Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Visa/Mastercard Verisign


  • Please log in to reply
5 replies to this topic

#1 desjakey

desjakey

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 14 April 2012 - 08:22 PM

I tried to order something online today and after entering my card details on the site I was then presented with a box that looked like the visa card verisign, however this was asking me for pin and mothers maiden name etc.

After some reading I think I am infected

Any help would be great as I have tried numerous programmes to rid my pc of this

Helllllllp :clapping:

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:49 AM

Posted 14 April 2012 - 10:39 PM

This looks like a ransomware.Can you boot into safemode?

Download

http://www.techspot.com/downloads/4716-malwarebytes-anti-malware.html

Install,update and run a full scan

Click on SHOW results.Select all infections and remove it

Reboot the PC and scan MBAM once in regular mode until you get a clean log


Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)



Are you able to run malwarebytes? I think ransomware sshould block even malwarebytes from running

Download

http://download.sysinternals.com/files/Autoruns.zip

Extract and launch Autoruns,allow it to finish the scan

Click on File-save as ,save it as

autorun.txt

Upload the text file to www.mediafire.com and post the link here

#3 desjakey

desjakey
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 15 April 2012 - 02:13 PM

20:04:13.0875 5164 TDSS rootkit removing tool 2.7.28.0 Apr 10 2012 16:54:05
20:04:14.0218 5164 ============================================================
20:04:14.0218 5164 Current date / time: 2012/04/15 20:04:14.0218
20:04:14.0218 5164 SystemInfo:
20:04:14.0218 5164
20:04:14.0218 5164 OS Version: 5.1.2600 ServicePack: 3.0
20:04:14.0218 5164 Product type: Workstation
20:04:14.0265 5164 ComputerName: BEDROOM
20:04:14.0265 5164 UserName: Del
20:04:14.0265 5164 Windows directory: C:\WINDOWS
20:04:14.0265 5164 System windows directory: C:\WINDOWS
20:04:14.0265 5164 Processor architecture: Intel x86
20:04:14.0265 5164 Number of processors: 2
20:04:14.0265 5164 Page size: 0x1000
20:04:14.0265 5164 Boot type: Normal boot
20:04:14.0265 5164 ============================================================
20:04:15.0984 5164 Drive \Device\Harddisk0\DR0 - Size: 0x2540BE4000 (149.01 Gb), SectorSize: 0x200, Cylinders: 0x4BFC, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
20:04:15.0984 5164 \Device\Harddisk0\DR0:
20:04:15.0984 5164 MBR used
20:04:15.0984 5164 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0xD92431D
20:04:16.0015 5164 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xD93FAA3, BlocksNum 0x4A7967E
20:04:16.0250 5164 Initialize success
20:04:16.0250 5164 ============================================================
20:04:26.0359 0480 ============================================================
20:04:26.0359 0480 Scan started
20:04:26.0359 0480 Mode: Manual; TDLFS;
20:04:26.0359 0480 ============================================================
20:04:31.0437 0480 0zx_fqi6i.sys - ok
20:04:31.0656 0480 Aavmker4 (473f97edc5a5312f3665ab2921196c0c) C:\WINDOWS\system32\drivers\Aavmker4.sys
20:04:31.0656 0480 Aavmker4 - ok
20:04:32.0093 0480 Abiosdsk - ok
20:04:32.0515 0480 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
20:04:32.0531 0480 abp480n5 - ok
20:04:33.0140 0480 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
20:04:33.0187 0480 ACPI - ok
20:04:33.0687 0480 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
20:04:33.0703 0480 ACPIEC - ok
20:04:34.0078 0480 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
20:04:34.0140 0480 AdobeFlashPlayerUpdateSvc - ok
20:04:34.0625 0480 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
20:04:34.0656 0480 adpu160m - ok
20:04:35.0234 0480 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
20:04:35.0265 0480 aec - ok
20:04:35.0812 0480 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
20:04:35.0843 0480 AFD - ok
20:04:36.0000 0480 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
20:04:36.0031 0480 agp440 - ok
20:04:36.0109 0480 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
20:04:36.0140 0480 agpCPQ - ok
20:04:36.0343 0480 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
20:04:36.0343 0480 Aha154x - ok
20:04:36.0453 0480 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
20:04:36.0468 0480 aic78u2 - ok
20:04:36.0531 0480 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
20:04:36.0546 0480 aic78xx - ok
20:04:36.0656 0480 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
20:04:36.0750 0480 Alerter - ok
20:04:36.0890 0480 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
20:04:36.0953 0480 ALG - ok
20:04:37.0046 0480 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
20:04:37.0078 0480 AliIde - ok
20:04:37.0187 0480 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
20:04:37.0218 0480 alim1541 - ok
20:04:37.0359 0480 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
20:04:37.0359 0480 amdagp - ok
20:04:37.0406 0480 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
20:04:37.0421 0480 amsint - ok
20:04:37.0625 0480 AOL ACS (7f8a24a83193a3a1998ebffdef8e03fb) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
20:04:37.0640 0480 AOL ACS - ok
20:04:37.0859 0480 Apple Mobile Device (2e3e53a6aef23e24f402c7855b9b1542) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:04:37.0859 0480 Apple Mobile Device - ok
20:04:37.0968 0480 AppMgmt - ok
20:04:38.0140 0480 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
20:04:38.0156 0480 asc - ok
20:04:38.0203 0480 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
20:04:38.0203 0480 asc3350p - ok
20:04:38.0234 0480 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
20:04:38.0250 0480 asc3550 - ok
20:04:38.0296 0480 ASPI32 (5b01af89d16d562825c4db4530f20cbb) C:\WINDOWS\system32\drivers\ASPI32.sys
20:04:38.0296 0480 ASPI32 - ok
20:04:38.0437 0480 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
20:04:38.0468 0480 aspnet_state - ok
20:04:38.0546 0480 aswFsBlk (0ae43c6c411254049279c2ee55630f95) C:\WINDOWS\system32\drivers\aswFsBlk.sys
20:04:38.0562 0480 aswFsBlk - ok
20:04:38.0609 0480 aswFW (80beddcbb4a1417cec0c78a61cac0f66) C:\WINDOWS\system32\drivers\aswFW.sys
20:04:38.0609 0480 aswFW - ok
20:04:38.0656 0480 aswKbd (81e695913fefd4e23360a69c0f151797) C:\WINDOWS\system32\drivers\aswKbd.sys
20:04:38.0671 0480 aswKbd - ok
20:04:38.0718 0480 aswMon2 (8c30b7ddd2f1d8d138ebe40345af2b11) C:\WINDOWS\system32\drivers\aswMon2.sys
20:04:38.0734 0480 aswMon2 - ok
20:04:38.0796 0480 aswNdis (7b948e3657bea62e437bc46ca6ef6012) C:\WINDOWS\system32\DRIVERS\aswNdis.sys
20:04:38.0796 0480 aswNdis - ok
20:04:38.0859 0480 aswNdis2 (72c8f79d72b4ff6e1627276ddf4b01c9) C:\WINDOWS\system32\drivers\aswNdis2.sys
20:04:38.0859 0480 aswNdis2 - ok
20:04:38.0890 0480 AswRdr (da12626fd9a67f4e917e2f2fbe1e1764) C:\WINDOWS\system32\drivers\AswRdr.sys
20:04:38.0906 0480 AswRdr - ok
20:04:38.0953 0480 aswSnx (dcb199b967375753b5019ec15f008f53) C:\WINDOWS\system32\drivers\aswSnx.sys
20:04:38.0968 0480 aswSnx - ok
20:04:39.0000 0480 aswSP (b32873e5a1443c0a1e322266e203bf10) C:\WINDOWS\system32\drivers\aswSP.sys
20:04:39.0000 0480 aswSP - ok
20:04:39.0015 0480 aswTdi (6ff544175a9180c5d88534d3d9c9a9f7) C:\WINDOWS\system32\drivers\aswTdi.sys
20:04:39.0031 0480 aswTdi - ok
20:04:39.0093 0480 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
20:04:39.0093 0480 AsyncMac - ok
20:04:39.0125 0480 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
20:04:39.0140 0480 atapi - ok
20:04:39.0156 0480 Atdisk - ok
20:04:39.0171 0480 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
20:04:39.0187 0480 Atmarpc - ok
20:04:39.0312 0480 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
20:04:39.0328 0480 AudioSrv - ok
20:04:39.0609 0480 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
20:04:39.0625 0480 audstub - ok
20:04:39.0765 0480 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
20:04:39.0765 0480 avast! Antivirus - ok
20:04:39.0812 0480 avast! Firewall (7d465549dfb0eca6601e9609c72cd20a) C:\Program Files\AVAST Software\Avast\afwServ.exe
20:04:39.0812 0480 avast! Firewall - ok
20:04:39.0859 0480 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
20:04:39.0875 0480 Beep - ok
20:04:39.0953 0480 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
20:04:40.0031 0480 BITS - ok
20:04:40.0171 0480 Bonjour Service (5ab58c337ac65837fe404462ad6265ab) C:\Program Files\Bonjour\mDNSResponder.exe
20:04:40.0187 0480 Bonjour Service - ok
20:04:40.0234 0480 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
20:04:40.0250 0480 Bridge - ok
20:04:40.0250 0480 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
20:04:40.0250 0480 BridgeMP - ok
20:04:40.0296 0480 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
20:04:40.0296 0480 Browser - ok
20:04:40.0328 0480 BVRPMPR5 (248dfa5762dde38dfddbbd44149e9d7a) C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
20:04:40.0343 0480 BVRPMPR5 - ok
20:04:40.0390 0480 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
20:04:40.0390 0480 cbidf - ok
20:04:40.0406 0480 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
20:04:40.0406 0480 cbidf2k - ok
20:04:40.0453 0480 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
20:04:40.0453 0480 cd20xrnt - ok
20:04:40.0484 0480 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
20:04:40.0484 0480 Cdaudio - ok
20:04:40.0546 0480 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
20:04:40.0546 0480 Cdfs - ok
20:04:40.0578 0480 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
20:04:40.0593 0480 Cdrom - ok
20:04:40.0625 0480 Changer - ok
20:04:40.0703 0480 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
20:04:40.0703 0480 CiSvc - ok
20:04:40.0750 0480 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
20:04:40.0765 0480 ClipSrv - ok
20:04:40.0906 0480 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:04:41.0046 0480 clr_optimization_v2.0.50727_32 - ok
20:04:41.0265 0480 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
20:04:41.0281 0480 CmdIde - ok
20:04:41.0296 0480 COMSysApp - ok
20:04:41.0328 0480 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
20:04:41.0343 0480 Cpqarray - ok
20:04:41.0421 0480 Creative Labs Licensing Service (7db5e3f44d797bd38b8e336ccc2e49d5) C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
20:04:41.0421 0480 Creative Labs Licensing Service - ok
20:04:41.0468 0480 Creative Service for CDROM Access (3c8b6609712f4ff78e521f6dcfc4032b) C:\WINDOWS\system32\CTsvcCDA.exe
20:04:41.0484 0480 Creative Service for CDROM Access - ok
20:04:41.0515 0480 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
20:04:41.0531 0480 CryptSvc - ok
20:04:41.0578 0480 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys
20:04:41.0578 0480 ctsfm2k - ok
20:04:41.0625 0480 CTUSFSYN (4ee8822adb764edd28ce44e808097995) C:\WINDOWS\system32\drivers\ctusfsyn.sys
20:04:41.0625 0480 CTUSFSYN - ok
20:04:41.0656 0480 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
20:04:41.0656 0480 dac2w2k - ok
20:04:41.0703 0480 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
20:04:41.0718 0480 dac960nt - ok
20:04:41.0781 0480 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
20:04:41.0812 0480 DcomLaunch - ok
20:04:41.0859 0480 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
20:04:41.0875 0480 Dhcp - ok
20:04:41.0906 0480 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
20:04:41.0921 0480 Disk - ok
20:04:42.0015 0480 DLABOIOM (a14524d3f130a57163e0b3e057fc85d5) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
20:04:42.0031 0480 DLABOIOM - ok
20:04:42.0062 0480 DLACDBHM (7581407a6a3c56860ae31e6e423fe824) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
20:04:42.0062 0480 DLACDBHM - ok
20:04:42.0078 0480 DLADResN (7c4cdf8a684b63d7482e0bf7440dc3b5) C:\WINDOWS\system32\DLA\DLADResN.SYS
20:04:42.0078 0480 DLADResN - ok
20:04:42.0093 0480 DLAIFS_M (97bca2aac06a9fea56615b4b15bdb9b8) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
20:04:42.0109 0480 DLAIFS_M - ok
20:04:42.0125 0480 DLAOPIOM (be8d558cf749424f0de612813f7c6725) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
20:04:42.0125 0480 DLAOPIOM - ok
20:04:42.0140 0480 DLAPoolM (7e5277cb45dc5e2a86af8ce093c7ef31) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
20:04:42.0140 0480 DLAPoolM - ok
20:04:42.0156 0480 DLARTL_N (693dfd92d41a3d270053cd97834e4960) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
20:04:42.0156 0480 DLARTL_N - ok
20:04:42.0156 0480 DLAUDFAM (d886b6d02b51e5bd61b8a571a16d5ca2) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
20:04:42.0171 0480 DLAUDFAM - ok
20:04:42.0171 0480 DLAUDF_M (2c0ecf7a9d5162d87c64e2ae868b5039) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
20:04:42.0187 0480 DLAUDF_M - ok
20:04:42.0187 0480 dmadmin - ok
20:04:42.0343 0480 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
20:04:42.0359 0480 dmboot - ok
20:04:42.0421 0480 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
20:04:42.0437 0480 dmio - ok
20:04:42.0453 0480 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
20:04:42.0468 0480 dmload - ok
20:04:42.0531 0480 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
20:04:42.0531 0480 dmserver - ok
20:04:42.0578 0480 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
20:04:42.0578 0480 DMusic - ok
20:04:42.0625 0480 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
20:04:42.0640 0480 Dnscache - ok
20:04:42.0718 0480 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
20:04:42.0734 0480 Dot3svc - ok
20:04:42.0765 0480 Dot4 (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
20:04:42.0765 0480 Dot4 - ok
20:04:42.0812 0480 Dot4Print (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
20:04:42.0812 0480 Dot4Print - ok
20:04:42.0859 0480 dot4usb (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
20:04:42.0859 0480 dot4usb - ok
20:04:42.0875 0480 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
20:04:42.0890 0480 dpti2o - ok
20:04:42.0906 0480 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
20:04:42.0906 0480 drmkaud - ok
20:04:42.0953 0480 DRVMCDB (73623d89faef4d1aa600edee8b490bc5) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
20:04:42.0953 0480 DRVMCDB - ok
20:04:42.0968 0480 DRVNDDM (2aeee1600d0f14ba535f90a1f4411b54) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
20:04:42.0968 0480 DRVNDDM - ok
20:04:43.0093 0480 DSproct (2ac2372ffad9adc85672cc8e8ae14be9) C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys
20:04:43.0093 0480 DSproct - ok
20:04:43.0125 0480 E100B (3fca03cbca11269f973b70fa483c88ef) C:\WINDOWS\system32\DRIVERS\e100b325.sys
20:04:43.0125 0480 E100B - ok
20:04:43.0156 0480 e1express (6de32a9123ef60f9d423e9163af0e305) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
20:04:43.0156 0480 e1express - ok
20:04:43.0203 0480 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
20:04:43.0203 0480 EapHost - ok
20:04:43.0234 0480 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
20:04:43.0250 0480 ERSvc - ok
20:04:43.0281 0480 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
20:04:43.0312 0480 Eventlog - ok
20:04:43.0359 0480 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\Es.dll
20:04:43.0359 0480 EventSystem - ok
20:04:43.0421 0480 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
20:04:43.0437 0480 Fastfat - ok
20:04:43.0484 0480 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
20:04:43.0484 0480 FastUserSwitchingCompatibility - ok
20:04:43.0515 0480 Fax (e97d6a8684466df94ff3bc24fb787a07) C:\WINDOWS\system32\fxssvc.exe
20:04:43.0531 0480 Fax - ok
20:04:43.0562 0480 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
20:04:43.0562 0480 Fdc - ok
20:04:43.0734 0480 FileMonitor (9200a69413d69ab86add9bc81960be7b) C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys
20:04:43.0734 0480 FileMonitor - ok
20:04:43.0781 0480 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
20:04:43.0781 0480 Fips - ok
20:04:43.0812 0480 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
20:04:43.0812 0480 Flpydisk - ok
20:04:43.0875 0480 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
20:04:43.0921 0480 FltMgr - ok
20:04:44.0140 0480 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
20:04:44.0156 0480 FontCache3.0.0.0 - ok
20:04:44.0203 0480 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
20:04:44.0203 0480 Fs_Rec - ok
20:04:44.0234 0480 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
20:04:44.0234 0480 Ftdisk - ok
20:04:44.0281 0480 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
