Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected


  • Please log in to reply
16 replies to this topic

#1 HateTechnology

HateTechnology

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 12:59 PM

Hello,

 I am running a windows 7 64bit system with Total Defense as my AV.

 

My son downloaded u-torrent and now im infected.

 

The issues happening are as follows:

 

random scanning with report of issues by program that i never installed.

 

Can not update AV software.

 

Can not delete programs from the system using controll panel ( says i am not an administrator)

 

I did talk with a Total Defense tech and after remoting into my system he informed me that i did have a virus and would cost $700.00 to send a tech to remove it from my system and restore to origanal operation.

 

How can i fix this:  PLEASE HELP !!!!!

 

By the way I am not that computer smart but can follow basic instructions lol.

 

Thank You.

 

 



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:36 PM

Posted 18 July 2013 - 01:11 PM

Hello and welcome.

We probably need to Safe Mode with Networking.

Please download Rkill by Grinler and save it to your desktop.
  • Link 1
  • Link 2
    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista, right-click on it and Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • If the tool does not run from any of the links provided, please let me know.
  • Do not reboot the computer, you will need to run the application again.
Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
Note: When using "Reset FF Proxy Settings" option Firefox should be closed.



Please Download TDSSkiller
Launch it.
Click on change parameters-Select TDLFS file system
Click on "Scan".
Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results.



Please download AdwCleaner by Xplode onto your desktop.
Close all open programs and internet browsers.
Double click on adwcleaner.exe to run the tool.
Click on Delete.
Confirm each time with Ok.
You will be prompted to restart your computer. A text file will open after the restart.
Please post the contents of that logfile with your next reply.
You can find the logfile at C:\AdwCleaner[S1].txt as well.



Last run ESET.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 01:15 PM

Boopme

 

Thanks I will work on this when i get home and post any results i get.

 

Thank you.



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:36 PM

Posted 18 July 2013 - 01:19 PM

OK, I'll look back tonite
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 05:46 PM

ok here is the RKILL Log

 

Rkill 2.5.6 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 07/18/2013 04:08:07 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Checking Registry for malware related settings:

 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
 C:\Users\Lunn Family\Desktop\rkill\rkill-07-18-2013-04-08-08.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * Windows Defender Disabled

   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001

 * Windows Firewall Disabled

   [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
   "EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

 * COM+ Event System (EventSystem) is not Running.
   Startup Type set to: Automatic

 * Windows Defender (WinDefend) is not Running.
   Startup Type set to: Manual

 * Security Center (wscsvc) is not Running.
   Startup Type set to: Automatic (Delayed Start)

 * Windows Update (wuauserv) is not Running.
   Startup Type set to: Automatic (Delayed Start)

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * No issues found.

Program finished at: 07/18/2013 04:08:35 PM
Execution time: 0 hours(s), 0 minute(s), and 28 seconds(s)



The MINI TOOLBOX LOG

 

MiniToolBox by Farbar  Version: 13-07-2013
Ran by Lunn Family (administrator) on 18-07-2013 at 16:12:05
Running from "C:\Users\Lunn Family\Desktop\Virus Tools"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Network
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================

 

========================= IP Configuration: ================================

Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC = Wireless Network Connection (Connected)
Realtek PCIe GBE Family Controller = Local Area Connection (Media disconnected)

# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled

popd
# End of IPv4 configuration

 

Windows IP Configuration

   Host Name . . . . . . . . . . . . : LunnFamily-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : elp.rr.com

Wireless LAN adapter Wireless Network Connection:

   Connection-specific DNS Suffix  . : elp.rr.com
   Description . . . . . . . . . . . : Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
   Physical Address. . . . . . . . . : 44-6D-57-EC-91-BA
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2605:6000:b1c0:ea00:bd20:28d:f2d0:f103(Preferred)
   Temporary IPv6 Address. . . . . . : 2605:6000:b1c0:ea00:7869:1eda:54d1:b0ca(Preferred)
   Link-local IPv6 Address . . . . . : fe80::bd20:28d:f2d0:f103%13(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.0.8(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Thursday, July 18, 2013 4:07:31 PM
   Lease Expires . . . . . . . . . . : Thursday, July 18, 2013 5:07:31 PM
   Default Gateway . . . . . . . . . : fe80::21d:cfff:fe5d:5f11%13
                                       192.168.0.1
   DHCP Server . . . . . . . . . . . : 192.168.0.1
   DHCPv6 IAID . . . . . . . . . . . : 323251543
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-17-5C-70-63-8C-89-A5-D3-D7-03
   DNS Servers . . . . . . . . . . . : 209.18.47.61
                                       209.18.47.62
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : 8C-89-A5-D3-D7-03
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 12:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.elp.rr.com:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  dns-cac-lb-01.rr.com
Address:  209.18.47.61

Name:    google.com
Addresses:  2607:f8b0:4000:805::1008
   74.125.227.206
   74.125.227.192
   74.125.227.193
   74.125.227.194
   74.125.227.195
   74.125.227.196
   74.125.227.197
   74.125.227.198
   74.125.227.199
   74.125.227.200
   74.125.227.201

Pinging google.com [2001:4860:4002:801::100e] with 32 bytes of data:
Reply from 2001:4860:4002:801::100e: time=38ms
Reply from 2001:4860:4002:801::100e: time=26ms

Ping statistics for 2001:4860:4002:801::100e:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 26ms, Maximum = 38ms, Average = 32ms
Server:  dns-cac-lb-01.rr.com
Address:  209.18.47.61

Name:    yahoo.com
Addresses:  98.139.183.24
   206.190.36.45
   98.138.253.109

Ping request could not find host yahoo.com. Please check the name and try again.

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 13...44 6d 57 ec 91 ba ......Realtek RTL8188CE Wireless LAN 802.11n PCI-E NIC
 11...8c 89 a5 d3 d7 03 ......Realtek PCIe GBE Family Controller
  1...........................Software Loopback Interface 1
 12...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
 16...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.0.1      192.168.0.8     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.0.0    255.255.255.0         On-link       192.168.0.8    281
      192.168.0.8  255.255.255.255         On-link       192.168.0.8    281
    192.168.0.255  255.255.255.255         On-link       192.168.0.8    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link       192.168.0.8    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link       192.168.0.8    281
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 13    281 ::/0                     fe80::21d:cfff:fe5d:5f11
  1    306 ::1/128                  On-link
 13     33 2605:6000:b1c0:ea00::/64 On-link
 13    281 2605:6000:b1c0:ea00:7869:1eda:54d1:b0ca/128
                                    On-link
 13    281 2605:6000:b1c0:ea00:bd20:28d:f2d0:f103/128
                                    On-link
 13    281 fe80::/64                On-link
 13    281 fe80::bd20:28d:f2d0:f103/128
                                    On-link
  1    306 ff00::/8                 On-link
 13    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\system32\VetRedir.dll [97360] (Computer Associates International, Inc.)
Catalog9 02 C:\Windows\system32\VetRedir.dll [97360] (Computer Associates International, Inc.)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 12 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\VetRedir.dll [97360] (Computer Associates International, Inc.)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\VetRedir64.dll [105552] (Computer Associates International, Inc.)
x64-Catalog9 02 C:\Windows\System32\VetRedir64.dll [105552] (Computer Associates International, Inc.)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 12 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 13 C:\Windows\System32\VetRedir64.dll [105552] (Computer Associates International, Inc.)

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/18/2013 04:07:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/18/2013 03:58:06 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/27/2013 06:17:03 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5007

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5007

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4009

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4009

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/21/2013 04:15:18 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3010

System errors:
=============
Error: (07/18/2013 04:07:35 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:35 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:35 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:33 PM) (Source: Service Control Manager) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:33 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:33 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:07:33 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:06:25 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT AUTHORITY)
Description: WLAN Extensibility Module has failed to start.

Module Path: C:\Windows\system32\Rtlihvs.dll
Error Code: 21

Error: (07/18/2013 04:06:15 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Error: (07/18/2013 04:06:15 PM) (Source: Service Control Manager) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068

Microsoft Office Sessions:
=========================
Error: (07/18/2013 04:07:50 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/18/2013 03:58:06 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/27/2013 06:17:03 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5007

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5007

Error: (06/21/2013 04:15:20 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4009

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4009

Error: (06/21/2013 04:15:19 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (06/21/2013 04:15:18 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3010

CodeIntegrity Errors:
===================================
  Date: 2013-05-14 12:06:56.874
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:54.334
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:23.070
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:19.570
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:17.739
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:16.049
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:06:10.878
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-05-14 12:05:46.856
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-13 20:44:57.435
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

  Date: 2013-04-13 20:43:31.636
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Total Defense\Internet Security Suite\Anti-Spam\QSP-9.0.0.471\QOEHook.dll because the set of per-page image hashes could not be found on the system.

=========================== Installed Programs ============================

ActivClient CAC x64 (Version: 6.2)
Adobe Flash Player 11 ActiveX 64-bit (Version: 11.1.102.55)
Adobe Reader XI (11.0.02) (Version: 11.0.02)
Anti-Virus (Version: 3.0.0.548)
APH placeholder
Apple Application Support (Version: 2.3.3)
Apple Mobile Device Support (Version: 6.1.0.13)
Apple Software Update (Version: 2.1.3.127)
Ashampoo Home Designer Pro v.1.0.1 (Version: 1.0.1)
Bonjour (Version: 3.0.0.10)
Canon MP Navigator EX 3.0
Canon MP250 series MP Drivers
Cisco EAP-FAST Module (Version: 2.2.14)
Cisco LEAP Module (Version: 1.0.19)
Cisco PEAP Module (Version: 1.1.6)
Crysis®3 (Version: 1.0.0.0)
D3DX10 (Version: 15.4.2368.0902)
DirectX for Managed Code Update (Summer 2004) (Version: 9.02.2904)
DNAMigrator (Version: 14.0.0.238)
Driver & Application Installation (Version: 6.01.1214)
e-Sign Desktop 6.6 (Version: 6.60.3.1000)
Google Chrome (Version: 27.0.1453.116)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.5.4209.2358)
Google Update Helper (Version: 1.3.21.145)
HIPS (Version: 13.0.0.383)
IBM Forms Viewer 4.0.0 (Version: 4.0.0.1)
Intel® Control Center (Version: 1.2.1.1007)
Intel® Manageability Engine Firmware Recovery Agent (Version: 1.0.0.35132)
Intel® Management Engine Components (Version: 8.0.0.1351)
Intel® Rapid Storage Technology (Version: 11.0.0.1032)
Intel® USB 3.0 eXtensible Host Controller Driver (Version: 1.0.0.199)
Intel® Trusted Connect Service Client (Version: 1.23.216.0)
iTunes (Version: 11.0.2.26)
Java 7 Update 21 (64-bit) (Version: 7.0.210)
Java 7 Update 21 (Version: 7.0.210)
Java Auto Updater (Version: 2.1.9.5)
Java SE Development Kit 7 Update 21 (64-bit) (Version: 1.7.0.210)
Junk Mail filter update (Version: 15.4.3502.0922)
Lenovo Blacksilk USB Keyboard Driver (Version: V1.4.11.0608)
Lenovo Power2Go (Version: 6.0.6008)
Lenovo Registration (Version: 1.0.4)
Lenovo Rescue System (Version: 3.0.3609)
Lenovo Screensaver (Version: 1.0.5.120109)
LVT (Version: 1.01.0213)
Mesh Runtime (Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Professional Plus 2013 - en-us (Version: 15.0.4505.1510)
Microsoft S/MIME (Version: 14.2.247.1)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (Version: 10.0.30319)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT_amd64 (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
NVIDIA 3D Vision Controller Driver 314.22 (Version: 314.22)
NVIDIA 3D Vision Driver 314.22 (Version: 314.22)
NVIDIA Control Panel 314.22 (Version: 314.22)
NVIDIA Graphics Driver 314.22 (Version: 314.22)
NVIDIA HD Audio Driver 1.3.23.1 (Version: 1.3.23.1)
NVIDIA Install Application (Version: 2.1002.115.743)
NVIDIA PhysX (Version: 9.12.1031)
NVIDIA PhysX System Software 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.13.1422)
NVIDIA Update 1.12.12 (Version: 1.12.12)
NVIDIA Update Components (Version: 1.12.12)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4505.1510)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4505.1510)
Office 15 Click-to-Run Localization Component (Version: 15.0.4505.1510)
Origin (Version: 9.1.10.2728)
Power Control Switch (Version: 4.0.0.1226)
Realtek Ethernet Controller Driver (Version: 7.48.823.2011)
Realtek High Definition Audio Driver (Version: 6.0.1.6454)
Realtek USB 2.0 Card Reader (Version: 6.1.7601.30131)
REALTEK Wireless LAN Driver (Version: 1.00.0180)
Search Protect by conduit (Version: 1.5.0.71)
ThemeWallpaper (Version: 1.2.0.111103)
Total Defense Internet Security Suite (Version: 8.0.0.215)
TouchCopy 12 (Version: 12.07)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3508.1109)
Windows Live Family Safety (Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (Version: 15.4.3502.0922)
Windows Live Mesh (Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (Version: 15.4.5722.2)
Windows Live Messenger (Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (Version: 15.4.3502.0922)
Windows Live Photo Common (Version: 15.4.3502.0922)
Windows Live Photo Gallery (Version: 15.4.3502.0922)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)

========================= Memory info: ===================================

Percentage of memory in use: 10%
Total physical RAM: 8154.91 MB
Available physical RAM: 7312.42 MB
Total Pagefile: 16308.01 MB
Available Pagefile: 15512.34 MB
Total Virtual: 4095.88 MB
Available Virtual: 3979.29 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:1837.75 GB) (Free:1764.88 GB) NTFS
2 Drive e: (Premium) (CDROM) (Total:0.62 GB) (Free:0 GB) CDFS

========================= Users: ========================================

User accounts for \\LUNNFAMILY-PC

Administrator            Guest                    Lunn Family             
UpdatusUser             

**** End of log ****



#6 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 05:48 PM

TDSKILLER LOG

 

16:15:19.0060 1444  TDSS rootkit removing tool 2.8.18.0 Jun 10 2013 21:44:19
16:15:19.0621 1444  ============================================================
16:15:19.0621 1444  Current date / time: 2013/07/18 16:15:19.0621
16:15:19.0621 1444  SystemInfo:
16:15:19.0621 1444 
16:15:19.0621 1444  OS Version: 6.1.7601 ServicePack: 1.0
16:15:19.0621 1444  Product type: Workstation
16:15:19.0621 1444  ComputerName: LUNNFAMILY-PC
16:15:19.0621 1444  UserName: Lunn Family
16:15:19.0621 1444  Windows directory: C:\Windows
16:15:19.0621 1444  System windows directory: C:\Windows
16:15:19.0621 1444  Running under WOW64
16:15:19.0621 1444  Processor architecture: Intel x64
16:15:19.0621 1444  Number of processors: 8
16:15:19.0621 1444  Page size: 0x1000
16:15:19.0621 1444  Boot type: Safe boot with network
16:15:19.0621 1444  ============================================================
16:15:20.0417 1444  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:15:20.0432 1444  ============================================================
16:15:20.0432 1444  \Device\Harddisk0\DR0:
16:15:20.0432 1444  MBR partitions:
16:15:20.0432 1444  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
16:15:20.0432 1444  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0xE5B7E800
16:15:20.0432 1444  ============================================================
16:15:20.0464 1444  C: <-> \Device\Harddisk0\DR0\Partition2
16:15:20.0464 1444  ============================================================
16:15:20.0464 1444  Initialize success
16:15:20.0464 1444  ============================================================
16:15:52.0303 0436  ============================================================
16:15:52.0303 0436  Scan started
16:15:52.0303 0436  Mode: Manual; TDLFS;
16:15:52.0303 0436  ============================================================
16:15:52.0553 0436  ================ Scan system memory ========================
16:15:52.0553 0436  System memory - ok
16:15:52.0553 0436  ================ Scan services =============================
16:15:52.0693 0436  [ A87D604AEA360176311474C87A63BB88 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
16:15:52.0709 0436  1394ohci - ok
16:15:52.0756 0436  [ 5E8EFEB338DEB1F485420B090FE6C85E ] ac.sharedstore  C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
16:15:52.0756 0436  ac.sharedstore - ok
16:15:52.0803 0436  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
16:15:52.0803 0436  ACPI - ok
16:15:52.0803 0436  [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
16:15:52.0803 0436  AcpiPmi - ok
16:15:52.0865 0436  [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:15:52.0865 0436  AdobeARMservice - ok
16:15:52.0881 0436  [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
16:15:52.0881 0436  adp94xx - ok
16:15:52.0881 0436  [ 597F78224EE9224EA1A13D6350CED962 ] adpahci         C:\Windows\system32\drivers\adpahci.sys
16:15:52.0896 0436  adpahci - ok
16:15:52.0912 0436  [ E109549C90F62FB570B9540C4B148E54 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
16:15:52.0912 0436  adpu320 - ok
16:15:52.0943 0436  [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
16:15:52.0943 0436  AeLookupSvc - ok
16:15:53.0021 0436  [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD             C:\Windows\system32\drivers\afd.sys
16:15:53.0021 0436  AFD - ok
16:15:53.0037 0436  [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440          C:\Windows\system32\drivers\agp440.sys
16:15:53.0037 0436  agp440 - ok
16:15:53.0052 0436  [ 3290D6946B5E30E70414990574883DDB ] ALG             C:\Windows\System32\alg.exe
16:15:53.0052 0436  ALG - ok
16:15:53.0052 0436  [ 5812713A477A3AD7363C7438CA2EE038 ] aliide          C:\Windows\system32\drivers\aliide.sys
16:15:53.0068 0436  aliide - ok
16:15:53.0068 0436  [ 1FF8B4431C353CE385C875F194924C0C ] amdide          C:\Windows\system32\drivers\amdide.sys
16:15:53.0068 0436  amdide - ok
16:15:53.0068 0436  [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
16:15:53.0083 0436  AmdK8 - ok
16:15:53.0099 0436  [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
16:15:53.0099 0436  AmdPPM - ok
16:15:53.0099 0436  [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
16:15:53.0115 0436  amdsata - ok
16:15:53.0115 0436  [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
16:15:53.0115 0436  amdsbs - ok
16:15:53.0130 0436  [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
16:15:53.0130 0436  amdxata - ok
16:15:53.0130 0436  [ 89A69C3F2F319B43379399547526D952 ] AppID           C:\Windows\system32\drivers\appid.sys
16:15:53.0130 0436  AppID - ok
16:15:53.0146 0436  [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
16:15:53.0146 0436  AppIDSvc - ok
16:15:53.0161 0436  [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo         C:\Windows\System32\appinfo.dll
16:15:53.0177 0436  Appinfo - ok
16:15:53.0239 0436  [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:15:53.0239 0436  Apple Mobile Device - ok
16:15:53.0255 0436  [ C484F8CEB1717C540242531DB7845C4E ] arc             C:\Windows\system32\drivers\arc.sys
16:15:53.0255 0436  arc - ok
16:15:53.0271 0436  [ 019AF6924AEFE7839F61C830227FE79C ] arcsas          C:\Windows\system32\drivers\arcsas.sys
16:15:53.0271 0436  arcsas - ok
16:15:53.0302 0436  [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
16:15:53.0302 0436  AsyncMac - ok
16:15:53.0302 0436  [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi           C:\Windows\system32\drivers\atapi.sys
16:15:53.0302 0436  atapi - ok
16:15:53.0333 0436  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
16:15:53.0333 0436  AudioEndpointBuilder - ok
16:15:53.0333 0436  [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
16:15:53.0349 0436  AudioSrv - ok
16:15:53.0349 0436  [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV        C:\Windows\System32\AxInstSV.dll
16:15:53.0364 0436  AxInstSV - ok
16:15:53.0364 0436  [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
16:15:53.0364 0436  b06bdrv - ok
16:15:53.0395 0436  [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
16:15:53.0395 0436  b57nd60a - ok
16:15:53.0411 0436  [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC          C:\Windows\System32\bdesvc.dll
16:15:53.0411 0436  BDESVC - ok
16:15:53.0442 0436  [ 16A47CE2DECC9B099349A5F840654746 ] Beep            C:\Windows\system32\drivers\Beep.sys
16:15:53.0442 0436  Beep - ok
16:15:53.0458 0436  [ 82974D6A2FD19445CC5171FC378668A4 ] BFE             C:\Windows\System32\bfe.dll
16:15:53.0458 0436  BFE - ok
16:15:53.0489 0436  [ 1EA7969E3271CBC59E1730697DC74682 ] BITS            C:\Windows\System32\qmgr.dll
16:15:53.0505 0436  BITS - ok
16:15:53.0520 0436  [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
16:15:53.0520 0436  blbdrive - ok
16:15:53.0551 0436  [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
16:15:53.0551 0436  Bonjour Service - ok
16:15:53.0583 0436  [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
16:15:53.0598 0436  bowser - ok
16:15:53.0614 0436  [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
16:15:53.0614 0436  BrFiltLo - ok
16:15:53.0614 0436  [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
16:15:53.0614 0436  BrFiltUp - ok
16:15:53.0629 0436  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser         C:\Windows\System32\browser.dll
16:15:53.0629 0436  Browser - ok
16:15:53.0645 0436  [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
16:15:53.0645 0436  Brserid - ok
16:15:53.0661 0436  [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
16:15:53.0661 0436  BrSerWdm - ok
16:15:53.0676 0436  [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
16:15:53.0676 0436  BrUsbMdm - ok
16:15:53.0676 0436  [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
16:15:53.0676 0436  BrUsbSer - ok
16:15:53.0676 0436  [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
16:15:53.0676 0436  BTHMODEM - ok
16:15:53.0692 0436  [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv         C:\Windows\system32\bthserv.dll
16:15:53.0692 0436  bthserv - ok
16:15:53.0754 0436  [ F972074401A1111BD3362D755F71DD6C ] CAAMSvc         C:\Program Files\Total Defense\Internet Security Suite\Anti-Virus\caamsvc.exe
16:15:53.0754 0436  CAAMSvc - ok
16:15:53.0801 0436  [ 3D6B42B56DE137DD12814754C47A9A0C ] CaCCProvSP      C:\Program Files\Total Defense\Internet Security Suite\ccprovsp.exe
16:15:53.0801 0436  CaCCProvSP - ok
16:15:53.0817 0436  [ EAE7BA27BBD8CC4E0319F29777A23EC2 ] CAISafe         C:\Program Files\Total Defense\Internet Security Suite\Anti-Virus\isafe.exe
16:15:53.0817 0436  CAISafe - ok
16:15:53.0832 0436  [ 79E517D769611969B7A7345235F230D0 ] ccSchedulerSVC  C:\Program Files\Total Defense\Internet Security Suite\ccschedulersvc.exe
16:15:53.0848 0436  ccSchedulerSVC - ok
16:15:53.0848 0436  [ B8BD2BB284668C84865658C77574381A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
16:15:53.0848 0436  cdfs - ok
16:15:53.0863 0436  [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
16:15:53.0863 0436  cdrom - ok
16:15:53.0879 0436  [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc     C:\Windows\System32\certprop.dll
16:15:53.0879 0436  CertPropSvc - ok
16:15:53.0879 0436  [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass        C:\Windows\system32\drivers\circlass.sys
16:15:53.0895 0436  circlass - ok
16:15:53.0926 0436  [ FE1EC06F2253F691FE36217C592A0206 ] CLFS            C:\Windows\system32\CLFS.sys
16:15:53.0941 0436  CLFS - ok
16:15:53.0973 0436  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:15:53.0973 0436  clr_optimization_v2.0.50727_32 - ok
16:15:53.0988 0436  [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
16:15:53.0988 0436  clr_optimization_v2.0.50727_64 - ok
16:15:54.0019 0436  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:15:54.0019 0436  clr_optimization_v4.0.30319_32 - ok
16:15:54.0035 0436  [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
16:15:54.0035 0436  clr_optimization_v4.0.30319_64 - ok
16:15:54.0066 0436  [ 934F4153380EDB6809EB9231C6B5F2A9 ] CltMngSvc       C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
16:15:54.0066 0436  CltMngSvc - ok
16:15:54.0082 0436  [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
16:15:54.0082 0436  CmBatt - ok
16:15:54.0082 0436  [ E19D3F095812725D88F9001985B94EDD ] cmdide          C:\Windows\system32\drivers\cmdide.sys
16:15:54.0097 0436  cmdide - ok
16:15:54.0113 0436  [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG             C:\Windows\system32\Drivers\cng.sys
16:15:54.0129 0436  CNG - ok
16:15:54.0129 0436  [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
16:15:54.0129 0436  Compbatt - ok
16:15:54.0160 0436  [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
16:15:54.0160 0436  CompositeBus - ok
16:15:54.0175 0436  COMSysApp - ok
16:15:54.0191 0436  [ 1C827878A998C18847245FE1F34EE597 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
16:15:54.0191 0436  crcdisk - ok
16:15:54.0222 0436  [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc        C:\Windows\system32\cryptsvc.dll
16:15:54.0222 0436  CryptSvc - ok
16:15:54.0253 0436  [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch      C:\Windows\system32\rpcss.dll
16:15:54.0253 0436  DcomLaunch - ok
16:15:54.0253 0436  [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc       C:\Windows\System32\defragsvc.dll
16:15:54.0269 0436  defragsvc - ok
16:15:54.0300 0436  [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
16:15:54.0300 0436  DfsC - ok
16:15:54.0316 0436  [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp            C:\Windows\system32\dhcpcore.dll
16:15:54.0316 0436  Dhcp - ok
16:15:54.0331 0436  [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache        C:\Windows\system32\drivers\discache.sys
16:15:54.0331 0436  discache - ok
16:15:54.0347 0436  [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk            C:\Windows\system32\drivers\disk.sys
16:15:54.0347 0436  Disk - ok
16:15:54.0363 0436  [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
16:15:54.0363 0436  Dnscache - ok
16:15:54.0363 0436  [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc         C:\Windows\System32\dot3svc.dll
16:15:54.0363 0436  dot3svc - ok
16:15:54.0378 0436  [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS             C:\Windows\system32\dps.dll
16:15:54.0378 0436  DPS - ok
16:15:54.0378 0436  [ 9B19F34400D24DF84C858A421C205754 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
16:15:54.0378 0436  drmkaud - ok
16:15:54.0425 0436  [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
16:15:54.0425 0436  DXGKrnl - ok
16:15:54.0425 0436  [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost         C:\Windows\System32\eapsvc.dll
16:15:54.0425 0436  EapHost - ok
16:15:54.0472 0436  [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv           C:\Windows\system32\drivers\evbda.sys
16:15:54.0503 0436  ebdrv - ok
16:15:54.0519 0436  [ C118A82CD78818C29AB228366EBF81C3 ] EFS             C:\Windows\System32\lsass.exe
16:15:54.0519 0436  EFS - ok
16:15:54.0565 0436  [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
16:15:54.0565 0436  ehRecvr - ok
16:15:54.0581 0436  [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched         C:\Windows\ehome\ehsched.exe
16:15:54.0581 0436  ehSched - ok
16:15:54.0581 0436  [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
16:15:54.0597 0436  elxstor - ok
16:15:54.0597 0436  [ 34A3C54752046E79A126E15C51DB409B ] ErrDev          C:\Windows\system32\drivers\errdev.sys
16:15:54.0612 0436  ErrDev - ok
16:15:54.0643 0436  [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem     C:\Windows\system32\es.dll
16:15:54.0643 0436  EventSystem - ok
16:15:54.0659 0436  [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat           C:\Windows\system32\drivers\exfat.sys
16:15:54.0659 0436  exfat - ok
16:15:54.0675 0436  [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
16:15:54.0675 0436  fastfat - ok
16:15:54.0690 0436  [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax             C:\Windows\system32\fxssvc.exe
16:15:54.0690 0436  Fax - ok
16:15:54.0706 0436  [ D765D19CD8EF61F650C384F62FAC00AB ] fdc             C:\Windows\system32\drivers\fdc.sys
16:15:54.0706 0436  fdc - ok
16:15:54.0706 0436  [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost         C:\Windows\system32\fdPHost.dll
16:15:54.0706 0436  fdPHost - ok
16:15:54.0721 0436  [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub        C:\Windows\system32\fdrespub.dll
16:15:54.0721 0436  FDResPub - ok
16:15:54.0737 0436  [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
16:15:54.0737 0436  FileInfo - ok
16:15:54.0753 0436  [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
16:15:54.0753 0436  Filetrace - ok
16:15:54.0753 0436  [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
16:15:54.0753 0436  flpydisk - ok
16:15:54.0768 0436  [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
16:15:54.0768 0436  FltMgr - ok
16:15:54.0815 0436  [ C4C183E6551084039EC862DA1C945E3D ] FontCache       C:\Windows\system32\FntCache.dll
16:15:54.0831 0436  FontCache - ok
16:15:54.0846 0436  [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
16:15:54.0846 0436  FontCache3.0.0.0 - ok
16:15:54.0846 0436  [ D43703496149971890703B4B1B723EAC ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
16:15:54.0846 0436  FsDepends - ok
16:15:54.0862 0436  [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr         C:\Windows\system32\DRIVERS\fssfltr.sys
16:15:54.0862 0436  fssfltr - ok
16:15:54.0893 0436  [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc          C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
16:15:54.0909 0436  fsssvc - ok
16:15:54.0924 0436  [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
16:15:54.0924 0436  Fs_Rec - ok
16:15:54.0940 0436  [ 1F7B25B858FA27015169FE95E54108ED ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
16:15:54.0940 0436  fvevol - ok
16:15:54.0940 0436  [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
16:15:54.0955 0436  gagp30kx - ok
16:15:54.0971 0436  [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
16:15:54.0971 0436  GEARAspiWDM - ok
16:15:54.0987 0436  [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc           C:\Windows\System32\gpsvc.dll
16:15:54.0987 0436  gpsvc - ok
16:15:55.0018 0436  [ F02A533F517EB38333CB12A9E8963773 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:15:55.0018 0436  gupdate - ok
16:15:55.0018 0436  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:15:55.0018 0436  gupdatem - ok
16:15:55.0049 0436  [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc           C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
16:15:55.0049 0436  gusvc - ok
16:15:55.0065 0436  [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
16:15:55.0065 0436  hcw85cir - ok
16:15:55.0080 0436  [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
16:15:55.0080 0436  HdAudAddService - ok
16:15:55.0080 0436  [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
16:15:55.0080 0436  HDAudBus - ok
16:15:55.0096 0436  [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
16:15:55.0096 0436  HidBatt - ok
16:15:55.0096 0436  [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
16:15:55.0096 0436  HidBth - ok
16:15:55.0111 0436  [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr           C:\Windows\system32\drivers\hidir.sys
16:15:55.0111 0436  HidIr - ok
16:15:55.0111 0436  [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv         C:\Windows\system32\hidserv.dll
16:15:55.0111 0436  hidserv - ok
16:15:55.0127 0436  [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
16:15:55.0127 0436  HidUsb - ok
16:15:55.0143 0436  [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc          C:\Windows\system32\kmsvc.dll
16:15:55.0143 0436  hkmsvc - ok
16:15:55.0158 0436  [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
16:15:55.0158 0436  HomeGroupListener - ok
16:15:55.0158 0436  [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
16:15:55.0158 0436  HomeGroupProvider - ok
16:15:55.0174 0436  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
16:15:55.0174 0436  HpSAMD - ok
16:15:55.0189 0436  [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
16:15:55.0189 0436  HTTP - ok
16:15:55.0205 0436  [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
16:15:55.0205 0436  hwpolicy - ok
16:15:55.0221 0436  [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
16:15:55.0221 0436  i8042prt - ok
16:15:55.0236 0436  [ C224331A54571C8C9162F7714400BBBD ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
16:15:55.0236 0436  iaStor - ok
16:15:55.0267 0436  [ 7D4B9A48430ED57ACA6373B71D5904CA ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
16:15:55.0267 0436  IAStorDataMgrSvc - ok
16:15:55.0283 0436  [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
16:15:55.0299 0436  iaStorV - ok
16:15:55.0330 0436  [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
16:15:55.0330 0436  idsvc - ok
16:15:55.0345 0436  [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
16:15:55.0345 0436  iirsp - ok
16:15:55.0361 0436  [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT          C:\Windows\System32\ikeext.dll
16:15:55.0377 0436  IKEEXT - ok
16:15:55.0439 0436  [ 651972B4061F940DC154C6F7B948B76A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
16:15:55.0486 0436  IntcAzAudAddService - ok
16:15:55.0501 0436  [ 2D66067C7A8A0112156BCD1C0BAA7042 ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
16:15:55.0501 0436  Intel® Capability Licensing Service Interface - ok
16:15:55.0533 0436  [ C9DCE1CB628AEED3C0C30ABBF4F1E718 ] Intel® ME Service C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
16:15:55.0533 0436  Intel® ME Service - ok
16:15:55.0548 0436  [ F00F20E70C6EC3AA366910083A0518AA ] intelide        C:\Windows\system32\drivers\intelide.sys
16:15:55.0548 0436  intelide - ok
16:15:55.0564 0436  [ ADA036632C664CAA754079041CF1F8C1 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
16:15:55.0564 0436  intelppm - ok
16:15:55.0595 0436  [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
16:15:55.0595 0436  IPBusEnum - ok
16:15:55.0611 0436  [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
16:15:55.0611 0436  IpFilterDriver - ok
16:15:55.0626 0436  [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
16:15:55.0626 0436  iphlpsvc - ok
16:15:55.0626 0436  [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
16:15:55.0642 0436  IPMIDRV - ok
16:15:55.0642 0436  [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
16:15:55.0642 0436  IPNAT - ok
16:15:55.0657 0436  [ 4EFFC8FF6D349E971E94B1C670C0C66A ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
16:15:55.0657 0436  iPod Service - ok
16:15:55.0673 0436  [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
16:15:55.0673 0436  IRENUM - ok
16:15:55.0673 0436  [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
16:15:55.0673 0436  isapnp - ok
16:15:55.0689 0436  [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
16:15:55.0689 0436  iScsiPrt - ok
16:15:55.0720 0436  [ DC0DBA5164F657DE2AE94B9D1FF75DA4 ] iusb3hcs        C:\Windows\system32\DRIVERS\iusb3hcs.sys
16:15:55.0720 0436  iusb3hcs - ok
16:15:55.0735 0436  [ BA4F3A70F03584E5B907DA815677727D ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
16:15:55.0735 0436  iusb3hub - ok
16:15:55.0751 0436  [ E6130F70D61867C7EFC13A2F808EDC58 ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
16:15:55.0751 0436  iusb3xhc - ok
16:15:55.0767 0436  [ 3628933AF5305EAB8173949BFF912F04 ] jhi_service     C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
16:15:55.0767 0436  jhi_service - ok
16:15:55.0782 0436  [ 1DED0D0AA513E2A5862B20A520D3A1E1 ] JME Keyboard    C:\Windows\jmesoft\Service.exe
16:15:55.0782 0436  JME Keyboard - ok
16:15:55.0798 0436  [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
16:15:55.0798 0436  kbdclass - ok
16:15:55.0798 0436  [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
16:15:55.0798 0436  kbdhid - ok
16:15:55.0813 0436  [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso          C:\Windows\system32\lsass.exe
16:15:55.0813 0436  KeyIso - ok
16:15:55.0829 0436  [ 77481D3753F6DCB0A499C3A01460DC00 ] KmxAgent        C:\Windows\system32\DRIVERS\kmxagent.sys
16:15:55.0829 0436  KmxAgent - ok
16:15:55.0845 0436  [ C30A499E4A05FA7C1B2B1325953F12D4 ] KmxAMRT         C:\Windows\system32\DRIVERS\KmxAMRT.sys
16:15:55.0860 0436  KmxAMRT - ok
16:15:55.0876 0436  [ 2896919A9E5A4DC267A2D916F75D2346 ] KmxCF           C:\Windows\system32\DRIVERS\KmxCF.sys
16:15:55.0876 0436  KmxCF - ok
16:15:55.0876 0436  [ 2FA4CB9DCA3ED83583659670F3B40916 ] KmxCfg          C:\Windows\system32\DRIVERS\kmxcfg.sys
16:15:55.0891 0436  KmxCfg - ok
16:15:55.0891 0436  [ EB0576050B2A618563CAA3ECBF19F2EF ] KmxFile         C:\Windows\system32\DRIVERS\KmxFile.sys
16:15:55.0891 0436  KmxFile - ok
16:15:55.0923 0436  [ 87DA5AFC8950EC34D0CDDF3438370727 ] KmxFilter       C:\Windows\system32\DRIVERS\KmxFilter.sys
16:15:55.0923 0436  KmxFilter - ok
16:15:55.0938 0436  [ 15260D1B5BB6BA8E5079E758FCE88207 ] KmxFw           C:\Windows\system32\DRIVERS\kmxfw.sys
16:15:55.0938 0436  KmxFw - ok
16:15:55.0938 0436  [ EEF33889A80990C70595457A5C97EE09 ] KmxSbx          C:\Windows\system32\DRIVERS\KmxSbx.sys
16:15:55.0938 0436  KmxSbx - ok
16:15:55.0969 0436  [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
16:15:55.0969 0436  KSecDD - ok
16:15:55.0985 0436  [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
16:15:55.0985 0436  KSecPkg - ok
16:15:55.0985 0436  [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
16:15:55.0985 0436  ksthunk - ok
16:15:56.0001 0436  [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm           C:\Windows\system32\msdtckrm.dll
16:15:56.0001 0436  KtmRm - ok
16:15:56.0016 0436  [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer    C:\Windows\system32\srvsvc.dll
16:15:56.0016 0436  LanmanServer - ok
16:15:56.0032 0436  [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
16:15:56.0047 0436  LanmanWorkstation - ok
16:15:56.0063 0436  [ 5BBEB3DD63BB7598A32BE23667A553BD ] LenovoCOMSvc    C:\Program Files\Lenovo\Power Control Switch\LenovoCOMSvc.exe
16:15:56.0063 0436  LenovoCOMSvc - ok
16:15:56.0063 0436  [ 369409D958ECF23951C4FB3C7111CE9F ] LitModeCtrl     C:\Program Files\Lenovo\Power Control Switch\LitModeCtrl.exe
16:15:56.0063 0436  LitModeCtrl - ok
16:15:56.0079 0436  [ 1538831CF8AD2979A04C423779465827 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
16:15:56.0094 0436  lltdio - ok
16:15:56.0110 0436  [ C1185803384AB3FEED115F79F109427F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
16:15:56.0110 0436  lltdsvc - ok
16:15:56.0110 0436  [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts         C:\Windows\System32\lmhsvc.dll
16:15:56.0110 0436  lmhosts - ok
16:15:56.0125 0436  [ BF22ACF4CF3734D61357E67F0521BC03 ] LMS             C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
16:15:56.0125 0436  LMS - ok
16:15:56.0141 0436  [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
16:15:56.0141 0436  LSI_FC - ok
16:15:56.0141 0436  [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
16:15:56.0141 0436  LSI_SAS - ok
16:15:56.0157 0436  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
16:15:56.0157 0436  LSI_SAS2 - ok
16:15:56.0172 0436  [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
16:15:56.0172 0436  LSI_SCSI - ok
16:15:56.0188 0436  [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv           C:\Windows\system32\drivers\luafv.sys
16:15:56.0188 0436  luafv - ok
16:15:56.0203 0436  McAfee SiteAdvisor Service - ok
16:15:56.0235 0436  [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
16:15:56.0235 0436  Mcx2Svc - ok
16:15:56.0235 0436  [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas         C:\Windows\system32\drivers\megasas.sys
16:15:56.0235 0436  megasas - ok
16:15:56.0250 0436  [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
16:15:56.0250 0436  MegaSR - ok
16:15:56.0266 0436  [ 6B01B7414A105B9E51652089A03027CF ] MEIx64          C:\Windows\system32\DRIVERS\HECIx64.sys
16:15:56.0281 0436  MEIx64 - ok
16:15:56.0281 0436  [ E40E80D0304A73E8D269F7141D77250B ] MMCSS           C:\Windows\system32\mmcss.dll
16:15:56.0281 0436  MMCSS - ok
16:15:56.0297 0436  [ 800BA92F7010378B09F9ED9270F07137 ] Modem           C:\Windows\system32\drivers\modem.sys
16:15:56.0297 0436  Modem - ok
16:15:56.0328 0436  [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
16:15:56.0328 0436  monitor - ok
16:15:56.0328 0436  [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
16:15:56.0344 0436  mouclass - ok
16:15:56.0359 0436  [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
16:15:56.0359 0436  mouhid - ok
16:15:56.0359 0436  [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
16:15:56.0359 0436  mountmgr - ok
16:15:56.0375 0436  [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio            C:\Windows\system32\drivers\mpio.sys
16:15:56.0375 0436  mpio - ok
16:15:56.0375 0436  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
16:15:56.0375 0436  mpsdrv - ok
16:15:56.0406 0436  [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc          C:\Windows\system32\mpssvc.dll
16:15:56.0406 0436  MpsSvc - ok
16:15:56.0406 0436  [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
16:15:56.0406 0436  MRxDAV - ok
16:15:56.0437 0436  [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
16:15:56.0437 0436  mrxsmb - ok
16:15:56.0437 0436  [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
16:15:56.0453 0436  mrxsmb10 - ok
16:15:56.0469 0436  [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
16:15:56.0469 0436  mrxsmb20 - ok
16:15:56.0469 0436  [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci          C:\Windows\system32\drivers\msahci.sys
16:15:56.0469 0436  msahci - ok
16:15:56.0484 0436  [ DB801A638D011B9633829EB6F663C900 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
16:15:56.0484 0436  msdsm - ok
16:15:56.0484 0436  [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC           C:\Windows\System32\msdtc.exe
16:15:56.0484 0436  MSDTC - ok
16:15:56.0515 0436  [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
16:15:56.0515 0436  Msfs - ok
16:15:56.0515 0436  [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
16:15:56.0515 0436  mshidkmdf - ok
16:15:56.0515 0436  [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
16:15:56.0515 0436  msisadrv - ok
16:15:56.0531 0436  [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
16:15:56.0531 0436  MSiSCSI - ok
16:15:56.0531 0436  msiserver - ok
16:15:56.0547 0436  [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
16:15:56.0547 0436  MSKSSRV - ok
16:15:56.0547 0436  [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
16:15:56.0547 0436  MSPCLOCK - ok
16:15:56.0547 0436  [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
16:15:56.0547 0436  MSPQM - ok
16:15:56.0562 0436  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
16:15:56.0562 0436  MsRPC - ok
16:15:56.0562 0436  [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
16:15:56.0562 0436  mssmbios - ok
16:15:56.0562 0436  [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
16:15:56.0562 0436  MSTEE - ok
16:15:56.0562 0436  [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
16:15:56.0562 0436  MTConfig - ok
16:15:56.0578 0436  [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup             C:\Windows\system32\Drivers\mup.sys
16:15:56.0578 0436  Mup - ok
16:15:56.0593 0436  [ 582AC6D9873E31DFA28A4547270862DD ] napagent        C:\Windows\system32\qagentRT.dll
16:15:56.0593 0436  napagent - ok
16:15:56.0609 0436  [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
16:15:56.0609 0436  NativeWifiP - ok
16:15:56.0640 0436  [ C38B8AE57F78915905064A9A24DC1586 ] NDIS            C:\Windows\system32\drivers\ndis.sys
16:15:56.0640 0436  NDIS - ok
16:15:56.0656 0436  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
16:15:56.0656 0436  NdisCap - ok
16:15:56.0671 0436  [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
16:15:56.0671 0436  NdisTapi - ok
16:15:56.0671 0436  [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
16:15:56.0671 0436  Ndisuio - ok
16:15:56.0671 0436  [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
16:15:56.0671 0436  NdisWan - ok
16:15:56.0687 0436  [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
16:15:56.0687 0436  NDProxy - ok
16:15:56.0703 0436  [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
16:15:56.0703 0436  NetBIOS - ok
16:15:56.0734 0436  [ 09594D1089C523423B32A4229263F068 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
16:15:56.0734 0436  NetBT - ok
16:15:56.0734 0436  [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon        C:\Windows\system32\lsass.exe
16:15:56.0734 0436  Netlogon - ok
16:15:56.0749 0436  [ 847D3AE376C0817161A14A82C8922A9E ] Netman          C:\Windows\System32\netman.dll
16:15:56.0749 0436  Netman - ok
16:15:56.0765 0436  [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm        C:\Windows\System32\netprofm.dll
16:15:56.0781 0436  netprofm - ok
16:15:56.0796 0436  [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:15:56.0796 0436  NetTcpPortSharing - ok
16:15:56.0812 0436  [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
16:15:56.0812 0436  nfrd960 - ok
16:15:56.0827 0436  [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc          C:\Windows\System32\nlasvc.dll
16:15:56.0827 0436  NlaSvc - ok
16:15:56.0827 0436  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
16:15:56.0827 0436  Npfs - ok
16:15:56.0843 0436  [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi             C:\Windows\system32\nsisvc.dll
16:15:56.0843 0436  nsi - ok
16:15:56.0859 0436  [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
16:15:56.0859 0436  nsiproxy - ok
16:15:56.0890 0436  [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
16:15:56.0905 0436  Ntfs - ok
16:15:56.0921 0436  [ 9899284589F75FA8724FF3D16AED75C1 ] Null            C:\Windows\system32\drivers\Null.sys
16:15:56.0921 0436  Null - ok
16:15:56.0937 0436  [ B4F53BCA4C688FF47F04FA90098F896E ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
16:15:56.0937 0436  NVHDA - ok
16:15:57.0046 0436  [ 4EE399576F76D38C04745DB739BBC8C7 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
16:15:57.0155 0436  nvlddmkm - ok
16:15:57.0171 0436  [ 0A92CB65770442ED0DC44834632F66AD ] nvraid          C:\Windows\system32\drivers\nvraid.sys
16:15:57.0171 0436  nvraid - ok
16:15:57.0171 0436  [ DAB0E87525C10052BF65F06152F37E4A ] nvstor          C:\Windows\system32\drivers\nvstor.sys
16:15:57.0171 0436  nvstor - ok
16:15:57.0217 0436  [ 7335C3D78A7746D76D37F6722CC4A466 ] nvsvc           C:\Windows\system32\nvvsvc.exe
16:15:57.0217 0436  nvsvc - ok
16:15:57.0264 0436  [ B7C53DA1C73FF39F4A6248643EFD979A ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
16:15:57.0280 0436  nvUpdatusService - ok
16:15:57.0295 0436  [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
16:15:57.0295 0436  nv_agp - ok
16:15:57.0373 0436  [ CF7B55AEF7AA9CF053C8B33D8055C367 ] OfficeSvc       C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
16:15:57.0405 0436  OfficeSvc - ok
16:15:57.0420 0436  [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
16:15:57.0420 0436  ohci1394 - ok
16:15:57.0436 0436  [ 11E0B35479C895888BA3D7F619DCFFF3 ] ose64           C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:15:57.0436 0436  ose64 - ok
16:15:57.0498 0436  [ FE9C0029E1AF26350D9985D00520E5C8 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
16:15:57.0561 0436  osppsvc - ok
16:15:57.0576 0436  [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
16:15:57.0576 0436  p2pimsvc - ok
16:15:57.0592 0436  [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc          C:\Windows\system32\p2psvc.dll
16:15:57.0592 0436  p2psvc - ok
16:15:57.0592 0436  [ 0086431C29C35BE1DBC43F52CC273887 ] Parport         C:\Windows\system32\drivers\parport.sys
16:15:57.0592 0436  Parport - ok
16:15:57.0607 0436  [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
16:15:57.0623 0436  partmgr - ok
16:15:57.0623 0436  [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc          C:\Windows\System32\pcasvc.dll
16:15:57.0623 0436  PcaSvc - ok
16:15:57.0639 0436  [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci             C:\Windows\system32\drivers\pci.sys
16:15:57.0639 0436  pci - ok
16:15:57.0639 0436  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide          C:\Windows\system32\drivers\pciide.sys
16:15:57.0639 0436  pciide - ok
16:15:57.0654 0436  [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
16:15:57.0654 0436  pcmcia - ok
16:15:57.0670 0436  [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw             C:\Windows\system32\drivers\pcw.sys
16:15:57.0670 0436  pcw - ok
16:15:57.0685 0436  [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
16:15:57.0685 0436  PEAUTH - ok
16:15:57.0732 0436  [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost        C:\Windows\SysWow64\perfhost.exe
16:15:57.0732 0436  PerfHost - ok
16:15:57.0748 0436  [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla             C:\Windows\system32\pla.dll
16:15:57.0779 0436  pla - ok
16:15:57.0795 0436  [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
16:15:57.0795 0436  PlugPlay - ok
16:15:57.0810 0436  [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
16:15:57.0810 0436  PNRPAutoReg - ok
16:15:57.0810 0436  [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
16:15:57.0810 0436  PNRPsvc - ok
16:15:57.0841 0436  [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
16:15:57.0841 0436  PolicyAgent - ok
16:15:57.0857 0436  [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power           C:\Windows\system32\umpo.dll
16:15:57.0857 0436  Power - ok
16:15:57.0873 0436  [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
16:15:57.0873 0436  PptpMiniport - ok
16:15:57.0873 0436  [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor       C:\Windows\system32\drivers\processr.sys
16:15:57.0873 0436  Processor - ok
16:15:57.0888 0436  [ 5C78838B4D166D1A27DB3A8A820C799A ] ProfSvc         C:\Windows\system32\profsvc.dll
16:15:57.0888 0436  ProfSvc - ok
16:15:57.0904 0436  [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
16:15:57.0904 0436  ProtectedStorage - ok
16:15:57.0919 0436  [ 0557CF5A2556BD58E26384169D72438D ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
16:15:57.0919 0436  Psched - ok
16:15:57.0935 0436  [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
16:15:57.0951 0436  ql2300 - ok
16:15:57.0951 0436  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
16:15:57.0951 0436  ql40xx - ok
16:15:57.0966 0436  [ 906191634E99AEA92C4816150BDA3732 ] QWAVE           C:\Windows\system32\qwave.dll
16:15:57.0966 0436  QWAVE - ok
16:15:57.0966 0436  [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
16:15:57.0966 0436  QWAVEdrv - ok
16:15:57.0982 0436  [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
16:15:57.0982 0436  RasAcd - ok
16:15:57.0997 0436  [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
16:15:57.0997 0436  RasAgileVpn - ok
16:15:57.0997 0436  [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto         C:\Windows\System32\rasauto.dll
16:15:57.0997 0436  RasAuto - ok
16:15:58.0013 0436  [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
16:15:58.0013 0436  Rasl2tp - ok
16:15:58.0029 0436  [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan          C:\Windows\System32\rasmans.dll
16:15:58.0029 0436  RasMan - ok
16:15:58.0029 0436  [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
16:15:58.0029 0436  RasPppoe - ok
16:15:58.0044 0436  [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
16:15:58.0044 0436  RasSstp - ok
16:15:58.0044 0436  [ 77F665941019A1594D887A74F301FA2F ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
16:15:58.0044 0436  rdbss - ok
16:15:58.0060 0436  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus          C:\Windows\system32\drivers\rdpbus.sys
16:15:58.0060 0436  rdpbus - ok
16:15:58.0060 0436  [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
16:15:58.0060 0436  RDPCDD - ok
16:15:58.0075 0436  [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
16:15:58.0075 0436  RDPENCDD - ok
16:15:58.0075 0436  [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
16:15:58.0075 0436  RDPREFMP - ok
16:15:58.0091 0436  [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
16:15:58.0091 0436  RDPWD - ok
16:15:58.0122 0436  [ A115F49BEA840A5F049BC6310F35F776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
16:15:58.0122 0436  rdyboost - ok
16:15:58.0138 0436  [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess    C:\Windows\System32\mprdim.dll
16:15:58.0138 0436  RemoteAccess - ok
16:15:58.0138 0436  [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
16:15:58.0138 0436  RemoteRegistry - ok
16:15:58.0153 0436  [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
16:15:58.0153 0436  RpcEptMapper - ok
16:15:58.0153 0436  [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator      C:\Windows\system32\locator.exe
16:15:58.0153 0436  RpcLocator - ok
16:15:58.0169 0436  [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs           C:\Windows\system32\rpcss.dll
16:15:58.0169 0436  RpcSs - ok
16:15:58.0185 0436  [ DDC86E4F8E7456261E637E3552E804FF ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
16:15:58.0185 0436  rspndr - ok
16:15:58.0200 0436  [ D20C15D0F6D660044646C1749BF04216 ] RSUSBSTOR       C:\Windows\system32\Drivers\RtsUStor.sys
16:15:58.0200 0436  RSUSBSTOR - ok
16:15:58.0231 0436  [ 9140DB0911DE035FED0A9A77A2D156EA ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
16:15:58.0231 0436  RTL8167 - ok
16:15:58.0247 0436  [ 3C22753DE0BA84C2DE2C1DAC268357BE ] RTL8192Ce       C:\Windows\system32\DRIVERS\rtl8192Ce.sys
16:15:58.0263 0436  RTL8192Ce - ok
16:15:58.0263 0436  [ C118A82CD78818C29AB228366EBF81C3 ] SamSs           C:\Windows\system32\lsass.exe
16:15:58.0263 0436  SamSs - ok
16:15:58.0263 0436  [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
16:15:58.0278 0436  sbp2port - ok
16:15:58.0278 0436  [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr        C:\Windows\System32\SCardSvr.dll
16:15:58.0278 0436  SCardSvr - ok
16:15:58.0294 0436  [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
16:15:58.0294 0436  scfilter - ok
16:15:58.0309 0436  [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule        C:\Windows\system32\schedsvc.dll
16:15:58.0325 0436  Schedule - ok
16:15:58.0325 0436  [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc     C:\Windows\System32\certprop.dll
16:15:58.0325 0436  SCPolicySvc - ok
16:15:58.0325 0436  [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
16:15:58.0341 0436  SDRSVC - ok
16:15:58.0356 0436  [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
16:15:58.0356 0436  secdrv - ok
16:15:58.0356 0436  [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon        C:\Windows\system32\seclogon.dll
16:15:58.0372 0436  seclogon - ok
16:15:58.0372 0436  [ C32AB8FA018EF34C0F113BD501436D21 ] SENS            C:\Windows\System32\sens.dll
16:15:58.0387 0436  SENS - ok
16:15:58.0387 0436  [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
16:15:58.0387 0436  SensrSvc - ok
16:15:58.0403 0436  [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
16:15:58.0403 0436  Serenum - ok
16:15:58.0419 0436  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
16:15:58.0419 0436  Serial - ok
16:15:58.0419 0436  [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse        C:\Windows\system32\drivers\sermouse.sys
16:15:58.0419 0436  sermouse - ok
16:15:58.0434 0436  [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv      C:\Windows\system32\sessenv.dll
16:15:58.0434 0436  SessionEnv - ok
16:15:58.0434 0436  [ A554811BCD09279536440C964AE35BBF ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
16:15:58.0434 0436  sffdisk - ok
16:15:58.0434 0436  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
16:15:58.0434 0436  sffp_mmc - ok
16:15:58.0465 0436  [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
16:15:58.0465 0436  sffp_sd - ok
16:15:58.0465 0436  [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
16:15:58.0465 0436  sfloppy - ok
16:15:58.0497 0436  [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess    C:\Windows\System32\ipnathlp.dll
16:15:58.0497 0436  SharedAccess - ok
16:15:58.0543 0436  [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
16:15:58.0543 0436  ShellHWDetection - ok
16:15:58.0543 0436  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
16:15:58.0543 0436  SiSRaid2 - ok
16:15:58.0543 0436  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
16:15:58.0543 0436  SiSRaid4 - ok
16:15:58.0559 0436  [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
16:15:58.0559 0436  Smb - ok
16:15:58.0559 0436  [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
16:15:58.0559 0436  SNMPTRAP - ok
16:15:58.0575 0436  [ B9E31E5CACDFE584F34F730A677803F9 ] spldr           C:\Windows\system32\drivers\spldr.sys
16:15:58.0575 0436  spldr - ok
16:15:58.0590 0436  [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler         C:\Windows\System32\spoolsv.exe
16:15:58.0590 0436  Spooler - ok
16:15:58.0621 0436  [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc          C:\Windows\system32\sppsvc.exe
16:15:58.0668 0436  sppsvc - ok
16:15:58.0668 0436  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
16:15:58.0684 0436  sppuinotify - ok
16:15:58.0699 0436  [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv             C:\Windows\system32\DRIVERS\srv.sys
16:15:58.0699 0436  srv - ok
16:15:58.0731 0436  [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
16:15:58.0731 0436  srv2 - ok
16:15:58.0746 0436  [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
16:15:58.0746 0436  srvnet - ok
16:15:58.0762 0436  [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
16:15:58.0762 0436  SSDPSRV - ok
16:15:58.0777 0436  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc         C:\Windows\system32\sstpsvc.dll
16:15:58.0777 0436  SstpSvc - ok
16:15:58.0824 0436  [ 81F177C1954453AF407604160BD149CB ] Stereo Service  C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
16:15:58.0840 0436  Stereo Service - ok
16:15:58.0840 0436  [ F3817967ED533D08327DC73BC4D5542A ] stexstor        C:\Windows\system32\drivers\stexstor.sys
16:15:58.0840 0436  stexstor - ok
16:15:58.0855 0436  [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc          C:\Windows\System32\wiaservc.dll
16:15:58.0871 0436  stisvc - ok
16:15:58.0871 0436  [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
16:15:58.0871 0436  swenum - ok
16:15:58.0902 0436  [ E08E46FDD841B7184194011CA1955A0B ] swprv           C:\Windows\System32\swprv.dll
16:15:58.0902 0436  swprv - ok
16:15:58.0933 0436  [ 7BE4CDEA6BC7832BFE3112A350D8B9EA ] SysMain         C:\Windows\system32\sysmain.dll
16:15:58.0965 0436  SysMain - ok
16:15:58.0965 0436  [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
16:15:58.0980 0436  TabletInputService - ok
16:15:58.0980 0436  [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv         C:\Windows\System32\tapisrv.dll
16:15:58.0980 0436  TapiSrv - ok
16:15:58.0996 0436  [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS             C:\Windows\System32\tbssvc.dll
16:15:58.0996 0436  TBS - ok
16:15:59.0027 0436  [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
16:15:59.0027 0436  Tcpip - ok
16:15:59.0058 0436  [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
16:15:59.0058 0436  TCPIP6 - ok
16:15:59.0074 0436  [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
16:15:59.0074 0436  tcpipreg - ok
16:15:59.0089 0436  [ 3371D21011695B16333A3934340C4E7C ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
16:15:59.0089 0436  TDPIPE - ok
16:15:59.0105 0436  [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
16:15:59.0105 0436  TDTCP - ok
16:15:59.0121 0436  [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
16:15:59.0121 0436  tdx - ok
16:15:59.0136 0436  [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
16:15:59.0136 0436  TermDD - ok
16:15:59.0152 0436  [ 2E648163254233755035B46DD7B89123 ] TermService     C:\Windows\System32\termsrv.dll
16:15:59.0152 0436  TermService - ok
16:15:59.0152 0436  [ F0344071948D1A1FA732231785A0664C ] Themes          C:\Windows\system32\themeservice.dll
16:15:59.0152 0436  Themes - ok
16:15:59.0167 0436  [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER     C:\Windows\system32\mmcss.dll
16:15:59.0167 0436  THREADORDER - ok
16:15:59.0183 0436  [ DBCC20C02E8A3E43B03C304A4E40A84F ] TPM             C:\Windows\system32\drivers\tpm.sys
16:15:59.0183 0436  TPM - ok
16:15:59.0183 0436  [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks          C:\Windows\System32\trkwks.dll
16:15:59.0183 0436  TrkWks - ok
16:15:59.0214 0436  [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
16:15:59.0214 0436  TrustedInstaller - ok
16:15:59.0230 0436  [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
16:15:59.0230 0436  tssecsrv - ok
16:15:59.0230 0436  [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
16:15:59.0245 0436  TsUsbFlt - ok
16:15:59.0245 0436  [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
16:15:59.0245 0436  TsUsbGD - ok
16:15:59.0245 0436  [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
16:15:59.0261 0436  tunnel - ok
16:15:59.0261 0436  [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
16:15:59.0277 0436  uagp35 - ok
16:15:59.0292 0436  [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
16:15:59.0292 0436  udfs - ok
16:15:59.0292 0436  [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
16:15:59.0292 0436  UI0Detect - ok
16:15:59.0292 0436  [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
16:15:59.0292 0436  uliagpkx - ok
16:15:59.0308 0436  [ DC54A574663A895C8763AF0FA1FF7561 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
16:15:59.0308 0436  umbus - ok
16:15:59.0323 0436  [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
16:15:59.0323 0436  UmPass - ok
16:15:59.0370 0436  [ AF950F62E5FC72FFDB7363F72600B21C ] UmxEngine       C:\Program Files\CA\SharedComponents\TMEngine\UmxEngine.exe
16:15:59.0370 0436  UmxEngine - ok
16:15:59.0433 0436  [ B097EBA0E3FEB020BB65FE43AF5ECCFF ] UNS             C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
16:15:59.0433 0436  UNS - ok
16:15:59.0448 0436  [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost        C:\Windows\System32\upnphost.dll
16:15:59.0448 0436  upnphost - ok
16:15:59.0495 0436  [ C9E9D59C0099A9FF51697E9306A44240 ] USBAAPL64       C:\Windows\system32\Drivers\usbaapl64.sys
16:15:59.0495 0436  USBAAPL64 - ok
16:15:59.0511 0436  [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
16:15:59.0511 0436  usbccgp - ok
16:15:59.0511 0436  [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
16:15:59.0526 0436  usbcir - ok
16:15:59.0542 0436  [ C025055FE7B87701EB042095DF1A2D7B ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
16:15:59.0542 0436  usbehci - ok
16:15:59.0557 0436  [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
16:15:59.0557 0436  usbhub - ok
16:15:59.0557 0436  [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
16:15:59.0557 0436  usbohci - ok
16:15:59.0573 0436  [ 73188F58FB384E75C4063D29413CEE3D ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
16:15:59.0573 0436  usbprint - ok
16:15:59.0604 0436  [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
16:15:59.0604 0436  usbscan - ok
16:15:59.0635 0436  [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
16:15:59.0635 0436  USBSTOR - ok
16:15:59.0635 0436  [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
16:15:59.0635 0436  usbuhci - ok
16:15:59.0651 0436  [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
16:15:59.0651 0436  usbvideo - ok
16:15:59.0667 0436  [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms           C:\Windows\System32\uxsms.dll
16:15:59.0667 0436  UxSms - ok
16:15:59.0667 0436  [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc        C:\Windows\system32\lsass.exe
16:15:59.0667 0436  VaultSvc - ok
16:15:59.0682 0436  [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
16:15:59.0682 0436  vdrvroot - ok
16:15:59.0698 0436  [ 8D6B481601D01A456E75C3210F1830BE ] vds             C:\Windows\System32\vds.exe
16:15:59.0698 0436  vds - ok
16:15:59.0698 0436  [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
16:15:59.0698 0436  vga - ok
16:15:59.0713 0436  [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave         C:\Windows\System32\drivers\vga.sys
16:15:59.0713 0436  VgaSave - ok
16:15:59.0729 0436  [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
16:15:59.0729 0436  vhdmp - ok
16:15:59.0745 0436  [ E5689D93FFE4E5D66C0178761240DD54 ] viaide          C:\Windows\system32\drivers\viaide.sys
16:15:59.0745 0436  viaide - ok
16:15:59.0760 0436  [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
16:15:59.0760 0436  volmgr - ok
16:15:59.0776 0436  [ A255814907C89BE58B79EF2F189B843B ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
16:15:59.0776 0436  volmgrx - ok
16:15:59.0807 0436  [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
16:15:59.0807 0436  volsnap - ok
16:15:59.0823 0436  [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
16:15:59.0823 0436  vsmraid - ok
16:15:59.0869 0436  [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS             C:\Windows\system32\vssvc.exe
16:15:59.0885 0436  VSS - ok
16:15:59.0901 0436  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
16:15:59.0901 0436  vwifibus - ok
16:15:59.0916 0436  [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
16:15:59.0916 0436  vwififlt - ok
16:15:59.0932 0436  [ 1C9D80CC3849B3788048078C26486E1A ] W32Time         C:\Windows\system32\w32time.dll
16:15:59.0932 0436  W32Time - ok
16:15:59.0932 0436  [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
16:15:59.0932 0436  WacomPen - ok
16:15:59.0947 0436  [ 356AFD78A6ED4457169241AC3965230C ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
16:15:59.0947 0436  WANARP - ok
16:15:59.0947 0436  [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
16:15:59.0947 0436  Wanarpv6 - ok
16:15:59.0979 0436  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
16:15:59.0994 0436  WatAdminSvc - ok
16:16:00.0025 0436  [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine        C:\Windows\system32\wbengine.exe
16:16:00.0041 0436  wbengine - ok
16:16:00.0057 0436  [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
16:16:00.0057 0436  WbioSrvc - ok
16:16:00.0072 0436  [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc         C:\Windows\System32\wcncsvc.dll
16:16:00.0072 0436  wcncsvc - ok
16:16:00.0088 0436  [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
16:16:00.0088 0436  WcsPlugInService - ok
16:16:00.0088 0436  [ 72889E16FF12BA0F235467D6091B17DC ] Wd              C:\Windows\system32\drivers\wd.sys
16:16:00.0088 0436  Wd - ok
16:16:00.0119 0436  [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
16:16:00.0119 0436  Wdf01000 - ok
16:16:00.0150 0436  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost  C:\Windows\system32\wdi.dll
16:16:00.0150 0436  WdiServiceHost - ok
16:16:00.0150 0436  [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost   C:\Windows\system32\wdi.dll
16:16:00.0150 0436  WdiSystemHost - ok
16:16:00.0166 0436  [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient       C:\Windows\System32\webclnt.dll
16:16:00.0166 0436  WebClient - ok
16:16:00.0181 0436  [ C749025A679C5103E575E3B48E092C43 ] Wecsvc          C:\Windows\system32\wecsvc.dll
16:16:00.0181 0436  Wecsvc - ok
16:16:00.0181 0436  [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
16:16:00.0181 0436  wercplsupport - ok
16:16:00.0197 0436  [ 6D137963730144698CBD10F202E9F251 ] WerSvc          C:\Windows\System32\WerSvc.dll
16:16:00.0197 0436  WerSvc - ok
16:16:00.0228 0436  [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
16:16:00.0228 0436  WfpLwf - ok
16:16:00.0244 0436  [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
16:16:00.0244 0436  WIMMount - ok
16:16:00.0259 0436  WinDefend - ok
16:16:00.0259 0436  WinHttpAutoProxySvc - ok
16:16:00.0291 0436  [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
16:16:00.0291 0436  Winmgmt - ok
16:16:00.0322 0436  [ BCB1310604AA415C4508708975B3931E ] WinRM           C:\Windows\system32\WsmSvc.dll
16:16:00.0337 0436  WinRM - ok
16:16:00.0369 0436  [ 29E89E8A427D5F8AD7659AFDD8C3F83C ] WinSvchostManagerSrv C:\Windows\SysWOW64\cfgmig32.exe
16:16:00.0369 0436  WinSvchostManagerSrv - ok
16:16:00.0384 0436  [ FE88B288356E7B47B74B13372ADD906D ] WinUsb          C:\Windows\system32\DRIVERS\WinUSB.sys
16:16:00.0384 0436  WinUsb - ok
16:16:00.0431 0436  [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc         C:\Windows\System32\wlansvc.dll
16:16:00.0431 0436  Wlansvc - ok
16:16:00.0462 0436  [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc        C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
16:16:00.0462 0436  wlcrasvc - ok
16:16:00.0509 0436  [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:16:00.0525 0436  wlidsvc - ok
16:16:00.0540 0436  [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
16:16:00.0540 0436  WmiAcpi - ok
16:16:00.0556 0436  [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
16:16:00.0571 0436  wmiApSrv - ok
16:16:00.0571 0436  WMPNetworkSvc - ok
16:16:00.0571 0436  [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
16:16:00.0587 0436  WPCSvc - ok
16:16:00.0587 0436  [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
16:16:00.0587 0436  WPDBusEnum - ok
16:16:00.0603 0436  [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
16:16:00.0603 0436  ws2ifsl - ok
16:16:00.0603 0436  [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc          C:\Windows\System32\wscsvc.dll
16:16:00.0603 0436  wscsvc - ok
16:16:00.0603 0436  WSearch - ok
16:16:00.0634 0436  [ 83575C43B2BFE9AB0661A7F957E843C0 ] wsvd            C:\Windows\system32\DRIVERS\wsvd.sys
16:16:00.0634 0436  wsvd - ok
16:16:00.0665 0436  [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv        C:\Windows\system32\wuaueng.dll
16:16:00.0696 0436  wuauserv - ok
16:16:00.0696 0436  [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
16:16:00.0712 0436  WudfPf - ok
16:16:00.0712 0436  [ CF8D590BE3373029D57AF80914190682 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
16:16:00.0712 0436  WUDFRd - ok
16:16:00.0727 0436  [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
16:16:00.0727 0436  wudfsvc - ok
16:16:00.0743 0436  [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc         C:\Windows\System32\wwansvc.dll
16:16:00.0743 0436  WwanSvc - ok
16:16:00.0743 0436  ================ Scan global ===============================
16:16:00.0790 0436  [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
16:16:00.0805 0436  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
16:16:00.0805 0436  [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
16:16:00.0821 0436  [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
16:16:00.0837 0436  [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
16:16:00.0852 0436  [Global] - ok
16:16:00.0852 0436  ================ Scan MBR ==================================
16:16:00.0852 0436  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
16:16:01.0039 0436  \Device\Harddisk0\DR0 - ok
16:16:01.0039 0436  ================ Scan VBR ==================================
16:16:01.0039 0436  [ C881A699828E7C3644ADB0D6D5E1226B ] \Device\Harddisk0\DR0\Partition1
16:16:01.0039 0436  \Device\Harddisk0\DR0\Partition1 - ok
16:16:01.0039 0436  [ C12D9AB08C64F34786B8B3ECA8840055 ] \Device\Harddisk0\DR0\Partition2
16:16:01.0039 0436  \Device\Harddisk0\DR0\Partition2 - ok
16:16:01.0039 0436  ============================================================
16:16:01.0039 0436  Scan finished
16:16:01.0039 0436  ============================================================
16:16:01.0039 1300  Detected object count: 0
16:16:01.0039 1300  Actual detected object count: 0
 



#7 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 05:49 PM

ADCLEANER LOG

 

# AdwCleaner v2.305 - Logfile created 07/18/2013 at 16:18:38
# Updated 11/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Lunn Family - LUNNFAMILY-PC
# Boot Mode : Safe mode with networking
# Running from : C:\Users\Lunn Family\Desktop\Virus Tools\AdwCleaner.exe
# Option [Delete]

***** [Services] *****

Stopped & Deleted : CltMngSvc

***** [Files / Folders] *****

Deleted on reboot : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
Deleted on reboot : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
Deleted on reboot : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
File Deleted : C:\END
File Deleted : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\SearchProtect
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\Lunn Family\AppData\Local\Conduit
Folder Deleted : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
Folder Deleted : C:\Users\Lunn Family\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Lunn Family\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Lunn Family\AppData\Roaming\SearchProtect

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\SearchProtect
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3274043
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\SearchProtect
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dknnnemlggnbpceofncdgnakmgfnhbli
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [searchprotect]
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [SearchProtectAll]

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16611

[OK] Registry is clean.

-\\ Google Chrome v27.0.1453.116

File : C:\Users\Lunn Family\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.23] : icon_url = "hxxp://search.conduit.com/fav.ico",
Deleted [l.26] : keyword = "search.conduit.com",
Deleted [l.30] : search_url = "hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&cui=UN25[...]
Deleted [l.31] : suggest_url = "hxxp://suggest.search.conduit.com/Suggest.ashx?q=[{searchTerms}]"
Deleted [l.2118] : homepage = "hxxp://search.conduit.com/?ctid=CT3289075&SearchSource=48&CUI=UN25971836973058919&UM[...]
Deleted [l.2376] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3289075&SearchSource=48&CUI[...]

*************************

AdwCleaner[S1].txt - [3518 octets] - [18/07/2013 16:18:38]

########## EOF - C:\AdwCleaner[S1].txt - [3578 octets] ##########



Currently awaiting for ESET Scan to Finish



#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:36 PM

Posted 18 July 2013 - 06:54 PM

OK, do you need a free antivirus, I do not see one installed?

In Control Panel uninstall these and reboot.

Java 7 Update 21 (64-bit) (Version: 7.0.210)
Java 7 Update 21 (Version: 7.0.210)

Install Java Version 7 Update 25
 
Also I see we will need to run his....
 
thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
How is it now?
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 06:57 PM

I currently have total Defense premium internet security that has its own av.

 

Currently at 99% on the ESET Scan with 1 infected file so far.



#10 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 07:07 PM

ESET Scan complete

 

C:\Users\Lunn Family\AppData\Local\Temp\SecondStepInstaller.exe multiple threats cleaned by deleting - quarantined



#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:36 PM

Posted 18 July 2013 - 07:27 PM

That's a Conduit malware file.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 07:56 PM

this is what I got from the JRT

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.1.6 (07.17.2013:4)
OS: Windows 7 Home Premium x64
Ran by Lunn Family on Thu 07/18/2013 at 18:36:24.36
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

~~~ Services

 

~~~ Registry Values

 

~~~ Registry Keys

 

~~~ Files

 

~~~ Folders

 

~~~ Chrome

Successfully deleted: [Folder] C:\Users\Lunn Family\appdata\local\Google\Chrome\User Data\Default\Extensions\cijeeimilokkhlfjombmalgpabbonmah

 

~~~ Event Viewer Logs were cleared

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 07/18/2013 at 18:45:28.48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



#13 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 08:03 PM

do I need to do anything else now that ESET says it cleaned that file.



#14 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:09:36 PM

Posted 18 July 2013 - 08:06 PM

Looks good to me.
Running well?
 
Empty your temp folders using TFC (Temporary File Cleaner)
 
[list]
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#15 HateTechnology

HateTechnology
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Fort Bliss Texas
  • Local time:07:36 PM

Posted 18 July 2013 - 08:08 PM

it is running a lot better. I can now update AV.

uninstall from control panel.

 

I also did my wifes laptop and it is much better.

 

Thank you.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users