Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Themida Virus?


  • Please log in to reply
8 replies to this topic

#1 GTT54

GTT54

  • Members
  • 72 posts
  • OFFLINE
  •  
  • Local time:06:33 AM

Posted 05 November 2012 - 04:54 PM

I keep getting usb device not recognized. I uninstalled and then reinstalled. I then a box that said themida which told me to stop running services. I have never seen this before. I have avast av and ran it several times and on boot scan. Nothing came up. I also ran Mbam in safe and normal mode. It showed nothing. I feel like there is something wrong. When I try sending a message from my exchange account at school, it hangs and then times out. I do not have this problem on other computers. I use Firefox and IE8. I have Windows XP. Please advise. Thanks.

BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,058 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:33 AM

Posted 05 November 2012 - 08:18 PM

Hello and welcome,please run these so we can get some more info.

MiniToolBox
Please download MiniToolBox, save it to your desktop and run it.Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.



Please download CKScanner and save it to your Desktop. <-Important!!!
  • Double-click on CKScanner.exe and click Search For Files.
  • If using Vista, right-click on it and Run As Administrator.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A text file will be created on your desktop named ckfiles.txt.
  • Click OK at the file saved message box.
  • Double-click the ckfiles.txt icon on your desktop to open the log and copy/paste the contents in your next reply.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 GTT54

GTT54
  • Topic Starter

  • Members
  • 72 posts
  • OFFLINE
  •  
  • Local time:06:33 AM

Posted 06 November 2012 - 07:47 AM

MiniToolBox by Farbar Version: 23-07-2012
Ran by Farfalla (administrator) on 06-11-2012 at 07:39:03
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================


127.0.0.1 localhost

========================= IP Configuration: ================================

Atheros AR5007EG Wireless Network Adapter = Wireless Network Connection (Connected)
Microsoft TV/Video Connection = Local Area Connection 2 (Connected)
Realtek RTL8102E Family PCI-E Fast Ethernet NIC = Local Area Connection (Media disconnected)


# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection"

set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp

# Interface IP Configuration for "Wireless Network Connection"

set address name="Wireless Network Connection" source=dhcp
set dns name="Wireless Network Connection" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection" source=dhcp

# Interface IP Configuration for "Local Area Connection 2"

set address name="Local Area Connection 2" source=dhcp
set dns name="Local Area Connection 2" source=dhcp register=PRIMARY
set wins name="Local Area Connection 2" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : Piccolo

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Hybrid

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : hsd1.nj.comcast.net.



Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC

Physical Address. . . . . . . . . : 00-23-8B-31-B9-57



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . : hsd1.nj.comcast.net.

Description . . . . . . . . . . . : Atheros AR5007EG Wireless Network Adapter

Physical Address. . . . . . . . . : 00-23-4E-77-7E-C5

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.0.103

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.0.1

DHCP Server . . . . . . . . . . . : 192.168.0.1

DNS Servers . . . . . . . . . . . : 75.75.75.75

75.75.76.76

Lease Obtained. . . . . . . . . . : Tuesday, November 06, 2012 7:33:10 AM

Lease Expires . . . . . . . . . . : Wednesday, November 07, 2012 7:33:10 AM



Ethernet adapter Local Area Connection 2:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Microsoft TV/Video Connection

Physical Address. . . . . . . . . : 00-00-00-00-00-00

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Autoconfiguration IP Address. . . : 0.1.0.5

Subnet Mask . . . . . . . . . . . : 255.255.255.255

Default Gateway . . . . . . . . . :

Server: cdns01.comcast.net
Address: 75.75.75.75

Name: google.com
Addresses: 74.125.228.96, 74.125.228.97, 74.125.228.98, 74.125.228.101
74.125.228.99, 74.125.228.100, 74.125.228.110, 74.125.228.103, 74.125.228.102
74.125.228.104, 74.125.228.105



Pinging google.com [173.194.43.36] with 32 bytes of data:



Reply from 173.194.43.36: bytes=32 time=14ms TTL=54

Reply from 173.194.43.36: bytes=32 time=14ms TTL=54



Ping statistics for 173.194.43.36:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 14ms, Maximum = 14ms, Average = 14ms

Server: cdns01.comcast.net
Address: 75.75.75.75

Name: yahoo.com
Addresses: 98.138.253.109, 72.30.38.140, 98.139.183.24



Pinging yahoo.com [72.30.38.140] with 32 bytes of data:



Reply from 72.30.38.140: bytes=32 time=162ms TTL=47

Reply from 72.30.38.140: bytes=32 time=174ms TTL=47



Ping statistics for 72.30.38.140:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 162ms, Maximum = 174ms, Average = 168ms

Server: cdns01.comcast.net
Address: 75.75.75.75

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Reply from 208.43.87.2: Destination host unreachable.

Reply from 208.43.87.2: Destination host unreachable.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=64

Reply from 127.0.0.1: bytes=32 time<1ms TTL=64



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 23 8b 31 b9 57 ...... Realtek RTL8102E Family PCI-E Fast Ethernet NIC - Packet Scheduler Miniport
0x3 ...00 23 4e 77 7e c5 ...... Atheros AR5007EG Wireless Network Adapter - Packet Scheduler Miniport
0x10005 ...00 00 00 00 00 00 ...... Microsoft TV/Video Connection
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.103 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.0.0 255.255.255.0 192.168.0.103 192.168.0.103 25
192.168.0.103 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.0.255 255.255.255.255 192.168.0.103 192.168.0.103 25
224.0.0.0 240.0.0.0 192.168.0.103 192.168.0.103 25
255.255.255.255 255.255.255.255 192.168.0.103 2 1
255.255.255.255 255.255.255.255 192.168.0.103 192.168.0.103 1
Default Gateway: 192.168.0.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (11/06/2012 07:39:19 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:39:19.812]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:38:45 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:38:45.140]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:38:10 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:38:10.500]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:37:35 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:37:35.828]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:37:01 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:37:01.171]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:36:26 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:36:26.500]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:35:51 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:35:51.843]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:35:17 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:35:17.171]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:34:42 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:34:42.515]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error

Error: (11/06/2012 07:34:07 AM) (Source: Brother BrLog) (User: )
Description: STI BrtSTI: [2012/11/06 07:34:07.812]: [00001984]: GetDeviceIpAddress: GetAddressByName [BRW00225871481D] Error


System errors:
=============
Error: (11/05/2012 02:51:33 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (11/05/2012 02:51:11 PM) (Source: DCOM) (User: PICCOLO)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error: (11/05/2012 07:23:50 AM) (Source: DCOM) (User: PICCOLO)
Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
in order to run the server:
{BA126AE5-2166-11D1-B1D0-00805FC1270E}

Error: (11/05/2012 07:22:14 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
Aavmker4
AFD
aswRdr
aswSnx
aswSP
aswTdi
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip

Error: (11/05/2012 07:22:14 AM) (Source: Service Control Manager) (User: )
Description: The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error:
%%31

Error: (11/05/2012 07:22:14 AM) (Source: Service Control Manager) (User: )
Description: The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error:
%%31

Error: (11/05/2012 07:22:14 AM) (Source: Service Control Manager) (User: )
Description: The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error:
%%31

Error: (11/05/2012 07:22:14 AM) (Source: Service Control Manager) (User: )
Description: The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error:
%%31

Error: (11/05/2012 07:21:38 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (11/04/2012 07:56:14 PM) (Source: 0) (User: )
Description: \Device\Harddisk1\D


Microsoft Office Sessions:
=========================

=========================== Installed Programs ============================

32 Bit HP CIO Components Installer (Version: 6.1.1)
4500_G510nz_Help (Version: 000.0.439.000)
4500G510nz (Version: 000.0.439.000)
4500G510nz_Software_Min (Version: 000.0.423.000)
5500 (Version: 40.0.105.000)
5500_Help (Version: 40.0.105.000)
5500Tour (Version: 40.0.105.000)
5500Trb (Version: 40.0.105.000)
Acer Crystal Eye webcam (Version: 5.8.33.001)
Acer ScreenSaver (Version: 1.11.0613)
Acrobat.com (Version: 0.0.0)
Acrobat.com (Version: 1.1.377)
Adobe AIR (Version: 2.5.1.17730)
Adobe Flash Player 11 ActiveX (Version: 11.2.202.235)
Adobe Flash Player 11 Plugin (Version: 11.4.402.287)
Adobe Reader X (10.1.4) (Version: 10.1.4)
AIM 7
AiO_Scan (Version: 40.0.105.000)
AIOMinimal (Version: 40.0.105.000)
AiOSoftware (Version: 40.0.105.000)
Amazon MP3 Downloader 1.0.10
Apple Application Support (Version: 1.4.1)
Apple Software Update (Version: 2.1.1.116)
Atheros for Acer Driver v7.6.0.224_Foxconn Installation Program (Version: 7.6.0.224)
avast! Free Antivirus (Version: 7.0.1466.0)
Becker's CPA Exam Review and PassMaster - 2010 Edition (Version: 5.0)
Becker CPA Review CD-ROM Course and PassMaster - 2009 Edition (Version: 4.2)
Brother MFL-Pro Suite MFC-J410W (Version: 0.0.1.0)
BufferChm (Version: 130.0.331.000)
CCleaner (Version: 3.24)
Copy (Version: 5.35.0.065)
CreativeProjects (Version: 5.35.0.059)
CyberLink DVD Suite (Version: 6.0.2426)
CyberLink Power2Go (Version: 6.0.2410a)
CyberLink UDF Reader 5.0
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Destinations (Version: 130.0.0.0)
DeviceDiscovery (Version: 130.0.372.000)
DocMgr (Version: 130.0.000.000)
DocProc (Version: 13.0.0.0)
doPDF 7.1 printer
Download Updater (AOL LLC)
Facebook Messenger 2.1.4651.0 (Version: 2.1.4651.0)
Fax (Version: 130.0.418.000)
Free Picture Resize Starter 4.5 (Version: 5.5.18)
Glary Utilities 2.33.0.1158 (Version: 2.33.0.1158)
Google Chrome (Version: 18.0.1025.162)
Google Update Helper (Version: 1.3.21.111)
GPBaseService2 (Version: 130.0.371.000)
HP Customer Participation Program 13.0 (Version: 13.0)
HP Document Manager 2.0 (Version: 2.0)
HP Image Zone 3.5 (Version: 3.5)
HP Imaging Device Functions 13.0 (Version: 13.0)
HP Officejet 4500 G510n-z (Version: 13.0)
HP PSC & OfficeJet 3.5 (Version: 3.5)
HP Smart Web Printing 4.5 (Version: 4.5)
HP Solution Center 13.0 (Version: 13.0)
HP Update (Version: 4.000.011.006)
hpmdtab (Version: 2.0.479.1607)
HPProductAssistant (Version: 130.0.371.000)
HPSSupply (Version: 130.0.371.000)
HPSystemDiagnostics (Version: 1.5.0.0)
InstantShare (Version: 3.5.0.21)
Intel® Graphics Media Accelerator Driver
InterVideo Register Manager (Version: 1.0.4.0)
InterVideo WinDVD (Version: 5.0-B11.1255)
IObit Malware Fighter (Version: 1.0)
Java Auto Updater (Version: 2.0.7.2)
Java™ 6 Update 37 (Version: 6.0.370)
JMicron JMB38X Flash Media Controller (Version: 1.00.16.01)
Juniper Networks Host Checker (Version: 6.4.0.14343)
Juniper Networks, Inc. Setup Client (Version: 7.1.4.13103)
Juniper Terminal Services Client (Version: 7.1.0.19525)
Launch Manager
Malwarebytes Anti-Malware version 1.65.0.1400 (Version: 1.65.0.1400)
MarketResearch (Version: 130.0.374.000)
Memories Disc Creator 2.0 (Version: 2.0.479.1607)
Microsoft .NET Framework 1.1 (Version: 1.1.4322)
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2005 (Version: 14)
Microsoft Money 2005 System Pack (Version: 14.0.150)
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Small Business (Version: 9.00.3821)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Access Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Spanish) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Suite Activation Assistant (Version: 2.9)
Microsoft Office Word MUI (English) 2010 (Version: 14.0.6029.1000)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft Software Update for Web Folders (English) 14 (Version: 14.0.6029.1000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Works (Version: 08.05.0818)
Move Media Player
Mozilla Firefox 16.0.2 (x86 en-US) (Version: 16.0.2)
Mozilla Maintenance Service (Version: 16.0.2)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP2 Parser and SDK (Version: 4.20.9818.0)
Network (Version: 130.0.374.000)
OCR Software by I.R.I.S. 13.0 (Version: 13.0)
Optimum App for Laptop 1.62 (Version: 1.62)
Overland (Version: 2.1.4)
overland (Version: 2.1.5)
Personal Ancestral File 5
Personal Ancestral File Companion 5.4 (Version: 5.4)
PhotoGallery (Version: 5.35.0.059)
PrintScreen (Version: 5.35.0.035)
QFolder (Version: 1.00.0000)
QuickBooks (Version: 22.0.4005.2206)
QuickBooks Pro 2012 (Version: 22.0.4005.2206)
QuickProjects (Version: 5.35.0.047)
QuickTime (Version: 7.69.80.9)
Readme (Version: 40.0.105.000)
REALTEK GbE & FE Ethernet PCI-E NIC Driver (Version: 1.17.0000)
Realtek High Definition Audio Driver (Version: 5.10.0.5628)
Respondus 4.0 Campus-Wide (Version: 4.00.0000)
Respondus Equation Editor 4
SampleTestInstall (Version: 1.0.0.0)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.550.0)
Scan (Version: 13.0.0.0)
Shop for HP Supplies (Version: 13.0)
SkinsHP1 (Version: 5.35.0.043)
SkinsHP2 (Version: 5.35.0.043)
Skype™ 5.10 (Version: 5.10.116)
SmartWebPrinting (Version: 130.0.373.000)
SolutionCenter (Version: 130.0.373.000)
Status (Version: 130.0.373.000)
Synaptics Pointing Device Driver (Version: 11.1.4.0)
TestGen
Toolbox (Version: 130.0.648.000)
TrayApp (Version: 130.0.376.000)
TurboTax 2011
TurboTax 2011 WinPerFedFormset (Version: 011.000.2999)
TurboTax 2011 WinPerReleaseEngine (Version: 011.000.0474)
TurboTax 2011 WinPerTaxSupport (Version: 011.000.0214)
TurboTax 2011 wnjiper (Version: 011.000.1627)
TurboTax 2011 wnyiper (Version: 011.000.1628)
TurboTax 2011 wrapper (Version: 011.000.0121)
TVicPort 4.1 Free Personal Edition (Version: )
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Windows Internet Explorer 8 (KB2598845) (Version: 1)
Update for Windows Internet Explorer 8 (KB2632503) (Version: 1)
Update for Windows Internet Explorer 8 (KB975364) (Version: 1)
Update for Windows Internet Explorer 8 (KB976662) (Version: 1)
Update for Windows Internet Explorer 8 (KB976749) (Version: 1)
Update for Windows Internet Explorer 8 (KB980182) (Version: 1)
Update for Windows XP (KB2141007) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2467659) (Version: 1)
Update for Windows XP (KB2492386) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2661254-v2) (Version: 2)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB2736233) (Version: 1)
Update for Windows XP (KB2749655) (Version: 1)
Update for Windows XP (KB898461) (Version: 1)
Update for Windows XP (KB942763) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB955839) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Verizon Wireless Software Upgrade Assistant - SAMSUNG (TL-PC) (Version: 1.11.1001)
Verizon Wireless Software Upgrade Assistant - Samsung (Version: 1.11.1009)
Visual C++ 2008 x86 Runtime - (v9.0.30729) (Version: 9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (Version: 9.0.30729.01)
WebFldrs XP (Version: 9.50.7523)
WebReg (Version: 130.0.132.017)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows Management Framework Core
Yahoo! Messenger

========================= Memory info: ===================================

Percentage of memory in use: 41%
Total physical RAM: 1011.88 MB
Available physical RAM: 592.7 MB
Total Pagefile: 2427.89 MB
Available Pagefile: 2153.73 MB
Total Virtual: 2047.88 MB
Available Virtual: 1970.35 MB

========================= Partitions: =====================================

1 Drive c: (ACER) (Fixed) (Total:144.17 GB) (Free:107.82 GB) NTFS

========================= Users: ========================================

User accounts for \\PICCOLO

Administrator ASPNET Farfalla
Guest HelpAssistant SUPPORT_388945a0


**** End of log ****


CKScanner 2.1 - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.FSNAAG
----- EOF -----

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,058 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:33 AM

Posted 06 November 2012 - 02:38 PM

Themida is a monitoring program,which may be used by malware. So we need to look further.


Please Download

TDSSkiller


Launch it. Click on change parameters-Select TDLFS file system

Click on "Scan".
Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results.



Please download AdwCleaner by Xplode onto your desktop.


  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.



Please download aswMBR ( 4.5MB ) to your desktop.
  • Double click the aswMBR.exe icon, and click Run.
  • When asked if you'd like to "download the latest Avast! virus definitions", click Yes.
  • Click the Scan button to start the scan.
  • On completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 GTT54

GTT54
  • Topic Starter

  • Members
  • 72 posts
  • OFFLINE
  •  
  • Local time:06:33 AM

Posted 07 November 2012 - 11:06 AM

10:21:12.0015 3276 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
10:21:13.0031 3276 ============================================================
10:21:13.0031 3276 Current date / time: 2012/11/07 10:21:13.0031
10:21:13.0031 3276 SystemInfo:
10:21:13.0031 3276
10:21:13.0031 3276 OS Version: 5.1.2600 ServicePack: 3.0
10:21:13.0031 3276 Product type: Workstation
10:21:13.0031 3276 ComputerName: PICCOLO
10:21:13.0031 3276 UserName: Farfalla
10:21:13.0031 3276 Windows directory: C:\WINDOWS
10:21:13.0031 3276 System windows directory: C:\WINDOWS
10:21:13.0031 3276 Processor architecture: Intel x86
10:21:13.0031 3276 Number of processors: 2
10:21:13.0031 3276 Page size: 0x1000
10:21:13.0031 3276 Boot type: Normal boot
10:21:13.0031 3276 ============================================================
10:21:15.0187 3276 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
10:21:15.0187 3276 ============================================================
10:21:15.0187 3276 \Device\Harddisk0\DR0:
10:21:15.0187 3276 MBR partitions:
10:21:15.0187 3276 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x9C263D, BlocksNum 0x12056484
10:21:15.0187 3276 ============================================================
10:21:15.0234 3276 C: <-> \Device\Harddisk0\DR0\Partition1
10:21:15.0234 3276 ============================================================
10:21:15.0234 3276 Initialize success
10:21:15.0234 3276 ============================================================
10:21:47.0156 1396 ============================================================
10:21:47.0156 1396 Scan started
10:21:47.0156 1396 Mode: Manual; TDLFS;
10:21:47.0156 1396 ============================================================
10:21:48.0328 1396 ================ Scan system memory ========================
10:21:48.0328 1396 System memory - ok
10:21:48.0328 1396 ================ Scan services =============================
10:21:48.0625 1396 [ 0352A73CD6B1782EA3ED7A03A8268F55 ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
10:21:48.0640 1396 Aavmker4 - ok
10:21:48.0656 1396 Abiosdsk - ok
10:21:48.0687 1396 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
10:21:48.0703 1396 abp480n5 - ok
10:21:48.0718 1396 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:21:48.0734 1396 ACPI - ok
10:21:48.0750 1396 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
10:21:48.0765 1396 ACPIEC - ok
10:21:48.0796 1396 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
10:21:48.0796 1396 adpu160m - ok
10:21:48.0828 1396 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
10:21:48.0828 1396 aec - ok
10:21:48.0875 1396 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
10:21:48.0875 1396 AFD - ok
10:21:48.0937 1396 [ 0EBB674888CBDEFD5773341C16DD6A07 ] AFS2K C:\WINDOWS\system32\drivers\AFS2K.sys
10:21:48.0937 1396 AFS2K - ok
10:21:48.0953 1396 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
10:21:48.0968 1396 agp440 - ok
10:21:48.0968 1396 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
10:21:48.0984 1396 agpCPQ - ok
10:21:49.0000 1396 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
10:21:49.0000 1396 Aha154x - ok
10:21:49.0031 1396 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
10:21:49.0046 1396 aic78u2 - ok
10:21:49.0062 1396 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
10:21:49.0062 1396 aic78xx - ok
10:21:49.0109 1396 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
10:21:49.0109 1396 Alerter - ok
10:21:49.0140 1396 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
10:21:49.0156 1396 ALG - ok
10:21:49.0156 1396 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
10:21:49.0171 1396 AliIde - ok
10:21:49.0187 1396 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
10:21:49.0187 1396 alim1541 - ok
10:21:49.0203 1396 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
10:21:49.0218 1396 amdagp - ok
10:21:49.0218 1396 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
10:21:49.0234 1396 amsint - ok
10:21:49.0250 1396 AppMgmt - ok
10:21:49.0328 1396 [ 7CAE93FE5511D0C0688CFA56CF241E31 ] AR5416 C:\WINDOWS\system32\DRIVERS\athw.sys
10:21:49.0375 1396 AR5416 - ok
10:21:49.0390 1396 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
10:21:49.0406 1396 asc - ok
10:21:49.0421 1396 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
10:21:49.0421 1396 asc3350p - ok
10:21:49.0437 1396 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
10:21:49.0453 1396 asc3550 - ok
10:21:49.0593 1396 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
10:21:49.0609 1396 aspnet_state - ok
10:21:49.0640 1396 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
10:21:49.0640 1396 aswFsBlk - ok
10:21:49.0656 1396 [ 2B9B1DF809E965EF63402CBBA6DB50AE ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
10:21:49.0671 1396 aswMon2 - ok
10:21:49.0703 1396 [ B7D5E4486BA658ED08624D8084ABB830 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr.sys
10:21:49.0703 1396 aswRdr - ok
10:21:49.0765 1396 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
10:21:49.0796 1396 aswSnx - ok
10:21:49.0828 1396 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
10:21:49.0843 1396 aswSP - ok
10:21:49.0875 1396 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
10:21:49.0875 1396 aswTdi - ok
10:21:49.0906 1396 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:21:49.0906 1396 AsyncMac - ok
10:21:49.0937 1396 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
10:21:49.0937 1396 atapi - ok
10:21:49.0953 1396 Atdisk - ok
10:21:49.0984 1396 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:21:49.0984 1396 Atmarpc - ok
10:21:50.0046 1396 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
10:21:50.0046 1396 AudioSrv - ok
10:21:50.0109 1396 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
10:21:50.0125 1396 audstub - ok
10:21:50.0234 1396 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
10:21:50.0234 1396 avast! Antivirus - ok
10:21:50.0265 1396 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
10:21:50.0265 1396 Beep - ok
10:21:50.0343 1396 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
10:21:50.0375 1396 BITS - ok
10:21:50.0437 1396 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
10:21:50.0437 1396 Browser - ok
10:21:50.0546 1396 [ EA7E57F87D6FEE5FD6C5F813C04E8CD2 ] BrYNSvc C:\Program Files\Browny02\BrYNSvc.exe
10:21:50.0562 1396 BrYNSvc - ok
10:21:50.0593 1396 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
10:21:50.0609 1396 cbidf - ok
10:21:50.0625 1396 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
10:21:50.0640 1396 cbidf2k - ok
10:21:50.0703 1396 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
10:21:50.0703 1396 CCDECODE - ok
10:21:50.0734 1396 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
10:21:50.0734 1396 cd20xrnt - ok
10:21:50.0765 1396 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
10:21:50.0765 1396 Cdaudio - ok
10:21:50.0796 1396 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
10:21:50.0812 1396 Cdfs - ok
10:21:50.0843 1396 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:21:50.0843 1396 Cdrom - ok
10:21:50.0859 1396 Changer - ok
10:21:50.0921 1396 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
10:21:50.0921 1396 CiSvc - ok
10:21:50.0968 1396 [ CC82215750723D839DBC5D2D625FC130 ] CLBStor C:\WINDOWS\system32\drivers\CLBStor.sys
10:21:50.0968 1396 CLBStor - ok
10:21:50.0984 1396 [ C002F79E6EE9BDF442514435C3D2BCB6 ] CLBUDFR C:\WINDOWS\system32\drivers\CLBUDFR.sys
10:21:50.0984 1396 CLBUDFR - ok
10:21:51.0031 1396 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
10:21:51.0031 1396 ClipSrv - ok
10:21:51.0140 1396 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:21:51.0203 1396 clr_optimization_v2.0.50727_32 - ok
10:21:51.0250 1396 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:21:51.0296 1396 clr_optimization_v4.0.30319_32 - ok
10:21:51.0312 1396 [ 0F6C187D38D98F8DF904589A5F94D411 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
10:21:51.0312 1396 CmBatt - ok
10:21:51.0328 1396 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
10:21:51.0328 1396 CmdIde - ok
10:21:51.0343 1396 [ 6E4C9F21F0FAE8940661144F41B13203 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
10:21:51.0359 1396 Compbatt - ok
10:21:51.0375 1396 COMSysApp - ok
10:21:51.0406 1396 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
10:21:51.0406 1396 Cpqarray - ok
10:21:51.0437 1396 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
10:21:51.0453 1396 CryptSvc - ok
10:21:51.0500 1396 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
10:21:51.0515 1396 dac2w2k - ok
10:21:51.0515 1396 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
10:21:51.0531 1396 dac960nt - ok
10:21:51.0625 1396 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
10:21:51.0718 1396 DcomLaunch - ok
10:21:51.0750 1396 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
10:21:51.0750 1396 Dhcp - ok
10:21:51.0765 1396 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
10:21:51.0781 1396 Disk - ok
10:21:51.0843 1396 [ 08D30AF92C270F2E76787C81589DBAD6 ] DKbFltr C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
10:21:51.0859 1396 DKbFltr - ok
10:21:51.0859 1396 dmadmin - ok
10:21:51.0921 1396 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
10:21:51.0968 1396 dmboot - ok
10:21:52.0000 1396 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
10:21:52.0015 1396 dmio - ok
10:21:52.0046 1396 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
10:21:52.0046 1396 dmload - ok
10:21:52.0093 1396 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
10:21:52.0109 1396 dmserver - ok
10:21:52.0140 1396 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
10:21:52.0156 1396 DMusic - ok
10:21:52.0203 1396 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
10:21:52.0218 1396 Dnscache - ok
10:21:52.0250 1396 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
10:21:52.0265 1396 Dot3svc - ok
10:21:52.0312 1396 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
10:21:52.0312 1396 dpti2o - ok
10:21:52.0343 1396 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
10:21:52.0343 1396 drmkaud - ok
10:21:52.0390 1396 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
10:21:52.0406 1396 EapHost - ok
10:21:52.0421 1396 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
10:21:52.0437 1396 ERSvc - ok
10:21:52.0484 1396 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
10:21:52.0531 1396 Eventlog - ok
10:21:52.0609 1396 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
10:21:52.0625 1396 EventSystem - ok
10:21:52.0671 1396 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
10:21:52.0687 1396 Fastfat - ok
10:21:52.0734 1396 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
10:21:52.0781 1396 FastUserSwitchingCompatibility - ok
10:21:52.0812 1396 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
10:21:52.0859 1396 Fax - ok
10:21:52.0875 1396 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
10:21:52.0890 1396 Fdc - ok
10:21:53.0015 1396 [ 9200A69413D69AB86ADD9BC81960BE7B ] FileMonitor C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys
10:21:53.0046 1396 FileMonitor - ok
10:21:53.0093 1396 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
10:21:53.0093 1396 Fips - ok
10:21:53.0125 1396 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
10:21:53.0140 1396 Flpydisk - ok
10:21:53.0156 1396 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
10:21:53.0171 1396 FltMgr - ok
10:21:53.0296 1396 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
10:21:53.0312 1396 FontCache3.0.0.0 - ok
10:21:53.0375 1396 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:21:53.0375 1396 Fs_Rec - ok
10:21:53.0437 1396 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:21:53.0453 1396 Ftdisk - ok
10:21:53.0468 1396 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:21:53.0484 1396 Gpc - ok
10:21:53.0640 1396 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
10:21:53.0640 1396 gupdate - ok
10:21:53.0671 1396 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
10:21:53.0671 1396 gupdatem - ok
10:21:53.0703 1396 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
10:21:53.0718 1396 HDAudBus - ok
10:21:53.0796 1396 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
10:21:53.0812 1396 helpsvc - ok
10:21:53.0890 1396 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
10:21:53.0906 1396 HidServ - ok
10:21:53.0968 1396 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:21:53.0968 1396 HidUsb - ok
10:21:54.0031 1396 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
10:21:54.0046 1396 hkmsvc - ok
10:21:54.0078 1396 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
10:21:54.0078 1396 hpn - ok
10:21:54.0187 1396 [ 0A3C6AA4A9FC38C20BA4EAC2C3351C05 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
10:21:54.0265 1396 hpqcxs08 - ok
10:21:54.0281 1396 [ F3F72A2A86C22610BCA5439FA789DD52 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
10:21:54.0312 1396 hpqddsvc - ok
10:21:54.0375 1396 [ 568E44F6DCFA173F3670172B69379891 ] HPSLPSVC C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
10:21:54.0421 1396 HPSLPSVC - ok
10:21:54.0484 1396 [ D03D10F7DED688FECF50F8FBF1EA9B8A ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
10:21:54.0484 1396 HPZid412 - ok
10:21:54.0546 1396 [ 89F41658929393487B6B7D13C8528CE3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
10:21:54.0562 1396 HPZipr12 - ok
10:21:54.0609 1396 [ ABCB05CCDBF03000354B9553820E39F8 ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
10:21:54.0625 1396 HPZius12 - ok
10:21:54.0671 1396 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
10:21:54.0687 1396 HTTP - ok
10:21:54.0750 1396 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
10:21:54.0796 1396 HTTPFilter - ok
10:21:54.0843 1396 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
10:21:54.0843 1396 i2omgmt - ok
10:21:54.0875 1396 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
10:21:54.0875 1396 i2omp - ok
10:21:54.0921 1396 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:21:54.0921 1396 i8042prt - ok
10:21:55.0187 1396 [ 48846B31BE5A4FA662CCFDE7A1BA86B9 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
10:21:55.0375 1396 ialm - ok
10:21:55.0484 1396 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
10:21:55.0531 1396 idsvc - ok
10:21:55.0578 1396 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
10:21:55.0593 1396 Imapi - ok
10:21:55.0656 1396 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
10:21:55.0671 1396 ImapiService - ok
10:21:55.0750 1396 [ 8AE99EBE30E8338907361018D9030835 ] IMFservice C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
10:21:55.0781 1396 IMFservice - ok
10:21:55.0828 1396 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
10:21:55.0843 1396 ini910u - ok
10:21:55.0921 1396 [ 4D8D5B1C895EA0F2A721B98A7CE198F1 ] int15.sys C:\Acer\Empowering Technology\eRecovery\int15.sys
10:21:55.0921 1396 int15.sys - ok
10:21:56.0187 1396 [ 19AFBB8427CE65042599555E578170DF ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
10:21:56.0406 1396 IntcAzAudAddService - ok
10:21:56.0453 1396 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
10:21:56.0453 1396 IntelIde - ok
10:21:56.0484 1396 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:21:56.0500 1396 intelppm - ok
10:21:56.0671 1396 [ 1663A135865F0BA6E853353E98E67F2A ] IntuitUpdateServiceV4 C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
10:21:56.0671 1396 IntuitUpdateServiceV4 - ok
10:21:56.0703 1396 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
10:21:56.0703 1396 Ip6Fw - ok
10:21:56.0734 1396 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:21:56.0750 1396 IpFilterDriver - ok
10:21:56.0781 1396 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:21:56.0781 1396 IpInIp - ok
10:21:56.0812 1396 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:21:56.0828 1396 IpNat - ok
10:21:56.0843 1396 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:21:56.0843 1396 IPSec - ok
10:21:56.0875 1396 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
10:21:56.0875 1396 IRENUM - ok
10:21:56.0906 1396 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:21:56.0906 1396 isapnp - ok
10:21:56.0968 1396 [ 213822072085B5BBAD9AF30AB577D817 ] IviRegMgr C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
10:21:56.0968 1396 IviRegMgr - ok
10:21:57.0109 1396 [ 691B9B7C0CC1653732717D292D6B305D ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
10:21:57.0109 1396 JavaQuickStarterService - ok
10:21:57.0156 1396 [ DA971CFC625D13636E04C405948E9D62 ] JMCR C:\WINDOWS\system32\DRIVERS\jmcr.sys
10:21:57.0171 1396 JMCR - ok
10:21:57.0187 1396 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:21:57.0187 1396 Kbdclass - ok
10:21:57.0250 1396 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
10:21:57.0250 1396 kbdhid - ok
10:21:57.0265 1396 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
10:21:57.0281 1396 kmixer - ok
10:21:57.0312 1396 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
10:21:57.0328 1396 KSecDD - ok
10:21:57.0359 1396 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
10:21:57.0390 1396 LanmanServer - ok
10:21:57.0437 1396 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
10:21:57.0484 1396 lanmanworkstation - ok
10:21:57.0484 1396 lbrtfdc - ok
10:21:57.0562 1396 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
10:21:57.0578 1396 LmHosts - ok
10:21:57.0625 1396 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
10:21:57.0640 1396 Messenger - ok
10:21:57.0671 1396 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
10:21:57.0671 1396 mnmdd - ok
10:21:57.0687 1396 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
10:21:57.0703 1396 mnmsrvc - ok
10:21:57.0734 1396 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
10:21:57.0734 1396 Modem - ok
10:21:57.0750 1396 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:21:57.0750 1396 Mouclass - ok
10:21:57.0796 1396 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:21:57.0796 1396 mouhid - ok
10:21:57.0812 1396 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
10:21:57.0828 1396 MountMgr - ok
10:21:57.0906 1396 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
10:21:57.0906 1396 MozillaMaintenance - ok
10:21:57.0921 1396 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
10:21:57.0921 1396 mraid35x - ok
10:21:57.0968 1396 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:21:57.0968 1396 MRxDAV - ok
10:21:58.0031 1396 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
10:21:58.0062 1396 MRxSmb - ok
10:21:58.0093 1396 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
10:21:58.0125 1396 MSDTC - ok
10:21:58.0156 1396 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
10:21:58.0171 1396 Msfs - ok
10:21:58.0187 1396 MSIServer - ok
10:21:58.0218 1396 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:21:58.0234 1396 MSKSSRV - ok
10:21:58.0234 1396 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:21:58.0250 1396 MSPCLOCK - ok
10:21:58.0250 1396 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
10:21:58.0265 1396 MSPQM - ok
10:21:58.0281 1396 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:21:58.0296 1396 mssmbios - ok
10:21:58.0343 1396 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
10:21:58.0359 1396 MSTEE - ok
10:21:58.0375 1396 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
10:21:58.0390 1396 Mup - ok
10:21:58.0453 1396 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
10:21:58.0453 1396 NABTSFEC - ok
10:21:58.0515 1396 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
10:21:58.0562 1396 napagent - ok
10:21:58.0562 1396 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
10:21:58.0578 1396 NDIS - ok
10:21:58.0609 1396 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
10:21:58.0609 1396 NdisIP - ok
10:21:58.0640 1396 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:21:58.0640 1396 NdisTapi - ok
10:21:58.0671 1396 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:21:58.0687 1396 Ndisuio - ok
10:21:58.0703 1396 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:21:58.0703 1396 NdisWan - ok
10:21:58.0734 1396 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
10:21:58.0734 1396 NDProxy - ok
10:21:58.0765 1396 [ 510C138564486FF926A3F773205C63D1 ] Net Driver HPZ12 C:\WINDOWS\system32\HPZinw12.dll
10:21:58.0781 1396 Net Driver HPZ12 - ok
10:21:58.0796 1396 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
10:21:58.0796 1396 NetBIOS - ok
10:21:58.0843 1396 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
10:21:58.0859 1396 NetBT - ok
10:21:58.0921 1396 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
10:21:58.0953 1396 NetDDE - ok
10:21:58.0968 1396 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
10:21:58.0984 1396 NetDDEdsdm - ok
10:21:59.0046 1396 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
10:21:59.0062 1396 Netlogon - ok
10:21:59.0093 1396 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
10:21:59.0125 1396 Netman - ok
10:21:59.0156 1396 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
10:21:59.0156 1396 NetTcpPortSharing - ok
10:21:59.0218 1396 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
10:21:59.0234 1396 Nla - ok
10:21:59.0250 1396 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
10:21:59.0250 1396 Npfs - ok
10:21:59.0296 1396 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
10:21:59.0328 1396 Ntfs - ok
10:21:59.0343 1396 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
10:21:59.0359 1396 NtLmSsp - ok
10:21:59.0421 1396 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
10:21:59.0468 1396 NtmsSvc - ok
10:21:59.0515 1396 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
10:21:59.0531 1396 Null - ok
10:21:59.0578 1396 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:21:59.0593 1396 NwlnkFlt - ok
10:21:59.0609 1396 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:21:59.0625 1396 NwlnkFwd - ok
10:21:59.0703 1396 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:21:59.0703 1396 ose - ok
10:22:00.0015 1396 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:22:00.0203 1396 osppsvc - ok
10:22:00.0250 1396 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
10:22:00.0265 1396 Parport - ok
10:22:00.0281 1396 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
10:22:00.0296 1396 PartMgr - ok
10:22:00.0296 1396 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
10:22:00.0312 1396 ParVdm - ok
10:22:00.0328 1396 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
10:22:00.0328 1396 PCI - ok
10:22:00.0343 1396 PCIDump - ok
10:22:00.0375 1396 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
10:22:00.0390 1396 PCIIde - ok
10:22:00.0406 1396 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
10:22:00.0406 1396 Pcmcia - ok
10:22:00.0421 1396 PDCOMP - ok
10:22:00.0437 1396 PDFRAME - ok
10:22:00.0453 1396 PDRELI - ok
10:22:00.0468 1396 PDRFRAME - ok
10:22:00.0484 1396 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
10:22:00.0484 1396 perc2 - ok
10:22:00.0515 1396 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
10:22:00.0531 1396 perc2hib - ok
10:22:00.0578 1396 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
10:22:00.0593 1396 PlugPlay - ok
10:22:00.0625 1396 [ 37E5E8FFBAD35605DAEEC3224EA0E465 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.dll
10:22:00.0625 1396 Pml Driver HPZ12 - ok
10:22:00.0671 1396 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
10:22:00.0671 1396 PolicyAgent - ok
10:22:00.0687 1396 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:22:00.0703 1396 PptpMiniport - ok
10:22:00.0703 1396 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
10:22:00.0718 1396 ProtectedStorage - ok
10:22:00.0734 1396 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
10:22:00.0750 1396 PSched - ok
10:22:00.0765 1396 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:22:00.0765 1396 Ptilink - ok
10:22:00.0859 1396 [ 4080E220EB20D87AE74D12570B8A8027 ] QBCFMonitorService C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
10:22:00.0859 1396 QBCFMonitorService - ok
10:22:00.0906 1396 [ 6BEE1814470DC12FA20C53DFC3C97EBB ] QBFCService C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
10:22:00.0906 1396 QBFCService - ok
10:22:01.0000 1396 [ 25FC19BADF78B7FB1D835AAC4B0B91A5 ] QBVSS C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe
10:22:01.0062 1396 QBVSS - ok
10:22:01.0093 1396 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
10:22:01.0109 1396 ql1080 - ok
10:22:01.0125 1396 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
10:22:01.0125 1396 Ql10wnt - ok
10:22:01.0140 1396 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
10:22:01.0156 1396 ql12160 - ok
10:22:01.0171 1396 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
10:22:01.0187 1396 ql1240 - ok
10:22:01.0203 1396 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
10:22:01.0218 1396 ql1280 - ok
10:22:01.0234 1396 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:22:01.0234 1396 RasAcd - ok
10:22:01.0281 1396 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:22:01.0312 1396 RasAuto - ok
10:22:01.0328 1396 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:22:01.0343 1396 Rasl2tp - ok
10:22:01.0406 1396 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
10:22:01.0484 1396 RasMan - ok
10:22:01.0500 1396 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:22:01.0500 1396 RasPppoe - ok
10:22:01.0515 1396 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
10:22:01.0531 1396 Raspti - ok
10:22:01.0562 1396 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:22:01.0578 1396 Rdbss - ok
10:22:01.0593 1396 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:22:01.0593 1396 RDPCDD - ok
10:22:01.0656 1396 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
10:22:01.0671 1396 rdpdr - ok
10:22:01.0734 1396 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
10:22:01.0750 1396 RDPWD - ok
10:22:01.0781 1396 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
10:22:01.0828 1396 RDSessMgr - ok
10:22:01.0859 1396 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
10:22:01.0875 1396 redbook - ok
10:22:01.0906 1396 [ D03FA5EC6B855FEE1EE16C5B0C0BA42C ] RegFilter C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys
10:22:01.0906 1396 RegFilter - ok
10:22:01.0953 1396 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:22:01.0984 1396 RemoteAccess - ok
10:22:02.0062 1396 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
10:22:02.0109 1396 RpcLocator - ok
10:22:02.0281 1396 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:22:02.0328 1396 RpcSs - ok
10:22:02.0359 1396 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
10:22:02.0468 1396 RSVP - ok
10:22:02.0531 1396 [ F0A21C62B9B835E1C96268EAAE31D239 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
10:22:02.0546 1396 RTLE8023xp - ok
10:22:02.0609 1396 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
10:22:02.0625 1396 SamSs - ok
10:22:02.0671 1396 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
10:22:02.0718 1396 SCardSvr - ok
10:22:02.0812 1396 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:22:02.0859 1396 Schedule - ok
10:22:02.0906 1396 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:22:02.0906 1396 Secdrv - ok
10:22:02.0937 1396 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
10:22:02.0953 1396 seclogon - ok
10:22:02.0984 1396 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
10:22:03.0000 1396 SENS - ok
10:22:03.0031 1396 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
10:22:03.0031 1396 Serial - ok
10:22:03.0093 1396 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
10:22:03.0109 1396 Sfloppy - ok
10:22:03.0171 1396 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
10:22:03.0187 1396 SharedAccess - ok
10:22:03.0218 1396 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:22:03.0234 1396 ShellHWDetection - ok
10:22:03.0250 1396 Simbad - ok
10:22:03.0265 1396 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
10:22:03.0281 1396 sisagp - ok
10:22:03.0312 1396 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
10:22:03.0328 1396 SkypeUpdate - ok
10:22:03.0375 1396 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
10:22:03.0390 1396 SLIP - ok
10:22:03.0515 1396 [ 0302BC619D4A723317E7F8EB0C362BD3 ] SNP2UVC C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
10:22:03.0609 1396 SNP2UVC - ok
10:22:03.0625 1396 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
10:22:03.0640 1396 Sparrow - ok
10:22:03.0671 1396 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
10:22:03.0671 1396 splitter - ok
10:22:03.0734 1396 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
10:22:03.0765 1396 Spooler - ok
10:22:03.0765 1396 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
10:22:03.0781 1396 sr - ok
10:22:03.0843 1396 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
10:22:03.0921 1396 srservice - ok
10:22:03.0984 1396 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:22:04.0015 1396 Srv - ok
10:22:04.0062 1396 [ FFE42941E0326C322F40B0B79A46493C ] sscdbus C:\WINDOWS\system32\DRIVERS\sscdbus.sys
10:22:04.0078 1396 sscdbus - ok
10:22:04.0093 1396 [ A68E7D87ADFBB8C50D88CD58230C6819 ] sscdmdfl C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys
10:22:04.0093 1396 sscdmdfl - ok
10:22:04.0125 1396 [ B534B24151281856EC2F69ED3D6D60DD ] sscdmdm C:\WINDOWS\system32\DRIVERS\sscdmdm.sys
10:22:04.0140 1396 sscdmdm - ok
10:22:04.0156 1396 [ D04BD59F28C78E2E66632092CAFC0A2B ] sscdserd C:\WINDOWS\system32\DRIVERS\sscdserd.sys
10:22:04.0171 1396 sscdserd - ok
10:22:04.0203 1396 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:22:04.0234 1396 SSDPSRV - ok
10:22:04.0281 1396 [ A9573045BAA16EAB9B1085205B82F1ED ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
10:22:04.0296 1396 StillCam - ok
10:22:04.0375 1396 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
10:22:04.0453 1396 stisvc - ok
10:22:04.0468 1396 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
10:22:04.0484 1396 streamip - ok
10:22:04.0500 1396 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
10:22:04.0515 1396 swenum - ok
10:22:04.0562 1396 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
10:22:04.0578 1396 swmidi - ok
10:22:04.0593 1396 SwPrv - ok
10:22:04.0625 1396 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
10:22:04.0640 1396 symc810 - ok
10:22:04.0656 1396 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
10:22:04.0671 1396 symc8xx - ok
10:22:04.0687 1396 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
10:22:04.0703 1396 sym_hi - ok
10:22:04.0734 1396 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
10:22:04.0734 1396 sym_u3 - ok
10:22:04.0765 1396 [ 409F7EEB079D6154CCB26A02E6E27844 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys
10:22:04.0765 1396 SynTP - ok
10:22:04.0796 1396 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
10:22:04.0796 1396 sysaudio - ok
10:22:04.0859 1396 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
10:22:04.0890 1396 SysmonLog - ok
10:22:04.0921 1396 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:22:04.0953 1396 TapiSrv - ok
10:22:05.0031 1396 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:22:05.0046 1396 Tcpip - ok
10:22:05.0078 1396 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
10:22:05.0093 1396 TDPIPE - ok
10:22:05.0093 1396 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
10:22:05.0109 1396 TDTCP - ok
10:22:05.0140 1396 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
10:22:05.0156 1396 TermDD - ok
10:22:05.0218 1396 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
10:22:05.0250 1396 TermService - ok
10:22:05.0281 1396 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
10:22:05.0296 1396 Themes - ok
10:22:05.0343 1396 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
10:22:05.0343 1396 TosIde - ok
10:22:05.0390 1396 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
10:22:05.0421 1396 TrkWks - ok
10:22:05.0468 1396 [ 3147063508EAE931BECC01573C204FAC ] TVicPort C:\WINDOWS\system32\drivers\TVicPort.sys
10:22:05.0468 1396 TVicPort - ok
10:22:05.0500 1396 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
10:22:05.0515 1396 Udfs - ok
10:22:05.0546 1396 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
10:22:05.0562 1396 ultra - ok
10:22:05.0593 1396 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
10:22:05.0625 1396 Update - ok
10:22:05.0671 1396 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
10:22:05.0718 1396 upnphost - ok
10:22:05.0765 1396 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
10:22:05.0781 1396 UPS - ok
10:22:05.0828 1396 [ CB41CD653916362CA5ECD242382A156E ] UrlFilter C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys
10:22:05.0828 1396 UrlFilter - ok
10:22:05.0890 1396 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:22:05.0890 1396 usbccgp - ok
10:22:05.0921 1396 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:22:05.0937 1396 usbehci - ok
10:22:05.0953 1396 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:22:05.0968 1396 usbhub - ok
10:22:06.0000 1396 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:22:06.0000 1396 usbprint - ok
10:22:06.0062 1396 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:22:06.0078 1396 usbscan - ok
10:22:06.0140 1396 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:22:06.0156 1396 USBSTOR - ok
10:22:06.0187 1396 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:22:06.0203 1396 usbuhci - ok
10:22:06.0218 1396 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
10:22:06.0234 1396 VgaSave - ok
10:22:06.0265 1396 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
10:22:06.0281 1396 viaagp - ok
10:22:06.0296 1396 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
10:22:06.0312 1396 ViaIde - ok
10:22:06.0328 1396 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
10:22:06.0343 1396 VolSnap - ok
10:22:06.0406 1396 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
10:22:06.0453 1396 VSS - ok
10:22:06.0484 1396 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
10:22:06.0515 1396 W32Time - ok
10:22:06.0578 1396 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:22:06.0578 1396 Wanarp - ok
10:22:06.0593 1396 WDICA - ok
10:22:06.0640 1396 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
10:22:06.0640 1396 wdmaud - ok
10:22:06.0703 1396 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:22:06.0718 1396 WebClient - ok
10:22:06.0843 1396 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:22:06.0843 1396 winmgmt - ok
10:22:06.0953 1396 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll
10:22:07.0046 1396 WinRM - ok
10:22:07.0156 1396 [ C7E39EA41233E9F5B86C8DA3A9F1E4A8 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
10:22:07.0171 1396 WmdmPmSN - ok
10:22:07.0218 1396 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
10:22:07.0234 1396 WmiAcpi - ok
10:22:07.0312 1396 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
10:22:07.0328 1396 WmiApSrv - ok
10:22:07.0421 1396 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
10:22:07.0468 1396 WPFFontCache_v0400 - ok
10:22:07.0546 1396 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
10:22:07.0593 1396 wscsvc - ok
10:22:07.0640 1396 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
10:22:07.0656 1396 WSTCODEC - ok
10:22:07.0703 1396 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
10:22:07.0750 1396 wuauserv - ok
10:22:07.0796 1396 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
10:22:07.0859 1396 WZCSVC - ok
10:22:07.0890 1396 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
10:22:07.0937 1396 xmlprov - ok
10:22:07.0953 1396 ================ Scan global ===============================
10:22:08.0000 1396 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
10:22:08.0046 1396 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:22:08.0093 1396 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
10:22:08.0140 1396 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
10:22:08.0156 1396 [Global] - ok
10:22:08.0156 1396 ================ Scan MBR ==================================
10:22:08.0187 1396 [ 99852D5C3A78447C3D6D82B6155FE848 ] \Device\Harddisk0\DR0
10:22:16.0328 1396 \Device\Harddisk0\DR0 - ok
10:22:16.0328 1396 ================ Scan VBR ==================================
10:22:16.0328 1396 [ 2A37241898074C76F3C9346063A23D10 ] \Device\Harddisk0\DR0\Partition1
10:22:16.0328 1396 \Device\Harddisk0\DR0\Partition1 - ok
10:22:16.0343 1396 ============================================================
10:22:16.0343 1396 Scan finished
10:22:16.0343 1396 ============================================================
10:22:16.0359 0404 Detected object count: 0
10:22:16.0359 0404 Actual detected object count: 0


# AdwCleaner v2.007 - Logfile created 11/07/2012 at 10:28:22
# Updated 06/11/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Farfalla - PICCOLO
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Farfalla\desktop\AdwCleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.xpt
Folder Deleted : C:\Documents and Settings\All Users\Application Data\InstallMate
Folder Deleted : C:\Program Files\Common Files\Software Update Utility

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SoftwareUpdUtility
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v16.0.2 (en-US)

Profile name : default
File : C:\Documents and Settings\Farfalla\Application Data\Mozilla\Firefox\Profiles\czg9ts25.default\prefs.js

C:\Documents and Settings\Farfalla\Application Data\Mozilla\Firefox\Profiles\czg9ts25.default\user.js ... Deleted !

[OK] File is clean.

-\\ Google Chrome v18.0.1025.162

File : C:\Documents and Settings\Farfalla\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2880 octets] - [07/11/2012 10:28:22]

########## EOF - C:\AdwCleaner[S1].txt - [2940 octets] ##########


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-11-07 10:38:04
-----------------------------
10:38:04.171 OS Version: Windows 5.1.2600 Service Pack 3
10:38:04.171 Number of processors: 2 586 0x1C02
10:38:04.171 ComputerName: PICCOLO UserName:
10:38:05.609 Initialize success
10:38:08.937 AVAST engine defs: 12110700
10:38:55.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
10:38:55.812 Disk 0 Vendor: WDC_WD1600BEVT-22ZCT0 11.01A11 Size: 152627MB BusType: 3
10:38:55.843 Disk 0 MBR read successfully
10:38:55.859 Disk 0 MBR scan
10:38:55.875 Disk 0 unknown MBR code
10:38:55.906 Disk 0 Partition 1 00 12 Compaq diag MSWIN4.1 4996 MB offset 63
10:38:55.921 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 147628 MB offset 10233405
10:38:55.953 Disk 0 scanning sectors +312576705
10:38:56.062 Disk 0 scanning C:\WINDOWS\system32\drivers
10:39:07.812 Service scanning
10:39:22.046 Service int15.sys C:\Acer\Empowering Technology\eRecovery\int15.sys **INFECTED** Win32:Zeroot-B [Rtk]
10:39:22.812 Service intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys **LOCKED** 32
10:39:37.656 Modules scanning
10:40:09.203 Disk 0 trace - called modules:
10:40:09.312 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
10:40:09.328 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f582c8]
10:40:09.359 3 CLASSPNP.SYS[f78e7fd7] -> nt!IofCallDriver -> \Device\00000095[0x86f60818]
10:40:09.375 5 ACPI.sys[f77de620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86f9fd98]
10:40:11.734 AVAST engine scan C:\WINDOWS
10:40:28.156 AVAST engine scan C:\WINDOWS\system32
10:44:28.046 AVAST engine scan C:\WINDOWS\system32\drivers
10:44:46.375 AVAST engine scan C:\Documents and Settings\Farfalla
10:56:33.671 AVAST engine scan C:\Documents and Settings\All Users
10:59:45.765 Scan finished successfully
11:05:30.796 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Farfalla\Desktop\MBR.dat"
11:05:30.843 The log file has been saved successfully to "C:\Documents and Settings\Farfalla\Desktop\aswMBR.txt"

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,058 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:33 AM

Posted 07 November 2012 - 03:25 PM

OK,I see nothing here. To be sure nothing is attacking you I suggest you make a new topic about Themida.

I think we should get a deeper look. Please follow this Preparation Guide and post in a new topic.
If Gmer won't run,skip it.

Let me know if all went well.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 GTT54

GTT54
  • Topic Starter

  • Members
  • 72 posts
  • OFFLINE
  •  
  • Local time:06:33 AM

Posted 07 November 2012 - 03:38 PM

Thanks, before I move it. I saw these lines above:

0:39:22.046 Service int15.sys C:\Acer\Empowering Technology\eRecovery\int15.sys **INFECTED** Win32:Zeroot-B [Rtk]
10:39:22.812 Service intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys **LOCKED** 32

That does not mean anything?

#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,058 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:33 AM

Posted 07 November 2012 - 03:49 PM

Yes,that's the rootkit we want to get out and there may be others we canot see with the tools we ran here.
Sorry I wrote the wrong line above.

Edited by boopme, 07 November 2012 - 03:51 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 GTT54

GTT54
  • Topic Starter

  • Members
  • 72 posts
  • OFFLINE
  •  
  • Local time:06:33 AM

Posted 07 November 2012 - 04:01 PM

Thanks! I will follow the next steps. I am not sure how I got this. I am very careful with sites I visit and keeping my AV up to date.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users