I think that my comp may be infected. The Hijack this report as shown.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:01:29 AM, on 5/21/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\NetWorx\networx.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Neel\Downloads\HiJackThis.exe
C:\Windows\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1060933
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
R3 - URLSearchHook: (no name) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - (no file)
O2 - BHO: Complitly - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Users\Neel\AppData\Roaming\Complitly\Complitly.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: RoboForm BHO - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.0.0.9\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [NetWorx] "C:\Program Files\NetWorx\networx.exe" /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
O4 - HKLM\..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
O4 - HKCU\..\Run: [Google Update] "C:\Users\Neel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Neel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{983C7EA8-54AD-4AB7-8ED4-849D2436A231}: NameServer = 218.248.255.147 218.248.255.146
O17 - HKLM\System\CS1\Services\Tcpip\..\{983C7EA8-54AD-4AB7-8ED4-849D2436A231}: NameServer = 218.248.255.147 218.248.255.146
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.0.2\ViProtocol.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
O23 - Service: vToolbarUpdater11.0.2 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
–
End of file - 10287 bytes
**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days.
Hello there,
neel385
I'm
Conspire , I'll be glad to help you with your computer problems.
Please observe these rules while we work:
Read the entire procedure It is important to perform ALL actions in sequence. If you don't know, stop and ask! Don't keep going on. Please reply to this thread. Do not start a new topic. Stick with me till you're given the all clear. Remember, absence of symptoms does not mean the infection is all gone. Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
—————————————————————————————————
Can you please describe your problem in further detail?
—————————————————————————————————
By browsing speed is very slow and even when no applications seem to be running,there is unaccounted for net activity. I have carried out various virus scans which have failed to show up anything and on trying a root-kit remover, I got partial success when, it was unable to clear all root-kits. I'm attaching the report:
+—————————————————-
| Trend Micro RootkitBuster
| Module version: 5.0.0.1061
| Computer Name: NEEL-PC
| OS version: 6.1-7600
| User Name: Neel
+—————————————————-
–== Dump Hidden MBR, Hidden Files and Alternate Data Streams on C:\ ==–
MBR unsupported disk type
[FILE_STREAM]:
FullPath : C:\ProgramData\TEMP:0B4227B4:$DATA
FullPathLength: 27
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x2030
ShareAccess : 0x0
Type : 0x0
[FILE_STREAM]:
FullPath : C:\Users\All Users\TEMP:0B4227B4:$DATA
FullPathLength: 31
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x2030
ShareAccess : 0x0
Type : 0x0
[FILE_STREAM]:
FullPath : C:\Users\Neel\Downloads\drweb-cureit.exe:Zone.Identifier:$DATA
FullPathLength: 40
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
[FILE_STREAM]:
FullPath : C:\Users\Neel\Downloads\RootkitBuster_v5_1061.exe:Zone.Identifier:$DATA
FullPathLength: 49
DesiredAccess : 0x0
Options : 0x0
Attributes : 0x20
ShareAccess : 0x0
Type : 0x0
4 hidden files found.
–== Dump Hidden Registry Value on HKLM ==–
[HIDDEN_REGISTRY][Hidden Reg Key]:
KeyPath : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\523
SubKey : 523
FullLength: 90
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
Root : 70fbf94
SubKey : Parameters
ValueName : DhcpDomain
Data : home
ValueType : 1
AccessType: 0
FullLength: 69
DataSize : 10
[HIDDEN_REGISTRY][Hidden Reg Value]:
KeyPath : HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
Root : 70fbf94
SubKey : Parameters
ValueName : DhcpNameServer
Data : 192.168.0.1
ValueType : 1
AccessType: 0
FullLength: 69
DataSize : 24
3 hidden registry entries found.
–== Dump Hidden Process ==–
No hidden processes found.
–== Dump Hidden Driver ==–
No hidden drivers found.
–== Service Win32 API Hook List ==–
[HOOKED_SERVICE_API]:
Service API : ZwAdjustPrivilegesToken
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c19875
CurrentHandler : 0x8fc4cf26
ServiceNumber : 0xc
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwAlpcConnectPort
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c5f821
CurrentHandler : 0x8fc4d112
ServiceNumber : 0x16
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwConnectPort
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c84894
CurrentHandler : 0x8fc4c286
ServiceNumber : 0x3b
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateFile
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c56e82
CurrentHandler : 0x8fc4cb8c
ServiceNumber : 0x42
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateSection
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c3cce3
CurrentHandler : 0x8fc4c940
ServiceNumber : 0x54
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateSymbolicLinkObject
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c1b059
CurrentHandler : 0x8fc4dc8a
ServiceNumber : 0x56
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateThread
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82ce6c0e
CurrentHandler : 0x8fc4bc72
ServiceNumber : 0x57
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwCreateThreadEx
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c44d51
CurrentHandler : 0x8fc4d340
ServiceNumber : 0x58
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwLoadDriver
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82bad279
CurrentHandler : 0x8fc4d6bc
ServiceNumber : 0x9b
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwMakeTemporaryObject
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c13363
CurrentHandler : 0x8fc4c54e
ServiceNumber : 0xa4
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwNotifyChangeKey
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c05ce5
CurrentHandler : 0x92421004
ServiceNumber : 0xac
ModuleName : avgidsshimx.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwNotifyChangeMultipleKeys
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c0508f
CurrentHandler : 0x924210d4
ServiceNumber : 0xad
ModuleName : avgidsshimx.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenFile
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c865c4
CurrentHandler : 0x8fc4cd68
ServiceNumber : 0xb3
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenProcess
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c8d531
CurrentHandler : 0x92420d76
ServiceNumber : 0xbe
ModuleName : avgidsshimx.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwOpenSection
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c8b1ba
CurrentHandler : 0x8fc4c7e8
ServiceNumber : 0xc2
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSetSystemInformation
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c96df5
CurrentHandler : 0x8fc4d9a8
ServiceNumber : 0x15e
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwShutdownSystem
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82d0d64b
CurrentHandler : 0x8fc4c4b8
ServiceNumber : 0x168
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwSystemDebugControl
Image Path : C:\Windows\System32\DRIVERS\cmdguard.sys
OriginalHandler : 0x82c152fc
CurrentHandler : 0x8fc4c6d4
ServiceNumber : 0x170
ModuleName : cmdguard.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwTerminateProcess
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c6db3d
CurrentHandler : 0x92420e1e
ServiceNumber : 0x172
ModuleName : avgidsshimx.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwTerminateThread
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c808e4
CurrentHandler : 0x92420eba
ServiceNumber : 0x173
ModuleName : avgidsshimx.sys
SDTType : 0x0
[HOOKED_SERVICE_API]:
Service API : ZwWriteVirtualMemory
Image Path : C:\Windows\system32\DRIVERS\avgidsshimx.sys
OriginalHandler : 0x82c935b5
CurrentHandler : 0x92420f56
ServiceNumber : 0x18f
ModuleName : avgidsshimx.sys
SDTType : 0x0
No hidden operating system service hooks found.
–== Dump Hidden Port ==–
No hidden ports found.
–== Dump Kernel Code Patching ==–
No kernel code patching detected.
–== Dump Hidden Services ==–
No hidden services found.
I am in a bit of a hurry as I am re-locating and I will not be able to access the internet from the 25th of this month till about the 20th of next month.
Thanks..
Neel.
Hi Neel, I'm sorry but due to the difference in timezone, I don't think I can go through it for you as quick as I could have hoped for. This is because it usually takes more than 3 days or more depending on the nature of infection to successfully eradicate malware.
We can still carry on as much as we can. It's up to you.
Hello there,
Download
OTL to your Desktop
Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. Click on Minimal Output at the top Download the following file scan.txt to your Desktop . Click here to download it . You may need to right click on it and select "Save" Double click inside the Custom Scan box at the bottom A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel" Click the OK button and navigate to the file scan.txt which we just saved to your desktop Select scan.txt and click Open. Writing will now appear under the Custom Scan box Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt . These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
===================================================
[external image: Posted Image] Please download GMER from one of the following locations, and save it to your desktop:
Main Mirror
This version will download a randomly named file (Recommended) Zip Mirror
This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
Extract the contents of the zipped file to desktop (applicable only to Zip mirror) . Double click [external image: Posted Image] or [external image: Posted Image] on your desktop. If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO .
[external image: Posted Image]
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Uncheck the following … IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
===================================================
Download
Security Check by screen317 from
here or
here .
Save it to your Desktop. Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. A Notepad document should open automatically called checkup.txt ; please post the contents of that document.
===================================================
On your next reply please post :
OTL log
GMER log
Checkup log
Please
STOP and let me know if you have any problems in performing with the steps above or any questions you may have.
Good Day!
Did as told. Attaching the requested log files.
the OTL log is attached.
Thank you, and will try and remain online till the 27th so as to try and fix the prob.
Hi,
I would like to ask, did you perform an uninstall procedure for AVG 2011?
Also how did you install Comodo? Did you just click next all the way or specified only firewall to be installed?
I'm asking this is because I think the Comodo AV and AVG may have clashed together, so I just want to be clear that you only have Comodo act as your firewall and AVG as AV.
===================================================
You have ( µTorrent ) , a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing .
I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
If you wish to keep it, please do not use it until your computer is cleaned.
===================================================
Thanks for the prompt reply…
No I did not perform an uninstall procedure for AVG 2011…a pop up asked me to update to 2012 and I did after verifying that i was downloading the real stuff.
I do not remember as to how I installed Comodo, but my intention was to only install the Firewall. So yes, my intention is for Comodo to act as Firewall and AVG as AV.
Point about P2P is well taken. I generally keep it OFF and put it on only when I want to, but I get your point about the content. Will not use it as for now.
Thank You.
Ok, thanks.
Go to your right-hand corner, click on the Taskbar, right click on Comodo icon, go to Configurations, then see if you have Internet Security selected or Firewall Security.
Just wanted to make sure that the configuration is correct.
Only Firewall is selected.
Thanks.
Sorry I forgot to ask you to provide me the TDSS killer log. If it finds any threats.
What is the TDSS killer log?? (Sorry!)
O.K. Got it! The report is pasted below. It did not find anything.
22:56:22.0579 5672 TDSS rootkit removing tool [removed] May 23 2012 08:15:30
22:56:23.0467 5672 ============================================================
22:56:23.0467 5672 Current date / time: 2012/05/23 22:56:23.0467
22:56:23.0467 5672 SystemInfo:
22:56:23.0467 5672
22:56:23.0467 5672 OS Version: 6.1.7600 ServicePack: 0.0
22:56:23.0468 5672 Product type: Workstation
22:56:23.0468 5672 ComputerName: NEEL-PC
22:56:23.0468 5672 UserName: Neel
22:56:23.0469 5672 Windows directory: C:\Windows
22:56:23.0469 5672 System windows directory: C:\Windows
22:56:23.0469 5672 Processor architecture: Intel x86
22:56:23.0469 5672 Number of processors: 1
22:56:23.0469 5672 Page size: 0x1000
22:56:23.0469 5672 Boot type: Normal boot
22:56:23.0469 5672 ============================================================
22:56:24.0617 5672 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:56:24.0754 5672 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1D92650, SectorsPerTrack: 0x3F, TracksPerCylinder: 0x1, Type 'W'
22:56:30.0803 5672 ============================================================
22:56:30.0803 5672 \Device\Harddisk0\DR0:
22:56:30.0814 5672 MBR partitions:
22:56:30.0814 5672 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4E1EDEC
22:56:30.0834 5672 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x4E1EE6A, BlocksNum 0x23293F8
22:56:30.0849 5672 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x71482A1, BlocksNum 0x23C235F
22:56:30.0849 5672 \Device\Harddisk1\DR1:
22:56:30.0850 5672 MBR partitions:
22:56:30.0850 5672 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x747059C1
22:56:30.0850 5672 ============================================================
22:56:30.0891 5672 C: <-> \Device\Harddisk0\DR0\Partition0
22:56:30.0932 5672 D: <-> \Device\Harddisk0\DR0\Partition1
22:56:30.0969 5672 E: <-> \Device\Harddisk0\DR0\Partition2
22:56:30.0979 5672 G: <-> \Device\Harddisk1\DR1\Partition0
22:56:30.0980 5672 ============================================================
22:56:30.0980 5672 Initialize success
22:56:30.0980 5672 ============================================================
22:56:32.0978 4280 ============================================================
22:56:32.0978 4280 Scan started
22:56:32.0978 4280 Mode: Manual;
22:56:32.0978 4280 ============================================================
22:56:33.0967 4280 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
22:56:33.0982 4280 1394ohci - ok
22:56:34.0037 4280 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
22:56:34.0040 4280 ACPI - ok
22:56:34.0108 4280 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
22:56:34.0110 4280 AcpiPmi - ok
22:56:34.0249 4280 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:56:34.0252 4280 AdobeARMservice - ok
22:56:34.0354 4280 AdobeFlashPlayerUpdateSvc (0d4c486a24a711a45fd83acdf4d18506) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:56:34.0357 4280 AdobeFlashPlayerUpdateSvc - ok
22:56:34.0446 4280 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
22:56:34.0457 4280 adp94xx - ok
22:56:34.0501 4280 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
22:56:34.0514 4280 adpahci - ok
22:56:34.0578 4280 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
22:56:34.0584 4280 adpu320 - ok
22:56:34.0639 4280 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll
22:56:34.0641 4280 AeLookupSvc - ok
22:56:34.0769 4280 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys
22:56:34.0773 4280 AFD - ok
22:56:34.0824 4280 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
22:56:34.0827 4280 agp440 - ok
22:56:34.0888 4280 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
22:56:34.0891 4280 aic78xx - ok
22:56:34.0954 4280 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe
22:56:34.0957 4280 ALG - ok
22:56:34.0978 4280 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
22:56:34.0980 4280 aliide - ok
22:56:35.0033 4280 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
22:56:35.0036 4280 amdagp - ok
22:56:35.0059 4280 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
22:56:35.0061 4280 amdide - ok
22:56:35.0122 4280 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
22:56:35.0125 4280 AmdK8 - ok
22:56:35.0161 4280 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
22:56:35.0165 4280 AmdPPM - ok
22:56:35.0219 4280 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\drivers\amdsata.sys
22:56:35.0222 4280 amdsata - ok
22:56:35.0351 4280 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
22:56:35.0366 4280 amdsbs - ok
22:56:35.0397 4280 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\drivers\amdxata.sys
22:56:35.0399 4280 amdxata - ok
22:56:35.0506 4280 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
22:56:35.0509 4280 AppID - ok
22:56:35.0561 4280 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll
22:56:35.0577 4280 AppIDSvc - ok
22:56:35.0613 4280 Appinfo (7dead9e3f65dcb2794f2711003bbf650) C:\Windows\System32\appinfo.dll
22:56:35.0615 4280 Appinfo - ok
22:56:35.0678 4280 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll
22:56:35.0685 4280 AppMgmt - ok
22:56:35.0741 4280 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
22:56:35.0744 4280 arc - ok
22:56:35.0782 4280 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
22:56:35.0789 4280 arcsas - ok
22:56:35.0832 4280 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
22:56:35.0834 4280 AsyncMac - ok
22:56:35.0889 4280 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
22:56:35.0890 4280 atapi - ok
22:56:36.0065 4280 AudioEndpointBuilder (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll
22:56:36.0090 4280 AudioEndpointBuilder - ok
22:56:36.0108 4280 Audiosrv (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll
22:56:36.0114 4280 Audiosrv - ok
22:56:36.0565 4280 AVGIDSAgent (ba60fd7a64b9759a14c0fba4a9ed4c7b) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
22:56:36.0602 4280 AVGIDSAgent - ok
22:56:36.0785 4280 AVGIDSDriver (1074f787080068c71303b61fae7e7ca4) C:\Windows\system32\DRIVERS\avgidsdriverx.sys
22:56:36.0788 4280 AVGIDSDriver - ok
22:56:36.0829 4280 AVGIDSFilter (61a7e0b02f82cff3db2445bbe50b3589) C:\Windows\system32\DRIVERS\avgidsfilterx.sys
22:56:36.0832 4280 AVGIDSFilter - ok
22:56:36.0960 4280 AVGIDSHX (d63d83659eedf60b3a3e620281a888e5) C:\Windows\system32\DRIVERS\avgidshx.sys
22:56:36.0962 4280 AVGIDSHX - ok
22:56:36.0994 4280 AVGIDSShim (baf975b72062f53d327788e99d64197e) C:\Windows\system32\DRIVERS\avgidsshimx.sys
22:56:36.0996 4280 AVGIDSShim - ok
22:56:37.0036 4280 Avgldx86 (dda6a2a18841e4c9172bb85958b8d948) C:\Windows\system32\DRIVERS\avgldx86.sys
22:56:37.0039 4280 Avgldx86 - ok
22:56:37.0075 4280 Avgmfx86 (ccdd61545aaea265977e4b1efdc74e8c) C:\Windows\system32\DRIVERS\avgmfx86.sys
22:56:37.0076 4280 Avgmfx86 - ok
22:56:37.0117 4280 Avgrkx86 (1fd90b28d2c3100bf4500199c8ad6358) C:\Windows\system32\DRIVERS\avgrkx86.sys
22:56:37.0185 4280 Avgrkx86 - ok
22:56:37.0224 4280 Avgtdix (1263f2554ace925c237a40b4c568d815) C:\Windows\system32\DRIVERS\avgtdix.sys
22:56:37.0275 4280 Avgtdix - ok
22:56:37.0388 4280 avgwd (ea1145debcd508fd25bd1e95c4346929) C:\Program Files\AVG\AVG2012\avgwdsvc.exe
22:56:37.0391 4280 avgwd - ok
22:56:37.0458 4280 AxInstSV (dd6a431b43e34b91a767d1ce33728175) C:\Windows\System32\AxInstSV.dll
22:56:37.0471 4280 AxInstSV - ok
22:56:37.0557 4280 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
22:56:37.0571 4280 b06bdrv - ok
22:56:37.0630 4280 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
22:56:37.0645 4280 b57nd60x - ok
22:56:37.0707 4280 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll
22:56:37.0710 4280 BDESVC - ok
22:56:37.0767 4280 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
22:56:37.0769 4280 Beep - ok
22:56:37.0851 4280 BFE (85ac71c045ceb054ed48a7841aae0c11) C:\Windows\System32\bfe.dll
22:56:37.0873 4280 BFE - ok
22:56:37.0957 4280 BITS (53f476476f55a27f580661bde09c4ec4) C:\Windows\System32\qmgr.dll
22:56:37.0983 4280 BITS - ok
22:56:38.0036 4280 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
22:56:38.0038 4280 blbdrive - ok
22:56:38.0063 4280 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys
22:56:38.0065 4280 bowser - ok
22:56:38.0089 4280 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:56:38.0093 4280 BrFiltLo - ok
22:56:38.0150 4280 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:56:38.0154 4280 BrFiltUp - ok
22:56:38.0209 4280 Browser (598e1280e7ff3744f4b8329366cc5635) C:\Windows\System32\browser.dll
22:56:38.0223 4280 Browser - ok
22:56:38.0275 4280 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
22:56:38.0285 4280 Brserid - ok
22:56:38.0326 4280 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
22:56:38.0330 4280 BrSerWdm - ok
22:56:38.0391 4280 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
22:56:38.0394 4280 BrUsbMdm - ok
22:56:38.0414 4280 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
22:56:38.0417 4280 BrUsbSer - ok
22:56:38.0455 4280 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
22:56:38.0458 4280 BTHMODEM - ok
22:56:38.0534 4280 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll
22:56:38.0537 4280 bthserv - ok
22:56:38.0597 4280 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
22:56:38.0600 4280 cdfs - ok
22:56:38.0641 4280 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
22:56:38.0643 4280 cdrom - ok
22:56:38.0717 4280 CertPropSvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll
22:56:38.0720 4280 CertPropSvc - ok
22:56:38.0766 4280 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
22:56:38.0768 4280 circlass - ok
22:56:38.0831 4280 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
22:56:38.0834 4280 CLFS - ok
22:56:38.0998 4280 CLPSLS (be465a17fda2e79ed49053cbec7e9335) C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
22:56:39.0006 4280 CLPSLS - ok
22:56:39.0100 4280 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:56:39.0104 4280 clr_optimization_v2.0.50727_32 - ok
22:56:39.0225 4280 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
22:56:39.0227 4280 CmBatt - ok
22:56:39.0337 4280 cmdAgent (907324001ae25ac5959c91eaa34cabae) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
22:56:39.0352 4280 cmdAgent - ok
22:56:39.0507 4280 cmdGuard (ed042da80d9d6a087e83df395ceefd65) C:\Windows\system32\DRIVERS\cmdguard.sys
22:56:39.0512 4280 cmdGuard - ok
22:56:39.0525 4280 cmdHlp (ed6b6a222cb9adf6751e02ad478a89fb) C:\Windows\system32\DRIVERS\cmdhlp.sys
22:56:39.0527 4280 cmdHlp - ok
22:56:39.0557 4280 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
22:56:39.0560 4280 cmdide - ok
22:56:39.0590 4280 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
22:56:39.0594 4280 CNG - ok
22:56:39.0631 4280 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
22:56:39.0634 4280 Compbatt - ok
22:56:39.0677 4280 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
22:56:39.0678 4280 CompositeBus - ok
22:56:39.0705 4280 COMSysApp - ok
22:56:39.0751 4280 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
22:56:39.0754 4280 crcdisk - ok
22:56:39.0831 4280 CryptSvc (9c231178ce4fb385f4b54b0a9080b8a4) C:\Windows\system32\cryptsvc.dll
22:56:39.0847 4280 CryptSvc - ok
22:56:39.0889 4280 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys
22:56:39.0898 4280 CSC - ok
22:56:39.0981 4280 CscService (56fb5f222ea30d3d3fc459879772cb73) C:\Windows\System32\cscsvc.dll
22:56:39.0999 4280 CscService - ok
22:56:40.0071 4280 DcomLaunch (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll
22:56:40.0086 4280 DcomLaunch - ok
22:56:40.0144 4280 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll
22:56:40.0161 4280 defragsvc - ok
22:56:40.0248 4280 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys
22:56:40.0250 4280 DfsC - ok
22:56:40.0332 4280 Dhcp (c56495fbd770712367cad35e5de72da6) C:\Windows\system32\dhcpcore.dll
22:56:40.0348 4280 Dhcp - ok
22:56:40.0388 4280 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
22:56:40.0390 4280 discache - ok
22:56:40.0472 4280 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
22:56:40.0475 4280 Disk - ok
22:56:40.0561 4280 Dnscache (d0722e963d3c6145446874241401b209) C:\Windows\System32\dnsrslvr.dll
22:56:40.0568 4280 Dnscache - ok
22:56:40.0636 4280 dot3svc (4408c85c21eea48eb0ce486baeef0502) C:\Windows\System32\dot3svc.dll
22:56:40.0670 4280 dot3svc - ok
22:56:40.0732 4280 DPS (7fa81c6e11caa594adb52084da73a1e5) C:\Windows\system32\dps.dll
22:56:40.0746 4280 DPS - ok
22:56:40.0818 4280 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
22:56:40.0820 4280 drmkaud - ok
22:56:40.0917 4280 DXGKrnl (8b6c3464d7fac176500061dbfff42ad4) C:\Windows\System32\drivers\dxgkrnl.sys
22:56:40.0923 4280 DXGKrnl - ok
22:56:41.0007 4280 E100B (20de769b84960606d8dbb2aec123021a) C:\Windows\system32\DRIVERS\e100b325.sys
22:56:41.0010 4280 E100B - ok
22:56:41.0069 4280 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll
22:56:41.0077 4280 EapHost - ok
22:56:41.0237 4280 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
22:56:41.0316 4280 ebdrv - ok
22:56:41.0603 4280 EFS (f42309c4191c506b71db5d1126d26318) C:\Windows\System32\lsass.exe
22:56:41.0607 4280 EFS - ok
22:56:41.0706 4280 ehRecvr (3a74a6e33685662b125a3269b1f2114f) C:\Windows\ehome\ehRecvr.exe
22:56:41.0734 4280 ehRecvr - ok
22:56:41.0806 4280 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe
22:56:41.0819 4280 ehSched - ok
22:56:41.0960 4280 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
22:56:41.0983 4280 elxstor - ok
22:56:42.0013 4280 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
22:56:42.0018 4280 ErrDev - ok
22:56:42.0107 4280 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll
22:56:42.0123 4280 EventSystem - ok
22:56:42.0180 4280 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
22:56:42.0185 4280 exfat - ok
22:56:42.0217 4280 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
22:56:42.0223 4280 fastfat - ok
22:56:42.0308 4280 Fax (f7ea23cc5e6bf2181f3f399d54f6efc1) C:\Windows\system32\fxssvc.exe
22:56:42.0333 4280 Fax - ok
22:56:42.0391 4280 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
22:56:42.0394 4280 fdc - ok
22:56:42.0452 4280 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll
22:56:42.0455 4280 fdPHost - ok
22:56:42.0484 4280 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll
22:56:42.0487 4280 FDResPub - ok
22:56:42.0520 4280 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
22:56:42.0522 4280 FileInfo - ok
22:56:42.0572 4280 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
22:56:42.0574 4280 Filetrace - ok
22:56:42.0596 4280 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
22:56:42.0598 4280 flpydisk - ok
22:56:42.0645 4280 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
22:56:42.0647 4280 FltMgr - ok
22:56:42.0743 4280 FontCache (b6512a85815fdc3d560c3705f5bdb93d) C:\Windows\system32\FntCache.dll
22:56:42.0808 4280 FontCache - ok
22:56:43.0019 4280 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:56:43.0035 4280 FontCache3.0.0.0 - ok
22:56:43.0080 4280 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
22:56:43.0088 4280 FsDepends - ok
22:56:43.0132 4280 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
22:56:43.0133 4280 Fs_Rec - ok
22:56:43.0176 4280 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys
22:56:43.0179 4280 fvevol - ok
22:56:43.0243 4280 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
22:56:43.0246 4280 gagp30kx - ok
22:56:43.0320 4280 gpsvc (8ba3c04702bf8f927ab36ae8313ca4ee) C:\Windows\System32\gpsvc.dll
22:56:43.0340 4280 gpsvc - ok
22:56:43.0522 4280 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
22:56:43.0524 4280 gupdate - ok
22:56:43.0567 4280 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
22:56:43.0569 4280 gupdatem - ok
22:56:43.0623 4280 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
22:56:43.0635 4280 gusvc - ok
22:56:43.0683 4280 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
22:56:43.0686 4280 hcw85cir - ok
22:56:43.0765 4280 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys
22:56:43.0768 4280 HdAudAddService - ok
22:56:43.0836 4280 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
22:56:43.0838 4280 HDAudBus - ok
22:56:43.0865 4280 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
22:56:43.0868 4280 HidBatt - ok
22:56:43.0918 4280 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
22:56:43.0925 4280 HidBth - ok
22:56:43.0971 4280 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
22:56:43.0974 4280 HidIr - ok
22:56:44.0024 4280 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\system32\hidserv.dll
22:56:44.0028 4280 hidserv - ok
22:56:44.0099 4280 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
22:56:44.0101 4280 HidUsb - ok
22:56:44.0155 4280 hkmsvc (741c2a45ca8407e374aaba3e330b7872) C:\Windows\system32\kmsvc.dll
22:56:44.0159 4280 hkmsvc - ok
22:56:44.0216 4280 HomeGroupListener (a768ca158bb06782a2835b907f4873c3) C:\Windows\system32\ListSvc.dll
22:56:44.0229 4280 HomeGroupListener - ok
22:56:44.0284 4280 HomeGroupProvider (fb08dec5ef43d0c66d83b8e9694e7549) C:\Windows\system32\provsvc.dll
22:56:44.0297 4280 HomeGroupProvider - ok
22:56:44.0363 4280 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
22:56:44.0366 4280 HpSAMD - ok
22:56:44.0418 4280 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
22:56:44.0423 4280 HTTP - ok
22:56:44.0463 4280 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
22:56:44.0465 4280 hwpolicy - ok
22:56:44.0522 4280 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
22:56:44.0524 4280 i8042prt - ok
22:56:44.0588 4280 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\drivers\iaStorV.sys
22:56:44.0608 4280 iaStorV - ok
22:56:44.0730 4280 idsvc (5af815eb5bc9802e5a064e2ba62bfc0c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:56:44.0753 4280 idsvc - ok
22:56:45.0003 4280 igfx (9467514ea189475a6e7fdc5d7bde9d3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
22:56:45.0043 4280 igfx - ok
22:56:45.0202 4280 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
22:56:45.0204 4280 iirsp - ok
22:56:45.0332 4280 IJPLMSVC (ad5df6f4fbbc798636edc66bfec7d0de) C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
22:56:45.0334 4280 IJPLMSVC - ok
22:56:45.0406 4280 IKEEXT (fac0ee6562b121b1399d6e855583f7a5) C:\Windows\System32\ikeext.dll
22:56:45.0429 4280 IKEEXT - ok
22:56:45.0475 4280 inspect (2ee3db2c1760171c6f72f2f1792a47b5) C:\Windows\system32\DRIVERS\inspect.sys
22:56:45.0477 4280 inspect - ok
22:56:45.0527 4280 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
22:56:45.0529 4280 intelide - ok
22:56:45.0562 4280 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
22:56:45.0564 4280 intelppm - ok
22:56:45.0611 4280 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll
22:56:45.0626 4280 IPBusEnum - ok
22:56:45.0653 4280 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:56:45.0656 4280 IpFilterDriver - ok
22:56:45.0725 4280 iphlpsvc (477397b432a256a50ee7e4339eb9ea14) C:\Windows\System32\iphlpsvc.dll
22:56:45.0745 4280 iphlpsvc - ok
22:56:45.0792 4280 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
22:56:45.0795 4280 IPMIDRV - ok
22:56:45.0824 4280 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
22:56:45.0831 4280 IPNAT - ok
22:56:45.0898 4280 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
22:56:45.0900 4280 IRENUM - ok
22:56:45.0933 4280 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
22:56:45.0936 4280 isapnp - ok
22:56:45.0982 4280 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
22:56:45.0997 4280 iScsiPrt - ok
22:56:46.0067 4280 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
22:56:46.0070 4280 kbdclass - ok
22:56:46.0113 4280 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
22:56:46.0115 4280 kbdhid - ok
22:56:46.0159 4280 KeyIso (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe
22:56:46.0162 4280 KeyIso - ok
22:56:46.0212 4280 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
22:56:46.0214 4280 KSecDD - ok
22:56:46.0268 4280 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
22:56:46.0271 4280 KSecPkg - ok
22:56:46.0338 4280 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll
22:56:46.0362 4280 KtmRm - ok
22:56:46.0440 4280 LanmanServer (bca92cb047a4326925ecef759dbaa233) C:\Windows\system32\srvsvc.dll
22:56:46.0457 4280 LanmanServer - ok
22:56:46.0509 4280 LanmanWorkstation (b9891f885dcf1f0513a51cb58493cb1f) C:\Windows\System32\wkssvc.dll
22:56:46.0525 4280 LanmanWorkstation - ok
22:56:46.0779 4280 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
22:56:46.0781 4280 lltdio - ok
22:56:46.0841 4280 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll
22:56:46.0858 4280 lltdsvc - ok
22:56:46.0894 4280 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll
22:56:46.0898 4280 lmhosts - ok
22:56:46.0963 4280 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
22:56:46.0971 4280 LSI_FC - ok
22:56:47.0019 4280 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
22:56:47.0027 4280 LSI_SAS - ok
22:56:47.0087 4280 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:56:47.0090 4280 LSI_SAS2 - ok
22:56:47.0126 4280 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:56:47.0139 4280 LSI_SCSI - ok
22:56:47.0241 4280 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
22:56:47.0243 4280 luafv - ok
22:56:47.0299 4280 LVRS (ed643e777ba3f7151ef3f0fb6be4f7f0) C:\Windows\system32\DRIVERS\lvrs.sys
22:56:47.0303 4280 LVRS - ok
22:56:47.0513 4280 LVUVC (5bc80451109a8dd7f2ddd35bce2929a3) C:\Windows\system32\DRIVERS\lvuvc.sys
22:56:47.0545 4280 LVUVC - ok
22:56:47.0676 4280 Mcx2Svc (e2b0887816ed336685954e3d8fdaa51d) C:\Windows\system32\Mcx2Svc.dll
22:56:47.0692 4280 Mcx2Svc - ok
22:56:47.0761 4280 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
22:56:47.0764 4280 megasas - ok
22:56:47.0825 4280 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
22:56:47.0839 4280 MegaSR - ok
22:56:47.0893 4280 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
22:56:47.0897 4280 MMCSS - ok
22:56:47.0923 4280 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
22:56:47.0926 4280 Modem - ok
22:56:47.0986 4280 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
22:56:47.0987 4280 monitor - ok
22:56:48.0025 4280 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
22:56:48.0027 4280 mouclass - ok
22:56:48.0112 4280 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
22:56:48.0115 4280 mouhid - ok
22:56:48.0144 4280 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
22:56:48.0146 4280 mountmgr - ok
22:56:48.0205 4280 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
22:56:48.0213 4280 mpio - ok
22:56:48.0249 4280 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
22:56:48.0251 4280 mpsdrv - ok
22:56:48.0424 4280 MpsSvc (5cd996cecf45cbc3e8d109c86b82d69e) C:\Windows\system32\mpssvc.dll
22:56:48.0454 4280 MpsSvc - ok
22:56:48.0551 4280 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
22:56:48.0623 4280 MRxDAV - ok
22:56:48.0649 4280 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys
22:56:48.0651 4280 mrxsmb - ok
22:56:48.0718 4280 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:56:48.0722 4280 mrxsmb10 - ok
22:56:48.0753 4280 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:56:48.0755 4280 mrxsmb20 - ok
22:56:48.0790 4280 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
22:56:48.0792 4280 msahci - ok
22:56:48.0848 4280 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
22:56:48.0854 4280 msdsm - ok
22:56:48.0929 4280 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe
22:56:48.0945 4280 MSDTC - ok
22:56:48.0979 4280 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
22:56:48.0981 4280 Msfs - ok
22:56:49.0032 4280 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
22:56:49.0034 4280 mshidkmdf - ok
22:56:49.0052 4280 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
22:56:49.0055 4280 msisadrv - ok
22:56:49.0127 4280 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll
22:56:49.0155 4280 MSiSCSI - ok
22:56:49.0169 4280 msiserver - ok
22:56:49.0229 4280 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
22:56:49.0234 4280 MSKSSRV - ok
22:56:49.0291 4280 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
22:56:49.0293 4280 MSPCLOCK - ok
22:56:49.0312 4280 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
22:56:49.0314 4280 MSPQM - ok
22:56:49.0359 4280 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
22:56:49.0362 4280 MsRPC - ok
22:56:49.0395 4280 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
22:56:49.0397 4280 mssmbios - ok
22:56:49.0452 4280 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
22:56:49.0454 4280 MSTEE - ok
22:56:49.0477 4280 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
22:56:49.0494 4280 MTConfig - ok
22:56:49.0540 4280 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
22:56:49.0542 4280 Mup - ok
22:56:49.0606 4280 napagent (80284f1985c70c86f0b5f86da2dfe1df) C:\Windows\system32\qagentRT.dll
22:56:49.0621 4280 napagent - ok
22:56:49.0705 4280 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
22:56:49.0722 4280 NativeWifiP - ok
22:56:49.0781 4280 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
22:56:49.0787 4280 NDIS - ok
22:56:49.0847 4280 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
22:56:49.0849 4280 NdisCap - ok
22:56:49.0883 4280 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
22:56:49.0885 4280 NdisTapi - ok
22:56:49.0924 4280 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
22:56:49.0926 4280 Ndisuio - ok
22:56:49.0979 4280 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
22:56:49.0982 4280 NdisWan - ok
22:56:50.0005 4280 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
22:56:50.0008 4280 NDProxy - ok
22:56:50.0071 4280 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
22:56:50.0073 4280 NetBIOS - ok
22:56:50.0104 4280 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
22:56:50.0107 4280 NetBT - ok
22:56:50.0158 4280 Netlogon (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe
22:56:50.0161 4280 Netlogon - ok
22:56:50.0245 4280 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll
22:56:50.0265 4280 Netman - ok
22:56:50.0304 4280 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll
22:56:50.0324 4280 netprofm - ok
22:56:50.0447 4280 NetTcpPortSharing (fe2aa5a684b0dd9b1fae57b7817c198b) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:56:50.0459 4280 NetTcpPortSharing - ok
22:56:50.0543 4280 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
22:56:50.0545 4280 nfrd960 - ok
22:56:50.0608 4280 NlaSvc (2226496e34bd40734946a054b1cd657f) C:\Windows\System32\nlasvc.dll
22:56:50.0620 4280 NlaSvc - ok
22:56:50.0742 4280 NPF (b48dc6abcd3aeff8618350ccbdc6b09a) C:\Windows\system32\drivers\npf.sys
22:56:50.0744 4280 NPF - ok
22:56:50.0783 4280 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
22:56:50.0785 4280 Npfs - ok
22:56:50.0839 4280 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll
22:56:50.0847 4280 nsi - ok
22:56:50.0882 4280 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
22:56:50.0883 4280 nsiproxy - ok
22:56:50.0987 4280 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys
22:56:50.0997 4280 Ntfs - ok
22:56:51.0021 4280 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
22:56:51.0022 4280 Null - ok
22:56:51.0068 4280 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\drivers\nvraid.sys
22:56:51.0080 4280 nvraid - ok
22:56:51.0128 4280 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\drivers\nvstor.sys
22:56:51.0140 4280 nvstor - ok
22:56:51.0185 4280 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
22:56:51.0198 4280 nv_agp - ok
22:56:51.0241 4280 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
22:56:51.0244 4280 ohci1394 - ok
22:56:51.0300 4280 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
22:56:51.0316 4280 p2pimsvc - ok
22:56:51.0374 4280 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll
22:56:51.0387 4280 p2psvc - ok
22:56:51.0457 4280 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
22:56:51.0459 4280 Parport - ok
22:56:51.0480 4280 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
22:56:51.0482 4280 partmgr - ok
22:56:51.0535 4280 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
22:56:51.0537 4280 Parvdm - ok
22:56:51.0588 4280 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll
22:56:51.0603 4280 PcaSvc - ok
22:56:51.0685 4280 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys
22:56:51.0687 4280 pccsmcfd - ok
22:56:51.0744 4280 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
22:56:51.0747 4280 pci - ok
22:56:51.0774 4280 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
22:56:51.0776 4280 pciide - ok
22:56:51.0870 4280 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
22:56:51.0884 4280 pcmcia - ok
22:56:51.0946 4280 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
22:56:51.0948 4280 pcw - ok
22:56:52.0015 4280 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
22:56:52.0021 4280 PEAUTH - ok
22:56:52.0127 4280 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll
22:56:52.0155 4280 PeerDistSvc - ok
22:56:52.0303 4280 pla (9c1bff7910c89a1d12e57343475840cb) C:\Windows\system32\pla.dll
22:56:52.0357 4280 pla - ok
22:56:52.0517 4280 PlugPlay (2cc2008f1296968fba162ed9f9afe328) C:\Windows\system32\umpnpmgr.dll
22:56:52.0546 4280 PlugPlay - ok
22:56:52.0607 4280 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll
22:56:52.0611 4280 PNRPAutoReg - ok
22:56:52.0668 4280 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll
22:56:52.0673 4280 PNRPsvc - ok
22:56:52.0725 4280 PolicyAgent (48e1b75c6dc0232fd92baae4bd344721) C:\Windows\System32\ipsecsvc.dll
22:56:52.0742 4280 PolicyAgent - ok
22:56:52.0780 4280 Power (dbff83f709a91049621c1d35dd45c92c) C:\Windows\system32\umpo.dll
22:56:52.0795 4280 Power - ok
22:56:52.0883 4280 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
22:56:52.0885 4280 PptpMiniport - ok
22:56:52.0927 4280 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
22:56:52.0930 4280 Processor - ok
22:56:52.0995 4280 ProfSvc (630cf26f0227498b7d5a92b12548960f) C:\Windows\system32\profsvc.dll
22:56:53.0008 4280 ProfSvc - ok
22:56:53.0056 4280 ProtectedStorage (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe
22:56:53.0060 4280 ProtectedStorage - ok
22:56:53.0136 4280 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
22:56:53.0141 4280 Psched - ok
22:56:53.0188 4280 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\Windows\system32\Drivers\pssdk42.sys
22:56:53.0190 4280 PSSDK42 - ok
22:56:53.0286 4280 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
22:56:53.0322 4280 ql2300 - ok
22:56:53.0473 4280 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
22:56:53.0484 4280 ql40xx - ok
22:56:53.0543 4280 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll
22:56:53.0560 4280 QWAVE - ok
22:56:53.0609 4280 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
22:56:53.0611 4280 QWAVEdrv - ok
22:56:53.0640 4280 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
22:56:53.0643 4280 RasAcd - ok
22:56:53.0698 4280 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
22:56:53.0700 4280 RasAgileVpn - ok
22:56:53.0751 4280 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll
22:56:53.0771 4280 RasAuto - ok
22:56:53.0817 4280 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
22:56:53.0820 4280 Rasl2tp - ok
22:56:53.0906 4280 RasMan (0ce66ec736b7fc526d78f7624c7d2a94) C:\Windows\System32\rasmans.dll
22:56:53.0919 4280 RasMan - ok
22:56:53.0980 4280 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
22:56:53.0982 4280 RasPppoe - ok
22:56:54.0039 4280 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
22:56:54.0041 4280 RasSstp - ok
22:56:54.0069 4280 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
22:56:54.0073 4280 rdbss - ok
22:56:54.0128 4280 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
22:56:54.0129 4280 rdpbus - ok
22:56:54.0154 4280 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
22:56:54.0158 4280 RDPCDD - ok
22:56:54.0202 4280 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys
22:56:54.0215 4280 RDPDR - ok
22:56:54.0271 4280 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
22:56:54.0273 4280 RDPENCDD - ok
22:56:54.0309 4280 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
22:56:54.0311 4280 RDPREFMP - ok
22:56:54.0341 4280 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
22:56:54.0355 4280 RDPWD - ok
22:56:54.0419 4280 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
22:56:54.0422 4280 rdyboost - ok
22:56:54.0483 4280 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll
22:56:54.0491 4280 RemoteAccess - ok
22:56:54.0548 4280 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll
22:56:54.0560 4280 RemoteRegistry - ok
22:56:54.0641 4280 rpcapd (b60f58f175de20a6739194e85b035178) C:\Program Files\WinPcap\rpcapd.exe
22:56:54.0652 4280 rpcapd - ok
22:56:54.0719 4280 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll
22:56:54.0725 4280 RpcEptMapper - ok
22:56:54.0774 4280 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe
22:56:54.0782 4280 RpcLocator - ok
22:56:54.0848 4280 RpcSs (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll
22:56:54.0856 4280 RpcSs - ok
22:56:54.0914 4280 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
22:56:54.0916 4280 rspndr - ok
22:56:54.0968 4280 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys
22:56:54.0970 4280 s3cap - ok
22:56:55.0022 4280 SamSs (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe
22:56:55.0025 4280 SamSs - ok
22:56:55.0067 4280 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
22:56:55.0075 4280 sbp2port - ok
22:56:55.0128 4280 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll
22:56:55.0149 4280 SCardSvr - ok
22:56:55.0201 4280 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
22:56:55.0204 4280 scfilter - ok
22:56:55.0299 4280 Schedule (3e8b0c453e25613a1f59762a5c42aa75) C:\Windows\system32\schedsvc.dll
22:56:55.0326 4280 Schedule - ok
22:56:55.0384 4280 SCPolicySvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll
22:56:55.0386 4280 SCPolicySvc - ok
22:56:55.0437 4280 SDRSVC (5fd90abdbfaee85986802622cbb03446) C:\Windows\System32\SDRSVC.dll
22:56:55.0452 4280 SDRSVC - ok
22:56:55.0509 4280 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
22:56:55.0510 4280 secdrv - ok
22:56:55.0555 4280 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll
22:56:55.0563 4280 seclogon - ok
22:56:55.0621 4280 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll
22:56:55.0629 4280 SENS - ok
22:56:55.0650 4280 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll
22:56:55.0666 4280 SensrSvc - ok
22:56:55.0694 4280 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
22:56:55.0696 4280 Serenum - ok
22:56:55.0757 4280 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
22:56:55.0759 4280 Serial - ok
22:56:55.0789 4280 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
22:56:55.0791 4280 sermouse - ok
22:56:55.0903 4280 SessionEnv (8f55ce568c543d5adf45c409d16718fc) C:\Windows\system32\sessenv.dll
22:56:55.0919 4280 SessionEnv - ok
22:56:55.0965 4280 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
22:56:55.0967 4280 sffdisk - ok
22:56:55.0992 4280 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
22:56:55.0995 4280 sffp_mmc - ok
22:56:56.0035 4280 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
22:56:56.0037 4280 sffp_sd - ok
22:56:56.0064 4280 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
22:56:56.0068 4280 sfloppy - ok
22:56:56.0132 4280 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll
22:56:56.0149 4280 SharedAccess - ok
22:56:56.0218 4280 ShellHWDetection (cd2e48fa5b29ee2b3b5858056d246ef2) C:\Windows\System32\shsvcs.dll
22:56:56.0233 4280 ShellHWDetection - ok
22:56:56.0293 4280 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
22:56:56.0295 4280 sisagp - ok
22:56:56.0354 4280 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:56:56.0356 4280 SiSRaid2 - ok
22:56:56.0411 4280 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
22:56:56.0415 4280 SiSRaid4 - ok
22:56:56.0482 4280 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
22:56:56.0485 4280 Smb - ok
22:56:56.0560 4280 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe
22:56:56.0567 4280 SNMPTRAP - ok
22:56:56.0611 4280 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
22:56:56.0613 4280 spldr - ok
22:56:56.0687 4280 Spooler (49b6dd6ab3715b7a67965f17194e98a9) C:\Windows\System32\spoolsv.exe
22:56:56.0693 4280 Spooler - ok
22:56:56.0862 4280 sppsvc (4c287f9069fedbd791178876ee9de536) C:\Windows\system32\sppsvc.exe
22:56:56.0946 4280 sppsvc - ok
22:56:57.0063 4280 sppuinotify (d8e3e19eebdab49dd4a8d3062ead4ec7) C:\Windows\system32\sppuinotify.dll
22:56:57.0069 4280 sppuinotify - ok
22:56:57.0158 4280 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys
22:56:57.0162 4280 srv - ok
22:56:57.0203 4280 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys
22:56:57.0206 4280 srv2 - ok
22:56:57.0234 4280 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys
22:56:57.0237 4280 srvnet - ok
22:56:57.0301 4280 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll
22:56:57.0316 4280 SSDPSRV - ok
22:56:57.0374 4280 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll
22:56:57.0386 4280 SstpSvc - ok
22:56:57.0441 4280 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
22:56:57.0444 4280 stexstor - ok
22:56:57.0501 4280 StiSvc (a22825e7bb7018e8af3e229a5af17221) C:\Windows\System32\wiaservc.dll
22:56:57.0520 4280 StiSvc - ok
22:56:57.0572 4280 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys
22:56:57.0574 4280 storflt - ok
22:56:57.0632 4280 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys
22:56:57.0634 4280 storvsc - ok
22:56:57.0680 4280 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
22:56:57.0682 4280 swenum - ok
22:56:57.0746 4280 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll
22:56:57.0763 4280 swprv - ok
22:56:57.0863 4280 SysMain (04105c8da62353589c29bdaeb8d88bd8) C:\Windows\system32\sysmain.dll
22:56:57.0896 4280 SysMain - ok
22:56:57.0953 4280 TabletInputService (fcfb6c552fbc0da299799cbd50ad9fd4) C:\Windows\System32\TabSvc.dll
22:56:57.0961 4280 TabletInputService - ok
22:56:58.0014 4280 TapiSrv (2f46b0c70a4adc8c90cf825da3b4feaf) C:\Windows\System32\tapisrv.dll
22:56:58.0028 4280 TapiSrv - ok
22:56:58.0096 4280 tapoas (827c8058c284ff0013e4462efe2591a3) C:\Windows\system32\DRIVERS\tapoas.sys
22:56:58.0098 4280 tapoas - ok
22:56:58.0163 4280 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll
22:56:58.0169 4280 TBS - ok
22:56:58.0287 4280 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys
22:56:58.0298 4280 Tcpip - ok
22:56:58.0346 4280 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys
22:56:58.0356 4280 TCPIP6 - ok
22:56:58.0410 4280 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
22:56:58.0414 4280 tcpipreg - ok
22:56:58.0473 4280 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
22:56:58.0475 4280 TDPIPE - ok
22:56:58.0492 4280 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
22:56:58.0495 4280 TDTCP - ok
22:56:58.0526 4280 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
22:56:58.0528 4280 tdx - ok
22:56:58.0587 4280 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
22:56:58.0589 4280 TermDD - ok
22:56:58.0662 4280 TermService (a01e50a04d7b1960b33e92b9080e6a94) C:\Windows\System32\termsrv.dll
22:56:58.0684 4280 TermService - ok
22:56:58.0735 4280 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll
22:56:58.0743 4280 Themes - ok
22:56:58.0797 4280 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll
22:56:58.0800 4280 THREADORDER - ok
22:56:58.0858 4280 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll
22:56:58.0865 4280 TrkWks - ok
22:56:58.0943 4280 TrustedInstaller (41a4c781d2286208d397d72099304133) C:\Windows\servicing\TrustedInstaller.exe
22:56:58.0982 4280 TrustedInstaller - ok
22:56:59.0026 4280 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
22:56:59.0034 4280 tssecsrv - ok
22:56:59.0070 4280 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
22:56:59.0073 4280 tunnel - ok
22:56:59.0119 4280 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
22:56:59.0122 4280 uagp35 - ok
22:56:59.0153 4280 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
22:56:59.0167 4280 udfs - ok
22:56:59.0233 4280 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe
22:56:59.0282 4280 UI0Detect - ok
22:56:59.0335 4280 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
22:56:59.0338 4280 uliagpkx - ok
22:56:59.0386 4280 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
22:56:59.0394 4280 umbus - ok
22:56:59.0417 4280 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
22:56:59.0419 4280 UmPass - ok
22:56:59.0487 4280 UmRdpService (8ecaca5454844f66386f7be4ae0d7cd1) C:\Windows\System32\umrdp.dll
22:56:59.0498 4280 UmRdpService - ok
22:56:59.0618 4280 UMVPFSrv (67a95b9d129ed5399e7965cd09cf30e7) C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
22:56:59.0623 4280 UMVPFSrv - ok
22:56:59.0673 4280 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll
22:56:59.0686 4280 upnphost - ok
22:56:59.0744 4280 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys
22:56:59.0747 4280 usbaudio - ok
22:56:59.0795 4280 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys
22:56:59.0798 4280 usbccgp - ok
22:56:59.0848 4280 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
22:56:59.0860 4280 usbcir - ok
22:56:59.0916 4280 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys
22:56:59.0918 4280 usbehci - ok
22:56:59.0964 4280 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys
22:56:59.0968 4280 usbhub - ok
22:57:00.0021 4280 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys
22:57:00.0023 4280 usbohci - ok
22:57:00.0076 4280 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
22:57:00.0078 4280 usbprint - ok
22:57:00.0123 4280 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
22:57:00.0126 4280 usbscan - ok
22:57:00.0182 4280 usbser (88701eca76145e2c011c0eeff0f7b70e) C:\Windows\system32\drivers\usbser.sys
22:57:00.0184 4280 usbser - ok
22:57:00.0219 4280 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:57:00.0221 4280 USBSTOR - ok
22:57:00.0273 4280 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys
22:57:00.0275 4280 usbuhci - ok
22:57:00.0350 4280 usbvideo (f642a7e4bf78cfa359cca0a3557c28d7) C:\Windows\system32\Drivers\usbvideo.sys
22:57:00.0361 4280 usbvideo - ok
22:57:00.0416 4280 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll
22:57:00.0422 4280 UxSms - ok
22:57:00.0478 4280 VaultSvc (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe
22:57:00.0481 4280 VaultSvc - ok
22:57:00.0550 4280 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
22:57:00.0553 4280 vdrvroot - ok
22:57:00.0632 4280 vds (8c4e7c49d3641bc9e299e466a7f8867d) C:\Windows\System32\vds.exe
22:57:00.0653 4280 vds - ok
22:57:00.0717 4280 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
22:57:00.0720 4280 vga - ok
22:57:00.0752 4280 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
22:57:00.0754 4280 VgaSave - ok
22:57:00.0789 4280 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
22:57:00.0796 4280 vhdmp - ok
22:57:00.0851 4280 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
22:57:00.0859 4280 viaagp - ok
22:57:00.0884 4280 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
22:57:00.0887 4280 ViaC7 - ok
22:57:00.0935 4280 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
22:57:00.0937 4280 viaide - ok
22:57:00.0978 4280 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys
22:57:00.0991 4280 vmbus - ok
22:57:01.0035 4280 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys
22:57:01.0038 4280 VMBusHID - ok
22:57:01.0092 4280 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
22:57:01.0100 4280 volmgr - ok
22:57:01.0131 4280 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
22:57:01.0135 4280 volmgrx - ok
22:57:01.0207 4280 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
22:57:01.0211 4280 volsnap - ok
22:57:01.0261 4280 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
22:57:01.0274 4280 vsmraid - ok
22:57:01.0366 4280 VSS (7ea2bcd94d9cfaf4c556f5cc94532a6c) C:\Windows\system32\vssvc.exe
22:57:01.0399 4280 VSS - ok
22:57:01.0575 4280 vToolbarUpdater11.0.2 (56e1e4442e4613fb2039a6b7421f4e58) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.0.2\ToolbarUpdater.exe
22:57:01.0582 4280 vToolbarUpdater11.0.2 - ok
22:57:01.0742 4280 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
22:57:01.0744 4280 vwifibus - ok
22:57:01.0810 4280 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll
22:57:01.0826 4280 W32Time - ok
22:57:01.0882 4280 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
22:57:01.0884 4280 WacomPen - ok
22:57:01.0926 4280 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
22:57:01.0928 4280 WANARP - ok
22:57:01.0942 4280 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
22:57:01.0944 4280 Wanarpv6 - ok
22:57:02.0043 4280 wbengine (7790b77fe1e5ee47dcc66247095bb4c9) C:\Windows\system32\wbengine.exe
22:57:02.0079 4280 wbengine - ok
22:57:02.0110 4280 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll
22:57:02.0125 4280 WbioSrvc - ok
22:57:02.0181 4280 wcncsvc (d0f88aa11ee1a62bcc6d6a8a7783ca11) C:\Windows\System32\wcncsvc.dll
22:57:02.0194 4280 wcncsvc - ok
22:57:02.0242 4280 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll
22:57:02.0251 4280 WcsPlugInService - ok
22:57:02.0337 4280 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
22:57:02.0339 4280 Wd - ok
22:57:02.0425 4280 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
22:57:02.0435 4280 Wdf01000 - ok
22:57:02.0460 4280 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
22:57:02.0475 4280 WdiServiceHost - ok
22:57:02.0489 4280 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll
22:57:02.0495 4280 WdiSystemHost - ok
22:57:02.0552 4280 WebClient (d87c7d2c517f82a5ab7a73e203063d9e) C:\Windows\System32\webclnt.dll
22:57:02.0566 4280 WebClient - ok
22:57:02.0621 4280 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll
22:57:02.0637 4280 Wecsvc - ok
22:57:02.0683 4280 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll
22:57:02.0691 4280 wercplsupport - ok
22:57:02.0751 4280 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll
22:57:02.0763 4280 WerSvc - ok
22:57:02.0817 4280 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
22:57:02.0819 4280 WfpLwf - ok
22:57:02.0850 4280 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
22:57:02.0854 4280 WIMMount - ok
22:57:02.0995 4280 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll
22:57:03.0020 4280 WinDefend - ok
22:57:03.0043 4280 WinHttpAutoProxySvc - ok
22:57:03.0134 4280 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll
22:57:03.0148 4280 Winmgmt - ok
22:57:03.0244 4280 WinRM (c4f5d3901d1b41d602ddc196e0b95b51) C:\Windows\system32\WsmSvc.dll
22:57:03.0282 4280 WinRM - ok
22:57:03.0381 4280 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
22:57:03.0384 4280 WinUsb - ok
22:57:03.0470 4280 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll
22:57:03.0495 4280 Wlansvc - ok
22:57:03.0546 4280 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
22:57:03.0548 4280 WmiAcpi - ok
22:57:03.0636 4280 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe
22:57:03.0658 4280 wmiApSrv - ok
22:57:03.0794 4280 WMPNetworkSvc (77fbd400984cf72ba0fc4b3489d65f74) C:\Program Files\Windows Media Player\wmpnetwk.exe
22:57:03.0803 4280 WMPNetworkSvc - ok
22:57:03.0857 4280 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll
22:57:03.0862 4280 WPCSvc - ok
22:57:03.0888 4280 WPDBusEnum (b7f658a2ebc07129538ad9ab35212637) C:\Windows\system32\wpdbusenum.dll
22:57:03.0902 4280 WPDBusEnum - ok
22:57:03.0983 4280 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
22:57:03.0985 4280 ws2ifsl - ok
22:57:04.0063 4280 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\System32\wscsvc.dll
22:57:04.0078 4280 wscsvc - ok
22:57:04.0093 4280 WSearch - ok
22:57:04.0226 4280 wuauserv (a33408cc036f9c08142b11be5e93f0a1) C:\Windows\system32\wuaueng.dll
22:57:04.0314 4280 wuauserv - ok
22:57:04.0459 4280 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
22:57:04.0462 4280 WudfPf - ok
22:57:04.0520 4280 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
22:57:04.0527 4280 WUDFRd - ok
22:57:04.0601 4280 wudfsvc (ddee3682fe97037c45f4d7ab467cb8b6) C:\Windows\System32\WUDFSvc.dll
22:57:04.0607 4280 wudfsvc - ok
22:57:04.0649 4280 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll
22:57:04.0687 4280 WwanSvc - ok
22:57:04.0773 4280 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
22:57:04.0961 4280 \Device\Harddisk0\DR0 - ok
22:57:04.0975 4280 MBR (0x1B8) (739b36f7a373fc81121d831231b6d311) \Device\Harddisk1\DR1
22:57:05.0358 4280 \Device\Harddisk1\DR1 - ok
22:57:05.0381 4280 Boot (0x1200) (4ccd8149d97cf7a43e7aa6254f81579d) \Device\Harddisk0\DR0\Partition0
22:57:05.0383 4280 \Device\Harddisk0\DR0\Partition0 - ok
22:57:05.0417 4280 Boot (0x1200) (29d1b16527f5fadb56e554830ee808b3) \Device\Harddisk0\DR0\Partition1
22:57:05.0419 4280 \Device\Harddisk0\DR0\Partition1 - ok
22:57:05.0452 4280 Boot (0x1200) (d87a060e29b41e4d06bd82134904f589) \Device\Harddisk0\DR0\Partition2
22:57:05.0454 4280 \Device\Harddisk0\DR0\Partition2 - ok
22:57:05.0466 4280 Boot (0x1200) (47dc14d1c3f4e315b209e4f9fecdac00) \Device\Harddisk1\DR1\Partition0
22:57:05.0469 4280 \Device\Harddisk1\DR1\Partition0 - ok
22:57:05.0475 4280 ============================================================
22:57:05.0475 4280 Scan finished
22:57:05.0475 4280 ============================================================
22:57:05.0498 2716 Detected object count: 0
22:57:05.0498 2716 Actual detected object count: 0
Nothing significant or alarming I can see from your log. As far as I can tell it is clean. Do you carry out regular maintenance on your computer like clearing temporary files, defragmentation, anti-malware scan?
I think the unaccounted network activity is due to the automatic update of your software, because I see some of your programs are out of date like Firefox, Java, and also your Windows update.
That said, please run these for me. Thanks.
Download
TFC to your
desktop
Close any open windows. Double click the TFC icon to run the program TFC will close all open programs itself in order to run, Click the Start button to begin the process. Allow TFC to run uninterrupted. The program should not take long to finish it's job Once its finished it should automatically reboot your machine, if it doesn't, manually reboot to ensure a complete clean
===================================================
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop. Check [external image: Posted Image] Click the [external image: Posted Image] button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option "Remove found threats" is Unchecked Push the Start button. ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as MyEsetScan . Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt . Include the contents of this report in your next reply.Push the Back button.Select Uninstall application on close check box and push [external image: Posted Image]
===================================================
Malwarebytes' Anti-Malware
Download
Malwarebytes' Anti-Malware here and save to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.) At the end, be sure a checkmark is placed next to:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-Malware Then click Finish . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform quick scan , then click Scan . When the scan is complete, click OK, then Show Results to view the results. Be sure that everything is checked, and click Remove Selected . When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note: The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.
===================================================
On your next reply please post :
ESET log
MBAM log
Please
STOP and let me know if you have any problems in performing with the steps above or any questions you may have.
Good Day!
Carried out the scans as asked. The logs are placed below:
ESET Log:
C:\WGASetup.exe probably a variant of Win32/Agent.JUBXKMB trojan
C:\Users\Neel\DoctorWeb\Quarantine\WGA_v1.9.40.0_crack.exe probably a variant of Win32/Agent.NARLUUV trojan
D:\programme files\Setup_FreeConverter.exe Win32/Toolbar.Widgi application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpgefbvs Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpko4_hv Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmplrrwhw Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpsbb58u Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpvrzp_u Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\tmpyja8an Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\rbia.exe Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\Launcher.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rbmonitor.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rbnotifier.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_decryptor.exe Win32/RegistryBooster application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_move_serial.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\rb_track_install.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Documents and Settings\NANDI\Local Settings\Temp\mia14B.tmp\data\OFFLINE\FB000E7F\DBD9B16A\registrybooster.exe Win32/Packed.RBCrypt.A.Gen application
G:\Windows.old\Program Files\Secret Crush Revealer\Zugo.exe Win32/Toolbar.Zugo application
MBAM Log:
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.24.01
Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Neel :: NEEL-PC [administrator]
5/24/2012 10:37:50 AM
mbam-log-2012-05-24 (10-37-50).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 191851
Time elapsed: 7 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\WGASetup.exe (Hacktool.WPA) -> Quarantined and deleted successfully.
(end)
Thanks.