Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Chrome - Certificate Security Issue


  • Please log in to reply
5 replies to this topic

#1 jingram2b

jingram2b

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:11:29 AM

Posted 31 July 2012 - 04:01 PM

Hey all,

I beleive I may have run into a malware situation.

I am running Windows 7 and use Google Chrome.

When I went to log in to various sites: Facebook, Yahoo, Twitter - pretty much anything with a login - I received this message:

The site's security certificate is signed using a weak signature algorithm!
You attempted to reach login.yahoo.com, but the server presented a certificate signed using a weak signature algorithm. This means that the security credentials the server presented could have been forged, and the server may not be the server you expected (you may be communicating with an attacker).
You should not proceed, especially if you have never seen this warning before for this site.
Proceed anyway Back to safety
Help me understand
When you connect to a secure website, the server hosting that site presents your browser with something called a "certificate" to verify its identity. This certificate contains identity information, such as the address of the website, which is verified by a third party that your computer trusts. By checking that the address in the certificate matches the address of the website, it is possible to verify that you are securely communicating with the website you intended, and not a third party (such as an attacker on your network).

In this case, the server certificate or an intermediate CA certificate presented to your browser is signed using a weak signature algorithm such as RSA-MD2. Recent research by computer scientists showed the signature algorithm is weaker than previously believed, and the signature algorithm is rarely used by trustworthy websites today. This certificate could have been forged.


It seems to only affect Chrome - the only other browser I have is IE, which seems to work fine.

Any thoughts? If I've left out any vital information, please forgive me.

EDIT: I ran Malware Bytes and it returned a Trojan.Dropper.BCMiner - I did the removal, but it appears it did not go away after the reboot.

Edited by jingram2b, 31 July 2012 - 04:26 PM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:11:29 AM

Posted 31 July 2012 - 04:58 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 jingram2b

jingram2b
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:11:29 AM

Posted 31 July 2012 - 05:32 PM

Thanks for the reply!

