Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus.Win32.Sirefef.r (v)


  • Please log in to reply
5 replies to this topic

#1 ETPhoneMyHome

ETPhoneMyHome

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:20 PM

Posted 01 August 2012 - 01:33 PM

This virus has caused me so much trouble. First it started with the google redirects that's when I started running scans with Avast! Avast picked up on several of these html redirect objects in my system and I removed them. But the problem kept reoccurring, soon enough I was forced restarted by the virus followed by a continuous BSOD. After finally resolving the BSOD I quickly launched other AV's and Ad-Aware and the AV program Vipre popped up with the Virus.Win32.Sirefef.r (v). I was like "Cool I can finally resolve this." NOPE. Anytime I try to disinfect it or quarantine it, it says the action has failed(On both VIPRE and Ad-Aware), I am unsure if is due to the fact that the virus is connected directly to C:\Windows\System32\Services.exe or what. I am running avast right now to at least block these redirect sites from opening but this is annoying knowing that I am not safe. If someone can suggest what to do or if there is an AV or Anti Spyware program out there that will cleanse my services.exe file it would be greatly appreciated. Thank you a lot.

Edited by ETPhoneMyHome, 01 August 2012 - 01:34 PM.


BC AdBot (Login to Remove)

 


#2 D-FRED-BROWN

D-FRED-BROWN

    Resident Bracketologist


  • Malware Response Team
  • 834 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kansas, USA
  • Local time:08:20 PM

Posted 01 August 2012 - 02:30 PM

Hello and welcome to Bleeping Computer!

I am D-FRED-BROWN and I will be helping you. :)


Please print or save this topic. It will make it easier for you to follow the instructions and complete all of the necessary steps.


----------Step 1----------------
I know you've already run TDSSKiller before, but please run it one more time so we have an up-to-date idea of what may be remaining on the computer.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Skip is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: Do not choose Cure or Delete unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

----------Step 2----------------
Please download ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingc...to-use-combofix

***IMPORTANT: save ComboFix to your Desktop***

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please go here to see a list of programs that should be disabled.

**Note: Do not mouseclick ComboFix's window while it's running. That may cause it to stall**

Please include the C:\ComboFix.txt in your next reply for further review.


----------Step 3----------------
Please download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

----------Step 4----------------
In your next reply, please include the following:
  • TDSSKiller's logfile
  • ComboFix's report (C:\ComboFix.txt)
  • Security Check checkup.txt
After that, please let me know: How is your computer running now? Do you have any questions or concerns you'd like me to address? Don't hesitate to ask. :)
Proud graduate of SpywareInfo Bootcamp
Follow me on Twitter! @dfredbrown
Posted Image
Unified Network of Instructors and Trained Eliminators

I volunteer my free time to help you. Please consider making a donation so I can continue helping people like you.
Posted Image
Thank you!

#3 ETPhoneMyHome

ETPhoneMyHome
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:20 PM

Posted 01 August 2012 - 07:50 PM

Step One:
13:38:31.0459 3024 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
13:38:32.0038 3024 ============================================================
13:38:32.0038 3024 Current date / time: 2012/08/01 13:38:32.0038
13:38:32.0038 3024 SystemInfo:
13:38:32.0038 3024
13:38:32.0038 3024 OS Version: 6.1.7601 ServicePack: 1.0
13:38:32.0038 3024 Product type: Workstation
13:38:32.0038 3024 ComputerName: ERIC-PC
13:38:32.0038 3024 UserName: Eric
13:38:32.0038 3024 Windows directory: C:\Windows
13:38:32.0038 3024 System windows directory: C:\Windows
13:38:32.0038 3024 Running under WOW64
13:38:32.0038 3024 Processor architecture: Intel x64
13:38:32.0038 3024 Number of processors: 4
13:38:32.0038 3024 Page size: 0x1000
13:38:32.0038 3024 Boot type: Normal boot
13:38:32.0038 3024 ============================================================
13:38:34.0310 3024 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:38:34.0314 3024 ============================================================
13:38:34.0314 3024 \Device\Harddisk0\DR0:
13:38:34.0336 3024 MBR partitions:
13:38:34.0336 3024 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
13:38:34.0336 3024 ============================================================
13:38:34.0437 3024 C: <-> \Device\Harddisk0\DR0\Partition0
13:38:34.0437 3024 ============================================================
13:38:34.0437 3024 Initialize success
13:38:34.0438 3024 ============================================================
13:38:35.0877 4552 ============================================================
13:38:35.0877 4552 Scan started
13:38:35.0877 4552 Mode: Manual;
13:38:35.0877 4552 ============================================================
13:38:40.0173 4552 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:38:40.0186 4552 1394ohci - ok
13:38:40.0228 4552 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:38:40.0253 4552 ACPI - ok
13:38:40.0274 4552 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:38:40.0293 4552 AcpiPmi - ok
13:38:40.0418 4552 Ad-Aware Service (af9658974154c3b6a333d86dc2e0aac8) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
13:38:40.0423 4552 Ad-Aware Service - ok
13:38:40.0729 4552 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:38:40.0731 4552 AdobeARMservice - ok
13:38:40.0841 4552 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
13:38:40.0866 4552 adp94xx - ok
13:38:40.0893 4552 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
13:38:40.0916 4552 adpahci - ok
13:38:40.0934 4552 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
13:38:40.0946 4552 adpu320 - ok
13:38:40.0971 4552 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
13:38:40.0972 4552 AeLookupSvc - ok
13:38:41.0044 4552 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
13:38:41.0065 4552 AFD - ok
13:38:41.0106 4552 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:38:41.0139 4552 agp440 - ok
13:38:41.0177 4552 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
13:38:41.0186 4552 ALG - ok
13:38:41.0227 4552 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:38:41.0238 4552 aliide - ok
13:38:41.0559 4552 ALSysIO - ok
13:38:41.0597 4552 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:38:41.0614 4552 amdide - ok
13:38:41.0662 4552 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
13:38:41.0665 4552 AmdK8 - ok
13:38:41.0694 4552 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
13:38:41.0703 4552 AmdPPM - ok
13:38:41.0807 4552 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:38:41.0818 4552 amdsata - ok
13:38:41.0896 4552 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
13:38:41.0912 4552 amdsbs - ok
13:38:41.0971 4552 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:38:41.0990 4552 amdxata - ok
13:38:42.0069 4552 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:38:42.0088 4552 AppID - ok
13:38:42.0120 4552 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
13:38:42.0138 4552 AppIDSvc - ok
13:38:42.0202 4552 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
13:38:42.0214 4552 Appinfo - ok
13:38:42.0347 4552 Apple Mobile Device (20f6f19fe9e753f2780dc2fa083ad597) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:38:42.0350 4552 Apple Mobile Device - ok
13:38:42.0398 4552 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll
13:38:42.0417 4552 AppMgmt - ok
13:38:42.0439 4552 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
13:38:42.0442 4552 arc - ok
13:38:42.0450 4552 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
13:38:42.0468 4552 arcsas - ok
13:38:42.0567 4552 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:38:42.0666 4552 aspnet_state - ok
13:38:42.0760 4552 aswFsBlk (df59b8e8df0bd2e0e303778a3806a17d) C:\Windows\system32\drivers\aswFsBlk.sys
13:38:42.0781 4552 aswFsBlk - ok
13:38:42.0854 4552 aswMonFlt (f8e6ab4f876feff69250f2e0c29ef004) C:\Windows\system32\drivers\aswMonFlt.sys
13:38:42.0871 4552 aswMonFlt - ok
13:38:42.0885 4552 aswRdr (aa92bc4bcba40ca3aa3ffd1be24f0c09) C:\Windows\System32\Drivers\aswrdr2.sys
13:38:42.0901 4552 aswRdr - ok
13:38:43.0010 4552 aswSnx (f06e230e1e8ca9437a6474b7b551cd37) C:\Windows\system32\drivers\aswSnx.sys
13:38:43.0053 4552 aswSnx - ok
13:38:43.0117 4552 aswSP (3610ca74a69e380424f0452dec5c1317) C:\Windows\system32\drivers\aswSP.sys
13:38:43.0123 4552 aswSP - ok
13:38:43.0143 4552 aswTdi (87de3e31cb0091d22351349869324065) C:\Windows\system32\drivers\aswTdi.sys
13:38:43.0146 4552 aswTdi - ok
13:38:43.0177 4552 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:38:43.0200 4552 AsyncMac - ok
13:38:43.0222 4552 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:38:43.0232 4552 atapi - ok
13:38:43.0293 4552 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:38:43.0319 4552 AudioEndpointBuilder - ok
13:38:43.0324 4552 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
13:38:43.0327 4552 AudioSrv - ok
13:38:43.0429 4552 avast! Antivirus (2f7c0f3e39c45e0127fb78b2f18a41f3) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
13:38:43.0432 4552 avast! Antivirus - ok
13:38:43.0475 4552 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
13:38:43.0488 4552 AxInstSV - ok
13:38:43.0527 4552 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
13:38:43.0553 4552 b06bdrv - ok
13:38:43.0582 4552 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:38:43.0598 4552 b57nd60a - ok
13:38:43.0664 4552 BCMH43XX (e49110a58a32e9450356686a95dd7763) C:\Windows\system32\DRIVERS\bcmwlhigh664.sys
13:38:43.0701 4552 BCMH43XX - ok
13:38:43.0738 4552 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
13:38:43.0757 4552 BDESVC - ok
13:38:43.0780 4552 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:38:43.0793 4552 Beep - ok
13:38:43.0829 4552 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
13:38:43.0847 4552 blbdrive - ok
13:38:43.0947 4552 Bonjour Service (1c87705ccb2f60172b0fc86b5d82f00d) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
13:38:43.0970 4552 Bonjour Service - ok
13:38:44.0002 4552 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:38:44.0015 4552 bowser - ok
13:38:44.0032 4552 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:38:44.0048 4552 BrFiltLo - ok
13:38:44.0067 4552 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:38:44.0081 4552 BrFiltUp - ok
13:38:44.0115 4552 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
13:38:44.0127 4552 BridgeMP - ok
13:38:44.0165 4552 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
13:38:44.0181 4552 Browser - ok
13:38:44.0210 4552 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:38:44.0226 4552 Brserid - ok
13:38:44.0244 4552 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:38:44.0247 4552 BrSerWdm - ok
13:38:44.0255 4552 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:38:44.0268 4552 BrUsbMdm - ok
13:38:44.0303 4552 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:38:44.0315 4552 BrUsbSer - ok
13:38:44.0368 4552 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
13:38:44.0381 4552 BTHMODEM - ok
13:38:44.0436 4552 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
13:38:44.0452 4552 bthserv - ok
13:38:44.0494 4552 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:38:44.0506 4552 cdfs - ok
13:38:44.0608 4552 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
13:38:44.0621 4552 cdrom - ok
13:38:44.0656 4552 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:38:44.0659 4552 CertPropSvc - ok
13:38:44.0671 4552 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
13:38:44.0673 4552 circlass - ok
13:38:44.0697 4552 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:38:44.0703 4552 CLFS - ok
13:38:44.0763 4552 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:38:44.0767 4552 clr_optimization_v2.0.50727_32 - ok
13:38:44.0823 4552 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:38:44.0828 4552 clr_optimization_v2.0.50727_64 - ok
13:38:44.0888 4552 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:38:45.0062 4552 clr_optimization_v4.0.30319_32 - ok
13:38:45.0102 4552 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:38:45.0118 4552 clr_optimization_v4.0.30319_64 - ok
13:38:45.0126 4552 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
13:38:45.0143 4552 CmBatt - ok
13:38:45.0167 4552 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:38:45.0183 4552 cmdide - ok
13:38:45.0229 4552 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
13:38:45.0254 4552 CNG - ok
13:38:45.0300 4552 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
13:38:45.0312 4552 Compbatt - ok
13:38:45.0337 4552 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:38:45.0339 4552 CompositeBus - ok
13:38:45.0342 4552 COMSysApp - ok
13:38:45.0354 4552 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
13:38:45.0356 4552 crcdisk - ok
13:38:45.0413 4552 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
13:38:45.0434 4552 CryptSvc - ok
13:38:45.0480 4552 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
13:38:45.0514 4552 CSC - ok
13:38:45.0557 4552 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll
13:38:45.0570 4552 CscService - ok
13:38:45.0621 4552 dc3d (1ca90212a99db6975c344826d11055c9) C:\Windows\system32\DRIVERS\dc3d.sys
13:38:45.0628 4552 dc3d - ok
13:38:45.0735 4552 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:38:45.0853 4552 DcomLaunch - ok
13:38:45.0925 4552 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
13:38:45.0944 4552 defragsvc - ok
13:38:46.0112 4552 Desura Install Service (2b9a817dc1bdad9ce5495099b6a7136a) C:\Program Files (x86)\Common Files\Desura\desura_service.exe
13:38:46.0118 4552 Desura Install Service - ok
13:38:46.0171 4552 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:38:46.0188 4552 DfsC - ok
13:38:46.0291 4552 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
13:38:46.0314 4552 Dhcp - ok
13:38:46.0358 4552 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:38:46.0369 4552 discache - ok
13:38:46.0424 4552 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
13:38:46.0438 4552 Disk - ok
13:38:46.0542 4552 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
13:38:46.0554 4552 Dnscache - ok
13:38:46.0692 4552 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
13:38:46.0708 4552 dot3svc - ok
13:38:46.0736 4552 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
13:38:46.0740 4552 DPS - ok
13:38:46.0756 4552 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:38:46.0758 4552 drmkaud - ok
13:38:46.0798 4552 dtsoftbus01 (400582b09e0bb557d0ec28a945150eeb) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
13:38:46.0821 4552 dtsoftbus01 - ok
13:38:46.0881 4552 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:38:46.0901 4552 DXGKrnl - ok
13:38:46.0927 4552 EagleX64 - ok
13:38:46.0951 4552 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
13:38:46.0968 4552 EapHost - ok
13:38:47.0100 4552 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
13:38:47.0168 4552 ebdrv - ok
13:38:47.0262 4552 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
13:38:47.0266 4552 EFS - ok
13:38:47.0385 4552 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
13:38:47.0412 4552 ehRecvr - ok
13:38:47.0430 4552 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
13:38:47.0431 4552 ehSched - ok
13:38:47.0476 4552 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
13:38:47.0508 4552 elxstor - ok
13:38:47.0536 4552 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:38:47.0555 4552 ErrDev - ok
13:38:47.0595 4552 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
13:38:47.0616 4552 EventSystem - ok
13:38:47.0643 4552 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:38:47.0657 4552 exfat - ok
13:38:47.0677 4552 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:38:47.0700 4552 fastfat - ok
13:38:47.0761 4552 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
13:38:47.0793 4552 Fax - ok
13:38:47.0815 4552 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
13:38:47.0834 4552 fdc - ok
13:38:47.0849 4552 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
13:38:47.0862 4552 fdPHost - ok
13:38:47.0874 4552 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
13:38:47.0892 4552 FDResPub - ok
13:38:47.0905 4552 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:38:47.0925 4552 FileInfo - ok
13:38:47.0937 4552 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:38:47.0957 4552 Filetrace - ok
13:38:48.0084 4552 FLEXnet Licensing Service (bb0667b0171b632b97ea759515476f07) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
13:38:48.0101 4552 FLEXnet Licensing Service - ok
13:38:48.0113 4552 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
13:38:48.0132 4552 flpydisk - ok
13:38:48.0165 4552 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:38:48.0170 4552 FltMgr - ok
13:38:48.0232 4552 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
13:38:48.0260 4552 FontCache - ok
13:38:48.0395 4552 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:38:48.0414 4552 FontCache3.0.0.0 - ok
13:38:48.0465 4552 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:38:48.0479 4552 FsDepends - ok
13:38:48.0548 4552 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
13:38:48.0565 4552 Fs_Rec - ok
13:38:48.0715 4552 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:38:48.0732 4552 fvevol - ok
13:38:48.0772 4552 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
13:38:48.0786 4552 gagp30kx - ok
13:38:48.0947 4552 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:38:48.0966 4552 GEARAspiWDM - ok
13:38:49.0173 4552 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
13:38:49.0181 4552 gpsvc - ok
13:38:49.0259 4552 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:38:49.0261 4552 gupdate - ok
13:38:49.0281 4552 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:38:49.0282 4552 gupdatem - ok
13:38:49.0323 4552 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
13:38:49.0340 4552 hamachi - ok
13:38:49.0755 4552 Hamachi2Svc (d483dbaef409e8ab7477c28615fcd853) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
13:38:49.0791 4552 Hamachi2Svc - ok
13:38:49.0855 4552 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:38:49.0876 4552 hcw85cir - ok
13:38:49.0923 4552 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:38:49.0929 4552 HdAudAddService - ok
13:38:49.0972 4552 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:38:50.0009 4552 HDAudBus - ok
13:38:50.0042 4552 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
13:38:50.0057 4552 HidBatt - ok
13:38:50.0098 4552 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
13:38:50.0113 4552 HidBth - ok
13:38:50.0125 4552 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
13:38:50.0140 4552 HidIr - ok
13:38:50.0164 4552 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
13:38:50.0184 4552 hidserv - ok
13:38:50.0212 4552 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
13:38:50.0232 4552 HidUsb - ok
13:38:50.0268 4552 HiPatchService (7388756bc5f9fe857c400e340b878af2) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
13:38:50.0270 4552 HiPatchService - ok
13:38:50.0286 4552 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
13:38:50.0305 4552 hkmsvc - ok
13:38:50.0332 4552 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
13:38:50.0346 4552 HomeGroupListener - ok
13:38:50.0373 4552 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
13:38:50.0405 4552 HomeGroupProvider - ok
13:38:50.0443 4552 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:38:50.0462 4552 HpSAMD - ok
13:38:50.0519 4552 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:38:50.0544 4552 HTTP - ok
13:38:50.0576 4552 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:38:50.0592 4552 hwpolicy - ok
13:38:50.0622 4552 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
13:38:50.0643 4552 i8042prt - ok
13:38:50.0687 4552 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:38:50.0704 4552 iaStorV - ok
13:38:50.0812 4552 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
13:38:50.0816 4552 IDriverT - ok
13:38:50.0920 4552 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:38:50.0943 4552 idsvc - ok
13:38:51.0001 4552 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
13:38:51.0019 4552 iirsp - ok
13:38:51.0078 4552 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
13:38:51.0114 4552 IKEEXT - ok
13:38:51.0134 4552 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:38:51.0136 4552 intelide - ok
13:38:51.0161 4552 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
13:38:51.0177 4552 intelppm - ok
13:38:51.0196 4552 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
13:38:51.0210 4552 IPBusEnum - ok
13:38:51.0231 4552 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:38:51.0245 4552 IpFilterDriver - ok
13:38:51.0266 4552 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:38:51.0279 4552 IPMIDRV - ok
13:38:51.0297 4552 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:38:51.0318 4552 IPNAT - ok
13:38:51.0413 4552 iPod Service (b7cb0b121962cd89f98c0dd89331b0c0) C:\Program Files\iPod\bin\iPodService.exe
13:38:51.0417 4552 iPod Service - ok
13:38:51.0438 4552 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:38:51.0459 4552 IRENUM - ok
13:38:51.0481 4552 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:38:51.0495 4552 isapnp - ok
13:38:51.0524 4552 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:38:51.0529 4552 iScsiPrt - ok
13:38:51.0586 4552 ISODrive (7ebda65260289c9043ba48b85135702c) C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys
13:38:51.0590 4552 ISODrive - ok
13:38:51.0600 4552 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
13:38:51.0621 4552 kbdclass - ok
13:38:51.0643 4552 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
13:38:51.0654 4552 kbdhid - ok
13:38:51.0699 4552 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:38:51.0701 4552 KeyIso - ok
13:38:51.0734 4552 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
13:38:51.0747 4552 KSecDD - ok
13:38:51.0829 4552 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
13:38:51.0852 4552 KSecPkg - ok
13:38:51.0903 4552 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:38:51.0915 4552 ksthunk - ok
13:38:52.0023 4552 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
13:38:52.0031 4552 KtmRm - ok
13:38:52.0081 4552 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
13:38:52.0103 4552 LanmanServer - ok
13:38:52.0124 4552 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
13:38:52.0146 4552 LanmanWorkstation - ok
13:38:52.0182 4552 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:38:52.0197 4552 lltdio - ok
13:38:52.0240 4552 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
13:38:52.0265 4552 lltdsvc - ok
13:38:52.0277 4552 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
13:38:52.0298 4552 lmhosts - ok
13:38:52.0333 4552 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
13:38:52.0351 4552 LSI_FC - ok
13:38:52.0375 4552 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
13:38:52.0388 4552 LSI_SAS - ok
13:38:52.0410 4552 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:38:52.0427 4552 LSI_SAS2 - ok
13:38:52.0442 4552 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:38:52.0455 4552 LSI_SCSI - ok
13:38:52.0475 4552 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:38:52.0489 4552 luafv - ok
13:38:52.0521 4552 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys
13:38:52.0905 4552 MBAMProtector - ok
13:38:53.0007 4552 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
13:38:53.0025 4552 MBAMService - ok
13:38:53.0067 4552 Mcx2Svc - ok
13:38:53.0136 4552 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
13:38:53.0149 4552 megasas - ok
13:38:53.0177 4552 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
13:38:53.0195 4552 MegaSR - ok
13:38:53.0221 4552 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:38:53.0225 4552 MMCSS - ok
13:38:53.0241 4552 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:38:53.0244 4552 Modem - ok
13:38:53.0269 4552 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:38:53.0281 4552 monitor - ok
13:38:53.0353 4552 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:38:53.0356 4552 mouclass - ok
13:38:53.0370 4552 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:38:53.0380 4552 mouhid - ok
13:38:53.0411 4552 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:38:53.0431 4552 mountmgr - ok
13:38:53.0468 4552 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:38:53.0489 4552 mpio - ok
13:38:53.0504 4552 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:38:53.0515 4552 mpsdrv - ok
13:38:53.0541 4552 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:38:53.0562 4552 MRxDAV - ok
13:38:53.0596 4552 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:38:53.0613 4552 mrxsmb - ok
13:38:53.0636 4552 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:38:53.0681 4552 mrxsmb10 - ok
13:38:53.0733 4552 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:38:53.0755 4552 mrxsmb20 - ok
13:38:53.0768 4552 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:38:53.0787 4552 msahci - ok
13:38:53.0819 4552 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:38:53.0842 4552 msdsm - ok
13:38:53.0864 4552 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
13:38:53.0884 4552 MSDTC - ok
13:38:53.0906 4552 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:38:53.0908 4552 Msfs - ok
13:38:53.0914 4552 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:38:53.0924 4552 mshidkmdf - ok
13:38:53.0940 4552 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:38:53.0942 4552 msisadrv - ok
13:38:53.0974 4552 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
13:38:53.0988 4552 MSiSCSI - ok
13:38:53.0990 4552 msiserver - ok
13:38:54.0018 4552 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:38:54.0038 4552 MSKSSRV - ok
13:38:54.0068 4552 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:38:54.0083 4552 MSPCLOCK - ok
13:38:54.0085 4552 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:38:54.0089 4552 MSPQM - ok
13:38:54.0122 4552 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:38:54.0144 4552 MsRPC - ok
13:38:54.0162 4552 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:38:54.0175 4552 mssmbios - ok
13:38:54.0186 4552 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:38:54.0188 4552 MSTEE - ok
13:38:54.0197 4552 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
13:38:54.0214 4552 MTConfig - ok
13:38:54.0269 4552 MTsensor (03b7145c889603537e9ffeabb1ad1089) C:\Windows\system32\DRIVERS\ASACPI.sys
13:38:54.0281 4552 MTsensor - ok
13:38:54.0312 4552 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:38:54.0329 4552 Mup - ok
13:38:54.0393 4552 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
13:38:54.0427 4552 napagent - ok
13:38:54.0467 4552 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:38:54.0486 4552 NativeWifiP - ok
13:38:54.0544 4552 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:38:54.0574 4552 NDIS - ok
13:38:54.0605 4552 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:38:54.0621 4552 NdisCap - ok
13:38:54.0641 4552 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:38:54.0658 4552 NdisTapi - ok
13:38:54.0697 4552 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:38:54.0717 4552 Ndisuio - ok
13:38:54.0747 4552 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:38:54.0764 4552 NdisWan - ok
13:38:54.0791 4552 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:38:54.0794 4552 NDProxy - ok
13:38:54.0816 4552 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:38:54.0827 4552 NetBIOS - ok
13:38:54.0858 4552 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:38:54.0878 4552 NetBT - ok
13:38:54.0907 4552 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:38:54.0908 4552 Netlogon - ok
13:38:54.0949 4552 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
13:38:54.0965 4552 Netman - ok
13:38:55.0079 4552 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:38:55.0097 4552 NetMsmqActivator - ok
13:38:55.0118 4552 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:38:55.0119 4552 NetPipeActivator - ok
13:38:55.0153 4552 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
13:38:55.0173 4552 netprofm - ok
13:38:55.0176 4552 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:38:55.0177 4552 NetTcpActivator - ok
13:38:55.0179 4552 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:38:55.0180 4552 NetTcpPortSharing - ok
13:38:55.0224 4552 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
13:38:55.0236 4552 nfrd960 - ok
13:38:55.0264 4552 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
13:38:55.0281 4552 NlaSvc - ok
13:38:55.0316 4552 NPF (c31fa031335eff434b2d94278e74bcce) C:\Windows\system32\DRIVERS\npf.sys
13:38:55.0320 4552 NPF - ok
13:38:55.0333 4552 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:38:55.0347 4552 Npfs - ok
13:38:55.0362 4552 npggsvc - ok
13:38:55.0374 4552 NPPTNT2 - ok
13:38:55.0395 4552 npusbio (95a2ab418251a3b2a2571cde880b80d0) C:\Windows\system32\Drivers\npusbio_x64.sys
13:38:55.0766 4552 npusbio - ok
13:38:55.0781 4552 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
13:38:55.0802 4552 nsi - ok
13:38:55.0815 4552 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:38:55.0834 4552 nsiproxy - ok
13:38:56.0239 4552 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:38:56.0281 4552 Ntfs - ok
13:38:56.0350 4552 nTuneService - ok
13:38:56.0460 4552 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:38:56.0462 4552 Null - ok
13:38:56.0489 4552 NVENETFD (a85b4f2ef3a7304a5399ef0526423040) C:\Windows\system32\DRIVERS\nvm62x64.sys
13:38:56.0496 4552 NVENETFD - ok
13:38:56.0522 4552 NVHDA (5f1ff880adacf7e0ff7c27ba188b05da) C:\Windows\system32\drivers\nvhda64v.sys
13:38:56.0568 4552 NVHDA - ok
13:38:56.0970 4552 nvlddmkm (39defe644321f9a4b7f527664f628dea) C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:38:57.0342 4552 nvlddmkm - ok
13:38:57.0387 4552 nvoclk64 (8c1d181480796d7d3366a9381fd7782d) C:\Windows\system32\DRIVERS\nvoclk64.sys
13:38:57.0390 4552 nvoclk64 - ok
13:38:57.0419 4552 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:38:57.0432 4552 nvraid - ok
13:38:57.0471 4552 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:38:57.0472 4552 nvstor - ok
13:38:57.0547 4552 nvsvc (a8bd627c6b78745ce8d591e9636e533f) C:\Windows\system32\nvvsvc.exe
13:38:57.0557 4552 nvsvc - ok
13:38:57.0652 4552 nvUpdatusService (abf9218bc7b87ed93c0b5dead9e2f7e9) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
13:38:57.0659 4552 nvUpdatusService - ok
13:38:57.0696 4552 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:38:57.0711 4552 nv_agp - ok
13:38:57.0743 4552 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:38:57.0759 4552 ohci1394 - ok
13:38:57.0909 4552 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:38:57.0913 4552 ose - ok
13:38:57.0977 4552 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:38:58.0004 4552 p2pimsvc - ok
13:38:58.0081 4552 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
13:38:58.0101 4552 p2psvc - ok
13:38:58.0184 4552 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
13:38:58.0197 4552 Parport - ok
13:38:58.0223 4552 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
13:38:58.0241 4552 partmgr - ok
13:38:58.0260 4552 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
13:38:58.0282 4552 PcaSvc - ok
13:38:58.0301 4552 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:38:58.0324 4552 pci - ok
13:38:58.0327 4552 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:38:58.0334 4552 pciide - ok
13:38:58.0355 4552 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
13:38:58.0369 4552 pcmcia - ok
13:38:58.0389 4552 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:38:58.0406 4552 pcw - ok
13:38:58.0446 4552 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:38:58.0490 4552 PEAUTH - ok
13:38:58.0554 4552 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll
13:38:58.0601 4552 PeerDistSvc - ok
13:38:58.0669 4552 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
13:38:58.0673 4552 PerfHost - ok
13:38:58.0762 4552 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
13:38:58.0807 4552 pla - ok
13:38:58.0855 4552 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
13:38:58.0880 4552 PlugPlay - ok
13:38:58.0910 4552 PnkBstrA - ok
13:38:58.0919 4552 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
13:38:58.0934 4552 PNRPAutoReg - ok
13:38:58.0947 4552 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
13:38:58.0950 4552 PNRPsvc - ok
13:38:59.0018 4552 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
13:38:59.0054 4552 PolicyAgent - ok
13:38:59.0085 4552 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
13:38:59.0091 4552 Power - ok
13:38:59.0137 4552 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:38:59.0141 4552 PptpMiniport - ok
13:38:59.0160 4552 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
13:38:59.0162 4552 Processor - ok
13:38:59.0207 4552 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
13:38:59.0230 4552 ProfSvc - ok
13:38:59.0251 4552 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:38:59.0253 4552 ProtectedStorage - ok
13:38:59.0283 4552 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:38:59.0287 4552 Psched - ok
13:38:59.0358 4552 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
13:38:59.0405 4552 ql2300 - ok
13:38:59.0469 4552 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
13:38:59.0486 4552 ql40xx - ok
13:38:59.0517 4552 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
13:38:59.0538 4552 QWAVE - ok
13:38:59.0554 4552 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:38:59.0556 4552 QWAVEdrv - ok
13:38:59.0565 4552 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:38:59.0580 4552 RasAcd - ok
13:38:59.0605 4552 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:38:59.0616 4552 RasAgileVpn - ok
13:38:59.0638 4552 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
13:38:59.0643 4552 RasAuto - ok
13:38:59.0656 4552 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:38:59.0660 4552 Rasl2tp - ok
13:38:59.0694 4552 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
13:38:59.0702 4552 RasMan - ok
13:38:59.0722 4552 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:38:59.0741 4552 RasPppoe - ok
13:38:59.0756 4552 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:38:59.0769 4552 RasSstp - ok
13:38:59.0794 4552 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:38:59.0812 4552 rdbss - ok
13:38:59.0819 4552 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:38:59.0821 4552 rdpbus - ok
13:38:59.0840 4552 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:38:59.0852 4552 RDPCDD - ok
13:38:59.0886 4552 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
13:38:59.0903 4552 RDPDR - ok
13:38:59.0924 4552 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:38:59.0927 4552 RDPENCDD - ok
13:38:59.0942 4552 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:38:59.0962 4552 RDPREFMP - ok
13:39:00.0005 4552 RdpVideoMiniport (70cba1a0c98600a2aa1863479b35cb90) C:\Windows\system32\drivers\rdpvideominiport.sys
13:39:00.0022 4552 RdpVideoMiniport - ok
13:39:00.0056 4552 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
13:39:00.0075 4552 RDPWD - ok
13:39:00.0105 4552 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:39:00.0119 4552 rdyboost - ok
13:39:00.0167 4552 RemoteAccess - ok
13:39:00.0215 4552 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
13:39:00.0221 4552 RemoteRegistry - ok
13:39:00.0307 4552 RivaTuner64 (a10b40cf9eb57d24e44717a2d38a00f4) C:\Program Files (x86)\RivaTuner v2.24\RivaTuner64.sys
13:39:00.0309 4552 RivaTuner64 - ok
13:39:00.0328 4552 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
13:39:00.0347 4552 RpcEptMapper - ok
13:39:00.0374 4552 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
13:39:00.0386 4552 RpcLocator - ok
13:39:00.0435 4552 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
13:39:00.0439 4552 RpcSs - ok
13:39:00.0446 4552 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:39:00.0487 4552 rspndr - ok
13:39:00.0549 4552 RzSynapse (24510c4a77aba3b07aefa840db888637) C:\Windows\system32\DRIVERS\RzSynapse.sys
13:39:00.0562 4552 RzSynapse - ok
13:39:00.0591 4552 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
13:39:00.0611 4552 s3cap - ok
13:39:00.0652 4552 SaiH0762 (cf0e5155a089c7c8d7cfd9d1088afda4) C:\Windows\system32\DRIVERS\SaiH0762.sys
13:39:00.0666 4552 SaiH0762 - ok
13:39:00.0677 4552 SaiMini (9e7e53891d1747a01f491ab25b95135d) C:\Windows\system32\DRIVERS\SaiMini.sys
13:39:00.0679 4552 SaiMini - ok
13:39:00.0695 4552 SaiNtBus (b3b86be19a0caf025f679c39fd21e735) C:\Windows\system32\drivers\SaiBus.sys
13:39:00.0697 4552 SaiNtBus - ok
13:39:00.0729 4552 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:39:00.0731 4552 SamSs - ok
13:39:00.0883 4552 SBAMSvc (bce943896289a91ad75cc5652620b1c6) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
13:39:00.0936 4552 SBAMSvc - ok
13:39:01.0035 4552 sbapifs (6e342316e72f4b6fa39c99e06373a1a3) C:\Windows\system32\DRIVERS\sbapifs.sys
13:39:01.0057 4552 sbapifs - ok
13:39:01.0085 4552 SbFw (e69df6ec9606c2c42ccb4ea3a18cc344) C:\Windows\system32\drivers\SbFw.sys
13:39:01.0108 4552 SbFw - ok
13:39:01.0128 4552 SBFWIMCL (f60bc3ef681ea9aa5ae25fa67e3aa310) C:\Windows\system32\DRIVERS\sbfwim.sys
13:39:01.0131 4552 SBFWIMCL - ok
13:39:01.0134 4552 SBFWIMCLMP (f60bc3ef681ea9aa5ae25fa67e3aa310) C:\Windows\system32\DRIVERS\SBFWIM.sys
13:39:01.0135 4552 SBFWIMCLMP - ok
13:39:01.0156 4552 SbHips (b671eef468d13016b9286f5835a06ae1) C:\Windows\system32\drivers\sbhips.sys
13:39:01.0171 4552 SbHips - ok
13:39:01.0192 4552 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:39:01.0211 4552 sbp2port - ok
13:39:01.0484 4552 SBPIMSvc (9ffbe1a6d3a919d83ad7984dbc012f8c) C:\Program Files (x86)\Sunbelt Software\VIPRE\SBPIMSvc.exe
13:39:01.0487 4552 SBPIMSvc - ok
13:39:01.0510 4552 SBRE (9aceb2a2362fc87a3825963e61ba9076) C:\Windows\system32\drivers\SBREdrv.sys
13:39:01.0522 4552 SBRE - ok
13:39:01.0527 4552 SbTis (c470fa779d0bd9a2309a04e49dd0eb8c) C:\Windows\system32\drivers\sbtis.sys
13:39:01.0530 4552 SbTis - ok
13:39:01.0555 4552 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
13:39:01.0577 4552 SCardSvr - ok
13:39:01.0607 4552 SCDEmu (b2f50286dc82b93c013e3fc57ba1a956) C:\Windows\system32\drivers\SCDEmu.sys
13:39:02.0004 4552 SCDEmu - ok
13:39:02.0028 4552 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:39:02.0048 4552 scfilter - ok
13:39:02.0162 4552 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
13:39:02.0195 4552 Schedule - ok
13:39:02.0215 4552 SCMNdisP (6011cdf54bb6f4c69f38faccdad73d7e) C:\Windows\system32\DRIVERS\scmndisp.sys
13:39:02.0235 4552 SCMNdisP - ok
13:39:02.0256 4552 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
13:39:02.0257 4552 SCPolicySvc - ok
13:39:02.0284 4552 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
13:39:02.0306 4552 SDRSVC - ok
13:39:02.0340 4552 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:39:02.0355 4552 secdrv - ok
13:39:02.0377 4552 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
13:39:02.0400 4552 seclogon - ok
13:39:02.0426 4552 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
13:39:02.0440 4552 SENS - ok
13:39:02.0454 4552 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
13:39:02.0472 4552 SensrSvc - ok
13:39:02.0500 4552 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
13:39:02.0502 4552 Serenum - ok
13:39:02.0514 4552 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
13:39:02.0528 4552 Serial - ok
13:39:02.0570 4552 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
13:39:02.0589 4552 sermouse - ok
13:39:02.0629 4552 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
13:39:02.0654 4552 SessionEnv - ok
13:39:02.0681 4552 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
13:39:02.0696 4552 sffdisk - ok
13:39:02.0708 4552 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:39:02.0710 4552 sffp_mmc - ok
13:39:02.0717 4552 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
13:39:02.0738 4552 sffp_sd - ok
13:39:02.0754 4552 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
13:39:02.0770 4552 sfloppy - ok
13:39:02.0808 4552 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
13:39:02.0829 4552 ShellHWDetection - ok
13:39:02.0843 4552 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:39:02.0846 4552 SiSRaid2 - ok
13:39:02.0851 4552 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
13:39:02.0862 4552 SiSRaid4 - ok
13:39:02.0882 4552 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:39:02.0894 4552 Smb - ok
13:39:02.0926 4552 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
13:39:02.0930 4552 SNMPTRAP - ok
13:39:03.0013 4552 speedfan (12583af6cbe0050651eaf2723b3ad7b3) C:\Windows\syswow64\speedfan.sys
13:39:03.0017 4552 speedfan - ok
13:39:03.0026 4552 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:39:03.0046 4552 spldr - ok
13:39:03.0099 4552 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
13:39:03.0118 4552 Spooler - ok
13:39:03.0271 4552 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
13:39:03.0335 4552 sppsvc - ok
13:39:03.0415 4552 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
13:39:03.0437 4552 sppuinotify - ok
13:39:03.0496 4552 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:39:03.0521 4552 srv - ok
13:39:03.0552 4552 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:39:03.0567 4552 srv2 - ok
13:39:03.0590 4552 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:39:03.0603 4552 srvnet - ok
13:39:03.0644 4552 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
13:39:03.0650 4552 SSDPSRV - ok
13:39:03.0664 4552 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
13:39:03.0687 4552 SstpSvc - ok
13:39:03.0732 4552 Steam Client Service - ok
13:39:03.0813 4552 Stereo Service (2c25a72b53b28034be260d81c4ea4955) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
13:39:03.0820 4552 Stereo Service - ok
13:39:03.0848 4552 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
13:39:03.0861 4552 stexstor - ok
13:39:03.0921 4552 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
13:39:03.0985 4552 stisvc - ok
13:39:04.0013 4552 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
13:39:04.0034 4552 storflt - ok
13:39:04.0047 4552 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
13:39:04.0065 4552 storvsc - ok
13:39:04.0076 4552 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:39:04.0089 4552 swenum - ok
13:39:04.0131 4552 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
13:39:04.0200 4552 swprv - ok
13:39:04.0232 4552 Synth3dVsc - ok
13:39:04.0304 4552 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
13:39:04.0363 4552 SysMain - ok
13:39:04.0411 4552 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
13:39:04.0433 4552 TabletInputService - ok
13:39:04.0458 4552 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
13:39:04.0479 4552 TapiSrv - ok
13:39:04.0500 4552 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
13:39:04.0505 4552 TBS - ok
13:39:04.0608 4552 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
13:39:04.0658 4552 Tcpip - ok
13:39:04.0762 4552 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
13:39:04.0770 4552 TCPIP6 - ok
13:39:04.0802 4552 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:39:04.0805 4552 tcpipreg - ok
13:39:04.0814 4552 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:39:04.0829 4552 TDPIPE - ok
13:39:04.0855 4552 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
13:39:04.0865 4552 TDTCP - ok
13:39:04.0893 4552 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:39:04.0913 4552 tdx - ok
13:39:04.0933 4552 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:39:04.0944 4552 TermDD - ok
13:39:04.0986 4552 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
13:39:05.0020 4552 TermService - ok
13:39:05.0039 4552 Themes (142408368385dc9f9ebfdbc872157102) C:\Windows\system32\themeservice.dll
13:39:05.0139 4552 Themes - ok
13:39:05.0165 4552 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
13:39:05.0167 4552 THREADORDER - ok
13:39:05.0181 4552 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
13:39:05.0186 4552 TrkWks - ok
13:39:05.0230 4552 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
13:39:05.0235 4552 TrustedInstaller - ok
13:39:05.0245 4552 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:39:05.0260 4552 tssecsrv - ok
13:39:05.0295 4552 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:39:05.0309 4552 TsUsbFlt - ok
13:39:05.0321 4552 tsusbhub - ok
13:39:05.0351 4552 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:39:05.0369 4552 tunnel - ok
13:39:05.0391 4552 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
13:39:05.0408 4552 uagp35 - ok
13:39:05.0434 4552 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:39:05.0451 4552 udfs - ok
13:39:05.0470 4552 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
13:39:05.0485 4552 UI0Detect - ok
13:39:05.0507 4552 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:39:05.0526 4552 uliagpkx - ok
13:39:05.0560 4552 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
13:39:05.0574 4552 umbus - ok
13:39:05.0591 4552 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
13:39:05.0609 4552 UmPass - ok
13:39:05.0636 4552 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll
13:39:05.0658 4552 UmRdpService - ok
13:39:05.0763 4552 UnlockerDriver5 (9dc07e73a4abb9acf692113b36a5009f) C:\Program Files\Unlocker\UnlockerDriver5.sys
13:39:05.0766 4552 UnlockerDriver5 - ok
13:39:05.0790 4552 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
13:39:05.0808 4552 upnphost - ok
13:39:05.0829 4552 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
13:39:05.0872 4552 USBAAPL64 - ok
13:39:05.0907 4552 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
13:39:05.0924 4552 usbaudio - ok
13:39:05.0953 4552 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:39:05.0969 4552 usbccgp - ok
13:39:06.0004 4552 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:39:06.0007 4552 usbcir - ok
13:39:06.0024 4552 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
13:39:06.0045 4552 usbehci - ok
13:39:06.0072 4552 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:39:06.0090 4552 usbhub - ok
13:39:06.0104 4552 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
13:39:06.0120 4552 usbohci - ok
13:39:06.0133 4552 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:39:06.0135 4552 usbprint - ok
13:39:06.0159 4552 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:39:06.0181 4552 USBSTOR - ok
13:39:06.0217 4552 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
13:39:06.0230 4552 usbuhci - ok
13:39:06.0252 4552 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
13:39:06.0256 4552 UxSms - ok
13:39:06.0284 4552 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
13:39:06.0286 4552 VaultSvc - ok
13:39:06.0292 4552 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:39:06.0294 4552 vdrvroot - ok
13:39:06.0323 4552 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
13:39:06.0357 4552 vds - ok
13:39:06.0421 4552 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:39:06.0433 4552 vga - ok
13:39:06.0454 4552 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:39:06.0466 4552 VgaSave - ok
13:39:06.0498 4552 VGPU - ok
13:39:06.0520 4552 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:39:06.0561 4552 vhdmp - ok
13:39:06.0612 4552 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:39:06.0632 4552 viaide - ok
13:39:06.0658 4552 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
13:39:06.0679 4552 vmbus - ok
13:39:06.0700 4552 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
13:39:06.0720 4552 VMBusHID - ok
13:39:06.0738 4552 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:39:06.0750 4552 volmgr - ok
13:39:06.0779 4552 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:39:06.0785 4552 volmgrx - ok
13:39:06.0819 4552 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:39:06.0825 4552 volsnap - ok
13:39:06.0892 4552 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
13:39:06.0906 4552 vsmraid - ok
13:39:07.0040 4552 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
13:39:07.0125 4552 VSS - ok
13:39:07.0222 4552 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
13:39:07.0224 4552 vwifibus - ok
13:39:07.0239 4552 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
13:39:07.0255 4552 vwififlt - ok
13:39:07.0318 4552 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
13:39:07.0327 4552 W32Time - ok
13:39:07.0365 4552 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
13:39:07.0384 4552 WacomPen - ok
13:39:07.0417 4552 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:39:07.0432 4552 WANARP - ok
13:39:07.0443 4552 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:39:07.0444 4552 Wanarpv6 - ok
13:39:07.0523 4552 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
13:39:07.0563 4552 WatAdminSvc - ok
13:39:07.0806 4552 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
13:39:07.0880 4552 wbengine - ok
13:39:08.0044 4552 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
13:39:08.0052 4552 WbioSrvc - ok
13:39:08.0148 4552 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
13:39:08.0164 4552 wcncsvc - ok
13:39:08.0185 4552 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
13:39:08.0200 4552 WcsPlugInService - ok
13:39:08.0218 4552 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
13:39:08.0238 4552 Wd - ok
13:39:08.0277 4552 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:39:08.0315 4552 Wdf01000 - ok
13:39:08.0335 4552 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:39:08.0340 4552 WdiServiceHost - ok
13:39:08.0342 4552 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
13:39:08.0345 4552 WdiSystemHost - ok
13:39:08.0398 4552 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
13:39:08.0419 4552 WebClient - ok
13:39:08.0441 4552 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
13:39:08.0469 4552 Wecsvc - ok
13:39:08.0507 4552 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
13:39:08.0522 4552 wercplsupport - ok
13:39:08.0545 4552 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
13:39:08.0549 4552 WerSvc - ok
13:39:08.0560 4552 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:39:08.0575 4552 WfpLwf - ok
13:39:08.0591 4552 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:39:08.0611 4552 WIMMount - ok
13:39:08.0616 4552 WinHttpAutoProxySvc - ok
13:39:08.0677 4552 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
13:39:08.0698 4552 Winmgmt - ok
13:39:08.0781 4552 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
13:39:08.0875 4552 WinRM - ok
13:39:09.0140 4552 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
13:39:09.0162 4552 Wlansvc - ok
13:39:09.0410 4552 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:39:09.0456 4552 wlidsvc - ok
13:39:09.0499 4552 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:39:09.0511 4552 WmiAcpi - ok
13:39:09.0555 4552 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
13:39:09.0570 4552 wmiApSrv - ok
13:39:09.0620 4552 WMPNetworkSvc - ok
13:39:09.0649 4552 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
13:39:09.0662 4552 WPCSvc - ok
13:39:09.0686 4552 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
13:39:09.0702 4552 WPDBusEnum - ok
13:39:09.0715 4552 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:39:09.0728 4552 ws2ifsl - ok
13:39:09.0750 4552 WsAudio_DeviceS(1) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(1).sys
13:39:09.0764 4552 WsAudio_DeviceS(1) - ok
13:39:09.0781 4552 WsAudio_DeviceS(2) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(2).sys
13:39:09.0783 4552 WsAudio_DeviceS(2) - ok
13:39:09.0795 4552 WsAudio_DeviceS(3) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(3).sys
13:39:09.0797 4552 WsAudio_DeviceS(3) - ok
13:39:09.0806 4552 WsAudio_DeviceS(4) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(4).sys
13:39:09.0808 4552 WsAudio_DeviceS(4) - ok
13:39:09.0823 4552 WsAudio_DeviceS(5) (ad12f5c7251bb8d575d560894e73cbba) C:\Windows\system32\drivers\WsAudio_DeviceS(5).sys
13:39:09.0826 4552 WsAudio_DeviceS(5) - ok
13:39:09.0828 4552 WSearch - ok
13:39:09.0906 4552 WSWNA3100 (d0697918519a4cf059c2c7e3b9e93a53) C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe
13:39:09.0912 4552 WSWNA3100 - ok
13:39:09.0926 4552 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:39:09.0940 4552 WudfPf - ok
13:39:10.0071 4552 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:39:10.0086 4552 WUDFRd - ok
13:39:10.0144 4552 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
13:39:10.0157 4552 wudfsvc - ok
13:39:10.0179 4552 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
13:39:10.0250 4552 WwanSvc - ok
13:39:10.0341 4552 X6va005 - ok
13:39:10.0405 4552 X6va008 - ok
13:39:10.0443 4552 xusb21 (2c6bc21b2d5b58d8b1d638c1704cb494) C:\Windows\system32\DRIVERS\xusb21.sys
13:39:10.0460 4552 xusb21 - ok
13:39:10.0499 4552 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:39:10.0810 4552 \Device\Harddisk0\DR0 - ok
13:39:10.0812 4552 Boot (0x1200) (2b8bdca7a375efac94db9b51b7cc0f5b) \Device\Harddisk0\DR0\Partition0
13:39:10.0813 4552 \Device\Harddisk0\DR0\Partition0 - ok
13:39:10.0813 4552 ============================================================
13:39:10.0813 4552 Scan finished
13:39:10.0813 4552 ============================================================
13:39:10.0820 3948 Detected object count: 0
13:39:10.0820 3948 Actual detected object count: 0
13:39:18.0091 2492 Deinitialize success
----------
Step Two: Unsuccessful.. I saved combofix to the desktop and after it runs through the system backup it just hangs on its dialog box. When I opened taskmanager I found that the cmd.exe that combofix turns on was running but nothing was showing up on my screen. Any tips?
----------
Step Three
Results of screen317's Security Check version 0.99.43
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Ad-Aware
Malwarebytes Anti-Malware version 1.62.0.1300
Java™ 6 Update 27
Java™ 7 Update 2
Java™ SE Development Kit 6 Update 30
Java version out of Date!
Adobe Reader X (10.1.0)
Mozilla Firefox (5.0.1)
Google Chrome 20.0.1132.47
Google Chrome 20.0.1132.57
````````Process Check: objlist.exe by Laurent````````
Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

#4 ETPhoneMyHome

ETPhoneMyHome
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:20 PM

Posted 01 August 2012 - 07:58 PM

Also a process called ctfmon.exe was running in processes while I was browsing the web, I also noticed that my flash player was open along with two other fishy processes, dont remember the exact name I think it was "flashplayer_11x33" so I deleted all three computer ran fine. But then I started avast just recently and all of a sudden it says it blocked a object from my Windows/Installer program so I deleted the contents of the malicious folder but it said the process was my services.exe file again. I mean should I just let a full system scan from avast just run again tonight and see what happens?

Edited by ETPhoneMyHome, 01 August 2012 - 08:02 PM.


#5 D-FRED-BROWN

D-FRED-BROWN

    Resident Bracketologist


  • Malware Response Team
  • 834 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kansas, USA
  • Local time:08:20 PM

Posted 01 August 2012 - 08:56 PM

ctfmon.exe and the flashplayer_11x33.exe are legitimate. Don't worry about them.

We'll leave Avast for later.

Step Two: Unsuccessful.. I saved combofix to the desktop and after it runs through the system backup it just hangs on its dialog box. When I opened taskmanager I found that the cmd.exe that combofix turns on was running but nothing was showing up on my screen. Any tips?

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu). Try running ComboFix from there.

---------------------------
If that doesn't work, try this:

The Kaspersky Rescue Disk is a bootable CD based version of Kaspersky Antivirus.
The download is in ISO format.
If you are not sure how to burn an image, please read How to write a CD/DVD image or ISO. If you need a FREE utility to burn the ISO image, download and use ImgBurn.

Download the Kaspersky Rescue Disk:
http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/ .
  • Burn the Kaspersky Rescue Disk ISO image to CD.
  • Insert the Kaspersky Rescue Disk CD into your CD/DVD drive and boot the computer (you may need to change the boot sequence in your system's BIOS to boot from the CD/DVD drive).
  • Follow the instructions in the initial text screen to press Enter to start Kaspersky AntiVirus.
  • Select your language (or wait a few seconds for the default English to load).
  • Your screen may go blank for several minutes while the program loads.
  • After the Kaspersky Rescue Disk loads, the database will be updated (if you have network connectivity)
    • Click the Update tab to view the update progress.
    • When the update has completed, click the Scan tab.
  • Place a checkmark in all the available drives to scan the entire system.
  • Click the "Security level" option, and select options.
    • Make sure "All Files" is selected
    • Under "Scan of compound files" ensure all options are selected and click the OK button.
  • Click the "On threat detection" option
    • Select "Do not prompt", "Disinfect", and "Delete if disinfection fails".
  • Click the "Start scan" button.
  • When the scan has completed, click the Reports button.
    • Click the Save button, and select your System drive (normally your C: drive)
    • In the "File name" box, name the file krd-log and click the Save button.
    • Click Close to close the Reports window.
  • Click the Exit button to close the Rescue Disk program and confirm.
    In the lower left of the screen, left-click the red K button, select Logout, and confirm.
  • The computer will shut down.
  • Restart the computer and reboot normally.
  • Please post the log (krd-log.txt) in your next reply.

Edited by D-FRED-BROWN, 01 August 2012 - 08:57 PM.

Proud graduate of SpywareInfo Bootcamp
Follow me on Twitter! @dfredbrown
Posted Image
Unified Network of Instructors and Trained Eliminators

I volunteer my free time to help you. Please consider making a donation so I can continue helping people like you.
Posted Image
Thank you!

#6 D-FRED-BROWN

D-FRED-BROWN

    Resident Bracketologist


  • Malware Response Team
  • 834 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Kansas, USA
  • Local time:08:20 PM

Posted 05 August 2012 - 03:41 PM

(bump)

Are you still with me? If your problems still persist, let me know and we'll go about fixing them. :wink:
If not, please let me know so I can close this topic.

-DFB
Proud graduate of SpywareInfo Bootcamp
Follow me on Twitter! @dfredbrown
Posted Image
Unified Network of Instructors and Trained Eliminators

I volunteer my free time to help you. Please consider making a donation so I can continue helping people like you.
Posted Image
Thank you!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users