Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet access lost after about 1 hour after reboot


  • Please log in to reply
18 replies to this topic

#1 cma6

cma6

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 09 June 2013 - 08:57 PM

Mod Edit:Moved to forum for DDS logs ~~ boopme

 

Starting a month ago, after I uninstalled and reinstalled System Suite 14, which includes a firewall, on my Win XP Pro system, my internet access would slow to a crawl or be entirely lost, usually after about one hour after rebooting.

 The uninstall/reinstall of SS14 also caused me to lose access to the Win XP Pro GUI because of deletion of key Win XP Pro files: NTLDR, NTDETECT.com and boot.ini. However, I was able to recover from that problem.

 

I have tried various winsock and TCP/IP repair programs but with only temporary improvement.

 

I have attached my Hijackthis log.

 

Thanks for your assistance,

           CMA

Attached Files


Edited by boopme, 09 June 2013 - 09:03 PM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:09:23 PM

Posted 12 June 2013 - 09:59 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===
Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete tab follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).
Please download ComboFix from one of these locations:
Link 1
Link 2
IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Some Rookit infection may damage your boot sector. The Windows Recovery Console may be needed to restore it. Do not bypass this installation. You may regret it.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
RcAuto1.gif
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
whatnext.png
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Note: If you have difficulty properly disabling your protection programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

Do not mouse click ComboFix's window while it's running. That may cause it to stall

Note: If after running ComboFix you get this error message "Illegal operation attempted on a registry key that has been marked for deletion." when attempting to run a program all you need to do is restart the computer to reset the registry.
===

Third party programs if not up to date can be the cause of infiltration an infection.

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Please paste the logs in your next reply, DO NOT ATTACH THEM
Let me know what problem persists.

#3 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 12 June 2013 - 01:51 PM

Nasdaq, thank you for the detailed response. I have already run my System Suite 14 virus scans and also Malwarebytes.

Does Adwcleaner do anything different?

Do I need to shut down System Suite's firewall before running AdwCleaner?

Do I need to install the Microsoft Windows Recovery Console before running AdwCleaner?

I am not clear if I am supposed to run first AdwCleaner and report back to you or run both AdwCleaner and then Combofix before reporting back to you.

              Thanks for your expertise.



#4 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 12 June 2013 - 04:35 PM

Nasdaq: Here is the contents of the AdwCleaner report. I greatly appreciate your expert assistance.

 

# AdwCleaner v2.303 - Logfile created 06/12/2013 at 17:20:41
# Updated 08/06/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : lao - MORPHY
# Boot Mode : Normal
# Running from : C:\Net_copy1\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\All Users\Application Data\Viewpoint
Folder Deleted : C:\Program Files\Viewpoint

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\Software\MetaStream
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
Key Deleted : HKLM\Software\Viewpoint

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Documents and Settings\lao\Application Data\Mozilla\Firefox\Profiles\ewxql6zj.default\prefs.js

C:\Documents and Settings\lao\Application Data\Mozilla\Firefox\Profiles\ewxql6zj.default\user.js ... Deleted !

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2778 octets] - [12/06/2013 17:20:41]

########## EOF - C:\AdwCleaner[S1].txt - [2838 octets] ##########



#5 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:09:23 PM

Posted 13 June 2013 - 07:26 AM

Shut down System Suite's firewall
There is no need to install the Microsoft Windows Recovery Console. It it's all ready installed disable it also.

If ComboFix still give you sign that they are running ignore it and run the tool.

Post the log for my review.

#6 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 13 June 2013 - 07:47 AM

Nasdaq:

 How would I disable the Microsoft Windows Recovery Console before running Combofix?

                Thanks, CMA



#7 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:09:23 PM

Posted 13 June 2013 - 08:28 AM

How would I disable the Microsoft Windows Recovery Console before running Combofix?


Sorry about that leave that as it is.
I was thinking of Microsoft defender.

#8 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 13 June 2013 - 09:35 AM

Hi Nasdaq:

  Are you a stock trader? I used to be an options market maker on the ASE and still do a lot with stocks and options.

  Combofix required me to install the MS Win Recovery Console because it was not active. Here is the log. I hope you find something there.

                    Thank you,

                                    CMA

 

