Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Redirector Virus Found


  • Please log in to reply
5 replies to this topic

#1 Nick7560

Nick7560

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:46 PM

Posted 14 September 2012 - 07:44 PM

Hello,
My wife was experiencing a redirect virus or rootkit when logged in to her desktop acct. Clicking on any Google search results only brought you to some random page. (Doesn't help that she insists on using IE as her browser despite my warnings). Anyway I did an ESET online scan in Safe Mode and it found and cleaned 2 items :
Win32/PowerReg application\Users\Marilee
JS/Redirector.NCA trojan
The redirecting behavior has now stopped, and everything seems normal. However, every time she logs in to her desktop account there's immediately a pop-up text which reads:
"There was a problem starting. C:\Users\Marilee\AppData\Local\Apple\Adobe\rtfzrvfnz.dll The specified module could not be found"
As you know, Apple and Adobe have no relationship to each other, so its making me nervous to see this because I use editing programs from both companies on this laptop.
Are we still infected here or did the virus/rootkit damage or corrupt something even though it was cleaned out?? I did experience a few random crashes while logged into my acct. Usually this happens when the PC wakes after sleeping for awhile and then we try to go back to whatever we were doing, and a minute or so later it crashes. Or is this a complete separate issue??
I'm using Win 7 64bit w/12mb ram. Also have MBAM installed and it found nothing. Please help.

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:46 PM

Posted 14 September 2012 - 07:53 PM

Hello, Its not unusual to receive such an error after using specialized fix tools.

A "Cannot find...", "Could not run...", "Error loading... or "specific module could not be found" message is usually related to malware that was set to run at startup but has been deleted. Windows is trying to load this file but cannot locate it since the file was mostly likely removed during an anti-virus or anti-malware scan. However, an associated orphaned registry entry remains and is telling Windows to load the file when you boot up. Since the file no longer exists, Windows will display an error message. You need to remove this registry entry so Windows stops searching for the file when it loads.

To resolve this, download Autoruns search for the related entry and then delete it.

Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click here if you're not sure how to do this.)
Open the folder and double-click on autoruns.exe to launch it.
Please be patient as it scans and populates the entries.
When done scanning, it will say Ready at the bottom.
Scroll through the list and look for a startup entry related to the file(s) in the error message.
Right-click on the entry and choose delete. -->> rtfzrvfnz.dll
Reboot your computer and see if the startup error returns.



As this was from a rogue security program please also run these.



Run RKill....


Download and Run RKill
  • Please download RKill by Grinler from one of the 4 links below and save it to your desktop.

    Link 1
    Link 2
    Link 3
    Link 4

  • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
  • Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • If nothing happens or if the tool does not run, please let me know in your next reply

Do not reboot your computer after running rkill as the malware programs will start again. Or if rebooting is required run it again.


If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.



Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click on Change Parameters
  • Put a check in the box of Detect TDLFS file system
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log has a name like: TDSSKiller.Version_Date_Time_log.txt.


Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.

Please ask any needed questions,post logs and Let us know how the PC is running now.

Edited by boopme, 14 September 2012 - 07:58 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Nick7560

Nick7560
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:46 PM

Posted 16 September 2012 - 11:44 PM

Hello Boopme,
Thanks so much for your help. Ran the Autoruns and RKill programs and followed your instructions with no issues. Ran TDSSKiller and no reboot was required. Here is the log info:

19:46:08.0869 3244 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
19:46:09.0399 3244 ============================================================
19:46:09.0399 3244 Current date / time: 2012/09/16 19:46:09.0399
19:46:09.0399 3244 SystemInfo:
19:46:09.0399 3244
19:46:09.0399 3244 OS Version: 6.1.7601 ServicePack: 1.0
19:46:09.0399 3244 Product type: Workstation
19:46:09.0399 3244 ComputerName: NICK-LAPTOP
19:46:09.0399 3244 UserName: Nick
19:46:09.0399 3244 Windows directory: C:\Windows
19:46:09.0399 3244 System windows directory: C:\Windows
19:46:09.0399 3244 Running under WOW64
19:46:09.0399 3244 Processor architecture: Intel x64
19:46:09.0399 3244 Number of processors: 8
19:46:09.0399 3244 Page size: 0x1000
19:46:09.0399 3244 Boot type: Normal boot
19:46:09.0399 3244 ============================================================
19:46:10.0819 3244 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:46:11.0053 3244 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:46:11.0131 3244 ============================================================
19:46:11.0131 3244 \Device\Harddisk0\DR0:
19:46:11.0131 3244 MBR partitions:
19:46:11.0131 3244 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
19:46:11.0131 3244 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x14084352
19:46:11.0131 3244 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x140E8B91, BlocksNum 0x2629C0B0
19:46:11.0131 3244 \Device\Harddisk1\DR1:
19:46:11.0147 3244 MBR partitions:
19:46:11.0147 3244 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x247DFCE
19:46:11.0147 3244 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x247E80D, BlocksNum 0xEF3FCC1
19:46:11.0162 3244 \Device\Harddisk1\DR1\Partition3: MBR, Type 0x7, StartLBA 0x113BE50D, BlocksNum 0x28FC6734
19:46:11.0178 3244 ============================================================
19:46:11.0178 3244 C: <-> \Device\Harddisk0\DR0\Partition2
19:46:11.0193 3244 D: <-> \Device\Harddisk1\DR1\Partition1
19:46:11.0240 3244 F: <-> \Device\Harddisk1\DR1\Partition2
19:46:11.0256 3244 G: <-> \Device\Harddisk1\DR1\Partition3
19:46:12.0441 3244 K: <-> \Device\Harddisk0\DR0\Partition3
19:46:12.0441 3244 ============================================================
19:46:12.0441 3244 Initialize success
19:46:12.0441 3244 ============================================================
19:49:02.0116 4156 ============================================================
19:49:02.0116 4156 Scan started
19:49:02.0116 4156 Mode: Manual; TDLFS;
19:49:02.0116 4156 ============================================================
19:49:03.0239 4156 ================ Scan system memory ========================
19:49:03.0239 4156 System memory - ok
19:49:03.0239 4156 ================ Scan services =============================
19:49:03.0785 4156 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
19:49:03.0785 4156 1394ohci - ok
19:49:03.0848 4156 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
19:49:03.0848 4156 ACPI - ok
19:49:03.0879 4156 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
19:49:03.0895 4156 AcpiPmi - ok
19:49:04.0004 4156 [ 047BD1EB681453A7FE492A71802AC9F3 ] AdobeActiveFileMonitor10.0 C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe
19:49:04.0004 4156 AdobeActiveFileMonitor10.0 - ok
19:49:04.0129 4156 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:49:04.0129 4156 AdobeARMservice - ok
19:49:04.0409 4156 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:49:04.0409 4156 AdobeFlashPlayerUpdateSvc - ok
19:49:04.0503 4156 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
19:49:04.0503 4156 adp94xx - ok
19:49:04.0659 4156 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
19:49:04.0675 4156 adpahci - ok
19:49:04.0799 4156 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
19:49:04.0815 4156 adpu320 - ok
19:49:04.0862 4156 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
19:49:04.0877 4156 AeLookupSvc - ok
19:49:05.0002 4156 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
19:49:05.0002 4156 AFD - ok
19:49:05.0065 4156 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
19:49:05.0065 4156 agp440 - ok
19:49:06.0125 4156 [ 0923671CF87CD511E46D4668B53F5E76 ] Akamai c:\program files (x86)\common files\akamai/netsession_win_5891ae0.dll
19:49:06.0125 4156 Suspicious file (Hidden): c:\program files (x86)\common files\akamai/netsession_win_5891ae0.dll. md5: 0923671CF87CD511E46D4668B53F5E76
19:49:06.0125 4156 Akamai ( HiddenFile.Multi.Generic ) - warning
19:49:06.0125 4156 Akamai - detected HiddenFile.Multi.Generic (1)
19:49:06.0157 4156 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
19:49:06.0157 4156 ALG - ok
19:49:06.0297 4156 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
19:49:06.0297 4156 aliide - ok
19:49:06.0578 4156 ALSysIO - ok
19:49:06.0625 4156 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
19:49:06.0625 4156 amdide - ok
19:49:06.0640 4156 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
19:49:06.0640 4156 AmdK8 - ok
19:49:06.0671 4156 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
19:49:06.0671 4156 AmdPPM - ok
19:49:06.0734 4156 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
19:49:06.0734 4156 amdsata - ok
19:49:06.0859 4156 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
19:49:06.0859 4156 amdsbs - ok
19:49:06.0874 4156 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
19:49:06.0874 4156 amdxata - ok
19:49:06.0983 4156 [ 30A14404F582BB650BEE08DD01F88766 ] apmwin C:\Windows\system32\DRIVERS\apmwin.sys
19:49:06.0983 4156 apmwin - ok
19:49:07.0139 4156 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
19:49:07.0139 4156 AppID - ok
19:49:07.0233 4156 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
19:49:07.0233 4156 AppIDSvc - ok
19:49:07.0311 4156 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
19:49:07.0327 4156 Appinfo - ok
19:49:07.0405 4156 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
19:49:07.0405 4156 Apple Mobile Device - ok
19:49:07.0436 4156 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
19:49:07.0436 4156 arc - ok
19:49:07.0436 4156 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
19:49:07.0436 4156 arcsas - ok
19:49:07.0607 4156 [ 9ABE091AC231833762016658A494D505 ] ArgusMonitor C:\Windows\syswow64\drivers\ArgusMonitor.sys
19:49:07.0607 4156 ArgusMonitor - ok
19:49:07.0654 4156 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
19:49:07.0654 4156 AsyncMac - ok
19:49:07.0717 4156 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
19:49:07.0717 4156 atapi - ok
19:49:07.0841 4156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:49:07.0857 4156 AudioEndpointBuilder - ok
19:49:07.0873 4156 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
19:49:07.0873 4156 AudioSrv - ok
19:49:07.0966 4156 [ F57DE310BF3BD9DF0F7D301C1D7F5432 ] avc3 C:\Windows\system32\DRIVERS\avc3.sys
19:49:07.0982 4156 avc3 - ok
19:49:08.0060 4156 [ 4C6BCC638798ABE1F70AFCA70D889C3F ] avchv C:\Windows\system32\DRIVERS\avchv.sys
19:49:08.0060 4156 avchv - ok
19:49:08.0185 4156 [ 6DC4CCA415BBF2FC629BEB532AA0E6CD ] avckf C:\Windows\system32\DRIVERS\avckf.sys
19:49:08.0185 4156 avckf - ok
19:49:08.0325 4156 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
19:49:08.0341 4156 AxInstSV - ok
19:49:08.0434 4156 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
19:49:08.0434 4156 b06bdrv - ok
19:49:08.0559 4156 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
19:49:08.0575 4156 b57nd60a - ok
19:49:08.0621 4156 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
19:49:08.0621 4156 BDESVC - ok
19:49:09.0433 4156 [ EA195950FA5DD4A8F7BC00822213A363 ] bdfsfltr C:\Windows\system32\DRIVERS\bdfsfltr.sys
19:49:09.0433 4156 bdfsfltr - ok
19:49:09.0511 4156 [ 4CE4B0098FC315C237FA8867F07886C4 ] bdfwfpf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys
19:49:09.0511 4156 bdfwfpf - ok
19:49:09.0698 4156 [ 5F8A4C7F567D9DBDEE2BB9CF6B53CE14 ] bdisk C:\Windows\system32\drivers\bdisk.sys
19:49:09.0698 4156 bdisk - ok
19:49:09.0932 4156 [ 31571D77C6186AD228F52EE4EBDF8EE9 ] bdsandbox C:\Windows\system32\drivers\bdsandbox.sys
19:49:09.0947 4156 bdsandbox - ok
19:49:09.0979 4156 [ B89DEFF4817B4CC6FC2BCD8F83B4E75D ] BDVEDISK C:\Windows\system32\DRIVERS\bdvedisk.sys
19:49:09.0979 4156 BDVEDISK - ok
19:49:10.0057 4156 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
19:49:10.0057 4156 Beep - ok
19:49:10.0103 4156 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
19:49:10.0119 4156 BFE - ok
19:49:10.0150 4156 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
19:49:10.0166 4156 BITS - ok
19:49:10.0275 4156 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
19:49:10.0275 4156 blbdrive - ok
19:49:10.0415 4156 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
19:49:10.0415 4156 Bonjour Service - ok
19:49:10.0462 4156 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
19:49:10.0478 4156 bowser - ok
19:49:10.0571 4156 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
19:49:10.0571 4156 BrFiltLo - ok
19:49:10.0571 4156 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
19:49:10.0571 4156 BrFiltUp - ok
19:49:10.0571 4156 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
19:49:10.0571 4156 Browser - ok
19:49:10.0634 4156 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
19:49:10.0634 4156 Brserid - ok
19:49:10.0649 4156 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
19:49:10.0649 4156 BrSerWdm - ok
19:49:10.0649 4156 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
19:49:10.0649 4156 BrUsbMdm - ok
19:49:10.0665 4156 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
19:49:10.0665 4156 BrUsbSer - ok
19:49:10.0696 4156 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
19:49:10.0696 4156 BTHMODEM - ok
19:49:10.0805 4156 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
19:49:10.0805 4156 bthserv - ok
19:49:11.0133 4156 [ D8466DF7629A7ACD2BED0CDE206E5DF9 ] CbFs C:\Windows\system32\drivers\cbfs.sys
19:49:11.0133 4156 CbFs - ok
19:49:11.0164 4156 [ 3D17F92309F13871C459B9D86DF1FC56 ] CBUfs C:\Windows\system32\drivers\CBUFS.sys
19:49:11.0164 4156 CBUfs - ok
19:49:11.0242 4156 [ A8EC5F92388F2596499C1F22AD6ECAFD ] cbvd C:\Windows\system32\DRIVERS\cbvd.sys
19:49:11.0242 4156 cbvd - ok
19:49:11.0273 4156 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
19:49:11.0273 4156 cdfs - ok
19:49:11.0336 4156 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
19:49:11.0336 4156 cdrom - ok
19:49:11.0398 4156 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
19:49:11.0398 4156 CertPropSvc - ok
19:49:11.0414 4156 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
19:49:11.0414 4156 circlass - ok
19:49:11.0429 4156 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
19:49:11.0429 4156 CLFS - ok
19:49:11.0461 4156 [ 524DC3807CB1746225F9D26ADD19C319 ] CLKMSVC10_38F51D56 c:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe
19:49:11.0695 4156 CLKMSVC10_38F51D56 - ok
19:49:11.0741 4156 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:49:11.0757 4156 clr_optimization_v2.0.50727_32 - ok
19:49:11.0757 4156 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:49:11.0757 4156 clr_optimization_v2.0.50727_64 - ok
19:49:11.0944 4156 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:49:11.0944 4156 clr_optimization_v4.0.30319_32 - ok
19:49:12.0022 4156 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:49:12.0022 4156 clr_optimization_v4.0.30319_64 - ok
19:49:12.0053 4156 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
19:49:12.0069 4156 CmBatt - ok
19:49:12.0085 4156 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
19:49:12.0085 4156 cmdide - ok
19:49:12.0178 4156 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
19:49:12.0194 4156 CNG - ok
19:49:12.0319 4156 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
19:49:12.0319 4156 Compbatt - ok
19:49:12.0397 4156 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
19:49:12.0397 4156 CompositeBus - ok
19:49:12.0397 4156 COMSysApp - ok
19:49:12.0802 4156 [ 49DB436E840491EAA2DFCD0780A2A2DF ] COSService.exe C:\Program Files\COMODO\COMMON\COSService.exe
19:49:12.0818 4156 COSService.exe - ok
19:49:12.0849 4156 cpuz130 - ok
19:49:12.0865 4156 [ E2CEC73B4D221B9FFE906748D1F5FC54 ] CrashPlanService C:\Program Files\CrashPlan\CrashPlanService.exe
19:49:12.0880 4156 CrashPlanService - ok
19:49:12.0911 4156 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
19:49:12.0911 4156 crcdisk - ok
19:49:12.0927 4156 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
19:49:12.0927 4156 CryptSvc - ok
19:49:13.0099 4156 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
19:49:13.0099 4156 cvhsvc - ok
19:49:13.0177 4156 [ 7AF9DAC504FBD047CBC3E64AE52C92BF ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys
19:49:13.0177 4156 dc3d - ok
19:49:13.0223 4156 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
19:49:13.0645 4156 DcomLaunch - ok
19:49:13.0785 4156 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
19:49:13.0801 4156 defragsvc - ok
19:49:13.0832 4156 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
19:49:13.0832 4156 DfsC - ok
19:49:13.0894 4156 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
19:49:13.0894 4156 Dhcp - ok
19:49:13.0972 4156 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
19:49:13.0972 4156 discache - ok
19:49:14.0081 4156 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
19:49:14.0081 4156 Disk - ok
19:49:14.0113 4156 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
19:49:14.0113 4156 Dnscache - ok
19:49:14.0175 4156 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
19:49:14.0175 4156 dot3svc - ok
19:49:14.0191 4156 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
19:49:14.0191 4156 DPS - ok
19:49:14.0206 4156 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
19:49:14.0222 4156 drmkaud - ok
19:49:14.0565 4156 [ 1ED08A6264C5C92099D6D1DAE5E8F530 ] DrvAgent64 C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS
19:49:14.0565 4156 DrvAgent64 - ok
19:49:14.0846 4156 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
19:49:14.0846 4156 DXGKrnl - ok
19:49:14.0877 4156 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
19:49:14.0877 4156 EapHost - ok
19:49:15.0049 4156 [ 64585B1D85FF7566B99CED303A02F357 ] EaseUS Agent C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
19:49:15.0049 4156 EaseUS Agent - ok
19:49:15.0470 4156 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
19:49:15.0548 4156 ebdrv - ok
19:49:15.0563 4156 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
19:49:15.0563 4156 EFS - ok
19:49:15.0626 4156 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
19:49:15.0641 4156 ehRecvr - ok
19:49:16.0375 4156 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
19:49:16.0375 4156 ehSched - ok
19:49:16.0453 4156 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
19:49:16.0453 4156 elxstor - ok
19:49:16.0562 4156 [ 9EAFB3B3B60B8AD958985152A9309ACA ] epmntdrv C:\Windows\system32\epmntdrv.sys
19:49:16.0562 4156 epmntdrv - ok
19:49:16.0562 4156 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
19:49:16.0562 4156 ErrDev - ok
19:49:16.0577 4156 [ BF217BE3DB6907579C13438C6EFE002D ] EUBAKUP C:\Windows\system32\drivers\eubakup.sys
19:49:16.0577 4156 EUBAKUP - ok
19:49:16.0593 4156 EUBAKUP0 - ok
19:49:16.0702 4156 [ 92E3BD1F7D6D29A10929C1F9F7660FC3 ] EUBKMON C:\Windows\system32\drivers\EUBKMON.sys
19:49:16.0702 4156 EUBKMON - ok
19:49:16.0702 4156 EUBKMON0 - ok
19:49:16.0702 4156 [ D17446353E4FEE5B7D710610E8B18AC4 ] EUDSKACS C:\Windows\system32\drivers\eudskacs.sys
19:49:16.0702 4156 EUDSKACS - ok
19:49:16.0780 4156 [ 8AD925DA2E4BCD1A6E657A7248CCDED2 ] EUFDDISK C:\Windows\system32\drivers\EuFdDisk.sys
19:49:16.0780 4156 EUFDDISK - ok
19:49:16.0811 4156 EUFDDISK0 - ok
19:49:16.0889 4156 [ FB949ED2C93C878A189039F3D7730942 ] EuGdiDrv C:\Windows\system32\EuGdiDrv.sys
19:49:16.0889 4156 EuGdiDrv - ok
19:49:16.0905 4156 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
19:49:16.0921 4156 EventSystem - ok
19:49:17.0030 4156 [ 7EE9F35BC1DD0CE1A4976032F9AC5162 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
19:49:17.0061 4156 EvtEng - ok
19:49:17.0139 4156 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
19:49:17.0139 4156 exfat - ok
19:49:17.0155 4156 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
19:49:17.0155 4156 fastfat - ok
19:49:17.0217 4156 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
19:49:17.0217 4156 Fax - ok
19:49:17.0248 4156 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
19:49:17.0248 4156 fdc - ok
19:49:17.0248 4156 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
19:49:17.0248 4156 fdPHost - ok
19:49:17.0264 4156 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
19:49:17.0264 4156 FDResPub - ok
19:49:17.0295 4156 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
19:49:17.0295 4156 FileInfo - ok
19:49:17.0295 4156 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
19:49:17.0295 4156 Filetrace - ok
19:49:17.0498 4156 [ 8669BE94F63944E4F899C3950B520241 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
19:49:17.0513 4156 FLEXnet Licensing Service - ok
19:49:17.0529 4156 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
19:49:17.0529 4156 flpydisk - ok
19:49:17.0545 4156 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
19:49:17.0545 4156 FltMgr - ok
19:49:17.0623 4156 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
19:49:17.0638 4156 FontCache - ok
19:49:17.0654 4156 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:49:17.0654 4156 FontCache3.0.0.0 - ok
19:49:17.0685 4156 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
19:49:17.0685 4156 FsDepends - ok
19:49:17.0701 4156 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
19:49:17.0716 4156 Fs_Rec - ok
19:49:17.0747 4156 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
19:49:17.0747 4156 fvevol - ok
19:49:17.0794 4156 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
19:49:17.0810 4156 gagp30kx - ok
19:49:17.0935 4156 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
19:49:17.0935 4156 GEARAspiWDM - ok
19:49:18.0059 4156 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
19:49:18.0122 4156 gpsvc - ok
19:49:18.0122 4156 [ 56BB51F0F9BDD47F3B2B29B4ADBC159D ] gpt_loader C:\Windows\system32\DRIVERS\gpt_loader.sys
19:49:18.0122 4156 gpt_loader - ok
19:49:18.0169 4156 [ A6A4223573CFCF87843CFCB3A9C237C7 ] Guard Agent C:\Program Files (x86)\EaseUS\Todo Backup\bin\GuardAgent.exe
19:49:18.0169 4156 Guard Agent - ok
19:49:18.0325 4156 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:49:18.0325 4156 gupdate - ok
19:49:18.0325 4156 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
19:49:18.0325 4156 gupdatem - ok
19:49:18.0340 4156 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
19:49:18.0340 4156 gusvc - ok
19:49:18.0340 4156 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
19:49:18.0356 4156 hcw85cir - ok
19:49:18.0434 4156 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:49:18.0449 4156 HdAudAddService - ok
19:49:18.0465 4156 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
19:49:18.0465 4156 HDAudBus - ok
19:49:18.0559 4156 [ 5EBA8CE3EF8C06F39351B70532F5F19B ] Hfsplus C:\Windows\system32\DRIVERS\hfsplus.sys
19:49:18.0559 4156 Hfsplus - ok
19:49:18.0574 4156 [ 7B2A631E410BAEA98ED802250C88C9AB ] HfsplusRec C:\Windows\system32\DRIVERS\hfsplusrec.sys
19:49:18.0574 4156 HfsplusRec - ok
19:49:18.0574 4156 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
19:49:18.0574 4156 HidBatt - ok
19:49:18.0574 4156 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
19:49:18.0574 4156 HidBth - ok
19:49:18.0637 4156 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
19:49:18.0637 4156 HidIr - ok
19:49:18.0637 4156 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
19:49:18.0652 4156 hidserv - ok
19:49:18.0761 4156 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
19:49:18.0761 4156 HidUsb - ok
19:49:18.0777 4156 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
19:49:18.0777 4156 hkmsvc - ok
19:49:18.0933 4156 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:49:18.0949 4156 HomeGroupListener - ok
19:49:18.0949 4156 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:49:18.0949 4156 HomeGroupProvider - ok
19:49:18.0980 4156 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
19:49:18.0980 4156 HpSAMD - ok
19:49:19.0011 4156 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
19:49:19.0011 4156 HTTP - ok
19:49:19.0027 4156 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
19:49:19.0027 4156 hwpolicy - ok
19:49:19.0073 4156 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
19:49:19.0073 4156 i8042prt - ok
19:49:19.0183 4156 [ 26CF4275034214ECEDD8EC17B0A18A99 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
19:49:19.0198 4156 iaStor - ok
19:49:19.0307 4156 [ E79A8E33BD136D14BAE1FA20EB2EF124 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
19:49:19.0307 4156 IAStorDataMgrSvc - ok
19:49:19.0354 4156 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
19:49:19.0385 4156 iaStorV - ok
19:49:19.0526 4156 [ C1010ADD3DDAE1196ED21057AF7B2AAE ] ICCWDT C:\Windows\system32\DRIVERS\ICCWDT.sys
19:49:19.0526 4156 ICCWDT - ok
19:49:19.0588 4156 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:49:19.0604 4156 idsvc - ok
19:49:19.0619 4156 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
19:49:19.0619 4156 iirsp - ok
19:49:19.0651 4156 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
19:49:19.0666 4156 IKEEXT - ok
19:49:20.0087 4156 [ 13089F31AA37CDE1CE3784EE01A48484 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
19:49:20.0103 4156 IntcAzAudAddService - ok
19:49:20.0134 4156 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
19:49:20.0150 4156 intelide - ok
19:49:20.0212 4156 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
19:49:20.0212 4156 intelppm - ok
19:49:20.0243 4156 [ 9160D7B5CFA88697179C039BC852A945 ] IOCBIOS C:\ProgramData\Intel\Extreme Tuning Utility\IOCbios\64bit\IOCBIOS.sys
19:49:20.0243 4156 IOCBIOS - ok
19:49:20.0275 4156 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
19:49:20.0290 4156 IPBusEnum - ok
19:49:20.0321 4156 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:49:20.0321 4156 IpFilterDriver - ok
19:49:20.0431 4156 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
19:49:20.0431 4156 iphlpsvc - ok
19:49:20.0431 4156 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
19:49:20.0431 4156 IPMIDRV - ok
19:49:20.0462 4156 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
19:49:20.0462 4156 IPNAT - ok
19:49:20.0649 4156 [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
19:49:20.0680 4156 iPod Service - ok
19:49:20.0711 4156 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
19:49:20.0711 4156 IRENUM - ok
19:49:20.0852 4156 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
19:49:20.0852 4156 isapnp - ok
19:49:20.0852 4156 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
19:49:20.0867 4156 iScsiPrt - ok
19:49:20.0899 4156 [ 8D990A44B4F2B68E2C56A3724EC3EB84 ] itecir C:\Windows\system32\DRIVERS\itecir.sys
19:49:20.0899 4156 itecir - ok
19:49:20.0961 4156 [ E5F9A5AC854529EFBE37E475149615C1 ] JMCR C:\Windows\system32\DRIVERS\jmcr.sys
19:49:20.0961 4156 JMCR - ok
19:49:20.0961 4156 [ A4F45625CCD360DE35DA5051FDA0B47F ] JME C:\Windows\system32\DRIVERS\JME.sys
19:49:20.0977 4156 JME - ok
19:49:20.0992 4156 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
19:49:20.0992 4156 kbdclass - ok
19:49:20.0992 4156 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
19:49:20.0992 4156 kbdhid - ok
19:49:21.0008 4156 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
19:49:21.0008 4156 KeyIso - ok
19:49:21.0008 4156 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
19:49:21.0008 4156 KSecDD - ok
19:49:21.0023 4156 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
19:49:21.0023 4156 KSecPkg - ok
19:49:21.0023 4156 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
19:49:21.0039 4156 ksthunk - ok
19:49:21.0070 4156 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
19:49:21.0086 4156 KtmRm - ok
19:49:21.0179 4156 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
19:49:21.0179 4156 LanmanServer - ok
19:49:21.0195 4156 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:49:21.0195 4156 LanmanWorkstation - ok
19:49:21.0445 4156 [ 7772DFAB22611050B79504E671B06E6E ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
19:49:21.0460 4156 LBTServ - ok
19:49:21.0491 4156 [ ED7EC050CD6C20E1A93A4DAFB7EFD14D ] LEqdUsb C:\Windows\system32\DRIVERS\LEqdUsb.Sys
19:49:21.0491 4156 LEqdUsb - ok
19:49:21.0523 4156 [ 3267BC698E29474A8381E68904EB0390 ] LHidEqd C:\Windows\system32\DRIVERS\LHidEqd.Sys
19:49:21.0523 4156 LHidEqd - ok
19:49:21.0554 4156 [ 241F2648ADF090E2A10095BD6D6F5DCB ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
19:49:21.0554 4156 LHidFilt - ok
19:49:21.0632 4156 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
19:49:21.0632 4156 lltdio - ok
19:49:21.0663 4156 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
19:49:21.0663 4156 lltdsvc - ok
19:49:21.0694 4156 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
19:49:21.0694 4156 lmhosts - ok
19:49:21.0694 4156 [ 342ED5A4B3326014438F36D22D803737 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
19:49:21.0694 4156 LMouFilt - ok
19:49:21.0757 4156 [ 2ED1786B7542CDA261029F6B526EDF44 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
19:49:21.0757 4156 LMS - ok
19:49:21.0835 4156 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
19:49:21.0850 4156 LSI_FC - ok
19:49:21.0913 4156 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
19:49:21.0913 4156 LSI_SAS - ok
19:49:21.0944 4156 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
19:49:21.0944 4156 LSI_SAS2 - ok
19:49:21.0975 4156 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
19:49:21.0991 4156 LSI_SCSI - ok
19:49:22.0006 4156 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
19:49:22.0006 4156 luafv - ok
19:49:22.0100 4156 [ 29C733E1DE824670DC9315CFC9BDBCD3 ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys
19:49:22.0100 4156 LUsbFilt - ok
19:49:22.0131 4156 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
19:49:22.0131 4156 Mcx2Svc - ok
19:49:22.0131 4156 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
19:49:22.0131 4156 megasas - ok
19:49:22.0318 4156 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
19:49:22.0334 4156 MegaSR - ok
19:49:22.0334 4156 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
19:49:22.0334 4156 MEIx64 - ok
19:49:22.0334 4156 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
19:49:22.0334 4156 MMCSS - ok
19:49:22.0381 4156 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
19:49:22.0381 4156 Modem - ok
19:49:22.0381 4156 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
19:49:22.0381 4156 monitor - ok
19:49:22.0396 4156 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
19:49:22.0396 4156 mouclass - ok
19:49:22.0396 4156 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
19:49:22.0396 4156 mouhid - ok
19:49:22.0427 4156 [ 5EB154778552121FE1E61FFC30729A2D ] mounthlp C:\Windows\system32\DRIVERS\mounthlp.sys
19:49:22.0427 4156 mounthlp - ok
19:49:22.0459 4156 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
19:49:22.0459 4156 mountmgr - ok
19:49:22.0537 4156 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
19:49:22.0537 4156 MozillaMaintenance - ok
19:49:22.0568 4156 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
19:49:22.0568 4156 mpio - ok
19:49:22.0568 4156 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
19:49:22.0568 4156 mpsdrv - ok
19:49:22.0599 4156 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
19:49:22.0615 4156 MpsSvc - ok
19:49:22.0646 4156 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
19:49:22.0646 4156 MRxDAV - ok
19:49:22.0661 4156 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
19:49:22.0661 4156 mrxsmb - ok
19:49:22.0708 4156 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:49:22.0708 4156 mrxsmb10 - ok
19:49:22.0724 4156 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:49:22.0724 4156 mrxsmb20 - ok
19:49:22.0724 4156 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
19:49:22.0724 4156 msahci - ok
19:49:22.0739 4156 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
19:49:22.0739 4156 msdsm - ok
19:49:22.0755 4156 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
19:49:22.0755 4156 MSDTC - ok
19:49:22.0786 4156 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
19:49:22.0786 4156 Msfs - ok
19:49:22.0817 4156 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
19:49:22.0817 4156 mshidkmdf - ok
19:49:22.0817 4156 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
19:49:22.0817 4156 msisadrv - ok
19:49:22.0849 4156 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
19:49:22.0849 4156 MSiSCSI - ok
19:49:22.0849 4156 msiserver - ok
19:49:22.0958 4156 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
19:49:22.0958 4156 MSKSSRV - ok
19:49:22.0989 4156 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
19:49:22.0989 4156 MSPCLOCK - ok
19:49:22.0989 4156 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
19:49:22.0989 4156 MSPQM - ok
19:49:23.0083 4156 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
19:49:23.0083 4156 MsRPC - ok
19:49:23.0098 4156 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
19:49:23.0098 4156 mssmbios - ok
19:49:23.0098 4156 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
19:49:23.0098 4156 MSTEE - ok
19:49:23.0114 4156 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
19:49:23.0114 4156 MTConfig - ok
19:49:23.0114 4156 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
19:49:23.0129 4156 Mup - ok
19:49:23.0176 4156 [ 0CF5580F27918FFD2E165ECAFA734103 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
19:49:23.0192 4156 MyWiFiDHCPDNS - ok
19:49:23.0270 4156 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
19:49:23.0270 4156 napagent - ok
19:49:23.0285 4156 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
19:49:23.0285 4156 NativeWifiP - ok
19:49:23.0597 4156 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
19:49:23.0613 4156 NDIS - ok
19:49:23.0660 4156 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
19:49:23.0660 4156 NdisCap - ok
19:49:23.0675 4156 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
19:49:23.0675 4156 NdisTapi - ok
19:49:23.0675 4156 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
19:49:23.0675 4156 Ndisuio - ok
19:49:23.0691 4156 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
19:49:23.0691 4156 NdisWan - ok
19:49:23.0691 4156 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
19:49:23.0707 4156 NDProxy - ok
19:49:23.0707 4156 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
19:49:23.0707 4156 NetBIOS - ok
19:49:23.0722 4156 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
19:49:23.0722 4156 NetBT - ok
19:49:23.0753 4156 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
19:49:23.0753 4156 Netlogon - ok
19:49:23.0816 4156 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
19:49:23.0816 4156 Netman - ok
19:49:24.0268 4156 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
19:49:24.0284 4156 netprofm - ok
19:49:24.0299 4156 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
19:49:24.0299 4156 NetTcpPortSharing - ok
19:49:25.0345 4156 [ B25FE0FA523579B6FA327311A579866E ] NETwNs64 C:\Windows\system32\DRIVERS\NETwNs64.sys
19:49:25.0485 4156 NETwNs64 - ok
19:49:25.0547 4156 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
19:49:25.0547 4156 nfrd960 - ok
19:49:25.0579 4156 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
19:49:25.0579 4156 NlaSvc - ok
19:49:25.0594 4156 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
19:49:25.0594 4156 Npfs - ok
19:49:25.0594 4156 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
19:49:25.0594 4156 nsi - ok
19:49:25.0657 4156 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
19:49:25.0657 4156 nsiproxy - ok
19:49:25.0859 4156 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
19:49:25.0859 4156 Ntfs - ok
19:49:25.0922 4156 [ 317020D31F1696334679B9D0416EB62E ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys
19:49:25.0937 4156 NuidFltr - ok
19:49:25.0937 4156 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
19:49:25.0937 4156 Null - ok
19:49:25.0937 4156 [ 0EBC9D13CD96C15B1B18D8678A609E4B ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
19:49:25.0937 4156 nusb3hub - ok
19:49:25.0969 4156 [ 7BDEC000D56D485021D9C1E63C2F81CA ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
19:49:25.0969 4156 nusb3xhc - ok
19:49:26.0047 4156 [ 8D4AAC74B571FC356560E5B308955E93 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
19:49:26.0047 4156 NVHDA - ok
19:49:28.0262 4156 [ 0EB204639119370F5F8F2871FBF4E14B ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:49:28.0324 4156 nvlddmkm - ok
19:49:28.0387 4156 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
19:49:28.0387 4156 nvraid - ok
19:49:28.0449 4156 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
19:49:28.0449 4156 nvstor - ok
19:49:28.0511 4156 [ 32FF8EE6DCEE5C0CB91FF892FB1CA364 ] NVSvc C:\Windows\system32\nvvsvc.exe
19:49:28.0527 4156 NVSvc - ok
19:49:28.0605 4156 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
19:49:28.0605 4156 nv_agp - ok
19:49:28.0605 4156 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
19:49:28.0621 4156 ohci1394 - ok
19:49:29.0011 4156 [ D8A0164A79D4BFD6083945C5431E41E7 ] OpenVPNService C:\Program Files (x86)\HMA! Pro VPN\bin\openvpnserv.exe
19:49:29.0026 4156 OpenVPNService - ok
19:49:29.0182 4156 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:49:29.0182 4156 ose - ok
19:49:32.0271 4156 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
19:49:32.0365 4156 osppsvc - ok
19:49:32.0474 4156 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
19:49:32.0474 4156 p2pimsvc - ok
19:49:32.0599 4156 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
19:49:32.0599 4156 p2psvc - ok
19:49:32.0630 4156 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
19:49:32.0630 4156 Parport - ok
19:49:32.0630 4156 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
19:49:32.0630 4156 partmgr - ok
19:49:32.0645 4156 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
19:49:32.0645 4156 PcaSvc - ok
19:49:32.0661 4156 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
19:49:32.0661 4156 pci - ok
19:49:32.0692 4156 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
19:49:32.0692 4156 pciide - ok
19:49:32.0708 4156 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
19:49:32.0708 4156 pcmcia - ok
19:49:32.0708 4156 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
19:49:32.0708 4156 pcw - ok
19:49:32.0723 4156 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
19:49:32.0739 4156 PEAUTH - ok
19:49:33.0020 4156 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
19:49:33.0020 4156 PerfHost - ok
19:49:34.0018 4156 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
19:49:34.0143 4156 pla - ok
19:49:34.0205 4156 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
19:49:34.0205 4156 PlugPlay - ok
19:49:34.0221 4156 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
19:49:34.0221 4156 PNRPAutoReg - ok
19:49:34.0237 4156 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
19:49:34.0237 4156 PNRPsvc - ok
19:49:34.0517 4156 [ 4F0878FD62D5F7444C5F1C4C66D9D293 ] Point64 C:\Windows\system32\DRIVERS\point64.sys
19:49:34.0517 4156 Point64 - ok
19:49:35.0048 4156 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
19:49:35.0048 4156 PolicyAgent - ok
19:49:35.0063 4156 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
19:49:35.0063 4156 Power - ok
19:49:35.0141 4156 [ 969D428C21F71E552CEF1DDD486455DC ] PowerBiosServer c:\Program Files (x86)\Hotkey\PowerBiosServer.exe
19:49:35.0157 4156 PowerBiosServer - ok
19:49:35.0173 4156 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
19:49:35.0173 4156 PptpMiniport - ok
19:49:35.0204 4156 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
19:49:35.0204 4156 Processor - ok
19:49:35.0219 4156 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
19:49:35.0219 4156 ProfSvc - ok
19:49:35.0219 4156 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
19:49:35.0219 4156 ProtectedStorage - ok
19:49:35.0235 4156 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
19:49:35.0235 4156 Psched - ok
19:49:35.0375 4156 [ D3438A41E02BA2079BA14125DF358BFE ] PuranDefrag C:\Windows\system32\PuranDefragS.exe
19:49:35.0375 4156 PuranDefrag - ok
19:49:35.0422 4156 [ 87B04878A6D59D6C79251DC960C674C1 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys
19:49:35.0422 4156 PxHlpa64 - ok
19:49:35.0875 4156 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
19:49:35.0937 4156 ql2300 - ok
19:49:35.0999 4156 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
19:49:36.0015 4156 ql40xx - ok
19:49:36.0046 4156 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
19:49:36.0046 4156 QWAVE - ok
19:49:36.0046 4156 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
19:49:36.0046 4156 QWAVEdrv - ok
19:49:36.0077 4156 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
19:49:36.0077 4156 RasAcd - ok
19:49:36.0124 4156 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
19:49:36.0124 4156 RasAgileVpn - ok
19:49:36.0124 4156 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
19:49:36.0140 4156 RasAuto - ok
19:49:36.0140 4156 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
19:49:36.0140 4156 Rasl2tp - ok
19:49:36.0187 4156 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
19:49:36.0202 4156 RasMan - ok
19:49:36.0202 4156 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
19:49:36.0202 4156 RasPppoe - ok
19:49:36.0218 4156 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
19:49:36.0218 4156 RasSstp - ok
19:49:36.0311 4156 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
19:49:36.0311 4156 rdbss - ok
19:49:36.0327 4156 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
19:49:36.0327 4156 rdpbus - ok
19:49:36.0436 4156 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
19:49:36.0436 4156 RDPCDD - ok
19:49:36.0467 4156 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
19:49:36.0467 4156 RDPENCDD - ok
19:49:36.0467 4156 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
19:49:36.0467 4156 RDPREFMP - ok
19:49:36.0499 4156 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
19:49:36.0499 4156 RDPWD - ok
19:49:36.0530 4156 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
19:49:36.0530 4156 rdyboost - ok
19:49:36.0701 4156 [ AA9FD849C028CCB441A78061B57DB734 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
19:49:36.0717 4156 RegSrvc - ok
19:49:36.0717 4156 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
19:49:36.0733 4156 RemoteAccess - ok
19:49:36.0779 4156 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
19:49:36.0795 4156 RemoteRegistry - ok
19:49:36.0826 4156 [ 3644F601AAA415651B1FC3E2726D1605 ] reparse C:\Windows\system32\DRIVERS\cbreparse.sys
19:49:36.0826 4156 reparse - ok
19:49:36.0904 4156 [ 9C3AC71A9934B884FAC567A8807E9C4D ] Revoflt C:\Windows\system32\DRIVERS\revoflt.sys
19:49:36.0920 4156 Revoflt - ok
19:49:36.0920 4156 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
19:49:36.0920 4156 RpcEptMapper - ok
19:49:36.0920 4156 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
19:49:36.0920 4156 RpcLocator - ok
19:49:36.0951 4156 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
19:49:36.0951 4156 RpcSs - ok
19:49:37.0185 4156 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
19:49:37.0185 4156 rspndr - ok
19:49:37.0201 4156 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
19:49:37.0201 4156 SamSs - ok
19:49:37.0216 4156 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
19:49:37.0216 4156 sbp2port - ok
19:49:37.0279 4156 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
19:49:37.0279 4156 SCardSvr - ok
19:49:37.0279 4156 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
19:49:37.0294 4156 scfilter - ok
19:49:37.0325 4156 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
19:49:37.0325 4156 Schedule - ok
19:49:37.0419 4156 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
19:49:37.0419 4156 SCPolicySvc - ok
19:49:37.0450 4156 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
19:49:37.0466 4156 sdbus - ok
19:49:37.0466 4156 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
19:49:37.0466 4156 SDRSVC - ok
19:49:37.0513 4156 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
19:49:37.0513 4156 secdrv - ok
19:49:37.0513 4156 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
19:49:37.0513 4156 seclogon - ok
19:49:37.0528 4156 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
19:49:37.0528 4156 SENS - ok
19:49:37.0622 4156 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
19:49:37.0622 4156 SensrSvc - ok
19:49:37.0653 4156 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
19:49:37.0653 4156 Serenum - ok
19:49:37.0840 4156 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
19:49:37.0840 4156 Serial - ok
19:49:37.0840 4156 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
19:49:37.0840 4156 sermouse - ok
19:49:37.0856 4156 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
19:49:37.0856 4156 SessionEnv - ok
19:49:37.0871 4156 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
19:49:37.0871 4156 sffdisk - ok
19:49:37.0918 4156 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
19:49:37.0918 4156 sffp_mmc - ok
19:49:37.0934 4156 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
19:49:37.0934 4156 sffp_sd - ok
19:49:37.0981 4156 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
19:49:37.0981 4156 sfloppy - ok
19:49:38.0105 4156 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
19:49:38.0105 4156 Sftfs - ok
19:49:38.0215 4156 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
19:49:38.0230 4156 sftlist - ok
19:49:38.0246 4156 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
19:49:38.0246 4156 Sftplay - ok
19:49:38.0246 4156 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
19:49:38.0246 4156 Sftredir - ok
19:49:38.0261 4156 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
19:49:38.0261 4156 Sftvol - ok
19:49:38.0417 4156 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
19:49:38.0417 4156 sftvsa - ok
19:49:38.0449 4156 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
19:49:38.0449 4156 SharedAccess - ok
19:49:38.0464 4156 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:49:38.0464 4156 ShellHWDetection - ok
19:49:38.0527 4156 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
19:49:38.0527 4156 SiSRaid2 - ok
19:49:38.0542 4156 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
19:49:38.0542 4156 SiSRaid4 - ok
19:49:38.0667 4156 [ EA396139541706B4B433641D62EA53CE ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
19:49:38.0667 4156 SkypeUpdate - ok
19:49:38.0683 4156 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
19:49:38.0683 4156 Smb - ok
19:49:38.0776 4156 [ 3DA591BBAB178A3152B8685DC43B20CD ] smbusp C:\Windows\system32\DRIVERS\intelsmb.sys
19:49:38.0776 4156 smbusp - ok
19:49:38.0854 4156 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
19:49:38.0854 4156 SNMPTRAP - ok
19:49:38.0854 4156 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
19:49:38.0854 4156 spldr - ok
19:49:38.0870 4156 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
19:49:38.0870 4156 Spooler - ok
19:49:39.0712 4156 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
19:49:39.0728 4156 sppsvc - ok
19:49:39.0728 4156 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
19:49:39.0728 4156 sppuinotify - ok
19:49:39.0775 4156 [ D8B882C520FC83547E22014FF5EC66D7 ] Spyder3 C:\Windows\system32\DRIVERS\Spyder3.sys
19:49:39.0775 4156 Spyder3 - ok
19:49:39.0790 4156 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
19:49:39.0790 4156 srv - ok
19:49:39.0806 4156 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
19:49:39.0821 4156 srv2 - ok
19:49:39.0837 4156 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
19:49:39.0837 4156 srvnet - ok
19:49:39.0884 4156 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
19:49:39.0884 4156 SSDPSRV - ok
19:49:40.0040 4156 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
19:49:40.0040 4156 SstpSvc - ok
19:49:40.0071 4156 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
19:49:40.0071 4156 stexstor - ok
19:49:40.0118 4156 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
19:49:40.0118 4156 stisvc - ok
19:49:40.0118 4156 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
19:49:40.0118 4156 swenum - ok
19:49:40.0133 4156 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
19:49:40.0149 4156 swprv - ok
19:49:40.0601 4156 [ 63B74B3C62E0AEA3084A7D5799D1243E ] SynchronizationService.exe C:\Program Files\COMODO\COMMON\SynchronizationService.exe
19:49:40.0617 4156 SynchronizationService.exe - ok
19:49:41.0163 4156 [ F4DB1D9E6A42D491F0F8E21854301C0B ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
19:49:41.0163 4156 SynTP - ok
19:49:41.0444 4156 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
19:49:41.0475 4156 SysMain - ok
19:49:41.0475 4156 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:49:41.0475 4156 TabletInputService - ok
19:49:41.0538 4156 [ 3B73C849B41FB20D77B0E553214061A5 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys
19:49:41.0538 4156 tap0901 - ok
19:49:41.0616 4156 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
19:49:41.0616 4156 TapiSrv - ok
19:49:41.0631 4156 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
19:49:41.0631 4156 TBS - ok
19:49:41.0850 4156 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
19:49:41.0865 4156 Tcpip - ok
19:49:41.0881 4156 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
19:49:41.0896 4156 TCPIP6 - ok
19:49:41.0896 4156 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
19:49:41.0912 4156 tcpipreg - ok
19:49:41.0928 4156 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
19:49:41.0928 4156 TDPIPE - ok
19:49:41.0990 4156 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
19:49:41.0990 4156 TDTCP - ok
19:49:42.0006 4156 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
19:49:42.0006 4156 tdx - ok
19:49:42.0661 4156 [ A4D2CE94B028EF1E437CF4AC3D8FF26C ] TeamViewer7 C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
19:49:42.0676 4156 TeamViewer7 - ok
19:49:42.0676 4156 [ F5520DBB47C60EE83024B38720ABDA24 ] teamviewervpn C:\Windows\system32\DRIVERS\teamviewervpn.sys
19:49:42.0676 4156 teamviewervpn - ok
19:49:42.0708 4156 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
19:49:42.0708 4156 TermDD - ok
19:49:42.0817 4156 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
19:49:42.0817 4156 TermService - ok
19:49:42.0832 4156 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
19:49:42.0848 4156 Themes - ok
19:49:42.0848 4156 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
19:49:42.0848 4156 THREADORDER - ok
19:49:42.0864 4156 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
19:49:42.0864 4156 TrkWks - ok
19:49:43.0129 4156 [ DF219721DDFFCBE03AA894B6B6742BA1 ] trufos C:\Windows\system32\DRIVERS\trufos.sys
19:49:43.0129 4156 trufos - ok
19:49:43.0144 4156 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:49:43.0144 4156 TrustedInstaller - ok
19:49:43.0144 4156 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
19:49:43.0144 4156 tssecsrv - ok
19:49:43.0160 4156 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
19:49:43.0160 4156 TsUsbFlt - ok
19:49:43.0191 4156 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
19:49:43.0191 4156 TsUsbGD - ok
19:49:43.0347 4156 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
19:49:43.0347 4156 tunnel - ok
19:49:43.0347 4156 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
19:49:43.0347 4156 uagp35 - ok
19:49:43.0378 4156 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
19:49:43.0378 4156 udfs - ok
19:49:43.0394 4156 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
19:49:43.0394 4156 UI0Detect - ok
19:49:43.0410 4156 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
19:49:43.0410 4156 uliagpkx - ok
19:49:43.0456 4156 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
19:49:43.0456 4156 umbus - ok
19:49:43.0488 4156 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
19:49:43.0488 4156 UmPass - ok
19:49:43.0597 4156 [ 9DC07E73A4ABB9ACF692113B36A5009F ] UnlockerDriver5 C:\Program Files\Unlocker\UnlockerDriver5.sys
19:49:43.0597 4156 UnlockerDriver5 - ok
19:49:44.0049 4156 [ 7E5E1603D0FF2D240AE70295C5C3FEFC ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
19:49:44.0080 4156 UNS - ok
19:49:44.0907 4156 [ 7DE3F30967CF77BD1FC440C2B847629A ] Update Server C:\Program Files\Common Files\Bitdefender\Bitdefender Arrakis Server\bin\arrakis3.exe
19:49:44.0923 4156 Update Server - ok
19:49:45.0063 4156 [ DDC49896DC045AADC1988D0D0330811A ] UPDATESRV C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe
19:49:45.0063 4156 UPDATESRV - ok
19:49:45.0079 4156 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
19:49:45.0079 4156 upnphost - ok
19:49:45.0126 4156 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
19:49:45.0126 4156 usbaudio - ok
19:49:45.0391 4156 [ 5FCC71487888589A9244AF54CFEFAB29 ] usbbus C:\Windows\system32\DRIVERS\lgx64bus.sys
19:49:45.0391 4156 usbbus - ok
19:49:45.0453 4156 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
19:49:45.0453 4156 usbccgp - ok
19:49:45.0562 4156 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
19:49:45.0578 4156 usbcir - ok
19:49:45.0578 4156 [ 3FB6E423F7567C92C32EA786F5FD0C69 ] UsbDiag C:\Windows\system32\DRIVERS\lgx64diag.sys
19:49:45.0578 4156 UsbDiag - ok
19:49:45.0578 4156 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\drivers\usbehci.sys
19:49:45.0594 4156 usbehci - ok
19:49:45.0687 4156 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
19:49:45.0687 4156 usbhub - ok
19:49:45.0765 4156 [ 78D551F5B93488B4666F5FC8DD4815F3 ] USBModem C:\Windows\system32\DRIVERS\lgx64modem.sys
19:49:45.0765 4156 USBModem - ok
19:49:45.0765 4156 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
19:49:45.0765 4156 usbohci - ok
19:49:45.0796 4156 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
19:49:45.0796 4156 usbprint - ok
19:49:45.0859 4156 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:49:45.0859 4156 USBSTOR - ok
19:49:45.0874 4156 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
19:49:45.0874 4156 usbuhci - ok
19:49:45.0937 4156 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
19:49:45.0937 4156 usbvideo - ok
19:49:45.0952 4156 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
19:49:45.0952 4156 UxSms - ok
19:49:46.0015 4156 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
19:49:46.0030 4156 VaultSvc - ok
19:49:46.0077 4156 [ 19EB1DDE7DA662F6E486B6EF53635E15 ] vdbus C:\Windows\system32\DRIVERS\vdbus.sys
19:49:46.0077 4156 vdbus - ok
19:49:46.0093 4156 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
19:49:46.0093 4156 vdrvroot - ok
19:49:46.0108 4156 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
19:49:46.0124 4156 vds - ok
19:49:46.0171 4156 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
19:49:46.0171 4156 vga - ok
19:49:46.0171 4156 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
19:49:46.0171 4156 VgaSave - ok
19:49:46.0186 4156 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
19:49:46.0186 4156 vhdmp - ok
19:49:46.0311 4156 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
19:49:46.0311 4156 viaide - ok
19:49:46.0342 4156 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
19:49:46.0342 4156 volmgr - ok
19:49:46.0389 4156 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
19:49:46.0405 4156 volmgrx - ok
19:49:46.0405 4156 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
19:49:46.0420 4156 volsnap - ok
19:49:46.0452 4156 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
19:49:46.0452 4156 vsmraid - ok
19:49:46.0779 4156 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
19:49:46.0826 4156 VSS - ok
19:49:46.0826 4156 VSSERV - ok
19:49:46.0826 4156 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
19:49:46.0826 4156 vwifibus - ok
19:49:46.0826 4156 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
19:49:46.0842 4156 vwififlt - ok
19:49:46.0842 4156 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
19:49:46.0842 4156 vwifimp - ok
19:49:46.0857 4156 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
19:49:46.0857 4156 W32Time - ok
19:49:46.0904 4156 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
19:49:46.0904 4156 WacomPen - ok
19:49:46.0966 4156 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
19:49:46.0982 4156 WANARP - ok
19:49:46.0998 4156 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
19:49:46.0998 4156 Wanarpv6 - ok
19:49:47.0185 4156 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
19:49:47.0232 4156 WatAdminSvc - ok
19:49:47.0403 4156 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
19:49:47.0419 4156 wbengine - ok
19:49:47.0466 4156 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
19:49:47.0481 4156 WbioSrvc - ok
19:49:47.0481 4156 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
19:49:47.0497 4156 wcncsvc - ok
19:49:47.0497 4156 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:49:47.0497 4156 WcsPlugInService - ok
19:49:47.0497 4156 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
19:49:47.0497 4156 Wd - ok
19:49:47.0575 4156 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
19:49:47.0575 4156 Wdf01000 - ok
19:49:47.0575 4156 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
19:49:47.0590 4156 WdiServiceHost - ok
19:49:47.0590 4156 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
19:49:47.0590 4156 WdiSystemHost - ok
19:49:47.0622 4156 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
19:49:47.0622 4156 WebClient - ok
19:49:47.0637 4156 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
19:49:47.0653 4156 Wecsvc - ok
19:49:47.0653 4156 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
19:49:47.0653 4156 wercplsupport - ok
19:49:47.0700 4156 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
19:49:47.0700 4156 WerSvc - ok
19:49:47.0731 4156 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
19:49:47.0746 4156 WfpLwf - ok
19:49:47.0824 4156 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
19:49:47.0824 4156 WIMMount - ok
19:49:47.0824 4156 WinDefend - ok
19:49:47.0934 4156 [ 160BF82F830C05D29EE830D1E526F551 ] Windows7FirewallService C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe
19:49:47.0949 4156 Windows7FirewallService - ok
19:49:47.0949 4156 WinHttpAutoProxySvc - ok
19:49:48.0074 4156 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
19:49:48.0152 4156 Winmgmt - ok
19:49:48.0417 4156 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
19:49:48.0448 4156 WinRM - ok
19:49:48.0464 4156 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys
19:49:48.0464 4156 WinUsb - ok
19:49:48.0558 4156 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
19:49:48.0589 4156 Wlansvc - ok
19:49:48.0604 4156 [ 680A7846370000D20D7E74917D5B7936 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
19:49:48.0604 4156 WmBEnum - ok
19:49:48.0994 4156 [ 14C35BA8189C6F65D839163AA285E954 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
19:49:48.0994 4156 WmFilter - ok
19:49:49.0150 4156 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
19:49:49.0150 4156 WmiAcpi - ok
19:49:49.0228 4156 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
19:49:49.0228 4156 wmiApSrv - ok
19:49:49.0244 4156 WMPNetworkSvc - ok
19:49:49.0260 4156 [ 8488DD91A3EE54A8E29F02AD7BB8201E ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
19:49:49.0275 4156 WmVirHid - ok
19:49:49.0291 4156 [ 14802B3A30AA849C97CB968CCC813BF3 ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
19:49:49.0291 4156 WmXlCore - ok
19:49:49.0322 4156 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
19:49:49.0322 4156 WPCSvc - ok
19:49:49.0338 4156 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
19:49:49.0338 4156 WPDBusEnum - ok
19:49:49.0353 4156 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
19:49:49.0353 4156 ws2ifsl - ok
19:49:49.0353 4156 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
19:49:49.0353 4156 wscsvc - ok
19:49:49.0369 4156 WSearch - ok
19:49:49.0540 4156 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
19:49:49.0587 4156 wuauserv - ok
19:49:49.0603 4156 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
19:49:49.0603 4156 WudfPf - ok
19:49:49.0603 4156 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
19:49:49.0618 4156 WUDFRd - ok
19:49:49.0618 4156 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
19:49:49.0618 4156 wudfsvc - ok
19:49:49.0650 4156 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
19:49:49.0650 4156 WwanSvc - ok
19:49:49.0852 4156 [ 876F0C41035C04BA7A44EC0418408F69 ] XTUService C:\Program Files (x86)\Common Files\Intel\Intel Extreme Tuning Utility\PerfTuneService.exe
19:49:49.0852 4156 XTUService - ok
19:49:49.0915 4156 ================ Scan global ===============================
19:49:49.0930 4156 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
19:49:49.0930 4156 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
19:49:49.0946 4156 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
19:49:49.0962 4156 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
19:49:49.0977 4156 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
19:49:49.0977 4156 [Global] - ok
19:49:49.0977 4156 ================ Scan MBR ==================================
19:49:49.0977 4156 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
19:50:00.0850 4156 \Device\Harddisk0\DR0 - ok
19:50:00.0850 4156 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
19:50:01.0194 4156 \Device\Harddisk1\DR1 - ok
19:50:01.0194 4156 ================ Scan VBR ==================================
19:50:01.0194 4156 [ 4B5ABE6C539F2C9CDFDDEE53114417BC ] \Device\Harddisk0\DR0\Partition1
19:50:01.0194 4156 \Device\Harddisk0\DR0\Partition1 - ok
19:50:01.0209 4156 [ 665AEAA5E8C43D28890D1054986C52F2 ] \Device\Harddisk0\DR0\Partition2
19:50:01.0209 4156 \Device\Harddisk0\DR0\Partition2 - ok
19:50:01.0209 4156 [ 1D993C3A2CCC267EB5E40314870DFE2A ] \Device\Harddisk0\DR0\Partition3
19:50:01.0209 4156 \Device\Harddisk0\DR0\Partition3 - ok
19:50:01.0256 4156 [ 2ED78F4B973F10A66FDE61D86E58D940 ] \Device\Harddisk1\DR1\Partition1
19:50:01.0256 4156 \Device\Harddisk1\DR1\Partition1 - ok
19:50:01.0272 4156 [ EF7A4868E0AECBEA743EEF388C5B0ABF ] \Device\Harddisk1\DR1\Partition2
19:50:01.0272 4156 \Device\Harddisk1\DR1\Partition2 - ok
19:50:01.0272 4156 [ 7D93CA8882C972FFA07D6C688DE6150A ] \Device\Harddisk1\DR1\Partition3
19:50:01.0272 4156 \Device\Harddisk1\DR1\Partition3 - ok
19:50:01.0272 4156 ============================================================
19:50:01.0272 4156 Scan finished
19:50:01.0272 4156 ============================================================
19:50:01.0272 5528 Detected object count: 1
19:50:01.0272 5528 Actual detected object count: 1
19:53:18.0466 5528 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
19:53:18.0466 5528 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
19:59:33.0472 4868 Deinitialize success
=========================================================================================

Also Ran MBAM in Normal mode after updating:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.16.13

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Nick :: NICK-LAPTOP [administrator]

9/16/2012 8:10:05 PM
mbam-log-2012-09-16 (20-10-05).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 239902
Time elapsed: 2 minute(s), 12 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

No longer having an issue with the pop-up message at log-in. All seems to be working nicely so far. Haven't seen any crashes yet either. If you believe that it may be a separate issue then I will post in a different topic in this forum if it continues.
Is there anything else I should check?

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:46 PM

Posted 17 September 2012 - 10:10 AM

Look s good here. Now you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 Nick7560

Nick7560
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:11:46 PM

Posted 17 September 2012 - 04:11 PM

I set up a new Restore Point and all seems to be running fine again. Thank you for taking the time Boopme. I'm very glad that I finally registered with you guys in this forum after sneaking in from time to time for years, lol. Makes me kinda feel "legal" now, lol.
Thanks,
Nick

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,530 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:10:46 PM

Posted 17 September 2012 - 06:31 PM

You're welcome and thanks for being a member!!
Lurker tag officially removed :lol:

Edited by boopme, 17 September 2012 - 06:31 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users