Jump to content

206.161.121.3 & 94.102.51.238


Recommended Posts

I'm getting MBAM realtime blocking to the IPs listed in the topic. MBAM detects nothing, ESET online detected 3 instances of MyWebSearch which were removed, TDSSKiller won't run regardless of name or extension (tried .com) and Google redirects to ad pages in multiple browsers (IE and Chrome for example).

.

DDS (Ver_2011-08-26.01) - NTFSAMD64

Internet Explorer: 9.0.8112.16421

Run by Finance Manager at 13:43:42 on 2012-08-03

Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3993.1767 [GMT -4:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}

.

============== Running Processes ===============

.

C:\Windows\system32\wininit.exe

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

c:\Program Files\Microsoft Security Client\MsMpEng.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\System32\spoolsv.exe

C:\Windows\System32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Program Files\Common Files\SPBA\upeksvr.exe

C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE

C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe

C:\Windows\system32\taskhost.exe

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe

C:\OPTI-SAFE Sentinel for Windows\Sentinel_Service.Exe

C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe

C:\Windows\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\OPTI-SAFE Sentinel for Windows\UPSInt2.exe

C:\Windows\system32\conhost.exe

C:\Windows\system32\wbem\unsecapp.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\System32\igfxtray.exe

C:\Windows\System32\hkcmd.exe

C:\Windows\System32\igfxpers.exe

C:\dell\DBRM\Reminder\DbrmTrayicon.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe

C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe

C:\OPTI-SAFE Sentinel for Windows\Sentinel.exe

C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe

C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe

C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe

C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe

C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe

C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe

C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

C:\Program Files (x86)\Browny02\BrYNSvc.exe

C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe

C:\Windows\system32\SearchIndexer.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe

C:\Users\FINANC~1\AppData\Local\Temp\HouseCall\housecall.bin

C:\Windows\system32\taskhost.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

C:\Windows\system32\igfxsrvc.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\DllHost.exe

C:\Windows\system32\REGSVR32.exe

C:\Windows\SysWOW64\cmd.exe

C:\Windows\system32\conhost.exe

C:\Windows\SysWOW64\cscript.exe

.

============== Pseudo HJT Report ===============

.

uSearch Bar = Preserve

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: TmIEPlugInBHO Class: {1ca1377b-dc1d-4a52-9585-6e06050fac53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll

BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll

BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"

mRun: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"

mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"

mRun: [sentinel] C:\OPTI-SAFE Sentinel for Windows\Sentinel.exe

mRun: [brMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

mRun: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun: [indexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"

mRun: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"

mRun: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"

mRun: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe

mRun: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe

mRun: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun

mRun: [brStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

mPolicies-explorer: NoActiveDesktop = 1 (0x1)

mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)

mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)

mPolicies-system: EnableUIADesktopToggle = 0 (0x0)

mPolicies-system: DisableCAD = 1 (0x1)

IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll

IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll

Trusted Zone: jmagroup.com

Trusted Zone: jmagroup.com\dealer

Trusted Zone: jmfamily.com

DPF: Launcher - hxxp://dealer.alp.jmagroup.com/jmfsdpweb/Content/cabs/launcher.cab

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{2A7C4B1B-1871-4007-98CF-874C8F4F62E2} : DhcpNameServer = 192.168.1.1

Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL

Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} -

Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll

IFEO: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect

BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO-X64: AcroIEHelperStub - No File

BHO-X64: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - c:\Program Files (x86)\Trend Micro\Client Server Security Agent\bho\1009\TmIEPlg32.dll

BHO-X64: Trend Micro NSC BHO - No File

BHO-X64: PlusIEEventHelper Class: {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll

BHO-X64: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll

BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll

BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL

BHO-X64: URLRedirectionBHO - No File

BHO-X64: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

TB-X64: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll"

TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

mRun-x64: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe"

mRun-x64: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe"

mRun-x64: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"

mRun-x64: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"

mRun-x64: [sentinel] C:\OPTI-SAFE Sentinel for Windows\Sentinel.exe

mRun-x64: [brMfcWnd] C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN

mRun-x64: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun

mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

mRun-x64: [indexSearch] "C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe"

mRun-x64: [PaperPort PTD] "C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe"

mRun-x64: [PPort12reminder] "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"

mRun-x64: [PDFHook] C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe

mRun-x64: [PDF5 Registry Controller] C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe

mRun-x64: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun

mRun-x64: [brStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN

mRun-x64: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

mRunOnce-x64: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

IFEO-X64: ehshell.exe - "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect

.

============= SERVICES / DRIVERS ===============

.

R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]

R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]

R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-1-3 63928]

R2 BBUpdate;BBUpdate;C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE [2011-5-12 249648]

R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2012-6-19 173056]

R2 jhi_service;Intel® Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-2-24 212944]

R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2011-9-26 375208]

R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files (x86)\LogMeIn\x64\rainfo.sys [2011-9-16 15928]

R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\Windows\system32\drivers\LMIRfsDriver.sys --> C:\Windows\system32\drivers\LMIRfsDriver.sys [?]

R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-1 655944]

R2 PDFProFiltSrvPP;PDFProFiltSrvPP;C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-3-9 144672]

R2 SentinelService;SentinelService;C:\OPTI-SAFE Sentinel for Windows\Sentinel_Service.exe [2011-11-16 375296]

R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-11-3 2656280]

R3 BrSerIb;Brother MFC Serial Interface Driver(WDM);C:\Windows\system32\DRIVERS\BrSerIb.sys --> C:\Windows\system32\DRIVERS\BrSerIb.sys [?]

R3 BrUsbSIb;Brother MFC Serial USB Driver(WDM);C:\Windows\system32\DRIVERS\BrUsbSIb.sys --> C:\Windows\system32\DRIVERS\BrUsbSIb.sys [?]

R3 BrYNSvc;BrYNSvc;C:\Program Files (x86)\Browny02\BrYNSvc.exe [2011-12-1 245760]

R3 IntcDAud;Intel® Display Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys --> C:\Windows\system32\DRIVERS\IntcDAud.sys [?]

R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]

R3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys --> C:\Windows\system32\DRIVERS\HECIx64.sys [?]

R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]

R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-24 136176]

S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-11-25 219632]

S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-5-10 250056]

S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-6-7 191752]

S3 dmvsc;dmvsc;C:\Windows\system32\drivers\dmvsc.sys --> C:\Windows\system32\drivers\dmvsc.sys [?]

S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]

S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]

S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-7-24 136176]

S3 netvsc;netvsc;C:\Windows\system32\DRIVERS\netvsc60.sys --> C:\Windows\system32\DRIVERS\netvsc60.sys [?]

S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]

S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]

S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-11-25 1116656]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]

S3 SynthVid;SynthVid;C:\Windows\system32\DRIVERS\VMBusVideoM.sys --> C:\Windows\system32\DRIVERS\VMBusVideoM.sys [?]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]

S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]

.

=============== Created Last 30 ================

.

2012-08-03 16:26:06 -------- d-----w- C:\Program Files (x86)\ESET

2012-08-03 15:37:12 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys

2012-08-03 14:54:36 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B8929D4E-2D00-44E2-9879-47FE7AD7960F}\mpengine.dll

2012-08-02 14:53:27 9133488 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll

2012-08-01 16:31:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware

2012-07-24 19:03:09 -------- d-----w- C:\Windows\System32\appmgmt

2012-07-24 18:07:56 -------- d-----w- C:\Users\Finance Manager\AppData\Local\Google

2012-07-18 18:12:58 -------- d-----w- C:\$RECYCLE.BIN

2012-07-18 17:31:22 -------- d-----w- C:\ComboFix

2012-07-18 16:57:40 3148800 ----a-w- C:\Windows\System32\win32k.sys

2012-07-18 16:55:45 2004480 ----a-w- C:\Windows\System32\msxml6.dll

2012-07-18 16:55:45 1881600 ----a-w- C:\Windows\System32\msxml3.dll

2012-07-18 16:55:45 1390080 ----a-w- C:\Windows\SysWow64\msxml6.dll

2012-07-18 16:55:44 2048 ----a-w- C:\Windows\SysWow64\msxml3r.dll

2012-07-18 16:55:44 2048 ----a-w- C:\Windows\System32\msxml3r.dll

2012-07-18 16:55:44 1236992 ----a-w- C:\Windows\SysWow64\msxml3.dll

2012-07-18 16:43:12 -------- d-----w- C:\Users\Finance Manager\AppData\Roaming\Roxio Burn

2012-07-18 16:39:44 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2012-07-18 16:39:32 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D1D53D89-5A4A-4C7E-8DEE-91943EE846C3}\gapaengine.dll

2012-07-18 16:39:15 99840 ----a-w- C:\Windows\System32\wudriver.dll

2012-07-18 16:38:46 36864 ----a-w- C:\Windows\System32\wuapp.exe

2012-07-18 16:38:46 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2012-07-17 23:01:40 328704 ----a-w- C:\Windows\System32\services.exe.D8E43AA25CC2B395

.

==================== Find3M ====================

.

2012-08-03 01:51:14 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2012-08-03 01:51:14 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2012-08-03 01:51:04 9827016 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe

2012-07-18 16:36:13 87488 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll

2012-07-18 16:36:12 80800 ----a-w- C:\Windows\System32\LMIinit.dll

2012-07-18 16:36:12 34720 ----a-w- C:\Windows\System32\LMIport.dll

2012-06-25 20:04:24 1394248 ----a-w- C:\Windows\SysWow64\msxml4.dll

2012-06-06 06:02:54 1133568 ----a-w- C:\Windows\System32\cdosys.dll

2012-06-06 05:03:06 805376 ----a-w- C:\Windows\SysWow64\cdosys.dll

2012-06-02 05:50:10 458704 ----a-w- C:\Windows\System32\drivers\cng.sys

2012-06-02 05:48:16 95600 ----a-w- C:\Windows\System32\drivers\ksecdd.sys

2012-06-02 05:48:16 151920 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys

2012-06-02 05:45:31 340992 ----a-w- C:\Windows\System32\schannel.dll

2012-06-02 05:44:21 307200 ----a-w- C:\Windows\System32\ncrypt.dll

2012-06-02 04:40:42 22016 ----a-w- C:\Windows\SysWow64\secur32.dll

2012-06-02 04:40:39 225280 ----a-w- C:\Windows\SysWow64\schannel.dll

2012-06-02 04:39:10 219136 ----a-w- C:\Windows\SysWow64\ncrypt.dll

2012-06-02 04:34:09 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll

2012-05-22 14:51:07 87456 ----a-w- C:\Windows\System32\LMIRfsClientNP.dll.000.bak

.

============= FINISH: 13:52:09.57 ===============

Attach.txt

Link to post
Share on other sites

Welcome to the forum.

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller to your desktop.

For Windows XP, double-click to start.

For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

MrC

Link to post
Share on other sites

RogueKiller V7.6.5 [08/03/2012] by Tigzy

mail: tigzyRK<at>gmail<dot>com

Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/

Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version

Started in : Normal mode

User: Finance Manager [Admin rights]

Mode: Scan -- Date: 08/03/2012 14:18:39

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 8 ¤¤¤

[sUSP PATH] {02CEFDD3-9675-42D9-8CF9-37368F25C23A}.job @ : C:\Users\Finance Manager\AppData\Local\PCAPPS.COM\Mobilizer -> FOUND

[sUSP PATH] {587EA87C-C0F2-4850-88DF-3AFA7326C6CD}.job @ : C:\Users\Finance Manager\Desktop\SmartClientMobilizer.exe -> FOUND

[sUSP PATH] {8DB35515-547C-403D-BC1D-69496409DCBD}.job @ : C:\Users\Finance Manager\Desktop\SmartClientMobilizer.exe -> FOUND

[sUSP PATH] {A25B32C5-742A-44E0-B03C-78B67CC51B27}.job @ : C:\Users\Finance Manager\AppData\Local\PCAPPS.COM\Mobilizer -> FOUND

[sUSP PATH] {E11E4544-9A28-44F1-808D-B99AC74B03A5}.job @ : C:\Users\Finance Manager\AppData\Local\PCAPPS.COM\Mobilizer -> FOUND

[sUSP PATH] {EB74ACF9-A2A6-40E3-9BA6-642971C9A37D}.job @ : C:\Users\Finance Manager\AppData\Local\PCAPPS.COM\Mobilizer -> FOUND

[iFEO] HKLM\[...]\Image File Execution Options : ehshell.exe ("C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" -MceShellRedirect) -> FOUND

[sCRSV] HKCU\[...]\Desktop : SCRNSAVE.EXE (C:\Windows\WLXPGSS.SCR) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : Root.MBR ¤¤¤

¤¤¤ HOSTS File: ¤¤¤

127.0.0.1 localhost

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD5000AAKX-753CA1 ATA Device +++++

--- User ---

[MBR] c55043a33b7786797f45e4ed840a86ac

[bSP] 1f550747e09dbebd5e8b4c76dfeef83c : Windows Vista MBR Code

Partition table:

0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo

1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 16538 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 33951744 | Size: 460352 Mo

User = LL1 ... OK!

User != LL2 ... KO!

--- LL2 ---

[MBR] 07c3bea8dbd43b53d35d56415e09844e

[bSP] 1f550747e09dbebd5e8b4c76dfeef83c : Windows Vista MBR Code

Partition table:

0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo

1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 16538 Mo

2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 33951744 | Size: 460352 Mo

3 - [ACTIVE] NTFS (0x17) [HIDDEN!] Offset (sectors): 976771072 | Size: 1 Mo

Finished : << RKreport[1].txt >>

RKreport[1].txt

Link to post
Share on other sites

Please make sure system restore is running and create a new restore point before continuing.

XP <===> Vista & W7

XP users > please back up the registry using ERUNT.

-----------------------------------------

Please download and run TDSSKiller to your desktop as outlined below:

Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

For Windows XP, double-click to start.

For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

tdss_1.jpg

-------------------------

Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

tdss_2.jpg

------------------------

Click the Start Scan button.

tdss_3.jpg

-----------------------

If a suspicious object is detected, the default action will be Skip, click on Continue

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose

Skip and click on Continue

tdss_4.jpg

----------------------

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

tdss_5.jpg

--------------------

A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.

Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

-------------------

Here's a summary of what to do if you would like to print it out:

If a suspicious object is detected, the default action will be Skip, click on Continue

If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose

Skip and click on Continue

If malicious objects are found, they will show in the Scan results and offer three (3) options.

Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.

Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.

MrC

Link to post
Share on other sites

OK, I forgot you mentioned that, the infection is blocking you from running it.

Try this....

Cut and paste TDSSKiller.exe into Malwarebytes Chameleon folder:

C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon

Install the Chameleon driver by doing the following:

Press the Windows key + R and in the Run box, copy and paste the following command then press Enter.

"%programfiles (x86)\%\Malwarebytes' Anti-Malware\Chameleon/mbam-chameleon.com" /o

A black DOS prompt will appear with a prompt to press any key to continue, please do until the Dos prompt disappears.

Execute TDSSKiller.exe by doubleclicking on it in the Chameleon folder.

See if it runs.

Let me know, MrC

Link to post
Share on other sites

I just tried it. I was excited because you suggested something I hadn't tried before. I copied TDSSKiller.exe, installed the driver and verified that the driver was running because it wouldn't let me delete it. I ran it and same result: nothing comes up after the UAC prompt.

Link to post
Share on other sites

¤¤¤ Infection : Root.MBR ¤¤¤

Your MBR is infected, that's the problem.

-------------------------

When you get done........

For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

How to tell > 32 or 64 bit

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:

  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:

  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:



    • Startup Repair
      System Restore
      Windows Complete PC Restore
      Windows Memory Diagnostic Tool
      Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.

[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]FRST will let you know when the scan is complete and has written the FRST.txt to file, close out this message, then

[*]Type exit and reboot the computer normally

MrC

Link to post
Share on other sites

also be careful, one of these scanners may attempt to fix the mbr and then you'll end up with a computer that won't boot, MrC

That's exactly what happened. BitDefender fixed the MBR and the computer stopped booting, I used TestDisk to fix the partition table and the computer now starts up just fine and runs TDSSKiller.

16:36:26.0714 1788 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32

16:36:27.0083 1788 ============================================================

16:36:27.0083 1788 Current date / time: 2012/08/03 16:36:27.0083

16:36:27.0083 1788 SystemInfo:

16:36:27.0083 1788

16:36:27.0083 1788 OS Version: 6.1.7601 ServicePack: 1.0

16:36:27.0083 1788 Product type: Workstation

16:36:27.0084 1788 ComputerName: FINMGR-PC

16:36:27.0084 1788 UserName: Finance Manager

16:36:27.0084 1788 Windows directory: C:\Windows

16:36:27.0084 1788 System windows directory: C:\Windows

16:36:27.0084 1788 Running under WOW64

16:36:27.0084 1788 Processor architecture: Intel x64

16:36:27.0084 1788 Number of processors: 4

16:36:27.0084 1788 Page size: 0x1000

16:36:27.0084 1788 Boot type: Normal boot

16:36:27.0084 1788 ============================================================

16:36:29.0430 1788 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

16:36:30.0272 1788 Drive \Device\Harddisk1\DR2 - Size: 0x3C7C00000 (15.12 Gb), SectorSize: 0x200, Cylinders: 0x7B5, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'

16:36:30.0284 1788 ============================================================

16:36:30.0284 1788 \Device\Harddisk0\DR0:

16:36:30.0305 1788 MBR partitions:

16:36:30.0305 1788 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x6, StartLBA 0x3F, BlocksNum 0x13986

16:36:30.0305 1788 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x204D000

16:36:30.0305 1788 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2061000, BlocksNum 0x38320800

16:36:30.0346 1788 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x3A385800, BlocksNum 0x1000

16:36:30.0346 1788 \Device\Harddisk1\DR2:

16:36:30.0350 1788 MBR partitions:

16:36:30.0350 1788 \Device\Harddisk1\DR2\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x1E3DFC1

16:36:30.0350 1788 ============================================================

16:36:30.0521 1788 C: <-> \Device\Harddisk0\DR0\Partition2

16:36:30.0526 1788 V: <-> \Device\Harddisk0\DR0\Partition0

16:36:30.0568 1788 ============================================================

16:36:30.0568 1788 Initialize success

16:36:30.0568 1788 ============================================================

16:38:23.0385 2248 ============================================================

16:38:23.0385 2248 Scan started

16:38:23.0385 2248 Mode: Manual; SigCheck; TDLFS;

16:38:23.0385 2248 ============================================================

16:38:24.0715 2248 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys

16:38:24.0885 2248 1394ohci - ok

16:38:24.0919 2248 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys

16:38:24.0937 2248 ACPI - ok

16:38:24.0949 2248 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys

16:38:24.0985 2248 AcpiPmi - ok

16:38:25.0066 2248 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

16:38:25.0091 2248 AdobeARMservice - ok

16:38:25.0182 2248 AdobeFlashPlayerUpdateSvc (f19c98ad81d2c0e1bbfd8153d2c80ee8) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

16:38:25.0237 2248 AdobeFlashPlayerUpdateSvc - ok

16:38:25.0269 2248 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys

16:38:25.0292 2248 adp94xx - ok

16:38:25.0315 2248 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys

16:38:25.0331 2248 adpahci - ok

16:38:25.0348 2248 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys

16:38:25.0362 2248 adpu320 - ok

16:38:25.0386 2248 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll

16:38:25.0434 2248 AeLookupSvc - ok

16:38:25.0475 2248 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys

16:38:25.0531 2248 AFD - ok

16:38:25.0548 2248 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys

16:38:25.0561 2248 agp440 - ok

16:38:25.0573 2248 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe

16:38:25.0588 2248 ALG - ok

16:38:25.0592 2248 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys

16:38:25.0606 2248 aliide - ok

16:38:25.0610 2248 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys

16:38:25.0623 2248 amdide - ok

16:38:25.0637 2248 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys

16:38:25.0655 2248 AmdK8 - ok

16:38:25.0661 2248 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys

16:38:25.0698 2248 AmdPPM - ok

16:38:25.0808 2248 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys

16:38:25.0831 2248 amdsata - ok

16:38:25.0840 2248 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys

16:38:25.0854 2248 amdsbs - ok

16:38:25.0870 2248 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys

16:38:25.0881 2248 amdxata - ok

16:38:25.0886 2248 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys

16:38:25.0937 2248 AppID - ok

16:38:25.0961 2248 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll

16:38:25.0991 2248 AppIDSvc - ok

16:38:26.0013 2248 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll

16:38:26.0063 2248 Appinfo - ok

16:38:26.0096 2248 AppMgmt (4aba3e75a76195a3e38ed2766c962899) C:\Windows\System32\appmgmts.dll

16:38:26.0127 2248 AppMgmt - ok

16:38:26.0132 2248 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys

16:38:26.0153 2248 arc - ok

16:38:26.0176 2248 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys

16:38:26.0206 2248 arcsas - ok

16:38:26.0285 2248 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe

16:38:26.0317 2248 aspnet_state - ok

16:38:26.0326 2248 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys

16:38:26.0375 2248 AsyncMac - ok

16:38:26.0403 2248 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys

16:38:26.0413 2248 atapi - ok

16:38:26.0457 2248 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll

16:38:26.0518 2248 AudioEndpointBuilder - ok

16:38:26.0524 2248 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll

16:38:26.0558 2248 AudioSrv - ok

16:38:26.0617 2248 avc3 (f57de310bf3bd9df0f7d301c1d7f5432) C:\Windows\system32\DRIVERS\avc3.sys

16:38:26.0684 2248 avc3 - ok

16:38:26.0709 2248 avchv (4c6bcc638798abe1f70afca70d889c3f) C:\Windows\system32\DRIVERS\avchv.sys

16:38:26.0737 2248 avchv - ok

16:38:26.0768 2248 avckf (6dc4cca415bbf2fc629beb532aa0e6cd) C:\Windows\system32\DRIVERS\avckf.sys

16:38:26.0791 2248 avckf - ok

16:38:26.0809 2248 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll

16:38:26.0851 2248 AxInstSV - ok

16:38:26.0898 2248 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys

16:38:26.0943 2248 b06bdrv - ok

16:38:26.0983 2248 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys

16:38:27.0028 2248 b57nd60a - ok

16:38:27.0097 2248 BBSvc (87f3bcf82a63e900af896cd930bf7e05) C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE

16:38:27.0135 2248 BBSvc - ok

16:38:27.0163 2248 BBUpdate (78779ee07231c658b483b1f38b5088df) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE

16:38:27.0211 2248 BBUpdate - ok

16:38:27.0233 2248 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll

16:38:27.0263 2248 BDESVC - ok

16:38:27.0366 2248 bdfwfpf (4ce4b0098fc315c237fa8867f07886c4) C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys

16:38:27.0386 2248 bdfwfpf - ok

16:38:27.0416 2248 BDSandBox (31571d77c6186ad228f52ee4ebdf8ee9) C:\Windows\system32\drivers\bdsandbox.sys

16:38:27.0436 2248 BDSandBox - ok

16:38:27.0452 2248 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys

16:38:27.0510 2248 Beep - ok

16:38:27.0569 2248 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll

16:38:27.0632 2248 BFE - ok

16:38:27.0718 2248 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll

16:38:27.0771 2248 BITS - ok

16:38:27.0816 2248 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys

16:38:27.0828 2248 blbdrive - ok

16:38:27.0847 2248 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys

16:38:27.0879 2248 bowser - ok

16:38:27.0900 2248 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys

16:38:27.0913 2248 BrFiltLo - ok

16:38:27.0927 2248 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys

16:38:27.0939 2248 BrFiltUp - ok

16:38:27.0957 2248 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys

16:38:28.0000 2248 BridgeMP - ok

16:38:28.0037 2248 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll

16:38:28.0086 2248 Browser - ok

16:38:28.0130 2248 BrSerIb (e5e9b1625a767ceb6f319c12d33eab78) C:\Windows\system32\DRIVERS\BrSerIb.sys

16:38:28.0172 2248 BrSerIb - ok

16:38:28.0184 2248 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys

16:38:28.0199 2248 Brserid - ok

16:38:28.0219 2248 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys

16:38:28.0255 2248 BrSerWdm - ok

16:38:28.0258 2248 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys

16:38:28.0278 2248 BrUsbMdm - ok

16:38:28.0281 2248 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys

16:38:28.0296 2248 BrUsbSer - ok

16:38:28.0332 2248 BrUsbSIb (d9f6b30ad93cbd165ec71fadf51df25e) C:\Windows\system32\DRIVERS\BrUsbSIb.sys

16:38:28.0367 2248 BrUsbSIb - ok

16:38:28.0446 2248 BrYNSvc (ea7e57f87d6fee5fd6c5f813c04e8cd2) C:\Program Files (x86)\Browny02\BrYNSvc.exe

16:38:28.0487 2248 BrYNSvc ( UnsignedFile.Multi.Generic ) - warning

16:38:28.0487 2248 BrYNSvc - detected UnsignedFile.Multi.Generic (1)

16:38:28.0492 2248 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys

16:38:28.0523 2248 BTHMODEM - ok

16:38:28.0557 2248 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll

16:38:28.0623 2248 bthserv - ok

16:38:28.0654 2248 catchme - ok

16:38:28.0689 2248 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys

16:38:28.0720 2248 cdfs - ok

16:38:28.0740 2248 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys

16:38:28.0770 2248 cdrom - ok

16:38:28.0792 2248 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll

16:38:28.0855 2248 CertPropSvc - ok

16:38:28.0877 2248 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys

16:38:28.0893 2248 circlass - ok

16:38:28.0921 2248 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys

16:38:28.0939 2248 CLFS - ok

16:38:28.0994 2248 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

16:38:29.0038 2248 clr_optimization_v2.0.50727_32 - ok

16:38:29.0077 2248 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe

16:38:29.0097 2248 clr_optimization_v2.0.50727_64 - ok

16:38:29.0137 2248 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe

16:38:29.0258 2248 clr_optimization_v4.0.30319_32 - ok

16:38:29.0369 2248 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

16:38:29.0394 2248 clr_optimization_v4.0.30319_64 - ok

16:38:29.0407 2248 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys

16:38:29.0440 2248 CmBatt - ok

16:38:29.0442 2248 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys

16:38:29.0455 2248 cmdide - ok

16:38:29.0569 2248 CNG (9ac4f97c2d3e93367e2148ea940cd2cd) C:\Windows\system32\Drivers\cng.sys

16:38:29.0608 2248 CNG - ok

16:38:29.0687 2248 CnxtHdAudService (5c855932e4df00b1b6f5f6f57e82b6c5) C:\Windows\system32\drivers\CHDRT64.sys

16:38:29.0737 2248 CnxtHdAudService - ok

16:38:29.0807 2248 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys

16:38:29.0825 2248 Compbatt - ok

16:38:29.0839 2248 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys

16:38:29.0873 2248 CompositeBus - ok

16:38:29.0875 2248 COMSysApp - ok

16:38:29.0879 2248 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys

16:38:29.0890 2248 crcdisk - ok

16:38:29.0928 2248 CryptSvc (4f5414602e2544a4554d95517948b705) C:\Windows\system32\cryptsvc.dll

16:38:29.0942 2248 CryptSvc - ok

16:38:29.0981 2248 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys

16:38:30.0037 2248 CSC - ok

16:38:30.0107 2248 CscService (3ab183ab4d2c79dcf459cd2c1266b043) C:\Windows\System32\cscsvc.dll

16:38:30.0154 2248 CscService - ok

16:38:30.0205 2248 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll

16:38:30.0265 2248 DcomLaunch - ok

16:38:30.0309 2248 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll

16:38:30.0362 2248 defragsvc - ok

16:38:30.0422 2248 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys

16:38:30.0483 2248 DfsC - ok

16:38:30.0517 2248 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll

16:38:30.0568 2248 Dhcp - ok

16:38:30.0593 2248 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys

16:38:30.0650 2248 discache - ok

16:38:30.0664 2248 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys

16:38:30.0677 2248 Disk - ok

16:38:30.0696 2248 dmvsc (5db085a8a6600be6401f2b24eecb5415) C:\Windows\system32\drivers\dmvsc.sys

16:38:30.0709 2248 dmvsc - ok

16:38:30.0734 2248 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll

16:38:30.0773 2248 Dnscache - ok

16:38:30.0815 2248 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll

16:38:30.0876 2248 dot3svc - ok

16:38:30.0907 2248 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll

16:38:30.0954 2248 DPS - ok

16:38:30.0980 2248 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys

16:38:31.0017 2248 drmkaud - ok

16:38:31.0084 2248 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys

16:38:31.0113 2248 DXGKrnl - ok

16:38:31.0125 2248 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll

16:38:31.0177 2248 EapHost - ok

16:38:31.0442 2248 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys

16:38:31.0572 2248 ebdrv - ok

16:38:31.0662 2248 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe

16:38:31.0689 2248 EFS - ok

16:38:31.0774 2248 ehRecvr (c4002b6b41975f057d98c439030cea07) C:\Windows\ehome\ehRecvr.exe

16:38:31.0829 2248 ehRecvr - ok

16:38:31.0858 2248 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe

16:38:31.0872 2248 ehSched - ok

16:38:31.0924 2248 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys

16:38:31.0948 2248 elxstor - ok

16:38:31.0957 2248 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys

16:38:31.0989 2248 ErrDev - ok

16:38:32.0034 2248 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll

16:38:32.0084 2248 EventSystem - ok

16:38:32.0114 2248 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys

16:38:32.0145 2248 exfat - ok

16:38:32.0164 2248 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys

16:38:32.0210 2248 fastfat - ok

16:38:32.0260 2248 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe

16:38:32.0308 2248 Fax - ok

16:38:32.0333 2248 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys

16:38:32.0370 2248 fdc - ok

16:38:32.0395 2248 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll

16:38:32.0439 2248 fdPHost - ok

16:38:32.0449 2248 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll

16:38:32.0497 2248 FDResPub - ok

16:38:32.0518 2248 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys

16:38:32.0528 2248 FileInfo - ok

16:38:32.0536 2248 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys

16:38:32.0581 2248 Filetrace - ok

16:38:32.0627 2248 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys

16:38:32.0638 2248 flpydisk - ok

16:38:32.0661 2248 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys

16:38:32.0677 2248 FltMgr - ok

16:38:32.0734 2248 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll

16:38:32.0779 2248 FontCache - ok

16:38:32.0843 2248 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

16:38:32.0868 2248 FontCache3.0.0.0 - ok

16:38:32.0893 2248 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys

16:38:32.0905 2248 FsDepends - ok

16:38:32.0926 2248 fssfltr (07da62c960ddccc2d35836aeab4fc578) C:\Windows\system32\DRIVERS\fssfltr.sys

16:38:32.0937 2248 fssfltr - ok

16:38:33.0065 2248 fsssvc (28ddeeec44e988657b732cf404d504cb) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe

16:38:33.0160 2248 fsssvc - ok

16:38:33.0253 2248 Fs_Rec (6bd9295cc032dd3077c671fccf579a7b) C:\Windows\system32\drivers\Fs_Rec.sys

16:38:33.0270 2248 Fs_Rec - ok

16:38:33.0295 2248 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys

16:38:33.0319 2248 fvevol - ok

16:38:33.0332 2248 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys

16:38:33.0343 2248 gagp30kx - ok

16:38:33.0389 2248 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll

16:38:33.0425 2248 gpsvc - ok

16:38:33.0495 2248 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

16:38:33.0540 2248 gupdate - ok

16:38:33.0542 2248 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

16:38:33.0559 2248 gupdatem - ok

16:38:33.0603 2248 gzflt (07177b5a8c277074c30ac515febd4f37) C:\Windows\system32\DRIVERS\gzflt.sys

16:38:33.0624 2248 gzflt - ok

16:38:33.0635 2248 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys

16:38:33.0661 2248 hcw85cir - ok

16:38:33.0689 2248 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys

16:38:33.0717 2248 HDAudBus - ok

16:38:33.0734 2248 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys

16:38:33.0765 2248 HidBatt - ok

16:38:33.0773 2248 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys

16:38:33.0794 2248 HidBth - ok

16:38:33.0817 2248 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys

16:38:33.0831 2248 HidIr - ok

16:38:33.0848 2248 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll

16:38:33.0895 2248 hidserv - ok

16:38:33.0927 2248 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys

16:38:33.0947 2248 HidUsb - ok

16:38:33.0960 2248 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll

16:38:34.0005 2248 hkmsvc - ok

16:38:34.0037 2248 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll

16:38:34.0083 2248 HomeGroupListener - ok

16:38:34.0119 2248 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll

16:38:34.0165 2248 HomeGroupProvider - ok

16:38:34.0195 2248 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys

16:38:34.0207 2248 HpSAMD - ok

16:38:34.0246 2248 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys

16:38:34.0302 2248 HTTP - ok

16:38:34.0323 2248 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys

16:38:34.0333 2248 hwpolicy - ok

16:38:34.0351 2248 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys

16:38:34.0364 2248 i8042prt - ok

16:38:34.0403 2248 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys

16:38:34.0438 2248 iaStorV - ok

16:38:34.0528 2248 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe

16:38:34.0564 2248 idsvc - ok

16:38:34.0954 2248 igfx (9937600a1584ff00565d5379eb4c9edb) C:\Windows\system32\DRIVERS\igdkmd64.sys

16:38:35.0253 2248 igfx - ok

16:38:35.0368 2248 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys

16:38:35.0387 2248 iirsp - ok

16:38:35.0438 2248 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll

16:38:35.0523 2248 IKEEXT - ok

16:38:35.0569 2248 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\Windows\system32\DRIVERS\IntcDAud.sys

16:38:35.0597 2248 IntcDAud - ok

16:38:35.0630 2248 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys

16:38:35.0666 2248 intelide - ok

16:38:35.0684 2248 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys

16:38:35.0711 2248 intelppm - ok

16:38:35.0739 2248 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll

16:38:35.0791 2248 IPBusEnum - ok

16:38:35.0824 2248 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys

16:38:35.0852 2248 IpFilterDriver - ok

16:38:35.0881 2248 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll

16:38:35.0935 2248 iphlpsvc - ok

16:38:35.0961 2248 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys

16:38:35.0998 2248 IPMIDRV - ok

16:38:36.0022 2248 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys

16:38:36.0065 2248 IPNAT - ok

16:38:36.0073 2248 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys

16:38:36.0088 2248 IRENUM - ok

16:38:36.0102 2248 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys

16:38:36.0112 2248 isapnp - ok

16:38:36.0134 2248 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys

16:38:36.0153 2248 iScsiPrt - ok

16:38:36.0208 2248 jhi_service (6c85719a21b3f62c2c76280f4bd36c7b) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe

16:38:36.0254 2248 jhi_service - ok

16:38:36.0268 2248 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys

16:38:36.0279 2248 kbdclass - ok

16:38:36.0291 2248 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys

16:38:36.0319 2248 kbdhid - ok

16:38:36.0352 2248 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe

16:38:36.0369 2248 KeyIso - ok

16:38:36.0405 2248 KSecDD (97a7070aea4c058b6418519e869a63b4) C:\Windows\system32\Drivers\ksecdd.sys

16:38:36.0416 2248 KSecDD - ok

16:38:36.0451 2248 KSecPkg (26c43a7c2862447ec59deda188d1da07) C:\Windows\system32\Drivers\ksecpkg.sys

16:38:36.0467 2248 KSecPkg - ok

16:38:36.0482 2248 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys

16:38:36.0539 2248 ksthunk - ok

16:38:36.0582 2248 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll

16:38:36.0662 2248 KtmRm - ok

16:38:36.0703 2248 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll

16:38:36.0754 2248 LanmanServer - ok

16:38:36.0778 2248 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll

16:38:36.0842 2248 LanmanWorkstation - ok

16:38:36.0870 2248 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys

16:38:36.0932 2248 lltdio - ok

16:38:36.0969 2248 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll

16:38:37.0019 2248 lltdsvc - ok

16:38:37.0037 2248 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll

16:38:37.0064 2248 lmhosts - ok

16:38:37.0160 2248 LMIGuardianSvc (98b0fcc176dfb711b67651becb88c445) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe

16:38:37.0181 2248 LMIGuardianSvc - ok

16:38:37.0209 2248 LMIInfo (0317335b15ff3bda8e10197e3434cfc0) C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys

16:38:37.0219 2248 LMIInfo - ok

16:38:37.0245 2248 LMIMaint (b712511029cbd68645a90a241fd6ae43) C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe

16:38:37.0257 2248 LMIMaint - ok

16:38:37.0281 2248 lmimirr (413ecdcfad9a82804d3674c8d7eec24e) C:\Windows\system32\DRIVERS\lmimirr.sys

16:38:37.0296 2248 lmimirr - ok

16:38:37.0300 2248 LMIRfsClientNP - ok

16:38:37.0315 2248 LMIRfsDriver (c57d3faa50e6f395759ffb7c709bd944) C:\Windows\system32\drivers\LMIRfsDriver.sys

16:38:37.0326 2248 LMIRfsDriver - ok

16:38:37.0364 2248 LMS (5f5899711df18a02162b6d518c17b0d7) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

16:38:37.0398 2248 LMS - ok

16:38:37.0442 2248 LogMeIn (d3760bc17e1755091b7120cf32dbf56b) C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe

16:38:37.0471 2248 LogMeIn - ok

16:38:37.0496 2248 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys

16:38:37.0509 2248 LSI_FC - ok

16:38:37.0515 2248 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys

16:38:37.0526 2248 LSI_SAS - ok

16:38:37.0531 2248 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys

16:38:37.0542 2248 LSI_SAS2 - ok

16:38:37.0548 2248 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys

16:38:37.0560 2248 LSI_SCSI - ok

16:38:37.0574 2248 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys

16:38:37.0621 2248 luafv - ok

16:38:37.0649 2248 MBAMProtector (dc8490812a3b72811ae534f423b4c206) C:\Windows\system32\drivers\mbam.sys

16:38:37.0661 2248 MBAMProtector - ok

16:38:37.0729 2248 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

16:38:37.0769 2248 MBAMService - ok

16:38:37.0790 2248 Mcx2Svc (0be09cd858abf9df6ed259d57a1a1663) C:\Windows\system32\Mcx2Svc.dll

16:38:37.0803 2248 Mcx2Svc - ok

16:38:37.0807 2248 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys

16:38:37.0818 2248 megasas - ok

16:38:37.0842 2248 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys

16:38:37.0861 2248 MegaSR - ok

16:38:37.0879 2248 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\DRIVERS\HECIx64.sys

16:38:37.0890 2248 MEIx64 - ok

16:38:37.0906 2248 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll

16:38:37.0952 2248 MMCSS - ok

16:38:37.0972 2248 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys

16:38:38.0015 2248 Modem - ok

16:38:38.0049 2248 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys

16:38:38.0090 2248 monitor - ok

16:38:38.0131 2248 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys

16:38:38.0151 2248 mouclass - ok

16:38:38.0165 2248 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys

16:38:38.0194 2248 mouhid - ok

16:38:38.0223 2248 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys

16:38:38.0234 2248 mountmgr - ok

16:38:38.0249 2248 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys

16:38:38.0263 2248 mpio - ok

16:38:38.0280 2248 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys

16:38:38.0308 2248 mpsdrv - ok

16:38:38.0361 2248 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll

16:38:38.0429 2248 MpsSvc - ok

16:38:38.0454 2248 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys

16:38:38.0487 2248 MRxDAV - ok

16:38:38.0512 2248 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys

16:38:38.0555 2248 mrxsmb - ok

16:38:38.0597 2248 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys

16:38:38.0628 2248 mrxsmb10 - ok

16:38:38.0643 2248 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys

16:38:38.0656 2248 mrxsmb20 - ok

16:38:38.0682 2248 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys

16:38:38.0693 2248 msahci - ok

16:38:38.0718 2248 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys

16:38:38.0732 2248 msdsm - ok

16:38:38.0756 2248 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe

16:38:38.0794 2248 MSDTC - ok

16:38:38.0828 2248 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys

16:38:38.0855 2248 Msfs - ok

16:38:38.0863 2248 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys

16:38:38.0905 2248 mshidkmdf - ok

16:38:38.0936 2248 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys

16:38:38.0955 2248 msisadrv - ok

16:38:38.0979 2248 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll

16:38:39.0036 2248 MSiSCSI - ok

16:38:39.0038 2248 msiserver - ok

16:38:39.0061 2248 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys

16:38:39.0122 2248 MSKSSRV - ok

16:38:39.0143 2248 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys

16:38:39.0186 2248 MSPCLOCK - ok

16:38:39.0188 2248 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys

16:38:39.0223 2248 MSPQM - ok

16:38:39.0254 2248 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys

16:38:39.0271 2248 MsRPC - ok

16:38:39.0287 2248 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys

16:38:39.0298 2248 mssmbios - ok

16:38:39.0309 2248 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys

16:38:39.0364 2248 MSTEE - ok

16:38:39.0367 2248 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys

16:38:39.0378 2248 MTConfig - ok

16:38:39.0397 2248 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys

16:38:39.0417 2248 Mup - ok

16:38:39.0453 2248 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll

16:38:39.0512 2248 napagent - ok

16:38:39.0547 2248 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys

16:38:39.0592 2248 NativeWifiP - ok

16:38:39.0657 2248 NDIS (c38b8ae57f78915905064a9a24dc1586) C:\Windows\system32\drivers\ndis.sys

16:38:39.0683 2248 NDIS - ok

16:38:39.0692 2248 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys

16:38:39.0721 2248 NdisCap - ok

16:38:39.0736 2248 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys

16:38:39.0764 2248 NdisTapi - ok

16:38:39.0781 2248 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys

16:38:39.0848 2248 Ndisuio - ok

16:38:39.0876 2248 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys

16:38:39.0936 2248 NdisWan - ok

16:38:39.0958 2248 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys

16:38:39.0985 2248 NDProxy - ok

16:38:39.0999 2248 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys

16:38:40.0043 2248 NetBIOS - ok

16:38:40.0070 2248 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys

16:38:40.0102 2248 NetBT - ok

16:38:40.0119 2248 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe

16:38:40.0128 2248 Netlogon - ok

16:38:40.0171 2248 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll

16:38:40.0226 2248 Netman - ok

16:38:40.0313 2248 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

16:38:40.0331 2248 NetMsmqActivator - ok

16:38:40.0334 2248 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

16:38:40.0346 2248 NetPipeActivator - ok

16:38:40.0381 2248 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll

16:38:40.0449 2248 netprofm - ok

16:38:40.0452 2248 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

16:38:40.0464 2248 NetTcpActivator - ok

16:38:40.0466 2248 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe

16:38:40.0478 2248 NetTcpPortSharing - ok

16:38:40.0522 2248 netvsc (73ce12b8bdd747b0063cb0a7ef44cea7) C:\Windows\system32\DRIVERS\netvsc60.sys

16:38:40.0554 2248 netvsc - ok

16:38:40.0584 2248 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys

16:38:40.0598 2248 nfrd960 - ok

16:38:40.0647 2248 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll

16:38:40.0701 2248 NlaSvc - ok

16:38:40.0724 2248 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys

16:38:40.0752 2248 Npfs - ok

16:38:40.0764 2248 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll

16:38:40.0808 2248 nsi - ok

16:38:40.0827 2248 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys

16:38:40.0854 2248 nsiproxy - ok

16:38:40.0943 2248 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys

16:38:41.0026 2248 Ntfs - ok

16:38:41.0125 2248 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys

16:38:41.0165 2248 Null - ok

16:38:41.0184 2248 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys

16:38:41.0197 2248 nvraid - ok

16:38:41.0213 2248 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys

16:38:41.0226 2248 nvstor - ok

16:38:41.0246 2248 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys

16:38:41.0258 2248 nv_agp - ok

16:38:41.0264 2248 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys

16:38:41.0298 2248 ohci1394 - ok

16:38:41.0346 2248 ose (9d10f99a6712e28f8acd5641e3a7ea6b) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE

16:38:41.0379 2248 ose - ok

16:38:41.0573 2248 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE

16:38:41.0726 2248 osppsvc - ok

16:38:41.0927 2248 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll

16:38:41.0979 2248 p2pimsvc - ok

16:38:42.0014 2248 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll

16:38:42.0033 2248 p2psvc - ok

16:38:42.0077 2248 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys

16:38:42.0094 2248 Parport - ok

16:38:42.0125 2248 partmgr (e9766131eeade40a27dc27d2d68fba9c) C:\Windows\system32\drivers\partmgr.sys

16:38:42.0144 2248 partmgr - ok

16:38:42.0166 2248 PBADRV (363b3f857abee85767e01e3044c539cd) C:\Windows\system32\DRIVERS\PBADRV.sys

16:38:42.0182 2248 PBADRV - ok

16:38:42.0203 2248 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll

16:38:42.0235 2248 PcaSvc - ok

16:38:42.0268 2248 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys

16:38:42.0290 2248 pci - ok

16:38:42.0304 2248 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys

16:38:42.0314 2248 pciide - ok

16:38:42.0349 2248 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys

16:38:42.0385 2248 pcmcia - ok

16:38:42.0406 2248 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys

16:38:42.0418 2248 pcw - ok

16:38:42.0470 2248 PDFProFiltSrvPP (c1c3baf078be5a14384a4ba2d730817d) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe

16:38:42.0515 2248 PDFProFiltSrvPP - ok

16:38:42.0546 2248 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys

16:38:42.0627 2248 PEAUTH - ok

16:38:42.0692 2248 PeerDistSvc (b9b0a4299dd2d76a4243f75fd54dc680) C:\Windows\system32\peerdistsvc.dll

16:38:42.0740 2248 PeerDistSvc - ok

16:38:42.0835 2248 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe

16:38:42.0865 2248 PerfHost - ok

16:38:43.0012 2248 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll

16:38:43.0078 2248 pla - ok

16:38:43.0154 2248 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll

16:38:43.0192 2248 PlugPlay - ok

16:38:43.0214 2248 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll

16:38:43.0250 2248 PNRPAutoReg - ok

16:38:43.0286 2248 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll

16:38:43.0307 2248 PNRPsvc - ok

16:38:43.0352 2248 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll

16:38:43.0411 2248 PolicyAgent - ok

16:38:43.0438 2248 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll

16:38:43.0487 2248 Power - ok

16:38:43.0541 2248 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys

16:38:43.0600 2248 PptpMiniport - ok

16:38:43.0634 2248 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys

16:38:43.0665 2248 Processor - ok

16:38:43.0706 2248 ProfSvc (53e83f1f6cf9d62f32801cf66d8352a8) C:\Windows\system32\profsvc.dll

16:38:43.0738 2248 ProfSvc - ok

16:38:43.0761 2248 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe

16:38:43.0771 2248 ProtectedStorage - ok

16:38:43.0791 2248 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys

16:38:43.0837 2248 Psched - ok

16:38:43.0871 2248 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys

16:38:43.0881 2248 PxHlpa64 - ok

16:38:43.0961 2248 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys

16:38:44.0020 2248 ql2300 - ok

16:38:44.0098 2248 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys

16:38:44.0128 2248 ql40xx - ok

16:38:44.0160 2248 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll

16:38:44.0186 2248 QWAVE - ok

16:38:44.0254 2248 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys

16:38:44.0298 2248 QWAVEdrv - ok

16:38:44.0301 2248 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys

16:38:44.0381 2248 RasAcd - ok

16:38:44.0409 2248 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys

16:38:44.0440 2248 RasAgileVpn - ok

16:38:44.0450 2248 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll

16:38:44.0500 2248 RasAuto - ok

16:38:44.0525 2248 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys

16:38:44.0578 2248 Rasl2tp - ok

16:38:44.0615 2248 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll

16:38:44.0674 2248 RasMan - ok

16:38:44.0694 2248 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys

16:38:44.0741 2248 RasPppoe - ok

16:38:44.0769 2248 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys

16:38:44.0817 2248 RasSstp - ok

16:38:44.0854 2248 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys

16:38:44.0914 2248 rdbss - ok

16:38:44.0932 2248 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys

16:38:44.0947 2248 rdpbus - ok

16:38:44.0953 2248 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys

16:38:44.0998 2248 RDPCDD - ok

16:38:45.0033 2248 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys

16:38:45.0046 2248 RDPDR - ok

16:38:45.0054 2248 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys

16:38:45.0099 2248 RDPENCDD - ok

16:38:45.0124 2248 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys

16:38:45.0150 2248 RDPREFMP - ok

16:38:45.0185 2248 RDPWD (e61608aa35e98999af9aaeeea6114b0a) C:\Windows\system32\drivers\RDPWD.sys

16:38:45.0199 2248 RDPWD - ok

16:38:45.0219 2248 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys

16:38:45.0232 2248 rdyboost - ok

16:38:45.0258 2248 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll

16:38:45.0317 2248 RemoteAccess - ok

16:38:45.0353 2248 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll

16:38:45.0409 2248 RemoteRegistry - ok

16:38:45.0548 2248 RoxMediaDB12OEM (3c957189b31c34d3ad21967b12b6aed7) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

16:38:45.0610 2248 RoxMediaDB12OEM - ok

16:38:45.0637 2248 RoxWatch12 (2b73088cc2ca757a172b425c9398e5bc) C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

16:38:45.0666 2248 RoxWatch12 - ok

16:38:45.0752 2248 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll

16:38:45.0815 2248 RpcEptMapper - ok

16:38:45.0837 2248 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe

16:38:45.0849 2248 RpcLocator - ok

16:38:45.0879 2248 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll

16:38:45.0908 2248 RpcSs - ok

16:38:45.0945 2248 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys

16:38:45.0999 2248 rspndr - ok

16:38:46.0059 2248 RTL8167 (ee082e06a82ff630351d1e0ebbd3d8d0) C:\Windows\system32\DRIVERS\Rt64win7.sys

16:38:46.0095 2248 RTL8167 - ok

16:38:46.0115 2248 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys

16:38:46.0151 2248 s3cap - ok

16:38:46.0177 2248 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe

16:38:46.0187 2248 SamSs - ok

16:38:46.0200 2248 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys

16:38:46.0214 2248 sbp2port - ok

16:38:46.0230 2248 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll

16:38:46.0258 2248 SCardSvr - ok

16:38:46.0273 2248 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys

16:38:46.0318 2248 scfilter - ok

16:38:46.0382 2248 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll

16:38:46.0469 2248 Schedule - ok

16:38:46.0502 2248 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll

16:38:46.0537 2248 SCPolicySvc - ok

16:38:46.0553 2248 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll

16:38:46.0567 2248 SDRSVC - ok

16:38:46.0597 2248 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys

16:38:46.0653 2248 secdrv - ok

16:38:46.0665 2248 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll

16:38:46.0697 2248 seclogon - ok

16:38:46.0835 2248 SecureStorageService (f3d951071c624137430fe65a67541ef9) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe

16:38:46.0945 2248 SecureStorageService ( UnsignedFile.Multi.Generic ) - warning

16:38:46.0945 2248 SecureStorageService - detected UnsignedFile.Multi.Generic (1)

16:38:47.0060 2248 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll

16:38:47.0110 2248 SENS - ok

16:38:47.0171 2248 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll

16:38:47.0215 2248 SensrSvc - ok

16:38:47.0463 2248 SentinelService (1087e43ffc39e59de316d1b1976b203c) C:\OPTI-SAFE Sentinel for Windows\Sentinel_Service.Exe

16:38:47.0567 2248 SentinelService ( UnsignedFile.Multi.Generic ) - warning

16:38:47.0567 2248 SentinelService - detected UnsignedFile.Multi.Generic (1)

16:38:47.0643 2248 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys

16:38:47.0678 2248 Serenum - ok

16:38:47.0703 2248 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys

16:38:47.0742 2248 Serial - ok

16:38:47.0761 2248 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys

16:38:47.0785 2248 sermouse - ok

16:38:47.0826 2248 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll

16:38:47.0883 2248 SessionEnv - ok

16:38:47.0887 2248 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys

16:38:47.0899 2248 sffdisk - ok

16:38:47.0903 2248 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys

16:38:47.0916 2248 sffp_mmc - ok

16:38:47.0921 2248 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys

16:38:47.0955 2248 sffp_sd - ok

16:38:47.0958 2248 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys

16:38:47.0970 2248 sfloppy - ok

16:38:48.0018 2248 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll

16:38:48.0062 2248 SharedAccess - ok

16:38:48.0147 2248 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll

16:38:48.0240 2248 ShellHWDetection - ok

16:38:48.0321 2248 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys

16:38:48.0338 2248 SiSRaid2 - ok

16:38:48.0344 2248 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys

16:38:48.0359 2248 SiSRaid4 - ok

16:38:48.0371 2248 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys

16:38:48.0426 2248 Smb - ok

16:38:48.0466 2248 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe

16:38:48.0505 2248 SNMPTRAP - ok

16:38:48.0524 2248 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys

16:38:48.0534 2248 spldr - ok

16:38:48.0579 2248 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe

16:38:48.0618 2248 Spooler - ok

16:38:48.0817 2248 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe

16:38:48.0967 2248 sppsvc - ok

16:38:49.0079 2248 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll

16:38:49.0110 2248 sppuinotify - ok

16:38:49.0170 2248 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys

16:38:49.0246 2248 srv - ok

16:38:49.0296 2248 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys

16:38:49.0327 2248 srv2 - ok

16:38:49.0359 2248 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys

16:38:49.0373 2248 srvnet - ok

16:38:49.0399 2248 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll

16:38:49.0452 2248 SSDPSRV - ok

16:38:49.0473 2248 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll

16:38:49.0505 2248 SstpSvc - ok

16:38:49.0522 2248 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys

16:38:49.0542 2248 stexstor - ok

16:38:49.0562 2248 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys

16:38:49.0581 2248 StillCam - ok

16:38:49.0651 2248 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll

16:38:49.0682 2248 stisvc - ok

16:38:49.0777 2248 stllssvr (7731f46ec0d687a931cba063e8f90ef0) C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe

16:38:49.0816 2248 stllssvr - ok

16:38:49.0845 2248 StorSvc (c40841817ef57d491f22eb103da587cc) C:\Windows\system32\storsvc.dll

16:38:49.0882 2248 StorSvc - ok

16:38:49.0914 2248 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys

16:38:49.0929 2248 storvsc - ok

16:38:49.0974 2248 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys

16:38:49.0993 2248 swenum - ok

16:38:50.0045 2248 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll

16:38:50.0127 2248 swprv - ok

16:38:50.0146 2248 SynthVid (4cdd7df58730d23ba9cb5829a6e2ecea) C:\Windows\system32\DRIVERS\VMBusVideoM.sys

16:38:50.0173 2248 SynthVid - ok

16:38:50.0377 2248 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll

16:38:50.0448 2248 SysMain - ok

16:38:50.0656 2248 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll

16:38:50.0710 2248 TabletInputService - ok

16:38:50.0774 2248 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll

16:38:50.0856 2248 TapiSrv - ok

16:38:50.0937 2248 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll

16:38:50.0978 2248 TBS - ok

16:38:51.0145 2248 Tcpip (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\drivers\tcpip.sys

16:38:51.0207 2248 Tcpip - ok

16:38:51.0449 2248 TCPIP6 (acb82bda8f46c84f465c1afa517dc4b9) C:\Windows\system32\DRIVERS\tcpip.sys

16:38:51.0479 2248 TCPIP6 - ok

16:38:51.0614 2248 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys

16:38:51.0667 2248 tcpipreg - ok

16:38:51.0892 2248 tcsd_win32.exe (e42d560e2163480e7b586b14abeb3386) C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe

16:38:51.0983 2248 tcsd_win32.exe ( UnsignedFile.Multi.Generic ) - warning

16:38:51.0983 2248 tcsd_win32.exe - detected UnsignedFile.Multi.Generic (1)

16:38:52.0379 2248 TdmService (347d6407c90c0b6ac82f8249eba9a482) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe

16:38:52.0464 2248 TdmService - ok

16:38:52.0654 2248 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys

16:38:52.0667 2248 TDPIPE - ok

16:38:52.0726 2248 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys

16:38:52.0766 2248 TDTCP - ok

16:38:52.0794 2248 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys

16:38:52.0838 2248 tdx - ok

16:38:52.0855 2248 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys

16:38:52.0865 2248 TermDD - ok

16:38:52.0951 2248 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll

16:38:53.0014 2248 TermService - ok

16:38:53.0095 2248 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll

16:38:53.0155 2248 Themes - ok

16:38:53.0196 2248 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll

16:38:53.0223 2248 THREADORDER - ok

16:38:53.0271 2248 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll

16:38:53.0342 2248 TrkWks - ok

16:38:53.0398 2248 trufos (df219721ddffcbe03aa894b6b6742ba1) C:\Windows\system32\DRIVERS\trufos.sys

16:38:53.0425 2248 trufos - ok

16:38:53.0476 2248 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe

16:38:53.0523 2248 TrustedInstaller - ok

16:38:53.0569 2248 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys

16:38:53.0635 2248 tssecsrv - ok

16:38:53.0721 2248 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys

16:38:53.0778 2248 TsUsbFlt - ok

16:38:53.0782 2248 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys

16:38:53.0793 2248 TsUsbGD - ok

16:38:53.0829 2248 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys

16:38:53.0887 2248 tunnel - ok

16:38:53.0914 2248 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys

16:38:53.0925 2248 uagp35 - ok

16:38:53.0939 2248 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys

16:38:54.0004 2248 udfs - ok

16:38:54.0048 2248 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe

16:38:54.0065 2248 UI0Detect - ok

16:38:54.0072 2248 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys

16:38:54.0089 2248 uliagpkx - ok

16:38:54.0093 2248 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys

16:38:54.0124 2248 umbus - ok

16:38:54.0127 2248 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys

16:38:54.0152 2248 UmPass - ok

16:38:54.0359 2248 UmRdpService (a293dcd756d04d8492a750d03b9a297c) C:\Windows\System32\umrdp.dll

16:38:54.0408 2248 UmRdpService - ok

16:38:54.0722 2248 UNS (f7a1f83f28b125aa3737bc06eabb0cd5) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

16:38:54.0813 2248 UNS - ok

16:38:55.0026 2248 UPDATESRV (2b1970c804c16d887c28246db6078ec4) C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe

16:38:55.0046 2248 UPDATESRV - ok

16:38:55.0166 2248 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll

16:38:55.0219 2248 upnphost - ok

16:38:55.0303 2248 usbccgp (19ad7990c0b67e48dac5b26f99628223) C:\Windows\system32\DRIVERS\usbccgp.sys

16:38:55.0341 2248 usbccgp - ok

16:38:55.0376 2248 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys

16:38:55.0402 2248 usbcir - ok

16:38:55.0419 2248 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys

16:38:55.0430 2248 usbehci - ok

16:38:55.0480 2248 usbhub (8b892002d7b79312821169a14317ab86) C:\Windows\system32\DRIVERS\usbhub.sys

16:38:55.0524 2248 usbhub - ok

16:38:55.0555 2248 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys

16:38:55.0594 2248 usbohci - ok

16:38:55.0624 2248 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys

16:38:55.0662 2248 usbprint - ok

16:38:55.0837 2248 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys

16:38:55.0859 2248 usbscan - ok

16:38:55.0889 2248 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS

16:38:55.0902 2248 USBSTOR - ok

16:38:55.0948 2248 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys

16:38:55.0988 2248 usbuhci - ok

16:38:56.0021 2248 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll

16:38:56.0070 2248 UxSms - ok

16:38:56.0119 2248 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe

16:38:56.0136 2248 VaultSvc - ok

16:38:56.0210 2248 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys

16:38:56.0220 2248 vdrvroot - ok

16:38:56.0290 2248 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe

16:38:56.0371 2248 vds - ok

16:38:56.0407 2248 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys

16:38:56.0428 2248 vga - ok

16:38:56.0440 2248 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys

16:38:56.0467 2248 VgaSave - ok

16:38:56.0498 2248 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys

16:38:56.0521 2248 vhdmp - ok

16:38:56.0524 2248 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys

16:38:56.0535 2248 viaide - ok

16:38:56.0553 2248 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys

16:38:56.0588 2248 VMBusHID - ok

16:38:56.0613 2248 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys

16:38:56.0624 2248 volmgr - ok

16:38:56.0649 2248 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys

16:38:56.0668 2248 volmgrx - ok

16:38:56.0728 2248 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys

16:38:56.0753 2248 volsnap - ok

16:38:56.0822 2248 vpcbus (b4a73ca4ef9a02b9738cea9ad5fe5917) C:\Windows\system32\DRIVERS\vpchbus.sys

16:38:56.0861 2248 vpcbus - ok

16:38:56.0885 2248 vpcnfltr (e675fb2b48c54f09895482e2253b289c) C:\Windows\system32\DRIVERS\vpcnfltr.sys

16:38:56.0922 2248 vpcnfltr - ok

16:38:57.0066 2248 vpcusb (5fb42082b0d19a0268705f1dd343df20) C:\Windows\system32\DRIVERS\vpcusb.sys

16:38:57.0126 2248 vpcusb - ok

16:38:57.0194 2248 vpcvmm (30d4243726a15a14f5c5e45898d14394) C:\Windows\system32\drivers\vpcvmm.sys

16:38:57.0220 2248 vpcvmm - ok

16:38:57.0240 2248 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys

16:38:57.0253 2248 vsmraid - ok

16:38:57.0425 2248 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe

16:38:57.0519 2248 VSS - ok

16:38:58.0115 2248 VSSERV (44a325ddd4199f68c56492b33e7e3b75) C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe

16:38:58.0194 2248 VSSERV - ok

16:38:58.0391 2248 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys

16:38:58.0436 2248 vwifibus - ok

16:38:58.0486 2248 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll

16:38:58.0550 2248 W32Time - ok

16:38:58.0569 2248 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys

16:38:58.0598 2248 WacomPen - ok

16:38:58.0620 2248 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys

16:38:58.0662 2248 WANARP - ok

16:38:58.0664 2248 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys

16:38:58.0691 2248 Wanarpv6 - ok

16:38:58.0993 2248 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe

16:38:59.0066 2248 WatAdminSvc - ok

16:38:59.0240 2248 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe

16:38:59.0295 2248 wbengine - ok

16:38:59.0459 2248 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll

16:38:59.0504 2248 WbioSrvc - ok

16:38:59.0551 2248 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll

16:38:59.0642 2248 wcncsvc - ok

16:38:59.0673 2248 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll

16:38:59.0720 2248 WcsPlugInService - ok

16:38:59.0804 2248 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys

16:38:59.0843 2248 Wd - ok

16:38:59.0905 2248 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys

16:38:59.0930 2248 Wdf01000 - ok

16:38:59.0969 2248 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll

16:39:00.0009 2248 WdiServiceHost - ok

16:39:00.0012 2248 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll

16:39:00.0026 2248 WdiSystemHost - ok

16:39:00.0114 2248 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll

16:39:00.0162 2248 WebClient - ok

16:39:00.0225 2248 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll

16:39:00.0308 2248 Wecsvc - ok

16:39:00.0445 2248 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll

16:39:00.0487 2248 wercplsupport - ok

16:39:00.0514 2248 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll

16:39:00.0574 2248 WerSvc - ok

16:39:00.0647 2248 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys

16:39:00.0678 2248 WfpLwf - ok

16:39:00.0686 2248 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys

16:39:00.0697 2248 WIMMount - ok

16:39:00.0719 2248 WinDefend - ok

16:39:00.0725 2248 WinHttpAutoProxySvc - ok

16:39:00.0844 2248 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll

16:39:00.0884 2248 Winmgmt - ok

16:39:01.0209 2248 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll

16:39:01.0306 2248 WinRM - ok

16:39:01.0599 2248 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll

16:39:01.0660 2248 Wlansvc - ok

16:39:01.0736 2248 wlcrasvc (06c8fa1cf39de6a735b54d906ba791c6) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

16:39:01.0755 2248 wlcrasvc - ok

16:39:01.0931 2248 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

16:39:02.0022 2248 wlidsvc - ok

16:39:02.0187 2248 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys

16:39:02.0222 2248 WmiAcpi - ok

16:39:02.0357 2248 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe

16:39:02.0396 2248 wmiApSrv - ok

16:39:02.0445 2248 WMPNetworkSvc - ok

16:39:02.0582 2248 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll

16:39:02.0597 2248 WPCSvc - ok

16:39:02.0624 2248 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll

16:39:02.0639 2248 WPDBusEnum - ok

16:39:02.0660 2248 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys

16:39:02.0688 2248 ws2ifsl - ok

16:39:02.0755 2248 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll

16:39:02.0808 2248 wscsvc - ok

16:39:02.0811 2248 WSearch - ok

16:39:03.0084 2248 wuauserv (d9ef901dca379cfe914e9fa13b73b4c4) C:\Windows\system32\wuaueng.dll

16:39:03.0169 2248 wuauserv - ok

16:39:03.0319 2248 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys

16:39:03.0378 2248 WudfPf - ok

16:39:03.0419 2248 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys

16:39:03.0483 2248 WUDFRd - ok

16:39:03.0555 2248 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll

16:39:03.0596 2248 wudfsvc - ok

16:39:03.0631 2248 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll

16:39:03.0686 2248 WwanSvc - ok

16:39:03.0721 2248 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0

16:39:04.0247 2248 \Device\Harddisk0\DR0 - ok

16:39:05.0211 2248 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR2

16:39:16.0425 2248 \Device\Harddisk1\DR2 - ok

16:39:16.0437 2248 Boot (0x1200) (f745bc2f4c4a0b4da595b91f89eeb1e5) \Device\Harddisk0\DR0\Partition0

16:39:16.0439 2248 \Device\Harddisk0\DR0\Partition0 - ok

16:39:16.0443 2248 Boot (0x1200) (e2e81c8662666787ab5c105c1276b97f) \Device\Harddisk0\DR0\Partition1

16:39:16.0443 2248 \Device\Harddisk0\DR0\Partition1 - ok

16:39:16.0458 2248 Boot (0x1200) (237b7bde2f96ff64bbeb69408a4f6330) \Device\Harddisk0\DR0\Partition2

16:39:16.0459 2248 \Device\Harddisk0\DR0\Partition2 - ok

16:39:16.0491 2248 Boot (0x1200) (e5db029ff9041ec5dc8501e4cc3a5068) \Device\Harddisk0\DR0\Partition3

16:39:16.0556 2248 \Device\Harddisk0\DR0\Partition3 - ok

16:39:16.0560 2248 Boot (0x1200) (335ca546de2f950d582c019ab8794347) \Device\Harddisk1\DR2\Partition0

16:39:16.0560 2248 \Device\Harddisk1\DR2\Partition0 - ok

16:39:16.0561 2248 ============================================================

16:39:16.0561 2248 Scan finished

16:39:16.0561 2248 ============================================================

16:39:16.0570 1652 Detected object count: 4

16:39:16.0570 1652 Actual detected object count: 4

16:40:02.0582 1652 BrYNSvc ( UnsignedFile.Multi.Generic ) - skipped by user

16:40:02.0582 1652 BrYNSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip

16:40:02.0583 1652 SecureStorageService ( UnsignedFile.Multi.Generic ) - skipped by user

16:40:02.0583 1652 SecureStorageService ( UnsignedFile.Multi.Generic ) - User select action: Skip

16:40:02.0586 1652 SentinelService ( UnsignedFile.Multi.Generic ) - skipped by user

16:40:02.0586 1652 SentinelService ( UnsignedFile.Multi.Generic ) - User select action: Skip

16:40:02.0587 1652 tcsd_win32.exe ( UnsignedFile.Multi.Generic ) - skipped by user

16:40:02.0587 1652 tcsd_win32.exe ( UnsignedFile.Multi.Generic ) - User select action: Skip

16:40:06.0171 3296 Deinitialize success

Link to post
Share on other sites

I used TestDisk to fix the partition table and the computer now starts up just fine and runs TDSSKiller.

What did you do to fix it?

-----------------------------------

That scan was clean, run ComboFix to clean up any left overs, post the log.

MrC

Link to post
Share on other sites

What did you do to fix it?

-----------------------------------

That scan was clean, run ComboFix to clean up any left overs, post the log.

MrC

Using TestDisk I was able to restore the partition table to an earlier state and then change the active partition back to the recovery partition which the system used in order to boot Windows 7. On this particular Dell Optiplex, the default partition was a Dell it was the recovery partition and not the bootkit partition. Using TestDisk I was able to fix the partition table and change the active partition in order to run bootrec /fixmbr and bootrec /fixboot to restore the Windows 7 MBR and boot sector, as well as use Disk Management to delete the 10 MB bootkit partition.

An identical infection was found on another machine. This time, instead of fixing it using BitDefender which corrupted the partition, I booted the system using a PE disk and changed the active partition using Disk Management. This booted Windows bypassing the bootkit and allowed me to run TDSS killer to in order to detect and remove a TDSS filesystem partition. Using that method I didn't have to restore the partition table using TestDisk.

Link to post
Share on other sites

Good so you're all set.

My closing speech>>>>

-------------------------------------

A little clean up to do....

Please Uninstall ComboFix: (if you used it)

Press the Windows logo key + R to bring up the "run box"

Copy and paste next command in the field:

ComboFix /uninstall

Make sure there's a space between Combofix and /

cf2.jpg

Then hit enter.

This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point

(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall)

---------------------------------

Please download OTL from one of the links below: (you may already have OTL on the system)

http://oldtimer.geekstogo.com/OTL.exe

http://oldtimer.geekstogo.com/OTL.com

http://www.itxassoci...T-Tools/OTL.exe

Save it to your desktop.

Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)

Any other programs or logs you can manually delete.

IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, etc....

-------------------------------

Any questions...please post back.

If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum, MrC

Link to post
Share on other sites

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.