Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Save my Computer


  • Please log in to reply
5 replies to this topic

#1 SafetyBox

SafetyBox

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 30 September 2012 - 04:35 PM

Hey guys, Im in for the ride. So far, recovering my computer has been helpless.

Ive used Hitman pro 64 bit, AVG antivirus, and Malwarebytes. Nothing has worked.

What I have is some sort of virus that redirects me to a different webpage when I click on a link in google, although Im not sure what all it does.

Im willing to provide as much details as possible for anybody who is competent in dealing with issues like this.

I cant remember clearly how I got this virus, but I think it was from replacing something in my host file and connecting to a proxy that the author designed to redirect data packets for a game called Realm of The Mad God, thereby enabling some cool hacked features that made it easier to progress in the game.

But the author has some different purposes in mind as well it seems and Ive had multiple hack attempts on my computer, some of which have seemed to work out.

If its not that, then it may be from something else about 8 months ago, where I put some random folder in my windows folder, but hitman pro was able to identify that as not something authorized being there, so that seems to be gone.

It may have also been from a fake flash player update. Hitman Pro identified that as well, but Im unclear as to whether it was removed or not.

But the thing is, I don't know where it came from and how I can identify it, so I would assume that's the first step in getting rid of it.

Is there any way I can offer more info to the experts who are willing to lend me a hand at eliminating this virus (probably a root-kit)?

Im eager to get this over with and Ill be checking back on here every hour or so, a prompt reply would be nice.

Just tell me whats next and Im all game.

Thank you!

edit:

my operating system is Windows 7 64 Bit.

Edited by SafetyBox, 30 September 2012 - 05:03 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:17 PM

Posted 30 September 2012 - 08:45 PM

Welcome

Are you on a router? Are other machines on it,if so are they redirecting?

Do you use the Firefox or Chrome browser?


Run RKill....


Download and Run RKill
  • Please download RKill by Grinler from one of the 4 links below and save it to your desktop.

    Link 1
    Link 2
    Link 3
    Link 4

  • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
  • Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • If nothing happens or if the tool does not run, please let me know in your next reply

Do not reboot your computer after running rkill as the malware programs will start again. Or if rebooting is required run it again.


If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.



Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click on Change Parameters
  • Put a check in the box of Detect TDLFS file system
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log has a name like: TDSSKiller.Version_Date_Time_log.txt.




I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and check Remove found threats
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image


NOTE: In some instances if no malware is found there will be no log produced.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 SafetyBox

SafetyBox
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 01 October 2012 - 04:54 PM

Im on a router. Other machines arent redirecting

I use Firefox and Chrome, both of them redirect.

I ran Rkill and it worked, do you need the log that it gives you at the end?

