Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Search Engine Redirect Virus


  • Please log in to reply
4 replies to this topic

#1 unpaidassassin

unpaidassassin

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:02:56 PM

Posted 02 May 2012 - 01:42 AM

Ok I have read many threads here and have searched before .


I initially noticed this problem several months ago, sometime before November. At first it was on Google searches on Chrome browser (Firefox was fine). Also the not all of the user accounts on the computer had this issue, but a few did.

Occasionally I had this problem using Firefox on Google searches (main user account) and most of the time with Google on Chrome. I also tried Bing and Yahoo searches which would also have redirects. One of the other user accounts had this redirect problem quite often on Firefox/Google.

I looked at several "guides" which supposedly helped others. Nothing worked for me. Some stuff I downloaded to "fix" this redirect virus include rkill and tdsskiller (I even changed the file extension .exe).

---
I gave up trying to resolve this until now.

Recently I updated Firefox (had been using an old version). I noticed I was not having redirects on the other user account (Firefox/Google). Unfortunately my main uer account on Firefox and google searches has this redirect issue nearly everytime now.


I use to be able to "get around" the redirects by constantly clicking the link (from search result) or refreshing before the page/redirect loads.

Now this 'trick' doesn't work. Also when I check the url for the search results, the actual url is not shown but some junk after google. This would show before but I would sometimes fresh the google search and the urls would appear fine, indicating that clicking a link would go to the result and NOT redirect.

Edited by unpaidassassin, 02 May 2012 - 01:50 AM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:56 PM

Posted 02 May 2012 - 02:45 AM

Download

FIXTDSS

Launch it ,It may ask for restart,reboot the PC

On reboot ,click on REPAIR


Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Please download GMER from here(doesnot work on 64 bit OS)

http://www2.gmer.net/download.php

Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.

GMER will open to the Rootkit/Malware tab and perform an automatic Full Scan when first run. (do not use the computer while the scan is in progress)

If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
Now click the Scan button. If you see a rootkit warning window, click OK.
When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
Click the Copy button and paste the results into your next reply.

#3 unpaidassassin

unpaidassassin
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:02:56 PM

Posted 11 May 2012 - 07:04 PM

The redirects from search results "stopped" for several days, but then came back.


Earlier today, I ran FIXTDSS and TDSSkiller (tried in the past) - didn't use GMER (have Vista 64 bit on this computer).

FIXTDSS did not open after I restarted. I run it again but it is the same message to click Proceed to restart.

TDSSkiller removed some items and then restarted computer. I ran it again and no infected items showed up.


The redirects still occur.

#4 unpaidassassin

unpaidassassin
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Local time:02:56 PM

Posted 11 May 2012 - 07:22 PM

Here's the TDSSkiller log


19:45:51.0030 2932 TDSS rootkit removing tool 2.7.34.0 May 2 2012 09:59:18
19:45:51.0342 2932 ============================================================
19:45:51.0342 2932 Current date / time: 2012/05/11 19:45:51.0342
19:45:51.0342 2932 SystemInfo:
19:45:51.0342 2932
19:45:51.0342 2932 OS Version: 6.0.6001 ServicePack: 1.0
19:45:51.0342 2932 Product type: Workstation
19:45:51.0342 2932 ComputerName: @#%^&^%-PC
19:45:51.0342 2932 UserName: $%^Y&UIO
19:45:51.0342 2932 Windows directory: C:\Windows
19:45:51.0342 2932 System windows directory: C:\Windows
19:45:51.0342 2932 Running under WOW64
19:45:51.0342 2932 Processor architecture: Intel x64
19:45:51.0342 2932 Number of processors: 2
19:45:51.0342 2932 Page size: 0x1000
19:45:51.0342 2932 Boot type: Normal boot
19:45:51.0342 2932 ============================================================
19:45:51.0920 2932 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:45:51.0935 2932 ============================================================
19:45:51.0935 2932 \Device\Harddisk0\DR0:
19:45:51.0935 2932 MBR partitions:
19:45:51.0935 2932 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1F9F3D1
19:45:51.0935 2932 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1F9F410, BlocksNum 0x1B225171
19:45:51.0935 2932 ============================================================
19:45:51.0966 2932 C: <-> \Device\Harddisk0\DR0\Partition1
19:45:51.0998 2932 D: <-> \Device\Harddisk0\DR0\Partition0
19:45:51.0998 2932 ============================================================
19:45:51.0998 2932 Initialize success
19:45:51.0998 2932 ============================================================
19:46:02.0684 2580 ============================================================
19:46:02.0684 2580 Scan started
19:46:02.0684 2580 Mode: Manual; TDLFS;
19:46:02.0684 2580 ============================================================
19:46:03.0261 2580 !SASCORE (7d9d615201a483d6fa99491c2e655a5a) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
19:46:03.0276 2580 !SASCORE - ok
19:46:03.0542 2580 ACPI (8c99ed256a889d647935a97c543b7b85) C:\Windows\system32\drivers\acpi.sys
19:46:03.0542 2580 ACPI - ok
19:46:03.0635 2580 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:46:03.0635 2580 AdobeARMservice - ok
19:46:04.0150 2580 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:46:04.0197 2580 AdobeFlashPlayerUpdateSvc - ok
19:46:04.0275 2580 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
19:46:04.0306 2580 adp94xx - ok
19:46:04.0368 2580 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
19:46:04.0400 2580 adpahci - ok
19:46:04.0415 2580 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
19:46:04.0431 2580 adpu160m - ok
19:46:04.0462 2580 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
19:46:04.0478 2580 adpu320 - ok
19:46:04.0509 2580 AeLookupSvc (0f421175574bfe0bf2f4d8e910a253bb) C:\Windows\System32\aelupsvc.dll
19:46:04.0509 2580 AeLookupSvc - ok
19:46:04.0571 2580 AFD (db37041ab857abc7e179e856d8e1582c) C:\Windows\system32\drivers\afd.sys
19:46:04.0602 2580 AFD - ok
19:46:04.0634 2580 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
19:46:04.0649 2580 agp440 - ok
19:46:04.0696 2580 ahcix64s (dada9751964a7d217a762c873c332b0e) C:\Windows\system32\drivers\ahcix64s.sys
19:46:04.0712 2580 ahcix64s - ok
19:46:04.0758 2580 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
19:46:04.0758 2580 aic78xx - ok
19:46:04.0774 2580 ALG (5922f4f59b7868f3d74bbbbeb7b825a3) C:\Windows\System32\alg.exe
19:46:04.0774 2580 ALG - ok
19:46:04.0790 2580 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
19:46:04.0790 2580 aliide - ok
19:46:04.0805 2580 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
19:46:04.0805 2580 amdide - ok
19:46:04.0836 2580 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
19:46:04.0836 2580 AmdK8 - ok
19:46:04.0883 2580 Appinfo (9c37b3fd5615477cb9a0cd116cf43f5c) C:\Windows\System32\appinfo.dll
19:46:04.0899 2580 Appinfo - ok
19:46:04.0930 2580 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
19:46:04.0930 2580 arc - ok
19:46:04.0961 2580 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
19:46:04.0961 2580 arcsas - ok
19:46:05.0008 2580 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
19:46:05.0008 2580 AsyncMac - ok
19:46:05.0024 2580 atapi (1898fae8e07d97f2f6c2d5326c633fac) C:\Windows\system32\drivers\atapi.sys
19:46:05.0024 2580 atapi - ok
19:46:05.0133 2580 Ati External Event Utility (9f9e73327c456f418eb6b0cc98d1e3f4) C:\Windows\system32\Ati2evxx.exe
19:46:05.0148 2580 Ati External Event Utility - ok
19:46:05.0538 2580 atikmdag (2ec33a384281fddfd5954caa327d361b) C:\Windows\system32\DRIVERS\atikmdag.sys
19:46:05.0663 2580 atikmdag - ok
19:46:05.0882 2580 AudioEndpointBuilder (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll
19:46:05.0928 2580 AudioEndpointBuilder - ok
19:46:05.0944 2580 AudioSrv (2a54b6a48ab6d2166271b05e9469326e) C:\Windows\System32\Audiosrv.dll
19:46:05.0944 2580 AudioSrv - ok
19:46:06.0116 2580 BITS (d896a0d43f8ab81ecb1fc6c24decfd58) C:\Windows\System32\qmgr.dll
19:46:06.0194 2580 BITS - ok
19:46:06.0256 2580 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
19:46:06.0256 2580 blbdrive - ok
19:46:06.0287 2580 bowser (8b2b19031d0aeade6e1b933df1acba7e) C:\Windows\system32\DRIVERS\bowser.sys
19:46:06.0303 2580 bowser - ok
19:46:06.0318 2580 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
19:46:06.0318 2580 BrFiltLo - ok
19:46:06.0334 2580 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
19:46:06.0350 2580 BrFiltUp - ok
19:46:06.0381 2580 Browser (a1b39de453433b115b4ea69ee0343816) C:\Windows\System32\browser.dll
19:46:06.0381 2580 Browser - ok
19:46:06.0412 2580 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
19:46:06.0412 2580 Brserid - ok
19:46:06.0428 2580 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
19:46:06.0428 2580 BrSerWdm - ok
19:46:06.0443 2580 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
19:46:06.0443 2580 BrUsbMdm - ok
19:46:06.0459 2580 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
19:46:06.0459 2580 BrUsbSer - ok
19:46:06.0474 2580 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
19:46:06.0474 2580 BTHMODEM - ok
19:46:06.0537 2580 CAXHWAZL (fdb53a8d3bc52dc29884587e768e3388) C:\Windows\system32\DRIVERS\CAXHWAZL.sys
19:46:06.0552 2580 CAXHWAZL - ok
19:46:06.0599 2580 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
19:46:06.0615 2580 cdfs - ok
19:46:06.0646 2580 cdrom (3b2fb35363423ed60c8fbf15fc8680bd) C:\Windows\system32\DRIVERS\cdrom.sys
19:46:06.0646 2580 cdrom - ok
19:46:06.0677 2580 CertPropSvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll
19:46:06.0677 2580 CertPropSvc - ok
19:46:06.0708 2580 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
19:46:06.0708 2580 circlass - ok
19:46:06.0755 2580 CLFS (caeda2572b7042b11062f327f099251d) C:\Windows\system32\CLFS.sys
19:46:06.0755 2580 CLFS - ok
19:46:06.0849 2580 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:46:06.0849 2580 clr_optimization_v2.0.50727_32 - ok
19:46:06.0896 2580 clr_optimization_v2.0.50727_64 (fa58b51ed71c9133e141164eaa7c54eb) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:46:06.0911 2580 clr_optimization_v2.0.50727_64 - ok
19:46:06.0974 2580 CmBatt (b52d9a14ce4101577900a364ba86f3df) C:\Windows\system32\DRIVERS\CmBatt.sys
19:46:06.0974 2580 CmBatt - ok
19:46:07.0036 2580 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
19:46:07.0036 2580 cmdide - ok
19:46:07.0083 2580 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\DRIVERS\compbatt.sys
19:46:07.0083 2580 Compbatt - ok
19:46:07.0083 2580 COMSysApp - ok
19:46:07.0098 2580 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
19:46:07.0098 2580 crcdisk - ok
19:46:07.0161 2580 CryptSvc (4374f784121d8b3bb466b03f5e5ebd33) C:\Windows\system32\cryptsvc.dll
19:46:07.0192 2580 CryptSvc - ok
19:46:07.0332 2580 DcomLaunch (ff27be0ba7b3c48d5c99afcb56d436c2) C:\Windows\system32\rpcss.dll
19:46:07.0364 2580 DcomLaunch - ok
19:46:07.0426 2580 DfsC (bd4acc56e477ad7419cbe90fceeb621b) C:\Windows\system32\Drivers\dfsc.sys
19:46:07.0426 2580 DfsC - ok
19:46:08.0034 2580 DFSR (1781f99840979ee7b126c9073c377fd0) C:\Windows\system32\DFSR.exe
19:46:08.0159 2580 DFSR - ok
19:46:08.0424 2580 Dhcp (fdaa0edfcfb70cd529589ad654651b40) C:\Windows\System32\dhcpcsvc.dll
19:46:08.0456 2580 Dhcp - ok
19:46:08.0549 2580 disk (2dc415fc05fb8a079f896cbbacb19324) C:\Windows\system32\drivers\disk.sys
19:46:08.0549 2580 disk - ok
19:46:08.0580 2580 Dnscache (93ce26dbed3182634f18dd2fe10e41be) C:\Windows\System32\dnsrslvr.dll
19:46:08.0596 2580 Dnscache - ok
19:46:08.0643 2580 dot3svc (cc661867677627f2911c2a4970dee0f1) C:\Windows\System32\dot3svc.dll
19:46:08.0674 2580 dot3svc - ok
19:46:08.0736 2580 Dot4 (74c02b1717740c3b8039539e23e4b53f) C:\Windows\system32\DRIVERS\Dot4.sys
19:46:08.0752 2580 Dot4 - ok
19:46:08.0783 2580 Dot4Print (08321d1860235bf42cf2854234337aea) C:\Windows\system32\DRIVERS\Dot4Prt.sys
19:46:08.0783 2580 Dot4Print - ok
19:46:08.0799 2580 dot4usb (4adccf0124f2b6911d3786a5d0e779e5) C:\Windows\system32\DRIVERS\dot4usb.sys
19:46:08.0799 2580 dot4usb - ok
19:46:08.0861 2580 DPS (1583b39790db3eaec7edb0cb0140c708) C:\Windows\system32\dps.dll
19:46:08.0877 2580 DPS - ok
19:46:08.0924 2580 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
19:46:08.0924 2580 drmkaud - ok
19:46:09.0048 2580 DXGKrnl (645b6c9dad903edde4703cb76929b7dc) C:\Windows\System32\drivers\dxgkrnl.sys
19:46:09.0095 2580 DXGKrnl - ok
19:46:09.0173 2580 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
19:46:09.0189 2580 E1G60 - ok
19:46:09.0236 2580 EapHost (c2303883fd9be49dc36a6400643002ea) C:\Windows\System32\eapsvc.dll
19:46:09.0236 2580 EapHost - ok
19:46:09.0282 2580 Ecache (7343d950a34a95dcb7441642e3e6beef) C:\Windows\system32\drivers\ecache.sys
19:46:09.0282 2580 Ecache - ok
19:46:09.0392 2580 ehRecvr (14ce384d2e27b64c256bda4dc39c312d) C:\Windows\ehome\ehRecvr.exe
19:46:09.0407 2580 ehRecvr - ok
19:46:09.0438 2580 ehSched (b93159c1313d66fdfbbe876f5189cd52) C:\Windows\ehome\ehsched.exe
19:46:09.0454 2580 ehSched - ok
19:46:09.0501 2580 ehstart (f5ee2527d74449868e3c3227a59bcd28) C:\Windows\ehome\ehstart.dll
19:46:09.0501 2580 ehstart - ok
19:46:09.0579 2580 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
19:46:09.0610 2580 elxstor - ok
19:46:09.0704 2580 EMDMgmt (31272dd1f13ee5031af1e3ea054fd92c) C:\Windows\system32\emdmgmt.dll
19:46:09.0719 2580 EMDMgmt - ok
19:46:09.0750 2580 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
19:46:09.0750 2580 ErrDev - ok
19:46:09.0828 2580 EventSystem (d8338e6b3c23ad36096a6fdabd039283) C:\Windows\system32\es.dll
19:46:09.0828 2580 EventSystem - ok
19:46:09.0875 2580 exfat (2a546b9a84658b0554b1ec35cd9adaf5) C:\Windows\system32\drivers\exfat.sys
19:46:09.0906 2580 exfat - ok
19:46:09.0969 2580 fastfat (fe731d345ed9eeabbc72a59b35941834) C:\Windows\system32\drivers\fastfat.sys
19:46:10.0000 2580 fastfat - ok
19:46:10.0047 2580 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
19:46:10.0062 2580 fdc - ok
19:46:10.0078 2580 fdPHost (bb9267acacd8b7533dd936c34a0cba5e) C:\Windows\system32\fdPHost.dll
19:46:10.0094 2580 fdPHost - ok
19:46:10.0109 2580 FDResPub (300c80931eabbe1db7591c516efe8d0f) C:\Windows\system32\fdrespub.dll
19:46:10.0109 2580 FDResPub - ok
19:46:10.0125 2580 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
19:46:10.0125 2580 FileInfo - ok
19:46:10.0172 2580 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
19:46:10.0187 2580 Filetrace - ok
19:46:10.0203 2580 FixTDSS (00940c5e43282206994659d16b4ac412) C:\Windows\system32\drivers\FixTDSS.sys
19:46:10.0203 2580 FixTDSS - ok
19:46:10.0234 2580 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
19:46:10.0234 2580 flpydisk - ok
19:46:10.0281 2580 FltMgr (7dacf1a3a4219575070c6dc7c957428a) C:\Windows\system32\drivers\fltmgr.sys
19:46:10.0281 2580 FltMgr - ok
19:46:10.0437 2580 FontCache3.0.0.0 (73d0f1d32edae3dcc4e84468bf910add) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:46:10.0437 2580 FontCache3.0.0.0 - ok
19:46:10.0468 2580 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
19:46:10.0468 2580 Fs_Rec - ok
19:46:10.0484 2580 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
19:46:10.0499 2580 gagp30kx - ok
19:46:10.0608 2580 gpsvc (9e5b254d58232ec8921ec3c5a94c81ed) C:\Windows\System32\gpsvc.dll
19:46:10.0640 2580 gpsvc - ok
19:46:10.0702 2580 HdAudAddService (df45f8142dc6df9d18c39b3effbd0409) C:\Windows\system32\drivers\HdAudio.sys
19:46:10.0718 2580 HdAudAddService - ok
19:46:10.0796 2580 HDAudBus (0c0d0f8a3ff09ecc81963d09ec6a0a84) C:\Windows\system32\DRIVERS\HDAudBus.sys
19:46:10.0796 2580 HDAudBus - ok
19:46:10.0811 2580 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
19:46:10.0811 2580 HidBth - ok
19:46:10.0827 2580 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
19:46:10.0842 2580 HidIr - ok
19:46:10.0858 2580 hidserv (0aa154538544e988429da2d5aa803a6c) C:\Windows\system32\hidserv.dll
19:46:10.0874 2580 hidserv - ok
19:46:10.0905 2580 HidUsb (128e2da8483fdd4dd0c7b3f9abd6f323) C:\Windows\system32\DRIVERS\hidusb.sys
19:46:10.0905 2580 HidUsb - ok
19:46:10.0920 2580 hkmsvc (b12f367ea39c0795fd57e31242ce1a5a) C:\Windows\system32\kmsvc.dll
19:46:10.0936 2580 hkmsvc - ok
19:46:10.0983 2580 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
19:46:10.0983 2580 HpCISSs - ok
19:46:11.0061 2580 HSFHWAZL (57ba73b5b321291e5114cb21350e1ea0) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
19:46:11.0076 2580 HSFHWAZL - ok
19:46:11.0357 2580 HSF_DPV (e90d0e3d9715f3bec7db2d6321dddee8) C:\Windows\system32\DRIVERS\CAX_DPV.sys
19:46:11.0420 2580 HSF_DPV - ok
19:46:11.0747 2580 HTTP (7c39506bc3be2b77b7671bb320fdb736) C:\Windows\system32\drivers\HTTP.sys
19:46:11.0778 2580 HTTP - ok
19:46:11.0794 2580 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
19:46:11.0794 2580 i2omp - ok
19:46:11.0825 2580 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
19:46:11.0825 2580 i8042prt - ok
19:46:11.0919 2580 IAANTMON (72b53e9c8924949dec8f3799bcba2251) C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaantmon.exe
19:46:11.0934 2580 IAANTMON - ok
19:46:12.0012 2580 iaStor (16a4671255cfb842225f0fdb6dbdb414) C:\Windows\system32\DRIVERS\iaStor.sys
19:46:12.0028 2580 iaStor - ok
19:46:12.0075 2580 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
19:46:12.0106 2580 iaStorV - ok
19:46:12.0356 2580 idsvc (76ea63cdb2d88dae7209691d089bef1d) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:46:12.0434 2580 idsvc - ok
19:46:12.0480 2580 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
19:46:12.0480 2580 iirsp - ok
19:46:12.0574 2580 IKEEXT (3a3b232140c33376e134e7b61a0eaa44) C:\Windows\System32\ikeext.dll
19:46:12.0605 2580 IKEEXT - ok
19:46:12.0652 2580 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
19:46:12.0652 2580 intelide - ok
19:46:12.0683 2580 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
19:46:12.0683 2580 intelppm - ok
19:46:12.0714 2580 IPBusEnum (5624bc1bc5eeb49c0ab76a8114f05ea3) C:\Windows\system32\ipbusenum.dll
19:46:12.0730 2580 IPBusEnum - ok
19:46:12.0777 2580 IpFilterDriver (99b821f5bebd6a3cc3fe564f802ae0fd) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:46:12.0777 2580 IpFilterDriver - ok
19:46:12.0792 2580 IpInIp - ok
19:46:12.0824 2580 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
19:46:12.0824 2580 IPMIDRV - ok
19:46:12.0886 2580 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
19:46:12.0917 2580 IPNAT - ok
19:46:12.0964 2580 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
19:46:12.0964 2580 IRENUM - ok
19:46:12.0995 2580 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
19:46:12.0995 2580 isapnp - ok
19:46:13.0042 2580 iScsiPrt (49e4ccbf74783fce5d2cc1ff6480e1f4) C:\Windows\system32\DRIVERS\msiscsi.sys
19:46:13.0042 2580 iScsiPrt - ok
19:46:13.0089 2580 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
19:46:13.0104 2580 iteatapi - ok
19:46:13.0120 2580 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
19:46:13.0120 2580 iteraid - ok
19:46:13.0151 2580 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
19:46:13.0151 2580 kbdclass - ok
19:46:13.0151 2580 kbdhid (bf8783a5066cfecf45095459e8010fa7) C:\Windows\system32\DRIVERS\kbdhid.sys
19:46:13.0151 2580 kbdhid - ok
19:46:13.0229 2580 KeyIso (1b461e9f6db0ef829b4369f47a24bbec) C:\Windows\system32\lsass.exe
19:46:13.0229 2580 KeyIso - ok
19:46:13.0292 2580 KSecDD (a6f636c447cf3def5f50018f0c0e1aae) C:\Windows\system32\Drivers\ksecdd.sys
19:46:13.0307 2580 KSecDD - ok
19:46:13.0323 2580 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
19:46:13.0323 2580 ksthunk - ok
19:46:13.0401 2580 KtmRm (1faf6926f3416d3da05c5b265491bdae) C:\Windows\system32\msdtckrm.dll
19:46:13.0463 2580 KtmRm - ok
19:46:13.0526 2580 LanmanServer (6f212edd7aae8bd905c9e8824a34f8ae) C:\Windows\system32\srvsvc.dll
19:46:13.0541 2580 LanmanServer - ok
19:46:13.0588 2580 LanmanWorkstation (d81690276c9e06a50d398cd1ae3c89ab) C:\Windows\System32\wkssvc.dll
19:46:13.0604 2580 LanmanWorkstation - ok
19:46:13.0635 2580 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
19:46:13.0635 2580 lltdio - ok
19:46:13.0697 2580 lltdsvc (961ccbd0b1ccb5675d64976fae37d092) C:\Windows\System32\lltdsvc.dll
19:46:13.0744 2580 lltdsvc - ok
19:46:13.0775 2580 lmhosts (a47f8080cacc23c91fe823ad19aa5612) C:\Windows\System32\lmhsvc.dll
19:46:13.0775 2580 lmhosts - ok
19:46:13.0822 2580 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
19:46:13.0822 2580 LSI_FC - ok
19:46:13.0853 2580 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
19:46:13.0869 2580 LSI_SAS - ok
19:46:13.0931 2580 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
19:46:13.0947 2580 LSI_SCSI - ok
19:46:14.0025 2580 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
19:46:14.0056 2580 luafv - ok
19:46:14.0150 2580 Mcx2Svc (76a58df02bd4ea29f189b82d0bef17f8) C:\Windows\system32\Mcx2Svc.dll
19:46:14.0150 2580 Mcx2Svc - ok
19:46:14.0196 2580 mdmxsdk (e4f44ec214b3e381e1fc844a02926666) C:\Windows\system32\DRIVERS\mdmxsdk.sys
19:46:14.0196 2580 mdmxsdk - ok
19:46:14.0228 2580 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
19:46:14.0228 2580 megasas - ok
19:46:14.0290 2580 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
19:46:14.0306 2580 MegaSR - ok
19:46:14.0321 2580 MMCSS (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:46:14.0321 2580 MMCSS - ok
19:46:14.0337 2580 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
19:46:14.0337 2580 Modem - ok
19:46:14.0352 2580 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
19:46:14.0352 2580 monitor - ok
19:46:14.0368 2580 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
19:46:14.0368 2580 mouclass - ok
19:46:14.0384 2580 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
19:46:14.0384 2580 mouhid - ok
19:46:14.0399 2580 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
19:46:14.0399 2580 MountMgr - ok
19:46:14.0462 2580 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
19:46:14.0477 2580 MozillaMaintenance - ok
19:46:14.0524 2580 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
19:46:14.0540 2580 mpio - ok
19:46:14.0555 2580 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
19:46:14.0555 2580 mpsdrv - ok
19:46:14.0618 2580 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
19:46:14.0618 2580 Mraid35x - ok
19:46:14.0649 2580 MRxDAV (fe2706c15f8345c342820e4e4583fea0) C:\Windows\system32\drivers\mrxdav.sys
19:46:14.0649 2580 MRxDAV - ok
19:46:14.0711 2580 mrxsmb (8e01ed1d845b0dac094a9be50d426187) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:46:14.0711 2580 mrxsmb - ok
19:46:14.0742 2580 mrxsmb10 (7aca70376a4eca01a8e02957e55d2710) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:46:14.0758 2580 mrxsmb10 - ok
19:46:14.0789 2580 mrxsmb20 (168da84ebf8afbc6e8f8ee229cc6dc9f) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:46:14.0789 2580 mrxsmb20 - ok
