This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Super Slow Laptop, Won't do Important Updates [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I am running windows 7 on my laptop and seem to be having some issues. Not only is it running at an extremely slow pace, but everyday It Automatically restarts while booting up it says it's installing new updates and takes about 20 mins and then it says that the updates Weren't installed and has to Revert back to the way it was before. It's been doing this for awhile now and i'm getting really annoyed. So I think my computer is running bad because I can't update anything at all…. last successful update of anything (ie Frameworks etc ) was 2011 I'm not sure if this is due to a Virus or what, but any help woukld be greatly appreciated :) DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 12:41:46 on 2012-12-20 Microsoft Windows 7 Starter 6.1.7601.1.1252.2.1033.18.1013.147 [GMT -8:00] . SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Launch Manager\dsiwmis.exe C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe C:\Program Files\Acer\Registration\GREGsvc.exe C:\Program Files\Acer\Acer VCM\RS_Service.exe C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe C:\Program Files\Acer\Acer Updater\UpdaterService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Launch Manager\LManager.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\PLFSetI.exe C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Launch Manager\LMworker.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\EgisTec IPS\EgisUpdate.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\system32\igfxext.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\taskhost.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Ares\Ares.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Windows\system32\wuauclt.exe C:\Program Files\Apple Software Update\SoftwareUpdate.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\MsiExec.exe C:\Windows\system32\MsiExec.exe C:\Windows\system32\conhost.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted . ============== Pseudo HJT Report =============== . mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=1009&m;=aod255&r;=27b51210w555l0434ww65w4712u741 BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: PlayBryte BHO: {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: PlayBryte Toolbar: {b278d9f8-0fa9-465e-9938-0c392605d8e3} - uRun: [ares] "c:\program files\ares\Ares.exe" -h uRun: [Google Update] "c:\users\monta\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [Xvid] c:\program files\xvid\CheckUpdate.exe uRun: [AdobeBridge] mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [EgisUpdate] "c:\program files\egistec ips\EgisUpdate.exe" -d mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [LManager] c:\program files\launch manager\LManager.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [PLFSetI] c:\windows\PLFSetI.exe mRun: [Acer ePower Management] c:\program files\acer\acer epower management\ePowerTray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [WatcherHelper] "c:\program files\sierra wireless inc\watcher\WaHelper.exe" mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi go pro\volume panel\VolPanlu.exe" /r mRun: [Creative SB Monitoring Utility] RunDll32 sbavmon.dll,SBAVMonitor mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswaxf.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/110926/CTPID.cab DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} - hxxp://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab TCP: NameServer = 192.168.1.254 TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD} : DHCPNameServer = 192.168.1.254 TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD}\2454C4C47594649404D43444F4E414C44435 : DHCPNameServer = 10.254.0.1 TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD}\2756262656361677 : DHCPNameServer = 192.168.1.254 TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD}\4756C65737 : DHCPNameServer = 192.168.1.254 TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD}\C696E6B6379737 : DHCPNameServer = [removed] [removed] [removed] TCP: Interfaces\{65D03981-9B85-465C-B333-F8B48239C4DD}\F44676560313 : DHCPNameServer = 192.168.1.254 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\users\monta\appdata\roaming\mozilla\firefox\profiles\lb0arw84.default\ FF - prefs.js: browser.search.selectedEngine - Amazon.com FF - prefs.js: browser.startup.homepage - hxxp://ca.msn.com/?ocid=OIE9HP FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - plugin: c:\users\monta\appdata\local\google\update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_135.dll . ============= SERVICES / DRIVERS =============== . R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [2011-12-28 1254400] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2010-7-6 68208] R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfslh.sys [2011-10-1 579944] R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplaylh.sys [2011-10-1 194408] R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirlh.sys [2011-10-1 21864] R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvollh.sys [2011-10-1 19304] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 EUCR;EUCR;c:\windows\system32\drivers\EUCR6SK.sys [2010-7-6 82768] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-5-25 52224] . =============== File Associations =============== . FileExt: .js: JSFile="c:\program files\adobe\adobe dreamweaver cs5.5\Dreamweaver.exe","%1" . =============== Created Last 30 ================ . 2012-12-13 07:19:55 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-11 22:10:31 16363960 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe 2012-12-05 07:49:41 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-11-23 08:44:55 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe . ==================== Find3M ==================== . 2012-12-11 22:11:01 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-09 23:59:22 0 —-a-w- c:\windows\system32\sho22C8.tmp 2012-09-28 18:32:56 5989776 —-a-w- c:\windows\system32\usbaaplrc.dll 2012-09-28 18:32:56 44544 —-a-w- c:\windows\system32\drivers\usbaapl.sys 2011-04-02 23:41:23 242413 –sha-w- c:\windows\system32\sysprep\CRYPTBASE.DLL . ============= FINISH: 12:54:19.06 ===============
Hello,

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
aswMBR log
MBR.dat (attachment)
TDSS Killer log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
yes, sorry. Okay i tried to do all you asked but when i opened up TDsskiller i pressed scan and then i tried to X out of the program and it cured it anyways!! it says it has to reboot in order to complete but i have yet to reboot. By the time you get this my computer will have probably rebooted. :S anyways! here's the log files regardless of both.

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-12-30 17:54:20
—————————–
17:54:20.225 OS Version: Windows 6.1.7601 Service Pack 1
17:54:20.226 Number of processors: 2 586 0x1C0A
17:54:20.231 ComputerName: MONTA-PC UserName: Monta
17:59:44.278 Initialize success
18:21:40.583 AVAST engine defs: 12123001
18:30:37.307 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
18:30:37.377 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3
18:30:37.477 Disk 0 MBR read successfully
18:30:37.491 Disk 0 MBR scan
18:30:38.385 Disk 0 Windows 7 default MBR code
18:30:38.433 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 13312 MB offset 2048
18:30:38.484 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 27265024
18:30:38.533 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 225061 MB offset 27469824
18:30:38.578 Disk 0 scanning sectors +488394752
18:30:39.241 Disk 0 scanning C:\Windows\system32\drivers
18:31:47.395 Service scanning
18:44:12.490 Service volsnap C:\Windows\system32\drivers\tsk1F7.tmp **LOCKED** 32
18:45:21.770 Modules scanning
18:46:17.718 Disk 0 trace - called modules:
18:46:17.725
18:49:46.664 AVAST engine scan C:\Windows
18:50:00.617 AVAST engine scan C:\Windows\system32
19:00:33.157 AVAST engine scan C:\Windows\system32\drivers
19:01:23.461 AVAST engine scan C:\Users\Monta
19:29:26.690 File: C:\Users\Monta\AppData\Local\temp\iqu_bootstrap.exe **INFECTED** Win32:Adware-gen [Adw]
19:31:16.797 Disk 0 MBR has been saved successfully to "C:\Users\Monta\Desktop\MBR.dat"
19:31:17.147 The log file has been saved successfully to "C:\Users\Monta\Desktop\aswMBR.txt"





TDSSKILLER :

17:54:31.0583 1272 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:54:33.0286 1272 ============================================================
17:54:33.0287 1272 Current date / time: 2012/12/30 17:54:33.0286
17:54:33.0287 1272 SystemInfo:
17:54:33.0287 1272
17:54:33.0287 1272 OS Version: 6.1.7601 ServicePack: 1.0
17:54:33.0287 1272 Product type: Workstation
17:54:33.0287 1272 ComputerName: MONTA-PC
17:54:33.0288 1272 UserName: Monta
17:54:33.0288 1272 Windows directory: C:\Windows
17:54:33.0288 1272 System windows directory: C:\Windows
17:54:33.0288 1272 Processor architecture: Intel x86
17:54:33.0288 1272 Number of processors: 2
17:54:33.0288 1272 Page size: 0x1000
17:54:33.0288 1272 Boot type: Normal boot
17:54:33.0288 1272 ============================================================
17:55:33.0303 1272 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:55:33.0308 1272 ============================================================
17:55:33.0308 1272 \Device\Harddisk0\DR0:
17:55:33.0310 1272 MBR partitions:
17:55:33.0310 1272 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A00800, BlocksNum 0x32000
17:55:33.0310 1272 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1A32800, BlocksNum 0x1B792800
17:55:33.0310 1272 ============================================================
17:55:33.0363 1272 C: <-> \Device\Harddisk0\DR0\Partition2
17:55:34.0018 1272 ============================================================
17:55:34.0018 1272 Initialize success
17:55:34.0019 1272 ============================================================
17:56:16.0471 3404 ============================================================
17:56:16.0471 3404 Scan started
17:56:16.0471 3404 Mode: Manual;
17:56:16.0471 3404 ============================================================
17:56:17.0099 3404 ================ Scan system memory ========================
17:56:17.0099 3404 System memory - ok
17:56:17.0102 3404 ================ Scan services =============================
17:56:17.0561 3404 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:56:17.0959 3404 1394ohci - ok
17:56:18.0029 3404 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:56:18.0519 3404 ACPI - ok
17:56:18.0607 3404 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:56:18.0905 3404 AcpiPmi - ok
17:56:19.0822 3404 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
17:56:20.0604 3404 AdobeARMservice - ok
17:56:21.0228 3404 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:56:21.0275 3404 AdobeFlashPlayerUpdateSvc - ok
17:56:21.0575 3404 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
17:56:21.0648 3404 adp94xx - ok
17:56:21.0718 3404 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\drivers\adpahci.sys
17:56:21.0807 3404 adpahci - ok
17:56:21.0898 3404 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
17:56:21.0977 3404 adpu320 - ok
17:56:22.0029 3404 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:56:22.0252 3404 AeLookupSvc - ok
17:56:22.0695 3404 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
17:56:22.0877 3404 AFD - ok
17:56:22.0944 3404 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:56:23.0184 3404 agp440 - ok
17:56:23.0290 3404 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
17:56:23.0326 3404 aic78xx - ok
17:56:23.0423 3404 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:56:23.0450 3404 ALG - ok
17:56:23.0510 3404 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:56:23.0697 3404 aliide - ok
17:56:23.0779 3404 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:56:24.0075 3404 amdagp - ok
17:56:24.0139 3404 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:56:24.0433 3404 amdide - ok
17:56:24.0521 3404 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
17:56:24.0694 3404 AmdK8 - ok
17:56:24.0732 3404 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
17:56:24.0813 3404 AmdPPM - ok
17:56:24.0871 3404 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:56:25.0067 3404 amdsata - ok
17:56:25.0265 3404 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
17:56:25.0271 3404 amdsbs - ok
17:56:25.0364 3404 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:56:25.0562 3404 amdxata - ok
17:56:25.0657 3404 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:56:25.0918 3404 AppID - ok
17:56:25.0992 3404 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:56:26.0403 3404 AppIDSvc - ok
17:56:26.0477 3404 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
17:56:26.0644 3404 Appinfo - ok
17:56:27.0206 3404 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:56:27.0625 3404 Apple Mobile Device - ok
17:56:27.0727 3404 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\drivers\arc.sys
17:56:27.0768 3404 arc - ok
17:56:27.0798 3404 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\drivers\arcsas.sys
17:56:27.0902 3404 arcsas - ok
17:56:28.0001 3404 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:56:28.0065 3404 AsyncMac - ok
17:56:28.0143 3404 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:56:28.0403 3404 atapi - ok
17:56:28.0519 3404 [ 8D6E8178AB4379C932C34A109D27C5A9 ] athr C:\Windows\system32\DRIVERS\athr.sys
17:56:28.0795 3404 athr - ok
17:56:28.0884 3404 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:56:29.0104 3404 AudioEndpointBuilder - ok
17:56:29.0130 3404 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:56:29.0404 3404 Audiosrv - ok
17:56:29.0480 3404 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:56:29.0665 3404 AxInstSV - ok
17:56:29.0740 3404 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys
17:56:30.0039 3404 b06bdrv - ok
17:56:30.0207 3404 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:56:30.0534 3404 b57nd60x - ok
17:56:30.0833 3404 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:56:30.0863 3404 BDESVC - ok
17:56:30.0959 3404 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:56:31.0222 3404 Beep - ok
17:56:31.0427 3404 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:56:31.0612 3404 BFE - ok
17:56:31.0750 3404 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\system32\qmgr.dll
17:56:32.0404 3404 BITS - ok
17:56:32.0476 3404 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
17:56:32.0807 3404 blbdrive - ok
17:56:32.0935 3404 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
17:56:32.0946 3404 Bonjour Service - ok
17:56:33.0016 3404 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:56:33.0204 3404 bowser - ok
17:56:33.0258 3404 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
17:56:33.0429 3404 BrFiltLo - ok
17:56:33.0529 3404 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
17:56:33.0916 3404 BrFiltUp - ok
17:56:34.0007 3404 [ 6E11F33D14D020F58D5E02E4D67DFA19 ] Browser C:\Windows\System32\browser.dll
17:56:34.0056 3404 Browser - ok
