Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Getting random redirects


  • Please log in to reply
13 replies to this topic

#1 csixtyfour

csixtyfour

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 22 October 2012 - 07:28 PM

Ok, to start, last Thursday I decided I wanted to play Aliens vs Predator 2 again. I installed the app (store bought version) but didn't get around to playing it. I shut my computer down and didn't think much about it.

The next day I booted up and got 2 messages. One was a Windows popup related to wmscr.dll and the other was Avast saying something was detected and a boot time scan was needed.

I rebooted and let the scan run. Three files were found. The 1st was a trojan java:agent-bxy and the other 2 were PUP ELF: Androot-J and Looter-H. The last 2 were from either my attempts to root my Nook or my phone.

Afterwards I booted up and ran a full Avast scan plus a full rootkit scan, no issues were found.

I got online with Firefox and started getting random redirects. After some Google searches, I found the proxy settings in Firefox had changed. I switched it back to No Proxy. I then ran both Spybot and malware-bytes, no issues found. Everything seemed to be working fine.

Over the weekend I played some AvP 2. Afterwards, I started getting random redirects. I checked the proxy, still set to no proxy.

I booted into safemode and ran full Avast, Malwarebytes and Spybot but found no issues. Checked my router, seeing a bunch of port 13 outgoing in the log, not sure if its related.

I'm still experiencing some random redirects. I really don't know if the AvP 2 install has anything to do with it but it's really the only thing I have done in the last couple months.

I need some help figuring out what is going on. I am using windows 7.

Edited by csixtyfour, 22 October 2012 - 07:30 PM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 22 October 2012 - 07:39 PM

Welcome csixtyfour

Lets look at a couple morelogs and see what we get.

Posted Image Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.



Please Download

TDSSkiller


Launch it. Click on change parameters-Select TDLFS file system

Click on "Scan".
Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results.



Please download MiniToolBox, save it to your desktop and run it.Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 22 October 2012 - 08:14 PM

JRT:

Junkware Removal Tool (JRT) by Thisisu
Version: 1.2.0 (10.22.2012)
OS: Windows 7 Professional x86
Ran by Seth on Mon 10/22/2012 at 20:57:37.86
Blog: http://thisisudax.blogspot.com
**************************************************************




*** Services: 0 Detections



*** Registry Values: 0 Detections



*** Registry Keys:

Successfully deleted: [KEY] "hkey_current_user\software\appdatalow\software\conduit"
Successfully deleted: [KEY] "hkey_current_user\software\appdatalow\software\smartbar"
Successfully deleted: [KEY] "hkey_current_user\software\appdatalow\toolbar"
Successfully deleted: [KEY] "hkey_current_user\software\conduit"
Successfully deleted: [KEY] "hkey_local_machine\software\conduit"
Successfully deleted: [KEY] hkey_classes_root\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1}



*** Files:

Successfully deleted: [FILE] C:\Program Files\conduit\community alerts\Alert.dll



*** Folders:

Successfully deleted: [FOLDER] "C:\Users\Seth\appdata\local\conduit"
Successfully deleted: [FOLDER] "C:\Users\Seth\appdata\locallow\conduit"
Successfully deleted: [FOLDER] "C:\Program Files\conduit"



*** FireFox detected and repaired

Successfully deleted: [conduit.xml] from C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\9gfgde3z.default\searchplugins
Removed the following from [prefs.js] :

user_pref("browser.search.defaulturl", "http://search.conduit.com/ResultsExt.aspx?ctid=CT2611275&SearchSource=3&q={searchTerms}");


*** Event Viewer Logs - Cleared





**************************************************************
Scan was completed on Mon 10/22/2012 at 21:11:04.80
End of Report

#4 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 22 October 2012 - 08:16 PM

TDSSkiller:

21:15:04.0265 5168 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
21:15:04.0670 5168 ============================================================
21:15:04.0670 5168 Current date / time: 2012/10/22 21:15:04.0670
21:15:04.0670 5168 SystemInfo:
21:15:04.0670 5168
21:15:04.0670 5168 OS Version: 6.1.7600 ServicePack: 0.0
21:15:04.0670 5168 Product type: Workstation
21:15:04.0670 5168 ComputerName: SETH-PC
21:15:04.0670 5168 UserName: Seth
21:15:04.0670 5168 Windows directory: C:\Windows
21:15:04.0670 5168 System windows directory: C:\Windows
21:15:04.0670 5168 Processor architecture: Intel x86
21:15:04.0670 5168 Number of processors: 2
21:15:04.0670 5168 Page size: 0x1000
21:15:04.0670 5168 Boot type: Normal boot
21:15:04.0670 5168 ============================================================
21:15:05.0809 5168 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
21:15:05.0825 5168 ============================================================
21:15:05.0825 5168 \Device\Harddisk0\DR0:
21:15:05.0825 5168 MBR partitions:
21:15:05.0825 5168 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
21:15:05.0825 5168 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x7530000
21:15:05.0825 5168 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x7562800, BlocksNum 0x15C62000
21:15:05.0825 5168 ============================================================
21:15:05.0872 5168 C: <-> \Device\Harddisk0\DR0\Partition2
21:15:05.0903 5168 E: <-> \Device\Harddisk0\DR0\Partition3
21:15:05.0903 5168 ============================================================
21:15:05.0903 5168 Initialize success
21:15:05.0903 5168 ============================================================
21:15:29.0006 3992 ============================================================
21:15:29.0006 3992 Scan started
21:15:29.0006 3992 Mode: Manual; TDLFS;
21:15:29.0006 3992 ============================================================
21:15:30.0582 3992 ================ Scan system memory ========================
21:15:30.0582 3992 System memory - ok
21:15:30.0582 3992 ================ Scan services =============================
21:15:30.0769 3992 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
21:15:30.0785 3992 1394ohci - ok
21:15:30.0800 3992 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
21:15:30.0800 3992 ACPI - ok
21:15:30.0816 3992 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
21:15:30.0832 3992 AcpiPmi - ok
21:15:30.0847 3992 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
21:15:30.0863 3992 adp94xx - ok
21:15:30.0878 3992 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
21:15:30.0878 3992 adpahci - ok
21:15:30.0894 3992 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
21:15:30.0910 3992 adpu320 - ok
21:15:30.0941 3992 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:15:30.0941 3992 AeLookupSvc - ok
21:15:30.0988 3992 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\Windows\system32\drivers\afd.sys
21:15:30.0988 3992 AFD - ok
21:15:31.0003 3992 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
21:15:31.0003 3992 agp440 - ok
21:15:31.0034 3992 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
21:15:31.0034 3992 aic78xx - ok
21:15:31.0066 3992 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
21:15:31.0066 3992 ALG - ok
21:15:31.0081 3992 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
21:15:31.0097 3992 aliide - ok
21:15:31.0097 3992 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
21:15:31.0097 3992 amdagp - ok
21:15:31.0112 3992 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
21:15:31.0112 3992 amdide - ok
21:15:31.0128 3992 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
21:15:31.0128 3992 AmdK8 - ok
21:15:31.0144 3992 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
21:15:31.0144 3992 AmdPPM - ok
21:15:31.0175 3992 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\Windows\system32\drivers\amdsata.sys
21:15:31.0190 3992 amdsata - ok
21:15:31.0206 3992 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
21:15:31.0206 3992 amdsbs - ok
21:15:31.0222 3992 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\Windows\system32\drivers\amdxata.sys
21:15:31.0222 3992 amdxata - ok
21:15:31.0237 3992 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
21:15:31.0253 3992 AppID - ok
21:15:31.0268 3992 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
21:15:31.0268 3992 AppIDSvc - ok
21:15:31.0284 3992 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
21:15:31.0284 3992 Appinfo - ok
21:15:31.0378 3992 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
21:15:31.0378 3992 Apple Mobile Device - ok
21:15:31.0424 3992 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
21:15:31.0424 3992 AppMgmt - ok
21:15:31.0471 3992 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
21:15:31.0471 3992 arc - ok
21:15:31.0487 3992 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
21:15:31.0502 3992 arcsas - ok
21:15:31.0534 3992 [ 054DF24C92B55427E0757CFFF160E4F2 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
21:15:31.0534 3992 aswFsBlk - ok
21:15:31.0549 3992 [ 258143605E77E4008F1758481D6A977D ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
21:15:31.0565 3992 aswMonFlt - ok
21:15:31.0565 3992 [ 352D5A48EBAB35A7693B048679304831 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
21:15:31.0565 3992 aswRdr - ok
21:15:31.0596 3992 [ 8D34D2B24297E27D93E847319ABFDEC4 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
21:15:31.0596 3992 aswSnx - ok
21:15:31.0612 3992 [ 010012597333DA1F46C3243F33F8409E ] aswSP C:\Windows\system32\drivers\aswSP.sys
21:15:31.0612 3992 aswSP - ok
21:15:31.0643 3992 [ F9F84364416658E9786235904D448D37 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
21:15:31.0643 3992 aswTdi - ok
21:15:31.0658 3992 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:15:31.0658 3992 AsyncMac - ok
21:15:31.0674 3992 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
21:15:31.0674 3992 atapi - ok
21:15:31.0705 3992 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:15:31.0721 3992 AudioEndpointBuilder - ok
21:15:31.0736 3992 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
21:15:31.0736 3992 Audiosrv - ok
21:15:31.0768 3992 [ 996E6D052438E8D8DFD501F31560B2E0 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
21:15:31.0783 3992 avast! Antivirus - ok
21:15:31.0799 3992 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
21:15:31.0799 3992 AxInstSV - ok
21:15:31.0830 3992 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
21:15:31.0830 3992 b06bdrv - ok
21:15:31.0861 3992 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
21:15:31.0861 3992 b57nd60x - ok
21:15:31.0955 3992 [ F9CE9B5E049EFC66B8E6C73C18EE8438 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
21:15:32.0017 3992 BCM43XX - ok
21:15:32.0033 3992 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
21:15:32.0033 3992 BDESVC - ok
21:15:32.0048 3992 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
21:15:32.0048 3992 Beep - ok
21:15:32.0095 3992 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
21:15:32.0095 3992 BFE - ok
21:15:32.0142 3992 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\System32\qmgr.dll
21:15:32.0158 3992 BITS - ok
21:15:32.0158 3992 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
21:15:32.0173 3992 blbdrive - ok
21:15:32.0236 3992 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
21:15:32.0251 3992 Bonjour Service - ok
21:15:32.0298 3992 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:15:32.0298 3992 bowser - ok
21:15:32.0329 3992 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
21:15:32.0329 3992 BrFiltLo - ok
21:15:32.0345 3992 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
21:15:32.0345 3992 BrFiltUp - ok
21:15:32.0376 3992 [ 598E1280E7FF3744F4B8329366CC5635 ] Browser C:\Windows\System32\browser.dll
21:15:32.0376 3992 Browser - ok
21:15:32.0407 3992 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
21:15:32.0407 3992 Brserid - ok
21:15:32.0423 3992 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
21:15:32.0423 3992 BrSerWdm - ok
21:15:32.0423 3992 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
21:15:32.0438 3992 BrUsbMdm - ok
21:15:32.0438 3992 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
21:15:32.0438 3992 BrUsbSer - ok
21:15:32.0454 3992 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
21:15:32.0454 3992 BTHMODEM - ok
21:15:32.0485 3992 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
21:15:32.0501 3992 bthserv - ok
21:15:32.0532 3992 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:15:32.0532 3992 cdfs - ok
21:15:32.0563 3992 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:15:32.0563 3992 cdrom - ok
21:15:32.0594 3992 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
21:15:32.0594 3992 CertPropSvc - ok
21:15:32.0610 3992 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
21:15:32.0626 3992 circlass - ok
21:15:32.0641 3992 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
21:15:32.0641 3992 CLFS - ok
21:15:32.0704 3992 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:15:32.0719 3992 clr_optimization_v2.0.50727_32 - ok
21:15:32.0766 3992 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:15:32.0782 3992 clr_optimization_v4.0.30319_32 - ok
21:15:32.0782 3992 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
21:15:32.0782 3992 CmBatt - ok
21:15:32.0813 3992 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
21:15:32.0813 3992 cmdide - ok
21:15:32.0844 3992 [ 36C252E474B2FFA0F0FBBFF20D92A640 ] CNG C:\Windows\system32\Drivers\cng.sys
21:15:32.0844 3992 CNG - ok
21:15:32.0860 3992 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
21:15:32.0875 3992 Compbatt - ok
21:15:32.0891 3992 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
21:15:32.0891 3992 CompositeBus - ok
21:15:32.0906 3992 COMSysApp - ok
21:15:32.0922 3992 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
21:15:32.0922 3992 crcdisk - ok
21:15:32.0953 3992 [ 9C231178CE4FB385F4B54B0A9080B8A4 ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:15:32.0953 3992 CryptSvc - ok
21:15:32.0984 3992 [ 27C9490BDD0AE48911AB8CF1932591ED ] CSC C:\Windows\system32\drivers\csc.sys
21:15:33.0000 3992 CSC - ok
21:15:33.0000 3992 [ 56FB5F222EA30D3D3FC459879772CB73 ] CscService C:\Windows\System32\cscsvc.dll
21:15:33.0016 3992 CscService - ok
21:15:33.0062 3992 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
21:15:33.0078 3992 DcomLaunch - ok
21:15:33.0094 3992 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
21:15:33.0109 3992 defragsvc - ok
21:15:33.0140 3992 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:15:33.0140 3992 DfsC - ok
21:15:33.0156 3992 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
21:15:33.0172 3992 Dhcp - ok
21:15:33.0187 3992 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
21:15:33.0203 3992 discache - ok
21:15:33.0234 3992 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
21:15:33.0234 3992 Disk - ok
21:15:33.0250 3992 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:15:33.0265 3992 Dnscache - ok
21:15:33.0281 3992 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
21:15:33.0281 3992 dot3svc - ok
21:15:33.0296 3992 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
21:15:33.0312 3992 DPS - ok
21:15:33.0343 3992 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:15:33.0343 3992 drmkaud - ok
21:15:33.0374 3992 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:15:33.0390 3992 DXGKrnl - ok
21:15:33.0406 3992 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
21:15:33.0406 3992 EapHost - ok
21:15:33.0515 3992 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
21:15:33.0577 3992 ebdrv - ok
21:15:33.0593 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\Windows\System32\lsass.exe
21:15:33.0593 3992 EFS - ok
21:15:33.0655 3992 [ 1697C39978CD69F6FBC15302EDCECE1F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:15:33.0686 3992 ehRecvr - ok
21:15:33.0702 3992 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
21:15:33.0718 3992 ehSched - ok
21:15:33.0764 3992 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
21:15:33.0780 3992 elxstor - ok
21:15:33.0842 3992 [ 8FE6AB59CAB8F2C038FEA9522A5EEBA7 ] EPSON_PM_RPCV4_01 C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXE
21:15:33.0842 3992 EPSON_PM_RPCV4_01 - ok
21:15:33.0874 3992 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
21:15:33.0874 3992 ErrDev - ok
21:15:33.0920 3992 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
21:15:33.0920 3992 EventSystem - ok
21:15:33.0952 3992 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
21:15:33.0952 3992 exfat - ok
21:15:33.0983 3992 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:15:33.0983 3992 fastfat - ok
21:15:34.0014 3992 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
21:15:34.0030 3992 Fax - ok
21:15:34.0030 3992 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
21:15:34.0030 3992 fdc - ok
21:15:34.0045 3992 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
21:15:34.0045 3992 fdPHost - ok
21:15:34.0061 3992 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
21:15:34.0061 3992 FDResPub - ok
21:15:34.0076 3992 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:15:34.0076 3992 FileInfo - ok
21:15:34.0092 3992 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:15:34.0092 3992 Filetrace - ok
21:15:34.0108 3992 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
21:15:34.0108 3992 flpydisk - ok
21:15:34.0123 3992 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:15:34.0123 3992 FltMgr - ok
21:15:34.0154 3992 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\Windows\system32\FntCache.dll
21:15:34.0170 3992 FontCache - ok
21:15:34.0232 3992 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:15:34.0232 3992 FontCache3.0.0.0 - ok
21:15:34.0279 3992 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
21:15:34.0279 3992 FsDepends - ok
21:15:34.0295 3992 [ A574B4360E438977038AAE4BF60D79A2 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:15:34.0295 3992 Fs_Rec - ok
21:15:34.0326 3992 [ DAFBD9FE39197495AED6D51F3B85B5D2 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
21:15:34.0326 3992 fvevol - ok
21:15:34.0357 3992 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
21:15:34.0357 3992 gagp30kx - ok
21:15:34.0388 3992 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
21:15:34.0388 3992 GEARAspiWDM - ok
21:15:34.0435 3992 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
21:15:34.0435 3992 gpsvc - ok
21:15:34.0466 3992 [ F058C5F64DFF28A2C8D7D1D04171E604 ] guardian2 C:\Windows\system32\Drivers\oz776.sys
21:15:34.0482 3992 guardian2 - ok
21:15:34.0544 3992 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
21:15:34.0560 3992 gupdate - ok
21:15:34.0560 3992 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
21:15:34.0560 3992 gupdatem - ok
21:15:34.0591 3992 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
21:15:34.0591 3992 hcw85cir - ok
21:15:34.0622 3992 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:15:34.0622 3992 HdAudAddService - ok
21:15:34.0654 3992 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
21:15:34.0654 3992 HDAudBus - ok
21:15:34.0669 3992 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
21:15:34.0685 3992 HidBatt - ok
21:15:34.0700 3992 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
21:15:34.0700 3992 HidBth - ok
21:15:34.0700 3992 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
21:15:34.0716 3992 HidIr - ok
21:15:34.0732 3992 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
21:15:34.0732 3992 hidserv - ok
21:15:34.0747 3992 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:15:34.0747 3992 HidUsb - ok
21:15:34.0747 3992 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
21:15:34.0763 3992 hkmsvc - ok
21:15:34.0763 3992 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
21:15:34.0778 3992 HomeGroupListener - ok
21:15:34.0794 3992 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
21:15:34.0810 3992 HomeGroupProvider - ok
21:15:34.0825 3992 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
21:15:34.0825 3992 HpSAMD - ok
21:15:34.0872 3992 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:15:34.0872 3992 HTTP - ok
21:15:34.0888 3992 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
21:15:34.0888 3992 hwpolicy - ok
21:15:34.0919 3992 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
21:15:34.0919 3992 i8042prt - ok
21:15:34.0950 3992 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
21:15:34.0950 3992 iaStorV - ok
21:15:34.0997 3992 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:15:35.0028 3992 idsvc - ok
21:15:35.0137 3992 [ 9467514EA189475A6E7FDC5D7BDE9D3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
21:15:35.0231 3992 igfx - ok
21:15:35.0278 3992 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
21:15:35.0278 3992 iirsp - ok
21:15:35.0340 3992 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
21:15:35.0356 3992 IKEEXT - ok
21:15:35.0371 3992 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
21:15:35.0371 3992 intelide - ok
21:15:35.0403 3992 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
21:15:35.0403 3992 intelppm - ok
21:15:35.0418 3992 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:15:35.0434 3992 IPBusEnum - ok
21:15:35.0449 3992 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:15:35.0449 3992 IpFilterDriver - ok
21:15:35.0465 3992 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:15:35.0481 3992 iphlpsvc - ok
21:15:35.0496 3992 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
21:15:35.0496 3992 IPMIDRV - ok
21:15:35.0512 3992 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
21:15:35.0512 3992 IPNAT - ok
21:15:35.0543 3992 [ 49918803B661367023BF325CF602AFDC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
21:15:35.0559 3992 iPod Service - ok
21:15:35.0590 3992 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:15:35.0590 3992 IRENUM - ok
21:15:35.0605 3992 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
21:15:35.0605 3992 isapnp - ok
21:15:35.0621 3992 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
21:15:35.0621 3992 iScsiPrt - ok
21:15:35.0668 3992 [ 08A811BFD207DFDEC588881C18BACBAA ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
21:15:35.0668 3992 ISWKL - ok
21:15:35.0683 3992 [ 5B2CCEF06F96DFB22893AB8F0B3F891D ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
21:15:35.0699 3992 IswSvc - ok
21:15:35.0715 3992 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
21:15:35.0730 3992 kbdclass - ok
21:15:35.0746 3992 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
21:15:35.0746 3992 kbdhid - ok
21:15:35.0777 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\Windows\system32\lsass.exe
21:15:35.0777 3992 KeyIso - ok
21:15:35.0793 3992 [ 0263364ACB9C834ACE52FB85C2C064EC ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:15:35.0808 3992 KSecDD - ok
21:15:35.0808 3992 [ 27391DB553BE2A4E2B0ADEEA2873B2AF ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
21:15:35.0824 3992 KSecPkg - ok
21:15:35.0855 3992 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
21:15:35.0855 3992 KtmRm - ok
21:15:35.0886 3992 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\Windows\system32\srvsvc.dll
21:15:35.0902 3992 LanmanServer - ok
21:15:35.0917 3992 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:15:35.0933 3992 LanmanWorkstation - ok
21:15:35.0980 3992 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:15:35.0980 3992 lltdio - ok
21:15:35.0995 3992 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:15:36.0011 3992 lltdsvc - ok
21:15:36.0011 3992 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
21:15:36.0027 3992 lmhosts - ok
21:15:36.0058 3992 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
21:15:36.0058 3992 LSI_FC - ok
21:15:36.0073 3992 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
21:15:36.0073 3992 LSI_SAS - ok
21:15:36.0089 3992 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
21:15:36.0089 3992 LSI_SAS2 - ok
21:15:36.0105 3992 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
21:15:36.0105 3992 LSI_SCSI - ok
21:15:36.0120 3992 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
21:15:36.0120 3992 luafv - ok
21:15:36.0151 3992 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:15:36.0151 3992 Mcx2Svc - ok
21:15:36.0167 3992 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
21:15:36.0167 3992 megasas - ok
21:15:36.0198 3992 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
21:15:36.0198 3992 MegaSR - ok
21:15:36.0229 3992 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
21:15:36.0229 3992 MMCSS - ok
21:15:36.0245 3992 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
21:15:36.0245 3992 Modem - ok
21:15:36.0276 3992 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:15:36.0276 3992 monitor - ok
21:15:36.0307 3992 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:15:36.0307 3992 mouclass - ok
21:15:36.0323 3992 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:15:36.0323 3992 mouhid - ok
21:15:36.0354 3992 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
21:15:36.0354 3992 mountmgr - ok
21:15:36.0417 3992 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
21:15:36.0417 3992 MozillaMaintenance - ok
21:15:36.0463 3992 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
21:15:36.0463 3992 mpio - ok
21:15:36.0479 3992 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:15:36.0479 3992 mpsdrv - ok
21:15:36.0510 3992 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
21:15:36.0526 3992 MpsSvc - ok
21:15:36.0541 3992 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:15:36.0541 3992 MRxDAV - ok
21:15:36.0573 3992 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:15:36.0573 3992 mrxsmb - ok
21:15:36.0588 3992 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:15:36.0588 3992 mrxsmb10 - ok
21:15:36.0619 3992 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:15:36.0635 3992 mrxsmb20 - ok
21:15:36.0651 3992 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
21:15:36.0651 3992 msahci - ok
21:15:36.0682 3992 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
21:15:36.0682 3992 msdsm - ok
21:15:36.0697 3992 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
21:15:36.0713 3992 MSDTC - ok
21:15:36.0729 3992 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:15:36.0744 3992 Msfs - ok
21:15:36.0744 3992 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
21:15:36.0760 3992 mshidkmdf - ok
21:15:36.0760 3992 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
21:15:36.0760 3992 msisadrv - ok
21:15:36.0807 3992 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:15:36.0807 3992 MSiSCSI - ok
21:15:36.0807 3992 msiserver - ok
21:15:36.0838 3992 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:15:36.0838 3992 MSKSSRV - ok
21:15:36.0853 3992 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:15:36.0853 3992 MSPCLOCK - ok
21:15:36.0869 3992 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:15:36.0869 3992 MSPQM - ok
21:15:36.0885 3992 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:15:36.0885 3992 MsRPC - ok
21:15:36.0900 3992 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
21:15:36.0900 3992 mssmbios - ok
21:15:36.0900 3992 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:15:36.0916 3992 MSTEE - ok
21:15:36.0916 3992 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
21:15:36.0916 3992 MTConfig - ok
21:15:36.0931 3992 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
21:15:36.0931 3992 Mup - ok
21:15:36.0963 3992 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
21:15:36.0963 3992 napagent - ok
21:15:37.0009 3992 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:15:37.0009 3992 NativeWifiP - ok
21:15:37.0041 3992 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:15:37.0041 3992 NDIS - ok
21:15:37.0056 3992 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
21:15:37.0072 3992 NdisCap - ok
21:15:37.0087 3992 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:15:37.0087 3992 NdisTapi - ok
21:15:37.0103 3992 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:15:37.0103 3992 Ndisuio - ok
21:15:37.0119 3992 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:15:37.0119 3992 NdisWan - ok
21:15:37.0134 3992 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:15:37.0134 3992 NDProxy - ok
21:15:37.0134 3992 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:15:37.0134 3992 NetBIOS - ok
21:15:37.0150 3992 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
21:15:37.0150 3992 NetBT - ok
21:15:37.0165 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\Windows\system32\lsass.exe
21:15:37.0181 3992 Netlogon - ok
21:15:37.0228 3992 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
21:15:37.0228 3992 Netman - ok
21:15:37.0243 3992 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
21:15:37.0259 3992 netprofm - ok
21:15:37.0275 3992 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
21:15:37.0275 3992 NetTcpPortSharing - ok
21:15:37.0306 3992 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
21:15:37.0306 3992 nfrd960 - ok
21:15:37.0321 3992 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
21:15:37.0337 3992 NlaSvc - ok
21:15:37.0353 3992 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:15:37.0353 3992 Npfs - ok
21:15:37.0353 3992 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
21:15:37.0368 3992 nsi - ok
21:15:37.0368 3992 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:15:37.0368 3992 nsiproxy - ok
21:15:37.0431 3992 [ 187002CE05693C306F43C873F821381F ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:15:37.0446 3992 Ntfs - ok
21:15:37.0477 3992 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
21:15:37.0477 3992 Null - ok
21:15:37.0524 3992 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:15:37.0524 3992 nvraid - ok
21:15:37.0555 3992 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:15:37.0555 3992 nvstor - ok
21:15:37.0571 3992 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
21:15:37.0571 3992 nv_agp - ok
21:15:37.0587 3992 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
21:15:37.0602 3992 ohci1394 - ok
21:15:37.0618 3992 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
21:15:37.0633 3992 p2pimsvc - ok
21:15:37.0649 3992 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
21:15:37.0665 3992 p2psvc - ok
21:15:37.0680 3992 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
21:15:37.0680 3992 Parport - ok
21:15:37.0696 3992 [ FF4218952B51DE44FE910953A3E686B9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:15:37.0696 3992 partmgr - ok
21:15:37.0711 3992 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
21:15:37.0711 3992 Parvdm - ok
21:15:37.0727 3992 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
21:15:37.0743 3992 PcaSvc - ok
21:15:37.0758 3992 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
21:15:37.0758 3992 pci - ok
21:15:37.0774 3992 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
21:15:37.0774 3992 pciide - ok
21:15:37.0774 3992 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
21:15:37.0789 3992 pcmcia - ok
21:15:37.0789 3992 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
21:15:37.0805 3992 pcw - ok
21:15:37.0821 3992 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:15:37.0836 3992 PEAUTH - ok
21:15:37.0867 3992 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
21:15:37.0899 3992 PeerDistSvc - ok
21:15:37.0930 3992 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
21:15:37.0977 3992 pla - ok
21:15:38.0023 3992 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:15:38.0023 3992 PlugPlay - ok
21:15:38.0055 3992 [ 3A2BDD76E7D2A5F40A7174793D1BA794 ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
21:15:38.0055 3992 PnkBstrA - ok
21:15:38.0070 3992 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
21:15:38.0086 3992 PNRPAutoReg - ok
21:15:38.0101 3992 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
21:15:38.0101 3992 PNRPsvc - ok
21:15:38.0133 3992 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:15:38.0133 3992 PolicyAgent - ok
21:15:38.0164 3992 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
21:15:38.0179 3992 Power - ok
21:15:38.0211 3992 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:15:38.0211 3992 PptpMiniport - ok
21:15:38.0226 3992 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
21:15:38.0226 3992 Processor - ok
21:15:38.0257 3992 [ 630CF26F0227498B7D5A92B12548960F ] ProfSvc C:\Windows\system32\profsvc.dll
21:15:38.0257 3992 ProfSvc - ok
21:15:38.0273 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:15:38.0273 3992 ProtectedStorage - ok
21:15:38.0304 3992 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
21:15:38.0304 3992 Psched - ok
21:15:38.0351 3992 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
21:15:38.0367 3992 ql2300 - ok
21:15:38.0398 3992 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
21:15:38.0398 3992 ql40xx - ok
21:15:38.0429 3992 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
21:15:38.0429 3992 QWAVE - ok
21:15:38.0445 3992 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:15:38.0445 3992 QWAVEdrv - ok
21:15:38.0460 3992 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:15:38.0460 3992 RasAcd - ok
21:15:38.0491 3992 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
21:15:38.0507 3992 RasAgileVpn - ok
21:15:38.0507 3992 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
21:15:38.0523 3992 RasAuto - ok
21:15:38.0523 3992 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:15:38.0523 3992 Rasl2tp - ok
21:15:38.0554 3992 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
21:15:38.0554 3992 RasMan - ok
21:15:38.0569 3992 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:15:38.0569 3992 RasPppoe - ok
21:15:38.0585 3992 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:15:38.0585 3992 RasSstp - ok
21:15:38.0601 3992 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:15:38.0616 3992 rdbss - ok
21:15:38.0632 3992 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
21:15:38.0632 3992 rdpbus - ok
21:15:38.0647 3992 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:15:38.0647 3992 RDPCDD - ok
21:15:38.0679 3992 [ C5FF95883FFEF704D50C40D21CFB3AB5 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
21:15:38.0679 3992 RDPDR - ok
21:15:38.0694 3992 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:15:38.0694 3992 RDPENCDD - ok
21:15:38.0710 3992 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
21:15:38.0710 3992 RDPREFMP - ok
21:15:38.0741 3992 [ 0399C725A9C95A6F1862B93F008DDF4A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:15:38.0741 3992 RDPWD - ok
21:15:38.0757 3992 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
21:15:38.0757 3992 rdyboost - ok
21:15:38.0788 3992 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
21:15:38.0788 3992 RemoteAccess - ok
21:15:38.0819 3992 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:15:38.0819 3992 RemoteRegistry - ok
21:15:38.0850 3992 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
21:15:38.0850 3992 RpcEptMapper - ok
21:15:38.0866 3992 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
21:15:38.0866 3992 RpcLocator - ok
21:15:38.0897 3992 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
21:15:38.0897 3992 RpcSs - ok
21:15:38.0913 3992 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:15:38.0928 3992 rspndr - ok
21:15:38.0944 3992 [ 5423D8437051E89DD34749F242C98648 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
21:15:38.0944 3992 s3cap - ok
21:15:38.0959 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\Windows\system32\lsass.exe
21:15:38.0959 3992 SamSs - ok
21:15:38.0991 3992 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
21:15:38.0991 3992 sbp2port - ok
21:15:39.0006 3992 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:15:39.0022 3992 SCardSvr - ok
21:15:39.0037 3992 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
21:15:39.0037 3992 scfilter - ok
21:15:39.0069 3992 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\Windows\system32\schedsvc.dll
21:15:39.0100 3992 Schedule - ok
21:15:39.0115 3992 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
21:15:39.0115 3992 SCPolicySvc - ok
21:15:39.0131 3992 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:15:39.0147 3992 SDRSVC - ok
21:15:39.0178 3992 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:15:39.0178 3992 secdrv - ok
21:15:39.0193 3992 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
21:15:39.0193 3992 seclogon - ok
21:15:39.0209 3992 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
21:15:39.0209 3992 SENS - ok
21:15:39.0240 3992 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
21:15:39.0240 3992 SensrSvc - ok
21:15:39.0271 3992 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
21:15:39.0271 3992 Serenum - ok
21:15:39.0287 3992 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
21:15:39.0287 3992 Serial - ok
21:15:39.0303 3992 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
21:15:39.0303 3992 sermouse - ok
21:15:39.0318 3992 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
21:15:39.0334 3992 SessionEnv - ok
21:15:39.0349 3992 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
21:15:39.0349 3992 sffdisk - ok
21:15:39.0365 3992 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
21:15:39.0365 3992 sffp_mmc - ok
21:15:39.0381 3992 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
21:15:39.0396 3992 sffp_sd - ok
21:15:39.0412 3992 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
21:15:39.0412 3992 sfloppy - ok
21:15:39.0427 3992 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:15:39.0443 3992 SharedAccess - ok
21:15:39.0459 3992 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:15:39.0474 3992 ShellHWDetection - ok
21:15:39.0474 3992 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
21:15:39.0474 3992 sisagp - ok
21:15:39.0505 3992 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
21:15:39.0505 3992 SiSRaid2 - ok
21:15:39.0521 3992 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
21:15:39.0521 3992 SiSRaid4 - ok
21:15:39.0537 3992 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:15:39.0552 3992 Smb - ok
21:15:39.0568 3992 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:15:39.0583 3992 SNMPTRAP - ok
21:15:39.0599 3992 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
21:15:39.0599 3992 spldr - ok
21:15:39.0630 3992 [ D1BB750EB51694DE183E08B9C33BE5B2 ] Spooler C:\Windows\System32\spoolsv.exe
21:15:39.0630 3992 Spooler - ok
21:15:39.0724 3992 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
21:15:39.0786 3992 sppsvc - ok
21:15:39.0786 3992 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
21:15:39.0802 3992 sppuinotify - ok
21:15:39.0833 3992 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\Windows\system32\DRIVERS\srv.sys
21:15:39.0833 3992 srv - ok
21:15:39.0849 3992 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:15:39.0849 3992 srv2 - ok
21:15:39.0880 3992 [ E00FDFAFF025E94F9821153750C35A6D ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL3.SYS
21:15:39.0895 3992 SrvHsfHDA - ok
21:15:39.0927 3992 [ CEB4E3B6890E1E42DCA6694D9E59E1A0 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV3.SYS
21:15:39.0942 3992 SrvHsfV92 - ok
21:15:39.0973 3992 [ BC0C7EA89194C299F051C24119000E17 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
21:15:39.0973 3992 SrvHsfWinac - ok
21:15:39.0989 3992 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:15:39.0989 3992 srvnet - ok
21:15:40.0020 3992 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:15:40.0036 3992 SSDPSRV - ok
21:15:40.0036 3992 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:15:40.0051 3992 SstpSvc - ok
21:15:40.0067 3992 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
21:15:40.0067 3992 stexstor - ok
21:15:40.0114 3992 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
21:15:40.0145 3992 StiSvc - ok
21:15:40.0176 3992 [ 957E346CA948668F2496A6CCF6FF82CC ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
21:15:40.0176 3992 storflt - ok
21:15:40.0207 3992 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll
21:15:40.0223 3992 StorSvc - ok
21:15:40.0239 3992 [ D5751969DC3E4B88BF482AC8EC9FE019 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
21:15:40.0239 3992 storvsc - ok
21:15:40.0270 3992 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
21:15:40.0270 3992 swenum - ok
21:15:40.0285 3992 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
21:15:40.0301 3992 swprv - ok
21:15:40.0348 3992 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
21:15:40.0379 3992 SysMain - ok
21:15:40.0395 3992 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:15:40.0395 3992 TabletInputService - ok
21:15:40.0410 3992 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
21:15:40.0410 3992 TapiSrv - ok
21:15:40.0426 3992 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
21:15:40.0426 3992 TBS - ok
21:15:40.0473 3992 [ 56C198AC82EFA622DD93E9E43575F79C ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:15:40.0504 3992 Tcpip - ok
21:15:40.0519 3992 [ 56C198AC82EFA622DD93E9E43575F79C ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
21:15:40.0535 3992 TCPIP6 - ok
21:15:40.0551 3992 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:15:40.0551 3992 tcpipreg - ok
21:15:40.0582 3992 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:15:40.0582 3992 TDPIPE - ok
21:15:40.0597 3992 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:15:40.0597 3992 TDTCP - ok
21:15:40.0613 3992 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:15:40.0613 3992 tdx - ok
21:15:40.0629 3992 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
21:15:40.0629 3992 TermDD - ok
21:15:40.0644 3992 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\Windows\System32\termsrv.dll
21:15:40.0675 3992 TermService - ok
21:15:40.0675 3992 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
21:15:40.0691 3992 Themes - ok
21:15:40.0707 3992 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
21:15:40.0707 3992 THREADORDER - ok
21:15:40.0722 3992 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
21:15:40.0738 3992 TrkWks - ok
21:15:40.0769 3992 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:15:40.0785 3992 TrustedInstaller - ok
21:15:40.0800 3992 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:15:40.0800 3992 tssecsrv - ok
21:15:40.0847 3992 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:15:40.0847 3992 tunnel - ok
21:15:40.0878 3992 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
21:15:40.0878 3992 uagp35 - ok
21:15:40.0894 3992 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:15:40.0909 3992 udfs - ok
21:15:40.0941 3992 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:15:40.0941 3992 UI0Detect - ok
21:15:40.0956 3992 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
21:15:40.0972 3992 uliagpkx - ok
21:15:40.0987 3992 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:15:40.0987 3992 umbus - ok
21:15:41.0003 3992 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
21:15:41.0003 3992 UmPass - ok
21:15:41.0034 3992 [ 8ECACA5454844F66386F7BE4AE0D7CD1 ] UmRdpService C:\Windows\System32\umrdp.dll
21:15:41.0034 3992 UmRdpService - ok
21:15:41.0050 3992 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
21:15:41.0065 3992 upnphost - ok
21:15:41.0081 3992 [ C31AE588E403042632DC796CF09E30B0 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
21:15:41.0081 3992 usbccgp - ok
21:15:41.0097 3992 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
21:15:41.0112 3992 usbcir - ok
21:15:41.0128 3992 [ E4C436D914768CE965D5E659BA7EEBD8 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
21:15:41.0128 3992 usbehci - ok
21:15:41.0143 3992 [ BDCD7156EC37448F08633FD899823620 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:15:41.0143 3992 usbhub - ok
21:15:41.0159 3992 [ EB2D819A639015253C871CDA09D91D58 ] usbohci C:\Windows\system32\drivers\usbohci.sys
21:15:41.0159 3992 usbohci - ok
21:15:41.0190 3992 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:15:41.0190 3992 usbprint - ok
21:15:41.0206 3992 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:15:41.0221 3992 usbscan - ok
21:15:41.0237 3992 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:15:41.0237 3992 USBSTOR - ok
21:15:41.0253 3992 [ 22480BF4E5A09192E5E30BA4DDE79FA4 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
21:15:41.0253 3992 usbuhci - ok
21:15:41.0284 3992 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
21:15:41.0284 3992 UxSms - ok
21:15:41.0299 3992 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\Windows\system32\lsass.exe
21:15:41.0299 3992 VaultSvc - ok
21:15:41.0331 3992 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
21:15:41.0331 3992 vdrvroot - ok
21:15:41.0346 3992 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
21:15:41.0362 3992 vds - ok
21:15:41.0377 3992 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:15:41.0377 3992 vga - ok
21:15:41.0377 3992 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
21:15:41.0393 3992 VgaSave - ok
21:15:41.0409 3992 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
21:15:41.0409 3992 vhdmp - ok
21:15:41.0424 3992 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
21:15:41.0440 3992 viaagp - ok
21:15:41.0440 3992 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
21:15:41.0440 3992 ViaC7 - ok
21:15:41.0455 3992 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
21:15:41.0455 3992 viaide - ok
21:15:41.0487 3992 [ 379B349F65F453D2A6E75EA6B7448E49 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
21:15:41.0487 3992 vmbus - ok
21:15:41.0502 3992 [ EC2BBAB4B84D0738C6C83D2234DC36FE ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
21:15:41.0502 3992 VMBusHID - ok
21:15:41.0518 3992 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
21:15:41.0518 3992 volmgr - ok
21:15:41.0533 3992 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:15:41.0533 3992 volmgrx - ok
21:15:41.0549 3992 [ 58DF9D2481A56EDDE167E51B334D44FD ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
21:15:41.0549 3992 volsnap - ok
21:15:41.0580 3992 [ 6292C794BA68E0F46A6D45468461AFE1 ] Vsdatant C:\Windows\system32\DRIVERS\vsdatant.sys
21:15:41.0580 3992 Vsdatant - ok
21:15:41.0611 3992 vsmon - ok
21:15:41.0643 3992 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
21:15:41.0643 3992 vsmraid - ok
21:15:41.0674 3992 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
21:15:41.0705 3992 VSS - ok
21:15:41.0721 3992 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
21:15:41.0721 3992 vwifibus - ok
21:15:41.0752 3992 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
21:15:41.0752 3992 vwififlt - ok
21:15:41.0783 3992 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
21:15:41.0799 3992 W32Time - ok
21:15:41.0814 3992 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
21:15:41.0830 3992 WacomPen - ok
21:15:41.0845 3992 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
21:15:41.0845 3992 WANARP - ok
21:15:41.0845 3992 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:15:41.0845 3992 Wanarpv6 - ok
21:15:41.0892 3992 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
21:15:41.0923 3992 WatAdminSvc - ok
21:15:41.0955 3992 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
21:15:41.0986 3992 wbengine - ok
21:15:42.0001 3992 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
21:15:42.0017 3992 WbioSrvc - ok
21:15:42.0048 3992 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:15:42.0048 3992 wcncsvc - ok
21:15:42.0079 3992 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:15:42.0079 3992 WcsPlugInService - ok
21:15:42.0111 3992 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
21:15:42.0111 3992 Wd - ok
21:15:42.0126 3992 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:15:42.0142 3992 Wdf01000 - ok
21:15:42.0142 3992 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:15:42.0157 3992 WdiServiceHost - ok
21:15:42.0157 3992 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:15:42.0173 3992 WdiSystemHost - ok
21:15:42.0204 3992 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\Windows\System32\webclnt.dll
21:15:42.0204 3992 WebClient - ok
21:15:42.0220 3992 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:15:42.0220 3992 Wecsvc - ok
21:15:42.0235 3992 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:15:42.0251 3992 wercplsupport - ok
21:15:42.0267 3992 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
21:15:42.0282 3992 WerSvc - ok
21:15:42.0298 3992 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
21:15:42.0298 3992 WfpLwf - ok
21:15:42.0345 3992 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
21:15:42.0345 3992 WIMMount - ok
21:15:42.0407 3992 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
21:15:42.0423 3992 WinDefend - ok
21:15:42.0438 3992 WinHttpAutoProxySvc - ok
21:15:42.0501 3992 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:15:42.0516 3992 Winmgmt - ok
21:15:42.0563 3992 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
21:15:42.0610 3992 WinRM - ok
21:15:42.0641 3992 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys
21:15:42.0657 3992 WinUsb - ok
21:15:42.0688 3992 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
21:15:42.0719 3992 Wlansvc - ok
21:15:42.0750 3992 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
21:15:42.0750 3992 WmiAcpi - ok
21:15:42.0766 3992 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:15:42.0766 3992 wmiApSrv - ok
21:15:42.0859 3992 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
21:15:42.0875 3992 WMPNetworkSvc - ok
21:15:42.0891 3992 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:15:42.0891 3992 WPCSvc - ok
21:15:42.0906 3992 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:15:42.0906 3992 WPDBusEnum - ok
21:15:42.0937 3992 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:15:42.0953 3992 ws2ifsl - ok
21:15:42.0969 3992 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\Windows\System32\wscsvc.dll
21:15:42.0969 3992 wscsvc - ok
21:15:42.0969 3992 WSearch - ok
21:15:43.0047 3992 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
21:15:43.0093 3992 wuauserv - ok
21:15:43.0093 3992 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:15:43.0109 3992 WudfPf - ok
21:15:43.0125 3992 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:15:43.0125 3992 WUDFRd - ok
21:15:43.0140 3992 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:15:43.0156 3992 wudfsvc - ok
21:15:43.0171 3992 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
21:15:43.0171 3992 WwanSvc - ok
21:15:43.0187 3992 ================ Scan global ===============================
21:15:43.0218 3992 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
21:15:43.0234 3992 [ 008F51AE989C3DF1CBAF8B39DC423CCC ] C:\Windows\system32\winsrv.dll
21:15:43.0249 3992 [ 008F51AE989C3DF1CBAF8B39DC423CCC ] C:\Windows\system32\winsrv.dll
21:15:43.0281 3992 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
21:15:43.0312 3992 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
21:15:43.0327 3992 [Global] - ok
21:15:43.0327 3992 ================ Scan MBR ==================================
21:15:43.0327 3992 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
21:15:43.0795 3992 \Device\Harddisk0\DR0 - ok
21:15:43.0795 3992 ================ Scan VBR ==================================
21:15:43.0811 3992 [ 6B311931DCC9F83EA93C09EFB58190B6 ] \Device\Harddisk0\DR0\Partition1
21:15:43.0811 3992 \Device\Harddisk0\DR0\Partition1 - ok
21:15:43.0842 3992 [ 657479A07D9759C61A8B24C753C8CE0A ] \Device\Harddisk0\DR0\Partition2
21:15:43.0842 3992 \Device\Harddisk0\DR0\Partition2 - ok
21:15:43.0873 3992 [ 325F40056B0EE3F3447FA501DC6EA54F ] \Device\Harddisk0\DR0\Partition3
21:15:43.0873 3992 \Device\Harddisk0\DR0\Partition3 - ok
21:15:43.0873 3992 ============================================================
21:15:43.0873 3992 Scan finished
21:15:43.0873 3992 ============================================================
21:15:43.0905 4520 Detected object count: 0
21:15:43.0905 4520 Actual detected object count: 0

#5 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 22 October 2012 - 08:22 PM

MiniToolBox:

MiniToolBox by Farbar Version: 23-07-2012
Ran by Seth (administrator) on 22-10-2012 at 21:17:49
Microsoft Windows 7 Professional (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================

"network.proxy.type", 0

"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================


127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com

There are 15273 more lines starting with "127.0.0.1"

========================= IP Configuration: ================================

Broadcom NetXtreme 57xx Gigabit Controller = Local Area Connection (Connected)
Dell Wireless 1390 WLAN Mini-Card = Wireless Network Connection (Hardware not present)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Seth-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller
Physical Address. . . . . . . . . : 00-21-70-D1-9E-4B
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::b53e:41f9:6b40:1e61%11(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.104(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Monday, October 22, 2012 5:20:25 PM
Lease Expires . . . . . . . . . . : Tuesday, October 23, 2012 6:43:59 PM
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 234889584
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-BE-6D-E9-00-21-70-D1-9E-4B
DNS Servers . . . . . . . . . . . : 68.94.156.1
68.94.157.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{F8093BB8-17AB-4A29-825F-D5F75BBD88D3}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 9:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6ab8:88:3bdc:9ce0:f1ba(Preferred)
Link-local IPv6 Address . . . . . : fe80::88:3bdc:9ce0:f1ba%14(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: dnsr1.sbcglobal.net
Address: 68.94.156.1

Name: google.com
Addresses: 2607:f8b0:4009:800::1004
74.125.225.37
74.125.225.38
74.125.225.39
74.125.225.40
74.125.225.41
74.125.225.46
74.125.225.32
74.125.225.33
74.125.225.34
74.125.225.35
74.125.225.36


Pinging google.com [74.125.225.41] with 32 bytes of data:
Reply from 74.125.225.41: bytes=32 time=15ms TTL=55
Reply from 74.125.225.41: bytes=32 time=16ms TTL=55

Ping statistics for 74.125.225.41:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 15ms, Maximum = 16ms, Average = 15ms
Server: dnsr1.sbcglobal.net
Address: 68.94.156.1

Name: yahoo.com
Addresses: 72.30.38.140
98.138.253.109
98.139.183.24


Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
Reply from 98.138.253.109: bytes=32 time=82ms TTL=48
Reply from 98.138.253.109: bytes=32 time=132ms TTL=49

Ping statistics for 98.138.253.109:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 82ms, Maximum = 132ms, Average = 107ms
Server: dnsr1.sbcglobal.net
Address: 68.94.156.1

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Request timed out.
Request timed out.

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
===========================================================================
Interface List
11...00 21 70 d1 9e 4b ......Broadcom NetXtreme 57xx Gigabit Controller
1...........................Software Loopback Interface 1
15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
14...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.104 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.104 276
192.168.1.104 255.255.255.255 On-link 192.168.1.104 276
192.168.1.255 255.255.255.255 On-link 192.168.1.104 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.104 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.104 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
14 58 ::/0 On-link
1 306 ::1/128 On-link
14 58 2001::/32 On-link
14 306 2001:0:9d38:6ab8:88:3bdc:9ce0:f1ba/128
On-link
11 276 fe80::/64 On-link
14 306 fe80::/64 On-link
14 306 fe80::88:3bdc:9ce0:f1ba/128
On-link
11 276 fe80::b53e:41f9:6b40:1e61/128
On-link
1 306 ff00::/8 On-link
14 306 ff00::/8 On-link
11 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\system32\NLAapi.dll [51712] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 04 C:\Windows\system32\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 05 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 06 C:\Windows\system32\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [232448] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================

System errors:
=============

Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

3DVIA player 5.0 (Version: 5.0.0.15)
Adobe Flash Player 11 ActiveX (Version: 11.3.300.265)
Adobe Flash Player 11 Plugin (Version: 11.1.102.55)
Aliens vs. Predator 2
Amazon MP3 Downloader 1.0.17 (Version: 1.0.17)
Apple Application Support (Version: 2.1.6)
Apple Mobile Device Support (Version: 4.0.0.97)
Apple Software Update (Version: 2.1.3.127)
avast! Free Antivirus (Version: 6.0.1367.0)
Battlefield Heroes
BitTorrent (Version: 7.6.1)
BitTorrentBar Toolbar (Version: 6.8.9.0)
Bonjour (Version: 3.0.0.10)
CCleaner (Version: 3.15)
DHTML Editing Component (Version: 6.02.0001)
DivX Web Player (Version: 1.5.0)
Dropbox (Version: 1.4.7)
DVD Shrink 3.2
DVDFab 8.1.6.0 (01/02/2012) Qt
EPSON Printer Software
EPSON Scan
FileZilla Client 3.5.3 (Version: 3.5.3)
Foxit Reader 5.1 (Version: 5.1.4.104)
Freemake Video Converter version 3.0.1 (Version: 3.0.1)
GameSpy Arcade
GIMP 2.8.0 (Version: 2.8.0)
Google Chrome (Version: 22.0.1229.94)
Google Drive (Version: 1.4.3365.1552)
Google Update Helper (Version: 1.3.21.123)
HandBrake 0.9.5 (Version: 0.9.5)
Intel® Graphics Media Accelerator Driver (Version: 8.15.10.1930)
Intel® TV Wizard
iTunes (Version: 10.5.3.3)
LastPass (uninstall only)
Malwarebytes Anti-Malware version 1.65.1.1000 (Version: 1.65.1.1000)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Mozilla Firefox 14.0.1 (x86 en-US) (Version: 14.0.1)
Mozilla Maintenance Service (Version: 14.0.1)
Mozilla Thunderbird 14.0 (x86 en-US) (Version: 14.0)
Netflix in Windows Media Center (Version: 3.3.101.0)
OpenOffice.org 3.3 (Version: 3.3.9567)
PunkBuster Services (Version: 0.990)
SDFormatter (Version: 3.1.0)
Spybot - Search & Destroy (Version: 1.6.2)
Trillian
Turbo Lister 2 (Version: 2.00.0000)
Unity Web Player (Version: )
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
VC 9.0 Runtime (Version: 1.0.0)
VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0)
VLC media player 1.1.11 (Version: 1.1.11)
ZoneAlarm Firewall (Version: 10.1.079.000)
ZoneAlarm Free (Version: 10.1.079.000)
ZoneAlarm Security (Version: 10.1.079.000)
ZoneAlarm Toolbar

========================= Memory info: ===================================

Percentage of memory in use: 40%
Total physical RAM: 2037.97 MB
Available physical RAM: 1207.98 MB
Total Pagefile: 4075.94 MB
Available Pagefile: 2947.93 MB
Total Virtual: 2047.88 MB
Available Virtual: 1936.95 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:58.59 GB) (Free:14.16 GB) NTFS
2 Drive d: (AvP2_1) (CDROM) (Total:0.54 GB) (Free:0 GB) CDFS
3 Drive e: (DATA) (Fixed) (Total:174.19 GB) (Free:20.73 GB) NTFS

========================= Users: ========================================

User accounts for \\SETH-PC

Administrator Grace Guest
Seth


**** End of log ****

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 22 October 2012 - 10:28 PM

How are the redirects?
Is Firefox your usual browser?
I suspect torrent downloads are the source of your infection.



Please download AdwCleaner by Xplode onto your desktop.


[list]
[*]Close all open programs and internet browsers.
[*]Double click on adwcleaner.exe to run the tool.
[*]Click on Delete.
[*]Confirm each time with Ok.
[*]You will be prompted to restart your computer. A text file will open after the restart.
[*]Please post the contents of that logfile with your next reply.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 23 October 2012 - 05:19 AM

The redirects are still happening.
Yes, Firefox is my usual browser.
Torrent downloads? I know BitTorrent is on my computer though I forget why. I am fairly certain, outside of opening it, I've never used the program.

AdwCleaner:

# AdwCleaner v2.005 - Logfile created 10/23/2012 at 06:05:01
# Updated 14/10/2012 by Xplode
# Operating system : Windows 7 Professional (32 bits)
# User : Seth - SETH-PC
# Boot Mode : Normal
# Running from : C:\Users\Seth\Downloads\AdwCleaner(1).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Program Files\BitTorrentBar
Folder Deleted : C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
Folder Deleted : C:\Users\Seth\AppData\LocalLow\BitTorrentBar

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\BitTorrentBar
Key Deleted : HKCU\Software\Google\Chrome\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Key Deleted : HKLM\Software\BitTorrentBar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{32804100-B238-45F4-B15E-C5A2F2F7400B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mhfdcmehmjcclgopdodkjdicohagipid
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{85C5AD3A-F566-4E05-9C48-5BCA497A9BEA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C581BBAF-BE64-4FC4-96B8-CE076903E48D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{88C7F2AA-F93F-432C-8F0E-B7D85967A527}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{32804100-B238-45F4-B15E-C5A2F2F7400B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\incredibar.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\incredibar.com
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrentBar Toolbar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{88C7F2AA-F93F-432C-8F0E-B7D85967A527}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (en-US)

Profile name : default
File : C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\iql3mo3f.default\prefs.js

[OK] File is clean.

Profile name : Default User
File : C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\en2ivr00.TES_APRIL2011\prefs.js

[OK] File is clean.

Profile name : SETH-MAIN [Profil par défaut]
File : C:\Users\Seth\AppData\Roaming\Mozilla\Firefox\Profiles\9gfgde3z.default\prefs.js

Deleted : user_pref("browser.search.defaultthis.engineName", "ZoneAlarm Customized Web Search");

Profile name : default
File : C:\Users\Grace\AppData\Roaming\Mozilla\Firefox\Profiles\ys5qs6wt.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v22.0.1229.94

File : C:\Users\Seth\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [3998 octets] - [23/10/2012 06:05:01]

########## EOF - C:\AdwCleaner[S1].txt - [4058 octets] ##########

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 23 October 2012 - 10:44 AM

In FireFox it may be the Add ons/Plugins. try disabling them one at a time and see which one was at fault.

How to disable extensions and plugins

Keeping your third-party plugins up to date
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 23 October 2012 - 07:20 PM

I haven't disabled anything but so far, not having any issues.

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 23 October 2012 - 09:09 PM

OK,I wasn't sure if they stopped.

If all is well...Create a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been backed up, renamed and saved in System Restore. Since this is a protected directory your tools cannot access to delete these files, they sometimes can reinfect your system if you accidentally use an old restore point. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Posted Image > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name, then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then use Disk Cleanup to remove all but the most recently created Restore Point.
  • Go to Posted Image > Run... and type: Cleanmgr
  • Click "Ok". Disk Cleanup will scan your files for several minutes, then open.
  • Click the "More Options" tab, then click the "Clean up" button under System Restore.
  • Click Ok. You will be prompted with "Are you sure you want to delete all but the most recent restore point?"
  • Click Yes, then click Ok.
  • Click Yes again when prompted with "Are you sure you want to perform these actions?"
  • Disk Cleanup will remove the files and close automatically.
Vista and Windows 7 users can refer to these links:

Edited by boopme, 23 October 2012 - 09:11 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 24 October 2012 - 05:40 AM

And it's back. I'll have to try disabling later when I return. Seems I cannot use the same search terms. Once I get a redirect from one, it doesn't redirect a second time.

Edited by csixtyfour, 24 October 2012 - 05:49 AM.


#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 24 October 2012 - 01:25 PM

Try post 8.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 csixtyfour

csixtyfour
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 24 October 2012 - 04:18 PM

Just for reference, I booted up and logged in. I got 2 popups again.

1st:

RunDLL
The was a problem starting c:\users\seth\appdata\roaming\ubrent.dll

Operation did not complete successfully because the file contains a virus.

2nd is an Avast popup stating to finish the cleanup process, a boot-time scan is recommended.


I'm not doing anything with either of these. The file isn't in the location.

Should I allow the boot-time scan?

I went ahead and tried disabling, but could not recreate the issue. Re-enabled, still could not recreate.

Edited by csixtyfour, 24 October 2012 - 05:27 PM.


#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,490 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:05:28 PM

Posted 24 October 2012 - 08:04 PM

Hello, the boot scan is Avast seeing something (maybe?) wrong and wants to verify. So I would allow it.

Since this involves RUNDLL may have an infection, I think we should get a deeper look. Please follow this Preparation Guide and post in a new topic.
If Gmer won't run,skip it.

Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users