This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tidserv Problems [Solved]

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Norton Antivirus detected Backdoor.Tidserv out of the blue. I was just surfing the net, checking facebook and whatnot and didn't download anything to my knowledge. Now when I am using the internet it seems kinda slow. Also it is always re-routing me to a few different unknown search engines or pages that I have to try and navigate to get back to my correct page. It's really annoying, but I fear worse things are going on behind the scenes. I am computer literate enough to know that a blue screen is no bueno. I've had a blue screen pop up a few times, but usually my computer will restart normally. A couple times I had to run it in Safe Mode and then restart it. I just want this thing out of my PC. I know you guys are geniuses because I've looked through the forums and seen the many successes. Please help me out! I went ahead an did the DDS thing and here is the log: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 16:53:18.61 on Sat 01/07/2012 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3325.1904 [GMT -6:00] . AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202} FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\mobsync.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\philblow\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.ask.com/?l=dis&o=102868&gct=hp uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll uRun: [Google Update] "c:\users\philblow\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Spotify] "c:\users\philblow\downloads\Spotify Installer.exe" /uri spotify:autostart uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [CarboniteSetupLite] "c:\program files\carbonite\CarbonitePreinstaller.exe" /preinstalled /showonfirst /reshowat=900 mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {38E51477-DDB4-4aed-9D61-D0C193E10749} - {38E51477-DDB4-4aed-9D61-D0C193E10749} - c:\program files\soundtaxi\YouTubeRipper.dll LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab . ================= FIREFOX =================== . FF - ProfilePath - c:\users\philblow\appdata\roaming\mozilla\firefox\profiles\da8bqo0h.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - about:home FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z133&form=ZGAADF&install_date=20110927&q= FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\coffplgn\components\coFFPlgn.dll FF - component: c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.1.0.32\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\users\philblow\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll . ============= SERVICES / DRIVERS =============== . R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-5-26 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-5-26 744568] R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111223.001\BHDrvx86.sys [2011-11-30 820344] R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20120106.002\IDSvix86.sys [2012-1-6 368248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-5-26 136312] R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0501000.01d\symtdiv.sys [2011-5-26 331384] R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-29 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-31 652872] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-5-26 130008] R2 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\oracle.exe xe –> c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE [?] R2 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\bin\TNSLSNR.EXE [2006-2-2 204800] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-11-9 106104] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-31 20464] R3 SndTAudio;SndTAudio;c:\windows\system32\drivers\SndTAudio.sys [2010-12-26 23608] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 GSService;GSService;c:\windows\system32\GSService.exe [2010-12-26 385024] S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632] S3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [2010-12-26 245760] S3 STSService;STSService;c:\program files\soundtaxi media suite\STSService.exe [2010-12-4 385024] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\extjob.exe xe –> c:\oraclexe\app\oracle\product\10.2.0\server\bin\extjob.exe XE [?] . =============== Created Last 30 ================ . 2012-01-01 01:45:55 ——– d—–w- c:\users\philblow\appdata\roaming\Malwarebytes 2012-01-01 01:45:47 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-01 01:45:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-01-01 01:45:47 ——– d—–w- c:\progra~2\Malwarebytes 2011-12-15 17:42:58 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-12-15 17:42:58 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-12-15 17:42:56 429056 —-a-w- c:\windows\system32\EncDec.dll 2011-12-15 17:42:54 2043904 —-a-w- c:\windows\system32\win32k.sys 2011-12-15 17:42:53 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2011-12-15 17:42:51 49152 —-a-w- c:\windows\system32\csrsrv.dll 2011-12-15 17:42:49 2048 —-a-w- c:\windows\system32\tzres.dll . ==================== Find3M ==================== . 2011-11-03 22:47:42 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- c:\windows\system32\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 16:53:32.59 ===============
Hi Levijudah,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hello NoodleTech! Thank you so much for answering me! It is very much appreciated! I've done what you requested and the logs are below, also the MBR.dat is attached. Thank you again so much! I want this thing gone! aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-08 22:57:46 —————————– 22:57:46.887 OS Version: Windows 6.0.6002 Service Pack 2 22:57:46.887 Number of processors: 2 586 0x1706 22:57:46.889 ComputerName: PHILBLOW-PC UserName: philblow 22:57:47.341 Initialize success 22:57:56.374 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 22:57:56.377 Disk 0 Vendor: ST3250310AS 3.ADA Size: 238418MB BusType: 3 22:57:56.381 Disk 0 MBR read successfully 22:57:56.383 Disk 0 MBR scan 22:57:56.385 Disk 0 Windows VISTA default MBR code 22:57:56.387 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63 22:57:56.398 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238362 MB offset 112640 22:57:56.403 Disk 0 scanning sectors +488278016 22:57:56.459 Disk 0 scanning C:\Windows\system32\drivers 22:58:01.429 Service scanning 22:58:02.660 Modules scanning 22:58:05.289 Module: C:\Windows\system32\drivers\afd.sys **SUSPICIOUS** 22:58:09.149 Disk 0 trace - called modules: 22:58:09.175 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86e55ea0]<< 22:58:09.178 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85bcbac8] 22:58:09.181 3 CLASSPNP.SYS[8afab8b3] -> nt!IofCallDriver -> [0x86d92500] 22:58:09.184 \Driver\00001364[0x86048f38] -> IRP_MJ_CREATE -> 0x86e55ea0 22:58:09.187 Scan finished successfully 22:58:16.650 Disk 0 MBR has been saved successfully to "C:\Users\philblow\Desktop\MBR.dat" 22:58:16.655 The log file has been saved successfully to "C:\Users\philblow\Desktop\aswMBR.txt" TDSSKILLER Log: 22:58:55.0103 5760 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 22:58:55.0956 5760 ============================================================ 22:58:55.0956 5760 Current date / time: 2012/01/08 22:58:55.0956 22:58:55.0956 5760 SystemInfo: 22:58:55.0956 5760 22:58:55.0956 5760 OS Version: 6.0.6002 ServicePack: 2.0 22:58:55.0956 5760 Product type: Workstation 22:58:55.0956 5760 ComputerName: PHILBLOW-PC 22:58:55.0956 5760 UserName: philblow 22:58:55.0956 5760 Windows directory: C:\Windows 22:58:55.0956 5760 System windows directory: C:\Windows 22:58:55.0956 5760 Processor architecture: Intel x86 22:58:55.0956 5760 Number of processors: 2 22:58:55.0956 5760 Page size: 0x1000 22:58:55.0956 5760 Boot type: Normal boot 22:58:55.0957 5760 ============================================================ 22:58:57.0498 5760 Initialize success 22:58:59.0812 3408 ============================================================ 22:58:59.0812 3408 Scan started 22:58:59.0812 3408 Mode: Manual; 22:58:59.0812 3408 ============================================================ 22:59:00.0936 3408 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 22:59:00.0939 3408 ACPI - ok 22:59:00.0998 3408 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 22:59:01.0004 3408 adp94xx - ok 22:59:01.0019 3408 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 22:59:01.0023 3408 adpahci - ok 22:59:01.0043 3408 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 22:59:01.0044 3408 adpu160m - ok 22:59:01.0069 3408 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 22:59:01.0071 3408 adpu320 - ok 22:59:01.0178 3408 AFD (da1730b56d7c22a89f2854f687ed9042) C:\Windows\system32\drivers\afd.sys 22:59:01.0181 3408 AFD - ok 22:59:01.0235 3408 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 22:59:01.0236 3408 agp440 - ok 22:59:01.0274 3408 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 22:59:01.0275 3408 aic78xx - ok 22:59:01.0301 3408 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 22:59:01.0302 3408 aliide - ok 22:59:01.0460 3408 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 22:59:01.0461 3408 amdagp - ok 22:59:01.0525 3408 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 22:59:01.0526 3408 amdide - ok 22:59:01.0590 3408 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 22:59:01.0590 3408 AmdK7 - ok 22:59:01.0637 3408 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 22:59:01.0637 3408 AmdK8 - ok 22:59:01.0698 3408 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 22:59:01.0699 3408 arc - ok 22:59:01.0755 3408 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 22:59:01.0756 3408 arcsas - ok 22:59:01.0826 3408 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 22:59:01.0826 3408 AsyncMac - ok 22:59:01.0867 3408 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 22:59:01.0867 3408 atapi - ok 22:59:02.0015 3408 atikmdag (18f4c1c503f1cdd39ad006aa54b79ea8) C:\Windows\system32\DRIVERS\atikmdag.sys 22:59:02.0183 3408 atikmdag - ok 22:59:02.0282 3408 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 22:59:02.0288 3408 BCM43XV - ok 22:59:02.0334 3408 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 22:59:02.0335 3408 Beep - ok 22:59:02.0485 3408 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111223.001\BHDrvx86.sys 22:59:02.0519 3408 BHDrvx86 - ok 22:59:02.0616 3408 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 22:59:02.0617 3408 blbdrive - ok 22:59:02.0695 3408 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 22:59:02.0697 3408 bowser - ok 22:59:02.0746 3408 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 22:59:02.0746 3408 BrFiltLo - ok 22:59:02.0763 3408 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 22:59:02.0764 3408 BrFiltUp - ok 22:59:02.0794 3408 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 22:59:02.0794 3408 Brserid - ok 22:59:02.0823 3408 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 22:59:02.0824 3408 BrSerWdm - ok 22:59:02.0847 3408 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 22:59:02.0848 3408 BrUsbMdm - ok 22:59:02.0868 3408 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 22:59:02.0868 3408 BrUsbSer - ok 22:59:02.0908 3408 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 22:59:02.0909 3408 BTHMODEM - ok 22:59:02.0952 3408 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 22:59:02.0953 3408 cdfs - ok 22:59:02.0981 3408 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 22:59:02.0982 3408 cdrom - ok 22:59:03.0016 3408 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 22:59:03.0017 3408 circlass - ok 22:59:03.0056 3408 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 22:59:03.0061 3408 CLFS - ok 22:59:03.0119 3408 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 22:59:03.0119 3408 cmdide - ok 22:59:03.0138 3408 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 22:59:03.0139 3408 Compbatt - ok 22:59:03.0168 3408 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 22:59:03.0169 3408 crcdisk - ok 22:59:03.0194 3408 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 22:59:03.0195 3408 Crusoe - ok 22:59:03.0237 3408 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 22:59:03.0237 3408 DfsC - ok 22:59:03.0437 3408 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 22:59:03.0437 3408 disk - ok 22:59:03.0506 3408 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 22:59:03.0506 3408 drmkaud - ok 22:59:03.0556 3408 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 22:59:03.0562 3408 DXGKrnl - ok 22:59:03.0599 3408 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys 22:59:03.0602 3408 e1express - ok 22:59:03.0640 3408 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 22:59:03.0641 3408 E1G60 - ok 22:59:03.0706 3408 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 22:59:03.0708 3408 Ecache - ok 22:59:03.0777 3408 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 22:59:03.0782 3408 eeCtrl - ok 22:59:03.0893 3408 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 22:59:03.0897 3408 elxstor - ok 22:59:03.0964 3408 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 22:59:03.0966 3408 EraserUtilRebootDrv - ok 22:59:04.0030 3408 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 22:59:04.0030 3408 ErrDev - ok 22:59:04.0094 3408 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 22:59:04.0095 3408 exfat - ok 22:59:04.0129 3408 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 22:59:04.0130 3408 fastfat - ok 22:59:04.0180 3408 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 22:59:04.0181 3408 fdc - ok 22:59:04.0199 3408 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 22:59:04.0200 3408 FileInfo - ok 22:59:04.0227 3408 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 22:59:04.0227 3408 Filetrace - ok 22:59:04.0264 3408 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 22:59:04.0264 3408 flpydisk - ok 22:59:04.0315 3408 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 22:59:04.0317 3408 FltMgr - ok 22:59:04.0368 3408 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 22:59:04.0368 3408 Fs_Rec - ok 22:59:04.0396 3408 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 22:59:04.0397 3408 gagp30kx - ok 22:59:04.0426 3408 GEARAspiWDM (5ae3a887ece5bbb72cfab273c2fd1cfa) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 22:59:04.0427 3408 GEARAspiWDM - ok 22:59:04.0474 3408 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 22:59:04.0477 3408 HdAudAddService - ok 22:59:04.0508 3408 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 22:59:04.0516 3408 HDAudBus - ok 22:59:04.0556 3408 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 22:59:04.0557 3408 HidBth - ok 22:59:04.0577 3408 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 22:59:04.0578 3408 HidIr - ok 22:59:04.0620 3408 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 22:59:04.0621 3408 HidUsb - ok 22:59:04.0647 3408 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 22:59:04.0648 3408 HpCISSs - ok 22:59:04.0684 3408 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 22:59:04.0688 3408 HTTP - ok 22:59:04.0716 3408 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 22:59:04.0717 3408 i2omp - ok 22:59:04.0769 3408 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 22:59:04.0770 3408 i8042prt - ok 22:59:04.0798 3408 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 22:59:04.0801 3408 iaStorV - ok 22:59:04.0988 3408 IDSVix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120106.002\IDSvix86.sys 22:59:04.0993 3408 IDSVix86 - ok 22:59:05.0058 3408 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 22:59:05.0059 3408 iirsp - ok 22:59:05.0172 3408 IntcAzAudAddService (f8f53c5449f15b23d4c61d51d2701da8) C:\Windows\system32\drivers\RTKVHDA.sys 22:59:05.0230 3408 IntcAzAudAddService - ok 22:59:05.0311 3408 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 22:59:05.0311 3408 intelide - ok 22:59:05.0348 3408 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 22:59:05.0348 3408 intelppm - ok 22:59:05.0377 3408 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:59:05.0378 3408 IpFilterDriver - ok 22:59:05.0387 3408 IpInIp - ok 22:59:05.0410 3408 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 22:59:05.0411 3408 IPMIDRV - ok 22:59:05.0436 3408 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 22:59:05.0437 3408 IPNAT - ok 22:59:05.0484 3408 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 22:59:05.0485 3408 IRENUM - ok 22:59:05.0508 3408 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 22:59:05.0508 3408 isapnp - ok 22:59:05.0550 3408 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 22:59:05.0552 3408 iScsiPrt - ok 22:59:05.0587 3408 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 22:59:05.0588 3408 iteatapi - ok 22:59:05.0609 3408 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 22:59:05.0610 3408 iteraid - ok 22:59:05.0627 3408 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 22:59:05.0627 3408 kbdclass - ok 22:59:05.0652 3408 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 22:59:05.0653 3408 kbdhid - ok 22:59:05.0689 3408 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 22:59:05.0695 3408 KSecDD - ok 22:59:05.0731 3408 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 22:59:05.0732 3408 lltdio - ok 22:59:05.0761 3408 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 22:59:05.0762 3408 LSI_FC - ok 22:59:05.0780 3408 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 22:59:05.0781 3408 LSI_SAS - ok 22:59:05.0813 3408 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 22:59:05.0814 3408 LSI_SCSI - ok 22:59:05.0839 3408 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 22:59:05.0840 3408 luafv - ok 22:59:05.0881 3408 ManyCam (c6d085c7045200143528136a43a65fde) C:\Windows\system32\DRIVERS\ManyCam.sys 22:59:05.0882 3408 ManyCam - ok 22:59:05.0916 3408 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys 22:59:05.0917 3408 MBAMProtector - ok 22:59:05.0947 3408 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 22:59:05.0947 3408 megasas - ok 22:59:05.0978 3408 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 22:59:05.0982 3408 MegaSR - ok 22:59:06.0013 3408 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 22:59:06.0014 3408 Modem - ok 22:59:06.0030 3408 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 22:59:06.0031 3408 monitor - ok 22:59:06.0041 3408 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 22:59:06.0042 3408 mouclass - ok 22:59:06.0071 3408 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 22:59:06.0071 3408 mouhid - ok 22:59:06.0091 3408 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 22:59:06.0092 3408 MountMgr - ok 22:59:06.0125 3408 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 22:59:06.0127 3408 mpio - ok 22:59:06.0154 3408 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 22:59:06.0155 3408 mpsdrv - ok 22:59:06.0169 3408 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 22:59:06.0170 3408 Mraid35x - ok 22:59:06.0202 3408 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 22:59:06.0203 3408 MRxDAV - ok 22:59:06.0237 3408 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 22:59:06.0238 3408 mrxsmb - ok 22:59:06.0273 3408 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:59:06.0276 3408 mrxsmb10 - ok 22:59:06.0285 3408 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:59:06.0286 3408 mrxsmb20 - ok 22:59:06.0316 3408 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 22:59:06.0316 3408 msahci - ok 22:59:06.0344 3408 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 22:59:06.0345 3408 msdsm - ok 22:59:06.0389 3408 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 22:59:06.0389 3408 Msfs - ok 22:59:06.0415 3408 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 22:59:06.0415 3408 msisadrv - ok 22:59:06.0440 3408 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 22:59:06.0440 3408 MSKSSRV - ok 22:59:06.0480 3408 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 22:59:06.0481 3408 MSPCLOCK - ok 22:59:06.0521 3408 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 22:59:06.0521 3408 MSPQM - ok 22:59:06.0553 3408 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 22:59:06.0555 3408 MsRPC - ok 22:59:06.0582 3408 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 22:59:06.0582 3408 mssmbios - ok 22:59:06.0605 3408 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 22:59:06.0606 3408 MSTEE - ok 22:59:06.0635 3408 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 22:59:06.0635 3408 Mup - ok 22:59:06.0714 3408 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 22:59:06.0716 3408 NativeWifiP - ok 22:59:06.0853 3408 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120108.006\NAVENG.SYS 22:59:06.0855 3408 NAVENG - ok 22:59:06.0936 3408 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120108.006\NAVEX15.SYS 22:59:06.0995 3408 NAVEX15 - ok 22:59:07.0084 3408 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 22:59:07.0090 3408 NDIS - ok 22:59:07.0149 3408 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 22:59:07.0150 3408 NdisTapi - ok 22:59:07.0176 3408 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 22:59:07.0177 3408 Ndisuio - ok 22:59:07.0216 3408 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 22:59:07.0217 3408 NdisWan - ok 22:59:07.0251 3408 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 22:59:07.0251 3408 NDProxy - ok 22:59:07.0265 3408 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 22:59:07.0266 3408 NetBIOS - ok 22:59:07.0292 3408 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 22:59:07.0294 3408 netbt - ok 22:59:07.0357 3408 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 22:59:07.0358 3408 nfrd960 - ok 22:59:07.0407 3408 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 22:59:07.0408 3408 Npfs - ok 22:59:07.0426 3408 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 22:59:07.0427 3408 nsiproxy - ok 22:59:07.0457 3408 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 22:59:07.0498 3408 Ntfs - ok 22:59:07.0523 3408 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 22:59:07.0524 3408 ntrigdigi - ok 22:59:07.0531 3408 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 22:59:07.0532 3408 Null - ok 22:59:07.0555 3408 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 22:59:07.0556 3408 nvraid - ok 22:59:07.0582 3408 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 22:59:07.0582 3408 nvstor - ok 22:59:07.0605 3408 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 22:59:07.0606 3408 nv_agp - ok 22:59:07.0618 3408 NwlnkFlt - ok 22:59:07.0628 3408 NwlnkFwd - ok 22:59:07.0677 3408 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 22:59:07.0677 3408 ohci1394 - ok 22:59:07.0686 3408 OMCI - ok 22:59:07.0719 3408 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 22:59:07.0719 3408 Parport - ok 22:59:07.0742 3408 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 22:59:07.0744 3408 partmgr - ok 22:59:07.0760 3408 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 22:59:07.0760 3408 Parvdm - ok 22:59:07.0796 3408 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 22:59:07.0799 3408 pci - ok 22:59:07.0859 3408 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 22:59:07.0859 3408 pciide - ok 22:59:07.0931 3408 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 22:59:07.0933 3408 pcmcia - ok 22:59:07.0993 3408 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 22:59:08.0025 3408 PEAUTH - ok 22:59:08.0071 3408 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 22:59:08.0072 3408 PptpMiniport - ok 22:59:08.0105 3408 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 22:59:08.0106 3408 Processor - ok 22:59:08.0160 3408 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 22:59:08.0161 3408 PSched - ok 22:59:08.0213 3408 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys 22:59:08.0214 3408 PxHelp20 - ok 22:59:08.0289 3408 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 22:59:08.0307 3408 ql2300 - ok 22:59:08.0343 3408 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 22:59:08.0344 3408 ql40xx - ok 22:59:08.0387 3408 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 22:59:08.0388 3408 QWAVEdrv - ok 22:59:08.0425 3408 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 22:59:08.0425 3408 RasAcd - ok 22:59:08.0445 3408 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 22:59:08.0446 3408 Rasl2tp - ok 22:59:08.0648 3408 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 22:59:08.0649 3408 RasPppoe - ok 22:59:08.0683 3408 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 22:59:08.0683 3408 RasSstp - ok 22:59:08.0702 3408 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 22:59:08.0706 3408 rdbss - ok 22:59:08.0732 3408 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 22:59:08.0733 3408 RDPCDD - ok 22:59:08.0759 3408 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 22:59:08.0762 3408 rdpdr - ok 22:59:08.0770 3408 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 22:59:08.0771 3408 RDPENCDD - ok 22:59:08.0814 3408 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 22:59:08.0817 3408 RDPWD - ok 22:59:08.0853 3408 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 22:59:08.0854 3408 rspndr - ok 22:59:08.0900 3408 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 22:59:08.0901 3408 sbp2port - ok 22:59:08.0941 3408 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 22:59:08.0941 3408 secdrv - ok 22:59:08.0968 3408 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 22:59:08.0969 3408 Serenum - ok 22:59:08.0987 3408 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 22:59:08.0987 3408 Serial - ok 22:59:09.0024 3408 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 22:59:09.0025 3408 sermouse - ok 22:59:09.0048 3408 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 22:59:09.0048 3408 sffdisk - ok 22:59:09.0074 3408 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 22:59:09.0074 3408 sffp_mmc - ok 22:59:09.0096 3408 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 22:59:09.0097 3408 sffp_sd - ok 22:59:09.0120 3408 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 22:59:09.0121 3408 sfloppy - ok 22:59:09.0148 3408 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 22:59:09.0149 3408 sisagp - ok 22:59:09.0162 3408 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 22:59:09.0163 3408 SiSRaid2 - ok 22:59:09.0189 3408 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 22:59:09.0190 3408 SiSRaid4 - ok 22:59:09.0234 3408 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 22:59:09.0235 3408 Smb - ok 22:59:09.0295 3408 SndTAudio (6b6cb09bbe72d408cec9ec9d448463dc) C:\Windows\system32\drivers\SndTAudio.sys 22:59:09.0296 3408 SndTAudio - ok 22:59:09.0340 3408 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 22:59:09.0340 3408 spldr - ok 22:59:09.0451 3408 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS 22:59:09.0458 3408 SRTSP - ok 22:59:09.0512 3408 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS 22:59:09.0513 3408 SRTSPX - ok 22:59:09.0559 3408 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 22:59:09.0562 3408 srv - ok 22:59:09.0601 3408 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 22:59:09.0603 3408 srv2 - ok 22:59:09.0611 3408 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 22:59:09.0612 3408 srvnet - ok 22:59:09.0655 3408 sscdbus (d5dffeaa1e15d4effabb9d9a3068ac5b) C:\Windows\system32\DRIVERS\sscdbus.sys 22:59:09.0656 3408 sscdbus - ok 22:59:09.0756 3408 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 22:59:09.0757 3408 swenum - ok 22:59:09.0790 3408 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 22:59:09.0790 3408 Symc8xx - ok 22:59:09.0875 3408 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS 22:59:09.0880 3408 SymDS - ok 22:59:09.0955 3408 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS 22:59:09.0965 3408 SymEFA - ok 22:59:09.0989 3408 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 22:59:09.0991 3408 SymEvent - ok 22:59:10.0016 3408 SymIM (8d49cdbb93c3e58e1bfc39fb29444c0a) C:\Windows\system32\DRIVERS\SymIMv.sys 22:59:10.0017 3408 SymIM - ok 22:59:10.0070 3408 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS 22:59:10.0073 3408 SymIRON - ok 22:59:10.0140 3408 SYMTDIv (5136f99a60ddbdeb1f6fd1eefc44407f) C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS 22:59:10.0144 3408 SYMTDIv - ok 22:59:10.0175 3408 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 22:59:10.0176 3408 Sym_hi - ok 22:59:10.0201 3408 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 22:59:10.0202 3408 Sym_u3 - ok 22:59:10.0265 3408 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 22:59:10.0283 3408 Tcpip - ok 22:59:10.0323 3408 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 22:59:10.0328 3408 Tcpip6 - ok 22:59:10.0361 3408 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 22:59:10.0361 3408 tcpipreg - ok 22:59:10.0385 3408 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 22:59:10.0386 3408 TDPIPE - ok 22:59:10.0413 3408 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 22:59:10.0414 3408 TDTCP - ok 22:59:10.0443 3408 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 22:59:10.0444 3408 tdx - ok 22:59:10.0472 3408 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 22:59:10.0473 3408 TermDD - ok 22:59:10.0509 3408 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 22:59:10.0510 3408 tssecsrv - ok 22:59:10.0531 3408 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 22:59:10.0531 3408 tunmp - ok 22:59:10.0554 3408 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 22:59:10.0555 3408 tunnel - ok 22:59:10.0580 3408 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 22:59:10.0581 3408 uagp35 - ok 22:59:10.0610 3408 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 22:59:10.0613 3408 udfs - ok 22:59:10.0644 3408 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 22:59:10.0645 3408 uliagpkx - ok 22:59:10.0667 3408 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 22:59:10.0670 3408 uliahci - ok 22:59:10.0688 3408 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 22:59:10.0689 3408 UlSata - ok 22:59:10.0716 3408 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 22:59:10.0717 3408 ulsata2 - ok 22:59:10.0740 3408 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 22:59:10.0740 3408 umbus - ok 22:59:10.0799 3408 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys 22:59:10.0800 3408 USBAAPL - ok 22:59:10.0836 3408 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 22:59:10.0837 3408 usbccgp - ok 22:59:10.0863 3408 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 22:59:10.0864 3408 usbcir - ok 22:59:10.0902 3408 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 22:59:10.0903 3408 usbehci - ok 22:59:10.0917 3408 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 22:59:10.0920 3408 usbhub - ok 22:59:10.0957 3408 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 22:59:10.0957 3408 usbohci - ok 22:59:10.0994 3408 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 22:59:10.0995 3408 usbprint - ok 22:59:11.0023 3408 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 22:59:11.0024 3408 usbscan - ok 22:59:11.0048 3408 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:59:11.0049 3408 USBSTOR - ok 22:59:11.0076 3408 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 22:59:11.0076 3408 usbuhci - ok 22:59:11.0108 3408 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 22:59:11.0108 3408 vga - ok 22:59:11.0119 3408 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 22:59:11.0119 3408 VgaSave - ok 22:59:11.0138 3408 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 22:59:11.0139 3408 viaagp - ok 22:59:11.0159 3408 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 22:59:11.0160 3408 ViaC7 - ok 22:59:11.0189 3408 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 22:59:11.0190 3408 viaide - ok 22:59:11.0198 3408 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 22:59:11.0199 3408 volmgr - ok 22:59:11.0246 3408 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 22:59:11.0249 3408 volmgrx - ok 22:59:11.0314 3408 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 22:59:11.0316 3408 volsnap - ok 22:59:11.0339 3408 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 22:59:11.0340 3408 vsmraid - ok 22:59:11.0371 3408 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 22:59:11.0371 3408 WacomPen - ok 22:59:11.0592 3408 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 22:59:11.0593 3408 Wanarp - ok 22:59:11.0597 3408 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 22:59:11.0598 3408 Wanarpv6 - ok 22:59:11.0626 3408 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 22:59:11.0627 3408 Wd - ok 22:59:11.0665 3408 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 22:59:11.0672 3408 Wdf01000 - ok 22:59:11.0750 3408 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 22:59:11.0750 3408 WmiAcpi - ok 22:59:11.0811 3408 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 22:59:11.0812 3408 WpdUsb - ok 22:59:11.0850 3408 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 22:59:11.0851 3408 ws2ifsl - ok 22:59:11.0892 3408 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 22:59:11.0893 3408 WUDFRd - ok 22:59:11.0952 3408 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 22:59:12.0002 3408 \Device\Harddisk0\DR0 - ok 22:59:12.0006 3408 Boot (0x1200) (e9f8a3b89b4cd7f2f6ff9569eabf705a) \Device\Harddisk0\DR0\Partition0 22:59:12.0006 3408 \Device\Harddisk0\DR0\Partition0 - ok 22:59:12.0007 3408 ============================================================ 22:59:12.0007 3408 Scan finished 22:59:12.0007 3408 ============================================================ 22:59:12.0015 5312 Detected object count: 0 22:59:12.0015 5312 Actual detected object count: 0 22:59:23.0452 5188 ============================================================ 22:59:23.0452 5188 Scan started 22:59:23.0452 5188 Mode: Manual; 22:59:23.0452 5188 ============================================================ 22:59:24.0391 5188 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys 22:59:24.0393 5188 ACPI - ok 22:59:24.0436 5188 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys 22:59:24.0439 5188 adp94xx - ok 22:59:24.0533 5188 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys 22:59:24.0534 5188 adpahci - ok 22:59:24.0557 5188 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys 22:59:24.0558 5188 adpu160m - ok 22:59:24.0591 5188 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys 22:59:24.0592 5188 adpu320 - ok 22:59:24.0633 5188 AFD (da1730b56d7c22a89f2854f687ed9042) C:\Windows\system32\drivers\afd.sys 22:59:24.0635 5188 AFD - ok 22:59:24.0665 5188 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys 22:59:24.0666 5188 agp440 - ok 22:59:24.0687 5188 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys 22:59:24.0688 5188 aic78xx - ok 22:59:24.0715 5188 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys 22:59:24.0715 5188 aliide - ok 22:59:24.0741 5188 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys 22:59:24.0741 5188 amdagp - ok 22:59:24.0764 5188 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys 22:59:24.0764 5188 amdide - ok 22:59:24.0787 5188 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys 22:59:24.0787 5188 AmdK7 - ok 22:59:24.0809 5188 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys 22:59:24.0809 5188 AmdK8 - ok 22:59:24.0829 5188 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys 22:59:24.0829 5188 arc - ok 22:59:24.0844 5188 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys 22:59:24.0845 5188 arcsas - ok 22:59:24.0873 5188 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys 22:59:24.0873 5188 AsyncMac - ok 22:59:24.0906 5188 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys 22:59:24.0906 5188 atapi - ok 22:59:25.0020 5188 atikmdag (18f4c1c503f1cdd39ad006aa54b79ea8) C:\Windows\system32\DRIVERS\atikmdag.sys 22:59:25.0046 5188 atikmdag - ok 22:59:25.0162 5188 BCM43XV (cf6a67c90951e3e763d2135dede44b85) C:\Windows\system32\DRIVERS\bcmwl6.sys 22:59:25.0165 5188 BCM43XV - ok 22:59:25.0190 5188 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys 22:59:25.0190 5188 Beep - ok 22:59:25.0341 5188 BHDrvx86 (e685ba3267c5a4ec4ce9e2b4a1481725) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111223.001\BHDrvx86.sys 22:59:25.0346 5188 BHDrvx86 - ok 22:59:25.0430 5188 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys 22:59:25.0431 5188 blbdrive - ok 22:59:25.0474 5188 bowser (35f376253f687bde63976ccb3f2108ca) C:\Windows\system32\DRIVERS\bowser.sys 22:59:25.0475 5188 bowser - ok 22:59:25.0502 5188 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys 22:59:25.0502 5188 BrFiltLo - ok 22:59:25.0519 5188 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys 22:59:25.0519 5188 BrFiltUp - ok 22:59:25.0541 5188 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys 22:59:25.0541 5188 Brserid - ok 22:59:25.0562 5188 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys 22:59:25.0563 5188 BrSerWdm - ok 22:59:25.0586 5188 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys 22:59:25.0587 5188 BrUsbMdm - ok 22:59:25.0606 5188 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys 22:59:25.0607 5188 BrUsbSer - ok 22:59:25.0630 5188 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys 22:59:25.0631 5188 BTHMODEM - ok 22:59:25.0649 5188 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys 22:59:25.0650 5188 cdfs - ok 22:59:25.0678 5188 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys 22:59:25.0679 5188 cdrom - ok 22:59:25.0705 5188 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys 22:59:25.0706 5188 circlass - ok 22:59:25.0745 5188 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys 22:59:25.0746 5188 CLFS - ok 22:59:25.0774 5188 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys 22:59:25.0775 5188 cmdide - ok 22:59:25.0794 5188 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\drivers\compbatt.sys 22:59:25.0794 5188 Compbatt - ok 22:59:25.0824 5188 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys 22:59:25.0824 5188 crcdisk - ok 22:59:25.0850 5188 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys 22:59:25.0850 5188 Crusoe - ok 22:59:25.0892 5188 DfsC (622c41a07ca7e6dd91770f50d532cb6c) C:\Windows\system32\Drivers\dfsc.sys 22:59:25.0893 5188 DfsC - ok 22:59:25.0916 5188 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys 22:59:25.0917 5188 disk - ok 22:59:25.0961 5188 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys 22:59:25.0962 5188 drmkaud - ok 22:59:26.0004 5188 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys 22:59:26.0008 5188 DXGKrnl - ok 22:59:26.0046 5188 e1express (908ed85b7806e8af3af5e9b74f7809d4) C:\Windows\system32\DRIVERS\e1e6032.sys 22:59:26.0048 5188 e1express - ok 22:59:26.0088 5188 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys 22:59:26.0089 5188 E1G60 - ok 22:59:26.0129 5188 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys 22:59:26.0130 5188 Ecache - ok 22:59:26.0191 5188 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 22:59:26.0194 5188 eeCtrl - ok 22:59:26.0316 5188 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys 22:59:26.0318 5188 elxstor - ok 22:59:26.0378 5188 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 22:59:26.0379 5188 EraserUtilRebootDrv - ok 22:59:26.0444 5188 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys 22:59:26.0444 5188 ErrDev - ok 22:59:26.0520 5188 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys 22:59:26.0521 5188 exfat - ok 22:59:26.0568 5188 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys 22:59:26.0569 5188 fastfat - ok 22:59:26.0644 5188 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys 22:59:26.0645 5188 fdc - ok 22:59:26.0670 5188 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys 22:59:26.0671 5188 FileInfo - ok 22:59:26.0699 5188 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys 22:59:26.0700 5188 Filetrace - ok 22:59:26.0744 5188 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys 22:59:26.0745 5188 flpydisk - ok 22:59:26.0795 5188 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys 22:59:26.0797 5188 FltMgr - ok 22:59:26.0824 5188 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys 22:59:26.0824 5188 Fs_Rec - ok 22:59:26.0860 5188 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys 22:59:26.0861 5188 gagp30kx - ok 22:59:26.0899 5188 GEARAspiWDM (5ae3a887ece5bbb72cfab273c2fd1cfa) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 22:59:26.0899 5188 GEARAspiWDM - ok 22:59:26.0938 5188 HdAudAddService (3f90e001369a07243763bd5a523d8722) C:\Windows\system32\drivers\HdAudio.sys 22:59:26.0940 5188 HdAudAddService - ok 22:59:26.0972 5188 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys 22:59:26.0975 5188 HDAudBus - ok 22:59:27.0004 5188 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys 22:59:27.0004 5188 HidBth - ok 22:59:27.0033 5188 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys 22:59:27.0034 5188 HidIr - ok 22:59:27.0067 5188 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys 22:59:27.0068 5188 HidUsb - ok 22:59:27.0094 5188 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys 22:59:27.0095 5188 HpCISSs - ok 22:59:27.0132 5188 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys 22:59:27.0134 5188 HTTP - ok 22:59:27.0164 5188 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys 22:59:27.0164 5188 i2omp - ok 22:59:27.0183 5188 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys 22:59:27.0184 5188 i8042prt - ok 22:59:27.0212 5188 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys 22:59:27.0214 5188 iaStorV - ok 22:59:27.0402 5188 IDSVix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120106.002\IDSvix86.sys 22:59:27.0404 5188 IDSVix86 - ok 22:59:27.0481 5188 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys 22:59:27.0481 5188 iirsp - ok 22:59:27.0586 5188 IntcAzAudAddService (f8f53c5449f15b23d4c61d51d2701da8) C:\Windows\system32\drivers\RTKVHDA.sys 22:59:27.0598 5188 IntcAzAudAddService - ok 22:59:27.0633 5188 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys 22:59:27.0634 5188 intelide - ok 22:59:27.0662 5188 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys 22:59:27.0662 5188 intelppm - ok 22:59:27.0708 5188 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys 22:59:27.0708 5188 IpFilterDriver - ok 22:59:27.0731 5188 IpInIp - ok 22:59:27.0766 5188 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys 22:59:27.0766 5188 IPMIDRV - ok 22:59:27.0791 5188 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys 22:59:27.0792 5188 IPNAT - ok 22:59:27.0857 5188 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys 22:59:27.0857 5188 IRENUM - ok 22:59:27.0913 5188 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys 22:59:27.0914 5188 isapnp - ok 22:59:27.0955 5188 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys 22:59:27.0956 5188 iScsiPrt - ok 22:59:27.0984 5188 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys 22:59:27.0985 5188 iteatapi - ok 22:59:28.0007 5188 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys 22:59:28.0007 5188 iteraid - ok 22:59:28.0024 5188 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys 22:59:28.0025 5188 kbdclass - ok 22:59:28.0049 5188 kbdhid (ede59ec70e25c24581add1fbec7325f7) C:\Windows\system32\DRIVERS\kbdhid.sys 22:59:28.0050 5188 kbdhid - ok 22:59:28.0118 5188 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys 22:59:28.0121 5188 KSecDD - ok 22:59:28.0161 5188 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys 22:59:28.0162 5188 lltdio - ok 22:59:28.0192 5188 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys 22:59:28.0193 5188 LSI_FC - ok 22:59:28.0211 5188 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys 22:59:28.0212 5188 LSI_SAS - ok 22:59:28.0235 5188 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys 22:59:28.0236 5188 LSI_SCSI - ok 22:59:28.0261 5188 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys 22:59:28.0262 5188 luafv - ok 22:59:28.0295 5188 ManyCam (c6d085c7045200143528136a43a65fde) C:\Windows\system32\DRIVERS\ManyCam.sys 22:59:28.0296 5188 ManyCam - ok 22:59:28.0330 5188 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\Windows\system32\drivers\mbam.sys 22:59:28.0331 5188 MBAMProtector - ok 22:59:28.0377 5188 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys 22:59:28.0378 5188 megasas - ok 22:59:28.0409 5188 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys 22:59:28.0411 5188 MegaSR - ok 22:59:28.0444 5188 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys 22:59:28.0445 5188 Modem - ok 22:59:28.0460 5188 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys 22:59:28.0461 5188 monitor - ok 22:59:28.0480 5188 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys 22:59:28.0481 5188 mouclass - ok 22:59:28.0493 5188 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys 22:59:28.0494 5188 mouhid - ok 22:59:28.0505 5188 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys 22:59:28.0506 5188 MountMgr - ok 22:59:28.0531 5188 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys 22:59:28.0532 5188 mpio - ok 22:59:28.0560 5188 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys 22:59:28.0561 5188 mpsdrv - ok 22:59:28.0583 5188 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys 22:59:28.0584 5188 Mraid35x - ok 22:59:28.0615 5188 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys 22:59:28.0616 5188 MRxDAV - ok 22:59:28.0651 5188 mrxsmb (1e94971c4b446ab2290deb71d01cf0c2) C:\Windows\system32\DRIVERS\mrxsmb.sys 22:59:28.0652 5188 mrxsmb - ok 22:59:28.0670 5188 mrxsmb10 (4fccb34d793b116423209c0f8b7a3b03) C:\Windows\system32\DRIVERS\mrxsmb10.sys 22:59:28.0671 5188 mrxsmb10 - ok 22:59:28.0687 5188 mrxsmb20 (c3cb1b40ad4a0124d617a1199b0b9d7c) C:\Windows\system32\DRIVERS\mrxsmb20.sys 22:59:28.0688 5188 mrxsmb20 - ok 22:59:28.0721 5188 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys 22:59:28.0722 5188 msahci - ok 22:59:28.0749 5188 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys 22:59:28.0750 5188 msdsm - ok 22:59:28.0778 5188 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys 22:59:28.0778 5188 Msfs - ok 22:59:28.0795 5188 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys 22:59:28.0796 5188 msisadrv - ok 22:59:28.0837 5188 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys 22:59:28.0838 5188 MSKSSRV - ok 22:59:28.0853 5188 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys 22:59:28.0853 5188 MSPCLOCK - ok 22:59:28.0876 5188 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys 22:59:28.0877 5188 MSPQM - ok 22:59:28.0909 5188 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys 22:59:28.0910 5188 MsRPC - ok 22:59:28.0937 5188 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys 22:59:28.0938 5188 mssmbios - ok 22:59:28.0953 5188 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys 22:59:28.0953 5188 MSTEE - ok 22:59:28.0965 5188 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys 22:59:28.0966 5188 Mup - ok 22:59:28.0995 5188 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys 22:59:28.0996 5188 NativeWifiP - ok 22:59:29.0125 5188 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120108.006\NAVENG.SYS 22:59:29.0126 5188 NAVENG - ok 22:59:29.0208 5188 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120108.006\NAVEX15.SYS 22:59:29.0218 5188 NAVEX15 - ok 22:59:29.0307 5188 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys 22:59:29.0310 5188 NDIS - ok 22:59:29.0347 5188 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys 22:59:29.0347 5188 NdisTapi - ok 22:59:29.0373 5188 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys 22:59:29.0374 5188 Ndisuio - ok 22:59:29.0405 5188 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys 22:59:29.0406 5188 NdisWan - ok 22:59:29.0427 5188 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys 22:59:29.0428 5188 NDProxy - ok 22:59:29.0446 5188 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys 22:59:29.0446 5188 NetBIOS - ok 22:59:29.0473 5188 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys 22:59:29.0474 5188 netbt - ok 22:59:29.0529 5188 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys 22:59:29.0530 5188 nfrd960 - ok 22:59:29.0572 5188 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys 22:59:29.0573 5188 Npfs - ok 22:59:29.0623 5188 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys 22:59:29.0624 5188 nsiproxy - ok 22:59:29.0679 5188 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys 22:59:29.0686 5188 Ntfs - ok 22:59:29.0737 5188 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys 22:59:29.0738 5188 ntrigdigi - ok 22:59:29.0771 5188 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys 22:59:29.0771 5188 Null - ok 22:59:29.0803 5188 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys 22:59:29.0804 5188 nvraid - ok 22:59:29.0819 5188 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys 22:59:29.0820 5188 nvstor - ok 22:59:29.0852 5188 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys 22:59:29.0853 5188 nv_agp - ok 22:59:29.0862 5188 NwlnkFlt - ok 22:59:29.0873 5188 NwlnkFwd - ok 22:59:29.0907 5188 ohci1394 (be32da025a0be1878f0ee8d6d9386cd5) C:\Windows\system32\drivers\ohci1394.sys 22:59:29.0908 5188 ohci1394 - ok 22:59:29.0916 5188 OMCI - ok 22:59:29.0949 5188 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys 22:59:29.0950 5188 Parport - ok 22:59:29.0972 5188 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys 22:59:29.0973 5188 partmgr - ok 22:59:29.0990 5188 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys 22:59:29.0991 5188 Parvdm - ok 22:59:30.0019 5188 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys 22:59:30.0020 5188 pci - ok 22:59:30.0031 5188 pciide (1636d43f10416aeb483bc6001097b26c) C:\Windows\system32\drivers\pciide.sys 22:59:30.0032 5188 pciide - ok 22:59:30.0070 5188 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys 22:59:30.0072 5188 pcmcia - ok 22:59:30.0107 5188 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys 22:59:30.0112 5188 PEAUTH - ok 22:59:30.0152 5188 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys 22:59:30.0153 5188 PptpMiniport - ok 22:59:30.0178 5188 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys 22:59:30.0179 5188 Processor - ok 22:59:30.0241 5188 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys 22:59:30.0242 5188 PSched - ok 22:59:30.0268 5188 PxHelp20 (03e0fe281823ba64b3782f5b38950e73) C:\Windows\system32\Drivers\PxHelp20.sys 22:59:30.0269 5188 PxHelp20 - ok 22:59:30.0353 5188 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys 22:59:30.0360 5188 ql2300 - ok 22:59:30.0390 5188 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys 22:59:30.0391 5188 ql40xx - ok 22:59:30.0460 5188 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys 22:59:30.0461 5188 QWAVEdrv - ok 22:59:30.0481 5188 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys 22:59:30.0481 5188 RasAcd - ok 22:59:30.0501 5188 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys 22:59:30.0502 5188 Rasl2tp - ok 22:59:30.0529 5188 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys 22:59:30.0530 5188 RasPppoe - ok 22:59:30.0555 5188 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys 22:59:30.0556 5188 RasSstp - ok 22:59:30.0575 5188 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys 22:59:30.0576 5188 rdbss - ok 22:59:30.0605 5188 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys 22:59:30.0605 5188 RDPCDD - ok 22:59:30.0624 5188 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys 22:59:30.0625 5188 rdpdr - ok 22:59:30.0635 5188 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys 22:59:30.0636 5188 RDPENCDD - ok 22:59:30.0670 5188 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys 22:59:30.0672 5188 RDPWD - ok 22:59:30.0709 5188 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys 22:59:30.0710 5188 rspndr - ok 22:59:30.0765 5188 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys 22:59:30.0766 5188 sbp2port - ok 22:59:30.0813 5188 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 22:59:30.0814 5188 secdrv - ok 22:59:30.0849 5188 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys 22:59:30.0850 5188 Serenum - ok 22:59:30.0893 5188 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys 22:59:30.0893 5188 Serial - ok 22:59:30.0930 5188 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys 22:59:30.0931 5188 sermouse - ok 22:59:30.0953 5188 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys 22:59:30.0954 5188 sffdisk - ok 22:59:30.0980 5188 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys 22:59:30.0980 5188 sffp_mmc - ok 22:59:31.0002 5188 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys 22:59:31.0003 5188 sffp_sd - ok 22:59:31.0026 5188 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys 22:59:31.0027 5188 sfloppy - ok 22:59:31.0054 5188 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys 22:59:31.0055 5188 sisagp - ok 22:59:31.0068 5188 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys 22:59:31.0069 5188 SiSRaid2 - ok 22:59:31.0095 5188 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys 22:59:31.0096 5188 SiSRaid4 - ok 22:59:31.0131 5188 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys 22:59:31.0132 5188 Smb - ok 22:59:31.0168 5188 SndTAudio (6b6cb09bbe72d408cec9ec9d448463dc) C:\Windows\system32\drivers\SndTAudio.sys 22:59:31.0168 5188 SndTAudio - ok 22:59:31.0204 5188 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys 22:59:31.0205 5188 spldr - ok 22:59:31.0281 5188 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS 22:59:31.0285 5188 SRTSP - ok 22:59:31.0309 5188 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS 22:59:31.0310 5188 SRTSPX - ok 22:59:31.0340 5188 srv (41987f9fc0e61adf54f581e15029ad91) C:\Windows\system32\DRIVERS\srv.sys 22:59:31.0342 5188 srv - ok 22:59:31.0374 5188 srv2 (ff33aff99564b1aa534f58868cbe41ef) C:\Windows\system32\DRIVERS\srv2.sys 22:59:31.0376 5188 srv2 - ok 22:59:31.0405 5188 srvnet (7605c0e1d01a08f3ecd743f38b834a44) C:\Windows\system32\DRIVERS\srvnet.sys 22:59:31.0407 5188 srvnet - ok 22:59:31.0436 5188 sscdbus (d5dffeaa1e15d4effabb9d9a3068ac5b) C:\Windows\system32\DRIVERS\sscdbus.sys 22:59:31.0437 5188 sscdbus - ok 22:59:31.0479 5188 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys 22:59:31.0480 5188 swenum - ok 22:59:31.0504 5188 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys 22:59:31.0505 5188 Symc8xx - ok 22:59:31.0581 5188 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS 22:59:31.0583 5188 SymDS - ok 22:59:31.0670 5188 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS 22:59:31.0674 5188 SymEFA - ok 22:59:31.0721 5188 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 22:59:31.0722 5188 SymEvent - ok 22:59:31.0764 5188 SymIM (8d49cdbb93c3e58e1bfc39fb29444c0a) C:\Windows\system32\DRIVERS\SymIMv.sys 22:59:31.0765 5188 SymIM - ok 22:59:31.0834 5188 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS 22:59:31.0835 5188 SymIRON - ok 22:59:31.0913 5188 SYMTDIv (5136f99a60ddbdeb1f6fd1eefc44407f) C:\Windows\system32\drivers\N360\0501000.01D\SYMTDIV.SYS 22:59:31.0915 5188 SYMTDIv - ok 22:59:31.0948 5188 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys 22:59:31.0949 5188 Sym_hi - ok 22:59:31.0974 5188 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys 22:59:31.0975 5188 Sym_u3 - ok 22:59:32.0038 5188 Tcpip (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\drivers\tcpip.sys 22:59:32.0043 5188 Tcpip - ok 22:59:32.0088 5188 Tcpip6 (814a1c66fbd4e1b310a517221f1456bf) C:\Windows\system32\DRIVERS\tcpip.sys 22:59:32.0093 5188 Tcpip6 - ok 22:59:32.0117 5188 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys 22:59:32.0117 5188 tcpipreg - ok 22:59:32.0141 5188 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys 22:59:32.0142 5188 TDPIPE - ok 22:59:32.0169 5188 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys 22:59:32.0170 5188 TDTCP - ok 22:59:32.0208 5188 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys 22:59:32.0209 5188 tdx - ok 22:59:32.0245 5188 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys 22:59:32.0246 5188 TermDD - ok 22:59:32.0282 5188 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys 22:59:32.0282 5188 tssecsrv - ok 22:59:32.0295 5188 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys 22:59:32.0295 5188 tunmp - ok 22:59:32.0316 5188 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys 22:59:32.0317 5188 tunnel - ok 22:59:32.0345 5188 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys 22:59:32.0346 5188 uagp35 - ok 22:59:32.0378 5188 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys 22:59:32.0380 5188 udfs - ok 22:59:32.0408 5188 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys 22:59:32.0409 5188 uliagpkx - ok 22:59:32.0431 5188 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys 22:59:32.0434 5188 uliahci - ok 22:59:32.0461 5188 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys 22:59:32.0462 5188 UlSata - ok 22:59:32.0489 5188 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys 22:59:32.0490 5188 ulsata2 - ok 22:59:32.0512 5188 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys 22:59:32.0513 5188 umbus - ok 22:59:32.0564 5188 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys 22:59:32.0564 5188 USBAAPL - ok 22:59:32.0600 5188 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys 22:59:32.0601 5188 usbccgp - ok 22:59:32.0627 5188 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys 22:59:32.0628 5188 usbcir - ok 22:59:32.0658 5188 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys 22:59:32.0659 5188 usbehci - ok 22:59:32.0673 5188 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys 22:59:32.0675 5188 usbhub - ok 22:59:32.0713 5188 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys 22:59:32.0713 5188 usbohci - ok 22:59:32.0750 5188 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys 22:59:32.0751 5188 usbprint - ok 22:59:32.0779 5188 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys 22:59:32.0780 5188 usbscan - ok 22:59:32.0804 5188 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS 22:59:32.0805 5188 USBSTOR - ok 22:59:32.0823 5188 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys 22:59:32.0824 5188 usbuhci - ok 22:59:32.0855 5188 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys 22:59:32.0856 5188 vga - ok 22:59:32.0871 5188 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys 22:59:32.0872 5188 VgaSave - ok 22:59:32.0902 5188 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys 22:59:32.0903 5188 viaagp - ok 22:59:32.0924 5188 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys 22:59:32.0925 5188 ViaC7 - ok 22:59:32.0953 5188 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys 22:59:32.0954 5188 viaide - ok 22:59:32.0963 5188 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys 22:59:32.0964 5188 volmgr - ok 22:59:33.0002 5188 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys 22:59:33.0004 5188 volmgrx - ok 22:59:33.0025 5188 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys 22:59:33.0026 5188 volsnap - ok 22:59:33.0053 5188 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys 22:59:33.0054 5188 vsmraid - ok 22:59:33.0093 5188 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys 22:59:33.0094 5188 WacomPen - ok 22:59:33.0123 5188 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 22:59:33.0124 5188 Wanarp - ok 22:59:33.0127 5188 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys 22:59:33.0128 5188 Wanarpv6 - ok 22:59:33.0157 5188 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys 22:59:33.0158 5188 Wd - ok 22:59:33.0196 5188 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys 22:59:33.0199 5188 Wdf01000 - ok 22:59:33.0264 5188 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\drivers\wmiacpi.sys 22:59:33.0265 5188 WmiAcpi - ok 22:59:33.0309 5188 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys 22:59:33.0309 5188 WpdUsb - ok 22:59:33.0356 5188 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys 22:59:33.0357 5188 ws2ifsl - ok 22:59:33.0390 5188 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys 22:59:33.0391 5188 WUDFRd - ok 22:59:33.0424 5188 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 22:59:33.0475 5188 \Device\Harddisk0\DR0 - ok 22:59:33.0478 5188 Boot (0x1200) (e9f8a3b89b4cd7f2f6ff9569eabf705a) \Device\Harddisk0\DR0\Partition0 22:59:33.0479 5188 \Device\Harddisk0\DR0\Partition0 - ok 22:59:33.0480 5188 ============================================================ 22:59:33.0480 5188 Scan finished 22:59:33.0480 5188 ============================================================ 22:59:33.0488 4996 Detected object count: 0 22:59:33.0488 4996 Actual detected object count: 0

Attachments:

Hi Levijudah,

It is my pleasure :).

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.


  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Hello, So I did exactly what you said, but now my computer won't run outside of Safe Mode….so I can't connect to the internet. Or can I? Is there a way to connect to the internet in Safe Mode? I tried Safe Mode with Networking, but it only would connect locally, not to the internet. I have the log you wanted, but there is just no way to get it to you. I am using someone elses computer to type this to you now. Please let me know what I should do. Thank you so much for your help so far, i really do appreciate it.
Hi Levijudah, Can you be more specific? What happens when you try to boot your computer up in normal mode? Can you transfer the ComboFix log over to the friend's computer by copying it to a flash drive? That would help me better understand what's going on with your computer.
Lol…they are afraid of getting the virus! I will get a USB and try to do it at a library or something. When I start normally it's ok for about a minute then it goes to a blue screen that starts off with "a problem has been detected and Windows has been shut down to prevent damage to your computer." It then goes on to talk about new hardware or software being properly installed….it ends with some stuff about memory dump…
Also it says something about the recycle bin being corrupted for C drive and asked if I want to empty it…it did that like 3 or 4 times
Hello Noodletech,

Sorry for the delay! I really hope you can help me. Below is the log you requested…thank you. Any ideas on the random corrupted recycle bin error/request to empty? :huh:


ComboFix 12-01-09.07 - philblow 01/09/2012 23:42:04.2.2 - x86 MINIMAL
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3325.2675 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-12-10 to 2012-01-10 )))))))))))))))))))))))))))))))
.
.
2012-01-10 05:44 . 2012-01-10 05:44 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-01-10 05:44 . 2012-01-10 05:44 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2012-01-10 05:18 . 2012-01-10 05:44 ——– d—–w- c:\users\philblow\AppData\Local\temp
2012-01-01 01:45 . 2012-01-01 01:45 ——– d—–w- c:\users\philblow\AppData\Roaming\Malwarebytes
2012-01-01 01:45 . 2012-01-01 01:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-01 01:45 . 2012-01-01 01:45 ——– d—–w- c:\programdata\Malwarebytes
2012-01-01 01:45 . 2011-12-10 21:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-15 17:42 . 2011-10-27 08:01 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-15 17:42 . 2011-10-27 08:01 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-12-15 17:42 . 2011-10-14 16:02 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-12-15 17:42 . 2011-11-23 13:37 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-12-15 17:42 . 2011-11-08 12:10 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-15 17:42 . 2011-10-25 15:56 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-12-15 17:42 . 2011-11-08 14:42 2048 —-a-w- c:\windows\system32\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-09 18:24 . 2011-05-09 01:13 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2011-06-16 6276408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarboniteSetupLite]
2009-08-04 07:49 318096 —-a-w- c:\program files\Carbonite\CarbonitePreinstaller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 23:06 421736 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 23:36 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808957660-3837036214-124702685-1004Core.job
- c:\users\philblow\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-27 04:07]
.
2012-01-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-808957660-3837036214-124702685-1004UA.job
- c:\users\philblow\AppData\Local\Google\Update\GoogleUpdate.exe [2010-07-27 04:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?l=dis&o;=102868&gct;=hp
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\philblow\AppData\Roaming\Mozilla\Firefox\Profiles\da8bqo0h.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z133&form;=ZGAADF&install;_date=20110927&q;=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-09 23:44
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
Completion time: 2012-01-09 23:45:05
ComboFix-quarantined-files.txt 2012-01-10 05:45
ComboFix2.txt 2012-01-10 05:18
ComboFix3.txt 2012-01-10 04:27
.
Pre-Run: 142,044,741,632 bytes free
Post-Run: 141,989,642,240 bytes free
.
- - End Of File - - 52476E1C33FF4446505902156482CC73
I do want to add that no matter how I tried…it was still saying it detected Norton…I disabled per this forums instructons, and even ended the process, but it still detected Norton…I went and ran sense I had followed the instructions to disable and I know that Norton is darn near integrated into the very being of my PC….just want to give you every bit of information I can… I hope my poor PC isn't toast…. Thanks Again!
Hi Levijudah,

Thanks for the information. No idea about the recycle bin, but it's probably related to whatever is causing your system to run haywire.

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Hello Noodletech… Here is the log you requested…hope it helps Farbar Service Scanner Ran by [removed] (administrator) on 14-01-2012 at 12:00:34 Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Nerwork **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. Windows Firewall: ============= MpsSvc Service is not running. Checking service configuration: Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking LEGACY_MpsSvc: Attention! Unable to open LEGACY_MpsSvc\0000 registry key. The key does not exist. mpsdrv Service is not running. Checking service configuration: The start type of mpsdrv service is OK. The ImagePath of mpsdrv service is OK. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=DWORD:0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=DWORD:0 System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. Checking LEGACY_SDRSVC: Attention! Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist. Windows Update: =========== wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. BITS Service is not running. Checking service configuration: The start type of BITS service is OK. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. Checking LEGACY_BITS: Attention! Unable to open LEGACY_BITS\0000 registry key. The key does not exist. EventSystem Service is not running. Checking service configuration: The start type of EventSystem service is OK. The ImagePath of EventSystem service is OK. The ServiceDll of EventSystem service is OK. File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys [2011-06-16 09:45] - [2011-04-21 07:58] - 0273408 ____A () DA1730B56D7C22A89F2854F687ED9042 C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0061440 ____A (Microsoft Corporation) 1CA6C40261DDC0425987980D0CD2AAAB C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0758784 ____A (Microsoft Corporation) 93952506C6D67330367F7E7934B6A02F C:\Windows\system32\es.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0268800 ____A (Microsoft Corporation) 67058C46504BC12D821F38CF99B7B28F C:\Windows\system32\cryptsvc.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0129024 ____A (Microsoft Corporation) FB27772BEAF8E1D28CCD825C09DA939B C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****Farbar Service Scanner Ran by [removed] (administrator) on 14-01-2012 at 12:00:34 Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Nerwork **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. Windows Firewall: ============= MpsSvc Service is not running. Checking service configuration: Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist. Checking LEGACY_MpsSvc: Attention! Unable to open LEGACY_MpsSvc\0000 registry key. The key does not exist. mpsdrv Service is not running. Checking service configuration: The start type of mpsdrv service is OK. The ImagePath of mpsdrv service is OK. Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall"=DWORD:0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "EnableFirewall"=DWORD:0 System Restore: ============ SDRSVC Service is not running. Checking service configuration: The start type of SDRSVC service is OK. The ImagePath of SDRSVC service is OK. The ServiceDll of SDRSVC service is OK. Checking LEGACY_SDRSVC: Attention! Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist. VSS Service is not running. Checking service configuration: The start type of VSS service is OK. The ImagePath of VSS service is OK. System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist. Windows Update: =========== wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is OK. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. BITS Service is not running. Checking service configuration: The start type of BITS service is OK. The ImagePath of BITS service is OK. The ServiceDll of BITS service is OK. Checking LEGACY_BITS: Attention! Unable to open LEGACY_BITS\0000 registry key. The key does not exist. EventSystem Service is not running. Checking service configuration: The start type of EventSystem service is OK. The ImagePath of EventSystem service is OK. The ServiceDll of EventSystem service is OK. File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys [2011-06-16 09:45] - [2011-04-21 07:58] - 0273408 ____A () DA1730B56D7C22A89F2854F687ED9042 C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0061440 ____A (Microsoft Corporation) 1CA6C40261DDC0425987980D0CD2AAAB C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0758784 ____A (Microsoft Corporation) 93952506C6D67330367F7E7934B6A02F C:\Windows\system32\es.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0268800 ____A (Microsoft Corporation) 67058C46504BC12D821F38CF99B7B28F C:\Windows\system32\cryptsvc.dll [2010-07-24 09:49] - [2009-04-10 22:28] - 0129024 ____A (Microsoft Corporation) FB27772BEAF8E1D28CCD825C09DA939B C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log ****

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI