Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Toonagerhig/City Ville on Facebook


  • This topic is locked This topic is locked
7 replies to this topic

#1 Megsbigbear

Megsbigbear

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sheffield, UK
  • Local time:02:13 AM

Posted 09 March 2011 - 12:26 PM

Hi,

Over the last few days I keep being redirected from Google (not all the time but occasionally - and often when I first try to search for something like Sky who are my ISP). As it is being redirected I am getting "toonagerhig" (I think that's what it's saying)in the address bar before it changes and I end up at a different page. Often this is either "City Ville on Facebook" or one of thiose sites which flashes up that I've been infected and pretends to do a scan showing that virtually all the files are infected. I have run MBAM and SuperAntiSpyware and they have said I have had some things which they quarantined and deleted. However, it is still doing it and when I have run MBAM again it keeps finding, quarantining and deleting a trojan - Fake AI (I think).

I received great advice and step by step instruction a couple of years ago on here that helped me get rid of the "Windowclick" virus, so I'm hoping you might be able to help me again.

Please!!

By the way I am operating Windows 7 32 bit on a Lenovo G550 laptop.

Thanks,

Mick

Edited by Megsbigbear, 09 March 2011 - 12:27 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:13 PM

Posted 09 March 2011 - 05:19 PM

Hi Mick, Let's do these next and see how it is after.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.


TFC by OT (Temp File Cleaner)
Please download TFC by Old Timer and save it to your desktop.
alternate download link

Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal/regular mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Megsbigbear

Megsbigbear
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sheffield, UK
  • Local time:02:13 AM

Posted 10 March 2011 - 04:43 PM

Thanks boopme for your help. I did as you suggested:

I ran TDSSKiller and it found 1 threat. As you can see, I had to run it twice as I realised it was set to 'skip'. Here is the log file;

2011/03/10 21:10:45.0461 2988 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
2011/03/10 21:10:46.0495 2988 ================================================================================
2011/03/10 21:10:46.0496 2988 SystemInfo:
2011/03/10 21:10:46.0496 2988
2011/03/10 21:10:46.0496 2988 OS Version: 6.1.7600 ServicePack: 0.0
2011/03/10 21:10:46.0496 2988 Product type: Workstation
2011/03/10 21:10:46.0496 2988 ComputerName: MICK-PC
2011/03/10 21:10:46.0497 2988 UserName: Mick
2011/03/10 21:10:46.0497 2988 Windows directory: C:\windows
2011/03/10 21:10:46.0497 2988 System windows directory: C:\windows
2011/03/10 21:10:46.0497 2988 Processor architecture: Intel x86
2011/03/10 21:10:46.0497 2988 Number of processors: 2
2011/03/10 21:10:46.0497 2988 Page size: 0x1000
2011/03/10 21:10:46.0497 2988 Boot type: Normal boot
2011/03/10 21:10:46.0497 2988 ================================================================================
2011/03/10 21:10:52.0942 2988 Initialize success
2011/03/10 21:11:06.0345 0988 ================================================================================
2011/03/10 21:11:06.0345 0988 Scan started
2011/03/10 21:11:06.0345 0988 Mode: Manual;
2011/03/10 21:11:06.0345 0988 ================================================================================
2011/03/10 21:11:06.0647 0988 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
2011/03/10 21:11:06.0974 0988 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
2011/03/10 21:11:07.0059 0988 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
2011/03/10 21:11:07.0179 0988 ACPIVPC (87114efedeb94af49323ca61f344716d) C:\windows\system32\DRIVERS\AcpiVpc.sys
2011/03/10 21:11:07.0341 0988 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
2011/03/10 21:11:07.0486 0988 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
2011/03/10 21:11:07.0623 0988 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
2011/03/10 21:11:07.0771 0988 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys
2011/03/10 21:11:07.0880 0988 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
2011/03/10 21:11:08.0000 0988 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
2011/03/10 21:11:08.0128 0988 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
2011/03/10 21:11:08.0232 0988 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
2011/03/10 21:11:08.0308 0988 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
2011/03/10 21:11:08.0404 0988 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
2011/03/10 21:11:08.0455 0988 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
2011/03/10 21:11:08.0560 0988 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
2011/03/10 21:11:08.0642 0988 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
2011/03/10 21:11:08.0741 0988 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
2011/03/10 21:11:08.0854 0988 ApfiltrService (0f83cb9bcb247869bcad28026b8f134b) C:\windows\system32\DRIVERS\Apfiltr.sys
2011/03/10 21:11:08.0977 0988 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
2011/03/10 21:11:09.0115 0988 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
2011/03/10 21:11:09.0180 0988 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
2011/03/10 21:11:09.0287 0988 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
2011/03/10 21:11:09.0419 0988 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
2011/03/10 21:11:09.0562 0988 atksgt (70f72c50d39f5afa76c17f86223a7c4f) C:\windows\system32\DRIVERS\atksgt.sys
2011/03/10 21:11:09.0797 0988 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
2011/03/10 21:11:09.0935 0988 b57nd60x (6f41a4c5745bb99f89406f57164f099e) C:\windows\system32\DRIVERS\b57nd60x.sys
2011/03/10 21:11:10.0159 0988 BCM43XX (f9ce9b5e049efc66b8e6c73c18ee8438) C:\windows\system32\DRIVERS\bcmwl6.sys
2011/03/10 21:11:10.0340 0988 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
2011/03/10 21:11:10.0444 0988 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
2011/03/10 21:11:10.0589 0988 bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys
2011/03/10 21:11:10.0655 0988 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
2011/03/10 21:11:10.0734 0988 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
2011/03/10 21:11:10.0843 0988 Bridge0 (b35bb97b6dd9913093579f5c83962636) C:\windows\system32\drivers\WDBridge.sys
2011/03/10 21:11:11.0072 0988 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
2011/03/10 21:11:11.0185 0988 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
2011/03/10 21:11:11.0257 0988 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
2011/03/10 21:11:11.0326 0988 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
2011/03/10 21:11:11.0402 0988 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\DRIVERS\BthEnum.sys
2011/03/10 21:11:11.0479 0988 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
2011/03/10 21:11:11.0596 0988 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
2011/03/10 21:11:11.0719 0988 BTHPORT (4a34888e13224678dd062466afec4240) C:\windows\system32\Drivers\BTHport.sys
2011/03/10 21:11:11.0845 0988 BTHUSB (fa04c63916fa221dbb91fce153d07a55) C:\windows\system32\Drivers\BTHUSB.sys
2011/03/10 21:11:11.0956 0988 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
2011/03/10 21:11:12.0074 0988 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
2011/03/10 21:11:12.0191 0988 cfwids (7e6f7da1c4de5680820f964562548949) C:\windows\system32\drivers\cfwids.sys
2011/03/10 21:11:12.0291 0988 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
2011/03/10 21:11:12.0406 0988 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
2011/03/10 21:11:12.0537 0988 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
2011/03/10 21:11:12.0607 0988 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
2011/03/10 21:11:12.0700 0988 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
2011/03/10 21:11:12.0834 0988 CnxtHdAudService (7c47786b58ae503777dbd12fae20ed42) C:\windows\system32\drivers\CHDRT32.sys
2011/03/10 21:11:13.0060 0988 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
2011/03/10 21:11:13.0166 0988 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
2011/03/10 21:11:13.0284 0988 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
2011/03/10 21:11:13.0421 0988 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys
2011/03/10 21:11:13.0537 0988 dgderdrv (d0d4f3ca1d3a4400e1f40f36a800cd12) C:\windows\system32\drivers\dgderdrv.sys
2011/03/10 21:11:13.0779 0988 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
2011/03/10 21:11:13.0913 0988 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
2011/03/10 21:11:14.0049 0988 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
2011/03/10 21:11:14.0182 0988 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
2011/03/10 21:11:14.0435 0988 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
2011/03/10 21:11:14.0663 0988 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
2011/03/10 21:11:14.0797 0988 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
2011/03/10 21:11:14.0936 0988 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
2011/03/10 21:11:15.0071 0988 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
2011/03/10 21:11:15.0179 0988 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
2011/03/10 21:11:15.0257 0988 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
2011/03/10 21:11:15.0350 0988 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
2011/03/10 21:11:15.0416 0988 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
2011/03/10 21:11:15.0524 0988 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
2011/03/10 21:11:15.0592 0988 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
2011/03/10 21:11:15.0708 0988 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\windows\system32\DRIVERS\fssfltr.sys
2011/03/10 21:11:15.0932 0988 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\windows\system32\FsUsbExDisk.SYS
2011/03/10 21:11:16.0068 0988 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
2011/03/10 21:11:16.0193 0988 funfrm (f626f291e3f56e8969e35945552feca3) C:\windows\system32\drivers\funfrm.sys
2011/03/10 21:11:16.0382 0988 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys
2011/03/10 21:11:16.0707 0988 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
2011/03/10 21:11:16.0782 0988 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
2011/03/10 21:11:16.0962 0988 ggflt (007aea2e06e7cef7372e40c277163959) C:\windows\system32\DRIVERS\ggflt.sys
2011/03/10 21:11:17.0137 0988 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\windows\system32\DRIVERS\ggsemc.sys
2011/03/10 21:11:17.0242 0988 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
2011/03/10 21:11:17.0356 0988 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
2011/03/10 21:11:17.0478 0988 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
2011/03/10 21:11:17.0580 0988 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
2011/03/10 21:11:17.0637 0988 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
2011/03/10 21:11:17.0764 0988 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
2011/03/10 21:11:17.0909 0988 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
2011/03/10 21:11:18.0045 0988 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
2011/03/10 21:11:18.0170 0988 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
2011/03/10 21:11:18.0303 0988 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
2011/03/10 21:11:18.0415 0988 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
