Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Happili redirect virus


  • This topic is locked This topic is locked
4 replies to this topic

#1 MarkPeter

MarkPeter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 30 April 2012 - 03:17 AM

I am getting redirects from Google searches. It is intermittent. Often the redirect goes to Happili.com, but there are other redirected sites as well. I'm running Norton Internet Security 2012, and did a full system scan, but it didn't find anything. I must confess that prior to reading your warnings here, I tried running ComboFix on my own, and also tried TDSSKiller. Neither of those resolved anything. Now that I understand your process here, I will refrain from running anything without your instructions if I can get someone here to help me.

I have a Toshiba Satellite laptop running Win7 64-bit. I have seen the redirects occur on IE8, Chrome and Firefox.

Thanks in advance for any assistance you can provide.

Mark

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:08:23 AM

Posted 30 April 2012 - 04:25 AM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)


Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

#3 MarkPeter

MarkPeter
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:23 AM

Posted 30 April 2012 - 06:47 AM

Thank you so much for your assistance. The logs are pasted below. aswMBR did find an infection, and it has a "FixMBR" button available, but I didn't execute that. Let me know if I should.

TDSSKiller Log:

04:33:51.0327 3344 TDSS rootkit removing tool 2.7.33.0 Apr 24 2012 18:43:43
04:33:51.0859 3344 ============================================================
04:33:51.0859 3344 Current date / time: 2012/04/30 04:33:51.0859
04:33:51.0859 3344 SystemInfo:
04:33:51.0859 3344
04:33:51.0859 3344 OS Version: 6.1.7601 ServicePack: 1.0
04:33:51.0859 3344 Product type: Workstation
04:33:51.0859 3344 ComputerName: BRAHMS
04:33:51.0860 3344 UserName: Mark
04:33:51.0860 3344 Windows directory: C:\windows
04:33:51.0860 3344 System windows directory: C:\windows
04:33:51.0860 3344 Running under WOW64
04:33:51.0860 3344 Processor architecture: Intel x64
04:33:51.0860 3344 Number of processors: 8
04:33:51.0860 3344 Page size: 0x1000
04:33:51.0860 3344 Boot type: Normal boot
04:33:51.0860 3344 ============================================================
04:33:52.0867 3344 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
04:33:52.0874 3344 Drive \Device\Harddisk1\DR1 - Size: 0x1D1C0F00000 (1863.01 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
04:34:04.0208 3344 ============================================================
04:34:04.0208 3344 \Device\Harddisk0\DR0:
04:34:04.0237 3344 MBR partitions:
04:34:04.0237 3344 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x389E6000
04:34:04.0237 3344 \Device\Harddisk1\DR1:
04:34:04.0237 3344 MBR partitions:
04:34:04.0237 3344 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07000
04:34:04.0237 3344 ============================================================
04:34:04.0282 3344 C: <-> \Device\Harddisk0\DR0\Partition0
04:34:04.0310 3344 E: <-> \Device\Harddisk1\DR1\Partition0
04:34:04.0310 3344 ============================================================
04:34:04.0310 3344 Initialize success
04:34:04.0310 3344 ============================================================
04:34:35.0745 6824 ============================================================
04:34:35.0745 6824 Scan started
04:34:35.0745 6824 Mode: Manual; TDLFS;
04:34:35.0745 6824 ============================================================
04:34:37.0206 6824 1394ohci (a87d604aea360176311474c87a63bb88) C:\windows\system32\drivers\1394ohci.sys
04:34:37.0221 6824 1394ohci - ok
04:34:37.0260 6824 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\windows\system32\drivers\ACPI.sys
04:34:37.0275 6824 ACPI - ok
04:34:37.0318 6824 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\windows\system32\drivers\acpipmi.sys
04:34:37.0320 6824 AcpiPmi - ok
04:34:37.0439 6824 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
04:34:37.0442 6824 AdobeARMservice - ok
04:34:37.0587 6824 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
04:34:37.0589 6824 AdobeFlashPlayerUpdateSvc - ok
04:34:37.0645 6824 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
04:34:37.0659 6824 adp94xx - ok
04:34:37.0693 6824 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
04:34:37.0703 6824 adpahci - ok
04:34:37.0724 6824 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
04:34:37.0738 6824 adpu320 - ok
04:34:37.0767 6824 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\windows\System32\aelupsvc.dll
04:34:37.0771 6824 AeLookupSvc - ok
04:34:37.0837 6824 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\windows\system32\drivers\afd.sys
04:34:37.0851 6824 AFD - ok
04:34:37.0907 6824 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\drivers\agp440.sys
04:34:37.0922 6824 agp440 - ok
04:34:37.0946 6824 ALG (3290d6946b5e30e70414990574883ddb) C:\windows\System32\alg.exe
04:34:37.0949 6824 ALG - ok
04:34:37.0976 6824 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\drivers\aliide.sys
04:34:37.0979 6824 aliide - ok
04:34:37.0992 6824 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\drivers\amdide.sys
04:34:37.0995 6824 amdide - ok
04:34:38.0025 6824 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
04:34:38.0028 6824 AmdK8 - ok
04:34:38.0039 6824 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
04:34:38.0042 6824 AmdPPM - ok
04:34:38.0067 6824 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\windows\system32\drivers\amdsata.sys
04:34:38.0070 6824 amdsata - ok
04:34:38.0092 6824 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
04:34:38.0102 6824 amdsbs - ok
04:34:38.0118 6824 amdxata (540daf1cea6094886d72126fd7c33048) C:\windows\system32\drivers\amdxata.sys
04:34:38.0121 6824 amdxata - ok
04:34:38.0139 6824 andnetadb (ac00b4a1faf27cc2ff99d0961fc9b77c) C:\windows\system32\Drivers\lgandnetadb.sys
04:34:38.0141 6824 andnetadb - ok
04:34:38.0205 6824 AppID (89a69c3f2f319b43379399547526d952) C:\windows\system32\drivers\appid.sys
04:34:38.0207 6824 AppID - ok
04:34:38.0221 6824 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\windows\System32\appidsvc.dll
04:34:38.0224 6824 AppIDSvc - ok
04:34:38.0269 6824 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\windows\System32\appinfo.dll
04:34:38.0271 6824 Appinfo - ok
04:34:38.0381 6824 Application Updater (f81aa50926463340975c22203df936e0) C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
04:34:38.0405 6824 Application Updater - ok
04:34:38.0452 6824 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\windows\System32\appmgmts.dll
04:34:38.0463 6824 AppMgmt - ok
04:34:38.0497 6824 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
04:34:38.0500 6824 arc - ok
04:34:38.0513 6824 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
04:34:38.0516 6824 arcsas - ok
04:34:38.0540 6824 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
04:34:38.0544 6824 AsyncMac - ok
04:34:38.0606 6824 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\drivers\atapi.sys
04:34:38.0608 6824 atapi - ok
04:34:38.0720 6824 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
04:34:38.0751 6824 AudioEndpointBuilder - ok
04:34:38.0756 6824 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\windows\System32\Audiosrv.dll
04:34:38.0759 6824 AudioSrv - ok
04:34:38.0840 6824 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\windows\System32\AxInstSV.dll
04:34:38.0844 6824 AxInstSV - ok
04:34:38.0890 6824 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
04:34:38.0904 6824 b06bdrv - ok
04:34:38.0936 6824 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
04:34:38.0949 6824 b57nd60a - ok
04:34:38.0980 6824 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\windows\System32\bdesvc.dll
04:34:38.0983 6824 BDESVC - ok
04:34:38.0994 6824 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
04:34:38.0996 6824 Beep - ok
04:34:39.0102 6824 BFE (82974d6a2fd19445cc5171fc378668a4) C:\windows\System32\bfe.dll
04:34:39.0129 6824 BFE - ok
04:34:39.0513 6824 BHDrvx64 (5b1fe9d351c284701c8051da2aa81df6) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.6.2.10\Definitions\BASHDefs\20120413.001\BHDrvx64.sys
04:34:39.0557 6824 BHDrvx64 - ok
04:34:39.0729 6824 BITS (1ea7969e3271cbc59e1730697dc74682) C:\windows\System32\qmgr.dll
04:34:39.0762 6824 BITS - ok
04:34:39.0814 6824 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
04:34:39.0816 6824 blbdrive - ok
04:34:39.0874 6824 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\windows\system32\DRIVERS\bowser.sys
04:34:39.0878 6824 bowser - ok
04:34:39.0903 6824 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
04:34:39.0905 6824 BrFiltLo - ok
04:34:39.0915 6824 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
04:34:39.0917 6824 BrFiltUp - ok
04:34:39.0962 6824 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\windows\system32\DRIVERS\bridge.sys
04:34:39.0965 6824 BridgeMP - ok
04:34:40.0017 6824 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\windows\System32\browser.dll
04:34:40.0021 6824 Browser - ok
04:34:40.0051 6824 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
04:34:40.0065 6824 Brserid - ok
04:34:40.0085 6824 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
04:34:40.0088 6824 BrSerWdm - ok
04:34:40.0106 6824 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
04:34:40.0108 6824 BrUsbMdm - ok
04:34:40.0126 6824 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
04:34:40.0129 6824 BrUsbSer - ok
04:34:40.0145 6824 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
04:34:40.0148 6824 BTHMODEM - ok
04:34:40.0187 6824 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\windows\system32\bthserv.dll
04:34:40.0190 6824 bthserv - ok
04:34:40.0346 6824 ccSet_NIS (0e1737a63aec0f6de231bb59836c0a11) C:\windows\system32\drivers\NISx64\1307000.009\ccSetx64.sys
04:34:40.0362 6824 ccSet_NIS - ok
04:34:40.0375 6824 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
04:34:40.0378 6824 cdfs - ok
04:34:40.0708 6824 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\windows\system32\drivers\cdrom.sys
04:34:40.0858 6824 cdrom - ok
04:34:40.0932 6824 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
04:34:40.0944 6824 CertPropSvc - ok
04:34:40.0961 6824 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
04:34:40.0964 6824 circlass - ok
04:34:41.0001 6824 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
04:34:41.0017 6824 CLFS - ok
04:34:41.0084 6824 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
04:34:41.0098 6824 clr_optimization_v2.0.50727_32 - ok
04:34:41.0139 6824 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
04:34:41.0155 6824 clr_optimization_v2.0.50727_64 - ok
04:34:41.0234 6824 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
04:34:41.0244 6824 clr_optimization_v4.0.30319_32 - ok
04:34:41.0273 6824 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
04:34:41.0284 6824 clr_optimization_v4.0.30319_64 - ok
04:34:41.0301 6824 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
04:34:41.0303 6824 CmBatt - ok
04:34:41.0348 6824 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\drivers\cmdide.sys
04:34:41.0351 6824 cmdide - ok
04:34:41.0422 6824 CNG (c4943b6c962e4b82197542447ad599f4) C:\windows\system32\Drivers\cng.sys
04:34:41.0436 6824 CNG - ok
04:34:41.0513 6824 CnxtHdAudService (a7d943bcfb70f1f053c274b348267b55) C:\windows\system32\drivers\CHDRT64.sys
04:34:41.0541 6824 CnxtHdAudService - ok
04:34:41.0567 6824 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
04:34:41.0569 6824 Compbatt - ok
04:34:41.0661 6824 CompositeBus (03edb043586cceba243d689bdda370a8) C:\windows\system32\drivers\CompositeBus.sys
04:34:41.0664 6824 CompositeBus - ok
04:34:41.0688 6824 COMSysApp - ok
04:34:41.0761 6824 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
04:34:41.0763 6824 crcdisk - ok
04:34:42.0112 6824 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\windows\system32\cryptsvc.dll
04:34:42.0138 6824 CryptSvc - ok
04:34:42.0280 6824 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\windows\system32\drivers\csc.sys
04:34:42.0301 6824 CSC - ok
04:34:42.0349 6824 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\windows\System32\cscsvc.dll
04:34:42.0372 6824 CscService - ok
04:34:42.0417 6824 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
04:34:42.0454 6824 DcomLaunch - ok
04:34:42.0488 6824 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\windows\System32\defragsvc.dll
04:34:42.0499 6824 defragsvc - ok
04:34:42.0561 6824 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\windows\system32\Drivers\dfsc.sys
04:34:42.0564 6824 DfsC - ok
04:34:42.0606 6824 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\windows\system32\dhcpcore.dll
04:34:42.0618 6824 Dhcp - ok
04:34:42.0644 6824 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
04:34:42.0645 6824 discache - ok
04:34:42.0678 6824 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
04:34:42.0680 6824 Disk - ok
04:34:42.0735 6824 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\windows\System32\dnsrslvr.dll
04:34:42.0745 6824 Dnscache - ok
04:34:42.0807 6824 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\windows\System32\dot3svc.dll
04:34:42.0821 6824 dot3svc - ok
04:34:42.0845 6824 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\windows\system32\dps.dll
04:34:42.0854 6824 DPS - ok
04:34:42.0871 6824 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
04:34:42.0873 6824 drmkaud - ok
04:34:42.0948 6824 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\windows\System32\drivers\dxgkrnl.sys
04:34:42.0978 6824 DXGKrnl - ok
04:34:43.0005 6824 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\windows\System32\eapsvc.dll
04:34:43.0008 6824 EapHost - ok
04:34:43.0205 6824 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
04:34:43.0276 6824 ebdrv - ok
04:34:43.0372 6824 eeCtrl (0c3f9eff8ddd9f9eb56d754b4620155f) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
04:34:43.0402 6824 eeCtrl - ok
04:34:43.0541 6824 EFS (c118a82cd78818c29ab228366ebf81c3) C:\windows\System32\lsass.exe
04:34:43.0544 6824 EFS - ok
04:34:43.0660 6824 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\windows\ehome\ehRecvr.exe
04:34:43.0690 6824 ehRecvr - ok
04:34:43.0714 6824 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\windows\ehome\ehsched.exe
04:34:43.0718 6824 ehSched - ok
04:34:43.0796 6824 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
04:34:43.0830 6824 elxstor - ok
04:34:43.0924 6824 EraserUtilDrv11122 (8c0f9b877bc0b7ffd327ef55f9efb642) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11122.sys
04:34:43.0941 6824 EraserUtilDrv11122 - ok
04:34:44.0026 6824 EraserUtilRebootDrv (8c0f9b877bc0b7ffd327ef55f9efb642) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
04:34:44.0040 6824 EraserUtilRebootDrv - ok
04:34:44.0103 6824 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\drivers\errdev.sys
04:34:44.0106 6824 ErrDev - ok
04:34:44.0187 6824 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\windows\system32\es.dll
04:34:44.0198 6824 EventSystem - ok
04:34:44.0225 6824 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
04:34:44.0240 6824 exfat - ok
04:34:44.0269 6824 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
04:34:44.0284 6824 fastfat - ok
04:34:44.0378 6824 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\windows\system32\fxssvc.exe
04:34:44.0408 6824 Fax - ok
04:34:44.0435 6824 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
04:34:44.0438 6824 fdc - ok
04:34:44.0455 6824 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\windows\system32\fdPHost.dll
04:34:44.0457 6824 fdPHost - ok
04:34:44.0474 6824 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\windows\system32\fdrespub.dll
04:34:44.0476 6824 FDResPub - ok
04:34:44.0487 6824 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
04:34:44.0490 6824 FileInfo - ok
04:34:44.0504 6824 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
04:34:44.0506 6824 Filetrace - ok
04:34:44.0522 6824 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
04:34:44.0524 6824 flpydisk - ok
04:34:44.0550 6824 FltMgr (da6b67270fd9db3697b20fce94950741) C:\windows\system32\drivers\fltmgr.sys
04:34:44.0564 6824 FltMgr - ok
04:34:44.0669 6824 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\windows\system32\FntCache.dll
04:34:44.0705 6824 FontCache - ok
04:34:44.0787 6824 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
04:34:44.0790 6824 FontCache3.0.0.0 - ok
04:34:44.0825 6824 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
04:34:44.0827 6824 FsDepends - ok
04:34:44.0851 6824 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\windows\system32\drivers\Fs_Rec.sys
04:34:44.0853 6824 Fs_Rec - ok
04:34:44.0908 6824 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\windows\system32\DRIVERS\fvevol.sys
04:34:44.0923 6824 fvevol - ok
04:34:44.0942 6824 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
04:34:44.0945 6824 gagp30kx - ok
04:34:45.0038 6824 GameConsoleService (ce16683cfd11fe70bde435dda5ea1fca) C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
04:34:45.0053 6824 GameConsoleService - ok
04:34:45.0140 6824 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\windows\System32\gpsvc.dll
04:34:45.0165 6824 gpsvc - ok
04:34:45.0232 6824 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
04:34:45.0233 6824 gupdate - ok
04:34:45.0259 6824 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
04:34:45.0261 6824 gupdatem - ok
04:34:45.0651 6824 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
04:34:45.0661 6824 gusvc - ok
04:34:45.0699 6824 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
04:34:45.0702 6824 hcw85cir - ok
04:34:45.0753 6824 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\windows\system32\drivers\HdAudio.sys
04:34:45.0764 6824 HdAudAddService - ok
04:34:45.0820 6824 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\windows\system32\drivers\HDAudBus.sys
04:34:45.0823 6824 HDAudBus - ok
04:34:45.0856 6824 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\windows\system32\DRIVERS\HECIx64.sys
04:34:45.0858 6824 HECIx64 - ok
04:34:45.0871 6824 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
04:34:45.0873 6824 HidBatt - ok
04:34:45.0892 6824 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
04:34:45.0895 6824 HidBth - ok
04:34:45.0920 6824 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
04:34:45.0922 6824 HidIr - ok
04:34:45.0940 6824 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\windows\System32\hidserv.dll
04:34:45.0943 6824 hidserv - ok
04:34:45.0970 6824 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\windows\system32\DRIVERS\hidusb.sys
04:34:45.0974 6824 HidUsb - ok
04:34:46.0025 6824 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\windows\system32\kmsvc.dll
04:34:46.0029 6824 hkmsvc - ok
04:34:46.0093 6824 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\windows\system32\ListSvc.dll
04:34:46.0098 6824 HomeGroupListener - ok
04:34:46.0151 6824 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\windows\system32\provsvc.dll
04:34:46.0167 6824 HomeGroupProvider - ok
04:34:46.0190 6824 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\windows\system32\drivers\HpSAMD.sys
04:34:46.0193 6824 HpSAMD - ok
04:34:46.0256 6824 HTCAND64 (f47cec45fb85791d4ab237563ad0fa8f) C:\windows\system32\Drivers\ANDROIDUSB.sys
04:34:46.0259 6824 HTCAND64 - ok
04:34:46.0341 6824 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\windows\system32\drivers\HTTP.sys
04:34:46.0369 6824 HTTP - ok
04:34:46.0416 6824 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\windows\system32\drivers\hwpolicy.sys
04:34:46.0416 6824 hwpolicy - ok
04:34:46.0446 6824 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\drivers\i8042prt.sys
04:34:46.0450 6824 i8042prt - ok
04:34:46.0500 6824 iaStor (5e60dd5f090ab4a563c7204c289c4650) C:\windows\system32\DRIVERS\iaStor.sys
04:34:46.0503 6824 iaStor - ok
04:34:46.0551 6824 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\windows\system32\drivers\iaStorV.sys
04:34:46.0567 6824 iaStorV - ok
04:34:46.0627 6824 IDMWFP (2a63036283b36b3b68cdc6f85a7d53ed) C:\windows\system32\DRIVERS\idmwfp.sys
04:34:46.0638 6824 IDMWFP - ok
04:34:46.0714 6824 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
04:34:46.0718 6824 IDriverT - ok
04:34:46.0845 6824 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
04:34:46.0881 6824 idsvc - ok
04:34:47.0177 6824 IDSVia64 (18c40c3f368323b203ace403cb430db1) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.6.2.10\Definitions\IPSDefs\20120427.001\IDSvia64.sys
04:34:47.0196 6824 IDSVia64 - ok
04:34:47.0309 6824 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
04:34:47.0312 6824 iirsp - ok
04:34:47.0406 6824 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\windows\System32\ikeext.dll
04:34:47.0436 6824 IKEEXT - ok
04:34:47.0488 6824 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\drivers\intelide.sys
04:34:47.0492 6824 intelide - ok
04:34:47.0512 6824 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
04:34:47.0514 6824 intelppm - ok
04:34:47.0537 6824 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\windows\system32\ipbusenum.dll
04:34:47.0572 6824 IPBusEnum - ok
04:34:47.0631 6824 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\windows\system32\DRIVERS\ipfltdrv.sys
04:34:47.0635 6824 IpFilterDriver - ok
04:34:47.0725 6824 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\windows\System32\iphlpsvc.dll
04:34:47.0753 6824 iphlpsvc - ok
04:34:47.0806 6824 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\windows\system32\drivers\IPMIDrv.sys
04:34:47.0809 6824 IPMIDRV - ok
04:34:47.0827 6824 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
04:34:47.0830 6824 IPNAT - ok
04:34:47.0856 6824 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
04:34:47.0873 6824 IRENUM - ok
04:34:47.0892 6824 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\drivers\isapnp.sys
04:34:47.0895 6824 isapnp - ok
04:34:47.0921 6824 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\windows\system32\drivers\msiscsi.sys
04:34:47.0934 6824 iScsiPrt - ok
04:34:48.0003 6824 IviRegMgr (f415a88162d23977b5edae4f0410e903) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
04:34:48.0005 6824 IviRegMgr - ok
04:34:48.0064 6824 ivusb (2f9f76349bb8c578873a58c840ba0589) C:\windows\system32\DRIVERS\ivusb.sys
04:34:48.0066 6824 ivusb - ok
04:34:48.0094 6824 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\drivers\kbdclass.sys
04:34:48.0097 6824 kbdclass - ok
04:34:48.0152 6824 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\windows\system32\drivers\kbdhid.sys
04:34:48.0155 6824 kbdhid - ok
04:34:48.0203 6824 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
04:34:48.0204 6824 KeyIso - ok
04:34:48.0227 6824 KMService - ok
04:34:48.0243 6824 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\windows\system32\Drivers\ksecdd.sys
04:34:48.0247 6824 KSecDD - ok
04:34:48.0266 6824 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\windows\system32\Drivers\ksecpkg.sys
04:34:48.0276 6824 KSecPkg - ok
04:34:48.0305 6824 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
04:34:48.0307 6824 ksthunk - ok
04:34:48.0356 6824 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\windows\system32\msdtckrm.dll
04:34:48.0372 6824 KtmRm - ok
04:34:48.0400 6824 L1C (ff60e112fc03f6d0eb74b3bfd7d6b7c9) C:\windows\system32\DRIVERS\L1C62x64.sys
04:34:48.0403 6824 L1C - ok
04:34:48.0465 6824 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\windows\System32\srvsvc.dll
04:34:48.0480 6824 LanmanServer - ok
04:34:48.0535 6824 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\windows\System32\wkssvc.dll
04:34:48.0540 6824 LanmanWorkstation - ok
04:34:48.0568 6824 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
04:34:48.0571 6824 lltdio - ok
04:34:48.0613 6824 lltdsvc (c1185803384ab3feed115f79f109427f) C:\windows\System32\lltdsvc.dll
04:34:48.0648 6824 lltdsvc - ok
04:34:48.0678 6824 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\windows\System32\lmhsvc.dll
04:34:48.0680 6824 lmhosts - ok
04:34:48.0765 6824 LMS (dbc1136a62bd4decc3632df650284c2e) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
04:34:48.0780 6824 LMS - ok
04:34:48.0808 6824 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
04:34:48.0811 6824 LSI_FC - ok
04:34:48.0837 6824 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
04:34:48.0840 6824 LSI_SAS - ok
04:34:48.0854 6824 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
04:34:48.0856 6824 LSI_SAS2 - ok
04:34:48.0876 6824 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
04:34:48.0879 6824 LSI_SCSI - ok
04:34:48.0897 6824 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
04:34:48.0901 6824 luafv - ok
04:34:48.0951 6824 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\windows\system32\Mcx2Svc.dll
04:34:48.0955 6824 Mcx2Svc - ok
04:34:48.0973 6824 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
04:34:48.0976 6824 megasas - ok
04:34:49.0006 6824 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
04:34:49.0019 6824 MegaSR - ok
04:34:49.0129 6824 Microsoft SharePoint Workspace Audit Service - ok
04:34:49.0180 6824 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
04:34:49.0183 6824 MMCSS - ok
04:34:49.0192 6824 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
04:34:49.0195 6824 Modem - ok
04:34:49.0216 6824 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
04:34:49.0217 6824 monitor - ok
04:34:49.0235 6824 MotDev - ok
04:34:49.0292 6824 motmodem (060f0ef84f430802df3788f3dcfd009c) C:\windows\system32\DRIVERS\motmodem.sys
04:34:49.0294 6824 motmodem - ok
04:34:49.0417 6824 MotoHelper (3bbc6c2402242401f791548aaebf3d39) C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe
04:34:49.0426 6824 MotoHelper - ok
04:34:49.0475 6824 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
04:34:49.0478 6824 mouclass - ok
04:34:49.0500 6824 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
04:34:49.0502 6824 mouhid - ok
04:34:49.0557 6824 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\windows\system32\drivers\mountmgr.sys
04:34:49.0560 6824 mountmgr - ok
04:34:49.0672 6824 mozybackup (82a4b602578dedf49343efa622afbb61) C:\Program Files\MozyHome\mozybackup.exe
04:34:49.0674 6824 mozybackup - ok
04:34:49.0748 6824 mozyFilter (e7b36791858fa16d1d90e095898724e1) C:\windows\system32\DRIVERS\mozy.sys
04:34:49.0752 6824 mozyFilter - ok
04:34:49.0801 6824 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\windows\system32\drivers\mpio.sys
04:34:49.0812 6824 mpio - ok
04:34:49.0828 6824 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
04:34:49.0831 6824 mpsdrv - ok
04:34:49.0887 6824 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\windows\system32\drivers\mrxdav.sys
04:34:49.0898 6824 MRxDAV - ok
04:34:49.0957 6824 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\windows\system32\DRIVERS\mrxsmb.sys
04:34:49.0966 6824 mrxsmb - ok
04:34:50.0010 6824 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\windows\system32\DRIVERS\mrxsmb10.sys
04:34:50.0022 6824 mrxsmb10 - ok
04:34:50.0064 6824 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\windows\system32\DRIVERS\mrxsmb20.sys
04:34:50.0067 6824 mrxsmb20 - ok
04:34:50.0110 6824 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\windows\system32\drivers\msahci.sys
04:34:50.0113 6824 msahci - ok
04:34:50.0168 6824 msdsm (db801a638d011b9633829eb6f663c900) C:\windows\system32\drivers\msdsm.sys
04:34:50.0172 6824 msdsm - ok
04:34:50.0199 6824 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\windows\System32\msdtc.exe
04:34:50.0204 6824 MSDTC - ok
04:34:50.0246 6824 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
04:34:50.0248 6824 Msfs - ok
04:34:50.0271 6824 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
04:34:50.0273 6824 mshidkmdf - ok
04:34:50.0286 6824 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\drivers\msisadrv.sys
04:34:50.0289 6824 msisadrv - ok
04:34:50.0321 6824 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\windows\system32\iscsiexe.dll
04:34:50.0349 6824 MSiSCSI - ok
04:34:50.0352 6824 msiserver - ok
04:34:50.0368 6824 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
04:34:50.0371 6824 MSKSSRV - ok
04:34:50.0380 6824 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
04:34:50.0382 6824 MSPCLOCK - ok
04:34:50.0397 6824 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
04:34:50.0399 6824 MSPQM - ok
04:34:50.0470 6824 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\windows\system32\drivers\MsRPC.sys
04:34:50.0486 6824 MsRPC - ok
04:34:50.0499 6824 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\drivers\mssmbios.sys
04:34:50.0500 6824 mssmbios - ok
04:34:50.0579 6824 MSSQL$SQLEXPRESS - ok
04:34:50.0599 6824 MSSQLServerADHelper (adaf062116b4e6d96e44d26486a87af6) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe
04:34:50.0612 6824 MSSQLServerADHelper - ok
04:34:50.0630 6824 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
04:34:50.0632 6824 MSTEE - ok
04:34:51.0583 6824 msvsmon80 (95dc808a9a177f575de9fd49f7d97312) C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x64\msvsmon.exe
04:34:51.0705 6824 msvsmon80 - ok
04:34:51.0875 6824 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
04:34:51.0877 6824 MTConfig - ok
04:34:51.0906 6824 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
04:34:51.0915 6824 Mup - ok
04:34:51.0988 6824 MySQL - ok
04:34:52.0058 6824 napagent (582ac6d9873e31dfa28a4547270862dd) C:\windows\system32\qagentRT.dll
04:34:52.0080 6824 napagent - ok
04:34:52.0127 6824 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
04:34:52.0137 6824 NativeWifiP - ok
04:34:52.0340 6824 NAVENG (2dbe90210de76be6e1653bb20ec70ec2) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.6.2.10\Definitions\VirusDefs\20120429.009\ENG64.SYS
04:34:52.0343 6824 NAVENG - ok
04:34:52.0470 6824 NAVEX15 (346da70e203b8e2c850277713de8f71b) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.6.2.10\Definitions\VirusDefs\20120429.009\EX64.SYS
04:34:52.0527 6824 NAVEX15 - ok
04:34:52.0741 6824 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\windows\system32\drivers\ndis.sys
04:34:52.0771 6824 NDIS - ok
04:34:52.0799 6824 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
04:34:52.0801 6824 NdisCap - ok
04:34:52.0822 6824 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
04:34:52.0825 6824 NdisTapi - ok
04:34:52.0879 6824 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\windows\system32\DRIVERS\ndisuio.sys
04:34:52.0896 6824 Ndisuio - ok
04:34:52.0949 6824 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\windows\system32\DRIVERS\ndiswan.sys
04:34:52.0959 6824 NdisWan - ok
04:34:53.0010 6824 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\windows\system32\drivers\NDProxy.sys
04:34:53.0013 6824 NDProxy - ok
04:34:53.0025 6824 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
04:34:53.0028 6824 NetBIOS - ok
04:34:53.0051 6824 NetBT (09594d1089c523423b32a4229263f068) C:\windows\system32\DRIVERS\netbt.sys
04:34:53.0065 6824 NetBT - ok
04:34:53.0113 6824 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
04:34:53.0114 6824 Netlogon - ok
04:34:53.0171 6824 Netman (847d3ae376c0817161a14a82c8922a9e) C:\windows\System32\netman.dll
04:34:53.0189 6824 Netman - ok
04:34:53.0229 6824 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\windows\System32\netprofm.dll
04:34:53.0259 6824 netprofm - ok
04:34:53.0322 6824 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
04:34:53.0325 6824 NetTcpPortSharing - ok
04:34:53.0355 6824 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
04:34:53.0357 6824 nfrd960 - ok
04:34:53.0573 6824 NIS (c6948f034d7edabcfa2234d399fc78bc) C:\Program Files (x86)\Norton Internet Security\Engine\19.7.0.9\ccSvcHst.exe
04:34:53.0582 6824 NIS - ok
04:34:53.0651 6824 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\windows\System32\nlasvc.dll
04:34:53.0666 6824 NlaSvc - ok
04:34:53.0708 6824 Norton PC Checkup Application Launcher - ok
04:34:53.0719 6824 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
04:34:53.0722 6824 Npfs - ok
04:34:53.0745 6824 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\windows\system32\nsisvc.dll
04:34:53.0748 6824 nsi - ok
04:34:53.0770 6824 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
04:34:53.0770 6824 nsiproxy - ok
04:34:53.0908 6824 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\windows\system32\drivers\Ntfs.sys
04:34:53.0947 6824 Ntfs - ok
04:34:54.0048 6824 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
04:34:54.0050 6824 Null - ok
04:34:54.0095 6824 NVHDA (a842341ef3c702ef8208e610be0fd1d9) C:\windows\system32\drivers\nvhda64v.sys
04:34:54.0098 6824 NVHDA - ok
04:34:54.0797 6824 nvlddmkm (6850d89c7abdd8b4fb0b3659da961379) C:\windows\system32\DRIVERS\nvlddmkm.sys
04:34:54.0993 6824 nvlddmkm - ok
04:34:55.0166 6824 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\windows\system32\drivers\nvraid.sys
04:34:55.0170 6824 nvraid - ok
04:34:55.0202 6824 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\windows\system32\drivers\nvstor.sys
04:34:55.0213 6824 nvstor - ok
04:34:55.0232 6824 nvsvc (2cbaf74c49c472160ebd73adab8dab50) C:\windows\system32\nvvsvc.exe
04:34:55.0236 6824 nvsvc - ok
04:34:55.0294 6824 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\drivers\nv_agp.sys
04:34:55.0304 6824 nv_agp - ok
04:34:55.0331 6824 O2FLASH (d955d5de998db2476bf0892be3a96c26) C:\windows\system32\DRIVERS\o2flash.exe
04:34:55.0333 6824 O2FLASH - ok
04:34:55.0360 6824 O2MDGRDR (3840f61d55dbf32f4b88fa15fb03c461) C:\windows\system32\DRIVERS\o2mdgx64.sys
04:34:55.0362 6824 O2MDGRDR - ok
04:34:55.0378 6824 O2SDGRDR (fa1eed3a10992eba9a39172b50346434) C:\windows\system32\DRIVERS\o2sdgx64.sys
04:34:55.0381 6824 O2SDGRDR - ok
04:34:55.0401 6824 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\drivers\ohci1394.sys
04:34:55.0403 6824 ohci1394 - ok
04:34:55.0497 6824 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
04:34:55.0533 6824 ose64 - ok
04:34:55.0894 6824 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
04:34:55.0970 6824 osppsvc - ok
04:34:56.0082 6824 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
04:34:56.0094 6824 p2pimsvc - ok
04:34:56.0141 6824 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\windows\system32\p2psvc.dll
04:34:56.0156 6824 p2psvc - ok
04:34:56.0195 6824 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
04:34:56.0198 6824 Parport - ok
04:34:56.0246 6824 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\windows\system32\drivers\partmgr.sys
04:34:56.0250 6824 partmgr - ok
04:34:56.0268 6824 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\windows\System32\pcasvc.dll
04:34:56.0282 6824 PcaSvc - ok
04:34:56.0360 6824 PCCUJobMgr (2f86be1818c2d7ac90478e3323ee7fcb) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.3.198\ccSvcHst.exe
04:34:56.0369 6824 PCCUJobMgr - ok
04:34:56.0429 6824 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\windows\system32\drivers\pci.sys
04:34:56.0438 6824 pci - ok
04:34:56.0459 6824 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\drivers\pciide.sys
04:34:56.0461 6824 pciide - ok
04:34:56.0487 6824 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
04:34:56.0501 6824 pcmcia - ok
04:34:56.0521 6824 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
04:34:56.0523 6824 pcw - ok
04:34:56.0567 6824 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
04:34:56.0600 6824 PEAUTH - ok
04:34:56.0695 6824 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\windows\system32\peerdistsvc.dll
04:34:56.0722 6824 PeerDistSvc - ok
04:34:56.0791 6824 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\windows\SysWow64\perfhost.exe
04:34:56.0793 6824 PerfHost - ok
04:34:56.0887 6824 PGEffect (663962900e7fea522126ba287715bb4a) C:\windows\system32\DRIVERS\pgeffect.sys
04:34:56.0889 6824 PGEffect - ok
04:34:57.0007 6824 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\windows\system32\pla.dll
04:34:57.0053 6824 pla - ok
04:34:57.0122 6824 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\windows\system32\umpnpmgr.dll
04:34:57.0137 6824 PlugPlay - ok
04:34:57.0161 6824 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\windows\system32\pnrpauto.dll
04:34:57.0164 6824 PNRPAutoReg - ok
04:34:57.0187 6824 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\windows\system32\pnrpsvc.dll
04:34:57.0191 6824 PNRPsvc - ok
04:34:57.0223 6824 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\windows\System32\ipsecsvc.dll
04:34:57.0240 6824 PolicyAgent - ok
