17:52:48.0443 5528 TDSS rootkit removing tool 2.7.41.0 Jun 20 2012 20:53:32 17:52:50.0502 5528 ============================================================ 17:52:50.0502 5528 Current date / time: 2012/06/23 17:52:50.0502 17:52:50.0502 5528 SystemInfo: 17:52:50.0502 5528 17:52:50.0502 5528 OS Version: 6.1.7600 ServicePack: 0.0 17:52:50.0502 5528 Product type: Workstation 17:52:50.0502 5528 ComputerName: BRENDA-PC 17:52:50.0502 5528 UserName: Brenda 17:52:50.0502 5528 Windows directory: C:\Windows 17:52:50.0502 5528 System windows directory: C:\Windows 17:52:50.0502 5528 Processor architecture: Intel x86 17:52:50.0502 5528 Number of processors: 1 17:52:50.0502 5528 Page size: 0x1000 17:52:50.0502 5528 Boot type: Normal boot 17:52:50.0502 5528 ============================================================ 17:52:52.0952 5528 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 17:52:52.0967 5528 ============================================================ 17:52:52.0967 5528 \Device\Harddisk0\DR0: 17:52:52.0967 5528 MBR partitions: 17:52:52.0967 5528 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 17:52:52.0967 5528 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x27753000 17:52:52.0967 5528 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27785800, BlocksNum 0x12BFF800 17:52:52.0967 5528 ============================================================ 17:52:53.0061 5528 C: <-> \Device\Harddisk0\DR0\Partition1 17:52:53.0108 5528 X: <-> \Device\Harddisk0\DR0\Partition2 17:52:53.0108 5528 ============================================================ 17:52:53.0108 5528 Initialize success 17:52:53.0108 5528 ============================================================ 17:53:06.0836 5244 ============================================================ 17:53:06.0836 5244 Scan started 17:53:06.0836 5244 Mode: Manual; 17:53:06.0851 5244 ============================================================ 17:53:10.0049 5244 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 17:53:10.0065 5244 1394ohci - ok 17:53:10.0112 5244 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 17:53:10.0127 5244 ACPI - ok 17:53:10.0158 5244 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 17:53:10.0158 5244 AcpiPmi - ok 17:53:10.0221 5244 adfs (6d7f09cd92a9fef3a8efce66231fdd79) C:\Windows\system32\drivers\adfs.sys 17:53:10.0221 5244 adfs - ok 17:53:10.0314 5244 Adobe LM Service (8b46d5a1d3ef08232c04d0eafb871fb2) C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe 17:53:10.0314 5244 Adobe LM Service - ok 17:53:10.0455 5244 AdobeFlashPlayerUpdateSvc (f3cd7b20b27d1772c946df993ff3635c) C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 17:53:10.0470 5244 AdobeFlashPlayerUpdateSvc - ok 17:53:10.0548 5244 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 17:53:10.0580 5244 adp94xx - ok 17:53:10.0611 5244 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 17:53:10.0642 5244 adpahci - ok 17:53:10.0673 5244 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 17:53:10.0673 5244 adpu320 - ok 17:53:10.0720 5244 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 17:53:10.0720 5244 AeLookupSvc - ok 17:53:10.0829 5244 AFD (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys 17:53:10.0845 5244 AFD - ok 17:53:10.0892 5244 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 17:53:10.0892 5244 agp440 - ok 17:53:11.0235 5244 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 17:53:11.0282 5244 aic78xx - ok 17:53:11.0625 5244 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 17:53:11.0625 5244 ALG - ok 17:53:11.0734 5244 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 17:53:11.0734 5244 aliide - ok 17:53:11.0874 5244 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 17:53:11.0874 5244 amdagp - ok 17:53:11.0937 5244 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 17:53:11.0937 5244 amdide - ok 17:53:12.0030 5244 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 17:53:12.0030 5244 AmdK8 - ok 17:53:12.0062 5244 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 17:53:12.0062 5244 AmdPPM - ok 17:53:12.0124 5244 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys 17:53:12.0124 5244 amdsata - ok 17:53:12.0171 5244 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 17:53:12.0186 5244 amdsbs - ok 17:53:12.0233 5244 amdxata (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys 17:53:12.0233 5244 amdxata - ok 17:53:12.0280 5244 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 17:53:12.0280 5244 AppID - ok 17:53:12.0311 5244 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 17:53:12.0327 5244 AppIDSvc - ok 17:53:12.0358 5244 Appinfo (7dead9e3f65dcb2794f2711003bbf650) C:\Windows\System32\appinfo.dll 17:53:12.0358 5244 Appinfo - ok 17:53:12.0420 5244 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 17:53:12.0420 5244 AppMgmt - ok 17:53:12.0483 5244 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 17:53:12.0483 5244 arc - ok 17:53:12.0514 5244 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 17:53:12.0514 5244 arcsas - ok 17:53:12.0561 5244 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 17:53:12.0561 5244 AsyncMac - ok 17:53:12.0592 5244 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 17:53:12.0592 5244 atapi - ok 17:53:12.0701 5244 athr (b01751cc563aecac09bbe36aaa21fbef) C:\Windows\system32\DRIVERS\athr.sys 17:53:12.0748 5244 athr - ok 17:53:13.0403 5244 Ati External Event Utility (2039e24fe00639a9123dcd6f22d42d74) C:\Windows\system32\Ati2evxx.exe 17:53:13.0419 5244 Ati External Event Utility - ok 17:53:13.0684 5244 atikmdag (d2e9acb68fa61c911cc21e07f87705bf) C:\Windows\system32\DRIVERS\atikmdag.sys 17:53:13.0778 5244 atikmdag - ok 17:53:14.0152 5244 AudioEndpointBuilder (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:53:14.0152 5244 AudioEndpointBuilder - ok 17:53:14.0168 5244 Audiosrv (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:53:14.0183 5244 Audiosrv - ok 17:53:14.0480 5244 Avgfwfd (c46ba2c177df0b84f9c0bfc1e4574dc7) C:\Windows\system32\DRIVERS\avgfwd6x.sys 17:53:14.0495 5244 Avgfwfd - ok 17:53:15.0057 5244 avgfws (5cd22eb540f82c70e33e530003f3903b) C:\Program Files\AVG\AVG2012\avgfws.exe 17:53:15.0088 5244 avgfws - ok 17:53:15.0400 5244 AVGIDSEH (19a08a6728a6e02099d64268218cd799) C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 17:53:15.0400 5244 AVGIDSEH - ok 17:53:15.0462 5244 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\Windows\system32\DRIVERS\avgldx86.sys 17:53:15.0478 5244 Avgldx86 - ok 17:53:15.0494 5244 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\Windows\system32\DRIVERS\avgmfx86.sys 17:53:15.0509 5244 Avgmfx86 - ok 17:53:15.0540 5244 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\Windows\system32\DRIVERS\avgrkx86.sys 17:53:15.0572 5244 Avgrkx86 - ok 17:53:15.0821 5244 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\Windows\system32\DRIVERS\avgtdix.sys 17:53:15.0852 5244 Avgtdix - ok 17:53:16.0008 5244 avgwd (6699ece24fe4b3f752a66c66a602ee86) C:\Program Files\AVG\AVG2012\avgwdsvc.exe 17:53:16.0008 5244 avgwd - ok 17:53:16.0055 5244 AxInstSV (dd6a431b43e34b91a767d1ce33728175) C:\Windows\System32\AxInstSV.dll 17:53:16.0071 5244 AxInstSV - ok 17:53:16.0133 5244 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 17:53:16.0180 5244 b06bdrv - ok 17:53:16.0242 5244 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 17:53:16.0258 5244 b57nd60x - ok 17:53:16.0336 5244 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 17:53:16.0336 5244 BDESVC - ok 17:53:16.0352 5244 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 17:53:16.0367 5244 Beep - ok 17:53:16.0445 5244 BFE (85ac71c045ceb054ed48a7841aae0c11) C:\Windows\System32\bfe.dll 17:53:16.0445 5244 BFE - ok 17:53:16.0508 5244 BITS (53f476476f55a27f580661bde09c4ec4) C:\Windows\system32\qmgr.dll 17:53:16.0554 5244 BITS - ok 17:53:16.0586 5244 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 17:53:16.0601 5244 blbdrive - ok 17:53:16.0710 5244 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys 17:53:16.0710 5244 bowser - ok 17:53:16.0788 5244 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:53:16.0788 5244 BrFiltLo - ok 17:53:16.0835 5244 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:53:16.0835 5244 BrFiltUp - ok 17:53:16.0991 5244 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys 17:53:17.0069 5244 BridgeMP - ok 17:53:17.0584 5244 Browser (598e1280e7ff3744f4b8329366cc5635) C:\Windows\System32\browser.dll 17:53:17.0584 5244 Browser - ok 17:53:17.0912 5244 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 17:53:17.0927 5244 Brserid - ok 17:53:18.0083 5244 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 17:53:18.0099 5244 BrSerWdm - ok 17:53:18.0130 5244 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:53:18.0130 5244 BrUsbMdm - ok 17:53:18.0177 5244 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 17:53:18.0177 5244 BrUsbSer - ok 17:53:18.0286 5244 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 17:53:18.0286 5244 BTHMODEM - ok 17:53:18.0738 5244 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 17:53:18.0738 5244 bthserv - ok 17:53:19.0035 5244 catchme - ok 17:53:19.0300 5244 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 17:53:19.0347 5244 cdfs - ok 17:53:19.0659 5244 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 17:53:19.0674 5244 cdrom - ok 17:53:19.0955 5244 CertPropSvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:53:19.0971 5244 CertPropSvc - ok 17:53:20.0049 5244 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 17:53:20.0064 5244 circlass - ok 17:53:20.0751 5244 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 17:53:20.0766 5244 CLFS - ok 17:53:21.0297 5244 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:53:21.0344 5244 clr_optimization_v2.0.50727_32 - ok 17:53:22.0061 5244 clr_optimization_v4.0.30319_32 (c5a75eb48e2344abdc162bda79e16841) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 17:53:22.0170 5244 clr_optimization_v4.0.30319_32 - ok 17:53:22.0342 5244 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 17:53:22.0389 5244 CmBatt - ok 17:53:22.0529 5244 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 17:53:22.0529 5244 cmdide - ok 17:53:22.0779 5244 CNG (36c252e474b2ffa0f0fbbff20d92a640) C:\Windows\system32\Drivers\cng.sys 17:53:22.0794 5244 CNG - ok 17:53:22.0904 5244 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 17:53:22.0904 5244 Compbatt - ok 17:53:23.0044 5244 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 17:53:23.0044 5244 CompositeBus - ok 17:53:23.0106 5244 COMSysApp - ok 17:53:23.0153 5244 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 17:53:23.0153 5244 crcdisk - ok 17:53:23.0730 5244 CryptSvc (9c231178ce4fb385f4b54b0a9080b8a4) C:\Windows\system32\cryptsvc.dll 17:53:23.0808 5244 CryptSvc - ok 17:53:23.0918 5244 CSC (27c9490bdd0ae48911ab8cf1932591ed) C:\Windows\system32\drivers\csc.sys 17:53:23.0949 5244 CSC - ok 17:53:24.0339 5244 CscService (56fb5f222ea30d3d3fc459879772cb73) C:\Windows\System32\cscsvc.dll 17:53:24.0354 5244 CscService - ok 17:53:25.0150 5244 DcomLaunch (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 17:53:25.0181 5244 DcomLaunch - ok 17:53:25.0228 5244 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 17:53:25.0244 5244 defragsvc - ok 17:53:25.0618 5244 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys 17:53:25.0649 5244 DfsC - ok 17:53:26.0024 5244 Dhcp (c56495fbd770712367cad35e5de72da6) C:\Windows\system32\dhcpcore.dll 17:53:26.0039 5244 Dhcp - ok 17:53:26.0180 5244 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 17:53:26.0180 5244 discache - ok 17:53:26.0367 5244 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 17:53:26.0414 5244 Disk - ok 17:53:26.0694 5244 Dnscache (b15be77a2bacf9c3177d27518afe26a9) C:\Windows\System32\dnsrslvr.dll 17:53:26.0694 5244 Dnscache - ok 17:53:27.0303 5244 dot3svc (4408c85c21eea48eb0ce486baeef0502) C:\Windows\System32\dot3svc.dll 17:53:27.0365 5244 dot3svc - ok 17:53:27.0552 5244 DPS (7fa81c6e11caa594adb52084da73a1e5) C:\Windows\system32\dps.dll 17:53:27.0568 5244 DPS - ok 17:53:27.0662 5244 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 17:53:27.0677 5244 drmkaud - ok 17:53:29.0518 5244 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys 17:53:29.0580 5244 DXGKrnl - ok 17:53:29.0783 5244 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 17:53:29.0783 5244 EapHost - ok 17:53:30.0922 5244 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 17:53:31.0031 5244 ebdrv - ok 17:53:32.0373 5244 EFS (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\System32\lsass.exe 17:53:32.0404 5244 EFS - ok 17:53:33.0480 5244 ehRecvr (1697c39978cd69f6fbc15302edcece1f) C:\Windows\ehome\ehRecvr.exe 17:53:33.0527 5244 ehRecvr - ok 17:53:33.0605 5244 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 17:53:33.0621 5244 ehSched - ok 17:53:33.0761 5244 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 17:53:33.0777 5244 elxstor - ok 17:53:33.0792 5244 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 17:53:33.0808 5244 ErrDev - ok 17:53:34.0557 5244 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 17:53:34.0604 5244 EventSystem - ok 17:53:35.0025 5244 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 17:53:35.0072 5244 exfat - ok 17:53:35.0571 5244 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 17:53:35.0571 5244 fastfat - ok 17:53:37.0443 5244 Fax (f7ea23cc5e6bf2181f3f399d54f6efc1) C:\Windows\system32\fxssvc.exe 17:53:37.0505 5244 Fax - ok 17:53:37.0708 5244 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 17:53:37.0708 5244 fdc - ok 17:53:37.0817 5244 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 17:53:37.0817 5244 fdPHost - ok 17:53:37.0942 5244 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 17:53:37.0942 5244 FDResPub - ok 17:53:38.0129 5244 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 17:53:38.0207 5244 FileInfo - ok 17:53:38.0348 5244 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 17:53:38.0348 5244 Filetrace - ok 17:53:38.0800 5244 FLEXnet Licensing Service (1f63900e2eb00101b9aca2b7a870704e) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 17:53:38.0847 5244 FLEXnet Licensing Service - ok 17:53:38.0909 5244 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 17:53:38.0925 5244 flpydisk - ok 17:53:39.0393 5244 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 17:53:39.0393 5244 FltMgr - ok 17:53:40.0344 5244 FontCache (7fe4995528a7529a761875151ee3d512) C:\Windows\system32\FntCache.dll 17:53:40.0376 5244 FontCache - ok 17:53:40.0672 5244 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 17:53:40.0734 5244 FontCache3.0.0.0 - ok 17:53:40.0844 5244 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 17:53:40.0844 5244 FsDepends - ok 17:53:41.0031 5244 Fs_Rec (500a9814fd9446a8126858a5a7f7d273) C:\Windows\system32\drivers\Fs_Rec.sys 17:53:41.0046 5244 Fs_Rec - ok 17:53:41.0702 5244 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys 17:53:41.0748 5244 fvevol - ok 17:53:41.0842 5244 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 17:53:41.0842 5244 gagp30kx - ok 17:53:42.0107 5244 Giraffic - ok 17:53:43.0090 5244 gpsvc (8ba3c04702bf8f927ab36ae8313ca4ee) C:\Windows\System32\gpsvc.dll 17:53:43.0137 5244 gpsvc - ok 17:53:43.0308 5244 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 17:53:43.0355 5244 hcw85cir - ok 17:53:43.0667 5244 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\Windows\system32\drivers\HdAudio.sys 17:53:43.0683 5244 HdAudAddService - ok 17:53:43.0964 5244 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 17:53:44.0026 5244 HDAudBus - ok 17:53:44.0106 5244 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 17:53:44.0126 5244 HidBatt - ok 17:53:44.0166 5244 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 17:53:44.0176 5244 HidBth - ok 17:53:44.0206 5244 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 17:53:44.0216 5244 HidIr - ok 17:53:44.0316 5244 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 17:53:44.0326 5244 hidserv - ok 17:53:44.0486 5244 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 17:53:44.0496 5244 HidUsb - ok 17:53:44.0716 5244 hkmsvc (741c2a45ca8407e374aaba3e330b7872) C:\Windows\system32\kmsvc.dll 17:53:44.0726 5244 hkmsvc - ok 17:53:45.0086 5244 HomeGroupListener (a768ca158bb06782a2835b907f4873c3) C:\Windows\system32\ListSvc.dll 17:53:45.0116 5244 HomeGroupListener - ok 17:53:45.0386 5244 HomeGroupProvider (fb08dec5ef43d0c66d83b8e9694e7549) C:\Windows\system32\provsvc.dll 17:53:45.0406 5244 HomeGroupProvider - ok 17:53:45.0586 5244 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 17:53:45.0656 5244 HpSAMD - ok 17:53:46.0856 5244 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 17:53:46.0876 5244 HTTP - ok 17:53:46.0966 5244 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 17:53:46.0966 5244 hwpolicy - ok 17:53:47.0206 5244 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 17:53:47.0216 5244 i8042prt - ok 17:53:47.0746 5244 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys 17:53:47.0766 5244 iaStorV - ok 17:53:47.0906 5244 idsvc (5af815eb5bc9802e5a064e2ba62bfc0c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 17:53:47.0976 5244 idsvc - ok 17:53:49.0096 5244 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 17:53:49.0136 5244 iirsp - ok 17:53:50.0676 5244 IKEEXT (fac0ee6562b121b1399d6e855583f7a5) C:\Windows\System32\ikeext.dll 17:53:50.0706 5244 IKEEXT - ok 17:53:52.0916 5244 IntcAzAudAddService (5d26ccb06e1f3b5c26e863df3f4f2611) C:\Windows\system32\drivers\RTKVHDA.sys 17:53:52.0976 5244 IntcAzAudAddService - ok 17:53:53.0996 5244 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 17:53:53.0996 5244 intelide - ok 17:53:54.0126 5244 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 17:53:54.0166 5244 intelppm - ok 17:53:54.0456 5244 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 17:53:54.0456 5244 IPBusEnum - ok 17:53:54.0616 5244 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:53:54.0686 5244 IpFilterDriver - ok 17:53:54.0936 5244 iphlpsvc (477397b432a256a50ee7e4339eb9ea14) C:\Windows\System32\iphlpsvc.dll 17:53:54.0956 5244 iphlpsvc - ok 17:53:55.0096 5244 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 17:53:55.0106 5244 IPMIDRV - ok 17:53:55.0286 5244 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 17:53:55.0296 5244 IPNAT - ok 17:53:55.0416 5244 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 17:53:55.0416 5244 IRENUM - ok 17:53:55.0496 5244 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 17:53:55.0516 5244 isapnp - ok 17:53:55.0776 5244 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 17:53:55.0796 5244 iScsiPrt - ok 17:53:55.0846 5244 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 17:53:55.0846 5244 kbdclass - ok 17:53:55.0926 5244 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 17:53:55.0926 5244 kbdhid - ok 17:53:55.0986 5244 KeyIso (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\system32\lsass.exe 17:53:55.0996 5244 KeyIso - ok 17:53:56.0026 5244 KSecDD (0263364acb9c834ace52fb85c2c064ec) C:\Windows\system32\Drivers\ksecdd.sys 17:53:56.0026 5244 KSecDD - ok 17:53:56.0076 5244 KSecPkg (27391db553be2a4e2b0adeea2873b2af) C:\Windows\system32\Drivers\ksecpkg.sys 17:53:56.0076 5244 KSecPkg - ok 17:53:56.0126 5244 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 17:53:56.0146 5244 KtmRm - ok 17:53:56.0236 5244 LanmanServer (8f6bf790d3168224c16f2af68a84438c) C:\Windows\System32\srvsvc.dll 17:53:56.0246 5244 LanmanServer - ok 17:53:56.0306 5244 LanmanWorkstation (b9891f885dcf1f0513a51cb58493cb1f) C:\Windows\System32\wkssvc.dll 17:53:56.0326 5244 LanmanWorkstation - ok 17:53:56.0476 5244 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 17:53:56.0476 5244 lltdio - ok 17:53:56.0986 5244 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 17:53:57.0006 5244 lltdsvc - ok 17:53:57.0096 5244 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 17:53:57.0096 5244 lmhosts - ok 17:53:57.0406 5244 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 17:53:57.0426 5244 LSI_FC - ok 17:53:57.0686 5244 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 17:53:57.0696 5244 LSI_SAS - ok 17:53:58.0146 5244 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:53:58.0306 5244 LSI_SAS2 - ok 17:53:58.0686 5244 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:53:58.0696 5244 LSI_SCSI - ok 17:53:59.0346 5244 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 17:53:59.0356 5244 luafv - ok 17:54:00.0056 5244 Mcx2Svc (e2b0887816ed336685954e3d8fdaa51d) C:\Windows\system32\Mcx2Svc.dll 17:54:00.0306 5244 Mcx2Svc - ok 17:54:00.0596 5244 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 17:54:00.0696 5244 megasas - ok 17:54:01.0626 5244 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 17:54:01.0786 5244 MegaSR - ok 17:54:02.0378 5244 Microsoft Office Groove Audit Service (123271bd5237ab991dc5c21fdf8835eb) C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 17:54:02.0386 5244 Microsoft Office Groove Audit Service - ok 17:54:02.0707 5244 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:54:02.0889 5244 MMCSS - ok 17:54:03.0478 5244 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 17:54:03.0522 5244 Modem - ok 17:54:04.0052 5244 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 17:54:04.0056 5244 monitor - ok 17:54:04.0159 5244 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 17:54:04.0162 5244 mouclass - ok 17:54:04.0274 5244 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 17:54:04.0288 5244 mouhid - ok 17:54:04.0590 5244 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 17:54:04.0600 5244 mountmgr - ok 17:54:05.0057 5244 MozillaMaintenance (15d5398eed42c2504bb3d4fc875c15d1) C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 17:54:05.0063 5244 MozillaMaintenance - ok 17:54:05.0106 5244 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 17:54:05.0111 5244 mpio - ok 17:54:05.0296 5244 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 17:54:05.0337 5244 mpsdrv - ok 17:54:07.0622 5244 MpsSvc (5cd996cecf45cbc3e8d109c86b82d69e) C:\Windows\system32\mpssvc.dll 17:54:07.0657 5244 MpsSvc - ok 17:54:08.0222 5244 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 17:54:08.0237 5244 MRxDAV - ok 17:54:08.0744 5244 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:54:08.0838 5244 mrxsmb - ok 17:54:09.0731 5244 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:54:09.0791 5244 mrxsmb10 - ok 17:54:09.0850 5244 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:54:09.0854 5244 mrxsmb20 - ok 17:54:09.0893 5244 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 17:54:09.0902 5244 msahci - ok 17:54:10.0019 5244 MSCamSvc (b03e3f64b70f8031e65eb26da23de91a) C:\Program Files\Microsoft LifeCam\MSCamS32.exe 17:54:10.0024 5244 MSCamSvc - ok 17:54:10.0074 5244 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 17:54:10.0090 5244 msdsm - ok 17:54:10.0139 5244 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 17:54:10.0167 5244 MSDTC - ok 17:54:10.0223 5244 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 17:54:10.0227 5244 Msfs - ok 17:54:10.0268 5244 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 17:54:10.0287 5244 mshidkmdf - ok 17:54:10.0306 5244 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 17:54:10.0318 5244 msisadrv - ok 17:54:10.0384 5244 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 17:54:10.0456 5244 MSiSCSI - ok 17:54:10.0473 5244 msiserver - ok 17:54:10.0526 5244 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 17:54:10.0529 5244 MSKSSRV - ok 17:54:10.0559 5244 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 17:54:10.0562 5244 MSPCLOCK - ok 17:54:10.0587 5244 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 17:54:10.0594 5244 MSPQM - ok 17:54:10.0638 5244 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 17:54:10.0661 5244 MsRPC - ok 17:54:10.0717 5244 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 17:54:10.0718 5244 mssmbios - ok 17:54:10.0749 5244 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 17:54:10.0753 5244 MSTEE - ok 17:54:10.0782 5244 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 17:54:10.0794 5244 MTConfig - ok 17:54:10.0860 5244 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 17:54:10.0894 5244 Mup - ok 17:54:11.0001 5244 napagent (80284f1985c70c86f0b5f86da2dfe1df) C:\Windows\system32\qagentRT.dll 17:54:11.0025 5244 napagent - ok 17:54:11.0099 5244 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 17:54:11.0125 5244 NativeWifiP - ok 17:54:11.0442 5244 NBService (b498a14133bd09ad0817590ace4470ad) C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe 17:54:11.0477 5244 NBService - ok 17:54:11.0563 5244 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 17:54:11.0600 5244 NDIS - ok 17:54:11.0640 5244 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 17:54:11.0661 5244 NdisCap - ok 17:54:11.0710 5244 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 17:54:11.0714 5244 NdisTapi - ok 17:54:11.0741 5244 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 17:54:11.0745 5244 Ndisuio - ok 17:54:11.0777 5244 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 17:54:11.0780 5244 NdisWan - ok 17:54:11.0843 5244 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 17:54:11.0850 5244 NDProxy - ok 17:54:11.0875 5244 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 17:54:11.0879 5244 NetBIOS - ok 17:54:11.0914 5244 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 17:54:11.0930 5244 NetBT - ok 17:54:11.0974 5244 Netlogon (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\system32\lsass.exe 17:54:11.0977 5244 Netlogon - ok 17:54:12.0038 5244 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 17:54:12.0061 5244 Netman - ok 17:54:12.0128 5244 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 17:54:12.0151 5244 netprofm - ok 17:54:12.0245 5244 NetTcpPortSharing (fe2aa5a684b0dd9b1fae57b7817c198b) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:54:12.0250 5244 NetTcpPortSharing - ok 17:54:12.0309 5244 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 17:54:12.0313 5244 nfrd960 - ok 17:54:12.0369 5244 NlaSvc (2226496e34bd40734946a054b1cd657f) C:\Windows\System32\nlasvc.dll 17:54:12.0384 5244 NlaSvc - ok 17:54:12.0476 5244 NMIndexingService (a328a46d87bb92ce4d8a4528e9d84787) C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe 17:54:12.0499 5244 NMIndexingService - ok 17:54:12.0526 5244 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 17:54:12.0529 5244 Npfs - ok 17:54:12.0565 5244 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 17:54:12.0570 5244 nsi - ok 17:54:12.0608 5244 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 17:54:12.0611 5244 nsiproxy - ok 17:54:12.0762 5244 Ntfs (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys 17:54:12.0803 5244 Ntfs - ok 17:54:12.0958 5244 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 17:54:12.0963 5244 Null - ok 17:54:13.0018 5244 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys 17:54:13.0028 5244 nvraid - ok 17:54:13.0066 5244 nvstor (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys 17:54:13.0086 5244 nvstor - ok 17:54:13.0136 5244 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 17:54:13.0143 5244 nv_agp - ok 17:54:13.0270 5244 odserv (785f487a64950f3cb8e9f16253ba3b7b) C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 17:54:13.0287 5244 odserv - ok 17:54:13.0338 5244 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 17:54:13.0342 5244 ohci1394 - ok 17:54:13.0406 5244 ose (5a432a042dae460abe7199b758e8606c) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 17:54:13.0423 5244 ose - ok 17:54:13.0487 5244 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:54:13.0518 5244 p2pimsvc - ok 17:54:13.0582 5244 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 17:54:13.0600 5244 p2psvc - ok 17:54:13.0645 5244 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 17:54:13.0651 5244 Parport - ok 17:54:13.0724 5244 partmgr (66d3415c159741ade7038a277efff99f) C:\Windows\system32\drivers\partmgr.sys 17:54:13.0731 5244 partmgr - ok 17:54:13.0760 5244 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 17:54:13.0789 5244 Parvdm - ok 17:54:13.0833 5244 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 17:54:13.0848 5244 PcaSvc - ok 17:54:13.0901 5244 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 17:54:13.0962 5244 pci - ok 17:54:13.0983 5244 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 17:54:13.0988 5244 pciide - ok 17:54:14.0032 5244 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 17:54:14.0037 5244 pcmcia - ok 17:54:14.0063 5244 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 17:54:14.0066 5244 pcw - ok 17:54:14.0153 5244 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 17:54:14.0178 5244 PEAUTH - ok 17:54:14.0288 5244 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 17:54:14.0344 5244 PeerDistSvc - ok 17:54:14.0493 5244 pla (9c1bff7910c89a1d12e57343475840cb) C:\Windows\system32\pla.dll 17:54:14.0543 5244 pla - ok 17:54:14.0685 5244 PlugPlay (71def5ec79774c798342d0ea16e41780) C:\Windows\system32\umpnpmgr.dll 17:54:14.0711 5244 PlugPlay - ok 17:54:14.0764 5244 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 17:54:14.0771 5244 PNRPAutoReg - ok 17:54:14.0811 5244 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:54:14.0818 5244 PNRPsvc - ok 17:54:14.0880 5244 PolicyAgent (48e1b75c6dc0232fd92baae4bd344721) C:\Windows\System32\ipsecsvc.dll 17:54:14.0907 5244 PolicyAgent - ok 17:54:15.0061 5244 Power (dbff83f709a91049621c1d35dd45c92c) C:\Windows\system32\umpo.dll 17:54:15.0082 5244 Power - ok 17:54:15.0159 5244 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 17:54:15.0163 5244 PptpMiniport - ok 17:54:15.0203 5244 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 17:54:15.0208 5244 Processor - ok 17:54:15.0258 5244 ProfSvc (aea3bdbdba667aa6f678cb38907e4f5e) C:\Windows\system32\profsvc.dll 17:54:15.0319 5244 ProfSvc - ok 17:54:15.0363 5244 ProtectedStorage (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\system32\lsass.exe 17:54:15.0369 5244 ProtectedStorage - ok 17:54:15.0427 5244 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 17:54:15.0431 5244 Psched - ok 17:54:15.0524 5244 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 17:54:15.0589 5244 ql2300 - ok 17:54:15.0718 5244 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 17:54:15.0723 5244 ql40xx - ok 17:54:15.0777 5244 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 17:54:15.0794 5244 QWAVE - ok 17:54:15.0826 5244 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 17:54:15.0830 5244 QWAVEdrv - ok 17:54:15.0853 5244 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 17:54:15.0859 5244 RasAcd - ok 17:54:15.0904 5244 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:54:15.0911 5244 RasAgileVpn - ok 17:54:15.0952 5244 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 17:54:15.0959 5244 RasAuto - ok 17:54:15.0990 5244 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:54:16.0001 5244 Rasl2tp - ok 17:54:16.0069 5244 RasMan (0ce66ec736b7fc526d78f7624c7d2a94) C:\Windows\System32\rasmans.dll 17:54:16.0096 5244 RasMan - ok 17:54:16.0140 5244 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 17:54:16.0145 5244 RasPppoe - ok 17:54:16.0208 5244 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 17:54:16.0212 5244 RasSstp - ok 17:54:16.0289 5244 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 17:54:16.0304 5244 rdbss - ok 17:54:16.0326 5244 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 17:54:16.0329 5244 rdpbus - ok 17:54:16.0391 5244 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:54:16.0394 5244 RDPCDD - ok 17:54:16.0455 5244 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys 17:54:16.0460 5244 RDPDR - ok 17:54:16.0507 5244 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 17:54:16.0509 5244 RDPENCDD - ok 17:54:16.0547 5244 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 17:54:16.0550 5244 RDPREFMP - ok 17:54:16.0603 5244 RDPWD (c5b8d47a4688de9d335204ea757c2240) C:\Windows\system32\drivers\RDPWD.sys 17:54:16.0631 5244 RDPWD - ok 17:54:16.0679 5244 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 17:54:16.0706 5244 rdyboost - ok 17:54:16.0761 5244 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 17:54:16.0766 5244 RemoteAccess - ok 17:54:16.0817 5244 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 17:54:16.0842 5244 RemoteRegistry - ok 17:54:16.0876 5244 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 17:54:16.0882 5244 RpcEptMapper - ok 17:54:16.0916 5244 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 17:54:16.0937 5244 RpcLocator - ok 17:54:16.0997 5244 RpcSs (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\System32\rpcss.dll 17:54:17.0004 5244 RpcSs - ok 17:54:17.0067 5244 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 17:54:17.0078 5244 rspndr - ok 17:54:17.0145 5244 RTL8167 (5283b9a27ff230f2ff70d92451ff409a) C:\Windows\system32\DRIVERS\Rt86win7.sys 17:54:17.0168 5244 RTL8167 - ok 17:54:17.0212 5244 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys 17:54:17.0221 5244 s3cap - ok 17:54:17.0246 5244 SamSs (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\system32\lsass.exe 17:54:17.0249 5244 SamSs - ok 17:54:17.0294 5244 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 17:54:17.0299 5244 sbp2port - ok 17:54:17.0347 5244 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 17:54:17.0354 5244 SCardSvr - ok 17:54:17.0398 5244 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 17:54:17.0405 5244 scfilter - ok 17:54:17.0479 5244 Schedule (df1e5c82e4d09cf8105cc644980c4803) C:\Windows\system32\schedsvc.dll 17:54:17.0559 5244 Schedule - ok 17:54:17.0601 5244 SCPolicySvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:54:17.0603 5244 SCPolicySvc - ok 17:54:17.0651 5244 SDRSVC (5fd90abdbfaee85986802622cbb03446) C:\Windows\System32\SDRSVC.dll 17:54:17.0675 5244 SDRSVC - ok 17:54:17.0723 5244 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 17:54:17.0730 5244 secdrv - ok 17:54:17.0753 5244 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 17:54:17.0775 5244 seclogon - ok 17:54:17.0842 5244 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\system32\sens.dll 17:54:17.0890 5244 SENS - ok 17:54:17.0932 5244 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 17:54:17.0964 5244 SensrSvc - ok 17:54:17.0988 5244 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 17:54:17.0993 5244 Serenum - ok 17:54:18.0037 5244 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 17:54:18.0042 5244 Serial - ok 17:54:18.0078 5244 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 17:54:18.0084 5244 sermouse - ok 17:54:18.0169 5244 SessionEnv (8f55ce568c543d5adf45c409d16718fc) C:\Windows\system32\sessenv.dll 17:54:18.0188 5244 SessionEnv - ok 17:54:18.0219 5244 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 17:54:18.0222 5244 sffdisk - ok 17:54:18.0241 5244 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 17:54:18.0248 5244 sffp_mmc - ok 17:54:18.0278 5244 sffp_sd (a0708bbd07d245c06ff9de549ca47185) C:\Windows\system32\DRIVERS\sffp_sd.sys 17:54:18.0283 5244 sffp_sd - ok 17:54:18.0330 5244 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 17:54:18.0352 5244 sfloppy - ok 17:54:18.0498 5244 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 17:54:18.0508 5244 SharedAccess - ok 17:54:18.0563 5244 ShellHWDetection (cd2e48fa5b29ee2b3b5858056d246ef2) C:\Windows\System32\shsvcs.dll 17:54:18.0588 5244 ShellHWDetection - ok 17:54:18.0631 5244 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 17:54:18.0641 5244 sisagp - ok 17:54:18.0678 5244 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:54:18.0688 5244 SiSRaid2 - ok 17:54:18.0728 5244 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 17:54:18.0732 5244 SiSRaid4 - ok 17:54:18.0857 5244 SkypeUpdate (579ba0a911ff5ea70cb604cd3b744b0a) C:\Program Files\Skype\Updater\Updater.exe 17:54:18.0877 5244 SkypeUpdate - ok 17:54:18.0918 5244 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 17:54:18.0922 5244 Smb - ok 17:54:18.0981 5244 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 17:54:18.0986 5244 SNMPTRAP - ok 17:54:19.0027 5244 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 17:54:19.0039 5244 spldr - ok 17:54:19.0091 5244 Spooler (d1bb750eb51694de183e08b9c33be5b2) C:\Windows\System32\spoolsv.exe 17:54:19.0114 5244 Spooler - ok 17:54:19.0317 5244 sppsvc (4c287f9069fedbd791178876ee9de536) C:\Windows\system32\sppsvc.exe 17:54:19.0408 5244 sppsvc - ok 17:54:19.0551 5244 sppuinotify (d8e3e19eebdab49dd4a8d3062ead4ec7) C:\Windows\system32\sppuinotify.dll 17:54:19.0571 5244 sppuinotify - ok 17:54:19.0662 5244 sptd (f42efefb765235f24b24e1d2b6f99f46) C:\Windows\System32\Drivers\sptd.sys 17:54:19.0666 5244 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: f42efefb765235f24b24e1d2b6f99f46 17:54:19.0669 5244 sptd ( LockedFile.Multi.Generic ) - warning 17:54:19.0669 5244 sptd - detected LockedFile.Multi.Generic (1) 17:54:19.0748 5244 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys 17:54:19.0758 5244 srv - ok 17:54:19.0837 5244 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys 17:54:19.0844 5244 srv2 - ok 17:54:19.0924 5244 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys 17:54:19.0934 5244 srvnet - ok 17:54:19.0984 5244 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 17:54:20.0007 5244 SSDPSRV - ok 17:54:20.0039 5244 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 17:54:20.0048 5244 SstpSvc - ok 17:54:20.0174 5244 StarWindServiceAE (e5c796b621f6fba8616511063d7f0ffe) C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe 17:54:20.0198 5244 StarWindServiceAE - ok 17:54:20.0251 5244 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 17:54:20.0282 5244 stexstor - ok 17:54:20.0337 5244 StiSvc (a22825e7bb7018e8af3e229a5af17221) C:\Windows\System32\wiaservc.dll 17:54:20.0369 5244 StiSvc - ok 17:54:20.0443 5244 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys 17:54:20.0471 5244 storflt - ok 17:54:20.0604 5244 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys 17:54:20.0610 5244 storvsc - ok 17:54:20.0665 5244 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 17:54:20.0669 5244 swenum - ok 17:54:20.0719 5244 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 17:54:20.0748 5244 swprv - ok 17:54:20.0919 5244 SysMain (04105c8da62353589c29bdaeb8d88bd8) C:\Windows\system32\sysmain.dll 17:54:20.0961 5244 SysMain - ok 17:54:21.0001 5244 TabletInputService (fcfb6c552fbc0da299799cbd50ad9fd4) C:\Windows\System32\TabSvc.dll 17:54:21.0016 5244 TabletInputService - ok 17:54:21.0054 5244 TapiSrv (2f46b0c70a4adc8c90cf825da3b4feaf) C:\Windows\System32\tapisrv.dll 17:54:21.0079 5244 TapiSrv - ok 17:54:21.0110 5244 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 17:54:21.0118 5244 TBS - ok 17:54:21.0296 5244 Tcpip (55e9965552741f3850cb22cbba9671ed) C:\Windows\system32\drivers\tcpip.sys 17:54:21.0351 5244 Tcpip - ok 17:54:21.0597 5244 TCPIP6 (55e9965552741f3850cb22cbba9671ed) C:\Windows\system32\DRIVERS\tcpip.sys 17:54:21.0610 5244 TCPIP6 - ok 17:54:21.0737 5244 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 17:54:21.0743 5244 tcpipreg - ok 17:54:21.0801 5244 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 17:54:21.0804 5244 TDPIPE - ok 17:54:21.0868 5244 TDTCP (7156308896d34ea75a582f9a09e50c17) C:\Windows\system32\drivers\tdtcp.sys 17:54:21.0871 5244 TDTCP - ok 17:54:21.0902 5244 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 17:54:21.0906 5244 tdx - ok 17:54:21.0930 5244 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 17:54:21.0933 5244 TermDD - ok 17:54:22.0007 5244 TermService (a01e50a04d7b1960b33e92b9080e6a94) C:\Windows\System32\termsrv.dll 17:54:22.0048 5244 TermService - ok 17:54:22.0107 5244 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 17:54:22.0122 5244 Themes - ok 17:54:22.0152 5244 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:54:22.0156 5244 THREADORDER - ok 17:54:22.0190 5244 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 17:54:22.0210 5244 TrkWks - ok 17:54:22.0294 5244 TrustedInstaller (41a4c781d2286208d397d72099304133) C:\Windows\servicing\TrustedInstaller.exe 17:54:22.0310 5244 TrustedInstaller - ok 17:54:22.0343 5244 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:54:22.0348 5244 tssecsrv - ok 17:54:22.0431 5244 TuneUp.Defrag (4196d7bc21786883201747dcc0dc84a0) C:\Windows\System32\TuneUpDefragService.exe 17:54:22.0464 5244 TuneUp.Defrag - ok 17:54:22.0567 5244 TuneUp.ProgramStatisticsSvc (02e5f68a55cd413c5bfb9f2df677dd01) C:\Windows\System32\TUProgSt.exe 17:54:22.0591 5244 TuneUp.ProgramStatisticsSvc - ok 17:54:22.0654 5244 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 17:54:22.0659 5244 tunnel - ok 17:54:22.0686 5244 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 17:54:22.0691 5244 uagp35 - ok 17:54:22.0731 5244 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 17:54:22.0747 5244 udfs - ok 17:54:22.0800 5244 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 17:54:22.0806 5244 UI0Detect - ok 17:54:22.0996 5244 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 17:54:22.0999 5244 uliagpkx - ok 17:54:23.0056 5244 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 17:54:23.0066 5244 umbus - ok 17:54:23.0091 5244 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 17:54:23.0096 5244 UmPass - ok 17:54:23.0156 5244 UmRdpService (8ecaca5454844f66386f7be4ae0d7cd1) C:\Windows\System32\umrdp.dll 17:54:23.0175 5244 UmRdpService - ok 17:54:23.0232 5244 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 17:54:23.0259 5244 upnphost - ok 17:54:23.0333 5244 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 17:54:23.0338 5244 usbaudio - ok 17:54:23.0383 5244 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\Windows\system32\DRIVERS\usbccgp.sys 17:54:23.0388 5244 usbccgp - ok 17:54:23.0581 5244 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 17:54:23.0610 5244 usbcir - ok 17:54:23.0657 5244 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\Windows\system32\DRIVERS\usbehci.sys 17:54:23.0663 5244 usbehci - ok 17:54:23.0729 5244 usbhub (bdcd7156ec37448f08633fd899823620) C:\Windows\system32\DRIVERS\usbhub.sys 17:54:23.0749 5244 usbhub - ok 17:54:23.0783 5244 usbohci (eb2d819a639015253c871cda09d91d58) C:\Windows\system32\DRIVERS\usbohci.sys 17:54:23.0788 5244 usbohci - ok 17:54:23.0839 5244 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 17:54:23.0846 5244 usbprint - ok 17:54:23.0886 5244 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:54:23.0890 5244 USBSTOR - ok 17:54:23.0917 5244 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\Windows\system32\drivers\usbuhci.sys 17:54:23.0920 5244 usbuhci - ok 17:54:23.0981 5244 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\Windows\system32\Drivers\usbvideo.sys 17:54:23.0987 5244 usbvideo - ok 17:54:24.0019 5244 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 17:54:24.0024 5244 UxSms - ok 17:54:24.0103 5244 UxTuneUp (4360d5653e885479fed75c378e9faab3) C:\Windows\System32\uxtuneup.dll 17:54:24.0114 5244 UxTuneUp - ok 17:54:24.0158 5244 VaultSvc (c2243ff9e9aad0c30e8b1a0914da15b6) C:\Windows\system32\lsass.exe 17:54:24.0161 5244 VaultSvc - ok 17:54:24.0210 5244 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 17:54:24.0213 5244 vdrvroot - ok 17:54:24.0287 5244 vds (8c4e7c49d3641bc9e299e466a7f8867d) C:\Windows\System32\vds.exe 17:54:24.0314 5244 vds - ok 17:54:24.0346 5244 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 17:54:24.0352 5244 vga - ok 17:54:24.0386 5244 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 17:54:24.0389 5244 VgaSave - ok 17:54:24.0429 5244 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 17:54:24.0436 5244 vhdmp - ok 17:54:24.0490 5244 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 17:54:24.0504 5244 viaagp - ok 17:54:24.0530 5244 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 17:54:24.0536 5244 ViaC7 - ok 17:54:24.0557 5244 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 17:54:24.0561 5244 viaide - ok 17:54:24.0631 5244 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys 17:54:24.0637 5244 vmbus - ok 17:54:24.0670 5244 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys 17:54:24.0674 5244 VMBusHID - ok 17:54:24.0707 5244 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 17:54:24.0711 5244 volmgr - ok 17:54:24.0759 5244 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 17:54:24.0766 5244 volmgrx - ok 17:54:24.0817 5244 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 17:54:24.0845 5244 volsnap - ok 17:54:24.0890 5244 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 17:54:24.0896 5244 vsmraid - ok 17:54:24.0992 5244 VSS (7ea2bcd94d9cfaf4c556f5cc94532a6c) C:\Windows\system32\vssvc.exe 17:54:25.0043 5244 VSS - ok 17:54:25.0088 5244 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 17:54:25.0093 5244 vwifibus - ok 17:54:25.0131 5244 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 17:54:25.0134 5244 vwififlt - ok 17:54:25.0182 5244 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 17:54:25.0210 5244 W32Time - ok 17:54:25.0273 5244 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 17:54:25.0286 5244 WacomPen - ok 17:54:25.0368 5244 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:54:25.0371 5244 WANARP - ok 17:54:25.0388 5244 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:54:25.0390 5244 Wanarpv6 - ok 17:54:25.0512 5244 WatAdminSvc (353a04c273ec58475d8633e75ccd5604) C:\Windows\system32\Wat\WatAdminSvc.exe 17:54:25.0593 5244 WatAdminSvc - ok 17:54:25.0926 5244 wbengine (7790b77fe1e5ee47dcc66247095bb4c9) C:\Windows\system32\wbengine.exe 17:54:25.0982 5244 wbengine - ok 17:54:26.0022 5244 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 17:54:26.0041 5244 WbioSrvc - ok 17:54:26.0090 5244 wcncsvc (6d9b75275c3e3a5f51aef81affadb2b6) C:\Windows\System32\wcncsvc.dll 17:54:26.0116 5244 wcncsvc - ok 17:54:26.0159 5244 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 17:54:26.0165 5244 WcsPlugInService - ok 17:54:26.0232 5244 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 17:54:26.0236 5244 Wd - ok 17:54:26.0283 5244 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 17:54:26.0305 5244 Wdf01000 - ok 17:54:26.0335 5244 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:54:26.0399 5244 WdiServiceHost - ok 17:54:26.0430 5244 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:54:26.0434 5244 WdiSystemHost - ok 17:54:26.0489 5244 WebClient (bb5ec38f8d4600119b4720bc5d4211f1) C:\Windows\System32\webclnt.dll 17:54:26.0505 5244 WebClient - ok 17:54:26.0555 5244 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 17:54:26.0573 5244 Wecsvc - ok 17:54:26.0605 5244 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 17:54:26.0613 5244 wercplsupport - ok 17:54:26.0662 5244 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 17:54:26.0669 5244 WerSvc - ok 17:54:26.0771 5244 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 17:54:26.0773 5244 WfpLwf - ok 17:54:26.0852 5244 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 17:54:26.0860 5244 WIMMount - ok 17:54:27.0366 5244 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 17:54:27.0410 5244 WinDefend - ok 17:54:27.0434 5244 WinHttpAutoProxySvc - ok 17:54:27.0515 5244 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 17:54:27.0521 5244 Winmgmt - ok 17:54:27.0628 5244 WinRM (c4f5d3901d1b41d602ddc196e0b95b51) C:\Windows\system32\WsmSvc.dll 17:54:27.0689 5244 WinRM - ok 17:54:28.0114 5244 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 17:54:28.0118 5244 WinUsb - ok 17:54:28.0527 5244 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 17:54:28.0577 5244 Wlansvc - ok 17:54:29.0212 5244 wlidsvc (fb01d4ae207b9efdbabfc55dc95c7e31) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 17:54:29.0280 5244 wlidsvc - ok 17:54:30.0562 5244 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 17:54:30.0564 5244 WmiAcpi - ok 17:54:31.0014 5244 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 17:54:31.0026 5244 wmiApSrv - ok 17:54:31.0471 5244 WMPNetworkSvc (77fbd400984cf72ba0fc4b3489d65f74) C:\Program Files\Windows Media Player\wmpnetwk.exe 17:54:31.0506 5244 WMPNetworkSvc - ok 17:54:32.0261 5244 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 17:54:32.0267 5244 WPCSvc - ok 17:54:32.0302 5244 WPDBusEnum (b7f658a2ebc07129538ad9ab35212637) C:\Windows\system32\wpdbusenum.dll 17:54:32.0309 5244 WPDBusEnum - ok 17:54:32.0493 5244 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 17:54:32.0506 5244 ws2ifsl - ok 17:54:32.0569 5244 wscsvc (a661a76333057b383a06e65f0073222f) C:\Windows\system32\wscsvc.dll 17:54:32.0577 5244 wscsvc - ok 17:54:32.0602 5244 WSearch - ok 17:54:34.0195 5244 wuauserv (a33408cc036f9c08142b11be5e93f0a1) C:\Windows\system32\wuaueng.dll 17:54:34.0245 5244 wuauserv - ok 17:54:35.0017 5244 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 17:54:35.0021 5244 WudfPf - ok 17:54:35.0064 5244 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:54:35.0070 5244 WUDFRd - ok 17:54:35.0240 5244 wudfsvc (ddee3682fe97037c45f4d7ab467cb8b6) C:\Windows\System32\WUDFSvc.dll 17:54:35.0246 5244 wudfsvc - ok 17:54:35.0402 5244 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 17:54:35.0430 5244 WwanSvc - ok 17:54:35.0630 5244 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:54:35.0714 5244 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 17:54:35.0714 5244 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 17:54:35.0752 5244 Boot (0x1200) (b682a74e39767606f3f76430de435f48) \Device\Harddisk0\DR0\Partition0 17:54:35.0756 5244 \Device\Harddisk0\DR0\Partition0 - ok 17:54:35.0775 5244 Boot (0x1200) (1eee5bf50dd6ce6b55c4c1ca34038752) \Device\Harddisk0\DR0\Partition1 17:54:35.0780 5244 \Device\Harddisk0\DR0\Partition1 - ok 17:54:35.0817 5244 Boot (0x1200) (e296dcdcb3c8b807ce3de57f7467b928) \Device\Harddisk0\DR0\Partition2 17:54:35.0824 5244 \Device\Harddisk0\DR0\Partition2 - ok 17:54:35.0830 5244 ============================================================ 17:54:35.0830 5244 Scan finished 17:54:35.0830 5244 ============================================================ 17:54:35.0856 2236 Detected object count: 2 17:54:35.0856 2236 Actual detected object count: 2 17:55:32.0252 2236 sptd ( LockedFile.Multi.Generic ) - skipped by user 17:55:32.0252 2236 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 17:55:32.0920 2236 \Device\Harddisk0\DR0\# - copied to quarantine 17:55:32.0921 2236 \Device\Harddisk0\DR0 - copied to quarantine 17:55:33.0027 2236 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 17:55:33.0069 2236 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 17:55:33.0078 2236 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 17:55:33.0113 2236 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 17:55:33.0134 2236 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 17:55:33.0137 2236 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 17:55:33.0139 2236 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 17:55:33.0142 2236 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 17:55:33.0147 2236 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 17:55:33.0153 2236 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 17:55:33.0156 2236 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 17:55:33.0158 2236 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 17:55:33.0211 2236 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 17:55:33.0255 2236 \Device\Harddisk0\DR0 - ok 17:55:33.0407 2236 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 17:55:36.0239 3788 Deinitialize success