Here is the TDSS log

332 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
16:40:25.0518 6332 ============================================================
16:40:25.0518 6332 Current date / time: 2012/10/01 16:40:25.0518
16:40:25.0518 6332 SystemInfo:
16:40:25.0518 6332
16:40:25.0518 6332 OS Version: 6.1.7601 ServicePack: 1.0
16:40:25.0518 6332 Product type: Workstation
16:40:25.0518 6332 ComputerName: SPENCER-PC
16:40:25.0518 6332 UserName: Spencer
16:40:25.0518 6332 Windows directory: C:\windows
16:40:25.0518 6332 System windows directory: C:\windows
16:40:25.0518 6332 Running under WOW64
16:40:25.0518 6332 Processor architecture: Intel x64
16:40:25.0518 6332 Number of processors: 2
16:40:25.0518 6332 Page size: 0x1000
16:40:25.0518 6332 Boot type: Normal boot
16:40:25.0518 6332 ============================================================
16:40:26.0348 6332 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:40:26.0353 6332 Drive \Device\Harddisk1\DR1 - Size: 0x7470C05E00 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
16:40:26.0638 6332 ============================================================
16:40:26.0638 6332 \Device\Harddisk0\DR0:
16:40:26.0643 6332 MBR partitions:
16:40:26.0643 6332 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
16:40:26.0643 6332 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x34BA1000
16:40:26.0668 6332 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x34C06000, BlocksNum 0x39FD800
16:40:26.0668 6332 \Device\Harddisk1\DR1:
16:40:26.0713 6332 MBR partitions:
16:40:26.0713 6332 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A384C41
16:40:26.0713 6332 ============================================================
16:40:26.0758 6332 C: <-> \Device\Harddisk0\DR0\Partition2
16:40:26.0793 6332 D: <-> \Device\Harddisk0\DR0\Partition3
16:40:26.0903 6332 H: <-> \Device\Harddisk1\DR1\Partition1
16:40:26.0903 6332 ============================================================
16:40:26.0903 6332 Initialize success
16:40:26.0903 6332 ============================================================
16:41:11.0100 6188 ============================================================
16:41:11.0100 6188 Scan started
16:41:11.0100 6188 Mode: Manual; TDLFS;
16:41:11.0100 6188 ============================================================
16:41:12.0380 6188 ================ Scan system memory ========================
16:41:12.0380 6188 System memory - ok
16:41:12.0380 6188 ================ Scan services =============================
16:41:12.0525 6188 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
16:41:12.0525 6188 !SASCORE - ok
16:41:12.0790 6188 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
16:41:12.0790 6188 1394ohci - ok
16:41:12.0885 6188 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
16:41:12.0885 6188 ACDaemon - ok
16:41:12.0900 6188 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys
16:41:12.0905 6188 ACPI - ok
16:41:12.0925 6188 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
16:41:12.0925 6188 AcpiPmi - ok
16:41:12.0975 6188 [ 5BBFF8B826EC38D32C26334E079C7EFC ] ACPIVPC C:\windows\system32\DRIVERS\AcpiVpc.sys
16:41:12.0980 6188 ACPIVPC - ok
16:41:13.0065 6188 [ 4AE327C9C375D985FF2A2AAB92765218 ] Adobe LM Service C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
16:41:13.0065 6188 Adobe LM Service - ok
16:41:13.0105 6188 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
16:41:13.0115 6188 adp94xx - ok
16:41:13.0130 6188 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\drivers\adpahci.sys
16:41:13.0135 6188 adpahci - ok
16:41:13.0160 6188 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\drivers\adpu320.sys
16:41:13.0160 6188 adpu320 - ok
16:41:13.0230 6188 [ 3D672573EF8F317F10C2AABBB2586262 ] AdvancedSystemCareService5 C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
16:41:13.0240 6188 AdvancedSystemCareService5 - ok
16:41:13.0290 6188 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
16:41:13.0295 6188 AeLookupSvc - ok
16:41:13.0480 6188 [ 6CCD1135320109D6B219F1A6E04AD9F6 ] Afc C:\windows\syswow64\drivers\Afc.sys
16:41:13.0485 6188 Afc - ok
16:41:13.0545 6188 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys
16:41:13.0545 6188 AFD - ok
16:41:13.0580 6188 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys
16:41:13.0585 6188 agp440 - ok
16:41:13.0625 6188 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe
16:41:13.0625 6188 ALG - ok
16:41:13.0655 6188 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys
16:41:13.0655 6188 aliide - ok
16:41:13.0675 6188 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys
16:41:13.0675 6188 amdide - ok
16:41:13.0695 6188 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
16:41:13.0695 6188 AmdK8 - ok
16:41:13.0705 6188 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
16:41:13.0710 6188 AmdPPM - ok
16:41:13.0730 6188 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys
16:41:13.0730 6188 amdsata - ok
16:41:13.0750 6188 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\drivers\amdsbs.sys
16:41:13.0755 6188 amdsbs - ok
16:41:13.0765 6188 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys
16:41:13.0765 6188 amdxata - ok
16:41:13.0795 6188 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys
16:41:13.0800 6188 AppID - ok
16:41:13.0830 6188 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll
16:41:13.0830 6188 AppIDSvc - ok
16:41:13.0850 6188 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\windows\System32\appinfo.dll
16:41:13.0850 6188 Appinfo - ok
16:41:13.0925 6188 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:41:13.0930 6188 Apple Mobile Device - ok
16:41:13.0985 6188 [ 52AD9ED5BD05E7801AF5EFD99652C74F ] Application Updater C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
16:41:13.0995 6188 Application Updater - ok
16:41:14.0035 6188 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\drivers\arc.sys
16:41:14.0035 6188 arc - ok
16:41:14.0065 6188 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\drivers\arcsas.sys
16:41:14.0065 6188 arcsas - ok
16:41:14.0160 6188 [ 29EC2FB2D3A5D2177EF6BA600E0305AE ] aswKbd C:\windows\system32\drivers\aswKbd.sys
16:41:14.0160 6188 aswKbd - ok
16:41:14.0180 6188 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
16:41:14.0185 6188 AsyncMac - ok
16:41:14.0210 6188 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys
16:41:14.0210 6188 atapi - ok
16:41:14.0255 6188 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
16:41:14.0265 6188 AudioEndpointBuilder - ok
16:41:14.0275 6188 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll
16:41:14.0280 6188 AudioSrv - ok
16:41:14.0320 6188 [ 96B4456F1DCA4EDA506ED31C7D2D6B05 ] Avgfwfd C:\windows\system32\DRIVERS\avgfwd6a.sys
16:41:14.0325 6188 Avgfwfd - ok
16:41:14.0425 6188 [ BD5D11CEDBCDE4FA97D2387E7069B1FF ] avgfws C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
16:41:14.0475 6188 avgfws - ok
16:41:14.0590 6188 [ F6A528DE535396C2FB1A4E3C6F00CEC4 ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe
16:41:14.0680 6188 AVGIDSAgent - ok
16:41:14.0740 6188 [ 1B2E9FCDC26DC7C81D4131430E2DC936 ] AVGIDSDriver C:\windows\system32\DRIVERS\avgidsdrivera.sys
16:41:14.0745 6188 AVGIDSDriver - ok
16:41:14.0790 6188 [ 0F293406F64B48D5D2F0D3A1117F3A83 ] AVGIDSFilter C:\windows\system32\DRIVERS\avgidsfiltera.sys
16:41:14.0790 6188 AVGIDSFilter - ok
16:41:14.0840 6188 [ CFFC3A4A638F462E0561CB368B9A7A3A ] AVGIDSHA C:\windows\system32\DRIVERS\avgidsha.sys
16:41:14.0845 6188 AVGIDSHA - ok
16:41:14.0875 6188 [ 221FEBAB02D6C97C95558348CC354A85 ] Avgldx64 C:\windows\system32\DRIVERS\avgldx64.sys
16:41:14.0880 6188 Avgldx64 - ok
16:41:14.0930 6188 [ A6AEC362AAE5E2DDA7445E7690CB0F33 ] Avgmfx64 C:\windows\system32\DRIVERS\avgmfx64.sys
16:41:14.0930 6188 Avgmfx64 - ok
16:41:15.0005 6188 [ 645C7F0A0E39758A0024A9B1748273C0 ] Avgrkx64 C:\windows\system32\DRIVERS\avgrkx64.sys
16:41:15.0005 6188 Avgrkx64 - ok
16:41:15.0020 6188 [ F8C3C7ED612A41B05C66358FC9786BFD ] Avgtdia C:\windows\system32\DRIVERS\avgtdia.sys
16:41:15.0025 6188 Avgtdia - ok
16:41:15.0080 6188 [ E1B8EC60C85A266CB604CD46921606B4 ] avgtp C:\windows\system32\drivers\avgtpx64.sys
16:41:15.0085 6188 avgtp - ok
16:41:15.0110 6188 [ EA1145DEBCD508FD25BD1E95C4346929 ] avgwd C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
16:41:15.0115 6188 avgwd - ok
16:41:15.0145 6188 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll
16:41:15.0150 6188 AxInstSV - ok
16:41:15.0195 6188 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
16:41:15.0200 6188 b06bdrv - ok
16:41:15.0250 6188 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys
16:41:15.0255 6188 b57nd60a - ok
16:41:15.0370 6188 [ B5D54119CE0BB77872C33A717CB76386 ] BCM43XX C:\windows\system32\DRIVERS\bcmwl664.sys
16:41:15.0450 6188 BCM43XX - ok
16:41:15.0470 6188 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll
16:41:15.0470 6188 BDESVC - ok
16:41:15.0480 6188 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys
16:41:15.0480 6188 Beep - ok
16:41:15.0515 6188 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll
16:41:15.0525 6188 BFE - ok
16:41:15.0575 6188 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\System32\qmgr.dll
16:41:15.0590 6188 BITS - ok
16:41:15.0625 6188 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
16:41:15.0625 6188 blbdrive - ok
16:41:15.0710 6188 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
16:41:15.0715 6188 Bonjour Service - ok
16:41:15.0780 6188 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys
16:41:15.0780 6188 bowser - ok
16:41:15.0835 6188 [ AAA4F992F879977A000FE8B8C730CD2C ] BPntDrv C:\windows\system32\drivers\BPntDrv.sys
16:41:15.0835 6188 BPntDrv - ok
16:41:15.0855 6188 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
16:41:15.0860 6188 BrFiltLo - ok
16:41:15.0875 6188 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
16:41:15.0875 6188 BrFiltUp - ok
16:41:15.0940 6188 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll
16:41:15.0940 6188 Browser - ok
16:41:15.0955 6188 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys
16:41:15.0960 6188 Brserid - ok
16:41:16.0000 6188 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
16:41:16.0000 6188 BrSerWdm - ok
16:41:16.0010 6188 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
16:41:16.0010 6188 BrUsbMdm - ok
16:41:16.0020 6188 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
16:41:16.0020 6188 BrUsbSer - ok
16:41:16.0075 6188 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\windows\system32\drivers\BthEnum.sys
16:41:16.0075 6188 BthEnum - ok
16:41:16.0095 6188 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
16:41:16.0095 6188 BTHMODEM - ok
16:41:16.0115 6188 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
16:41:16.0120 6188 BthPan - ok
16:41:16.0140 6188 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
16:41:16.0145 6188 BTHPORT - ok
16:41:16.0190 6188 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll
16:41:16.0190 6188 bthserv - ok
16:41:16.0205 6188 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
16:41:16.0205 6188 BTHUSB - ok
16:41:16.0235 6188 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
16:41:16.0240 6188 cdfs - ok
16:41:16.0270 6188 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
16:41:16.0270 6188 cdrom - ok
16:41:16.0305 6188 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll
16:41:16.0310 6188 CertPropSvc - ok
16:41:16.0325 6188 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\drivers\circlass.sys
16:41:16.0325 6188 circlass - ok
16:41:16.0355 6188 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys
16:41:16.0360 6188 CLFS - ok
16:41:16.0420 6188 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:41:16.0440 6188 clr_optimization_v2.0.50727_32 - ok
16:41:16.0470 6188 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:41:16.0475 6188 clr_optimization_v2.0.50727_64 - ok
16:41:16.0600 6188 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:41:16.0610 6188 clr_optimization_v4.0.30319_32 - ok
16:41:16.0645 6188 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:41:16.0645 6188 clr_optimization_v4.0.30319_64 - ok
16:41:16.0710 6188 [ E13A438F9E51DD034730678E33B73290 ] clwvd C:\windows\system32\DRIVERS\clwvd.sys
16:41:16.0710 6188 clwvd - ok
16:41:16.0755 6188 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
16:41:16.0755 6188 CmBatt - ok
16:41:16.0780 6188 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys
16:41:16.0780 6188 cmdide - ok
16:41:16.0845 6188 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys
16:41:16.0850 6188 CNG - ok
16:41:16.0885 6188 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\drivers\compbatt.sys
16:41:16.0885 6188 Compbatt - ok
16:41:16.0910 6188 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
16:41:16.0910 6188 CompositeBus - ok
16:41:16.0925 6188 COMSysApp - ok
16:41:16.0945 6188 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
16:41:16.0950 6188 crcdisk - ok
16:41:17.0010 6188 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\windows\system32\cryptsvc.dll
16:41:17.0010 6188 CryptSvc - ok
16:41:17.0105 6188 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
16:41:17.0115 6188 cvhsvc - ok
16:41:17.0145 6188 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll
16:41:17.0150 6188 DcomLaunch - ok
16:41:17.0185 6188 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll
16:41:17.0190 6188 defragsvc - ok
16:41:17.0225 6188 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys
16:41:17.0225 6188 DfsC - ok
16:41:17.0265 6188 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll
16:41:17.0265 6188 Dhcp - ok
16:41:17.0295 6188 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys
16:41:17.0300 6188 discache - ok
16:41:17.0325 6188 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\drivers\disk.sys
16:41:17.0325 6188 Disk - ok
16:41:17.0345 6188 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll
16:41:17.0350 6188 Dnscache - ok
16:41:17.0370 6188 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll
16:41:17.0375 6188 dot3svc - ok
16:41:17.0385 6188 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll
16:41:17.0390 6188 DPS - ok
16:41:17.0495 6188 [ F7BDA38AFBDA04F0A89DEBA767EEDA79 ] DragonSvc C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe
16:41:17.0500 6188 DragonSvc - ok
16:41:17.0545 6188 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
16:41:17.0545 6188 drmkaud - ok
16:41:17.0575 6188 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
16:41:17.0590 6188 DXGKrnl - ok
16:41:17.0615 6188 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll
16:41:17.0620 6188 EapHost - ok
16:41:17.0691 6188 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\drivers\evbda.sys
16:41:17.0761 6188 ebdrv - ok
16:41:17.0801 6188 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe
16:41:17.0801 6188 EFS - ok
16:41:17.0901 6188 [ 2C1A297638E4319179A1112D4D6522B8 ] EgisTec Service C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe
16:41:17.0911 6188 EgisTec Service - ok
16:41:17.0951 6188 [ 7745AAFFB61438C28C75E18CE98D4E64 ] EgisTec Ticket Service C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
16:41:17.0961 6188 EgisTec Ticket Service - ok
16:41:18.0036 6188 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe
16:41:18.0046 6188 ehRecvr - ok
16:41:18.0056 6188 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe
16:41:18.0061 6188 ehSched - ok
16:41:18.0106 6188 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\drivers\elxstor.sys
16:41:18.0111 6188 elxstor - ok
16:41:18.0126 6188 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys
16:41:18.0131 6188 ErrDev - ok
16:41:18.0181 6188 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll
16:41:18.0186 6188 EventSystem - ok
16:41:18.0231 6188 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys
16:41:18.0236 6188 exfat - ok
16:41:18.0251 6188 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys
16:41:18.0251 6188 fastfat - ok
16:41:18.0271 6188 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe
16:41:18.0281 6188 Fax - ok
16:41:18.0306 6188 [ 3191ACA33088EE2481044FC0DB736442 ] fbfmon C:\windows\system32\drivers\fbfmon.sys
16:41:18.0311 6188 fbfmon - ok
16:41:18.0321 6188 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\drivers\fdc.sys
16:41:18.0321 6188 fdc - ok
16:41:18.0341 6188 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll
16:41:18.0341 6188 fdPHost - ok
16:41:18.0356 6188 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll
16:41:18.0356 6188 FDResPub - ok
16:41:18.0366 6188 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
16:41:18.0366 6188 FileInfo - ok
16:41:18.0376 6188 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys
16:41:18.0376 6188 Filetrace - ok
16:41:18.0486 6188 [ BB0667B0171B632B97EA759515476F07 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
16:41:18.0496 6188 FLEXnet Licensing Service - ok
16:41:18.0526 6188 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\drivers\flpydisk.sys
16:41:18.0526 6188 flpydisk - ok
16:41:18.0551 6188 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
16:41:18.0556 6188 FltMgr - ok
16:41:18.0601 6188 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\windows\system32\FntCache.dll
16:41:18.0621 6188 FontCache - ok
16:41:18.0661 6188 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:41:18.0666 6188 FontCache3.0.0.0 - ok
16:41:18.0696 6188 [ 1899D0FB4C5AD0D6D0BFA258C54903F7 ] FPSensor C:\windows\system32\Drivers\FPSensor.sys
16:41:18.0701 6188 FPSensor - ok
16:41:18.0711 6188 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys
16:41:18.0711 6188 FsDepends - ok
16:41:18.0776 6188 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
16:41:18.0776 6188 Fs_Rec - ok
16:41:18.0816 6188 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
16:41:18.0821 6188 fvevol - ok
16:41:18.0841 6188 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
16:41:18.0846 6188 gagp30kx - ok
16:41:18.0891 6188 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
16:41:18.0891 6188 GEARAspiWDM - ok
16:41:18.0966 6188 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll
16:41:18.0976 6188 gpsvc - ok
16:41:19.0066 6188 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:41:19.0066 6188 gupdate - ok
16:41:19.0106 6188 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:41:19.0106 6188 gupdatem - ok
16:41:19.0121 6188 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
16:41:19.0126 6188 hcw85cir - ok
16:41:19.0166 6188 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
16:41:19.0171 6188 HdAudAddService - ok
16:41:19.0196 6188 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
16:41:19.0201 6188 HDAudBus - ok
16:41:19.0201 6188 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\drivers\HidBatt.sys
16:41:19.0206 6188 HidBatt - ok
16:41:19.0221 6188 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\drivers\hidbth.sys
16:41:19.0226 6188 HidBth - ok
16:41:19.0241 6188 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\drivers\hidir.sys
16:41:19.0241 6188 HidIr - ok
16:41:19.0261 6188 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\system32\hidserv.dll
16:41:19.0261 6188 hidserv - ok
16:41:19.0281 6188 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
16:41:19.0286 6188 HidUsb - ok
16:41:19.0336 6188 [ 44F92C1F913E582BEF9CAC66443C6230 ] hitmanpro36 C:\windows\system32\drivers\hitmanpro36.sys
16:41:19.0341 6188 hitmanpro36 - ok
16:41:19.0411 6188 [ 0926C3B5CBF64C88F432FF449B211807 ] HitmanProScheduler C:\Program Files\HitmanPro\hmpsched.exe
16:41:19.0416 6188 HitmanProScheduler - ok
16:41:19.0441 6188 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll
16:41:19.0441 6188 hkmsvc - ok
16:41:19.0481 6188 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll
16:41:19.0486 6188 HomeGroupListener - ok
16:41:19.0511 6188 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll
16:41:19.0516 6188 HomeGroupProvider - ok
16:41:19.0546 6188 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
16:41:19.0546 6188 HpSAMD - ok
16:41:19.0586 6188 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys
16:41:19.0591 6188 HTTP - ok
16:41:19.0596 6188 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
16:41:19.0601 6188 hwpolicy - ok
16:41:19.0646 6188 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
16:41:19.0646 6188 i8042prt - ok
16:41:19.0681 6188 [ 53CC5BF8B5A219119953C7ABB19A7705 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
16:41:19.0686 6188 iaStor - ok
16:41:19.0726 6188 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
16:41:19.0731 6188 iaStorV - ok
16:41:19.0796 6188 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:41:19.0811 6188 idsvc - ok
16:41:20.0046 6188 [ 795C99DC4F574C97C03D0BB39CF099EE ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
16:41:20.0286 6188 igfx - ok
16:41:20.0316 6188 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\drivers\iirsp.sys
16:41:20.0316 6188 iirsp - ok
16:41:20.0356 6188 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll
16:41:20.0371 6188 IKEEXT - ok
16:41:20.0471 6188 [ 03076F51AF9F78A272CCCDE03E9340CE ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys
16:41:20.0516 6188 IntcAzAudAddService - ok
16:41:20.0556 6188 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
16:41:20.0561 6188 IntcDAud - ok
16:41:20.0586 6188 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys
16:41:20.0586 6188 intelide - ok
16:41:20.0616 6188 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
16:41:20.0616 6188 intelppm - ok
16:41:20.0656 6188 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll
16:41:20.0656 6188 IPBusEnum - ok
16:41:20.0691 6188 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
16:41:20.0691 6188 IpFilterDriver - ok
16:41:20.0726 6188 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
16:41:20.0736 6188 iphlpsvc - ok
16:41:20.0756 6188 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
16:41:20.0761 6188 IPMIDRV - ok
16:41:20.0771 6188 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys
16:41:20.0771 6188 IPNAT - ok
16:41:20.0851 6188 [ 50D6CCC6FF5561F9F56946B3E6164FB8 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
16:41:20.0871 6188 iPod Service - ok
16:41:20.0906 6188 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys
16:41:20.0911 6188 IRENUM - ok
16:41:20.0921 6188 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys
16:41:20.0926 6188 isapnp - ok
16:41:20.0951 6188 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
16:41:20.0956 6188 iScsiPrt - ok
16:41:20.0981 6188 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
16:41:20.0986 6188 kbdclass - ok
16:41:21.0001 6188 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
16:41:21.0001 6188 kbdhid - ok
16:41:21.0026 6188 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe
16:41:21.0026 6188 KeyIso - ok
16:41:21.0066 6188 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
16:41:21.0071 6188 KSecDD - ok
16:41:21.0116 6188 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
16:41:21.0121 6188 KSecPkg - ok
16:41:21.0136 6188 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys
16:41:21.0141 6188 ksthunk - ok
16:41:21.0171 6188 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll
16:41:21.0176 6188 KtmRm - ok
16:41:21.0216 6188 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\system32\srvsvc.dll
16:41:21.0221 6188 LanmanServer - ok
16:41:21.0236 6188 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll
16:41:21.0241 6188 LanmanWorkstation - ok
16:41:21.0271 6188 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\windows\system32\DRIVERS\LhdX64.sys
16:41:21.0271 6188 LHDmgr - ok
16:41:21.0301 6188 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
16:41:21.0301 6188 lltdio - ok
16:41:21.0321 6188 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll
16:41:21.0326 6188 lltdsvc - ok
16:41:21.0361 6188 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll
16:41:21.0361 6188 lmhosts - ok
16:41:21.0441 6188 [ 2ED1786B7542CDA261029F6B526EDF44 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
16:41:21.0446 6188 LMS - ok
16:41:21.0471 6188 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
16:41:21.0476 6188 LSI_FC - ok
16:41:21.0496 6188 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
16:41:21.0501 6188 LSI_SAS - ok
16:41:21.0506 6188 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
16:41:21.0511 6188 LSI_SAS2 - ok
16:41:21.0521 6188 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
16:41:21.0526 6188 LSI_SCSI - ok
16:41:21.0566 6188 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys
16:41:21.0566 6188 luafv - ok
16:41:21.0636 6188 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\windows\system32\drivers\mbam.sys
16:41:21.0641 6188 MBAMProtector - ok
16:41:21.0711 6188 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
16:41:21.0716 6188 MBAMScheduler - ok
16:41:21.0736 6188 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
16:41:21.0746 6188 MBAMService - ok
16:41:21.0791 6188 [ 79D51E7F5926E8CE1B3EBECEBAE28CFF ] mcdbus C:\windows\system32\DRIVERS\mcdbus.sys
16:41:21.0796 6188 mcdbus - ok
16:41:21.0821 6188 McMPFSvc - ok
16:41:21.0866 6188 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
16:41:21.0871 6188 Mcx2Svc - ok
16:41:21.0886 6188 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\drivers\megasas.sys
16:41:21.0886 6188 megasas - ok
16:41:21.0926 6188 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
16:41:21.0926 6188 MegaSR - ok
16:41:21.0986 6188 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\windows\system32\DRIVERS\HECIx64.sys
16:41:21.0991 6188 MEIx64 - ok
16:41:22.0001 6188 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll
16:41:22.0006 6188 MMCSS - ok
16:41:22.0016 6188 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys
16:41:22.0016 6188 Modem - ok
16:41:22.0046 6188 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys
16:41:22.0051 6188 monitor - ok
16:41:22.0076 6188 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
16:41:22.0076 6188 mouclass - ok
16:41:22.0106 6188 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
16:41:22.0106 6188 mouhid - ok
16:41:22.0161 6188 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys
16:41:22.0161 6188 mountmgr - ok
16:41:22.0266 6188 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
16:41:22.0271 6188 MozillaMaintenance - ok
16:41:22.0286 6188 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys
16:41:22.0291 6188 mpio - ok
16:41:22.0296 6188 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
16:41:22.0296 6188 mpsdrv - ok
16:41:22.0336 6188 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll
16:41:22.0351 6188 MpsSvc - ok
16:41:22.0361 6188 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
16:41:22.0361 6188 MRxDAV - ok
16:41:22.0376 6188 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
16:41:22.0381 6188 mrxsmb - ok
16:41:22.0436 6188 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
16:41:22.0441 6188 mrxsmb10 - ok
16:41:22.0451 6188 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
16:41:22.0451 6188 mrxsmb20 - ok
16:41:22.0466 6188 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\drivers\msahci.sys
16:41:22.0471 6188 msahci - ok
16:41:22.0486 6188 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys
16:41:22.0491 6188 msdsm - ok
16:41:22.0511 6188 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe
16:41:22.0511 6188 MSDTC - ok
16:41:22.0546 6188 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys
16:41:22.0546 6188 Msfs - ok
16:41:22.0571 6188 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
16:41:22.0571 6188 mshidkmdf - ok
16:41:22.0581 6188 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys
16:41:22.0586 6188 msisadrv - ok
16:41:22.0611 6188 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll
16:41:22.0616 6188 MSiSCSI - ok
16:41:22.0621 6188 msiserver - ok
16:41:22.0656 6188 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
16:41:22.0656 6188 MSKSSRV - ok
16:41:22.0696 6188 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
16:41:22.0696 6188 MSPCLOCK - ok
16:41:22.0711 6188 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
16:41:22.0711 6188 MSPQM - ok
16:41:22.0736 6188 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys
16:41:22.0741 6188 MsRPC - ok
16:41:22.0761 6188 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
16:41:22.0761 6188 mssmbios - ok
16:41:22.0776 6188 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
16:41:22.0781 6188 MSTEE - ok
16:41:22.0801 6188 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\drivers\MTConfig.sys
16:41:22.0801 6188 MTConfig - ok
16:41:22.0821 6188 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys
16:41:22.0826 6188 Mup - ok
16:41:22.0851 6188 [ 9B1EAC6FAF6F37305E822F5588DC8056 ] mwlPSDFilter C:\windows\system32\DRIVERS\mwlPSDFilter.sys
16:41:22.0856 6188 mwlPSDFilter - ok
16:41:22.0866 6188 [ AD55C1524B296280ED9C6E0D730D35DA ] mwlPSDNServ C:\windows\system32\DRIVERS\mwlPSDNServ.sys
16:41:22.0871 6188 mwlPSDNServ - ok
16:41:22.0881 6188 [ 2B599E6EC8843637BDD62E7F8F3BA201 ] mwlPSDVDisk C:\windows\system32\DRIVERS\mwlPSDVDisk.sys
16:41:22.0881 6188 mwlPSDVDisk - ok
16:41:22.0911 6188 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll
16:41:22.0916 6188 napagent - ok
16:41:22.0956 6188 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
16:41:22.0961 6188 NativeWifiP - ok
16:41:23.0026 6188 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\windows\system32\drivers\ndis.sys
16:41:23.0031 6188 NDIS - ok
16:41:23.0056 6188 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
16:41:23.0056 6188 NdisCap - ok
16:41:23.0086 6188 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
16:41:23.0086 6188 NdisTapi - ok
16:41:23.0101 6188 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
16:41:23.0106 6188 Ndisuio - ok
16:41:23.0116 6188 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
16:41:23.0116 6188 NdisWan - ok
16:41:23.0141 6188 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
16:41:23.0141 6188 NDProxy - ok
16:41:23.0166 6188 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
16:41:23.0166 6188 NetBIOS - ok
16:41:23.0181 6188 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
16:41:23.0181 6188 NetBT - ok
16:41:23.0201 6188 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe
16:41:23.0201 6188 Netlogon - ok
16:41:23.0231 6188 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll
16:41:23.0231 6188 Netman - ok
16:41:23.0271 6188 [ 3E5A36127E201DDF663176B66828FAFE ] NetMsmqActivator C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:41:23.0276 6188 NetMsmqActivator - ok
16:41:23.0281 6188 [ 3E5A36127E201DDF663176B66828FAFE ] NetPipeActivator C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:41:23.0281 6188 NetPipeActivator - ok
16:41:23.0361 6188 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll
16:41:23.0371 6188 netprofm - ok
16:41:23.0376 6188 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpActivator C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:41:23.0376 6188 NetTcpActivator - ok
16:41:23.0381 6188 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:41:23.0381 6188 NetTcpPortSharing - ok
16:41:23.0441 6188 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
16:41:23.0441 6188 nfrd960 - ok
16:41:23.0471 6188 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\windows\System32\nlasvc.dll
16:41:23.0476 6188 NlaSvc - ok
16:41:23.0516 6188 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys
16:41:23.0516 6188 Npfs - ok
16:41:23.0526 6188 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll
16:41:23.0531 6188 nsi - ok
16:41:23.0541 6188 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
16:41:23.0541 6188 nsiproxy - ok
16:41:23.0581 6188 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
16:41:23.0591 6188 Ntfs - ok
16:41:23.0601 6188 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys
16:41:23.0601 6188 Null - ok
16:41:23.0626 6188 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys
16:41:23.0631 6188 nvraid - ok
16:41:23.0651 6188 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys
16:41:23.0651 6188 nvstor - ok
16:41:23.0681 6188 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys
16:41:23.0681 6188 nv_agp - ok
16:41:23.0781 6188 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
16:41:23.0791 6188 odserv - ok
16:41:23.0806 6188 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
16:41:23.0811 6188 ohci1394 - ok
16:41:23.0866 6188 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:41:23.0871 6188 ose - ok
16:41:24.0054 6188 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
16:41:24.0183 6188 osppsvc - ok
16:41:24.0208 6188 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll
16:41:24.0213 6188 p2pimsvc - ok
16:41:24.0228 6188 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll
16:41:24.0238 6188 p2psvc - ok
16:41:24.0263 6188 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\drivers\parport.sys
16:41:24.0263 6188 Parport - ok
16:41:24.0303 6188 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys
16:41:24.0308 6188 partmgr - ok
16:41:24.0323 6188 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll
16:41:24.0323 6188 PcaSvc - ok
16:41:24.0343 6188 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys
16:41:24.0348 6188 pci - ok
16:41:24.0358 6188 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\drivers\pciide.sys
16:41:24.0358 6188 pciide - ok
16:41:24.0373 6188 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\drivers\pcmcia.sys
16:41:24.0378 6188 pcmcia - ok
16:41:24.0393 6188 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys
16:41:24.0393 6188 pcw - ok
16:41:24.0423 6188 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys
16:41:24.0428 6188 PEAUTH - ok
16:41:24.0548 6188 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe
16:41:24.0548 6188 PerfHost - ok
16:41:24.0598 6188 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll
16:41:24.0633 6188 pla - ok
16:41:24.0698 6188 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll
16:41:24.0703 6188 PlugPlay - ok
16:41:24.0713 6188 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
16:41:24.0718 6188 PNRPAutoReg - ok
16:41:24.0728 6188 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll
16:41:24.0733 6188 PNRPsvc - ok
16:41:24.0768 6188 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
16:41:24.0773 6188 PolicyAgent - ok
16:41:24.0798 6188 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\windows\system32\umpo.dll
16:41:24.0803 6188 Power - ok
16:41:24.0843 6188 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
16:41:24.0843 6188 PptpMiniport - ok
16:41:24.0868 6188 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\drivers\processr.sys
16:41:24.0868 6188 Processor - ok
16:41:24.0908 6188 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll
16:41:24.0913 6188 ProfSvc - ok
16:41:24.0923 6188 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe
16:41:24.0923 6188 ProtectedStorage - ok
16:41:24.0953 6188 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys
16:41:24.0958 6188 Psched - ok
16:41:25.0013 6188 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\drivers\ql2300.sys
16:41:25.0048 6188 ql2300 - ok
16:41:25.0068 6188 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
16:41:25.0068 6188 ql40xx - ok
16:41:25.0098 6188 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll
16:41:25.0103 6188 QWAVE - ok
16:41:25.0113 6188 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
16:41:25.0113 6188 QWAVEdrv - ok
16:41:25.0128 6188 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
16:41:25.0128 6188 RasAcd - ok
16:41:25.0163 6188 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
16:41:25.0163 6188 RasAgileVpn - ok
16:41:25.0173 6188 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll
16:41:25.0178 6188 RasAuto - ok
16:41:25.0198 6188 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
16:41:25.0198 6188 Rasl2tp - ok
16:41:25.0223 6188 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll
16:41:25.0228 6188 RasMan - ok
16:41:25.0253 6188 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
16:41:25.0253 6188 RasPppoe - ok
16:41:25.0273 6188 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
16:41:25.0278 6188 RasSstp - ok
16:41:25.0288 6188 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
16:41:25.0293 6188 rdbss - ok
16:41:25.0313 6188 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\drivers\rdpbus.sys
16:41:25.0313 6188 rdpbus - ok
16:41:25.0338 6188 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
16:41:25.0338 6188 RDPCDD - ok
16:41:25.0348 6188 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
16:41:25.0348 6188 RDPENCDD - ok
16:41:25.0378 6188 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
16:41:25.0378 6188 RDPREFMP - ok
16:41:25.0433 6188 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys
16:41:25.0438 6188 RDPWD - ok
16:41:25.0463 6188 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
16:41:25.0468 6188 rdyboost - ok
16:41:25.0488 6188 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll
16:41:25.0493 6188 RemoteAccess - ok
16:41:25.0518 6188 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll
16:41:25.0523 6188 RemoteRegistry - ok
16:41:25.0563 6188 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
16:41:25.0563 6188 RFCOMM - ok
16:41:25.0593 6188 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
16:41:25.0593 6188 RpcEptMapper - ok
16:41:25.0618 6188 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe
16:41:25.0618 6188 RpcLocator - ok
16:41:25.0633 6188 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll
16:41:25.0638 6188 RpcSs - ok
16:41:25.0658 6188 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
16:41:25.0663 6188 rspndr - ok
16:41:25.0713 6188 [ E54A5586A28D0630A79A68BBAB84BFCF ] RSUSBVSTOR C:\windows\system32\Drivers\RtsUVStor.sys
16:41:25.0718 6188 RSUSBVSTOR - ok
16:41:25.0748 6188 [ 20A466B9EA2BD828C0EC723F99B8CFE7 ] RTL8167 C:\windows\system32\DRIVERS\Rt64win7.sys
16:41:25.0753 6188 RTL8167 - ok
16:41:25.0758 6188 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe
16:41:25.0758 6188 SamSs - ok
16:41:25.0833 6188 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
16:41:25.0833 6188 SASDIFSV - ok
16:41:25.0863 6188 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
16:41:25.0868 6188 SASKUTIL - ok
16:41:25.0883 6188 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys
16:41:25.0888 6188 sbp2port - ok
16:41:25.0913 6188 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll
16:41:25.0918 6188 SCardSvr - ok
16:41:25.0923 6188 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
16:41:25.0928 6188 scfilter - ok
16:41:25.0958 6188 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll
16:41:25.0968 6188 Schedule - ok
16:41:25.0993 6188 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll
16:41:25.0998 6188 SCPolicySvc - ok
16:41:26.0018 6188 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll
16:41:26.0023 6188 SDRSVC - ok
16:41:26.0053 6188 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys
16:41:26.0053 6188 secdrv - ok
16:41:26.0063 6188 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll
16:41:26.0063 6188 seclogon - ok
16:41:26.0078 6188 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\System32\sens.dll
16:41:26.0083 6188 SENS - ok
16:41:26.0103 6188 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll
16:41:26.0103 6188 SensrSvc - ok
16:41:26.0123 6188 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\drivers\serenum.sys
16:41:26.0123 6188 Serenum - ok
16:41:26.0153 6188 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\windows\system32\drivers\serial.sys
16:41:26.0153 6188 Serial - ok
16:41:26.0183 6188 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\drivers\sermouse.sys
16:41:26.0188 6188 sermouse - ok
16:41:26.0208 6188 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll
16:41:26.0208 6188 SessionEnv - ok
16:41:26.0228 6188 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys
16:41:26.0228 6188 sffdisk - ok
16:41:26.0243 6188 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
16:41:26.0248 6188 sffp_mmc - ok
16:41:26.0263 6188 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
16:41:26.0263 6188 sffp_sd - ok
16:41:26.0278 6188 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
16:41:26.0278 6188 sfloppy - ok
16:41:26.0378 6188 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys
16:41:26.0388 6188 Sftfs - ok
16:41:26.0473 6188 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
16:41:26.0478 6188 sftlist - ok
16:41:26.0508 6188 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys
16:41:26.0513 6188 Sftplay - ok
16:41:26.0523 6188 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\windows\system32\DRIVERS\Sftredirlh.sys
16:41:26.0528 6188 Sftredir - ok
16:41:26.0573 6188 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\windows\system32\DRIVERS\Sftvollh.sys
16:41:26.0578 6188 Sftvol - ok
16:41:26.0613 6188 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
16:41:26.0618 6188 sftvsa - ok
16:41:26.0678 6188 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\windows\System32\ipnathlp.dll
16:41:26.0683 6188 SharedAccess - ok
16:41:26.0718 6188 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\windows\System32\shsvcs.dll
16:41:26.0723 6188 ShellHWDetection - ok
16:41:26.0758 6188 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
16:41:26.0758 6188 SiSRaid2 - ok
16:41:26.0778 6188 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
16:41:26.0778 6188 SiSRaid4 - ok
16:41:26.0813 6188 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\windows\system32\DRIVERS\smb.sys
16:41:26.0813 6188 Smb - ok
16:41:26.0838 6188 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\windows\System32\snmptrap.exe
16:41:26.0838 6188 SNMPTRAP - ok
16:41:26.0848 6188 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\windows\system32\drivers\spldr.sys
16:41:26.0848 6188 spldr - ok
16:41:26.0903 6188 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\windows\System32\spoolsv.exe
16:41:26.0913 6188 Spooler - ok
16:41:26.0978 6188 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\windows\system32\sppsvc.exe
16:41:27.0058 6188 sppsvc - ok
16:41:27.0073 6188 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\windows\system32\sppuinotify.dll
16:41:27.0073 6188 sppuinotify - ok
16:41:27.0098 6188 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\windows\system32\DRIVERS\srv.sys
16:41:27.0098 6188 srv - ok
16:41:27.0188 6188 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
16:41:27.0193 6188 srv2 - ok
16:41:27.0208 6188 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
16:41:27.0208 6188 srvnet - ok
16:41:27.0248 6188 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
16:41:27.0253 6188 SSDPSRV - ok
16:41:27.0268 6188 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\windows\system32\sstpsvc.dll
16:41:27.0268 6188 SstpSvc - ok
16:41:27.0288 6188 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\windows\system32\drivers\stexstor.sys
16:41:27.0288 6188 stexstor - ok
16:41:27.0323 6188 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\windows\System32\wiaservc.dll
16:41:27.0333 6188 stisvc - ok
16:41:27.0358 6188 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\windows\system32\DRIVERS\swenum.sys
16:41:27.0358 6188 swenum - ok
16:41:27.0373 6188 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\windows\System32\swprv.dll
16:41:27.0383 6188 swprv - ok
16:41:27.0463 6188 [ 08425CD92972C6430F350A9697F4A553 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
16:41:27.0498 6188 SynTP - ok
16:41:27.0533 6188 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\windows\system32\sysmain.dll
16:41:27.0568 6188 SysMain - ok
16:41:27.0583 6188 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\windows\System32\TabSvc.dll
16:41:27.0588 6188 TabletInputService - ok
16:41:27.0613 6188 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\windows\System32\tapisrv.dll
16:41:27.0613 6188 TapiSrv - ok
16:41:27.0628 6188 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\windows\System32\tbssvc.dll
16:41:27.0633 6188 TBS - ok
16:41:27.0753 6188 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\windows\system32\drivers\tcpip.sys
16:41:27.0768 6188 Tcpip - ok
16:41:27.0828 6188 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
16:41:27.0843 6188 TCPIP6 - ok
16:41:27.0873 6188 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
16:41:27.0873 6188 tcpipreg - ok
16:41:27.0893 6188 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
16:41:27.0898 6188 TDPIPE - ok
16:41:27.0933 6188 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
16:41:27.0933 6188 TDTCP - ok
16:41:27.0943 6188 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\windows\system32\DRIVERS\tdx.sys
16:41:27.0948 6188 tdx - ok
16:41:27.0973 6188 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\windows\system32\DRIVERS\termdd.sys
16:41:27.0978 6188 TermDD - ok
16:41:28.0008 6188 [ 2E648163254233755035B46DD7B89123 ] TermService C:\windows\System32\termsrv.dll
16:41:28.0013 6188 TermService - ok
16:41:28.0028 6188 [ F0344071948D1A1FA732231785A0664C ] Themes C:\windows\system32\themeservice.dll
16:41:28.0028 6188 Themes - ok
16:41:28.0048 6188 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\windows\system32\mmcss.dll
16:41:28.0048 6188 THREADORDER - ok
16:41:28.0058 6188 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\windows\System32\trkwks.dll
16:41:28.0063 6188 TrkWks - ok
16:41:28.0113 6188 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
16:41:28.0118 6188 TrustedInstaller - ok
16:41:28.0158 6188 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
16:41:28.0163 6188 tssecsrv - ok
16:41:28.0188 6188 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
16:41:28.0193 6188 TsUsbFlt - ok
16:41:28.0223 6188 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\windows\system32\drivers\TsUsbGD.sys
16:41:28.0223 6188 TsUsbGD - ok
16:41:28.0268 6188 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
16:41:28.0273 6188 tunnel - ok
16:41:28.0288 6188 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\windows\system32\drivers\uagp35.sys
16:41:28.0288 6188 uagp35 - ok
16:41:28.0313 6188 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\windows\system32\DRIVERS\udfs.sys
16:41:28.0313 6188 udfs - ok
16:41:28.0348 6188 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\windows\system32\UI0Detect.exe
16:41:28.0348 6188 UI0Detect - ok
16:41:28.0373 6188 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
16:41:28.0378 6188 uliagpkx - ok
16:41:28.0413 6188 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\windows\system32\DRIVERS\umbus.sys
16:41:28.0413 6188 umbus - ok
16:41:28.0443 6188 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\windows\system32\drivers\umpass.sys
16:41:28.0448 6188 UmPass - ok
16:41:28.0578 6188 [ 7E5E1603D0FF2D240AE70295C5C3FEFC ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
16:41:28.0623 6188 UNS - ok
16:41:28.0663 6188 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\windows\System32\upnphost.dll
16:41:28.0668 6188 upnphost - ok
16:41:28.0718 6188 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\windows\system32\Drivers\usbaapl64.sys
16:41:28.0718 6188 USBAAPL64 - ok
16:41:28.0783 6188 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\windows\system32\drivers\usbaudio.sys
16:41:28.0788 6188 usbaudio - ok
16:41:28.0818 6188 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
16:41:28.0818 6188 usbccgp - ok
16:41:28.0843 6188 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\windows\system32\drivers\usbcir.sys
16:41:28.0848 6188 usbcir - ok
16:41:28.0863 6188 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
16:41:28.0863 6188 usbehci - ok
16:41:28.0898 6188 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
16:41:28.0898 6188 usbhub - ok
16:41:28.0918 6188 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\windows\system32\drivers\usbohci.sys
16:41:28.0918 6188 usbohci - ok
16:41:28.0928 6188 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
16:41:28.0933 6188 usbprint - ok
16:41:28.0988 6188 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\windows\system32\DRIVERS\usbscan.sys
16:41:28.0988 6188 usbscan - ok
16:41:29.0008 6188 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
16:41:29.0008 6188 USBSTOR - ok
16:41:29.0023 6188 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\windows\system32\drivers\usbuhci.sys
16:41:29.0023 6188 usbuhci - ok
16:41:29.0058 6188 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys
16:41:29.0058 6188 usbvideo - ok
16:41:29.0093 6188 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\windows\System32\uxsms.dll
16:41:29.0093 6188 UxSms - ok
16:41:29.0113 6188 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\windows\system32\lsass.exe
16:41:29.0113 6188 VaultSvc - ok
16:41:29.0163 6188 [ 58E2365E7FD880624F648C63C5D22009 ] VBoxNetAdp C:\windows\system32\DRIVERS\VBoxNetAdp.sys
16:41:29.0168 6188 VBoxNetAdp - ok
16:41:29.0178 6188 VBoxNetFlt - ok
16:41:29.0203 6188 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
16:41:29.0203 6188 vdrvroot - ok
16:41:29.0233 6188 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\windows\System32\vds.exe
16:41:29.0238 6188 vds - ok
16:41:29.0308 6188 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\windows\system32\DRIVERS\vgapnp.sys
16:41:29.0308 6188 vga - ok
16:41:29.0323 6188 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\windows\System32\drivers\vga.sys
16:41:29.0323 6188 VgaSave - ok
16:41:29.0368 6188 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\windows\system32\drivers\vhdmp.sys
16:41:29.0368 6188 vhdmp - ok
16:41:29.0388 6188 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\windows\system32\drivers\viaide.sys
16:41:29.0393 6188 viaide - ok
16:41:29.0443 6188 [ B977390908F5FC42B66E74D1E96843E6 ] vm331avs C:\windows\system32\Drivers\vm331avs.sys
16:41:29.0448 6188 vm331avs - ok
16:41:29.0453 6188 [ 40C39413A2458016FF43444750F467CA ] vmuvcflt C:\windows\system32\Drivers\vmuvcflt.sys
16:41:29.0458 6188 vmuvcflt - ok
16:41:29.0468 6188 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\windows\system32\drivers\volmgr.sys
16:41:29.0468 6188 volmgr - ok
16:41:29.0488 6188 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\windows\system32\drivers\volmgrx.sys
16:41:29.0498 6188 volmgrx - ok
16:41:29.0508 6188 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\windows\system32\drivers\volsnap.sys
16:41:29.0513 6188 volsnap - ok
16:41:29.0548 6188 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
16:41:29.0553 6188 vsmraid - ok
16:41:29.0603 6188 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\windows\system32\vssvc.exe
16:41:29.0648 6188 VSS - ok
16:41:29.0823 6188 [ 3DA649C6EC481D8F36B54F33FC01DD1E ] vToolbarUpdater12.1.5 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.1.5\ToolbarUpdater.exe
16:41:29.0833 6188 vToolbarUpdater12.1.5 - ok
16:41:29.0868 6188 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
16:41:29.0868 6188 vwifibus - ok
16:41:29.0893 6188 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
16:41:29.0893 6188 vwififlt - ok
16:41:29.0898 6188 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
16:41:29.0898 6188 vwifimp - ok
16:41:29.0933 6188 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\windows\system32\w32time.dll
16:41:29.0938 6188 W32Time - ok
16:41:29.0953 6188 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\windows\system32\drivers\wacompen.sys
16:41:29.0953 6188 WacomPen - ok
16:41:30.0028 6188 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
16:41:30.0028 6188 WANARP - ok
16:41:30.0033 6188 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
16:41:30.0033 6188 Wanarpv6 - ok
16:41:30.0113 6188 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
16:41:30.0178 6188 WatAdminSvc - ok
16:41:30.0233 6188 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\windows\system32\wbengine.exe
16:41:30.0263 6188 wbengine - ok
16:41:30.0303 6188 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
16:41:30.0308 6188 WbioSrvc - ok
16:41:30.0323 6188 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\windows\System32\wcncsvc.dll
16:41:30.0333 6188 wcncsvc - ok
16:41:30.0348 6188 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
16:41:30.0348 6188 WcsPlugInService - ok
16:41:30.0368 6188 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\windows\system32\drivers\wd.sys
16:41:30.0373 6188 Wd - ok
16:41:30.0398 6188 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
16:41:30.0408 6188 Wdf01000 - ok
16:41:30.0423 6188 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\windows\system32\wdi.dll
16:41:30.0428 6188 WdiServiceHost - ok
16:41:30.0433 6188 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\windows\system32\wdi.dll
16:41:30.0438 6188 WdiSystemHost - ok
16:41:30.0458 6188 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\windows\System32\webclnt.dll
16:41:30.0463 6188 WebClient - ok
16:41:30.0483 6188 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\windows\system32\wecsvc.dll
16:41:30.0493 6188 Wecsvc - ok
16:41:30.0498 6188 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\windows\System32\wercplsupport.dll
16:41:30.0503 6188 wercplsupport - ok
16:41:30.0528 6188 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\windows\System32\WerSvc.dll
16:41:30.0533 6188 WerSvc - ok
16:41:30.0563 6188 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
16:41:30.0563 6188 WfpLwf - ok
16:41:30.0583 6188 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\windows\system32\drivers\wimmount.sys
16:41:30.0583 6188 WIMMount - ok
16:41:30.0598 6188 WinDefend - ok
16:41:30.0598 6188 WinHttpAutoProxySvc - ok
16:41:30.0648 6188 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
16:41:30.0653 6188 Winmgmt - ok
16:41:30.0713 6188 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\windows\system32\WsmSvc.dll
16:41:30.0758 6188 WinRM - ok
16:41:30.0833 6188 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
16:41:30.0833 6188 WinUsb - ok
16:41:30.0883 6188 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\windows\System32\wlansvc.dll
16:41:30.0898 6188 Wlansvc - ok
16:41:30.0958 6188 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
16:41:30.0958 6188 wlcrasvc - ok
16:41:31.0053 6188 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:41:31.0098 6188 wlidsvc - ok
16:41:31.0163 6188 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\windows\system32\DRIVERS\wmiacpi.sys
16:41:31.0163 6188 WmiAcpi - ok
16:41:31.0198 6188 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
16:41:31.0203 6188 wmiApSrv - ok
16:41:31.0238 6188 WMPNetworkSvc - ok
16:41:31.0258 6188 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\windows\System32\wpcsvc.dll
16:41:31.0263 6188 WPCSvc - ok
16:41:31.0278 6188 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
16:41:31.0283 6188 WPDBusEnum - ok
16:41:31.0308 6188 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
16:41:31.0308 6188 ws2ifsl - ok
16:41:31.0363 6188 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(1) C:\windows\system32\drivers\WsAudio_DeviceS(1).sys
16:41:31.0363 6188 WsAudio_DeviceS(1) - ok
16:41:31.0403 6188 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(2) C:\windows\system32\drivers\WsAudio_DeviceS(2).sys
16:41:31.0403 6188 WsAudio_DeviceS(2) - ok
16:41:31.0423 6188 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(3) C:\windows\system32\drivers\WsAudio_DeviceS(3).sys
16:41:31.0423 6188 WsAudio_DeviceS(3) - ok
16:41:31.0428 6188 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(4) C:\windows\system32\drivers\WsAudio_DeviceS(4).sys
16:41:31.0428 6188 WsAudio_DeviceS(4) - ok
16:41:31.0443 6188 [ AD12F5C7251BB8D575D560894E73CBBA ] WsAudio_DeviceS(5) C:\windows\system32\drivers\WsAudio_DeviceS(5).sys
16:41:31.0448 6188 WsAudio_DeviceS(5) - ok
16:41:31.0473 6188 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\windows\System32\wscsvc.dll
16:41:31.0478 6188 wscsvc - ok
16:41:31.0478 6188 WSearch - ok
16:41:31.0518 6188 [ 83575C43B2BFE9AB0661A7F957E843C0 ] wsvd C:\windows\system32\DRIVERS\wsvd.sys
16:41:31.0523 6188 wsvd - ok
16:41:31.0608 6188 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\windows\system32\wuaueng.dll
16:41:31.0653 6188 wuauserv - ok
16:41:31.0668 6188 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\windows\system32\drivers\WudfPf.sys
16:41:31.0673 6188 WudfPf - ok
16:41:31.0703 6188 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
16:41:31.0703 6188 WUDFRd - ok
16:41:31.0723 6188 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\windows\System32\WUDFSvc.dll
16:41:31.0728 6188 wudfsvc - ok
16:41:31.0743 6188 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\windows\System32\wwansvc.dll
16:41:31.0748 6188 WwanSvc - ok
16:41:31.0783 6188 ================ Scan global ===============================
16:41:31.0803 6188 [ BA0CD8C393E8C9F83354106093832C7B ] C:\windows\system32\basesrv.dll
16:41:31.0858 6188 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\windows\system32\winsrv.dll
16:41:31.0863 6188 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\windows\system32\winsrv.dll
16:41:31.0893 6188 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\windows\system32\sxssrv.dll
16:41:31.0943 6188 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\windows\system32\services.exe
16:41:31.0948 6188 [Global] - ok
16:41:31.0948 6188 ================ Scan MBR ==================================
16:41:31.0968 6188 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
16:41:32.0393 6188 \Device\Harddisk0\DR0 - ok
16:41:32.0684 6188 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
16:41:32.0994 6188 \Device\Harddisk1\DR1 - ok
16:41:32.0994 6188 ================ Scan VBR ==================================
16:41:32.0994 6188 [ A90DB433A797AC1333DBF83B49756D5A ] \Device\Harddisk0\DR0\Partition1
16:41:32.0999 6188 \Device\Harddisk0\DR0\Partition1 - ok
16:41:33.0009 6188 [ 0D3617B7C3E54F8CCC90237C9724B42D ] \Device\Harddisk0\DR0\Partition2
16:41:33.0009 6188 \Device\Harddisk0\DR0\Partition2 - ok
16:41:33.0034 6188 [ 38585A458B5BEBBFCF4C35E168ADA7DE ] \Device\Harddisk0\DR0\Partition3
16:41:33.0039 6188 \Device\Harddisk0\DR0\Partition3 - ok
16:41:33.0044 6188 [ 85927DF768A233C23AA566341B04DC5B ] \Device\Harddisk1\DR1\Partition1
16:41:33.0044 6188 \Device\Harddisk1\DR1\Partition1 - ok
16:41:33.0044 6188 ============================================================
16:41:33.0044 6188 Scan finished
16:41:33.0044 6188 ============================================================
16:41:33.0054 6500 Detected object count: 0
16:41:33.0054 6500 Actual detected object count: 0

And the ESET scan

14e555.rbf a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.10 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.11 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.12 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.13 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.14 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.15 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.16 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.17 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.5 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.6 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.7 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.8 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\Common Files\Spigot\wtxpcom\components\WidgiToolbarFF.dll.9 a variant of Win32/Toolbar.Widgi application
C:\Program Files (x86)\YTD Toolbar\IE\6.3\ytdToolbarIE.dll a variant of Win32/Toolbar.Widgi application
C:\ProgramData\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application
C:\Users\All Users\Tarma Installer\{2E1037EA-038A-425F-86B9-6CD19B8497E9}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application
C:\Users\Spencer\AppData\Local\Google\Chrome\User Data\Default\Default\aadfdadjgddbdagcdfgedagbdedhgbgf\background.html Win32/BHO.OEI trojan
C:\Users\Spencer\AppData\Local\Google\Chrome\User Data\Default\Default\aadfdadjgddbdagcdfgedagbdedhgbgf\ContentScript.js Win32/BHO.OEI trojan
C:\Users\Spencer\AppData\Local\{D3E208BB-01B7-11E2-8271-B8AC6F996F26}\chrome\content\browser.xul JS/Redirector.NIQ trojan
C:\Users\Spencer\AppData\Roaming\Mozilla\Firefox\Profiles\np8yxx6e.default\extensions\mafxpbtnkz@mafxpbtnkz.org.xpi JS/Redirector.NCA trojan
C:\Users\Spencer\Documents\Main Hacking Tools\Cheat Engine 6\cheatengine-i386.exe a variant of Win32/HackTool.CheatEngine.AB application
C:\Users\Spencer\Documents\Main Hacking Tools\Cheat Engine 6\dbk32.sys probably a variant of Win32/HackTool.CheatEngine.AA application
C:\Users\Spencer\Downloads\OrbitDownloaderSetup.exe Win32/OpenCandy application
C:\Windows\Installer\139b34e6.msi a variant of Win32/Toolbar.Widgi application
H:\$RECYCLE.BIN\S-1-5-21-3820014931-1602163007-988893026-1000\$RCDE5MD\Backup Set 2012-03-15 183533\Backup Files 2012-03-15 183533\Backup files 11.zip a variant of Win32/Adware.Yontoo.B application
H:\$RECYCLE.BIN\S-1-5-21-3820014931-1602163007-988893026-1000\$RCDE5MD\Backup Set 2012-03-15 183533\Backup Files 2012-03-15 183533\Backup files 5.zip multiple threats
H:\$RECYCLE.BIN\S-1-5-21-3820014931-1602163007-988893026-1000\$RCDE5MD\Backup Set 2012-03-15 183533\Backup Files 2012-03-15 183533\Backup files 6.zip multiple threats
H:\Jeff Johnson-Underground Training Lab\Bonus DVD.rar JS/Tivso.Gen trojan
H:\Jeff Johnson-Underground Training Lab\legal\terms_disclaimer.html JS/Tivso.Gen trojan
H:\Jeff Johnson-Underground Training Lab\legal\terms_earnings.html JS/Tivso.Gen trojan
H:\Jeff Johnson-Underground Training Lab\legal\terms_privacy.html JS/Tivso.Gen trojan
H:\Jeff Johnson-Underground Training Lab\legal\terms_tos.html JS/Tivso.Gen trojan
H:\Transfer\Jeff Johnson-Underground Training Lab\Bonus DVD.rar JS/Tivso.Gen trojan
H:\Transfer\Jeff Johnson-Underground Training Lab\legal\terms_disclaimer.html JS/Tivso.Gen trojan
H:\Transfer\Jeff Johnson-Underground Training Lab\legal\terms_earnings.html JS/Tivso.Gen trojan
H:\Transfer\Jeff Johnson-Underground Training Lab\legal\terms_privacy.html JS/Tivso.Gen trojan
H:\Transfer\Jeff Johnson-Underground Training Lab\legal\terms_tos.html JS/Tivso.Gen trojan
H:\Transfer5\Image-Line.FL.Studio.Edition.v10.0.0 @vAin4us\flstudio_10.0.exe Win32/OpenCandy application

It scanned my external USB drive as well, the H drive. Looking at it, Ive decided I wont be so torrent happy as I used to be in the past. Damn.

Awaiting further instruction.

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:17 PM

Posted 01 October 2012 - 09:45 PM

OK, sorry I could not be back sooner.
Does it still redirect?


Yes torrents are so loaded with malware. That's why it's free they give you free stuff loaded with info stealing viruses.
Now there are legitimate uses of torrents most people are not doing that and get infected.

This is the longer post I usually give on this matter to educate users.
What Is a Torrent Site and Are They Dangerous?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 SafetyBox

SafetyBox
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 02 October 2012 - 08:07 PM

No more redirects at the moment. Sometimes, it goes away for a day or two but then comes back. If I dont post back in 5 days we can assume its gone for good.

Thanks for the help! I definitely cleaned alot of stuff out of my system.

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:17 PM

Posted 02 October 2012 - 08:41 PM

You're welcome. If all is good after that time then you should Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users