This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search engine redirects [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey y'all,
Something apparently made it in past McAfee yesterday. Experiencing redirects when clicking links from search results in Google, Yahoo, and Bing today.
Please help.
Thx in advance!

Here's my HijackThis! log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:23:32 PM, on 6/5/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\drivers\audio\r267815\payload\wdm\stacsv.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
C:\WINDOWS\system32\HPSIsvc.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\Program Files\Xobni\XobniService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WIDCOMM\Bluetooth Software\BtTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\OA001Mon.exe
C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe
C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe
C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
c:\program files\real\realplayer\RealPlay.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Companion\Installs\cpn0\ytbb.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\jzipkin\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110919093418.dll
O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [OA001Mon] C:\WINDOWS\OA001Mon.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [ChangeTPMAuth] C:\Program Files\Wave Systems Corp\Common\ChangeTPMAuth.exe /T:NTRU12
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [EmbassySecurityCheck] "C:\Program Files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe"
O4 - HKLM\..\Run: [DellControlPoint] "C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe"
O4 - HKLM\..\Run: [DCPstrApp] C:\Program Files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe
O4 - HKLM\..\Run: [DellConnectionManager] "C:\Program Files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe"
O4 - HKLM\..\Run: [MVS Splash] "C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe"
O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe"
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\Act for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [7c37fc] wscript /B C:\WINDOWS\TEMP\7c37fc.vbs
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Facebook Update] "C:\Documents and Settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell ControlPoint System Manager.lnk = C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com (HKLM)
O15 - Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - Trusted Zone: http://www.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://*.mcafee.com (HKLM)
O15 - ESC Trusted Zone: http://betavscan.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://vs.mcafeeasap.com (HKLM)
O15 - ESC Trusted Zone: http://www.mcafeeasap.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1307550125529
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = waypoint.local
O17 - HKLM\Software\..\Telephony: DomainName = waypoint.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = waypoint.local
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ACT! Scheduler - Sage Software, Inc. - C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Dell ControlPoint Button Service (buttonsvc32) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
O23 - Service: Credential Vault Host Control Service - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
O23 - Service: Credential Vault Host Storage - Broadcom Corporation - C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
O23 - Service: Dell ControlPoint System Manager (dcpsysmgrsvc) - Dell Inc. - C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP SI Service (HPSIService) - HP - C:\WINDOWS\system32\HPSIsvc.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: McAfee SiteAdvisor Enterprise Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINDOWS\system32\mfevtps.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: McAfee Peer Distribution Service (RumorServer) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Smith Micro Connection Manager Service (SMManager) - Smith Micro Software, Inc. - C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\drivers\audio\r267815\payload\wdm\stacsv.exe
O23 - Service: NTRU TSS v1.2.1.27 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 19231 bytes
ran an ESET scan. this is what was found: C:\Documents and Settings\jzipkin\Local Settings\temp\SetupDataMngr_Searchqu.exe a variant of Win32/Toolbar.SearchSuite application C:\Documents and Settings\jzipkin\Local Settings\temp\nsj9FF\nsnA00.tmp\SetupDataMngr_Searchqu.exe a variant of Win32/Toolbar.SearchSuite application C:\Documents and Settings\jzipkin\Local Settings\temp\nst9F1\nsp9F2.tmp\SetupDataMngr_Searchqu.exe a variant of Win32/Toolbar.SearchSuite application C:\TDSSKiller_Quarantine\26.04.2012_22.46.52\rtkt0000\svc0000\tsk0000.dta Win32/Sirefef.DA trojan Operating memory probably a variant of Win32/Ponmocup.AA trojan
Hello,

Please download TDSSKiller.zip and and extract it.
  • Run TDSSKiller.exe.
  • Click on Change Parameters
  • Put a check in the box of Detect TDLFS file system
  • Click Start scan.
  • When it is finished the utility outputs a list of detected objects with description.
    The utility automatically selects an action (Cure or Delete) for malicious objects.
    The utility prompts the user to select an action to apply to suspicious objects (Skip, by default). Let the options as it is and click Continue
  • Let reboot if needed and tell me if the tool needed a reboot.
  • Click on Report and post the contents of the text file that will open.

    Note: By default, the utility outputs the log into system disk (it is usually the disk with installed operating system, C:\) root folder. The Log have a name like: TDSSKiller.Version_Date_Time_log.txt.

===================================================

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.

===================================================

On your next reply please post :
TDSS Killer log
ComboFix log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thx for the help Conspire.

TDSKiller found one med level threat but defaulted to 'skip' which I did.
Here's the log:

11:05:57.0749 7796 TDSS rootkit removing tool [removed] May 21 2012 16:40:16
11:05:58.0029 7796 ============================================================
11:05:58.0029 7796 Current date / time: 2012/06/06 11:05:58.0029
11:05:58.0029 7796 SystemInfo:
11:05:58.0029 7796
11:05:58.0029 7796 OS Version: 5.1.2600 ServicePack: 3.0
11:05:58.0029 7796 Product type: Workstation
11:05:58.0029 7796 ComputerName: C4LHXH1
11:05:58.0029 7796 UserName: jzipkin
11:05:58.0029 7796 Windows directory: C:\WINDOWS
11:05:58.0029 7796 System windows directory: C:\WINDOWS
11:05:58.0029 7796 Processor architecture: Intel x86
11:05:58.0029 7796 Number of processors: 2
11:05:58.0029 7796 Page size: 0x1000
11:05:58.0029 7796 Boot type: Normal boot
11:05:58.0029 7796 ============================================================
11:05:58.0403 7796 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:05:58.0403 7796 ============================================================
11:05:58.0403 7796 \Device\Harddisk0\DR0:
11:05:58.0403 7796 MBR partitions:
11:05:58.0403 7796 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1F608, BlocksNum 0x129F94B9
11:05:58.0403 7796 ============================================================
11:05:58.0450 7796 C: <-> \Device\Harddisk0\DR0\Partition0
11:05:58.0450 7796 ============================================================
11:05:58.0450 7796 Initialize success
11:05:58.0450 7796 ============================================================
11:06:04.0155 1840 ============================================================
11:06:04.0155 1840 Scan started
11:06:04.0155 1840 Mode: Manual; TDLFS;
11:06:04.0155 1840 ============================================================
11:06:05.0183 1840 Abiosdsk - ok
11:06:05.0230 1840 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
11:06:05.0230 1840 abp480n5 - ok
11:06:05.0246 1840 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:06:05.0246 1840 ACPI - ok
11:06:05.0261 1840 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
11:06:05.0261 1840 ACPIEC - ok
11:06:05.0386 1840 ACT! Scheduler (04fa07c4eed949b3ba64b536d1438130) C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
11:06:05.0386 1840 ACT! Scheduler - ok
11:06:05.0542 1840 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
11:06:05.0542 1840 AdobeFlashPlayerUpdateSvc - ok
11:06:05.0573 1840 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
11:06:05.0573 1840 adpu160m - ok
11:06:05.0620 1840 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:06:05.0620 1840 aec - ok
11:06:05.0635 1840 AESTAud (822d53766d57c90c437536232ece9023) C:\WINDOWS\system32\drivers\AESTAud.sys
11:06:05.0635 1840 AESTAud - ok
11:06:05.0682 1840 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
11:06:05.0682 1840 AFD - ok
11:06:05.0698 1840 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
11:06:05.0698 1840 agp440 - ok
11:06:05.0713 1840 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
11:06:05.0713 1840 agpCPQ - ok
11:06:05.0729 1840 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
11:06:05.0729 1840 Aha154x - ok
11:06:05.0760 1840 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
11:06:05.0760 1840 aic78u2 - ok
11:06:05.0791 1840 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
11:06:05.0791 1840 aic78xx - ok
11:06:05.0822 1840 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
11:06:05.0822 1840 Alerter - ok
11:06:05.0854 1840 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
11:06:05.0854 1840 ALG - ok
11:06:05.0869 1840 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
11:06:05.0869 1840 AliIde - ok
11:06:05.0900 1840 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
11:06:05.0900 1840 alim1541 - ok
11:06:05.0916 1840 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
11:06:05.0916 1840 amdagp - ok
11:06:05.0947 1840 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
11:06:05.0947 1840 amsint - ok
11:06:05.0994 1840 ApfiltrService (22403504e15810e99a563782e9d45311) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
11:06:05.0994 1840 ApfiltrService - ok
11:06:06.0165 1840 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:06:06.0165 1840 Apple Mobile Device - ok
11:06:06.0196 1840 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
11:06:06.0196 1840 AppMgmt - ok
11:06:06.0243 1840 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
11:06:06.0243 1840 Arp1394 - ok
11:06:06.0259 1840 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
11:06:06.0259 1840 asc - ok
11:06:06.0259 1840 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
11:06:06.0259 1840 asc3350p - ok
11:06:06.0274 1840 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
11:06:06.0274 1840 asc3550 - ok
11:06:06.0384 1840 ASFAgent (9ad6ef4d591211a93848103368125b41) C:\Program Files\Intel\ASF Agent\ASFAgent.exe
11:06:06.0384 1840 ASFAgent - ok
11:06:06.0493 1840 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
11:06:06.0493 1840 aspnet_state - ok
11:06:06.0524 1840 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:06:06.0524 1840 AsyncMac - ok
11:06:06.0571 1840 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:06:06.0571 1840 atapi - ok
11:06:06.0571 1840 Atdisk - ok
11:06:06.0602 1840 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:06:06.0602 1840 Atmarpc - ok
11:06:06.0648 1840 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
11:06:06.0648 1840 AudioSrv - ok
11:06:06.0664 1840 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:06:06.0664 1840 audstub - ok
11:06:06.0773 1840 BCM43XX (9208c78bd9283f79a30252ad954c77a2) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
11:06:06.0789 1840 BCM43XX - ok
11:06:06.0804 1840 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:06:06.0804 1840 Beep - ok
11:06:06.0898 1840 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
11:06:06.0913 1840 BITS - ok
11:06:07.0054 1840 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
11:06:07.0069 1840 Bonjour Service - ok
11:06:07.0100 1840 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
11:06:07.0116 1840 Browser - ok
11:06:07.0178 1840 btaudio (f688bbbe8e3e7e03e35caabd66616ddb) C:\WINDOWS\system32\drivers\btaudio.sys
11:06:07.0178 1840 btaudio - ok
11:06:07.0256 1840 BTDriver (2f9f111d31aa3fbbe5781d829a4524e6) C:\WINDOWS\system32\DRIVERS\btport.sys
11:06:07.0256 1840 BTDriver - ok
11:06:07.0350 1840 BTKRNL (38a3331e2f690d4cdc9de0604b9416e5) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
11:06:07.0365 1840 BTKRNL - ok
11:06:07.0475 1840 btwdins (d48148110ae078cb7221d0fcf20adfec) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
11:06:07.0490 1840 btwdins - ok
11:06:07.0724 1840 BTWDNDIS (80f61de965c116051614ac2f04222ff7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
11:06:07.0739 1840 BTWDNDIS - ok
11:06:07.0739 1840 btwhid (949eca9c56f657c06d3166d51f3226c7) C:\WINDOWS\system32\DRIVERS\btwhid.sys
11:06:07.0739 1840 btwhid - ok
11:06:07.0771 1840 btwmodem (5922bae0cd84924b9cd7e6bb515ee070) C:\WINDOWS\system32\DRIVERS\btwmodem.sys
11:06:07.0771 1840 btwmodem - ok
11:06:07.0817 1840 BTWUSB (d5af663711660d32ec230c6aaf7b6b83) C:\WINDOWS\system32\Drivers\btwusb.sys
11:06:07.0817 1840 BTWUSB - ok
11:06:07.0911 1840 buttonsvc32 (4c2a9823c48882bce93e26105e1434e2) C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
11:06:07.0911 1840 buttonsvc32 - ok
11:06:08.0098 1840 catchme - ok
11:06:08.0129 1840 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
11:06:08.0129 1840 cbidf - ok
11:06:08.0129 1840 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:06:08.0129 1840 cbidf2k - ok
11:06:08.0160 1840 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:06:08.0160 1840 CCDECODE - ok
11:06:08.0207 1840 CCIDFILTER (d006b6a67b8daed85e6d91783e9b45d6) C:\WINDOWS\system32\DRIVERS\ccidflt.sys
11:06:08.0207 1840 CCIDFILTER - ok
11:06:08.0238 1840 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
11:06:08.0238 1840 cd20xrnt - ok
11:06:08.0254 1840 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:06:08.0254 1840 Cdaudio - ok
11:06:08.0285 1840 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:06:08.0285 1840 Cdfs - ok
11:06:08.0301 1840 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:06:08.0301 1840 Cdrom - ok
11:06:08.0316 1840 Changer - ok
11:06:08.0347 1840 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
11:06:08.0347 1840 CiSvc - ok
11:06:08.0363 1840 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
11:06:08.0363 1840 ClipSrv - ok
11:06:08.0441 1840 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:06:08.0441 1840 clr_optimization_v2.0.50727_32 - ok
11:06:08.0488 1840 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
11:06:08.0488 1840 CmBatt - ok
11:06:08.0519 1840 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
11:06:08.0519 1840 CmdIde - ok
11:06:08.0550 1840 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
11:06:08.0550 1840 Compbatt - ok
11:06:08.0550 1840 COMSysApp - ok
11:06:08.0581 1840 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
11:06:08.0581 1840 Cpqarray - ok
11:06:08.0706 1840 Credential Vault Host Control Service (9d57165906778c9e5e0ecb34b311564b) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
11:06:08.0706 1840 Credential Vault Host Control Service - ok
11:06:08.0721 1840 Credential Vault Host Storage (e31e97859deee648d5867eadfbdbf25a) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
11:06:08.0721 1840 Credential Vault Host Storage - ok
11:06:08.0768 1840 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
11:06:08.0768 1840 CryptSvc - ok
11:06:08.0815 1840 cvusbdrv (dc6429fbc73b0b0b38cc5386c8a607ed) C:\WINDOWS\system32\Drivers\cvusbdrv.sys
11:06:08.0815 1840 cvusbdrv - ok
11:06:08.0862 1840 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
11:06:08.0862 1840 dac2w2k - ok
11:06:08.0877 1840 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
11:06:08.0877 1840 dac960nt - ok
11:06:08.0940 1840 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
11:06:08.0940 1840 DcomLaunch - ok
11:06:09.0080 1840 dcpsysmgrsvc (ce597e34d62c603871e2f2f5155a88e5) C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
11:06:09.0095 1840 dcpsysmgrsvc - ok
11:06:09.0283 1840 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
11:06:09.0298 1840 Dhcp - ok
11:06:09.0329 1840 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:06:09.0329 1840 Disk - ok
11:06:09.0329 1840 dmadmin - ok
11:06:09.0438 1840 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
11:06:09.0454 1840 dmboot - ok
11:06:09.0470 1840 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
11:06:09.0470 1840 dmio - ok
11:06:09.0532 1840 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:06:09.0532 1840 dmload - ok
11:06:09.0547 1840 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
11:06:09.0547 1840 dmserver - ok
11:06:09.0579 1840 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:06:09.0579 1840 DMusic - ok
11:06:09.0610 1840 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
11:06:09.0610 1840 Dnscache - ok
11:06:09.0625 1840 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
11:06:09.0641 1840 Dot3svc - ok
11:06:09.0657 1840 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
11:06:09.0657 1840 dpti2o - ok
11:06:09.0657 1840 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:06:09.0657 1840 drmkaud - ok
11:06:09.0703 1840 e1yexpress (71ff7ad30bd9e3c06df112383bb60089) C:\WINDOWS\system32\DRIVERS\e1y5132.sys
11:06:09.0703 1840 e1yexpress - ok
11:06:09.0750 1840 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
11:06:09.0750 1840 EapHost - ok
11:06:09.0766 1840 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
11:06:09.0766 1840 ERSvc - ok
11:06:09.0797 1840 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:06:09.0797 1840 Eventlog - ok
11:06:09.0844 1840 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
11:06:09.0844 1840 EventSystem - ok
11:06:09.0890 1840 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:06:09.0890 1840 Fastfat - ok
11:06:09.0937 1840 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:06:09.0953 1840 FastUserSwitchingCompatibility - ok
11:06:10.0249 1840 Fax (e97d6a8684466df94ff3bc24fb787a07) C:\WINDOWS\system32\fxssvc.exe
11:06:10.0264 1840 Fax - ok
11:06:10.0389 1840 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
11:06:10.0389 1840 Fdc - ok
11:06:10.0405 1840 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
11:06:10.0405 1840 Fips - ok
11:06:10.0545 1840 FLEXnet Licensing Service (f76d04f7413b07daa029f6520b64b4e8) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
11:06:10.0545 1840 FLEXnet Licensing Service - ok
11:06:10.0576 1840 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
11:06:10.0576 1840 Flpydisk - ok
11:06:10.0607 1840 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
11:06:10.0607 1840 FltMgr - ok
11:06:10.0701 1840 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
11:06:10.0701 1840 FontCache3.0.0.0 - ok
11:06:10.0732 1840 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:06:10.0732 1840 Fs_Rec - ok
11:06:10.0748 1840 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:06:10.0763 1840 Ftdisk - ok
11:06:10.0779 1840 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
11:06:10.0779 1840 GEARAspiWDM - ok
11:06:10.0810 1840 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:06:10.0810 1840 Gpc - ok
11:06:10.0857 1840 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
11:06:10.0857 1840 gupdate - ok
11:06:10.0872 1840 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
11:06:10.0872 1840 gupdatem - ok
11:06:10.0903 1840 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
11:06:10.0903 1840 HDAudBus - ok
11:06:10.0997 1840 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
11:06:10.0997 1840 helpsvc - ok
11:06:11.0028 1840 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
11:06:11.0028 1840 HidServ - ok
11:06:11.0044 1840 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:06:11.0059 1840 hidusb - ok
11:06:11.0075 1840 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
11:06:11.0090 1840 hkmsvc - ok
11:06:11.0106 1840 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
11:06:11.0106 1840 hpn - ok
11:06:11.0153 1840 HPSIService (a9d667f5308982a3305f364eb02458d0) C:\WINDOWS\system32\HPSIsvc.exe
11:06:11.0153 1840 HPSIService - ok
11:06:11.0200 1840 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:06:11.0215 1840 HTTP - ok
11:06:11.0262 1840 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
11:06:11.0262 1840 HTTPFilter - ok
11:06:11.0293 1840 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
11:06:11.0293 1840 i2omgmt - ok
11:06:11.0309 1840 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
11:06:11.0309 1840 i2omp - ok
11:06:11.0355 1840 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:06:11.0355 1840 i8042prt - ok
11:06:11.0418 1840 iaStor (26541a068572f650a2fa490726fe81be) C:\WINDOWS\system32\drivers\iaStor.sys
11:06:11.0433 1840 iaStor - ok
11:06:11.0574 1840 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
11:06:11.0574 1840 IAStorDataMgrSvc - ok
11:06:11.0574 1840 idebusdr - ok
11:06:11.0745 1840 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:06:11.0745 1840 idsvc - ok
11:06:11.0854 1840 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:06:11.0854 1840 Imapi - ok
11:06:11.0901 1840 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
11:06:11.0901 1840 ImapiService - ok
11:06:11.0917 1840 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
11:06:11.0932 1840 ini910u - ok
11:06:11.0948 1840 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
11:06:11.0948 1840 IntelIde - ok
11:06:11.0963 1840 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
11:06:11.0963 1840 intelppm - ok
11:06:11.0994 1840 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
11:06:11.0994 1840 Ip6Fw - ok
11:06:12.0010 1840 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:06:12.0010 1840 IpFilterDriver - ok
11:06:12.0026 1840 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:06:12.0026 1840 IpInIp - ok
11:06:12.0057 1840 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:06:12.0072 1840 IpNat - ok
11:06:12.0197 1840 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
11:06:12.0213 1840 iPod Service - ok
11:06:12.0213 1840 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:06:12.0228 1840 IPSec - ok
11:06:12.0244 1840 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:06:12.0244 1840 IRENUM - ok
11:06:12.0275 1840 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:06:12.0275 1840 isapnp - ok
11:06:12.0353 1840 JavaQuickStarterService (5472d771c0197355c1d347f20392b982) C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
11:06:12.0369 1840 JavaQuickStarterService - ok
11:06:12.0384 1840 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:06:12.0400 1840 Kbdclass - ok
11:06:12.0415 1840 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:06:12.0415 1840 kbdhid - ok
11:06:12.0462 1840 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:06:12.0462 1840 kmixer - ok
11:06:12.0493 1840 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:06:12.0493 1840 KSecDD - ok
11:06:12.0540 1840 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
11:06:12.0540 1840 LanmanServer - ok
11:06:12.0571 1840 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
11:06:12.0571 1840 lanmanworkstation - ok
11:06:12.0618 1840 LBeepKE (ca63fe81705ad660e482bef210bf2c73) C:\WINDOWS\system32\Drivers\LBeepKE.sys
11:06:12.0618 1840 LBeepKE - ok
11:06:12.0618 1840 lbrtfdc - ok
11:06:12.0743 1840 LBTServ (ab097d0f93b30a6d79d430422ac6a7e8) C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
11:06:12.0743 1840 LBTServ - ok
11:06:12.0774 1840 LHidFilt (b68309f25c5787385da842eb5b496958) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
11:06:12.0774 1840 LHidFilt - ok
11:06:12.0805 1840 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
11:06:12.0805 1840 LmHosts - ok
11:06:12.0836 1840 LMouFilt (63d3b1d3cd267fcc186a0146b80d453b) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
11:06:12.0836 1840 LMouFilt - ok
11:06:12.0836 1840 MBAMSwissArmy - ok
11:06:12.0914 1840 McAfee SiteAdvisor Enterprise Service (4f2d526298cbc517edb82501e8041112) C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
11:06:12.0914 1840 McAfee SiteAdvisor Enterprise Service - ok
11:06:12.0992 1840 McShield (1fe222eaf4ba73ced5a0707b38f3c0b1) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
11:06:12.0992 1840 McShield - ok
11:06:13.0023 1840 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
11:06:13.0023 1840 Messenger - ok
11:06:13.0070 1840 mfeapfk (37364b530339ff0b0ababc8df1c532c3) C:\WINDOWS\system32\drivers\mfeapfk.sys
11:06:13.0085 1840 mfeapfk - ok
11:06:13.0101 1840 MfeAVFK (cd2a8a43bd6b0d15a3255829b1778285) C:\WINDOWS\system32\drivers\mfeavfk.sys
11:06:13.0117 1840 MfeAVFK - ok
11:06:13.0117 1840 mfeavfk01 - ok
11:06:13.0132 1840 MfeBOPK (2cd52e91ba338f10ba14d3f90bbda5e8) C:\WINDOWS\system32\drivers\mfebopk.sys
11:06:13.0132 1840 MfeBOPK - ok
11:06:13.0226 1840 mfehidk (cf669582f5f98c4ba79d59cfe169198b) C:\WINDOWS\system32\drivers\mfehidk.sys
11:06:13.0241 1840 mfehidk - ok
11:06:13.0273 1840 mferkdet (42f84c2a82a057d74c54ef70e0cf0a2c) C:\WINDOWS\system32\drivers\mferkdet.sys
11:06:13.0273 1840 mferkdet - ok
11:06:13.0304 1840 MfeRKDK (820d6aa3f7f0cfa8a1fa8f63d3f1df04) C:\WINDOWS\system32\drivers\MfeRKDK.sys
11:06:13.0304 1840 MfeRKDK - ok
11:06:13.0319 1840 mfetdi2k (03b2b8bd4d0a2d3636be9248b5dce33a) C:\WINDOWS\system32\drivers\mfetdi2k.sys
11:06:13.0319 1840 mfetdi2k - ok
11:06:13.0366 1840 mfetdik (3812e49fa67a3f604895f0d0c2e1ef90) C:\WINDOWS\system32\drivers\mfetdik.sys
11:06:13.0366 1840 mfetdik - ok
11:06:13.0413 1840 mfevtp (5339baac5c43ddbdb448863f8ea8fcdc) C:\WINDOWS\system32\mfevtps.exe
11:06:13.0428 1840 mfevtp - ok
11:06:13.0460 1840 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:06:13.0460 1840 mnmdd - ok
11:06:13.0491 1840 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
11:06:13.0491 1840 mnmsrvc - ok
11:06:13.0522 1840 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
11:06:13.0522 1840 Modem - ok
11:06:13.0569 1840 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:06:13.0569 1840 Mouclass - ok
11:06:13.0584 1840 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:06:13.0584 1840 mouhid - ok
11:06:13.0615 1840 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:06:13.0631 1840 MountMgr - ok
11:06:13.0647 1840 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
11:06:13.0647 1840 mraid35x - ok
11:06:13.0678 1840 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:06:13.0678 1840 MRxDAV - ok
11:06:13.0787 1840 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:06:13.0802 1840 MRxSmb - ok
11:06:13.0896 1840 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
11:06:13.0896 1840 MSDTC - ok
11:06:13.0927 1840 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:06:13.0927 1840 Msfs - ok
11:06:13.0927 1840 MSIServer - ok
11:06:13.0958 1840 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:06:13.0958 1840 MSKSSRV - ok
11:06:13.0974 1840 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:06:13.0974 1840 MSPCLOCK - ok
11:06:13.0974 1840 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:06:13.0989 1840 MSPQM - ok
11:06:13.0989 1840 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:06:13.0989 1840 mssmbios - ok
11:06:14.0114 1840 MSSQL$ACT7 - ok
11:06:14.0161 1840 MSSQL$SQLEXPRESS - ok
11:06:14.0208 1840 MSSQLServerADHelper (1d89eb4e2a99cabd4e81225f4f4c4b25) C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
11:06:14.0208 1840 MSSQLServerADHelper - ok
11:06:14.0332 1840 MSSQLServerADHelper100 (f1761c8fb2b25a32c6d63e36bb88c3ae) c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
11:06:14.0332 1840 MSSQLServerADHelper100 - ok
11:06:14.0364 1840 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:06:14.0364 1840 MSTEE - ok
11:06:14.0410 1840 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:06:14.0426 1840 Mup - ok
11:06:14.0551 1840 myAgtSvc (a35ab0a7a983ebca85805da63d763382) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
11:06:14.0551 1840 myAgtSvc - ok
11:06:14.0597 1840 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:06:14.0597 1840 NABTSFEC - ok
11:06:14.0644 1840 NAL (1d99ac4ce3abbd96a8c0d77ff104096d) C:\WINDOWS\system32\Drivers\iqvw32.sys
11:06:14.0644 1840 NAL - ok
11:06:14.0675 1840 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
11:06:14.0691 1840 napagent - ok
11:06:14.0722 1840 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:06:14.0722 1840 NDIS - ok
11:06:14.0753 1840 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:06:14.0753 1840 NdisIP - ok
11:06:14.0784 1840 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:06:14.0784 1840 NdisTapi - ok
11:06:14.0800 1840 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:06:14.0816 1840 Ndisuio - ok
11:06:14.0816 1840 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:06:14.0816 1840 NdisWan - ok
11:06:14.0862 1840 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:06:14.0862 1840 NDProxy - ok
11:06:14.0878 1840 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:06:14.0878 1840 NetBIOS - ok
11:06:14.0925 1840 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:06:14.0925 1840 NetBT - ok
11:06:14.0971 1840 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:06:14.0971 1840 NetDDE - ok
11:06:14.0971 1840 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:06:14.0971 1840 NetDDEdsdm - ok
11:06:15.0003 1840 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:06:15.0003 1840 Netlogon - ok
11:06:15.0034 1840 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
11:06:15.0034 1840 Netman - ok
11:06:15.0127 1840 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:06:15.0127 1840 NetTcpPortSharing - ok
11:06:15.0158 1840 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
11:06:15.0174 1840 NIC1394 - ok
11:06:15.0221 1840 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
11:06:15.0221 1840 Nla - ok
11:06:15.0252 1840 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:06:15.0252 1840 Npfs - ok
11:06:15.0330 1840 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:06:15.0330 1840 Ntfs - ok
11:06:15.0330 1840 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:06:15.0345 1840 NtLmSsp - ok
11:06:15.0392 1840 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
11:06:15.0408 1840 NtmsSvc - ok
11:06:15.0439 1840 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:06:15.0439 1840 Null - ok
11:06:15.0953 1840 nv (2e095f4f396f7106a5f1d8b00ec00d4f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
11:06:16.0031 1840 nv - ok
11:06:16.0234 1840 nvsvc (328acce9c643fe050a4143fe3ec3c025) C:\WINDOWS\system32\nvsvc32.exe
11:06:16.0234 1840 nvsvc - ok
11:06:16.0296 1840 NWADI (fc2a8aaa0f3321f41231ede0af1968ae) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys
11:06:16.0296 1840 NWADI - ok
11:06:16.0296 1840 nwcworkstation - ok
11:06:16.0327 1840 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:06:16.0327 1840 NwlnkFlt - ok
11:06:16.0327 1840 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:06:16.0343 1840 NwlnkFwd - ok
11:06:16.0359 1840 NWUSBCDFIL (224131778c92aee8c13afac5fbff19ca) C:\WINDOWS\system32\DRIVERS\NwUsbCdFil.sys
11:06:16.0359 1840 NWUSBCDFIL - ok
11:06:16.0390 1840 NWUSBModem (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys
11:06:16.0390 1840 NWUSBModem - ok
11:06:16.0421 1840 NWUSBPort (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbser.sys
11:06:16.0421 1840 NWUSBPort - ok
11:06:16.0421 1840 NWUSBPort2 (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbser2.sys
11:06:16.0421 1840 NWUSBPort2 - ok
11:06:16.0452 1840 OA001Afx (0f538df1673e5216f3baacb6911d9d0f) C:\WINDOWS\system32\Drivers\OA001Afx.sys
11:06:16.0468 1840 OA001Afx - ok
11:06:16.0499 1840 OA001Ufd (2cf21d5f8f1b74bb1922135ac2b12ddb) C:\WINDOWS\system32\DRIVERS\OA001Ufd.sys
11:06:16.0499 1840 OA001Ufd - ok
11:06:16.0530 1840 OA001Vid (159e5a08a6a5231863cddbd787a4eabb) C:\WINDOWS\system32\DRIVERS\OA001Vid.sys
11:06:16.0530 1840 OA001Vid - ok
11:06:16.0686 1840 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
11:06:16.0686 1840 odserv - ok
11:06:16.0733 1840 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
11:06:16.0733 1840 ohci1394 - ok
11:06:16.0811 1840 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:06:16.0811 1840 ose - ok
11:06:16.0842 1840 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
11:06:16.0842 1840 Parport - ok
11:06:16.0857 1840 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:06:16.0888 1840 PartMgr - ok
11:06:16.0888 1840 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:06:16.0888 1840 ParVdm - ok
11:06:16.0888 1840 pavprsrv - ok
11:06:16.0920 1840 PBADRV (4088c1ecd1f54281a92fa663b0fdc36f) C:\WINDOWS\system32\DRIVERS\PBADRV.sys
11:06:16.0920 1840 PBADRV - ok
11:06:16.0951 1840 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\PCASp50.sys
11:06:16.0951 1840 PCASp50 - ok
11:06:16.0966 1840 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
11:06:16.0966 1840 PCI - ok
11:06:16.0966 1840 PCIDump - ok
11:06:16.0998 1840 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:06:16.0998 1840 PCIIde - ok
11:06:17.0029 1840 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
11:06:17.0029 1840 Pcmcia - ok
11:06:17.0029 1840 PDCOMP - ok
11:06:17.0029 1840 PDFRAME - ok
11:06:17.0029 1840 PDRELI - ok
11:06:17.0044 1840 PDRFRAME - ok
11:06:17.0060 1840 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
11:06:17.0060 1840 perc2 - ok
11:06:17.0060 1840 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
11:06:17.0060 1840 perc2hib - ok
11:06:17.0107 1840 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:06:17.0107 1840 PlugPlay - ok
11:06:17.0138 1840 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:06:17.0138 1840 PolicyAgent - ok
11:06:17.0169 1840 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:06:17.0169 1840 PptpMiniport - ok
11:06:17.0185 1840 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:06:17.0185 1840 ProtectedStorage - ok
11:06:17.0200 1840 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:06:17.0200 1840 PSched - ok
11:06:17.0231 1840 PSI_SVC_2 (e0d0cb09aa07b22be984e4f7ec0326f5) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
11:06:17.0247 1840 PSI_SVC_2 - ok
11:06:17.0263 1840 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:06:17.0263 1840 Ptilink - ok
11:06:17.0294 1840 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
11:06:17.0294 1840 ql1080 - ok
11:06:17.0309 1840 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
11:06:17.0309 1840 Ql10wnt - ok
11:06:17.0325 1840 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
11:06:17.0325 1840 ql12160 - ok
11:06:17.0340 1840 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
11:06:17.0340 1840 ql1240 - ok
11:06:17.0356 1840 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
11:06:17.0356 1840 ql1280 - ok
11:06:17.0418 1840 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:06:17.0418 1840 RasAcd - ok
11:06:17.0465 1840 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
11:06:17.0465 1840 RasAuto - ok
11:06:17.0481 1840 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:06:17.0481 1840 Rasl2tp - ok
11:06:17.0512 1840 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
11:06:17.0527 1840 RasMan - ok
11:06:17.0543 1840 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:06:17.0543 1840 RasPppoe - ok
11:06:17.0559 1840 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:06:17.0559 1840 Raspti - ok
11:06:17.0590 1840 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:06:17.0590 1840 Rdbss - ok
11:06:17.0621 1840 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:06:17.0621 1840 RDPCDD - ok
11:06:17.0637 1840 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
11:06:17.0637 1840 rdpdr - ok
11:06:17.0668 1840 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
11:06:17.0668 1840 RDPWD - ok
11:06:17.0699 1840 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
11:06:17.0699 1840 RDSessMgr - ok
11:06:17.0730 1840 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:06:17.0730 1840 redbook - ok
11:06:17.0761 1840 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
11:06:17.0761 1840 RemoteAccess - ok
11:06:17.0777 1840 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
11:06:17.0777 1840 RemoteRegistry - ok
11:06:17.0808 1840 rimmptsk (ea885e7a56f1be1f14c372337c42fe48) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
11:06:17.0808 1840 rimmptsk - ok
11:06:17.0855 1840 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
11:06:17.0855 1840 RpcLocator - ok
11:06:17.0902 1840 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
11:06:17.0902 1840 RpcSs - ok
11:06:17.0964 1840 RsFx0105 (6a7360e36cbd636972aeef0dd292a946) C:\WINDOWS\system32\DRIVERS\RsFx0105.sys
11:06:17.0964 1840 RsFx0105 - ok
11:06:17.0995 1840 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
11:06:17.0995 1840 RSVP - ok
11:06:18.0135 1840 RumorServer (a35ab0a7a983ebca85805da63d763382) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
11:06:18.0151 1840 RumorServer - ok
11:06:18.0198 1840 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:06:18.0198 1840 SamSs - ok
11:06:18.0244 1840 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
11:06:18.0244 1840 SCardSvr - ok
11:06:18.0291 1840 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
11:06:18.0291 1840 Schedule - ok
11:06:18.0322 1840 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
11:06:18.0322 1840 sdbus - ok
11:06:18.0338 1840 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:06:18.0338 1840 Secdrv - ok
11:06:18.0354 1840 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
11:06:18.0369 1840 seclogon - ok
11:06:18.0494 1840 SecureStorageService (e80163f46ae96cc0a05fb9f3f55deb18) C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
11:06:18.0494 1840 SecureStorageService - ok
11:06:18.0556 1840 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
11:06:18.0556 1840 SENS - ok
11:06:18.0603 1840 Sentinel (8627c992b8a80504fc477b2e8ff8ec4f) C:\WINDOWS\System32\Drivers\SENTINEL.SYS
11:06:18.0603 1840 Sentinel - ok
11:06:18.0650 1840 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:06:18.0650 1840 Serenum - ok
11:06:18.0681 1840 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
11:06:18.0681 1840 Serial - ok
11:06:18.0728 1840 sermouse (1f16931c722c69e4a7866244796c66a0) C:\WINDOWS\system32\DRIVERS\sermouse.sys
11:06:18.0728 1840 sermouse - ok
11:06:18.0728 1840 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
11:06:18.0728 1840 sffdisk - ok
11:06:18.0759 1840 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
11:06:18.0759 1840 sffp_sd - ok
11:06:18.0759 1840 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:06:18.0759 1840 Sfloppy - ok
11:06:18.0806 1840 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
11:06:18.0806 1840 SharedAccess - ok
11:06:18.0837 1840 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:06:18.0837 1840 ShellHWDetection - ok
11:06:18.0837 1840 Simbad - ok
11:06:18.0852 1840 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
11:06:18.0852 1840 sisagp - ok
11:06:18.0868 1840 slee_503_service - ok
11:06:18.0883 1840 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:06:18.0883 1840 SLIP - ok
11:06:19.0024 1840 SMManager (24d62fc9201d172f69c47355d185213b) C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
11:06:19.0024 1840 SMManager - ok
11:06:19.0102 1840 SMSIVZAM5 (1e715247efffdda938c085913045d599) C:\PROGRA~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS
11:06:19.0102 1840 SMSIVZAM5 - ok
11:06:19.0133 1840 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
11:06:19.0133 1840 Sparrow - ok
11:06:19.0164 1840 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:06:19.0164 1840 splitter - ok
11:06:19.0195 1840 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
11:06:19.0195 1840 Spooler - ok
11:06:19.0304 1840 SQLAgent$SQLEXPRESS (a892134c28777978ecde8283dc57ac0f) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
11:06:19.0320 1840 SQLAgent$SQLEXPRESS - ok
11:06:19.0413 1840 SQLBrowser (10d936dced9eacd1a1b3fcdda6d7a4eb) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
11:06:19.0413 1840 SQLBrowser - ok
11:06:19.0445 1840 SQLWriter (135cdccc167ef0c250125bbd3abe18d5) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
11:06:19.0445 1840 SQLWriter - ok
11:06:19.0491 1840 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:06:19.0491 1840 sr - ok
11:06:19.0538 1840 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
11:06:19.0538 1840 srservice - ok
11:06:19.0600 1840 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:06:19.0616 1840 Srv - ok
11:06:19.0694 1840 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
11:06:19.0694 1840 SSDPSRV - ok
11:06:19.0772 1840 STacSV (0a8fa56553913e87aa24a6ce218b88de) c:\drivers\audio\r267815\payload\wdm\stacsv.exe
11:06:19.0772 1840 STacSV - ok
11:06:19.0943 1840 STHDA (c111965a8dbd00768787d807ec3113ff) C:\WINDOWS\system32\drivers\sthda.sys
11:06:19.0959 1840 STHDA - ok
11:06:20.0084 1840 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
11:06:20.0084 1840 stisvc - ok
11:06:20.0146 1840 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:06:20.0146 1840 streamip - ok
11:06:20.0177 1840 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:06:20.0177 1840 swenum - ok
11:06:20.0193 1840 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:06:20.0193 1840 swmidi - ok
11:06:20.0208 1840 SwPrv - ok
11:06:20.0224 1840 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
11:06:20.0224 1840 symc810 - ok
11:06:20.0224 1840 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
11:06:20.0224 1840 symc8xx - ok
11:06:20.0239 1840 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
11:06:20.0239 1840 sym_hi - ok
11:06:20.0255 1840 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
11:06:20.0255 1840 sym_u3 - ok
11:06:20.0271 1840 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:06:20.0271 1840 sysaudio - ok
11:06:20.0349 1840 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
11:06:20.0349 1840 SysmonLog - ok
11:06:20.0380 1840 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
11:06:20.0380 1840 TapiSrv - ok
11:06:20.0426 1840 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:06:20.0442 1840 Tcpip - ok
11:06:20.0598 1840 tcsd_win32.exe (ba9202e263a6fc1ffd7889fea186a2c4) C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
11:06:20.0614 1840 tcsd_win32.exe - ok
11:06:20.0738 1840 TdmService (ea63bf38938ad9917beb1846d6d15c84) C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
11:06:20.0754 1840 TdmService - ok
11:06:20.0972 1840 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:06:20.0988 1840 TDPIPE - ok
11:06:21.0003 1840 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:06:21.0003 1840 TDTCP - ok
11:06:21.0019 1840 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:06:21.0019 1840 TermDD - ok
11:06:21.0081 1840 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
11:06:21.0081 1840 TermService - ok
11:06:21.0128 1840 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:06:21.0143 1840 Themes - ok
11:06:21.0175 1840 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe
11:06:21.0175 1840 TlntSvr - ok
11:06:21.0206 1840 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
11:06:21.0206 1840 TosIde - ok
11:06:21.0221 1840 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
11:06:21.0221 1840 TrkWks - ok
11:06:21.0268 1840 TrmbTS (5070590587118b2960e14927b4393d32) C:\WINDOWS\system32\Drivers\TrmbTS.sys
11:06:21.0268 1840 TrmbTS - ok
11:06:21.0284 1840 TRMUSB5K - ok
11:06:21.0330 1840 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:06:21.0330 1840 Udfs - ok
11:06:21.0362 1840 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
11:06:21.0362 1840 ultra - ok
11:06:21.0393 1840 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:06:21.0408 1840 Update - ok
11:06:21.0455 1840 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
11:06:21.0471 1840 upnphost - ok
11:06:21.0486 1840 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
11:06:21.0502 1840 UPS - ok
11:06:21.0580 1840 USA19H (6d1e41657fdb48f9147598c773297513) C:\WINDOWS\system32\DRIVERS\USA19H2k.sys
11:06:21.0595 1840 USA19H - ok
11:06:21.0642 1840 USA19H2KP (8a217fc16dd14ab8ad2eaa1f08b3b5c5) C:\WINDOWS\system32\DRIVERS\USA19H2kp.SYS
11:06:21.0642 1840 USA19H2KP - ok
11:06:21.0751 1840 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\WINDOWS\system32\Drivers\usbaapl.sys
11:06:21.0767 1840 USBAAPL - ok
11:06:21.0798 1840 usbccgp (c18d6c74953621346df6b0a11f80c1cc) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:06:21.0798 1840 usbccgp - ok
11:06:21.0845 1840 USBCCID (150442fa5224dc338028543e2fffa7b4) C:\WINDOWS\system32\DRIVERS\usbccid.sys
11:06:21.0845 1840 USBCCID - ok
11:06:21.0907 1840 usbehci (4bac8df07f1d8434fc640e677a62204e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:06:21.0907 1840 usbehci - ok
11:06:21.0954 1840 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:06:21.0970 1840 usbhub - ok
11:06:22.0001 1840 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:06:22.0001 1840 usbprint - ok
11:06:22.0032 1840 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:06:22.0032 1840 usbscan - ok
11:06:22.0079 1840 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:06:22.0079 1840 USBSTOR - ok
11:06:22.0110 1840 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
11:06:22.0110 1840 usbuhci - ok
11:06:22.0157 1840 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
11:06:22.0172 1840 usbvideo - ok
11:06:22.0203 1840 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
11:06:22.0203 1840 usb_rndisx - ok
11:06:22.0250 1840 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:06:22.0250 1840 VgaSave - ok
11:06:22.0281 1840 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
11:06:22.0281 1840 viaagp - ok
11:06:22.0297 1840 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
11:06:22.0297 1840 ViaIde - ok
11:06:22.0328 1840 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
11:06:22.0328 1840 VolSnap - ok
11:06:22.0390 1840 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
11:06:22.0390 1840 VSS - ok
11:06:22.0421 1840 w32time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
11:06:22.0437 1840 w32time - ok
11:06:22.0484 1840 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:06:22.0484 1840 Wanarp - ok
11:06:22.0531 1840 WavxDMgr (0be8dd6c95c5bdff9c5f3fa8095d304c) C:\WINDOWS\system32\DRIVERS\WavxDMgr.sys
11:06:22.0531 1840 WavxDMgr - ok
11:06:22.0593 1840 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
11:06:22.0593 1840 wceusbsh - ok
11:06:22.0655 1840 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
11:06:22.0671 1840 Wdf01000 - ok
11:06:22.0671 1840 WDICA - ok
11:06:22.0686 1840 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:06:22.0686 1840 wdmaud - ok
11:06:22.0749 1840 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
11:06:22.0749 1840 WebClient - ok
11:06:22.0764 1840 WinDriver6 - ok
11:06:22.0842 1840 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
11:06:22.0842 1840 winmgmt - ok
11:06:22.0936 1840 WinRM (18f347402da544a780949b8fdf83351b) C:\WINDOWS\system32\WsmSvc.dll
11:06:22.0967 1840 WinRM - ok
11:06:23.0014 1840 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
11:06:23.0014 1840 WmdmPmSN - ok
11:06:23.0092 1840 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
11:06:23.0092 1840 Wmi - ok
11:06:23.0216 1840 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
11:06:23.0216 1840 WmiAcpi - ok
11:06:23.0263 1840 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
11:06:23.0263 1840 WmiApSrv - ok
11:06:23.0403 1840 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
11:06:23.0419 1840 WMPNetworkSvc - ok
11:06:23.0419 1840 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
11:06:23.0419 1840 WS2IFSL - ok
11:06:23.0481 1840 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
11:06:23.0481 1840 wscsvc - ok
11:06:23.0497 1840 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:06:23.0497 1840 WSTCODEC - ok
11:06:23.0513 1840 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
11:06:23.0513 1840 wuauserv - ok
11:06:23.0544 1840 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:06:23.0544 1840 WudfPf - ok
11:06:23.0575 1840 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:06:23.0575 1840 WudfRd - ok
11:06:23.0575 1840 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
11:06:23.0590 1840 WudfSvc - ok
11:06:23.0637 1840 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
11:06:23.0637 1840 WZCSVC - ok
11:06:23.0746 1840 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
11:06:23.0746 1840 xmlprov - ok
11:06:23.0824 1840 XobniService (986c5b8f380f7408ecee96c3c5dbf66c) C:\Program Files\Xobni\XobniService.exe
11:06:23.0824 1840 XobniService - ok
11:06:23.0933 1840 YahooAUService (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
11:06:23.0933 1840 YahooAUService - ok
11:06:24.0089 1840 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
11:06:24.0697 1840 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
11:06:24.0697 1840 \Device\Harddisk0\DR0 - detected TDSS File System (1)
11:06:24.0697 1840 Boot (0x1200) (1164849f2816b8faac91ba9894555e1e) \Device\Harddisk0\DR0\Partition0
11:06:24.0697 1840 \Device\Harddisk0\DR0\Partition0 - ok
11:06:24.0697 1840 ============================================================
11:06:24.0697 1840 Scan finished
11:06:24.0697 1840 ============================================================
11:06:24.0697 0556 Detected object count: 1
11:06:24.0697 0556 Actual detected object count: 1
11:06:36.0012 0556 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
11:06:36.0012 0556 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip


Here's the Combofix log:

ComboFix 12-06-05.04 - jzipkin 06/06/2012 11:12:03.11.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.2751 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee® Security-as-a-Service Anti-virus *Disabled/Updated* {8C354827-2F54-4E28-90DC-AD391E77808C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\8615B8621C.sys
c:\windows\Temp\tmp3.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-05-06 to 2012-06-06 )))))))))))))))))))))))))))))))
.
.
2012-06-04 15:01 . 2012-06-04 15:01 163840 –sha-r- c:\windows\system32\c_1257I.dll
2012-05-25 15:49 . 2011-09-29 18:20 484352 —-a-w- c:\windows\system32\lame_enc.dll
2012-05-25 15:28 . 2009-05-18 17:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-05-25 15:28 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2012-05-25 15:27 . 2012-05-25 15:27 ——– d—–w- c:\program files\iPod
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\program files\iTunes
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-05-25 15:26 . 2012-05-25 15:26 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2012-05-25 15:26 . 2012-02-15 15:01 4547944 —-a-w- c:\windows\system32\usbaaplrc.dll
2012-05-25 15:26 . 2012-02-15 15:01 43520 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2012-05-25 15:20 . 2012-05-25 15:20 ——– d—–w- c:\program files\Bonjour
2012-05-25 15:01 . 2012-05-25 15:01 ——– d—–w- c:\program files\uTorrent
2012-05-25 15:00 . 2012-05-25 17:21 ——– d—–w- c:\documents and settings\JZipkin\Application Data\uTorrent
2012-05-14 20:49 . 2012-05-14 20:49 ——– d—–w- c:\documents and settings\JZipkin\Application Data\Unity
2012-05-14 19:48 . 2012-05-14 19:48 ——– d—–w- c:\documents and settings\JZipkin\Local Settings\Application Data\Unity
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-05-11 15:47 . 2012-05-11 15:48 ——– d—–w- c:\program files\QuickTime
2012-05-11 15:47 . 2012-05-25 15:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2012-05-09 19:47 . 2010-04-05 09:19 3354624 —-a-w- c:\windows\system32\stlang.dll
2012-05-09 19:47 . 2010-04-05 09:18 11870298 —-a-w- c:\windows\system32\idtsg.cpl
2012-05-09 19:47 . 2010-04-05 09:18 253952 —-a-w- c:\windows\system32\AESTCtrl.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-06 14:29 . 2010-07-26 18:14 1994 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2012-06-04 13:10 . 2010-07-23 18:20 0 —-a-w- c:\documents and settings\JZipkin\Local Settings\Application Data\WavXMapDrive.bat
2012-05-09 16:25 . 2012-04-25 13:45 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 16:25 . 2011-06-29 15:20 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-27 02:53 . 2008-04-25 16:16 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2012-04-26 17:04 . 2012-04-26 17:05 388608 —-a-w- C:\HiJackThis.exe
2012-04-04 22:47 . 2012-04-30 15:32 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-04-04 22:47 . 2012-04-30 15:32 772504 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-04-04 22:47 . 2010-07-22 17:11 687504 —-a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-03-21 1523512]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{022F2F51-CDDA-4873-8A29-72C66C808A3F}"
[HKEY_CLASSES_ROOT\CLSID\{022F2F51-CDDA-4873-8A29-72C66C808A3F}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{661963C1-99A1-44e7-A671-1CF3768AE9D4}"
[HKEY_CLASSES_ROOT\CLSID\{661963C1-99A1-44e7-A671-1CF3768AE9D4}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Facebook Update"="c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-21 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2010-04-05 737280]
"nwiz"="nwiz.exe" [2009-12-15 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-15 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-15 13770752]
"NVHotkey"="nvHotkey.dll" [2009-12-15 86016]
"OA001Mon"="c:\windows\OA001Mon.exe" [2010-01-28 24576]
"IAStorIcon"="c:\program files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2008-05-30 180224]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2008-05-14 105472]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2008-06-24 243000]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2008-06-24 79160]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-08-18 598016]
"DCPstrApp"="c:\program files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe" [2008-08-04 6656]
"DellConnectionManager"="c:\program files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe" [2008-10-01 1454080]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\DesktopUI\XTray.exe" [2011-08-25 476480]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Act.Outlook.Service"="c:\program files\ACT\Act for Windows\Act.Outlook.Service.exe" [2009-02-24 28672]
"Act! Preloader"="c:\program files\ACT\Act for Windows\ActSage.exe" [2009-02-24 393216]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-03-27 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-03-26 640440]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-06-29 273544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-04-05 495708]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"7c37fc"="wscript" [X]
.
c:\documents and settings\McAfeeMVSUser\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [N/A]
.
c:\documents and settings\ataylor.WAYPOINT.000\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-8-15 604776]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-11-11 950048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29 64592 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\ACT\\Act for Windows\\ActSage.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/12/2010 2:55 PM 89624]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 6:56 AM 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [9/4/2008 6:28 PM 406808]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [11/11/2008 5:35 PM 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [11/11/2008 5:35 PM 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [11/11/2008 4:00 PM 451872]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [12/29/2011 4:47 PM 99896]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [7/22/2010 1:13 PM 13336]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [7/26/2010 11:19 AM 10448]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [5/12/2011 11:48 AM 324928]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/16/2010 10:37 AM 148520]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 6:29 PM 29293408]
R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 RumorServer;McAfee Peer Distribution Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe [10/1/2008 5:28 AM 90112]
R2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [5/20/2010 1:46 PM 55016]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [7/21/2010 5:25 PM 113664]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [7/22/2010 1:11 PM 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [7/21/2010 5:27 PM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [7/21/2010 5:25 PM 240344]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [7/21/2010 5:25 PM 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [7/21/2010 5:25 PM 281472]
S2 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [2/24/2009 2:08 PM 81920]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/25/2012 9:45 AM 257696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/12/2010 2:55 PM 87808]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [12/18/2009 12:13 PM 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/18/2009 12:12 PM 174720]
S3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [7/21/2010 5:25 PM 134144]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [4/14/2010 8:29 PM 32408]
S3 TrmbTS;TrmbTS;c:\windows\system32\drivers\TrmbTS.sys [8/26/2010 12:49 PM 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.sys –> c:\windows\system32\drivers\TRMUSB5K.sys [?]
S3 USA19H;USA19H;c:\windows\system32\drivers\USA19H2k.sys [8/13/2010 3:56 PM 704000]
S3 USA19H2KP;Keyspan USB Serial Port Driver;c:\windows\system32\drivers\USA19H2kp.sys [8/13/2010 3:56 PM 24192]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 12:16 PM 14336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/22/2009 11:08 PM 47128]
S4 RsFx0105;RsFx0105 Driver;c:\windows\system32\drivers\RsFx0105.sys [9/22/2011 6:10 PM 238696]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [9/22/2011 6:17 PM 370024]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 07084589
*NewlyCreated* - 76278505
*Deregistered* - 07084589
*Deregistered* - 76278505
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pavprsrv
slee_503_service
idebusdr
slimsvc
PAC7302
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-25 16:25]
.
2011-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-06-05 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145Core.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145UA.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-04 c:\windows\Tasks\geipcppjz.job
- c:\windows\system32\c_1257I.dll [2012-06-04 15:01]
.
2012-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-06 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2012-06-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 10.0.0.11
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-06 11:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1000)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2012-06-06 11:21:30
ComboFix-quarantined-files.txt 2012-06-06 15:21
ComboFix2.txt 2012-05-10 16:31
.
Pre-Run: 116,092,207,104 bytes free
Post-Run: 116,479,049,728 bytes free
.
- - End Of File - - DDD29D8C06C53C9211488C644A3AF295
You have ( uTorrent ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

Please select Delete this time for TDSS Killer. Post back the results in your next reply.

===================================================

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"7c37fc"=-


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

On your next reply please post :
TDSS Killer log
Combofix log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Thx again.
Followed all your instructions, including uninstalling uTorrent.

Here are my logs:

09:32:14.0986 3796 TDSS rootkit removing tool [removed] May 21 2012 16:40:16
09:32:15.0294 3796 ============================================================
09:32:15.0294 3796 Current date / time: 2012/06/07 09:32:15.0294
09:32:15.0294 3796 SystemInfo:
09:32:15.0294 3796
09:32:15.0294 3796 OS Version: 5.1.2600 ServicePack: 3.0
09:32:15.0294 3796 Product type: Workstation
09:32:15.0294 3796 ComputerName: C4LHXH1
09:32:15.0294 3796 UserName: jzipkin
09:32:15.0294 3796 Windows directory: C:\WINDOWS
09:32:15.0294 3796 System windows directory: C:\WINDOWS
09:32:15.0294 3796 Processor architecture: Intel x86
09:32:15.0294 3796 Number of processors: 2
09:32:15.0294 3796 Page size: 0x1000
09:32:15.0294 3796 Boot type: Normal boot
09:32:15.0294 3796 ============================================================
09:32:15.0479 3796 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
09:32:15.0479 3796 ============================================================
09:32:15.0479 3796 \Device\Harddisk0\DR0:
09:32:15.0479 3796 MBR partitions:
09:32:15.0479 3796 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1F608, BlocksNum 0x129F94B9
09:32:15.0479 3796 ============================================================
09:32:15.0525 3796 C: <-> \Device\Harddisk0\DR0\Partition0
09:32:15.0525 3796 ============================================================
09:32:15.0525 3796 Initialize success
09:32:15.0525 3796 ============================================================
09:32:21.0372 6832 ============================================================
09:32:21.0372 6832 Scan started
09:32:21.0372 6832 Mode: Manual; TDLFS;
09:32:21.0372 6832 ============================================================
09:32:22.0003 6832 Abiosdsk - ok
09:32:22.0049 6832 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
09:32:22.0049 6832 abp480n5 - ok
09:32:22.0064 6832 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
09:32:22.0080 6832 ACPI - ok
09:32:22.0080 6832 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
09:32:22.0080 6832 ACPIEC - ok
09:32:22.0203 6832 ACT! Scheduler (04fa07c4eed949b3ba64b536d1438130) C:\Program Files\ACT\Act for Windows\Act.Scheduler.exe
09:32:22.0203 6832 ACT! Scheduler - ok
09:32:22.0295 6832 AdobeFlashPlayerUpdateSvc (76d5a3d2a50402a0b9b6ed13c4371e79) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
09:32:22.0310 6832 AdobeFlashPlayerUpdateSvc - ok
09:32:22.0341 6832 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
09:32:22.0341 6832 adpu160m - ok
09:32:22.0387 6832 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
09:32:22.0387 6832 aec - ok
09:32:22.0418 6832 AESTAud (822d53766d57c90c437536232ece9023) C:\WINDOWS\system32\drivers\AESTAud.sys
09:32:22.0418 6832 AESTAud - ok
09:32:22.0449 6832 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
09:32:22.0449 6832 AFD - ok
09:32:22.0480 6832 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
09:32:22.0480 6832 agp440 - ok
09:32:22.0480 6832 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
09:32:22.0495 6832 agpCPQ - ok
09:32:22.0510 6832 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
09:32:22.0510 6832 Aha154x - ok
09:32:22.0526 6832 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
09:32:22.0526 6832 aic78u2 - ok
09:32:22.0541 6832 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
09:32:22.0557 6832 aic78xx - ok
09:32:22.0587 6832 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
09:32:22.0587 6832 Alerter - ok
09:32:22.0618 6832 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
09:32:22.0618 6832 ALG - ok
09:32:22.0634 6832 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
09:32:22.0634 6832 AliIde - ok
09:32:22.0649 6832 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
09:32:22.0664 6832 alim1541 - ok
09:32:22.0680 6832 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
09:32:22.0680 6832 amdagp - ok
09:32:22.0710 6832 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
09:32:22.0710 6832 amsint - ok
09:32:22.0757 6832 ApfiltrService (22403504e15810e99a563782e9d45311) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
09:32:22.0772 6832 ApfiltrService - ok
09:32:22.0941 6832 Apple Mobile Device (7ef47644b74ebe721cc32211d3c35e76) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
09:32:22.0941 6832 Apple Mobile Device - ok
09:32:22.0972 6832 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
09:32:22.0987 6832 AppMgmt - ok
09:32:23.0018 6832 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
09:32:23.0034 6832 Arp1394 - ok
09:32:23.0034 6832 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
09:32:23.0034 6832 asc - ok
09:32:23.0049 6832 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
09:32:23.0049 6832 asc3350p - ok
09:32:23.0064 6832 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
09:32:23.0064 6832 asc3550 - ok
09:32:23.0172 6832 ASFAgent (9ad6ef4d591211a93848103368125b41) C:\Program Files\Intel\ASF Agent\ASFAgent.exe
09:32:23.0203 6832 ASFAgent - ok
09:32:23.0326 6832 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
09:32:23.0326 6832 aspnet_state - ok
09:32:23.0372 6832 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
09:32:23.0372 6832 AsyncMac - ok
09:32:23.0403 6832 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
09:32:23.0418 6832 atapi - ok
09:32:23.0418 6832 Atdisk - ok
09:32:23.0449 6832 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
09:32:23.0449 6832 Atmarpc - ok
09:32:23.0495 6832 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
09:32:23.0495 6832 AudioSrv - ok
09:32:23.0511 6832 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
09:32:23.0526 6832 audstub - ok
09:32:23.0634 6832 BCM43XX (9208c78bd9283f79a30252ad954c77a2) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
09:32:23.0711 6832 BCM43XX - ok
09:32:23.0711 6832 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
09:32:23.0711 6832 Beep - ok
09:32:23.0772 6832 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
09:32:23.0880 6832 BITS - ok
09:32:23.0988 6832 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
09:32:24.0018 6832 Bonjour Service - ok
09:32:24.0034 6832 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
09:32:24.0049 6832 Browser - ok
09:32:24.0095 6832 btaudio (f688bbbe8e3e7e03e35caabd66616ddb) C:\WINDOWS\system32\drivers\btaudio.sys
09:32:24.0095 6832 btaudio - ok
09:32:24.0141 6832 BTDriver (2f9f111d31aa3fbbe5781d829a4524e6) C:\WINDOWS\system32\DRIVERS\btport.sys
09:32:24.0141 6832 BTDriver - ok
09:32:24.0234 6832 BTKRNL (38a3331e2f690d4cdc9de0604b9416e5) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
09:32:24.0280 6832 BTKRNL - ok
09:32:24.0403 6832 btwdins (d48148110ae078cb7221d0fcf20adfec) C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
09:32:24.0418 6832 btwdins - ok
09:32:24.0649 6832 BTWDNDIS (80f61de965c116051614ac2f04222ff7) C:\WINDOWS\system32\DRIVERS\btwdndis.sys
09:32:24.0649 6832 BTWDNDIS - ok
09:32:24.0665 6832 btwhid (949eca9c56f657c06d3166d51f3226c7) C:\WINDOWS\system32\DRIVERS\btwhid.sys
09:32:24.0665 6832 btwhid - ok
09:32:24.0680 6832 btwmodem (5922bae0cd84924b9cd7e6bb515ee070) C:\WINDOWS\system32\DRIVERS\btwmodem.sys
09:32:24.0680 6832 btwmodem - ok
09:32:24.0726 6832 BTWUSB (d5af663711660d32ec230c6aaf7b6b83) C:\WINDOWS\system32\Drivers\btwusb.sys
09:32:24.0726 6832 BTWUSB - ok
09:32:24.0818 6832 buttonsvc32 (4c2a9823c48882bce93e26105e1434e2) C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe
09:32:24.0849 6832 buttonsvc32 - ok
09:32:25.0018 6832 catchme - ok
09:32:25.0049 6832 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
09:32:25.0049 6832 cbidf - ok
09:32:25.0065 6832 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
09:32:25.0065 6832 cbidf2k - ok
09:32:25.0080 6832 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
09:32:25.0095 6832 CCDECODE - ok
09:32:25.0142 6832 CCIDFILTER (d006b6a67b8daed85e6d91783e9b45d6) C:\WINDOWS\system32\DRIVERS\ccidflt.sys
09:32:25.0142 6832 CCIDFILTER - ok
09:32:25.0172 6832 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
09:32:25.0188 6832 cd20xrnt - ok
09:32:25.0188 6832 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
09:32:25.0203 6832 Cdaudio - ok
09:32:25.0249 6832 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
09:32:25.0249 6832 Cdfs - ok
09:32:25.0265 6832 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
09:32:25.0311 6832 Cdrom - ok
09:32:25.0311 6832 Changer - ok
09:32:25.0357 6832 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
09:32:25.0357 6832 CiSvc - ok
09:32:25.0372 6832 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
09:32:25.0372 6832 ClipSrv - ok
09:32:25.0449 6832 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
09:32:25.0480 6832 clr_optimization_v2.0.50727_32 - ok
09:32:25.0511 6832 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
09:32:25.0511 6832 CmBatt - ok
09:32:25.0542 6832 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
09:32:25.0542 6832 CmdIde - ok
09:32:25.0572 6832 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
09:32:25.0572 6832 Compbatt - ok
09:32:25.0572 6832 COMSysApp - ok
09:32:25.0603 6832 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
09:32:25.0618 6832 Cpqarray - ok
09:32:25.0711 6832 Credential Vault Host Control Service (9d57165906778c9e5e0ecb34b311564b) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
09:32:25.0772 6832 Credential Vault Host Control Service - ok
09:32:25.0788 6832 Credential Vault Host Storage (e31e97859deee648d5867eadfbdbf25a) C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
09:32:25.0788 6832 Credential Vault Host Storage - ok
09:32:25.0819 6832 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
09:32:25.0834 6832 CryptSvc - ok
09:32:25.0865 6832 cvusbdrv (dc6429fbc73b0b0b38cc5386c8a607ed) C:\WINDOWS\system32\Drivers\cvusbdrv.sys
09:32:25.0865 6832 cvusbdrv - ok
09:32:25.0911 6832 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
09:32:25.0926 6832 dac2w2k - ok
09:32:25.0942 6832 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
09:32:25.0942 6832 dac960nt - ok
09:32:25.0988 6832 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
09:32:26.0019 6832 DcomLaunch - ok
09:32:26.0126 6832 dcpsysmgrsvc (ce597e34d62c603871e2f2f5155a88e5) C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe
09:32:26.0157 6832 dcpsysmgrsvc - ok
09:32:26.0219 6832 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
09:32:26.0219 6832 Dhcp - ok
09:32:26.0249 6832 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
09:32:26.0249 6832 Disk - ok
09:32:26.0249 6832 dmadmin - ok
09:32:26.0372 6832 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
09:32:26.0403 6832 dmboot - ok
09:32:26.0434 6832 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
09:32:26.0434 6832 dmio - ok
09:32:26.0465 6832 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
09:32:26.0465 6832 dmload - ok
09:32:26.0480 6832 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
09:32:26.0480 6832 dmserver - ok
09:32:26.0511 6832 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
09:32:26.0511 6832 DMusic - ok
09:32:26.0542 6832 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
09:32:26.0542 6832 Dnscache - ok
09:32:26.0557 6832 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
09:32:26.0572 6832 Dot3svc - ok
09:32:26.0572 6832 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
09:32:26.0588 6832 dpti2o - ok
09:32:26.0588 6832 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
09:32:26.0588 6832 drmkaud - ok
09:32:26.0634 6832 e1yexpress (71ff7ad30bd9e3c06df112383bb60089) C:\WINDOWS\system32\DRIVERS\e1y5132.sys
09:32:26.0649 6832 e1yexpress - ok
09:32:26.0680 6832 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
09:32:26.0680 6832 EapHost - ok
09:32:26.0696 6832 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
09:32:26.0711 6832 ERSvc - ok
09:32:26.0742 6832 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
09:32:26.0757 6832 Eventlog - ok
09:32:26.0788 6832 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
09:32:26.0803 6832 EventSystem - ok
09:32:26.0865 6832 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
09:32:26.0865 6832 Fastfat - ok
09:32:26.0911 6832 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
09:32:26.0926 6832 FastUserSwitchingCompatibility - ok
09:32:26.0957 6832 Fax (e97d6a8684466df94ff3bc24fb787a07) C:\WINDOWS\system32\fxssvc.exe
09:32:26.0988 6832 Fax - ok
09:32:27.0019 6832 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
09:32:27.0019 6832 Fdc - ok
09:32:27.0034 6832 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
09:32:27.0034 6832 Fips - ok
09:32:27.0157 6832 FLEXnet Licensing Service (f76d04f7413b07daa029f6520b64b4e8) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
09:32:27.0219 6832 FLEXnet Licensing Service - ok
09:32:27.0234 6832 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
09:32:27.0249 6832 Flpydisk - ok
09:32:27.0280 6832 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
09:32:27.0280 6832 FltMgr - ok
09:32:27.0373 6832 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
09:32:27.0388 6832 FontCache3.0.0.0 - ok
09:32:27.0403 6832 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
09:32:27.0419 6832 Fs_Rec - ok
09:32:27.0434 6832 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
09:32:27.0434 6832 Ftdisk - ok
09:32:27.0465 6832 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
09:32:27.0465 6832 GEARAspiWDM - ok
09:32:27.0496 6832 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
09:32:27.0496 6832 Gpc - ok
09:32:27.0542 6832 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
09:32:27.0542 6832 gupdate - ok
09:32:27.0557 6832 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files\Google\Update\GoogleUpdate.exe
09:32:27.0557 6832 gupdatem - ok
09:32:27.0588 6832 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
09:32:27.0588 6832 HDAudBus - ok
09:32:27.0680 6832 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
09:32:27.0680 6832 helpsvc - ok
09:32:27.0711 6832 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
09:32:27.0711 6832 HidServ - ok
09:32:27.0726 6832 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
09:32:27.0742 6832 hidusb - ok
09:32:27.0757 6832 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
09:32:27.0773 6832 hkmsvc - ok
09:32:27.0788 6832 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
09:32:27.0788 6832 hpn - ok
09:32:27.0834 6832 HPSIService (a9d667f5308982a3305f364eb02458d0) C:\WINDOWS\system32\HPSIsvc.exe
09:32:27.0834 6832 HPSIService - ok
09:32:27.0880 6832 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
09:32:27.0896 6832 HTTP - ok
09:32:27.0942 6832 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
09:32:27.0942 6832 HTTPFilter - ok
09:32:27.0973 6832 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
09:32:27.0973 6832 i2omgmt - ok
09:32:27.0988 6832 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
09:32:28.0003 6832 i2omp - ok
09:32:28.0034 6832 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
09:32:28.0034 6832 i8042prt - ok
09:32:28.0096 6832 iaStor (26541a068572f650a2fa490726fe81be) C:\WINDOWS\system32\drivers\iaStor.sys
09:32:28.0111 6832 iaStor - ok
09:32:28.0265 6832 IAStorDataMgrSvc (31a0e93cdf29007d6c6fffb632f375ed) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
09:32:28.0265 6832 IAStorDataMgrSvc - ok
09:32:28.0265 6832 idebusdr - ok
09:32:28.0465 6832 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
09:32:28.0527 6832 idsvc - ok
09:32:28.0588 6832 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
09:32:28.0588 6832 Imapi - ok
09:32:28.0619 6832 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
09:32:28.0634 6832 ImapiService - ok
09:32:28.0650 6832 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
09:32:28.0665 6832 ini910u - ok
09:32:28.0680 6832 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
09:32:28.0680 6832 IntelIde - ok
09:32:28.0711 6832 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
09:32:28.0711 6832 intelppm - ok
09:32:28.0727 6832 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
09:32:28.0742 6832 Ip6Fw - ok
09:32:28.0742 6832 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
09:32:28.0757 6832 IpFilterDriver - ok
09:32:28.0773 6832 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
09:32:28.0773 6832 IpInIp - ok
09:32:28.0803 6832 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
09:32:28.0803 6832 IpNat - ok
09:32:28.0942 6832 iPod Service (57edb35ea2feca88f8b17c0c095c9a56) C:\Program Files\iPod\bin\iPodService.exe
09:32:29.0003 6832 iPod Service - ok
09:32:29.0019 6832 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
09:32:29.0034 6832 IPSec - ok
09:32:29.0050 6832 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
09:32:29.0050 6832 IRENUM - ok
09:32:29.0096 6832 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
09:32:29.0096 6832 isapnp - ok
09:32:29.0173 6832 JavaQuickStarterService (5472d771c0197355c1d347f20392b982) C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
09:32:29.0173 6832 JavaQuickStarterService - ok
09:32:29.0204 6832 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
09:32:29.0204 6832 Kbdclass - ok
09:32:29.0219 6832 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
09:32:29.0219 6832 kbdhid - ok
09:32:29.0280 6832 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
09:32:29.0280 6832 kmixer - ok
09:32:29.0311 6832 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
09:32:29.0311 6832 KSecDD - ok
09:32:29.0342 6832 LanmanServer (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
09:32:29.0357 6832 LanmanServer - ok
09:32:29.0373 6832 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
09:32:29.0388 6832 lanmanworkstation - ok
09:32:29.0419 6832 LBeepKE (ca63fe81705ad660e482bef210bf2c73) C:\WINDOWS\system32\Drivers\LBeepKE.sys
09:32:29.0419 6832 LBeepKE - ok
09:32:29.0434 6832 lbrtfdc - ok
09:32:29.0634 6832 LBTServ (ab097d0f93b30a6d79d430422ac6a7e8) C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
09:32:29.0665 6832 LBTServ - ok
09:32:29.0696 6832 LHidFilt (b68309f25c5787385da842eb5b496958) C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
09:32:29.0711 6832 LHidFilt - ok
09:32:29.0727 6832 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
09:32:29.0727 6832 LmHosts - ok
09:32:29.0757 6832 LMouFilt (63d3b1d3cd267fcc186a0146b80d453b) C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
09:32:29.0757 6832 LMouFilt - ok
09:32:29.0757 6832 MBAMSwissArmy - ok
09:32:29.0834 6832 McAfee SiteAdvisor Enterprise Service (4f2d526298cbc517edb82501e8041112) C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
09:32:29.0850 6832 McAfee SiteAdvisor Enterprise Service - ok
09:32:29.0927 6832 McShield (1fe222eaf4ba73ced5a0707b38f3c0b1) C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
09:32:29.0927 6832 McShield - ok
09:32:29.0957 6832 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
09:32:29.0957 6832 Messenger - ok
09:32:30.0004 6832 mfeapfk (37364b530339ff0b0ababc8df1c532c3) C:\WINDOWS\system32\drivers\mfeapfk.sys
09:32:30.0019 6832 mfeapfk - ok
09:32:30.0034 6832 MfeAVFK (cd2a8a43bd6b0d15a3255829b1778285) C:\WINDOWS\system32\drivers\mfeavfk.sys
09:32:30.0050 6832 MfeAVFK - ok
09:32:30.0050 6832 mfeavfk01 - ok
09:32:30.0065 6832 MfeBOPK (2cd52e91ba338f10ba14d3f90bbda5e8) C:\WINDOWS\system32\drivers\mfebopk.sys
09:32:30.0065 6832 MfeBOPK - ok
09:32:30.0111 6832 mfehidk (cf669582f5f98c4ba79d59cfe169198b) C:\WINDOWS\system32\drivers\mfehidk.sys
09:32:30.0142 6832 mfehidk - ok
09:32:30.0173 6832 mferkdet (42f84c2a82a057d74c54ef70e0cf0a2c) C:\WINDOWS\system32\drivers\mferkdet.sys
09:32:30.0173 6832 mferkdet - ok
09:32:30.0219 6832 MfeRKDK (820d6aa3f7f0cfa8a1fa8f63d3f1df04) C:\WINDOWS\system32\drivers\MfeRKDK.sys
09:32:30.0219 6832 MfeRKDK - ok
09:32:30.0219 6832 mfetdi2k (03b2b8bd4d0a2d3636be9248b5dce33a) C:\WINDOWS\system32\drivers\mfetdi2k.sys
09:32:30.0219 6832 mfetdi2k - ok
09:32:30.0250 6832 mfetdik (3812e49fa67a3f604895f0d0c2e1ef90) C:\WINDOWS\system32\drivers\mfetdik.sys
09:32:30.0265 6832 mfetdik - ok
09:32:30.0311 6832 mfevtp (5339baac5c43ddbdb448863f8ea8fcdc) C:\WINDOWS\system32\mfevtps.exe
09:32:30.0327 6832 mfevtp - ok
09:32:30.0358 6832 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
09:32:30.0358 6832 mnmdd - ok
09:32:30.0388 6832 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
09:32:30.0388 6832 mnmsrvc - ok
09:32:30.0419 6832 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
09:32:30.0434 6832 Modem - ok
09:32:30.0465 6832 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
09:32:30.0481 6832 Mouclass - ok
09:32:30.0496 6832 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
09:32:30.0511 6832 mouhid - ok
09:32:30.0527 6832 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
09:32:30.0527 6832 MountMgr - ok
09:32:30.0558 6832 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
09:32:30.0558 6832 mraid35x - ok
09:32:30.0588 6832 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
09:32:30.0588 6832 MRxDAV - ok
09:32:30.0650 6832 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
09:32:30.0665 6832 MRxSmb - ok
09:32:30.0711 6832 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
09:32:30.0711 6832 MSDTC - ok
09:32:30.0742 6832 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
09:32:30.0758 6832 Msfs - ok
09:32:30.0758 6832 MSIServer - ok
09:32:30.0788 6832 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
09:32:30.0804 6832 MSKSSRV - ok
09:32:30.0804 6832 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
09:32:30.0819 6832 MSPCLOCK - ok
09:32:30.0819 6832 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
09:32:30.0819 6832 MSPQM - ok
09:32:30.0819 6832 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
09:32:30.0819 6832 mssmbios - ok
09:32:31.0050 6832 MSSQL$ACT7 - ok
09:32:31.0096 6832 MSSQL$SQLEXPRESS - ok
09:32:31.0142 6832 MSSQLServerADHelper (1d89eb4e2a99cabd4e81225f4f4c4b25) C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
09:32:31.0142 6832 MSSQLServerADHelper - ok
09:32:31.0235 6832 MSSQLServerADHelper100 (f1761c8fb2b25a32c6d63e36bb88c3ae) c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE
09:32:31.0235 6832 MSSQLServerADHelper100 - ok
09:32:31.0265 6832 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
09:32:31.0265 6832 MSTEE - ok
09:32:31.0358 6832 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
09:32:31.0388 6832 Mup - ok
09:32:31.0496 6832 myAgtSvc (a35ab0a7a983ebca85805da63d763382) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
09:32:31.0527 6832 myAgtSvc - ok
09:32:31.0558 6832 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
09:32:31.0558 6832 NABTSFEC - ok
09:32:31.0604 6832 NAL (1d99ac4ce3abbd96a8c0d77ff104096d) C:\WINDOWS\system32\Drivers\iqvw32.sys
09:32:31.0619 6832 NAL - ok
09:32:31.0650 6832 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
09:32:31.0650 6832 napagent - ok
09:32:31.0696 6832 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
09:32:31.0696 6832 NDIS - ok
09:32:31.0712 6832 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
09:32:31.0727 6832 NdisIP - ok
09:32:31.0758 6832 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
09:32:31.0758 6832 NdisTapi - ok
09:32:31.0773 6832 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
09:32:31.0773 6832 Ndisuio - ok
09:32:31.0788 6832 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
09:32:31.0788 6832 NdisWan - ok
09:32:31.0819 6832 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
09:32:31.0819 6832 NDProxy - ok
09:32:31.0835 6832 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
09:32:31.0835 6832 NetBIOS - ok
09:32:31.0865 6832 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
09:32:31.0865 6832 NetBT - ok
09:32:31.0912 6832 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
09:32:31.0912 6832 NetDDE - ok
09:32:31.0912 6832 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
09:32:31.0912 6832 NetDDEdsdm - ok
09:32:31.0942 6832 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
09:32:31.0958 6832 Netlogon - ok
09:32:32.0004 6832 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
09:32:32.0019 6832 Netman - ok
09:32:32.0112 6832 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
09:32:32.0127 6832 NetTcpPortSharing - ok
09:32:32.0158 6832 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
09:32:32.0158 6832 NIC1394 - ok
09:32:32.0219 6832 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
09:32:32.0219 6832 Nla - ok
09:32:32.0235 6832 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
09:32:32.0235 6832 Npfs - ok
09:32:32.0327 6832 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
09:32:32.0358 6832 Ntfs - ok
09:32:32.0358 6832 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
09:32:32.0373 6832 NtLmSsp - ok
09:32:32.0435 6832 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
09:32:32.0450 6832 NtmsSvc - ok
09:32:32.0496 6832 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
09:32:32.0496 6832 Null - ok
09:32:33.0019 6832 nv (2e095f4f396f7106a5f1d8b00ec00d4f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
09:32:33.0389 6832 nv - ok
09:32:33.0589 6832 nvsvc (328acce9c643fe050a4143fe3ec3c025) C:\WINDOWS\system32\nvsvc32.exe
09:32:33.0604 6832 nvsvc - ok
09:32:33.0681 6832 NWADI (fc2a8aaa0f3321f41231ede0af1968ae) C:\WINDOWS\system32\DRIVERS\NWADIenum.sys
09:32:33.0696 6832 NWADI - ok
09:32:33.0696 6832 nwcworkstation - ok
09:32:33.0727 6832 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
09:32:33.0727 6832 NwlnkFlt - ok
09:32:33.0743 6832 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
09:32:33.0743 6832 NwlnkFwd - ok
09:32:33.0773 6832 NWUSBCDFIL (224131778c92aee8c13afac5fbff19ca) C:\WINDOWS\system32\DRIVERS\NwUsbCdFil.sys
09:32:33.0773 6832 NWUSBCDFIL - ok
09:32:33.0819 6832 NWUSBModem (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys
09:32:33.0819 6832 NWUSBModem - ok
09:32:33.0850 6832 NWUSBPort (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbser.sys
09:32:33.0850 6832 NWUSBPort - ok
09:32:33.0881 6832 NWUSBPort2 (b7112f30d7eff4b5052eba879f46228f) C:\WINDOWS\system32\DRIVERS\nwusbser2.sys
09:32:33.0896 6832 NWUSBPort2 - ok
09:32:33.0958 6832 OA001Afx (0f538df1673e5216f3baacb6911d9d0f) C:\WINDOWS\system32\Drivers\OA001Afx.sys
09:32:33.0973 6832 OA001Afx - ok
09:32:34.0004 6832 OA001Ufd (2cf21d5f8f1b74bb1922135ac2b12ddb) C:\WINDOWS\system32\DRIVERS\OA001Ufd.sys
09:32:34.0004 6832 OA001Ufd - ok
09:32:34.0035 6832 OA001Vid (159e5a08a6a5231863cddbd787a4eabb) C:\WINDOWS\system32\DRIVERS\OA001Vid.sys
09:32:34.0050 6832 OA001Vid - ok
09:32:34.0204 6832 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
09:32:34.0219 6832 odserv - ok
09:32:34.0266 6832 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
09:32:34.0266 6832 ohci1394 - ok
09:32:34.0343 6832 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:32:34.0358 6832 ose - ok
09:32:34.0389 6832 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
09:32:34.0389 6832 Parport - ok
09:32:34.0404 6832 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
09:32:34.0404 6832 PartMgr - ok
09:32:34.0420 6832 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
09:32:34.0435 6832 ParVdm - ok
09:32:34.0435 6832 pavprsrv - ok
09:32:34.0435 6832 PBADRV (4088c1ecd1f54281a92fa663b0fdc36f) C:\WINDOWS\system32\DRIVERS\PBADRV.sys
09:32:34.0435 6832 PBADRV - ok
09:32:34.0466 6832 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\PCASp50.sys
09:32:34.0466 6832 PCASp50 - ok
09:32:34.0481 6832 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
09:32:34.0481 6832 PCI - ok
09:32:34.0496 6832 PCIDump - ok
09:32:34.0558 6832 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
09:32:34.0558 6832 PCIIde - ok
09:32:34.0589 6832 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
09:32:34.0589 6832 Pcmcia - ok
09:32:34.0604 6832 PDCOMP - ok
09:32:34.0604 6832 PDFRAME - ok
09:32:34.0620 6832 PDRELI - ok
09:32:34.0620 6832 PDRFRAME - ok
09:32:34.0635 6832 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
09:32:34.0635 6832 perc2 - ok
09:32:34.0650 6832 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
09:32:34.0650 6832 perc2hib - ok
09:32:34.0696 6832 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
09:32:34.0696 6832 PlugPlay - ok
09:32:34.0727 6832 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
09:32:34.0727 6832 PolicyAgent - ok
09:32:34.0758 6832 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
09:32:34.0758 6832 PptpMiniport - ok
09:32:34.0773 6832 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
09:32:34.0773 6832 ProtectedStorage - ok
09:32:34.0789 6832 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
09:32:34.0789 6832 PSched - ok
09:32:34.0866 6832 PSI_SVC_2 (e0d0cb09aa07b22be984e4f7ec0326f5) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
09:32:34.0866 6832 PSI_SVC_2 - ok
09:32:34.0896 6832 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
09:32:34.0896 6832 Ptilink - ok
09:32:34.0912 6832 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
09:32:34.0927 6832 ql1080 - ok
09:32:34.0943 6832 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
09:32:34.0943 6832 Ql10wnt - ok
09:32:34.0973 6832 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
09:32:34.0973 6832 ql12160 - ok
09:32:34.0989 6832 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
09:32:34.0989 6832 ql1240 - ok
09:32:35.0004 6832 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
09:32:35.0004 6832 ql1280 - ok
09:32:35.0035 6832 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
09:32:35.0035 6832 RasAcd - ok
09:32:35.0066 6832 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
09:32:35.0066 6832 RasAuto - ok
09:32:35.0097 6832 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
09:32:35.0097 6832 Rasl2tp - ok
09:32:35.0127 6832 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
09:32:35.0158 6832 RasMan - ok
09:32:35.0158 6832 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
09:32:35.0158 6832 RasPppoe - ok
09:32:35.0173 6832 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
09:32:35.0173 6832 Raspti - ok
09:32:35.0220 6832 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
09:32:35.0235 6832 Rdbss - ok
09:32:35.0266 6832 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
09:32:35.0281 6832 RDPCDD - ok
09:32:35.0312 6832 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
09:32:35.0343 6832 rdpdr - ok
09:32:35.0389 6832 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
09:32:35.0389 6832 RDPWD - ok
09:32:35.0420 6832 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
09:32:35.0435 6832 RDSessMgr - ok
09:32:35.0481 6832 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
09:32:35.0481 6832 redbook - ok
09:32:35.0512 6832 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
09:32:35.0512 6832 RemoteAccess - ok
09:32:35.0543 6832 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
09:32:35.0558 6832 RemoteRegistry - ok
09:32:35.0589 6832 rimmptsk (ea885e7a56f1be1f14c372337c42fe48) C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
09:32:35.0589 6832 rimmptsk - ok
09:32:35.0650 6832 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
09:32:35.0666 6832 RpcLocator - ok
09:32:35.0712 6832 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
09:32:35.0727 6832 RpcSs - ok
09:32:35.0789 6832 RsFx0105 (6a7360e36cbd636972aeef0dd292a946) C:\WINDOWS\system32\DRIVERS\RsFx0105.sys
09:32:35.0804 6832 RsFx0105 - ok
09:32:35.0835 6832 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
09:32:35.0850 6832 RSVP - ok
09:32:35.0989 6832 RumorServer (a35ab0a7a983ebca85805da63d763382) C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
09:32:35.0989 6832 RumorServer - ok
09:32:36.0035 6832 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
09:32:36.0035 6832 SamSs - ok
09:32:36.0081 6832 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
09:32:36.0097 6832 SCardSvr - ok
09:32:36.0127 6832 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
09:32:36.0143 6832 Schedule - ok
09:32:36.0204 6832 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
09:32:36.0204 6832 sdbus - ok
09:32:36.0204 6832 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
09:32:36.0204 6832 Secdrv - ok
09:32:36.0235 6832 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
09:32:36.0235 6832 seclogon - ok
09:32:36.0343 6832 SecureStorageService (e80163f46ae96cc0a05fb9f3f55deb18) C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
09:32:36.0389 6832 SecureStorageService - ok
09:32:36.0420 6832 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
09:32:36.0420 6832 SENS - ok
09:32:36.0466 6832 Sentinel (8627c992b8a80504fc477b2e8ff8ec4f) C:\WINDOWS\System32\Drivers\SENTINEL.SYS
09:32:36.0466 6832 Sentinel - ok
09:32:36.0497 6832 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
09:32:36.0497 6832 Serenum - ok
09:32:36.0527 6832 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
09:32:36.0527 6832 Serial - ok
09:32:36.0574 6832 sermouse (1f16931c722c69e4a7866244796c66a0) C:\WINDOWS\system32\DRIVERS\sermouse.sys
09:32:36.0574 6832 sermouse - ok
09:32:36.0589 6832 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
09:32:36.0589 6832 sffdisk - ok
09:32:36.0604 6832 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
09:32:36.0604 6832 sffp_sd - ok
09:32:36.0620 6832 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
09:32:36.0620 6832 Sfloppy - ok
09:32:36.0681 6832 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
09:32:36.0697 6832 SharedAccess - ok
09:32:36.0743 6832 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
09:32:36.0743 6832 ShellHWDetection - ok
09:32:36.0758 6832 Simbad - ok
09:32:36.0835 6832 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
09:32:36.0835 6832 sisagp - ok
09:32:36.0835 6832 slee_503_service - ok
09:32:36.0866 6832 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
09:32:36.0866 6832 SLIP - ok
09:32:37.0143 6832 SMManager (24d62fc9201d172f69c47355d185213b) C:\Program Files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe
09:32:37.0143 6832 SMManager - ok
09:32:37.0220 6832 SMSIVZAM5 (1e715247efffdda938c085913045d599) C:\PROGRA~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS
09:32:37.0235 6832 SMSIVZAM5 - ok
09:32:37.0281 6832 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
09:32:37.0297 6832 Sparrow - ok
09:32:37.0328 6832 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
09:32:37.0328 6832 splitter - ok
09:32:37.0420 6832 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
09:32:37.0451 6832 Spooler - ok
09:32:37.0728 6832 SQLAgent$SQLEXPRESS (a892134c28777978ecde8283dc57ac0f) c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE
09:32:37.0758 6832 SQLAgent$SQLEXPRESS - ok
09:32:38.0143 6832 SQLBrowser (10d936dced9eacd1a1b3fcdda6d7a4eb) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
09:32:38.0158 6832 SQLBrowser - ok
09:32:38.0205 6832 SQLWriter (135cdccc167ef0c250125bbd3abe18d5) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
09:32:38.0205 6832 SQLWriter - ok
09:32:38.0266 6832 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
09:32:38.0266 6832 sr - ok
09:32:38.0312 6832 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
09:32:38.0343 6832 srservice - ok
09:32:39.0189 6832 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
09:32:39.0220 6832 Srv - ok
09:32:39.0512 6832 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
09:32:39.0512 6832 SSDPSRV - ok
09:32:39.0620 6832 STacSV (0a8fa56553913e87aa24a6ce218b88de) c:\drivers\audio\r267815\payload\wdm\stacsv.exe
09:32:39.0635 6832 STacSV - ok
09:32:39.0789 6832 STHDA (c111965a8dbd00768787d807ec3113ff) C:\WINDOWS\system32\drivers\sthda.sys
09:32:39.0866 6832 STHDA - ok
09:32:40.0020 6832 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
09:32:40.0036 6832 stisvc - ok
09:32:40.0128 6832 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
09:32:40.0128 6832 streamip - ok
09:32:40.0159 6832 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
09:32:40.0159 6832 swenum - ok
09:32:40.0174 6832 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
09:32:40.0174 6832 swmidi - ok
09:32:40.0205 6832 SwPrv - ok
09:32:40.0205 6832 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
09:32:40.0220 6832 symc810 - ok
09:32:40.0220 6832 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
09:32:40.0236 6832 symc8xx - ok
09:32:40.0236 6832 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
09:32:40.0251 6832 sym_hi - ok
09:32:40.0266 6832 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
09:32:40.0266 6832 sym_u3 - ok
09:32:40.0297 6832 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
09:32:40.0328 6832 sysaudio - ok
09:32:40.0374 6832 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
09:32:40.0389 6832 SysmonLog - ok
09:32:40.0420 6832 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
09:32:40.0451 6832 TapiSrv - ok
09:32:40.0513 6832 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
09:32:40.0528 6832 Tcpip - ok
09:32:40.0713 6832 tcsd_win32.exe (ba9202e263a6fc1ffd7889fea186a2c4) C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
09:32:40.0774 6832 tcsd_win32.exe - ok
09:32:40.0913 6832 TdmService (ea63bf38938ad9917beb1846d6d15c84) C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
09:32:40.0959 6832 TdmService - ok
09:32:41.0420 6832 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
09:32:41.0420 6832 TDPIPE - ok
09:32:41.0528 6832 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
09:32:41.0528 6832 TDTCP - ok
09:32:41.0590 6832 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
09:32:41.0605 6832 TermDD - ok
09:32:42.0328 6832 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
09:32:42.0374 6832 TermService - ok
09:32:42.0467 6832 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
09:32:42.0482 6832 Themes - ok
09:32:42.0513 6832 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe
09:32:42.0528 6832 TlntSvr - ok
09:32:42.0544 6832 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
09:32:42.0544 6832 TosIde - ok
09:32:42.0559 6832 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
09:32:42.0574 6832 TrkWks - ok
09:32:42.0620 6832 TrmbTS (5070590587118b2960e14927b4393d32) C:\WINDOWS\system32\Drivers\TrmbTS.sys
09:32:42.0636 6832 TrmbTS - ok
09:32:42.0636 6832 TRMUSB5K - ok
09:32:42.0697 6832 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
09:32:42.0697 6832 Udfs - ok
09:32:42.0728 6832 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
09:32:42.0728 6832 ultra - ok
09:32:42.0774 6832 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
09:32:42.0805 6832 Update - ok
09:32:42.0836 6832 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
09:32:42.0851 6832 upnphost - ok
09:32:42.0882 6832 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
09:32:42.0882 6832 UPS - ok
09:32:42.0974 6832 USA19H (6d1e41657fdb48f9147598c773297513) C:\WINDOWS\system32\DRIVERS\USA19H2k.sys
09:32:43.0051 6832 USA19H - ok
09:32:43.0067 6832 USA19H2KP (8a217fc16dd14ab8ad2eaa1f08b3b5c5) C:\WINDOWS\system32\DRIVERS\USA19H2kp.SYS
09:32:43.0067 6832 USA19H2KP - ok
09:32:43.0128 6832 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\WINDOWS\system32\Drivers\usbaapl.sys
09:32:43.0128 6832 USBAAPL - ok
09:32:43.0174 6832 usbccgp (c18d6c74953621346df6b0a11f80c1cc) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
09:32:43.0174 6832 usbccgp - ok
09:32:43.0221 6832 USBCCID (150442fa5224dc338028543e2fffa7b4) C:\WINDOWS\system32\DRIVERS\usbccid.sys
09:32:43.0221 6832 USBCCID - ok
09:32:43.0267 6832 usbehci (4bac8df07f1d8434fc640e677a62204e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
09:32:43.0267 6832 usbehci - ok
09:32:43.0282 6832 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
09:32:43.0282 6832 usbhub - ok
09:32:43.0313 6832 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
09:32:43.0328 6832 usbprint - ok
09:32:43.0359 6832 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
09:32:43.0359 6832 usbscan - ok
09:32:43.0421 6832 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
09:32:43.0421 6832 USBSTOR - ok
09:32:43.0421 6832 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
09:32:43.0436 6832 usbuhci - ok
09:32:43.0482 6832 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
09:32:43.0482 6832 usbvideo - ok
09:32:43.0528 6832 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
09:32:43.0528 6832 usb_rndisx - ok
09:32:43.0574 6832 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
09:32:43.0574 6832 VgaSave - ok
09:32:43.0590 6832 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
09:32:43.0605 6832 viaagp - ok
09:32:43.0621 6832 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
09:32:43.0621 6832 ViaIde - ok
09:32:43.0651 6832 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
09:32:43.0651 6832 VolSnap - ok
09:32:43.0698 6832 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
09:32:43.0728 6832 VSS - ok
09:32:43.0744 6832 w32time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
09:32:43.0759 6832 w32time - ok
09:32:43.0774 6832 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
09:32:43.0790 6832 Wanarp - ok
09:32:43.0821 6832 WavxDMgr (0be8dd6c95c5bdff9c5f3fa8095d304c) C:\WINDOWS\system32\DRIVERS\WavxDMgr.sys
09:32:43.0836 6832 WavxDMgr - ok
09:32:43.0882 6832 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
09:32:43.0882 6832 wceusbsh - ok
09:32:43.0959 6832 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys
09:32:43.0974 6832 Wdf01000 - ok
09:32:43.0974 6832 WDICA - ok
09:32:43.0990 6832 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
09:32:44.0021 6832 wdmaud - ok
09:32:44.0067 6832 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
09:32:44.0067 6832 WebClient - ok
09:32:44.0082 6832 WinDriver6 - ok
09:32:44.0174 6832 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
09:32:44.0174 6832 winmgmt - ok
09:32:44.0267 6832 WinRM (18f347402da544a780949b8fdf83351b) C:\WINDOWS\system32\WsmSvc.dll
09:32:44.0328 6832 WinRM - ok
09:32:44.0375 6832 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
09:32:44.0375 6832 WmdmPmSN - ok
09:32:44.0451 6832 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
09:32:44.0513 6832 Wmi - ok
09:32:44.0605 6832 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
09:32:44.0605 6832 WmiAcpi - ok
09:32:44.0667 6832 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
09:32:44.0667 6832 WmiApSrv - ok
09:32:45.0313 6832 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
09:32:45.0344 6832 WMPNetworkSvc - ok
09:32:45.0359 6832 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
09:32:45.0375 6832 WS2IFSL - ok
09:32:45.0405 6832 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
09:32:45.0405 6832 wscsvc - ok
09:32:45.0436 6832 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
09:32:45.0436 6832 WSTCODEC - ok
09:32:45.0452 6832 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
09:32:45.0452 6832 wuauserv - ok
09:32:45.0498 6832 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
09:32:45.0513 6832 WudfPf - ok
09:32:45.0528 6832 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
09:32:45.0528 6832 WudfRd - ok
09:32:45.0559 6832 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
09:32:45.0559 6832 WudfSvc - ok
09:32:45.0621 6832 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
09:32:45.0652 6832 WZCSVC - ok
09:32:45.0682 6832 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
09:32:45.0682 6832 xmlprov - ok
09:32:45.0790 6832 XobniService (986c5b8f380f7408ecee96c3c5dbf66c) C:\Program Files\Xobni\XobniService.exe
09:32:45.0805 6832 XobniService - ok
09:32:45.0898 6832 YahooAUService (dd0042f0c3b606a6a8b92d49afb18ad6) C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
09:32:45.0898 6832 YahooAUService - ok
09:32:46.0067 6832 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
09:32:46.0575 6832 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
09:32:46.0575 6832 \Device\Harddisk0\DR0 - detected TDSS File System (1)
09:32:46.0575 6832 Boot (0x1200) (1164849f2816b8faac91ba9894555e1e) \Device\Harddisk0\DR0\Partition0
09:32:46.0590 6832 \Device\Harddisk0\DR0\Partition0 - ok
09:32:46.0590 6832 ============================================================
09:32:46.0590 6832 Scan finished
09:32:46.0590 6832 ============================================================
09:32:46.0590 4976 Detected object count: 1
09:32:46.0590 4976 Actual detected object count: 1
09:32:50.0975 4976 \Device\Harddisk0\DR0\TDLFS\phm - copied to quarantine
09:32:50.0975 4976 \Device\Harddisk0\DR0\TDLFS\phs - copied to quarantine
09:32:51.0006 4976 \Device\Harddisk0\DR0\TDLFS\ph.dll - copied to quarantine
09:32:51.0021 4976 \Device\Harddisk0\DR0\TDLFS\phdata - copied to quarantine
09:32:51.0021 4976 \Device\Harddisk0\DR0\TDLFS\phld - copied to quarantine
09:32:51.0021 4976 \Device\Harddisk0\DR0\TDLFS\phln - copied to quarantine
09:32:51.0021 4976 \Device\Harddisk0\DR0\TDLFS - deleted
09:32:51.0021 4976 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete


ComboFix 12-06-07.03 - jzipkin 06/07/2012 9:38.12.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.2593 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jzipkin\Desktop\CFScript.txt
AV: McAfee® Security-as-a-Service Anti-virus *Disabled/Updated* {8C354827-2F54-4E28-90DC-AD391E77808C}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\8615B8621C.sys
.
.
((((((((((((((((((((((((( Files Created from 2012-05-07 to 2012-06-07 )))))))))))))))))))))))))))))))
.
.
2012-06-04 15:01 . 2012-06-04 15:01 163840 –sha-r- c:\windows\system32\c_1257I.dll
2012-05-25 15:49 . 2011-09-29 18:20 484352 —-a-w- c:\windows\system32\lame_enc.dll
2012-05-25 15:28 . 2009-05-18 17:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-05-25 15:28 . 2008-04-17 16:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2012-05-25 15:27 . 2012-05-25 15:27 ——– d—–w- c:\program files\iPod
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\program files\iTunes
2012-05-25 15:27 . 2012-05-25 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2012-05-25 15:26 . 2012-05-25 15:26 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2012-05-25 15:26 . 2012-02-15 15:01 4547944 —-a-w- c:\windows\system32\usbaaplrc.dll
2012-05-25 15:26 . 2012-02-15 15:01 43520 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2012-05-25 15:20 . 2012-05-25 15:20 ——– d—–w- c:\program files\Bonjour
2012-05-14 20:49 . 2012-05-14 20:49 ——– d—–w- c:\documents and settings\JZipkin\Application Data\Unity
2012-05-14 19:48 . 2012-05-14 19:48 ——– d—–w- c:\documents and settings\JZipkin\Local Settings\Application Data\Unity
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-05-11 15:48 . 2012-05-11 15:48 159744 —-a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-05-11 15:47 . 2012-05-11 15:48 ——– d—–w- c:\program files\QuickTime
2012-05-11 15:47 . 2012-05-25 15:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2012-05-09 19:47 . 2010-04-05 09:19 3354624 —-a-w- c:\windows\system32\stlang.dll
2012-05-09 19:47 . 2010-04-05 09:18 11870298 —-a-w- c:\windows\system32\idtsg.cpl
2012-05-09 19:47 . 2010-04-05 09:18 253952 —-a-w- c:\windows\system32\AESTCtrl.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-07 13:25 . 2010-07-26 18:14 1994 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2012-06-04 13:10 . 2010-07-23 18:20 0 —-a-w- c:\documents and settings\JZipkin\Local Settings\Application Data\WavXMapDrive.bat
2012-05-09 16:25 . 2012-04-25 13:45 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-09 16:25 . 2011-06-29 15:20 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-27 02:53 . 2008-04-25 16:16 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2012-04-26 17:04 . 2012-04-26 17:05 388608 —-a-w- C:\HiJackThis.exe
2012-04-04 22:47 . 2012-04-30 15:32 143872 —-a-w- c:\windows\system32\javacpl.cpl
2012-04-04 22:47 . 2012-04-30 15:32 772504 —-a-w- c:\windows\system32\npDeployJava1.dll
2012-04-04 22:47 . 2010-07-22 17:11 687504 —-a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-06-06_15.19.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-06-06 20:58 . 2012-06-07 13:36 18634 c:\windows\SoftwareDistribution\EventCache\{CFB0530A-5AF7-4F21-A794-9E8B513068B3}.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-03-21 1523512]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{022F2F51-CDDA-4873-8A29-72C66C808A3F}"
[HKEY_CLASSES_ROOT\CLSID\{022F2F51-CDDA-4873-8A29-72C66C808A3F}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{661963C1-99A1-44e7-A671-1CF3768AE9D4}"
[HKEY_CLASSES_ROOT\CLSID\{661963C1-99A1-44e7-A671-1CF3768AE9D4}]
2009-11-07 05:07 297808 ——w- c:\windows\system32\mscoree.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Facebook Update"="c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" [2011-10-21 137536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2010-04-05 737280]
"nwiz"="nwiz.exe" [2009-12-15 1657448]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-15 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-15 13770752]
"NVHotkey"="nvHotkey.dll" [2009-12-15 86016]
"OA001Mon"="c:\windows\OA001Mon.exe" [2010-01-28 24576]
"IAStorIcon"="c:\program files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2008-05-30 180224]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2008-05-14 105472]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2008-06-24 243000]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2008-06-24 79160]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-08-18 598016]
"DCPstrApp"="c:\program files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe" [2008-08-04 6656]
"DellConnectionManager"="c:\program files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe" [2008-10-01 1454080]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\DesktopUI\XTray.exe" [2011-08-25 476480]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-06-26 1311312]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Act.Outlook.Service"="c:\program files\ACT\Act for Windows\Act.Outlook.Service.exe" [2009-02-24 28672]
"Act! Preloader"="c:\program files\ACT\Act for Windows\ActSage.exe" [2009-02-24 393216]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2012-03-27 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2012-03-26 640440]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-06-29 273544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-04-05 495708]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
.
c:\documents and settings\McAfeeMVSUser\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [N/A]
.
c:\documents and settings\ataylor.WAYPOINT.000\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe [2009-11-16 517384]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-8-15 604776]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-11-11 950048]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-05-06 09:29 64592 —-a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\ACT\\Act for Windows\\ActSage.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [8/12/2010 2:55 PM 89624]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 6:56 AM 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [9/4/2008 6:28 PM 406808]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [11/11/2008 5:35 PM 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [11/11/2008 5:35 PM 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [11/11/2008 4:00 PM 451872]
R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [12/29/2011 4:47 PM 99896]
R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [7/22/2010 1:13 PM 13336]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [7/26/2010 11:19 AM 10448]
R2 McAfee SiteAdvisor Enterprise Service;McAfee SiteAdvisor Enterprise Service;c:\program files\McAfee\SiteAdvisor Enterprise\McSACore.exe [5/12/2011 11:48 AM 324928]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/16/2010 10:37 AM 148520]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/10/2010 6:29 PM 29293408]
R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 RumorServer;McAfee Peer Distribution Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [8/23/2011 9:50 AM 291064]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe [10/1/2008 5:28 AM 90112]
R2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [5/20/2010 1:46 PM 55016]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [7/21/2010 5:25 PM 113664]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [7/22/2010 1:11 PM 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [7/21/2010 5:27 PM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [7/21/2010 5:25 PM 240344]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [7/21/2010 5:25 PM 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [7/21/2010 5:25 PM 281472]
S2 ACT! Scheduler;ACT! Scheduler;c:\program files\ACT\Act for Windows\Act.Scheduler.exe [2/24/2009 2:08 PM 81920]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/25/2012 9:45 AM 257696]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/26/2010 11:43 AM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [8/12/2010 2:55 PM 87808]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [12/18/2009 12:13 PM 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/18/2009 12:12 PM 174720]
S3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [7/21/2010 5:25 PM 134144]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [4/14/2010 8:29 PM 32408]
S3 TrmbTS;TrmbTS;c:\windows\system32\drivers\TrmbTS.sys [8/26/2010 12:49 PM 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.sys –> c:\windows\system32\drivers\TRMUSB5K.sys [?]
S3 USA19H;USA19H;c:\windows\system32\drivers\USA19H2k.sys [8/13/2010 3:56 PM 704000]
S3 USA19H2KP;Keyspan USB Serial Port Driver;c:\windows\system32\drivers\USA19H2kp.sys [8/13/2010 3:56 PM 24192]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 12:16 PM 14336]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/22/2009 11:08 PM 47128]
S4 RsFx0105;RsFx0105 Driver;c:\windows\system32\drivers\RsFx0105.sys [9/22/2011 6:10 PM 238696]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [9/22/2011 6:17 PM 370024]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 07084589
*NewlyCreated* - 76278505
*Deregistered* - 07084589
*Deregistered* - 76278505
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
pavprsrv
slee_503_service
idebusdr
slimsvc
PAC7302
.
Contents of the 'Scheduled Tasks' folder
.
2012-06-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-25 16:25]
.
2011-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2012-06-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145Core.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-06 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-308600077-3542235570-3293604796-1145UA.job
- c:\documents and settings\jzipkin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2011-10-21 17:46]
.
2012-06-06 c:\windows\Tasks\geipcppjz.job
- c:\windows\system32\c_1257I.dll [2012-06-04 15:01]
.
2012-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-26 15:43]
.
2012-06-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2012-06-07 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-308600077-3542235570-3293604796-1145.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
TCP: DhcpNameServer = 10.0.0.11
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-07 09:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1000)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2012-06-07 09:48:43
ComboFix-quarantined-files.txt 2012-06-07 13:48
ComboFix2.txt 2012-06-06 15:21
ComboFix3.txt 2012-05-10 16:31
.
Pre-Run: 116,348,469,248 bytes free
Post-Run: 116,424,413,184 bytes free
.
- - End Of File - - F6D67DA8110C3FC2FDA2ADDDF9181450
Great.

Let's check for remnants.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
well, good news and bad news (i think). ESET suggests there's something, but MBAM found nothing. Hmmm… Thx again. Here are the logs: C:\TDSSKiller_Quarantine\07.06.2012_09.32.15\tdlfs0000\tsk0002.dta a variant of Win32/Olmarik.AWO trojan C:\TDSSKiller_Quarantine\07.06.2012_09.32.15\tdlfs0000\tsk0005.dta Win32/Olmarik.AWO trojan C:\TDSSKiller_Quarantine\26.04.2012_22.46.52\rtkt0000\svc0000\tsk0000.dta Win32/Sirefef.DA trojan Operating memory probably a variant of Win32/Ponmocup.AA trojan Malwarebytes Anti-Malware 1.61.0.1400 www.malwarebytes.org Database version: v2012.06.07.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 jzipkin :: C4LHXH1 [administrator] 6/7/2012 1:49:29 PM mbam-log-2012-06-07 (13-49-29).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 349914 Time elapsed: 5 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
The again. Here's the log. .DAT attached. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-06-08 09:46:08 —————————– 09:46:08.159 OS Version: Windows 5.1.2600 Service Pack 3 09:46:08.159 Number of processors: 2 586 0x1706 09:46:08.159 ComputerName: C4LHXH1 UserName: jzipkin 09:46:26.933 Initialize success 09:48:00.817 AVAST engine defs: 12060800 09:48:07.494 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 09:48:07.494 Disk 0 Vendor: ST916031 D005 Size: 152627MB BusType: 8 09:48:07.525 Disk 0 MBR read successfully 09:48:07.525 Disk 0 MBR scan 09:48:07.727 Disk 0 Windows VISTA default MBR code 09:48:07.727 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 62 MB offset 63 09:48:07.758 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152562 MB offset 128520 09:48:07.789 Disk 0 scanning sectors +312576705 09:48:07.960 Disk 0 scanning C:\WINDOWS\system32\drivers 09:49:00.522 Service scanning 09:49:55.382 Modules scanning 09:50:03.488 Disk 0 trace - called modules: 09:50:03.504 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 09:50:03.504 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b2a4868] 09:50:03.504 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8b2f2028] 09:50:04.171 AVAST engine scan C:\WINDOWS 09:50:32.960 AVAST engine scan C:\WINDOWS\system32 09:56:33.624 AVAST engine scan C:\WINDOWS\system32\drivers 09:57:06.886 AVAST engine scan C:\Documents and Settings\jzipkin 10:07:42.559 AVAST engine scan C:\Documents and Settings\All Users 10:11:32.164 Scan finished successfully 10:13:51.842 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\MBR.dat" 10:13:51.842 The log file has been saved successfully to "C:\Documents and Settings\jzipkin\Desktop\aswMBR.txt"

Attachments:

Your MBR is clean.

I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@Echo on
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "flush.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]

Double click on flush.bat & allow it to run. A small black screen may briefly flash on and off, that normal.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI