Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan still not being removed


  • Please log in to reply
33 replies to this topic

#1 nave_80

nave_80

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 19 September 2012 - 11:33 AM

O/S windows 7
32 bit

History of the issue:
Recently I had a trojan attack on my system wherein I received some hard drive corrupted messages, most of my folders got hidden, had some random updates for my flash player which never went away and I could not start the windows security. I started on safe mode and searched the internet and came across this extremely helpful site and used some of the tools recommended such as Superantispyware, Rkill and Unhide.

With those tools I managed to remove the most of the errors, but the system is still not fully clean. Internet explorer is seriously corrupted i.e. everytime I click on a google searched link I will be redirected to some random ad website and if I do manage to get the correct site, the computer becomes so slow that it takes ages to load the pages. Everyday when I start the system the Superantispyware detects the same adware cookies which were previously deleted and sometimes trojans are detected.

It seems like some sort of trojan gets activated everytime I start the system and automatically creates these cookies and stores it in a folder which seems like one of the user's name but it is not, it is a folder with a name similar to the user name. I cannot find this folder under C:\Users when I try to look for it.

Any ideas of how to clean my computer without having to formatting the drive?

Your help is much appreciated.

*Moderator Edit: Moved topic from Windows 7 to the more appropriate forum. ~ Queen-Evie*

Edited by Queen-Evie, 19 September 2012 - 11:38 AM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 19 September 2012 - 12:59 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 19 September 2012 - 05:04 PM

Hi narenxp,

Thanks for your reply.

Re: TDSSKiller and aswMBR I can download the .exe files but can't seem to launch them. I tried in safemode as well still the same issue.


Re: ESET, below is the threat found

"Operating memory a variant of Win32/Olmarik.AYN trojan"

#4 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:07:15 AM

Posted 22 September 2012 - 06:13 AM

Hi

Re: TDSSKiller and aswMBR I can download the .exe files but can't seem to launch them. I tried in safemode as well still the same issue.

In that case, please do the following next:

Please download Rkill by Grinler from Link 1 and save it to your desktop.

Link 1
Link 2 (renamed Rkill)

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7, right-click on it and Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If that does not work: delete the file, then download and use the one provided in Link 2 above.
  • If that does not work: repeat the process and attempt to use one of the remaining links under RKill download links here until the tool runs.
  • If the tool does not run from any of the links provided, please let me know.
Do not reboot your computer after running rkill as the malware programs will start again. Or if rebooting is required run it again.

Please post the full contents of the log created by rkill in your next reply.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#5 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 22 September 2012 - 07:50 AM

System has MAXSS rootkit.RKILL cannot make TDSSkiller or ASWMBR run.

Download Listparts from here

For 32 bit

List parts 32

Launch it,click on SCAN ,post the Listparts log

Edited by narenxp, 22 September 2012 - 07:51 AM.


#6 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 24 September 2012 - 04:55 AM

Hi Narenxp,

Below is the listparts log:

ListParts by Farbar Version: 17-09-2012
Ran by Pool Laptop (administrator) on 24-09-2012 at 10:52:34
Windows 7 (X86)
Running From: C:\Users\Pool Laptop\Desktop\19.09.2012\New folder
Language: 0409
************************************************************

========================= Memory info ======================

Percentage of memory in use: 51%
Total physical RAM: 3548.36 MB
Available physical RAM: 1730.29 MB
Total Pagefile: 7095.01 MB
Available Pagefile: 4896.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1969.36 MB

======================= Partitions =========================

1 Drive c: (OS) (Fixed) (Total:134.35 GB) (Free:79.14 GB) NTFS

Disk ### Status Size Free Dyn Gpt
-------- ------------- ------- ------- --- ---
Disk 0 Online 149 GB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 OEM 39 MB 31 KB
Partition 2 Primary 14 GB 39 MB
Partition 3 Primary 134 GB 14 GB
Partition 4 Primary 10 MB 149 GB

======================================================================================================

Disk: 0
Partition 1
Type : DE
Hidden: Yes
Active: No

There is no volume associated with this partition.

======================================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 RECOVERY NTFS Partition 14 GB Healthy System (partition with boot components)

======================================================================================================

Disk: 0
Partition 3
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 C OS NTFS Partition 134 GB Healthy Boot

======================================================================================================

Disk: 0
Partition 4
Type : 17 (Suspicious Type)
Hidden: Yes
Active: No

There is no volume associated with this partition.

======================================================================================================

Windows Boot Manager
--------------------
identifier {9dea862c-5cdd-4e70-acc1-f32b344d4795}
device partition=\Device\HarddiskVolume2
description Windows Boot Manager
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
default {310c748c-b169-11df-8161-f04da24734ee}
resumeobject {310c748b-b169-11df-8161-f04da24734ee}
displayorder {310c748c-b169-11df-8161-f04da24734ee}
toolsdisplayorder {b2721d73-1db4-4c62-bf78-c548a880142d}
timeout 30

Windows Boot Loader
-------------------
identifier {310c748c-b169-11df-8161-f04da24734ee}
device partition=C:
path \Windows\system32\winload.exe
description Windows 7
locale en-US
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
recoverysequence {310c748d-b169-11df-8161-f04da24734ee}
recoveryenabled Yes
osdevice partition=C:
systemroot \Windows
resumeobject {310c748b-b169-11df-8161-f04da24734ee}
nx OptIn

Windows Boot Loader
-------------------
identifier {310c748d-b169-11df-8161-f04da24734ee}
device ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{310c748e-b169-11df-8161-f04da24734ee}
path \windows\system32\winload.exe
description Windows Recovery Environment
inherit {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
osdevice ramdisk=[\Device\HarddiskVolume2]\Recovery\WindowsRE\Winre.wim,{310c748e-b169-11df-8161-f04da24734ee}
systemroot \windows
nx OptIn
winpe Yes
custom:46000010 Yes

Resume from Hibernate
---------------------
identifier {310c748b-b169-11df-8161-f04da24734ee}
device partition=C:
path \Windows\system32\winresume.exe
description Windows Resume Application
locale en-US
inherit {1afa9c49-16ab-4a5c-901b-212802da9460}
filedevice partition=C:
filepath \hiberfil.sys
pae Yes
debugoptionenabled No

Windows Memory Tester
---------------------
identifier {b2721d73-1db4-4c62-bf78-c548a880142d}
device partition=\Device\HarddiskVolume2
path \boot\memtest.exe
description Windows Memory Diagnostic
locale en-US
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
badmemoryaccess Yes

EMS Settings
------------
identifier {0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
bootems Yes

Debugger Settings
-----------------
identifier {4636856e-540f-4170-a130-a84776f4c654}
debugtype Serial
debugport 1
baudrate 115200

RAM Defects
-----------
identifier {5189b25c-5558-4bf2-bca4-289b11bd29e2}

Global Settings
---------------
identifier {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
inherit {4636856e-540f-4170-a130-a84776f4c654}
{0ce4991b-e6b3-4b16-b23c-5e0d9250e5d9}
{5189b25c-5558-4bf2-bca4-289b11bd29e2}

Boot Loader Settings
--------------------
identifier {6efb52bf-1766-41db-a6b3-0ee5eff72bd7}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}
{7ff607e0-4395-11db-b0de-0800200c9a66}

Hypervisor Settings
-------------------
identifier {7ff607e0-4395-11db-b0de-0800200c9a66}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200

Resume Loader Settings
----------------------
identifier {1afa9c49-16ab-4a5c-901b-212802da9460}
inherit {7ea2e1ac-2e61-4728-aaa3-896d9d0a9f0e}

Device options
--------------
identifier {310c748e-b169-11df-8161-f04da24734ee}
description Ramdisk Options
ramdisksdidevice partition=\Device\HarddiskVolume2
ramdisksdipath \Recovery\WindowsRE\boot.sdi


****** End Of Log ******

#7 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 24 September 2012 - 05:06 AM

Tdsskiller and ASWMBR will launch now.Post the logs

Edited by narenxp, 24 September 2012 - 08:16 PM.


#8 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 24 September 2012 - 12:38 PM

Thank you.

TDSSKiller report below:

18:15:40.0139 2520 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
18:15:40.0217 2520 ============================================================
18:15:40.0217 2520 Current date / time: 2012/09/24 18:15:40.0217
18:15:40.0217 2520 SystemInfo:
18:15:40.0217 2520
18:15:40.0217 2520 OS Version: 6.1.7601 ServicePack: 1.0
18:15:40.0217 2520 Product type: Workstation
18:15:40.0217 2520 ComputerName: NAVEEN-LAPTOP
18:15:40.0217 2520 UserName: Pool Laptop
18:15:40.0217 2520 Windows directory: C:\Windows
18:15:40.0217 2520 System windows directory: C:\Windows
18:15:40.0217 2520 Processor architecture: Intel x86
18:15:40.0217 2520 Number of processors: 2
18:15:40.0217 2520 Page size: 0x1000
18:15:40.0217 2520 Boot type: Normal boot
18:15:40.0217 2520 ============================================================
18:15:42.0604 2520 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:15:42.0620 2520 ============================================================
18:15:42.0620 2520 \Device\Harddisk0\DR0:
18:15:42.0620 2520 MBR partitions:
18:15:42.0620 2520 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x1D4C000
18:15:42.0620 2520 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D5F9C5, BlocksNum 0x10CB2CEB
18:15:42.0620 2520 ============================================================
18:15:42.0635 2520 C: <-> \Device\Harddisk0\DR0\Partition2
18:15:42.0635 2520 ============================================================
18:15:42.0635 2520 Initialize success
18:15:42.0635 2520 ============================================================
18:15:44.0944 4164 ============================================================
18:15:44.0944 4164 Scan started
18:15:44.0944 4164 Mode: Manual;
18:15:44.0944 4164 ============================================================
18:15:45.0381 4164 ================ Scan system memory ========================
18:15:45.0381 4164 System memory - ok
18:15:45.0381 4164 ================ Scan services =============================
18:15:45.0537 4164 [ 01E81C84AD1D0ACC61CF3CFD06632210 ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
18:15:45.0537 4164 !SASCORE - ok
18:15:46.0130 4164 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:15:46.0130 4164 1394ohci - ok
18:15:46.0192 4164 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:15:46.0192 4164 ACPI - ok
18:15:46.0254 4164 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:15:46.0254 4164 AcpiPmi - ok
18:15:46.0379 4164 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
18:15:46.0379 4164 AdobeARMservice - ok
18:15:46.0457 4164 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:15:46.0457 4164 adp94xx - ok
18:15:46.0488 4164 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:15:46.0504 4164 adpahci - ok
18:15:46.0520 4164 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:15:46.0520 4164 adpu320 - ok
18:15:46.0582 4164 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:15:46.0582 4164 AeLookupSvc - ok
18:15:46.0629 4164 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
18:15:46.0644 4164 AFD - ok
18:15:46.0691 4164 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
18:15:46.0691 4164 agp440 - ok
18:15:46.0738 4164 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
18:15:46.0754 4164 aic78xx - ok
18:15:46.0972 4164 [ 0923671CF87CD511E46D4668B53F5E76 ] Akamai c:\program files\common files\akamai/netsession_win_5891ae0.dll
18:15:46.0972 4164 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_5891ae0.dll. md5: 0923671CF87CD511E46D4668B53F5E76
18:15:46.0972 4164 Akamai ( HiddenFile.Multi.Generic ) - warning
18:15:46.0972 4164 Akamai - detected HiddenFile.Multi.Generic (1)
18:15:47.0050 4164 [ 730E9D3BB324FB1899005AEA63C6782D ] aksfridge C:\Windows\system32\drivers\aksfridge.sys
18:15:47.0050 4164 aksfridge - ok
18:15:47.0128 4164 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
18:15:47.0128 4164 ALG - ok
18:15:47.0175 4164 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
18:15:47.0175 4164 aliide - ok
18:15:47.0222 4164 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:15:47.0222 4164 amdagp - ok
18:15:47.0237 4164 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
18:15:47.0237 4164 amdide - ok
18:15:47.0300 4164 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:15:47.0300 4164 AmdK8 - ok
18:15:47.0315 4164 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:15:47.0315 4164 AmdPPM - ok
18:15:47.0378 4164 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:15:47.0378 4164 amdsata - ok
18:15:47.0393 4164 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:15:47.0393 4164 amdsbs - ok
18:15:47.0456 4164 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:15:47.0456 4164 amdxata - ok
18:15:47.0518 4164 [ E8A8E6072CB7E2032E85E7735DAA511F ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
18:15:47.0518 4164 ApfiltrService - ok
18:15:47.0565 4164 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
18:15:47.0580 4164 AppID - ok
18:15:47.0627 4164 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:15:47.0627 4164 AppIDSvc - ok
18:15:47.0674 4164 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
18:15:47.0674 4164 Appinfo - ok
18:15:47.0721 4164 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
18:15:47.0721 4164 arc - ok
18:15:47.0752 4164 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:15:47.0752 4164 arcsas - ok
18:15:47.0924 4164 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:15:47.0924 4164 aspnet_state - ok
18:15:47.0955 4164 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:15:47.0955 4164 AsyncMac - ok
18:15:47.0986 4164 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
18:15:47.0986 4164 atapi - ok
18:15:48.0064 4164 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:15:48.0064 4164 AudioEndpointBuilder - ok
18:15:48.0095 4164 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:15:48.0095 4164 Audiosrv - ok
18:15:48.0173 4164 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:15:48.0173 4164 AxInstSV - ok
18:15:48.0220 4164 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
18:15:48.0236 4164 b06bdrv - ok
18:15:48.0282 4164 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
18:15:48.0282 4164 b57nd60x - ok
18:15:48.0516 4164 [ 825F81A6F7DD073509DB101F0BA6DC59 ] BBSvc C:\Program Files\Microsoft\BingBar\BBSvc.EXE
18:15:48.0516 4164 BBSvc - ok
18:15:48.0672 4164 [ EB4434444E2721D721A8AC8D5D2AD26B ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys
18:15:48.0688 4164 BCM42RLY - ok
18:15:48.0813 4164 [ 919832D1A7D067119CD5EE29BA76327A ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
18:15:48.0891 4164 BCM43XX - ok
18:15:48.0969 4164 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
18:15:48.0969 4164 BDESVC - ok
18:15:49.0031 4164 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
18:15:49.0031 4164 Beep - ok
18:15:49.0078 4164 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
18:15:49.0094 4164 BFE - ok
18:15:49.0187 4164 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
18:15:49.0203 4164 BITS - ok
18:15:49.0250 4164 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:15:49.0250 4164 blbdrive - ok
18:15:49.0296 4164 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:15:49.0296 4164 bowser - ok
18:15:49.0328 4164 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:15:49.0328 4164 BrFiltLo - ok
18:15:49.0343 4164 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:15:49.0343 4164 BrFiltUp - ok
18:15:49.0359 4164 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
18:15:49.0421 4164 Browser - ok
18:15:49.0452 4164 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:15:49.0468 4164 Brserid - ok
18:15:49.0484 4164 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:15:49.0484 4164 BrSerWdm - ok
18:15:49.0515 4164 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:15:49.0515 4164 BrUsbMdm - ok
18:15:49.0515 4164 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:15:49.0515 4164 BrUsbSer - ok
18:15:49.0577 4164 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
18:15:49.0608 4164 BthEnum - ok
18:15:49.0671 4164 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:15:49.0671 4164 BTHMODEM - ok
18:15:49.0702 4164 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
18:15:49.0702 4164 BthPan - ok
18:15:49.0764 4164 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
18:15:49.0796 4164 BTHPORT - ok
18:15:49.0842 4164 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
18:15:49.0842 4164 bthserv - ok
18:15:49.0889 4164 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
18:15:49.0936 4164 BTHUSB - ok
18:15:49.0952 4164 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:15:49.0967 4164 cdfs - ok
18:15:50.0014 4164 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:15:50.0014 4164 cdrom - ok
18:15:50.0061 4164 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
18:15:50.0061 4164 CertPropSvc - ok
18:15:50.0108 4164 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:15:50.0108 4164 circlass - ok
18:15:50.0154 4164 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
18:15:50.0154 4164 CLFS - ok
18:15:50.0248 4164 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:15:50.0248 4164 clr_optimization_v2.0.50727_32 - ok
18:15:50.0310 4164 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:15:50.0326 4164 clr_optimization_v4.0.30319_32 - ok
18:15:50.0342 4164 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:15:50.0342 4164 CmBatt - ok
18:15:50.0404 4164 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:15:50.0404 4164 cmdide - ok
18:15:50.0451 4164 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
18:15:50.0466 4164 CNG - ok
18:15:50.0513 4164 [ 053F7C2624D5B0FF60F1F372C4AC2FE7 ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT32.sys
18:15:50.0529 4164 CnxtHdAudService - ok
18:15:50.0607 4164 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:15:50.0607 4164 Compbatt - ok
18:15:50.0638 4164 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:15:50.0638 4164 CompositeBus - ok
18:15:50.0654 4164 COMSysApp - ok
18:15:50.0685 4164 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:15:50.0685 4164 crcdisk - ok
18:15:50.0747 4164 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:15:50.0763 4164 CryptSvc - ok
18:15:50.0825 4164 [ 0F538DF1673E5216F3BAACB6911D9D0F ] CtAudDrv C:\Windows\system32\Drivers\CtAudDrv.sys
18:15:50.0825 4164 CtAudDrv - ok
18:15:50.0872 4164 [ 9A6CA307151505730DBFC91D97F01C7E ] CtClsFlt C:\Windows\system32\DRIVERS\CtClsFlt.sys
18:15:50.0872 4164 CtClsFlt - ok
18:15:50.0919 4164 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
18:15:50.0919 4164 DcomLaunch - ok
18:15:50.0981 4164 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
18:15:50.0981 4164 defragsvc - ok
18:15:51.0044 4164 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:15:51.0044 4164 DfsC - ok
18:15:51.0106 4164 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:15:51.0106 4164 Dhcp - ok
18:15:51.0168 4164 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
18:15:51.0168 4164 discache - ok
18:15:51.0184 4164 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:15:51.0200 4164 Disk - ok
18:15:51.0215 4164 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:15:51.0215 4164 Dnscache - ok
18:15:51.0262 4164 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
18:15:51.0262 4164 dot3svc - ok
18:15:51.0309 4164 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
18:15:51.0309 4164 DPS - ok
18:15:51.0371 4164 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:15:51.0371 4164 drmkaud - ok
18:15:51.0434 4164 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:15:51.0449 4164 DXGKrnl - ok
18:15:51.0512 4164 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
18:15:51.0512 4164 EapHost - ok
18:15:51.0636 4164 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
18:15:51.0714 4164 ebdrv - ok
18:15:51.0777 4164 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
18:15:51.0777 4164 EFS - ok
18:15:51.0870 4164 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:15:51.0886 4164 ehRecvr - ok
18:15:51.0917 4164 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
18:15:51.0933 4164 ehSched - ok
18:15:51.0980 4164 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:15:51.0995 4164 elxstor - ok
18:15:52.0026 4164 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:15:52.0026 4164 ErrDev - ok
18:15:52.0089 4164 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
18:15:52.0104 4164 EventSystem - ok
18:15:52.0136 4164 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
18:15:52.0136 4164 exfat - ok
18:15:52.0151 4164 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:15:52.0151 4164 fastfat - ok
18:15:52.0214 4164 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
18:15:52.0229 4164 Fax - ok
18:15:52.0245 4164 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:15:52.0245 4164 fdc - ok
18:15:52.0292 4164 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
18:15:52.0292 4164 fdPHost - ok
18:15:52.0307 4164 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
18:15:52.0307 4164 FDResPub - ok
18:15:52.0323 4164 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:15:52.0323 4164 FileInfo - ok
18:15:52.0338 4164 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:15:52.0338 4164 Filetrace - ok
18:15:52.0354 4164 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:15:52.0354 4164 flpydisk - ok
18:15:52.0385 4164 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:15:52.0385 4164 FltMgr - ok
18:15:52.0448 4164 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
18:15:52.0463 4164 FontCache - ok
18:15:52.0557 4164 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:15:52.0557 4164 FontCache3.0.0.0 - ok
18:15:52.0588 4164 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:15:52.0588 4164 FsDepends - ok
18:15:52.0619 4164 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:15:52.0619 4164 Fs_Rec - ok
18:15:52.0666 4164 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:15:52.0666 4164 fvevol - ok
18:15:52.0728 4164 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:15:52.0728 4164 gagp30kx - ok
18:15:52.0791 4164 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
18:15:52.0791 4164 gpsvc - ok
18:15:52.0978 4164 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
18:15:52.0978 4164 gupdate - ok
18:15:52.0994 4164 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
18:15:52.0994 4164 gupdatem - ok
18:15:53.0040 4164 [ A9D587E31DBEE3E9BD97FEFECE0BA874 ] hardlock C:\Windows\system32\drivers\hardlock.sys
18:15:53.0056 4164 hardlock - ok
18:15:53.0072 4164 hasplms - ok
18:15:53.0087 4164 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:15:53.0087 4164 hcw85cir - ok
18:15:53.0134 4164 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:15:53.0134 4164 HDAudBus - ok
18:15:53.0150 4164 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:15:53.0150 4164 HidBatt - ok
18:15:53.0165 4164 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:15:53.0165 4164 HidBth - ok
18:15:53.0196 4164 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:15:53.0196 4164 HidIr - ok
18:15:53.0243 4164 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
18:15:53.0243 4164 hidserv - ok
18:15:53.0290 4164 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
18:15:53.0290 4164 HidUsb - ok
18:15:53.0337 4164 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:15:53.0337 4164 hkmsvc - ok
18:15:53.0384 4164 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:15:53.0399 4164 HomeGroupListener - ok
18:15:53.0430 4164 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:15:53.0446 4164 HomeGroupProvider - ok
18:15:53.0477 4164 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:15:53.0477 4164 HpSAMD - ok
18:15:53.0555 4164 [ 210388FD8225B02BD83D77628AAE64A9 ] HsfXAudioService C:\Windows\system32\XAudio32.dll
18:15:53.0555 4164 HsfXAudioService - ok
18:15:53.0633 4164 [ 227C3BA25012752BB7450235392C719F ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
18:15:53.0664 4164 HSF_DPV - ok
18:15:53.0774 4164 [ 4DF5C76302DC2F8F3465966C8426A292 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
18:15:53.0774 4164 HSXHWAZL - ok
18:15:53.0836 4164 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:15:53.0836 4164 HTTP - ok
18:15:53.0898 4164 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:15:53.0898 4164 hwpolicy - ok
18:15:53.0945 4164 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:15:53.0945 4164 i8042prt - ok
18:15:54.0023 4164 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:15:54.0023 4164 iaStorV - ok
18:15:54.0117 4164 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:15:54.0132 4164 idsvc - ok
18:15:54.0413 4164 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
18:15:54.0632 4164 igfx - ok
18:15:54.0694 4164 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:15:54.0694 4164 iirsp - ok
18:15:54.0772 4164 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
18:15:54.0772 4164 IKEEXT - ok
18:15:54.0803 4164 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
18:15:54.0803 4164 intelide - ok
18:15:54.0850 4164 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:15:54.0850 4164 intelppm - ok
18:15:54.0912 4164 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:15:54.0912 4164 IPBusEnum - ok
18:15:54.0944 4164 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:15:54.0944 4164 IpFilterDriver - ok
18:15:55.0006 4164 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:15:55.0006 4164 iphlpsvc - ok
18:15:55.0053 4164 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:15:55.0053 4164 IPMIDRV - ok
18:15:55.0068 4164 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:15:55.0084 4164 IPNAT - ok
18:15:55.0131 4164 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:15:55.0131 4164 IRENUM - ok
18:15:55.0146 4164 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:15:55.0146 4164 isapnp - ok
18:15:55.0193 4164 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:15:55.0209 4164 iScsiPrt - ok
18:15:55.0224 4164 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:15:55.0224 4164 kbdclass - ok
18:15:55.0256 4164 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:15:55.0256 4164 kbdhid - ok
18:15:55.0474 4164 Kernel Detective - ok
18:15:55.0505 4164 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
18:15:55.0505 4164 KeyIso - ok
18:15:55.0552 4164 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:15:55.0552 4164 KSecDD - ok
18:15:55.0599 4164 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:15:55.0599 4164 KSecPkg - ok
18:15:55.0661 4164 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
18:15:55.0661 4164 KtmRm - ok
18:15:55.0708 4164 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
18:15:55.0708 4164 LanmanServer - ok
18:15:55.0755 4164 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:15:55.0770 4164 LanmanWorkstation - ok
18:15:55.0817 4164 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:15:55.0817 4164 lltdio - ok
18:15:55.0864 4164 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:15:55.0864 4164 lltdsvc - ok
18:15:55.0895 4164 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
18:15:55.0895 4164 lmhosts - ok
18:15:56.0004 4164 [ 2098AF12149789FA6608422C8796F77C ] LNSUSvc C:\Program Files\IBM\Lotus\Notes\SUService.exe
18:15:56.0004 4164 LNSUSvc - ok
18:15:56.0207 4164 [ E4FA829273FDF5BD20FC9804FD5F9C20 ] Lotus Notes Diagnostics C:\Program Files\IBM\Lotus\Notes\nsd.exe
18:15:56.0332 4164 Lotus Notes Diagnostics - ok
18:15:56.0379 4164 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:15:56.0379 4164 LSI_FC - ok
18:15:56.0426 4164 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:15:56.0426 4164 LSI_SAS - ok
18:15:56.0441 4164 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:15:56.0457 4164 LSI_SAS2 - ok
18:15:56.0472 4164 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:15:56.0472 4164 LSI_SCSI - ok
18:15:56.0519 4164 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
18:15:56.0519 4164 luafv - ok
18:15:56.0582 4164 [ 7521C0C58EE91BE90B6CC33E792D10C7 ] LVRS C:\Windows\system32\DRIVERS\lvrs.sys
18:15:56.0597 4164 LVRS - ok
18:15:56.0738 4164 [ 5BC80451109A8DD7F2DDD35BCE2929A3 ] LVUVC C:\Windows\system32\DRIVERS\lvuvc.sys
18:15:56.0894 4164 LVUVC - ok
18:15:56.0956 4164 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:15:56.0956 4164 Mcx2Svc - ok
18:15:56.0972 4164 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
18:15:56.0972 4164 mdmxsdk - ok
18:15:57.0034 4164 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:15:57.0034 4164 megasas - ok
18:15:57.0065 4164 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:15:57.0065 4164 MegaSR - ok
18:15:57.0112 4164 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
18:15:57.0128 4164 MMCSS - ok
18:15:57.0128 4164 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
18:15:57.0128 4164 Modem - ok
18:15:57.0159 4164 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:15:57.0159 4164 monitor - ok
18:15:57.0190 4164 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
18:15:57.0190 4164 mouclass - ok
18:15:57.0221 4164 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:15:57.0221 4164 mouhid - ok
18:15:57.0268 4164 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:15:57.0268 4164 mountmgr - ok
18:15:57.0346 4164 [ D993BEA500E7382DC4E760BF4F35EFCB ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
18:15:57.0346 4164 MpFilter - ok
18:15:57.0362 4164 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
18:15:57.0362 4164 mpio - ok
18:15:57.0564 4164 [ A69630D039C38018689190234F866D77 ] MpKsl2f01f905 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1D655C2B-EEE1-4593-95D0-FC6F9F111A7D}\MpKsl2f01f905.sys
18:15:57.0564 4164 MpKsl2f01f905 - ok
18:15:57.0611 4164 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:15:57.0611 4164 mpsdrv - ok
18:15:57.0674 4164 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:15:57.0674 4164 MpsSvc - ok
18:15:57.0736 4164 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:15:57.0736 4164 MRxDAV - ok
18:15:57.0814 4164 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:15:57.0814 4164 mrxsmb - ok
18:15:57.0861 4164 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:15:57.0876 4164 mrxsmb10 - ok
18:15:57.0892 4164 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:15:57.0892 4164 mrxsmb20 - ok
18:15:57.0939 4164 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
18:15:57.0939 4164 msahci - ok
18:15:57.0986 4164 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:15:57.0986 4164 msdsm - ok
18:15:58.0001 4164 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
18:15:58.0017 4164 MSDTC - ok
18:15:58.0064 4164 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:15:58.0064 4164 Msfs - ok
18:15:58.0064 4164 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:15:58.0064 4164 mshidkmdf - ok
18:15:58.0110 4164 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:15:58.0110 4164 msisadrv - ok
18:15:58.0173 4164 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:15:58.0173 4164 MSiSCSI - ok
18:15:58.0188 4164 msiserver - ok
18:15:58.0220 4164 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:15:58.0220 4164 MSKSSRV - ok
18:15:58.0298 4164 [ 24516BF4E12A46CB67302E2CDCB8CDDF ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
18:15:58.0298 4164 MsMpSvc - ok
18:15:58.0313 4164 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:15:58.0313 4164 MSPCLOCK - ok
18:15:58.0329 4164 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:15:58.0329 4164 MSPQM - ok
18:15:58.0360 4164 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:15:58.0360 4164 MsRPC - ok
18:15:58.0407 4164 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:15:58.0422 4164 mssmbios - ok
18:15:58.0438 4164 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:15:58.0438 4164 MSTEE - ok
18:15:58.0454 4164 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:15:58.0454 4164 MTConfig - ok
18:15:58.0485 4164 [ FF54EA1617D15711690D5EF054512C21 ] Multi-user Cleanup Service C:\Program Files\IBM\Lotus\Notes\ntmulti.exe
18:15:58.0485 4164 Multi-user Cleanup Service - ok
18:15:58.0516 4164 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
18:15:58.0547 4164 Mup - ok
18:15:58.0625 4164 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
18:15:58.0625 4164 napagent - ok
18:15:58.0688 4164 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:15:58.0703 4164 NativeWifiP - ok
18:15:58.0781 4164 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:15:58.0781 4164 NDIS - ok
18:15:58.0844 4164 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:15:58.0844 4164 NdisCap - ok
18:15:58.0890 4164 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:15:58.0890 4164 NdisTapi - ok
18:15:58.0937 4164 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:15:58.0937 4164 Ndisuio - ok
18:15:58.0984 4164 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:15:58.0984 4164 NdisWan - ok
18:15:59.0031 4164 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:15:59.0031 4164 NDProxy - ok
18:15:59.0109 4164 [ 90EB97C8DBF11BB0016C51946AC5ECD6 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
18:15:59.0109 4164 Net Driver HPZ12 - ok
18:15:59.0156 4164 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:15:59.0171 4164 NetBIOS - ok
18:15:59.0218 4164 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:15:59.0218 4164 NetBT - ok
18:15:59.0234 4164 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
18:15:59.0234 4164 Netlogon - ok
18:15:59.0312 4164 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
18:15:59.0312 4164 Netman - ok
18:15:59.0405 4164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:15:59.0421 4164 NetMsmqActivator - ok
18:15:59.0421 4164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:15:59.0421 4164 NetPipeActivator - ok
18:15:59.0452 4164 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
18:15:59.0452 4164 netprofm - ok
18:15:59.0483 4164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:15:59.0483 4164 NetTcpActivator - ok
18:15:59.0483 4164 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:15:59.0483 4164 NetTcpPortSharing - ok
18:15:59.0561 4164 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:15:59.0561 4164 nfrd960 - ok
18:15:59.0639 4164 [ B52F26BADE7D7E4A79706E3FD91834CD ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
18:15:59.0639 4164 NisDrv - ok
18:15:59.0686 4164 [ 290C0D4C4889398797F8DF3BE00B9698 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
18:15:59.0686 4164 NisSrv - ok
18:15:59.0733 4164 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:15:59.0748 4164 NlaSvc - ok
18:15:59.0795 4164 [ CFE3462A9E94A57DCD9676F6B7FE7F67 ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
18:15:59.0795 4164 nmwcd - ok
18:15:59.0842 4164 [ 8F2A94F991F8C73CEC26B4B5620D1EDC ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
18:15:59.0858 4164 nmwcdc - ok
18:15:59.0889 4164 [ 99145C5D4B6C4D6F5CE83EE6ABFFE294 ] nmwcdnsu C:\Windows\system32\drivers\nmwcdnsu.sys
18:15:59.0889 4164 nmwcdnsu - ok
18:15:59.0951 4164 [ FAEE7B61C6885B091CEC1FF06DA2E1AB ] nmwcdnsuc C:\Windows\system32\drivers\nmwcdnsuc.sys
18:15:59.0951 4164 nmwcdnsuc - ok
18:15:59.0967 4164 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:15:59.0967 4164 Npfs - ok
18:15:59.0982 4164 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
18:15:59.0998 4164 nsi - ok
18:15:59.0998 4164 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:15:59.0998 4164 nsiproxy - ok
18:16:00.0076 4164 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:16:00.0092 4164 Ntfs - ok
18:16:00.0138 4164 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
18:16:00.0138 4164 Null - ok
18:16:00.0185 4164 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:16:00.0185 4164 nvraid - ok
18:16:00.0232 4164 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:16:00.0232 4164 nvstor - ok
18:16:00.0279 4164 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:16:00.0279 4164 nv_agp - ok
18:16:00.0404 4164 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:16:00.0419 4164 odserv - ok
18:16:00.0482 4164 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:16:00.0482 4164 ohci1394 - ok
18:16:00.0544 4164 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:16:00.0560 4164 ose - ok
18:16:00.0606 4164 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:16:00.0622 4164 p2pimsvc - ok
18:16:00.0684 4164 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
18:16:00.0684 4164 p2psvc - ok
18:16:00.0747 4164 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:16:00.0747 4164 Parport - ok
18:16:00.0794 4164 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:16:00.0794 4164 partmgr - ok
18:16:00.0809 4164 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:16:00.0809 4164 Parvdm - ok
18:16:00.0825 4164 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:16:00.0840 4164 PcaSvc - ok
18:16:00.0918 4164 [ FD2041E9BA03DB7764B2248F02475079 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
18:16:00.0918 4164 pccsmcfd - ok
18:16:00.0934 4164 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
18:16:00.0934 4164 pci - ok
18:16:00.0981 4164 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
18:16:00.0981 4164 pciide - ok
18:16:00.0996 4164 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:16:01.0012 4164 pcmcia - ok
18:16:01.0028 4164 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
18:16:01.0028 4164 pcw - ok
18:16:01.0074 4164 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:16:01.0074 4164 PEAUTH - ok
18:16:01.0152 4164 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
18:16:01.0199 4164 pla - ok
18:16:01.0262 4164 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:16:01.0277 4164 PlugPlay - ok
18:16:01.0324 4164 [ 2B85237F904C5BDF7AD386F0EDE19BD3 ] PMEM C:\Windows\system32\drivers\pmemnt.sys
18:16:01.0324 4164 PMEM - ok
18:16:01.0355 4164 [ F0EFAF6000E9FCBD77F769D527CE5F9D ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
18:16:01.0355 4164 Pml Driver HPZ12 - ok
18:16:01.0402 4164 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:16:01.0402 4164 PNRPAutoReg - ok
18:16:01.0418 4164 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:16:01.0433 4164 PNRPsvc - ok
18:16:01.0480 4164 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:16:01.0480 4164 PolicyAgent - ok
18:16:01.0511 4164 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
18:16:01.0511 4164 Power - ok
18:16:01.0574 4164 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:16:01.0574 4164 PptpMiniport - ok
18:16:01.0589 4164 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:16:01.0589 4164 Processor - ok
18:16:01.0636 4164 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
18:16:01.0636 4164 ProfSvc - ok
18:16:01.0652 4164 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:16:01.0667 4164 ProtectedStorage - ok
18:16:01.0714 4164 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:16:01.0714 4164 Psched - ok
18:16:01.0761 4164 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys
18:16:01.0776 4164 PxHelp20 - ok
18:16:01.0823 4164 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:16:01.0870 4164 ql2300 - ok
18:16:01.0886 4164 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:16:01.0886 4164 ql40xx - ok
18:16:01.0932 4164 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
18:16:01.0932 4164 QWAVE - ok
18:16:01.0948 4164 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:16:01.0948 4164 QWAVEdrv - ok
18:16:01.0979 4164 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:16:01.0979 4164 RasAcd - ok
18:16:02.0042 4164 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:16:02.0042 4164 RasAgileVpn - ok
18:16:02.0057 4164 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
18:16:02.0057 4164 RasAuto - ok
18:16:02.0073 4164 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:16:02.0073 4164 Rasl2tp - ok
18:16:02.0135 4164 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
18:16:02.0135 4164 RasMan - ok
18:16:02.0151 4164 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:16:02.0151 4164 RasPppoe - ok
18:16:02.0198 4164 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:16:02.0198 4164 RasSstp - ok
18:16:02.0244 4164 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:16:02.0244 4164 rdbss - ok
18:16:02.0260 4164 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:16:02.0276 4164 rdpbus - ok
18:16:02.0322 4164 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:16:02.0322 4164 RDPCDD - ok
18:16:02.0338 4164 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:16:02.0338 4164 RDPENCDD - ok
18:16:02.0369 4164 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:16:02.0369 4164 RDPREFMP - ok
18:16:02.0400 4164 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:16:02.0416 4164 RDPWD - ok
18:16:02.0463 4164 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:16:02.0463 4164 rdyboost - ok
18:16:02.0494 4164 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
18:16:02.0510 4164 RemoteAccess - ok
18:16:02.0556 4164 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:16:02.0556 4164 RemoteRegistry - ok
18:16:02.0603 4164 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
18:16:02.0603 4164 RFCOMM - ok
18:16:02.0650 4164 [ DF672613FBBCD58C38BB0BC2694BCFB0 ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
18:16:02.0650 4164 rimmptsk - ok
18:16:02.0697 4164 [ AF213955C4D952C914620E8DB0CD0CF7 ] rimspci C:\Windows\system32\DRIVERS\rimspe86.sys
18:16:02.0697 4164 rimspci - ok
18:16:02.0744 4164 [ 9BFB54D3559F2FF7301271D29D383564 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
18:16:02.0744 4164 rimsptsk - ok
18:16:02.0759 4164 [ 6978DECC2C38C5CE10A8B0F2B12F4451 ] risdpcie C:\Windows\system32\DRIVERS\risdpe86.sys
18:16:02.0759 4164 risdpcie - ok
18:16:02.0790 4164 [ DCB87DA83CC1010CBC9FC4DC9E395BBC ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys
18:16:02.0790 4164 rismxdp - ok
18:16:02.0790 4164 [ 764C1F3453E779724BA647327DE7DDD4 ] rixdpcie C:\Windows\system32\DRIVERS\rixdpe86.sys
18:16:02.0790 4164 rixdpcie - ok
18:16:02.0837 4164 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:16:02.0837 4164 RpcEptMapper - ok
18:16:02.0900 4164 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
18:16:02.0900 4164 RpcLocator - ok
18:16:02.0915 4164 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
18:16:02.0931 4164 RpcSs - ok
18:16:02.0978 4164 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:16:02.0978 4164 rspndr - ok
18:16:03.0040 4164 [ D5EDE44CA85899E0478208C8413C1C31 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
18:16:03.0056 4164 RTL8167 - ok
18:16:03.0056 4164 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
18:16:03.0056 4164 SamSs - ok
18:16:03.0134 4164 [ 39763504067962108505BFF25F024345 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
18:16:03.0134 4164 SASDIFSV - ok
18:16:03.0212 4164 [ 77B9FC20084B48408AD3E87570EB4A85 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
18:16:03.0212 4164 SASKUTIL - ok
18:16:03.0243 4164 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:16:03.0258 4164 sbp2port - ok
18:16:03.0290 4164 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:16:03.0305 4164 SCardSvr - ok
18:16:03.0336 4164 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:16:03.0336 4164 scfilter - ok
18:16:03.0399 4164 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
18:16:03.0414 4164 Schedule - ok
18:16:03.0461 4164 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:16:03.0461 4164 SCPolicySvc - ok
18:16:03.0508 4164 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:16:03.0508 4164 SDRSVC - ok
18:16:03.0617 4164 [ CC781378E7EDA615D2CDCA3B17829FA4 ] SeaPort C:\Program Files\Microsoft\BingBar\SeaPort.EXE
18:16:03.0617 4164 SeaPort - ok
18:16:03.0680 4164 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:16:03.0680 4164 secdrv - ok
18:16:03.0726 4164 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
18:16:03.0726 4164 seclogon - ok
18:16:03.0758 4164 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
18:16:03.0758 4164 SENS - ok
18:16:03.0789 4164 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:16:03.0804 4164 SensrSvc - ok
18:16:03.0820 4164 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:16:03.0820 4164 Serenum - ok
18:16:03.0836 4164 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:16:03.0836 4164 Serial - ok
18:16:03.0882 4164 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:16:03.0882 4164 sermouse - ok
18:16:04.0007 4164 [ 8C1F87F5FDD92229D1754B98F073913F ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
18:16:04.0007 4164 ServiceLayer - ok
18:16:04.0054 4164 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
18:16:04.0054 4164 SessionEnv - ok
18:16:04.0101 4164 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:16:04.0101 4164 sffdisk - ok
18:16:04.0116 4164 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:16:04.0132 4164 sffp_mmc - ok
18:16:04.0132 4164 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:16:04.0132 4164 sffp_sd - ok
18:16:04.0179 4164 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:16:04.0179 4164 sfloppy - ok
18:16:04.0241 4164 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:16:04.0241 4164 SharedAccess - ok
18:16:04.0304 4164 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:16:04.0304 4164 ShellHWDetection - ok
18:16:04.0350 4164 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:16:04.0350 4164 sisagp - ok
18:16:04.0382 4164 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:16:04.0397 4164 SiSRaid2 - ok
18:16:04.0413 4164 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:16:04.0413 4164 SiSRaid4 - ok
18:16:04.0522 4164 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
18:16:04.0522 4164 SkypeUpdate - ok
18:16:04.0553 4164 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:16:04.0553 4164 Smb - ok
18:16:04.0631 4164 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:16:04.0631 4164 SNMPTRAP - ok
18:16:04.0647 4164 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
18:16:04.0647 4164 spldr - ok
18:16:04.0709 4164 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
18:16:04.0709 4164 Spooler - ok
18:16:04.0834 4164 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
18:16:04.0912 4164 sppsvc - ok
18:16:04.0959 4164 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:16:04.0959 4164 sppuinotify - ok
18:16:05.0021 4164 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:16:05.0021 4164 srv - ok
18:16:05.0052 4164 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:16:05.0052 4164 srv2 - ok
18:16:05.0084 4164 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:16:05.0084 4164 srvnet - ok
18:16:05.0130 4164 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:16:05.0130 4164 SSDPSRV - ok
18:16:05.0146 4164 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:16:05.0162 4164 SstpSvc - ok
18:16:05.0208 4164 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:16:05.0208 4164 stexstor - ok
18:16:05.0255 4164 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
18:16:05.0271 4164 StiSvc - ok
18:16:05.0333 4164 [ E476C66713C842F58E61A95826ED1D57 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
18:16:05.0333 4164 stllssvr - ok
18:16:05.0380 4164 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
18:16:05.0380 4164 swenum - ok
18:16:05.0411 4164 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
18:16:05.0427 4164 swprv - ok
18:16:05.0489 4164 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
18:16:05.0520 4164 SysMain - ok
18:16:05.0567 4164 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:16:05.0567 4164 TabletInputService - ok
18:16:05.0614 4164 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
18:16:05.0614 4164 TapiSrv - ok
18:16:05.0661 4164 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
18:16:05.0661 4164 TBS - ok
18:16:05.0723 4164 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:16:05.0754 4164 Tcpip - ok
18:16:05.0786 4164 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:16:05.0801 4164 TCPIP6 - ok
18:16:05.0848 4164 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:16:05.0848 4164 tcpipreg - ok
18:16:05.0895 4164 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:16:05.0895 4164 TDPIPE - ok
18:16:05.0942 4164 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:16:05.0942 4164 TDTCP - ok
18:16:05.0988 4164 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:16:05.0988 4164 tdx - ok
18:16:06.0004 4164 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:16:06.0020 4164 TermDD - ok
18:16:06.0082 4164 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
18:16:06.0082 4164 TermService - ok
18:16:06.0129 4164 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
18:16:06.0129 4164 Themes - ok
18:16:06.0144 4164 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
18:16:06.0144 4164 THREADORDER - ok
18:16:06.0238 4164 [ AC88D258F20909EEB91796F490CFBB73 ] TOSHIBA Bluetooth Service c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
18:16:06.0238 4164 TOSHIBA Bluetooth Service - ok
18:16:06.0300 4164 [ 90AFA1A4451BBBEE87C9F18A665D8121 ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys
18:16:06.0316 4164 tosporte - ok
18:16:06.0363 4164 [ B168B345FB7073930C31E0D8B85E8353 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys
18:16:06.0363 4164 tosrfbd - ok
18:16:06.0378 4164 [ 74392BAB3F0D4810DA8436EC79D6955D ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys
18:16:06.0394 4164 tosrfbnp - ok
18:16:06.0441 4164 [ 1AD9EB1B5ABD0AEEE4084C8153476F1E ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys
18:16:06.0441 4164 Tosrfcom - ok
18:16:06.0488 4164 [ A72A3473180F378CC07D342803FFD580 ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys
18:16:06.0488 4164 Tosrfhid - ok
18:16:06.0519 4164 [ B2A1A6538245FD69578224BBF2FD4677 ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys
18:16:06.0519 4164 tosrfnds - ok
18:16:06.0566 4164 [ 97529D04178BF604C62C5BE4B8BB2129 ] Tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys
18:16:06.0566 4164 Tosrfusb - ok
18:16:06.0612 4164 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
18:16:06.0612 4164 TrkWks - ok
18:16:06.0706 4164 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:16:06.0706 4164 TrustedInstaller - ok
18:16:06.0753 4164 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:16:06.0768 4164 tssecsrv - ok
18:16:06.0815 4164 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:16:06.0815 4164 TsUsbFlt - ok
18:16:06.0878 4164 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:16:06.0878 4164 tunnel - ok
18:16:06.0924 4164 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:16:06.0924 4164 uagp35 - ok
18:16:06.0971 4164 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:16:06.0971 4164 udfs - ok
18:16:07.0034 4164 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:16:07.0034 4164 UI0Detect - ok
18:16:07.0065 4164 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:16:07.0065 4164 uliagpkx - ok
18:16:07.0112 4164 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
18:16:07.0143 4164 umbus - ok
18:16:07.0190 4164 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:16:07.0190 4164 UmPass - ok
18:16:07.0283 4164 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
18:16:07.0283 4164 UMVPFSrv - ok
18:16:07.0314 4164 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
18:16:07.0314 4164 upnphost - ok
18:16:07.0361 4164 [ EC01DA44B090D2651FC032C8B9257232 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
18:16:07.0361 4164 upperdev - ok
18:16:07.0424 4164 [ 1D9F2BD026E8E2D45033A4DF3F16B78C ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
18:16:07.0424 4164 usbaudio - ok
18:16:07.0470 4164 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
18:16:07.0470 4164 usbccgp - ok
18:16:07.0502 4164 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:16:07.0517 4164 usbcir - ok
18:16:07.0564 4164 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:16:07.0564 4164 usbehci - ok
18:16:07.0595 4164 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:16:07.0611 4164 usbhub - ok
18:16:07.0642 4164 [ A6FB7957EA7AFB1165991E54CE934B74 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
18:16:07.0658 4164 usbohci - ok
18:16:07.0689 4164 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:16:07.0689 4164 usbprint - ok
18:16:07.0751 4164 [ 31181DE6190B39FC8007DFFD1A48FFD6 ] usbser C:\Windows\system32\drivers\usbser.sys
18:16:07.0751 4164 usbser - ok
18:16:07.0782 4164 [ 4ABD37CFBD710E64F01F9DA8710C73F7 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
18:16:07.0782 4164 UsbserFilt - ok
18:16:07.0829 4164 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:16:07.0829 4164 USBSTOR - ok
18:16:07.0876 4164 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
18:16:07.0876 4164 usbuhci - ok
18:16:07.0954 4164 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
18:16:07.0954 4164 usbvideo - ok
18:16:07.0985 4164 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
18:16:07.0985 4164 UxSms - ok
18:16:08.0001 4164 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
18:16:08.0001 4164 VaultSvc - ok
18:16:08.0063 4164 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
18:16:08.0063 4164 vdrvroot - ok
18:16:08.0126 4164 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
18:16:08.0141 4164 vds - ok
18:16:08.0188 4164 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
18:16:08.0188 4164 vga - ok
18:16:08.0204 4164 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
18:16:08.0204 4164 VgaSave - ok
18:16:08.0250 4164 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
18:16:08.0250 4164 vhdmp - ok
18:16:08.0282 4164 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
18:16:08.0282 4164 viaagp - ok
18:16:08.0297 4164 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
18:16:08.0297 4164 ViaC7 - ok
18:16:08.0344 4164 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
18:16:08.0344 4164 viaide - ok
18:16:08.0360 4164 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
18:16:08.0360 4164 volmgr - ok
18:16:08.0391 4164 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
18:16:08.0391 4164 volmgrx - ok
18:16:08.0438 4164 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
18:16:08.0453 4164 volsnap - ok
18:16:08.0484 4164 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
18:16:08.0484 4164 vsmraid - ok
18:16:08.0562 4164 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
18:16:08.0594 4164 VSS - ok
18:16:08.0609 4164 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
18:16:08.0609 4164 vwifibus - ok
18:16:08.0672 4164 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
18:16:08.0672 4164 vwififlt - ok
18:16:08.0734 4164 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
18:16:08.0734 4164 vwifimp - ok
18:16:08.0781 4164 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
18:16:08.0796 4164 W32Time - ok
18:16:08.0812 4164 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
18:16:08.0812 4164 WacomPen - ok
18:16:08.0874 4164 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
18:16:08.0874 4164 WANARP - ok
18:16:08.0874 4164 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
18:16:08.0874 4164 Wanarpv6 - ok
18:16:08.0952 4164 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
18:16:08.0984 4164 WatAdminSvc - ok
18:16:09.0062 4164 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
18:16:09.0093 4164 wbengine - ok
18:16:09.0140 4164 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
18:16:09.0140 4164 WbioSrvc - ok
18:16:09.0202 4164 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
18:16:09.0202 4164 wcncsvc - ok
18:16:09.0249 4164 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
18:16:09.0249 4164 WcsPlugInService - ok
18:16:09.0296 4164 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
18:16:09.0296 4164 Wd - ok
18:16:09.0327 4164 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
18:16:09.0342 4164 Wdf01000 - ok
18:16:09.0374 4164 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
18:16:09.0374 4164 WdiServiceHost - ok
18:16:09.0374 4164 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
18:16:09.0374 4164 WdiSystemHost - ok
18:16:09.0436 4164 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
18:16:09.0436 4164 WebClient - ok
18:16:09.0452 4164 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
18:16:09.0452 4164 Wecsvc - ok
18:16:09.0483 4164 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
18:16:09.0483 4164 wercplsupport - ok
18:16:09.0514 4164 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
18:16:09.0530 4164 WerSvc - ok
18:16:09.0545 4164 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
18:16:09.0545 4164 WfpLwf - ok
18:16:09.0592 4164 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
18:16:09.0592 4164 WIMMount - ok
18:16:09.0654 4164 [ 8B976D4CA270110111DF4F313DA0E6E8 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
18:16:09.0654 4164 winachsf - ok
18:16:09.0748 4164 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
18:16:09.0764 4164 WinDefend - ok
18:16:09.0779 4164 WinHttpAutoProxySvc - ok
18:16:09.0873 4164 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
18:16:09.0873 4164 Winmgmt - ok
18:16:09.0935 4164 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
18:16:09.0966 4164 WinRM - ok
18:16:10.0029 4164 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
18:16:10.0029 4164 WinUsb - ok
18:16:10.0091 4164 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
18:16:10.0122 4164 Wlansvc - ok
18:16:10.0247 4164 [ 0A70F4022EC2E14C159EFC4F69AA2477 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:16:10.0294 4164 wlidsvc - ok
18:16:10.0372 4164 [ 3CBCE0C65CC433121001C1108B511D13 ] wltrysvc C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
18:16:10.0372 4164 wltrysvc - ok
18:16:10.0403 4164 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
18:16:10.0403 4164 WmiAcpi - ok
18:16:10.0466 4164 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
18:16:10.0466 4164 wmiApSrv - ok
18:16:10.0575 4164 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
18:16:10.0606 4164 WMPNetworkSvc - ok
18:16:10.0653 4164 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
18:16:10.0653 4164 WPCSvc - ok
18:16:10.0700 4164 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
18:16:10.0700 4164 WPDBusEnum - ok
18:16:10.0746 4164 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
18:16:10.0746 4164 ws2ifsl - ok
18:16:10.0762 4164 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\System32\wscsvc.dll
18:16:10.0762 4164 wscsvc - ok
18:16:10.0824 4164 [ 553F6CCD7C58EB98D4A8FBDAF283D7A9 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
18:16:10.0840 4164 WSDPrintDevice - ok
18:16:10.0856 4164 WSearch - ok
18:16:10.0965 4164 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
18:16:11.0027 4164 wuauserv - ok
18:16:11.0043 4164 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
18:16:11.0043 4164 WudfPf - ok
18:16:11.0105 4164 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
18:16:11.0121 4164 WUDFRd - ok
18:16:11.0168 4164 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
18:16:11.0183 4164 wudfsvc - ok
18:16:11.0230 4164 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
18:16:11.0230 4164 WwanSvc - ok
18:16:11.0277 4164 [ 894F963BE999BA9DB5AAC3AED55B115D ] XAudio C:\Windows\system32\DRIVERS\XAudio32.sys
18:16:11.0277 4164 XAudio - ok
18:16:11.0308 4164 ================ Scan global ===============================
18:16:11.0386 4164 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
18:16:11.0417 4164 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
18:16:11.0433 4164 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
18:16:11.0464 4164 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
18:16:11.0511 4164 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
18:16:11.0526 4164 [Global] - ok
18:16:11.0526 4164 ================ Scan MBR ==================================
18:16:11.0542 4164 [ F1EA7E5C20FECD2CDFA22358FD2FF8BA ] \Device\Harddisk0\DR0
18:16:11.0542 4164 Suspicious mbr (Forged): \Device\Harddisk0\DR0
18:16:11.0573 4164 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - infected
18:16:11.0573 4164 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0)
18:16:11.0573 4164 ================ Scan VBR ==================================
18:16:11.0604 4164 [ 5EB80AB35ACD4479263445A63ED60943 ] \Device\Harddisk0\DR0\Partition1
18:16:11.0604 4164 \Device\Harddisk0\DR0\Partition1 - ok
18:16:11.0620 4164 [ 333A2BA39B3F3A71D9CFAD99E502FD02 ] \Device\Harddisk0\DR0\Partition2
18:16:11.0620 4164 \Device\Harddisk0\DR0\Partition2 - ok
18:16:11.0620 4164 ============================================================
18:16:11.0620 4164 Scan finished
18:16:11.0620 4164 ============================================================
18:16:11.0651 5648 Detected object count: 2
18:16:11.0651 5648 Actual detected object count: 2
18:16:55.0987 5648 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
18:16:55.0987 5648 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
18:16:56.0595 5648 \Device\Harddisk0\DR0\# - copied to quarantine
18:16:56.0673 5648 \Device\Harddisk0\DR0 - copied to quarantine
18:16:57.0359 5648 \Device\Harddisk0\DR0\TDLFS\mbr - copied to quarantine
18:16:57.0422 5648 \Device\Harddisk0\DR0\TDLFS\vbr - copied to quarantine
18:16:57.0469 5648 \Device\Harddisk0\DR0\TDLFS\bid - copied to quarantine
18:16:57.0515 5648 \Device\Harddisk0\DR0\TDLFS\affid - copied to quarantine
18:16:57.0578 5648 \Device\Harddisk0\DR0\TDLFS\boot - copied to quarantine
18:16:57.0671 5648 \Device\Harddisk0\DR0\TDLFS\cmd32 - copied to quarantine
18:16:57.0781 5648 \Device\Harddisk0\DR0\TDLFS\cmd64 - copied to quarantine
18:16:57.0937 5648 \Device\Harddisk0\DR0\TDLFS\dbg32 - copied to quarantine
18:16:57.0999 5648 \Device\Harddisk0\DR0\TDLFS\dbg64 - copied to quarantine
18:16:58.0108 5648 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
18:16:58.0186 5648 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
18:16:58.0217 5648 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
18:16:58.0233 5648 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
18:16:58.0295 5648 \Device\Harddisk0\DR0\TDLFS\main - copied to quarantine
18:16:58.0311 5648 \Device\Harddisk0\DR0\TDLFS\subid - copied to quarantine
18:16:58.0311 5648 \Device\Harddisk0\DR0\TDLFS\tdi32 - copied to quarantine
18:16:58.0405 5648 \Device\Harddisk0\DR0\TDLFS\tdi64 - copied to quarantine
18:16:58.0436 5648 \Device\Harddisk0\DR0\TDLFS\main1 - copied to quarantine
18:16:58.0498 5648 \Device\Harddisk0\DR0 - processing error
18:17:16.0501 5648 \Device\Harddisk0\DR0 - will be restored on reboot
18:17:16.0516 5648 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - User select action: Cure Restore
18:20:31.0033 4364 Deinitialize success


After the restart, the program started another scan it just detected one threat - AKAMAI which I moved to quarantine. Do you want that log as well?



I will post the aswMBR scan separately below.

#9 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 24 September 2012 - 12:59 PM

aswMBR scan log:

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-24 18:28:58
-----------------------------
18:28:58.445 OS Version: Windows 6.1.7601 Service Pack 1
18:28:58.445 Number of processors: 2 586 0x170A
18:28:58.445 ComputerName: NAVEEN-LAPTOP UserName: Pool Laptop
18:28:59.724 Initialize success
18:30:39.611 AVAST engine defs: 12092400
18:32:11.199 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
18:32:11.199 Disk 0 Vendor: WDC_WD1600BEVT-75A23T0 01.01A01 Size: 152627MB BusType: 11
18:32:11.230 Disk 0 MBR read successfully
18:32:11.246 Disk 0 MBR scan
18:32:11.246 Disk 0 Windows XP default MBR code
18:32:11.246 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
18:32:11.277 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 80325
18:32:11.324 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 137573 MB offset 30800325
18:32:11.386 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 10 MB offset 312551424
18:32:11.386 Disk 0 scanning sectors +312571904
18:32:11.449 Disk 0 scanning C:\Windows\system32\drivers
18:32:46.658 Service scanning
18:33:17.640 Service MpKsl685f8e02 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1D655C2B-EEE1-4593-95D0-FC6F9F111A7D}\MpKsl685f8e02.sys **LOCKED** 32
18:33:44.253 Modules scanning
18:33:56.858 Disk 0 trace - called modules:
18:33:56.874 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys ndis.sys bcmwl6.sys
18:33:56.889 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x864fc530]
18:33:56.889 3 CLASSPNP.SYS[8c3b859e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x863d2908]
18:33:57.435 AVAST engine scan C:\Windows
18:34:00.415 AVAST engine scan C:\Windows\system32
18:39:57.072 AVAST engine scan C:\Windows\system32\drivers
18:40:23.186 AVAST engine scan C:\Users\Pool Laptop
18:44:33.504 File: C:\Users\Pool Laptop\AppData\Local\Temp\jure83852.exe **INFECTED** Win32:FakeSysdefs-D [Trj]
18:54:22.624 AVAST engine scan C:\ProgramData
18:58:23.660 Scan finished successfully
18:58:43.191 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
18:58:43.207 The log file has been saved successfully to "C:\aswMBR.txt"

#10 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 24 September 2012 - 08:16 PM

Good work.

Please run ASWMBR once again and post the log along with ESET log

#11 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 25 September 2012 - 04:27 PM

Below is the latest aswMBR scan.


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-25 21:57:59
-----------------------------
21:57:59.730 OS Version: Windows 6.1.7601 Service Pack 1
21:57:59.730 Number of processors: 2 586 0x170A
21:57:59.730 ComputerName: NAVEEN-LAPTOP UserName: Pool Laptop
21:58:01.508 Initialize success
21:58:14.175 AVAST engine defs: 12092400
21:58:20.244 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:58:20.244 Disk 0 Vendor: WDC_WD1600BEVT-75A23T0 01.01A01 Size: 152627MB BusType: 11
21:58:20.259 Disk 0 MBR read successfully
21:58:20.259 Disk 0 MBR scan
21:58:20.275 Disk 0 Windows XP default MBR code
21:58:20.275 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
21:58:20.291 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 80325
21:58:20.353 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 137573 MB offset 30800325
21:58:20.415 Disk 0 Partition 4 00 17 Hidd HPFS/NTFS NTFS 10 MB offset 312551424
21:58:20.431 Disk 0 scanning sectors +312571904
21:58:20.525 Disk 0 scanning C:\Windows\system32\drivers
21:58:53.347 Service scanning
21:59:23.134 Service MpKsl48072f61 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1D655C2B-EEE1-4593-95D0-FC6F9F111A7D}\MpKsl48072f61.sys **LOCKED** 32
21:59:53.648 Modules scanning
22:00:16.840 Disk 0 trace - called modules:
22:00:16.860 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll PCIIDEX.SYS msahci.sys
22:00:16.860 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x864f7510]
22:00:16.860 3 CLASSPNP.SYS[8c59959e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x8600d908]
22:00:19.294 AVAST engine scan C:\Windows
22:00:22.674 AVAST engine scan C:\Windows\system32
22:06:22.139 AVAST engine scan C:\Windows\system32\drivers
22:06:51.981 AVAST engine scan C:\Users\Pool Laptop
22:11:10.088 File: C:\Users\Pool Laptop\AppData\Local\Temp\jure83852.exe **INFECTED** Win32:FakeSysdefs-D [Trj]
22:21:06.444 AVAST engine scan C:\ProgramData
22:25:00.446 Scan finished successfully
22:25:16.171 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
22:25:16.187 The log file has been saved successfully to "C:\aswMBR-2.txt"


ESET log in the following reply

#12 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 25 September 2012 - 04:39 PM

Please post the LIST PARTS log.

Download

Malwarebytes

Install,update and run a full scan

Click on Show results.Right click on the list ,select all and remove them.

Post the generated log here

Download

mini toolbox

Checkmark following boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size
List restore points

Click Go and post the result.

Download

FSS

Checkmark all the boxes

Click on "Scan".
Please copy and paste the log to your reply.

Download

adware cleaner

Launch it click on Delete

A log should be generated after scan ,post it here

Download

Junkware removal tool

Launch it and scan should start running.After scan gets completed,post the generated log here.

Edited by narenxp, 25 September 2012 - 04:41 PM.


#13 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 25 September 2012 - 05:48 PM

ESET log:


C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0006.dta Win64/Olmasco.Y trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmasco.O trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0010.dta Win64/Olmasco.AA trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0011.dta Win32/Olmasco.Q trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0015.dta Win32/Olmasco.AA trojan cleaned by deleting - quarantined
C:\TDSSKiller_Quarantine\24.09.2012_18.15.40\mbr0000\tdlfs0000\tsk0016.dta Win64/Olmasco.Z trojan cleaned by deleting - quarantined

#14 nave_80

nave_80
  • Topic Starter

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 25 September 2012 - 06:05 PM

Do you want me to run List parts again? Or did you mean eset? I am currently running the other programs you have asked me to, will post the logs after they are done

#15 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:02:15 AM

Posted 25 September 2012 - 06:09 PM

Please run listparts again




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users