This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System running very slow and detecting Trojan Horse with Norton! [

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My laptop is Win 7 (32 bit). Recently, it started taking about 3-4 mins for startup so I run full scan using Norton Antivirus Corporate Edition. Now, it scans and it started giving me Trojan Horse infected files and there are ton of files that are infected in temp folder and in Symantec folder in appdata also.

I ran Hijack this tool and posting the results. Please help!!


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at PM 10:37:13, on 15-07-2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Symantec AntiVirus\SavUI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Symantec AntiVirus\vpc32.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Vijay\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Vijay\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Vijay\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Vijay\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Vijay\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_265.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…rio&pf=cnnb
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-21-818653106-4120140212-1750785515-1005\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-818653106-4120140212-1750785515-1005\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-818653106-4120140212-1750785515-1005\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer…DataManager.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{48330B93-88E8-47AB-9FFA-1F1BC113E19E}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{98A2A3BA-92DA-4C9C-8253-A96B6738C3F2}: NameServer = 172.16.16.1,4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ciqindia.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ciqindia.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ciqindia.com
O18 - Protocol: HTLFP - {03B7A5D4-96B0-4316-95F8-072D326A58F1} - ielpview.dll (file missing)
O18 - Protocol: vfsp - {E4CB5121-E242-11D4-8ED6-00010219EB22} - VFSProtocol.dll (file missing)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Change Modem Device Service - Unknown owner - C:\Windows\system32\ChgService.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HWDeviceService.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Check Point VPN-1 Securemote service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point VPN-1 Securemote watchdog (SR_Watchdog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10190 bytes
Hi vijay.gupta,

:welcome:

My name is NoodleTech. I would be glad to assist you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please be aware that removing malware is not without risk and while unrecoverable damage to systems is rare, it can happen and may require a re-format and re-install of your operating system. Because of this it is a good idea to back-up anything important saved on your computer.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not delete anything unless instructed to.
  • DO NOT use tools such as ComboFix without supervision.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Failure to respond within 3 days will result in this topic being closed - If you need more time to complete the steps required, please let me know.
===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments,  attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_33
Run by [removed] at 10:49:48 on 2012-07-16
Microsoft Windows 7 Home Basic 6.1.7601.1.1252.91.1033.18.3039.1733 [GMT 5.5:30]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\ChgService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\ProgramData\DatacardService\HWDeviceService.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Windows\System32\WerFault.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_IN&c=94&bd=Presario&pf=cnnb
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mCustomizeSearch = hxxp://www.google.com/ie
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live

\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [vmware-tray] c:\program files\vmware\vmware workstation\vmware-tray.exe
dRunOnce: []
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 1 (0x1)
dPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
dPolicies-system: WallpaperStyle = 2
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxp://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
TCP: Interfaces\{48330B93-88E8-47AB-9FFA-1F1BC113E19E} : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{48330B93-88E8-47AB-9FFA-1F1BC113E19E}\14E64627F69646140563237313 : DhcpNameServer = 192.168.43.1
TCP: Interfaces\{98A2A3BA-92DA-4C9C-8253-A96B6738C3F2} : NameServer = 172.16.16.1,4.2.2.2
Handler: HTLFP - {03B7A5D4-96B0-4316-95F8-072D326A58F1} -
Handler: vfsp - {E4CB5121-E242-11D4-8ED6-00010219EB22} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
SEH: {A5949E07-8536-4625-A3D0-2DD83F559990} - No File
LSA: Notification Packages = scecli CPNP
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\vijay\appdata\roaming\mozilla\firefox\profiles\c3pzohvf.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\vijay\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\users\vijay\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\vijay\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_265.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R1 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [2010-10-2 38976]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe [2009-3-2 81920]
R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [2012-5-19 135168]
R2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [2007-5-24 36368]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\hewlett-packard\shared\HPDrvMntSvc.exe [2011-1-25 92216]
R2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\datacardservice\hwdeviceservice.exe -/service –> c:\programdata\datacardservice

\HWDeviceService.exe -/service [?]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-10-14 1956552]
R2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\drivers\vnasc.sys [2007-5-24 110032]
R2 VPN-1;VPN-1 Module;c:\windows\system32\drivers\vpn.sys [2007-5-24 673456]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2010-10-2 29472]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2012-6-1 106656]
R3 FW1;SecuRemote Miniport;c:\windows\system32\drivers\fw.sys [2007-5-24 2234800]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\drivers\ew_jubusenum.sys [2012-3-13 73216]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-12-24 139880]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-6-10 394856]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-12-24 2253120]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-1 250056]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-5-13 30312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\drivers\cmnsusbser.sys [2010-10-2 103424]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-8-25 228408]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\drivers\ew_hwusbdev.sys [2012-3-13 102784]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-3 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-11-9 36640]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2009-7-23 116136]
S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-11 4231168]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2012-1-9 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2012-1-9 8576]
S3 SavRoam;SavRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-10-14 122056]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-5-13 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-5-13 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-5-13 136808]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-13 52224]
S3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\drivers\3GDatausbser.sys [2009-4-7 102656]
S3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\drivers\ZTEusbvoice.sys [2012-6-17 107776]
S4 ICM_UpdaterService;ICM_UpdaterService Disp;c:\program files\samsung\samsung networking wizard\ICM_Service.exe [2011-3-18 204883]
S4 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-5 113120]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-07-15 17:06:46 388096 —-a-r- c:\users\vijay\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-07-15 16:59:19 ——– d—–w- c:\program files\Trend Micro
2012-07-15 13:22:02 ——– d—–w- c:\users\vijay\VirtualBox VMs
2012-07-15 08:29:22 ——– d—–w- c:\users\vijay\.VirtualBox
2012-07-15 08:27:47 158552 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2012-07-15 08:27:28 91992 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2012-07-15 08:27:22 ——– d—–w- c:\program files\Oracle
2012-07-13 18:50:48 6762896 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{43c4b7ce-ea77-498b-b24d-

4a5b2812b24e}\mpengine.dll
2012-07-13 18:50:47 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-07-12 04:41:56 2345984 —-a-w- c:\windows\system32\win32k.sys
2012-07-05 17:56:21 ——– d—–w- c:\program files\Gophoto.it
2012-07-05 17:55:25 ——– d—–w- c:\program files\1ClickDownload
2012-07-05 05:08:34 ——– d—–w- C:\garg
2012-06-30 19:32:25 ——– d—–w- C:\f2820a3e66ec22977737ae
2012-06-27 18:28:33 ——– d—–w- c:\programdata\FarmFrenzy-PizzaParty
2012-06-26 17:49:09 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll
2012-06-26 17:49:09 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll
2012-06-25 18:01:51 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-25 18:01:39 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-25 18:01:18 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-06-25 18:01:18 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-25 10:34:24 1394248 —-a-w- c:\windows\system32\msxml4.dll
2012-06-21 04:54:17 ——– d—–w- c:\users\vijay\appdata\local\visi_coupon
2012-06-19 18:53:03 ——– d—–w- c:\users\vijay\appdata\local\Macromedia
2012-06-17 11:27:36 107776 —-a-w- c:\windows\system32\drivers\ZTEusbvoice.sys
2012-06-17 11:27:36 107776 —-a-w- c:\windows\system32\drivers\ZTEusbser6k.sys
2012-06-17 11:27:36 107776 —-a-w- c:\windows\system32\drivers\ZTEusbnmea.sys
2012-06-17 11:27:36 107776 —-a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys
2012-06-17 11:27:10 ——– d—–w- c:\program files\Beetel Connection Manager
2012-06-17 11:18:02 18816 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-06-17 11:17:50 ——– d—–w- c:\program files\PC Connectivity Solution
2012-06-17 10:06:40 ——– d—–w- C:\data
2012-06-16 21:59:28 476936 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-06-16 21:31:00 821824 —-a-w- c:\windows\system32\dgderapi.dll
2012-06-16 20:31:14 89600 —-a-w- c:\windows\system32\MSCAL.OCX
2012-06-16 20:31:14 191248 —-a-w- c:\windows\system32\TABCTL32.OCX
2012-06-16 20:30:06 71680 —-a-w- c:\windows\ST5UNST.EXE
2012-06-16 20:30:06 29696 —-a-w- c:\windows\system32\VB5StKit.dll
2012-06-16 20:30:06 1355776 —-a-w- c:\windows\system32\MSVBVM50.dll
2012-06-16 15:34:58 ——– d—–w- c:\windows\system32\SupportAppXL
.
==================== Find3M ====================
.
2012-07-12 05:35:22 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 05:35:22 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-16 21:59:07 472840 —-a-w- c:\windows\system32\deployJava1.dll
2012-06-06 05:05:52 1390080 —-a-w- c:\windows\system32\msxml6.dll
2012-06-06 05:05:52 1236992 —-a-w- c:\windows\system32\msxml3.dll
2012-06-06 05:03:06 805376 —-a-w- c:\windows\system32\cdosys.dll
2012-06-05 11:03:00 116056 —-a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2012-06-05 11:03:00 104792 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2012-06-05 11:02:58 135512 —-a-w- c:\windows\system32\VBoxNetFltNobj.dll
2012-06-02 04:45:04 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 04:45:03 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 04:40:59 369336 —-a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 04:40:39 225280 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 04:39:10 219136 —-a-w- c:\windows\system32\ncrypt.dll
2012-05-15 03:03:54 981504 —-a-w- c:\windows\system32\wininet.dll
2012-05-04 09:59:54 514560 —-a-w- c:\windows\system32\qdvd.dll
2012-05-01 04:44:12 164352 —-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17:07 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45:55 58880 —-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45:54 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41:16 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 04:36:42 140288 —-a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 04:36:42 1158656 —-a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36:42 103936 —-a-w- c:\windows\system32\cryptnet.dll
2012-04-20 03:16:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-08-20 16:04:39 161736 —-a-w- c:\program files\64res.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: Hitachi_HTS723232L9A360 rev.FC4OC60D -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: >>UNKNOWN [0x8341F000]<< >>UNKNOWN [0x8C015000]<< >>UNKNOWN [0x8CBD7000]<< >>UNKNOWN [0x8BE91000]<< >>UNKNOWN [0x83831000]<< >>UNKNOWN

[0x8C126000]<< >>UNKNOWN [0x8BFD8000]<< >>UNKNOWN [0x8C1A9000]<<
_asm { DEC EBP; POP EDX; NOP ; ADD [EBX], AL; ADD [EAX], AL; ADD [EAX+EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x8345655A] -> \Device\Harddisk0\DR0[0x871DC030]
\Driver\Disk[0x871DBC78] -> IRP_MJ_CREATE -> 0x8C01939F
3 [0x8C01959E] -> ntkrnlpa!IofCallDriver[0x8345655A] -> [0x870CEB90]
\Driver\ACPI[0x8637DF38] -> IRP_MJ_CREATE -> 0x8BE9A4CC
5 [0x8BE9A3D4] -> ntkrnlpa!IofCallDriver[0x8345655A] -> \Device\Ide\IdeDeviceP0T0L0-0[0x87090030]
\Driver\atapi[0x87081140] -> IRP_MJ_CREATE -> 0x8C1408CC
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV ES, AX; MOV DS, AX; MOV SI, SP; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; JMP FAR 0x0:0x660;

}
user & kernel MBR OK
copy of MBR has been found in sector 2 !
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 10:51:00.73 ===============
Hi vijay.gupta,

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
===================================================

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan.
    • If Malicious objects are found, DO NOT cure them.
    • Choose Skip then click on Continue.
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
I allowed it. Posting the log file: aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-07-16 23:09:53 —————————– 23:09:53.572 OS Version: Windows 6.1.7601 Service Pack 1 23:09:53.572 Number of processors: 2 586 0x170A 23:09:53.582 ComputerName: VIJAY-LAPTOP UserName: Vijay 23:09:54.392 Initialize success 23:33:38.149 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 23:33:38.152 Disk 0 Vendor: Hitachi_HTS723232L9A360 FC4OC60D Size: 305245MB BusType: 11 23:33:38.252 Disk 0 MBR read successfully 23:33:38.252 Disk 0 MBR scan 23:33:38.257 Disk 0 unknown MBR code 23:33:38.257 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 23:33:38.282 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 146561 MB offset 409600 23:33:38.287 Disk 0 Partition - 00 0F Extended LBA 145435 MB offset 300566528 23:33:38.317 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 13048 MB offset 598417408 23:33:38.347 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 145433 MB offset 300568576 23:33:38.502 Disk 0 scanning sectors +625139712 23:33:38.592 Disk 0 scanning C:\Windows\system32\drivers 23:33:53.276 Service scanning 23:34:15.945 Modules scanning 23:34:31.748 Disk 0 trace - called modules: 23:34:31.779 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys afd.sys ndis.sys bthpan.sys SYMTDI.SYS 23:34:31.794 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x871d8030] 23:34:31.810 3 CLASSPNP.SYS[8c02459e] -> nt!IofCallDriver -> [0x870d7c10] 23:34:31.810 5 ACPI.sys[8bec23d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x87086030] 23:34:31.826 Scan finished successfully 23:42:26.794 Disk 0 MBR has been saved successfully to "C:\Users\Vijay\Desktop\MBR.dat" 23:42:26.804 The log file has been saved successfully to "C:\Users\Vijay\Desktop\aswMBR.txt" 23:44:56.0526 5380 TDSS rootkit removing tool 2.7.45.0 Jul 9 2012 12:46:35 23:44:57.0185 5380 ============================================================ 23:44:57.0185 5380 Current date / time: 2012/07/16 23:44:57.0185 23:44:57.0185 5380 SystemInfo: 23:44:57.0185 5380 23:44:57.0185 5380 OS Version: 6.1.7601 ServicePack: 1.0 23:44:57.0185 5380 Product type: Workstation 23:44:57.0185 5380 ComputerName: VIJAY-LAPTOP 23:44:57.0185 5380 UserName: Vijay 23:44:57.0185 5380 Windows directory: C:\Windows 23:44:57.0185 5380 System windows directory: C:\Windows 23:44:57.0185 5380 Processor architecture: Intel x86 23:44:57.0185 5380 Number of processors: 2 23:44:57.0185 5380 Page size: 0x1000 23:44:57.0185 5380 Boot type: Normal boot 23:44:57.0185 5380 ============================================================ 23:44:58.0845 5380 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 23:44:58.0955 5380 ============================================================ 23:44:58.0955 5380 \Device\Harddisk0\DR0: 23:44:58.0955 5380 MBR partitions: 23:44:58.0955 5380 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800 23:44:58.0955 5380 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x11E40800 23:44:58.0975 5380 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x11EA5000, BlocksNum 0x11C0C800 23:44:58.0975 5380 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x23AB2000, BlocksNum 0x197C000 23:44:58.0975 5380 ============================================================ 23:44:59.0005 5380 C: <-> \Device\Harddisk0\DR0\Partition1 23:44:59.0045 5380 D: <-> \Device\Harddisk0\DR0\Partition2 23:44:59.0095 5380 E: <-> \Device\Harddisk0\DR0\Partition3 23:44:59.0095 5380 ============================================================ 23:44:59.0095 5380 Initialize success 23:44:59.0095 5380 ============================================================ 23:45:01.0265 4084 ============================================================ 23:45:01.0265 4084 Scan started 23:45:01.0265 4084 Mode: Manual; 23:45:01.0265 4084 ============================================================ 23:45:03.0645 4084 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 23:45:03.0645 4084 1394ohci - ok 23:45:03.0739 4084 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 23:45:03.0739 4084 ACPI - ok 23:45:03.0755 4084 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 23:45:03.0755 4084 AcpiPmi - ok 23:45:03.0895 4084 AdobeARMservice (62b7936f9036dd6ed36e6a7efa805dc0) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 23:45:03.0911 4084 AdobeARMservice - ok 23:45:04.0004 4084 AdobeFlashPlayerUpdateSvc (5e1a953c6472e7bb644892a4d0df5e72) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 23:45:04.0060 4084 AdobeFlashPlayerUpdateSvc - ok 23:45:04.0150 4084 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 23:45:04.0160 4084 adp94xx - ok 23:45:04.0190 4084 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 23:45:04.0200 4084 adpahci - ok 23:45:04.0220 4084 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 23:45:04.0230 4084 adpu320 - ok 23:45:04.0270 4084 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 23:45:04.0270 4084 AeLookupSvc - ok 23:45:04.0540 4084 AESTFilters (827dbc22c96eecf6d36a13162fabafd3) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe 23:45:04.0590 4084 AESTFilters - ok 23:45:04.0680 4084 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 23:45:04.0680 4084 AFD - ok 23:45:04.0870 4084 AgereSoftModem (7e10e3bb9b258ad8a9300f91214d67b9) C:\Windows\system32\DRIVERS\AGRSM.sys 23:45:04.0890 4084 AgereSoftModem - ok 23:45:04.0930 4084 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 23:45:04.0930 4084 agp440 - ok 23:45:04.0970 4084 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 23:45:04.0970 4084 aic78xx - ok 23:45:05.0030 4084 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 23:45:05.0060 4084 ALG - ok 23:45:05.0090 4084 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 23:45:05.0100 4084 aliide - ok 23:45:05.0110 4084 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 23:45:05.0110 4084 amdagp - ok 23:45:05.0120 4084 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 23:45:05.0120 4084 amdide - ok 23:45:05.0170 4084 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 23:45:05.0170 4084 AmdK8 - ok 23:45:05.0190 4084 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 23:45:05.0190 4084 AmdPPM - ok 23:45:05.0230 4084 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys 23:45:05.0230 4084 amdsata - ok 23:45:05.0250 4084 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 23:45:05.0250 4084 amdsbs - ok 23:45:05.0260 4084 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys 23:45:05.0260 4084 amdxata - ok 23:45:05.0310 4084 androidusb (dd8d9c597af7cd2f6b70a3d6a4a1acea) C:\Windows\system32\Drivers\ssadadb.sys 23:45:05.0310 4084 androidusb - ok 23:45:05.0380 4084 ApfiltrService (7df70a08b56cbbc874744d9b0b396272) C:\Windows\system32\DRIVERS\Apfiltr.sys 23:45:05.0380 4084 ApfiltrService - ok 23:45:05.0440 4084 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 23:45:05.0440 4084 AppID - ok 23:45:05.0460 4084 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 23:45:05.0470 4084 AppIDSvc - ok 23:45:05.0530 4084 Appinfo (fb1959012294d6ad43e5304df65e3c26) C:\Windows\System32\appinfo.dll 23:45:05.0550 4084 Appinfo - ok 23:45:05.0710 4084 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 23:45:05.0720 4084 arc - ok 23:45:05.0740 4084 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 23:45:05.0740 4084 arcsas - ok 23:45:05.0770 4084 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 23:45:05.0770 4084 AsyncMac - ok 23:45:05.0820 4084 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 23:45:05.0820 4084 atapi - ok 23:45:05.0960 4084 AudioEndpointBuilder (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 23:45:05.0990 4084 AudioEndpointBuilder - ok 23:45:06.0000 4084 Audiosrv (ce3b4e731638d2ef62fcb419be0d39f0) C:\Windows\System32\Audiosrv.dll 23:45:06.0000 4084 Audiosrv - ok 23:45:06.0060 4084 AxInstSV (6e30d02aac9cac84f421622e3a2f6178) C:\Windows\System32\AxInstSV.dll 23:45:06.0080 4084 AxInstSV - ok 23:45:06.0170 4084 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 23:45:06.0180 4084 b06bdrv - ok 23:45:06.0220 4084 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 23:45:06.0220 4084 b57nd60x - ok 23:45:06.0840 4084 BCM43XX (36a47e6ab1f0967c97722183e21adb1a) C:\Windows\system32\DRIVERS\bcmwl6.sys 23:45:06.0910 4084 BCM43XX - ok 23:45:07.0010 4084 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 23:45:07.0020 4084 BDESVC - ok 23:45:07.0090 4084 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 23:45:07.0090 4084 Beep - ok 23:45:07.0190 4084 BFE (1e2bac209d184bb851e1a187d8a29136) C:\Windows\System32\bfe.dll 23:45:07.0210 4084 BFE - ok 23:45:07.0530 4084 BITS (e585445d5021971fae10393f0f1c3961) C:\Windows\system32\qmgr.dll 23:45:07.0560 4084 BITS - ok 23:45:07.0570 4084 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 23:45:07.0580 4084 blbdrive - ok 23:45:07.0620 4084 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 23:45:07.0620 4084 bowser - ok 23:45:07.0650 4084 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 23:45:07.0650 4084 BrFiltLo - ok 23:45:07.0710 4084 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 23:45:07.0710 4084 BrFiltUp - ok 23:45:07.0760 4084 Browser (6e11f33d14d020f58d5e02e4d67dfa19) C:\Windows\System32\browser.dll 23:45:07.0770 4084 Browser - ok 23:45:07.0800 4084 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 23:45:07.0800 4084 Brserid - ok 23:45:07.0810 4084 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 23:45:07.0810 4084 BrSerWdm - ok 23:45:07.0820 4084 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 23:45:07.0820 4084 BrUsbMdm - ok 23:45:07.0840 4084 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 23:45:07.0840 4084 BrUsbSer - ok 23:45:07.0900 4084 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\DRIVERS\BthEnum.sys 23:45:07.0910 4084 BthEnum - ok 23:45:07.0930 4084 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 23:45:07.0930 4084 BTHMODEM - ok 23:45:07.0950 4084 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys 23:45:07.0950 4084 BthPan - ok 23:45:07.0980 4084 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys 23:45:07.0980 4084 BTHPORT - ok 23:45:08.0030 4084 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 23:45:08.0040 4084 bthserv - ok 23:45:08.0060 4084 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys 23:45:08.0060 4084 BTHUSB - ok 23:45:08.0100 4084 btwaudio (d57d29132efe13a83133d9bd449e0cf1) C:\Windows\system32\drivers\btwaudio.sys 23:45:08.0100 4084 btwaudio - ok 23:45:08.0140 4084 btwavdt (d282c14a69357d0e1bafaecc2ca98c3a) C:\Windows\system32\DRIVERS\btwavdt.sys 23:45:08.0140 4084 btwavdt - ok 23:45:08.0260 4084 btwdins (7d2dd14e60ce4ff3308d66fda7990546) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe 23:45:08.0340 4084 btwdins - ok 23:45:08.0350 4084 btwl2cap (aafd7cb76ba61fbb08e302da208c974a) C:\Windows\system32\DRIVERS\btwl2cap.sys 23:45:08.0350 4084 btwl2cap - ok 23:45:08.0370 4084 btwrchid (02eb4d2b05967df2d32f29c84ab1fb17) C:\Windows\system32\DRIVERS\btwrchid.sys 23:45:08.0370 4084 btwrchid - ok 23:45:08.0800 4084 catchme - ok 23:45:08.0950 4084 ccEvtMgr (adf6c0aa0bb213e93c147cf09335dc31) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 23:45:08.0950 4084 ccEvtMgr - ok 23:45:08.0960 4084 ccSetMgr (adf6c0aa0bb213e93c147cf09335dc31) C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 23:45:08.0960 4084 ccSetMgr - ok 23:45:09.0110 4084 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 23:45:09.0110 4084 cdfs - ok 23:45:09.0170 4084 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\DRIVERS\cdrom.sys 23:45:09.0170 4084 cdrom - ok 23:45:09.0230 4084 CertPropSvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 23:45:09.0250 4084 CertPropSvc - ok 23:45:09.0360 4084 Change Modem Device Service (82eb138d83737459358d9f2c01850378) C:\Windows\system32\ChgService.exe 23:45:09.0390 4084 Change Modem Device Service - ok 23:45:09.0420 4084 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 23:45:09.0420 4084 circlass - ok 23:45:09.0580 4084 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 23:45:09.0580 4084 CLFS - ok 23:45:09.0800 4084 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 23:45:09.0860 4084 clr_optimization_v2.0.50727_32 - ok 23:45:09.0970 4084 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 23:45:10.0000 4084 clr_optimization_v4.0.30319_32 - ok 23:45:10.0010 4084 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 23:45:10.0010 4084 CmBatt - ok 23:45:10.0050 4084 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 23:45:10.0060 4084 cmdide - ok 23:45:10.0120 4084 cmnsusbser (675d67423980fc1784b93aa47d350a31) C:\Windows\system32\DRIVERS\cmnsusbser.sys 23:45:10.0120 4084 cmnsusbser - ok 23:45:10.0180 4084 CNG (247b4ce2dab1160cd422d532d5241e1f) C:\Windows\system32\Drivers\cng.sys 23:45:10.0180 4084 CNG - ok 23:45:10.0280 4084 Com4QLBEx (f9a79c5b27037821112c50a9c8fb367a) C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe 23:45:10.0370 4084 Com4QLBEx - ok 23:45:10.0420 4084 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 23:45:10.0420 4084 Compbatt - ok 23:45:10.0460 4084 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 23:45:10.0460 4084 CompositeBus - ok 23:45:10.0480 4084 COMSysApp - ok 23:45:10.0540 4084 CP_OMDRV (7f1706911862276f5144984d07ba9e3b) C:\Windows\system32\drivers\omdrv.sys 23:45:10.0540 4084 CP_OMDRV - ok 23:45:10.0560 4084 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 23:45:10.0560 4084 crcdisk - ok 23:45:10.0650 4084 CryptSvc (06e771aa596b8761107ab57e99f128d7) C:\Windows\system32\cryptsvc.dll 23:45:10.0680 4084 CryptSvc - ok 23:45:10.0750 4084 DcomLaunch (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 23:45:10.0760 4084 DcomLaunch - ok 23:45:10.0800 4084 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 23:45:10.0820 4084 defragsvc - ok 23:45:10.0840 4084 DefWatch (9865f004933a57d73153efe94376d03b) C:\Program Files\Symantec AntiVirus\DefWatch.exe 23:45:10.0860 4084 DefWatch - ok 23:45:10.0910 4084 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 23:45:10.0910 4084 DfsC - ok 23:45:10.0930 4084 dgderdrv - ok 23:45:10.0980 4084 Dhcp (e9e01eb683c132f7fa27cd607b8a2b63) C:\Windows\system32\dhcpcore.dll 23:45:11.0000 4084 Dhcp - ok 23:45:11.0020 4084 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 23:45:11.0020 4084 discache - ok 23:45:11.0100 4084 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 23:45:11.0100 4084 Disk - ok 23:45:11.0150 4084 Dnscache (33ef4861f19a0736b11314aad9ae28d0) C:\Windows\System32\dnsrslvr.dll 23:45:11.0170 4084 Dnscache - ok 23:45:11.0220 4084 dot3svc (366ba8fb4b7bb7435e3b9eacb3843f67) C:\Windows\System32\dot3svc.dll 23:45:11.0240 4084 dot3svc - ok 23:45:11.0260 4084 DPS (8ec04ca86f1d68da9e11952eb85973d6) C:\Windows\system32\dps.dll 23:45:11.0270 4084 DPS - ok 23:45:11.0310 4084 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 23:45:11.0310 4084 drmkaud - ok 23:45:11.0400 4084 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 23:45:11.0410 4084 DXGKrnl - ok 23:45:11.0440 4084 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 23:45:11.0450 4084 EapHost - ok 23:45:11.0620 4084 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 23:45:11.0690 4084 ebdrv - ok 23:45:11.0790 4084 eeCtrl (fce87ba643d5e9a8b6e0378508d1b22d) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 23:45:11.0790 4084 eeCtrl - ok 23:45:11.0910 4084 EFS (81951f51e318aecc2d68559e47485cc4) C:\Windows\System32\lsass.exe 23:45:11.0950 4084 EFS - ok 23:45:12.0040 4084 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 23:45:12.0050 4084 elxstor - ok 23:45:12.0120 4084 EraserUtilRebootDrv (115dc729465a8c386615207f28875255) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 23:45:12.0130 4084 EraserUtilRebootDrv - ok 23:45:12.0160 4084 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 23:45:12.0160 4084 ErrDev - ok 23:45:12.0270 4084 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 23:45:12.0290 4084 EventSystem - ok 23:45:12.0360 4084 ew_hwusbdev (57c171ea22f0a7f068fcb0caedd1e8e7) C:\Windows\system32\DRIVERS\ew_hwusbdev.sys 23:45:12.0360 4084 ew_hwusbdev - ok 23:45:12.0400 4084 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 23:45:12.0400 4084 exfat - ok 23:45:12.0430 4084 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 23:45:12.0440 4084 fastfat - ok 23:45:12.0560 4084 Fax (967ea5b213e9984cbe270205df37755b) C:\Windows\system32\fxssvc.exe 23:45:12.0630 4084 Fax - ok 23:45:12.0650 4084 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 23:45:12.0650 4084 fdc - ok 23:45:12.0670 4084 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 23:45:12.0680 4084 fdPHost - ok 23:45:12.0700 4084 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 23:45:12.0700 4084 FDResPub - ok 23:45:12.0790 4084 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 23:45:12.0790 4084 FileInfo - ok 23:45:12.0830 4084 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 23:45:12.0830 4084 Filetrace - ok 23:45:12.0840 4084 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 23:45:12.0840 4084 flpydisk - ok 23:45:12.0880 4084 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 23:45:12.0890 4084 FltMgr - ok 23:45:12.0970 4084 FontCache (b3a5ec6b6b6673db7e87c2bcdbddc074) C:\Windows\system32\FntCache.dll 23:45:12.0990 4084 FontCache - ok 23:45:13.0050 4084 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 23:45:13.0070 4084 FontCache3.0.0.0 - ok 23:45:13.0090 4084 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 23:45:13.0090 4084 FsDepends - ok 23:45:13.0140 4084 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys 23:45:13.0140 4084 fssfltr - ok 23:45:13.0360 4084 fsssvc (4ce9dac1518ff7e77bd213e6394b9d77) C:\Program Files\Windows Live\Family Safety\fsssvc.exe 23:45:13.0460 4084 fsssvc - ok 23:45:13.0890 4084 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\Windows\system32\FsUsbExDisk.SYS 23:45:13.0890 4084 FsUsbExDisk - ok 23:45:13.0960 4084 Fs_Rec (7dae5ebcc80e45d3253f4923dc424d05) C:\Windows\system32\drivers\Fs_Rec.sys 23:45:13.0960 4084 Fs_Rec - ok 23:45:14.0030 4084 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 23:45:14.0040 4084 fvevol - ok 23:45:14.0320 4084 FW1 (e03a6d546c2cccfcf07ae8a1a0a9347d) C:\Windows\system32\DRIVERS\fw.sys 23:45:14.0380 4084 FW1 - ok 23:45:14.0520 4084 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 23:45:14.0520 4084 gagp30kx - ok 23:45:14.0600 4084 GameConsoleService (551d463e4cceb5240234da6718c93a44) C:\Program Files\HP Games\HP Game Console\GameConsoleService.exe 23:45:14.0630 4084 GameConsoleService - ok 23:45:14.0720 4084 gpsvc (e897eaf5ed6ba41e081060c9b447a673) C:\Windows\System32\gpsvc.dll 23:45:14.0760 4084 gpsvc - ok 23:45:14.0840 4084 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 23:45:14.0870 4084 gusvc - ok 23:45:14.0910 4084 hcmon (0b455ab4bb345f0aa1fac2dd5da6e3ac) C:\Windows\system32\Drivers\hcmon.sys 23:45:14.0920 4084 hcmon - ok 23:45:14.0940 4084 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 23:45:14.0940 4084 hcw85cir - ok 23:45:15.0010 4084 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 23:45:15.0020 4084 HdAudAddService - ok 23:45:15.0060 4084 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 23:45:15.0070 4084 HDAudBus - ok 23:45:15.0080 4084 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 23:45:15.0080 4084 HidBatt - ok 23:45:15.0100 4084 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 23:45:15.0110 4084 HidBth - ok 23:45:15.0160 4084 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 23:45:15.0160 4084 HidIr - ok 23:45:15.0180 4084 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 23:45:15.0200 4084 hidserv - ok 23:45:15.0240 4084 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys 23:45:15.0240 4084 HidUsb - ok 23:45:15.0280 4084 hkmsvc (196b4e3f4cccc24af836ce58facbb699) C:\Windows\system32\kmsvc.dll 23:45:15.0290 4084 hkmsvc - ok 23:45:15.0340 4084 HomeGroupListener (6658f4404de03d75fe3ba09f7aba6a30) C:\Windows\system32\ListSvc.dll 23:45:15.0360 4084 HomeGroupListener - ok 23:45:15.0410 4084 HomeGroupProvider (dbc02d918fff1cad628acbe0c0eaa8e8) C:\Windows\system32\provsvc.dll 23:45:15.0440 4084 HomeGroupProvider - ok 23:45:15.0580 4084 HPDrvMntSvc.exe (f55442690a70a0278a7eed4faaebf576) C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe 23:45:15.0610 4084 HPDrvMntSvc.exe - ok 23:45:15.0650 4084 HpqKbFiltr (1210960ff8928950d2a786895b0c424a) C:\Windows\system32\DRIVERS\HpqKbFiltr.sys 23:45:15.0650 4084 HpqKbFiltr - ok 23:45:15.0750 4084 hpqwmiex (640e51db253265c3eac075866b3d2b33) C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 23:45:15.0810 4084 hpqwmiex - ok 23:45:15.0870 4084 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 23:45:15.0870 4084 HpSAMD - ok 23:45:15.0960 4084 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 23:45:15.0970 4084 HTTP - ok 23:45:16.0030 4084 huawei_enumerator (f44461e66f1b7dd267957fe9baa63ed0) C:\Windows\system32\DRIVERS\ew_jubusenum.sys 23:45:16.0030 4084 huawei_enumerator - ok 23:45:16.0130 4084 hwdatacard (f547f862b8907f1bcbd9b72a72a6449e) C:\Windows\system32\DRIVERS\ewusbmdm.sys 23:45:16.0130 4084 hwdatacard - ok 23:45:16.0250 4084 HWDeviceService.exe - ok 23:45:16.0310 4084 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 23:45:16.0310 4084 hwpolicy - ok 23:45:16.0340 4084 hwusbdev - ok 23:45:16.0420 4084 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 23:45:16.0420 4084 i8042prt - ok 23:45:16.0500 4084 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys 23:45:16.0510 4084 iaStorV - ok 23:45:16.0650 4084 ICM_UpdaterService (99730c456c8ff7a544d23445c7eeda4a) C:\Program Files\SAMSUNG\Samsung Networking Wizard\ICM_Service.exe 23:45:16.0670 4084 ICM_UpdaterService - ok 23:45:16.0880 4084 idsvc (c521d7eb6497bb1af6afa89e322fb43c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 23:45:16.0930 4084 idsvc - ok 23:45:17.0020 4084 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 23:45:17.0020 4084 iirsp - ok 23:45:17.0130 4084 IKEEXT (f95622f161474511b8d80d6b093aa610) C:\Windows\System32\ikeext.dll 23:45:17.0160 4084 IKEEXT - ok 23:45:17.0200 4084 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 23:45:17.0200 4084 intelide - ok 23:45:17.0240 4084 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 23:45:17.0250 4084 intelppm - ok 23:45:17.0280 4084 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 23:45:17.0310 4084 IPBusEnum - ok 23:45:17.0330 4084 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 23:45:17.0330 4084 IpFilterDriver - ok 23:45:17.0400 4084 iphlpsvc (4d65a07b795d6674312f879d09aa7663) C:\Windows\System32\iphlpsvc.dll 23:45:17.0430 4084 iphlpsvc - ok 23:45:17.0480 4084 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 23:45:17.0480 4084 IPMIDRV - ok 23:45:17.0500 4084 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 23:45:17.0500 4084 IPNAT - ok 23:45:17.0520 4084 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 23:45:17.0520 4084 IRENUM - ok 23:45:17.0540 4084 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 23:45:17.0550 4084 isapnp - ok 23:45:17.0580 4084 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 23:45:17.0580 4084 iScsiPrt - ok 23:45:17.0640 4084 JMCR (65da9fa42c0972fe5b9b7d6047f06f4c) C:\Windows\system32\DRIVERS\jmcr.sys 23:45:17.0640 4084 JMCR - ok 23:45:17.0680 4084 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys 23:45:17.0690 4084 kbdclass - ok 23:45:17.0700 4084 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys 23:45:17.0700 4084 kbdhid - ok 23:45:17.0750 4084 KeyIso (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 23:45:17.0760 4084 KeyIso - ok 23:45:17.0820 4084 KSecDD (b7895b4182c0d16f6efadeb8081e8d36) C:\Windows\system32\Drivers\ksecdd.sys 23:45:17.0830 4084 KSecDD - ok 23:45:17.0910 4084 KSecPkg (d30159ac9237519fbc62c6ec247d2d46) C:\Windows\system32\Drivers\ksecpkg.sys 23:45:17.0910 4084 KSecPkg - ok 23:45:17.0960 4084 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 23:45:17.0980 4084 KtmRm - ok 23:45:18.0050 4084 LanmanServer (d64af876d53eca3668bb97b51b4e70ab) C:\Windows\System32\srvsvc.dll 23:45:18.0080 4084 LanmanServer - ok 23:45:18.0120 4084 LanmanWorkstation (58405e4f68ba8e4057c6e914f326aba2) C:\Windows\System32\wkssvc.dll 23:45:18.0130 4084 LanmanWorkstation - ok 23:45:18.0190 4084 LightScribeService (83d8be94e1cbcbe2ea8372db1a95a159) C:\Program Files\Common Files\LightScribe\LSSrvc.exe 23:45:18.0220 4084 LightScribeService - ok 23:45:18.0500 4084 LiveUpdate (e605b9aabe1e2c88a4e21244379d524c) C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE 23:45:18.0580 4084 LiveUpdate - ok 23:45:18.0750 4084 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 23:45:18.0750 4084 lltdio - ok 23:45:18.0780 4084 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 23:45:18.0800 4084 lltdsvc - ok 23:45:18.0820 4084 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 23:45:18.0830 4084 lmhosts - ok 23:45:19.0010 4084 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 23:45:19.0010 4084 LSI_FC - ok 23:45:19.0030 4084 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 23:45:19.0030 4084 LSI_SAS - ok 23:45:19.0050 4084 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 23:45:19.0050 4084 LSI_SAS2 - ok 23:45:19.0070 4084 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 23:45:19.0070 4084 LSI_SCSI - ok 23:45:19.0120 4084 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 23:45:19.0120 4084 luafv - ok 23:45:19.0140 4084 massfilter - ok 23:45:19.0170 4084 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 23:45:19.0170 4084 megasas - ok 23:45:19.0200 4084 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 23:45:19.0200 4084 MegaSR - ok 23:45:19.0220 4084 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 23:45:19.0220 4084 MMCSS - ok 23:45:19.0240 4084 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 23:45:19.0240 4084 Modem - ok 23:45:19.0280 4084 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 23:45:19.0280 4084 monitor - ok 23:45:19.0330 4084 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys 23:45:19.0330 4084 mouclass - ok 23:45:19.0360 4084 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 23:45:19.0360 4084 mouhid - ok 23:45:19.0410 4084 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 23:45:19.0410 4084 mountmgr - ok 23:45:19.0520 4084 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 23:45:19.0560 4084 MozillaMaintenance - ok 23:45:19.0580 4084 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 23:45:19.0580 4084 mpio - ok 23:45:19.0600 4084 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 23:45:19.0600 4084 mpsdrv - ok 23:45:19.0670 4084 MpsSvc (9835584e999d25004e1ee8e5f3e3b881) C:\Windows\system32\mpssvc.dll 23:45:19.0680 4084 MpsSvc - ok 23:45:19.0730 4084 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 23:45:19.0730 4084 MRxDAV - ok 23:45:19.0790 4084 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 23:45:19.0790 4084 mrxsmb - ok 23:45:19.0840 4084 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 23:45:19.0850 4084 mrxsmb10 - ok 23:45:19.0860 4084 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 23:45:19.0870 4084 mrxsmb20 - ok 23:45:19.0910 4084 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 23:45:19.0920 4084 msahci - ok 23:45:19.0970 4084 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 23:45:19.0970 4084 msdsm - ok 23:45:20.0000 4084 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 23:45:20.0050 4084 MSDTC - ok 23:45:20.0100 4084 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 23:45:20.0100 4084 Msfs - ok 23:45:20.0110 4084 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 23:45:20.0110 4084 mshidkmdf - ok 23:45:20.0120 4084 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 23:45:20.0120 4084 msisadrv - ok 23:45:20.0180 4084 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 23:45:20.0200 4084 MSiSCSI - ok 23:45:20.0200 4084 msiserver - ok 23:45:20.0240 4084 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 23:45:20.0240 4084 MSKSSRV - ok 23:45:20.0260 4084 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 23:45:20.0260 4084 MSPCLOCK - ok 23:45:20.0280 4084 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 23:45:20.0280 4084 MSPQM - ok 23:45:20.0310 4084 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 23:45:20.0310 4084 MsRPC - ok 23:45:20.0350 4084 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 23:45:20.0350 4084 mssmbios - ok 23:45:20.0360 4084 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 23:45:20.0360 4084 MSTEE - ok 23:45:20.0400 4084 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 23:45:20.0400 4084 MTConfig - ok 23:45:20.0410 4084 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 23:45:20.0410 4084 Mup - ok 23:45:20.0490 4084 napagent (61d57a5d7c6d9afe10e77dae6e1b445e) C:\Windows\system32\qagentRT.dll 23:45:20.0500 4084 napagent - ok 23:45:20.0550 4084 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 23:45:20.0550 4084 NativeWifiP - ok 23:45:20.0710 4084 NAVENG (f11033730b38260b6892e837c457fb4b) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120716.002\NAVENG.SYS 23:45:20.0710 4084 NAVENG - ok 23:45:20.0870 4084 NAVEX15 (4e4e7c0259d3bb97de24a636c0e06aba) C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20120716.002\NAVEX15.SYS 23:45:20.0890 4084 NAVEX15 - ok 23:45:21.0090 4084 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 23:45:21.0110 4084 NDIS - ok 23:45:21.0160 4084 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 23:45:21.0160 4084 NdisCap - ok 23:45:21.0200 4084 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 23:45:21.0200 4084 NdisTapi - ok 23:45:21.0230 4084 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 23:45:21.0230 4084 Ndisuio - ok 23:45:21.0280 4084 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 23:45:21.0280 4084 NdisWan - ok 23:45:21.0330 4084 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 23:45:21.0330 4084 NDProxy - ok 23:45:21.0340 4084 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 23:45:21.0350 4084 NetBIOS - ok 23:45:21.0400 4084 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 23:45:21.0400 4084 NetBT - ok 23:45:21.0440 4084 Netlogon (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 23:45:21.0440 4084 Netlogon - ok 23:45:21.0500 4084 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 23:45:21.0520 4084 Netman - ok 23:45:21.0550 4084 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 23:45:21.0550 4084 netprofm - ok 23:45:21.0620 4084 NetTcpPortSharing (f476ec40033cdb91efbe73eb99b8362d) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 23:45:21.0630 4084 NetTcpPortSharing - ok 23:45:21.0860 4084 netw5v32 (58218ec6b61b1169cf54aab0d00f5fe2) C:\Windows\system32\DRIVERS\netw5v32.sys 23:45:21.0930 4084 netw5v32 - ok 23:45:22.0030 4084 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 23:45:22.0030 4084 nfrd960 - ok 23:45:22.0080 4084 NlaSvc (912084381d30d8b89ec4e293053f4710) C:\Windows\System32\nlasvc.dll 23:45:22.0080 4084 NlaSvc - ok 23:45:22.0140 4084 nmwcd (f6c40e0a565ee3ce5aeeb325e10054f2) C:\Windows\system32\drivers\ccdcmb.sys 23:45:22.0140 4084 nmwcd - ok 23:45:22.0180 4084 nmwcdc (2a394e9e1fa3565e4b2fea470ffe4d6b) C:\Windows\system32\drivers\ccdcmbo.sys 23:45:22.0190 4084 nmwcdc - ok 23:45:22.0250 4084 nmwcdnsu (99b224f8026cb534724aa3c408561e45) C:\Windows\system32\drivers\nmwcdnsu.sys 23:45:22.0250 4084 nmwcdnsu - ok 23:45:22.0300 4084 nmwcdnsuc (d23257682d349a5e2e4507ed33decc16) C:\Windows\system32\drivers\nmwcdnsuc.sys 23:45:22.0300 4084 nmwcdnsuc - ok 23:45:22.0310 4084 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 23:45:22.0310 4084 Npfs - ok 23:45:22.0370 4084 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 23:45:22.0370 4084 nsi - ok 23:45:22.0400 4084 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 23:45:22.0400 4084 nsiproxy - ok 23:45:22.0490 4084 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys 23:45:22.0510 4084 Ntfs - ok 23:45:22.0530 4084 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 23:45:22.0530 4084 Null - ok 23:45:22.0580 4084 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys 23:45:22.0590 4084 NVENETFD - ok 23:45:22.0660 4084 NVHDA (93c0f383b39b1f5fe7203e3270d4cf52) C:\Windows\system32\drivers\nvhda32v.sys 23:45:22.0660 4084 NVHDA - ok 23:45:23.0370 4084 nvlddmkm (66b4bf606fcc7f0622d4a21bb1461089) C:\Windows\system32\DRIVERS\nvlddmkm.sys 23:45:23.0520 4084 nvlddmkm - ok 23:45:23.0640 4084 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys 23:45:23.0650 4084 nvraid - ok 23:45:23.0670 4084 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys 23:45:23.0670 4084 nvstor - ok 23:45:23.0780 4084 nvsvc (d122f7c5f79c68868f5dc28cefeb2ecf) C:\Windows\system32\nvvsvc.exe 23:45:23.0820 4084 nvsvc - ok 23:45:24.0260 4084 nvUpdatusService (003cb0a155568b4a53a301f07c734233) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 23:45:24.0330 4084 nvUpdatusService - ok 23:45:24.0440 4084 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 23:45:24.0450 4084 nv_agp - ok 23:45:24.0560 4084 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 23:45:24.0610 4084 odserv - ok 23:45:24.0630 4084 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 23:45:24.0630 4084 ohci1394 - ok 23:45:24.0700 4084 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 23:45:24.0800 4084 ose - ok 23:45:24.0840 4084 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 23:45:24.0870 4084 p2pimsvc - ok 23:45:24.0910 4084 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 23:45:24.0930 4084 p2psvc - ok 23:45:24.0970 4084 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 23:45:24.0970 4084 Parport - ok 23:45:25.0010 4084 partmgr (3f34a1b4c5f6475f320c275e63afce9b) C:\Windows\system32\drivers\partmgr.sys 23:45:25.0010 4084 partmgr - ok 23:45:25.0020 4084 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 23:45:25.0020 4084 Parvdm - ok 23:45:25.0050 4084 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 23:45:25.0070 4084 PcaSvc - ok 23:45:25.0110 4084 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys 23:45:25.0120 4084 pccsmcfd - ok 23:45:25.0170 4084 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 23:45:25.0170 4084 pci - ok 23:45:25.0190 4084 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 23:45:25.0190 4084 pciide - ok 23:45:25.0210 4084 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 23:45:25.0220 4084 pcmcia - ok 23:45:25.0230 4084 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 23:45:25.0230 4084 pcw - ok 23:45:25.0320 4084 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 23:45:25.0330 4084 PEAUTH - ok 23:45:25.0500 4084 pla (414bba67a3ded1d28437eb66aeb8a720) C:\Windows\system32\pla.dll 23:45:25.0540 4084 pla - ok 23:45:25.0710 4084 PlugPlay (ec7bc28d207da09e79b3e9faf8b232ca) C:\Windows\system32\umpnpmgr.dll 23:45:25.0730 4084 PlugPlay - ok 23:45:25.0750 4084 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 23:45:25.0770 4084 PNRPAutoReg - ok 23:45:25.0810 4084 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 23:45:25.0810 4084 PNRPsvc - ok 23:45:25.0860 4084 PolicyAgent (53946b69ba0836bd95b03759530c81ec) C:\Windows\System32\ipsecsvc.dll 23:45:25.0880 4084 PolicyAgent - ok 23:45:25.0930 4084 Power (f87d30e72e03d579a5199ccb3831d6ea) C:\Windows\system32\umpo.dll 23:45:25.0950 4084 Power - ok 23:45:26.0020 4084 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 23:45:26.0020 4084 PptpMiniport - ok 23:45:26.0040 4084 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 23:45:26.0040 4084 Processor - ok 23:45:26.0100 4084 ProfSvc (cadefac453040e370a1bdff3973be00d) C:\Windows\system32\profsvc.dll 23:45:26.0130 4084 ProfSvc - ok 23:45:26.0160 4084 ProtectedStorage (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 23:45:26.0170 4084 ProtectedStorage - ok 23:45:26.0220 4084 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 23:45:26.0220 4084 Psched - ok 23:45:26.0290 4084 PSSDK42 (c8eb36910d3bd582891977e80925e21e) C:\Windows\system32\Drivers\pssdk42.sys 23:45:26.0290 4084 PSSDK42 - ok 23:45:26.0480 4084 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 23:45:26.0520 4084 ql2300 - ok 23:45:26.0650 4084 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 23:45:26.0660 4084 ql40xx - ok 23:45:26.0700 4084 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 23:45:26.0730 4084 QWAVE - ok 23:45:26.0740 4084 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 23:45:26.0740 4084 QWAVEdrv - ok 23:45:26.0760 4084 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 23:45:26.0760 4084 RasAcd - ok 23:45:26.0810 4084 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 23:45:26.0810 4084 RasAgileVpn - ok 23:45:26.0830 4084 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 23:45:26.0850 4084 RasAuto - ok 23:45:26.0870 4084 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 23:45:26.0870 4084 Rasl2tp - ok 23:45:27.0010 4084 RasMan (cb9e04dc05eacf5b9a36ca276d475006) C:\Windows\System32\rasmans.dll 23:45:27.0040 4084 RasMan - ok 23:45:27.0100 4084 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 23:45:27.0100 4084 RasPppoe - ok 23:45:27.0110 4084 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 23:45:27.0120 4084 RasSstp - ok 23:45:27.0160 4084 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 23:45:27.0160 4084 rdbss - ok 23:45:27.0170 4084 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 23:45:27.0170 4084 rdpbus - ok 23:45:27.0220 4084 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 23:45:27.0220 4084 RDPCDD - ok 23:45:27.0260 4084 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 23:45:27.0260 4084 RDPENCDD - ok 23:45:27.0270 4084 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 23:45:27.0270 4084 RDPREFMP - ok 23:45:27.0320 4084 RDPWD (f031683e6d1fea157abb2ff260b51e61) C:\Windows\system32\drivers\RDPWD.sys 23:45:27.0330 4084 RDPWD - ok 23:45:27.0370 4084 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 23:45:27.0380 4084 rdyboost - ok 23:45:27.0420 4084 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 23:45:27.0430 4084 RemoteAccess - ok 23:45:27.0460 4084 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 23:45:27.0480 4084 RemoteRegistry - ok 23:45:27.0540 4084 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys 23:45:27.0540 4084 RFCOMM - ok 23:45:27.0660 4084 RichVideo (498eb62a160674e793fa40fd65390625) C:\Program Files\CyberLink\Shared files\RichVideo.exe 23:45:27.0690 4084 RichVideo - ok 23:45:27.0720 4084 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 23:45:27.0740 4084 RpcEptMapper - ok 23:45:27.0750 4084 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 23:45:27.0770 4084 RpcLocator - ok 23:45:27.0840 4084 RpcSs (7660f01d3b38aca1747e397d21d790af) C:\Windows\system32\rpcss.dll 23:45:27.0850 4084 RpcSs - ok 23:45:27.0890 4084 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 23:45:27.0890 4084 rspndr - ok 23:45:27.0960 4084 RTL8167 (5283b9a27ff230f2ff70d92451ff409a) C:\Windows\system32\DRIVERS\Rt86win7.sys 23:45:27.0960 4084 RTL8167 - ok 23:45:28.0000 4084 SamSs (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 23:45:28.0010 4084 SamSs - ok 23:45:28.0050 4084 SavRoam (18b2c0bb057c62cc48466094e298d27f) C:\Program Files\Symantec AntiVirus\SavRoam.exe 23:45:28.0070 4084 SavRoam - ok 23:45:28.0130 4084 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 23:45:28.0130 4084 sbp2port - ok 23:45:28.0160 4084 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 23:45:28.0180 4084 SCardSvr - ok 23:45:28.0210 4084 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 23:45:28.0210 4084 scfilter - ok 23:45:28.0330 4084 Schedule (a04bb13f8a72f8b6e8b4071723e4e336) C:\Windows\system32\schedsvc.dll 23:45:28.0370 4084 Schedule - ok 23:45:28.0410 4084 SCPolicySvc (319c6b309773d063541d01df8ac6f55f) C:\Windows\System32\certprop.dll 23:45:28.0410 4084 SCPolicySvc - ok 23:45:28.0460 4084 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys 23:45:28.0460 4084 sdbus - ok 23:45:28.0480 4084 SDRSVC (08236c4bce5edd0a0318a438af28e0f7) C:\Windows\System32\SDRSVC.dll 23:45:28.0500 4084 SDRSVC - ok 23:45:28.0550 4084 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 23:45:28.0550 4084 secdrv - ok 23:45:28.0570 4084 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 23:45:28.0580 4084 seclogon - ok 23:45:28.0610 4084 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll 23:45:28.0630 4084 SENS - ok 23:45:28.0680 4084 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 23:45:28.0700 4084 SensrSvc - ok 23:45:28.0710 4084 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 23:45:28.0710 4084 Serenum - ok 23:45:28.0760 4084 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 23:45:28.0770 4084 Serial - ok 23:45:28.0810 4084 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 23:45:28.0810 4084 sermouse - ok 23:45:28.0990 4084 ServiceLayer (f31e9531af225ca25350d5e87e999b31) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 23:45:29.0030 4084 ServiceLayer - ok 23:45:29.0090 4084 SessionEnv (4ae380f39a0032eab7dd953030b26d28) C:\Windows\system32\sessenv.dll 23:45:29.0110 4084 SessionEnv - ok 23:45:29.0120 4084 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys 23:45:29.0130 4084 sffdisk - ok 23:45:29.0140 4084 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 23:45:29.0140 4084 sffp_mmc - ok 23:45:29.0160 4084 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys 23:45:29.0160 4084 sffp_sd - ok 23:45:29.0210 4084 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 23:45:29.0210 4084 sfloppy - ok 23:45:29.0280 4084 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 23:45:29.0310 4084 SharedAccess - ok 23:45:29.0360 4084 ShellHWDetection (414da952a35bf5d50192e28263b40577) C:\Windows\System32\shsvcs.dll 23:45:29.0390 4084 ShellHWDetection - ok 23:45:29.0430 4084 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 23:45:29.0430 4084 sisagp - ok 23:45:29.0470 4084 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 23:45:29.0470 4084 SiSRaid2 - ok 23:45:29.0490 4084 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 23:45:29.0490 4084 SiSRaid4 - ok 23:45:29.0530 4084 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 23:45:29.0530 4084 Smb - ok 23:45:29.0580 4084 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 23:45:29.0610 4084 SNMPTRAP - ok 23:45:29.0700 4084 SPBBCDrv (905782bcf15b6e5af9905b77923c7fa2) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 23:45:29.0700 4084 SPBBCDrv - ok 23:45:29.0710 4084 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 23:45:29.0720 4084 spldr - ok 23:45:29.0780 4084 Spooler (866a43013535dc8587c258e43579c764) C:\Windows\System32\spoolsv.exe 23:45:29.0840 4084 Spooler - ok 23:45:30.0150 4084 sppsvc (cf87a1de791347e75b98885214ced2b8) C:\Windows\system32\sppsvc.exe 23:45:30.0450 4084 sppsvc - ok 23:45:30.0590 4084 sppuinotify (b0180b20b065d89232a78a40fe56eaa6) C:\Windows\system32\sppuinotify.dll 23:45:30.0600 4084 sppuinotify - ok 23:45:30.0660 4084 SRTSP (8b938345e1d2e49465cc9c11ae410438) C:\Windows\system32\Drivers\SRTSP.SYS 23:45:30.0660 4084 SRTSP - ok 23:45:30.0700 4084 SRTSPL (f1eb4f77241ddf0bc11f5d638402a788) C:\Windows\system32\Drivers\SRTSPL.SYS 23:45:30.0700 4084 SRTSPL - ok 23:45:30.0710 4084 SRTSPX (be24052f4173bb6fe5badc032b6bc978) C:\Windows\system32\Drivers\SRTSPX.SYS 23:45:30.0710 4084 SRTSPX - ok 23:45:30.0780 4084 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 23:45:30.0790 4084 srv - ok 23:45:30.0820 4084 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 23:45:30.0820 4084 srv2 - ok 23:45:30.0890 4084 SrvHsfHDA (e00fdfaff025e94f9821153750c35a6d) C:\Windows\system32\DRIVERS\VSTAZL3.SYS 23:45:30.0890 4084 SrvHsfHDA - ok 23:45:31.0000 4084 SrvHsfV92 (ceb4e3b6890e1e42dca6694d9e59e1a0) C:\Windows\system32\DRIVERS\VSTDPV3.SYS 23:45:31.0030 4084 SrvHsfV92 - ok 23:45:31.0100 4084 SrvHsfWinac (bc0c7ea89194c299f051c24119000e17) C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 23:45:31.0110 4084 SrvHsfWinac - ok 23:45:31.0140 4084 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 23:45:31.0140 4084 srvnet - ok 23:45:31.0230 4084 SR_Service (addd489e5eea2f725cb13cebb36a042d) C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe 23:45:31.0240 4084 SR_Service - ok 23:45:31.0290 4084 SR_Watchdog (342e76ead7561675c67540750b5fda49) C:\Program Files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe 23:45:31.0310 4084 SR_Watchdog - ok 23:45:31.0360 4084 ssadbus (64e44acd8c238fcbbb78f0ba4bdc4b05) C:\Windows\system32\DRIVERS\ssadbus.sys 23:45:31.0370 4084 ssadbus - ok 23:45:31.0410 4084 ssadmdfl (bb2c84a15c765da89fd832b0e73f26ce) C:\Windows\system32\DRIVERS\ssadmdfl.sys 23:45:31.0410 4084 ssadmdfl - ok 23:45:31.0440 4084 ssadmdm (6d0d132ddc6f43eda00dced6d8b1ca31) C:\Windows\system32\DRIVERS\ssadmdm.sys 23:45:31.0440 4084 ssadmdm - ok 23:45:31.0530 4084 sscdbus (069351a1d7d291013177a90ae6edccbc) C:\Windows\system32\DRIVERS\sscdbus.sys 23:45:31.0530 4084 sscdbus - ok 23:45:31.0580 4084 sscdmdfl (1c925be223a5c0f9f469252292a48df6) C:\Windows\system32\DRIVERS\sscdmdfl.sys 23:45:31.0580 4084 sscdmdfl - ok 23:45:31.0610 4084 sscdmdm (ae3e77ae0fbdb07eb1ac3fed74a0695e) C:\Windows\system32\DRIVERS\sscdmdm.sys 23:45:31.0610 4084 sscdmdm - ok 23:45:31.0660 4084 sscdserd (6c239402a3303c66016f5f915e0e8698) C:\Windows\system32\DRIVERS\sscdserd.sys 23:45:31.0670 4084 sscdserd - ok 23:45:31.0710 4084 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 23:45:31.0730 4084 SSDPSRV - ok 23:45:31.0750 4084 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 23:45:31.0770 4084 SstpSvc - ok 23:45:31.0940 4084 STacSV (fe7f776f2590c8331123bda3a3a21de6) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe 23:45:31.0970 4084 STacSV - ok 23:45:31.0990 4084 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 23:45:31.0990 4084 stexstor - ok 23:45:32.0070 4084 STHDA (dadb74bf26766757dbba9c5912969ebf) C:\Windows\system32\DRIVERS\stwrt.sys 23:45:32.0070 4084 STHDA - ok 23:45:32.0150 4084 StiSvc (e1fb3706030fb4578a0d72c2fc3689e4) C:\Windows\System32\wiaservc.dll 23:45:32.0180 4084 StiSvc - ok 23:45:32.0220 4084 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 23:45:32.0220 4084 swenum - ok 23:45:32.0270 4084 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 23:45:32.0290 4084 swprv - ok 23:45:32.0490 4084 Symantec AntiVirus (3ce76938766fb2e1694957c138ddd1ca) C:\Program Files\Symantec AntiVirus\Rtvscan.exe 23:45:32.0530 4084 Symantec AntiVirus - ok 23:45:32.0580 4084 SymEvent (d430a5fa6a82d0b53db969067535c92b) C:\Program Files\Symantec\SYMEVENT.SYS 23:45:32.0580 4084 SymEvent - ok 23:45:32.0690 4084 SYMREDRV (90a15cd58994ceaf7697f03ab4b304a0) C:\Windows\System32\Drivers\SYMREDRV.SYS 23:45:32.0690 4084 SYMREDRV - ok 23:45:32.0720 4084 SYMTDI (169cc67cc03c1c7195787c49d200e232) C:\Windows\System32\Drivers\SYMTDI.SYS 23:45:32.0720 4084 SYMTDI - ok 23:45:32.0850 4084 SysMain (36650d618ca34c9d357dfd3d89b2c56f) C:\Windows\system32\sysmain.dll 23:45:32.0890 4084 SysMain - ok 23:45:32.0960 4084 TabletInputService (763fecdc3d30c815fe72dd57936c6cd1) C:\Windows\System32\TabSvc.dll 23:45:32.0970 4084 TabletInputService - ok 23:45:33.0030 4084 TapiSrv (613bf4820361543956909043a265c6ac) C:\Windows\System32\tapisrv.dll 23:45:33.0050 4084 TapiSrv - ok 23:45:33.0080 4084 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 23:45:33.0100 4084 TBS - ok 23:45:33.0240 4084 Tcpip (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\drivers\tcpip.sys 23:45:33.0270 4084 Tcpip - ok 23:45:33.0300 4084 TCPIP6 (7fa2e0f8b072bd04b77b421480b6cc22) C:\Windows\system32\DRIVERS\tcpip.sys 23:45:33.0310 4084 TCPIP6 - ok 23:45:33.0360 4084 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 23:45:33.0360 4084 tcpipreg - ok 23:45:33.0410 4084 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 23:45:33.0410 4084 TDPIPE - ok 23:45:33.0450 4084 TDTCP (2c2c5afe7ee4f620d69c23c0617651a8) C:\Windows\system32\drivers\tdtcp.sys 23:45:33.0450 4084 TDTCP - ok 23:45:33.0490 4084 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 23:45:33.0500 4084 tdx - ok 23:45:33.0530 4084 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 23:45:33.0530 4084 TermDD - ok 23:45:33.0610 4084 TermService (382c804c92811be57829d8e550a900e2) C:\Windows\System32\termsrv.dll 23:45:33.0640 4084 TermService - ok 23:45:33.0660 4084 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 23:45:33.0680 4084 Themes - ok 23:45:33.0710 4084 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 23:45:33.0710 4084 THREADORDER - ok 23:45:33.0750 4084 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 23:45:33.0770 4084 TrkWks - ok 23:45:33.0840 4084 TrustedInstaller (2c49b175aee1d4364b91b531417fe583) C:\Windows\servicing\TrustedInstaller.exe 23:45:33.0870 4084 TrustedInstaller - ok 23:45:33.0890 4084 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 23:45:33.0890 4084 tssecsrv - ok 23:45:33.0940 4084 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 23:45:33.0940 4084 TsUsbFlt - ok 23:45:34.0000 4084 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 23:45:34.0000 4084 tunnel - ok 23:45:34.0030 4084 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 23:45:34.0030 4084 uagp35 - ok 23:45:34.0090 4084 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 23:45:34.0090 4084 udfs - ok 23:45:34.0390 4084 ufad-ws60 (d2c615d21d4c69459ef2306980ff3e39) C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe 23:45:34.0470 4084 ufad-ws60 - ok 23:45:34.0510 4084 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 23:45:34.0520 4084 UI0Detect - ok 23:45:34.0560 4084 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 23:45:34.0560 4084 uliagpkx - ok 23:45:34.0620 4084 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 23:45:34.0620 4084 umbus - ok 23:45:34.0660 4084 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 23:45:34.0660 4084 UmPass - ok 23:45:34.0690 4084 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 23:45:34.0720 4084 upnphost - ok 23:45:34.0770 4084 upperdev (47f5f9d837d80ffd5882a14db9da0a67) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys 23:45:34.0770 4084 upperdev - ok 23:45:34.0810 4084 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys 23:45:34.0810 4084 usbccgp - ok 23:45:34.0840 4084 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 23:45:34.0840 4084 usbcir - ok 23:45:34.0880 4084 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\DRIVERS\usbehci.sys 23:45:34.0880 4084 usbehci - ok 23:45:34.0910 4084 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys 23:45:34.0910 4084 usbhub - ok 23:45:34.0940 4084 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 23:45:34.0940 4084 usbohci - ok 23:45:34.0950 4084 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 23:45:34.0950 4084 usbprint - ok 23:45:35.0000 4084 usbser (31181de6190b39fc8007dffd1a48ffd6) C:\Windows\system32\drivers\usbser.sys 23:45:35.0000 4084 usbser - ok 23:45:35.0050 4084 UsbserFilt (e44f0d17be0908b58dcc99ccb99c6c32) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys 23:45:35.0050 4084 UsbserFilt - ok 23:45:35.0140 4084 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 23:45:35.0140 4084 USBSTOR - ok 23:45:35.0190 4084 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\DRIVERS\usbuhci.sys 23:45:35.0190 4084 usbuhci - ok 23:45:35.0240 4084 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys 23:45:35.0240 4084 usbvideo - ok 23:45:35.0300 4084 usb_rndisx (d82f43d15fdaa666856c0190cb73e7c9) C:\Windows\system32\DRIVERS\usb8023x.sys 23:45:35.0300 4084 usb_rndisx - ok 23:45:35.0320 4084 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 23:45:35.0340 4084 UxSms - ok 23:45:35.0370 4084 VaultSvc (81951f51e318aecc2d68559e47485cc4) C:\Windows\system32\lsass.exe 23:45:35.0370 4084 VaultSvc - ok 23:45:35.0460 4084 VBoxDrv (1d7e97b590d36cfb228c7db30da83992) C:\Windows\system32\DRIVERS\VBoxDrv.sys 23:45:35.0460 4084 VBoxDrv - ok 23:45:35.0510 4084 VBoxNetAdp (4ee5d94e3aee7cd9584a46793613e114) C:\Windows\system32\DRIVERS\VBoxNetAdp.sys 23:45:35.0510 4084 VBoxNetAdp - ok 23:45:35.0540 4084 VBoxNetFlt (67dd12dda776f1cdf449b88bb65287b7) C:\Windows\system32\DRIVERS\VBoxNetFlt.sys 23:45:35.0540 4084 VBoxNetFlt - ok 23:45:35.0600 4084 VBoxUSBMon (3530ae9d65ab9cda3f5e3acbc485895e) C:\Windows\system32\DRIVERS\VBoxUSBMon.sys 23:45:35.0600 4084 VBoxUSBMon - ok 23:45:35.0630 4084 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 23:45:35.0630 4084 vdrvroot - ok 23:45:35.0700 4084 vds (c3cd30495687c2a2f66a65ca6fd89be9) C:\Windows\System32\vds.exe 23:45:35.0760 4084 vds - ok 23:45:35.0790 4084 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 23:45:35.0790 4084 vga - ok 23:45:35.0800 4084 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 23:45:35.0800 4084 VgaSave - ok 23:45:35.0850 4084 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 23:45:35.0850 4084 vhdmp - ok 23:45:35.0900 4084 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 23:45:35.0900 4084 viaagp - ok 23:45:35.0920 4084 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 23:45:35.0920 4084 ViaC7 - ok 23:45:35.0930 4084 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 23:45:35.0930 4084 viaide - ok 23:45:36.0040 4084 VMAuthdService (e72dca96ff461bd94cb432eb1aab24e5) C:\Program Files\VMware\VMware Workstation\vmware-authd.exe 23:45:36.0070 4084 VMAuthdService - ok 23:45:36.0110 4084 vmkbd (94ee89070a4de65e78f384eb0b01ff52) C:\Windows\system32\drivers\VMkbd.sys 23:45:36.0110 4084 vmkbd - ok 23:45:36.0140 4084 VMnetAdapter (f68c99f41c3cf6e1c3c542fadd2e20cf) C:\Windows\system32\DRIVERS\vmnetadapter.sys 23:45:36.0140 4084 VMnetAdapter - ok 23:45:36.0160 4084 VMnetBridge (121fbda3a14f0744a8c213d3e9f14d63) C:\Windows\system32\DRIVERS\vmnetbridge.sys 23:45:36.0160 4084 VMnetBridge - ok 23:45:36.0190 4084 VMnetDHCP (b50a9bf5d713f4c7712e683ed13c5734) C:\Windows\system32\vmnetdhcp.exe 23:45:36.0220 4084 VMnetDHCP - ok 23:45:36.0230 4084 VMnetuserif (8e4e32effb6d28936c532ae4997e85a7) C:\Windows\system32\drivers\vmnetuserif.sys 23:45:36.0230 4084 VMnetuserif - ok 23:45:36.0300 4084 vmount2 (7becf16932abbcd71627c500e31a8be6) C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe 23:45:36.0330 4084 vmount2 - ok 23:45:36.0370 4084 VMware NAT Service (e5d4417659a2cb305a5f6a47ade9da3b) C:\Windows\system32\vmnat.exe 23:45:36.0390 4084 VMware NAT Service - ok 23:45:36.0440 4084 vmx86 (1f985607e66d66591e7abd552b8ea618) C:\Windows\system32\Drivers\vmx86.sys 23:45:36.0450 4084 vmx86 - ok 23:45:36.0530 4084 VNASC (5fb77241b22bfbdc2fdef011696701b2) C:\Windows\system32\DRIVERS\vnasc.sys 23:45:36.0530 4084 VNASC - ok 23:45:36.0570 4084 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 23:45:36.0570 4084 volmgr - ok 23:45:36.0620 4084 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 23:45:36.0630 4084 volmgrx - ok 23:45:36.0680 4084 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 23:45:36.0680 4084 volsnap - ok 23:45:36.0810 4084 VPN-1 (f93742fa61f8b204d9a70d2d4b333782) C:\Windows\System32\drivers\vpn.sys 23:45:36.0820 4084 VPN-1 - ok 23:45:36.0870 4084 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 23:45:36.0870 4084 vsmraid - ok 23:45:36.0990 4084 VSS (209a3b1901b83aeb8527ed211cce9e4c) C:\Windows\system32\vssvc.exe 23:45:37.0050 4084 VSS - ok 23:45:37.0210 4084 vstor2 (9e4ff401725fe6a26d8fe492bf0ea2b1) C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vstor2.sys 23:45:37.0210 4084 vstor2 - ok 23:45:37.0280 4084 vstor2-ws60 (b44a2eb67d1a819ec5d95e3af9cad46d) C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys 23:45:37.0280 4084 vstor2-ws60 - ok 23:45:37.0300 4084 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 23:45:37.0300 4084 vwifibus - ok 23:45:37.0310 4084 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 23:45:37.0320 4084 vwififlt - ok 23:45:37.0360 4084 vwifimp (a3f04cbea6c2a10e6cb01f8b47611882) C:\Windows\system32\DRIVERS\vwifimp.sys 23:45:37.0360 4084 vwifimp - ok 23:45:37.0410 4084 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 23:45:37.0440 4084 W32Time - ok 23:45:37.0470 4084 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 23:45:37.0470 4084 WacomPen - ok 23:45:37.0520 4084 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 23:45:37.0520 4084 WANARP - ok 23:45:37.0530 4084 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 23:45:37.0530 4084 Wanarpv6 - ok 23:45:37.0660 4084 wbengine (691e3285e53dca558e1a84667f13e15a) C:\Windows\system32\wbengine.exe 23:45:37.0740 4084 wbengine - ok 23:45:37.0770 4084 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 23:45:37.0790 4084 WbioSrvc - ok 23:45:37.0850 4084 wcncsvc (34eee0dfaadb4f691d6d5308a51315dc) C:\Windows\System32\wcncsvc.dll 23:45:37.0880 4084 wcncsvc - ok 23:45:37.0900 4084 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 23:45:37.0920 4084 WcsPlugInService - ok 23:45:37.0970 4084 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 23:45:37.0970 4084 Wd - ok 23:45:38.0040 4084 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 23:45:38.0050 4084 Wdf01000 - ok 23:45:38.0070 4084 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 23:45:38.0090 4084 WdiServiceHost - ok 23:45:38.0100 4084 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 23:45:38.0100 4084 WdiSystemHost - ok 23:45:38.0150 4084 WebClient (a9d880f97530d5b8fee278923349929d) C:\Windows\System32\webclnt.dll 23:45:38.0170 4084 WebClient - ok 23:45:38.0210 4084 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 23:45:38.0230 4084 Wecsvc - ok 23:45:38.0260 4084 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 23:45:38.0280 4084 wercplsupport - ok 23:45:38.0320 4084 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 23:45:38.0330 4084 WerSvc - ok 23:45:38.0350 4084 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 23:45:38.0350 4084 WfpLwf - ok 23:45:38.0380 4084 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 23:45:38.0380 4084 WIMMount - ok 23:45:38.0520 4084 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 23:45:38.0550 4084 WinDefend - ok 23:45:38.0560 4084 WinHttpAutoProxySvc - ok 23:45:38.0620 4084 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 23:45:38.0640 4084 Winmgmt - ok 23:45:38.0770 4084 WinRM (1b91cd34ea3a90ab6a4ef0550174f4cc) C:\Windows\system32\WsmSvc.dll 23:45:38.0810 4084 WinRM - ok 23:45:38.0910 4084 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys 23:45:38.0910 4084 WinUsb - ok 23:45:38.0980 4084 wirelessusbser (ccaec5175f1ebc6eb0dbd607eea791c1) C:\Windows\system32\DRIVERS\3GDatausbser.sys 23:45:38.0980 4084 wirelessusbser - ok 23:45:39.0080 4084 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 23:45:39.0110 4084 Wlansvc - ok 23:45:39.0250 4084 wlcrasvc (6067acef367e79914af628fa1e9b5330) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 23:45:39.0280 4084 wlcrasvc - ok 23:45:39.0660 4084 wlidsvc (0a70f4022ec2e14c159efc4f69aa2477) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 23:45:39.0760 4084 wlidsvc - ok 23:45:39.0890 4084 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 23:45:39.0890 4084 WmiAcpi - ok 23:45:39.0950 4084 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 23:45:39.0980 4084 wmiApSrv - ok 23:45:40.0190 4084 WMPNetworkSvc (3b40d3a61aa8c21b88ae57c58ab3122e) C:\Program Files\Windows Media Player\wmpnetwk.exe 23:45:40.0220 4084 WMPNetworkSvc - ok 23:45:40.0240 4084 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 23:45:40.0250 4084 WPCSvc - ok 23:45:40.0310 4084 WPDBusEnum (aa53356d60af47eacc85bc617a4f3f66) C:\Windows\system32\wpdbusenum.dll 23:45:40.0330 4084 WPDBusEnum - ok 23:45:40.0380 4084 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 23:45:40.0380 4084 ws2ifsl - ok 23:45:40.0420 4084 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 23:45:40.0440 4084 wscsvc - ok 23:45:40.0450 4084 WSearch - ok 23:45:40.0650 4084 wuauserv (fc3ec24fce372c89423e015a2ac1a31e) C:\Windows\system32\wuaueng.dll 23:45:40.0720 4084 wuauserv - ok 23:45:40.0860 4084 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 23:45:40.0870 4084 WudfPf - ok 23:45:40.0920 4084 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 23:45:40.0920 4084 WUDFRd - ok 23:45:40.0970 4084 wudfsvc (8d1e1e529a2c9e9b6a85b55a345f7629) C:\Windows\System32\WUDFSvc.dll 23:45:40.0980 4084 wudfsvc - ok 23:45:41.0030 4084 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 23:45:41.0050 4084 WwanSvc - ok 23:45:41.0120 4084 ZTEusbmdm6k (f6520e06c15dea5ab7bb016309fe4bb3) C:\Windows\system32\DRIVERS\ZTEusbmdm6k.sys 23:45:41.0120 4084 ZTEusbmdm6k - ok 23:45:41.0140 4084 ZTEusbnmea (f6520e06c15dea5ab7bb016309fe4bb3) C:\Windows\system32\DRIVERS\ZTEusbnmea.sys 23:45:41.0140 4084 ZTEusbnmea - ok 23:45:41.0170 4084 ZTEusbser6k (f6520e06c15dea5ab7bb016309fe4bb3) C:\Windows\system32\DRIVERS\ZTEusbser6k.sys 23:45:41.0170 4084 ZTEusbser6k - ok 23:45:41.0220 4084 ZTEusbvoice (f6520e06c15dea5ab7bb016309fe4bb3) C:\Windows\system32\DRIVERS\ZTEusbvoice.sys 23:45:41.0220 4084 ZTEusbvoice - ok 23:45:41.0300 4084 MBR (0x1B8) (d71a8b323c50cda37be17fc9dc225361) \Device\Harddisk0\DR0 23:45:41.0590 4084 \Device\Harddisk0\DR0 - ok 23:45:41.0600 4084 Boot (0x1200) (470ac0092d6b1a5738b604fbeefd857d) \Device\Harddisk0\DR0\Partition0 23:45:41.0600 4084 \Device\Harddisk0\DR0\Partition0 - ok 23:45:41.0610 4084 Boot (0x1200) (b8c5a812b3be44a4616aefe6b6881948) \Device\Harddisk0\DR0\Partition1 23:45:41.0610 4084 \Device\Harddisk0\DR0\Partition1 - ok 23:45:41.0640 4084 Boot (0x1200) (1e2722d1c2ca05e0214fe489074ebd1e) \Device\Harddisk0\DR0\Partition2 23:45:41.0640 4084 \Device\Harddisk0\DR0\Partition2 - ok 23:45:41.0670 4084 Boot (0x1200) (d3861554f0f1a452f208f9176371ae85) \Device\Harddisk0\DR0\Partition3 23:45:41.0670 4084 \Device\Harddisk0\DR0\Partition3 - ok 23:45:41.0670 4084 ============================================================ 23:45:41.0670 4084 Scan finished 23:45:41.0670 4084 ============================================================ 23:45:41.0690 2548 Detected object count: 0 23:45:41.0690 2548 Actual detected object count: 0

Attachments:

Hi vijay.gupta,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————


NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
ComboFix 12-07-16.01 - Vijay 17-07-2012 1:37.2.2 - x86 Microsoft Windows 7 Home Basic 6.1.7601.1.1252.91.1033.18.3039.1844 [GMT 5.5:30] Running from: c:\users\[removed]\Downloads\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe c:\program files\FunWebProducts c:\program files\TelevisionFanaticEI C:\test.txt c:\windows\system32\drivers\etc\hosts.ics c:\windows\system32\muzapp.exe . . ((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 ))))))))))))))))))))))))))))))) . . 2012-07-16 20:23 . 2012-07-16 20:23 ——– d—–w- c:\users\UpdatusUser\AppData\Local\temp 2012-07-16 20:23 . 2012-07-16 20:23 ——– d—–w- c:\users\Public\AppData\Local\temp 2012-07-16 20:23 . 2012-07-16 20:23 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-07-15 17:06 . 2012-07-15 17:06 388096 —-a-r- c:\users\Vijay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-07-15 16:59 . 2012-07-15 16:59 ——– d—–w- c:\program files\Trend Micro 2012-07-15 14:38 . 2012-07-15 14:38 ——– d—–w- c:\users\Vijay\AppData\Roaming\Yahoo! 2012-07-15 13:22 . 2012-07-15 13:22 ——– d—–w- c:\users\Vijay\VirtualBox VMs 2012-07-15 08:30 . 2012-07-16 20:13 56200 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\offreg.dll 2012-07-15 08:29 . 2012-07-15 15:56 ——– d—–w- c:\users\Vijay\.VirtualBox 2012-07-15 08:27 . 2012-06-05 11:03 158552 —-a-w- c:\windows\system32\drivers\VBoxDrv.sys 2012-07-15 08:27 . 2012-06-05 11:03 91992 —-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2012-07-15 08:27 . 2012-07-15 08:27 ——– d—–w- c:\program files\Oracle 2012-07-13 18:50 . 2012-06-17 21:44 6762896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\mpengine.dll 2012-07-13 18:50 . 2012-05-31 06:55 237072 ——w- c:\windows\system32\MpSigStub.exe 2012-07-12 04:41 . 2012-06-12 02:40 2345984 —-a-w- c:\windows\system32\win32k.sys 2012-07-05 17:56 . 2012-07-05 17:56 ——– d—–w- c:\program files\Gophoto.it 2012-07-05 17:55 . 2012-07-05 18:39 ——– d—–w- c:\program files\1ClickDownload 2012-07-05 05:08 . 2012-07-05 05:08 ——– d—–w- C:\garg 2012-06-30 19:32 . 2012-07-06 07:00 ——– d—–w- C:\f2820a3e66ec22977737ae 2012-06-27 18:28 . 2012-06-27 18:34 ——– d—–w- c:\programdata\FarmFrenzy-PizzaParty 2012-06-26 17:49 . 2012-06-26 17:49 770384 —-a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-26 17:49 . 2012-06-26 17:49 421200 —-a-w- c:\program files\Mozilla Firefox\msvcp100.dll 2012-06-25 18:01 . 2012-06-02 22:19 53784 —-a-w- c:\windows\system32\wuauclt.exe 2012-06-25 18:01 . 2012-06-02 22:19 45080 —-a-w- c:\windows\system32\wups2.dll 2012-06-25 18:01 . 2012-06-02 22:19 1933848 —-a-w- c:\windows\system32\wuaueng.dll 2012-06-25 18:01 . 2012-06-02 22:12 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-25 18:01 . 2012-06-02 22:19 35864 —-a-w- c:\windows\system32\wups.dll 2012-06-25 18:01 . 2012-06-02 22:19 577048 —-a-w- c:\windows\system32\wuapi.dll 2012-06-25 18:01 . 2012-06-02 22:12 88576 —-a-w- c:\windows\system32\wudriver.dll 2012-06-25 18:01 . 2012-06-02 09:49 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-25 18:01 . 2012-06-02 09:42 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-25 10:34 . 2012-06-25 10:34 1394248 —-a-w- c:\windows\system32\msxml4.dll 2012-06-21 04:54 . 2012-06-21 04:54 ——– d—–w- c:\users\Vijay\AppData\Local\visi_coupon 2012-06-19 18:53 . 2012-06-19 18:53 ——– d—–w- c:\users\Vijay\AppData\Local\Macromedia 2012-06-17 11:27 . 2011-03-26 05:07 107776 —-a-w- c:\windows\system32\drivers\ZTEusbvoice.sys 2012-06-17 11:27 . 2011-03-26 05:07 107776 —-a-w- c:\windows\system32\drivers\ZTEusbser6k.sys 2012-06-17 11:27 . 2011-03-26 05:07 107776 —-a-w- c:\windows\system32\drivers\ZTEusbnmea.sys 2012-06-17 11:27 . 2011-03-26 05:07 107776 —-a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys 2012-06-17 11:27 . 2012-07-06 07:00 ——– d—–w- c:\program files\Beetel Connection Manager 2012-06-17 11:18 . 2008-08-26 03:56 18816 —-a-w- c:\windows\system32\drivers\pccsmcfd.sys 2012-06-17 11:17 . 2012-06-17 11:17 ——– d—–w- c:\program files\PC Connectivity Solution 2012-06-17 10:06 . 2012-06-17 10:07 ——– d—–w- C:\data 2012-06-16 21:59 . 2012-06-16 21:59 ——– d—–w- c:\program files\Common Files\Java 2012-06-16 21:59 . 2012-06-16 21:59 476936 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-06-16 21:59 . 2012-06-16 21:59 ——– d—–w- c:\program files\Java 2012-06-16 21:31 . 2011-04-27 08:49 821824 —-a-w- c:\windows\system32\dgderapi.dll 2012-06-16 20:31 . 1997-01-15 18:30 191248 —-a-w- c:\windows\system32\TABCTL32.OCX 2012-06-16 20:31 . 1996-11-16 18:30 89600 —-a-w- c:\windows\system32\MSCAL.OCX 2012-06-16 20:30 . 1998-09-01 10:14 1355776 —-a-w- c:\windows\system32\MSVBVM50.dll 2012-06-16 20:30 . 1997-01-15 18:30 71680 —-a-w- c:\windows\ST5UNST.EXE 2012-06-16 20:30 . 1997-01-15 18:30 29696 —-a-w- c:\windows\system32\VB5StKit.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-12 05:35 . 2012-04-01 04:38 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-12 05:35 . 2011-06-19 18:26 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-16 21:59 . 2010-10-02 06:59 472840 —-a-w- c:\windows\system32\deployJava1.dll 2012-06-05 11:03 . 2012-06-05 11:03 116056 —-a-w- c:\windows\system32\drivers\VBoxNetFlt.sys 2012-06-05 11:03 . 2012-06-05 11:03 104792 —-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2012-06-05 11:02 . 2012-06-05 11:02 135512 —-a-w- c:\windows\system32\VBoxNetFltNobj.dll 2012-05-21 19:23 . 2010-06-24 06:03 19736 —-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-15 03:03 . 2012-06-13 04:44 981504 —-a-w- c:\windows\system32\wininet.dll 2012-05-04 09:59 . 2012-06-13 04:45 514560 —-a-w- c:\windows\system32\qdvd.dll 2012-05-01 04:44 . 2012-06-13 04:43 164352 —-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17 . 2012-06-13 04:44 183808 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45 . 2012-06-13 04:43 58880 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45 . 2012-06-13 04:43 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41 . 2012-06-13 04:43 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-24 04:36 . 2012-06-13 04:43 1158656 —-a-w- c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-13 04:43 140288 —-a-w- c:\windows\system32\cryptsvc.dll 2012-04-24 04:36 . 2012-06-13 04:43 103936 —-a-w- c:\windows\system32\cryptnet.dll 2012-04-20 03:16 . 2012-06-13 04:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-08-20 16:04 . 2011-08-22 06:30 161736 —-a-w- c:\program files\64res.dll 2012-06-26 17:49 . 2011-03-26 10:22 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-15 282624] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-13 95848] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-14 134856] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-03-23 495708] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2007-05-01 68400] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-31 795936] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "HideFastUserSwitching"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system] "WallpaperStyle"= 2 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Users^Vijay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^IDrive Tray.lnk] path=c:\users\Vijay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDrive Tray.lnk backup=c:\windows\pss\IDrive Tray.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 07:37 843712 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2012-06-14 17:52 116648 —-atw- c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR] 2009-07-16 00:51 1668664 —-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper] 2011-04-28 19:54 934800 —-a-w- c:\program files\Samsung\Kies\KiesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR] 2011-04-28 19:54 19856 —-a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2011-04-28 19:54 3373968 —-a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe] 2009-06-24 21:57 320056 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-18 08:32 254696 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu] 2009-02-18 04:21 218408 ——w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut] 2009-05-20 05:16 222504 —-a-w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray] 2007-05-01 17:22 56112 —-a-w- c:\program files\VMware\VMware Workstation\hqtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray] 2007-05-01 17:22 68400 —-a-w- c:\program files\VMware\VMware Workstation\vmware-tray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant] 2009-07-23 18:04 498744 —-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys [x] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] R3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x] R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\3GDatausbser.sys [x] R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [x] R4 ICM_UpdaterService;ICM_UpdaterService Disp;c:\program files\SAMSUNG\Samsung Networking Wizard\ICM_Service.exe [x] R4 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe [x] S2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [x] S2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [x] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x] S2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\DatacardService\HWDeviceService.exe [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x] S2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\DRIVERS\vnasc.sys [x] S2 VPN-1;VPN-1 Module;c:\windows\System32\drivers\vpn.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 FW1;SecuRemote Miniport;c:\windows\system32\DRIVERS\fw.sys [x] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x] S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 19:11 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-07-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 05:35] . 2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000Core.job - c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52] . 2012-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000UA.job - c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52] . . ——- Supplementary Scan ——- . uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_IN&c=94&bd=Presario&pf=cnnb uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 TCP: Interfaces\{48330B93-88E8-47AB-9FFA-1F1BC113E19E}: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{98A2A3BA-92DA-4C9C-8253-A96B6738C3F2}: NameServer = 172.16.16.1,4.2.2.2 FF - ProfilePath - c:\users\Vijay\AppData\Roaming\Mozilla\Firefox\Profiles\c3pzohvf.default\ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file) Toolbar-Locked - (no file) ShellExecuteHooks-{A5949E07-8536-4625-A3D0-2DD83F559990} - (no file) MSConfigStartUp-NSU_agent - c:\program files\Nokia\Nokia Software Updater\nsu3ui_agent.exe MSConfigStartUp-OliveDcService - c:\program files\TATA Photon+\Olive\CE310\Drivers\OliveDcService.exe MSConfigStartUp-QPService - c:\program files\HP\QuickPlay\QPService.exe MSConfigStartUp-TATA Photon+ Dialer - c:\program files\TATA Photon+\Olive\CE310\TTSL Olive CE310 Dialer Ver 1.1.7 AddRemove-01_Simmental - c:\program files\SAMSUNG\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - c:\program files\SAMSUNG\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - c:\program files\SAMSUNG\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - c:\program files\SAMSUNG\USB Drivers\04_semseyite\Uninstall.exe AddRemove-05_Sloan - c:\program files\SAMSUNG\USB Drivers\05_Sloan\Uninstall.exe AddRemove-06_Spencer - c:\program files\SAMSUNG\USB Drivers\06_Spencer\Uninstall.exe AddRemove-07_Schorl - c:\program files\SAMSUNG\USB Drivers\07_Schorl\Uninstall.exe AddRemove-08_EMPChipset - c:\program files\SAMSUNG\USB Drivers\08_EMPChipset\Uninstall.exe AddRemove-09_Hsp - c:\program files\SAMSUNG\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-12_Symbian_USB_Download_Driver - c:\program files\SAMSUNG\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\SAMSUNG\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe AddRemove-16_Shrewsbury - c:\program files\SAMSUNG\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-17_EMP_Chipset2 - c:\program files\SAMSUNG\USB Drivers\17_EMP_Chipset2\Uninstall.exe AddRemove-18_Zinia_Serial_Driver - c:\program files\SAMSUNG\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe AddRemove-19_VIA_driver - c:\program files\SAMSUNG\USB Drivers\19_VIA_driver\Uninstall.exe AddRemove-20_NXP_Driver - c:\program files\SAMSUNG\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-21_Searsburg - c:\program files\SAMSUNG\USB Drivers\21_Searsburg\Uninstall.exe AddRemove-22_WiBro_WiMAX - c:\program files\SAMSUNG\USB Drivers\22_WiBro_WiMAX\Uninstall.exe AddRemove-24_flashusbdriver - c:\program files\SAMSUNG\USB Drivers\24_flashusbdriver\Uninstall.exe AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-818653106-4120140212-1750785515-1000) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0014\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0015\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0023\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(3844) c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr . ———————— Other Running Processes ———————— . c:\windows\system32\nvvsvc.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\STacSV.exe c:\program files\NVIDIA Corporation\Display\nvxdsync.exe c:\windows\system32\nvvsvc.exe c:\program files\CheckPoint\SecuRemote\bin\SR_Service.exe c:\program files\CheckPoint\SecuRemote\bin\SR_Watchdog.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\windows\system32\taskhost.exe c:\program files\CheckPoint\SecuRemote\bin\SR_GUI.Exe c:\windows\system32\conhost.exe c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\CyberLink\Shared files\RichVideo.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\program files\NVIDIA Corporation\Display\nvtray.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Apoint2K\ApMsgFwd.exe c:\program files\Symantec AntiVirus\VPTray.exe c:\program files\Apoint2K\Apntex.exe c:\windows\system32\conhost.exe c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe c:\program files\Symantec AntiVirus\SavUI.exe c:\windows\system32\sppsvc.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2012-07-17 02:04:12 - machine was rebooted ComboFix-quarantined-files.txt 2012-07-16 20:34 ComboFix2.txt 2011-04-09 08:51 . Pre-Run: 5,118,541,824 bytes free Post-Run: 5,912,154,112 bytes free . - - End Of File - - 72C177CEE7636BB7AC7E85955B5E8255
Hi vijay.gupta,

Did you remove Norton Antivirus Corporate Edition?

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
No, don't remove it. I was asking because I did not see it in the logs. You always want to have one antivirus installed. Please proceed with the other two scans.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI