Hello,
I have a Gateway laptop that I believe is severely infected. The browser is being repeatedly hijacked, and there are a number of fake virus alerts that keep popping up. It is also running extremely slow and gets hung up whenever I try to run MBam.
Here are the specs:
Gateway laptop
Windows 7 Ultimate
Pentium M 1.73 GHz
1 Gb Ram
Any help is greatly appreciated,
Thank you very much,
mike
Hello and
My name is
patndoris . I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs. Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean. Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask! Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive. Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so. Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post. Please reply within 3 days . If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed !
1GB of RAM is the minimum requirement for Windows 7 so you are at the lowest end of the requirements for it. That will affect your performance, but obviously you have other issues going on.
Download and Run DDS by sUBs
We need to see some information about what is happening in your machine. Please perform the following scan:
Download DDS by sUBs from one of the following links. Save it to your desktop. Double click on the DDS icon, allow it to run. A small box will open, with an explaination about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that pop up for posting the results. Close the program window, and delete the program from your desktop. Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control
HERE
Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.
Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
๐ผ Click to load external image (Posted Image)
If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.
๐ผ Click to load external image (Posted Image)
If a suspicious file is detected, the default action will be Skip , click on Continue.
๐ผ Click to load external image (Posted Image)
It may ask you to reboot the computer to complete the process. Click on Reboot Now .
๐ผ Click to load external image (Posted Image)
If no reboot is require, click on Report . A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt ". Please copy and paste the contents of that file here.
Here ye be,
DDS Report
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2
Run by [removed] at 17:13:02 on 2012-12-27
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1014.201 [GMT -8:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\FpHidSrv.exe
C:\Program Files\Cricket Broadband AC3781\AC3781\bin\MonServiceUDisk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Chris\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
.
============== Pseudo HJT Report ===============
.
BHO: {3049C3E9-B461-4BC5-8870-4C09146192CA} -
BHO: Javaโข Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Javaโข Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{23B9AF9F-1EE1-4F80-AAFF-5ADB1F3F73CC} : NameServer = 192.168.1.1
TCP: Interfaces\{23B9AF9F-1EE1-4F80-AAFF-5ADB1F3F73CC} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{63A10AE0-3CB1-416C-B1D8-8DAFC5BFFFFB} : NameServer = 10.133.20.11 10.132.20.11
TCP: Interfaces\{6F8ECB1F-0B12-412C-9628-A515C93F267A} : NameServer = 10.133.20.11
TCP: Interfaces\{812CB92E-6997-437B-9EBA-C582EAA921AA} : NameServer = 192.168.33.1,205.171.3.25,205.171.2.25
TCP: Interfaces\{812CB92E-6997-437B-9EBA-C582EAA921AA} : DHCPNameServer = 192.168.33.1 [removed] [removed]
TCP: Interfaces\{812CB92E-6997-437B-9EBA-C582EAA921AA}\14E64627F696461405 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{812CB92E-6997-437B-9EBA-C582EAA921AA}\46C666634346D27657563747 : DHCPNameServer = 75.75.75.75 75.75.76.76
SSODL: WebCheck -
.
============= SERVICES / DRIVERS ===============
.
R0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [2012-12-10 13184]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-8-30 193552]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
R3 FinePnt;FinePoint Innovations HID Driver;c:\windows\system32\drivers\FpHidDrv.sys [2006-10-30 24736]
R3 MSTabBtn;Quanta Computer Tablet PC Buttons HID Driver;c:\windows\system32\drivers\mstabbtn.sys [2007-3-9 10496]
R3 NETw2v32;Intelยฎ PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2007-3-6 2595840]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 CT_ZTEMT_U_USBNET;ZTEMT USB-NDIS miniport;c:\windows\system32\drivers\CT_ZTEMT_U_USBNET.SYS [2012-12-10 182272]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-12-25 31560]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-12-25 40776]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 99272]
S3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys [2012-12-10 105472]
.
=============== Created Last 30 ================
.
2012-12-27 07:45:32 โโโ d-shโw- C:\$RECYCLE.BIN
2012-12-27 07:34:52 98816 โ-a-w- c:\windows\sed.exe
2012-12-27 07:34:52 256000 โ-a-w- c:\windows\PEV.exe
2012-12-27 07:34:52 208896 โ-a-w- c:\windows\MBR.exe
2012-12-27 04:11:22 โโโ dโโw- c:\program files\CCleaner
2012-12-27 01:47:24 34304 โ-a-w- c:\windows\system32\atmlib.dll
2012-12-27 01:47:24 295424 โ-a-w- c:\windows\system32\atmfd.dll
2012-12-27 00:55:24 6812136 โ-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{2e6cf893-3e26-41d5-909d-438289d1ac3f}\mpengine.dll
2012-12-26 22:29:01 2048 โ-a-w- c:\windows\system32\tzres.dll
2012-12-26 22:13:34 388096 โ-a-r- c:\users\chris\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-12-26 22:13:34 โโโ dโโw- c:\program files\Trend Micro
2012-12-26 02:19:37 40776 โ-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-12-26 01:18:16 31560 โ-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2012-12-26 00:17:46 6812136 โ-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-12-25 23:15:37 โโโ dโโw- C:\7e3275a5fbad84e9cfbb825a5bc28e
2012-12-25 23:14:34 โโโ dโโw- c:\users\chris\appdata\roaming\Malwarebytes
2012-12-25 23:14:19 โโโ dโโw- c:\programdata\Malwarebytes
2012-12-25 23:14:17 22856 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-25 23:14:17 โโโ dโโw- c:\program files\Malwarebytes' Anti-Malware
2012-12-25 21:45:58 49152 -cโ-w- c:\programdata\microsoft\windows\wer\reportqueue\appcrash_msmpeng.exe_c297628e14506b9a4cd538cc45b546b1c3562f8_cab_09df58a0\taskhost.exe
2012-12-16 22:17:52 โโโ dโโw- c:\windows\system32\MpEngineStore
2012-12-12 18:02:44 โโโ dโโw- c:\users\chris\appdata\local\ElevatedDiagnostics
2012-12-10 21:11:41 โโโ dโโw- C:\inetpub
2012-12-10 12:43:52 โโโ dโโw- c:\users\chris\appdata\roaming\searchresultstb
2012-12-10 12:43:50 โโโ dโโw- c:\users\chris\appdata\roaming\ilividtoolbarguid
2012-12-10 12:39:53 โโโ dโโw- c:\users\chris\appdata\roaming\ZteUpdateUI
2012-12-10 12:39:53 โโโ dโโw- c:\users\chris\appdata\roaming\ZTEEVDO
2012-12-10 12:39:04 โโโ dโโw- C:\ZTEEVDOAutoRun
2012-12-10 12:38:32 182272 โ-a-w- c:\windows\system32\drivers\CT_ZTEMT_U_USBNET.SYS
2012-12-10 12:38:32 105472 โ-a-w- c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys
2012-12-10 12:38:23 24192 โ-a-w- c:\windows\system32\drivers\tcpipBM.sys
2012-12-10 12:38:23 13712 โ-a-w- c:\windows\system32\sporder.dll
2012-12-10 12:38:23 13184 โ-a-w- c:\windows\system32\drivers\BMLoad.sys
2012-12-10 12:38:22 724608 โ-a-w- c:\windows\system32\bmutil.dll
2012-12-10 12:38:22 480384 โ-a-w- c:\windows\system32\bmnet.dll
2012-12-10 12:38:22 312448 โ-a-w- c:\windows\system32\bminstall.dll
2012-12-10 12:38:22 132224 โ-a-w- c:\windows\system32\bmdumpd.bin
2012-12-10 12:38:20 โโโ dโโw- c:\program files\Cricket Broadband AC3781
2012-12-10 11:24:51 โโโ dcโ-w- c:\users\chris\appdata\local\MigWiz
2012-12-09 14:21:00 โโโ dโโw- C:\b6c06dbed4e20ad14bb34519702c04
2012-12-08 22:22:13 โโโ dโโw- C:\BigFishGamesCache
2012-12-08 06:26:21 โโโ dโโw- c:\program files\SaveValet
2012-12-06 22:14:11 โโโ dโโw- c:\program files\Haali
2012-12-06 22:05:52 โโโ dโโw- c:\users\chris\appdata\roaming\PerformerSoft
2012-12-06 22:03:28 โโโ dโโw- c:\programdata\Tarma Installer
2012-12-06 22:02:51 โโโ dโโw- c:\program files\File Scout
2012-12-04 06:42:47 โโโ dโโw- c:\users\chris\appdata\roaming\PC Utility Kit
2012-12-04 06:42:47 โโโ dโโw- c:\users\chris\appdata\roaming\DriverCure
2012-12-04 06:42:02 โโโ dโโw- c:\programdata\PC Utility Kit
2012-12-03 10:33:37 73656 โ-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-03 10:33:37 697272 โ-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-03 09:59:36 โโโ dโโw- c:\program files\Ask.com
2012-12-03 09:58:59 โโโ dโโw- c:\users\chris\appdata\local\APN
2012-12-03 09:58:14 โโโ dโโw- c:\users\chris\appdata\roaming\Sammsoft
2012-12-03 00:27:13 โโโ dโโw- c:\users\chris\appdata\local\Programs
2012-12-02 18:19:57 โโโ dโโw- c:\users\chris\appdata\local\Torch
2012-12-02 18:17:49 746984 โ-a-w- c:\windows\system32\deployJava1.dll
2012-12-02 18:17:48 821736 โ-a-w- c:\windows\system32\npDeployJava1.dll
2012-12-02 18:16:50 93672 โ-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-12-02 18:15:35 773968 โ-a-w- c:\windows\system32\msvcr100.dll
2012-12-02 10:43:51 740840 โโw- c:\programdata\microsoft\microsoft antimalware\definition updates\{9ae13faf-a47a-4059-9184-d82c3d6c764c}\gapaengine.dll
2012-12-02 10:21:47 โโโ dโโw- c:\users\chris\appdata\roaming\PCCUStubInstaller
2012-12-02 10:19:56 โโโ dโโw- c:\programdata\Norton
2012-12-02 10:19:50 โโโ dโโw- c:\programdata\NortonInstaller
2012-12-02 04:59:31 โโโ dโโw- c:\programdata\boost_interprocess
2012-12-02 04:57:08 โโโ dโโw- c:\users\chris\appdata\roaming\Cricket Broadband AC3781
.
==================== Find3M ====================
.
2012-11-22 07:43:13 2344960 โ-a-w- c:\windows\system32\win32k.sys
2012-11-14 02:09:22 1800704 โ-a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 โ-a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 โ-a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 โ-a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 โ-a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 โ-a-w- c:\windows\system32\mshtml.tlb
2012-11-02 04:48:28 376832 โ-a-w- c:\windows\system32\dpnet.dll
2012-10-16 20:34:37 559104 โ-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-04 16:53:53 169984 โ-a-w- c:\windows\system32\winsrv.dll
2012-10-04 16:49:12 293376 โ-a-w- c:\windows\system32\KernelBase.dll
2012-10-04 15:00:00 271360 โ-a-w- c:\windows\system32\conhost.exe
2012-10-04 14:44:29 6144 โha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-10-04 14:44:29 4608 โha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-10-04 14:44:29 3584 โha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-10-04 14:44:29 3072 โha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
.
============= FINISH: 17:19:16.12 ===============
TDSSKiller
17:24:35.0424 3300 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
17:24:35.0956 3300 ============================================================
17:24:35.0956 3300 Current date / time: 2012/12/27 17:24:35.0956
17:24:35.0956 3300 SystemInfo:
17:24:35.0956 3300
17:24:35.0956 3300 OS Version: 6.1.7600 ServicePack: 0.0
17:24:35.0956 3300 Product type: Workstation
17:24:35.0956 3300 ComputerName: CHRIS-PC
17:24:35.0956 3300 UserName: Chris
17:24:35.0956 3300 Windows directory: C:\Windows
17:24:35.0956 3300 System windows directory: C:\Windows
17:24:35.0956 3300 Processor architecture: Intel x86
17:24:35.0956 3300 Number of processors: 1
17:24:35.0956 3300 Page size: 0x1000
17:24:35.0956 3300 Boot type: Normal boot
17:24:35.0956 3300 ============================================================
17:24:37.0721 3300 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:24:37.0721 3300 ============================================================
17:24:37.0721 3300 \Device\Harddisk0\DR0:
17:24:37.0721 3300 MBR partitions:
17:24:37.0721 3300 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xDAE73D, BlocksNum 0x875BEC3
17:24:37.0721 3300 \Device\Harddisk0\DR0\Partition2: MBR, Type 0xB, StartLBA 0x3F, BlocksNum 0xDAE6FE
17:24:37.0721 3300 ============================================================
17:24:37.0752 3300 C: <-> \Device\Harddisk0\DR0\Partition1
17:24:37.0752 3300 D: <-> \Device\Harddisk0\DR0\Partition2
17:24:37.0768 3300 ============================================================
17:24:37.0768 3300 Initialize success
17:24:37.0768 3300 ============================================================
17:24:44.0035 3776 ============================================================
17:24:44.0035 3776 Scan started
17:24:44.0035 3776 Mode: Manual;
17:24:44.0035 3776 ============================================================
17:24:45.0816 3776 ================ Scan system memory ========================
17:24:45.0816 3776 System memory - ok
17:24:45.0832 3776 ================ Scan services =============================
17:24:46.0127 3776 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
17:24:46.0132 3776 1394ohci - ok
17:24:46.0178 3776 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
17:24:46.0189 3776 ACPI - ok
17:24:46.0240 3776 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
17:24:46.0241 3776 AcpiPmi - ok
17:24:46.0369 3776 [ 95CE557D16A75606CCC2D7F3B0B0BCCB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:24:46.0377 3776 AdobeFlashPlayerUpdateSvc - ok
17:24:46.0454 3776 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:24:46.0466 3776 adp94xx - ok
17:24:46.0508 3776 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:24:46.0516 3776 adpahci - ok
17:24:46.0550 3776 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:24:46.0559 3776 adpu320 - ok
17:24:46.0618 3776 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:24:46.0619 3776 AeLookupSvc - ok
17:24:46.0699 3776 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\Windows\system32\drivers\afd.sys
17:24:46.0708 3776 AFD - ok
17:24:46.0750 3776 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
17:24:46.0753 3776 agp440 - ok
17:24:46.0815 3776 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:24:46.0818 3776 aic78xx - ok
17:24:46.0877 3776 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:24:46.0879 3776 ALG - ok
17:24:46.0909 3776 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
17:24:46.0911 3776 aliide - ok
17:24:46.0931 3776 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
17:24:46.0947 3776 amdagp - ok
17:24:46.0962 3776 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
17:24:46.0962 3776 amdide - ok
17:24:47.0009 3776 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:24:47.0025 3776 AmdK8 - ok
17:24:47.0056 3776 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:24:47.0056 3776 AmdPPM - ok
17:24:47.0119 3776 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:24:47.0134 3776 amdsata - ok
17:24:47.0166 3776 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:24:47.0166 3776 amdsbs - ok
17:24:47.0228 3776 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:24:47.0228 3776 amdxata - ok
17:24:47.0291 3776 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
17:24:47.0291 3776 AppID - ok
17:24:47.0400 3776 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:24:47.0400 3776 AppIDSvc - ok
17:24:47.0462 3776 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
17:24:47.0462 3776 Appinfo - ok
17:24:47.0603 3776 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:24:47.0603 3776 Apple Mobile Device - ok
17:24:47.0650 3776 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:24:47.0650 3776 AppMgmt - ok
17:24:47.0712 3776 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:24:47.0712 3776 arc - ok
17:24:47.0744 3776 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:24:47.0744 3776 arcsas - ok
17:24:47.0775 3776 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:24:47.0775 3776 AsyncMac - ok
17:24:47.0806 3776 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
17:24:47.0806 3776 atapi - ok
17:24:47.0837 3776 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:24:47.0853 3776 AudioEndpointBuilder - ok
17:24:47.0869 3776 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:24:47.0884 3776 Audiosrv - ok
17:24:47.0916 3776 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:24:47.0916 3776 AxInstSV - ok
17:24:47.0978 3776 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:24:47.0978 3776 b06bdrv - ok
17:24:48.0025 3776 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:24:48.0025 3776 b57nd60x - ok
17:24:48.0056 3776 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:24:48.0072 3776 BDESVC - ok
17:24:48.0087 3776 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:24:48.0087 3776 Beep - ok
17:24:48.0150 3776 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
17:24:48.0166 3776 BFE - ok
17:24:48.0228 3776 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\system32\qmgr.dll
17:24:48.0244 3776 BITS - ok
17:24:48.0291 3776 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:24:48.0291 3776 blbdrive - ok
17:24:48.0369 3776 [ 3E90FA8A58A687AAA7A07BDD9215F67E ] BMLoad C:\Windows\system32\drivers\BMLoad.sys
17:24:48.0369 3776 BMLoad - ok
17:24:48.0478 3776 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
17:24:48.0478 3776 Bonjour Service - ok
17:24:48.0541 3776 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:24:48.0541 3776 bowser - ok
17:24:48.0572 3776 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:24:48.0572 3776 BrFiltLo - ok
17:24:48.0587 3776 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:24:48.0587 3776 BrFiltUp - ok
17:24:48.0619 3776 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
17:24:48.0619 3776 BridgeMP - ok
17:24:48.0681 3776 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\Windows\System32\browser.dll
17:24:48.0681 3776 Browser - ok
17:24:48.0712 3776 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:24:48.0712 3776 Brserid - ok
17:24:48.0728 3776 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:24:48.0744 3776 BrSerWdm - ok
17:24:48.0744 3776 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:24:48.0744 3776 BrUsbMdm - ok
17:24:48.0759 3776 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:24:48.0759 3776 BrUsbSer - ok
17:24:48.0791 3776 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:24:48.0791 3776 BTHMODEM - ok
17:24:48.0853 3776 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:24:48.0853 3776 bthserv - ok
17:24:48.0916 3776 [ CCE1F3C7C8E7383B90372229454999CF ] CAMCAUD C:\Windows\system32\drivers\camc6aud.sys
17:24:48.0916 3776 CAMCAUD - ok
17:24:48.0947 3776 [ 9A3BBDE74DAB737EFA82DE7EF4B40BEA ] CAMCHALA C:\Windows\system32\drivers\camc6hal.sys
17:24:48.0962 3776 CAMCHALA - ok
17:24:49.0056 3776 catchme - ok
17:24:49.0103 3776 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:24:49.0119 3776 cdfs - ok
17:24:49.0181 3776 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:24:49.0197 3776 cdrom - ok
17:24:49.0244 3776 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
17:24:49.0244 3776 CertPropSvc - ok
17:24:49.0275 3776 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:24:49.0275 3776 circlass - ok
17:24:49.0337 3776 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:24:49.0353 3776 CLFS - ok
17:24:49.0462 3776 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:24:49.0462 3776 clr_optimization_v2.0.50727_32 - ok
17:24:49.0603 3776 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:24:49.0619 3776 clr_optimization_v4.0.30319_32 - ok
17:24:49.0650 3776 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:24:49.0650 3776 CmBatt - ok
17:24:49.0666 3776 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
17:24:49.0666 3776 cmdide - ok
17:24:49.0728 3776 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\Windows\system32\Drivers\cng.sys
17:24:49.0744 3776 CNG - ok
17:24:49.0791 3776 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:24:49.0791 3776 Compbatt - ok
17:24:49.0837 3776 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
17:24:49.0837 3776 CompositeBus - ok
17:24:49.0869 3776 COMSysApp - ok
17:24:49.0900 3776 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:24:49.0900 3776 crcdisk - ok
17:24:49.0978 3776 [ F2FDE6C8DBAAD44CC58D1E07E4AF4EED ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:24:49.0994 3776 CryptSvc - ok
17:24:50.0041 3776 [ 27C9490BDD0AE48911AB8CF1932591ED ] CSC C:\Windows\system32\drivers\csc.sys
17:24:50.0041 3776 CSC - ok
17:24:50.0119 3776 [ 56FB5F222EA30D3D3FC459879772CB73 ] CscService C:\Windows\System32\cscsvc.dll
17:24:50.0134 3776 CscService - ok
17:24:50.0212 3776 [ 2BE3E3CDAED8A624D2FDC58109478C52 ] CT_ZTEMT_U_USBNET C:\Windows\system32\DRIVERS\CT_ZTEMT_U_USBNET.SYS
17:24:50.0212 3776 CT_ZTEMT_U_USBNET - ok
17:24:50.0275 3776 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
17:24:50.0291 3776 DcomLaunch - ok
17:24:50.0322 3776 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:24:50.0337 3776 defragsvc - ok
17:24:50.0369 3776 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:24:50.0369 3776 DfsC - ok
17:24:50.0416 3776 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:24:50.0431 3776 Dhcp - ok
17:24:50.0462 3776 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:24:50.0462 3776 discache - ok
17:24:50.0509 3776 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:24:50.0525 3776 Disk - ok
17:24:50.0587 3776 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:24:50.0587 3776 Dnscache - ok
17:24:50.0650 3776 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
17:24:50.0650 3776 dot3svc - ok
17:24:50.0681 3776 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
17:24:50.0681 3776 DPS - ok
17:24:50.0728 3776 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:24:50.0728 3776 drmkaud - ok
17:24:50.0806 3776 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:24:50.0822 3776 DXGKrnl - ok
17:24:50.0916 3776 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:24:50.0916 3776 EapHost - ok
17:24:51.0242 3776 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:24:51.0320 3776 ebdrv - ok
17:24:51.0351 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\Windows\System32\lsass.exe
17:24:51.0351 3776 EFS - ok
17:24:51.0445 3776 [ 1697C39978CD69F6FBC15302EDCECE1F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:24:51.0460 3776 ehRecvr - ok
17:24:51.0523 3776 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:24:51.0523 3776 ehSched - ok
17:24:51.0601 3776 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:24:51.0601 3776 elxstor - ok
17:24:51.0632 3776 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
17:24:51.0632 3776 ErrDev - ok
17:24:51.0710 3776 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:24:51.0710 3776 EventSystem - ok
17:24:51.0742 3776 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:24:51.0742 3776 exfat - ok
17:24:51.0773 3776 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:24:51.0773 3776 fastfat - ok
17:24:51.0835 3776 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
17:24:51.0851 3776 Fax - ok
17:24:51.0867 3776 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:24:51.0867 3776 fdc - ok
17:24:51.0898 3776 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:24:51.0898 3776 fdPHost - ok
17:24:51.0914 3776 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:24:51.0914 3776 FDResPub - ok
17:24:51.0945 3776 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:24:51.0945 3776 FileInfo - ok
17:24:51.0960 3776 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:24:51.0960 3776 Filetrace - ok
17:24:52.0007 3776 [ EB65EFBE82110329CAC8836364D3E3E1 ] FinePnt C:\Windows\system32\DRIVERS\FpHidDrv.sys
17:24:52.0007 3776 FinePnt - ok
17:24:52.0039 3776 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:24:52.0039 3776 flpydisk - ok
17:24:52.0070 3776 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:24:52.0070 3776 FltMgr - ok
17:24:52.0149 3776 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\Windows\system32\FntCache.dll
17:24:52.0180 3776 FontCache - ok
17:24:52.0258 3776 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:24:52.0258 3776 FontCache3.0.0.0 - ok
17:24:52.0321 3776 FpHidSrv - ok
17:24:52.0383 3776 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:24:52.0383 3776 FsDepends - ok
17:24:52.0430 3776 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:24:52.0430 3776 Fs_Rec - ok
17:24:52.0493 3776 [ DAFBD9FE39197495AED6D51F3B85B5D2 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:24:52.0493 3776 fvevol - ok
17:24:52.0540 3776 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:24:52.0555 3776 gagp30kx - ok
17:24:52.0602 3776 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:24:52.0602 3776 GEARAspiWDM - ok
17:24:52.0680 3776 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
17:24:52.0696 3776 gpsvc - ok
17:24:52.0852 3776 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
17:24:52.0852 3776 gupdate - ok
17:24:52.0883 3776 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
17:24:52.0883 3776 gupdatem - ok
17:24:52.0977 3776 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
17:24:52.0993 3776 gusvc - ok
17:24:53.0008 3776 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:24:53.0024 3776 hcw85cir - ok
17:24:53.0040 3776 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
17:24:53.0055 3776 HDAudBus - ok
17:24:53.0071 3776 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:24:53.0071 3776 HidBatt - ok
17:24:53.0118 3776 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:24:53.0118 3776 HidBth - ok
17:24:53.0149 3776 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:24:53.0165 3776 HidIr - ok
17:24:53.0196 3776 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
17:24:53.0196 3776 hidserv - ok
17:24:53.0258 3776 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:24:53.0258 3776 HidUsb - ok
17:24:53.0305 3776 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:24:53.0305 3776 hkmsvc - ok
17:24:53.0321 3776 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:24:53.0321 3776 HomeGroupListener - ok
17:24:53.0383 3776 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:24:53.0383 3776 HomeGroupProvider - ok
17:24:53.0430 3776 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
17:24:53.0446 3776 HpSAMD - ok
17:24:53.0508 3776 [ E7BCC7EC37DD2DD36A39BB9AC87A897B ] HSFHWICH C:\Windows\system32\DRIVERS\HSFHWICH.sys
17:24:53.0508 3776 HSFHWICH - ok
17:24:53.0571 3776 [ 822C60F2ABEE73A0E089230D94064F39 ] HSF_DPV C:\Windows\system32\DRIVERS\HSF_DPV.sys
17:24:53.0586 3776 HSF_DPV - ok
17:24:53.0665 3776 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:24:53.0680 3776 HTTP - ok
17:24:53.0711 3776 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:24:53.0711 3776 hwpolicy - ok
17:24:53.0743 3776 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:24:53.0758 3776 i8042prt - ok
17:24:53.0836 3776 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:24:53.0836 3776 iaStorV - ok
17:24:53.0946 3776 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:24:53.0977 3776 idsvc - ok
17:24:54.0024 3776 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:24:54.0040 3776 iirsp - ok
17:24:54.0118 3776 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
17:24:54.0133 3776 IKEEXT - ok
17:24:54.0180 3776 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
17:24:54.0180 3776 intelide - ok
17:24:54.0211 3776 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:24:54.0211 3776 intelppm - ok
17:24:54.0243 3776 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:24:54.0243 3776 IPBusEnum - ok
17:24:54.0274 3776 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:24:54.0274 3776 IpFilterDriver - ok
17:24:54.0336 3776 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:24:54.0352 3776 iphlpsvc - ok
17:24:54.0383 3776 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
17:24:54.0383 3776 IPMIDRV - ok
17:24:54.0430 3776 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:24:54.0446 3776 IPNAT - ok
17:24:54.0524 3776 [ E6BE7A41A28D8F2DB174957454D32448 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
17:24:54.0555 3776 iPod Service - ok
17:24:54.0586 3776 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:24:54.0586 3776 IRENUM - ok
17:24:54.0633 3776 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
17:24:54.0633 3776 isapnp - ok
17:24:54.0680 3776 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
17:24:54.0680 3776 iScsiPrt - ok
17:24:54.0743 3776 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:24:54.0743 3776 kbdclass - ok
17:24:54.0774 3776 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
17:24:54.0774 3776 kbdhid - ok
17:24:54.0805 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\Windows\system32\lsass.exe
17:24:54.0805 3776 KeyIso - ok
17:24:54.0852 3776 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:24:54.0852 3776 KSecDD - ok
17:24:54.0868 3776 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:24:54.0868 3776 KSecPkg - ok
17:24:54.0915 3776 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:24:54.0930 3776 KtmRm - ok
17:24:54.0961 3776 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\Windows\System32\srvsvc.dll
17:24:54.0977 3776 LanmanServer - ok
17:24:55.0024 3776 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:24:55.0024 3776 LanmanWorkstation - ok
17:24:55.0055 3776 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:24:55.0055 3776 lltdio - ok
17:24:55.0133 3776 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:24:55.0149 3776 lltdsvc - ok
17:24:55.0211 3776 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:24:55.0227 3776 lmhosts - ok
17:24:55.0274 3776 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:24:55.0274 3776 LSI_FC - ok
17:24:55.0336 3776 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:24:55.0336 3776 LSI_SAS - ok
17:24:55.0383 3776 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:24:55.0383 3776 LSI_SAS2 - ok
17:24:55.0415 3776 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:24:55.0415 3776 LSI_SCSI - ok
17:24:55.0446 3776 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:24:55.0446 3776 luafv - ok
17:24:55.0493 3776 [ D1D7EF163775449FDC38208ABF94B926 ] mbamchameleon C:\Windows\system32\drivers\mbamchameleon.sys
17:24:55.0493 3776 mbamchameleon - ok
17:24:55.0555 3776 [ 0DB7527DB188C7D967A37BB51BBF3963 ] MBAMSwissArmy C:\Windows\system32\drivers\mbamswissarmy.sys
17:24:55.0555 3776 MBAMSwissArmy - ok
17:24:55.0586 3776 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:24:55.0586 3776 Mcx2Svc - ok
17:24:55.0633 3776 [ 3C318B9CD391371BED62126581EE9961 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
17:24:55.0633 3776 mdmxsdk - ok
17:24:55.0680 3776 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:24:55.0680 3776 megasas - ok
17:24:55.0711 3776 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:24:55.0711 3776 MegaSR - ok
17:24:55.0774 3776 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:24:55.0774 3776 MMCSS - ok
17:24:55.0790 3776 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:24:55.0805 3776 Modem - ok
17:24:55.0836 3776 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:24:55.0836 3776 monitor - ok
17:24:55.0883 3776 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:24:55.0883 3776 mouclass - ok
17:24:55.0930 3776 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:24:55.0930 3776 mouhid - ok
17:24:55.0946 3776 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:24:55.0946 3776 mountmgr - ok
17:24:56.0066 3776 [ EE728AF83850DDAD9A3FCAC0AAB3AD97 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
17:24:56.0073 3776 MpFilter - ok
17:24:56.0112 3776 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
17:24:56.0115 3776 mpio - ok
17:24:56.0229 3776 MpKsl8cef4730 - ok
17:24:56.0275 3776 MpKslc2282ffa - ok
17:24:56.0346 3776 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:24:56.0348 3776 mpsdrv - ok
17:24:56.0419 3776 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
17:24:56.0440 3776 MpsSvc - ok
17:24:56.0494 3776 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:24:56.0496 3776 MRxDAV - ok
17:24:56.0543 3776 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:24:56.0546 3776 mrxsmb - ok
17:24:56.0578 3776 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:24:56.0581 3776 mrxsmb10 - ok
17:24:56.0624 3776 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:24:56.0625 3776 mrxsmb20 - ok
17:24:56.0646 3776 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
17:24:56.0648 3776 msahci - ok
17:24:56.0685 3776 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
17:24:56.0688 3776 msdsm - ok
17:24:56.0719 3776 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:24:56.0723 3776 MSDTC - ok
17:24:56.0768 3776 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:24:56.0768 3776 Msfs - ok
17:24:56.0795 3776 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:24:56.0796 3776 mshidkmdf - ok
17:24:56.0827 3776 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
17:24:56.0828 3776 msisadrv - ok
17:24:56.0887 3776 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:24:56.0894 3776 MSiSCSI - ok
17:24:56.0915 3776 msiserver - ok
17:24:56.0962 3776 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:24:56.0963 3776 MSKSSRV - ok
17:24:57.0074 3776 [ E077FCA2A7E79FB9BF67D3E30B5CE593 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
17:24:57.0074 3776 MsMpSvc - ok
17:24:57.0105 3776 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:24:57.0105 3776 MSPCLOCK - ok
17:24:57.0136 3776 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:24:57.0136 3776 MSPQM - ok
17:24:57.0167 3776 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:24:57.0167 3776 MsRPC - ok
17:24:57.0199 3776 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:24:57.0199 3776 mssmbios - ok
17:24:57.0261 3776 [ DC2CE790C9B1C5B294C298B81D66FE65 ] MSTabBtn C:\Windows\system32\DRIVERS\mstabbtn.sys
17:24:57.0261 3776 MSTabBtn - ok
17:24:57.0292 3776 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:24:57.0292 3776 MSTEE - ok
17:24:57.0324 3776 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:24:57.0324 3776 MTConfig - ok
17:24:57.0355 3776 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:24:57.0371 3776 Mup - ok
17:24:57.0417 3776 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
17:24:57.0433 3776 napagent - ok
17:24:57.0558 3776 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:24:57.0605 3776 NativeWifiP - ok
17:24:57.0730 3776 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:24:57.0792 3776 NDIS - ok
17:24:57.0871 3776 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:24:57.0871 3776 NdisCap - ok
17:24:57.0917 3776 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:24:57.0917 3776 NdisTapi - ok
17:24:57.0964 3776 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:24:57.0964 3776 Ndisuio - ok
17:24:57.0996 3776 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:24:57.0996 3776 NdisWan - ok
17:24:58.0011 3776 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:24:58.0011 3776 NDProxy - ok
17:24:58.0042 3776 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:24:58.0042 3776 NetBIOS - ok
17:24:58.0074 3776 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:24:58.0074 3776 NetBT - ok
17:24:58.0105 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\Windows\system32\lsass.exe
17:24:58.0105 3776 Netlogon - ok
17:24:58.0167 3776 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:24:58.0183 3776 Netman - ok
17:24:58.0230 3776 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:24:58.0230 3776 netprofm - ok
17:24:58.0261 3776 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:24:58.0277 3776 NetTcpPortSharing - ok
17:24:58.0417 3776 [ 2BA416A948360FCBA8016DF6DCBC4165 ] NETw2v32 C:\Windows\system32\DRIVERS\NETw2v32.sys
17:24:58.0480 3776 NETw2v32 - ok
17:24:58.0527 3776 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:24:58.0542 3776 nfrd960 - ok
17:24:58.0636 3776 [ 2CD24A6AF497D0E9B9BF3DA924ED05E6 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
17:24:58.0636 3776 NisDrv - ok
17:24:58.0683 3776 [ 3B846434055F80D9E89D0742F3ADAD34 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
17:24:58.0683 3776 NisSrv - ok
17:24:58.0746 3776 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
17:24:58.0761 3776 NlaSvc - ok
17:24:58.0792 3776 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:24:58.0792 3776 Npfs - ok
17:24:58.0808 3776 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:24:58.0824 3776 nsi - ok
17:24:58.0839 3776 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:24:58.0839 3776 nsiproxy - ok
17:24:58.0933 3776 [ 5126C5402C730C2A953275D8497A4715 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:24:58.0964 3776 Ntfs - ok
17:24:59.0011 3776 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:24:59.0011 3776 Null - ok
17:24:59.0074 3776 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:24:59.0074 3776 nvraid - ok
17:24:59.0121 3776 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:24:59.0121 3776 nvstor - ok
17:24:59.0152 3776 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
17:24:59.0152 3776 nv_agp - ok
17:24:59.0183 3776 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
17:24:59.0183 3776 ohci1394 - ok
17:24:59.0230 3776 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:24:59.0230 3776 p2pimsvc - ok
17:24:59.0261 3776 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:24:59.0277 3776 p2psvc - ok
17:24:59.0308 3776 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:24:59.0308 3776 Parport - ok
17:24:59.0355 3776 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:24:59.0355 3776 partmgr - ok
17:24:59.0386 3776 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:24:59.0386 3776 Parvdm - ok
17:24:59.0417 3776 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:24:59.0433 3776 PcaSvc - ok
17:24:59.0464 3776 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
17:24:59.0464 3776 pci - ok
17:24:59.0496 3776 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
17:24:59.0496 3776 pciide - ok
17:24:59.0542 3776 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:24:59.0542 3776 pcmcia - ok
17:24:59.0574 3776 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:24:59.0574 3776 pcw - ok
17:24:59.0636 3776 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:24:59.0652 3776 PEAUTH - ok
17:24:59.0730 3776 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:24:59.0761 3776 PeerDistSvc - ok
17:24:59.0886 3776 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
17:24:59.0933 3776 pla - ok
17:25:00.0011 3776 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:25:00.0027 3776 PlugPlay - ok
17:25:00.0074 3776 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:25:00.0074 3776 PNRPAutoReg - ok
17:25:00.0105 3776 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:25:00.0121 3776 PNRPsvc - ok
17:25:00.0167 3776 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:25:00.0183 3776 PolicyAgent - ok
17:25:00.0246 3776 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
17:25:00.0246 3776 Power - ok
17:25:00.0324 3776 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:25:00.0324 3776 PptpMiniport - ok
17:25:00.0355 3776 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:25:00.0355 3776 Processor - ok
17:25:00.0417 3776 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\Windows\system32\profsvc.dll
17:25:00.0417 3776 ProfSvc - ok
17:25:00.0449 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:25:00.0449 3776 ProtectedStorage - ok
17:25:00.0480 3776 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:25:00.0496 3776 Psched - ok
17:25:00.0574 3776 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:25:00.0621 3776 ql2300 - ok
17:25:00.0652 3776 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:25:00.0652 3776 ql40xx - ok
17:25:00.0714 3776 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:25:00.0714 3776 QWAVE - ok
17:25:00.0746 3776 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:25:00.0746 3776 QWAVEdrv - ok
17:25:00.0792 3776 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:25:00.0792 3776 RasAcd - ok
17:25:00.0871 3776 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:25:00.0871 3776 RasAgileVpn - ok
17:25:00.0886 3776 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:25:00.0886 3776 RasAuto - ok
17:25:00.0917 3776 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:25:00.0917 3776 Rasl2tp - ok
17:25:00.0964 3776 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
17:25:00.0980 3776 RasMan - ok
17:25:01.0011 3776 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:25:01.0011 3776 RasPppoe - ok
17:25:01.0027 3776 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:25:01.0027 3776 RasSstp - ok
17:25:01.0058 3776 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:25:01.0074 3776 rdbss - ok
17:25:01.0105 3776 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:25:01.0105 3776 rdpbus - ok
17:25:01.0136 3776 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:25:01.0136 3776 RDPCDD - ok
17:25:01.0183 3776 [ C5FF95883FFEF704D50C40D21CFB3AB5 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:25:01.0183 3776 RDPDR - ok
17:25:01.0214 3776 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:25:01.0214 3776 RDPENCDD - ok
17:25:01.0246 3776 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:25:01.0246 3776 RDPREFMP - ok
17:25:01.0292 3776 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:25:01.0292 3776 RDPWD - ok
17:25:01.0324 3776 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:25:01.0339 3776 rdyboost - ok
17:25:01.0386 3776 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:25:01.0386 3776 RemoteAccess - ok
17:25:01.0449 3776 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:25:01.0449 3776 RemoteRegistry - ok
17:25:01.0496 3776 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:25:01.0496 3776 RpcEptMapper - ok
17:25:01.0542 3776 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:25:01.0542 3776 RpcLocator - ok
17:25:01.0574 3776 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
17:25:01.0574 3776 RpcSs - ok
17:25:01.0621 3776 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:25:01.0636 3776 rspndr - ok
17:25:01.0667 3776 [ 5423D8437051E89DD34749F242C98648 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
17:25:01.0667 3776 s3cap - ok
17:25:01.0699 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\Windows\system32\lsass.exe
17:25:01.0699 3776 SamSs - ok
17:25:01.0746 3776 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
17:25:01.0746 3776 sbp2port - ok
17:25:01.0808 3776 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:25:01.0824 3776 SCardSvr - ok
17:25:01.0855 3776 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:25:01.0855 3776 scfilter - ok
17:25:01.0917 3776 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\Windows\system32\schedsvc.dll
17:25:01.0933 3776 Schedule - ok
17:25:01.0964 3776 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
17:25:01.0964 3776 SCPolicySvc - ok
17:25:02.0027 3776 [ 7B48CFF3A475FE849DEA65EC4D35C425 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys
17:25:02.0027 3776 sdbus - ok
17:25:02.0058 3776 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:25:02.0074 3776 SDRSVC - ok
17:25:02.0121 3776 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:25:02.0121 3776 secdrv - ok
17:25:02.0167 3776 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:25:02.0167 3776 seclogon - ok
17:25:02.0199 3776 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
17:25:02.0214 3776 SENS - ok
17:25:02.0246 3776 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:25:02.0246 3776 SensrSvc - ok
17:25:02.0277 3776 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:25:02.0277 3776 Serenum - ok
17:25:02.0308 3776 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:25:02.0308 3776 Serial - ok
17:25:02.0339 3776 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:25:02.0339 3776 sermouse - ok
17:25:02.0386 3776 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
17:25:02.0402 3776 SessionEnv - ok
17:25:02.0417 3776 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
17:25:02.0417 3776 sffdisk - ok
17:25:02.0433 3776 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
17:25:02.0433 3776 sffp_mmc - ok
17:25:02.0464 3776 [ 4F1E5B0FE7C8050668DBFADE8999AEFB ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
17:25:02.0464 3776 sffp_sd - ok
17:25:02.0480 3776 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:25:02.0480 3776 sfloppy - ok
17:25:02.0542 3776 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:25:02.0558 3776 SharedAccess - ok
17:25:02.0621 3776 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:25:02.0652 3776 ShellHWDetection - ok
17:25:02.0683 3776 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
17:25:02.0683 3776 sisagp - ok
17:25:02.0746 3776 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:25:02.0746 3776 SiSRaid2 - ok
17:25:02.0777 3776 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:25:02.0777 3776 SiSRaid4 - ok
17:25:02.0824 3776 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:25:02.0824 3776 Smb - ok
17:25:02.0886 3776 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:25:02.0886 3776 SNMPTRAP - ok
17:25:02.0917 3776 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:25:02.0917 3776 spldr - ok
17:25:02.0980 3776 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\Windows\System32\spoolsv.exe
17:25:02.0996 3776 Spooler - ok
17:25:03.0162 3776 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
17:25:03.0224 3776 sppsvc - ok
17:25:03.0271 3776 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:25:03.0271 3776 sppuinotify - ok
17:25:03.0349 3776 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\Windows\system32\DRIVERS\srv.sys
17:25:03.0349 3776 srv - ok
17:25:03.0412 3776 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:25:03.0412 3776 srv2 - ok
17:25:03.0443 3776 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:25:03.0443 3776 srvnet - ok
17:25:03.0490 3776 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:25:03.0505 3776 SSDPSRV - ok
17:25:03.0552 3776 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:25:03.0568 3776 SstpSvc - ok
17:25:03.0599 3776 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:25:03.0599 3776 stexstor - ok
17:25:03.0677 3776 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
17:25:03.0693 3776 StiSvc - ok
17:25:03.0724 3776 [ 957E346CA948668F2496A6CCF6FF82CC ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
17:25:03.0724 3776 storflt - ok
17:25:03.0755 3776 [ D5751969DC3E4B88BF482AC8EC9FE019 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
17:25:03.0755 3776 storvsc - ok
17:25:03.0771 3776 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:25:03.0787 3776 swenum - ok
17:25:03.0818 3776 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:25:03.0818 3776 swprv - ok
17:25:03.0896 3776 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
17:25:03.0927 3776 SysMain - ok
17:25:03.0974 3776 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:25:03.0974 3776 TabletInputService - ok
17:25:04.0005 3776 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
17:25:04.0021 3776 TapiSrv - ok
17:25:04.0052 3776 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:25:04.0052 3776 TBS - ok
17:25:04.0153 3776 [ 55E9965552741F3850CB22CBBA9671ED ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:25:04.0189 3776 Tcpip - ok
17:25:04.0236 3776 [ 55E9965552741F3850CB22CBBA9671ED ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:25:04.0251 3776 TCPIP6 - ok
17:25:04.0361 3776 [ CC53F9C0FF42C0A39207F8FB366668BE ] tcpipBM C:\Windows\system32\drivers\tcpipBM.sys
17:25:04.0361 3776 tcpipBM - ok
17:25:04.0423 3776 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:25:04.0423 3776 tcpipreg - ok
17:25:04.0470 3776 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:25:04.0470 3776 TDPIPE - ok
17:25:04.0501 3776 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:25:04.0501 3776 TDTCP - ok
17:25:04.0533 3776 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:25:04.0548 3776 tdx - ok
17:25:04.0564 3776 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:25:04.0564 3776 TermDD - ok
17:25:04.0642 3776 [ C468ADABA2040F6585FE04EA4C81984A ] TermService C:\Windows\System32\termsrv.dll
17:25:04.0658 3776 TermService - ok
17:25:04.0689 3776 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:25:04.0689 3776 Themes - ok
17:25:04.0720 3776 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:25:04.0720 3776 THREADORDER - ok
17:25:04.0751 3776 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:25:04.0751 3776 TrkWks - ok
17:25:04.0830 3776 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:25:04.0845 3776 TrustedInstaller - ok
17:25:04.0876 3776 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:25:04.0876 3776 tssecsrv - ok
17:25:04.0923 3776 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:25:04.0923 3776 tunnel - ok
17:25:04.0970 3776 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:25:04.0970 3776 uagp35 - ok
17:25:05.0033 3776 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:25:05.0033 3776 udfs - ok
17:25:05.0200 3776 [ 3F3995FC18827786025F2DC29549960F ] UDisk Monitor C:\Program Files\Cricket Broadband AC3781\AC3781\bin\MonServiceUDisk.exe
17:25:05.0215 3776 UDisk Monitor - ok
17:25:05.0262 3776 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:25:05.0278 3776 UI0Detect - ok
17:25:05.0309 3776 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
17:25:05.0309 3776 uliagpkx - ok
17:25:05.0372 3776 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:25:05.0372 3776 umbus - ok
17:25:05.0418 3776 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:25:05.0418 3776 UmPass - ok
17:25:05.0497 3776 [ 8ECACA5454844F66386F7BE4AE0D7CD1 ] UmRdpService C:\Windows\System32\umrdp.dll
17:25:05.0512 3776 UmRdpService - ok
17:25:05.0559 3776 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:25:05.0575 3776 upnphost - ok
17:25:05.0637 3776 [ C31AE588E403042632DC796CF09E30B0 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:25:05.0653 3776 usbccgp - ok
17:25:05.0762 3776 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
17:25:05.0762 3776 usbcir - ok
17:25:05.0793 3776 [ E4C436D914768CE965D5E659BA7EEBD8 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:25:05.0793 3776 usbehci - ok
17:25:05.0840 3776 [ BDCD7156EC37448F08633FD899823620 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:25:05.0856 3776 usbhub - ok
17:25:05.0872 3776 [ EB2D819A639015253C871CDA09D91D58 ] usbohci C:\Windows\system32\drivers\usbohci.sys
17:25:05.0887 3776 usbohci - ok
17:25:05.0903 3776 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:25:05.0918 3776 usbprint - ok
17:25:05.0981 3776 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:25:05.0981 3776 USBSTOR - ok
17:25:06.0012 3776 [ 22480BF4E5A09192E5E30BA4DDE79FA4 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:25:06.0012 3776 usbuhci - ok
17:25:06.0075 3776 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:25:06.0075 3776 UxSms - ok
17:25:06.0106 3776 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\Windows\system32\lsass.exe
17:25:06.0122 3776 VaultSvc - ok
17:25:06.0153 3776 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
17:25:06.0153 3776 vdrvroot - ok
17:25:06.0202 3776 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
17:25:06.0217 3776 vds - ok
17:25:06.0233 3776 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:25:06.0249 3776 vga - ok
17:25:06.0264 3776 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:25:06.0264 3776 VgaSave - ok
17:25:06.0311 3776 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
17:25:06.0311 3776 vhdmp - ok
17:25:06.0358 3776 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
17:25:06.0358 3776 viaagp - ok
17:25:06.0405 3776 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:25:06.0405 3776 ViaC7 - ok
17:25:06.0436 3776 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
17:25:06.0436 3776 viaide - ok
17:25:06.0467 3776 [ 379B349F65F453D2A6E75EA6B7448E49 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
17:25:06.0467 3776 vmbus - ok
17:25:06.0499 3776 [ EC2BBAB4B84D0738C6C83D2234DC36FE ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
17:25:06.0499 3776 VMBusHID - ok
17:25:06.0530 3776 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
17:25:06.0530 3776 volmgr - ok
17:25:06.0561 3776 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:25:06.0577 3776 volmgrx - ok
17:25:06.0624 3776 [ 59F06B4968E58BC83DFC56CA4517960E ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:25:06.0624 3776 volsnap - ok
17:25:06.0670 3776 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:25:06.0686 3776 vsmraid - ok
17:25:06.0764 3776 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
17:25:06.0780 3776 VSS - ok
17:25:06.0811 3776 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:25:06.0811 3776 vwifibus - ok
17:25:06.0889 3776 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:25:06.0889 3776 W32Time - ok
17:25:06.0936 3776 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:25:06.0936 3776 WacomPen - ok
17:25:06.0983 3776 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:25:06.0983 3776 WANARP - ok
17:25:06.0999 3776 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:25:06.0999 3776 Wanarpv6 - ok
17:25:07.0092 3776 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:25:07.0124 3776 WatAdminSvc - ok
17:25:07.0233 3776 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
17:25:07.0249 3776 wbengine - ok
17:25:07.0295 3776 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:25:07.0295 3776 WbioSrvc - ok
17:25:07.0358 3776 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:25:07.0374 3776 wcncsvc - ok
17:25:07.0436 3776 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:25:07.0436 3776 WcsPlugInService - ok
17:25:07.0467 3776 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:25:07.0483 3776 Wd - ok
17:25:07.0561 3776 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:25:07.0577 3776 Wdf01000 - ok
17:25:07.0608 3776 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:25:07.0608 3776 WdiServiceHost - ok
17:25:07.0624 3776 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:25:07.0639 3776 WdiSystemHost - ok
17:25:07.0686 3776 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\Windows\System32\webclnt.dll
17:25:07.0702 3776 WebClient - ok
17:25:07.0733 3776 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:25:07.0749 3776 Wecsvc - ok
17:25:07.0811 3776 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:25:07.0827 3776 wercplsupport - ok
17:25:07.0858 3776 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:25:07.0858 3776 WerSvc - ok
17:25:07.0905 3776 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:25:07.0905 3776 WfpLwf - ok
17:25:07.0920 3776 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:25:07.0936 3776 WIMMount - ok
17:25:08.0014 3776 [ 5EA185425BFCBC2D4B96D673D8C4DEAF ] winachsf C:\Windows\system32\DRIVERS\HSF_CNXT.sys
17:25:08.0030 3776 winachsf - ok
17:25:08.0148 3776 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:25:08.0168 3776 WinDefend - ok
17:25:08.0197 3776 WinHttpAutoProxySvc - ok
17:25:08.0288 3776 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:25:08.0293 3776 Winmgmt - ok
17:25:08.0390 3776 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
17:25:08.0424 3776 WinRM - ok
17:25:08.0518 3776 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:25:08.0540 3776 Wlansvc - ok
17:25:08.0580 3776 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
17:25:08.0582 3776 WmiAcpi - ok
17:25:08.0622 3776 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:25:08.0625 3776 wmiApSrv - ok
17:25:08.0750 3776 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:25:08.0778 3776 WMPNetworkSvc - ok
17:25:08.0813 3776 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:25:08.0819 3776 WPCSvc - ok
17:25:08.0846 3776 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:25:08.0851 3776 WPDBusEnum - ok
17:25:08.0872 3776 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:25:08.0874 3776 ws2ifsl - ok
17:25:08.0920 3776 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\Windows\system32\wscsvc.dll
17:25:08.0926 3776 wscsvc - ok
17:25:08.0941 3776 WSearch - ok
17:25:09.0071 3776 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:25:09.0117 3776 wuauserv - ok
17:25:09.0179 3776 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:25:09.0179 3776 WudfPf - ok
17:25:09.0226 3776 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:25:09.0242 3776 WUDFRd - ok
17:25:09.0304 3776 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:25:09.0304 3776 wudfsvc - ok
17:25:09.0382 3776 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:25:09.0398 3776 WwanSvc - ok
17:25:09.0445 3776 [ 0032C7CD295FB084862785F219970329 ] ztemtusbser C:\Windows\system32\DRIVERS\CT_ZTEMT_U_USBSER.sys
17:25:09.0445 3776 ztemtusbser - ok
17:25:09.0492 3776 ================ Scan global ===============================
17:25:09.0554 3776 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
17:25:09.0585 3776 [ A9E43C040F405DB689FC29534EF0389B ] C:\Windows\system32\winsrv.dll
17:25:09.0617 3776 [ A9E43C040F405DB689FC29534EF0389B ] C:\Windows\system32\winsrv.dll
17:25:09.0648 3776 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:25:09.0710 3776 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:25:09.0710 3776 [Global] - ok
17:25:09.0726 3776 ================ Scan MBR ==================================
17:25:09.0742 3776 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:25:10.0304 3776 \Device\Harddisk0\DR0 - ok
17:25:10.0320 3776 ================ Scan VBR ==================================
17:25:10.0320 3776 [ 93034D8FE7DC50B27EAB2EC16691664C ] \Device\Harddisk0\DR0\Partition1
17:25:10.0320 3776 \Device\Harddisk0\DR0\Partition1 - ok
17:25:10.0335 3776 [ 7463D3B00FA122C486D39FD9ADACCBBF ] \Device\Harddisk0\DR0\Partition2
17:25:10.0335 3776 \Device\Harddisk0\DR0\Partition2 - ok
17:25:10.0335 3776 ============================================================
17:25:10.0335 3776 Scan finished
17:25:10.0335 3776 ============================================================
17:25:10.0367 3532 Detected object count: 0
17:25:10.0367 3532 Actual detected object count: 0
Download and Install Combofix
Download
ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your
Desktop
*
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
Double click on ComboFix.exe & follow the prompts.
When finished, it shall produce a log for you.
Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Computer is running much better. I had piddled with it before turning to WTT, and it did seem to improve quite a bit. However, the MBam scan kept hanging up, and the Hijackthis scan still had what to me looked like questionable entries so I thought it best to ask for help in making sure it was really clean.
ComboFix 12-12-27.03 - Chris 12/27/2012 21:37:16.2.1 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.1014.545 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2012-11-28 to 2012-12-28 )))))))))))))))))))))))))))))))
.
.
2012-12-28 05:45 . 2012-12-28 05:45 โโโ dโโw- c:\users\Default\AppData\Local\temp
2012-12-28 01:19 . 2012-11-08 18:00 6812136 โ-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{14A5CE5D-C15C-4BEE-8896-07C096C1599D}\mpengine.dll
2012-12-27 04:11 . 2012-12-27 04:11 โโโ dโโw- c:\program files\CCleaner
2012-12-27 01:47 . 2012-12-16 14:25 295424 โ-a-w- c:\windows\system32\atmfd.dll
2012-12-27 01:47 . 2012-12-16 14:25 34304 โ-a-w- c:\windows\system32\atmlib.dll
2012-12-27 00:55 . 2012-11-08 18:00 6812136 โ-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-12-26 22:29 . 2012-11-09 04:49 2048 โ-a-w- c:\windows\system32\tzres.dll
2012-12-26 22:13 . 2012-12-26 22:13 388096 โ-a-r- c:\users\Chris\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-12-26 22:13 . 2012-12-26 22:13 โโโ dโโw- c:\program files\Trend Micro
2012-12-26 02:19 . 2012-12-27 15:00 40776 โ-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-12-26 01:18 . 2012-12-26 01:18 31560 โ-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2012-12-25 23:15 . 2012-12-25 23:15 โโโ dโโw- C:\7e3275a5fbad84e9cfbb825a5bc28e
2012-12-25 23:14 . 2012-12-25 23:14 โโโ dโโw- c:\users\Chris\AppData\Roaming\Malwarebytes
2012-12-25 23:14 . 2012-12-25 23:14 โโโ dโโw- c:\programdata\Malwarebytes
2012-12-25 23:14 . 2012-12-25 23:14 โโโ dโโw- c:\program files\Malwarebytes' Anti-Malware
2012-12-25 23:14 . 2012-09-30 03:54 22856 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-12-25 21:45 . 2009-07-14 01:14 49152 -cโ-w- c:\programdata\Microsoft\Windows\WER\ReportQueue\AppCrash_MsMpEng.exe_c297628e14506b9a4cd538cc45b546b1c3562f8_cab_09df58a0\taskhost.exe
2012-12-16 22:17 . 2012-12-22 09:43 โโโ dโโw- c:\windows\system32\MpEngineStore
2012-12-12 18:02 . 2012-12-18 17:03 โโโ dโโw- c:\users\Chris\AppData\Local\ElevatedDiagnostics
2012-12-10 21:11 . 2012-12-10 21:11 โโโ dโโw- C:\inetpub
2012-12-10 12:43 . 2012-12-10 12:43 โโโ dโโw- c:\users\Chris\AppData\Roaming\searchresultstb
2012-12-10 12:43 . 2012-12-10 12:43 โโโ dโโw- c:\users\Chris\AppData\Roaming\ilividtoolbarguid
2012-12-10 12:39 . 2012-12-12 19:52 โโโ dโโw- c:\users\Chris\AppData\Roaming\ZTEEVDO
2012-12-10 12:39 . 2012-12-10 12:39 โโโ dโโw- c:\users\Chris\AppData\Roaming\ZteUpdateUI
2012-12-10 12:39 . 2012-12-10 12:39 โโโ dโโw- C:\ZTEEVDOAutoRun
2012-12-10 12:38 . 2012-02-28 18:21 182272 โ-a-w- c:\windows\system32\drivers\CT_ZTEMT_U_USBNET.SYS
2012-12-10 12:38 . 2012-02-28 18:21 105472 โ-a-w- c:\windows\system32\drivers\CT_ZTEMT_U_USBSER.sys
2012-12-10 12:38 . 2012-02-28 18:22 24192 โ-a-w- c:\windows\system32\drivers\tcpipBM.sys
2012-12-10 12:38 . 2012-02-28 18:22 13712 โ-a-w- c:\windows\system32\sporder.dll
2012-12-10 12:38 . 2012-02-28 18:22 13184 โ-a-w- c:\windows\system32\drivers\BMLoad.sys
2012-12-10 12:38 . 2012-02-28 18:22 724608 โ-a-w- c:\windows\system32\bmutil.dll
2012-12-10 12:38 . 2012-02-28 18:22 480384 โ-a-w- c:\windows\system32\bmnet.dll
2012-12-10 12:38 . 2012-02-28 18:22 312448 โ-a-w- c:\windows\system32\bminstall.dll
2012-12-10 12:38 . 2012-02-28 18:22 132224 โ-a-w- c:\windows\system32\bmdumpd.bin
2012-12-10 12:38 . 2012-12-10 12:38 โโโ dโโw- c:\program files\Cricket Broadband AC3781
2012-12-10 11:24 . 2012-12-27 04:12 โโโ dcโ-w- c:\users\Chris\AppData\Local\MigWiz
2012-12-09 14:21 . 2012-12-09 14:21 โโโ dโโw- C:\b6c06dbed4e20ad14bb34519702c04
2012-12-08 22:22 . 2012-12-08 22:22 โโโ dโโw- C:\BigFishGamesCache
2012-12-08 06:26 . 2012-12-08 06:26 โโโ dโโw- c:\program files\SaveValet
2012-12-06 22:14 . 2012-12-27 06:03 โโโ dโโw- c:\program files\Haali
2012-12-06 22:05 . 2012-12-27 06:04 โโโ dโโw- c:\users\Chris\AppData\Roaming\PerformerSoft
2012-12-06 22:03 . 2012-12-27 06:08 โโโ dโโw- c:\programdata\Tarma Installer
2012-12-06 22:02 . 2012-12-06 22:02 โโโ dโโw- c:\program files\File Scout
2012-12-04 06:42 . 2012-12-04 06:42 โโโ dโโw- c:\users\Chris\AppData\Roaming\DriverCure
2012-12-04 06:42 . 2012-12-04 06:42 โโโ dโโw- c:\users\Chris\AppData\Roaming\PC Utility Kit
2012-12-04 06:42 . 2012-12-04 19:11 โโโ dโโw- c:\programdata\PC Utility Kit
2012-12-03 10:33 . 2012-12-26 23:10 73656 โ-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-03 10:33 . 2012-12-26 23:10 697272 โ-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-12-03 10:33 . 2012-12-03 10:33 โโโ dโโw- c:\windows\system32\Macromed
2012-12-03 09:59 . 2012-12-03 10:00 โโโ dโโw- c:\program files\Ask.com
2012-12-03 09:58 . 2012-12-03 09:58 โโโ dโโw- c:\users\Chris\AppData\Local\APN
2012-12-03 09:58 . 2012-12-03 09:58 โโโ dโโw- c:\users\Chris\AppData\Roaming\Sammsoft
2012-12-03 00:27 . 2012-12-03 00:27 โโโ dโโw- c:\users\Chris\AppData\Local\Programs
2012-12-03 00:23 . 2012-12-03 00:23 โโโ dโโw- c:\program files\Microsoft.NET
2012-12-02 18:19 . 2012-12-03 06:59 โโโ dโโw- c:\users\Chris\AppData\Local\Torch
2012-12-02 18:18 . 2012-12-02 18:18 โโโ dโโw- c:\program files\Common Files\Java
2012-12-02 18:17 . 2012-12-02 18:14 746984 โ-a-w- c:\windows\system32\deployJava1.dll
2012-12-02 18:17 . 2012-12-02 18:14 821736 โ-a-w- c:\windows\system32\npDeployJava1.dll
2012-12-02 18:16 . 2012-12-02 18:14 93672 โ-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-12-02 18:15 . 2012-06-27 19:26 773968 โ-a-w- c:\windows\system32\msvcr100.dll
2012-12-02 18:13 . 2012-12-02 18:13 โโโ dโโw- c:\program files\Java
2012-12-02 17:26 . 2012-12-02 17:26 โโโ dโโw- c:\programdata\McAfee
2012-12-02 10:43 . 2012-12-02 10:42 740840 โโw- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9AE13FAF-A47A-4059-9184-D82C3D6C764C}\gapaengine.dll
2012-12-02 10:21 . 2012-12-02 10:21 โโโ dโโw- c:\users\Chris\AppData\Roaming\PCCUStubInstaller
2012-12-02 10:19 . 2012-12-12 18:45 โโโ dโโw- c:\programdata\Norton
2012-12-02 04:59 . 2012-12-11 05:37 โโโ dโโw- c:\programdata\boost_interprocess
2012-12-02 04:57 . 2012-12-02 04:57 โโโ dโโw- c:\users\Chris\AppData\Roaming\Cricket Broadband AC3781
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-27 12:01 . 2012-11-27 12:02 740784 โโw- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-10-16 20:34 . 2012-11-29 23:49 559104 โ-a-w- c:\windows\apppatch\AcLayers.dll
.
.
โโ- Sigcheck โโ-
Note: Unsigned files aren't necessarily malware.
.
[7] 2010-11-20 . 382C804C92811BE57829D8E550A900E2 . 521216 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.1.7601.17514_none_90a6abb3b286306d\termsrv.dll
[-] 2009-10-13 . C468ADABA2040F6585FE04EA4C81984A . 543232 . . [6.1.7600.16385] . . c:\windows\System32\termsrv.dll
[-] 2009-10-13 . C468ADABA2040F6585FE04EA4C81984A . 543232 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.1.7600.16385_none_8e7597ebb597acd3\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 947176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2012-06-08 02:33 421776 โ-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2012-08-09 11:35 296096 โ-a-w- c:\program files\Real\RealPlayer\Update\realsched.exe
.
R1 MpKsl8cef4730;MpKsl8cef4730;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12AF9B57-D045-4C57-BCD2-6183ED580BF2}\MpKsl8cef4730.sys [x]
R1 MpKslc2282ffa;MpKslc2282ffa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{12AF9B57-D045-4C57-BCD2-6183ED580BF2}\MpKslc2282ffa.sys [x]
R2 UDisk Monitor;UDisk Monitor;c:\program files\Cricket Broadband AC3781\AC3781\bin\MonServiceUDisk.exe [x]
R3 CT_ZTEMT_U_USBNET;ZTEMT USB-NDIS miniport;c:\windows\system32\DRIVERS\CT_ZTEMT_U_USBNET.SYS [x]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 ztemtusbser;ZTEMT Legacy Serial Communication;c:\windows\system32\DRIVERS\CT_ZTEMT_U_USBSER.sys [x]
S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [x]
S2 FpHidSrv;FinePoint Tablet Service;FpHidSrv.exe [x]
S3 FinePnt;FinePoint Innovations HID Driver;c:\windows\system32\DRIVERS\FpHidDrv.sys [x]
S3 MSTabBtn;Quanta Computer Tablet PC Buttons HID Driver;c:\windows\system32\DRIVERS\mstabbtn.sys [x]
S3 NETw2v32;Intelยฎ PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-12-03 23:10]
.
2012-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-09 11:27]
.
2012-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-08-09 11:27]
.
2012-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3805464660-3371822181-1644447673-1000Core.job
- c:\users\Chris\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-08 01:44]
.
2012-12-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3805464660-3371822181-1644447673-1000UA.job
- c:\users\Chris\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-08 01:44]
.
.
โโ- Supplementary Scan โโ-
.
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{23B9AF9F-1EE1-4F80-AAFF-5ADB1F3F73CC}: NameServer = 192.168.1.1
TCP: Interfaces\{63A10AE0-3CB1-416C-B1D8-8DAFC5BFFFFB}: NameServer = 10.133.20.11 10.132.20.11
TCP: Interfaces\{6F8ECB1F-0B12-412C-9628-A515C93F267A}: NameServer = 10.133.20.11
TCP: Interfaces\{812CB92E-6997-437B-9EBA-C582EAA921AA}: NameServer = 192.168.33.1,205.171.3.25,205.171.2.25
.
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-12-27 21:48:07
ComboFix-quarantined-files.txt 2012-12-28 05:48
ComboFix2.txt 2012-12-27 07:45
.
Pre-Run: 38,433,239,040 bytes free
Post-Run: 38,397,980,672 bytes free
.
- - End Of File - - 250BA7CC16E35E7938BEF33327BA86A3
Well, that didn't remove anything so you must have done a pretty good job of getting things cleaned up so far. There can be many reasons security programs stall out.
MBAM just released a new version today. Let's go ahead and try to update the program and then give it a whirl now. (That new version # is 1.70). If it won't run, move ahead to the ESET scan and just let me know MBAM still won't run.
I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing
Run as Administrator on the icon on the desktop.
Click on the tab labeled Update and then click on the button Check for updates . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform quick scan , then click Scan .
[external image: Posted Image] When the scan is complete, click OK , then Show Results to view the results. Be sure that everything is checked , and click Remove Selected . When completed, a log will open in Notepad. Please save it to a convenient location and post the results. Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.
Go
here to run an online scannner from ESET.
Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open. Turn off the real time scanner of any existing antivirus program while performing the online scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activex control to install Click Start Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked. Click on Advanced Settings, ensure the options Scan for potentially unwanted applications , Scan for potentially unsafe applications , and Enable Anti-Stealth Technology are ticked. Click Scan Wait for the scan to finish Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt Copy and paste that log as a reply to this topic and also let me know how things are now.
If it doesn't find anything there will be no log to post.
AhhโฆI forgot. I was able to successfully run Mbam once on quick scan mode. It's the longer scan that kept hanging up when it got to "c:\windows\softwaredistribution/downloadโฆ.." about 45 minutes into the scan. It did find 5 objects to be removed. After that, picking thru a HJT log, and a few other things the hijacking stopped and it did start to run much better. Love the new look of the MBam lol.
Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org
Database version: v2012.12.28.09
Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
Chris :: CHRIS-PC [administrator]
12/28/2012 9:08:05 AM
mbam-log-2012-12-28 (09-08-05).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 194331
Time elapsed: 5 minute(s), 45 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
Fantastic! Actually, there is no need to run a full scan with Malwarebytes. I read an
interview with the creator of MBAM and the only reason it is included as an option is for those people who don't believe that a full scan will catch everything. That will save you a lot of time in the future.
Were you able to run the ESET scan? I wasn't sure if you did and it was clear or if you haven't done that yet.
I forgot to run ESET. When I tried running it a few minutes ago, I got an 'Unexpected error 2002.'
In your attach.txt I believe you already had a version of the ESET online scanner installed. Please go to Control Panel > Programs & Features and uninstall the one that shows in the installed programs. Then try following the instructions again. See if that helps.
I've tried to run eset twice, but each time windows shuts down about an hour into the scan about 1/2 way thru and reboots. I don't think it's hardware or temp related. i've checked for eset logs in case it finished while i wasn't looking, but have found none. Just in case where would they be located?
An ESET log would be located at C:\Program Files\Eset\Eset Online Scanner\log.txt
The fact that it's actually rebooting the machine is extremely odd. Below are two other options for online scanners, please pick
one and give it a try.
Kaspersky Virus Removal Tool
The Kaspersky Virus Removal Tool is a scan-and-remove solution from Kaspersky that searches out the most common malware and attempts to remove it from your computer.
Please download the Kaspersky Virus Removal Tool from
Kaspersky's Official Link and save it to your Desktop.
Double-click the Setup file to install it on your computer. Once it has installed, review and accept the agreement and press the Start button. You will presented with the main interface, but don't scan yet, click the options tab (gear icon):
[external image: Posted Image] On the Scan Scope tab, make sure to checkmark all the options, except for the CD/DVD drive:
[external image: Posted Image] On the Security Level tab, make sure to move the slider up denoting "Current Security Level: High "
[external image: Posted Image] Now, go back to the Automatic Scan tab, and choose "Start Scanning". It may take several hours to complete. Please allow it to do so. Once done scanning, choose the Report tab (page icon), select Detected Threats tab on left, and choose Disinfect All:
[external image: Posted Image] Then, choose Save. Also, in the Automatic Report tab, select Save:
[external image: Posted Image] Please post the reports in your next reply. Once you exit, the tool should uninstall automatically.
Run an Online Anti-Virus Scan .
Perform an online scan with Internet Explorer with
Panda ActiveScan
Once you are on the Panda site click the Scan your PC button A new window will openโฆclick the Check Now button Click the big Scan Now button If it wants to install an ActiveX component allow it It will start downloading the files it requires for the scan (Note: It may take a couple of minutes) When download is complete, it should start to scan automatically When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop. Post the report in your next reply.
Note: Turn off the real time scanner of any existing antivirus program while performing the online scan
yes, it is odd. Could it be a hardware issue? It wouldn't explain a reboot though. Could there be a setting in the BIOS prompting an auto reboot after shutdown due to temp or hardware issues? Also, like I mentioned, before I sought help it was freezing up on MBam and Combofix and I now recall a BSoD a couple of times. This is my ex's computer so I'm not sure of it's normal operating quirks. In addition to the latest scans you've requested, I'm going to run the hell out of this machine to see if I can cause it to shut down and reboot, or something similar.
Yes, it could be a hardware issue. It might be overheating from use (or it could just need a good cleaning. Dust and dirt can cause this too.) I'm not sure about BIOS settings for hardware issues and reboot - that would be a question for our Windows forum.
As for "running the hell out of the machine" to try and duplicate the issueโฆ.you sound a lot like the people here that like to help others on the board. We don't like to give up until we've figured it out LOL. You've actually done a very good job cleaning up the items you originally had issues with. If you enjoy this kind of "detective work" and research to find and eliminate malware and have the time and desire to learn how to help others, you might want to consider our
malware classroom .
As for the scans - just pick one. If you still can't get them to run, I'm not terribly worried about it. Your machine seems to be malware free, I just like to do an online scan as a double check. But they are resource intensive and if your machine has an overheating problem, it definitely could cause it to max out and crash. Don't worry about it if the other scans won't work - just let me know and we'll go ahead and clean up tools.
Well, tried to run Kaspersky with the same result. It shut down about two hours in. It's running great though, so I'm good to go if you think it's ok to go ahead and finish up.