20:04:44.0281 0480 GearAspiWDM - ok
20:04:44.0296 0480 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
20:04:44.0312 0480 Gpc - ok
20:04:44.0375 0480 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
20:04:44.0375 0480 HDAudBus - ok
20:04:44.0468 0480 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
20:04:44.0468 0480 helpsvc - ok
20:04:44.0515 0480 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
20:04:44.0531 0480 HidServ - ok
20:04:44.0546 0480 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
20:04:44.0546 0480 HidUsb - ok
20:04:44.0593 0480 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
20:04:44.0593 0480 hkmsvc - ok
20:04:44.0640 0480 hnmwrlspkt (cabba915f11ff2013c550bb1a9b977df) C:\WINDOWS\system32\DRIVERS\hnm_wrls_pkt.sys
20:04:44.0640 0480 hnmwrlspkt - ok
20:04:44.0671 0480 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
20:04:44.0671 0480 hpn - ok
20:04:44.0796 0480 HsdService (45a033481b6eccc4534e14b6e2416a00) C:\Program Files\Virgin Media\Digital Home Support\HsdService.exe
20:04:44.0843 0480 HsdService - ok
20:04:44.0890 0480 HTCAND32 (cbd09ed9cf6822177ee85aea4d8816a2) C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys
20:04:44.0890 0480 HTCAND32 - ok
20:04:44.0937 0480 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
20:04:44.0953 0480 HTTP - ok
20:04:44.0968 0480 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
20:04:45.0000 0480 HTTPFilter - ok
20:04:45.0031 0480 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
20:04:45.0031 0480 i2omgmt - ok
20:04:45.0062 0480 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
20:04:45.0062 0480 i2omp - ok
20:04:45.0093 0480 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
20:04:45.0093 0480 i8042prt - ok
20:04:45.0203 0480 IAANTMON (b122be74e283a2bc7febc180bfd2efd5) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
20:04:45.0203 0480 IAANTMON - ok
20:04:45.0250 0480 iastor (d5edb998656e6ecf1a17c78dab019a3c) C:\WINDOWS\system32\drivers\iastor.sys
20:04:45.0250 0480 iastor - ok
20:04:45.0375 0480 IDriverT (daf66902f08796f9c694901660e5a64a) C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
20:04:45.0390 0480 IDriverT - ok
20:04:45.0515 0480 idsvc (c01ac32dc5c03076cfb852cb5da5229c) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
20:04:45.0546 0480 idsvc - ok
20:04:45.0625 0480 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
20:04:45.0625 0480 Imapi - ok
20:04:45.0687 0480 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
20:04:45.0687 0480 ImapiService - ok
20:04:45.0828 0480 IMFservice (8ae99ebe30e8338907361018d9030835) C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
20:04:45.0843 0480 IMFservice - ok
20:04:45.0890 0480 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
20:04:45.0890 0480 ini910u - ok
20:04:45.0953 0480 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
20:04:45.0953 0480 IntelIde - ok
20:04:46.0000 0480 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
20:04:46.0015 0480 intelppm - ok
20:04:46.0078 0480 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
20:04:46.0078 0480 Ip6Fw - ok
20:04:46.0109 0480 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
20:04:46.0109 0480 IpFilterDriver - ok
20:04:46.0140 0480 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
20:04:46.0140 0480 IpInIp - ok
20:04:46.0171 0480 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
20:04:46.0171 0480 IpNat - ok
20:04:46.0250 0480 iPod Service (8f610078437a459948480407f4db91ea) C:\Program Files\iPod\bin\iPodService.exe
20:04:46.0250 0480 iPod Service - ok
20:04:46.0296 0480 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
20:04:46.0296 0480 IPSec - ok
20:04:46.0343 0480 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
20:04:46.0359 0480 IRENUM - ok
20:04:46.0375 0480 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
20:04:46.0390 0480 isapnp - ok
20:04:46.0531 0480 JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Program Files\Java\jre6\bin\jqs.exe
20:04:46.0578 0480 JavaQuickStarterService - ok
20:04:46.0640 0480 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
20:04:46.0671 0480 Kbdclass - ok
20:04:46.0687 0480 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
20:04:46.0718 0480 kbdhid - ok
20:04:46.0843 0480 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
20:04:46.0875 0480 kmixer - ok
20:04:46.0937 0480 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
20:04:46.0968 0480 KSecDD - ok
20:04:47.0062 0480 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
20:04:47.0500 0480 lanmanserver - ok
20:04:47.0750 0480 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
20:04:48.0000 0480 lanmanworkstation - ok
20:04:48.0093 0480 lbrtfdc - ok
20:04:48.0140 0480 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
20:04:48.0156 0480 LmHosts - ok
20:04:48.0187 0480 massfilter (112db6314bb175ba5f27a66e11c01d77) C:\WINDOWS\system32\drivers\massfilter.sys
20:04:48.0187 0480 massfilter - ok
20:04:48.0234 0480 MBAMProtector (fb097bbc1a18f044bd17bd2fccf97865) C:\WINDOWS\system32\drivers\mbam.sys
20:04:48.0250 0480 MBAMProtector - ok
20:04:48.0406 0480 MBAMService (ba400ed640bca1eae5c727ae17c10207) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
20:04:48.0453 0480 MBAMService - ok
20:04:48.0484 0480 MBAMSwissArmy - ok
20:04:48.0531 0480 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
20:04:48.0546 0480 Messenger - ok
20:04:48.0578 0480 mferkdk (41fe2f288e05a6c8ab85dd56770ffbad) C:\WINDOWS\system32\drivers\mferkdk.sys
20:04:48.0593 0480 mferkdk - ok
