Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

"JS/Blacole.CM" Detected by MSSE


  • Please log in to reply
20 replies to this topic

#1 Cyntil8ing

Cyntil8ing

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 28 February 2012 - 02:57 PM

Hello,

MSSE recently detected "JS/Blacole.CM" in my comp. I selected clean and it was reported cleaned by MSSE but i was still getting browser redirects to some bogus wiki page and random inability to reach desired pages/sites. Unusual 404s and "DNS" failures have so far been the results but even they look fake as well.

I went ahead and ran MSSE again in full scan and nothing else was found. I also ran SuperAntiSpyware, MBAM, and ESET Online scan. MSSE, despite the initial detection, found nothing. Super found nothing as well. MBAM effectively found nothing except for an app that I've been using for quite a while now. ESET Online had better results.

Anther bit of information that, I think, may be of importance is that the JAVA console was open when it was detected.

I'll be posting the ff logs: MiniToolBox, MBAM, and ESET online.


Thanks.

BC AdBot (Login to Remove)

 


#2 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 28 February 2012 - 02:58 PM

MiniToolBox by Farbar Version: 18-01-2012
Ran by Mao (administrator) on 28-02-2012 at 15:56:27
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================



========================= IP Configuration: ================================

Intel® PRO/1000 MT Desktop Adapter = Local Area Connection 2 (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Mao-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection 2:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel® PRO/1000 MT Desktop Adapter
Physical Address. . . . . . . . . : 00-07-E9-10-93-5D
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv4 Address. . . . . . . . . . . : 192.168.1.5(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Tuesday, February 28, 2012 9:48:09 AM
Lease Expires . . . . . . . . . . : Wednesday, February 29, 2012 9:48:09 AM
Default Gateway . . . . . . . . . : 192.168.1.2
DHCP Server . . . . . . . . . . . : 192.168.1.2
DNS Servers . . . . . . . . . . . : 192.168.1.2
8.8.8.8
8.8.4.4
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{4EC56C13-9910-4F3B-BFFE-B13E0E7723BC}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: UnKnown
Address: 192.168.1.2

Name: google.com
Addresses: 74.125.71.139
74.125.71.138
74.125.71.100
74.125.71.101
74.125.71.102
74.125.71.113


Pinging google.com [74.125.71.113] with 32 bytes of data:
Reply from 74.125.71.113: bytes=32 time=50ms TTL=51
Reply from 74.125.71.113: bytes=32 time=58ms TTL=54

Ping statistics for 74.125.71.113:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 50ms, Maximum = 58ms, Average = 54ms
Server: UnKnown
Address: 192.168.1.2

Name: yahoo.com
Addresses: 98.139.127.62
98.139.183.24
209.191.122.70


Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
Reply from 209.191.122.70: bytes=32 time=230ms TTL=46
Reply from 209.191.122.70: bytes=32 time=229ms TTL=47

Ping statistics for 209.191.122.70:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 229ms, Maximum = 230ms, Average = 229ms
Server: UnKnown
Address: 192.168.1.2

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
15...00 07 e9 10 93 5d ......Intel® PRO/1000 MT Desktop Adapter
1...........................Software Loopback Interface 1
10...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
11...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.2 192.168.1.5 10
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.5 266
192.168.1.5 255.255.255.255 On-link 192.168.1.5 266
192.168.1.255 255.255.255.255 On-link 192.168.1.5 266
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.5 266
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.5 266
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
1 306 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (02/28/2012 07:02:08 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/27/2012 03:10:19 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/26/2012 04:44:53 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/25/2012 02:18:08 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/24/2012 03:35:45 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/23/2012 03:32:21 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/22/2012 06:04:43 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "imaging1".Error in manifest or policy file "imaging2" on line imaging3.
The element imaging appears as a child of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by this version of Windows.

Error: (02/22/2012 01:38:23 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (02/22/2012 01:37:25 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.

Error: (02/22/2012 00:42:18 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.
.


System errors:
=============
Error: (02/28/2012 09:50:48 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1058

Error: (02/28/2012 09:48:25 AM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error: (02/28/2012 00:52:17 AM) (Source: TermDD) (User: )
Description: The Terminal Server security layer detected an error in the protocol stream and has disconnected the client.
Client IP: 192.168.1.4.

Error: (02/24/2012 10:06:34 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1058

Error: (02/24/2012 10:06:07 AM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error: (02/24/2012 10:04:44 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1058

Error: (02/24/2012 10:00:11 AM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1058

Error: (02/24/2012 09:59:39 AM) (Source: SNMP) (User: )
Description: The SNMP Service encountered an error while accessing the registry key SYSTEM\CurrentControlSet\Services\SNMP\Parameters\TrapConfiguration.

Error: (02/24/2012 09:59:22 AM) (Source: Service Control Manager) (User: )
Description: The AODDriver4.01 service failed to start due to the following error:
%%3

Error: (02/24/2012 09:57:43 AM) (Source: Service Control Manager) (User: )
Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
%%1068


Microsoft Office Sessions:
=========================
Error: (02/28/2012 07:02:08 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/27/2012 03:10:19 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/26/2012 04:44:53 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/25/2012 02:18:08 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/24/2012 03:35:45 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/23/2012 03:32:21 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/22/2012 06:04:43 AM) (Source: SideBySide)(User: )
Description: imagingurn:schemas-microsoft-com:asm.v1^assemblyc:\program files\microsoft security client\MSESysprep.dllc:\program files\microsoft security client\MSESysprep.dll10

Error: (02/22/2012 01:38:23 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (02/22/2012 01:37:25 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.

Error: (02/22/2012 00:42:18 AM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: Details:
AddWin32ServiceFiles: Unable to back up image of service NovaStor NovaBACKUP Backup/Copy Engine since QueryServiceConfig API failed

System Error:
The system cannot find the file specified.


=========================== Installed Programs ============================

µTorrent (Version: 3.1.0)
Adobe AIR (Version: 2.7.1.19610)
Adobe Flash Player 10 ActiveX (Version: 10.3.183.10)
Adobe Flash Player 11 Plugin 64-bit (Version: 11.1.102.62)
Adobe Reader X (10.1.2) (Version: 10.1.2)
AMD APP SDK Runtime (Version: 10.0.851.4)
AMD Catalyst Install Manager (Version: 3.0.859.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2010.1125.2148.39102)
AMD Fuel (Version: 2011.1205.2215.39827)
AMD Media Foundation Decoders (Version: 1.0.61205.2219)
AMD VISION Engine Control Center (Version: 2011.1205.2215.39827)
ATI Problem Report Wizard (Version: 3.0.804.0)
Boxee
BUFFALO LinkStation(LS-VL Series) Setup Guide
BUFFALO NAS Navigator2
BUFFALO Network-USB Navigator (Version: 1.10)
BUFFALO TurboCopy
BUFFALO TurboPC for FLASH/HDD
Canon iP2700 series Printer Driver
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2010.1125.2148.39102)
Catalyst Control Center Graphics Previews Common (Version: 2011.1205.2215.39827)
Catalyst Control Center InstallProxy (Version: 2010.1125.2148.39102)
Catalyst Control Center InstallProxy (Version: 2011.0419.2218.38209)
Catalyst Control Center InstallProxy (Version: 2011.0908.1355.23115)
Catalyst Control Center InstallProxy (Version: 2011.1205.2215.39827)
Catalyst Control Center Localization All (Version: 2010.1125.2148.39102)
Catalyst Control Center Localization All (Version: 2011.1205.2215.39827)
Catalyst Control Center Profiles Desktop (Version: 2010.1125.2148.39102)
ccc-core-static (Version: 2010.1125.2148.39102)
ccc-utility64 (Version: 2010.1125.2148.39102)
ccc-utility64 (Version: 2011.1205.2215.39827)
CCC Help Chinese Standard (Version: 2010.1125.2147.39102)
CCC Help Chinese Standard (Version: 2011.1205.2214.39827)
CCC Help Chinese Traditional (Version: 2010.1125.2147.39102)
CCC Help Chinese Traditional (Version: 2011.1205.2214.39827)
CCC Help Czech (Version: 2010.1125.2147.39102)
CCC Help Czech (Version: 2011.1205.2214.39827)
CCC Help Danish (Version: 2010.1125.2147.39102)
CCC Help Danish (Version: 2011.1205.2214.39827)
CCC Help Dutch (Version: 2010.1125.2147.39102)
CCC Help Dutch (Version: 2011.1205.2214.39827)
CCC Help English (Version: 2010.1125.2147.39102)
CCC Help English (Version: 2011.1205.2214.39827)
CCC Help Finnish (Version: 2010.1125.2147.39102)
CCC Help Finnish (Version: 2011.1205.2214.39827)
CCC Help French (Version: 2010.1125.2147.39102)
CCC Help French (Version: 2011.1205.2214.39827)
CCC Help German (Version: 2010.1125.2147.39102)
CCC Help German (Version: 2011.1205.2214.39827)
CCC Help Greek (Version: 2010.1125.2147.39102)
CCC Help Greek (Version: 2011.1205.2214.39827)
CCC Help Hungarian (Version: 2010.1125.2147.39102)
CCC Help Hungarian (Version: 2011.1205.2214.39827)
CCC Help Italian (Version: 2010.1125.2147.39102)
CCC Help Italian (Version: 2011.1205.2214.39827)
CCC Help Japanese (Version: 2010.1125.2147.39102)
CCC Help Japanese (Version: 2011.1205.2214.39827)
CCC Help Korean (Version: 2010.1125.2147.39102)
CCC Help Korean (Version: 2011.1205.2214.39827)
CCC Help Norwegian (Version: 2010.1125.2147.39102)
CCC Help Norwegian (Version: 2011.1205.2214.39827)
CCC Help Polish (Version: 2010.1125.2147.39102)
CCC Help Polish (Version: 2011.1205.2214.39827)
CCC Help Portuguese (Version: 2010.1125.2147.39102)
CCC Help Portuguese (Version: 2011.1205.2214.39827)
CCC Help Russian (Version: 2010.1125.2147.39102)
CCC Help Russian (Version: 2011.1205.2214.39827)
CCC Help Spanish (Version: 2010.1125.2147.39102)
CCC Help Spanish (Version: 2011.1205.2214.39827)
CCC Help Swedish (Version: 2010.1125.2147.39102)
CCC Help Swedish (Version: 2011.1205.2214.39827)
CCC Help Thai (Version: 2010.1125.2147.39102)
CCC Help Thai (Version: 2011.1205.2214.39827)
CCC Help Turkish (Version: 2011.1205.2214.39827)
CCleaner (Version: 3.16)
Cinema HD 2.0 (Version: 2.11.715)
CNET TechTracker (Version: 2.0.0)
CPUID HWMonitor 1.19
CrystalDiskInfo 4.3.0 Beta1 (Version: 4.3.0 Beta1)
Curse Client (Version: 4.0.1.260)
D3DX10 (Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition
Disktrix UltimateDefrag 3.0 (Version: 3.0.100.39)
Driver Sweeper version 3.2.0 (Version: 3.2.0)
DVD Flick 1.3.0.7 (Version: 1.3.0.7)
eReg (Version: 1.20.138.34)
Game Booster 3 (Version: 3.2)
HD Tune Pro 5.00
ImgBurn (Version: 2.5.5.0)
Internet TV for Windows Media Center (Version: 4.2.2.0)
IZArc 4.1.6 (Version: 4.1.6)
Java Auto Updater (Version: 2.0.7.1)
Java™ 6 Update 31 (64-bit) (Version: 6.0.310)
Java™ 6 Update 31 (Version: 6.0.310)
JeS Updater (Version: 0.10.0000)
Junk Mail filter update (Version: 15.4.3502.0922)
K-Lite Codec Pack 5.9.0 (64-bit) (Version: 5.9.0)
K-Lite Mega Codec Pack 8.4.0 (Version: 8.4.0)
Mafia II
magicJack (Version: 2.0.6073.4252)
Malwarebytes Anti-Malware version 1.60.1.1000 (Version: 1.60.1.1000)
Mass Effect 2 (Version: 1.02)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Antimalware (Version: 3.0.8402.2)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft IntelliPoint 8.2 (Version: 8.20.468.0)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Groove MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office InfoPath MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared 32-bit MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Security Client (Version: 2.1.1116.0)
Microsoft Security Essentials (Version: 2.1.1116.0)
Microsoft Silverlight (Version: 5.0.61118.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (MYMOVIES) (Version: 9.4.5000.00)
Microsoft SQL Server 2005 Tools Express Edition (Version: 9.4.5000.00)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft XML Parser (Version: 8.70.1104.04)
Mozilla Firefox 10.0.2 (x86 en-US) (Version: 10.0.2)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
NetWorx 5.2.2
NirSoft VideoCacheView
NVIDIA Drivers (Version: 1.10.62.40)
NVIDIA Install Application (Version: 2.0.14.0)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX System Software 9.10.0514 (Version: 9.10.0514)
PDF Form Filler 2 (Version: 2.0.43)
PeerBlock 1.1 (r518) (Version: 1.1.0.518)
PlayReady PC Runtime amd64 (Version: 1.3.0)
PLDT-WatchPad (Version: 1.0.0.21)
Protected Folder
Realtek High Definition Audio Driver (Version: 6.0.1.6526)
Revo Uninstaller Pro 2.5.7 (Version: 2.5.7)
Secunia PSI (2.0.0.4003) (Version: 2.0.0.4003)
SUPERAntiSpyware (Version: 5.0.1108)
SyQic Yoonic Engine - PLDT Watchpad (Version: 1.0.0)
System Requirements Lab
System Requirements Lab for Intel (Version: 4.4.24.0)
Tixati
Torrent Episode Downloader (Version: 0.972)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft Excel 2010 (KB2553439) 64-Bit Edition
Update for Microsoft Office 2010 (KB2494150)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition
Update for Microsoft Office 2010 (KB2553385) 64-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2597091) 64-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition
Update for Microsoft Outlook 2010 (KB2553323) 64-Bit Edition
Update for Microsoft Outlook Social Connector (KB2583935)
Veetle TV 0.9.18 (Version: 0.9.18)
Ventrilo Client for Windows x64 (Version: 3.0.8.0)
VLC media player 2.0.0 (Version: 2.0.0)
Windows 7 USB/DVD Download Tool (Version: 1.0.24.0)
Windows 7 USB/DVD Download Tool (Version: 1.0.30)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3538.0513)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows XP Mode (Version: 1.3.7600.16423)

