Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

The Curious Case of The Google Re-Direct


  • Please log in to reply
3 replies to this topic

#1 TheJord

TheJord

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 31 October 2012 - 10:55 AM

Hi all,

Long time-lurker here, really helpful site. *Coos*

My tech unsavvy uncle has shoved his laptop onto me telling me it's "broken". To my knowledge, the problem is that his browser (both IE and Firefox) redirect to other websites (mainly eBay). It seems this only happens via links and Google and manually entering a URL by-passes the problem. Malware Bytes, TDSSKiller, Adaware have been tried. I believe as well as ComboFix.

I've also had trouble doing a HiJackThis scan. I'm having problems saving the log file. ("No Internet Connection Available", even though it is.)

Any help or advice on how to proceed would be much appreciated.
Thank you.

Edited by hamluis, 31 October 2012 - 12:14 PM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:04:57 AM

Posted 31 October 2012 - 10:19 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here.If you get crashes in normal mode,run it in safemode with networking

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 TheJord

TheJord
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 04 November 2012 - 11:45 AM

TDSS KILLER

16:29:39.0599 4920 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
16:29:40.0130 4920 ============================================================
16:29:40.0130 4920 Current date / time: 2012/11/04 16:29:40.0130
16:29:40.0146 4920 SystemInfo:
16:29:40.0146 4920
16:29:40.0146 4920 OS Version: 6.1.7601 ServicePack: 1.0
16:29:40.0146 4920 Product type: Workstation
16:29:40.0146 4920 ComputerName: CRAOG-TOSH
16:29:40.0146 4920 UserName: craog
16:29:40.0146 4920 Windows directory: C:\Windows
16:29:40.0146 4920 System windows directory: C:\Windows
16:29:40.0146 4920 Running under WOW64
16:29:40.0146 4920 Processor architecture: Intel x64
16:29:40.0146 4920 Number of processors: 2
16:29:40.0146 4920 Page size: 0x1000
16:29:40.0146 4920 Boot type: Normal boot
16:29:40.0146 4920 ============================================================
16:29:42.0938 4920 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:29:42.0954 4920 ============================================================
16:29:42.0954 4920 \Device\Harddisk0\DR0:
16:29:42.0954 4920 MBR partitions:
16:29:42.0954 4920 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xC8800, BlocksNum 0x3A2BC800
16:29:42.0954 4920 ============================================================
16:29:42.0985 4920 C: <-> \Device\Harddisk0\DR0\Partition1
16:29:42.0985 4920 ============================================================
16:29:42.0985 4920 Initialize success
16:29:42.0985 4920 ============================================================
16:29:56.0697 3040 ============================================================
16:29:56.0697 3040 Scan started
16:29:56.0697 3040 Mode: Manual; TDLFS;
16:29:56.0697 3040 ============================================================
16:29:58.0101 3040 ================ Scan system memory ========================
16:29:58.0101 3040 System memory - ok
16:29:58.0101 3040 ================ Scan services =============================
16:29:58.0351 3040 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
16:29:58.0367 3040 1394ohci - ok
16:29:58.0429 3040 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
16:29:58.0429 3040 ACPI - ok
16:29:58.0476 3040 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
16:29:58.0476 3040 AcpiPmi - ok
16:29:58.0757 3040 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:29:58.0757 3040 AdobeFlashPlayerUpdateSvc - ok
16:29:58.0850 3040 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
16:29:58.0866 3040 adp94xx - ok
16:29:58.0928 3040 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
16:29:58.0944 3040 adpahci - ok
16:29:58.0959 3040 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
16:29:58.0975 3040 adpu320 - ok
16:29:59.0022 3040 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
16:29:59.0037 3040 AeLookupSvc - ok
16:29:59.0115 3040 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
16:29:59.0131 3040 AFD - ok
16:29:59.0193 3040 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
16:29:59.0209 3040 agp440 - ok
16:29:59.0256 3040 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
16:29:59.0271 3040 ALG - ok
16:29:59.0303 3040 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
16:29:59.0303 3040 aliide - ok
16:29:59.0365 3040 [ 310F88A93C3B02E3D1F906FB57B9E01E ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
16:29:59.0381 3040 AMD External Events Utility - ok
16:29:59.0412 3040 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
16:29:59.0412 3040 amdide - ok
16:29:59.0443 3040 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
16:29:59.0443 3040 AmdK8 - ok
16:29:59.0771 3040 [ 62DDF55680F8C53E4B8DDE4189ADA0B8 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
16:30:00.0020 3040 amdkmdag - ok
16:30:00.0083 3040 [ 51F027DFFEDFB8D763FABFFA06B56E6D ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
16:30:00.0083 3040 amdkmdap - ok
16:30:00.0145 3040 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
16:30:00.0161 3040 AmdPPM - ok
16:30:00.0207 3040 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
16:30:00.0207 3040 amdsata - ok
16:30:00.0239 3040 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
16:30:00.0239 3040 amdsbs - ok
16:30:00.0270 3040 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
16:30:00.0270 3040 amdxata - ok
16:30:00.0317 3040 [ 8A2B4818215D8A6FF54DC3F0D63CBB2D ] amd_sata C:\Windows\system32\DRIVERS\amd_sata.sys
16:30:00.0317 3040 amd_sata - ok
16:30:00.0332 3040 [ A2D8977623E13591B15F6370C6CC37B0 ] amd_xata C:\Windows\system32\DRIVERS\amd_xata.sys
16:30:00.0332 3040 amd_xata - ok
16:30:00.0395 3040 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
16:30:00.0410 3040 AppID - ok
16:30:00.0441 3040 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
16:30:00.0441 3040 AppIDSvc - ok
16:30:00.0473 3040 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
16:30:00.0473 3040 Appinfo - ok
16:30:00.0597 3040 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:30:00.0597 3040 Apple Mobile Device - ok
16:30:00.0660 3040 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
16:30:00.0660 3040 arc - ok
16:30:00.0691 3040 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
16:30:00.0707 3040 arcsas - ok
16:30:00.0738 3040 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
16:30:00.0738 3040 AsyncMac - ok
16:30:00.0800 3040 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
16:30:00.0800 3040 atapi - ok
16:30:00.0925 3040 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
16:30:00.0941 3040 AudioEndpointBuilder - ok
16:30:01.0003 3040 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
16:30:01.0019 3040 AudioSrv - ok
16:30:01.0065 3040 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
16:30:01.0081 3040 AxInstSV - ok
16:30:01.0112 3040 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
16:30:01.0128 3040 b06bdrv - ok
16:30:01.0190 3040 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
16:30:01.0190 3040 b57nd60a - ok
16:30:01.0268 3040 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
16:30:01.0268 3040 BDESVC - ok
16:30:01.0299 3040 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
16:30:01.0299 3040 Beep - ok
16:30:01.0346 3040 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
16:30:01.0362 3040 blbdrive - ok
16:30:01.0455 3040 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
16:30:01.0471 3040 Bonjour Service - ok
16:30:01.0533 3040 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
16:30:01.0533 3040 bowser - ok
16:30:01.0627 3040 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
16:30:01.0627 3040 BrFiltLo - ok
16:30:01.0643 3040 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
16:30:01.0643 3040 BrFiltUp - ok
16:30:01.0689 3040 [ 8EF0D5C41EC907751B8429162B1239ED ] Browser C:\Windows\System32\browser.dll
16:30:01.0689 3040 Browser - ok
16:30:01.0752 3040 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
16:30:01.0752 3040 Brserid - ok
16:30:01.0767 3040 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
16:30:01.0767 3040 BrSerWdm - ok
16:30:01.0783 3040 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
16:30:01.0783 3040 BrUsbMdm - ok
16:30:01.0799 3040 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
16:30:01.0799 3040 BrUsbSer - ok
16:30:01.0814 3040 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
16:30:01.0814 3040 BTHMODEM - ok
16:30:01.0877 3040 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
16:30:01.0892 3040 bthserv - ok
16:30:01.0923 3040 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
16:30:01.0939 3040 cdfs - ok
16:30:01.0986 3040 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
16:30:01.0986 3040 cdrom - ok
16:30:02.0033 3040 [ 7E83E47BD1FF93E11CD69F1AD65A9581 ] CeKbFilter C:\Windows\system32\DRIVERS\CeKbFilter.sys
16:30:02.0033 3040 CeKbFilter - ok
16:30:02.0079 3040 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
16:30:02.0079 3040 CertPropSvc - ok
16:30:02.0189 3040 [ 41E7C4FA6491747402CFCA77CC1C7AAB ] cfWiMAXService C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
16:30:02.0189 3040 cfWiMAXService - ok
16:30:02.0235 3040 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
16:30:02.0235 3040 circlass - ok
16:30:02.0313 3040 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
16:30:02.0313 3040 CLFS - ok
16:30:02.0407 3040 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:30:02.0423 3040 clr_optimization_v2.0.50727_32 - ok
16:30:02.0469 3040 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:30:02.0485 3040 clr_optimization_v2.0.50727_64 - ok
16:30:02.0610 3040 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:30:02.0657 3040 clr_optimization_v4.0.30319_32 - ok
16:30:02.0703 3040 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:30:02.0703 3040 clr_optimization_v4.0.30319_64 - ok
16:30:02.0766 3040 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
16:30:02.0766 3040 CmBatt - ok
16:30:02.0813 3040 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
16:30:02.0813 3040 cmdide - ok
16:30:02.0875 3040 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
16:30:02.0891 3040 CNG - ok
16:30:02.0937 3040 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
16:30:02.0937 3040 Compbatt - ok
16:30:02.0984 3040 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
16:30:03.0000 3040 CompositeBus - ok
16:30:03.0015 3040 COMSysApp - ok
16:30:03.0078 3040 [ CAB0EEAF5295FC96DDD3E19DCE27E131 ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
16:30:03.0078 3040 ConfigFree Service - ok
16:30:03.0125 3040 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
16:30:03.0125 3040 crcdisk - ok
16:30:03.0187 3040 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
16:30:03.0203 3040 CryptSvc - ok
16:30:03.0296 3040 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
16:30:03.0312 3040 DcomLaunch - ok
16:30:03.0437 3040 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
16:30:03.0437 3040 defragsvc - ok
16:30:03.0530 3040 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
16:30:03.0530 3040 DfsC - ok
16:30:03.0702 3040 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
16:30:03.0702 3040 Dhcp - ok
16:30:03.0795 3040 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
16:30:03.0795 3040 discache - ok
16:30:03.0873 3040 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
16:30:03.0889 3040 Disk - ok
16:30:03.0951 3040 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
16:30:03.0967 3040 Dnscache - ok
16:30:04.0014 3040 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
16:30:04.0014 3040 dot3svc - ok
16:30:04.0107 3040 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
16:30:04.0107 3040 DPS - ok
16:30:04.0201 3040 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
16:30:04.0201 3040 drmkaud - ok
16:30:04.0373 3040 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
16:30:04.0388 3040 DXGKrnl - ok
16:30:04.0466 3040 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
16:30:04.0466 3040 EapHost - ok
16:30:04.0653 3040 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
16:30:04.0763 3040 ebdrv - ok
16:30:04.0794 3040 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
16:30:04.0794 3040 EFS - ok
16:30:04.0872 3040 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
16:30:04.0887 3040 ehRecvr - ok
16:30:04.0919 3040 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
16:30:04.0919 3040 ehSched - ok
16:30:04.0997 3040 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
16:30:05.0012 3040 elxstor - ok
16:30:05.0028 3040 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
16:30:05.0028 3040 ErrDev - ok
16:30:05.0121 3040 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
16:30:05.0121 3040 EventSystem - ok
16:30:05.0199 3040 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
16:30:05.0199 3040 exfat - ok
16:30:05.0215 3040 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
16:30:05.0215 3040 fastfat - ok
16:30:05.0293 3040 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
16:30:05.0309 3040 Fax - ok
16:30:05.0324 3040 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
16:30:05.0340 3040 fdc - ok
16:30:05.0387 3040 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
16:30:05.0387 3040 fdPHost - ok
16:30:05.0418 3040 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
16:30:05.0418 3040 FDResPub - ok
16:30:05.0433 3040 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
16:30:05.0449 3040 FileInfo - ok
16:30:05.0465 3040 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
16:30:05.0465 3040 Filetrace - ok
16:30:05.0480 3040 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
16:30:05.0496 3040 flpydisk - ok
16:30:05.0511 3040 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
16:30:05.0511 3040 FltMgr - ok
16:30:05.0636 3040 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
16:30:05.0652 3040 FontCache - ok
16:30:05.0714 3040 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:30:05.0714 3040 FontCache3.0.0.0 - ok
16:30:05.0761 3040 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
16:30:05.0761 3040 FsDepends - ok
16:30:05.0808 3040 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
16:30:05.0808 3040 Fs_Rec - ok
16:30:05.0855 3040 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
16:30:05.0870 3040 fvevol - ok
16:30:05.0933 3040 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
16:30:05.0948 3040 gagp30kx - ok
16:30:05.0979 3040 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:30:05.0979 3040 GEARAspiWDM - ok
16:30:06.0073 3040 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
16:30:06.0089 3040 gpsvc - ok
16:30:06.0151 3040 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
16:30:06.0151 3040 hcw85cir - ok
16:30:06.0213 3040 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
16:30:06.0213 3040 HdAudAddService - ok
16:30:06.0260 3040 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
16:30:06.0276 3040 HDAudBus - ok
16:30:06.0291 3040 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
16:30:06.0291 3040 HidBatt - ok
16:30:06.0307 3040 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
16:30:06.0323 3040 HidBth - ok
16:30:06.0338 3040 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
16:30:06.0338 3040 HidIr - ok
16:30:06.0385 3040 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
16:30:06.0385 3040 hidserv - ok
16:30:06.0447 3040 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
16:30:06.0447 3040 HidUsb - ok
16:30:06.0494 3040 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
16:30:06.0510 3040 hkmsvc - ok
16:30:06.0557 3040 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
16:30:06.0572 3040 HomeGroupListener - ok
16:30:06.0619 3040 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
16:30:06.0635 3040 HomeGroupProvider - ok
16:30:06.0697 3040 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
16:30:06.0713 3040 HpSAMD - ok
16:30:06.0791 3040 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
16:30:06.0806 3040 HTTP - ok
16:30:06.0837 3040 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
16:30:06.0837 3040 hwpolicy - ok
16:30:06.0869 3040 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
16:30:06.0869 3040 i8042prt - ok
16:30:06.0915 3040 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
16:30:06.0931 3040 iaStorV - ok
16:30:07.0056 3040 [ DABFBE88774A3C1A8CEA198348E02740 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
16:30:07.0087 3040 IconMan_R - ok
16:30:07.0165 3040 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:30:07.0181 3040 idsvc - ok
16:30:07.0243 3040 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
16:30:07.0259 3040 iirsp - ok
16:30:07.0337 3040 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
16:30:07.0368 3040 IKEEXT - ok
16:30:07.0524 3040 [ 8BC7EB3BF3FA1C434AA830A50456DD02 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
16:30:07.0555 3040 IntcAzAudAddService - ok
16:30:07.0586 3040 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
16:30:07.0602 3040 intelide - ok
16:30:07.0649 3040 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\drivers\intelppm.sys
16:30:07.0649 3040 intelppm - ok
16:30:07.0695 3040 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
16:30:07.0711 3040 IPBusEnum - ok
16:30:07.0711 3040 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:30:07.0727 3040 IpFilterDriver - ok
16:30:07.0742 3040 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
16:30:07.0742 3040 IPMIDRV - ok
16:30:07.0773 3040 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
16:30:07.0773 3040 IPNAT - ok
16:30:07.0883 3040 [ 755E4BA6DCE627A2683BB7640553C8D6 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
16:30:07.0898 3040 iPod Service - ok
16:30:07.0961 3040 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
16:30:07.0961 3040 IRENUM - ok
16:30:07.0976 3040 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
16:30:07.0976 3040 isapnp - ok
16:30:08.0007 3040 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
16:30:08.0023 3040 iScsiPrt - ok
16:30:08.0070 3040 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
16:30:08.0070 3040 kbdclass - ok
16:30:08.0101 3040 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
16:30:08.0101 3040 kbdhid - ok
16:30:08.0132 3040 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
16:30:08.0132 3040 KeyIso - ok
16:30:08.0179 3040 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
16:30:08.0179 3040 KSecDD - ok
16:30:08.0210 3040 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
16:30:08.0210 3040 KSecPkg - ok
16:30:08.0257 3040 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
16:30:08.0257 3040 ksthunk - ok
16:30:08.0319 3040 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
16:30:08.0335 3040 KtmRm - ok
16:30:08.0413 3040 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
16:30:08.0429 3040 LanmanServer - ok
16:30:08.0475 3040 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
16:30:08.0475 3040 LanmanWorkstation - ok
16:30:08.0569 3040 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
16:30:08.0569 3040 lltdio - ok
16:30:08.0678 3040 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
16:30:08.0694 3040 lltdsvc - ok
16:30:08.0725 3040 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
16:30:08.0725 3040 lmhosts - ok
16:30:08.0772 3040 [ 2825A71E7501CB33B3B9F856610C729D ] LPCFilter C:\Windows\system32\DRIVERS\LPCFilter.sys
16:30:08.0787 3040 LPCFilter - ok
16:30:08.0850 3040 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
16:30:08.0865 3040 LSI_FC - ok
16:30:08.0881 3040 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
16:30:08.0881 3040 LSI_SAS - ok
16:30:08.0912 3040 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
16:30:08.0912 3040 LSI_SAS2 - ok
16:30:08.0928 3040 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
16:30:08.0928 3040 LSI_SCSI - ok
16:30:08.0975 3040 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
16:30:08.0990 3040 luafv - ok
16:30:09.0053 3040 [ 79D51E7F5926E8CE1B3EBECEBAE28CFF ] mcdbus C:\Windows\system32\DRIVERS\mcdbus.sys
16:30:09.0053 3040 mcdbus - ok
16:30:09.0084 3040 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
16:30:09.0084 3040 Mcx2Svc - ok
16:30:09.0115 3040 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
16:30:09.0115 3040 megasas - ok
16:30:09.0162 3040 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
16:30:09.0177 3040 MegaSR - ok
16:30:09.0193 3040 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
16:30:09.0193 3040 MMCSS - ok
16:30:09.0209 3040 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
16:30:09.0225 3040 Modem - ok
16:30:09.0272 3040 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
16:30:09.0272 3040 monitor - ok
16:30:09.0303 3040 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
16:30:09.0303 3040 mouclass - ok
16:30:09.0350 3040 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\drivers\mouhid.sys
16:30:09.0366 3040 mouhid - ok
