19:22:13.0253 3560 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 19:22:13.0349 3560 ============================================================ 19:22:13.0349 3560 Current date / time: 2012/09/09 19:22:13.0349 19:22:13.0349 3560 SystemInfo: 19:22:13.0349 3560 19:22:13.0349 3560 OS Version: 6.0.6002 ServicePack: 2.0 19:22:13.0350 3560 Product type: Workstation 19:22:13.0350 3560 ComputerName: KRZYSZTOF-PC 19:22:13.0350 3560 UserName: Krzysztof_2 19:22:13.0350 3560 Windows directory: C:\Windows 19:22:13.0350 3560 System windows directory: C:\Windows 19:22:13.0350 3560 Processor architecture: Intel x86 19:22:13.0350 3560 Number of processors: 2 19:22:13.0350 3560 Page size: 0x1000 19:22:13.0350 3560 Boot type: Normal boot 19:22:13.0350 3560 ============================================================ 19:22:14.0442 3560 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 19:22:14.0455 3560 ============================================================ 19:22:14.0455 3560 \Device\Harddisk0\DR0: 19:22:14.0455 3560 MBR partitions: 19:22:14.0455 3560 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C3D81 19:22:14.0455 3560 ============================================================ 19:22:14.0475 3560 C: <-> \Device\Harddisk0\DR0\Partition1 19:22:14.0476 3560 ============================================================ 19:22:14.0476 3560 Initialize success 19:22:14.0476 3560 ============================================================ 19:31:33.0022 1128 ============================================================ 19:31:33.0022 1128 Scan started 19:31:33.0022 1128 Mode: Manual; 19:31:33.0022 1128 ============================================================ 19:31:33.0319 1128 ================ Scan system memory ======================== 19:31:33.0319 1128 System memory - ok 19:31:33.0319 1128 ================ Scan services ============================= 19:31:33.0416 1128 [ 03E71A46342BF7FC5A44C890E9FAB0D5 ] AAMWRegFilter C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Regfilter32.sys 19:31:33.0471 1128 AAMWRegFilter - ok 19:31:33.0531 1128 [ 3D41392C1AF4452EF8742A6B99224C71 ] AAMWService C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_Service.exe 19:31:33.0553 1128 AAMWService - ok 19:31:33.0580 1128 [ EA87DF1A0D4287DB88DEBE30E449514F ] AAMW_WSC_Service_Vista C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_WSC_Service_Vista.exe 19:31:33.0659 1128 AAMW_WSC_Service_Vista - ok 19:31:33.0766 1128 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys 19:31:33.0773 1128 ACPI - ok 19:31:33.0829 1128 [ B01A51996A3251023A5FD19FC88F5057 ] ADIHdAudAddService C:\Windows\system32\drivers\ADIHdAud.sys 19:31:33.0839 1128 ADIHdAudAddService - ok 19:31:33.0929 1128 [ 63AB43534CBF5D7F3EB81DFDC8161490 ] AdobeActiveFileMonitor5.0 C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe 19:31:34.0015 1128 AdobeActiveFileMonitor5.0 - ok 19:31:34.0089 1128 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 19:31:34.0192 1128 AdobeARMservice - ok 19:31:34.0246 1128 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 19:31:34.0447 1128 AdobeFlashPlayerUpdateSvc - ok 19:31:34.0495 1128 [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 19:31:34.0507 1128 adp94xx - ok 19:31:34.0534 1128 [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci C:\Windows\system32\drivers\adpahci.sys 19:31:34.0543 1128 adpahci - ok 19:31:34.0563 1128 [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 19:31:34.0569 1128 adpu160m - ok 19:31:34.0592 1128 [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320 C:\Windows\system32\drivers\adpu320.sys 19:31:34.0598 1128 adpu320 - ok 19:31:34.0638 1128 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 19:31:34.0639 1128 AeLookupSvc - ok 19:31:34.0683 1128 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys 19:31:34.0692 1128 AFD - ok 19:31:34.0737 1128 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys 19:31:34.0833 1128 aic78xx - ok 19:31:34.0864 1128 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe 19:31:34.0867 1128 ALG - ok 19:31:34.0889 1128 [ 90395B64600EBB4552E26E178C94B2E4 ] aliide C:\Windows\system32\drivers\aliide.sys 19:31:34.0938 1128 aliide - ok 19:31:34.0971 1128 [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp C:\Windows\system32\drivers\amdagp.sys 19:31:35.0054 1128 amdagp - ok 19:31:35.0069 1128 [ 0577DF1D323FE75A739C787893D300EA ] amdide C:\Windows\system32\drivers\amdide.sys 19:31:35.0121 1128 amdide - ok 19:31:35.0144 1128 [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys 19:31:35.0187 1128 AmdK7 - ok 19:31:35.0207 1128 [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 19:31:35.0250 1128 AmdK8 - ok 19:31:35.0288 1128 [ 868AE6FA93C29C8A105539F3E6D5A77F ] Amfilter C:\Windows\system32\DRIVERS\Amfilter.sys 19:31:35.0334 1128 Amfilter - ok 19:31:35.0390 1128 [ 4C7C8F1678E516A961CD79A1CA0A0C82 ] Amps2prt C:\Windows\system32\DRIVERS\Amps2prt.sys 19:31:35.0441 1128 Amps2prt - ok 19:31:35.0464 1128 [ D627AEB90B9FDF921B85942BA3EBBE85 ] Amusbprt C:\Windows\system32\DRIVERS\Amusbprt.sys 19:31:35.0516 1128 Amusbprt - ok 19:31:35.0589 1128 [ DFAE18C675D71FD06D57DC69D2913975 ] AppHostSvc C:\Windows\system32\inetsrv\apphostsvc.dll 19:31:35.0591 1128 AppHostSvc - ok 19:31:35.0637 1128 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll 19:31:35.0639 1128 Appinfo - ok 19:31:35.0710 1128 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 19:31:36.0060 1128 Apple Mobile Device - ok 19:31:36.0086 1128 [ 5F673180268BB1FDB69C99B6619FE379 ] arc C:\Windows\system32\drivers\arc.sys 19:31:36.0166 1128 arc - ok 19:31:36.0196 1128 [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas C:\Windows\system32\drivers\arcsas.sys 19:31:36.0278 1128 arcsas - ok 19:31:36.0305 1128 [ 18E421CE7AEBE59F6383E635728BC714 ] ASW3Scan C:\Program Files\Ashampoo\Ashampoo Anti-Malware\AAMW_IFS32.sys 19:31:36.0306 1128 ASW3Scan - ok 19:31:36.0341 1128 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 19:31:36.0392 1128 AsyncMac - ok 19:31:36.0408 1128 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys 19:31:36.0409 1128 atapi - ok 19:31:36.0456 1128 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 19:31:36.0462 1128 AudioEndpointBuilder - ok 19:31:36.0472 1128 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll 19:31:36.0475 1128 Audiosrv - ok 19:31:36.0504 1128 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys 19:31:36.0554 1128 Beep - ok 19:31:36.0564 1128 blbdrive - ok 19:31:36.0582 1128 BlueletAudio - ok 19:31:36.0592 1128 BlueletSCOAudio - ok 19:31:36.0658 1128 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 19:31:36.0922 1128 Bonjour Service - ok 19:31:36.0943 1128 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys 19:31:37.0029 1128 bowser - ok 19:31:37.0071 1128 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 19:31:37.0123 1128 BrFiltLo - ok 19:31:37.0139 1128 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 19:31:37.0186 1128 BrFiltUp - ok 19:31:37.0210 1128 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll 19:31:37.0213 1128 Browser - ok 19:31:37.0236 1128 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys 19:31:37.0331 1128 Brserid - ok 19:31:37.0350 1128 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 19:31:37.0354 1128 BrSerWdm - ok 19:31:37.0374 1128 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 19:31:37.0428 1128 BrUsbMdm - ok 19:31:37.0450 1128 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 19:31:37.0503 1128 BrUsbSer - ok 19:31:37.0513 1128 BT - ok 19:31:37.0531 1128 Btcsrusb - ok 19:31:37.0562 1128 [ 5EAB553A9F317B07D7A5912FF182357C ] BthAvrcp C:\Windows\system32\DRIVERS\BthAvrcp.sys 19:31:37.0614 1128 BthAvrcp - ok 19:31:37.0657 1128 [ 6D39C954799B63BA866910234CF7D726 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys 19:31:37.0714 1128 BthEnum - ok 19:31:37.0733 1128 BTHidEnum - ok 19:31:37.0742 1128 BTHidMgr - ok 19:31:37.0784 1128 [ 9A966A8E86D1771911AE34A20D11BFF3 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 19:31:37.0870 1128 BTHMODEM - ok 19:31:37.0900 1128 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 19:31:38.0001 1128 BthPan - ok 19:31:38.0071 1128 [ 611FF3F2F095C8D4A6D4CFD9DCC09793 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys 19:31:38.0092 1128 BTHPORT - ok 19:31:38.0119 1128 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll 19:31:38.0121 1128 BthServ - ok 19:31:38.0146 1128 [ D330803EAB2A15CAEC7F011F1D4CB30E ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys 19:31:38.0215 1128 BTHUSB - ok 19:31:38.0250 1128 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 19:31:38.0344 1128 cdfs - ok 19:31:38.0369 1128 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 19:31:38.0373 1128 cdrom - ok 19:31:38.0417 1128 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll 19:31:38.0419 1128 CertPropSvc - ok 19:31:38.0440 1128 [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass C:\Windows\system32\drivers\circlass.sys 19:31:38.0474 1128 circlass - ok 19:31:38.0499 1128 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys 19:31:38.0506 1128 CLFS - ok 19:31:38.0562 1128 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 19:31:38.0636 1128 clr_optimization_v2.0.50727_32 - ok 19:31:38.0698 1128 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 19:31:38.0755 1128 clr_optimization_v4.0.30319_32 - ok 19:31:38.0773 1128 [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide C:\Windows\system32\drivers\cmdide.sys 19:31:38.0832 1128 cmdide - ok 19:31:38.0860 1128 [ 82B8C91D327CFECF76CB58716F7D4997 ] Compbatt C:\Windows\system32\drivers\compbatt.sys 19:31:38.0913 1128 Compbatt - ok 19:31:38.0930 1128 COMSysApp - ok 19:31:38.0953 1128 [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 19:31:39.0005 1128 crcdisk - ok 19:31:39.0023 1128 [ 22A7F883508176489F559EE745B5BF5D ] Crusoe C:\Windows\system32\drivers\crusoe.sys 19:31:39.0067 1128 Crusoe - ok 19:31:39.0104 1128 [ 75C6A297E364014840B48ECCD7525E30 ] CryptSvc C:\Windows\system32\cryptsvc.dll 19:31:39.0107 1128 CryptSvc - ok 19:31:39.0157 1128 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll 19:31:39.0167 1128 DcomLaunch - ok 19:31:39.0197 1128 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys 19:31:39.0296 1128 DfsC - ok 19:31:39.0384 1128 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe 19:31:39.0442 1128 DFSR - ok 19:31:39.0488 1128 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll 19:31:39.0492 1128 Dhcp - ok 19:31:39.0534 1128 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys 19:31:39.0617 1128 disk - ok 19:31:39.0651 1128 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll 19:31:39.0654 1128 Dnscache - ok 19:31:39.0675 1128 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll 19:31:39.0680 1128 dot3svc - ok 19:31:39.0708 1128 [ 4F59C172C094E1A1D46463A8DC061CBD ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 19:31:39.0713 1128 Dot4 - ok 19:31:39.0734 1128 [ 80BF3BA09F6F2523C8F6B7CC6DBF7BD5 ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 19:31:39.0795 1128 Dot4Print - ok 19:31:39.0821 1128 [ C55004CA6B419B6695970DFE849B122F ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 19:31:39.0896 1128 dot4usb - ok 19:31:39.0921 1128 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll 19:31:39.0924 1128 DPS - ok 19:31:39.0964 1128 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 19:31:40.0007 1128 drmkaud - ok 19:31:40.0045 1128 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 19:31:40.0061 1128 DXGKrnl - ok 19:31:40.0106 1128 [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys 19:31:40.0122 1128 E1G60 - ok 19:31:40.0147 1128 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll 19:31:40.0150 1128 EapHost - ok 19:31:40.0197 1128 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys 19:31:40.0202 1128 Ecache - ok 19:31:40.0251 1128 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 19:31:40.0259 1128 ehRecvr - ok 19:31:40.0281 1128 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe 19:31:40.0286 1128 ehSched - ok 19:31:40.0301 1128 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll 19:31:40.0400 1128 ehstart - ok 19:31:40.0437 1128 [ E8F3F21A71720C84BCF423B80028359F ] elxstor C:\Windows\system32\drivers\elxstor.sys 19:31:40.0446 1128 elxstor - ok 19:31:40.0491 1128 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll 19:31:40.0502 1128 EMDMgmt - ok 19:31:40.0534 1128 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll 19:31:40.0539 1128 EventSystem - ok 19:31:40.0592 1128 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys 19:31:40.0700 1128 exfat - ok 19:31:40.0729 1128 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys 19:31:40.0734 1128 fastfat - ok 19:31:40.0757 1128 [ 63BDADA84951B9C03E641800E176898A ] fdc C:\Windows\system32\DRIVERS\fdc.sys 