21:16:51.0234 0x0ddc TDSS rootkit removing tool 2.9.2.0 Aug 15 2013 16:44:29 21:16:51.0593 0x0ddc ============================================================ 21:16:51.0593 0x0ddc Current date / time: 2013/08/28 21:16:51.0593 21:16:51.0593 0x0ddc SystemInfo: 21:16:51.0593 0x0ddc 21:16:51.0593 0x0ddc OS Version: 5.1.2600 ServicePack: 3.0 21:16:51.0593 0x0ddc Product type: Workstation 21:16:51.0593 0x0ddc ComputerName: COMPUTER 21:16:51.0593 0x0ddc UserName: Administrator 21:16:51.0593 0x0ddc Windows directory: C:\WINDOWS 21:16:51.0593 0x0ddc System windows directory: C:\WINDOWS 21:16:51.0593 0x0ddc Processor architecture: Intel x86 21:16:51.0593 0x0ddc Number of processors: 4 21:16:51.0593 0x0ddc Page size: 0x1000 21:16:51.0593 0x0ddc Boot type: Normal boot 21:16:51.0593 0x0ddc ============================================================ 21:16:53.0859 0x0ddc Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 21:16:53.0875 0x0ddc ============================================================ 21:16:53.0875 0x0ddc \Device\Harddisk0\DR0: 21:16:53.0875 0x0ddc MBR partitions: 21:16:53.0875 0x0ddc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1A79AB, BlocksNum 0x9F6D8E7 21:16:53.0890 0x0ddc \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xA1152D1, BlocksNum 0x9D8F0ED 21:16:53.0890 0x0ddc \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x13EA43FD, BlocksNum 0x9CEE404 21:16:53.0906 0x0ddc \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x1DB92840, BlocksNum 0x789AE81 21:16:53.0906 0x0ddc ============================================================ 21:16:53.0968 0x0ddc C: <-> \Device\Harddisk0\DR0\Partition1 21:16:54.0046 0x0ddc D: <-> \Device\Harddisk0\DR0\Partition2 21:16:54.0203 0x0ddc E: <-> \Device\Harddisk0\DR0\Partition3 21:16:54.0375 0x0ddc F: <-> \Device\Harddisk0\DR0\Partition4 21:16:54.0375 0x0ddc ============================================================ 21:16:54.0375 0x0ddc Initialize success 21:16:54.0375 0x0ddc ============================================================ 21:17:22.0171 0x0b70 ============================================================ 21:17:22.0171 0x0b70 Scan started 21:17:22.0171 0x0b70 Mode: Manual; 21:17:22.0171 0x0b70 ============================================================ 21:17:22.0968 0x0b70 ================ Scan system memory ======================== 21:17:22.0968 0x0b70 System memory - ok 21:17:22.0968 0x0b70 ================ Scan services ============================= 21:17:23.0265 0x0b70 Abiosdsk - ok 21:17:23.0265 0x0b70 abp480n5 - ok 21:17:23.0343 0x0b70 [ 05118282F5D039595A2B92B4A4AFE197 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 21:17:23.0375 0x0b70 ACPI - ok 21:17:23.0406 0x0b70 [ 66A42B7DB194E24B973BBCCE840A0F3F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 21:17:23.0437 0x0b70 ACPIEC - ok 21:17:23.0593 0x0b70 [ 5AC144F03B31AFAB6717AD3622D1680D ] ACS C:\WINDOWS\system32\acs.exe 21:17:23.0593 0x0b70 ACS - ok 21:17:23.0843 0x0b70 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 21:17:23.0937 0x0b70 AdobeFlashPlayerUpdateSvc - ok 21:17:23.0937 0x0b70 adpu160m - ok 21:17:23.0984 0x0b70 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 21:17:24.0046 