Tech Support Forum banner
Status
Not open for further replies.

Other can access my ip address to login to different accounts

1K views 6 replies 2 participants last post by  chemist 
#1 ·
I've been notified that I had 3 different accounts login to a site but I only use 1 account. I feel that I've been used as socks. Please check if there are viruses, trojans and malwares. In addition, I feel that I have been ratted by looking at the start up. Lastly, I don't have any Windows Install disc or BOOT CD. Thanks for your time :)

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.3.1
Run by badong at 2:23:36 on 2012-04-09
Microsoft Windows 7 Home Basic 6.1.7601.0.1252.1.1033.18.4095.1262 [GMT 8:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Windows\system32\taskeng.exe
C:\Users\badong\AppData\Local\Akamai\netsession_win.exe
C:\Users\badong\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
C:\Users\badong\Local Settings\Apps\F.lux\flux.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Users\badong\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Users\badong\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler64.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
svchost.exe
svchost.exe
svchost.exe
C:\Windows\system32\wuauclt.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Users\badong\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uWindow Title = Microsoft Internet Explorer
mStart Page = hxxp://www.bigseekpro.com/bsprpc/{D1B464FB-0E4E-4B90-9D1C-BF18DEEB8F15}
uInternet Settings,ProxyServer = socks=173.67.103.56:1010
uInternet Settings,ProxyOverride = <local>
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB: {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [Akamai NetSession Interface] "C:\Users\badong\AppData\Local\Akamai\netsession_win.exe"
uRun: [Google Update] "C:\Users\badong\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRun: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\badong\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\badong\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
LSP: %SystemRoot%\system32\PrxerDrv.dll
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 8.8.8.8 202.57.96.3 121.1.3.81
TCP: Interfaces\{D21F9C98-09F2-448D-B94B-F0563E2FCF97} : DhcpNameServer = 8.8.8.8 202.57.96.3 121.1.3.81
TCP: Interfaces\{D21F9C98-09F2-448D-B94B-F0563E2FCF97}\05C44445D4974435C435F6279616E6F6 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D21F9C98-09F2-448D-B94B-F0563E2FCF97}\3656E64756E6F6 : DhcpNameServer = 124.106.5.2 124.106.6.2
TCP: Interfaces\{D21F9C98-09F2-448D-B94B-F0563E2FCF97}\45164747F6F6 : DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{D21F9C98-09F2-448D-B94B-F0563E2FCF97}\C696E6B6379737 : DhcpNameServer = 8.8.4.4 124.106.5.2
TCP: Interfaces\{E3023E7A-C0D8-4AFF-B9A5-E784A9754337} : DhcpNameServer = 10.92.96.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
BHO-X64: 0x1 - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO-X64: Search Helper - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO-X64: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
BHO-X64: Ask Toolbar BHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll
BHO-X64: Hotspot Shield Class: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE.dll
BHO-X64: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
TB-X64: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll
TB-X64: {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB-X64: Avira SearchFree Toolbar plus Web Protection: {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRun-x64: [Trend Micro RUBotted V2.0 Beta] C:\Program Files (x86)\Trend Micro\RUBotted\RUBottedGUI.exe
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
Hosts: 127.94.0.1 client.openvpn.net
Hosts: 127.94.0.1 client.openvpn.net
Hosts: 127.94.0.5 openvpn-client.us.shieldexchange.com
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 AFBAgent;AFBAgent;"C:\Windows\system32\FBAgent.exe" --> C:\Windows\system32\FBAgent.exe [?]
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 20992]
R2 ASMMAP64;ASMMAP64;C:\Program Files\ATKGFNEX\ASMMAP64.sys [2009-12-22 14904]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-3-9 44768]
R2 hshld;Hotspot Shield Service;C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe [2012-3-27 542040]
R2 HssWd;Hotspot Shield Monitoring Service;C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS --> C:\Program Files (x86)\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-11-6 366152]
R2 OberonGameConsoleService;Oberon Media Game Console service;C:\Program Files (x86)\ASUS\Game Park\GameConsole\OberonGameConsoleService.exe [2009-12-22 44312]
R2 RUBotSrv;Trend Micro RUBotted Service;C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe [2012-3-9 439632]
R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys --> C:\Windows\system32\DRIVERS\ETD.sys [?]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys --> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-3-22 163480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-7-30 136176]
S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-7-30 136176]
S3 Revoflt;Revoflt;C:\Windows\system32\DRIVERS\revoflt.sys --> C:\Windows\system32\DRIVERS\revoflt.sys [?]
S3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys --> C:\Windows\system32\DRIVERS\SiSG664.sys [?]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys --> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 TmProxy;Trend Micro Proxy Service; [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;C:\Windows\system32\DRIVERS\vwifimp.sys --> C:\Windows\system32\DRIVERS\vwifimp.sys [?]
.
=============== Created Last 30 ================
.
2012-04-08 15:06:58 561992 ----a-w- C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com\components\afurladvisor90.dll
2012-04-08 15:06:08 -------- d-----w- C:\ProgramData\Hotspot Shield
2012-04-08 15:05:58 -------- d-----w- C:\Hotspot Shield
2012-04-08 15:05:19 -------- d-----w- C:\Program Files (x86)\Hotspot Shield
2012-04-07 20:04:44 -------- d-----r- C:\Sandbox
2012-04-07 19:04:38 -------- d-----w- C:\Program Files\Unlocker
2012-04-07 19:02:05 -------- d-----w- C:\Program Files (x86)\Unlocker
2012-04-07 18:55:13 -------- d-----w- C:\Program Files (x86)\FileASSASSIN
2012-04-07 07:59:36 8669240 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FD44936F-E4F3-42A0-9702-1FE6B662028C}\mpengine.dll
2012-04-03 20:40:50 -------- d-----w- C:\Program Files (x86)\Captch Sniper
2012-04-03 20:12:33 -------- d-----w- C:\Users\badong\AppData\Roaming\UBot Studio
2012-04-03 04:48:51 -------- d-----w- C:\Users\badong\AppData\Local\{6E37C267-E80E-49C1-AE1D-E0436D957C06}
2012-03-26 21:45:18 56832 ----a-w- C:\Windows\System32\drivers\HssDrv.sys
2012-03-23 10:53:30 -------- d-----w- C:\Users\badong\AppData\Local\{62676290-6D20-43F5-969A-AC07363057CF}
2012-03-23 10:53:14 -------- d-----w- C:\Users\badong\AppData\Local\{52A63E58-4D2A-4770-8EF6-329B500F4A12}
2012-03-18 11:19:29 -------- d-----w- C:\Windows\System32\%LOCALAPPDATA%
2012-03-14 09:54:15 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-14 09:54:13 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-14 09:54:12 3913584 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-14 09:42:11 634880 ----a-w- C:\Windows\System32\msvcrt.dll
2012-03-14 09:42:10 690688 ----a-w- C:\Windows\SysWow64\msvcrt.dll
2012-03-14 09:42:00 509952 ----a-w- C:\Windows\System32\ntshrui.dll
2012-03-14 09:42:00 442880 ----a-w- C:\Windows\SysWow64\ntshrui.dll
2012-03-12 18:54:18 -------- d-----w- C:\Program Files (x86)\IconChanger
2012-03-12 11:46:31 -------- d-----w- C:\Program Files (x86)\Glarysoft
2012-03-10 08:35:12 -------- d-----w- C:\Program Files (x86)\Oracle
2012-03-10 08:32:03 637848 ----a-w- C:\Windows\SysWow64\npdeployJava1.dll
2012-03-10 06:03:53 -------- d-----w- C:\Users\badong\AppData\Roaming\JAM Software
.
==================== Find3M ====================
.
2012-03-23 17:20:18 45056 ----a-w- C:\Windows\System32\acovcnt.exe
2012-03-07 00:15:19 41184 ----a-w- C:\Windows\avastSS.scr
2012-03-07 00:04:06 819032 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2012-03-07 00:02:20 53080 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys
2012-03-07 00:01:52 69976 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-03-05 00:26:06 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-23 01:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe
2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll
2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys
2012-02-02 17:43:55 185 ----a-w- C:\Windows\SysWow64\msblcd32.dll
2012-02-02 17:43:21 124688 ----a-w- C:\Windows\SysWow64\Mswinsck.ocx
2012-01-26 04:28:42 1015808 ----a-w- C:\Windows\SysWow64\libeay32.dll
2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-01-22 11:21:50 1700352 ----a-w- C:\Windows\SysWow64\gdiplus.dll
2012-01-22 11:21:50 1060864 ----a-w- C:\Windows\SysWow64\mfc71.dll
2012-01-10 05:57:10 567696 ----a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 2:27:17.52 ===============
 

Attachments

See less See more
#2 ·
Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please download aswMBR.exe to your desktop.
  • Double-click aswMBR.exe to run it.
  • Click the Scan button to start scan.
  • Wait until it says, 'Scan finished successfully'. (Note - do not select any Fix at this time)
  • Click Save log, and save it to your desktop.
  • Click Exit.
  • Please post the contents of that log, aswMBR.txt, in your next reply.
There shall also be a file on your desktop named MBR.dat. Right-click that file and select Send To > Compressed (zipped) folder. Please attach that zipped file in your next reply.

------------------------------------------------------

When you run this tool, remember to choose 'Skip' not 'Cure' if it finds something. We just want a scan, not a fix.

Download tdsskiller.exe and Save it to your Desktop.

Double-click tdsskiller.exe and click 'Run'

Click 'Change parameters' then under 'Additional options' tick both boxes > OK.

Click 'Start scan'.

If no infection is found, click 'Close' and let me know.

If an infection is found, select 'Skip' from the dropdown menu under 'Cure' then click 'Continue' > 'Close' > 'Close'.

It will produce a log here > C:\TDSSKiller.2.7.26.0_date_time_log.txt

Please navigate to the file, double-click to open it, and copy/paste the contents in your next reply.

------------------------------------------------------
 
#3 ·
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-04-12 05:26:39
-----------------------------
05:26:39.187 OS Version: Windows x64 6.1.7601
05:26:39.187 Number of processors: 2 586 0x170A
05:26:39.188 ComputerName: BADONG-PC UserName: badong
05:26:40.341 Initialize success
05:26:40.471 AVAST engine defs: 12041100
05:27:21.821 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007a
05:27:21.836 Disk 0 Vendor: ST932032 0002 Size: 305245MB BusType: 3
05:27:21.852 Disk 0 MBR read successfully
05:27:21.852 Disk 0 MBR scan
05:27:21.868 Disk 0 Windows VISTA default MBR code
05:27:21.868 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 15000 MB offset 2048
05:27:21.899 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 76311 MB offset 30722048
05:27:21.899 Disk 0 Partition - 00 0F Extended LBA 213932 MB offset 187006976
05:27:21.930 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 213931 MB offset 187009024
05:27:21.969 Disk 0 scanning C:\Windows\system32\drivers
05:27:33.540 Service scanning
05:27:58.139 Modules scanning
05:27:58.153 Disk 0 trace - called modules:
05:27:58.226 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys
05:27:58.235 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80041fa790]
05:27:58.244 3 CLASSPNP.SYS[fffff88001b9943f] -> nt!IofCallDriver -> [0xfffffa8003694e40]
05:27:58.250 5 ACPI.sys[fffff88000f527a1] -> nt!IofCallDriver -> \Device\0000007a[0xfffffa80040af250]
05:27:58.959 AVAST engine scan C:\Windows
05:28:02.008 AVAST engine scan C:\Windows\system32
05:32:18.572 AVAST engine scan C:\Windows\system32\drivers
05:32:32.574 AVAST engine scan C:\Users\badong
05:41:02.225 AVAST engine scan C:\ProgramData
05:42:35.976 Scan finished successfully
05:43:06.534 Disk 0 MBR has been saved successfully to "C:\Users\badong\Desktop\MBR.dat"
05:43:06.540 The log file has been saved successfully to "C:\Users\badong\Desktop\aswMBR.txt"
 

Attachments

#4 ·
05:29:37.0151 4652 TDSS rootkit removing tool 2.7.28.0 Apr 10 2012 16:54:05
05:29:38.0031 4652 ============================================================
05:29:38.0031 4652 Current date / time: 2012/04/12 05:29:38.0031
05:29:38.0031 4652 SystemInfo:
05:29:38.0031 4652
05:29:38.0031 4652 OS Version: 6.1.7601 ServicePack: 0.0
05:29:38.0031 4652 Product type: Workstation
05:29:38.0031 4652 ComputerName: BADONG-PC
05:29:38.0032 4652 UserName: badong
05:29:38.0032 4652 Windows directory: C:\Windows
05:29:38.0032 4652 System windows directory: C:\Windows
05:29:38.0032 4652 Running under WOW64
05:29:38.0032 4652 Processor architecture: Intel x64
05:29:38.0032 4652 Number of processors: 2
05:29:38.0032 4652 Page size: 0x1000
05:29:38.0032 4652 Boot type: Normal boot
05:29:38.0032 4652 ============================================================
05:29:40.0242 4652 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
05:29:40.0258 4652 \Device\Harddisk0\DR0:
05:29:40.0289 4652 MBR used
05:29:40.0289 4652 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x1D4C800, BlocksNum 0x950B800
05:29:40.0305 4652 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xB258800, BlocksNum 0x1A1D5800
05:29:40.0525 4652 Initialize success
05:29:40.0525 4652 ============================================================
05:29:57.0240 5708 ============================================================
05:29:57.0240 5708 Scan started
05:29:57.0240 5708 Mode: Manual; SigCheck; TDLFS;
05:29:57.0240 5708 ============================================================
05:29:58.0966 5708 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\DRIVERS\1394ohci.sys
05:29:59.0122 5708 1394ohci - ok
05:29:59.0239 5708 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\DRIVERS\ACPI.sys
05:29:59.0276 5708 ACPI - ok
05:29:59.0312 5708 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\DRIVERS\acpipmi.sys
05:29:59.0347 5708 AcpiPmi - ok
05:29:59.0468 5708 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
05:29:59.0511 5708 adp94xx - ok
05:29:59.0673 5708 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
05:29:59.0699 5708 adpahci - ok
05:29:59.0851 5708 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
05:29:59.0881 5708 adpu320 - ok
05:30:00.0100 5708 ADSMService (c0bf554d2277f7a4c735d475ade2e3b2) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
05:30:00.0145 5708 ADSMService ( UnsignedFile.Multi.Generic ) - warning
05:30:00.0145 5708 ADSMService - detected UnsignedFile.Multi.Generic (1)
05:30:00.0410 5708 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
05:30:00.0472 5708 AeLookupSvc - ok
05:30:00.0644 5708 AFBAgent (fb2be0bae9b3f248080cdbf91ef16c7f) C:\Windows\system32\FBAgent.exe
05:30:00.0695 5708 AFBAgent - ok
05:30:00.0828 5708 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
05:30:00.0869 5708 AFD - ok
05:30:00.0999 5708 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
05:30:01.0019 5708 agp440 - ok
05:30:01.0310 5708 Akamai (1125c7d9fb8898015829c387c1bc87c7) c:\program files (x86)\common files\akamai/netsession_win_6c825ce.dll
05:30:01.0420 5708 Suspicious file (Hidden): c:\program files (x86)\common files\akamai/netsession_win_6c825ce.dll. md5: 1125c7d9fb8898015829c387c1bc87c7
05:30:01.0430 5708 Akamai ( HiddenFile.Multi.Generic ) - warning
05:30:01.0431 5708 Akamai - detected HiddenFile.Multi.Generic (1)
05:30:01.0551 5708 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
05:30:01.0585 5708 ALG - ok
05:30:01.0698 5708 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
05:30:01.0730 5708 aliide - ok
05:30:01.0792 5708 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
05:30:01.0823 5708 amdide - ok
05:30:02.0010 5708 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
05:30:02.0042 5708 AmdK8 - ok
05:30:02.0104 5708 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
05:30:02.0135 5708 AmdPPM - ok
05:30:02.0288 5708 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\DRIVERS\amdsata.sys
05:30:02.0316 5708 amdsata - ok
05:30:02.0466 5708 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
05:30:02.0492 5708 amdsbs - ok
05:30:02.0625 5708 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\DRIVERS\amdxata.sys
05:30:02.0651 5708 amdxata - ok
05:30:02.0795 5708 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
05:30:02.0854 5708 AppID - ok
05:30:02.0973 5708 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
05:30:03.0022 5708 AppIDSvc - ok
05:30:03.0174 5708 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
05:30:03.0225 5708 Appinfo - ok
05:30:03.0378 5708 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
05:30:03.0409 5708 arc - ok
05:30:03.0534 5708 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
05:30:03.0549 5708 arcsas - ok
05:30:03.0752 5708 AsDsm (88fbc8bebfd38566235eaa5e4dbc4e05) C:\Windows\system32\drivers\AsDsm.sys
05:30:03.0768 5708 AsDsm - ok
05:30:03.0863 5708 ASLDRService (18e5c2f937f9deb8c282df66a3761925) C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
05:30:03.0890 5708 ASLDRService - ok
05:30:03.0966 5708 ASMMAP64 (2db34edd17d3a8da7105a19c95a3dd68) C:\Program Files\ATKGFNEX\ASMMAP64.sys
05:30:03.0985 5708 ASMMAP64 - ok
05:30:04.0130 5708 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
05:30:04.0212 5708 aspnet_state - ok
05:30:04.0311 5708 aswFsBlk (b9da213b5271db5fce962d827e6d620d) C:\Windows\system32\drivers\aswFsBlk.sys
05:30:04.0336 5708 aswFsBlk - ok
05:30:04.0432 5708 aswMonFlt (21c9835d0e5ad2ff0f16134bcb32cc71) C:\Windows\system32\drivers\aswMonFlt.sys
05:30:04.0455 5708 aswMonFlt - ok
05:30:04.0598 5708 aswRdr (1b96a5867abd4fa6135d8298fcccf9c6) C:\Windows\System32\Drivers\aswrdr2.sys
05:30:04.0622 5708 aswRdr - ok
05:30:04.0737 5708 aswSnx (6e98bb288696777a3a8a07a52b0eaee9) C:\Windows\system32\drivers\aswSnx.sys
05:30:04.0773 5708 aswSnx - ok
05:30:04.0885 5708 aswSP (d9fb49f16e4eb02efecae8cbfe4bcb4c) C:\Windows\system32\drivers\aswSP.sys
05:30:04.0931 5708 aswSP - ok
05:30:05.0119 5708 aswTdi (7352bb9a564b94bbd7c9cbf165f55006) C:\Windows\system32\drivers\aswTdi.sys
05:30:05.0134 5708 aswTdi - ok
05:30:05.0243 5708 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
05:30:05.0290 5708 AsyncMac - ok
05:30:05.0433 5708 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
05:30:05.0459 5708 atapi - ok
05:30:05.0738 5708 athr (a5e770426d18f8ef332a593f3289da91) C:\Windows\system32\DRIVERS\athrx.sys
05:30:05.0854 5708 athr - ok
05:30:05.0939 5708 ATKGFNEXSrv (7c157574a181b19b9dcf5f339e25337e) C:\Program Files\ATKGFNEX\GFNEXSrv.exe
05:30:05.0950 5708 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - warning
05:30:05.0950 5708 ATKGFNEXSrv - detected UnsignedFile.Multi.Generic (1)
05:30:06.0171 5708 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
05:30:06.0253 5708 AudioEndpointBuilder - ok
05:30:06.0268 5708 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
05:30:06.0318 5708 AudioSrv - ok
05:30:06.0414 5708 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
05:30:06.0414 5708 avast! Antivirus - ok
05:30:06.0554 5708 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
05:30:06.0601 5708 AxInstSV - ok
05:30:06.0757 5708 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
05:30:06.0804 5708 b06bdrv - ok
05:30:06.0919 5708 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
05:30:06.0945 5708 b57nd60a - ok
05:30:06.0997 5708 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
05:30:07.0017 5708 BDESVC - ok
05:30:07.0039 5708 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
05:30:07.0089 5708 Beep - ok
05:30:07.0177 5708 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
05:30:07.0252 5708 BFE - ok
05:30:07.0370 5708 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
05:30:07.0449 5708 BITS - ok
05:30:07.0590 5708 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
05:30:07.0622 5708 blbdrive - ok
05:30:07.0697 5708 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
05:30:07.0729 5708 bowser - ok
05:30:07.0774 5708 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
05:30:07.0795 5708 BrFiltLo - ok
05:30:07.0905 5708 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
05:30:07.0936 5708 BrFiltUp - ok
05:30:07.0999 5708 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
05:30:08.0046 5708 Browser - ok
05:30:08.0295 5708 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
05:30:08.0326 5708 Brserid - ok
05:30:08.0451 5708 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
05:30:08.0490 5708 BrSerWdm - ok
05:30:08.0605 5708 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
05:30:08.0636 5708 BrUsbMdm - ok
05:30:08.0806 5708 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
05:30:08.0837 5708 BrUsbSer - ok
05:30:09.0009 5708 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
05:30:09.0031 5708 BTHMODEM - ok
05:30:09.0134 5708 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
05:30:09.0192 5708 bthserv - ok
05:30:09.0217 5708 catchme - ok
05:30:09.0334 5708 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
05:30:09.0412 5708 cdfs - ok
05:30:09.0521 5708 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
05:30:09.0568 5708 cdrom - ok
05:30:09.0677 5708 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
05:30:09.0755 5708 CertPropSvc - ok
05:30:09.0880 5708 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
05:30:09.0911 5708 circlass - ok
05:30:10.0040 5708 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
05:30:10.0068 5708 CLFS - ok
05:30:10.0192 5708 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
05:30:10.0269 5708 clr_optimization_v2.0.50727_32 - ok
05:30:10.0399 5708 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
05:30:10.0464 5708 clr_optimization_v2.0.50727_64 - ok
05:30:10.0701 5708 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
05:30:10.0889 5708 clr_optimization_v4.0.30319_32 - ok
05:30:11.0059 5708 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
05:30:11.0231 5708 clr_optimization_v4.0.30319_64 - ok
05:30:11.0356 5708 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
05:30:11.0402 5708 CmBatt - ok
05:30:11.0543 5708 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
05:30:11.0575 5708 cmdide - ok
05:30:11.0708 5708 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
05:30:11.0757 5708 CNG - ok
05:30:11.0897 5708 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
05:30:11.0923 5708 Compbatt - ok
05:30:12.0075 5708 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
05:30:12.0149 5708 CompositeBus - ok
05:30:12.0242 5708 COMSysApp - ok
05:30:12.0403 5708 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
05:30:12.0429 5708 crcdisk - ok
05:30:12.0613 5708 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
05:30:12.0691 5708 CryptSvc - ok
05:30:12.0878 5708 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
05:30:12.0940 5708 DcomLaunch - ok
05:30:13.0179 5708 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
05:30:13.0240 5708 defragsvc - ok
05:30:13.0397 5708 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
05:30:13.0451 5708 DfsC - ok
05:30:13.0572 5708 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
05:30:13.0635 5708 Dhcp - ok
05:30:13.0782 5708 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
05:30:13.0839 5708 discache - ok
05:30:13.0991 5708 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
05:30:14.0018 5708 Disk - ok
05:30:14.0120 5708 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
05:30:14.0151 5708 Dnscache - ok
05:30:14.0260 5708 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
05:30:14.0322 5708 dot3svc - ok
05:30:14.0432 5708 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
05:30:14.0494 5708 DPS - ok
05:30:14.0619 5708 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
05:30:14.0666 5708 drmkaud - ok
05:30:14.0891 5708 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
05:30:14.0963 5708 DXGKrnl - ok
05:30:15.0069 5708 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
05:30:15.0130 5708 EapHost - ok
05:30:15.0462 5708 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
05:30:15.0598 5708 ebdrv - ok
05:30:15.0767 5708 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
05:30:15.0798 5708 EFS - ok
05:30:16.0032 5708 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
05:30:16.0079 5708 elxstor - ok
05:30:16.0219 5708 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
05:30:16.0262 5708 ErrDev - ok
05:30:16.0408 5708 ETD (1299d1ea00b7a4bf69c5869dca31e0f6) C:\Windows\system32\DRIVERS\ETD.sys
05:30:16.0443 5708 ETD - ok
05:30:16.0615 5708 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
05:30:16.0683 5708 EventSystem - ok
05:30:16.0796 5708 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
05:30:16.0862 5708 exfat - ok
05:30:16.0968 5708 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
05:30:17.0034 5708 fastfat - ok
05:30:17.0199 5708 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
05:30:17.0231 5708 Fax - ok
05:30:17.0449 5708 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
05:30:17.0480 5708 fdc - ok
05:30:17.0605 5708 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
05:30:17.0652 5708 fdPHost - ok
05:30:17.0761 5708 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
05:30:17.0832 5708 FDResPub - ok
05:30:17.0949 5708 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
05:30:17.0977 5708 FileInfo - ok
05:30:18.0119 5708 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
05:30:18.0182 5708 Filetrace - ok
05:30:18.0421 5708 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
05:30:18.0440 5708 flpydisk - ok
05:30:18.0608 5708 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
05:30:18.0644 5708 FltMgr - ok
05:30:18.0784 5708 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
05:30:18.0862 5708 FontCache - ok
05:30:19.0003 5708 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
05:30:19.0018 5708 FontCache3.0.0.0 - ok
05:30:19.0174 5708 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
05:30:19.0206 5708 FsDepends - ok
05:30:19.0348 5708 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
05:30:19.0371 5708 fssfltr - ok
05:30:19.0550 5708 fsssvc (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
05:30:19.0646 5708 fsssvc - ok
05:30:19.0818 5708 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
05:30:19.0844 5708 Fs_Rec - ok
05:30:20.0007 5708 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
05:30:20.0038 5708 fvevol - ok
05:30:20.0102 5708 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
05:30:20.0124 5708 gagp30kx - ok
05:30:20.0224 5708 GGSAFERDriver - ok
05:30:20.0464 5708 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
05:30:20.0542 5708 gpsvc - ok
05:30:20.0682 5708 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
05:30:20.0713 5708 gupdate - ok
05:30:20.0760 5708 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
05:30:20.0760 5708 gupdatem - ok
05:30:20.0928 5708 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
05:30:20.0954 5708 gusvc - ok
05:30:21.0097 5708 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
05:30:21.0119 5708 hcw85cir - ok
05:30:21.0248 5708 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
05:30:21.0274 5708 HdAudAddService - ok
05:30:21.0415 5708 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
05:30:21.0447 5708 HDAudBus - ok
05:30:21.0619 5708 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
05:30:21.0638 5708 HidBatt - ok
05:30:21.0822 5708 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
05:30:21.0859 5708 HidBth - ok
05:30:22.0064 5708 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
05:30:22.0095 5708 HidIr - ok
05:30:22.0298 5708 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
05:30:22.0361 5708 hidserv - ok
05:30:22.0505 5708 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
05:30:22.0530 5708 HidUsb - ok
05:30:22.0618 5708 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
05:30:22.0669 5708 hkmsvc - ok
05:30:22.0820 5708 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
05:30:22.0856 5708 HomeGroupListener - ok
05:30:23.0029 5708 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
05:30:23.0067 5708 HomeGroupProvider - ok
05:30:23.0191 5708 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\DRIVERS\HpSAMD.sys
05:30:23.0213 5708 HpSAMD - ok
05:30:23.0404 5708 hshld (575546ee9a39dd5cb3b4e34a146a8a3e) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
05:30:23.0446 5708 hshld - ok
05:30:23.0649 5708 HssDrv (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
05:30:23.0665 5708 HssDrv - ok
05:30:23.0899 5708 HssSrv (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
05:30:23.0930 5708 HssSrv - ok
05:30:24.0090 5708 HssTrayService (4efb7fc2a11db10ab6205206d60c432b) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
05:30:24.0118 5708 HssTrayService - ok
05:30:24.0243 5708 HssWd - ok
05:30:24.0411 5708 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
05:30:24.0492 5708 HTTP - ok
05:30:24.0644 5708 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
05:30:24.0660 5708 hwpolicy - ok
05:30:24.0795 5708 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
05:30:24.0822 5708 i8042prt - ok
05:30:24.0994 5708 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\DRIVERS\iaStorV.sys
05:30:25.0016 5708 iaStorV - ok
05:30:25.0172 5708 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
05:30:25.0250 5708 idsvc - ok
05:30:25.0344 5708 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
05:30:25.0375 5708 iirsp - ok
05:30:25.0531 5708 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
05:30:25.0620 5708 IKEEXT - ok
05:30:25.0891 5708 IntcAzAudAddService (ef75c94792187a143871fbb87611b0b7) C:\Windows\system32\drivers\RTKVHD64.sys
05:30:26.0025 5708 IntcAzAudAddService - ok
05:30:26.0176 5708 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
05:30:26.0196 5708 intelide - ok
05:30:26.0329 5708 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
05:30:26.0360 5708 intelppm - ok
05:30:26.0436 5708 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
05:30:26.0485 5708 IPBusEnum - ok
05:30:26.0664 5708 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
05:30:26.0742 5708 IpFilterDriver - ok
05:30:26.0898 5708 iphlpsvc (a34a587fffd45fa649fba6d03784d257) C:\Windows\System32\iphlpsvc.dll
05:30:26.0976 5708 iphlpsvc - ok
05:30:27.0151 5708 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\DRIVERS\IPMIDrv.sys
05:30:27.0180 5708 IPMIDRV - ok
05:30:27.0338 5708 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
05:30:27.0398 5708 IPNAT - ok
05:30:27.0583 5708 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
05:30:27.0622 5708 IRENUM - ok
05:30:27.0726 5708 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
05:30:27.0752 5708 isapnp - ok
05:30:27.0879 5708 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\DRIVERS\msiscsi.sys
05:30:27.0910 5708 iScsiPrt - ok
05:30:28.0023 5708 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
05:30:28.0045 5708 kbdclass - ok
05:30:28.0192 5708 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
05:30:28.0223 5708 kbdhid - ok
05:30:28.0254 5708 kbfiltr (e63ef8c3271d014f14e2469ce75fecb4) C:\Windows\system32\DRIVERS\kbfiltr.sys
05:30:28.0270 5708 kbfiltr - ok
05:30:28.0317 5708 KeyIso (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
05:30:28.0348 5708 KeyIso - ok
05:30:28.0535 5708 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
05:30:28.0551 5708 KSecDD - ok
05:30:28.0722 5708 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
05:30:28.0762 5708 KSecPkg - ok
05:30:28.0921 5708 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
05:30:28.0970 5708 ksthunk - ok
05:30:29.0094 5708 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
05:30:29.0146 5708 KtmRm - ok
05:30:29.0260 5708 LanmanServer (d9f42719019740baa6d1c6d536cbdaa6) C:\Windows\System32\srvsvc.dll
05:30:29.0380 5708 LanmanServer - ok
05:30:29.0437 5708 LanmanWorkstation (851a1382eed3e3a7476db004f4ee3e1a) C:\Windows\System32\wkssvc.dll
05:30:29.0498 5708 LanmanWorkstation - ok
05:30:29.0608 5708 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
05:30:29.0659 5708 lltdio - ok
05:30:29.0824 5708 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
05:30:29.0886 5708 lltdsvc - ok
05:30:29.0995 5708 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
05:30:30.0042 5708 lmhosts - ok
05:30:30.0198 5708 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
05:30:30.0230 5708 LSI_FC - ok
05:30:30.0369 5708 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
05:30:30.0396 5708 LSI_SAS - ok
05:30:30.0529 5708 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
05:30:30.0558 5708 LSI_SAS2 - ok
05:30:30.0746 5708 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
05:30:30.0771 5708 LSI_SCSI - ok
05:30:31.0057 5708 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
05:30:31.0113 5708 luafv - ok
05:30:31.0471 5708 ManyCam (d33e2b74cf8b3a652bf0a9fbd068e87a) C:\Windows\system32\DRIVERS\ManyCam_x64.sys
05:30:31.0486 5708 ManyCam - ok
05:30:31.0674 5708 MBAMProtector (23a854450dab5c9b7a42ab9be6f2e4bd) C:\Windows\system32\drivers\mbam.sys
05:30:31.0705 5708 MBAMProtector - ok
05:30:31.0809 5708 MBAMService (94e920be59b9ab65d95e582dbaa136ac) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
05:30:31.0838 5708 MBAMService - ok
05:30:31.0970 5708 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
05:30:31.0989 5708 megasas - ok
05:30:32.0187 5708 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
05:30:32.0233 5708 MegaSR - ok
05:30:32.0363 5708 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
05:30:32.0406 5708 Microsoft Office Groove Audit Service - ok
05:30:32.0585 5708 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
05:30:32.0660 5708 MMCSS - ok
05:30:32.0766 5708 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
05:30:32.0807 5708 Modem - ok
05:30:33.0041 5708 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
05:30:33.0057 5708 monitor - ok
05:30:33.0135 5708 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
05:30:33.0150 5708 mouclass - ok
05:30:33.0197 5708 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
05:30:33.0228 5708 mouhid - ok
05:30:33.0351 5708 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
05:30:33.0379 5708 mountmgr - ok
05:30:33.0504 5708 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\DRIVERS\mpio.sys
05:30:33.0553 5708 mpio - ok
05:30:33.0706 5708 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
05:30:33.0750 5708 mpsdrv - ok
05:30:33.0977 5708 MpsSvc (54ffc9c8898113ace189d4aa7199d2c1) C:\Windows\system32\mpssvc.dll
05:30:34.0091 5708 MpsSvc - ok
05:30:34.0246 5708 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
05:30:34.0284 5708 MRxDAV - ok
05:30:34.0439 5708 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
05:30:34.0485 5708 mrxsmb - ok
05:30:34.0626 5708 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
05:30:34.0673 5708 mrxsmb10 - ok
05:30:34.0797 5708 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
05:30:34.0829 5708 mrxsmb20 - ok
05:30:34.0972 5708 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\DRIVERS\msahci.sys
05:30:35.0000 5708 msahci - ok
05:30:35.0223 5708 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\DRIVERS\msdsm.sys
05:30:35.0241 5708 msdsm - ok
05:30:35.0407 5708 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
05:30:35.0447 5708 MSDTC - ok
05:30:35.0654 5708 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
05:30:35.0711 5708 Msfs - ok
05:30:35.0882 5708 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
05:30:35.0930 5708 mshidkmdf - ok
05:30:36.0148 5708 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
05:30:36.0179 5708 msisadrv - ok
05:30:36.0398 5708 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
05:30:36.0490 5708 MSiSCSI - ok
05:30:36.0656 5708 msiserver - ok
05:30:36.0811 5708 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
05:30:36.0873 5708 MSKSSRV - ok
05:30:37.0038 5708 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
05:30:37.0099 5708 MSPCLOCK - ok
05:30:37.0175 5708 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
05:30:37.0228 5708 MSPQM - ok
05:30:37.0395 5708 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
05:30:37.0429 5708 MsRPC - ok
05:30:37.0532 5708 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
05:30:37.0548 5708 mssmbios - ok
05:30:37.0657 5708 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
05:30:37.0704 5708 MSTEE - ok
05:30:37.0860 5708 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
05:30:37.0891 5708 MTConfig - ok
05:30:38.0049 5708 MTsensor (032d35c996f21d19a205a7c8f0b76f3c) C:\Windows\system32\DRIVERS\ATK64AMD.sys
05:30:38.0067 5708 MTsensor - ok
05:30:38.0195 5708 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
05:30:38.0219 5708 Mup - ok
05:30:38.0451 5708 napagent (582ac6d9873e31dfa28a4547270862dd) C:\Windows\system32\qagentRT.dll
05:30:38.0555 5708 napagent - ok
05:30:38.0737 5708 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
05:30:38.0793 5708 NativeWifiP - ok
05:30:38.0984 5708 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
05:30:39.0023 5708 NDIS - ok
05:30:39.0148 5708 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
05:30:39.0195 5708 NdisCap - ok
05:30:39.0351 5708 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
05:30:39.0398 5708 NdisTapi - ok
05:30:39.0554 5708 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
05:30:39.0620 5708 Ndisuio - ok
05:30:39.0789 5708 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
05:30:39.0844 5708 NdisWan - ok
05:30:40.0000 5708 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
05:30:40.0057 5708 NDProxy - ok
05:30:40.0204 5708 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
05:30:40.0259 5708 NetBIOS - ok
05:30:40.0408 5708 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
05:30:40.0457 5708 NetBT - ok
05:30:40.0569 5708 Netlogon (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
05:30:40.0601 5708 Netlogon - ok
05:30:40.0741 5708 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
05:30:40.0803 5708 Netman - ok
05:30:40.0959 5708 NetMsmqActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
05:30:41.0037 5708 NetMsmqActivator - ok
05:30:41.0037 5708 NetPipeActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
05:30:41.0053 5708 NetPipeActivator - ok
05:30:41.0189 5708 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
05:30:41.0251 5708 netprofm - ok
05:30:41.0367 5708 NetTcpActivator (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
05:30:41.0382 5708 NetTcpActivator - ok
05:30:41.0397 5708 NetTcpPortSharing (d22cd77d4f0d63d1169bb35911bff12d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
05:30:41.0413 5708 NetTcpPortSharing - ok
05:30:41.0562 5708 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
05:30:41.0584 5708 nfrd960 - ok
05:30:41.0843 5708 NlaSvc (1ee99a89cc788ada662441d1e9830529) C:\Windows\System32\nlasvc.dll
05:30:41.0907 5708 NlaSvc - ok
05:30:42.0100 5708 NPF (351533acc2a069b94e80bbfc177e8fdf) C:\Windows\system32\drivers\npf.sys
05:30:42.0123 5708 NPF - ok
05:30:42.0248 5708 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
05:30:42.0310 5708 Npfs - ok
05:30:42.0435 5708 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
05:30:42.0497 5708 nsi - ok
05:30:42.0607 5708 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
05:30:42.0669 5708 nsiproxy - ok
05:30:42.0897 5708 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
05:30:42.0997 5708 Ntfs - ok
05:30:43.0139 5708 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
05:30:43.0190 5708 Null - ok
05:30:43.0981 5708 nvlddmkm (b34e9bfbd9c61048ef6281c3e7ec210a) C:\Windows\system32\DRIVERS\nvlddmkm.sys
05:30:44.0419 5708 nvlddmkm - ok
05:30:44.0623 5708 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\DRIVERS\nvraid.sys
05:30:44.0643 5708 nvraid - ok
05:30:44.0783 5708 nvsmu (e58d81fb8616d0cb55c1e36aa0b213c9) C:\Windows\system32\DRIVERS\nvsmu.sys
05:30:44.0801 5708 nvsmu - ok
05:30:44.0929 5708 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\DRIVERS\nvstor.sys
05:30:44.0949 5708 nvstor - ok
05:30:45.0030 5708 nvstor64 (1978dd2ee567287d040b5a9468eceb72) C:\Windows\system32\DRIVERS\nvstor64.sys
05:30:45.0046 5708 nvstor64 - ok
05:30:45.0134 5708 nvsvc (dfda089bb2cd0ff7e789e2ef6ba1e4ba) C:\Windows\system32\nvvsvc.exe
05:30:45.0186 5708 nvsvc - ok
05:30:45.0333 5708 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
05:30:45.0349 5708 nv_agp - ok
05:30:45.0473 5708 OberonGameConsoleService (649791f5b905e6a8ecced15ad8efd436) C:\Program Files (x86)\Asus\Game Park\GameConsole\OberonGameConsoleService.exe
05:30:45.0536 5708 OberonGameConsoleService - ok
05:30:45.0629 5708 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
05:30:45.0739 5708 odserv - ok
05:30:45.0888 5708 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
05:30:45.0920 5708 ohci1394 - ok
05:30:46.0060 5708 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
05:30:46.0088 5708 ose - ok
05:30:46.0242 5708 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
05:30:46.0274 5708 p2pimsvc - ok
05:30:46.0365 5708 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
05:30:46.0401 5708 p2psvc - ok
05:30:46.0486 5708 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
05:30:46.0506 5708 Parport - ok
05:30:46.0573 5708 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
05:30:46.0591 5708 partmgr - ok
05:30:46.0736 5708 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
05:30:46.0783 5708 PcaSvc - ok
05:30:46.0951 5708 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\DRIVERS\pci.sys
05:30:46.0969 5708 pci - ok
05:30:47.0035 5708 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
05:30:47.0063 5708 pciide - ok
05:30:47.0132 5708 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
05:30:47.0157 5708 pcmcia - ok
05:30:47.0327 5708 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
05:30:47.0357 5708 pcw - ok
05:30:47.0526 5708 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
05:30:47.0597 5708 PEAUTH - ok
05:30:47.0740 5708 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
05:30:47.0773 5708 PerfHost - ok
05:30:47.0973 5708 pla (c7cf6a6e137463219e1259e3f0f0dd6c) C:\Windows\system32\pla.dll
05:30:48.0066 5708 pla - ok
05:30:48.0270 5708 PlugPlay (25fbdef06c4d92815b353f6e792c8129) C:\Windows\system32\umpnpmgr.dll
05:30:48.0312 5708 PlugPlay - ok
05:30:48.0460 5708 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
05:30:48.0487 5708 PNRPAutoReg - ok
05:30:48.0594 5708 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
05:30:48.0637 5708 PNRPsvc - ok
05:30:48.0776 5708 PolicyAgent (4f15d75adf6156bf56eced6d4a55c389) C:\Windows\System32\ipsecsvc.dll
05:30:48.0848 5708 PolicyAgent - ok
05:30:48.0987 5708 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
05:30:49.0050 5708 Power - ok
05:30:49.0214 5708 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
05:30:49.0262 5708 PptpMiniport - ok
05:30:49.0410 5708 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
05:30:49.0433 5708 Processor - ok
05:30:49.0564 5708 ProfSvc (5c78838b4d166d1a27db3a8a820c799a) C:\Windows\system32\profsvc.dll
05:30:49.0620 5708 ProfSvc - ok
05:30:49.0729 5708 ProtectedStorage (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
05:30:49.0755 5708 ProtectedStorage - ok
05:30:49.0883 5708 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
05:30:49.0976 5708 Psched - ok
05:30:50.0224 5708 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
05:30:50.0324 5708 ql2300 - ok
05:30:50.0421 5708 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
05:30:50.0452 5708 ql40xx - ok
05:30:50.0555 5708 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
05:30:50.0594 5708 QWAVE - ok
05:30:50.0793 5708 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
05:30:50.0823 5708 QWAVEdrv - ok
05:30:50.0936 5708 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
05:30:51.0025 5708 RasAcd - ok
05:30:51.0194 5708 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
05:30:51.0242 5708 RasAgileVpn - ok
05:30:51.0443 5708 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
05:30:51.0492 5708 RasAuto - ok
05:30:51.0600 5708 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
05:30:51.0642 5708 Rasl2tp - ok
05:30:51.0863 5708 RasMan (ee867a0870fc9e4972ba9eaad35651e2) C:\Windows\System32\rasmans.dll
05:30:51.0980 5708 RasMan - ok
05:30:52.0283 5708 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
05:30:52.0333 5708 RasPppoe - ok
05:30:52.0429 5708 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
05:30:52.0474 5708 RasSstp - ok
05:30:52.0625 5708 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
05:30:52.0677 5708 rdbss - ok
05:30:52.0772 5708 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
05:30:52.0798 5708 rdpbus - ok
05:30:52.0902 5708 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
05:30:52.0947 5708 RDPCDD - ok
05:30:53.0122 5708 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
05:30:53.0178 5708 RDPENCDD - ok
05:30:53.0449 5708 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
05:30:53.0507 5708 RDPREFMP - ok
05:30:53.0708 5708 RDPWD (6d76e6433574b058adcb0c50df834492) C:\Windows\system32\drivers\RDPWD.sys
05:30:53.0739 5708 RDPWD - ok
05:30:53.0875 5708 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
05:30:53.0896 5708 rdyboost - ok
05:30:53.0997 5708 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
05:30:54.0045 5708 RemoteAccess - ok
05:30:54.0155 5708 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
05:30:54.0210 5708 RemoteRegistry - ok
05:30:54.0380 5708 Revoflt (9c3ac71a9934b884fac567a8807e9c4d) C:\Windows\system32\DRIVERS\revoflt.sys
05:30:54.0404 5708 Revoflt - ok
05:30:54.0545 5708 RichVideo (8cfca7e2fd4b57c2bef929c1c1a4c56e) C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe
05:30:54.0567 5708 RichVideo - ok
05:30:54.0723 5708 rpcapd (b60f58f175de20a6739194e85b035178) C:\Program Files (x86)\WinPcap\rpcapd.exe
05:30:54.0745 5708 rpcapd - ok
05:30:54.0863 5708 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
05:30:54.0911 5708 RpcEptMapper - ok
05:30:55.0127 5708 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
05:30:55.0163 5708 RpcLocator - ok
05:30:55.0335 5708 RpcSs (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\System32\rpcss.dll
05:30:55.0388 5708 RpcSs - ok
05:30:55.0526 5708 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
05:30:55.0575 5708 rspndr - ok
05:30:55.0861 5708 RTL8167 (f65f171165fbb613f7aa3cc78e8cab42) C:\Windows\system32\DRIVERS\Rt64win7.sys
05:30:55.0921 5708 RTL8167 - ok
05:30:56.0092 5708 RUBotSrv (a0eea6f631349d0e0b7a6caa7e099cb0) C:\Program Files (x86)\Trend Micro\RUBotted\RUBotSrv.exe
05:30:56.0138 5708 RUBotSrv - ok
05:30:56.0311 5708 SamSs (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
05:30:56.0334 5708 SamSs - ok
05:30:56.0440 5708 SASDIFSV (3289766038db2cb14d07dc84392138d5) C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
05:30:56.0460 5708 SASDIFSV - ok
05:30:56.0506 5708 SASKUTIL (58a38e75f3316a83c23df6173d41f2b5) C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
05:30:56.0521 5708 SASKUTIL - ok
05:30:56.0659 5708 SbieDrv (687cdadd7b13529e6d6eda30b3f67051) C:\Program Files\Sandboxie\SbieDrv.sys
05:30:56.0702 5708 SbieDrv - ok
05:30:56.0803 5708 SbieSvc (4cdb30762d89264ff570d2c64ba9b8a6) C:\Program Files\Sandboxie\SbieSvc.exe
05:30:56.0827 5708 SbieSvc - ok
05:30:57.0074 5708 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\DRIVERS\sbp2port.sys
05:30:57.0098 5708 sbp2port - ok
05:30:57.0477 5708 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
05:30:57.0733 5708 SCardSvr - ok
05:30:58.0024 5708 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
05:30:58.0064 5708 scfilter - ok
05:30:58.0367 5708 Schedule (262f6592c3299c005fd6bec90fc4463a) C:\Windows\system32\schedsvc.dll
05:30:58.0464 5708 Schedule - ok
05:30:58.0710 5708 SCPolicySvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
05:30:58.0751 5708 SCPolicySvc - ok
05:30:58.0908 5708 SDRSVC (6ea4234dc55346e0709560fe7c2c1972) C:\Windows\System32\SDRSVC.dll
05:30:58.0941 5708 SDRSVC - ok
05:30:59.0212 5708 SeaPort (16a252022535b680046f6e34e136d378) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
05:30:59.0233 5708 SeaPort - ok
05:30:59.0448 5708 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
05:30:59.0503 5708 secdrv - ok
05:30:59.0682 5708 seclogon (bc617a4e1b4fa8df523a061739a0bd87) C:\Windows\system32\seclogon.dll
05:30:59.0744 5708 seclogon - ok
05:30:59.0870 5708 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\system32\sens.dll
05:30:59.0932 5708 SENS - ok
05:31:00.0010 5708 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
05:31:00.0042 5708 SensrSvc - ok
05:31:00.0217 5708 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
05:31:00.0241 5708 Serenum - ok
05:31:00.0314 5708 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
05:31:00.0349 5708 Serial - ok
05:31:00.0491 5708 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
05:31:00.0519 5708 sermouse - ok
05:31:00.0666 5708 SessionEnv (0b6231bf38174a1628c4ac812cc75804) C:\Windows\system32\sessenv.dll
05:31:00.0713 5708 SessionEnv - ok
05:31:00.0865 5708 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
05:31:00.0896 5708 sffdisk - ok
05:31:01.0004 5708 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
05:31:01.0043 5708 sffp_mmc - ok
05:31:01.0196 5708 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\DRIVERS\sffp_sd.sys
05:31:01.0233 5708 sffp_sd - ok
05:31:01.0356 5708 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
05:31:01.0381 5708 sfloppy - ok
05:31:01.0543 5708 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
05:31:01.0603 5708 SharedAccess - ok
05:31:01.0986 5708 ShellHWDetection (aaf932b4011d14052955d4b212a4da8d) C:\Windows\System32\shsvcs.dll
05:31:02.0058 5708 ShellHWDetection - ok
05:31:02.0344 5708 SiSGbeLH (1bc348cf6baa90ec8e533ef6e6a69933) C:\Windows\system32\DRIVERS\SiSG664.sys
05:31:02.0364 5708 SiSGbeLH - ok
05:31:02.0678 5708 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
05:31:02.0694 5708 SiSRaid2 - ok
05:31:02.0806 5708 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
05:31:02.0824 5708 SiSRaid4 - ok
05:31:03.0307 5708 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
05:31:03.0363 5708 Smb - ok
05:31:03.0469 5708 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
05:31:03.0497 5708 SNMPTRAP - ok
05:31:03.0850 5708 SNP2UVC (1d8474722cdffbb8fca5fa12c50a05a2) C:\Windows\system32\DRIVERS\snp2uvc.sys
05:31:03.0945 5708 SNP2UVC - ok
05:31:04.0135 5708 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
05:31:04.0166 5708 spldr - ok
05:31:04.0337 5708 Spooler (b96c17b5dc1424d56eea3a99e97428cd) C:\Windows\System32\spoolsv.exe
05:31:04.0425 5708 Spooler - ok
05:31:04.0788 5708 sppsvc (e17e0188bb90fae42d83e98707efa59c) C:\Windows\system32\sppsvc.exe
05:31:04.0966 5708 sppsvc - ok
05:31:05.0144 5708 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
05:31:05.0200 5708 sppuinotify - ok
05:31:05.0349 5708 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
05:31:05.0375 5708 srv - ok
05:31:05.0578 5708 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
05:31:05.0607 5708 srv2 - ok
05:31:05.0760 5708 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
05:31:05.0814 5708 srvnet - ok
05:31:06.0020 5708 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
05:31:06.0096 5708 SSDPSRV - ok
05:31:06.0299 5708 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
05:31:06.0359 5708 SstpSvc - ok
05:31:06.0425 5708 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
05:31:06.0442 5708 stexstor - ok
05:31:06.0800 5708 stisvc (8dd52e8e6128f4b2da92ce27402871c1) C:\Windows\System32\wiaservc.dll
05:31:06.0905 5708 stisvc - ok
05:31:07.0137 5708 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
05:31:07.0157 5708 swenum - ok
05:31:07.0463 5708 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
05:31:07.0551 5708 swprv - ok
05:31:07.0779 5708 SysMain (bf9ccc0bf39b418c8d0ae8b05cf95b7d) C:\Windows\system32\sysmain.dll
05:31:07.0929 5708 SysMain - ok
05:31:08.0091 5708 TabletInputService (e3c61fd7b7c2557e1f1b0b4cec713585) C:\Windows\System32\TabSvc.dll
05:31:08.0125 5708 TabletInputService - ok
05:31:08.0374 5708 tap0901 (e965fc7627862779ba31a4fcb7d0c1ef) C:\Windows\system32\DRIVERS\tap0901.sys
05:31:08.0400 5708 tap0901 - ok
05:31:08.0546 5708 taphss (f33fdc72298df4bf9813a55d21f4eb31) C:\Windows\system32\DRIVERS\taphss.sys
05:31:08.0564 5708 taphss - ok
05:31:08.0730 5708 TapiSrv (40f0849f65d13ee87b9a9ae3c1dd6823) C:\Windows\System32\tapisrv.dll
05:31:08.0825 5708 TapiSrv - ok
05:31:09.0083 5708 tapoas (927d0cdb3f96efc1e98fb1a2c9fb67ad) C:\Windows\system32\DRIVERS\tapoas.sys
05:31:09.0123 5708 tapoas - ok
05:31:09.0335 5708 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
05:31:09.0383 5708 TBS - ok
05:31:09.0548 5708 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
05:31:09.0680 5708 Tcpip - ok
05:31:09.0907 5708 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
05:31:09.0959 5708 TCPIP6 - ok
05:31:10.0153 5708 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
05:31:10.0200 5708 tcpipreg - ok
05:31:10.0406 5708 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
05:31:10.0423 5708 TDPIPE - ok
05:31:10.0501 5708 TDTCP (51c5eceb1cdee2468a1748be550cfbc8) C:\Windows\system32\drivers\tdtcp.sys
05:31:10.0522 5708 TDTCP - ok
05:31:10.0628 5708 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
05:31:10.0671 5708 tdx - ok
05:31:10.0822 5708 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\DRIVERS\termdd.sys
05:31:10.0849 5708 TermDD - ok
05:31:11.0109 5708 TermService (2e648163254233755035b46dd7b89123) C:\Windows\System32\termsrv.dll
05:31:11.0195 5708 TermService - ok
05:31:11.0323 5708 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
05:31:11.0387 5708 Themes - ok
05:31:11.0563 5708 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
05:31:11.0629 5708 THREADORDER - ok
05:31:11.0761 5708 tmpreflt - ok
05:31:11.0843 5708 tmtdi - ok
05:31:11.0983 5708 tmxpflt - ok
05:31:12.0100 5708 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
05:31:12.0181 5708 TrkWks - ok
05:31:12.0281 5708 TrustedInstaller (773212b2aaa24c1e31f10246b15b276c) C:\Windows\servicing\TrustedInstaller.exe
05:31:12.0439 5708 TrustedInstaller - ok
05:31:12.0675 5708 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
05:31:12.0723 5708 tssecsrv - ok
05:31:12.0909 5708 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
05:31:12.0965 5708 tunnel - ok
05:31:13.0268 5708 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
05:31:13.0284 5708 uagp35 - ok
05:31:13.0690 5708 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
05:31:13.0773 5708 udfs - ok
05:31:14.0083 5708 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
05:31:14.0124 5708 UI0Detect - ok
05:31:14.0534 5708 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
05:31:14.0570 5708 uliagpkx - ok
05:31:14.0734 5708 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
05:31:14.0768 5708 umbus - ok
05:31:14.0916 5708 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
05:31:14.0939 5708 UmPass - ok
05:31:15.0067 5708 UnlockerDriver5 (9dc07e73a4abb9acf692113b36a5009f) C:\Program Files\Unlocker\UnlockerDriver5.sys
05:31:15.0090 5708 UnlockerDriver5 - ok
05:31:15.0236 5708 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
05:31:15.0317 5708 upnphost - ok
05:31:15.0448 5708 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
05:31:15.0475 5708 usbccgp - ok
05:31:15.0622 5708 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
05:31:15.0665 5708 usbcir - ok
05:31:15.0816 5708 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\DRIVERS\usbehci.sys
05:31:15.0840 5708 usbehci - ok
05:31:15.0939 5708 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
05:31:16.0012 5708 usbhub - ok
05:31:16.0153 5708 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\DRIVERS\usbohci.sys
05:31:16.0201 5708 usbohci - ok
05:31:16.0333 5708 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
05:31:16.0370 5708 usbprint - ok
05:31:16.0491 5708 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
05:31:16.0517 5708 USBSTOR - ok
05:31:16.0644 5708 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\DRIVERS\usbuhci.sys
05:31:16.0678 5708 usbuhci - ok
05:31:16.0777 5708 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\system32\Drivers\usbvideo.sys
05:31:16.0815 5708 usbvideo - ok
05:31:16.0957 5708 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
05:31:17.0029 5708 UxSms - ok
05:31:17.0142 5708 VaultSvc (c118a82cd78818c29ab228366ebf81c3) C:\Windows\system32\lsass.exe
05:31:17.0171 5708 VaultSvc - ok
05:31:17.0341 5708 VClone (fd911873c0bb6945fa38c16e9a2b58f9) C:\Windows\system32\DRIVERS\VClone.sys
05:31:17.0371 5708 VClone - ok
05:31:17.0593 5708 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
05:31:17.0610 5708 vdrvroot - ok
05:31:17.0774 5708 vds (8d6b481601d01a456e75c3210f1830be) C:\Windows\System32\vds.exe
05:31:17.0895 5708 vds - ok
05:31:18.0159 5708 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
05:31:18.0201 5708 vga - ok
05:31:18.0387 5708 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
05:31:18.0452 5708 VgaSave - ok
05:31:18.0692 5708 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\DRIVERS\vhdmp.sys
05:31:18.0741 5708 vhdmp - ok
05:31:18.0888 5708 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
05:31:18.0915 5708 viaide - ok
05:31:19.0074 5708 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\DRIVERS\volmgr.sys
05:31:19.0101 5708 volmgr - ok
05:31:19.0247 5708 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
05:31:19.0308 5708 volmgrx - ok
05:31:19.0437 5708 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\DRIVERS\volsnap.sys
05:31:19.0460 5708 volsnap - ok
05:31:19.0560 5708 vsapint - ok
05:31:19.0630 5708 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
05:31:19.0657 5708 vsmraid - ok
05:31:19.0755 5708 VSS (b60ba0bc31b0cb414593e169f6f21cc2) C:\Windows\system32\vssvc.exe
05:31:19.0869 5708 VSS - ok
05:31:20.0005 5708 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
05:31:20.0051 5708 vwifibus - ok
05:31:20.0193 5708 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
05:31:20.0223 5708 vwififlt - ok
05:31:20.0361 5708 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
05:31:20.0410 5708 vwifimp - ok
05:31:20.0488 5708 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
05:31:20.0550 5708 W32Time - ok
05:31:20.0644 5708 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
05:31:20.0659 5708 WacomPen - ok
05:31:20.0737 5708 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
05:31:20.0815 5708 WANARP - ok
05:31:20.0847 5708 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
05:31:20.0878 5708 Wanarpv6 - ok
05:31:21.0062 5708 wbengine (78f4e7f5c56cb9716238eb57da4b6a75) C:\Windows\system32\wbengine.exe
05:31:21.0163 5708 wbengine - ok
05:31:21.0308 5708 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
05:31:21.0353 5708 WbioSrvc - ok
05:31:21.0488 5708 wcncsvc (7368a2afd46e5a4481d1de9d14848edd) C:\Windows\System32\wcncsvc.dll
05:31:21.0534 5708 wcncsvc - ok
05:31:21.0627 5708 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
05:31:21.0655 5708 WcsPlugInService - ok
05:31:21.0750 5708 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
05:31:21.0773 5708 Wd - ok
05:31:21.0920 5708 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
05:31:21.0987 5708 Wdf01000 - ok
05:31:22.0104 5708 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
05:31:22.0151 5708 WdiServiceHost - ok
05:31:22.0166 5708 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
05:31:22.0182 5708 WdiSystemHost - ok
05:31:22.0307 5708 WebClient (3db6d04e1c64272f8b14eb8bc4616280) C:\Windows\System32\webclnt.dll
05:31:22.0617 5708 WebClient - ok
05:31:22.0740 5708 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
05:31:22.0811 5708 Wecsvc - ok
05:31:22.0943 5708 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
05:31:23.0003 5708 wercplsupport - ok
05:31:23.0173 5708 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
05:31:23.0231 5708 WerSvc - ok
05:31:23.0354 5708 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
05:31:23.0411 5708 WfpLwf - ok
05:31:23.0528 5708 WimFltr (52ded146e4797e6ccf94799e8e22bb2a) C:\Windows\system32\DRIVERS\wimfltr.sys
05:31:23.0552 5708 WimFltr - ok
05:31:23.0613 5708 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
05:31:23.0644 5708 WIMMount - ok
05:31:23.0706 5708 WinDefend - ok
05:31:23.0753 5708 WinHttpAutoProxySvc - ok
05:31:23.0878 5708 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
05:31:24.0065 5708 Winmgmt - ok
05:31:24.0281 5708 WinRM (bcb1310604aa415c4508708975b3931e) C:\Windows\system32\WsmSvc.dll
05:31:24.0405 5708 WinRM - ok
05:31:24.0642 5708 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
05:31:24.0680 5708 WinUsb - ok
05:31:24.0960 5708 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
05:31:25.0064 5708 Wlansvc - ok
05:31:25.0401 5708 wlidsvc (2bacd71123f42cea603f4e205e1ae337) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
05:31:25.0464 5708 wlidsvc - ok
05:31:25.0682 5708 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
05:31:25.0742 5708 WmiAcpi - ok
05:31:25.0910 5708 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
05:31:25.0946 5708 wmiApSrv - ok
05:31:26.0011 5708 WMPNetworkSvc - ok
05:31:26.0110 5708 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
05:31:26.0150 5708 WPCSvc - ok
05:31:26.0231 5708 WPDBusEnum (93221146d4ebbf314c29b23cd6cc391d) C:\Windows\system32\wpdbusenum.dll
05:31:26.0280 5708 WPDBusEnum - ok
05:31:26.0414 5708 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
05:31:26.0472 5708 ws2ifsl - ok
05:31:26.0613 5708 wscsvc (e8b1fe6669397d1772d8196df0e57a9e) C:\Windows\system32\wscsvc.dll
05:31:26.0655 5708 wscsvc - ok
05:31:26.0705 5708 WSearch - ok
05:31:26.0986 5708 wuauserv (9df12edbc698b0bc353b3ef84861e430) C:\Windows\system32\wuaueng.dll
05:31:27.0158 5708 wuauserv - ok
05:31:27.0324 5708 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
05:31:27.0375 5708 WudfPf - ok
05:31:27.0521 5708 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
05:31:27.0581 5708 WUDFRd - ok
05:31:27.0712 5708 wudfsvc (7a95c95b6c4cf292d689106bcae49543) C:\Windows\System32\WUDFSvc.dll
05:31:27.0775 5708 wudfsvc - ok
05:31:27.0907 5708 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
05:31:27.0952 5708 WwanSvc - ok
05:31:28.0093 5708 X6va005 - ok
05:31:28.0174 5708 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0
05:31:28.0732 5708 \Device\Harddisk0\DR0 - ok
05:31:28.0763 5708 Boot (0x1200) (23a18713bc457ddc83a8d2704de7a05b) \Device\Harddisk0\DR0\Partition0
05:31:28.0779 5708 \Device\Harddisk0\DR0\Partition0 - ok
05:31:28.0810 5708 Boot (0x1200) (7b65ad1d5dc9a5a4dac1ec773b2e0d63) \Device\Harddisk0\DR0\Partition1
05:31:28.0833 5708 \Device\Harddisk0\DR0\Partition1 - ok
05:31:28.0836 5708 ============================================================
05:31:28.0836 5708 Scan finished
05:31:28.0836 5708 ============================================================
05:31:28.0853 5848 Detected object count: 3
05:31:28.0853 5848 Actual detected object count: 3
05:33:56.0256 5848 ADSMService ( UnsignedFile.Multi.Generic ) - skipped by user
05:33:56.0256 5848 ADSMService ( UnsignedFile.Multi.Generic ) - User select action: Skip
05:33:56.0256 5848 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
05:33:56.0256 5848 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
05:33:56.0272 5848 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - skipped by user
05:33:56.0272 5848 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
05:34:40.0769 1804 ============================================================
05:34:40.0769 1804 Scan started
05:34:40.0769 1804 Mode: Manual; SigCheck; TDLFS;
05:34:40.0769 1804 ============================================================
05:34:41.0443 1804 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\DRIVERS\1394ohci.sys
05:34:41.0490 1804 1394ohci - ok
05:34:41.0671 1804 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\DRIVERS\ACPI.sys
05:34:41.0705 1804 ACPI - ok
05:34:41.0888 1804 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\DRIVERS\acpipmi.sys
05:34:41.0928 1804 AcpiPmi - ok
05:34:42.0129 1804 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
05:34:42.0161 1804 adp94xx - ok
05:34:42.0358 1804 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
05:34:42.0388 1804 adpahci - ok
05:34:42.0555 1804 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
05:34:42.0573 1804 adpu320 - ok
05:34:42.0731 1804 ADSMService (c0bf554d2277f7a4c735d475ade2e3b2) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe
05:34:42.0747 1804 ADSMService ( UnsignedFile.Multi.Generic ) - warning
05:34:42.0747 1804 ADSMService - detected UnsignedFile.Multi.Generic (1)
05:34:42.0887 1804 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
05:34:42.0934 1804 AeLookupSvc - ok
05:34:43.0106 1804 AFBAgent (fb2be0bae9b3f248080cdbf91ef16c7f) C:\Windows\system32\FBAgent.exe
05:34:43.0137 1804 AFBAgent - ok
05:34:43.0311 1804 AFD (1c7857b62de5994a75b054a9fd4c3825) C:\Windows\system32\drivers\afd.sys
05:34:43.0348 1804 AFD - ok
05:34:43.0487 1804 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
05:34:43.0514 1804 agp440 - ok
05:34:43.0878 1804 Akamai (1125c7d9fb8898015829c387c1bc87c7) c:\program files (x86)\common files\akamai/netsession_win_6c825ce.dll
05:34:43.0879 1804 Suspicious file (Hidden): c:\program files (x86)\common files\akamai/netsession_win_6c825ce.dll. md5: 1125c7d9fb8898015829c387c1bc87c7
05:34:43.0888 1804 Akamai ( HiddenFile.Multi.Generic ) - warning
05:34:43.0889 1804 Akamai - detected HiddenFile.Multi.Generic (1)
05:34:44.0039 1804 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
05:34:44.0071 1804 ALG - ok
05:34:44.0316 1804 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
05:34:44.0347 1804 aliide - ok
05:34:44.0628 1804 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
05:34:44.0659 1804 amdide - ok
05:34:44.0823 1804 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
05:34:44.0857 1804 AmdK8 - ok
05:34:45.0065 1804 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
05:34:45.0109 1804 AmdPPM - ok
05:34:45.0249 1804 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\DRIVERS\amdsata.sys
05:34:45.0278 1804 amdsata - ok
05:34:45.0459 1804 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
05:34:45.0491 1804 amdsbs - ok
05:34:45.0696 1804 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\DRIVERS\amdxata.sys
05:34:45.0713 1804 amdxata - ok
05:34:45.0887 1804 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
05:34:45.0934 1804 AppID - ok
05:34:46.0043 1804 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
05:34:46.0090 1804 AppIDSvc - ok
05:34:46.0277 1804 Appinfo (3977d4a871ca0d4f2ed1e7db46829731) C:\Windows\System32\appinfo.dll
05:34:46.0326 1804 Appinfo - ok
05:34:46.0517 1804 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
05:34:46.0543 1804 arc - ok
05:34:46.0719 1804 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
05:34:46.0739 1804 arcsas - ok
05:34:46.0942 1804 AsDsm (88fbc8bebfd38566235eaa5e4dbc4e05) C:\Windows\system32\drivers\AsDsm.sys
05:34:46.0965 1804 AsDsm - ok
05:34:47.0098 1804 ASLDRService (18e5c2f937f9deb8c282df66a3761925) C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
05:34:47.0120 1804 ASLDRService - ok
05:34:47.0202 1804 ASMMAP64 (2db34edd17d3a8da7105a19c95a3dd68) C:\Program Files\ATKGFNEX\ASMMAP64.sys
05:34:47.0214 1804 ASMMAP64 - ok
05:34:47.0363 1804 aspnet_state (9217d874131ae6ff8f642f124f00a555) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
05:34:47.0379 1804 aspnet_state - ok
05:34:47.0550 1804 aswFsBlk (b9da213b5271db5fce962d827e6d620d) C:\Windows\system32\drivers\aswFsBlk.sys
05:34:47.0581 1804 aswFsBlk - ok
05:34:47.0753 1804 aswMonFlt (21c9835d0e5ad2ff0f16134bcb32cc71) C:\Windows\system32\drivers\aswMonFlt.sys
05:34:47.0784 1804 aswMonFlt - ok
05:34:47.0966 1804 aswRdr (1b96a5867abd4fa6135d8298fcccf9c6) C:\Windows\System32\Drivers\aswrdr2.sys
05:34:47.0989 1804 aswRdr - ok
05:34:48.0219 1804 aswSnx (6e98bb288696777a3a8a07a52b0eaee9) C:\Windows\system32\drivers\aswSnx.sys
05:34:48.0262 1804 aswSnx - ok
05:34:48.0462 1804 aswSP (d9fb49f16e4eb02efecae8cbfe4bcb4c) C:\Windows\system32\drivers\aswSP.sys
05:34:48.0492 1804 aswSP - ok
05:34:48.0675 1804 aswTdi (7352bb9a564b94bbd7c9cbf165f55006) C:\Windows\system32\drivers\aswTdi.sys
05:34:48.0698 1804 aswTdi - ok
05:34:48.0846 1804 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
05:34:48.0892 1804 AsyncMac - ok
05:34:49.0033 1804 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
05:34:49.0048 1804 atapi - ok
05:34:49.0360 1804 athr (a5e770426d18f8ef332a593f3289da91) C:\Windows\system32\DRIVERS\athrx.sys
05:34:49.0426 1804 athr - ok
05:34:49.0516 1804 ATKGFNEXSrv (7c157574a181b19b9dcf5f339e25337e) C:\Program Files\ATKGFNEX\GFNEXSrv.exe
05:34:49.0526 1804 ATKGFNEXSrv ( UnsignedFile.Multi.Generic ) - warning
05:34:49.0526 1804 ATKGFNEXSrv - detected UnsignedFile.Multi.Generic (1)
05:34:49.0750 1804 AudioEndpointBuilder (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
05:34:49.0808 1804 AudioEndpointBuilder - ok
05:34:49.0863 1804 AudioSrv (f23fef6d569fce88671949894a8becf1) C:\Windows\System32\Audiosrv.dll
05:34:49.0911 1804 AudioSrv - ok
05:34:50.0057 1804 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
05:34:50.0084 1804 avast! Antivirus - ok
05:34:50.0285 1804 AxInstSV (a6bf31a71b409dfa8cac83159e1e2aff) C:\Windows\System32\AxInstSV.dll
05:34:50.0315 1804 AxInstSV - ok
05:34:50.0495 1804 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
05:34:50.0511 1804 b06bdrv - ok
05:34:50.0792 1804 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
05:34:50.0823 1804 b57nd60a - ok
05:34:51.0004 1804 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
05:34:51.0037 1804 BDESVC - ok
05:34:51.0266 1804 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
05:34:51.0317 1804 Beep - ok
05:34:51.0560 1804 BFE (82974d6a2fd19445cc5171fc378668a4) C:\Windows\System32\bfe.dll
05:34:51.0633 1804 BFE - ok
05:34:51.0979 1804 BITS (1ea7969e3271cbc59e1730697dc74682) C:\Windows\system32\qmgr.dll
05:34:52.0033 1804 BITS - ok
05:34:52.0322 1804 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
05:34:52.0354 1804 blbdrive - ok
05:34:52.0573 1804 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
05:34:52.0605 1804 bowser - ok
05:34:52.0750 1804 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
05:34:52.0786 1804 BrFiltLo - ok
05:34:52.0948 1804 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
05:34:52.0978 1804 BrFiltUp - ok
05:34:53.0117 1804 Browser (8ef0d5c41ec907751b8429162b1239ed) C:\Windows\System32\browser.dll
05:34:53.0172 1804 Browser - ok
05:34:53.0333 1804 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
05:34:53.0365 1804 Brserid - ok
05:34:53.0491 1804 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
05:34:53.0538 1804 BrSerWdm - ok
05:34:53.0662 1804 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
05:34:53.0694 1804 BrUsbMdm - ok
05:34:53.0772 1804 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
05:34:53.0803 1804 BrUsbSer - ok
05:34:53.0928 1804 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
05:34:53.0959 1804 BTHMODEM - ok
05:34:54.0064 1804 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
05:34:54.0108 1804 bthserv - ok
05:34:54.0112 1804 catchme - ok
05:34:54.0264 1804 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
05:34:54.0317 1804 cdfs - ok
05:34:54.0462 1804 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
05:34:54.0496 1804 cdrom - ok
05:34:54.0593 1804 CertPropSvc (f17d1d393bbc69c5322fbfafaca28c7f) C:\Windows\System32\certprop.dll
05:34:54.0645 1804 CertPropSvc - ok
05:34:54.0786 1804 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
05:34:54.0825 1804 circlass - ok
05:34:54.0961 1804 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
05:34:54.0988 1804 CLFS - ok
05:34:55.0125 1804 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
05:34:55.0157 1804 clr_optimization_v2.0.50727_32 - ok
05:34:55.0328 1804 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
05:34:55.0344 1804 clr_optimization_v2.0.50727_64 - ok
05:34:55.0531 1804 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
05:34:55.0547 1804 clr_optimization_v4.0.30319_32 - ok
05:34:55.0748 1804 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
05:34:55.0773 1804 clr_optimization_v4.0.30319_64 - ok
05:34:55.0927 1804 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
05:34:55.0959 1804 CmBatt - ok
05:34:56.0123 1804 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
05:34:56.0138 1804 cmdide - ok
05:34:56.0283 1804 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
05:34:56.0331 1804 CNG - ok
05:34:56.0530 1804 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
05:34:56.0556 1804 Compbatt - ok
05:34:56.0788 1804 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\DRIVERS\CompositeBus.sys
05:34:56.0819 1804 CompositeBus - ok
05:34:56.0913 1804 COMSysApp - ok
05:34:57.0053 1804 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
05:34:57.0069 1804 crcdisk - ok
05:34:57.0263 1804 CryptSvc (15597883fbe9b056f276ada3ad87d9af) C:\Windows\system32\cryptsvc.dll
05:34:57.0315 1804 CryptSvc - ok
05:34:57.0479 1804 DcomLaunch (5c627d1b1138676c0a7ab2c2c190d123) C:\Windows\system32\rpcss.dll
05:34:57.0537 1804 DcomLaunch - ok
05:34:57.0677 1804 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
05:34:57.0736 1804 defragsvc - ok
05:34:57.0899 1804 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
05:34:57.0960 1804 DfsC - ok
05:34:58.0100 1804 Dhcp (43d808f5d9e1a18e5eeb5ebc83969e4e) C:\Windows\system32\dhcpcore.dll
05:34:58.0155 1804 Dhcp - ok
05:34:58.0295 1804 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
05:34:58.0357 1804 discache - ok
05:34:58.0498 1804 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
05:34:58.0529 1804 Disk - ok
05:34:58.0638 1804 Dnscache (16835866aaa693c7d7fceba8fff706e4) C:\Windows\System32\dnsrslvr.dll
05:34:58.0669 1804 Dnscache - ok
05:34:58.0848 1804 dot3svc (b1fb3ddca0fdf408750d5843591afbc6) C:\Windows\System32\dot3svc.dll
05:34:58.0904 1804 dot3svc - ok
05:34:59.0045 1804 DPS (b26f4f737e8f9df4f31af6cf31d05820) C:\Windows\system32\dps.dll
05:34:59.0102 1804 DPS - ok
05:34:59.0234 1804 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
05:34:59.0254 1804 drmkaud - ok
05:34:59.0515 1804 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
05:34:59.0554 1804 DXGKrnl - ok
05:34:59.0680 1804 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
05:34:59.0724 1804 EapHost - ok
05:35:00.0129 1804 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
05:35:00.0176 1804 ebdrv - ok
05:35:00.0326 1804 EFS (c118a82cd78818c29ab228366ebf81c3) C:\Windows\System32\lsass.exe
05:35:00.0356 1804 EFS - ok
05:35:00.0538 1804 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
05:35:00.0577 1804 elxstor - ok
05:35:00.0732 1804 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
05:35:00.0807 1804 ErrDev - ok
05:35:01.0004 1804 ETD (1299d1ea00b7a4bf69c5869dca31e0f6) C:\Windows\system32\DRIVERS\ETD.sys
05:35:01.0033 1804 ETD - ok
05:35:01.0209 1804 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
05:35:01.0257 1804 EventSystem - ok
05:35:01.0407 1804 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
05:35:01.0459 1804 exfat - ok
05:35:01.0627 1804 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
05:35:01.0689 1804 fastfat - ok
05:35:01.0879 1804 Fax (dbefd454f8318a0ef691fdd2eaab44eb) C:\Windows\system32\fxssvc.exe
05:35:01.0918 1804 Fax - ok
05:35:02.0073 1804 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
05:35:02.0107 1804 fdc - ok
05:35:02.0232 1804 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
05:35:02.0285 1804 fdPHost - ok
05:35:02.0424 1804 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
05:35:02.0479 1804 FDResPub - ok
05:35:02.0584 1804 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
05:35:02.0607 1804 FileInfo - ok
05:35:02.0665 1804 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
05:35:02.0714 1804 Filetrace - ok
05:35:02.0896 1804 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
05:35:03.0052 1804 flpydisk - ok
05:35:03.0333 1804 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
05:35:03.0348 1804 FltMgr - ok
05:35:03.0580 1804 FontCache (5c4cb4086fb83115b153e47add961a0c) C:\Windows\system32\FntCache.dll
05:35:03.0616 1804 FontCache - ok
05:35:03.0779 1804 FontCache3.0.0.0 (a8b7f3818ab65695e3a0bb3279f6dce6) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
05:35:03.0800 1804 FontCache3.0.0.0 - ok
05:35:03.0977 1804 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
05:35:04.0003 1804 FsDepends - ok
05:35:04.0246 1804 fssfltr (6c06701bf1db05405804d7eb610991ce) C:\Windows\system32\DRIVERS\fssfltr.sys
05:35:04.0261 1804 fssfltr - ok
05:35:04.0508 1804 fsssvc (40cdfad174b3d5e80f95dda003c0b97f) C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
05:35:04.0570 1804 fsssvc - ok
05:35:04.0757 1804 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
05:35:04.0788 1804 Fs_Rec - ok
05:35:04.0929 1804 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
05:35:04.0971 1804 fvevol - ok
05:35:05.0153 1804 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
05:35:05.0169 1804 gagp30kx - ok
05:35:05.0297 1804 GGSAFERDriver - ok
05:35:05.0616 1804 gpsvc (277bbc7e1aa1ee957f573a10eca7ef3a) C:\Windows\System32\gpsvc.dll
05:35:05.0670 1804 gpsvc - ok
05:35:05.0864 1804 gupdate (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
05:35:05.0878 1804 gupdate - ok
05:35:05.0899 1804 gupdatem (f02a533f517eb38333cb12a9e8963773) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
05:35:05.0912 1804 gupdatem - ok
05:35:06.0030 1804 gusvc (cc839e8d766cc31a7710c9f38cf3e375) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
05:35:06.0046 1804 gusvc - ok
05:35:06.0202 1804 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
05:35:06.0233 1804 hcw85cir - ok
05:35:06.0404 1804 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
05:35:06.0451 1804 HdAudAddService - ok
05:35:06.0598 1804 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\DRIVERS\HDAudBus.sys
05:35:06.0622 1804 HDAudBus - ok
05:35:06.0758 1804 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
05:35:06.0796 1804 HidBatt - ok
05:35:07.0028 1804 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
05:35:07.0066 1804 HidBth - ok
05:35:07.0331 1804 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
05:35:07.0368 1804 HidIr - ok
05:35:07.0478 1804 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
05:35:07.0507 1804 hidserv - ok
05:35:07.0663 1804 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
05:35:07.0709 1804 HidUsb - ok
05:35:07.0865 1804 hkmsvc (387e72e739e15e3d37907a86d9ff98e2) C:\Windows\system32\kmsvc.dll
05:35:07.0928 1804 hkmsvc - ok
05:35:08.0102 1804 HomeGroupListener (efdfb3dd38a4376f93e7985173813abd) C:\Windows\system32\ListSvc.dll
05:35:08.0132 1804 HomeGroupListener - ok
05:35:08.0280 1804 HomeGroupProvider (908acb1f594274965a53926b10c81e89) C:\Windows\system32\provsvc.dll
05:35:08.0312 1804 HomeGroupProvider - ok
05:35:08.0496 1804 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\DRIVERS\HpSAMD.sys
05:35:08.0526 1804 HpSAMD - ok
05:35:08.0741 1804 hshld (575546ee9a39dd5cb3b4e34a146a8a3e) C:\Program Files (x86)\Hotspot Shield\bin\openvpnas.exe
05:35:08.0775 1804 hshld - ok
05:35:08.0938 1804 HssDrv (a60c877e1cd3aa2e4e5ccd8af305c0f1) C:\Windows\system32\DRIVERS\HssDrv.sys
05:35:08.0964 1804 HssDrv - ok
05:35:09.0154 1804 HssSrv (2cfea9c337b699aca38487e8a7438f35) C:\Program Files (x86)\Hotspot Shield\HssWPR\hsssrv.exe
05:35:09.0185 1804 HssSrv - ok
05:35:09.0325 1804 HssTrayService (4efb7fc2a11db10ab6205206d60c432b) C:\Program Files (x86)\Hotspot Shield\bin\HssTrayService.EXE
05:35:09.0357 1804 HssTrayService - ok
05:35:09.0466 1804 HssWd - ok
05:35:09.0713 1804 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
05:35:09.0774 1804 HTTP - ok
05:35:09.0959 1804 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
05:35:09.0983 1804 hwpolicy - ok
05:35:10.0144 1804 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
05:35:10.0169 1804 i8042prt - ok
05:35:10.0330 1804 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\DRIVERS\iaStorV.sys
05:35:10.0366 1804 iaStorV - ok
05:35:10.0548 1804 idsvc (5988fc40f8db5b0739cd1e3a5d0d78bd) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
05:35:10.0585 1804 idsvc - ok
05:35:10.0739 1804 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
05:35:10.0754 1804 iirsp - ok
05:35:11.0019 1804 IKEEXT (fcd84c381e0140af901e58d48882d26b) C:\Windows\System32\ikeext.dll
05:35:11.0082 1804 IKEEXT - ok
05:35:11.0329 1804 IntcAzAudAddService (ef75c94792187a143871fbb87611b0b7) C:\Windows\system32\drivers\RTKVHD64.sys
05:35:11.0392 1804 IntcAzAudAddService - ok
05:35:11.0514 1804 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
05:35:11.0529 1804 intelide - ok
05:35:11.0635 1804 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
05:35:11.0680 1804 intelppm - ok
05:35:11.0807 1804 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
05:35:11.0855 1804 IPBusEnum - ok
 
#5 ·
Hello lechugas.

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

If there are any personal files, pics, etc. on your computer you cannot live without, back them up now just as a precaution.

Emergency Backup Procedure - Tech Support Forum

------------------------------------------------------

Please download ComboFix and Save it to your Desktop.

**Note: It is important that it is saved directly to your desktop**

------------------------------------------------------

Disable your antivirus and antispyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with ComboFix.

Get help here

Open Notepad and copy/paste all the text in the codebox below into Notepad:

Code:
DDS::
mStart Page = hxxp://www.bigseekpro.com/bsprpc/{D1B464FB-0E4E-4B90-9D1C-BF18DEEB8F15}
uInternet Settings,ProxyServer = socks=173.67.103.56:1010
uInternet Settings,ProxyOverride = <local>
Save this Notepad file as CFScript.txt to your Desktop and then close the file.





Referring to the picture above, drag CFScript onto ComboFix

Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

Please re-enable your antivirus before posting the ComboFix.txt log.

If you get an 'Illegal operation attempted on a Registry key which has been marked for deletion' error message, please reboot your machine.

------------------------------------------------------
 
#6 ·
Still with us, lechugas? I generally unsubscribe from threads after 3 days of inactivity. If you do not reply within 24 hours, this thread will be closed.

------------------------------------------------------
 
#7 ·
Due to lack of response, this topic will now be closed. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:

IMPORTANT - Read This Before Posting For Malware Removal Help

------------------------------------------------------
 
Status
Not open for further replies.
You have insufficient privileges to reply here.
Top