Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Persistent iexplore.exe annoyance [Solved]


  • This topic is locked This topic is locked

#46
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Before I run OTL, there has been some degree of success with TDSS. Background iexplore.exe activity seems to have ceased, and avast has stopped alerting. Shall I still run the OTL fix with regard to chkdsk? Here is the TDSS log:


21:57:39.0906 2848 TDSS rootkit removing tool 2.7.28.0 Apr 10 2012 16:54:05
21:57:40.0875 2848 ============================================================
21:57:40.0875 2848 Current date / time: 2012/04/17 21:57:40.0875
21:57:40.0875 2848 SystemInfo:
21:57:40.0875 2848
21:57:40.0875 2848 OS Version: 5.1.2600 ServicePack: 3.0
21:57:40.0875 2848 Product type: Workstation
21:57:40.0875 2848 ComputerName: PIVANA100
21:57:40.0875 2848 UserName: Peter Ivan
21:57:40.0875 2848 Windows directory: C:\WINDOWS
21:57:40.0875 2848 System windows directory: C:\WINDOWS
21:57:40.0875 2848 Processor architecture: Intel x86
21:57:40.0875 2848 Number of processors: 2
21:57:40.0875 2848 Page size: 0x1000
21:57:40.0875 2848 Boot type: Normal boot
21:57:40.0875 2848 ============================================================
21:57:49.0359 2848 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 (74.53 Gb), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:57:49.0359 2848 \Device\Harddisk0\DR0:
21:57:49.0359 2848 MBR used
21:57:49.0359 2848 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x9490C62
21:57:49.0437 2848 Initialize success
21:57:49.0437 2848 ============================================================
21:58:51.0781 2356 ============================================================
21:58:51.0781 2356 Scan started
21:58:51.0781 2356 Mode: Manual; SigCheck; TDLFS;
21:58:51.0781 2356 ============================================================
21:58:52.0218 2356 !SASCORE (c0393eb99a6c72c6bef9bfc4a72b33a6) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
21:58:52.0515 2356 !SASCORE - ok
21:58:52.0781 2356 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys
21:58:55.0593 2356 61883 - ok
21:58:55.0812 2356 Aavmker4 (473f97edc5a5312f3665ab2921196c0c) C:\WINDOWS\system32\drivers\Aavmker4.sys
21:58:55.0921 2356 Aavmker4 - ok
21:58:55.0937 2356 Abiosdsk - ok
21:58:55.0953 2356 abp480n5 - ok
21:58:55.0984 2356 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:58:56.0203 2356 ACPI - ok
21:58:56.0203 2356 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
21:58:56.0375 2356 ACPIEC - ok
21:58:56.0500 2356 AdobeFlashPlayerUpdateSvc (459ac130c6ab892b1cd5d7544626efc5) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
21:58:56.0531 2356 AdobeFlashPlayerUpdateSvc - ok
21:58:56.0703 2356 adpu160m - ok
21:58:56.0781 2356 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
21:58:56.0968 2356 aec - ok
21:58:57.0046 2356 AegisP (12dafd934641dcf61e446313bc261ec2) C:\WINDOWS\system32\DRIVERS\AegisP.sys
21:58:57.0046 2356 AegisP ( UnsignedFile.Multi.Generic ) - warning
21:58:57.0046 2356 AegisP - detected UnsignedFile.Multi.Generic (1)
21:58:57.0109 2356 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
21:58:57.0203 2356 AFD - ok
21:58:57.0265 2356 AgereSoftModem (b3192376c7a3814b5341efc2202022f8) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
21:58:57.0468 2356 AgereSoftModem - ok
21:58:57.0671 2356 Aha154x - ok
21:58:57.0687 2356 aic78u2 - ok
21:58:57.0703 2356 aic78xx - ok
21:58:57.0750 2356 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
21:58:57.0921 2356 Alerter - ok
21:58:57.0953 2356 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
21:58:58.0062 2356 ALG - ok
21:58:58.0078 2356 AliIde - ok
21:58:58.0093 2356 amsint - ok
21:58:58.0156 2356 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
21:58:58.0234 2356 AppMgmt - ok
21:58:58.0312 2356 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
21:58:58.0453 2356 Arp1394 - ok
21:58:58.0703 2356 ASAPIW2k (4f9cbbf95e8f7a0d4c0edcfe3b78102e) C:\WINDOWS\system32\drivers\ASAPIW2k.sys
21:58:58.0734 2356 ASAPIW2k ( UnsignedFile.Multi.Generic ) - warning
21:58:58.0734 2356 ASAPIW2k - detected UnsignedFile.Multi.Generic (1)
21:58:58.0750 2356 asc - ok
21:58:58.0765 2356 asc3350p - ok
21:58:58.0781 2356 asc3550 - ok
21:58:58.0875 2356 aspnet_state (e1a1206a4fb19b675e947b29ccd25fba) C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
21:58:58.0906 2356 aspnet_state ( UnsignedFile.Multi.Generic ) - warning
21:58:58.0906 2356 aspnet_state - detected UnsignedFile.Multi.Generic (1)
21:58:58.0953 2356 aswFsBlk (0ae43c6c411254049279c2ee55630f95) C:\WINDOWS\system32\drivers\aswFsBlk.sys
21:58:58.0968 2356 aswFsBlk - ok
21:58:59.0031 2356 aswMon2 (8c30b7ddd2f1d8d138ebe40345af2b11) C:\WINDOWS\system32\drivers\aswMon2.sys
21:58:59.0062 2356 aswMon2 - ok
21:58:59.0109 2356 AswRdr (da12626fd9a67f4e917e2f2fbe1e1764) C:\WINDOWS\system32\drivers\AswRdr.sys
21:58:59.0125 2356 AswRdr - ok
21:58:59.0375 2356 aswSnx (dcb199b967375753b5019ec15f008f53) C:\WINDOWS\system32\drivers\aswSnx.sys
21:58:59.0468 2356 aswSnx - ok
21:58:59.0546 2356 aswSP (b32873e5a1443c0a1e322266e203bf10) C:\WINDOWS\system32\drivers\aswSP.sys
21:58:59.0578 2356 aswSP - ok
21:58:59.0687 2356 aswTdi (6ff544175a9180c5d88534d3d9c9a9f7) C:\WINDOWS\system32\drivers\aswTdi.sys
21:58:59.0703 2356 aswTdi - ok
21:58:59.0750 2356 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:58:59.0921 2356 AsyncMac - ok
21:59:00.0093 2356 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
21:59:00.0265 2356 atapi - ok
21:59:00.0281 2356 Atdisk - ok
21:59:00.0328 2356 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:59:00.0484 2356 Atmarpc - ok
21:59:00.0531 2356 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
21:59:00.0781 2356 AudioSrv - ok
21:59:00.0812 2356 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
21:59:00.0984 2356 audstub - ok
21:59:01.0156 2356 avast! Antivirus (4041d31508a2a084dfb42c595854090f) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
21:59:01.0171 2356 avast! Antivirus - ok
21:59:01.0421 2356 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys
21:59:01.0562 2356 Avc - ok
21:59:01.0593 2356 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
21:59:01.0765 2356 Beep - ok
21:59:02.0031 2356 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
21:59:02.0375 2356 BITS - ok
21:59:02.0515 2356 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
21:59:02.0640 2356 Browser - ok
21:59:02.0718 2356 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
21:59:02.0890 2356 cbidf2k - ok
21:59:02.0937 2356 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
21:59:03.0093 2356 CCDECODE - ok
21:59:03.0156 2356 cd20xrnt - ok
21:59:03.0218 2356 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
21:59:03.0375 2356 Cdaudio - ok
21:59:03.0406 2356 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
21:59:03.0546 2356 Cdfs - ok
21:59:03.0562 2356 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:59:03.0703 2356 Cdrom - ok
21:59:03.0843 2356 CFSvcs (3cb0cc8879956c187e87e18634ee5164) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
21:59:03.0859 2356 CFSvcs ( UnsignedFile.Multi.Generic ) - warning
21:59:03.0859 2356 CFSvcs - detected UnsignedFile.Multi.Generic (1)
21:59:03.0921 2356 Changer - ok
21:59:03.0953 2356 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
21:59:04.0125 2356 CiSvc - ok
21:59:04.0171 2356 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
21:59:04.0328 2356 ClipSrv - ok
21:59:04.0437 2356 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
21:59:04.0578 2356 CmBatt - ok
21:59:04.0656 2356 CmdIde - ok
21:59:04.0687 2356 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
21:59:04.0843 2356 Compbatt - ok
21:59:04.0859 2356 COMSysApp - ok
21:59:04.0875 2356 Cpqarray - ok
21:59:04.0921 2356 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
21:59:05.0078 2356 CryptSvc - ok
21:59:05.0140 2356 dac2w2k - ok
21:59:05.0156 2356 dac960nt - ok
21:59:05.0234 2356 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
21:59:05.0390 2356 DcomLaunch - ok
21:59:05.0515 2356 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
21:59:05.0656 2356 Dhcp - ok
21:59:05.0828 2356 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
21:59:05.0968 2356 Disk - ok
21:59:06.0031 2356 DLABOIOM (ee4325becef51b8c32b4329097e4f301) C:\WINDOWS\system32\DLA\DLABOIOM.SYS
21:59:06.0062 2356 DLABOIOM ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0062 2356 DLABOIOM - detected UnsignedFile.Multi.Generic (1)
21:59:06.0093 2356 DLACDBHM (d979bebcf7edcc9c9ee1857d1a68c67b) C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
21:59:06.0109 2356 DLACDBHM ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0109 2356 DLACDBHM - detected UnsignedFile.Multi.Generic (1)
21:59:06.0125 2356 DLADResN (1e6c6597833a04c2157be7b39ea92ce1) C:\WINDOWS\system32\DLA\DLADResN.SYS
21:59:06.0125 2356 DLADResN ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0125 2356 DLADResN - detected UnsignedFile.Multi.Generic (1)
21:59:06.0140 2356 DLAIFS_M (752376e109a090970bfa9722f0f40b03) C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
21:59:06.0171 2356 DLAIFS_M ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0171 2356 DLAIFS_M - detected UnsignedFile.Multi.Generic (1)
21:59:06.0203 2356 DLAOPIOM (62ee7902e74b90bf1ccc4643fc6c07a7) C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
21:59:06.0218 2356 DLAOPIOM ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0218 2356 DLAOPIOM - detected UnsignedFile.Multi.Generic (1)
21:59:06.0296 2356 DLAPoolM (5c220124c5afeaee84a9bb89d685c17b) C:\WINDOWS\system32\DLA\DLAPoolM.SYS
21:59:06.0328 2356 DLAPoolM ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0328 2356 DLAPoolM - detected UnsignedFile.Multi.Generic (1)
21:59:06.0343 2356 DLARTL_N (7ee0852ae8907689df25049dcd2342e8) C:\WINDOWS\system32\Drivers\DLARTL_N.SYS
21:59:06.0359 2356 DLARTL_N ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0359 2356 DLARTL_N - detected UnsignedFile.Multi.Generic (1)
21:59:06.0453 2356 DLAUDFAM (4ebb78d9bbf072119363b35b9b3e518f) C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
21:59:06.0484 2356 DLAUDFAM ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0484 2356 DLAUDFAM - detected UnsignedFile.Multi.Generic (1)
21:59:06.0515 2356 DLAUDF_M (333b770e52d2cea7bd86391120466e43) C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
21:59:06.0531 2356 DLAUDF_M ( UnsignedFile.Multi.Generic ) - warning
21:59:06.0546 2356 DLAUDF_M - detected UnsignedFile.Multi.Generic (1)
21:59:06.0546 2356 dmadmin - ok
21:59:06.0687 2356 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
21:59:06.0921 2356 dmboot - ok
21:59:06.0953 2356 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
21:59:07.0093 2356 dmio - ok
21:59:07.0265 2356 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
21:59:07.0578 2356 dmload - ok
21:59:07.0656 2356 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
21:59:07.0828 2356 dmserver - ok
21:59:07.0937 2356 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
21:59:08.0078 2356 DMusic - ok
21:59:08.0140 2356 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
21:59:08.0234 2356 Dnscache - ok
21:59:08.0312 2356 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
21:59:08.0468 2356 Dot3svc - ok
21:59:08.0546 2356 dpti2o - ok
21:59:08.0625 2356 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
21:59:08.0765 2356 drmkaud - ok
21:59:08.0828 2356 DRVMCDB (fd0f95981fef9073659d8ec58e40aa3c) C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
21:59:08.0859 2356 DRVMCDB ( UnsignedFile.Multi.Generic ) - warning
21:59:08.0859 2356 DRVMCDB - detected UnsignedFile.Multi.Generic (1)
21:59:08.0875 2356 DRVNDDM (b4869d320428cdc5ec4d7f5e808e99b5) C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
21:59:08.0890 2356 DRVNDDM ( UnsignedFile.Multi.Generic ) - warning
21:59:08.0890 2356 DRVNDDM - detected UnsignedFile.Multi.Generic (1)
21:59:08.0953 2356 DVD-RAM_Service (c9ffbd6b8edc46cd3d13e3c6db914fb7) C:\WINDOWS\system32\DVDRAMSV.exe
21:59:08.0953 2356 DVD-RAM_Service ( UnsignedFile.Multi.Generic ) - warning
21:59:08.0953 2356 DVD-RAM_Service - detected UnsignedFile.Multi.Generic (1)
21:59:09.0031 2356 e1express (e1fa10ed8f9f700c1be1eae05a80ef57) C:\WINDOWS\system32\DRIVERS\e1e5132.sys
21:59:09.0062 2356 e1express - ok
21:59:09.0218 2356 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
21:59:09.0343 2356 EapHost - ok
21:59:09.0625 2356 eeCtrl (089296aedb9b72b4916ac959752bdc89) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:59:09.0671 2356 eeCtrl - ok
21:59:09.0734 2356 EraserUtilRebootDrv (850259334652d392e33ee3412562e583) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:59:09.0750 2356 EraserUtilRebootDrv - ok
21:59:09.0921 2356 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
21:59:10.0109 2356 ERSvc - ok
21:59:10.0218 2356 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
21:59:10.0281 2356 Eventlog - ok
21:59:10.0375 2356 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
21:59:10.0468 2356 EventSystem - ok
21:59:10.0656 2356 EvtEng (56ded3ade453272e6a0ad582d945d1a4) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
21:59:10.0687 2356 EvtEng ( UnsignedFile.Multi.Generic ) - warning
21:59:10.0687 2356 EvtEng - detected UnsignedFile.Multi.Generic (1)
21:59:10.0906 2356 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
21:59:11.0046 2356 Fastfat - ok
21:59:11.0109 2356 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
21:59:11.0187 2356 FastUserSwitchingCompatibility - ok
21:59:11.0218 2356 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
21:59:11.0375 2356 Fdc - ok
21:59:11.0515 2356 FdRedir (8affa5814b135417494e48eb9c0b6c5e) C:\Program Files\Common Files\Protector Suite QL\Drivers\FdRedir.sys
21:59:11.0531 2356 FdRedir ( UnsignedFile.Multi.Generic ) - warning
21:59:11.0531 2356 FdRedir - detected UnsignedFile.Multi.Generic (1)
21:59:11.0546 2356 FileDisk2 (6ed5c6a25174118036e978b42f0974d1) C:\Program Files\Common Files\Protector Suite QL\Drivers\filedisk.sys
21:59:11.0562 2356 FileDisk2 ( UnsignedFile.Multi.Generic ) - warning
21:59:11.0562 2356 FileDisk2 - detected UnsignedFile.Multi.Generic (1)
21:59:11.0796 2356 FilterService (20fe03294ac1429ae88a64c2f754b0d4) C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys
21:59:11.0812 2356 FilterService - ok
21:59:11.0859 2356 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
21:59:12.0000 2356 Fips - ok
21:59:12.0046 2356 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
21:59:12.0187 2356 Flpydisk - ok
21:59:12.0218 2356 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
21:59:12.0390 2356 FltMgr - ok
21:59:12.0421 2356 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:59:12.0578 2356 Fs_Rec - ok
21:59:12.0625 2356 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:59:12.0765 2356 Ftdisk - ok
21:59:12.0937 2356 giveio (77ebf3e9386daa51551af429052d88d0) C:\WINDOWS\system32\giveio.sys
21:59:13.0000 2356 giveio ( UnsignedFile.Multi.Generic ) - warning
21:59:13.0000 2356 giveio - detected UnsignedFile.Multi.Generic (1)
21:59:13.0109 2356 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:59:13.0265 2356 Gpc - ok
21:59:13.0296 2356 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
21:59:13.0453 2356 HDAudBus - ok
21:59:13.0531 2356 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
21:59:13.0671 2356 helpsvc - ok
21:59:13.0687 2356 HidServ - ok
21:59:13.0765 2356 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
21:59:13.0906 2356 hkmsvc - ok
21:59:14.0031 2356 hpn - ok
21:59:14.0218 2356 hpqcxs08 (38d6b51f04def7fb248fa56e4c47407e) C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
21:59:14.0250 2356 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
21:59:14.0250 2356 hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
21:59:14.0265 2356 hpqddsvc (3ee4a63539ec04ee2d4bd293985087ab) C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
21:59:14.0296 2356 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
21:59:14.0296 2356 hpqddsvc - detected UnsignedFile.Multi.Generic (1)
21:59:14.0406 2356 HPSLPSVC (50aed60ea813124d6daee41814e4aaac) C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL
21:59:14.0468 2356 HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning
21:59:14.0468 2356 HPSLPSVC - detected UnsignedFile.Multi.Generic (1)
21:59:14.0828 2356 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
21:59:14.0906 2356 HTTP - ok
21:59:14.0953 2356 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
21:59:15.0140 2356 HTTPFilter - ok
21:59:15.0156 2356 i2omgmt - ok
21:59:15.0171 2356 i2omp - ok
21:59:15.0234 2356 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:59:15.0406 2356 i8042prt - ok
21:59:15.0421 2356 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
21:59:15.0578 2356 Imapi - ok
21:59:15.0640 2356 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
21:59:15.0796 2356 ImapiService - ok
21:59:15.0968 2356 ini910u - ok
21:59:16.0203 2356 IntcAzAudAddService (b12a9fc49cd2765a43829d834f518aed) C:\WINDOWS\system32\drivers\RtkHDAud.sys
21:59:16.0625 2356 IntcAzAudAddService - ok
21:59:16.0640 2356 IntelIde - ok
21:59:16.0703 2356 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:59:16.0859 2356 intelppm - ok
21:59:16.0890 2356 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
21:59:17.0046 2356 Ip6Fw - ok
21:59:17.0078 2356 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:59:17.0218 2356 IpFilterDriver - ok
21:59:17.0281 2356 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:59:17.0421 2356 IpInIp - ok
21:59:17.0640 2356 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:59:17.0796 2356 IpNat - ok
21:59:17.0843 2356 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:59:18.0000 2356 IPSec - ok
21:59:18.0015 2356 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
21:59:18.0093 2356 IRENUM - ok
21:59:18.0125 2356 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:59:18.0281 2356 isapnp - ok
21:59:18.0312 2356 Iviaspi (f59c3569a2f2c464bb78cb1bdcdca55e) C:\WINDOWS\system32\drivers\iviaspi.sys
21:59:18.0328 2356 Iviaspi ( UnsignedFile.Multi.Generic ) - warning
21:59:18.0328 2356 Iviaspi - detected UnsignedFile.Multi.Generic (1)
21:59:18.0609 2356 JavaQuickStarterService (d9b1e929f2464d4c23fa9cb47df4a1d4) C:\Program Files\Java\jre7\bin\jqs.exe
21:59:18.0625 2356 JavaQuickStarterService - ok
21:59:18.0843 2356 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:59:18.0984 2356 Kbdclass - ok
21:59:19.0031 2356 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
21:59:19.0203 2356 kmixer - ok
21:59:19.0265 2356 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
21:59:19.0390 2356 KSecDD - ok
21:59:19.0546 2356 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
21:59:19.0625 2356 lanmanserver - ok
21:59:19.0656 2356 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
21:59:19.0796 2356 lanmanworkstation - ok
21:59:19.0937 2356 Lavasoft Kernexplorer - ok
21:59:20.0000 2356 lbrtfdc - ok
21:59:20.0171 2356 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
21:59:20.0328 2356 LmHosts - ok
21:59:20.0453 2356 lvpopflt (af280405c10f0d20f37670b7432e5c2f) C:\WINDOWS\system32\DRIVERS\lvpopflt.sys
21:59:20.0468 2356 lvpopflt - ok
21:59:20.0515 2356 LVRS (e52f5a2cadcf08d07f559962f807a0a2) C:\WINDOWS\system32\DRIVERS\lvrs.sys
21:59:20.0546 2356 LVRS - ok
21:59:20.0687 2356 LVUVC (032686f872925340e94277964b6ce806) C:\WINDOWS\system32\DRIVERS\lvuvc.sys
21:59:21.0015 2356 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\lvuvc.sys. Real md5: 032686f872925340e94277964b6ce806, Fake md5: c3d02260beb2b48dea1efdfca91e4b69
21:59:21.0046 2356 LVUVC ( ForgedFile.Multi.Generic ) - warning
21:59:21.0046 2356 LVUVC - detected ForgedFile.Multi.Generic (1)
21:59:21.0234 2356 MarvinBus (d51e16339213898bc20c58670274ec3e) C:\WINDOWS\system32\DRIVERS\MarvinBus.sys
21:59:21.0343 2356 MarvinBus - ok
21:59:21.0375 2356 meiudf (7efac183a25b30fb5d64cc9d484b1eb6) C:\WINDOWS\system32\Drivers\meiudf.sys
21:59:21.0406 2356 meiudf ( UnsignedFile.Multi.Generic ) - warning
21:59:21.0406 2356 meiudf - detected UnsignedFile.Multi.Generic (1)
21:59:21.0468 2356 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
21:59:21.0625 2356 Messenger - ok
21:59:21.0671 2356 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
21:59:21.0828 2356 mnmdd - ok
21:59:21.0890 2356 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
21:59:22.0046 2356 mnmsrvc - ok
21:59:22.0218 2356 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
21:59:22.0359 2356 Modem - ok
21:59:22.0390 2356 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:59:22.0531 2356 Mouclass - ok
21:59:22.0578 2356 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
21:59:22.0718 2356 mouhid - ok
21:59:22.0734 2356 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
21:59:22.0890 2356 MountMgr - ok
21:59:22.0906 2356 mraid35x - ok
21:59:22.0921 2356 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:59:23.0062 2356 MRxDAV - ok
21:59:23.0140 2356 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:59:23.0281 2356 MRxSmb - ok
21:59:23.0328 2356 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
21:59:23.0484 2356 MSDTC - ok
21:59:23.0734 2356 MSDV (1477849772712bac69c144dcf2c9ce81) C:\WINDOWS\system32\DRIVERS\msdv.sys
21:59:23.0890 2356 MSDV - ok
21:59:23.0921 2356 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
21:59:24.0078 2356 Msfs - ok
21:59:24.0093 2356 MSIServer - ok
21:59:24.0140 2356 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:59:24.0296 2356 MSKSSRV - ok
21:59:24.0312 2356 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:59:24.0468 2356 MSPCLOCK - ok
21:59:24.0500 2356 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
21:59:24.0656 2356 MSPQM - ok
21:59:24.0718 2356 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:59:24.0859 2356 mssmbios - ok
21:59:24.0859 2356 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
21:59:25.0000 2356 MSTEE - ok
21:59:25.0078 2356 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
21:59:25.0125 2356 Mup - ok
21:59:25.0328 2356 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
21:59:25.0500 2356 NABTSFEC - ok
21:59:25.0593 2356 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
21:59:25.0734 2356 napagent - ok
21:59:25.0781 2356 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
21:59:25.0953 2356 NDIS - ok
21:59:25.0984 2356 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
21:59:26.0140 2356 NdisIP - ok
21:59:26.0203 2356 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:59:26.0312 2356 NdisTapi - ok
21:59:26.0531 2356 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:59:26.0703 2356 Ndisuio - ok
21:59:26.0734 2356 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:59:26.0875 2356 NdisWan - ok
21:59:26.0937 2356 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
21:59:27.0000 2356 NDProxy - ok
21:59:27.0062 2356 Net Driver HPZ12 (9eac175ba34898308620c1984c881845) C:\WINDOWS\system32\HPZinw12.dll
21:59:27.0125 2356 Net Driver HPZ12 - ok
21:59:27.0156 2356 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
21:59:27.0296 2356 NetBIOS - ok
21:59:27.0328 2356 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
21:59:27.0484 2356 NetBT - ok
21:59:27.0625 2356 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
21:59:27.0796 2356 NetDDE - ok
21:59:27.0796 2356 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
21:59:27.0937 2356 NetDDEdsdm - ok
21:59:28.0062 2356 Netdevio (1265eb253ed4ebe4acb3bd5f548ff796) C:\WINDOWS\system32\DRIVERS\netdevio.sys
21:59:28.0078 2356 Netdevio ( UnsignedFile.Multi.Generic ) - warning
21:59:28.0078 2356 Netdevio - detected UnsignedFile.Multi.Generic (1)
21:59:28.0125 2356 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
21:59:28.0265 2356 Netlogon - ok
21:59:28.0296 2356 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
21:59:28.0484 2356 Netman - ok
21:59:28.0531 2356 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
21:59:28.0671 2356 NIC1394 - ok
21:59:28.0703 2356 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
21:59:28.0734 2356 Nla - ok
21:59:29.0125 2356 NLNdisPT (1b49b83747509b2b1d707cd4b09aa504) C:\WINDOWS\system32\DRIVERS\nlndis.sys
21:59:29.0578 2356 NLNdisPT - ok
21:59:29.0687 2356 nmwcd (65ac8baa2f916ee9203ee48d7fcee605) C:\WINDOWS\system32\drivers\ccdcmb.sys
21:59:29.0859 2356 nmwcd - ok
21:59:30.0015 2356 nmwcdc (29af182734a247240d89a0fe63dbef03) C:\WINDOWS\system32\drivers\ccdcmbo.sys
21:59:30.0078 2356 nmwcdc - ok
21:59:30.0125 2356 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
21:59:30.0281 2356 Npfs - ok
21:59:30.0343 2356 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
21:59:30.0562 2356 Ntfs - ok
21:59:30.0609 2356 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
21:59:30.0750 2356 NtLmSsp - ok
21:59:30.0781 2356 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
21:59:31.0000 2356 NtmsSvc - ok
21:59:31.0187 2356 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
21:59:31.0343 2356 Null - ok
21:59:31.0546 2356 nv (7d504e6fd9a69efd4bc8f8f4db66a01b) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
21:59:31.0953 2356 nv - ok
21:59:32.0000 2356 NVSvc (86fbfda2d525adffafdbf8668834f5a7) C:\WINDOWS\system32\nvsvc32.exe
21:59:32.0015 2356 NVSvc - ok
21:59:32.0031 2356 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:59:32.0187 2356 NwlnkFlt - ok
21:59:32.0218 2356 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:59:32.0359 2356 NwlnkFwd - ok
21:59:32.0609 2356 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
21:59:32.0765 2356 ohci1394 - ok
21:59:32.0937 2356 ose (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:59:32.0953 2356 ose - ok
21:59:33.0015 2356 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys
21:59:33.0171 2356 Parport - ok
21:59:33.0218 2356 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
21:59:33.0375 2356 PartMgr - ok
21:59:33.0625 2356 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
21:59:33.0781 2356 ParVdm - ok
21:59:33.0843 2356 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys
21:59:33.0890 2356 pccsmcfd - ok
21:59:33.0953 2356 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
21:59:34.0093 2356 PCI - ok
21:59:34.0109 2356 PCIDump - ok
21:59:34.0156 2356 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
21:59:34.0312 2356 PCIIde - ok
21:59:34.0359 2356 PCLEPCI (1bebe7de8508a02650cdce45c664c2a2) C:\WINDOWS\system32\drivers\pclepci.sys
21:59:34.0359 2356 PCLEPCI ( UnsignedFile.Multi.Generic ) - warning
21:59:34.0359 2356 PCLEPCI - detected UnsignedFile.Multi.Generic (1)
21:59:34.0375 2356 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
21:59:34.0515 2356 Pcmcia - ok
21:59:34.0640 2356 Pcouffin - ok
21:59:34.0734 2356 PDCOMP - ok
21:59:34.0750 2356 PDFRAME - ok
21:59:34.0765 2356 PDRELI - ok
21:59:34.0781 2356 PDRFRAME - ok
21:59:34.0781 2356 perc2 - ok
21:59:34.0796 2356 perc2hib - ok
21:59:34.0875 2356 Pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys
21:59:34.0890 2356 Pfc ( UnsignedFile.Multi.Generic ) - warning
21:59:34.0890 2356 Pfc - detected UnsignedFile.Multi.Generic (1)
21:59:34.0953 2356 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
21:59:34.0984 2356 PlugPlay - ok
21:59:35.0046 2356 Pml Driver HPZ12 (75cf9de0a67af916ed591743dfb69694) C:\WINDOWS\system32\HPZipm12.dll
21:59:35.0109 2356 Pml Driver HPZ12 - ok
21:59:35.0156 2356 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
21:59:35.0296 2356 PolicyAgent - ok
21:59:35.0359 2356 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:59:35.0515 2356 PptpMiniport - ok
21:59:35.0609 2356 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
21:59:35.0750 2356 ProtectedStorage - ok
21:59:35.0843 2356 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
21:59:36.0000 2356 PSched - ok
21:59:36.0078 2356 PSEXESVC (a283e768fa12ef33087f07b01f82d6dd) C:\WINDOWS\PSEXESVC.EXE
21:59:38.0406 2356 PSEXESVC - ok
21:59:38.0609 2356 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:59:38.0750 2356 Ptilink - ok
21:59:38.0781 2356 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys
21:59:38.0796 2356 PxHelp20 - ok
21:59:38.0843 2356 ql1080 - ok
21:59:38.0859 2356 Ql10wnt - ok
21:59:38.0875 2356 ql12160 - ok
21:59:38.0890 2356 ql1240 - ok
21:59:38.0906 2356 ql1280 - ok
21:59:38.0937 2356 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:59:39.0078 2356 RasAcd - ok
21:59:39.0156 2356 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
21:59:39.0296 2356 RasAuto - ok
21:59:39.0375 2356 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:59:39.0515 2356 Rasl2tp - ok
21:59:39.0671 2356 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
21:59:39.0828 2356 RasMan - ok
21:59:39.0890 2356 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:59:40.0031 2356 RasPppoe - ok
21:59:40.0078 2356 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
21:59:40.0250 2356 Raspti - ok
21:59:40.0281 2356 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:59:40.0437 2356 Rdbss - ok
21:59:40.0468 2356 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:59:40.0593 2356 RDPCDD - ok
21:59:40.0671 2356 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:59:40.0828 2356 rdpdr - ok
21:59:40.0968 2356 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
21:59:41.0062 2356 RDPWD - ok
21:59:41.0125 2356 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
21:59:41.0281 2356 RDSessMgr - ok
21:59:41.0390 2356 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
21:59:41.0531 2356 redbook - ok
21:59:41.0671 2356 RegSrvc (1b2857ef12d79a9f9adba14b0637cbf8) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
21:59:41.0703 2356 RegSrvc ( UnsignedFile.Multi.Generic ) - warning
21:59:41.0703 2356 RegSrvc - detected UnsignedFile.Multi.Generic (1)
21:59:41.0890 2356 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
21:59:42.0046 2356 RemoteAccess - ok
21:59:42.0093 2356 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
21:59:42.0234 2356 RemoteRegistry - ok
21:59:42.0390 2356 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
21:59:42.0531 2356 ROOTMODEM - ok
21:59:42.0593 2356 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
21:59:42.0750 2356 RpcLocator - ok
21:59:42.0937 2356 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
21:59:43.0015 2356 RpcSs - ok
21:59:43.0062 2356 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
21:59:43.0218 2356 RSVP - ok
21:59:43.0359 2356 S24EventMonitor (6c5155cc0e805c7be6028bff7ac14524) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
21:59:43.0406 2356 S24EventMonitor ( UnsignedFile.Multi.Generic ) - warning
21:59:43.0406 2356 S24EventMonitor - detected UnsignedFile.Multi.Generic (1)
21:59:43.0593 2356 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
21:59:43.0609 2356 s24trans ( UnsignedFile.Multi.Generic ) - warning
21:59:43.0609 2356 s24trans - detected UnsignedFile.Multi.Generic (1)
21:59:43.0656 2356 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
21:59:43.0812 2356 SamSs - ok
21:59:43.0937 2356 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
21:59:43.0953 2356 SASDIFSV - ok
21:59:44.0015 2356 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
21:59:44.0031 2356 SASKUTIL - ok
21:59:44.0062 2356 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
21:59:44.0250 2356 SCardSvr - ok
21:59:44.0406 2356 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
21:59:44.0562 2356 Schedule - ok
21:59:44.0625 2356 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys
21:59:44.0796 2356 sdbus - ok
21:59:44.0859 2356 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:59:44.0953 2356 Secdrv - ok
21:59:44.0968 2356 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
21:59:45.0109 2356 seclogon - ok
21:59:45.0125 2356 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
21:59:45.0296 2356 SENS - ok
21:59:45.0359 2356 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
21:59:45.0531 2356 Serial - ok
21:59:45.0703 2356 ServiceLayer (6ad303a3529b7aef99391de19f5b400b) C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
21:59:45.0781 2356 ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
21:59:45.0796 2356 ServiceLayer - detected UnsignedFile.Multi.Generic (1)
21:59:46.0015 2356 sffdisk (0fa803c64df0914b41f807ea276bf2a6) C:\WINDOWS\system32\DRIVERS\sffdisk.sys
21:59:46.0171 2356 sffdisk - ok
21:59:46.0203 2356 sffp_sd (c17c331e435ed8737525c86a7557b3ac) C:\WINDOWS\system32\DRIVERS\sffp_sd.sys
21:59:46.0359 2356 sffp_sd - ok
21:59:46.0421 2356 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
21:59:46.0578 2356 Sfloppy - ok
21:59:46.0640 2356 SharedAccess (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
21:59:46.0843 2356 SharedAccess - ok
21:59:46.0906 2356 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
21:59:46.0953 2356 ShellHWDetection - ok
21:59:47.0109 2356 Simbad - ok
21:59:47.0140 2356 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
21:59:47.0281 2356 SLIP - ok
21:59:47.0390 2356 smihlp (aef89571c4e567575db8bdf120765b6c) C:\Program Files\Protector Suite QL\smihlp.sys
21:59:47.0406 2356 smihlp ( UnsignedFile.Multi.Generic ) - warning
21:59:47.0406 2356 smihlp - detected UnsignedFile.Multi.Generic (1)
21:59:47.0421 2356 Sparrow - ok
21:59:47.0531 2356 speedfan (3fa2e254bfbce52b3c6f1bf23aab6911) C:\WINDOWS\system32\speedfan.sys
21:59:47.0546 2356 speedfan - ok
21:59:47.0750 2356 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
21:59:47.0875 2356 splitter - ok
21:59:47.0937 2356 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
21:59:48.0015 2356 Spooler - ok
21:59:48.0046 2356 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
21:59:48.0125 2356 sr - ok
21:59:48.0203 2356 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
21:59:48.0265 2356 srservice - ok
21:59:48.0343 2356 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
21:59:48.0453 2356 Srv - ok
21:59:48.0578 2356 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
21:59:48.0687 2356 SSDPSRV - ok
21:59:48.0796 2356 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
21:59:48.0921 2356 StillCam - ok
21:59:48.0984 2356 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
21:59:49.0171 2356 stisvc - ok
21:59:49.0234 2356 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
21:59:49.0375 2356 streamip - ok
21:59:49.0421 2356 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
21:59:49.0562 2356 swenum - ok
21:59:49.0687 2356 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
21:59:49.0843 2356 swmidi - ok
21:59:49.0906 2356 SwPrv - ok
21:59:49.0968 2356 symc810 - ok
21:59:49.0984 2356 symc8xx - ok
21:59:50.0093 2356 SymEvent (3c6790d26d03fe5163e2bec490e51a7e) C:\Program Files\Symantec\SYMEVENT.SYS
21:59:50.0109 2356 SymEvent - ok
21:59:50.0125 2356 sym_hi - ok
21:59:50.0140 2356 sym_u3 - ok
21:59:50.0203 2356 SynTP (e295fffff3aaf9a6a40b29497901908f) C:\WINDOWS\system32\DRIVERS\SynTP.sys
21:59:50.0281 2356 SynTP - ok
21:59:50.0421 2356 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
21:59:50.0578 2356 sysaudio - ok
21:59:50.0687 2356 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
21:59:50.0843 2356 SysmonLog - ok
21:59:50.0906 2356 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
21:59:51.0062 2356 TapiSrv - ok
21:59:51.0187 2356 TAPPSRV (90861642fd6d8fafb1408ee26fa93cb4) C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
21:59:51.0218 2356 TAPPSRV ( UnsignedFile.Multi.Generic ) - warning
21:59:51.0218 2356 TAPPSRV - detected UnsignedFile.Multi.Generic (1)
21:59:51.0343 2356 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:59:51.0406 2356 Tcpip - ok
21:59:51.0609 2356 TcUsb (fc6fe02f400308606a911640e72326b5) C:\WINDOWS\system32\Drivers\tcusb.sys
21:59:51.0671 2356 TcUsb - ok
21:59:51.0687 2356 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
21:59:51.0843 2356 TDPIPE - ok
21:59:51.0875 2356 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
21:59:52.0015 2356 TDTCP - ok
21:59:52.0125 2356 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
21:59:52.0265 2356 TermDD - ok
21:59:52.0343 2356 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
21:59:52.0515 2356 TermService - ok
21:59:52.0656 2356 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
21:59:52.0687 2356 Themes - ok
21:59:52.0781 2356 tifm21 (244cfbffdefb77f3df571a8cd108fc06) C:\WINDOWS\system32\drivers\tifm21.sys
21:59:52.0843 2356 tifm21 - ok
21:59:52.0890 2356 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe
21:59:52.0968 2356 TlntSvr - ok
21:59:53.0046 2356 toshidpt (e362d54fd394999c4178936396664e57) C:\WINDOWS\system32\drivers\Toshidpt.sys
21:59:53.0062 2356 toshidpt ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0062 2356 toshidpt - detected UnsignedFile.Multi.Generic (1)
21:59:53.0062 2356 TosIde - ok
21:59:53.0234 2356 tosporte (d626e0af9232d8799d3a449530f3c220) C:\WINDOWS\system32\DRIVERS\tosporte.sys
21:59:53.0250 2356 tosporte ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0250 2356 tosporte - detected UnsignedFile.Multi.Generic (1)
21:59:53.0281 2356 Tosrfbd (294675c8e4316302efe14b1a1219d942) C:\WINDOWS\system32\Drivers\tosrfbd.sys
21:59:53.0312 2356 Tosrfbd ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0312 2356 Tosrfbd - detected UnsignedFile.Multi.Generic (1)
21:59:53.0359 2356 Tosrfbnp (613e09572f4c5b92ca6be8bdc4cc5b7d) C:\WINDOWS\system32\Drivers\tosrfbnp.sys
21:59:53.0390 2356 Tosrfbnp ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0390 2356 Tosrfbnp - detected UnsignedFile.Multi.Generic (1)
21:59:53.0421 2356 Tosrfcom (5ba1ca3b3cddb1ddc67df473f05d1ec2) C:\WINDOWS\system32\Drivers\tosrfcom.sys
21:59:53.0421 2356 Tosrfcom ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0421 2356 Tosrfcom - detected UnsignedFile.Multi.Generic (1)
21:59:53.0453 2356 tosrfec (cc069342ee0eae55b32a0ae99cf6185c) C:\WINDOWS\system32\DRIVERS\tosrfec.sys
21:59:53.0468 2356 tosrfec ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0468 2356 tosrfec - detected UnsignedFile.Multi.Generic (1)
21:59:53.0531 2356 Tosrfhid (31b0145c289d2b3e3e9948345caa7b6f) C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys
21:59:53.0546 2356 Tosrfhid ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0546 2356 Tosrfhid - detected UnsignedFile.Multi.Generic (1)
21:59:53.0578 2356 tosrfnds (c52fd27b9adf3a1f22cb90e6bcf9b0cb) C:\WINDOWS\system32\DRIVERS\tosrfnds.sys
21:59:53.0593 2356 tosrfnds ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0593 2356 tosrfnds - detected UnsignedFile.Multi.Generic (1)
21:59:53.0609 2356 TosRfSnd (0d86d15caff2b3203c785d604ec7c942) C:\WINDOWS\system32\drivers\TosRfSnd.sys
21:59:53.0625 2356 TosRfSnd ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0625 2356 TosRfSnd - detected UnsignedFile.Multi.Generic (1)
21:59:53.0781 2356 Tosrfusb (7414a6461bc83a22b0ae009ace3e375b) C:\WINDOWS\system32\Drivers\tosrfusb.sys
21:59:53.0796 2356 Tosrfusb ( UnsignedFile.Multi.Generic ) - warning
21:59:53.0796 2356 Tosrfusb - detected UnsignedFile.Multi.Generic (1)
21:59:53.0875 2356 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
21:59:54.0015 2356 TrkWks - ok
21:59:54.0093 2356 truecrypt (aceb4f4f83b895e15c8c1a2f55009783) C:\WINDOWS\system32\drivers\truecrypt.sys
21:59:54.0109 2356 truecrypt - ok
21:59:54.0171 2356 TVALD (676db15ddf2e0ff6ec03068dea428b8b) C:\WINDOWS\system32\DRIVERS\NBSMI.sys
21:59:54.0203 2356 TVALD ( UnsignedFile.Multi.Generic ) - warning
21:59:54.0203 2356 TVALD - detected UnsignedFile.Multi.Generic (1)
21:59:54.0312 2356 Tvs (cc6763889198ef975b143d49789bcfa9) C:\WINDOWS\system32\DRIVERS\Tvs.sys
21:59:54.0343 2356 Tvs ( UnsignedFile.Multi.Generic ) - warning
21:59:54.0343 2356 Tvs - detected UnsignedFile.Multi.Generic (1)
21:59:54.0406 2356 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
21:59:54.0562 2356 Udfs - ok
21:59:54.0671 2356 ultra - ok
21:59:54.0750 2356 UMWdf (c81b8635dee0d3ef5f64b3dd643023a5) C:\WINDOWS\system32\wdfmgr.exe
21:59:54.0828 2356 UMWdf - ok
21:59:54.0859 2356 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
21:59:55.0062 2356 Update - ok
21:59:55.0109 2356 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
21:59:55.0203 2356 upnphost - ok
21:59:55.0312 2356 upperdev (2522747ba661514e3770e508cce45b64) C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys
21:59:55.0375 2356 upperdev - ok
21:59:55.0640 2356 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
21:59:55.0781 2356 UPS - ok
21:59:55.0875 2356 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
21:59:56.0015 2356 usbaudio - ok
21:59:56.0093 2356 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:59:56.0234 2356 usbccgp - ok
21:59:56.0296 2356 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:59:56.0453 2356 usbehci - ok
21:59:56.0531 2356 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:59:56.0687 2356 usbhub - ok
21:59:56.0828 2356 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
21:59:56.0984 2356 usbprint - ok
21:59:57.0078 2356 usbser (1c888b000c2f9492f4b15b5b6b84873e) C:\WINDOWS\system32\DRIVERS\usbser.sys
21:59:57.0234 2356 usbser - ok
21:59:57.0296 2356 UsbserFilt (8aa5f86a6c3b3234beed9556d145bfac) C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys
21:59:57.0359 2356 UsbserFilt - ok
21:59:57.0453 2356 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:59:57.0609 2356 USBSTOR - ok
21:59:57.0687 2356 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:59:57.0828 2356 usbuhci - ok
21:59:57.0953 2356 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
21:59:58.0093 2356 usbvideo - ok
21:59:58.0140 2356 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
21:59:58.0281 2356 VgaSave - ok
21:59:58.0296 2356 ViaIde - ok
21:59:58.0312 2356 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
21:59:58.0468 2356 VolSnap - ok
21:59:58.0531 2356 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
21:59:58.0609 2356 VSS - ok
21:59:58.0640 2356 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
21:59:58.0796 2356 W32Time - ok
21:59:58.0937 2356 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys
21:59:59.0171 2356 w39n51 - ok
21:59:59.0296 2356 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:59:59.0453 2356 Wanarp - ok
21:59:59.0515 2356 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
21:59:59.0578 2356 Wdf01000 - ok
21:59:59.0593 2356 WDICA - ok
21:59:59.0640 2356 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
21:59:59.0796 2356 wdmaud - ok
21:59:59.0859 2356 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
22:00:00.0015 2356 WebClient - ok
22:00:00.0187 2356 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
22:00:00.0437 2356 winmgmt - ok
22:00:00.0640 2356 WmdmPmSN (a477391b7a8b0a0daabadb17cf533a4b) C:\WINDOWS\system32\MsPMSNSv.dll
22:00:00.0765 2356 WmdmPmSN - ok
22:00:01.0015 2356 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
22:00:01.0312 2356 Wmi - ok
22:00:01.0703 2356 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:00:01.0890 2356 WmiApSrv - ok
22:00:01.0984 2356 wscsvc (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
22:00:02.0171 2356 wscsvc - ok
22:00:02.0406 2356 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:00:02.0546 2356 WSTCODEC - ok
22:00:02.0578 2356 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
22:00:02.0734 2356 wuauserv - ok
22:00:02.0812 2356 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
22:00:03.0031 2356 WZCSVC - ok
22:00:03.0218 2356 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
22:00:03.0359 2356 xmlprov - ok
22:00:03.0406 2356 MBR (0x1B8) (3dfbd33517922022aab2367021b4bbec) \Device\Harddisk0\DR0
22:00:03.0437 2356 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - infected
22:00:03.0437 2356 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Wistler.a (0)
22:00:03.0546 2356 Boot (0x1200) (b1ea1f031d645e7788a127aa8c98f59b) \Device\Harddisk0\DR0\Partition0
22:00:03.0546 2356 \Device\Harddisk0\DR0\Partition0 - ok
22:00:03.0546 2356 ============================================================
22:00:03.0546 2356 Scan finished
22:00:03.0546 2356 ============================================================
22:00:03.0656 2928 Detected object count: 48
22:00:03.0656 2928 Actual detected object count: 48
22:02:25.0375 2928 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0375 2928 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0375 2928 ASAPIW2k ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0375 2928 ASAPIW2k ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0375 2928 aspnet_state ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0375 2928 aspnet_state ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0375 2928 CFSvcs ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0375 2928 CFSvcs ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0375 2928 DLABOIOM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0375 2928 DLABOIOM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLACDBHM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLACDBHM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLADResN ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLADResN ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLAIFS_M ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLAIFS_M ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLAOPIOM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLAOPIOM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLAPoolM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLAPoolM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLARTL_N ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLARTL_N ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0390 2928 DLAUDFAM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0390 2928 DLAUDFAM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 DLAUDF_M ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 DLAUDF_M ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 DRVMCDB ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 DRVMCDB ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 DRVNDDM ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 DRVNDDM ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 DVD-RAM_Service ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 DVD-RAM_Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 EvtEng ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 EvtEng ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 FdRedir ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 FdRedir ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0406 2928 FileDisk2 ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0406 2928 FileDisk2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 Iviaspi ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 Iviaspi ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 LVUVC ( ForgedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 LVUVC ( ForgedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 meiudf ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 meiudf ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 Netdevio ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 Netdevio ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 PCLEPCI ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 PCLEPCI ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0421 2928 Pfc ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0421 2928 Pfc ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 RegSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 RegSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 S24EventMonitor ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 S24EventMonitor ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 s24trans ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 s24trans ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 smihlp ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 smihlp ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 TAPPSRV ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 TAPPSRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 toshidpt ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 toshidpt ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 tosporte ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 tosporte ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0437 2928 Tosrfbd ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0437 2928 Tosrfbd ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 Tosrfbnp ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 Tosrfbnp ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 Tosrfcom ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 Tosrfcom ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 tosrfec ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 tosrfec ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 Tosrfhid ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 Tosrfhid ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 tosrfnds ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 tosrfnds ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 TosRfSnd ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 TosRfSnd ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0453 2928 Tosrfusb ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0453 2928 Tosrfusb ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0468 2928 TVALD ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0468 2928 TVALD ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:25.0468 2928 Tvs ( UnsignedFile.Multi.Generic ) - skipped by user
22:02:25.0468 2928 Tvs ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:02:26.0015 2928 \Device\Harddisk0\DR0\# - copied to quarantine
22:02:26.0015 2928 \Device\Harddisk0\DR0 - copied to quarantine
22:02:26.0031 2928 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - will be cured on reboot
22:02:26.0031 2928 \Device\Harddisk0\DR0 - ok
22:02:26.0031 2928 \Device\Harddisk0\DR0 ( Rootkit.Boot.Wistler.a ) - User select action: Cure
22:03:10.0640 1748 Deinitialize success
  • 0