16:30:09.0381 3040 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
16:30:09.0381 3040 mountmgr - ok
16:30:09.0490 3040 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
16:30:09.0490 3040 MozillaMaintenance - ok
16:30:09.0553 3040 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
16:30:09.0553 3040 mpio - ok
16:30:09.0600 3040 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
16:30:09.0615 3040 mpsdrv - ok
16:30:09.0646 3040 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
16:30:09.0662 3040 MRxDAV - ok
16:30:09.0678 3040 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
16:30:09.0678 3040 mrxsmb - ok
16:30:09.0740 3040 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:30:09.0740 3040 mrxsmb10 - ok
16:30:09.0771 3040 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:30:09.0771 3040 mrxsmb20 - ok
16:30:09.0802 3040 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
16:30:09.0802 3040 msahci - ok
16:30:09.0834 3040 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
16:30:09.0834 3040 msdsm - ok
16:30:09.0849 3040 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
16:30:09.0849 3040 MSDTC - ok
16:30:09.0896 3040 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
16:30:09.0896 3040 Msfs - ok
16:30:09.0912 3040 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
16:30:09.0912 3040 mshidkmdf - ok
16:30:09.0943 3040 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
16:30:09.0943 3040 msisadrv - ok
16:30:09.0990 3040 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
16:30:10.0005 3040 MSiSCSI - ok
16:30:10.0021 3040 msiserver - ok
16:30:10.0052 3040 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
16:30:10.0052 3040 MSKSSRV - ok
16:30:10.0083 3040 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
16:30:10.0099 3040 MSPCLOCK - ok
16:30:10.0099 3040 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
16:30:10.0114 3040 MSPQM - ok
16:30:10.0146 3040 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
16:30:10.0146 3040 MsRPC - ok
16:30:10.0177 3040 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
16:30:10.0177 3040 mssmbios - ok
16:30:10.0224 3040 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
16:30:10.0240 3040 MSTEE - ok
16:30:10.0240 3040 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
16:30:10.0240 3040 MTConfig - ok
16:30:10.0271 3040 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
16:30:10.0271 3040 Mup - ok
16:30:10.0318 3040 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
16:30:10.0334 3040 napagent - ok
16:30:10.0381 3040 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
16:30:10.0381 3040 NativeWifiP - ok
16:30:10.0474 3040 [ 13AA2130F2A104DD775EAD0F0EE5417B ] NAUpdate c:\Program Files (x86)\Nero\Update\NASvc.exe
16:30:10.0490 3040 NAUpdate - ok
16:30:10.0646 3040 [ B498A14133BD09AD0817590ACE4470AD ] NBService C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
16:30:10.0661 3040 NBService - ok
16:30:10.0724 3040 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
16:30:10.0739 3040 NDIS - ok
16:30:10.0786 3040 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
16:30:10.0786 3040 NdisCap - ok
16:30:10.0833 3040 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
16:30:10.0833 3040 NdisTapi - ok
16:30:10.0849 3040 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
16:30:10.0849 3040 Ndisuio - ok
16:30:10.0880 3040 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
16:30:10.0880 3040 NdisWan - ok
16:30:10.0895 3040 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
16:30:10.0895 3040 NDProxy - ok
16:30:10.0911 3040 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
16:30:10.0911 3040 NetBIOS - ok
16:30:10.0942 3040 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
16:30:10.0942 3040 NetBT - ok
16:30:10.0958 3040 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
16:30:10.0958 3040 Netlogon - ok
16:30:11.0020 3040 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
16:30:11.0036 3040 Netman - ok
16:30:11.0051 3040 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
16:30:11.0067 3040 netprofm - ok
16:30:11.0098 3040 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:30:11.0114 3040 NetTcpPortSharing - ok
16:30:11.0161 3040 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
16:30:11.0161 3040 nfrd960 - ok
16:30:11.0223 3040 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
16:30:11.0239 3040 NlaSvc - ok
16:30:11.0427 3040 [ A328A46D87BB92CE4D8A4528E9D84787 ] NMIndexingService C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
16:30:11.0442 3040 NMIndexingService - ok
16:30:11.0489 3040 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
16:30:11.0489 3040 Npfs - ok
16:30:11.0552 3040 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
16:30:11.0552 3040 nsi - ok
16:30:11.0583 3040 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
16:30:11.0583 3040 nsiproxy - ok
16:30:11.0676 3040 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
16:30:11.0723 3040 Ntfs - ok
16:30:11.0739 3040 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
16:30:11.0739 3040 Null - ok
16:30:11.0786 3040 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
16:30:11.0801 3040 nvraid - ok
16:30:11.0801 3040 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
16:30:11.0817 3040 nvstor - ok
16:30:11.0832 3040 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
16:30:11.0848 3040 nv_agp - ok
16:30:11.0879 3040 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
16:30:11.0879 3040 ohci1394 - ok
16:30:11.0926 3040 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
16:30:11.0926 3040 p2pimsvc - ok
16:30:11.0957 3040 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
16:30:11.0973 3040 p2psvc - ok
16:30:11.0988 3040 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
16:30:11.0988 3040 Parport - ok
16:30:12.0020 3040 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
16:30:12.0035 3040 partmgr - ok
16:30:12.0051 3040 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
16:30:12.0066 3040 PcaSvc - ok
16:30:12.0082 3040 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
16:30:12.0082 3040 pci - ok
16:30:12.0098 3040 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\DRIVERS\pciide.sys
16:30:12.0113 3040 pciide - ok
16:30:12.0129 3040 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
16:30:12.0144 3040 pcmcia - ok
16:30:12.0160 3040 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
16:30:12.0160 3040 pcw - ok
16:30:12.0207 3040 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
16:30:12.0222 3040 PEAUTH - ok
16:30:12.0316 3040 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
16:30:12.0332 3040 PerfHost - ok
16:30:12.0410 3040 [ 663962900E7FEA522126BA287715BB4A ] PGEffect C:\Windows\system32\DRIVERS\pgeffect.sys
16:30:12.0410 3040 PGEffect - ok
16:30:12.0488 3040 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
16:30:12.0519 3040 pla - ok
16:30:12.0644 3040 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
16:30:12.0659 3040 PlugPlay - ok
16:30:12.0706 3040 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
16:30:12.0706 3040 PNRPAutoReg - ok
16:30:12.0737 3040 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
16:30:12.0753 3040 PNRPsvc - ok
16:30:12.0815 3040 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
16:30:12.0831 3040 PolicyAgent - ok
16:30:12.0878 3040 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
16:30:12.0878 3040 Power - ok
16:30:12.0940 3040 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
16:30:12.0940 3040 PptpMiniport - ok
16:30:12.0956 3040 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
16:30:12.0971 3040 Processor - ok
16:30:13.0018 3040 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
16:30:13.0018 3040 ProfSvc - ok
16:30:13.0049 3040 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
16:30:13.0049 3040 ProtectedStorage - ok
16:30:13.0112 3040 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
16:30:13.0112 3040 Psched - ok
16:30:13.0221 3040 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
16:30:13.0252 3040 ql2300 - ok
16:30:13.0283 3040 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
16:30:13.0283 3040 ql40xx - ok
16:30:13.0314 3040 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
16:30:13.0314 3040 QWAVE - ok
16:30:13.0330 3040 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
16:30:13.0346 3040 QWAVEdrv - ok
16:30:13.0346 3040 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
16:30:13.0346 3040 RasAcd - ok
16:30:13.0408 3040 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
16:30:13.0408 3040 RasAgileVpn - ok
16:30:13.0439 3040 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
16:30:13.0455 3040 RasAuto - ok
16:30:13.0470 3040 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
16:30:13.0470 3040 Rasl2tp - ok
16:30:13.0517 3040 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
16:30:13.0533 3040 RasMan - ok
16:30:13.0580 3040 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
16:30:13.0580 3040 RasPppoe - ok
16:30:13.0595 3040 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
16:30:13.0595 3040 RasSstp - ok
16:30:13.0642 3040 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
16:30:13.0642 3040 rdbss - ok
16:30:13.0673 3040 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
16:30:13.0673 3040 rdpbus - ok
16:30:13.0689 3040 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
16:30:13.0689 3040 RDPCDD - ok
16:30:13.0720 3040 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
16:30:13.0736 3040 RDPENCDD - ok
16:30:13.0767 3040 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
16:30:13.0767 3040 RDPREFMP - ok
16:30:13.0814 3040 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
16:30:13.0829 3040 RDPWD - ok
16:30:13.0860 3040 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
16:30:13.0876 3040 rdyboost - ok
16:30:13.0923 3040 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
16:30:13.0923 3040 RemoteAccess - ok
16:30:14.0001 3040 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
16:30:14.0001 3040 RemoteRegistry - ok
16:30:14.0032 3040 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
16:30:14.0032 3040 RpcEptMapper - ok
16:30:14.0063 3040 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
16:30:14.0079 3040 RpcLocator - ok
16:30:14.0110 3040 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
16:30:14.0126 3040 RpcSs - ok
16:30:14.0204 3040 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
16:30:14.0204 3040 rspndr - ok
16:30:14.0282 3040 [ 9BEB5F18A418FF70659CE2E356829568 ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
16:30:14.0282 3040 RSUSBSTOR - ok
16:30:14.0360 3040 [ 5D6A444BD37B52FF846387C87DCDF98A ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
16:30:14.0375 3040 RTL8167 - ok
16:30:14.0453 3040 [ FA088015155C4C6DAB5D1D9E68EB9D6B ] RTL8192Ce C:\Windows\system32\DRIVERS\rtl8192Ce.sys
16:30:14.0469 3040 RTL8192Ce - ok
16:30:14.0484 3040 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
16:30:14.0484 3040 SamSs - ok
16:30:14.0500 3040 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
16:30:14.0516 3040 sbp2port - ok
16:30:14.0594 3040 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
16:30:14.0594 3040 SCardSvr - ok
16:30:14.0640 3040 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
16:30:14.0640 3040 scfilter - ok
16:30:14.0703 3040 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
16:30:14.0734 3040 Schedule - ok
16:30:14.0765 3040 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
16:30:14.0765 3040 SCPolicySvc - ok
16:30:14.0812 3040 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
16:30:14.0828 3040 SDRSVC - ok
16:30:14.0874 3040 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
16:30:14.0890 3040 secdrv - ok
16:30:14.0906 3040 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
16:30:14.0921 3040 seclogon - ok
16:30:14.0952 3040 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
16:30:14.0968 3040 SENS - ok
16:30:15.0030 3040 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
16:30:15.0030 3040 SensrSvc - ok
16:30:15.0062 3040 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
16:30:15.0062 3040 Serenum - ok
16:30:15.0108 3040 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
16:30:15.0108 3040 Serial - ok
16:30:15.0140 3040 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
16:30:15.0140 3040 sermouse - ok
16:30:15.0202 3040 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
16:30:15.0218 3040 SessionEnv - ok
16:30:15.0218 3040 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
16:30:15.0233 3040 sffdisk - ok
16:30:15.0233 3040 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
16:30:15.0249 3040 sffp_mmc - ok
16:30:15.0249 3040 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
16:30:15.0264 3040 sffp_sd - ok
16:30:15.0264 3040 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
16:30:15.0280 3040 sfloppy - ok
16:30:15.0311 3040 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
16:30:15.0327 3040 ShellHWDetection - ok
16:30:15.0327 3040 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
16:30:15.0342 3040 SiSRaid2 - ok
16:30:15.0358 3040 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
16:30:15.0358 3040 SiSRaid4 - ok
16:30:15.0452 3040 [ 6128E98EAAED364ED1A32708D2FD22CB ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
16:30:15.0452 3040 SkypeUpdate - ok
16:30:15.0498 3040 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
16:30:15.0498 3040 Smb - ok
16:30:15.0592 3040 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
16:30:15.0608 3040 SNMPTRAP - ok
16:30:15.0623 3040 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
16:30:15.0639 3040 spldr - ok
16:30:15.0686 3040 [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler C:\Windows\System32\spoolsv.exe
16:30:15.0701 3040 Spooler - ok
16:30:15.0795 3040 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
16:30:15.0857 3040 sppsvc - ok
16:30:15.0873 3040 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
16:30:15.0888 3040 sppuinotify - ok
16:30:15.0920 3040 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
16:30:15.0935 3040 srv - ok
16:30:15.0966 3040 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
16:30:15.0966 3040 srv2 - ok
16:30:15.0998 3040 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
16:30:15.0998 3040 srvnet - ok
16:30:16.0044 3040 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
16:30:16.0044 3040 SSDPSRV - ok
16:30:16.0060 3040 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
16:30:16.0060 3040 SstpSvc - ok
16:30:16.0076 3040 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
16:30:16.0091 3040 stexstor - ok
16:30:16.0154 3040 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
16:30:16.0169 3040 stisvc - ok
16:30:16.0200 3040 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
16:30:16.0200 3040 swenum - ok
16:30:16.0247 3040 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
16:30:16.0263 3040 swprv - ok
16:30:16.0372 3040 [ 9484C1DE568173DC1C44DF80F16092CC ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
16:30:16.0403 3040 SynTP - ok
16:30:16.0466 3040 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
16:30:16.0497 3040 SysMain - ok
16:30:16.0559 3040 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
16:30:16.0575 3040 TabletInputService - ok
16:30:16.0637 3040 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
16:30:16.0653 3040 TapiSrv - ok
16:30:16.0700 3040 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
16:30:16.0700 3040 TBS - ok
16:30:16.0824 3040 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
16:30:16.0856 3040 Tcpip - ok
16:30:16.0934 3040 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
16:30:16.0965 3040 TCPIP6 - ok
16:30:17.0012 3040 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
16:30:17.0012 3040 tcpipreg - ok
16:30:17.0090 3040 [ FD542B661BD22FA69CA789AD0AC58C29 ] tdcmdpst C:\Windows\system32\DRIVERS\tdcmdpst.sys
16:30:17.0090 3040 tdcmdpst - ok
16:30:17.0121 3040 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
16:30:17.0121 3040 TDPIPE - ok
16:30:17.0168 3040 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
16:30:17.0168 3040 TDTCP - ok
16:30:17.0199 3040 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
16:30:17.0214 3040 tdx - ok
16:30:17.0292 3040 [ 1B709733A04DCC41A63F9CD1F76A4EBE ] TemproMonitoringService C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
16:30:17.0308 3040 TemproMonitoringService - ok
16:30:17.0324 3040 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
16:30:17.0324 3040 TermDD - ok
16:30:17.0370 3040 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
16:30:17.0386 3040 TermService - ok
16:30:17.0417 3040 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
16:30:17.0417 3040 Themes - ok
16:30:17.0448 3040 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
16:30:17.0448 3040 THREADORDER - ok
16:30:17.0526 3040 [ DFE9BA871B9F3DBB591BD113611CBCC0 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
16:30:17.0542 3040 TMachInfo - ok
16:30:17.0604 3040 [ 8E2C799D3476EAC32C3BA0DF7CE6AF19 ] TODDSrv C:\Windows\system32\TODDSrv.exe
16:30:17.0604 3040 TODDSrv - ok
16:30:17.0729 3040 [ DB9719688C08F42705FEB3F6A0C98B91 ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
16:30:17.0745 3040 TosCoSrv - ok
16:30:17.0792 3040 [ 74C2FA8C3765EE71A9C22182EC108457 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
16:30:17.0807 3040 TOSHIBA HDD SSD Alert Service - ok
16:30:17.0838 3040 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
16:30:17.0854 3040 TrkWks - ok
16:30:17.0901 3040 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
16:30:17.0916 3040 TrustedInstaller - ok
16:30:17.0948 3040 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
16:30:17.0948 3040 tssecsrv - ok
16:30:17.0979 3040 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
16:30:17.0979 3040 TsUsbFlt - ok
16:30:18.0010 3040 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
16:30:18.0026 3040 TsUsbGD - ok
16:30:18.0072 3040 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
16:30:18.0072 3040 tunnel - ok
16:30:18.0135 3040 [ 550B567F9364D8F7684C3FB3EA665A72 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS
16:30:18.0150 3040 TVALZ - ok
16:30:18.0166 3040 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
16:30:18.0182 3040 uagp35 - ok
16:30:18.0213 3040 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
16:30:18.0228 3040 udfs - ok
16:30:18.0275 3040 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
16:30:18.0291 3040 UI0Detect - ok
16:30:18.0322 3040 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
16:30:18.0322 3040 uliagpkx - ok
16:30:18.0369 3040 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
16:30:18.0369 3040 umbus - ok
16:30:18.0416 3040 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
16:30:18.0416 3040 UmPass - ok
16:30:18.0462 3040 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
16:30:18.0478 3040 upnphost - ok
16:30:18.0618 3040 [ FB251567F41BC61988B26731DEC19E4B ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
16:30:18.0618 3040 USBAAPL64 - ok
16:30:18.0665 3040 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
16:30:18.0665 3040 usbccgp - ok
16:30:18.0728 3040 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
16:30:18.0728 3040 usbcir - ok
16:30:18.0743 3040 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
16:30:18.0743 3040 usbehci - ok
16:30:18.0790 3040 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
16:30:18.0806 3040 usbhub - ok
16:30:18.0837 3040 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
16:30:18.0852 3040 usbohci - ok
16:30:18.0884 3040 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
16:30:18.0884 3040 usbprint - ok
16:30:18.0915 3040 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:30:18.0915 3040 USBSTOR - ok
16:30:18.0946 3040 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
16:30:18.0946 3040 usbuhci - ok
16:30:18.0993 3040 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
16:30:18.0993 3040 usbvideo - ok
16:30:19.0040 3040 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
16:30:19.0055 3040 UxSms - ok
16:30:19.0071 3040 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
16:30:19.0071 3040 VaultSvc - ok
16:30:19.0133 3040 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
16:30:19.0133 3040 vdrvroot - ok
16:30:19.0180 3040 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
16:30:19.0196 3040 vds - ok
16:30:19.0227 3040 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
16:30:19.0227 3040 vga - ok
16:30:19.0258 3040 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
16:30:19.0258 3040 VgaSave - ok
16:30:19.0274 3040 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
16:30:19.0274 3040 vhdmp - ok
16:30:19.0289 3040 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
16:30:19.0289 3040 viaide - ok
16:30:19.0320 3040 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
16:30:19.0320 3040 volmgr - ok
16:30:19.0336 3040 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
16:30:19.0336 3040 volmgrx - ok
16:30:19.0368 3040 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
16:30:19.0384 3040 volsnap - ok
16:30:19.0431 3040 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
16:30:19.0446 3040 vsmraid - ok
16:30:19.0524 3040 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
16:30:19.0571 3040 VSS - ok
16:30:19.0602 3040 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
16:30:19.0602 3040 vwifibus - ok
16:30:19.0665 3040 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
16:30:19.0680 3040 vwififlt - ok
16:30:19.0711 3040 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
16:30:19.0727 3040 W32Time - ok
16:30:19.0743 3040 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
16:30:19.0758 3040 WacomPen - ok
16:30:19.0805 3040 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
16:30:19.0805 3040 WANARP - ok
16:30:19.0836 3040 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
16:30:19.0836 3040 Wanarpv6 - ok
16:30:19.0914 3040 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
16:30:19.0945 3040 WatAdminSvc - ok
16:30:20.0023 3040 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
16:30:20.0055 3040 wbengine - ok
16:30:20.0070 3040 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
16:30:20.0086 3040 WbioSrvc - ok
16:30:20.0101 3040 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
16:30:20.0117 3040 wcncsvc - ok
16:30:20.0148 3040 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
16:30:20.0148 3040 WcsPlugInService - ok
16:30:20.0195 3040 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
16:30:20.0195 3040 Wd - ok
16:30:20.0242 3040 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
16:30:20.0242 3040 Wdf01000 - ok
16:30:20.0273 3040 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
16:30:20.0273 3040 WdiServiceHost - ok
16:30:20.0289 3040 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
16:30:20.0289 3040 WdiSystemHost - ok
16:30:20.0320 3040 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
16:30:20.0335 3040 WebClient - ok
16:30:20.0368 3040 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
16:30:20.0383 3040 Wecsvc - ok
16:30:20.0414 3040 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
16:30:20.0414 3040 wercplsupport - ok
16:30:20.0446 3040 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
16:30:20.0446 3040 WerSvc - ok
16:30:20.0477 3040 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
16:30:20.0477 3040 WfpLwf - ok
16:30:20.0492 3040 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
16:30:20.0492 3040 WIMMount - ok
16:30:20.0524 3040 WinHttpAutoProxySvc - ok
16:30:20.0633 3040 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
16:30:20.0633 3040 Winmgmt - ok
16:30:20.0726 3040 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
16:30:20.0789 3040 WinRM - ok
16:30:20.0867 3040 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
16:30:20.0882 3040 WinUsb - ok
16:30:21.0070 3040 [ F44FFC6CEC9D30CD361541A90858958B ] WINZIPSSDiskOptimizer C:\Program Files (x86)\WinZip System Utilities Suite\WINZIPSSDefragSrv64.exe
16:30:21.0085 3040 WINZIPSSDiskOptimizer - ok
16:30:21.0148 3040 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
16:30:21.0179 3040 Wlansvc - ok
16:30:21.0241 3040 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
16:30:21.0257 3040 wlcrasvc - ok
16:30:21.0413 3040 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:30:21.0444 3040 wlidsvc - ok
16:30:21.0475 3040 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
16:30:21.0475 3040 WmiAcpi - ok
16:30:21.0522 3040 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
16:30:21.0522 3040 wmiApSrv - ok
16:30:21.0600 3040 WMPNetworkSvc - ok
16:30:21.0647 3040 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
16:30:21.0647 3040 WPCSvc - ok
16:30:21.0678 3040 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
16:30:21.0678 3040 WPDBusEnum - ok
16:30:21.0725 3040 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
16:30:21.0725 3040 ws2ifsl - ok
16:30:21.0740 3040 WSearch - ok
16:30:21.0772 3040 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
16:30:21.0772 3040 WudfPf - ok
16:30:21.0818 3040 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
16:30:21.0834 3040 WUDFRd - ok
16:30:21.0850 3040 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
16:30:21.0865 3040 wudfsvc - ok
16:30:21.0896 3040 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
16:30:21.0896 3040 WwanSvc - ok
16:30:21.0928 3040 ================ Scan global ===============================
16:30:21.0974 3040 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
16:30:22.0006 3040 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
16:30:22.0021 3040 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
16:30:22.0052 3040 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
16:30:22.0099 3040 [ 50BEA589F7D7958BDD2528A8F69D05CC ] C:\Windows\system32\services.exe
16:30:22.0115 3040 C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.a ) - infected
16:30:22.0115 3040 C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.a (0)
16:30:22.0115 3040 ================ Scan MBR ==================================
16:30:22.0130 3040 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
16:30:23.0347 3040 \Device\Harddisk0\DR0 - ok
16:30:23.0363 3040 ================ Scan VBR ==================================
16:30:23.0394 3040 [ 3E23B1B1F2C7299A89F2746717D0E87E ] \Device\Harddisk0\DR0\Partition1
16:30:23.0394 3040 \Device\Harddisk0\DR0\Partition1 - ok
16:30:23.0394 3040 ============================================================
16:30:23.0394 3040 Scan finished
16:30:23.0394 3040 ============================================================
16:30:23.0441 2008 Detected object count: 1
16:30:23.0441 2008 Actual detected object count: 1
16:30:46.0409 2008 C:\Windows\system32\services.exe - copied to quarantine
16:30:47.0142 2008 C:\Windows\assembly\GAC_32\desktop.ini - copied to quarantine
16:30:47.0142 2008 C:\Windows\assembly\GAC_64\desktop.ini - copied to quarantine
16:30:47.0563 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\@ - copied to quarantine
16:30:47.0579 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\L\00000004.@ - copied to quarantine
16:30:47.0595 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\L\1afb2d56 - copied to quarantine
16:30:47.0595 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\L\201d3dde - copied to quarantine
16:30:47.0626 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\L\55490ac4 - copied to quarantine
16:30:47.0626 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\00000004.@ - copied to quarantine
16:30:47.0626 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\00000008.@ - copied to quarantine
16:30:47.0641 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\000000cb.@ - copied to quarantine
16:30:47.0641 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\80000000.@ - copied to quarantine
16:30:47.0641 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\80000032.@ - copied to quarantine
16:30:47.0641 2008 C:\Windows\installer\{a9764319-0d8b-0a5c-34e4-88fdf6a95589}\U\80000064.@ - copied to quarantine

#4 TheJord

TheJord
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:57 AM

Posted 04 November 2012 - 12:06 PM

Due to time constraints I don't have the full aswMBR scan. I'll post the full results tomorrow, however some infections HAVE been found.


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-11-04 16:44:14
-----------------------------
16:44:14.706 OS Version: Windows x64 6.1.7601 Service Pack 1
16:44:14.706 Number of processors: 2 586 0x200
16:44:14.711 ComputerName: CRAOG-TOSH UserName: craog
16:44:17.832 Initialize success
16:44:34.950 AVAST engine defs: 12110400
16:44:43.506 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000062
16:44:43.513 Disk 0 Vendor: TOSHIBA_ GT00 Size: 476940MB BusType: 11
16:44:43.546 Disk 0 MBR read successfully
16:44:43.555 Disk 0 MBR scan
16:44:43.569 Disk 0 Windows 7 default MBR code
16:44:43.603 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 400 MB offset 2048
16:44:43.627 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 476537 MB offset 821248
16:44:43.680 Disk 0 scanning C:\Windows\system32\drivers
16:45:07.014 Service scanning
16:46:03.949 Modules scanning
16:46:03.969 Disk 0 trace - called modules:
16:46:04.019 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
16:46:04.029 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003041060]
16:46:04.049 3 CLASSPNP.SYS[fffff8800161743f] -> nt!IofCallDriver -> [0xfffffa8002ee9ac0]
16:46:04.069 5 amd_xata.sys[fffff880010ac8b4] -> nt!IofCallDriver -> \Device\00000062[0xfffffa8002a07220]
16:46:07.360 AVAST engine scan C:\Windows
16:46:18.757 AVAST engine scan C:\Windows\system32
16:49:23.908 File: C:\Windows\system32\services.exe **INFECTED** Win32:Sirefef-ZT [Trj]
16:50:23.319 File: C:\Windows\assembly\GAC_32\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
16:50:27.047 File: C:\Windows\assembly\GAC_64\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk]
16:52:29.900 AVAST engine scan C:\Windows\system32\drivers
16:52:48.001 AVAST engine scan C:\Users\craog
17:05:14.437 Disk 0 MBR has been saved successfully to "C:\Users\craog\Desktop\MBR.dat"
17:05:14.453 The log file has been saved successfully to "C:\Users\craog\Desktop\aswMBR.txt"




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users