BleepingComputer.com: Windows 7 Won't Boot After ComboFix

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Windows 7 Won't Boot After ComboFix

#31 User is offline   msgail 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 26-June 08

Posted 12 October 2011 - 07:25 PM

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK

#32 User is offline   msgail 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 26-June 08

Posted 12 October 2011 - 07:27 PM

Here are the ESET scan results:

C:\TDSSKiller_Quarantine\01.10.2011_15.31.45\susp0000\svc0000\tsk0000.dta a variant of Win32/Sirefef.CR trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\01.10.2011_15.31.45\susp0001\svc0000\tsk0000.dta a variant of Win32/Kryptik.TKY trojan cleaned by deleting - quarantined
C:\Users\DesJon\AppData\Local\MSOLAP90ErrorLookup\MSOLAP90ErrorLookup.dll a variant of Win32/Sefnit.AD trojan cleaned by deleting - quarantined
C:\Users\DesJon\Desktop\winzip155.exe a variant of Win32/Adware.OpenInstall application cleaned by deleting - quarantined
C:\Users\DesJon\Downloads\credit-aid-pro-credit-repair-software-7.0.1.b.exe a variant of Win32/Sefnit.AD trojan deleted - quarantined
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V3GGZ88K\toolbarinstaller[1].exe Win32/Adware.Linkular application deleted - quarantined

#33 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,817
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 13 October 2011 - 05:50 AM

The Malwarebyes and ESET scan show there were malware in Java cache and in Temporary Internet Files directory. Also both scans show the following uTorrent download folder: C:\Users\DesJon\Downloads

  • Please remove the following folder: C:\Users\DesJon\Downloads

  • To Clear the Java Runtime Environment (JRE) cache, do this:
    • Click Start > Settings > Control Panel.
    • Double-click the Java icon.
      -The Java Control Panel appears.
    • Click "Settings" under Temporary Internet Files.
      -The Temporary Files Settings dialog box appears.
    • Click "Delete Files".
      -The Delete Temporary Files dialog box appears.
      -There are three options on this window to clear the cache.
      • Delete Files
      • View Applications
      • View Applets

    • Click "OK" on Delete Temporary Files window.
      -Note: This deletes all the Downloaded Applications and Applets from the cache.
    • Click "OK" on Temporary Files Settings window.
    • Close the Java Control Panel.
    You can also view these instructions along with screenshots here.

  • Run CCleaner (make sure under Windows tab all the boxes of Internet Explorer and Windows explorer are checked. Under System check Empty Recycle Bin and Temporary Files. Under Application tab all the boxes should be checked). Then click run cleaner.

  • I recommend using Site Advisor for safe surfing. It is a free extension both for Internet Explorer and Firefox. When you search a site it gives you an indication of how safe a site is.

  • I recommend installing this small application for safe surfing: Javacoolsİ SpywareBlaster
    SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
    • Download and install it.
    • Update it manually by clicking on Updates in the left pane and then Check for Updates.
    • Then enable all the protections by clicking on Protection Status on the left pane. Then click on Enable All Protection.
    • The free version doesn't have an automatic update. Update it once in two or three weeks and enable all protection again.

  • Please run TDSSKiller once more and post the log if it found anything and tell me if you still get redirected.

Posted Image

#34 User is offline   msgail 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 26-June 08

Posted 13 October 2011 - 02:56 PM

I followed all of your instructions. I haven't gotten any redirects since yesterday. Here is the log:

14:50:26.0201 3412 TDSS rootkit removing tool 2.6.8.0 Oct 12 2011 07:30:54
14:50:26.0497 3412 ============================================================
14:50:26.0497 3412 Current date / time: 2011/10/13 14:50:26.0497
14:50:26.0497 3412 SystemInfo:
14:50:26.0497 3412
14:50:26.0497 3412 OS Version: 6.1.7600 ServicePack: 0.0
14:50:26.0497 3412 Product type: Workstation
14:50:26.0497 3412 ComputerName: DESJON-PC
14:50:26.0497 3412 UserName: DesJon
14:50:26.0497 3412 Windows directory: C:\windows
14:50:26.0497 3412 System windows directory: C:\windows
14:50:26.0497 3412 Processor architecture: Intel x86
14:50:26.0497 3412 Number of processors: 2
14:50:26.0497 3412 Page size: 0x1000
14:50:26.0497 3412 Boot type: Normal boot
14:50:26.0497 3412 ============================================================
14:50:27.0761 3412 Initialize success
14:50:29.0571 5024 ============================================================
14:50:29.0571 5024 Scan started
14:50:29.0571 5024 Mode: Manual;
14:50:29.0571 5024 ============================================================
14:50:32.0613 5024 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
14:50:32.0613 5024 1394ohci - ok
14:50:32.0706 5024 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
14:50:32.0706 5024 ACPI - ok
14:50:32.0800 5024 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
14:50:32.0815 5024 AcpiPmi - ok
14:50:32.0925 5024 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
14:50:32.0956 5024 adp94xx - ok
14:50:33.0065 5024 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
14:50:33.0065 5024 adpahci - ok
14:50:33.0127 5024 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
14:50:33.0127 5024 adpu320 - ok
14:50:33.0190 5024 AFD (0db7a48388d54d154ebec120461a0fcd) C:\windows\system32\drivers\afd.sys
14:50:33.0205 5024 AFD - ok
14:50:33.0330 5024 AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys
14:50:33.0346 5024 AgereSoftModem - ok
14:50:33.0455 5024 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
14:50:33.0455 5024 agp440 - ok
14:50:33.0658 5024 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
14:50:33.0673 5024 aic78xx - ok
14:50:33.0767 5024 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
14:50:33.0767 5024 aliide - ok
14:50:33.0861 5024 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
14:50:33.0861 5024 amdagp - ok
14:50:33.0923 5024 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
14:50:33.0923 5024 amdide - ok
14:50:34.0001 5024 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
14:50:34.0001 5024 AmdK8 - ok
14:50:34.0095 5024 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
14:50:34.0095 5024 AmdPPM - ok
14:50:34.0188 5024 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
14:50:34.0188 5024 amdsata - ok
14:50:34.0297 5024 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
14:50:34.0313 5024 amdsbs - ok
14:50:34.0375 5024 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
14:50:34.0375 5024 amdxata - ok
14:50:34.0469 5024 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
14:50:34.0469 5024 AppID - ok
14:50:34.0625 5024 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
14:50:34.0625 5024 arc - ok
14:50:34.0641 5024 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
14:50:34.0641 5024 arcsas - ok
14:50:34.0750 5024 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
14:50:34.0750 5024 AsyncMac - ok
14:50:34.0765 5024 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
14:50:34.0765 5024 atapi - ok
14:50:34.0999 5024 atikmdag (c97be8350fbcb1960b22fad2e6c2b514) C:\windows\system32\DRIVERS\atikmdag.sys
14:50:35.0093 5024 atikmdag - ok
14:50:35.0187 5024 AtiPcie (b73c832088dd54b55e04ff6f9646ad8c) C:\windows\system32\DRIVERS\AtiPcie.sys
14:50:35.0187 5024 AtiPcie - ok
14:50:35.0296 5024 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
14:50:35.0311 5024 b06bdrv - ok
14:50:35.0358 5024 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
14:50:35.0358 5024 b57nd60x - ok
14:50:35.0452 5024 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
14:50:35.0452 5024 Beep - ok
14:50:35.0545 5024 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
14:50:35.0545 5024 blbdrive - ok
14:50:35.0686 5024 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\windows\system32\DRIVERS\bowser.sys
14:50:35.0686 5024 bowser - ok
14:50:35.0764 5024 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
14:50:35.0764 5024 BrFiltLo - ok
14:50:35.0779 5024 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
14:50:35.0779 5024 BrFiltUp - ok
14:50:35.0857 5024 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
14:50:35.0873 5024 Brserid - ok
14:50:35.0889 5024 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
14:50:35.0904 5024 BrSerWdm - ok
14:50:35.0982 5024 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
14:50:35.0982 5024 BrUsbMdm - ok
14:50:36.0013 5024 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
14:50:36.0013 5024 BrUsbSer - ok
14:50:36.0107 5024 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
14:50:36.0107 5024 BTHMODEM - ok
14:50:36.0232 5024 catchme - ok
14:50:36.0325 5024 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
14:50:36.0325 5024 cdfs - ok
14:50:36.0419 5024 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
14:50:36.0419 5024 cdrom - ok
14:50:36.0544 5024 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
14:50:36.0544 5024 circlass - ok
14:50:36.0575 5024 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
14:50:36.0575 5024 CLFS - ok
14:50:36.0669 5024 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
14:50:36.0669 5024 CmBatt - ok
14:50:36.0684 5024 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
14:50:36.0684 5024 cmdide - ok
14:50:36.0700 5024 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
14:50:36.0715 5024 CNG - ok
14:50:36.0793 5024 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
14:50:36.0793 5024 Compbatt - ok
14:50:36.0887 5024 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
14:50:36.0887 5024 CompositeBus - ok
14:50:36.0965 5024 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
14:50:36.0965 5024 crcdisk - ok
14:50:37.0043 5024 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\windows\system32\Drivers\dfsc.sys
14:50:37.0043 5024 DfsC - ok
14:50:37.0152 5024 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
14:50:37.0152 5024 discache - ok
14:50:37.0183 5024 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
14:50:37.0183 5024 Disk - ok
14:50:37.0277 5024 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
14:50:37.0277 5024 drmkaud - ok
14:50:37.0371 5024 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\windows\System32\drivers\dxgkrnl.sys
14:50:37.0386 5024 DXGKrnl - ok
14:50:37.0527 5024 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
14:50:37.0589 5024 ebdrv - ok
14:50:37.0698 5024 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
14:50:37.0698 5024 elxstor - ok
14:50:37.0807 5024 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
14:50:37.0807 5024 ErrDev - ok
14:50:37.0901 5024 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
14:50:37.0901 5024 exfat - ok
14:50:37.0932 5024 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
14:50:37.0932 5024 fastfat - ok
14:50:37.0963 5024 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
14:50:37.0979 5024 fdc - ok
14:50:38.0026 5024 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
14:50:38.0041 5024 FileInfo - ok
14:50:38.0088 5024 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
14:50:38.0104 5024 Filetrace - ok
14:50:38.0135 5024 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
14:50:38.0135 5024 flpydisk - ok
14:50:38.0197 5024 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
14:50:38.0197 5024 FltMgr - ok
14:50:38.0229 5024 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
14:50:38.0229 5024 FsDepends - ok
14:50:38.0275 5024 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
14:50:38.0275 5024 Fs_Rec - ok
14:50:38.0338 5024 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\windows\system32\DRIVERS\fvevol.sys
14:50:38.0338 5024 fvevol - ok
14:50:38.0385 5024 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
14:50:38.0400 5024 gagp30kx - ok
14:50:38.0525 5024 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
14:50:38.0525 5024 GEARAspiWDM - ok
14:50:38.0650 5024 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
14:50:38.0650 5024 hcw85cir - ok
14:50:38.0946 5024 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
14:50:38.0946 5024 HdAudAddService - ok
14:50:39.0055 5024 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
14:50:39.0055 5024 HDAudBus - ok
14:50:39.0102 5024 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
14:50:39.0102 5024 HidBatt - ok
14:50:39.0149 5024 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
14:50:39.0149 5024 HidBth - ok
14:50:39.0196 5024 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
14:50:39.0211 5024 HidIr - ok
14:50:39.0321 5024 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
14:50:39.0321 5024 HidUsb - ok
14:50:39.0399 5024 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
14:50:39.0414 5024 HpSAMD - ok
14:50:39.0508 5024 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
14:50:39.0523 5024 HTTP - ok
14:50:39.0617 5024 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
14:50:39.0617 5024 hwpolicy - ok
14:50:39.0711 5024 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
14:50:39.0711 5024 i8042prt - ok
14:50:39.0789 5024 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
14:50:39.0789 5024 iaStorV - ok
14:50:39.0835 5024 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
14:50:39.0851 5024 iirsp - ok
14:50:39.0991 5024 IntcAzAudAddService (e4a2e810cb2607c9c159c0dfb0bd4c88) C:\windows\system32\drivers\RTKVHDA.sys
14:50:40.0054 5024 IntcAzAudAddService - ok
14:50:40.0132 5024 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
14:50:40.0132 5024 intelide - ok
14:50:40.0241 5024 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
14:50:40.0241 5024 intelppm - ok
14:50:40.0303 5024 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
14:50:40.0303 5024 IpFilterDriver - ok
14:50:40.0381 5024 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
14:50:40.0381 5024 IPMIDRV - ok
14:50:40.0475 5024 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
14:50:40.0475 5024 IPNAT - ok
14:50:40.0569 5024 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
14:50:40.0569 5024 IRENUM - ok
14:50:40.0631 5024 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
14:50:40.0647 5024 isapnp - ok
14:50:40.0678 5024 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
14:50:40.0693 5024 iScsiPrt - ok
14:50:40.0787 5024 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
14:50:40.0787 5024 kbdclass - ok
14:50:40.0849 5024 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
14:50:40.0849 5024 kbdhid - ok
14:50:40.0896 5024 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
14:50:40.0912 5024 KSecDD - ok
14:50:40.0974 5024 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
14:50:40.0974 5024 KSecPkg - ok
14:50:41.0099 5024 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
14:50:41.0099 5024 lltdio - ok
14:50:41.0193 5024 LPCFilter (6e3d3816749e107883eec5734ce44493) C:\windows\system32\DRIVERS\LPCFilter.sys
14:50:41.0193 5024 LPCFilter - ok
14:50:41.0286 5024 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
14:50:41.0286 5024 LSI_FC - ok
14:50:41.0349 5024 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
14:50:41.0349 5024 LSI_SAS - ok
14:50:41.0395 5024 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
14:50:41.0395 5024 LSI_SAS2 - ok
14:50:41.0520 5024 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
14:50:41.0536 5024 LSI_SCSI - ok
14:50:41.0598 5024 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
14:50:41.0598 5024 luafv - ok
14:50:41.0645 5024 MBAMSwissArmy - ok
14:50:41.0739 5024 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
14:50:41.0739 5024 megasas - ok
14:50:41.0817 5024 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
14:50:41.0817 5024 MegaSR - ok
14:50:41.0879 5024 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
14:50:41.0879 5024 Modem - ok
14:50:41.0910 5024 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
14:50:41.0910 5024 monitor - ok
14:50:42.0019 5024 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
14:50:42.0019 5024 mouclass - ok
14:50:42.0066 5024 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
14:50:42.0066 5024 mouhid - ok
14:50:42.0144 5024 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
14:50:42.0144 5024 mountmgr - ok
14:50:42.0207 5024 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
14:50:42.0207 5024 mpio - ok
14:50:42.0253 5024 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
14:50:42.0253 5024 mpsdrv - ok
14:50:42.0316 5024 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
14:50:42.0331 5024 MRxDAV - ok
14:50:42.0409 5024 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\windows\system32\DRIVERS\mrxsmb.sys
14:50:42.0409 5024 mrxsmb - ok
14:50:42.0472 5024 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\windows\system32\DRIVERS\mrxsmb10.sys
14:50:42.0472 5024 mrxsmb10 - ok
14:50:42.0534 5024 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\windows\system32\DRIVERS\mrxsmb20.sys
14:50:42.0550 5024 mrxsmb20 - ok
14:50:42.0581 5024 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
14:50:42.0581 5024 msahci - ok
14:50:42.0643 5024 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
14:50:42.0643 5024 msdsm - ok
14:50:42.0706 5024 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
14:50:42.0706 5024 Msfs - ok
14:50:42.0753 5024 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
14:50:42.0753 5024 mshidkmdf - ok
14:50:42.0784 5024 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
14:50:42.0784 5024 msisadrv - ok
14:50:42.0862 5024 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
14:50:42.0862 5024 MSKSSRV - ok
14:50:42.0893 5024 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
14:50:42.0893 5024 MSPCLOCK - ok
14:50:42.0987 5024 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
14:50:42.0987 5024 MSPQM - ok
14:50:43.0033 5024 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
14:50:43.0033 5024 MsRPC - ok
14:50:43.0080 5024 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
14:50:43.0096 5024 mssmbios - ok
14:50:43.0127 5024 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
14:50:43.0127 5024 MSTEE - ok
14:50:43.0143 5024 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
14:50:43.0143 5024 MTConfig - ok
14:50:43.0158 5024 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
14:50:43.0158 5024 Mup - ok
14:50:43.0221 5024 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
14:50:43.0252 5024 NativeWifiP - ok
14:50:43.0330 5024 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
14:50:43.0361 5024 NDIS - ok
14:50:43.0439 5024 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
14:50:43.0439 5024 NdisCap - ok
14:50:43.0470 5024 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
14:50:43.0470 5024 NdisTapi - ok
14:50:43.0533 5024 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
14:50:43.0548 5024 Ndisuio - ok
14:50:43.0548 5024 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
14:50:43.0564 5024 NdisWan - ok
14:50:43.0564 5024 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
14:50:43.0579 5024 NDProxy - ok
14:50:43.0689 5024 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
14:50:43.0689 5024 NetBIOS - ok
14:50:43.0720 5024 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
14:50:43.0720 5024 NetBT - ok
14:50:44.0016 5024 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
14:50:44.0016 5024 nfrd960 - ok
14:50:44.0313 5024 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
14:50:44.0313 5024 Npfs - ok
14:50:44.0344 5024 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
14:50:44.0344 5024 nsiproxy - ok
14:50:44.0437 5024 Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys
14:50:44.0484 5024 Ntfs - ok
14:50:44.0562 5024 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
14:50:44.0562 5024 Null - ok
14:50:44.0609 5024 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys
14:50:44.0609 5024 nvraid - ok
14:50:44.0656 5024 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys
14:50:44.0656 5024 nvstor - ok
14:50:44.0734 5024 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
14:50:44.0734 5024 nv_agp - ok
14:50:44.0781 5024 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
14:50:44.0781 5024 ohci1394 - ok
14:50:44.0905 5024 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
14:50:44.0921 5024 Parport - ok
14:50:45.0030 5024 Partizan (6ddcf3f801ec15fe698f6a215cf30a1f) C:\windows\system32\drivers\Partizan.sys
14:50:45.0030 5024 Partizan - ok
14:50:45.0061 5024 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
14:50:45.0077 5024 partmgr - ok
14:50:45.0139 5024 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
14:50:45.0139 5024 Parvdm - ok
14:50:45.0171 5024 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
14:50:45.0171 5024 pci - ok
14:50:45.0264 5024 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
14:50:45.0264 5024 pciide - ok
14:50:45.0295 5024 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
14:50:45.0342 5024 pcmcia - ok
14:50:45.0405 5024 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
14:50:45.0420 5024 pcw - ok
14:50:45.0483 5024 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
14:50:45.0498 5024 PEAUTH - ok
14:50:45.0592 5024 PGEffect (1b5011dd8d57f53aed31ff0f7d635802) C:\windows\system32\DRIVERS\pgeffect.sys
14:50:45.0592 5024 PGEffect - ok
14:50:45.0670 5024 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
14:50:45.0670 5024 PptpMiniport - ok
14:50:45.0732 5024 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
14:50:45.0732 5024 Processor - ok
14:50:45.0810 5024 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
14:50:45.0810 5024 Psched - ok
14:50:45.0857 5024 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
14:50:45.0904 5024 ql2300 - ok
14:50:45.0951 5024 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
14:50:45.0966 5024 ql40xx - ok
14:50:46.0029 5024 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
14:50:46.0029 5024 QWAVEdrv - ok
14:50:46.0075 5024 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
14:50:46.0075 5024 RasAcd - ok
14:50:46.0122 5024 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
14:50:46.0122 5024 RasAgileVpn - ok
14:50:46.0200 5024 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
14:50:46.0200 5024 Rasl2tp - ok
14:50:46.0278 5024 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
14:50:46.0278 5024 RasPppoe - ok
14:50:46.0309 5024 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
14:50:46.0309 5024 RasSstp - ok
14:50:46.0387 5024 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
14:50:46.0387 5024 rdbss - ok
14:50:46.0465 5024 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
14:50:46.0465 5024 rdpbus - ok
14:50:46.0497 5024 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
14:50:46.0497 5024 RDPCDD - ok
14:50:46.0575 5024 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
14:50:46.0575 5024 RDPENCDD - ok
14:50:46.0621 5024 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
14:50:46.0621 5024 RDPREFMP - ok
14:50:46.0715 5024 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
14:50:46.0715 5024 RDPWD - ok
14:50:46.0793 5024 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
14:50:46.0809 5024 rdyboost - ok
14:50:46.0902 5024 RegGuard (37ecebdd930395a9c399fb18a3c236d3) C:\windows\system32\Drivers\regguard.sys
14:50:46.0902 5024 RegGuard - ok
14:50:47.0011 5024 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
14:50:47.0011 5024 rspndr - ok
14:50:47.0089 5024 RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\system32\Drivers\RtsUStor.sys
14:50:47.0089 5024 RSUSBSTOR - ok
14:50:47.0183 5024 RTL8167 (26a9d6227d12b9d9da5a81bb9b55d810) C:\windows\system32\DRIVERS\Rt86win7.sys
14:50:47.0183 5024 RTL8167 - ok
14:50:47.0292 5024 rtl8192se (fd0b1d3ce2e7debd0ae8456494d21488) C:\windows\system32\DRIVERS\rtl8192se.sys
14:50:47.0308 5024 rtl8192se - ok
14:50:47.0386 5024 RtsUIR - ok
14:50:47.0433 5024 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
14:50:47.0433 5024 sbp2port - ok
14:50:47.0495 5024 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
14:50:47.0495 5024 scfilter - ok
14:50:47.0542 5024 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
14:50:47.0542 5024 secdrv - ok
14:50:47.0635 5024 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
14:50:47.0635 5024 Serenum - ok
14:50:47.0713 5024 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
14:50:47.0713 5024 Serial - ok
14:50:47.0776 5024 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
14:50:47.0776 5024 sermouse - ok
14:50:47.0854 5024 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
14:50:47.0854 5024 sffdisk - ok
14:50:47.0932 5024 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
14:50:47.0932 5024 sffp_mmc - ok
14:50:47.0979 5024 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys
14:50:47.0979 5024 sffp_sd - ok
14:50:48.0041 5024 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
14:50:48.0041 5024 sfloppy - ok
14:50:48.0135 5024 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
14:50:48.0135 5024 sisagp - ok
14:50:48.0213 5024 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
14:50:48.0213 5024 SiSRaid2 - ok
14:50:48.0291 5024 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
14:50:48.0306 5024 SiSRaid4 - ok
14:50:48.0384 5024 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
14:50:48.0384 5024 Smb - ok
14:50:48.0431 5024 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
14:50:48.0431 5024 spldr - ok
14:50:48.0525 5024 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\windows\system32\DRIVERS\srv.sys
14:50:48.0525 5024 srv - ok
14:50:48.0618 5024 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\windows\system32\DRIVERS\srv2.sys
14:50:48.0634 5024 srv2 - ok
14:50:48.0712 5024 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\windows\system32\DRIVERS\srvnet.sys
14:50:48.0712 5024 srvnet - ok
14:50:48.0805 5024 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
14:50:48.0805 5024 stexstor - ok
14:50:48.0883 5024 StillCam (edb05bd63148796f23ea78506404a538) C:\windows\system32\DRIVERS\serscan.sys
14:50:48.0883 5024 StillCam - ok
14:50:48.0977 5024 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
14:50:48.0977 5024 swenum - ok
14:50:49.0071 5024 SynTP (8bd10dc8809dc69a1c5a795cb10add76) C:\windows\system32\DRIVERS\SynTP.sys
14:50:49.0086 5024 SynTP - ok
14:50:49.0476 5024 Tcpip (c2daaeb48f3a47c410b041a0d2382ee1) C:\windows\system32\drivers\tcpip.sys
14:50:49.0554 5024 Tcpip - ok
14:50:49.0679 5024 TCPIP6 (c2daaeb48f3a47c410b041a0d2382ee1) C:\windows\system32\DRIVERS\tcpip.sys
14:50:49.0695 5024 TCPIP6 - ok
14:50:49.0757 5024 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
14:50:49.0757 5024 tcpipreg - ok
14:50:49.0835 5024 tdcmdpst (4084ea00d50c858d6f9038f86ae2e2d0) C:\windows\system32\DRIVERS\tdcmdpst.sys
14:50:49.0835 5024 tdcmdpst - ok
14:50:49.0897 5024 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
14:50:49.0897 5024 TDPIPE - ok
14:50:49.0960 5024 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
14:50:49.0960 5024 TDTCP - ok
14:50:49.0991 5024 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
14:50:49.0991 5024 tdx - ok
14:50:50.0053 5024 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
14:50:50.0053 5024 TermDD - ok
14:50:50.0225 5024 tos_sps32 (969377943fe7284609babbab4e06b93c) C:\windows\system32\DRIVERS\tos_sps32.sys
14:50:50.0225 5024 tos_sps32 - ok
14:50:50.0272 5024 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
14:50:50.0272 5024 tssecsrv - ok
14:50:50.0350 5024 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
14:50:50.0365 5024 tunnel - ok
14:50:50.0397 5024 TVALZ (fc24015b4052600c324c43e3a79c0664) C:\windows\system32\DRIVERS\TVALZ_O.SYS
14:50:50.0397 5024 TVALZ - ok
14:50:50.0490 5024 TVALZFL (866462f5ae3f375ef83ef9dce436031c) C:\windows\system32\DRIVERS\TVALZFL.sys
14:50:50.0490 5024 TVALZFL - ok
14:50:50.0553 5024 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
14:50:50.0553 5024 uagp35 - ok
14:50:50.0568 5024 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
14:50:50.0584 5024 udfs - ok
14:50:50.0662 5024 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
14:50:50.0662 5024 uliagpkx - ok
14:50:50.0693 5024 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
14:50:50.0709 5024 umbus - ok
14:50:50.0755 5024 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
14:50:50.0755 5024 UmPass - ok
14:50:50.0849 5024 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
14:50:50.0849 5024 usbaudio - ok
14:50:50.0911 5024 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys
14:50:50.0911 5024 usbccgp - ok
14:50:50.0943 5024 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
14:50:50.0943 5024 usbcir - ok
14:50:51.0021 5024 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys
14:50:51.0021 5024 usbehci - ok
14:50:51.0067 5024 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys
14:50:51.0067 5024 usbhub - ok
14:50:51.0161 5024 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys
14:50:51.0177 5024 usbohci - ok
14:50:51.0208 5024 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
14:50:51.0208 5024 usbprint - ok
14:50:51.0286 5024 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS
14:50:51.0286 5024 USBSTOR - ok
14:50:51.0333 5024 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys
14:50:51.0333 5024 usbuhci - ok
14:50:51.0426 5024 usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\windows\system32\Drivers\usbvideo.sys
14:50:51.0442 5024 usbvideo - ok
14:50:51.0520 5024 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
14:50:51.0520 5024 vdrvroot - ok
14:50:51.0535 5024 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
14:50:51.0535 5024 vga - ok
14:50:51.0551 5024 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
14:50:51.0551 5024 VgaSave - ok
14:50:51.0567 5024 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
14:50:51.0582 5024 vhdmp - ok
14:50:51.0660 5024 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
14:50:51.0660 5024 viaagp - ok
14:50:51.0676 5024 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
14:50:51.0676 5024 ViaC7 - ok
14:50:51.0691 5024 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
14:50:51.0691 5024 viaide - ok
14:50:51.0707 5024 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
14:50:51.0707 5024 volmgr - ok
14:50:51.0738 5024 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
14:50:51.0738 5024 volmgrx - ok
14:50:51.0832 5024 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
14:50:51.0832 5024 volsnap - ok
14:50:51.0925 5024 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
14:50:51.0925 5024 vsmraid - ok
14:50:51.0941 5024 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
14:50:51.0941 5024 vwifibus - ok
14:50:52.0003 5024 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
14:50:52.0003 5024 vwififlt - ok
14:50:52.0066 5024 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
14:50:52.0066 5024 WacomPen - ok
14:50:52.0159 5024 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
14:50:52.0159 5024 WANARP - ok
14:50:52.0159 5024 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
14:50:52.0159 5024 Wanarpv6 - ok
14:50:52.0269 5024 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
14:50:52.0269 5024 Wd - ok
14:50:52.0300 5024 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
14:50:52.0300 5024 Wdf01000 - ok
14:50:52.0425 5024 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
14:50:52.0425 5024 WfpLwf - ok
14:50:52.0440 5024 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
14:50:52.0440 5024 WIMMount - ok
14:50:52.0565 5024 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
14:50:52.0565 5024 WinUsb - ok
14:50:52.0612 5024 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
14:50:52.0612 5024 WmiAcpi - ok
14:50:52.0690 5024 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
14:50:52.0690 5024 ws2ifsl - ok
14:50:52.0799 5024 WSDPrintDevice (553f6ccd7c58eb98d4a8fbdaf283d7a9) C:\windows\system32\DRIVERS\WSDPrint.sys
14:50:52.0799 5024 WSDPrintDevice - ok
14:50:52.0846 5024 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
14:50:52.0846 5024 WudfPf - ok
14:50:52.0955 5024 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
14:50:52.0955 5024 WUDFRd - ok
14:50:53.0017 5024 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
14:50:53.0017 5024 \Device\Harddisk0\DR0 - ok
14:50:53.0033 5024 Boot (0x1200) (812a8ca52030af64a407027329b060f0) \Device\Harddisk0\DR0\Partition0
14:50:53.0033 5024 \Device\Harddisk0\DR0\Partition0 - ok
14:50:53.0033 5024 ============================================================
14:50:53.0033 5024 Scan finished
14:50:53.0033 5024 ============================================================
14:50:53.0049 4332 Detected object count: 0
14:50:53.0049 4332 Actual detected object count: 0

#35 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,817
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 13 October 2011 - 03:16 PM

It looks good and you are good to go now. :thumbup2:

  • It is important to uninstall ComboFix.

    Disable your antivirus temporarily, rename ComboFix to Uninstall and double-click to run it.

    This will uninstall Combofix.

  • Please run OTL.
    • Click Clean Up button.
    • Accept any prompts.
    • This will remove OTL, and will require a reboot.

  • You may delete any tool or log we used from your computer.

  • Make sure your aninvirus is running and updated.

  • Remove the old restore points and create a new restore point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Setting a new restore point AFTER cleaning your system will enable your computer to "roll-back" to a clean working state if needed. :
    • Go to Start => Right-click "Computer" and select "Properties".
    • In the left pane select "System Protection".
    • Press "Configure".
    • Select "Delete". Then press "Continue" close and "OK".
    • Select your drive (drive C) and press "Create".
      Fill in a name for the restore point and press "Create".
      After finished press "Close".

Happy Surfing msgail.:)
Posted Image

#36 User is offline   msgail 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 22
  • Joined: 26-June 08

Posted 14 October 2011 - 04:26 PM

Okay, I have followed all of your instructions, including creating the new restore point. My computer has not run this well in so long. I can not thank you enough. You are wonderful, Farbar, just absolutely wonderful! Thank you.

This post has been edited by msgail: 14 October 2011 - 04:26 PM


#37 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,817
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 14 October 2011 - 04:31 PM

You are most welcome msgail. :)

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a Private Message and I will reopen it for you. If you should have a new issue, please start a new topic.

Every one else should start a new topic.
Posted Image

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users