2011/03/10 21:11:18.0553 0988 iaStor (d483687eace0c065ee772481a96e05f5) C:\windows\system32\DRIVERS\iaStor.sys
2011/03/10 21:11:18.0669 0988 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
2011/03/10 21:11:19.0008 0988 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\windows\system32\DRIVERS\igdkmd32.sys
2011/03/10 21:11:19.0387 0988 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
2011/03/10 21:11:19.0470 0988 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
2011/03/10 21:11:19.0574 0988 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
2011/03/10 21:11:19.0661 0988 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
2011/03/10 21:11:19.0785 0988 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
2011/03/10 21:11:19.0842 0988 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
2011/03/10 21:11:19.0978 0988 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
2011/03/10 21:11:20.0095 0988 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
2011/03/10 21:11:20.0179 0988 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
2011/03/10 21:11:20.0281 0988 k57nd60x (c4c95805b85bce1eb9d20f4a02fc5f9b) C:\windows\system32\DRIVERS\k57nd60x.sys
2011/03/10 21:11:20.0409 0988 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
2011/03/10 21:11:20.0528 0988 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
2011/03/10 21:11:20.0636 0988 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
2011/03/10 21:11:20.0766 0988 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
2011/03/10 21:11:21.0027 0988 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\windows\system32\DRIVERS\lirsgt.sys
2011/03/10 21:11:21.0152 0988 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
2011/03/10 21:11:21.0289 0988 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
2011/03/10 21:11:21.0377 0988 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
2011/03/10 21:11:21.0470 0988 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
2011/03/10 21:11:21.0547 0988 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
2011/03/10 21:11:21.0620 0988 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
2011/03/10 21:11:21.0716 0988 MAUSBMICRO (c46265d6723f3259e53a7643c090059d) C:\windows\system32\DRIVERS\MAudioMicro.sys
2011/03/10 21:11:21.0924 0988 MAUSBMIDI (69bc2b743d723d1923fce50eb68003cb) C:\windows\system32\DRIVERS\MAudioUSBMIDI.sys
2011/03/10 21:11:22.0176 0988 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\windows\system32\DRIVERS\mcdbus.sys
2011/03/10 21:11:22.0408 0988 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
2011/03/10 21:11:22.0515 0988 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
2011/03/10 21:11:22.0654 0988 mfeapfk (84d59a3eddfb9438fb94f7f80d37859d) C:\windows\system32\drivers\mfeapfk.sys
2011/03/10 21:11:22.0824 0988 mfeavfk (67e961988312b1a28d6f93357b0bf998) C:\windows\system32\drivers\mfeavfk.sys
2011/03/10 21:11:23.0048 0988 mfebopk (19161b1796cf74a6a326abde309062ba) C:\windows\system32\drivers\mfebopk.sys
2011/03/10 21:11:23.0223 0988 mfefirek (d5f89b4934960c70882924d992c6abfc) C:\windows\system32\drivers\mfefirek.sys
2011/03/10 21:11:23.0374 0988 mfehidk (0efab2b91b27543fe589de700de07136) C:\windows\system32\drivers\mfehidk.sys
2011/03/10 21:11:23.0548 0988 mfenlfk (b4022e16569bbd1a85e68e7e78e68880) C:\windows\system32\DRIVERS\mfenlfk.sys
2011/03/10 21:11:23.0711 0988 mferkdet (c9eda1eada2ab6e34cd1a10c3a24ab25) C:\windows\system32\drivers\mferkdet.sys
2011/03/10 21:11:23.0883 0988 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\windows\system32\drivers\mferkdk.sys
2011/03/10 21:11:24.0043 0988 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\windows\system32\drivers\mfesmfk.sys
2011/03/10 21:11:24.0240 0988 mfewfpk (183f32c79d1693170df3baecec611125) C:\windows\system32\drivers\mfewfpk.sys
2011/03/10 21:11:24.0358 0988 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
2011/03/10 21:11:24.0470 0988 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
2011/03/10 21:11:24.0581 0988 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
2011/03/10 21:11:24.0707 0988 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
2011/03/10 21:11:24.0820 0988 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
2011/03/10 21:11:24.0957 0988 MpFilter (dfa1cd670ea50a21c87c92c727c50950) C:\windows\system32\DRIVERS\MpFilter.sys
2011/03/10 21:11:25.0145 0988 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
2011/03/10 21:11:25.0470 0988 MpKsl3986093a (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{202FCCF0-472E-49EA-A31C-392018C5F312}\MpKsl3986093a.sys
2011/03/10 21:11:25.0728 0988 MpNWMon (77075a384a94b83e19d78efbcf8a832e) C:\windows\system32\DRIVERS\MpNWMon.sys
2011/03/10 21:11:25.0861 0988 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
2011/03/10 21:11:25.0957 0988 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
2011/03/10 21:11:26.0037 0988 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\windows\system32\DRIVERS\mrxsmb.sys
2011/03/10 21:11:26.0202 0988 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\windows\system32\DRIVERS\mrxsmb10.sys
2011/03/10 21:11:26.0360 0988 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\windows\system32\DRIVERS\mrxsmb20.sys
2011/03/10 21:11:26.0535 0988 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
2011/03/10 21:11:26.0620 0988 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
2011/03/10 21:11:26.0716 0988 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
2011/03/10 21:11:26.0802 0988 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
2011/03/10 21:11:26.0857 0988 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
2011/03/10 21:11:26.0997 0988 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
2011/03/10 21:11:27.0126 0988 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
2011/03/10 21:11:27.0221 0988 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
2011/03/10 21:11:27.0298 0988 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
2011/03/10 21:11:27.0422 0988 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
2011/03/10 21:11:27.0541 0988 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
2011/03/10 21:11:27.0603 0988 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
2011/03/10 21:11:27.0708 0988 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
2011/03/10 21:11:27.0851 0988 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
2011/03/10 21:11:28.0024 0988 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
2011/03/10 21:11:28.0162 0988 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
2011/03/10 21:11:28.0255 0988 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
2011/03/10 21:11:28.0339 0988 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
2011/03/10 21:11:28.0447 0988 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
2011/03/10 21:11:28.0511 0988 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
2011/03/10 21:11:28.0614 0988 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
2011/03/10 21:11:28.0697 0988 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
2011/03/10 21:11:28.0933 0988 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\windows\system32\DRIVERS\netw5v32.sys
2011/03/10 21:11:29.0163 0988 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
2011/03/10 21:11:29.0295 0988 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
2011/03/10 21:11:29.0349 0988 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
2011/03/10 21:11:29.0472 0988 Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys
2011/03/10 21:11:29.0639 0988 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
2011/03/10 21:11:29.0749 0988 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys
2011/03/10 21:11:29.0833 0988 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys
2011/03/10 21:11:29.0919 0988 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
2011/03/10 21:11:29.0999 0988 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
2011/03/10 21:11:30.0150 0988 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
2011/03/10 21:11:30.0262 0988 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
2011/03/10 21:11:30.0336 0988 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
2011/03/10 21:11:30.0451 0988 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
2011/03/10 21:11:30.0560 0988 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
2011/03/10 21:11:30.0681 0988 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
2011/03/10 21:11:30.0821 0988 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\windows\system32\Drivers\pcouffin.sys
2011/03/10 21:11:30.0971 0988 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
2011/03/10 21:11:31.0069 0988 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
2011/03/10 21:11:31.0312 0988 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
2011/03/10 21:11:31.0423 0988 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
2011/03/10 21:11:31.0576 0988 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
2011/03/10 21:11:31.0739 0988 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
2011/03/10 21:11:31.0907 0988 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
2011/03/10 21:11:32.0019 0988 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
2011/03/10 21:11:32.0082 0988 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
2011/03/10 21:11:32.0220 0988 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
2011/03/10 21:11:32.0359 0988 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
2011/03/10 21:11:32.0491 0988 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
2011/03/10 21:11:32.0623 0988 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
2011/03/10 21:11:32.0684 0988 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
2011/03/10 21:11:32.0792 0988 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
2011/03/10 21:11:32.0866 0988 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
2011/03/10 21:11:33.0000 0988 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
2011/03/10 21:11:33.0068 0988 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
2011/03/10 21:11:33.0170 0988 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
2011/03/10 21:11:33.0299 0988 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
2011/03/10 21:11:33.0466 0988 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
2011/03/10 21:11:33.0631 0988 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
2011/03/10 21:11:33.0755 0988 RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\System32\Drivers\RtsUStor.sys
2011/03/10 21:11:34.0047 0988 s116bus (815445f4676cc96bc9aeec303c727e19) C:\windows\system32\DRIVERS\s116bus.sys
2011/03/10 21:11:34.0225 0988 s116mdfl (333d1e0743e6de1779c3c418ac601c3a) C:\windows\system32\DRIVERS\s116mdfl.sys
2011/03/10 21:11:34.0380 0988 s116mdm (50d6e5b021e9ec7553ab8a3553cc1b6b) C:\windows\system32\DRIVERS\s116mdm.sys
2011/03/10 21:11:34.0536 0988 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/03/10 21:11:34.0646 0988 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/03/10 21:11:34.0792 0988 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
2011/03/10 21:11:34.0876 0988 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
2011/03/10 21:11:35.0041 0988 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
2011/03/10 21:11:35.0178 0988 seehcri (e5b56569a9f79b70314fede6c953641e) C:\windows\system32\DRIVERS\seehcri.sys
2011/03/10 21:11:35.0359 0988 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
2011/03/10 21:11:35.0421 0988 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
2011/03/10 21:11:35.0534 0988 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
2011/03/10 21:11:35.0669 0988 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
2011/03/10 21:11:35.0739 0988 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
2011/03/10 21:11:35.0848 0988 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys
2011/03/10 21:11:35.0917 0988 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
2011/03/10 21:11:36.0028 0988 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
2011/03/10 21:11:36.0161 0988 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
2011/03/10 21:11:36.0276 0988 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
2011/03/10 21:11:36.0442 0988 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
2011/03/10 21:11:36.0589 0988 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
2011/03/10 21:11:36.0729 0988 sptd (cdddec541bc3c96f91ecb48759673505) C:\windows\system32\Drivers\sptd.sys
2011/03/10 21:11:36.0729 0988 Suspicious file (NoAccess): C:\windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/03/10 21:11:36.0737 0988 sptd - detected Locked file (1)
2011/03/10 21:11:36.0813 0988 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\windows\system32\DRIVERS\srv.sys
2011/03/10 21:11:37.0026 0988 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\windows\system32\DRIVERS\srv2.sys
2011/03/10 21:11:37.0253 0988 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\windows\system32\DRIVERS\srvnet.sys
2011/03/10 21:11:37.0479 0988 sscebus (b2063ce662af3ab20045121a5b716df6) C:\windows\system32\DRIVERS\sscebus.sys
2011/03/10 21:11:37.0653 0988 sscemdfl (66799dc0afe3dcaf8368cae17394a762) C:\windows\system32\DRIVERS\sscemdfl.sys
2011/03/10 21:11:37.0758 0988 sscemdm (cbf03ffc08f8db547bab2f79aa663d16) C:\windows\system32\DRIVERS\sscemdm.sys
2011/03/10 21:11:37.0925 0988 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
2011/03/10 21:11:38.0046 0988 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
2011/03/10 21:11:38.0203 0988 tbhsd (77bd6143c6dce0a1bf7b5571bed860dc) C:\windows\system32\drivers\tbhsd.sys
2011/03/10 21:11:38.0390 0988 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\drivers\tcpip.sys
2011/03/10 21:11:38.0604 0988 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\DRIVERS\tcpip.sys
2011/03/10 21:11:38.0741 0988 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
2011/03/10 21:11:38.0879 0988 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
2011/03/10 21:11:38.0967 0988 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
2011/03/10 21:11:39.0047 0988 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
2011/03/10 21:11:39.0154 0988 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
2011/03/10 21:11:39.0315 0988 TPkd (a00dbb3ccf4e0821dd531db8746a1374) C:\windows\system32\drivers\TPkd.sys
2011/03/10 21:11:39.0531 0988 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
2011/03/10 21:11:39.0670 0988 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
2011/03/10 21:11:39.0783 0988 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
2011/03/10 21:11:39.0862 0988 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
2011/03/10 21:11:40.0012 0988 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
2011/03/10 21:11:40.0135 0988 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
2011/03/10 21:11:40.0198 0988 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
2011/03/10 21:11:40.0318 0988 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\windows\system32\Drivers\usbaapl.sys
2011/03/10 21:11:40.0539 0988 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
2011/03/10 21:11:40.0644 0988 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys
2011/03/10 21:11:40.0810 0988 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
2011/03/10 21:11:40.0922 0988 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys
2011/03/10 21:11:41.0042 0988 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys
2011/03/10 21:11:41.0186 0988 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys
2011/03/10 21:11:41.0300 0988 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
2011/03/10 21:11:41.0437 0988 usbsmi (44cdcf77305096e866381688635064d8) C:\windows\system32\DRIVERS\SMIksdrv.sys
2011/03/10 21:11:41.0614 0988 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS
2011/03/10 21:11:41.0721 0988 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys
2011/03/10 21:11:41.0855 0988 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\System32\Drivers\usbvideo.sys
2011/03/10 21:11:42.0065 0988 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
2011/03/10 21:11:42.0193 0988 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
2011/03/10 21:11:42.0238 0988 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
2011/03/10 21:11:42.0350 0988 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
2011/03/10 21:11:42.0484 0988 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
2011/03/10 21:11:42.0593 0988 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
2011/03/10 21:11:42.0665 0988 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
2011/03/10 21:11:42.0782 0988 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
2011/03/10 21:11:42.0851 0988 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
2011/03/10 21:11:42.0983 0988 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
2011/03/10 21:11:43.0120 0988 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
2011/03/10 21:11:43.0215 0988 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
2011/03/10 21:11:43.0299 0988 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
2011/03/10 21:11:43.0389 0988 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
2011/03/10 21:11:43.0490 0988 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
2011/03/10 21:11:43.0608 0988 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/10 21:11:43.0641 0988 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/10 21:11:43.0803 0988 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
2011/03/10 21:11:43.0884 0988 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
2011/03/10 21:11:44.0035 0988 wdmirror (ea4e9dd00e69b35f9bd3d39acb113e3f) C:\windows\system32\DRIVERS\WDMirror.sys
2011/03/10 21:11:44.0264 0988 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
2011/03/10 21:11:44.0380 0988 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\windows\system32\DRIVERS\wimfltr.sys
2011/03/10 21:11:44.0505 0988 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
2011/03/10 21:11:44.0690 0988 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
2011/03/10 21:11:44.0869 0988 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
2011/03/10 21:11:45.0033 0988 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
2011/03/10 21:11:45.0154 0988 wsvd (baedc491374defd5e76336901d6d397d) C:\windows\system32\DRIVERS\wsvd.sys
2011/03/10 21:11:45.0325 0988 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
2011/03/10 21:11:45.0421 0988 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
2011/03/10 21:11:45.0583 0988 xusb21 (276842a27953be204a2507096f09b1f3) C:\windows\system32\DRIVERS\xusb21.sys
2011/03/10 21:11:45.0696 0988 ================================================================================
2011/03/10 21:11:45.0696 0988 Scan finished
2011/03/10 21:11:45.0696 0988 ================================================================================
2011/03/10 21:11:45.0711 2776 Detected object count: 1
2011/03/10 21:13:05.0907 2776 Locked file(sptd) - User select action: Skip
2011/03/10 21:13:12.0197 4236 ================================================================================
2011/03/10 21:13:12.0197 4236 Scan started
2011/03/10 21:13:12.0197 4236 Mode: Manual;
2011/03/10 21:13:12.0197 4236 ================================================================================
2011/03/10 21:13:12.0492 4236 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
2011/03/10 21:13:12.0619 4236 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
2011/03/10 21:13:12.0716 4236 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
2011/03/10 21:13:12.0769 4236 ACPIVPC (87114efedeb94af49323ca61f344716d) C:\windows\system32\DRIVERS\AcpiVpc.sys
2011/03/10 21:13:12.0863 4236 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
2011/03/10 21:13:12.0942 4236 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
2011/03/10 21:13:13.0023 4236 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
2011/03/10 21:13:13.0127 4236 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\windows\system32\drivers\afd.sys
2011/03/10 21:13:13.0180 4236 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
2011/03/10 21:13:13.0700 4236 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
2011/03/10 21:13:13.0805 4236 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
2011/03/10 21:13:13.0876 4236 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
2011/03/10 21:13:13.0964 4236 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
2011/03/10 21:13:14.0014 4236 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
2011/03/10 21:13:14.0066 4236 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
2011/03/10 21:13:14.0137 4236 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\windows\system32\DRIVERS\amdsata.sys
2011/03/10 21:13:14.0242 4236 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
2011/03/10 21:13:14.0296 4236 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\windows\system32\DRIVERS\amdxata.sys
2011/03/10 21:13:14.0364 4236 ApfiltrService (0f83cb9bcb247869bcad28026b8f134b) C:\windows\system32\DRIVERS\Apfiltr.sys
2011/03/10 21:13:14.0421 4236 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
2011/03/10 21:13:14.0504 4236 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
2011/03/10 21:13:14.0568 4236 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
2011/03/10 21:13:14.0631 4236 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
2011/03/10 21:13:14.0696 4236 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
2011/03/10 21:13:14.0795 4236 atksgt (70f72c50d39f5afa76c17f86223a7c4f) C:\windows\system32\DRIVERS\atksgt.sys
2011/03/10 21:13:14.0886 4236 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
2011/03/10 21:13:14.0968 4236 b57nd60x (6f41a4c5745bb99f89406f57164f099e) C:\windows\system32\DRIVERS\b57nd60x.sys
2011/03/10 21:13:15.0091 4236 BCM43XX (f9ce9b5e049efc66b8e6c73c18ee8438) C:\windows\system32\DRIVERS\bcmwl6.sys
2011/03/10 21:13:15.0206 4236 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
2011/03/10 21:13:15.0266 4236 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
2011/03/10 21:13:15.0355 4236 bowser (fcafaef6798d7b51ff029f99a9898961) C:\windows\system32\DRIVERS\bowser.sys
2011/03/10 21:13:15.0433 4236 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
2011/03/10 21:13:15.0500 4236 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
2011/03/10 21:13:15.0763 4236 Bridge0 (b35bb97b6dd9913093579f5c83962636) C:\windows\system32\drivers\WDBridge.sys
2011/03/10 21:13:16.0050 4236 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
2011/03/10 21:13:16.0095 4236 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
2011/03/10 21:13:16.0189 4236 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
2011/03/10 21:13:16.0259 4236 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
2011/03/10 21:13:16.0323 4236 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\DRIVERS\BthEnum.sys
2011/03/10 21:13:16.0401 4236 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
2011/03/10 21:13:16.0473 4236 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
2011/03/10 21:13:16.0562 4236 BTHPORT (4a34888e13224678dd062466afec4240) C:\windows\system32\Drivers\BTHport.sys
2011/03/10 21:13:16.0623 4236 BTHUSB (fa04c63916fa221dbb91fce153d07a55) C:\windows\system32\Drivers\BTHUSB.sys
2011/03/10 21:13:16.0711 4236 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
2011/03/10 21:13:16.0796 4236 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
2011/03/10 21:13:16.0857 4236 cfwids (7e6f7da1c4de5680820f964562548949) C:\windows\system32\drivers\cfwids.sys
2011/03/10 21:13:16.0946 4236 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
2011/03/10 21:13:17.0017 4236 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
2011/03/10 21:13:17.0126 4236 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
2011/03/10 21:13:17.0162 4236 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
2011/03/10 21:13:17.0266 4236 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
2011/03/10 21:13:17.0344 4236 CnxtHdAudService (7c47786b58ae503777dbd12fae20ed42) C:\windows\system32\drivers\CHDRT32.sys
2011/03/10 21:13:17.0415 4236 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
2011/03/10 21:13:17.0487 4236 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
2011/03/10 21:13:17.0561 4236 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
2011/03/10 21:13:17.0665 4236 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\windows\system32\Drivers\dfsc.sys
2011/03/10 21:13:17.0748 4236 dgderdrv (d0d4f3ca1d3a4400e1f40f36a800cd12) C:\windows\system32\drivers\dgderdrv.sys
2011/03/10 21:13:17.0823 4236 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
2011/03/10 21:13:17.0879 4236 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
2011/03/10 21:13:17.0970 4236 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
2011/03/10 21:13:18.0058 4236 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
2011/03/10 21:13:18.0202 4236 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
2011/03/10 21:13:18.0329 4236 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
2011/03/10 21:13:18.0396 4236 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
2011/03/10 21:13:18.0480 4236 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
2011/03/10 21:13:18.0549 4236 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
2011/03/10 21:13:18.0611 4236 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
2011/03/10 21:13:18.0712 4236 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
2011/03/10 21:13:18.0774 4236 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
2011/03/10 21:13:18.0838 4236 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
2011/03/10 21:13:18.0924 4236 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
2011/03/10 21:13:18.0991 4236 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
2011/03/10 21:13:19.0096 4236 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\windows\system32\DRIVERS\fssfltr.sys
2011/03/10 21:13:19.0175 4236 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\windows\system32\FsUsbExDisk.SYS
2011/03/10 21:13:19.0278 4236 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
2011/03/10 21:13:19.0348 4236 funfrm (f626f291e3f56e8969e35945552feca3) C:\windows\system32\drivers\funfrm.sys
2011/03/10 21:13:19.0448 4236 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys
2011/03/10 21:13:19.0528 4236 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
2011/03/10 21:13:19.0581 4236 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
2011/03/10 21:13:19.0684 4236 ggflt (007aea2e06e7cef7372e40c277163959) C:\windows\system32\DRIVERS\ggflt.sys
2011/03/10 21:13:19.0736 4236 ggsemc (c73de35960ca75c5ab4ae636b127c64e) C:\windows\system32\DRIVERS\ggsemc.sys
2011/03/10 21:13:19.0841 4236 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
2011/03/10 21:13:19.0911 4236 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
2011/03/10 21:13:20.0021 4236 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
2011/03/10 21:13:20.0113 4236 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
2011/03/10 21:13:20.0170 4236 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
2011/03/10 21:13:20.0252 4236 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
2011/03/10 21:13:20.0319 4236 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
2011/03/10 21:13:20.0400 4236 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
2011/03/10 21:13:20.0458 4236 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
2011/03/10 21:13:20.0535 4236 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
2011/03/10 21:13:20.0592 4236 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
2011/03/10 21:13:20.0685 4236 iaStor (d483687eace0c065ee772481a96e05f5) C:\windows\system32\DRIVERS\iaStor.sys
2011/03/10 21:13:20.0790 4236 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\windows\system32\DRIVERS\iaStorV.sys
2011/03/10 21:13:21.0071 4236 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\windows\system32\DRIVERS\igdkmd32.sys
2011/03/10 21:13:21.0209 4236 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
2011/03/10 21:13:21.0269 4236 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
2011/03/10 21:13:21.0362 4236 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
2011/03/10 21:13:21.0472 4236 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
2011/03/10 21:13:21.0550 4236 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
2011/03/10 21:13:21.0630 4236 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
2011/03/10 21:13:21.0700 4236 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
2011/03/10 21:13:21.0772 4236 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
2011/03/10 21:13:21.0844 4236 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
2011/03/10 21:13:21.0936 4236 k57nd60x (c4c95805b85bce1eb9d20f4a02fc5f9b) C:\windows\system32\DRIVERS\k57nd60x.sys
2011/03/10 21:13:21.0997 4236 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
2011/03/10 21:13:22.0072 4236 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
2011/03/10 21:13:22.0135 4236 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
2011/03/10 21:13:22.0209 4236 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
2011/03/10 21:13:22.0326 4236 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\windows\system32\DRIVERS\lirsgt.sys
2011/03/10 21:13:22.0395 4236 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
2011/03/10 21:13:22.0488 4236 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
2011/03/10 21:13:22.0554 4236 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
2011/03/10 21:13:22.0613 4236 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
2011/03/10 21:13:22.0669 4236 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
2011/03/10 21:13:22.0742 4236 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
2011/03/10 21:13:22.0815 4236 MAUSBMICRO (c46265d6723f3259e53a7643c090059d) C:\windows\system32\DRIVERS\MAudioMicro.sys
2011/03/10 21:13:22.0901 4236 MAUSBMIDI (69bc2b743d723d1923fce50eb68003cb) C:\windows\system32\DRIVERS\MAudioUSBMIDI.sys
2011/03/10 21:13:22.0997 4236 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\windows\system32\DRIVERS\mcdbus.sys
2011/03/10 21:13:23.0151 4236 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
2011/03/10 21:13:23.0214 4236 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
2011/03/10 21:13:23.0309 4236 mfeapfk (84d59a3eddfb9438fb94f7f80d37859d) C:\windows\system32\drivers\mfeapfk.sys
2011/03/10 21:13:23.0368 4236 mfeavfk (67e961988312b1a28d6f93357b0bf998) C:\windows\system32\drivers\mfeavfk.sys
2011/03/10 21:13:23.0491 4236 mfebopk (19161b1796cf74a6a326abde309062ba) C:\windows\system32\drivers\mfebopk.sys
2011/03/10 21:13:23.0599 4236 mfefirek (d5f89b4934960c70882924d992c6abfc) C:\windows\system32\drivers\mfefirek.sys
2011/03/10 21:13:23.0695 4236 mfehidk (0efab2b91b27543fe589de700de07136) C:\windows\system32\drivers\mfehidk.sys
2011/03/10 21:13:23.0770 4236 mfenlfk (b4022e16569bbd1a85e68e7e78e68880) C:\windows\system32\DRIVERS\mfenlfk.sys
2011/03/10 21:13:23.0865 4236 mferkdet (c9eda1eada2ab6e34cd1a10c3a24ab25) C:\windows\system32\drivers\mferkdet.sys
2011/03/10 21:13:23.0927 4236 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\windows\system32\drivers\mferkdk.sys
2011/03/10 21:13:24.0020 4236 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\windows\system32\drivers\mfesmfk.sys
2011/03/10 21:13:24.0095 4236 mfewfpk (183f32c79d1693170df3baecec611125) C:\windows\system32\drivers\mfewfpk.sys
2011/03/10 21:13:24.0201 4236 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
2011/03/10 21:13:24.0246 4236 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
2011/03/10 21:13:24.0335 4236 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
2011/03/10 21:13:24.0384 4236 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
2011/03/10 21:13:24.0486 4236 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
2011/03/10 21:13:24.0589 4236 MpFilter (dfa1cd670ea50a21c87c92c727c50950) C:\windows\system32\DRIVERS\MpFilter.sys
2011/03/10 21:13:24.0699 4236 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
2011/03/10 21:13:24.0902 4236 MpKsl3986093a (5f53edfead46fa7adb78eee9ecce8fdf) C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{202FCCF0-472E-49EA-A31C-392018C5F312}\MpKsl3986093a.sys
2011/03/10 21:13:25.0082 4236 MpNWMon (77075a384a94b83e19d78efbcf8a832e) C:\windows\system32\DRIVERS\MpNWMon.sys
2011/03/10 21:13:25.0148 4236 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
2011/03/10 21:13:25.0232 4236 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
2011/03/10 21:13:25.0301 4236 mrxsmb (f1b6aa08497ea86ca6ef6f7a08b0bfb8) C:\windows\system32\DRIVERS\mrxsmb.sys
2011/03/10 21:13:25.0377 4236 mrxsmb10 (5613358b4050f46f5a9832da8050d6e4) C:\windows\system32\DRIVERS\mrxsmb10.sys
2011/03/10 21:13:25.0457 4236 mrxsmb20 (25c9792778d80feb4c8201e62281bfdf) C:\windows\system32\DRIVERS\mrxsmb20.sys
2011/03/10 21:13:25.0533 4236 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
2011/03/10 21:13:25.0584 4236 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
2011/03/10 21:13:25.0692 4236 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
2011/03/10 21:13:25.0756 4236 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
2011/03/10 21:13:25.0832 4236 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
2011/03/10 21:13:25.0906 4236 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
2011/03/10 21:13:25.0979 4236 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
2011/03/10 21:13:26.0030 4236 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
2011/03/10 21:13:26.0096 4236 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
2011/03/10 21:13:26.0165 4236 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
2011/03/10 21:13:26.0249 4236 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
2011/03/10 21:13:26.0312 4236 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
2011/03/10 21:13:26.0394 4236 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
2011/03/10 21:13:26.0471 4236 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
2011/03/10 21:13:26.0600 4236 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
2011/03/10 21:13:26.0704 4236 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
2011/03/10 21:13:26.0808 4236 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
2011/03/10 21:13:26.0903 4236 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
2011/03/10 21:13:26.0967 4236 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
2011/03/10 21:13:27.0042 4236 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
2011/03/10 21:13:27.0089 4236 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
2011/03/10 21:13:27.0161 4236 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
2011/03/10 21:13:27.0340 4236 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\windows\system32\DRIVERS\netw5v32.sys
2011/03/10 21:13:27.0449 4236 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
2011/03/10 21:13:27.0549 4236 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
2011/03/10 21:13:27.0615 4236 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
2011/03/10 21:13:27.0704 4236 Ntfs (3795dcd21f740ee799fb7223234215af) C:\windows\system32\drivers\Ntfs.sys
2011/03/10 21:13:27.0783 4236 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
2011/03/10 21:13:27.0848 4236 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\windows\system32\DRIVERS\nvraid.sys
2011/03/10 21:13:27.0932 4236 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\windows\system32\DRIVERS\nvstor.sys
2011/03/10 21:13:28.0018 4236 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
2011/03/10 21:13:28.0075 4236 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
2011/03/10 21:13:28.0204 4236 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
2011/03/10 21:13:28.0305 4236 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
2011/03/10 21:13:28.0401 4236 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
2011/03/10 21:13:28.0472 4236 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
2011/03/10 21:13:28.0570 4236 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
2011/03/10 21:13:28.0680 4236 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
2011/03/10 21:13:28.0797 4236 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\windows\system32\Drivers\pcouffin.sys
2011/03/10 21:13:28.0881 4236 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
2011/03/10 21:13:28.0945 4236 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
2011/03/10 21:13:29.0133 4236 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
2011/03/10 21:13:29.0210 4236 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
2011/03/10 21:13:29.0330 4236 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
2011/03/10 21:13:29.0471 4236 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
2011/03/10 21:13:29.0593 4236 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
2011/03/10 21:13:29.0706 4236 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
2011/03/10 21:13:29.0814 4236 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
2011/03/10 21:13:29.0918 4236 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
2011/03/10 21:13:29.0980 4236 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
2011/03/10 21:13:30.0078 4236 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
2011/03/10 21:13:30.0188 4236 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
2011/03/10 21:13:30.0272 4236 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
2011/03/10 21:13:30.0324 4236 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
2011/03/10 21:13:30.0420 4236 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
2011/03/10 21:13:30.0477 4236 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
2011/03/10 21:13:30.0600 4236 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
2011/03/10 21:13:30.0669 4236 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
2011/03/10 21:13:30.0742 4236 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
2011/03/10 21:13:30.0854 4236 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
2011/03/10 21:13:30.0940 4236 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
2011/03/10 21:13:31.0031 4236 RSUSBSTOR (ef8b2afc3c0751c5e5a59983c8893260) C:\windows\System32\Drivers\RtsUStor.sys
2011/03/10 21:13:31.0190 4236 s116bus (815445f4676cc96bc9aeec303c727e19) C:\windows\system32\DRIVERS\s116bus.sys
2011/03/10 21:13:31.0279 4236 s116mdfl (333d1e0743e6de1779c3c418ac601c3a) C:\windows\system32\DRIVERS\s116mdfl.sys
2011/03/10 21:13:31.0390 4236 s116mdm (50d6e5b021e9ec7553ab8a3553cc1b6b) C:\windows\system32\DRIVERS\s116mdm.sys
2011/03/10 21:13:31.0479 4236 SASDIFSV (a3281aec37e0720a2bc28034c2df2a56) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
2011/03/10 21:13:31.0512 4236 SASKUTIL (61db0d0756a99506207fd724e3692b25) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
2011/03/10 21:13:31.0613 4236 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
2011/03/10 21:13:31.0686 4236 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
2011/03/10 21:13:31.0784 4236 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
2011/03/10 21:13:31.0866 4236 seehcri (e5b56569a9f79b70314fede6c953641e) C:\windows\system32\DRIVERS\seehcri.sys
2011/03/10 21:13:31.0969 4236 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
2011/03/10 21:13:32.0042 4236 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
2011/03/10 21:13:32.0121 4236 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
2011/03/10 21:13:32.0234 4236 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
2011/03/10 21:13:32.0293 4236 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
2011/03/10 21:13:32.0368 4236 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys
2011/03/10 21:13:32.0438 4236 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
2011/03/10 21:13:32.0527 4236 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
2011/03/10 21:13:32.0615 4236 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
2011/03/10 21:13:32.0686 4236 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
2011/03/10 21:13:32.0773 4236 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
2011/03/10 21:13:32.0865 4236 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
2011/03/10 21:13:32.0973 4236 sptd (cdddec541bc3c96f91ecb48759673505) C:\windows\system32\Drivers\sptd.sys
2011/03/10 21:13:32.0973 4236 Suspicious file (NoAccess): C:\windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/03/10 21:13:32.0983 4236 sptd - detected Locked file (1)
2011/03/10 21:13:33.0078 4236 srv (2dbedfb1853f06110ec2aa7f3213c89f) C:\windows\system32\DRIVERS\srv.sys
2011/03/10 21:13:33.0158 4236 srv2 (db37131d1027c50ea7ee21c8bb4536aa) C:\windows\system32\DRIVERS\srv2.sys
2011/03/10 21:13:33.0240 4236 srvnet (f5980b74124db9233b33f86fc5ebbb4f) C:\windows\system32\DRIVERS\srvnet.sys
2011/03/10 21:13:33.0333 4236 sscebus (b2063ce662af3ab20045121a5b716df6) C:\windows\system32\DRIVERS\sscebus.sys
2011/03/10 21:13:33.0418 4236 sscemdfl (66799dc0afe3dcaf8368cae17394a762) C:\windows\system32\DRIVERS\sscemdfl.sys
2011/03/10 21:13:33.0490 4236 sscemdm (cbf03ffc08f8db547bab2f79aa663d16) C:\windows\system32\DRIVERS\sscemdm.sys
2011/03/10 21:13:33.0568 4236 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
2011/03/10 21:13:33.0633 4236 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
2011/03/10 21:13:33.0735 4236 tbhsd (77bd6143c6dce0a1bf7b5571bed860dc) C:\windows\system32\drivers\tbhsd.sys
2011/03/10 21:13:33.0847 4236 Tcpip (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\drivers\tcpip.sys
2011/03/10 21:13:33.0946 4236 TCPIP6 (bb7f39c31c4a4417fd318e7cd184e225) C:\windows\system32\DRIVERS\tcpip.sys
2011/03/10 21:13:34.0040 4236 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
2011/03/10 21:13:34.0111 4236 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
2011/03/10 21:13:34.0198 4236 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
2011/03/10 21:13:34.0267 4236 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
2011/03/10 21:13:34.0352 4236 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
2011/03/10 21:13:34.0469 4236 TPkd (a00dbb3ccf4e0821dd531db8746a1374) C:\windows\system32\drivers\TPkd.sys
2011/03/10 21:13:34.0563 4236 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
2011/03/10 21:13:34.0623 4236 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
2011/03/10 21:13:34.0715 4236 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
2011/03/10 21:13:34.0804 4236 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
2011/03/10 21:13:34.0943 4236 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
2011/03/10 21:13:35.0011 4236 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
2011/03/10 21:13:35.0085 4236 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
2011/03/10 21:13:35.0195 4236 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\windows\system32\Drivers\usbaapl.sys
2011/03/10 21:13:35.0282 4236 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
2011/03/10 21:13:35.0365 4236 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\windows\system32\DRIVERS\usbccgp.sys
2011/03/10 21:13:35.0508 4236 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
2011/03/10 21:13:35.0609 4236 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\windows\system32\DRIVERS\usbehci.sys
2011/03/10 21:13:35.0673 4236 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\windows\system32\DRIVERS\usbhub.sys
2011/03/10 21:13:35.0762 4236 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\windows\system32\DRIVERS\usbohci.sys
2011/03/10 21:13:35.0832 4236 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
2011/03/10 21:13:35.0913 4236 usbsmi (44cdcf77305096e866381688635064d8) C:\windows\system32\DRIVERS\SMIksdrv.sys
2011/03/10 21:13:35.0968 4236 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\windows\system32\DRIVERS\USBSTOR.SYS
2011/03/10 21:13:36.0030 4236 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\windows\system32\DRIVERS\usbuhci.sys
2011/03/10 21:13:36.0120 4236 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\System32\Drivers\usbvideo.sys
2011/03/10 21:13:36.0218 4236 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
2011/03/10 21:13:36.0292 4236 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
2011/03/10 21:13:36.0380 4236 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
2011/03/10 21:13:36.0493 4236 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
2011/03/10 21:13:36.0593 4236 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
2011/03/10 21:13:36.0680 4236 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
2011/03/10 21:13:36.0752 4236 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
2011/03/10 21:13:36.0825 4236 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
2011/03/10 21:13:36.0904 4236 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
2011/03/10 21:13:37.0015 4236 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
2011/03/10 21:13:37.0074 4236 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
2011/03/10 21:13:37.0191 4236 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
2011/03/10 21:13:37.0297 4236 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
2011/03/10 21:13:37.0364 4236 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\windows\system32\DRIVERS\vwifimp.sys
2011/03/10 21:13:37.0465 4236 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
2011/03/10 21:13:37.0561 4236 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/10 21:13:37.0583 4236 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
2011/03/10 21:13:37.0712 4236 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
2011/03/10 21:13:37.0793 4236 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
2011/03/10 21:13:37.0910 4236 wdmirror (ea4e9dd00e69b35f9bd3d39acb113e3f) C:\windows\system32\DRIVERS\WDMirror.sys
2011/03/10 21:13:38.0006 4236 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
2011/03/10 21:13:38.0099 4236 WimFltr (f9ad3a5e3fd7e0bdb18b8202b0fdd4e4) C:\windows\system32\DRIVERS\wimfltr.sys
2011/03/10 21:13:38.0213 4236 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
2011/03/10 21:13:38.0376 4236 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
2011/03/10 21:13:38.0455 4236 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
2011/03/10 21:13:38.0586 4236 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
2011/03/10 21:13:38.0729 4236 wsvd (baedc491374defd5e76336901d6d397d) C:\windows\system32\DRIVERS\wsvd.sys
2011/03/10 21:13:38.0844 4236 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
2011/03/10 21:13:38.0952 4236 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
2011/03/10 21:13:39.0080 4236 xusb21 (276842a27953be204a2507096f09b1f3) C:\windows\system32\DRIVERS\xusb21.sys
2011/03/10 21:13:39.0149 4236 ================================================================================
2011/03/10 21:13:39.0149 4236 Scan finished
2011/03/10 21:13:39.0149 4236 ================================================================================
2011/03/10 21:13:39.0162 5960 Detected object count: 1
2011/03/10 21:14:01.0006 5960 HKLM\SYSTEM\ControlSet001\services\sptd - will be deleted after reboot
2011/03/10 21:14:01.0035 5960 HKLM\SYSTEM\ControlSet002\services\sptd - will be deleted after reboot
2011/03/10 21:14:01.0054 5960 C:\windows\system32\Drivers\sptd.sys - will be deleted after reboot
2011/03/10 21:14:01.0054 5960 Locked file(sptd) - User select action: Delete
2011/03/10 21:14:13.0408 4120 Deinitialize success

I then ran TFC followed by MBAM. MBAM showed clear of malicious items. Here is the MBAM log file;

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6012

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

10/03/2011 21:32:03
mbam-log-2011-03-10 (21-32-03).txt

Scan type: Quick scan
Objects scanned: 150623
Time elapsed: 8 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


How does it look to you now?

Thanks,

Mick

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:13 PM

Posted 10 March 2011 - 05:16 PM

OK, the redirecting is gone?

we should still run an Online scan.

ESET Online Scan
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Megsbigbear

Megsbigbear
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sheffield, UK
  • Local time:02:13 AM

Posted 11 March 2011 - 03:10 AM

Ok. So I've run ESETScan and the log file is as follows:

C:\Users\Mick\Documents\KINGSTON\Setup_FreeConverter.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\Users\Mick\Documents\KINGSTON\SmitfraudFix.exe multiple threats deleted - quarantined
C:\Users\Mick\Documents\Programs\Setup_FreeConverter.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\Users\Mick\Kingston\KINGSTON\Setup_FreeConverter.exe Win32/Adware.Toolbar.Dealio application deleted - quarantined
C:\Users\Mick\Kingston\KINGSTON\SmitfraudFix.exe multiple threats deleted - quarantined

But when I came to log on to submit the report, I'm still getting redirected and it took 3 attempts to get here - via City Ville at Facebook and Swiss IT I think it was. And each time it redirected, the address bar temporarily showed diffenet variations of www.toonagernhig.com searches. Imanaged to copy a couple of them so you could see in case you'd come across it before:

hxxp://www.goingonearth.com/search.php?q=amazon&n=1299830522
hxxp://www.goingonearth.com/search.php?q=bbc&n=1299830466

You can see in the address that I was searching for amazon and bbc - just to see if I could capture the redirecting address.

I hope this might be useful to you - because it's really bugging me. I've noticed that there are quite a few posts about Google redirect - does it seem to be a malicious thing or just an annoying thing? Also am I better avoiding Google for the time being?

Thanks,

Mick

Edited by Orange Blossom, 15 April 2011 - 08:10 PM.
Deactivated links. ~ OB


#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,213 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:13 PM

Posted 11 March 2011 - 04:45 PM

Mostly annoying,but some times they want to redirct you to a page with a malicious script in it to install more sinister malware.
Problem we have now is I cannot see it so it must be protected. Hence we need our malware team to dig this out.

We need a deeper look. Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
Include the GMER log you posted earlier.
Let me know if that went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 Megsbigbear

Megsbigbear
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Sheffield, UK
  • Local time:02:13 AM

Posted 15 March 2011 - 02:53 AM

Hi Boopme.
Just in the process of doing the prep (including finally backing up!). I'll let you know how I get on.
Thanks again for all your help. This site and people like you are fantastic!!!

#8 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,947 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:10:13 PM

Posted 15 April 2011 - 08:11 PM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic390363.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users