19:31:40.0817 1128 fdc - ok 19:31:40.0843 1128 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll 19:31:40.0845 1128 fdPHost - ok 19:31:40.0877 1128 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll 19:31:40.0879 1128 FDResPub - ok 19:31:40.0920 1128 [ B2B2C38E916184FF8523C7439DDD417F ] FETNDIS C:\Windows\system32\DRIVERS\fetnd5.sys 19:31:40.0985 1128 FETNDIS - ok 19:31:41.0029 1128 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 19:31:41.0118 1128 FileInfo - ok 19:31:41.0145 1128 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys 19:31:41.0207 1128 Filetrace - ok 19:31:41.0234 1128 [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 19:31:41.0295 1128 flpydisk - ok 19:31:41.0326 1128 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 19:31:41.0332 1128 FltMgr - ok 19:31:41.0397 1128 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll 19:31:41.0413 1128 FontCache - ok 19:31:41.0459 1128 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 19:31:41.0479 1128 FontCache3.0.0.0 - ok 19:31:41.0500 1128 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 19:31:41.0558 1128 Fs_Rec - ok 19:31:41.0585 1128 [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 19:31:41.0664 1128 gagp30kx - ok 19:31:41.0704 1128 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\Drivers\GEARAspiWDM.sys 19:31:41.0763 1128 GEARAspiWDM - ok 19:31:41.0801 1128 [ 007AEA2E06E7CEF7372E40C277163959 ] ggflt C:\Windows\system32\DRIVERS\ggflt.sys 19:31:41.0818 1128 ggflt - ok 19:31:41.0843 1128 [ C73DE35960CA75C5AB4AE636B127C64E ] ggsemc C:\Windows\system32\DRIVERS\ggsemc.sys 19:31:41.0867 1128 ggsemc - ok 19:31:41.0906 1128 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll 19:31:41.0918 1128 gpsvc - ok 19:31:41.0982 1128 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 19:31:41.0984 1128 gupdate - ok 19:31:42.0004 1128 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 19:31:42.0006 1128 gupdatem - ok 19:31:42.0061 1128 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 19:31:42.0069 1128 gusvc - ok 19:31:42.0107 1128 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 19:31:42.0114 1128 HdAudAddService - ok 19:31:42.0152 1128 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 19:31:42.0181 1128 HDAudBus - ok 19:31:42.0210 1128 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys 19:31:42.0282 1128 HidBth - ok 19:31:42.0295 1128 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys 19:31:42.0362 1128 HidIr - ok 19:31:42.0386 1128 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll 19:31:42.0388 1128 hidserv - ok 19:31:42.0411 1128 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 19:31:42.0481 1128 HidUsb - ok 19:31:42.0505 1128 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll 19:31:42.0510 1128 hkmsvc - ok 19:31:42.0526 1128 [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 19:31:42.0605 1128 HpCISSs - ok 19:31:42.0692 1128 [ 38D6B51F04DEF7FB248FA56E4C47407E ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll 19:31:42.0697 1128 hpqcxs08 - ok 19:31:42.0712 1128 [ 3EE4A63539EC04EE2D4BD293985087AB ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll 19:31:42.0885 1128 hpqddsvc - ok 19:31:42.0916 1128 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys 19:31:42.0927 1128 HTTP - ok 19:31:42.0951 1128 [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp C:\Windows\system32\drivers\i2omp.sys 19:31:43.0011 1128 i2omp - ok 19:31:43.0054 1128 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 19:31:43.0127 1128 i8042prt - ok 19:31:43.0153 1128 [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 19:31:43.0160 1128 iaStorV - ok 19:31:43.0217 1128 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 19:31:43.0238 1128 idsvc - ok 19:31:43.0261 1128 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys 19:31:43.0327 1128 iirsp - ok 19:31:43.0380 1128 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll 19:31:43.0388 1128 IKEEXT - ok 19:31:43.0431 1128 [ 97469037714070E45194ED318D636401 ] intelide C:\Windows\system32\drivers\intelide.sys 19:31:43.0477 1128 intelide - ok 19:31:43.0519 1128 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 19:31:43.0552 1128 intelppm - ok 19:31:43.0581 1128 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 19:31:43.0584 1128 IPBusEnum - ok 19:31:43.0612 1128 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 19:31:43.0687 1128 IpFilterDriver - ok 19:31:43.0695 1128 IpInIp - ok 19:31:43.0730 1128 [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 19:31:43.0759 1128 IPMIDRV - ok 19:31:43.0783 1128 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 19:31:43.0787 1128 IPNAT - ok 19:31:43.0849 1128 [ E6BE7A41A28D8F2DB174957454D32448 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 19:31:44.0219 1128 iPod Service - ok 19:31:44.0238 1128 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 19:31:44.0289 1128 IRENUM - ok 19:31:44.0317 1128 [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp C:\Windows\system32\drivers\isapnp.sys 19:31:44.0399 1128 isapnp - ok 19:31:44.0432 1128 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 19:31:44.0438 1128 iScsiPrt - ok 19:31:44.0453 1128 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 19:31:44.0518 1128 iteatapi - ok 19:31:44.0548 1128 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys 19:31:44.0613 1128 iteraid - ok 19:31:44.0638 1128 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 19:31:44.0708 1128 kbdclass - ok 19:31:44.0733 1128 [ EDE59EC70E25C24581ADD1FBEC7325F7 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 19:31:44.0786 1128 kbdhid - ok 19:31:44.0804 1128 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe 19:31:44.0842 1128 KeyIso - ok 19:31:44.0870 1128 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 19:31:44.0882 1128 KSecDD - ok 19:31:44.0933 1128 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll 19:31:44.0941 1128 KtmRm - ok 19:31:44.0982 1128 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll 19:31:44.0987 1128 LanmanServer - ok 19:31:45.0033 1128 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 19:31:45.0040 1128 LanmanWorkstation - ok 19:31:45.0066 1128 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 19:31:45.0070 1128 lltdio - ok 19:31:45.0109 1128 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll 19:31:45.0114 1128 lltdsvc - ok 19:31:45.0137 1128 