - ok
12:22:52.0773 0240 [ 238935C3CF2854886DC7CBB2A0E2CC66 ] TabletInputService C:\Windows\System32\TabSvc.dll
12:22:52.0773 0240 TabletInputService - ok
12:22:52.0803 0240 [ 884264AC597B690C5707C89723BB8E7B ] TapiSrv C:\Windows\System32\tapisrv.dll
12:22:52.0813 0240 TapiSrv - ok
12:22:52.0843 0240 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
12:22:52.0843 0240 TBS - ok
12:22:53.0023 0240 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:22:53.0093 0240 Tcpip - ok
12:22:53.0263 0240 [ 624C5B3AA4C99B3184BB922D9ECE3FF0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
12:22:53.0333 0240 TCPIP6 - ok
12:22:53.0383 0240 [ 76D078AF6F587B162D50210F761EB9ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:22:53.0383 0240 tcpipreg - ok
12:22:53.0403 0240 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:22:53.0413 0240 TDPIPE - ok
12:22:53.0473 0240 [ 7518F7BCFD4B308ABC9192BACAF6C970 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:22:53.0483 0240 TDTCP - ok
12:22:53.0513 0240 [ 079125C4B17B01FCAEEBCE0BCB290C0F ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:22:53.0523 0240 tdx - ok
12:22:53.0553 0240 [ C448651339196C0E869A355171875522 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
12:22:53.0563 0240 TermDD - ok
12:22:53.0633 0240 [ 0F05EC2887BFE197AD82A13287D2F404 ] TermService C:\Windows\System32\termsrv.dll
12:22:53.0663 0240 TermService - ok
12:22:53.0693 0240 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
12:22:53.0693 0240 Themes - ok
12:22:53.0723 0240 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
12:22:53.0733 0240 THREADORDER - ok
12:22:53.0793 0240 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
12:22:53.0793 0240 TrkWks - ok
12:22:53.0893 0240 [ 840F7FB849F5887A49BA18C13B2DA920 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:22:53.0893 0240 TrustedInstaller - ok
12:22:53.0923 0240 [ 61B96C26131E37B24E93327A0BD1FB95 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:22:53.0923 0240 tssecsrv - ok
12:22:53.0993 0240 [ 3836171A2CDF3AF8EF10856DB9835A70 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:22:53.0993 0240 tunnel - ok
12:22:54.0013 0240 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
12:22:54.0023 0240 uagp35 - ok
12:22:54.0073 0240 [ 31BA4A33AFAB6A69EA092B18017F737F ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:22:54.0093 0240 udfs - ok
12:22:54.0143 0240 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:22:54.0153 0240 UI0Detect - ok
12:22:54.0163 0240 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
12:22:54.0173 0240 uliagpkx - ok
12:22:54.0303 0240 [ EAB6C35E62B1B0DB0D1B48B671D3A117 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
12:22:54.0313 0240 umbus - ok
12:22:54.0323 0240 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
12:22:54.0333 0240 UmPass - ok
12:22:54.0383 0240 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
12:22:54.0413 0240 upnphost - ok
12:22:54.0443 0240 [ 537A4E03D7103C12D42DFD8FFDB5BDC9 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:22:54.0453 0240 usbccgp - ok
12:22:54.0503 0240 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
12:22:54.0503 0240 usbcir - ok
12:22:54.0543 0240 [ FBB21EBE49F6D560DB37AC25FBC68E66 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:22:54.0543 0240 usbehci - ok
12:22:54.0673 0240 [ 6B7A8A99C4A459E73C286A6763EA24CC ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:22:54.0713 0240 usbhub - ok
12:22:54.0763 0240 [ 8C88AA7617B4CBC2E4BED61D26B33A27 ] usbohci C:\Windows\system32\drivers\usbohci.sys
12:22:54.0763 0240 usbohci - ok
12:22:54.0793 0240 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:22:54.0803 0240 usbprint - ok
12:22:54.0853 0240 [ F39983647BC1F3E6100778DDFE9DCE29 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:22:54.0853 0240 USBSTOR - ok
12:22:54.0913 0240 [ 0B5B3B2DF3FD1709618ACFA50B8392B0 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
12:22:54.0913 0240 usbuhci - ok
12:22:55.0053 0240 [ 7CB8C573C6E4A2714402CC0A36EAB4FE ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
12:22:55.0063 0240 usbvideo - ok
12:22:55.0103 0240 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
12:22:55.0103 0240 UxSms - ok
12:22:55.0123 0240 [ 156F6159457D0AA7E59B62681B56EB90 ] VaultSvc C:\Windows\system32\lsass.exe
12:22:55.0123 0240 VaultSvc - ok
12:22:55.0213 0240 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
12:22:55.0213 0240 vdrvroot - ok
12:22:55.0363 0240 [ 44D73E0BBC1D3C8981304BA15135C2F2 ] vds C:\Windows\System32\vds.exe
12:22:55.0383 0240 vds - ok
12:22:55.0503 0240 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:22:55.0503 0240 vga - ok
12:22:55.0533 0240 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
12:22:55.0543 0240 VgaSave - ok
12:22:55.0603 0240 [ C82E748660F62A242B2DFAC1442F22A4 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
12:22:55.0633 0240 vhdmp - ok
12:22:55.0693 0240 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
12:22:55.0693 0240 viaide - ok
12:22:55.0733 0240 [ 2B1A3DAE2B4E70DBBA822B7A03FBD4A3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
12:22:55.0743 0240 volmgr - ok
12:22:55.0783 0240 [ 99B0CBB569CA79ACAED8C91461D765FB ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:22:55.0793 0240 volmgrx - ok
12:22:55.0833 0240 [ 58F82EED8CA24B461441F9C3E4F0BF5C ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
12:22:55.0843 0240 volsnap - ok
12:22:55.0883 0240 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
12:22:55.0903 0240 vsmraid - ok
12:22:56.0053 0240 [ 787898BF9FB6D7BD87A36E2D95C899BA ] VSS C:\Windows\system32\vssvc.exe
12:22:56.0143 0240 VSS - ok
12:22:56.0163 0240 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
12:22:56.0173 0240 vwifibus - ok
12:22:56.0233 0240 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
12:22:56.0243 0240 vwififlt - ok
12:22:56.0403 0240 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
12:22:56.0423 0240 W32Time - ok
12:22:56.0463 0240 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
12:22:56.0473 0240 WacomPen - ok
12:22:56.0533 0240 [ 47CA49400643EFFD3F1C9A27E1D69324 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
12:22:56.0533 0240 WANARP - ok
12:22:56.0543 0240 [ 47CA49400643EFFD3F1C9A27E1D69324 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:22:56.0543 0240 Wanarpv6 - ok
12:22:56.0743 0240 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
12:22:56.0843 0240 WatAdminSvc - ok
12:22:56.0983 0240 [ 5AB1BB85BD8B5089CC5D64200DEDAE68 ] wbengine C:\Windows\system32\wbengine.exe
12:22:57.0043 0240 wbengine - ok
12:22:57.0063 0240 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:22:57.0073 0240 WbioSrvc - ok
12:22:57.0133 0240 [ DD1BAE8EBFC653824D29CCF8C9054D68 ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:22:57.0213 0240 wcncsvc - ok
12:22:57.0243 0240 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:22:57.0253 0240 WcsPlugInService - ok
12:22:57.0313 0240 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
12:22:57.0313 0240 Wd - ok
12:22:57.0493 0240 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:22:57.0653 0240 Wdf01000 - ok
12:22:57.0683 0240 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:22:57.0693 0240 WdiServiceHost - ok
12:22:57.0693 0240 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:22:57.0703 0240 WdiSystemHost - ok
12:22:57.0753 0240 [ 733006127F235BE7C35354EBEE7B9A7B ] WebClient C:\Windows\System32\webclnt.dll
12:22:57.0763 0240 WebClient - ok
12:22:57.0833 0240 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:22:57.0883 0240 Wecsvc - ok
12:22:57.0943 0240 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:22:57.0943 0240 wercplsupport - ok
12:22:58.0123 0240 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
12:22:58.0123 0240 WerSvc - ok
12:22:58.0233 0240 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
12:22:58.0243 0240 WfpLwf - ok
12:22:58.0273 0240 [ B14EF15BD757FA488F9C970EEE9C0D35 ] WimFltr C:\Windows\system32\DRIVERS\wimfltr.sys
12:22:58.0273 0240 WimFltr - ok
12:22:58.0323 0240 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:22:58.0333 0240 WIMMount - ok
12:22:58.0363 0240 WinDefend - ok
12:22:58.0373 0240 WinHttpAutoProxySvc - ok
12:22:58.0553 0240 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:22:58.0563 0240 Winmgmt - ok
12:22:58.0813 0240 [ 41FBB751936B387F9179E7F03A74FE29 ] WinRM C:\Windows\system32\WsmSvc.dll
12:22:58.0923 0240 WinRM - ok
12:22:59.0103 0240 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
12:22:59.0163 0240 Wlansvc - ok
12:22:59.0243 0240 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
12:22:59.0243 0240 WmiAcpi - ok
12:22:59.0293 0240 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:22:59.0313 0240 wmiApSrv - ok
12:22:59.0373 0240 WMPNetworkSvc - ok
12:22:59.0443 0240 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:22:59.0453 0240 WPCSvc - ok
12:22:59.0473 0240 [ 2E57DDF2880A7E52E76F41C7E96D327B ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:22:59.0483 0240 WPDBusEnum - ok
12:22:59.0523 0240 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:22:59.0523 0240 ws2ifsl - ok
12:22:59.0573 0240 [ 8F9F3969933C02DA96EB0F84576DB43E ] wscsvc C:\Windows\System32\wscsvc.dll
12:22:59.0583 0240 wscsvc - ok
12:22:59.0583 0240 WSearch - ok
12:22:59.0963 0240 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
12:23:00.0043 0240 wuauserv - ok
12:23:00.0113 0240 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:23:00.0133 0240 WudfPf - ok
12:23:00.0203 0240 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:23:00.0203 0240 WUDFRd - ok
12:23:00.0243 0240 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:23:00.0243 0240 wudfsvc - ok
12:23:00.0363 0240 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
12:23:00.0393 0240 WwanSvc - ok
12:23:00.0533 0240 [ 79D9CE9614C955DD31AA2556B4014662 ] yukonw7 C:\Windows\system32\DRIVERS\yk62x64.sys
12:23:00.0553 0240 yukonw7 - ok
12:23:00.0563 0240 ================ Scan global ===============================
12:23:00.0593 0240 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
12:23:00.0643 0240 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
12:23:00.0653 0240 [ 79CDA06F75AD5373DD447F57575C4400 ] C:\Windows\system32\winsrv.dll
12:23:00.0683 0240 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
12:23:00.0743 0240 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
12:23:00.0763 0240 [Global] - ok
12:23:00.0773 0240 ================ Scan MBR ==================================
12:23:00.0843 0240 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
12:23:02.0193 0240 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
12:23:02.0193 0240 \Device\Harddisk0\DR0 - detected TDSS File System (1)
12:23:02.0193 0240 ================ Scan VBR ==================================
12:23:02.0203 0240 [ DA95CC62C3DD36D8F886BC7D401D0B4B ] \Device\Harddisk0\DR0\Partition1
12:23:02.0213 0240 \Device\Harddisk0\DR0\Partition1 - ok
12:23:02.0233 0240 [ D55F103D8F93626BC96715CE52A9F530 ] \Device\Harddisk0\DR0\Partition2
12:23:02.0243 0240 \Device\Harddisk0\DR0\Partition2 - ok
12:23:02.0243 0240 ============================================================
12:23:02.0243 0240 Scan finished
12:23:02.0243 0240 ============================================================
12:23:02.0253 5096 Detected object count: 1
12:23:02.0253 5096 Actual detected object count: 1
12:23:58.0453 5096 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
12:23:58.0643 5096 \Device\Harddisk0\DR0\TDLFS\phx.dll - copied to quarantine
12:23:58.0873 5096 \Device\Harddisk0\DR0\TDLFS\phd - copied to quarantine
12:24:01.0883 5096 \Device\Harddisk0\DR0\TDLFS\phdx - copied to quarantine
12:24:02.0913 5096 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
12:24:03.0283 5096 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
12:24:04.0033 5096 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
12:24:04.0543 5096 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
12:24:04.0823 5096 \Device\Harddisk0\DR0\TDLFS\phlx - copied to quarantine
12:24:04.0883 5096 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
12:24:04.0923 5096 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Quarantine

#4 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 02:50 PM

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-12-01 12:24:23
-----------------------------
12:24:23.563 OS Version: Windows x64 6.1.7600
12:24:23.563 Number of processors: 2 586 0x170A
12:24:23.563 ComputerName: RANDI-PC UserName: Randi
12:24:42.433 Initialize success
12:25:50.872 AVAST engine defs: 12120100
12:26:14.992 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
12:26:15.002 Disk 0 Vendor: ST932032 0002 Size: 305245MB BusType: 3
12:26:15.062 Disk 0 MBR read successfully
12:26:15.062 Disk 0 MBR scan
12:26:15.112 Disk 0 Windows XP default MBR code
12:26:15.112 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
12:26:15.162 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 81920
12:26:15.202 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290204 MB offset 30801920
12:26:15.282 Disk 0 scanning C:\Windows\system32\drivers
12:26:42.252 Service scanning
12:28:17.662 Modules scanning
12:28:17.672 Disk 0 trace - called modules:
12:28:17.702 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
12:28:18.042 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003026680]
12:28:18.052 3 CLASSPNP.SYS[fffff880015a343f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002e16050]
12:28:24.022 AVAST engine scan C:\Windows
12:28:33.792 AVAST engine scan C:\Windows\system32
12:37:25.804 AVAST engine scan C:\Windows\system32\drivers
12:38:21.654 AVAST engine scan C:\Users\Randi
12:41:49.224 AVAST engine scan C:\ProgramData
12:47:52.594 Scan finished successfully
12:50:00.385 Disk 0 MBR has been saved successfully to "C:\Users\Randi\Documents\MBR.dat"
12:50:00.545 The log file has been saved successfully to "C:\Users\Randi\Documents\aswMBR.txt"

#5 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 03:04 PM

now running eset....
only 8 % complete so this could take a while LOL
so stay posted :)

#6 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 03:34 PM

well malwarebytes was doing a full scan (like i said originally) and it is now complete and it didnt find anything.
i am still doing eset 10% complete now.

how did all this get past malwarebytes?

#7 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:22 PM

C:\TDSSKiller_Quarantine\01.12.2012_12.21.47\tdlfs0000\tsk0001.dta Win64/Olmarik.AD trojan cleaned by deleting - quarantined

#8 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:42 PM

so am i okay now????

#9 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:18 PM

Posted 01 December 2012 - 05:44 PM

Download

Malwarebytes

Install,update and run a full scan

Click on Show results.Right click on the list ,select all and remove them.

Post the generated log here


Download

http://www.bleepingcomputer.com/download/rkill/

Run it and after scan finishes,post the contents of RKILL log located on the desktop here


Download

Autoruns

Extract and launch autoruns.exe

Allow the scan to get finished

Now click on FILE-SAVE

Filename:Autoruns.txt
Save as :Text

Paste the contents of text here

#10 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:49 PM

i already have malwarebytes and ran a full scan which it did not find anything.

#11 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:50 PM

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.01.08

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Randi :: RANDI-PC [administrator]

12/1/2012 11:40:06 AM
mbam-log-2012-12-01 (11-40-06).txt

Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 425173
Time elapsed: 1 hour(s), 52 minute(s), 27 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#12 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:56 PM

Rkill 2.4.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2012 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 12/01/2012 03:51:20 PM in x64 mode.
Windows Version: Windows 7 Home Premium

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Windows\System32\jusched.exe (PID: 4524) [FI]
* C:\Windows\System32\jucheck.exe (PID: 2292) [WD-HEUR]

2 proccesses terminated!

Checking Registry for malware related settings:

* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
C:\Users\Randi\Desktop\rkill\rkill-12-01-2012-03-51-27.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 12/01/2012 03:51:42 PM
Execution time: 0 hours(s), 0 minute(s), and 22 seconds(s)

#13 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 05:58 PM

and i dont understand the last one you want me to do....?

#14 monismama

monismama
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:18 PM

Posted 01 December 2012 - 06:00 PM

"HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms" "" "" ""
+ "rdpclip" "" "" "File not found: rdpclip"
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" ""
+ "HotKeysCmds" "hkcmd Module" "Intel Corporation" "c:\windows\system32\hkcmd.exe"
+ "IAAnotif" "Event Monitor User Notification Tool" "Intel Corporation" "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe"
+ "IgfxTray" "igfxTray Module" "Intel Corporation" "c:\windows\system32\igfxtray.exe"
+ "IntelliPoint" "IPoint.exe" "Microsoft Corporation" "c:\program files\microsoft mouse and keyboard center\ipoint.exe"
+ "IntelliType Pro" "IType.exe" "Microsoft Corporation" "c:\program files\microsoft mouse and keyboard center\itype.exe"
+ "MSC" "Microsoft Security Client User Interface" "Microsoft Corporation" "c:\program files\microsoft security client\msseces.exe"
+ "Persistence" "persistence Module" "Intel Corporation" "c:\windows\system32\igfxpers.exe"
+ "QuickSet" "QuickSet" "Dell Inc." "c:\program files\dell\quickset\quickset.exe"
+ "SynTPEnh" "Synaptics TouchPad Enhancements" "Synaptics Incorporated" "c:\program files\synaptics\syntp\syntpenh.exe"
+ "SysTrayApp" "IDT PC Audio" "IDT, Inc." "c:\program files\idt\wdm\sttray64.exe"
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" "" "" ""
+ "Adobe Reader Speed Launcher" "Adobe Acrobat SpeedLauncher" "Adobe Systems Incorporated" "c:\program files (x86)\adobe\reader 9.0\reader\reader_sl.exe"
+ "Dell DataSafe Online" "DataSafeOnline" "" "c:\program files (x86)\dell datasafe online\datasafeonline.exe"
+ "Dell Webcam Central" "WebcamDell2.exe" "Creative Technology Ltd" "c:\program files (x86)\dell webcam\dell webcam central\webcamdell2.exe"
+ "DellSupportCenter" "Dell Support Center Updates" "SupportSoft, Inc." "c:\program files (x86)\dell support center\bin\sprtcmd.exe"
+ "Desktop Disc Tool" "Roxio Burn Launcher" "" "c:\program files (x86)\roxio\roxio burn\roxioburnlauncher.exe"
+ "PDVDDXSrv" "CyberLink PowerDVD Resident Program" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe"
+ "TkBellExe" "RealNetworks Scheduler" "RealNetworks, Inc." "c:\program files (x86)\real\realplayer\update\realsched.exe"
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce" "" "" ""
+ "Launcher" "VistaLauncher" "Softthinks" "c:\program files (x86)\dell datasafe local backup\components\scheduler\launcher.exe"
"C:\Users\Randi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" "" "" ""
+ "Dell Dock.lnk" "Dell Dock" "Stardock Corporation" "c:\program files\dell\delldock\delldock.exe"
"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" ""
+ "Microsoft Windows" "Windows Mail" "Microsoft Corporation" "c:\program files\windows mail\winmail.exe"
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" "" "" ""
+ "Microsoft Windows" "Windows Mail" "Microsoft Corporation" "c:\program files (x86)\windows mail\winmail.exe"
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run" "" "" ""
+ "Xvid" "" "" "c:\program files (x86)\xvid\checkupdate.exe"
"HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" ""
+ "text/xml" "Microsoft Office XML MIME Filter" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoxmlmf.dll"
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""
+ "EPP" "Microsoft Security Client Shell Extension" "Microsoft Corporation" "c:\program files\microsoft security client\shellext.dll"
"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" ""
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files (x86)\malwarebytes' anti-malware\mbamext.dll"
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers" "" "" ""
+ "EPP" "Microsoft Security Client Shell Extension" "Microsoft Corporation" "c:\program files\microsoft security client\shellext.dll"
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""
+ "Gadgets" "Sidebar droptarget" "Microsoft Corporation" "c:\program files\windows sidebar\sbdrop.dll"
+ "igfxcui" "igfxpph Module" "Intel Corporation" "c:\windows\system32\igfxpph.dll"
"HKLM\Software\Wow6432Node\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""
+ "Gadgets" "Sidebar droptarget" "Microsoft Corporation" "c:\program files (x86)\windows sidebar\sbdrop.dll"
"HKLM\Software\Wow6432Node\Classes\Folder\Shellex\ColumnHandlers" "" "" ""
+ "PDF Shell Extension" "PDF Shell Extension" "Adobe Systems, Inc." "c:\program files (x86)\common files\adobe\acrobat\activex\pdfshell.dll"
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" ""
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files (x86)\malwarebytes' anti-malware\mbamext.dll"
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" ""
+ "Bing Bar Helper" "Bing Client Extensions" "Microsoft Corporation." "c:\program files (x86)\microsoft\bingbar\bingext.dll"
+ "RealPlayer Download and Record Plugin for Internet Explorer" "RealPlayer Download and Record Plugin" "RealPlayer" "c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll"
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar" "" "" ""
+ "Bing" "Bing Client Extensions" "Microsoft Corporation." "c:\program files (x86)\microsoft\bingbar\bingext.dll"
"HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions" "" "" ""
+ "&Blog This in Windows Live Writer" "Windows Live Writer Blog This Extension" "Microsoft Corporation" "c:\program files (x86)\windows live\writer\writerbrowserextension.dll"
+ "S&end to OneNote" "Microsoft Office OneNote Internet Explorer Add-in" "Microsoft Corporation" "c:\program files (x86)\microsoft office\office12\onbttnie.dll"
"Task Scheduler" "" "" ""
+ "\JavaUpdateSched" "Java™ Platform SE binary" "Sun Microsystems, Inc." "c:\windows\system32\jusched.exe"
+ "\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan" "Microsoft Malware Protection Command Line Utility" "Microsoft Corporation" "c:\program files\microsoft security client\mpcmdrun.exe"
+ "\Microsoft\Windows\NetTrace\GatherNetworkInfo" "" "" "c:\windows\system32\gathernetworkinfo.vbs"
+ "\Microsoft\Windows\Windows Media Sharing\UpdateLibrary" "Windows Media Player Network Sharing Service Configuration Application" "Microsoft Corporation" "c:\program files\windows media player\wmpnscfg.exe"
+ "\Microsoft_Hardware_Launch_ipoint_exe" "IPoint.exe" "Microsoft Corporation" "c:\program files\microsoft mouse and keyboard center\ipoint.exe"
+ "\Microsoft_Hardware_Launch_itype_exe" "IType.exe" "Microsoft Corporation" "c:\program files\microsoft mouse and keyboard center\itype.exe"
+ "\Microsoft_Hardware_Launch_mousekeyboardcenter_exe" "Microsoft Mouse and Keyboard Center" "Microsoft" "c:\program files\microsoft mouse and keyboard center\mousekeyboardcenter.exe"
+ "\RealUpgradeLogonTaskS-1-5-21-4265505565-2887419862-550575693-1001" "RealUpgrade Launcher" "RealNetworks, Inc." "c:\program files (x86)\real\realupgrade\realupgrade.exe"
+ "\RealUpgradeScheduledTaskS-1-5-21-4265505565-2887419862-550575693-1001" "RealUpgrade Launcher" "RealNetworks, Inc." "c:\program files (x86)\real\realupgrade\realupgrade.exe"
"HKLM\System\CurrentControlSet\Services" "" "" ""
+ "AdobeFlashPlayerUpdateSvc" "This service keeps your Adobe Flash Player installation up to date with the latest enhancements and security fixes." "Adobe Systems Incorporated" "c:\windows\syswow64\macromed\flash\flashplayerupdateservice.exe"
+ "BBSvc" "Keeps Bing Bar up-to-date. Disabling this service might prevent updates and expose your computer to security vulnerabilities or functional flaws in Bing Bar." "Microsoft Corporation." "c:\program files (x86)\microsoft\bingbar\bbsvc.exe"
+ "BBUpdate" "Enables the detection, download and installation of up-to-date configuration files for Bing Bar. Also provides server communication for the customer experience improvement program. Stopping or disabling this service may prevent you from getting the latest updates for Bing Bar, which may expose your computer to security vulnerabilities or functional flaws in the Bing Bar." "Microsoft Corporation" "c:\program files (x86)\microsoft\bingbar\seaport.exe"
+ "DockLoginService" "Dock Login Service" "Stardock Corporation" "c:\program files\dell\delldock\docklogin.exe"
+ "GameConsoleService" "GameConsole management services" "WildTangent, Inc." "c:\program files (x86)\wildtangent\dell games\dell game console\gameconsoleservice.exe"
+ "GoToAssist" "Citrix GoToAssist provides remote help to this PC." "Citrix Online, a division of Citrix Systems, Inc." "c:\program files (x86)\citrix\gotoassist\514\g2aservice.exe"
+ "IAANTMON" "RAID Monitor" "Intel Corporation" "c:\program files (x86)\intel\intel matrix storage manager\iaantmon.exe"
+ "MozillaMaintenance" "The Mozilla Maintenance Service ensures that you have the latest and most secure version of Mozilla Firefox on your computer. Keeping Firefox up to date is very important for your online security, and Mozilla strongly recommends that you keep this service enabled." "Mozilla Foundation" "c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe"
+ "MsMpSvc" "Helps protect users from malware and other potentially unwanted software" "Microsoft Corporation" "c:\program files\microsoft security client\msmpeng.exe"
+ "NisSrv" "Helps guard against intrusion attempts targeting known and newly discovered vulnerabilities in network protocols" "Microsoft Corporation" "c:\program files\microsoft security client\nissrv.exe"
+ "odserv" "Run portions of Microsoft Office Diagnostics." "Microsoft Corporation" "c:\program files (x86)\common files\microsoft shared\office12\odserv.exe"
+ "ose" "Saves installation files used for updates and repairs and is required for the downloading of Setup updates and Watson error reports." "Microsoft Corporation" "c:\program files (x86)\common files\microsoft shared\source engine\ose.exe"
+ "SftService" "SoftThinks Agent Service" "SoftThinks SAS" "c:\program files (x86)\dell datasafe local backup\sftservice.exe"
+ "sprtsvc_DellSupportCenter" "SupportSoft Sprocket Service (DellSupportCenter)" "SupportSoft, Inc." "c:\program files (x86)\dell support center\bin\sprtsvc.exe"
+ "STacSV" "Manages audio jack configurations." "IDT, Inc." "c:\windows\system32\driverstore\filerepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe"
+ "WinDefend" "Protection against spyware and potentially unwanted software" "Microsoft Corporation" "c:\program files\windows defender\mpsvc.dll"
+ "WMPNetworkSvc" "Shares Windows Media Player libraries to other networked players and media devices using Universal Plug and Play" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe"
"HKLM\System\CurrentControlSet\Services" "" "" ""
+ "adp94xx" "Adaptec Windows SAS/SATA Storport Driver" "Adaptec, Inc." "c:\windows\system32\drivers\adp94xx.sys"
+ "adpahci" "Adaptec Windows SATA Storport Driver" "Adaptec, Inc." "c:\windows\system32\drivers\adpahci.sys"
+ "adpu320" "Adaptec StorPort Ultra320 SCSI Driver (X64)" "Adaptec, Inc." "c:\windows\system32\drivers\adpu320.sys"
+ "aliide" "ALi mini IDE Driver" "Acer Laboratories Inc." "c:\windows\system32\drivers\aliide.sys"
+ "amdsata" "AHCI 1.2 Device Driver" "Advanced Micro Devices" "c:\windows\system32\drivers\amdsata.sys"
+ "amdsbs" "AMD Technology AHCI Compatible Controller Driver for Windows - AMD64 platform" "AMD Technologies Inc." "c:\windows\system32\drivers\amdsbs.sys"
+ "amdxata" "Storage Filter Driver" "Advanced Micro Devices" "c:\windows\system32\drivers\amdxata.sys"
+ "arc" "Adaptec RAID Storport Driver" "Adaptec, Inc." "c:\windows\system32\drivers\arc.sys"
+ "arcsas" "Adaptec SAS RAID WS03 Driver" "Adaptec, Inc." "c:\windows\system32\drivers\arcsas.sys"
+ "aswMBR" "" "" "File not found: C:\Users\Randi\AppData\Local\Temp\aswMBR.sys"
+ "b06bdrv" "Broadcom NetXtreme II GigE VBD" "Broadcom Corporation" "c:\windows\system32\drivers\bxvbda.sys"
+ "b57nd60a" "Broadcom NetXtreme Gigabit Ethernet NDIS6.x Unified Driver." "Broadcom Corporation" "c:\windows\system32\drivers\b57nd60a.sys"
+ "BrFiltLo" "Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltlo.sys"
+ "BrFiltUp" "Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltup.sys"
+ "Brserid" "Brotehr Serial I/F Driver (WDM)" "Brother Industries Ltd." "c:\windows\system32\drivers\brserid.sys"
+ "BrSerWdm" "Brother Serial driver (WDM version)" "Brother Industries Ltd." "c:\windows\system32\drivers\brserwdm.sys"
+ "BrUsbMdm" "Brother USB MDM Driver " "Brother Industries Ltd." "c:\windows\system32\drivers\brusbmdm.sys"
+ "BrUsbSer" "Brother USB Serial Driver" "Brother Industries Ltd." "c:\windows\system32\drivers\brusbser.sys"
+ "cmdide" "CMD PCI IDE Bus Driver" "CMD Technology, Inc." "c:\windows\system32\drivers\cmdide.sys"
+ "CtClsFlt" "Video Class Upper Filter Driver (64-bit)" "Creative Technology Ltd." "c:\windows\system32\drivers\ctclsflt.sys"
+ "ebdrv" "Broadcom NetXtreme II 10 GigE VBD" "Broadcom Corporation" "c:\windows\system32\drivers\evbda.sys"
+ "elxstor" "Storport Miniport Driver for LightPulse HBAs" "Emulex" "c:\windows\system32\drivers\elxstor.sys"
+ "hcw85cir" "Hauppauge WinTV 885 Consumer IR Driver for eHome" "Hauppauge Computer Works, Inc." "c:\windows\system32\drivers\hcw85cir.sys"
+ "HpSAMD" "Smart Array SAS/SATA Controller Media Driver" "Hewlett-Packard Company" "c:\windows\system32\drivers\hpsamd.sys"
+ "iaStor" "Intel Matrix Storage Manager driver - x64" "Intel Corporation" "c:\windows\system32\drivers\iastor.sys"
+ "iaStorV" "Intel Matrix Storage Manager driver - x64" "Intel Corporation" "c:\windows\system32\drivers\iastorv.sys"
+ "igfx" "Intel Graphics Kernel Mode Driver" "Intel Corporation" "c:\windows\system32\drivers\igdkmd64.sys"
+ "iirsp" "Intel/ICP Raid Storport Driver" "Intel Corp./ICP vortex GmbH" "c:\windows\system32\drivers\iirsp.sys"
+ "LSI_FC" "LSI Fusion-MPT FC Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_fc.sys"
+ "LSI_SAS" "LSI Fusion-MPT SAS Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_sas.sys"
+ "LSI_SAS2" "LSI SAS Gen2 Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_sas2.sys"
+ "LSI_SCSI" "LSI Fusion-MPT SCSI Driver (StorPort)" "LSI Corporation" "c:\windows\system32\drivers\lsi_scsi.sys"
+ "megasas" "MEGASAS RAID Controller Driver for Windows 7\Server 2008 R2 for x64" "LSI Corporation" "c:\windows\system32\drivers\megasas.sys"
+ "MegaSR" "LSI MegaRAID Software RAID Driver" "LSI Corporation, Inc." "c:\windows\system32\drivers\megasr.sys"
+ "NETw5s64" "Intel® Wireless WiFi Link Driver" "Intel Corporation" "c:\windows\system32\drivers\netw5s64.sys"
+ "nfrd960" "IBM ServeRAID Controller Driver" "IBM Corporation" "c:\windows\system32\drivers\nfrd960.sys"
+ "nvraid" "NVIDIA® nForce™ RAID Driver" "NVIDIA Corporation" "c:\windows\system32\drivers\nvraid.sys"
+ "nvstor" "NVIDIA® nForce™ Sata Performance Driver" "NVIDIA Corporation" "c:\windows\system32\drivers\nvstor.sys"
+ "PxHlpa64" "Px Engine Device Driver for 64-bit Windows" "Sonic Solutions" "c:\windows\system32\drivers\pxhlpa64.sys"
+ "ql2300" "QLogic Fibre Channel Stor Miniport Driver" "QLogic Corporation" "c:\windows\system32\drivers\ql2300.sys"
+ "ql40xx" "QLogic iSCSI Storport Miniport Driver" "QLogic Corporation" "c:\windows\system32\drivers\ql40xx.sys"
+ "RSUSBSTOR" "Realtek USB Mass Storage Driver for 2K/XP/Vista/win7" "Realtek Semiconductor Corp." "c:\windows\system32\drivers\rtsustor.sys"
+ "secdrv" "Macrovision SECURITY Driver" "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K." "c:\windows\system32\drivers\secdrv.sys"
+ "SiSRaid2" "SiS RAID Stor Miniport Driver" "Silicon Integrated Systems Corp." "c:\windows\system32\drivers\sisraid2.sys"
+ "SiSRaid4" "SiS AHCI Stor-Miniport Driver" "Silicon Integrated Systems" "c:\windows\system32\drivers\sisraid4.sys"
+ "stexstor" "Promise SuperTrak EX Series Driver for Windows " "Promise Technology" "c:\windows\system32\drivers\stexstor.sys"
+ "STHDA" "IDT PC Audio" "IDT, Inc." "c:\windows\system32\drivers\stwrt64.sys"
+ "SynTP" "Synaptics Touchpad Driver" "Synaptics Incorporated" "c:\windows\system32\drivers\syntp.sys"
+ "viaide" "VIA Generic PCI IDE Bus Driver" "VIA Technologies, Inc." "c:\windows\system32\drivers\viaide.sys"
+ "vsmraid" "VIA RAID DRIVER FOR AMD-X86-64" "VIA Technologies Inc.,Ltd" "c:\windows\system32\drivers\vsmraid.sys"
+ "yukonw7" "Miniport Driver for Marvell Yukon Ethernet Controller." "Marvell" "c:\windows\system32\drivers\yk62x64.sys"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm"
+ "vidc.XVID" "" "" "c:\windows\system32\xvidvfw.dll"
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""
+ "msacm.l3acm" "MPEG Audio Layer-3 Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\syswow64\l3codecp.acm"
+ "vidc.cvid" "Cinepak® Codec" "Radius Inc." "c:\windows\syswow64\iccvid.dll"
+ "vidc.XVID" "" "" "c:\windows\syswow64\xvidvfw.dll"
"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""
+ "Xvid MPEG-4 Video Decoder" "" "" "c:\windows\system32\xvid.ax"
"HKLM\Software\Wow6432Node\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""
+ "Capture File Writer" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "Creative MJPEG Decoder 2" "Decoder" "Creative Technology Ltd." "c:\program files (x86)\creative\shared files\ctmjpgdec2.ax"
+ "Creative Video Processing Filter" "Creative Video Processing Filter" "Creative Technology Ltd." "c:\program files (x86)\creative\shared files\vidprocu.ax"
+ "CyberLink Audio Decoder" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\claud.ax"
+ "CyberLink Audio Effect" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\claudfx.ax"
+ "CyberLink Audio Spectrum Analyzer" "CLAudSpa.ax" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\claudspa.ax"
+ "CyberLink Audio Wizard" "CyberLink Audio Wizard Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\claudwizard.ax"
+ "CyberLink AudioCD Filter" "CyberLink AudioCD Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\claudiocd.ax"
+ "CyberLink Demultiplexer" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\cldemuxer.ax"
+ "CyberLink DVD Navigator" "CyberLink DVD Navigation Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clnavx.ax"
+ "CyberLink Line21 Decoder Filter" "CyberLink Line21 Decoder Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clline21.ax"
+ "Cyberlink SubTitle Importor" "CLSubTitle.ax" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clsubtitle.ax"
+ "CyberLink TimeStretch Filter" "CLAuTS.ax" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clauts.ax"
+ "CyberLink Tzan Filter" "Cyberlink Tzan Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\cltzan.ax"
+ "CyberLink Video Effect" "CLVidFx" "CyberLink" "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clvidfx.ax"
+ "CyberLink Video/SP Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files (x86)\cyberlink\powerdvd dx\kernel\movie\clvsd.ax"
+ "RealPlayer Audio Filter" "Audio Filter Plugin" "RealNetworks, Inc." "c:\program files (x86)\real\realplayer\rdsf3260.dll"
+ "RealPlayer Transcode Filter" "Audio Filter Plugin" "RealNetworks, Inc." "c:\program files (x86)\real\realplayer\rdsf3260.dll"
+ "RealPlayer Video Filter" "Audio Filter Plugin" "RealNetworks, Inc." "c:\program files (x86)\real\realplayer\rdsf3260.dll"
+ "Record Queue" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WM VIH2 Fix" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT DV Extract Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Sample Info Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Switch Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Renderer" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Source" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files (x86)\windows live\photo gallery\wlxvafilt.dll"
+ "Xvid MPEG-4 Video Decoder" "" "" "c:\windows\syswow64\xvid.ax"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify" "" "" ""
+ "GoToAssist" "" "" "File not found: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll"
+ "igfxcui" "igfxdev Module" "Intel Corporation" "c:\windows\system32\igfxdev.dll"

#15 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:18 PM

Posted 01 December 2012 - 06:28 PM

Download

mini toolbox

Checkmark following boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List restore points

Click Go and post the result.

Download

Farbar service scanner

Checkmark all the boxes

Click on "Scan".
Please copy and paste the log to your reply.

Download

adware cleaner

Launch it click on Delete

A log should be generated after scan ,post it here

Download

Junkware removal tool

For vista and windows 7 right click on the tool and select run as administrator

After scan gets completed,post the generated log here.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users