Here's the TDSSkiller report:
17:29:39.0236 6252 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
17:29:39.0616 6252 ============================================================
17:29:39.0616 6252 Current date / time: 2012/07/31 17:29:39.0616
17:29:39.0616 6252 SystemInfo:
17:29:39.0616 6252
17:29:39.0616 6252 OS Version: 6.1.7601 ServicePack: 1.0
17:29:39.0616 6252 Product type: Workstation
17:29:39.0616 6252 ComputerName: INTERN0003-PC
17:29:39.0616 6252 UserName: jingram
17:29:39.0616 6252 Windows directory: C:\Windows
17:29:39.0616 6252 System windows directory: C:\Windows
17:29:39.0616 6252 Running under WOW64
17:29:39.0616 6252 Processor architecture: Intel x64
17:29:39.0616 6252 Number of processors: 4
17:29:39.0616 6252 Page size: 0x1000
17:29:39.0616 6252 Boot type: Normal boot
17:29:39.0616 6252 ============================================================
17:29:40.0105 6252 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
17:29:40.0105 6252 ============================================================
17:29:40.0105 6252 \Device\Harddisk0\DR0:
17:29:40.0105 6252 MBR partitions:
17:29:40.0105 6252 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x204E000
17:29:40.0105 6252 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2062000, BlocksNum 0x1B162000
17:29:40.0105 6252 ============================================================
17:29:40.0145 6252 C: <-> \Device\Harddisk0\DR0\Partition1
17:29:40.0145 6252 ============================================================
17:29:40.0145 6252 Initialize success
17:29:40.0145 6252 ============================================================
17:29:53.0026 6440 ============================================================
17:29:53.0026 6440 Scan started
17:29:53.0026 6440 Mode: Manual; TDLFS;
17:29:53.0026 6440 ============================================================
17:29:55.0115 6440 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\DRIVERS\1394ohci.sys
17:29:55.0115 6440 1394ohci - ok
17:29:55.0177 6440 Acceler (e0065cbf1a25c015c218457d2cd522b9) C:\Windows\system32\DRIVERS\Accelern.sys
17:29:55.0177 6440 Acceler - ok
17:29:55.0240 6440 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
17:29:55.0240 6440 ACPI - ok
17:29:55.0271 6440 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
17:29:55.0271 6440 AcpiPmi - ok
17:29:55.0567 6440 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
17:29:55.0567 6440 AdobeARMservice - ok
17:29:55.0707 6440 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
17:29:55.0707 6440 AdobeFlashPlayerUpdateSvc - ok
17:29:55.0785 6440 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
17:29:55.0785 6440 adp94xx - ok
17:29:55.0879 6440 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
17:29:55.0894 6440 adpahci - ok
17:29:55.0894 6440 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
17:29:55.0894 6440 adpu320 - ok
17:29:55.0925 6440 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
17:29:55.0925 6440 AeLookupSvc - ok
17:29:56.0003 6440 AESTFilters (a6fb9db8f1a86861d955fd6975977ae0) C:\Program Files\IDT\WDM\AESTSr64.exe
17:29:56.0003 6440 AESTFilters - ok
17:29:56.0081 6440 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
17:29:56.0081 6440 AFD - ok
17:29:56.0128 6440 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
17:29:56.0128 6440 agp440 - ok
17:29:56.0148 6440 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
17:29:56.0148 6440 ALG - ok
17:29:56.0178 6440 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
17:29:56.0178 6440 aliide - ok
17:29:56.0198 6440 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
17:29:56.0198 6440 amdide - ok
17:29:56.0218 6440 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
17:29:56.0218 6440 AmdK8 - ok
17:29:56.0228 6440 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
17:29:56.0228 6440 AmdPPM - ok
17:29:56.0268 6440 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
17:29:56.0268 6440 amdsata - ok
17:29:56.0278 6440 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
17:29:56.0278 6440 amdsbs - ok
17:29:56.0298 6440 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
17:29:56.0298 6440 amdxata - ok
17:29:56.0358 6440 ApfiltrService (e4f6a272a696b6442e5c84ec470e3676) C:\Windows\system32\DRIVERS\Apfiltr.sys
17:29:56.0358 6440 ApfiltrService - ok
17:29:56.0408 6440 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
17:29:56.0408 6440 AppID - ok
17:29:56.0428 6440 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
17:29:56.0428 6440 AppIDSvc - ok
17:29:56.0438 6440 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
17:29:56.0438 6440 Appinfo - ok
17:29:56.0518 6440 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
17:29:56.0518 6440 AppMgmt - ok
17:29:56.0528 6440 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
17:29:56.0528 6440 arc - ok
17:29:56.0578 6440 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
17:29:56.0578 6440 arcsas - ok
17:29:56.0688 6440 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
17:29:56.0698 6440 aspnet_state - ok
17:29:56.0758 6440 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
17:29:56.0758 6440 AsyncMac - ok
17:29:56.0788 6440 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
17:29:56.0788 6440 atapi - ok
17:29:56.0997 6440 ATService (e604f606d37b153b32bddececb024f81) C:\Program Files\Fingerprint Sensor\ATService.exe
17:29:57.0017 6440 ATService - ok
17:29:57.0357 6440 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
17:29:57.0377 6440 AudioEndpointBuilder - ok
17:29:57.0397 6440 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
17:29:57.0397 6440 AudioSrv - ok
17:29:57.0497 6440 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
17:29:57.0497 6440 AxInstSV - ok
17:29:57.0587 6440 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
17:29:57.0597 6440 b06bdrv - ok
17:29:57.0657 6440 b57nd60a (00e4fd35ce3e817f19d6bc2b6f97fd90) C:\Windows\system32\DRIVERS\b57nd60a.sys
17:29:57.0657 6440 b57nd60a - ok
17:29:57.0767 6440 BBSvc (87f3bcf82a63e900af896cd930bf7e05) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE
17:29:57.0767 6440 BBSvc - ok
17:29:57.0807 6440 BBUpdate (78779ee07231c658b483b1f38b5088df) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
17:29:57.0817 6440 BBUpdate - ok
17:29:57.0857 6440 BCM42RLY (c3d8920a5aaf10a72cedb57d3339280a) C:\Windows\system32\drivers\BCM42RLY.sys
17:29:57.0857 6440 BCM42RLY - ok
17:29:58.0116 6440 BCM43XX (d20ee58c13ff343b90550861ebcd9ddd) C:\Windows\system32\DRIVERS\bcmwl664.sys
17:29:58.0136 6440 BCM43XX - ok
17:29:58.0322 6440 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
17:29:58.0322 6440 BDESVC - ok
17:29:58.0416 6440 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
17:29:58.0416 6440 Beep - ok
17:29:58.0509 6440 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
17:29:58.0525 6440 BFE - ok
17:29:58.0634 6440 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\System32\qmgr.dll
17:29:58.0634 6440 BITS - ok
17:29:58.0681 6440 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
17:29:58.0681 6440 blbdrive - ok
17:29:58.0743 6440 Blfp (228086f7ed08e8f1f8622e8f0ded7b6e) C:\Windows\system32\DRIVERS\basp.sys
17:29:58.0743 6440 Blfp - ok
17:29:58.0805 6440 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
17:29:58.0805 6440 bowser - ok
17:29:58.0852 6440 BrcmMgmtAgent (96afb6d33247fe90421a5b2e76f4ed59) C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe
17:29:58.0852 6440 BrcmMgmtAgent - ok
17:29:58.0868 6440 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
17:29:58.0868 6440 BrFiltLo - ok
17:29:58.0883 6440 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
17:29:58.0883 6440 BrFiltUp - ok
17:29:58.0915 6440 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
17:29:58.0915 6440 Browser - ok
17:29:58.0930 6440 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
17:29:58.0930 6440 Brserid - ok
17:29:58.0930 6440 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
17:29:58.0930 6440 BrSerWdm - ok
17:29:58.0930 6440 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
17:29:58.0946 6440 BrUsbMdm - ok
17:29:58.0961 6440 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
17:29:58.0961 6440 BrUsbSer - ok
17:29:59.0039 6440 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\DRIVERS\BthEnum.sys
17:29:59.0039 6440 BthEnum - ok
17:29:59.0055 6440 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
17:29:59.0055 6440 BTHMODEM - ok
17:29:59.0086 6440 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
17:29:59.0086 6440 BthPan - ok
17:29:59.0133 6440 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\system32\Drivers\BTHport.sys
17:29:59.0148 6440 BTHPORT - ok
17:29:59.0180 6440 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
17:29:59.0180 6440 bthserv - ok
17:29:59.0195 6440 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\system32\Drivers\BTHUSB.sys
17:29:59.0195 6440 BTHUSB - ok
17:29:59.0273 6440 BTWAMPFL (a0dfb69ade3444c78b17636fcf28e898) C:\Windows\system32\DRIVERS\btwampfl.sys
17:29:59.0289 6440 BTWAMPFL - ok
17:29:59.0382 6440 btwaudio (7cf028ce78696882b327ff13d2dfa534) C:\Windows\system32\drivers\btwaudio.sys
17:29:59.0382 6440 btwaudio - ok
17:29:59.0445 6440 btwavdt (3def2370e414b4e299673558ba171a51) C:\Windows\system32\DRIVERS\btwavdt.sys
17:29:59.0445 6440 btwavdt - ok
17:29:59.0550 6440 btwdins (cc9dae7759ac2c0d19111c0d38ddd232) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
17:29:59.0560 6440 btwdins - ok
17:29:59.0580 6440 btwl2cap (9ad0fa253ed531d39fb2d74fe12a5fa9) C:\Windows\system32\DRIVERS\btwl2cap.sys
17:29:59.0580 6440 btwl2cap - ok
17:29:59.0630 6440 btwrchid (9937e0e4dfc0030560a6dfe9d3a94b39) C:\Windows\system32\DRIVERS\btwrchid.sys
17:29:59.0630 6440 btwrchid - ok
17:29:59.0680 6440 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
17:29:59.0690 6440 cdfs - ok
17:29:59.0740 6440 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
17:29:59.0740 6440 cdrom - ok
17:29:59.0800 6440 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
17:29:59.0800 6440 CertPropSvc - ok
17:29:59.0820 6440 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
17:29:59.0820 6440 circlass - ok
17:29:59.0860 6440 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
17:29:59.0870 6440 CLFS - ok
17:29:59.0990 6440 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:29:59.0990 6440 clr_optimization_v2.0.50727_32 - ok
17:30:00.0050 6440 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
17:30:00.0060 6440 clr_optimization_v2.0.50727_64 - ok
17:30:00.0140 6440 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:30:00.0150 6440 clr_optimization_v4.0.30319_32 - ok
17:30:00.0210 6440 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
17:30:00.0220 6440 clr_optimization_v4.0.30319_64 - ok
17:30:00.0270 6440 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
17:30:00.0270 6440 CmBatt - ok
17:30:00.0280 6440 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
17:30:00.0280 6440 cmdide - ok
17:30:00.0339 6440 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
17:30:00.0339 6440 CNG - ok
17:30:00.0389 6440 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
17:30:00.0389 6440 Compbatt - ok
17:30:00.0429 6440 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
17:30:00.0439 6440 CompositeBus - ok
17:30:00.0449 6440 COMSysApp - ok
17:30:00.0529 6440 cpuz135 - ok
17:30:00.0559 6440 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
17:30:00.0559 6440 crcdisk - ok
17:30:00.0669 6440 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
17:30:00.0669 6440 CryptSvc - ok
17:30:00.0719 6440 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
17:30:00.0719 6440 CSC - ok
17:30:00.0799 6440 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll
17:30:00.0799 6440 CscService - ok
17:30:00.0869 6440 CtClsFlt (8ce04a5bdd2ce6e62ce02a1c27093104) C:\Windows\system32\DRIVERS\CtClsFlt.sys
17:30:00.0869 6440 CtClsFlt - ok
17:30:00.0969 6440 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
17:30:00.0979 6440 DcomLaunch - ok
17:30:01.0109 6440 dcpsysmgrsvc (3562c84415080b8b0c4d695a43372e3e) c:\Program Files\Dell\Dell System Manager\DCPSysMgrSvc.exe
17:30:01.0119 6440 dcpsysmgrsvc - ok
17:30:01.0199 6440 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
17:30:01.0199 6440 defragsvc - ok
17:30:01.0309 6440 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
17:30:01.0309 6440 DfsC - ok
17:30:01.0369 6440 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
17:30:01.0379 6440 Dhcp - ok
17:30:01.0379 6440 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
17:30:01.0379 6440 discache - ok
17:30:01.0439 6440 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
17:30:01.0439 6440 Disk - ok
17:30:01.0489 6440 dmvsc (5db085a8a6600be6401f2b24eecb5415) C:\Windows\system32\drivers\dmvsc.sys
17:30:01.0499 6440 dmvsc - ok
17:30:01.0529 6440 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
17:30:01.0538 6440 Dnscache - ok
17:30:01.0688 6440 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
17:30:01.0688 6440 dot3svc - ok
17:30:01.0708 6440 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
17:30:01.0718 6440 DPS - ok
17:30:01.0768 6440 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
17:30:01.0768 6440 drmkaud - ok
17:30:01.0868 6440 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
17:30:01.0868 6440 DXGKrnl - ok
17:30:01.0908 6440 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
17:30:01.0918 6440 EapHost - ok
17:30:02.0118 6440 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
17:30:02.0148 6440 ebdrv - ok
17:30:02.0328 6440 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
17:30:02.0328 6440 EFS - ok
17:30:02.0538 6440 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
17:30:02.0548 6440 ehRecvr - ok
17:30:02.0568 6440 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
17:30:02.0568 6440 ehSched - ok
17:30:02.0678 6440 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
17:30:02.0678 6440 elxstor - ok
17:30:02.0688 6440 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
17:30:02.0688 6440 ErrDev - ok
17:30:02.0768 6440 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
17:30:02.0768 6440 EventSystem - ok
17:30:02.0837 6440 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
17:30:02.0847 6440 exfat - ok
17:30:02.0887 6440 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
17:30:02.0887 6440 fastfat - ok
17:30:02.0957 6440 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
17:30:02.0957 6440 Fax - ok
17:30:02.0997 6440 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
17:30:02.0997 6440 fdc - ok
17:30:03.0017 6440 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
17:30:03.0017 6440 fdPHost - ok
17:30:03.0027 6440 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
17:30:03.0027 6440 FDResPub - ok
17:30:03.0067 6440 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
17:30:03.0067 6440 FileInfo - ok
17:30:03.0097 6440 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
17:30:03.0097 6440 Filetrace - ok
17:30:03.0297 6440 FLEXnet Licensing Service (bb0667b0171b632b97ea759515476f07) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
17:30:03.0297 6440 FLEXnet Licensing Service - ok
17:30:03.0327 6440 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
17:30:03.0327 6440 flpydisk - ok
17:30:03.0377 6440 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
17:30:03.0387 6440 FltMgr - ok
17:30:03.0517 6440 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
17:30:03.0537 6440 FontCache - ok
17:30:03.0664 6440 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
17:30:03.0664 6440 FontCache3.0.0.0 - ok
17:30:03.0726 6440 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
17:30:03.0726 6440 FsDepends - ok
17:30:03.0757 6440 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
17:30:03.0757 6440 Fs_Rec - ok
17:30:03.0804 6440 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
17:30:03.0804 6440 fvevol - ok
17:30:03.0835 6440 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
17:30:03.0835 6440 gagp30kx - ok
17:30:03.0913 6440 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
17:30:03.0929 6440 gpsvc - ok
17:30:03.0975 6440 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
17:30:03.0975 6440 hcw85cir - ok
17:30:03.0991 6440 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
17:30:04.0007 6440 HDAudBus - ok
17:30:04.0007 6440 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
17:30:04.0007 6440 HidBatt - ok
17:30:04.0007 6440 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
17:30:04.0007 6440 HidBth - ok
17:30:04.0022 6440 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
17:30:04.0022 6440 HidIr - ok
17:30:04.0053 6440 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
17:30:04.0053 6440 hidserv - ok
17:30:04.0116 6440 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
17:30:04.0116 6440 HidUsb - ok
17:30:04.0147 6440 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
17:30:04.0162 6440 hkmsvc - ok
17:30:04.0178 6440 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
17:30:04.0178 6440 HomeGroupListener - ok
17:30:04.0256 6440 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
17:30:04.0256 6440 HomeGroupProvider - ok
17:30:04.0272 6440 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
17:30:04.0272 6440 HpSAMD - ok
17:30:04.0321 6440 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
17:30:04.0331 6440 HTTP - ok
17:30:04.0361 6440 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
17:30:04.0361 6440 hwpolicy - ok
17:30:04.0421 6440 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
17:30:04.0421 6440 i8042prt - ok
17:30:04.0521 6440 iaStor (d7921d5a870b11cc1adab198a519d50a) C:\Windows\system32\drivers\iaStor.sys
17:30:04.0531 6440 iaStor - ok
17:30:04.0611 6440 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
17:30:04.0611 6440 iaStorV - ok
17:30:04.0761 6440 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
17:30:04.0791 6440 idsvc - ok
17:30:05.0950 6440 igfx (9937600a1584ff00565d5379eb4c9edb) C:\Windows\system32\DRIVERS\igdkmd64.sys
17:30:06.0210 6440 igfx - ok
17:30:06.0420 6440 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
17:30:06.0420 6440 iirsp - ok
17:30:06.0580 6440 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
17:30:06.0580 6440 IKEEXT - ok
17:30:06.0650 6440 Impcd (dd587a55390ed2295bce6d36ad567da9) C:\Windows\system32\drivers\Impcd.sys
17:30:06.0650 6440 Impcd - ok
17:30:06.0720 6440 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys
17:30:06.0730 6440 IntcDAud - ok
17:30:06.0770 6440 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
17:30:06.0770 6440 intelide - ok
17:30:06.0799 6440 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
17:30:06.0799 6440 intelppm - ok
17:30:06.0829 6440 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
17:30:06.0829 6440 IPBusEnum - ok
17:30:06.0869 6440 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:30:06.0869 6440 IpFilterDriver - ok
17:30:06.0939 6440 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
17:30:06.0939 6440 iphlpsvc - ok
17:30:06.0959 6440 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
17:30:06.0959 6440 IPMIDRV - ok
17:30:06.0959 6440 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
17:30:06.0969 6440 IPNAT - ok
17:30:07.0009 6440 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
17:30:07.0009 6440 IRENUM - ok
17:30:07.0009 6440 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
17:30:07.0009 6440 isapnp - ok
17:30:07.0029 6440 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
17:30:07.0039 6440 iScsiPrt - ok
17:30:07.0159 6440 jhi_service (6c85719a21b3f62c2c76280f4bd36c7b) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
17:30:07.0169 6440 jhi_service - ok
17:30:07.0219 6440 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
17:30:07.0219 6440 kbdclass - ok
17:30:07.0249 6440 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
17:30:07.0249 6440 kbdhid - ok
17:30:07.0269 6440 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
17:30:07.0269 6440 KeyIso - ok
17:30:07.0309 6440 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
17:30:07.0309 6440 KSecDD - ok
17:30:07.0349 6440 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
17:30:07.0349 6440 KSecPkg - ok
17:30:07.0359 6440 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
17:30:07.0369 6440 ksthunk - ok
17:30:07.0419 6440 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
17:30:07.0429 6440 KtmRm - ok
17:30:07.0479 6440 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
17:30:07.0479 6440 LanmanServer - ok
17:30:07.0519 6440 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
17:30:07.0519 6440 LanmanWorkstation - ok
17:30:07.0579 6440 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
17:30:07.0579 6440 lltdio - ok
17:30:07.0609 6440 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
17:30:07.0619 6440 lltdsvc - ok
17:30:07.0629 6440 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
17:30:07.0629 6440 lmhosts - ok
17:30:07.0729 6440 LMS (5f5899711df18a02162b6d518c17b0d7) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
17:30:07.0729 6440 LMS - ok
17:30:07.0769 6440 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
17:30:07.0769 6440 LSI_FC - ok
17:30:07.0779 6440 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
17:30:07.0779 6440 LSI_SAS - ok
17:30:07.0789 6440 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
17:30:07.0789 6440 LSI_SAS2 - ok
17:30:07.0809 6440 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
17:30:07.0809 6440 LSI_SCSI - ok
17:30:08.0908 6440 LTService (1ef84ab6c8043835cb914080a4d06869) C:\Windows\LTSVC\LTSVC.exe
17:30:08.0968 6440 LTService - ok
17:30:09.0178 6440 LTSvcMon (880b96625544c4c34aea975a68756c91) C:\Windows\LTSvc\LTSvcMon.exe
17:30:09.0178 6440 LTSvcMon - ok
17:30:09.0337 6440 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
17:30:09.0337 6440 luafv - ok
17:30:09.0367 6440 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
17:30:09.0377 6440 Mcx2Svc - ok
17:30:09.0687 6440 MDM (7cf1b716372b89568ae4c0fe769f5869) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
17:30:09.0687 6440 MDM - ok
17:30:09.0707 6440 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
17:30:09.0717 6440 megasas - ok
17:30:09.0727 6440 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
17:30:09.0737 6440 MegaSR - ok
17:30:09.0797 6440 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys
17:30:09.0797 6440 MEIx64 - ok
17:30:09.0987 6440 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
17:30:09.0987 6440 Microsoft Office Groove Audit Service - ok
17:30:10.0075 6440 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
17:30:10.0075 6440 MMCSS - ok
17:30:10.0075 6440 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
17:30:10.0075 6440 Modem - ok
17:30:10.0122 6440 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
17:30:10.0122 6440 monitor - ok
17:30:10.0168 6440 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
17:30:10.0168 6440 mouclass - ok
17:30:10.0184 6440 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
17:30:10.0184 6440 mouhid - ok
17:30:10.0200 6440 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
17:30:10.0200 6440 mountmgr - ok
17:30:10.0231 6440 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
17:30:10.0246 6440 mpio - ok
17:30:10.0262 6440 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
17:30:10.0278 6440 mpsdrv - ok
17:30:10.0324 6440 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
17:30:10.0340 6440 MpsSvc - ok
17:30:10.0355 6440 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
17:30:10.0355 6440 MRxDAV - ok
17:30:10.0387 6440 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:30:10.0402 6440 mrxsmb - ok
17:30:10.0465 6440 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:30:10.0465 6440 mrxsmb10 - ok
17:30:10.0511 6440 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:30:10.0511 6440 mrxsmb20 - ok
17:30:10.0537 6440 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
17:30:10.0537 6440 msahci - ok
17:30:10.0587 6440 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
17:30:10.0587 6440 msdsm - ok
17:30:10.0647 6440 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
17:30:10.0647 6440 MSDTC - ok
17:30:10.0707 6440 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
17:30:10.0707 6440 Msfs - ok
17:30:10.0747 6440 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
17:30:10.0747 6440 mshidkmdf - ok
17:30:10.0767 6440 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
17:30:10.0767 6440 msisadrv - ok
17:30:10.0817 6440 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
17:30:10.0817 6440 MSiSCSI - ok
17:30:10.0827 6440 msiserver - ok
17:30:10.0847 6440 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
17:30:10.0847 6440 MSKSSRV - ok
17:30:10.0877 6440 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
17:30:10.0877 6440 MSPCLOCK - ok
17:30:10.0877 6440 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
17:30:10.0877 6440 MSPQM - ok
17:30:10.0917 6440 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
17:30:10.0927 6440 MsRPC - ok
17:30:10.0937 6440 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
17:30:10.0937 6440 mssmbios - ok
17:30:10.0967 6440 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
17:30:10.0967 6440 MSTEE - ok
17:30:10.0967 6440 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
17:30:10.0967 6440 MTConfig - ok
17:30:10.0977 6440 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
17:30:10.0977 6440 Mup - ok
17:30:11.0036 6440 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
17:30:11.0036 6440 napagent - ok
17:30:11.0096 6440 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
17:30:11.0096 6440 NativeWifiP - ok
17:30:11.0166 6440 NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys
17:30:11.0166 6440 NDIS - ok
17:30:11.0196 6440 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
17:30:11.0196 6440 NdisCap - ok
17:30:11.0236 6440 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
17:30:11.0236 6440 NdisTapi - ok
17:30:11.0246 6440 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
17:30:11.0246 6440 Ndisuio - ok
17:30:11.0286 6440 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
17:30:11.0296 6440 NdisWan - ok
17:30:11.0346 6440 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
17:30:11.0356 6440 NDProxy - ok
17:30:11.0396 6440 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
17:30:11.0396 6440 NetBIOS - ok
17:30:11.0406 6440 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
17:30:11.0406 6440 NetBT - ok
17:30:11.0446 6440 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
17:30:11.0446 6440 Netlogon - ok
17:30:11.0556 6440 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
17:30:11.0556 6440 Netman - ok
17:30:11.0676 6440 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:30:11.0676 6440 NetMsmqActivator - ok
17:30:11.0676 6440 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:30:11.0686 6440 NetPipeActivator - ok
17:30:11.0736 6440 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
17:30:11.0746 6440 netprofm - ok
17:30:11.0746 6440 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:30:11.0746 6440 NetTcpActivator - ok
17:30:11.0746 6440 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
17:30:11.0746 6440 NetTcpPortSharing - ok
17:30:11.0926 6440 netvsc (73ce12b8bdd747b0063cb0a7ef44cea7) C:\Windows\system32\DRIVERS\netvsc60.sys
17:30:11.0976 6440 netvsc - ok
17:30:12.0026 6440 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
17:30:12.0026 6440 nfrd960 - ok
17:30:12.0106 6440 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
17:30:12.0116 6440 NlaSvc - ok
17:30:12.0146 6440 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
17:30:12.0146 6440 Npfs - ok
17:30:12.0166 6440 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
17:30:12.0166 6440 nsi - ok
17:30:12.0186 6440 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
17:30:12.0186 6440 nsiproxy - ok
17:30:12.0305 6440 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
17:30:12.0325 6440 Ntfs - ok
17:30:12.0700 6440 ntrtscan (4e6e6be52ef05e666cc7d6d99c2c426a) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\ntrtscan.exe
17:30:12.0731 6440 ntrtscan - ok
17:30:12.0934 6440 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
17:30:12.0934 6440 Null - ok
17:30:12.0996 6440 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
17:30:12.0996 6440 nvraid - ok
17:30:13.0027 6440 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
17:30:13.0027 6440 nvstor - ok
17:30:13.0058 6440 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
17:30:13.0058 6440 nv_agp - ok
17:30:13.0121 6440 O2FLASH (4e37455db16aec75862b1d0bc35b589e) C:\Windows\system32\DRIVERS\o2flash.exe
17:30:13.0121 6440 O2FLASH - ok
17:30:13.0168 6440 O2MDFRDR (6172db160fc566cf24307941c0e94d8e) C:\Windows\system32\drivers\O2MDFw7x64.sys
17:30:13.0168 6440 O2MDFRDR - ok
17:30:13.0199 6440 O2MDRRDR (8ed738aba394bbf6d7802698be453112) C:\Windows\system32\DRIVERS\O2MDRw7x64.sys
17:30:13.0199 6440 O2MDRRDR - ok
17:30:13.0323 6440 O2SDIOAssist (4635935fc972c582632bf45c26bfcb0e) c:\Windows\SysWOW64\srvany.exe
17:30:13.0323 6440 O2SDIOAssist - ok
17:30:13.0355 6440 O2SDJRDR (a9c1e6b7c134fad124338b7944fa996d) C:\Windows\system32\DRIVERS\o2sdjw7x64.sys
17:30:13.0355 6440 O2SDJRDR - ok
17:30:13.0526 6440 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:30:13.0526 6440 odserv - ok
17:30:13.0557 6440 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
17:30:13.0557 6440 ohci1394 - ok
17:30:13.0635 6440 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:30:13.0635 6440 ose - ok
17:30:13.0775 6440 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
17:30:13.0775 6440 p2pimsvc - ok
17:30:13.0822 6440 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
17:30:13.0822 6440 p2psvc - ok
17:30:13.0931 6440 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
17:30:13.0931 6440 Parport - ok
17:30:13.0971 6440 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
17:30:13.0971 6440 partmgr - ok
17:30:14.0011 6440 PBADRV (363b3f857abee85767e01e3044c539cd) C:\Windows\system32\DRIVERS\PBADRV.sys
17:30:14.0011 6440 PBADRV - ok
17:30:14.0041 6440 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
17:30:14.0041 6440 PcaSvc - ok
17:30:14.0091 6440 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
17:30:14.0091 6440 pci - ok
17:30:14.0141 6440 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
17:30:14.0141 6440 pciide - ok
17:30:14.0171 6440 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
17:30:14.0171 6440 pcmcia - ok
17:30:14.0201 6440 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
17:30:14.0201 6440 pcw - ok
17:30:14.0251 6440 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
17:30:14.0251 6440 PEAUTH - ok
17:30:14.0421 6440 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
17:30:14.0461 6440 PeerDistSvc - ok
17:30:14.0601 6440 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
17:30:14.0611 6440 PerfHost - ok
17:30:14.0801 6440 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
17:30:14.0821 6440 pla - ok
17:30:14.0911 6440 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
17:30:14.0911 6440 PlugPlay - ok
17:30:14.0921 6440 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
17:30:14.0921 6440 PNRPAutoReg - ok
17:30:15.0080 6440 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
17:30:15.0080 6440 PNRPsvc - ok
17:30:15.0190 6440 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
17:30:15.0210 6440 PolicyAgent - ok
17:30:15.0250 6440 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
17:30:15.0250 6440 Power - ok
17:30:15.0340 6440 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
17:30:15.0340 6440 PptpMiniport - ok
17:30:15.0380 6440 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
17:30:15.0380 6440 Processor - ok
17:30:15.0440 6440 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
17:30:15.0440 6440 ProfSvc - ok
17:30:15.0490 6440 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
17:30:15.0490 6440 ProtectedStorage - ok
17:30:15.0530 6440 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
17:30:15.0540 6440 Psched - ok
17:30:15.0580 6440 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
17:30:15.0580 6440 PxHlpa64 - ok
17:30:15.0720 6440 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
17:30:15.0740 6440 ql2300 - ok
17:30:15.0940 6440 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
17:30:15.0940 6440 ql40xx - ok
17:30:15.0980 6440 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
17:30:15.0980 6440 QWAVE - ok
17:30:16.0000 6440 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
17:30:16.0000 6440 QWAVEdrv - ok
17:30:16.0010 6440 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
17:30:16.0010 6440 RasAcd - ok
17:30:16.0090 6440 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
17:30:16.0100 6440 RasAgileVpn - ok
17:30:16.0120 6440 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
17:30:16.0120 6440 RasAuto - ok
17:30:16.0160 6440 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:30:16.0160 6440 Rasl2tp - ok
17:30:16.0210 6440 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
17:30:16.0220 6440 RasMan - ok
17:30:16.0270 6440 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
17:30:16.0270 6440 RasPppoe - ok
17:30:16.0339 6440 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
17:30:16.0349 6440 RasSstp - ok
17:30:16.0399 6440 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
17:30:16.0399 6440 rdbss - ok
17:30:16.0439 6440 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
17:30:16.0439 6440 rdpbus - ok
17:30:16.0449 6440 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:30:16.0449 6440 RDPCDD - ok
17:30:16.0479 6440 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
17:30:16.0489 6440 RDPDR - ok
17:30:16.0539 6440 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
17:30:16.0539 6440 RDPENCDD - ok
17:30:16.0569 6440 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
17:30:16.0569 6440 RDPREFMP - ok
17:30:16.0640 6440 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
17:30:16.0640 6440 RDPWD - ok
17:30:16.0703 6440 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
17:30:16.0703 6440 rdyboost - ok
17:30:16.0750 6440 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
17:30:16.0750 6440 RemoteAccess - ok
17:30:16.0843 6440 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
17:30:16.0843 6440 RemoteRegistry - ok
17:30:16.0883 6440 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
17:30:16.0893 6440 RFCOMM - ok
17:30:16.0933 6440 RimUsb (7b04c9843921ab1f695fb395422c5360) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
17:30:16.0933 6440 RimUsb - ok
17:30:17.0193 6440 RoxMediaDB12OEM (3c957189b31c34d3ad21967b12b6aed7) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe
17:30:17.0203 6440 RoxMediaDB12OEM - ok
17:30:17.0273 6440 RoxWatch12 (2b73088cc2ca757a172b425c9398e5bc) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe
17:30:17.0273 6440 RoxWatch12 - ok
17:30:17.0522 6440 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
17:30:17.0532 6440 RpcEptMapper - ok
17:30:17.0562 6440 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
17:30:17.0562 6440 RpcLocator - ok
17:30:17.0592 6440 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
17:30:17.0602 6440 RpcSs - ok
17:30:17.0672 6440 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
17:30:17.0672 6440 rspndr - ok
17:30:17.0742 6440 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
17:30:17.0742 6440 s3cap - ok
17:30:17.0762 6440 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
17:30:17.0762 6440 SamSs - ok
17:30:17.0782 6440 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
17:30:17.0782 6440 sbp2port - ok
17:30:17.0822 6440 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
17:30:17.0822 6440 SCardSvr - ok
17:30:17.0862 6440 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
17:30:17.0862 6440 scfilter - ok
17:30:17.0972 6440 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
17:30:17.0982 6440 Schedule - ok
17:30:18.0032 6440 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
17:30:18.0042 6440 SCPolicySvc - ok
17:30:18.0092 6440 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
17:30:18.0092 6440 SDRSVC - ok
17:30:18.0162 6440 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
17:30:18.0162 6440 secdrv - ok
17:30:18.0172 6440 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
17:30:18.0172 6440 seclogon - ok
17:30:18.0452 6440 SecureStorageService (8365191d0fe7df5972b889821adbe62b) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe
17:30:18.0472 6440 SecureStorageService - ok
17:30:18.0652 6440 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
17:30:18.0652 6440 SENS - ok
17:30:18.0682 6440 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
17:30:18.0682 6440 SensrSvc - ok
17:30:18.0791 6440 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
17:30:18.0791 6440 Serenum - ok
17:30:18.0801 6440 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
17:30:18.0811 6440 Serial - ok
17:30:18.0811 6440 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
17:30:18.0811 6440 sermouse - ok
17:30:18.0851 6440 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
17:30:18.0851 6440 SessionEnv - ok
17:30:18.0851 6440 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
17:30:18.0861 6440 sffdisk - ok
17:30:18.0861 6440 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
17:30:18.0861 6440 sffp_mmc - ok
17:30:18.0861 6440 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
17:30:18.0861 6440 sffp_sd - ok
17:30:18.0871 6440 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
17:30:18.0871 6440 sfloppy - ok
17:30:18.0931 6440 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
17:30:18.0941 6440 SharedAccess - ok
17:30:18.0991 6440 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
17:30:18.0991 6440 ShellHWDetection - ok
17:30:19.0011 6440 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
17:30:19.0011 6440 SiSRaid2 - ok
17:30:19.0021 6440 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
17:30:19.0021 6440 SiSRaid4 - ok
17:30:19.0052 6440 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
17:30:19.0052 6440 Smb - ok
17:30:19.0130 6440 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
17:30:19.0130 6440 SNMPTRAP - ok
17:30:19.0146 6440 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
17:30:19.0146 6440 spldr - ok
17:30:19.0177 6440 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
17:30:19.0177 6440 Spooler - ok
17:30:19.0442 6440 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
17:30:19.0567 6440 sppsvc - ok
17:30:19.0816 6440 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
17:30:19.0832 6440 sppuinotify - ok
17:30:19.0910 6440 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
17:30:19.0910 6440 srv - ok
17:30:19.0981 6440 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
17:30:19.0991 6440 srv2 - ok
17:30:20.0021 6440 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
17:30:20.0031 6440 srvnet - ok
17:30:20.0091 6440 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
17:30:20.0091 6440 SSDPSRV - ok
17:30:20.0111 6440 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
17:30:20.0111 6440 SstpSvc - ok
17:30:20.0211 6440 STacSV (b2d8b364a831427a5741f6c408fa8ae3) C:\Program Files\IDT\WDM\STacSV64.exe
17:30:20.0221 6440 STacSV - ok
17:30:20.0241 6440 stdcfltn (92e7f6666633d2dd91d527503daa7be0) C:\Windows\system32\DRIVERS\stdcfltn.sys
17:30:20.0241 6440 stdcfltn - ok
17:30:20.0281 6440 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
17:30:20.0281 6440 stexstor - ok
17:30:20.0331 6440 STHDA (ef5acde92ba3f691bbfef781cb063501) C:\Windows\system32\DRIVERS\stwrt64.sys
17:30:20.0331 6440 STHDA - ok
17:30:20.0391 6440 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
17:30:20.0391 6440 stisvc - ok
17:30:20.0481 6440 stllssvr (7731f46ec0d687a931cba063e8f90ef0) C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
17:30:20.0491 6440 stllssvr - ok
17:30:20.0540 6440 StorSvc (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll
17:30:20.0540 6440 StorSvc - ok
17:30:20.0590 6440 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
17:30:20.0590 6440 storvsc - ok
17:30:20.0930 6440 svcGenericHost (da8da61cb3289ae3840d35c3c73317a3) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\HostedAgent\svcGenericHost.exe
17:30:20.0940 6440 svcGenericHost - ok
17:30:20.0990 6440 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
17:30:20.0990 6440 swenum - ok
17:30:21.0240 6440 SwitchBoard (f577910a133a592234ebaad3f3afa258) C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
17:30:21.0250 6440 SwitchBoard - ok
17:30:21.0340 6440 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
17:30:21.0340 6440 swprv - ok
17:30:21.0440 6440 SynthVid (4cdd7df58730d23ba9cb5829a6e2ecea) C:\Windows\system32\DRIVERS\VMBusVideoM.sys
17:30:21.0440 6440 SynthVid - ok
17:30:21.0530 6440 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
17:30:21.0540 6440 SysMain - ok
17:30:21.0700 6440 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
17:30:21.0700 6440 TabletInputService - ok
17:30:21.0809 6440 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
17:30:21.0809 6440 TapiSrv - ok
17:30:21.0859 6440 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
17:30:21.0869 6440 TBS - ok
17:30:22.0162 6440 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
17:30:22.0177 6440 Tcpip - ok
17:30:22.0551 6440 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
17:30:22.0551 6440 TCPIP6 - ok
17:30:22.0744 6440 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
17:30:22.0744 6440 tcpipreg - ok
17:30:22.0946 6440 tcsd_win32.exe (3d52b206d9f6f3ecfdb5d676614e47b6) C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
17:30:22.0977 6440 tcsd_win32.exe - ok
17:30:23.0414 6440 TdmService (e2f626e4a23e12de31d8820ff143a456) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe
17:30:23.0507 6440 TdmService - ok
17:30:23.0751 6440 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
17:30:23.0751 6440 TDPIPE - ok
17:30:23.0851 6440 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
17:30:23.0851 6440 TDTCP - ok
17:30:24.0081 6440 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
17:30:24.0091 6440 tdx - ok
17:30:24.0121 6440 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
17:30:24.0121 6440 TermDD - ok
17:30:24.0201 6440 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
17:30:24.0201 6440 TermService - ok
17:30:24.0211 6440 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
17:30:24.0211 6440 Themes - ok
17:30:24.0231 6440 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
17:30:24.0231 6440 THREADORDER - ok
17:30:24.0511 6440 TmFilter (5602f33ccc295c7c80e9db2b2c5ceb06) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmXPFlt.sys
17:30:24.0511 6440 TmFilter - ok
17:30:24.0720 6440 tmlisten (bac43306908f70e878bfe01f3a9079ca) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\tmlisten.exe
17:30:24.0730 6440 tmlisten - ok
17:30:24.0980 6440 tmlwf (b5c00fc8786a237937c33aabee68ca26) C:\Windows\system32\DRIVERS\tmlwf.sys
17:30:24.0980 6440 tmlwf - ok
17:30:25.0330 6440 TmPfw (48d09383511757645c0a828622ef5ab3) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmPfw.exe
17:30:25.0330 6440 TmPfw - ok
17:30:25.0370 6440 TmPreFilter (aa78d4e62e335ead1c200875d7dac9fa) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmPreFlt.sys
17:30:25.0370 6440 TmPreFilter - ok
17:30:25.0430 6440 TmProxy (a4b0e0d9cb7aaed795bf880c3edaa08f) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\TmProxy.exe
17:30:25.0440 6440 TmProxy - ok
17:30:25.0730 6440 tmtdi (a42e6780c52b248af54c6010a9a93384) C:\Windows\system32\DRIVERS\tmtdi.sys
17:30:25.0730 6440 tmtdi - ok
17:30:25.0849 6440 tmwfp (5d38c32a4b093bc8190cf3fb9078c9cd) C:\Windows\system32\DRIVERS\tmwfp.sys
17:30:25.0849 6440 tmwfp - ok
17:30:25.0921 6440 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
17:30:25.0921 6440 TrkWks - ok
17:30:26.0045 6440 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
17:30:26.0045 6440 TrustedInstaller - ok
17:30:26.0071 6440 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:30:26.0071 6440 tssecsrv - ok
17:30:26.0111 6440 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
17:30:26.0111 6440 TsUsbFlt - ok
17:30:26.0121 6440 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
17:30:26.0121 6440 TsUsbGD - ok
17:30:26.0191 6440 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
17:30:26.0191 6440 tunnel - ok
17:30:26.0191 6440 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
17:30:26.0191 6440 uagp35 - ok
17:30:26.0231 6440 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
17:30:26.0241 6440 udfs - ok
17:30:26.0311 6440 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
17:30:26.0321 6440 UI0Detect - ok
17:30:26.0341 6440 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
17:30:26.0341 6440 uliagpkx - ok
17:30:26.0391 6440 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
17:30:26.0391 6440 umbus - ok
17:30:26.0391 6440 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
17:30:26.0391 6440 UmPass - ok
17:30:26.0431 6440 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll
17:30:26.0441 6440 UmRdpService - ok
17:30:26.0730 6440 UNS (f7a1f83f28b125aa3737bc06eabb0cd5) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
17:30:26.0770 6440 UNS - ok
17:30:27.0020 6440 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
17:30:27.0020 6440 upnphost - ok
17:30:27.0140 6440 usbccgp (19ad7990c0b67e48dac5b26f99628223) C:\Windows\system32\DRIVERS\usbccgp.sys
17:30:27.0140 6440 usbccgp - ok
17:30:27.0200 6440 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
17:30:27.0200 6440 usbcir - ok
17:30:27.0240 6440 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
17:30:27.0240 6440 usbehci - ok
17:30:27.0300 6440 usbhub (8b892002d7b79312821169a14317ab86) C:\Windows\system32\DRIVERS\usbhub.sys
17:30:27.0300 6440 usbhub - ok
17:30:27.0350 6440 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
17:30:27.0360 6440 usbohci - ok
17:30:27.0410 6440 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
17:30:27.0410 6440 usbprint - ok
17:30:27.0450 6440 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:30:27.0450 6440 USBSTOR - ok
17:30:27.0480 6440 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
17:30:27.0490 6440 usbuhci - ok
17:30:27.0530 6440 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
17:30:27.0540 6440 usbvideo - ok
17:30:27.0560 6440 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
17:30:27.0560 6440 UxSms - ok
17:30:27.0580 6440 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
17:30:27.0580 6440 VaultSvc - ok
17:30:27.0620 6440 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
17:30:27.0620 6440 vdrvroot - ok
17:30:27.0690 6440 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
17:30:27.0700 6440 vds - ok
17:30:27.0720 6440 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
17:30:27.0720 6440 vga - ok
17:30:27.0740 6440 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
17:30:27.0740 6440 VgaSave - ok
17:30:27.0759 6440 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
17:30:27.0769 6440 vhdmp - ok
17:30:27.0769 6440 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
17:30:27.0769 6440 viaide - ok
17:30:27.0799 6440 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
17:30:27.0799 6440 VMBusHID - ok
17:30:27.0809 6440 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
17:30:27.0809 6440 volmgr - ok
17:30:27.0829 6440 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
17:30:27.0839 6440 volmgrx - ok
17:30:27.0859 6440 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
17:30:27.0859 6440 volsnap - ok
17:30:27.0919 6440 vpcbus (b4a73ca4ef9a02b9738cea9ad5fe5917) C:\Windows\system32\DRIVERS\vpchbus.sys
17:30:27.0919 6440 vpcbus - ok
17:30:27.0979 6440 vpcnfltr (e675fb2b48c54f09895482e2253b289c) C:\Windows\system32\DRIVERS\vpcnfltr.sys
17:30:27.0979 6440 vpcnfltr - ok
17:30:28.0019 6440 vpcusb (5fb42082b0d19a0268705f1dd343df20) C:\Windows\system32\DRIVERS\vpcusb.sys
17:30:28.0029 6440 vpcusb - ok
17:30:28.0109 6440 vpcvmm (30d4243726a15a14f5c5e45898d14394) C:\Windows\system32\drivers\vpcvmm.sys
17:30:28.0109 6440 vpcvmm - ok
17:30:28.0571 6440 VSApiNt (ad4ba28b99bcfbff40a550872a652a33) c:\Program Files (x86)\Trend Micro\Client Server Security Agent\VSApiNt.sys
17:30:28.0581 6440 VSApiNt - ok
17:30:28.0761 6440 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
17:30:28.0761 6440 vsmraid - ok
17:30:28.0901 6440 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
17:30:28.0911 6440 VSS - ok
17:30:28.0951 6440 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
17:30:28.0961 6440 vwifibus - ok
17:30:29.0001 6440 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
17:30:29.0001 6440 vwififlt - ok
17:30:29.0051 6440 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
17:30:29.0051 6440 vwifimp - ok
17:30:29.0081 6440 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
17:30:29.0081 6440 W32Time - ok
17:30:29.0091 6440 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
17:30:29.0091 6440 WacomPen - ok
17:30:29.0141 6440 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
17:30:29.0151 6440 WANARP - ok
17:30:29.0151 6440 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
17:30:29.0151 6440 Wanarpv6 - ok
17:30:29.0291 6440 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
17:30:29.0321 6440 WatAdminSvc - ok
17:30:29.0601 6440 Wave Authentication Manager Service (e45bce01f15eeb240fe9db83b9d86be3) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe
17:30:29.0621 6440 Wave Authentication Manager Service - ok
17:30:30.0000 6440 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
17:30:30.0020 6440 wbengine - ok
17:30:30.0263 6440 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
17:30:30.0263 6440 WbioSrvc - ok
17:30:30.0310 6440 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
17:30:30.0325 6440 wcncsvc - ok
17:30:30.0341 6440 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
17:30:30.0341 6440 WcsPlugInService - ok
17:30:30.0403 6440 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
17:30:30.0403 6440 Wd - ok
17:30:30.0481 6440 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
17:30:30.0481 6440 Wdf01000 - ok
17:30:30.0528 6440 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
17:30:30.0528 6440 WdiServiceHost - ok
17:30:30.0528 6440 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
17:30:30.0528 6440 WdiSystemHost - ok
17:30:30.0559 6440 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
17:30:30.0575 6440 WebClient - ok
17:30:30.0606 6440 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
17:30:30.0606 6440 Wecsvc - ok
17:30:30.0637 6440 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
17:30:30.0637 6440 wercplsupport - ok
17:30:30.0684 6440 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
17:30:30.0699 6440 WerSvc - ok
17:30:30.0793 6440 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
17:30:30.0793 6440 WfpLwf - ok
17:30:30.0824 6440 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
17:30:30.0824 6440 WIMMount - ok
17:30:30.0871 6440 WinDefend - ok
17:30:30.0871 6440 WinHttpAutoProxySvc - ok
17:30:30.0933 6440 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
17:30:30.0933 6440 Winmgmt - ok
17:30:31.0120 6440 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
17:30:31.0151 6440 WinRM - ok
17:30:31.0370 6440 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
17:30:31.0385 6440 Wlansvc - ok
17:30:31.0447 6440 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
17:30:31.0447 6440 wlcrasvc - ok
17:30:31.0759 6440 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:30:31.0775 6440 wlidsvc - ok
17:30:31.0853 6440 wltrysvc (55dbb16fdc57808615323389241fdc99) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
17:30:31.0853 6440 wltrysvc - ok
17:30:32.0040 6440 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
17:30:32.0040 6440 WmiAcpi - ok
17:30:32.0133 6440 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
17:30:32.0133 6440 wmiApSrv - ok
17:30:32.0164 6440 WMPNetworkSvc - ok
17:30:32.0196 6440 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
17:30:32.0196 6440 WPCSvc - ok
17:30:32.0211 6440 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
17:30:32.0211 6440 WPDBusEnum - ok
17:30:32.0258 6440 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
17:30:32.0258 6440 ws2ifsl - ok
17:30:32.0289 6440 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\System32\wscsvc.dll
17:30:32.0289 6440 wscsvc - ok
17:30:32.0305 6440 WSearch - ok
17:30:32.0461 6440 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll
17:30:32.0492 6440 wuauserv - ok
17:30:32.0804 6440 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
17:30:32.0804 6440 WudfPf - ok
17:30:32.0866 6440 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:30:32.0866 6440 WUDFRd - ok
17:30:32.0913 6440 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
17:30:32.0913 6440 wudfsvc - ok
17:30:32.0944 6440 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
17:30:32.0944 6440 WwanSvc - ok
17:30:32.0991 6440 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
17:30:33.0789 6440 \Device\Harddisk0\DR0 - ok
17:30:33.0819 6440 Boot (0x1200) (0233c41453bdad069cf44fc73eda3914) \Device\Harddisk0\DR0\Partition0
17:30:33.0819 6440 \Device\Harddisk0\DR0\Partition0 - ok
17:30:33.0849 6440 Boot (0x1200) (71f6f23ec61e89644d5a15265eba049d) \Device\Harddisk0\DR0\Partition1
17:30:33.0849 6440 \Device\Harddisk0\DR0\Partition1 - ok
17:30:33.0849 6440 ============================================================
17:30:33.0849 6440 Scan finished
17:30:33.0849 6440 ============================================================
17:30:33.0859 6432 Detected object count: 0
17:30:33.0859 6432 Actual detected object count: 0

#4 jingram2b

jingram2b
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:11:29 AM

Posted 31 July 2012 - 05:41 PM

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-31 11:57:32
-----------------------------
11:57:32.618 OS Version: Windows x64 6.1.7601 Service Pack 1
11:57:32.618 Number of processors: 4 586 0x2A07
11:57:32.618 ComputerName: INTERN0003-PC UserName: jingram
11:57:33.937 Initialize success
11:57:41.562 AVAST engine defs: 12073101
11:57:42.991 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:57:42.997 Disk 0 Vendor: TOSHIBA_ MH00 Size: 238475MB BusType: 3
11:57:43.022 Disk 0 MBR read successfully
11:57:43.028 Disk 0 MBR scan
11:57:43.037 Disk 0 Windows VISTA default MBR code
11:57:43.045 Disk 0 Partition 1 00 DE Dell Utility DELL 4.1 39 MB offset 63
11:57:43.074 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 16540 MB offset 81920
11:57:43.087 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 221892 MB offset 33955840
11:57:43.105 Disk 0 scanning C:\Windows\system32\drivers
11:57:56.811 Service scanning
11:58:28.559 Modules scanning
11:58:28.561 Disk 0 trace - called modules:
11:58:28.580 ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys iaStor.sys hal.dll
11:58:28.582 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006306060]
11:58:28.582 3 CLASSPNP.SYS[fffff8800180143f] -> nt!IofCallDriver -> [0xfffffa800619ecb0]
11:58:28.582 5 stdcfltn.sys[fffff88001b1ec52] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80050a9050]
11:58:30.184 AVAST engine scan C:\Windows
11:58:32.409 AVAST engine scan C:\Windows\system32
12:03:37.490 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
12:03:44.376 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
12:06:32.156 AVAST engine scan C:\Windows\system32\drivers
12:06:55.673 AVAST engine scan C:\Users\jingram
12:12:20.971 File: C:\Users\jingram\AppData\Local\{0cce4cc5-b811-754e-074f-6012026c6652}\n **INFECTED** Win32:Sirefef-PL [Rtk]
12:16:28.600 AVAST engine scan C:\ProgramData
13:32:39.467 Scan finished successfully
13:37:46.447 Disk 0 MBR has been saved successfully to "C:\Users\jingram\Desktop\MBR.dat"
13:37:46.450 The log file has been saved successfully to "C:\Users\jingram\Desktop\aswMBR.txt"

#5 jingram2b

jingram2b
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:11:29 AM

Posted 31 July 2012 - 05:48 PM

ESET running now...

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:11:29 AM

Posted 31 July 2012 - 06:17 PM

We need advanced tools to remove this one

Read the guide here

http://www.bleepingcomputer.com/forums/topic34773.html

and create a topic here

http://www.bleepingcomputer.com/forums/forum22.html

Good luck




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users