Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

Aiutoooo ragazzi virus finanza.. Opzioni
sodomino
Inviato: Wednesday, March 28, 2012 12:23:17 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
Ciao ragazzi ancora una volta mi rivolgo a voi che mi avete risolto un sacco di problemi e siete i migliori.
Mi è capitato oggi che nel mio pc mentre navigavo è comparsa una schermata della guardia di finanza che diceva che avevo materiale pedopornografico ecc... e mi diceva che devo pagare 100€ per sbloccare il pc ho subito pensato a un virus sono andato a leggere su internet e effettivamente lo è come elimino questo fastidioso problema? grazie in anticipo

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:04:48, on 28/03/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Giada\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - {e3393495-8103-46a0-8181-270273eddd60} - (no file)
R3 - URLSearchHook: (no name) - {707db484-2428-402d-afb5-d85b387544c7} - (no file)
R3 - URLSearchHook: (no name) - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - (no file)
R3 - URLSearchHook: (no name) - {e29dfa44-501b-45be-be17-393b9e5e058a} - (no file)
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
R3 - URLSearchHook: (no name) - {33fe4405-0591-4965-a84c-ae30a1d4cfc6} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Smad] "C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\MF.exe" /opentotray
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Cerca nel web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8724 bytes

Posso chiedervi anche se lo pulite un pochino?? grazie a tutti
Sponsor
Inviato: Wednesday, March 28, 2012 12:23:17 PM

 
miticoalex
Inviato: Wednesday, March 28, 2012 12:45:57 PM

Rank: AiutAmico

Iscritto dal : 10/19/2010
Posts: 14,635
In attesa del controllo del log, puoi dare un'occhiata qui.

Saluti


sodomino
Inviato: Wednesday, March 28, 2012 1:07:37 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
grazie miticoalex ho dato un occhiata e potrei anche provare a risolvere così ma prima di fare qualcosa vorrei avere una scansione del log per eliminare eventuali altri virus o sporcizia e essere sicuro di non fare danni grazie tante per l'interessamento
bustocb
Inviato: Wednesday, March 28, 2012 5:00:51 PM

Rank: AiutAmico

Iscritto dal : 2/23/2012
Posts: 260
Ciao, oltre al link indicato da mitico, se ne è parlato anche nel forum QUI esegui le operazioni senza paura.

Riguardo al log, sei messo maluccio.
Prima cosa non vedo nessun antivirus, cosa usi ?

Questo molto probabilmente è una minaccia: C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe
quindi eliminalo seguendo il percorso.

Poi scarica QUESTO programma, lo aggiorni e fai una scansione COMPLETA, non rapida elimina tutto quello che trova, posta il log.

Fammi sapere poi proseguiamo. Speak to the hand

sodomino
Inviato: Wednesday, March 28, 2012 5:56:25 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
io uso avast free antivirus sono messo maluccio?? mi riesci a dire cosa devo eliminare dal log?? stasera farò la scansione. grazie
bustocb
Inviato: Wednesday, March 28, 2012 6:29:07 PM

Rank: AiutAmico

Iscritto dal : 2/23/2012
Posts: 260
Nel log non è presente nessun antivirus, controlla se è attivato o no.
Poi dovevi fare una scansione con Malwarebytes e postare il log.
Aspetto.
sodomino
Inviato: Thursday, March 29, 2012 12:04:27 AM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
log mbam

Malwarebytes Anti-Malware (Prova) 1.60.1.1000
www.malwarebytes.org

Versione database: v2012.03.28.06

Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Giada :: JOEPC [amministratore]

Protezione: Attivata

28/03/2012 22:58:28
mbam-log-2012-03-28 (22-58-28).txt

Tipo di scansione: Scansione completa
Opzioni di scansione attive: Memoria | Esecuzione automatica | Registro | File system | Euristica/Extra | Euristica/Shuriken | PUP | PUM
Opzioni di scansione disattivate: P2P
Elementi esaminati: 525358
Tempo impiegato: 1 ore, 49 minuti, 56 secondi

Processi rilevati in memoria: 1
C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe (Trojan.Agent) -> 1416 -> Verrà eliminato al riavvio.

Moduli di memoria rilevati: 0
(non sono stati rilevati elementi nocivi)

Chiavi di registro rilevate: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smad (Trojan.Agent) -> Spostato in quarantena ed eliminato con successo.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FX - WMV Converter (Adware.Agent) -> Spostato in quarantena ed eliminato con successo.

Valori di registro rilevati: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Smad (Trojan.Agent) -> Dati: "C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe" -> Spostato in quarantena ed eliminato con successo.

Voci rilevate nei dati di registro: 0
(non sono stati rilevati elementi nocivi)

Cartelle rilevate: 0
(non sono stati rilevati elementi nocivi)

File rilevati: 9
C:\Users\Giada\AppData\Local\SanctionedMedia\Smad\Smad.exe (Trojan.Agent) -> Verrà eliminato al riavvio.
C:\Program Files (x86)\FoxTabVideoConverter\Uninstall\Uninstall.exe (Adware.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\programmi g\SoftonicDownloader_per_picture-collage-maker.exe (PUP.BundleOffer.Downloader.S) -> Spostato in quarantena ed eliminato con successo.
C:\programmi g\SoftonicDownloader_per_shape-collage.exe (PUP.BundleOffer.Downloader.S) -> Spostato in quarantena ed eliminato con successo.
C:\programmi g\WmvConverterSetup.exe (Adware.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\Users\Giada\AppData\Local\Temp\mor.exe (Spyware.Zeus) -> Spostato in quarantena ed eliminato con successo.
C:\Users\Giada\AppData\Local\Temp\rwmcsxaone.exe (Spyware.Agent) -> Spostato in quarantena ed eliminato con successo.
C:\Users\Joe\Desktop\Joe\Programmi\Bit defender total security fino 2045\bitdefender crack Box_BD2011_3.1\Box_BD2011.exe (RiskWare.Tool.CK) -> Spostato in quarantena ed eliminato con successo.
C:\Users\Giada\AppData\Local\Temp\cgs8h0.exe (Exploit.Drop) -> Spostato in quarantena ed eliminato con successo.

(fine)

i file rilevati sono in quarantena

log hijackthis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:04:00, on 29/03/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Giada\Downloads\HiJackThis.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_ActiveX.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - {e3393495-8103-46a0-8181-270273eddd60} - (no file)
R3 - URLSearchHook: (no name) - {707db484-2428-402d-afb5-d85b387544c7} - (no file)
R3 - URLSearchHook: (no name) - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - (no file)
R3 - URLSearchHook: (no name) - {e29dfa44-501b-45be-be17-393b9e5e058a} - (no file)
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
R3 - URLSearchHook: (no name) - {33fe4405-0591-4965-a84c-ae30a1d4cfc6} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\MF.exe" /opentotray
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Cerca nel web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files (x86)\Media Finder\hook.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8731 bytes

grazie tante aspetto risposta
bustocb
Inviato: Thursday, March 29, 2012 12:28:05 AM

Rank: AiutAmico

Iscritto dal : 2/23/2012
Posts: 260
Continuo a non vedere l'antivirus, se dici di avere Avast controlla che sia l'ultima versione QUI.

Malwarebytes ha già eliminato qualcosa.
Chiudi tutti i programmi e disconnesso lanci HJT e clicca sul secondo pulsante: Do a system scan only poi metti la spunta alle voci che ti indico e alla fine clic su Fix checked.

R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
R3 - URLSearchHook: (no name) - {e3393495-8103-46a0-8181-270273eddd60} - (no file)
R3 - URLSearchHook: (no name) - {707db484-2428-402d-afb5-d85b387544c7} - (no file)
R3 - URLSearchHook: (no name) - {2c965f3f-8efd-4bfc-a2c5-1672845fdbbf} - (no file)
R3 - URLSearchHook: (no name) - {e29dfa44-501b-45be-be17-393b9e5e058a} - (no file)
R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)
R3 - URLSearchHook: (no name) - {33fe4405-0591-4965-a84c-ae30a1d4cfc6} - (no file)
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files (x86)\Media Finder\MF.exe" /opentotray
O8 - Extra context menu item: Cerca nel web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
Poi fai una pulizia con Ccleaner compreso il Registro.
Fai sapere come va il pc. Ciao
sodomino
Inviato: Friday, March 30, 2012 8:41:00 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
ok fatto tutto ora vi posto il nuovo log di hijackthis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:40:11, on 30/03/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Joe\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {ecdee021-0d17-467f-a1ff-c7a115230949} - (no file)
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Babylon toolbar helper - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Kwyshell MidpX BHO - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: I&nvia a OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Link to &MidpX - C:\Program Files (x86)\Kwyshell\MidpX\JadInvoker\Extent\jad_wrap.htm
O8 - Extra context menu item: Search the Web - C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Note collegate di OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7913 bytes

Posso eliminare ancora qualcosa per fare un pò di pulizia??? grazie tante a tutti fantastici come sempre
sodomino
Inviato: Friday, March 30, 2012 8:50:09 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
un altra cosa ragazzi avast mi rileva un rootkit

nome file: SVC: ScFBP nome del rc: Win64:ZAcc

azioni da intraprendere elimina ora(consigliato) che faccio??

siamo sicuri ke sia un virus?? siamo sicuri che li ha eliminati tutti malwarebites?
poi è possibile che malwarebites vada in conflitto con avast? perchè quando c'era installato malware bites avast me lo rilevava come virus e se io facevo ignora il pc non si avviava più ho dovuto fare il ripristino di configurazione di sistema 3 volte quando poi mi sono stancato ho disinstallato malwarebites e ora non me lo fa più grazie tante
r16
Inviato: Friday, March 30, 2012 8:55:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
sodomino ha scritto:
un altra cosa ragazzi avast mi rileva un rootkit

nome file: SVC: ScFBP nome del rc: Win64:ZAcc

azioni da intraprendere elimina ora(consigliato) che faccio??

siamo sicuri ke sia un virus??

E grosso anche.Whistle
bustocb
Inviato: Friday, March 30, 2012 11:24:51 PM

Rank: AiutAmico

Iscritto dal : 2/23/2012
Posts: 260
r16 ha scritto:
sodomino ha scritto:
un altra cosa ragazzi avast mi rileva un rootkit

nome file: SVC: ScFBP nome del rc: Win64:ZAcc

azioni da intraprendere elimina ora(consigliato) che faccio??

siamo sicuri ke sia un virus??

E grosso anche.Whistle


r16 tu cosa consigli ?
sodomino
Inviato: Saturday, March 31, 2012 12:13:45 AM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
ragazzi sono messo male è gia la quarta volta che rreinstallo le cose spengo il pc lo riaccendo e non ci sono più stessa cosa per quello che disinstallo poi ho anche un virus grosso mi sto preoccupando... aiutatemi voi se potete grazie tante
bustocb
Inviato: Saturday, March 31, 2012 12:20:56 AM

Rank: AiutAmico

Iscritto dal : 2/23/2012
Posts: 260
sodomino ha scritto:
ragazzi sono messo male è gia la quarta volta che rreinstallo le cose spengo il pc lo riaccendo e non ci sono più stessa cosa per quello che disinstallo poi ho anche un virus grosso mi sto preoccupando... aiutatemi voi se potete grazie tante


Attendi con pazienza r16 che ti dirà cosa fare.
r16
Inviato: Saturday, March 31, 2012 12:30:04 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
L'infezione è la stessa di Loredana 74: (Zero Access)
http://forum.aiutamici.com/yaf_postst84136_problemi-con-trojan.aspx

Scarica Defogger:
http://download.bleepingcomputer.com/jpshortstuff/Defogger.exe
Si tratta di un programma che provvederà a disattivare temporaneamente i driver impiegati da software per l'emulazione di CD/DVD.
Eseguilo e clicca su "Disable", premi "Yes" per confermare quindi attendi la fine della procedura.
Defogger richiederà un riavvio del pc.

Scarica TDSSKiller.zip sul desktop:
http://support.kaspersky.com/viruses/solutions?qid=208280684
Estrai i dati in una cartella e fai doppio clik su TDSSKiller.exe
clicca su "Start Scan"
Se trova qualche infezione di default avrai l'opzione "Cure" per cui, clicca su "Continue".
Se un file sospetto viene trovato,l'azione di default sarà "skip",clicca su "Continue".
Se è richiesto il riavvio,(Reboot) acconsenti. (per eliminare l'infezione è necessario riavviare il pc)
Se nessun riavvio è richiesto clicca su report e salva il contenuto in un file di testo.
Il log lo trovi in C:\
Postalo qui.

Scarica aswMBR.exe sul desktop.
http://public.avast.com/~gmerek/aswMBR.exe
Fai doppio clic aswMBR.exe per eseguirlo
Clicca sul pulsante Scan per avviare la scansione
Al termine della scansione clicca su Save log,e salvalo sul desktop.
Postalo qui

Scarica Combofix (usa Internet Explorer)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop. (è obbligatorio)

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (se usi Vista: tasto destro su Combofix.exe e clicca su: "Esegui come Amministratore" )

Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.

E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix) tu ignorali.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.

Per postare i log:
Collegati ad internet e vai alla pagina WikiSend: http://www.wikisend.com/
Clicca sul bottone "Sfoglia"
Seleziona il file appena salvato
Clicca su Upload file
Dopo qualche secondo, vieni spostato su una nuova pagina con il link in diversi formati:
Download Link / Forum Link
Seleziona Forum Link, copialo e incollalo in un nuovo messaggio per il forum.

N.B:
Se riscontri problemi con le una scansione, salta alla scansione successiva.
assembler
Inviato: Saturday, March 31, 2012 12:44:13 PM
Rank: AiutAmico

Iscritto dal : 1/24/2012
Posts: 0
Commenta:
Attendi con pazienza r16 che ti dirà cosa fare.

Commenta:
L'infezione è la stessa di Loredana 74: (Zero Access)

Si sa dopo le 10 pagine come ha concluso Loredana?? Ha formattato oppure cosa !!!
r16
Inviato: Saturday, March 31, 2012 1:48:54 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
@assembler
Commenta:
Si sa dopo le 10 pagine come ha concluso Loredana?? Ha formattato oppure cosa !!!

E te pareva che non intervenisse a vanvera, il solito disturbatore.Shhh
Non hai visto che per onestà, ho postato anche il link, per far rendere conto all'utente delle difficoltà?
O pensi che l'utente non sia capace leggere....Think
Pensi proprio che aveva bisogno di una tua "riflessione"?
Che poi.....se non lo dico che l'infezione è simile, tu manco ci arrivavi. (come in un'altra occasione.)

@sodomino:
Vedi tu se eseguire le indicazioni.
E non farti intimidire da certi spaventapasseri.
Per loro il format è la regola.

sodomino
Inviato: Sunday, April 01, 2012 2:11:19 PM
Rank: AiutAmico

Iscritto dal : 7/17/2008
Posts: 96
r16 grazie per avermi aiutato ma ho riscontrato 2 problemi prima cosa il programma di avast lo ho avviato 3 volte fatto lo scan solo che ad un certo punto tutte e 3 le volte mi è usicto il programma ha smesso di funzionare chiudere il programma. l'altro invece combofix mentre eliminava i file infetti mi si è presentata una schermata blu come se avesse eliminato quallche file di sistema e mi si è riavviato il pc e non partiva più ho dovuto ripristinarlo con la console di ripristino all'avvio.
cmq ti posto i log di quello che sono riuscito a fare:
defogger

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 12:18 on 01/04/2012 (Joe)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
HKCU:DAEMON Tools Lite -> Removed

Checking for services/drivers...
SPTD -> Disabled (Service running -> reboot required)


-=E.O.F=-

tdsskiller

12:23:51.0848 3152 TDSS rootkit removing tool 2.7.23.0 Mar 26 2012 13:40:18
12:23:52.0191 3152 ============================================================
12:23:52.0191 3152 Current date / time: 2012/04/01 12:23:52.0191
12:23:52.0191 3152 SystemInfo:
12:23:52.0191 3152
12:23:52.0191 3152 OS Version: 6.1.7600 ServicePack: 0.0
12:23:52.0191 3152 Product type: Workstation
12:23:52.0191 3152 ComputerName: JOEPC
12:23:52.0191 3152 UserName: Joe
12:23:52.0191 3152 Windows directory: C:\Windows
12:23:52.0191 3152 System windows directory: C:\Windows
12:23:52.0191 3152 Running under WOW64
12:23:52.0191 3152 Processor architecture: Intel x64
12:23:52.0191 3152 Number of processors: 2
12:23:52.0191 3152 Page size: 0x1000
12:23:52.0191 3152 Boot type: Normal boot
12:23:52.0191 3152 ============================================================
12:23:56.0044 3152 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x872FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0x1C, Type 'K0', Flags 0x00000040
12:23:56.0044 3152 \Device\Harddisk0\DR0:
12:23:56.0044 3152 MBR used
12:23:56.0044 3152 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:23:56.0044 3152 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000
12:23:56.0075 3152 Initialize success
12:23:56.0075 3152 ============================================================
12:24:02.0908 3292 ============================================================
12:24:02.0908 3292 Scan started
12:24:02.0908 3292 Mode: Manual;
12:24:02.0908 3292 ============================================================
12:24:05.0295 3292 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
12:24:05.0311 3292 1394ohci - ok
12:24:05.0389 3292 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
12:24:05.0389 3292 ACPI - ok
12:24:05.0435 3292 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
12:24:05.0451 3292 AcpiPmi - ok
12:24:05.0560 3292 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
12:24:05.0576 3292 adp94xx - ok
12:24:05.0623 3292 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
12:24:05.0623 3292 adpahci - ok
12:24:05.0716 3292 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
12:24:05.0716 3292 adpu320 - ok
12:24:05.0779 3292 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
12:24:05.0779 3292 AeLookupSvc - ok
12:24:05.0903 3292 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
12:24:05.0919 3292 AFD - ok
12:24:05.0981 3292 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
12:24:05.0981 3292 agp440 - ok
12:24:06.0044 3292 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
12:24:06.0044 3292 ALG - ok
12:24:06.0122 3292 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
12:24:06.0122 3292 aliide - ok
12:24:06.0153 3292 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
12:24:06.0153 3292 amdide - ok
12:24:06.0184 3292 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
12:24:06.0184 3292 AmdK8 - ok
12:24:06.0215 3292 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
12:24:06.0215 3292 AmdPPM - ok
12:24:06.0278 3292 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
12:24:06.0278 3292 amdsata - ok
12:24:06.0371 3292 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
12:24:06.0371 3292 amdsbs - ok
12:24:06.0418 3292 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
12:24:06.0418 3292 amdxata - ok
12:24:06.0481 3292 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
12:24:06.0481 3292 AppID - ok
12:24:06.0527 3292 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
12:24:06.0527 3292 AppIDSvc - ok
12:24:06.0574 3292 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
12:24:06.0574 3292 Appinfo - ok
12:24:06.0683 3292 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
12:24:06.0683 3292 arc - ok
12:24:06.0699 3292 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
12:24:06.0699 3292 arcsas - ok
12:24:06.0761 3292 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
12:24:06.0761 3292 AsyncMac - ok
12:24:06.0777 3292 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
12:24:06.0777 3292 atapi - ok
12:24:06.0855 3292 athr (38562a6a9cb10844759eaf2b01a7fcd3) C:\Windows\system32\DRIVERS\athrx.sys
12:24:06.0902 3292 athr - ok
12:24:07.0027 3292 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
12:24:07.0058 3292 AudioEndpointBuilder - ok
12:24:07.0073 3292 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
12:24:07.0073 3292 AudioSrv - ok
12:24:07.0136 3292 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
12:24:07.0151 3292 AxInstSV - ok
12:24:07.0229 3292 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
12:24:07.0229 3292 b06bdrv - ok
12:24:07.0323 3292 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
12:24:07.0323 3292 b57nd60a - ok
12:24:07.0385 3292 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
12:24:07.0385 3292 BDESVC - ok
12:24:07.0448 3292 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
12:24:07.0448 3292 Beep - ok
12:24:07.0495 3292 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
12:24:07.0541 3292 BITS - ok
12:24:07.0619 3292 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
12:24:07.0619 3292 blbdrive - ok
12:24:07.0666 3292 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
12:24:07.0666 3292 bowser - ok
12:24:07.0713 3292 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:24:07.0713 3292 BrFiltLo - ok
12:24:07.0744 3292 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:24:07.0744 3292 BrFiltUp - ok
12:24:07.0853 3292 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
12:24:07.0869 3292 BridgeMP - ok
12:24:07.0916 3292 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
12:24:07.0916 3292 Browser - ok
12:24:07.0963 3292 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
12:24:07.0963 3292 Brserid - ok
12:24:07.0994 3292 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
12:24:07.0994 3292 BrSerWdm - ok
12:24:08.0041 3292 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
12:24:08.0041 3292 BrUsbMdm - ok
12:24:08.0072 3292 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
12:24:08.0072 3292 BrUsbSer - ok
12:24:08.0150 3292 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
12:24:08.0165 3292 BTHMODEM - ok
12:24:08.0212 3292 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
12:24:08.0212 3292 bthserv - ok
12:24:08.0259 3292 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
12:24:08.0259 3292 cdfs - ok
12:24:08.0321 3292 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
12:24:08.0321 3292 cdrom - ok
12:24:08.0384 3292 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
12:24:08.0384 3292 CertPropSvc - ok
12:24:08.0462 3292 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
12:24:08.0462 3292 circlass - ok
12:24:08.0493 3292 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
12:24:08.0509 3292 CLFS - ok
12:24:08.0555 3292 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:24:08.0571 3292 clr_optimization_v2.0.50727_32 - ok
12:24:08.0633 3292 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:24:08.0633 3292 clr_optimization_v2.0.50727_64 - ok
12:24:08.0789 3292 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:24:08.0805 3292 clr_optimization_v4.0.30319_32 - ok
12:24:08.0899 3292 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:24:08.0899 3292 clr_optimization_v4.0.30319_64 - ok
12:24:08.0977 3292 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
12:24:08.0977 3292 CmBatt - ok
12:24:08.0992 3292 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
12:24:08.0992 3292 cmdide - ok
12:24:09.0055 3292 CNG (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
12:24:09.0070 3292 CNG - ok
12:24:09.0117 3292 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
12:24:09.0133 3292 Compbatt - ok
12:24:09.0164 3292 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
12:24:09.0164 3292 CompositeBus - ok
12:24:09.0195 3292 COMSysApp - ok
12:24:09.0242 3292 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
12:24:09.0242 3292 crcdisk - ok
12:24:09.0320 3292 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
12:24:09.0320 3292 CryptSvc - ok
12:24:09.0460 3292 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
12:24:09.0460 3292 DcomLaunch - ok
12:24:09.0491 3292 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
12:24:09.0491 3292 defragsvc - ok
12:24:09.0585 3292 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
12:24:09.0585 3292 DfsC - ok
12:24:09.0663 3292 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
12:24:09.0663 3292 Dhcp - ok
12:24:09.0694 3292 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
12:24:09.0710 3292 discache - ok
12:24:09.0757 3292 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
12:24:09.0757 3292 Disk - ok
12:24:09.0819 3292 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
12:24:09.0819 3292 Dnscache - ok
12:24:09.0850 3292 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
12:24:09.0866 3292 dot3svc - ok
12:24:09.0881 3292 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
12:24:09.0881 3292 DPS - ok
12:24:09.0959 3292 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
12:24:09.0959 3292 drmkaud - ok
12:24:10.0053 3292 dtsoftbus01 (d3d64cf7b2bceaa34a270f45a3fffb36) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
12:24:10.0069 3292 dtsoftbus01 - ok
12:24:10.0147 3292 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
12:24:10.0162 3292 DXGKrnl - ok
12:24:10.0225 3292 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
12:24:10.0225 3292 EapHost - ok
12:24:10.0349 3292 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
12:24:10.0443 3292 ebdrv - ok
12:24:10.0537 3292 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
12:24:10.0537 3292 EFS - ok
12:24:10.0615 3292 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
12:24:10.0630 3292 ehRecvr - ok
12:24:10.0677 3292 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
12:24:10.0677 3292 ehSched - ok
12:24:10.0739 3292 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
12:24:10.0755 3292 elxstor - ok
12:24:10.0802 3292 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
12:24:10.0802 3292 ErrDev - ok
12:24:10.0864 3292 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
12:24:10.0864 3292 EventSystem - ok
12:24:10.0895 3292 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
12:24:10.0895 3292 exfat - ok
12:24:10.0927 3292 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
12:24:10.0927 3292 fastfat - ok
12:24:11.0036 3292 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
12:24:11.0067 3292 Fax - ok
12:24:11.0114 3292 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
12:24:11.0114 3292 fdc - ok
12:24:11.0161 3292 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
12:24:11.0161 3292 fdPHost - ok
12:24:11.0176 3292 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
12:24:11.0192 3292 FDResPub - ok
12:24:11.0223 3292 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
12:24:11.0223 3292 FileInfo - ok
12:24:11.0254 3292 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
12:24:11.0254 3292 Filetrace - ok
12:24:11.0285 3292 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
12:24:11.0285 3292 flpydisk - ok
12:24:11.0317 3292 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
12:24:11.0317 3292 FltMgr - ok
12:24:11.0395 3292 FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
12:24:11.0426 3292 FontCache - ok
12:24:11.0519 3292 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:24:11.0519 3292 FontCache3.0.0.0 - ok
12:24:11.0566 3292 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
12:24:11.0582 3292 FsDepends - ok
12:24:11.0613 3292 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
12:24:11.0613 3292 Fs_Rec - ok
12:24:11.0722 3292 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
12:24:11.0722 3292 fvevol - ok
12:24:11.0769 3292 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
12:24:11.0769 3292 gagp30kx - ok
12:24:11.0816 3292 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
12:24:11.0847 3292 gpsvc - ok
12:24:11.0956 3292 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
12:24:11.0972 3292 gusvc - ok
12:24:12.0065 3292 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
12:24:12.0065 3292 hcw85cir - ok
12:24:12.0128 3292 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
12:24:12.0143 3292 HdAudAddService - ok
12:24:12.0206 3292 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
12:24:12.0206 3292 HDAudBus - ok
12:24:12.0299 3292 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
12:24:12.0299 3292 HidBatt - ok
12:24:12.0315 3292 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
12:24:12.0315 3292 HidBth - ok
12:24:12.0331 3292 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
12:24:12.0331 3292 HidIr - ok
12:24:12.0377 3292 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
12:24:12.0377 3292 hidserv - ok
12:24:12.0440 3292 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
12:24:12.0440 3292 HidUsb - ok
12:24:12.0471 3292 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
12:24:12.0487 3292 hkmsvc - ok
12:24:12.0502 3292 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
12:24:12.0518 3292 HomeGroupListener - ok
12:24:12.0565 3292 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
12:24:12.0565 3292 HomeGroupProvider - ok
12:24:12.0674 3292 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
12:24:12.0674 3292 HpSAMD - ok
12:24:12.0721 3292 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
12:24:12.0752 3292 HTTP - ok
12:24:12.0830 3292 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
12:24:12.0830 3292 hwpolicy - ok
12:24:12.0892 3292 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
12:24:12.0892 3292 i8042prt - ok
12:24:12.0955 3292 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
12:24:12.0970 3292 iaStorV - ok
12:24:13.0064 3292 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:24:13.0111 3292 idsvc - ok
12:24:13.0391 3292 igfx (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys
12:24:13.0532 3292 igfx - ok
12:24:13.0641 3292 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
12:24:13.0657 3292 iirsp - ok
12:24:13.0735 3292 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
12:24:13.0781 3292 IKEEXT - ok
12:24:13.0828 3292 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
12:24:13.0828 3292 intelide - ok
12:24:13.0859 3292 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
12:24:13.0875 3292 intelppm - ok
12:24:13.0906 3292 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
12:24:13.0906 3292 IPBusEnum - ok
12:24:13.0953 3292 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:24:13.0953 3292 IpFilterDriver - ok
12:24:14.0109 3292 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
12:24:14.0125 3292 iphlpsvc - ok
12:24:14.0171 3292 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:24:14.0171 3292 IPMIDRV - ok
12:24:14.0218 3292 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
12:24:14.0234 3292 IPNAT - ok
12:24:14.0265 3292 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
12:24:14.0265 3292 IRENUM - ok
12:24:14.0281 3292 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
12:24:14.0281 3292 isapnp - ok
12:24:14.0312 3292 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
12:24:14.0327 3292 iScsiPrt - ok
12:24:14.0405 3292 jrdusbser (2d967bc62a651fea616ef787f787d796) C:\Windows\system32\DRIVERS\jrdusbser.sys
12:24:14.0405 3292 jrdusbser - ok
12:24:14.0468 3292 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
12:24:14.0468 3292 kbdclass - ok
12:24:14.0499 3292 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
12:24:14.0499 3292 kbdhid - ok
12:24:14.0546 3292 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:24:14.0561 3292 KeyIso - ok
12:24:14.0593 3292 KSecDD (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
12:24:14.0593 3292 KSecDD - ok
12:24:14.0639 3292 KSecPkg (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
12:24:14.0639 3292 KSecPkg - ok
12:24:14.0686 3292 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
12:24:14.0686 3292 ksthunk - ok
12:24:14.0764 3292 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
12:24:14.0780 3292 KtmRm - ok
12:24:14.0842 3292 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\System32\srvsvc.dll
12:24:14.0858 3292 LanmanServer - ok
12:24:14.0920 3292 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
12:24:14.0920 3292 LanmanWorkstation - ok
12:24:14.0998 3292 LgBttPort (6377a3efa96e855fdfdf4c4cb1e55bf0) C:\Windows\system32\DRIVERS\lgbtpt64.sys
12:24:14.0998 3292 LgBttPort - ok
12:24:15.0029 3292 lgbusenum (3490dca88dac89e53328a6160f26ed09) C:\Windows\system32\DRIVERS\lgbtbs64.sys
12:24:15.0045 3292 lgbusenum - ok
12:24:15.0107 3292 lgmdbus (678cb7b4d20d700e075b3b1054737008) C:\Windows\system32\DRIVERS\lgmdbus.sys
12:24:15.0107 3292 lgmdbus - ok
12:24:15.0123 3292 lgmdmdfl (620e7edf1d6c5f882c4c7fcb13f0d45c) C:\Windows\system32\DRIVERS\lgmdmdfl.sys
12:24:15.0123 3292 lgmdmdfl - ok
12:24:15.0154 3292 lgmdmdm (baac03b6e2016b5a16977e7571411302) C:\Windows\system32\DRIVERS\lgmdmdm.sys
12:24:15.0154 3292 lgmdmdm - ok
12:24:15.0170 3292 lgmdmgmt (33cec7f1fc47b05fab306e88a2b68883) C:\Windows\system32\DRIVERS\lgmdmgmt.sys
12:24:15.0185 3292 lgmdmgmt - ok
12:24:15.0201 3292 lgmdobex (9d2c14824a059ead09809d359a4e9a04) C:\Windows\system32\DRIVERS\lgmdobex.sys
12:24:15.0201 3292 lgmdobex - ok
12:24:15.0248 3292 LGVMODEM (e494371d06d6956469658969633dac06) C:\Windows\system32\DRIVERS\lgvmdm64.sys
12:24:15.0248 3292 LGVMODEM - ok
12:24:15.0326 3292 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
12:24:15.0326 3292 lltdio - ok
12:24:15.0388 3292 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
12:24:15.0404 3292 lltdsvc - ok
12:24:15.0419 3292 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
12:24:15.0435 3292 lmhosts - ok
12:24:15.0513 3292 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
12:24:15.0513 3292 LSI_FC - ok
12:24:15.0529 3292 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
12:24:15.0529 3292 LSI_SAS - ok
12:24:15.0544 3292 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:24:15.0544 3292 LSI_SAS2 - ok
12:24:15.0575 3292 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:24:15.0575 3292 LSI_SCSI - ok
12:24:15.0607 3292 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