ComboFix 13-06-08.02 - lao 06/13/2013  10:25:32.1.2 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.3070.2693 [GMT -4:00]
Running from: c:\net_copy1\ComboFix.exe
AV: Avanquest SystemSuite *Disabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\lao\GoToAssistDownloadHelper.exe
c:\windows\AutoRun.ini
c:\windows\EventSystem.log
c:\windows\system32\SET16A.tmp
c:\windows\system32\SET16C.tmp
c:\windows\system32\SET17A.tmp
c:\windows\system32\SET6D.tmp
c:\windows\system32\SET6E.tmp
c:\windows\system32\SET6F.tmp
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((((   Files Created from 2013-05-13 to 2013-06-13  )))))))))))))))))))))))))))))))
.
.
2013-06-09 17:19 . 2013-06-09 17:19    --------    d-----w-    c:\windows\system32\wbem\Repository
2013-06-07 00:11 . 2013-06-07 00:11    --------    d-----w-    C:\Firefox
2013-06-06 23:48 . 2013-06-06 23:48    --------    d-----w-    C:\ERDNT
2013-06-06 18:08 . 2013-06-06 18:08    --------    d-----w-    c:\windows\system32\drivers\VDD
2013-05-31 18:37 . 2013-06-06 18:08    --------    d-----r-    C:\_Backup.RC
2013-05-31 18:37 . 2013-04-11 15:06    41584    ----a-w-    c:\windows\system32\drivers\gfiark.sys
2013-05-31 18:36 . 2012-10-24 17:39    66344    ----a-w-    c:\windows\system32\drivers\sbapifs.sys
2013-05-31 18:36 . 2012-10-24 17:39    22064    ----a-w-    c:\windows\system32\drivers\sbaphd.sys
2013-05-31 18:31 . 2013-04-08 22:24    16776    ------w-    c:\windows\system32\drivers\AQFileRestore.sys
2013-05-31 18:31 . 2012-02-09 17:58    35000    ----a-w-    c:\windows\system32\mxntdfg.exe
2013-05-31 18:30 . 2013-06-06 18:08    --------    d-----w-    c:\documents and settings\All Users\Application Data\Avanquest
2013-05-31 18:29 . 2013-06-13 14:18    --------    d-----w-    C:\SS14
2013-05-31 17:55 . 2013-05-31 17:55    --------    d-----w-    c:\documents and settings\All Users\Application Data\GFI Software
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-07 22:30 . 2004-08-11 21:00    920064    ----a-w-    c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2004-08-11 21:00    43520    ----a-w-    c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2004-08-11 21:00    1469440    ----a-w-    c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2004-08-11 21:00    385024    ------w-    c:\windows\system32\html.iec
2013-05-03 01:30 . 2004-08-11 21:00    2149888    ------w-    c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2004-08-04 02:59    2028544    ------w-    c:\windows\system32\ntkrnlpa.exe
2013-04-20 04:41 . 2012-05-07 13:59    691592    ------w-    c:\windows\system32\FlashPlayerApp.exe
2013-04-20 04:41 . 2011-06-07 23:07    71048    ------w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-20 04:39 . 2013-04-20 04:39    144896    ------w-    c:\windows\system32\javacpl.cpl
2013-04-20 04:39 . 2013-04-20 04:39    94112    ------w-    c:\windows\system32\WindowsAccessBridge.dll
2013-04-20 04:39 . 2012-07-12 23:40    866720    ------w-    c:\windows\system32\npDeployJava1.dll
2013-04-20 04:39 . 2011-08-17 23:08    788896    ------w-    c:\windows\system32\deployJava1.dll
2013-04-10 01:31 . 2004-08-11 21:00    1876352    ------w-    c:\windows\system32\win32k.sys
2013-04-04 18:50 . 2012-01-01 01:20    22856    ------w-    c:\windows\system32\drivers\mbam.sys
2013-03-17 03:38 . 2012-12-07 15:46    64544    ------w-    c:\documents and settings\lao\MSSSerif96.fon
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PxDotNetLoader"="c:\activetraderpro\Fidelity Active Trader\System\ATPStartupAssistant.exe" [2013-04-19 44104]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoNetworkConnections"= 01000000
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29    64592    ------w-    c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute    REG_MULTI_SZ       \0
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 1000 series.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logo Calibration Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logo Calibration Loader.lnk
backup=c:\windows\pss\Logo Calibration Loader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ProfileReminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ProfileReminder.lnk
backup=c:\windows\pss\ProfileReminder.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Qshelf.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Qshelf.lnk
backup=c:\windows\pss\Qshelf.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Adobe Gamma.cpl.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Adobe Gamma.cpl.lnk
backup=c:\windows\pss\Adobe Gamma.cpl.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^IDrive Tray.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\IDrive Tray.lnk
backup=c:\windows\pss\IDrive Tray.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=c:\windows\pss\OpenOffice.org 2.0.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^QuickShelf 2000.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\QuickShelf 2000.lnk
backup=c:\windows\pss\QuickShelf 2000.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Sonic INSTALLit! Setup.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Sonic INSTALLit! Setup.lnk
backup=c:\windows\pss\Sonic INSTALLit! Setup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^lao^Start Menu^Programs^Startup^Yahoo! Desktop Search System Tray.lnk]
path=c:\documents and settings\lao\Start Menu\Programs\Startup\Yahoo! Desktop Search System Tray.lnk
backup=c:\windows\pss\Yahoo! Desktop Search System Tray.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-02-16 23:49    149024    -c----w-    c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-02-16 23:57    1945960    -c----w-    c:\acronis10\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-04-04 21:06    958576    ----a-w-    c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 08:44    500208    ------w-    c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-07-23 03:10    402432    ------w-    c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2008-12-03 13:58    2356088    ------w-    c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12    15360    ------w-    c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2006-07-17 01:29    389120    -c----w-    c:\program files\Dell Support\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
2005-07-26 22:52    184408    -c----w-    c:\diskeeper\DkIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2010-10-28 23:32    1352272    ------w-    c:\logitech\SetPointP\SetPoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-12-06 21:57    136176    -----tw-    c:\documents and settings\lao\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDriveE Startup]
2010-10-28 14:38    180224    ------w-    c:\idrive\IDrvieEStartup.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Intuit SyncManager]
2011-02-22 07:28    1497352    ------w-    c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 20:50    221184    -c----w-    c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2008-10-24 14:14    79136    ------w-    c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2012-05-25 08:25    6595928    ------w-    c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2011-01-08 00:58    13880424    ------w-    c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-01-08 00:58    111208    ------w-    c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2010-11-04 13:51    1753192    ------w-    c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 22:36    421888    ------w-    c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 11:32    253816    ------w-    c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 18:37    517096    ------w-    c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
2007-02-16 23:45    1169776    -c----w-    c:\acronis10\TrueImageMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"RemoteRegistry"=2 (0x2)
"RasMan"=3 (0x3)
"mnmsrvc"=3 (0x3)
"ERSvc"=2 (0x2)
"Diskeeper"=3 (0x3)
"AcrSch2Svc"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"Fax"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"QBFCService"=3 (0x3)
"QBCFMonitorService"=2 (0x2)
"YahooAUService"=2 (0x2)
"RasAuto"=3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2010 9.0.0.736\\English\\setup.exe"=
"c:\\QuickBooks Pro 2010\\QBDBMgrN.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
.
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [5/31/2013 2:36 PM 22064]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [6/9/2010 7:33 PM 10448]
R2 PDIHWCTL;PDIHWCTL;c:\windows\system32\drivers\pdihwctl.sys [9/22/2009 12:00 AM 14416]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [5/31/2013 2:36 PM 66344]
R2 VCOMCloudAgent;VCOM Cloud Agent Service;c:\syssuite14\VcomCloudAgent.exe [4/11/2013 6:05 PM 86392]
R3 KFilter;KFilter;c:\ss14\KFilter.sys [5/31/2013 2:31 PM 62496]
R3 TFilter;TFilter;c:\ss14\TFilter.sys [5/31/2013 2:31 PM 29016]
S1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys --> c:\windows\system32\drivers\SBREDrv.sys [?]
S2 .AVQWindowsMonitorService;SystemSuite Professional Process Monitor;c:\ss14\AVQWinMonEngine.exe [5/31/2013 2:31 PM 249120]
S2 AQFileRestoreSrv;AQFileRestoreSrv;c:\ss14\AQFileRestoreSrv.exe [5/31/2013 2:31 PM 82808]
S2 RoxLiveShare10;LiveShare P2P Server 10;"c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" --> c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [?]
S2 SBAMSvc;SystemSuite;c:\ss14\Antivirus\SBAMSvc.exe [9/20/2012 5:39 AM 3677000]
S2 SessionLauncher;SessionLauncher;c:\docume~1\lao\LOCALS~1\Temp\DX9\SessionLauncher.exe --> c:\docume~1\lao\LOCALS~1\Temp\DX9\SessionLauncher.exe [?]
S3 Apni2ofints;Apni2ofints; [x]
S3 AQFileRestore;AQFileRestore;c:\windows\system32\drivers\AQFileRestore.sys [5/31/2013 2:31 PM 16776]
S3 eyeonedp;eye-one display;c:\windows\system32\drivers\EyeOneDp.sys [9/22/2009 12:00 AM 44344]
S3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys [5/31/2013 2:37 PM 41584]
S3 i1display;i1 Display;c:\windows\system32\drivers\i1display.sys [5/23/2008 3:19 PM 44344]
S3 IDriveE Service;IDriveE Service;c:\idrive\IDriveE Service.exe [11/4/2010 7:50 PM 143360]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 2:37 PM 517096]
S4 IDriveWebM;IDrive WebManager;c:\idrive\IDriveWebM.exe [11/4/2010 7:51 PM 267720]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - TFILTER
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-11 c:\windows\Tasks\AdobeAAMUpdater-1.0-MORPHY-lao.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-12-22 08:44]
.
2013-06-13 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.vintagetextile.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\lao\Application Data\Mozilla\Firefox\Profiles\ewxql6zj.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - ExtSQL: 2013-06-06 14:09; donottrackplus@abine.com; c:\documents and settings\lao\Application Data\Mozilla\Firefox\Profiles\ewxql6zj.default\extensions\donottrackplus@abine.com
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\adobe\Reader\Reader_sl.exe
MSConfigStartUp-CaISSDT - c:\pest patrol\caissdt.exe
MSConfigStartUp-DLA - c:\windows\System32\DLA\DLACTRLW.EXE
MSConfigStartUp-DMXLauncher - c:\dell\Cineplayer\DMXLauncher.exe
MSConfigStartUp-eTrustPPAP - c:\pest patrol\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
MSConfigStartUp-Logitech Hardware Abstraction Layer - c:\windows\KHALMNPR.EXE
MSConfigStartUp-Malwarebytes' Anti-Malware - c:\malwarebytes\mbamgui.exe
MSConfigStartUp-PxDotNetLoader - c:\atpro\Fidelity Active Trader\System\ATPStartupAssistant.exe
MSConfigStartUp-SBCSTray - c:\counterspy\SBCSTray.exe
MSConfigStartUp-SMSystemAnalyzer - c:\system mechanic7\SMSystemAnalyzer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-13 10:28
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ...
.
scanning hidden files ...  
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(788)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'lsass.exe'(844)
c:\windows\system32\relog_ap.dll
.
Completion time: 2013-06-13  10:30:43
ComboFix-quarantined-files.txt  2013-06-13 14:30
.
Pre-Run: 138,132,705,280 bytes free
Post-Run: 138,224,263,168 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
timeout=2
Default=multi(0)disk(0)rdisk(0)partition(2)\Windows
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\Windows="3RD TRY THIS wahlen Sie diesen Third" /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\Windows="1ST TRY THIS seleccione esto primero" /fastdetect
multi(0)disk(0)rdisk(1)partition(1)\Windows="2ND TRY THIS essayez ceci en deuzieme" /fastdetect
multi(0)disk(0)rdisk(1)partition(2)\Windows="4TH TRY THIS selezioni questo fourth" /fastdetect
multi(0)disk(0)rdisk(0)partition(3)\Windows="5TH TRY THIS selecione este fifth" /fastdetect
multi(0)disk(0)rdisk(1)partition(3)\Windows="6TH TRY THIS seleccione este sexto" /fastdetect
multi(0)disk(0)rdisk(0)partition(4)\Windows="7TH TRY THIS essayez ceci en septieme" /fastdetect
multi(0)disk(0)rdisk(1)partition(4)\Windows="8TH TRY THIS wahlen Sie dieses achte" /fastdetect
C:\="9TH TRY THIS selezioni questo nono"
D:\="10TH TRY THIS selecione este decimo"
.
- - End Of File - - B458EF75B1462A726A9D956A507CA3ED
D1AD4C53EADD115593E05FA56D6B9DEA
 



#9 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:09:23 PM

Posted 13 June 2013 - 10:12 AM

Any improvement?

#10 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 13 June 2013 - 10:20 AM

Nasdaq:

I thought that Combofix, unlike the Adcleaner I ran yesterday, only reports on problems, but doesn't clean out malware.  However, if Combofix also repairs, then maybe there will be some improvement.

  I ran Combofix at 10:25 AM today. The first sign that there is some improvement will be if, in 3-5 hours, my internet access remains, instead of gradually fading away as it always does. I should know for sure about the effectiveness, if any, of Combofix by this evening.

I will let you know later.

               CMA



#11 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 13 June 2013 - 04:55 PM

Nasdaq:

  System has had good internet access for 7.5 hours since I ran Combofix. That is a good sign. If I can say the same at this time tomorrow, then you will have fixed the problem. I will let you know.

              CMA



#12 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 14 June 2013 - 09:13 AM

Internet worked all day yesterday. However, when I rebooted this morning, Windows installed two updates. I think they were the Windows Recovery Console but they were not identified. Today, the internet stopped working after about one hour.



#13 nasdaq

nasdaq

  • Malware Response Team
  • 40,171 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:09:23 PM

Posted 14 June 2013 - 10:12 AM

Read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • Double-click on TDSSKiller.exe to run the application.
    tdss1.png
  • Click Change parameters
    settings20121003115955.png
  • Check the boxes next to Verify Driver Digital Signature and Detect TDLFS file system, then click OK
    tdss3.png
  • Click on the Start Scan button to begin the scan and wait for it to finish.
    NOTE: Do not use the computer during the scan!
  • During the scan it will look similar to the image below:
    tdss4.jpg
  • When it finishes, you will either see a report that no threats were found like below:
    tdss5.jpg
    If no threats are found at this point, just click the Report selection on the top right of the form to generate a log. A log file report will pop which you can just close since the report file is already saved.
  • If any infection or suspected items are found, you will see a window similar to below:
    tdss7.jpg
    • If you have files that are shown to fail signature check do not take any action on these. Make sure you select Skip. I will tell you what to do with these later. They may not be issues at all.
    • If Suspicious objects are detected, the default action will be Skip. Leave the default set to Skip.
    • If Malicious objects are detected, they will show in the Scan results. TDSSKiller automatically selects an action (Cure or Delete) for malicious objects
    • Make sure that Cure is selected. Important! - If Cure is not available, please choose Skip instead. Do not choose Delete unless instructed to do so.
  • Click Continue to apply selected actions.
  • A reboot may be required to complete disinfection. A window like the below will appear:
    tdss6.jpg
    Reboot immediately if TDSSKiller states that one is needed.
  • Whether an infection is found or not, a log file should have already been created on your C: drive (or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run.
  • Paste the log to your next reply, DO NOT ATTACH IT.
===

Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it
  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please post the contents of that log in your next reply.
  • There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

    Note: You may be asked if you want to download Avast Free Antivirus I suggest you deny this download unless you do not have any Antivirus protection on the computer.
    ===


#14 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 14 June 2013 - 11:30 AM

Nasdaq:

 Below is the TDSSKiller log. There were 17 Suspicious objects found, all "Unsigned file", all Medium risk. So all were skipped. The following were unknown to me:

  LHidUsbK,  PDIHWCTL,   Switchboard, tifsfilter,  timeounter.

                     Thank you, CMA

 

12:18:22.0000 3692  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
12:18:23.0281 3692  ============================================================
12:18:23.0281 3692  Current date / time: 2013/06/14 12:18:23.0281
12:18:23.0281 3692  SystemInfo:
12:18:23.0281 3692  
12:18:23.0281 3692  OS Version: 5.1.2600 ServicePack: 3.0
12:18:23.0281 3692  Product type: Workstation
12:18:23.0281 3692  ComputerName: MORPHY
12:18:23.0281 3692  UserName: lao
12:18:23.0281 3692  Windows directory: C:\Windows
12:18:23.0281 3692  System windows directory: C:\Windows
12:18:23.0281 3692  Processor architecture: Intel x86
12:18:23.0281 3692  Number of processors: 2
12:18:23.0281 3692  Page size: 0x1000
12:18:23.0281 3692  Boot type: Normal boot
12:18:23.0281 3692  ============================================================
12:18:23.0750 3692  Drive \Device\Harddisk0\DR0 - Size: 0x3A35000000 (232.83 Gb), SectorSize: 0x200, Cylinders: 0x76B9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
12:18:23.0750 3692  Drive \Device\Harddisk1\DR5 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
12:18:23.0843 3692  ============================================================
12:18:23.0843 3692  \Device\Harddisk0\DR0:
12:18:23.0843 3692  MBR partitions:
12:18:23.0843 3692  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x156DD1AB
12:18:23.0859 3692  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x156F8931, BlocksNum 0x746066D
12:18:23.0859 3692  \Device\Harddisk1\DR5:
12:18:23.0875 3692  MBR partitions:
12:18:23.0875 3692  \Device\Harddisk1\DR5\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82
12:18:23.0875 3692  ============================================================
12:18:23.0906 3692  C: <-> \Device\Harddisk0\DR0\Partition1
12:18:23.0937 3692  K: <-> \Device\Harddisk1\DR5\Partition1
12:18:23.0968 3692  D: <-> \Device\Harddisk0\DR0\Partition2
12:18:23.0968 3692  ============================================================
12:18:23.0968 3692  Initialize success
12:18:23.0968 3692  ============================================================
12:18:58.0656 3852  ============================================================
12:18:58.0656 3852  Scan started
12:18:58.0656 3852  Mode: Manual; SigCheck; TDLFS;
12:18:58.0656 3852  ============================================================
12:18:58.0937 3852  ================ Scan system memory ========================
12:18:58.0937 3852  System memory - ok
12:18:58.0937 3852  ================ Scan services =============================
12:18:59.0046 3852  [ D222B9CBE9847681A84EFA181C4E4D4E ] .AVQWindowsMonitorService C:\SS14\AVQWinMonEngine.exe
12:18:59.0218 3852  .AVQWindowsMonitorService - ok
12:18:59.0281 3852  Abiosdsk - ok
12:18:59.0296 3852  [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5        C:\Windows\system32\DRIVERS\ABP480N5.SYS
12:19:00.0578 3852  abp480n5 - ok
12:19:00.0625 3852  [ 8FD99680A539792A30E97944FDAECF17 ] ACPI            C:\Windows\system32\DRIVERS\ACPI.sys
12:19:00.0734 3852  ACPI - ok
12:19:00.0765 3852  [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC          C:\Windows\system32\drivers\ACPIEC.sys
12:19:00.0843 3852  ACPIEC - ok
12:19:00.0921 3852  [ 46A5CBB09B8F0C46F8CBE9210E5E3BE2 ] AcrSch2Svc      C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
12:19:01.0000 3852  AcrSch2Svc - ok
12:19:01.0015 3852  [ C1EB9968EC89FBA5F3A264E2E57923AB ] Adobe LM Service C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
12:19:01.0062 3852  Adobe LM Service ( UnsignedFile.Multi.Generic ) - warning
12:19:01.0062 3852  Adobe LM Service - detected UnsignedFile.Multi.Generic (1)
12:19:01.0093 3852  [ 9A11864873DA202C996558B2106B0BBC ] adpu160m        C:\Windows\system32\DRIVERS\adpu160m.sys
12:19:01.0187 3852  adpu160m - ok
12:19:01.0218 3852  [ 8BED39E3C35D6A489438B8141717A557 ] aec             C:\Windows\system32\drivers\aec.sys
12:19:01.0328 3852  aec - ok
12:19:01.0343 3852  [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD             C:\Windows\System32\drivers\afd.sys
12:19:01.0406 3852  AFD - ok
12:19:01.0421 3852  [ 0EBB674888CBDEFD5773341C16DD6A07 ] AFS2K           C:\Windows\system32\drivers\AFS2K.sys
12:19:01.0718 3852  AFS2K - ok
12:19:01.0750 3852  [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440          C:\Windows\system32\DRIVERS\agp440.sys
12:19:01.0843 3852  agp440 - ok
12:19:01.0859 3852  [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ          C:\Windows\system32\DRIVERS\agpCPQ.sys
12:19:01.0968 3852  agpCPQ - ok
12:19:02.0000 3852  [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x         C:\Windows\system32\DRIVERS\aha154x.sys
12:19:02.0062 3852  Aha154x - ok
12:19:02.0078 3852  [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2         C:\Windows\system32\DRIVERS\aic78u2.sys
12:19:02.0187 3852  aic78u2 - ok
12:19:02.0203 3852  [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx         C:\Windows\system32\DRIVERS\aic78xx.sys
12:19:02.0296 3852  aic78xx - ok
12:19:02.0312 3852  [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter         C:\Windows\system32\alrsvc.dll
12:19:02.0421 3852  Alerter - ok
12:19:02.0437 3852  [ 8C515081584A38AA007909CD02020B3D ] ALG             C:\Windows\System32\alg.exe
12:19:02.0500 3852  ALG - ok
12:19:02.0515 3852  [ 1140AB9938809700B46BB88E46D72A96 ] AliIde          C:\Windows\system32\DRIVERS\aliide.sys
12:19:02.0625 3852  AliIde - ok
12:19:02.0640 3852  [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541        C:\Windows\system32\DRIVERS\alim1541.sys
12:19:02.0750 3852  alim1541 - ok
12:19:02.0765 3852  [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp          C:\Windows\system32\DRIVERS\amdagp.sys
12:19:02.0875 3852  amdagp - ok
12:19:02.0890 3852  [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint          C:\Windows\system32\DRIVERS\amsint.sys
12:19:02.0953 3852  amsint - ok
12:19:02.0953 3852  Apni2ofints - ok
12:19:03.0000 3852  [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt         C:\Windows\System32\appmgmts.dll
12:19:03.0046 3852  AppMgmt - ok
12:19:03.0062 3852  [ 384D260F28FE914AA836C637B24F3A91 ] AQFileRestore   C:\Windows\system32\DRIVERS\AQFileRestore.sys
12:19:03.0234 3852  AQFileRestore - ok
12:19:03.0265 3852  [ C9CC7A2A02281194115117E95BC80D5B ] AQFileRestoreSrv C:\SS14\AQFileRestoreSrv.exe
12:19:03.0281 3852  AQFileRestoreSrv - ok
12:19:03.0296 3852  [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394         C:\Windows\system32\DRIVERS\arp1394.sys
12:19:03.0390 3852  Arp1394 - ok
12:19:03.0406 3852  [ 62D318E9A0C8FC9B780008E724283707 ] asc             C:\Windows\system32\DRIVERS\asc.sys
12:19:03.0484 3852  asc - ok
12:19:03.0515 3852  [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p        C:\Windows\system32\DRIVERS\asc3350p.sys
12:19:03.0578 3852  asc3350p - ok
12:19:03.0593 3852  [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550         C:\Windows\system32\DRIVERS\asc3550.sys
12:19:03.0703 3852  asc3550 - ok
12:19:03.0718 3852  [ D880831279ED91F9A4190A2DB9539EA9 ] ASCTRM          C:\Windows\system32\drivers\ASCTRM.sys
12:19:03.0734 3852  ASCTRM ( UnsignedFile.Multi.Generic ) - warning
12:19:03.0734 3852  ASCTRM - detected UnsignedFile.Multi.Generic (1)
12:19:03.0781 3852  [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
12:19:03.0796 3852  aspnet_state - ok
12:19:03.0828 3852  [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
12:19:03.0921 3852  AsyncMac - ok
12:19:03.0937 3852  [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi           C:\Windows\system32\DRIVERS\atapi.sys
12:19:04.0031 3852  atapi - ok
12:19:04.0031 3852  Atdisk - ok
12:19:04.0062 3852  [ 9916C1225104BA14794209CFA8012159 ] Atmarpc         C:\Windows\system32\DRIVERS\atmarpc.sys
12:19:04.0171 3852  Atmarpc - ok
12:19:04.0203 3852  [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv        C:\Windows\System32\audiosrv.dll
12:19:04.0296 3852  AudioSrv - ok
12:19:04.0296 3852  [ D9F724AA26C010A217C97606B160ED68 ] audstub         C:\Windows\system32\DRIVERS\audstub.sys
12:19:04.0390 3852  audstub - ok
12:19:04.0421 3852  [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep            C:\Windows\system32\drivers\Beep.sys
12:19:04.0500 3852  Beep - ok
12:19:04.0531 3852  [ 574738F61FCA2935F5265DC4E5691314 ] BITS            C:\Windows\system32\qmgr.dll
12:19:04.0656 3852  BITS - ok
12:19:04.0687 3852  [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser         C:\Windows\System32\browser.dll
12:19:04.0765 3852  Browser - ok
12:19:04.0796 3852  catchme - ok
12:19:04.0812 3852  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf           C:\Windows\system32\DRIVERS\cbidf2k.sys
12:19:04.0921 3852  cbidf - ok
12:19:04.0921 3852  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k         C:\Windows\system32\drivers\cbidf2k.sys
12:19:05.0015 3852  cbidf2k - ok
12:19:05.0031 3852  [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt        C:\Windows\system32\DRIVERS\cd20xrnt.sys
12:19:05.0093 3852  cd20xrnt - ok
12:19:05.0125 3852  [ C1B486A7658353D33A10CC15211A873B ] Cdaudio         C:\Windows\system32\drivers\Cdaudio.sys
12:19:05.0234 3852  Cdaudio - ok
12:19:05.0265 3852  [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs            C:\Windows\system32\drivers\Cdfs.sys
12:19:05.0359 3852  Cdfs - ok
12:19:05.0375 3852  [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
12:19:05.0484 3852  Cdrom - ok
12:19:05.0484 3852  Changer - ok
12:19:05.0515 3852  [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc           C:\Windows\system32\cisvc.exe
12:19:05.0625 3852  CiSvc - ok
12:19:05.0625 3852  [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv         C:\Windows\system32\clipsrv.exe
12:19:05.0718 3852  ClipSrv - ok
12:19:05.0781 3852  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:19:05.0796 3852  clr_optimization_v2.0.50727_32 - ok
12:19:05.0812 3852  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:19:05.0828 3852  clr_optimization_v4.0.30319_32 - ok
12:19:05.0859 3852  [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde          C:\Windows\system32\DRIVERS\cmdide.sys
12:19:05.0953 3852  CmdIde - ok
12:19:05.0953 3852  COMSysApp - ok
12:19:05.0968 3852  [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray        C:\Windows\system32\DRIVERS\cpqarray.sys
12:19:06.0078 3852  Cpqarray - ok
12:19:06.0093 3852  [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc        C:\Windows\System32\cryptsvc.dll
12:19:06.0234 3852  CryptSvc - ok
12:19:06.0234 3852  [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k         C:\Windows\system32\DRIVERS\dac2w2k.sys
12:19:06.0343 3852  dac2w2k - ok
12:19:06.0359 3852  [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt        C:\Windows\system32\DRIVERS\dac960nt.sys
12:19:06.0453 3852  dac960nt - ok
12:19:06.0484 3852  [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:19:06.0578 3852  DcomLaunch - ok
12:19:06.0609 3852  [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
12:19:06.0718 3852  Dhcp - ok
12:19:06.0734 3852  [ 044452051F3E02E7963599FC8F4F3E25 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
12:19:06.0828 3852  Disk - ok
12:19:06.0875 3852  [ 15A2F2D06B1F8D2AD2BE055C40CB1B74 ] Diskeeper       C:\Diskeeper\DkService.exe
12:19:07.0718 3852  Diskeeper ( UnsignedFile.Multi.Generic ) - warning
12:19:07.0718 3852  Diskeeper - detected UnsignedFile.Multi.Generic (1)
12:19:07.0718 3852  dmadmin - ok
12:19:07.0765 3852  [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot          C:\Windows\system32\drivers\dmboot.sys
12:19:07.0875 3852  dmboot - ok
12:19:07.0890 3852  [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio            C:\Windows\system32\drivers\dmio.sys
12:19:08.0000 3852  dmio - ok
12:19:08.0015 3852  [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload          C:\Windows\system32\drivers\dmload.sys
12:19:08.0125 3852  dmload - ok
12:19:08.0156 3852  [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver        C:\Windows\System32\dmserver.dll
12:19:08.0265 3852  dmserver - ok
12:19:08.0265 3852  [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic          C:\Windows\system32\drivers\DMusic.sys
12:19:08.0359 3852  DMusic - ok
12:19:08.0375 3852  [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:19:08.0453 3852  Dnscache - ok
12:19:08.0484 3852  [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc         C:\Windows\System32\dot3svc.dll
12:19:08.0593 3852  Dot3svc - ok
12:19:08.0609 3852  [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o          C:\Windows\system32\DRIVERS\dpti2o.sys
12:19:08.0718 3852  dpti2o - ok
12:19:08.0734 3852  [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
12:19:08.0828 3852  drmkaud - ok
12:19:08.0859 3852  [ 2AC2372FFAD9ADC85672CC8E8AE14BE9 ] DSproct         C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys
12:19:09.0046 3852  DSproct ( UnsignedFile.Multi.Generic ) - warning
12:19:09.0046 3852  DSproct - detected UnsignedFile.Multi.Generic (1)
12:19:09.0062 3852  [ 3FCA03CBCA11269F973B70FA483C88EF ] E100B           C:\Windows\system32\DRIVERS\e100b325.sys
12:19:09.0171 3852  E100B - ok
12:19:09.0187 3852  [ 6F7CCD3C02B26D530900F06D98171A69 ] e1express       C:\Windows\system32\DRIVERS\e1e5132.sys
12:19:09.0281 3852  e1express - ok
12:19:09.0296 3852  [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost         C:\Windows\System32\eapsvc.dll
12:19:09.0406 3852  EapHost - ok
12:19:09.0421 3852  [ BC93B4A066477954555966D77FEC9ECB ] ERSvc           C:\Windows\System32\ersvc.dll
12:19:09.0531 3852  ERSvc - ok
12:19:09.0562 3852  [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog        C:\Windows\system32\services.exe
12:19:09.0609 3852  Eventlog - ok
12:19:09.0625 3852  [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem     C:\WINDOWS\system32\es.dll
12:19:09.0703 3852  EventSystem - ok
12:19:09.0718 3852  [ 8313A6AF9DE34A9D24DF2329A548B004 ] eyeonedp        C:\Windows\system32\DRIVERS\eyeonedp.sys
12:19:09.0734 3852  eyeonedp ( UnsignedFile.Multi.Generic ) - warning
12:19:09.0734 3852  eyeonedp - detected UnsignedFile.Multi.Generic (1)
12:19:09.0765 3852  [ 38D332A6D56AF32635675F132548343E ] Fastfat         C:\Windows\system32\drivers\Fastfat.sys
12:19:09.0859 3852  Fastfat - ok
12:19:09.0875 3852  [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\Windows\System32\shsvcs.dll
12:19:09.0953 3852  FastUserSwitchingCompatibility - ok
12:19:09.0984 3852  [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax             C:\Windows\system32\fxssvc.exe
12:19:10.0093 3852  Fax - ok
12:19:10.0093 3852  [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc             C:\Windows\system32\DRIVERS\fdc.sys
12:19:10.0203 3852  Fdc - ok
12:19:10.0218 3852  [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips            C:\Windows\system32\drivers\Fips.sys
12:19:10.0312 3852  Fips - ok
12:19:10.0359 3852  [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
12:19:10.0406 3852  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
12:19:10.0406 3852  FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
12:19:10.0437 3852  [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
12:19:10.0531 3852  Flpydisk - ok
12:19:10.0562 3852  [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:19:10.0656 3852  FltMgr - ok
12:19:10.0703 3852  [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
12:19:10.0718 3852  FontCache3.0.0.0 - ok
12:19:10.0718 3852  [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:19:10.0812 3852  Fs_Rec - ok
12:19:10.0843 3852  [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk          C:\Windows\system32\DRIVERS\ftdisk.sys
12:19:10.0921 3852  Ftdisk - ok
12:19:10.0953 3852  [ 035EAF9A18B84F9560984BCF41F52E99 ] gfiark          C:\Windows\system32\drivers\gfiark.sys
12:19:10.0968 3852  gfiark - ok
12:19:10.0984 3852  [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc             C:\Windows\system32\DRIVERS\msgpc.sys
12:19:11.0093 3852  Gpc - ok
12:19:11.0109 3852  [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
12:19:11.0203 3852  HDAudBus - ok
12:19:11.0234 3852  [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc         C:\Windows\PCHealth\HelpCtr\Binaries\pchsvc.dll
12:19:11.0312 3852  helpsvc - ok
12:19:11.0328 3852  [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ         C:\Windows\System32\hidserv.dll
12:19:11.0437 3852  HidServ - ok
12:19:11.0437 3852  [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
12:19:11.0531 3852  HidUsb - ok
12:19:11.0562 3852  [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc          C:\Windows\System32\kmsvc.dll
12:19:11.0671 3852  hkmsvc - ok
12:19:11.0687 3852  [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn             C:\Windows\system32\DRIVERS\hpn.sys
12:19:11.0781 3852  hpn - ok
12:19:11.0796 3852  [ 863CC3A82C63C9F60ACF2E85D5310620 ] HPZid412        C:\Windows\system32\DRIVERS\HPZid412.sys
12:19:11.0859 3852  HPZid412 - ok
12:19:11.0859 3852  [ 08CB72E95DD75B61F2966B311D0E4366 ] HPZipr12        C:\Windows\system32\DRIVERS\HPZipr12.sys
12:19:11.0906 3852  HPZipr12 - ok
12:19:11.0921 3852  [ CA990306ED4EF732AF9695BFF24FC96F ] HPZius12        C:\Windows\system32\DRIVERS\HPZius12.sys
12:19:11.0984 3852  HPZius12 - ok
12:19:12.0015 3852  [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP            C:\Windows\system32\Drivers\HTTP.sys
12:19:12.0078 3852  HTTP - ok
12:19:12.0109 3852  [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter      C:\Windows\System32\w3ssl.dll
12:19:12.0296 3852  HTTPFilter - ok
12:19:12.0328 3852  [ 8313A6AF9DE34A9D24DF2329A548B004 ] i1display       C:\Windows\system32\Drivers\i1display.sys
12:19:12.0328 3852  i1display ( UnsignedFile.Multi.Generic ) - warning
12:19:12.0328 3852  i1display - detected UnsignedFile.Multi.Generic (1)
12:19:12.0343 3852  [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt         C:\Windows\system32\drivers\i2omgmt.sys
12:19:12.0437 3852  i2omgmt - ok
12:19:12.0453 3852  [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp           C:\Windows\system32\DRIVERS\i2omp.sys
12:19:12.0546 3852  i2omp - ok
12:19:12.0562 3852  [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
12:19:12.0656 3852  i8042prt - ok
12:19:12.0703 3852  [ B122BE74E283A2BC7FEBC180BFD2EFD5 ] IAANTMON        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
12:19:13.0109 3852  IAANTMON ( UnsignedFile.Multi.Generic ) - warning
12:19:13.0109 3852  IAANTMON - detected UnsignedFile.Multi.Generic (1)
12:19:13.0109 3852  [ 019CF5F31C67030841233C545A0E217A ] iastor          C:\Windows\system32\drivers\iastor.sys
12:19:13.0171 3852  iastor - ok
12:19:13.0234 3852  [ D0DA8F43AA90A28852959A9E7F97D7CE ] IDriveE Service C:\IDrive\IDriveE Service.exe
12:19:13.0703 3852  IDriveE Service ( UnsignedFile.Multi.Generic ) - warning
12:19:13.0703 3852  IDriveE Service - detected UnsignedFile.Multi.Generic (1)
12:19:13.0734 3852  [ 45E3112848D61A011E31F522BE6DEE7F ] IDriveWebM      C:\IDrive\IDriveWebM.exe
12:19:13.0765 3852  IDriveWebM - ok
12:19:13.0843 3852  [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc           c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:19:13.0906 3852  idsvc - ok
12:19:13.0921 3852  [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi           C:\Windows\system32\DRIVERS\imapi.sys
12:19:14.0031 3852  Imapi - ok
12:19:14.0062 3852  [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService    C:\Windows\system32\imapi.exe
12:19:14.0187 3852  ImapiService - ok
12:19:14.0203 3852  [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u         C:\Windows\system32\DRIVERS\ini910u.sys
12:19:14.0312 3852  ini910u - ok
12:19:14.0328 3852  [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde        C:\Windows\system32\DRIVERS\intelide.sys
12:19:14.0421 3852  IntelIde - ok
12:19:14.0453 3852  [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
12:19:14.0531 3852  intelppm - ok
12:19:14.0546 3852  [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw           C:\Windows\system32\drivers\ip6fw.sys
12:19:14.0656 3852  Ip6Fw - ok
12:19:14.0671 3852  [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:19:14.0765 3852  IpFilterDriver - ok
12:19:14.0796 3852  [ B87AB476DCF76E72010632B5550955F5 ] IpInIp          C:\Windows\system32\DRIVERS\ipinip.sys
12:19:14.0875 3852  IpInIp - ok
12:19:14.0890 3852  [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat           C:\Windows\system32\DRIVERS\ipnat.sys
12:19:14.0984 3852  IpNat - ok
12:19:14.0984 3852  [ 23C74D75E36E7158768DD63D92789A91 ] IPSec           C:\Windows\system32\DRIVERS\ipsec.sys
12:19:15.0078 3852  IPSec - ok
12:19:15.0078 3852  [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM          C:\Windows\system32\DRIVERS\irenum.sys
12:19:15.0171 3852  IRENUM - ok
12:19:15.0203 3852  [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp          C:\Windows\system32\DRIVERS\isapnp.sys
12:19:15.0296 3852  isapnp - ok
12:19:15.0343 3852  [ 5739F2821D49975CEDE6BF0153D0CF01 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
12:19:15.0359 3852  JavaQuickStarterService - ok
12:19:15.0375 3852  [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
12:19:15.0484 3852  Kbdclass - ok
12:19:15.0484 3852  [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
12:19:15.0593 3852  kbdhid - ok
12:19:15.0593 3852  [ CA346C880AA16B50CC773AAFA19D852D ] KFilter         C:\SS14\KFilter.sys
12:19:15.0906 3852  KFilter - ok
12:19:15.0921 3852  [ 692BCF44383D056AED41B045A323D378 ] kmixer          C:\Windows\system32\drivers\kmixer.sys
12:19:16.0015 3852  kmixer - ok
12:19:16.0031 3852  [ B467646C54CC746128904E1654C750C1 ] KSecDD          C:\Windows\system32\drivers\KSecDD.sys
12:19:16.0078 3852  KSecDD - ok
12:19:16.0125 3852  [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver    C:\Windows\System32\srvsvc.dll
12:19:16.0203 3852  lanmanserver - ok
12:19:16.0234 3852  [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\Windows\System32\wkssvc.dll
12:19:16.0296 3852  lanmanworkstation - ok
12:19:16.0328 3852  [ C99BA72106A858CB8B521BB4C02C93ED ] LBeepKE         C:\Windows\system32\Drivers\LBeepKE.sys
12:19:16.0343 3852  LBeepKE - ok
12:19:16.0343 3852  lbrtfdc - ok
12:19:16.0390 3852  [ 0F98B9384C37C8C29904B8AE4359A54F ] LBTServ         C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
12:19:16.0406 3852  LBTServ - ok
12:19:16.0421 3852  [ 318B3D608FBEC44B7E0C23BF759DCED5 ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
12:19:16.0437 3852  LHidFilt - ok
12:19:16.0468 3852  [ A0D6A7E4F95ADC2472D3F53305874D55 ] LHidUsbK        C:\Windows\system32\Drivers\LHidUsbK.Sys
12:19:16.0718 3852  LHidUsbK ( UnsignedFile.Multi.Generic ) - warning
12:19:16.0718 3852  LHidUsbK - detected UnsignedFile.Multi.Generic (1)
12:19:16.0734 3852  [ A7DB739AE99A796D91580147E919CC59 ] LmHosts         C:\Windows\System32\lmhsvc.dll
12:19:16.0843 3852  LmHosts - ok
12:19:16.0859 3852  [ 84AF069D219DF3C43DC6792B2BBD7BED ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
12:19:16.0875 3852  LMouFilt - ok
12:19:16.0875 3852  LMouKE - ok
12:19:16.0890 3852  [ 144011D14BD35F4E36136AE057B1AADD ] LUsbFilt        C:\Windows\system32\Drivers\LUsbFilt.Sys
12:19:16.0906 3852  LUsbFilt - ok
12:19:16.0937 3852  [ B8EAC4507EB4655377B1E094FCE7F12E ] Macromedia Licensing Service C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
12:19:17.0343 3852  Macromedia Licensing Service ( UnsignedFile.Multi.Generic ) - warning
12:19:17.0343 3852  Macromedia Licensing Service - detected UnsignedFile.Multi.Generic (1)
12:19:17.0406 3852  [ 11F714F85530A2BD134074DC30E99FCA ] MDM             C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
12:19:17.0421 3852  MDM - ok
12:19:17.0437 3852  [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger       C:\Windows\System32\msgsvc.dll
12:19:17.0593 3852  Messenger - ok
12:19:17.0593 3852  [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd           C:\Windows\system32\drivers\mnmdd.sys
12:19:17.0671 3852  mnmdd - ok
12:19:17.0687 3852  [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc         C:\WINDOWS\system32\mnmsrvc.exe
12:19:17.0796 3852  mnmsrvc - ok
12:19:17.0828 3852  [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem           C:\Windows\system32\drivers\Modem.sys
12:19:17.0921 3852  Modem - ok
12:19:17.0921 3852  [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
12:19:18.0015 3852  Mouclass - ok
12:19:18.0015 3852  [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
12:19:18.0093 3852  mouhid - ok
12:19:18.0140 3852  [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr        C:\Windows\system32\drivers\MountMgr.sys
12:19:18.0234 3852  MountMgr - ok
12:19:18.0265 3852  [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x        C:\Windows\system32\DRIVERS\mraid35x.sys
12:19:18.0359 3852  mraid35x - ok
12:19:18.0375 3852  [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV          C:\Windows\system32\DRIVERS\mrxdav.sys
12:19:18.0500 3852  MRxDAV - ok
12:19:18.0531 3852  [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:19:18.0593 3852  MRxSmb - ok
12:19:18.0640 3852  [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC           C:\WINDOWS\system32\msdtc.exe
12:19:18.0750 3852  MSDTC - ok
12:19:18.0750 3852  [ C941EA2454BA8350021D774DAF0F1027 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:19:18.0843 3852  Msfs - ok
12:19:18.0843 3852  MSIServer - ok
12:19:18.0859 3852  [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
12:19:18.0937 3852  MSKSSRV - ok
12:19:18.0953 3852  [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:19:19.0031 3852  MSPCLOCK - ok
12:19:19.0031 3852  [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
12:19:19.0140 3852  MSPQM - ok
12:19:19.0187 3852  [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
12:19:19.0265 3852  mssmbios - ok
12:19:19.0281 3852  [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup             C:\Windows\system32\drivers\Mup.sys
12:19:19.0328 3852  Mup - ok
12:19:19.0359 3852  [ 0102140028FAD045756796E1C685D695 ] napagent        C:\Windows\System32\qagentrt.dll
12:19:19.0484 3852  napagent - ok
12:19:19.0500 3852  [ 1DF7F42665C94B825322FAE71721130D ] NDIS            C:\Windows\system32\drivers\NDIS.sys
12:19:19.0593 3852  NDIS - ok
12:19:19.0593 3852  [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:19:19.0640 3852  NdisTapi - ok
12:19:19.0671 3852  [ F927A4434C5028758A842943EF1A3849 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
12:19:19.0765 3852  Ndisuio - ok
12:19:19.0765 3852  [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
12:19:19.0843 3852  NdisWan - ok
12:19:19.0859 3852  [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
12:19:19.0921 3852  NDProxy - ok
12:19:19.0953 3852  [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
12:19:20.0031 3852  NetBIOS - ok
12:19:20.0046 3852  [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
12:19:20.0140 3852  NetBT - ok
12:19:20.0187 3852  [ B857BA82860D7FF85AE29B095645563B ] NetDDE          C:\Windows\system32\netdde.exe
12:19:20.0312 3852  NetDDE - ok
12:19:20.0312 3852  [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm      C:\Windows\system32\netdde.exe
12:19:20.0421 3852  NetDDEdsdm - ok
12:19:20.0453 3852  [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon        C:\Windows\system32\lsass.exe
12:19:20.0546 3852  Netlogon - ok
12:19:20.0578 3852  [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman          C:\Windows\System32\netman.dll
12:19:20.0703 3852  Netman - ok
12:19:20.0734 3852  [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:19:20.0750 3852  NetTcpPortSharing - ok
12:19:20.0750 3852  [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394         C:\Windows\system32\DRIVERS\nic1394.sys
12:19:20.0843 3852  NIC1394 - ok
12:19:20.0859 3852  [ 943337D786A56729263071623BBB9DE5 ] Nla             C:\Windows\System32\mswsock.dll
12:19:20.0906 3852  Nla - ok
12:19:20.0921 3852  [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:19:21.0015 3852  Npfs - ok
12:19:21.0031 3852  [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:19:21.0171 3852  Ntfs - ok
12:19:21.0187 3852  [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp         C:\Windows\system32\lsass.exe
12:19:21.0281 3852  NtLmSsp - ok
12:19:21.0312 3852  [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc         C:\Windows\system32\ntmssvc.dll
12:19:21.0421 3852  NtmsSvc - ok
12:19:21.0453 3852  [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null            C:\Windows\system32\drivers\Null.sys
12:19:21.0546 3852  Null - ok
12:19:21.0765 3852  [ 7C56F3FD65B2BDB315CA3605A5392D7B ] nv              C:\Windows\system32\DRIVERS\nv4_mini.sys
12:19:22.0140 3852  nv - ok
12:19:22.0171 3852  [ A8C1E6FF53FB0628A302843EA5FA5AB6 ] NVSvc           C:\Windows\system32\nvsvc32.exe
12:19:22.0234 3852  NVSvc - ok
12:19:22.0250 3852  [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt        C:\Windows\system32\DRIVERS\nwlnkflt.sys
12:19:22.0343 3852  NwlnkFlt - ok
12:19:22.0359 3852  [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd        C:\Windows\system32\DRIVERS\nwlnkfwd.sys
12:19:22.0437 3852  NwlnkFwd - ok
12:19:22.0453 3852  [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394        C:\Windows\system32\DRIVERS\ohci1394.sys
12:19:22.0562 3852  ohci1394 - ok
12:19:22.0578 3852  [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:19:22.0593 3852  ose - ok
12:19:22.0625 3852  [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport         C:\Windows\system32\DRIVERS\parport.sys
12:19:22.0718 3852  Parport - ok
12:19:22.0734 3852  [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr         C:\Windows\system32\drivers\PartMgr.sys
12:19:22.0828 3852  PartMgr - ok
12:19:22.0843 3852  [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm          C:\Windows\system32\drivers\ParVdm.sys
12:19:22.0937 3852  ParVdm - ok
12:19:22.0937 3852  [ A219903CCF74233761D92BEF471A07B1 ] PCI             C:\Windows\system32\DRIVERS\pci.sys
12:19:23.0015 3852  PCI - ok
12:19:23.0031 3852  PCIDump - ok
12:19:23.0046 3852  [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde          C:\Windows\system32\DRIVERS\pciide.sys
12:19:23.0125 3852  PCIIde - ok
12:19:23.0140 3852  [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia          C:\Windows\system32\drivers\Pcmcia.sys
12:19:23.0218 3852  Pcmcia - ok
12:19:23.0234 3852  PDCOMP - ok
12:19:23.0234 3852  PDFRAME - ok
12:19:23.0265 3852  [ 274FB48DC92E0EC012D4D8D866CFAF8A ] PDIHWCTL        C:\WINDOWS\system32\drivers\pdihwctl.sys
12:19:23.0562 3852  PDIHWCTL ( UnsignedFile.Multi.Generic ) - warning
12:19:23.0562 3852  PDIHWCTL - detected UnsignedFile.Multi.Generic (1)
12:19:23.0578 3852  PDRELI - ok
12:19:23.0578 3852  PDRFRAME - ok
12:19:23.0593 3852  [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2           C:\Windows\system32\DRIVERS\perc2.sys
12:19:23.0687 3852  perc2 - ok
12:19:23.0703 3852  [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib        C:\Windows\system32\DRIVERS\perc2hib.sys
12:19:23.0796 3852  perc2hib - ok
12:19:23.0812 3852  [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay        C:\Windows\system32\services.exe
12:19:23.0859 3852  PlugPlay - ok
12:19:23.0875 3852  [ FB03F341FF5380394BF2EE52F1979925 ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe
12:19:23.0890 3852  Pml Driver HPZ12 - ok
12:19:23.0890 3852  [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent     C:\Windows\system32\lsass.exe
12:19:23.0984 3852  PolicyAgent - ok
12:19:24.0015 3852  [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
12:19:24.0093 3852  PptpMiniport - ok
12:19:24.0093 3852  [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:19:24.0187 3852  ProtectedStorage - ok
12:19:24.0187 3852  [ 09298EC810B07E5D582CB3A3F9255424 ] PSched          C:\Windows\system32\DRIVERS\psched.sys
12:19:24.0265 3852  PSched - ok
12:19:24.0281 3852  [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink         C:\Windows\system32\DRIVERS\ptilink.sys
12:19:24.0375 3852  Ptilink - ok
12:19:24.0375 3852  [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20        C:\Windows\system32\Drivers\PxHelp20.sys
12:19:24.0390 3852  PxHelp20 - ok
12:19:24.0453 3852  [ 45FF9E4EC506FCA0C263A3299809B73A ] QBCFMonitorService C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
12:19:24.0609 3852  QBCFMonitorService ( UnsignedFile.Multi.Generic ) - warning
12:19:24.0609 3852  QBCFMonitorService - detected UnsignedFile.Multi.Generic (1)
12:19:24.0671 3852  [ 6BEE1814470DC12FA20C53DFC3C97EBB ] QBFCService     C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
12:19:24.0687 3852  QBFCService ( UnsignedFile.Multi.Generic ) - warning
12:19:24.0687 3852  QBFCService - detected UnsignedFile.Multi.Generic (1)
12:19:24.0703 3852  [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080          C:\Windows\system32\DRIVERS\ql1080.sys
12:19:24.0796 3852  ql1080 - ok
12:19:24.0812 3852  [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt         C:\Windows\system32\DRIVERS\ql10wnt.sys
12:19:24.0921 3852  Ql10wnt - ok
12:19:24.0937 3852  [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160         C:\Windows\system32\DRIVERS\ql12160.sys
12:19:25.0015 3852  ql12160 - ok
12:19:25.0031 3852  [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240          C:\Windows\system32\DRIVERS\ql1240.sys
12:19:25.0109 3852  ql1240 - ok
12:19:25.0125 3852  [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280          C:\Windows\system32\DRIVERS\ql1280.sys
12:19:25.0234 3852  ql1280 - ok
12:19:25.0281 3852  [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:19:25.0359 3852  RasAcd - ok
12:19:25.0390 3852  [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto         C:\Windows\System32\rasauto.dll
12:19:25.0500 3852  RasAuto - ok
12:19:25.0531 3852  [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
12:19:25.0625 3852  Rasl2tp - ok
12:19:25.0656 3852  [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan          C:\Windows\System32\rasmans.dll
12:19:25.0765 3852  RasMan - ok
12:19:25.0765 3852  [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:19:25.0859 3852  RasPppoe - ok
12:19:25.0875 3852  [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti          C:\Windows\system32\DRIVERS\raspti.sys
12:19:25.0968 3852  Raspti - ok
12:19:25.0984 3852  [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
12:19:26.0078 3852  Rdbss - ok
12:19:26.0093 3852  [ 4912D5B403614CE99C28420F75353332 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
12:19:26.0187 3852  RDPCDD - ok
12:19:26.0203 3852  [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr           C:\Windows\system32\DRIVERS\rdpdr.sys
12:19:26.0296 3852  rdpdr - ok
12:19:26.0328 3852  [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
12:19:26.0375 3852  RDPWD - ok
12:19:26.0390 3852  [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr       C:\WINDOWS\system32\sessmgr.exe
12:19:26.0515 3852  RDSessMgr - ok
12:19:26.0531 3852  [ F828DD7E1419B6653894A8F97A0094C5 ] redbook         C:\Windows\system32\DRIVERS\redbook.sys
12:19:26.0625 3852  redbook - ok
12:19:26.0656 3852  [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:19:26.0781 3852  RemoteAccess - ok
12:19:26.0796 3852  [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:19:26.0906 3852  RemoteRegistry - ok
12:19:26.0921 3852  RoxLiveShare10 - ok
12:19:26.0937 3852  [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator      C:\Windows\system32\locator.exe
12:19:27.0031 3852  RpcLocator - ok
12:19:27.0062 3852  [ 6B27A5C03DFB94B4245739065431322C ] RpcSs           C:\Windows\System32\rpcss.dll
12:19:27.0125 3852  RpcSs - ok
12:19:27.0171 3852  [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP            C:\Windows\system32\rsvp.exe
12:19:27.0328 3852  RSVP - ok
12:19:27.0328 3852  [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs           C:\Windows\system32\lsass.exe
12:19:27.0421 3852  SamSs - ok
12:19:27.0515 3852  [ 99FC1599F89A80216E41175B8CA44D89 ] SBAMSvc         C:\SS14\Antivirus\SBAMSvc.exe
12:19:27.0656 3852  SBAMSvc - ok
12:19:27.0703 3852  [ 862EEC4DFFF55AB124C9F4C758BECC39 ] sbaphd          C:\Windows\system32\drivers\sbaphd.sys
12:19:27.0718 3852  sbaphd - ok
12:19:27.0765 3852  [ 87574F4C899E8AEDDDC1EDF71D3E045E ] sbapifs         C:\Windows\system32\drivers\sbapifs.sys
12:19:27.0781 3852  sbapifs - ok
12:19:27.0781 3852  SBRE - ok
12:19:27.0828 3852  [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr        C:\Windows\System32\SCardSvr.exe
12:19:27.0937 3852  SCardSvr - ok
12:19:27.0968 3852  [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule        C:\Windows\system32\schedsvc.dll
12:19:28.0078 3852  Schedule - ok
12:19:28.0109 3852  [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv          C:\Windows\system32\DRIVERS\secdrv.sys
12:19:28.0187 3852  Secdrv - ok
12:19:28.0218 3852  [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon        C:\Windows\System32\seclogon.dll
12:19:28.0312 3852  seclogon - ok
12:19:28.0328 3852  [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS            C:\Windows\system32\sens.dll
12:19:28.0437 3852  SENS - ok
12:19:28.0468 3852  [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum         C:\Windows\system32\DRIVERS\serenum.sys
12:19:28.0578 3852  serenum - ok
12:19:28.0578 3852  [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
12:19:28.0656 3852  Serial - ok
12:19:28.0671 3852  SessionLauncher - ok
12:19:28.0687 3852  [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy         C:\Windows\system32\drivers\Sfloppy.sys
12:19:28.0765 3852  Sfloppy - ok
12:19:28.0796 3852  [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:19:28.0921 3852  SharedAccess - ok
12:19:28.0937 3852  [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:19:28.0984 3852  ShellHWDetection - ok
12:19:28.0984 3852  Simbad - ok
12:19:29.0000 3852  [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp          C:\Windows\system32\DRIVERS\sisagp.sys
12:19:29.0093 3852  sisagp - ok
12:19:29.0125 3852  [ E78C98378A071CE4D48A7C514FA98FA1 ] snapman         C:\Windows\system32\DRIVERS\snapman.sys
12:19:29.0140 3852  snapman - ok
12:19:29.0187 3852  [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow         C:\Windows\system32\DRIVERS\sparrow.sys
12:19:29.0234 3852  Sparrow - ok
12:19:29.0265 3852  [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter        C:\Windows\system32\drivers\splitter.sys
12:19:29.0359 3852  splitter - ok
12:19:29.0359 3852  [ 60784F891563FB1B767F70117FC2428F ] Spooler         C:\Windows\system32\spoolsv.exe
12:19:29.0437 3852  Spooler - ok
12:19:29.0468 3852  [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr              C:\Windows\system32\DRIVERS\sr.sys
12:19:29.0531 3852  sr - ok
12:19:29.0546 3852  [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice       C:\Windows\system32\srsvc.dll
12:19:29.0625 3852  srservice - ok
12:19:29.0640 3852  [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv             C:\Windows\system32\DRIVERS\srv.sys
12:19:29.0687 3852  Srv - ok
12:19:29.0734 3852  [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
12:19:29.0828 3852  SSDPSRV - ok
12:19:29.0859 3852  [ 797FCC1D859B203958E915BB82528DA9 ] STHDA           C:\Windows\system32\drivers\sthda.sys
12:19:29.0953 3852  STHDA - ok
12:19:29.0984 3852  [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc          C:\Windows\system32\wiaservc.dll
12:19:30.0125 3852  stisvc - ok
12:19:30.0140 3852  [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
12:19:30.0265 3852  swenum - ok
12:19:30.0328 3852  [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard     C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
12:19:30.0421 3852  SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
12:19:30.0421 3852  SwitchBoard - detected UnsignedFile.Multi.Generic (1)
12:19:30.0437 3852  [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi          C:\Windows\system32\drivers\swmidi.sys
12:19:30.0515 3852  swmidi - ok
12:19:30.0531 3852  SwPrv - ok
12:19:30.0546 3852  [ 1FF3217614018630D0A6758630FC698C ] symc810         C:\Windows\system32\DRIVERS\symc810.sys
12:19:30.0625 3852  symc810 - ok
12:19:30.0640 3852  [ 070E001D95CF725186EF8B20335F933C ] symc8xx         C:\Windows\system32\DRIVERS\symc8xx.sys
12:19:30.0734 3852  symc8xx - ok
12:19:30.0750 3852  [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi          C:\Windows\system32\DRIVERS\sym_hi.sys
12:19:30.0843 3852  sym_hi - ok
12:19:30.0859 3852  [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3          C:\Windows\system32\DRIVERS\sym_u3.sys
12:19:30.0937 3852  sym_u3 - ok
12:19:30.0937 3852  [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio        C:\Windows\system32\drivers\sysaudio.sys
12:19:31.0046 3852  sysaudio - ok
12:19:31.0078 3852  [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog       C:\Windows\system32\smlogsvc.exe
12:19:31.0218 3852  SysmonLog - ok
12:19:31.0218 3852  SystemSuite Task Manager - ok
12:19:31.0250 3852  [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv         C:\Windows\System32\tapisrv.dll
12:19:31.0375 3852  TapiSrv - ok
12:19:31.0406 3852  [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip           C:\Windows\system32\DRIVERS\tcpip.sys
12:19:31.0437 3852  Tcpip - ok
12:19:31.0484 3852  [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE          C:\Windows\system32\drivers\TDPIPE.sys
12:19:31.0562 3852  TDPIPE - ok
12:19:31.0578 3852  [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP           C:\Windows\system32\drivers\TDTCP.sys
12:19:31.0656 3852  TDTCP - ok
12:19:31.0671 3852  [ 88155247177638048422893737429D9E ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
12:19:31.0765 3852  TermDD - ok
12:19:31.0796 3852  [ FF3477C03BE7201C294C35F684B3479F ] TermService     C:\Windows\System32\termsrv.dll
12:19:31.0937 3852  TermService - ok
12:19:31.0953 3852  [ 0AC9258D8B1C4429FBFD0E168B75B28E ] TFilter         C:\SS14\TFilter.sys
12:19:32.0234 3852  TFilter - ok
12:19:32.0265 3852  [ 99BC0B50F511924348BE19C7C7313BBF ] Themes          C:\Windows\System32\shsvcs.dll
12:19:32.0296 3852  Themes - ok
12:19:32.0312 3852  [ B84B82C0CBEB1B0D7EB7A946BADE5830 ] tifsfilter      C:\Windows\system32\DRIVERS\tifsfilt.sys
12:19:32.0328 3852  tifsfilter ( UnsignedFile.Multi.Generic ) - warning
12:19:32.0328 3852  tifsfilter - detected UnsignedFile.Multi.Generic (1)
12:19:32.0359 3852  [ 74711884439BDF9CCF446C79CB05FAC0 ] timounter       C:\Windows\system32\DRIVERS\timntr.sys
12:19:32.0406 3852  timounter ( UnsignedFile.Multi.Generic ) - warning
12:19:32.0421 3852  timounter - detected UnsignedFile.Multi.Generic (1)
12:19:32.0437 3852  [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr         C:\WINDOWS\system32\tlntsvr.exe
12:19:32.0531 3852  TlntSvr - ok
12:19:32.0546 3852  [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde          C:\Windows\system32\DRIVERS\toside.sys
12:19:32.0625 3852  TosIde - ok
12:19:32.0656 3852  [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks          C:\Windows\system32\trkwks.dll
12:19:32.0781 3852  TrkWks - ok
12:19:32.0796 3852  [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs            C:\Windows\system32\drivers\Udfs.sys
12:19:32.0890 3852  Udfs - ok
12:19:32.0906 3852  [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra           C:\Windows\system32\DRIVERS\ultra.sys
12:19:32.0953 3852  ultra - ok
12:19:32.0984 3852  [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update          C:\Windows\system32\DRIVERS\update.sys
12:19:33.0109 3852  Update - ok
12:19:33.0140 3852  [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost        C:\Windows\System32\upnphost.dll
12:19:33.0234 3852  upnphost - ok
12:19:33.0265 3852  [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS             C:\Windows\System32\ups.exe
12:19:33.0390 3852  UPS - ok
12:19:33.0406 3852  [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
12:19:33.0500 3852  usbccgp - ok
12:19:33.0515 3852  [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
12:19:33.0609 3852  usbehci - ok
12:19:33.0609 3852  [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
12:19:33.0687 3852  usbhub - ok
12:19:33.0718 3852  [ A717C8721046828520C9EDF31288FC00 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
12:19:33.0812 3852  usbprint - ok
12:19:33.0828 3852  [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
12:19:33.0906 3852  usbscan - ok
12:19:33.0921 3852  [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:19:34.0015 3852  USBSTOR - ok
12:19:34.0015 3852  [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
12:19:34.0109 3852  usbuhci - ok
12:19:34.0218 3852  [ E734456069A51754C15C860DE1EAA462 ] VCOMCloudAgent  C:\SysSuite14\VcomCloudAgent.exe
12:19:34.0234 3852  VCOMCloudAgent - ok
12:19:34.0281 3852  [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave         C:\Windows\System32\drivers\vga.sys
12:19:34.0359 3852  VgaSave - ok
12:19:34.0390 3852  [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp          C:\Windows\system32\DRIVERS\viaagp.sys
12:19:34.0484 3852  viaagp - ok
12:19:34.0500 3852  [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde          C:\Windows\system32\DRIVERS\viaide.sys
12:19:34.0593 3852  ViaIde - ok
12:19:34.0593 3852  [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap         C:\Windows\system32\drivers\VolSnap.sys
12:19:34.0687 3852  VolSnap - ok
12:19:34.0718 3852  [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS             C:\Windows\System32\vssvc.exe
12:19:34.0812 3852  VSS - ok
12:19:34.0828 3852  [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time         C:\Windows\system32\w32time.dll
12:19:34.0953 3852  w32time - ok
12:19:34.0953 3852  [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
12:19:35.0046 3852  Wanarp - ok
12:19:35.0046 3852  wanatw - ok
12:19:35.0062 3852  [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000        C:\Windows\system32\DRIVERS\Wdf01000.sys
12:19:35.0093 3852  Wdf01000 - ok
12:19:35.0093 3852  WDICA - ok
12:19:35.0109 3852  [ 6768ACF64B18196494413695F0C3A00F ] wdmaud          C:\Windows\system32\drivers\wdmaud.sys
12:19:35.0203 3852  wdmaud - ok
12:19:35.0218 3852  [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient       C:\Windows\System32\webclnt.dll
12:19:35.0328 3852  WebClient - ok
12:19:35.0375 3852  [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
12:19:35.0515 3852  winmgmt - ok
12:19:35.0546 3852  [ 051B1BDECD6DEE18C771B5D5EC7F044D ] WmdmPmSN        C:\WINDOWS\system32\MsPMSNSv.dll
12:19:35.0640 3852  WmdmPmSN - ok
12:19:35.0671 3852  [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi             C:\Windows\System32\advapi32.dll
12:19:35.0750 3852  Wmi - ok
12:19:35.0765 3852  [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv        C:\WINDOWS\system32\wbem\wmiapsrv.exe
12:19:35.0859 3852  WmiApSrv - ok
12:19:35.0921 3852  [ 6BAB4DC65515A098505F8B3D01FB6FE5 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\WMPNetwk.exe
12:19:35.0984 3852  WMPNetworkSvc - ok
12:19:36.0046 3852  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:19:36.0093 3852  WPFFontCache_v0400 - ok
12:19:36.0156 3852  [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL         C:\Windows\System32\drivers\ws2ifsl.sys
12:19:36.0234 3852  WS2IFSL - ok
12:19:36.0281 3852  [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc          C:\Windows\system32\wscsvc.dll
12:19:36.0421 3852  wscsvc - ok
12:19:36.0421 3852  [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv        C:\Windows\system32\wuauserv.dll
12:19:36.0546 3852  wuauserv - ok
12:19:36.0578 3852  [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf          C:\Windows\system32\DRIVERS\WudfPf.sys
12:19:36.0640 3852  WudfPf - ok
12:19:36.0656 3852  [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd          C:\Windows\system32\DRIVERS\wudfrd.sys
12:19:36.0687 3852  WudfRd - ok
12:19:36.0703 3852  [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc         C:\Windows\System32\WUDFSvc.dll
12:19:36.0765 3852  WudfSvc - ok
12:19:36.0796 3852  [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC          C:\Windows\System32\wzcsvc.dll
12:19:36.0921 3852  WZCSVC - ok
12:19:36.0937 3852  [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov         C:\Windows\System32\xmlprov.dll
12:19:37.0062 3852  xmlprov - ok
12:19:37.0125 3852  [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService  C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
12:19:37.0171 3852  YahooAUService - ok
12:19:37.0187 3852  ================ Scan global ===============================
12:19:37.0218 3852  [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\Windows\system32\basesrv.dll
12:19:37.0234 3852  [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\Windows\system32\winsrv.dll
12:19:37.0281 3852  [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\Windows\system32\winsrv.dll
12:19:37.0343 3852  [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\Windows\system32\services.exe
12:19:37.0375 3852  [Global] - ok
12:19:37.0375 3852  ================ Scan MBR ==================================
12:19:37.0390 3852  [ D1AD4C53EADD115593E05FA56D6B9DEA ] \Device\Harddisk0\DR0
12:19:37.0765 3852  \Device\Harddisk0\DR0 - ok
12:19:37.0937 3852  [ 671B81004FDD1588FA9ED1331C9CECA9 ] \Device\Harddisk1\DR5
12:19:38.0109 3852  \Device\Harddisk1\DR5 - ok
12:19:38.0109 3852  ================ Scan VBR ==================================
12:19:38.0140 3852  [ A920C41F56CD5DF936F7A032CAA69EEC ] \Device\Harddisk0\DR0\Partition1
12:19:38.0140 3852  \Device\Harddisk0\DR0\Partition1 - ok
12:19:38.0187 3852  [ 1631F5931BED3FED8A984DF2F9329C52 ] \Device\Harddisk0\DR0\Partition2
12:19:38.0187 3852  \Device\Harddisk0\DR0\Partition2 - ok
12:19:38.0187 3852  [ 38F6E1A201F6E415479CAFE43E6BCA51 ] \Device\Harddisk1\DR5\Partition1
12:19:38.0187 3852  \Device\Harddisk1\DR5\Partition1 - ok
12:19:38.0187 3852  ============================================================
12:19:38.0187 3852  Scan finished
12:19:38.0187 3852  ============================================================
12:19:38.0296 3844  Detected object count: 17
12:19:38.0296 3844  Actual detected object count: 17
12:25:10.0859 3844  Adobe LM Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  Adobe LM Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  ASCTRM ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  ASCTRM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  Diskeeper ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  Diskeeper ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  DSproct ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  DSproct ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  eyeonedp ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  eyeonedp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  i1display ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  i1display ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  IAANTMON ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  IAANTMON ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  IDriveE Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  IDriveE Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  LHidUsbK ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  LHidUsbK ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  Macromedia Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  Macromedia Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  PDIHWCTL ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  PDIHWCTL ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  QBCFMonitorService ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  QBCFMonitorService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  QBFCService ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  QBFCService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  tifsfilter ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  tifsfilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:10.0859 3844  timounter ( UnsignedFile.Multi.Generic ) - skipped by user
12:25:10.0859 3844  timounter ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:25:35.0812 3680  Deinitialize success
 



#15 cma6

cma6
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:23 PM

Posted 14 June 2013 - 11:43 AM

Nasdaq:

 I did not see an option to attach a file. However, but MBR.dat and MBR.zip are only 1 kb.

                       Best, CMA

 

Here is the MBR log:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-06-14 12:31:05
-----------------------------
12:31:05.828    OS Version: Windows 5.1.2600 Service Pack 3
12:31:05.828    Number of processors: 2 586 0xF06
12:31:05.828    ComputerName: MORPHY  UserName: lao
12:31:06.312    Initialize success
12:32:17.453    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-2
12:32:17.453    Disk 0 Vendor: Intel___ 1.0. Size: 238416MB BusType: 3
12:32:17.515    Disk 0 MBR read successfully
12:32:17.515    Disk 0 MBR scan
12:32:17.515    Disk 0 unknown MBR code
12:32:17.515    Disk 0 Partition 1 00     DE Dell Utility Dell 8.0       54 MB offset 63
12:32:17.515    Disk 0 Partition 2 80 (A) 07    HPFS/NTFS NTFS       175546 MB offset 112455
12:32:17.515    Disk 0 Partition - 00     05     Extended             59584 MB offset 359631090
12:32:17.531    Disk 0 Partition 3 00     DB  CP/M / CTOS MSDOS5.0     3223 MB offset 481660830
12:32:17.546    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS        59584 MB offset 359631153
12:32:17.546    Disk 0 scanning sectors +488263545
12:32:17.609    Disk 0 scanning C:\Windows\system32\drivers
12:32:24.000    Service scanning
12:32:33.593    Modules scanning
12:32:46.578    Disk 0 trace - called modules:
12:32:46.906    ntoskrnl.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
12:32:46.921    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8abbf838]
12:32:46.921    3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-2[0x8a6be030]
12:32:46.921    Scan finished successfully
12:33:33.734    Disk 0 MBR has been saved successfully to "C:\Net_copy1\MBR.dat"
12:33:33.765    The log file has been saved successfully to "C:\Net_copy1\aswMBR.txt"

 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users