Advertisements


#47
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
It was the new whistler, I will pass that on to Avast and GMER

No try the command prompts please

22:02:25.0421 2928 LVUVC ( ForgedFile.Multi.Generic ) - skipped by user

TDSSKillere reports a forged MD5 on this file, do you use a Logitech video camera ? If so do you have the driver disc for it ? as we may need to delete it
  • 0

#48
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Yes, I have a Logitech camera, only installed about 6 months ago. Have software for it, so let me know what to do.

Sorry, I meant cmd, not otl, so will run those now.
  • 0

#49
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
I might be doing something wrong, as the cmd process isn't doing anything. To be clear:

I run cmd prompt
Type chkntfs /x c:
Hit enter
Result: The type of the file system is NTFS
I shut down all power
Start machine
Once in Windows, run cmd prompt again
Type chkdsk /f /r c:
Type 'Y' to schedule disk check on next restart
Type 'exit' to close prompt
I restart/reboot the machine (have tried it both ways)

Unfortunately, Windows begins to load, then the chkdsk screen says direct access to volume isn't possible, disk check terminates, and the machine continues to the log on screen.

Am I missing something?

Edited by pivan, 17 April 2012 - 07:16 AM.

  • 0

#50
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Nope the commands are correct I will revisit that area - Meanwhile re-run TDSSKiller

When you see this then select Cure
If cure is not available then select Delete

LVUVC ( ForgedFile.Multi.Generic )

You will then need to re-install the software

Meanwhile back to a bit of digging and replaying
  • 0

#51
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Hmmm, our friend LVUVC ( ForgedFile.Multi.Generic ) doesn't appear in the latest TDSS scan. I'll try again later in the day in case something changes.
  • 0

#52
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
As it no longer appears it may well have just been hooked by the MBR malware

Use the following command to reset disc check please

CHKNTFS /D C:

There is a hotfix for IE8 that should stop the previous behaviour, however the problem should have been fixed with SP3

Download the following Hotfix to your desktop


http://www.microsoft...;displaylang=en

Reinstall IE8, if you get the same error then run the hotfix and reboot
  • 0

#53
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Will do. Although I'm reluctant to revisit IE8.
  • 0

#54
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
That latest command returns:

CHKNTFS: Incorrect command-line format.
  • 0

#55
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
If you get the same error then run the hotfix
  • 0

Advertisements


#56
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Yes, the IE8 aspect is under control, and am basically waiting to see if any crashes occur (so far 2 hours crash-free), but my last post was re the CHKNTFS message. Anything more on that front? Cheers.
  • 0

#57
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Do you get the check disc error now when you reboot ?
  • 0

#58
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
Yes.

I can only assume a process is using the volume during start up.
  • 0

#59
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
It is a low level driver causing that

Now we can work that out using the recovery console

Do you have the windows CD ? If not we can install the recovery console seperately and then run Chk disc prior to windows loading
  • 0

#60
pivan

pivan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 39 posts
I had a look for the Windows CD the other day, actually. Computer came preinstalled, and only received Windows booklet with key number, and a Toshiba CD that has some Windows stuff on it too. I think it's a recovery disc with a few other bits and pieces on it. Don't have it with me now, sorry. Does that sound right for a Satellite notebook?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP