20:56:31.0530 1368 TDSS rootkit removing tool 2.8.6.0 Aug 13 2012 17:24:05 20:56:31.0920 1368 ============================================================ 20:56:31.0920 1368 Current date / time: 2012/08/16 20:56:31.0920 20:56:31.0920 1368 SystemInfo: 20:56:31.0920 1368 20:56:31.0920 1368 OS Version: 6.1.7601 ServicePack: 1.0 20:56:31.0920 1368 Product type: Workstation 20:56:31.0920 1368 ComputerName: USER-PC 20:56:31.0920 1368 UserName: User 20:56:31.0920 1368 Windows directory: C:\Windows 20:56:31.0920 1368 System windows directory: C:\Windows 20:56:31.0920 1368 Processor architecture: Intel x86 20:56:31.0920 1368 Number of processors: 2 20:56:31.0920 1368 Page size: 0x1000 20:56:31.0920 1368 Boot type: Safe boot with network 20:56:31.0920 1368 ============================================================ 20:56:33.0807 1368 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000050 20:56:33.0807 1368 ============================================================ 20:56:33.0807 1368 \Device\Harddisk0\DR0: 20:56:33.0807 1368 MBR partitions: 20:56:33.0807 1368 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000 20:56:33.0807 1368 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x129E6800 20:56:33.0807 1368 ============================================================ 20:56:33.0839 1368 C: <-> \Device\Harddisk0\DR0\Partition2 20:56:33.0854 1368 E: <-> \Device\Harddisk0\DR0\Partition1 20:56:33.0854 1368 ============================================================ 20:56:33.0854 1368 Initialize success 20:56:33.0854 1368 ============================================================ 20:57:02.0699 1848 ============================================================ 20:57:02.0699 1848 Scan started 20:57:02.0699 1848 Mode: Manual; 20:57:02.0699 1848 ============================================================ 20:57:03.0635 1848 ================ Scan services ============================= 20:57:03.0838 1848 [ 1b133875b8aa8ac48969bd3458afe9f5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 20:57:03.0838 1848 1394ohci - ok 20:57:04.0072 1848 [ adc420616c501b45d26c0fd3ef1e54e4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 20:57:04.0072 1848 ACDaemon - ok 20:57:04.0134 1848 [ cea80c80bed809aa0da6febc04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys 20:57:04.0134 1848 ACPI - ok 20:57:04.0196 1848 [ 1efbc664abff416d1d07db115dcb264f ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 20:57:04.0196 1848 AcpiPmi - ok 20:57:04.0306 1848 [ f19c98ad81d2c0e1bbfd8153d2c80ee8 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 20:57:04.0321 1848 AdobeFlashPlayerUpdateSvc - ok 20:57:04.0384 1848 [ 21e785ebd7dc90a06391141aac7892fb ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 20:57:04.0399 1848 adp94xx - ok 20:57:04.0415 1848 [ 0c676bc278d5b59ff5abd57bbe9123f2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 20:57:04.0430 1848 adpahci - ok 20:57:04.0462 1848 [ 7c7b5ee4b7b822ec85321fe23a27db33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 20:57:04.0462 1848 adpu320 - ok 20:57:04.0524 1848 [ 8b5eefeec1e6d1a72a06c526628ad161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:57:04.0524 1848 AeLookupSvc - ok 20:57:04.0602 1848 [ 9ebbba55060f786f0fcaa3893bfa2806 ] AFD C:\Windows\system32\drivers\afd.sys 20:57:04.0602 1848 AFD - ok 20:57:04.0633 1848 [ 507812c3054c21cef746b6ee3d04dd6e ] agp440 C:\Windows\system32\drivers\agp440.sys 20:57:04.0649 1848 agp440 - ok 20:57:04.0711 1848 [ 8b30250d573a8f6b4bd23195160d8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys 20:57:04.0711 1848 aic78xx - ok 20:57:04.0758 1848 [ 18a54e132947cd98fea9accc57f98f13 ] ALG C:\Windows\System32\alg.exe 20:57:04.0758 1848 ALG - ok 20:57:04.0836 1848 [ 0d40bcf52ea90fc7df2aeab6503dea44 ] aliide C:\Windows\system32\drivers\aliide.sys 20:57:04.0836 1848 aliide - ok 20:57:04.0836 1848 [ 3c6600a0696e90a463771c7422e23ab5 ] amdagp C:\Windows\system32\drivers\amdagp.sys 20:57:04.0836 1848 amdagp - ok 20:57:04.0852 1848 [ cd5914170297126b6266860198d1d4f0 ] amdide C:\Windows\system32\drivers\amdide.sys 20:57:04.0852 1848 amdide - ok 20:57:04.0914 1848 [ 00dda200d71bac534bf56a9db5dfd666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 20:57:04.0914 1848 AmdK8 - ok 20:57:04.0945 1848 [ 3cbf30f5370fda40dd3e87df38ea53b6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 20:57:04.0945 1848 AmdPPM - ok 20:57:04.0992 1848 [ d320bf87125326f996d4904fe24300fc ] amdsata C:\Windows\system32\drivers\amdsata.sys 20:57:04.0992 1848 amdsata - ok 20:57:05.0023 1848 [ ea43af0c423ff267355f74e7a53bdaba ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 20:57:05.0023 1848 amdsbs - ok 20:57:05.0054 1848 [ 46387fb17b086d16dea267d5be23a2f2 ] amdxata C:\Windows\system32\drivers\amdxata.sys 20:57:05.0054 1848 amdxata - ok 20:57:05.0132 1848 [ aea177f783e20150ace5383ee368da19 ] AppID C:\Windows\system32\drivers\appid.sys 20:57:05.0132 1848 AppID - ok 20:57:05.0195 1848 [ 62a9c86cb6085e20db4823e4e97826f5 ] AppIDSvc C:\Windows\System32\appidsvc.dll 20:57:05.0210 1848 AppIDSvc - ok 20:57:05.0242 1848 [ fb1959012294d6ad43e5304df65e3c26 ] Appinfo C:\Windows\System32\appinfo.dll 20:57:05.0242 1848 Appinfo - ok 20:57:05.0320 1848 [ 7ef47644b74ebe721cc32211d3c35e76 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 20:57:05.0335 1848 Apple Mobile Device - ok 20:57:05.0382 1848 [ 2932004f49677bd84dbc72edb754ffb3 ] arc C:\Windows\system32\DRIVERS\arc.sys 20:57:05.0382 1848 arc - ok 20:57:05.0398 1848 [ 5d6f36c46fd283ae1b57bd2e9feb0bc7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 20:57:05.0398 1848 arcsas - ok 20:57:05.0476 1848 [ dfd07f0a36bd4f7e7ad2bc5548213694 ] ArcSoftKsUFilter C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys 20:57:05.0476 1848 ArcSoftKsUFilter - ok 20:57:05.0522 1848 [ add2ade1c2b285ab8378d2daaf991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:57:05.0522 1848 AsyncMac - ok 20:57:05.0569 1848 [ 338c86357871c167a96ab976519bf59e ] atapi C:\Windows\system32\drivers\atapi.sys 20:57:05.0569 1848 atapi - ok 20:57:05.0616 1848 [ 2039e24fe00639a9123dcd6f22d42d74 ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe 20:57:05.0632 1848 Ati External Event Utility - ok 20:57:05.0803 1848 [ d2e9acb68fa61c911cc21e07f87705bf ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys 20:57:05.0959 1848 atikmdag - ok 20:57:06.0022 1848 [ ce3b4e731638d2ef62fcb419be0d39f0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:57:06.0037 1848 AudioEndpointBuilder - ok 20:57:06.0053 1848 [ ce3b4e731638d2ef62fcb419be0d39f0 ] Audiosrv C:\Windows\System32\Audiosrv.dll 20:57:06.0053 1848 Audiosrv - ok 20:57:06.0115 1848 [ 6e30d02aac9cac84f421622e3a2f6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll 20:57:06.0115 1848 AxInstSV - ok 20:57:06.0209 1848 [ 1a231abec60fd316ec54c66715543cec ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys 20:57:06.0209 1848 b06bdrv - ok 20:57:06.0256 1848 [ bd8869eb9cde6bbe4508d869929869ee ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 20:57:06.0271 1848 b57nd60x - ok 20:57:06.0334 1848 [ 0d1ea7509f394d8b705b239ee71f5118 ] BBSvc C:\Program Files\Microsoft\BingBar\BBSvc.EXE 20:57:06.0349 1848 BBSvc - ok 20:57:06.0396 1848 [ ee1e9c3bb8228ae423dd38db69128e71 ] BDESVC C:\Windows\System32\bdesvc.dll 20:57:06.0396 1848 BDESVC - ok 20:57:06.0443 1848 [ 505506526a9d467307b3c393dedaf858 ] Beep C:\Windows\system32\drivers\Beep.sys 20:57:06.0443 1848 Beep - ok 20:57:06.0521 1848 [ 1e2bac209d184bb851e1a187d8a29136 ] BFE C:\Windows\System32\bfe.dll 20:57:06.0521 1848 BFE - ok 20:57:06.0568 1848 [ e585445d5021971fae10393f0f1c3961 ] BITS C:\Windows\System32\qmgr.dll 20:57:06.0630 1848 BITS - ok 20:57:06.0646 1848 [ 2287078ed48fcfc477b05b20cf38f36f ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 20:57:06.0646 1848 blbdrive - ok 20:57:06.0755 1848 [ db5bea73edaf19ac68b2c0fad0f92b1a ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 20:57:06.0755 1848 Bonjour Service - ok 20:57:06.0817 1848 [ 8f2da3028d5fcbd1a060a3de64cd6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:57:06.0817 1848 bowser - ok 20:57:06.0880 1848 [ 9f9acc7f7ccde8a15c282d3f88b43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 20:57:06.0880 1848 BrFiltLo - ok 20:57:06.0895 1848 [ 56801ad62213a41f6497f96dee83755a ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 20:57:06.0895 1848 BrFiltUp - ok 20:57:06.0926 1848 [ 6e11f33d14d020f58d5e02e4d67dfa19 ] Browser C:\Windows\System32\browser.dll 20:57:06.0926 1848 Browser - ok 20:57:07.0004 1848 [ 845b8ce732e67f3b4133164868c666ea ] Brserid C:\Windows\System32\Drivers\Brserid.sys 20:57:07.0004 1848 Brserid - ok 20:57:07.0020 1848 [ 203f0b1e73adadbbb7b7b1fabd901f6b ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 20:57:07.0020 1848 BrSerWdm - ok 20:57:07.0020 1848 [ bd456606156ba17e60a04e18016ae54b ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 20:57:07.0036 1848 BrUsbMdm - ok 20:57:07.0036 1848 [ af72ed54503f717a43268b3cc5faec2e ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 20:57:07.0036 1848 BrUsbSer - ok 20:57:07.0051 1848 [ ed3df7c56ce0084eb2034432fc56565a ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 20:57:07.0051 1848 BTHMODEM - ok 20:57:07.0098 1848 [ 1df19c96eef6c29d1c3e1a8678e07190 ] bthserv C:\Windows\system32\bthserv.dll 20:57:07.0114 1848 bthserv - ok 20:57:07.0160 1848 [ 77ea11b065e0a8ab902d78145ca51e10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:57:07.0160 1848 cdfs - ok 20:57:07.0254 1848 [ be167ed0fdb9c1fa1133953c18d5a6c9 ] cdrom C:\Windows\system32\drivers\cdrom.sys 20:57:07.0254 1848 cdrom - ok 20:57:07.0316 1848 [ 319c6b309773d063541d01df8ac6f55f ] CertPropSvc C:\Windows\System32\certprop.dll 20:57:07.0316 1848 CertPropSvc - ok 20:57:07.0348 1848 [ 3fe3fe94a34df6fb06e6418d0f6a0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 20:57:07.0348 1848 circlass - ok 20:57:07.0379 1848 [ 635181e0e9bbf16871bf5380d71db02d ] CLFS C:\Windows\system32\CLFS.sys 20:57:07.0394 1848 CLFS - ok 20:57:07.0535 1848 [ d88040f816fda31c3b466f0fa0918f29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:57:07.0550 1848 clr_optimization_v2.0.50727_32 - ok 20:57:07.0644 1848 [ c5a75eb48e2344abdc162bda79e16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:57:07.0706 1848 clr_optimization_v4.0.30319_32 - ok 20:57:07.0722 1848 [ dea805815e587dad1dd2c502220b5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:57:07.0722 1848 CmBatt - ok 20:57:07.0753 1848 [ c537b1db64d495b9b4717b4d6d9edbf2 ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:57:07.0753 1848 cmdide - ok 20:57:07.0816 1848 [ 247b4ce2dab1160cd422d532d5241e1f ] CNG C:\Windows\system32\Drivers\cng.sys 20:57:07.0816 1848 CNG - ok 20:57:07.0878 1848 [ a6023d3823c37043986713f118a89bee ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:57:07.0878 1848 Compbatt - ok 20:57:07.0940 1848 [ cbe8c58a8579cfe5fccf809e6f114e89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 20:57:07.0940 1848 CompositeBus - ok 20:57:08.0018 1848 COMSysApp - ok 20:57:08.0034 1848 [ 2c4ebcfc84a9b44f209dff6c6e6c61d1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 20:57:08.0034 1848 crcdisk - ok 20:57:08.0096 1848 [ 06e771aa596b8761107ab57e99f128d7 ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:57:08.0096 1848 CryptSvc - ok 20:57:08.0143 1848 [ 7660f01d3b38aca1747e397d21d790af ] DcomLaunch C:\Windows\system32\rpcss.dll 20:57:08.0159 1848 DcomLaunch - ok 20:57:08.0190 1848 [ 8d6e10a2d9a5eed59562d9b82cf804e1 ] defragsvc C:\Windows\System32\defragsvc.dll 20:57:08.0206 1848 defragsvc - ok 20:57:08.0268 1848 [ f024449c97ec1e464aaffda18593db88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:57:08.0268 1848 DfsC - ok 20:57:08.0330 1848 [ e9e01eb683c132f7fa27cd607b8a2b63 ] Dhcp C:\Windows\system32\dhcpcore.dll 20:57:08.0346 1848 Dhcp - ok 20:57:08.0393 1848 [ 1a050b0274bfb3890703d490f330c0da ] discache C:\Windows\system32\drivers\discache.sys 20:57:08.0393 1848 discache - ok 20:57:08.0440 1848 [ 565003f326f99802e68ca78f2a68e9ff ] Disk C:\Windows\system32\DRIVERS\disk.sys 20:57:08.0440 1848 Disk - ok 20:57:08.0471 1848 [ 33ef4861f19a0736b11314aad9ae28d0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:57:08.0471 1848 Dnscache - ok 20:57:08.0518 1848 [ 366ba8fb4b7bb7435e3b9eacb3843f67 ] dot3svc C:\Windows\System32\dot3svc.dll 20:57:08.0518 1848 dot3svc - ok 20:57:08.0549 1848 [ 8ec04ca86f1d68da9e11952eb85973d6 ] DPS C:\Windows\system32\dps.dll 20:57:08.0564 1848 DPS - ok 20:57:08.0642 1848 [ b918e7c5f9bf77202f89e1a9539f2eb4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:57:08.0642 1848 drmkaud - ok 20:57:08.0689 1848 [ 23f5d28378a160352ba8f817bd8c71cb ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:57:08.0705 1848 DXGKrnl - ok 20:57:08.0783 1848 [ cf0a6015f437161698c5b2a0a12cf052 ] e1express C:\Windows\system32\DRIVERS\e1e6032.sys 20:57:08.0783 1848 e1express - ok 20:57:08.0830 1848 EagleXNt - ok 20:57:08.0876 1848 [ 8600142fa91c1b96367d3300ad0f3f3a ] EapHost C:\Windows\System32\eapsvc.dll 20:57:08.0876 1848 EapHost - ok 20:57:09.0001 1848 [ 024e1b5cac09731e4d868e64dbfb4ab0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys 20:57:09.0048 1848 ebdrv - ok 20:57:09.0095 1848 [ 81951f51e318aecc2d68559e47485cc4 ] EFS C:\Windows\System32\lsass.exe 20:57:09.0095 1848 EFS - ok 20:57:09.0220 1848 [ a8c362018efc87beb013ee28f29c0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:57:09.0220 1848 ehRecvr - ok 20:57:09.0251 1848 [ d389bff34f80caede417bf9d1507996a ] ehSched C:\Windows\ehome\ehsched.exe 20:57:09.0251 1848 ehSched - ok 20:57:09.0329 1848 [ 0ed67910c8c326796faa00b2bf6d9d3c ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 20:57:09.0329 1848 elxstor - ok 20:57:09.0391 1848 [ abdd5ad016affd34ad40e944ce94bf59 ] EpsonBidirectionalService C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe 20:57:09.0422 1848 EpsonBidirectionalService - ok 20:57:09.0516 1848 [ b78436ca173ff723a1eace5cd4900375 ] EpsonCustomerParticipation C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe 20:57:09.0547 1848 EpsonCustomerParticipation - ok 20:57:09.0594 1848 [ 8fc3208352dd3912c94367a206ab3f11 ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:57:09.0594 1848 ErrDev - ok 20:57:09.0688 1848 [ f6916efc29d9953d5d0df06882ae8e16 ] EventSystem C:\Windows\system32\es.dll 20:57:09.0688 1848 EventSystem - ok 20:57:09.0703 1848 [ 2dc9108d74081149cc8b651d3a26207f ] exfat C:\Windows\system32\drivers\exfat.sys 20:57:09.0719 1848 exfat - ok 20:57:09.0750 1848 [ 7e0ab74553476622fb6ae36f73d97d35 ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:57:09.0750 1848 fastfat - ok 20:57:09.0828 1848 [ 967ea5b213e9984cbe270205df37755b ] Fax C:\Windows\system32\fxssvc.exe 20:57:09.0844 1848 Fax - ok 20:57:09.0844 1848 [ e817a017f82df2a1f8cfdbda29388b29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 20:57:09.0844 1848 fdc - ok 20:57:09.0890 1848 [ f3222c893bd2f5821a0179e5c71e88fb ] fdPHost C:\Windows\system32\fdPHost.dll 20:57:09.0890 1848 fdPHost - ok 20:57:09.0922 1848 [ 7dbe8cbfe79efbdeb98c9fb08d3a9a5b ] FDResPub C:\Windows\system32\fdrespub.dll 20:57:09.0922 1848 FDResPub - ok 20:57:09.0953 1848 [ 6cf00369c97f3cf563be99be983d13d8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:57:09.0953 1848 FileInfo - ok 20:57:09.0984 1848 [ 42c51dc94c91da21cb9196eb64c45db9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:57:09.0984 1848 Filetrace - ok 20:57:10.0000 1848 [ 87907aa70cb3c56600f1c2fb8841579b ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 20:57:10.0000 1848 flpydisk - ok 20:57:10.0078 1848 [ 7520ec808e0c35e0ee6f841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:57:10.0078 1848 FltMgr - ok 20:57:10.0124 1848 [ b3a5ec6b6b6673db7e87c2bcdbddc074 ] FontCache C:\Windows\system32\FntCache.dll 20:57:10.0140 1848 FontCache - ok 20:57:10.0234 1848 [ e56f39f6b7fda0ac77a79b0fd3de1a2f ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 20:57:10.0234 1848 FontCache3.0.0.0 - ok 20:57:10.0249 1848 [ 1a16b57943853e598cff37fe2b8cbf1d ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 20:57:10.0249 1848 FsDepends - ok 20:57:10.0312 1848 [ b0082808a6856a252f7cdd939892ce50 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys 20:57:10.0312 1848 fssfltr - ok 20:57:10.0452 1848 [ 28ddeeec44e988657b732cf404d504cb ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe 20:57:10.0483 1848 fsssvc - ok 20:57:10.0514 1848 [ 7dae5ebcc80e45d3253f4923dc424d05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:57:10.0514 1848 Fs_Rec - ok 20:57:10.0561 1848 [ 8a73e79089b282100b9393b644cb853b ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 20:57:10.0561 1848 fvevol - ok 20:57:10.0624 1848 [ 65ee0c7a58b65e74ae05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 20:57:10.0624 1848 gagp30kx - ok 20:57:10.0655 1848 [ 8182ff89c65e4d38b2de4bb0fb18564e ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 20:57:10.0655 1848 GEARAspiWDM - ok 20:57:10.0686 1848 [ e897eaf5ed6ba41e081060c9b447a673 ] gpsvc C:\Windows\System32\gpsvc.dll 20:57:10.0702 1848 gpsvc - ok 20:57:10.0748 1848 [ 833051c6c6c42117191935f734cfbd97 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys 20:57:10.0748 1848 hamachi - ok 20:57:10.0951 1848 [ f31d7f8a7699575dbb3b3a3ab4aa6216 ] Hamachi2Svc C:\Program Files\LogMeIn Hamachi\hamachi-2.exe 20:57:10.0982 1848 Hamachi2Svc - ok 20:57:11.0014 1848 [ c44e3c2bab6837db337ddee7544736db ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 20:57:11.0014 1848 hcw85cir - ok 20:57:11.0076 1848 [ a5ef29d5315111c80a5c1abad14c8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:57:11.0092 1848 HdAudAddService - ok 20:57:11.0138 1848 [ 9036377b8a6c15dc2eec53e489d159b5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 20:57:11.0138 1848 HDAudBus - ok 20:57:11.0154 1848 [ 1d58a7f3e11a9731d0eaaaa8405acc36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 20:57:11.0154 1848 HidBatt - ok 20:57:11.0170 1848 [ 89448f40e6df260c206a193a4683ba78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 20:57:11.0170 1848 HidBth - ok 20:57:11.0216 1848 [ cf50b4cf4a4f229b9f3c08351f99ca5e ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 20:57:11.0216 1848 HidIr - ok 20:57:11.0248 1848 [ 2bc6f6a1992b3a77f5f41432ca6b3b6b ] hidserv C:\Windows\system32\hidserv.dll 20:57:11.0263 1848 hidserv - ok 20:57:11.0326 1848 [ 10c19f8290891af023eaec0832e1eb4d ] HidUsb C:\Windows\system32\drivers\hidusb.sys 20:57:11.0326 1848 HidUsb - ok 20:57:11.0357 1848 [ 196b4e3f4cccc24af836ce58facbb699 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:57:11.0357 1848 hkmsvc - ok 20:57:11.0404 1848 [ 6658f4404de03d75fe3ba09f7aba6a30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 20:57:11.0404 1848 HomeGroupListener - ok 20:57:11.0450 1848 [ dbc02d918fff1cad628acbe0c0eaa8e8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 20:57:11.0450 1848 HomeGroupProvider - ok 20:57:11.0544 1848 [ 295fdc419039090eb8b49ffdbb374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 20:57:11.0544 1848 HpSAMD - ok 20:57:11.0653 1848 [ 871917b07a141bff43d76d8844d48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:57:11.0653 1848 HTTP - ok 20:57:11.0684 1848 [ 0c4e035c7f105f1299258c90886c64c5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 20:57:11.0684 1848 hwpolicy - ok 20:57:11.0778 1848 [ f151f0bdc47f4a28b1b20a0818ea36d6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 20:57:11.0778 1848 i8042prt - ok 20:57:11.0809 1848 [ 5cd5f9a5444e6cdcb0ac89bd62d8b76e ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 20:57:11.0825 1848 iaStorV - ok 20:57:11.0872 1848 [ bf648877413f6160e480814a24942b65 ] IBMPMDRV C:\Windows\system32\DRIVERS\ibmpmdrv.sys 20:57:11.0887 1848 IBMPMDRV - ok 20:57:11.0903 1848 [ a75ce11915e4ecc5e1597d6e0f7bb2db ] IBMPMSVC C:\Windows\system32\ibmpmsvc.exe 20:57:11.0903 1848 IBMPMSVC - ok 20:57:11.0981 1848 [ c521d7eb6497bb1af6afa89e322fb43c ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 20:57:11.0996 1848 idsvc - ok 20:57:12.0043 1848 [ 4173ff5708f3236cf25195fecd742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 20:57:12.0043 1848 iirsp - ok 20:57:12.0152 1848 [ f95622f161474511b8d80d6b093aa610 ] IKEEXT C:\Windows\System32\ikeext.dll 20:57:12.0152 1848 IKEEXT - ok 20:57:12.0215 1848 [ a0f12f2c9ba6c72f3987ce780e77c130 ] intelide C:\Windows\system32\drivers\intelide.sys 20:57:12.0215 1848 intelide - ok 20:57:12.0262 1848 [ 3b514d27bfc4accb4037bc6685f766e0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:57:12.0277 1848 intelppm - ok 20:57:12.0340 1848 [ acb364b9075a45c0736e5c47be5cae19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:57:12.0340 1848 IPBusEnum - ok 20:57:12.0355 1848 [ 709d1761d3b19a932ff0238ea6d50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:57:12.0355 1848 IpFilterDriver - ok 20:57:12.0418 1848 [ 4d65a07b795d6674312f879d09aa7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 20:57:12.0433 1848 iphlpsvc - ok 20:57:12.0480 1848 [ 4bd7134618c1d2a27466a099062547bf ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 20:57:12.0480 1848 IPMIDRV - ok 20:57:12.0527 1848 [ a5fa468d67abcdaa36264e463a7bb0cd ] IPNAT C:\Windows\system32\drivers\ipnat.sys 20:57:12.0527 1848 IPNAT - ok 20:57:12.0605 1848 [ 57edb35ea2feca88f8b17c0c095c9a56 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 20:57:12.0620 1848 iPod Service - ok 20:57:12.0636 1848 [ 9f7e491fb0ba0f9e370163834fc1fe31 ] irda C:\Windows\system32\DRIVERS\irda.sys 20:57:12.0636 1848 irda - ok 20:57:12.0683 1848 [ 42996cff20a3084a56017b7902307e9f ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:57:12.0683 1848 IRENUM - ok 20:57:12.0730 1848 [ 4220d2f03d5c4226d0a1aa4b84025e45 ] Irmon C:\Windows\System32\irmon.dll 20:57:12.0745 1848 Irmon - ok 20:57:12.0776 1848 [ 1f32bb6b38f62f7df1a7ab7292638a35 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:57:12.0776 1848 isapnp - ok 20:57:12.0839 1848 [ cb7a9abb12b8415bce5d74994c7ba3ae ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 20:57:12.0839 1848 iScsiPrt - ok 20:57:12.0886 1848 [ adef52ca1aeae82b50df86b56413107e ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 20:57:12.0886 1848 kbdclass - ok 20:57:12.0917 1848 [ 9e3ced91863e6ee98c24794d05e27a71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 20:57:12.0917 1848 kbdhid - ok 20:57:12.0964 1848 [ 81951f51e318aecc2d68559e47485cc4 ] KeyIso C:\Windows\system32\lsass.exe 20:57:12.0964 1848 KeyIso - ok 20:57:13.0010 1848 [ b7895b4182c0d16f6efadeb8081e8d36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:57:13.0010 1848 KSecDD - ok 20:57:13.0042 1848 [ d30159ac9237519fbc62c6ec247d2d46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 20:57:13.0057 1848 KSecPkg - ok 20:57:13.0088 1848 [ 89a7b9cc98d0d80c6f31b91c0a310fcd ] KtmRm C:\Windows\system32\msdtckrm.dll 20:57:13.0088 1848 KtmRm - ok 20:57:13.0120 1848 [ d64af876d53eca3668bb97b51b4e70ab ] LanmanServer C:\Windows\system32\srvsvc.dll 20:57:13.0120 1848 LanmanServer - ok 20:57:13.0151 1848 [ 58405e4f68ba8e4057c6e914f326aba2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:57:13.0166 1848 LanmanWorkstation - ok 20:57:13.0260 1848 [ f7611ec07349979da9b0ae1f18ccc7a6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:57:13.0260 1848 lltdio - ok 20:57:13.0276 1848 [ 5700673e13a2117fa3b9020c852c01e2 ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:57:13.0291 1848 lltdsvc - ok 20:57:13.0322 1848 [ 55ca01ba19d0006c8f2639b6c045e08b ] lmhosts C:\Windows\System32\lmhsvc.dll 20:57:13.0322 1848 lmhosts - ok 20:57:13.0369 1848 [ eb119a53ccf2acc000ac71b065b78fef ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 20:57:13.0369 1848 LSI_FC - ok 20:57:13.0447 1848 [ 8ade1c877256a22e49b75d1cc9161f9c ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 20:57:13.0447 1848 LSI_SAS - ok 20:57:13.0478 1848 [ dc9dc3d3daa0e276fd2ec262e38b11e9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 20:57:13.0478 1848 LSI_SAS2 - ok 20:57:13.0494 1848 [ 0a036c7d7cab643a7f07135ac47e0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 20:57:13.0494 1848 LSI_SCSI - ok 20:57:13.0510 1848 [ 6703e366cc18d3b6e534f5cf7df39cee ] luafv C:\Windows\system32\drivers\luafv.sys 20:57:13.0525 1848 luafv - ok 20:57:13.0588 1848 [ 8e17d513d8011b0ee03c355eaab0e0cc ] ManyCam C:\Windows\system32\DRIVERS\mcvidrv.sys 20:57:13.0588 1848 ManyCam - ok 20:57:13.0650 1848 [ fb097bbc1a18f044bd17bd2fccf97865 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 20:57:13.0650 1848 MBAMProtector - ok 20:57:13.0744 1848 [ ba400ed640bca1eae5c727ae17c10207 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 20:57:13.0744 1848 MBAMService - ok 20:57:13.0806 1848 [ 562d95e00e14a944debe655decbd3f5b ] mcaudrv_simple C:\Windows\system32\drivers\mcaudrv.sys 20:57:13.0806 1848 mcaudrv_simple - ok 20:57:13.0884 1848 [ bfb9ee8ee977efe85d1a3105abef6dd1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:57:13.0884 1848 Mcx2Svc - ok 20:57:13.0915 1848 [ 0fff5b045293002ab38eb1fd1fc2fb74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 20:57:13.0915 1848 megasas - ok 20:57:13.0962 1848 [ dcbab2920c75f390caf1d29f675d03d6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 20:57:13.0962 1848 MegaSR - ok 20:57:14.0040 1848 [ 123271bd5237ab991dc5c21fdf8835eb ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 20:57:14.0040 1848 Microsoft Office Groove Audit Service - ok 20:57:14.0102 1848 [ 146b6f43a673379a3c670e86d89be5ea ] MMCSS C:\Windows\system32\mmcss.dll 20:57:14.0102 1848 MMCSS - ok 20:57:14.0118 1848 [ f001861e5700ee84e2d4e52c712f4964 ] Modem C:\Windows\system32\drivers\modem.sys 20:57:14.0118 1848 Modem - ok 20:57:14.0149 1848 [ 79d10964de86b292320e9dfe02282a23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:57:14.0180 1848 monitor - ok 20:57:14.0227 1848 [ fb18cc1d4c2e716b6b903b0ac0cc0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys 20:57:14.0227 1848 mouclass - ok 20:57:14.0290 1848 [ 2c388d2cd01c9042596cf3c8f3c7b24d ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:57:14.0290 1848 mouhid - ok 20:57:14.0336 1848 [ fc8771f45ecccfd89684e38842539b9b ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 20:57:14.0336 1848 mountmgr - ok 20:57:14.0414 1848 [ d993bea500e7382dc4e760bf4f35efcb ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys 20:57:14.0414 1848 MpFilter - ok 20:57:14.0461 1848 [ 2d699fb6e89ce0d8da14ecc03b3edfe0 ] mpio C:\Windows\system32\drivers\mpio.sys 20:57:14.0461 1848 mpio - ok 20:57:14.0492 1848 [ ad2723a7b53dd1aacae6ad8c0bfbf4d0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:57:14.0508 1848 mpsdrv - ok 20:57:14.0555 1848 [ 9835584e999d25004e1ee8e5f3e3b881 ] MpsSvc C:\Windows\system32\mpssvc.dll 20:57:14.0555 1848 MpsSvc - ok 20:57:14.0602 1848 [ ceb46ab7c01c9f825f8cc6babc18166a ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:57:14.0602 1848 MRxDAV - ok 20:57:14.0680 1848 [ 5d16c921e3671636c0eba3bbaac5fd25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:57:14.0680 1848 mrxsmb - ok 20:57:14.0711 1848 [ 6d17a4791aca19328c685d256349fefc ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:57:14.0711 1848 mrxsmb10 - ok 20:57:14.0726 1848 [ b81f204d146000be76651a50670a5e9e ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:57:14.0726 1848 mrxsmb20 - ok 20:57:14.0773 1848 [ 012c5f4e9349e711e11e0f19a8589f0a ] msahci C:\Windows\system32\drivers\msahci.sys 20:57:14.0773 1848 msahci - ok 20:57:14.0836 1848 [ 55055f8ad8be27a64c831322a780a228 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:57:14.0836 1848 msdsm - ok 20:57:14.0851 1848 [ e1bce74a3bd9902b72599c0192a07e27 ] MSDTC C:\Windows\System32\msdtc.exe 20:57:14.0867 1848 MSDTC - ok 20:57:14.0929 1848 [ daefb28e3af5a76abcc2c3078c07327f ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:57:14.0929 1848 Msfs - ok 20:57:14.0945 1848 [ 3e1e5767043c5af9367f0056295e9f84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 20:57:14.0945 1848 mshidkmdf - ok 20:57:14.0960 1848 [ 0a4e5757ae09fa9622e3158cc1aef114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:57:14.0960 1848 msisadrv - ok 20:57:15.0038 1848 [ 90f7d9e6b6f27e1a707d4a297f077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:57:15.0038 1848 MSiSCSI - ok 20:57:15.0038 1848 msiserver - ok 20:57:15.0116 1848 [ 8c0860d6366aaffb6c5bb9df9448e631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:57:15.0116 1848 MSKSSRV - ok 20:57:15.0148 1848 [ 24516bf4e12a46cb67302e2cdcb8cddf ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe 20:57:15.0148 1848 MsMpSvc - ok 20:57:15.0179 1848 [ 3ea8b949f963562cedbb549eac0c11ce ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:57:15.0194 1848 MSPCLOCK - ok 20:57:15.0210 1848 [ f456e973590d663b1073e9c463b40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:57:15.0241 1848 MSPQM - ok 20:57:15.0272 1848 [ 0e008fc4819d238c51d7c93e7b41e560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:57:15.0272 1848 MsRPC - ok 20:57:15.0304 1848 [ fc6b9ff600cc585ea38b12589bd4e246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 20:57:15.0319 1848 mssmbios - ok 20:57:15.0335 1848 [ b42c6b921f61a6e55159b8be6cd54a36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:57:15.0335 1848 MSTEE - ok 20:57:15.0350 1848 [ 33599130f44e1f34631cea241de8ac84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 20:57:15.0350 1848 MTConfig - ok 20:57:15.0382 1848 [ 159fad02f64e6381758c990f753bcc80 ] Mup C:\Windows\system32\Drivers\mup.sys 20:57:15.0382 1848 Mup - ok 20:57:15.0444 1848 [ 61d57a5d7c6d9afe10e77dae6e1b445e ] napagent C:\Windows\system32\qagentRT.dll 20:57:15.0460 1848 napagent - ok 20:57:15.0538 1848 [ 26384429fcd85d83746f63e798ab1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:57:15.0538 1848 NativeWifiP - ok 20:57:15.0616 1848 [ e7c54812a2aaf43316eb6930c1ffa108 ] NDIS C:\Windows\system32\drivers\ndis.sys 20:57:15.0631 1848 NDIS - ok 20:57:15.0647 1848 [ 0e1787aa6c9191d3d319e8bafe86f80c ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 20:57:15.0662 1848 NdisCap - ok 20:57:15.0709 1848 [ e4a8aec125a2e43a9e32afeea7c9c888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:57:15.0709 1848 NdisTapi - ok 20:57:15.0740 1848 [ d8a65dafb3eb41cbb622745676fcd072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:57:15.0740 1848 Ndisuio - ok 20:57:15.0772 1848 [ 38fbe267e7e6983311179230facb1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:57:15.0787 1848 NdisWan - ok 20:57:15.0865 1848 [ a4bdc541e69674fbff1a8ff00be913f2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:57:15.0865 1848 NDProxy - ok 20:57:15.0928 1848 [ 80b275b1ce3b0e79909db7b39af74d51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:57:15.0928 1848 NetBIOS - ok 20:57:15.0959 1848 [ 280122ddcf04b378edd1ad54d71c1e54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 20:57:15.0974 1848 NetBT - ok 20:57:16.0006 1848 [ 81951f51e318aecc2d68559e47485cc4 ] Netlogon C:\Windows\system32\lsass.exe 20:57:16.0006 1848 Netlogon - ok 20:57:16.0115 1848 [ 7cccfca7510684768da22092d1fa4db2 ] Netman C:\Windows\System32\netman.dll 20:57:16.0115 1848 Netman - ok 20:57:16.0162 1848 [ 8c338238c16777a802d6a9211eb2ba50 ] netprofm C:\Windows\System32\netprofm.dll 20:57:16.0162 1848 netprofm - ok 20:57:16.0240 1848 [ f476ec40033cdb91efbe73eb99b8362d ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 20:57:16.0240 1848 NetTcpPortSharing - ok 20:57:16.0396 1848 [ 58218ec6b61b1169cf54aab0d00f5fe2 ] netw5v32 C:\Windows\system32\DRIVERS\netw5v32.sys 20:57:16.0505 1848 netw5v32 - ok 20:57:16.0567 1848 [ 1d85c4b390b0ee09c7a46b91efb2c097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 20:57:16.0567 1848 nfrd960 - ok 20:57:16.0645 1848 [ b52f26bade7d7e4a79706e3fd91834cd ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys 20:57:16.0645 1848 NisDrv - ok 20:57:16.0692 1848 [ 290c0d4c4889398797f8df3be00b9698 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe 20:57:16.0692 1848 NisSrv - ok 20:57:16.0723 1848 [ 912084381d30d8b89ec4e293053f4710 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:57:16.0739 1848 NlaSvc - ok 20:57:16.0754 1848 [ 1db262a9f8c087e8153d89bef3d2235f ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:57:16.0754 1848 Npfs - ok 20:57:16.0848 1848 [ 6d8d2e5652fc2442c810c5d8be784148 ] NSCIRDA C:\Windows\system32\DRIVERS\nscirda.sys 20:57:16.0848 1848 NSCIRDA - ok 20:57:16.0879 1848 [ ba387e955e890c8a88306d9b8d06bf17 ] nsi C:\Windows\system32\nsisvc.dll 20:57:16.0879 1848 nsi - ok 20:57:16.0910 1848 [ e9a0a4d07e53d8fea2bb8387a3293c58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:57:16.0910 1848 nsiproxy - ok 20:57:16.0988 1848 [ 81189c3d7763838e55c397759d49007a ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:57:17.0004 1848 Ntfs - ok 20:57:17.0035 1848 [ f9756a98d69098dca8945d62858a812c ] Null C:\Windows\system32\drivers\Null.sys 20:57:17.0035 1848 Null - ok 20:57:17.0082 1848 [ b3e25ee28883877076e0e1ff877d02e0 ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:57:17.0098 1848 nvraid - ok 20:57:17.0144 1848 [ 4380e59a170d88c4f1022eff6719a8a4 ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:57:17.0144 1848 nvstor - ok 20:57:17.0160 1848 [ 5a0983915f02bae73267cc2a041f717d ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:57:17.0160 1848 nv_agp - ok 20:57:17.0269 1848 [ 785f487a64950f3cb8e9f16253ba3b7b ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 20:57:17.0285 1848 odserv - ok 20:57:17.0332 1848 [ 08a70a1f2cdde9bb49b885cb817a66eb ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 20:57:17.0332 1848 ohci1394 - ok 20:57:17.0394 1848 [ 5a432a042dae460abe7199b758e8606c ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:57:17.0394 1848 ose - ok 20:57:17.0472 1848 [ 82a8521ddc60710c3d3d3e7325209bec ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 20:57:17.0472 1848 p2pimsvc - ok 20:57:17.0503 1848 [ 59c3ddd501e39e006dac31bf55150d91 ] p2psvc C:\Windows\system32\p2psvc.dll 20:57:17.0519 1848 p2psvc - ok 20:57:17.0550 1848 [ 2ea877ed5dd9713c5ac74e8ea7348d14 ] Parport C:\Windows\system32\DRIVERS\parport.sys 20:57:17.0566 1848 Parport - ok 20:57:17.0612 1848 [ 3f34a1b4c5f6475f320c275e63afce9b ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:57:17.0612 1848 partmgr - ok 20:57:17.0644 1848 [ eb0a59f29c19b86479d36b35983daadc ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 20:57:17.0644 1848 Parvdm - ok 20:57:17.0675 1848 [ 358ab7956d3160000726574083dfc8a6 ] PcaSvc C:\Windows\System32\pcasvc.dll 20:57:17.0675 1848 PcaSvc - ok 20:57:17.0690 1848 [ 673e55c3498eb970088e812ea820aa8f ] pci C:\Windows\system32\drivers\pci.sys 20:57:17.0706 1848 pci - ok 20:57:17.0737 1848 [ afe86f419014db4e5593f69ffe26ce0a ] pciide C:\Windows\system32\drivers\pciide.sys 20:57:17.0737 1848 pciide - ok 20:57:17.0753 1848 [ f396431b31693e71e8a80687ef523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 20:57:17.0768 1848 pcmcia - ok 20:57:17.0784 1848 [ 250f6b43d2b613172035c6747aeeb19f ] pcw C:\Windows\system32\drivers\pcw.sys 20:57:17.0784 1848 pcw - ok 20:57:17.0878 1848 [ 9e0104ba49f4e6973749a02bf41344ed ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:57:17.0878 1848 PEAUTH - ok 20:57:17.0971 1848 [ 414bba67a3ded1d28437eb66aeb8a720 ] pla C:\Windows\system32\pla.dll 20:57:17.0987 1848 pla - ok 20:57:18.0080 1848 [ ec7bc28d207da09e79b3e9faf8b232ca ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:57:18.0080 1848 PlugPlay - ok 20:57:18.0127 1848 [ 63ff8572611249931eb16bb8eed6afc8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 20:57:18.0127 1848 PNRPAutoReg - ok 20:57:18.0143 1848 [ 82a8521ddc60710c3d3d3e7325209bec ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 20:57:18.0158 1848 PNRPsvc - ok 20:57:18.0190 1848 [ 53946b69ba0836bd95b03759530c81ec ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:57:18.0205 1848 PolicyAgent - ok 20:57:18.0236 1848 [ f87d30e72e03d579a5199ccb3831d6ea ] Power C:\Windows\system32\umpo.dll 20:57:18.0236 1848 Power - ok 20:57:18.0314 1848 [ 631e3e205ad6d86f2aed6a4a8e69f2db ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:57:18.0314 1848 PptpMiniport - ok 20:57:18.0346 1848 [ 85b1e3a0c7585bc4aae6899ec6fcf011 ] Processor C:\Windows\system32\DRIVERS\processr.sys 20:57:18.0346 1848 Processor - ok 20:57:18.0408 1848 [ cadefac453040e370a1bdff3973be00d ] ProfSvc C:\Windows\system32\profsvc.dll 20:57:18.0408 1848 ProfSvc - ok 20:57:18.0424 1848 [ 81951f51e318aecc2d68559e47485cc4 ] ProtectedStorage C:\Windows\system32\lsass.exe 20:57:18.0424 1848 ProtectedStorage - ok 20:57:18.0486 1848 [ 6270ccae2a86de6d146529fe55b3246a ] Psched C:\Windows\system32\DRIVERS\pacer.sys 20:57:18.0486 1848 Psched - ok 20:57:18.0548 1848 [ ab95ecf1f6659a60ddc166d8315b0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 20:57:18.0580 1848 ql2300 - ok 20:57:18.0595 1848 [ b4dd51dd25182244b86737dc51af2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 20:57:18.0595 1848 ql40xx - ok 20:57:18.0658 1848 [ 31ac809e7707eb580b2bdb760390765a ] QWAVE C:\Windows\system32\qwave.dll 20:57:18.0658 1848 QWAVE - ok 20:57:18.0673 1848 [ 584078ca1b95ca72df2a27c336f9719d ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:57:18.0673 1848 QWAVEdrv - ok 20:57:18.0689 1848 [ 30a81b53c766d0133bb86d234e5556ab ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:57:18.0689 1848 RasAcd - ok 20:57:18.0767 1848 [ 57ec4aef73660166074d8f7f31c0d4fd ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 20:57:18.0767 1848 RasAgileVpn - ok 20:57:18.0798 1848 [ a60f1839849c0c00739787fd5ec03f13 ] RasAuto C:\Windows\System32\rasauto.dll 20:57:18.0798 1848 RasAuto - ok 20:57:18.0829 1848 [ d9f91eafec2815365cbe6d167e4e332a ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:57:18.0829 1848 Rasl2tp - ok 20:57:18.0876 1848 [ cb9e04dc05eacf5b9a36ca276d475006 ] RasMan C:\Windows\System32\rasmans.dll 20:57:18.0876 1848 RasMan - ok 20:57:18.0907 1848 [ 0fe8b15916307a6ac12bfb6a63e45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:57:18.0907 1848 RasPppoe - ok 20:57:18.0938 1848 [ 44101f495a83ea6401d886e7fd70096b ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:57:18.0938 1848 RasSstp - ok 20:57:19.0001 1848 [ d528bc58a489409ba40334ebf96a311b ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:57:19.0001 1848 rdbss - ok 20:57:19.0032 1848 [ 0d8f05481cb76e70e1da06ee9f0da9df ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 20:57:19.0032 1848 rdpbus - ok 20:57:19.0063 1848 [ 23dae03f29d253ae74c44f99e515f9a1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:57:19.0063 1848 RDPCDD - ok 20:57:19.0110 1848 [ 5a53ca1598dd4156d44196d200c94b8a ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:57:19.0110 1848 RDPENCDD - ok 20:57:19.0157 1848 [ 44b0a53cd4f27d50ed461dae0c0b4e1f ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 20:57:19.0157 1848 RDPREFMP - ok 20:57:19.0188 1848 [ f031683e6d1fea157abb2ff260b51e61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:57:19.0188 1848 RDPWD - ok 20:57:19.0266 1848 [ 518395321dc96fe2c9f0e96ac743b656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 20:57:19.0266 1848 rdyboost - ok 20:57:19.0297 1848 [ 7b5e1419717fac363a31cc302895217a ] RemoteAccess C:\Windows\System32\mprdim.dll 20:57:19.0313 1848 RemoteAccess - ok 20:57:19.0360 1848 [ cb9a8683f4ef2bf99e123d79950d7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:57:19.0360 1848 RemoteRegistry - ok 20:57:19.0438 1848 [ 78d072f35bc45d9e4e1b61895c152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 20:57:19.0453 1848 RpcEptMapper - ok 20:57:19.0516 1848 [ 94d36c0e44677dd26981d2bfeef2a29d ] RpcLocator C:\Windows\system32\locator.exe 20:57:19.0531 1848 RpcLocator - ok 20:57:19.0547 1848 [ 7660f01d3b38aca1747e397d21d790af ] RpcSs C:\Windows\system32\rpcss.dll 20:57:19.0547 1848 RpcSs - ok 20:57:19.0594 1848 [ 032b0d36ad92b582d869879f5af5b928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:57:19.0609 1848 rspndr - ok 20:57:19.0640 1848 [ 81951f51e318aecc2d68559e47485cc4 ] SamSs C:\Windows\system32\lsass.exe 20:57:19.0640 1848 SamSs - ok 20:57:19.0703 1848 [ 05d860da1040f111503ac416ccef2bca ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:57:19.0703 1848 sbp2port - ok 20:57:19.0750 1848 [ 8fc518ffe9519c2631d37515a68009c4 ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:57:19.0750 1848 SCardSvr - ok 20:57:19.0828 1848 [ 90226947195699eee8b1241627fe77ce ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys 20:57:19.0828 1848 SCDEmu - ok 20:57:19.0859 1848 [ 0693b5ec673e34dc147e195779a4dcf6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 20:57:19.0859 1848 scfilter - ok 20:57:19.0921 1848 [ a04bb13f8a72f8b6e8b4071723e4e336 ] Schedule C:\Windows\system32\schedsvc.dll 20:57:19.0921 1848 Schedule - ok 20:57:19.0937 1848 [ 319c6b309773d063541d01df8ac6f55f ] SCPolicySvc C:\Windows\System32\certprop.dll 20:57:19.0937 1848 SCPolicySvc - ok 20:57:19.0984 1848 [ 08236c4bce5edd0a0318a438af28e0f7 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:57:19.0984 1848 SDRSVC - ok 20:57:20.0077 1848 [ 78779ee07231c658b483b1f38b5088df ] SeaPort C:\Program Files\Microsoft\BingBar\SeaPort.EXE 20:57:20.0077 1848 SeaPort - ok 20:57:20.0124 1848 [ 90a3935d05b494a5a39d37e71f09a677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:57:20.0124 1848 secdrv - ok 20:57:20.0155 1848 [ a59b3a4442c52060cc7a85293aa3546f ] seclogon C:\Windows\system32\seclogon.dll 20:57:20.0155 1848 seclogon - ok 20:57:20.0218 1848 [ dcb7fcdcc97f87360f75d77425b81737 ] SENS C:\Windows\System32\sens.dll 20:57:20.0218 1848 SENS - ok 20:57:20.0264 1848 [ 50087fe1ee447009c9cc2997b90de53f ] SensrSvc C:\Windows\system32\sensrsvc.dll 20:57:20.0264 1848 SensrSvc - ok 20:57:20.0280 1848 [ 9ad8b8b515e3df6acd4212ef465de2d1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 20:57:20.0280 1848 Serenum - ok 20:57:20.0296 1848 [ 5fb7fcea0490d821f26f39cc5ea3d1e2 ] Serial C:\Windows\system32\DRIVERS\serial.sys 20:57:20.0296 1848 Serial - ok 20:57:20.0374 1848 [ 79bffb520327ff916a582dfea17aa813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 20:57:20.0374 1848 sermouse - ok 20:57:20.0420 1848 [ 4ae380f39a0032eab7dd953030b26d28 ] SessionEnv C:\Windows\system32\sessenv.dll 20:57:20.0420 1848 SessionEnv - ok 20:57:20.0467 1848 [ 9f976e1eb233df46fce808d9dea3eb9c ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 20:57:20.0483 1848 sffdisk - ok 20:57:20.0498 1848 [ 932a68ee27833cfd57c1639d375f2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:57:20.0498 1848 sffp_mmc - ok 20:57:20.0514 1848 [ 6d4ccaedc018f1cf52866bbbaa235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 20:57:20.0514 1848 sffp_sd - ok 20:57:20.0545 1848 [ db96666cc8312ebc45032f30b007a547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 20:57:20.0545 1848 sfloppy - ok 20:57:20.0592 1848 [ d1a079a0de2ea524513b6930c24527a2 ] SharedAccess C:\Windows\System32\ipnathlp.dll 20:57:20.0592 1848 SharedAccess - ok 20:57:20.0623 1848 [ 414da952a35bf5d50192e28263b40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:57:20.0623 1848 ShellHWDetection - ok 20:57:20.0670 1848 [ 2565cac0dc9fe0371bdce60832582b2e ] sisagp C:\Windows\system32\drivers\sisagp.sys 20:57:20.0686 1848 sisagp - ok 20:57:20.0732 1848 [ a9f0486851becb6dda1d89d381e71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 20:57:20.0748 1848 SiSRaid2 - ok 20:57:20.0764 1848 [ 3727097b55738e2f554972c3be5bc1aa ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 20:57:20.0764 1848 SiSRaid4 - ok 20:57:21.0029 1848 [ 0f97e7a47a52f4a36969f0fc319654c2 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 20:57:21.0200 1848 Skype C2C Service - ok 20:57:21.0341 1848 [ ef3b592545676301cdeb7c2609eed7bf ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 20:57:21.0341 1848 SkypeUpdate - ok 20:57:21.0403 1848 [ 3e21c083b8a01cb70ba1f09303010fce ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:57:21.0403 1848 Smb - ok 20:57:21.0450 1848 [ 0b9c01236d25bdcb37aa79dc59dfb7d3 ] smihlp C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys 20:57:21.0450 1848 smihlp - ok 20:57:21.0528 1848 [ 6a984831644eca1a33ffeae4126f4f37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:57:21.0528 1848 SNMPTRAP - ok 20:57:21.0590 1848 [ 95cf1ae7527fb70f7816563cbc09d942 ] spldr C:\Windows\system32\drivers\spldr.sys 20:57:21.0590 1848 spldr - ok 20:57:21.0622 1848 [ 866a43013535dc8587c258e43579c764 ] Spooler C:\Windows\System32\spoolsv.exe 20:57:21.0637 1848 Spooler - ok 20:57:21.0731 1848 [ cf87a1de791347e75b98885214ced2b8 ] sppsvc C:\Windows\system32\sppsvc.exe 20:57:21.0778 1848 sppsvc - ok 20:57:21.0809 1848 [ b0180b20b065d89232a78a40fe56eaa6 ] sppuinotify C:\Windows\system32\sppuinotify.dll 20:57:21.0809 1848 sppuinotify - ok 20:57:21.0856 1848 [ e4c2764065d66ea1d2d3ebc28fe99c46 ] srv C:\Windows\system32\DRIVERS\srv.sys 20:57:21.0856 1848 srv - ok 20:57:21.0887 1848 [ 03f0545bd8d4c77fa0ae1ceedfcc71ab ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:57:21.0887 1848 srv2 - ok 20:57:21.0949 1848 [ e00fdfaff025e94f9821153750c35a6d ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL3.SYS 20:57:21.0949 1848 SrvHsfHDA - ok 20:57:21.0996 1848 [ ceb4e3b6890e1e42dca6694d9e59e1a0 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV3.SYS 20:57:22.0012 1848 SrvHsfV92 - ok 20:57:22.0043 1848 [ bc0c7ea89194c299f051c24119000e17 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT3.SYS 20:57:22.0058 1848 SrvHsfWinac - ok 20:57:22.0105 1848 [ be6bd660caa6f291ae06a718a4fa8abc ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:57:22.0105 1848 srvnet - ok 20:57:22.0152 1848 [ d887c9fd02ac9fa880f6e5027a43e118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:57:22.0152 1848 SSDPSRV - ok 20:57:22.0168 1848 [ d318f23be45d5e3a107469eb64815b50 ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:57:22.0168 1848 SstpSvc - ok 20:57:22.0199 1848 [ db32d325c192b801df274bfd12a7e72b ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 20:57:22.0199 1848 stexstor - ok 20:57:22.0261 1848 [ e1fb3706030fb4578a0d72c2fc3689e4 ] StiSvc C:\Windows\System32\wiaservc.dll 20:57:22.0277 1848 StiSvc - ok 20:57:22.0324 1848 [ e58c78a848add9610a4db6d214af5224 ] swenum C:\Windows\system32\drivers\swenum.sys 20:57:22.0324 1848 swenum - ok 20:57:22.0480 1848 [ f577910a133a592234ebaad3f3afa258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 20:57:22.0480 1848 SwitchBoard - ok 20:57:22.0558 1848 [ a28bd92df340e57b024ba433165d34d7 ] swprv C:\Windows\System32\swprv.dll 20:57:22.0558 1848 swprv - ok 20:57:22.0636 1848 [ 36650d618ca34c9d357dfd3d89b2c56f ] SysMain C:\Windows\system32\sysmain.dll 20:57:22.0651 1848 SysMain - ok 20:57:22.0698 1848 [ 763fecdc3d30c815fe72dd57936c6cd1 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:57:22.0698 1848 TabletInputService - ok 20:57:22.0745 1848 [ 613bf4820361543956909043a265c6ac ] TapiSrv C:\Windows\System32\tapisrv.dll 20:57:22.0745 1848 TapiSrv - ok 20:57:22.0776 1848 [ b799d9fdb26111737f58288d8dc172d9 ] TBS C:\Windows\System32\tbssvc.dll 20:57:22.0776 1848 TBS - ok 20:57:22.0838 1848 [ 7fa2e0f8b072bd04b77b421480b6cc22 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:57:22.0854 1848 Tcpip - ok 20:57:22.0901 1848 [ 7fa2e0f8b072bd04b77b421480b6cc22 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 20:57:22.0901 1848 TCPIP6 - ok 20:57:22.0948 1848 [ cca24162e055c3714ce5a88b100c64ed ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:57:22.0948 1848 tcpipreg - ok 20:57:22.0994 1848 [ 1cb91b2bd8f6dd367dfc2ef26fd751b2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:57:22.0994 1848 TDPIPE - ok 20:57:23.0010 1848 [ 2c2c5afe7ee4f620d69c23c0617651a8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:57:23.0026 1848 TDTCP - ok 20:57:23.0057 1848 [ b459575348c20e8121d6039da063c704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:57:23.0057 1848 tdx - ok 20:57:23.0072 1848 [ 04dbf4b01ea4bf25a9a3e84affac9b20 ] TermDD C:\Windows\system32\drivers\termdd.sys 20:57:23.0072 1848 TermDD - ok 20:57:23.0166 1848 [ 382c804c92811be57829d8e550a900e2 ] TermService C:\Windows\System32\termsrv.dll 20:57:23.0166 1848 TermService - ok 20:57:23.0213 1848 [ 42fb6afd6b79d9fe07381609172e7ca4 ] Themes C:\Windows\system32\themeservice.dll 20:57:23.0213 1848 Themes - ok 20:57:23.0244 1848 [ 146b6f43a673379a3c670e86d89be5ea ] THREADORDER C:\Windows\system32\mmcss.dll 20:57:23.0244 1848 THREADORDER - ok 20:57:23.0291 1848 [ 4792c0378db99a9bc2ae2de6cfff0c3a ] TrkWks C:\Windows\System32\trkwks.dll 20:57:23.0291 1848 TrkWks - ok 20:57:23.0353 1848 [ b3c9c35dc93563b8d19ad414edf2fc82 ] TrueSight c:\windows\system32\drivers\TrueSight.sys 20:57:23.0353 1848 TrueSight - ok 20:57:23.0447 1848 [ 2c49b175aee1d4364b91b531417fe583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:57:23.0462 1848 TrustedInstaller - ok 20:57:23.0509 1848 [ 254bb140eee3c59d6114c1a86b636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:57:23.0509 1848 tssecsrv - ok 20:57:23.0587 1848 [ fd1d6c73e6333be727cbcc6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 20:57:23.0587 1848 TsUsbFlt - ok 20:57:23.0665 1848 [ b2fa25d9b17a68bb93d58b0556e8c90d ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:57:23.0665 1848 tunnel - ok 20:57:23.0696 1848 [ 750fbcb269f4d7dd2e420c56b795db6d ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 20:57:23.0696 1848 uagp35 - ok 20:57:23.0806 1848 [ 63f6d08c54d5b3c1b12a6172032055c7 ] uCamMonitor C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe 20:57:23.0806 1848 uCamMonitor - ok 20:57:23.0837 1848 [ ee43346c7e4b5e63e54f927babbb32ff ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:57:23.0837 1848 udfs - ok 20:57:23.0884 1848 [ 8344fd4fce927880aa1aa7681d4927e5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:57:23.0884 1848 UI0Detect - ok 20:57:23.0946 1848 [ 44e8048ace47befbfdc2e9be4cbc8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:57:23.0946 1848 uliagpkx - ok 20:57:24.0008 1848 [ d295bed4b898f0fd999fcfa9b32b071b ] umbus C:\Windows\system32\drivers\umbus.sys 20:57:24.0008 1848 umbus - ok 20:57:24.0055 1848 [ 7550ad0c6998ba1cb4843e920ee0feac ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 20:57:24.0071 1848 UmPass - ok 20:57:24.0086 1848 [ 833fbb672460efce8011d262175fad33 ] upnphost C:\Windows\System32\upnphost.dll 20:57:24.0102 1848 upnphost - ok 20:57:24.0164 1848 [ eafe1e00739afe6c51487a050e772e17 ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys 20:57:24.0164 1848 USBAAPL - ok 20:57:24.0227 1848 [ 1d9f2bd026e8e2d45033a4df3f16b78c ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 20:57:24.0227 1848 usbaudio - ok 20:57:24.0289 1848 [ bd9c55d7023c5de374507acc7a14e2ac ] usbccgp C:\Windows\system32\drivers\usbccgp.sys 20:57:24.0305 1848 usbccgp - ok 20:57:24.0336 1848 [ 04ec7cec62ec3b6d9354eee93327fc82 ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:57:24.0336 1848 usbcir - ok 20:57:24.0367 1848 [ f92de757e4b7ce9c07c5e65423f3ae3b ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 20:57:24.0367 1848 usbehci - ok 20:57:24.0414 1848 [ 8dc94aec6a7e644a06135ae7506dc2e9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:57:24.0414 1848 usbhub - ok 20:57:24.0445 1848 [ e185d44fac515a18d9deddc23c2cdf44 ] usbohci C:\Windows\system32\drivers\usbohci.sys 20:57:24.0445 1848 usbohci - ok 20:57:24.0508 1848 [ 797d862fe0875e75c7cc4c1ad7b30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 20:57:24.0508 1848 usbprint - ok 20:57:24.0523 1848 [ f991ab9cc6b908db552166768176896a ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:57:24.0523 1848 USBSTOR - ok 20:57:24.0586 1848 [ 68df884cf41cdada664beb01daf67e3d ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 20:57:24.0586 1848 usbuhci - ok 20:57:24.0664 1848 [ 45f4e7bf43db40a6c6b4d92c76cbc3f2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 20:57:24.0664 1848 usbvideo - ok 20:57:24.0695 1848 [ 081e6e1c91aec36758902a9f727cd23c ] UxSms C:\Windows\System32\uxsms.dll 20:57:24.0695 1848 UxSms - ok 20:57:24.0710 1848 [ 81951f51e318aecc2d68559e47485cc4 ] VaultSvc C:\Windows\system32\lsass.exe 20:57:24.0710 1848 VaultSvc - ok 20:57:24.0773 1848 [ a059c4c3edb09e07d21a8e5c0aabd3cb ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 20:57:24.0773 1848 vdrvroot - ok 20:57:24.0820 1848 [ c3cd30495687c2a2f66a65ca6fd89be9 ] vds C:\Windows\System32\vds.exe 20:57:24.0835 1848 vds - ok 20:57:24.0866 1848 [ 17c408214ea61696cec9c66e388b14f3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:57:24.0866 1848 vga - ok 20:57:24.0882 1848 [ 8e38096ad5c8570a6f1570a61e251561 ] VgaSave C:\Windows\System32\drivers\vga.sys 20:57:24.0898 1848 VgaSave - ok 20:57:24.0960 1848 [ 5461686cca2fda57b024547733ab42e3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 20:57:24.0960 1848 vhdmp - ok 20:57:25.0007 1848 [ c829317a37b4bea8f39735d4b076e923 ] viaagp C:\Windows\system32\drivers\viaagp.sys 20:57:25.0007 1848 viaagp - ok 20:57:25.0054 1848 [ e02f079a6aa107f06b16549c6e5c7b74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys 20:57:25.0054 1848 ViaC7 - ok 20:57:25.0116 1848 [ e43574f6a56a0ee11809b48c09e4fd3c ] viaide C:\Windows\system32\drivers\viaide.sys 20:57:25.0116 1848 viaide - ok 20:57:25.0225 1848 [ e19c382e2b1f1478f76c6a285adbb993 ] vm331avs C:\Windows\system32\Drivers\vm331avs.sys 20:57:25.0241 1848 vm331avs - ok 20:57:25.0272 1848 [ 4c63e00f2f4b5f86ab48a58cd990f212 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:57:25.0272 1848 volmgr - ok 20:57:25.0334 1848 [ b5bb72067ddddbbfb04b2f89ff8c3c87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:57:25.0334 1848 volmgrx - ok 20:57:25.0381 1848 [ f497f67932c6fa693d7de2780631cfe7 ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:57:25.0381 1848 volsnap - ok 20:57:25.0444 1848 [ 9dfa0cc2f8855a04816729651175b631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 20:57:25.0444 1848 vsmraid - ok 20:57:25.0537 1848 [ 209a3b1901b83aeb8527ed211cce9e4c ] VSS C:\Windows\system32\vssvc.exe 20:57:25.0553 1848 VSS - ok 20:57:25.0740 1848 [ 8ed347bad8d1fb7c40b593bfb01786d2 ] vToolbarUpdater11.2.0 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe 20:57:25.0756 1848 vToolbarUpdater11.2.0 - ok 20:57:25.0818 1848 [ ccde899c270f65d6f9835130067913ca ] vvftav323 C:\Windows\system32\drivers\vvftav323.sys 20:57:25.0818 1848 vvftav323 - ok 20:57:25.0834 1848 [ 90567b1e658001e79d7c8bbd3dde5aa6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 20:57:25.0834 1848 vwifibus - ok 20:57:25.0927 1848 [ 55187fd710e27d5095d10a472c8baf1c ] W32Time C:\Windows\system32\w32time.dll 20:57:25.0927 1848 W32Time - ok 20:57:25.0990 1848 [ de3721e89c653aa281428c8a69745d90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 20:57:25.0990 1848 WacomPen - ok 20:57:26.0068 1848 [ 3c3c78515f5ab448b022bdf5b8ffdd2e ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 20:57:26.0068 1848 WANARP - ok 20:57:26.0068 1848 [ 3c3c78515f5ab448b022bdf5b8ffdd2e ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:57:26.0068 1848 Wanarpv6 - ok 20:57:26.0146 1848 [ 353a04c273ec58475d8633e75ccd5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 20:57:26.0161 1848 WatAdminSvc - ok 20:57:26.0224 1848 [ 691e3285e53dca558e1a84667f13e15a ] wbengine C:\Windows\system32\wbengine.exe 20:57:26.0239 1848 wbengine - ok 20:57:26.0286 1848 [ 9614b5d29dc76ac3c29f6d2d3aa70e67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 20:57:26.0286 1848 WbioSrvc - ok 20:57:26.0348 1848 [ 34eee0dfaadb4f691d6d5308a51315dc ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:57:26.0364 1848 wcncsvc - ok 20:57:26.0395 1848 [ 5d930b6357a6d2af4d7653bdabbf352f ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:57:26.0411 1848 WcsPlugInService - ok 20:57:26.0442 1848 [ 1112a9badacb47b7c0bb0392e3158dff ] Wd C:\Windows\system32\DRIVERS\wd.sys 20:57:26.0442 1848 Wd - ok 20:57:26.0458 1848 [ 9950e3d0f08141c7e89e64456ae7dc73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:57:26.0473 1848 Wdf01000 - ok 20:57:26.0489 1848 [ 46ef9dc96265fd0b423db72e7c38c2a5 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:57:26.0489 1848 WdiServiceHost - ok 20:57:26.0520 1848 [ 46ef9dc96265fd0b423db72e7c38c2a5 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:57:26.0520 1848 WdiSystemHost - ok 20:57:26.0551 1848 [ a9d880f97530d5b8fee278923349929d ] WebClient C:\Windows\System32\webclnt.dll 20:57:26.0567 1848 WebClient - ok 20:57:26.0598 1848 [ 760f0afe937a77cff27153206534f275 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:57:26.0598 1848 Wecsvc - ok 20:57:26.0614 1848 [ ac804569bb2364fb6017370258a4091b ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:57:26.0614 1848 wercplsupport - ok 20:57:26.0660 1848 [ 08e420d873e4fd85241ee2421b02c4a4 ] WerSvc C:\Windows\System32\WerSvc.dll 20:57:26.0676 1848 WerSvc - ok 20:57:26.0738 1848 [ 8b9a943f3b53861f2bfaf6c186168f79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 20:57:26.0738 1848 WfpLwf - ok 20:57:26.0785 1848 [ 5cf95b35e59e2a38023836fff31be64c ] WIMMount C:\Windows\system32\drivers\wimmount.sys 20:57:26.0785 1848 WIMMount - ok 20:57:26.0863 1848 [ 3fae8f94296001c32eab62cd7d82e0fd ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 20:57:26.0879 1848 WinDefend - ok 20:57:26.0894 1848 WinHttpAutoProxySvc - ok 20:57:26.0972 1848 [ f62e510b6ad4c21eb9fe8668ed251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:57:26.0972 1848 Winmgmt - ok 20:57:27.0050 1848 [ 1b91cd34ea3a90ab6a4ef0550174f4cc ] WinRM C:\Windows\system32\WsmSvc.dll 20:57:27.0066 1848 WinRM - ok 20:57:27.0175 1848 [ a67e5f9a400f3bd1be3d80613b45f708 ] WinUsb C:\Windows\system32\DRIVERS\WinUSB.sys 20:57:27.0175 1848 WinUsb - ok 20:57:27.0238 1848 [ 16935c98ff639d185086a3529b1f2067 ] Wlansvc C:\Windows\System32\wlansvc.dll 20:57:27.0253 1848 Wlansvc - ok 20:57:27.0300 1848 [ 6067acef367e79914af628fa1e9b5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 20:57:27.0300 1848 wlcrasvc - ok 20:57:27.0394 1848 [ fb01d4ae207b9efdbabfc55dc95c7e31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:57:27.0425 1848 wlidsvc - ok 20:57:27.0472 1848 [ 0217679b8fca58714c3bf2726d2ca84e ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 20:57:27.0472 1848 WmiAcpi - ok 20:57:27.0534 1848 [ 6eb6b66517b048d87dc1856ddf1f4c3f ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:57:27.0550 1848 wmiApSrv - ok 20:57:27.0659 1848 [ 3b40d3a61aa8c21b88ae57c58ab3122e ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 20:57:27.0690 1848 WMPNetworkSvc - ok 20:57:27.0706 1848 [ a2f0ec770a92f2b3f9de6d518e11409c ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:57:27.0706 1848 WPCSvc - ok 20:57:27.0752 1848 [ aa53356d60af47eacc85bc617a4f3f66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:57:27.0752 1848 WPDBusEnum - ok 20:57:27.0784 1848 [ 6db3276587b853bf886b69528fdb048c ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:57:27.0784 1848 ws2ifsl - ok 20:57:27.0815 1848 [ 6f5d49efe0e7164e03ae773a3fe25340 ] wscsvc C:\Windows\System32\wscsvc.dll 20:57:27.0815 1848 wscsvc - ok 20:57:27.0830 1848 WSearch - ok 20:57:27.0955 1848 [ fc3ec24fce372c89423e015a2ac1a31e ] wuauserv C:\Windows\system32\wuaueng.dll 20:57:27.0986 1848 wuauserv - ok 20:57:28.0018 1848 [ e714a1c0354636837e20ccbf00888ee7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:57:28.0018 1848 WudfPf - ok 20:57:28.0049 1848 [ 1023ee888c9b47178c5293ed5336ab69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:57:28.0049 1848 WUDFRd - ok 20:57:28.0111 1848 [ 8d1e1e529a2c9e9b6a85b55a345f7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:57:28.0127 1848 wudfsvc - ok 20:57:28.0158 1848 [ ff2d745b560f7c71b31f30f4d49f73d2 ] WwanSvc C:\Windows\System32\wwansvc.dll 20:57:28.0158 1848 WwanSvc - ok 20:57:28.0252 1848 [ 74ec37b9eaf9fca015b933a526825c7a ] {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} C:\Program Files\CyberLink\PowerDVD10\NavFilter\000.fcl 20:57:28.0267 1848 {1BA31E5A-C098-42d8-8F88-3C9F78A2FDDC} - ok 20:57:28.0314 1848 ================ Scan global =============================== 20:57:28.0345 1848 (dab748ae0439955ed2fa22357533dddb) C:\Windows\system32\basesrv.dll 20:57:28.0376 1848 (183b4188d5d91b271613ec3efd1b3cef) C:\Windows\system32\winsrv.dll 20:57:28.0392 1848 (183b4188d5d91b271613ec3efd1b3cef) C:\Windows\system32\winsrv.dll 20:57:28.0408 1848 (364455805e64882844ee9acb72522830) C:\Windows\system32\sxssrv.dll 20:57:28.0423 1848 (5f1b6a9c35d3d5ca72d6d6fdef9747d6) C:\Windows\system32\services.exe 20:57:28.0423 1848 [Global] - ok 20:57:28.0423 1848 ================ Scan MBR ================================== 20:57:28.0439 1848 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 20:57:28.0439 1848 Suspicious mbr (Forged): \Device\Harddisk0\DR0 20:57:28.0486 1848 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected 20:57:28.0486 1848 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0) 20:57:28.0486 1848 ================ Scan VBR ================================== 20:57:28.0501 1848 Boot (0x1200) (3712a9fa3fba85998190cd752cee4323) \Device\Harddisk0\DR0\Partition1 20:57:28.0501 1848 \Device\Harddisk0\DR0\Partition1 - ok 20:57:28.0501 1848 Boot (0x1200) (44aeb71a70097b0131dcf11e38471b21) \Device\Harddisk0\DR0\Partition2 20:57:28.0517 1848 \Device\Harddisk0\DR0\Partition2 - ok 20:57:28.0517 1848 ============================================================ 20:57:28.0517 1848 Scan finished 20:57:28.0517 1848 ============================================================ 20:57:28.0532 1588 Detected object count: 1 20:57:28.0532 1588 Actual detected object count: 1 20:59:18.0045 1588 \Device\Harddisk0\DR0\# - copied to quarantine 20:59:18.0045 1588 \Device\Harddisk0\DR0 - copied to quarantine 20:59:18.0076 1588 \Device\Harddisk0\DR0\TDLFS\ldrm - copied to quarantine 20:59:18.0076 1588 \Device\Harddisk0\DR0\TDLFS\cmd.dll - copied to quarantine 20:59:18.0076 1588 \Device\Harddisk0\DR0\TDLFS\cmd64.dll - copied to quarantine 20:59:18.0076 1588 \Device\Harddisk0\DR0\TDLFS\sub.dll - copied to quarantine 20:59:18.0091 1588 \Device\Harddisk0\DR0\TDLFS\subx.dll - copied to quarantine 20:59:18.0091 1588 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\servers.dat - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\config.ini - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\ldr16 - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\s - copied to quarantine 20:59:18.0107 1588 \Device\Harddisk0\DR0\TDLFS\u - copied to quarantine 20:59:18.0138 1588 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - will be cured on reboot 20:59:18.0138 1588 \Device\Harddisk0\DR0 - ok 20:59:18.0138 1588 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - User select action: Cure 20:59:31.0414 1348 Deinitialize success