C:\Windows\svchost.exe.Trojan.Agent causing blue screen and random crashes do not know how to fix

Inactive
By rlhartzell
Nov 6, 2012
  1. I need help with removing this Trojan and making sure that my computer is alright. I cannot seem to fix it on my own. Malwarebytes detects it each scan and "removes" it but it does not. Please help... I cannot replace this laptop and I need it for school. Thank you
  2. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Malwarebytes Anti-Malware 1.65.1.1000
    www.malwarebytes.org
    Database version: v2012.11.04.05
    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Sunshine :: SUNSHINE-HP [administrator]
    11/6/2012 7:15:31 AM
    mbam-log-2012-11-06 (07-15-31).txt
    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 242279
    Time elapsed: 4 minute(s), 38 second(s)
    Memory Processes Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> 4668 -> Delete on reboot.
    Memory Modules Detected: 0
    (No malicious items detected)
    Registry Keys Detected: 0
    (No malicious items detected)
    Registry Values Detected: 0
    (No malicious items detected)
    Registry Data Items Detected: 0
    (No malicious items detected)
    Folders Detected: 0
    (No malicious items detected)
    Files Detected: 1
    C:\Windows\svchost.exe (Trojan.Agent) -> Delete on reboot.
    (end)
    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2012-11-06 08:35:13
    Windows 6.1.7601 Service Pack 1
    Running: f04bhlw2.exe

    ---- Registry - GMER 1.0.15 ----
    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e4d53dfa1bdb
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e4d53dfa1bdb (not active ControlSet)
    ---- EOF - GMER 1.0.15 ----
    DDS (Ver_2012-11-05.02) - NTFS_AMD64
    Internet Explorer: 9.0.8112.16450
    Run by Sunshine at 8:38:06 on 2012-11-06
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6092.3358 [GMT -5:00]
    .
    AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files\IDT\WDM\STacSV64.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
    C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
    C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe
    C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Windows\system32\taskhost.exe
    C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler.exe
    C:\Program Files (x86)\Google\Update\1.3.21.123\GoogleCrashHandler64.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files (x86)\Secunia\PSI\sua.exe
    C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
    C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
    C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
    C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
    C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe
    \\.\globalroot\systemroot\svchost.exe -netsvcs
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
    C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\splwow64.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Windows\system32\notepad.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files (x86)\Internet Explorer\iexplore.exe
    C:\Windows\system32\svchost.exe -k WbioSvcGroup
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uURLSearchHooks: {462be121-2b54-4218-bf00-b9bf8135b23f} - <orphaned>
    mWinlogon: Userinit = userinit.exe,
    BHO: AutorunsDisabled - <orphaned>
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll
    BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ips\ipsbho.dll
    BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - <orphaned>
    BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll
    BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll
    TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\coieplg.dll
    TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    uRun: [EPSON NX330 Series] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIHAA.EXE /FU "C:\Users\Sunshine\AppData\Local\Temp\E_SEEFF.tmp" /EF "HKCU"
    mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
    mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
    mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
    mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll",ProcessCleanupScript
    dRun: [EPSONE6C464 (Epson Stylus NX330) (Copy 1)] C:\Windows\System32\spool\DRIVERS\x64\3\E_IATIHAA.EXE /FU "C:\Windows\TEMP\E_S6151.tmp" /EF "HKCU"
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\SECUNI~1.LNK - C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect119b.cab
    DPF: {BEA7310D-06C4-4339-A784-DC3804819809} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
    TCP: NameServer = 10.0.0.1
    TCP: Interfaces\{6B80B8EA-1AE3-4E27-9430-4F4955EF6B82} : DHCPNameServer = 40.20.1.201 40.20.1.202
    TCP: Interfaces\{723CC1D6-ED65-4BD7-A980-94E3E460CDAA} : DHCPNameServer = 10.0.0.1
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    SSODL: WebCheck - <orphaned>
    LSA: Notification Packages = scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
    mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
    x64-BHO: TrueSuite Website Log On: {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
    x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
    x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
    x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
    x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
    x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
    x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    x64-IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    x64-Notify: igfxcui - igfxdev.dll
    x64-SSODL: WebCheck - <orphaned>
    x64-mASetup: {0CE7EBAF-157D-4111-9146-057CB2A4023E} - msiexec /fu {0CE7EBAF-157D-4111-9146-057CB2A4023E} /qn
    .
    ============= SERVICES / DRIVERS ===============
    .
    R2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2012-2-21 168448]
    R2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2012-2-21 131072]
    R2 FPLService;TrueSuiteService;C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-8-19 260424]
    R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
    R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-17 682040]
    R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
    R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-9-6 197536]
    R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-30 13592]
    R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-10-30 2425960]
    R2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe [2011-9-28 212944]
    R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccsvchst.exe [2012-10-1 138272]
    R2 Secunia PSI Agent;Secunia PSI Agent;C:\Program Files (x86)\Secunia\PSI\psia.exe [2012-9-24 1328736]
    R2 Secunia Update Agent;Secunia Update Agent;C:\Program Files (x86)\Secunia\PSI\sua.exe [2012-9-24 656480]
    R3 bcbtums;Bluetooth RAM Firmware Download USB Filter;C:\Windows\System32\drivers\bcbtums.sys [2011-10-30 133672]
    R3 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\BASHDefs\20121030.002\BHDrvx64.sys [2012-11-5 1385632]
    R3 btwampfl;btwampfl Bluetooth filter driver;C:\Windows\System32\drivers\btwampfl.sys [2011-10-30 620584]
    R3 BTWDPAN;Bluetooth Personal Area Network;C:\Windows\System32\drivers\btwdpan.sys [2011-10-30 89640]
    R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2011-10-30 39976]
    R3 ccSet_N360;Norton 360 Settings Manager;C:\Windows\System32\drivers\N360x64\0604000.009\ccsetx64.sys [2012-10-1 167072]
    R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2010-7-28 31088]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-8-9 138912]
    R3 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\IPSDefs\20121103.001\IDSviA64.sys [2012-11-6 513184]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2011-8-26 317440]
    R3 PSI;PSI;C:\Windows\System32\drivers\psi_mf.sys [2011-12-16 17976]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-10-30 565352]
    R3 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\0604000.009\symds64.sys [2012-10-1 451192]
    R3 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\0604000.009\symefa64.sys [2012-10-1 1129120]
    R3 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\0604000.009\ironx64.sys [2012-10-1 190072]
    R3 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\0604000.009\symnets.sys [2012-10-1 405624]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
    S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    S3 HP8207_8307;HP-HP8207_8307;C:\Windows\System32\drivers\HP8207_8307.sys [2010-2-4 15360]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-4 19456]
    S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-10-30 339048]
    S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
    S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
    S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-11-4 57856]
    S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-4 30208]
    S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-2-24 1255736]
    S3 WSDScan;WSD Scan Support via UMB;C:\Windows\System32\drivers\WSDScan.sys [2009-7-13 25088]
    S4 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-10-30 2656280]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    .
    =============== Created Last 30 ================
    .
    2012-11-05 18:56:28 20480 ------w- C:\Windows\svchost.exe
    2012-11-05 17:39:19 -------- d-----w- C:\Program Files (x86)\HP
    2012-11-05 03:58:32 -------- d-----w- C:\Windows\pss
    2012-11-04 05:53:58 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    2012-11-04 05:53:58 458712 ----a-w- C:\Windows\System32\drivers\cng.sys
    2012-11-04 05:53:58 340992 ----a-w- C:\Windows\System32\schannel.dll
    2012-11-04 05:53:58 307200 ----a-w- C:\Windows\System32\ncrypt.dll
    2012-11-04 05:53:58 247808 ----a-w- C:\Windows\SysWow64\schannel.dll
    2012-11-04 05:53:58 220160 ----a-w- C:\Windows\SysWow64\ncrypt.dll
    2012-11-04 05:53:58 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
    2012-11-04 05:53:58 154480 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2012-11-04 05:53:58 1448448 ----a-w- C:\Windows\System32\lsasrv.dll
    2012-11-04 05:53:51 514560 ----a-w- C:\Windows\SysWow64\qdvd.dll
    2012-11-04 05:53:50 366592 ----a-w- C:\Windows\System32\qdvd.dll
    2012-11-04 05:48:22 -------- d-----w- C:\Windows\SysWow64\N360_BACKUP
    2012-11-04 04:45:59 -------- d-----w- C:\Users\Sunshine\AppData\Local\Secunia PSI
    2012-11-04 04:45:49 -------- d-----w- C:\Program Files (x86)\Secunia
    2012-11-04 03:41:39 -------- d-----w- C:\Users\Sunshine\AppData\Roaming\Malwarebytes
    2012-11-04 03:41:17 -------- d-----w- C:\ProgramData\Malwarebytes
    2012-11-04 03:41:16 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-11-04 03:41:16 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-11-03 01:06:13 73656 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-11-03 01:06:13 696760 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-11-02 19:00:54 -------- d-sh--w- C:\$RECYCLE.BIN
    2012-10-31 17:33:44 -------- d-----w- C:\Users\Sunshine\AppData\Local\{4619D3FA-A7E4-4EA1-993F-2CF2C632768F}
    2012-10-23 18:31:27 1670656 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM3.dll
    2012-10-23 18:31:27 1668096 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM6.dll
    2012-10-23 18:31:27 1667584 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM5.dll
    2012-10-23 18:31:27 1667072 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM4.dll
    2012-10-23 18:31:27 1666048 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM7.dll
    2012-10-21 08:13:25 -------- d-----w- C:\Users\Sunshine\AppData\Local\Macromedia
    2012-10-21 08:01:31 -------- d-----w- C:\Users\Sunshine\AppData\Local\Mozilla
    2012-10-19 20:03:48 -------- d-----w- C:\Users\Sunshine\.smplayer
    2012-10-19 19:33:58 -------- d-----w- C:\Users\Sunshine\AppData\Roaming\Symantec
    2012-10-19 03:33:13 -------- d-----w- C:\Program Files (x86)\OApps
    2012-10-19 03:32:25 -------- d-----w- C:\Program Files (x86)\Conduit
    2012-10-19 03:32:23 -------- d-----w- C:\Users\Sunshine\AppData\Local\Conduit
    2012-10-10 10:18:57 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
    2012-10-10 10:18:57 2048 ----a-w- C:\Windows\System32\tzres.dll
    2012-10-10 10:18:51 715776 ----a-w- C:\Windows\System32\kerberos.dll
    2012-10-10 10:18:51 542208 ----a-w- C:\Windows\SysWow64\kerberos.dll
    2012-10-10 10:18:46 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
    2012-10-10 10:18:46 1464320 ----a-w- C:\Windows\System32\crypt32.dll
    2012-10-10 10:18:46 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
    2012-10-10 10:18:46 140288 ----a-w- C:\Windows\System32\cryptnet.dll
    2012-10-10 10:18:46 1159680 ----a-w- C:\Windows\SysWow64\crypt32.dll
    2012-10-10 10:18:46 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
    .
    ==================== Find3M ====================
    .
    2012-08-31 18:19:35 1659760 ----a-w- C:\Windows\System32\drivers\ntfs.sys
    2012-08-30 18:03:45 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2012-08-30 17:12:02 3968880 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2012-08-30 17:12:02 3914096 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2012-08-24 18:05:07 220160 ----a-w- C:\Windows\System32\wintrust.dll
    2012-08-24 16:57:48 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
    2012-08-24 10:31:32 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2012-08-24 10:21:18 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-08-24 10:20:11 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-08-24 10:14:45 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-08-24 10:13:29 599040 ----a-w- C:\Windows\System32\vbscript.dll
    2012-08-24 10:09:42 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-08-24 06:59:17 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-08-24 06:51:27 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-08-24 06:51:02 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-08-24 06:47:26 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-08-24 06:47:12 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2012-08-24 06:43:58 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-08-23 14:13:11 243200 ----a-w- C:\Windows\System32\rdpudd.dll
    2012-08-23 14:10:20 19456 ----a-w- C:\Windows\System32\drivers\rdpvideominiport.sys
    2012-08-23 14:08:26 30208 ----a-w- C:\Windows\System32\drivers\TsUsbGD.sys
    2012-08-23 14:07:35 57856 ----a-w- C:\Windows\System32\drivers\TsUsbFlt.sys
    2012-08-23 13:47:20 46592 ----a-w- C:\Windows\SysWow64\MsRdpWebAccess.dll
    2012-08-23 13:46:20 16896 ----a-w- C:\Windows\SysWow64\wksprtPS.dll
    2012-08-23 13:41:52 13312 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
    2012-08-23 13:40:56 13312 ----a-w- C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
    2012-08-23 13:24:57 15360 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
    2012-08-23 13:20:40 54272 ----a-w- C:\Windows\System32\MsRdpWebAccess.dll
    2012-08-23 13:18:14 37376 ----a-w- C:\Windows\SysWow64\tsgqec.dll
    2012-08-23 13:17:54 18432 ----a-w- C:\Windows\System32\wksprtPS.dll
    2012-08-23 13:06:58 43520 ----a-w- C:\Windows\System32\TsUsbGDCoInstaller.dll
    2012-08-23 12:52:53 44032 ----a-w- C:\Windows\System32\tsgqec.dll
    2012-08-23 11:20:06 62976 ----a-w- C:\Windows\System32\TSWbPrxy.exe
    2012-08-23 11:15:57 269312 ----a-w- C:\Windows\SysWow64\aaclient.dll
    2012-08-23 11:14:09 384000 ----a-w- C:\Windows\System32\wksprt.exe
    2012-08-23 11:12:17 192000 ----a-w- C:\Windows\SysWow64\rdpendp_winip.dll
    2012-08-23 10:54:24 322560 ----a-w- C:\Windows\System32\aaclient.dll
    2012-08-23 10:51:14 228864 ----a-w- C:\Windows\System32\rdpendp_winip.dll
    2012-08-23 10:39:24 1048064 ----a-w- C:\Windows\SysWow64\mstsc.exe
    2012-08-23 10:22:22 1123840 ----a-w- C:\Windows\System32\mstsc.exe
    2012-08-23 09:51:57 3174912 ----a-w- C:\Windows\System32\rdpcorets.dll
    2012-08-23 08:19:01 4916224 ----a-w- C:\Windows\SysWow64\mstscax.dll
    2012-08-23 08:13:07 5773824 ----a-w- C:\Windows\System32\mstscax.dll
    2012-08-22 18:12:50 1913200 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2012-08-22 18:12:40 950128 ----a-w- C:\Windows\System32\drivers\ndis.sys
    2012-08-22 18:12:40 376688 ----a-w- C:\Windows\System32\drivers\netio.sys
    2012-08-22 18:12:33 288624 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
    2012-08-21 21:01:00 245760 ----a-w- C:\Windows\System32\OxpsConverter.exe
    2012-08-20 18:48:44 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2012-08-20 18:48:44 243200 ----a-w- C:\Windows\System32\wow64.dll
    2012-08-20 18:48:44 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2012-08-20 18:48:43 215040 ----a-w- C:\Windows\System32\winsrv.dll
    2012-08-20 18:48:37 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2012-08-20 18:48:35 424448 ----a-w- C:\Windows\System32\KernelBase.dll
    2012-08-20 18:46:22 338432 ----a-w- C:\Windows\System32\conhost.exe
    2012-08-20 17:40:21 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2012-08-20 17:38:44 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2012-08-20 17:38:26 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2012-08-20 17:37:19 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2012-08-20 17:37:18 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2012-08-20 15:38:21 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2012-08-20 15:38:20 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2012-08-20 15:33:28 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2012-08-20 15:33:28 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2012-08-20 15:33:28 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2012-08-20 15:33:28 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    .
    ============= FINISH: 8:38:38.30 ===============
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-05.02)
    .
    Microsoft Windows 7 Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2/21/2012 9:54:16 PM
    System Uptime: 11/6/2012 7:12:14 AM (1 hours ago)
    .
    Motherboard: Hewlett-Packard | | 1671
    Processor: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz | CPU1 | 1587/1333mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 674 GiB total, 617.971 GiB free.
    D: is FIXED (NTFS) - 20 GiB total, 2.172 GiB free.
    F: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP55: 10/19/2012 3:47:09 PM - Removed Blio.
    RP56: 10/29/2012 12:19:28 PM - Removed Broadcom Bluetooth Software
    RP57: 11/1/2012 3:44:15 PM - HPSF Applying updates
    RP58: 11/2/2012 5:54:08 PM - Windows Backup
    RP59: 11/2/2012 9:04:06 PM - Removed Adobe Reader X (10.1.4) MUI.
    RP60: 11/4/2012 12:46:31 AM - Norton 360 Registry Clean
    RP61: 11/4/2012 12:56:30 AM - Windows Update
    RP62: 11/4/2012 7:00:20 PM - Windows Backup
    RP63: 11/5/2012 12:55:56 PM - Installed HP Application Assistant.
    RP64: 11/5/2012 12:58:22 PM - Installed HP Software Framework
    .
    ==== Installed Programs ======================
    .
    Adobe Reader XI
    Adobe Shockwave Player 11.6
    AuthenTec TrueAPI
    Bejeweled 3
    Blackhawk Striker 2
    Broadcom 802.11 Wireless LAN Adapter
    Broadcom Bluetooth Software
    Broadcom InConcert Maestro
    Chuzzle Deluxe
    Coupon Printer for Windows
    Cradle of Rome 2
    CyberLink YouCam
    D3DX10
    Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
    Dora's World Adventure
    EPSON NX330 Series Printer Uninstall
    EPSON Scan
    ESU for Microsoft Windows 7 SP1
    Evernote v. 4.2.3
    Farm Frenzy
    Farmscapes
    FATE
    Final Drive Fury
    Google Chrome
    Google Talk Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    Hewlett-Packard ACLM.NET v1.1.2.0
    Hoyle Card Games
    HP Application Assistant
    HP Auto
    HP Client Services
    HP Customer Experience Enhancements
    HP Documentation
    HP Games
    HP Launch Box
    HP MovieStore
    HP On Screen Display
    HP Power Manager
    HP Product Detection
    HP Quick Launch
    HP QuickWeb
    HP Recovery Manager
    HP Security Assistant
    HP Setup
    HP Setup Manager
    HP SimplePass PE 2011
    HP Software Framework
    HP Support Assistant
    IDT Audio
    Intel(R) Control Center
    Intel(R) Identity Protection Technology 1.2.22.0
    Intel(R) Management Engine Components
    Intel(R) Processor Graphics
    Intel(R) Rapid Storage Technology
    Internet Explorer (Enable DEP)
    Java Auto Updater
    Jewel Match 3
    Jewel Quest Mysteries: The Seventh Gate Collector's Edition
    John Deere Drive Green
    Junk Mail filter update
    Letters from Nowhere 2
    Luxor HD
    Mah Jong Medley
    Malwarebytes Anti-Malware version 1.65.1.1000
    Mesh Runtime
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Office 2010 Service Pack 1 (SP1)
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Home and Student 2010
    Microsoft Office Office 64-bit Components 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared 64-bit MUI (English) 2010
    Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Single Image 2010
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable (x64)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
    Microsoft WSE 3.0 Runtime
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Norton 360
    opensource
    Penguins!
    Plants vs. Zombies - Game of the Year
    PlayReady PC Runtime x86
    Poker Superstars III
    Polar Bowler
    Polar Golfer
    Realtek Ethernet Controller Driver
    Realtek PCIE Card Reader
    RollerCoaster Tycoon 3: Platinum
    Secunia PSI (3.0.0.4001)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft Excel 2010 (KB2597166) 32-Bit Edition
    Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553091)
    Security Update for Microsoft Office 2010 (KB2553096)
    Security Update for Microsoft Office 2010 (KB2553260) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2589322) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
    Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
    Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition
    Security Update for Microsoft SharePoint Workspace 2010 (KB2566445)
    Security Update for Microsoft Visio Viewer 2010 (KB2598287) 32-Bit Edition
    Security Update for Microsoft Word 2010 (KB2553488) 32-Bit Edition
    Skype™ 5.10
    swMSM
    Synaptics TouchPad Driver
    The Treasures of Mystery Island: The Ghost Ship
    Torchlight
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Update for Microsoft Office 2010 (KB2553065)
    Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553272) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2566458)
    Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
    Update for Microsoft Office 2010 (KB2598289) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
    Update for Microsoft OneNote 2010 (KB2589345) 32-Bit Edition
    Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition
    Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
    Update Installer for WildTangent Games App
    Virtual Villagers 4 - The Tree of Life
    WildTangent Games App (HP Games)
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Language Selector
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live Remote Client
    Windows Live Remote Client Resources
    Windows Live Remote Service
    Windows Live Remote Service Resources
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Zuma's Revenge
    .
    ==== Event Viewer Messages From Past Week ========
    .
    11/5/2012 12:37:40 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    11/5/2012 12:23:32 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
    11/5/2012 12:23:32 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
    11/5/2012 10:38:44 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the HPAuto service.
    11/4/2012 9:37:03 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
    11/4/2012 9:36:53 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000096, 0xfffff80002ec316a, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110412-24102-01.
    11/4/2012 3:44:43 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} and APPID {9BA05972-F6A8-11CF-A442-00A0C90A8F39} to the user Sunshine-HP\Sunshine SID (S-1-5-21-2287709962-1369759385-1701767626-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    11/4/2012 12:32:57 AM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    11/4/2012 12:29:16 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    11/4/2012 11:23:00 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service COMSysApp with arguments "" in order to run the server: {ECABAFB9-7F19-11D2-978E-0000F8757E2A}
    11/4/2012 11:22:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service COMSysApp with arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
    11/4/2012 11:22:48 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service COMSysApp with arguments "" in order to run the server: {182C40F0-32E4-11D0-818B-00A0C9231C29}
    11/4/2012 11:18:09 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
    11/4/2012 11:10:11 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    11/4/2012 10:53:50 PM, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
    11/4/2012 10:53:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    11/4/2012 10:53:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    11/4/2012 10:53:46 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    11/4/2012 10:53:28 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    11/4/2012 10:53:27 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\bcmihvsrv64.dll Error Code: 21
    11/4/2012 10:53:18 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom discache spldr Wanarpv6
    11/4/2012 10:53:11 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8000317763a, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110412-20264-01.
    11/4/2012 10:00:45 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: discache spldr Wanarpv6
    11/4/2012 1:37:10 AM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107.
    11/4/2012 1:37:10 AM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
    11/3/2012 8:15:58 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031db63a, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110312-36987-01.
    11/3/2012 11:54:49 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    11/3/2012 11:54:49 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    11/3/2012 11:54:28 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8000317763a, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110412-38766-01.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC discache NetBIOS NetBT nsiproxy Psched rdbss spldr tdx vwififlt Wanarpv6 WfpLwf
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    11/3/2012 11:54:24 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    11/3/2012 11:32:34 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa80091b1bb0, 0x0000000000000000, 0x000000007ef88000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110412-26036-01.
    11/3/2012 11:31:35 AM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
    11/1/2012 10:03:24 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff800031da63a, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 110112-19515-01.
    10/30/2012 11:14:44 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff8000305cdd7, 0xfffff880033cb928, 0xfffff880033cb180). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 103012-29827-01.
    .
    ==== End Of File ===========================
  3. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Hello, and welcome to TechSpot.


    [​IMG] Please see here for the board rules and other FAQ.

    Please feel free to introduce yourself, after you follow the steps below to get started.

    Information
    • From this point on, please do not make any more changes to your computer; such as install/uninstall programs, use special fix tools, delete files, edit the registry, etc. - unless advised by a malware removal helper.
    • Please do not ask for help elsewhere (in this site or other sites). Doing so can result in system changes, which may not show up in the logs you post.
    • If you have already asked for help somewhere, please post the link to the topic you were helped.
    • We try our best to reply quickly, but for any reason we do not reply in two days, please reply to this topic with the word BUMP!
    • Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal. Persist in this topic until its close, and your computer is declared clean.

    ComboFix scan

    Please download ComboFix[​IMG] by sUBs
    From BleepingComputer.com

    Please save the file to your Desktop.

    Important information about ComboFix


    After the download:
    • Close any open browsers.
    • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Please visit here if you don't know how.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
    • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.
    Running ComboFix:
    • Double click on ComboFix.exe & follow the prompts.
    • When ComboFix finishes, it will produce a report for you.
    • Please post the report, which will launch or be found at "C:\Combo-Fix.txt" in your next reply.
    Troubleshooting ComboFix

    Safe Mode:

    If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

    (To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
    logo appears. A list of options will appear, select "Safe Mode.")

    Re-downloading:

    If this doesn't work either, try the same method (above method), but try to download it again, except name
    ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

    Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.

    NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
  4. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    ComboFix 12-11-06.03 - Sunshine 11/06/2012 17:01:56.1.4 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.6092.4519 [GMT -5:00]
    Running from: c:\users\Sunshine\Desktop\ComboFix.exe
    AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
    FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
    SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Sunshine\AppData\Roaming\JomCap.dll
    c:\users\Sunshine\Documents\~WRL2154.tmp
    c:\windows\svchost.exe
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-10-06 to 2012-11-06 )))))))))))))))))))))))))))))))
    .
    .
    2012-11-06 22:09 . 2012-11-06 22:09 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-11-05 17:39 . 2012-11-05 17:39 -------- d-----w- c:\program files (x86)\HP
    2012-11-04 05:53 . 2012-08-24 18:13 154480 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
    2012-11-04 05:53 . 2012-08-24 18:09 458712 ----a-w- c:\windows\system32\drivers\cng.sys
    2012-11-04 05:53 . 2012-08-24 18:05 340992 ----a-w- c:\windows\system32\schannel.dll
    2012-11-04 05:53 . 2012-08-24 18:04 307200 ----a-w- c:\windows\system32\ncrypt.dll
    2012-11-04 05:53 . 2012-08-24 18:03 1448448 ----a-w- c:\windows\system32\lsasrv.dll
    2012-11-04 05:53 . 2012-08-24 16:57 247808 ----a-w- c:\windows\SysWow64\schannel.dll
    2012-11-04 05:53 . 2012-08-24 16:57 22016 ----a-w- c:\windows\SysWow64\secur32.dll
    2012-11-04 05:53 . 2012-08-24 16:57 220160 ----a-w- c:\windows\SysWow64\ncrypt.dll
    2012-11-04 05:53 . 2012-08-24 16:53 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
    2012-11-04 05:53 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
    2012-11-04 05:53 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
    2012-11-04 05:48 . 2012-11-04 05:48 -------- d-----w- c:\windows\SysWow64\N360_BACKUP
    2012-11-04 04:45 . 2012-11-04 04:45 -------- d-----w- c:\users\Sunshine\AppData\Local\Secunia PSI
    2012-11-04 04:45 . 2012-11-04 04:45 -------- d-----w- c:\program files (x86)\Secunia
    2012-11-04 03:41 . 2012-11-04 03:41 -------- d-----w- c:\users\Sunshine\AppData\Roaming\Malwarebytes
    2012-11-04 03:41 . 2012-11-04 03:41 -------- d-----w- c:\programdata\Malwarebytes
    2012-11-04 03:41 . 2012-11-05 03:06 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-11-04 03:41 . 2012-09-30 00:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-11-03 01:06 . 2012-11-06 13:58 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-11-03 01:06 . 2012-11-06 13:58 697272 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-10-30 02:47 . 2012-10-30 02:47 -------- d-----w- c:\windows\Sun
    2012-10-29 18:41 . 2012-11-01 00:50 -------- d-----w- c:\users\Kiddos
    2012-10-21 08:13 . 2012-10-21 08:13 -------- d-----w- c:\users\Sunshine\AppData\Local\Macromedia
    2012-10-21 08:01 . 2012-10-21 08:01 -------- d-----w- c:\users\Sunshine\AppData\Local\Mozilla
    2012-10-19 20:03 . 2012-10-19 20:03 -------- d-----w- c:\users\Sunshine\.smplayer
    2012-10-19 19:33 . 2012-10-19 19:33 -------- d-----w- c:\users\Sunshine\AppData\Roaming\Symantec
    2012-10-19 03:33 . 2012-11-04 04:15 -------- d-----w- c:\program files (x86)\OApps
    2012-10-19 03:32 . 2012-10-19 03:32 -------- d-----w- c:\program files (x86)\Conduit
    2012-10-19 03:32 . 2012-10-19 19:33 -------- d-----w- c:\users\Sunshine\AppData\Local\Conduit
    2012-10-10 10:18 . 2012-09-14 19:19 2048 ----a-w- c:\windows\system32\tzres.dll
    2012-10-10 10:18 . 2012-09-14 18:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2012-10-10 10:18 . 2012-08-11 00:56 715776 ----a-w- c:\windows\system32\kerberos.dll
    2012-10-10 10:18 . 2012-08-10 23:56 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
    2012-10-10 10:18 . 2012-06-02 05:41 184320 ----a-w- c:\windows\system32\cryptsvc.dll
    2012-10-10 10:18 . 2012-06-02 05:41 140288 ----a-w- c:\windows\system32\cryptnet.dll
    2012-10-10 10:18 . 2012-06-02 05:41 1464320 ----a-w- c:\windows\system32\crypt32.dll
    2012-10-10 10:18 . 2012-06-02 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
    2012-10-10 10:18 . 2012-06-02 04:36 1159680 ----a-w- c:\windows\SysWow64\crypt32.dll
    2012-10-10 10:18 . 2012-06-02 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-10-11 16:58 . 2012-02-24 12:43 65309168 ----a-w- c:\windows\system32\MRT.exe
    2012-08-24 11:15 . 2012-09-21 20:40 17810944 ----a-w- c:\windows\system32\mshtml.dll
    2012-08-24 10:39 . 2012-09-21 20:40 10925568 ----a-w- c:\windows\system32\ieframe.dll
    2012-08-24 10:31 . 2012-09-21 20:40 2312704 ----a-w- c:\windows\system32\jscript9.dll
    2012-08-24 10:22 . 2012-09-21 20:40 1346048 ----a-w- c:\windows\system32\urlmon.dll
    2012-08-24 10:21 . 2012-09-21 20:40 1392128 ----a-w- c:\windows\system32\wininet.dll
    2012-08-24 10:20 . 2012-09-21 20:40 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-08-24 10:18 . 2012-09-21 20:40 237056 ----a-w- c:\windows\system32\url.dll
    2012-08-24 10:17 . 2012-09-21 20:40 85504 ----a-w- c:\windows\system32\jsproxy.dll
    2012-08-24 10:14 . 2012-09-21 20:40 173056 ----a-w- c:\windows\system32\ieUnatt.exe
    2012-08-24 10:14 . 2012-09-21 20:40 816640 ----a-w- c:\windows\system32\jscript.dll
    2012-08-24 10:13 . 2012-09-21 20:40 599040 ----a-w- c:\windows\system32\vbscript.dll
    2012-08-24 10:12 . 2012-09-21 20:40 2144768 ----a-w- c:\windows\system32\iertutil.dll
    2012-08-24 10:11 . 2012-09-21 20:40 729088 ----a-w- c:\windows\system32\msfeeds.dll
    2012-08-24 10:10 . 2012-09-21 20:40 96768 ----a-w- c:\windows\system32\mshtmled.dll
    2012-08-24 10:09 . 2012-09-21 20:40 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2012-08-24 10:04 . 2012-09-21 20:40 248320 ----a-w- c:\windows\system32\ieui.dll
    2012-08-24 06:59 . 2012-09-21 20:40 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
    2012-08-24 06:51 . 2012-09-21 20:40 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
    2012-08-24 06:51 . 2012-09-21 20:40 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
    2012-08-24 06:47 . 2012-09-21 20:40 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
    2012-08-24 06:47 . 2012-09-21 20:40 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
    2012-08-24 06:43 . 2012-09-21 20:40 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
    2012-08-22 18:12 . 2012-09-11 21:01 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
    2012-08-22 18:12 . 2012-09-11 21:01 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
    2012-08-22 18:12 . 2012-09-11 21:01 376688 ----a-w- c:\windows\system32\drivers\netio.sys
    2012-08-22 18:12 . 2012-09-11 21:01 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
    2012-08-21 21:01 . 2012-09-26 11:24 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
    2012-08-20 17:38 . 2012-10-10 10:19 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "HPQuickWebProxy"="c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-10-08 169528]
    "HPOSD"="c:\program files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe" [2011-08-19 379960]
    "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-03-05 578944]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2011-9-20 1338144]
    Secunia PSI Tray.lnk - c:\program files (x86)\Secunia\PSI\psi_tray.exe [2012-9-24 573536]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli c:\program files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
    .
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
    R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    R3 HP8207_8307;HP-HP8207_8307;c:\windows\system32\DRIVERS\HP8207_8307.sys [2010-02-05 15360]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
    R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys [2011-09-02 339048]
    R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
    R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
    R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-02-25 1255736]
    R3 WSDScan;WSD Scan Support via UMB;c:\windows\system32\DRIVERS\WSDScan.sys [2009-07-14 25088]
    R4 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
    S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE [2011-01-12 168448]
    S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE [2011-01-12 131072]
    S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-08-19 260424]
    S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]
    S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
    S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
    S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-09-06 197536]
    S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-03-05 35200]
    S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-04-30 13592]
    S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2011-09-01 2425960]
    S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-09-28 212944]
    S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe [2012-06-16 138272]
    S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files (x86)\Secunia\PSI\PSIA.exe [2012-09-24 1328736]
    S2 Secunia Update Agent;Secunia Update Agent;c:\program files (x86)\Secunia\PSI\sua.exe [2012-09-24 656480]
    S3 bcbtums;Bluetooth RAM Firmware Download USB Filter;c:\windows\system32\drivers\bcbtums.sys [2011-09-21 133672]
    S3 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\BASHDefs\20121030.002\BHDrvx64.sys [2012-10-05 1385632]
    S3 btwampfl;btwampfl Bluetooth filter driver;c:\windows\system32\drivers\btwampfl.sys [2011-09-21 620584]
    S3 BTWDPAN;Bluetooth Personal Area Network;c:\windows\system32\DRIVERS\btwdpan.sys [2011-09-21 89640]
    S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-09-21 39976]
    S3 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys [2012-06-07 167072]
    S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-07-28 31088]
    S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-09 138912]
    S3 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\IPSDefs\20121103.001\IDSvia64.sys [2012-10-30 513184]
    S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2011-08-26 317440]
    S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2011-12-16 17976]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-08-24 565352]
    S3 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS [2012-01-17 451192]
    S3 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS [2012-05-22 1129120]
    S3 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS [2012-01-17 190072]
    S3 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS [2012-01-17 405624]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-11-06 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-03 13:58]
    .
    2012-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-27 20:07]
    .
    2012-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-27 20:07]
    .
    2012-11-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2287709962-1369759385-1701767626-1001Core.job
    - c:\users\Sunshine\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-26 00:20]
    .
    2012-11-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2287709962-1369759385-1701767626-1001UA.job
    - c:\users\Sunshine\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-26 00:20]
    .
    2012-11-05 c:\windows\Tasks\HPCeeScheduleForSUNSHINE-HP$.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 11:43]
    .
    2012-11-01 c:\windows\Tasks\HPCeeScheduleForSunshine.job
    - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 11:43]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-26 392472]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-26 416024]
    "SetDefault"="c:\program files\Hewlett-Packard\HP LaunchBox\SetDefault.exe" [2011-12-20 44880]
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    TCP: DhcpNameServer = 10.0.0.1
    .
    - - - - ORPHANS REMOVED - - - -
    .
    HKLM_Wow6432Node-ActiveSetup-{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec
    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
    AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
    "ImagePath"="\"c:\program files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\6.4.0.9\diMaster.dll\" /prefetch:1"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_110_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_110_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.11"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_110.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker5"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
    @Denied: (A) (Everyone)
    "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
    @Denied: (A) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
    "Key"="ActionsPane3"
    "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2012-11-06 17:12:52
    ComboFix-quarantined-files.txt 2012-11-06 22:12
    .
    Pre-Run: 663,399,575,552 bytes free
    Post-Run: 663,381,708,800 bytes free
    .
    - - End Of File - - 9B44BCE09DEF3EA57EEC76ADB4A0BEF0
  5. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Great work! Now to kill the main infection...

    TDSSKiller Scan

    Please download and run TDSSKiller to your desktop as outlined below:

    Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.

    For Windows XP, double-click to start.
    For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

    [​IMG]

    -------------------------

    Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

    [​IMG]

    ------------------------

    Click the Start Scan button.

    [​IMG]

    -----------------------

    If a suspicious object is detected, the default action will be Skip, click on Continue
    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue


    [​IMG]

    ----------------------

    If malicious objects are found, they will show in the Scan results and offer three (3) options.

    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.


    [​IMG]


    --------------------

    A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
    Sometimes these logs can be very large, in that case please attach it or zip it up and attach it.

    -------------------

    Here's a summary of what to do if you would like to print it out:

    If a suspicious object is detected, the default action will be Skip, click on Continue
    If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose
    Skip and click on Continue

    If malicious objects are found, they will show in the Scan results and offer three (3) options.

    Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.


    avast! aswMBR

    Please download aswMBR from here
    • Save aswMBR.exe to your Desktop
    • Double click aswMBR.exe to run it
    • Uncheck "Trace disk IO calls".
    • Click the Scan button to start the scan as illustrated below
    [​IMG]
    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives.
    • Once the scan finishes click Save log to save the log to your Desktop
      [​IMG]
    • Copy and paste the contents of aswMBR.txt back here for review
    • Please also find MBR.dat on your Desktop, and rename it to MBRscan.txt. Upload that as well. Do not copy and paste MBR.dat/txt, it needs to be uploaded.
  6. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    17:11:11.0398 9708 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
    17:11:12.0421 9708 ============================================================
    17:11:12.0421 9708 Current date / time: 2012/11/07 17:11:12.0421
    17:11:12.0421 9708 SystemInfo:
    17:11:12.0422 9708
    17:11:12.0422 9708 OS Version: 6.1.7601 ServicePack: 1.0
    17:11:12.0422 9708 Product type: Workstation
    17:11:12.0422 9708 ComputerName: SUNSHINE-HP
    17:11:12.0422 9708 UserName: Sunshine
    17:11:12.0422 9708 Windows directory: C:\Windows
    17:11:12.0422 9708 System windows directory: C:\Windows
    17:11:12.0422 9708 Running under WOW64
    17:11:12.0422 9708 Processor architecture: Intel x64
    17:11:12.0422 9708 Number of processors: 4
    17:11:12.0422 9708 Page size: 0x1000
    17:11:12.0422 9708 Boot type: Normal boot
    17:11:12.0422 9708 ============================================================
    17:11:12.0958 9708 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    17:11:12.0963 9708 ============================================================
    17:11:12.0963 9708 \Device\Harddisk0\DR0:
    17:11:12.0964 9708 MBR partitions:
    17:11:12.0964 9708 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
    17:11:12.0964 9708 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x544D2800
    17:11:12.0964 9708 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x54536800, BlocksNum 0x2820000
    17:11:12.0964 9708 ============================================================
    17:11:12.0998 9708 C: <-> \Device\Harddisk0\DR0\Partition2
    17:11:13.0035 9708 D: <-> \Device\Harddisk0\DR0\Partition3
    17:11:13.0035 9708 ============================================================
    17:11:13.0036 9708 Initialize success
    17:11:13.0036 9708 ============================================================
    17:12:37.0152 2252 ============================================================
    17:12:37.0152 2252 Scan started
    17:12:37.0152 2252 Mode: Manual; SigCheck; TDLFS;
    17:12:37.0152 2252 ============================================================
    17:12:37.0685 2252 ================ Scan system memory ========================
    17:12:37.0685 2252 System memory - ok
    17:12:37.0687 2252 ================ Scan services =============================
    17:12:37.0919 2252 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
    17:12:38.0070 2252 1394ohci - ok
    17:12:38.0099 2252 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
    17:12:38.0116 2252 ACPI - ok
    17:12:38.0136 2252 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
    17:12:38.0184 2252 AcpiPmi - ok
    17:12:38.0298 2252 [ B1EA9681502EE57F87DB71D726288A5B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    17:12:38.0325 2252 AdobeARMservice - ok
    17:12:38.0485 2252 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    17:12:38.0512 2252 AdobeFlashPlayerUpdateSvc - ok
    17:12:38.0584 2252 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    17:12:38.0618 2252 adp94xx - ok
    17:12:38.0650 2252 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
    17:12:38.0666 2252 adpahci - ok
    17:12:38.0687 2252 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    17:12:38.0701 2252 adpu320 - ok
    17:12:38.0733 2252 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    17:12:38.0797 2252 AeLookupSvc - ok
    17:12:38.0854 2252 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
    17:12:38.0889 2252 AFD - ok
    17:12:38.0928 2252 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
    17:12:38.0939 2252 agp440 - ok
    17:12:38.0972 2252 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
    17:12:39.0019 2252 ALG - ok
    17:12:39.0073 2252 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
    17:12:39.0083 2252 aliide - ok
    17:12:39.0110 2252 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
    17:12:39.0121 2252 amdide - ok
    17:12:39.0164 2252 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
    17:12:39.0176 2252 AmdK8 - ok
    17:12:39.0188 2252 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
    17:12:39.0216 2252 AmdPPM - ok
    17:12:39.0258 2252 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    17:12:39.0287 2252 amdsata - ok
    17:12:39.0319 2252 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
    17:12:39.0341 2252 amdsbs - ok
    17:12:39.0356 2252 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    17:12:39.0371 2252 amdxata - ok
    17:12:39.0416 2252 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
    17:12:39.0500 2252 AppID - ok
    17:12:39.0547 2252 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    17:12:39.0607 2252 AppIDSvc - ok
    17:12:39.0647 2252 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
    17:12:39.0725 2252 Appinfo - ok
    17:12:39.0765 2252 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
    17:12:39.0780 2252 arc - ok
    17:12:39.0817 2252 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
    17:12:39.0844 2252 arcsas - ok
    17:12:39.0873 2252 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    17:12:39.0917 2252 AsyncMac - ok
    17:12:39.0933 2252 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
    17:12:39.0943 2252 atapi - ok
    17:12:39.0981 2252 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    17:12:40.0021 2252 AudioEndpointBuilder - ok
    17:12:40.0031 2252 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    17:12:40.0068 2252 AudioSrv - ok
    17:12:40.0095 2252 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
    17:12:40.0186 2252 AxInstSV - ok
    17:12:40.0233 2252 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
    17:12:40.0281 2252 b06bdrv - ok
    17:12:40.0302 2252 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
    17:12:40.0335 2252 b57nd60a - ok
    17:12:40.0379 2252 [ 09A19C806110CE839111850EC27E65F5 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys
    17:12:40.0398 2252 bcbtums - ok
    17:12:40.0532 2252 [ 461E574D7967E895640109A371A912A5 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
    17:12:40.0616 2252 BCM43XX - ok
    17:12:40.0659 2252 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
    17:12:40.0702 2252 BDESVC - ok
    17:12:40.0743 2252 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
    17:12:40.0786 2252 Beep - ok
    17:12:40.0842 2252 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
    17:12:40.0894 2252 BFE - ok
    17:12:41.0113 2252 [ 652F4D186325B69FFE80EE18AE9ACC77 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\BASHDefs\20121030.002\BHDrvx64.sys
    17:12:41.0164 2252 BHDrvx64 - ok
    17:12:41.0211 2252 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
    17:12:41.0271 2252 BITS - ok
    17:12:41.0318 2252 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
    17:12:41.0345 2252 blbdrive - ok
    17:12:41.0393 2252 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    17:12:41.0436 2252 bowser - ok
    17:12:41.0471 2252 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
    17:12:41.0487 2252 BrFiltLo - ok
    17:12:41.0500 2252 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
    17:12:41.0525 2252 BrFiltUp - ok
    17:12:41.0580 2252 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
    17:12:41.0656 2252 BridgeMP - ok
    17:12:41.0696 2252 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
    17:12:41.0717 2252 Browser - ok
    17:12:41.0746 2252 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
    17:12:41.0786 2252 Brserid - ok
    17:12:41.0820 2252 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    17:12:41.0855 2252 BrSerWdm - ok
    17:12:41.0865 2252 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    17:12:41.0892 2252 BrUsbMdm - ok
    17:12:41.0914 2252 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
    17:12:41.0928 2252 BrUsbSer - ok
    17:12:41.0980 2252 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
    17:12:42.0035 2252 BthEnum - ok
    17:12:42.0070 2252 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
    17:12:42.0098 2252 BTHMODEM - ok
    17:12:42.0115 2252 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
    17:12:42.0152 2252 BthPan - ok
    17:12:42.0180 2252 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
    17:12:42.0208 2252 BTHPORT - ok
    17:12:42.0246 2252 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
    17:12:42.0305 2252 bthserv - ok
    17:12:42.0327 2252 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
    17:12:42.0355 2252 BTHUSB - ok
    17:12:42.0391 2252 [ 0E78584D5FACA0509DFA97BD8B635075 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys
    17:12:42.0409 2252 btwampfl - ok
    17:12:42.0425 2252 [ 409C4117E6027672EF41E68ACE1468AD ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
    17:12:42.0435 2252 btwaudio - ok
    17:12:42.0456 2252 [ 8CA7CABD13316ABACE386D9F380B4CF3 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
    17:12:42.0467 2252 btwavdt - ok
    17:12:42.0640 2252 [ 1249EDE2280F9A1564C946AFDDCD59D5 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    17:12:42.0684 2252 btwdins - ok
    17:12:42.0730 2252 [ 41933521A618475644B6E8D8487AF326 ] BTWDPAN C:\Windows\system32\DRIVERS\btwdpan.sys
    17:12:42.0740 2252 BTWDPAN - ok
    17:12:42.0757 2252 [ B9354F9F111C64F2495B60F1E24CB453 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
    17:12:42.0766 2252 btwl2cap - ok
    17:12:42.0786 2252 [ 71A04F2D9DEB21B162561EB574D7D629 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
    17:12:42.0794 2252 btwrchid - ok
    17:12:42.0829 2252 catchme - ok
    17:12:42.0909 2252 [ 2C6FFCCA37B002AAB3C7C31A6D780A76 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys
    17:12:42.0919 2252 ccSet_N360 - ok
    17:12:42.0960 2252 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    17:12:43.0005 2252 cdfs - ok
    17:12:43.0037 2252 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    17:12:43.0061 2252 cdrom - ok
    17:12:43.0102 2252 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
    17:12:43.0148 2252 CertPropSvc - ok
    17:12:43.0176 2252 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
    17:12:43.0206 2252 circlass - ok
    17:12:43.0251 2252 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
    17:12:43.0267 2252 CLFS - ok
    17:12:43.0317 2252 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    17:12:43.0341 2252 clr_optimization_v2.0.50727_32 - ok
    17:12:43.0374 2252 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    17:12:43.0389 2252 clr_optimization_v2.0.50727_64 - ok
    17:12:43.0462 2252 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    17:12:43.0476 2252 clr_optimization_v4.0.30319_32 - ok
    17:12:43.0515 2252 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    17:12:43.0526 2252 clr_optimization_v4.0.30319_64 - ok
    17:12:43.0549 2252 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
    17:12:43.0558 2252 clwvd - ok
    17:12:43.0590 2252 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
    17:12:43.0617 2252 CmBatt - ok
    17:12:43.0629 2252 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
    17:12:43.0639 2252 cmdide - ok
    17:12:43.0685 2252 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
    17:12:43.0722 2252 CNG - ok
    17:12:43.0778 2252 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
    17:12:43.0791 2252 Compbatt - ok
    17:12:43.0828 2252 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
    17:12:43.0863 2252 CompositeBus - ok
    17:12:43.0885 2252 COMSysApp - ok
    17:12:43.0898 2252 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
    17:12:43.0911 2252 crcdisk - ok
    17:12:43.0965 2252 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
    17:12:43.0994 2252 CryptSvc - ok
    17:12:44.0031 2252 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
    17:12:44.0073 2252 DcomLaunch - ok
    17:12:44.0102 2252 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
    17:12:44.0158 2252 defragsvc - ok
    17:12:44.0196 2252 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    17:12:44.0240 2252 DfsC - ok
    17:12:44.0276 2252 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
    17:12:44.0337 2252 Dhcp - ok
    17:12:44.0363 2252 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
    17:12:44.0407 2252 discache - ok
    17:12:44.0443 2252 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
    17:12:44.0454 2252 Disk - ok
    17:12:44.0495 2252 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    17:12:44.0618 2252 Dnscache - ok
    17:12:44.0642 2252 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
    17:12:44.0718 2252 dot3svc - ok
    17:12:44.0741 2252 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
    17:12:44.0794 2252 DPS - ok
    17:12:44.0835 2252 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    17:12:44.0883 2252 drmkaud - ok
    17:12:44.0930 2252 [ A4F408AD1065C7AD2ED332C68025B435 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    17:12:44.0961 2252 DXGKrnl - ok
    17:12:44.0991 2252 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
    17:12:45.0042 2252 EapHost - ok
    17:12:45.0112 2252 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
    17:12:45.0169 2252 ebdrv - ok
    17:12:45.0262 2252 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    17:12:45.0293 2252 eeCtrl - ok
    17:12:45.0323 2252 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
    17:12:45.0344 2252 EFS - ok
    17:12:45.0413 2252 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    17:12:45.0477 2252 ehRecvr - ok
    17:12:45.0481 2252 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
    17:12:45.0511 2252 ehSched - ok
    17:12:45.0555 2252 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
    17:12:45.0575 2252 elxstor - ok
    17:12:45.0648 2252 [ 7C5BFAAC8DCE7292B0C04EBF892E71F9 ] EPSON_EB_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
    17:12:45.0702 2252 EPSON_EB_RPCV4_04 - ok
    17:12:45.0711 2252 [ D4615670CD49A1679E6067F155C47C68 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
    17:12:45.0737 2252 EPSON_PM_RPCV4_04 - ok
    17:12:45.0770 2252 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    17:12:45.0783 2252 EraserUtilRebootDrv - ok
    17:12:45.0816 2252 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
    17:12:45.0859 2252 ErrDev - ok
    17:12:45.0930 2252 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
    17:12:45.0982 2252 EventSystem - ok
    17:12:46.0025 2252 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
    17:12:46.0061 2252 exfat - ok
    17:12:46.0079 2252 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
    17:12:46.0126 2252 fastfat - ok
    17:12:46.0176 2252 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
    17:12:46.0217 2252 Fax - ok
    17:12:46.0261 2252 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
    17:12:46.0300 2252 fdc - ok
    17:12:46.0346 2252 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
    17:12:46.0405 2252 fdPHost - ok
    17:12:46.0418 2252 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
    17:12:46.0451 2252 FDResPub - ok
    17:12:46.0479 2252 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    17:12:46.0491 2252 FileInfo - ok
    17:12:46.0503 2252 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    17:12:46.0551 2252 Filetrace - ok
    17:12:46.0577 2252 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
    17:12:46.0588 2252 flpydisk - ok
    17:12:46.0594 2252 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    17:12:46.0610 2252 FltMgr - ok
    17:12:46.0657 2252 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
    17:12:46.0709 2252 FontCache - ok
    17:12:46.0766 2252 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    17:12:46.0776 2252 FontCache3.0.0.0 - ok
    17:12:46.0839 2252 [ EC3949088F617ACC056FC1AB54A6A13B ] FPLService C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    17:12:46.0872 2252 FPLService - ok
    17:12:46.0879 2252 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    17:12:46.0891 2252 FsDepends - ok
    17:12:46.0919 2252 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    17:12:46.0932 2252 Fs_Rec - ok
    17:12:46.0987 2252 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    17:12:47.0006 2252 fvevol - ok
    17:12:47.0059 2252 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    17:12:47.0070 2252 gagp30kx - ok
    17:12:47.0130 2252 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
    17:12:47.0161 2252 GamesAppService - ok
    17:12:47.0203 2252 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
    17:12:47.0250 2252 gpsvc - ok
    17:12:47.0338 2252 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    17:12:47.0365 2252 gupdate - ok
    17:12:47.0376 2252 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    17:12:47.0391 2252 gupdatem - ok
    17:12:47.0460 2252 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    17:12:47.0474 2252 gusvc - ok
    17:12:47.0504 2252 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    17:12:47.0559 2252 hcw85cir - ok
    17:12:47.0591 2252 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    17:12:47.0626 2252 HdAudAddService - ok
    17:12:47.0656 2252 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
    17:12:47.0691 2252 HDAudBus - ok
    17:12:47.0718 2252 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
    17:12:47.0738 2252 HidBatt - ok
    17:12:47.0754 2252 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
    17:12:47.0780 2252 HidBth - ok
    17:12:47.0805 2252 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
    17:12:47.0819 2252 HidIr - ok
    17:12:47.0841 2252 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
    17:12:47.0888 2252 hidserv - ok
    17:12:47.0922 2252 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    17:12:47.0949 2252 HidUsb - ok
    17:12:47.0959 2252 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
    17:12:48.0011 2252 hkmsvc - ok
    17:12:48.0045 2252 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    17:12:48.0079 2252 HomeGroupListener - ok
    17:12:48.0101 2252 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    17:12:48.0131 2252 HomeGroupProvider - ok
    17:12:48.0201 2252 [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    17:12:48.0224 2252 HP Support Assistant Service - ok
    17:12:48.0266 2252 [ 3015B37029AD15C67EBCA5053C422F90 ] HP8207_8307 C:\Windows\system32\DRIVERS\HP8207_8307.sys
    17:12:48.0286 2252 HP8207_8307 - ok
    17:12:48.0348 2252 [ 7B8C1B09C11E8DB7C4480ABD7D17E821 ] HPAuto C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    17:12:48.0385 2252 HPAuto - ok
    17:12:48.0411 2252 [ 6A181452D4E240B8ECC7614B9A19BDE9 ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    17:12:48.0426 2252 HPClientSvc - ok
    17:12:48.0489 2252 [ 9BFDA0BC109EB6D16F2CB862BB85E28C ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    17:12:48.0519 2252 HPDrvMntSvc.exe - ok
    17:12:48.0582 2252 [ 514455F6586473791C5C6B25BA4E1BAB ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    17:12:48.0618 2252 hpqwmiex - ok
    17:12:48.0656 2252 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    17:12:48.0668 2252 HpSAMD - ok
    17:12:48.0710 2252 [ 2BEC76BDCD1BC080210325E7B5094834 ] HPWMISVC C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    17:12:48.0718 2252 HPWMISVC - ok
    17:12:48.0738 2252 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    17:12:48.0792 2252 HTTP - ok
    17:12:48.0811 2252 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    17:12:48.0821 2252 hwpolicy - ok
    17:12:48.0860 2252 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    17:12:48.0886 2252 i8042prt - ok
    17:12:48.0911 2252 [ 26CF4275034214ECEDD8EC17B0A18A99 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    17:12:48.0932 2252 iaStor - ok
    17:12:49.0042 2252 [ E79A8E33BD136D14BAE1FA20EB2EF124 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    17:12:49.0065 2252 IAStorDataMgrSvc - ok
    17:12:49.0107 2252 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    17:12:49.0139 2252 iaStorV - ok
    17:12:49.0240 2252 [ D3090576412EC63E0C6271D8B0974D73 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    17:12:49.0297 2252 IconMan_R - ok
    17:12:49.0352 2252 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    17:12:49.0399 2252 idsvc - ok
    17:12:49.0496 2252 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\IPSDefs\20121103.001\IDSvia64.sys
    17:12:49.0525 2252 IDSVia64 - ok
    17:12:49.0783 2252 [ 33FAA40B288002C89529DBD14F3AB72C ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    17:12:50.0158 2252 igfx - ok
    17:12:50.0191 2252 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    17:12:50.0203 2252 iirsp - ok
    17:12:50.0248 2252 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
    17:12:50.0303 2252 IKEEXT - ok
    17:12:50.0350 2252 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
    17:12:50.0380 2252 IntcDAud - ok
    17:12:50.0412 2252 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
    17:12:50.0423 2252 intelide - ok
    17:12:50.0463 2252 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    17:12:50.0485 2252 intelppm - ok
    17:12:50.0513 2252 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    17:12:50.0563 2252 IPBusEnum - ok
    17:12:50.0574 2252 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    17:12:50.0607 2252 IpFilterDriver - ok
    17:12:50.0634 2252 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    17:12:50.0682 2252 iphlpsvc - ok
    17:12:50.0704 2252 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
    17:12:50.0727 2252 IPMIDRV - ok
    17:12:50.0745 2252 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    17:12:50.0794 2252 IPNAT - ok
    17:12:50.0825 2252 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
    17:12:50.0841 2252 IRENUM - ok
    17:12:50.0880 2252 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    17:12:50.0891 2252 isapnp - ok
    17:12:50.0916 2252 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
    17:12:50.0931 2252 iScsiPrt - ok
    17:12:51.0003 2252 [ 5A9894E80575647DC77A7D1954B05CE7 ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
    17:12:51.0015 2252 jhi_service - ok
    17:12:51.0062 2252 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
    17:12:51.0072 2252 kbdclass - ok
    17:12:51.0094 2252 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
    17:12:51.0105 2252 kbdhid - ok
    17:12:51.0123 2252 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
    17:12:51.0134 2252 KeyIso - ok
    17:12:51.0153 2252 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    17:12:51.0165 2252 KSecDD - ok
    17:12:51.0192 2252 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    17:12:51.0204 2252 KSecPkg - ok
    17:12:51.0246 2252 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    17:12:51.0293 2252 ksthunk - ok
    17:12:51.0322 2252 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
    17:12:51.0371 2252 KtmRm - ok
    17:12:51.0425 2252 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
    17:12:51.0478 2252 LanmanServer - ok
    17:12:51.0506 2252 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    17:12:51.0550 2252 LanmanWorkstation - ok
    17:12:51.0586 2252 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    17:12:51.0639 2252 lltdio - ok
    17:12:51.0675 2252 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    17:12:51.0756 2252 lltdsvc - ok
    17:12:51.0770 2252 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
    17:12:51.0804 2252 lmhosts - ok
    17:12:51.0871 2252 [ D75C4B4A8FE6D7FD74A7EECDBAEC729F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    17:12:51.0897 2252 LMS - ok
    17:12:51.0924 2252 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
    17:12:51.0936 2252 LSI_FC - ok
    17:12:51.0950 2252 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    17:12:51.0962 2252 LSI_SAS - ok
    17:12:51.0980 2252 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
    17:12:51.0991 2252 LSI_SAS2 - ok
    17:12:52.0004 2252 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    17:12:52.0017 2252 LSI_SCSI - ok
    17:12:52.0035 2252 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
    17:12:52.0077 2252 luafv - ok
    17:12:52.0109 2252 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    17:12:52.0151 2252 Mcx2Svc - ok
    17:12:52.0177 2252 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
    17:12:52.0189 2252 megasas - ok
    17:12:52.0242 2252 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
    17:12:52.0275 2252 MegaSR - ok
    17:12:52.0309 2252 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
    17:12:52.0319 2252 MEIx64 - ok
    17:12:52.0360 2252 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
    17:12:52.0437 2252 MMCSS - ok
    17:12:52.0457 2252 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
    17:12:52.0505 2252 Modem - ok
    17:12:52.0530 2252 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    17:12:52.0554 2252 monitor - ok
    17:12:52.0578 2252 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    17:12:52.0589 2252 mouclass - ok
    17:12:52.0611 2252 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    17:12:52.0640 2252 mouhid - ok
    17:12:52.0675 2252 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    17:12:52.0686 2252 mountmgr - ok
    17:12:52.0716 2252 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
    17:12:52.0728 2252 mpio - ok
    17:12:52.0744 2252 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    17:12:52.0778 2252 mpsdrv - ok
    17:12:52.0814 2252 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
    17:12:52.0871 2252 MpsSvc - ok
    17:12:52.0890 2252 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    17:12:52.0916 2252 MRxDAV - ok
    17:12:52.0940 2252 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    17:12:52.0988 2252 mrxsmb - ok
    17:12:53.0012 2252 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    17:12:53.0027 2252 mrxsmb10 - ok
    17:12:53.0045 2252 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    17:12:53.0058 2252 mrxsmb20 - ok
    17:12:53.0084 2252 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
    17:12:53.0094 2252 msahci - ok
    17:12:53.0120 2252 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    17:12:53.0132 2252 msdsm - ok
    17:12:53.0144 2252 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
    17:12:53.0170 2252 MSDTC - ok
    17:12:53.0199 2252 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    17:12:53.0233 2252 Msfs - ok
    17:12:53.0272 2252 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    17:12:53.0349 2252 mshidkmdf - ok
    17:12:53.0380 2252 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    17:12:53.0390 2252 msisadrv - ok
    17:12:53.0411 2252 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    17:12:53.0465 2252 MSiSCSI - ok
    17:12:53.0468 2252 msiserver - ok
    17:12:53.0493 2252 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    17:12:53.0526 2252 MSKSSRV - ok
    17:12:53.0553 2252 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    17:12:53.0629 2252 MSPCLOCK - ok
    17:12:53.0644 2252 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    17:12:53.0694 2252 MSPQM - ok
    17:12:53.0718 2252 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    17:12:53.0735 2252 MsRPC - ok
    17:12:53.0744 2252 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
    17:12:53.0755 2252 mssmbios - ok
    17:12:53.0796 2252 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    17:12:53.0876 2252 MSTEE - ok
    17:12:53.0889 2252 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
    17:12:53.0918 2252 MTConfig - ok
    17:12:53.0941 2252 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
    17:12:53.0954 2252 Mup - ok
    17:12:54.0110 2252 [ F2840DBFE9322F35557219AE82CC4597 ] N360 C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe
    17:12:54.0135 2252 N360 - ok
    17:12:54.0173 2252 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
    17:12:54.0252 2252 napagent - ok
    17:12:54.0288 2252 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    17:12:54.0317 2252 NativeWifiP - ok
    17:12:54.0401 2252 [ C58D8A669D6551F616D90244BD2C2D4F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121106.004\ENG64.SYS
    17:12:54.0417 2252 NAVENG - ok
    17:12:54.0476 2252 [ A3DBDB412ADFA5882DD6843B11FE0828 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121106.004\EX64.SYS
    17:12:54.0513 2252 NAVEX15 - ok
    17:12:54.0571 2252 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
    17:12:54.0606 2252 NDIS - ok
    17:12:54.0653 2252 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    17:12:54.0732 2252 NdisCap - ok
    17:12:54.0759 2252 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    17:12:54.0792 2252 NdisTapi - ok
    17:12:54.0807 2252 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    17:12:54.0857 2252 Ndisuio - ok
    17:12:54.0880 2252 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    17:12:54.0934 2252 NdisWan - ok
    17:12:54.0949 2252 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    17:12:54.0982 2252 NDProxy - ok
    17:12:55.0015 2252 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    17:12:55.0088 2252 NetBIOS - ok
    17:12:55.0103 2252 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    17:12:55.0138 2252 NetBT - ok
    17:12:55.0168 2252 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
    17:12:55.0181 2252 Netlogon - ok
    17:12:55.0222 2252 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
    17:12:55.0260 2252 Netman - ok
    17:12:55.0268 2252 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
    17:12:55.0317 2252 netprofm - ok
    17:12:55.0342 2252 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    17:12:55.0352 2252 NetTcpPortSharing - ok
    17:12:55.0386 2252 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    17:12:55.0406 2252 nfrd960 - ok
    17:12:55.0455 2252 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
    17:12:55.0515 2252 NlaSvc - ok
    17:12:55.0539 2252 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    17:12:55.0573 2252 Npfs - ok
    17:12:55.0583 2252 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
    17:12:55.0632 2252 nsi - ok
    17:12:55.0643 2252 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    17:12:55.0694 2252 nsiproxy - ok
    17:12:55.0745 2252 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    17:12:55.0783 2252 Ntfs - ok
    17:12:55.0804 2252 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
    17:12:55.0836 2252 Null - ok
    17:12:55.0872 2252 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
    17:12:55.0901 2252 NVENETFD - ok
    17:12:55.0920 2252 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
    17:12:55.0932 2252 nvraid - ok
    17:12:55.0975 2252 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
    17:12:55.0988 2252 nvstor - ok
    17:12:56.0033 2252 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    17:12:56.0045 2252 nv_agp - ok
    17:12:56.0079 2252 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    17:12:56.0123 2252 ohci1394 - ok
    17:12:56.0194 2252 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    17:12:56.0218 2252 ose - ok
    17:12:56.0394 2252 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    17:12:56.0548 2252 osppsvc - ok
    17:12:56.0596 2252 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    17:12:56.0636 2252 p2pimsvc - ok
    17:12:56.0659 2252 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
    17:12:56.0682 2252 p2psvc - ok
    17:12:56.0710 2252 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
    17:12:56.0728 2252 Parport - ok
    17:12:56.0763 2252 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
    17:12:56.0779 2252 partmgr - ok
    17:12:56.0814 2252 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
    17:12:56.0859 2252 PcaSvc - ok
    17:12:57.0114 2252 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
    17:12:57.0533 2252 pci - ok
    17:12:57.0578 2252 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
    17:12:57.0599 2252 pciide - ok
    17:12:57.0641 2252 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    17:12:57.0655 2252 pcmcia - ok
    17:12:57.0681 2252 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
    17:12:57.0692 2252 pcw - ok
    17:12:57.0734 2252 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    17:12:57.0797 2252 PEAUTH - ok
    17:12:57.0932 2252 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    17:12:57.0996 2252 PerfHost - ok
    17:12:58.0050 2252 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
    17:12:58.0126 2252 pla - ok
    17:12:58.0189 2252 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    17:12:58.0242 2252 PlugPlay - ok
    17:12:58.0264 2252 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    17:12:58.0297 2252 PNRPAutoReg - ok
    17:12:58.0317 2252 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    17:12:58.0334 2252 PNRPsvc - ok
    17:12:58.0365 2252 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    17:12:58.0424 2252 PolicyAgent - ok
    17:12:58.0448 2252 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
    17:12:58.0495 2252 Power - ok
    17:12:58.0527 2252 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    17:12:58.0608 2252 PptpMiniport - ok
    17:12:58.0641 2252 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
    17:12:58.0681 2252 Processor - ok
    17:12:58.0730 2252 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
    17:12:58.0779 2252 ProfSvc - ok
    17:12:58.0803 2252 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
    17:12:58.0829 2252 ProtectedStorage - ok
    17:12:58.0860 2252 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    17:12:58.0918 2252 Psched - ok
    17:12:58.0956 2252 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
    17:12:58.0965 2252 PSI - ok
    17:12:59.0002 2252 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
    17:12:59.0039 2252 ql2300 - ok
    17:12:59.0063 2252 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
    17:12:59.0075 2252 ql40xx - ok
    17:12:59.0098 2252 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
    17:12:59.0118 2252 QWAVE - ok
    17:12:59.0137 2252 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    17:12:59.0164 2252 QWAVEdrv - ok
    17:12:59.0183 2252 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    17:12:59.0227 2252 RasAcd - ok
    17:12:59.0264 2252 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    17:12:59.0330 2252 RasAgileVpn - ok
    17:12:59.0352 2252 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
    17:12:59.0399 2252 RasAuto - ok
    17:12:59.0417 2252 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    17:12:59.0464 2252 Rasl2tp - ok
    17:12:59.0492 2252 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
    17:12:59.0530 2252 RasMan - ok
    17:12:59.0557 2252 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    17:12:59.0600 2252 RasPppoe - ok
    17:12:59.0614 2252 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    17:12:59.0659 2252 RasSstp - ok
    17:12:59.0679 2252 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    17:12:59.0727 2252 rdbss - ok
    17:12:59.0763 2252 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
    17:12:59.0788 2252 rdpbus - ok
    17:12:59.0809 2252 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    17:12:59.0858 2252 RDPCDD - ok
    17:12:59.0869 2252 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    17:12:59.0902 2252 RDPENCDD - ok
    17:12:59.0907 2252 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
    17:12:59.0940 2252 RDPREFMP - ok
    17:12:59.0975 2252 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
    17:12:59.0993 2252 RdpVideoMiniport - ok
    17:13:00.0024 2252 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    17:13:00.0046 2252 RDPWD - ok
    17:13:00.0070 2252 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    17:13:00.0085 2252 rdyboost - ok
    17:13:00.0112 2252 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
    17:13:00.0178 2252 RemoteAccess - ok
    17:13:00.0205 2252 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    17:13:00.0241 2252 RemoteRegistry - ok
    17:13:00.0288 2252 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
    17:13:00.0319 2252 RFCOMM - ok
    17:13:00.0335 2252 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    17:13:00.0390 2252 RpcEptMapper - ok
    17:13:00.0417 2252 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
    17:13:00.0429 2252 RpcLocator - ok
    17:13:00.0470 2252 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
    17:13:00.0522 2252 RpcSs - ok
    17:13:00.0557 2252 [ 6E5C3D18C3BCC72AA527DBC5FA61AB8F ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys
    17:13:00.0569 2252 RSPCIESTOR - ok
    17:13:00.0607 2252 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    17:13:00.0682 2252 rspndr - ok
    17:13:00.0733 2252 [ 9140DB0911DE035FED0A9A77A2D156EA ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
    17:13:00.0773 2252 RTL8167 - ok
    17:13:00.0780 2252 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
    17:13:00.0796 2252 SamSs - ok
    17:13:00.0814 2252 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    17:13:00.0826 2252 sbp2port - ok
    17:13:00.0843 2252 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
    17:13:00.0897 2252 SCardSvr - ok
    17:13:00.0934 2252 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    17:13:01.0004 2252 scfilter - ok
    17:13:01.0042 2252 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
    17:13:01.0086 2252 Schedule - ok
    17:13:01.0115 2252 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
    17:13:01.0147 2252 SCPolicySvc - ok
    17:13:01.0202 2252 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
    17:13:01.0261 2252 sdbus - ok
    17:13:01.0289 2252 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    17:13:01.0323 2252 SDRSVC - ok
    17:13:01.0351 2252 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    17:13:01.0405 2252 secdrv - ok
    17:13:01.0416 2252 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
    17:13:01.0450 2252 seclogon - ok
    17:13:01.0637 2252 [ 9901DCF2B6DD2AD12CB42BD559E0C92D ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    17:13:01.0686 2252 Secunia PSI Agent - ok
    17:13:01.0782 2252 [ 4F2056349F8BA4154D5213BF8A476B14 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
    17:13:01.0810 2252 Secunia Update Agent - ok
    17:13:01.0847 2252 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
    17:13:01.0896 2252 SENS - ok
    17:13:01.0926 2252 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
    17:13:01.0981 2252 SensrSvc - ok
    17:13:02.0023 2252 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
    17:13:02.0051 2252 Serenum - ok
    17:13:02.0078 2252 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
    17:13:02.0114 2252 Serial - ok
    17:13:02.0156 2252 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
    17:13:02.0184 2252 sermouse - ok
    17:13:02.0231 2252 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
    17:13:02.0312 2252 SessionEnv - ok
    17:13:02.0344 2252 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    17:13:02.0388 2252 sffdisk - ok
    17:13:02.0413 2252 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    17:13:02.0448 2252 sffp_mmc - ok
    17:13:02.0469 2252 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    17:13:02.0512 2252 sffp_sd - ok
    17:13:02.0538 2252 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
    17:13:02.0563 2252 sfloppy - ok
    17:13:02.0600 2252 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
    17:13:02.0644 2252 SharedAccess - ok
    17:13:02.0675 2252 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    17:13:02.0712 2252 ShellHWDetection - ok
    17:13:02.0743 2252 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
    17:13:02.0754 2252 SiSRaid2 - ok
    17:13:02.0778 2252 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    17:13:02.0789 2252 SiSRaid4 - ok
    17:13:02.0839 2252 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    17:13:02.0850 2252 SkypeUpdate - ok
    17:13:02.0885 2252 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    17:13:02.0931 2252 Smb - ok
    17:13:02.0982 2252 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    17:13:03.0013 2252 SNMPTRAP - ok
    17:13:03.0039 2252 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
    17:13:03.0050 2252 spldr - ok
    17:13:03.0087 2252 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
    17:13:03.0118 2252 Spooler - ok
    17:13:03.0211 2252 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
    17:13:03.0335 2252 sppsvc - ok
  7. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Continued
    17:13:03.0356 2252 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
    17:13:03.0396 2252 sppuinotify - ok
    17:13:03.0474 2252 [ 891793E00432FA055CF040605C260E49 ] SRTSP C:\Windows\System32\Drivers\N360x64\0604000.009\SRTSP64.SYS
    17:13:03.0496 2252 SRTSP - ok
    17:13:03.0509 2252 [ 1CB7BB3B0561FB5ECFE37F7731E8BF3E ] SRTSPX C:\Windows\system32\drivers\N360x64\0604000.009\SRTSPX64.SYS
    17:13:03.0517 2252 SRTSPX - ok
    17:13:03.0548 2252 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
    17:13:03.0603 2252 srv - ok
    17:13:03.0621 2252 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    17:13:03.0654 2252 srv2 - ok
    17:13:03.0692 2252 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    17:13:03.0716 2252 SrvHsfHDA - ok
    17:13:03.0756 2252 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS
    17:13:03.0800 2252 SrvHsfV92 - ok
    17:13:03.0826 2252 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
    17:13:03.0855 2252 SrvHsfWinac - ok
    17:13:03.0883 2252 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    17:13:03.0896 2252 srvnet - ok
    17:13:03.0929 2252 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    17:13:03.0965 2252 SSDPSRV - ok
    17:13:03.0969 2252 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
    17:13:04.0004 2252 SstpSvc - ok
    17:13:04.0086 2252 [ 7BF818B11C1FEDC3E76D233124470A30 ] STacSV C:\Program Files\IDT\WDM\STacSV64.exe
    17:13:04.0172 2252 STacSV - ok
    17:13:04.0192 2252 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
    17:13:04.0208 2252 stexstor - ok
    17:13:04.0284 2252 [ EBC1A5E076A9BE314D3D9E8ED19ABB0A ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
    17:13:04.0331 2252 STHDA - ok
    17:13:04.0378 2252 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
    17:13:04.0403 2252 stisvc - ok
    17:13:04.0414 2252 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
    17:13:04.0424 2252 swenum - ok
    17:13:04.0456 2252 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
    17:13:04.0514 2252 swprv - ok
    17:13:04.0548 2252 [ 8B2430762099598DA40686F754632EFD ] SymDS C:\Windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS
    17:13:04.0562 2252 SymDS - ok
    17:13:04.0613 2252 [ 5CB7F2FD7E30A0F52F93574BFC3A8041 ] SymEFA C:\Windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS
    17:13:04.0656 2252 SymEFA - ok
    17:13:04.0701 2252 [ 898BB48C797483420DF523B2BBC1ECDB ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
    17:13:04.0725 2252 SymEvent - ok
    17:13:04.0766 2252 [ 5013A76CAAA1D7CF1C55214B490B4E35 ] SymIRON C:\Windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS
    17:13:04.0780 2252 SymIRON - ok
    17:13:04.0806 2252 [ 3911BD0E68C010E5438A87706ABBE9AB ] SymNetS C:\Windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS
    17:13:04.0820 2252 SymNetS - ok
    17:13:04.0858 2252 [ AC3CC98B1BDB6540021D3FFB105AC2B9 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
    17:13:04.0872 2252 SynTP - ok
    17:13:04.0916 2252 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
    17:13:04.0967 2252 SysMain - ok
    17:13:04.0990 2252 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
    17:13:05.0027 2252 TabletInputService - ok
    17:13:05.0060 2252 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
    17:13:05.0096 2252 TapiSrv - ok
    17:13:05.0106 2252 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
    17:13:05.0142 2252 TBS - ok
    17:13:05.0237 2252 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    17:13:05.0299 2252 Tcpip - ok
    17:13:05.0330 2252 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    17:13:05.0366 2252 TCPIP6 - ok
    17:13:05.0396 2252 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    17:13:05.0465 2252 tcpipreg - ok
    17:13:05.0489 2252 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    17:13:05.0499 2252 TDPIPE - ok
    17:13:05.0522 2252 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    17:13:05.0544 2252 TDTCP - ok
    17:13:05.0569 2252 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    17:13:05.0602 2252 tdx - ok
    17:13:05.0631 2252 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
    17:13:05.0643 2252 TermDD - ok
    17:13:05.0679 2252 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
    17:13:05.0720 2252 TermService - ok
    17:13:05.0733 2252 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
    17:13:05.0750 2252 Themes - ok
    17:13:05.0773 2252 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
    17:13:05.0820 2252 THREADORDER - ok
    17:13:05.0858 2252 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
    17:13:05.0906 2252 TrkWks - ok
    17:13:05.0969 2252 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    17:13:06.0039 2252 TrustedInstaller - ok
    17:13:06.0069 2252 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    17:13:06.0113 2252 tssecsrv - ok
    17:13:06.0158 2252 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    17:13:06.0236 2252 TsUsbFlt - ok
    17:13:06.0268 2252 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
    17:13:06.0283 2252 TsUsbGD - ok
    17:13:06.0318 2252 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    17:13:06.0375 2252 tunnel - ok
    17:13:06.0408 2252 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    17:13:06.0420 2252 uagp35 - ok
    17:13:06.0434 2252 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    17:13:06.0489 2252 udfs - ok
    17:13:06.0520 2252 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
    17:13:06.0551 2252 UI0Detect - ok
    17:13:06.0583 2252 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    17:13:06.0595 2252 uliagpkx - ok
    17:13:06.0639 2252 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    17:13:06.0663 2252 umbus - ok
    17:13:06.0691 2252 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
    17:13:06.0721 2252 UmPass - ok
    17:13:06.0839 2252 [ 758C2CE427C343F780A205E28555C98D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    17:13:06.0895 2252 UNS - ok
    17:13:06.0924 2252 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
    17:13:06.0980 2252 upnphost - ok
    17:13:07.0013 2252 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    17:13:07.0049 2252 usbccgp - ok
    17:13:07.0081 2252 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    17:13:07.0101 2252 usbcir - ok
    17:13:07.0118 2252 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
    17:13:07.0147 2252 usbehci - ok
    17:13:07.0174 2252 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\drivers\usbhub.sys
    17:13:07.0209 2252 usbhub - ok
    17:13:07.0222 2252 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    17:13:07.0251 2252 usbohci - ok
    17:13:07.0282 2252 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
    17:13:07.0319 2252 usbprint - ok
    17:13:07.0353 2252 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    17:13:07.0387 2252 USBSTOR - ok
    17:13:07.0405 2252 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
    17:13:07.0432 2252 usbuhci - ok
    17:13:07.0484 2252 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
    17:13:07.0521 2252 usbvideo - ok
    17:13:07.0555 2252 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
    17:13:07.0621 2252 UxSms - ok
    17:13:07.0636 2252 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
    17:13:07.0648 2252 VaultSvc - ok
    17:13:07.0664 2252 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    17:13:07.0675 2252 vdrvroot - ok
    17:13:07.0692 2252 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
    17:13:07.0749 2252 vds - ok
    17:13:07.0771 2252 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    17:13:07.0786 2252 vga - ok
    17:13:07.0801 2252 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
    17:13:07.0844 2252 VgaSave - ok
    17:13:07.0874 2252 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
    17:13:07.0888 2252 vhdmp - ok
    17:13:07.0903 2252 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
    17:13:07.0914 2252 viaide - ok
    17:13:07.0965 2252 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    17:13:07.0978 2252 volmgr - ok
    17:13:07.0997 2252 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    17:13:08.0013 2252 volmgrx - ok
    17:13:08.0031 2252 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\Windows\system32\drivers\volsnap.sys
    17:13:08.0046 2252 volsnap - ok
    17:13:08.0072 2252 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    17:13:08.0085 2252 vsmraid - ok
    17:13:08.0132 2252 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
    17:13:08.0205 2252 VSS - ok
    17:13:08.0230 2252 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
    17:13:08.0245 2252 vwifibus - ok
    17:13:08.0261 2252 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    17:13:08.0294 2252 vwififlt - ok
    17:13:08.0349 2252 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
    17:13:08.0366 2252 vwifimp - ok
    17:13:08.0397 2252 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
    17:13:08.0441 2252 W32Time - ok
    17:13:08.0474 2252 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
    17:13:08.0506 2252 WacomPen - ok
    17:13:08.0540 2252 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
    17:13:08.0593 2252 WANARP - ok
    17:13:08.0596 2252 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    17:13:08.0628 2252 Wanarpv6 - ok
    17:13:08.0710 2252 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
    17:13:08.0750 2252 WatAdminSvc - ok
    17:13:08.0800 2252 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
    17:13:08.0858 2252 wbengine - ok
    17:13:08.0875 2252 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    17:13:08.0894 2252 WbioSrvc - ok
    17:13:08.0915 2252 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
    17:13:08.0949 2252 wcncsvc - ok
    17:13:08.0970 2252 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    17:13:08.0986 2252 WcsPlugInService - ok
    17:13:09.0014 2252 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
    17:13:09.0024 2252 Wd - ok
    17:13:09.0054 2252 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    17:13:09.0075 2252 Wdf01000 - ok
    17:13:09.0088 2252 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
    17:13:09.0155 2252 WdiServiceHost - ok
    17:13:09.0161 2252 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
    17:13:09.0183 2252 WdiSystemHost - ok
    17:13:09.0212 2252 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
    17:13:09.0248 2252 WebClient - ok
    17:13:09.0272 2252 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
    17:13:09.0319 2252 Wecsvc - ok
    17:13:09.0346 2252 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    17:13:09.0381 2252 wercplsupport - ok
    17:13:09.0403 2252 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
    17:13:09.0452 2252 WerSvc - ok
    17:13:09.0487 2252 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
    17:13:09.0545 2252 WfpLwf - ok
    17:13:09.0564 2252 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    17:13:09.0575 2252 WIMMount - ok
    17:13:09.0588 2252 WinDefend - ok
    17:13:09.0593 2252 WinHttpAutoProxySvc - ok
    17:13:09.0647 2252 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    17:13:09.0712 2252 Winmgmt - ok
    17:13:09.0766 2252 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
    17:13:09.0830 2252 WinRM - ok
    17:13:09.0893 2252 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
    17:13:09.0947 2252 Wlansvc - ok
    17:13:09.0998 2252 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    17:13:10.0020 2252 wlcrasvc - ok
    17:13:10.0147 2252 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    17:13:10.0198 2252 wlidsvc - ok
    17:13:10.0223 2252 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    17:13:10.0246 2252 WmiAcpi - ok
    17:13:10.0280 2252 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    17:13:10.0310 2252 wmiApSrv - ok
    17:13:10.0346 2252 WMPNetworkSvc - ok
    17:13:10.0373 2252 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
    17:13:10.0398 2252 WPCSvc - ok
    17:13:10.0414 2252 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    17:13:10.0429 2252 WPDBusEnum - ok
    17:13:10.0457 2252 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    17:13:10.0490 2252 ws2ifsl - ok
    17:13:10.0509 2252 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
    17:13:10.0544 2252 wscsvc - ok
    17:13:10.0577 2252 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
    17:13:10.0591 2252 WSDPrintDevice - ok
    17:13:10.0633 2252 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
    17:13:10.0666 2252 WSDScan - ok
    17:13:10.0669 2252 WSearch - ok
    17:13:10.0754 2252 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    17:13:10.0813 2252 wuauserv - ok
    17:13:10.0831 2252 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    17:13:10.0879 2252 WudfPf - ok
    17:13:10.0905 2252 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    17:13:10.0939 2252 WUDFRd - ok
    17:13:10.0972 2252 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    17:13:11.0006 2252 wudfsvc - ok
    17:13:11.0039 2252 [ CE8CF9DE9CBFDAA318BD04D8BE3FCADA ] WwanSvc C:\Windows\System32\wwansvc.dll
    17:13:11.0070 2252 WwanSvc - ok
    17:13:11.0114 2252 ================ Scan global ===============================
    17:13:11.0137 2252 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
    17:13:11.0168 2252 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    17:13:11.0175 2252 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    17:13:11.0206 2252 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
    17:13:11.0242 2252 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
    17:13:11.0245 2252 [Global] - ok
    17:13:11.0246 2252 ================ Scan MBR ==================================
    17:13:11.0258 2252 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    17:13:11.0259 2252 Suspicious mbr (Forged): \Device\Harddisk0\DR0
    17:13:11.0312 2252 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
    17:13:11.0313 2252 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
    17:13:12.0048 2252 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
    17:13:12.0048 2252 \Device\Harddisk0\DR0 - detected TDSS File System (1)
    17:13:12.0048 2252 ================ Scan VBR ==================================
    17:13:12.0078 2252 [ 7893EF093958182A7A126B2E3CEE4DF1 ] \Device\Harddisk0\DR0\Partition1
    17:13:12.0080 2252 \Device\Harddisk0\DR0\Partition1 - ok
    17:13:12.0100 2252 [ 2041DA3A0667CAB1C92135CB70185EEF ] \Device\Harddisk0\DR0\Partition2
    17:13:12.0101 2252 \Device\Harddisk0\DR0\Partition2 - ok
    17:13:12.0132 2252 [ B8174525FD82EE856AE374E606C70890 ] \Device\Harddisk0\DR0\Partition3
    17:13:12.0134 2252 \Device\Harddisk0\DR0\Partition3 - ok
    17:13:12.0135 2252 ============================================================
    17:13:12.0135 2252 Scan finished
    17:13:12.0135 2252 ============================================================
    17:13:12.0150 3084 Detected object count: 2
    17:13:12.0150 3084 Actual detected object count: 2
    17:14:46.0897 3084 \Device\Harddisk0\DR0\# - copied to quarantine
    17:14:46.0900 3084 \Device\Harddisk0\DR0 - copied to quarantine
    17:14:46.0952 3084 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
    17:14:46.0955 3084 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
    17:14:46.0978 3084 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
    17:14:46.0989 3084 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
    17:14:46.0991 3084 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
    17:14:46.0993 3084 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
    17:14:46.0996 3084 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
    17:14:46.0999 3084 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
    17:14:47.0003 3084 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
    17:14:47.0006 3084 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
    17:14:47.0009 3084 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
    17:14:47.0011 3084 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
    17:14:47.0042 3084 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
    17:14:47.0051 3084 \Device\Harddisk0\DR0 - ok
    17:14:47.0655 3084 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
    17:14:47.0656 3084 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    17:14:47.0656 3084 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
    17:14:50.0308 7960 Deinitialize success
  8. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    When I rebooted, I was told to rescan. Here is the report from that scan

    17:17:46.0673 1020 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
    17:17:47.0219 1020 ============================================================
    17:17:47.0219 1020 Current date / time: 2012/11/07 17:17:47.0219
    17:17:47.0219 1020 SystemInfo:
    17:17:47.0219 1020
    17:17:47.0219 1020 OS Version: 6.1.7601 ServicePack: 1.0
    17:17:47.0219 1020 Product type: Workstation
    17:17:47.0219 1020 ComputerName: SUNSHINE-HP
    17:17:47.0219 1020 UserName: Sunshine
    17:17:47.0219 1020 Windows directory: C:\Windows
    17:17:47.0219 1020 System windows directory: C:\Windows
    17:17:47.0219 1020 Running under WOW64
    17:17:47.0219 1020 Processor architecture: Intel x64
    17:17:47.0219 1020 Number of processors: 4
    17:17:47.0219 1020 Page size: 0x1000
    17:17:47.0219 1020 Boot type: Normal boot
    17:17:47.0219 1020 ============================================================
    17:17:48.0747 1020 BG loaded
    17:17:49.0200 1020 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    17:17:49.0215 1020 ============================================================
    17:17:49.0215 1020 \Device\Harddisk0\DR0:
    17:17:49.0215 1020 MBR partitions:
    17:17:49.0215 1020 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
    17:17:49.0215 1020 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x544D2800
    17:17:49.0215 1020 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x54536800, BlocksNum 0x2820000
    17:17:49.0215 1020 \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x56D56800, BlocksNum 0x7EF000
    17:17:49.0215 1020 ============================================================
    17:17:49.0262 1020 C: <-> \Device\Harddisk0\DR0\Partition2
    17:17:49.0543 1020 D: <-> \Device\Harddisk0\DR0\Partition3
    17:17:49.0559 1020 E: <-> \Device\Harddisk0\DR0\Partition4
    17:17:49.0559 1020 ============================================================
    17:17:49.0559 1020 Initialize success
    17:17:49.0559 1020 ============================================================
    17:18:08.0513 5452 ============================================================
    17:18:08.0513 5452 Scan started
    17:18:08.0513 5452 Mode: Manual; SigCheck; TDLFS;
    17:18:08.0513 5452 ============================================================
    17:18:09.0683 5452 ================ Scan system memory ========================
    17:18:09.0683 5452 System memory - ok
    17:18:09.0683 5452 ================ Scan services =============================
    17:18:09.0901 5452 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
    17:18:10.0089 5452 1394ohci - ok
    17:18:10.0167 5452 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
    17:18:10.0182 5452 ACPI - ok
    17:18:10.0213 5452 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
    17:18:10.0323 5452 AcpiPmi - ok
    17:18:10.0447 5452 [ B1EA9681502EE57F87DB71D726288A5B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    17:18:10.0479 5452 AdobeARMservice - ok
    17:18:10.0681 5452 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    17:18:10.0744 5452 AdobeFlashPlayerUpdateSvc - ok
    17:18:10.0837 5452 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    17:18:10.0884 5452 adp94xx - ok
    17:18:10.0931 5452 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
    17:18:11.0009 5452 adpahci - ok
    17:18:11.0074 5452 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    17:18:11.0090 5452 adpu320 - ok
    17:18:11.0136 5452 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    17:18:11.0261 5452 AeLookupSvc - ok
    17:18:11.0308 5452 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
    17:18:11.0386 5452 AFD - ok
    17:18:11.0464 5452 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
    17:18:11.0464 5452 agp440 - ok
    17:18:11.0542 5452 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
    17:18:11.0636 5452 ALG - ok
    17:18:11.0745 5452 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
    17:18:11.0760 5452 aliide - ok
    17:18:11.0823 5452 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
    17:18:11.0838 5452 amdide - ok
    17:18:11.0932 5452 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
    17:18:12.0041 5452 AmdK8 - ok
    17:18:12.0088 5452 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
    17:18:12.0182 5452 AmdPPM - ok
    17:18:12.0260 5452 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    17:18:12.0260 5452 amdsata - ok
    17:18:12.0306 5452 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
    17:18:12.0353 5452 amdsbs - ok
    17:18:12.0494 5452 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    17:18:12.0525 5452 amdxata - ok
    17:18:12.0650 5452 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
    17:18:13.0258 5452 AppID - ok
    17:18:13.0320 5452 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    17:18:13.0461 5452 AppIDSvc - ok
    17:18:13.0539 5452 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
    17:18:13.0601 5452 Appinfo - ok
    17:18:13.0820 5452 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
    17:18:14.0194 5452 arc - ok
    17:18:14.0350 5452 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
    17:18:14.0381 5452 arcsas - ok
    17:18:14.0522 5452 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    17:18:14.0584 5452 AsyncMac - ok
    17:18:14.0631 5452 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
    17:18:14.0678 5452 atapi - ok
    17:18:14.0740 5452 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    17:18:14.0818 5452 AudioEndpointBuilder - ok
    17:18:14.0880 5452 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    17:18:14.0958 5452 AudioSrv - ok
    17:18:15.0021 5452 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
    17:18:15.0161 5452 AxInstSV - ok
    17:18:15.0224 5452 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
    17:18:15.0333 5452 b06bdrv - ok
    17:18:15.0380 5452 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
    17:18:15.0489 5452 b57nd60a - ok
    17:18:15.0567 5452 [ 09A19C806110CE839111850EC27E65F5 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys
    17:18:15.0614 5452 bcbtums - ok
    17:18:15.0972 5452 [ 461E574D7967E895640109A371A912A5 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
    17:18:16.0066 5452 BCM43XX - ok
    17:18:16.0128 5452 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
    17:18:16.0222 5452 BDESVC - ok
    17:18:16.0284 5452 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
    17:18:16.0347 5452 Beep - ok
    17:18:16.0472 5452 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
    17:18:16.0534 5452 BFE - ok
    17:18:16.0986 5452 [ 652F4D186325B69FFE80EE18AE9ACC77 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\BASHDefs\20121030.002\BHDrvx64.sys
    17:18:17.0018 5452 BHDrvx64 - ok
    17:18:17.0096 5452 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
    17:18:17.0189 5452 BITS - ok
    17:18:17.0252 5452 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
    17:18:17.0501 5452 blbdrive - ok
    17:18:17.0564 5452 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    17:18:17.0610 5452 bowser - ok
    17:18:17.0642 5452 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
    17:18:17.0688 5452 BrFiltLo - ok
    17:18:17.0735 5452 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
    17:18:17.0751 5452 BrFiltUp - ok
    17:18:17.0860 5452 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
    17:18:17.0922 5452 BridgeMP - ok
    17:18:17.0969 5452 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
    17:18:18.0016 5452 Browser - ok
    17:18:18.0063 5452 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
    17:18:18.0141 5452 Brserid - ok
    17:18:18.0188 5452 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    17:18:18.0234 5452 BrSerWdm - ok
    17:18:18.0312 5452 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    17:18:18.0375 5452 BrUsbMdm - ok
    17:18:18.0437 5452 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
    17:18:18.0546 5452 BrUsbSer - ok
    17:18:18.0640 5452 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
    17:18:18.0702 5452 BthEnum - ok
    17:18:18.0936 5452 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
    17:18:19.0030 5452 BTHMODEM - ok
    17:18:19.0498 5452 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
    17:18:19.0545 5452 BthPan - ok
    17:18:19.0607 5452 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
    17:18:19.0685 5452 BTHPORT - ok
    17:18:19.0748 5452 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
    17:18:19.0810 5452 bthserv - ok
    17:18:19.0841 5452 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
    17:18:19.0888 5452 BTHUSB - ok
    17:18:19.0950 5452 [ 0E78584D5FACA0509DFA97BD8B635075 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys
    17:18:19.0966 5452 btwampfl - ok
    17:18:19.0982 5452 [ 409C4117E6027672EF41E68ACE1468AD ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
    17:18:19.0997 5452 btwaudio - ok
    17:18:20.0044 5452 [ 8CA7CABD13316ABACE386D9F380B4CF3 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
    17:18:20.0060 5452 btwavdt - ok
    17:18:20.0262 5452 [ 1249EDE2280F9A1564C946AFDDCD59D5 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    17:18:20.0294 5452 btwdins - ok
    17:18:20.0387 5452 [ 41933521A618475644B6E8D8487AF326 ] BTWDPAN C:\Windows\system32\DRIVERS\btwdpan.sys
    17:18:20.0403 5452 BTWDPAN - ok
    17:18:20.0465 5452 [ B9354F9F111C64F2495B60F1E24CB453 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
    17:18:20.0512 5452 btwl2cap - ok
    17:18:20.0574 5452 [ 71A04F2D9DEB21B162561EB574D7D629 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
    17:18:20.0590 5452 btwrchid - ok
    17:18:20.0746 5452 catchme - ok
    17:18:20.0902 5452 [ 2C6FFCCA37B002AAB3C7C31A6D780A76 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys
    17:18:20.0933 5452 ccSet_N360 - ok
    17:18:20.0964 5452 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    17:18:21.0042 5452 cdfs - ok
    17:18:21.0183 5452 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    17:18:21.0354 5452 cdrom - ok
    17:18:21.0557 5452 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
    17:18:21.0635 5452 CertPropSvc - ok
    17:18:21.0744 5452 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
    17:18:21.0838 5452 circlass - ok
    17:18:21.0916 5452 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
    17:18:21.0932 5452 CLFS - ok
    17:18:22.0041 5452 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    17:18:22.0041 5452 clr_optimization_v2.0.50727_32 - ok
    17:18:22.0134 5452 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    17:18:22.0150 5452 clr_optimization_v2.0.50727_64 - ok
    17:18:22.0322 5452 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    17:18:22.0368 5452 clr_optimization_v4.0.30319_32 - ok
    17:18:22.0431 5452 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    17:18:22.0446 5452 clr_optimization_v4.0.30319_64 - ok
    17:18:22.0478 5452 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
    17:18:22.0493 5452 clwvd - ok
    17:18:22.0556 5452 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
    17:18:22.0649 5452 CmBatt - ok
    17:18:22.0696 5452 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
    17:18:22.0696 5452 cmdide - ok
    17:18:22.0743 5452 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
    17:18:22.0758 5452 CNG - ok
    17:18:22.0790 5452 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
    17:18:22.0805 5452 Compbatt - ok
    17:18:22.0852 5452 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
    17:18:22.0914 5452 CompositeBus - ok
    17:18:22.0930 5452 COMSysApp - ok
    17:18:22.0946 5452 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
    17:18:22.0961 5452 crcdisk - ok
    17:18:23.0024 5452 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
    17:18:23.0055 5452 CryptSvc - ok
    17:18:23.0117 5452 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
    17:18:23.0195 5452 DcomLaunch - ok
    17:18:23.0226 5452 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
    17:18:23.0273 5452 defragsvc - ok
    17:18:23.0320 5452 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    17:18:23.0367 5452 DfsC - ok
    17:18:23.0429 5452 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
    17:18:23.0492 5452 Dhcp - ok
    17:18:23.0523 5452 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
    17:18:23.0570 5452 discache - ok
    17:18:23.0601 5452 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
    17:18:23.0616 5452 Disk - ok
    17:18:23.0663 5452 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    17:18:23.0835 5452 Dnscache - ok
    17:18:23.0882 5452 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
    17:18:23.0960 5452 dot3svc - ok
    17:18:23.0991 5452 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
    17:18:24.0038 5452 DPS - ok
    17:18:24.0069 5452 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    17:18:24.0116 5452 drmkaud - ok
    17:18:24.0162 5452 [ A4F408AD1065C7AD2ED332C68025B435 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    17:18:24.0194 5452 DXGKrnl - ok
    17:18:24.0225 5452 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
    17:18:24.0303 5452 EapHost - ok
    17:18:24.0412 5452 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
    17:18:24.0521 5452 ebdrv - ok
    17:18:24.0630 5452 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    17:18:24.0662 5452 eeCtrl - ok
    17:18:24.0693 5452 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
    17:18:24.0724 5452 EFS - ok
    17:18:24.0802 5452 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    17:18:24.0896 5452 ehRecvr - ok
    17:18:24.0896 5452 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
    17:18:24.0911 5452 ehSched - ok
    17:18:24.0958 5452 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
    17:18:25.0020 5452 elxstor - ok
    17:18:25.0098 5452 [ 7C5BFAAC8DCE7292B0C04EBF892E71F9 ] EPSON_EB_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
    17:18:25.0130 5452 EPSON_EB_RPCV4_04 - ok
    17:18:25.0145 5452 [ D4615670CD49A1679E6067F155C47C68 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
    17:18:25.0192 5452 EPSON_PM_RPCV4_04 - ok
    17:18:25.0239 5452 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    17:18:25.0239 5452 EraserUtilRebootDrv - ok
    17:18:25.0270 5452 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
    17:18:25.0301 5452 ErrDev - ok
    17:18:25.0364 5452 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
    17:18:25.0426 5452 EventSystem - ok
    17:18:25.0457 5452 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
    17:18:25.0504 5452 exfat - ok
    17:18:25.0535 5452 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
    17:18:25.0582 5452 fastfat - ok
    17:18:25.0629 5452 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
    17:18:25.0676 5452 Fax - ok
    17:18:25.0707 5452 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
    17:18:25.0722 5452 fdc - ok
    17:18:25.0785 5452 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
    17:18:25.0832 5452 fdPHost - ok
    17:18:25.0847 5452 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
    17:18:25.0878 5452 FDResPub - ok
    17:18:25.0925 5452 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    17:18:25.0925 5452 FileInfo - ok
    17:18:25.0956 5452 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    17:18:26.0034 5452 Filetrace - ok
    17:18:26.0066 5452 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
    17:18:26.0112 5452 flpydisk - ok
    17:18:26.0144 5452 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    17:18:26.0159 5452 FltMgr - ok
    17:18:26.0222 5452 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
    17:18:26.0284 5452 FontCache - ok
    17:18:26.0346 5452 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    17:18:26.0346 5452 FontCache3.0.0.0 - ok
    17:18:26.0424 5452 [ EC3949088F617ACC056FC1AB54A6A13B ] FPLService C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    17:18:26.0456 5452 FPLService - ok
    17:18:26.0471 5452 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    17:18:26.0471 5452 FsDepends - ok
    17:18:26.0502 5452 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    17:18:26.0518 5452 Fs_Rec - ok
    17:18:26.0565 5452 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    17:18:26.0580 5452 fvevol - ok
    17:18:26.0612 5452 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    17:18:26.0643 5452 gagp30kx - ok
    17:18:26.0721 5452 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
    17:18:26.0736 5452 GamesAppService - ok
    17:18:26.0783 5452 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
    17:18:26.0830 5452 gpsvc - ok
    17:18:26.0924 5452 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    17:18:26.0955 5452 gupdate - ok
    17:18:26.0955 5452 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    17:18:26.0970 5452 gupdatem - ok
    17:18:27.0064 5452 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    17:18:27.0095 5452 gusvc - ok
    17:18:27.0126 5452 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    17:18:27.0189 5452 hcw85cir - ok
    17:18:27.0220 5452 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    17:18:27.0251 5452 HdAudAddService - ok
    17:18:27.0282 5452 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
    17:18:27.0345 5452 HDAudBus - ok
    17:18:27.0376 5452 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
    17:18:27.0407 5452 HidBatt - ok
    17:18:27.0423 5452 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
    17:18:27.0470 5452 HidBth - ok
    17:18:27.0501 5452 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
    17:18:27.0532 5452 HidIr - ok
    17:18:27.0563 5452 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
    17:18:27.0626 5452 hidserv - ok
    17:18:27.0657 5452 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    17:18:27.0688 5452 HidUsb - ok
    17:18:27.0719 5452 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
    17:18:27.0813 5452 hkmsvc - ok
    17:18:27.0828 5452 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    17:18:27.0860 5452 HomeGroupListener - ok
    17:18:27.0891 5452 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    17:18:27.0922 5452 HomeGroupProvider - ok
    17:18:27.0984 5452 [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    17:18:28.0016 5452 HP Support Assistant Service - ok
    17:18:28.0047 5452 [ 3015B37029AD15C67EBCA5053C422F90 ] HP8207_8307 C:\Windows\system32\DRIVERS\HP8207_8307.sys
    17:18:28.0109 5452 HP8207_8307 - ok
    17:18:28.0172 5452 [ 7B8C1B09C11E8DB7C4480ABD7D17E821 ] HPAuto C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    17:18:28.0203 5452 HPAuto - ok
    17:18:28.0234 5452 [ 6A181452D4E240B8ECC7614B9A19BDE9 ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    17:18:28.0234 5452 HPClientSvc - ok
    17:18:28.0312 5452 [ 9BFDA0BC109EB6D16F2CB862BB85E28C ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    17:18:28.0343 5452 HPDrvMntSvc.exe - ok
    17:18:28.0406 5452 [ 514455F6586473791C5C6B25BA4E1BAB ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    17:18:28.0437 5452 hpqwmiex - ok
    17:18:28.0468 5452 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    17:18:28.0468 5452 HpSAMD - ok
    17:18:28.0515 5452 [ 2BEC76BDCD1BC080210325E7B5094834 ] HPWMISVC C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    17:18:28.0546 5452 HPWMISVC - ok
    17:18:28.0562 5452 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    17:18:28.0624 5452 HTTP - ok
    17:18:28.0655 5452 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    17:18:28.0655 5452 hwpolicy - ok
    17:18:28.0686 5452 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    17:18:28.0702 5452 i8042prt - ok
    17:18:28.0733 5452 [ 26CF4275034214ECEDD8EC17B0A18A99 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    17:18:28.0749 5452 iaStor - ok
    17:18:28.0811 5452 [ E79A8E33BD136D14BAE1FA20EB2EF124 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    17:18:28.0827 5452 IAStorDataMgrSvc - ok
    17:18:28.0874 5452 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    17:18:28.0889 5452 iaStorV - ok
    17:18:28.0983 5452 [ D3090576412EC63E0C6271D8B0974D73 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    17:18:29.0030 5452 IconMan_R - ok
    17:18:29.0076 5452 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    17:18:29.0092 5452 idsvc - ok
    17:18:29.0186 5452 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\IPSDefs\20121103.001\IDSvia64.sys
    17:18:29.0201 5452 IDSVia64 - ok
    17:18:29.0466 5452 [ 33FAA40B288002C89529DBD14F3AB72C ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    17:18:29.0654 5452 igfx - ok
    17:18:29.0669 5452 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    17:18:29.0685 5452 iirsp - ok
    17:18:29.0763 5452 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
    17:18:29.0841 5452 IKEEXT - ok
    17:18:29.0903 5452 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
    17:18:29.0950 5452 IntcDAud - ok
    17:18:29.0981 5452 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
    17:18:30.0012 5452 intelide - ok
    17:18:30.0044 5452 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    17:18:30.0090 5452 intelppm - ok
    17:18:30.0106 5452 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    17:18:30.0168 5452 IPBusEnum - ok
    17:18:30.0200 5452 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    17:18:30.0246 5452 IpFilterDriver - ok
  9. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Continuation of 2nd scan

    17:18:30.0278 5452 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    17:18:30.0371 5452 iphlpsvc - ok
    17:18:30.0402 5452 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
    17:18:30.0418 5452 IPMIDRV - ok
    17:18:30.0449 5452 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    17:18:30.0496 5452 IPNAT - ok
    17:18:30.0527 5452 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
    17:18:30.0543 5452 IRENUM - ok
    17:18:30.0558 5452 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    17:18:30.0574 5452 isapnp - ok
    17:18:30.0605 5452 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
    17:18:30.0652 5452 iScsiPrt - ok
    17:18:30.0777 5452 [ 5A9894E80575647DC77A7D1954B05CE7 ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
    17:18:30.0792 5452 jhi_service - ok
    17:18:30.0839 5452 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
    17:18:30.0855 5452 kbdclass - ok
    17:18:30.0886 5452 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
    17:18:30.0917 5452 kbdhid - ok
    17:18:30.0948 5452 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
    17:18:30.0948 5452 KeyIso - ok
    17:18:30.0980 5452 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    17:18:31.0011 5452 KSecDD - ok
    17:18:31.0073 5452 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    17:18:31.0151 5452 KSecPkg - ok
    17:18:31.0229 5452 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    17:18:31.0354 5452 ksthunk - ok
    17:18:31.0401 5452 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
    17:18:31.0588 5452 KtmRm - ok
    17:18:31.0650 5452 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
    17:18:31.0728 5452 LanmanServer - ok
    17:18:31.0775 5452 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    17:18:31.0853 5452 LanmanWorkstation - ok
    17:18:31.0916 5452 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    17:18:31.0962 5452 lltdio - ok
    17:18:32.0009 5452 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    17:18:32.0103 5452 lltdsvc - ok
    17:18:32.0118 5452 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
    17:18:32.0150 5452 lmhosts - ok
    17:18:32.0228 5452 [ D75C4B4A8FE6D7FD74A7EECDBAEC729F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    17:18:32.0274 5452 LMS - ok
    17:18:32.0337 5452 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
    17:18:32.0352 5452 LSI_FC - ok
    17:18:32.0352 5452 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    17:18:32.0368 5452 LSI_SAS - ok
    17:18:32.0384 5452 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
    17:18:32.0415 5452 LSI_SAS2 - ok
    17:18:32.0430 5452 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    17:18:32.0446 5452 LSI_SCSI - ok
    17:18:32.0477 5452 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
    17:18:32.0540 5452 luafv - ok
    17:18:32.0571 5452 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    17:18:32.0602 5452 Mcx2Svc - ok
    17:18:32.0633 5452 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
    17:18:32.0633 5452 megasas - ok
    17:18:32.0696 5452 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
    17:18:32.0711 5452 MegaSR - ok
    17:18:32.0789 5452 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
    17:18:32.0789 5452 MEIx64 - ok
    17:18:32.0820 5452 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
    17:18:32.0883 5452 MMCSS - ok
    17:18:32.0914 5452 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
    17:18:32.0992 5452 Modem - ok
    17:18:33.0054 5452 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    17:18:33.0132 5452 monitor - ok
    17:18:33.0226 5452 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    17:18:33.0242 5452 mouclass - ok
    17:18:33.0273 5452 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    17:18:33.0335 5452 mouhid - ok
    17:18:33.0382 5452 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    17:18:33.0398 5452 mountmgr - ok
    17:18:33.0413 5452 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
    17:18:33.0429 5452 mpio - ok
    17:18:33.0522 5452 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    17:18:33.0585 5452 mpsdrv - ok
    17:18:33.0616 5452 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
    17:18:33.0678 5452 MpsSvc - ok
    17:18:33.0694 5452 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    17:18:33.0725 5452 MRxDAV - ok
    17:18:33.0741 5452 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    17:18:33.0803 5452 mrxsmb - ok
    17:18:33.0819 5452 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    17:18:33.0834 5452 mrxsmb10 - ok
    17:18:33.0850 5452 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    17:18:33.0866 5452 mrxsmb20 - ok
    17:18:33.0897 5452 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
    17:18:33.0897 5452 msahci - ok
    17:18:33.0944 5452 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    17:18:33.0944 5452 msdsm - ok
    17:18:33.0959 5452 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
    17:18:34.0010 5452 MSDTC - ok
    17:18:34.0058 5452 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    17:18:34.0103 5452 Msfs - ok
    17:18:34.0175 5452 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    17:18:34.0225 5452 mshidkmdf - ok
    17:18:34.0250 5452 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    17:18:34.0290 5452 msisadrv - ok
    17:18:34.0370 5452 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    17:18:34.0440 5452 MSiSCSI - ok
    17:18:34.0443 5452 msiserver - ok
    17:18:34.0495 5452 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    17:18:34.0580 5452 MSKSSRV - ok
    17:18:34.0645 5452 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    17:18:34.0713 5452 MSPCLOCK - ok
    17:18:34.0803 5452 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    17:18:34.0853 5452 MSPQM - ok
    17:18:34.0890 5452 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    17:18:34.0910 5452 MsRPC - ok
    17:18:34.0925 5452 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
    17:18:34.0935 5452 mssmbios - ok
    17:18:34.0955 5452 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    17:18:35.0005 5452 MSTEE - ok
    17:18:35.0035 5452 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
    17:18:35.0050 5452 MTConfig - ok
    17:18:35.0078 5452 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
    17:18:35.0088 5452 Mup - ok
    17:18:35.0380 5452 [ F2840DBFE9322F35557219AE82CC4597 ] N360 C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe
    17:18:35.0405 5452 N360 - ok
    17:18:35.0460 5452 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
    17:18:35.0538 5452 napagent - ok
    17:18:35.0580 5452 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    17:18:35.0625 5452 NativeWifiP - ok
    17:18:35.0748 5452 [ C58D8A669D6551F616D90244BD2C2D4F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121106.004\ENG64.SYS
    17:18:35.0763 5452 NAVENG - ok
    17:18:35.0880 5452 [ A3DBDB412ADFA5882DD6843B11FE0828 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121106.004\EX64.SYS
    17:18:35.0918 5452 NAVEX15 - ok
    17:18:36.0023 5452 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
    17:18:36.0050 5452 NDIS - ok
    17:18:36.0100 5452 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    17:18:36.0155 5452 NdisCap - ok
    17:18:36.0240 5452 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    17:18:36.0273 5452 NdisTapi - ok
    17:18:36.0365 5452 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    17:18:36.0435 5452 Ndisuio - ok
    17:18:36.0573 5452 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    17:18:36.0645 5452 NdisWan - ok
    17:18:36.0685 5452 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    17:18:36.0732 5452 NDProxy - ok
    17:18:36.0795 5452 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    17:18:36.0841 5452 NetBIOS - ok
    17:18:36.0873 5452 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    17:18:36.0919 5452 NetBT - ok
    17:18:36.0935 5452 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
    17:18:36.0951 5452 Netlogon - ok
    17:18:37.0013 5452 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
    17:18:37.0075 5452 Netman - ok
    17:18:37.0185 5452 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
    17:18:37.0293 5452 netprofm - ok
    17:18:37.0346 5452 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    17:18:37.0356 5452 NetTcpPortSharing - ok
    17:18:37.0423 5452 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    17:18:37.0438 5452 nfrd960 - ok
    17:18:37.0501 5452 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
    17:18:37.0579 5452 NlaSvc - ok
    17:18:37.0611 5452 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    17:18:37.0642 5452 Npfs - ok
    17:18:37.0704 5452 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
    17:18:37.0751 5452 nsi - ok
    17:18:37.0767 5452 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    17:18:37.0798 5452 nsiproxy - ok
    17:18:37.0876 5452 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    17:18:37.0954 5452 Ntfs - ok
    17:18:37.0985 5452 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
    17:18:38.0016 5452 Null - ok
    17:18:38.0099 5452 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
    17:18:38.0144 5452 NVENETFD - ok
    17:18:38.0212 5452 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
    17:18:38.0227 5452 nvraid - ok
    17:18:38.0259 5452 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
    17:18:38.0289 5452 nvstor - ok
    17:18:38.0337 5452 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    17:18:38.0483 5452 nv_agp - ok
    17:18:38.0514 5452 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    17:18:38.0530 5452 ohci1394 - ok
    17:18:38.0655 5452 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    17:18:38.0670 5452 ose - ok
    17:18:39.0030 5452 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    17:18:39.0280 5452 osppsvc - ok
    17:18:39.0326 5452 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    17:18:39.0389 5452 p2pimsvc - ok
    17:18:39.0451 5452 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
    17:18:39.0482 5452 p2psvc - ok
    17:18:39.0545 5452 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
    17:18:39.0576 5452 Parport - ok
    17:18:39.0623 5452 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
    17:18:39.0623 5452 partmgr - ok
    17:18:39.0654 5452 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
    17:18:39.0701 5452 PcaSvc - ok
    17:18:39.0731 5452 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
    17:18:39.0743 5452 pci - ok
    17:18:39.0771 5452 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
    17:18:39.0793 5452 pciide - ok
    17:18:39.0821 5452 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    17:18:39.0838 5452 pcmcia - ok
    17:18:39.0863 5452 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
    17:18:39.0873 5452 pcw - ok
    17:18:39.0941 5452 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    17:18:40.0016 5452 PEAUTH - ok
    17:18:40.0133 5452 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    17:18:40.0171 5452 PerfHost - ok
    17:18:40.0243 5452 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
    17:18:40.0321 5452 pla - ok
    17:18:40.0415 5452 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    17:18:40.0477 5452 PlugPlay - ok
    17:18:40.0508 5452 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    17:18:40.0602 5452 PNRPAutoReg - ok
    17:18:40.0663 5452 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    17:18:40.0680 5452 PNRPsvc - ok
    17:18:40.0713 5452 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    17:18:40.0765 5452 PolicyAgent - ok
    17:18:40.0805 5452 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
    17:18:40.0878 5452 Power - ok
    17:18:40.0930 5452 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    17:18:41.0005 5452 PptpMiniport - ok
    17:18:41.0033 5452 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
    17:18:41.0060 5452 Processor - ok
    17:18:41.0098 5452 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
    17:18:41.0158 5452 ProfSvc - ok
    17:18:41.0173 5452 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
    17:18:41.0183 5452 ProtectedStorage - ok
    17:18:41.0218 5452 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    17:18:41.0283 5452 Psched - ok
    17:18:41.0348 5452 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
    17:18:41.0395 5452 PSI - ok
    17:18:41.0450 5452 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
    17:18:41.0498 5452 ql2300 - ok
    17:18:41.0533 5452 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
    17:18:41.0545 5452 ql40xx - ok
    17:18:41.0568 5452 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
    17:18:41.0590 5452 QWAVE - ok
    17:18:41.0605 5452 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    17:18:41.0645 5452 QWAVEdrv - ok
    17:18:41.0663 5452 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    17:18:41.0730 5452 RasAcd - ok
    17:18:41.0800 5452 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    17:18:41.0838 5452 RasAgileVpn - ok
    17:18:41.0865 5452 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
    17:18:41.0953 5452 RasAuto - ok
    17:18:41.0975 5452 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    17:18:42.0038 5452 Rasl2tp - ok
    17:18:42.0061 5452 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
    17:18:42.0106 5452 RasMan - ok
    17:18:42.0126 5452 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    17:18:42.0193 5452 RasPppoe - ok
    17:18:42.0216 5452 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    17:18:42.0286 5452 RasSstp - ok
    17:18:42.0311 5452 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    17:18:42.0371 5452 rdbss - ok
    17:18:42.0398 5452 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
    17:18:42.0428 5452 rdpbus - ok
    17:18:42.0446 5452 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    17:18:42.0496 5452 RDPCDD - ok
    17:18:42.0506 5452 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    17:18:42.0566 5452 RDPENCDD - ok
    17:18:42.0591 5452 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
    17:18:42.0626 5452 RDPREFMP - ok
    17:18:42.0666 5452 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
    17:18:42.0751 5452 RdpVideoMiniport - ok
    17:18:42.0781 5452 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    17:18:42.0816 5452 RDPWD - ok
    17:18:42.0838 5452 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    17:18:42.0853 5452 rdyboost - ok
    17:18:42.0878 5452 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
    17:18:42.0991 5452 RemoteAccess - ok
    17:18:43.0041 5452 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    17:18:43.0116 5452 RemoteRegistry - ok
    17:18:43.0178 5452 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
    17:18:43.0223 5452 RFCOMM - ok
    17:18:43.0296 5452 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    17:18:43.0356 5452 RpcEptMapper - ok
    17:18:43.0386 5452 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
    17:18:43.0401 5452 RpcLocator - ok
    17:18:43.0433 5452 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
    17:18:43.0478 5452 RpcSs - ok
    17:18:43.0513 5452 [ 6E5C3D18C3BCC72AA527DBC5FA61AB8F ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys
    17:18:43.0548 5452 RSPCIESTOR - ok
    17:18:43.0576 5452 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    17:18:43.0636 5452 rspndr - ok
    17:18:43.0736 5452 [ 9140DB0911DE035FED0A9A77A2D156EA ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
    17:18:43.0756 5452 RTL8167 - ok
    17:18:43.0806 5452 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
    17:18:43.0816 5452 SamSs - ok
    17:18:43.0851 5452 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    17:18:43.0861 5452 sbp2port - ok
    17:18:43.0901 5452 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
    17:18:43.0936 5452 SCardSvr - ok
    17:18:43.0991 5452 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    17:18:44.0106 5452 scfilter - ok
    17:18:44.0176 5452 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
    17:18:44.0241 5452 Schedule - ok
    17:18:44.0271 5452 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
    17:18:44.0316 5452 SCPolicySvc - ok
    17:18:44.0401 5452 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
    17:18:44.0446 5452 sdbus - ok
    17:18:44.0516 5452 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    17:18:44.0566 5452 SDRSVC - ok
    17:18:44.0606 5452 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    17:18:44.0661 5452 secdrv - ok
    17:18:44.0686 5452 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
    17:18:44.0731 5452 seclogon - ok
    17:18:45.0071 5452 [ 9901DCF2B6DD2AD12CB42BD559E0C92D ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    17:18:45.0101 5452 Secunia PSI Agent - ok
    17:18:45.0226 5452 [ 4F2056349F8BA4154D5213BF8A476B14 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
    17:18:45.0243 5452 Secunia Update Agent - ok
    17:18:45.0303 5452 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
    17:18:45.0363 5452 SENS - ok
    17:18:45.0451 5452 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
    17:18:45.0516 5452 SensrSvc - ok
    17:18:45.0591 5452 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
    17:18:45.0631 5452 Serenum - ok
    17:18:45.0701 5452 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
    17:18:45.0781 5452 Serial - ok
    17:18:45.0826 5452 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
    17:18:45.0858 5452 sermouse - ok
    17:18:45.0908 5452 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
    17:18:46.0083 5452 SessionEnv - ok
    17:18:46.0103 5452 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    17:18:46.0113 5452 sffdisk - ok
    17:18:46.0158 5452 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    17:18:46.0183 5452 sffp_mmc - ok
    17:18:46.0228 5452 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    17:18:46.0248 5452 sffp_sd - ok
    17:18:46.0273 5452 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
    17:18:46.0283 5452 sfloppy - ok
    17:18:46.0338 5452 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
    17:18:46.0388 5452 SharedAccess - ok
    17:18:46.0423 5452 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    17:18:46.0468 5452 ShellHWDetection - ok
    17:18:46.0523 5452 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
    17:18:46.0543 5452 SiSRaid2 - ok
    17:18:46.0568 5452 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    17:18:46.0588 5452 SiSRaid4 - ok
    17:18:46.0643 5452 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    17:18:46.0653 5452 SkypeUpdate - ok
    17:18:46.0698 5452 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    17:18:46.0763 5452 Smb - ok
    17:18:46.0838 5452 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    17:18:46.0878 5452 SNMPTRAP - ok
    17:18:46.0918 5452 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
    17:18:46.0928 5452 spldr - ok
    17:18:46.0973 5452 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
    17:18:47.0028 5452 Spooler - ok
    17:18:47.0188 5452 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
    17:18:47.0303 5452 sppsvc - ok
    17:18:47.0338 5452 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
    17:18:47.0368 5452 sppuinotify - ok
    17:18:47.0468 5452 [ 891793E00432FA055CF040605C260E49 ] SRTSP C:\Windows\System32\Drivers\N360x64\0604000.009\SRTSP64.SYS
    17:18:47.0508 5452 SRTSP - ok
    17:18:47.0523 5452 [ 1CB7BB3B0561FB5ECFE37F7731E8BF3E ] SRTSPX C:\Windows\system32\drivers\N360x64\0604000.009\SRTSPX64.SYS
    17:18:47.0533 5452 SRTSPX - ok
    17:18:47.0573 5452 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
    17:18:47.0613 5452 srv - ok
    17:18:47.0633 5452 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    17:18:47.0673 5452 srv2 - ok
    17:18:47.0718 5452 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    17:18:47.0748 5452 SrvHsfHDA - ok
    17:18:47.0838 5452 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS
    17:18:47.0958 5452 SrvHsfV92 - ok
    17:18:48.0033 5452 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
    17:18:48.0078 5452 SrvHsfWinac - ok
    17:18:48.0153 5452 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    17:18:48.0178 5452 srvnet - ok
    17:18:48.0218 5452 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    17:18:48.0273 5452 SSDPSRV - ok
    17:18:48.0343 5452 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
    17:18:48.0383 5452 SstpSvc - ok
    17:18:48.0553 5452 [ 7BF818B11C1FEDC3E76D233124470A30 ] STacSV C:\Program Files\IDT\WDM\STacSV64.exe
    17:18:48.0678 5452 STacSV - ok
    17:18:48.0718 5452 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
    17:18:48.0728 5452 stexstor - ok
    17:18:48.0838 5452 [ EBC1A5E076A9BE314D3D9E8ED19ABB0A ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
    17:18:48.0928 5452 STHDA - ok
    17:18:48.0978 5452 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
    17:18:49.0023 5452 stisvc - ok
    17:18:49.0048 5452 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
    17:18:49.0058 5452 swenum - ok
    17:18:49.0123 5452 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
    17:18:49.0183 5452 swprv - ok
    17:18:49.0228 5452 [ 8B2430762099598DA40686F754632EFD ] SymDS C:\Windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS
    17:18:49.0243 5452 SymDS - ok
    17:18:49.0363 5452 [ 5CB7F2FD7E30A0F52F93574BFC3A8041 ] SymEFA C:\Windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS
    17:18:49.0388 5452 SymEFA - ok
    17:18:49.0433 5452 [ 898BB48C797483420DF523B2BBC1ECDB ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
    17:18:49.0448 5452 SymEvent - ok
    17:18:49.0488 5452 [ 5013A76CAAA1D7CF1C55214B490B4E35 ] SymIRON C:\Windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS
    17:18:49.0503 5452 SymIRON - ok
    17:18:49.0543 5452 [ 3911BD0E68C010E5438A87706ABBE9AB ] SymNetS C:\Windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS
    17:18:49.0593 5452 SymNetS - ok
    17:18:49.0648 5452 [ AC3CC98B1BDB6540021D3FFB105AC2B9 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
    17:18:49.0663 5452 SynTP - ok
    17:18:49.0718 5452 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
    17:18:49.0768 5452 SysMain - ok
    17:18:49.0793 5452 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
    17:18:49.0828 5452 TabletInputService - ok
    17:18:49.0873 5452 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
    17:18:49.0973 5452 TapiSrv - ok
    17:18:49.0998 5452 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
    17:18:50.0038 5452 TBS - ok
    17:18:50.0133 5452 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    17:18:50.0178 5452 Tcpip - ok
    17:18:50.0218 5452 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    17:18:50.0263 5452 TCPIP6 - ok
    17:18:50.0298 5452 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    17:18:50.0343 5452 tcpipreg - ok
    17:18:50.0368 5452 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    17:18:50.0383 5452 TDPIPE - ok
    17:18:50.0413 5452 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    17:18:50.0433 5452 TDTCP - ok
    17:18:50.0458 5452 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    17:18:50.0493 5452 tdx - ok
    17:18:50.0523 5452 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
    17:18:50.0533 5452 TermDD - ok
    17:18:50.0623 5452 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
    17:18:50.0678 5452 TermService - ok
    17:18:50.0703 5452 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
    17:18:50.0733 5452 Themes - ok
    17:18:50.0763 5452 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
    17:18:50.0798 5452 THREADORDER - ok
    17:18:50.0813 5452 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
    17:18:50.0873 5452 TrkWks - ok
    17:18:50.0923 5452 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    17:18:51.0028 5452 TrustedInstaller - ok
    17:18:51.0048 5452 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    17:18:51.0108 5452 tssecsrv - ok
    17:18:51.0148 5452 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    17:18:51.0203 5452 TsUsbFlt - ok
    17:18:51.0238 5452 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
    17:18:51.0248 5452 TsUsbGD - ok
    17:18:51.0288 5452 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    17:18:51.0333 5452 tunnel - ok
    17:18:51.0368 5452 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    17:18:51.0378 5452 uagp35 - ok
    17:18:51.0403 5452 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    17:18:51.0448 5452 udfs - ok
    17:18:51.0478 5452 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
    17:18:51.0493 5452 UI0Detect - ok
    17:18:51.0543 5452 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    17:18:51.0553 5452 uliagpkx - ok
    17:18:51.0573 5452 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    17:18:51.0603 5452 umbus - ok
    17:18:51.0638 5452 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
    17:18:51.0663 5452 UmPass - ok
    17:18:51.0778 5452 [ 758C2CE427C343F780A205E28555C98D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    17:18:51.0843 5452 UNS - ok
    17:18:51.0873 5452 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
    17:18:51.0928 5452 upnphost - ok
    17:18:51.0958 5452 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    17:18:51.0993 5452 usbccgp - ok
    17:18:52.0018 5452 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    17:18:52.0038 5452 usbcir - ok
    17:18:52.0053 5452 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
    17:18:52.0083 5452 usbehci - ok
    17:18:52.0108 5452 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\drivers\usbhub.sys
    17:18:52.0148 5452 usbhub - ok
    17:18:52.0168 5452 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    17:18:52.0198 5452 usbohci - ok
    17:18:52.0228 5452 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
    17:18:52.0253 5452 usbprint - ok
    17:18:52.0288 5452 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    17:18:52.0338 5452 USBSTOR - ok
    17:18:52.0353 5452 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
    17:18:52.0383 5452 usbuhci - ok
    17:18:52.0408 5452 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
    17:18:52.0428 5452 usbvideo - ok
    17:18:52.0468 5452 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
    17:18:52.0513 5452 UxSms - ok
    17:18:52.0528 5452 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
    17:18:52.0538 5452 VaultSvc - ok
    17:18:52.0553 5452 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    17:18:52.0563 5452 vdrvroot - ok
    17:18:52.0583 5452 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
    17:18:52.0643 5452 vds - ok
    17:18:52.0673 5452 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    17:18:52.0688 5452 vga - ok
    17:18:52.0703 5452 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
    17:18:52.0778 5452 VgaSave - ok
    17:18:52.0808 5452 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
    17:18:52.0823 5452 vhdmp - ok
    17:18:52.0838 5452 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
    17:18:52.0848 5452 viaide - ok
    17:18:52.0878 5452 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    17:18:52.0888 5452 volmgr - ok
    17:18:52.0913 5452 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    17:18:52.0928 5452 volmgrx - ok
    17:18:52.0943 5452 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\Windows\system32\drivers\volsnap.sys
    17:18:52.0958 5452 volsnap - ok
    17:18:52.0983 5452 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    17:18:52.0998 5452 vsmraid - ok
    17:18:53.0048 5452 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
    17:18:53.0118 5452 VSS - ok
    17:18:53.0143 5452 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
    17:18:53.0173 5452 vwifibus - ok
    17:18:53.0183 5452 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    17:18:53.0208 5452 vwififlt - ok
    17:18:53.0253 5452 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
    17:18:53.0268 5452 vwifimp - ok
    17:18:53.0288 5452 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
    17:18:53.0328 5452 W32Time - ok
    17:18:53.0353 5452 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
    17:18:53.0373 5452 WacomPen - ok
    17:18:53.0408 5452 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
    17:18:53.0508 5452 WANARP - ok
    17:18:53.0513 5452 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    17:18:53.0553 5452 Wanarpv6 - ok
    17:18:53.0638 5452 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
    17:18:53.0683 5452 WatAdminSvc - ok
    17:18:53.0743 5452 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
    17:18:53.0803 5452 wbengine - ok
    17:18:53.0823 5452 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    17:18:53.0838 5452 WbioSrvc - ok
    17:18:53.0863 5452 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
    17:18:53.0898 5452 wcncsvc - ok
    17:18:53.0918 5452 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    17:18:53.0943 5452 WcsPlugInService - ok
    17:18:53.0973 5452 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
    17:18:53.0983 5452 Wd - ok
    17:18:54.0028 5452 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    17:18:54.0073 5452 Wdf01000 - ok
    17:18:54.0093 5452 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
    17:18:54.0163 5452 WdiServiceHost - ok
    17:18:54.0168 5452 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
    17:18:54.0183 5452 WdiSystemHost - ok
    17:18:54.0213 5452 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
    17:18:54.0253 5452 WebClient - ok
    17:18:54.0273 5452 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
    17:18:54.0323 5452 Wecsvc - ok
    17:18:54.0338 5452 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    17:18:54.0373 5452 wercplsupport - ok
    17:18:54.0403 5452 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
    17:18:54.0453 5452 WerSvc - ok
    17:18:54.0478 5452 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
    17:18:54.0538 5452 WfpLwf - ok
    17:18:54.0558 5452 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    17:18:54.0568 5452 WIMMount - ok
    17:18:54.0578 5452 WinDefend - ok
    17:18:54.0583 5452 WinHttpAutoProxySvc - ok
    17:18:54.0638 5452 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    17:18:54.0678 5452 Winmgmt - ok
    17:18:54.0736 5452 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
    17:18:54.0796 5452 WinRM - ok
    17:18:54.0856 5452 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
    17:18:54.0906 5452 Wlansvc - ok
    17:18:54.0956 5452 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    17:18:54.0981 5452 wlcrasvc - ok
    17:18:55.0131 5452 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    17:18:55.0196 5452 wlidsvc - ok
    17:18:55.0226 5452 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    17:18:55.0261 5452 WmiAcpi - ok
    17:18:55.0306 5452 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    17:18:55.0336 5452 wmiApSrv - ok
    17:18:55.0371 5452 WMPNetworkSvc - ok
    17:18:55.0396 5452 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
    17:18:55.0431 5452 WPCSvc - ok
    17:18:55.0441 5452 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    17:18:55.0481 5452 WPDBusEnum - ok
    17:18:55.0516 5452 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    17:18:55.0556 5452 ws2ifsl - ok
    17:18:55.0566 5452 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
    17:18:55.0601 5452 wscsvc - ok
    17:18:55.0636 5452 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
    17:18:55.0651 5452 WSDPrintDevice - ok
    17:18:55.0691 5452 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
    17:18:55.0726 5452 WSDScan - ok
    17:18:55.0731 5452 WSearch - ok
    17:18:55.0826 5452 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    17:18:55.0876 5452 wuauserv - ok
    17:18:55.0891 5452 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    17:18:55.0936 5452 WudfPf - ok
    17:18:55.0966 5452 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    17:18:56.0016 5452 WUDFRd - ok
    17:18:56.0051 5452 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    17:18:56.0086 5452 wudfsvc - ok
    17:18:56.0121 5452 [ CE8CF9DE9CBFDAA318BD04D8BE3FCADA ] WwanSvc C:\Windows\System32\wwansvc.dll
    17:18:56.0151 5452 WwanSvc - ok
    17:18:56.0206 5452 ================ Scan global ===============================
    17:18:56.0231 5452 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
    17:18:56.0261 5452 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    17:18:56.0266 5452 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    17:18:56.0296 5452 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
    17:18:56.0336 5452 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
    17:18:56.0336 5452 [Global] - ok
    17:18:56.0336 5452 ================ Scan MBR ==================================
    17:18:56.0351 5452 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    17:18:57.0186 5452 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
    17:18:57.0186 5452 \Device\Harddisk0\DR0 - detected TDSS File System (1)
    17:18:57.0186 5452 ================ Scan VBR ==================================
    17:18:57.0216 5452 [ 7893EF093958182A7A126B2E3CEE4DF1 ] \Device\Harddisk0\DR0\Partition1
    17:18:57.0216 5452 \Device\Harddisk0\DR0\Partition1 - ok
    17:18:57.0226 5452 [ 2041DA3A0667CAB1C92135CB70185EEF ] \Device\Harddisk0\DR0\Partition2
    17:18:57.0226 5452 \Device\Harddisk0\DR0\Partition2 - ok
    17:18:57.0256 5452 [ B8174525FD82EE856AE374E606C70890 ] \Device\Harddisk0\DR0\Partition3
    17:18:57.0261 5452 \Device\Harddisk0\DR0\Partition3 - ok
    17:18:57.0276 5452 [ 626CDAED975D0B276F162356B94FE557 ] \Device\Harddisk0\DR0\Partition4
    17:18:57.0276 5452 \Device\Harddisk0\DR0\Partition4 - ok
    17:18:57.0281 5452 ============================================================
    17:18:57.0281 5452 Scan finished
    17:18:57.0281 5452 ============================================================
    17:18:57.0296 5444 Detected object count: 1
    17:18:57.0296 5444 Actual detected object count: 1
    17:19:11.0358 5444 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    17:19:11.0358 5444 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
    17:26:08.0719 4432 Deinitialize success
  10. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-11-07 17:26:11
    -----------------------------
    17:26:11.832 OS Version: Windows x64 6.1.7601 Service Pack 1
    17:26:11.832 Number of processors: 4 586 0x2A07
    17:26:11.832 ComputerName: SUNSHINE-HP UserName: Sunshine
    17:26:13.592 Initialize success
    17:26:18.275 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    17:26:18.280 Disk 0 Vendor: TOSHIBA_ GT00 Size: 715404MB BusType: 3
    17:26:18.295 Disk 0 MBR read successfully
    17:26:18.300 Disk 0 MBR scan
    17:26:18.305 Disk 0 Windows 7 default MBR code
    17:26:18.315 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
    17:26:18.335 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 690597 MB offset 409600
    17:26:18.370 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 20544 MB offset 1414752256
    17:26:18.390 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 4062 MB offset 1456826368
    17:26:18.435 Disk 0 scanning C:\Windows\system32\drivers
    17:26:25.055 Service scanning
    17:26:51.265 Modules scanning
    17:26:51.280 Scan finished successfully
    17:27:30.398 Disk 0 MBR has been saved successfully to "C:\Users\Sunshine\Desktop\MBR.dat"
    17:27:30.403 The log file has been saved successfully to "C:\Users\Sunshine\Desktop\aswMBR.txt"
  11. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Here is the document that is to be uploaded.
    Thank you again for your help!! It is much appreciated.
    Becky

    Attached Files:

     
  12. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Kaspersky Virus Removal Tool

    The Kaspersky Virus Removal Tool is a scan-and-remove solution from Kaspersky that searches out the most common malware and attempts to remove it from your computer.

    Please download the Kaspersky Virus Removal Tool from Kaspersky's Official Link and save it to your Desktop.

    • Double-click the Setup file to install it on your computer.
    • Once it has installed, review and accept the agreement and press the Start button.
    • You will presented with the main interface, but don't scan yet, click the options tab (gear icon):
      [​IMG]
    • On the Scan Scope tab, make sure to checkmark all the options, except for the CD/DVD drive:
      [​IMG]
    • On the Security Level tab, make sure to move the slider up denoting "Current Security Level: High":
      [​IMG]
    • Now, go back to the Automatic Scan tab, and choose "Start Scanning". It may take several hours to complete. Please allow it to do so.
    • Once done scanning, choose the Report tab (page icon), select Detected Threats tab on left, and choose Disinfect All:
      [​IMG]
    • Then, choose Save. Also, in the Automatic Report tab, select Save:
      [​IMG]
    • Please post the reports in your next reply.
    • Once you exit, the tool should uninstall automatically.
  13. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Status: Deleted (events: 3)
    11/9/2012 6:08:29 AM Deleted Trojan program Rootkit.Boot.Pihar.b C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\mbr0000\tsk0000.dta//HDDImage High
    11/9/2012 6:10:51 AM Deleted Trojan program Rootkit.Win64.TDSS.q C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\tdlfs0000\tsk0003.dta High
    11/9/2012 6:08:29 AM Deleted Trojan program Rootkit.Boot.Pihar.b C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\mbr0000\tsk0000.dta High
    Status: Detected (events: 3)
    11/8/2012 11:54:38 AM Detected Trojan program Rootkit.Boot.Pihar.b C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\mbr0000\tsk0001.dta//vbr0 High
    11/8/2012 12:06:53 PM Detected Trojan program Trojan.Win64.TDSS.c C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\tdlfs0000\tsk0001.dta High
    11/8/2012 10:06:29 PM Detected Trojan program Rootkit.Win32.TDSS.gq C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\tdlfs0000\tsk0007.dta High

    Also it would not let me disinfect any of the detected. When I clicked on disinfect, it came up with saying saying delete (recommended). I clicked on that and then it came up Could not perform that either and my only option was skip. The scan said it detected 5 things but I am not sure if they are all gone.
  14. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Now TDSSKiller once more and then this:

    avast! aswMBR

    Please download aswMBR from here
    • Save aswMBR.exe to your Desktop
    • Double click aswMBR.exe to run it
    • Uncheck "Trace disk IO calls".
    • Click the Scan button to start the scan as illustrated below
    [​IMG]
    Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives.
    • Once the scan finishes click Save log to save the log to your Desktop
      [​IMG]
    • Copy and paste the contents of aswMBR.txt back here for review
    • Please also find MBR.dat on your Desktop, and rename it to MBRscan.txt. Upload that as well. Do not copy and paste MBR.dat/txt, it needs to be uploaded.
  15. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    21:11:56.0025 7640 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
    21:11:56.0430 7640 ============================================================
    21:11:56.0430 7640 Current date / time: 2012/11/09 21:11:56.0430
    21:11:56.0430 7640 SystemInfo:
    21:11:56.0430 7640
    21:11:56.0430 7640 OS Version: 6.1.7601 ServicePack: 1.0
    21:11:56.0430 7640 Product type: Workstation
    21:11:56.0430 7640 ComputerName: SUNSHINE-HP
    21:11:56.0430 7640 UserName: Sunshine
    21:11:56.0430 7640 Windows directory: C:\Windows
    21:11:56.0430 7640 System windows directory: C:\Windows
    21:11:56.0430 7640 Running under WOW64
    21:11:56.0430 7640 Processor architecture: Intel x64
    21:11:56.0430 7640 Number of processors: 4
    21:11:56.0430 7640 Page size: 0x1000
    21:11:56.0430 7640 Boot type: Normal boot
    21:11:56.0430 7640 ============================================================
    21:11:57.0235 7640 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    21:11:57.0250 7640 ============================================================
    21:11:57.0250 7640 \Device\Harddisk0\DR0:
    21:11:57.0250 7640 MBR partitions:
    21:11:57.0250 7640 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800
    21:11:57.0250 7640 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x544D2800
    21:11:57.0250 7640 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x54536800, BlocksNum 0x2820000
    21:11:57.0250 7640 \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x56D56800, BlocksNum 0x7EF000
    21:11:57.0250 7640 ============================================================
    21:11:57.0285 7640 C: <-> \Device\Harddisk0\DR0\Partition2
    21:11:57.0320 7640 D: <-> \Device\Harddisk0\DR0\Partition3
    21:11:57.0340 7640 E: <-> \Device\Harddisk0\DR0\Partition4
    21:11:57.0340 7640 ============================================================
    21:11:57.0340 7640 Initialize success
    21:11:57.0340 7640 ============================================================
    21:12:08.0155 8384 ============================================================
    21:12:08.0155 8384 Scan started
    21:12:08.0155 8384 Mode: Manual; SigCheck; TDLFS;
    21:12:08.0155 8384 ============================================================
    21:12:09.0575 8384 ================ Scan system memory ========================
    21:12:09.0575 8384 System memory - ok
    21:12:09.0580 8384 ================ Scan services =============================
    21:12:09.0785 8384 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
    21:12:09.0920 8384 1394ohci - ok
    21:12:09.0995 8384 [ E656FE10D6D27794AFA08136685A69E8 ] 85507188 C:\Windows\system32\DRIVERS\85507188.sys
    21:12:10.0045 8384 85507188 - ok
    21:12:10.0090 8384 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
    21:12:10.0110 8384 ACPI - ok
    21:12:10.0140 8384 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
    21:12:10.0195 8384 AcpiPmi - ok
    21:12:10.0300 8384 [ B1EA9681502EE57F87DB71D726288A5B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    21:12:10.0340 8384 AdobeARMservice - ok
    21:12:10.0510 8384 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    21:12:10.0550 8384 AdobeFlashPlayerUpdateSvc - ok
    21:12:10.0620 8384 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    21:12:10.0675 8384 adp94xx - ok
    21:12:10.0710 8384 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
    21:12:10.0730 8384 adpahci - ok
    21:12:10.0745 8384 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    21:12:10.0765 8384 adpu320 - ok
    21:12:10.0790 8384 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    21:12:10.0845 8384 AeLookupSvc - ok
    21:12:10.0890 8384 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
    21:12:10.0925 8384 AFD - ok
    21:12:10.0965 8384 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
    21:12:10.0980 8384 agp440 - ok
    21:12:11.0020 8384 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
    21:12:11.0055 8384 ALG - ok
    21:12:11.0110 8384 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
    21:12:11.0125 8384 aliide - ok
    21:12:11.0145 8384 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
    21:12:11.0165 8384 amdide - ok
    21:12:11.0210 8384 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
    21:12:11.0245 8384 AmdK8 - ok
    21:12:11.0260 8384 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
    21:12:11.0290 8384 AmdPPM - ok
    21:12:11.0325 8384 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    21:12:11.0345 8384 amdsata - ok
    21:12:11.0375 8384 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
    21:12:11.0395 8384 amdsbs - ok
    21:12:11.0415 8384 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    21:12:11.0430 8384 amdxata - ok
    21:12:11.0485 8384 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
    21:12:11.0545 8384 AppID - ok
    21:12:11.0570 8384 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    21:12:11.0640 8384 AppIDSvc - ok
    21:12:11.0685 8384 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
    21:12:11.0745 8384 Appinfo - ok
    21:12:11.0780 8384 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
    21:12:11.0795 8384 arc - ok
    21:12:11.0820 8384 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
    21:12:11.0835 8384 arcsas - ok
    21:12:11.0875 8384 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    21:12:11.0965 8384 AsyncMac - ok
    21:12:11.0980 8384 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
    21:12:11.0995 8384 atapi - ok
    21:12:12.0040 8384 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    21:12:12.0105 8384 AudioEndpointBuilder - ok
    21:12:12.0115 8384 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    21:12:12.0160 8384 AudioSrv - ok
    21:12:12.0200 8384 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
    21:12:12.0235 8384 AxInstSV - ok
    21:12:12.0280 8384 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
    21:12:12.0315 8384 b06bdrv - ok
    21:12:12.0335 8384 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
    21:12:12.0380 8384 b57nd60a - ok
    21:12:12.0425 8384 [ 09A19C806110CE839111850EC27E65F5 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys
    21:12:12.0440 8384 bcbtums - ok
    21:12:12.0565 8384 [ 461E574D7967E895640109A371A912A5 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys
    21:12:12.0670 8384 BCM43XX - ok
    21:12:12.0695 8384 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
    21:12:12.0725 8384 BDESVC - ok
    21:12:12.0765 8384 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
    21:12:12.0830 8384 Beep - ok
    21:12:12.0890 8384 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
    21:12:12.0955 8384 BFE - ok
    21:12:13.0160 8384 [ 652F4D186325B69FFE80EE18AE9ACC77 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\BASHDefs\20121030.002\BHDrvx64.sys
    21:12:13.0225 8384 BHDrvx64 - ok
    21:12:13.0260 8384 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
    21:12:13.0330 8384 BITS - ok
    21:12:13.0375 8384 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
    21:12:13.0440 8384 blbdrive - ok
    21:12:13.0485 8384 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    21:12:13.0520 8384 bowser - ok
    21:12:13.0550 8384 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
    21:12:13.0590 8384 BrFiltLo - ok
    21:12:13.0615 8384 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
    21:12:13.0635 8384 BrFiltUp - ok
    21:12:13.0695 8384 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
    21:12:13.0755 8384 BridgeMP - ok
    21:12:13.0800 8384 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
    21:12:13.0840 8384 Browser - ok
    21:12:13.0870 8384 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
    21:12:13.0945 8384 Brserid - ok
    21:12:13.0965 8384 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    21:12:14.0005 8384 BrSerWdm - ok
    21:12:14.0035 8384 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    21:12:14.0065 8384 BrUsbMdm - ok
    21:12:14.0085 8384 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
    21:12:14.0120 8384 BrUsbSer - ok
    21:12:14.0160 8384 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
    21:12:14.0200 8384 BthEnum - ok
    21:12:14.0250 8384 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
    21:12:14.0310 8384 BTHMODEM - ok
    21:12:14.0330 8384 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
    21:12:14.0365 8384 BthPan - ok
    21:12:14.0390 8384 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
    21:12:14.0435 8384 BTHPORT - ok
    21:12:14.0480 8384 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
    21:12:14.0540 8384 bthserv - ok
    21:12:14.0565 8384 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
    21:12:14.0635 8384 BTHUSB - ok
    21:12:14.0670 8384 [ 0E78584D5FACA0509DFA97BD8B635075 ] btwampfl C:\Windows\system32\drivers\btwampfl.sys
    21:12:14.0700 8384 btwampfl - ok
    21:12:14.0725 8384 [ 409C4117E6027672EF41E68ACE1468AD ] btwaudio C:\Windows\system32\drivers\btwaudio.sys
    21:12:14.0745 8384 btwaudio - ok
    21:12:14.0770 8384 [ 8CA7CABD13316ABACE386D9F380B4CF3 ] btwavdt C:\Windows\system32\DRIVERS\btwavdt.sys
    21:12:14.0785 8384 btwavdt - ok
    21:12:14.0945 8384 [ 1249EDE2280F9A1564C946AFDDCD59D5 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    21:12:14.0985 8384 btwdins - ok
    21:12:15.0035 8384 [ 41933521A618475644B6E8D8487AF326 ] BTWDPAN C:\Windows\system32\DRIVERS\btwdpan.sys
    21:12:15.0065 8384 BTWDPAN - ok
    21:12:15.0080 8384 [ B9354F9F111C64F2495B60F1E24CB453 ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys
    21:12:15.0105 8384 btwl2cap - ok
    21:12:15.0130 8384 [ 71A04F2D9DEB21B162561EB574D7D629 ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys
    21:12:15.0145 8384 btwrchid - ok
    21:12:15.0185 8384 catchme - ok
    21:12:15.0255 8384 [ 2C6FFCCA37B002AAB3C7C31A6D780A76 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\0604000.009\ccSetx64.sys
    21:12:15.0270 8384 ccSet_N360 - ok
    21:12:15.0320 8384 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    21:12:15.0365 8384 cdfs - ok
    21:12:15.0395 8384 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    21:12:15.0425 8384 cdrom - ok
    21:12:15.0485 8384 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
    21:12:15.0580 8384 CertPropSvc - ok
    21:12:15.0610 8384 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
    21:12:15.0650 8384 circlass - ok
    21:12:15.0700 8384 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
    21:12:15.0720 8384 CLFS - ok
    21:12:15.0775 8384 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    21:12:15.0790 8384 clr_optimization_v2.0.50727_32 - ok
    21:12:15.0830 8384 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    21:12:15.0845 8384 clr_optimization_v2.0.50727_64 - ok
    21:12:15.0955 8384 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    21:12:15.0980 8384 clr_optimization_v4.0.30319_32 - ok
    21:12:16.0040 8384 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    21:12:16.0080 8384 clr_optimization_v4.0.30319_64 - ok
    21:12:16.0120 8384 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
    21:12:16.0135 8384 clwvd - ok
    21:12:16.0180 8384 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
    21:12:16.0230 8384 CmBatt - ok
    21:12:16.0240 8384 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
    21:12:16.0260 8384 cmdide - ok
    21:12:16.0310 8384 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
    21:12:16.0360 8384 CNG - ok
    21:12:16.0400 8384 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
    21:12:16.0440 8384 Compbatt - ok
    21:12:16.0475 8384 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
    21:12:16.0525 8384 CompositeBus - ok
    21:12:16.0540 8384 COMSysApp - ok
    21:12:16.0555 8384 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
    21:12:16.0570 8384 crcdisk - ok
    21:12:16.0625 8384 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
    21:12:16.0710 8384 CryptSvc - ok
    21:12:16.0770 8384 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
    21:12:16.0855 8384 DcomLaunch - ok
    21:12:16.0880 8384 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
    21:12:16.0945 8384 defragsvc - ok
    21:12:16.0985 8384 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    21:12:17.0045 8384 DfsC - ok
    21:12:17.0090 8384 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
    21:12:17.0155 8384 Dhcp - ok
    21:12:17.0190 8384 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
    21:12:17.0235 8384 discache - ok
    21:12:17.0265 8384 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
    21:12:17.0285 8384 Disk - ok
    21:12:17.0330 8384 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    21:12:17.0390 8384 Dnscache - ok
    21:12:17.0420 8384 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
    21:12:17.0485 8384 dot3svc - ok
    21:12:17.0500 8384 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
    21:12:17.0555 8384 DPS - ok
    21:12:17.0595 8384 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    21:12:17.0630 8384 drmkaud - ok
    21:12:17.0675 8384 [ A4F408AD1065C7AD2ED332C68025B435 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    21:12:17.0710 8384 DXGKrnl - ok
    21:12:17.0740 8384 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
    21:12:17.0795 8384 EapHost - ok
    21:12:17.0880 8384 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
    21:12:17.0955 8384 ebdrv - ok
    21:12:18.0055 8384 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    21:12:18.0095 8384 eeCtrl - ok
    21:12:18.0125 8384 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
    21:12:18.0155 8384 EFS - ok
    21:12:18.0235 8384 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    21:12:18.0290 8384 ehRecvr - ok
    21:12:18.0305 8384 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
    21:12:18.0325 8384 ehSched - ok
    21:12:18.0365 8384 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
    21:12:18.0395 8384 elxstor - ok
    21:12:18.0460 8384 [ 7C5BFAAC8DCE7292B0C04EBF892E71F9 ] EPSON_EB_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE
    21:12:18.0505 8384 EPSON_EB_RPCV4_04 - ok
    21:12:18.0515 8384 [ D4615670CD49A1679E6067F155C47C68 ] EPSON_PM_RPCV4_04 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE
    21:12:18.0545 8384 EPSON_PM_RPCV4_04 - ok
    21:12:18.0585 8384 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    21:12:18.0600 8384 EraserUtilRebootDrv - ok
    21:12:18.0630 8384 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
    21:12:18.0665 8384 ErrDev - ok
    21:12:18.0720 8384 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
    21:12:18.0785 8384 EventSystem - ok
    21:12:18.0825 8384 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
    21:12:18.0870 8384 exfat - ok
    21:12:18.0880 8384 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
    21:12:18.0935 8384 fastfat - ok
    21:12:18.0980 8384 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
    21:12:19.0015 8384 Fax - ok
    21:12:19.0040 8384 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
    21:12:19.0070 8384 fdc - ok
    21:12:19.0115 8384 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
    21:12:19.0155 8384 fdPHost - ok
    21:12:19.0165 8384 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
    21:12:19.0205 8384 FDResPub - ok
    21:12:19.0225 8384 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    21:12:19.0240 8384 FileInfo - ok
    21:12:19.0260 8384 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    21:12:19.0315 8384 Filetrace - ok
    21:12:19.0335 8384 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
    21:12:19.0350 8384 flpydisk - ok
    21:12:19.0360 8384 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    21:12:19.0380 8384 FltMgr - ok
    21:12:19.0415 8384 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
    21:12:19.0460 8384 FontCache - ok
    21:12:19.0515 8384 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    21:12:19.0525 8384 FontCache3.0.0.0 - ok
    21:12:19.0590 8384 [ EC3949088F617ACC056FC1AB54A6A13B ] FPLService C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
    21:12:19.0620 8384 FPLService - ok
    21:12:19.0625 8384 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    21:12:19.0640 8384 FsDepends - ok
    21:12:19.0665 8384 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    21:12:19.0680 8384 Fs_Rec - ok
    21:12:19.0745 8384 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    21:12:19.0770 8384 fvevol - ok
    21:12:19.0805 8384 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    21:12:19.0820 8384 gagp30kx - ok
    21:12:19.0890 8384 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
    21:12:19.0925 8384 GamesAppService - ok
    21:12:19.0970 8384 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
    21:12:20.0030 8384 gpsvc - ok
    21:12:20.0140 8384 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:12:20.0180 8384 gupdate - ok
    21:12:20.0185 8384 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:12:20.0200 8384 gupdatem - ok
    21:12:20.0265 8384 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    21:12:20.0300 8384 gusvc - ok
    21:12:20.0330 8384 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    21:12:20.0365 8384 hcw85cir - ok
    21:12:20.0390 8384 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    21:12:20.0430 8384 HdAudAddService - ok
    21:12:20.0470 8384 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
    21:12:20.0505 8384 HDAudBus - ok
    21:12:20.0530 8384 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
    21:12:20.0555 8384 HidBatt - ok
    21:12:20.0580 8384 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
    21:12:20.0610 8384 HidBth - ok
    21:12:20.0640 8384 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
    21:12:20.0665 8384 HidIr - ok
    21:12:20.0690 8384 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
    21:12:20.0785 8384 hidserv - ok
    21:12:20.0815 8384 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    21:12:20.0830 8384 HidUsb - ok
    21:12:20.0840 8384 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
    21:12:20.0895 8384 hkmsvc - ok
    21:12:20.0915 8384 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    21:12:20.0955 8384 HomeGroupListener - ok
    21:12:20.0980 8384 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    21:12:21.0015 8384 HomeGroupProvider - ok
    21:12:21.0095 8384 [ 13BB1114451C63BFB41BA7DAA4D70A29 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
    21:12:21.0120 8384 HP Support Assistant Service - ok
    21:12:21.0160 8384 [ 3015B37029AD15C67EBCA5053C422F90 ] HP8207_8307 C:\Windows\system32\DRIVERS\HP8207_8307.sys
    21:12:21.0195 8384 HP8207_8307 - ok
    21:12:21.0280 8384 [ 7B8C1B09C11E8DB7C4480ABD7D17E821 ] HPAuto C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
    21:12:21.0315 8384 HPAuto - ok
    21:12:21.0345 8384 [ 6A181452D4E240B8ECC7614B9A19BDE9 ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
    21:12:21.0365 8384 HPClientSvc - ok
    21:12:21.0435 8384 [ 9BFDA0BC109EB6D16F2CB862BB85E28C ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    21:12:21.0450 8384 HPDrvMntSvc.exe - ok
    21:12:21.0520 8384 [ 514455F6586473791C5C6B25BA4E1BAB ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
    21:12:21.0565 8384 hpqwmiex - ok
    21:12:21.0590 8384 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    21:12:21.0610 8384 HpSAMD - ok
    21:12:21.0655 8384 [ 2BEC76BDCD1BC080210325E7B5094834 ] HPWMISVC C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
    21:12:21.0690 8384 HPWMISVC - ok
    21:12:21.0710 8384 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    21:12:21.0765 8384 HTTP - ok
    21:12:21.0790 8384 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    21:12:21.0805 8384 hwpolicy - ok
    21:12:21.0830 8384 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    21:12:21.0845 8384 i8042prt - ok
    21:12:21.0880 8384 [ 26CF4275034214ECEDD8EC17B0A18A99 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    21:12:21.0900 8384 iaStor - ok
    21:12:21.0965 8384 [ E79A8E33BD136D14BAE1FA20EB2EF124 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    21:12:21.0980 8384 IAStorDataMgrSvc - ok
    21:12:22.0005 8384 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    21:12:22.0030 8384 iaStorV - ok
    21:12:22.0125 8384 [ D3090576412EC63E0C6271D8B0974D73 ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
    21:12:22.0185 8384 IconMan_R - ok
    21:12:22.0235 8384 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    21:12:22.0265 8384 idsvc - ok
    21:12:22.0360 8384 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\IPSDefs\20121108.001\IDSvia64.sys
    21:12:22.0385 8384 IDSVia64 - ok
    21:12:22.0645 8384 [ 33FAA40B288002C89529DBD14F3AB72C ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    21:12:22.0965 8384 igfx - ok
    21:12:22.0995 8384 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    21:12:23.0010 8384 iirsp - ok
    21:12:23.0050 8384 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
    21:12:23.0120 8384 IKEEXT - ok
    21:12:23.0175 8384 [ FC727061C0F47C8059E88E05D5C8E381 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
    21:12:23.0200 8384 IntcDAud - ok
    21:12:23.0225 8384 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
    21:12:23.0240 8384 intelide - ok
    21:12:23.0290 8384 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    21:12:23.0315 8384 intelppm - ok
    21:12:23.0350 8384 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    21:12:23.0405 8384 IPBusEnum - ok
    21:12:23.0420 8384 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:12:23.0460 8384 IpFilterDriver - ok
    21:12:23.0490 8384 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    21:12:23.0545 8384 iphlpsvc - ok
    21:12:23.0575 8384 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
    21:12:23.0615 8384 IPMIDRV - ok
    21:12:23.0625 8384 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    21:12:23.0680 8384 IPNAT - ok
    21:12:23.0715 8384 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
    21:12:23.0740 8384 IRENUM - ok
    21:12:23.0770 8384 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    21:12:23.0785 8384 isapnp - ok
    21:12:23.0805 8384 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
    21:12:23.0825 8384 iScsiPrt - ok
    21:12:23.0895 8384 [ 5A9894E80575647DC77A7D1954B05CE7 ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
    21:12:23.0915 8384 jhi_service - ok
    21:12:23.0955 8384 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
    21:12:23.0970 8384 kbdclass - ok
    21:12:23.0995 8384 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
    21:12:24.0025 8384 kbdhid - ok
    21:12:24.0035 8384 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
    21:12:24.0055 8384 KeyIso - ok
    21:12:24.0080 8384 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    21:12:24.0095 8384 KSecDD - ok
    21:12:24.0130 8384 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    21:12:24.0145 8384 KSecPkg - ok
    21:12:24.0180 8384 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    21:12:24.0235 8384 ksthunk - ok
    21:12:24.0270 8384 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
    21:12:24.0325 8384 KtmRm - ok
    21:12:24.0370 8384 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
    21:12:24.0430 8384 LanmanServer - ok
    21:12:24.0455 8384 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    21:12:24.0500 8384 LanmanWorkstation - ok
    21:12:24.0535 8384 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    21:12:24.0590 8384 lltdio - ok
    21:12:24.0655 8384 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    21:12:24.0755 8384 lltdsvc - ok
    21:12:24.0770 8384 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
    21:12:24.0815 8384 lmhosts - ok
    21:12:24.0875 8384 [ D75C4B4A8FE6D7FD74A7EECDBAEC729F ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    21:12:24.0910 8384 LMS - ok
    21:12:24.0950 8384 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
    21:12:24.0965 8384 LSI_FC - ok
    21:12:24.0985 8384 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    21:12:25.0005 8384 LSI_SAS - ok
    21:12:25.0015 8384 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
    21:12:25.0035 8384 LSI_SAS2 - ok
    21:12:25.0050 8384 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    21:12:25.0070 8384 LSI_SCSI - ok
    21:12:25.0095 8384 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
    21:12:25.0150 8384 luafv - ok
    21:12:25.0190 8384 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    21:12:25.0235 8384 Mcx2Svc - ok
    21:12:25.0255 8384 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
    21:12:25.0275 8384 megasas - ok
    21:12:25.0325 8384 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
    21:12:25.0365 8384 MegaSR - ok
    21:12:25.0400 8384 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
    21:12:25.0415 8384 MEIx64 - ok
    21:12:25.0440 8384 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
    21:12:25.0515 8384 MMCSS - ok
    21:12:25.0540 8384 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
    21:12:25.0590 8384 Modem - ok
    21:12:25.0600 8384 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    21:12:25.0630 8384 monitor - ok
    21:12:25.0645 8384 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    21:12:25.0665 8384 mouclass - ok
    21:12:25.0700 8384 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    21:12:25.0735 8384 mouhid - ok
    21:12:25.0790 8384 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    21:12:25.0805 8384 mountmgr - ok
    21:12:25.0820 8384 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
    21:12:25.0835 8384 mpio - ok
    21:12:25.0845 8384 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    21:12:25.0885 8384 mpsdrv - ok
    21:12:25.0920 8384 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
    21:12:25.0980 8384 MpsSvc - ok
    21:12:26.0025 8384 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    21:12:26.0070 8384 MRxDAV - ok
    21:12:26.0100 8384 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:12:26.0135 8384 mrxsmb - ok
    21:12:26.0160 8384 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:12:26.0185 8384 mrxsmb10 - ok
    21:12:26.0205 8384 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:12:26.0225 8384 mrxsmb20 - ok
    21:12:26.0255 8384 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
    21:12:26.0275 8384 msahci - ok
    21:12:26.0310 8384 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    21:12:26.0330 8384 msdsm - ok
    21:12:26.0345 8384 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
    21:12:26.0380 8384 MSDTC - ok
    21:12:26.0400 8384 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    21:12:26.0440 8384 Msfs - ok
    21:12:26.0450 8384 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    21:12:26.0510 8384 mshidkmdf - ok
    21:12:26.0540 8384 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    21:12:26.0555 8384 msisadrv - ok
    21:12:26.0590 8384 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    21:12:26.0655 8384 MSiSCSI - ok
    21:12:26.0660 8384 msiserver - ok
    21:12:26.0685 8384 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    21:12:26.0735 8384 MSKSSRV - ok
    21:12:26.0765 8384 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    21:12:26.0860 8384 MSPCLOCK - ok
    21:12:26.0870 8384 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    21:12:26.0930 8384 MSPQM - ok
    21:12:26.0955 8384 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    21:12:26.0975 8384 MsRPC - ok
    21:12:26.0990 8384 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
    21:12:27.0005 8384 mssmbios - ok
    21:12:27.0055 8384 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    21:12:27.0135 8384 MSTEE - ok
    21:12:27.0170 8384 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
    21:12:27.0205 8384 MTConfig - ok
    21:12:27.0220 8384 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
    21:12:27.0235 8384 Mup - ok
    21:12:27.0380 8384 [ F2840DBFE9322F35557219AE82CC4597 ] N360 C:\Program Files (x86)\Norton 360\Engine\6.4.0.9\ccSvcHst.exe
    21:12:27.0400 8384 N360 - ok
    21:12:27.0430 8384 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
    21:12:27.0490 8384 napagent - ok
    21:12:27.0525 8384 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    21:12:27.0570 8384 NativeWifiP - ok
    21:12:27.0655 8384 [ C58D8A669D6551F616D90244BD2C2D4F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121109.004\ENG64.SYS
    21:12:27.0675 8384 NAVENG - ok
    21:12:27.0720 8384 [ A3DBDB412ADFA5882DD6843B11FE0828 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Definitions\VirusDefs\20121109.004\EX64.SYS
    21:12:27.0770 8384 NAVEX15 - ok
    21:12:27.0890 8384 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
    21:12:27.0925 8384 NDIS - ok
    21:12:27.0980 8384 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    21:12:28.0060 8384 NdisCap - ok
    21:12:28.0095 8384 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    21:12:28.0135 8384 NdisTapi - ok
    21:12:28.0155 8384 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    21:12:28.0210 8384 Ndisuio - ok
    21:12:28.0240 8384 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    21:12:28.0300 8384 NdisWan - ok
    21:12:28.0320 8384 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    21:12:28.0360 8384 NDProxy - ok
    21:12:28.0395 8384 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    21:12:28.0450 8384 NetBIOS - ok
    21:12:28.0460 8384 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    21:12:28.0505 8384 NetBT - ok
    21:12:28.0535 8384 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
    21:12:28.0555 8384 Netlogon - ok
    21:12:28.0600 8384 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
    21:12:28.0665 8384 Netman - ok
    21:12:28.0670 8384 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
    21:12:28.0725 8384 netprofm - ok
    21:12:28.0755 8384 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    21:12:28.0770 8384 NetTcpPortSharing - ok
    21:12:28.0800 8384 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    21:12:28.0815 8384 nfrd960 - ok
    21:12:28.0860 8384 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
    21:12:28.0945 8384 NlaSvc - ok
    21:12:28.0975 8384 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    21:12:29.0015 8384 Npfs - ok
    21:12:29.0030 8384 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
    21:12:29.0085 8384 nsi - ok
    21:12:29.0100 8384 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    21:12:29.0160 8384 nsiproxy - ok
    21:12:29.0215 8384 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    21:12:29.0260 8384 Ntfs - ok
    21:12:29.0285 8384 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
    21:12:29.0325 8384 Null - ok
    21:12:29.0340 8384 [ A85B4F2EF3A7304A5399EF0526423040 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys
    21:12:29.0375 8384 NVENETFD - ok
    21:12:29.0410 8384 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
    21:12:29.0430 8384 nvraid - ok
    21:12:29.0445 8384 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
    21:12:29.0465 8384 nvstor - ok
    21:12:29.0490 8384 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    21:12:29.0510 8384 nv_agp - ok
    21:12:29.0535 8384 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    21:12:29.0555 8384 ohci1394 - ok
    21:12:29.0630 8384 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    21:12:29.0650 8384 ose - ok
    21:12:29.0830 8384 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    21:12:29.0995 8384 osppsvc - ok
    21:12:30.0040 8384 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    21:12:30.0075 8384 p2pimsvc - ok
    21:12:30.0095 8384 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
    21:12:30.0120 8384 p2psvc - ok
    21:12:30.0145 8384 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
    21:12:30.0165 8384 Parport - ok
    21:12:30.0200 8384 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
    21:12:30.0215 8384 partmgr - ok
    21:12:30.0250 8384 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
    21:12:30.0290 8384 PcaSvc - ok
    21:12:30.0330 8384 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
    21:12:30.0365 8384 pci - ok
    21:12:30.0395 8384 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
    21:12:30.0410 8384 pciide - ok
    21:12:30.0445 8384 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    21:12:30.0460 8384 pcmcia - ok
    21:12:30.0475 8384 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
    21:12:30.0490 8384 pcw - ok
    21:12:30.0515 8384 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    21:12:30.0570 8384 PEAUTH - ok
    21:12:30.0655 8384 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    21:12:30.0710 8384 PerfHost - ok
    21:12:30.0760 8384 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
    21:12:30.0835 8384 pla - ok
    21:12:30.0885 8384 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    21:12:30.0935 8384 PlugPlay - ok
    21:12:30.0955 8384 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    21:12:30.0990 8384 PNRPAutoReg - ok
    21:12:31.0020 8384 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    21:12:31.0040 8384 PNRPsvc - ok
    21:12:31.0080 8384 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    21:12:31.0175 8384 PolicyAgent - ok
    21:12:31.0205 8384 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
    21:12:31.0260 8384 Power - ok
    21:12:31.0295 8384 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    21:12:31.0350 8384 PptpMiniport - ok
    21:12:31.0375 8384 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
    21:12:31.0410 8384 Processor - ok
    21:12:31.0440 8384 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
    21:12:31.0470 8384 ProfSvc - ok
    21:12:31.0480 8384 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
    21:12:31.0500 8384 ProtectedStorage - ok
    21:12:31.0530 8384 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    21:12:31.0585 8384 Psched - ok
    21:12:31.0625 8384 [ FB46E9A827A8799EBD7BFA9128C91F37 ] PSI C:\Windows\system32\DRIVERS\psi_mf.sys
    21:12:31.0640 8384 PSI - ok
    21:12:31.0680 8384 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
    21:12:31.0730 8384 ql2300 - ok
    21:12:31.0755 8384 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
    21:12:31.0770 8384 ql40xx - ok
    21:12:31.0800 8384 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
    21:12:31.0825 8384 QWAVE - ok
    21:12:31.0840 8384 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    21:12:31.0870 8384 QWAVEdrv - ok
    21:12:31.0895 8384 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    21:12:31.0945 8384 RasAcd - ok
    21:12:32.0000 8384 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    21:12:32.0040 8384 RasAgileVpn - ok
    21:12:32.0065 8384 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
    21:12:32.0115 8384 RasAuto - ok
    21:12:32.0130 8384 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:12:32.0180 8384 Rasl2tp - ok
  16. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Continued
    21:12:32.0230 8384 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
    21:12:32.0275 8384 RasMan - ok
    21:12:32.0305 8384 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    21:12:32.0365 8384 RasPppoe - ok
    21:12:32.0380 8384 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    21:12:32.0435 8384 RasSstp - ok
    21:12:32.0450 8384 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    21:12:32.0500 8384 rdbss - ok
    21:12:32.0530 8384 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
    21:12:32.0575 8384 rdpbus - ok
    21:12:32.0590 8384 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:12:32.0645 8384 RDPCDD - ok
    21:12:32.0660 8384 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    21:12:32.0715 8384 RDPENCDD - ok
    21:12:32.0730 8384 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
    21:12:32.0775 8384 RDPREFMP - ok
    21:12:32.0820 8384 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
    21:12:32.0850 8384 RdpVideoMiniport - ok
    21:12:32.0880 8384 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    21:12:32.0910 8384 RDPWD - ok
    21:12:32.0950 8384 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    21:12:32.0980 8384 rdyboost - ok
    21:12:33.0015 8384 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
    21:12:33.0080 8384 RemoteAccess - ok
    21:12:33.0120 8384 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    21:12:33.0175 8384 RemoteRegistry - ok
    21:12:33.0200 8384 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
    21:12:33.0240 8384 RFCOMM - ok
    21:12:33.0260 8384 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    21:12:33.0310 8384 RpcEptMapper - ok
    21:12:33.0330 8384 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
    21:12:33.0350 8384 RpcLocator - ok
    21:12:33.0390 8384 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
    21:12:33.0445 8384 RpcSs - ok
    21:12:33.0480 8384 [ 6E5C3D18C3BCC72AA527DBC5FA61AB8F ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys
    21:12:33.0500 8384 RSPCIESTOR - ok
    21:12:33.0530 8384 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    21:12:33.0580 8384 rspndr - ok
    21:12:33.0635 8384 [ 9140DB0911DE035FED0A9A77A2D156EA ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
    21:12:33.0660 8384 RTL8167 - ok
    21:12:33.0670 8384 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
    21:12:33.0690 8384 SamSs - ok
    21:12:33.0705 8384 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    21:12:33.0725 8384 sbp2port - ok
    21:12:33.0745 8384 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
    21:12:33.0800 8384 SCardSvr - ok
    21:12:33.0825 8384 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    21:12:33.0895 8384 scfilter - ok
    21:12:33.0920 8384 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
    21:12:33.0990 8384 Schedule - ok
    21:12:34.0015 8384 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
    21:12:34.0065 8384 SCPolicySvc - ok
    21:12:34.0115 8384 [ 111E0EBC0AD79CB0FA014B907B231CF0 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
    21:12:34.0155 8384 sdbus - ok
    21:12:34.0180 8384 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    21:12:34.0215 8384 SDRSVC - ok
    21:12:34.0242 8384 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    21:12:34.0300 8384 secdrv - ok
    21:12:34.0320 8384 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
    21:12:34.0370 8384 seclogon - ok
    21:12:34.0532 8384 [ 9901DCF2B6DD2AD12CB42BD559E0C92D ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe
    21:12:34.0575 8384 Secunia PSI Agent - ok
    21:12:34.0660 8384 [ 4F2056349F8BA4154D5213BF8A476B14 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe
    21:12:34.0682 8384 Secunia Update Agent - ok
    21:12:34.0727 8384 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
    21:12:34.0787 8384 SENS - ok
    21:12:34.0817 8384 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
    21:12:34.0852 8384 SensrSvc - ok
    21:12:34.0882 8384 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
    21:12:34.0907 8384 Serenum - ok
    21:12:34.0947 8384 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
    21:12:34.0982 8384 Serial - ok
    21:12:35.0022 8384 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
    21:12:35.0052 8384 sermouse - ok
    21:12:35.0087 8384 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
    21:12:35.0137 8384 SessionEnv - ok
    21:12:35.0167 8384 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    21:12:35.0202 8384 sffdisk - ok
    21:12:35.0227 8384 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    21:12:35.0257 8384 sffp_mmc - ok
    21:12:35.0272 8384 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    21:12:35.0297 8384 sffp_sd - ok
    21:12:35.0327 8384 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
    21:12:35.0347 8384 sfloppy - ok
    21:12:35.0377 8384 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
    21:12:35.0427 8384 SharedAccess - ok
    21:12:35.0452 8384 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    21:12:35.0507 8384 ShellHWDetection - ok
    21:12:35.0532 8384 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
    21:12:35.0547 8384 SiSRaid2 - ok
    21:12:35.0582 8384 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    21:12:35.0602 8384 SiSRaid4 - ok
    21:12:35.0652 8384 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    21:12:35.0667 8384 SkypeUpdate - ok
    21:12:35.0697 8384 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    21:12:35.0762 8384 Smb - ok
    21:12:35.0817 8384 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    21:12:35.0862 8384 SNMPTRAP - ok
    21:12:35.0887 8384 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
    21:12:35.0902 8384 spldr - ok
    21:12:35.0932 8384 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
    21:12:35.0967 8384 Spooler - ok
    21:12:36.0052 8384 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
    21:12:36.0167 8384 sppsvc - ok
    21:12:36.0182 8384 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
    21:12:36.0227 8384 sppuinotify - ok
    21:12:36.0307 8384 [ 891793E00432FA055CF040605C260E49 ] SRTSP C:\Windows\System32\Drivers\N360x64\0604000.009\SRTSP64.SYS
    21:12:36.0345 8384 SRTSP - ok
    21:12:36.0355 8384 [ 1CB7BB3B0561FB5ECFE37F7731E8BF3E ] SRTSPX C:\Windows\system32\drivers\N360x64\0604000.009\SRTSPX64.SYS
    21:12:36.0370 8384 SRTSPX - ok
    21:12:36.0395 8384 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
    21:12:36.0430 8384 srv - ok
    21:12:36.0457 8384 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    21:12:36.0495 8384 srv2 - ok
    21:12:36.0540 8384 [ 0C4540311E11664B245A263E1154CEF8 ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS
    21:12:36.0560 8384 SrvHsfHDA - ok
    21:12:36.0617 8384 [ 02071D207A9858FBE3A48CBFD59C4A04 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS
    21:12:36.0672 8384 SrvHsfV92 - ok
    21:12:36.0707 8384 [ 18E40C245DBFAF36FD0134A7EF2DF396 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
    21:12:36.0737 8384 SrvHsfWinac - ok
    21:12:36.0772 8384 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    21:12:36.0792 8384 srvnet - ok
    21:12:36.0832 8384 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    21:12:36.0900 8384 SSDPSRV - ok
    21:12:36.0907 8384 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
    21:12:36.0955 8384 SstpSvc - ok
    21:12:37.0020 8384 [ 7BF818B11C1FEDC3E76D233124470A30 ] STacSV C:\Program Files\IDT\WDM\STacSV64.exe
    21:12:37.0065 8384 STacSV - ok
    21:12:37.0095 8384 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
    21:12:37.0117 8384 stexstor - ok
    21:12:37.0172 8384 [ EBC1A5E076A9BE314D3D9E8ED19ABB0A ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys
    21:12:37.0220 8384 STHDA - ok
    21:12:37.0270 8384 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
    21:12:37.0310 8384 stisvc - ok
    21:12:37.0327 8384 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
    21:12:37.0350 8384 swenum - ok
    21:12:37.0382 8384 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
    21:12:37.0455 8384 swprv - ok
    21:12:37.0485 8384 [ 8B2430762099598DA40686F754632EFD ] SymDS C:\Windows\system32\drivers\N360x64\0604000.009\SYMDS64.SYS
    21:12:37.0512 8384 SymDS - ok
    21:12:37.0562 8384 [ 5CB7F2FD7E30A0F52F93574BFC3A8041 ] SymEFA C:\Windows\system32\drivers\N360x64\0604000.009\SYMEFA64.SYS
    21:12:37.0597 8384 SymEFA - ok
    21:12:37.0632 8384 [ 898BB48C797483420DF523B2BBC1ECDB ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
    21:12:37.0652 8384 SymEvent - ok
    21:12:37.0692 8384 [ 5013A76CAAA1D7CF1C55214B490B4E35 ] SymIRON C:\Windows\system32\drivers\N360x64\0604000.009\Ironx64.SYS
    21:12:37.0712 8384 SymIRON - ok
    21:12:37.0732 8384 [ 3911BD0E68C010E5438A87706ABBE9AB ] SymNetS C:\Windows\System32\Drivers\N360x64\0604000.009\SYMNETS.SYS
    21:12:37.0757 8384 SymNetS - ok
    21:12:37.0802 8384 [ AC3CC98B1BDB6540021D3FFB105AC2B9 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
    21:12:37.0827 8384 SynTP - ok
    21:12:37.0887 8384 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
    21:12:37.0945 8384 SysMain - ok
    21:12:37.0960 8384 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
    21:12:38.0000 8384 TabletInputService - ok
    21:12:38.0030 8384 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
    21:12:38.0107 8384 TapiSrv - ok
    21:12:38.0122 8384 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
    21:12:38.0172 8384 TBS - ok
    21:12:38.0259 8384 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    21:12:38.0317 8384 Tcpip - ok
    21:12:38.0357 8384 [ F782CAD3CEDBB3F9FFE3BF2775D92DDC ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    21:12:38.0402 8384 TCPIP6 - ok
    21:12:38.0432 8384 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    21:12:38.0482 8384 tcpipreg - ok
    21:12:38.0502 8384 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    21:12:38.0517 8384 TDPIPE - ok
    21:12:38.0547 8384 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    21:12:38.0577 8384 TDTCP - ok
    21:12:38.0592 8384 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    21:12:38.0632 8384 tdx - ok
    21:12:38.0657 8384 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
    21:12:38.0672 8384 TermDD - ok
    21:12:38.0702 8384 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
    21:12:38.0757 8384 TermService - ok
    21:12:38.0767 8384 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
    21:12:38.0792 8384 Themes - ok
    21:12:38.0822 8384 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
    21:12:38.0862 8384 THREADORDER - ok
    21:12:38.0872 8384 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
    21:12:38.0922 8384 TrkWks - ok
    21:12:38.0982 8384 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    21:12:39.0047 8384 TrustedInstaller - ok
    21:12:39.0082 8384 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:12:39.0147 8384 tssecsrv - ok
    21:12:39.0492 8384 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    21:12:39.0552 8384 TsUsbFlt - ok
    21:12:39.0602 8384 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
    21:12:39.0622 8384 TsUsbGD - ok
    21:12:39.0677 8384 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    21:12:39.0762 8384 tunnel - ok
    21:12:39.0867 8384 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    21:12:39.0882 8384 uagp35 - ok
    21:12:39.0937 8384 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    21:12:40.0012 8384 udfs - ok
    21:12:40.0067 8384 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
    21:12:40.0532 8384 UI0Detect - ok
    21:12:40.0562 8384 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    21:12:40.0582 8384 uliagpkx - ok
    21:12:40.0619 8384 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    21:12:40.0659 8384 umbus - ok
    21:12:40.0684 8384 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
    21:12:40.0722 8384 UmPass - ok
    21:12:40.0859 8384 [ 758C2CE427C343F780A205E28555C98D ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    21:12:40.0934 8384 UNS - ok
    21:12:40.0984 8384 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
    21:12:41.0057 8384 upnphost - ok
    21:12:41.0094 8384 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    21:12:41.0112 8384 usbccgp - ok
    21:12:41.0152 8384 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    21:12:41.0179 8384 usbcir - ok
    21:12:41.0199 8384 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
    21:12:41.0244 8384 usbehci - ok
    21:12:41.0264 8384 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\drivers\usbhub.sys
    21:12:41.0304 8384 usbhub - ok
    21:12:41.0324 8384 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    21:12:41.0359 8384 usbohci - ok
    21:12:41.0384 8384 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
    21:12:41.0414 8384 usbprint - ok
    21:12:41.0444 8384 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    21:12:41.0469 8384 USBSTOR - ok
    21:12:41.0484 8384 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
    21:12:41.0514 8384 usbuhci - ok
    21:12:41.0539 8384 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
    21:12:41.0564 8384 usbvideo - ok
    21:12:41.0589 8384 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
    21:12:41.0644 8384 UxSms - ok
    21:12:41.0659 8384 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
    21:12:41.0679 8384 VaultSvc - ok
    21:12:41.0689 8384 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    21:12:41.0704 8384 vdrvroot - ok
    21:12:41.0729 8384 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
    21:12:41.0789 8384 vds - ok
    21:12:41.0819 8384 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    21:12:41.0839 8384 vga - ok
    21:12:41.0849 8384 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
    21:12:41.0894 8384 VgaSave - ok
    21:12:41.0934 8384 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
    21:12:41.0974 8384 vhdmp - ok
    21:12:41.0984 8384 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
    21:12:41.0999 8384 viaide - ok
    21:12:42.0034 8384 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    21:12:42.0049 8384 volmgr - ok
    21:12:42.0079 8384 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    21:12:42.0099 8384 volmgrx - ok
    21:12:42.0109 8384 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\Windows\system32\drivers\volsnap.sys
    21:12:42.0129 8384 volsnap - ok
    21:12:42.0149 8384 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    21:12:42.0169 8384 vsmraid - ok
    21:12:42.0224 8384 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
    21:12:42.0304 8384 VSS - ok
    21:12:42.0334 8384 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
    21:12:42.0369 8384 vwifibus - ok
    21:12:42.0369 8384 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    21:12:42.0404 8384 vwififlt - ok
    21:12:42.0429 8384 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
    21:12:42.0449 8384 vwifimp - ok
    21:12:42.0489 8384 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
    21:12:42.0534 8384 W32Time - ok
    21:12:42.0564 8384 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
    21:12:42.0599 8384 WacomPen - ok
    21:12:42.0629 8384 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
    21:12:42.0689 8384 WANARP - ok
    21:12:42.0709 8384 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    21:12:42.0749 8384 Wanarpv6 - ok
    21:12:42.0824 8384 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
    21:12:42.0884 8384 WatAdminSvc - ok
    21:12:42.0934 8384 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
    21:12:42.0989 8384 wbengine - ok
    21:12:43.0009 8384 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    21:12:43.0034 8384 WbioSrvc - ok
    21:12:43.0059 8384 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
    21:12:43.0104 8384 wcncsvc - ok
    21:12:43.0129 8384 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    21:12:43.0149 8384 WcsPlugInService - ok
    21:12:43.0169 8384 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
    21:12:43.0189 8384 Wd - ok
    21:12:43.0224 8384 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    21:12:43.0264 8384 Wdf01000 - ok
    21:12:43.0279 8384 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
    21:12:43.0324 8384 WdiServiceHost - ok
    21:12:43.0329 8384 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
    21:12:43.0349 8384 WdiSystemHost - ok
    21:12:43.0379 8384 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
    21:12:43.0424 8384 WebClient - ok
    21:12:43.0439 8384 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
    21:12:43.0494 8384 Wecsvc - ok
    21:12:43.0514 8384 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    21:12:43.0554 8384 wercplsupport - ok
    21:12:43.0604 8384 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
    21:12:43.0659 8384 WerSvc - ok
    21:12:43.0689 8384 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
    21:12:43.0729 8384 WfpLwf - ok
    21:12:43.0744 8384 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    21:12:43.0759 8384 WIMMount - ok
    21:12:43.0779 8384 WinDefend - ok
    21:12:43.0784 8384 WinHttpAutoProxySvc - ok
    21:12:43.0839 8384 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    21:12:43.0924 8384 Winmgmt - ok
    21:12:43.0979 8384 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
    21:12:44.0049 8384 WinRM - ok
    21:12:44.0104 8384 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
    21:12:44.0179 8384 Wlansvc - ok
    21:12:44.0234 8384 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    21:12:44.0249 8384 wlcrasvc - ok
    21:12:44.0394 8384 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    21:12:44.0454 8384 wlidsvc - ok
    21:12:44.0494 8384 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    21:12:44.0519 8384 WmiAcpi - ok
    21:12:44.0559 8384 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    21:12:44.0594 8384 wmiApSrv - ok
    21:12:44.0624 8384 WMPNetworkSvc - ok
    21:12:44.0654 8384 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
    21:12:44.0674 8384 WPCSvc - ok
    21:12:44.0684 8384 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    21:12:44.0704 8384 WPDBusEnum - ok
    21:12:44.0739 8384 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    21:12:44.0779 8384 ws2ifsl - ok
    21:12:44.0789 8384 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
    21:12:44.0829 8384 wscsvc - ok
    21:12:44.0869 8384 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
    21:12:44.0889 8384 WSDPrintDevice - ok
    21:12:44.0934 8384 [ 4A2A5C50DD1A63577D3ACA94269FBC7F ] WSDScan C:\Windows\system32\DRIVERS\WSDScan.sys
    21:12:44.0974 8384 WSDScan - ok
    21:12:44.0979 8384 WSearch - ok
    21:12:45.0099 8384 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    21:12:45.0159 8384 wuauserv - ok
    21:12:45.0179 8384 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    21:12:45.0229 8384 WudfPf - ok
    21:12:45.0264 8384 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:12:45.0319 8384 WUDFRd - ok
    21:12:45.0354 8384 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    21:12:45.0394 8384 wudfsvc - ok
    21:12:45.0429 8384 [ CE8CF9DE9CBFDAA318BD04D8BE3FCADA ] WwanSvc C:\Windows\System32\wwansvc.dll
    21:12:45.0454 8384 WwanSvc - ok
    21:12:45.0499 8384 ================ Scan global ===============================
    21:12:45.0529 8384 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
    21:12:45.0559 8384 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    21:12:45.0579 8384 [ F46BBAAC1C4980F4D0DD463F190A42D3 ] C:\Windows\system32\winsrv.dll
    21:12:45.0619 8384 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
    21:12:45.0659 8384 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
    21:12:45.0669 8384 [Global] - ok
    21:12:45.0669 8384 ================ Scan MBR ==================================
    21:12:45.0684 8384 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    21:12:47.0019 8384 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
    21:12:47.0019 8384 \Device\Harddisk0\DR0 - detected TDSS File System (1)
    21:12:47.0019 8384 ================ Scan VBR ==================================
    21:12:47.0049 8384 [ 7893EF093958182A7A126B2E3CEE4DF1 ] \Device\Harddisk0\DR0\Partition1
    21:12:47.0049 8384 \Device\Harddisk0\DR0\Partition1 - ok
    21:12:47.0069 8384 [ 2041DA3A0667CAB1C92135CB70185EEF ] \Device\Harddisk0\DR0\Partition2
    21:12:47.0069 8384 \Device\Harddisk0\DR0\Partition2 - ok
    21:12:47.0099 8384 [ B8174525FD82EE856AE374E606C70890 ] \Device\Harddisk0\DR0\Partition3
    21:12:47.0104 8384 \Device\Harddisk0\DR0\Partition3 - ok
    21:12:47.0124 8384 [ 626CDAED975D0B276F162356B94FE557 ] \Device\Harddisk0\DR0\Partition4
    21:12:47.0124 8384 \Device\Harddisk0\DR0\Partition4 - ok
    21:12:47.0124 8384 ============================================================
    21:12:47.0124 8384 Scan finished
    21:12:47.0124 8384 ============================================================
    21:12:47.0139 8216 Detected object count: 1
    21:12:47.0139 8216 Actual detected object count: 1
    21:16:06.0790 8216 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    21:16:06.0790 8216 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
  17. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
    Run date: 2012-11-09 21:24:01
    -----------------------------
    21:24:01.605 OS Version: Windows x64 6.1.7601 Service Pack 1
    21:24:01.605 Number of processors: 4 586 0x2A07
    21:24:01.605 ComputerName: SUNSHINE-HP UserName: Sunshine
    21:24:03.480 Initialize success
    21:24:20.125 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    21:24:20.130 Disk 0 Vendor: TOSHIBA_ GT00 Size: 715404MB BusType: 3
    21:24:20.150 Disk 0 MBR read successfully
    21:24:20.160 Disk 0 MBR scan
    21:24:20.165 Disk 0 Windows 7 default MBR code
    21:24:20.170 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
    21:24:20.190 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 690597 MB offset 409600
    21:24:20.225 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 20544 MB offset 1414752256
    21:24:20.245 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 4062 MB offset 1456826368
    21:24:20.295 Disk 0 scanning C:\Windows\system32\drivers
    21:24:27.145 Service scanning
    21:24:54.100 Modules scanning
    21:24:54.115 Scan finished successfully
    21:25:40.810 Disk 0 MBR has been saved successfully to "C:\Users\Sunshine\Desktop\MBR.dat"
    21:25:40.835 The log file has been saved successfully to "C:\Users\Sunshine\Desktop\aswMBR.txt"
  18. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Here is my second scan from the MBRscan application.

    Attached Files:

  19. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Hitman Pro

    Please download Hitman Pro

    • After the download completes please double click the program to run it.
    • Accept the terms of the license agreement and click Next
    • Let the scan run. It will not take long
    • When the scan finishes, and all the files have been uploaded to the Scan Cloud, click Next
    • Click Next again. At the bottom left you will see Export Scan Results To XML File. Click that and save it in a convenient location
    • Upload log.xml here for review please
  20. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    When I clicked next it never showed Export Scan Results To XML File.. did I do something wrong?
    Code:
    HitmanPro 3.6.2.173
    [URL='http://www.hitmanpro.com']www.hitmanpro.com[/URL]
       Computer name . . . . : SUNSHINE-HP
       Windows . . . . . . . : 6.1.1.7601.X64/4
       User name . . . . . . : Sunshine-HP\Sunshine
       UAC . . . . . . . . . : Enabled
       License . . . . . . . : Free
       Scan date . . . . . . : 2012-11-10 11:13:48
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 3m 18s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : Internet
       Reboot  . . . . . . . : No
       Threats . . . . . . . : 0
       Traces  . . . . . . . : 37
       Objects scanned . . . : 1,346,595
       Files scanned . . . . : 19,744
       Remnants scanned  . . : 247,862 files / 1,078,989 keys
    Cookies _____________________________________________________________________
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.360yield.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ad.yieldmanager.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:adbrite.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.bleepingcomputer.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.cartoonnetwork.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pointroll.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ads.pubmatic.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:adserver.adtechus.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:adtech.de
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:advertising.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:apmebf.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ar.atwola.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:at.atwola.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:atdmt.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:atwola.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:burstnet.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:c1.atdmt.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:casalemedia.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:doubleclick.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:fastclick.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:invitemedia.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:kontera.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:media6degrees.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:mediaplex.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:microsoftsto.112.2o7.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:pointroll.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:questionmarket.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:revsci.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:ru4.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:server.cpmstar.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:serving-sys.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:specificclick.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:survey.g.doubleclick.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.at.atwola.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:tacoda.net
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:tribalfusion.com
       C:\Users\Sunshine\AppData\Local\Google\Chrome\User Data\Default\Cookies:www.googleadservices.com
    
    
  21. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Good job!

    Norman Malware Cleaner

    Please download Norman Malware Cleaner and save to your desktop.
    alternate download link
    • Double-click on Norman_Malware_Cleaner.exe to start the program.
    • Read the End User License Agreement and click the Accept button to open the scanning window.
    • Click Start Scan to begin.
    • In some cases Norman Malware Cleaner may require that you restart the computer to completely remove an infection. If prompted, reboot and run the tool again to ensure that all infections are removed.
    • After the scan has finished, a log file with the date (I.e. NFix_2009-06-22_07-08-56.log) will be created on your desktop with the results.
    Note: For usb flash drives and/or other removable drives to scan, use the Add button to browse to the drives location, click on the drive to highlight and choose Ok.
  22. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    Norman Malware Cleaner v2.06.01
    Copyright © 1990 - 2012, Norman ASA.
    Norman Scanner Engine Version: 7.00.12
    nvcbin.def: Version: 7.00.1850, Date: 2012/11/12 08:40:57, Variants: 15355348
    nvcmacro.def: Version: 0.00.00, Date: 1969/12/31 19:00:00, Variants: 0
    Operating System: Windows 7 Service Pack 1 x64
    Switches: /iagree
    Scan started: 2012/11/13 01:24:42
    Running pre-scan cleanup routine...
    Number of malicious objects found: 0
    Number of malicious objects cleaned: 0
    Scanning time: 0s
    Scanning running processes and process memory...
    Number of objects found: 1499
    Number of objects scanned: 1499
    Number of objects not scanned: 0
    Number of malicious memory objects found: 0
    Number of malicious objects cleaned: 0
    Number of malicious files found: 0
    Number of malicious files cleaned: 0
    Scanning time: 41s
    Scanning system for FakeAV...
    Number of malicious objects found: 0
    Number of malicious objects cleaned: 0
    Number of malicious files found: 0
    Number of malicious files cleaned: 0
    Scanning time: 0s
    Running full scan...
    C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log: Error opening file for read: 0x00000020
    C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log: Error opening file for read: 0x00000020
    C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb: Error opening file for read: 0x00000020
    C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\00000082\00000123\000005e0\cltLMS1.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\00000082\00000123\000005e0\cltLMS2.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccGEvt\Global\LM2.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccGLog\ccGenericLog.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccJobMgr\JobMgr.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccJobMgr\JobMgr.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\1eb57a9d-0a4c-44e2-98a4-db11d36dd9bb.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\3b6138df-731f-4692-b706-90357bce634a.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\47ffc7aa-e82b-4626-8354-eefe902fe2b2.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\4f980fae-bfd9-4d5c-8f6d-cafffa491cbe.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\84b542e4-ce8f-4e25-89bc-6f5671b9391e.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\b881f91b-53b3-4d49-a251-2e8c5a4e330a.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\ffa870fc-24a8-4c4a-836f-ca7c009389d0.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\settings_6.4.0.9.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\Volatile.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\ccSetMgr\Volatile.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\EMPxyOpt.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_ICFMGR_{F34173A0-C9EA-45ab-B832-29D35E6D04EC}G: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_RDRPluginG: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_NPC.Tray.{1AFE47BB-FCF1-4096-9039-1FEBC9A0CCCF}1: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_ISDATAPR_{FF9AC67A-E394-46ae-B150-B3365343F166}G: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_SvcMgr-A2B50D70-5EA1-45a0-A983-0DB9E7101676G: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_UI.Host.{1AFE47BB-FCF1-4096-9039-1FEBC9A0CCCF}1: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_{4E9CB39A-5F78-4887-A3D6-2790DE9DDE11}1: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\CmnClnt\_lck\_SNDPluginG: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Connections\connectn.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\diStRptr\diStRptr.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\diStRptr\diStRptr.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{05DD78B7-77A1-4393-888E-D8EC961A3B19}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{0693F93A-DEFD-22EE-B444-87D156D89593}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{1EC30809-4D73-45e5-9FB7-4556BF2591F7}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{2F090208-20DC-42f0-BBD8-B68B472F7215}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{352A29CB-F796-4122-A5C1-F8001F96A569}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{511C2222-DEFD-22EE-B154-4A6A546B9793}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{5779E169-C4E2-4487-B4B1-55A24863F4C6}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{591D2F72-6BF6-4E6D-AEE1-2C53200DE57E}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{591D2F72-BEEF-4E6D-AEE1-2C53200DE57E}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{59414fa6-c6d4-4c78-a752-b677cbdd3c6b}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{5B2B85BE-2999-486f-87D2-CEFAEA5984A2}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{5BD0D294-A689-4606-B58C-47A511ED1C14}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{5BD0D294-BEEF-4606-B58C-47A511ED1C14}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{5DE264E3-CED0-4cee-B206-6D287630A7B9}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{64A1EE4A-948D-4bd0-A3E6-9D6BF96DF72A}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{65190544-26C3-43a4-A78A-694964901607}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{691538C6-034F-4d32-9A14-A53B8BAF68AF}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{69EDD4E1-116E-4773-A0AC-C59945720C2A}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{6A585666-3EAE-44c3-8821-711CCE3F2873}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{6C76977D-A5FD-452b-AAAF-51799B8EA9B4}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{6C817099-B8B4-4137-A53F-68B7EA75EC55}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{6E3396BD-C6A6-4f0f-9254-267F9058FEC4}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{70623C4D-BEEF-4025-91D1-3307B948E7DD}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{7C40284F-C1DE-459c-A195-6D854DB8C783}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{89E020E9-BE3E-40cc-9C00-66A3FBA23106}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{93545EED-DE0A-4efa-B44D-68C5CBF1D4F7}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{98A25227-3754-475b-B325-D658972C6E98}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{9BDDC6E8-4FBD-4449-A8CC-142376A325D5}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{70623C4D-9D8A-4025-91D1-3307B948E7DD}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{9F920DB1-1600-4bba-817B-A4F33B0607D1}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{A96E24EE-101F-4f7f-887C-30680DCFF3E4}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{D418C996-433A-42df-8D3C-E1A24C0AD3C0}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{D4F4CC32-7A41-4684-AE57-41E59E9B4503}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{DEC5A7DC-730A-4eff-89E6-DCEEC5DB5287}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{E644497C-3550-4a24-B153-CB0F7A64ADFD}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{E6941702-E564-4caf-84E1-572AEB95826F}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{E8827B4A-4F58-4dea-8C93-07B32A63D1C5}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{F9AF8C8D-BEEF-40db-A228-0F22ECC66E88}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{E8827B4A-BEEF-4dea-8C93-07B32A63D1C5}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{F9AF8C8D-DED9-40db-A228-0F22ECC66E88}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{FF3D8359-103B-1175-AD36-D479E4BBE107}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\DuLuCbkPkg\{FD0D6765-46D2-4399-82E1-8E9D500823F8}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Framework\O2Reg.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Framework\oxygen.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Framework\SpocSelfTune.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\bash.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\ClientIDS.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\DAAlert.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\DADown.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\LU.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\NasState.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\nco2.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\Performance.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Logs\SymNetDrv.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Lue\LueDyn.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Lue\LueDyn.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\LuReg\{648D9F44-15C3-4554-9624-36BEA55E1B88}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\LuReg\{82E8AF44-7C45-42a1-B9D5-A531BEEA7C9E}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\LuReg\{C6EC303F-DEB3-4b76-AA4A-652A7641B359}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\LuReg\{D06948D5-FB30-4721-9983-45F86F6D2D85}.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NCO\IDD2.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NPC\InstOpts.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NPC\Settings.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NPC\Support.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NUM\Settings.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\NUM\Settings.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\asDynam.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\Backup.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\BackupProvider.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\BackupSettings.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\CAVDNode.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\CAVDNode.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\cltDynam.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\cltDynam.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\depend.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\Layout.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\LCset.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\LCset.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\OEM.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\ProdExcl.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\set-priv.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\set-priv.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\TuneupElements.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\User.dat: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\Product\User.dat.log: Error opening file for read: 0x00000020
    C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.1.2.10\SRTSP\SrtspSet.dat: Error opening file for read: 0x00000020
    C:\System Volume Information\Syscache.hve: Error opening file for read: 0x00000020
    C:\System Volume Information\Syscache.hve.LOG1: Error opening file for read: 0x00000020
    C:\System Volume Information\Syscache.hve.LOG2: Error opening file for read: 0x00000020
    C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\tdlfs0000\tsk0001.dta: File infected with doslegacy/Suspicious_Gen4.BLGIU
    Delete file: C:\TDSSKiller_Quarantine\07.11.2012_17.11.12\mbr0000\tdlfs0000\tsk0001.dta
    Cleaning successful
    C:\Users\Sunshine\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{59520D1C-2CEC-11E2-97A7-E4D53DFA1BDB}.dat: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{00361FB4-2D59-11E2-97A7-E4D53DFA1BDB}.dat: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{17603CE7-2D59-11E2-97A7-E4D53DFA1BDB}.dat: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2B947153-196C-46FB-ADFD-F3A5C28468F5}.tmp: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{426ABF17-8194-4A41-A089-8D33FBAF49F8}.tmp: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{43BE70E5-AD93-4E75-A2CA-6E78B923409F}.tmp: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B3CA5589-1A5C-4687-A965-D7B5A1849229}.tmp: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FBE2DE4A-AC9D-4DF8-A92C-DA038848F8D8}.tmp: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\UsrClass.dat: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF0DE1C6154EE11F3F.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF2008890BF79A52F0.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF27FA4F2C8C11C39F.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF421F2C0454239F6A.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF686A43B267B467E2.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF71A6B8AFF385886D.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF8F3C268A5A5A2BD9.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF91441ADBD8E40B61.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF9A757BCF47724B6A.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF9C7EEC2D47487F12.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DF9DDBD64E1F6B73A7.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFA16E182DFBC57B96.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFA59365BE4651FCCA.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFB63671D8721EB67A.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFDC137E67B6C5731B.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFDD2A9EE920F6AD6A.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\AppData\Local\Temp\~DFEFE04662628C2955.TMP: Error opening file for read: 0x00000020
    C:\Users\Sunshine\Desktop\aswMBR.exe: File infected with winpe/Rootkit.EODN
    C:\Users\Sunshine\Desktop\dds.com: File infected with winpe/Rootkit.ENZD
    Delete file: C:\Users\Sunshine\Desktop\aswMBR.exe
    Delete file: C:\Users\Sunshine\Desktop\dds.com
    Cleaning successful
    Cleaning successful
    C:\Users\Sunshine\ntuser.dat: Error opening file for read: 0x00000020
    C:\Users\Sunshine\ntuser.dat.LOG1: Error opening file for read: 0x00000020
    C:\Users\Sunshine\ntuser.dat.LOG2: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\240b0879e9732eb0d5b95dc2541d4a91d7a252a6.HomeGroupClassifier\7828bd1b927daee4ca98f5985ee0ba8c\grouping\db.mdb: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\240b0879e9732eb0d5b95dc2541d4a91d7a252a6.HomeGroupClassifier\7828bd1b927daee4ca98f5985ee0ba8c\grouping\edb.log: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\240b0879e9732eb0d5b95dc2541d4a91d7a252a6.HomeGroupClassifier\7828bd1b927daee4ca98f5985ee0ba8c\grouping\tmp.edb: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\ntuser.dat: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\NetworkService\ntuser.dat: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1: Error opening file for read: 0x00000020
    C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\catroot2\edb.log: Error opening file for read: 0x00000020
    C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb: Error opening file for read: 0x00000020
    C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb: Error opening file for read: 0x00000020
    C:\Windows\System32\config\default: Error opening file for read: 0x00000020
    C:\Windows\System32\config\DEFAULT.LOG1: Error opening file for read: 0x00000020
    C:\Windows\System32\config\DEFAULT.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\config\RegBack\DEFAULT: Error opening file for read: 0x00000020
    C:\Windows\System32\config\RegBack\SAM: Error opening file for read: 0x00000020
    C:\Windows\System32\config\RegBack\SECURITY: Error opening file for read: 0x00000020
    C:\Windows\System32\config\RegBack\SOFTWARE: Error opening file for read: 0x00000020
    C:\Windows\System32\config\RegBack\SYSTEM: Error opening file for read: 0x00000020
    C:\Windows\System32\config\sam: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SAM.LOG1: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SAM.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\config\security: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SECURITY.LOG1: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SECURITY.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\config\software: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SOFTWARE.LOG1: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SOFTWARE.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\config\system: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SYSTEM.LOG1: Error opening file for read: 0x00000020
    C:\Windows\System32\config\SYSTEM.LOG2: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTAdmin_PS_Provider.etl: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl: Error opening file for read: 0x00000020
    C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl: Error opening file for read: 0x00000020
    Number of files found: 142422
    Number of archives unpacked: 4248
    Number of objects found: 678253
    Number of objects scanned: 678058
    Number of objects not scanned: 195
    Number of malicious objects found: 3
    Number of malicious objects cleaned: 3
    Number of malicious files found: 3
    Number of malicious files cleaned: 3
    Scanning time: 1h 17m 19s
    Running post-scan cleanup routine...
    Number of malicious objects found: 0
    Number of malicious objects cleaned: 0
    Scanning time: 0s
    Results:
    Total number of files found: 142422
    Total number of archives unpacked: 4248
    Total number of objects found: 679752
    Total number of objects scanned: 679557
    Total number of objects not scanned: 195
    Total number of malicious objects found: 3
    Total number of malicious objects cleaned: 3
    Total number of malicious files found: 3
    Total number of malicious files cleaned: 3
    Total number of objects quarantined: 3
    Total scanning time: 1h 18m 0s
  23. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Any more issues?

    We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

    Many of the things to note for us would be:

    • Slow computer
    • Error messages
    • Fake antivirus alerts or the icon in the system tray
    • svchost.exe running at 100%
    • System crashes or blue screen of death
  24. rlhartzell

    rlhartzell Newcomer, in training Topic Starter Posts: 34

    My computer does run slow. I have a lot of problems with internet explorer. It constantly wants to shut down and claims there is an error. I believe it states something about the internet connection not being found. Usually refreshing the page and it will load but I have to do this several times throughout my time on the computer. When on facebook, I have problems with adobe... If I am playing a game it will suddenly quit and tell me to get the newest version but when I go to the page it states that I have the newest version. Since you have been helping me I have not had the system crashes or the blue screen of death. I am not sure what else to say. Just loading pages takes forever, and there is something wrong with the bluetooth connectivity. I get an error message about it. Do I really need the bluetooth? Let me know if there is anything else you need. Thank you!!!
  25. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    I want to take an external look if we can...

    Farbar Recovery Scan Tool x64

    Download Farbar Recovery Scan Tool and save it to a flash drive.


    Please make sure to get the 64-bit version

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    To enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
      • Startup Repair
        System Restore
        Windows Complete PC Restore
        Windows Memory Diagnostic Tool
        Command Prompt
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to the disclaimer.
    • Place a check next to List Drivers MD5 as well as the default check marks that are already there
    • Press Scan button. It will do its scan and save a log on your flash drive.
    • Close out of the message after that, then type in the text services.exe in to the "Search:" text box. Then, press the Search file(s) button, just as below:
      [​IMG]
      When done searching, FRST makes a log, Search.txt, on the C:\ drive or on your flash drive.
    • Type exit in the Command Prompt window and reboot the computer normally
    • FRST will make a log (FRST.txt) on the flash drive and also the search.txt logfile, please copy and paste the logs in your reply.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.