20:04:48.0625 0480 mfesmfk (096b52ea918aa909ba5903d79e129005) C:\WINDOWS\system32\drivers\mfesmfk.sys
20:04:48.0625 0480 mfesmfk - ok
20:04:48.0734 0480 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
20:04:48.0750 0480 mnmdd - ok
20:04:48.0875 0480 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
20:04:48.0890 0480 mnmsrvc - ok
20:04:49.0000 0480 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
20:04:49.0000 0480 Modem - ok
20:04:49.0078 0480 monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\monfilt.sys
20:04:49.0109 0480 monfilt - ok
20:04:49.0140 0480 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
20:04:49.0156 0480 Mouclass - ok
20:04:49.0203 0480 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
20:04:49.0203 0480 mouhid - ok
20:04:49.0250 0480 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
20:04:49.0265 0480 MountMgr - ok
20:04:49.0343 0480 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
20:04:49.0359 0480 mraid35x - ok
20:04:49.0500 0480 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
20:04:49.0515 0480 MRxDAV - ok
20:04:49.0687 0480 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
20:04:49.0703 0480 MRxSmb - ok
20:04:49.0843 0480 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
20:04:49.0859 0480 MSDTC - ok
20:04:49.0984 0480 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
20:04:49.0984 0480 Msfs - ok
20:04:50.0031 0480 MSIServer - ok
20:04:50.0093 0480 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
20:04:50.0109 0480 MSKSSRV - ok
20:04:50.0171 0480 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
20:04:50.0187 0480 MSPCLOCK - ok
20:04:50.0265 0480 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
20:04:50.0281 0480 MSPQM - ok
20:04:50.0359 0480 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
20:04:50.0359 0480 mssmbios - ok
20:04:50.0406 0480 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
20:04:50.0421 0480 Mup - ok
20:04:50.0609 0480 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
20:04:50.0687 0480 napagent - ok
20:04:50.0812 0480 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
20:04:50.0828 0480 NDIS - ok
20:04:50.0984 0480 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
20:04:51.0015 0480 NdisTapi - ok
20:04:51.0062 0480 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
20:04:51.0078 0480 Ndisuio - ok
20:04:51.0171 0480 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
20:04:51.0187 0480 NdisWan - ok
20:04:51.0218 0480 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
20:04:51.0218 0480 NDProxy - ok
20:04:51.0281 0480 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
20:04:51.0296 0480 NetBIOS - ok
20:04:51.0343 0480 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
20:04:51.0359 0480 NetBT - ok
20:04:51.0390 0480 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
20:04:51.0406 0480 NetDDE - ok
20:04:51.0406 0480 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
20:04:51.0421 0480 NetDDEdsdm - ok
20:04:51.0453 0480 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
20:04:51.0468 0480 Netlogon - ok
20:04:51.0484 0480 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
20:04:51.0500 0480 Netman - ok
20:04:51.0625 0480 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:04:51.0625 0480 NetTcpPortSharing - ok
20:04:51.0734 0480 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
20:04:51.0750 0480 Nla - ok
20:04:51.0875 0480 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
20:04:51.0890 0480 Npfs - ok
20:04:52.0046 0480 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
20:04:52.0093 0480 Ntfs - ok
20:04:52.0171 0480 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
20:04:52.0171 0480 NtLmSsp - ok
20:04:52.0343 0480 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
20:04:52.0375 0480 NtmsSvc - ok
20:04:52.0453 0480 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
20:04:52.0453 0480 Null - ok
20:04:54.0875 0480 nv (4b54dcd6adee535df80f07c59ddd8f14) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
20:04:56.0656 0480 nv - ok
20:04:57.0000 0480 NVSvc (0573c75a2895d973ea6ef2495620ba49) C:\WINDOWS\system32\nvsvc32.exe
20:04:57.0015 0480 NVSvc - ok
20:04:57.0640 0480 nvUpdatusService (9c84945feee40ea42d3bca5c22250d47) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
20:04:57.0703 0480 nvUpdatusService - ok
20:04:57.0968 0480 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
20:04:57.0968 0480 NwlnkFlt - ok
20:04:57.0984 0480 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
20:04:57.0984 0480 NwlnkFwd - ok
20:04:58.0062 0480 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys
20:04:58.0078 0480 ossrv - ok
20:04:58.0109 0480 Packet (ec0d523b492764b15b3b6b1e17172201) C:\WINDOWS\system32\DRIVERS\packet.sys
20:04:58.0109 0480 Packet - ok
20:04:58.0140 0480 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
20:04:58.0140 0480 Parport - ok
20:04:58.0171 0480 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
20:04:58.0171 0480 PartMgr - ok
20:04:58.0203 0480 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
20:04:58.0218 0480 ParVdm - ok
20:04:58.0250 0480 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
20:04:58.0250 0480 PCI - ok
20:04:58.0312 0480 PCIDump - ok
20:04:58.0359 0480 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
20:04:58.0359 0480 PCIIde - ok
20:04:58.0390 0480 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
20:04:58.0390 0480 Pcmcia - ok
20:04:58.0406 0480 PDCOMP - ok
20:04:58.0406 0480 PDFRAME - ok
20:04:58.0437 0480 PDRELI - ok
20:04:58.0453 0480 PDRFRAME - ok
20:04:58.0484 0480 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
20:04:58.0484 0480 perc2 - ok
20:04:58.0515 0480 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
20:04:58.0531 0480 perc2hib - ok
20:04:58.0609 0480 PfModNT (ede8241b75dadef090aadb6c81c8e1d7) C:\WINDOWS\system32\drivers\PfModNT.sys
20:04:58.0609 0480 PfModNT - ok
20:04:58.0656 0480 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
20:04:58.0671 0480 PlugPlay - ok
20:04:58.0718 0480 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
20:04:58.0718 0480 PolicyAgent - ok
20:04:58.0734 0480 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
20:04:58.0750 0480 PptpMiniport - ok
20:04:58.0750 0480 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
20:04:58.0765 0480 ProtectedStorage - ok
20:04:58.0796 0480 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
20:04:58.0796 0480 PSched - ok
20:04:58.0812 0480 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
20:04:58.0812 0480 Ptilink - ok
20:04:58.0859 0480 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
20:04:58.0875 0480 PxHelp20 - ok
20:04:58.0906 0480 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
20:04:58.0937 0480 ql1080 - ok
20:04:58.0968 0480 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
20:04:58.0984 0480 Ql10wnt - ok
20:04:59.0046 0480 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
20:04:59.0078 0480 ql12160 - ok
20:04:59.0140 0480 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
20:04:59.0171 0480 ql1240 - ok
20:04:59.0203 0480 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
20:04:59.0218 0480 ql1280 - ok
20:04:59.0250 0480 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
20:04:59.0281 0480 RasAcd - ok
20:04:59.0328 0480 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
20:04:59.0328 0480 RasAuto - ok
20:04:59.0390 0480 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
20:04:59.0390 0480 Rasl2tp - ok
20:04:59.0453 0480 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
20:04:59.0468 0480 RasMan - ok
20:04:59.0500 0480 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
20:04:59.0515 0480 RasPppoe - ok
20:04:59.0593 0480 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
20:04:59.0593 0480 Raspti - ok
20:04:59.0703 0480 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
20:04:59.0750 0480 Rdbss - ok
20:04:59.0828 0480 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
20:04:59.0843 0480 RDPCDD - ok
20:04:59.0937 0480 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
20:04:59.0937 0480 rdpdr - ok
20:05:00.0078 0480 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
20:05:00.0093 0480 RDPWD - ok
20:05:00.0234 0480 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
20:05:00.0265 0480 RDSessMgr - ok
20:05:00.0312 0480 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
20:05:00.0312 0480 redbook - ok
20:05:00.0359 0480 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
20:05:00.0375 0480 RemoteAccess - ok
20:05:00.0421 0480 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
20:05:00.0453 0480 RpcLocator - ok
20:05:00.0562 0480 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
20:05:00.0578 0480 RpcSs - ok
20:05:00.0671 0480 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
20:05:00.0687 0480 RSVP - ok
20:05:00.0734 0480 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
20:05:00.0750 0480 SamSs - ok
20:05:00.0812 0480 SBRE (1fd538c4feb36b793d2121f20bbdc16f) C:\WINDOWS\system32\drivers\SBREdrv.sys
20:05:00.0828 0480 SBRE - ok
20:05:00.0937 0480 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
20:05:00.0953 0480 SCardSvr - ok
20:05:01.0062 0480 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
20:05:01.0078 0480 Schedule - ok
20:05:01.0203 0480 se44bus (3097cff31374e309a8950775111a52bd) C:\WINDOWS\system32\DRIVERS\se44bus.sys
20:05:01.0218 0480 se44bus - ok
20:05:01.0281 0480 se44mdfl (4a03dd4fb5b7cb2c53d8fe8848455a4e) C:\WINDOWS\system32\DRIVERS\se44mdfl.sys
20:05:01.0281 0480 se44mdfl - ok
20:05:01.0406 0480 se44mdm (2ca2e66a945b5de1228ab5f5341d0e97) C:\WINDOWS\system32\DRIVERS\se44mdm.sys
20:05:01.0453 0480 se44mdm - ok
20:05:01.0609 0480 se44mgmt (1977fb3c58c7c714a0ba8ad7960efb26) C:\WINDOWS\system32\DRIVERS\se44mgmt.sys
20:05:01.0625 0480 se44mgmt - ok
20:05:01.0687 0480 se44nd5 (9bd87c965eb93475bcbd732936f46e7c) C:\WINDOWS\system32\DRIVERS\se44nd5.sys
20:05:01.0687 0480 se44nd5 - ok
20:05:01.0703 0480 se44obex (5eff45d05677695417c523d89c1757b6) C:\WINDOWS\system32\DRIVERS\se44obex.sys
20:05:01.0703 0480 se44obex - ok
20:05:01.0812 0480 se44unic (037d2d26f91ca67bad9da36fe5c88640) C:\WINDOWS\system32\DRIVERS\se44unic.sys
20:05:01.0828 0480 se44unic - ok
20:05:01.0921 0480 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
20:05:01.0921 0480 Secdrv - ok
20:05:01.0968 0480 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
20:05:01.0984 0480 seclogon - ok
20:05:02.0078 0480 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
20:05:02.0093 0480 SENS - ok
20:05:02.0187 0480 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
20:05:02.0187 0480 serenum - ok
20:05:02.0296 0480 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
20:05:02.0312 0480 Serial - ok
20:05:02.0625 0480 ServicepointService (aec6c79f72aa0e86bafcb18d2bd2e74c) C:\Program Files\Virgin Media\Service Manager\ServicepointService.exe
20:05:02.0718 0480 ServicepointService - ok
20:05:03.0031 0480 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
20:05:03.0046 0480 Sfloppy - ok
20:05:03.0203 0480 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
20:05:03.0265 0480 SharedAccess - ok
20:05:03.0421 0480 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
20:05:03.0437 0480 ShellHWDetection - ok
20:05:03.0531 0480 Simbad - ok
20:05:03.0640 0480 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
20:05:03.0640 0480 sisagp - ok
20:05:03.0671 0480 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
20:05:03.0703 0480 Sparrow - ok
20:05:03.0734 0480 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
20:05:03.0734 0480 splitter - ok
20:05:03.0765 0480 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
20:05:03.0781 0480 Spooler - ok
20:05:03.0984 0480 sptd (d390675b8ce45e5fb359338e5e649329) C:\WINDOWS\system32\Drivers\sptd.sys
20:05:03.0984 0480 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d390675b8ce45e5fb359338e5e649329
20:05:03.0984 0480 sptd ( LockedFile.Multi.Generic ) - warning
20:05:03.0984 0480 sptd - detected LockedFile.Multi.Generic (1)
20:05:04.0046 0480 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
20:05:04.0062 0480 sr - ok
20:05:04.0187 0480 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
20:05:04.0203 0480 srservice - ok
20:05:04.0359 0480 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
20:05:04.0390 0480 Srv - ok
20:05:04.0421 0480 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
20:05:04.0437 0480 SSDPSRV - ok
20:05:04.0687 0480 StarWindServiceAE (b1691af4a072cb674d600db16dd7308e) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
20:05:04.0734 0480 StarWindServiceAE - ok
20:05:04.0984 0480 STHDA (797fcc1d859b203958e915bb82528da9) C:\WINDOWS\system32\drivers\sthda.sys
20:05:05.0078 0480 STHDA - ok
20:05:05.0375 0480 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
20:05:05.0421 0480 stisvc - ok
20:05:05.0546 0480 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
20:05:05.0578 0480 swenum - ok
20:05:05.0703 0480 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
20:05:05.0718 0480 swmidi - ok
20:05:05.0765 0480 SwPrv - ok
20:05:05.0812 0480 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
20:05:05.0828 0480 symc810 - ok
20:05:05.0984 0480 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
20:05:05.0984 0480 symc8xx - ok
20:05:06.0046 0480 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
20:05:06.0062 0480 sym_hi - ok
20:05:06.0140 0480 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
20:05:06.0156 0480 sym_u3 - ok
20:05:06.0234 0480 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
20:05:06.0234 0480 sysaudio - ok
20:05:06.0281 0480 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
20:05:06.0296 0480 SysmonLog - ok
20:05:06.0406 0480 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
20:05:06.0437 0480 TapiSrv - ok
20:05:06.0687 0480 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
20:05:06.0703 0480 Tcpip - ok
20:05:06.0796 0480 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
20:05:06.0812 0480 TDPIPE - ok
20:05:06.0906 0480 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
20:05:06.0921 0480 TDTCP - ok
20:05:06.0968 0480 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
20:05:06.0968 0480 TermDD - ok
20:05:07.0125 0480 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
20:05:07.0140 0480 TermService - ok
20:05:07.0250 0480 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
20:05:07.0250 0480 Themes - ok
20:05:07.0375 0480 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
20:05:07.0406 0480 TosIde - ok
20:05:07.0468 0480 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
20:05:07.0484 0480 TrkWks - ok
20:05:07.0796 0480 TVersityMediaServer (e0a9b5b92097211a57fd16d27f2b3750) C:\Program Files\TVersity\Media Server\MediaServer.exe
20:05:07.0843 0480 TVersityMediaServer - ok
20:05:08.0140 0480 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
20:05:08.0156 0480 Udfs - ok
20:05:08.0265 0480 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
20:05:08.0281 0480 ultra - ok
20:05:08.0359 0480 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
20:05:08.0375 0480 Update - ok
20:05:08.0453 0480 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
20:05:08.0484 0480 upnphost - ok
20:05:08.0531 0480 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
20:05:08.0546 0480 UPS - ok
20:05:08.0656 0480 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\WINDOWS\system32\Drivers\usbaapl.sys
20:05:08.0656 0480 USBAAPL - ok
20:05:08.0718 0480 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
20:05:08.0734 0480 usbaudio - ok
20:05:08.0890 0480 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
20:05:08.0890 0480 usbccgp - ok
20:05:08.0984 0480 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
20:05:09.0000 0480 usbehci - ok
20:05:09.0046 0480 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
20:05:09.0062 0480 usbhub - ok
20:05:09.0125 0480 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
20:05:09.0140 0480 usbscan - ok
20:05:09.0218 0480 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
20:05:09.0234 0480 USBSTOR - ok
20:05:09.0265 0480 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
20:05:09.0281 0480 usbuhci - ok
20:05:09.0328 0480 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
20:05:09.0343 0480 usb_rndisx - ok
20:05:09.0375 0480 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
20:05:09.0390 0480 VgaSave - ok
20:05:09.0437 0480 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
20:05:09.0453 0480 viaagp - ok
20:05:09.0500 0480 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
20:05:09.0515 0480 ViaIde - ok
20:05:09.0593 0480 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
20:05:09.0593 0480 VolSnap - ok
20:05:09.0687 0480 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
20:05:09.0718 0480 VSS - ok
20:05:09.0750 0480 w32time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
20:05:09.0765 0480 w32time - ok
20:05:09.0796 0480 w810bus (5e8b60606fc4173b69cdecd964f22d28) C:\WINDOWS\system32\DRIVERS\w810bus.sys
20:05:09.0812 0480 w810bus - ok
20:05:09.0828 0480 w810mdfl (c0cc4f5a3c58b4c07ec4a82a5ae24714) C:\WINDOWS\system32\DRIVERS\w810mdfl.sys
20:05:09.0828 0480 w810mdfl - ok
20:05:09.0859 0480 w810mdm (2aafeedc3bfe14419cbce7ceea59dd05) C:\WINDOWS\system32\DRIVERS\w810mdm.sys
20:05:09.0859 0480 w810mdm - ok
20:05:09.0875 0480 w810mgmt (b0037db3f890d0ffcf7e35f356a435ec) C:\WINDOWS\system32\DRIVERS\w810mgmt.sys
20:05:09.0890 0480 w810mgmt - ok
20:05:09.0906 0480 w810obex (bf609636068f17246f94b490c5812483) C:\WINDOWS\system32\DRIVERS\w810obex.sys
20:05:09.0906 0480 w810obex - ok
20:05:09.0921 0480 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
20:05:09.0921 0480 Wanarp - ok
20:05:09.0968 0480 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
20:05:09.0968 0480 wanatw - ok
20:05:10.0031 0480 Wdf01000 (4769596d7cc0f5fa447d2babc239672a) C:\WINDOWS\system32\Drivers\wdf01000.sys
20:05:10.0031 0480 Wdf01000 - ok
20:05:10.0046 0480 WDICA - ok
20:05:10.0078 0480 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
20:05:10.0078 0480 wdmaud - ok
20:05:10.0109 0480 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
20:05:10.0125 0480 WebClient - ok
20:05:10.0203 0480 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
20:05:10.0203 0480 winmgmt - ok
20:05:10.0250 0480 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
20:05:10.0250 0480 WmdmPmSN - ok
20:05:10.0296 0480 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
20:05:10.0296 0480 WmiApSrv - ok
20:05:10.0406 0480 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
20:05:10.0421 0480 WMPNetworkSvc - ok
20:05:10.0437 0480 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
20:05:10.0453 0480 WS2IFSL - ok
20:05:10.0515 0480 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
20:05:10.0531 0480 wscsvc - ok
20:05:10.0593 0480 wsppkt (22068dca607f93bf5fd5926390fb478f) C:\WINDOWS\system32\DRIVERS\wsp_pkt.sys
20:05:10.0593 0480 wsppkt - ok
20:05:10.0640 0480 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
20:05:10.0656 0480 wuauserv - ok
20:05:10.0718 0480 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
20:05:10.0734 0480 WudfPf - ok
20:05:10.0781 0480 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
20:05:10.0781 0480 WudfRd - ok
20:05:10.0812 0480 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
20:05:10.0828 0480 WudfSvc - ok
20:05:10.0875 0480 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
20:05:10.0890 0480 WZCSVC - ok
20:05:10.0906 0480 xcpip - ok
20:05:10.0937 0480 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
20:05:10.0953 0480 xmlprov - ok
20:05:10.0968 0480 xpsec - ok
20:05:11.0078 0480 YahooAUService (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
20:05:11.0093 0480 YahooAUService - ok
20:05:11.0140 0480 ZTEusbmdm6k (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys
20:05:11.0140 0480 ZTEusbmdm6k - ok
20:05:11.0171 0480 ZTEusbnet (d788e7d89cc491644d7a45b227f9b25e) C:\WINDOWS\system32\DRIVERS\ZTEusbnet.sys
20:05:11.0171 0480 ZTEusbnet - ok
20:05:11.0203 0480 ZTEusbnmea (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys
20:05:11.0203 0480 ZTEusbnmea - ok
20:05:11.0218 0480 ZTEusbser6k (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys
20:05:11.0234 0480 ZTEusbser6k - ok
20:05:11.0328 0480 ZuneNetworkSvc (6bba0510e705a6b9891fdbd9806ed78e) C:\Program Files\Zune\ZuneNss.exe
20:05:11.0359 0480 ZuneNetworkSvc - ok
20:05:11.0375 0480 MBR (0x1B8) (01d0f71795f2cd0dc04f3eac61d62b4f) \Device\Harddisk0\DR0
20:05:11.0375 0480 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected
20:05:11.0375 0480 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0)
20:05:11.0515 0480 Boot (0x1200) (a9ca0dfdde4c32dec24297fd670f3d6e) \Device\Harddisk0\DR0\Partition0
20:05:11.0515 0480 \Device\Harddisk0\DR0\Partition0 - ok
20:05:11.0531 0480 Boot (0x1200) (4f4c40311a96a7de9d68fd689e402e57) \Device\Harddisk0\DR0\Partition1
20:05:11.0546 0480 \Device\Harddisk0\DR0\Partition1 - ok
20:05:11.0546 0480 ============================================================
20:05:11.0546 0480 Scan finished
20:05:11.0546 0480 ============================================================
20:05:11.0546 2584 Detected object count: 2
20:05:11.0546 2584 Actual detected object count: 2
20:11:53.0109 2584 C:\WINDOWS\system32\Drivers\sptd.sys - copied to quarantine
20:11:53.0406 2584 sptd ( LockedFile.Multi.Generic ) - User select action: Quarantine
20:11:53.0468 2584 \Device\Harddisk0\DR0\# - copied to quarantine
20:11:53.0468 2584 \Device\Harddisk0\DR0 - copied to quarantine
20:11:53.0468 2584 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Quarantine

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:49 AM

Posted 15 April 2012 - 06:45 PM

waiting for other logs :thumbsup:

#5 desjakey

desjakey
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:49 AM

Posted 05 July 2012 - 02:32 PM

Apologies for the delay..... it worked ....thank you so much, amazing service

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:49 AM

Posted 05 July 2012 - 02:57 PM

:thumbup2:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users