========================= Memory info: ===================================

Percentage of memory in use: 36%
Total physical RAM: 4095.24 MB
Available physical RAM: 2616.3 MB
Total Pagefile: 8188.68 MB
Available Pagefile: 6481.74 MB
Total Virtual: 4095.88 MB
Available Virtual: 3966.7 MB

========================= Partitions: =====================================

1 Drive c: (Win7) (Fixed) (Total:297.99 GB) (Free:214 GB) NTFS
2 Drive d: (Media) (Fixed) (Total:1397.26 GB) (Free:1085.59 GB) NTFS
3 Drive e: (WinXP) (Fixed) (Total:186.31 GB) (Free:97.75 GB) NTFS
4 Drive f: (GRTMHFPP_EN) (CDROM) (Total:0.55 GB) (Free:0 GB) CDFS

========================= Users: ========================================

User accounts for \\MAO-PC

Administrator Guest Mao


**** End of log ****

#3 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 28 February 2012 - 03:01 PM

C:\Users\Mao\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9\689faa49-42fe9efc a variant of Java/Exploit.CVE-2011-3544.AU trojan deleted - quarantined
C:\Users\Mao\AppData\Roaming\Microsoft\Windows\Templates\keygen.exe a variant of MSIL/TrojanDownloader.Agent.AO trojan cleaned by deleting - quarantined
C:\Users\Mao\Downloads\CrystalDiskInfo4_0_3-en.exe Win32/OpenCandy application deleted - quarantined
C:\Users\Mao\Downloads\DriverSweeper_3.2.0.exe Win32/OpenCandy application deleted - quarantined
C:\Users\Mao\Downloads\Apps\Audio-Video Utilities\cnet_DTLite4413-0173_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\Users\Mao\Downloads\Apps\Compression Utilities\IZArc4.1.6.exe Win32/OpenCandy application deleted - quarantined
C:\Users\Mao\Downloads\Apps\Utilities\CrystalDiskInfo4_3_0B1-en.exe Win32/OpenCandy application deleted - quarantined
C:\Windows\AutoKMS\AutoKMS.exe probably a variant of Win32/HackKMS.B application cleaned by deleting - quarantined
D:\Apps\Video Converter\avc-free.exe Win32/OpenCandy application deleted - quarantined
D:\Apps\Win7\Hax\SLIC_ToolKit_V3.2.rar a variant of Win32/FlyStudio application deleted - quarantined
D:\Apps\Win7\Hax\SLIC_ToolKit_V3.2\SLIC_ToolKit_V3.2.EXE a variant of Win32/FlyStudio application cleaned by deleting - quarantined
D:\Games\Assassins.Creed.II-SKIDROW\sr-acii.iso a variant of Win32/Packed.VMProtect.AAA trojan deleted - quarantined
D:\Games\Mass_Effect_2-Razor1911\bws-0589.rar a variant of Win32/GameHack.E application deleted - quarantined
D:\Games\Mass_Effect_2-Razor1911\bws-me202.exe a variant of Win32/GameHack.E application cleaned by deleting - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Backup Apps\fbsetup.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\HD Diagnostics and Utilities\CrystalDiskInfo4_0_2a-en.exe Win32/OpenCandy application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Maintenance Utilities\CNET_TechTracker_2_0_4_Setup.exe Win32/OpenCandy application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Maintenance Utilities\DriverSweeper_3.1.0.exe Win32/OpenCandy application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Maintenance Utilities\sd2-setup220.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Media\SUPERsetup.exe Win32/OpenCandy application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\cnet_DTLite4413-0173_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\gamebooster.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\gamebooster_001.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\gb3-setup.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\GBv2.1FULL.rar a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\IZArc4.1.6.exe Win32/OpenCandy application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\GB2.2\gamebooster22.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Misc Utilities\GB2.2\GB2.2.rar a variant of Win32/Toolbar.Widgi application deleted - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Net Utilities\cnet_jre-6u27-windows-i586_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
E:\Documents and Settings\Mao\My Documents\Downloads\Net Utilities\networx_setup_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
E:\WINDOWS\KMSEmulator.exe a variant of Win32/HackKMS.A application cleaned by deleting - quarantined

Edited by Cyntil8ing, 28 February 2012 - 03:03 PM.


#4 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 28 February 2012 - 03:03 PM

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.27.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Mao :: MAO-PC [administrator]

2/27/2012 11:31:16 PM
mbam-log-2012-02-27 (23-31-16).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 440953
Time elapsed: 3 hour(s), 33 minute(s), 33 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Users\Mao\Downloads\Apps\Utilities\Revo Uninstaller Pro 2.5.7\patch\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> No action taken.
C:\Program Files\VS Revo Group\Revo Uninstaller Pro\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.

(end)

#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 02 March 2012 - 08:46 PM

Hello,what happened was the other posts ,removed the 0 repltes and makes it appear as if you are being helped.
Appears you were infected from a torrent.

Which scan log is that in post 3?


Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log have a name like: TDSSKiller.Version_Date_Time_log.txt.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 02 March 2012 - 11:04 PM

Hello and thanks for the response.
The unlabeled log was from ESET online. Odd, I could've sworn it was labeled.

Here's the TDSSKiller log you requested:

11:49:58.0301 3820 TDSS rootkit removing tool 2.7.18.0 Mar 2 2012 09:40:07
11:49:59.0514 3820 ============================================================
11:49:59.0514 3820 Current date / time: 2012/03/03 11:49:59.0514
11:49:59.0514 3820 SystemInfo:
11:49:59.0514 3820
11:49:59.0514 3820 OS Version: 6.1.7601 ServicePack: 1.0
11:49:59.0514 3820 Product type: Workstation
11:49:59.0514 3820 ComputerName: MAO-PC
11:49:59.0514 3820 UserName: Mao
11:49:59.0514 3820 Windows directory: C:\Windows
11:49:59.0514 3820 System windows directory: C:\Windows
11:49:59.0514 3820 Running under WOW64
11:49:59.0514 3820 Processor architecture: Intel x64
11:49:59.0514 3820 Number of processors: 2
11:49:59.0514 3820 Page size: 0x1000
11:49:59.0514 3820 Boot type: Normal boot
11:49:59.0514 3820 ============================================================
11:50:00.0060 3820 Drive \Device\Harddisk0\DR0 - Size: 0x2E93E36000 (186.31 Gb), SectorSize: 0x200, Cylinders: 0x5F01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:50:00.0532 3820 Drive \Device\Harddisk1\DR1 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:50:00.0547 3820 Drive \Device\Harddisk2\DR2 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:50:00.0554 3820 \Device\Harddisk0\DR0:
11:50:00.0554 3820 MBR used
11:50:00.0554 3820 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1000, BlocksNum 0x1749E000
11:50:00.0554 3820 \Device\Harddisk1\DR1:
11:50:00.0554 3820 MBR used
11:50:00.0554 3820 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x1000, BlocksNum 0xAEA86000
11:50:00.0554 3820 \Device\Harddisk2\DR2:
11:50:00.0755 3820 MBR used
11:50:00.0755 3820 \Device\Harddisk2\DR2\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:50:00.0755 3820 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x253FB800
11:50:00.0936 3820 Initialize success
11:50:00.0936 3820 ============================================================
11:50:32.0846 1304 ============================================================
11:50:32.0846 1304 Scan started
11:50:32.0846 1304 Mode: Manual;
11:50:32.0846 1304 ============================================================
11:50:33.0318 1304 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
11:50:33.0320 1304 1394ohci - ok
11:50:33.0378 1304 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
11:50:33.0382 1304 ACPI - ok
11:50:33.0422 1304 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
11:50:33.0424 1304 AcpiPmi - ok
11:50:33.0507 1304 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:50:33.0513 1304 adp94xx - ok
11:50:33.0544 1304 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:50:33.0547 1304 adpahci - ok
11:50:33.0592 1304 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:50:33.0594 1304 adpu320 - ok
11:50:33.0640 1304 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
11:50:33.0646 1304 AFD - ok
11:50:33.0696 1304 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
11:50:33.0699 1304 agp440 - ok
11:50:33.0768 1304 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
11:50:33.0769 1304 aliide - ok
11:50:33.0861 1304 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
11:50:33.0864 1304 amdide - ok
11:50:33.0925 1304 amdiox64 (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\Windows\system32\DRIVERS\amdiox64.sys
11:50:33.0927 1304 amdiox64 - ok
11:50:34.0027 1304 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:50:34.0030 1304 AmdK8 - ok
11:50:34.0294 1304 amdkmdag (9e3b4946f7e1bca0b763e19d81edbf2c) C:\Windows\system32\DRIVERS\atikmdag.sys
11:50:34.0565 1304 amdkmdag - ok
11:50:34.0650 1304 amdkmdap (b9e1c7b7f1865f99b16ff2e1bb94edb6) C:\Windows\system32\DRIVERS\atikmpag.sys
11:50:34.0673 1304 amdkmdap - ok
11:50:34.0694 1304 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:50:34.0696 1304 AmdPPM - ok
11:50:34.0722 1304 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
11:50:34.0724 1304 amdsata - ok
11:50:34.0766 1304 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:50:34.0769 1304 amdsbs - ok
11:50:34.0812 1304 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
11:50:34.0812 1304 amdxata - ok
11:50:34.0895 1304 AODDriver4.01 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
11:50:34.0904 1304 AODDriver4.01 - ok
11:50:34.0956 1304 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
11:50:34.0958 1304 AppID - ok
11:50:34.0986 1304 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:50:34.0988 1304 arc - ok
11:50:35.0004 1304 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:50:35.0007 1304 arcsas - ok
11:50:35.0040 1304 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:50:35.0042 1304 AsyncMac - ok
11:50:35.0078 1304 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
11:50:35.0079 1304 atapi - ok
11:50:35.0153 1304 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
11:50:35.0155 1304 AtiHDAudioService - ok
11:50:35.0235 1304 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:50:35.0240 1304 b06bdrv - ok
11:50:35.0288 1304 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:50:35.0292 1304 b57nd60a - ok
11:50:35.0319 1304 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:50:35.0320 1304 Beep - ok
11:50:35.0373 1304 bftpdskc64 (64ad8335b0c34e667e46e8eaf1404245) C:\Windows\system32\drivers\bftpdskc64.sys
11:50:35.0374 1304 bftpdskc64 - ok
11:50:35.0410 1304 bftpusbx64 (e8583ccfeeb45bb94d4ce078f7ec8834) C:\Windows\system32\drivers\bftpusbx64.sys
11:50:35.0444 1304 bftpusbx64 - ok
11:50:35.0484 1304 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:50:35.0486 1304 blbdrive - ok
11:50:35.0517 1304 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
11:50:35.0519 1304 bowser - ok
11:50:35.0555 1304 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:50:35.0557 1304 BrFiltLo - ok
11:50:35.0573 1304 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:50:35.0575 1304 BrFiltUp - ok
11:50:35.0605 1304 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:50:35.0609 1304 Brserid - ok
11:50:35.0630 1304 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:50:35.0632 1304 BrSerWdm - ok
11:50:35.0649 1304 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:50:35.0650 1304 BrUsbMdm - ok
11:50:35.0669 1304 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:50:35.0670 1304 BrUsbSer - ok
11:50:35.0686 1304 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:50:35.0688 1304 BTHMODEM - ok
11:50:35.0733 1304 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:50:35.0734 1304 cdfs - ok
11:50:35.0772 1304 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
11:50:35.0775 1304 cdrom - ok
11:50:35.0789 1304 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:50:35.0791 1304 circlass - ok
11:50:35.0818 1304 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:50:35.0822 1304 CLFS - ok
11:50:35.0879 1304 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:50:35.0881 1304 CmBatt - ok
11:50:35.0900 1304 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
11:50:35.0902 1304 cmdide - ok
11:50:35.0953 1304 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
11:50:35.0958 1304 CNG - ok
11:50:35.0999 1304 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:50:36.0000 1304 Compbatt - ok
11:50:36.0045 1304 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
11:50:36.0047 1304 CompositeBus - ok
11:50:36.0157 1304 cpudrv64 (3ca734ce373e5675fbc15ca2c45228e5) C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys
11:50:36.0159 1304 cpudrv64 - ok
11:50:36.0221 1304 cpuz135 (c08063f052308b6f5882482615387f30) C:\Windows\system32\drivers\cpuz135_x64.sys
11:50:36.0223 1304 cpuz135 - ok
11:50:36.0269 1304 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:50:36.0271 1304 crcdisk - ok
11:50:36.0315 1304 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
11:50:36.0320 1304 CSC - ok
11:50:36.0358 1304 dc3d (7af9dac504fbd047cbc3e64ae52c92bf) C:\Windows\system32\DRIVERS\dc3d.sys
11:50:36.0360 1304 dc3d - ok
11:50:36.0406 1304 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
11:50:36.0408 1304 DfsC - ok
11:50:36.0428 1304 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:50:36.0430 1304 discache - ok
11:50:36.0457 1304 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:50:36.0459 1304 Disk - ok
11:50:36.0497 1304 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:50:36.0498 1304 drmkaud - ok
11:50:36.0559 1304 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
11:50:36.0568 1304 DXGKrnl - ok
11:50:36.0622 1304 E1G60 (edc6e9c057c9d7f83eea22b4cef5dcad) C:\Windows\system32\DRIVERS\E1G6032E.sys
11:50:36.0624 1304 E1G60 - ok
11:50:36.0688 1304 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:50:36.0732 1304 ebdrv - ok
11:50:36.0790 1304 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:50:36.0795 1304 elxstor - ok
11:50:36.0850 1304 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
11:50:36.0852 1304 ErrDev - ok
11:50:36.0903 1304 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:50:36.0905 1304 exfat - ok
11:50:36.0946 1304 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:50:36.0948 1304 fastfat - ok
11:50:36.0987 1304 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:50:36.0988 1304 fdc - ok
11:50:37.0034 1304 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:50:37.0036 1304 FileInfo - ok
11:50:37.0078 1304 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:50:37.0079 1304 Filetrace - ok
11:50:37.0096 1304 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:50:37.0098 1304 flpydisk - ok
11:50:37.0149 1304 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
11:50:37.0152 1304 FltMgr - ok
11:50:37.0206 1304 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:50:37.0208 1304 FsDepends - ok
11:50:37.0221 1304 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:50:37.0223 1304 Fs_Rec - ok
11:50:37.0262 1304 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:50:37.0264 1304 fvevol - ok
11:50:37.0308 1304 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:50:37.0310 1304 gagp30kx - ok
11:50:37.0330 1304 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:50:37.0332 1304 hcw85cir - ok
11:50:37.0385 1304 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
11:50:37.0398 1304 HdAudAddService - ok
11:50:37.0417 1304 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
11:50:37.0420 1304 HDAudBus - ok
11:50:37.0458 1304 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:50:37.0460 1304 HidBatt - ok
11:50:37.0474 1304 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:50:37.0476 1304 HidBth - ok
11:50:37.0492 1304 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:50:37.0494 1304 HidIr - ok
11:50:37.0536 1304 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
11:50:37.0539 1304 HidUsb - ok
11:50:37.0583 1304 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
11:50:37.0585 1304 HpSAMD - ok
11:50:37.0642 1304 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
11:50:37.0650 1304 HTTP - ok
11:50:37.0691 1304 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
11:50:37.0691 1304 hwpolicy - ok
11:50:37.0734 1304 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
11:50:37.0737 1304 i8042prt - ok
11:50:37.0783 1304 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
11:50:37.0788 1304 iaStorV - ok
11:50:37.0850 1304 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:50:37.0852 1304 iirsp - ok
11:50:37.0961 1304 IntcAzAudAddService (150ac23f21dbdbf8488408ba944b0d65) C:\Windows\system32\drivers\RTKVHD64.sys
11:50:38.0022 1304 IntcAzAudAddService - ok
11:50:38.0064 1304 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
11:50:38.0065 1304 intelide - ok
11:50:38.0103 1304 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:50:38.0105 1304 intelppm - ok
11:50:38.0164 1304 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:50:38.0166 1304 IpFilterDriver - ok
11:50:38.0183 1304 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
11:50:38.0184 1304 IPMIDRV - ok
11:50:38.0202 1304 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:50:38.0205 1304 IPNAT - ok
11:50:38.0223 1304 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:50:38.0225 1304 IRENUM - ok
11:50:38.0240 1304 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
11:50:38.0242 1304 isapnp - ok
11:50:38.0265 1304 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
11:50:38.0269 1304 iScsiPrt - ok
11:50:38.0306 1304 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
11:50:38.0308 1304 kbdclass - ok
11:50:38.0349 1304 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
11:50:38.0351 1304 kbdhid - ok
11:50:38.0400 1304 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
11:50:38.0402 1304 KSecDD - ok
11:50:38.0422 1304 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
11:50:38.0424 1304 KSecPkg - ok
11:50:38.0442 1304 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:50:38.0444 1304 ksthunk - ok
11:50:38.0507 1304 LHidFilt (241f2648adf090e2a10095bd6d6f5dcb) C:\Windows\system32\DRIVERS\LHidFilt.Sys
11:50:38.0509 1304 LHidFilt - ok
11:50:38.0524 1304 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:50:38.0605 1304 lltdio - ok
11:50:38.0626 1304 LMouFilt (342ed5a4b3326014438f36d22d803737) C:\Windows\system32\DRIVERS\LMouFilt.Sys
11:50:38.0628 1304 LMouFilt - ok
11:50:38.0668 1304 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:50:38.0670 1304 LSI_FC - ok
11:50:38.0691 1304 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:50:38.0694 1304 LSI_SAS - ok
11:50:38.0714 1304 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:50:38.0716 1304 LSI_SAS2 - ok
11:50:38.0732 1304 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:50:38.0734 1304 LSI_SCSI - ok
11:50:38.0782 1304 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:50:38.0784 1304 luafv - ok
11:50:38.0822 1304 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:50:38.0823 1304 megasas - ok
11:50:38.0867 1304 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:50:38.0871 1304 MegaSR - ok
11:50:38.0961 1304 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:50:38.0963 1304 Modem - ok
11:50:39.0009 1304 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:50:39.0011 1304 monitor - ok
11:50:39.0046 1304 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:50:39.0048 1304 mouclass - ok
11:50:39.0067 1304 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:50:39.0070 1304 mouhid - ok
11:50:39.0107 1304 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
11:50:39.0109 1304 mountmgr - ok
11:50:39.0153 1304 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys
11:50:39.0155 1304 MpFilter - ok
11:50:39.0198 1304 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
11:50:39.0200 1304 mpio - ok
11:50:39.0259 1304 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys
11:50:39.0260 1304 MpNWMon - ok
11:50:39.0285 1304 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:50:39.0287 1304 mpsdrv - ok
11:50:39.0348 1304 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
11:50:39.0350 1304 MRxDAV - ok
11:50:39.0410 1304 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:50:39.0412 1304 mrxsmb - ok
11:50:39.0449 1304 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:50:39.0452 1304 mrxsmb10 - ok
11:50:39.0485 1304 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:50:39.0486 1304 mrxsmb20 - ok
11:50:39.0537 1304 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
11:50:39.0539 1304 msahci - ok
11:50:39.0576 1304 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
11:50:39.0578 1304 msdsm - ok
11:50:39.0623 1304 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:50:39.0624 1304 Msfs - ok
11:50:39.0663 1304 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:50:39.0664 1304 mshidkmdf - ok
11:50:39.0704 1304 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
11:50:39.0705 1304 msisadrv - ok
11:50:39.0748 1304 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:50:39.0750 1304 MSKSSRV - ok
11:50:39.0773 1304 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:50:39.0774 1304 MSPCLOCK - ok
11:50:39.0816 1304 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:50:39.0819 1304 MSPQM - ok
11:50:39.0852 1304 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
11:50:39.0856 1304 MsRPC - ok
11:50:39.0879 1304 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
11:50:39.0881 1304 mssmbios - ok
11:50:39.0924 1304 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:50:39.0926 1304 MSTEE - ok
11:50:39.0940 1304 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:50:39.0941 1304 MTConfig - ok
11:50:39.0983 1304 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:50:39.0984 1304 Mup - ok
11:50:40.0047 1304 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:50:40.0051 1304 NativeWifiP - ok
11:50:40.0117 1304 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
11:50:40.0127 1304 NDIS - ok
11:50:40.0163 1304 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:50:40.0165 1304 NdisCap - ok
11:50:40.0198 1304 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:50:40.0200 1304 NdisTapi - ok
11:50:40.0253 1304 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
11:50:40.0255 1304 Ndisuio - ok
11:50:40.0306 1304 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
11:50:40.0309 1304 NdisWan - ok
11:50:40.0342 1304 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
11:50:40.0344 1304 NDProxy - ok
11:50:40.0358 1304 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:50:40.0359 1304 NetBIOS - ok
11:50:40.0394 1304 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
11:50:40.0397 1304 NetBT - ok
11:50:40.0426 1304 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:50:40.0428 1304 nfrd960 - ok
11:50:40.0456 1304 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:50:40.0458 1304 NisDrv - ok
11:50:40.0479 1304 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:50:40.0479 1304 Npfs - ok
11:50:40.0506 1304 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:50:40.0507 1304 nsiproxy - ok
11:50:40.0598 1304 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
11:50:40.0624 1304 Ntfs - ok
11:50:40.0648 1304 NuidFltr (317020d31f1696334679b9d0416eb62e) C:\Windows\system32\DRIVERS\NuidFltr.sys
11:50:40.0651 1304 NuidFltr - ok
11:50:40.0668 1304 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:50:40.0670 1304 Null - ok
11:50:40.0703 1304 NVENETFD (a85b4f2ef3a7304a5399ef0526423040) C:\Windows\system32\DRIVERS\nvm62x64.sys
11:50:40.0707 1304 NVENETFD - ok
11:50:40.0762 1304 NVNET (0ad267a4674805b61a5d7b911d2a978a) C:\Windows\system32\DRIVERS\nvmf6264.sys
11:50:40.0766 1304 NVNET - ok
11:50:40.0819 1304 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
11:50:40.0822 1304 nvraid - ok
11:50:40.0845 1304 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
11:50:40.0847 1304 nvstor - ok
11:50:40.0887 1304 nvstor64 (b253bb1adeb4004fdb1b640750eb2b4e) C:\Windows\system32\DRIVERS\nvstor64.sys
11:50:40.0889 1304 nvstor64 - ok
11:50:40.0949 1304 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
11:50:40.0951 1304 nv_agp - ok
11:50:40.0991 1304 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
11:50:40.0993 1304 ohci1394 - ok
11:50:41.0044 1304 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:50:41.0046 1304 Parport - ok
11:50:41.0082 1304 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
11:50:41.0083 1304 partmgr - ok
11:50:41.0106 1304 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
11:50:41.0109 1304 pci - ok
11:50:41.0147 1304 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
11:50:41.0148 1304 pciide - ok
11:50:41.0190 1304 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:50:41.0193 1304 pcmcia - ok
11:50:41.0231 1304 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:50:41.0231 1304 pcw - ok
11:50:41.0263 1304 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:50:41.0270 1304 PEAUTH - ok
11:50:41.0326 1304 Point64 (4f0878fd62d5f7444c5f1c4c66d9d293) C:\Windows\system32\DRIVERS\point64.sys
11:50:41.0328 1304 Point64 - ok
11:50:41.0378 1304 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
11:50:41.0380 1304 PptpMiniport - ok
11:50:41.0401 1304 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:50:41.0403 1304 Processor - ok
11:50:41.0446 1304 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
11:50:41.0449 1304 Psched - ok
11:50:41.0512 1304 PSI (fb46e9a827a8799ebd7bfa9128c91f37) C:\Windows\system32\DRIVERS\psi_mf.sys
11:50:41.0520 1304 PSI - ok
11:50:41.0554 1304 PSSDK42 (cd33cb6fecf65520466f95ab89cc4af5) C:\Windows\system32\Drivers\pssdk42.sys
11:50:41.0592 1304 PSSDK42 - ok
11:50:41.0686 1304 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:50:41.0720 1304 ql2300 - ok
11:50:41.0740 1304 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:50:41.0742 1304 ql40xx - ok
11:50:41.0767 1304 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:50:41.0769 1304 QWAVEdrv - ok
11:50:41.0790 1304 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:50:41.0791 1304 RasAcd - ok
11:50:41.0836 1304 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:50:41.0838 1304 RasAgileVpn - ok
11:50:41.0879 1304 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:50:41.0881 1304 Rasl2tp - ok
11:50:41.0900 1304 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:50:41.0902 1304 RasPppoe - ok
11:50:41.0919 1304 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:50:41.0921 1304 RasSstp - ok
11:50:41.0964 1304 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
11:50:41.0967 1304 rdbss - ok
11:50:41.0990 1304 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:50:41.0991 1304 rdpbus - ok
11:50:42.0010 1304 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:50:42.0012 1304 RDPCDD - ok
11:50:42.0049 1304 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
11:50:42.0052 1304 RDPDR - ok
11:50:42.0064 1304 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:50:42.0064 1304 RDPENCDD - ok
11:50:42.0112 1304 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:50:42.0114 1304 RDPREFMP - ok
11:50:42.0180 1304 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
11:50:42.0182 1304 RdpVideoMiniport - ok
11:50:42.0233 1304 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
11:50:42.0236 1304 RDPWD - ok
11:50:42.0274 1304 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
11:50:42.0276 1304 rdyboost - ok
11:50:42.0331 1304 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys
11:50:42.0339 1304 Revoflt - ok
11:50:42.0374 1304 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:50:42.0376 1304 rspndr - ok
11:50:42.0426 1304 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
11:50:42.0427 1304 s3cap - ok
11:50:42.0526 1304 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
11:50:42.0527 1304 SASDIFSV - ok
11:50:42.0636 1304 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
11:50:42.0637 1304 SASKUTIL - ok
11:50:42.0679 1304 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
11:50:42.0681 1304 sbp2port - ok
11:50:42.0752 1304 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
11:50:42.0754 1304 scfilter - ok
11:50:42.0809 1304 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:50:42.0811 1304 secdrv - ok
11:50:42.0872 1304 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:50:42.0874 1304 Serenum - ok
11:50:42.0895 1304 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:50:42.0898 1304 Serial - ok
11:50:42.0967 1304 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:50:42.0969 1304 sermouse - ok
11:50:43.0044 1304 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
11:50:43.0061 1304 sffdisk - ok
11:50:43.0072 1304 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
11:50:43.0074 1304 sffp_mmc - ok
11:50:43.0093 1304 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
11:50:43.0094 1304 sffp_sd - ok
11:50:43.0119 1304 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:50:43.0121 1304 sfloppy - ok
11:50:43.0189 1304 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:50:43.0191 1304 SiSRaid2 - ok
11:50:43.0206 1304 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:50:43.0208 1304 SiSRaid4 - ok
11:50:43.0229 1304 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:50:43.0231 1304 Smb - ok
11:50:43.0277 1304 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:50:43.0278 1304 spldr - ok
11:50:43.0316 1304 sptd (a6cff1af7664627a296b6a0a96cf876e) C:\Windows\System32\Drivers\sptd.sys
11:50:43.0316 1304 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: a6cff1af7664627a296b6a0a96cf876e
11:50:43.0317 1304 sptd ( LockedFile.Multi.Generic ) - warning
11:50:43.0317 1304 sptd - detected LockedFile.Multi.Generic (1)
11:50:43.0363 1304 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
11:50:43.0368 1304 srv - ok
11:50:43.0407 1304 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
11:50:43.0412 1304 srv2 - ok
11:50:43.0451 1304 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
11:50:43.0453 1304 srvnet - ok
11:50:43.0497 1304 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:50:43.0498 1304 stexstor - ok
11:50:43.0558 1304 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
11:50:43.0559 1304 storflt - ok
11:50:43.0598 1304 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
11:50:43.0600 1304 storvsc - ok
11:50:43.0644 1304 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
11:50:43.0646 1304 swenum - ok
11:50:43.0701 1304 sxuptp (11c9c422583eaeadd807c3fbcfc7496c) C:\Windows\system32\DRIVERS\sxuptp.sys
11:50:43.0714 1304 sxuptp - ok
11:50:43.0732 1304 Synth3dVsc - ok
11:50:43.0808 1304 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
11:50:43.0842 1304 Tcpip - ok
11:50:43.0883 1304 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
11:50:43.0891 1304 TCPIP6 - ok
11:50:43.0928 1304 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
11:50:43.0930 1304 tcpipreg - ok
11:50:43.0974 1304 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:50:43.0975 1304 TDPIPE - ok
11:50:44.0014 1304 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:50:44.0016 1304 TDTCP - ok
11:50:44.0055 1304 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
11:50:44.0057 1304 tdx - ok
11:50:44.0065 1304 TEAM - ok
11:50:44.0100 1304 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
11:50:44.0102 1304 TermDD - ok
11:50:44.0152 1304 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:50:44.0154 1304 tssecsrv - ok
11:50:44.0206 1304 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
11:50:44.0208 1304 TsUsbFlt - ok
11:50:44.0217 1304 tsusbhub - ok
11:50:44.0267 1304 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
11:50:44.0270 1304 tunnel - ok
11:50:44.0310 1304 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:50:44.0312 1304 uagp35 - ok
11:50:44.0365 1304 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
11:50:44.0369 1304 udfs - ok
11:50:44.0421 1304 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
11:50:44.0423 1304 uliagpkx - ok
11:50:44.0468 1304 Ultra (1536b8a53df917e5a3f3b0207df06fda) C:\Windows\system32\DRIVERS\Ultra.sys
11:50:44.0469 1304 Ultra - ok
11:50:44.0485 1304 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
11:50:44.0487 1304 umbus - ok
11:50:44.0526 1304 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:50:44.0530 1304 UmPass - ok
11:50:44.0622 1304 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
11:50:44.0625 1304 usbaudio - ok
11:50:44.0659 1304 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
11:50:44.0662 1304 usbccgp - ok
11:50:44.0700 1304 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
11:50:44.0702 1304 usbcir - ok
11:50:44.0749 1304 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
11:50:44.0751 1304 usbehci - ok
11:50:44.0779 1304 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
11:50:44.0783 1304 usbhub - ok
11:50:44.0808 1304 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
11:50:44.0810 1304 usbohci - ok
11:50:44.0860 1304 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:50:44.0862 1304 usbprint - ok
11:50:44.0932 1304 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
11:50:44.0933 1304 usbscan - ok
11:50:44.0980 1304 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:50:44.0983 1304 USBSTOR - ok
11:50:45.0030 1304 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
11:50:45.0032 1304 usbuhci - ok
11:50:45.0072 1304 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
11:50:45.0073 1304 vdrvroot - ok
11:50:45.0117 1304 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:50:45.0120 1304 vga - ok
11:50:45.0154 1304 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:50:45.0156 1304 VgaSave - ok
11:50:45.0164 1304 VGPU - ok
11:50:45.0211 1304 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
11:50:45.0214 1304 vhdmp - ok
11:50:45.0280 1304 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
11:50:45.0282 1304 viaide - ok
11:50:45.0319 1304 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
11:50:45.0321 1304 vmbus - ok
11:50:45.0364 1304 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
11:50:45.0365 1304 VMBusHID - ok
11:50:45.0405 1304 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
11:50:45.0406 1304 volmgr - ok
11:50:45.0444 1304 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
11:50:45.0447 1304 volmgrx - ok
11:50:45.0470 1304 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
11:50:45.0474 1304 volsnap - ok
11:50:45.0505 1304 vpcbus (b4a73ca4ef9a02b9738cea9ad5fe5917) C:\Windows\system32\DRIVERS\vpchbus.sys
11:50:45.0508 1304 vpcbus - ok
11:50:45.0541 1304 vpcnfltr (e675fb2b48c54f09895482e2253b289c) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:50:45.0543 1304 vpcnfltr - ok
11:50:45.0558 1304 vpcusb (5fb42082b0d19a0268705f1dd343df20) C:\Windows\system32\DRIVERS\vpcusb.sys
11:50:45.0560 1304 vpcusb - ok
11:50:45.0598 1304 vpcvmm (207b6539799cc1c112661a9b620dd233) C:\Windows\system32\drivers\vpcvmm.sys
11:50:45.0602 1304 vpcvmm - ok
11:50:45.0651 1304 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:50:45.0654 1304 vsmraid - ok
11:50:45.0674 1304 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:50:45.0675 1304 vwifibus - ok
11:50:45.0700 1304 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:50:45.0702 1304 WacomPen - ok
11:50:45.0757 1304 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
11:50:45.0759 1304 WANARP - ok
11:50:45.0764 1304 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
11:50:45.0765 1304 Wanarpv6 - ok
11:50:45.0795 1304 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:50:45.0797 1304 Wd - ok
11:50:45.0822 1304 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:50:45.0828 1304 Wdf01000 - ok
11:50:45.0859 1304 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:50:45.0861 1304 WfpLwf - ok
11:50:45.0901 1304 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:50:45.0902 1304 WIMMount - ok
11:50:46.0006 1304 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
11:50:46.0008 1304 WinUsb - ok
11:50:46.0077 1304 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
11:50:46.0079 1304 WmiAcpi - ok
11:50:46.0102 1304 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:50:46.0105 1304 ws2ifsl - ok
11:50:46.0170 1304 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
11:50:46.0173 1304 WudfPf - ok
11:50:46.0217 1304 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:50:46.0219 1304 WUDFRd - ok
11:50:46.0276 1304 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
11:50:46.0449 1304 \Device\Harddisk0\DR0 - ok
11:50:46.0453 1304 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
11:50:46.0484 1304 \Device\Harddisk1\DR1 - ok
11:50:46.0491 1304 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
11:50:46.0556 1304 \Device\Harddisk2\DR2 - ok
11:50:46.0560 1304 Boot (0x1200) (1664e8b7d6bf1d92287b9166174c961e) \Device\Harddisk0\DR0\Partition0
11:50:46.0562 1304 \Device\Harddisk0\DR0\Partition0 - ok
11:50:46.0586 1304 Boot (0x1200) (e6d4378ed8015e8a5e9a57f171e25b35) \Device\Harddisk1\DR1\Partition0
11:50:46.0587 1304 \Device\Harddisk1\DR1\Partition0 - ok
11:50:46.0614 1304 Boot (0x1200) (b294162502cd86c25a830a0cd97a10d9) \Device\Harddisk2\DR2\Partition0
11:50:46.0615 1304 \Device\Harddisk2\DR2\Partition0 - ok
11:50:46.0628 1304 Boot (0x1200) (18ad71ad5b6a7bbc20abccba8c122408) \Device\Harddisk2\DR2\Partition1
11:50:46.0630 1304 \Device\Harddisk2\DR2\Partition1 - ok
11:50:46.0631 1304 ============================================================
11:50:46.0631 1304 Scan finished
11:50:46.0631 1304 ============================================================
11:50:46.0647 4240 Detected object count: 1
11:50:46.0647 4240 Actual detected object count: 1
11:52:13.0850 4240 sptd ( LockedFile.Multi.Generic ) - skipped by user
11:52:13.0850 4240 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
11:52:54.0646 5012 ============================================================
11:52:54.0646 5012 Scan started
11:52:54.0646 5012 Mode: Manual;
11:52:54.0646 5012 ============================================================
11:52:55.0021 5012 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
11:52:55.0022 5012 1394ohci - ok
11:52:55.0081 5012 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
11:52:55.0083 5012 ACPI - ok
11:52:55.0117 5012 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
11:52:55.0118 5012 AcpiPmi - ok
11:52:55.0202 5012 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
11:52:55.0204 5012 adp94xx - ok
11:52:55.0239 5012 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
11:52:55.0240 5012 adpahci - ok
11:52:55.0278 5012 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
11:52:55.0279 5012 adpu320 - ok
11:52:55.0327 5012 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
11:52:55.0329 5012 AFD - ok
11:52:55.0374 5012 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
11:52:55.0375 5012 agp440 - ok
11:52:55.0446 5012 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
11:52:55.0446 5012 aliide - ok
11:52:55.0464 5012 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
11:52:55.0464 5012 amdide - ok
11:52:55.0520 5012 amdiox64 (6a2eeb0c4133b20773bb3dd0b7b377b4) C:\Windows\system32\DRIVERS\amdiox64.sys
11:52:55.0521 5012 amdiox64 - ok
11:52:55.0546 5012 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
11:52:55.0547 5012 AmdK8 - ok
11:52:55.0805 5012 amdkmdag (9e3b4946f7e1bca0b763e19d81edbf2c) C:\Windows\system32\DRIVERS\atikmdag.sys
11:52:55.0854 5012 amdkmdag - ok
11:52:55.0920 5012 amdkmdap (b9e1c7b7f1865f99b16ff2e1bb94edb6) C:\Windows\system32\DRIVERS\atikmpag.sys
11:52:55.0921 5012 amdkmdap - ok
11:52:55.0939 5012 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
11:52:55.0939 5012 AmdPPM - ok
11:52:55.0967 5012 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
11:52:55.0967 5012 amdsata - ok
11:52:56.0011 5012 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
11:52:56.0012 5012 amdsbs - ok
11:52:56.0057 5012 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
11:52:56.0057 5012 amdxata - ok
11:52:56.0140 5012 AODDriver4.01 (f312fad7dbd49ed21a194ac71b497832) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
11:52:56.0142 5012 AODDriver4.01 - ok
11:52:56.0193 5012 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
11:52:56.0193 5012 AppID - ok
11:52:56.0222 5012 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
11:52:56.0223 5012 arc - ok
11:52:56.0241 5012 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
11:52:56.0242 5012 arcsas - ok
11:52:56.0293 5012 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
11:52:56.0294 5012 AsyncMac - ok
11:52:56.0331 5012 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
11:52:56.0332 5012 atapi - ok
11:52:56.0389 5012 AtiHDAudioService (4bf5bca6e2608cd8a00bc4a6673a9f47) C:\Windows\system32\drivers\AtihdW76.sys
11:52:56.0390 5012 AtiHDAudioService - ok
11:52:56.0430 5012 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
11:52:56.0432 5012 b06bdrv - ok
11:52:56.0475 5012 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
11:52:56.0476 5012 b57nd60a - ok
11:52:56.0497 5012 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
11:52:56.0497 5012 Beep - ok
11:52:56.0543 5012 bftpdskc64 (64ad8335b0c34e667e46e8eaf1404245) C:\Windows\system32\drivers\bftpdskc64.sys
11:52:56.0543 5012 bftpdskc64 - ok
11:52:56.0580 5012 bftpusbx64 (e8583ccfeeb45bb94d4ce078f7ec8834) C:\Windows\system32\drivers\bftpusbx64.sys
11:52:56.0582 5012 bftpusbx64 - ok
11:52:56.0604 5012 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
11:52:56.0605 5012 blbdrive - ok
11:52:56.0637 5012 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
11:52:56.0638 5012 bowser - ok
11:52:56.0675 5012 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:52:56.0676 5012 BrFiltLo - ok
11:52:56.0743 5012 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:52:56.0744 5012 BrFiltUp - ok
11:52:56.0775 5012 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
11:52:56.0777 5012 Brserid - ok
11:52:56.0800 5012 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
11:52:56.0800 5012 BrSerWdm - ok
11:52:56.0819 5012 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
11:52:56.0819 5012 BrUsbMdm - ok
11:52:56.0839 5012 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
11:52:56.0839 5012 BrUsbSer - ok
11:52:56.0856 5012 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
11:52:56.0857 5012 BTHMODEM - ok
11:52:56.0902 5012 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
11:52:56.0903 5012 cdfs - ok
11:52:56.0942 5012 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
11:52:56.0943 5012 cdrom - ok
11:52:56.0957 5012 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
11:52:56.0958 5012 circlass - ok
11:52:56.0988 5012 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
11:52:56.0990 5012 CLFS - ok
11:52:57.0041 5012 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
11:52:57.0041 5012 CmBatt - ok
11:52:57.0112 5012 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
11:52:57.0112 5012 cmdide - ok
11:52:57.0165 5012 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
11:52:57.0167 5012 CNG - ok
11:52:57.0219 5012 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
11:52:57.0219 5012 Compbatt - ok
11:52:57.0257 5012 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
11:52:57.0257 5012 CompositeBus - ok
11:52:57.0344 5012 cpudrv64 (3ca734ce373e5675fbc15ca2c45228e5) C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys
11:52:57.0344 5012 cpudrv64 - ok
11:52:57.0391 5012 cpuz135 (c08063f052308b6f5882482615387f30) C:\Windows\system32\drivers\cpuz135_x64.sys
11:52:57.0392 5012 cpuz135 - ok
11:52:57.0430 5012 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
11:52:57.0431 5012 crcdisk - ok
11:52:57.0477 5012 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
11:52:57.0479 5012 CSC - ok
11:52:57.0520 5012 dc3d (7af9dac504fbd047cbc3e64ae52c92bf) C:\Windows\system32\DRIVERS\dc3d.sys
11:52:57.0520 5012 dc3d - ok
11:52:57.0576 5012 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
11:52:57.0576 5012 DfsC - ok
11:52:57.0598 5012 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
11:52:57.0599 5012 discache - ok
11:52:57.0619 5012 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
11:52:57.0620 5012 Disk - ok
11:52:57.0650 5012 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
11:52:57.0651 5012 drmkaud - ok
11:52:57.0704 5012 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
11:52:57.0708 5012 DXGKrnl - ok
11:52:57.0751 5012 E1G60 (edc6e9c057c9d7f83eea22b4cef5dcad) C:\Windows\system32\DRIVERS\E1G6032E.sys
11:52:57.0752 5012 E1G60 - ok
11:52:57.0816 5012 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
11:52:57.0831 5012 ebdrv - ok
11:52:57.0885 5012 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
11:52:57.0887 5012 elxstor - ok
11:52:57.0937 5012 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
11:52:57.0937 5012 ErrDev - ok
11:52:57.0989 5012 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
11:52:57.0990 5012 exfat - ok
11:52:58.0041 5012 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
11:52:58.0042 5012 fastfat - ok
11:52:58.0082 5012 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
11:52:58.0082 5012 fdc - ok
11:52:58.0129 5012 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
11:52:58.0130 5012 FileInfo - ok
11:52:58.0173 5012 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
11:52:58.0173 5012 Filetrace - ok
11:52:58.0199 5012 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
11:52:58.0200 5012 flpydisk - ok
11:52:58.0253 5012 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
11:52:58.0254 5012 FltMgr - ok
11:52:58.0301 5012 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
11:52:58.0302 5012 FsDepends - ok
11:52:58.0316 5012 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
11:52:58.0316 5012 Fs_Rec - ok
11:52:58.0357 5012 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
11:52:58.0358 5012 fvevol - ok
11:52:58.0394 5012 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
11:52:58.0395 5012 gagp30kx - ok
11:52:58.0417 5012 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
11:52:58.0417 5012 hcw85cir - ok
11:52:58.0480 5012 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
11:52:58.0481 5012 HdAudAddService - ok
11:52:58.0504 5012 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
11:52:58.0505 5012 HDAudBus - ok
11:52:58.0553 5012 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
11:52:58.0554 5012 HidBatt - ok
11:52:58.0569 5012 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
11:52:58.0570 5012 HidBth - ok
11:52:58.0587 5012 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
11:52:58.0588 5012 HidIr - ok
11:52:58.0631 5012 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
11:52:58.0631 5012 HidUsb - ok
11:52:58.0678 5012 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
11:52:58.0678 5012 HpSAMD - ok
11:52:58.0729 5012 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
11:52:58.0733 5012 HTTP - ok
11:52:58.0769 5012 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
11:52:58.0770 5012 hwpolicy - ok
11:52:58.0813 5012 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
11:52:58.0813 5012 i8042prt - ok
11:52:58.0862 5012 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
11:52:58.0864 5012 iaStorV - ok
11:52:58.0929 5012 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
11:52:58.0929 5012 iirsp - ok
11:52:59.0039 5012 IntcAzAudAddService (150ac23f21dbdbf8488408ba944b0d65) C:\Windows\system32\drivers\RTKVHD64.sys
11:52:59.0060 5012 IntcAzAudAddService - ok
11:52:59.0100 5012 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
11:52:59.0101 5012 intelide - ok
11:52:59.0140 5012 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
11:52:59.0141 5012 intelppm - ok
11:52:59.0192 5012 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:52:59.0193 5012 IpFilterDriver - ok
11:52:59.0211 5012 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
11:52:59.0212 5012 IPMIDRV - ok
11:52:59.0231 5012 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
11:52:59.0231 5012 IPNAT - ok
11:52:59.0251 5012 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
11:52:59.0252 5012 IRENUM - ok
11:52:59.0277 5012 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
11:52:59.0277 5012 isapnp - ok
11:52:59.0377 5012 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
11:52:59.0378 5012 iScsiPrt - ok
11:52:59.0418 5012 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
11:52:59.0418 5012 kbdclass - ok
11:52:59.0461 5012 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
11:52:59.0461 5012 kbdhid - ok
11:52:59.0520 5012 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
11:52:59.0521 5012 KSecDD - ok
11:52:59.0559 5012 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
11:52:59.0560 5012 KSecPkg - ok
11:52:59.0587 5012 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
11:52:59.0588 5012 ksthunk - ok
11:52:59.0652 5012 LHidFilt (241f2648adf090e2a10095bd6d6f5dcb) C:\Windows\system32\DRIVERS\LHidFilt.Sys
11:52:59.0652 5012 LHidFilt - ok
11:52:59.0693 5012 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
11:52:59.0693 5012 lltdio - ok
11:52:59.0721 5012 LMouFilt (342ed5a4b3326014438f36d22d803737) C:\Windows\system32\DRIVERS\LMouFilt.Sys
11:52:59.0722 5012 LMouFilt - ok
11:52:59.0763 5012 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
11:52:59.0763 5012 LSI_FC - ok
11:52:59.0778 5012 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
11:52:59.0778 5012 LSI_SAS - ok
11:52:59.0800 5012 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:52:59.0801 5012 LSI_SAS2 - ok
11:52:59.0814 5012 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:52:59.0814 5012 LSI_SCSI - ok
11:52:59.0852 5012 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
11:52:59.0853 5012 luafv - ok
11:52:59.0892 5012 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
11:52:59.0892 5012 megasas - ok
11:52:59.0937 5012 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
11:52:59.0939 5012 MegaSR - ok
11:52:59.0981 5012 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
11:52:59.0982 5012 Modem - ok
11:53:00.0037 5012 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
11:53:00.0038 5012 monitor - ok
11:53:00.0074 5012 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
11:53:00.0075 5012 mouclass - ok
11:53:00.0096 5012 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
11:53:00.0096 5012 mouhid - ok
11:53:00.0136 5012 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
11:53:00.0136 5012 mountmgr - ok
11:53:00.0181 5012 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys
11:53:00.0183 5012 MpFilter - ok
11:53:00.0235 5012 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
11:53:00.0236 5012 mpio - ok
11:53:00.0296 5012 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys
11:53:00.0296 5012 MpNWMon - ok
11:53:00.0321 5012 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
11:53:00.0322 5012 mpsdrv - ok
11:53:00.0376 5012 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
11:53:00.0377 5012 MRxDAV - ok
11:53:00.0439 5012 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
11:53:00.0440 5012 mrxsmb - ok
11:53:00.0494 5012 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:53:00.0496 5012 mrxsmb10 - ok
11:53:00.0555 5012 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:53:00.0556 5012 mrxsmb20 - ok
11:53:00.0607 5012 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
11:53:00.0607 5012 msahci - ok
11:53:00.0663 5012 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
11:53:00.0664 5012 msdsm - ok
11:53:00.0702 5012 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
11:53:00.0702 5012 Msfs - ok
11:53:00.0741 5012 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
11:53:00.0742 5012 mshidkmdf - ok
11:53:00.0783 5012 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
11:53:00.0783 5012 msisadrv - ok
11:53:00.0826 5012 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
11:53:00.0827 5012 MSKSSRV - ok
11:53:00.0843 5012 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
11:53:00.0843 5012 MSPCLOCK - ok
11:53:00.0877 5012 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
11:53:00.0878 5012 MSPQM - ok
11:53:00.0914 5012 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
11:53:00.0916 5012 MsRPC - ok
11:53:00.0958 5012 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
11:53:00.0958 5012 mssmbios - ok
11:53:01.0002 5012 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
11:53:01.0003 5012 MSTEE - ok
11:53:01.0018 5012 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
11:53:01.0019 5012 MTConfig - ok
11:53:01.0062 5012 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
11:53:01.0062 5012 Mup - ok
11:53:01.0117 5012 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
11:53:01.0119 5012 NativeWifiP - ok
11:53:01.0187 5012 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
11:53:01.0192 5012 NDIS - ok
11:53:01.0233 5012 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
11:53:01.0233 5012 NdisCap - ok
11:53:01.0276 5012 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
11:53:01.0277 5012 NdisTapi - ok
11:53:01.0331 5012 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
11:53:01.0332 5012 Ndisuio - ok
11:53:01.0385 5012 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
11:53:01.0385 5012 NdisWan - ok
11:53:01.0420 5012 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
11:53:01.0421 5012 NDProxy - ok
11:53:01.0445 5012 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
11:53:01.0446 5012 NetBIOS - ok
11:53:01.0481 5012 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
11:53:01.0482 5012 NetBT - ok
11:53:01.0513 5012 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
11:53:01.0514 5012 nfrd960 - ok
11:53:01.0542 5012 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:53:01.0543 5012 NisDrv - ok
11:53:01.0566 5012 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
11:53:01.0566 5012 Npfs - ok
11:53:01.0592 5012 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
11:53:01.0593 5012 nsiproxy - ok
11:53:01.0660 5012 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
11:53:01.0667 5012 Ntfs - ok
11:53:01.0693 5012 NuidFltr (317020d31f1696334679b9d0416eb62e) C:\Windows\system32\DRIVERS\NuidFltr.sys
11:53:01.0693 5012 NuidFltr - ok
11:53:01.0714 5012 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
11:53:01.0714 5012 Null - ok
11:53:01.0748 5012 NVENETFD (a85b4f2ef3a7304a5399ef0526423040) C:\Windows\system32\DRIVERS\nvm62x64.sys
11:53:01.0750 5012 NVENETFD - ok
11:53:01.0807 5012 NVNET (0ad267a4674805b61a5d7b911d2a978a) C:\Windows\system32\DRIVERS\nvmf6264.sys
11:53:01.0809 5012 NVNET - ok
11:53:01.0856 5012 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
11:53:01.0857 5012 nvraid - ok
11:53:01.0881 5012 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
11:53:01.0882 5012 nvstor - ok
11:53:01.0916 5012 nvstor64 (b253bb1adeb4004fdb1b640750eb2b4e) C:\Windows\system32\DRIVERS\nvstor64.sys
11:53:01.0917 5012 nvstor64 - ok
11:53:01.0977 5012 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
11:53:01.0978 5012 nv_agp - ok
11:53:02.0027 5012 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
11:53:02.0028 5012 ohci1394 - ok
11:53:02.0072 5012 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
11:53:02.0073 5012 Parport - ok
11:53:02.0110 5012 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
11:53:02.0111 5012 partmgr - ok
11:53:02.0168 5012 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
11:53:02.0169 5012 pci - ok
11:53:02.0209 5012 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
11:53:02.0209 5012 pciide - ok
11:53:02.0252 5012 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
11:53:02.0253 5012 pcmcia - ok
11:53:02.0293 5012 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
11:53:02.0293 5012 pcw - ok
11:53:02.0325 5012 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
11:53:02.0328 5012 PEAUTH - ok
11:53:02.0388 5012 Point64 (4f0878fd62d5f7444c5f1c4c66d9d293) C:\Windows\system32\DRIVERS\point64.sys
11:53:02.0388 5012 Point64 - ok
11:53:02.0431 5012 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
11:53:02.0432 5012 PptpMiniport - ok
11:53:02.0446 5012 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
11:53:02.0446 5012 Processor - ok
11:53:02.0491 5012 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
11:53:02.0492 5012 Psched - ok
11:53:02.0532 5012 PSI (fb46e9a827a8799ebd7bfa9128c91f37) C:\Windows\system32\DRIVERS\psi_mf.sys
11:53:02.0534 5012 PSI - ok
11:53:02.0674 5012 PSSDK42 (cd33cb6fecf65520466f95ab89cc4af5) C:\Windows\system32\Drivers\pssdk42.sys
11:53:02.0677 5012 PSSDK42 - ok
11:53:02.0748 5012 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
11:53:02.0754 5012 ql2300 - ok
11:53:02.0785 5012 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
11:53:02.0786 5012 ql40xx - ok
11:53:02.0812 5012 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
11:53:02.0813 5012 QWAVEdrv - ok
11:53:02.0835 5012 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
11:53:02.0835 5012 RasAcd - ok
11:53:02.0881 5012 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
11:53:02.0881 5012 RasAgileVpn - ok
11:53:02.0924 5012 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
11:53:02.0925 5012 Rasl2tp - ok
11:53:02.0945 5012 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
11:53:02.0946 5012 RasPppoe - ok
11:53:02.0956 5012 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
11:53:02.0957 5012 RasSstp - ok
11:53:03.0000 5012 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
11:53:03.0002 5012 rdbss - ok
11:53:03.0027 5012 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
11:53:03.0028 5012 rdpbus - ok
11:53:03.0047 5012 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
11:53:03.0047 5012 RDPCDD - ok
11:53:03.0095 5012 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
11:53:03.0095 5012 RDPDR - ok
11:53:03.0106 5012 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
11:53:03.0106 5012 RDPENCDD - ok
11:53:03.0121 5012 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
11:53:03.0122 5012 RDPREFMP - ok
11:53:03.0175 5012 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
11:53:03.0176 5012 RdpVideoMiniport - ok
11:53:03.0228 5012 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
11:53:03.0229 5012 RDPWD - ok
11:53:03.0252 5012 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
11:53:03.0253 5012 rdyboost - ok
11:53:03.0292 5012 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys
11:53:03.0294 5012 Revoflt - ok
11:53:03.0327 5012 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
11:53:03.0328 5012 rspndr - ok
11:53:03.0379 5012 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
11:53:03.0380 5012 s3cap - ok
11:53:03.0462 5012 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
11:53:03.0463 5012 SASDIFSV - ok
11:53:03.0481 5012 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
11:53:03.0481 5012 SASKUTIL - ok
11:53:03.0524 5012 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
11:53:03.0525 5012 sbp2port - ok
11:53:03.0597 5012 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
11:53:03.0597 5012 scfilter - ok
11:53:03.0654 5012 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
11:53:03.0655 5012 secdrv - ok
11:53:03.0709 5012 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
11:53:03.0710 5012 Serenum - ok
11:53:03.0732 5012 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
11:53:03.0733 5012 Serial - ok
11:53:03.0796 5012 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
11:53:03.0796 5012 sermouse - ok
11:53:03.0873 5012 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
11:53:03.0873 5012 sffdisk - ok
11:53:03.0884 5012 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
11:53:03.0885 5012 sffp_mmc - ok
11:53:03.0904 5012 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
11:53:03.0905 5012 sffp_sd - ok
11:53:03.0923 5012 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
11:53:03.0923 5012 sfloppy - ok
11:53:03.0951 5012 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:53:03.0951 5012 SiSRaid2 - ok
11:53:03.0976 5012 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
11:53:03.0976 5012 SiSRaid4 - ok
11:53:03.0999 5012 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
11:53:04.0000 5012 Smb - ok
11:53:04.0047 5012 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
11:53:04.0048 5012 spldr - ok
11:53:04.0086 5012 sptd (a6cff1af7664627a296b6a0a96cf876e) C:\Windows\System32\Drivers\sptd.sys
11:53:04.0086 5012 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: a6cff1af7664627a296b6a0a96cf876e
11:53:04.0087 5012 sptd ( LockedFile.Multi.Generic ) - warning
11:53:04.0087 5012 sptd - detected LockedFile.Multi.Generic (1)
11:53:04.0134 5012 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
11:53:04.0136 5012 srv - ok
11:53:04.0177 5012 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
11:53:04.0179 5012 srv2 - ok
11:53:04.0196 5012 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
11:53:04.0197 5012 srvnet - ok
11:53:04.0250 5012 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
11:53:04.0251 5012 stexstor - ok
11:53:04.0303 5012 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
11:53:04.0304 5012 storflt - ok
11:53:04.0351 5012 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
11:53:04.0352 5012 storvsc - ok
11:53:04.0406 5012 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
11:53:04.0407 5012 swenum - ok
11:53:04.0446 5012 sxuptp (11c9c422583eaeadd807c3fbcfc7496c) C:\Windows\system32\DRIVERS\sxuptp.sys
11:53:04.0449 5012 sxuptp - ok
11:53:04.0460 5012 Synth3dVsc - ok
11:53:04.0570 5012 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
11:53:04.0578 5012 Tcpip - ok
11:53:04.0620 5012 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
11:53:04.0628 5012 TCPIP6 - ok
11:53:04.0665 5012 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
11:53:04.0666 5012 tcpipreg - ok
11:53:04.0711 5012 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
11:53:04.0711 5012 TDPIPE - ok
11:53:04.0751 5012 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
11:53:04.0752 5012 TDTCP - ok
11:53:04.0792 5012 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
11:53:04.0793 5012 tdx - ok
11:53:04.0802 5012 TEAM - ok
11:53:04.0837 5012 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
11:53:04.0838 5012 TermDD - ok
11:53:04.0889 5012 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
11:53:04.0889 5012 tssecsrv - ok
11:53:04.0943 5012 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
11:53:04.0943 5012 TsUsbFlt - ok
11:53:04.0952 5012 tsusbhub - ok
11:53:05.0004 5012 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
11:53:05.0005 5012 tunnel - ok
11:53:05.0055 5012 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
11:53:05.0056 5012 uagp35 - ok
11:53:05.0110 5012 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
11:53:05.0112 5012 udfs - ok
11:53:05.0174 5012 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
11:53:05.0175 5012 uliagpkx - ok
11:53:05.0221 5012 Ultra (1536b8a53df917e5a3f3b0207df06fda) C:\Windows\system32\DRIVERS\Ultra.sys
11:53:05.0222 5012 Ultra - ok
11:53:05.0238 5012 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
11:53:05.0239 5012 umbus - ok
11:53:05.0288 5012 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
11:53:05.0288 5012 UmPass - ok
11:53:05.0334 5012 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
11:53:05.0335 5012 usbaudio - ok
11:53:05.0371 5012 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
11:53:05.0372 5012 usbccgp - ok
11:53:05.0412 5012 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
11:53:05.0412 5012 usbcir - ok
11:53:05.0461 5012 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
11:53:05.0462 5012 usbehci - ok
11:53:05.0482 5012 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
11:53:05.0484 5012 usbhub - ok
11:53:05.0512 5012 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
11:53:05.0512 5012 usbohci - ok
11:53:05.0564 5012 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
11:53:05.0564 5012 usbprint - ok
11:53:05.0635 5012 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
11:53:05.0636 5012 usbscan - ok
11:53:05.0683 5012 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:53:05.0684 5012 USBSTOR - ok
11:53:05.0734 5012 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
11:53:05.0734 5012 usbuhci - ok
11:53:05.0792 5012 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
11:53:05.0792 5012 vdrvroot - ok
11:53:05.0846 5012 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
11:53:05.0847 5012 vga - ok
11:53:05.0891 5012 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
11:53:05.0892 5012 VgaSave - ok
11:53:05.0904 5012 VGPU - ok
11:53:05.0965 5012 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
11:53:05.0966 5012 vhdmp - ok
11:53:06.0026 5012 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
11:53:06.0026 5012 viaide - ok
11:53:06.0081 5012 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
11:53:06.0082 5012 vmbus - ok
11:53:06.0117 5012 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
11:53:06.0118 5012 VMBusHID - ok
11:53:06.0158 5012 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
11:53:06.0159 5012 volmgr - ok
11:53:06.0197 5012 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
11:53:06.0199 5012 volmgrx - ok
11:53:06.0224 5012 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
11:53:06.0225 5012 volsnap - ok
11:53:06.0250 5012 vpcbus (b4a73ca4ef9a02b9738cea9ad5fe5917) C:\Windows\system32\DRIVERS\vpchbus.sys
11:53:06.0251 5012 vpcbus - ok
11:53:06.0294 5012 vpcnfltr (e675fb2b48c54f09895482e2253b289c) C:\Windows\system32\DRIVERS\vpcnfltr.sys
11:53:06.0295 5012 vpcnfltr - ok
11:53:06.0312 5012 vpcusb (5fb42082b0d19a0268705f1dd343df20) C:\Windows\system32\DRIVERS\vpcusb.sys
11:53:06.0313 5012 vpcusb - ok
11:53:06.0352 5012 vpcvmm (207b6539799cc1c112661a9b620dd233) C:\Windows\system32\drivers\vpcvmm.sys
11:53:06.0353 5012 vpcvmm - ok
11:53:06.0405 5012 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
11:53:06.0406 5012 vsmraid - ok
11:53:06.0427 5012 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
11:53:06.0428 5012 vwifibus - ok
11:53:06.0454 5012 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
11:53:06.0454 5012 WacomPen - ok
11:53:06.0511 5012 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
11:53:06.0512 5012 WANARP - ok
11:53:06.0528 5012 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
11:53:06.0528 5012 Wanarpv6 - ok
11:53:06.0566 5012 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
11:53:06.0566 5012 Wd - ok
11:53:06.0592 5012 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
11:53:06.0596 5012 Wdf01000 - ok
11:53:06.0629 5012 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
11:53:06.0630 5012 WfpLwf - ok
11:53:06.0679 5012 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
11:53:06.0680 5012 WIMMount - ok
11:53:06.0768 5012 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
11:53:06.0768 5012 WinUsb - ok
11:53:06.0839 5012 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
11:53:06.0839 5012 WmiAcpi - ok
11:53:06.0872 5012 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
11:53:06.0872 5012 ws2ifsl - ok
11:53:06.0932 5012 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
11:53:06.0933 5012 WudfPf - ok
11:53:06.0971 5012 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
11:53:06.0972 5012 WUDFRd - ok
11:53:07.0021 5012 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
11:53:07.0176 5012 \Device\Harddisk0\DR0 - ok
11:53:07.0180 5012 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
11:53:07.0182 5012 \Device\Harddisk1\DR1 - ok
11:53:07.0211 5012 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk2\DR2
11:53:07.0276 5012 \Device\Harddisk2\DR2 - ok
11:53:07.0281 5012 Boot (0x1200) (1664e8b7d6bf1d92287b9166174c961e) \Device\Harddisk0\DR0\Partition0
11:53:07.0282 5012 \Device\Harddisk0\DR0\Partition0 - ok
11:53:07.0299 5012 Boot (0x1200) (e6d4378ed8015e8a5e9a57f171e25b35) \Device\Harddisk1\DR1\Partition0
11:53:07.0299 5012 \Device\Harddisk1\DR1\Partition0 - ok
11:53:07.0309 5012 Boot (0x1200) (b294162502cd86c25a830a0cd97a10d9) \Device\Harddisk2\DR2\Partition0
11:53:07.0311 5012 \Device\Harddisk2\DR2\Partition0 - ok
11:53:07.0324 5012 Boot (0x1200) (18ad71ad5b6a7bbc20abccba8c122408) \Device\Harddisk2\DR2\Partition1
11:53:07.0326 5012 \Device\Harddisk2\DR2\Partition1 - ok
11:53:07.0326 5012 ============================================================
11:53:07.0326 5012 Scan finished
11:53:07.0326 5012 ============================================================
11:53:07.0337 3680 Detected object count: 1
11:53:07.0337 3680 Actual detected object count: 1
11:53:17.0375 3680 sptd ( LockedFile.Multi.Generic ) - skipped by user
11:53:17.0375 3680 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

#7 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 02 March 2012 - 11:18 PM

One more please,how is it running?

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
Click the "Scan" button to start scan:
Posted Image

On completion of the scan click "Save log", save it to your desktop and post in your next reply:
Posted Image

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#8 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 03 March 2012 - 05:18 AM

Hi,

Here's the aswMBR log you requested. I tried to select the option to scan the entire drive but, it would not complete and repeatedly kept on locking up in regular and safe mode.
The following log is was done under the option of "QuickScan" if i remember right.


aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-03 17:15:46
-----------------------------
17:15:46.508 OS Version: Windows x64 6.1.7601 Service Pack 1
17:15:46.508 Number of processors: 2 586 0x602
17:15:46.508 ComputerName: MAO-PC UserName: Mao
17:15:47.335 Initialize success
17:15:55.853 AVAST engine defs: 12030201
17:15:59.456 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-1
17:15:59.456 Disk 0 Vendor: ST3200822A 3.01 Size: 190782MB BusType: 3
17:15:59.472 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000069
17:15:59.472 Disk 1 Vendor: WDC_WD15 01.0 Size: 1430799MB BusType: 3
17:15:59.472 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\0000006a
17:15:59.472 Disk 2 Vendor: ST332061 CC2F Size: 305245MB BusType: 3
17:15:59.488 Disk 2 MBR read successfully
17:15:59.488 Disk 2 MBR scan
17:15:59.488 Disk 2 Windows 7 default MBR code
17:15:59.503 Disk 2 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
17:15:59.581 Disk 2 Partition 2 00 07 HPFS/NTFS NTFS 305143 MB offset 206848
17:15:59.659 Disk 2 scanning C:\Windows\system32\drivers
17:16:28.602 Service scanning
17:17:13.439 Modules scanning
17:17:13.445 Disk 2 trace - called modules:
17:17:13.456 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa80045e22c0]<<sptd.sys storport.sys hal.dll nvstor64.sys
17:17:13.460 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0xfffffa8004bfe790]
17:17:13.463 3 CLASSPNP.SYS[fffff8800185143f] -> nt!IofCallDriver -> [0xfffffa8004798d30]
17:17:13.466 5 ACPI.sys[fffff88000f887a1] -> nt!IofCallDriver -> \Device\0000006a[0xfffffa800479b060]
17:17:13.470 \Driver\nvstor64[0xfffffa8004766940] -> IRP_MJ_CREATE -> 0xfffffa80045e22c0
17:17:15.910 AVAST engine scan C:\Windows
17:17:21.574 AVAST engine scan C:\Windows\system32
17:23:31.998 AVAST engine scan C:\Windows\system32\drivers
17:24:01.368 AVAST engine scan C:\Users\Mao
17:51:43.155 AVAST engine scan C:\ProgramData
17:55:13.503 Scan finished successfully
17:55:35.851 Disk 2 MBR has been saved successfully to "C:\Users\Mao\Desktop\MBR.dat"
17:55:35.908 The log file has been saved successfully to "C:\Users\Mao\Desktop\aswMBR.txt"

#9 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 03 March 2012 - 08:24 PM

Looks clean now,everything OK?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#10 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 03 March 2012 - 11:30 PM

Hi,

Thanks Boopme. It seems clean. I haven't been getting any redirects so far.

Couple of quick questions though if you can spare the time;

1. Were the redirects the only thing that resulted from the infection? I mean is there anything else I should be concerned about?
2. You mentioned it coming from torrenting but the only thing I managed to find about it was the compromised ads from sites are the cause. I'd appreciate it if you could point me in the right direction so i can read up more on the particular infection I was struck with. A link would be great. MSSE db, despite it being the AV that detected it, doesn't have anything on that particular malware.

Thanks again and I appreciate the time you took to help.

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 04 March 2012 - 12:18 AM

Hello, the most serious things were the Hack infections. These have backdoor capabilities. Meaning they try to make contact with their host and send personal info from your PC to theirs. Such as passwords and financial data. If you do any banking or other financial transactions on the PC,passwords should be changed and it would be wise to contact those same financial institutions to apprise them of your situation.


People can and do send legal files via torrents. The risks are what.where you load from.



Many torrent downloads contain,malware and java scripts (JS) to install other malware.
This is commomn with Free/cracked apps. It's why they are so willing to give it away.

The practice of using cracking tools, keygens, warez or any pirated software is not only considered illegal activity but it is a serious security risk.

Cracking applications are used for illegally breaking (cracking) various copy-protection and registration techniques used in commercial software. These programs may be distributed via Web sites, Usenet, and P2P networks.

trendmicro.com/vinfo

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...

Keygen and Crack Sites Distribute VIRUX and FakeAV

...warez/piracy sites ranked the highest in downloading spyware...just opening the web page usually sets off an exploit, never mind actually downloading anything. And by the time the malware is finished downloading, often the machine is trashed and rendered useless.

University of Washington spyware study

...One of the most aggressive and intrusive of all bad websites on the Internet are serial, warez, software cracking type sites...they sneak malware onto your system...Where do trojan viruses originate? One of the biggest malware distributors on the Internet are serial/warez/code cracking sites.

Bad Web Sites: Malware

When you use these kind of programs, be forewarned that some of the worst types of malware infections can be contracted and spread by visiting crack, keygen, warez and other pirated software sites. In many cases, those sites are infested with a smörgåsbord of malware and an increasing source of system infection. Those who attempt to get software for free can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

Before we can continue, I need you to remove all cracks and keygens immediately to reduce the risk of infection/reinfection. If not, then we are just wasting time trying to clean your system. Further, other tools used during the disinfection process may detect crack and keygens so we need to ensure they have been removed.

Using these types of programs or the websites you visited to get them is almost a guaranteed way to get yourself infected!!
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 04 March 2012 - 06:26 AM

Hello, the most serious things were the Hack infections. These have backdoor capabilities. Meaning they try to make contact with their host and send personal info from your PC to theirs. Such as passwords and financial data. If you do any banking or other financial transactions on the PC,passwords should be changed and it would be wise to contact those same financial institutions to apprise them of your situation.



Ugh, your first paragraph is what I was most afraid of the most. I have no idea how long the infection/s were there for but I will be taking precautions for sure.

Thanks again for your time in assisting me Boopme

#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 04 March 2012 - 06:03 PM

Did you run the other tools yet? As looking at them will tell me if reformatting is the best option for security.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#14 Cyntil8ing

Cyntil8ing
  • Topic Starter

  • Members
  • 77 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 04 March 2012 - 11:15 PM

I ran the detection tools again that I mentioned in my original post. Beyond those, no.
Just a second sweep to be on the safe side.

Did you want me to run something/s in particular for verification?

#15 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:39 AM

Posted 05 March 2012 - 09:08 AM

Hello, the only thing i saw left is that your HOSTS file is misplaced so..

Reset the HOSTS file
As this infection also changes your Windows HOSTS file, we want to replace this file with the default version for your operating system.
Some types of malware will alter the HOSTS file as part of its infection. Please follow the instructions provided in How do I reset the hosts file back to the default?

To reset the hosts file automatically,go HERE click the Posted Image button. Then just follow the prompts in the Fix it wizard.


OR
Click Run in the File Download dialog box or save MicrosoftFixit50267.msi to your Desktop and double-click on it to run. Then just follow the promots in the Fix it wizard.




If there are no more problems or signs of infection, you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users