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll 19:31:45.0141 1128 lmhosts - ok 19:31:45.0166 1128 [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 19:31:45.0252 1128 LSI_FC - ok 19:31:45.0266 1128 [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 19:31:45.0356 1128 LSI_SAS - ok 19:31:45.0386 1128 [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 19:31:45.0473 1128 LSI_SCSI - ok 19:31:45.0500 1128 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys 19:31:45.0590 1128 luafv - ok 19:31:45.0607 1128 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 19:31:45.0610 1128 Mcx2Svc - ok 19:31:45.0645 1128 [ D153B14FC6598EAE8422A2037553ADCE ] megasas C:\Windows\system32\drivers\megasas.sys 19:31:45.0703 1128 megasas - ok 19:31:45.0735 1128 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll 19:31:45.0744 1128 MMCSS - ok 19:31:45.0771 1128 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys 19:31:45.0834 1128 Modem - ok 19:31:45.0874 1128 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 19:31:45.0915 1128 monitor - ok 19:31:45.0929 1128 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 19:31:45.0985 1128 mouclass - ok 19:31:46.0013 1128 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 19:31:46.0064 1128 mouhid - ok 19:31:46.0093 1128 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 19:31:46.0165 1128 MountMgr - ok 19:31:46.0201 1128 [ E8D79312373F254DC13F3965BDB3D521 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 19:31:46.0292 1128 MozillaMaintenance - ok 19:31:46.0336 1128 [ 583A41F26278D9E0EA548163D6139397 ] mpio C:\Windows\system32\drivers\mpio.sys 19:31:46.0355 1128 mpio - ok 19:31:46.0386 1128 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 19:31:46.0459 1128 mpsdrv - ok 19:31:46.0476 1128 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 19:31:46.0534 1128 Mraid35x - ok 19:31:46.0563 1128 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 19:31:46.0670 1128 MRxDAV - ok 19:31:46.0697 1128 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 19:31:46.0835 1128 mrxsmb - ok 19:31:46.0863 1128 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 19:31:46.0870 1128 mrxsmb10 - ok 19:31:46.0881 1128 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 19:31:46.0991 1128 mrxsmb20 - ok 19:31:47.0022 1128 [ 742AED7939E734C36B7E8D6228CE26B7 ] msahci C:\Windows\system32\drivers\msahci.sys 19:31:47.0075 1128 msahci - ok 19:31:47.0095 1128 [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm C:\Windows\system32\drivers\msdsm.sys 19:31:47.0189 1128 msdsm - ok 19:31:47.0222 1128 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe 19:31:47.0277 1128 MSDTC - ok 19:31:47.0336 1128 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys 19:31:47.0339 1128 Msfs - ok 19:31:47.0370 1128 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 19:31:47.0386 1128 msisadrv - ok 19:31:47.0410 1128 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 19:31:47.0414 1128 MSiSCSI - ok 19:31:47.0424 1128 msiserver - ok 19:31:47.0452 1128 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 19:31:47.0506 1128 MSKSSRV - ok 19:31:47.0519 1128 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 19:31:47.0571 1128 MSPCLOCK - ok 19:31:47.0593 1128 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 19:31:47.0637 1128 MSPQM - ok 19:31:47.0658 1128 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 19:31:47.0664 1128 MsRPC - ok 19:31:47.0680 1128 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 19:31:47.0737 1128 mssmbios - ok 19:31:47.0756 1128 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 19:31:47.0801 1128 MSTEE - ok 19:31:47.0834 1128 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys 19:31:47.0850 1128 MTsensor - ok 19:31:47.0875 1128 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys 19:31:47.0949 1128 Mup - ok 19:31:47.0983 1128 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll 19:31:47.0990 1128 napagent - ok 19:31:48.0032 1128 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 19:31:48.0037 1128 NativeWifiP - ok 19:31:48.0068 1128 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys 19:31:48.0082 1128 NDIS - ok 19:31:48.0108 1128 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 19:31:48.0164 1128 NdisTapi - ok 19:31:48.0188 1128 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 19:31:48.0242 1128 Ndisuio - ok 19:31:48.0264 1128 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 19:31:48.0269 1128 NdisWan - ok 19:31:48.0291 1128 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 19:31:48.0376 1128 NDProxy - ok 19:31:48.0458 1128 [ 78073F606AE3B24F6C1F555759AA8511 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 19:31:48.0960 1128 Nero BackItUp Scheduler 3 - ok 19:31:49.0012 1128 [ 2969D26EEE289BE7422AA46FC55F4E38 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 19:31:49.0015 1128 Net Driver HPZ12 - ok 19:31:49.0034 1128 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 19:31:49.0108 1128 NetBIOS - ok 19:31:49.0142 1128 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 19:31:49.0149 1128 netbt - ok 19:31:49.0169 1128 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe 19:31:49.0171 1128 Netlogon - ok 19:31:49.0204 1128 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll 19:31:49.0211 1128 Netman - ok 19:31:49.0238 1128 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll 19:31:49.0245 1128 netprofm - ok 19:31:49.0268 1128 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 19:31:49.0308 1128 NetTcpPortSharing - ok 19:31:49.0335 1128 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 19:31:49.0412 1128 nfrd960 - ok 19:31:49.0440 1128 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll 19:31:49.0445 1128 NlaSvc - ok 19:31:49.0528 1128 [ 62F68443D244024845B875B44D76A92F ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 19:31:50.0113 1128 NMIndexingService - ok 19:31:50.0131 1128 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys 19:31:50.0199 1128 Npfs - ok 19:31:50.0229 1128 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll 19:31:50.0231 1128 nsi - ok 19:31:50.0255 1128 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 19:31:50.0306 1128 nsiproxy - ok 19:31:50.0359 1128 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 19:31:50.0395 1128 Ntfs - ok 19:31:50.0422 1128 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys 19:31:50.0485 1128 ntrigdigi - ok 19:31:50.0509 1128 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys 19:31:50.0553 1128 Null - ok 19:31:50.0873 1128 [ F452E6AD3EDA2852F44BE492E283C40F ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 19:31:51.0798 1128 nvlddmkm - ok 19:31:51.0824 1128 [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid C:\Windows\system32\drivers\nvraid.sys 19:31:51.0828 1128 nvraid - ok 19:31:51.0842 1128 [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor C:\Windows\system32\drivers\nvstor.sys 19:31:51.0917 1128 nvstor - ok 19:31:51.0975 1128 [ 70145ADE9EFE2CE296DD5FC761B4969B ] nvsvc C:\Windows\system32\nvvsvc.exe 19:31:52.0344 1128 nvsvc - ok 19:31:52.0455 1128 [ A19BBE1E3E3FEF50B94CA07DCC0FB776 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 19:31:52.0873 1128 nvUpdatusService - ok 19:31:52.0893 1128 [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 19:31:52.0979 1128 nv_agp - ok 19:31:52.0988 1128 NwlnkFlt - ok 19:31:52.0996 1128 NwlnkFwd - ok 19:31:53.0041 1128 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 19:31:53.0113 1128 ohci1394 - ok 19:31:53.0162 1128 [ DA345DE3B450E9E1691E7B9956D8FFC3 ] OMSI download service C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe 19:31:53.0263 1128 OMSI download service - ok 19:31:53.0308 1128 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll 19:31:53.0322 1128 p2pimsvc - ok 19:31:53.0339 1128 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll 19:31:53.0348 1128 p2psvc - ok 19:31:53.0376 1128 [ 8A79FDF04A73428597E2CAF9D0D67850 ] Parport C:\Windows\system32\DRIVERS\parport.sys 19:31:53.0380 1128 Parport - ok 19:31:53.0404 1128 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys 19:31:53.0480 1128 partmgr - ok 19:31:53.0496 1128 [ 6C580025C81CAF3AE9E3617C22CAD00E ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 19:31:53.0544 1128 Parvdm - ok 19:31:53.0568 1128 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll 19:31:53.0572 1128 PcaSvc - ok 19:31:53.0596 1128 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys 19:31:53.0602 1128 pci - ok 19:31:53.0615 1128 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys 19:31:53.0657 1128 pciide - ok 19:31:53.0690 1128 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 19:31:53.0696 1128 pcmcia - ok 19:31:53.0742 1128 [ 5B6C11DE7E839C05248CED8825470FEF ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys 19:31:53.0817 1128 pcouffin - ok 19:31:53.0873 1128 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 19:31:53.0894 1128 PEAUTH - ok 19:31:53.0971 1128 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll 19:31:53.0999 1128 pla - ok 19:31:54.0030 1128 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\system32\IoctlSvc.exe 19:31:54.0132 1128 PLFlash DeviceIoControl Service - ok 19:31:54.0158 1128 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll 19:31:54.0165 1128 PlugPlay - ok 19:31:54.0191 1128 [ BAFC9706BDF425A02B66468AB2605C59 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 19:31:54.0194 1128 Pml Driver HPZ12 - ok 19:31:54.0225 1128 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 19:31:54.0234 1128 PNRPAutoReg - ok 19:31:54.0251 1128 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll 19:31:54.0260 1128 PNRPsvc - ok 19:31:54.0286 1128 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 19:31:54.0294 1128 PolicyAgent - ok 19:31:54.0328 1128 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 19:31:54.0428 1128 PptpMiniport - ok 19:31:54.0449 1128 [ 0E3CEF5D28B40CF273281D620C50700A ] Processor C:\Windows\system32\drivers\processr.sys 19:31:54.0495 1128 Processor - ok 19:31:54.0522 1128 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll 19:31:54.0528 1128 ProfSvc - ok 19:31:54.0543 1128 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe 19:31:54.0545 1128 ProtectedStorage - ok 19:31:54.0588 1128 [ 64E413BA0C529AA40C3924BBCC4153DB ] ProtexisLicensing C:\Windows\system32\PSIService.exe 19:31:54.0599 1128 ProtexisLicensing - ok 19:31:54.0629 1128 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys 19:31:54.0633 1128 PSched - ok 19:31:54.0675 1128 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys 19:31:54.0749 1128 PxHelp20 - ok 19:31:54.0792 1128 [ CCDAC889326317792480C0A67156A1EC ] ql2300 C:\Windows\system32\drivers\ql2300.sys 19:31:54.0813 1128 ql2300 - ok 19:31:54.0843 1128 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 19:31:54.0850 1128 ql40xx - ok 19:31:54.0884 1128 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll 19:31:54.0891 1128 QWAVE - ok 19:31:54.0912 1128 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 19:31:54.0915 1128 QWAVEdrv - ok 19:31:54.0937 1128 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 19:31:54.0940 1128 RasAcd - ok 19:31:54.0965 1128 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll 19:31:54.0970 1128 RasAuto - ok 19:31:54.0999 1128 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 19:31:55.0003 1128 Rasl2tp - ok 19:31:55.0030 1128 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll 19:31:55.0037 1128 RasMan - ok 19:31:55.0067 1128 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 19:31:55.0151 1128 RasPppoe - ok 19:31:55.0183 1128 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 19:31:55.0275 1128 RasSstp - ok 19:31:55.0310 1128 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 19:31:55.0317 1128 rdbss - ok 19:31:55.0342 1128 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 19:31:55.0390 1128 RDPCDD - ok 19:31:55.0419 1128 [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 19:31:55.0427 1128 rdpdr - ok 19:31:55.0438 1128 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 19:31:55.0483 1128 RDPENCDD - ok 19:31:55.0517 1128 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 19:31:55.0523 1128 RDPWD - ok 19:31:55.0550 1128 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll 19:31:55.0554 1128 RemoteAccess - ok 19:31:55.0584 1128 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll 19:31:55.0589 1128 RemoteRegistry - ok 19:31:55.0621 1128 [ 6482707F9F4DA0ECBAB43B2E0398A101 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 19:31:55.0626 1128 RFCOMM - ok 19:31:55.0659 1128 [ 75E8A6BFA7374ABA833AE92BF41AE4E6 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys 19:31:55.0706 1128 ROOTMODEM - ok 19:31:55.0724 1128 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe 19:31:55.0759 1128 RpcLocator - ok 