Thanks for the reply maniac, i appriecate the help. i unistalled utorrent and Ask toolbar, used the TDSS Killer... One more thing ive been noticing is that my firewall (Comodo firewall) has been randomly say a message reading Opps! you found an error and comodo Firewall needs to close... but it never closes and i cant accually send the report.... And malwarebytes Anti-Malware has been blocking randon ip's from website claiming there malicous is this normal? (Here are the logs)(TTDS First)
------------------------------------------------------------
12:34:50.0718 2928 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32
12:34:51.0015 2928 ============================================================
12:34:51.0015 2928 Current date / time: 2012/07/31 12:34:51.0015
12:34:51.0015 2928 SystemInfo:
12:34:51.0015 2928
12:34:51.0015 2928 OS Version: 5.1.2600 ServicePack: 3.0
12:34:51.0015 2928 Product type: Workstation
12:34:51.0015 2928 ComputerName: COLTON-68A0AE49
12:34:51.0015 2928 UserName: colton
12:34:51.0015 2928 Windows directory: C:\WINDOWS
12:34:51.0015 2928 System windows directory: C:\WINDOWS
12:34:51.0015 2928 Processor architecture: Intel x86
12:34:51.0015 2928 Number of processors: 2
12:34:51.0015 2928 Page size: 0x1000
12:34:51.0015 2928 Boot type: Normal boot
12:34:51.0015 2928 ============================================================
12:34:52.0218 2928 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
12:34:52.0296 2928 Drive \Device\Harddisk1\DR3 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
12:34:52.0296 2928 ============================================================
12:34:52.0296 2928 \Device\Harddisk0\DR0:
12:34:52.0296 2928 MBR partitions:
12:34:52.0296 2928 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC7FF53F
12:34:52.0312 2928 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xC7FF5BD, BlocksNum 0x109C4FC4
12:34:52.0312 2928 \Device\Harddisk1\DR3:
12:34:52.0312 2928 MBR partitions:
12:34:52.0312 2928 \Device\Harddisk1\DR3\Partition0: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x12A18A82
12:34:52.0312 2928 ============================================================
12:34:52.0312 2928 F: <-> \Device\Harddisk1\DR3\Partition0
12:34:52.0343 2928 C: <-> \Device\Harddisk0\DR0\Partition0
12:34:52.0390 2928 L: <-> \Device\Harddisk0\DR0\Partition1
12:34:52.0390 2928 ============================================================
12:34:52.0390 2928 Initialize success
12:34:52.0390 2928 ============================================================
12:35:05.0468 2596 ============================================================
12:35:05.0468 2596 Scan started
12:35:05.0468 2596 Mode: Manual;
12:35:05.0468 2596 ============================================================
12:35:05.0593 2596 Abiosdsk - ok
12:35:05.0593 2596 abp480n5 - ok
12:35:05.0640 2596 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
12:35:05.0640 2596 ACPI - ok
12:35:05.0671 2596 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
12:35:05.0671 2596 ACPIEC - ok
12:35:05.0734 2596 AdobeFlashPlayerUpdateSvc (6c40d5ed8951ab7b90d08af655224ee4) C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
12:35:05.0734 2596 AdobeFlashPlayerUpdateSvc - ok
12:35:05.0750 2596 adpu160m - ok
12:35:05.0781 2596 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
12:35:05.0781 2596 aec - ok
12:35:05.0812 2596 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
12:35:05.0812 2596 AFD - ok
12:35:05.0828 2596 Aha154x - ok
12:35:05.0828 2596 aic78u2 - ok
12:35:05.0828 2596 aic78xx - ok
12:35:05.0859 2596 Alerter (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
12:35:05.0859 2596 Alerter - ok
12:35:05.0875 2596 ALG (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
12:35:05.0875 2596 ALG - ok
12:35:05.0875 2596 AliIde - ok
12:35:05.0968 2596 Ambfilt (267fc636801edc5ab28e14036349e3be) C:\WINDOWS\system32\drivers\Ambfilt.sys
12:35:06.0015 2596 Ambfilt - ok
12:35:06.0078 2596 AmdPPM (033448d435e65c4bd72e70521fd05c76) C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
12:35:06.0078 2596 AmdPPM - ok
12:35:06.0078 2596 amsint - ok
12:35:06.0140 2596 Apple Mobile Device (f401929ee0cc92bfe7f15161ca535383) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:35:06.0156 2596 Apple Mobile Device - ok
12:35:06.0187 2596 AppMgmt (d8849f77c0b66226335a59d26cb4edc6) C:\WINDOWS\System32\appmgmts.dll
12:35:06.0187 2596 AppMgmt - ok
12:35:06.0187 2596 asc - ok
12:35:06.0187 2596 asc3350p - ok
12:35:06.0187 2596 asc3550 - ok
12:35:06.0218 2596 AsIO (9d8cb58b9a9e177ddd599791a58a654d) C:\WINDOWS\system32\drivers\AsIO.sys
12:35:06.0218 2596 AsIO - ok
12:35:06.0328 2596 aspnet_state (0e5e4957549056e2bf2c49f4f6b601ad) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
12:35:06.0359 2596 aspnet_state - ok
12:35:06.0375 2596 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
12:35:06.0375 2596 AsyncMac - ok
12:35:06.0406 2596 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
12:35:06.0406 2596 atapi - ok
12:35:06.0406 2596 Atdisk - ok
12:35:06.0421 2596 ATITool (0e4bb35c5305099ac82053ac992e3e0e) C:\WINDOWS\system32\DRIVERS\ATITool.sys
12:35:06.0421 2596 ATITool - ok
12:35:06.0437 2596 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
12:35:06.0437 2596 Atmarpc - ok
12:35:06.0468 2596 AudioSrv (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
12:35:06.0468 2596 AudioSrv - ok
12:35:06.0515 2596 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
12:35:06.0515 2596 audstub - ok
12:35:06.0546 2596 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
12:35:06.0546 2596 Beep - ok
12:35:06.0562 2596 BIOS (be5d50529799b9bab6be879ec768b6cf) C:\WINDOWS\system32\drivers\BIOS.sys
12:35:06.0578 2596 BIOS - ok
12:35:06.0656 2596 BITS (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
12:35:06.0687 2596 BITS - ok
12:35:06.0750 2596 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe
12:35:06.0750 2596 Bonjour Service - ok
12:35:06.0796 2596 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
12:35:06.0796 2596 Bridge - ok
12:35:06.0796 2596 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys
12:35:06.0796 2596 BridgeMP - ok
12:35:06.0828 2596 Browser (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
12:35:06.0828 2596 Browser - ok
12:35:06.0859 2596 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
12:35:06.0859 2596 BrScnUsb - ok
12:35:06.0890 2596 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
12:35:06.0890 2596 cbidf2k - ok
12:35:06.0906 2596 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
12:35:06.0906 2596 CCDECODE - ok
12:35:06.0906 2596 cd20xrnt - ok
12:35:06.0937 2596 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
12:35:06.0937 2596 Cdaudio - ok
12:35:06.0953 2596 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
12:35:06.0953 2596 Cdfs - ok
12:35:06.0953 2596 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
12:35:06.0953 2596 Cdrom - ok
12:35:06.0953 2596 Changer - ok
12:35:07.0000 2596 CiSvc (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
12:35:07.0000 2596 CiSvc - ok
12:35:07.0015 2596 ClipSrv (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
12:35:07.0015 2596 ClipSrv - ok
12:35:07.0109 2596 clr_optimization_v2.0.50727_32 (d87acaed61e417bba546ced5e7e36d9c) C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:35:07.0156 2596 clr_optimization_v2.0.50727_32 - ok
12:35:07.0234 2596 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:35:07.0234 2596 clr_optimization_v4.0.30319_32 - ok
12:35:07.0406 2596 cmdAgent (907324001ae25ac5959c91eaa34cabae) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
12:35:07.0406 2596 cmdAgent - ok
12:35:07.0515 2596 cmdGuard (bee235831f8e3f0baaca18b39d285cf5) C:\WINDOWS\system32\DRIVERS\cmdguard.sys
12:35:07.0593 2596 cmdGuard - ok
12:35:07.0640 2596 cmdHlp (de548946f36cab62fec2e6aa0149a619) C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
12:35:07.0671 2596 cmdHlp - ok
12:35:07.0671 2596 CmdIde - ok
12:35:07.0687 2596 COMSysApp - ok
12:35:07.0687 2596 Cpqarray - ok
12:35:07.0718 2596 CryptSvc (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
12:35:07.0718 2596 CryptSvc - ok
12:35:07.0718 2596 dac2w2k - ok
12:35:07.0734 2596 dac960nt - ok
12:35:07.0781 2596 DcomLaunch (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
12:35:07.0781 2596 DcomLaunch - ok
12:35:07.0812 2596 Dhcp (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
12:35:07.0828 2596 Dhcp - ok
12:35:07.0828 2596 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
12:35:07.0828 2596 Disk - ok
12:35:07.0828 2596 dmadmin - ok
12:35:07.0875 2596 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
12:35:07.0890 2596 dmboot - ok
12:35:07.0906 2596 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
12:35:07.0906 2596 dmio - ok
12:35:07.0921 2596 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
12:35:07.0921 2596 dmload - ok
12:35:07.0953 2596 dmserver (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
12:35:07.0953 2596 dmserver - ok
12:35:07.0953 2596 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
12:35:07.0953 2596 DMusic - ok
12:35:08.0000 2596 Dnscache (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
12:35:08.0000 2596 Dnscache - ok
12:35:08.0031 2596 Dot3svc (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
12:35:08.0031 2596 Dot3svc - ok
12:35:08.0031 2596 dpti2o - ok
12:35:08.0062 2596 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
12:35:08.0062 2596 drmkaud - ok
12:35:08.0062 2596 EagleNT - ok
12:35:08.0078 2596 EagleXNt - ok
12:35:08.0093 2596 EapHost (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
12:35:08.0093 2596 EapHost - ok
12:35:08.0125 2596 ERSvc (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
12:35:08.0125 2596 ERSvc - ok
12:35:08.0156 2596 Eventlog (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
12:35:08.0156 2596 Eventlog - ok
12:35:08.0203 2596 EventSystem (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
12:35:08.0203 2596 EventSystem - ok
12:35:08.0218 2596 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
12:35:08.0218 2596 Fastfat - ok
12:35:08.0265 2596 FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
12:35:08.0265 2596 FastUserSwitchingCompatibility - ok
12:35:08.0281 2596 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
12:35:08.0281 2596 Fdc - ok
12:35:08.0312 2596 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
12:35:08.0312 2596 Fips - ok
12:35:08.0312 2596 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
12:35:08.0312 2596 Flpydisk - ok
12:35:08.0328 2596 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
12:35:08.0328 2596 FltMgr - ok
12:35:08.0437 2596 FontCache3.0.0.0 (8ba7c024070f2b7fdd98ed8a4ba41789) C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
12:35:08.0437 2596 FontCache3.0.0.0 - ok
12:35:08.0468 2596 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
12:35:08.0468 2596 Fs_Rec - ok
12:35:08.0468 2596 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
12:35:08.0484 2596 Ftdisk - ok
12:35:08.0515 2596 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
12:35:08.0515 2596 GEARAspiWDM - ok
12:35:08.0546 2596 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
12:35:08.0546 2596 Gpc - ok
12:35:08.0578 2596 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
12:35:08.0578 2596 HDAudBus - ok
12:35:08.0656 2596 helpsvc (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
12:35:08.0656 2596 helpsvc - ok
12:35:08.0671 2596 HidServ (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
12:35:08.0671 2596 HidServ - ok
12:35:08.0703 2596 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
12:35:08.0703 2596 hidusb - ok
12:35:08.0734 2596 hkmsvc (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
12:35:08.0734 2596 hkmsvc - ok
12:35:08.0734 2596 hpn - ok
12:35:08.0765 2596 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
12:35:08.0781 2596 HTTP - ok
12:35:08.0796 2596 HTTPFilter (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
12:35:08.0812 2596 HTTPFilter - ok
12:35:08.0812 2596 i2omgmt - ok
12:35:08.0812 2596 i2omp - ok
12:35:08.0843 2596 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
12:35:08.0843 2596 i8042prt - ok
12:35:08.0906 2596 IDriverT (1cf03c69b49acb70c722df92755c0c8c) C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
12:35:08.0921 2596 IDriverT - ok
12:35:08.0984 2596 idsvc (c01ac32dc5c03076cfb852cb5da5229c) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:35:09.0031 2596 idsvc - ok
12:35:09.0046 2596 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
12:35:09.0046 2596 Imapi - ok
12:35:09.0078 2596 ImapiService (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
12:35:09.0078 2596 ImapiService - ok
12:35:09.0078 2596 ini910u - ok
12:35:09.0125 2596 Inspect (f89849cf13805ef49da64a8a63193af7) C:\WINDOWS\system32\DRIVERS\inspect.sys
12:35:09.0187 2596 Inspect - ok
12:35:09.0406 2596 IntcAzAudAddService (a799e941c3d19bcf6f93cbe12b55bc17) C:\WINDOWS\system32\drivers\RtkHDAud.sys
12:35:09.0421 2596 IntcAzAudAddService - ok
12:35:09.0484 2596 IntelIde - ok
12:35:09.0515 2596 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
12:35:09.0515 2596 Ip6Fw - ok
12:35:09.0531 2596 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
12:35:09.0531 2596 IpFilterDriver - ok
12:35:09.0546 2596 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
12:35:09.0546 2596 IpInIp - ok
12:35:09.0578 2596 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
12:35:09.0578 2596 IpNat - ok
12:35:09.0703 2596 iPod Service (e6be7a41a28d8f2db174957454d32448) C:\Program Files\iPod\bin\iPodService.exe
12:35:09.0718 2596 iPod Service - ok
12:35:09.0734 2596 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
12:35:09.0734 2596 IPSec - ok
12:35:09.0750 2596 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
12:35:09.0750 2596 IRENUM - ok
12:35:09.0781 2596 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
12:35:09.0781 2596 isapnp - ok
12:35:09.0828 2596 JavaQuickStarterService (0a5709543986843d37a92290b7838340) C:\Program Files\Java\jre6\bin\jqs.exe
12:35:09.0828 2596 JavaQuickStarterService - ok
12:35:09.0875 2596 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
12:35:09.0875 2596 Kbdclass - ok
12:35:09.0875 2596 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
12:35:09.0875 2596 kbdhid - ok
12:35:09.0890 2596 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
12:35:09.0890 2596 kmixer - ok
12:35:09.0937 2596 KMWDFILTER (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys
12:35:09.0937 2596 KMWDFILTER - ok
12:35:09.0968 2596 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
12:35:09.0968 2596 KSecDD - ok
12:35:10.0000 2596 lanmanserver (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
12:35:10.0000 2596 lanmanserver - ok
12:35:10.0046 2596 lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
12:35:10.0046 2596 lanmanworkstation - ok
12:35:10.0046 2596 lbrtfdc - ok
12:35:10.0093 2596 LmHosts (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
12:35:10.0093 2596 LmHosts - ok
12:35:10.0125 2596 MBAMProtector (6dfe7f2e8e8a337263aa5c92a215f161) C:\WINDOWS\system32\drivers\mbam.sys
12:35:10.0125 2596 MBAMProtector - ok
12:35:10.0171 2596 MBAMService (43683e970f008c93c9429ef428147a54) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
12:35:10.0171 2596 MBAMService - ok
12:35:10.0187 2596 Messenger (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
12:35:10.0187 2596 Messenger - ok
12:35:10.0218 2596 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
12:35:10.0218 2596 mnmdd - ok
12:35:10.0250 2596 mnmsrvc (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
12:35:10.0265 2596 mnmsrvc - ok
12:35:10.0281 2596 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
12:35:10.0281 2596 Modem - ok
12:35:10.0343 2596 monfilt (c7d9f9717916b34c1b00dd4834af485c) C:\WINDOWS\system32\drivers\monfilt.sys
12:35:10.0375 2596 monfilt - ok
12:35:10.0390 2596 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
12:35:10.0390 2596 Mouclass - ok
12:35:10.0421 2596 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
12:35:10.0421 2596 mouhid - ok
12:35:10.0453 2596 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
12:35:10.0453 2596 MountMgr - ok
12:35:10.0484 2596 MpFilter (d993bea500e7382dc4e760bf4f35efcb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
12:35:10.0500 2596 MpFilter - ok
12:35:10.0562 2596 MpKslf6cb42fe (a69630d039c38018689190234f866d77) C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9203D9E2-B2B7-48C5-91EF-65217EECE86E}\MpKslf6cb42fe.sys
12:35:10.0562 2596 MpKslf6cb42fe - ok
12:35:10.0578 2596 mraid35x - ok
12:35:10.0593 2596 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
12:35:10.0593 2596 MRxDAV - ok
12:35:10.0640 2596 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
12:35:10.0640 2596 MRxSmb - ok
12:35:10.0687 2596 MSDTC (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
12:35:10.0687 2596 MSDTC - ok
12:35:10.0703 2596 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
12:35:10.0703 2596 Msfs - ok
12:35:10.0703 2596 MSIServer - ok
12:35:10.0718 2596 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
12:35:10.0718 2596 MSKSSRV - ok
12:35:10.0796 2596 MsMpSvc (24516bf4e12a46cb67302e2cdcb8cddf) C:\Program Files\Microsoft Security Client\MsMpEng.exe
12:35:10.0796 2596 MsMpSvc - ok
12:35:10.0796 2596 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
12:35:10.0796 2596 MSPCLOCK - ok
12:35:10.0812 2596 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
12:35:10.0812 2596 MSPQM - ok
12:35:10.0812 2596 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
12:35:10.0812 2596 mssmbios - ok
12:35:10.0843 2596 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
12:35:10.0843 2596 MSTEE - ok
12:35:10.0890 2596 MTsensor (d48659bb24c48345d926ecb45c1ebdf5) C:\WINDOWS\system32\DRIVERS\ASACPI.sys
12:35:10.0890 2596 MTsensor - ok
12:35:10.0921 2596 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
12:35:10.0921 2596 Mup - ok
12:35:10.0953 2596 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
12:35:10.0953 2596 NABTSFEC - ok
12:35:11.0000 2596 napagent (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
12:35:11.0000 2596 napagent - ok
12:35:11.0031 2596 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
12:35:11.0031 2596 NDIS - ok
12:35:11.0062 2596 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
12:35:11.0062 2596 NdisIP - ok
12:35:11.0093 2596 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
12:35:11.0093 2596 NdisTapi - ok
12:35:11.0109 2596 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
12:35:11.0109 2596 Ndisuio - ok
12:35:11.0109 2596 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
12:35:11.0109 2596 NdisWan - ok
12:35:11.0156 2596 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
12:35:11.0156 2596 NDProxy - ok
12:35:11.0171 2596 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
12:35:11.0171 2596 NetBIOS - ok
12:35:11.0171 2596 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
12:35:11.0187 2596 NetBT - ok
12:35:11.0203 2596 NetDDE (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
12:35:11.0218 2596 NetDDE - ok
12:35:11.0218 2596 NetDDEdsdm (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
12:35:11.0218 2596 NetDDEdsdm - ok
12:35:11.0218 2596 Netlogon (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
12:35:11.0218 2596 Netlogon - ok
12:35:11.0250 2596 Netman (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
12:35:11.0250 2596 Netman - ok
12:35:11.0328 2596 NetTcpPortSharing (d34612c5d02d026535b3095d620626ae) C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
12:35:11.0328 2596 NetTcpPortSharing - ok
12:35:11.0375 2596 Nla (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
12:35:11.0375 2596 Nla - ok
12:35:11.0406 2596 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
12:35:11.0406 2596 Npfs - ok
12:35:11.0437 2596 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
12:35:11.0453 2596 Ntfs - ok
12:35:11.0453 2596 NtLmSsp (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
12:35:11.0453 2596 NtLmSsp - ok
12:35:11.0500 2596 NtmsSvc (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
12:35:11.0500 2596 NtmsSvc - ok
12:35:11.0531 2596 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
12:35:11.0531 2596 Null - ok
12:35:12.0125 2596 nv (062c16f3364c7706713282163586988e) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
12:35:12.0281 2596 nv - ok
12:35:12.0359 2596 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
12:35:12.0359 2596 NVENETFD - ok
12:35:12.0375 2596 nvgts (ea98bfe4931bd13d747d647c1859796e) C:\WINDOWS\system32\DRIVERS\nvgts.sys
12:35:12.0375 2596 nvgts - ok
12:35:12.0390 2596 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
12:35:12.0390 2596 nvnetbus - ok
12:35:12.0421 2596 NVSvc (b2f5ac506c9b1103827b62ba18a2c514) C:\WINDOWS\system32\nvsvc32.exe
12:35:12.0421 2596 NVSvc - ok
12:35:12.0593 2596 nvUpdatusService (844a25c9e3076edef2b12e0beded755d) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
12:35:12.0625 2596 nvUpdatusService - ok
12:35:12.0703 2596 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
12:35:12.0718 2596 NwlnkFlt - ok
12:35:12.0718 2596 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
12:35:12.0718 2596 NwlnkFwd - ok
12:35:12.0750 2596 NwlnkIpx (8b8b1be2dba4025da6786c645f77f123) C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys
12:35:12.0750 2596 NwlnkIpx - ok
12:35:12.0750 2596 NwlnkNb (56d34a67c05e94e16377c60609741ff8) C:\WINDOWS\system32\DRIVERS\nwlnknb.sys
12:35:12.0750 2596 NwlnkNb - ok
12:35:12.0750 2596 NwlnkSpx (c0bb7d1615e1acbdc99757f6ceaf8cf0) C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys
12:35:12.0765 2596 NwlnkSpx - ok
12:35:12.0765 2596 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
12:35:12.0765 2596 Parport - ok
12:35:12.0781 2596 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
12:35:12.0781 2596 PartMgr - ok
12:35:12.0812 2596 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
12:35:12.0812 2596 ParVdm - ok
12:35:12.0843 2596 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
12:35:12.0843 2596 PCI - ok
12:35:12.0843 2596 PCIDump - ok
12:35:12.0859 2596 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
12:35:12.0859 2596 PCIIde - ok
12:35:12.0890 2596 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
12:35:12.0890 2596 Pcmcia - ok
12:35:12.0890 2596 PDCOMP - ok
12:35:12.0906 2596 PDFRAME - ok
12:35:12.0906 2596 PDRELI - ok
12:35:12.0906 2596 PDRFRAME - ok
12:35:12.0906 2596 perc2 - ok
12:35:12.0921 2596 perc2hib - ok
12:35:12.0953 2596 PlugPlay (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
12:35:12.0953 2596 PlugPlay - ok
12:35:13.0000 2596 PnkBstrA (3a2e85f7d90d15460c337ce80c2e3b29) C:\WINDOWS\system32\PnkBstrA.exe
12:35:13.0000 2596 PnkBstrA - ok
12:35:13.0031 2596 PolicyAgent (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
12:35:13.0031 2596 PolicyAgent - ok
12:35:13.0062 2596 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
12:35:13.0062 2596 PptpMiniport - ok
12:35:13.0078 2596 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
12:35:13.0078 2596 Processor - ok
12:35:13.0078 2596 ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
12:35:13.0093 2596 ProtectedStorage - ok
12:35:13.0093 2596 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
12:35:13.0093 2596 PSched - ok
12:35:13.0109 2596 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
12:35:13.0109 2596 Ptilink - ok
12:35:13.0109 2596 ql1080 - ok
12:35:13.0125 2596 Ql10wnt - ok
12:35:13.0125 2596 ql12160 - ok
12:35:13.0125 2596 ql1240 - ok
12:35:13.0125 2596 ql1280 - ok
12:35:13.0156 2596 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
12:35:13.0156 2596 RasAcd - ok
12:35:13.0171 2596 RasAuto (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
12:35:13.0187 2596 RasAuto - ok
12:35:13.0203 2596 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
12:35:13.0203 2596 Rasl2tp - ok
12:35:13.0234 2596 RasMan (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
12:35:13.0234 2596 RasMan - ok
12:35:13.0234 2596 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
12:35:13.0234 2596 RasPppoe - ok
12:35:13.0250 2596 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
12:35:13.0250 2596 Raspti - ok
12:35:13.0265 2596 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
12:35:13.0265 2596 Rdbss - ok
12:35:13.0281 2596 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
12:35:13.0281 2596 RDPCDD - ok
12:35:13.0296 2596 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
12:35:13.0296 2596 rdpdr - ok
12:35:13.0328 2596 RDPWD (6589db6e5969f8eee594cf71171c5028) C:\WINDOWS\system32\drivers\RDPWD.sys
12:35:13.0328 2596 RDPWD - ok
12:35:13.0359 2596 RDSessMgr (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
12:35:13.0359 2596 RDSessMgr - ok
12:35:13.0406 2596 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
12:35:13.0406 2596 redbook - ok
12:35:13.0437 2596 RemoteAccess (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
12:35:13.0437 2596 RemoteAccess - ok
12:35:13.0468 2596 RemoteRegistry (5b19b557b0c188210a56a6b699d90b8f) C:\WINDOWS\system32\regsvc.dll
12:35:13.0468 2596 RemoteRegistry - ok
12:35:13.0484 2596 RpcLocator (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
12:35:13.0500 2596 RpcLocator - ok
12:35:13.0546 2596 RpcSs (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
12:35:13.0546 2596 RpcSs - ok
12:35:13.0593 2596 RSVP (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
12:35:13.0593 2596 RSVP - ok
12:35:13.0640 2596 RT61 (581e74880aeb1dba1cb5ac8e6e6c0a69) C:\WINDOWS\system32\DRIVERS\RT61.sys
12:35:13.0640 2596 RT61 - ok
12:35:13.0671 2596 SamSs (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
12:35:13.0671 2596 SamSs - ok
12:35:13.0718 2596 SCardSvr (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
12:35:13.0718 2596 SCardSvr - ok
12:35:13.0734 2596 SCDEmu (9feb2026a460916d1a1198b460632630) C:\WINDOWS\system32\drivers\SCDEmu.sys
12:35:13.0796 2596 SCDEmu - ok
12:35:13.0843 2596 Schedule (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
12:35:13.0859 2596 Schedule - ok
12:35:13.0875 2596 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
12:35:13.0875 2596 Secdrv - ok
12:35:13.0906 2596 seclogon (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
12:35:13.0906 2596 seclogon - ok
12:35:13.0906 2596 SENS (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
12:35:13.0921 2596 SENS - ok
12:35:13.0921 2596 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
12:35:13.0921 2596 Serenum - ok
12:35:13.0921 2596 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
12:35:13.0937 2596 Serial - ok
12:35:13.0968 2596 sfdrv01 (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
12:35:14.0000 2596 sfdrv01 - ok
12:35:14.0000 2596 sfhlp02 (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
12:35:14.0000 2596 sfhlp02 - ok
12:35:14.0078 2596 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
12:35:14.0093 2596 Sfloppy - ok
12:35:14.0109 2596 sfvfs02 (d5a7e09d2c6a702809e49190d52adc9f) C:\WINDOWS\system32\drivers\sfvfs02.sys
12:35:14.0140 2596 sfvfs02 - ok
12:35:14.0171 2596 ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
12:35:14.0171 2596 ShellHWDetection - ok
12:35:14.0171 2596 Simbad - ok
12:35:14.0250 2596 SkypeUpdate (6128e98eaaed364ed1a32708d2fd22cb) C:\Program Files\Skype\Updater\Updater.exe
12:35:14.0265 2596 SkypeUpdate - ok
12:35:14.0281 2596 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
12:35:14.0296 2596 SLIP - ok
12:35:14.0296 2596 Sparrow - ok
12:35:14.0328 2596 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
12:35:14.0328 2596 splitter - ok
12:35:14.0375 2596 Spooler (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
12:35:14.0375 2596 Spooler - ok
12:35:14.0390 2596 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
12:35:14.0390 2596 sr - ok
12:35:14.0406 2596 srservice (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
12:35:14.0406 2596 srservice - ok
12:35:14.0453 2596 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
12:35:14.0453 2596 Srv - ok
12:35:14.0468 2596 SSDPSRV (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
12:35:14.0468 2596 SSDPSRV - ok
12:35:14.0500 2596 Steam Client Service - ok
12:35:14.0531 2596 stisvc (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
12:35:14.0546 2596 stisvc - ok
12:35:14.0562 2596 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
12:35:14.0562 2596 streamip - ok
12:35:14.0593 2596 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
12:35:14.0593 2596 swenum - ok
12:35:14.0593 2596 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
12:35:14.0593 2596 swmidi - ok
12:35:14.0609 2596 SwPrv - ok
12:35:14.0609 2596 symc810 - ok
12:35:14.0609 2596 symc8xx - ok
12:35:14.0609 2596 sym_hi - ok
12:35:14.0625 2596 sym_u3 - ok
12:35:14.0625 2596 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
12:35:14.0625 2596 sysaudio - ok
12:35:14.0656 2596 SysmonLog (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
12:35:14.0656 2596 SysmonLog - ok
12:35:14.0687 2596 TapiSrv (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
12:35:14.0687 2596 TapiSrv - ok
12:35:14.0750 2596 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
12:35:14.0750 2596 Tcpip - ok
12:35:14.0781 2596 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
12:35:14.0781 2596 TDPIPE - ok
12:35:14.0796 2596 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
12:35:14.0796 2596 TDTCP - ok
12:35:14.0812 2596 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
12:35:14.0812 2596 TermDD - ok
12:35:14.0843 2596 TermService (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
12:35:14.0843 2596 TermService - ok
12:35:14.0875 2596 Themes (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
12:35:14.0875 2596 Themes - ok
12:35:14.0906 2596 TlntSvr (db7205804759ff62c34e3efd8a4cc76a) C:\WINDOWS\system32\tlntsvr.exe
12:35:14.0906 2596 TlntSvr - ok
12:35:14.0921 2596 TosIde - ok
12:35:14.0953 2596 TrkWks (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
12:35:14.0953 2596 TrkWks - ok
12:35:14.0984 2596 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
12:35:14.0984 2596 Udfs - ok
12:35:14.0984 2596 ultra - ok
12:35:15.0031 2596 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
12:35:15.0046 2596 Update - ok
12:35:15.0078 2596 upnphost (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
12:35:15.0078 2596 upnphost - ok
12:35:15.0093 2596 UPS (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
12:35:15.0093 2596 UPS - ok
12:35:15.0109 2596 USBAAPL (eafe1e00739afe6c51487a050e772e17) C:\WINDOWS\system32\Drivers\usbaapl.sys
12:35:15.0125 2596 USBAAPL - ok
12:35:15.0140 2596 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
12:35:15.0140 2596 usbaudio - ok
12:35:15.0171 2596 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
12:35:15.0171 2596 usbccgp - ok
12:35:15.0171 2596 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
12:35:15.0171 2596 usbehci - ok
12:35:15.0218 2596 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
12:35:15.0218 2596 usbhub - ok
12:35:15.0218 2596 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
12:35:15.0218 2596 usbohci - ok
12:35:15.0250 2596 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
12:35:15.0250 2596 usbprint - ok
12:35:15.0281 2596 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
12:35:15.0281 2596 usbscan - ok
12:35:15.0281 2596 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:35:15.0281 2596 USBSTOR - ok
12:35:15.0312 2596 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
12:35:15.0312 2596 usbvideo - ok
12:35:15.0312 2596 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
12:35:15.0312 2596 VgaSave - ok
12:35:15.0390 2596 VIAHdAudAddService (1c43d4c8818dcbd8814e7c260744bcc4) C:\WINDOWS\system32\drivers\viahduaa.sys
12:35:15.0406 2596 VIAHdAudAddService - ok
12:35:15.0421 2596 ViaIde - ok
12:35:15.0453 2596 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
12:35:15.0453 2596 VolSnap - ok
12:35:15.0500 2596 VSS (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
12:35:15.0500 2596 VSS - ok
12:35:15.0515 2596 W32Time (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
12:35:15.0515 2596 W32Time - ok
12:35:15.0546 2596 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
12:35:15.0562 2596 Wanarp - ok
12:35:15.0562 2596 WDICA - ok
12:35:15.0562 2596 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
12:35:15.0562 2596 wdmaud - ok
12:35:15.0609 2596 WebClient (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
12:35:15.0609 2596 WebClient - ok
12:35:15.0687 2596 winmgmt (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
12:35:15.0687 2596 winmgmt - ok
12:35:15.0796 2596 WinRing0_1_2_0 (845af1ba23c8d5e64def61bcc441604c) C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys
12:35:15.0812 2596 WinRing0_1_2_0 - ok
12:35:15.0875 2596 WinRM (18f347402da544a780949b8fdf83351b) C:\WINDOWS\system32\WsmSvc.dll
12:35:15.0921 2596 WinRM - ok
12:35:16.0031 2596 wlidsvc (5144ae67d60ec653f97ddf3feed29e77) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
12:35:16.0062 2596 wlidsvc - ok
12:35:16.0156 2596 WmdmPmSN (c51b4a5c05a5475708e3c81c7765b71d) C:\WINDOWS\system32\MsPMSNSv.dll
12:35:16.0156 2596 WmdmPmSN - ok
12:35:16.0218 2596 Wmi (e76f8807070ed04e7408a86d6d3a6137) C:\WINDOWS\System32\advapi32.dll
12:35:16.0218 2596 Wmi - ok
12:35:16.0250 2596 WmiApSrv (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
12:35:16.0265 2596 WmiApSrv - ok
12:35:16.0390 2596 WMPNetworkSvc (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
12:35:16.0437 2596 WMPNetworkSvc - ok
12:35:16.0578 2596 WPFFontCache_v0400 (dcf3e3edf5109ee8bc02fe6e1f045795) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
12:35:16.0593 2596 WPFFontCache_v0400 - ok
12:35:16.0687 2596 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
12:35:16.0687 2596 WS2IFSL - ok
12:35:16.0703 2596 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
12:35:16.0703 2596 WSTCODEC - ok
12:35:16.0750 2596 wuauserv (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
12:35:16.0750 2596 wuauserv - ok
12:35:16.0781 2596 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
12:35:16.0781 2596 WudfPf - ok
12:35:16.0796 2596 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
12:35:16.0796 2596 WudfRd - ok
12:35:16.0812 2596 WudfSvc (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
12:35:16.0843 2596 WudfSvc - ok
12:35:16.0890 2596 WZCSVC (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
12:35:16.0906 2596 WZCSVC - ok
12:35:16.0906 2596 XDva390 - ok
12:35:16.0984 2596 xmlprov (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
12:35:17.0015 2596 xmlprov - ok
12:35:17.0031 2596 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
12:35:17.0062 2596 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
12:35:17.0062 2596 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
12:35:17.0062 2596 MBR (0x1B8) (aac4f0d2ae484abe318cbd52270c0a6e) \Device\Harddisk1\DR3
12:35:17.0218 2596 \Device\Harddisk1\DR3 - ok
12:35:17.0218 2596 Boot (0x1200) (3e11779a10b8db3758f3ba4dc4d2d48a) \Device\Harddisk0\DR0\Partition0
12:35:17.0218 2596 \Device\Harddisk0\DR0\Partition0 - ok
12:35:17.0234 2596 Boot (0x1200) (c163deef373f0bef5442a54abc7f7e2b) \Device\Harddisk0\DR0\Partition1
12:35:17.0234 2596 \Device\Harddisk0\DR0\Partition1 - ok
12:35:17.0234 2596 Boot (0x1200) (685b48152fe5b6ce026342d5af742671) \Device\Harddisk1\DR3\Partition0
12:35:17.0250 2596 \Device\Harddisk1\DR3\Partition0 - ok
12:35:17.0250 2596 ============================================================
12:35:17.0250 2596 Scan finished
12:35:17.0250 2596 ============================================================
12:35:17.0250 1932 Detected object count: 1
12:35:17.0250 1932 Actual detected object count: 1
12:35:43.0265 1932 \Device\Harddisk0\DR0\# - copied to quarantine
12:35:43.0265 1932 \Device\Harddisk0\DR0 - copied to quarantine
12:35:43.0328 1932 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine
12:35:43.0343 1932 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine
12:35:43.0406 1932 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine
12:35:43.0421 1932 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine
12:35:43.0453 1932 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine
12:35:43.0500 1932 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine
12:35:43.0562 1932 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine
12:35:43.0625 1932 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine
12:35:43.0640 1932 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine
12:35:43.0640 1932 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine
12:35:43.0843 1932 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine
12:35:43.0875 1932 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine
12:35:43.0890 1932 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine
12:35:43.0890 1932 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine
12:35:43.0953 1932 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot
12:35:43.0953 1932 \Device\Harddisk0\DR0 - ok
12:35:43.0953 1932 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure
12:35:50.0156 3864 Deinitialize success
-------------------------------------------------------------------------------------
Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.31.10
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
colton :: COLTON-68A0AE49 [administrator]
Protection: Enabled
7/31/2012 12:43:38 PM
mbam-log-2012-07-31 (12-43-38).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 237865
Time elapsed: 12 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)