SledgeProne
Posts: 91 +0
Yesterday, my system began hanging on various tasks and duties, coupled with freezing webpages. An updated scan of Malwarebytes initially netted some nefarious clutter, but the cleansing produced no significant improvements in performance.
Unsure of whether it was malware related, I cleaned up resources with Tuneup Utilities, while I sought an alternate opinion of viral analysis from HouseCall.
Meanwhile, Malwarebytes was returning negative scans for any high profile threats. This, in stark contrast to diminishing system performance, and responsiveness. HouseCall however, found no offending threats.
Convinced a hijacker was nevertheless aboard, and simply evading detection, I downloaded the latest TDSSKiller,which unearthed a rootkit. Despite efforts to disinfect, it was back this evening, in a return engagement, which consequently has returned me to your doorstep, seeking a rat trap.
23:51:02.0046 5320 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
23:51:02.0984 5320 ============================================================
23:51:02.0984 5320 Current date / time: 2012/11/23 23:51:02.0984
23:51:02.0984 5320 SystemInfo:
23:51:02.0984 5320
23:51:02.0984 5320 OS Version: 5.1.2600 ServicePack: 3.0
23:51:02.0984 5320 Product type: Workstation
23:51:02.0984 5320 ComputerName: ENDLESS
23:51:02.0984 5320 UserName: Master Blaster
23:51:02.0984 5320 Windows directory: C:\WINDOWS
23:51:02.0984 5320 System windows directory: C:\WINDOWS
23:51:02.0984 5320 Processor architecture: Intel x86
23:51:02.0984 5320 Number of processors: 2
23:51:02.0984 5320 Page size: 0x1000
23:51:02.0984 5320 Boot type: Normal boot
23:51:02.0984 5320 ============================================================
23:51:04.0593 5320 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:51:04.0609 5320 Drive \Device\Harddisk1\DR1 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:51:04.0656 5320 ============================================================
23:51:04.0656 5320 \Device\Harddisk0\DR0:
23:51:04.0656 5320 MBR partitions:
23:51:04.0656 5320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xFFFAC05
23:51:04.0656 5320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFFFAC44, BlocksNum 0x4754A6BD
23:51:04.0656 5320 \Device\Harddisk1\DR1:
23:51:04.0656 5320 MBR partitions:
23:51:04.0656 5320 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
23:51:04.0656 5320 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x12A14C00, BlocksNum 0x12A18AC1
23:51:04.0656 5320 ============================================================
23:51:04.0687 5320 C: <-> \Device\Harddisk0\DR0\Partition1
23:51:04.0843 5320 E: <-> \Device\Harddisk1\DR1\Partition1
23:51:05.0078 5320 F: <-> \Device\Harddisk1\DR1\Partition2
23:51:05.0484 5320 G: <-> \Device\Harddisk0\DR0\Partition2
23:51:05.0484 5320 ============================================================
23:51:05.0484 5320 Initialize success
23:51:05.0484 5320 ============================================================
23:51:08.0843 4220 ============================================================
23:51:08.0843 4220 Scan started
23:51:08.0843 4220 Mode: Manual;
23:51:08.0843 4220 ============================================================
23:51:11.0890 4220 ================ Scan system memory ========================
23:51:11.0906 4220 System memory - ok
23:51:11.0906 4220 ================ Scan services =============================
23:51:12.0015 4220 Abiosdsk - ok
23:51:12.0031 4220 abp480n5 - ok
23:51:12.0078 4220 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:51:12.0093 4220 ACPI - ok
23:51:12.0125 4220 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
23:51:12.0125 4220 ACPIEC - ok
23:51:12.0203 4220 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
23:51:12.0218 4220 AdobeFlashPlayerUpdateSvc - ok
23:51:12.0234 4220 adpu160m - ok
23:51:12.0296 4220 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
23:51:12.0296 4220 aec - ok
23:51:12.0343 4220 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
23:51:12.0359 4220 AFD - ok
23:51:12.0359 4220 Aha154x - ok
23:51:12.0375 4220 aic78u2 - ok
23:51:12.0375 4220 aic78xx - ok
23:51:13.0125 4220 [ B9B98E08EC127900025F42462D3D0A66 ] Akamai c:\program files\common files\akamai/netsession_win_ce5ba24.dll
23:51:13.0125 4220 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_ce5ba24.dll. md5: B9B98E08EC127900025F42462D3D0A66
23:51:13.0140 4220 Akamai ( HiddenFile.Multi.Generic ) - warning
23:51:13.0140 4220 Akamai - detected HiddenFile.Multi.Generic (1)
23:51:13.0156 4220 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
23:51:13.0187 4220 Alerter - ok
23:51:13.0203 4220 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
23:51:13.0203 4220 ALG - ok
23:51:13.0203 4220 AliIde - ok
23:51:13.0203 4220 amsint - ok
23:51:13.0218 4220 ANC - ok
23:51:13.0250 4220 [ 1BF91F352D746AD7469FA71783B5FAE8 ] APLMp50 C:\WINDOWS\system32\Drivers\APLMp50.sys
23:51:13.0250 4220 APLMp50 - ok
23:51:13.0328 4220 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
23:51:13.0343 4220 Apple Mobile Device - ok
23:51:13.0375 4220 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
23:51:13.0390 4220 AppMgmt - ok
23:51:13.0390 4220 asc - ok
23:51:13.0406 4220 asc3350p - ok
23:51:13.0406 4220 asc3550 - ok
23:51:13.0406 4220 ashampoodefragservice - ok
23:51:13.0500 4220 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
23:51:13.0500 4220 aspnet_state - ok
23:51:13.0546 4220 [ 0C83FC56707BF68DB04947052A8188B1 ] ASTSRV C:\WINDOWS\system32\ASTSRV.EXE
23:51:13.0546 4220 ASTSRV - ok
23:51:13.0578 4220 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:51:13.0578 4220 AsyncMac - ok
23:51:13.0593 4220 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
23:51:13.0593 4220 atapi - ok
23:51:13.0593 4220 Atdisk - ok
23:51:13.0687 4220 [ D80A3FD3DB6F999F6D1C6D23A293851B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
23:51:13.0750 4220 Ati HotKey Poller - ok
23:51:14.0468 4220 [ C832BF76F003999D2E91E5115583C69E ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
23:51:15.0203 4220 ati2mtag - ok
23:51:15.0250 4220 [ 0D6B8359677D05142B624F09C28D643A ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdXP3.sys
23:51:15.0250 4220 AtiHDAudioService - ok
23:51:15.0265 4220 atinevxx - ok
23:51:15.0281 4220 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:51:15.0281 4220 Atmarpc - ok
23:51:15.0312 4220 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
23:51:15.0312 4220 AudioSrv - ok
23:51:15.0343 4220 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
23:51:15.0359 4220 audstub - ok
23:51:15.0375 4220 bc_pat_f - ok
23:51:15.0390 4220 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
23:51:15.0390 4220 Beep - ok
23:51:15.0468 4220 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
23:51:15.0515 4220 Bonjour Service - ok
23:51:15.0562 4220 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
23:51:15.0578 4220 Browser - ok
23:51:15.0687 4220 catchme - ok
23:51:15.0718 4220 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
23:51:15.0718 4220 cbidf2k - ok
23:51:15.0734 4220 ccproxy - ok
23:51:15.0734 4220 cd20xrnt - ok
23:51:15.0750 4220 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
23:51:15.0750 4220 Cdaudio - ok
23:51:15.0781 4220 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
23:51:15.0781 4220 Cdfs - ok
23:51:15.0828 4220 [ 4B0A100EAF5C49EF3CCA8C641431EACC ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:51:15.0828 4220 Cdrom - ok
23:51:15.0828 4220 Changer - ok
23:51:15.0843 4220 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] cisvc C:\WINDOWS\system32\cisvc.exe
23:51:15.0843 4220 cisvc - ok
23:51:15.0859 4220 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
23:51:15.0859 4220 ClipSrv - ok
23:51:15.0890 4220 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:51:15.0906 4220 clr_optimization_v2.0.50727_32 - ok
23:51:15.0984 4220 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:51:16.0000 4220 clr_optimization_v4.0.30319_32 - ok
23:51:16.0000 4220 CmdIde - ok
23:51:16.0000 4220 COMSysApp - ok
23:51:16.0015 4220 Cpqarray - ok
23:51:16.0031 4220 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
23:51:16.0046 4220 CryptSvc - ok
23:51:16.0046 4220 ctdvda2k - ok
23:51:16.0046 4220 ctxcpubal - ok
23:51:16.0046 4220 dac2w2k - ok
23:51:16.0062 4220 dac960nt - ok
23:51:16.0125 4220 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
23:51:16.0250 4220 DcomLaunch - ok
23:51:16.0281 4220 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
23:51:16.0281 4220 Dhcp - ok
23:51:16.0312 4220 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
23:51:16.0312 4220 Disk - ok
23:51:16.0312 4220 dmadmin - ok
23:51:16.0406 4220 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
23:51:16.0515 4220 dmboot - ok
23:51:16.0546 4220 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
23:51:16.0562 4220 dmio - ok
23:51:16.0578 4220 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
23:51:16.0578 4220 dmload - ok
23:51:16.0593 4220 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
23:51:16.0593 4220 dmserver - ok
23:51:16.0625 4220 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
23:51:16.0640 4220 DMusic - ok
23:51:16.0656 4220 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
23:51:16.0656 4220 Dnscache - ok
23:51:16.0687 4220 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
23:51:16.0703 4220 Dot3svc - ok
23:51:16.0718 4220 dpti2o - ok
23:51:16.0750 4220 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
23:51:16.0750 4220 drmkaud - ok
23:51:16.0765 4220 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
23:51:16.0781 4220 EapHost - ok
23:51:16.0781 4220 ENTECH - ok
23:51:16.0796 4220 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
23:51:16.0796 4220 ERSvc - ok
23:51:16.0828 4220 [ EADA995E71211537FB3726C700AF6FAC ] EUBAKUP C:\WINDOWS\system32\drivers\eubakup.sys
23:51:16.0828 4220 EUBAKUP - ok
23:51:16.0859 4220 [ 37ABA51F85518FC381CEFC8D76F2E2C4 ] EuDisk C:\WINDOWS\system32\DRIVERS\EuDisk.sys
23:51:16.0875 4220 EuDisk - ok
23:51:16.0875 4220 [ CB41E20CE4A32584EA592F07F5DA12C5 ] EUDSKACS C:\WINDOWS\system32\drivers\eudskacs.sys
23:51:16.0875 4220 EUDSKACS - ok
23:51:16.0890 4220 [ A08E9E711CD7661D7C3F19EE638102C2 ] EUFS C:\WINDOWS\system32\drivers\eufs.sys
23:51:16.0890 4220 EUFS - ok
23:51:16.0937 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
23:51:16.0937 4220 Eventlog - ok
23:51:17.0000 4220 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
23:51:17.0015 4220 EventSystem - ok
23:51:17.0046 4220 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
23:51:17.0093 4220 Fastfat - ok
23:51:17.0109 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
23:51:17.0125 4220 FastUserSwitchingCompatibility - ok
23:51:17.0125 4220 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
23:51:17.0140 4220 Fdc - ok
23:51:17.0156 4220 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
23:51:17.0156 4220 Fips - ok
23:51:17.0171 4220 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:51:17.0171 4220 Flpydisk - ok
23:51:17.0203 4220 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
23:51:17.0203 4220 FltMgr - ok
23:51:17.0265 4220 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
23:51:17.0265 4220 FontCache3.0.0.0 - ok
23:51:17.0296 4220 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:51:17.0296 4220 Fs_Rec - ok
23:51:17.0312 4220 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:51:17.0328 4220 Ftdisk - ok
23:51:17.0328 4220 G400DH - ok
23:51:17.0328 4220 GMSIPCI - ok
23:51:17.0343 4220 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:51:17.0343 4220 Gpc - ok
23:51:17.0437 4220 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
23:51:17.0453 4220 gupdate - ok
23:51:17.0468 4220 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
23:51:17.0468 4220 gupdatem - ok
23:51:17.0515 4220 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
23:51:17.0546 4220 HDAudBus - ok
23:51:17.0578 4220 helpsvc - ok
23:51:17.0609 4220 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
23:51:17.0609 4220 HidServ - ok
23:51:17.0640 4220 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:51:17.0640 4220 HidUsb - ok
23:51:17.0671 4220 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
23:51:17.0687 4220 hkmsvc - ok
23:51:17.0687 4220 hpn - ok
23:51:17.0687 4220 hpqwmiex - ok
23:51:17.0687 4220 hpt3xx - ok
23:51:17.0734 4220 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
23:51:17.0765 4220 HTTP - ok
23:51:17.0796 4220 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
23:51:17.0890 4220 HTTPFilter - ok
23:51:17.0890 4220 i2omgmt - ok
23:51:17.0906 4220 i2omp - ok
23:51:17.0906 4220 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:51:17.0921 4220 i8042prt - ok
23:51:18.0031 4220 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:51:18.0156 4220 idsvc - ok
23:51:18.0171 4220 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
23:51:18.0171 4220 Imapi - ok
23:51:18.0218 4220 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
23:51:18.0234 4220 ImapiService - ok
23:51:18.0234 4220 ini910u - ok
23:51:18.0250 4220 IntelIde - ok
23:51:18.0296 4220 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:51:18.0296 4220 intelppm - ok
23:51:18.0312 4220 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
23:51:18.0312 4220 ip6fw - ok
23:51:18.0328 4220 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:51:18.0328 4220 IpFilterDriver - ok
23:51:18.0328 4220 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:51:18.0328 4220 IpInIp - ok
23:51:18.0359 4220 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:51:18.0375 4220 IpNat - ok
23:51:18.0390 4220 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:51:18.0390 4220 IPSec - ok
23:51:18.0406 4220 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
23:51:18.0406 4220 IRENUM - ok
23:51:18.0421 4220 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:51:18.0421 4220 isapnp - ok
23:51:18.0546 4220 [ A12175F063302CD68F8FC6D572D7E5FD ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
23:51:18.0562 4220 JavaQuickStarterService - ok
23:51:18.0562 4220 k750mgmt - ok
23:51:18.0593 4220 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:51:18.0593 4220 Kbdclass - ok
23:51:18.0609 4220 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
23:51:18.0609 4220 kbdhid - ok
23:51:18.0640 4220 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
23:51:18.0656 4220 kmixer - ok
23:51:18.0671 4220 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
23:51:18.0687 4220 KSecDD - ok
23:51:18.0718 4220 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
23:51:18.0734 4220 lanmanserver - ok
23:51:18.0781 4220 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
23:51:18.0812 4220 lanmanworkstation - ok
23:51:18.0828 4220 [ BE2DC24D403643A2D1D98F33C7087B38 ] LBeepKE C:\WINDOWS\system32\Drivers\LBeepKE.sys
23:51:18.0843 4220 LBeepKE - ok
23:51:18.0843 4220 lbrtfdc - ok
23:51:18.0953 4220 [ 910344E2A984010435AE84783B25E5EB ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
23:51:18.0984 4220 LBTServ - ok
23:51:19.0015 4220 [ 717E6714BCA808F2A372E636AFF3D15A ] LEqdUsb C:\WINDOWS\system32\Drivers\LEqdUsb.Sys
23:51:19.0015 4220 LEqdUsb - ok
23:51:19.0046 4220 [ 2786F7B4003ADFF88CE28BC1800B5407 ] LHidEqd C:\WINDOWS\system32\Drivers\LHidEqd.Sys
23:51:19.0046 4220 LHidEqd - ok
23:51:19.0078 4220 [ 01CC7FB6E790EF044B411377F3A1FF41 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
23:51:19.0093 4220 LHidFilt - ok
23:51:19.0125 4220 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
23:51:19.0125 4220 LmHosts - ok
23:51:19.0140 4220 [ A2E7EAE8898D7B4B8C302B8F4E836BB5 ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
23:51:19.0140 4220 LMouFilt - ok
23:51:19.0156 4220 ltmodem5 - ok
23:51:19.0156 4220 lvpopflt - ok
23:51:19.0156 4220 lxcf_device - ok
23:51:19.0187 4220 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
23:51:19.0187 4220 MBAMProtector - ok
23:51:19.0265 4220 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:51:19.0328 4220 MBAMScheduler - ok
23:51:19.0437 4220 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
23:51:19.0515 4220 MBAMService - ok
23:51:19.0562 4220 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
23:51:19.0562 4220 Messenger - ok
23:51:19.0578 4220 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
23:51:19.0578 4220 mnmdd - ok
23:51:19.0609 4220 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
23:51:19.0609 4220 mnmsrvc - ok
23:51:19.0625 4220 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
23:51:19.0625 4220 Modem - ok
23:51:19.0671 4220 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:51:19.0671 4220 Mouclass - ok
23:51:19.0687 4220 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:51:19.0687 4220 mouhid - ok
23:51:19.0734 4220 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
23:51:19.0734 4220 MountMgr - ok
23:51:19.0781 4220 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
23:51:19.0796 4220 MozillaMaintenance - ok
23:51:19.0796 4220 mraid35x - ok
23:51:19.0828 4220 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:51:19.0843 4220 MRxDAV - ok
23:51:19.0921 4220 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:51:19.0968 4220 MRxSmb - ok
23:51:20.0000 4220 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
23:51:20.0015 4220 MSDTC - ok
23:51:20.0015 4220 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
23:51:20.0015 4220 Msfs - ok
23:51:20.0031 4220 MSIServer - ok
23:51:20.0062 4220 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:51:20.0078 4220 MSKSSRV - ok
23:51:20.0078 4220 MSMQ - ok
23:51:20.0109 4220 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:51:20.0109 4220 MSPCLOCK - ok
23:51:20.0140 4220 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
23:51:20.0140 4220 MSPQM - ok
23:51:20.0156 4220 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:51:20.0156 4220 mssmbios - ok
23:51:20.0187 4220 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
23:51:20.0203 4220 Mup - ok
23:51:20.0265 4220 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
23:51:20.0296 4220 napagent - ok
23:51:20.0328 4220 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
23:51:20.0343 4220 NDIS - ok
23:51:20.0390 4220 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:51:20.0390 4220 NdisTapi - ok
23:51:20.0406 4220 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:51:20.0406 4220 Ndisuio - ok
23:51:20.0437 4220 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:51:20.0437 4220 NdisWan - ok
23:51:20.0453 4220 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
23:51:20.0468 4220 NDProxy - ok
23:51:20.0484 4220 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
23:51:20.0484 4220 NetBIOS - ok
23:51:20.0515 4220 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
23:51:20.0546 4220 NetBT - ok
23:51:20.0578 4220 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
23:51:20.0593 4220 NetDDE - ok
23:51:20.0609 4220 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
23:51:20.0609 4220 NetDDEdsdm - ok
23:51:20.0640 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
23:51:20.0640 4220 Netlogon - ok
23:51:20.0671 4220 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
23:51:20.0687 4220 Netman - ok
23:51:20.0734 4220 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
23:51:20.0750 4220 NetTcpPortSharing - ok
23:51:20.0781 4220 [ 13EC0B1767DBFBC3A6C89EECB0B84F34 ] networx C:\WINDOWS\system32\drivers\networx.sys
23:51:20.0781 4220 networx - ok
23:51:20.0828 4220 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
23:51:20.0843 4220 Nla - ok
23:51:20.0890 4220 [ B9730495E0CF674680121E34BD95A73B ] NPF C:\WINDOWS\system32\drivers\npf.sys
23:51:20.0890 4220 NPF - ok
23:51:20.0906 4220 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
23:51:20.0906 4220 Npfs - ok
23:51:20.0968 4220 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
23:51:21.0015 4220 Ntfs - ok
23:51:21.0015 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
23:51:21.0015 4220 NtLmSsp - ok
23:51:21.0078 4220 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
23:51:21.0156 4220 NtmsSvc - ok
23:51:21.0203 4220 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
23:51:21.0203 4220 NuidFltr - ok
23:51:21.0218 4220 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
23:51:21.0218 4220 Null - ok
23:51:21.0250 4220 [ 7D275ECDA4628318912F6C945D5CF963 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
23:51:21.0250 4220 NVENETFD - ok
23:51:21.0328 4220 [ B64AACEFAD2BE5BFF5353FE681253C67 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
23:51:21.0328 4220 nvnetbus - ok
23:51:21.0375 4220 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:51:21.0375 4220 NwlnkFlt - ok
23:51:21.0390 4220 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:51:21.0390 4220 NwlnkFwd - ok
23:51:21.0390 4220 ofcpfwsvc - ok
23:51:21.0406 4220 ovt519 - ok
23:51:21.0421 4220 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
23:51:21.0437 4220 Parport - ok
23:51:21.0437 4220 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
23:51:21.0437 4220 PartMgr - ok
23:51:21.0468 4220 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
23:51:21.0468 4220 ParVdm - ok
23:51:21.0468 4220 pav_security - ok
23:51:21.0515 4220 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
23:51:21.0531 4220 PCI - ok
23:51:21.0531 4220 PCIDump - ok
23:51:21.0562 4220 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
23:51:21.0578 4220 PCIIde - ok
23:51:21.0593 4220 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
23:51:21.0609 4220 Pcmcia - ok
23:51:21.0609 4220 PDCOMP - ok
23:51:21.0609 4220 PDFRAME - ok
23:51:21.0625 4220 pdlnatdl - ok
23:51:21.0625 4220 PDRELI - ok
23:51:21.0625 4220 PDRFRAME - ok
23:51:21.0640 4220 perc2 - ok
23:51:21.0640 4220 perc2hib - ok
23:51:21.0671 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
23:51:21.0671 4220 PlugPlay - ok
23:51:21.0671 4220 pneclo - ok
23:51:21.0718 4220 [ E5582E43E167CF367757D81E9727DA2A ] Point32 C:\WINDOWS\system32\DRIVERS\point32.sys
23:51:21.0718 4220 Point32 - ok
23:51:21.0718 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
23:51:21.0718 4220 PolicyAgent - ok
23:51:21.0750 4220 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:51:21.0750 4220 PptpMiniport - ok
23:51:21.0750 4220 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
23:51:21.0765 4220 Processor - ok
23:51:21.0765 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
23:51:21.0765 4220 ProtectedStorage - ok
23:51:21.0765 4220 protectionservice - ok
23:51:21.0781 4220 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
23:51:21.0796 4220 PSched - ok
23:51:21.0796 4220 PSSdk21 - ok
23:51:21.0812 4220 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:51:21.0812 4220 Ptilink - ok
23:51:21.0828 4220 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
23:51:21.0843 4220 PxHelp20 - ok
23:51:21.0843 4220 ql1080 - ok
23:51:21.0843 4220 Ql10wnt - ok
23:51:21.0843 4220 ql12160 - ok
23:51:21.0859 4220 ql1240 - ok
23:51:21.0875 4220 ql1280 - ok
23:51:21.0890 4220 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:51:21.0890 4220 RasAcd - ok
23:51:21.0921 4220 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
23:51:21.0937 4220 RasAuto - ok
23:51:21.0953 4220 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:51:21.0953 4220 Rasl2tp - ok
23:51:22.0015 4220 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
23:51:22.0031 4220 RasMan - ok
23:51:22.0046 4220 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:51:22.0046 4220 RasPppoe - ok
23:51:22.0046 4220 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
23:51:22.0046 4220 Raspti - ok
23:51:22.0078 4220 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:51:22.0093 4220 Rdbss - ok
23:51:22.0093 4220 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:51:22.0093 4220 RDPCDD - ok
23:51:22.0125 4220 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
23:51:22.0156 4220 rdpdr - ok
23:51:22.0187 4220 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
23:51:22.0203 4220 RDPWD - ok
23:51:22.0265 4220 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
23:51:22.0281 4220 RDSessMgr - ok
23:51:22.0312 4220 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
23:51:22.0312 4220 redbook - ok
23:51:22.0359 4220 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
23:51:22.0359 4220 RemoteAccess - ok
23:51:22.0375 4220 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
23:51:22.0390 4220 RemoteRegistry - ok
23:51:22.0390 4220 rismxdp - ok
23:51:22.0453 4220 [ A780D3EAA74582EA1DEB6BD9C7A3D9C9 ] rpcapd C:\Program Files\WinPcap\rpcapd.exe
23:51:22.0468 4220 rpcapd - ok
23:51:22.0484 4220 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\System32\locator.exe
23:51:22.0484 4220 RpcLocator - ok
23:51:22.0546 4220 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
23:51:22.0546 4220 RpcSs - ok
23:51:22.0593 4220 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\System32\rsvp.exe
23:51:22.0609 4220 RSVP - ok
23:51:22.0609 4220 s116obex - ok
23:51:22.0656 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
23:51:22.0656 4220 SamSs - ok
23:51:22.0718 4220 [ A3281AEC37E0720A2BC28034C2DF2A56 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
23:51:22.0718 4220 SASDIFSV - ok
23:51:22.0734 4220 [ 61DB0D0756A99506207FD724E3692B25 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
23:51:22.0734 4220 SASKUTIL - ok
23:51:22.0765 4220 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
23:51:22.0781 4220 SCardSvr - ok
23:51:22.0812 4220 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
23:51:22.0843 4220 Schedule - ok
23:51:22.0859 4220 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:51:22.0875 4220 Secdrv - ok
23:51:22.0906 4220 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
23:51:22.0906 4220 seclogon - ok
23:51:22.0937 4220 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
23:51:22.0953 4220 SENS - ok
23:51:22.0953 4220 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
23:51:22.0953 4220 serenum - ok
23:51:22.0984 4220 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
23:51:22.0984 4220 Serial - ok
23:51:23.0000 4220 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
23:51:23.0000 4220 Sfloppy - ok
23:51:23.0031 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:51:23.0031 4220 ShellHWDetection - ok
23:51:23.0046 4220 Simbad - ok
23:51:23.0046 4220 Sparrow - ok
23:51:23.0078 4220 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
23:51:23.0078 4220 splitter - ok
23:51:23.0109 4220 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
23:51:23.0109 4220 Spooler - ok
23:51:23.0125 4220 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
23:51:23.0125 4220 sr - ok
23:51:23.0171 4220 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
23:51:23.0187 4220 srservice - ok
23:51:23.0296 4220 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
23:51:23.0328 4220 Srv - ok
23:51:23.0359 4220 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
23:51:23.0359 4220 SSDPSRV - ok
23:51:23.0531 4220 [ 61536F3D6BA7CE09025D60B3398A8260 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys
23:51:23.0718 4220 STHDA - ok
23:51:23.0765 4220 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
23:51:23.0812 4220 stisvc - ok
23:51:23.0812 4220 StkASSrv - ok
23:51:23.0812 4220 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
23:51:23.0812 4220 swenum - ok
23:51:23.0828 4220 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
23:51:23.0843 4220 swmidi - ok
23:51:23.0843 4220 SwPrv - ok
23:51:23.0843 4220 symc810 - ok
23:51:23.0859 4220 symc8xx - ok
23:51:23.0859 4220 sym_hi - ok
23:51:23.0875 4220 sym_u3 - ok
23:51:23.0906 4220 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
23:51:23.0906 4220 sysaudio - ok
23:51:23.0921 4220 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
23:51:23.0937 4220 SysmonLog - ok
23:51:23.0984 4220 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
23:51:24.0000 4220 TapiSrv - ok
23:51:24.0046 4220 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:51:24.0093 4220 Tcpip - ok
23:51:24.0140 4220 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
23:51:24.0140 4220 TDPIPE - ok
23:51:24.0171 4220 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
23:51:24.0171 4220 TDTCP - ok
23:51:24.0203 4220 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
23:51:24.0203 4220 TermDD - ok
23:51:24.0250 4220 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
23:51:24.0281 4220 TermService - ok
23:51:24.0328 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
23:51:24.0328 4220 Themes - ok
23:51:24.0328 4220 TIEHDUSB - ok
23:51:24.0359 4220 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
23:51:24.0359 4220 TlntSvr - ok
23:51:24.0375 4220 tng-dtmg - ok
23:51:24.0375 4220 tng-dts - ok
23:51:24.0375 4220 TosIde - ok
23:51:24.0421 4220 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
23:51:24.0437 4220 TrkWks - ok
23:51:24.0500 4220 [ 6A29CD69D1128BDF49A705BEFC614A5B ] TuneUp.Defrag C:\WINDOWS\System32\TuneUpDefragService.exe
23:51:24.0531 4220 TuneUp.Defrag - ok
23:51:24.0609 4220 [ 51EE2913ED525DE18FDA96DCCBC5386A ] TuneUp.ProgramStatisticsSvc C:\WINDOWS\System32\TUProgSt.exe
23:51:24.0703 4220 TuneUp.ProgramStatisticsSvc - ok
23:51:24.0718 4220 [ E6D35F3AA51A65EB35C1F2340154A25E ] ubsvve C:\WINDOWS\system32\drivers\tnloa.sys
23:51:24.0718 4220 ubsvve - ok
23:51:24.0734 4220 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
23:51:24.0750 4220 Udfs - ok
23:51:24.0750 4220 ultra - ok
23:51:24.0750 4220 UPATC - ok
23:51:24.0828 4220 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
23:51:24.0859 4220 Update - ok
23:51:24.0890 4220 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
23:51:24.0906 4220 upnphost - ok
23:51:24.0921 4220 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
23:51:24.0921 4220 UPS - ok
23:51:24.0968 4220 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
23:51:24.0968 4220 usbaudio - ok
23:51:25.0000 4220 [ 9419FAAC6552A51542DBBA02971C841C ] usbbus C:\WINDOWS\system32\DRIVERS\lgusbbus.sys
23:51:25.0000 4220 usbbus - ok
23:51:25.0031 4220 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:51:25.0031 4220 usbccgp - ok
23:51:25.0046 4220 [ C0A466FA4FFEC464320E159BC1BBDC0C ] UsbDiag C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys
23:51:25.0046 4220 UsbDiag - ok
23:51:25.0078 4220 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:51:25.0078 4220 usbehci - ok
23:51:25.0109 4220 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:51:25.0125 4220 usbhub - ok
23:51:25.0140 4220 [ F74A54774A9B0AFEB3C40ADEC68AA600 ] USBModem C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys
23:51:25.0140 4220 USBModem - ok
23:51:25.0171 4220 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
23:51:25.0171 4220 usbohci - ok
23:51:25.0203 4220 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:51:25.0203 4220 usbprint - ok
23:51:25.0234 4220 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:51:25.0250 4220 usbscan - ok
23:51:25.0250 4220 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:51:25.0265 4220 USBSTOR - ok
23:51:25.0281 4220 [ 2E2E93041C8058BC7DE6F0D743C4A0C6 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll
23:51:25.0296 4220 UxTuneUp - ok
23:51:25.0296 4220 vet-filt - ok
23:51:25.0312 4220 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
23:51:25.0312 4220 VgaSave - ok
23:51:25.0312 4220 ViaIde - ok
23:51:25.0359 4220 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
23:51:25.0359 4220 VolSnap - ok
23:51:25.0406 4220 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
23:51:25.0421 4220 VSS - ok
23:51:25.0437 4220 vstor2-ws60 - ok
23:51:25.0500 4220 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
23:51:25.0515 4220 W32Time - ok
23:51:25.0546 4220 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:51:25.0546 4220 Wanarp - ok
23:51:25.0625 4220 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
23:51:25.0671 4220 Wdf01000 - ok
23:51:25.0671 4220 WDICA - ok
23:51:25.0703 4220 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
23:51:25.0718 4220 wdmaud - ok
23:51:25.0734 4220 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
23:51:25.0750 4220 WebClient - ok
23:51:25.0796 4220 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
23:51:25.0812 4220 winmgmt - ok
23:51:25.0843 4220 [ FD600B032E741EB6AAB509FC630F7C42 ] WinUSB C:\WINDOWS\system32\DRIVERS\WinUSB.sys
23:51:25.0859 4220 WinUSB - ok
23:51:25.0875 4220 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
23:51:25.0890 4220 WmdmPmSN - ok
23:51:25.0953 4220 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
23:51:26.0015 4220 Wmi - ok
23:51:26.0015 4220 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
23:51:26.0015 4220 WmiAcpi - ok
23:51:26.0046 4220 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
23:51:26.0062 4220 WmiApSrv - ok
23:51:26.0234 4220 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
23:51:26.0359 4220 WMPNetworkSvc - ok
23:51:26.0406 4220 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
23:51:26.0406 4220 WpdUsb - ok
23:51:26.0593 4220 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:51:26.0671 4220 WPFFontCache_v0400 - ok
23:51:26.0687 4220 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
23:51:26.0703 4220 WS2IFSL - ok
23:51:26.0734 4220 [ EAA6324F51214D2F6718977EC9CE0DEF ] WudfPf C:\WINDOWS\system32\DRIVERS\WUDFPF.SYS
23:51:26.0734 4220 WudfPf - ok
23:51:26.0765 4220 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
23:51:26.0765 4220 WudfRd - ok
23:51:26.0812 4220 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
23:51:26.0828 4220 WudfSvc - ok
23:51:26.0828 4220 wwsecsvc - ok
23:51:26.0890 4220 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
23:51:26.0937 4220 WZCSVC - ok
23:51:26.0984 4220 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
23:51:27.0000 4220 xmlprov - ok
23:51:27.0015 4220 zumbus - ok
23:51:27.0015 4220 ================ Scan global ===============================
23:51:27.0046 4220 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
23:51:27.0109 4220 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
23:51:27.0187 4220 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
23:51:27.0218 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
23:51:27.0234 4220 [Global] - ok
23:51:27.0234 4220 ================ Scan MBR ==================================
23:51:27.0234 4220 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
23:51:27.0234 4220 Suspicious mbr (Forged): \Device\Harddisk0\DR0
23:51:27.0265 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
23:51:27.0265 4220 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
23:51:27.0281 4220 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
23:51:27.0656 4220 \Device\Harddisk1\DR1 - ok
23:51:27.0656 4220 ================ Scan VBR ==================================
23:51:27.0656 4220 [ 69EED2EF33A11298E239910E24E272B3 ] \Device\Harddisk0\DR0\Partition1
23:51:27.0656 4220 \Device\Harddisk0\DR0\Partition1 - ok
23:51:27.0671 4220 [ A49216FCA2A788E234F8FE99B972065F ] \Device\Harddisk0\DR0\Partition2
23:51:27.0671 4220 \Device\Harddisk0\DR0\Partition2 - ok
23:51:27.0671 4220 [ A0E19D7F186228B02D332DF17C82E035 ] \Device\Harddisk1\DR1\Partition1
23:51:27.0671 4220 \Device\Harddisk1\DR1\Partition1 - ok
23:51:27.0687 4220 [ 88DB4795C5F45EB4FDB0663D0381F632 ] \Device\Harddisk1\DR1\Partition2
23:51:27.0703 4220 \Device\Harddisk1\DR1\Partition2 - ok
23:51:27.0703 4220 ============================================================
23:51:27.0703 4220 Scan finished
23:51:27.0703 4220 ============================================================
23:51:27.0703 3492 Detected object count: 2
23:51:27.0703 3492 Actual detected object count: 2
23:53:38.0953 3492 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
23:53:38.0953 3492 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
23:53:39.0515 3492 \Device\Harddisk0\DR0\# - copied to quarantine
23:53:39.0515 3492 \Device\Harddisk0\DR0 - copied to quarantine
23:53:41.0453 3492 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
23:53:41.0468 3492 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
23:53:41.0468 3492 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
23:53:41.0578 3492 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
23:53:41.0578 3492 \Device\Harddisk0\DR0 - ok
23:53:42.0718 3492 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
23:53:49.0187 4528 Deinitialize success
Unsure of whether it was malware related, I cleaned up resources with Tuneup Utilities, while I sought an alternate opinion of viral analysis from HouseCall.
Meanwhile, Malwarebytes was returning negative scans for any high profile threats. This, in stark contrast to diminishing system performance, and responsiveness. HouseCall however, found no offending threats.
Convinced a hijacker was nevertheless aboard, and simply evading detection, I downloaded the latest TDSSKiller,which unearthed a rootkit. Despite efforts to disinfect, it was back this evening, in a return engagement, which consequently has returned me to your doorstep, seeking a rat trap.
23:51:02.0046 5320 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
23:51:02.0984 5320 ============================================================
23:51:02.0984 5320 Current date / time: 2012/11/23 23:51:02.0984
23:51:02.0984 5320 SystemInfo:
23:51:02.0984 5320
23:51:02.0984 5320 OS Version: 5.1.2600 ServicePack: 3.0
23:51:02.0984 5320 Product type: Workstation
23:51:02.0984 5320 ComputerName: ENDLESS
23:51:02.0984 5320 UserName: Master Blaster
23:51:02.0984 5320 Windows directory: C:\WINDOWS
23:51:02.0984 5320 System windows directory: C:\WINDOWS
23:51:02.0984 5320 Processor architecture: Intel x86
23:51:02.0984 5320 Number of processors: 2
23:51:02.0984 5320 Page size: 0x1000
23:51:02.0984 5320 Boot type: Normal boot
23:51:02.0984 5320 ============================================================
23:51:04.0593 5320 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:51:04.0609 5320 Drive \Device\Harddisk1\DR1 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
23:51:04.0656 5320 ============================================================
23:51:04.0656 5320 \Device\Harddisk0\DR0:
23:51:04.0656 5320 MBR partitions:
23:51:04.0656 5320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xFFFAC05
23:51:04.0656 5320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFFFAC44, BlocksNum 0x4754A6BD
23:51:04.0656 5320 \Device\Harddisk1\DR1:
23:51:04.0656 5320 MBR partitions:
23:51:04.0656 5320 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
23:51:04.0656 5320 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x12A14C00, BlocksNum 0x12A18AC1
23:51:04.0656 5320 ============================================================
23:51:04.0687 5320 C: <-> \Device\Harddisk0\DR0\Partition1
23:51:04.0843 5320 E: <-> \Device\Harddisk1\DR1\Partition1
23:51:05.0078 5320 F: <-> \Device\Harddisk1\DR1\Partition2
23:51:05.0484 5320 G: <-> \Device\Harddisk0\DR0\Partition2
23:51:05.0484 5320 ============================================================
23:51:05.0484 5320 Initialize success
23:51:05.0484 5320 ============================================================
23:51:08.0843 4220 ============================================================
23:51:08.0843 4220 Scan started
23:51:08.0843 4220 Mode: Manual;
23:51:08.0843 4220 ============================================================
23:51:11.0890 4220 ================ Scan system memory ========================
23:51:11.0906 4220 System memory - ok
23:51:11.0906 4220 ================ Scan services =============================
23:51:12.0015 4220 Abiosdsk - ok
23:51:12.0031 4220 abp480n5 - ok
23:51:12.0078 4220 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:51:12.0093 4220 ACPI - ok
23:51:12.0125 4220 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
23:51:12.0125 4220 ACPIEC - ok
23:51:12.0203 4220 [ 0CB0AA071C7B86A64F361DCFDF357329 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
23:51:12.0218 4220 AdobeFlashPlayerUpdateSvc - ok
23:51:12.0234 4220 adpu160m - ok
23:51:12.0296 4220 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
23:51:12.0296 4220 aec - ok
23:51:12.0343 4220 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
23:51:12.0359 4220 AFD - ok
23:51:12.0359 4220 Aha154x - ok
23:51:12.0375 4220 aic78u2 - ok
23:51:12.0375 4220 aic78xx - ok
23:51:13.0125 4220 [ B9B98E08EC127900025F42462D3D0A66 ] Akamai c:\program files\common files\akamai/netsession_win_ce5ba24.dll
23:51:13.0125 4220 Suspicious file (Hidden): c:\program files\common files\akamai/netsession_win_ce5ba24.dll. md5: B9B98E08EC127900025F42462D3D0A66
23:51:13.0140 4220 Akamai ( HiddenFile.Multi.Generic ) - warning
23:51:13.0140 4220 Akamai - detected HiddenFile.Multi.Generic (1)
23:51:13.0156 4220 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
23:51:13.0187 4220 Alerter - ok
23:51:13.0203 4220 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
23:51:13.0203 4220 ALG - ok
23:51:13.0203 4220 AliIde - ok
23:51:13.0203 4220 amsint - ok
23:51:13.0218 4220 ANC - ok
23:51:13.0250 4220 [ 1BF91F352D746AD7469FA71783B5FAE8 ] APLMp50 C:\WINDOWS\system32\Drivers\APLMp50.sys
23:51:13.0250 4220 APLMp50 - ok
23:51:13.0328 4220 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
23:51:13.0343 4220 Apple Mobile Device - ok
23:51:13.0375 4220 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
23:51:13.0390 4220 AppMgmt - ok
23:51:13.0390 4220 asc - ok
23:51:13.0406 4220 asc3350p - ok
23:51:13.0406 4220 asc3550 - ok
23:51:13.0406 4220 ashampoodefragservice - ok
23:51:13.0500 4220 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
23:51:13.0500 4220 aspnet_state - ok
23:51:13.0546 4220 [ 0C83FC56707BF68DB04947052A8188B1 ] ASTSRV C:\WINDOWS\system32\ASTSRV.EXE
23:51:13.0546 4220 ASTSRV - ok
23:51:13.0578 4220 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:51:13.0578 4220 AsyncMac - ok
23:51:13.0593 4220 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
23:51:13.0593 4220 atapi - ok
23:51:13.0593 4220 Atdisk - ok
23:51:13.0687 4220 [ D80A3FD3DB6F999F6D1C6D23A293851B ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
23:51:13.0750 4220 Ati HotKey Poller - ok
23:51:14.0468 4220 [ C832BF76F003999D2E91E5115583C69E ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
23:51:15.0203 4220 ati2mtag - ok
23:51:15.0250 4220 [ 0D6B8359677D05142B624F09C28D643A ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdXP3.sys
23:51:15.0250 4220 AtiHDAudioService - ok
23:51:15.0265 4220 atinevxx - ok
23:51:15.0281 4220 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:51:15.0281 4220 Atmarpc - ok
23:51:15.0312 4220 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
23:51:15.0312 4220 AudioSrv - ok
23:51:15.0343 4220 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
23:51:15.0359 4220 audstub - ok
23:51:15.0375 4220 bc_pat_f - ok
23:51:15.0390 4220 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
23:51:15.0390 4220 Beep - ok
23:51:15.0468 4220 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
23:51:15.0515 4220 Bonjour Service - ok
23:51:15.0562 4220 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
23:51:15.0578 4220 Browser - ok
23:51:15.0687 4220 catchme - ok
23:51:15.0718 4220 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
23:51:15.0718 4220 cbidf2k - ok
23:51:15.0734 4220 ccproxy - ok
23:51:15.0734 4220 cd20xrnt - ok
23:51:15.0750 4220 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
23:51:15.0750 4220 Cdaudio - ok
23:51:15.0781 4220 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
23:51:15.0781 4220 Cdfs - ok
23:51:15.0828 4220 [ 4B0A100EAF5C49EF3CCA8C641431EACC ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:51:15.0828 4220 Cdrom - ok
23:51:15.0828 4220 Changer - ok
23:51:15.0843 4220 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] cisvc C:\WINDOWS\system32\cisvc.exe
23:51:15.0843 4220 cisvc - ok
23:51:15.0859 4220 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
23:51:15.0859 4220 ClipSrv - ok
23:51:15.0890 4220 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
23:51:15.0906 4220 clr_optimization_v2.0.50727_32 - ok
23:51:15.0984 4220 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
23:51:16.0000 4220 clr_optimization_v4.0.30319_32 - ok
23:51:16.0000 4220 CmdIde - ok
23:51:16.0000 4220 COMSysApp - ok
23:51:16.0015 4220 Cpqarray - ok
23:51:16.0031 4220 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
23:51:16.0046 4220 CryptSvc - ok
23:51:16.0046 4220 ctdvda2k - ok
23:51:16.0046 4220 ctxcpubal - ok
23:51:16.0046 4220 dac2w2k - ok
23:51:16.0062 4220 dac960nt - ok
23:51:16.0125 4220 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
23:51:16.0250 4220 DcomLaunch - ok
23:51:16.0281 4220 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
23:51:16.0281 4220 Dhcp - ok
23:51:16.0312 4220 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
23:51:16.0312 4220 Disk - ok
23:51:16.0312 4220 dmadmin - ok
23:51:16.0406 4220 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
23:51:16.0515 4220 dmboot - ok
23:51:16.0546 4220 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
23:51:16.0562 4220 dmio - ok
23:51:16.0578 4220 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
23:51:16.0578 4220 dmload - ok
23:51:16.0593 4220 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
23:51:16.0593 4220 dmserver - ok
23:51:16.0625 4220 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
23:51:16.0640 4220 DMusic - ok
23:51:16.0656 4220 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
23:51:16.0656 4220 Dnscache - ok
23:51:16.0687 4220 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
23:51:16.0703 4220 Dot3svc - ok
23:51:16.0718 4220 dpti2o - ok
23:51:16.0750 4220 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
23:51:16.0750 4220 drmkaud - ok
23:51:16.0765 4220 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
23:51:16.0781 4220 EapHost - ok
23:51:16.0781 4220 ENTECH - ok
23:51:16.0796 4220 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
23:51:16.0796 4220 ERSvc - ok
23:51:16.0828 4220 [ EADA995E71211537FB3726C700AF6FAC ] EUBAKUP C:\WINDOWS\system32\drivers\eubakup.sys
23:51:16.0828 4220 EUBAKUP - ok
23:51:16.0859 4220 [ 37ABA51F85518FC381CEFC8D76F2E2C4 ] EuDisk C:\WINDOWS\system32\DRIVERS\EuDisk.sys
23:51:16.0875 4220 EuDisk - ok
23:51:16.0875 4220 [ CB41E20CE4A32584EA592F07F5DA12C5 ] EUDSKACS C:\WINDOWS\system32\drivers\eudskacs.sys
23:51:16.0875 4220 EUDSKACS - ok
23:51:16.0890 4220 [ A08E9E711CD7661D7C3F19EE638102C2 ] EUFS C:\WINDOWS\system32\drivers\eufs.sys
23:51:16.0890 4220 EUFS - ok
23:51:16.0937 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
23:51:16.0937 4220 Eventlog - ok
23:51:17.0000 4220 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
23:51:17.0015 4220 EventSystem - ok
23:51:17.0046 4220 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
23:51:17.0093 4220 Fastfat - ok
23:51:17.0109 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
23:51:17.0125 4220 FastUserSwitchingCompatibility - ok
23:51:17.0125 4220 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
23:51:17.0140 4220 Fdc - ok
23:51:17.0156 4220 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
23:51:17.0156 4220 Fips - ok
23:51:17.0171 4220 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:51:17.0171 4220 Flpydisk - ok
23:51:17.0203 4220 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
23:51:17.0203 4220 FltMgr - ok
23:51:17.0265 4220 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
23:51:17.0265 4220 FontCache3.0.0.0 - ok
23:51:17.0296 4220 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:51:17.0296 4220 Fs_Rec - ok
23:51:17.0312 4220 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:51:17.0328 4220 Ftdisk - ok
23:51:17.0328 4220 G400DH - ok
23:51:17.0328 4220 GMSIPCI - ok
23:51:17.0343 4220 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:51:17.0343 4220 Gpc - ok
23:51:17.0437 4220 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
23:51:17.0453 4220 gupdate - ok
23:51:17.0468 4220 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
23:51:17.0468 4220 gupdatem - ok
23:51:17.0515 4220 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
23:51:17.0546 4220 HDAudBus - ok
23:51:17.0578 4220 helpsvc - ok
23:51:17.0609 4220 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
23:51:17.0609 4220 HidServ - ok
23:51:17.0640 4220 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:51:17.0640 4220 HidUsb - ok
23:51:17.0671 4220 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
23:51:17.0687 4220 hkmsvc - ok
23:51:17.0687 4220 hpn - ok
23:51:17.0687 4220 hpqwmiex - ok
23:51:17.0687 4220 hpt3xx - ok
23:51:17.0734 4220 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
23:51:17.0765 4220 HTTP - ok
23:51:17.0796 4220 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
23:51:17.0890 4220 HTTPFilter - ok
23:51:17.0890 4220 i2omgmt - ok
23:51:17.0906 4220 i2omp - ok
23:51:17.0906 4220 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:51:17.0921 4220 i8042prt - ok
23:51:18.0031 4220 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
23:51:18.0156 4220 idsvc - ok
23:51:18.0171 4220 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
23:51:18.0171 4220 Imapi - ok
23:51:18.0218 4220 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
23:51:18.0234 4220 ImapiService - ok
23:51:18.0234 4220 ini910u - ok
23:51:18.0250 4220 IntelIde - ok
23:51:18.0296 4220 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:51:18.0296 4220 intelppm - ok
23:51:18.0312 4220 [ 3BB22519A194418D5FEC05D800A19AD0 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
23:51:18.0312 4220 ip6fw - ok
23:51:18.0328 4220 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:51:18.0328 4220 IpFilterDriver - ok
23:51:18.0328 4220 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:51:18.0328 4220 IpInIp - ok
23:51:18.0359 4220 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:51:18.0375 4220 IpNat - ok
23:51:18.0390 4220 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:51:18.0390 4220 IPSec - ok
23:51:18.0406 4220 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
23:51:18.0406 4220 IRENUM - ok
23:51:18.0421 4220 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:51:18.0421 4220 isapnp - ok
23:51:18.0546 4220 [ A12175F063302CD68F8FC6D572D7E5FD ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
23:51:18.0562 4220 JavaQuickStarterService - ok
23:51:18.0562 4220 k750mgmt - ok
23:51:18.0593 4220 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:51:18.0593 4220 Kbdclass - ok
23:51:18.0609 4220 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
23:51:18.0609 4220 kbdhid - ok
23:51:18.0640 4220 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
23:51:18.0656 4220 kmixer - ok
23:51:18.0671 4220 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
23:51:18.0687 4220 KSecDD - ok
23:51:18.0718 4220 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
23:51:18.0734 4220 lanmanserver - ok
23:51:18.0781 4220 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
23:51:18.0812 4220 lanmanworkstation - ok
23:51:18.0828 4220 [ BE2DC24D403643A2D1D98F33C7087B38 ] LBeepKE C:\WINDOWS\system32\Drivers\LBeepKE.sys
23:51:18.0843 4220 LBeepKE - ok
23:51:18.0843 4220 lbrtfdc - ok
23:51:18.0953 4220 [ 910344E2A984010435AE84783B25E5EB ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
23:51:18.0984 4220 LBTServ - ok
23:51:19.0015 4220 [ 717E6714BCA808F2A372E636AFF3D15A ] LEqdUsb C:\WINDOWS\system32\Drivers\LEqdUsb.Sys
23:51:19.0015 4220 LEqdUsb - ok
23:51:19.0046 4220 [ 2786F7B4003ADFF88CE28BC1800B5407 ] LHidEqd C:\WINDOWS\system32\Drivers\LHidEqd.Sys
23:51:19.0046 4220 LHidEqd - ok
23:51:19.0078 4220 [ 01CC7FB6E790EF044B411377F3A1FF41 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
23:51:19.0093 4220 LHidFilt - ok
23:51:19.0125 4220 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
23:51:19.0125 4220 LmHosts - ok
23:51:19.0140 4220 [ A2E7EAE8898D7B4B8C302B8F4E836BB5 ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
23:51:19.0140 4220 LMouFilt - ok
23:51:19.0156 4220 ltmodem5 - ok
23:51:19.0156 4220 lvpopflt - ok
23:51:19.0156 4220 lxcf_device - ok
23:51:19.0187 4220 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
23:51:19.0187 4220 MBAMProtector - ok
23:51:19.0265 4220 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
23:51:19.0328 4220 MBAMScheduler - ok
23:51:19.0437 4220 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
23:51:19.0515 4220 MBAMService - ok
23:51:19.0562 4220 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
23:51:19.0562 4220 Messenger - ok
23:51:19.0578 4220 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
23:51:19.0578 4220 mnmdd - ok
23:51:19.0609 4220 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
23:51:19.0609 4220 mnmsrvc - ok
23:51:19.0625 4220 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
23:51:19.0625 4220 Modem - ok
23:51:19.0671 4220 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:51:19.0671 4220 Mouclass - ok
23:51:19.0687 4220 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:51:19.0687 4220 mouhid - ok
23:51:19.0734 4220 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
23:51:19.0734 4220 MountMgr - ok
23:51:19.0781 4220 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
23:51:19.0796 4220 MozillaMaintenance - ok
23:51:19.0796 4220 mraid35x - ok
23:51:19.0828 4220 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:51:19.0843 4220 MRxDAV - ok
23:51:19.0921 4220 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:51:19.0968 4220 MRxSmb - ok
23:51:20.0000 4220 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\System32\msdtc.exe
23:51:20.0015 4220 MSDTC - ok
23:51:20.0015 4220 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
23:51:20.0015 4220 Msfs - ok
23:51:20.0031 4220 MSIServer - ok
23:51:20.0062 4220 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:51:20.0078 4220 MSKSSRV - ok
23:51:20.0078 4220 MSMQ - ok
23:51:20.0109 4220 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:51:20.0109 4220 MSPCLOCK - ok
23:51:20.0140 4220 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
23:51:20.0140 4220 MSPQM - ok
23:51:20.0156 4220 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:51:20.0156 4220 mssmbios - ok
23:51:20.0187 4220 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
23:51:20.0203 4220 Mup - ok
23:51:20.0265 4220 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
23:51:20.0296 4220 napagent - ok
23:51:20.0328 4220 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
23:51:20.0343 4220 NDIS - ok
23:51:20.0390 4220 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:51:20.0390 4220 NdisTapi - ok
23:51:20.0406 4220 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:51:20.0406 4220 Ndisuio - ok
23:51:20.0437 4220 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:51:20.0437 4220 NdisWan - ok
23:51:20.0453 4220 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
23:51:20.0468 4220 NDProxy - ok
23:51:20.0484 4220 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
23:51:20.0484 4220 NetBIOS - ok
23:51:20.0515 4220 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
23:51:20.0546 4220 NetBT - ok
23:51:20.0578 4220 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
23:51:20.0593 4220 NetDDE - ok
23:51:20.0609 4220 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
23:51:20.0609 4220 NetDDEdsdm - ok
23:51:20.0640 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
23:51:20.0640 4220 Netlogon - ok
23:51:20.0671 4220 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
23:51:20.0687 4220 Netman - ok
23:51:20.0734 4220 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
23:51:20.0750 4220 NetTcpPortSharing - ok
23:51:20.0781 4220 [ 13EC0B1767DBFBC3A6C89EECB0B84F34 ] networx C:\WINDOWS\system32\drivers\networx.sys
23:51:20.0781 4220 networx - ok
23:51:20.0828 4220 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
23:51:20.0843 4220 Nla - ok
23:51:20.0890 4220 [ B9730495E0CF674680121E34BD95A73B ] NPF C:\WINDOWS\system32\drivers\npf.sys
23:51:20.0890 4220 NPF - ok
23:51:20.0906 4220 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
23:51:20.0906 4220 Npfs - ok
23:51:20.0968 4220 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
23:51:21.0015 4220 Ntfs - ok
23:51:21.0015 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
23:51:21.0015 4220 NtLmSsp - ok
23:51:21.0078 4220 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
23:51:21.0156 4220 NtmsSvc - ok
23:51:21.0203 4220 [ CF7E041663119E09D2E118521ADA9300 ] NuidFltr C:\WINDOWS\system32\DRIVERS\NuidFltr.sys
23:51:21.0203 4220 NuidFltr - ok
23:51:21.0218 4220 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
23:51:21.0218 4220 Null - ok
23:51:21.0250 4220 [ 7D275ECDA4628318912F6C945D5CF963 ] NVENETFD C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
23:51:21.0250 4220 NVENETFD - ok
23:51:21.0328 4220 [ B64AACEFAD2BE5BFF5353FE681253C67 ] nvnetbus C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
23:51:21.0328 4220 nvnetbus - ok
23:51:21.0375 4220 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:51:21.0375 4220 NwlnkFlt - ok
23:51:21.0390 4220 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:51:21.0390 4220 NwlnkFwd - ok
23:51:21.0390 4220 ofcpfwsvc - ok
23:51:21.0406 4220 ovt519 - ok
23:51:21.0421 4220 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
23:51:21.0437 4220 Parport - ok
23:51:21.0437 4220 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
23:51:21.0437 4220 PartMgr - ok
23:51:21.0468 4220 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
23:51:21.0468 4220 ParVdm - ok
23:51:21.0468 4220 pav_security - ok
23:51:21.0515 4220 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
23:51:21.0531 4220 PCI - ok
23:51:21.0531 4220 PCIDump - ok
23:51:21.0562 4220 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
23:51:21.0578 4220 PCIIde - ok
23:51:21.0593 4220 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
23:51:21.0609 4220 Pcmcia - ok
23:51:21.0609 4220 PDCOMP - ok
23:51:21.0609 4220 PDFRAME - ok
23:51:21.0625 4220 pdlnatdl - ok
23:51:21.0625 4220 PDRELI - ok
23:51:21.0625 4220 PDRFRAME - ok
23:51:21.0640 4220 perc2 - ok
23:51:21.0640 4220 perc2hib - ok
23:51:21.0671 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
23:51:21.0671 4220 PlugPlay - ok
23:51:21.0671 4220 pneclo - ok
23:51:21.0718 4220 [ E5582E43E167CF367757D81E9727DA2A ] Point32 C:\WINDOWS\system32\DRIVERS\point32.sys
23:51:21.0718 4220 Point32 - ok
23:51:21.0718 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
23:51:21.0718 4220 PolicyAgent - ok
23:51:21.0750 4220 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:51:21.0750 4220 PptpMiniport - ok
23:51:21.0750 4220 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
23:51:21.0765 4220 Processor - ok
23:51:21.0765 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
23:51:21.0765 4220 ProtectedStorage - ok
23:51:21.0765 4220 protectionservice - ok
23:51:21.0781 4220 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
23:51:21.0796 4220 PSched - ok
23:51:21.0796 4220 PSSdk21 - ok
23:51:21.0812 4220 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:51:21.0812 4220 Ptilink - ok
23:51:21.0828 4220 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
23:51:21.0843 4220 PxHelp20 - ok
23:51:21.0843 4220 ql1080 - ok
23:51:21.0843 4220 Ql10wnt - ok
23:51:21.0843 4220 ql12160 - ok
23:51:21.0859 4220 ql1240 - ok
23:51:21.0875 4220 ql1280 - ok
23:51:21.0890 4220 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:51:21.0890 4220 RasAcd - ok
23:51:21.0921 4220 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
23:51:21.0937 4220 RasAuto - ok
23:51:21.0953 4220 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:51:21.0953 4220 Rasl2tp - ok
23:51:22.0015 4220 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
23:51:22.0031 4220 RasMan - ok
23:51:22.0046 4220 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:51:22.0046 4220 RasPppoe - ok
23:51:22.0046 4220 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
23:51:22.0046 4220 Raspti - ok
23:51:22.0078 4220 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:51:22.0093 4220 Rdbss - ok
23:51:22.0093 4220 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:51:22.0093 4220 RDPCDD - ok
23:51:22.0125 4220 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
23:51:22.0156 4220 rdpdr - ok
23:51:22.0187 4220 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
23:51:22.0203 4220 RDPWD - ok
23:51:22.0265 4220 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
23:51:22.0281 4220 RDSessMgr - ok
23:51:22.0312 4220 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
23:51:22.0312 4220 redbook - ok
23:51:22.0359 4220 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
23:51:22.0359 4220 RemoteAccess - ok
23:51:22.0375 4220 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
23:51:22.0390 4220 RemoteRegistry - ok
23:51:22.0390 4220 rismxdp - ok
23:51:22.0453 4220 [ A780D3EAA74582EA1DEB6BD9C7A3D9C9 ] rpcapd C:\Program Files\WinPcap\rpcapd.exe
23:51:22.0468 4220 rpcapd - ok
23:51:22.0484 4220 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\System32\locator.exe
23:51:22.0484 4220 RpcLocator - ok
23:51:22.0546 4220 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
23:51:22.0546 4220 RpcSs - ok
23:51:22.0593 4220 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\System32\rsvp.exe
23:51:22.0609 4220 RSVP - ok
23:51:22.0609 4220 s116obex - ok
23:51:22.0656 4220 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
23:51:22.0656 4220 SamSs - ok
23:51:22.0718 4220 [ A3281AEC37E0720A2BC28034C2DF2A56 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
23:51:22.0718 4220 SASDIFSV - ok
23:51:22.0734 4220 [ 61DB0D0756A99506207FD724E3692B25 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
23:51:22.0734 4220 SASKUTIL - ok
23:51:22.0765 4220 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
23:51:22.0781 4220 SCardSvr - ok
23:51:22.0812 4220 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
23:51:22.0843 4220 Schedule - ok
23:51:22.0859 4220 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:51:22.0875 4220 Secdrv - ok
23:51:22.0906 4220 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
23:51:22.0906 4220 seclogon - ok
23:51:22.0937 4220 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
23:51:22.0953 4220 SENS - ok
23:51:22.0953 4220 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
23:51:22.0953 4220 serenum - ok
23:51:22.0984 4220 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
23:51:22.0984 4220 Serial - ok
23:51:23.0000 4220 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
23:51:23.0000 4220 Sfloppy - ok
23:51:23.0031 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
23:51:23.0031 4220 ShellHWDetection - ok
23:51:23.0046 4220 Simbad - ok
23:51:23.0046 4220 Sparrow - ok
23:51:23.0078 4220 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
23:51:23.0078 4220 splitter - ok
23:51:23.0109 4220 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
23:51:23.0109 4220 Spooler - ok
23:51:23.0125 4220 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
23:51:23.0125 4220 sr - ok
23:51:23.0171 4220 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
23:51:23.0187 4220 srservice - ok
23:51:23.0296 4220 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
23:51:23.0328 4220 Srv - ok
23:51:23.0359 4220 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
23:51:23.0359 4220 SSDPSRV - ok
23:51:23.0531 4220 [ 61536F3D6BA7CE09025D60B3398A8260 ] STHDA C:\WINDOWS\system32\drivers\sthda.sys
23:51:23.0718 4220 STHDA - ok
23:51:23.0765 4220 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
23:51:23.0812 4220 stisvc - ok
23:51:23.0812 4220 StkASSrv - ok
23:51:23.0812 4220 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
23:51:23.0812 4220 swenum - ok
23:51:23.0828 4220 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
23:51:23.0843 4220 swmidi - ok
23:51:23.0843 4220 SwPrv - ok
23:51:23.0843 4220 symc810 - ok
23:51:23.0859 4220 symc8xx - ok
23:51:23.0859 4220 sym_hi - ok
23:51:23.0875 4220 sym_u3 - ok
23:51:23.0906 4220 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
23:51:23.0906 4220 sysaudio - ok
23:51:23.0921 4220 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
23:51:23.0937 4220 SysmonLog - ok
23:51:23.0984 4220 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
23:51:24.0000 4220 TapiSrv - ok
23:51:24.0046 4220 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:51:24.0093 4220 Tcpip - ok
23:51:24.0140 4220 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
23:51:24.0140 4220 TDPIPE - ok
23:51:24.0171 4220 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
23:51:24.0171 4220 TDTCP - ok
23:51:24.0203 4220 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
23:51:24.0203 4220 TermDD - ok
23:51:24.0250 4220 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
23:51:24.0281 4220 TermService - ok
23:51:24.0328 4220 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
23:51:24.0328 4220 Themes - ok
23:51:24.0328 4220 TIEHDUSB - ok
23:51:24.0359 4220 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
23:51:24.0359 4220 TlntSvr - ok
23:51:24.0375 4220 tng-dtmg - ok
23:51:24.0375 4220 tng-dts - ok
23:51:24.0375 4220 TosIde - ok
23:51:24.0421 4220 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
23:51:24.0437 4220 TrkWks - ok
23:51:24.0500 4220 [ 6A29CD69D1128BDF49A705BEFC614A5B ] TuneUp.Defrag C:\WINDOWS\System32\TuneUpDefragService.exe
23:51:24.0531 4220 TuneUp.Defrag - ok
23:51:24.0609 4220 [ 51EE2913ED525DE18FDA96DCCBC5386A ] TuneUp.ProgramStatisticsSvc C:\WINDOWS\System32\TUProgSt.exe
23:51:24.0703 4220 TuneUp.ProgramStatisticsSvc - ok
23:51:24.0718 4220 [ E6D35F3AA51A65EB35C1F2340154A25E ] ubsvve C:\WINDOWS\system32\drivers\tnloa.sys
23:51:24.0718 4220 ubsvve - ok
23:51:24.0734 4220 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
23:51:24.0750 4220 Udfs - ok
23:51:24.0750 4220 ultra - ok
23:51:24.0750 4220 UPATC - ok
23:51:24.0828 4220 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
23:51:24.0859 4220 Update - ok
23:51:24.0890 4220 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
23:51:24.0906 4220 upnphost - ok
23:51:24.0921 4220 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
23:51:24.0921 4220 UPS - ok
23:51:24.0968 4220 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
23:51:24.0968 4220 usbaudio - ok
23:51:25.0000 4220 [ 9419FAAC6552A51542DBBA02971C841C ] usbbus C:\WINDOWS\system32\DRIVERS\lgusbbus.sys
23:51:25.0000 4220 usbbus - ok
23:51:25.0031 4220 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:51:25.0031 4220 usbccgp - ok
23:51:25.0046 4220 [ C0A466FA4FFEC464320E159BC1BBDC0C ] UsbDiag C:\WINDOWS\system32\DRIVERS\lgusbdiag.sys
23:51:25.0046 4220 UsbDiag - ok
23:51:25.0078 4220 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:51:25.0078 4220 usbehci - ok
23:51:25.0109 4220 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:51:25.0125 4220 usbhub - ok
23:51:25.0140 4220 [ F74A54774A9B0AFEB3C40ADEC68AA600 ] USBModem C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys
23:51:25.0140 4220 USBModem - ok
23:51:25.0171 4220 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
23:51:25.0171 4220 usbohci - ok
23:51:25.0203 4220 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:51:25.0203 4220 usbprint - ok
23:51:25.0234 4220 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:51:25.0250 4220 usbscan - ok
23:51:25.0250 4220 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:51:25.0265 4220 USBSTOR - ok
23:51:25.0281 4220 [ 2E2E93041C8058BC7DE6F0D743C4A0C6 ] UxTuneUp C:\WINDOWS\System32\uxtuneup.dll
23:51:25.0296 4220 UxTuneUp - ok
23:51:25.0296 4220 vet-filt - ok
23:51:25.0312 4220 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
23:51:25.0312 4220 VgaSave - ok
23:51:25.0312 4220 ViaIde - ok
23:51:25.0359 4220 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
23:51:25.0359 4220 VolSnap - ok
23:51:25.0406 4220 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
23:51:25.0421 4220 VSS - ok
23:51:25.0437 4220 vstor2-ws60 - ok
23:51:25.0500 4220 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
23:51:25.0515 4220 W32Time - ok
23:51:25.0546 4220 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:51:25.0546 4220 Wanarp - ok
23:51:25.0625 4220 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
23:51:25.0671 4220 Wdf01000 - ok
23:51:25.0671 4220 WDICA - ok
23:51:25.0703 4220 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
23:51:25.0718 4220 wdmaud - ok
23:51:25.0734 4220 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
23:51:25.0750 4220 WebClient - ok
23:51:25.0796 4220 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
23:51:25.0812 4220 winmgmt - ok
23:51:25.0843 4220 [ FD600B032E741EB6AAB509FC630F7C42 ] WinUSB C:\WINDOWS\system32\DRIVERS\WinUSB.sys
23:51:25.0859 4220 WinUSB - ok
23:51:25.0875 4220 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
23:51:25.0890 4220 WmdmPmSN - ok
23:51:25.0953 4220 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
23:51:26.0015 4220 Wmi - ok
23:51:26.0015 4220 [ C42584FD66CE9E17403AEBCA199F7BDB ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
23:51:26.0015 4220 WmiAcpi - ok
23:51:26.0046 4220 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
23:51:26.0062 4220 WmiApSrv - ok
23:51:26.0234 4220 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
23:51:26.0359 4220 WMPNetworkSvc - ok
23:51:26.0406 4220 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
23:51:26.0406 4220 WpdUsb - ok
23:51:26.0593 4220 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
23:51:26.0671 4220 WPFFontCache_v0400 - ok
23:51:26.0687 4220 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
23:51:26.0703 4220 WS2IFSL - ok
23:51:26.0734 4220 [ EAA6324F51214D2F6718977EC9CE0DEF ] WudfPf C:\WINDOWS\system32\DRIVERS\WUDFPF.SYS
23:51:26.0734 4220 WudfPf - ok
23:51:26.0765 4220 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
23:51:26.0765 4220 WudfRd - ok
23:51:26.0812 4220 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
23:51:26.0828 4220 WudfSvc - ok
23:51:26.0828 4220 wwsecsvc - ok
23:51:26.0890 4220 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
23:51:26.0937 4220 WZCSVC - ok
23:51:26.0984 4220 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
23:51:27.0000 4220 xmlprov - ok
23:51:27.0015 4220 zumbus - ok
23:51:27.0015 4220 ================ Scan global ===============================
23:51:27.0046 4220 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
23:51:27.0109 4220 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
23:51:27.0187 4220 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
23:51:27.0218 4220 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
23:51:27.0234 4220 [Global] - ok
23:51:27.0234 4220 ================ Scan MBR ==================================
23:51:27.0234 4220 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
23:51:27.0234 4220 Suspicious mbr (Forged): \Device\Harddisk0\DR0
23:51:27.0265 4220 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
23:51:27.0265 4220 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
23:51:27.0281 4220 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
23:51:27.0656 4220 \Device\Harddisk1\DR1 - ok
23:51:27.0656 4220 ================ Scan VBR ==================================
23:51:27.0656 4220 [ 69EED2EF33A11298E239910E24E272B3 ] \Device\Harddisk0\DR0\Partition1
23:51:27.0656 4220 \Device\Harddisk0\DR0\Partition1 - ok
23:51:27.0671 4220 [ A49216FCA2A788E234F8FE99B972065F ] \Device\Harddisk0\DR0\Partition2
23:51:27.0671 4220 \Device\Harddisk0\DR0\Partition2 - ok
23:51:27.0671 4220 [ A0E19D7F186228B02D332DF17C82E035 ] \Device\Harddisk1\DR1\Partition1
23:51:27.0671 4220 \Device\Harddisk1\DR1\Partition1 - ok
23:51:27.0687 4220 [ 88DB4795C5F45EB4FDB0663D0381F632 ] \Device\Harddisk1\DR1\Partition2
23:51:27.0703 4220 \Device\Harddisk1\DR1\Partition2 - ok
23:51:27.0703 4220 ============================================================
23:51:27.0703 4220 Scan finished
23:51:27.0703 4220 ============================================================
23:51:27.0703 3492 Detected object count: 2
23:51:27.0703 3492 Actual detected object count: 2
23:53:38.0953 3492 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
23:53:38.0953 3492 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
23:53:39.0515 3492 \Device\Harddisk0\DR0\# - copied to quarantine
23:53:39.0515 3492 \Device\Harddisk0\DR0 - copied to quarantine
23:53:41.0453 3492 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
23:53:41.0468 3492 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
23:53:41.0468 3492 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
23:53:41.0484 3492 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
23:53:41.0546 3492 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
23:53:41.0578 3492 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
23:53:41.0578 3492 \Device\Harddisk0\DR0 - ok
23:53:42.0718 3492 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
23:53:49.0187 4528 Deinitialize success