Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

rootkit.0access - I can't shift it.....please help


  • This topic is locked This topic is locked
17 replies to this topic

#1 rooster4t

rooster4t

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 15 July 2012 - 06:28 PM

Hi all - this started with MS Security Essentials continually rebooting my machine due to malware. I uninstalled in and tried other packages (lots of them!). The rebooting issue has gone but now Malware Bytes keeps throwing this up whenever I run a scan and I can't seem to resolve it. I'd really appreciate some help from anyone who can spare the time. Many thanks

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514
Run by Home at 0:13:54 on 2012-07-16
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4007.1742 [GMT 1:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\ibmpmsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Windows\SysWOW64\SAsrv.exe
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\PROGRA~1\LENOVO\VIRTSCRL\virtscrl.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\Lenovo\HOTKEY\tpnumlkd.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Windows\System32\TpShocks.exe
C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Lenovo\System Update\SUService.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe
C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
\\.\globalroot\systemroot\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U
C:\Windows\system32\taskhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
uSearch Bar = Preserve
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
mRun: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [<NO NAME>]
mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\ThinkPad\Bluetooth Software\BTTray.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{69518B5A-3514-4DC7-ADE6-F20F598844B7} : DhcpNameServer = 194.168.4.100 194.168.8.100
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
BHO-X64: SmartSelect - No File
TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"
TB-X64: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
mRun-x64: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [(Default)]
mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar
mRunOnce-x64: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\cv9zyglj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\MyFunCards_5mEI\Installr\1.bin\NP5mEISb.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM64.sys --> C:\Windows\system32\DRIVERS\ApsHM64.sys [?]
R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiifx64.sys --> C:\Windows\system32\DRIVERS\smiifx64.sys [?]
R1 PHCORE;PHCORE;C:\Program Files\Lenovo\RapidBoot\PHCORE64.sys [2010-12-3 31592]
R1 PSINKNC;PSINKNC;C:\Windows\system32\DRIVERS\psinknc.sys --> C:\Windows\system32\DRIVERS\psinknc.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute;C:\Program Files\Lenovo\Communications Utility\CamMute.exe [2011-6-9 40808]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute;C:\Program Files\Lenovo\HOTKEY\micmute.exe [2011-1-17 45496]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-6-9 59240]
R2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe [2011-1-17 93032]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-7-15 655944]
R2 NanoServiceMain;Panda Cloud Antivirus Service;C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-4-28 140608]
R2 PSINAFLT;PSINAFLT;C:\Windows\system32\DRIVERS\PSINAflt.sys --> C:\Windows\system32\DRIVERS\PSINAflt.sys [?]
R2 PSINFILE;PSINFILE;C:\Windows\system32\DRIVERS\PSINFile.sys --> C:\Windows\system32\DRIVERS\PSINFile.sys [?]
R2 PSINPROC;PSINPROC;C:\Windows\system32\DRIVERS\PSINProc.sys --> C:\Windows\system32\DRIVERS\PSINProc.sys [?]
R2 PSINPROT;PSINPROT;C:\Windows\system32\DRIVERS\PSINProt.sys --> C:\Windows\system32\DRIVERS\PSINProt.sys [?]
R2 risdxc;risdxc;C:\Windows\system32\DRIVERS\risdxc64.sys --> C:\Windows\system32\DRIVERS\risdxc64.sys [?]
R2 SAService;Conexant SmartAudio service;C:\Windows\System32\SASrv.exe [2011-6-9 446592]
R2 TPHKLOAD;Lenovo Hotkey Client Loader;C:\Program Files\Lenovo\HOTKEY\tphkload.exe [2011-1-17 114024]
R2 TPHKSVC;On Screen Display;C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe [2011-1-17 64440]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-6-9 2656280]
R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]
R3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;C:\Windows\system32\DRIVERS\NETwNs64.sys --> C:\Windows\system32\DRIVERS\NETwNs64.sys [?]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
R3 wdkmd;Intel WiDi KMD;C:\Windows\system32\DRIVERS\WDKMD.sys --> C:\Windows\system32\DRIVERS\WDKMD.sys [?]
S0 PsBoot;Panda boot driver;C:\Windows\system32\Drivers\PsBoot.sys --> C:\Windows\system32\Drivers\PsBoot.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 HyperW7Svc;HyperW7 Service;C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [2010-12-3 116072]
S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]
S3 BTWAMPFL;BTWAMPFL;C:\Windows\system32\DRIVERS\btwampfl.sys --> C:\Windows\system32\DRIVERS\btwampfl.sys [?]
S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys --> C:\Windows\system32\DRIVERS\btwl2cap.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-7 129976]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-2 340240]
S3 PCDSRVC{127174DC-C366ED8B-06020101}_0;PCDSRVC{127174DC-C366ED8B-06020101}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\PC-Doctor\pcdsrvc_x64.pkms [2010-12-9 25072]
S3 Power Manager DBC Service;Power Manager DBC Service;C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe [2011-6-9 79208]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 WSDPrintDevice;WSD Print Support via UMB;C:\Windows\system32\DRIVERS\WSDPrint.sys --> C:\Windows\system32\DRIVERS\WSDPrint.sys [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2012-07-15 22:03:35 28744 ----a-w- C:\Windows\System32\drivers\PsBoot.sys
2012-07-15 21:59:53 -------- d-----w- C:\Users\Home\AppData\Roaming\Panda Security
2012-07-15 21:58:52 -------- d-----w- C:\ProgramData\Panda Security
2012-07-15 21:58:52 -------- d-----w- C:\Program Files (x86)\Panda Security
2012-07-15 21:58:41 -------- d-----w- C:\temp
2012-07-15 20:32:42 -------- d-----w- C:\Users\Home\AppData\Local\NPE
2012-07-15 20:28:39 27256 ----a-w- C:\Windows\System32\drivers\FixZeroAccess.sys
2012-07-15 20:09:42 -------- d-----w- C:\Users\Home\AppData\Roaming\Malwarebytes
2012-07-15 20:09:34 -------- d-----w- C:\ProgramData\Malwarebytes
2012-07-15 20:09:33 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-07-15 20:09:33 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-15 19:56:39 328704 ----a-w- C:\Windows\System32\services.exe.93687A1F6275BFBB
2012-07-15 19:44:27 328704 ----a-w- C:\Windows\System32\services.exe.A98691B144D9B1A1
2012-07-15 19:38:49 328704 ----a-w- C:\Windows\System32\services.exe.5D480C11B1BC8FA6
2012-07-15 19:35:15 328704 ----a-w- C:\Windows\System32\services.exe.F36AE296F11AEA73
2012-07-15 19:31:47 328704 ----a-w- C:\Windows\System32\services.exe.2E0D6710C5178983
2012-07-15 19:29:00 328704 ----a-w- C:\Windows\System32\services.exe.15E9E681E7A1D354
2012-07-15 19:25:50 328704 ----a-w- C:\Windows\System32\services.exe.AE84BF21F00F2466
2012-07-15 19:21:24 328704 ----a-w- C:\Windows\System32\services.exe.E256FB92A541C5C3
2012-07-15 15:33:32 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2012-07-15 15:30:13 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-07-15 15:23:48 -------- d-sh--r- C:\Users\Home\AppData\Roaming\System32
2012-07-15 11:26:05 -------- d-----w- C:\Users\Home\AppData\Local\{FEDF202B-5638-4A89-AB62-D71DC04FDF72}
2012-07-15 11:25:52 -------- d-----w- C:\Users\Home\AppData\Local\{1D05CB46-2AA7-4B96-8B63-E6AC837BA48D}
2012-07-14 21:11:34 -------- d-----w- C:\Users\Home\AppData\Local\{3A7E0DBB-B034-4A65-8402-EAD10E9952FF}
2012-07-14 21:11:12 -------- d-----w- C:\Users\Home\AppData\Local\{1B2F83DC-4BC6-435B-880E-9BEC227A2C48}
2012-07-14 09:10:32 -------- d-----w- C:\Users\Home\AppData\Local\{743213FF-2645-46DB-9E5A-2350C52683DE}
2012-07-14 09:10:20 -------- d-----w- C:\Users\Home\AppData\Local\{38CC452C-8ABA-4CD1-B219-CECB25D0861F}
2012-07-13 18:43:23 -------- d-----w- C:\Users\Home\AppData\Local\{3C8526C9-DD9D-4089-B49C-F1F467521500}
2012-07-13 18:43:10 -------- d-----w- C:\Users\Home\AppData\Local\{8349C0BC-9049-4D94-A0E6-4C24CE2AECCE}
2012-07-13 06:02:11 -------- d-----w- C:\Users\Home\AppData\Local\{030377B2-7018-42D3-B0FD-E94F030CD351}
2012-07-13 06:01:48 -------- d-----w- C:\Users\Home\AppData\Local\{AB16D2DD-FAFB-4EFD-97D9-A55FD77C84C8}
2012-07-12 14:20:23 -------- d-----w- C:\Users\Home\AppData\Local\{05638CA4-825B-46A2-828C-54D3EB12ED44}
2012-07-12 14:20:11 -------- d-----w- C:\Users\Home\AppData\Local\{953026DD-8E12-4E76-BDE0-0289D4B338E6}
2012-07-12 06:19:54 3148800 ----a-w- C:\Windows\System32\win32k.sys
2012-07-11 18:30:35 -------- d-----w- C:\Users\Home\AppData\Local\{89449D27-7098-441C-B77C-75918985367F}
2012-07-11 18:30:11 -------- d-----w- C:\Users\Home\AppData\Local\{F32B1028-5FFA-449C-BB8E-E84857880D79}
2012-07-11 06:29:46 -------- d-----w- C:\Users\Home\AppData\Local\{1835EAB7-1DD8-486B-AEE5-3FAC403E734D}
2012-07-11 06:29:24 -------- d-----w- C:\Users\Home\AppData\Local\{D372AE28-256F-4CC7-BE13-F5A13C3F7999}
2012-07-10 14:21:19 -------- d-----w- C:\Users\Home\AppData\Local\{6D1DD9D4-2B8C-47C3-9539-14787491D3D0}
2012-07-10 14:21:07 -------- d-----w- C:\Users\Home\AppData\Local\{614FA0AC-7347-4047-8095-B6347055AAB8}
2012-07-09 18:43:17 -------- d-----w- C:\Users\Home\AppData\Local\{39CA7927-C320-4C31-891E-22176F65B9B5}
2012-07-09 18:42:54 -------- d-----w- C:\Users\Home\AppData\Local\{8C5C1385-2B7B-48AC-810D-E9145BB91201}
2012-07-09 06:38:00 -------- d-----w- C:\Users\Home\AppData\Local\{02048C16-30A2-453B-9165-2A5F1F645A58}
2012-07-09 06:37:46 -------- d-----w- C:\Users\Home\AppData\Local\{F2F29809-7049-42D7-AADE-9D0101DE327F}
2012-07-08 10:04:50 -------- d-----w- C:\Users\Home\AppData\Local\{4836B931-B3A8-4DAC-AB3F-403D2B714C51}
2012-07-08 10:04:39 -------- d-----w- C:\Users\Home\AppData\Local\{4BE5899C-3510-4A05-A035-99B9BE43AA68}
2012-07-07 09:47:22 -------- d-----w- C:\Users\Home\AppData\Local\{78FC7E15-34D8-421E-8DA6-DDEC88D8AFF3}
2012-07-07 09:47:10 -------- d-----w- C:\Users\Home\AppData\Local\{1974EAED-E5C8-4B68-BAB2-7CADC27B9479}
2012-07-06 08:47:49 294912 ----a-w- C:\Windows\System32\browserchoice.exe
2012-07-06 07:51:47 -------- d-----w- C:\Users\Home\AppData\Local\{D4030680-A818-49B5-B5F8-5FBE35DDDFDB}
2012-07-06 07:51:36 -------- d-----w- C:\Users\Home\AppData\Local\{FEDBC1FF-70A7-41CE-8FB0-5EE384F87CE0}
2012-07-05 14:31:01 -------- d-----w- C:\Users\Home\AppData\Local\{1A14A42C-E80C-4AB4-A9DD-56D70EF5D41F}
2012-07-05 14:30:47 -------- d-----w- C:\Users\Home\AppData\Local\{6AD5FF2C-056E-4B93-8489-F69D3B0523E2}
2012-07-04 13:58:38 -------- d-----w- C:\Users\Home\AppData\Local\{E763C98F-7C09-444F-B895-3C2C0F8BDA0F}
2012-07-04 13:58:26 -------- d-----w- C:\Users\Home\AppData\Local\{E26B61FF-9300-4C11-961C-A75467F62582}
2012-07-03 15:20:32 -------- d-----w- C:\Users\Home\AppData\Local\{14215009-F39F-4F90-9BCC-6419D75968E3}
2012-07-03 15:20:19 -------- d-----w- C:\Users\Home\AppData\Local\{972C4236-2528-42EF-82E0-B000A9DC6E6F}
2012-07-02 14:22:28 -------- d-----w- C:\Users\Home\AppData\Local\{5EA722CC-C449-4796-8F62-1946F4E239F8}
2012-07-02 14:22:15 -------- d-----w- C:\Users\Home\AppData\Local\{EBC1F503-CA14-4F65-B7D7-0DDAB6A3FBBE}
2012-07-01 10:01:47 -------- d-----w- C:\Users\Home\AppData\Local\{01DB9544-897A-4E62-AB20-7416C04182B7}
2012-07-01 10:01:24 -------- d-----w- C:\Users\Home\AppData\Local\{69806924-5CE4-4BD8-9492-BB79DA30E415}
2012-06-30 22:00:58 -------- d-----w- C:\Users\Home\AppData\Local\{015BE2A0-AE77-4932-81BE-B54459EA5C48}
2012-06-30 09:44:49 -------- d-----w- C:\Users\Home\AppData\Local\{4482D9C9-A540-4461-AE7E-6575A99D5593}
2012-06-30 09:44:37 -------- d-----w- C:\Users\Home\AppData\Local\{6135528F-8BF6-45BA-B773-294D974544B9}
2012-06-29 20:24:53 -------- d-----w- C:\Users\Home\AppData\Local\{57850179-BE5D-4E12-AD04-B4B98493B504}
2012-06-29 20:24:30 -------- d-----w- C:\Users\Home\AppData\Local\{69C69940-1E7A-4167-9CBF-D64665E35331}
2012-06-29 08:24:04 -------- d-----w- C:\Users\Home\AppData\Local\{E4BF7994-D285-4A57-B21E-68754E0C86A0}
2012-06-28 20:23:28 -------- d-----w- C:\Users\Home\AppData\Local\{203FA65D-0D56-4F81-8D1A-0E4DC70FC426}
2012-06-28 20:23:05 -------- d-----w- C:\Users\Home\AppData\Local\{45C529D0-E309-4E89-9DC5-45C8D481B1A3}
2012-06-28 08:22:38 -------- d-----w- C:\Users\Home\AppData\Local\{CCD8C754-FC35-4917-B74D-F5A202AFA519}
2012-06-28 08:22:26 -------- d-----w- C:\Users\Home\AppData\Local\{6C63CD9E-1798-4C8C-9E1D-725373AEA470}
2012-06-27 18:22:05 -------- d-----w- C:\Users\Home\AppData\Local\{A208C481-A507-45EE-A2EC-6DA0050488E7}
2012-06-27 06:21:22 -------- d-----w- C:\Users\Home\AppData\Local\{38EB443F-73B8-4CD7-8E58-9F9A39A4ACF3}
2012-06-27 06:21:10 -------- d-----w- C:\Users\Home\AppData\Local\{0936C949-07D4-4C76-856F-FAD197274906}
2012-06-26 18:12:13 -------- d-----w- C:\Users\Home\AppData\Local\{F0FEE1DC-F999-4B43-8022-FAD6E47080FE}
2012-06-26 18:11:50 -------- d-----w- C:\Users\Home\AppData\Local\{FEB52FFB-8907-48DE-803D-BEA62097C1D5}
2012-06-26 06:11:23 -------- d-----w- C:\Users\Home\AppData\Local\{4BAF97EA-0688-43AA-959D-8F675F17EECF}
2012-06-26 06:11:11 -------- d-----w- C:\Users\Home\AppData\Local\{ECA12399-AB30-4D1E-8EC8-6371DC3828CB}
2012-06-23 16:17:16 -------- d-----w- C:\Users\Home\AppData\Local\{93D42BAC-CCD2-4D3F-9024-1E8AA7A2F731}
2012-06-23 16:17:04 -------- d-----w- C:\Users\Home\AppData\Local\{9D44CC0A-F576-4537-BA17-18F03E0895B7}
2012-06-22 07:56:46 -------- d-----w- C:\Users\Home\AppData\Local\{7C4CCB26-8B73-4E01-9377-100252CB9666}
2012-06-22 07:56:34 -------- d-----w- C:\Users\Home\AppData\Local\{83D74644-DA9A-4414-8FD3-7A91DC2C7AAB}
2012-06-21 10:51:04 -------- d-----w- C:\Users\Home\AppData\Local\{6B338B42-5E85-4A33-A7A3-608D11FE5731}
2012-06-21 10:50:52 -------- d-----w- C:\Users\Home\AppData\Local\{EDD7E3E4-7399-4D7C-8AC3-04B81F4BA593}
2012-06-20 15:57:09 -------- d-----w- C:\Users\Home\AppData\Local\{90618171-3955-46BE-92CC-F7D37EF9EDF4}
2012-06-20 15:56:58 -------- d-----w- C:\Users\Home\AppData\Local\{8EFA0C53-9E92-4204-82AC-BA89664E6832}
2012-06-20 15:55:22 -------- d-----w- C:\Windows\en
2012-06-20 15:52:19 537432 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\DXSETUP.exe
2012-06-20 15:52:19 1801048 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\dsetup32.dll
2012-06-20 15:52:19 15712 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ac5144e11cd4efc02\MeshBetaRemover.exe
2012-06-20 15:52:18 89944 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\DSETUP.dll
2012-06-20 15:10:38 -------- d-----w- C:\Users\Home\AppData\Local\{B211EE25-8A70-4350-987F-3DEEB4E5B8B9}
2012-06-20 14:52:47 -------- d-----w- C:\Users\Home\AppData\Local\{4D5F9861-D7D6-47BF-A2CA-648D03703526}
2012-06-20 14:52:32 -------- d-----w- C:\Users\Home\AppData\Local\{2E510802-2BFD-4F78-80C8-2BAAE0A46AED}
2012-06-20 07:36:56 2622464 ----a-w- C:\Windows\System32\wucltux.dll
2012-06-20 07:36:48 99840 ----a-w- C:\Windows\System32\wudriver.dll
2012-06-20 07:36:37 36864 ----a-w- C:\Windows\System32\wuapp.exe
2012-06-20 07:36:37 186752 ----a-w- C:\Windows\System32\wuwebv.dll
2012-06-20 07:32:43 -------- d-----w- C:\Users\Home\AppData\Local\{84B78A5E-4C86-481A-91D6-CDB1BDBE78A6}
2012-06-20 07:32:21 -------- d-----w- C:\Users\Home\AppData\Local\{ADD0C457-A501-4921-8B2A-B3642874B909}
2012-06-20 06:31:56 -------- d-----w- C:\Users\Home\AppData\Local\{C01A2356-2BD7-4757-B97A-B2F8C029DF51}
2012-06-20 06:31:21 -------- d-----w- C:\Users\Home\AppData\Local\{06AF50B9-2091-4EFA-8CD4-09877A4F9A73}
2012-06-17 10:06:48 -------- d-----w- C:\Users\Home\AppData\Local\{8BCBE121-EF6D-47AD-BCA9-5B18C67ADC64}
2012-06-16 06:33:35 -------- d-----w- C:\Users\Home\AppData\Local\{0FD1DFF8-6722-4C49-AEBC-3E58FC3020A3}
.
==================== Find3M ====================
.
2012-07-15 19:52:03 328704 ----a-w- C:\Windows\System32\services.exe
2012-07-15 15:30:13 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-06-06 06:06:16 2004480 ----a-w- C:\Windows\System32\msxml6.dll
2012-06-06 06:06:16 1881600 ----a-w- C:\Windows\System32\msxml3.dll
2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll
2012-06-06 05:05:52 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll
2012-06-06 05:05:52 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll
2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll
2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys
2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll
2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll
2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll
2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2012-05-15 04:01:31 1188864 ----a-w- C:\Windows\System32\wininet.dll
2012-05-15 03:03:54 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-05-04 11:06:22 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-05-04 10:03:53 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03:50 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40:20 209920 ----a-w- C:\Windows\System32\profsvc.dll
2012-04-28 03:55:21 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-04-26 05:41:56 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-04-26 05:41:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-04-26 05:34:27 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-04-24 05:37:37 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2012-04-24 05:37:37 140288 ----a-w- C:\Windows\System32\cryptnet.dll
2012-04-24 05:37:36 1462272 ----a-w- C:\Windows\System32\crypt32.dll
2012-04-24 04:36:42 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- C:\Windows\SysWow64\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2012-04-20 03:45:41 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2012-04-20 03:16:44 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
.
============= FINISH: 0:14:36.32 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 15 July 2012 - 07:30 PM

Hello rooster4t,
  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

  • Finally, please reply using the ADD REPLY button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.

DO you have a Usb Flash drive you can use?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#3 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 16 July 2012 - 01:08 AM

Hi and thanks so much for the reply. Yes, I've got a USB flash drive.

#4 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 16 July 2012 - 04:21 PM

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt[*]In the command window type in notepad and press Enter.[*]The notepad opens. Under File menu select Open.[*]Select "Computer" and find your flash drive letter and close the notepad.[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.[*]The tool will start to run.[*]When the tool opens click Yes to disclaimer.[*]Press Scan button.[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list][/quote]

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#5 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 16 July 2012 - 04:51 PM

Hi Fireman4it - I've completed your request. The results are:


Scan result of Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 16-07-2012 22:43:49
Running from G:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
The current controlset is ControlSet001

========================== Registry (Whitelisted) =============

HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2731304 2011-03-24] (Synaptics Incorporated)
HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1933584 2010-11-02] (Intel® Corporation)
HKLM\...\Run: [TpShocks] TpShocks.exe [x]
HKLM\...\Run: [ForteConfig] C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2010-04-28] ()
HKLM\...\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe [167960 2011-03-30] (Intel Corporation)
HKLM\...\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe [391704 2011-03-30] (Intel Corporation)
HKLM\...\Run: [Persistence] C:\Windows\system32\igfxpers.exe [418840 2011-03-30] (Intel Corporation)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [41320 2011-01-27] (Lenovo Group Limited)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor [1522536 2011-02-03] (Lenovo Group Limited)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2010-11-29] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [421736 2011-07-19] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54840 2007-05-08] (Hewlett-Packard)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [36760 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [815512 2012-01-03] (Adobe Systems Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253672 2011-01-07] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation)
HKLM-x32\...\Run: [PSUNMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /Traybar [439616 2011-04-28] (Panda Security, S.L.)
HKU\Home\...\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation)
HKU\Home\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1242448 2011-12-26] (Valve Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll (Intel Corporation)
Tcpip\Parameters: [DhcpNameServer] 194.168.4.100 194.168.8.100
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)

==================== Services (Whitelisted) ======

2 btwdins; C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe [962848 2010-12-18] (Broadcom Corporation.)
2 HyperW7Svc; C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe [116072 2010-12-03] (Lenovo Group Limited)
2 IBMPMSVC; C:\Windows\System32\ibmpmsvc.exe [45928 2010-11-12] (Lenovo.)
2 LENOVO.CAMMUTE; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [40808 2011-01-27] (Lenovo Group Limited)
2 LENOVO.MICMUTE; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [45496 2010-11-23] (Lenovo Group Limited)
2 LENOVO.TPKNRSVC; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [59240 2011-01-27] (Lenovo Group Limited)
2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [93032 2010-04-06] (Lenovo Group Limited)
2 MBAMService; "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation)
3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-11-02] ()
2 NanoServiceMain; "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe" [140608 2011-04-28] (Panda Security, S.L.)
3 Power Manager DBC Service; "C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE" [79208 2011-02-03] (Lenovo)
2 SAService; C:\Windows\SysWow64\SAsrv.exe [446592 2010-11-18] (Conexant Systems, Inc.)
2 SUService; "C:\Program Files (x86)\Lenovo\System Update\SUService.exe" [28672 2010-11-25] (Lenovo Group Limited)
3 TPHDEXLGSVC; C:\Windows\System32\TPHDEXLG64.exe [47728 2011-01-13] (Lenovo.)
2 TPHKLOAD; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [114024 2010-12-02] (Lenovo Group Limited)
2 TPHKSVC; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [64440 2010-12-01] (Lenovo Group Limited)
2 UNS; "C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe" [2656280 2011-02-21] (Intel Corporation)

========================== Drivers (Whitelisted) =============

3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [24904 2012-07-03] (Malwarebytes Corporation)
1 PHCORE; \??\C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS [31592 2010-12-03] (Lenovo Group Limited)
2 PSINAflt; C:\Windows\System32\Drivers\PSINAflt.sys [161032 2012-01-05] (Panda Security, S.L.)
2 PSINFile; C:\Windows\System32\Drivers\PSINFile.sys [114760 2011-04-28] (Panda Security, S.L.)
1 PSINKNC; C:\Windows\System32\Drivers\PSINKNC.sys [149768 2011-11-23] (Panda Security, S.L.)
2 PSINProc; C:\Windows\System32\Drivers\PSINProc.sys [121928 2011-04-28] (Panda Security, S.L.)
2 PSINProt; C:\Windows\System32\Drivers\PSINProt.sys [128264 2011-11-30] (Panda Security, S.L.)
0 Shockprf; C:\Windows\System32\DRIVERS\Apsx64.sys [139888 2011-01-13] (Lenovo.)
0 TPDIGIMN; C:\Windows\System32\DRIVERS\ApsHM64.sys [23664 2011-01-13] (Lenovo.)
3 PCDSRVC{127174DC-C366ED8B-06020101}_0; \??\c:\program files\pc-doctor\pcdsrvc_x64.pkms [x]
4 PsBoot; C:\Windows\System32\Drivers\PsBoot.sys [x]

========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-07-16 13:31 - 2012-07-16 13:31 - 00000000 ____D C:\Users\Home\AppData\Local\{423F732D-92F7-4144-BB33-1258B2181773}
2012-07-16 13:30 - 2012-07-16 13:31 - 00000000 ____D C:\Users\Home\AppData\Local\{ED715286-DD55-4371-A1E7-1818CFE2BC3E}
2012-07-15 15:16 - 2012-07-15 15:16 - 00032059 ____A C:\Users\Home\Desktop\DDS.txt
2012-07-15 15:16 - 2012-07-15 15:16 - 00016312 ____A C:\Users\Home\Desktop\Attach.txt
2012-07-15 15:12 - 2012-07-15 15:12 - 00607260 ____R (Swearware) C:\Users\Home\Desktop\dds.scr
2012-07-15 15:11 - 2012-07-15 15:11 - 00000470 ____A C:\Users\Home\Desktop\defogger_disable.log
2012-07-15 15:11 - 2012-07-15 15:11 - 00000000 ____A C:\Users\Home\defogger_reenable
2012-07-15 15:10 - 2012-07-15 15:10 - 00050477 ____A C:\Users\Home\Desktop\Defogger.exe
2012-07-15 14:36 - 2012-07-15 14:36 - 00048930 ____A C:\Users\Home\Desktop\Extras.Txt
2012-07-15 14:34 - 2012-07-15 14:34 - 00101138 ____A C:\Users\Home\Desktop\OTL.Txt
2012-07-15 14:29 - 2012-07-15 14:29 - 00596480 ____A (OldTimer Tools) C:\Users\Home\Desktop\OTL.exe
2012-07-15 13:59 - 2012-07-16 13:29 - 00026690 ____A C:\Windows\SysWOW64\temp.txt
2012-07-15 13:59 - 2012-07-15 13:59 - 00000276 ____A C:\Windows\System32\PSUNCpl.dat
2012-07-15 13:59 - 2012-07-15 13:59 - 00000000 ____D C:\Users\Home\AppData\Roaming\Panda Security
2012-07-15 13:58 - 2012-07-15 13:58 - 00000000 ____D C:\Users\All Users\Panda Security
2012-07-15 13:58 - 2012-07-15 13:58 - 00000000 ____D C:\Program Files (x86)\Panda Security
2012-07-15 13:57 - 2012-07-15 13:57 - 00714392 ____A C:\Users\Home\Desktop\PandaCloudAntivirus.exe
2012-07-15 13:44 - 2012-07-15 13:44 - 00302592 ____A C:\Users\Home\Desktop\gn7zmtr4.exe
2012-07-15 13:28 - 2012-07-15 13:28 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Home\Desktop\tdsskiller.exe
2012-07-15 13:25 - 2012-07-15 13:25 - 04731392 ____A (AVAST Software) C:\Users\Home\Desktop\aswMBR.exe
2012-07-15 12:32 - 2012-07-15 13:01 - 00000000 ____D C:\Users\Home\AppData\Local\NPE
2012-07-15 12:28 - 2012-07-15 12:28 - 01805736 ____A (Symantec Corporation) C:\Users\Home\Downloads\FixZeroAccess.exe
2012-07-15 12:28 - 2012-07-15 12:28 - 00027256 ____A (Symantec Corporation) C:\Windows\System32\Drivers\FixZeroAccess.sys
2012-07-15 12:09 - 2012-07-15 12:09 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Home\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-15 12:09 - 2012-07-15 12:09 - 00001120 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-15 12:09 - 2012-07-15 12:09 - 00000000 ____D C:\Users\Home\AppData\Roaming\Malwarebytes
2012-07-15 12:09 - 2012-07-15 12:09 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-07-15 12:09 - 2012-07-15 12:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-07-15 12:09 - 2012-07-03 04:46 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-07-15 12:03 - 2012-07-15 12:07 - 00074057 ____A C:\Users\Home\Downloads\yorkyt.exe.log
2012-07-15 12:03 - 2012-07-15 12:03 - 01415784 ____A C:\Users\Home\Downloads\yorkyt.exe
2012-07-15 11:56 - 2012-07-15 11:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93687A1F6275BFBB
2012-07-15 11:44 - 2012-07-15 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A98691B144D9B1A1
2012-07-15 11:38 - 2012-07-15 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D480C11B1BC8FA6
2012-07-15 11:35 - 2012-07-15 11:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F36AE296F11AEA73
2012-07-15 11:31 - 2012-07-15 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2E0D6710C5178983
2012-07-15 11:29 - 2012-07-15 11:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15E9E681E7A1D354
2012-07-15 11:25 - 2012-07-15 11:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE84BF21F00F2466
2012-07-15 11:21 - 2012-07-15 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E256FB92A541C5C3
2012-07-15 07:33 - 2012-07-15 07:33 - 00000000 __SHD C:\Windows\System32\%APPDATA%
2012-07-15 07:30 - 2012-07-15 07:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-15 03:26 - 2012-07-15 03:26 - 00000000 ____D C:\Users\Home\AppData\Local\{FEDF202B-5638-4A89-AB62-D71DC04FDF72}
2012-07-15 03:25 - 2012-07-15 03:26 - 00000000 ____D C:\Users\Home\AppData\Local\{1D05CB46-2AA7-4B96-8B63-E6AC837BA48D}
2012-07-14 13:11 - 2012-07-14 13:11 - 00000000 ____D C:\Users\Home\AppData\Local\{3A7E0DBB-B034-4A65-8402-EAD10E9952FF}
2012-07-14 13:11 - 2012-07-14 13:11 - 00000000 ____D C:\Users\Home\AppData\Local\{1B2F83DC-4BC6-435B-880E-9BEC227A2C48}
2012-07-14 01:10 - 2012-07-14 01:10 - 00000000 ____D C:\Users\Home\AppData\Local\{743213FF-2645-46DB-9E5A-2350C52683DE}
2012-07-14 01:10 - 2012-07-14 01:10 - 00000000 ____D C:\Users\Home\AppData\Local\{38CC452C-8ABA-4CD1-B219-CECB25D0861F}
2012-07-13 10:43 - 2012-07-13 10:43 - 00000000 ____D C:\Users\Home\AppData\Local\{8349C0BC-9049-4D94-A0E6-4C24CE2AECCE}
2012-07-13 10:43 - 2012-07-13 10:43 - 00000000 ____D C:\Users\Home\AppData\Local\{3C8526C9-DD9D-4089-B49C-F1F467521500}
2012-07-12 22:02 - 2012-07-12 22:02 - 00000000 ____D C:\Users\Home\AppData\Local\{030377B2-7018-42D3-B0FD-E94F030CD351}
2012-07-12 22:01 - 2012-07-12 22:02 - 00000000 ____D C:\Users\Home\AppData\Local\{AB16D2DD-FAFB-4EFD-97D9-A55FD77C84C8}
2012-07-12 06:20 - 2012-07-12 06:20 - 00000000 ____D C:\Users\Home\AppData\Local\{953026DD-8E12-4E76-BDE0-0289D4B338E6}
2012-07-12 06:20 - 2012-07-12 06:20 - 00000000 ____D C:\Users\Home\AppData\Local\{05638CA4-825B-46A2-828C-54D3EB12ED44}
2012-07-11 22:19 - 2012-06-11 19:08 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-07-11 10:30 - 2012-07-11 10:30 - 00000000 ____D C:\Users\Home\AppData\Local\{F32B1028-5FFA-449C-BB8E-E84857880D79}
2012-07-11 10:30 - 2012-07-11 10:30 - 00000000 ____D C:\Users\Home\AppData\Local\{89449D27-7098-441C-B77C-75918985367F}
2012-07-11 00:47 - 2012-06-08 21:43 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-07-11 00:47 - 2012-06-08 20:41 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-07-11 00:47 - 2012-06-05 22:06 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-07-11 00:47 - 2012-06-05 22:06 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-07-11 00:47 - 2012-06-05 22:02 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-07-11 00:47 - 2012-06-05 21:05 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-07-11 00:47 - 2012-06-05 21:05 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-07-11 00:47 - 2012-06-05 21:03 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-07-11 00:47 - 2012-06-01 21:50 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-07-11 00:47 - 2012-06-01 21:48 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-07-11 00:47 - 2012-06-01 21:48 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-07-11 00:47 - 2012-06-01 21:45 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-07-11 00:47 - 2012-06-01 21:44 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-07-11 00:47 - 2012-06-01 20:40 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-07-11 00:47 - 2012-06-01 20:40 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-07-11 00:47 - 2012-06-01 20:39 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-07-11 00:47 - 2012-06-01 20:34 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-07-11 00:47 - 2010-06-25 19:55 - 00002048 ____A (Microsoft Corporation) C:\Windows\System32\msxml3r.dll
2012-07-11 00:47 - 2010-06-25 19:24 - 00002048 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2012-07-10 22:29 - 2012-07-10 22:29 - 00000000 ____D C:\Users\Home\AppData\Local\{D372AE28-256F-4CC7-BE13-F5A13C3F7999}
2012-07-10 22:29 - 2012-07-10 22:29 - 00000000 ____D C:\Users\Home\AppData\Local\{1835EAB7-1DD8-486B-AEE5-3FAC403E734D}
2012-07-10 06:21 - 2012-07-10 06:21 - 00000000 ____D C:\Users\Home\AppData\Local\{6D1DD9D4-2B8C-47C3-9539-14787491D3D0}
2012-07-10 06:21 - 2012-07-10 06:21 - 00000000 ____D C:\Users\Home\AppData\Local\{614FA0AC-7347-4047-8095-B6347055AAB8}
2012-07-09 10:43 - 2012-07-09 10:43 - 00000000 ____D C:\Users\Home\AppData\Local\{39CA7927-C320-4C31-891E-22176F65B9B5}
2012-07-09 10:42 - 2012-07-09 10:43 - 00000000 ____D C:\Users\Home\AppData\Local\{8C5C1385-2B7B-48AC-810D-E9145BB91201}
2012-07-08 22:38 - 2012-07-08 22:38 - 00000000 ____D C:\Users\Home\AppData\Local\{02048C16-30A2-453B-9165-2A5F1F645A58}
2012-07-08 22:37 - 2012-07-08 22:37 - 00000000 ____D C:\Users\Home\AppData\Local\{F2F29809-7049-42D7-AADE-9D0101DE327F}
2012-07-08 02:04 - 2012-07-08 02:05 - 00000000 ____D C:\Users\Home\AppData\Local\{4836B931-B3A8-4DAC-AB3F-403D2B714C51}
2012-07-08 02:04 - 2012-07-08 02:04 - 00000000 ____D C:\Users\Home\AppData\Local\{4BE5899C-3510-4A05-A035-99B9BE43AA68}
2012-07-07 01:47 - 2012-07-07 01:47 - 00000000 ____D C:\Users\Home\AppData\Local\{78FC7E15-34D8-421E-8DA6-DDEC88D8AFF3}
2012-07-07 01:47 - 2012-07-07 01:47 - 00000000 ____D C:\Users\Home\AppData\Local\{1974EAED-E5C8-4B68-BAB2-7CADC27B9479}
2012-07-06 00:47 - 2010-02-23 00:16 - 00294912 ____A (Microsoft Corporation) C:\Windows\System32\browserchoice.exe
2012-07-05 23:51 - 2012-07-05 23:51 - 00000000 ____D C:\Users\Home\AppData\Local\{FEDBC1FF-70A7-41CE-8FB0-5EE384F87CE0}
2012-07-05 23:51 - 2012-07-05 23:51 - 00000000 ____D C:\Users\Home\AppData\Local\{D4030680-A818-49B5-B5F8-5FBE35DDDFDB}
2012-07-05 06:31 - 2012-07-05 06:31 - 00000000 ____D C:\Users\Home\AppData\Local\{1A14A42C-E80C-4AB4-A9DD-56D70EF5D41F}
2012-07-05 06:30 - 2012-07-05 06:31 - 00000000 ____D C:\Users\Home\AppData\Local\{6AD5FF2C-056E-4B93-8489-F69D3B0523E2}
2012-07-04 05:58 - 2012-07-04 05:58 - 00000000 ____D C:\Users\Home\AppData\Local\{E763C98F-7C09-444F-B895-3C2C0F8BDA0F}
2012-07-04 05:58 - 2012-07-04 05:58 - 00000000 ____D C:\Users\Home\AppData\Local\{E26B61FF-9300-4C11-961C-A75467F62582}
2012-07-03 07:20 - 2012-07-03 07:20 - 00000000 ____D C:\Users\Home\AppData\Local\{972C4236-2528-42EF-82E0-B000A9DC6E6F}
2012-07-03 07:20 - 2012-07-03 07:20 - 00000000 ____D C:\Users\Home\AppData\Local\{14215009-F39F-4F90-9BCC-6419D75968E3}
2012-07-02 06:22 - 2012-07-02 06:22 - 00000000 ____D C:\Users\Home\AppData\Local\{EBC1F503-CA14-4F65-B7D7-0DDAB6A3FBBE}
2012-07-02 06:22 - 2012-07-02 06:22 - 00000000 ____D C:\Users\Home\AppData\Local\{5EA722CC-C449-4796-8F62-1946F4E239F8}
2012-07-01 02:01 - 2012-07-01 02:01 - 00000000 ____D C:\Users\Home\AppData\Local\{69806924-5CE4-4BD8-9492-BB79DA30E415}
2012-07-01 02:01 - 2012-07-01 02:01 - 00000000 ____D C:\Users\Home\AppData\Local\{01DB9544-897A-4E62-AB20-7416C04182B7}
2012-06-30 14:00 - 2012-06-30 14:01 - 00000000 ____D C:\Users\Home\AppData\Local\{015BE2A0-AE77-4932-81BE-B54459EA5C48}
2012-06-30 01:44 - 2012-06-30 14:00 - 00000000 ____D C:\Users\Home\AppData\Local\{6135528F-8BF6-45BA-B773-294D974544B9}
2012-06-30 01:44 - 2012-06-30 01:45 - 00000000 ____D C:\Users\Home\AppData\Local\{4482D9C9-A540-4461-AE7E-6575A99D5593}
2012-06-29 12:24 - 2012-06-29 12:25 - 00000000 ____D C:\Users\Home\AppData\Local\{57850179-BE5D-4E12-AD04-B4B98493B504}
2012-06-29 12:24 - 2012-06-29 12:24 - 00000000 ____D C:\Users\Home\AppData\Local\{69C69940-1E7A-4167-9CBF-D64665E35331}
2012-06-29 00:24 - 2012-06-29 00:24 - 00000000 ____D C:\Users\Home\AppData\Local\{E4BF7994-D285-4A57-B21E-68754E0C86A0}
2012-06-28 12:23 - 2012-06-29 00:24 - 00000000 ____D C:\Users\Home\AppData\Local\{45C529D0-E309-4E89-9DC5-45C8D481B1A3}
2012-06-28 12:23 - 2012-06-28 12:23 - 00000000 ____D C:\Users\Home\AppData\Local\{203FA65D-0D56-4F81-8D1A-0E4DC70FC426}
2012-06-28 00:22 - 2012-06-28 00:22 - 00000000 ____D C:\Users\Home\AppData\Local\{CCD8C754-FC35-4917-B74D-F5A202AFA519}
2012-06-28 00:22 - 2012-06-28 00:22 - 00000000 ____D C:\Users\Home\AppData\Local\{6C63CD9E-1798-4C8C-9E1D-725373AEA470}
2012-06-27 10:22 - 2012-06-27 10:22 - 00000000 ____D C:\Users\Home\AppData\Local\{A208C481-A507-45EE-A2EC-6DA0050488E7}
2012-06-26 22:21 - 2012-06-27 10:22 - 00000000 ____D C:\Users\Home\AppData\Local\{0936C949-07D4-4C76-856F-FAD197274906}
2012-06-26 22:21 - 2012-06-26 22:21 - 00000000 ____D C:\Users\Home\AppData\Local\{38EB443F-73B8-4CD7-8E58-9F9A39A4ACF3}
2012-06-26 10:12 - 2012-06-26 10:12 - 00000000 ____D C:\Users\Home\AppData\Local\{F0FEE1DC-F999-4B43-8022-FAD6E47080FE}
2012-06-26 10:11 - 2012-06-26 10:12 - 00000000 ____D C:\Users\Home\AppData\Local\{FEB52FFB-8907-48DE-803D-BEA62097C1D5}
2012-06-25 22:11 - 2012-06-25 22:11 - 00000000 ____D C:\Users\Home\AppData\Local\{ECA12399-AB30-4D1E-8EC8-6371DC3828CB}
2012-06-25 22:11 - 2012-06-25 22:11 - 00000000 ____D C:\Users\Home\AppData\Local\{4BAF97EA-0688-43AA-959D-8F675F17EECF}
2012-06-23 08:17 - 2012-06-23 08:17 - 00000000 ____D C:\Users\Home\AppData\Local\{9D44CC0A-F576-4537-BA17-18F03E0895B7}
2012-06-23 08:17 - 2012-06-23 08:17 - 00000000 ____D C:\Users\Home\AppData\Local\{93D42BAC-CCD2-4D3F-9024-1E8AA7A2F731}
2012-06-21 23:56 - 2012-06-21 23:56 - 00000000 ____D C:\Users\Home\AppData\Local\{83D74644-DA9A-4414-8FD3-7A91DC2C7AAB}
2012-06-21 23:56 - 2012-06-21 23:56 - 00000000 ____D C:\Users\Home\AppData\Local\{7C4CCB26-8B73-4E01-9377-100252CB9666}
2012-06-21 02:51 - 2012-06-21 02:51 - 00000000 ____D C:\Users\Home\AppData\Local\{6B338B42-5E85-4A33-A7A3-608D11FE5731}
2012-06-21 02:50 - 2012-06-21 02:51 - 00000000 ____D C:\Users\Home\AppData\Local\{EDD7E3E4-7399-4D7C-8AC3-04B81F4BA593}
2012-06-20 07:57 - 2012-06-20 07:57 - 00000000 ____D C:\Users\Home\AppData\Local\{90618171-3955-46BE-92CC-F7D37EF9EDF4}
2012-06-20 07:56 - 2012-06-20 07:57 - 00000000 ____D C:\Users\Home\AppData\Local\{8EFA0C53-9E92-4204-82AC-BA89664E6832}
2012-06-20 07:55 - 2012-06-20 07:55 - 00000000 ____D C:\Windows\en
2012-06-20 07:53 - 2012-06-20 07:53 - 00000000 ____D C:\Users\Home\Documents\Fax
2012-06-20 07:10 - 2012-06-20 07:10 - 00000000 ____D C:\Users\Home\AppData\Local\{B211EE25-8A70-4350-987F-3DEEB4E5B8B9}
2012-06-20 06:52 - 2012-06-20 07:10 - 00000000 ____D C:\Users\Home\AppData\Local\{2E510802-2BFD-4F78-80C8-2BAAE0A46AED}
2012-06-20 06:52 - 2012-06-20 06:52 - 00000000 ____D C:\Users\Home\AppData\Local\{4D5F9861-D7D6-47BF-A2CA-648D03703526}
2012-06-19 23:36 - 2012-06-02 14:19 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-19 23:36 - 2012-06-02 14:19 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-19 23:36 - 2012-06-02 14:19 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-19 23:36 - 2012-06-02 14:19 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-19 23:36 - 2012-06-02 14:19 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-19 23:36 - 2012-06-02 14:15 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-19 23:36 - 2012-06-02 14:15 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-19 23:36 - 2012-06-02 06:19 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-19 23:36 - 2012-06-02 06:15 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-19 23:32 - 2012-06-19 23:32 - 00000000 ____D C:\Users\Home\AppData\Local\{ADD0C457-A501-4921-8B2A-B3642874B909}
2012-06-19 23:32 - 2012-06-19 23:32 - 00000000 ____D C:\Users\Home\AppData\Local\{84B78A5E-4C86-481A-91D6-CDB1BDBE78A6}
2012-06-19 22:31 - 2012-06-19 22:32 - 00000000 ____D C:\Users\Home\AppData\Local\{C01A2356-2BD7-4757-B97A-B2F8C029DF51}
2012-06-19 22:31 - 2012-06-19 22:31 - 00000000 ____D C:\Users\Home\AppData\Local\{06AF50B9-2091-4EFA-8CD4-09877A4F9A73}
2012-06-17 02:06 - 2012-06-17 02:07 - 00000000 ____D C:\Users\Home\AppData\Local\{8BCBE121-EF6D-47AD-BCA9-5B18C67ADC64}


============ 3 Months Modified Files ========================

2012-07-16 13:37 - 2011-06-08 21:19 - 00000528 ____A C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2012-07-16 13:37 - 2009-07-13 20:45 - 00024608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-07-16 13:37 - 2009-07-13 20:45 - 00024608 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-07-16 13:33 - 2009-07-13 21:13 - 00726270 ____A C:\Windows\System32\PerfStringBackup.INI
2012-07-16 13:30 - 2011-06-08 21:19 - 00000382 ____A C:\Windows\Tasks\SystemToolsDailyTest.job
2012-07-16 13:29 - 2012-07-15 13:59 - 00026690 ____A C:\Windows\SysWOW64\temp.txt
2012-07-16 13:29 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-07-16 13:29 - 2009-07-13 20:51 - 00093965 ____A C:\Windows\setupact.log
2012-07-16 13:28 - 2010-11-20 19:47 - 00377286 ____A C:\Windows\PFRO.log
2012-07-15 15:16 - 2012-07-15 15:16 - 00032059 ____A C:\Users\Home\Desktop\DDS.txt
2012-07-15 15:16 - 2012-07-15 15:16 - 00016312 ____A C:\Users\Home\Desktop\Attach.txt
2012-07-15 15:12 - 2012-07-15 15:12 - 00607260 ____R (Swearware) C:\Users\Home\Desktop\dds.scr
2012-07-15 15:11 - 2012-07-15 15:11 - 00000470 ____A C:\Users\Home\Desktop\defogger_disable.log
2012-07-15 15:11 - 2012-07-15 15:11 - 00000000 ____A C:\Users\Home\defogger_reenable
2012-07-15 15:10 - 2012-07-15 15:10 - 00050477 ____A C:\Users\Home\Desktop\Defogger.exe
2012-07-15 14:36 - 2012-07-15 14:36 - 00048930 ____A C:\Users\Home\Desktop\Extras.Txt
2012-07-15 14:34 - 2012-07-15 14:34 - 00101138 ____A C:\Users\Home\Desktop\OTL.Txt
2012-07-15 14:29 - 2012-07-15 14:29 - 00596480 ____A (OldTimer Tools) C:\Users\Home\Desktop\OTL.exe
2012-07-15 13:59 - 2012-07-15 13:59 - 00000276 ____A C:\Windows\System32\PSUNCpl.dat
2012-07-15 13:57 - 2012-07-15 13:57 - 00714392 ____A C:\Users\Home\Desktop\PandaCloudAntivirus.exe
2012-07-15 13:44 - 2012-07-15 13:44 - 00302592 ____A C:\Users\Home\Desktop\gn7zmtr4.exe
2012-07-15 13:28 - 2012-07-15 13:28 - 02135640 ____A (Kaspersky Lab ZAO) C:\Users\Home\Desktop\tdsskiller.exe
2012-07-15 13:25 - 2012-07-15 13:25 - 04731392 ____A (AVAST Software) C:\Users\Home\Desktop\aswMBR.exe
2012-07-15 12:28 - 2012-07-15 12:28 - 01805736 ____A (Symantec Corporation) C:\Users\Home\Downloads\FixZeroAccess.exe
2012-07-15 12:28 - 2012-07-15 12:28 - 00027256 ____A (Symantec Corporation) C:\Windows\System32\Drivers\FixZeroAccess.sys
2012-07-15 12:09 - 2012-07-15 12:09 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Home\Downloads\mbam-setup-1.62.0.1300.exe
2012-07-15 12:09 - 2012-07-15 12:09 - 00001120 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-07-15 12:07 - 2012-07-15 12:03 - 00074057 ____A C:\Users\Home\Downloads\yorkyt.exe.log
2012-07-15 12:03 - 2012-07-15 12:03 - 01415784 ____A C:\Users\Home\Downloads\yorkyt.exe
2012-07-15 12:00 - 2011-06-26 07:42 - 00001945 ____A C:\Windows\epplauncher.mif
2012-07-15 11:56 - 2012-07-15 11:56 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.93687A1F6275BFBB
2012-07-15 11:52 - 2009-07-13 15:19 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe
2012-07-15 11:44 - 2012-07-15 11:44 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.A98691B144D9B1A1
2012-07-15 11:38 - 2012-07-15 11:38 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.5D480C11B1BC8FA6
2012-07-15 11:35 - 2012-07-15 11:35 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.F36AE296F11AEA73
2012-07-15 11:31 - 2012-07-15 11:31 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.2E0D6710C5178983
2012-07-15 11:29 - 2012-07-15 11:29 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.15E9E681E7A1D354
2012-07-15 11:25 - 2012-07-15 11:25 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.AE84BF21F00F2466
2012-07-15 11:21 - 2012-07-15 11:21 - 00328704 ____A (Microsoft Corporation) C:\Windows\System32\services.exe.E256FB92A541C5C3
2012-07-15 11:11 - 2011-06-08 20:58 - 01969588 ____A C:\Windows\WindowsUpdate.log
2012-07-15 11:10 - 2011-06-26 07:42 - 00735552 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2012-07-15 07:30 - 2012-07-15 07:30 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2012-07-15 07:30 - 2011-08-13 23:17 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2012-07-12 06:19 - 2011-06-14 10:36 - 00000891 ____A C:\Users\Home\Desktop\Downloads.lnk
2012-07-11 22:37 - 2009-07-13 20:45 - 00440512 ____A C:\Windows\System32\FNTCACHE.DAT
2012-07-11 22:19 - 2009-07-13 18:34 - 00000478 ____A C:\Windows\win.ini
2012-07-03 04:46 - 2012-07-15 12:09 - 00024904 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-06-20 07:53 - 2011-06-08 21:13 - 00235794 ____A C:\Windows\DirectX.log
2012-06-14 13:41 - 2012-06-14 13:15 - 00489984 ____A C:\Users\Home\Desktop\Q-13 early LCPD shut downs v2 20120614.pub
2012-06-11 19:08 - 2012-07-11 22:19 - 03148800 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-06-08 21:43 - 2012-07-11 00:47 - 14172672 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll
2012-06-08 20:41 - 2012-07-11 00:47 - 12873728 ____A (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2012-06-05 22:06 - 2012-07-11 00:47 - 02004480 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll
2012-06-05 22:06 - 2012-07-11 00:47 - 01881600 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll
2012-06-05 22:02 - 2012-07-11 00:47 - 01133568 ____A (Microsoft Corporation) C:\Windows\System32\cdosys.dll
2012-06-05 21:05 - 2012-07-11 00:47 - 01390080 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2012-06-05 21:05 - 2012-07-11 00:47 - 01236992 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2012-06-05 21:03 - 2012-07-11 00:47 - 00805376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2012-06-02 14:19 - 2012-06-19 23:36 - 02428952 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2012-06-02 14:19 - 2012-06-19 23:36 - 00701976 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2012-06-02 14:19 - 2012-06-19 23:36 - 00057880 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2012-06-02 14:19 - 2012-06-19 23:36 - 00044056 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll
2012-06-02 14:19 - 2012-06-19 23:36 - 00038424 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll
2012-06-02 14:15 - 2012-06-19 23:36 - 02622464 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2012-06-02 14:15 - 2012-06-19 23:36 - 00099840 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2012-06-02 06:19 - 2012-06-19 23:36 - 00186752 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2012-06-02 06:15 - 2012-06-19 23:36 - 00036864 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2012-06-01 21:50 - 2012-07-11 00:47 - 00458704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2012-06-01 21:48 - 2012-07-11 00:47 - 00151920 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2012-06-01 21:48 - 2012-07-11 00:47 - 00095600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2012-06-01 21:45 - 2012-07-11 00:47 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2012-06-01 21:44 - 2012-07-11 00:47 - 00307200 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2012-06-01 20:40 - 2012-07-11 00:47 - 00225280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2012-06-01 20:40 - 2012-07-11 00:47 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2012-06-01 20:39 - 2012-07-11 00:47 - 00219136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2012-06-01 20:34 - 2012-07-11 00:47 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2012-05-28 05:38 - 2009-07-13 21:08 - 00032608 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-05-14 20:01 - 2012-06-13 03:01 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-05-14 19:59 - 2012-06-13 03:01 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-05-14 19:03 - 2012-06-13 03:01 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-05-14 19:00 - 2012-06-13 03:01 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-05-07 05:34 - 2012-05-07 05:34 - 00001141 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2012-05-04 03:06 - 2012-06-13 03:01 - 05559664 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-04 02:03 - 2012-06-13 03:01 - 03968368 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2012-05-04 02:03 - 2012-06-13 03:01 - 03913072 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2012-04-30 21:40 - 2012-06-13 03:01 - 00209920 ____A (Microsoft Corporation) C:\Windows\System32\profsvc.dll
2012-04-29 09:20 - 2012-04-29 09:20 - 00109760 ____A C:\Users\Home\Documents\Nuclear Fission.pptx
2012-04-27 19:55 - 2012-06-13 03:01 - 00210944 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpwd.sys
2012-04-25 21:41 - 2012-06-13 03:01 - 00149504 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorekmts.dll
2012-04-25 21:41 - 2012-06-13 03:01 - 00077312 ____A (Microsoft Corporation) C:\Windows\System32\rdpwsx.dll
2012-04-25 21:34 - 2012-06-13 03:01 - 00009216 ____A (Microsoft Corporation) C:\Windows\System32\rdrmemptylst.exe
2012-04-23 21:37 - 2012-06-13 03:01 - 01462272 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2012-04-23 21:37 - 2012-06-13 03:01 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2012-04-23 21:37 - 2012-06-13 03:01 - 00140288 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2012-04-23 20:36 - 2012-06-13 03:01 - 01158656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2012-04-23 20:36 - 2012-06-13 03:01 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2012-04-23 20:36 - 2012-06-13 03:01 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 12297216 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 09059840 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 02454528 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 01494016 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 00735744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-04-19 21:42 - 2012-06-13 03:01 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-04-19 21:00 - 2012-06-13 03:01 - 01231360 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-04-19 21:00 - 2012-06-13 03:01 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-04-19 20:57 - 2012-06-13 03:01 - 06027776 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-04-19 20:57 - 2012-06-13 03:01 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-04-19 20:57 - 2012-06-13 03:01 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-04-19 20:56 - 2012-06-13 03:01 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-04-19 20:56 - 2012-06-13 03:01 - 02073600 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-04-19 20:56 - 2012-06-13 03:01 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-04-19 19:45 - 2012-06-13 03:01 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-04-19 19:16 - 2012-06-13 03:01 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb


ZeroAccess:
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\@
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\L
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U\00000001.@
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U\80000000.@
C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U\800000cb.@

ZeroAccess:
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27}
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\@
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\L
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U

========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

========================= Memory info ======================

Percentage of memory in use: 19%
Total physical RAM: 4007.23 MB
Available physical RAM: 3245.51 MB
Total Pagefile: 4005.43 MB
Available Pagefile: 3244.91 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

======================= Partitions =========================

1 Drive c: (Windows7_OS) (Fixed) (Total:287.15 GB) (Free:211.71 GB) NTFS ==>[System with boot components (obtained from reading drive)]
2 Drive e: (Lenovo_Recovery) (Fixed) (Total:9.77 GB) (Free:0.78 GB) NTFS
4 Drive g: () (Removable) (Total:0.12 GB) (Free:0.1 GB) FAT
5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
6 Drive y: (SYSTEM_DRV) (Fixed) (Total:1.17 GB) (Free:0.84 GB) NTFS ==>[System with boot components (obtained from reading drive)]

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 298 GB 0 B
Disk 1 Online 124 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 1200 MB 1024 KB
Partition 2 Primary 287 GB 1201 MB
Partition 3 Primary 9 GB 288 GB

==================================================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 Y SYSTEM_DRV NTFS Partition 1200 MB Healthy

==================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C Windows7_OS NTFS Partition 287 GB Healthy

==================================================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 E Lenovo_Reco NTFS Partition 9 GB Healthy

==================================================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 124 MB 16 KB

==================================================================================

Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 4 G FAT Removable 124 MB Healthy

==================================================================================

==========================================================

Last Boot: 2012-07-08 03:19

======================= End Of Log ==========================

#6 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 16 July 2012 - 05:20 PM

Hello,
We will fix those bad entries.


1.
Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27}
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27}

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.



2.
We need to find a replacement file on your system

Please do the following:

  • boot into System Recovery Options and run FRST64.
  • Type the following in the edit box after "Search:" so it looks like this:

    Search: services.exe

Click Search button and post the log it makes to your reply.



Things to include in your next reply::
fixlog.txt
Search log

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#7 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 16 July 2012 - 05:43 PM

ok, here we go:

Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 16-07-2012 02
Ran by SYSTEM at 2012-07-16 23:36:04 Run:1
Running from G:\

==============================================

C:\Windows\Installer\{bf83d6c1-5778-068c-640f-72bf52e1ee27} moved successfully.
C:\Users\Home\AppData\Local\{bf83d6c1-5778-068c-640f-72bf52e1ee27} moved successfully.

==== End of Fixlog ====





Farbar Recovery Scan Tool Version: 16-07-2012 02
Ran by SYSTEM at 2012-07-16 23:36:41
Running from G:\

================== Search: "services.exe" ===================

C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009-07-13 15:19] - [2009-07-13 17:39] - 0328704 ____A (Microsoft Corporation) 24ACB7E5BE595468E3B9AA488B9B4FCB

C:\Windows\System32\services.exe
[2009-07-13 15:19] - [2012-07-15 11:52] - 0328704 ____A (Microsoft Corporation) 014A9CB92514E27C0107614DF764BC06

====== End Of Search ======

#8 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 16 July 2012 - 05:52 PM

can't be sure but i think my problems started with a java update request...

#9 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 16 July 2012 - 07:39 PM

Hello,

We need to replace a bad file with a good one.

1.
Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

Replace: C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe  C:\Windows\System32\services.exe

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
On Windows XP: Now please boot into the BartPE CD.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#10 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 17 July 2012 - 02:26 AM

Done!


Fix result of Farbar Recovery Tool (FRST written by Farbar) Version: 16-07-2012 02
Ran by SYSTEM at 2012-07-17 08:22:14 Run:2
Running from G:\

==============================================

C:\Windows\System32\services.exe moved successfully.
C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe

==== End of Fixlog ====

#11 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 17 July 2012 - 01:41 PM

Hello,

Great job so far! :thumbup2:

Now that we have those fixed we can run our tools more successfully!


1.
Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not an option, Skip instead, do not choose Delete unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

2.
Install Recovery Console and Run ComboFix

This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • If you did not have it installed, you will see the prompt below. Choose YES.
  • Posted Image
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Posted Image
  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running.
ComboFix will restart your computer if malware is found; allow it to do so.


Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.




Things to include in your next reply::
TdssKiller log
Combofix.txt
How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#12 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 17 July 2012 - 04:15 PM

Hi there - thanks to your kind efforts I think that all's well! I ran TDSS and Combofix and all now seems to be working fine. The logs are detailed below:




08:32:20.0834 5116 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35
08:32:20.0943 5116 ============================================================
08:32:20.0943 5116 Current date / time: 2012/07/17 08:32:20.0943
08:32:20.0943 5116 SystemInfo:
08:32:20.0943 5116
08:32:20.0943 5116 OS Version: 6.1.7601 ServicePack: 1.0
08:32:20.0943 5116 Product type: Workstation
08:32:20.0943 5116 ComputerName: HOME-THINK
08:32:20.0943 5116 UserName: Home
08:32:20.0943 5116 Windows directory: C:\Windows
08:32:20.0943 5116 System windows directory: C:\Windows
08:32:20.0943 5116 Running under WOW64
08:32:20.0943 5116 Processor architecture: Intel x64
08:32:20.0943 5116 Number of processors: 4
08:32:20.0943 5116 Page size: 0x1000
08:32:20.0943 5116 Boot type: Normal boot
08:32:20.0943 5116 ============================================================
08:32:21.0380 5116 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
08:32:21.0380 5116 Drive \Device\Harddisk1\DR1 - Size: 0x7C7FE00 (0.12 Gb), SectorSize: 0x200, Cylinders: 0xF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
08:32:21.0380 5116 ============================================================
08:32:21.0380 5116 \Device\Harddisk0\DR0:
08:32:21.0380 5116 MBR partitions:
08:32:21.0380 5116 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x258000
08:32:21.0380 5116 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x258800, BlocksNum 0x23E4D800
08:32:21.0380 5116 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x240A6000, BlocksNum 0x1388000
08:32:21.0380 5116 \Device\Harddisk1\DR1:
08:32:21.0380 5116 MBR partitions:
08:32:21.0380 5116 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x6, StartLBA 0x20, BlocksNum 0x3E3DF
08:32:21.0380 5116 ============================================================
08:32:21.0505 5116 C: <-> \Device\Harddisk0\DR0\Partition1
08:32:21.0614 5116 Q: <-> \Device\Harddisk0\DR0\Partition2
08:32:21.0614 5116 ============================================================
08:32:21.0614 5116 Initialize success
08:32:21.0614 5116 ============================================================
08:32:32.0783 4856 ============================================================
08:32:32.0783 4856 Scan started
08:32:32.0783 4856 Mode: Manual;
08:32:32.0783 4856 ============================================================
08:32:33.0563 4856 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
08:32:33.0563 4856 1394ohci - ok
08:32:33.0641 4856 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
08:32:33.0641 4856 ACPI - ok
08:32:33.0704 4856 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
08:32:33.0704 4856 AcpiPmi - ok
08:32:33.0844 4856 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
08:32:33.0844 4856 adp94xx - ok
08:32:33.0969 4856 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
08:32:33.0985 4856 adpahci - ok
08:32:34.0000 4856 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
08:32:34.0000 4856 adpu320 - ok
08:32:34.0063 4856 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
08:32:34.0063 4856 AeLookupSvc - ok
08:32:34.0172 4856 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
08:32:34.0187 4856 AFD - ok
08:32:34.0187 4856 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
08:32:34.0187 4856 agp440 - ok
08:32:34.0203 4856 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
08:32:34.0203 4856 ALG - ok
08:32:34.0250 4856 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
08:32:34.0250 4856 aliide - ok
08:32:34.0265 4856 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
08:32:34.0265 4856 amdide - ok
08:32:34.0281 4856 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
08:32:34.0281 4856 AmdK8 - ok
08:32:34.0281 4856 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
08:32:34.0281 4856 AmdPPM - ok
08:32:34.0328 4856 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
08:32:34.0328 4856 amdsata - ok
08:32:34.0406 4856 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
08:32:34.0406 4856 amdsbs - ok
08:32:34.0421 4856 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
08:32:34.0421 4856 amdxata - ok
08:32:34.0453 4856 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
08:32:34.0453 4856 AppID - ok
08:32:34.0484 4856 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
08:32:34.0484 4856 AppIDSvc - ok
08:32:34.0531 4856 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
08:32:34.0546 4856 Appinfo - ok
08:32:34.0733 4856 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
08:32:34.0733 4856 Apple Mobile Device - ok
08:32:34.0780 4856 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
08:32:34.0780 4856 arc - ok
08:32:34.0796 4856 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
08:32:34.0796 4856 arcsas - ok
08:32:34.0843 4856 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
08:32:34.0843 4856 AsyncMac - ok
08:32:34.0889 4856 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
08:32:34.0889 4856 atapi - ok
08:32:35.0014 4856 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
08:32:35.0014 4856 AudioEndpointBuilder - ok
08:32:35.0030 4856 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
08:32:35.0030 4856 AudioSrv - ok
08:32:35.0201 4856 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
08:32:35.0201 4856 AxInstSV - ok
08:32:35.0295 4856 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
08:32:35.0311 4856 b06bdrv - ok
08:32:35.0373 4856 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
08:32:35.0373 4856 b57nd60a - ok
08:32:35.0482 4856 BBSvc (93ee7d9c35ae7e9ffda148d7805f1421) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
08:32:35.0482 4856 BBSvc - ok
08:32:35.0529 4856 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
08:32:35.0529 4856 BDESVC - ok
08:32:35.0576 4856 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
08:32:35.0576 4856 Beep - ok
08:32:35.0623 4856 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
08:32:35.0623 4856 blbdrive - ok
08:32:35.0779 4856 Bonjour Service (1c87705ccb2f60172b0fc86b5d82f00d) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
08:32:35.0779 4856 Bonjour Service - ok
08:32:35.0825 4856 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
08:32:35.0841 4856 bowser - ok
08:32:35.0888 4856 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
08:32:35.0888 4856 BrFiltLo - ok
08:32:35.0888 4856 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
08:32:35.0888 4856 BrFiltUp - ok
08:32:35.0919 4856 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
08:32:35.0919 4856 Browser - ok
08:32:35.0935 4856 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
08:32:35.0935 4856 Brserid - ok
08:32:35.0950 4856 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
08:32:35.0950 4856 BrSerWdm - ok
08:32:35.0950 4856 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
08:32:35.0950 4856 BrUsbMdm - ok
08:32:35.0966 4856 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
08:32:35.0966 4856 BrUsbSer - ok
08:32:36.0044 4856 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
08:32:36.0044 4856 BthEnum - ok
08:32:36.0091 4856 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
08:32:36.0091 4856 BTHMODEM - ok
08:32:36.0122 4856 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
08:32:36.0122 4856 BthPan - ok
08:32:36.0247 4856 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
08:32:36.0247 4856 BTHPORT - ok
08:32:36.0293 4856 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
08:32:36.0293 4856 bthserv - ok
08:32:36.0356 4856 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
08:32:36.0356 4856 BTHUSB - ok
08:32:36.0449 4856 BTWAMPFL (8834f87a6a745872894df8223201a6c3) C:\Windows\system32\DRIVERS\btwampfl.sys
08:32:36.0449 4856 BTWAMPFL - ok
08:32:36.0481 4856 btwaudio (9863d82ecbec6106d377ed73680d99d8) C:\Windows\system32\drivers\btwaudio.sys
08:32:36.0481 4856 btwaudio - ok
08:32:36.0543 4856 btwavdt (3432dd66ae75ab2de6d0527ad78dbfc7) C:\Windows\system32\DRIVERS\btwavdt.sys
08:32:36.0543 4856 btwavdt - ok
08:32:36.0761 4856 btwdins (eb4afe08fb39bb444f221d7d501e0915) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
08:32:36.0761 4856 btwdins - ok
08:32:36.0824 4856 btwl2cap (382dc5a631ced0462ea09b7eb898bdbf) C:\Windows\system32\DRIVERS\btwl2cap.sys
08:32:36.0824 4856 btwl2cap - ok
08:32:36.0839 4856 btwrchid (13a9c2cedd44c175e6ca39a536795ca6) C:\Windows\system32\DRIVERS\btwrchid.sys
08:32:36.0839 4856 btwrchid - ok
08:32:36.0886 4856 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
08:32:36.0902 4856 cdfs - ok
08:32:36.0964 4856 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
08:32:36.0964 4856 cdrom - ok
08:32:37.0011 4856 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
08:32:37.0011 4856 CertPropSvc - ok
08:32:37.0058 4856 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
08:32:37.0058 4856 circlass - ok
08:32:37.0105 4856 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
08:32:37.0105 4856 CLFS - ok
08:32:37.0198 4856 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:32:37.0198 4856 clr_optimization_v2.0.50727_32 - ok
08:32:37.0276 4856 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
08:32:37.0276 4856 clr_optimization_v2.0.50727_64 - ok
08:32:37.0354 4856 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:32:37.0354 4856 clr_optimization_v4.0.30319_32 - ok
08:32:37.0385 4856 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
08:32:37.0385 4856 clr_optimization_v4.0.30319_64 - ok
08:32:37.0448 4856 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
08:32:37.0448 4856 CmBatt - ok
08:32:37.0463 4856 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
08:32:37.0463 4856 cmdide - ok
08:32:37.0557 4856 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
08:32:37.0557 4856 CNG - ok
08:32:37.0760 4856 CnxtHdAudService (f50620115a751eff437cbaba0403600a) C:\Windows\system32\drivers\CHDRT64.sys
08:32:37.0775 4856 CnxtHdAudService - ok
08:32:38.0009 4856 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
08:32:38.0009 4856 Compbatt - ok
08:32:38.0119 4856 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
08:32:38.0119 4856 CompositeBus - ok
08:32:38.0134 4856 COMSysApp - ok
08:32:38.0165 4856 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
08:32:38.0165 4856 crcdisk - ok
08:32:38.0228 4856 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
08:32:38.0243 4856 CryptSvc - ok
08:32:38.0306 4856 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
08:32:38.0306 4856 DcomLaunch - ok
08:32:38.0431 4856 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
08:32:38.0446 4856 defragsvc - ok
08:32:38.0493 4856 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
08:32:38.0493 4856 DfsC - ok
08:32:38.0587 4856 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
08:32:38.0602 4856 Dhcp - ok
08:32:38.0665 4856 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
08:32:38.0665 4856 discache - ok
08:32:38.0758 4856 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
08:32:38.0758 4856 Disk - ok
08:32:38.0821 4856 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
08:32:38.0821 4856 Dnscache - ok
08:32:38.0867 4856 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
08:32:38.0867 4856 dot3svc - ok
08:32:38.0961 4856 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
08:32:38.0961 4856 Dot4 - ok
08:32:39.0039 4856 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys
08:32:39.0039 4856 Dot4Print - ok
08:32:39.0055 4856 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
08:32:39.0055 4856 dot4usb - ok
08:32:39.0086 4856 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
08:32:39.0086 4856 DPS - ok
08:32:39.0133 4856 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
08:32:39.0133 4856 drmkaud - ok
08:32:39.0273 4856 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
08:32:39.0273 4856 DXGKrnl - ok
08:32:39.0335 4856 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
08:32:39.0335 4856 EapHost - ok
08:32:39.0757 4856 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
08:32:39.0772 4856 ebdrv - ok
08:32:40.0115 4856 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
08:32:40.0115 4856 EFS - ok
08:32:40.0271 4856 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
08:32:40.0271 4856 ehRecvr - ok
08:32:40.0381 4856 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
08:32:40.0381 4856 ehSched - ok
08:32:40.0537 4856 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
08:32:40.0537 4856 elxstor - ok
08:32:40.0552 4856 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
08:32:40.0552 4856 ErrDev - ok
08:32:40.0817 4856 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
08:32:40.0817 4856 EventSystem - ok
08:32:41.0036 4856 EvtEng (f8f610093e1d7fdfa477fc34d15d5c60) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
08:32:41.0051 4856 EvtEng - ok
08:32:41.0161 4856 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
08:32:41.0161 4856 exfat - ok
08:32:41.0192 4856 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
08:32:41.0192 4856 fastfat - ok
08:32:41.0285 4856 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
08:32:41.0285 4856 Fax - ok
08:32:41.0301 4856 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
08:32:41.0301 4856 fdc - ok
08:32:41.0332 4856 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
08:32:41.0332 4856 fdPHost - ok
08:32:41.0363 4856 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
08:32:41.0363 4856 FDResPub - ok
08:32:41.0426 4856 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
08:32:41.0426 4856 FileInfo - ok
08:32:41.0441 4856 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
08:32:41.0441 4856 Filetrace - ok
08:32:41.0457 4856 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
08:32:41.0457 4856 flpydisk - ok
08:32:41.0488 4856 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
08:32:41.0488 4856 FltMgr - ok
08:32:41.0582 4856 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
08:32:41.0582 4856 FontCache - ok
08:32:41.0644 4856 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
08:32:41.0644 4856 FontCache3.0.0.0 - ok
08:32:41.0691 4856 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
08:32:41.0691 4856 FsDepends - ok
08:32:41.0753 4856 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
08:32:41.0753 4856 Fs_Rec - ok
08:32:41.0800 4856 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
08:32:41.0800 4856 fvevol - ok
08:32:41.0847 4856 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
08:32:41.0847 4856 gagp30kx - ok
08:32:41.0909 4856 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:32:41.0909 4856 GEARAspiWDM - ok
08:32:42.0003 4856 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
08:32:42.0019 4856 gpsvc - ok
08:32:42.0034 4856 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
08:32:42.0034 4856 hcw85cir - ok
08:32:42.0097 4856 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
08:32:42.0097 4856 HdAudAddService - ok
08:32:42.0128 4856 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
08:32:42.0128 4856 HDAudBus - ok
08:32:42.0143 4856 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
08:32:42.0143 4856 HidBatt - ok
08:32:42.0175 4856 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
08:32:42.0175 4856 HidBth - ok
08:32:42.0221 4856 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
08:32:42.0221 4856 HidIr - ok
08:32:42.0237 4856 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
08:32:42.0237 4856 hidserv - ok
08:32:42.0253 4856 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
08:32:42.0253 4856 HidUsb - ok
08:32:42.0315 4856 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
08:32:42.0315 4856 hkmsvc - ok
08:32:42.0346 4856 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
08:32:42.0346 4856 HomeGroupListener - ok
08:32:42.0393 4856 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
08:32:42.0393 4856 HomeGroupProvider - ok
08:32:42.0440 4856 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
08:32:42.0440 4856 HpSAMD - ok
08:32:43.0001 4856 HPSLPSVC (7f57926169c1b8aba9274ea7d4b70f18) C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
08:32:43.0017 4856 HPSLPSVC - ok
08:32:43.0235 4856 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
08:32:43.0251 4856 HTTP - ok
08:32:43.0298 4856 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
08:32:43.0298 4856 hwpolicy - ok
08:32:43.0407 4856 HyperW7Svc (9149907ff8681ad6475607eebf62dd2f) C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
08:32:43.0407 4856 HyperW7Svc - ok
08:32:43.0469 4856 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
08:32:43.0469 4856 i8042prt - ok
08:32:43.0547 4856 iaStor (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\DRIVERS\iaStor.sys
08:32:43.0563 4856 iaStor - ok
08:32:43.0657 4856 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
08:32:43.0672 4856 iaStorV - ok
08:32:43.0688 4856 IBMPMDRV (29ed470689b7c597a9701d6a4c57a578) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
08:32:43.0688 4856 IBMPMDRV - ok
08:32:43.0703 4856 IBMPMSVC (bc7af43eec24e995d770ec92a441d5d8) C:\Windows\system32\ibmpmsvc.exe
08:32:43.0703 4856 IBMPMSVC - ok
08:32:44.0140 4856 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
08:32:44.0156 4856 idsvc - ok
08:32:46.0699 4856 igfx (795c99dc4f574c97c03d0bb39cf099ee) C:\Windows\system32\DRIVERS\igdkmd64.sys
08:32:46.0917 4856 igfx - ok
08:32:47.0089 4856 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
08:32:47.0089 4856 iirsp - ok
08:32:47.0198 4856 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
08:32:47.0213 4856 IKEEXT - ok
08:32:47.0291 4856 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
08:32:47.0291 4856 IntcDAud - ok
08:32:47.0307 4856 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
08:32:47.0307 4856 intelide - ok
08:32:47.0369 4856 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
08:32:47.0369 4856 intelppm - ok
08:32:47.0432 4856 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
08:32:47.0432 4856 IPBusEnum - ok
08:32:47.0463 4856 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:32:47.0463 4856 IpFilterDriver - ok
08:32:47.0479 4856 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
08:32:47.0479 4856 IPMIDRV - ok
08:32:47.0541 4856 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
08:32:47.0541 4856 IPNAT - ok
08:32:47.0650 4856 iPod Service (fdf57f795098ab29af780824315c9859) C:\Program Files\iPod\bin\iPodService.exe
08:32:47.0650 4856 iPod Service - ok
08:32:47.0697 4856 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
08:32:47.0697 4856 IRENUM - ok
08:32:47.0713 4856 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
08:32:47.0713 4856 isapnp - ok
08:32:47.0759 4856 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
08:32:47.0775 4856 iScsiPrt - ok
08:32:48.0056 4856 jhi_service (6c85719a21b3f62c2c76280f4bd36c7b) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
08:32:48.0071 4856 jhi_service - ok
08:32:48.0103 4856 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
08:32:48.0118 4856 kbdclass - ok
08:32:48.0149 4856 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
08:32:48.0149 4856 kbdhid - ok
08:32:48.0181 4856 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:32:48.0181 4856 KeyIso - ok
08:32:48.0243 4856 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
08:32:48.0243 4856 KSecDD - ok
08:32:48.0305 4856 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
08:32:48.0305 4856 KSecPkg - ok
08:32:48.0352 4856 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
08:32:48.0352 4856 ksthunk - ok
08:32:48.0430 4856 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
08:32:48.0430 4856 KtmRm - ok
08:32:48.0524 4856 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
08:32:48.0539 4856 LanmanServer - ok
08:32:48.0555 4856 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
08:32:48.0571 4856 LanmanWorkstation - ok
08:32:48.0758 4856 LENOVO.CAMMUTE (646511b548d3799e576ecd46c6fe9ad3) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
08:32:48.0758 4856 LENOVO.CAMMUTE - ok
08:32:48.0836 4856 LENOVO.MICMUTE (fce735941da27929dbfc1918f286ffd8) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
08:32:48.0836 4856 LENOVO.MICMUTE - ok
08:32:48.0851 4856 lenovo.smi (2b9d8555dc004e240082d18e7725ce20) C:\Windows\system32\DRIVERS\smiifx64.sys
08:32:48.0851 4856 lenovo.smi - ok
08:32:48.0851 4856 LENOVO.TPKNRSVC (551e69c31eaf1577f1b2fa1681ba3078) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
08:32:48.0851 4856 LENOVO.TPKNRSVC - ok
08:32:48.0883 4856 Lenovo.VIRTSCRLSVC (6f2cc57eb5836d2ac9bd37f3554d55f8) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
08:32:48.0883 4856 Lenovo.VIRTSCRLSVC - ok
08:32:48.0945 4856 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
08:32:48.0945 4856 lltdio - ok
08:32:49.0023 4856 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
08:32:49.0023 4856 lltdsvc - ok
08:32:49.0070 4856 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
08:32:49.0070 4856 lmhosts - ok
08:32:49.0304 4856 LMS (e7859ba062db5e23c6dd34ad66b09f50) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
08:32:49.0319 4856 LMS - ok
08:32:49.0366 4856 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
08:32:49.0366 4856 LSI_FC - ok
08:32:49.0382 4856 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
08:32:49.0382 4856 LSI_SAS - ok
08:32:49.0382 4856 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
08:32:49.0397 4856 LSI_SAS2 - ok
08:32:49.0397 4856 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
08:32:49.0397 4856 LSI_SCSI - ok
08:32:49.0444 4856 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
08:32:49.0460 4856 luafv - ok
08:32:49.0538 4856 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
08:32:49.0538 4856 MBAMProtector - ok
08:32:49.0631 4856 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
08:32:49.0647 4856 MBAMService - ok
08:32:49.0678 4856 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
08:32:49.0678 4856 Mcx2Svc - ok
08:32:49.0725 4856 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
08:32:49.0725 4856 megasas - ok
08:32:49.0772 4856 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
08:32:49.0772 4856 MegaSR - ok
08:32:49.0787 4856 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
08:32:49.0787 4856 MEIx64 - ok
08:32:49.0850 4856 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
08:32:49.0850 4856 MMCSS - ok
08:32:49.0865 4856 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
08:32:49.0865 4856 Modem - ok
08:32:49.0897 4856 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
08:32:49.0897 4856 monitor - ok
08:32:49.0912 4856 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
08:32:49.0912 4856 mouclass - ok
08:32:49.0943 4856 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\drivers\mouhid.sys
08:32:49.0943 4856 mouhid - ok
08:32:49.0959 4856 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
08:32:49.0959 4856 mountmgr - ok
08:32:50.0053 4856 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
08:32:50.0053 4856 MozillaMaintenance - ok
08:32:50.0099 4856 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
08:32:50.0115 4856 mpio - ok
08:32:50.0115 4856 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
08:32:50.0131 4856 mpsdrv - ok
08:32:50.0146 4856 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
08:32:50.0146 4856 MRxDAV - ok
08:32:50.0193 4856 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:32:50.0193 4856 mrxsmb - ok
08:32:50.0255 4856 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:32:50.0255 4856 mrxsmb10 - ok
08:32:50.0287 4856 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:32:50.0287 4856 mrxsmb20 - ok
08:32:50.0302 4856 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
08:32:50.0318 4856 msahci - ok
08:32:50.0349 4856 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
08:32:50.0349 4856 msdsm - ok
08:32:50.0380 4856 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
08:32:50.0380 4856 MSDTC - ok
08:32:50.0411 4856 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
08:32:50.0411 4856 Msfs - ok
08:32:50.0458 4856 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
08:32:50.0458 4856 mshidkmdf - ok
08:32:50.0489 4856 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
08:32:50.0489 4856 msisadrv - ok
08:32:50.0521 4856 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
08:32:50.0521 4856 MSiSCSI - ok
08:32:50.0521 4856 msiserver - ok
08:32:50.0567 4856 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
08:32:50.0567 4856 MSKSSRV - ok
08:32:50.0583 4856 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
08:32:50.0583 4856 MSPCLOCK - ok
08:32:50.0583 4856 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
08:32:50.0583 4856 MSPQM - ok
08:32:50.0614 4856 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
08:32:50.0614 4856 MsRPC - ok
08:32:50.0645 4856 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
08:32:50.0645 4856 mssmbios - ok
08:32:50.0645 4856 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
08:32:50.0645 4856 MSTEE - ok
08:32:50.0661 4856 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
08:32:50.0661 4856 MTConfig - ok
08:32:50.0677 4856 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
08:32:50.0677 4856 Mup - ok
08:32:50.0770 4856 MyWiFiDHCPDNS (f6ea50dbc391f04ca49427010657ccb3) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
08:32:50.0786 4856 MyWiFiDHCPDNS - ok
08:32:51.0020 4856 NanoServiceMain (a830e59f98827943686e90bf79fc96fa) C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe
08:32:51.0035 4856 NanoServiceMain - ok
08:32:51.0082 4856 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
08:32:51.0098 4856 napagent - ok
08:32:51.0160 4856 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
08:32:51.0176 4856 NativeWifiP - ok
08:32:51.0269 4856 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
08:32:51.0285 4856 NDIS - ok
08:32:51.0332 4856 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
08:32:51.0332 4856 NdisCap - ok
08:32:51.0379 4856 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
08:32:51.0379 4856 NdisTapi - ok
08:32:51.0410 4856 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
08:32:51.0425 4856 Ndisuio - ok
08:32:51.0425 4856 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
08:32:51.0441 4856 NdisWan - ok
08:32:51.0441 4856 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
08:32:51.0441 4856 NDProxy - ok
08:32:51.0503 4856 Net Driver HPZ12 (d5ac41ae382738483faffbd7e373d49a) C:\Windows\system32\HPZinw12.dll
08:32:51.0503 4856 Net Driver HPZ12 - ok
08:32:51.0550 4856 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
08:32:51.0550 4856 NetBIOS - ok
08:32:51.0597 4856 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
08:32:51.0597 4856 NetBT - ok
08:32:51.0613 4856 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:32:51.0613 4856 Netlogon - ok
08:32:51.0675 4856 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
08:32:51.0691 4856 Netman - ok
08:32:51.0722 4856 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
08:32:51.0722 4856 netprofm - ok
08:32:51.0800 4856 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
08:32:51.0815 4856 NetTcpPortSharing - ok
08:32:53.0485 4856 NETwNs64 (30933bb56fb611d0252bad488adfb533) C:\Windows\system32\DRIVERS\NETwNs64.sys
08:32:53.0641 4856 NETwNs64 - ok
08:32:53.0984 4856 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
08:32:53.0984 4856 nfrd960 - ok
08:32:54.0046 4856 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
08:32:54.0046 4856 NlaSvc - ok
08:32:54.0062 4856 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
08:32:54.0062 4856 Npfs - ok
08:32:54.0077 4856 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
08:32:54.0077 4856 nsi - ok
08:32:54.0093 4856 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
08:32:54.0093 4856 nsiproxy - ok
08:32:54.0187 4856 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
08:32:54.0202 4856 Ntfs - ok
08:32:54.0296 4856 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
08:32:54.0296 4856 Null - ok
08:32:54.0343 4856 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
08:32:54.0358 4856 nvraid - ok
08:32:54.0405 4856 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
08:32:54.0405 4856 nvstor - ok
08:32:54.0467 4856 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
08:32:54.0467 4856 nv_agp - ok
08:32:54.0608 4856 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:32:54.0608 4856 odserv - ok
08:32:54.0686 4856 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
08:32:54.0686 4856 ohci1394 - ok
08:32:54.0795 4856 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:32:54.0811 4856 ose - ok
08:32:54.0889 4856 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
08:32:54.0889 4856 p2pimsvc - ok
08:32:54.0951 4856 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
08:32:54.0951 4856 p2psvc - ok
08:32:54.0982 4856 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
08:32:54.0982 4856 Parport - ok
08:32:55.0045 4856 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
08:32:55.0045 4856 partmgr - ok
08:32:55.0076 4856 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
08:32:55.0076 4856 PcaSvc - ok
08:32:55.0216 4856 PCDSRVC{127174DC-C366ED8B-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\pc-doctor\pcdsrvc_x64.pkms
08:32:55.0216 4856 PCDSRVC{127174DC-C366ED8B-06020101}_0 - ok
08:32:55.0263 4856 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
08:32:55.0263 4856 pci - ok
08:32:55.0279 4856 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
08:32:55.0279 4856 pciide - ok
08:32:55.0294 4856 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
08:32:55.0294 4856 pcmcia - ok
08:32:55.0310 4856 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
08:32:55.0310 4856 pcw - ok
08:32:55.0388 4856 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
08:32:55.0450 4856 PEAUTH - ok
08:32:55.0559 4856 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
08:32:55.0559 4856 PerfHost - ok
08:32:55.0622 4856 PHCORE (18eea095af22ac5fa16fc27fb98c82d3) C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS
08:32:55.0637 4856 PHCORE - ok
08:32:55.0840 4856 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
08:32:55.0871 4856 pla - ok
08:32:55.0965 4856 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
08:32:55.0965 4856 PlugPlay - ok
08:32:56.0027 4856 Pml Driver HPZ12 (37f6046cdc630442d7dc087501ff6fc6) C:\Windows\system32\HPZipm12.dll
08:32:56.0027 4856 Pml Driver HPZ12 - ok
08:32:56.0059 4856 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
08:32:56.0059 4856 PNRPAutoReg - ok
08:32:56.0105 4856 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
08:32:56.0105 4856 PNRPsvc - ok
08:32:56.0230 4856 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
08:32:56.0246 4856 PolicyAgent - ok
08:32:56.0308 4856 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
08:32:56.0308 4856 Power - ok
08:32:56.0449 4856 Power Manager DBC Service (21059f7e07233a24394405a7075362a1) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
08:32:56.0449 4856 Power Manager DBC Service - ok
08:32:56.0527 4856 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
08:32:56.0527 4856 PptpMiniport - ok
08:32:56.0558 4856 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
08:32:56.0558 4856 Processor - ok
08:32:56.0651 4856 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
08:32:56.0651 4856 ProfSvc - ok
08:32:56.0714 4856 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:32:56.0714 4856 ProtectedStorage - ok
08:32:56.0792 4856 psadd (515a7c5a0886fcc60901916785efd549) C:\Windows\system32\DRIVERS\psadd.sys
08:32:56.0792 4856 psadd - ok
08:32:56.0854 4856 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
08:32:56.0854 4856 Psched - ok
08:32:56.0932 4856 PSINAflt (bf6b640239be2c28a6bb43adc658fb7f) C:\Windows\system32\DRIVERS\PSINAflt.sys
08:32:56.0932 4856 PSINAflt - ok
08:32:56.0995 4856 PSINFile (2377f49c39725ed0021d75136fb0f746) C:\Windows\system32\DRIVERS\PSINFile.sys
08:32:56.0995 4856 PSINFile - ok
08:32:57.0041 4856 PSINKNC (a90f546b4f49122115768bc94bc81c04) C:\Windows\system32\DRIVERS\psinknc.sys
08:32:57.0041 4856 PSINKNC - ok
08:32:57.0073 4856 PSINProc (f8d7465cdd2a4ecae761ba8a0577d151) C:\Windows\system32\DRIVERS\PSINProc.sys
08:32:57.0073 4856 PSINProc - ok
08:32:57.0104 4856 PSINProt (076254556b4b03ade385619ff33e2f6b) C:\Windows\system32\DRIVERS\PSINProt.sys
08:32:57.0104 4856 PSINProt - ok
08:32:57.0322 4856 PSI_SVC_2 (f036cfb275d0c55f4e45fbbf5f98b3c8) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
08:32:57.0338 4856 PSI_SVC_2 - ok
08:32:57.0494 4856 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
08:32:57.0509 4856 ql2300 - ok
08:32:57.0603 4856 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
08:32:57.0603 4856 ql40xx - ok
08:32:57.0634 4856 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
08:32:57.0650 4856 QWAVE - ok
08:32:57.0665 4856 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
08:32:57.0665 4856 QWAVEdrv - ok
08:32:57.0681 4856 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
08:32:57.0681 4856 RasAcd - ok
08:32:57.0743 4856 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
08:32:57.0743 4856 RasAgileVpn - ok
08:32:57.0759 4856 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
08:32:57.0775 4856 RasAuto - ok
08:32:57.0790 4856 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:32:57.0806 4856 Rasl2tp - ok
08:32:57.0853 4856 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
08:32:57.0868 4856 RasMan - ok
08:32:57.0915 4856 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
08:32:57.0915 4856 RasPppoe - ok
08:32:57.0946 4856 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
08:32:57.0946 4856 RasSstp - ok
08:32:57.0977 4856 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
08:32:57.0977 4856 rdbss - ok
08:32:57.0993 4856 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
08:32:57.0993 4856 rdpbus - ok
08:32:58.0024 4856 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:32:58.0024 4856 RDPCDD - ok
08:32:58.0071 4856 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
08:32:58.0071 4856 RDPENCDD - ok
08:32:58.0102 4856 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
08:32:58.0102 4856 RDPREFMP - ok
08:32:58.0149 4856 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
08:32:58.0149 4856 RDPWD - ok
08:32:58.0180 4856 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
08:32:58.0180 4856 rdyboost - ok
08:32:58.0414 4856 RegSrvc (9276f4d4109fc349925d28e00e533146) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
08:32:58.0430 4856 RegSrvc - ok
08:32:58.0492 4856 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
08:32:58.0508 4856 RemoteAccess - ok
08:32:58.0555 4856 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
08:32:58.0555 4856 RemoteRegistry - ok
08:32:58.0742 4856 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
08:32:58.0742 4856 RFCOMM - ok
08:32:58.0804 4856 risdxc (ff501f212e5d5a97f8339928320f269e) C:\Windows\system32\DRIVERS\risdxc64.sys
08:32:58.0804 4856 risdxc - ok
08:32:58.0867 4856 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
08:32:58.0867 4856 RpcEptMapper - ok
08:32:58.0913 4856 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
08:32:58.0913 4856 RpcLocator - ok
08:32:58.0960 4856 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
08:32:58.0976 4856 RpcSs - ok
08:32:59.0007 4856 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
08:32:59.0007 4856 rspndr - ok
08:32:59.0069 4856 RTL8167 (a0d5b3adcd3fa83029c5e4d25e21ae93) C:\Windows\system32\DRIVERS\Rt64win7.sys
08:32:59.0069 4856 RTL8167 - ok
08:32:59.0132 4856 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:32:59.0132 4856 SamSs - ok
08:32:59.0147 4856 SAService - ok
08:32:59.0179 4856 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
08:32:59.0194 4856 sbp2port - ok
08:32:59.0225 4856 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
08:32:59.0225 4856 SCardSvr - ok
08:32:59.0257 4856 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
08:32:59.0257 4856 scfilter - ok
08:32:59.0350 4856 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
08:32:59.0366 4856 Schedule - ok
08:32:59.0475 4856 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
08:32:59.0491 4856 SCPolicySvc - ok
08:32:59.0553 4856 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
08:32:59.0569 4856 SDRSVC - ok
08:32:59.0709 4856 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
08:32:59.0709 4856 SeaPort - ok
08:32:59.0834 4856 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
08:32:59.0834 4856 secdrv - ok
08:32:59.0865 4856 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
08:32:59.0865 4856 seclogon - ok
08:32:59.0881 4856 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
08:32:59.0881 4856 SENS - ok
08:32:59.0927 4856 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
08:32:59.0927 4856 SensrSvc - ok
08:32:59.0943 4856 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
08:32:59.0959 4856 Serenum - ok
08:33:00.0005 4856 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
08:33:00.0005 4856 Serial - ok
08:33:00.0037 4856 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
08:33:00.0037 4856 sermouse - ok
08:33:00.0130 4856 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
08:33:00.0130 4856 SessionEnv - ok
08:33:00.0193 4856 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
08:33:00.0193 4856 sffdisk - ok
08:33:00.0208 4856 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
08:33:00.0208 4856 sffp_mmc - ok
08:33:00.0224 4856 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
08:33:00.0224 4856 sffp_sd - ok
08:33:00.0224 4856 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
08:33:00.0224 4856 sfloppy - ok
08:33:00.0271 4856 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
08:33:00.0286 4856 ShellHWDetection - ok
08:33:00.0302 4856 Shockprf (380b52126e62c6c2d3c8ba805aadfdc7) C:\Windows\system32\DRIVERS\Apsx64.sys
08:33:00.0302 4856 Shockprf - ok
08:33:00.0364 4856 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
08:33:00.0364 4856 SiSRaid2 - ok
08:33:00.0380 4856 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
08:33:00.0380 4856 SiSRaid4 - ok
08:33:00.0411 4856 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
08:33:00.0411 4856 Smb - ok
08:33:00.0458 4856 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
08:33:00.0458 4856 SNMPTRAP - ok
08:33:00.0473 4856 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
08:33:00.0473 4856 spldr - ok
08:33:00.0629 4856 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
08:33:00.0629 4856 Spooler - ok
08:33:01.0082 4856 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
08:33:01.0144 4856 sppsvc - ok
08:33:01.0316 4856 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
08:33:01.0316 4856 sppuinotify - ok
08:33:01.0409 4856 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
08:33:01.0409 4856 srv - ok
08:33:01.0456 4856 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
08:33:01.0472 4856 srv2 - ok
08:33:01.0487 4856 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
08:33:01.0487 4856 srvnet - ok
08:33:01.0565 4856 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
08:33:01.0565 4856 SSDPSRV - ok
08:33:01.0581 4856 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
08:33:01.0581 4856 SstpSvc - ok
08:33:01.0690 4856 Steam Client Service - ok
08:33:01.0737 4856 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
08:33:01.0737 4856 stexstor - ok
08:33:01.0799 4856 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
08:33:01.0799 4856 stisvc - ok
08:33:01.0924 4856 SUService (0586a2e9d4e6e18933c9a7d6d6eef70f) C:\Program Files (x86)\Lenovo\System Update\SUService.exe
08:33:01.0924 4856 SUService - ok
08:33:01.0971 4856 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
08:33:01.0971 4856 swenum - ok
08:33:02.0236 4856 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
08:33:02.0236 4856 swprv - ok
08:33:02.0377 4856 SynTP (06d602a637e171e151853f1d8ecd34f1) C:\Windows\system32\DRIVERS\SynTP.sys
08:33:02.0377 4856 SynTP - ok
08:33:03.0125 4856 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
08:33:03.0172 4856 SysMain - ok
08:33:03.0422 4856 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
08:33:03.0422 4856 TabletInputService - ok
08:33:03.0437 4856 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
08:33:03.0453 4856 TapiSrv - ok
08:33:03.0469 4856 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
08:33:03.0469 4856 TBS - ok
08:33:03.0890 4856 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
08:33:03.0921 4856 Tcpip - ok
08:33:04.0935 4856 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
08:33:04.0951 4856 TCPIP6 - ok
08:33:05.0372 4856 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
08:33:05.0372 4856 tcpipreg - ok
08:33:05.0387 4856 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
08:33:05.0387 4856 TDPIPE - ok
08:33:05.0434 4856 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
08:33:05.0434 4856 TDTCP - ok
08:33:05.0481 4856 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
08:33:05.0481 4856 tdx - ok
08:33:05.0497 4856 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
08:33:05.0497 4856 TermDD - ok
08:33:05.0949 4856 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
08:33:05.0965 4856 TermService - ok
08:33:05.0996 4856 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
08:33:05.0996 4856 Themes - ok
08:33:06.0043 4856 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
08:33:06.0043 4856 THREADORDER - ok
08:33:06.0105 4856 TPDIGIMN (5523c729f1ed31b63c88490af3d220fa) C:\Windows\system32\DRIVERS\ApsHM64.sys
08:33:06.0121 4856 TPDIGIMN - ok
08:33:06.0199 4856 TPHDEXLGSVC (ecb098a3404acb8a05f0673dc086bb43) C:\Windows\system32\TPHDEXLG64.exe
08:33:06.0199 4856 TPHDEXLGSVC - ok
08:33:06.0339 4856 TPHKLOAD (63626012e44caaa162677b57b6dcb542) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
08:33:06.0339 4856 TPHKLOAD - ok
08:33:06.0355 4856 TPHKSVC (9e6e4a9789f76593cc5a6a5af8fc5929) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
08:33:06.0355 4856 TPHKSVC - ok
08:33:06.0386 4856 TPM (dbcc20c02e8a3e43b03c304a4e40a84f) C:\Windows\system32\drivers\tpm.sys
08:33:06.0386 4856 TPM - ok
08:33:06.0448 4856 TPPWRIF (7165b5a9b4867f64a6d6935f57d4196b) C:\Windows\system32\drivers\Tppwr64v.sys
08:33:06.0448 4856 TPPWRIF - ok
08:33:06.0526 4856 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
08:33:06.0526 4856 TrkWks - ok
08:33:06.0589 4856 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
08:33:06.0589 4856 TrustedInstaller - ok
08:33:06.0604 4856 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:33:06.0604 4856 tssecsrv - ok
08:33:06.0635 4856 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
08:33:06.0635 4856 TsUsbFlt - ok
08:33:06.0667 4856 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
08:33:06.0667 4856 TsUsbGD - ok
08:33:06.0698 4856 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
08:33:06.0698 4856 tunnel - ok
08:33:06.0713 4856 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
08:33:06.0713 4856 uagp35 - ok
08:33:06.0745 4856 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
08:33:06.0760 4856 udfs - ok
08:33:06.0791 4856 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
08:33:06.0791 4856 UI0Detect - ok
08:33:06.0901 4856 UleadBurningHelper (be788a747457e6916586c410ec0111e7) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
08:33:06.0901 4856 UleadBurningHelper - ok
08:33:06.0979 4856 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
08:33:06.0979 4856 uliagpkx - ok
08:33:06.0994 4856 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
08:33:06.0994 4856 umbus - ok
08:33:07.0010 4856 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
08:33:07.0010 4856 UmPass - ok
08:33:07.0571 4856 UNS (e91f8afbd7fb96c94b266579d6bfa77a) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
08:33:07.0587 4856 UNS - ok
08:33:07.0852 4856 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
08:33:07.0852 4856 upnphost - ok
08:33:07.0946 4856 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
08:33:07.0946 4856 USBAAPL64 - ok
08:33:07.0977 4856 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
08:33:07.0977 4856 usbccgp - ok
08:33:08.0039 4856 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
08:33:08.0039 4856 usbcir - ok
08:33:08.0071 4856 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
08:33:08.0071 4856 usbehci - ok
08:33:08.0117 4856 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
08:33:08.0133 4856 usbhub - ok
08:33:08.0149 4856 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
08:33:08.0164 4856 usbohci - ok
08:33:08.0180 4856 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
08:33:08.0180 4856 usbprint - ok
08:33:08.0195 4856 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
08:33:08.0211 4856 usbscan - ok
08:33:08.0242 4856 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:33:08.0242 4856 USBSTOR - ok
08:33:08.0258 4856 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
08:33:08.0258 4856 usbuhci - ok
08:33:08.0273 4856 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
08:33:08.0289 4856 usbvideo - ok
08:33:08.0305 4856 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
08:33:08.0305 4856 UxSms - ok
08:33:08.0367 4856 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:33:08.0367 4856 VaultSvc - ok
08:33:08.0398 4856 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
08:33:08.0398 4856 vdrvroot - ok
08:33:08.0523 4856 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
08:33:08.0570 4856 vds - ok
08:33:08.0632 4856 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
08:33:08.0632 4856 vga - ok
08:33:08.0648 4856 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
08:33:08.0648 4856 VgaSave - ok
08:33:08.0663 4856 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
08:33:08.0663 4856 vhdmp - ok
08:33:08.0663 4856 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
08:33:08.0679 4856 viaide - ok
08:33:08.0695 4856 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
08:33:08.0695 4856 volmgr - ok
08:33:08.0726 4856 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
08:33:08.0726 4856 volmgrx - ok
08:33:08.0788 4856 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
08:33:08.0788 4856 volsnap - ok
08:33:08.0835 4856 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
08:33:08.0835 4856 vsmraid - ok
08:33:08.0960 4856 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
08:33:08.0975 4856 VSS - ok
08:33:09.0553 4856 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
08:33:09.0553 4856 vwifibus - ok
08:33:09.0568 4856 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
08:33:09.0568 4856 vwififlt - ok
08:33:09.0568 4856 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
08:33:09.0568 4856 vwifimp - ok
08:33:09.0646 4856 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
08:33:09.0662 4856 W32Time - ok
08:33:09.0677 4856 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
08:33:09.0677 4856 WacomPen - ok
08:33:09.0740 4856 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:33:09.0740 4856 WANARP - ok
08:33:09.0755 4856 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:33:09.0755 4856 Wanarpv6 - ok
08:33:10.0364 4856 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
08:33:10.0395 4856 WatAdminSvc - ok
08:33:10.0738 4856 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
08:33:10.0769 4856 wbengine - ok
08:33:11.0003 4856 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
08:33:11.0019 4856 WbioSrvc - ok
08:33:11.0050 4856 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
08:33:11.0066 4856 wcncsvc - ok
08:33:11.0081 4856 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
08:33:11.0081 4856 WcsPlugInService - ok
08:33:11.0128 4856 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
08:33:11.0128 4856 Wd - ok
08:33:11.0206 4856 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
08:33:11.0222 4856 Wdf01000 - ok
08:33:11.0237 4856 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
08:33:11.0237 4856 WdiServiceHost - ok
08:33:11.0237 4856 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
08:33:11.0253 4856 WdiSystemHost - ok
08:33:11.0269 4856 wdkmd (94dc2bf6cbaaa95e369c3756d3115a76) C:\Windows\system32\DRIVERS\WDKMD.sys
08:33:11.0269 4856 wdkmd - ok
08:33:11.0471 4856 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
08:33:11.0503 4856 WebClient - ok
08:33:11.0534 4856 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
08:33:11.0549 4856 Wecsvc - ok
08:33:11.0581 4856 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
08:33:11.0581 4856 wercplsupport - ok
08:33:11.0627 4856 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
08:33:11.0627 4856 WerSvc - ok
08:33:11.0659 4856 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
08:33:11.0659 4856 WfpLwf - ok
08:33:11.0674 4856 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
08:33:11.0674 4856 WIMMount - ok
08:33:11.0674 4856 WinHttpAutoProxySvc - ok
08:33:11.0752 4856 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
08:33:11.0752 4856 Winmgmt - ok
08:33:12.0329 4856 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
08:33:12.0392 4856 WinRM - ok
08:33:12.0751 4856 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
08:33:12.0751 4856 WinUsb - ok
08:33:13.0125 4856 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
08:33:13.0156 4856 Wlansvc - ok
08:33:13.0219 4856 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
08:33:13.0219 4856 wlcrasvc - ok
08:33:13.0640 4856 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:33:13.0702 4856 wlidsvc - ok
08:33:13.0983 4856 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
08:33:13.0983 4856 WmiAcpi - ok
08:33:14.0155 4856 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
08:33:14.0170 4856 wmiApSrv - ok
08:33:14.0186 4856 WMPNetworkSvc - ok
08:33:14.0248 4856 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
08:33:14.0248 4856 WPCSvc - ok
08:33:14.0264 4856 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
08:33:14.0279 4856 WPDBusEnum - ok
08:33:14.0295 4856 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
08:33:14.0295 4856 ws2ifsl - ok
08:33:14.0342 4856 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
08:33:14.0342 4856 WSDPrintDevice - ok
08:33:14.0342 4856 WSearch - ok
08:33:14.0373 4856 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
08:33:14.0373 4856 WudfPf - ok
08:33:14.0435 4856 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:33:14.0451 4856 WUDFRd - ok
08:33:14.0467 4856 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
08:33:14.0467 4856 wudfsvc - ok
08:33:14.0529 4856 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
08:33:14.0529 4856 WwanSvc - ok
08:33:14.0576 4856 MBR (0x1B8) (8ac4476c6870641b94b6e5c6e57b06af) \Device\Harddisk0\DR0
08:33:15.0059 4856 \Device\Harddisk0\DR0 - ok
08:33:15.0059 4856 MBR (0x1B8) (e5fa06aca0d60ba9c870d0ef3d9898c9) \Device\Harddisk1\DR1
08:33:17.0197 4856 \Device\Harddisk1\DR1 - ok
08:33:17.0197 4856 Boot (0x1200) (2a5a2d1eb66444e9041d5fe1d0003b79) \Device\Harddisk0\DR0\Partition0
08:33:17.0197 4856 \Device\Harddisk0\DR0\Partition0 - ok
08:33:17.0212 4856 Boot (0x1200) (7b61e0e6a5259a2edb4b0ac2cf74a04e) \Device\Harddisk0\DR0\Partition1
08:33:17.0212 4856 \Device\Harddisk0\DR0\Partition1 - ok
08:33:17.0243 4856 Boot (0x1200) (dade9de89a5885164057725133adb196) \Device\Harddisk0\DR0\Partition2
08:33:17.0243 4856 \Device\Harddisk0\DR0\Partition2 - ok
08:33:17.0243 4856 Boot (0x1200) (740fcfe5064bbd9dbef1dccc15f37cdf) \Device\Harddisk1\DR1\Partition0
08:33:17.0243 4856 \Device\Harddisk1\DR1\Partition0 - ok
08:33:17.0243 4856 ============================================================
08:33:17.0243 4856 Scan finished
08:33:17.0243 4856 ============================================================
08:33:17.0259 3636 Detected object count: 0
08:33:17.0259 3636 Actual detected object count: 0
08:38:36.0467 3444 ============================================================
08:38:36.0467 3444 Scan started
08:38:36.0467 3444 Mode: Manual;
08:38:36.0467 3444 ============================================================
08:38:36.0935 3444 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
08:38:36.0935 3444 1394ohci - ok
08:38:36.0997 3444 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
08:38:36.0997 3444 ACPI - ok
08:38:36.0997 3444 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
08:38:36.0997 3444 AcpiPmi - ok
08:38:37.0060 3444 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
08:38:37.0075 3444 adp94xx - ok
08:38:37.0106 3444 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
08:38:37.0106 3444 adpahci - ok
08:38:37.0122 3444 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
08:38:37.0122 3444 adpu320 - ok
08:38:37.0200 3444 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
08:38:37.0200 3444 AeLookupSvc - ok
08:38:37.0294 3444 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
08:38:37.0294 3444 AFD - ok
08:38:37.0340 3444 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
08:38:37.0340 3444 agp440 - ok
08:38:37.0372 3444 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
08:38:37.0372 3444 ALG - ok
08:38:37.0372 3444 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
08:38:37.0372 3444 aliide - ok
08:38:37.0387 3444 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
08:38:37.0387 3444 amdide - ok
08:38:37.0387 3444 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
08:38:37.0387 3444 AmdK8 - ok
08:38:37.0418 3444 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
08:38:37.0418 3444 AmdPPM - ok
08:38:37.0450 3444 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
08:38:37.0450 3444 amdsata - ok
08:38:37.0481 3444 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
08:38:37.0481 3444 amdsbs - ok
08:38:37.0496 3444 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
08:38:37.0496 3444 amdxata - ok
08:38:37.0512 3444 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
08:38:37.0512 3444 AppID - ok
08:38:37.0528 3444 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
08:38:37.0528 3444 AppIDSvc - ok
08:38:37.0543 3444 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
08:38:37.0543 3444 Appinfo - ok
08:38:37.0637 3444 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
08:38:37.0637 3444 Apple Mobile Device - ok
08:38:37.0652 3444 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
08:38:37.0652 3444 arc - ok
08:38:37.0668 3444 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
08:38:37.0668 3444 arcsas - ok
08:38:37.0684 3444 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
08:38:37.0699 3444 AsyncMac - ok
08:38:37.0699 3444 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
08:38:37.0699 3444 atapi - ok
08:38:37.0777 3444 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
08:38:37.0777 3444 AudioEndpointBuilder - ok
08:38:37.0793 3444 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
08:38:37.0793 3444 AudioSrv - ok
08:38:37.0824 3444 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
08:38:37.0824 3444 AxInstSV - ok
08:38:37.0871 3444 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
08:38:37.0871 3444 b06bdrv - ok
08:38:37.0918 3444 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
08:38:37.0918 3444 b57nd60a - ok
08:38:37.0980 3444 BBSvc (93ee7d9c35ae7e9ffda148d7805f1421) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
08:38:37.0996 3444 BBSvc - ok
08:38:38.0011 3444 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
08:38:38.0027 3444 BDESVC - ok
08:38:38.0027 3444 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
08:38:38.0042 3444 Beep - ok
08:38:38.0058 3444 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
08:38:38.0058 3444 blbdrive - ok
08:38:38.0136 3444 Bonjour Service (1c87705ccb2f60172b0fc86b5d82f00d) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
08:38:38.0136 3444 Bonjour Service - ok
08:38:38.0167 3444 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
08:38:38.0167 3444 bowser - ok
08:38:38.0183 3444 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
08:38:38.0183 3444 BrFiltLo - ok
08:38:38.0183 3444 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
08:38:38.0183 3444 BrFiltUp - ok
08:38:38.0214 3444 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
08:38:38.0214 3444 Browser - ok
08:38:38.0245 3444 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
08:38:38.0245 3444 Brserid - ok
08:38:38.0261 3444 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
08:38:38.0261 3444 BrSerWdm - ok
08:38:38.0261 3444 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
08:38:38.0261 3444 BrUsbMdm - ok
08:38:38.0276 3444 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
08:38:38.0276 3444 BrUsbSer - ok
08:38:38.0308 3444 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
08:38:38.0308 3444 BthEnum - ok
08:38:38.0323 3444 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
08:38:38.0323 3444 BTHMODEM - ok
08:38:38.0354 3444 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
08:38:38.0354 3444 BthPan - ok
08:38:38.0417 3444 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
08:38:38.0432 3444 BTHPORT - ok
08:38:38.0464 3444 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
08:38:38.0464 3444 bthserv - ok
08:38:38.0479 3444 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
08:38:38.0479 3444 BTHUSB - ok
08:38:38.0557 3444 BTWAMPFL (8834f87a6a745872894df8223201a6c3) C:\Windows\system32\DRIVERS\btwampfl.sys
08:38:38.0557 3444 BTWAMPFL - ok
08:38:38.0620 3444 btwaudio (9863d82ecbec6106d377ed73680d99d8) C:\Windows\system32\drivers\btwaudio.sys
08:38:38.0620 3444 btwaudio - ok
08:38:38.0635 3444 btwavdt (3432dd66ae75ab2de6d0527ad78dbfc7) C:\Windows\system32\DRIVERS\btwavdt.sys
08:38:38.0635 3444 btwavdt - ok
08:38:38.0744 3444 btwdins (eb4afe08fb39bb444f221d7d501e0915) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
08:38:38.0760 3444 btwdins - ok
08:38:38.0776 3444 btwl2cap (382dc5a631ced0462ea09b7eb898bdbf) C:\Windows\system32\DRIVERS\btwl2cap.sys
08:38:38.0776 3444 btwl2cap - ok
08:38:38.0807 3444 btwrchid (13a9c2cedd44c175e6ca39a536795ca6) C:\Windows\system32\DRIVERS\btwrchid.sys
08:38:38.0807 3444 btwrchid - ok
08:38:38.0838 3444 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
08:38:38.0838 3444 cdfs - ok
08:38:38.0854 3444 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
08:38:38.0869 3444 cdrom - ok
08:38:38.0885 3444 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
08:38:38.0885 3444 CertPropSvc - ok
08:38:38.0900 3444 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
08:38:38.0900 3444 circlass - ok
08:38:38.0947 3444 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
08:38:38.0947 3444 CLFS - ok
08:38:39.0025 3444 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:38:39.0025 3444 clr_optimization_v2.0.50727_32 - ok
08:38:39.0088 3444 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
08:38:39.0088 3444 clr_optimization_v2.0.50727_64 - ok
08:38:39.0119 3444 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:38:39.0119 3444 clr_optimization_v4.0.30319_32 - ok
08:38:39.0150 3444 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
08:38:39.0150 3444 clr_optimization_v4.0.30319_64 - ok
08:38:39.0181 3444 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
08:38:39.0181 3444 CmBatt - ok
08:38:39.0197 3444 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
08:38:39.0197 3444 cmdide - ok
08:38:39.0259 3444 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
08:38:39.0259 3444 CNG - ok
08:38:39.0368 3444 CnxtHdAudService (f50620115a751eff437cbaba0403600a) C:\Windows\system32\drivers\CHDRT64.sys
08:38:39.0368 3444 CnxtHdAudService - ok
08:38:39.0478 3444 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
08:38:39.0478 3444 Compbatt - ok
08:38:39.0493 3444 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
08:38:39.0493 3444 CompositeBus - ok
08:38:39.0493 3444 COMSysApp - ok
08:38:39.0509 3444 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
08:38:39.0509 3444 crcdisk - ok
08:38:39.0556 3444 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
08:38:39.0556 3444 CryptSvc - ok
08:38:39.0634 3444 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
08:38:39.0634 3444 DcomLaunch - ok
08:38:39.0680 3444 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
08:38:39.0680 3444 defragsvc - ok
08:38:39.0712 3444 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
08:38:39.0712 3444 DfsC - ok
08:38:39.0743 3444 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
08:38:39.0743 3444 Dhcp - ok
08:38:39.0774 3444 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
08:38:39.0774 3444 discache - ok
08:38:39.0790 3444 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
08:38:39.0790 3444 Disk - ok
08:38:39.0821 3444 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
08:38:39.0836 3444 Dnscache - ok
08:38:39.0868 3444 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
08:38:39.0868 3444 dot3svc - ok
08:38:39.0914 3444 Dot4 (b42ed0320c6e41102fde0005154849bb) C:\Windows\system32\DRIVERS\Dot4.sys
08:38:39.0914 3444 Dot4 - ok
08:38:39.0930 3444 Dot4Print (e9f5969233c5d89f3c35e3a66a52a361) C:\Windows\system32\DRIVERS\Dot4Prt.sys
08:38:39.0930 3444 Dot4Print - ok
08:38:39.0930 3444 dot4usb (fd05a02b0370bc3000f402e543ca5814) C:\Windows\system32\DRIVERS\dot4usb.sys
08:38:39.0930 3444 dot4usb - ok
08:38:39.0961 3444 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
08:38:39.0961 3444 DPS - ok
08:38:39.0992 3444 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
08:38:39.0992 3444 drmkaud - ok
08:38:40.0070 3444 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
08:38:40.0086 3444 DXGKrnl - ok
08:38:40.0117 3444 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
08:38:40.0117 3444 EapHost - ok
08:38:40.0289 3444 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
08:38:40.0320 3444 ebdrv - ok
08:38:40.0445 3444 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
08:38:40.0445 3444 EFS - ok
08:38:40.0538 3444 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
08:38:40.0538 3444 ehRecvr - ok
08:38:40.0570 3444 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
08:38:40.0570 3444 ehSched - ok
08:38:40.0648 3444 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
08:38:40.0648 3444 elxstor - ok
08:38:40.0663 3444 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
08:38:40.0663 3444 ErrDev - ok
08:38:40.0710 3444 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
08:38:40.0710 3444 EventSystem - ok
08:38:40.0850 3444 EvtEng (f8f610093e1d7fdfa477fc34d15d5c60) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
08:38:40.0866 3444 EvtEng - ok
08:38:40.0991 3444 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
08:38:40.0991 3444 exfat - ok
08:38:41.0022 3444 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
08:38:41.0022 3444 fastfat - ok
08:38:41.0084 3444 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
08:38:41.0100 3444 Fax - ok
08:38:41.0116 3444 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
08:38:41.0116 3444 fdc - ok
08:38:41.0162 3444 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
08:38:41.0162 3444 fdPHost - ok
08:38:41.0209 3444 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
08:38:41.0209 3444 FDResPub - ok
08:38:41.0240 3444 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
08:38:41.0240 3444 FileInfo - ok
08:38:41.0256 3444 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
08:38:41.0256 3444 Filetrace - ok
08:38:41.0272 3444 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
08:38:41.0272 3444 flpydisk - ok
08:38:41.0303 3444 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
08:38:41.0303 3444 FltMgr - ok
08:38:41.0412 3444 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
08:38:41.0412 3444 FontCache - ok
08:38:41.0474 3444 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
08:38:41.0474 3444 FontCache3.0.0.0 - ok
08:38:41.0521 3444 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
08:38:41.0521 3444 FsDepends - ok
08:38:41.0537 3444 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
08:38:41.0552 3444 Fs_Rec - ok
08:38:41.0568 3444 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
08:38:41.0568 3444 fvevol - ok
08:38:41.0599 3444 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
08:38:41.0599 3444 gagp30kx - ok
08:38:41.0646 3444 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
08:38:41.0646 3444 GEARAspiWDM - ok
08:38:41.0740 3444 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
08:38:41.0740 3444 gpsvc - ok
08:38:41.0755 3444 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
08:38:41.0755 3444 hcw85cir - ok
08:38:41.0802 3444 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
08:38:41.0802 3444 HdAudAddService - ok
08:38:41.0833 3444 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
08:38:41.0833 3444 HDAudBus - ok
08:38:41.0849 3444 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
08:38:41.0849 3444 HidBatt - ok
08:38:41.0864 3444 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
08:38:41.0864 3444 HidBth - ok
08:38:41.0880 3444 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
08:38:41.0880 3444 HidIr - ok
08:38:41.0896 3444 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
08:38:41.0896 3444 hidserv - ok
08:38:41.0911 3444 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
08:38:41.0911 3444 HidUsb - ok
08:38:41.0942 3444 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
08:38:41.0942 3444 hkmsvc - ok
08:38:41.0974 3444 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
08:38:41.0974 3444 HomeGroupListener - ok
08:38:42.0020 3444 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
08:38:42.0020 3444 HomeGroupProvider - ok
08:38:42.0036 3444 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
08:38:42.0036 3444 HpSAMD - ok
08:38:42.0176 3444 HPSLPSVC (7f57926169c1b8aba9274ea7d4b70f18) C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
08:38:42.0192 3444 HPSLPSVC - ok
08:38:42.0254 3444 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
08:38:42.0270 3444 HTTP - ok
08:38:42.0270 3444 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
08:38:42.0270 3444 hwpolicy - ok
08:38:42.0332 3444 HyperW7Svc (9149907ff8681ad6475607eebf62dd2f) C:\Program Files\Lenovo\RapidBoot\HyperW7Svc64.exe
08:38:42.0332 3444 HyperW7Svc - ok
08:38:42.0364 3444 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
08:38:42.0364 3444 i8042prt - ok
08:38:42.0410 3444 iaStor (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\DRIVERS\iaStor.sys
08:38:42.0426 3444 iaStor - ok
08:38:42.0473 3444 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
08:38:42.0473 3444 iaStorV - ok
08:38:42.0504 3444 IBMPMDRV (29ed470689b7c597a9701d6a4c57a578) C:\Windows\system32\DRIVERS\ibmpmdrv.sys
08:38:42.0504 3444 IBMPMDRV - ok
08:38:42.0520 3444 IBMPMSVC (bc7af43eec24e995d770ec92a441d5d8) C:\Windows\system32\ibmpmsvc.exe
08:38:42.0520 3444 IBMPMSVC - ok
08:38:42.0644 3444 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
08:38:42.0644 3444 idsvc - ok
08:38:43.0284 3444 igfx (795c99dc4f574c97c03d0bb39cf099ee) C:\Windows\system32\DRIVERS\igdkmd64.sys
08:38:43.0393 3444 igfx - ok
08:38:43.0596 3444 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
08:38:43.0596 3444 iirsp - ok
08:38:43.0690 3444 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
08:38:43.0705 3444 IKEEXT - ok
08:38:43.0752 3444 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
08:38:43.0752 3444 IntcDAud - ok
08:38:43.0768 3444 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
08:38:43.0768 3444 intelide - ok
08:38:43.0799 3444 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
08:38:43.0799 3444 intelppm - ok
08:38:43.0814 3444 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
08:38:43.0814 3444 IPBusEnum - ok
08:38:43.0846 3444 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
08:38:43.0846 3444 IpFilterDriver - ok
08:38:43.0861 3444 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
08:38:43.0861 3444 IPMIDRV - ok
08:38:43.0877 3444 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
08:38:43.0877 3444 IPNAT - ok
08:38:43.0970 3444 iPod Service (fdf57f795098ab29af780824315c9859) C:\Program Files\iPod\bin\iPodService.exe
08:38:43.0986 3444 iPod Service - ok
08:38:44.0002 3444 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
08:38:44.0002 3444 IRENUM - ok
08:38:44.0017 3444 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
08:38:44.0017 3444 isapnp - ok
08:38:44.0048 3444 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
08:38:44.0064 3444 iScsiPrt - ok
08:38:44.0142 3444 jhi_service (6c85719a21b3f62c2c76280f4bd36c7b) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
08:38:44.0142 3444 jhi_service - ok
08:38:44.0158 3444 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
08:38:44.0158 3444 kbdclass - ok
08:38:44.0189 3444 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
08:38:44.0189 3444 kbdhid - ok
08:38:44.0251 3444 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:38:44.0251 3444 KeyIso - ok
08:38:44.0282 3444 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
08:38:44.0298 3444 KSecDD - ok
08:38:44.0345 3444 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
08:38:44.0345 3444 KSecPkg - ok
08:38:44.0345 3444 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
08:38:44.0360 3444 ksthunk - ok
08:38:44.0407 3444 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
08:38:44.0407 3444 KtmRm - ok
08:38:44.0454 3444 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
08:38:44.0454 3444 LanmanServer - ok
08:38:44.0485 3444 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
08:38:44.0485 3444 LanmanWorkstation - ok
08:38:44.0563 3444 LENOVO.CAMMUTE (646511b548d3799e576ecd46c6fe9ad3) C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
08:38:44.0563 3444 LENOVO.CAMMUTE - ok
08:38:44.0594 3444 LENOVO.MICMUTE (fce735941da27929dbfc1918f286ffd8) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
08:38:44.0610 3444 LENOVO.MICMUTE - ok
08:38:44.0610 3444 lenovo.smi (2b9d8555dc004e240082d18e7725ce20) C:\Windows\system32\DRIVERS\smiifx64.sys
08:38:44.0610 3444 lenovo.smi - ok
08:38:44.0626 3444 LENOVO.TPKNRSVC (551e69c31eaf1577f1b2fa1681ba3078) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
08:38:44.0626 3444 LENOVO.TPKNRSVC - ok
08:38:44.0657 3444 Lenovo.VIRTSCRLSVC (6f2cc57eb5836d2ac9bd37f3554d55f8) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
08:38:44.0657 3444 Lenovo.VIRTSCRLSVC - ok
08:38:44.0672 3444 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
08:38:44.0672 3444 lltdio - ok
08:38:44.0704 3444 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
08:38:44.0719 3444 lltdsvc - ok
08:38:44.0735 3444 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
08:38:44.0735 3444 lmhosts - ok
08:38:44.0813 3444 LMS (e7859ba062db5e23c6dd34ad66b09f50) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
08:38:44.0828 3444 LMS - ok
08:38:44.0844 3444 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
08:38:44.0844 3444 LSI_FC - ok
08:38:44.0860 3444 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
08:38:44.0860 3444 LSI_SAS - ok
08:38:44.0875 3444 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
08:38:44.0875 3444 LSI_SAS2 - ok
08:38:44.0875 3444 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
08:38:44.0875 3444 LSI_SCSI - ok
08:38:44.0906 3444 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
08:38:44.0906 3444 luafv - ok
08:38:44.0922 3444 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
08:38:44.0922 3444 MBAMProtector - ok
08:38:45.0016 3444 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
08:38:45.0016 3444 MBAMService - ok
08:38:45.0062 3444 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
08:38:45.0062 3444 Mcx2Svc - ok
08:38:45.0094 3444 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
08:38:45.0094 3444 megasas - ok
08:38:45.0125 3444 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
08:38:45.0125 3444 MegaSR - ok
08:38:45.0156 3444 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
08:38:45.0156 3444 MEIx64 - ok
08:38:45.0187 3444 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
08:38:45.0187 3444 MMCSS - ok
08:38:45.0203 3444 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
08:38:45.0203 3444 Modem - ok
08:38:45.0218 3444 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
08:38:45.0234 3444 monitor - ok
08:38:45.0250 3444 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
08:38:45.0250 3444 mouclass - ok
08:38:45.0250 3444 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\drivers\mouhid.sys
08:38:45.0250 3444 mouhid - ok
08:38:45.0265 3444 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
08:38:45.0265 3444 mountmgr - ok
08:38:45.0328 3444 MozillaMaintenance (96aa8ba23142cc8e2b30f3cae0c80254) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
08:38:45.0328 3444 MozillaMaintenance - ok
08:38:45.0359 3444 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
08:38:45.0359 3444 mpio - ok
08:38:45.0374 3444 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
08:38:45.0374 3444 mpsdrv - ok
08:38:45.0390 3444 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
08:38:45.0390 3444 MRxDAV - ok
08:38:45.0437 3444 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
08:38:45.0437 3444 mrxsmb - ok
08:38:45.0484 3444 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
08:38:45.0484 3444 mrxsmb10 - ok
08:38:45.0499 3444 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
08:38:45.0499 3444 mrxsmb20 - ok
08:38:45.0515 3444 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
08:38:45.0530 3444 msahci - ok
08:38:45.0546 3444 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
08:38:45.0546 3444 msdsm - ok
08:38:45.0577 3444 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
08:38:45.0577 3444 MSDTC - ok
08:38:45.0608 3444 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
08:38:45.0608 3444 Msfs - ok
08:38:45.0608 3444 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
08:38:45.0608 3444 mshidkmdf - ok
08:38:45.0624 3444 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
08:38:45.0624 3444 msisadrv - ok
08:38:45.0655 3444 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
08:38:45.0655 3444 MSiSCSI - ok
08:38:45.0655 3444 msiserver - ok
08:38:45.0671 3444 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
08:38:45.0686 3444 MSKSSRV - ok
08:38:45.0686 3444 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
08:38:45.0686 3444 MSPCLOCK - ok
08:38:45.0702 3444 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
08:38:45.0702 3444 MSPQM - ok
08:38:45.0733 3444 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
08:38:45.0733 3444 MsRPC - ok
08:38:45.0764 3444 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
08:38:45.0764 3444 mssmbios - ok
08:38:45.0764 3444 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
08:38:45.0764 3444 MSTEE - ok
08:38:45.0780 3444 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
08:38:45.0780 3444 MTConfig - ok
08:38:45.0796 3444 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
08:38:45.0796 3444 Mup - ok
08:38:45.0874 3444 MyWiFiDHCPDNS (f6ea50dbc391f04ca49427010657ccb3) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
08:38:45.0874 3444 MyWiFiDHCPDNS - ok
08:38:46.0045 3444 NanoServiceMain (a830e59f98827943686e90bf79fc96fa) C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe
08:38:46.0061 3444 NanoServiceMain - ok
08:38:46.0123 3444 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
08:38:46.0123 3444 napagent - ok
08:38:46.0170 3444 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
08:38:46.0170 3444 NativeWifiP - ok
08:38:46.0248 3444 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
08:38:46.0248 3444 NDIS - ok
08:38:46.0279 3444 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
08:38:46.0279 3444 NdisCap - ok
08:38:46.0295 3444 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
08:38:46.0295 3444 NdisTapi - ok
08:38:46.0310 3444 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
08:38:46.0310 3444 Ndisuio - ok
08:38:46.0326 3444 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
08:38:46.0326 3444 NdisWan - ok
08:38:46.0342 3444 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
08:38:46.0342 3444 NDProxy - ok
08:38:46.0388 3444 Net Driver HPZ12 (d5ac41ae382738483faffbd7e373d49a) C:\Windows\system32\HPZinw12.dll
08:38:46.0388 3444 Net Driver HPZ12 - ok
08:38:46.0404 3444 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
08:38:46.0404 3444 NetBIOS - ok
08:38:46.0435 3444 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
08:38:46.0451 3444 NetBT - ok
08:38:46.0466 3444 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:38:46.0466 3444 Netlogon - ok
08:38:46.0529 3444 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
08:38:46.0529 3444 Netman - ok
08:38:46.0576 3444 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
08:38:46.0576 3444 netprofm - ok
08:38:46.0638 3444 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
08:38:46.0638 3444 NetTcpPortSharing - ok
08:38:47.0090 3444 NETwNs64 (30933bb56fb611d0252bad488adfb533) C:\Windows\system32\DRIVERS\NETwNs64.sys
08:38:47.0184 3444 NETwNs64 - ok
08:38:47.0293 3444 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
08:38:47.0293 3444 nfrd960 - ok
08:38:47.0340 3444 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
08:38:47.0340 3444 NlaSvc - ok
08:38:47.0356 3444 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
08:38:47.0356 3444 Npfs - ok
08:38:47.0371 3444 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
08:38:47.0371 3444 nsi - ok
08:38:47.0387 3444 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
08:38:47.0387 3444 nsiproxy - ok
08:38:47.0621 3444 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
08:38:47.0636 3444 Ntfs - ok
08:38:47.0746 3444 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
08:38:47.0746 3444 Null - ok
08:38:47.0792 3444 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
08:38:47.0792 3444 nvraid - ok
08:38:47.0824 3444 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
08:38:47.0824 3444 nvstor - ok
08:38:47.0839 3444 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
08:38:47.0839 3444 nv_agp - ok
08:38:47.0933 3444 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
08:38:47.0948 3444 odserv - ok
08:38:47.0964 3444 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
08:38:47.0964 3444 ohci1394 - ok
08:38:47.0995 3444 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:38:47.0995 3444 ose - ok
08:38:48.0058 3444 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
08:38:48.0058 3444 p2pimsvc - ok
08:38:48.0104 3444 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
08:38:48.0104 3444 p2psvc - ok
08:38:48.0136 3444 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
08:38:48.0136 3444 Parport - ok
08:38:48.0167 3444 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
08:38:48.0167 3444 partmgr - ok
08:38:48.0214 3444 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
08:38:48.0214 3444 PcaSvc - ok
08:38:48.0276 3444 PCDSRVC{127174DC-C366ED8B-06020101}_0 (7317a0b550f7ac0223b7070897670476) c:\program files\pc-doctor\pcdsrvc_x64.pkms
08:38:48.0276 3444 PCDSRVC{127174DC-C366ED8B-06020101}_0 - ok
08:38:48.0307 3444 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
08:38:48.0307 3444 pci - ok
08:38:48.0323 3444 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
08:38:48.0323 3444 pciide - ok
08:38:48.0354 3444 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
08:38:48.0354 3444 pcmcia - ok
08:38:48.0354 3444 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
08:38:48.0370 3444 pcw - ok
08:38:48.0416 3444 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
08:38:48.0416 3444 PEAUTH - ok
08:38:48.0510 3444 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
08:38:48.0510 3444 PerfHost - ok
08:38:48.0588 3444 PHCORE (18eea095af22ac5fa16fc27fb98c82d3) C:\Program Files\Lenovo\RapidBoot\PHCORE64.SYS
08:38:48.0588 3444 PHCORE - ok
08:38:48.0697 3444 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
08:38:48.0713 3444 pla - ok
08:38:48.0775 3444 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
08:38:48.0775 3444 PlugPlay - ok
08:38:48.0806 3444 Pml Driver HPZ12 (37f6046cdc630442d7dc087501ff6fc6) C:\Windows\system32\HPZipm12.dll
08:38:48.0806 3444 Pml Driver HPZ12 - ok
08:38:48.0838 3444 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
08:38:48.0838 3444 PNRPAutoReg - ok
08:38:48.0884 3444 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
08:38:48.0884 3444 PNRPsvc - ok
08:38:48.0931 3444 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
08:38:48.0931 3444 PolicyAgent - ok
08:38:48.0978 3444 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
08:38:48.0978 3444 Power - ok
08:38:49.0040 3444 Power Manager DBC Service (21059f7e07233a24394405a7075362a1) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
08:38:49.0056 3444 Power Manager DBC Service - ok
08:38:49.0103 3444 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
08:38:49.0103 3444 PptpMiniport - ok
08:38:49.0118 3444 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
08:38:49.0118 3444 Processor - ok
08:38:49.0165 3444 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
08:38:49.0165 3444 ProfSvc - ok
08:38:49.0212 3444 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:38:49.0212 3444 ProtectedStorage - ok
08:38:49.0228 3444 psadd (515a7c5a0886fcc60901916785efd549) C:\Windows\system32\DRIVERS\psadd.sys
08:38:49.0228 3444 psadd - ok
08:38:49.0259 3444 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
08:38:49.0259 3444 Psched - ok
08:38:49.0306 3444 PSINAflt (bf6b640239be2c28a6bb43adc658fb7f) C:\Windows\system32\DRIVERS\PSINAflt.sys
08:38:49.0306 3444 PSINAflt - ok
08:38:49.0321 3444 PSINFile (2377f49c39725ed0021d75136fb0f746) C:\Windows\system32\DRIVERS\PSINFile.sys
08:38:49.0321 3444 PSINFile - ok
08:38:49.0352 3444 PSINKNC (a90f546b4f49122115768bc94bc81c04) C:\Windows\system32\DRIVERS\psinknc.sys
08:38:49.0352 3444 PSINKNC - ok
08:38:49.0368 3444 PSINProc (f8d7465cdd2a4ecae761ba8a0577d151) C:\Windows\system32\DRIVERS\PSINProc.sys
08:38:49.0384 3444 PSINProc - ok
08:38:49.0399 3444 PSINProt (076254556b4b03ade385619ff33e2f6b) C:\Windows\system32\DRIVERS\PSINProt.sys
08:38:49.0399 3444 PSINProt - ok
08:38:49.0462 3444 PSI_SVC_2 (f036cfb275d0c55f4e45fbbf5f98b3c8) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
08:38:49.0462 3444 PSI_SVC_2 - ok
08:38:49.0571 3444 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
08:38:49.0586 3444 ql2300 - ok
08:38:49.0758 3444 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
08:38:49.0758 3444 ql40xx - ok
08:38:49.0789 3444 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
08:38:49.0789 3444 QWAVE - ok
08:38:49.0820 3444 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
08:38:49.0820 3444 QWAVEdrv - ok
08:38:49.0820 3444 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
08:38:49.0820 3444 RasAcd - ok
08:38:49.0852 3444 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
08:38:49.0852 3444 RasAgileVpn - ok
08:38:49.0867 3444 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
08:38:49.0867 3444 RasAuto - ok
08:38:49.0898 3444 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
08:38:49.0898 3444 Rasl2tp - ok
08:38:49.0961 3444 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
08:38:49.0961 3444 RasMan - ok
08:38:49.0976 3444 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
08:38:49.0976 3444 RasPppoe - ok
08:38:49.0992 3444 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
08:38:49.0992 3444 RasSstp - ok
08:38:50.0023 3444 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
08:38:50.0039 3444 rdbss - ok
08:38:50.0054 3444 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
08:38:50.0054 3444 rdpbus - ok
08:38:50.0070 3444 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
08:38:50.0070 3444 RDPCDD - ok
08:38:50.0086 3444 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
08:38:50.0086 3444 RDPENCDD - ok
08:38:50.0086 3444 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
08:38:50.0086 3444 RDPREFMP - ok
08:38:50.0132 3444 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
08:38:50.0132 3444 RDPWD - ok
08:38:50.0164 3444 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
08:38:50.0164 3444 rdyboost - ok
08:38:50.0288 3444 RegSrvc (9276f4d4109fc349925d28e00e533146) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
08:38:50.0288 3444 RegSrvc - ok
08:38:50.0335 3444 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
08:38:50.0335 3444 RemoteAccess - ok
08:38:50.0366 3444 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
08:38:50.0382 3444 RemoteRegistry - ok
08:38:50.0444 3444 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
08:38:50.0444 3444 RFCOMM - ok
08:38:50.0460 3444 risdxc (ff501f212e5d5a97f8339928320f269e) C:\Windows\system32\DRIVERS\risdxc64.sys
08:38:50.0476 3444 risdxc - ok
08:38:50.0507 3444 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
08:38:50.0507 3444 RpcEptMapper - ok
08:38:50.0522 3444 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
08:38:50.0522 3444 RpcLocator - ok
08:38:50.0569 3444 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
08:38:50.0585 3444 RpcSs - ok
08:38:50.0616 3444 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
08:38:50.0616 3444 rspndr - ok
08:38:50.0663 3444 RTL8167 (a0d5b3adcd3fa83029c5e4d25e21ae93) C:\Windows\system32\DRIVERS\Rt64win7.sys
08:38:50.0663 3444 RTL8167 - ok
08:38:50.0710 3444 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:38:50.0710 3444 SamSs - ok
08:38:50.0710 3444 SAService - ok
08:38:50.0725 3444 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
08:38:50.0725 3444 sbp2port - ok
08:38:50.0772 3444 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
08:38:50.0772 3444 SCardSvr - ok
08:38:50.0803 3444 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
08:38:50.0803 3444 scfilter - ok
08:38:50.0881 3444 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
08:38:50.0897 3444 Schedule - ok
08:38:50.0912 3444 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
08:38:50.0928 3444 SCPolicySvc - ok
08:38:50.0959 3444 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
08:38:50.0959 3444 SDRSVC - ok
08:38:51.0037 3444 SeaPort (cc781378e7eda615d2cdca3b17829fa4) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
08:38:51.0037 3444 SeaPort - ok
08:38:51.0084 3444 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
08:38:51.0084 3444 secdrv - ok
08:38:51.0100 3444 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
08:38:51.0100 3444 seclogon - ok
08:38:51.0115 3444 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
08:38:51.0115 3444 SENS - ok
08:38:51.0131 3444 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
08:38:51.0131 3444 SensrSvc - ok
08:38:51.0146 3444 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
08:38:51.0146 3444 Serenum - ok
08:38:51.0162 3444 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
08:38:51.0162 3444 Serial - ok
08:38:51.0162 3444 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
08:38:51.0162 3444 sermouse - ok
08:38:51.0193 3444 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
08:38:51.0193 3444 SessionEnv - ok
08:38:51.0224 3444 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
08:38:51.0224 3444 sffdisk - ok
08:38:51.0224 3444 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
08:38:51.0224 3444 sffp_mmc - ok
08:38:51.0224 3444 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
08:38:51.0224 3444 sffp_sd - ok
08:38:51.0240 3444 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
08:38:51.0240 3444 sfloppy - ok
08:38:51.0287 3444 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
08:38:51.0287 3444 ShellHWDetection - ok
08:38:51.0318 3444 Shockprf (380b52126e62c6c2d3c8ba805aadfdc7) C:\Windows\system32\DRIVERS\Apsx64.sys
08:38:51.0318 3444 Shockprf - ok
08:38:51.0334 3444 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
08:38:51.0334 3444 SiSRaid2 - ok
08:38:51.0349 3444 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
08:38:51.0349 3444 SiSRaid4 - ok
08:38:51.0365 3444 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
08:38:51.0365 3444 Smb - ok
08:38:51.0380 3444 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
08:38:51.0380 3444 SNMPTRAP - ok
08:38:51.0380 3444 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
08:38:51.0396 3444 spldr - ok
08:38:51.0443 3444 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
08:38:51.0458 3444 Spooler - ok
08:38:51.0646 3444 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
08:38:51.0677 3444 sppsvc - ok
08:38:51.0786 3444 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
08:38:51.0786 3444 sppuinotify - ok
08:38:51.0848 3444 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
08:38:51.0848 3444 srv - ok
08:38:51.0895 3444 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
08:38:51.0895 3444 srv2 - ok
08:38:51.0926 3444 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
08:38:51.0926 3444 srvnet - ok
08:38:51.0958 3444 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
08:38:51.0958 3444 SSDPSRV - ok
08:38:51.0989 3444 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
08:38:51.0989 3444 SstpSvc - ok
08:38:52.0020 3444 Steam Client Service - ok
08:38:52.0051 3444 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
08:38:52.0051 3444 stexstor - ok
08:38:52.0098 3444 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
08:38:52.0114 3444 stisvc - ok
08:38:52.0160 3444 SUService (0586a2e9d4e6e18933c9a7d6d6eef70f) C:\Program Files (x86)\Lenovo\System Update\SUService.exe
08:38:52.0160 3444 SUService - ok
08:38:52.0192 3444 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
08:38:52.0192 3444 swenum - ok
08:38:52.0254 3444 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
08:38:52.0254 3444 swprv - ok
08:38:52.0363 3444 SynTP (06d602a637e171e151853f1d8ecd34f1) C:\Windows\system32\DRIVERS\SynTP.sys
08:38:52.0379 3444 SynTP - ok
08:38:52.0566 3444 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
08:38:52.0582 3444 SysMain - ok
08:38:52.0644 3444 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
08:38:52.0644 3444 TabletInputService - ok
08:38:52.0675 3444 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
08:38:52.0675 3444 TapiSrv - ok
08:38:52.0706 3444 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
08:38:52.0706 3444 TBS - ok
08:38:52.0878 3444 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
08:38:52.0894 3444 Tcpip - ok
08:38:53.0128 3444 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
08:38:53.0143 3444 TCPIP6 - ok
08:38:53.0190 3444 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
08:38:53.0190 3444 tcpipreg - ok
08:38:53.0206 3444 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
08:38:53.0206 3444 TDPIPE - ok
08:38:53.0237 3444 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
08:38:53.0237 3444 TDTCP - ok
08:38:53.0268 3444 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
08:38:53.0268 3444 tdx - ok
08:38:53.0284 3444 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
08:38:53.0284 3444 TermDD - ok
08:38:53.0346 3444 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
08:38:53.0362 3444 TermService - ok
08:38:53.0377 3444 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
08:38:53.0377 3444 Themes - ok
08:38:53.0393 3444 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
08:38:53.0393 3444 THREADORDER - ok
08:38:53.0424 3444 TPDIGIMN (5523c729f1ed31b63c88490af3d220fa) C:\Windows\system32\DRIVERS\ApsHM64.sys
08:38:53.0424 3444 TPDIGIMN - ok
08:38:53.0440 3444 TPHDEXLGSVC (ecb098a3404acb8a05f0673dc086bb43) C:\Windows\system32\TPHDEXLG64.exe
08:38:53.0440 3444 TPHDEXLGSVC - ok
08:38:53.0533 3444 TPHKLOAD (63626012e44caaa162677b57b6dcb542) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
08:38:53.0533 3444 TPHKLOAD - ok
08:38:53.0549 3444 TPHKSVC (9e6e4a9789f76593cc5a6a5af8fc5929) C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
08:38:53.0549 3444 TPHKSVC - ok
08:38:53.0564 3444 TPM (dbcc20c02e8a3e43b03c304a4e40a84f) C:\Windows\system32\drivers\tpm.sys
08:38:53.0564 3444 TPM - ok
08:38:53.0596 3444 TPPWRIF (7165b5a9b4867f64a6d6935f57d4196b) C:\Windows\system32\drivers\Tppwr64v.sys
08:38:53.0596 3444 TPPWRIF - ok
08:38:53.0627 3444 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
08:38:53.0627 3444 TrkWks - ok
08:38:53.0689 3444 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
08:38:53.0689 3444 TrustedInstaller - ok
08:38:53.0705 3444 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
08:38:53.0720 3444 tssecsrv - ok
08:38:53.0736 3444 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
08:38:53.0736 3444 TsUsbFlt - ok
08:38:53.0752 3444 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
08:38:53.0752 3444 TsUsbGD - ok
08:38:53.0767 3444 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
08:38:53.0767 3444 tunnel - ok
08:38:53.0783 3444 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
08:38:53.0783 3444 uagp35 - ok
08:38:53.0814 3444 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
08:38:53.0830 3444 udfs - ok
08:38:53.0845 3444 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
08:38:53.0845 3444 UI0Detect - ok
08:38:53.0954 3444 UleadBurningHelper (be788a747457e6916586c410ec0111e7) C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
08:38:53.0954 3444 UleadBurningHelper - ok
08:38:53.0970 3444 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
08:38:53.0970 3444 uliagpkx - ok
08:38:53.0986 3444 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
08:38:53.0986 3444 umbus - ok
08:38:54.0001 3444 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
08:38:54.0001 3444 UmPass - ok
08:38:54.0204 3444 UNS (e91f8afbd7fb96c94b266579d6bfa77a) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
08:38:54.0220 3444 UNS - ok
08:38:54.0360 3444 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
08:38:54.0360 3444 upnphost - ok
08:38:54.0391 3444 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
08:38:54.0391 3444 USBAAPL64 - ok
08:38:54.0438 3444 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
08:38:54.0438 3444 usbccgp - ok
08:38:54.0469 3444 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
08:38:54.0469 3444 usbcir - ok
08:38:54.0500 3444 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
08:38:54.0500 3444 usbehci - ok
08:38:54.0532 3444 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
08:38:54.0532 3444 usbhub - ok
08:38:54.0547 3444 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
08:38:54.0547 3444 usbohci - ok
08:38:54.0563 3444 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
08:38:54.0563 3444 usbprint - ok
08:38:54.0594 3444 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
08:38:54.0594 3444 usbscan - ok
08:38:54.0625 3444 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
08:38:54.0625 3444 USBSTOR - ok
08:38:54.0672 3444 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
08:38:54.0672 3444 usbuhci - ok
08:38:54.0703 3444 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
08:38:54.0703 3444 usbvideo - ok
08:38:54.0719 3444 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
08:38:54.0719 3444 UxSms - ok
08:38:54.0766 3444 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
08:38:54.0766 3444 VaultSvc - ok
08:38:54.0781 3444 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
08:38:54.0781 3444 vdrvroot - ok
08:38:54.0828 3444 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
08:38:54.0828 3444 vds - ok
08:38:54.0844 3444 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
08:38:54.0844 3444 vga - ok
08:38:54.0859 3444 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
08:38:54.0859 3444 VgaSave - ok
08:38:54.0890 3444 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
08:38:54.0890 3444 vhdmp - ok
08:38:54.0890 3444 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
08:38:54.0906 3444 viaide - ok
08:38:54.0922 3444 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
08:38:54.0922 3444 volmgr - ok
08:38:54.0953 3444 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
08:38:54.0953 3444 volmgrx - ok
08:38:54.0984 3444 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
08:38:55.0000 3444 volsnap - ok
08:38:55.0015 3444 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
08:38:55.0015 3444 vsmraid - ok
08:38:55.0140 3444 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
08:38:55.0156 3444 VSS - ok
08:38:55.0265 3444 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
08:38:55.0265 3444 vwifibus - ok
08:38:55.0280 3444 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
08:38:55.0280 3444 vwififlt - ok
08:38:55.0280 3444 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
08:38:55.0280 3444 vwifimp - ok
08:38:55.0327 3444 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
08:38:55.0343 3444 W32Time - ok
08:38:55.0358 3444 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
08:38:55.0358 3444 WacomPen - ok
08:38:55.0374 3444 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:38:55.0390 3444 WANARP - ok
08:38:55.0390 3444 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
08:38:55.0390 3444 Wanarpv6 - ok
08:38:55.0483 3444 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
08:38:55.0499 3444 WatAdminSvc - ok
08:38:55.0624 3444 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
08:38:55.0639 3444 wbengine - ok
08:38:55.0764 3444 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
08:38:55.0764 3444 WbioSrvc - ok
08:38:55.0811 3444 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
08:38:55.0811 3444 wcncsvc - ok
08:38:55.0826 3444 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
08:38:55.0826 3444 WcsPlugInService - ok
08:38:55.0873 3444 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
08:38:55.0873 3444 Wd - ok
08:38:55.0936 3444 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
08:38:55.0936 3444 Wdf01000 - ok
08:38:55.0951 3444 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
08:38:55.0951 3444 WdiServiceHost - ok
08:38:55.0951 3444 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
08:38:55.0951 3444 WdiSystemHost - ok
08:38:55.0982 3444 wdkmd (94dc2bf6cbaaa95e369c3756d3115a76) C:\Windows\system32\DRIVERS\WDKMD.sys
08:38:55.0982 3444 wdkmd - ok
08:38:56.0029 3444 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
08:38:56.0029 3444 WebClient - ok
08:38:56.0060 3444 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
08:38:56.0060 3444 Wecsvc - ok
08:38:56.0092 3444 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
08:38:56.0092 3444 wercplsupport - ok
08:38:56.0092 3444 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
08:38:56.0092 3444 WerSvc - ok
08:38:56.0123 3444 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
08:38:56.0123 3444 WfpLwf - ok
08:38:56.0138 3444 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
08:38:56.0138 3444 WIMMount - ok
08:38:56.0138 3444 WinHttpAutoProxySvc - ok
08:38:56.0201 3444 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
08:38:56.0201 3444 Winmgmt - ok
08:38:56.0341 3444 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
08:38:56.0357 3444 WinRM - ok
08:38:56.0482 3444 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
08:38:56.0482 3444 WinUsb - ok
08:38:56.0575 3444 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
08:38:56.0591 3444 Wlansvc - ok
08:38:56.0638 3444 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
08:38:56.0638 3444 wlcrasvc - ok
08:38:56.0809 3444 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
08:38:56.0825 3444 wlidsvc - ok
08:38:56.0934 3444 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
08:38:56.0950 3444 WmiAcpi - ok
08:38:57.0012 3444 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
08:38:57.0012 3444 wmiApSrv - ok
08:38:57.0028 3444 WMPNetworkSvc - ok
08:38:57.0059 3444 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
08:38:57.0059 3444 WPCSvc - ok
08:38:57.0074 3444 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
08:38:57.0090 3444 WPDBusEnum - ok
08:38:57.0106 3444 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
08:38:57.0106 3444 ws2ifsl - ok
08:38:57.0137 3444 WSDPrintDevice (8d918b1db190a4d9b1753a66fa8c96e8) C:\Windows\system32\DRIVERS\WSDPrint.sys
08:38:57.0137 3444 WSDPrintDevice - ok
08:38:57.0152 3444 WSearch - ok
08:38:57.0168 3444 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
08:38:57.0168 3444 WudfPf - ok
08:38:57.0184 3444 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
08:38:57.0184 3444 WUDFRd - ok
08:38:57.0215 3444 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
08:38:57.0215 3444 wudfsvc - ok
08:38:57.0246 3444 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
08:38:57.0246 3444 WwanSvc - ok
08:38:57.0293 3444 MBR (0x1B8) (8ac4476c6870641b94b6e5c6e57b06af) \Device\Harddisk0\DR0
08:38:57.0527 3444 \Device\Harddisk0\DR0 - ok
08:38:57.0527 3444 MBR (0x1B8) (e5fa06aca0d60ba9c870d0ef3d9898c9) \Device\Harddisk1\DR1
08:38:59.0680 3444 \Device\Harddisk1\DR1 - ok
08:38:59.0680 3444 Boot (0x1200) (2a5a2d1eb66444e9041d5fe1d0003b79) \Device\Harddisk0\DR0\Partition0
08:38:59.0680 3444 \Device\Harddisk0\DR0\Partition0 - ok
08:38:59.0695 3444 Boot (0x1200) (7b61e0e6a5259a2edb4b0ac2cf74a04e) \Device\Harddisk0\DR0\Partition1
08:38:59.0695 3444 \Device\Harddisk0\DR0\Partition1 - ok
08:38:59.0726 3444 Boot (0x1200) (dade9de89a5885164057725133adb196) \Device\Harddisk0\DR0\Partition2
08:38:59.0726 3444 \Device\Harddisk0\DR0\Partition2 - ok
08:38:59.0726 3444 Boot (0x1200) (740fcfe5064bbd9dbef1dccc15f37cdf) \Device\Harddisk1\DR1\Partition0
08:38:59.0726 3444 \Device\Harddisk1\DR1\Partition0 - ok
08:38:59.0726 3444 ============================================================
08:38:59.0726 3444 Scan finished
08:38:59.0726 3444 ============================================================
08:38:59.0742 3348 Detected object count: 0
08:38:59.0742 3348 Actual detected object count: 0
08:39:59.0940 5088 Deinitialize success


ComboFix 12-07-16.01 - Home 17/07/2012 8:49.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4007.2220 [GMT 1:00]
Running from: c:\users\Home\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\MyFunCards_5mEI
c:\program files (x86)\MyFunCards_5mEI\Installr\1.bin\5mEIPlug.dll
c:\program files (x86)\MyFunCards_5mEI\Installr\1.bin\5mEZSETP.dll
c:\program files (x86)\MyFunCards_5mEI\Installr\1.bin\NP5mEISb.dll
c:\programdata\Roaming
c:\users\Home\AppData\Local\Temp\{2EE02C31-85FB-42AA-B152-47FC235E8A31}\fpb.tmp
c:\users\Home\AppData\Roaming\system32
c:\users\Home\AppData\Roaming\system32\rundll32.exe
c:\windows\system32\Thumbs.db
Q:\AUTORUN.INF
.
.
((((((((((((((((((((((((( Files Created from 2012-06-17 to 2012-07-17 )))))))))))))))))))))))))))))))
.
.
2012-07-17 07:58 . 2012-07-17 07:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-17 06:43 . 2012-07-17 06:43 -------- d-----w- C:\FRST
2012-07-15 21:59 . 2012-07-15 21:59 -------- d-----w- c:\users\Home\AppData\Roaming\Panda Security
2012-07-15 21:58 . 2012-07-15 21:58 -------- d-----w- c:\programdata\Panda Security
2012-07-15 21:58 . 2012-07-15 21:58 -------- d-----w- c:\program files (x86)\Panda Security
2012-07-15 21:58 . 2012-07-15 21:58 -------- d-----w- C:\temp
2012-07-15 20:32 . 2012-07-15 21:01 -------- d-----w- c:\users\Home\AppData\Local\NPE
2012-07-15 20:28 . 2012-07-15 20:28 27256 ----a-w- c:\windows\system32\drivers\FixZeroAccess.sys
2012-07-15 20:09 . 2012-07-15 20:09 -------- d-----w- c:\users\Home\AppData\Roaming\Malwarebytes
2012-07-15 20:09 . 2012-07-15 20:09 -------- d-----w- c:\programdata\Malwarebytes
2012-07-15 20:09 . 2012-07-15 20:09 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-07-15 20:09 . 2012-07-03 12:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-15 19:56 . 2012-07-15 19:56 328704 ----a-w- c:\windows\system32\services.exe.93687A1F6275BFBB
2012-07-15 19:44 . 2012-07-15 19:44 328704 ----a-w- c:\windows\system32\services.exe.A98691B144D9B1A1
2012-07-15 19:38 . 2012-07-15 19:38 328704 ----a-w- c:\windows\system32\services.exe.5D480C11B1BC8FA6
2012-07-15 19:35 . 2012-07-15 19:35 328704 ----a-w- c:\windows\system32\services.exe.F36AE296F11AEA73
2012-07-15 19:31 . 2012-07-15 19:31 328704 ----a-w- c:\windows\system32\services.exe.2E0D6710C5178983
2012-07-15 19:29 . 2012-07-15 19:29 328704 ----a-w- c:\windows\system32\services.exe.15E9E681E7A1D354
2012-07-15 19:25 . 2012-07-15 19:25 328704 ----a-w- c:\windows\system32\services.exe.AE84BF21F00F2466
2012-07-15 19:21 . 2012-07-15 19:21 328704 ----a-w- c:\windows\system32\services.exe.E256FB92A541C5C3
2012-07-15 15:33 . 2012-07-15 15:33 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-07-15 15:30 . 2012-07-15 15:30 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-07-12 06:19 . 2012-06-12 03:08 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-07-06 08:47 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2012-06-20 15:55 . 2012-06-20 15:55 -------- d-----w- c:\windows\en
2012-06-20 15:52 . 2012-06-20 15:52 537432 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\DXSETUP.exe
2012-06-20 15:52 . 2012-06-20 15:52 1801048 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\dsetup32.dll
2012-06-20 15:52 . 2012-06-20 15:52 15712 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ac5144e11cd4efc02\MeshBetaRemover.exe
2012-06-20 15:52 . 2012-06-20 15:52 89944 ----a-w- c:\program files (x86)\Common Files\Windows Live\.cache\ac09db991cd4efc01\DSETUP.dll
2012-06-20 07:36 . 2012-06-02 22:19 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-20 07:36 . 2012-06-02 22:19 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-20 07:36 . 2012-06-02 22:19 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-20 07:36 . 2012-06-02 22:15 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-20 07:36 . 2012-06-02 22:19 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-20 07:36 . 2012-06-02 22:19 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-20 07:36 . 2012-06-02 22:15 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-20 07:36 . 2012-06-02 14:19 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-20 07:36 . 2012-06-02 14:15 36864 ----a-w- c:\windows\system32\wuapp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-15 15:30 . 2011-08-14 07:17 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-15 04:01 . 2012-06-13 11:01 1188864 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 03:03 . 2012-06-13 11:01 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2012-05-04 11:06 . 2012-06-13 11:01 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 10:03 . 2012-06-13 11:01 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-05-04 10:03 . 2012-06-13 11:01 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-05-01 05:40 . 2012-06-13 11:01 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:55 . 2012-06-13 11:01 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 05:41 . 2012-06-13 11:01 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 05:41 . 2012-06-13 11:01 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 05:34 . 2012-06-13 11:01 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 05:37 . 2012-06-13 11:01 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 05:37 . 2012-06-13 11:01 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-24 05:37 . 2012-06-13 11:01 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36 . 2012-06-13 11:01 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-04-24 04:36 . 2012-06-13 11:01 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-04-24 04:36 . 2012-06-13 11:01 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-04-20 03:45 . 2012-06-13 11:01 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-04-20 03:16 . 2012-06-13 11:01 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2011-12-26 1242448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PWMTRV"="c:\progra~2\ThinkPad\UTILIT~1\PWMTR64V.DLL" [2011-02-03 1522536]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-07-19 421736]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"PSUNMain"="c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2011-04-28 439616]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2010-12-18 1202976]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HyperW7Svc;HyperW7 Service;c:\program files\Lenovo\RapidBoot\HyperW7Svc64.exe [2010-12-03 116072]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2010-12-18 425000]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-12-18 39464]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-21 129976]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [2010-11-02 340240]
R3 PCDSRVC{127174DC-C366ED8B-06020101}_0;PCDSRVC{127174DC-C366ED8B-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor\pcdsrvc_x64.pkms [2010-12-09 25072]
R3 Power Manager DBC Service;Power Manager DBC Service;c:\program files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE [2011-02-03 79208]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-23 1255736]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM64.sys [2011-01-13 23664]
S1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiifx64.sys [2010-09-07 15472]
S1 PHCORE;PHCORE;c:\program files\Lenovo\RapidBoot\PHCORE64.SYS [2010-12-03 31592]
S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys [2011-11-23 149768]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 jhi_service;Intel® Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S2 LENOVO.CAMMUTE;Lenovo Camera Mute;c:\program files\Lenovo\Communications Utility\CAMMUTE.exe [2011-01-27 40808]
S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\LENOVO\HOTKEY\MICMUTE.exe [2010-11-24 45496]
S2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction;c:\program files\Lenovo\Communications Utility\TPKNRSVC.exe [2011-01-27 59240]
S2 Lenovo.VIRTSCRLSVC;Lenovo Auto Scroll;c:\program files\LENOVO\VIRTSCRL\lvvsst.exe [2010-04-07 93032]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [2011-04-28 140608]
S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys [2012-01-05 161032]
S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys [2011-04-28 114760]
S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys [2011-04-28 121928]
S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys [2011-11-30 128264]
S2 risdxc;risdxc;c:\windows\system32\DRIVERS\risdxc64.sys [2010-12-15 98816]
S2 SAService;Conexant SmartAudio service;c:\windows\system32\SAsrv.exe [x]
S2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\LENOVO\HOTKEY\TPHKLOAD.exe [2010-12-03 114024]
S2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2010-12-02 64440]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-02-22 2656280]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-03-30 317440]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 NETwNs64;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETwNs64.sys [2010-11-09 8500736]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-12-07 412776]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys [2010-12-01 42392]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-17 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\PC-Doctor\uaclauncher.exe [2010-12-09 22:52]
.
2012-07-17 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\PC-Doctor\pcdrcui.exe [2010-12-09 22:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-11-02 1933584]
"TpShocks"="TpShocks.exe" [2011-01-14 380776]
"ForteConfig"="c:\program files\Conexant\ForteConfig\fmapp.exe" [2010-10-26 49056]
"SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2010-04-28 307768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-30 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-30 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-30 418840]
"LENOVO.TPKNRRES"="c:\program files\Lenovo\Communications Utility\TPKNRRES.exe" [2011-01-27 41320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.co.uk/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\cv9zyglj.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCDSRVC{127174DC-C366ED8B-06020101}_0]
"ImagePath"="\??\c:\program files\pc-doctor\pcdsrvc_x64.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_257_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_257.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Bonjour\mDNSResponder.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
c:\windows\SysWOW64\SAsrv.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\progra~1\LENOVO\VIRTSCRL\virtscrl.exe
c:\progra~1\Lenovo\HOTKEY\TPONSCR.EXE
c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Lenovo\System Update\SUService.exe
c:\program files (x86)\LENOVO\Message Center Plus\MCPLaunch.exe
.
**************************************************************************
.
Completion time: 2012-07-17 09:05:16 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-17 08:05
.
Pre-Run: 227,469,533,184 bytes free
Post-Run: 231,318,745,088 bytes free
.
- - End Of File - - B5AA60F0545F6FF8E5B77A5F2C314739

#13 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 17 July 2012 - 06:29 PM

Hello,


We are getting close. Just a little more work to do. We need to run a couple other scans to make sure no leftovers.

1.
Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Important!! When you save the mbam-setup file, rename it to something random (such as 123abc.exe) before beginning the download.
Malwarebytes may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet and double-click on the renamed file to install the application.
    For instructions with screenshots, please refer to this Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • Malwarebytes will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • Under the Scanner tab, make sure the "Perform Quick Scan" option is selected.
  • Click on the Scan button.
  • When finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box, then click the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked and then click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows the database version and your operating system.
  • Exit Malwarebytes when done.
Note: If Malwarebytes encounters a file that is difficult to remove, you will be asked to reboot your computer so it can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally will prevent Malwarebytes from removing all the malware.

2.
I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.

3.
Important Note: Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 7 and save it to your desktop.
  • Look for "Java Platform, Standard Edition".
  • Click the "Download JRE" button to the right.
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • From the list, select your OS and Platform (32-bit or 64-bit).
  • If a download for an Offline Installation is available, it is recommended to choose that and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Posted Image > Control Panel, double-click on Add/Remove Programs or Programs and Features in Vista/Windows 7 and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-7-windows-i586.exe to install the newest version.
  • If using Windows 7 or Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
  • The McAfee Security Scan Plus tool is installed by default unless you uncheck the McAfee installation box when updating Java.
Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications but it's not necessary.
To disable the JQS service if you don't want to use it:
  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.

Things to include in your next reply::
MBAM log
Eset log
How is your machine running now?

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#14 rooster4t

rooster4t
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:09:15 PM

Posted 18 July 2012 - 05:47 PM

Hi - as requested. Here are the logs. I already had Malware Bytes on my PC - does this matter?:


Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.18.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Home :: HOME-THINK [administrator]

Protection: Enabled

18/07/2012 22:26:04
mbam-log-2012-07-18 (22-26-04).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 212403
Time elapsed: 2 minute(s), 16 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

ESET LOG:

C:\FRST\Quarantine\services.exe Win64/Patched.B.Gen trojan deleted - quarantined
C:\FRST\Quarantine\{bf83d6c1-5778-068c-640f-72bf52e1ee27}\U\80000000.@ Win64/Sirefef.AL trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files (x86)\MyFunCards_5mEI\Installr\1.bin\5mEIPlug.dll.vir a variant of Win32/Toolbar.MyWebSearch application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Program Files (x86)\MyFunCards_5mEI\Installr\1.bin\5mEZSETP.dll.vir a variant of Win32/Toolbar.MyWebSearch.Q application cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\Users\Home\AppData\Roaming\System32\rundll32.exe.vir Win32/Agent.TUM trojan cleaned by deleting - quarantined
C:\Users\Home\Downloads\cnet2_Combined-Community-Codec-Pack-2011-07-30_exe.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined

#15 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,512 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:11:15 AM

Posted 18 July 2012 - 07:46 PM

Hello, rooster4t.
Congratulations! You now appear clean! :cool:

Uninstall Combofix
  • Make sure that Combofix.exe that you downloaded is on your Desktop but Do not run it!
    o *If it is not on your Desktop, the below will not work.
  • Click on Posted Image then Run....
  • Now copy & paste the green bolded text in the run-box and click OK.

    ComboFix /Uninstall

    Posted Image

    <Notice the space between the "x" and "/".> <--- It needs to be there
    Windows Vista users: Press the Windows Key + R to bring the Run... Command and then from there you can add in the Combofix /Uninstall

  • Please advise if this step is missed for any reason as it performs some important actions:
    "This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.
    It also makes a clean Restore Point and flashes all the old restore points in order to prevent possible reinfection from an old one through system restore".



Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

We Need to Clean Up Our Mess
  • Download OTC by OldTimer and save it to your desktop.
  • Double click Posted Image icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big Posted Image button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.


One of the most common questions found when cleaning malware is "how did my machine get infected?"

There are a variety of reasons, but the most common ones are that you are not practicing Safe Internet, you are not running the proper security software or that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer to help reduce the chance of being infected again in the future.

Do not use P2P programs
Peer-to-peer or file-sharing programs (such as uTorrent, Limewire and Bitorrent) are probably the primary route of infection nowadays. These programs allow file sharing between users as the name(s) suggest. It is almost impossible to know whether the file you’re downloading through P2P programs is safe.

It is therefore possible to be infected by downloading infected files via peer-to-peer programs and so I recommend that you do not use these programs. Should you wish to use them, they must be used with extreme care. Some further reading on this subject, along with included links, are as follows: "File-Sharing, otherwise known as Peer To Peer" and "Risks of File-Sharing Technology."

In addition, P2P programs facilitate cyber crime and help distribute pirated software, movies and other illegal material.

Practice Safe Internet
Another one of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on. Whether these things are files or sites it doesn't really matter. If something is out to get you, and you click on it, it most likely will.

Below are a list of simple precautions to take to keep your computer clean and running securely:
  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.
  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean. For the casual computer user, you will almost never receive a valid attachment of this type.
  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is. The email could be from someone you know who is themselves infected with malware which is trying to infect everyone in their address book. A key thing to look out for here is: does the email sound as though it’s from the person you know? Often, the email may simply have a web link or a “Run this file to make your PC run fast” message in it.
  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!. These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software. For an example of these types of pop-ups, or Foistware, you should read this article: Foistware, And how to avoid it.
    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. Removal instructions for a lot of these "rogues" can be found here.
  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you, or will download a file to your PC without your knowledge. You can check to see if it's a real alert by right-clicking on the window. If there is a menu that comes up saying Add to Favorites... you know it's a fake. DO NOT click on these windows, instead close them by finding the open window on your http://en.wikipedia.org/wiki/Taskbar#Screenshots '>Taskbar, right click and chose close.
  • Do not visit pornographic websites. I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites. I am not saying all adult sites do this, but a lot do, as this can often form part of their funding.
  • When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection. Instead when you receive a message that contains a link you should message back to the person asking if it is legit.
  • Stay away from Warez and Crack sites! As with Peer-2-Peer programs, in addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.
  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download files from a site, and are not sure if they are legitimate, you can use tools such as BitDefender Traffic Light, Norton Safe Web, or McAfee SiteAdvisor to look up info on the site and stay protected against malicious sites. Please be sure to only choose and install one of those tool bars.
  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money. By reading the agreement there is a good chance you can spot this and not install the software.
    Sometimes even legitimate programs will try to bundle extra, unwanted, software with the program you want - this is done to raise money for the program. Be sure to untick any boxes which may indicate that other programs will be downloaded.

Keep Windows up-to-date
Microsoft continually releases security and stability updates for its supported operating systems and you should always apply these to help keep your PC secure.

  • Windows XP users
    You should visit Windows Update to check for the latest updates to your system. The latest service pack (SP3) can be obtained directly from Microsoft here.
  • Windows Vista users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP2) can be obtained directly from Microsoft here.
  • Windows 7 users
    You should run the Windows Update program from your start menu to access the latest updates to your operating system (information can be found here). The latest service pack (SP1) can be obtained directly from Microsoft here


Keep your browser secure
Most modern browsers have come on in leaps and bounds with their inbuilt, default security. The best way to keep your browser secure nowadays is simply to keep it up-to-date.

The latest versions of the three common browsers can be found below:

Use an AntiVirus Software
It is very important that your computer has an up-to-date anti-virus software on it which has a real-time agent running. This alone can save you a lot of trouble with malware in the future.
See this link for a listing of some online & their stand-alone antivirus programs: Virus, Spyware, and Malware Protection and Removal Resources, a couple of free Anti-Virus programs you may be interested in are Microsoft Security Essentials and Avast.

It is imperative that you update your Antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out. If you use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.

All versions of Windows starting from XP have an in-built firewall. With Windows XP this firewall will protect you from incoming traffic (i.e. hackers). Starting with Windows Vista, the firewall was beefed up to also protect you against outgoing traffic (i.e. malicious programs installed on your machine should be blocked from sending data, such as your bank details and passwords, out).

In addition, if you connect to the internet via a router, this will normally have a firewall in-built.

Some people will recommend installing a different firewall (instead of the Windows’ built one), this is personal choice, but the message is to definitely have one! For a tutorial on Firewalls and a listing of some available ones see this link: Understanding and Using Firewalls

Install an Anti-Malware program
Recommended, and free, Anti-Malware programs are Malwarebytes Anti-Malware and SuperAntiSpyware.

You should regularly (perhaps once a week) scan your computer with an Anti-Malware program just as you would with an antivirus software.

Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is very important to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities (such as Adobe Reader and Java). You can check these by visiting Secunia Software Inspector.

Follow this list and your potential for being infected again will reduce dramatically.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users