[RESOLVED] what does this mean? - Page 4
Page 4 of 6 FirstFirst ... 23456 LastLast
Results 46 to 60 of 78

Thread: [RESOLVED] what does this mean?

  1. #46
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    I did this TDS and no reboot required so I clicked on report and it came up but it wont let me copy it

  2. #47
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    the cursor is a line not an arrow ?

  3. #48
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt

  4. #49
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    the cursor is a line not an arrow ?

  5. #50
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    19:28:07.0444 0x0738 [ 5F9A1272E79C4F68522B4B2E405E03AA ] \Device\Harddisk0\DR0\Partition2
    19:28:07.0444 0x0738 \Device\Harddisk0\DR0\Partition2 - ok
    19:28:07.0454 0x0738 [ 6E6DBD0763618B81F2C18254F946FF23 ] \Device\Harddisk1\DR1\Partition1
    19:28:07.0454 0x0738 \Device\Harddisk1\DR1\Partition1 - ok
    19:28:07.0454 0x0738 ================ Scan generic autorun ======================
    19:28:07.0526 0x0738 [ 47EA5F76FAB723C61AB4A0D79BAD512C, A7A38EB0A7068B160E6949945EF639F999A06AE35746F6E79C7350745798E5C9 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    19:28:07.0688 0x0738 Adobe ARM - ok
    19:28:07.0768 0x0738 [ 308F2EE28005510DE616409148CF077B, A2126CB185B0053086BDD6F0A16A503F6CA629AC677E4B7AE6D43C770061D087 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
    19:28:07.0788 0x0738 SunJavaUpdateSched - ok
    19:28:07.0908 0x0738 [ 34D296AFC913E302953C70463EF09A48, BC413307CBC56C039EE8A05B51A56E14EF59678FBB33815AEB320078056C8CE7 ] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    19:28:07.0918 0x0738 HP Software Update - ok
    19:28:07.0998 0x0738 [ E279E55C0D5F5DA2E1FD268EBD12F268, 06C40AF999881699DD9B73440D2ED48F404864C3FB8FF7B36560759892CAAA12 ] c:\Program Files\Microsoft Security Client\msseces.exe
    19:28:08.0088 0x0738 MSC - ok
    19:28:08.0208 0x0738 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
    19:28:08.0248 0x0738 Sidebar - ok
    19:28:08.0288 0x0738 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
    19:28:08.0288 0x0738 mctadmin - ok
    19:28:08.0288 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:09.0288 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:10.0288 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:11.0288 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:12.0288 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:13.0290 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:14.0292 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:15.0296 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:16.0298 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:17.0298 0x0738 Waiting for KSN requests completion. In queue: 346
    19:28:18.0298 0x0738 Waiting for KSN r

  6. #51
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    19:28:19.0321 0x0738 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.6.305.0 ), 0x61000 ( enabled : updated )
    19:28:19.0331 0x0738 Win FW state via NFP2: enabled
    19:28:21.0832 0x0738 ============================================================
    19:28:21.0832 0x0738 Scan finished
    19:28:21.0832 0x0738 ============================================================
    19:28:21.0852 0x0594 Detected object count: 0
    19:28:21.0852 0x0594 Actual detected object count: 0
    19:31:19.0018 0x038c Deinitialize success

  7. #52
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    You are extremely patient. It is so appreciated

  8. #53
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Not a problem but the log is incomplete.

  9. #54
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    I will try again it said the file was too large so I tried to split it sorry

  10. #55
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    19:27:05.0053 0x0c20 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
    19:27:18.0436 0x0c20 ============================================================
    19:27:18.0437 0x0c20 Current date / time: 2014/10/07 19:27:18.0436
    19:27:18.0437 0x0c20 SystemInfo:
    19:27:18.0437 0x0c20
    19:27:18.0437 0x0c20 OS Version: 6.1.7601 ServicePack: 1.0
    19:27:18.0437 0x0c20 Product type: Workstation
    19:27:18.0437 0x0c20 ComputerName: OWNER-PC
    19:27:18.0437 0x0c20 UserName: Owner
    19:27:18.0437 0x0c20 Windows directory: C:\Windows
    19:27:18.0438 0x0c20 System windows directory: C:\Windows
    19:27:18.0438 0x0c20 Processor architecture: Intel x86
    19:27:18.0438 0x0c20 Number of processors: 2
    19:27:18.0438 0x0c20 Page size: 0x1000
    19:27:18.0438 0x0c20 Boot type: Normal boot
    19:27:18.0438 0x0c20 ============================================================
    19:27:20.0726 0x0c20 KLMD registered as C:\Windows\system32\drivers\64890656.sys
    19:27:21.0101 0x0c20 System UUID: {EBC5C643-990D-37FB-8E32-BD4A2BB7371A}
    19:27:21.0792 0x0c20 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
    19:27:21.0801 0x0c20 Drive \Device\Harddisk1\DR1 - Size: 0x1D4600000 ( 7.32 Gb ), SectorSize: 0x200, Cylinders: 0x3BB, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    19:27:21.0802 0x0c20 ============================================================
    19:27:21.0802 0x0c20 \Device\Harddisk0\DR0:
    19:27:21.0802 0x0c20 MBR partitions:
    19:27:21.0802 0x0c20 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
    19:27:21.0802 0x0c20 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000
    19:27:21.0802 0x0c20 \Device\Harddisk1\DR1:
    19:27:21.0803 0x0c20 MBR partitions:
    19:27:21.0803 0x0c20 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x18, BlocksNum 0xEA2FE8
    19:27:21.0803 0x0c20 ============================================================
    19:27:21.0832 0x0c20 C: <-> \Device\Harddisk0\DR0\Partition2
    19:27:21.0832 0x0c20 ============================================================
    19:27:21.0833 0x0c20 Initialize success
    19:27:21.0833 0x0c20 ============================================================
    19:27:41.0633 0x0738 ============================================================
    19:27:41.0633 0x0738 Scan started
    19:27:41.0633 0x0738 Mode: Manual;
    19:27:41.0634 0x0738 ============================================================
    19:27:41.0634 0x0738 KSN ping started
    19:27:44.0081 0x0738 KSN ping finished: true
    19:27:44.0757 0x0738 ================ Scan system memory ========================
    19:27:44.0758 0x0738 System memory - ok
    19:27:44.0759 0x0738 ================ Scan services =============================
    19:27:44.0989 0x0738 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
    19:27:45.0002 0x0738 1394ohci - ok
    19:27:45.0066 0x0738 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys
    19:27:45.0074 0x0738 ACPI - ok
    19:27:45.0116 0x0738 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
    19:27:45.0117 0x0738 AcpiPmi - ok
    19:27:45.0231 0x0738 [ C5679E5186B2FC95BC76A8A9870D5456, 70AC61850B811A0A902532F098AE1D5DF4622455E56C78B89D4ABDBE4A061A48 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
    19:27:45.0278 0x0738 AdobeARMservice - ok
    19:27:45.0335 0x0738 [ 4ECFCAAE5CB380F58934F0DCF5F64E7F, D82B37E57D93484D7A3CB65470BCD54A578A695F0203A8DD441B1348C1EEA751 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    19:27:45.0345 0x0738 AdobeFlashPlayerUpdateSvc - ok
    19:27:45.0402 0x0738 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
    19:27:45.0415 0x0738 adp94xx - ok
    19:27:45.0433 0x0738 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
    19:27:45.0443 0x0738 adpahci - ok
    19:27:45.0456 0x0738 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
    19:27:45.0461 0x0738 adpu320 - ok
    19:27:45.0500 0x0738 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    19:27:45.0503 0x0738 AeLookupSvc - ok
    19:27:45.0574 0x0738 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\Windows\system32\drivers\afd.sys
    19:27:45.0604 0x0738 AFD - ok
    19:27:45.0659 0x0738 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
    19:27:45.0661 0x0738 agp440 - ok
    19:27:45.0677 0x0738 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
    19:27:45.0680 0x0738 aic78xx - ok
    19:27:45.0706 0x0738 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
    19:27:45.0709 0x0738 ALG - ok
    19:27:45.0752 0x0738 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
    19:27:45.0753 0x0738 aliide - ok
    19:27:45.0765 0x0738 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
    19:27:45.0768 0x0738 amdagp - ok
    19:27:45.0774 0x0738 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys
    19:27:45.0776 0x0738 amdide - ok
    19:27:45.0794 0x0738 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
    19:27:45.0796 0x0738 AmdK8 - ok
    19:27:45.0808 0x0738 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
    19:27:45.0810 0x0738 AmdPPM - ok
    19:27:45.0856 0x0738 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    19:27:45.0863 0x0738 amdsata - ok
    19:27:45.0897 0x0738 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
    19:27:45.0904 0x0738 amdsbs - ok
    19:27:45.0920 0x0738 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    19:27:45.0921 0x0738 amdxata - ok
    19:27:45.0964 0x0738 [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID C:\Windows\system32\drivers\appid.sys
    19:27:45.0967 0x0738 AppID - ok
    19:27:45.0977 0x0738 [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll
    19:27:45.0981 0x0738 AppIDSvc - ok
    19:27:46.0027 0x0738 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll
    19:27:46.0030 0x0738 Appinfo - ok
    19:27:46.0130 0x0738 [ 221564CC7BE37611FE15EACF443E1BF6, 381BDF17418C779D72332431BA174C2AD76CD9C7C1711FF5142EA9B05D5555E4 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    19:27:46.0135 0x0738 Apple Mobile Device - ok
    19:27:46.0175 0x0738 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
    19:27:46.0180 0x0738 arc - ok
    19:27:46.0196 0x0738 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
    19:27:46.0201 0x0738 arcsas - ok
    19:27:46.0351 0x0738 [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
    19:27:46.0382 0x0738 aspnet_state - ok
    19:27:46.0420 0x0738 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    19:27:46.0422 0x0738 AsyncMac - ok
    19:27:46.0465 0x0738 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
    19:27:46.0467 0x0738 atapi - ok
    19:27:46.0536 0x0738 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
    19:27:46.0555 0x0738 AudioEndpointBuilder - ok
    19:27:46.0573 0x0738 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv C:\Windows\System32\Audiosrv.dll
    19:27:46.0585 0x0738 Audiosrv - ok
    19:27:46.0640 0x0738 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll
    19:27:46.0648 0x0738 AxInstSV - ok
    19:27:46.0685 0x0738 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
    19:27:46.0704 0x0738 b06bdrv - ok
    19:27:46.0732 0x0738 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
    19:27:46.0740 0x0738 b57nd60x - ok
    19:27:46.0790 0x0738 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
    19:27:46.0797 0x0738 BDESVC - ok
    19:27:46.0810 0x0738 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
    19:27:46.0811 0x0738 Beep - ok
    19:27:46.0879 0x0738 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll
    19:27:46.0898 0x0738 BFE - ok
    19:27:46.0957 0x0738 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\system32\qmgr.dll
    19:27:46.0972 0x0738 BITS - ok
    19:27:46.0983 0x0738 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
    19:27:46.0985 0x0738 blbdrive - ok
    19:27:47.0027 0x0738 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    19:27:47.0033 0x0738 bowser - ok
    19:27:47.0052 0x0738 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
    19:27:47.0056 0x0738 BrFiltLo - ok
    19:27:47.0072 0x0738 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
    19:27:47.0074 0x0738 BrFiltUp - ok
    19:27:47.0109 0x0738 [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
    19:27:47.0113 0x0738 BridgeMP - ok
    19:27:47.0170 0x0738 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll
    19:27:47.0179 0x0738 Browser - ok
    19:27:47.0205 0x0738 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
    19:27:47.0215 0x0738 Brserid - ok
    19:27:47.0233 0x0738 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
    19:27:47.0236 0x0738 BrSerWdm - ok
    19:27:47.0246 0x0738 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
    19:27:47.0247 0x0738 BrUsbMdm - ok
    19:27:47.0255 0x0738 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
    19:27:47.0256 0x0738 BrUsbSer - ok
    19:27:47.0274 0x0738 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
    19:27:47.0276 0x0738 BTHMODEM - ok
    19:27:47.0336 0x0738 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
    19:27:47.0343 0x0738 bthserv - ok
    19:27:47.0448 0x0738 catchme - ok
    19:27:47.0471 0x0738 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    19:27:47.0477 0x0738 cdfs - ok
    19:27:47.0542 0x0738 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\drivers\cdrom.sys
    19:27:47.0552 0x0738 cdrom - ok
    19:27:47.0642 0x0738 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
    19:27:47.0645 0x0738 CertPropSvc - ok
    19:27:47.0661 0x0738 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
    19:27:47.0663 0x0738 circlass - ok
    19:27:47.0722 0x0738 [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys
    19:27:47.0743 0x0738 CLFS - ok
    19:27:47.0817 0x0738 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    19:27:47.0823 0x0738 clr_optimization_v2.0.50727_32 - ok
    19:27:47.0906 0x0738 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    19:27:47.0936 0x0738 clr_optimization_v4.0.30319_32 - ok
    19:27:47.0969 0x0738 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
    19:27:47.0972 0x0738 CmBatt - ok
    19:27:48.0017 0x0738 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
    19:27:48.0021 0x0738 cmdide - ok
    19:27:48.0094 0x0738 [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG C:\Windows\system32\Drivers\cng.sys
    19:27:48.0116 0x0738 CNG - ok
    19:27:48.0130 0x0738 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
    19:27:48.0132 0x0738 Compbatt - ok
    19:27:48.0156 0x0738 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
    19:27:48.0158 0x0738 CompositeBus - ok
    19:27:48.0164 0x0738 COMSysApp - ok
    19:27:48.0183 0x0738 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
    19:27:48.0185 0x0738 crcdisk - ok
    19:27:48.0256 0x0738 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc C:\Windows\system32\cryptsvc.dll
    19:27:48.0266 0x0738 CryptSvc - ok
    19:27:48.0332 0x0738 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll
    19:27:48.0346 0x0738 DcomLaunch - ok
    19:27:48.0395 0x0738 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
    19:27:48.0405 0x0738 defragsvc - ok
    19:27:48.0451 0x0738 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
    19:27:48.0454 0x0738 DfsC - ok
    19:27:48.0511 0x0738 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
    19:27:48.0520 0x0738 Dhcp - ok
    19:27:48.0532 0x0738 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
    19:27:48.0534 0x0738 discache - ok
    19:27:48.0562 0x0738 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
    19:27:48.0564 0x0738 Disk - ok
    19:27:48.0620 0x0738 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll
    19:27:48.0630 0x0738 Dnscache - ok
    19:27:48.0686 0x0738 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll
    19:27:48.0695 0x0738 dot3svc - ok
    19:27:48.0761 0x0738 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
    19:27:48.0773 0x0738 DPS - ok
    19:27:48.0821 0x0738 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    19:27:48.0824 0x0738 drmkaud - ok
    19:27:48.0912 0x0738 [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    19:27:48.0935 0x0738 DXGKrnl - ok
    19:27:48.0976 0x0738 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
    19:27:48.0980 0x0738 EapHost - ok
    19:27:49.0085 0x0738 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
    19:27:49.0205 0x0738 ebdrv - ok
    19:27:49.0257 0x0738 [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] EFS C:\Windows\System32\lsass.exe
    19:27:49.0259 0x0738 EFS - ok
    19:27:49.0349 0x0738 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
    19:27:49.0374 0x0738 ehRecvr - ok
    19:27:49.0423 0x0738 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
    19:27:49.0432 0x0738 ehSched - ok
    19:27:49.0471 0x0738 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
    19:27:49.0489 0x0738 elxstor - ok
    19:27:49.0531 0x0738 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
    19:27:49.0532 0x0738 ErrDev - ok
    19:27:49.0623 0x0738 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
    19:27:49.0635 0x0738 EventSystem - ok
    19:27:49.0674 0x0738 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
    19:27:49.0680 0x0738 exfat - ok
    19:27:49.0699 0x0738 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
    19:27:49.0704 0x0738 fastfat - ok
    19:27:49.0782 0x0738 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
    19:27:49.0805 0x0738 Fax - ok
    19:27:49.0819 0x0738 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
    19:27:49.0821 0x0738 fdc - ok
    19:27:49.0828 0x0738 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
    19:27:49.0830 0x0738 fdPHost - ok
    19:27:49.0836 0x0738 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
    19:27:49.0838 0x0738 FDResPub - ok
    19:27:49.0851 0x0738 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    19:27:49.0853 0x0738 FileInfo - ok
    19:27:49.0862 0x0738 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    19:27:49.0863 0x0738 Filetrace - ok
    19:27:49.0869 0x0738 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
    19:27:49.0871 0x0738 flpydisk - ok
    19:27:49.0886 0x0738 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    19:27:49.0892 0x0738 FltMgr - ok
    19:27:49.0972 0x0738 [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache C:\Windows\system32\FntCache.dll
    19:27:50.0006 0x0738 FontCache - ok
    19:27:50.0090 0x0738 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    19:27:50.0095 0x0738 FontCache3.0.0.0 - ok
    19:27:50.0120 0x0738 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    19:27:50.0125 0x0738 FsDepends - ok
    19:27:50.0167 0x0738 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    19:27:50.0170 0x0738 Fs_Rec - ok
    19:27:50.0224 0x0738 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    19:27:50.0238 0x0738 fvevol - ok
    19:27:50.0293 0x0738 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
    19:27:50.0299 0x0738 gagp30kx - ok
    19:27:50.0381 0x0738 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
    19:27:50.0408 0x0738 gpsvc - ok
    19:27:50.0422 0x0738 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
    19:27:50.0424 0x0738 hcw85cir - ok
    19:27:50.0503 0x0738 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    19:27:50.0528 0x0738 HdAudAddService - ok
    19:27:50.0550 0x0738 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
    19:27:50.0555 0x0738 HDAudBus - ok
    19:27:50.0570 0x0738 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
    19:27:50.0572 0x0738 HidBatt - ok
    19:27:50.0588 0x0738 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
    19:27:50.0593 0x0738 HidBth - ok
    19:27:50.0616 0x0738 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
    19:27:50.0619 0x0738 HidIr - ok
    19:27:50.0662 0x0738 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\System32\hidserv.dll
    19:27:50.0665 0x0738 hidserv - ok
    19:27:50.0726 0x0738 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
    19:27:50.0730 0x0738 HidUsb - ok
    19:27:50.0781 0x0738 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
    19:27:50.0789 0x0738 hkmsvc - ok
    19:27:50.0855 0x0738 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    19:27:50.0872 0x0738 HomeGroupListener - ok
    19:27:50.0931 0x0738 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    19:27:50.0948 0x0738 HomeGroupProvider - ok
    19:27:50.0971 0x0738 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    19:27:50.0975 0x0738 HpSAMD - ok
    19:27:51.0093 0x0738 [ 8313DC0085E8D05ED6662E90C6918443, AB2CC970833BF38376E8DC82E495384D0B7B30750567843DD645693919D1477B ] HPSupportSolutionsFrameworkService C:\Program Files\Hp\Common\HPSupportSolutionsFrameworkService.exe
    19:27:51.0098 0x0738 HPSupportSolutionsFrameworkService - ok
    19:27:51.0176 0x0738 [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP C:\Windows\system32\drivers\HTTP.sys
    19:27:51.0202 0x0738 HTTP - ok
    19:27:51.0244 0x0738 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    19:27:51.0245 0x0738 hwpolicy - ok
    19:27:51.0305 0x0738 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
    19:27:51.0311 0x0738 i8042prt - ok
    19:27:51.0374 0x0738 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    19:27:51.0399 0x0738 iaStorV - ok
    19:27:51.0522 0x0738 [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    19:27:51.0557 0x0738 idsvc - ok
    19:27:51.0608 0x0738 IEEtwCollectorService - ok
    19:27:51.0651 0x0738 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
    19:27:51.0653 0x0738 iirsp - ok
    19:27:51.0736 0x0738 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\Windows\System32\ikeext.dll
    19:27:51.0822 0x0738 IKEEXT - ok
    19:27:51.0835 0x0738 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
    19:27:51.0837 0x0738 intelide - ok
    19:27:51.0865 0x0738 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
    19:27:51.0867 0x0738 intelppm - ok
    19:27:51.0919 0x0738 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
    19:27:51.0928 0x0738 IPBusEnum - ok
    19:27:51.0949 0x0738 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    19:27:51.0953 0x0738 IpFilterDriver - ok
    19:27:52.0027 0x0738 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    19:27:52.0040 0x0738 iphlpsvc - ok
    19:27:52.0082 0x0738 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
    19:27:52.0085 0x0738 IPMIDRV - ok
    19:27:52.0106 0x0738 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    19:27:52.0109 0x0738 IPNAT - ok
    19:27:52.0128 0x0738 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
    19:27:52.0130 0x0738 IRENUM - ok
    19:27:52.0142 0x0738 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
    19:27:52.0144 0x0738 isapnp - ok
    19:27:52.0193 0x0738 [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
    19:27:52.0200 0x0738 iScsiPrt - ok
    19:27:52.0226 0x0738 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
    19:27:52.0228 0x0738 kbdclass - ok
    19:27:52.0239 0x0738 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
    19:27:52.0240 0x0738 kbdhid - ok
    19:27:52.0257 0x0738 [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] KeyIso C:\Windows\system32\lsass.exe
    19:27:52.0259 0x0738 KeyIso - ok
    19:27:52.0282 0x0738 [ 4120DA10AA42A9996F4575DB9E3E6E6E, 1C6E790772EA327ACB885D731A030408160534997DD56FEE4D6CEE6929873BB8 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    19:27:52.0285 0x0738 KSecDD - ok
    19:27:52.0313 0x0738 [ D3964885F0A11ACF51DA3AAA776973B2, 417ED5A3201FC50FBC0D646F8F2114A1E8A91E7919A62508DCBC156C0BFB2FBA ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    19:27:52.0317 0x0738 KSecPkg - ok
    19:27:52.0359 0x0738 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
    19:27:52.0370 0x0738 KtmRm - ok
    19:27:52.0392 0x0738 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\System32\srvsvc.dll
    19:27:52.0399 0x0738 LanmanServer - ok
    19:27:52.0412 0x0738 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    19:27:52.0417 0x0738 LanmanWorkstation - ok
    19:27:52.0441 0x0738 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    19:27:52.0443 0x0738 lltdio - ok
    19:27:52.0481 0x0738 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
    19:27:52.0501 0x0738 lltdsvc - ok
    19:27:52.0521 0x0738 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
    19:27:52.0531 0x0738 lmhosts - ok
    19:27:52.0561 0x0738 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
    19:27:52.0571 0x0738 LSI_SAS - ok
    19:27:52.0591 0x0738 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
    19:27:52.0591 0x0738 LSI_SAS2 - ok
    19:27:52.0611 0x0738 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
    19:27:52.0621 0x0738 LSI_SCSI - ok
    19:27:52.0641 0x0738 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
    19:27:52.0651 0x0738 luafv - ok
    19:27:52.0691 0x0738 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
    19:27:52.0701 0x0738 Mcx2Svc - ok
    19:27:52.0721 0x0738 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
    19:27:52.0721 0x0738 megasas - ok
    19:27:52.0741 0x0738 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys

  11. #56
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    I am trynig to figure out where I left off

  12. #57
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656
    Is there some way I can send the whole thing? I am not doing very well trying to do it in halfs

  13. #58
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Upload the file(s) here: http://www.sendspace.com/
    Click on Browse button and navigate to the file you want to upload.
    Click on Upload button.
    Click on FIRST Copy Link button and paste the link in your next reply.

  14. #59
    Join Date
    Sep 2007
    Location
    Maine
    Posts
    656

  15. #60
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    I don't see any signs of Alureon anywhere in your logs.

    When you say:
    The Microsoft Ess Sec keeps giving same message this is what the history says trojan; DOS/alureon
    what does it mean?
    Is it some current threat or some report from MSE history?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •