Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Relatively Long Infection


  • This topic is locked This topic is locked
7 replies to this topic

#1 Minlas

Minlas

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 09 August 2012 - 06:21 PM

So some time ago my brother was using my younger brother (isn't this how all of the stories start) was using my computer and clicked on some random e-mail link. I came home and there was the Security Essentials 2010 stuff popping up and running all over the place. At the time I was running AVG, I believe an expired McAfee was also on the machine. In any event that wasn't working I got the computer into safe mode downloaded Malwarebytes and thought I cleaned up that infection.

Some time later I noticed some google redirects and some general slowness on the machine. I decided i needed to start paying attention to my security stuff better did some googling and decided to go with MSE and a fresh copy of Malwarebytes together. The fresh copy of malwarebytes started picking up some rootkits which it couldn't clean. As soon as I installed MSE the computer basically went nuts and started restarting every minute or so. I system restored back to some point between the original clean up and the current problem. I again downloaded MSE and it contiued finding rootkits this time it was also finding sirefef.aa (I will also say I did experience the fake adobe update during this process which i have read is associated with sirefef). I uninstalled McAfee again and the sirefef findings stopped. At this point MSE was able to run scans and was finding the Alureon trojan.

I googled around on that virus a bit and found that windows offline boot defender might work. I burned into onto a CD ran the full scan of the CD and restarted. It did not fix the issue as I just got a redirect and MSE/Malwarebytes are still finding trojans they can't clean. I read about combofix and was thinking about giving that a try before I have to totally reformat (to get my computer back to where I can work on it will cost an incredible amount of time that would be a huge inconvenience at the moment).

The above issues may all be related and may not be, I figured I would give the whole history for this machine. I would appreciate any help and I realize this/these infections are my fault for being very lazy about my virus protection. I think I have become a lot more educated about the current state of net security and regardless of whether I am able to clean this up, these forums have provided a lot of helpful advice. Thanks.

Edit: this was posted from a laptop that I don't believe has any infections. The machine in question is right next to me and is off.

Edited by Minlas, 09 August 2012 - 06:23 PM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:23 AM

Posted 09 August 2012 - 06:30 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 Minlas

Minlas
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 09 August 2012 - 06:48 PM

Here is TDSSKiller log


19:45:17.0206 4052 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
19:45:19.0207 4052 ============================================================
19:45:19.0207 4052 Current date / time: 2012/08/09 19:45:19.0207
19:45:19.0207 4052 SystemInfo:
19:45:19.0207 4052
19:45:19.0207 4052 OS Version: 6.1.7601 ServicePack: 1.0
19:45:19.0207 4052 Product type: Workstation
19:45:19.0207 4052 ComputerName: ANDYV
19:45:19.0207 4052 UserName: Joseph
19:45:19.0207 4052 Windows directory: C:\Windows
19:45:19.0207 4052 System windows directory: C:\Windows
19:45:19.0207 4052 Running under WOW64
19:45:19.0207 4052 Processor architecture: Intel x64
19:45:19.0207 4052 Number of processors: 8
19:45:19.0207 4052 Page size: 0x1000
19:45:19.0208 4052 Boot type: Normal boot
19:45:19.0208 4052 ============================================================
19:45:19.0529 4052 Drive \Device\Harddisk0\DR0 - Size: 0xE8E1300000 (931.52 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:45:19.0533 4052 ============================================================
19:45:19.0533 4052 \Device\Harddisk0\DR0:
19:45:19.0533 4052 MBR partitions:
19:45:19.0533 4052 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x15C3000
19:45:19.0533 4052 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x15D7000, BlocksNum 0x73132000
19:45:19.0533 4052 ============================================================
19:45:19.0572 4052 C: <-> \Device\Harddisk0\DR0\Partition1
19:45:19.0572 4052 ============================================================
19:45:19.0572 4052 Initialize success
19:45:19.0572 4052 ============================================================
19:45:34.0532 5196 ============================================================
19:45:34.0532 5196 Scan started
19:45:34.0532 5196 Mode: Manual; TDLFS;
19:45:34.0532 5196 ============================================================
19:45:37.0386 5196 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
19:45:37.0387 5196 1394ohci - ok
19:45:37.0465 5196 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
19:45:37.0466 5196 ACPI - ok
19:45:37.0527 5196 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
19:45:37.0528 5196 AcpiPmi - ok
19:45:37.0590 5196 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
19:45:37.0592 5196 adp94xx - ok
19:45:37.0650 5196 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
19:45:37.0651 5196 adpahci - ok
19:45:37.0704 5196 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
19:45:37.0705 5196 adpu320 - ok
19:45:37.0738 5196 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
19:45:37.0739 5196 AeLookupSvc - ok
19:45:37.0795 5196 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
19:45:37.0797 5196 AFD - ok
19:45:37.0840 5196 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
19:45:37.0841 5196 agp440 - ok
19:45:37.0880 5196 akmcehgk (fa1dabdba6721f4fe345413b3a189ead) C:\Windows\system32\drivers\akmcehgk.sys
19:45:37.0881 5196 akmcehgk - ok
19:45:37.0911 5196 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
19:45:37.0912 5196 ALG - ok
19:45:37.0926 5196 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
19:45:37.0934 5196 aliide - ok
19:45:37.0996 5196 AMD External Events Utility (962227630779043b5c1d4cd157abb912) C:\Windows\system32\atiesrxx.exe
19:45:37.0997 5196 AMD External Events Utility - ok
19:45:38.0001 5196 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
19:45:38.0001 5196 amdide - ok
19:45:38.0060 5196 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
19:45:38.0061 5196 AmdK8 - ok
19:45:38.0236 5196 amdkmdag (56d6631761ec37745f0df16bcdc4caf4) C:\Windows\system32\DRIVERS\atikmdag.sys
19:45:38.0317 5196 amdkmdag - ok
19:45:38.0388 5196 amdkmdap (2d9005ea0bfd25c740e53c8dd3c069e0) C:\Windows\system32\DRIVERS\atikmpag.sys
19:45:38.0389 5196 amdkmdap - ok
19:45:38.0409 5196 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
19:45:38.0410 5196 AmdPPM - ok
19:45:38.0446 5196 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
19:45:38.0446 5196 amdsata - ok
19:45:38.0510 5196 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
19:45:38.0512 5196 amdsbs - ok
19:45:38.0552 5196 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
19:45:38.0552 5196 amdxata - ok
19:45:38.0658 5196 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
19:45:38.0658 5196 AppID - ok
19:45:38.0681 5196 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
19:45:38.0682 5196 AppIDSvc - ok
19:45:38.0749 5196 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
19:45:38.0749 5196 Appinfo - ok
19:45:38.0889 5196 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:45:38.0890 5196 Apple Mobile Device - ok
19:45:38.0936 5196 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
19:45:38.0937 5196 arc - ok
19:45:38.0981 5196 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
19:45:38.0990 5196 arcsas - ok
19:45:39.0027 5196 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
19:45:39.0027 5196 AsyncMac - ok
19:45:39.0098 5196 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
19:45:39.0099 5196 atapi - ok
19:45:39.0173 5196 athr (195786ed7a26e1913a4f9799fdbc2c71) C:\Windows\system32\DRIVERS\athrx.sys
19:45:39.0180 5196 athr - ok
19:45:39.0236 5196 AtiHDAudioService (2b3b05c0a7768bf033217eb8f33f9c35) C:\Windows\system32\drivers\AtihdW76.sys
19:45:39.0237 5196 AtiHDAudioService - ok
19:45:39.0283 5196 AtiHdmiService (77c149e6d702737b2e372dee166faef8) C:\Windows\system32\drivers\AtiHdmi.sys
19:45:39.0291 5196 AtiHdmiService - ok
19:45:39.0378 5196 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:45:39.0381 5196 AudioEndpointBuilder - ok
19:45:39.0385 5196 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
19:45:39.0387 5196 AudioSrv - ok
19:45:39.0456 5196 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
19:45:39.0464 5196 AxInstSV - ok
19:45:39.0514 5196 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
19:45:39.0519 5196 b06bdrv - ok
19:45:39.0547 5196 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
19:45:39.0549 5196 b57nd60a - ok
19:45:39.0684 5196 BBSvc (ceabb1e93186e7056ea46cbad8f8fd85) C:\Program Files (x86)\Microsoft\BingBar\7.1.382.0\BBSvc.exe
19:45:39.0685 5196 BBSvc - ok
19:45:39.0785 5196 BBUpdate (c0d34db1235b6a5c3df5a5c212d67f73) C:\Program Files (x86)\Microsoft\BingBar\7.1.382.0\SeaPort.exe
19:45:39.0786 5196 BBUpdate - ok
19:45:39.0846 5196 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
19:45:39.0856 5196 BDESVC - ok
19:45:39.0885 5196 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
19:45:39.0886 5196 Beep - ok
19:45:39.0936 5196 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
19:45:39.0937 5196 blbdrive - ok
19:45:40.0078 5196 Bonjour Service (ebbcd5dfbb1de70e8f4af8fa59e401fd) C:\Program Files\Bonjour\mDNSResponder.exe
19:45:40.0080 5196 Bonjour Service - ok
19:45:40.0128 5196 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
19:45:40.0129 5196 bowser - ok
19:45:40.0159 5196 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
19:45:40.0160 5196 BrFiltLo - ok
19:45:40.0173 5196 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
19:45:40.0174 5196 BrFiltUp - ok
19:45:40.0246 5196 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
19:45:40.0246 5196 Browser - ok
19:45:40.0289 5196 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
19:45:40.0290 5196 Brserid - ok
19:45:40.0316 5196 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
19:45:40.0317 5196 BrSerWdm - ok
19:45:40.0337 5196 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
19:45:40.0338 5196 BrUsbMdm - ok
19:45:40.0351 5196 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
19:45:40.0351 5196 BrUsbSer - ok
19:45:40.0370 5196 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
19:45:40.0371 5196 BTHMODEM - ok
19:45:40.0424 5196 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
19:45:40.0425 5196 bthserv - ok
19:45:40.0456 5196 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
19:45:40.0457 5196 cdfs - ok
19:45:40.0549 5196 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
19:45:40.0549 5196 cdrom - ok
19:45:40.0608 5196 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
19:45:40.0608 5196 CertPropSvc - ok
19:45:40.0655 5196 cfwids (ed0263b2eb24f0f4e3898036fa1d28a1) C:\Windows\system32\drivers\cfwids.sys
19:45:40.0656 5196 cfwids - ok
19:45:40.0694 5196 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
19:45:40.0694 5196 circlass - ok
19:45:40.0789 5196 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
19:45:40.0791 5196 CLFS - ok
19:45:40.0875 5196 CLKMSVC10_9EC60124 (fdff50af8a708a23b7de1d69c285a2ae) c:\Program Files (x86)\CyberLink\PowerDVD9\NavFilter\kmsvc.exe
19:45:40.0877 5196 CLKMSVC10_9EC60124 - ok
19:45:40.0955 5196 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:45:40.0957 5196 clr_optimization_v2.0.50727_32 - ok
19:45:40.0985 5196 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:45:40.0987 5196 clr_optimization_v2.0.50727_64 - ok
19:45:41.0087 5196 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:45:41.0088 5196 clr_optimization_v4.0.30319_32 - ok
19:45:41.0122 5196 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:45:41.0123 5196 clr_optimization_v4.0.30319_64 - ok
19:45:41.0153 5196 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
19:45:41.0154 5196 CmBatt - ok
19:45:41.0163 5196 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
19:45:41.0164 5196 cmdide - ok
19:45:41.0255 5196 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys
19:45:41.0257 5196 CNG - ok
19:45:41.0277 5196 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
19:45:41.0278 5196 Compbatt - ok
19:45:41.0305 5196 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
19:45:41.0313 5196 CompositeBus - ok
19:45:41.0315 5196 COMSysApp - ok
19:45:41.0512 5196 cpuz134 - ok
19:45:41.0540 5196 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
19:45:41.0540 5196 crcdisk - ok
19:45:41.0606 5196 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll
19:45:41.0607 5196 CryptSvc - ok
19:45:41.0739 5196 cvhsvc (72794d112cbaff3bc0c29bf7350d4741) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
19:45:41.0742 5196 cvhsvc - ok
19:45:41.0823 5196 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
19:45:41.0826 5196 DcomLaunch - ok
19:45:41.0870 5196 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
19:45:41.0871 5196 defragsvc - ok
19:45:41.0918 5196 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
19:45:41.0919 5196 DfsC - ok
19:45:41.0981 5196 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
19:45:41.0982 5196 Dhcp - ok
19:45:42.0004 5196 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
19:45:42.0005 5196 discache - ok
19:45:42.0021 5196 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
19:45:42.0022 5196 Disk - ok
19:45:42.0062 5196 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
19:45:42.0063 5196 Dnscache - ok
19:45:42.0219 5196 DockLoginService (0840abbbdf438691ee65a20040635cbe) C:\Program Files\Dell\DellDock\DockLogin.exe
19:45:42.0220 5196 DockLoginService - ok
19:45:42.0284 5196 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
19:45:42.0286 5196 dot3svc - ok
19:45:42.0353 5196 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
19:45:42.0355 5196 DPS - ok
19:45:42.0410 5196 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
19:45:42.0410 5196 drmkaud - ok
19:45:42.0474 5196 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
19:45:42.0478 5196 DXGKrnl - ok
19:45:42.0515 5196 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
19:45:42.0516 5196 EapHost - ok
19:45:42.0610 5196 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
19:45:42.0627 5196 ebdrv - ok
19:45:42.0710 5196 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
19:45:42.0711 5196 EFS - ok
19:45:42.0796 5196 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe
19:45:42.0802 5196 ehRecvr - ok
19:45:42.0829 5196 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
19:45:42.0830 5196 ehSched - ok
19:45:42.0895 5196 ElbyCDIO (9a47ac3dfcf81d30922cdaaf1c2d579f) C:\Windows\system32\Drivers\ElbyCDIO.sys
19:45:42.0895 5196 ElbyCDIO - ok
19:45:42.0964 5196 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
19:45:42.0967 5196 elxstor - ok
19:45:43.0004 5196 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
19:45:43.0004 5196 ErrDev - ok
19:45:43.0077 5196 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
19:45:43.0079 5196 EventSystem - ok
19:45:43.0139 5196 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
19:45:43.0140 5196 exfat - ok
19:45:43.0185 5196 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
19:45:43.0186 5196 fastfat - ok
19:45:43.0256 5196 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
19:45:43.0259 5196 Fax - ok
19:45:43.0270 5196 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
19:45:43.0271 5196 fdc - ok
19:45:43.0301 5196 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
19:45:43.0302 5196 fdPHost - ok
19:45:43.0319 5196 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
19:45:43.0319 5196 FDResPub - ok
19:45:43.0360 5196 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
19:45:43.0360 5196 FileInfo - ok
19:45:43.0374 5196 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
19:45:43.0374 5196 Filetrace - ok
19:45:43.0438 5196 FLEXnet Licensing Service (8669be94f63944e4f899c3950b520241) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
19:45:43.0443 5196 FLEXnet Licensing Service - ok
19:45:43.0472 5196 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
19:45:43.0473 5196 flpydisk - ok
19:45:43.0534 5196 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
19:45:43.0536 5196 FltMgr - ok
19:45:43.0607 5196 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
19:45:43.0612 5196 FontCache - ok
19:45:43.0702 5196 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:45:43.0703 5196 FontCache3.0.0.0 - ok
19:45:43.0730 5196 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
19:45:43.0731 5196 FsDepends - ok
19:45:43.0750 5196 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys
19:45:43.0750 5196 Fs_Rec - ok
19:45:43.0802 5196 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
19:45:43.0803 5196 fvevol - ok
19:45:43.0835 5196 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
19:45:43.0835 5196 gagp30kx - ok
19:45:43.0867 5196 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:45:43.0867 5196 GEARAspiWDM - ok
19:45:43.0961 5196 GoToAssist (d3316f6e3c011435f36e3d6e49b3196c) C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
19:45:43.0962 5196 GoToAssist - ok
19:45:44.0020 5196 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
19:45:44.0024 5196 gpsvc - ok
19:45:44.0048 5196 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
19:45:44.0071 5196 hcw85cir - ok
19:45:44.0148 5196 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
19:45:44.0148 5196 HDAudBus - ok
19:45:44.0179 5196 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
19:45:44.0180 5196 HidBatt - ok
19:45:44.0226 5196 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
19:45:44.0227 5196 HidBth - ok
19:45:44.0266 5196 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
19:45:44.0266 5196 HidIr - ok
19:45:44.0289 5196 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\system32\hidserv.dll
19:45:44.0290 5196 hidserv - ok
19:45:44.0354 5196 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\drivers\hidusb.sys
19:45:44.0354 5196 HidUsb - ok
19:45:44.0396 5196 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
19:45:44.0397 5196 hkmsvc - ok
19:45:44.0445 5196 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
19:45:44.0446 5196 HomeGroupListener - ok
19:45:44.0500 5196 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
19:45:44.0502 5196 HomeGroupProvider - ok
19:45:44.0521 5196 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
19:45:44.0522 5196 HpSAMD - ok
19:45:44.0557 5196 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
19:45:44.0561 5196 HTTP - ok
19:45:44.0579 5196 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
19:45:44.0579 5196 hwpolicy - ok
19:45:44.0628 5196 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
19:45:44.0629 5196 i8042prt - ok
19:45:44.0658 5196 iaStor (abbf174cb394f5c437410a788b7e404a) C:\Windows\system32\DRIVERS\iaStor.sys
19:45:44.0660 5196 iaStor - ok
19:45:44.0733 5196 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
19:45:44.0734 5196 IAStorDataMgrSvc - ok
19:45:44.0788 5196 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
19:45:44.0790 5196 iaStorV - ok
19:45:44.0896 5196 IDriverT (6f95324909b502e2651442c1548ab12f) C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
19:45:44.0906 5196 IDriverT - ok
19:45:45.0003 5196 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:45:45.0008 5196 idsvc - ok
19:45:45.0057 5196 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
19:45:45.0057 5196 iirsp - ok
19:45:45.0124 5196 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
19:45:45.0128 5196 IKEEXT - ok
19:45:45.0250 5196 IntcAzAudAddService (a0eab13a78cc5fb960ec76e3d6408da3) C:\Windows\system32\drivers\RTKVHD64.sys
19:45:45.0259 5196 IntcAzAudAddService - ok
19:45:45.0329 5196 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
19:45:45.0330 5196 intelide - ok
19:45:45.0359 5196 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
19:45:45.0360 5196 intelppm - ok
19:45:45.0436 5196 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
19:45:45.0437 5196 IPBusEnum - ok
19:45:45.0506 5196 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:45:45.0507 5196 IpFilterDriver - ok
19:45:45.0546 5196 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
19:45:45.0547 5196 IPMIDRV - ok
19:45:45.0595 5196 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
19:45:45.0596 5196 IPNAT - ok
19:45:45.0747 5196 iPod Service (755e4ba6dce627a2683bb7640553c8d6) C:\Program Files\iPod\bin\iPodService.exe
19:45:45.0751 5196 iPod Service - ok
19:45:45.0779 5196 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
19:45:45.0780 5196 IRENUM - ok
19:45:45.0857 5196 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
19:45:45.0858 5196 isapnp - ok
19:45:45.0926 5196 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
19:45:45.0928 5196 iScsiPrt - ok
19:45:45.0968 5196 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
19:45:45.0968 5196 kbdclass - ok
19:45:46.0007 5196 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
19:45:46.0007 5196 kbdhid - ok
19:45:46.0032 5196 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:45:46.0032 5196 KeyIso - ok
19:45:46.0097 5196 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys
19:45:46.0098 5196 KSecDD - ok
19:45:46.0130 5196 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys
19:45:46.0131 5196 KSecPkg - ok
19:45:46.0147 5196 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
19:45:46.0147 5196 ksthunk - ok
19:45:46.0363 5196 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
19:45:46.0365 5196 KtmRm - ok
19:45:46.0448 5196 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\system32\srvsvc.dll
19:45:46.0449 5196 LanmanServer - ok
19:45:46.0495 5196 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
19:45:46.0497 5196 LanmanWorkstation - ok
19:45:46.0538 5196 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
19:45:46.0538 5196 lltdio - ok
19:45:46.0606 5196 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
19:45:46.0608 5196 lltdsvc - ok
19:45:46.0631 5196 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
19:45:46.0631 5196 lmhosts - ok
19:45:46.0709 5196 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
19:45:46.0710 5196 LSI_FC - ok
19:45:46.0728 5196 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
19:45:46.0737 5196 LSI_SAS - ok
19:45:46.0743 5196 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
19:45:46.0750 5196 LSI_SAS2 - ok
19:45:46.0789 5196 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
19:45:46.0790 5196 LSI_SCSI - ok
19:45:46.0845 5196 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
19:45:46.0846 5196 luafv - ok
19:45:46.0977 5196 McShield (325b166bf78d8a8ad93e44ca7a6fc332) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
19:45:46.0978 5196 McShield - ok
19:45:47.0031 5196 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll
19:45:47.0033 5196 Mcx2Svc - ok
19:45:47.0056 5196 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
19:45:47.0056 5196 megasas - ok
19:45:47.0111 5196 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
19:45:47.0112 5196 MegaSR - ok
19:45:47.0178 5196 mfeapfk (ef3acfb7e3f82d5f7cde9ef5f0a4e2e2) C:\Windows\system32\drivers\mfeapfk.sys
19:45:47.0179 5196 mfeapfk - ok
19:45:47.0205 5196 mfeavfk (e7a60bdb4365b561d896019b82fb7dd0) C:\Windows\system32\drivers\mfeavfk.sys
19:45:47.0206 5196 mfeavfk - ok
19:45:47.0297 5196 mfefire (7d8fdc43972d059907e09ee4022f77e8) C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
19:45:47.0298 5196 mfefire - ok
19:45:47.0379 5196 mfefirek (670dffe55e2f9ab99d9169c428bcece9) C:\Windows\system32\drivers\mfefirek.sys
19:45:47.0381 5196 mfefirek - ok
19:45:47.0442 5196 mfehidk (1892616b7f9291fd77c3fa0a5811fe9f) C:\Windows\system32\drivers\mfehidk.sys
19:45:47.0445 5196 mfehidk - ok
19:45:47.0511 5196 mfenlfk (1721261c77f6e7a9e0cb51b7d9f31b60) C:\Windows\system32\DRIVERS\mfenlfk.sys
19:45:47.0511 5196 mfenlfk - ok
19:45:47.0575 5196 mferkdet (65776bd8029e409935b90de30bf99526) C:\Windows\system32\drivers\mferkdet.sys
19:45:47.0576 5196 mferkdet - ok
19:45:47.0677 5196 mfevtp (8a78905057308b084eaa29a9fe1b4f58) C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
19:45:47.0678 5196 mfevtp - ok
19:45:47.0762 5196 mfewfpk (4f17d8b85b903d96ef7033bb6ef50516) C:\Windows\system32\drivers\mfewfpk.sys
19:45:47.0763 5196 mfewfpk - ok
19:45:47.0877 5196 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
19:45:47.0878 5196 Microsoft Office Groove Audit Service - ok
19:45:47.0902 5196 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
19:45:47.0903 5196 MMCSS - ok
19:45:47.0927 5196 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
19:45:47.0928 5196 Modem - ok
19:45:47.0964 5196 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
19:45:47.0965 5196 monitor - ok
19:45:48.0000 5196 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\drivers\mouclass.sys
19:45:48.0001 5196 mouclass - ok
19:45:48.0025 5196 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
19:45:48.0026 5196 mouhid - ok
19:45:48.0083 5196 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
19:45:48.0084 5196 mountmgr - ok
19:45:48.0179 5196 MozillaMaintenance (46297fa8e30a6007f14118fc2b942fbc) C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
19:45:48.0180 5196 MozillaMaintenance - ok
19:45:48.0241 5196 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
19:45:48.0243 5196 mpio - ok
19:45:48.0279 5196 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
19:45:48.0280 5196 mpsdrv - ok
19:45:48.0359 5196 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
19:45:48.0360 5196 MRxDAV - ok
19:45:48.0435 5196 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
19:45:48.0436 5196 mrxsmb - ok
19:45:48.0521 5196 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:45:48.0522 5196 mrxsmb10 - ok
19:45:48.0553 5196 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:45:48.0554 5196 mrxsmb20 - ok
19:45:48.0575 5196 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
19:45:48.0576 5196 msahci - ok
19:45:48.0616 5196 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
19:45:48.0617 5196 msdsm - ok
19:45:48.0680 5196 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
19:45:48.0681 5196 MSDTC - ok
19:45:48.0731 5196 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
19:45:48.0731 5196 Msfs - ok
19:45:48.0742 5196 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
19:45:48.0742 5196 mshidkmdf - ok
19:45:48.0780 5196 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
19:45:48.0780 5196 msisadrv - ok
19:45:48.0843 5196 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
19:45:48.0849 5196 MSiSCSI - ok
19:45:48.0851 5196 msiserver - ok
19:45:48.0880 5196 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
19:45:48.0881 5196 MSKSSRV - ok
19:45:48.0914 5196 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
19:45:48.0915 5196 MSPCLOCK - ok
19:45:48.0927 5196 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
19:45:48.0935 5196 MSPQM - ok
19:45:48.0991 5196 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
19:45:48.0993 5196 MsRPC - ok
19:45:49.0009 5196 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
19:45:49.0009 5196 mssmbios - ok
19:45:49.0029 5196 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
19:45:49.0030 5196 MSTEE - ok
19:45:49.0061 5196 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
19:45:49.0062 5196 MTConfig - ok
19:45:49.0102 5196 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
19:45:49.0102 5196 Mup - ok
19:45:49.0167 5196 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
19:45:49.0170 5196 napagent - ok
19:45:49.0232 5196 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
19:45:49.0233 5196 NativeWifiP - ok
19:45:49.0291 5196 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
19:45:49.0295 5196 NDIS - ok
19:45:49.0316 5196 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
19:45:49.0317 5196 NdisCap - ok
19:45:49.0349 5196 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
19:45:49.0350 5196 NdisTapi - ok
19:45:49.0409 5196 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
19:45:49.0409 5196 Ndisuio - ok
19:45:49.0463 5196 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
19:45:49.0464 5196 NdisWan - ok
19:45:49.0516 5196 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
19:45:49.0516 5196 NDProxy - ok
19:45:49.0522 5196 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
19:45:49.0522 5196 NetBIOS - ok
19:45:49.0576 5196 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
19:45:49.0578 5196 NetBT - ok
19:45:49.0580 5196 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:45:49.0580 5196 Netlogon - ok
19:45:49.0627 5196 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
19:45:49.0629 5196 Netman - ok
19:45:49.0661 5196 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
19:45:49.0663 5196 netprofm - ok
19:45:49.0763 5196 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:45:49.0764 5196 NetTcpPortSharing - ok
19:45:49.0822 5196 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
19:45:49.0823 5196 nfrd960 - ok
19:45:49.0907 5196 nhsfjkkx (fa1dabdba6721f4fe345413b3a189ead) C:\Windows\system32\drivers\nhsfjkkx.sys
19:45:49.0907 5196 nhsfjkkx - ok
19:45:49.0963 5196 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
19:45:49.0965 5196 NlaSvc - ok
19:45:49.0990 5196 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
19:45:49.0990 5196 Npfs - ok
19:45:50.0004 5196 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
19:45:50.0005 5196 nsi - ok
19:45:50.0025 5196 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
19:45:50.0025 5196 nsiproxy - ok
19:45:50.0189 5196 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
19:45:50.0196 5196 Ntfs - ok
19:45:50.0263 5196 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
19:45:50.0263 5196 Null - ok
19:45:50.0326 5196 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
19:45:50.0327 5196 nvraid - ok
19:45:50.0371 5196 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
19:45:50.0372 5196 nvstor - ok
19:45:50.0414 5196 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
19:45:50.0416 5196 nv_agp - ok
19:45:50.0548 5196 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:45:50.0550 5196 odserv - ok
19:45:50.0608 5196 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
19:45:50.0608 5196 ohci1394 - ok
19:45:50.0695 5196 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:45:50.0696 5196 ose - ok
19:45:50.0830 5196 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:45:50.0880 5196 osppsvc - ok
19:45:50.0961 5196 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
19:45:50.0963 5196 p2pimsvc - ok
19:45:51.0015 5196 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
19:45:51.0018 5196 p2psvc - ok
19:45:51.0079 5196 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
19:45:51.0080 5196 Parport - ok
19:45:51.0131 5196 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys
19:45:51.0132 5196 partmgr - ok
19:45:51.0166 5196 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
19:45:51.0168 5196 PcaSvc - ok
19:45:51.0225 5196 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
19:45:51.0226 5196 pci - ok
19:45:51.0238 5196 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
19:45:51.0239 5196 pciide - ok
19:45:51.0275 5196 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
19:45:51.0276 5196 pcmcia - ok
19:45:51.0296 5196 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
19:45:51.0297 5196 pcw - ok
19:45:51.0340 5196 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
19:45:51.0343 5196 PEAUTH - ok
19:45:51.0416 5196 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
19:45:51.0418 5196 PerfHost - ok
19:45:51.0511 5196 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
19:45:51.0518 5196 pla - ok
19:45:51.0575 5196 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
19:45:51.0578 5196 PlugPlay - ok
19:45:51.0602 5196 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
19:45:51.0603 5196 PNRPAutoReg - ok
19:45:51.0641 5196 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
19:45:51.0643 5196 PNRPsvc - ok
19:45:51.0695 5196 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
19:45:51.0698 5196 PolicyAgent - ok
19:45:51.0740 5196 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
19:45:51.0742 5196 Power - ok
19:45:51.0797 5196 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
19:45:51.0803 5196 PptpMiniport - ok
19:45:51.0837 5196 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
19:45:51.0837 5196 Processor - ok
19:45:51.0901 5196 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll
19:45:51.0903 5196 ProfSvc - ok
19:45:51.0905 5196 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:45:51.0905 5196 ProtectedStorage - ok
19:45:51.0956 5196 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
19:45:51.0957 5196 Psched - ok
19:45:52.0000 5196 PxHlpa64 (4712cc14e720ecccc0aa16949d18aaf1) C:\Windows\system32\Drivers\PxHlpa64.sys
19:45:52.0001 5196 PxHlpa64 - ok
19:45:52.0140 5196 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
19:45:52.0151 5196 ql2300 - ok
19:45:52.0202 5196 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
19:45:52.0212 5196 ql40xx - ok
19:45:52.0286 5196 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
19:45:52.0288 5196 QWAVE - ok
19:45:52.0296 5196 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
19:45:52.0297 5196 QWAVEdrv - ok
19:45:52.0325 5196 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
19:45:52.0326 5196 RasAcd - ok
19:45:52.0349 5196 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
19:45:52.0350 5196 RasAgileVpn - ok
19:45:52.0373 5196 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
19:45:52.0374 5196 RasAuto - ok
19:45:52.0435 5196 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
19:45:52.0436 5196 Rasl2tp - ok
19:45:52.0510 5196 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
19:45:52.0512 5196 RasMan - ok
19:45:52.0544 5196 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
19:45:52.0544 5196 RasPppoe - ok
19:45:52.0619 5196 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
19:45:52.0620 5196 RasSstp - ok
19:45:52.0686 5196 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
19:45:52.0688 5196 rdbss - ok
19:45:52.0695 5196 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
19:45:52.0696 5196 rdpbus - ok
19:45:52.0718 5196 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
19:45:52.0718 5196 RDPCDD - ok
19:45:52.0771 5196 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
19:45:52.0772 5196 RDPENCDD - ok
19:45:52.0793 5196 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
19:45:52.0794 5196 RDPREFMP - ok
19:45:52.0849 5196 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys
19:45:52.0850 5196 RDPWD - ok
19:45:52.0923 5196 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
19:45:52.0924 5196 rdyboost - ok
19:45:52.0985 5196 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
19:45:52.0986 5196 RemoteAccess - ok
19:45:53.0032 5196 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
19:45:53.0034 5196 RemoteRegistry - ok
19:45:53.0127 5196 RoxMediaDB10 (05fc44d32a144925eae45570029fd6e1) c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
19:45:53.0132 5196 RoxMediaDB10 - ok
19:45:53.0169 5196 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
19:45:53.0170 5196 RpcEptMapper - ok
19:45:53.0201 5196 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
19:45:53.0202 5196 RpcLocator - ok
19:45:53.0295 5196 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
19:45:53.0298 5196 RpcSs - ok
19:45:53.0353 5196 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
19:45:53.0354 5196 rspndr - ok
19:45:53.0462 5196 RSUSBSTOR (5aab4808e8ccae8c2ecda5b791260616) C:\Windows\system32\Drivers\RtsUStor.sys
19:45:53.0463 5196 RSUSBSTOR - ok
19:45:53.0522 5196 RTL8167 (777fc2c418465404e3d8a290dc247d24) C:\Windows\system32\DRIVERS\Rt64win7.sys
19:45:53.0523 5196 RTL8167 - ok
19:45:53.0525 5196 RxFilter - ok
19:45:53.0528 5196 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:45:53.0529 5196 SamSs - ok
19:45:53.0582 5196 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
19:45:53.0583 5196 sbp2port - ok
19:45:53.0628 5196 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
19:45:53.0630 5196 SCardSvr - ok
19:45:53.0673 5196 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
19:45:53.0674 5196 scfilter - ok
19:45:53.0749 5196 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
19:45:53.0754 5196 Schedule - ok
19:45:53.0827 5196 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
19:45:53.0828 5196 SCPolicySvc - ok
19:45:53.0889 5196 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
19:45:53.0890 5196 SDRSVC - ok
19:45:53.0915 5196 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
19:45:53.0916 5196 secdrv - ok
19:45:53.0964 5196 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
19:45:53.0965 5196 seclogon - ok
19:45:54.0001 5196 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
19:45:54.0002 5196 SENS - ok
19:45:54.0006 5196 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
19:45:54.0007 5196 SensrSvc - ok
19:45:54.0023 5196 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
19:45:54.0023 5196 Serenum - ok
19:45:54.0069 5196 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
19:45:54.0070 5196 Serial - ok
19:45:54.0122 5196 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
19:45:54.0123 5196 sermouse - ok
19:45:54.0172 5196 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
19:45:54.0174 5196 SessionEnv - ok
19:45:54.0193 5196 SessionLauncher - ok
19:45:54.0240 5196 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
19:45:54.0241 5196 sffdisk - ok
19:45:54.0271 5196 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
19:45:54.0271 5196 sffp_mmc - ok
19:45:54.0276 5196 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
19:45:54.0277 5196 sffp_sd - ok
19:45:54.0332 5196 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
19:45:54.0333 5196 sfloppy - ok
19:45:54.0441 5196 Sftfs (c6cc9297bd53e5229653303e556aa539) C:\Windows\system32\DRIVERS\Sftfslh.sys
19:45:54.0445 5196 Sftfs - ok
19:45:54.0556 5196 sftlist (13693b6354dd6e72dc5131da7d764b90) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
19:45:54.0558 5196 sftlist - ok
19:45:54.0644 5196 Sftplay (390aa7bc52cee43f6790cdea1e776703) C:\Windows\system32\DRIVERS\Sftplaylh.sys
19:45:54.0645 5196 Sftplay - ok
19:45:54.0660 5196 Sftredir (617e29a0b0a2807466560d4c4e338d3e) C:\Windows\system32\DRIVERS\Sftredirlh.sys
19:45:54.0661 5196 Sftredir - ok
19:45:54.0779 5196 SftService (74ec60e20516aaa573be74f31175270f) C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
19:45:54.0786 5196 SftService - ok
19:45:54.0811 5196 Sftvol (8f571f016fa1976f445147e9e6c8ae9b) C:\Windows\system32\DRIVERS\Sftvollh.sys
19:45:54.0811 5196 Sftvol - ok
19:45:54.0856 5196 sftvsa (c3cddd18f43d44ab713cf8c4916f7696) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
19:45:54.0857 5196 sftvsa - ok
19:45:54.0922 5196 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
19:45:54.0924 5196 ShellHWDetection - ok
19:45:54.0946 5196 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
19:45:54.0953 5196 SiSRaid2 - ok
19:45:54.0987 5196 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
19:45:54.0988 5196 SiSRaid4 - ok
19:45:55.0005 5196 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
19:45:55.0006 5196 Smb - ok
19:45:55.0027 5196 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
19:45:55.0028 5196 SNMPTRAP - ok
19:45:55.0037 5196 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
19:45:55.0038 5196 spldr - ok
19:45:55.0092 5196 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
19:45:55.0095 5196 Spooler - ok
19:45:55.0167 5196 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
19:45:55.0195 5196 sppsvc - ok
19:45:55.0205 5196 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
19:45:55.0212 5196 sppuinotify - ok
19:45:55.0294 5196 sprtsvc_DellSupportCenter (d630b6f2e8379b6f10dc16e82a426552) C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
19:45:55.0295 5196 sprtsvc_DellSupportCenter - ok
19:45:55.0358 5196 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
19:45:55.0360 5196 srv - ok
19:45:55.0427 5196 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
19:45:55.0429 5196 srv2 - ok
19:45:55.0462 5196 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
19:45:55.0463 5196 srvnet - ok
19:45:55.0533 5196 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
19:45:55.0535 5196 SSDPSRV - ok
19:45:55.0568 5196 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
19:45:55.0569 5196 SstpSvc - ok
19:45:55.0612 5196 Steam Client Service - ok
19:45:55.0651 5196 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
19:45:55.0651 5196 stexstor - ok
19:45:55.0707 5196 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
19:45:55.0710 5196 stisvc - ok
19:45:55.0755 5196 stllssvr (ff5eb78af7dfb68c2fb363537aaf753e) c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
19:45:55.0756 5196 stllssvr - ok
19:45:55.0797 5196 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
19:45:55.0798 5196 swenum - ok
19:45:55.0846 5196 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
19:45:55.0862 5196 swprv - ok
19:45:55.0921 5196 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
19:45:55.0930 5196 SysMain - ok
19:45:55.0973 5196 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
19:45:55.0975 5196 TabletInputService - ok
19:45:56.0033 5196 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
19:45:56.0036 5196 TapiSrv - ok
19:45:56.0079 5196 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
19:45:56.0081 5196 TBS - ok
19:45:56.0179 5196 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys
19:45:56.0186 5196 Tcpip - ok
19:45:56.0206 5196 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys
19:45:56.0214 5196 TCPIP6 - ok
19:45:56.0249 5196 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
19:45:56.0249 5196 tcpipreg - ok
19:45:56.0270 5196 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
19:45:56.0270 5196 TDPIPE - ok
19:45:56.0311 5196 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
19:45:56.0311 5196 TDTCP - ok
19:45:56.0341 5196 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
19:45:56.0342 5196 tdx - ok
19:45:56.0377 5196 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
19:45:56.0378 5196 TermDD - ok
19:45:56.0402 5196 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
19:45:56.0406 5196 TermService - ok
19:45:56.0425 5196 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
19:45:56.0426 5196 Themes - ok
19:45:56.0450 5196 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
19:45:56.0451 5196 THREADORDER - ok
19:45:56.0470 5196 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
19:45:56.0471 5196 TrkWks - ok
19:45:56.0524 5196 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
19:45:56.0525 5196 TrustedInstaller - ok
19:45:56.0561 5196 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
19:45:56.0561 5196 tssecsrv - ok
19:45:56.0598 5196 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
19:45:56.0598 5196 TsUsbFlt - ok
19:45:56.0640 5196 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
19:45:56.0641 5196 tunnel - ok
19:45:56.0676 5196 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
19:45:56.0676 5196 uagp35 - ok
19:45:56.0734 5196 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
19:45:56.0735 5196 udfs - ok
19:45:56.0801 5196 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
19:45:56.0803 5196 UI0Detect - ok
19:45:56.0832 5196 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
19:45:56.0833 5196 uliagpkx - ok
19:45:56.0887 5196 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
19:45:56.0888 5196 umbus - ok
19:45:56.0905 5196 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
19:45:56.0906 5196 UmPass - ok
19:45:56.0954 5196 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
19:45:56.0956 5196 upnphost - ok
19:45:57.0027 5196 USBAAPL64 (fb251567f41bc61988b26731dec19e4b) C:\Windows\system32\Drivers\usbaapl64.sys
19:45:57.0027 5196 USBAAPL64 - ok
19:45:57.0072 5196 usbaudio (82e8f44688e6fac57b5b7c6fc7adbc2a) C:\Windows\system32\drivers\usbaudio.sys
19:45:57.0078 5196 usbaudio - ok
19:45:57.0105 5196 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
19:45:57.0105 5196 usbccgp - ok
19:45:57.0181 5196 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
19:45:57.0181 5196 usbcir - ok
19:45:57.0192 5196 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
19:45:57.0193 5196 usbehci - ok
19:45:57.0254 5196 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
19:45:57.0256 5196 usbhub - ok
19:45:57.0275 5196 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
19:45:57.0275 5196 usbohci - ok
19:45:57.0293 5196 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
19:45:57.0300 5196 usbprint - ok
19:45:57.0333 5196 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:45:57.0334 5196 USBSTOR - ok
19:45:57.0359 5196 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
19:45:57.0360 5196 usbuhci - ok
19:45:57.0388 5196 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
19:45:57.0389 5196 UxSms - ok
19:45:57.0427 5196 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
19:45:57.0428 5196 VaultSvc - ok
19:45:57.0494 5196 VClone (84bb306b7863883018d7f3eb0c453bd5) C:\Windows\system32\DRIVERS\VClone.sys
19:45:57.0495 5196 VClone - ok
19:45:57.0512 5196 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
19:45:57.0513 5196 vdrvroot - ok
19:45:57.0559 5196 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
19:45:57.0562 5196 vds - ok
19:45:57.0585 5196 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
19:45:57.0585 5196 vga - ok
19:45:57.0623 5196 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
19:45:57.0623 5196 VgaSave - ok
19:45:57.0675 5196 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
19:45:57.0680 5196 vhdmp - ok
19:45:57.0719 5196 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
19:45:57.0719 5196 viaide - ok
19:45:57.0740 5196 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
19:45:57.0740 5196 volmgr - ok
19:45:57.0810 5196 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
19:45:57.0812 5196 volmgrx - ok
19:45:57.0855 5196 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
19:45:57.0856 5196 volsnap - ok
19:45:57.0912 5196 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
19:45:57.0914 5196 vsmraid - ok
19:45:58.0001 5196 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
19:45:58.0009 5196 VSS - ok
19:45:58.0075 5196 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
19:45:58.0075 5196 vwifibus - ok
19:45:58.0213 5196 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
19:45:58.0214 5196 vwififlt - ok
19:45:58.0472 5196 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
19:45:58.0480 5196 vwifimp - ok
19:45:58.0574 5196 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
19:45:58.0576 5196 W32Time - ok
19:45:58.0598 5196 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
19:45:58.0599 5196 WacomPen - ok
19:45:58.0656 5196 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
19:45:58.0657 5196 WANARP - ok
19:45:58.0660 5196 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
19:45:58.0660 5196 Wanarpv6 - ok
19:45:58.0758 5196 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
19:45:58.0763 5196 WatAdminSvc - ok
19:45:58.0844 5196 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
19:45:58.0851 5196 wbengine - ok
19:45:58.0891 5196 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
19:45:58.0893 5196 WbioSrvc - ok
19:45:58.0937 5196 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
19:45:58.0940 5196 wcncsvc - ok
19:45:58.0961 5196 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
19:45:58.0963 5196 WcsPlugInService - ok
19:45:58.0982 5196 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
19:45:58.0982 5196 Wd - ok
19:45:59.0037 5196 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
19:45:59.0040 5196 Wdf01000 - ok
19:45:59.0062 5196 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
19:45:59.0064 5196 WdiServiceHost - ok
19:45:59.0065 5196 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
19:45:59.0067 5196 WdiSystemHost - ok
19:45:59.0106 5196 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
19:45:59.0109 5196 WebClient - ok
19:45:59.0150 5196 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
19:45:59.0153 5196 Wecsvc - ok
19:45:59.0191 5196 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
19:45:59.0193 5196 wercplsupport - ok
19:45:59.0257 5196 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
19:45:59.0259 5196 WerSvc - ok
19:45:59.0289 5196 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
19:45:59.0290 5196 WfpLwf - ok
19:45:59.0370 5196 WimFltr (b14ef15bd757fa488f9c970eee9c0d35) C:\Windows\system32\DRIVERS\wimfltr.sys
19:45:59.0372 5196 WimFltr - ok
19:45:59.0395 5196 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
19:45:59.0395 5196 WIMMount - ok
19:45:59.0398 5196 WinHttpAutoProxySvc - ok
19:45:59.0477 5196 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
19:45:59.0479 5196 Winmgmt - ok
19:45:59.0557 5196 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
19:45:59.0567 5196 WinRM - ok
19:45:59.0624 5196 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
19:45:59.0624 5196 WinUsb - ok
19:45:59.0679 5196 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
19:45:59.0684 5196 Wlansvc - ok
19:45:59.0723 5196 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
19:45:59.0724 5196 WmiAcpi - ok
19:45:59.0776 5196 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
19:45:59.0777 5196 wmiApSrv - ok
19:45:59.0798 5196 WMPNetworkSvc - ok
19:45:59.0839 5196 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
19:45:59.0840 5196 WPCSvc - ok
19:45:59.0892 5196 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
19:45:59.0893 5196 WPDBusEnum - ok
19:45:59.0914 5196 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
19:45:59.0914 5196 ws2ifsl - ok
19:45:59.0916 5196 WSearch - ok
19:45:59.0990 5196 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
19:45:59.0991 5196 WudfPf - ok
19:46:00.0103 5196 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
19:46:00.0104 5196 WUDFRd - ok
19:46:00.0167 5196 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
19:46:00.0170 5196 wudfsvc - ok
19:46:00.0213 5196 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
19:46:00.0215 5196 WwanSvc - ok
19:46:00.0250 5196 MBR (0x1B8) (cdb4de4bbd714f152979da2dcbef57eb) \Device\Harddisk0\DR0
19:46:00.0296 5196 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
19:46:00.0297 5196 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
19:46:00.0335 5196 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
19:46:00.0335 5196 \Device\Harddisk0\DR0 - detected TDSS File System (1)
19:46:00.0337 5196 Boot (0x1200) (592f3854991939bc6e1130c6fcee0040) \Device\Harddisk0\DR0\Partition0
19:46:00.0338 5196 \Device\Harddisk0\DR0\Partition0 - ok
19:46:00.0363 5196 Boot (0x1200) (935d58f82543ac645a0aa7136bdc312d) \Device\Harddisk0\DR0\Partition1
19:46:00.0372 5196 \Device\Harddisk0\DR0\Partition1 - ok
19:46:00.0372 5196 ============================================================
19:46:00.0372 5196 Scan finished
19:46:00.0372 5196 ============================================================
19:46:00.0379 1624 Detected object count: 2
19:46:00.0379 1624 Actual detected object count: 2

#4 Minlas

Minlas
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 09 August 2012 - 07:30 PM

aswMBR log. Doing the last one now.

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-09 19:49:39
-----------------------------
19:49:39.611 OS Version: Windows x64 6.1.7601 Service Pack 1
19:49:39.611 Number of processors: 8 586 0x1A05
19:49:39.612 ComputerName: ANDYV UserName:
19:49:41.546 Initialize success
19:52:09.475 AVAST engine defs: 12080901
19:52:36.831 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2
19:52:36.835 Disk 0 Vendor: Intel___ 1.0. Size: 953875MB BusType: 8
19:52:36.838 Device \Driver\iaStor -> MajorFunction fffffa800b25a5e8
19:52:36.841 Disk 0 MBR read successfully
19:52:36.844 Disk 0 MBR scan
19:52:36.849 Disk 0 Windows VISTA default MBR code
19:52:36.863 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
19:52:36.867 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 11142 MB offset 81920
19:52:36.870 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 942692 MB offset 22900736
19:52:36.883 Disk 0 scanning C:\Windows\system32\drivers
19:52:48.032 Service scanning
19:53:05.820 Modules scanning
19:53:05.832 Disk 0 trace - called modules:
19:53:05.847 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa800d76d9d0]<<83747569.sys >>UNKNOWN [0xfffffa800b25a5e8]<<
19:53:05.853 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008b80060]
19:53:05.860 3 CLASSPNP.SYS[fffff88001db543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0xfffffa8008757050]
19:53:05.864 \Driver\iaStor[0xfffffa80089eecb0] -> IRP_MJ_CREATE -> 0xfffffa800b25a5e8
19:53:07.485 AVAST engine scan C:\Windows
19:53:10.021 AVAST engine scan C:\Windows\system32
19:55:19.159 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
19:55:21.957 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
19:56:44.351 AVAST engine scan C:\Windows\system32\drivers
19:56:58.934 AVAST engine scan C:\Users\Joseph
19:58:24.995 Disk 0 MBR has been saved successfully to "C:\Users\Joseph\Documents\AdmissionsPkg\MBR.dat"
19:58:25.000 The log file has been saved successfully to "C:\Users\Joseph\Documents\AdmissionsPkg\aswMBR.txt"
20:10:50.666 AVAST engine scan C:\ProgramData
20:24:34.634 Scan finished successfully
20:30:27.377 Disk 0 MBR has been saved successfully to "C:\Users\Joseph\Documents\AdmissionsPkg\MBR.dat"
20:30:27.382 The log file has been saved successfully to "C:\Users\Joseph\Documents\AdmissionsPkg\aswMBR.txt"

#5 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:23 AM

Posted 09 August 2012 - 08:31 PM

We need advanced tools to remove this one

Read the guide here on preparing logs

http://www.bleepingcomputer.com/forums/topic34773.html

and create a topic here

http://www.bleepingcomputer.com/forums/forum22.html

Good luck

#6 Minlas

Minlas
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:05:23 AM

Posted 09 August 2012 - 09:21 PM

Here is the ESET Scanner

C:\$Recycle.Bin\S-1-5-21-3135079507-3317993538-4214395858-1001\$R9K8G8Z.exe a variant of Win32/SoftonicDownloader.A application cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0000.dta Win32/Olmarik.AYI trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0001.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0002.dta Win32/Olmarik.AYH trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AL trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0004.dta a variant of Win32/Rootkit.Kryptik.NH trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0005.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0009.dta Win32/Olmarik.AFK trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\09.08.2012_19.45.19\mbr0000\tdlfs0000\tsk0010.dta Win64/Olmarik.AK trojan cleaned by deleting - quarantined
C:\Users\Joseph\AppData\Local\Google\Chrome\User Data\Default\Default\aagedidbdhdedcdddhddgcdddedagcde\background.html Win32/BHO.OEI trojan cleaned by deleting - quarantined
C:\Users\Joseph\AppData\Local\Temp\ICReinstall\cnet2_GOMPLAYERENSETUP_EXE.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\Users\Joseph\Downloads\cnet2_GOMPLAYERENSETUP_EXE.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\Windows\Installer\{7557ca54-3210-d125-9f1c-97d293b7d07d}\n Win64/Sirefef.W trojan cleaned by deleting - quarantined
C:\Windows\Installer\{7557ca54-3210-d125-9f1c-97d293b7d07d}\U\00000008.@ Win64/Agent.BA trojan cleaned by deleting - quarantined
C:\Windows\Installer\{7557ca54-3210-d125-9f1c-97d293b7d07d}\U\000000cb.@ Win64/Conedex.B trojan cleaned by deleting - quarantined
C:\Windows\Installer\{7557ca54-3210-d125-9f1c-97d293b7d07d}\U\80000000.@ Win64/Sirefef.AP trojan cleaned by deleting - quarantined
C:\Windows\Installer\{7557ca54-3210-d125-9f1c-97d293b7d07d}\U\80000032.@ a variant of Win32/Sirefef.FD trojan cleaned by deleting - quarantined
C:\Windows\System32\config\systemprofile\AppData\Local\{7557ca54-3210-d125-9f1c-97d293b7d07d}\n Win64/Sirefef.W trojan cleaned by deleting - quarantined
Operating memory multiple threats

Edit: Thanks I am working on those two guides now.

Edited by Minlas, 09 August 2012 - 09:23 PM.


#7 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:23 AM

Posted 10 August 2012 - 03:26 AM

You're welcome :)

#8 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,049 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:05:23 AM

Posted 10 August 2012 - 06:32 AM

Hello,

Now that you have posted a log here: http://www.bleepingcomputer.com/forums/topic464595.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

Please be patient. It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

To avoid confusion, I am closing this topic. Good luck with your log.

Orange Blossom :cherry:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Internet Security, NoScript Firefox ext.


animinionsmalltext.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users