TechSpot

Help with Exploit.drop.9 (google redirect)

Solved
By Clevelantis
Sep 10, 2012
  1. What I am pretty sure came from a firefox update (second time a firefox auto update has done this to me), I picked up a virus. Noticed every google link I was clicking was taking me to some random spam site.

    Did some research and found this site, started with MBAM and it found Exploit.drop.9. I deleted it using MBAM, but alas still having re-directs. I read some similar posts and it looked like others that were helped needed more than just clearing it with MBAM.

    Ran the GMER and it found nothing, producing no log. Ran the DDS, will post the logs in a second.

    Any help would be much appreciated, also with just a general update on my anti-virus software. I got a free copy of Mcafee when I was school, now I am two years out and was never quite sure if it kept updating or if I was cut off. Never had problems so I never checked.

    I'm a little paranoid about this virus from what I've read so thanks in advance for the help!!
     
  2. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Malwarebytes Anti-Malware (Trial) 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.09.09.01

    Windows Vista Service Pack 2 x64 NTFS
    Internet Explorer 9.0.8112.16421
    August :: AUGUST-PC [administrator]

    Protection: Enabled

    9/8/2012 10:24:56 PM
    mbam-log-2012-09-08 (23-00-01).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 225720
    Time elapsed: 14 minute(s), 14 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Users\August\AppData\Local\Temp\0.7079080254149286 (Exploit.Drop.9) -> No action taken.

    (end)
     
  3. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Sorry, didn't realize the DDS didn't save. Will be posting once it runs again....
     
  4. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    .
    DDS (Ver_2011-08-26.01) - NTFSAMD64
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31
    Run by August at 20:32:15 on 2012-09-10
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.1855 [GMT -5:00]
    .
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Windows\SysWOW64\atashost.exe
    C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe
    C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\mfevtps.exe
    C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\Explorer.EXE
    C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    C:\Windows\system32\TODDSrv.exe
    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    C:\Program Files\TOSHIBA\TECO\TecoService.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mfeann.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\TOSHIBA\TECO\Teco.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
    C:\Windows\system32\igfxext.exe
    C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
    C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
    C:\Program Files (x86)\iTunes\iTunesHelper.exe
    C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\ehome\ehsched.exe
    C:\Program Files (x86)\iPod\bin\iPodService.exe
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Windows\ehome\ehRecvr.exe
    C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\SysWOW64\cmd.exe
    C:\Windows\SysWOW64\cscript.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://my.yahoo.com/linksys
    uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
    mStart Page = hxxp://my.yahoo.com/linksys
    mDefault_Page_URL = hxxp://my.yahoo.com/linksys
    uInternet Settings,ProxyOverride = <local>;192.168.*.*
    uURLSearchHooks: H - No File
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    uRun: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
    uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    uRun: [Google Update] "C:\Users\August\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
    uRun: [Desktop Software] "C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files (x86)\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden
    uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe -update plugin
    mRun: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
    mRun: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
    mRun: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe"
    mRun: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
    mRun: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MICROS~1.LNK - C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office10\EXCEL.EXE/3000
    IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UpdateCenter/applets/sync.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    TCP: Interfaces\{2FB0FBA6-6420-43BE-950B-BE7DDB297058} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{B763E676-6106-4F58-A81A-91ACBB15E641} : DhcpNameServer = 75.75.75.75 75.75.76.76
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    BHO-X64: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO-X64: 0x1 - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
    BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll
    BHO-X64: scriptproxy - No File
    BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO-X64: SkypeIEPluginBHO - No File
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
    mRun-x64: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
    mRun-x64: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe"
    mRun-x64: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe"
    mRun-x64: [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
    mRun-x64: [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun-x64: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    mRun-x64: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
    mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    IE-X64: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe
    IE-X64: {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\August\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
    FF - component: C:\Program Files (x86)\McAfee\SiteAdvisor\components\McFFPlg.dll
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.29\npGoogleOneClick8.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
    FF - plugin: C:\Program Files (x86)\Picasa2\npPicasa2.dll
    FF - plugin: C:\Program Files (x86)\Picasa2\npPicasa3.dll
    FF - plugin: C:\Users\August\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll
    FF - plugin: C:\Users\August\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    FF - plugin: C:\Users\August\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    ============= SERVICES / DRIVERS ===============
    .
    R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\system32\drivers\mfehidk.sys --> C:\Windows\system32\drivers\mfehidk.sys [?]
    R0 RapportKE64;RapportKE64;C:\Windows\system32\Drivers\RapportKE64.sys --> C:\Windows\system32\Drivers\RapportKE64.sys [?]
    R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\system32\DRIVERS\tos_sps64.sys --> C:\Windows\system32\DRIVERS\tos_sps64.sys [?]
    R1 RapportCerberus_42020;RapportCerberus_42020;C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys [2012-8-12 397720]
    R1 RapportEI64;RapportEI64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-7-29 55096]
    R1 RapportPG64;RapportPG64;C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-7-29 297240]
    R2 atashost;WebEx Service Host for Support Center;C:\Windows\SysWOW64\atashost.exe [2011-3-29 20376]
    R2 camsvc;TOSHIBA Web Camera Service;C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe [2009-7-15 20544]
    R2 ConfigFree Gadget Service;ConfigFree Gadget Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-3-6 36864]
    R2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-3-10 46448]
    R2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-9-10 399432]
    R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-9-8 676936]
    R2 McAfeeEngineService;McAfee Engine Service;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe [2008-9-29 17920]
    R2 McAfeeFramework;McAfee Framework Service;C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe [2008-3-14 103744]
    R2 McShield;McAfee McShield;C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe [2008-9-29 175072]
    R2 McTaskManager;McAfee Task Manager;C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe [2008-9-29 62800]
    R2 mfevtp;McAfee Validation Trust Protection Service;C:\Windows\system32\mfevtps.exe --> C:\Windows\system32\mfevtps.exe [?]
    R2 Motorola Device Manager;Motorola Device Manager Service;C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-6-4 116632]
    R2 PST Service;PST Service;C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2012-6-23 65657]
    R2 RapportMgmtService;Rapport Management Service;C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-7-29 976728]
    R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;C:\Program Files\TOSHIBA\TECO\TecoService.exe [2009-4-14 251392]
    R2 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-3-17 84480]
    R2 TPCHSrv;TPCH Service;C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [2009-4-9 803696]
    R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;C:\Windows\system32\DRIVERS\TVALZFL.sys --> C:\Windows\system32\DRIVERS\TVALZFL.sys [?]
    R2 UMVPFSrv;UMVPFSrv;C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [2012-1-18 450848]
    R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys --> C:\Windows\system32\DRIVERS\FwLnk.sys [?]
    R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
    R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\system32\drivers\mfeavfk.sys --> C:\Windows\system32\drivers\mfeavfk.sys [?]
    R3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
    R3 PGEffect;Pangu effect driver;C:\Windows\system32\DRIVERS\pgeffect.sys --> C:\Windows\system32\DRIVERS\pgeffect.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-8 135664]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-5 250056]
    S3 CompFilter64;UVCCompositeFilter;C:\Windows\system32\DRIVERS\lvbflt64.sys --> C:\Windows\system32\DRIVERS\lvbflt64.sys [?]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-8 135664]
    S3 LVRS64;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
    S3 LVUVC64;Logitech HD Webcam C525(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
    S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
    S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\system32\drivers\mferkdet.sys --> C:\Windows\system32\drivers\mferkdet.sys [?]
    S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-4-26 114144]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-3-17 89920]
    .
    =============== File Associations ===============
    .
    JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
    .
    =============== Created Last 30 ================
    .
    2012-09-10 22:30:23 711240 ----a-w- C:\Windows\isRS-000.tmp
    2012-09-09 03:23:03 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2012-09-07 06:34:54 9310152 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{04D9117E-87DD-41F4-939C-876081325D21}\mpengine.dll
    2012-08-31 01:03:05 -------- d-----w- C:\Users\August\AppData\Local\MetaGeek,_LLC
    2012-08-15 08:07:49 2769408 ----a-w- C:\Windows\System32\win32k.sys
    2012-08-15 08:06:48 788480 ----a-w- C:\Windows\System32\localspl.dll
    2012-08-15 08:06:48 623616 ----a-w- C:\Windows\SysWow64\localspl.dll
    .
    ==================== Find3M ====================
    .
    2012-09-07 22:04:46 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2012-08-15 08:01:02 70344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-08-15 08:01:02 426184 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2012-07-30 01:52:38 101688 ----a-w- C:\Windows\System32\drivers\RapportKE64.sys
    2012-06-28 03:28:35 2312704 ----a-w- C:\Windows\System32\jscript9.dll
    2012-06-28 03:21:17 1392128 ----a-w- C:\Windows\System32\wininet.dll
    2012-06-28 03:20:41 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
    2012-06-28 03:16:25 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
    2012-06-28 03:12:35 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
    2012-06-28 00:27:12 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2012-06-28 00:19:52 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2012-06-28 00:18:16 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
    2012-06-28 00:12:08 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2012-06-28 00:07:44 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2012-06-25 21:04:24 1394248 ----a-w- C:\Windows\SysWow64\msxml4.dll
    2012-06-23 16:56:13 5 ----a-w- C:\Windows\SysWow64\lMMLDeleteUserData42107612FX.tmp
    .
    ============= FINISH: 20:33:07.77 ===============
     
  5. Broni

    Broni Malware Annihilator Posts: 47,646   +267

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =====================================

    I still need Attach.txt part of DDS.

    Then your MBAM log says "No action taken".
    Re-run it, fix all issues, post new log.

    Next....

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.

    ====================================

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    ===================================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
     
  6. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Currently running the aswMBR. First time it ran, it gave me the blue screen and I had to re-start the CPU. Running it again, but in the mean time I'll post the other logs.

    I actually ran the MBAM after I cleared the virus a few days ago. I'm going to post that log.
     
  7. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    MBAM Post Cleaning

    Malwarebytes Anti-Malware (Trial) 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.09.09.01

    Windows Vista Service Pack 2 x64 NTFS
    Internet Explorer 9.0.8112.16421
    August :: AUGUST-PC [administrator]

    Protection: Enabled

    9/8/2012 11:17:06 PM
    mbam-log-2012-09-08 (23-17-06).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 225438
    Time elapsed: 18 minute(s), 6 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  8. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Attach

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 7/26/2009 12:17:17 AM
    System Uptime: 9/10/2012 5:31:28 PM (5 hours ago)
    .
    Motherboard: TOSHIBA | | Portable PC
    Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz | CPU | 2000/800mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 221 GiB total, 145.33 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP840: 9/6/2012 3:22:08 AM - Scheduled Checkpoint
    RP841: 9/7/2012 3:21:39 AM - Scheduled Checkpoint
    RP842: 9/7/2012 5:21:51 PM - Scheduled Checkpoint
    .
    ==== Installed Programs ======================
    .
    AAC Decoder
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 11 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Reader 9.5.1
    AIM 7
    Apple Application Support
    Apple Software Update
    AutoUpdate
    CameraHelperMsi
    Compatibility Pack for the 2007 Office system
    Direct DiscRecorder
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Plus Web Player
    DivX Version Checker
    Download Updater (AOL LLC)
    DVD MovieFactory for TOSHIBA
    erLT
    Google Chrome
    Google Talk Plugin
    Google Toolbar for Internet Explorer
    Google Update Helper
    H.264 Decoder
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Java Auto Updater
    Java(TM) 6 Update 31
    LightScribe 1.4.124.1
    Logitech Webcam Software
    LWS Facebook
    LWS Gallery
    LWS Help_main
    LWS Launcher
    LWS Motion Detection
    LWS Pictures And Video
    LWS Twitter
    LWS Video Mask Maker
    LWS Webcam Software
    LWS WLM Plugin
    LWS YouTube Plugin
    Malwarebytes Anti-Malware version 1.65.0.1400
    McAfee Agent
    McAfee AntiSpyware Enterprise Module
    McAfee Security Scan Plus
    McAfee VirusScan Enterprise
    Microsoft Choice Guard
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Suite Activation Assistant
    Microsoft Office XP Standard for Students and Teachers
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    MKV Splitter
    Motorola Device Manager
    Motorola Device Software Update
    Mozilla Firefox 15.0 (x86 en-US)
    Mozilla Firefox 15.0.1 (x86 en-US)
    Mozilla Maintenance Service
    MSVCRT
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    MSXML 4.0 SP3 Parser (KB973685)
    Picasa 3
    Project64 1.6
    QuickBooks Financial Center
    QuickTime
    Rapport
    Realtek 8136 8168 8169 Ethernet Driver
    Realtek High Definition Audio Driver
    Realtek USB 2.0 Card Reader
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Skype Click to Call
    Skype Launcher
    Skype™ 5.10
    Spelling Dictionaries Support For Adobe Reader 9
    TOSHIBA Agreement Notification Utility
    Toshiba Application Installer
    TOSHIBA Assist
    TOSHIBA ConfigFree
    TOSHIBA DVD PLAYER
    TOSHIBA eco Utility
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Face Recognition
    TOSHIBA Hardware Setup
    TOSHIBA HDD/SSD Alert
    Toshiba Quality Application
    Toshiba Registration
    Toshiba Resources Page
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    TOSHIBA Web Camera Application
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    VC80CRTRedist - 8.0.50727.4053
    WebEx Support Manager for Internet Explorer
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    .
    ==== Event Viewer Messages From Past Week ========
    .
    9/8/2012 9:40:55 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.84 for the Network Card with network address 001E65432A6E has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message).
    9/8/2012 3:22:13 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.102 for the Network Card with network address 001E65432A6E has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message).
    9/7/2012 3:36:54 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 001E65432A6E has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message).
    9/6/2012 4:40:42 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer KURTWILLIAMS-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{B763E676-6106-4F58-A81A-91ACBB15E641}. The master browser is stopping or an election is being forced.
    9/5/2012 9:55:30 AM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
    9/10/2012 9:28:10 AM, Error: Service Control Manager [7023] - The Portable Device Enumerator Service service terminated with the following error: The specified module could not be found.
    9/10/2012 5:24:38 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wcncsvc with arguments "" in order to run the server: {375FF000-DD27-11D9-8F9C-0002B3988E81}
    9/10/2012 5:24:38 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
    9/10/2012 4:59:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    9/10/2012 4:59:45 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
    9/10/2012 4:59:44 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    9/10/2012 4:59:36 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    9/10/2012 4:57:05 PM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
    9/10/2012 4:56:22 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: mfehidk RapportKE64 spldr Wanarpv6
    9/10/2012 4:56:22 PM, Error: Service Control Manager [7001] - The Windows Media Center Extender Service service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
    9/10/2012 4:56:22 PM, Error: Service Control Manager [7001] - The McAfee Validation Trust Protection Service service depends on the McAfee Inc. mfehidk service which failed to start because of the following error: A device attached to the system is not functioning.
    9/10/2012 4:56:22 PM, Error: Service Control Manager [7001] - The McAfee McShield service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error: The dependency service or group failed to start.
    9/10/2012 4:56:22 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    9/10/2012 4:55:20 PM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
    9/10/2012 4:55:05 PM, Error: Microsoft-Windows-TerminalServices-LocalSessionManager [1048] - Terminal Service start failed. The relevant status code was This service cannot be started in Safe Mode .
    9/10/2012 4:55:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
    9/10/2012 4:54:56 PM, Error: EventLog [6008] - The previous system shutdown at 9:58:45 AM on 9/10/2012 was unexpected.
    .
    ==== End Of File ===========================
     
  9. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    TDSSKiller Log (PART 1)

    21:53:44.0391 3884 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
    21:53:44.0711 3884 ============================================================
    21:53:44.0711 3884 Current date / time: 2012/09/10 21:53:44.0711
    21:53:44.0711 3884 SystemInfo:
    21:53:44.0711 3884
    21:53:44.0711 3884 OS Version: 6.0.6002 ServicePack: 2.0
    21:53:44.0711 3884 Product type: Workstation
    21:53:44.0711 3884 ComputerName: AUGUST-PC
    21:53:44.0721 3884 UserName: August
    21:53:44.0721 3884 Windows directory: C:\Windows
    21:53:44.0721 3884 System windows directory: C:\Windows
    21:53:44.0721 3884 Running under WOW64
    21:53:44.0721 3884 Processor architecture: Intel x64
    21:53:44.0721 3884 Number of processors: 2
    21:53:44.0721 3884 Page size: 0x1000
    21:53:44.0721 3884 Boot type: Normal boot
    21:53:44.0721 3884 ============================================================
    21:53:45.0531 3884 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    21:53:45.0551 3884 ============================================================
    21:53:45.0551 3884 \Device\Harddisk0\DR0:
    21:53:45.0551 3884 MBR partitions:
    21:53:45.0551 3884 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x1BABF000
    21:53:45.0551 3884 ============================================================
    21:53:45.0581 3884 C: <-> \Device\Harddisk0\DR0\Partition1
    21:53:45.0581 3884 ============================================================
    21:53:45.0581 3884 Initialize success
    21:53:45.0581 3884 ============================================================
    21:54:02.0518 5868 ============================================================
    21:54:02.0518 5868 Scan started
    21:54:02.0518 5868 Mode: Manual;
    21:54:02.0518 5868 ============================================================
    21:54:02.0814 5868 ================ Scan system memory ========================
    21:54:02.0814 5868 System memory - ok
    21:54:02.0814 5868 ================ Scan services =============================
    21:54:03.0033 5868 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys
    21:54:03.0033 5868 ACPI - ok
    21:54:03.0236 5868 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    21:54:03.0236 5868 AdobeFlashPlayerUpdateSvc - ok
    21:54:03.0298 5868 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    21:54:03.0298 5868 adp94xx - ok
    21:54:03.0392 5868 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys
    21:54:03.0392 5868 adpahci - ok
    21:54:03.0423 5868 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
    21:54:03.0423 5868 adpu160m - ok
    21:54:03.0454 5868 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    21:54:03.0454 5868 adpu320 - ok
    21:54:03.0516 5868 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    21:54:03.0516 5868 AeLookupSvc - ok
    21:54:03.0563 5868 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys
    21:54:03.0563 5868 AFD - ok
    21:54:03.0626 5868 [ E59BC94C0FC336F2F6A07A7E16441C48 ] AgereSoftModem C:\Windows\system32\DRIVERS\agrsm64.sys
    21:54:03.0641 5868 AgereSoftModem - ok
    21:54:03.0672 5868 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys
    21:54:03.0672 5868 agp440 - ok
    21:54:03.0750 5868 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
    21:54:03.0750 5868 aic78xx - ok
    21:54:03.0766 5868 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe
    21:54:03.0782 5868 ALG - ok
    21:54:03.0813 5868 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys
    21:54:03.0813 5868 aliide - ok
    21:54:03.0844 5868 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys
    21:54:03.0844 5868 amdide - ok
    21:54:03.0891 5868 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
    21:54:03.0891 5868 AmdK8 - ok
    21:54:03.0938 5868 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll
    21:54:03.0953 5868 Appinfo - ok
    21:54:04.0016 5868 [ 557F35D1CA42AEA14A6690E21887A31F ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    21:54:04.0016 5868 Apple Mobile Device - ok
    21:54:04.0047 5868 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys
    21:54:04.0047 5868 arc - ok
    21:54:04.0078 5868 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys
    21:54:04.0078 5868 arcsas - ok
    21:54:04.0125 5868 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    21:54:04.0125 5868 AsyncMac - ok
    21:54:04.0156 5868 [ B388797CAAB36D523840347CC6A39B96 ] atapi C:\Windows\system32\drivers\atapi.sys
    21:54:04.0156 5868 atapi - ok
    21:54:04.0203 5868 [ 40767B965A8D575D794F1F95E2E017E9 ] atashost C:\Windows\SysWOW64\atashost.exe
    21:54:04.0218 5868 atashost - ok
    21:54:04.0281 5868 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    21:54:04.0281 5868 AudioEndpointBuilder - ok
    21:54:04.0296 5868 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    21:54:04.0296 5868 AudioSrv - ok
    21:54:04.0359 5868 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll
    21:54:04.0359 5868 BFE - ok
    21:54:04.0452 5868 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\System32\qmgr.dll
    21:54:04.0452 5868 BITS - ok
    21:54:04.0499 5868 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
    21:54:04.0499 5868 blbdrive - ok
    21:54:04.0546 5868 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    21:54:04.0546 5868 Bonjour Service - ok
    21:54:04.0577 5868 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    21:54:04.0577 5868 bowser - ok
    21:54:04.0624 5868 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
    21:54:04.0624 5868 BrFiltLo - ok
    21:54:04.0640 5868 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
    21:54:04.0640 5868 BrFiltUp - ok
    21:54:04.0686 5868 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll
    21:54:04.0686 5868 Browser - ok
    21:54:04.0733 5868 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys
    21:54:04.0749 5868 Brserid - ok
    21:54:04.0764 5868 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
    21:54:04.0764 5868 BrSerWdm - ok
    21:54:04.0796 5868 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
    21:54:04.0796 5868 BrUsbMdm - ok
    21:54:04.0811 5868 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
    21:54:04.0811 5868 BrUsbSer - ok
    21:54:04.0858 5868 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
    21:54:04.0858 5868 BTHMODEM - ok
    21:54:04.0952 5868 [ F1140ED3A1E1D6824A63F27AFD9EEF32 ] camsvc C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    21:54:04.0967 5868 camsvc - ok
    21:54:04.0998 5868 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    21:54:04.0998 5868 cdfs - ok
    21:54:05.0045 5868 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    21:54:05.0045 5868 cdrom - ok
    21:54:05.0092 5868 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll
    21:54:05.0108 5868 CertPropSvc - ok
    21:54:05.0139 5868 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys
    21:54:05.0139 5868 circlass - ok
    21:54:05.0186 5868 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys
    21:54:05.0186 5868 CLFS - ok
    21:54:05.0291 5868 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    21:54:05.0291 5868 clr_optimization_v2.0.50727_32 - ok
    21:54:05.0341 5868 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    21:54:05.0341 5868 clr_optimization_v2.0.50727_64 - ok
    21:54:05.0441 5868 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    21:54:05.0441 5868 clr_optimization_v4.0.30319_32 - ok
    21:54:05.0471 5868 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    21:54:05.0481 5868 clr_optimization_v4.0.30319_64 - ok
    21:54:05.0541 5868 [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
    21:54:05.0541 5868 CmBatt - ok
    21:54:05.0561 5868 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys
    21:54:05.0561 5868 cmdide - ok
    21:54:05.0591 5868 [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
    21:54:05.0591 5868 Compbatt - ok
    21:54:05.0631 5868 [ 59D203C3F46F3CA536ECAC0E084CD887 ] CompFilter64 C:\Windows\system32\DRIVERS\lvbflt64.sys
    21:54:05.0641 5868 CompFilter64 - ok
    21:54:05.0641 5868 COMSysApp - ok
    21:54:05.0701 5868 [ BCF2C3177E4777E3793310BAC0244C1A ] ConfigFree Gadget Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    21:54:05.0701 5868 ConfigFree Gadget Service - ok
    21:54:05.0711 5868 [ CAB0EEAF5295FC96DDD3E19DCE27E131 ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    21:54:05.0711 5868 ConfigFree Service - ok
    21:54:05.0741 5868 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
    21:54:05.0741 5868 crcdisk - ok
    21:54:05.0791 5868 [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc C:\Windows\system32\cryptsvc.dll
    21:54:05.0801 5868 CryptSvc - ok
    21:54:05.0871 5868 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll
    21:54:05.0881 5868 DcomLaunch - ok
    21:54:05.0921 5868 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    21:54:05.0921 5868 DfsC - ok
    21:54:06.0051 5868 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe
    21:54:06.0081 5868 DFSR - ok
    21:54:06.0141 5868 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll
    21:54:06.0141 5868 Dhcp - ok
    21:54:06.0181 5868 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys
    21:54:06.0181 5868 disk - ok
    21:54:06.0221 5868 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    21:54:06.0281 5868 Dnscache - ok
    21:54:06.0321 5868 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll
    21:54:06.0331 5868 dot3svc - ok
    21:54:06.0381 5868 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll
    21:54:06.0381 5868 DPS - ok
    21:54:06.0431 5868 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    21:54:06.0431 5868 drmkaud - ok
    21:54:06.0481 5868 [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    21:54:06.0491 5868 DXGKrnl - ok
    21:54:06.0531 5868 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys
    21:54:06.0531 5868 E1G60 - ok
    21:54:06.0561 5868 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll
    21:54:06.0571 5868 EapHost - ok
    21:54:06.0611 5868 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys
    21:54:06.0621 5868 Ecache - ok
    21:54:06.0681 5868 [ 33510BE001CCDB5A01FCC88F4DD8DFC7 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    21:54:06.0771 5868 ehRecvr - ok
    21:54:06.0791 5868 [ 1ABC6436B0EDAA3D496D9C827F92820D ] ehSched C:\Windows\ehome\ehsched.exe
    21:54:06.0791 5868 ehSched - ok
    21:54:06.0821 5868 [ 08F48CB2CD4019AFB0456869B49CD76F ] ehstart C:\Windows\ehome\ehstart.dll
    21:54:06.0831 5868 ehstart - ok
    21:54:06.0861 5868 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys
    21:54:06.0861 5868 elxstor - ok
    21:54:06.0911 5868 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll
    21:54:06.0911 5868 EMDMgmt - ok
    21:54:06.0961 5868 [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev C:\Windows\system32\drivers\errdev.sys
    21:54:06.0971 5868 ErrDev - ok
    21:54:07.0011 5868 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll
    21:54:07.0021 5868 EventSystem - ok
    21:54:07.0151 5868 [ 7E763F8F300346A8F1DA8BB1DFA9CA97 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    21:54:07.0161 5868 EvtEng - ok
    21:54:07.0211 5868 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys
    21:54:07.0211 5868 exfat - ok
    21:54:07.0241 5868 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys
    21:54:07.0241 5868 fastfat - ok
    21:54:07.0281 5868 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
    21:54:07.0281 5868 fdc - ok
    21:54:07.0321 5868 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll
    21:54:07.0321 5868 fdPHost - ok
    21:54:07.0331 5868 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll
    21:54:07.0341 5868 FDResPub - ok
    21:54:07.0371 5868 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    21:54:07.0371 5868 FileInfo - ok
    21:54:07.0401 5868 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    21:54:07.0401 5868 Filetrace - ok
    21:54:07.0421 5868 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
    21:54:07.0421 5868 flpydisk - ok
    21:54:07.0461 5868 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    21:54:07.0461 5868 FltMgr - ok
    21:54:07.0551 5868 [ DE67B1AFAB1DDB6CA0BBA89A776F26FA ] FontCache C:\Windows\system32\FntCache.dll
    21:54:07.0561 5868 FontCache - ok
    21:54:07.0661 5868 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    21:54:07.0661 5868 FontCache3.0.0.0 - ok
    21:54:07.0691 5868 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    21:54:07.0771 5868 Fs_Rec - ok
    21:54:07.0811 5868 [ 6D06B5EEBBA23C16789EFC820EE1F253 ] FwLnk C:\Windows\system32\DRIVERS\FwLnk.sys
    21:54:07.0811 5868 FwLnk - ok
    21:54:07.0831 5868 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    21:54:07.0831 5868 gagp30kx - ok
    21:54:07.0871 5868 [ D279181E1CF2D85D31CDCFFD56B16795 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    21:54:07.0871 5868 GEARAspiWDM - ok
    21:54:07.0921 5868 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll
    21:54:07.0931 5868 gpsvc - ok
    21:54:08.0011 5868 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:54:08.0011 5868 gupdate - ok
    21:54:08.0051 5868 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:54:08.0051 5868 gupdatem - ok
    21:54:08.0111 5868 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    21:54:08.0111 5868 gusvc - ok
    21:54:08.0161 5868 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    21:54:08.0171 5868 HdAudAddService - ok
    21:54:08.0231 5868 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
    21:54:08.0241 5868 HDAudBus - ok
    21:54:08.0251 5868 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys
    21:54:08.0261 5868 HidBth - ok
    21:54:08.0291 5868 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys
    21:54:08.0291 5868 HidIr - ok
    21:54:08.0331 5868 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\system32\hidserv.dll
    21:54:08.0331 5868 hidserv - ok
    21:54:08.0371 5868 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    21:54:08.0371 5868 HidUsb - ok
    21:54:08.0401 5868 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll
    21:54:08.0401 5868 hkmsvc - ok
    21:54:08.0441 5868 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
    21:54:08.0441 5868 HpCISSs - ok
    21:54:08.0481 5868 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    21:54:08.0491 5868 HTTP - ok
    21:54:08.0511 5868 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
    21:54:08.0511 5868 i2omp - ok
    21:54:08.0551 5868 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    21:54:08.0551 5868 i8042prt - ok
    21:54:08.0611 5868 [ 1ADAA4F16073FD0C7270F451FD024E97 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    21:54:08.0621 5868 iaStor - ok
    21:54:08.0651 5868 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
    21:54:08.0661 5868 iaStorV - ok
    21:54:08.0721 5868 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    21:54:08.0721 5868 IDriverT - ok
    21:54:08.0811 5868 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    21:54:08.0821 5868 idsvc - ok
    21:54:09.0071 5868 [ 8B7DE1EA805335B1361D459ACB4ECE18 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    21:54:09.0261 5868 igfx - ok
    21:54:09.0291 5868 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    21:54:09.0291 5868 iirsp - ok
    21:54:09.0331 5868 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll
    21:54:09.0341 5868 IKEEXT - ok
    21:54:09.0421 5868 [ CE57D1A91272A35989837B868C8366DF ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
    21:54:09.0451 5868 IntcAzAudAddService - ok
    21:54:09.0481 5868 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys
    21:54:09.0481 5868 intelide - ok
    21:54:09.0501 5868 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    21:54:09.0501 5868 intelppm - ok
    21:54:09.0561 5868 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    21:54:09.0561 5868 IPBusEnum - ok
    21:54:09.0611 5868 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:54:09.0611 5868 IpFilterDriver - ok
    21:54:09.0651 5868 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    21:54:09.0651 5868 iphlpsvc - ok
    21:54:09.0661 5868 IpInIp - ok
    21:54:09.0701 5868 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
    21:54:09.0701 5868 IPMIDRV - ok
    21:54:09.0731 5868 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
    21:54:09.0731 5868 IPNAT - ok
    21:54:09.0791 5868 [ E8E568EA584973DFD99AAC7D00A16287 ] iPod Service C:\Program Files (x86)\iPod\bin\iPodService.exe
    21:54:09.0801 5868 iPod Service - ok
    21:54:09.0831 5868 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys
    21:54:09.0831 5868 IRENUM - ok
    21:54:09.0851 5868 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys
    21:54:09.0851 5868 isapnp - ok
    21:54:09.0891 5868 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
    21:54:09.0891 5868 iScsiPrt - ok
    21:54:09.0911 5868 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
    21:54:09.0911 5868 iteatapi - ok
    21:54:09.0951 5868 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys
    21:54:09.0951 5868 iteraid - ok
    21:54:09.0971 5868 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
    21:54:09.0971 5868 kbdclass - ok
    21:54:09.0991 5868 [ BF8783A5066CFECF45095459E8010FA7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
    21:54:09.0991 5868 kbdhid - ok
    21:54:10.0021 5868 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe
    21:54:10.0021 5868 KeyIso - ok
    21:54:10.0071 5868 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    21:54:10.0071 5868 KSecDD - ok
    21:54:10.0111 5868 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    21:54:10.0111 5868 ksthunk - ok
    21:54:10.0161 5868 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll
    21:54:10.0181 5868 KtmRm - ok
    21:54:10.0221 5868 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\system32\srvsvc.dll
    21:54:10.0231 5868 LanmanServer - ok
    21:54:10.0271 5868 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    21:54:10.0281 5868 LanmanWorkstation - ok
    21:54:10.0351 5868 [ 6E5DAC168D1FF9843E84A59D51D31107 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    21:54:10.0361 5868 LightScribeService - ok
    21:54:10.0391 5868 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    21:54:10.0391 5868 lltdio - ok
    21:54:10.0431 5868 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll
    21:54:10.0451 5868 lltdsvc - ok
    21:54:10.0461 5868 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll
    21:54:10.0471 5868 lmhosts - ok
    21:54:10.0491 5868 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
    21:54:10.0491 5868 LSI_FC - ok
    21:54:10.0521 5868 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    21:54:10.0521 5868 LSI_SAS - ok
    21:54:10.0551 5868 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    21:54:10.0561 5868 LSI_SCSI - ok
    21:54:10.0581 5868 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys
    21:54:10.0581 5868 luafv - ok
    21:54:10.0631 5868 [ 0C85B2B6FB74B36A251792D45E0EF860 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
    21:54:10.0641 5868 LVRS64 - ok
    21:54:10.0801 5868 [ FF3A488924B0032B1A9CA6948C1FA9E8 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
    21:54:10.0931 5868 LVUVC64 - ok
    21:54:10.0971 5868 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
    21:54:10.0971 5868 MBAMProtector - ok
    21:54:11.0071 5868 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    21:54:11.0081 5868 MBAMScheduler - ok
    21:54:11.0131 5868 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    21:54:11.0141 5868 MBAMService - ok
    21:54:11.0221 5868 [ 4A6DD3C84AA2FDDA86EFAA527D8AB7B6 ] McAfeeEngineService C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe
    21:54:11.0221 5868 McAfeeEngineService - ok
    21:54:11.0271 5868 [ 4CD3EE64736B4D156DAC5C1D6EB60C24 ] McAfeeFramework C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    21:54:11.0281 5868 McAfeeFramework - ok
    21:54:11.0331 5868 [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
    21:54:11.0331 5868 McComponentHostService - ok
    21:54:11.0371 5868 [ 39244B1D160FEC32EE4A7EA2635986C8 ] McShield C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe
    21:54:11.0371 5868 McShield - ok
    21:54:11.0381 5868 [ 9DF3A434657512B31549F8D20AFFAD5F ] McTaskManager C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    21:54:11.0391 5868 McTaskManager - ok
    21:54:11.0441 5868 [ 6DA30C0DE0CC8525E89D612C5063CAC1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    21:54:11.0521 5868 Mcx2Svc - ok
    21:54:11.0581 5868 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys
    21:54:11.0581 5868 megasas - ok
    21:54:11.0621 5868 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys
    21:54:11.0621 5868 MegaSR - ok
    21:54:11.0691 5868 [ 4DEA3F2DC347DEA7CB4535680C0E03F1 ] mfeapfk C:\Windows\system32\drivers\mfeapfk.sys
    21:54:11.0691 5868 mfeapfk - ok
    21:54:11.0711 5868 [ E555FED8762CBEE0A91C47450F81654E ] mfeavfk C:\Windows\system32\drivers\mfeavfk.sys
    21:54:11.0711 5868 mfeavfk - ok
    21:54:11.0791 5868 [ F3CE7173922B89CFA909695A489A0E9E ] mfehidk C:\Windows\system32\drivers\mfehidk.sys
    21:54:11.0801 5868 mfehidk - ok
    21:54:11.0821 5868 [ A4F8465B956571AB296EB70C167754DB ] mferkdet C:\Windows\system32\drivers\mferkdet.sys
    21:54:11.0821 5868 mferkdet - ok
    21:54:11.0871 5868 [ 4339AEE8F042ECB4292CD36D84A7CC2F ] mfetdik C:\Windows\system32\drivers\mfetdik.sys
    21:54:11.0871 5868 mfetdik - ok
    21:54:11.0891 5868 [ DBEB6C9C637703C51356F5A1C932FF51 ] mfevtp C:\Windows\system32\mfevtps.exe
    21:54:11.0891 5868 mfevtp - ok
    21:54:11.0921 5868 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll
    21:54:11.0931 5868 MMCSS - ok
    21:54:11.0951 5868 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys
    21:54:11.0961 5868 Modem - ok
    21:54:11.0981 5868 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    21:54:11.0981 5868 monitor - ok
    21:54:12.0051 5868 [ B1AD92BF8C780E37DEE2A5BFC689F3AD ] Motorola Device Manager C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    21:54:12.0061 5868 Motorola Device Manager - ok
    21:54:12.0091 5868 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    21:54:12.0091 5868 mouclass - ok
    21:54:12.0131 5868 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
     
  10. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    TDSSKiller Log (PART 2)

    21:54:12.0131 5868 mouhid - ok
    21:54:12.0161 5868 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
    21:54:12.0161 5868 MountMgr - ok
    21:54:12.0241 5868 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    21:54:12.0251 5868 MozillaMaintenance - ok
    21:54:12.0281 5868 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys
    21:54:12.0291 5868 mpio - ok
    21:54:12.0311 5868 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    21:54:12.0311 5868 mpsdrv - ok
    21:54:12.0361 5868 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll
    21:54:12.0391 5868 MpsSvc - ok
    21:54:12.0411 5868 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
    21:54:12.0411 5868 Mraid35x - ok
    21:54:12.0451 5868 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    21:54:12.0451 5868 MRxDAV - ok
    21:54:12.0491 5868 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:54:12.0491 5868 mrxsmb - ok
    21:54:12.0521 5868 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:54:12.0521 5868 mrxsmb10 - ok
    21:54:12.0551 5868 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:54:12.0551 5868 mrxsmb20 - ok
    21:54:12.0571 5868 [ E7E3E515D1D33A2A372D7FCE2BBEF5D9 ] msahci C:\Windows\system32\drivers\msahci.sys
    21:54:12.0571 5868 msahci - ok
    21:54:12.0601 5868 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    21:54:12.0601 5868 msdsm - ok
    21:54:12.0651 5868 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe
    21:54:12.0661 5868 MSDTC - ok
    21:54:12.0691 5868 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys
    21:54:12.0691 5868 Msfs - ok
    21:54:12.0731 5868 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    21:54:12.0731 5868 msisadrv - ok
    21:54:12.0771 5868 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    21:54:12.0781 5868 MSiSCSI - ok
    21:54:12.0791 5868 msiserver - ok
    21:54:12.0841 5868 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    21:54:12.0841 5868 MSKSSRV - ok
    21:54:12.0861 5868 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    21:54:12.0861 5868 MSPCLOCK - ok
    21:54:12.0881 5868 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    21:54:12.0881 5868 MSPQM - ok
    21:54:12.0921 5868 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    21:54:12.0921 5868 MsRPC - ok
    21:54:12.0961 5868 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
    21:54:12.0961 5868 mssmbios - ok
    21:54:13.0011 5868 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    21:54:13.0011 5868 MSTEE - ok
    21:54:13.0051 5868 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys
    21:54:13.0051 5868 Mup - ok
    21:54:13.0091 5868 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll
    21:54:13.0101 5868 napagent - ok
    21:54:13.0151 5868 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    21:54:13.0151 5868 NativeWifiP - ok
    21:54:13.0221 5868 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys
    21:54:13.0231 5868 NDIS - ok
    21:54:13.0261 5868 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    21:54:13.0261 5868 NdisTapi - ok
    21:54:13.0291 5868 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    21:54:13.0291 5868 Ndisuio - ok
    21:54:13.0331 5868 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    21:54:13.0331 5868 NdisWan - ok
    21:54:13.0361 5868 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    21:54:13.0361 5868 NDProxy - ok
    21:54:13.0391 5868 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    21:54:13.0391 5868 NetBIOS - ok
    21:54:13.0451 5868 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
    21:54:13.0451 5868 netbt - ok
    21:54:13.0461 5868 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe
    21:54:13.0471 5868 Netlogon - ok
    21:54:13.0511 5868 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll
    21:54:13.0511 5868 Netman - ok
    21:54:13.0551 5868 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll
    21:54:13.0551 5868 netprofm - ok
    21:54:13.0601 5868 [ 74751DDA198165947FD7454D83F49825 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    21:54:13.0601 5868 NetTcpPortSharing - ok
    21:54:13.0751 5868 [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64 C:\Windows\system32\DRIVERS\NETw5v64.sys
    21:54:13.0881 5868 NETw5v64 - ok
    21:54:13.0911 5868 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    21:54:13.0911 5868 nfrd960 - ok
    21:54:13.0941 5868 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll
    21:54:13.0951 5868 NlaSvc - ok
    21:54:13.0991 5868 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    21:54:13.0991 5868 Npfs - ok
    21:54:14.0011 5868 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll
    21:54:14.0011 5868 nsi - ok
    21:54:14.0041 5868 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    21:54:14.0041 5868 nsiproxy - ok
    21:54:14.0131 5868 [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    21:54:14.0141 5868 Ntfs - ok
    21:54:14.0171 5868 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys
    21:54:14.0181 5868 Null - ok
    21:54:14.0201 5868 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys
    21:54:14.0201 5868 nvraid - ok
    21:54:14.0221 5868 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys
    21:54:14.0221 5868 nvstor - ok
    21:54:14.0271 5868 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    21:54:14.0271 5868 nv_agp - ok
    21:54:14.0281 5868 NwlnkFlt - ok
    21:54:14.0291 5868 NwlnkFwd - ok
    21:54:14.0341 5868 [ 7B58953E2F263421FDBB09A192712A85 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    21:54:14.0341 5868 ohci1394 - ok
    21:54:14.0391 5868 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll
    21:54:14.0411 5868 p2pimsvc - ok
    21:54:14.0431 5868 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll
    21:54:14.0441 5868 p2psvc - ok
    21:54:14.0481 5868 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys
    21:54:14.0481 5868 Parport - ok
    21:54:14.0521 5868 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys
    21:54:14.0521 5868 partmgr - ok
    21:54:14.0551 5868 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll
    21:54:14.0551 5868 PcaSvc - ok
    21:54:14.0571 5868 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys
    21:54:14.0581 5868 pci - ok
    21:54:14.0601 5868 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\DRIVERS\pciide.sys
    21:54:14.0601 5868 pciide - ok
    21:54:14.0621 5868 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    21:54:14.0631 5868 pcmcia - ok
    21:54:14.0671 5868 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    21:54:14.0671 5868 PEAUTH - ok
    21:54:14.0751 5868 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    21:54:14.0751 5868 PerfHost - ok
    21:54:14.0811 5868 [ 2C3BA65F8CA712730050C29104E093F9 ] PGEffect C:\Windows\system32\DRIVERS\pgeffect.sys
    21:54:14.0811 5868 PGEffect - ok
    21:54:14.0881 5868 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll
    21:54:14.0901 5868 pla - ok
    21:54:14.0931 5868 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    21:54:14.0941 5868 PlugPlay - ok
    21:54:14.0971 5868 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
    21:54:14.0981 5868 PNRPAutoReg - ok
    21:54:15.0001 5868 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll
    21:54:15.0011 5868 PNRPsvc - ok
    21:54:15.0071 5868 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    21:54:15.0091 5868 PolicyAgent - ok
    21:54:15.0131 5868 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    21:54:15.0141 5868 PptpMiniport - ok
    21:54:15.0181 5868 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys
    21:54:15.0191 5868 Processor - ok
    21:54:15.0221 5868 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll
    21:54:15.0231 5868 ProfSvc - ok
    21:54:15.0241 5868 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
    21:54:15.0241 5868 ProtectedStorage - ok
    21:54:15.0291 5868 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
    21:54:15.0291 5868 PSched - ok
    21:54:15.0341 5868 [ EA735BF6DF13A857A83C99BF27A422AD ] PST Service C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    21:54:15.0351 5868 PST Service - ok
    21:54:15.0391 5868 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys
    21:54:15.0401 5868 ql2300 - ok
    21:54:15.0441 5868 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
    21:54:15.0441 5868 ql40xx - ok
    21:54:15.0491 5868 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll
    21:54:15.0491 5868 QWAVE - ok
    21:54:15.0521 5868 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    21:54:15.0521 5868 QWAVEdrv - ok
    21:54:15.0631 5868 [ 00935D8DA2DCD34017544CFEBA97D1E7 ] RapportCerberus_42020 C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys
    21:54:15.0641 5868 RapportCerberus_42020 - ok
    21:54:15.0701 5868 [ E00B1DAC20B52781A6F697235A1CE9D4 ] RapportEI64 C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
    21:54:15.0711 5868 RapportEI64 - ok
    21:54:15.0731 5868 [ A0D6937897654813C27CB149FC4337E4 ] RapportKE64 C:\Windows\system32\Drivers\RapportKE64.sys
    21:54:15.0741 5868 RapportKE64 - ok
    21:54:15.0831 5868 [ 61B37C0B3FD7DA7414C20D917469BFFF ] RapportMgmtService C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    21:54:15.0841 5868 RapportMgmtService - ok
    21:54:15.0871 5868 [ 9B5D119785654BF8219DCBD0C1925FF7 ] RapportPG64 C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
    21:54:15.0871 5868 RapportPG64 - ok
    21:54:15.0911 5868 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    21:54:15.0911 5868 RasAcd - ok
    21:54:15.0951 5868 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll
    21:54:15.0951 5868 RasAuto - ok
    21:54:15.0991 5868 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:54:15.0991 5868 Rasl2tp - ok
    21:54:16.0011 5868 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll
    21:54:16.0011 5868 RasMan - ok
    21:54:16.0061 5868 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    21:54:16.0061 5868 RasPppoe - ok
    21:54:16.0121 5868 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    21:54:16.0121 5868 RasSstp - ok
    21:54:16.0161 5868 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    21:54:16.0171 5868 rdbss - ok
    21:54:16.0201 5868 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:54:16.0201 5868 RDPCDD - ok
    21:54:16.0241 5868 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
    21:54:16.0241 5868 rdpdr - ok
    21:54:16.0251 5868 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    21:54:16.0251 5868 RDPENCDD - ok
    21:54:16.0301 5868 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    21:54:16.0301 5868 RDPWD - ok
    21:54:16.0432 5868 [ 0BF9E30D4F981CAFEDE7DE13604A45F5 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    21:54:16.0448 5868 RegSrvc - ok
    21:54:16.0479 5868 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll
    21:54:16.0479 5868 RemoteAccess - ok
    21:54:16.0510 5868 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    21:54:16.0510 5868 RemoteRegistry - ok
    21:54:16.0542 5868 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe
    21:54:16.0542 5868 RpcLocator - ok
    21:54:16.0614 5868 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\system32\rpcss.dll
    21:54:16.0614 5868 RpcSs - ok
    21:54:16.0644 5868 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    21:54:16.0654 5868 rspndr - ok
    21:54:16.0704 5868 [ 3E800D0DD24C5CFE61A1D71A3F6FEAB9 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh64.sys
    21:54:16.0784 5868 RTL8169 - ok
    21:54:16.0794 5868 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe
    21:54:16.0804 5868 SamSs - ok
    21:54:16.0834 5868 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    21:54:16.0844 5868 sbp2port - ok
    21:54:16.0874 5868 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll
    21:54:16.0884 5868 SCardSvr - ok
    21:54:16.0944 5868 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll
    21:54:16.0954 5868 Schedule - ok
    21:54:17.0004 5868 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll
    21:54:17.0004 5868 SCPolicySvc - ok
    21:54:17.0034 5868 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    21:54:17.0044 5868 SDRSVC - ok
    21:54:17.0074 5868 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    21:54:17.0074 5868 secdrv - ok
    21:54:17.0094 5868 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll
    21:54:17.0104 5868 seclogon - ok
    21:54:17.0134 5868 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\System32\sens.dll
    21:54:17.0144 5868 SENS - ok
    21:54:17.0164 5868 [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum C:\Windows\system32\drivers\serenum.sys
    21:54:17.0164 5868 Serenum - ok
    21:54:17.0204 5868 [ E62FAC91EE288DB29A9696A9D279929C ] Serial C:\Windows\system32\drivers\serial.sys
    21:54:17.0214 5868 Serial - ok
    21:54:17.0234 5868 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys
    21:54:17.0234 5868 sermouse - ok
    21:54:17.0294 5868 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll
    21:54:17.0294 5868 SessionEnv - ok
    21:54:17.0344 5868 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    21:54:17.0344 5868 sffdisk - ok
    21:54:17.0364 5868 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    21:54:17.0364 5868 sffp_mmc - ok
    21:54:17.0384 5868 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    21:54:17.0394 5868 sffp_sd - ok
    21:54:17.0424 5868 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
    21:54:17.0434 5868 sfloppy - ok
    21:54:17.0474 5868 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll
    21:54:17.0484 5868 SharedAccess - ok
    21:54:17.0514 5868 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    21:54:17.0524 5868 ShellHWDetection - ok
    21:54:17.0554 5868 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
    21:54:17.0554 5868 SiSRaid2 - ok
    21:54:17.0584 5868 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    21:54:17.0584 5868 SiSRaid4 - ok
    21:54:17.0644 5868 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    21:54:17.0654 5868 SkypeUpdate - ok
    21:54:17.0754 5868 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe
    21:54:17.0784 5868 slsvc - ok
    21:54:17.0824 5868 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll
    21:54:17.0834 5868 SLUINotify - ok
    21:54:17.0874 5868 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    21:54:17.0874 5868 Smb - ok
    21:54:17.0934 5868 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    21:54:17.0934 5868 SNMPTRAP - ok
    21:54:17.0964 5868 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys
    21:54:17.0964 5868 spldr - ok
    21:54:18.0014 5868 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe
    21:54:18.0024 5868 Spooler - ok
    21:54:18.0074 5868 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys
    21:54:18.0074 5868 srv - ok
    21:54:18.0114 5868 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    21:54:18.0124 5868 srv2 - ok
    21:54:18.0144 5868 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    21:54:18.0154 5868 srvnet - ok
    21:54:18.0194 5868 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    21:54:18.0194 5868 SSDPSRV - ok
    21:54:18.0244 5868 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll
    21:54:18.0244 5868 SstpSvc - ok
    21:54:18.0304 5868 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll
    21:54:18.0324 5868 stisvc - ok
    21:54:18.0354 5868 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys
    21:54:18.0364 5868 swenum - ok
    21:54:18.0404 5868 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll
    21:54:18.0414 5868 swprv - ok
    21:54:18.0444 5868 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
    21:54:18.0444 5868 Symc8xx - ok
    21:54:18.0474 5868 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
    21:54:18.0474 5868 Sym_hi - ok
    21:54:18.0494 5868 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
    21:54:18.0494 5868 Sym_u3 - ok
    21:54:18.0544 5868 [ 6DE6D25CC1D1CB694A1CC3E4604DB644 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
    21:54:18.0544 5868 SynTP - ok
    21:54:18.0604 5868 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll
    21:54:18.0614 5868 SysMain - ok
    21:54:18.0654 5868 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
    21:54:18.0654 5868 TabletInputService - ok
    21:54:18.0704 5868 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll
    21:54:18.0714 5868 TapiSrv - ok
    21:54:18.0744 5868 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll
    21:54:18.0744 5868 TBS - ok
    21:54:18.0814 5868 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    21:54:18.0824 5868 Tcpip - ok
    21:54:18.0854 5868 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
    21:54:18.0874 5868 Tcpip6 - ok
    21:54:18.0904 5868 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    21:54:18.0904 5868 tcpipreg - ok
    21:54:18.0944 5868 [ D45586A9FACB2C9708B10E491EF748A6 ] tdcmdpst C:\Windows\system32\DRIVERS\tdcmdpst.sys
    21:54:18.0944 5868 tdcmdpst - ok
    21:54:18.0984 5868 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    21:54:18.0984 5868 TDPIPE - ok
    21:54:19.0004 5868 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    21:54:19.0014 5868 TDTCP - ok
    21:54:19.0044 5868 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    21:54:19.0044 5868 tdx - ok
    21:54:19.0064 5868 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
    21:54:19.0064 5868 TermDD - ok
    21:54:19.0124 5868 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll
    21:54:19.0134 5868 TermService - ok
    21:54:19.0174 5868 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll
    21:54:19.0184 5868 Themes - ok
    21:54:19.0204 5868 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll
    21:54:19.0204 5868 THREADORDER - ok
    21:54:19.0304 5868 [ 22BC804EFE155F54252F389B0781D7F2 ] TNaviSrv C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    21:54:19.0304 5868 TNaviSrv - ok
    21:54:19.0364 5868 [ 19AF3434564E973BC232BBD629EC2BF6 ] TODDSrv C:\Windows\system32\TODDSrv.exe
    21:54:19.0364 5868 TODDSrv - ok
    21:54:19.0434 5868 [ 7810E3A97E004CD2641FD3FC5D2A62CD ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    21:54:19.0444 5868 TosCoSrv - ok
    21:54:19.0494 5868 [ 947B552AF9371BB52AB1E8C184D1A3D0 ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\TECO\TecoService.exe
    21:54:19.0494 5868 TOSHIBA eco Utility Service - ok
    21:54:19.0564 5868 [ B67C69E2982769355D9FF76DD3B2A0FD ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    21:54:19.0564 5868 TOSHIBA HDD SSD Alert Service - ok
    21:54:19.0604 5868 [ DD50A5DF5F7B29FDB6B5FEA728C43DC3 ] tos_sps64 C:\Windows\system32\DRIVERS\tos_sps64.sys
    21:54:19.0614 5868 tos_sps64 - ok
    21:54:19.0674 5868 [ 66C4503D050DBACAFC5B38FE54EDD86F ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    21:54:19.0684 5868 TPCHSrv - ok
    21:54:19.0724 5868 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll
    21:54:19.0734 5868 TrkWks - ok
    21:54:19.0804 5868 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    21:54:19.0804 5868 TrustedInstaller - ok
    21:54:19.0844 5868 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:54:19.0844 5868 tssecsrv - ok
    21:54:19.0914 5868 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
    21:54:19.0914 5868 tunmp - ok
    21:54:20.0004 5868 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    21:54:20.0004 5868 tunnel - ok
    21:54:20.0054 5868 [ 9A744CC3D804EC38A6C2C65BC3C6FCD8 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS
    21:54:20.0054 5868 TVALZ - ok
    21:54:20.0094 5868 [ BE32A8658A0B56474AD4D0BB8AFA8E55 ] TVALZFL C:\Windows\system32\DRIVERS\TVALZFL.sys
    21:54:20.0094 5868 TVALZFL - ok
    21:54:20.0134 5868 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    21:54:20.0134 5868 uagp35 - ok
    21:54:20.0184 5868 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    21:54:20.0184 5868 udfs - ok
    21:54:20.0234 5868 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe
    21:54:20.0234 5868 UI0Detect - ok
    21:54:20.0274 5868 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    21:54:20.0274 5868 uliagpkx - ok
    21:54:20.0304 5868 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys
    21:54:20.0304 5868 uliahci - ok
    21:54:20.0334 5868 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys
    21:54:20.0334 5868 UlSata - ok
    21:54:20.0374 5868 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
    21:54:20.0374 5868 ulsata2 - ok
    21:54:20.0404 5868 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    21:54:20.0404 5868 umbus - ok
    21:54:20.0444 5868 [ 01ABE05C401E70795B43A8933B44831E ] UMPass C:\Windows\system32\DRIVERS\umpass.sys
    21:54:20.0444 5868 UMPass - ok
    21:54:20.0544 5868 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    21:54:20.0544 5868 UMVPFSrv - ok
    21:54:20.0574 5868 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll
    21:54:20.0584 5868 upnphost - ok
    21:54:20.0624 5868 [ A2D6C837F4BC7D0E084A67D7704C4EA8 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
    21:54:20.0624 5868 USBAAPL64 - ok
    21:54:20.0654 5868 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
    21:54:20.0654 5868 usbaudio - ok
    21:54:20.0694 5868 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    21:54:20.0704 5868 usbccgp - ok
    21:54:20.0734 5868 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    21:54:20.0744 5868 usbcir - ok
    21:54:20.0804 5868 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
    21:54:20.0804 5868 usbehci - ok
    21:54:20.0854 5868 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
    21:54:20.0854 5868 usbhub - ok
    21:54:20.0894 5868 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    21:54:20.0894 5868 usbohci - ok
    21:54:20.0924 5868 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
    21:54:20.0924 5868 usbprint - ok
    21:54:20.0964 5868 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    21:54:20.0964 5868 USBSTOR - ok
    21:54:20.0994 5868 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
    21:54:20.0994 5868 usbuhci - ok
    21:54:21.0064 5868 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
    21:54:21.0064 5868 usbvideo - ok
    21:54:21.0114 5868 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll
    21:54:21.0114 5868 UxSms - ok
    21:54:21.0164 5868 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe
    21:54:21.0174 5868 vds - ok
    21:54:21.0214 5868 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    21:54:21.0214 5868 vga - ok
    21:54:21.0244 5868 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys
    21:54:21.0244 5868 VgaSave - ok
    21:54:21.0274 5868 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys
    21:54:21.0274 5868 viaide - ok
    21:54:21.0284 5868 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys
    21:54:21.0284 5868 volmgr - ok
    21:54:21.0344 5868 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    21:54:21.0344 5868 volmgrx - ok
    21:54:21.0374 5868 [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap C:\Windows\system32\drivers\volsnap.sys
    21:54:21.0374 5868 volsnap - ok
    21:54:21.0414 5868 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    21:54:21.0414 5868 vsmraid - ok
    21:54:21.0494 5868 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe
    21:54:21.0504 5868 VSS - ok
    21:54:21.0564 5868 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll
    21:54:21.0564 5868 W32Time - ok
    21:54:21.0614 5868 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
    21:54:21.0624 5868 WacomPen - ok
    21:54:21.0664 5868 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
    21:54:21.0664 5868 Wanarp - ok
    21:54:21.0674 5868 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    21:54:21.0674 5868 Wanarpv6 - ok
    21:54:21.0734 5868 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll
    21:54:21.0744 5868 wcncsvc - ok
    21:54:21.0784 5868 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    21:54:21.0784 5868 WcsPlugInService - ok
    21:54:21.0834 5868 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys
    21:54:21.0834 5868 Wd - ok
    21:54:21.0884 5868 [ D02E7E4567DA1E7582FBF6A91144B0DF ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    21:54:21.0884 5868 Wdf01000 - ok
    21:54:21.0914 5868 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll
    21:54:21.0914 5868 WdiServiceHost - ok
    21:54:21.0924 5868 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll
    21:54:21.0934 5868 WdiSystemHost - ok
    21:54:21.0984 5868 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll
    21:54:21.0984 5868 WebClient - ok
    21:54:22.0034 5868 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll
    21:54:22.0034 5868 Wecsvc - ok
    21:54:22.0064 5868 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    21:54:22.0064 5868 wercplsupport - ok
    21:54:22.0084 5868 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll
    21:54:22.0094 5868 WerSvc - ok
    21:54:22.0104 5868 WinDefend - ok
    21:54:22.0124 5868 WinHttpAutoProxySvc - ok
    21:54:22.0194 5868 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    21:54:22.0194 5868 Winmgmt - ok
    21:54:22.0274 5868 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll
    21:54:22.0294 5868 WinRM - ok
    21:54:22.0354 5868 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll
    21:54:22.0364 5868 Wlansvc - ok
    21:54:22.0404 5868 [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    21:54:22.0404 5868 WmiAcpi - ok
    21:54:22.0454 5868 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    21:54:22.0454 5868 wmiApSrv - ok
    21:54:22.0504 5868 WMPNetworkSvc - ok
    21:54:22.0554 5868 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
    21:54:22.0564 5868 WPCSvc - ok
    21:54:22.0614 5868 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    21:54:22.0614 5868 WPDBusEnum - ok
    21:54:22.0664 5868 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
    21:54:22.0664 5868 WpdUsb - ok
    21:54:22.0814 5868 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
    21:54:22.0824 5868 WPFFontCache_v0400 - ok
    21:54:22.0854 5868 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    21:54:22.0854 5868 ws2ifsl - ok
    21:54:22.0894 5868 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\System32\wscsvc.dll
    21:54:22.0904 5868 wscsvc - ok
    21:54:22.0914 5868 WSearch - ok
    21:54:23.0014 5868 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    21:54:23.0034 5868 wuauserv - ok
    21:54:23.0064 5868 [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:54:23.0074 5868 WUDFRd - ok
    21:54:23.0114 5868 [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    21:54:23.0124 5868 wudfsvc - ok
    21:54:23.0144 5868 ================ Scan global ===============================
    21:54:23.0164 5868 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
    21:54:23.0214 5868 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
    21:54:23.0234 5868 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
    21:54:23.0284 5868 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe
    21:54:23.0294 5868 [Global] - ok
    21:54:23.0294 5868 ================ Scan MBR ==================================
    21:54:23.0304 5868 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0
    21:54:23.0764 5868 \Device\Harddisk0\DR0 - ok
    21:54:23.0764 5868 ================ Scan VBR ==================================
    21:54:23.0764 5868 [ EAFDF337A8604F3B2CBBD2F54CD945C9 ] \Device\Harddisk0\DR0\Partition1
    21:54:23.0764 5868 \Device\Harddisk0\DR0\Partition1 - ok
    21:54:23.0764 5868 ============================================================
    21:54:23.0764 5868 Scan finished
    21:54:23.0764 5868 ============================================================
    21:54:23.0784 3704 Detected object count: 0
    21:54:23.0784 3704 Actual detected object count: 0
    21:55:02.0981 3768 ============================================================
    21:55:02.0981 3768 Scan started
    21:55:02.0981 3768 Mode: Manual; SigCheck; TDLFS;
    21:55:02.0981 3768 ============================================================
     
  11. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    TDSSKiller Log (Part 3)

    21:55:03.0161 3768 ================ Scan system memory ========================
    21:55:03.0161 3768 System memory - ok
    21:55:03.0161 3768 ================ Scan services =============================
    21:55:03.0291 3768 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys
    21:55:03.0511 3768 ACPI - ok
    21:55:03.0621 3768 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    21:55:03.0661 3768 AdobeFlashPlayerUpdateSvc - ok
    21:55:03.0701 3768 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    21:55:03.0751 3768 adp94xx - ok
    21:55:03.0791 3768 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys
    21:55:03.0831 3768 adpahci - ok
    21:55:03.0871 3768 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
    21:55:03.0901 3768 adpu160m - ok
    21:55:03.0921 3768 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    21:55:03.0961 3768 adpu320 - ok
    21:55:04.0001 3768 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    21:55:04.0191 3768 AeLookupSvc - ok
    21:55:04.0231 3768 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys
    21:55:04.0361 3768 AFD - ok
    21:55:04.0421 3768 [ E59BC94C0FC336F2F6A07A7E16441C48 ] AgereSoftModem C:\Windows\system32\DRIVERS\agrsm64.sys
    21:55:04.0821 3768 AgereSoftModem - ok
    21:55:04.0851 3768 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys
    21:55:04.0881 3768 agp440 - ok
    21:55:04.0921 3768 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
    21:55:04.0951 3768 aic78xx - ok
    21:55:04.0981 3768 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe
    21:55:05.0141 3768 ALG - ok
    21:55:05.0171 3768 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys
    21:55:05.0201 3768 aliide - ok
    21:55:05.0211 3768 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys
    21:55:05.0241 3768 amdide - ok
    21:55:05.0261 3768 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
    21:55:05.0361 3768 AmdK8 - ok
    21:55:05.0391 3768 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll
    21:55:05.0461 3768 Appinfo - ok
    21:55:05.0531 3768 [ 557F35D1CA42AEA14A6690E21887A31F ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    21:55:05.0561 3768 Apple Mobile Device - ok
    21:55:05.0591 3768 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys
    21:55:05.0621 3768 arc - ok
    21:55:05.0641 3768 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys
    21:55:05.0671 3768 arcsas - ok
    21:55:05.0701 3768 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    21:55:05.0781 3768 AsyncMac - ok
    21:55:05.0811 3768 [ B388797CAAB36D523840347CC6A39B96 ] atapi C:\Windows\system32\drivers\atapi.sys
    21:55:05.0841 3768 atapi - ok
    21:55:05.0871 3768 [ 40767B965A8D575D794F1F95E2E017E9 ] atashost C:\Windows\SysWOW64\atashost.exe
    21:55:05.0901 3768 atashost - ok
    21:55:05.0951 3768 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    21:55:06.0031 3768 AudioEndpointBuilder - ok
    21:55:06.0041 3768 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll
    21:55:06.0101 3768 AudioSrv - ok
    21:55:06.0151 3768 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll
    21:55:06.0301 3768 BFE - ok
    21:55:06.0371 3768 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\System32\qmgr.dll
    21:55:06.0531 3768 BITS - ok
    21:55:06.0571 3768 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
    21:55:06.0651 3768 blbdrive - ok
    21:55:06.0691 3768 [ 3F56903E124E820AEECE6D471583C6C1 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    21:55:06.0721 3768 Bonjour Service - ok
    21:55:06.0751 3768 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    21:55:06.0811 3768 bowser - ok
    21:55:06.0851 3768 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
    21:55:06.0911 3768 BrFiltLo - ok
    21:55:06.0931 3768 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
    21:55:07.0021 3768 BrFiltUp - ok
    21:55:07.0051 3768 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll
    21:55:07.0141 3768 Browser - ok
    21:55:07.0171 3768 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys
    21:55:07.0271 3768 Brserid - ok
    21:55:07.0281 3768 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
    21:55:07.0381 3768 BrSerWdm - ok
    21:55:07.0411 3768 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
    21:55:07.0521 3768 BrUsbMdm - ok
    21:55:07.0541 3768 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
    21:55:07.0641 3768 BrUsbSer - ok
    21:55:07.0671 3768 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
    21:55:07.0791 3768 BTHMODEM - ok
    21:55:07.0871 3768 [ F1140ED3A1E1D6824A63F27AFD9EEF32 ] camsvc C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    21:55:07.0911 3768 camsvc - ok
    21:55:07.0931 3768 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    21:55:08.0011 3768 cdfs - ok
    21:55:08.0041 3768 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
    21:55:08.0091 3768 cdrom - ok
    21:55:08.0131 3768 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll
    21:55:08.0201 3768 CertPropSvc - ok
    21:55:08.0221 3768 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys
    21:55:08.0311 3768 circlass - ok
    21:55:08.0361 3768 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys
    21:55:08.0391 3768 CLFS - ok
    21:55:08.0471 3768 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    21:55:08.0491 3768 clr_optimization_v2.0.50727_32 - ok
    21:55:08.0531 3768 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    21:55:08.0561 3768 clr_optimization_v2.0.50727_64 - ok
    21:55:08.0631 3768 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    21:55:08.0661 3768 clr_optimization_v4.0.30319_32 - ok
    21:55:08.0721 3768 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    21:55:08.0751 3768 clr_optimization_v4.0.30319_64 - ok
    21:55:08.0781 3768 [ B52D9A14CE4101577900A364BA86F3DF ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
    21:55:08.0861 3768 CmBatt - ok
    21:55:08.0891 3768 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys
    21:55:08.0911 3768 cmdide - ok
    21:55:08.0951 3768 [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
    21:55:08.0971 3768 Compbatt - ok
    21:55:09.0001 3768 [ 59D203C3F46F3CA536ECAC0E084CD887 ] CompFilter64 C:\Windows\system32\DRIVERS\lvbflt64.sys
    21:55:09.0021 3768 CompFilter64 - ok
    21:55:09.0021 3768 COMSysApp - ok
    21:55:09.0061 3768 [ BCF2C3177E4777E3793310BAC0244C1A ] ConfigFree Gadget Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    21:55:09.0081 3768 ConfigFree Gadget Service ( UnsignedFile.Multi.Generic ) - warning
    21:55:09.0081 3768 ConfigFree Gadget Service - detected UnsignedFile.Multi.Generic (1)
    21:55:09.0101 3768 [ CAB0EEAF5295FC96DDD3E19DCE27E131 ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    21:55:09.0121 3768 ConfigFree Service - ok
    21:55:09.0151 3768 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
    21:55:09.0181 3768 crcdisk - ok
    21:55:09.0231 3768 [ 62740B9D2A137E8CED41A9E4239A7A31 ] CryptSvc C:\Windows\system32\cryptsvc.dll
    21:55:09.0301 3768 CryptSvc - ok
    21:55:09.0361 3768 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll
    21:55:09.0471 3768 DcomLaunch - ok
    21:55:09.0531 3768 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    21:55:09.0611 3768 DfsC - ok
    21:55:09.0731 3768 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe
    21:55:09.0861 3768 DFSR - ok
    21:55:09.0901 3768 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll
    21:55:09.0971 3768 Dhcp - ok
    21:55:10.0021 3768 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys
    21:55:10.0041 3768 disk - ok
    21:55:10.0071 3768 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    21:55:10.0141 3768 Dnscache - ok
    21:55:10.0181 3768 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll
    21:55:10.0231 3768 dot3svc - ok
    21:55:10.0261 3768 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll
    21:55:10.0361 3768 DPS - ok
    21:55:10.0411 3768 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    21:55:10.0481 3768 drmkaud - ok
    21:55:10.0521 3768 [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    21:55:10.0571 3768 DXGKrnl - ok
    21:55:10.0601 3768 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys
    21:55:10.0661 3768 E1G60 - ok
    21:55:10.0691 3768 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll
    21:55:10.0771 3768 EapHost - ok
    21:55:10.0811 3768 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys
    21:55:10.0851 3768 Ecache - ok
    21:55:10.0911 3768 [ 33510BE001CCDB5A01FCC88F4DD8DFC7 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    21:55:11.0061 3768 ehRecvr - ok
    21:55:11.0081 3768 [ 1ABC6436B0EDAA3D496D9C827F92820D ] ehSched C:\Windows\ehome\ehsched.exe
    21:55:11.0121 3768 ehSched - ok
    21:55:11.0141 3768 [ 08F48CB2CD4019AFB0456869B49CD76F ] ehstart C:\Windows\ehome\ehstart.dll
    21:55:11.0181 3768 ehstart - ok
    21:55:11.0221 3768 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys
    21:55:11.0251 3768 elxstor - ok
    21:55:11.0301 3768 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll
    21:55:11.0411 3768 EMDMgmt - ok
    21:55:11.0441 3768 [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev C:\Windows\system32\drivers\errdev.sys
    21:55:11.0521 3768 ErrDev - ok
    21:55:11.0571 3768 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll
    21:55:11.0651 3768 EventSystem - ok
    21:55:11.0761 3768 [ 7E763F8F300346A8F1DA8BB1DFA9CA97 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    21:55:11.0821 3768 EvtEng ( UnsignedFile.Multi.Generic ) - warning
    21:55:11.0821 3768 EvtEng - detected UnsignedFile.Multi.Generic (1)
    21:55:11.0871 3768 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys
    21:55:11.0951 3768 exfat - ok
    21:55:11.0981 3768 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys
    21:55:12.0051 3768 fastfat - ok
    21:55:12.0081 3768 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
    21:55:12.0161 3768 fdc - ok
    21:55:12.0191 3768 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll
    21:55:12.0271 3768 fdPHost - ok
    21:55:12.0291 3768 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll
    21:55:12.0401 3768 FDResPub - ok
    21:55:12.0421 3768 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    21:55:12.0451 3768 FileInfo - ok
    21:55:12.0471 3768 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    21:55:12.0541 3768 Filetrace - ok
    21:55:12.0571 3768 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
    21:55:12.0631 3768 flpydisk - ok
    21:55:12.0671 3768 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    21:55:12.0701 3768 FltMgr - ok
    21:55:12.0751 3768 [ DE67B1AFAB1DDB6CA0BBA89A776F26FA ] FontCache C:\Windows\system32\FntCache.dll
    21:55:12.0911 3768 FontCache - ok
    21:55:13.0011 3768 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    21:55:13.0031 3768 FontCache3.0.0.0 - ok
    21:55:13.0071 3768 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    21:55:13.0131 3768 Fs_Rec - ok
    21:55:13.0161 3768 [ 6D06B5EEBBA23C16789EFC820EE1F253 ] FwLnk C:\Windows\system32\DRIVERS\FwLnk.sys
    21:55:13.0221 3768 FwLnk - ok
    21:55:13.0241 3768 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    21:55:13.0271 3768 gagp30kx - ok
    21:55:13.0311 3768 [ D279181E1CF2D85D31CDCFFD56B16795 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    21:55:13.0341 3768 GEARAspiWDM - ok
    21:55:13.0391 3768 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll
    21:55:13.0521 3768 gpsvc - ok
    21:55:13.0591 3768 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:55:13.0621 3768 gupdate - ok
    21:55:13.0621 3768 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    21:55:13.0651 3768 gupdatem - ok
    21:55:13.0701 3768 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
    21:55:13.0731 3768 gusvc - ok
    21:55:13.0771 3768 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    21:55:13.0891 3768 HdAudAddService - ok
    21:55:13.0951 3768 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
    21:55:14.0051 3768 HDAudBus - ok
    21:55:14.0071 3768 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys
    21:55:14.0181 3768 HidBth - ok
    21:55:14.0221 3768 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys
    21:55:14.0311 3768 HidIr - ok
    21:55:14.0351 3768 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\system32\hidserv.dll
    21:55:14.0411 3768 hidserv - ok
    21:55:14.0451 3768 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    21:55:14.0511 3768 HidUsb - ok
    21:55:14.0541 3768 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll
    21:55:14.0621 3768 hkmsvc - ok
    21:55:14.0641 3768 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
    21:55:14.0671 3768 HpCISSs - ok
    21:55:14.0711 3768 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    21:55:14.0831 3768 HTTP - ok
    21:55:14.0881 3768 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
    21:55:14.0921 3768 i2omp - ok
    21:55:14.0971 3768 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    21:55:15.0051 3768 i8042prt - ok
    21:55:15.0101 3768 [ 1ADAA4F16073FD0C7270F451FD024E97 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
    21:55:15.0131 3768 iaStor - ok
    21:55:15.0171 3768 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
    21:55:15.0211 3768 iaStorV - ok
    21:55:15.0271 3768 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    21:55:15.0311 3768 IDriverT ( UnsignedFile.Multi.Generic ) - warning
    21:55:15.0311 3768 IDriverT - detected UnsignedFile.Multi.Generic (1)
    21:55:15.0381 3768 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    21:55:15.0471 3768 idsvc - ok
    21:55:15.0731 3768 [ 8B7DE1EA805335B1361D459ACB4ECE18 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
    21:55:16.0031 3768 igfx - ok
    21:55:16.0061 3768 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    21:55:16.0091 3768 iirsp - ok
    21:55:16.0141 3768 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll
    21:55:16.0221 3768 IKEEXT - ok
    21:55:16.0301 3768 [ CE57D1A91272A35989837B868C8366DF ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
    21:55:16.0371 3768 IntcAzAudAddService - ok
    21:55:16.0401 3768 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys
    21:55:16.0431 3768 intelide - ok
    21:55:16.0451 3768 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    21:55:16.0531 3768 intelppm - ok
    21:55:16.0571 3768 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    21:55:16.0651 3768 IPBusEnum - ok
    21:55:16.0691 3768 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    21:55:16.0771 3768 IpFilterDriver - ok
    21:55:16.0811 3768 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    21:55:16.0881 3768 iphlpsvc - ok
    21:55:16.0891 3768 IpInIp - ok
    21:55:16.0931 3768 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
    21:55:17.0021 3768 IPMIDRV - ok
    21:55:17.0061 3768 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
    21:55:17.0151 3768 IPNAT - ok
    21:55:17.0201 3768 [ E8E568EA584973DFD99AAC7D00A16287 ] iPod Service C:\Program Files (x86)\iPod\bin\iPodService.exe
    21:55:17.0271 3768 iPod Service - ok
    21:55:17.0311 3768 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys
    21:55:17.0391 3768 IRENUM - ok
    21:55:17.0421 3768 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys
    21:55:17.0451 3768 isapnp - ok
    21:55:17.0491 3768 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
    21:55:17.0521 3768 iScsiPrt - ok
    21:55:17.0541 3768 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
    21:55:17.0571 3768 iteatapi - ok
    21:55:17.0601 3768 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys
    21:55:17.0631 3768 iteraid - ok
    21:55:17.0651 3768 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
    21:55:17.0691 3768 kbdclass - ok
    21:55:17.0711 3768 [ BF8783A5066CFECF45095459E8010FA7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
    21:55:17.0781 3768 kbdhid - ok
    21:55:17.0801 3768 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe
    21:55:17.0851 3768 KeyIso - ok
    21:55:17.0901 3768 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    21:55:17.0981 3768 KSecDD - ok
    21:55:18.0021 3768 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    21:55:18.0121 3768 ksthunk - ok
    21:55:18.0161 3768 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll
    21:55:18.0281 3768 KtmRm - ok
    21:55:18.0321 3768 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\system32\srvsvc.dll
    21:55:18.0371 3768 LanmanServer - ok
    21:55:18.0401 3768 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    21:55:18.0471 3768 LanmanWorkstation - ok
    21:55:18.0531 3768 [ 6E5DAC168D1FF9843E84A59D51D31107 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    21:55:18.0541 3768 LightScribeService ( UnsignedFile.Multi.Generic ) - warning
    21:55:18.0541 3768 LightScribeService - detected UnsignedFile.Multi.Generic (1)
    21:55:18.0571 3768 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    21:55:18.0651 3768 lltdio - ok
    21:55:18.0701 3768 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll
    21:55:18.0791 3768 lltdsvc - ok
    21:55:18.0821 3768 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll
    21:55:18.0901 3768 lmhosts - ok
    21:55:18.0921 3768 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
    21:55:18.0961 3768 LSI_FC - ok
    21:55:18.0991 3768 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    21:55:19.0031 3768 LSI_SAS - ok
    21:55:19.0051 3768 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    21:55:19.0081 3768 LSI_SCSI - ok
    21:55:19.0111 3768 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys
    21:55:19.0181 3768 luafv - ok
    21:55:19.0211 3768 [ 0C85B2B6FB74B36A251792D45E0EF860 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
    21:55:19.0241 3768 LVRS64 - ok
    21:55:19.0381 3768 [ FF3A488924B0032B1A9CA6948C1FA9E8 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
    21:55:19.0561 3768 LVUVC64 - ok
    21:55:19.0591 3768 [ B9FC4CCE5758B816F27DD4D1EED11841 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
    21:55:19.0621 3768 MBAMProtector - ok
    21:55:19.0701 3768 [ 0DCF16B1449811EFA47AB52CAC84093C ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    21:55:19.0741 3768 MBAMScheduler - ok
    21:55:19.0781 3768 [ 9EAABA4D601004BEA4DAA6E146E19A96 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    21:55:19.0861 3768 MBAMService - ok
    21:55:19.0961 3768 [ 4A6DD3C84AA2FDDA86EFAA527D8AB7B6 ] McAfeeEngineService C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe
    21:55:19.0981 3768 McAfeeEngineService - ok
    21:55:20.0031 3768 [ 4CD3EE64736B4D156DAC5C1D6EB60C24 ] McAfeeFramework C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    21:55:20.0051 3768 McAfeeFramework - ok
    21:55:20.0111 3768 [ F453D1E6D881E8F8717E20CCD4199E85 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
    21:55:20.0141 3768 McComponentHostService - ok
    21:55:20.0181 3768 [ 39244B1D160FEC32EE4A7EA2635986C8 ] McShield C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe
    21:55:20.0201 3768 McShield - ok
    21:55:20.0211 3768 [ 9DF3A434657512B31549F8D20AFFAD5F ] McTaskManager C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    21:55:20.0241 3768 McTaskManager - ok
    21:55:20.0281 3768 [ 6DA30C0DE0CC8525E89D612C5063CAC1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    21:55:20.0311 3768 Mcx2Svc - ok
    21:55:20.0331 3768 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys
    21:55:20.0371 3768 megasas - ok
    21:55:20.0391 3768 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys
    21:55:20.0421 3768 MegaSR - ok
    21:55:20.0461 3768 [ 4DEA3F2DC347DEA7CB4535680C0E03F1 ] mfeapfk C:\Windows\system32\drivers\mfeapfk.sys
    21:55:20.0481 3768 mfeapfk - ok
    21:55:20.0501 3768 [ E555FED8762CBEE0A91C47450F81654E ] mfeavfk C:\Windows\system32\drivers\mfeavfk.sys
    21:55:20.0531 3768 mfeavfk - ok
    21:55:20.0551 3768 [ F3CE7173922B89CFA909695A489A0E9E ] mfehidk C:\Windows\system32\drivers\mfehidk.sys
    21:55:20.0581 3768 mfehidk - ok
    21:55:20.0611 3768 [ A4F8465B956571AB296EB70C167754DB ] mferkdet C:\Windows\system32\drivers\mferkdet.sys
    21:55:20.0631 3768 mferkdet - ok
    21:55:20.0661 3768 [ 4339AEE8F042ECB4292CD36D84A7CC2F ] mfetdik C:\Windows\system32\drivers\mfetdik.sys
    21:55:20.0681 3768 mfetdik - ok
    21:55:20.0691 3768 [ DBEB6C9C637703C51356F5A1C932FF51 ] mfevtp C:\Windows\system32\mfevtps.exe
    21:55:20.0711 3768 mfevtp - ok
    21:55:20.0741 3768 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll
    21:55:20.0811 3768 MMCSS - ok
    21:55:20.0841 3768 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys
    21:55:20.0911 3768 Modem - ok
    21:55:20.0941 3768 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    21:55:21.0001 3768 monitor - ok
    21:55:21.0061 3768 [ B1AD92BF8C780E37DEE2A5BFC689F3AD ] Motorola Device Manager C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    21:55:21.0081 3768 Motorola Device Manager - ok
    21:55:21.0121 3768 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
    21:55:21.0151 3768 mouclass - ok
    21:55:21.0171 3768 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
    21:55:21.0251 3768 mouhid - ok
    21:55:21.0281 3768 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
    21:55:21.0311 3768 MountMgr - ok
    21:55:21.0371 3768 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    21:55:21.0401 3768 MozillaMaintenance - ok
    21:55:21.0451 3768 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys
    21:55:21.0481 3768 mpio - ok
    21:55:21.0511 3768 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    21:55:21.0581 3768 mpsdrv - ok
    21:55:21.0631 3768 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll
    21:55:21.0771 3768 MpsSvc - ok
    21:55:21.0801 3768 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
    21:55:21.0831 3768 Mraid35x - ok
    21:55:21.0871 3768 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    21:55:21.0911 3768 MRxDAV - ok
    21:55:21.0951 3768 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    21:55:22.0021 3768 mrxsmb - ok
    21:55:22.0051 3768 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    21:55:22.0101 3768 mrxsmb10 - ok
    21:55:22.0131 3768 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    21:55:22.0181 3768 mrxsmb20 - ok
    21:55:22.0201 3768 [ E7E3E515D1D33A2A372D7FCE2BBEF5D9 ] msahci C:\Windows\system32\drivers\msahci.sys
    21:55:22.0231 3768 msahci - ok
    21:55:22.0251 3768 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys
    21:55:22.0291 3768 msdsm - ok
    21:55:22.0321 3768 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe
    21:55:22.0411 3768 MSDTC - ok
    21:55:22.0441 3768 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys
    21:55:22.0531 3768 Msfs - ok
    21:55:22.0561 3768 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    21:55:22.0591 3768 msisadrv - ok
    21:55:22.0621 3768 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    21:55:22.0701 3768 MSiSCSI - ok
    21:55:22.0711 3768 msiserver - ok
    21:55:22.0741 3768 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    21:55:22.0811 3768 MSKSSRV - ok
    21:55:22.0841 3768 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    21:55:22.0901 3768 MSPCLOCK - ok
    21:55:22.0931 3768 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    21:55:23.0001 3768 MSPQM - ok
    21:55:23.0051 3768 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    21:55:23.0081 3768 MsRPC - ok
    21:55:23.0111 3768 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
     
     
  12. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    TDSSKiller Log (Part 4)

    21:55:23.0131 3768 mssmbios - ok
    21:55:23.0161 3768 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    21:55:23.0231 3768 MSTEE - ok
    21:55:23.0261 3768 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys
    21:55:23.0281 3768 Mup - ok
    21:55:23.0321 3768 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll
    21:55:23.0381 3768 napagent - ok
    21:55:23.0411 3768 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    21:55:23.0451 3768 NativeWifiP - ok
    21:55:23.0491 3768 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys
    21:55:23.0581 3768 NDIS - ok
    21:55:23.0621 3768 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    21:55:23.0721 3768 NdisTapi - ok
    21:55:23.0741 3768 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    21:55:23.0811 3768 Ndisuio - ok
    21:55:23.0851 3768 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    21:55:23.0901 3768 NdisWan - ok
    21:55:23.0941 3768 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    21:55:24.0001 3768 NDProxy - ok
    21:55:24.0031 3768 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    21:55:24.0101 3768 NetBIOS - ok
    21:55:24.0151 3768 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
    21:55:24.0241 3768 netbt - ok
    21:55:24.0261 3768 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe
    21:55:24.0301 3768 Netlogon - ok
    21:55:24.0331 3768 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll
    21:55:24.0411 3768 Netman - ok
    21:55:24.0441 3768 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll
    21:55:24.0511 3768 netprofm - ok
    21:55:24.0541 3768 [ 74751DDA198165947FD7454D83F49825 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    21:55:24.0561 3768 NetTcpPortSharing - ok
    21:55:24.0681 3768 [ 2BDCB7B7917380794C9D87AC2153CE33 ] NETw5v64 C:\Windows\system32\DRIVERS\NETw5v64.sys
    21:55:24.0861 3768 NETw5v64 - ok
    21:55:24.0891 3768 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    21:55:24.0911 3768 nfrd960 - ok
    21:55:24.0951 3768 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll
    21:55:25.0031 3768 NlaSvc - ok
    21:55:25.0091 3768 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    21:55:25.0151 3768 Npfs - ok
    21:55:25.0191 3768 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll
    21:55:25.0281 3768 nsi - ok
    21:55:25.0311 3768 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    21:55:25.0381 3768 nsiproxy - ok
    21:55:25.0451 3768 [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    21:55:25.0601 3768 Ntfs - ok
    21:55:25.0661 3768 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys
    21:55:25.0741 3768 Null - ok
    21:55:25.0761 3768 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys
    21:55:25.0801 3768 nvraid - ok
    21:55:25.0831 3768 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys
    21:55:25.0861 3768 nvstor - ok
    21:55:25.0891 3768 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    21:55:25.0921 3768 nv_agp - ok
    21:55:25.0931 3768 NwlnkFlt - ok
    21:55:25.0941 3768 NwlnkFwd - ok
    21:55:25.0971 3768 [ 7B58953E2F263421FDBB09A192712A85 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
    21:55:26.0071 3768 ohci1394 - ok
    21:55:26.0131 3768 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll
    21:55:26.0251 3768 p2pimsvc - ok
    21:55:26.0321 3768 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll
    21:55:26.0391 3768 p2psvc - ok
    21:55:26.0441 3768 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys
    21:55:26.0551 3768 Parport - ok
    21:55:26.0591 3768 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys
    21:55:26.0621 3768 partmgr - ok
    21:55:26.0661 3768 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll
    21:55:26.0691 3768 PcaSvc - ok
    21:55:26.0711 3768 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys
    21:55:26.0731 3768 pci - ok
    21:55:26.0751 3768 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\DRIVERS\pciide.sys
    21:55:26.0781 3768 pciide - ok
    21:55:26.0801 3768 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    21:55:26.0831 3768 pcmcia - ok
    21:55:26.0861 3768 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    21:55:27.0001 3768 PEAUTH - ok
    21:55:27.0081 3768 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe
    21:55:27.0151 3768 PerfHost - ok
    21:55:27.0201 3768 [ 2C3BA65F8CA712730050C29104E093F9 ] PGEffect C:\Windows\system32\DRIVERS\pgeffect.sys
    21:55:27.0221 3768 PGEffect - ok
    21:55:27.0281 3768 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll
    21:55:27.0391 3768 pla - ok
    21:55:27.0441 3768 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    21:55:27.0491 3768 PlugPlay - ok
    21:55:27.0521 3768 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
    21:55:27.0591 3768 PNRPAutoReg - ok
    21:55:27.0611 3768 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll
    21:55:27.0691 3768 PNRPsvc - ok
    21:55:27.0751 3768 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    21:55:27.0831 3768 PolicyAgent - ok
    21:55:27.0871 3768 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    21:55:27.0941 3768 PptpMiniport - ok
    21:55:27.0981 3768 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys
    21:55:28.0061 3768 Processor - ok
    21:55:28.0111 3768 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll
    21:55:28.0171 3768 ProfSvc - ok
    21:55:28.0181 3768 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
    21:55:28.0211 3768 ProtectedStorage - ok
    21:55:28.0261 3768 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
    21:55:28.0301 3768 PSched - ok
    21:55:28.0351 3768 [ EA735BF6DF13A857A83C99BF27A422AD ] PST Service C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    21:55:28.0361 3768 PST Service ( UnsignedFile.Multi.Generic ) - warning
    21:55:28.0361 3768 PST Service - detected UnsignedFile.Multi.Generic (1)
    21:55:28.0411 3768 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys
    21:55:28.0541 3768 ql2300 - ok
    21:55:28.0591 3768 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
    21:55:28.0621 3768 ql40xx - ok
    21:55:28.0671 3768 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll
    21:55:28.0721 3768 QWAVE - ok
    21:55:28.0751 3768 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    21:55:28.0791 3768 QWAVEdrv - ok
    21:55:28.0901 3768 [ 00935D8DA2DCD34017544CFEBA97D1E7 ] RapportCerberus_42020 C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys
    21:55:28.0931 3768 RapportCerberus_42020 - ok
    21:55:29.0011 3768 [ E00B1DAC20B52781A6F697235A1CE9D4 ] RapportEI64 C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys
    21:55:29.0041 3768 RapportEI64 - ok
    21:55:29.0081 3768 [ A0D6937897654813C27CB149FC4337E4 ] RapportKE64 C:\Windows\system32\Drivers\RapportKE64.sys
    21:55:29.0111 3768 RapportKE64 - ok
    21:55:29.0171 3768 [ 61B37C0B3FD7DA7414C20D917469BFFF ] RapportMgmtService C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    21:55:29.0231 3768 RapportMgmtService - ok
    21:55:29.0261 3768 [ 9B5D119785654BF8219DCBD0C1925FF7 ] RapportPG64 C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys
    21:55:29.0291 3768 RapportPG64 - ok
    21:55:29.0321 3768 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    21:55:29.0391 3768 RasAcd - ok
    21:55:29.0431 3768 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll
    21:55:29.0481 3768 RasAuto - ok
    21:55:29.0521 3768 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    21:55:29.0571 3768 Rasl2tp - ok
    21:55:29.0591 3768 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll
    21:55:29.0651 3768 RasMan - ok
    21:55:29.0691 3768 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    21:55:29.0751 3768 RasPppoe - ok
    21:55:29.0791 3768 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    21:55:29.0841 3768 RasSstp - ok
    21:55:29.0881 3768 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    21:55:29.0941 3768 rdbss - ok
    21:55:29.0981 3768 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
    21:55:30.0051 3768 RDPCDD - ok
    21:55:30.0091 3768 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
    21:55:30.0151 3768 rdpdr - ok
    21:55:30.0161 3768 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
    21:55:30.0231 3768 RDPENCDD - ok
    21:55:30.0271 3768 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    21:55:30.0311 3768 RDPWD - ok
    21:55:30.0401 3768 [ 0BF9E30D4F981CAFEDE7DE13604A45F5 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    21:55:30.0441 3768 RegSrvc ( UnsignedFile.Multi.Generic ) - warning
    21:55:30.0441 3768 RegSrvc - detected UnsignedFile.Multi.Generic (1)
    21:55:30.0481 3768 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll
    21:55:30.0591 3768 RemoteAccess - ok
    21:55:30.0631 3768 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll
    21:55:30.0711 3768 RemoteRegistry - ok
    21:55:30.0741 3768 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe
    21:55:30.0801 3768 RpcLocator - ok
    21:55:30.0871 3768 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\system32\rpcss.dll
    21:55:30.0961 3768 RpcSs - ok
    21:55:31.0011 3768 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    21:55:31.0081 3768 rspndr - ok
    21:55:31.0131 3768 [ 3E800D0DD24C5CFE61A1D71A3F6FEAB9 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh64.sys
    21:55:31.0211 3768 RTL8169 - ok
    21:55:31.0231 3768 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe
    21:55:31.0261 3768 SamSs - ok
    21:55:31.0291 3768 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    21:55:31.0311 3768 sbp2port - ok
    21:55:31.0351 3768 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll
    21:55:31.0401 3768 SCardSvr - ok
    21:55:31.0461 3768 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll
    21:55:31.0591 3768 Schedule - ok
    21:55:31.0651 3768 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll
    21:55:31.0711 3768 SCPolicySvc - ok
    21:55:31.0741 3768 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll
    21:55:31.0811 3768 SDRSVC - ok
    21:55:31.0851 3768 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    21:55:31.0951 3768 secdrv - ok
    21:55:31.0981 3768 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll
    21:55:32.0061 3768 seclogon - ok
    21:55:32.0081 3768 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\System32\sens.dll
    21:55:32.0161 3768 SENS - ok
    21:55:32.0191 3768 [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum C:\Windows\system32\drivers\serenum.sys
    21:55:32.0301 3768 Serenum - ok
    21:55:32.0351 3768 [ E62FAC91EE288DB29A9696A9D279929C ] Serial C:\Windows\system32\drivers\serial.sys
    21:55:32.0451 3768 Serial - ok
    21:55:32.0461 3768 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys
    21:55:32.0531 3768 sermouse - ok
    21:55:32.0581 3768 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll
    21:55:32.0651 3768 SessionEnv - ok
    21:55:32.0691 3768 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
    21:55:32.0781 3768 sffdisk - ok
    21:55:32.0791 3768 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
    21:55:32.0861 3768 sffp_mmc - ok
    21:55:32.0901 3768 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
    21:55:32.0981 3768 sffp_sd - ok
    21:55:33.0001 3768 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
    21:55:33.0111 3768 sfloppy - ok
    21:55:33.0161 3768 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll
    21:55:33.0261 3768 SharedAccess - ok
    21:55:33.0301 3768 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    21:55:33.0371 3768 ShellHWDetection - ok
    21:55:33.0391 3768 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
    21:55:33.0421 3768 SiSRaid2 - ok
    21:55:33.0461 3768 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    21:55:33.0491 3768 SiSRaid4 - ok
    21:55:33.0541 3768 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    21:55:33.0571 3768 SkypeUpdate - ok
    21:55:33.0671 3768 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe
    21:55:33.0801 3768 slsvc - ok
    21:55:33.0841 3768 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll
    21:55:33.0921 3768 SLUINotify - ok
    21:55:33.0951 3768 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys
    21:55:34.0011 3768 Smb - ok
    21:55:34.0061 3768 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    21:55:34.0111 3768 SNMPTRAP - ok
    21:55:34.0161 3768 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys
    21:55:34.0201 3768 spldr - ok
    21:55:34.0251 3768 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe
    21:55:34.0321 3768 Spooler - ok
    21:55:34.0371 3768 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys
    21:55:34.0451 3768 srv - ok
    21:55:34.0501 3768 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    21:55:34.0561 3768 srv2 - ok
    21:55:34.0591 3768 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    21:55:34.0631 3768 srvnet - ok
    21:55:34.0671 3768 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    21:55:34.0771 3768 SSDPSRV - ok
    21:55:34.0801 3768 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll
    21:55:34.0851 3768 SstpSvc - ok
    21:55:34.0911 3768 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll
    21:55:35.0031 3768 stisvc - ok
    21:55:35.0081 3768 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys
    21:55:35.0111 3768 swenum - ok
    21:55:35.0161 3768 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll
    21:55:35.0231 3768 swprv - ok
    21:55:35.0281 3768 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
    21:55:35.0311 3768 Symc8xx - ok
    21:55:35.0341 3768 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
    21:55:35.0371 3768 Sym_hi - ok
    21:55:35.0391 3768 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
    21:55:35.0421 3768 Sym_u3 - ok
    21:55:35.0461 3768 [ 6DE6D25CC1D1CB694A1CC3E4604DB644 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
    21:55:35.0501 3768 SynTP - ok
    21:55:35.0551 3768 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll
    21:55:35.0691 3768 SysMain - ok
    21:55:35.0731 3768 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
    21:55:35.0781 3768 TabletInputService - ok
    21:55:35.0831 3768 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll
    21:55:35.0891 3768 TapiSrv - ok
    21:55:35.0921 3768 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll
    21:55:36.0001 3768 TBS - ok
    21:55:36.0051 3768 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    21:55:36.0131 3768 Tcpip - ok
    21:55:36.0161 3768 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
    21:55:36.0281 3768 Tcpip6 - ok
    21:55:36.0341 3768 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    21:55:36.0411 3768 tcpipreg - ok
    21:55:36.0441 3768 [ D45586A9FACB2C9708B10E491EF748A6 ] tdcmdpst C:\Windows\system32\DRIVERS\tdcmdpst.sys
    21:55:36.0461 3768 tdcmdpst - ok
    21:55:36.0501 3768 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
    21:55:36.0581 3768 TDPIPE - ok
    21:55:36.0601 3768 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
    21:55:36.0691 3768 TDTCP - ok
    21:55:36.0721 3768 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    21:55:36.0781 3768 tdx - ok
    21:55:36.0801 3768 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
    21:55:36.0821 3768 TermDD - ok
    21:55:36.0881 3768 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll
    21:55:36.0951 3768 TermService - ok
    21:55:36.0981 3768 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll
    21:55:37.0021 3768 Themes - ok
    21:55:37.0031 3768 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll
    21:55:37.0091 3768 THREADORDER - ok
    21:55:37.0161 3768 [ 22BC804EFE155F54252F389B0781D7F2 ] TNaviSrv C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    21:55:37.0181 3768 TNaviSrv - ok
    21:55:37.0221 3768 [ 19AF3434564E973BC232BBD629EC2BF6 ] TODDSrv C:\Windows\system32\TODDSrv.exe
    21:55:37.0241 3768 TODDSrv ( UnsignedFile.Multi.Generic ) - warning
    21:55:37.0241 3768 TODDSrv - detected UnsignedFile.Multi.Generic (1)
    21:55:37.0321 3768 [ 7810E3A97E004CD2641FD3FC5D2A62CD ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    21:55:37.0361 3768 TosCoSrv - ok
    21:55:37.0401 3768 [ 947B552AF9371BB52AB1E8C184D1A3D0 ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\TECO\TecoService.exe
    21:55:37.0431 3768 TOSHIBA eco Utility Service ( UnsignedFile.Multi.Generic ) - warning
    21:55:37.0431 3768 TOSHIBA eco Utility Service - detected UnsignedFile.Multi.Generic (1)
    21:55:37.0491 3768 [ B67C69E2982769355D9FF76DD3B2A0FD ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    21:55:37.0501 3768 TOSHIBA HDD SSD Alert Service ( UnsignedFile.Multi.Generic ) - warning
    21:55:37.0501 3768 TOSHIBA HDD SSD Alert Service - detected UnsignedFile.Multi.Generic (1)
    21:55:37.0571 3768 [ DD50A5DF5F7B29FDB6B5FEA728C43DC3 ] tos_sps64 C:\Windows\system32\DRIVERS\tos_sps64.sys
    21:55:37.0641 3768 tos_sps64 - ok
    21:55:37.0721 3768 [ 66C4503D050DBACAFC5B38FE54EDD86F ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    21:55:37.0771 3768 TPCHSrv - ok
    21:55:37.0811 3768 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll
    21:55:37.0891 3768 TrkWks - ok
    21:55:37.0951 3768 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    21:55:38.0011 3768 TrustedInstaller - ok
    21:55:38.0051 3768 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
    21:55:38.0141 3768 tssecsrv - ok
    21:55:38.0161 3768 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
    21:55:38.0201 3768 tunmp - ok
    21:55:38.0251 3768 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    21:55:38.0291 3768 tunnel - ok
    21:55:38.0341 3768 [ 9A744CC3D804EC38A6C2C65BC3C6FCD8 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS
    21:55:38.0371 3768 TVALZ - ok
    21:55:38.0401 3768 [ BE32A8658A0B56474AD4D0BB8AFA8E55 ] TVALZFL C:\Windows\system32\DRIVERS\TVALZFL.sys
    21:55:38.0431 3768 TVALZFL - ok
    21:55:38.0471 3768 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    21:55:38.0501 3768 uagp35 - ok
    21:55:38.0541 3768 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
    21:55:38.0611 3768 udfs - ok
    21:55:38.0661 3768 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe
    21:55:38.0731 3768 UI0Detect - ok
    21:55:38.0771 3768 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    21:55:38.0801 3768 uliagpkx - ok
    21:55:38.0831 3768 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys
    21:55:38.0871 3768 uliahci - ok
    21:55:38.0891 3768 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys
    21:55:38.0931 3768 UlSata - ok
    21:55:38.0961 3768 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
    21:55:38.0991 3768 ulsata2 - ok
    21:55:39.0021 3768 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
    21:55:39.0091 3768 umbus - ok
    21:55:39.0141 3768 [ 01ABE05C401E70795B43A8933B44831E ] UMPass C:\Windows\system32\DRIVERS\umpass.sys
    21:55:39.0221 3768 UMPass - ok
    21:55:39.0331 3768 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    21:55:39.0371 3768 UMVPFSrv - ok
    21:55:39.0411 3768 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll
    21:55:39.0521 3768 upnphost - ok
    21:55:39.0571 3768 [ A2D6C837F4BC7D0E084A67D7704C4EA8 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
    21:55:39.0631 3768 USBAAPL64 - ok
    21:55:39.0651 3768 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
    21:55:39.0721 3768 usbaudio - ok
    21:55:39.0761 3768 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
    21:55:39.0821 3768 usbccgp - ok
    21:55:39.0861 3768 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys
    21:55:39.0971 3768 usbcir - ok
    21:55:40.0011 3768 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
    21:55:40.0071 3768 usbehci - ok
    21:55:40.0121 3768 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
    21:55:40.0171 3768 usbhub - ok
    21:55:40.0201 3768 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys
    21:55:40.0301 3768 usbohci - ok
    21:55:40.0331 3768 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
    21:55:40.0381 3768 usbprint - ok
    21:55:40.0431 3768 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
    21:55:40.0501 3768 USBSTOR - ok
    21:55:40.0541 3768 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
    21:55:40.0581 3768 usbuhci - ok
    21:55:40.0611 3768 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
    21:55:40.0671 3768 usbvideo - ok
    21:55:40.0711 3768 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll
    21:55:40.0761 3768 UxSms - ok
    21:55:40.0821 3768 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe
    21:55:40.0921 3768 vds - ok
    21:55:40.0961 3768 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
    21:55:41.0031 3768 vga - ok
    21:55:41.0051 3768 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys
    21:55:41.0141 3768 VgaSave - ok
    21:55:41.0181 3768 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys
    21:55:41.0211 3768 viaide - ok
    21:55:41.0231 3768 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys
    21:55:41.0281 3768 volmgr - ok
    21:55:41.0331 3768 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    21:55:41.0371 3768 volmgrx - ok
    21:55:41.0391 3768 [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap C:\Windows\system32\drivers\volsnap.sys
    21:55:41.0431 3768 volsnap - ok
    21:55:41.0471 3768 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    21:55:41.0501 3768 vsmraid - ok
    21:55:41.0581 3768 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe
    21:55:41.0761 3768 VSS - ok
    21:55:41.0851 3768 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll
    21:55:41.0921 3768 W32Time - ok
    21:55:41.0971 3768 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
    21:55:42.0091 3768 WacomPen - ok
    21:55:42.0131 3768 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
    21:55:42.0181 3768 Wanarp - ok
    21:55:42.0191 3768 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    21:55:42.0231 3768 Wanarpv6 - ok
    21:55:42.0291 3768 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll
    21:55:42.0351 3768 wcncsvc - ok
    21:55:42.0381 3768 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    21:55:42.0431 3768 WcsPlugInService - ok
    21:55:42.0461 3768 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys
    21:55:42.0491 3768 Wd - ok
    21:55:42.0521 3768 [ D02E7E4567DA1E7582FBF6A91144B0DF ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    21:55:42.0561 3768 Wdf01000 - ok
    21:55:42.0591 3768 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll
    21:55:42.0661 3768 WdiServiceHost - ok
    21:55:42.0671 3768 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll
    21:55:42.0721 3768 WdiSystemHost - ok
    21:55:42.0761 3768 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll
    21:55:42.0801 3768 WebClient - ok
    21:55:42.0851 3768 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll
    21:55:42.0901 3768 Wecsvc - ok
    21:55:42.0941 3768 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll
    21:55:42.0991 3768 wercplsupport - ok
    21:55:43.0031 3768 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll
    21:55:43.0091 3768 WerSvc - ok
    21:55:43.0101 3768 WinDefend - ok
    21:55:43.0121 3768 WinHttpAutoProxySvc - ok
    21:55:43.0171 3768 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    21:55:43.0231 3768 Winmgmt - ok
    21:55:43.0331 3768 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll
    21:55:43.0651 3768 WinRM - ok
    21:55:43.0721 3768 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll
    21:55:43.0831 3768 Wlansvc - ok
    21:55:43.0861 3768 [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
    21:55:43.0931 3768 WmiAcpi - ok
    21:55:43.0971 3768 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    21:55:44.0031 3768 wmiApSrv - ok
    21:55:44.0061 3768 WMPNetworkSvc - ok
    21:55:44.0101 3768 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
    21:55:44.0171 3768 WPCSvc - ok
    21:55:44.0221 3768 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    21:55:44.0291 3768 WPDBusEnum - ok
    21:55:44.0341 3768 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
    21:55:44.0371 3768 WpdUsb - ok
    21:55:44.0501 3768 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
    21:55:44.0561 3768 WPFFontCache_v0400 - ok
    21:55:44.0591 3768 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    21:55:44.0671 3768 ws2ifsl - ok
    21:55:44.0701 3768 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\System32\wscsvc.dll
    21:55:44.0741 3768 wscsvc - ok
    21:55:44.0751 3768 WSearch - ok
    21:55:44.0861 3768 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
    21:55:44.0961 3768 wuauserv - ok
    21:55:44.0991 3768 [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
    21:55:45.0071 3768 WUDFRd - ok
    21:55:45.0111 3768 [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    21:55:45.0191 3768 wudfsvc - ok
    21:55:45.0211 3768 ================ Scan global ===============================
    21:55:45.0231 3768 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
    21:55:45.0271 3768 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
    21:55:45.0291 3768 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
    21:55:45.0341 3768 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe
    21:55:45.0341 3768 [Global] - ok
    21:55:45.0341 3768 ================ Scan MBR ==================================
    21:55:45.0361 3768 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0
    21:55:46.0681 3768 \Device\Harddisk0\DR0 - ok
    21:55:46.0681 3768 ================ Scan VBR ==================================
    21:55:46.0711 3768 [ EAFDF337A8604F3B2CBBD2F54CD945C9 ] \Device\Harddisk0\DR0\Partition1
    21:55:46.0711 3768 \Device\Harddisk0\DR0\Partition1 - ok
    21:55:46.0711 3768 ============================================================
    21:55:46.0711 3768 Scan finished
    21:55:46.0711 3768 ============================================================
    21:55:46.0721 4512 Detected object count: 9
    21:55:46.0721 4512 Actual detected object count: 9
    21:55:55.0853 4512 ConfigFree Gadget Service ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0853 4512 ConfigFree Gadget Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0863 4512 EvtEng ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0863 4512 EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0863 4512 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0863 4512 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0863 4512 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0863 4512 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0873 4512 PST Service ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0873 4512 PST Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0873 4512 RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0873 4512 RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0873 4512 TODDSrv ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0873 4512 TODDSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0883 4512 TOSHIBA eco Utility Service ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0883 4512 TOSHIBA eco Utility Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
    21:55:55.0883 4512 TOSHIBA HDD SSD Alert Service ( UnsignedFile.Multi.Generic ) - skipped by user
    21:55:55.0883 4512 TOSHIBA HDD SSD Alert Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
     
  13. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Rouge Killer

    RogueKiller V8.0.2 [08/31/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows Vista (6.0.6002 Service Pack 2) 64 bits version
    Started in : Normal mode
    User : August [Admin rights]
    Mode : Scan -- Date : 09/10/2012 22:01:41

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 3 ¤¤¤
    [PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\Windows\system32\drivers\etc\hosts

    127.0.0.1 localhost
    ::1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: TOSHIBA MK2555GSX +++++
    --- User ---
    [MBR] f2bb3b8c7f8ed1f4869105564a100b57
    [BSP] 8ea8da6ccd3e743a70ab14bdd90dc819 : Windows Vista MBR Code
    Partition table:
    0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 226686 Mo
    2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 467326976 | Size: 10288 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[1].txt >>
    RKreport[1].txt
     
  14. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    awsMBR Log

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-09-10 22:24:14
    -----------------------------
    22:24:14.693 OS Version: Windows x64 6.0.6002 Service Pack 2
    22:24:14.693 Number of processors: 2 586 0x170A
    22:24:14.694 ComputerName: AUGUST-PC UserName: August
    22:24:16.872 Initialize success
    22:24:35.130 AVAST engine defs: 12091001
    22:24:43.946 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    22:24:43.956 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3
    22:24:43.976 Disk 0 MBR read successfully
    22:24:43.976 Disk 0 MBR scan
    22:24:44.046 Disk 0 Windows VISTA default MBR code
    22:24:44.076 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
    22:24:44.116 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 226686 MB offset 3074048
    22:24:44.156 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10288 MB offset 467326976
    22:24:44.236 Disk 0 scanning C:\Windows\system32\drivers
    22:25:06.776 Service scanning
    22:26:19.772 Modules scanning
    22:26:19.782 Disk 0 trace - called modules:
    22:26:19.812 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    22:26:19.822 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004dbb060]
    22:26:19.822 3 CLASSPNP.SYS[fffffa60014bdc33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bc9050]
    22:26:21.168 AVAST engine scan C:\Windows
    22:26:26.904 AVAST engine scan C:\Windows\system32
    22:35:36.550 AVAST engine scan C:\Windows\system32\drivers
    22:35:55.990 AVAST engine scan C:\Users\August
    22:59:36.875 AVAST engine scan C:\ProgramData
    23:04:56.655 Scan finished successfully
    23:08:11.022 Disk 0 MBR has been saved successfully to "C:\Users\August\Desktop\Exploit Removal\MBR.dat"
    23:08:11.042 The log file has been saved successfully to "C:\Users\August\Desktop\Exploit Removal\aswMBR.txt"
     
  15. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    That should be it for the logs, let me know if you need anything else to move forward. Thanks a ton for helping!
     
  16. Broni

    Broni Malware Annihilator Posts: 47,646   +267

    :)

    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.

    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
     
  17. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    I have to get to sleep, but again thank-you for all of the help. I will be completing these steps tomorrow around 7 PM CST.
     
  18. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Ok - I ran combofix but a few weird things were and are still happening after.

    1. I cannot connect to the internet
    2. During one of the restarts I did to try to fix the computer, windows installed something. When it went to shut down it said it was applying an update, no idea what that was. Note I could not connect to the internet before or after this
    3. I kept getting a windows error about a program that couldn't run properly called Motohelp. It's a program related to my phone. Regardless of how many times I hit "close" the notification kept popping up. I uninstalled the motohelp program and this notification stopped. I don't think this would have any effect on the rest of the computer, but want to make sure I laid out everything I did in the panic of not being able to connect to the internet.

    I put the Combofix log on a flash drive and will post it right after this. I tried resetting my internet connection with no avail. Not sure if things are better or worst now....

    PLEASE HELP!!!!
     
  19. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    ComboFix 12-09-11.02 - August 09/11/2012 18:40:18.1.2 - x64
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.1676 [GMT -5:00]
    Running from: c:\users\August\Desktop\ComboFix.exe
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\Roaming
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-08-12 to 2012-09-12 )))))))))))))))))))))))))))))))
    .
    .
    2012-09-12 00:06 . 2012-09-12 00:06 -------- d-----w- c:\users\Mcx1-AUGUST-PC\AppData\Local\temp
    2012-09-12 00:06 . 2012-09-12 00:06 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-09-11 22:29 . 2012-08-23 08:26 9310152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{5A16CAE9-F20D-4F69-8A4B-2A06E2976BEC}\mpengine.dll
    2012-09-09 03:23 . 2012-09-10 22:31 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2012-08-31 01:03 . 2012-08-31 01:03 -------- d-----w- c:\users\August\AppData\Local\MetaGeek,_LLC
    2012-08-15 08:07 . 2012-07-04 14:33 2769408 ----a-w- c:\windows\system32\win32k.sys
    2012-08-15 08:06 . 2012-05-11 16:34 788480 ----a-w- c:\windows\system32\localspl.dll
    2012-08-15 08:06 . 2012-05-11 15:57 623616 ----a-w- c:\windows\SysWow64\localspl.dll
    2012-08-15 02:55 . 2012-06-29 16:20 648192 ----a-w- c:\windows\system32\netapi32.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-09-07 22:04 . 2009-09-23 03:00 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-08-15 08:01 . 2006-11-02 12:35 62134624 ----a-w- c:\windows\system32\mrt.exe
    2012-08-15 08:01 . 2012-04-06 04:42 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2012-08-15 08:01 . 2011-12-14 22:59 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2012-07-30 01:52 . 2011-05-31 02:38 101688 ----a-w- c:\windows\system32\drivers\RapportKE64.sys
    2012-06-25 21:04 . 2012-06-25 21:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
    2012-06-23 16:56 . 2012-06-23 16:56 5 ----a-w- c:\windows\SysWow64\lMMLDeleteUserData42107612FX.tmp
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ISUSPM"="c:\programdata\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 152064]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-26 39408]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "TWebCamera"="%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe autorun" [X]
    "NDSTray.exe"="c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe" [2009-03-17 304496]
    "cfFncEnabler.exe"="c:\program files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe" [2009-03-24 16384]
    "McAfeeUpdaterUI"="c:\program files (x86)\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
    "ShStatEXE"="c:\program files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2009-07-13 292128]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2012-09-07 981656]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2011-10-24 421888]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
    "LWS"="c:\program files (x86)\Logitech\LWS\Webcam Software\LWS.exe" [2011-11-11 205336]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
    Microsoft Office.lnk - c:\program files (x86)\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
    @="Service"
    .
    R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]
    .
    .
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    Themes
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-09-11 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-06 08:01]
    .
    2012-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-08 07:18]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-08 07:18]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000Core.job
    - c:\users\August\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-10 20:33]
    .
    2012-09-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-577059922-3361006745-2873073242-1000UA.job
    - c:\users\August\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-10 20:33]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-03-13 153624]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-03-13 225816]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2009-03-13 200216]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-18 1713448]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe" [2009-03-24 1123840]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-03-13 7220768]
    "Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2009-03-13 1833504]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://my.yahoo.com/linksys
    mStart Page = hxxp://my.yahoo.com/linksys
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = <local>;192.168.*.*
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office10\EXCEL.EXE/3000
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UpdateCenter/applets/sync.cab
    CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
    FF - ProfilePath - c:\users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
    Wow6432Node-HKCU-Run-Desktop Software - c:\program files (x86)\Common Files\SupportSoft\bin\bcont.exe
    HKLM-Run-(Default) - (no file)
    HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
    HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
    HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
    HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
    HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
    HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
    HKLM-Run-TPCHWMsg - c:\program files (x86)\TOSHIBA\TPHM\TPCHWMsg.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msiserver]
    "ImagePath"="%systemroot%\system32\msiexec /V"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker3"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @SACL=
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @SACL=
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @SACL=
    @=""
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @SACL=
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
    c:\windows\SysWOW64\atashost.exe
    c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
    c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    c:\program files (x86)\McAfee\Common Framework\FrameworkService.exe
    c:\program files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    c:\program files (x86)\McAfee\Common Framework\naPrdMgr.exe
    c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    c:\program files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    c:\program files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
    c:\program files (x86)\iPod\bin\iPodService.exe
    c:\program files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    c:\program files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
    c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    c:\windows\SysWOW64\WerFault.exe
    .
    **************************************************************************
    .
    Completion time: 2012-09-11 19:19:32 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-09-12 00:19
    .
    Pre-Run: 149,231,935,488 bytes free
    Post-Run: 153,082,941,440 bytes free
    .
    - - End Of File - - 37D89ADFFA2AF4AD9F8E0B322AD87DA6
     
  20. Broni

    Broni Malware Annihilator Posts: 47,646   +267

    Please use restore point from before running Combofix and see if you get your connection back.
     
  21. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    That worked, I'm back on the internet. The system restore was actually for an hour before I even downloaded Combofix (downloaded at 6:30 CST, system restore was for 5:30 CST).

    Another weird thing I'm noticing now after the restore. I am getting a Windows Security Alert (I noticed it because there is a red shield icon next to the clock with an X), and it's telling me Windows Defender is off. I try to turn it back on and get the message "Security Center can't turn on Windows Defender. Please try again later."

    Still getting the redirects too. :oops:
     
  22. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    Nevermind on that part about the Windows Defender. As soon as I made that post, it started working LOL!

    Hopefully there is something else we can do here.
     
  23. Broni

    Broni Malware Annihilator Posts: 47,646   +267

    Which browser is getting redirected?
    What about other browser(s)?

    ===========================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  24. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    I am about to run OTL, but wanted to answer your question first after some testing.

    It is re-directing on Firefox and Chrome, but I tried about 8 different links on IE and there was zero re-directs. I also noticed that it doesn't happen everytime, maybe about every 1 in 5 links clicked. And actually after typing that last sentence I tried again and it took about 15 links, so it seems VERY random when it decides to re-direct. Here is an example of a link I am getting re-directed to (not sure if you actually want to click that, just wanted to provide an example).

    http://63.209.69.107/search/web/gym/C10/ecn/46573-133237-833-27681/v5
     
  25. Clevelantis

    Clevelantis TS Rookie Topic Starter Posts: 42

    OTL

    OTL logfile created on: 9/11/2012 10:33:33 PM - Run 1
    OTL by OldTimer - Version 3.2.61.3 Folder = C:\Users\August\Desktop
    64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
    Internet Explorer (Version = 9.0.8112.16421)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    3.87 Gb Total Physical Memory | 2.04 Gb Available Physical Memory | 52.70% Memory free
    7.94 Gb Paging File | 6.00 Gb Available in Paging File | 75.58% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 221.37 Gb Total Space | 134.54 Gb Free Space | 60.78% Space Free | Partition Type: NTFS

    Computer Name: AUGUST-PC | User Name: August | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2012/09/11 22:32:39 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\August\Desktop\OTL.exe
    PRC - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/09/07 17:04:44 | 000,766,536 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/07/29 20:52:22 | 000,976,728 | ---- | M] (Trusteer Ltd.) -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
    PRC - [2012/06/04 19:46:02 | 000,116,632 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
    PRC - [2012/01/18 01:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
    PRC - [2011/11/11 14:08:06 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
    PRC - [2011/11/11 14:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
    PRC - [2011/08/12 12:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
    PRC - [2010/01/15 07:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
    PRC - [2009/04/16 20:42:58 | 000,020,544 | ---- | M] (TOSHIBA) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe
    PRC - [2009/03/30 18:57:22 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    PRC - [2009/03/17 18:36:00 | 000,304,496 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
    PRC - [2009/03/10 20:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
    PRC - [2009/03/10 20:50:36 | 000,062,848 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
    PRC - [2009/03/06 19:27:10 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
    PRC - [2009/03/06 11:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) -- C:\Windows\SysWOW64\atashost.exe
    PRC - [2008/09/29 07:07:00 | 000,124,240 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\shstat.exe
    PRC - [2008/09/29 07:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe
    PRC - [2008/03/14 03:00:00 | 000,226,624 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe
    PRC - [2008/03/14 03:00:00 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe
    PRC - [2008/03/14 03:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe
    PRC - [2007/03/29 15:41:26 | 000,222,128 | ---- | M] (Macrovision Corporation) -- C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe


    ========== Modules (No Company Name) ==========

    MOD - [2011/11/11 14:09:20 | 000,336,408 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
    MOD - [2011/11/11 14:08:18 | 007,956,504 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
    MOD - [2011/11/11 14:08:18 | 000,342,552 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
    MOD - [2011/11/11 14:08:18 | 000,128,536 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
    MOD - [2011/11/11 14:08:18 | 000,029,208 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
    MOD - [2011/11/11 14:08:06 | 002,145,304 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
    MOD - [2011/11/11 14:07:54 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
    MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    MOD - [2011/08/12 12:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
    MOD - [2005/08/22 14:38:16 | 003,264,512 | ---- | M] () -- C:\Program Files (x86)\McAfee\Common Framework\cryptocme2.dll


    ========== Services (SafeList) ==========

    SRV:64bit: - [2009/04/14 19:57:28 | 000,251,392 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
    SRV:64bit: - [2009/04/09 18:03:58 | 000,803,696 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe -- (TPCHSrv)
    SRV:64bit: - [2009/03/17 13:48:54 | 000,084,480 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
    SRV:64bit: - [2009/03/06 20:30:32 | 000,488,288 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
    SRV:64bit: - [2008/10/16 20:05:00 | 001,449,984 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
    SRV:64bit: - [2008/10/16 19:27:20 | 000,826,368 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
    SRV:64bit: - [2008/09/29 07:07:00 | 000,075,656 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
    SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
    SRV:64bit: - [2007/11/21 18:53:16 | 000,135,168 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
    SRV - [2012/09/08 04:02:23 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/08/15 03:01:04 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/07/29 20:52:22 | 000,976,728 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
    SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/06/04 19:46:02 | 000,116,632 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)
    SRV - [2012/01/18 01:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
    SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)
    SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
    SRV - [2010/01/15 07:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
    SRV - [2009/04/16 20:42:58 | 000,020,544 | ---- | M] (TOSHIBA) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe -- (camsvc)
    SRV - [2009/03/30 18:57:22 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
    SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
    SRV - [2009/03/10 20:51:20 | 000,046,448 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
    SRV - [2009/03/06 19:27:10 | 000,036,864 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe -- (ConfigFree Gadget Service)
    SRV - [2009/03/06 11:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
    SRV - [2008/09/29 07:07:00 | 000,175,072 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mcshield.exe -- (McShield)
    SRV - [2008/09/29 07:07:00 | 000,062,800 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\vstskmgr.exe -- (McTaskManager)
    SRV - [2008/09/29 07:07:00 | 000,017,920 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\engineserver.exe -- (McAfeeEngineService)
    SRV - [2008/03/14 03:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/07/29 20:52:38 | 000,101,688 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\RapportKE64.sys -- (RapportKE64)
    DRV:64bit: - [2012/02/29 08:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/01/18 01:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lvuvc64.sys -- (LVUVC64)
    DRV:64bit: - [2012/01/18 01:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lvrs64.sys -- (LVRS64)
    DRV:64bit: - [2012/01/18 01:44:14 | 000,025,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\lvbflt64.sys -- (CompFilter64)
    DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
    DRV:64bit: - [2009/07/09 11:16:16 | 000,048,640 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
    DRV:64bit: - [2009/04/24 16:29:40 | 000,206,336 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
    DRV:64bit: - [2009/03/23 15:48:20 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\TVALZFL.sys -- (TVALZFL)
    DRV:64bit: - [2009/03/19 15:34:18 | 000,029,544 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
    DRV:64bit: - [2009/03/18 13:46:44 | 000,032,832 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\pgeffect.sys -- (PGEffect)
    DRV:64bit: - [2009/03/18 12:20:08 | 000,265,776 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\SynTP.sys -- (SynTP)
    DRV:64bit: - [2009/03/03 14:14:24 | 008,040,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
    DRV:64bit: - [2009/02/11 19:26:18 | 000,407,576 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\iaStor.sys -- (iaStor)
    DRV:64bit: - [2009/01/27 21:12:14 | 000,504,912 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\tos_sps64.sys -- (tos_sps64)
    DRV:64bit: - [2008/11/17 09:50:30 | 004,751,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\NETw5v64.sys -- (NETw5v64)
    DRV:64bit: - [2008/09/29 07:07:00 | 000,465,792 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
    DRV:64bit: - [2008/09/29 07:07:00 | 000,118,688 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
    DRV:64bit: - [2008/09/29 07:07:00 | 000,096,016 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
    DRV:64bit: - [2008/09/29 07:07:00 | 000,082,504 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfetdik.sys -- (mfetdik)
    DRV:64bit: - [2008/09/29 07:07:00 | 000,075,800 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
    DRV:64bit: - [2007/12/11 16:03:36 | 000,027,272 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\tdcmdpst.sys -- (tdcmdpst)
    DRV:64bit: - [2007/11/09 16:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\TVALZ_O.SYS -- (TVALZ)
    DRV:64bit: - [2006/11/20 00:11:06 | 000,008,704 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\FwLnk.sys -- (FwLnk)
    DRV:64bit: - [2006/09/18 16:38:10 | 001,074,688 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\agrsm64.sys -- (AgereSoftModem)
    DRV - [2012/08/12 21:53:23 | 000,397,720 | ---- | M] () [Kernel | System | Running] -- C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_42020.sys -- (RapportCerberus_42020)
    DRV - [2012/07/29 20:52:40 | 000,055,096 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys -- (RapportEI64)
    DRV - [2012/07/29 20:52:38 | 000,297,240 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys -- (RapportPG64)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {8A5F608D-708E-4DD0-85D0-58BA5F5C910C}
    IE:64bit: - HKLM\..\SearchScopes\{8A5F608D-708E-4DD0-85D0-58BA5F5C910C}: "URL" = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7TSHB
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.yahoo.com/linksys
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/linksys
    IE - HKLM\..\SearchScopes,DefaultScope = {7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" = http://slirsredirect.search.aol.com...}&invocationType=tb50-ie-aim-chromesbox-en-us
    IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?source...nputEncoding}&oe={outputEncoding}&rlz=1I7TSHB
    IE - HKLM\..\SearchScopes\{7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}: "URL" = http://www.google.com/search?q={sea...tartIndex={startIndex?}&startPage={startPage}


    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/linksys
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" = http://slirsredirect.search.aol.com...}&invocationType=tb50-ie-aim-chromesbox-en-us
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?source...ding}&oe={outputEncoding}&rlz=1I7TSHB_enUS338
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}: "URL" = http://www.google.com/search?q={sea...tartIndex={startIndex?}&startPage={startPage}
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://us.search.yahoo.com/search?p={searchTerms}&fr=chr-linksys
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\SearchScopes\{F08F2CEC-FF5F-4771-8D1B-F18219F16C7D}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;192.168.*.*

    ========== FireFox ==========

    FF - prefs.js..browser.search.defaultenginename: "AIM Search"
    FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us"
    FF - prefs.js..browser.search.order.1: "Fast Browser Search"
    FF - prefs.js..browser.search.selectedEngine: "Google"
    FF - prefs.js..browser.search.useDBForOrder: true
    FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
    FF - prefs.js..extensions.enabledAddons: vcsfgdyaxu@vcsfgdyaxu.org:1.0
    FF - prefs.js..extensions.enabledAddons: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.7.1
    FF - prefs.js..extensions.enabledItems: vshareus@toolbar:1.0.0
    FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.3
    FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=mcafee&p="


    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_271.dll File not found
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll (DivX, Inc)
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files (x86)\Picasa2\npPicasa2.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Picasa2\npPicasa3.dll (Google, Inc.)
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll File not found
    FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\August\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\August\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\August\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\August\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/08 04:02:24 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/08 04:02:18 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/08 04:02:24 | 000,000,000 | ---D | M]
    FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/08 04:02:18 | 000,000,000 | ---D | M]

    [2009/08/02 18:19:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\August\AppData\Roaming\Mozilla\Extensions
    [2012/07/12 10:37:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\extensions
    [1629/07/06 02:22:29 | 000,004,819 | ---- | M] () (No name found) -- C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\extensions\vcsfgdyaxu@vcsfgdyaxu.org.xpi
    [2012/04/09 21:59:58 | 000,372,140 | ---- | M] () (No name found) -- C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi
    [2010/04/20 20:56:30 | 000,002,267 | ---- | M] () -- C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\searchplugins\aim-search.xml
    [2009/11/07 11:41:46 | 000,005,413 | ---- | M] () -- C:\Users\August\AppData\Roaming\Mozilla\Firefox\Profiles\ae92old5.default\searchplugins\fast-browser-search.xml
    [2012/09/08 04:02:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2012/09/08 04:02:14 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    [2012/09/08 04:02:24 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2008/09/29 07:07:00 | 000,022,576 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
    [2012/04/04 23:16:06 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2012/08/30 19:03:24 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2010/12/20 00:58:01 | 000,002,024 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
    [2012/08/30 19:03:24 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    ========== Chrome ==========

    CHR - homepage: http://www.google.com
    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
    CHR - homepage: http://www.google.com
    CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Users\August\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\August\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Users\August\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
    CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
    CHR - plugin: downloadUpdater (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
    CHR - plugin: downloadUpdater2 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
    CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
    CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\August\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\August\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Picasa2\npPicasa2.dll
    CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Picasa2\npPicasa3.dll
    CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
    CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
    CHR - Extension: Awesome Screenshot: Capture & Annotate = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\alelhddbbhepgpmgidjdcjakblofbmce\3.3.6_0\
    CHR - Extension: YouTube = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
    CHR - Extension: Google Search = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
    CHR - Extension: Google Calendar = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
    CHR - Extension: IE Tab = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd\3.6.30.1_0\
    CHR - Extension: Skype Click to Call = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.9.0.9216_0\
    CHR - Extension: Google Maps = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.4_0\
    CHR - Extension: Google Dictionary (by Google) = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.12_0\
    CHR - Extension: Google Mail Checker = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
    CHR - Extension: Google Chrome to Phone Extension = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco\2.3.1_0\
    CHR - Extension: Gmail = C:\Users\August\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

    O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\scriptsn.dll (McAfee, Inc.)
    O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
    O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\McAfee\VirusScan Enterprise\scriptsn.dll (McAfee, Inc.)
    O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
    O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O3:64bit: - HKU\S-1-5-21-577059922-3361006745-2873073242-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
    O4:64bit: - HKLM..\Run: [] File not found
    O4:64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
    O4:64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [TPCHWMsg] C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
    O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [cfFncEnabler.exe] C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe (Toshiba Corporation)
    O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
    O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
    O4 - HKLM..\Run: [NDSTray.exe] C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
    O4 - HKLM..\Run: [ShStatEXE] C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
    O4 - HKLM..\Run: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun File not found
    O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
    O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
    O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
    O4 - HKU\S-1-5-21-577059922-3361006745-2873073242-1000..\Run: [Desktop Software] "C:\Program Files (x86)\Common Files\SupportSoft\bin\bcont.exe" /ini "C:\Program Files (x86)\ComcastUI\Desktop Software\uinstaller.ini" /fromrun /starthidden
     


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.