19:31:55.0789 1128 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll 19:31:55.0796 1128 RpcSs - ok 19:31:55.0824 1128 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 19:31:55.0916 1128 rspndr - ok 19:31:55.0961 1128 [ 59509AD6CBC28F2C73056268985B3E48 ] s0016bus C:\Windows\system32\DRIVERS\s0016bus.sys 19:31:56.0022 1128 s0016bus - ok 19:31:56.0048 1128 [ B98C3A6F91F4FBA285AF9606A240C6B4 ] s0016mdfl C:\Windows\system32\DRIVERS\s0016mdfl.sys 19:31:56.0066 1128 s0016mdfl - ok 19:31:56.0097 1128 [ 8A83426F4FB7B5212825D9DE76368B1A ] s0016mdm C:\Windows\system32\DRIVERS\s0016mdm.sys 19:31:56.0185 1128 s0016mdm - ok 19:31:56.0219 1128 [ 7A78BBA97FEB5E6D24C49E93A3BF7287 ] s0016mgmt C:\Windows\system32\DRIVERS\s0016mgmt.sys 19:31:56.0304 1128 s0016mgmt - ok 19:31:56.0332 1128 [ 34EF7B5F611957B73E7219DD5A222AD1 ] s0016nd5 C:\Windows\system32\DRIVERS\s0016nd5.sys 19:31:56.0361 1128 s0016nd5 - ok 19:31:56.0384 1128 [ 36792935847143E4A3CDA0DC87248487 ] s0016obex C:\Windows\system32\DRIVERS\s0016obex.sys 19:31:56.0462 1128 s0016obex - ok 19:31:56.0491 1128 [ 927208754FB27FC3E7A659E77500C5D1 ] s0016unic C:\Windows\system32\DRIVERS\s0016unic.sys 19:31:56.0580 1128 s0016unic - ok 19:31:56.0614 1128 [ 20EB79FD0A13A18B70B6731A1285CA94 ] s1039bus C:\Windows\system32\DRIVERS\s1039bus.sys 19:31:56.0680 1128 s1039bus - ok 19:31:56.0711 1128 [ 58780C6C3AD51DA84B57D6AE42DC49CA ] s1039mdfl C:\Windows\system32\DRIVERS\s1039mdfl.sys 19:31:56.0727 1128 s1039mdfl - ok 19:31:56.0748 1128 [ 1FF8B42D1346133A945B52876376ED40 ] s1039mdm C:\Windows\system32\DRIVERS\s1039mdm.sys 19:31:56.0831 1128 s1039mdm - ok 19:31:56.0878 1128 [ F64C13C549CB4732FE99C771FA35D038 ] s1039mgmt C:\Windows\system32\DRIVERS\s1039mgmt.sys 19:31:56.0958 1128 s1039mgmt - ok 19:31:56.0979 1128 [ EC22D9BAA464A892C0637982B67292E6 ] s1039nd5 C:\Windows\system32\DRIVERS\s1039nd5.sys 19:31:57.0001 1128 s1039nd5 - ok 19:31:57.0028 1128 [ 69E9CE002E7249E61FF2EA1336C71D89 ] s1039obex C:\Windows\system32\DRIVERS\s1039obex.sys 19:31:57.0108 1128 s1039obex - ok 19:31:57.0140 1128 [ 482DFB3721A0DE11CC22B439D17C348C ] s1039unic C:\Windows\system32\DRIVERS\s1039unic.sys 19:31:57.0223 1128 s1039unic - ok 19:31:57.0242 1128 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe 19:31:57.0244 1128 SamSs - ok 19:31:57.0271 1128 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 19:31:57.0354 1128 sbp2port - ok 19:31:57.0389 1128 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll 19:31:57.0394 1128 SCardSvr - ok 19:31:57.0434 1128 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll 19:31:57.0447 1128 Schedule - ok 19:31:57.0464 1128 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll 19:31:57.0465 1128 SCPolicySvc - ok 19:31:57.0481 1128 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll 19:31:57.0485 1128 SDRSVC - ok 19:31:57.0500 1128 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 19:31:57.0557 1128 secdrv - ok 19:31:57.0581 1128 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll 19:31:57.0585 1128 seclogon - ok 19:31:57.0630 1128 [ E5B56569A9F79B70314FEDE6C953641E ] seehcri C:\Windows\system32\DRIVERS\seehcri.sys 19:31:57.0682 1128 seehcri - ok 19:31:57.0695 1128 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll 19:31:57.0699 1128 SENS - ok 19:31:57.0724 1128 [ CE9EC966638EF0B10B864DDEDF62A099 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 19:31:57.0775 1128 Serenum - ok 19:31:57.0821 1128 [ 6D663022DB3E7058907784AE14B69898 ] Serial C:\Windows\system32\DRIVERS\serial.sys 19:31:57.0836 1128 Serial - ok 19:31:57.0848 1128 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys 19:31:57.0904 1128 sermouse - ok 19:31:57.0974 1128 [ 78546CD2ECA6DD6BDCD4B13048621F88 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 19:31:57.0982 1128 ServiceLayer - ok 19:31:58.0026 1128 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll 19:31:58.0030 1128 SessionEnv - ok 19:31:58.0053 1128 [ 103B79418DA647736EE95645F305F68A ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 19:31:58.0105 1128 sffdisk - ok 19:31:58.0121 1128 [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 19:31:58.0141 1128 sffp_mmc - ok 19:31:58.0154 1128 [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 19:31:58.0204 1128 sffp_sd - ok 19:31:58.0217 1128 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 19:31:58.0267 1128 sfloppy - ok 19:31:58.0306 1128 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 19:31:58.0312 1128 ShellHWDetection - ok 19:31:58.0337 1128 [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 19:31:58.0403 1128 SiSRaid2 - ok 19:31:58.0417 1128 [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 19:31:58.0489 1128 SiSRaid4 - ok 19:31:58.0542 1128 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 19:31:58.0549 1128 SkypeUpdate - ok 19:31:58.0658 1128 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe 19:31:58.0724 1128 slsvc - ok 19:31:58.0760 1128 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll 19:31:58.0764 1128 SLUINotify - ok 19:31:58.0786 1128 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys 19:31:58.0894 1128 Smb - ok 19:31:58.0929 1128 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 19:31:58.0933 1128 SNMPTRAP - ok 19:31:58.0959 1128 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys 19:31:59.0007 1128 spldr - ok 19:31:59.0031 1128 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe 19:31:59.0038 1128 Spooler - ok 19:31:59.0045 1128 sptd - ok 19:31:59.0074 1128 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys 19:31:59.0083 1128 srv - ok 19:31:59.0117 1128 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 19:31:59.0122 1128 srv2 - ok 19:31:59.0135 1128 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 19:31:59.0140 1128 srvnet - ok 19:31:59.0157 1128 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 19:31:59.0162 1128 SSDPSRV - ok 19:31:59.0207 1128 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll 19:31:59.0212 1128 SstpSvc - ok 19:31:59.0261 1128 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll 19:31:59.0272 1128 stisvc - ok 19:31:59.0287 1128 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 19:31:59.0336 1128 swenum - ok 19:31:59.0369 1128 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll 19:31:59.0377 1128 swprv - ok 19:31:59.0406 1128 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 19:31:59.0473 1128 Symc8xx - ok 19:31:59.0491 1128 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 19:31:59.0494 1128 Sym_hi - ok 19:31:59.0512 1128 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 19:31:59.0516 1128 Sym_u3 - ok 19:31:59.0554 1128 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll 19:31:59.0568 1128 SysMain - ok 19:31:59.0594 1128 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll 19:31:59.0600 1128 TabletInputService - ok 19:31:59.0631 1128 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll 19:31:59.0638 1128 TapiSrv - ok 19:31:59.0656 1128 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll 19:31:59.0660 1128 TBS - ok 19:31:59.0705 1128 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 19:32:09.0714 1128 Tcpip - ok 19:32:09.0839 1128 [ 27D470DABC77BC60D0A3B0E4DEB6CB91 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 19:32:19.0848 1128 Tcpip6 - ok 19:32:19.0884 1128 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 19:32:29.0036 1128 tcpipreg - ok 19:32:29.0062 1128 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 19:32:29.0124 1128 TDPIPE - ok 19:32:29.0145 1128 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 19:32:29.0215 1128 TDTCP - ok 19:32:29.0242 1128 [ DA4F9E23282EE01B439C740EB34AF368 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 19:32:29.0334 1128 Suspicious file (Forged): C:\Windows\system32\DRIVERS\tdx.sys. Real md5: DA4F9E23282EE01B439C740EB34AF368, Fake md5: 76B06EB8A01FC8624D699E7045303E54 19:32:29.0335 1128 tdx ( Virus.Win32.ZAccess.k ) - infected 19:32:29.0335 1128 tdx - detected Virus.Win32.ZAccess.k (0) 19:32:29.0365 1128 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 19:32:29.0443 1128 TermDD - ok 19:32:29.0470 1128 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll 19:32:29.0480 1128 TermService - ok 19:32:29.0500 1128 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll 19:32:29.0506 1128 Themes - ok 19:32:29.0518 1128 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll 19:32:29.0521 1128 THREADORDER - ok 19:32:29.0552 1128 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll 19:32:29.0556 1128 TrkWks - ok 19:32:29.0595 1128 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 19:32:29.0650 1128 TrustedInstaller - ok 19:32:29.0682 1128 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 19:32:29.0748 1128 tssecsrv - ok 19:32:29.0778 1128 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 19:32:29.0833 1128 tunmp - ok 19:32:29.0856 1128 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 19:32:29.0928 1128 tunnel - ok 19:32:29.0958 1128 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 19:32:30.0044 1128 uagp35 - ok 19:32:30.0074 1128 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 19:32:30.0082 1128 udfs - ok 19:32:30.0117 1128 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 19:32:30.0123 1128 UI0Detect - ok 19:32:30.0148 1128 [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 19:32:30.0238 1128 uliagpkx - ok 19:32:30.0260 1128 [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci C:\Windows\system32\drivers\uliahci.sys 19:32:30.0268 1128 uliahci - ok 19:32:30.0284 1128 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys 19:32:30.0290 1128 UlSata - ok 19:32:30.0312 1128 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 19:32:30.0317 1128 ulsata2 - ok 19:32:30.0344 1128 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 19:32:30.0388 1128 umbus - ok 19:32:30.0418 1128 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll 19:32:30.0426 1128 upnphost - ok 19:32:30.0476 1128 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 19:32:30.0575 1128 usbccgp - ok 19:32:30.0604 1128 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys 19:32:30.0646 1128 usbcir - ok 19:32:30.0673 1128 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 19:32:30.0747 1128 usbehci - ok 19:32:30.0766 1128 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 19:32:30.0772 1128 usbhub - ok 19:32:30.0794 1128 [ 38DBC7DD6CC5A72011F187425384388B ] usbohci C:\Windows\system32\drivers\usbohci.sys 19:32:30.0850 1128 usbohci - ok 19:32:30.0877 1128 [ E75C4B5269091D15A2E7DC0B6D35F2F5 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 19:32:30.0944 1128 usbprint - ok 19:32:30.0964 1128 [ A508C9BD8724980512136B039BBA65E9 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 19:32:31.0031 1128 usbscan - ok 19:32:31.0052 1128 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 19:32:31.0149 1128 USBSTOR - ok 19:32:31.0172 1128 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 19:32:31.0239 1128 usbuhci - ok 19:32:31.0285 1128 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 19:32:31.0290 1128 usbvideo - ok 19:32:31.0313 1128 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll 19:32:31.0317 1128 UxSms - ok 19:32:31.0357 1128 [ B8A50CE1D777764416446F71A9D3A3DC ] V0260VID C:\Windows\system32\DRIVERS\V0260Vid.sys 19:32:31.0425 1128 V0260VID - ok 19:32:31.0433 1128 VComm - ok 19:32:31.0443 1128 VcommMgr - ok 19:32:31.0472 1128 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe 19:32:31.0485 1128 vds - ok 19:32:31.0510 1128 [ 7D92BE0028ECDEDEC74617009084B5EF ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 19:32:31.0568 1128 vga - ok 19:32:31.0592 1128 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys 19:32:31.0648 1128 VgaSave - ok 19:32:31.0665 1128 [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp C:\Windows\system32\drivers\viaagp.sys 19:32:31.0750 1128 viaagp - ok 19:32:31.0765 1128 [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7 C:\Windows\system32\drivers\viac7.sys 19:32:31.0804 1128 ViaC7 - ok 19:32:31.0826 1128 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys 19:32:31.0872 1128 viaide - ok 19:32:31.0895 1128 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys 19:32:31.0898 1128 volmgr - ok 19:32:31.0935 1128 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 19:32:31.0943 1128 volmgrx - ok 19:32:31.0970 1128 [ 147281C01FCB1DF9252DE2A10D5E7093 ] volsnap C:\Windows\system32\drivers\volsnap.sys 19:32:31.0992 1128 volsnap - ok 19:32:32.0019 1128 [ D984439746D42B30FC65A4C3546C6829 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 19:32:32.0024 1128 vsmraid - ok 19:32:32.0074 1128 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe 19:32:32.0102 1128 VSS - ok 19:32:32.0123 1128 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll 19:32:32.0131 1128 W32Time - ok 19:32:32.0158 1128 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 19:32:32.0227 1128 WacomPen - ok 19:32:32.0250 1128 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 19:32:32.0335 1128 Wanarp - ok 19:32:32.0341 1128 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 19:32:32.0342 1128 Wanarpv6 - ok 19:32:32.0403 1128 [ 163FEC5765D0421BE8A11CACDC9534DF ] WAS C:\Windows\system32\inetsrv\iisw3adm.dll 19:32:32.0410 1128 WAS - ok 19:32:32.0439 1128 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll 19:32:32.0449 1128 wcncsvc - ok 19:32:32.0474 1128 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 19:32:32.0477 1128 WcsPlugInService - ok 19:32:32.0510 1128 [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd C:\Windows\system32\drivers\wd.sys 19:32:32.0568 1128 Wd - ok 19:32:32.0611 1128 [ B6F0A7AD6D4BD325FBCD8BAC96CD8D96 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 19:32:32.0634 1128 Wdf01000 - ok 19:32:32.0665 1128 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll 19:32:32.0671 1128 WdiServiceHost - ok 19:32:32.0679 1128 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll 19:32:32.0684 1128 WdiSystemHost - ok 19:32:32.0720 1128 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll 19:32:32.0727 1128 WebClient - ok 19:32:32.0752 1128 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll 19:32:32.0758 1128 Wecsvc - ok 19:32:32.0777 1128 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll 19:32:32.0782 1128 wercplsupport - ok 19:32:32.0814 1128 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll 19:32:32.0820 1128 WerSvc - ok 19:32:32.0828 1128 WinHttpAutoProxySvc - ok 19:32:32.0875 1128 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 19:32:32.0879 1128 Winmgmt - ok 19:32:32.0935 1128 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll 19:32:32.0959 1128 WinRM - ok 19:32:33.0003 1128 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll 19:32:33.0015 1128 Wlansvc - ok 19:32:33.0042 1128 [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 19:32:33.0097 1128 WmiAcpi - ok 19:32:33.0131 1128 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 19:32:33.0253 1128 wmiApSrv - ok 19:32:33.0316 1128 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 19:32:33.0337 1128 WMPNetworkSvc - ok 19:32:33.0370 1128 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll 19:32:33.0376 1128 WPCSvc - ok 19:32:33.0402 1128 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 19:32:33.0407 1128 WPDBusEnum - ok 19:32:33.0434 1128 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 19:32:33.0506 1128 WpdUsb - ok 19:32:33.0594 1128 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 19:32:33.0612 1128 WPFFontCache_v0400 - ok 19:32:33.0635 1128 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 19:32:33.0693 1128 ws2ifsl - ok 19:32:33.0701 1128 WSearch - ok 19:32:33.0727 1128 WTService - ok 19:32:33.0765 1128 [ AC13CB789D93412106B0FB6C7EB2BCB6 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 19:32:33.0769 1128 WUDFRd - ok 19:32:33.0797 1128 [ 575A4190D989F64732119E4114045A4F ] wudfsvc C:\Windows\System32\WUDFSvc.dll 19:32:33.0802 1128 wudfsvc - ok 19:32:33.0872 1128 ================ Scan global =============================== 19:32:33.0890 1128 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll 19:32:33.0926 1128 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 19:32:33.0947 1128 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 19:32:33.0981 1128 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe 19:32:33.0991 1128 [Global] - ok 19:32:33.0992 1128 ================ Scan MBR ================================== 19:32:34.0000 1128 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 19:32:34.0150 1128 \Device\Harddisk0\DR0 - ok 19:32:34.0151 1128 ================ Scan VBR ================================== 19:32:34.0155 1128 [ 2B583C2F05DF79CA62621EB72849894C ] \Device\Harddisk0\DR0\Partition1 19:32:34.0157 1128 \Device\Harddisk0\DR0\Partition1 - ok 19:32:34.0159 1128 ============================================================ 19:32:34.0159 1128 Scan finished 19:32:34.0159 1128 ============================================================ 19:32:34.0178 2172 Detected object count: 1 19:32:34.0178 2172 Actual detected object count: 1 19:34:35.0274 2172 C:\Windows\system32\DRIVERS\tdx.sys - copied to quarantine 19:34:37.0046 2172 C:\Windows\$NtUninstallKB13661$\1884308749\@ - copied to quarantine 19:34:37.0059 2172 C:\Windows\$NtUninstallKB13661$\1884308749\Desktop.ini - copied to quarantine 19:34:37.0073 2172 C:\Windows\$NtUninstallKB13661$\1884308749\L\00000004.@ - copied to quarantine 19:34:37.0075 2172 C:\Windows\$NtUninstallKB13661$\1884308749\L\201d3dde - copied to quarantine 19:34:37.0088 2172 C:\Windows\$NtUninstallKB13661$\1884308749\L\qnbwvoto - copied to quarantine 19:34:37.0098 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\00000004.@ - copied to quarantine 19:34:37.0117 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\00000008.@ - copied to quarantine 19:34:37.0127 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\000000cb.@ - copied to quarantine 19:34:37.0140 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\80000000.@ - copied to quarantine 19:34:37.0150 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\80000032.@ - copied to quarantine 19:34:37.0494 2172 Backup copy found, using it.. 19:34:37.0501 2172 C:\Windows\system32\DRIVERS\tdx.sys - will be cured on reboot 19:34:37.0583 2172 C:\Windows\$NtUninstallKB13661$\1884308749\@ - will be deleted on reboot 19:34:37.0584 2172 C:\Windows\$NtUninstallKB13661$\1884308749\Desktop.ini - will be deleted on reboot 19:34:37.0586 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\00000004.@ - will be deleted on reboot 19:34:37.0586 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\00000008.@ - will be deleted on reboot 19:34:37.0586 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\000000cb.@ - will be deleted on reboot 19:34:37.0587 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\80000000.@ - will be deleted on reboot 19:34:37.0587 2172 C:\Windows\$NtUninstallKB13661$\1884308749\U\80000032.@ - will be deleted on reboot 19:34:37.0588 2172 C:\Windows\$NtUninstallKB13661$\419713489 - will be deleted on reboot 19:34:37.0596 2172 tdx ( Virus.Win32.ZAccess.k ) - User select action: Cure 19:34:52.0474 2532 Deinitialize success