Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 10-12-2013 01
Ran by Lara at 2013-12-11 14:00:59 Run:1
Running from C:\Users\Lara\Downloads
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKCU\...0c966feabec1\InprocServer32: [Default-shell32] ATTENTION! ====> ZeroAccess?
ProxyServer: 75.125.242.146:80
ZeroAccess:
C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d}
C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d}\@
C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d}\U\00000001.@
*****************
HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1} => Key deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => Value deleted successfully.
C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d} => Moved successfully.
"C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d}\@" => File/Directory not found.
"C:\Users\Lara\AppData\Local\{5d96d0aa-55cc-4e45-dbc4-569667e6d76d}\U\00000001.@" => File/Directory not found.
==== End of Fixlog ==== Code:
14:04:42.0198 2408 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
14:04:44.0912 2408 ============================================================
14:04:44.0912 2408 Current date / time: 2013/12/11 14:04:44.0912
14:04:44.0912 2408 SystemInfo:
14:04:44.0912 2408
14:04:44.0912 2408 OS Version: 6.0.6002 ServicePack: 2.0
14:04:44.0912 2408 Product type: Workstation
14:04:44.0912 2408 ComputerName: LARA-PC
14:04:44.0912 2408 UserName: Lara
14:04:44.0912 2408 Windows directory: C:\Windows
14:04:44.0912 2408 System windows directory: C:\Windows
14:04:44.0912 2408 Processor architecture: Intel x86
14:04:44.0912 2408 Number of processors: 2
14:04:44.0912 2408 Page size: 0x1000
14:04:44.0912 2408 Boot type: Normal boot
14:04:44.0912 2408 ============================================================
14:04:47.0174 2408 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:04:47.0190 2408 ============================================================
14:04:47.0190 2408 \Device\Harddisk0\DR0:
14:04:47.0190 2408 MBR partitions:
14:04:47.0190 2408 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1400800, BlocksNum 0x11940000
14:04:47.0190 2408 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x12D40800, BlocksNum 0x126ED800
14:04:47.0190 2408 ============================================================
14:04:47.0206 2408 C: <-> \Device\Harddisk0\DR0\Partition1
14:04:47.0315 2408 D: <-> \Device\Harddisk0\DR0\Partition2
14:04:47.0315 2408 ============================================================
14:04:47.0315 2408 Initialize success
14:04:47.0330 2408 ============================================================
14:06:39.0270 5812 ============================================================
14:06:39.0270 5812 Scan started
14:06:39.0270 5812 Mode: Manual; SigCheck; TDLFS;
14:06:39.0270 5812 ============================================================
14:06:40.0144 5812 ================ Scan system memory ========================
14:06:40.0144 5812 System memory - ok
14:06:40.0144 5812 ================ Scan services =============================
14:06:40.0362 5812 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys
14:06:40.0565 5812 ACPI - ok
14:06:40.0721 5812 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
14:06:40.0736 5812 AdobeARMservice - ok
14:06:40.0830 5812 [ 1BA1AB4141A92EB34DA99F1249CA2D4D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:06:40.0846 5812 AdobeFlashPlayerUpdateSvc - ok
14:06:40.0908 5812 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
14:06:40.0939 5812 adp94xx - ok
14:06:40.0986 5812 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys
14:06:41.0002 5812 adpahci - ok
14:06:41.0033 5812 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
14:06:41.0048 5812 adpu160m - ok
14:06:41.0080 5812 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
14:06:41.0111 5812 adpu320 - ok
14:06:41.0142 5812 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:06:41.0236 5812 AeLookupSvc - ok
14:06:41.0298 5812 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys
14:06:41.0360 5812 AFD - ok
14:06:41.0392 5812 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys
14:06:41.0407 5812 agp440 - ok
14:06:41.0423 5812 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys
14:06:41.0438 5812 aic78xx - ok
14:06:41.0485 5812 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe
14:06:41.0548 5812 ALG - ok
14:06:41.0579 5812 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys
14:06:41.0594 5812 aliide - ok
14:06:41.0626 5812 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:06:41.0641 5812 amdagp - ok
14:06:41.0657 5812 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys
14:06:41.0672 5812 amdide - ok
14:06:41.0750 5812 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys
14:06:41.0813 5812 AmdK7 - ok
14:06:41.0828 5812 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
14:06:41.0891 5812 AmdK8 - ok
14:06:41.0922 5812 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll
14:06:41.0984 5812 Appinfo - ok
14:06:42.0062 5812 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
14:06:42.0078 5812 Apple Mobile Device - ok
14:06:42.0109 5812 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys
14:06:42.0140 5812 arc - ok
14:06:42.0187 5812 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys
14:06:42.0203 5812 arcsas - ok
14:06:42.0234 5812 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:06:42.0296 5812 AsyncMac - ok
14:06:42.0328 5812 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys
14:06:42.0343 5812 atapi - ok
14:06:42.0515 5812 [ F32FEE7CB2EE32C1F808409BC8019701 ] athr C:\Windows\system32\DRIVERS\athr.sys
14:06:42.0593 5812 athr - ok
14:06:42.0640 5812 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:06:42.0671 5812 AudioEndpointBuilder - ok
14:06:42.0702 5812 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:06:42.0733 5812 Audiosrv - ok
14:06:42.0827 5812 [ F48FEB7DA35821DA15E0B006DCB9A169 ] BBSvc C:\Program Files\Microsoft\BingBar\7.1.391.0\BBSvc.exe
14:06:42.0858 5812 BBSvc - ok
14:06:42.0905 5812 [ 8E16F7A85441986FD2B9CE6C879524E4 ] BBUpdate C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe
14:06:42.0936 5812 BBUpdate - ok
14:06:42.0983 5812 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys
14:06:43.0030 5812 Beep - ok
14:06:43.0123 5812 [ C789AF0F724FDA5852FB9A7D3A432381 ] BFE C:\Windows\System32\bfe.dll
14:06:43.0232 5812 BFE - ok
14:06:43.0279 5812 [ 93952506C6D67330367F7E7934B6A02F ] BITS C:\Windows\system32\qmgr.dll
14:06:43.0357 5812 BITS - ok
14:06:43.0404 5812 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
14:06:43.0451 5812 blbdrive - ok
14:06:43.0591 5812 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
14:06:43.0622 5812 Bonjour Service - ok
14:06:43.0654 5812 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:06:43.0700 5812 bowser - ok
14:06:43.0747 5812 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
14:06:43.0794 5812 BrFiltLo - ok
14:06:43.0825 5812 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
14:06:43.0903 5812 BrFiltUp - ok
14:06:43.0934 5812 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll
14:06:43.0997 5812 Browser - ok
14:06:44.0044 5812 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys
14:06:44.0293 5812 Brserid - ok
14:06:44.0309 5812 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
14:06:44.0387 5812 BrSerWdm - ok
14:06:44.0418 5812 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
14:06:44.0496 5812 BrUsbMdm - ok
14:06:44.0512 5812 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
14:06:44.0558 5812 BrUsbSer - ok
14:06:44.0605 5812 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
14:06:44.0668 5812 BTHMODEM - ok
14:06:44.0699 5812 catchme - ok
14:06:44.0714 5812 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:06:44.0761 5812 cdfs - ok
14:06:44.0792 5812 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:06:44.0839 5812 cdrom - ok
14:06:44.0870 5812 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll
14:06:44.0917 5812 CertPropSvc - ok
14:06:44.0948 5812 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys
14:06:45.0011 5812 circlass - ok
14:06:45.0073 5812 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys
14:06:45.0104 5812 CLFS - ok
14:06:45.0307 5812 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:06:45.0338 5812 clr_optimization_v2.0.50727_32 - ok
14:06:45.0416 5812 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:06:45.0432 5812 clr_optimization_v4.0.30319_32 - ok
14:06:45.0510 5812 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:06:45.0572 5812 CmBatt - ok
14:06:45.0619 5812 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:06:45.0635 5812 cmdide - ok
14:06:45.0666 5812 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:06:45.0697 5812 Compbatt - ok
14:06:45.0775 5812 COMSysApp - ok
14:06:45.0822 5812 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
14:06:45.0853 5812 crcdisk - ok
14:06:45.0962 5812 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys
14:06:46.0040 5812 Crusoe - ok
14:06:46.0087 5812 [ 684C130BBC6DB681BAD4920A4C944AA5 ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:06:46.0150 5812 CryptSvc - ok
14:06:46.0212 5812 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll
14:06:46.0321 5812 DcomLaunch - ok
14:06:46.0352 5812 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:06:46.0415 5812 DfsC - ok
14:06:46.0602 5812 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe
14:06:46.0742 5812 DFSR - ok
14:06:46.0805 5812 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll
14:06:46.0852 5812 Dhcp - ok
14:06:46.0898 5812 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys
14:06:46.0914 5812 disk - ok
14:06:46.0992 5812 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:06:47.0039 5812 Dnscache - ok
14:06:47.0070 5812 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll
14:06:47.0132 5812 dot3svc - ok
14:06:47.0179 5812 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll
14:06:47.0242 5812 DPS - ok
14:06:47.0304 5812 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:06:47.0351 5812 drmkaud - ok
14:06:47.0460 5812 [ 988670D8343EF9835FB3659DB71B2EFA ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:06:47.0507 5812 DXGKrnl - ok
14:06:47.0538 5812 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys
14:06:47.0600 5812 E1G60 - ok
14:06:47.0663 5812 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll
14:06:47.0725 5812 EapHost - ok
14:06:47.0788 5812 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys
14:06:47.0819 5812 Ecache - ok
14:06:47.0975 5812 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:06:48.0022 5812 ehRecvr - ok
14:06:48.0037 5812 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe
14:06:48.0100 5812 ehSched - ok
14:06:48.0115 5812 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll
14:06:48.0146 5812 ehstart - ok
14:06:48.0209 5812 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys
14:06:48.0224 5812 elxstor - ok
14:06:48.0271 5812 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll
14:06:48.0349 5812 EMDMgmt - ok
14:06:48.0349 5812 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:06:48.0396 5812 ErrDev - ok
14:06:48.0443 5812 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll
14:06:48.0490 5812 EventSystem - ok
14:06:48.0552 5812 [ C37B83B51CDF10E5BB6F78A7E4FED11A ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
14:06:48.0599 5812 EvtEng - ok
14:06:48.0677 5812 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys
14:06:48.0724 5812 exfat - ok
14:06:48.0739 5812 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:06:48.0802 5812 fastfat - ok
14:06:48.0833 5812 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:06:48.0880 5812 fdc - ok
14:06:48.0911 5812 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll
14:06:48.0942 5812 fdPHost - ok
14:06:48.0989 5812 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll
14:06:49.0067 5812 FDResPub - ok
14:06:49.0098 5812 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:06:49.0114 5812 FileInfo - ok
14:06:49.0129 5812 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:06:49.0192 5812 Filetrace - ok
14:06:49.0223 5812 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:06:49.0270 5812 flpydisk - ok
14:06:49.0316 5812 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:06:49.0332 5812 FltMgr - ok
14:06:49.0426 5812 [ 2AFA3A46986AE935DAECEBC7E66314CF ] FontCache C:\Windows\system32\FntCache.dll
14:06:49.0504 5812 FontCache - ok
14:06:49.0582 5812 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:06:49.0597 5812 FontCache3.0.0.0 - ok
14:06:49.0675 5812 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:06:49.0784 5812 Fs_Rec - ok
14:06:49.0816 5812 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
14:06:49.0847 5812 gagp30kx - ok
14:06:49.0894 5812 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
14:06:49.0909 5812 GEARAspiWDM - ok
14:06:50.0065 5812 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll
14:06:50.0159 5812 gpsvc - ok
14:06:50.0206 5812 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:06:50.0237 5812 gupdate - ok
14:06:50.0284 5812 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:06:50.0299 5812 gupdatem - ok
14:06:50.0362 5812 [ 3F90E001369A07243763BD5A523D8722 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:06:50.0440 5812 HdAudAddService - ok
14:06:50.0502 5812 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
14:06:50.0564 5812 HDAudBus - ok
14:06:50.0611 5812 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys
14:06:50.0705 5812 HidBth - ok
14:06:50.0720 5812 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys
14:06:50.0814 5812 HidIr - ok
14:06:50.0845 5812 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\System32\hidserv.dll
14:06:50.0892 5812 hidserv - ok
14:06:50.0923 5812 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:06:50.0970 5812 HidUsb - ok
14:06:51.0001 5812 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:06:51.0032 5812 hkmsvc - ok
14:06:51.0064 5812 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
14:06:51.0064 5812 HpCISSs - ok
14:06:51.0142 5812 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:06:51.0266 5812 HTTP - ok
14:06:51.0282 5812 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys
14:06:51.0298 5812 i2omp - ok
14:06:51.0329 5812 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
14:06:51.0376 5812 i8042prt - ok
14:06:51.0407 5812 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
14:06:51.0422 5812 iaStorV - ok
14:06:51.0563 5812 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:06:51.0610 5812 idsvc - ok
14:06:51.0625 5812 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys
14:06:51.0641 5812 iirsp - ok
14:06:51.0703 5812 [ 4687EE0C0DD2CE5F7AAA9C2E33C1DC78 ] IKEEXT C:\Windows\System32\ikeext.dll
14:06:51.0734 5812 IKEEXT - ok
14:06:51.0953 5812 [ AEE99ECF06CD1CEA95816CCB5BF73EC8 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
14:06:52.0140 5812 IntcAzAudAddService - ok
14:06:52.0171 5812 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys
14:06:52.0202 5812 intelide - ok
14:06:52.0234 5812 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:06:52.0296 5812 intelppm - ok
14:06:52.0358 5812 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:06:52.0436 5812 IPBusEnum - ok
14:06:52.0452 5812 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:06:52.0499 5812 IpFilterDriver - ok
14:06:52.0530 5812 [ 1998BD97F950680BB55F55A7244679C2 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
14:06:52.0577 5812 iphlpsvc - ok
14:06:52.0592 5812 IpInIp - ok
14:06:52.0624 5812 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
14:06:52.0655 5812 IPMIDRV - ok
14:06:52.0670 5812 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
14:06:52.0702 5812 IPNAT - ok
14:06:52.0748 5812 [ E8A39D41474BE42FD8830CED32932D6C ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
14:06:52.0764 5812 iPod Service - ok
14:06:52.0795 5812 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:06:52.0811 5812 IRENUM - ok
14:06:52.0842 5812 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:06:52.0858 5812 isapnp - ok
14:06:52.0904 5812 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
14:06:52.0920 5812 iScsiPrt - ok
14:06:52.0936 5812 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
14:06:52.0951 5812 iteatapi - ok
14:06:52.0967 5812 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys
14:06:52.0982 5812 iteraid - ok
14:06:52.0998 5812 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
14:06:53.0014 5812 kbdclass - ok
14:06:53.0029 5812 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
14:06:53.0076 5812 kbdhid - ok
14:06:53.0107 5812 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe
14:06:53.0154 5812 KeyIso - ok
14:06:53.0201 5812 [ EBC507F129DF8F0E0CA270DCFC0CF87F ] KMDFMEMIO C:\Windows\system32\DRIVERS\kmdfmemio.sys
14:06:53.0232 5812 KMDFMEMIO - ok
14:06:53.0279 5812 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:06:53.0310 5812 KSecDD - ok
14:06:53.0357 5812 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll
14:06:53.0419 5812 KtmRm - ok
14:06:53.0466 5812 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\System32\srvsvc.dll
14:06:53.0497 5812 LanmanServer - ok
14:06:53.0544 5812 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:06:53.0591 5812 LanmanWorkstation - ok
14:06:53.0638 5812 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:06:53.0700 5812 lltdio - ok
14:06:53.0794 5812 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:06:53.0887 5812 lltdsvc - ok
14:06:53.0918 5812 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll
14:06:53.0996 5812 lmhosts - ok
14:06:54.0012 5812 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
14:06:54.0043 5812 LSI_FC - ok
14:06:54.0090 5812 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
14:06:54.0121 5812 LSI_SAS - ok
14:06:54.0152 5812 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
14:06:54.0184 5812 LSI_SCSI - ok
14:06:54.0215 5812 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys
14:06:54.0246 5812 luafv - ok
14:06:54.0277 5812 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
14:06:54.0293 5812 MBAMProtector - ok
14:06:54.0464 5812 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
14:06:54.0480 5812 MBAMScheduler - ok
14:06:54.0527 5812 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
14:06:54.0574 5812 MBAMService - ok
14:06:54.0714 5812 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McNASvc C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:06:54.0730 5812 McNASvc - ok
14:06:54.0808 5812 [ 7E6932EEDA54C8EAF7DC6C2225261B85 ] McProxy C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
14:06:54.0823 5812 McProxy - ok
14:06:54.0870 5812 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:06:54.0917 5812 Mcx2Svc - ok
14:06:54.0964 5812 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys
14:06:54.0979 5812 megasas - ok
14:06:55.0026 5812 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys
14:06:55.0057 5812 MegaSR - ok
14:06:55.0088 5812 [ 43C31BDF404A6D7A7AC1BFD5EAD2A566 ] mfeapfk C:\Windows\system32\drivers\mfeapfk.sys
14:06:55.0104 5812 mfeapfk - ok
14:06:55.0198 5812 [ D1E998748BA24A731106611D535C6BBF ] mfehidk C:\Windows\system32\drivers\mfehidk.sys
14:06:55.0229 5812 mfehidk - ok
14:06:55.0276 5812 [ 2B8DFC60EDDDAA33EB5E9F7C91B48ACD ] mfevtp C:\Windows\system32\mfevtps.exe
14:06:55.0291 5812 mfevtp - ok
14:06:55.0322 5812 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll
14:06:55.0400 5812 MMCSS - ok
14:06:55.0432 5812 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys
14:06:55.0494 5812 Modem - ok
14:06:55.0525 5812 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:06:55.0588 5812 monitor - ok
14:06:55.0603 5812 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
14:06:55.0619 5812 mouclass - ok
14:06:55.0634 5812 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:06:55.0681 5812 mouhid - ok
14:06:55.0728 5812 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
14:06:55.0759 5812 MountMgr - ok
14:06:55.0853 5812 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:06:55.0884 5812 MozillaMaintenance - ok
14:06:55.0931 5812 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys
14:06:55.0962 5812 mpio - ok
14:06:55.0978 5812 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:06:56.0040 5812 mpsdrv - ok
14:06:56.0087 5812 [ 5DE62C6E9108F14F6794060A9BDECAEC ] MpsSvc C:\Windows\system32\mpssvc.dll
14:06:56.0180 5812 MpsSvc - ok
14:06:56.0212 5812 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
14:06:56.0227 5812 Mraid35x - ok
14:06:56.0274 5812 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:06:56.0305 5812 MRxDAV - ok
14:06:56.0368 5812 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:06:56.0414 5812 mrxsmb - ok
14:06:56.0492 5812 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:06:56.0555 5812 mrxsmb10 - ok
14:06:56.0570 5812 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:06:56.0617 5812 mrxsmb20 - ok
14:06:56.0664 5812 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys
14:06:56.0680 5812 msahci - ok
14:06:56.0758 5812 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:06:56.0773 5812 msdsm - ok
14:06:56.0804 5812 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe
14:06:56.0851 5812 MSDTC - ok
14:06:56.0882 5812 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:06:56.0929 5812 Msfs - ok
14:06:56.0960 5812 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:06:56.0960 5812 msisadrv - ok
14:06:56.0992 5812 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:06:57.0038 5812 MSiSCSI - ok
14:06:57.0038 5812 msiserver - ok
14:06:57.0085 5812 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:06:57.0116 5812 MSKSSRV - ok
14:06:57.0163 5812 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:06:57.0194 5812 MSPCLOCK - ok
14:06:57.0210 5812 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:06:57.0257 5812 MSPQM - ok
14:06:57.0335 5812 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:06:57.0382 5812 MsRPC - ok
14:06:57.0413 5812 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
14:06:57.0428 5812 mssmbios - ok
14:06:57.0444 5812 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
14:06:57.0475 5812 MSTEE - ok
14:06:57.0506 5812 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys
14:06:57.0522 5812 Mup - ok
14:06:57.0569 5812 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll
14:06:57.0616 5812 napagent - ok
14:06:57.0662 5812 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
14:06:57.0678 5812 NativeWifiP - ok
14:06:57.0725 5812 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys
14:06:57.0772 5812 NDIS - ok
14:06:57.0803 5812 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
14:06:57.0865 5812 NdisTapi - ok
14:06:57.0896 5812 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
14:06:57.0928 5812 Ndisuio - ok
14:06:57.0974 5812 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
14:06:58.0006 5812 NdisWan - ok
14:06:58.0037 5812 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
14:06:58.0084 5812 NDProxy - ok
14:06:58.0099 5812 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
14:06:58.0162 5812 NetBIOS - ok
14:06:58.0208 5812 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
14:06:58.0271 5812 netbt - ok
14:06:58.0286 5812 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe
14:06:58.0318 5812 Netlogon - ok
14:06:58.0364 5812 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll
14:06:58.0442 5812 Netman - ok
14:06:58.0474 5812 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll
14:06:58.0536 5812 netprofm - ok
14:06:58.0598 5812 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:06:58.0614 5812 NetTcpPortSharing - ok
14:06:58.0645 5812 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
14:06:58.0661 5812 nfrd960 - ok
14:06:58.0754 5812 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
14:06:58.0801 5812 NlaSvc - ok
14:06:58.0832 5812 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys
14:06:58.0926 5812 Npfs - ok
14:06:58.0957 5812 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll
14:06:59.0035 5812 nsi - ok
14:06:59.0082 5812 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
14:06:59.0129 5812 nsiproxy - ok
14:06:59.0347 5812 [ 2C1121F2B87E9A6B12485DF53CD848C7 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
14:06:59.0425 5812 Ntfs - ok
14:06:59.0472 5812 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys
14:06:59.0503 5812 ntrigdigi - ok
14:06:59.0534 5812 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys
14:06:59.0566 5812 Null - ok
14:06:59.0612 5812 [ B4F70FAC4EA61CF150823AA063A39FF9 ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
14:06:59.0628 5812 NVHDA - ok
14:07:00.0268 5812 [ 377140A534D013BD661C69F1741DE43C ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
14:07:00.0658 5812 nvlddmkm - ok
14:07:00.0704 5812 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys
14:07:00.0720 5812 nvraid - ok
14:07:00.0751 5812 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys
14:07:00.0767 5812 nvstor - ok
14:07:00.0798 5812 [ 4ED813EFD77A9B7E57E341CDC1C5CBC4 ] nvsvc C:\Windows\system32\nvvsvc.exe
14:07:00.0814 5812 nvsvc - ok
14:07:00.0829 5812 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
14:07:00.0845 5812 nv_agp - ok
14:07:00.0860 5812 NwlnkFlt - ok
14:07:00.0860 5812 NwlnkFwd - ok
14:07:00.0970 5812 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
14:07:01.0001 5812 odserv - ok
14:07:01.0032 5812 [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
14:07:01.0110 5812 ohci1394 - ok
14:07:01.0126 5812 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:07:01.0141 5812 ose - ok
14:07:01.0313 5812 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll
14:07:01.0484 5812 p2pimsvc - ok
14:07:01.0578 5812 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll
14:07:01.0625 5812 p2psvc - ok
14:07:01.0687 5812 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys
14:07:01.0765 5812 Parport - ok
14:07:01.0828 5812 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys
14:07:01.0843 5812 partmgr - ok
14:07:01.0874 5812 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys
14:07:01.0968 5812 Parvdm - ok
14:07:02.0030 5812 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll
14:07:02.0124 5812 PcaSvc - ok
14:07:02.0155 5812 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys
14:07:02.0186 5812 pci - ok
14:07:02.0233 5812 [ FC175F5DDAB666D7F4D17449A547626F ] pciide C:\Windows\system32\drivers\pciide.sys
14:07:02.0264 5812 pciide - ok
14:07:02.0296 5812 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
14:07:02.0327 5812 pcmcia - ok
14:07:02.0374 5812 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
14:07:02.0483 5812 PEAUTH - ok
14:07:02.0608 5812 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll
14:07:02.0686 5812 pla - ok
14:07:02.0732 5812 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll
14:07:02.0779 5812 PlugPlay - ok
14:07:02.0810 5812 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
14:07:02.0826 5812 PNRPAutoReg - ok
14:07:02.0888 5812 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll
14:07:02.0920 5812 PNRPsvc - ok
14:07:02.0966 5812 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
14:07:03.0029 5812 PolicyAgent - ok
14:07:03.0060 5812 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
14:07:03.0107 5812 PptpMiniport - ok
14:07:03.0122 5812 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\drivers\processr.sys
14:07:03.0169 5812 Processor - ok
14:07:03.0200 5812 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll
14:07:03.0232 5812 ProfSvc - ok
14:07:03.0247 5812 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe
14:07:03.0263 5812 ProtectedStorage - ok
14:07:03.0294 5812 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys
14:07:03.0341 5812 PSched - ok
14:07:03.0388 5812 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
14:07:03.0434 5812 ql2300 - ok
14:07:03.0466 5812 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
14:07:03.0481 5812 ql40xx - ok
14:07:03.0544 5812 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll
14:07:03.0575 5812 QWAVE - ok
14:07:03.0622 5812 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
14:07:03.0637 5812 QWAVEdrv - ok
14:07:03.0653 5812 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
14:07:03.0700 5812 RasAcd - ok
14:07:03.0731 5812 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll
14:07:03.0778 5812 RasAuto - ok
14:07:03.0809 5812 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
14:07:03.0840 5812 Rasl2tp - ok
14:07:03.0871 5812 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll
14:07:03.0918 5812 RasMan - ok
14:07:03.0949 5812 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
14:07:03.0965 5812 RasPppoe - ok
14:07:04.0012 5812 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
14:07:04.0027 5812 RasSstp - ok
14:07:04.0058 5812 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
14:07:04.0105 5812 rdbss - ok
14:07:04.0136 5812 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
14:07:04.0183 5812 RDPCDD - ok
14:07:04.0214 5812 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
14:07:04.0246 5812 rdpdr - ok
14:07:04.0246 5812 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
14:07:04.0308 5812 RDPENCDD - ok
14:07:04.0355 5812 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
14:07:04.0417 5812 RDPWD - ok
14:07:04.0542 5812 [ C96980CCCF84329824623B0B50383703 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
14:07:04.0573 5812 RegSrvc - ok
14:07:04.0604 5812 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll
14:07:04.0651 5812 RemoteAccess - ok
14:07:04.0698 5812 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll
14:07:04.0729 5812 RemoteRegistry - ok
14:07:04.0745 5812 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe
14:07:04.0792 5812 RpcLocator - ok
14:07:04.0823 5812 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll
14:07:04.0870 5812 RpcSs - ok
14:07:04.0916 5812 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
14:07:04.0994 5812 rspndr - ok
14:07:05.0010 5812 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe
14:07:05.0041 5812 SamSs - ok
14:07:05.0072 5812 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
14:07:05.0088 5812 sbp2port - ok
14:07:05.0150 5812 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll
14:07:05.0182 5812 SCardSvr - ok
14:07:05.0306 5812 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll
14:07:05.0369 5812 Schedule - ok
14:07:05.0400 5812 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll
14:07:05.0447 5812 SCPolicySvc - ok
14:07:05.0478 5812 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll
14:07:05.0540 5812 SDRSVC - ok
14:07:05.0587 5812 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
14:07:05.0696 5812 secdrv - ok
14:07:05.0712 5812 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll
14:07:05.0790 5812 seclogon - ok
14:07:05.0821 5812 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\system32\sens.dll
14:07:05.0868 5812 SENS - ok
14:07:05.0899 5812 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys
14:07:05.0977 5812 Serenum - ok
14:07:06.0024 5812 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys
14:07:06.0118 5812 Serial - ok
14:07:06.0149 5812 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys
14:07:06.0196 5812 sermouse - ok
14:07:06.0274 5812 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll
14:07:06.0352 5812 SessionEnv - ok
14:07:06.0383 5812 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
14:07:06.0414 5812 sffdisk - ok
14:07:06.0445 5812 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
14:07:06.0539 5812 sffp_mmc - ok
14:07:06.0554 5812 [ 3D0EA348784B7AC9EA9BD9F317980979 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
14:07:06.0601 5812 sffp_sd - ok
14:07:06.0617 5812 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
14:07:06.0710 5812 sfloppy - ok
14:07:06.0773 5812 [ E1499BD0FF76B1B2FBBF1AF339D91165 ] SharedAccess C:\Windows\System32\ipnathlp.dll
14:07:06.0851 5812 SharedAccess - ok
14:07:06.0929 5812 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:07:06.0976 5812 ShellHWDetection - ok
14:07:06.0991 5812 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys
14:07:07.0007 5812 sisagp - ok
14:07:07.0069 5812 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
14:07:07.0085 5812 SiSRaid2 - ok
14:07:07.0132 5812 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
14:07:07.0147 5812 SiSRaid4 - ok
14:07:07.0210 5812 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
14:07:07.0241 5812 SkypeUpdate - ok
14:07:07.0366 5812 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe
14:07:07.0475 5812 slsvc - ok
14:07:07.0537 5812 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll
14:07:07.0568 5812 SLUINotify - ok
14:07:07.0600 5812 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys
14:07:07.0615 5812 Smb - ok
14:07:07.0662 5812 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
14:07:07.0678 5812 SNMPTRAP - ok
14:07:07.0724 5812 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys
14:07:07.0756 5812 spldr - ok
14:07:07.0787 5812 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe
14:07:07.0849 5812 Spooler - ok
14:07:07.0880 5812 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys
14:07:07.0943 5812 srv - ok
14:07:07.0974 5812 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
14:07:07.0990 5812 srv2 - ok
14:07:08.0005 5812 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
14:07:08.0036 5812 srvnet - ok
14:07:08.0052 5812 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
14:07:08.0114 5812 SSDPSRV - ok
14:07:08.0146 5812 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll
14:07:08.0177 5812 SstpSvc - ok
14:07:08.0224 5812 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll
14:07:08.0270 5812 stisvc - ok
14:07:08.0302 5812 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
14:07:08.0333 5812 swenum - ok
14:07:08.0364 5812 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll
14:07:08.0426 5812 swprv - ok
14:07:08.0551 5812 [ CD77FD9B0071D2F36B14CC23DDE1AAD0 ] SXDS10 C:\Program Files\Common Files\soft Xpansion\sxds10.exe
14:07:08.0567 5812 SXDS10 ( UnsignedFile.Multi.Generic ) - warning
14:07:08.0567 5812 SXDS10 - detected UnsignedFile.Multi.Generic (1)
14:07:08.0614 5812 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
14:07:08.0645 5812 Symc8xx - ok
14:07:08.0660 5812 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
14:07:08.0692 5812 Sym_hi - ok
14:07:08.0738 5812 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
14:07:08.0754 5812 Sym_u3 - ok
14:07:08.0863 5812 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll
14:07:08.0941 5812 SysMain - ok
14:07:09.0004 5812 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:07:09.0066 5812 TabletInputService - ok
14:07:09.0113 5812 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll
14:07:09.0175 5812 TapiSrv - ok
14:07:09.0206 5812 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll
14:07:09.0300 5812 TBS - ok
14:07:09.0425 5812 [ D18D53974FD715D50FC76F9FFE1C830D ] Tcpip C:\Windows\system32\drivers\tcpip.sys
14:07:09.0487 5812 Tcpip - ok
14:07:09.0550 5812 [ D18D53974FD715D50FC76F9FFE1C830D ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
14:07:09.0612 5812 Tcpip6 - ok
14:07:09.0643 5812 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
14:07:09.0690 5812 tcpipreg - ok
14:07:09.0721 5812 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
14:07:09.0768 5812 TDPIPE - ok
14:07:09.0799 5812 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
14:07:09.0862 5812 TDTCP - ok
14:07:09.0908 5812 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
14:07:09.0971 5812 tdx - ok
14:07:10.0002 5812 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
14:07:10.0033 5812 TermDD - ok
14:07:10.0127 5812 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll
14:07:10.0205 5812 TermService - ok
14:07:10.0236 5812 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll
14:07:10.0267 5812 Themes - ok
14:07:10.0298 5812 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll
14:07:10.0345 5812 THREADORDER - ok
14:07:10.0423 5812 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll
14:07:10.0470 5812 TrkWks - ok
14:07:10.0579 5812 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:07:10.0626 5812 TrustedInstaller - ok
14:07:10.0673 5812 [ F4EAA7ECBCB25DE901C9B7F2CDCDA0B3 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
14:07:10.0735 5812 tssecsrv - ok
14:07:10.0782 5812 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
14:07:10.0829 5812 tunmp - ok
14:07:10.0860 5812 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
14:07:10.0891 5812 tunnel - ok
14:07:10.0922 5812 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys
14:07:10.0938 5812 uagp35 - ok
14:07:10.0985 5812 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
14:07:11.0016 5812 udfs - ok
14:07:11.0063 5812 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
14:07:11.0094 5812 UI0Detect - ok
14:07:11.0110 5812 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
14:07:11.0141 5812 uliagpkx - ok
14:07:11.0219 5812 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys
14:07:11.0234 5812 uliahci - ok
14:07:11.0250 5812 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys
14:07:11.0281 5812 UlSata - ok
14:07:11.0328 5812 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
14:07:11.0344 5812 ulsata2 - ok
14:07:11.0375 5812 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
14:07:11.0422 5812 umbus - ok
14:07:11.0484 5812 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll
14:07:11.0578 5812 upnphost - ok
14:07:11.0640 5812 [ AAB0B5F72D2D726FBFDC895A2902DE1D ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
14:07:11.0671 5812 usbccgp - ok
14:07:11.0718 5812 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys
14:07:11.0812 5812 usbcir - ok
14:07:11.0843 5812 [ 153E8515CB86F8BB5D1A8B478EBF4BB2 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
14:07:11.0874 5812 usbehci - ok
14:07:11.0921 5812 [ 2AE6BCEBD85D31317E433733DAF25888 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
14:07:11.0952 5812 usbhub - ok
14:07:11.0983 5812 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys
14:07:12.0061 5812 usbohci - ok
14:07:12.0139 5812 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
14:07:12.0186 5812 usbprint - ok
14:07:12.0233 5812 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:07:12.0295 5812 USBSTOR - ok
14:07:12.0311 5812 [ 44056325428A8E4C755830426E29878F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
14:07:12.0358 5812 usbuhci - ok
14:07:12.0404 5812 [ 73FF24E21B690625A58109637DDA0DF7 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
14:07:12.0451 5812 usbvideo - ok
14:07:12.0514 5812 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll
14:07:12.0560 5812 UxSms - ok
14:07:12.0592 5812 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe
14:07:12.0670 5812 vds - ok
14:07:12.0701 5812 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
14:07:12.0794 5812 vga - ok
14:07:12.0826 5812 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys
14:07:12.0888 5812 VgaSave - ok
14:07:12.0919 5812 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys
14:07:12.0950 5812 viaagp - ok
14:07:12.0966 5812 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys
14:07:13.0028 5812 ViaC7 - ok
14:07:13.0044 5812 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys
14:07:13.0060 5812 viaide - ok
14:07:13.0106 5812 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys
14:07:13.0138 5812 volmgr - ok
14:07:13.0216 5812 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
14:07:13.0247 5812 volmgrx - ok
14:07:13.0309 5812 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys
14:07:13.0356 5812 volsnap - ok
14:07:13.0418 5812 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
14:07:13.0434 5812 vsmraid - ok
14:07:13.0590 5812 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe
14:07:13.0684 5812 VSS - ok
14:07:13.0746 5812 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll
14:07:13.0793 5812 W32Time - ok
14:07:13.0808 5812 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
14:07:13.0918 5812 WacomPen - ok
14:07:13.0949 5812 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
14:07:14.0011 5812 Wanarp - ok
14:07:14.0011 5812 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
14:07:14.0058 5812 Wanarpv6 - ok
14:07:14.0089 5812 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll
14:07:14.0136 5812 wcncsvc - ok
14:07:14.0183 5812 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:07:14.0230 5812 WcsPlugInService - ok
14:07:14.0245 5812 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys
14:07:14.0276 5812 Wd - ok
14:07:14.0308 5812 [ 25944D2CC49E0A6C581D02A74B7D6645 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
14:07:14.0354 5812 Wdf01000 - ok
14:07:14.0370 5812 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll
14:07:14.0448 5812 WdiServiceHost - ok
14:07:14.0448 5812 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll
14:07:14.0510 5812 WdiSystemHost - ok
14:07:14.0573 5812 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll
14:07:14.0604 5812 WebClient - ok
14:07:14.0651 5812 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll
14:07:14.0682 5812 Wecsvc - ok
14:07:14.0698 5812 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll
14:07:14.0760 5812 wercplsupport - ok
14:07:14.0791 5812 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll
14:07:14.0807 5812 WerSvc - ok
14:07:14.0885 5812 [ 4575AA12561C5648483403541D0D7F2B ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
14:07:14.0900 5812 WinDefend - ok
14:07:14.0900 5812 WinHttpAutoProxySvc - ok
14:07:14.0994 5812 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
14:07:15.0010 5812 Winmgmt - ok
14:07:15.0119 5812 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll
14:07:15.0166 5812 WinRM - ok
14:07:15.0275 5812 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll
14:07:15.0337 5812 Wlansvc - ok
14:07:15.0431 5812 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
14:07:15.0634 5812 wlidsvc - ok
14:07:15.0696 5812 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
14:07:15.0774 5812 WmiAcpi - ok
14:07:15.0883 5812 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
14:07:15.0946 5812 wmiApSrv - ok
14:07:16.0070 5812 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
14:07:16.0164 5812 WMPNetworkSvc - ok
14:07:16.0195 5812 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll
14:07:16.0258 5812 WPCSvc - ok
14:07:16.0289 5812 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
14:07:16.0336 5812 WPDBusEnum - ok
14:07:16.0523 5812 [ 15673BD0B86150CB8E27766059C72A9B ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
14:07:16.0570 5812 WPFFontCache_v0400 - ok
14:07:16.0616 5812 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
14:07:16.0663 5812 ws2ifsl - ok
14:07:16.0694 5812 [ 1CA6C40261DDC0425987980D0CD2AAAB ] wscsvc C:\Windows\system32\wscsvc.dll
14:07:16.0741 5812 wscsvc - ok
14:07:16.0757 5812 WSearch - ok
14:07:17.0053 5812 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
14:07:17.0194 5812 wuauserv - ok
14:07:17.0240 5812 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
14:07:17.0272 5812 WudfPf - ok
14:07:17.0318 5812 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
14:07:17.0365 5812 WUDFRd - ok
14:07:17.0396 5812 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
14:07:17.0443 5812 wudfsvc - ok
14:07:17.0490 5812 [ C6CA0CC2F7FCDCFE5B551335BFE6D696 ] yukonwlh C:\Windows\system32\DRIVERS\yk60x86.sys
14:07:17.0568 5812 yukonwlh - ok
14:07:17.0584 5812 ================ Scan global ===============================
14:07:17.0615 5812 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll
14:07:17.0662 5812 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
14:07:17.0693 5812 [ A508314231C49AEE86987CEA3EAECAD1 ] C:\Windows\system32\winsrv.dll
14:07:17.0740 5812 [ 8737764F4FD36D6808EE80578409C843 ] C:\Windows\system32\services.exe
14:07:17.0740 5812 C:\Windows\system32\services.exe ( Virus.Win32.ZAccess.m ) - infected
14:07:17.0740 5812 C:\Windows\system32\services.exe - detected Virus.Win32.ZAccess.m (0)
14:07:17.0740 5812 ================ Scan MBR ==================================
14:07:17.0771 5812 [ 61A349592C4728853F4A90FF78F7628E ] \Device\Harddisk0\DR0
14:07:19.0424 5812 \Device\Harddisk0\DR0 - ok
14:07:19.0424 5812 ================ Scan VBR ==================================
14:07:19.0456 5812 [ 52A7C86CADD8EE821359ACF4A2E22203 ] \Device\Harddisk0\DR0\Partition1
14:07:19.0471 5812 \Device\Harddisk0\DR0\Partition1 - ok
14:07:19.0487 5812 [ 24CA742ADC9A9E55FAC882AAE8AA1358 ] \Device\Harddisk0\DR0\Partition2
14:07:19.0487 5812 \Device\Harddisk0\DR0\Partition2 - ok
14:07:19.0487 5812 ============================================================
14:07:19.0487 5812 Scan finished
14:07:19.0487 5812 ============================================================
14:07:19.0502 1080 Detected object count: 2
14:07:19.0502 1080 Actual detected object count: 2
14:07:37.0302 1080 SXDS10 ( UnsignedFile.Multi.Generic ) - skipped by user
14:07:37.0302 1080 SXDS10 ( UnsignedFile.Multi.Generic ) - User select action: Skip
14:07:37.0302 1080 C:\Windows\system32\services.exe ( Virus.Win32.ZAccess.m ) - skipped by user
14:07:37.0302 1080 C:\Windows\system32\services.exe ( Virus.Win32.ZAccess.m ) - User select action: Skip Es gab kein Problem mit services.exe, hier trotzdem ein neuer FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 10-12-2013 01
Ran by Lara (administrator) on LARA-PC on 11-12-2013 14:26:37
Running from C:\Users\Lara\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Windows\System32\userinit.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\EMET\EMET_notifier.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe
(SAMSUNG Electronics) C:\Program Files\SamSung\Easy Display Manager\dmhkcore.exe
(SAMSUNG Electronics co., LTD.) C:\Program Files\SamSung\EBM\EasyBatteryMgr3.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SamSung\Samsung Magic Doctor\MagicDoctorKbdHk.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9398888 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\Update\realsched.exe [296056 2012-06-02] (RealNetworks, Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2012-04-18] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [EMET Notifier] - C:\Program Files\EMET\EMET_notifier.exe [152152 2012-05-09] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152544 2012-12-12] (Apple Inc.)
HKLM\...\Run: [MRT] - C:\Windows\System32\mrt.exe [88123800 2013-12-01] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\wmpnscfg.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.zeit.de/index
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC02600405276CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {80217218-29AD-4019-BA0B-7F102706CC36} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: af0.Adblock.BHO - {90EFF544-3981-4d46-85C9-C0361D0931D6} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://www.zeit.de/index
FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=mcafee&p=
FF NetworkProxy: "no_proxies_on", "*.local"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Google.com/GoogleEarthPlugin - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=15.0.4.53 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lara\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lara\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Lara\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
FF Extension: EPUBReader - C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default\Extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
FF Extension: DownloadHelper - C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: jid1-0FHdJAAQ7Nb73Q - C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default\Extensions\jid1-0FHdJAAQ7Nb73Q@jetpack.xpi
FF Extension: prefs - C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default\Extensions\{7CA9CF31-1C73-46CD-8377-85AB71EA771F}.xpi
FF Extension: bprivacyprefs - C:\Users\Lara\AppData\Roaming\Mozilla\Firefox\Profiles\mky5g0nt.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF HKLM\...\Firefox\Extensions: [{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.zeit.de/index"
CHR DefaultSearchKeyword: google.com
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Lara\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lara\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\Lara\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft\u00AE Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll No File
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
CHR Plugin: (Unity Player) - C:\Users\Lara\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~1\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Awesome XKCD Widget [ANTP]) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigeakmkgpgffiojjihhjlggonmomacp\2012.134.4.0_0
CHR Extension: (YouTube) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0
CHR Extension: (Marble) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijhebjoppbkfocoeceijgihihgckeool\1.0_0
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0
CHR Extension: (You are Awesome) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkhopfdenimipdamjmfpijifmmpnakpc\8.2_0
CHR Extension: (Skype Click to Call) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0
CHR Extension: (Google Wallet) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (DivX Plus Web Player HTML5 \u003Cvideo\u003E) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0
CHR Extension: (Gmail) - C:\Users\Lara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx
CHR StartMenuInternet: Google Chrome - C:\Users\Lara\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S2 McNASvc; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [214904 2011-01-27] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe [214904 2011-01-27] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [151912 2012-05-25] (McAfee, Inc.)
S3 SXDS10; C:\Program Files\Common Files\soft Xpansion\sxds10.exe [229520 2011-12-08] (soft Xpansion)
==================== Drivers (Whitelisted) ====================
R2 KMDFMEMIO; C:\Windows\System32\DRIVERS\kmdfmemio.sys [13312 2006-11-14] (SAMSUNG ELECTRONICS CO., LTD.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [121544 2012-02-22] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [464304 2012-02-22] (McAfee, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-11 14:05 - 2013-12-11 14:05 - 00000000 ____D C:\Users\Lara\Downloads\tdsskiller
2013-12-11 14:03 - 2013-12-11 14:03 - 04101441 _____ C:\Users\Lara\Downloads\tdsskiller.zip
2013-12-11 14:03 - 2013-12-11 14:03 - 04101441 _____ C:\Users\Lara\Downloads\tdsskiller (1).zip
2013-12-11 14:01 - 2013-12-11 14:02 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Lara\Downloads\tdsskiller.exe
2013-12-11 13:55 - 2013-12-11 13:55 - 00000000 ___DC C:\FRST
2013-12-11 03:06 - 2013-12-11 03:06 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 03:02 - 2013-11-15 00:13 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-11 03:02 - 2013-11-14 23:50 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-11 03:02 - 2013-11-14 23:50 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-11 03:02 - 2013-11-14 23:43 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 03:02 - 2013-11-14 23:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-11 03:02 - 2013-11-14 23:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-11 03:02 - 2013-11-14 23:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-11 03:02 - 2013-11-14 23:40 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-11 03:02 - 2013-11-14 23:38 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-11 03:02 - 2013-11-14 23:38 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-11 03:02 - 2013-11-14 23:38 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-11 03:02 - 2013-11-14 23:37 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-11 03:02 - 2013-11-14 23:36 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-11 03:02 - 2013-11-14 23:36 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-11 03:02 - 2013-11-14 23:35 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-11 03:02 - 2013-11-14 23:32 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-11 02:58 - 2012-06-02 15:57 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2013-12-11 02:57 - 2012-07-26 04:39 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2013-12-11 02:57 - 2012-07-26 04:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2013-12-11 02:57 - 2012-07-26 04:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2013-12-11 02:57 - 2012-07-26 04:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2013-12-11 02:57 - 2012-07-26 04:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2013-12-11 02:57 - 2012-07-26 04:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2013-12-11 02:57 - 2012-07-26 03:46 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2013-12-11 02:57 - 2012-07-26 03:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2013-12-11 02:57 - 2012-07-26 03:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2013-12-11 02:57 - 2009-07-14 13:12 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\winusb.dll
2013-12-11 02:08 - 2013-12-11 02:08 - 00000000 ____D C:\Users\Lara\Downloads\FRST-OlderVersion
2013-12-11 02:03 - 2013-12-11 02:03 - 00000000 ____D C:\Windows\ERUNT
2013-12-11 02:02 - 2013-12-11 02:02 - 01034531 _____ (Thisisu) C:\Users\Lara\Downloads\JRT.exe
2013-12-11 01:48 - 2013-10-30 01:35 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 01:48 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2013-12-11 01:48 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2013-12-11 01:48 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2013-12-11 01:48 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2013-12-11 01:48 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2013-12-11 01:48 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2013-12-11 01:48 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2013-12-11 01:48 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2013-12-11 01:48 - 2013-08-27 02:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2013-12-11 01:48 - 2013-08-01 04:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-12-11 01:48 - 2013-08-01 03:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2013-12-11 01:48 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-12-11 01:48 - 2013-07-05 05:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-12-11 01:48 - 2013-06-15 14:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-12-11 01:48 - 2013-06-15 12:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-12-11 01:48 - 2012-09-25 17:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2013-12-11 01:48 - 2012-05-11 16:57 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2013-12-11 01:47 - 2013-10-30 03:12 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\SysFxUI.dll
2013-12-11 01:47 - 2013-10-30 02:43 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 01:47 - 2013-10-30 01:43 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 01:47 - 2013-10-11 03:08 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 01:47 - 2013-10-11 03:08 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 01:47 - 2013-10-11 03:08 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wshcon.dll
2013-12-11 01:47 - 2013-10-11 01:35 - 00155648 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 01:47 - 2013-10-11 01:35 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 01:47 - 2013-10-03 13:45 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-12-11 01:47 - 2013-08-02 05:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-12-11 01:47 - 2013-07-17 20:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 01:47 - 2013-07-12 10:04 - 00134272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-12-11 01:47 - 2013-07-10 10:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-12-11 01:47 - 2013-06-29 03:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-12-11 01:47 - 2013-06-29 03:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-12-11 01:47 - 2013-06-29 03:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-12-11 01:47 - 2013-06-29 03:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-12-11 01:47 - 2013-05-02 05:04 - 00443904 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2013-12-11 01:47 - 2013-05-02 05:03 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\printcom.dll
2013-12-11 01:47 - 2013-03-03 20:07 - 01082232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2013-12-11 01:47 - 2012-11-22 04:54 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2013-12-11 01:47 - 2012-11-20 05:22 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-12-11 01:47 - 2012-11-08 04:48 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2013-12-11 01:47 - 2012-11-02 11:18 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2013-12-11 01:47 - 2012-11-02 09:26 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\dpnsvr.exe
2013-12-11 01:47 - 2012-09-28 17:11 - 00892928 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-12-11 01:47 - 2012-08-21 12:47 - 00224640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2013-12-11 01:47 - 2012-06-29 17:01 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2013-12-11 01:47 - 2011-05-05 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-12-11 01:47 - 2011-05-05 14:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-12-11 01:46 - 2013-10-22 08:19 - 00158208 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 01:46 - 2013-10-11 03:08 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-12-11 01:46 - 2013-10-11 03:07 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-12-11 01:46 - 2013-10-11 01:39 - 00218228 _____ C:\Windows\system32\WFP.TMF
2013-12-11 01:46 - 2013-10-03 13:45 - 00993792 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-12-11 01:46 - 2013-07-16 05:35 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2013-12-11 01:46 - 2013-07-09 13:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-12-11 01:46 - 2013-07-08 05:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-12-11 01:46 - 2013-07-08 05:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-12-11 01:46 - 2013-06-27 00:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-12-11 01:46 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-12-11 01:46 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-12-11 01:46 - 2013-04-24 05:00 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2013-12-11 01:46 - 2013-04-24 02:46 - 00812544 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2013-12-11 01:46 - 2013-03-09 04:45 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2013-12-11 01:46 - 2013-03-09 02:28 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2013-12-11 01:46 - 2012-11-02 11:19 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2013-12-11 01:45 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-12-11 01:45 - 2013-07-03 03:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-12-11 01:45 - 2013-06-01 05:06 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-12-11 01:45 - 2013-04-17 13:30 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2013-12-11 01:45 - 2013-03-08 04:53 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-12-11 01:45 - 2013-03-08 04:52 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2013-12-11 01:45 - 2013-02-12 02:57 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2013-12-11 01:40 - 2013-12-11 01:56 - 00000000 ___DC C:\AdwCleaner
2013-12-11 01:40 - 2013-12-11 01:40 - 01226802 _____ C:\Users\Lara\Downloads\adwcleaner.exe
2013-12-11 01:32 - 2013-07-08 05:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-12-11 01:32 - 2013-07-08 05:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-12-11 01:32 - 2013-07-08 05:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-12-11 01:07 - 2013-12-11 01:07 - 00000000 ___DC C:\Program Files\Atheros WLAN Client
2013-12-11 01:07 - 2013-12-11 01:07 - 00000000 ____D C:\ProgramData\WLAN
2013-12-11 01:07 - 2009-12-18 00:02 - 01203712 _____ (Atheros Communications, Inc.) C:\Windows\system32\Drivers\athr.sys
2013-12-11 01:07 - 2009-05-01 02:14 - 00000589 _____ C:\Windows\dsetup.iss
2013-12-11 01:07 - 2009-03-19 04:31 - 02821120 _____ (Askey Computer Corporation.) C:\Windows\system32\AInst3141.exe
2013-12-11 01:07 - 2004-09-28 02:27 - 00000874 _____ C:\Windows\system32\WLL3141.cfgx
2013-12-11 00:39 - 2013-12-11 01:08 - 00000172 _____ C:\Windows\SamsungInstaller.log
2013-12-10 13:11 - 2013-12-10 13:11 - 00000000 ___DC C:\Program Files\Intel Desktop Board
2013-12-10 12:12 - 2013-12-10 12:12 - 00007935 ____C C:\ComboFix.txt
2013-12-10 12:05 - 2013-12-11 04:21 - 00001276 _____ C:\Windows\PFRO.log
2013-12-10 11:56 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-12-10 11:56 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-12-10 11:56 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-12-10 11:56 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-12-10 11:56 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-12-10 11:56 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-12-10 11:56 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-12-10 11:56 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-12-10 11:51 - 2013-12-10 11:52 - 05153091 ____R (Swearware) C:\Users\Lara\Downloads\ComboFix.exe
2013-12-10 11:49 - 2013-12-11 13:52 - 01891342 _____ C:\Windows\WindowsUpdate.log
2013-12-10 02:29 - 2013-12-11 14:26 - 00019935 _____ C:\Users\Lara\Downloads\FRST.txt
2013-12-10 02:29 - 2013-12-10 02:33 - 00021306 _____ C:\Users\Lara\Downloads\Addition.txt
2013-12-10 02:28 - 2013-12-11 13:57 - 00000000 ___DC C:\Users\Lara\Desktop\FRST
2013-12-10 02:28 - 2013-12-11 02:08 - 01061389 ____C (Farbar) C:\Users\Lara\Downloads\FRST.exe
2013-12-10 02:27 - 2013-12-10 02:27 - 00000000 _____ C:\Users\Lara\defogger_reenable
2013-12-10 02:26 - 2013-12-10 02:26 - 00050477 _____ C:\Users\Lara\Downloads\Defogger.exe
==================== One Month Modified Files and Folders =======
2013-12-11 14:26 - 2013-12-10 02:29 - 00019935 _____ C:\Users\Lara\Downloads\FRST.txt
2013-12-11 14:26 - 2011-02-25 16:12 - 00036821 _____ C:\ProgramData\nvModes.001
2013-12-11 14:26 - 2011-02-25 15:31 - 00001090 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-11 14:05 - 2013-12-11 14:05 - 00000000 ____D C:\Users\Lara\Downloads\tdsskiller
2013-12-11 14:03 - 2013-12-11 14:03 - 04101441 _____ C:\Users\Lara\Downloads\tdsskiller.zip
2013-12-11 14:03 - 2013-12-11 14:03 - 04101441 _____ C:\Users\Lara\Downloads\tdsskiller (1).zip
2013-12-11 14:02 - 2013-12-11 14:01 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Lara\Downloads\tdsskiller.exe
2013-12-11 13:57 - 2013-12-10 02:28 - 00000000 ___DC C:\Users\Lara\Desktop\FRST
2013-12-11 13:55 - 2013-12-11 13:55 - 00000000 ___DC C:\FRST
2013-12-11 13:55 - 2011-02-25 15:31 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-11 13:54 - 2008-01-21 08:16 - 01453972 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-11 13:52 - 2013-12-10 11:49 - 01891342 _____ C:\Windows\WindowsUpdate.log
2013-12-11 13:47 - 2011-02-25 16:12 - 00036821 _____ C:\ProgramData\nvModes.dat
2013-12-11 13:47 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-11 13:47 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-11 13:47 - 2006-11-02 13:47 - 00003616 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-11 04:44 - 2006-11-02 14:01 - 00032534 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-12-11 04:38 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\rescache
2013-12-11 04:35 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-12-11 04:34 - 2011-02-07 14:50 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3024481946-321734359-2265164632-1000UA.job
2013-12-11 04:31 - 2012-04-01 21:38 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-11 04:21 - 2013-12-10 12:05 - 00001276 _____ C:\Windows\PFRO.log
2013-12-11 04:02 - 2011-01-28 23:42 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-11 04:01 - 2006-11-02 13:47 - 00398704 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-11 03:58 - 2011-02-25 16:03 - 00000000 ____D C:\Windows\system32\RTCOM
2013-12-11 03:58 - 2008-01-21 08:15 - 00000000 ____D C:\Windows\system32\Drivers\de-DE
2013-12-11 03:58 - 2006-11-02 13:37 - 00000000 ____D C:\Windows\system32\XPSViewer
2013-12-11 03:58 - 2006-11-02 13:37 - 00000000 ____D C:\Program Files\Windows Journal
2013-12-11 03:58 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-11 03:51 - 2011-02-09 15:00 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-12-11 03:44 - 2011-04-25 19:10 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 03:06 - 2013-12-11 03:06 - 00000000 ____D C:\Windows\system32\MRT
2013-12-11 02:57 - 2006-11-02 11:23 - 00000219 _____ C:\Windows\win.ini
2013-12-11 02:34 - 2011-02-07 14:50 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3024481946-321734359-2265164632-1000Core.job
2013-12-11 02:31 - 2012-04-01 21:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-11 02:31 - 2011-06-21 13:03 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-11 02:08 - 2013-12-11 02:08 - 00000000 ____D C:\Users\Lara\Downloads\FRST-OlderVersion
2013-12-11 02:08 - 2013-12-10 02:28 - 01061389 ____C (Farbar) C:\Users\Lara\Downloads\FRST.exe
2013-12-11 02:03 - 2013-12-11 02:03 - 00000000 ____D C:\Windows\ERUNT
2013-12-11 02:02 - 2013-12-11 02:02 - 01034531 _____ (Thisisu) C:\Users\Lara\Downloads\JRT.exe
2013-12-11 01:56 - 2013-12-11 01:40 - 00000000 ___DC C:\AdwCleaner
2013-12-11 01:56 - 2011-02-07 18:37 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-12-11 01:40 - 2013-12-11 01:40 - 01226802 _____ C:\Users\Lara\Downloads\adwcleaner.exe
2013-12-11 01:15 - 2013-01-05 03:26 - 00000000 ___DC C:\Program Files\Malwarebytes' Anti-Malware
2013-12-11 01:08 - 2013-12-11 00:39 - 00000172 _____ C:\Windows\SamsungInstaller.log
2013-12-11 01:07 - 2013-12-11 01:07 - 00000000 ___DC C:\Program Files\Atheros WLAN Client
2013-12-11 01:07 - 2013-12-11 01:07 - 00000000 ____D C:\ProgramData\WLAN
2013-12-11 01:07 - 2011-01-28 18:55 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-12-11 01:07 - 2011-01-28 05:11 - 00000000 ____D C:\Users\Lara
2013-12-10 13:14 - 2011-02-25 16:02 - 00000000 ____D C:\Program Files\Realtek
2013-12-10 13:11 - 2013-12-10 13:11 - 00000000 ___DC C:\Program Files\Intel Desktop Board
2013-12-10 12:12 - 2013-12-10 12:12 - 00007935 ____C C:\ComboFix.txt
2013-12-10 12:12 - 2012-07-13 04:04 - 00000000 ___DC C:\Qoobox
2013-12-10 12:12 - 2006-11-02 12:18 - 00000000 __RHD C:\Users\Default
2013-12-10 12:12 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2013-12-10 12:10 - 2012-07-13 04:04 - 00000000 ____D C:\Windows\erdnt
2013-12-10 12:06 - 2006-11-02 11:23 - 00000215 ____C C:\Windows\system.ini
2013-12-10 11:52 - 2013-12-10 11:51 - 05153091 ____R (Swearware) C:\Users\Lara\Downloads\ComboFix.exe
2013-12-10 11:42 - 2011-08-11 09:49 - 00000000 ____D C:\Windows\Minidump
2013-12-10 02:36 - 2011-02-07 14:52 - 00000000 ____D C:\Users\Lara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2013-12-10 02:33 - 2013-12-10 02:29 - 00021306 _____ C:\Users\Lara\Downloads\Addition.txt
2013-12-10 02:27 - 2013-12-10 02:27 - 00000000 _____ C:\Users\Lara\defogger_reenable
2013-12-10 02:26 - 2013-12-10 02:26 - 00050477 _____ C:\Users\Lara\Downloads\Defogger.exe
2013-12-01 14:42 - 2006-11-02 11:24 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-11-19 03:33 - 2011-02-07 15:00 - 00230048 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2013-11-15 00:13 - 2013-12-11 03:02 - 12344320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-14 23:50 - 2013-12-11 03:02 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-14 23:50 - 2013-12-11 03:02 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-14 23:43 - 2013-12-11 03:02 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-14 23:42 - 2013-12-11 03:02 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-14 23:42 - 2013-12-11 03:02 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-14 23:41 - 2013-12-11 03:02 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-14 23:40 - 2013-12-11 03:02 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-14 23:38 - 2013-12-11 03:02 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-14 23:38 - 2013-12-11 03:02 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-14 23:38 - 2013-12-11 03:02 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-14 23:37 - 2013-12-11 03:02 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-14 23:36 - 2013-12-11 03:02 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-14 23:36 - 2013-12-11 03:02 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-14 23:35 - 2013-12-11 03:02 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-14 23:32 - 2013-12-11 03:02 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
Some content of TEMP:
====================
C:\Users\Lara\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe 8737764F4FD36D6808EE80578409C843 ZeroAccess <==== ATTENTION!.
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 13:54
==================== End Of Log ============================ --- --- --- |