Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible infection trojan.dropper?


  • Please log in to reply
3 replies to this topic

#1 mark123456

mark123456

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:39 PM

Posted 01 August 2013 - 12:02 PM

Hi,

My computer has been acting funny the past few days.

my computer runs XP Pro, Service Pack 3

I use Norton Internet Security, and been receiving the following the following message the past couple days:

"An intrusion attempt by "my computer" was blocked. Application Path:\DEVICE\HARDDISKVOLUME2\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE"

 

Yesterday I downloaded Malwarebytes to try and find the problem, and it found a few issues, but nothing that looked like this issue. Today, I've been getting iexplore.exe opening by itself in the "Processes" window and then Malwarebytes would give me this message: "IP-BLOCK    193.105.134.63 (Type: outgoing)"

I keep shutting down "iexplore.exe" from the processes and it keeps opening itself back up.

 

About an hour ago I got a message of Norton Security that Trojan.Dropper by detected by Auto-Protect and quarantined.

 

ixplore.exe keeps opening and trying to acccess the remote ip address. So I am definitely infected with something, but Norton and Malwarebytes can't find it. Please Help!!

 

I downloaded Hijackthis to help, anyone have any suggestions? Thank you!

 

 

 



BC AdBot (Login to Remove)

 


#2 GodfatherKing

GodfatherKing

  • Members
  • 587 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 01 August 2013 - 12:59 PM

:step1: Post MBAM log.

 

:step2: Running TDSSKiller to obtain log

 

Note: Don't cure or delete a threat, but choose skip for all instead.

  • Please download TDSSKiller from here and save it to your Desktop
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters

tds2.jpg

  • In the Additional options: Check Detect TDLFS file system
  • Click Start Scan and allow the scan process to run

tds4-1.jpg

  • Choose for all threats to Skip for all of them.
  • Click Continue
  • Please post the TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)

===================================================

 

:step3: ESET Online Scanner

==================

Note: If your AV is blocking Eset online scanner, please temporarily disable your AV.

 

I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and » UNCHECK "Remove found threats" <== Important
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Copy and paste the information in your next reply. (If no malware was found you will not be presented with a log).
  • Click the Back button.
  • Click the Finish button.

===================================================


If you have received help from me and I don't have respond to you for almost >= 3 days, send me a Private Message.  :hello:


#3 mark123456

mark123456
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:39 PM

Posted 01 August 2013 - 03:54 PM

Godfather,

 

Below are the

1. MBAM Log

2. TDSSKiller Log

3. ESET Online Scanner Log

 

*************************************************************************

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2013.07.31.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
mark360 :: MARKDELL360 [administrator]

Protection: Enabled

8/1/2013 9:17:23 AM
mbam-log-2013-08-01 (09-17-23).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 345804
Time elapsed: 2 hour(s), 15 minute(s), 4 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
*************************************************************

 

15:17:08.0140 6076  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
15:17:08.0140 6076  ============================================================
15:17:08.0140 6076  Current date / time: 2013/08/01 15:17:08.0140
15:17:08.0140 6076  SystemInfo:
15:17:08.0140 6076  
15:17:08.0140 6076  OS Version: 5.1.2600 ServicePack: 3.0
15:17:08.0140 6076  Product type: Workstation
15:17:08.0140 6076  ComputerName: MARKDELL360
15:17:08.0140 6076  UserName: mark360
15:17:08.0140 6076  Windows directory: C:\WINDOWS
15:17:08.0140 6076  System windows directory: C:\WINDOWS
15:17:08.0140 6076  Processor architecture: Intel x86
15:17:08.0140 6076  Number of processors: 2
15:17:08.0140 6076  Page size: 0x1000
15:17:08.0140 6076  Boot type: Normal boot
15:17:08.0140 6076  ============================================================
15:17:09.0875 6076  Drive \Device\Harddisk0\DR0 - Size: 0x2540BE4000 (149.01 Gb), SectorSize: 0x200, Cylinders: 0x4BFC, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
15:17:09.0890 6076  ============================================================
15:17:09.0890 6076  \Device\Harddisk0\DR0:
15:17:09.0890 6076  MBR partitions:
15:17:09.0890 6076  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x129F1720
15:17:09.0890 6076  ============================================================
15:17:09.0937 6076  C: <-> \Device\Harddisk0\DR0\Partition1
15:17:09.0937 6076  ============================================================
15:17:09.0937 6076  Initialize success
15:17:09.0937 6076  ============================================================
15:18:05.0718 6060  ============================================================
15:18:05.0718 6060  Scan started
15:18:05.0718 6060  Mode: Manual; TDLFS;
15:18:05.0718 6060  ============================================================
15:18:07.0406 6060  ================ Scan system memory ========================
15:18:07.0406 6060  System memory - ok
15:18:07.0406 6060  ================ Scan services =============================
15:18:07.0515 6060  Abiosdsk - ok
15:18:07.0562 6060  [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5        C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
15:18:07.0562 6060  abp480n5 - ok
15:18:07.0593 6060  [ 8FD99680A539792A30E97944FDAECF17 ] ACPI            C:\WINDOWS\system32\DRIVERS\ACPI.sys
15:18:07.0593 6060  ACPI - ok
15:18:07.0593 6060  [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC          C:\WINDOWS\system32\drivers\ACPIEC.sys
15:18:07.0593 6060  ACPIEC - ok
15:18:07.0640 6060  [ 803C7D4767132F2407431103055C9000 ] ADIHdAudAddService C:\WINDOWS\system32\drivers\ADIHdAud.sys
15:18:07.0640 6060  ADIHdAudAddService - ok
15:18:07.0671 6060  [ 9A11864873DA202C996558B2106B0BBC ] adpu160m        C:\WINDOWS\system32\DRIVERS\adpu160m.sys
15:18:07.0671 6060  adpu160m - ok
15:18:07.0703 6060  [ 8BED39E3C35D6A489438B8141717A557 ] aec             C:\WINDOWS\system32\drivers\aec.sys
15:18:07.0703 6060  aec - ok
15:18:07.0734 6060  [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD             C:\WINDOWS\System32\drivers\afd.sys
15:18:07.0750 6060  AFD - ok
15:18:07.0750 6060  [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440          C:\WINDOWS\system32\DRIVERS\agp440.sys
15:18:07.0750 6060  agp440 - ok
15:18:07.0750 6060  [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ          C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
15:18:07.0750 6060  agpCPQ - ok
15:18:07.0765 6060  [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x         C:\WINDOWS\system32\DRIVERS\aha154x.sys
15:18:07.0765 6060  Aha154x - ok
15:18:07.0765 6060  [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2         C:\WINDOWS\system32\DRIVERS\aic78u2.sys
15:18:07.0765 6060  aic78u2 - ok
15:18:07.0765 6060  [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx         C:\WINDOWS\system32\DRIVERS\aic78xx.sys
15:18:07.0765 6060  aic78xx - ok
15:18:07.0812 6060  [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter         C:\WINDOWS\system32\alrsvc.dll
15:18:07.0812 6060  Alerter - ok
15:18:07.0843 6060  [ 8C515081584A38AA007909CD02020B3D ] ALG             C:\WINDOWS\System32\alg.exe
15:18:07.0843 6060  ALG - ok
15:18:07.0906 6060  [ 1140AB9938809700B46BB88E46D72A96 ] AliIde          C:\WINDOWS\system32\DRIVERS\aliide.sys
15:18:07.0906 6060  AliIde - ok
15:18:07.0906 6060  [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541        C:\WINDOWS\system32\DRIVERS\alim1541.sys
15:18:07.0906 6060  alim1541 - ok
15:18:07.0906 6060  [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp          C:\WINDOWS\system32\DRIVERS\amdagp.sys
15:18:07.0906 6060  amdagp - ok
15:18:07.0921 6060  [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint          C:\WINDOWS\system32\DRIVERS\amsint.sys
15:18:07.0921 6060  amsint - ok
15:18:07.0937 6060  [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt         C:\WINDOWS\System32\appmgmts.dll
15:18:07.0968 6060  AppMgmt - ok
15:18:07.0968 6060  [ 62D318E9A0C8FC9B780008E724283707 ] asc             C:\WINDOWS\system32\DRIVERS\asc.sys
15:18:07.0968 6060  asc - ok
15:18:07.0968 6060  [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p        C:\WINDOWS\system32\DRIVERS\asc3350p.sys
15:18:07.0968 6060  asc3350p - ok
15:18:07.0968 6060  [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550         C:\WINDOWS\system32\DRIVERS\asc3550.sys
15:18:07.0968 6060  asc3550 - ok
15:18:08.0062 6060  [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
15:18:08.0062 6060  aspnet_state - ok
15:18:08.0078 6060  [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac        C:\WINDOWS\system32\DRIVERS\asyncmac.sys
15:18:08.0078 6060  AsyncMac - ok
15:18:08.0125 6060  [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi           C:\WINDOWS\system32\DRIVERS\atapi.sys
15:18:08.0125 6060  atapi - ok
15:18:08.0125 6060  Atdisk - ok
15:18:08.0156 6060  [ 9916C1225104BA14794209CFA8012159 ] Atmarpc         C:\WINDOWS\system32\DRIVERS\atmarpc.sys
15:18:08.0156 6060  Atmarpc - ok
15:18:08.0187 6060  [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv        C:\WINDOWS\System32\audiosrv.dll
15:18:08.0187 6060  AudioSrv - ok
15:18:08.0218 6060  [ D9F724AA26C010A217C97606B160ED68 ] audstub         C:\WINDOWS\system32\DRIVERS\audstub.sys
15:18:08.0218 6060  audstub - ok
15:18:08.0234 6060  [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
15:18:08.0250 6060  Beep - ok
15:18:08.0328 6060  [ 76154FA6A742C613B44BB636B1A7C057 ] BHDrvx86        C:\WINDOWS\System32\Drivers\NIS\1008030.006\BHDrvx86.sys
15:18:08.0343 6060  BHDrvx86 - ok
15:18:08.0375 6060  [ 574738F61FCA2935F5265DC4E5691314 ] BITS            C:\WINDOWS\system32\qmgr.dll
15:18:08.0390 6060  BITS - ok
15:18:08.0421 6060  [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser         C:\WINDOWS\System32\browser.dll
15:18:08.0421 6060  Browser - ok
15:18:08.0468 6060  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf           C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
15:18:08.0468 6060  cbidf - ok
15:18:08.0468 6060  [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k         C:\WINDOWS\system32\drivers\cbidf2k.sys
15:18:08.0468 6060  cbidf2k - ok
15:18:08.0500 6060  [ 3182B846490DC4D71FABD4A8CB6B73EA ] ccHP            C:\WINDOWS\System32\Drivers\NIS\1008030.006\ccHPx86.sys
15:18:08.0515 6060  ccHP - ok
15:18:08.0515 6060  [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt        C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
15:18:08.0515 6060  cd20xrnt - ok
15:18:08.0546 6060  [ C1B486A7658353D33A10CC15211A873B ] Cdaudio         C:\WINDOWS\system32\drivers\Cdaudio.sys
15:18:08.0562 6060  Cdaudio - ok
15:18:08.0593 6060  [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs            C:\WINDOWS\system32\drivers\Cdfs.sys
15:18:08.0593 6060  Cdfs - ok
15:18:08.0640 6060  [ 4B0A100EAF5C49EF3CCA8C641431EACC ] Cdrom           C:\WINDOWS\system32\DRIVERS\cdrom.sys
15:18:08.0640 6060  Cdrom - ok
15:18:08.0640 6060  Changer - ok
15:18:08.0671 6060  [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc           C:\WINDOWS\system32\cisvc.exe
15:18:08.0671 6060  CiSvc - ok
15:18:08.0687 6060  [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv         C:\WINDOWS\system32\clipsrv.exe
15:18:08.0687 6060  ClipSrv - ok
15:18:08.0718 6060  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:18:08.0718 6060  clr_optimization_v2.0.50727_32 - ok
15:18:08.0812 6060  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:18:08.0828 6060  clr_optimization_v4.0.30319_32 - ok
15:18:08.0828 6060  [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde          C:\WINDOWS\system32\DRIVERS\cmdide.sys
15:18:08.0828 6060  CmdIde - ok
15:18:08.0828 6060  COMSysApp - ok
15:18:08.0859 6060  [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray        C:\WINDOWS\system32\DRIVERS\cpqarray.sys
15:18:08.0859 6060  Cpqarray - ok
15:18:08.0890 6060  [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc        C:\WINDOWS\System32\cryptsvc.dll
15:18:08.0890 6060  CryptSvc - ok
15:18:08.0890 6060  [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k         C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
15:18:08.0890 6060  dac2w2k - ok
15:18:08.0906 6060  [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt        C:\WINDOWS\system32\DRIVERS\dac960nt.sys
15:18:08.0906 6060  dac960nt - ok
15:18:08.0953 6060  [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
15:18:08.0968 6060  DcomLaunch - ok
15:18:08.0984 6060  [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp            C:\WINDOWS\System32\dhcpcsvc.dll
15:18:08.0984 6060  Dhcp - ok
15:18:09.0062 6060  [ 044452051F3E02E7963599FC8F4F3E25 ] Disk            C:\WINDOWS\system32\DRIVERS\disk.sys
15:18:09.0062 6060  Disk - ok
15:18:09.0062 6060  dmadmin - ok
15:18:09.0093 6060  [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot          C:\WINDOWS\system32\drivers\dmboot.sys
15:18:09.0109 6060  dmboot - ok
15:18:09.0109 6060  [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio            C:\WINDOWS\system32\drivers\dmio.sys
15:18:09.0109 6060  dmio - ok
15:18:09.0125 6060  [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload          C:\WINDOWS\system32\drivers\dmload.sys
15:18:09.0125 6060  dmload - ok
15:18:09.0140 6060  [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver        C:\WINDOWS\System32\dmserver.dll
15:18:09.0156 6060  dmserver - ok
15:18:09.0171 6060  [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic          C:\WINDOWS\system32\drivers\DMusic.sys
15:18:09.0171 6060  DMusic - ok
15:18:09.0218 6060  [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
15:18:09.0218 6060  Dnscache - ok
15:18:09.0234 6060  [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc         C:\WINDOWS\System32\dot3svc.dll
15:18:09.0250 6060  Dot3svc - ok
15:18:09.0296 6060  [ 3E4B043F8BC6BE1D4820CC6C9C500306 ] Dot4            C:\WINDOWS\system32\DRIVERS\Dot4.sys
15:18:09.0296 6060  Dot4 - ok
15:18:09.0343 6060  [ 77CE63A8A34AE23D9FE4C7896D1DEBE7 ] Dot4Print       C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
15:18:09.0343 6060  Dot4Print - ok
15:18:09.0343 6060  [ 6EC3AF6BB5B30E488A0C559921F012E1 ] dot4usb         C:\WINDOWS\system32\DRIVERS\dot4usb.sys
15:18:09.0359 6060  dot4usb - ok
15:18:09.0375 6060  [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o          C:\WINDOWS\system32\DRIVERS\dpti2o.sys
15:18:09.0375 6060  dpti2o - ok
15:18:09.0406 6060  [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud         C:\WINDOWS\system32\drivers\drmkaud.sys
15:18:09.0406 6060  drmkaud - ok
15:18:09.0453 6060  [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost         C:\WINDOWS\System32\eapsvc.dll
15:18:09.0468 6060  EapHost - ok
15:18:09.0578 6060  [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl          C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
15:18:09.0609 6060  eeCtrl - ok
15:18:09.0640 6060  [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
15:18:09.0671 6060  EraserUtilRebootDrv - ok
15:18:09.0703 6060  [ BC93B4A066477954555966D77FEC9ECB ] ERSvc           C:\WINDOWS\System32\ersvc.dll
15:18:09.0703 6060  ERSvc - ok
15:18:09.0750 6060  [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog        C:\WINDOWS\system32\services.exe
15:18:09.0750 6060  Eventlog - ok
15:18:09.0796 6060  [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem     C:\WINDOWS\system32\es.dll
15:18:09.0796 6060  EventSystem - ok
15:18:09.0828 6060  [ 38D332A6D56AF32635675F132548343E ] Fastfat         C:\WINDOWS\system32\drivers\Fastfat.sys
15:18:09.0843 6060  Fastfat - ok
15:18:09.0890 6060  [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
15:18:09.0890 6060  FastUserSwitchingCompatibility - ok
15:18:09.0921 6060  [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax             C:\WINDOWS\system32\fxssvc.exe
15:18:09.0921 6060  Fax - ok
15:18:09.0921 6060  [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc             C:\WINDOWS\system32\drivers\Fdc.sys
15:18:09.0937 6060  Fdc - ok
15:18:09.0937 6060  [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips            C:\WINDOWS\system32\drivers\Fips.sys
15:18:09.0937 6060  Fips - ok
15:18:10.0000 6060  [ F76D04F7413B07DAA029F6520B64B4E8 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
15:18:10.0015 6060  FLEXnet Licensing Service - ok
15:18:10.0031 6060  [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk        C:\WINDOWS\system32\drivers\Flpydisk.sys
15:18:10.0031 6060  Flpydisk - ok
15:18:10.0078 6060  [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr          C:\WINDOWS\system32\DRIVERS\fltMgr.sys
15:18:10.0078 6060  FltMgr - ok
15:18:10.0156 6060  [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
15:18:10.0156 6060  FontCache3.0.0.0 - ok
15:18:10.0171 6060  [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
15:18:10.0171 6060  Fs_Rec - ok
15:18:10.0187 6060  [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk          C:\WINDOWS\system32\DRIVERS\ftdisk.sys
15:18:10.0187 6060  Ftdisk - ok
15:18:10.0203 6060  [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc             C:\WINDOWS\system32\DRIVERS\msgpc.sys
15:18:10.0203 6060  Gpc - ok
15:18:10.0218 6060  [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus        C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
15:18:10.0218 6060  HDAudBus - ok
15:18:10.0359 6060  [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc         C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
15:18:10.0359 6060  helpsvc - ok
15:18:10.0390 6060  [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ         C:\WINDOWS\System32\hidserv.dll
15:18:10.0390 6060  HidServ - ok
15:18:10.0406 6060  [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb          C:\WINDOWS\system32\DRIVERS\hidusb.sys
15:18:10.0406 6060  hidusb - ok
15:18:10.0437 6060  [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc          C:\WINDOWS\System32\kmsvc.dll
15:18:10.0453 6060  hkmsvc - ok
15:18:10.0484 6060  [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn             C:\WINDOWS\system32\DRIVERS\hpn.sys
15:18:10.0484 6060  hpn - ok
15:18:10.0515 6060  [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP            C:\WINDOWS\system32\Drivers\HTTP.sys
15:18:10.0515 6060  HTTP - ok
15:18:10.0546 6060  [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter      C:\WINDOWS\System32\w3ssl.dll
15:18:10.0562 6060  HTTPFilter - ok
15:18:10.0593 6060  [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt         C:\WINDOWS\system32\drivers\i2omgmt.sys
15:18:10.0609 6060  i2omgmt - ok
15:18:10.0656 6060  [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp           C:\WINDOWS\system32\DRIVERS\i2omp.sys
15:18:10.0656 6060  i2omp - ok
15:18:10.0687 6060  [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt        C:\WINDOWS\system32\DRIVERS\i8042prt.sys
15:18:10.0687 6060  i8042prt - ok
15:18:10.0812 6060  [ B2768350BB50469AEB1AFE694372B613 ] ialm            C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
15:18:10.0890 6060  ialm - ok
15:18:10.0984 6060  [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc           C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:18:11.0000 6060  idsvc - ok
15:18:11.0203 6060  [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86        C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20130731.001\IDSxpx86.sys
15:18:11.0203 6060  IDSxpx86 - ok
15:18:11.0218 6060  [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi           C:\WINDOWS\system32\DRIVERS\imapi.sys
15:18:11.0218 6060  Imapi - ok
15:18:11.0250 6060  [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService    C:\WINDOWS\system32\imapi.exe
15:18:11.0265 6060  ImapiService - ok
15:18:11.0265 6060  [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u         C:\WINDOWS\system32\DRIVERS\ini910u.sys
15:18:11.0265 6060  ini910u - ok
15:18:11.0281 6060  [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde        C:\WINDOWS\system32\DRIVERS\intelide.sys
15:18:11.0281 6060  IntelIde - ok
15:18:11.0312 6060  [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm        C:\WINDOWS\system32\DRIVERS\intelppm.sys
15:18:11.0312 6060  intelppm - ok
15:18:11.0406 6060  [ 3DC635B66DD7412E1C9C3A77B8D78F25 ] IntuitUpdateService C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
15:18:11.0406 6060  IntuitUpdateService - ok
15:18:11.0453 6060  [ D9DA7B3117BF5EFF921C0CDED4D58050 ] IntuitUpdateServiceV4 C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
15:18:11.0453 6060  IntuitUpdateServiceV4 - ok
15:18:11.0484 6060  [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw           C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
15:18:11.0484 6060  Ip6Fw - ok
15:18:11.0484 6060  [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
15:18:11.0484 6060  IpFilterDriver - ok
15:18:11.0515 6060  [ B87AB476DCF76E72010632B5550955F5 ] IpInIp          C:\WINDOWS\system32\DRIVERS\ipinip.sys
15:18:11.0515 6060  IpInIp - ok
15:18:11.0562 6060  [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat           C:\WINDOWS\system32\DRIVERS\ipnat.sys
15:18:11.0562 6060  IpNat - ok
15:18:11.0562 6060  [ 23C74D75E36E7158768DD63D92789A91 ] IPSec           C:\WINDOWS\system32\DRIVERS\ipsec.sys
15:18:11.0578 6060  IPSec - ok
15:18:11.0593 6060  [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM          C:\WINDOWS\system32\DRIVERS\irenum.sys
15:18:11.0593 6060  IRENUM - ok
15:18:11.0640 6060  [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp          C:\WINDOWS\system32\DRIVERS\isapnp.sys
15:18:11.0640 6060  isapnp - ok
15:18:11.0750 6060  [ 9ECF00E19736054E019C532AED8228FC ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
15:18:11.0781 6060  JavaQuickStarterService - ok
15:18:11.0812 6060  [ CB46C36F55CDFE4D20D9833E0F267C84 ] k57w2k          C:\WINDOWS\system32\DRIVERS\k57xp32.sys
15:18:11.0812 6060  k57w2k - ok
15:18:11.0843 6060  [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass        C:\WINDOWS\system32\DRIVERS\kbdclass.sys
15:18:11.0859 6060  Kbdclass - ok
15:18:11.0859 6060  [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid          C:\WINDOWS\system32\DRIVERS\kbdhid.sys
15:18:11.0859 6060  kbdhid - ok
15:18:11.0890 6060  [ 692BCF44383D056AED41B045A323D378 ] kmixer          C:\WINDOWS\system32\drivers\kmixer.sys
15:18:11.0890 6060  kmixer - ok
15:18:11.0953 6060  [ B467646C54CC746128904E1654C750C1 ] KSecDD          C:\WINDOWS\system32\drivers\KSecDD.sys
15:18:11.0968 6060  KSecDD - ok
15:18:12.0015 6060  [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer    C:\WINDOWS\System32\srvsvc.dll
15:18:12.0015 6060  LanmanServer - ok
15:18:12.0046 6060  [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
15:18:12.0046 6060  lanmanworkstation - ok
15:18:12.0046 6060  lbrtfdc - ok
15:18:12.0078 6060  [ A7DB739AE99A796D91580147E919CC59 ] LmHosts         C:\WINDOWS\System32\lmhsvc.dll
15:18:12.0078 6060  LmHosts - ok
15:18:12.0093 6060  [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector   C:\WINDOWS\system32\drivers\mbam.sys
15:18:12.0093 6060  MBAMProtector - ok
15:18:12.0187 6060  [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler   C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
15:18:12.0218 6060  MBAMScheduler - ok
15:18:12.0250 6060  [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService     C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
15:18:12.0296 6060  MBAMService - ok
15:18:12.0312 6060  [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy   C:\WINDOWS\system32\drivers\mbamswissarmy.sys
15:18:12.0312 6060  MBAMSwissArmy - ok
15:18:12.0343 6060  [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger       C:\WINDOWS\System32\msgsvc.dll
15:18:12.0359 6060  Messenger - ok
15:18:12.0390 6060  [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd           C:\WINDOWS\system32\drivers\mnmdd.sys
15:18:12.0421 6060  mnmdd - ok
15:18:12.0437 6060  [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc         C:\WINDOWS\system32\mnmsrvc.exe
15:18:12.0437 6060  mnmsrvc - ok
15:18:12.0453 6060  [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem           C:\WINDOWS\system32\drivers\Modem.sys
15:18:12.0453 6060  Modem - ok
15:18:12.0484 6060  [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass        C:\WINDOWS\system32\DRIVERS\mouclass.sys
15:18:12.0484 6060  Mouclass - ok
15:18:12.0500 6060  [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid          C:\WINDOWS\system32\DRIVERS\mouhid.sys
15:18:12.0500 6060  mouhid - ok
15:18:12.0531 6060  [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr        C:\WINDOWS\system32\drivers\MountMgr.sys
15:18:12.0531 6060  MountMgr - ok
15:18:12.0562 6060  [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x        C:\WINDOWS\system32\DRIVERS\mraid35x.sys
15:18:12.0562 6060  mraid35x - ok
15:18:12.0562 6060  [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV          C:\WINDOWS\system32\DRIVERS\mrxdav.sys
15:18:12.0562 6060  MRxDAV - ok
15:18:12.0781 6060  [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
15:18:12.0796 6060  MRxSmb - ok
15:18:12.0875 6060  [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC           C:\WINDOWS\system32\msdtc.exe
15:18:12.0875 6060  MSDTC - ok
15:18:12.0890 6060  [ C941EA2454BA8350021D774DAF0F1027 ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
15:18:12.0890 6060  Msfs - ok
15:18:12.0890 6060  MSIServer - ok
15:18:12.0921 6060  [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV         C:\WINDOWS\system32\drivers\MSKSSRV.sys
15:18:12.0921 6060  MSKSSRV - ok
15:18:12.0984 6060  [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
15:18:12.0984 6060  MSPCLOCK - ok
15:18:13.0031 6060  [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM           C:\WINDOWS\system32\drivers\MSPQM.sys
15:18:13.0031 6060  MSPQM - ok
15:18:13.0046 6060  [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios        C:\WINDOWS\system32\DRIVERS\mssmbios.sys
15:18:13.0046 6060  mssmbios - ok
15:18:13.0062 6060  [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup             C:\WINDOWS\system32\drivers\Mup.sys
15:18:13.0078 6060  Mup - ok
15:18:13.0109 6060  [ 0102140028FAD045756796E1C685D695 ] napagent        C:\WINDOWS\System32\qagentrt.dll
15:18:13.0125 6060  napagent - ok
15:18:13.0250 6060  [ CE2156DF796D41614AB60E68D107D573 ] NAVENG          C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130801.004\NAVENG.SYS
15:18:13.0250 6060  NAVENG - ok
15:18:13.0296 6060  [ 19CEB8F4EC8C800A53D0B67E658E0367 ] NAVEX15         C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20130801.004\NAVEX15.SYS
15:18:13.0328 6060  NAVEX15 - ok
15:18:13.0375 6060  [ 1DF7F42665C94B825322FAE71721130D ] NDIS            C:\WINDOWS\system32\drivers\NDIS.sys
15:18:13.0375 6060  NDIS - ok
15:18:13.0421 6060  [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:18:13.0421 6060  NdisTapi - ok
15:18:13.0437 6060  [ F927A4434C5028758A842943EF1A3849 ] Ndisuio         C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:18:13.0437 6060  Ndisuio - ok
15:18:13.0437 6060  [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan         C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:18:13.0453 6060  NdisWan - ok
15:18:13.0484 6060  [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy         C:\WINDOWS\system32\drivers\NDProxy.sys
15:18:13.0500 6060  NDProxy - ok
15:18:13.0531 6060  [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS         C:\WINDOWS\system32\DRIVERS\netbios.sys
15:18:13.0531 6060  NetBIOS - ok
15:18:13.0562 6060  [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
15:18:13.0562 6060  NetBT - ok
15:18:13.0609 6060  [ B857BA82860D7FF85AE29B095645563B ] NetDDE          C:\WINDOWS\system32\netdde.exe
15:18:13.0609 6060  NetDDE - ok
15:18:13.0609 6060  [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm      C:\WINDOWS\system32\netdde.exe
15:18:13.0609 6060  NetDDEdsdm - ok
15:18:13.0656 6060  [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon        C:\WINDOWS\system32\lsass.exe
15:18:13.0656 6060  Netlogon - ok
15:18:13.0687 6060  [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman          C:\WINDOWS\System32\netman.dll
15:18:13.0687 6060  Netman - ok
15:18:13.0750 6060  [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:18:13.0765 6060  NetTcpPortSharing - ok
15:18:13.0843 6060  [ 943337D786A56729263071623BBB9DE5 ] Nla             C:\WINDOWS\System32\mswsock.dll
15:18:13.0859 6060  Nla - ok
15:18:13.0984 6060  [ 64C89DB40949FD0E7C8FF303676A91F1 ] Norton Internet Security C:\Program Files\Norton Internet Security\Engine\16.8.3.6\ccSvcHst.exe
15:18:13.0984 6060  Norton Internet Security - ok
15:18:14.0031 6060  [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
15:18:14.0031 6060  Npfs - ok
15:18:14.0093 6060  [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
15:18:14.0109 6060  Ntfs - ok
15:18:14.0140 6060  [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp         C:\WINDOWS\system32\lsass.exe
15:18:14.0140 6060  NtLmSsp - ok
15:18:14.0187 6060  [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc         C:\WINDOWS\system32\ntmssvc.dll
15:18:14.0218 6060  NtmsSvc - ok
15:18:14.0250 6060  [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr        C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
15:18:14.0250 6060  NuidFltr - ok
15:18:14.0296 6060  [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null            C:\WINDOWS\system32\drivers\Null.sys
15:18:14.0312 6060  Null - ok
15:18:14.0328 6060  [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt        C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
15:18:14.0328 6060  NwlnkFlt - ok
15:18:14.0328 6060  [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd        C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
15:18:14.0328 6060  NwlnkFwd - ok
15:18:14.0484 6060  [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv          C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:18:14.0484 6060  odserv - ok
15:18:14.0531 6060  [ 5A432A042DAE460ABE7199B758E8606C ] ose             C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:18:14.0531 6060  ose - ok
15:18:14.0578 6060  [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport         C:\WINDOWS\system32\DRIVERS\parport.sys
15:18:14.0578 6060  Parport - ok
15:18:14.0593 6060  [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr         C:\WINDOWS\system32\drivers\PartMgr.sys
15:18:14.0593 6060  PartMgr - ok
15:18:14.0625 6060  [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm          C:\WINDOWS\system32\drivers\ParVdm.sys
15:18:14.0625 6060  ParVdm - ok
15:18:14.0656 6060  [ A219903CCF74233761D92BEF471A07B1 ] PCI             C:\WINDOWS\system32\DRIVERS\pci.sys
15:18:14.0656 6060  PCI - ok
15:18:14.0656 6060  PCIDump - ok
15:18:14.0656 6060  [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde          C:\WINDOWS\system32\DRIVERS\pciide.sys
15:18:14.0656 6060  PCIIde - ok
15:18:14.0656 6060  [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia          C:\WINDOWS\system32\drivers\Pcmcia.sys
15:18:14.0671 6060  Pcmcia - ok
15:18:14.0671 6060  PDCOMP - ok
15:18:14.0671 6060  PDFRAME - ok
15:18:14.0671 6060  PDRELI - ok
15:18:14.0687 6060  PDRFRAME - ok
15:18:14.0703 6060  [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2           C:\WINDOWS\system32\DRIVERS\perc2.sys
15:18:14.0703 6060  perc2 - ok
15:18:14.0703 6060  [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib        C:\WINDOWS\system32\DRIVERS\perc2hib.sys
15:18:14.0703 6060  perc2hib - ok
15:18:14.0718 6060  [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay        C:\WINDOWS\system32\services.exe
15:18:14.0718 6060  PlugPlay - ok
15:18:14.0765 6060  [ CF7C1868B90C90A265FC3F60CE46265B ] Point32         C:\WINDOWS\system32\DRIVERS\point32.sys
15:18:14.0765 6060  Point32 - ok
15:18:14.0781 6060  [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent     C:\WINDOWS\system32\lsass.exe
15:18:14.0781 6060  PolicyAgent - ok
15:18:14.0781 6060  [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport    C:\WINDOWS\system32\DRIVERS\raspptp.sys
15:18:14.0781 6060  PptpMiniport - ok
15:18:14.0796 6060  [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
15:18:14.0796 6060  ProtectedStorage - ok
15:18:14.0796 6060  [ 09298EC810B07E5D582CB3A3F9255424 ] PSched          C:\WINDOWS\system32\DRIVERS\psched.sys
15:18:14.0796 6060  PSched - ok
15:18:14.0812 6060  [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink         C:\WINDOWS\system32\DRIVERS\ptilink.sys
15:18:14.0812 6060  Ptilink - ok
15:18:14.0828 6060  [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080          C:\WINDOWS\system32\DRIVERS\ql1080.sys
15:18:14.0828 6060  ql1080 - ok
15:18:14.0828 6060  [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt         C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
15:18:14.0828 6060  Ql10wnt - ok
15:18:14.0843 6060  [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160         C:\WINDOWS\system32\DRIVERS\ql12160.sys
15:18:14.0843 6060  ql12160 - ok
15:18:14.0843 6060  [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240          C:\WINDOWS\system32\DRIVERS\ql1240.sys
15:18:14.0843 6060  ql1240 - ok
15:18:14.0859 6060  [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280          C:\WINDOWS\system32\DRIVERS\ql1280.sys
15:18:14.0859 6060  ql1280 - ok
15:18:14.0875 6060  [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:18:14.0875 6060  RasAcd - ok
15:18:14.0906 6060  [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
15:18:14.0921 6060  RasAuto - ok
15:18:14.0937 6060  [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp         C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
15:18:14.0937 6060  Rasl2tp - ok
15:18:14.0953 6060  [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan          C:\WINDOWS\System32\rasmans.dll
15:18:14.0953 6060  RasMan - ok
15:18:14.0968 6060  [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:18:14.0968 6060  RasPppoe - ok
15:18:14.0968 6060  [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti          C:\WINDOWS\system32\DRIVERS\raspti.sys
15:18:14.0968 6060  Raspti - ok
15:18:15.0015 6060  [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:18:15.0015 6060  Rdbss - ok
15:18:15.0031 6060  [ 4912D5B403614CE99C28420F75353332 ] RDPCDD          C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
15:18:15.0031 6060  RDPCDD - ok
15:18:15.0046 6060  [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr           C:\WINDOWS\system32\DRIVERS\rdpdr.sys
15:18:15.0062 6060  rdpdr - ok
15:18:15.0093 6060  [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD           C:\WINDOWS\system32\drivers\RDPWD.sys
15:18:15.0125 6060  RDPWD - ok
15:18:15.0171 6060  [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr       C:\WINDOWS\system32\sessmgr.exe
15:18:15.0171 6060  RDSessMgr - ok
15:18:15.0203 6060  [ F828DD7E1419B6653894A8F97A0094C5 ] redbook         C:\WINDOWS\system32\DRIVERS\redbook.sys
15:18:15.0203 6060  redbook - ok
15:18:15.0250 6060  [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
15:18:15.0265 6060  RemoteAccess - ok
15:18:15.0281 6060  [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
15:18:15.0281 6060  RemoteRegistry - ok
15:18:15.0312 6060  [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator      C:\WINDOWS\system32\locator.exe
15:18:15.0312 6060  RpcLocator - ok
15:18:15.0343 6060  [ 6B27A5C03DFB94B4245739065431322C ] RpcSs           C:\WINDOWS\system32\rpcss.dll
15:18:15.0343 6060  RpcSs - ok
15:18:15.0390 6060  [ 743D7D59767073A617B1DCC6C546F234 ] rspndr          C:\WINDOWS\system32\DRIVERS\rspndr.sys
15:18:15.0390 6060  rspndr - ok
15:18:15.0406 6060  [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP            C:\WINDOWS\system32\rsvp.exe
15:18:15.0406 6060  RSVP - ok
15:18:15.0421 6060  [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs           C:\WINDOWS\system32\lsass.exe
15:18:15.0421 6060  SamSs - ok
15:18:15.0437 6060  [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr        C:\WINDOWS\System32\SCardSvr.exe
15:18:15.0437 6060  SCardSvr - ok
15:18:15.0468 6060  [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule        C:\WINDOWS\system32\schedsvc.dll
15:18:15.0468 6060  Schedule - ok
15:18:15.0531 6060  [ 58DC20EB15F071804C56FCCC796417A2 ] SeaPort         C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
15:18:15.0531 6060  SeaPort - ok
15:18:15.0578 6060  [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv          C:\WINDOWS\system32\DRIVERS\secdrv.sys
15:18:15.0578 6060  Secdrv - ok
15:18:15.0578 6060  [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon        C:\WINDOWS\System32\seclogon.dll
15:18:15.0593 6060  seclogon - ok
15:18:15.0593 6060  [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS            C:\WINDOWS\system32\sens.dll
15:18:15.0609 6060  SENS - ok
15:18:15.0609 6060  [ 0F29512CCD6BEAD730039FB4BD2C85CE ] Serenum         C:\WINDOWS\system32\DRIVERS\serenum.sys
15:18:15.0625 6060  Serenum - ok
15:18:15.0625 6060  [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial          C:\WINDOWS\system32\DRIVERS\serial.sys
15:18:15.0625 6060  Serial - ok
15:18:15.0687 6060  [ B6401608579B6431994425BA7653F774 ] SFAUDIO         C:\WINDOWS\system32\drivers\sfaudio.sys
15:18:15.0687 6060  SFAUDIO - ok
15:18:15.0734 6060  [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy         C:\WINDOWS\system32\drivers\Sfloppy.sys
15:18:15.0750 6060  Sfloppy - ok
15:18:15.0796 6060  [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
15:18:15.0796 6060  SharedAccess - ok
15:18:15.0812 6060  [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
15:18:15.0812 6060  ShellHWDetection - ok
15:18:15.0812 6060  Simbad - ok
15:18:15.0828 6060  [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp          C:\WINDOWS\system32\DRIVERS\sisagp.sys
15:18:15.0828 6060  sisagp - ok
15:18:15.0859 6060  [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow         C:\WINDOWS\system32\DRIVERS\sparrow.sys
15:18:15.0859 6060  Sparrow - ok
15:18:15.0890 6060  [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter        C:\WINDOWS\system32\drivers\splitter.sys
15:18:15.0890 6060  splitter - ok
15:18:15.0937 6060  [ 60784F891563FB1B767F70117FC2428F ] Spooler         C:\WINDOWS\system32\spoolsv.exe
15:18:15.0937 6060  Spooler - ok
15:18:16.0000 6060  [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr              C:\WINDOWS\system32\DRIVERS\sr.sys
15:18:16.0015 6060  sr - ok
15:18:16.0109 6060  [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice       C:\WINDOWS\system32\srsvc.dll
15:18:16.0156 6060  srservice - ok
15:18:16.0234 6060  [ E81F6CAEAB9AD5732E94C07C97866AA2 ] SRTSP           C:\WINDOWS\System32\Drivers\NIS\1008030.006\SRTSP.SYS
15:18:16.0234 6060  SRTSP - ok
15:18:16.0265 6060  [ E28DE499D942B08058BFFAC69D4122B6 ] SRTSPX          C:\WINDOWS\system32\drivers\NIS\1008030.006\SRTSPX.SYS
15:18:16.0265 6060  SRTSPX - ok
15:18:16.0312 6060  [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv             C:\WINDOWS\system32\DRIVERS\srv.sys
15:18:16.0328 6060  Srv - ok
15:18:16.0343 6060  [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
15:18:16.0343 6060  SSDPSRV - ok
15:18:16.0375 6060  [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc          C:\WINDOWS\system32\wiaservc.dll
15:18:16.0375 6060  stisvc - ok
15:18:16.0406 6060  [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum          C:\WINDOWS\system32\DRIVERS\swenum.sys
15:18:16.0406 6060  swenum - ok
15:18:16.0421 6060  [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi          C:\WINDOWS\system32\drivers\swmidi.sys
15:18:16.0421 6060  swmidi - ok
15:18:16.0421 6060  SwPrv - ok
15:18:16.0453 6060  [ 1FF3217614018630D0A6758630FC698C ] symc810         C:\WINDOWS\system32\DRIVERS\symc810.sys
15:18:16.0453 6060  symc810 - ok
15:18:16.0484 6060  [ 070E001D95CF725186EF8B20335F933C ] symc8xx         C:\WINDOWS\system32\DRIVERS\symc8xx.sys
15:18:16.0484 6060  symc8xx - ok
15:18:16.0484 6060  SYMDNS - ok
15:18:16.0609 6060  [ D0885F6E24259A6C65E68D6AD749910A ] SymEFA          C:\WINDOWS\system32\drivers\NIS\1008030.006\SYMEFA.SYS
15:18:16.0609 6060  SymEFA - ok
15:18:16.0671 6060  [ A54FF04BD6E75DC4D8CB6F3E352635E0 ] SymEvent        C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
15:18:16.0718 6060  SymEvent - ok
15:18:16.0734 6060  [ A8C45C36309EE066F9191E511F88ED76 ] SYMFW           C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMFW.SYS
15:18:16.0750 6060  SYMFW - ok
15:18:16.0781 6060  [ F4DB00BC0C25BE3E05D4BBB8637CC3A3 ] SYMIDS          C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMIDS.SYS
15:18:16.0781 6060  SYMIDS - ok
15:18:16.0812 6060  [ C6DB9F873B09C63F5CB1DE10C08BF6F9 ] SymIM           C:\WINDOWS\system32\DRIVERS\SymIM.sys
15:18:16.0812 6060  SymIM - ok
15:18:16.0812 6060  [ C6DB9F873B09C63F5CB1DE10C08BF6F9 ] SymIMMP         C:\WINDOWS\system32\DRIVERS\SymIM.sys
15:18:16.0812 6060  SymIMMP - ok
15:18:16.0828 6060  [ 06A8ECFC68D61A26A67F0E96FF1CA9CC ] SYMNDIS         C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMNDIS.SYS
15:18:16.0828 6060  SYMNDIS - ok
15:18:16.0828 6060  SYMREDRV - ok
15:18:16.0875 6060  [ 26BC80EC79D7BA478249C266CBDF17B4 ] SYMTDI          C:\WINDOWS\System32\Drivers\NIS\1008030.006\SYMTDI.SYS
15:18:16.0875 6060  SYMTDI - ok
15:18:16.0890 6060  [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi          C:\WINDOWS\system32\DRIVERS\sym_hi.sys
15:18:16.0890 6060  sym_hi - ok
15:18:16.0906 6060  [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3          C:\WINDOWS\system32\DRIVERS\sym_u3.sys
15:18:16.0906 6060  sym_u3 - ok
15:18:16.0937 6060  [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio        C:\WINDOWS\system32\drivers\sysaudio.sys
15:18:16.0937 6060  sysaudio - ok
15:18:17.0000 6060  [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog       C:\WINDOWS\system32\smlogsvc.exe
15:18:17.0015 6060  SysmonLog - ok
15:18:17.0062 6060  [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
15:18:17.0078 6060  TapiSrv - ok
15:18:17.0109 6060  [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip           C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:18:17.0125 6060  Tcpip - ok
15:18:17.0140 6060  [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE          C:\WINDOWS\system32\drivers\TDPIPE.sys
15:18:17.0156 6060  TDPIPE - ok
15:18:17.0171 6060  [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP           C:\WINDOWS\system32\drivers\TDTCP.sys
15:18:17.0171 6060  TDTCP - ok
15:18:17.0187 6060  [ 88155247177638048422893737429D9E ] TermDD          C:\WINDOWS\system32\DRIVERS\termdd.sys
15:18:17.0187 6060  TermDD - ok
15:18:17.0234 6060  [ FF3477C03BE7201C294C35F684B3479F ] TermService     C:\WINDOWS\System32\termsrv.dll
15:18:17.0234 6060  TermService - ok
15:18:17.0250 6060  [ 99BC0B50F511924348BE19C7C7313BBF ] Themes          C:\WINDOWS\System32\shsvcs.dll
15:18:17.0250 6060  Themes - ok
15:18:17.0250 6060  [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr         C:\WINDOWS\system32\tlntsvr.exe
15:18:17.0265 6060  TlntSvr - ok
15:18:17.0281 6060  [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde          C:\WINDOWS\system32\DRIVERS\toside.sys
15:18:17.0281 6060  TosIde - ok
15:18:17.0296 6060  [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks          C:\WINDOWS\system32\trkwks.dll
15:18:17.0296 6060  TrkWks - ok
15:18:17.0328 6060  [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs            C:\WINDOWS\system32\drivers\Udfs.sys
15:18:17.0328 6060  Udfs - ok
15:18:17.0375 6060  [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra           C:\WINDOWS\system32\DRIVERS\ultra.sys
15:18:17.0375 6060  ultra - ok
15:18:17.0390 6060  [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update          C:\WINDOWS\system32\DRIVERS\update.sys
15:18:17.0390 6060  Update - ok
15:18:17.0421 6060  [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost        C:\WINDOWS\System32\upnphost.dll
15:18:17.0421 6060  upnphost - ok
15:18:17.0437 6060  [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS             C:\WINDOWS\System32\ups.exe
15:18:17.0453 6060  UPS - ok
15:18:17.0484 6060  [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp         C:\WINDOWS\system32\DRIVERS\usbccgp.sys
15:18:17.0484 6060  usbccgp - ok
15:18:17.0500 6060  [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci         C:\WINDOWS\system32\DRIVERS\usbehci.sys
15:18:17.0500 6060  usbehci - ok
15:18:17.0546 6060  [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub          C:\WINDOWS\system32\DRIVERS\usbhub.sys
15:18:17.0546 6060  usbhub - ok
15:18:17.0578 6060  [ A717C8721046828520C9EDF31288FC00 ] usbprint        C:\WINDOWS\system32\DRIVERS\usbprint.sys
15:18:17.0578 6060  usbprint - ok
15:18:17.0609 6060  [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR         C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:18:17.0609 6060  USBSTOR - ok
15:18:17.0609 6060  [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci         C:\WINDOWS\system32\DRIVERS\usbuhci.sys
15:18:17.0609 6060  usbuhci - ok
15:18:17.0671 6060  [ 2A7A8AD9D39A2FAF9D9293B5DAFF3A4B ] USB_RNDIS_XP    C:\WINDOWS\system32\DRIVERS\usb8023.sys
15:18:17.0671 6060  USB_RNDIS_XP - ok
15:18:17.0671 6060  [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave         C:\WINDOWS\System32\drivers\vga.sys
15:18:17.0671 6060  VgaSave - ok
15:18:17.0687 6060  [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp          C:\WINDOWS\system32\DRIVERS\viaagp.sys
15:18:17.0687 6060  viaagp - ok
15:18:17.0687 6060  [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde          C:\WINDOWS\system32\DRIVERS\viaide.sys
15:18:17.0687 6060  ViaIde - ok
15:18:17.0718 6060  [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap         C:\WINDOWS\system32\drivers\VolSnap.sys
15:18:17.0718 6060  VolSnap - ok
15:18:17.0765 6060  [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS             C:\WINDOWS\System32\vssvc.exe
15:18:17.0765 6060  VSS - ok
15:18:17.0781 6060  [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time         C:\WINDOWS\system32\w32time.dll
15:18:17.0781 6060  w32time - ok
15:18:17.0796 6060  [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp          C:\WINDOWS\system32\DRIVERS\wanarp.sys
15:18:17.0796 6060  Wanarp - ok
15:18:17.0828 6060  [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000        C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
15:18:17.0828 6060  Wdf01000 - ok
15:18:17.0828 6060  WDICA - ok
15:18:17.0843 6060  [ 6768ACF64B18196494413695F0C3A00F ] wdmaud          C:\WINDOWS\system32\drivers\wdmaud.sys
15:18:17.0859 6060  wdmaud - ok
15:18:17.0859 6060  [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient       C:\WINDOWS\System32\webclnt.dll
15:18:17.0875 6060  WebClient - ok
15:18:17.0968 6060  [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
15:18:17.0968 6060  winmgmt - ok
15:18:18.0031 6060  [ C7E39EA41233E9F5B86C8DA3A9F1E4A8 ] WmdmPmSN        C:\WINDOWS\system32\mspmsnsv.dll
15:18:18.0046 6060  WmdmPmSN - ok
15:18:18.0093 6060  [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi             C:\WINDOWS\System32\advapi32.dll
15:18:18.0109 6060  Wmi - ok
15:18:18.0171 6060  [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv        C:\WINDOWS\system32\wbem\wmiapsrv.exe
15:18:18.0171 6060  WmiApSrv - ok
15:18:18.0265 6060  [ B800EEC15851597405784126C407188C ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
15:18:18.0281 6060  WPFFontCache_v0400 - ok
15:18:18.0328 6060  [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc          C:\WINDOWS\system32\wscsvc.dll
15:18:18.0328 6060  wscsvc - ok
15:18:18.0343 6060  WSearch - ok
15:18:18.0390 6060  [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv        C:\WINDOWS\system32\wuauserv.dll
15:18:18.0390 6060  wuauserv - ok
15:18:18.0453 6060  [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC          C:\WINDOWS\System32\wzcsvc.dll
15:18:18.0453 6060  WZCSVC - ok
15:18:18.0484 6060  [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov         C:\WINDOWS\System32\xmlprov.dll
15:18:18.0593 6060  xmlprov - ok
15:18:18.0593 6060  ================ Scan global ===============================
15:18:18.0656 6060  [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:18:18.0687 6060  [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
15:18:18.0687 6060  [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
15:18:18.0703 6060  [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:18:18.0718 6060  [Global] - ok
15:18:18.0718 6060  ================ Scan MBR ==================================
15:18:18.0734 6060  [ CDB4DE4BBD714F152979DA2DCBEF57EB ] \Device\Harddisk0\DR0
15:18:19.0093 6060  \Device\Harddisk0\DR0 - ok
15:18:19.0093 6060  ================ Scan VBR ==================================
15:18:19.0093 6060  [ 1717F10AD3F9BA21D6EF6E67813B0927 ] \Device\Harddisk0\DR0\Partition1
15:18:19.0093 6060  \Device\Harddisk0\DR0\Partition1 - ok
15:18:19.0093 6060  ============================================================
15:18:19.0093 6060  Scan finished
15:18:19.0093 6060  ============================================================
15:18:19.0093 5608  Detected object count: 0
15:18:19.0093 5608  Actual detected object count: 0

 

******************************************************************************

*ESET Log*

C:\Documents and Settings\mark360\Local Settings\Temp\toxhoptf\toxhoptf.dll    Win32/TrojanDownloader.Tracur.V trojan
C:\Documents and Settings\mark360\My Documents\Downloads\cbsidlm-tr1_10a-SiteSpinner_Pro-SEO-10905635.exe    Win32/DownloadAdmin.G application
C:\Documents and Settings\mark360\My Documents\Downloads\winscp433setup.exe    Win32/OpenCandy application
 



#4 GodfatherKing

GodfatherKing

  • Members
  • 587 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:39 PM

Posted 02 August 2013 - 02:33 AM

:step1: Download TFC from the download link above and save the file on your desktop.

 
Note 1: Depending on how much data is currently stored in the Temp folders, this process can take quite a while to remove all of the files, so please be patient.
 
Note 2: This program will not delete your Cookies or Browser History.
 
  • Close ALL running applications as TFC will terminate them before attempting to clean up the temporary files.
  • Double-click on the TFC icon.
  • When the program starts, click on the Start button.  TFC will terminate the Explorer process and all running applications and then begin the process of cleaning out all of your temp folders.
  • When done, press OK to reboot your computer and finish the cleanup.

 

The program normally force a reboot.

 

:step2: Remove the found infections (some may be already gone by TFC) and clean then the recycle bin.

 

C:\Documents and Settings\mark360\Local Settings\Temp\toxhoptf\toxhoptf.dll    Win32/TrojanDownloader.Tracur.V trojan
C:\Documents and Settings\mark360\My Documents\Downloads\cbsidlm-tr1_10a-SiteSpinner_Pro-SEO-10905635.exe    Win32/DownloadAdmin.G application
C:\Documents and Settings\mark360\My Documents\Downloads\winscp433setup.exe    Win32/OpenCandy application


If you have received help from me and I don't have respond to you for almost >= 3 days, send me a Private Message.  :hello:





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users