smitfraud-c.generic

Status
Not open for further replies.

diane7

New member
This is my parents pc, they are in their 80s, the computer is their lifeline. I am not that savvy with tech stuff so please bear with me . Hope you can help as I am a bit unsure of what I am doing. I ran a check with spybot and found that smitfraud-c.genric but I can tell you this computer is a mess. It is barely running. Norton was of no help and they even came in but just ended up giving us a case number. When they ran the norton tool it showed no problems.


I have the attached.txt but it is not allowing me to compress it. Please advise. Thanks so much in advance for your time.


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 1.6.0_32
Run by member at 19:22:30 on 2013-02-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.5110.2277 [GMT -8:00]
.
AV: Norton 360 *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton 360 *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\connect.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
C:\Program Files (x86)\Belkin\Router Setup and Monitor\dlnaPlugin.exe
C:\Windows\system32\taskeng.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
C:\Windows\system32\wuauclt.exe
C:\PROGRA~2\MICROS~2\OFFICE11\OUTLOOK.EXE
\\.\globalroot\systemroot\svchost.exe -netsvcs
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uLocal Page = www.google.com
uSearch Bar = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com/
mLocal Page = hxxp://www.google.com/
mSearch Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/
mWinlogon: Userinit = userinit.exe
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: eGames Toolbar: {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\Program Files (x86)\eGames\egamestoolbar.dll
BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
BHO: Norton Identity Protection: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\CoIEPlg.dll
BHO: Norton Vulnerability Protection: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\IPS\IPSBHO.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
TB: Google Toolbar: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: ShopAtHome.com Toolbar: {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\member\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll
TB: eGames Toolbar: {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\Program Files (x86)\eGames\egamestoolbar.dll
TB: ShopAtHome.com Toolbar: {311B58DC-A4DC-4B04-B1B5-60299AD3D803} - C:\Users\member\AppData\Roaming\ShopAtHome\ShopAtHomeToolbar\tbcore3U.dll
TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\CoIEPlg.dll
uRun: [HP Officejet 4620 series (NET)] "C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN29R210JY05RT:NW" -scfn "HP Officejet 4620 series (NET)" -AutoStart 1
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
mRun: [InstaLAN] "C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
StartupFolder: C:\Users\member\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ERUNTA~1.LNK - C:\Windows\Speech\ERUNTcorrectone\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect119b.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{EA537523-3F90-44BF-960A-440561B31138} : DHCPNameServer = 192.168.2.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.97\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt
x64-mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cndt
x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\member\AppData\Roaming\Mozilla\Firefox\Profiles\p8ye63aw.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?l=dis&o=16148
FF - prefs.js: keyword.URL - hxxp://urlseek10.vmn.net/search.php?type=dns&tbn=egames3_1dn&q=
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll
FF - plugin: C:\Windows\SysWOW64\npdeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - ExtSQL: 2013-02-25 15:20; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\coFFPlgn
FF - ExtSQL: 2013-02-25 18:43; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\IPSFFPlgn
.
============= SERVICES / DRIVERS ===============
.
R0 SMR311;Symantec SMR Utility Service 3.1.1;C:\Windows\System32\drivers\SMR311.SYS [2013-2-22 95392]
R0 SymDS;Symantec Data Store;C:\Windows\System32\drivers\N360x64\1401010.002\SymDS64.sys [2013-2-22 493216]
R0 SymEFA;Symantec Extended File Attributes;C:\Windows\System32\drivers\N360x64\1401010.002\SymEFA64.sys [2013-2-22 1132192]
R1 BHDrvx64;BHDrvx64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130208.001\BHDrvx64.sys [2013-2-8 1388120]
R1 ccSet_N360;Norton 360 Settings Manager;C:\Windows\System32\drivers\N360x64\1401010.002\ccSetx64.sys [2013-2-22 168096]
R1 IDSVia64;IDSVia64;C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130223.001\IDSviA64.sys [2013-2-25 513184]
R1 SymIRON;Symantec Iron Driver;C:\Windows\System32\drivers\N360x64\1401010.002\Ironx64.sys [2013-2-22 224416]
R1 SymNetS;Symantec Network Security WFP Driver;C:\Windows\System32\drivers\N360x64\1401010.002\symnets.sys [2013-2-22 432800]
R2 Belkin Local Backup Service;Belkin Local Backup Service;C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [2012-5-6 181760]
R2 Belkin Network USB Helper;Belkin Network USB Helper;C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [2012-5-6 55296]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-6-17 13336]
R2 IntuitUpdateServiceV4;Intuit Update Service v4;C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-8-23 13672]
R2 N360;Norton 360;C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\ccSvcHst.exe [2013-2-22 143928]
R2 sxuptp;SXUPTP Driver;C:\Windows\System32\drivers\sxuptp.sys [2012-5-6 291352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-2-23 138912]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-9-9 233472]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 PCPitstop Scheduling;PCPitstop Scheduling;C:\Program Files (x86)\PCPitstop\PCPitstopScheduleService.exe [2011-4-5 91304]
S3 rcmirror;rcmirror;C:\Windows\System32\drivers\rcmirror.sys [2010-1-18 4608]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;C:\Windows\System32\drivers\wg111v3.sys [2010-5-16 446976]
S3 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-1-31 3289208]
S3 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-7-1 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-6 1255736]
.
=============== Created Last 30 ================
.
2013-02-23 04:16:04 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2013-02-23 02:57:45 177312 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2013-02-23 02:57:45 -------- d-----w- C:\Program Files\Symantec
2013-02-23 02:57:45 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2013-02-23 02:57:18 776352 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\srtsp64.sys
2013-02-23 02:57:18 493216 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\SymDS64.sys
2013-02-23 02:57:18 432800 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\symnets.sys
2013-02-23 02:57:18 37496 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\srtspx64.sys
2013-02-23 02:57:18 23448 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\SymELAM.sys
2013-02-23 02:57:18 224416 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\Ironx64.sys
2013-02-23 02:57:18 168096 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\ccSetx64.sys
2013-02-23 02:57:18 1132192 ----a-r- C:\Windows\System32\drivers\N360x64\1401010.002\SymEFA64.sys
2013-02-23 02:56:54 -------- d-----w- C:\Windows\System32\drivers\N360x64\1401010.002
2013-02-23 02:56:52 -------- d-----w- C:\Program Files (x86)\Norton 360
2013-02-23 02:56:46 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2013-02-23 01:46:47 95392 ----a-w- C:\Windows\System32\drivers\SMR311.SYS
2013-02-23 01:30:54 20480 ----a-w- C:\Windows\svchost.exe
2013-02-21 05:58:12 7168 ----a-w- C:\ProgramData\Microsoft\Windows\DRM\2E27.tmp
2013-02-21 05:58:12 7168 ----a-w- C:\ProgramData\Microsoft\Windows\DRM\2E17.tmp
2013-02-14 08:03:20 996352 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-14 08:03:20 768000 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2013-02-14 06:54:00 5553512 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-02-14 06:53:59 3967848 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-02-14 06:53:59 3913064 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-02-14 06:53:56 3153408 ----a-w- C:\Windows\System32\win32k.sys
2013-02-14 06:53:55 215040 ----a-w- C:\Windows\System32\winsrv.dll
2013-02-14 06:53:54 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-02-14 06:53:54 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-02-14 06:53:54 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-02-14 06:53:54 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-02-14 06:53:54 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-02-14 06:53:52 288088 ----a-w- C:\Windows\System32\drivers\FWPKCLNT.SYS
2013-02-14 06:53:52 1913192 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
==================== Find3M ====================
.
2013-02-17 08:16:02 71024 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-02-17 08:16:02 691568 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-01-09 01:19:09 2312704 ----a-w- C:\Windows\System32\jscript9.dll
2013-01-09 01:12:03 1392128 ----a-w- C:\Windows\System32\wininet.dll
2013-01-09 01:11:06 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl
2013-01-09 01:07:51 173056 ----a-w- C:\Windows\System32\ieUnatt.exe
2013-01-09 01:07:47 599040 ----a-w- C:\Windows\System32\vbscript.dll
2013-01-09 01:04:42 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2013-01-08 22:11:21 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-01-08 22:03:20 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-01-08 22:03:12 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-01-08 21:59:02 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-01-08 21:58:29 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll
2013-01-08 21:56:23 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-01-04 04:43:21 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2012-12-16 17:11:22 46080 ----a-w- C:\Windows\System32\atmlib.dll
2012-12-16 14:45:03 367616 ----a-w- C:\Windows\System32\atmfd.dll
2012-12-16 14:13:28 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll
2012-12-16 14:13:20 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2012-12-07 13:20:16 441856 ----a-w- C:\Windows\System32\Wpc.dll
2012-12-07 13:15:31 2746368 ----a-w- C:\Windows\System32\gameux.dll
2012-12-07 12:26:17 308736 ----a-w- C:\Windows\SysWow64\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- C:\Windows\SysWow64\gameux.dll
2012-12-07 11:20:04 30720 ----a-w- C:\Windows\System32\usk.rs
2012-12-07 11:20:03 43520 ----a-w- C:\Windows\System32\csrr.rs
2012-12-07 11:20:03 23552 ----a-w- C:\Windows\System32\oflc.rs
2012-12-07 11:20:01 45568 ----a-w- C:\Windows\System32\oflc-nz.rs
2012-12-07 11:20:01 44544 ----a-w- C:\Windows\System32\pegibbfc.rs
2012-12-07 11:20:01 20480 ----a-w- C:\Windows\System32\pegi-fi.rs
2012-12-07 11:20:00 20480 ----a-w- C:\Windows\System32\pegi-pt.rs
2012-12-07 11:19:59 20480 ----a-w- C:\Windows\System32\pegi.rs
2012-12-07 11:19:58 46592 ----a-w- C:\Windows\System32\fpb.rs
2012-12-07 11:19:57 40960 ----a-w- C:\Windows\System32\cob-au.rs
2012-12-07 11:19:57 21504 ----a-w- C:\Windows\System32\grb.rs
2012-12-07 11:19:57 15360 ----a-w- C:\Windows\System32\djctq.rs
2012-12-07 11:19:56 55296 ----a-w- C:\Windows\System32\cero.rs
2012-12-07 11:19:55 51712 ----a-w- C:\Windows\System32\esrb.rs
2012-11-30 05:45:35 362496 ----a-w- C:\Windows\System32\wow64win.dll
2012-11-30 05:45:35 243200 ----a-w- C:\Windows\System32\wow64.dll
2012-11-30 05:45:35 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2012-11-30 05:43:12 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2012-11-30 05:41:07 424448 ----a-w- C:\Windows\System32\KernelBase.dll
2012-11-30 04:53:59 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2012-11-30 03:23:48 338432 ----a-w- C:\Windows\System32\conhost.exe
2012-11-30 02:38:59 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-02-04 18:18:40 689552 ----a-w- C:\Program Files (x86)\2pUninstall Coupon Alert.dll
2012-02-04 18:18:40 161720 ----a-w- C:\Program Files (x86)\2pres.dll
2011-03-19 22:50:01 684032 ----a-w- C:\Program Files (x86)\Uninstall Coupon Alert.dll
.
============= FINISH: 19:23:14.72 ===============
 
Hello diane7 and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

I am not that savvy with tech stuff so please bear with me
Thats no problem whatsoever. If there is anything you are not sure about just ask - its what I am here for :)

I can definitely see malware on this machine but before we begin any fixing I will need a little more information.

Please describe as best you can exactly what symptoms the machine is displaying. Is it just running slow? Are you being redirected when you connect to the net? Are there any error messages?

I have the attached.txt but it is not allowing me to compress it. Please advise.
There is no need to attach any logs, just post them directly into your replies like you did with the dds.txt log.

As well as reviewing the log you tried to attach, I would also like to see the reports from the following tools:


  1. aswMBR

    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes.
    • Click the "Scan" button to start scan.

    aswMBR1.png

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    aswMBR2.png



    The following tool may give you the option of deleting/curing anything that is detected. At this time please DO NOT allow the machine to cure or remove anything (I would like to review the report first before we do anything).

  2. TDSS Killer

    • [*]Please read carefully and follow these steps.
    • Download TDSSKiller and save it to your Desktop.
    • Extract its contents to your desktop.
    • Once extracted, open the TDSSKiller folder and Right click on TDSSKiller.exe and select "Run as Administrator" to run the application.
    • When the window opens, click on Change Parameters.
    • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”.
    • Click on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on SKIP.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

    Please describe the machines main symptoms and post the DDS attach.txt log, the aswMBR log and the TDSSKiller log in your next reply. If you need to make more than one post to fit all of the information in go right ahead.

    If you encounter any difficulties just come back here and let me know :)
 
Thank you Jon Tom for your assistance and patience. The computer has toolbars and unwanted stuff that just start downloading things like shopathome junk while I was preparing the logs for you. I knew this because Norton would present the stuff as safe. It is slow beyond belief and the font on one of the user accounts that my mom uses is completely gone or messed up to the point I cant even get any settings to change. Per your request here is the other log:

THANK YOU!!!!!
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 12/11/2009 11:32:52 AM
System Uptime: 2/26/2013 1:00:52 PM (6 hours ago)
.
Motherboard: PEGATRON CORPORATION | | Benicia
Processor: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz | CPU 1 | 2600/800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 454 GiB total, 394.539 GiB free.
D: is FIXED (NTFS) - 12 GiB total, 2.167 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: SM/xD-Picture
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SM#XD-PICTURE&REV_1.02#058F63626476&2#
Manufacturer: Generic-
Name: H:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SM#XD-PICTURE&REV_1.02#058F63626476&2#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: Compact Flash
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.01#058F63626476&1#
Manufacturer: Generic-
Name: G:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_COMPACT_FLASH&REV_1.01#058F63626476&1#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: MS/MS-Pro
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_MS#MS-PRO&REV_1.03#058F63626476&3#
Manufacturer: Generic-
Name: I:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_MS#MS-PRO&REV_1.03#058F63626476&3#
Service: WUDFRd
.
Class GUID: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Description: SD/MMC
Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SD#MMC&REV_1.00#058F63626476&0#
Manufacturer: Generic-
Name: F:\
PNP Device ID: WPDBUSENUMROOT\UMB\2&37C186B&1&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_GENERIC-&PROD_SD#MMC&REV_1.00#058F63626476&0#
Service: WUDFRd
.
==== System Restore Points ===================
.
RP494: 2/12/2013 2:09:04 PM - Scheduled Checkpoint
RP495: 2/14/2013 12:01:17 AM - Windows Update
RP496: 2/14/2013 4:03:10 PM - Installed TurboTax 2012 wcaiper
RP497: 2/15/2013 11:59:15 PM - Norton 360 Registry Clean
RP498: 2/23/2013 3:18:11 AM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
3Dice Casino
Acrobat.com
Activate Norton Online Backup
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.2
Adobe Shockwave Player 11.5
Bejeweled 2 Deluxe
Bejeweled 3
Belkin Setup and Router Monitor
Belkin USB Print and Storage Center
Best of Slots II
Big Fish Games: Game Manager
CCleaner
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
CyberLink DVD Suite Deluxe
DirectX for Managed Code Update (Summer 2004)
eGames GameButler
eGames Toolbar
ERUNT 1.1j
Facebook Video Calling 1.2.0.159
FreeCell Wonderland
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Hallmark Card Studio 2
Hardware Diagnostic Tools
Hewlett-Packard ACLM.NET v1.2.1.1
Homepage Protection
HP Advisor
HP Customer Experience Enhancements
HP Games
HP MAINSTREAM KEYBOARD
HP MediaSmart Demo
HP MediaSmart DVD
HP MediaSmart Movie Themes
HP MediaSmart Music/Photo/Video
HP MediaSmart SmartMenu
HP Odometer
HP Officejet 4620 series Basic Device Software
HP Officejet 4620 series Help
HP Officejet 4620 series Product Improvement Study
HP Photo Creations
HP Product Detection
HP Remote Solution
HP Setup
HP Support Assistant
HP Support Information
HP Update
I.R.I.S. OCR
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
Internet Explorer (Enable DEP)
iSEEK AnswerWorks English Runtime
J2SE Runtime Environment 5.0
Java Auto Updater
Java(TM) 6 Update 32
LabelPrint
LightScribe System Software
Mahjong Escape (TM) - Ancient Japan
Mahjong Escape: Ancient China 1.0.0.5
Mahjongg Dimensions
Mahjongg Dimensions Deluxe (tb) (remove only)
Mahjongg Master Egyptian Edition
Masque Slots
Microsoft .NET Framework 1.1
Microsoft .NET Framework 4 Client Profile
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 60 day trial
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Mozilla Firefox 13.0.1 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NETGEAR WG111v3 wireless USB 2.0 adapter
Norton 360
Pando Media Booster
PC Matic 1.1.0.36
PictureMover
Playalot Games
Power2Go
PowerDirector
PowerRecover
Quicken 2001 Deluxe
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
ShopAtHome.com Helper
ShopAtHome.com Toolbar
Sierra Utilities
Skype Click to Call
Skype™ 5.10
Slots from Bally Gaming
SnapShot
Solitaire Master 4
Spybot - Search & Destroy
System Checkup 3.1
System Requirements Lab for Intel
The Weather Channel Desktop 6
TurboTax 2009
TurboTax 2009 wcaiper
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wrapper
TurboTax 2010
TurboTax 2010 wcaiper
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wrapper
TurboTax 2011
TurboTax 2011 wcaiper
TurboTax 2011 WinPerFedFormset
TurboTax 2011 WinPerReleaseEngine
TurboTax 2011 WinPerTaxSupport
TurboTax 2011 wrapper
TurboTax 2012
TurboTax 2012 wcaiper
TurboTax 2012 WinPerFedFormset
TurboTax 2012 WinPerReleaseEngine
TurboTax 2012 WinPerTaxSupport
TurboTax 2012 wrapper
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Video Mover
Web Publishing Wizard
.
==== Event Viewer Messages From Past Week ========
.
2/26/2013 12:02:04 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002ca626b, 0x0000000000000000, 0x000007fffffa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022613-33290-01.
2/26/2013 1:01:17 PM, Error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: This driver has been blocked from loading
2/26/2013 1:01:17 PM, Error: Application Popup [1060] - \SystemRoot\SysWow64\Drivers\mrtRate.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
2/25/2013 11:58:41 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa8007814bb0, 0x0000000000000000, 0x000000007efa8000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022513-48703-01.
2/24/2013 10:32:51 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff80002cfee45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022413-46956-01.
2/24/2013 10:30:26 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Software Protection service to connect.
2/24/2013 10:30:26 PM, Error: Service Control Manager [7000] - The Software Protection service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/24/2013 10:29:39 PM, Error: Service Control Manager [7022] - The Intuit Update Service v4 service hung on starting.
2/23/2013 3:06:06 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff80002cf6e45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022313-19936-01.
2/22/2013 7:30:24 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000600dd, 0x0000000000000002, 0x0000000000000001, 0xfffff80002cbee45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-21980-01.
2/22/2013 7:24:31 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:18:47 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
2/22/2013 7:16:22 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx64 ccSet_N360 DfsC discache IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf
2/22/2013 7:16:22 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
2/22/2013 7:16:22 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:16:22 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:16:22 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:16:22 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:16:21 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:16:21 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
2/22/2013 7:16:21 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
2/22/2013 7:16:21 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/22/2013 7:16:21 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
2/22/2013 7:16:21 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa8007843bb0, 0x0000000000000000, 0x000000007efa8000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-25131-01.
2/22/2013 7:11:20 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
2/22/2013 7:11:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
2/22/2013 7:11:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
2/22/2013 7:11:14 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/22/2013 7:11:08 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
2/22/2013 7:10:36 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: BHDrvx64 ccSet_N360 discache IDSVia64 spldr SRTSPX SymIRON SymNetS Wanarpv6
2/22/2013 7:10:32 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000002000027ef, 0x0000000000000002, 0x0000000000000001, 0xfffff80002cf3e45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-25225-01.
2/22/2013 7:04:26 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa800796abb0, 0x0000000000000000, 0x000000007efa8000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-26020-01.
2/22/2013 6:55:54 PM, Error: Service Control Manager [7034] - The Intel(R) Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s).
2/22/2013 6:54:17 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
2/22/2013 6:54:17 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/22/2013 6:54:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
2/22/2013 6:52:19 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dd, 0x0000000000000002, 0x0000000000000001, 0xfffff80002d0de45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-28126-01.
2/22/2013 6:46:10 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002f8ccda, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-32479-01.
2/22/2013 6:02:45 PM, Error: Service Control Manager [7031] - The Norton 360 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
2/22/2013 5:31:14 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/22/2013 5:31:14 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
2/22/2013 4:56:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
2/22/2013 4:55:44 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx64 ccSet_N360 DfsC discache eeCtrl IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss spldr SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf
2/22/2013 4:44:50 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002fbacda, 0x0000000000000001, 0x0000000000000018). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-50294-01.
2/22/2013 4:31:13 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x00000000000000dc, 0x0000000000000002, 0x0000000000000001, 0xfffff80001f0ce45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022213-79841-01.
2/21/2013 12:07:25 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa80078b2bb0, 0x0000000000000000, 0x000000007efa8000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022113-19375-01.
2/21/2013 1:21:29 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002c8f1c8, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022113-22339-01.
2/21/2013 1:17:32 AM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000401cd010c, 0x0000000000000002, 0x0000000000000001, 0xfffff80002cefe45). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022113-23212-01.
2/20/2013 10:07:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff80002ca226b, 0x0000000000000000, 0x000000007efa0000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022013-19141-01.
2/20/2013 10:02:55 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffffa80078c4bb0, 0x0000000000000000, 0x000000007ef88000). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 022013-18033-01.
.
==== End Of File ===========================


aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-26 19:56:27
-----------------------------
19:56:27.627 OS Version: Windows x64 6.1.7601 Service Pack 1
19:56:27.627 Number of processors: 2 586 0x170A
19:56:27.628 ComputerName: MEMBER-PC UserName: member
19:56:31.016 Initialize success
20:21:37.789 AVAST engine defs: 13022601
20:23:42.482 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
20:23:42.486 Disk 0 Vendor: WDC_WD50 05.0 Size: 476940MB BusType: 8
20:23:42.491 Device \Driver\iaStor -> MajorFunction fffffa80078715e8
20:23:42.495 Disk 0 MBR read successfully
20:23:42.500 Disk 0 MBR scan
20:23:42.507 Disk 0 unknown MBR code
20:23:42.513 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:23:42.530 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 464654 MB offset 206848
20:23:42.562 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 12184 MB offset 951818240
20:23:42.601 Disk 0 scanning C:\Windows\system32\drivers
20:23:51.274 Service scanning
20:24:12.243 Modules scanning
20:24:12.256 Disk 0 trace - called modules:
20:24:12.263 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80078715e8]<<
20:24:12.271 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80052fd530]
20:24:12.278 3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004fe7050]
20:24:12.284 \Driver\iaStor[0xfffffa80077dfb70] -> IRP_MJ_CREATE -> 0xfffffa80078715e8
20:24:14.621 AVAST engine scan C:\Windows
20:24:17.192 AVAST engine scan C:\Windows\system32
20:27:34.618 AVAST engine scan C:\Windows\system32\drivers
20:27:56.069 AVAST engine scan C:\Users\member
20:29:53.361 File: C:\Users\member\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@arcadeweb.com\components\arcadewebfirefox.dll **INFECTED** Win32:Adware-gen [Adw]
20:30:13.153 AVAST engine scan C:\ProgramData
20:31:13.751 File: C:\ProgramData\Microsoft\Windows\DRM\2E17.tmp **INFECTED** Win32:Malware-gen
20:31:13.803 File: C:\ProgramData\Microsoft\Windows\DRM\2E27.tmp **INFECTED** Win32:Malware-gen
20:33:56.627 Scan finished successfully
20:34:30.411 Disk 0 MBR has been saved successfully to "C:\Users\member\Documents\MBR.dat"
20:34:30.420 The log file has been saved successfully to "C:\Users\member\Documents\aswMBR.txt"
 
Here is the last log you requested.

20:01:33.0859 2940 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:01:33.0984 2940 ============================================================
20:01:33.0984 2940 Current date / time: 2013/02/27 20:01:33.0984
20:01:33.0984 2940 SystemInfo:
20:01:33.0984 2940
20:01:33.0984 2940 OS Version: 6.1.7601 ServicePack: 1.0
20:01:33.0984 2940 Product type: Workstation
20:01:33.0984 2940 ComputerName: MEMBER-PC
20:01:33.0984 2940 UserName: member
20:01:33.0984 2940 Windows directory: C:\Windows
20:01:33.0984 2940 System windows directory: C:\Windows
20:01:33.0984 2940 Running under WOW64
20:01:33.0984 2940 Processor architecture: Intel x64
20:01:33.0984 2940 Number of processors: 2
20:01:33.0984 2940 Page size: 0x1000
20:01:33.0984 2940 Boot type: Normal boot
20:01:33.0984 2940 ============================================================
20:01:34.0967 2940 BG loaded
20:01:35.0731 2940 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:01:35.0747 2940 ============================================================
20:01:35.0747 2940 \Device\Harddisk0\DR0:
20:01:35.0747 2940 MBR partitions:
20:01:35.0747 2940 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:01:35.0747 2940 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x38B87000
20:01:35.0747 2940 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x38BB9800, BlocksNum 0x17CC000
20:01:35.0747 2940 ============================================================
20:01:35.0778 2940 C: <-> \Device\Harddisk0\DR0\Partition2
20:01:36.0698 2940 D: <-> \Device\Harddisk0\DR0\Partition3
20:01:36.0698 2940 ============================================================
20:01:36.0698 2940 Initialize success
20:01:36.0698 2940 ============================================================
 
Hello diane7

Thank you for the attach.txt and for aswMBR.

Was that all the TDSSKiller scan produced? It looks as though the log may have been cut off. Please re-check to see if there is any more of it to post in your next reply.

If there is'nt anything else there, just come back and let me know.
 
I believe there was more to it as well. As it was scanning Norton jumped in and quarantined something but as of now I dont see that report.
 
Hello diane7

As it was scanning Norton jumped in and quarantined something but as of now I dont see that report.
Thats okay, just temporarily disable your Norton product and re-run the TDSSKiller scan as described.

Information about how to disable N360 can be found here

Once the scan has completed, save the log then re-engage Norton, then come back here and post the log for me to review.

If you run into any trouble just let me know :)
 
Im having a problem. I cant copy and paste as its way to big per your limits and wont allow it. I tried to upload it and I got the same result. Im sorry I need more direction as to how I can get this to you. Much appreciated, di
 
Hello diane7

Im sorry I need more direction as to how I can get this to you.
No problem at all.

Simply copy and paste it piece by piece into multiple posts. If you need to make lots of posts thats fine.

If you need any further help just let me know :)
 
22:34:23.0181 6788 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:34:23.0714 6788 ============================================================
22:34:23.0714 6788 Current date / time: 2013/03/01 22:34:23.0714
22:34:23.0714 6788 SystemInfo:
22:34:23.0714 6788
22:34:23.0714 6788 OS Version: 6.1.7601 ServicePack: 1.0
22:34:23.0714 6788 Product type: Workstation
22:34:23.0714 6788 ComputerName: MEMBER-PC
22:34:23.0715 6788 UserName: member
22:34:23.0715 6788 Windows directory: C:\Windows
22:34:23.0715 6788 System windows directory: C:\Windows
22:34:23.0715 6788 Running under WOW64
22:34:23.0715 6788 Processor architecture: Intel x64
22:34:23.0715 6788 Number of processors: 2
22:34:23.0715 6788 Page size: 0x1000
22:34:23.0715 6788 Boot type: Normal boot
22:34:23.0715 6788 ============================================================
22:34:24.0090 6788 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:34:24.0106 6788 ============================================================
22:34:24.0106 6788 \Device\Harddisk0\DR0:
22:34:24.0106 6788 MBR partitions:
22:34:24.0106 6788 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
22:34:24.0106 6788 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x38B87000
22:34:24.0106 6788 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x38BB9800, BlocksNum 0x17CC000
22:34:24.0106 6788 ============================================================
22:34:24.0135 6788 C: <-> \Device\Harddisk0\DR0\Partition2
22:34:24.0172 6788 D: <-> \Device\Harddisk0\DR0\Partition3
22:34:24.0172 6788 ============================================================
22:34:24.0172 6788 Initialize success
22:34:24.0172 6788 ============================================================
22:34:31.0320 5884 ============================================================
22:34:31.0320 5884 Scan started
22:34:31.0320 5884 Mode: Manual; TDLFS;
22:34:31.0320 5884 ============================================================
22:34:31.0511 5884 ================ Scan system memory ========================
22:34:31.0511 5884 System memory - ok
22:34:31.0512 5884 ================ Scan services =============================
22:34:31.0657 5884 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:34:31.0661 5884 1394ohci - ok
22:34:31.0677 5884 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:34:31.0682 5884 ACPI - ok
22:34:31.0708 5884 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:34:31.0710 5884 AcpiPmi - ok
22:34:31.0823 5884 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc
 
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:34:31.0825 5884 AdobeFlashPlayerUpdateSvc - ok
22:34:31.0861 5884 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
22:34:31.0869 5884 adp94xx - ok
22:34:31.0898 5884 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
22:34:31.0904 5884 adpahci - ok
22:34:31.0914 5884 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
22:34:31.0918 5884 adpu320 - ok
22:34:31.0943 5884 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:34:31.0944 5884 AeLookupSvc - ok
22:34:31.0995 5884 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
22:34:32.0003 5884 AFD - ok
22:34:32.0104 5884 [ 23E7CB4641B93CE8591D1057670A4F04 ] AffinegyService C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
22:34:32.0134 5884 AffinegyService - ok
22:34:32.0175 5884 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
22:34:32.0176 5884 agp440 - ok
22:34:32.0191 5884 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
22:34:32.0193 5884 ALG - ok
22:34:32.0219 5884 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
22:34:32.0220 5884 aliide - ok
22:34:32.0232 5884 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
22:34:32.0234 5884 amdide - ok
22:34:32.0249 5884 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:34:32.0251 5884 AmdK8 - ok
22:34:32.0257 5884 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
22:34:32.0259 5884 AmdPPM - ok
22:34:32.0281 5884 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:34:32.0283 5884 amdsata - ok
22:34:32.0306 5884 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
22:34:32.0309 5884 amdsbs - ok
22:34:32.0330 5884 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:34:32.0331 5884 amdxata - ok
22:34:32.0373 5884 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
22:34:32.0375 5884 AppID - ok
22:34:32.0396 5884 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:34:32.0409 5884 AppIDSvc - ok
22:34:32.0434 5884 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
22:34:32.0436 5884 Appinfo - ok
22:34:32.0460 5884 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
22:34:32.0462 5884 arc - ok
22:34:32.0479 5884 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
22:34:32.0481 5884 arcsas - ok
22:34:32.0534 5884 aspnet_state - ok
22:34:32.0570 5884 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:34:32.0571 5884 AsyncMac - ok
22:34:32.0614 5884 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
22:34:32.0615 5884 atapi - ok
22:34:32.0666 5884 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:34:32.0675 5884 AudioEndpointBuilder - ok
22:34:32.0691 5884 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
22:34:32.0699 5884 AudioSrv - ok
22:34:32.0740 5884 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:34:32.0743 5884 AxInstSV - ok
22:34:32.0775 5884 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
22:34:32.0783 5884 b06bdrv - ok
22:34:32.0823 5884 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
22:34:32.0826 5884 b57nd60a - ok
22:34:32.0859 5884 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
22:34:32.0861 5884 BDESVC - ok
22:34:32.0877 5884 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
22:34:32.0878 5884 Beep - ok
22:34:32.0964 5884 [ 9BB84C554D7429F0A2CDF4EA1836F233 ] Belkin Local Backup Service C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
22:34:32.0966 5884 Belkin Local Backup Service - ok
22:34:32.0998 5884 [ E62A04D615A8CAC83601E1F07C010D3C ] Belkin Network USB Helper C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
22:34:32.0999 5884 Belkin Network USB Helper - ok
22:34:33.0055 5884 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
22:34:33.0065 5884 BFE - ok
22:34:33.0226 5884 [ 866335C9C0E6733C753FB472C539A6B9 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130208.001\BHDrvx64.sys
22:34:33.0240 5884 BHDrvx64 - ok
22:34:33.0301 5884 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
22:34:33.0316 5884 BITS - ok
22:34:33.0348 5884 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:34:33.0350 5884 blbdrive - ok
22:34:33.0375 5884 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:34:33.0377 5884 bowser - ok
22:34:33.0397 5884 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:34:33.0399 5884 BrFiltLo - ok
22:34:33.0412 5884 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:34:33.0413 5884 BrFiltUp - ok
22:34:33.0451 5884 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
22:34:33.0454 5884 Browser - ok
22:34:33.0480 5884 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:34:33.0485 5884 Brserid - ok
22:34:33.0493 5884 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:34:33.0495 5884 BrSerWdm - ok
22:34:33.0528 5884 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:34:33.0529 5884 BrUsbMdm - ok
22:34:33.0534 5884 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:34:33.0535 5884 BrUsbSer - ok
22:34:33.0545 5884 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
22:34:33.0547 5884 BTHMODEM - ok
22:34:33.0567 5884 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
22:34:33.0569 5884 bthserv - ok
22:34:33.0628 5884 [ A5C13600F63EB92F8D15123D64BA9895 ] ccSet_N360 C:\Windows\system32\drivers\N360x64\1401010.002\ccSetx64.sys
22:34:33.0630 5884 ccSet_N360 - ok
22:34:33.0658 5884 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:34:33.0660 5884 cdfs - ok
22:34:33.0692 5884 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
22:34:33.0695 5884 cdrom - ok
22:34:33.0733 5884 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
22:34:33.0735 5884 CertPropSvc - ok
22:34:33.0745 5884 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
22:34:33.0746 5884 circlass - ok
22:34:33.0779 5884 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
22:34:33.0784 5884 CLFS - ok
22:34:33.0807 5884 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:34:33.0809 5884 clr_optimization_v2.0.50727_32 - ok
22:34:33.0853 5884 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:34:33.0855 5884 clr_optimization_v2.0.50727_64 - ok
22:34:33.0919 5884 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:34:33.0921 5884 clr_optimization_v4.0.30319_32 - ok
22:34:33.0947 5884 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:34:33.0949 5884 clr_optimization_v4.0.30319_64 - ok
22:34:33.0966 5884 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:34:33.0968 5884 CmBatt - ok
22:34:33.0996 5884 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:34:33.0997 5884 cmdide - ok
22:34:34.0025 5884 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
22:34:34.0032 5884 CNG - ok
22:34:34.0040 5884 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:34:34.0042 5884 Compbatt - ok
22:34:34.0071 5884 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
22:34:34.0072 5884 CompositeBus - ok
22:34:34.0082 5884 COMSysApp - ok
22:34:34.0113 5884 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
22:34:34.0114 5884 crcdisk - ok
22:34:34.0160 5884 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:34:34.0162 5884 CryptSvc - ok
22:34:34.0201 5884 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
22:34:34.0210 5884 DcomLaunch - ok
22:34:34.0233 5884 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
22:34:34.0237 5884 defragsvc - ok
22:34:34.0276 5884 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:34:34.0277 5884 DfsC - ok
22:34:34.0322 5884 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
22:34:34.0327 5884 Dhcp - ok
22:34:34.0352 5884 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
22:34:34.0353 5884 discache - ok
22:34:34.0376 5884 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
22:34:34.0378 5884 Disk - ok
22:34:34.0407 5884 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:34:34.0411 5884 Dnscache - ok
22:34:34.0439 5884 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
22:34:34.0444 5884 dot3svc - ok
22:34:34.0473 5884 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
22:34:34.0476 5884 DPS - ok
22:34:34.0508 5884 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:34:34.0509 5884 drmkaud - ok
22:34:34.0548 5884 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:34:34.0557 5884 DXGKrnl - ok
22:34:34.0579 5884 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
22:34:34.0581 5884 EapHost - ok
22:34:34.0656 5884 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
22:34:34.0744 5884 ebdrv - ok
22:34:34.0814 5884 [ 4353FF94D47A0A9D52B89ECCF0CDB013 ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
22:34:34.0819 5884 eeCtrl - ok
22:34:34.0845 5884 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
22:34:34.0847 5884 EFS - ok
22:34:34.0895 5884 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:34:34.0905 5884 ehRecvr - ok
22:34:34.0942 5884 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
22:34:34.0944 5884 ehSched - ok
22:34:34.0988 5884 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
22:34:34.0996 5884 elxstor - ok
22:34:35.0042 5884 [ C5BCCB378D0A896304A3E71BE7215983 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
22:34:35.0044 5884 EraserUtilRebootDrv - ok
22:34:35.0074 5884 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:34:35.0075 5884 ErrDev - ok
22:34:35.0112 5884 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
22:34:35.0115 5884 EventSystem - ok
22:34:35.0140 5884 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
22:34:35.0142 5884 exfat - ok
22:34:35.0149 5884 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:34:35.0152 5884 fastfat - ok
22:34:35.0188 5884 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
22:34:35.0199 5884 Fax - ok
22:34:35.0228 5884 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:34:35.0230 5884 fdc - ok
22:34:35.0243 5884 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
22:34:35.0245 5884 fdPHost - ok
22:34:35.0259 5884 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
22:34:35.0261 5884 FDResPub - ok
22:34:35.0271 5884 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:34:35.0272 5884 FileInfo - ok
22:34:35.0282 5884 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:34:35.0283 5884 Filetrace - ok
22:34:35.0295 5884 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:34:35.0296 5884 flpydisk - ok
22:34:35.0326 5884 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:34:35.0329 5884 FltMgr - ok
22:34:35.0385 5884 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
22:34:35.0399 5884 FontCache - ok
 
22:34:35.0472 5884 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:34:35.0473 5884 FontCache3.0.0.0 - ok
22:34:35.0481 5884 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:34:35.0483 5884 FsDepends - ok
22:34:35.0512 5884 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:34:35.0513 5884 Fs_Rec - ok
22:34:35.0551 5884 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:34:35.0555 5884 fvevol - ok
22:34:35.0575 5884 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
22:34:35.0577 5884 gagp30kx - ok
22:34:35.0624 5884 [ 81C1EB203DD3F0C111FE2086BADA2D67 ] GameConsoleService C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe
22:34:35.0628 5884 GameConsoleService - ok
22:34:35.0665 5884 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
22:34:35.0676 5884 gpsvc - ok
22:34:35.0763 5884 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:34:35.0764 5884 gupdate - ok
22:34:35.0775 5884 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:34:35.0777 5884 gupdatem - ok
22:34:35.0826 5884 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
22:34:35.0830 5884 gusvc - ok
22:34:35.0853 5884 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:34:35.0854 5884 hcw85cir - ok
22:34:35.0881 5884 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
22:34:35.0883 5884 HDAudBus - ok
22:34:35.0890 5884 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
22:34:35.0892 5884 HidBatt - ok
22:34:35.0917 5884 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
22:34:35.0919 5884 HidBth - ok
22:34:35.0925 5884 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
22:34:35.0926 5884 HidIr - ok
22:34:35.0954 5884 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
22:34:35.0955 5884 hidserv - ok
22:34:35.0981 5884 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:34:35.0983 5884 HidUsb - ok
22:34:36.0013 5884 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
22:34:36.0016 5884 hkmsvc - ok
22:34:36.0049 5884 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:34:36.0054 5884 HomeGroupListener - ok
22:34:36.0081 5884 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:34:36.0085 5884 HomeGroupProvider - ok
22:34:36.0159 5884 [ BB1FC298BE53AAB1E110F6E786BD8AC5 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
22:34:36.0160 5884 HP Support Assistant Service - ok
22:34:36.0222 5884 [ 9B7EDD3FE7C211C36E921D34D18A3A0A ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
22:34:36.0251 5884 hpqwmiex - ok
22:34:36.0266 5884 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:34:36.0268 5884 HpSAMD - ok
22:34:36.0324 5884 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:34:36.0335 5884 HTTP - ok
22:34:36.0365 5884 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:34:36.0366 5884 hwpolicy - ok
22:34:36.0393 5884 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
22:34:36.0395 5884 i8042prt - ok
22:34:36.0429 5884 [ ABBF174CB394F5C437410A788B7E404A ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
22:34:36.0432 5884 iaStor - ok
22:34:36.0464 5884 [ 31A0E93CDF29007D6C6FFFB632F375ED ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:34:36.0465 5884 IAStorDataMgrSvc - ok
22:34:36.0512 5884 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:34:36.0516 5884 iaStorV - ok
22:34:36.0550 5884 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:34:36.0559 5884 idsvc - ok
22:34:36.0647 5884 [ A48928D4CCA6F8B731989DB08CF2C0AB ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\IPSDefs\20130301.002\IDSvia64.sys
22:34:36.0652 5884 IDSVia64 - ok
22:34:36.0781 5884 [ 89B99E3E988DFA20ABB58FF1930ADD21 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
22:34:36.0901 5884 igfx - ok
22:34:36.0930 5884 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
22:34:36.0932 5884 iirsp - ok
22:34:36.0968 5884 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
22:34:36.0977 5884 IKEEXT - ok
22:34:37.0031 5884 [ BFBABCB231628A4551DBB10D0EA25D62 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
22:34:37.0042 5884 IntcAzAudAddService - ok
22:34:37.0060 5884 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
22:34:37.0061 5884 intelide - ok
22:34:37.0086 5884 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:34:37.0087 5884 intelppm - ok
22:34:37.0145 5884 [ 3DC635B66DD7412E1C9C3A77B8D78F25 ] IntuitUpdateService C:\Program Files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
22:34:37.0146 5884 IntuitUpdateService - ok
22:34:37.0204 5884 [ D9DA7B3117BF5EFF921C0CDED4D58050 ] IntuitUpdateServiceV4 C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
22:34:37.0205 5884 IntuitUpdateServiceV4 - ok
22:34:37.0225 5884 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:34:37.0230 5884 IPBusEnum - ok
22:34:37.0258 5884 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:34:37.0260 5884 IpFilterDriver - ok
22:34:37.0300 5884 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:34:37.0310 5884 iphlpsvc - ok
22:34:37.0343 5884 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:34:37.0346 5884 IPMIDRV - ok
22:34:37.0376 5884 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:34:37.0379 5884 IPNAT - ok
22:34:37.0395 5884 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:34:37.0397 5884 IRENUM - ok
22:34:37.0414 5884 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:34:37.0416 5884 isapnp - ok
22:34:37.0446 5884 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:34:37.0451 5884 iScsiPrt - ok
22:34:37.0477 5884 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
22:34:37.0479 5884 kbdclass - ok
22:34:37.0509 5884 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
22:34:37.0511 5884 kbdhid - ok
22:34:37.0528 5884 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
22:34:37.0531 5884 KeyIso - ok
22:34:37.0562 5884 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:34:37.0565 5884 KSecDD - ok
22:34:37.0600 5884 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:34:37.0603 5884 KSecPkg - ok
22:34:37.0610 5884 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
22:34:37.0611 5884 ksthunk - ok
22:34:37.0647 5884 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
22:34:37.0655 5884 KtmRm - ok
22:34:37.0689 5884 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
22:34:37.0695 5884 LanmanServer - ok
22:34:37.0729 5884 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:34:37.0735 5884 LanmanWorkstation - ok
22:34:37.0779 5884 [ 108333981C841EB0FF198AA5DFCF3D3B ] LightScribeService c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
22:34:37.0780 5884 LightScribeService - ok
22:34:37.0807 5884 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:34:37.0809 5884 lltdio - ok
22:34:37.0841 5884 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:34:37.0846 5884 lltdsvc - ok
22:34:37.0864 5884 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:34:37.0866 5884 lmhosts - ok
22:34:37.0891 5884 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
22:34:37.0893 5884 LSI_FC - ok
22:34:37.0915 5884 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
22:34:37.0917 5884 LSI_SAS - ok
22:34:37.0925 5884 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:34:37.0927 5884 LSI_SAS2 - ok
22:34:37.0945 5884 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:34:37.0947 5884 LSI_SCSI - ok
22:34:37.0974 5884 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
22:34:37.0976 5884 luafv - ok
22:34:38.0004 5884 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:34:38.0007 5884 Mcx2Svc - ok
22:34:38.0030 5884 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
22:34:38.0031 5884 megasas - ok
22:34:38.0051 5884 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
22:34:38.0055 5884 MegaSR - ok
22:34:38.0072 5884 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
22:34:38.0074 5884 MMCSS - ok
22:34:38.0084 5884 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
22:34:38.0086 5884 Modem - ok
22:34:38.0116 5884 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:34:38.0117 5884 monitor - ok
22:34:38.0135 5884 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:34:38.0136 5884 mouclass - ok
22:34:38.0166 5884 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:34:38.0167 5884 mouhid - ok
22:34:38.0198 5884 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:34:38.0200 5884 mountmgr - ok
22:34:38.0281 5884 [ 51A84B690DF519DCF656F780243D953E ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:34:38.0283 5884 MozillaMaintenance - ok
22:34:38.0298 5884 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
22:34:38.0301 5884 mpio - ok
22:34:38.0315 5884 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:34:38.0317 5884 mpsdrv - ok
22:34:38.0354 5884 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:34:38.0367 5884 MpsSvc - ok
22:34:38.0389 5884 mrtRate - ok
22:34:38.0418 5884 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:34:38.0420 5884 MRxDAV - ok
22:34:38.0449 5884 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:34:38.0452 5884 mrxsmb - ok
22:34:38.0480 5884 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:34:38.0485 5884 mrxsmb10 - ok
22:34:38.0494 5884 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:34:38.0496 5884 mrxsmb20 - ok
22:34:38.0509 5884 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
22:34:38.0510 5884 msahci - ok
22:34:38.0536 5884 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:34:38.0538 5884 msdsm - ok
22:34:38.0553 5884 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
22:34:38.0556 5884 MSDTC - ok
22:34:38.0576 5884 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:34:38.0577 5884 Msfs - ok
22:34:38.0588 5884 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:34:38.0589 5884 mshidkmdf - ok
22:34:38.0610 5884 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:34:38.0611 5884 msisadrv - ok
22:34:38.0635 5884 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:34:38.0638 5884 MSiSCSI - ok
22:34:38.0643 5884 msiserver - ok
22:34:38.0659 5884 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:34:38.0660 5884 MSKSSRV - ok
22:34:38.0685 5884 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:34:38.0686 5884 MSPCLOCK - ok
22:34:38.0701 5884 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:34:38.0702 5884 MSPQM - ok
22:34:38.0733 5884 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:34:38.0737 5884 MsRPC - ok
22:34:38.0752 5884 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
22:34:38.0752 5884 mssmbios - ok
22:34:38.0768 5884 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:34:38.0769 5884 MSTEE - ok
22:34:38.0790 5884 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
22:34:38.0792 5884 MTConfig - ok
22:34:38.0810 5884 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
22:34:38.0811 5884 Mup - ok
22:34:38.0893 5884 [ DFD8873E4DC08E621A8366C6CD98AB28 ] N360 C:\Program Files (x86)\Norton 360\Engine\20.1.1.2\ccSvcHst.exe
22:34:38.0895 5884 N360 - ok
22:34:38.0931 5884 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
22:34:38.0955 5884 napagent - ok
22:34:38.0989 5884 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:34:38.0994 5884 NativeWifiP - ok
22:34:39.0072 5884 [ 88A2F45CE66B904285978D6BB13AFEB2 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130301.025\ENG64.SYS
22:34:39.0074 5884 NAVENG - ok
22:34:39.0126 5884 [ D2A545DA3A90BBFA40E020C23F1B7A48 ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\VirusDefs\20130301.025\EX64.SYS
22:34:39.0146 5884 NAVEX15 - ok
22:34:39.0194 5884 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:34:39.0203 5884 NDIS - ok
22:34:39.0223 5884 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:34:39.0224 5884 NdisCap - ok
22:34:39.0246 5884 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:34:39.0247 5884 NdisTapi - ok
22:34:39.0267 5884 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:34:39.0268 5884 Ndisuio - ok
22:34:39.0291 5884 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:34:39.0294 5884 NdisWan - ok
22:34:39.0318 5884 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:34:39.0319 5884 NDProxy - ok
22:34:39.0331 5884 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:34:39.0332 5884 NetBIOS - ok
22:34:39.0362 5884 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:34:39.0365 5884 NetBT - ok
22:34:39.0377 5884 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
22:34:39.0379 5884 Netlogon - ok
22:34:39.0408 5884 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
22:34:39.0413 5884 Netman - ok
22:34:39.0432 5884 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
22:34:39.0437 5884 netprofm - ok
22:34:39.0459 5884 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:34:39.0460 5884 NetTcpPortSharing - ok
22:34:39.0491 5884 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
22:34:39.0492 5884 nfrd960 - ok
22:34:39.0522 5884 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:34:39.0528 5884 NlaSvc - ok
22:34:39.0543 5884 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:34:39.0545 5884 Npfs - ok
22:34:39.0568 5884 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
22:34:39.0571 5884 nsi - ok
22:34:39.0578 5884 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:34:39.0579 5884 nsiproxy - ok
22:34:39.0646 5884 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:34:39.0698 5884 Ntfs - ok
22:34:39.0713 5884 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
22:34:39.0714 5884 Null - ok
22:34:39.0741 5884 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:34:39.0744 5884 nvraid - ok
22:34:39.0759 5884 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:34:39.0762 5884 nvstor - ok
22:34:39.0777 5884 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:34:39.0779 5884 nv_agp - ok
22:34:39.0805 5884 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
22:34:39.0807 5884 ohci1394 - ok
22:34:39.0853 5884 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:34:39.0855 5884 ose - ok
22:34:39.0884 5884 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:34:39.0891 5884 p2pimsvc - ok
22:34:39.0915 5884 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
22:34:39.0925 5884 p2psvc - ok
22:34:39.0945 5884 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
22:34:39.0947 5884 Parport - ok
22:34:39.0972 5884 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:34:39.0974 5884 partmgr - ok
22:34:39.0991 5884 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
22:34:39.0994 5884 PcaSvc - ok
22:34:40.0068 5884 PcdrNdisuio - ok
22:34:40.0086 5884 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
22:34:40.0088 5884 pci - ok
22:34:40.0102 5884 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
22:34:40.0103 5884 pciide - ok
22:34:40.0124 5884 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
22:34:40.0127 5884 pcmcia - ok
22:34:40.0158 5884 [ EA762CEA5B7012381EF75F4A55C7BB62 ] PCPitstop Scheduling C:\Program Files (x86)\PCPitstop\PCPitstopScheduleService.exe
22:34:40.0160 5884 PCPitstop Scheduling - ok
22:34:40.0194 5884 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
22:34:40.0195 5884 pcw - ok
22:34:40.0215 5884 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:34:40.0225 5884 PEAUTH - ok
22:34:40.0250 5884 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
22:34:40.0251 5884 PerfHost - ok
22:34:40.0306 5884 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
22:34:40.0322 5884 pla - ok
22:34:40.0351 5884 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:34:40.0356 5884 PlugPlay - ok
22:34:40.0368 5884 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:34:40.0370 5884 PNRPAutoReg - ok
22:34:40.0391 5884 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:34:40.0394 5884 PNRPsvc - ok
22:34:40.0411 5884 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:34:40.0416 5884 PolicyAgent - ok
22:34:40.0434 5884 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
22:34:40.0436 5884 Power - ok
 
22:34:40.0469 5884 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:34:40.0471 5884 PptpMiniport - ok
22:34:40.0476 5884 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
22:34:40.0478 5884 Processor - ok
22:34:40.0521 5884 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
22:34:40.0524 5884 ProfSvc - ok
22:34:40.0536 5884 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
22:34:40.0537 5884 ProtectedStorage - ok
22:34:40.0574 5884 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:34:40.0575 5884 Psched - ok
22:34:40.0616 5884 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
22:34:40.0631 5884 ql2300 - ok
22:34:40.0639 5884 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
22:34:40.0641 5884 ql40xx - ok
22:34:40.0654 5884 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
22:34:40.0658 5884 QWAVE - ok
22:34:40.0682 5884 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:34:40.0683 5884 QWAVEdrv - ok
22:34:40.0694 5884 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:34:40.0694 5884 RasAcd - ok
22:34:40.0706 5884 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:34:40.0707 5884 RasAgileVpn - ok
22:34:40.0716 5884 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
22:34:40.0719 5884 RasAuto - ok
22:34:40.0745 5884 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:34:40.0747 5884 Rasl2tp - ok
22:34:40.0780 5884 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
22:34:40.0785 5884 RasMan - ok
22:34:40.0796 5884 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:34:40.0798 5884 RasPppoe - ok
22:34:40.0805 5884 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:34:40.0807 5884 RasSstp - ok
22:34:40.0847 5884 [ 96597C96D5ACF4A3EF0B24D396853879 ] rcmirror C:\Windows\system32\DRIVERS\rcmirror.sys
22:34:40.0848 5884 rcmirror - ok
22:34:40.0877 5884 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:34:40.0880 5884 rdbss - ok
22:34:40.0898 5884 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
22:34:40.0899 5884 rdpbus - ok
22:34:40.0922 5884 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:34:40.0923 5884 RDPCDD - ok
22:34:40.0930 5884 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:34:40.0931 5884 RDPENCDD - ok
22:34:40.0947 5884 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:34:40.0948 5884 RDPREFMP - ok
22:34:40.0980 5884 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:34:40.0983 5884 RDPWD - ok
22:34:41.0008 5884 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:34:41.0010 5884 rdyboost - ok
22:34:41.0034 5884 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:34:41.0037 5884 RemoteAccess - ok
22:34:41.0053 5884 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:34:41.0056 5884 RemoteRegistry - ok
22:34:41.0069 5884 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:34:41.0071 5884 RpcEptMapper - ok
22:34:41.0100 5884 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
22:34:41.0102 5884 RpcLocator - ok
22:34:41.0132 5884 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
22:34:41.0136 5884 RpcSs - ok
22:34:41.0147 5884 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:34:41.0148 5884 rspndr - ok
22:34:41.0179 5884 [ 91296F0B2653281B2F11E0FCE56AA427 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
22:34:41.0181 5884 RTL8167 - ok
22:34:41.0214 5884 [ 4A06585C8673F4458E9FBBC9DDDB4D28 ] RTL8187B C:\Windows\system32\DRIVERS\wg111v3.sys
22:34:41.0219 5884 RTL8187B - ok
22:34:41.0236 5884 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
22:34:41.0237 5884 SamSs - ok
22:34:41.0268 5884 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:34:41.0270 5884 sbp2port - ok
22:34:41.0285 5884 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:34:41.0289 5884 SCardSvr - ok
22:34:41.0313 5884 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:34:41.0315 5884 scfilter - ok
22:34:41.0354 5884 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
22:34:41.0365 5884 Schedule - ok
22:34:41.0390 5884 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
22:34:41.0391 5884 SCPolicySvc - ok
22:34:41.0423 5884 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:34:41.0426 5884 SDRSVC - ok
22:34:41.0543 5884 [ 206387AB881E93A1A6EB89966C8651F1 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
22:34:41.0554 5884 SDScannerService - ok
22:34:41.0595 5884 [ A529CFE32565C0B145578FFB2B32C9A5 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
22:34:41.0609 5884 SDUpdateService - ok
22:34:41.0641 5884 [ CB63BDB77BB86549FC3303C2F11EDC18 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
22:34:41.0643 5884 SDWSCService - ok
22:34:41.0676 5884 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:34:41.0677 5884 secdrv - ok
22:34:41.0702 5884 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
22:34:41.0705 5884 seclogon - ok
22:34:41.0717 5884 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
22:34:41.0721 5884 SENS - ok
22:34:41.0739 5884 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:34:41.0743 5884 SensrSvc - ok
22:34:41.0762 5884 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
22:34:41.0763 5884 Serenum - ok
22:34:41.0771 5884 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
22:34:41.0774 5884 Serial - ok
22:34:41.0797 5884 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
22:34:41.0798 5884 sermouse - ok
22:34:41.0834 5884 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
22:34:41.0836 5884 SessionEnv - ok
22:34:41.0866 5884 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
22:34:41.0867 5884 sffdisk - ok
22:34:41.0874 5884 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:34:41.0875 5884 sffp_mmc - ok
22:34:41.0880 5884 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
22:34:41.0881 5884 sffp_sd - ok
22:34:41.0894 5884 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
22:34:41.0895 5884 sfloppy - ok
22:34:41.0919 5884 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:34:41.0924 5884 SharedAccess - ok
22:34:41.0953 5884 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:34:41.0958 5884 ShellHWDetection - ok
22:34:41.0989 5884 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:34:41.0990 5884 SiSRaid2 - ok
22:34:42.0004 5884 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
22:34:42.0006 5884 SiSRaid4 - ok
22:34:42.0126 5884 [ 23E3C83DFF7B09A97B01A85ED8A44478 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:34:42.0191 5884 Skype C2C Service - ok
22:34:42.0256 5884 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
22:34:42.0258 5884 SkypeUpdate - ok
22:34:42.0296 5884 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:34:42.0298 5884 Smb - ok
22:34:42.0339 5884 [ D48F87803F3965EE04D9BCB318791AAB ] SMR311 C:\Windows\system32\drivers\SMR311.SYS
22:34:42.0340 5884 SMR311 - ok
22:34:42.0384 5884 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:34:42.0387 5884 SNMPTRAP - ok
22:34:42.0395 5884 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
22:34:42.0396 5884 spldr - ok
22:34:42.0432 5884 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
22:34:42.0438 5884 Spooler - ok
22:34:42.0526 5884 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
22:34:42.0623 5884 sppsvc - ok
22:34:42.0639 5884 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:34:42.0642 5884 sppuinotify - ok
22:34:42.0732 5884 [ B2FE88C5E621C8345CC9BAC5CFD366B0 ] SRTSP C:\Windows\system32\drivers\N360x64\1401010.002\SRTSP64.SYS
22:34:42.0739 5884 SRTSP - ok
22:34:42.0755 5884 [ 1B884D876E87EABF5A3356BBD7321412 ] SRTSPX C:\Windows\system32\drivers\N360x64\1401010.002\SRTSPX64.SYS
22:34:42.0756 5884 SRTSPX - ok
22:34:42.0787 5884 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
22:34:42.0795 5884 srv - ok
22:34:42.0833 5884 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:34:42.0839 5884 srv2 - ok
22:34:42.0858 5884 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:34:42.0861 5884 srvnet - ok
22:34:42.0890 5884 [ ED161B91FDF7EAA39469D72D463D5F4E ] sscdbus C:\Windows\system32\DRIVERS\sscdbus.sys
22:34:42.0892 5884 sscdbus - ok
22:34:42.0928 5884 [ 4CB09E77593DBD8D7AF33B37375CA715 ] sscdmdfl C:\Windows\system32\DRIVERS\sscdmdfl.sys
22:34:42.0929 5884 sscdmdfl - ok
22:34:42.0949 5884 [ C7B4CF53497A6E5363F3439427663882 ] sscdmdm C:\Windows\system32\DRIVERS\sscdmdm.sys
22:34:42.0951 5884 sscdmdm - ok
22:34:42.0985 5884 [ 05FFA552F578E27AB2D41B6828DB477F ] sscdserd C:\Windows\system32\DRIVERS\sscdserd.sys
22:34:42.0987 5884 sscdserd - ok
22:34:43.0009 5884 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:34:43.0012 5884 SSDPSRV - ok
22:34:43.0023 5884 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:34:43.0025 5884 SstpSvc - ok
22:34:43.0046 5884 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
22:34:43.0047 5884 stexstor - ok
22:34:43.0084 5884 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
22:34:43.0085 5884 StillCam - ok
22:34:43.0124 5884 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
22:34:43.0131 5884 stisvc - ok
22:34:43.0155 5884 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
22:34:43.0155 5884 swenum - ok
22:34:43.0181 5884 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
22:34:43.0187 5884 swprv - ok
22:34:43.0223 5884 [ 52EB25BD8AB4E331028C48B178441B36 ] sxuptp C:\Windows\system32\DRIVERS\sxuptp.sys
22:34:43.0225 5884 sxuptp - ok
22:34:43.0274 5884 [ 688BBE78970E639BC1D66AE733394DCF ] SymDS C:\Windows\system32\drivers\N360x64\1401010.002\SYMDS64.SYS
22:34:43.0279 5884 SymDS - ok
22:34:43.0365 5884 [ A17EE0D0D762CC9B56FB9218D7089AFB ] SymEFA C:\Windows\system32\drivers\N360x64\1401010.002\SYMEFA64.SYS
22:34:43.0380 5884 SymEFA - ok
22:34:43.0416 5884 [ F5D6D3B7468C46EA2DDC1D19D2A6DA0F ] SymEvent C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
22:34:43.0417 5884 SymEvent - ok
22:34:43.0452 5884 [ ADF37F1A715D6C56C8E065FD8569A9A4 ] SymIRON C:\Windows\system32\drivers\N360x64\1401010.002\Ironx64.SYS
22:34:43.0453 5884 SymIRON - ok
22:34:43.0491 5884 [ 1605EBD8CB86AFC4430116065995279A ] SymNetS C:\Windows\system32\drivers\N360x64\1401010.002\SYMNETS.SYS
22:34:43.0494 5884 SymNetS - ok
22:34:43.0547 5884 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
22:34:43.0583 5884 SysMain - ok
22:34:43.0608 5884 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
22:34:43.0613 5884 TabletInputService - ok
22:34:43.0642 5884 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
22:34:43.0650 5884 TapiSrv - ok
22:34:43.0663 5884 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
22:34:43.0667 5884 TBS - ok
22:34:43.0727 5884 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:34:43.0769 5884 Tcpip - ok
22:34:43.0798 5884 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:34:43.0811 5884 TCPIP6 - ok
22:34:43.0839 5884 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:34:43.0840 5884 tcpipreg - ok
22:34:43.0862 5884 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:34:43.0863 5884 TDPIPE - ok
22:34:43.0882 5884 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:34:43.0884 5884 TDTCP - ok
22:34:43.0915 5884 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:34:43.0917 5884 tdx - ok
22:34:43.0936 5884 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
22:34:43.0937 5884 TermDD - ok
22:34:43.0981 5884 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
22:34:43.0993 5884 TermService - ok
22:34:44.0010 5884 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
22:34:44.0012 5884 Themes - ok
22:34:44.0041 5884 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
22:34:44.0043 5884 THREADORDER - ok
22:34:44.0049 5884 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
22:34:44.0053 5884 TrkWks - ok
22:34:44.0095 5884 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:34:44.0099 5884 TrustedInstaller - ok
22:34:44.0131 5884 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:34:44.0133 5884 tssecsrv - ok
22:34:44.0167 5884 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
22:34:44.0169 5884 TsUsbFlt - ok
22:34:44.0199 5884 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:34:44.0201 5884 tunnel - ok
22:34:44.0233 5884 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
22:34:44.0235 5884 uagp35 - ok
22:34:44.0270 5884 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:34:44.0275 5884 udfs - ok
22:34:44.0302 5884 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:34:44.0306 5884 UI0Detect - ok
22:34:44.0321 5884 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:34:44.0323 5884 uliagpkx - ok
22:34:44.0349 5884 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
22:34:44.0350 5884 umbus - ok
22:34:44.0372 5884 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
22:34:44.0373 5884 UmPass - ok
22:34:44.0390 5884 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
22:34:44.0395 5884 upnphost - ok
22:34:44.0408 5884 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:34:44.0410 5884 usbccgp - ok
22:34:44.0439 5884 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:34:44.0441 5884 usbcir - ok
22:34:44.0446 5884 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:34:44.0448 5884 usbehci - ok
22:34:44.0467 5884 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:34:44.0472 5884 usbhub - ok
22:34:44.0484 5884 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
22:34:44.0485 5884 usbohci - ok
22:34:44.0513 5884 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:34:44.0514 5884 usbprint - ok
22:34:44.0544 5884 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
22:34:44.0545 5884 usbscan - ok
22:34:44.0557 5884 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
22:34:44.0559 5884 USBSTOR - ok
22:34:44.0572 5884 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
22:34:44.0574 5884 usbuhci - ok
22:34:44.0590 5884 [ D0FE8CB5F84303E73FF0754437FAD3D1 ] USB_RNDIS C:\Windows\system32\DRIVERS\usb8023.sys
22:34:44.0591 5884 USB_RNDIS - ok
22:34:44.0613 5884 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
22:34:44.0615 5884 UxSms - ok
22:34:44.0627 5884 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
22:34:44.0628 5884 VaultSvc - ok
22:34:44.0654 5884 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
22:34:44.0655 5884 vdrvroot - ok
22:34:44.0685 5884 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
22:34:44.0692 5884 vds - ok
22:34:44.0709 5884 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:34:44.0710 5884 vga - ok
22:34:44.0716 5884 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
22:34:44.0717 5884 VgaSave - ok
22:34:44.0733 5884 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
22:34:44.0736 5884 vhdmp - ok
22:34:44.0754 5884 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
22:34:44.0755 5884 viaide - ok
22:34:44.0770 5884 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:34:44.0771 5884 volmgr - ok
22:34:44.0806 5884 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:34:44.0809 5884 volmgrx - ok
22:34:44.0826 5884 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:34:44.0830 5884 volsnap - ok
22:34:44.0864 5884 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
22:34:44.0866 5884 vsmraid - ok
22:34:44.0922 5884 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
22:34:44.0963 5884 VSS - ok
22:34:44.0977 5884 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
22:34:44.0978 5884 vwifibus - ok
22:34:44.0994 5884 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
22:34:44.0996 5884 vwififlt - ok
22:34:45.0014 5884 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
22:34:45.0021 5884 W32Time - ok
22:34:45.0047 5884 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
22:34:45.0048 5884 WacomPen - ok
22:34:45.0067 5884 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:34:45.0068 5884 WANARP - ok
22:34:45.0072 5884 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:34:45.0074 5884 Wanarpv6 - ok
22:34:45.0119 5884 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
22:34:45.0140 5884 WatAdminSvc - ok
22:34:45.0188 5884 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
22:34:45.0205 5884 wbengine - ok
22:34:45.0229 5884 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:34:45.0233 5884 WbioSrvc - ok
22:34:45.0268 5884 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:34:45.0273 5884 wcncsvc - ok
22:34:45.0285 5884 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:34:45.0288 5884 WcsPlugInService - ok
22:34:45.0307 5884 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
22:34:45.0308 5884 Wd - ok
22:34:45.0346 5884 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:34:45.0354 5884 Wdf01000 - ok
22:34:45.0372 5884 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:34:45.0375 5884 WdiServiceHost - ok
22:34:45.0380 5884 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:34:45.0384 5884 WdiSystemHost - ok
22:34:45.0406 5884 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
22:34:45.0411 5884 WebClient - ok
22:34:45.0427 5884 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:34:45.0432 5884 Wecsvc - ok
22:34:45.0442 5884 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:34:45.0445 5884 wercplsupport - ok
22:34:45.0466 5884 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
22:34:45.0469 5884 WerSvc - ok
22:34:45.0488 5884 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:34:45.0489 5884 WfpLwf - ok
22:34:45.0505 5884 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:34:45.0507 5884 WIMMount - ok
22:34:45.0517 5884 WinDefend - ok
22:34:45.0523 5884 WinHttpAutoProxySvc - ok
22:34:45.0573 5884 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:34:45.0576 5884 Winmgmt - ok
22:34:45.0632 5884 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
22:34:45.0684 5884 WinRM - ok
22:34:45.0719 5884 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
22:34:45.0729 5884 Wlansvc - ok
22:34:45.0758 5884 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
22:34:45.0759 5884 WmiAcpi - ok
22:34:45.0781 5884 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:34:45.0785 5884 wmiApSrv - ok
22:34:45.0807 5884 WMPNetworkSvc - ok
22:34:45.0825 5884 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:34:45.0827 5884 WPCSvc - ok
22:34:45.0842 5884 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:34:45.0844 5884 WPDBusEnum - ok
22:34:45.0860 5884 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:34:45.0861 5884 ws2ifsl - ok
22:34:45.0876 5884 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
22:34:45.0879 5884 wscsvc - ok
22:34:45.0885 5884 WSearch - ok
22:34:45.0950 5884 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
22:34:45.0982 5884 wuauserv - ok
22:34:46.0012 5884 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:34:46.0014 5884 WudfPf - ok
22:34:46.0042 5884 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:34:46.0045 5884 wudfsvc - ok
22:34:46.0058 5884 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
22:34:46.0063 5884 WwanSvc - ok
22:34:46.0083 5884 ================ Scan global ===============================
22:34:46.0104 5884 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
22:34:46.0129 5884 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:34:46.0138 5884 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
22:34:46.0160 5884 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
22:34:46.0193 5884 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
22:34:46.0196 5884 [Global] - ok
22:34:46.0196 5884 ================ Scan MBR ==================================
22:34:46.0208 5884 [ 89750024E83C5387C5B5F649AFB20429 ] \Device\Harddisk0\DR0
22:34:46.0457 5884 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
22:34:46.0457 5884 \Device\Harddisk0\DR0 - detected TDSS File System (1)
22:34:46.0458 5884 ================ Scan VBR ==================================
22:34:46.0464 5884 [ 0CB555645E88FB9D32D324EDD502BEAA ] \Device\Harddisk0\DR0\Partition1
22:34:46.0466 5884 \Device\Harddisk0\DR0\Partition1 - ok
22:34:46.0502 5884 [ C88532FE8C261DC926E34F2EEDC1F880 ] \Device\Harddisk0\DR0\Partition2
22:34:46.0504 5884 \Device\Harddisk0\DR0\Partition2 - ok
22:34:46.0534 5884 [ 3A96162BAA79A5A8E0F50DA9AB06DE36 ] \Device\Harddisk0\DR0\Partition3
22:34:46.0536 5884 \Device\Harddisk0\DR0\Partition3 - ok
22:34:46.0537 5884 ============================================================
22:34:46.0537 5884 Scan finished
22:34:46.0537 5884 ============================================================
22:34:46.0556 5388 Detected object count: 1
22:34:46.0556 5388 Actual detected object count: 1
22:34:53.0367 5388 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
22:34:53.0367 5388 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
 
Hello diane7

Thank you for the log :)

If this machine is used to perform any kind of financial transactions please use an uninfected machine to change your passwords as soon as you can.

Please disable your Norton product and run TDSSKiller again.

When the following item is detected:

Detected object count: 1
22:34:46.0556 5388 Actual detected object count: 1
22:34:53.0367 5388 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
22:34:53.0367 5388 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
Select Delete.

Once you have done that, save the log produced by TDSSKiller then download and run the following tool:

  1. Combofix

    • Download ComboFix from one of the following locations:

      Link 1
      Link 2
    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Right click on ComboFix.exe and select "Run as Administrator" to run the program. Follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    RC1.png

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    RC2-1.png

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
    • Should there be issues with internet afterward:

      In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

      In Firefox: Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

    Please post the TDSSKiller log and the Combofix log in your next reply.

    If you run into any problems just let me know :)
 
12:26:42.0037 2392 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42

12:26:42.0551 2392 ============================================================

12:26:42.0551 2392 Current date / time: 2013/03/02 12:26:42.0551

12:26:42.0551 2392 SystemInfo:

12:26:42.0551 2392

12:26:42.0551 2392 OS Version: 6.1.7601 ServicePack: 1.0

12:26:42.0551 2392 Product type: Workstation

12:26:42.0551 2392 ComputerName: MEMBER-PC

12:26:42.0551 2392 UserName: member

12:26:42.0552 2392 Windows directory: C:\Windows

12:26:42.0552 2392 System windows directory: C:\Windows

12:26:42.0552 2392 Running under WOW64

12:26:42.0552 2392 Processor architecture: Intel x64

12:26:42.0552 2392 Number of processors: 2

12:26:42.0552 2392 Page size: 0x1000

12:26:42.0552 2392 Boot type: Normal boot

12:26:42.0552 2392 ============================================================

12:26:42.0921 2392 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

12:26:42.0937 2392 ============================================================

12:26:42.0937 2392 \Device\Harddisk0\DR0:
 
12:26:42.0552 2392 ============================================================

12:26:42.0921 2392 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

12:26:42.0937 2392 ============================================================

12:26:42.0937 2392 \Device\Harddisk0\DR0:

12:26:42.0937 2392 MBR partitions:

12:26:42.0937 2392 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000

12:26:42.0937 2392 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x38B87000

12:26:42.0937 2392 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x38BB9800, BlocksNum 0x17CC000

12:26:42.0937 2392 ============================================================

12:26:42.0960 2392 C: <-> \Device\Harddisk0\DR0\Partition2

12:26:42.0995 2392 D: <-> \Device\Harddisk0\DR0\Partition3

12:26:42.0995 2392 ============================================================

12:26:42.0995 2392 Initialize success

12:26:42.0995 2392 ============================================================

12:26:45.0911 3840 ============================================================

12:26:45.0911 3840 Scan started

12:26:45.0911 3840 Mode: Manual;

12:26:45.0911 3840 ============================================================

12:26:46.0138 3840 ================ Scan system memory ========================

12:26:46.0138 3840 System memory - ok

12:26:46.0139 3840 ================ Scan services
 
12:26:46.0281 3840 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys

12:26:46.0285 3840 1394ohci - ok

12:26:46.0318 3840 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys

12:26:46.0323 3840 ACPI - ok

12:26:46.0357 3840 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys

12:26:46.0358 3840 AcpiPmi - ok

12:26:46.0470 3840 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

12:26:46.0472 3840 AdobeFlashPlayerUpdateSvc - ok

12:26:46.0509 3840 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys

12:26:46.0516 3840 adp94xx - ok

12:26:46.0563 3840 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys

12:26:46.0568 3840 adpahci - ok

12:26:46.0583 3840 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys

12:26:46.0586 3840 adpu320 - ok

12:26:46.0633 3840 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll

12:26:46.0633 3840 AeLookupSvc - ok

12:26:46.0833 3840 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys

12:26:46.0838 3840 AFD - ok

12:26:46.0960 3840 [ 23E7CB4641B93CE8591D1057670A4F04 ] AffinegyService C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe

12:26:46.0966 3840 AffinegyService - ok
 
12:26:46.0998 3840 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys

12:26:46.0999 3840 agp440 - ok

12:26:47.0032 3840 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe

12:26:47.0034 3840 ALG - ok

12:26:47.0059 3840 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys

12:26:47.0060 3840 aliide - ok

12:26:47.0089 3840 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys

12:26:47.0090 3840 amdide - ok

12:26:47.0114 3840 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys

12:26:47.0116 3840 AmdK8 - ok

12:26:47.0124 3840 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys

12:26:47.0126 3840 AmdPPM - ok

12:26:47.0162 3840 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys

12:26:47.0164 3840 amdsata - ok

12:26:47.0188 3840 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys

12:26:47.0190 3840 amdsbs - ok

12:26:47.0211 3840 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys

12:26:47.0212 3840 amdxata - ok

12:26:47.0246 3840 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys

12:26:47.0247 3840 AppID - ok

12:26:47.0269 3840 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll

12:26:47.0270 3840 AppIDSvc - ok
 
12:26:47.0299 3840 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll

12:26:47.0300 3840 Appinfo - ok

12:26:47.0316 3840 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys

12:26:47.0317 3840 arc - ok

12:26:47.0325 3840 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys

12:26:47.0326 3840 arcsas - ok

12:26:47.0382 3840 aspnet_state - ok

12:26:47.0410 3840 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys

12:26:47.0411 3840 AsyncMac - ok

12:26:47.0454 3840 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys

12:26:47.0455 3840 atapi - ok

12:26:47.0504 3840 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

12:26:47.0508 3840 AudioEndpointBuilder - ok

12:26:47.0529 3840 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll

12:26:47.0534 3840 AudioSrv - ok

12:26:47.0571 3840 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll

12:26:47.0573 3840 AxInstSV - ok

12:26:47.0597 3840 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys

12:26:47.0602 3840 b06bdrv - ok
 
12:26:47.0629 3840 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys

12:26:47.0633 3840 b57nd60a - ok

12:26:47.0674 3840 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll

12:26:47.0676 3840 BDESVC - ok

12:26:47.0692 3840 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys

12:26:47.0693 3840 Beep - ok

12:26:47.0787 3840 [ 9BB84C554D7429F0A2CDF4EA1836F233 ] Belkin Local Backup Service C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe

12:26:47.0789 3840 Belkin Local Backup Service - ok

12:26:47.0821 3840 [ E62A04D615A8CAC83601E1F07C010D3C ] Belkin Network USB Helper C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe

12:26:47.0822 3840 Belkin Network USB Helper - ok

12:26:47.0878 3840 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll

12:26:47.0885 3840 BFE - ok

12:26:48.0041 3840 [ 866335C9C0E6733C753FB472C539A6B9 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.1.2\Definitions\BASHDefs\20130208.001\BHDrvx64.sys

12:26:48.0054 3840 BHDrvx64 - ok

12:26:48.0099 3840 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll

12:26:48.0109 3840 BITS - ok

12:26:48.0130 3840 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys

12:26:48.0131 3840 blbdrive - ok

12:26:48.0156 3840 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys

12:26:48.0158 3840 bowser - ok

12:26:48.0179 3840 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys

12:26:48.0180 3840 BrFiltLo - ok
 
Status
Not open for further replies.
Back
Top