17:56:34.0119 3404 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:56:34.0396 3404 Brserid - ok
17:56:34.0442 3404 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:56:34.0727 3404 BrSerWdm - ok
17:56:34.0782 3404 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:56:35.0064 3404 BrUsbMdm - ok
17:56:35.0152 3404 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:56:35.0359 3404 BrUsbSer - ok
17:56:35.0405 3404 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
17:56:35.0480 3404 BTHMODEM - ok
17:56:35.0552 3404 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:56:35.0933 3404 bthserv - ok
17:56:36.0209 3404 catchme - ok
17:56:36.0262 3404 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:56:36.0364 3404 cdfs - ok
17:56:36.0461 3404 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:56:36.0670 3404 cdrom - ok
17:56:36.0754 3404 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:56:37.0047 3404 CertPropSvc - ok
17:56:37.0122 3404 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\drivers\circlass.sys
17:56:37.0312 3404 circlass - ok
17:56:37.0379 3404 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:56:37.0664 3404 CLFS - ok
17:56:37.0804 3404 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:56:38.0154 3404 clr_optimization_v2.0.50727_32 - ok
17:56:38.0270 3404 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:56:38.0656 3404 clr_optimization_v4.0.30319_32 - ok
17:56:38.0713 3404 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
17:56:39.0012 3404 CmBatt - ok
17:56:39.0092 3404 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:56:39.0481 3404 cmdide - ok
17:56:39.0529 3404 [ 1B675691ED940766149C93E8F4488D68 ] CNG C:\Windows\system32\Drivers\cng.sys
17:56:39.0757 3404 CNG - ok
17:56:39.0816 3404 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\drivers\compbatt.sys
17:56:40.0118 3404 Compbatt - ok
17:56:40.0170 3404 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
17:56:40.0451 3404 CompositeBus - ok
17:56:40.0500 3404 COMSysApp - ok
17:56:40.0549 3404 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
17:56:40.0585 3404 crcdisk - ok
17:56:40.0740 3404 [ C8BD651E13895B93ED9EC5B4F1DF42BC ] Creative ALchemy AL6 Licensing Service C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
17:56:41.0207 3404 Creative ALchemy AL6 Licensing Service - ok
17:56:41.0235 3404 [ C0EAD9F8AB83D41FF07303C75589C2B8 ] Creative Audio Engine Licensing Service C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
17:56:41.0331 3404 Creative Audio Engine Licensing Service - ok
17:56:41.0418 3404 [ 06E771AA596B8761107AB57E99F128D7 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:56:41.0470 3404 CryptSvc - ok
17:56:41.0588 3404 [ 5CE3D0E1D1B3832EE052CFC442EEE0FA ] CTAudSvcService C:\Program Files\Creative\Shared Files\CTAudSvc.exe
17:56:41.0597 3404 CTAudSvcService - ok
17:56:41.0857 3404 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
17:56:42.0103 3404 cvhsvc - ok
17:56:42.0200 3404 [ 7CAAF4AF453EF3582FEF65DD72CAA0AA ] dc3d C:\Windows\system32\DRIVERS\dc3d.sys
17:56:42.0457 3404 dc3d - ok
17:56:42.0512 3404 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:56:42.0864 3404 DcomLaunch - ok
17:56:42.0930 3404 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:56:43.0211 3404 defragsvc - ok
17:56:43.0291 3404 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:56:43.0577 3404 DfsC - ok
17:56:43.0779 3404 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:56:44.0089 3404 Dhcp - ok
17:56:44.0158 3404 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:56:44.0316 3404 discache - ok
17:56:44.0383 3404 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\drivers\disk.sys
17:56:44.0543 3404 Disk - ok
17:56:44.0664 3404 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:56:44.0849 3404 Dnscache - ok
17:56:44.0914 3404 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:56:45.0331 3404 dot3svc - ok
17:56:45.0388 3404 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:56:45.0615 3404 DPS - ok
17:56:45.0691 3404 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:56:45.0991 3404 drmkaud - ok
17:56:46.0220 3404 [ 1FCA854CEDFC2CCD0C22E46EA4EA18F1 ] DsiWMIService C:\Program Files\Launch Manager\dsiwmis.exe
17:56:46.0426 3404 DsiWMIService - ok
17:56:46.0486 3404 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:56:46.0878 3404 DXGKrnl - ok
17:56:46.0955 3404 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:56:47.0024 3404 EapHost - ok
17:56:47.0205 3404 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\drivers\evbdx.sys
17:56:47.0713 3404 ebdrv - ok
17:56:47.0819 3404 [ F42309C4191C506B71DB5D1126D26318 ] EFS C:\Windows\System32\lsass.exe
17:56:48.0110 3404 EFS - ok
17:56:48.0213 3404 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\drivers\elxstor.sys
17:56:48.0385 3404 elxstor - ok
17:56:48.0608 3404 [ 2609A5B13DE9B2EEB38F3A83A406D079 ] ePowerSvc C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
17:56:48.0963 3404 ePowerSvc - ok
17:56:49.0010 3404 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:56:49.0495 3404 ErrDev - ok
17:56:49.0677 3404 [ 4FAB8DFAF156E048AD514EABD268AB3A ] EUCR C:\Windows\system32\DRIVERS\EUCR6SK.SYS
17:56:49.0872 3404 EUCR - ok
17:56:49.0942 3404 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:56:50.0235 3404 EventSystem - ok
17:56:50.0307 3404 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:56:50.0559 3404 exfat - ok
17:56:50.0591 3404 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:56:50.0920 3404 fastfat - ok
17:56:51.0168 3404 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:56:51.0490 3404 Fax - ok
17:56:51.0546 3404 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\drivers\fdc.sys
17:56:51.0853 3404 fdc - ok
17:56:51.0900 3404 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:56:52.0087 3404 fdPHost - ok
17:56:52.0126 3404 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:56:52.0224 3404 FDResPub - ok
17:56:52.0252 3404 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:56:52.0623 3404 FileInfo - ok
17:56:52.0680 3404 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:56:52.0754 3404 Filetrace - ok
17:56:52.0835 3404 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
17:56:53.0108 3404 flpydisk - ok
17:56:53.0160 3404 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:56:53.0548 3404 FltMgr - ok
17:56:53.0628 3404 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
17:56:53.0922 3404 FontCache - ok
17:56:54.0025 3404 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:56:54.0513 3404 FontCache3.0.0.0 - ok
17:56:54.0614 3404 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:56:54.0854 3404 FsDepends - ok
17:56:54.0934 3404 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:56:55.0771 3404 Fs_Rec - ok
17:56:55.0842 3404 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:56:56.0110 3404 fvevol - ok
17:56:56.0169 3404 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
17:56:56.0339 3404 gagp30kx - ok
17:56:56.0453 3404 [ CE16683CFD11FE70BDE435DDA5EA1FCA ] GameConsoleService C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe
17:56:56.0903 3404 GameConsoleService - ok
17:56:57.0033 3404 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:56:57.0135 3404 GEARAspiWDM - ok
17:56:57.0201 3404 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:56:57.0485 3404 gpsvc - ok
17:56:57.0595 3404 [ 0191DEE9B9EB7902AF2CF4F67301095D ] GREGService C:\Program Files\Acer\Registration\GREGsvc.exe
17:56:57.0738 3404 GREGService - ok
17:56:57.0796 3404 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:56:58.0201 3404 hcw85cir - ok
17:56:58.0268 3404 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:56:58.0772 3404 HdAudAddService - ok
17:56:58.0821 3404 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
17:56:59.0153 3404 HDAudBus - ok
17:56:59.0209 3404 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
17:56:59.0484 3404 HidBatt - ok
17:56:59.0532 3404 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\drivers\hidbth.sys
17:56:59.0788 3404 HidBth - ok
17:56:59.0857 3404 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\drivers\hidir.sys
17:57:00.0207 3404 HidIr - ok
17:57:00.0278 3404 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
17:57:00.0594 3404 hidserv - ok
17:57:00.0685 3404 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:57:00.0968 3404 HidUsb - ok
17:57:01.0051 3404 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:57:01.0421 3404 hkmsvc - ok
17:57:01.0534 3404 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:57:01.0821 3404 HomeGroupListener - ok
17:57:01.0934 3404 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:57:02.0249 3404 HomeGroupProvider - ok
17:57:02.0376 3404 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:57:02.0435 3404 HpSAMD - ok
17:57:02.0519 3404 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:57:02.0794 3404 HTTP - ok
17:57:02.0864 3404 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:57:03.0146 3404 hwpolicy - ok
17:57:03.0263 3404 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
17:57:03.0615 3404 i8042prt - ok
17:57:03.0706 3404 [ 660BF3255A1EB18ED803FD2FBA6AE400 ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
17:57:03.0751 3404 IAANTMON - ok
17:57:03.0861 3404 [ 0BAA4115DFFFD6A6D809A89D65E1281A ] iaStor C:\Windows\system32\drivers\iaStor.sys
17:57:03.0956 3404 iaStor - ok
17:57:04.0058 3404 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:57:04.0159 3404 iaStorV - ok
17:57:04.0368 3404 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:57:04.0840 3404 idsvc - ok
17:57:05.0044 3404 [ D0074897C6BC132F3980EA4654BF7FB9 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys
17:57:05.0425 3404 igfx - ok
17:57:05.0491 3404 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\drivers\iirsp.sys
17:57:05.0894 3404 iirsp - ok
17:57:05.0990 3404 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:57:06.0302 3404 IKEEXT - ok
17:57:06.0519 3404 [ 0DBEF9CD5A2CD71240DD5AFCEE56D073 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
17:57:07.0199 3404 IntcAzAudAddService - ok
17:57:07.0249 3404 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:57:07.0550 3404 intelide - ok
17:57:07.0634 3404 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:57:08.0064 3404 intelppm - ok
17:57:08.0134 3404 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:57:08.0582 3404 IPBusEnum - ok
17:57:08.0755 3404 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:57:09.0086 3404 iphlpsvc - ok
17:57:09.0156 3404 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:57:09.0449 3404 IPMIDRV - ok
17:57:09.0503 3404 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:57:09.0824 3404 IPNAT - ok
17:57:09.0990 3404 [ E8A39D41474BE42FD8830CED32932D6C ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
17:57:10.0003 3404 iPod Service - ok
17:57:10.0093 3404 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:57:10.0372 3404 IRENUM - ok
17:57:10.0424 3404 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:57:10.0718 3404 isapnp - ok
17:57:10.0788 3404 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:57:11.0045 3404 iScsiPrt - ok
17:57:11.0131 3404 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
17:57:11.0205 3404 kbdclass - ok
17:57:11.0298 3404 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:57:11.0594 3404 kbdhid - ok
17:57:11.0619 3404 [ F42309C4191C506B71DB5D1126D26318 ] KeyIso C:\Windows\system32\lsass.exe
17:57:11.0836 3404 KeyIso - ok
17:57:11.0957 3404 [ 81AA03E754381EB80BCA3E012CF6E5F1 ] ksaud C:\Windows\system32\drivers\ksaud.sys
17:57:12.0294 3404 ksaud - ok
17:57:12.0358 3404 [ 412CEA1AA78CC02A447F5C9E62B32FF1 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:57:12.0556 3404 KSecDD - ok
17:57:12.0646 3404 [ 26C046977E85B95036453D7B88BA1820 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:57:13.0038 3404 KSecPkg - ok
17:57:13.0110 3404 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:57:13.0516 3404 KtmRm - ok
17:57:13.0584 3404 [ 12DE252A44C344A7A044B3C1190DF63B ] L1C C:\Windows\system32\DRIVERS\L1C62x86.sys
17:57:13.0905 3404 L1C - ok
17:57:14.0035 3404 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll
17:57:14.0304 3404 LanmanServer - ok
17:57:14.0350 3404 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:57:14.0705 3404 LanmanWorkstation - ok
17:57:14.0801 3404 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:57:15.0140 3404 lltdio - ok
17:57:15.0199 3404 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:57:15.0544 3404 lltdsvc - ok
17:57:15.0594 3404 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:57:15.0842 3404 lmhosts - ok
17:57:16.0005 3404 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
17:57:16.0083 3404 LSI_FC - ok
17:57:16.0138 3404 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
17:57:16.0442 3404 LSI_SAS - ok
17:57:16.0557 3404 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
17:57:16.0646 3404 LSI_SAS2 - ok
17:57:16.0679 3404 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
17:57:16.0779 3404 LSI_SCSI - ok
17:57:16.0853 3404 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:57:17.0224 3404 luafv - ok
17:57:17.0376 3404 MBAMProtector - ok
17:57:17.0583 3404 [ EC60491A5FF57700F10FE0403F7DCAD4 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:57:18.0007 3404 MBAMService - ok
17:57:18.0069 3404 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\drivers\megasas.sys
17:57:18.0527 3404 megasas - ok
17:57:18.0585 3404 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
17:57:18.0594 3404 MegaSR - ok
17:57:18.0708 3404 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:57:19.0081 3404 MMCSS - ok
17:57:19.0149 3404 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:57:19.0570 3404 Modem - ok
17:57:19.0607 3404 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:57:19.0704 3404 monitor - ok
17:57:19.0751 3404 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:57:20.0034 3404 mouclass - ok
17:57:20.0100 3404 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:57:20.0291 3404 mouhid - ok
17:57:20.0400 3404 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:57:20.0781 3404 mountmgr - ok
17:57:20.0946 3404 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:57:20.0953 3404 MozillaMaintenance - ok
17:57:21.0043 3404 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:57:21.0122 3404 mpio - ok
17:57:21.0221 3404 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:57:21.0519 3404 mpsdrv - ok
17:57:21.0750 3404 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:57:22.0064 3404 MpsSvc - ok
17:57:22.0104 3404 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:57:22.0408 3404 MRxDAV - ok
17:57:22.0462 3404 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:57:22.0730 3404 mrxsmb - ok
17:57:22.0829 3404 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:57:23.0094 3404 mrxsmb10 - ok
17:57:23.0163 3404 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:57:23.0462 3404 mrxsmb20 - ok
17:57:23.0507 3404 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:57:23.0690 3404 msahci - ok
17:57:23.0732 3404 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:57:23.0908 3404 msdsm - ok
17:57:23.0976 3404 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:57:24.0431 3404 MSDTC - ok
17:57:24.0502 3404 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:57:24.0831 3404 Msfs - ok
17:57:24.0877 3404 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:57:25.0296 3404 mshidkmdf - ok
17:57:25.0349 3404 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:57:25.0533 3404 msisadrv - ok
17:57:25.0610 3404 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:57:26.0022 3404 MSiSCSI - ok
17:57:26.0041 3404 msiserver - ok
17:57:26.0122 3404 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:57:26.0266 3404 MSKSSRV - ok
17:57:26.0321 3404 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:57:26.0609 3404 MSPCLOCK - ok
17:57:26.0639 3404 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:57:26.0853 3404 MSPQM - ok
17:57:26.0910 3404 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:57:27.0203 3404 MsRPC - ok
17:57:27.0274 3404 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
17:57:27.0547 3404 mssmbios - ok
17:57:27.0606 3404 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:57:28.0028 3404 MSTEE - ok
17:57:28.0055 3404 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
17:57:28.0385 3404 MTConfig - ok
17:57:28.0431 3404 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:57:28.0786 3404 Mup - ok
17:57:28.0858 3404 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:57:29.0104 3404 napagent - ok
17:57:29.0226 3404 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:57:29.0473 3404 NativeWifiP - ok
17:57:29.0546 3404 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:57:29.0883 3404 NDIS - ok
17:57:29.0936 3404 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:57:30.0236 3404 NdisCap - ok
17:57:30.0265 3404 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:57:30.0481 3404 NdisTapi - ok
17:57:30.0555 3404 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:57:30.0783 3404 Ndisuio - ok
17:57:30.0835 3404 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:57:31.0133 3404 NdisWan - ok
17:57:31.0190 3404 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:57:31.0461 3404 NDProxy - ok
17:57:31.0526 3404 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:57:31.0807 3404 NetBIOS - ok
17:57:31.0882 3404 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:57:32.0149 3404 NetBT - ok
17:57:32.0173 3404 [ F42309C4191C506B71DB5D1126D26318 ] Netlogon C:\Windows\system32\lsass.exe
17:57:32.0385 3404 Netlogon - ok
17:57:32.0547 3404 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:57:32.0907 3404 Netman - ok
17:57:32.0970 3404 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:57:33.0289 3404 netprofm - ok
17:57:33.0351 3404 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:57:33.0503 3404 NetTcpPortSharing - ok
17:57:33.0560 3404 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
17:57:33.0859 3404 nfrd960 - ok
17:57:33.0929 3404 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:57:34.0203 3404 NlaSvc - ok
17:57:34.0249 3404 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:57:34.0658 3404 Npfs - ok
17:57:34.0773 3404 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:57:35.0012 3404 nsi - ok
17:57:35.0047 3404 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:57:35.0230 3404 nsiproxy - ok
17:57:35.0334 3404 [ 81189C3D7763838E55C397759D49007A ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:57:35.0642 3404 Ntfs - ok
17:57:35.0763 3404 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:57:36.0051 3404 Null - ok
17:57:36.0129 3404 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:57:36.0531 3404 nvraid - ok
17:57:36.0611 3404 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:57:36.0910 3404 nvstor - ok
17:57:36.0960 3404 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:57:37.0435 3404 nv_agp - ok
17:57:37.0528 3404 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:57:37.0822 3404 ohci1394 - ok
17:57:37.0912 3404 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:57:38.0078 3404 ose - ok
17:57:38.0270 3404 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
17:57:38.0732 3404 osppsvc - ok
17:57:38.0787 3404 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:57:39.0116 3404 p2pimsvc - ok
17:57:39.0191 3404 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:57:39.0511 3404 p2psvc - ok
17:57:39.0568 3404 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\drivers\parport.sys
17:57:39.0876 3404 Parport - ok
17:57:39.0930 3404 [ BF8F6AF06DA75B336F07E23AEF97D93B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:57:40.0293 3404 partmgr - ok
17:57:40.0328 3404 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\drivers\parvdm.sys
17:57:40.0657 3404 Parvdm - ok
17:57:40.0741 3404 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:57:41.0023 3404 PcaSvc - ok
17:57:41.0137 3404 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:57:41.0377 3404 pci - ok
17:57:41.0408 3404 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:57:41.0766 3404 pciide - ok
17:57:41.0848 3404 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:57:42.0032 3404 pcmcia - ok
17:57:42.0098 3404 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:57:42.0244 3404 pcw - ok
17:57:42.0444 3404 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:57:42.0555 3404 PEAUTH - ok
17:57:43.0140 3404 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:57:43.0389 3404 pla - ok
17:57:43.0473 3404 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:57:43.0913 3404 PlugPlay - ok
17:57:43.0968 3404 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:57:44.0506 3404 PNRPAutoReg - ok
17:57:44.0565 3404 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:57:44.0949 3404 PNRPsvc - ok
17:57:45.0083 3404 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:57:45.0375 3404 PolicyAgent - ok
17:57:45.0464 3404 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:57:45.0764 3404 Power - ok
17:57:45.0834 3404 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:57:46.0079 3404 PptpMiniport - ok
17:57:46.0125 3404 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys
17:57:46.0424 3404 Processor - ok
17:57:46.0474 3404 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
17:57:46.0780 3404 ProfSvc - ok
17:57:46.0829 3404 [ F42309C4191C506B71DB5D1126D26318 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:57:46.0909 3404 ProtectedStorage - ok
17:57:47.0028 3404 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:57:47.0197 3404 Psched - ok
17:57:47.0344 3404 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:57:47.0641 3404 ql2300 - ok
17:57:47.0743 3404 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:57:48.0098 3404 ql40xx - ok
17:57:48.0198 3404 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:57:48.0531 3404 QWAVE - ok
17:57:48.0569 3404 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:57:48.0917 3404 QWAVEdrv - ok
17:57:48.0957 3404 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:57:49.0165 3404 RasAcd - ok
17:57:49.0219 3404 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:57:49.0386 3404 RasAgileVpn - ok
17:57:49.0436 3404 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:57:49.0511 3404 RasAuto - ok
17:57:49.0616 3404 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:57:49.0675 3404 Rasl2tp - ok
17:57:49.0871 3404 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:57:50.0166 3404 RasMan - ok
17:57:50.0221 3404 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:57:50.0499 3404 RasPppoe - ok
17:57:50.0556 3404 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:57:50.0871 3404 RasSstp - ok
17:57:50.0968 3404 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:57:51.0240 3404 rdbss - ok
17:57:51.0296 3404 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
17:57:51.0678 3404 rdpbus - ok
17:57:51.0741 3404 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:57:51.0898 3404 RDPCDD - ok
17:57:51.0993 3404 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:57:52.0142 3404 RDPENCDD - ok
17:57:52.0201 3404 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:57:52.0425 3404 RDPREFMP - ok
17:57:52.0476 3404 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:57:52.0789 3404 RDPWD - ok
17:57:52.0947 3404 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:57:53.0265 3404 rdyboost - ok
17:57:53.0302 3404 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:57:53.0834 3404 RemoteAccess - ok
17:57:53.0895 3404 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:57:54.0329 3404 RemoteRegistry - ok
17:57:54.0471 3404 [ F17713D108ACA124A139FDE877EEF68A ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys
17:57:54.0508 3404 RimUsb - ok
17:57:54.0624 3404 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:57:54.0749 3404 RpcEptMapper - ok
17:57:54.0805 3404 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:57:55.0247 3404 RpcLocator - ok
17:57:55.0289 3404 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\System32\rpcss.dll
17:57:55.0575 3404 RpcSs - ok
17:57:55.0635 3404 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:57:55.0844 3404 rspndr - ok
17:57:56.0028 3404 [ 7CB9F0FDD730F4A4ECF6CDE15EA12E8A ] RS_Service C:\Program Files\Acer\Acer VCM\RS_Service.exe
17:57:56.0421 3404 RS_Service - ok
17:57:56.0462 3404 [ F42309C4191C506B71DB5D1126D26318 ] SamSs C:\Windows\system32\lsass.exe
17:57:56.0796 3404 SamSs - ok
17:57:56.0899 3404 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:57:57.0104 3404 sbp2port - ok
17:57:57.0134 3404 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:57:57.0534 3404 SCardSvr - ok
17:57:57.0607 3404 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:57:57.0668 3404 scfilter - ok
17:57:57.0810 3404 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:57:58.0081 3404 Schedule - ok
17:57:58.0108 3404 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:57:58.0374 3404 SCPolicySvc - ok
17:57:58.0437 3404 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:57:59.0115 3404 SDRSVC - ok
17:57:59.0163 3404 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:57:59.0480 3404 secdrv - ok
17:57:59.0547 3404 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:57:59.0915 3404 seclogon - ok
17:57:59.0962 3404 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
17:58:00.0062 3404 SENS - ok
17:58:00.0098 3404 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\drivers\serenum.sys
17:58:00.0418 3404 Serenum - ok
17:58:00.0490 3404 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\drivers\serial.sys
17:58:01.0000 3404 Serial - ok
17:58:01.0106 3404 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:58:01.0261 3404 sermouse - ok
17:58:01.0337 3404 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:58:01.0769 3404 SessionEnv - ok
17:58:01.0814 3404 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:58:02.0094 3404 sffdisk - ok
17:58:02.0146 3404 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:58:02.0530 3404 sffp_mmc - ok
17:58:02.0611 3404 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:58:02.0992 3404 sffp_sd - ok
17:58:03.0045 3404 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
17:58:03.0346 3404 sfloppy - ok
17:58:03.0491 3404 [ D9B734638DD8DBA9D59AAD3189CD0FAD ] Sftfs C:\Windows\system32\DRIVERS\Sftfslh.sys
17:58:03.0580 3404 Sftfs - ok
17:58:03.0712 3404 [ CB73BC422C07FB611F194DA18D1E7F36 ] sftlist C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
17:58:04.0010 3404 sftlist - ok
17:58:04.0057 3404 [ 2F61BD46C0BFF4EB36E1E359CA17BFC5 ] Sftplay C:\Windows\system32\DRIVERS\Sftplaylh.sys
17:58:04.0406 3404 Sftplay - ok
17:58:04.0433 3404 [ 518BAC0179F94304F422696B47C0EC12 ] Sftredir C:\Windows\system32\DRIVERS\Sftredirlh.sys
17:58:04.0716 3404 Sftredir - ok
17:58:04.0751 3404 [ 747325236D88B3F05FFD27FF9EC711C5 ] Sftvol C:\Windows\system32\DRIVERS\Sftvollh.sys
17:58:05.0005 3404 Sftvol - ok
17:58:05.0100 3404 [ A5812F0281CA5081BF696626F9BF324D ] sftvsa C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
17:58:05.0350 3404 sftvsa - ok
17:58:05.0502 3404 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:58:05.0724 3404 SharedAccess - ok
17:58:05.0769 3404 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:58:06.0046 3404 ShellHWDetection - ok
17:58:06.0106 3404 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:58:06.0307 3404 sisagp - ok
17:58:06.0376 3404 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
17:58:06.0731 3404 SiSRaid2 - ok
17:58:06.0782 3404 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:58:07.0059 3404 SiSRaid4 - ok
17:58:07.0154 3404 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
17:58:07.0509 3404 SkypeUpdate - ok
17:58:07.0573 3404 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:58:07.0845 3404 Smb - ok
17:58:07.0969 3404 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:58:08.0123 3404 SNMPTRAP - ok
17:58:08.0181 3404 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:58:08.0415 3404 spldr - ok
17:58:08.0491 3404 [ 866A43013535DC8587C258E43579C764 ] Spooler C:\Windows\System32\spoolsv.exe
17:58:08.0801 3404 Spooler - ok
17:58:09.0954 3404 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:58:10.0322 3404 sppsvc - ok
17:58:10.0382 3404 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:58:10.0700 3404 sppuinotify - ok
17:58:10.0756 3404 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:58:11.0052 3404 srv - ok
17:58:11.0171 3404 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:58:11.0573 3404 srv2 - ok
17:58:11.0613 3404 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:58:12.0254 3404 srvnet - ok
17:58:12.0312 3404 [ D5DFFEAA1E15D4EFFABB9D9A3068AC5B ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
17:58:12.0638 3404 sscdbus - ok
17:58:12.0695 3404 [ 8A1BE0C347814F482F493AEA619D57F6 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
17:58:13.0167 3404 sscdmdfl - ok
17:58:13.0207 3404 [ 5AB0B1987F682A59B15B78F84C6AD7D0 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
17:58:13.0620 3404 sscdmdm - ok
17:58:13.0700 3404 [ 751E66EB32EFA80633B80F5D7FF0A1D8 ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
17:58:14.0029 3404 sscdserd - ok
17:58:14.0072 3404 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:58:14.0478 3404 SSDPSRV - ok
17:58:14.0538 3404 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:58:14.0911 3404 SstpSvc - ok
17:58:14.0968 3404 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys
17:58:15.0307 3404 stexstor - ok
17:58:15.0492 3404 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:58:15.0864 3404 StiSvc - ok
17:58:16.0030 3404 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
17:58:16.0068 3404 swenum - ok
17:58:16.0154 3404 [ E6C797B33A454840245C0C96E7F08B0A ] swmsflt C:\Windows\System32\drivers\swmsflt.sys
17:58:16.0466 3404 swmsflt - ok
17:58:16.0539 3404 [ A56848914C78093A1EC84A6CE424C7BF ] SWMX00 C:\Windows\system32\DRIVERS\swmx00.sys
17:58:16.0885 3404 SWMX00 - ok
17:58:16.0940 3404 [ F797787D579E1A9396D2E416240A2259 ] SWNC5E00 C:\Windows\system32\DRIVERS\SWNC5E00.sys
17:58:17.0311 3404 SWNC5E00 - ok
17:58:17.0380 3404 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:58:17.0682 3404 swprv - ok
17:58:17.0713 3404 SWUMX20 - ok
17:58:17.0930 3404 [ 5CDD124913E91C7F79B4D5CAE1C7C4DE ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
17:58:18.0182 3404 SynTP - ok
17:58:18.0277 3404 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:58:18.0725 3404 SysMain - ok
17:58:18.0775 3404 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:58:19.0062 3404 TabletInputService - ok
17:58:19.0105 3404 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:58:19.0450 3404 TapiSrv - ok
17:58:19.0501 3404 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:58:19.0598 3404 TBS - ok
17:58:19.0760 3404 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:58:20.0107 3404 Tcpip - ok
17:58:20.0182 3404 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:58:20.0441 3404 TCPIP6 - ok
17:58:20.0549 3404 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:58:20.0877 3404 tcpipreg - ok
17:58:20.0956 3404 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:58:21.0360 3404 TDPIPE - ok
17:58:21.0491 3404 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:58:21.0844 3404 TDTCP - ok
17:58:21.0913 3404 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:58:22.0239 3404 tdx - ok
17:58:22.0314 3404 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
17:58:22.0364 3404 TermDD - ok
17:58:22.0445 3404 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:58:22.0765 3404 TermService - ok
17:58:22.0821 3404 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:58:23.0098 3404 Themes - ok
17:58:23.0128 3404 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:58:23.0356 3404 THREADORDER - ok
17:58:23.0440 3404 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:58:23.0722 3404 TrkWks - ok
17:58:23.0845 3404 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:58:23.0888 3404 TrustedInstaller - ok
17:58:23.0947 3404 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:58:24.0111 3404 tssecsrv - ok
17:58:24.0281 3404 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:58:24.0493 3404 TsUsbFlt - ok
17:58:24.0565 3404 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:58:24.0880 3404 tunnel - ok
17:58:24.0950 3404 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:58:25.0179 3404 uagp35 - ok
17:58:25.0238 3404 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:58:25.0532 3404 udfs - ok
17:58:25.0619 3404 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:58:25.0833 3404 UI0Detect - ok
17:58:25.0916 3404 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:58:26.0201 3404 uliagpkx - ok
17:58:26.0274 3404 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
17:58:26.0744 3404 umbus - ok
17:58:26.0816 3404 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys
17:58:26.0980 3404 UmPass - ok
17:58:27.0158 3404 [ F9EC9ACD504D823D9B9CA98A4F8D3CA2 ] Updater Service C:\Program Files\Acer\Acer Updater\UpdaterService.exe
17:58:27.0532 3404 Updater Service - ok
17:58:27.0680 3404 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:58:27.0937 3404 upnphost - ok
17:58:27.0996 3404 [ 8BF5D980CDCE35FB26F05047144BB57E ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys
17:58:28.0289 3404 USBAAPL - ok
17:58:28.0378 3404 [ 1D9F2BD026E8E2D45033A4DF3F16B78C ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
17:58:28.0712 3404 usbaudio - ok
17:58:28.0759 3404 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:58:29.0046 3404 usbccgp - ok
17:58:29.0115 3404 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:58:29.0409 3404 usbcir - ok
17:58:29.0517 3404 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\drivers\usbehci.sys
17:58:29.0742 3404 usbehci - ok
17:58:29.0814 3404 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:58:30.0071 3404 usbhub - ok
17:58:30.0137 3404 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
17:58:30.0302 3404 usbohci - ok
17:58:30.0349 3404 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\drivers\usbprint.sys
17:58:30.0678 3404 usbprint - ok
17:58:30.0738 3404 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:58:31.0048 3404 USBSTOR - ok
17:58:31.0103 3404 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:58:31.0264 3404 usbuhci - ok
17:58:31.0389 3404 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
17:58:31.0534 3404 usbvideo - ok
17:58:31.0579 3404 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:58:31.0881 3404 UxSms - ok
17:58:31.0983 3404 [ F42309C4191C506B71DB5D1126D26318 ] VaultSvc C:\Windows\system32\lsass.exe
17:58:32.0090 3404 VaultSvc - ok
17:58:32.0174 3404 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:58:32.0603 3404 vdrvroot - ok
17:58:32.0681 3404 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:58:33.0127 3404 vds - ok
17:58:33.0211 3404 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:58:33.0384 3404 vga - ok
17:58:33.0445 3404 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:58:33.0771 3404 VgaSave - ok
17:58:33.0846 3404 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:58:34.0099 3404 vhdmp - ok
17:58:34.0194 3404 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:58:34.0443 3404 viaagp - ok
17:58:34.0534 3404 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:58:34.0766 3404 ViaC7 - ok
17:58:34.0832 3404 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:58:34.0981 3404 viaide - ok
17:58:35.0052 3404 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:58:35.0396 3404 volmgr - ok
17:58:35.0444 3404 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:58:35.0823 3404 volmgrx - ok
17:58:35.0891 3404 [ 394E022FBD2B6C11D272CA504600851A ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:58:35.0967 3404 Suspicious file (Forged): C:\Windows\system32\drivers\volsnap.sys. Real md5: 394E022FBD2B6C11D272CA504600851A, Fake md5: F497F67932C6FA693D7DE2780631CFE7
17:58:36.0063 3404 volsnap ( Rootkit.Win32.TDSS.tdl3 ) - infected
17:58:36.0063 3404 volsnap - detected Rootkit.Win32.TDSS.tdl3 (0)
17:58:36.0121 3404 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:58:36.0296 3404 vsmraid - ok
17:58:36.0611 3404 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:58:36.0882 3404 VSS - ok
17:58:36.0907 3404 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
17:58:37.0109 3404 vwifibus - ok
17:58:37.0296 3404 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
17:58:37.0565 3404 vwififlt - ok
17:58:37.0633 3404 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:58:37.0908 3404 W32Time - ok
17:58:37.0961 3404 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:58:38.0166 3404 WacomPen - ok
17:58:38.0256 3404 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:58:38.0498 3404 WANARP - ok
17:58:38.0513 3404 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:58:38.0516 3404 Wanarpv6 - ok
17:58:38.0630 3404 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:58:38.0754 3404 wbengine - ok
17:58:38.0914 3404 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:58:39.0323 3404 WbioSrvc - ok
17:58:39.0502 3404 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:58:39.0944 3404 wcncsvc - ok
17:58:40.0070 3404 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:58:40.0449 3404 WcsPlugInService - ok
17:58:40.0512 3404 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys
17:58:40.0920 3404 Wd - ok
17:58:40.0994 3404 [ D6EFAF429FD30C5DF613D220E344CCE7 ] WDC_SAM C:\Windows\system32\DRIVERS\wdcsam.sys
17:58:41.0209 3404 WDC_SAM - ok
17:58:41.0247 3404 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:58:41.0558 3404 Wdf01000 - ok
17:58:41.0695 3404 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:58:41.0744 3404 WdiServiceHost - ok
17:58:41.0757 3404 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:58:41.0883 3404 WdiSystemHost - ok
17:58:42.0033 3404 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:58:42.0280 3404 WebClient - ok
17:58:42.0512 3404 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:58:42.0945 3404 Wecsvc - ok
17:58:43.0019 3404 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:58:43.0294 3404 wercplsupport - ok
17:58:43.0603 3404 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:58:43.0812 3404 WerSvc - ok
17:58:43.0899 3404 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:58:44.0382 3404 WfpLwf - ok
17:58:44.0417 3404 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:58:44.0643 3404 WIMMount - ok
17:58:44.0685 3404 WinHttpAutoProxySvc - ok
17:58:44.0829 3404 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:58:45.0167 3404 Winmgmt - ok
17:58:45.0287 3404 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:58:45.0794 3404 WinRM - ok
17:58:45.0928 3404 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:58:46.0091 3404 WinUsb - ok
17:58:46.0180 3404 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:58:46.0559 3404 Wlansvc - ok
17:58:46.0701 3404 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
17:58:46.0980 3404 wlidsvc - ok
17:58:47.0048 3404 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
17:58:47.0248 3404 WmiAcpi - ok
17:58:49.0728 3404 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:58:50.0287 3404 wmiApSrv - ok
17:58:50.0612 3404 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:58:50.0796 3404 WMPNetworkSvc - ok
17:58:50.0848 3404 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:58:51.0306 3404 WPCSvc - ok
17:58:51.0373 3404 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:58:51.0938 3404 WPDBusEnum - ok
17:58:51.0992 3404 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:58:52.0311 3404 ws2ifsl - ok
17:58:52.0425 3404 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll
17:58:52.0499 3404 wscsvc - ok
17:58:52.0514 3404 WSearch - ok
17:58:52.0992 3404 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:58:53.0366 3404 wuauserv - ok
17:58:53.0427 3404 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:58:53.0861 3404 WudfPf - ok
17:58:53.0933 3404 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:58:54.0014 3404 WUDFRd - ok
17:58:54.0095 3404 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:58:54.0180 3404 wudfsvc - ok
17:58:54.0310 3404 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:58:55.0104 3404 WwanSvc - ok
17:58:55.0206 3404 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
17:58:55.0347 3404 YahooAUService - ok
17:58:55.0400 3404 ================ Scan global ===============================
17:58:55.0452 3404 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:58:55.0614 3404 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:58:55.0707 3404 [ 183B4188D5D91B271613EC3EFD1B3CEF ] C:\Windows\system32\winsrv.dll
17:58:56.0125 3404 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:58:56.0504 3404 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:58:56.0899 3404 [Global] - ok
17:58:56.0901 3404 ================ Scan MBR ==================================
17:58:56.0943 3404 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:58:57.0611 3404 \Device\Harddisk0\DR0 - ok
17:58:57.0612 3404 ================ Scan VBR ==================================
17:58:57.0641 3404 [ 37C2AF8DC409F36BB0B6807260516F19 ] \Device\Harddisk0\DR0\Partition1
17:58:57.0647 3404 \Device\Harddisk0\DR0\Partition1 - ok
17:58:57.0722 3404 [ 10DC3BFA03E13073F7D3B89FD2901525 ] \Device\Harddisk0\DR0\Partition2
17:58:57.0752 3404 \Device\Harddisk0\DR0\Partition2 - ok
17:58:57.0753 3404 ============================================================
17:58:57.0753 3404 Scan finished
17:58:57.0753 3404 ============================================================
17:58:57.0794 4884 Detected object count: 1
17:58:57.0796 4884 Actual detected object count: 1
18:31:38.0269 4884 C:\Windows\system32\drivers\volsnap.sys - copied to quarantine
18:31:55.0283 4884 Backup copy found, using it..
18:31:55.0498 4884 C:\Windows\system32\drivers\volsnap.sys - will be cured on reboot
18:31:55.0498 4884 volsnap ( Rootkit.Win32.TDSS.tdl3 ) - User select action: Cure
18:33:10.0584 1380 Deinitialize success

Attachments:

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 12-12-30.01 - Monta 30/12/2012 22:45:48.5.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.2.1033.18.1013.331 [GMT -8:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\system32\sysprep\CRYPTBASE.DLL c:\windows\wininit.ini . . ((((((((((((((((((((((((( Files Created from 2012-11-28 to 2012-12-31 ))))))))))))))))))))))))))))))) . . 2012-12-31 07:38 . 2012-12-31 07:38 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-12-31 02:31 . 2012-12-31 02:31 177496 —-a-w- c:\windows\system32\drivers\42764613.sys 2012-12-31 02:31 . 2012-12-31 02:31 ——– d—–w- C:\TDSSKiller_Quarantine 2012-12-21 09:34 . 2012-12-21 09:34 ——– d—–w- c:\users\Monta\AppData\Roaming\Media Player Classic 2012-12-20 20:44 . 2012-12-20 20:44 ——– d—–w- c:\program files\iPod 2012-12-20 20:44 . 2012-12-20 20:46 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-12-20 20:44 . 2012-12-20 20:46 ——– d—–w- c:\program files\iTunes 2012-12-13 07:19 . 2012-11-09 04:42 2048 —-a-w- c:\windows\system32\tzres.dll 2012-12-11 22:10 . 2012-12-11 22:10 16363960 —-a-w- c:\windows\system32\FlashPlayerInstaller.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-11 22:11 . 2012-11-23 08:44 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-12-11 22:11 . 2012-07-17 02:23 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-09 23:59 . 2012-10-09 23:59 0 —-a-w- c:\windows\system32\sho22C8.tmp 2012-12-08 11:23 . 2012-12-08 11:23 262112 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\Monta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\Monta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2012-02-15 00:32 94208 —-a-w- c:\users\Monta\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ares"="c:\program files\Ares\Ares.exe" [2010-10-27 1015808] "Xvid"="c:\program files\Xvid\CheckUpdate.exe" [2011-01-17 8192] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2012-05-25 6595928] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "EgisUpdate"="c:\program files\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-06-16 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552] "LManager"="c:\program files\Launch Manager\LManager.exe" [2010-06-22 968272] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-08-15 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 715296] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888] "WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-05-28 114688] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-12-14 11487848] "VolPanel"="c:\program files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe" [2010-02-19 241789] "Creative SB Monitoring Utility"="sbavmon.dll" [2010-08-03 104448] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "5AAF9E96-F052-4BD5-8B04-2DAFCE6E8747"="start" [X] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [x] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [x] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x] R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [x] R3 ksaud;Creative USB Audio Driver;c:\windows\system32\drivers\ksaud.sys [x] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [x] S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [x] S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [x] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 55099990 *Deregistered* - 55099990 *Deregistered* - aswMBR . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2012-12-31 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-23 22:11] . 2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job - c:\users\Monta\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-21 01:56] . 2012-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job - c:\users\Monta\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-21 01:56] . . ——- Supplementary Scan ——- . mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aod255&r=27b51210w555l0434ww65w4712u741 uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.254 DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab FF - ProfilePath - c:\users\Monta\AppData\Roaming\Mozilla\Firefox\Profiles\lb0arw84.default\ FF - prefs.js: browser.search.selectedEngine - Amazon.com FF - prefs.js: browser.startup.homepage - hxxp://ca.msn.com/?ocid=OIE9HP FF - prefs.js: network.proxy.type - 0 . - - - - ORPHANS REMOVED - - - - . HKCU-Run-AdobeBridge - (no file) SafeBoot-59767010.sys . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\volsnap] "ImagePath"="system32\drivers\tsk1F7.tmp" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-12-31 00:01:03 ComboFix-quarantined-files.txt 2012-12-31 08:00 ComboFix2.txt 2011-07-04 22:54 ComboFix3.txt 2011-06-14 06:59 ComboFix4.txt 2011-06-14 06:10 ComboFix5.txt 2012-12-31 06:35 . Pre-Run: 82,931,929,088 bytes free Post-Run: 85,135,912,960 bytes free . - - End Of File - - 9117D53425A098A03506D510B7BCA16F
You have ( Ares ), a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.

I would recommend that you uninstall it, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


===================================================

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
===================================================

On your next reply please post :
AdwCleaner log
Any improvements so far apart from not being to update?


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
I think it seems to be running better… that restart was faster than usual. here's the log # AdwCleaner v2.104 - Logfile created 12/31/2012 at 01:16:44 # Updated 29/12/2012 by Xplode # Operating system : Windows 7 Starter Service Pack 1 (32 bits) # User : Monta - MONTA-PC # Boot Mode : Normal # Running from : C:\Users\Monta\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Program Files\Free Offers from Freeze.com Folder Deleted : C:\ProgramData\Partner ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\alot Key Deleted : HKLM\Software\Freeze.com ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v17.0.1 (en-US) File : C:\Users\Monta\AppData\Roaming\Mozilla\Firefox\Profiles\lb0arw84.default\prefs.js [OK] File is clean. -\\ Google Chrome v23.0.1271.97 File : C:\Users\Monta\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[S1].txt - [1003 octets] - [31/12/2012 01:16:44] ########## EOF - C:\AdwCleaner[S1].txt - [1063 octets] ##########
Let's move on.

Please download Windows Repair (all in one) from here

Install the program then run it
  • Go to step 2 and allow it to run Disk check
  • Once that is done then go to step 3 and allow it to run SFC
  • On the the Start Repairs tab => Click the Start
  • Click on the select all check box and then click on Start
  • DON'T use the computer while each scan is in progress.
  • Restart may be needed to finish the repair procedure.

Please tell me if you are able to update.
Great! Please stay with me on this. There's still some things to do left.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Alternatively, look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Push the Back button.
  • Make sure you saved the log somewhere else. Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI