Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Words become random hyperlinks


  • Please log in to reply
10 replies to this topic

#1 night16

night16

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 24 December 2012 - 03:42 PM

I am trying to determine what I am infected with and how to proceed. I was streaming video from gorillavid.com and the website prompted me update a plug-in. I obliged (my mistake) and during the installing AVG pinged it as a virus. I canceled the process, but it was too late. I began seeing words randomly hyperlinked all across the web. One such instance occurred while here on bleeping computer:

Posted Image
Posted Image

I have Windows 7 and was using Firefox. I have tried to determine what I downloaded, but I had cleared my history and downloads. (unfortunate coincidence) I looked into system restore only to discover one restore point, which I believe was logged after I was infected. I tried anyway but the restore failed and a Microsoft dialogue box suggested I disable my anti-virus. I didn't think this prudent considering I believe my compy is infected. How can I find out what I am infected with?

BC AdBot (Login to Remove)

 


#2 Jimbob85

Jimbob85

  • Members
  • 308 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:VA, USA
  • Local time:11:51 PM

Posted 27 December 2012 - 02:24 PM

Hi, Welcome to BC!

Lets try a few scans and see if we can find out what you have.

Please Download Malwarebytes AKA MBAM

Update Malwarebytes via the update tab.
Run a full scan
When the scan finnishes please select Remove Selected and make sure all of the boxs are checked
Please post the results

The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report in your next reply. Be sure to post the complete log to
include the top portion which shows MBAM's database version and your operating system.



Please Download Tdsskiller

Run TDSSKiller.exe
Click on Change Parameters
Put a check in the box of Detect TDLFS file system
Start scan
When it is finished the utility outputs a list of detected objects with descriptions:
The utility automatically selects an action (Cure or Delete) for malicious objects and asks you what to do with suspicious objects (Skip, by default)
Just stick with the default options and click Continue
If it wants to reboot please allow it to do so and let me know
Click on Report and post the contents of the text file that will open

By default, the utility outputs the log into system disk (it is usually the disk where the operating system is installed, C:\) root folder. The Log will have a name like: TDSSKiller.Version_Date_Time_log.txt.




Download

ESET online scanner

Install it

Click on START, it should download the virus definitions
When scan completes, click on LIST of found threats

Export the list to desktop, copy the contents of the text file in your reply
You may not get a listing if nothing is found

#3 night16

night16
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 28 December 2012 - 12:18 AM

Hi Jimbob85, thanks for taking the time to help out. Before I followed your steps I ran my anti-virus one more time and it identified a threat and moved it to the "virus vault." This cleared up all signs of the infection, but I know these things can be sticky so I followed you directions too.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.27.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
XXX :: XXX-DESKTOP [administrator]

12/27/2012 5:43:52 PM
mbam-log-2012-12-27 (17-43-52).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 478485
Time elapsed: 1 hour(s), 46 minute(s), 18 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 4
C:\Users\XXX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\47LOCX6K\50d6a7c73ac7d[1].exe (Adware.Dropper) -> Quarantined and deleted successfully.
C:\Users\XXX\AppData\Local\Temp\install_flash_player.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Users\XXX\AppData\Local\Temp\{0DD12A5C-D48D-4E4A-ACA1-9CAFD63208AA}\Addons\vaudix_extension.exe (Adware.Dropper) -> Quarantined and deleted successfully.
C:\Users\XXX\Downloads\VLCSetup.exe (Adware.Hotbar) -> Quarantined and deleted successfully.

(end)

---------------------------------------------------------------------------------------------------------------------------------------------------------------------------

20:35:58.0234 4320 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
20:35:58.0706 4320 ============================================================
20:35:58.0706 4320 Current date / time: 2012/12/27 20:35:58.0706
20:35:58.0706 4320 SystemInfo:
20:35:58.0706 4320
20:35:58.0706 4320 OS Version: 6.1.7601 ServicePack: 1.0
20:35:58.0706 4320 Product type: Workstation
20:35:58.0706 4320 ComputerName: XXX-DESKTOP
20:35:58.0707 4320 UserName: XXX
20:35:58.0707 4320 Windows directory: C:\Windows
20:35:58.0707 4320 System windows directory: C:\Windows
20:35:58.0707 4320 Running under WOW64
20:35:58.0707 4320 Processor architecture: Intel x64
20:35:58.0707 4320 Number of processors: 3
20:35:58.0707 4320 Page size: 0x1000
20:35:58.0707 4320 Boot type: Normal boot
20:35:58.0707 4320 ============================================================
20:36:01.0830 4320 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:36:01.0846 4320 Drive \Device\Harddisk3\DR3 - Size: 0x772EFE00 (1.86 Gb), SectorSize: 0x200, Cylinders: 0xF3, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
20:36:01.0846 4320 ============================================================
20:36:01.0846 4320 \Device\Harddisk0\DR0:
20:36:01.0846 4320 MBR partitions:
20:36:01.0846 4320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B58800, BlocksNum 0x32000
20:36:01.0846 4320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1B8BF86, BlocksNum 0x72B7A62A
20:36:01.0846 4320 \Device\Harddisk3\DR3:
20:36:01.0846 4320 MBR partitions:
20:36:01.0846 4320 \Device\Harddisk3\DR3\Partition1: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x3B95A1
20:36:01.0846 4320 ============================================================
20:36:01.0955 4320 C: <-> \Device\Harddisk0\DR0\Partition2
20:36:01.0955 4320 ============================================================
20:36:01.0955 4320 Initialize success
20:36:01.0955 4320 ============================================================
20:36:16.0966 5920 ============================================================
20:36:16.0966 5920 Scan started
20:36:16.0966 5920 Mode: Manual; TDLFS;
20:36:16.0966 5920 ============================================================
20:36:19.0057 5920 ================ Scan system memory ========================
20:36:19.0057 5920 System memory - ok
20:36:19.0057 5920 ================ Scan services =============================
20:36:19.0353 5920 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:36:19.0369 5920 1394ohci - ok
20:36:19.0509 5920 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
20:36:19.0509 5920 ACDaemon - ok
20:36:19.0525 5920 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:36:19.0525 5920 ACPI - ok
20:36:19.0540 5920 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:36:19.0556 5920 AcpiPmi - ok
20:36:19.0634 5920 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:36:19.0634 5920 AdobeARMservice - ok
20:36:19.0759 5920 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:36:19.0790 5920 AdobeFlashPlayerUpdateSvc - ok
20:36:19.0837 5920 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
20:36:19.0852 5920 adp94xx - ok
20:36:19.0868 5920 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
20:36:19.0884 5920 adpahci - ok
20:36:19.0915 5920 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
20:36:19.0915 5920 adpu320 - ok
20:36:19.0962 5920 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:36:19.0962 5920 AeLookupSvc - ok
20:36:20.0024 5920 [ 6CCD1135320109D6B219F1A6E04AD9F6 ] Afc C:\Windows\syswow64\drivers\Afc.sys
20:36:20.0040 5920 Afc - ok
20:36:20.0086 5920 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:36:20.0102 5920 AFD - ok
20:36:20.0164 5920 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:36:20.0180 5920 agp440 - ok
20:36:20.0196 5920 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
20:36:20.0196 5920 ALG - ok
20:36:20.0211 5920 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
20:36:20.0211 5920 aliide - ok
20:36:20.0227 5920 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
20:36:20.0227 5920 amdide - ok
20:36:20.0242 5920 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
20:36:20.0258 5920 AmdK8 - ok
20:36:20.0274 5920 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
20:36:20.0274 5920 AmdPPM - ok
20:36:20.0305 5920 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
20:36:20.0320 5920 amdsata - ok
20:36:20.0352 5920 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
20:36:20.0352 5920 amdsbs - ok
20:36:20.0383 5920 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
20:36:20.0383 5920 amdxata - ok
20:36:20.0414 5920 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
20:36:20.0414 5920 AppID - ok
20:36:20.0414 5920 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:36:20.0414 5920 AppIDSvc - ok
20:36:20.0461 5920 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
20:36:20.0461 5920 Appinfo - ok
20:36:20.0492 5920 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:36:20.0492 5920 Apple Mobile Device - ok
20:36:20.0508 5920 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
20:36:20.0523 5920 arc - ok
20:36:20.0539 5920 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
20:36:20.0554 5920 arcsas - ok
20:36:20.0570 5920 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
20:36:20.0570 5920 AsyncMac - ok
20:36:20.0586 5920 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
20:36:20.0586 5920 atapi - ok
20:36:20.0804 5920 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:36:20.0804 5920 AudioEndpointBuilder - ok
20:36:20.0866 5920 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
20:36:20.0866 5920 AudioSrv - ok
20:36:21.0865 5920 [ 56C73C5BC1656656CAC38A23B4310466 ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
20:36:21.0896 5920 AVGIDSAgent - ok
20:36:21.0990 5920 [ 388056EBD5FE6718FE669078DBE37897 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys
20:36:21.0990 5920 AVGIDSDriver - ok
20:36:22.0052 5920 [ 550E981747D6A6C55078C77346FFC2C6 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys
20:36:22.0052 5920 AVGIDSHA - ok
20:36:22.0146 5920 [ 5989592A91A17587799792A81E1541D4 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys
20:36:22.0161 5920 Avgldx64 - ok
20:36:22.0239 5920 [ 3FC43AA02545FCDDC22817829114DEC8 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys
20:36:22.0239 5920 Avgloga - ok
20:36:22.0302 5920 [ 767B4A485FB22AA0FC0BF5EEF00572B9 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys
20:36:22.0302 5920 Avgmfx64 - ok
20:36:22.0364 5920 [ FE4F444DBE4BBBDFD8FECF49398DEFC7 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys
20:36:22.0364 5920 Avgrkx64 - ok
20:36:22.0380 5920 [ 6E634525613D48A1D1657FB21F21F3B2 ] Avgtdia C:\Windows\system32\DRIVERS\avgtdia.sys
20:36:22.0380 5920 Avgtdia - ok
20:36:22.0426 5920 [ 371428CF0F71934CB0F2344823ADFA32 ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
20:36:22.0442 5920 avgtp - ok
20:36:22.0473 5920 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] avgwd C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
20:36:22.0473 5920 avgwd - ok
20:36:22.0536 5920 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:36:22.0536 5920 AxInstSV - ok
20:36:22.0567 5920 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
20:36:22.0582 5920 b06bdrv - ok
20:36:22.0629 5920 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
20:36:22.0645 5920 b57nd60a - ok
20:36:22.0848 5920 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.exe
20:36:22.0848 5920 BBSvc - ok
20:36:22.0894 5920 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.exe
20:36:22.0894 5920 BBUpdate - ok
20:36:22.0926 5920 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
20:36:22.0926 5920 BDESVC - ok
20:36:22.0988 5920 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
20:36:22.0988 5920 Beep - ok
20:36:23.0082 5920 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
20:36:23.0082 5920 BFE - ok
20:36:23.0144 5920 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
20:36:23.0144 5920 BITS - ok
20:36:23.0175 5920 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
20:36:23.0175 5920 blbdrive - ok
20:36:23.0238 5920 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
20:36:23.0238 5920 Bonjour Service - ok
20:36:23.0284 5920 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:36:23.0284 5920 bowser - ok
20:36:23.0300 5920 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
20:36:23.0316 5920 BrFiltLo - ok
20:36:23.0331 5920 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
20:36:23.0331 5920 BrFiltUp - ok
20:36:23.0378 5920 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
20:36:23.0378 5920 Browser - ok
20:36:23.0394 5920 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
20:36:23.0409 5920 Brserid - ok
20:36:23.0440 5920 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
20:36:23.0440 5920 BrSerWdm - ok
20:36:23.0456 5920 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
20:36:23.0472 5920 BrUsbMdm - ok
20:36:23.0487 5920 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
20:36:23.0487 5920 BrUsbSer - ok
20:36:23.0503 5920 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
20:36:23.0518 5920 BTHMODEM - ok
20:36:23.0550 5920 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
20:36:23.0550 5920 bthserv - ok
20:36:23.0565 5920 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:36:23.0565 5920 cdfs - ok
20:36:23.0612 5920 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
20:36:23.0628 5920 cdrom - ok
20:36:23.0674 5920 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
20:36:23.0674 5920 CertPropSvc - ok
20:36:23.0690 5920 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
20:36:23.0690 5920 circlass - ok
20:36:23.0706 5920 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
20:36:23.0721 5920 CLFS - ok
20:36:23.0986 5920 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:36:23.0986 5920 clr_optimization_v2.0.50727_32 - ok
20:36:24.0064 5920 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:36:24.0064 5920 clr_optimization_v2.0.50727_64 - ok
20:36:24.0205 5920 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:36:24.0252 5920 clr_optimization_v4.0.30319_32 - ok
20:36:24.0283 5920 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:36:24.0283 5920 clr_optimization_v4.0.30319_64 - ok
20:36:24.0314 5920 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
20:36:24.0314 5920 CmBatt - ok
20:36:24.0330 5920 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
20:36:24.0345 5920 cmdide - ok
20:36:24.0439 5920 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
20:36:24.0439 5920 CNG - ok
20:36:24.0454 5920 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
20:36:24.0470 5920 Compbatt - ok
20:36:24.0501 5920 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
20:36:24.0501 5920 CompositeBus - ok
20:36:24.0517 5920 COMSysApp - ok
20:36:24.0532 5920 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
20:36:24.0532 5920 crcdisk - ok
20:36:24.0610 5920 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:36:24.0610 5920 CryptSvc - ok
20:36:24.0688 5920 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:36:24.0688 5920 DcomLaunch - ok
20:36:24.0720 5920 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
20:36:24.0720 5920 defragsvc - ok
20:36:24.0782 5920 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
20:36:24.0782 5920 DfsC - ok
20:36:24.0813 5920 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
20:36:24.0829 5920 Dhcp - ok
20:36:24.0829 5920 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
20:36:24.0829 5920 discache - ok
20:36:24.0860 5920 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
20:36:24.0860 5920 Disk - ok
20:36:24.0938 5920 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:36:24.0938 5920 Dnscache - ok
20:36:24.0985 5920 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
20:36:24.0985 5920 dot3svc - ok
20:36:25.0016 5920 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
20:36:25.0016 5920 DPS - ok
20:36:25.0063 5920 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:36:25.0063 5920 drmkaud - ok
20:36:25.0344 5920 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:36:25.0344 5920 DXGKrnl - ok
20:36:25.0375 5920 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
20:36:25.0375 5920 EapHost - ok
20:36:25.0515 5920 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
20:36:25.0593 5920 ebdrv - ok
20:36:25.0656 5920 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
20:36:25.0656 5920 EFS - ok
20:36:25.0905 5920 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
20:36:25.0921 5920 ehRecvr - ok
20:36:25.0968 5920 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
20:36:25.0968 5920 ehSched - ok
20:36:25.0983 5920 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
20:36:25.0999 5920 elxstor - ok
20:36:26.0030 5920 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
20:36:26.0030 5920 ErrDev - ok
20:36:26.0061 5920 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
20:36:26.0061 5920 EventSystem - ok
20:36:26.0139 5920 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
20:36:26.0139 5920 exfat - ok
20:36:26.0155 5920 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:36:26.0170 5920 fastfat - ok
20:36:26.0233 5920 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
20:36:26.0248 5920 Fax - ok
20:36:26.0248 5920 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
20:36:26.0264 5920 fdc - ok
20:36:26.0280 5920 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
20:36:26.0280 5920 fdPHost - ok
20:36:26.0295 5920 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
20:36:26.0295 5920 FDResPub - ok
20:36:26.0311 5920 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:36:26.0311 5920 FileInfo - ok
20:36:26.0326 5920 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:36:26.0326 5920 Filetrace - ok
20:36:26.0342 5920 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
20:36:26.0358 5920 flpydisk - ok
20:36:26.0404 5920 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:36:26.0404 5920 FltMgr - ok
20:36:26.0701 5920 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
20:36:26.0701 5920 FontCache - ok
20:36:26.0779 5920 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:36:26.0779 5920 FontCache3.0.0.0 - ok
20:36:27.0028 5920 [ A9FF65EA14E4CABFCC1BB8ECE111A249 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
20:36:27.0044 5920 ForceWare Intelligent Application Manager (IAM) - ok
20:36:27.0060 5920 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:36:27.0060 5920 FsDepends - ok
20:36:27.0106 5920 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
20:36:27.0122 5920 fssfltr - ok
20:36:27.0481 5920 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
20:36:27.0496 5920 fsssvc - ok
20:36:27.0574 5920 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:36:27.0574 5920 Fs_Rec - ok
20:36:27.0621 5920 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:36:27.0621 5920 fvevol - ok
20:36:27.0637 5920 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
20:36:27.0652 5920 gagp30kx - ok
20:36:27.0793 5920 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
20:36:27.0808 5920 GamesAppService - ok
20:36:27.0855 5920 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:36:27.0871 5920 GEARAspiWDM - ok
20:36:27.0964 5920 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
20:36:27.0964 5920 gpsvc - ok
20:36:28.0011 5920 [ 816FD5A6F3C2F3D600900096632FC60E ] Greg_Service C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
20:36:28.0011 5920 Greg_Service - ok
20:36:28.0058 5920 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:36:28.0058 5920 gupdate - ok
20:36:28.0074 5920 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:36:28.0074 5920 gupdatem - ok
20:36:28.0089 5920 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
20:36:28.0089 5920 gusvc - ok
20:36:28.0292 5920 [ 662BA5623C7F686297E18E09A2E320BC ] HauppaugeTVServer C:\PROGRA~2\WinTV\TVServer\HAUPPA~1.EXE
20:36:28.0292 5920 HauppaugeTVServer - ok
20:36:28.0698 5920 [ 98405343D7DCD330FE1B08C8F4C3900C ] HCW85BDA C:\Windows\system32\drivers\HCW85BDA.sys
20:36:28.0760 5920 HCW85BDA - ok
20:36:28.0791 5920 [ A31B6C4DE6C01F2013CDB9AF59A18005 ] hcw85cir C:\Windows\system32\drivers\hcw85cir3.sys
20:36:28.0807 5920 hcw85cir - ok
20:36:28.0869 5920 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:36:28.0885 5920 HdAudAddService - ok
20:36:28.0916 5920 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
20:36:28.0916 5920 HDAudBus - ok
20:36:28.0963 5920 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
20:36:28.0963 5920 HidBatt - ok
20:36:28.0978 5920 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
20:36:28.0994 5920 HidBth - ok
20:36:29.0025 5920 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
20:36:29.0025 5920 HidIr - ok
20:36:29.0072 5920 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
20:36:29.0072 5920 hidserv - ok
20:36:29.0088 5920 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
20:36:29.0103 5920 HidUsb - ok
20:36:29.0134 5920 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:36:29.0150 5920 hkmsvc - ok
20:36:29.0197 5920 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:36:29.0197 5920 HomeGroupListener - ok
20:36:29.0228 5920 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:36:29.0228 5920 HomeGroupProvider - ok
20:36:29.0244 5920 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:36:29.0259 5920 HpSAMD - ok
20:36:29.0306 5920 [ F47CEC45FB85791D4AB237563AD0FA8F ] HTCAND64 C:\Windows\system32\Drivers\ANDROIDUSB.sys
20:36:29.0322 5920 HTCAND64 - ok
20:36:29.0384 5920 [ B8B1B284362E1D8135112573395D5DA5 ] htcnprot C:\Windows\system32\DRIVERS\htcnprot.sys
20:36:29.0384 5920 htcnprot - ok
20:36:29.0446 5920 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:36:29.0446 5920 HTTP - ok
20:36:29.0478 5920 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:36:29.0478 5920 hwpolicy - ok
20:36:29.0524 5920 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
20:36:29.0524 5920 i8042prt - ok
20:36:29.0571 5920 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:36:29.0587 5920 iaStorV - ok
20:36:29.0634 5920 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:36:29.0634 5920 idsvc - ok
20:36:29.0680 5920 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
20:36:29.0680 5920 iirsp - ok
20:36:29.0743 5920 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
20:36:29.0774 5920 IKEEXT - ok
20:36:29.0868 5920 [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
20:36:29.0883 5920 IntcAzAudAddService - ok
20:36:29.0914 5920 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
20:36:29.0914 5920 intelide - ok
20:36:29.0930 5920 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
20:36:29.0946 5920 intelppm - ok
20:36:29.0992 5920 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
20:36:29.0992 5920 IPBusEnum - ok
20:36:30.0024 5920 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:36:30.0024 5920 IpFilterDriver - ok
20:36:30.0086 5920 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:36:30.0086 5920 iphlpsvc - ok
20:36:30.0117 5920 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
20:36:30.0133 5920 IPMIDRV - ok
20:36:30.0148 5920 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:36:30.0148 5920 IPNAT - ok
20:36:30.0195 5920 [ A9E53E1A9C4274EEBC00D36AE5ED40DE ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
20:36:30.0211 5920 iPod Service - ok
20:36:30.0226 5920 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:36:30.0226 5920 IRENUM - ok
20:36:30.0258 5920 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:36:30.0258 5920 isapnp - ok
20:36:30.0336 5920 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
20:36:30.0367 5920 iScsiPrt - ok
20:36:30.0382 5920 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
20:36:30.0398 5920 kbdclass - ok
20:36:30.0429 5920 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
20:36:30.0445 5920 kbdhid - ok
20:36:30.0445 5920 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
20:36:30.0445 5920 KeyIso - ok
20:36:30.0492 5920 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:36:30.0492 5920 KSecDD - ok
20:36:30.0538 5920 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:36:30.0538 5920 KSecPkg - ok
20:36:30.0570 5920 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:36:30.0570 5920 ksthunk - ok
20:36:30.0585 5920 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
20:36:30.0601 5920 KtmRm - ok
20:36:30.0663 5920 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
20:36:30.0663 5920 LanmanServer - ok
20:36:30.0710 5920 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:36:30.0710 5920 LanmanWorkstation - ok
20:36:30.0741 5920 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:36:30.0741 5920 lltdio - ok
20:36:30.0757 5920 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:36:30.0757 5920 lltdsvc - ok
20:36:30.0772 5920 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:36:30.0772 5920 lmhosts - ok
20:36:30.0804 5920 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
20:36:30.0819 5920 LSI_FC - ok
20:36:30.0835 5920 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
20:36:30.0850 5920 LSI_SAS - ok
20:36:30.0866 5920 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
20:36:30.0882 5920 LSI_SAS2 - ok
20:36:30.0897 5920 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
20:36:30.0897 5920 LSI_SCSI - ok
20:36:30.0913 5920 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
20:36:30.0928 5920 luafv - ok
20:36:30.0975 5920 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
20:36:30.0975 5920 Mcx2Svc - ok
20:36:30.0991 5920 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
20:36:31.0006 5920 megasas - ok
20:36:31.0022 5920 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
20:36:31.0038 5920 MegaSR - ok
20:36:31.0038 5920 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
20:36:31.0038 5920 MMCSS - ok
20:36:31.0053 5920 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
20:36:31.0053 5920 Modem - ok
20:36:31.0084 5920 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
20:36:31.0084 5920 monitor - ok
20:36:31.0100 5920 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\drivers\mouclass.sys
20:36:31.0116 5920 mouclass - ok
20:36:31.0131 5920 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
20:36:31.0147 5920 mouhid - ok
20:36:31.0194 5920 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:36:31.0194 5920 mountmgr - ok
20:36:31.0334 5920 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:36:31.0334 5920 MozillaMaintenance - ok
20:36:31.0381 5920 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
20:36:31.0396 5920 mpio - ok
20:36:31.0412 5920 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:36:31.0412 5920 mpsdrv - ok
20:36:31.0474 5920 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:36:31.0474 5920 MpsSvc - ok
20:36:31.0537 5920 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:36:31.0552 5920 MRxDAV - ok
20:36:31.0584 5920 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:36:31.0584 5920 mrxsmb - ok
20:36:31.0662 5920 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:36:31.0662 5920 mrxsmb10 - ok
20:36:31.0708 5920 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:36:31.0708 5920 mrxsmb20 - ok
20:36:31.0740 5920 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
20:36:31.0740 5920 msahci - ok
20:36:31.0771 5920 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
20:36:31.0786 5920 msdsm - ok
20:36:31.0802 5920 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
20:36:31.0802 5920 MSDTC - ok
20:36:31.0833 5920 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:36:31.0833 5920 Msfs - ok
20:36:31.0864 5920 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:36:31.0864 5920 mshidkmdf - ok
20:36:31.0911 5920 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:36:31.0911 5920 msisadrv - ok
20:36:31.0974 5920 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:36:31.0974 5920 MSiSCSI - ok
20:36:31.0989 5920 msiserver - ok
20:36:32.0020 5920 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:36:32.0020 5920 MSKSSRV - ok
20:36:32.0052 5920 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:36:32.0052 5920 MSPCLOCK - ok
20:36:32.0067 5920 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:36:32.0067 5920 MSPQM - ok
20:36:32.0114 5920 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:36:32.0114 5920 MsRPC - ok
20:36:32.0161 5920 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
20:36:32.0161 5920 mssmbios - ok
20:36:32.0192 5920 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:36:32.0192 5920 MSTEE - ok
20:36:32.0208 5920 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
20:36:32.0223 5920 MTConfig - ok
20:36:32.0254 5920 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
20:36:32.0254 5920 Mup - ok
20:36:32.0317 5920 [ 6FFECC25B39DC7652A0CEC0ADA9DB589 ] mwlPSDFilter C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
20:36:32.0317 5920 mwlPSDFilter - ok
20:36:32.0332 5920 [ 0BEFE32CA56D6EE89D58175725596A85 ] mwlPSDNServ C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
20:36:32.0348 5920 mwlPSDNServ - ok
20:36:32.0379 5920 [ D43BC633B8660463E446E28E14A51262 ] mwlPSDVDisk C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
20:36:32.0379 5920 mwlPSDVDisk - ok
20:36:32.0457 5920 [ 2F139207F618EC2933830227EEFFDDB4 ] MWLService C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe
20:36:32.0457 5920 MWLService - ok
20:36:32.0504 5920 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
20:36:32.0520 5920 napagent - ok
20:36:32.0535 5920 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:36:32.0535 5920 NativeWifiP - ok
20:36:32.0582 5920 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
20:36:32.0598 5920 NDIS - ok
20:36:32.0613 5920 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:36:32.0613 5920 NdisCap - ok
20:36:32.0644 5920 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:36:32.0644 5920 NdisTapi - ok
20:36:32.0676 5920 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:36:32.0676 5920 Ndisuio - ok
20:36:32.0769 5920 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:36:32.0769 5920 NdisWan - ok
20:36:32.0816 5920 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:36:32.0816 5920 NDProxy - ok
20:36:32.0894 5920 [ 7D2633295EB6FF2B938185874884059D ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
20:36:32.0910 5920 Nero BackItUp Scheduler 4.0 - ok
20:36:32.0925 5920 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:36:32.0925 5920 NetBIOS - ok
20:36:33.0019 5920 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:36:33.0019 5920 NetBT - ok
20:36:33.0034 5920 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
20:36:33.0034 5920 Netlogon - ok
20:36:33.0066 5920 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
20:36:33.0081 5920 Netman - ok
20:36:33.0097 5920 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
20:36:33.0097 5920 netprofm - ok
20:36:33.0144 5920 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
20:36:33.0144 5920 NetTcpPortSharing - ok
20:36:33.0159 5920 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
20:36:33.0175 5920 nfrd960 - ok
20:36:33.0222 5920 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
20:36:33.0222 5920 NlaSvc - ok
20:36:33.0237 5920 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:36:33.0237 5920 Npfs - ok
20:36:33.0268 5920 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
20:36:33.0268 5920 nsi - ok
20:36:33.0284 5920 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:36:33.0284 5920 nsiproxy - ok
20:36:33.0284 5920 [ C04F5DEF37E55F6A34428B050F44D3D6 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
20:36:33.0300 5920 nSvcIp - ok
20:36:33.0393 5920 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:36:33.0393 5920 Ntfs - ok
20:36:33.0487 5920 [ BD691091AC7D9713D8F0B07C6B099E6C ] NTI IScheduleSvc C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
20:36:33.0487 5920 NTI IScheduleSvc - ok
20:36:33.0487 5920 [ 64DDD0DEE976302F4BD93E5EFCC2F013 ] NTIDrvr C:\Windows\system32\drivers\NTIDrvr.sys
20:36:33.0502 5920 NTIDrvr - ok
20:36:33.0518 5920 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
20:36:33.0518 5920 Null - ok
20:36:33.0549 5920 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
20:36:33.0565 5920 NVENETFD - ok
20:36:33.0612 5920 [ CB599955CE2CE9694721562F9481CD84 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
20:36:33.0627 5920 NVHDA - ok
20:36:35.0000 5920 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:36:35.0078 5920 nvlddmkm - ok
20:36:35.0109 5920 [ 956A1F47826514C1EA0C295FE13C7377 ] NVNET C:\Windows\system32\DRIVERS\nvmf6264.sys
20:36:35.0125 5920 NVNET - ok
20:36:35.0140 5920 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:36:35.0156 5920 nvraid - ok
20:36:35.0203 5920 [ AFDE3015BB8D76E26BEC3B287C5443A0 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
20:36:35.0203 5920 nvsmu - ok
20:36:35.0218 5920 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:36:35.0234 5920 nvstor - ok
20:36:35.0250 5920 [ 7C7EEF51979658CE15BBC04F96A77D56 ] nvstor64 C:\Windows\system32\DRIVERS\nvstor64.sys
20:36:35.0265 5920 nvstor64 - ok
20:36:35.0296 5920 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe
20:36:35.0296 5920 nvsvc - ok
20:36:35.0359 5920 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:36:35.0359 5920 nv_agp - ok
20:36:35.0484 5920 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
20:36:35.0499 5920 odserv - ok
20:36:35.0562 5920 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
20:36:35.0562 5920 ohci1394 - ok
20:36:35.0593 5920 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
20:36:35.0593 5920 ose - ok
20:36:35.0640 5920 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:36:35.0640 5920 p2pimsvc - ok
20:36:35.0671 5920 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
20:36:35.0671 5920 p2psvc - ok
20:36:35.0718 5920 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
20:36:35.0733 5920 Parport - ok
20:36:35.0764 5920 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:36:35.0780 5920 partmgr - ok
20:36:35.0858 5920 [ AFADA8B97BE3C9398DC6C770409C3544 ] PassThru Service C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
20:36:35.0858 5920 PassThru Service - ok
20:36:35.0920 5920 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:36:35.0920 5920 PcaSvc - ok
20:36:35.0967 5920 [ BC0018C2D29F655188A0ED3FA94FDB24 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
20:36:35.0983 5920 pccsmcfd - ok
20:36:35.0998 5920 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
20:36:35.0998 5920 pci - ok
20:36:36.0045 5920 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
20:36:36.0045 5920 pciide - ok
20:36:36.0123 5920 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
20:36:36.0139 5920 pcmcia - ok
20:36:36.0154 5920 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
20:36:36.0154 5920 pcw - ok
20:36:36.0170 5920 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:36:36.0170 5920 PEAUTH - ok
20:36:36.0810 5920 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:36:36.0810 5920 PerfHost - ok
20:36:36.0856 5920 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
20:36:36.0872 5920 pla - ok
20:36:37.0028 5920 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:36:37.0044 5920 PlugPlay - ok
20:36:37.0075 5920 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:36:37.0075 5920 PNRPAutoReg - ok
20:36:37.0106 5920 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:36:37.0106 5920 PNRPsvc - ok
20:36:37.0215 5920 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:36:37.0231 5920 PolicyAgent - ok
20:36:37.0262 5920 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
20:36:37.0278 5920 Power - ok
20:36:37.0324 5920 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
20:36:37.0340 5920 PptpMiniport - ok
20:36:37.0356 5920 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
20:36:37.0371 5920 Processor - ok
20:36:37.0402 5920 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
20:36:37.0402 5920 ProfSvc - ok
20:36:37.0434 5920 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:36:37.0434 5920 ProtectedStorage - ok
20:36:37.0480 5920 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:36:37.0480 5920 Psched - ok
20:36:37.0543 5920 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
20:36:37.0590 5920 ql2300 - ok
20:36:37.0636 5920 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
20:36:37.0652 5920 ql40xx - ok
20:36:37.0683 5920 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
20:36:37.0699 5920 QWAVE - ok
20:36:37.0730 5920 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:36:37.0730 5920 QWAVEdrv - ok
20:36:37.0746 5920 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:36:37.0746 5920 RasAcd - ok
20:36:37.0777 5920 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
20:36:37.0777 5920 RasAgileVpn - ok
20:36:37.0792 5920 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
20:36:37.0792 5920 RasAuto - ok
20:36:37.0824 5920 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
20:36:37.0824 5920 Rasl2tp - ok
20:36:37.0870 5920 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
20:36:37.0886 5920 RasMan - ok
20:36:37.0886 5920 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:36:37.0886 5920 RasPppoe - ok
20:36:37.0902 5920 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
20:36:37.0902 5920 RasSstp - ok
20:36:38.0011 5920 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:36:38.0026 5920 rdbss - ok
20:36:38.0058 5920 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
20:36:38.0058 5920 rdpbus - ok
20:36:38.0073 5920 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
20:36:38.0073 5920 RDPCDD - ok
20:36:38.0104 5920 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
20:36:38.0104 5920 RDPENCDD - ok
20:36:38.0120 5920 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
20:36:38.0120 5920 RDPREFMP - ok
20:36:38.0151 5920 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
20:36:38.0151 5920 RDPWD - ok
20:36:38.0198 5920 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:36:38.0198 5920 rdyboost - ok
20:36:38.0214 5920 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:36:38.0214 5920 RemoteAccess - ok
20:36:38.0245 5920 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:36:38.0245 5920 RemoteRegistry - ok
20:36:38.0260 5920 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:36:38.0260 5920 RpcEptMapper - ok
20:36:38.0276 5920 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
20:36:38.0276 5920 RpcLocator - ok
20:36:38.0432 5920 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
20:36:38.0432 5920 RpcSs - ok
20:36:38.0463 5920 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:36:38.0463 5920 rspndr - ok
20:36:38.0510 5920 [ FC00C0DE6DC83DE1B2B01420E2195B21 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys
20:36:38.0526 5920 RTL8192su - ok
20:36:38.0541 5920 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
20:36:38.0541 5920 SamSs - ok
20:36:38.0572 5920 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:36:38.0588 5920 sbp2port - ok
20:36:38.0619 5920 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:36:38.0619 5920 SCardSvr - ok
20:36:38.0650 5920 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:36:38.0666 5920 scfilter - ok
20:36:38.0962 5920 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
20:36:38.0978 5920 Schedule - ok
20:36:39.0025 5920 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
20:36:39.0025 5920 SCPolicySvc - ok
20:36:39.0118 5920 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
20:36:39.0118 5920 SDRSVC - ok
20:36:39.0150 5920 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:36:39.0150 5920 secdrv - ok
20:36:39.0181 5920 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
20:36:39.0181 5920 seclogon - ok
20:36:39.0212 5920 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
20:36:39.0212 5920 SENS - ok
20:36:39.0228 5920 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:36:39.0228 5920 SensrSvc - ok
20:36:39.0243 5920 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
20:36:39.0259 5920 Serenum - ok
20:36:39.0290 5920 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
20:36:39.0306 5920 Serial - ok
20:36:39.0337 5920 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
20:36:39.0337 5920 sermouse - ok
20:36:39.0384 5920 [ 2D841B7B7F6DEC32162EDFCC69D61F42 ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
20:36:39.0399 5920 ServiceLayer - ok
20:36:39.0446 5920 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
20:36:39.0446 5920 SessionEnv - ok
20:36:39.0477 5920 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
20:36:39.0493 5920 sffdisk - ok
20:36:39.0493 5920 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
20:36:39.0508 5920 sffp_mmc - ok
20:36:39.0540 5920 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
20:36:39.0540 5920 sffp_sd - ok
20:36:39.0555 5920 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
20:36:39.0571 5920 sfloppy - ok
20:36:39.0586 5920 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:36:39.0602 5920 SharedAccess - ok
20:36:39.0711 5920 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:36:39.0711 5920 ShellHWDetection - ok
20:36:39.0758 5920 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
20:36:39.0774 5920 SiSRaid2 - ok
20:36:39.0789 5920 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
20:36:39.0789 5920 SiSRaid4 - ok
20:36:39.0836 5920 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
20:36:39.0836 5920 Smb - ok
20:36:39.0867 5920 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:36:39.0867 5920 SNMPTRAP - ok
20:36:39.0883 5920 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
20:36:39.0883 5920 spldr - ok
20:36:39.0930 5920 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
20:36:39.0930 5920 Spooler - ok
20:36:40.0850 5920 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
20:36:40.0897 5920 sppsvc - ok
20:36:40.0928 5920 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
20:36:40.0928 5920 sppuinotify - ok
20:36:41.0068 5920 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
20:36:41.0068 5920 srv - ok
20:36:41.0115 5920 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:36:41.0115 5920 srv2 - ok
20:36:41.0131 5920 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:36:41.0146 5920 srvnet - ok
20:36:41.0162 5920 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:36:41.0162 5920 SSDPSRV - ok
20:36:41.0178 5920 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:36:41.0178 5920 SstpSvc - ok
20:36:41.0256 5920 [ F0359F7CE712D69ACEF0886BDB4792ED ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
20:36:41.0256 5920 Stereo Service - ok
20:36:41.0271 5920 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
20:36:41.0287 5920 stexstor - ok
20:36:41.0334 5920 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
20:36:41.0334 5920 stisvc - ok
20:36:41.0365 5920 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
20:36:41.0365 5920 swenum - ok
20:36:41.0396 5920 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
20:36:41.0412 5920 swprv - ok
20:36:41.0505 5920 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
20:36:41.0521 5920 SysMain - ok
20:36:41.0583 5920 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:36:41.0583 5920 TabletInputService - ok
20:36:41.0630 5920 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:36:41.0630 5920 TapiSrv - ok
20:36:41.0646 5920 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
20:36:41.0646 5920 TBS - ok
20:36:41.0739 5920 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:36:41.0755 5920 Tcpip - ok
20:36:41.0786 5920 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:36:41.0802 5920 TCPIP6 - ok
20:36:41.0848 5920 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:36:41.0848 5920 tcpipreg - ok
20:36:41.0880 5920 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
20:36:41.0880 5920 TDPIPE - ok
20:36:41.0911 5920 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
20:36:41.0911 5920 TDTCP - ok
20:36:41.0942 5920 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:36:41.0958 5920 tdx - ok
20:36:41.0989 5920 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
20:36:41.0989 5920 TermDD - ok
20:36:42.0176 5920 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
20:36:42.0192 5920 TermService - ok
20:36:42.0207 5920 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
20:36:42.0207 5920 Themes - ok
20:36:42.0238 5920 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
20:36:42.0238 5920 THREADORDER - ok
20:36:42.0254 5920 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
20:36:42.0254 5920 TrkWks - ok
20:36:42.0379 5920 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:36:42.0379 5920 TrustedInstaller - ok
20:36:42.0410 5920 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
20:36:42.0410 5920 tssecsrv - ok
20:36:42.0472 5920 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:36:42.0472 5920 TsUsbFlt - ok
20:36:42.0535 5920 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:36:42.0535 5920 tunnel - ok
20:36:42.0566 5920 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
20:36:42.0582 5920 uagp35 - ok
20:36:42.0597 5920 [ 2E22C1FD397A5A9FFEF55E9D1FC96C00 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys
20:36:42.0597 5920 UBHelper - ok
20:36:42.0660 5920 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:36:42.0660 5920 udfs - ok
20:36:42.0675 5920 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:36:42.0675 5920 UI0Detect - ok
20:36:42.0691 5920 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:36:42.0691 5920 uliagpkx - ok
20:36:42.0722 5920 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
20:36:42.0738 5920 umbus - ok
20:36:42.0753 5920 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
20:36:42.0769 5920 UmPass - ok
20:36:42.0831 5920 [ 70DDE3A86DBEB1D6C3C30AD687B1877A ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
20:36:42.0831 5920 Updater Service - ok
20:36:42.0847 5920 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
20:36:42.0862 5920 upnphost - ok
20:36:42.0894 5920 [ 54D4B48D443E7228BF64CF7CDC3118AC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
20:36:42.0925 5920 USBAAPL64 - ok
20:36:42.0940 5920 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
20:36:42.0956 5920 usbccgp - ok
20:36:42.0987 5920 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
20:36:43.0003 5920 usbcir - ok
20:36:43.0018 5920 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
20:36:43.0018 5920 usbehci - ok
20:36:43.0034 5920 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
20:36:43.0050 5920 usbhub - ok
20:36:43.0065 5920 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
20:36:43.0065 5920 usbohci - ok
20:36:43.0096 5920 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
20:36:43.0096 5920 usbprint - ok
20:36:43.0112 5920 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:36:43.0128 5920 USBSTOR - ok
20:36:43.0143 5920 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
20:36:43.0143 5920 usbuhci - ok
20:36:43.0159 5920 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
20:36:43.0159 5920 UxSms - ok
20:36:43.0174 5920 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
20:36:43.0174 5920 VaultSvc - ok
20:36:43.0206 5920 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:36:43.0206 5920 vdrvroot - ok
20:36:43.0284 5920 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
20:36:43.0315 5920 vds - ok
20:36:43.0330 5920 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
20:36:43.0330 5920 vga - ok
20:36:43.0346 5920 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
20:36:43.0346 5920 VgaSave - ok
20:36:43.0362 5920 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
20:36:43.0377 5920 vhdmp - ok
20:36:43.0393 5920 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
20:36:43.0408 5920 viaide - ok
20:36:43.0408 5920 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:36:43.0424 5920 volmgr - ok
20:36:43.0455 5920 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:36:43.0455 5920 volmgrx - ok
20:36:43.0471 5920 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:36:43.0471 5920 volsnap - ok
20:36:43.0502 5920 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
20:36:43.0502 5920 vsmraid - ok
20:36:43.0767 5920 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
20:36:43.0783 5920 VSS - ok
20:36:43.0970 5920 [ 7D110D645030C05A06C3CD08D1E47D0A ] vToolbarUpdater13.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe
20:36:43.0986 5920 vToolbarUpdater13.2.0 - ok
20:36:44.0001 5920 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
20:36:44.0001 5920 vwifibus - ok
20:36:44.0048 5920 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
20:36:44.0048 5920 vwififlt - ok
20:36:44.0142 5920 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
20:36:44.0157 5920 W32Time - ok
20:36:44.0173 5920 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
20:36:44.0188 5920 WacomPen - ok
20:36:44.0204 5920 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
20:36:44.0204 5920 WANARP - ok
20:36:44.0220 5920 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
20:36:44.0220 5920 Wanarpv6 - ok
20:36:44.0298 5920 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
20:36:44.0547 5920 WatAdminSvc - ok
20:36:44.0625 5920 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
20:36:44.0641 5920 wbengine - ok
20:36:44.0656 5920 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:36:44.0656 5920 WbioSrvc - ok
20:36:44.0703 5920 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:36:44.0703 5920 wcncsvc - ok
20:36:44.0734 5920 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:36:44.0734 5920 WcsPlugInService - ok
20:36:44.0750 5920 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
20:36:44.0766 5920 Wd - ok
20:36:44.0812 5920 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:36:44.0828 5920 Wdf01000 - ok
20:36:44.0844 5920 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:36:44.0844 5920 WdiServiceHost - ok
20:36:44.0859 5920 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:36:44.0859 5920 WdiSystemHost - ok
20:36:44.0890 5920 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
20:36:44.0906 5920 WebClient - ok
20:36:44.0922 5920 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
20:36:44.0922 5920 Wecsvc - ok
20:36:44.0922 5920 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:36:44.0937 5920 wercplsupport - ok
20:36:44.0984 5920 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
20:36:44.0984 5920 WerSvc - ok
20:36:45.0031 5920 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
20:36:45.0031 5920 WfpLwf - ok
20:36:45.0046 5920 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:36:45.0046 5920 WIMMount - ok
20:36:45.0062 5920 WinDefend - ok
20:36:45.0078 5920 WinHttpAutoProxySvc - ok
20:36:45.0171 5920 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:36:45.0171 5920 Winmgmt - ok
20:36:45.0234 5920 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
20:36:45.0280 5920 WinRM - ok
20:36:45.0343 5920 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\drivers\WinUSB.SYS
20:36:45.0343 5920 WinUsb - ok
20:36:45.0390 5920 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
20:36:45.0390 5920 Wlansvc - ok
20:36:45.0514 5920 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
20:36:45.0514 5920 wlcrasvc - ok
20:36:46.0138 5920 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
20:36:46.0154 5920 wlidsvc - ok
20:36:46.0201 5920 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
20:36:46.0201 5920 WmiAcpi - ok
20:36:46.0248 5920 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:36:46.0248 5920 wmiApSrv - ok
20:36:46.0279 5920 WMPNetworkSvc - ok
20:36:46.0435 5920 [ 83B6CA03C846FCD47F9883D77D1EB27B ] WMZuneComm C:\Program Files\Zune\WMZuneComm.exe
20:36:46.0435 5920 WMZuneComm - ok
20:36:46.0466 5920 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:36:46.0466 5920 WPCSvc - ok
20:36:46.0513 5920 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:36:46.0513 5920 WPDBusEnum - ok
20:36:46.0544 5920 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:36:46.0544 5920 ws2ifsl - ok
20:36:46.0544 5920 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
20:36:46.0560 5920 wscsvc - ok
20:36:46.0560 5920 WSearch - ok
20:36:47.0199 5920 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
20:36:47.0230 5920 wuauserv - ok
20:36:47.0293 5920 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:36:47.0293 5920 WudfPf - ok
20:36:47.0324 5920 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
20:36:47.0324 5920 WUDFRd - ok
20:36:47.0355 5920 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:36:47.0371 5920 wudfsvc - ok
20:36:47.0386 5920 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
20:36:47.0402 5920 WwanSvc - ok
20:36:47.0589 5920 [ 67B787C34FB2888D01B130AE007042D8 ] ZuneNetworkSvc C:\Program Files\Zune\ZuneNss.exe
20:36:47.0714 5920 ZuneNetworkSvc - ok
20:36:47.0792 5920 [ 4D89FC1C20CF655739EFAC5DA81A67BC ] ZuneWlanCfgSvc C:\Program Files\Zune\ZuneWlanCfgSvc.exe
20:36:47.0808 5920 ZuneWlanCfgSvc - ok
20:36:47.0823 5920 ================ Scan global ===============================
20:36:47.0823 5920 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:36:47.0901 5920 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
20:36:47.0917 5920 [ 72CC564BBC70DE268784BCE91EB8A28F ] C:\Windows\system32\winsrv.dll
20:36:47.0979 5920 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:36:48.0104 5920 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:36:48.0104 5920 [Global] - ok
20:36:48.0120 5920 ================ Scan MBR ==================================
20:36:48.0135 5920 [ 70E629B51C16B3C007730C6AE57144C9 ] \Device\Harddisk0\DR0
20:36:50.0413 5920 \Device\Harddisk0\DR0 - ok
20:36:50.0428 5920 [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk3\DR3
20:36:50.0522 5920 \Device\Harddisk3\DR3 - ok
20:36:50.0522 5920 ================ Scan VBR ==================================
20:36:50.0538 5920 [ 022497C1B7BCAD2D5CEEA13EDFA891A2 ] \Device\Harddisk0\DR0\Partition1
20:36:50.0553 5920 \Device\Harddisk0\DR0\Partition1 - ok
20:36:50.0553 5920 [ 33C6D49B30B988DAF454BE0CF3716AC7 ] \Device\Harddisk0\DR0\Partition2
20:36:50.0569 5920 \Device\Harddisk0\DR0\Partition2 - ok
20:36:50.0569 5920 [ D65466E90817479B23742BF9A26B79AC ] \Device\Harddisk3\DR3\Partition1
20:36:50.0569 5920 \Device\Harddisk3\DR3\Partition1 - ok
20:36:50.0569 5920 ============================================================
20:36:50.0569 5920 Scan finished
20:36:50.0569 5920 ============================================================
20:36:50.0584 5916 Detected object count: 0
20:36:50.0584 5916 Actual detected object count: 0

---------------------------------------------------------------------------------------------------------------------------------------------------------------

C:\Users\All Users\Vaudix\50d6a7c724655.ocx Win32/Adware.MultiPlug.D application unable to clean
C:\ProgramData\Vaudix\50d6a7c724655.ocx Win32/Adware.MultiPlug.D application cleaned by deleting - quarantined

#4 Jimbob85

Jimbob85

  • Members
  • 308 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:VA, USA
  • Local time:11:51 PM

Posted 28 December 2012 - 08:54 AM

I would like some more info before I offer any more steps to finish the cleanup process.

If you can I would like to know more about the threat that AVG found. Name and or original file location may be very helpful.
Did you, knowingly, install the vaudix plugin? This is something I am unfamiliar with that appears to be ok but most of the scans see it as adware.
Do you still have any of your original symptoms?

#5 night16

night16
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 28 December 2012 - 11:21 AM

AVG:

"";"Trojan horse Downloader.Generic13.NPN,
C:\Users\XXX\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UBGIYC3V\aol_checker[1].exe";
"Moved to Virus Vault"

Yes I did knowingly install the "plug-in." There are some details I failed to mention, so let me give a run down.
-I installed vaudix.
-Noticed on all websites that certain words would link to ads. Only occurred on infected computer.
-Failed to identify issue, made post on bleepingcomputer.
-Noticed that full blown ads (as opposed to links) were being inserted on facebook. (on profiles under their info and in their news feed.) Did not notice this on other sites.
-Scanned with AVG a few days later, it identifies an issues and quarantines.
-Return to facebook and the ads are gone.
-Continue to browse and notice that words are still linked.
-Check my Chrome extensions (derp) vaudix is an extension. Disable and delete vaudix from extension.
-Clears up all noticed symptoms.
-I check in on bleeping computer, see your post, and reply with the reports.
-Afterwards I check other browsers to see if they have the same symptoms.
-Firefox: has "link" problem. Vaudix is installed as extension. Disable and delete.
-IE: no problems, no Vaudix extension.
-Opera: no problems, no Vaudix extension.

Everything seems fine now. It always just appeared as adware, but I was afraid that it could be more malicious.

#6 Jimbob85

Jimbob85

  • Members
  • 308 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:VA, USA
  • Local time:11:51 PM

Posted 28 December 2012 - 11:34 AM

Ok. Let me see if I understand everything. At this point everything is ok, all browsers function properly?

If this is the case I would like to see a quick scan of MBAM and suggest another run of ESET.

If you are still having problems please let me know.

As far as good security practice goes it is recommended to only have one web browser, other than IE, on your pc. If you chose to run more than one, as a lot of people do, please make sure that you keep them up to date and all of the plugins (for each browser) updated as well.

#7 night16

night16
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 28 December 2012 - 06:09 PM

Yep, everything looks just fine, just though you would like all the details. Makes sense to have only one browser. I nearly always use Chrome, and had the others just to try them.

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.12.27.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
XXX :: XXX-DESKTOP [administrator]

12/28/2012 2:53:49 PM
mbam-log-2012-12-28 (14-53-49).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 480569
Time elapsed: 1 hour(s), 37 minute(s), 2 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#8 night16

night16
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 29 December 2012 - 12:42 AM

Just finished ESET scan, found nothing new.

#9 Jimbob85

Jimbob85

  • Members
  • 308 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:VA, USA
  • Local time:11:51 PM

Posted 29 December 2012 - 12:43 PM

Glad to hear that everything is back up and running properly! Happy new year!

#10 night16

night16
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:10:51 PM

Posted 29 December 2012 - 09:54 PM

Thanks again for all your help and happy new year to you too!

#11 Jimbob85

Jimbob85

  • Members
  • 308 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:VA, USA
  • Local time:11:51 PM

Posted 29 December 2012 - 09:55 PM

You are very welcome! Just glad to help.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users