12:24:15.0622 3292 luafv - ok
12:24:15.0716 3292 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
12:24:15.0716 3292 MarvinBus - ok
12:24:15.0856 3292 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
12:24:15.0856 3292 MBAMProtector - ok
12:24:15.0981 3292 MBAMService (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:24:15.0997 3292 MBAMService - ok
12:24:16.0106 3292 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
12:24:16.0106 3292 Mcx2Svc - ok
12:24:16.0168 3292 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
12:24:16.0168 3292 megasas - ok
12:24:16.0199 3292 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
12:24:16.0215 3292 MegaSR - ok
12:24:16.0324 3292 Microsoft SharePoint Workspace Audit Service - ok
12:24:16.0418 3292 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:24:16.0418 3292 MMCSS - ok
12:24:16.0449 3292 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
12:24:16.0465 3292 Modem - ok
12:24:16.0511 3292 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
12:24:16.0511 3292 monitor - ok
12:24:16.0574 3292 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
12:24:16.0574 3292 mouclass - ok
12:24:16.0605 3292 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
12:24:16.0605 3292 mouhid - ok
12:24:16.0652 3292 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
12:24:16.0652 3292 mountmgr - ok
12:24:16.0667 3292 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
12:24:16.0667 3292 mpio - ok
12:24:16.0714 3292 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
12:24:16.0714 3292 mpsdrv - ok
12:24:16.0730 3292 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
12:24:16.0745 3292 MRxDAV - ok
12:24:16.0777 3292 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
12:24:16.0792 3292 mrxsmb - ok
12:24:16.0839 3292 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:24:16.0839 3292 mrxsmb10 - ok
12:24:16.0870 3292 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:24:16.0870 3292 mrxsmb20 - ok
12:24:16.0901 3292 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
12:24:16.0901 3292 msahci - ok
12:24:16.0933 3292 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
12:24:16.0933 3292 msdsm - ok
12:24:16.0979 3292 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
12:24:16.0995 3292 MSDTC - ok
12:24:17.0073 3292 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
12:24:17.0073 3292 Msfs - ok
12:24:17.0089 3292 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
12:24:17.0089 3292 mshidkmdf - ok
12:24:17.0120 3292 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
12:24:17.0120 3292 msisadrv - ok
12:24:17.0182 3292 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
12:24:17.0198 3292 MSiSCSI - ok
12:24:17.0198 3292 msiserver - ok
12:24:17.0291 3292 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
12:24:17.0291 3292 MSKSSRV - ok
12:24:17.0338 3292 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
12:24:17.0338 3292 MSPCLOCK - ok
12:24:17.0385 3292 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
12:24:17.0385 3292 MSPQM - ok
12:24:17.0432 3292 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
12:24:17.0432 3292 MsRPC - ok
12:24:17.0447 3292 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
12:24:17.0447 3292 mssmbios - ok
12:24:17.0494 3292 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
12:24:17.0494 3292 MSTEE - ok
12:24:17.0525 3292 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
12:24:17.0525 3292 MTConfig - ok
12:24:17.0541 3292 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
12:24:17.0541 3292 Mup - ok
12:24:17.0588 3292 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
12:24:17.0603 3292 napagent - ok
12:24:17.0728 3292 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
12:24:17.0744 3292 NativeWifiP - ok
12:24:17.0837 3292 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
12:24:17.0853 3292 NDIS - ok
12:24:17.0931 3292 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
12:24:17.0931 3292 NdisCap - ok
12:24:17.0978 3292 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
12:24:17.0978 3292 NdisTapi - ok
12:24:18.0025 3292 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
12:24:18.0025 3292 Ndisuio - ok
12:24:18.0056 3292 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
12:24:18.0056 3292 NdisWan - ok
12:24:18.0071 3292 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
12:24:18.0087 3292 NDProxy - ok
12:24:18.0134 3292 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
12:24:18.0134 3292 NetBIOS - ok
12:24:18.0149 3292 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
12:24:18.0165 3292 NetBT - ok
12:24:18.0212 3292 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:24:18.0212 3292 Netlogon - ok
12:24:18.0274 3292 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
12:24:18.0274 3292 Netman - ok
12:24:18.0305 3292 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
12:24:18.0321 3292 netprofm - ok
12:24:18.0383 3292 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:24:18.0383 3292 NetTcpPortSharing - ok
12:24:18.0446 3292 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
12:24:18.0461 3292 nfrd960 - ok
12:24:18.0539 3292 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
12:24:18.0539 3292 NlaSvc - ok
12:24:18.0571 3292 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
12:24:18.0571 3292 Npfs - ok
12:24:18.0602 3292 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
12:24:18.0617 3292 nsi - ok
12:24:18.0649 3292 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
12:24:18.0649 3292 nsiproxy - ok
12:24:18.0727 3292 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
12:24:18.0773 3292 Ntfs - ok
12:24:18.0805 3292 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
12:24:18.0820 3292 Null - ok
12:24:18.0867 3292 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
12:24:18.0867 3292 nvraid - ok
12:24:18.0914 3292 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
12:24:18.0914 3292 nvstor - ok
12:24:18.0976 3292 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
12:24:18.0992 3292 nv_agp - ok
12:24:18.0992 3292 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
12:24:19.0007 3292 ohci1394 - ok
12:24:19.0179 3292 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:24:19.0179 3292 ose64 - ok
12:24:19.0366 3292 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
12:24:19.0522 3292 osppsvc - ok
12:24:19.0647 3292 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:24:19.0663 3292 p2pimsvc - ok
12:24:19.0694 3292 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
12:24:19.0694 3292 p2psvc - ok
12:24:19.0756 3292 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
12:24:19.0756 3292 Parport - ok
12:24:19.0787 3292 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
12:24:19.0787 3292 partmgr - ok
12:24:19.0819 3292 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
12:24:19.0834 3292 PcaSvc - ok
12:24:19.0897 3292 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
12:24:19.0897 3292 pci - ok
12:24:19.0990 3292 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
12:24:19.0990 3292 pciide - ok
12:24:20.0006 3292 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
12:24:20.0021 3292 pcmcia - ok
12:24:20.0037 3292 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
12:24:20.0037 3292 pcw - ok
12:24:20.0068 3292 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
12:24:20.0084 3292 PEAUTH - ok
12:24:20.0146 3292 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
12:24:20.0255 3292 PerfHost - ok
12:24:20.0380 3292 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
12:24:20.0427 3292 pla - ok
12:24:20.0521 3292 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
12:24:20.0536 3292 PlugPlay - ok
12:24:20.0552 3292 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
12:24:20.0567 3292 PNRPAutoReg - ok
12:24:20.0583 3292 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:24:20.0599 3292 PNRPsvc - ok
12:24:20.0645 3292 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
12:24:20.0645 3292 PolicyAgent - ok
12:24:20.0692 3292 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
12:24:20.0692 3292 Power - ok
12:24:20.0770 3292 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
12:24:20.0770 3292 PptpMiniport - ok
12:24:20.0801 3292 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
12:24:20.0801 3292 Processor - ok
12:24:20.0833 3292 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
12:24:20.0848 3292 ProfSvc - ok
12:24:20.0879 3292 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:24:20.0879 3292 ProtectedStorage - ok
12:24:20.0957 3292 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
12:24:20.0973 3292 Psched - ok
12:24:21.0020 3292 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
12:24:21.0082 3292 ql2300 - ok
12:24:21.0160 3292 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
12:24:21.0160 3292 ql40xx - ok
12:24:21.0223 3292 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
12:24:21.0223 3292 QWAVE - ok
12:24:21.0254 3292 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
12:24:21.0254 3292 QWAVEdrv - ok
12:24:21.0269 3292 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
12:24:21.0269 3292 RasAcd - ok
12:24:21.0332 3292 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
12:24:21.0332 3292 RasAgileVpn - ok
12:24:21.0363 3292 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
12:24:21.0363 3292 RasAuto - ok
12:24:21.0425 3292 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
12:24:21.0425 3292 Rasl2tp - ok
12:24:21.0503 3292 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
12:24:21.0519 3292 RasMan - ok
12:24:21.0566 3292 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
12:24:21.0566 3292 RasPppoe - ok
12:24:21.0613 3292 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
12:24:21.0613 3292 RasSstp - ok
12:24:21.0644 3292 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
12:24:21.0644 3292 rdbss - ok
12:24:21.0675 3292 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
12:24:21.0691 3292 rdpbus - ok
12:24:21.0706 3292 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
12:24:21.0706 3292 RDPCDD - ok
12:24:21.0769 3292 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
12:24:21.0769 3292 RDPENCDD - ok
12:24:21.0784 3292 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
12:24:21.0784 3292 RDPREFMP - ok
12:24:21.0831 3292 RDPWD (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys
12:24:21.0831 3292 RDPWD - ok
12:24:21.0878 3292 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
12:24:21.0878 3292 rdyboost - ok
12:24:21.0956 3292 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
12:24:21.0971 3292 RemoteAccess - ok
12:24:22.0003 3292 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
12:24:22.0003 3292 RemoteRegistry - ok
12:24:22.0034 3292 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
12:24:22.0065 3292 RpcEptMapper - ok
12:24:22.0143 3292 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
12:24:22.0143 3292 RpcLocator - ok
12:24:22.0174 3292 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
12:24:22.0190 3292 RpcSs - ok
12:24:22.0299 3292 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
12:24:22.0299 3292 rspndr - ok
12:24:22.0361 3292 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
12:24:22.0361 3292 RTL8167 - ok
12:24:22.0455 3292 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:24:22.0455 3292 SamSs - ok
12:24:22.0502 3292 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
12:24:22.0502 3292 sbp2port - ok
12:24:22.0595 3292 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
12:24:22.0595 3292 SCardSvr - ok
12:24:22.0751 3292 ScFBPNT2 (a4f18227d12749425928c3ac642e4daa) C:\Windows\system32\mvwebserver.dll
12:24:22.0751 3292 ScFBPNT2 ( Backdoor.Multi.ZAccess.gen ) - infected
12:24:22.0751 3292 ScFBPNT2 - detected Backdoor.Multi.ZAccess.gen (0)
12:24:22.0814 3292 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
12:24:22.0814 3292 scfilter - ok
12:24:22.0954 3292 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
12:24:22.0985 3292 Schedule - ok
12:24:23.0032 3292 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
12:24:23.0048 3292 SCPolicySvc - ok
12:24:23.0079 3292 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
12:24:23.0079 3292 SDRSVC - ok
12:24:23.0141 3292 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
12:24:23.0157 3292 secdrv - ok
12:24:23.0188 3292 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
12:24:23.0188 3292 seclogon - ok
12:24:23.0219 3292 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
12:24:23.0219 3292 SENS - ok
12:24:23.0235 3292 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
12:24:23.0235 3292 SensrSvc - ok
12:24:23.0297 3292 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
12:24:23.0297 3292 Serenum - ok
12:24:23.0344 3292 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
12:24:23.0344 3292 Serial - ok
12:24:23.0360 3292 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
12:24:23.0360 3292 sermouse - ok
12:24:23.0422 3292 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
12:24:23.0422 3292 SessionEnv - ok
12:24:23.0438 3292 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
12:24:23.0438 3292 sffdisk - ok
12:24:23.0453 3292 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:24:23.0453 3292 sffp_mmc - ok
12:24:23.0469 3292 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
12:24:23.0469 3292 sffp_sd - ok
12:24:23.0485 3292 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
12:24:23.0485 3292 sfloppy - ok
12:24:23.0563 3292 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
12:24:23.0563 3292 SharedAccess - ok
12:24:23.0625 3292 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
12:24:23.0641 3292 ShellHWDetection - ok
12:24:23.0703 3292 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:24:23.0703 3292 SiSRaid2 - ok
12:24:23.0734 3292 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
12:24:23.0734 3292 SiSRaid4 - ok
12:24:23.0750 3292 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
12:24:23.0750 3292 Smb - ok
12:24:23.0812 3292 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
12:24:23.0828 3292 SNMPTRAP - ok
12:24:23.0843 3292 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
12:24:23.0843 3292 spldr - ok
12:24:23.0906 3292 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
12:24:23.0921 3292 Spooler - ok
12:24:24.0015 3292 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
12:24:24.0093 3292 sppsvc - ok
12:24:24.0109 3292 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
12:24:24.0124 3292 sppuinotify - ok
12:24:24.0171 3292 sptd - ok
12:24:24.0249 3292 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
12:24:24.0249 3292 srv - ok
12:24:24.0280 3292 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
12:24:24.0280 3292 srv2 - ok
12:24:24.0343 3292 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
12:24:24.0343 3292 SrvHsfHDA - ok
12:24:24.0421 3292 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
12:24:24.0452 3292 SrvHsfV92 - ok
12:24:24.0514 3292 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
12:24:24.0514 3292 SrvHsfWinac - ok
12:24:24.0577 3292 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
12:24:24.0577 3292 srvnet - ok
12:24:24.0608 3292 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
12:24:24.0608 3292 SSDPSRV - ok
12:24:24.0639 3292 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
12:24:24.0639 3292 SstpSvc - ok
12:24:24.0701 3292 StarOpen - ok
12:24:24.0748 3292 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
12:24:24.0748 3292 stexstor - ok
12:24:24.0811 3292 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
12:24:24.0826 3292 stisvc - ok
12:24:24.0842 3292 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
12:24:24.0842 3292 swenum - ok
12:24:24.0889 3292 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
12:24:24.0904 3292 swprv - ok
12:24:24.0967 3292 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
12:24:25.0013 3292 SysMain - ok
12:24:25.0029 3292 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
12:24:25.0045 3292 TabletInputService - ok
12:24:25.0076 3292 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
12:24:25.0091 3292 TapiSrv - ok
12:24:25.0107 3292 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
12:24:25.0123 3292 TBS - ok
12:24:25.0201 3292 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
12:24:25.0247 3292 Tcpip - ok
12:24:25.0372 3292 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
12:24:25.0388 3292 TCPIP6 - ok
12:24:25.0435 3292 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
12:24:25.0435 3292 tcpipreg - ok
12:24:25.0466 3292 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
12:24:25.0466 3292 TDPIPE - ok
12:24:25.0513 3292 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
12:24:25.0513 3292 TDTCP - ok
12:24:25.0544 3292 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
12:24:25.0544 3292 tdx - ok
12:24:25.0559 3292 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
12:24:25.0575 3292 TermDD - ok
12:24:25.0622 3292 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
12:24:25.0637 3292 TermService - ok
12:24:25.0669 3292 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
12:24:25.0669 3292 Themes - ok
12:24:25.0700 3292 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:24:25.0700 3292 THREADORDER - ok
12:24:25.0731 3292 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
12:24:25.0731 3292 TrkWks - ok
12:24:25.0809 3292 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
12:24:25.0809 3292 TrustedInstaller - ok
12:24:25.0871 3292 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
12:24:25.0871 3292 tssecsrv - ok
12:24:25.0949 3292 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
12:24:25.0965 3292 tunnel - ok
12:24:25.0996 3292 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
12:24:25.0996 3292 uagp35 - ok
12:24:26.0027 3292 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
12:24:26.0027 3292 udfs - ok
12:24:26.0074 3292 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
12:24:26.0074 3292 UI0Detect - ok
12:24:26.0152 3292 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
12:24:26.0152 3292 uliagpkx - ok
12:24:26.0199 3292 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
12:24:26.0199 3292 umbus - ok
12:24:26.0215 3292 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
12:24:26.0215 3292 UmPass - ok
12:24:26.0261 3292 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
12:24:26.0261 3292 upnphost - ok
12:24:26.0308 3292 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
12:24:26.0308 3292 usbccgp - ok
12:24:26.0386 3292 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
12:24:26.0386 3292 usbcir - ok
12:24:26.0433 3292 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
12:24:26.0433 3292 usbehci - ok
12:24:26.0495 3292 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
12:24:26.0495 3292 usbhub - ok
12:24:26.0527 3292 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
12:24:26.0527 3292 usbohci - ok
12:24:26.0589 3292 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
12:24:26.0589 3292 usbprint - ok
12:24:26.0651 3292 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
12:24:26.0651 3292 usbscan - ok
12:24:26.0714 3292 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:24:26.0714 3292 USBSTOR - ok
12:24:26.0761 3292 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
12:24:26.0761 3292 usbuhci - ok
12:24:26.0823 3292 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
12:24:26.0839 3292 usbvideo - ok
12:24:26.0870 3292 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
12:24:26.0870 3292 UxSms - ok
12:24:26.0917 3292 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:24:26.0917 3292 VaultSvc - ok
12:24:27.0010 3292 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
12:24:27.0026 3292 vdrvroot - ok
12:24:27.0057 3292 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
12:24:27.0057 3292 vds - ok
12:24:27.0104 3292 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
12:24:27.0104 3292 vga - ok
12:24:27.0135 3292 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
12:24:27.0135 3292 VgaSave - ok
12:24:27.0166 3292 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
12:24:27.0166 3292 vhdmp - ok
12:24:27.0182 3292 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
12:24:27.0182 3292 viaide - ok
12:24:27.0213 3292 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
12:24:27.0213 3292 volmgr - ok
12:24:27.0244 3292 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
12:24:27.0244 3292 volmgrx - ok
12:24:27.0275 3292 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
12:24:27.0275 3292 volsnap - ok
12:24:27.0307 3292 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
12:24:27.0307 3292 vsmraid - ok
12:24:27.0385 3292 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
12:24:27.0431 3292 VSS - ok
12:24:27.0525 3292 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
12:24:27.0525 3292 vwifibus - ok
12:24:27.0556 3292 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
12:24:27.0556 3292 vwififlt - ok
12:24:27.0603 3292 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
12:24:27.0603 3292 vwifimp - ok
12:24:27.0650 3292 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
12:24:27.0665 3292 W32Time - ok
12:24:27.0697 3292 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
12:24:27.0697 3292 WacomPen - ok
12:24:27.0759 3292 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:24:27.0759 3292 WANARP - ok
12:24:27.0775 3292 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:24:27.0775 3292 Wanarpv6 - ok
12:24:27.0946 3292 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
12:24:27.0977 3292 WatAdminSvc - ok
12:24:28.0040 3292 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
12:24:28.0087 3292 wbengine - ok
12:24:28.0118 3292 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
12:24:28.0133 3292 WbioSrvc - ok
12:24:28.0180 3292 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
12:24:28.0196 3292 wcncsvc - ok
12:24:28.0211 3292 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
12:24:28.0227 3292 WcsPlugInService - ok
12:24:28.0258 3292 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
12:24:28.0258 3292 Wd - ok
12:24:28.0289 3292 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
12:24:28.0305 3292 Wdf01000 - ok
12:24:28.0321 3292 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:24:28.0336 3292 WdiServiceHost - ok
12:24:28.0336 3292 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:24:28.0336 3292 WdiSystemHost - ok
12:24:28.0383 3292 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
12:24:28.0399 3292 WebClient - ok
12:24:28.0430 3292 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
12:24:28.0430 3292 Wecsvc - ok
12:24:28.0461 3292 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
12:24:28.0461 3292 wercplsupport - ok
12:24:28.0508 3292 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
12:24:28.0508 3292 WerSvc - ok
12:24:28.0617 3292 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
12:24:28.0617 3292 WfpLwf - ok
12:24:28.0633 3292 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
12:24:28.0633 3292 WIMMount - ok
12:24:28.0773 3292 WinDefend - ok
12:24:28.0789 3292 WinHttpAutoProxySvc - ok
12:24:28.0882 3292 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
12:24:28.0882 3292 Winmgmt - ok
12:24:28.0960 3292 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
12:24:29.0023 3292 WinRM - ok
12:24:29.0132 3292 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
12:24:29.0132 3292 WinUsb - ok
12:24:29.0179 3292 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
12:24:29.0210 3292 Wlansvc - ok
12:24:29.0381 3292 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:24:29.0428 3292 wlidsvc - ok
12:24:29.0506 3292 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
12:24:29.0522 3292 WmiAcpi - ok
12:24:29.0569 3292 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
12:24:29.0584 3292 wmiApSrv - ok
12:24:29.0615 3292 WMPNetworkSvc - ok
12:24:29.0678 3292 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
12:24:29.0693 3292 WPCSvc - ok
12:24:29.0709 3292 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
12:24:29.0709 3292 WPDBusEnum - ok
12:24:29.0740 3292 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
12:24:29.0756 3292 ws2ifsl - ok
12:24:29.0881 3292 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\system32\wscsvc.dll
12:24:29.0881 3292 wscsvc - ok
12:24:29.0896 3292 WSearch - ok
12:24:29.0990 3292 wuauserv (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
12:24:30.0052 3292 wuauserv - ok
12:24:30.0083 3292 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
12:24:30.0099 3292 WudfPf - ok
12:24:30.0161 3292 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
12:24:30.0161 3292 WUDFRd - ok
12:24:30.0193 3292 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
12:24:30.0208 3292 wudfsvc - ok
12:24:30.0239 3292 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
12:24:30.0239 3292 WwanSvc - ok
12:24:30.0286 3292 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
12:24:30.0364 3292 \Device\Harddisk0\DR0 - ok
12:24:30.0364 3292 Boot (0x1200) (995e7438fda39eeede8094ab26f48291) \Device\Harddisk0\DR0\Partition0
12:24:30.0364 3292 \Device\Harddisk0\DR0\Partition0 - ok
12:24:30.0380 3292 Boot (0x1200) (69a2e5766b6410e8ee49937c95ec120f) \Device\Harddisk0\DR0\Partition1
12:24:30.0380 3292 \Device\Harddisk0\DR0\Partition1 - ok
12:24:30.0380 3292 ============================================================
12:24:30.0380 3292 Scan finished
12:24:30.0380 3292 ============================================================
12:24:30.0411 3284 Detected object count: 1
12:24:30.0411 3284 Actual detected object count: 1
12:26:02.0649 3284 ScFBPNT2 ( Backdoor.Multi.ZAccess.gen ) - skipped by user
12:26:02.0649 3284 ScFBPNT2 ( Backdoor.Multi.ZAccess.gen ) - User select action: Skip
12:51:44.0774 1612 ============================================================
12:51:44.0774 1612 Scan started
12:51:44.0774 1612 Mode: Manual;
12:51:44.0774 1612 ============================================================
12:51:45.0866 1612 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
12:51:45.0881 1612 1394ohci - ok
12:51:45.0928 1612 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
12:51:45.0928 1612 ACPI - ok
12:51:45.0944 1612 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
12:51:45.0944 1612 AcpiPmi - ok
12:51:45.0991 1612 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
12:51:46.0006 1612 adp94xx - ok
12:51:46.0022 1612 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
12:51:46.0022 1612 adpahci - ok
12:51:46.0037 1612 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
12:51:46.0053 1612 adpu320 - ok
12:51:46.0100 1612 AeLookupSvc (4b78b431f225fd8624c5655cb1de7b61) C:\Windows\System32\aelupsvc.dll
12:51:46.0100 1612 AeLookupSvc - ok
12:51:46.0162 1612 AFD (db9d6c6b2cd95a9ca414d045b627422e) C:\Windows\system32\drivers\afd.sys
12:51:46.0178 1612 AFD - ok
12:51:46.0240 1612 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
12:51:46.0240 1612 agp440 - ok
12:51:46.0287 1612 ALG (3290d6946b5e30e70414990574883ddb) C:\Windows\System32\alg.exe
12:51:46.0287 1612 ALG - ok
12:51:46.0334 1612 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
12:51:46.0349 1612 aliide - ok
12:51:46.0349 1612 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
12:51:46.0365 1612 amdide - ok
12:51:46.0381 1612 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
12:51:46.0396 1612 AmdK8 - ok
12:51:46.0427 1612 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
12:51:46.0427 1612 AmdPPM - ok
12:51:46.0474 1612 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
12:51:46.0474 1612 amdsata - ok
12:51:46.0521 1612 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
12:51:46.0521 1612 amdsbs - ok
12:51:46.0583 1612 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
12:51:46.0583 1612 amdxata - ok
12:51:46.0630 1612 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
12:51:46.0630 1612 AppID - ok
12:51:46.0693 1612 AppIDSvc (0bc381a15355a3982216f7172f545de1) C:\Windows\System32\appidsvc.dll
12:51:46.0708 1612 AppIDSvc - ok
12:51:46.0739 1612 Appinfo (d065be66822847b7f127d1f90158376e) C:\Windows\System32\appinfo.dll
12:51:46.0739 1612 Appinfo - ok
12:51:46.0786 1612 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
12:51:46.0786 1612 arc - ok
12:51:46.0802 1612 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
12:51:46.0802 1612 arcsas - ok
12:51:46.0833 1612 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
12:51:46.0833 1612 AsyncMac - ok
12:51:46.0864 1612 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
12:51:46.0864 1612 atapi - ok
12:51:46.0927 1612 athr (38562a6a9cb10844759eaf2b01a7fcd3) C:\Windows\system32\DRIVERS\athrx.sys
12:51:46.0942 1612 athr - ok
12:51:47.0005 1612 AudioEndpointBuilder (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
12:51:47.0020 1612 AudioEndpointBuilder - ok
12:51:47.0036 1612 AudioSrv (07721a77180edd4d39ccb865bf63c7fd) C:\Windows\System32\Audiosrv.dll
12:51:47.0051 1612 AudioSrv - ok
12:51:47.0083 1612 AxInstSV (b20b5fa5ca050e9926e4d1db81501b32) C:\Windows\System32\AxInstSV.dll
12:51:47.0083 1612 AxInstSV - ok
12:51:47.0145 1612 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
12:51:47.0145 1612 b06bdrv - ok
12:51:47.0192 1612 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
12:51:47.0192 1612 b57nd60a - ok
12:51:47.0254 1612 BDESVC (fde360167101b4e45a96f939f388aeb0) C:\Windows\System32\bdesvc.dll
12:51:47.0254 1612 BDESVC - ok
12:51:47.0285 1612 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
12:51:47.0285 1612 Beep - ok
12:51:47.0363 1612 BITS (7f0c323fe3da28aa4aa1bda3f575707f) C:\Windows\System32\qmgr.dll
12:51:47.0363 1612 BITS - ok
12:51:47.0395 1612 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
12:51:47.0395 1612 blbdrive - ok
12:51:47.0441 1612 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
12:51:47.0441 1612 bowser - ok
12:51:47.0473 1612 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:51:47.0473 1612 BrFiltLo - ok
12:51:47.0504 1612 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:51:47.0504 1612 BrFiltUp - ok
12:51:47.0519 1612 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
12:51:47.0519 1612 BridgeMP - ok
12:51:47.0582 1612 Browser (94fbc06f294d58d02361918418f996e3) C:\Windows\System32\browser.dll
12:51:47.0582 1612 Browser - ok
12:51:47.0613 1612 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
12:51:47.0613 1612 Brserid - ok
12:51:47.0629 1612 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
12:51:47.0629 1612 BrSerWdm - ok
12:51:47.0660 1612 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
12:51:47.0660 1612 BrUsbMdm - ok
12:51:47.0660 1612 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
12:51:47.0675 1612 BrUsbSer - ok
12:51:47.0691 1612 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
12:51:47.0691 1612 BTHMODEM - ok
12:51:47.0722 1612 bthserv (95f9c2976059462cbbf227f7aab10de9) C:\Windows\system32\bthserv.dll
12:51:47.0738 1612 bthserv - ok
12:51:47.0769 1612 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
12:51:47.0769 1612 cdfs - ok
12:51:47.0785 1612 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
12:51:47.0785 1612 cdrom - ok
12:51:47.0816 1612 CertPropSvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
12:51:47.0816 1612 CertPropSvc - ok
12:51:47.0863 1612 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
12:51:47.0863 1612 circlass - ok
12:51:47.0894 1612 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
12:51:47.0909 1612 CLFS - ok
12:51:47.0956 1612 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:51:47.0972 1612 clr_optimization_v2.0.50727_32 - ok
12:51:48.0019 1612 clr_optimization_v2.0.50727_64 (d1ceea2b47cb998321c579651ce3e4f8) C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
12:51:48.0034 1612 clr_optimization_v2.0.50727_64 - ok
12:51:48.0112 1612 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:51:48.0112 1612 clr_optimization_v4.0.30319_32 - ok
12:51:48.0175 1612 clr_optimization_v4.0.30319_64 (c6f9af94dcd58122a4d7e89db6bed29d) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
12:51:48.0175 1612 clr_optimization_v4.0.30319_64 - ok
12:51:48.0237 1612 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
12:51:48.0237 1612 CmBatt - ok
12:51:48.0253 1612 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
12:51:48.0253 1612 cmdide - ok
12:51:48.0377 1612 CNG (937beb186a735aca91d717044a49d17e) C:\Windows\system32\Drivers\cng.sys
12:51:48.0377 1612 CNG - ok
12:51:48.0409 1612 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
12:51:48.0409 1612 Compbatt - ok
12:51:48.0440 1612 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
12:51:48.0440 1612 CompositeBus - ok
12:51:48.0455 1612 COMSysApp - ok
12:51:48.0487 1612 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
12:51:48.0487 1612 crcdisk - ok
12:51:48.0549 1612 CryptSvc (8c57411b66282c01533cb776f98ad384) C:\Windows\system32\cryptsvc.dll
12:51:48.0549 1612 CryptSvc - ok
12:51:48.0674 1612 DcomLaunch (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
12:51:48.0674 1612 DcomLaunch - ok
12:51:48.0721 1612 defragsvc (3cec7631a84943677aa8fa8ee5b6b43d) C:\Windows\System32\defragsvc.dll
12:51:48.0721 1612 defragsvc - ok
12:51:48.0783 1612 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
12:51:48.0783 1612 DfsC - ok
12:51:48.0845 1612 Dhcp (ce3b9562d997f69b330d181a8875960f) C:\Windows\system32\dhcpcore.dll
12:51:48.0845 1612 Dhcp - ok
12:51:49.0001 1612 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
12:51:49.0001 1612 discache - ok
12:51:49.0298 1612 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
12:51:49.0298 1612 Disk - ok
12:51:49.0360 1612 Dnscache (85cf424c74a1d5ec33533e1dbff9920a) C:\Windows\System32\dnsrslvr.dll
12:51:49.0360 1612 Dnscache - ok
12:51:49.0407 1612 dot3svc (14452acdb09b70964c8c21bf80a13acb) C:\Windows\System32\dot3svc.dll
12:51:49.0407 1612 dot3svc - ok
12:51:49.0423 1612 DPS (8c2ba6bea949ee6e68385f5692bafb94) C:\Windows\system32\dps.dll
12:51:49.0423 1612 DPS - ok
12:51:49.0454 1612 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
12:51:49.0454 1612 drmkaud - ok
12:51:49.0516 1612 dtsoftbus01 (d3d64cf7b2bceaa34a270f45a3fffb36) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
12:51:49.0516 1612 dtsoftbus01 - ok
12:51:49.0594 1612 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
12:51:49.0594 1612 DXGKrnl - ok
12:51:49.0625 1612 EapHost (e2dda8726da9cb5b2c4000c9018a9633) C:\Windows\System32\eapsvc.dll
12:51:49.0625 1612 EapHost - ok
12:51:49.0735 1612 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
12:51:49.0750 1612 ebdrv - ok
12:51:49.0797 1612 EFS (156f6159457d0aa7e59b62681b56eb90) C:\Windows\System32\lsass.exe
12:51:49.0797 1612 EFS - ok
12:51:49.0875 1612 ehRecvr (47c071994c3f649f23d9cd075ac9304a) C:\Windows\ehome\ehRecvr.exe
12:51:49.0875 1612 ehRecvr - ok
12:51:49.0922 1612 ehSched (4705e8ef9934482c5bb488ce28afc681) C:\Windows\ehome\ehsched.exe
12:51:49.0922 1612 ehSched - ok
12:51:49.0984 1612 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
12:51:50.0000 1612 elxstor - ok
12:51:50.0031 1612 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
12:51:50.0031 1612 ErrDev - ok
12:51:50.0109 1612 EventSystem (4166f82be4d24938977dd1746be9b8a0) C:\Windows\system32\es.dll
12:51:50.0109 1612 EventSystem - ok
12:51:50.0156 1612 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
12:51:50.0156 1612 exfat - ok
12:51:50.0218 1612 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
12:51:50.0234 1612 fastfat - ok
12:51:50.0281 1612 Fax (d607b2f1bee3992aa6c2c92c0a2f0855) C:\Windows\system32\fxssvc.exe
12:51:50.0281 1612 Fax - ok
12:51:50.0312 1612 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
12:51:50.0327 1612 fdc - ok
12:51:50.0343 1612 fdPHost (0438cab2e03f4fb61455a7956026fe86) C:\Windows\system32\fdPHost.dll
12:51:50.0343 1612 fdPHost - ok
12:51:50.0374 1612 FDResPub (802496cb59a30349f9a6dd22d6947644) C:\Windows\system32\fdrespub.dll
12:51:50.0374 1612 FDResPub - ok
12:51:50.0421 1612 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
12:51:50.0421 1612 FileInfo - ok
12:51:50.0437 1612 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
12:51:50.0437 1612 Filetrace - ok
12:51:50.0468 1612 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
12:51:50.0468 1612 flpydisk - ok
12:51:50.0499 1612 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
12:51:50.0499 1612 FltMgr - ok
12:51:50.0577 1612 FontCache (cb5e4b9c319e3c6bb363eb7e58a4a051) C:\Windows\system32\FntCache.dll
12:51:50.0577 1612 FontCache - ok
12:51:50.0655 1612 FontCache3.0.0.0 (8d89e3131c27fdd6932189cb785e1b7a) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:51:50.0655 1612 FontCache3.0.0.0 - ok
12:51:50.0717 1612 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
12:51:50.0717 1612 FsDepends - ok
12:51:50.0749 1612 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
12:51:50.0764 1612 Fs_Rec - ok
12:51:50.0811 1612 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
12:51:50.0811 1612 fvevol - ok
12:51:51.0154 1612 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
12:51:51.0154 1612 gagp30kx - ok
12:51:51.0482 1612 gpsvc (fe5ab4525bc2ec68b9119a6e5d40128b) C:\Windows\System32\gpsvc.dll
12:51:51.0482 1612 gpsvc - ok
12:51:51.0575 1612 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
12:51:51.0575 1612 gusvc - ok
12:51:51.0669 1612 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
12:51:51.0669 1612 hcw85cir - ok
12:51:51.0700 1612 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
12:51:51.0716 1612 HdAudAddService - ok
12:51:51.0731 1612 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
12:51:51.0731 1612 HDAudBus - ok
12:51:51.0763 1612 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
12:51:51.0763 1612 HidBatt - ok
12:51:51.0763 1612 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
12:51:51.0778 1612 HidBth - ok
12:51:51.0778 1612 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
12:51:51.0778 1612 HidIr - ok
12:51:51.0825 1612 hidserv (bd9eb3958f213f96b97b1d897dee006d) C:\Windows\System32\hidserv.dll
12:51:51.0825 1612 hidserv - ok
12:51:51.0841 1612 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
12:51:51.0841 1612 HidUsb - ok
12:51:51.0856 1612 hkmsvc (efa58ede58dd74388ffd04cb32681518) C:\Windows\system32\kmsvc.dll
12:51:51.0856 1612 hkmsvc - ok
12:51:51.0887 1612 HomeGroupListener (046b2673767ca626e2cfb7fdf735e9e8) C:\Windows\system32\ListSvc.dll
12:51:51.0887 1612 HomeGroupListener - ok
12:51:51.0934 1612 HomeGroupProvider (06a7422224d9865a5613710a089987df) C:\Windows\system32\provsvc.dll
12:51:51.0934 1612 HomeGroupProvider - ok
12:51:51.0965 1612 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
12:51:51.0965 1612 HpSAMD - ok
12:51:52.0059 1612 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
12:51:52.0059 1612 HTTP - ok
12:51:52.0075 1612 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
12:51:52.0075 1612 hwpolicy - ok
12:51:52.0106 1612 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
12:51:52.0106 1612 i8042prt - ok
12:51:52.0153 1612 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
12:51:52.0153 1612 iaStorV - ok
12:51:52.0246 1612 idsvc (2f2be70d3e02b6fa877921ab9516d43c) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
12:51:52.0246 1612 idsvc - ok
12:51:52.0465 1612 igfx (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys
12:51:52.0527 1612 igfx - ok
12:51:52.0574 1612 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
12:51:52.0574 1612 iirsp - ok
12:51:52.0636 1612 IKEEXT (c5b4683680df085b57bc53e5ef34861f) C:\Windows\System32\ikeext.dll
12:51:52.0652 1612 IKEEXT - ok
12:51:52.0683 1612 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
12:51:52.0683 1612 intelide - ok
12:51:52.0699 1612 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
12:51:52.0699 1612 intelppm - ok
12:51:52.0730 1612 IPBusEnum (098a91c54546a3b878dad6a7e90a455b) C:\Windows\system32\ipbusenum.dll
12:51:52.0730 1612 IPBusEnum - ok
12:51:52.0761 1612 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:51:52.0761 1612 IpFilterDriver - ok
12:51:52.0808 1612 iphlpsvc (f8e058d17363ec580e4b7232778b6cb5) C:\Windows\System32\iphlpsvc.dll
12:51:52.0808 1612 iphlpsvc - ok
12:51:52.0839 1612 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
12:51:52.0839 1612 IPMIDRV - ok
12:51:52.0901 1612 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
12:51:52.0901 1612 IPNAT - ok
12:51:52.0948 1612 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
12:51:52.0948 1612 IRENUM - ok
12:51:52.0964 1612 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
12:51:52.0964 1612 isapnp - ok
12:51:52.0995 1612 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
12:51:52.0995 1612 iScsiPrt - ok
12:51:53.0042 1612 jrdusbser (2d967bc62a651fea616ef787f787d796) C:\Windows\system32\DRIVERS\jrdusbser.sys
12:51:53.0042 1612 jrdusbser - ok
12:51:53.0151 1612 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
12:51:53.0151 1612 kbdclass - ok
12:51:53.0167 1612 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
12:51:53.0167 1612 kbdhid - ok
12:51:53.0229 1612 KeyIso (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:51:53.0229 1612 KeyIso - ok
12:51:53.0260 1612 KSecDD (16c1b906fc5ead84769f90b736b6bf0e) C:\Windows\system32\Drivers\ksecdd.sys
12:51:53.0260 1612 KSecDD - ok
12:51:53.0307 1612 KSecPkg (0b711550c56444879d71c7daabda6c83) C:\Windows\system32\Drivers\ksecpkg.sys
12:51:53.0307 1612 KSecPkg - ok
12:51:53.0338 1612 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
12:51:53.0338 1612 ksthunk - ok
12:51:53.0416 1612 KtmRm (6ab66e16aa859232f64deb66887a8c9c) C:\Windows\system32\msdtckrm.dll
12:51:53.0416 1612 KtmRm - ok
12:51:53.0463 1612 LanmanServer (81f1d04d4d0e433099365127375fd501) C:\Windows\System32\srvsvc.dll
12:51:53.0479 1612 LanmanServer - ok
12:51:53.0510 1612 LanmanWorkstation (27026eac8818e8a6c00a1cad2f11d29a) C:\Windows\System32\wkssvc.dll
12:51:53.0510 1612 LanmanWorkstation - ok
12:51:53.0557 1612 LgBttPort (6377a3efa96e855fdfdf4c4cb1e55bf0) C:\Windows\system32\DRIVERS\lgbtpt64.sys
12:51:53.0557 1612 LgBttPort - ok
12:51:53.0572 1612 lgbusenum (3490dca88dac89e53328a6160f26ed09) C:\Windows\system32\DRIVERS\lgbtbs64.sys
12:51:53.0572 1612 lgbusenum - ok
12:51:53.0619 1612 lgmdbus (678cb7b4d20d700e075b3b1054737008) C:\Windows\system32\DRIVERS\lgmdbus.sys
12:51:53.0619 1612 lgmdbus - ok
12:51:53.0666 1612 lgmdmdfl (620e7edf1d6c5f882c4c7fcb13f0d45c) C:\Windows\system32\DRIVERS\lgmdmdfl.sys
12:51:53.0666 1612 lgmdmdfl - ok
12:51:54.0040 1612 lgmdmdm (baac03b6e2016b5a16977e7571411302) C:\Windows\system32\DRIVERS\lgmdmdm.sys
12:51:54.0040 1612 lgmdmdm - ok
12:51:54.0134 1612 lgmdmgmt (33cec7f1fc47b05fab306e88a2b68883) C:\Windows\system32\DRIVERS\lgmdmgmt.sys
12:51:54.0134 1612 lgmdmgmt - ok
12:51:54.0165 1612 lgmdobex (9d2c14824a059ead09809d359a4e9a04) C:\Windows\system32\DRIVERS\lgmdobex.sys
12:51:54.0165 1612 lgmdobex - ok
12:51:54.0196 1612 LGVMODEM (e494371d06d6956469658969633dac06) C:\Windows\system32\DRIVERS\lgvmdm64.sys
12:51:54.0196 1612 LGVMODEM - ok
12:51:54.0227 1612 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
12:51:54.0227 1612 lltdio - ok
12:51:54.0274 1612 lltdsvc (c1185803384ab3feed115f79f109427f) C:\Windows\System32\lltdsvc.dll
12:51:54.0274 1612 lltdsvc - ok
12:51:54.0290 1612 lmhosts (f993a32249b66c9d622ea5592a8b76b8) C:\Windows\System32\lmhsvc.dll
12:51:54.0290 1612 lmhosts - ok
12:51:54.0352 1612 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
12:51:54.0352 1612 LSI_FC - ok
12:51:54.0368 1612 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
12:51:54.0368 1612 LSI_SAS - ok
12:51:54.0383 1612 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:51:54.0383 1612 LSI_SAS2 - ok
12:51:54.0399 1612 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:51:54.0399 1612 LSI_SCSI - ok
12:51:54.0430 1612 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
12:51:54.0430 1612 luafv - ok
12:51:54.0477 1612 MarvinBus (024da28053d57e9e32bee52600576bbb) C:\Windows\system32\DRIVERS\MarvinBus64.sys
12:51:54.0477 1612 MarvinBus - ok
12:51:54.0508 1612 MBAMProtector (79da94b35371b9e7104460c7693dcb2c) C:\Windows\system32\drivers\mbam.sys
12:51:54.0508 1612 MBAMProtector - ok
12:51:54.0617 1612 MBAMService (056b19651bd7b7ce5f89a3ac46dbdc08) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
12:51:54.0617 1612 MBAMService - ok
12:51:54.0711 1612 Mcx2Svc (f84c8f1000bc11e3b7b23cbd3baff111) C:\Windows\system32\Mcx2Svc.dll
12:51:54.0727 1612 Mcx2Svc - ok
12:51:54.0773 1612 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
12:51:54.0773 1612 megasas - ok
12:51:54.0805 1612 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
12:51:54.0805 1612 MegaSR - ok
12:51:54.0883 1612 Microsoft SharePoint Workspace Audit Service - ok
12:51:54.0961 1612 MMCSS (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:51:54.0961 1612 MMCSS - ok
12:51:55.0007 1612 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
12:51:55.0007 1612 Modem - ok
12:51:55.0023 1612 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
12:51:55.0039 1612 monitor - ok
12:51:55.0054 1612 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
12:51:55.0054 1612 mouclass - ok
12:51:55.0070 1612 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
12:51:55.0070 1612 mouhid - ok
12:51:55.0085 1612 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
12:51:55.0085 1612 mountmgr - ok
12:51:55.0117 1612 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
12:51:55.0117 1612 mpio - ok
12:51:55.0163 1612 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
12:51:55.0163 1612 mpsdrv - ok
12:51:55.0195 1612 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
12:51:55.0195 1612 MRxDAV - ok
12:51:55.0241 1612 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
12:51:55.0241 1612 mrxsmb - ok
12:51:55.0288 1612 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:51:55.0288 1612 mrxsmb10 - ok
12:51:55.0319 1612 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:51:55.0319 1612 mrxsmb20 - ok
12:51:55.0351 1612 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
12:51:55.0351 1612 msahci - ok
12:51:55.0397 1612 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
12:51:55.0397 1612 msdsm - ok
12:51:55.0429 1612 MSDTC (de0ece52236cfa3ed2dbfc03f28253a8) C:\Windows\System32\msdtc.exe
12:51:55.0429 1612 MSDTC - ok
12:51:55.0491 1612 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
12:51:55.0491 1612 Msfs - ok
12:51:55.0538 1612 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
12:51:55.0538 1612 mshidkmdf - ok
12:51:55.0569 1612 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
12:51:55.0569 1612 msisadrv - ok
12:51:55.0600 1612 MSiSCSI (808e98ff49b155c522e6400953177b08) C:\Windows\system32\iscsiexe.dll
12:51:55.0600 1612 MSiSCSI - ok
12:51:55.0616 1612 msiserver - ok
12:51:55.0678 1612 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
12:51:55.0678 1612 MSKSSRV - ok
12:51:55.0694 1612 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
12:51:55.0694 1612 MSPCLOCK - ok
12:51:55.0709 1612 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
12:51:55.0709 1612 MSPQM - ok
12:51:55.0756 1612 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
12:51:55.0756 1612 MsRPC - ok
12:51:55.0772 1612 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
12:51:55.0772 1612 mssmbios - ok
12:51:55.0803 1612 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
12:51:55.0803 1612 MSTEE - ok
12:51:55.0819 1612 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
12:51:55.0834 1612 MTConfig - ok
12:51:55.0850 1612 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
12:51:55.0850 1612 Mup - ok
12:51:55.0897 1612 napagent (4987e079a4530fa737a128be54b63b12) C:\Windows\system32\qagentRT.dll
12:51:55.0897 1612 napagent - ok
12:51:55.0975 1612 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
12:51:55.0990 1612 NativeWifiP - ok
12:51:56.0037 1612 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
12:51:56.0037 1612 NDIS - ok
12:51:56.0146 1612 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
12:51:56.0146 1612 NdisCap - ok
12:51:56.0162 1612 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
12:51:56.0162 1612 NdisTapi - ok
12:51:56.0193 1612 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
12:51:56.0193 1612 Ndisuio - ok
12:51:56.0224 1612 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
12:51:56.0224 1612 NdisWan - ok
12:51:56.0255 1612 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
12:51:56.0255 1612 NDProxy - ok
12:51:56.0271 1612 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
12:51:56.0271 1612 NetBIOS - ok
12:51:56.0287 1612 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
12:51:56.0287 1612 NetBT - ok
12:51:56.0349 1612 Netlogon (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:51:56.0349 1612 Netlogon - ok
12:51:56.0411 1612 Netman (847d3ae376c0817161a14a82c8922a9e) C:\Windows\System32\netman.dll
12:51:56.0411 1612 Netman - ok
12:51:56.0443 1612 netprofm (5f28111c648f1e24f7dbc87cdeb091b8) C:\Windows\System32\netprofm.dll
12:51:56.0443 1612 netprofm - ok
12:51:56.0521 1612 NetTcpPortSharing (3e5a36127e201ddf663176b66828fafe) C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:51:56.0521 1612 NetTcpPortSharing - ok
12:51:56.0583 1612 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
12:51:56.0583 1612 nfrd960 - ok
12:51:56.0645 1612 NlaSvc (d9a0ce66046d6efa0c61baa885cba0a8) C:\Windows\System32\nlasvc.dll
12:51:56.0645 1612 NlaSvc - ok
12:51:56.0677 1612 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
12:51:56.0677 1612 Npfs - ok
12:51:56.0755 1612 nsi (d54bfdf3e0c953f823b3d0bfe4732528) C:\Windows\system32\nsisvc.dll
12:51:56.0755 1612 nsi - ok
12:51:56.0770 1612 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
12:51:56.0770 1612 nsiproxy - ok
12:51:56.0864 1612 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
12:51:56.0879 1612 Ntfs - ok
12:51:56.0895 1612 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
12:51:56.0895 1612 Null - ok
12:51:56.0942 1612 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
12:51:56.0942 1612 nvraid - ok
12:51:56.0989 1612 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
12:51:56.0989 1612 nvstor - ok
12:51:57.0035 1612 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
12:51:57.0035 1612 nv_agp - ok
12:51:57.0035 1612 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
12:51:57.0051 1612 ohci1394 - ok
12:51:57.0129 1612 ose64 (4965b005492cba7719e82b71e3245495) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:51:57.0129 1612 ose64 - ok
12:51:57.0316 1612 osppsvc (61bffb5f57ad12f83ab64b7181829b34) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
12:51:57.0347 1612 osppsvc - ok
12:51:57.0441 1612 p2pimsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:51:57.0441 1612 p2pimsvc - ok
12:51:57.0472 1612 p2psvc (927463ecb02179f88e4b9a17568c63c3) C:\Windows\system32\p2psvc.dll
12:51:57.0472 1612 p2psvc - ok
12:51:57.0519 1612 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
12:51:57.0519 1612 Parport - ok
12:51:57.0550 1612 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
12:51:57.0550 1612 partmgr - ok
12:51:57.0597 1612 PcaSvc (3aeaa8b561e63452c655dc0584922257) C:\Windows\System32\pcasvc.dll
12:51:57.0597 1612 PcaSvc - ok
12:51:57.0644 1612 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
12:51:57.0644 1612 pci - ok
12:51:57.0675 1612 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
12:51:57.0675 1612 pciide - ok
12:51:57.0691 1612 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
12:51:57.0691 1612 pcmcia - ok
12:51:57.0722 1612 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
12:51:57.0722 1612 pcw - ok
12:51:57.0753 1612 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
12:51:57.0753 1612 PEAUTH - ok
12:51:57.0815 1612 PerfHost (e495e408c93141e8fc72dc0c6046ddfa) C:\Windows\SysWow64\perfhost.exe
12:51:57.0831 1612 PerfHost - ok
12:51:57.0909 1612 pla (557e9a86f65f0de18c9b6751dfe9d3f1) C:\Windows\system32\pla.dll
12:51:57.0925 1612 pla - ok
12:51:57.0971 1612 PlugPlay (98b1721b8718164293b9701b98c52d77) C:\Windows\system32\umpnpmgr.dll
12:51:57.0987 1612 PlugPlay - ok
12:51:58.0003 1612 PNRPAutoReg (7195581cec9bb7d12abe54036acc2e38) C:\Windows\system32\pnrpauto.dll
12:51:58.0003 1612 PNRPAutoReg - ok
12:51:58.0034 1612 PNRPsvc (3eac4455472cc2c97107b5291e0dcafe) C:\Windows\system32\pnrpsvc.dll
12:51:58.0034 1612 PNRPsvc - ok
12:51:58.0081 1612 PolicyAgent (166eb40d1f5b47e615de3d0fffe5f243) C:\Windows\System32\ipsecsvc.dll
12:51:58.0096 1612 PolicyAgent - ok
12:51:58.0159 1612 Power (6ba9d927dded70bd1a9caded45f8b184) C:\Windows\system32\umpo.dll
12:51:58.0159 1612 Power - ok
12:51:58.0205 1612 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
12:51:58.0205 1612 PptpMiniport - ok
12:51:58.0237 1612 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
12:51:58.0252 1612 Processor - ok
12:51:58.0283 1612 ProfSvc (f381975e1f4346de875cb07339ce8d3a) C:\Windows\system32\profsvc.dll
12:51:58.0283 1612 ProfSvc - ok
12:51:58.0330 1612 ProtectedStorage (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:51:58.0330 1612 ProtectedStorage - ok
12:51:58.0408 1612 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
12:51:58.0408 1612 Psched - ok
12:51:58.0471 1612 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
12:51:58.0486 1612 ql2300 - ok
12:51:58.0517 1612 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
12:51:58.0517 1612 ql40xx - ok
12:51:58.0564 1612 QWAVE (906191634e99aea92c4816150bda3732) C:\Windows\system32\qwave.dll
12:51:58.0564 1612 QWAVE - ok
12:51:58.0611 1612 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
12:51:58.0611 1612 QWAVEdrv - ok
12:51:58.0627 1612 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
12:51:58.0627 1612 RasAcd - ok
12:51:58.0658 1612 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
12:51:58.0658 1612 RasAgileVpn - ok
12:51:58.0720 1612 RasAuto (8f26510c5383b8dbe976de1cd00fc8c7) C:\Windows\System32\rasauto.dll
12:51:58.0720 1612 RasAuto - ok
12:51:58.0767 1612 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
12:51:58.0767 1612 Rasl2tp - ok
12:51:58.0798 1612 RasMan (47394ed3d16d053f5906efe5ab51cc83) C:\Windows\System32\rasmans.dll
12:51:58.0798 1612 RasMan - ok
12:51:58.0829 1612 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
12:51:58.0829 1612 RasPppoe - ok
12:51:58.0845 1612 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
12:51:58.0861 1612 RasSstp - ok
12:51:58.0876 1612 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
12:51:58.0876 1612 rdbss - ok
12:51:58.0907 1612 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
12:51:58.0907 1612 rdpbus - ok
12:51:58.0923 1612 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
12:51:58.0939 1612 RDPCDD - ok
12:51:58.0970 1612 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
12:51:58.0970 1612 RDPENCDD - ok
12:51:59.0001 1612 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
12:51:59.0001 1612 RDPREFMP - ok
12:51:59.0048 1612 RDPWD (074ac702d8b8b660b0e1371555995386) C:\Windows\system32\drivers\RDPWD.sys
12:51:59.0048 1612 RDPWD - ok
12:51:59.0063 1612 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
12:51:59.0079 1612 rdyboost - ok
12:51:59.0110 1612 RemoteAccess (254fb7a22d74e5511c73a3f6d802f192) C:\Windows\System32\mprdim.dll
12:51:59.0110 1612 RemoteAccess - ok
12:51:59.0453 1612 RemoteRegistry (e4d94f24081440b5fc5aa556c7c62702) C:\Windows\system32\regsvc.dll
12:51:59.0453 1612 RemoteRegistry - ok
12:51:59.0516 1612 RpcEptMapper (e4dc58cf7b3ea515ae917ff0d402a7bb) C:\Windows\System32\RpcEpMap.dll
12:51:59.0516 1612 RpcEptMapper - ok
12:51:59.0547 1612 RpcLocator (d5ba242d4cf8e384db90e6a8ed850b8c) C:\Windows\system32\locator.exe
12:51:59.0547 1612 RpcLocator - ok
12:51:59.0578 1612 RpcSs (7266972e86890e2b30c0c322e906b027) C:\Windows\system32\rpcss.dll
12:51:59.0578 1612 RpcSs - ok
12:51:59.0672 1612 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
12:51:59.0672 1612 rspndr - ok
12:51:59.0719 1612 RTL8167 (baefee35d27a5440d35092ce10267bec) C:\Windows\system32\DRIVERS\Rt64win7.sys
12:51:59.0719 1612 RTL8167 - ok
12:51:59.0750 1612 SamSs (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:51:59.0750 1612 SamSs - ok
12:51:59.0781 1612 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
12:51:59.0781 1612 sbp2port - ok
12:51:59.0828 1612 SCardSvr (9b7395789e3791a3b6d000fe6f8b131e) C:\Windows\System32\SCardSvr.dll
12:51:59.0828 1612 SCardSvr - ok
12:51:59.0875 1612 ScFBPNT2 (a4f18227d12749425928c3ac642e4daa) C:\Windows\system32\mvwebserver.dll
12:51:59.0875 1612 ScFBPNT2 ( Backdoor.Multi.ZAccess.gen ) - infected
12:51:59.0875 1612 ScFBPNT2 - detected Backdoor.Multi.ZAccess.gen (0)
12:51:59.0906 1612 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
12:51:59.0906 1612 scfilter - ok
12:51:59.0968 1612 Schedule (624d0f5ff99428bb90a5b8a4123e918e) C:\Windows\system32\schedsvc.dll
12:51:59.0984 1612 Schedule - ok
12:52:00.0015 1612 SCPolicySvc (312e2f82af11e79906898ac3e3d58a1f) C:\Windows\System32\certprop.dll
12:52:00.0015 1612 SCPolicySvc - ok
12:52:00.0062 1612 SDRSVC (765a27c3279ce11d14cb9e4f5869fca5) C:\Windows\System32\SDRSVC.dll
12:52:00.0062 1612 SDRSVC - ok
12:52:00.0093 1612 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
12:52:00.0093 1612 secdrv - ok
12:52:00.0109 1612 seclogon (463b386ebc70f98da5dff85f7e654346) C:\Windows\system32\seclogon.dll
12:52:00.0124 1612 seclogon - ok
12:52:00.0140 1612 SENS (c32ab8fa018ef34c0f113bd501436d21) C:\Windows\System32\sens.dll
12:52:00.0140 1612 SENS - ok
12:52:00.0155 1612 SensrSvc (0336cffafaab87a11541f1cf1594b2b2) C:\Windows\system32\sensrsvc.dll
12:52:00.0171 1612 SensrSvc - ok
12:52:00.0202 1612 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
12:52:00.0202 1612 Serenum - ok
12:52:00.0233 1612 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
12:52:00.0233 1612 Serial - ok
12:52:00.0249 1612 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
12:52:00.0249 1612 sermouse - ok
12:52:00.0280 1612 SessionEnv (c3bc61ce47ff6f4e88ab8a3b429a36af) C:\Windows\system32\sessenv.dll
12:52:00.0296 1612 SessionEnv - ok
12:52:00.0296 1612 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
12:52:00.0296 1612 sffdisk - ok
12:52:00.0311 1612 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
12:52:00.0311 1612 sffp_mmc - ok
12:52:00.0327 1612 sffp_sd (5588b8c6193eb1522490c122eb94dffa) C:\Windows\system32\DRIVERS\sffp_sd.sys
12:52:00.0327 1612 sffp_sd - ok
12:52:00.0358 1612 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
12:52:00.0358 1612 sfloppy - ok
12:52:00.0436 1612 SharedAccess (b95f6501a2f8b2e78c697fec401970ce) C:\Windows\System32\ipnathlp.dll
12:52:00.0436 1612 SharedAccess - ok
12:52:00.0467 1612 ShellHWDetection (0298ac45d0efffb2db4baa7dd186e7bf) C:\Windows\System32\shsvcs.dll
12:52:00.0483 1612 ShellHWDetection - ok
12:52:00.0499 1612 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:52:00.0499 1612 SiSRaid2 - ok
12:52:00.0530 1612 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
12:52:00.0530 1612 SiSRaid4 - ok
12:52:00.0545 1612 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
12:52:00.0545 1612 Smb - ok
12:52:00.0577 1612 SNMPTRAP (6313f223e817cc09aa41811daa7f541d) C:\Windows\System32\snmptrap.exe
12:52:00.0577 1612 SNMPTRAP - ok
12:52:00.0608 1612 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
12:52:00.0608 1612 spldr - ok
12:52:00.0670 1612 Spooler (f8e1fa03cb70d54a9892ac88b91d1e7b) C:\Windows\System32\spoolsv.exe
12:52:00.0670 1612 Spooler - ok
12:52:00.0764 1612 sppsvc (913d843498553a1bc8f8dbad6358e49f) C:\Windows\system32\sppsvc.exe
12:52:00.0795 1612 sppsvc - ok
12:52:00.0811 1612 sppuinotify (93d7d61317f3d4bc4f4e9f8a96a7de45) C:\Windows\system32\sppuinotify.dll
12:52:00.0826 1612 sppuinotify - ok
12:52:00.0826 1612 sptd - ok
12:52:00.0873 1612 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
12:52:00.0889 1612 srv - ok
12:52:00.0920 1612 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
12:52:00.0920 1612 srv2 - ok
12:52:00.0951 1612 SrvHsfHDA (0c4540311e11664b245a263e1154cef8) C:\Windows\system32\DRIVERS\VSTAZL6.SYS
12:52:00.0951 1612 SrvHsfHDA - ok
12:52:01.0013 1612 SrvHsfV92 (02071d207a9858fbe3a48cbfd59c4a04) C:\Windows\system32\DRIVERS\VSTDPV6.SYS
12:52:01.0013 1612 SrvHsfV92 - ok
12:52:01.0060 1612 SrvHsfWinac (18e40c245dbfaf36fd0134a7ef2df396) C:\Windows\system32\DRIVERS\VSTCNXT6.SYS
12:52:01.0060 1612 SrvHsfWinac - ok
12:52:01.0107 1612 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
12:52:01.0107 1612 srvnet - ok
12:52:01.0138 1612 SSDPSRV (51b52fbd583cde8aa9ba62b8b4298f33) C:\Windows\System32\ssdpsrv.dll
12:52:01.0154 1612 SSDPSRV - ok
12:52:01.0169 1612 SstpSvc (ab7aebf58dad8daab7a6c45e6a8885cb) C:\Windows\system32\sstpsvc.dll
12:52:01.0169 1612 SstpSvc - ok
12:52:01.0185 1612 StarOpen - ok
12:52:01.0232 1612 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
12:52:01.0232 1612 stexstor - ok
12:52:01.0279 1612 stisvc (52d0e33b681bd0f33fdc08812fee4f7d) C:\Windows\System32\wiaservc.dll
12:52:01.0279 1612 stisvc - ok
12:52:01.0294 1612 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
12:52:01.0294 1612 swenum - ok
12:52:01.0341 1612 swprv (e08e46fdd841b7184194011ca1955a0b) C:\Windows\System32\swprv.dll
12:52:01.0341 1612 swprv - ok
12:52:01.0403 1612 SysMain (3c1284516a62078fb68f768de4f1a7be) C:\Windows\system32\sysmain.dll
12:52:01.0419 1612 SysMain - ok
12:52:01.0435 1612 TabletInputService (238935c3cf2854886dc7cbb2a0e2cc66) C:\Windows\System32\TabSvc.dll
12:52:01.0435 1612 TabletInputService - ok
12:52:01.0466 1612 TapiSrv (884264ac597b690c5707c89723bb8e7b) C:\Windows\System32\tapisrv.dll
12:52:01.0466 1612 TapiSrv - ok
12:52:01.0497 1612 TBS (1be03ac720f4d302ea01d40f588162f6) C:\Windows\System32\tbssvc.dll
12:52:01.0497 1612 TBS - ok
12:52:01.0591 1612 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\drivers\tcpip.sys
12:52:01.0591 1612 Tcpip - ok
12:52:01.0653 1612 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\Windows\system32\DRIVERS\tcpip.sys
12:52:01.0669 1612 TCPIP6 - ok
12:52:01.0715 1612 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
12:52:01.0715 1612 tcpipreg - ok
12:52:01.0747 1612 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
12:52:01.0747 1612 TDPIPE - ok
12:52:01.0809 1612 TDTCP (7518f7bcfd4b308abc9192bacaf6c970) C:\Windows\system32\drivers\tdtcp.sys
12:52:01.0809 1612 TDTCP - ok
12:52:01.0825 1612 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
12:52:01.0840 1612 tdx - ok
12:52:01.0856 1612 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
12:52:01.0856 1612 TermDD - ok
12:52:01.0903 1612 TermService (0f05ec2887bfe197ad82a13287d2f404) C:\Windows\System32\termsrv.dll
12:52:01.0918 1612 TermService - ok
12:52:01.0949 1612 Themes (f0344071948d1a1fa732231785a0664c) C:\Windows\system32\themeservice.dll
12:52:01.0949 1612 Themes - ok
12:52:01.0981 1612 THREADORDER (e40e80d0304a73e8d269f7141d77250b) C:\Windows\system32\mmcss.dll
12:52:01.0981 1612 THREADORDER - ok
12:52:01.0996 1612 TrkWks (7e7afd841694f6ac397e99d75cead49d) C:\Windows\System32\trkwks.dll
12:52:01.0996 1612 TrkWks - ok
12:52:02.0043 1612 TrustedInstaller (840f7fb849f5887a49ba18c13b2da920) C:\Windows\servicing\TrustedInstaller.exe
12:52:02.0043 1612 TrustedInstaller - ok
12:52:02.0105 1612 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
12:52:02.0105 1612 tssecsrv - ok
12:52:02.0121 1612 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
12:52:02.0121 1612 tunnel - ok
12:52:02.0152 1612 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
12:52:02.0152 1612 uagp35 - ok
12:52:02.0183 1612 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
12:52:02.0199 1612 udfs - ok
12:52:02.0230 1612 UI0Detect (3cbdec8d06b9968aba702eba076364a1) C:\Windows\system32\UI0Detect.exe
12:52:02.0246 1612 UI0Detect - ok
12:52:02.0277 1612 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
12:52:02.0277 1612 uliagpkx - ok
12:52:02.0293 1612 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
12:52:02.0293 1612 umbus - ok
12:52:02.0308 1612 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
12:52:02.0308 1612 UmPass - ok
12:52:02.0355 1612 upnphost (d47ec6a8e81633dd18d2436b19baf6de) C:\Windows\System32\upnphost.dll
12:52:02.0355 1612 upnphost - ok
12:52:02.0386 1612 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\DRIVERS\usbccgp.sys
12:52:02.0386 1612 usbccgp - ok
12:52:02.0417 1612 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
12:52:02.0417 1612 usbcir - ok
12:52:02.0464 1612 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
12:52:02.0464 1612 usbehci - ok
12:52:02.0527 1612 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
12:52:02.0527 1612 usbhub - ok
12:52:02.0573 1612 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
12:52:02.0573 1612 usbohci - ok
12:52:02.0620 1612 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
12:52:02.0620 1612 usbprint - ok
12:52:02.0651 1612 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
12:52:02.0667 1612 usbscan - ok
12:52:02.0714 1612 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\DRIVERS\USBSTOR.SYS
12:52:02.0714 1612 USBSTOR - ok
12:52:02.0761 1612 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\DRIVERS\usbuhci.sys
12:52:02.0761 1612 usbuhci - ok
12:52:02.0823 1612 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\System32\Drivers\usbvideo.sys
12:52:02.0823 1612 usbvideo - ok
12:52:02.0854 1612 UxSms (edbb23cbcf2cdf727d64ff9b51a6070e) C:\Windows\System32\uxsms.dll
12:52:02.0854 1612 UxSms - ok
12:52:02.0901 1612 VaultSvc (156f6159457d0aa7e59b62681b56eb90) C:\Windows\system32\lsass.exe
12:52:02.0901 1612 VaultSvc - ok
12:52:02.0932 1612 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
12:52:02.0932 1612 vdrvroot - ok
12:52:02.0963 1612 vds (44d73e0bbc1d3c8981304ba15135c2f2) C:\Windows\System32\vds.exe
12:52:02.0963 1612 vds - ok
12:52:02.0995 1612 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
12:52:02.0995 1612 vga - ok
12:52:03.0026 1612 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
12:52:03.0026 1612 VgaSave - ok
12:52:03.0057 1612 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
12:52:03.0057 1612 vhdmp - ok
12:52:03.0073 1612 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
12:52:03.0073 1612 viaide - ok
12:52:03.0088 1612 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
12:52:03.0088 1612 volmgr - ok
12:52:03.0119 1612 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
12:52:03.0119 1612 volmgrx - ok
12:52:03.0151 1612 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
12:52:03.0151 1612 volsnap - ok
12:52:03.0182 1612 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
12:52:03.0182 1612 vsmraid - ok
12:52:03.0260 1612 VSS (787898bf9fb6d7bd87a36e2d95c899ba) C:\Windows\system32\vssvc.exe
12:52:03.0275 1612 VSS - ok
12:52:03.0307 1612 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
12:52:03.0307 1612 vwifibus - ok
12:52:03.0338 1612 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
12:52:03.0338 1612 vwififlt - ok
12:52:03.0353 1612 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
12:52:03.0353 1612 vwifimp - ok
12:52:03.0416 1612 W32Time (1c9d80cc3849b3788048078c26486e1a) C:\Windows\system32\w32time.dll
12:52:03.0416 1612 W32Time - ok
12:52:03.0478 1612 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
12:52:03.0478 1612 WacomPen - ok
12:52:03.0494 1612 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:52:03.0494 1612 WANARP - ok
12:52:03.0494 1612 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
12:52:03.0494 1612 Wanarpv6 - ok
12:52:03.0587 1612 WatAdminSvc (3cec96de223e49eaae3651fcf8faea6c) C:\Windows\system32\Wat\WatAdminSvc.exe
12:52:03.0587 1612 WatAdminSvc - ok
12:52:03.0665 1612 wbengine (5ab1bb85bd8b5089cc5d64200dedae68) C:\Windows\system32\wbengine.exe
12:52:03.0665 1612 wbengine - ok
12:52:03.0728 1612 WbioSrvc (3aa101e8edab2db4131333f4325c76a3) C:\Windows\System32\wbiosrvc.dll
12:52:03.0728 1612 WbioSrvc - ok
12:52:03.0775 1612 wcncsvc (dd1bae8ebfc653824d29ccf8c9054d68) C:\Windows\System32\wcncsvc.dll
12:52:03.0775 1612 wcncsvc - ok
12:52:03.0821 1612 WcsPlugInService (20f7441334b18cee52027661df4a6129) C:\Windows\System32\WcsPlugInService.dll
12:52:03.0821 1612 WcsPlugInService - ok
12:52:03.0853 1612 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
12:52:03.0853 1612 Wd - ok
12:52:03.0899 1612 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
12:52:03.0899 1612 Wdf01000 - ok
12:52:03.0931 1612 WdiServiceHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:52:03.0931 1612 WdiServiceHost - ok
12:52:03.0931 1612 WdiSystemHost (bf1fc3f79b863c914687a737c2f3d681) C:\Windows\system32\wdi.dll
12:52:03.0946 1612 WdiSystemHost - ok
12:52:03.0993 1612 WebClient (733006127f235be7c35354ebee7b9a7b) C:\Windows\System32\webclnt.dll
12:52:03.0993 1612 WebClient - ok
12:52:04.0024 1612 Wecsvc (c749025a679c5103e575e3b48e092c43) C:\Windows\system32\wecsvc.dll
12:52:04.0024 1612 Wecsvc - ok
12:52:04.0055 1612 wercplsupport (7e591867422dc788b9e5bd337a669a08) C:\Windows\System32\wercplsupport.dll
12:52:04.0055 1612 wercplsupport - ok
12:52:04.0071 1612 WerSvc (6d137963730144698cbd10f202e9f251) C:\Windows\System32\WerSvc.dll
12:52:04.0071 1612 WerSvc - ok
12:52:04.0087 1612 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
12:52:04.0087 1612 WfpLwf - ok
12:52:04.0118 1612 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
12:52:04.0118 1612 WIMMount - ok
12:52:04.0133 1612 WinDefend - ok
12:52:04.0149 1612 WinHttpAutoProxySvc - ok
12:52:04.0211 1612 Winmgmt (19b07e7e8915d701225da41cb3877306) C:\Windows\system32\wbem\WMIsvc.dll
12:52:04.0211 1612 Winmgmt - ok
12:52:04.0289 1612 WinRM (41fbb751936b387f9179e7f03a74fe29) C:\Windows\system32\WsmSvc.dll
12:52:04.0305 1612 WinRM - ok
12:52:04.0352 1612 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
12:52:04.0352 1612 WinUsb - ok
12:52:04.0399 1612 Wlansvc (4fada86e62f18a1b2f42ba18ae24e6aa) C:\Windows\System32\wlansvc.dll
12:52:04.0399 1612 Wlansvc - ok
12:52:04.0617 1612 wlidsvc (7e47c328fc4768cb8beafbcfafa70362) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:52:04.0648 1612 wlidsvc - ok
12:52:04.0867 1612 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
12:52:04.0867 1612 WmiAcpi - ok
12:52:04.0929 1612 wmiApSrv (38b84c94c5a8af291adfea478ae54f93) C:\Windows\system32\wbem\WmiApSrv.exe
12:52:04.0929 1612 wmiApSrv - ok
12:52:04.0976 1612 WMPNetworkSvc - ok
12:52:05.0038 1612 WPCSvc (96c6e7100d724c69fcf9e7bf590d1dca) C:\Windows\System32\wpcsvc.dll
12:52:05.0038 1612 WPCSvc - ok
12:52:05.0069 1612 WPDBusEnum (2e57ddf2880a7e52e76f41c7e96d327b) C:\Windows\system32\wpdbusenum.dll
12:52:05.0069 1612 WPDBusEnum - ok
12:52:05.0101 1612 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
12:52:05.0101 1612 ws2ifsl - ok
12:52:05.0147 1612 wscsvc (8f9f3969933c02da96eb0f84576db43e) C:\Windows\system32\wscsvc.dll
12:52:05.0147 1612 wscsvc - ok
12:52:05.0163 1612 WSearch - ok
12:52:05.0257 1612 wuauserv (38340204a2d0228f1e87740fc5e554a7) C:\Windows\system32\wuaueng.dll
12:52:05.0272 1612 wuauserv - ok
12:52:05.0319 1612 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
12:52:05.0319 1612 WudfPf - ok
12:52:05.0335 1612 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
12:52:05.0335 1612 WUDFRd - ok
12:52:05.0381 1612 wudfsvc (b551d6637aa0e132c18ac6e504f7b79b) C:\Windows\System32\WUDFSvc.dll
12:52:05.0381 1612 wudfsvc - ok
12:52:05.0413 1612 WwanSvc (9a3452b3c2a46c073166c5cf49fad1ae) C:\Windows\System32\wwansvc.dll
12:52:05.0413 1612 WwanSvc - ok
12:52:05.0459 1612 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
12:52:05.0537 1612 \Device\Harddisk0\DR0 - ok
12:52:05.0537 1612 Boot (0x1200) (995e7438fda39eeede8094ab26f48291) \Device\Harddisk0\DR0\Partition0
12:52:05.0537 1612 \Device\Harddisk0\DR0\Partition0 - ok
12:52:05.0553 1612 Boot (0x1200) (69a2e5766b6410e8ee49937c95ec120f) \Device\Harddisk0\DR0\Partition1
12:52:05.0553 1612 \Device\Harddisk0\DR0\Partition1 - ok
12:52:05.0553 1612 ============================================================
12:52:05.0553 1612 Scan finished
12:52:05.0553 1612 ============================================================
12:52:05.0569 3240 Detected object count: 1
12:52:05.0569 3240 Actual detected object count: 1
12:52:15.0553 3240 C:\Windows\system32\mvwebserver.dll - copied to quarantine
12:52:15.0568 3240 HKLM\SYSTEM\ControlSet001\services\ScFBPNT2 - will be deleted on reboot
12:52:15.0615 3240 HKLM\SYSTEM\ControlSet002\services\ScFBPNT2 - will be deleted on reboot
12:52:15.0740 3240 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - cured
12:52:15.0771 3240 C:\Windows\system32\mvwebserver.dll - will be deleted on reboot
12:52:15.0771 3240 ScFBPNT2 ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete
12:52:20.0545 2508 Deinitialize success
r16
Inviato: Sunday, April 01, 2012 2:36:08 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
E sì che ti avevo indicato come fare per postare i log ......Think

Esegui queste indicazioni:

Scarica lo strumento yorkyt.exe

http://www.pandasecurity.com/resources/tools/yorkyt.exe

Salva il file sul desktop .

Fai doppio clic sul file yorkyt.exe.

Un riavvio verrà richiesto per installare un driver.( Clicca YES)

Un altro riavvio verrà richiesto . (clicca YES)

Si presenta una finestra : "Please wait.....Running..."

Aspetta pazientemente che la scansione termini.

Poi compare "Cleanup Completed"

Clicca OK.

Posta il log che rilascia sul desktop.

Poi:

Scarica OTL, e salvalo sul desktop:

http://oldtimer.geekstogo.com/OTL.exe

Clicca sull'icona di OTL che trovi sul tuo desktop .

Metti la spunta su SCAN ALL USERS.

Sotto output, metti la spunta : minimal output

Clicca sulla freccettina di File Age e seleziona 60 Days

Metti la spunta a LOP Check e Purity Check.

Sotto "Custom Scans\Fixes" copia-incolla questo codice:


Code:
"%WinDir%\$NtUninstallKB*$."



Clicca su RUN SCAN

Lascia fare la scansione senza interferire.

Al termine della scansione trovi 2 log sul desktop. OTL.txt ed Extras.txt, salvali e caricali su Wikisend, per postarli sul forum.

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.