19:46:14.0805 2580 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
19:46:14.0805 2580 msahci - ok
19:46:14.0836 2580 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
19:46:14.0852 2580 msdsm - ok
19:46:14.0898 2580 MSDTC (7ec02ce772f068ed0beafa3da341a9bc) C:\Windows\System32\msdtc.exe
19:46:14.0914 2580 MSDTC - ok
19:46:14.0961 2580 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
19:46:14.0961 2580 Msfs - ok
19:46:14.0976 2580 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
19:46:14.0976 2580 msisadrv - ok
19:46:15.0023 2580 MSiSCSI (366b0c1f4478b519c181e37d43dcda32) C:\Windows\system32\iscsiexe.dll
19:46:15.0039 2580 MSiSCSI - ok
19:46:15.0039 2580 msiserver - ok
19:46:15.0070 2580 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
19:46:15.0070 2580 MSKSSRV - ok
19:46:15.0086 2580 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
19:46:15.0086 2580 MSPCLOCK - ok
19:46:15.0101 2580 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
19:46:15.0117 2580 MSPQM - ok
19:46:15.0164 2580 MsRPC (b8e32e6103fbba9fbb1d0c11ff0d13b5) C:\Windows\system32\drivers\MsRPC.sys
19:46:15.0164 2580 MsRPC - ok
19:46:15.0179 2580 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
19:46:15.0179 2580 mssmbios - ok
19:46:15.0195 2580 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
19:46:15.0195 2580 MSTEE - ok
19:46:15.0210 2580 Mup (ddf133501f68d6988a0f55dfa88637b4) C:\Windows\system32\Drivers\mup.sys
19:46:15.0210 2580 Mup - ok
19:46:15.0273 2580 napagent (c25022cdd18980846973b598900915f8) C:\Windows\system32\qagentRT.dll
19:46:15.0288 2580 napagent - ok
19:46:15.0335 2580 NativeWifiP (7c81124ea83cca576558371c6ac0896d) C:\Windows\system32\DRIVERS\nwifi.sys
19:46:15.0335 2580 NativeWifiP - ok
19:46:15.0413 2580 NDIS (2a2ee457af36c5c9a6808c768bd3a12b) C:\Windows\system32\drivers\ndis.sys
19:46:15.0429 2580 NDIS - ok
19:46:15.0444 2580 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
19:46:15.0460 2580 NdisTapi - ok
19:46:15.0476 2580 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
19:46:15.0476 2580 Ndisuio - ok
19:46:15.0491 2580 NdisWan (52e3e8e35101399be9b2938c992aa087) C:\Windows\system32\DRIVERS\ndiswan.sys
19:46:15.0507 2580 NdisWan - ok
19:46:15.0522 2580 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
19:46:15.0522 2580 NDProxy - ok
19:46:15.0569 2580 Net Driver HPZ12 (458a00528bf213a31f51896ec37b91f4) C:\Windows\system32\HPZinw12.dll
19:46:15.0569 2580 Net Driver HPZ12 - ok
19:46:15.0585 2580 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
19:46:15.0585 2580 NetBIOS - ok
19:46:15.0616 2580 netbt (7a29ca243a629230799754162d80120f) C:\Windows\system32\DRIVERS\netbt.sys
19:46:15.0632 2580 netbt - ok
19:46:15.0663 2580 Netlogon (1b461e9f6db0ef829b4369f47a24bbec) C:\Windows\system32\lsass.exe
19:46:15.0663 2580 Netlogon - ok
19:46:15.0710 2580 Netman (9b63b29defc0f3115a559d2597bf5d75) C:\Windows\System32\netman.dll
19:46:15.0741 2580 Netman - ok
19:46:15.0788 2580 netprofm (7846d0136cc2b264926a73047ba7688a) C:\Windows\System32\netprofm.dll
19:46:15.0803 2580 netprofm - ok
19:46:15.0866 2580 NetTcpPortSharing (b84613b469b98e09f50a748c1d02e132) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:46:15.0866 2580 NetTcpPortSharing - ok
19:46:17.0410 2580 NETw4v64 (520d367b45b12a75022b0070fff2b937) C:\Windows\system32\DRIVERS\NETw4v64.sys
19:46:17.0535 2580 NETw4v64 - ok
19:46:18.0112 2580 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
19:46:18.0112 2580 nfrd960 - ok
19:46:18.0174 2580 NlaSvc (f145bf4c4668e7e312069f81ef847cfc) C:\Windows\System32\nlasvc.dll
19:46:18.0268 2580 NlaSvc - ok
19:46:18.0284 2580 Npfs (b06154e2a2c91e9be5599fca53bc4cd0) C:\Windows\system32\drivers\Npfs.sys
19:46:18.0299 2580 Npfs - ok
19:46:18.0330 2580 nsi (acb62baa1c319b17752553df3026eeeb) C:\Windows\system32\nsisvc.dll
19:46:18.0330 2580 nsi - ok
19:46:18.0346 2580 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
19:46:18.0346 2580 nsiproxy - ok
19:46:18.0752 2580 Ntfs (fe86ba5ac3b50e2ca911e9c60c07b638) C:\Windows\system32\drivers\Ntfs.sys
19:46:18.0845 2580 Ntfs - ok
19:46:19.0188 2580 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
19:46:19.0188 2580 Null - ok
19:46:19.0220 2580 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
19:46:19.0220 2580 nvraid - ok
19:46:19.0313 2580 nvrd64 (9340b273f9d2b4efdb94bdcd89550c1f) C:\Windows\system32\drivers\nvrd64.sys
19:46:19.0313 2580 nvrd64 - ok
19:46:19.0360 2580 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
19:46:19.0360 2580 nvstor - ok
19:46:19.0422 2580 nvstor64 (3e92c341f7a5bb9245dec53ddee61a8d) C:\Windows\system32\drivers\nvstor64.sys
19:46:19.0469 2580 nvstor64 - ok
19:46:19.0516 2580 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
19:46:19.0516 2580 nv_agp - ok
19:46:19.0532 2580 NwlnkFlt - ok
19:46:19.0547 2580 NwlnkFwd - ok
19:46:19.0766 2580 odserv (84de1dd996b48b05ace31ad015fa108a) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:46:19.0812 2580 odserv - ok
19:46:19.0875 2580 ohci1394 (7b58953e2f263421fdbb09a192712a85) C:\Windows\system32\drivers\ohci1394.sys
19:46:19.0875 2580 ohci1394 - ok
19:46:19.0937 2580 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:46:19.0968 2580 ose - ok
19:46:20.0156 2580 p2pimsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
19:46:20.0218 2580 p2pimsvc - ok
19:46:20.0234 2580 p2psvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
19:46:20.0249 2580 p2psvc - ok
19:46:20.0296 2580 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
19:46:20.0296 2580 Parport - ok
19:46:20.0343 2580 partmgr (5ab40c36894f4c06bdab0c9a2fba282d) C:\Windows\system32\drivers\partmgr.sys
19:46:20.0358 2580 partmgr - ok
19:46:20.0374 2580 PcaSvc (9ab157b374192ff276c1628fbdba2b0e) C:\Windows\System32\pcasvc.dll
19:46:20.0390 2580 PcaSvc - ok
19:46:20.0421 2580 pci (2a5b2a51559066ea84742909b5b2cd69) C:\Windows\system32\drivers\pci.sys
19:46:20.0421 2580 pci - ok
19:46:20.0452 2580 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
19:46:20.0452 2580 pciide - ok
19:46:20.0499 2580 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
19:46:20.0514 2580 pcmcia - ok
19:46:20.0655 2580 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
19:46:20.0702 2580 PEAUTH - ok
19:46:20.0858 2580 PerfHost (0ed8727ea0172860f47258456c06caea) C:\Windows\SysWow64\perfhost.exe
19:46:20.0889 2580 PerfHost - ok
19:46:21.0232 2580 pla (e9e68c1a0f25cf4a7ac966eea74ee89e) C:\Windows\system32\pla.dll
19:46:21.0326 2580 pla - ok
19:46:21.0388 2580 PlugPlay (5aaa0c5534b05ed49919fcd9dbd11a5b) C:\Windows\system32\umpnpmgr.dll
19:46:21.0466 2580 PlugPlay - ok
19:46:21.0528 2580 Pml Driver HPZ12 (bb3bf7b26daadcbab3ba90c4bcf9e73c) C:\Windows\system32\HPZipm12.dll
19:46:21.0575 2580 Pml Driver HPZ12 - ok
19:46:22.0043 2580 PNRPAutoReg (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
19:46:22.0059 2580 PNRPAutoReg - ok
19:46:22.0074 2580 PNRPsvc (430f35c5592d253f43a26b4f5a523dbf) C:\Windows\system32\p2psvc.dll
19:46:22.0074 2580 PNRPsvc - ok
19:46:22.0215 2580 PolicyAgent (93edfb7be39dc47645069b4890b2ce7e) C:\Windows\System32\ipsecsvc.dll
19:46:22.0230 2580 PolicyAgent - ok
19:46:22.0402 2580 PptpMiniport (f5739f2c6db2534c384ad5150808e8f5) C:\Windows\system32\DRIVERS\raspptp.sys
19:46:22.0402 2580 PptpMiniport - ok
19:46:22.0449 2580 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
19:46:22.0464 2580 Processor - ok
19:46:22.0511 2580 ProfSvc (b21fe10dad3ab59e78df7aa3fbf41e70) C:\Windows\system32\profsvc.dll
19:46:22.0542 2580 ProfSvc - ok
19:46:22.0589 2580 ProtectedStorage (1b461e9f6db0ef829b4369f47a24bbec) C:\Windows\system32\lsass.exe
19:46:22.0605 2580 ProtectedStorage - ok
19:46:22.0620 2580 PSched (ce3aecb2bf2c377380ee028864841f4e) C:\Windows\system32\DRIVERS\pacer.sys
19:46:22.0620 2580 PSched - ok
19:46:22.0808 2580 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
19:46:22.0886 2580 ql2300 - ok
19:46:22.0901 2580 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
19:46:22.0917 2580 ql40xx - ok
19:46:22.0995 2580 QWAVE (90574842c3da781e279061a3eff91f07) C:\Windows\system32\qwave.dll
19:46:23.0042 2580 QWAVE - ok
19:46:23.0057 2580 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
19:46:23.0057 2580 QWAVEdrv - ok
19:46:23.0073 2580 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
19:46:23.0073 2580 RasAcd - ok
19:46:23.0104 2580 RasAuto (b2ae18f847d07f0044404ddf7cb04497) C:\Windows\System32\rasauto.dll
19:46:23.0120 2580 RasAuto - ok
19:46:23.0244 2580 Rasl2tp (3b9085f91ef00abd15a6f36570e90e12) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:46:23.0260 2580 Rasl2tp - ok
19:46:23.0354 2580 RasMan (2a63d46b01685fd4be9778ca3c231c2d) C:\Windows\System32\rasmans.dll
19:46:23.0369 2580 RasMan - ok
19:46:23.0463 2580 RasPppoe (2ce1703c27196094fb6e4c6e439f2c21) C:\Windows\system32\DRIVERS\raspppoe.sys
19:46:23.0463 2580 RasPppoe - ok
19:46:23.0494 2580 RasSstp (fcd04fa67e8b40fa0ad361dd38593942) C:\Windows\system32\DRIVERS\rassstp.sys
19:46:23.0494 2580 RasSstp - ok
19:46:23.0541 2580 rdbss (33fa5b6136d92ee0f53f021c79091300) C:\Windows\system32\DRIVERS\rdbss.sys
19:46:23.0556 2580 rdbss - ok
19:46:23.0572 2580 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:46:23.0572 2580 RDPCDD - ok
19:46:23.0634 2580 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
19:46:23.0697 2580 rdpdr - ok
19:46:23.0697 2580 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
19:46:23.0697 2580 RDPENCDD - ok
19:46:23.0744 2580 RDPWD (7747082f672aa2846235c9cea42e2e72) C:\Windows\system32\drivers\RDPWD.sys
19:46:23.0759 2580 RDPWD - ok
19:46:23.0806 2580 RemoteAccess (c612b9557da73f70d41f8a6fbc8e5344) C:\Windows\System32\mprdim.dll
19:46:23.0822 2580 RemoteAccess - ok
19:46:23.0868 2580 RemoteRegistry (416c611369cbe49074b89cee2f83abef) C:\Windows\system32\regsvc.dll
19:46:23.0884 2580 RemoteRegistry - ok
19:46:23.0915 2580 RpcLocator (f46c457840d4b7a4daafee739ce04102) C:\Windows\system32\locator.exe
19:46:23.0915 2580 RpcLocator - ok
19:46:24.0024 2580 RpcSs (ff27be0ba7b3c48d5c99afcb56d436c2) C:\Windows\system32\rpcss.dll
19:46:24.0024 2580 RpcSs - ok
19:46:24.0118 2580 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
19:46:24.0118 2580 rspndr - ok
19:46:24.0180 2580 RTL8169 (479f29909b9a48726a07971662f77316) C:\Windows\system32\DRIVERS\Rtlh64.sys
19:46:24.0212 2580 RTL8169 - ok
19:46:24.0258 2580 RTSTOR (0851174830dafad4eacc4dd818d803d1) C:\Windows\system32\drivers\RTSTOR64.SYS
19:46:24.0258 2580 RTSTOR - ok
19:46:24.0290 2580 SamSs (1b461e9f6db0ef829b4369f47a24bbec) C:\Windows\system32\lsass.exe
19:46:24.0290 2580 SamSs - ok
19:46:24.0352 2580 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
19:46:24.0352 2580 SASDIFSV - ok
19:46:24.0368 2580 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
19:46:24.0368 2580 SASKUTIL - ok
19:46:24.0430 2580 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
19:46:24.0430 2580 sbp2port - ok
19:46:24.0477 2580 SCardSvr (f024d560fea06f8b56d673849eb89ae6) C:\Windows\System32\SCardSvr.dll
19:46:24.0524 2580 SCardSvr - ok
19:46:24.0664 2580 Schedule (c74c6c01353d87aafe1193b426d667b0) C:\Windows\system32\schedsvc.dll
19:46:24.0711 2580 Schedule - ok
19:46:24.0742 2580 SCPolicySvc (edfffc8b6afb609bf33dbe0a900426b6) C:\Windows\System32\certprop.dll
19:46:24.0742 2580 SCPolicySvc - ok
19:46:24.0789 2580 SDRSVC (4ff71b076a7760fe75ea5ae2d0ee0018) C:\Windows\System32\SDRSVC.dll
19:46:24.0820 2580 SDRSVC - ok
19:46:24.0882 2580 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
19:46:24.0882 2580 secdrv - ok
19:46:24.0898 2580 seclogon (5acdcbc67fcf894a1815b9f96d704490) C:\Windows\system32\seclogon.dll
19:46:24.0898 2580 seclogon - ok
19:46:24.0945 2580 SENS (90973a64b96cd647ff81c79443618eed) C:\Windows\System32\sens.dll
19:46:24.0945 2580 SENS - ok
19:46:24.0992 2580 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
19:46:24.0992 2580 Serenum - ok
19:46:25.0038 2580 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
19:46:25.0038 2580 Serial - ok
19:46:25.0070 2580 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
19:46:25.0070 2580 sermouse - ok
19:46:25.0132 2580 SessionEnv (a8e4a4407a09f35dccc3771af590b0c4) C:\Windows\system32\sessenv.dll
19:46:25.0148 2580 SessionEnv - ok
19:46:25.0163 2580 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
19:46:25.0179 2580 sffdisk - ok
19:46:25.0194 2580 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
19:46:25.0194 2580 sffp_mmc - ok
19:46:25.0194 2580 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
19:46:25.0210 2580 sffp_sd - ok
19:46:25.0226 2580 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
19:46:25.0226 2580 sfloppy - ok
19:46:25.0272 2580 SharedAccess (4c5aee179da7e1ee9a9ccb9da289af34) C:\Windows\System32\ipnathlp.dll
19:46:25.0304 2580 SharedAccess - ok
19:46:25.0335 2580 ShellHWDetection (eb3114330236cf030e8edf62881baf67) C:\Windows\System32\shsvcs.dll
19:46:25.0366 2580 ShellHWDetection - ok
19:46:25.0397 2580 simbad (5f22132c9153639762708909f156b33d) C:\Windows\system32\psimsvc.dll
19:46:25.0538 2580 simbad ( Backdoor.Multi.ZAccess.gen ) - infected
19:46:25.0538 2580 simbad - detected Backdoor.Multi.ZAccess.gen (0)
19:46:25.0584 2580 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
19:46:25.0584 2580 SiSRaid2 - ok
19:46:25.0616 2580 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
19:46:25.0616 2580 SiSRaid4 - ok
19:46:25.0959 2580 slsvc (a301d2cefb4747dfe0c24425dcbe0b78) C:\Windows\system32\SLsvc.exe
19:46:26.0037 2580 slsvc - ok
19:46:26.0177 2580 SLUINotify (f5ddf7c0af85eb72cb295171f8c3cb35) C:\Windows\system32\SLUINotify.dll
19:46:26.0193 2580 SLUINotify - ok
19:46:26.0255 2580 Smb (41eb2e8e005feedcafce301983eff932) C:\Windows\system32\DRIVERS\smb.sys
19:46:26.0255 2580 Smb - ok
19:46:26.0286 2580 SNMPTRAP (f8f47f38909823b1af28d60b96340cff) C:\Windows\System32\snmptrap.exe
19:46:26.0286 2580 SNMPTRAP - ok
19:46:26.0302 2580 spldr (f9cb0672162f7f04248e2b82c1ff4617) C:\Windows\system32\drivers\spldr.sys
19:46:26.0302 2580 spldr - ok
19:46:26.0349 2580 Spooler (e6519a9e756d74dc51c697ba62162f51) C:\Windows\System32\spoolsv.exe
19:46:26.0396 2580 Spooler - ok
19:46:26.0442 2580 srv (b02f20d0d581496b826e21f8572c62b0) C:\Windows\system32\DRIVERS\srv.sys
19:46:26.0489 2580 srv - ok
19:46:26.0520 2580 srv2 (68dcd148225f40ef1cdf6cfc115cb6fe) C:\Windows\system32\DRIVERS\srv2.sys
19:46:26.0536 2580 srv2 - ok
19:46:26.0552 2580 srvnet (4d0858b640cdbcba671c5439a8ef45cb) C:\Windows\system32\DRIVERS\srvnet.sys
19:46:26.0552 2580 srvnet - ok
19:46:26.0614 2580 SSDPSRV (192c74646ec5725aef3f80d19ff75f6a) C:\Windows\System32\ssdpsrv.dll
19:46:26.0645 2580 SSDPSRV - ok
19:46:26.0676 2580 SstpSvc (2ee3fa0308e6185ba64a9a7f2e74332b) C:\Windows\system32\sstpsvc.dll
19:46:26.0692 2580 SstpSvc - ok
19:46:26.0817 2580 STacSV (3592f566dd9829cdd5d500e6638746c8) C:\Program Files (x86)\IDT\WDM\STacSV64.exe
19:46:26.0848 2580 STacSV - ok
19:46:26.0973 2580 STHDA (ef5536527a1def7161ef832dbc74ac47) C:\Windows\system32\drivers\stwrt64.sys
19:46:27.0035 2580 STHDA - ok
19:46:27.0191 2580 stisvc (f14f7d7d68a66777fb999d5d0f21138d) C:\Windows\System32\wiaservc.dll
19:46:27.0238 2580 stisvc - ok
19:46:27.0269 2580 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
19:46:27.0269 2580 swenum - ok
19:46:27.0347 2580 swprv (da34d6eb4a3154c0bebaeb0a2483ef3e) C:\Windows\System32\swprv.dll
19:46:27.0394 2580 swprv - ok
19:46:27.0425 2580 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
19:46:27.0425 2580 Symc8xx - ok
19:46:27.0456 2580 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
19:46:27.0456 2580 Sym_hi - ok
19:46:27.0472 2580 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
19:46:27.0472 2580 Sym_u3 - ok
19:46:27.0566 2580 SynTP (6149bb382bff81c0b453048cb048b81e) C:\Windows\system32\DRIVERS\SynTP.sys
19:46:27.0581 2580 SynTP - ok
19:46:27.0690 2580 SysMain (bea0d5521ed21df8f6ffeed86daede7b) C:\Windows\system32\sysmain.dll
19:46:27.0706 2580 SysMain - ok
19:46:27.0753 2580 TabletInputService (005ce42567f9113a3bccb3b20073b029) C:\Windows\System32\TabSvc.dll
19:46:27.0753 2580 TabletInputService - ok
19:46:27.0815 2580 TapiSrv (52091001caf20ae84cf47023ee21b4bb) C:\Windows\System32\tapisrv.dll
19:46:27.0846 2580 TapiSrv - ok
19:46:27.0878 2580 TBS (cdbe8d7c1e201b911cdc346d06617fb5) C:\Windows\System32\tbssvc.dll
19:46:27.0878 2580 TBS - ok
19:46:28.0096 2580 Tcpip (7a1183fbb802f5abad7fa18bc67e0858) C:\Windows\system32\drivers\tcpip.sys
19:46:28.0127 2580 Tcpip - ok
19:46:28.0564 2580 Tcpip6 (7a1183fbb802f5abad7fa18bc67e0858) C:\Windows\system32\DRIVERS\tcpip.sys
19:46:28.0580 2580 Tcpip6 - ok
19:46:28.0798 2580 tcpipreg (c29d4b3b08ad0b7e8564814e4ff6a57b) C:\Windows\system32\drivers\tcpipreg.sys
19:46:28.0798 2580 tcpipreg - ok
19:46:28.0829 2580 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
19:46:28.0829 2580 TDPIPE - ok
19:46:28.0845 2580 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
19:46:28.0845 2580 TDTCP - ok
19:46:28.0892 2580 tdx (8c39c72e0e853de04748c0337d9b9216) C:\Windows\system32\DRIVERS\tdx.sys
19:46:28.0892 2580 tdx - ok
19:46:29.0016 2580 TermDD (3f0ebf6ee609f2a276c0d5faf244ec90) C:\Windows\system32\DRIVERS\termdd.sys
19:46:29.0016 2580 TermDD - ok
19:46:29.0204 2580 TermService (f870a5589d6a94b426efb13689023946) C:\Windows\System32\termsrv.dll
19:46:29.0235 2580 TermService - ok
19:46:29.0344 2580 Themes (eb3114330236cf030e8edf62881baf67) C:\Windows\system32\shsvcs.dll
19:46:29.0344 2580 Themes - ok
19:46:29.0375 2580 THREADORDER (3cbe4995e80e13ccfbc42e5dcf3ac81a) C:\Windows\system32\mmcss.dll
19:46:29.0391 2580 THREADORDER - ok
19:46:29.0438 2580 TrkWks (f4689f05af472a651a7b1b7b02d200e7) C:\Windows\System32\trkwks.dll
19:46:29.0469 2580 TrkWks - ok
19:46:29.0531 2580 TrustedInstaller (ac6ff1df22ed90bad6417ee5a4c6e2f0) C:\Windows\servicing\TrustedInstaller.exe
19:46:29.0531 2580 TrustedInstaller - ok
19:46:29.0640 2580 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:46:29.0640 2580 tssecsrv - ok
19:46:29.0672 2580 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
19:46:29.0687 2580 tunmp - ok
19:46:29.0703 2580 tunnel (f6a4fba7c03ac2efd00f3301c0c1e067) C:\Windows\system32\DRIVERS\tunnel.sys
19:46:29.0703 2580 tunnel - ok
19:46:29.0750 2580 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
19:46:29.0750 2580 uagp35 - ok
19:46:29.0812 2580 udfs (eca6629e33f122afff18a2ab7c3eb033) C:\Windows\system32\DRIVERS\udfs.sys
19:46:29.0843 2580 udfs - ok
19:46:29.0906 2580 UI0Detect (060507c4113391394478f6953a79eedc) C:\Windows\system32\UI0Detect.exe
19:46:29.0906 2580 UI0Detect - ok
19:46:29.0937 2580 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
19:46:29.0952 2580 uliagpkx - ok
19:46:29.0999 2580 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
19:46:30.0030 2580 uliahci - ok
19:46:30.0062 2580 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
19:46:30.0108 2580 UlSata - ok
19:46:30.0171 2580 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
19:46:30.0202 2580 ulsata2 - ok
19:46:30.0280 2580 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
19:46:30.0280 2580 umbus - ok
19:46:30.0342 2580 upnphost (7093799ff80e9deca0680d2e3535be60) C:\Windows\System32\upnphost.dll
19:46:30.0405 2580 upnphost - ok
19:46:30.0530 2580 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
19:46:30.0545 2580 usbccgp - ok
19:46:30.0639 2580 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
19:46:30.0639 2580 usbcir - ok
19:46:30.0686 2580 usbehci (da6d8d8ed0a53c63ac6f4bd40fe83fbe) C:\Windows\system32\DRIVERS\usbehci.sys
19:46:30.0686 2580 usbehci - ok
19:46:30.0795 2580 usbhub (99045369ae3216216573d0775fd7ed56) C:\Windows\system32\DRIVERS\usbhub.sys
19:46:30.0810 2580 usbhub - ok
19:46:30.0842 2580 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
19:46:30.0857 2580 usbohci - ok
19:46:30.0888 2580 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
19:46:30.0888 2580 usbprint - ok
19:46:30.0951 2580 usbscan (ea0bf666868964fbe8cb10e50c97b9f1) C:\Windows\system32\DRIVERS\usbscan.sys
19:46:30.0951 2580 usbscan - ok
19:46:31.0107 2580 USBSTOR (586d9876a4945779c8eea926c0d16889) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:46:31.0107 2580 USBSTOR - ok
19:46:31.0138 2580 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
19:46:31.0138 2580 usbuhci - ok
19:46:31.0185 2580 usbvideo (fc33099877790d51b0927b7039059855) C:\Windows\system32\Drivers\usbvideo.sys
19:46:31.0200 2580 usbvideo - ok
19:46:31.0232 2580 UVCFTR (fa3ca291f80ee13a1ac210492a7dfbb9) C:\Windows\system32\Drivers\UVCFTR_S.SYS
19:46:31.0232 2580 UVCFTR - ok
19:46:31.0263 2580 UxSms (9190f03c82547afa87367f1ceca88f3b) C:\Windows\System32\uxsms.dll
19:46:31.0263 2580 UxSms - ok
19:46:31.0310 2580 vds (c15a4a550cba7b9f1f68b72528e04ce1) C:\Windows\System32\vds.exe
19:46:31.0372 2580 vds - ok
19:46:31.0419 2580 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
19:46:31.0419 2580 vga - ok
19:46:31.0434 2580 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
19:46:31.0434 2580 VgaSave - ok
19:46:31.0466 2580 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
19:46:31.0466 2580 viaide - ok
19:46:31.0497 2580 volmgr (793d9b32a1c462c91f6f70358283ac97) C:\Windows\system32\drivers\volmgr.sys
19:46:31.0497 2580 volmgr - ok
19:46:31.0528 2580 volmgrx (5aa217da5dc4ff5b9ac9ab86563b3223) C:\Windows\system32\drivers\volmgrx.sys
19:46:31.0544 2580 volmgrx - ok
19:46:31.0575 2580 volsnap (de4307412d98050239026e56a7dff3c0) C:\Windows\system32\drivers\volsnap.sys
19:46:31.0590 2580 volsnap - ok
19:46:31.0653 2580 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
19:46:31.0653 2580 vsmraid - ok
19:46:31.0918 2580 VSS (186bd53f8a408ad20f5a056c05678629) C:\Windows\system32\vssvc.exe
19:46:32.0027 2580 VSS - ok
19:46:32.0339 2580 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
19:46:32.0339 2580 WacomPen - ok
19:46:32.0402 2580 Wanarp (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys
19:46:32.0402 2580 Wanarp - ok
19:46:32.0417 2580 Wanarpv6 (aea75207e443c8623c36b8d03596f84f) C:\Windows\system32\DRIVERS\wanarp.sys
19:46:32.0417 2580 Wanarpv6 - ok
19:46:32.0542 2580 wcncsvc (055449247c490e24b968b44fe8a969eb) C:\Windows\System32\wcncsvc.dll
19:46:32.0558 2580 wcncsvc - ok
19:46:32.0589 2580 WcsPlugInService (ea4b369560e986f19d93f45a881484ac) C:\Windows\System32\WcsPlugInService.dll
19:46:32.0729 2580 WcsPlugInService - ok
19:46:32.0792 2580 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
19:46:32.0792 2580 Wd - ok
19:46:33.0010 2580 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
19:46:33.0041 2580 Wdf01000 - ok
19:46:33.0104 2580 WdiServiceHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:46:33.0119 2580 WdiServiceHost - ok
19:46:33.0119 2580 WdiSystemHost (c5efda73ebfca8b02a094898de0a9276) C:\Windows\system32\wdi.dll
19:46:33.0119 2580 WdiSystemHost - ok
19:46:33.0228 2580 WebClient (3d4ab55f8178fd0cd3ca45cd0ec9cf5b) C:\Windows\System32\webclnt.dll
19:46:33.0275 2580 WebClient - ok
19:46:33.0338 2580 Wecsvc (bd9a749f36710ffa02e0e530f7451936) C:\Windows\system32\wecsvc.dll
19:46:33.0369 2580 Wecsvc - ok
19:46:33.0447 2580 wercplsupport (9c980351d7e96288ea0c23ae232bd065) C:\Windows\System32\wercplsupport.dll
19:46:33.0462 2580 wercplsupport - ok
19:46:33.0556 2580 WerSvc (66b9ecebc46683f47edc06333c075fef) C:\Windows\System32\WerSvc.dll
19:46:33.0556 2580 WerSvc - ok
19:46:33.0759 2580 winachsf (057b062cf9a11e04db45b8c3afc28b11) C:\Windows\system32\DRIVERS\CAX_CNXT.sys
19:46:33.0774 2580 winachsf - ok
19:46:33.0790 2580 WinHttpAutoProxySvc - ok
19:46:33.0915 2580 Winmgmt (ac98f38feab066a8f983d54ff3f4fd4c) C:\Windows\system32\wbem\WMIsvc.dll
19:46:33.0930 2580 Winmgmt - ok
19:46:34.0071 2580 WinRM (aeb6c5200fd5517f06076af0ee4538e1) C:\Windows\system32\WsmSvc.dll
19:46:34.0164 2580 WinRM - ok
19:46:34.0289 2580 Wlansvc (05477e53b7b529435026f705b4235324) C:\Windows\System32\wlansvc.dll
19:46:34.0336 2580 Wlansvc - ok
19:46:34.0414 2580 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
19:46:34.0414 2580 WmiAcpi - ok
19:46:34.0508 2580 wmiApSrv (d303322dd577c3deda1251ed2e7a496c) C:\Windows\system32\wbem\WmiApSrv.exe
19:46:34.0508 2580 wmiApSrv - ok
19:46:34.0554 2580 WMPNetworkSvc - ok
19:46:34.0601 2580 WPCSvc (cbc156c913f099e6680d1df9307db7a8) C:\Windows\System32\wpcsvc.dll
19:46:34.0617 2580 WPCSvc - ok
19:46:34.0679 2580 WPDBusEnum (a27c8f92d84e2ddc151978e4692c978e) C:\Windows\system32\wpdbusenum.dll
19:46:34.0679 2580 WPDBusEnum - ok
19:46:34.0757 2580 WpdUsb (6329d1990db931073b86ab5946d8e317) C:\Windows\system32\DRIVERS\wpdusb.sys
19:46:34.0757 2580 WpdUsb - ok
19:46:34.0788 2580 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
19:46:34.0788 2580 ws2ifsl - ok
19:46:34.0804 2580 WSearch - ok
19:46:35.0163 2580 wuauserv (fb3796754fe00f0bdc87a36f164a5f4d) C:\Windows\system32\wuaueng.dll
19:46:35.0256 2580 wuauserv - ok
19:46:35.0522 2580 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:46:35.0553 2580 WUDFRd - ok
19:46:35.0631 2580 wudfsvc (6cbd51ff913c851d56ed9dc7f2a27dde) C:\Windows\System32\WUDFSvc.dll
19:46:35.0631 2580 wudfsvc - ok
19:46:35.0662 2580 XAudio (283bd3e0dffb8f6b4c62a5649959f9ef) C:\Windows\system32\DRIVERS\xaudio64.sys
19:46:35.0662 2580 XAudio - ok
19:46:35.0709 2580 XAudioService (340d7e19df14a65f73bce33b8ecd5fb6) C:\Windows\system32\DRIVERS\xaudio64.exe
19:46:35.0771 2580 XAudioService - ok
19:46:35.0818 2580 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
19:46:37.0269 2580 \Device\Harddisk0\DR0 - ok
19:46:37.0284 2580 Boot (0x1200) (810d47dfcf4a5d8c30e1b0c2b80a0452) \Device\Harddisk0\DR0\Partition0
19:46:37.0284 2580 \Device\Harddisk0\DR0\Partition0 - ok
19:46:37.0300 2580 Boot (0x1200) (11a0f4651f487f9a53bde7258ef37875) \Device\Harddisk0\DR0\Partition1
19:46:37.0316 2580 \Device\Harddisk0\DR0\Partition1 - ok
19:46:37.0316 2580 ============================================================
19:46:37.0316 2580 Scan finished
19:46:37.0316 2580 ============================================================
19:46:37.0331 1660 Detected object count: 1
19:46:37.0331 1660 Actual detected object count: 1
19:46:43.0618 1660 C:\Windows\system32\psimsvc.dll - copied to quarantine
19:46:43.0618 1660 HKLM\SYSTEM\ControlSet001\services\simbad - will be deleted on reboot
19:46:43.0665 1660 HKLM\SYSTEM\ControlSet002\services\simbad - will be deleted on reboot
19:46:43.0852 1660 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - cured
19:46:43.0961 1660 C:\Windows\system32\psimsvc.dll - will be deleted on reboot
19:46:43.0961 1660 simbad ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
19:46:46.0052 2912 Deinitialize success

#5 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:01:56 PM

Posted 11 May 2012 - 09:27 PM

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users