04:34:57.0274 6824 Power (6ba9d927dded70bd1a9caded45f8b184) C:\windows\system32\umpo.dll
04:34:57.0286 6824 Power - ok
04:34:57.0370 6824 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\windows\system32\DRIVERS\raspptp.sys
04:34:57.0374 6824 PptpMiniport - ok
04:34:57.0398 6824 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
04:34:57.0400 6824 Processor - ok
04:34:57.0432 6824 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\windows\system32\profsvc.dll
04:34:57.0447 6824 ProfSvc - ok
04:34:57.0493 6824 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
04:34:57.0494 6824 ProtectedStorage - ok
04:34:57.0552 6824 Psched (0557cf5a2556bd58e26384169d72438d) C:\windows\system32\DRIVERS\pacer.sys
04:34:57.0554 6824 Psched - ok
04:34:57.0620 6824 PSI_SVC_2 (f036cfb275d0c55f4e45fbbf5f98b3c8) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
04:34:57.0632 6824 PSI_SVC_2 - ok
04:34:57.0674 6824 QIOMem (c8fcb4899f8b70cc34e0d9876a80963c) C:\windows\system32\DRIVERS\QIOMem.sys
04:34:57.0676 6824 QIOMem - ok
04:34:57.0782 6824 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
04:34:57.0830 6824 ql2300 - ok
04:34:57.0965 6824 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
04:34:57.0968 6824 ql40xx - ok
04:34:57.0999 6824 QWAVE (906191634e99aea92c4816150bda3732) C:\windows\system32\qwave.dll
04:34:58.0031 6824 QWAVE - ok
04:34:58.0040 6824 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
04:34:58.0041 6824 QWAVEdrv - ok
04:34:58.0052 6824 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
04:34:58.0055 6824 RasAcd - ok
04:34:58.0084 6824 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
04:34:58.0086 6824 RasAgileVpn - ok
04:34:58.0100 6824 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\windows\System32\rasauto.dll
04:34:58.0103 6824 RasAuto - ok
04:34:58.0159 6824 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\windows\system32\DRIVERS\rasl2tp.sys
04:34:58.0162 6824 Rasl2tp - ok
04:34:58.0197 6824 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\windows\System32\rasmans.dll
04:34:58.0234 6824 RasMan - ok
04:34:58.0253 6824 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
04:34:58.0256 6824 RasPppoe - ok
04:34:58.0271 6824 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
04:34:58.0273 6824 RasSstp - ok
04:34:58.0301 6824 rdbss (77f665941019a1594d887a74f301fa2f) C:\windows\system32\DRIVERS\rdbss.sys
04:34:58.0311 6824 rdbss - ok
04:34:58.0326 6824 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
04:34:58.0328 6824 rdpbus - ok
04:34:58.0353 6824 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
04:34:58.0353 6824 RDPCDD - ok
04:34:58.0409 6824 RDPDR (1b6163c503398b23ff8b939c67747683) C:\windows\system32\drivers\rdpdr.sys
04:34:58.0419 6824 RDPDR - ok
04:34:58.0434 6824 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
04:34:58.0435 6824 RDPENCDD - ok
04:34:58.0452 6824 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
04:34:58.0452 6824 RDPREFMP - ok
04:34:58.0507 6824 RDPWD (6d76e6433574b058adcb0c50df834492) C:\windows\system32\drivers\RDPWD.sys
04:34:58.0521 6824 RDPWD - ok
04:34:58.0576 6824 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\windows\system32\drivers\rdyboost.sys
04:34:58.0590 6824 rdyboost - ok
04:34:58.0609 6824 regi (4d9afddda0efe97cdbfd3b5fa48b05f6) C:\windows\system32\drivers\regi.sys
04:34:58.0611 6824 regi - ok
04:34:58.0651 6824 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\windows\System32\mprdim.dll
04:34:58.0654 6824 RemoteAccess - ok
04:34:58.0671 6824 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\windows\system32\regsvc.dll
04:34:58.0683 6824 RemoteRegistry - ok
04:34:58.0746 6824 RimUsb (71b48ddaf5e9c2b40e64de5c405f5aac) C:\windows\system32\Drivers\RimUsb_AMD64.sys
04:34:58.0781 6824 RimUsb - ok
04:34:58.0817 6824 RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\windows\system32\DRIVERS\RimSerial_AMD64.sys
04:34:58.0820 6824 RimVSerPort - ok
04:34:58.0848 6824 ROOTMODEM (388d3dd1a6457280f3badba9f3acd6b1) C:\windows\system32\Drivers\RootMdm.sys
04:34:58.0850 6824 ROOTMODEM - ok
04:34:58.0878 6824 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\windows\System32\RpcEpMap.dll
04:34:58.0881 6824 RpcEptMapper - ok
04:34:58.0909 6824 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\windows\system32\locator.exe
04:34:58.0912 6824 RpcLocator - ok
04:34:58.0983 6824 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\windows\system32\rpcss.dll
04:34:58.0988 6824 RpcSs - ok
04:34:59.0018 6824 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
04:34:59.0022 6824 rspndr - ok
04:34:59.0115 6824 rtl8192se (7475548b0ba58eba4d12414fc9e9dfe6) C:\windows\system32\DRIVERS\rtl8192se.sys
04:34:59.0146 6824 rtl8192se - ok
04:34:59.0194 6824 s3cap (e60c0a09f997826c7627b244195ab581) C:\windows\system32\drivers\vms3cap.sys
04:34:59.0197 6824 s3cap - ok
04:34:59.0243 6824 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
04:34:59.0244 6824 SamSs - ok
04:34:59.0266 6824 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\windows\system32\drivers\sbp2port.sys
04:34:59.0269 6824 sbp2port - ok
04:34:59.0292 6824 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\windows\System32\SCardSvr.dll
04:34:59.0324 6824 SCardSvr - ok
04:34:59.0366 6824 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\windows\system32\DRIVERS\scfilter.sys
04:34:59.0368 6824 scfilter - ok
04:34:59.0439 6824 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\windows\system32\schedsvc.dll
04:34:59.0476 6824 Schedule - ok
04:34:59.0530 6824 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\windows\System32\certprop.dll
04:34:59.0531 6824 SCPolicySvc - ok
04:34:59.0586 6824 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\windows\system32\DRIVERS\sdbus.sys
04:34:59.0590 6824 sdbus - ok
04:34:59.0646 6824 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\windows\System32\SDRSVC.dll
04:34:59.0656 6824 SDRSVC - ok
04:34:59.0682 6824 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
04:34:59.0701 6824 secdrv - ok
04:34:59.0708 6824 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\windows\system32\seclogon.dll
04:34:59.0710 6824 seclogon - ok
04:34:59.0743 6824 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\windows\System32\sens.dll
04:34:59.0746 6824 SENS - ok
04:34:59.0769 6824 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\windows\system32\sensrsvc.dll
04:34:59.0773 6824 SensrSvc - ok
04:34:59.0798 6824 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
04:34:59.0801 6824 Serenum - ok
04:34:59.0819 6824 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
04:34:59.0822 6824 Serial - ok
04:34:59.0839 6824 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
04:34:59.0841 6824 sermouse - ok
04:34:59.0901 6824 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\windows\system32\sessenv.dll
04:34:59.0912 6824 SessionEnv - ok
04:34:59.0925 6824 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\drivers\sffdisk.sys
04:34:59.0927 6824 sffdisk - ok
04:34:59.0937 6824 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\drivers\sffp_mmc.sys
04:34:59.0939 6824 sffp_mmc - ok
04:34:59.0944 6824 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\windows\system32\drivers\sffp_sd.sys
04:34:59.0945 6824 sffp_sd - ok
04:34:59.0962 6824 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
04:34:59.0965 6824 sfloppy - ok
04:35:00.0023 6824 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\windows\System32\ipnathlp.dll
04:35:00.0038 6824 SharedAccess - ok
04:35:00.0107 6824 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\windows\System32\shsvcs.dll
04:35:00.0127 6824 ShellHWDetection - ok
04:35:00.0147 6824 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
04:35:00.0149 6824 SiSRaid2 - ok
04:35:00.0168 6824 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
04:35:00.0171 6824 SiSRaid4 - ok
04:35:00.0207 6824 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
04:35:00.0234 6824 Smb - ok
04:35:00.0256 6824 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\windows\System32\snmptrap.exe
04:35:00.0259 6824 SNMPTRAP - ok
04:35:00.0268 6824 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
04:35:00.0270 6824 spldr - ok
04:35:00.0348 6824 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\windows\System32\spoolsv.exe
04:35:00.0375 6824 Spooler - ok
04:35:00.0612 6824 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\windows\system32\sppsvc.exe
04:35:00.0683 6824 sppsvc - ok
04:35:00.0776 6824 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\windows\system32\sppuinotify.dll
04:35:00.0793 6824 sppuinotify - ok
04:35:00.0925 6824 SQLBrowser (3612108d36ea74f6f9fc5005e88e353b) c:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
04:35:00.0940 6824 SQLBrowser - ok
04:35:01.0118 6824 SQLWriter (27a547b061c44d72afa6c1e71665d4a5) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
04:35:01.0133 6824 SQLWriter - ok
04:35:01.0333 6824 SRTSP (4d56f175f76c685a06471800a03219b2) C:\windows\System32\Drivers\NISx64\1306020.00A\SRTSP64.SYS
04:35:01.0366 6824 SRTSP - ok
04:35:01.0470 6824 SRTSPX (fbb8945a61e55a2345d12487c74a9d76) C:\windows\system32\drivers\NISx64\1307000.009\SRTSPX64.SYS
04:35:01.0480 6824 SRTSPX - ok
04:35:01.0552 6824 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\windows\system32\DRIVERS\srv.sys
04:35:01.0580 6824 srv - ok
04:35:01.0652 6824 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\windows\system32\DRIVERS\srv2.sys
04:35:01.0666 6824 srv2 - ok
04:35:01.0683 6824 srvnet (27e461f0be5bff5fc737328f749538c3) C:\windows\system32\DRIVERS\srvnet.sys
04:35:01.0695 6824 srvnet - ok
04:35:01.0730 6824 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\windows\System32\ssdpsrv.dll
04:35:01.0745 6824 SSDPSRV - ok
04:35:01.0760 6824 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\windows\system32\sstpsvc.dll
04:35:01.0764 6824 SstpSvc - ok
04:35:01.0790 6824 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
04:35:01.0793 6824 stexstor - ok
04:35:01.0879 6824 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\windows\System32\wiaservc.dll
04:35:01.0907 6824 stisvc - ok
04:35:01.0952 6824 storflt (7785dc213270d2fc066538daf94087e7) C:\windows\system32\drivers\vmstorfl.sys
04:35:01.0955 6824 storflt - ok
04:35:01.0974 6824 StorSvc (c40841817ef57d491f22eb103da587cc) C:\windows\system32\storsvc.dll
04:35:01.0990 6824 StorSvc - ok
04:35:02.0007 6824 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\windows\system32\drivers\storvsc.sys
04:35:02.0009 6824 storvsc - ok
04:35:02.0027 6824 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\drivers\swenum.sys
04:35:02.0030 6824 swenum - ok
04:35:02.0191 6824 SwitchBoard (f577910a133a592234ebaad3f3afa258) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
04:35:02.0219 6824 SwitchBoard - ok
04:35:02.0265 6824 swprv (e08e46fdd841b7184194011ca1955a0b) C:\windows\System32\swprv.dll
04:35:02.0294 6824 swprv - ok
04:35:02.0435 6824 SymDS (8b2430762099598da40686f754632efd) C:\windows\system32\drivers\NISx64\1307000.009\SYMDS64.SYS
04:35:02.0465 6824 SymDS - ok
04:35:02.0576 6824 SymEFA (f90c7a190399165d3ab2245048d34786) C:\windows\system32\drivers\NISx64\1307000.009\SYMEFA64.SYS
04:35:02.0628 6824 SymEFA - ok
04:35:02.0667 6824 SymEvent (898bb48c797483420df523b2bbc1ecdb) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
04:35:02.0679 6824 SymEvent - ok
04:35:02.0735 6824 SymIRON (5013a76caaa1d7cf1c55214b490b4e35) C:\windows\system32\drivers\NISx64\1307000.009\Ironx64.SYS
04:35:02.0748 6824 SymIRON - ok
04:35:02.0881 6824 SymNetS (3911bd0e68c010e5438a87706abbe9ab) C:\windows\System32\Drivers\NISx64\1306020.00A\SYMNETS.SYS
04:35:02.0894 6824 SymNetS - ok
04:35:02.0958 6824 SynTP (56f16a398affe40afab04ba0081cdc27) C:\windows\system32\DRIVERS\SynTP.sys
04:35:02.0970 6824 SynTP - ok
04:35:03.0108 6824 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\windows\system32\sysmain.dll
04:35:03.0148 6824 SysMain - ok
04:35:03.0274 6824 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\windows\System32\TabSvc.dll
04:35:03.0279 6824 TabletInputService - ok
04:35:03.0346 6824 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\windows\System32\tapisrv.dll
04:35:03.0362 6824 TapiSrv - ok
04:35:03.0389 6824 TBS (1be03ac720f4d302ea01d40f588162f6) C:\windows\System32\tbssvc.dll
04:35:03.0393 6824 TBS - ok
04:35:03.0566 6824 Tcpip (fc62769e7bff2896035aeed399108162) C:\windows\system32\drivers\tcpip.sys
04:35:03.0620 6824 Tcpip - ok
04:35:03.0928 6824 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\windows\system32\DRIVERS\tcpip.sys
04:35:03.0939 6824 TCPIP6 - ok
04:35:04.0075 6824 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\windows\system32\drivers\tcpipreg.sys
04:35:04.0078 6824 tcpipreg - ok
04:35:04.0103 6824 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\windows\system32\DRIVERS\tdcmdpst.sys
04:35:04.0106 6824 tdcmdpst - ok
04:35:04.0125 6824 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
04:35:04.0127 6824 TDPIPE - ok
04:35:04.0173 6824 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\windows\system32\drivers\tdtcp.sys
04:35:04.0176 6824 TDTCP - ok
04:35:04.0240 6824 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\windows\system32\DRIVERS\tdx.sys
04:35:04.0250 6824 tdx - ok
04:35:04.0302 6824 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\windows\system32\drivers\termdd.sys
04:35:04.0305 6824 TermDD - ok
04:35:04.0348 6824 TermService (2e648163254233755035b46dd7b89123) C:\windows\System32\termsrv.dll
04:35:04.0380 6824 TermService - ok
04:35:04.0405 6824 Themes (f0344071948d1a1fa732231785a0664c) C:\windows\system32\themeservice.dll
04:35:04.0409 6824 Themes - ok
04:35:04.0442 6824 Thpdrv (c013f6acaa9761f571bd28dada7c157d) C:\windows\system32\DRIVERS\thpdrv.sys
04:35:04.0445 6824 Thpdrv - ok
04:35:04.0455 6824 Thpevm (b4e609047434ed948af7bdef2fa66e38) C:\windows\system32\DRIVERS\Thpevm.SYS
04:35:04.0457 6824 Thpevm - ok
04:35:04.0495 6824 Thpsrv (f6927bba3b09aff26a53a9191f7378f9) C:\windows\system32\ThpSrv.exe
04:35:04.0530 6824 Thpsrv - ok
04:35:04.0554 6824 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\windows\system32\mmcss.dll
04:35:04.0555 6824 THREADORDER - ok
04:35:04.0611 6824 TMachInfo (f120967184a27e927052e8ddbb727851) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
04:35:04.0613 6824 TMachInfo - ok
04:35:04.0645 6824 TODDSrv (ed32035bdfeced1ad66d459fd9cc1140) C:\Windows\system32\TODDSrv.exe
04:35:04.0649 6824 TODDSrv - ok
04:35:04.0744 6824 TosCoSrv (98c864481d62f86ec8af65be3419a95b) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
04:35:04.0774 6824 TosCoSrv - ok
04:35:04.0817 6824 TOSHIBA Bluetooth Service (8f099be5db17d025e19652851399b9f1) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
04:35:04.0851 6824 TOSHIBA Bluetooth Service - ok
04:35:04.0950 6824 TOSHIBA eco Utility Service (152da63a2843e7e63eca8ae90d853763) C:\Program Files\TOSHIBA\TECO\TecoService.exe
04:35:04.0962 6824 TOSHIBA eco Utility Service - ok
04:35:05.0008 6824 TOSHIBA HDD SSD Alert Service (74c2fa8c3765ee71a9c22182ec108457) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
04:35:05.0011 6824 TOSHIBA HDD SSD Alert Service - ok
04:35:05.0125 6824 Tosrfcom - ok
04:35:05.0149 6824 tosrfec (f5e3ac4cbcd154ee80849b21887fd0b0) C:\windows\system32\DRIVERS\tosrfec.sys
04:35:05.0152 6824 tosrfec - ok
04:35:05.0190 6824 Tosrfusb (8197b0eae0d804ac3466045ddc5da98b) C:\windows\system32\DRIVERS\tosrfusb.sys
04:35:05.0193 6824 Tosrfusb - ok
04:35:05.0237 6824 tos_sps64 (09ff7b0b1b5c3d225495cb6f5a9b39f8) C:\windows\system32\DRIVERS\tos_sps64.sys
04:35:05.0259 6824 tos_sps64 - ok
04:35:05.0328 6824 TPCHSrv (6f9e17819bfa53cff67cb1e16669500f) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
04:35:05.0356 6824 TPCHSrv - ok
04:35:05.0428 6824 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\windows\System32\trkwks.dll
04:35:05.0432 6824 TrkWks - ok
04:35:05.0508 6824 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\windows\servicing\TrustedInstaller.exe
04:35:05.0510 6824 TrustedInstaller - ok
04:35:05.0576 6824 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\windows\system32\DRIVERS\tssecsrv.sys
04:35:05.0578 6824 tssecsrv - ok
04:35:05.0638 6824 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\windows\system32\drivers\tsusbflt.sys
04:35:05.0641 6824 TsUsbFlt - ok
04:35:05.0710 6824 tunnel (3566a8daafa27af944f5d705eaa64894) C:\windows\system32\DRIVERS\tunnel.sys
04:35:05.0714 6824 tunnel - ok
04:35:05.0743 6824 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\windows\system32\DRIVERS\TVALZ_O.SYS
04:35:05.0747 6824 TVALZ - ok
04:35:05.0769 6824 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\windows\system32\DRIVERS\TVALZFL.sys
04:35:05.0773 6824 TVALZFL - ok
04:35:05.0802 6824 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
04:35:05.0805 6824 uagp35 - ok
04:35:05.0835 6824 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\windows\system32\DRIVERS\udfs.sys
04:35:05.0847 6824 udfs - ok
04:35:05.0876 6824 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\windows\system32\UI0Detect.exe
04:35:05.0879 6824 UI0Detect - ok
04:35:05.0919 6824 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\drivers\uliagpkx.sys
04:35:05.0921 6824 uliagpkx - ok
04:35:05.0977 6824 umbus (dc54a574663a895c8763af0fa1ff7561) C:\windows\system32\drivers\umbus.sys
04:35:05.0979 6824 umbus - ok
04:35:05.0995 6824 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
04:35:05.0998 6824 UmPass - ok
04:35:06.0058 6824 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\windows\System32\umrdp.dll
04:35:06.0071 6824 UmRdpService - ok
04:35:06.0253 6824 UNS (7466809e6da561d60c2f1ce8ede3c73f) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
04:35:06.0307 6824 UNS - ok
04:35:06.0423 6824 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\windows\System32\upnphost.dll
04:35:06.0437 6824 upnphost - ok
04:35:06.0526 6824 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\windows\system32\drivers\usbaudio.sys
04:35:06.0529 6824 usbaudio - ok
04:35:06.0559 6824 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\windows\system32\DRIVERS\usbccgp.sys
04:35:06.0562 6824 usbccgp - ok
04:35:06.0625 6824 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\drivers\usbcir.sys
04:35:06.0628 6824 usbcir - ok
04:35:06.0645 6824 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\windows\system32\drivers\usbehci.sys
04:35:06.0648 6824 usbehci - ok
04:35:06.0696 6824 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\windows\system32\DRIVERS\usbhub.sys
04:35:06.0711 6824 usbhub - ok
04:35:06.0735 6824 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\windows\system32\drivers\usbohci.sys
04:35:06.0738 6824 usbohci - ok
04:35:06.0765 6824 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
04:35:06.0767 6824 usbprint - ok
04:35:06.0829 6824 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\windows\system32\DRIVERS\usbscan.sys
04:35:06.0843 6824 usbscan - ok
04:35:06.0869 6824 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\windows\system32\DRIVERS\USBSTOR.SYS
04:35:06.0884 6824 USBSTOR - ok
04:35:06.0900 6824 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\windows\system32\drivers\usbuhci.sys
04:35:06.0903 6824 usbuhci - ok
04:35:06.0932 6824 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\windows\System32\Drivers\usbvideo.sys
04:35:06.0947 6824 usbvideo - ok
04:35:06.0969 6824 usb_rndisx (70d05ee263568a742d14e1876df80532) C:\windows\system32\DRIVERS\usb8023x.sys
04:35:06.0971 6824 usb_rndisx - ok
04:35:07.0001 6824 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\windows\System32\uxsms.dll
04:35:07.0005 6824 UxSms - ok
04:35:07.0056 6824 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\windows\system32\lsass.exe
04:35:07.0058 6824 VaultSvc - ok
04:35:07.0104 6824 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\windows\system32\DRIVERS\VClone.sys
04:35:07.0107 6824 VClone - ok
04:35:07.0129 6824 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\drivers\vdrvroot.sys
04:35:07.0132 6824 vdrvroot - ok
04:35:07.0202 6824 vds (8d6b481601d01a456e75c3210f1830be) C:\windows\System32\vds.exe
04:35:07.0229 6824 vds - ok
04:35:07.0247 6824 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
04:35:07.0249 6824 vga - ok
04:35:07.0274 6824 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
04:35:07.0277 6824 VgaSave - ok
04:35:07.0302 6824 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\windows\system32\drivers\vhdmp.sys
04:35:07.0318 6824 vhdmp - ok
04:35:07.0332 6824 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\drivers\viaide.sys
04:35:07.0335 6824 viaide - ok
04:35:07.0356 6824 vmbus (86ea3e79ae350fea5331a1303054005f) C:\windows\system32\drivers\vmbus.sys
04:35:07.0365 6824 vmbus - ok
04:35:07.0378 6824 VMBusHID (7de90b48f210d29649380545db45a187) C:\windows\system32\drivers\VMBusHID.sys
04:35:07.0380 6824 VMBusHID - ok
04:35:07.0397 6824 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\windows\system32\drivers\volmgr.sys
04:35:07.0400 6824 volmgr - ok
04:35:07.0464 6824 volmgrx (a255814907c89be58b79ef2f189b843b) C:\windows\system32\drivers\volmgrx.sys
04:35:07.0474 6824 volmgrx - ok
04:35:07.0503 6824 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\windows\system32\drivers\volsnap.sys
04:35:07.0517 6824 volsnap - ok
04:35:07.0555 6824 vpcbus (b4a73ca4ef9a02b9738cea9ad5fe5917) C:\windows\system32\DRIVERS\vpchbus.sys
04:35:07.0569 6824 vpcbus - ok
04:35:07.0617 6824 vpcnfltr (e675fb2b48c54f09895482e2253b289c) C:\windows\system32\DRIVERS\vpcnfltr.sys
04:35:07.0619 6824 vpcnfltr - ok
04:35:07.0637 6824 vpcusb (5fb42082b0d19a0268705f1dd343df20) C:\windows\system32\DRIVERS\vpcusb.sys
04:35:07.0640 6824 vpcusb - ok
04:35:07.0703 6824 vpcvmm (207b6539799cc1c112661a9b620dd233) C:\windows\system32\drivers\vpcvmm.sys
04:35:07.0714 6824 vpcvmm - ok
04:35:07.0760 6824 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
04:35:07.0794 6824 vsmraid - ok
04:35:07.0896 6824 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\windows\system32\vssvc.exe
04:35:07.0939 6824 VSS - ok
04:35:08.0060 6824 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
04:35:08.0062 6824 vwifibus - ok
04:35:08.0082 6824 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
04:35:08.0085 6824 vwififlt - ok
04:35:08.0125 6824 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\windows\system32\w32time.dll
04:35:08.0141 6824 W32Time - ok
04:35:08.0159 6824 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
04:35:08.0161 6824 WacomPen - ok
04:35:08.0233 6824 WANARP (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
04:35:08.0270 6824 WANARP - ok
04:35:08.0274 6824 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\windows\system32\DRIVERS\wanarp.sys
04:35:08.0275 6824 Wanarpv6 - ok
04:35:08.0372 6824 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\windows\system32\Wat\WatAdminSvc.exe
04:35:08.0451 6824 WatAdminSvc - ok
04:35:08.0573 6824 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\windows\system32\wbengine.exe
04:35:08.0605 6824 wbengine - ok
04:35:08.0691 6824 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\windows\System32\wbiosrvc.dll
04:35:08.0706 6824 WbioSrvc - ok
04:35:08.0788 6824 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\windows\System32\wcncsvc.dll
04:35:08.0799 6824 wcncsvc - ok
04:35:08.0822 6824 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\windows\System32\WcsPlugInService.dll
04:35:08.0825 6824 WcsPlugInService - ok
04:35:08.0855 6824 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
04:35:08.0857 6824 Wd - ok
04:35:08.0906 6824 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
04:35:08.0928 6824 Wdf01000 - ok
04:35:08.0942 6824 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
04:35:08.0946 6824 WdiServiceHost - ok
04:35:08.0950 6824 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\windows\system32\wdi.dll
04:35:08.0952 6824 WdiSystemHost - ok
04:35:09.0010 6824 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\windows\System32\webclnt.dll
04:35:09.0025 6824 WebClient - ok
04:35:09.0058 6824 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\windows\system32\wecsvc.dll
04:35:09.0074 6824 Wecsvc - ok
04:35:09.0095 6824 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\windows\System32\wercplsupport.dll
04:35:09.0099 6824 wercplsupport - ok
04:35:09.0124 6824 WerSvc (6d137963730144698cbd10f202e9f251) C:\windows\System32\WerSvc.dll
04:35:09.0128 6824 WerSvc - ok
04:35:09.0156 6824 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
04:35:09.0158 6824 WfpLwf - ok
04:35:09.0174 6824 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
04:35:09.0176 6824 WIMMount - ok
04:35:09.0237 6824 WinDefend - ok
04:35:09.0242 6824 WinHttpAutoProxySvc - ok
04:35:09.0293 6824 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\windows\system32\wbem\WMIsvc.dll
04:35:09.0307 6824 Winmgmt - ok
04:35:09.0469 6824 WinRM (bcb1310604aa415c4508708975b3931e) C:\windows\system32\WsmSvc.dll
04:35:09.0519 6824 WinRM - ok
04:35:09.0700 6824 WinUsb (fe88b288356e7b47b74b13372add906d) C:\windows\system32\DRIVERS\WinUsb.sys
04:35:09.0703 6824 WinUsb - ok
04:35:09.0760 6824 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\windows\System32\wlansvc.dll
04:35:09.0789 6824 Wlansvc - ok
04:35:09.0837 6824 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\drivers\wmiacpi.sys
04:35:09.0837 6824 WmiAcpi - ok
04:35:09.0884 6824 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\windows\system32\wbem\WmiApSrv.exe
04:35:09.0918 6824 wmiApSrv - ok
04:35:09.0960 6824 WMPNetworkSvc - ok
04:35:09.0984 6824 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\windows\System32\wpcsvc.dll
04:35:09.0988 6824 WPCSvc - ok
04:35:10.0035 6824 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\windows\system32\wpdbusenum.dll
04:35:10.0037 6824 WPDBusEnum - ok
04:35:10.0065 6824 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
04:35:10.0066 6824 ws2ifsl - ok
04:35:10.0126 6824 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\windows\system32\wscsvc.dll
04:35:10.0129 6824 wscsvc - ok
04:35:10.0133 6824 WSearch - ok
04:35:10.0315 6824 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\windows\system32\wuaueng.dll
04:35:10.0369 6824 wuauserv - ok
04:35:10.0513 6824 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\windows\system32\drivers\WudfPf.sys
04:35:10.0530 6824 WudfPf - ok
04:35:10.0548 6824 WUDFRd (cf8d590be3373029d57af80914190682) C:\windows\system32\DRIVERS\WUDFRd.sys
04:35:10.0557 6824 WUDFRd - ok
04:35:10.0605 6824 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\windows\System32\WUDFSvc.dll
04:35:10.0609 6824 wudfsvc - ok
04:35:10.0647 6824 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\windows\System32\wwansvc.dll
04:35:10.0660 6824 WwanSvc - ok
04:35:10.0822 6824 YahooAUService (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
04:35:10.0846 6824 YahooAUService - ok
04:35:10.0873 6824 MBR (0x1B8) (5b5e648d12fcadc244c1ec30318e1eb9) \Device\Harddisk0\DR0
04:35:11.0227 6824 \Device\Harddisk0\DR0 - ok
04:35:11.0264 6824 Boot (0x1200) (1f668e8841d5466c3d5b09f6912073ab) \Device\Harddisk0\DR0\Partition0
04:35:11.0270 6824 \Device\Harddisk0\DR0\Partition0 - ok
04:35:11.0274 6824 ============================================================
04:35:11.0274 6824 Scan finished
04:35:11.0274 6824 ============================================================
04:35:11.0288 5972 Detected object count: 0
04:35:11.0288 5972 Actual detected object count: 0



aswMBR Log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-04-30 04:37:06
-----------------------------
04:37:06.493 OS Version: Windows x64 6.1.7601 Service Pack 1
04:37:06.493 Number of processors: 8 586 0x1E05
04:37:06.494 ComputerName: BRAHMS UserName: Mark
04:37:08.162 Initialize success
04:37:50.285 AVAST engine defs: 12043000
04:38:04.936 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
04:38:04.939 Disk 0 Vendor: ST950042 0001 Size: 476940MB BusType: 3
04:38:04.976 Disk 0 MBR read successfully
04:38:04.979 Disk 0 MBR scan
04:38:04.985 Disk 0 Windows VISTA default MBR code
04:38:05.004 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
04:38:05.022 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 463820 MB offset 3074048
04:38:05.062 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 11619 MB offset 952977408
04:38:05.149 Disk 0 scanning C:\windows\system32\drivers
04:38:20.368 Service scanning
04:38:51.734 Modules scanning
04:38:51.746 Disk 0 trace - called modules:
04:38:51.778 ntoskrnl.exe CLASSPNP.SYS disk.sys thpdrv.sys iaStor.sys hal.dll
04:38:51.793 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800664d790]
04:38:51.800 3 CLASSPNP.SYS[fffff88001a0143f] -> nt!IofCallDriver -> \Device\THPDRV1[0xfffffa8006647710]
04:38:51.808 5 thpdrv.sys[fffff88001f3ecc0] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80063cf050]
04:38:55.275 AVAST engine scan C:\windows
04:38:58.831 AVAST engine scan C:\windows\system32
04:41:14.413 File: C:\windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
04:42:50.432 AVAST engine scan C:\windows\system32\drivers
04:43:18.993 AVAST engine scan C:\Users\Mark
04:44:26.774 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
04:44:26.784 The log file has been saved successfully to "C:\aswMBR.txt"

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:08:23 AM

Posted 30 April 2012 - 06:50 AM

it has a "FixMBR" button available, but I didn't execute that. Let me know if I should.

Never do that.This is a zero access rootkit.We need more advanced tools

Read the guide here on preparing logs

http://www.bleepingcomputer.com/forums/topic34773.html

and create a topic here

http://www.bleepingcomputer.com/forums/forum22.html

Good luck

#5 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:23 PM

Posted 30 April 2012 - 05:22 PM

New topic here: http://www.bleepingcomputer.com/forums/topic451970.html

I will close this topic to avoid confusion.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users