0x0b70 aec - ok 21:17:24.0109 0x0b70 [ 271FB95F02D26C0543C425D4F2530C28 ] AFD C:\WINDOWS\System32\drivers\afd.sys 21:17:24.0109 0x0b70 Suspicious file (Forged): C:\WINDOWS\System32\drivers\afd.sys. Real md5: 271FB95F02D26C0543C425D4F2530C28, Fake md5: 355556D9E580915118CD7EF736653A89 21:17:24.0109 0x0b70 AFD ( Virus.Win32.ZAccess.k ) - infected 21:17:24.0109 0x0b70 AFD - detected Virus.Win32.ZAccess.k (0) 21:17:24.0125 0x0b70 Aha154x - ok 21:17:24.0125 0x0b70 aic78u2 - ok 21:17:24.0125 0x0b70 aic78xx - ok 21:17:24.0156 0x0b70 [ 27AF056D8C42F0AB3CF1DFDCBBEB3243 ] Alerter C:\WINDOWS\system32\alrsvc.dll 21:17:24.0156 0x0b70 Alerter - ok 21:17:24.0187 0x0b70 [ D1738DDDFF196C5CEE6D867C136AF745 ] ALG C:\WINDOWS\System32\alg.exe 21:17:24.0187 0x0b70 ALG - ok 21:17:24.0203 0x0b70 AliIde - ok 21:17:24.0828 0x0b70 [ 267FC636801EDC5AB28E14036349E3BE ] Ambfilt C:\WINDOWS\system32\drivers\Ambfilt.sys 21:17:25.0328 0x0b70 Ambfilt - ok 21:17:25.0343 0x0b70 amsint - ok 21:17:25.0406 0x0b70 [ 1561430DA2F2AB81CC0CE71AF95A778D ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 21:17:25.0484 0x0b70 AppMgmt - ok 21:17:26.0203 0x0b70 [ 7141E281D840699D9D79B18F4062DD58 ] AR9271 C:\WINDOWS\system32\DRIVERS\athuw.sys 21:17:26.0812 0x0b70 AR9271 - ok 21:17:26.0812 0x0b70 asc - ok 21:17:26.0828 0x0b70 asc3350p - ok 21:17:26.0828 0x0b70 asc3550 - ok 21:17:26.0953 0x0b70 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 21:17:27.0000 0x0b70 aspnet_state - ok 21:17:27.0015 0x0b70 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 21:17:27.0046 0x0b70 AsyncMac - ok 21:17:27.0093 0x0b70 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 21:17:27.0093 0x0b70 atapi - ok 21:17:27.0093 0x0b70 Atdisk - ok 21:17:27.0187 0x0b70 [ F0D933B42CD0594048E4D5200AE9E417 ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys 21:17:27.0218 0x0b70 atksgt - ok 21:17:27.0250 0x0b70 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 21:17:27.0296 0x0b70 Atmarpc - ok 21:17:27.0328 0x0b70 [ 3A28D3E7BAD0EED3810CD918B2525B54 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 21:17:27.0328 0x0b70 AudioSrv - ok 21:17:27.0359 0x0b70 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 21:17:27.0375 0x0b70 audstub - ok 21:17:27.0406 0x0b70 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 21:17:27.0437 0x0b70 Beep - ok 21:17:27.0468 0x0b70 [ B98ED6D85339A66A73F32FB569EB6C01 ] Browser C:\WINDOWS\System32\browser.dll 21:17:27.0484 0x0b70 Browser - ok 21:17:27.0515 0x0b70 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 21:17:27.0546 0x0b70 cbidf2k - ok 21:17:27.0546 0x0b70 cd20xrnt - ok 21:17:27.0562 0x0b70 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 21:17:27.0593 0x0b70 Cdaudio - ok 21:17:27.0609 0x0b70 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 21:17:27.0656 0x0b70 Cdfs - ok 21:17:27.0781 0x0b70 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 21:17:27.0828 0x0b70 Cdrom - ok 21:17:27.0828 0x0b70 Changer - ok 21:17:27.0843 0x0b70 [ 45B63DF2FB498D219FCBB4425CADE676 ] CiSvc C:\WINDOWS\system32\cisvc.exe 21:17:27.0859 0x0b70 CiSvc - ok 21:17:27.0875 0x0b70 [ C94F1B6F61858D6389C0FA06954FB9C4 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 21:17:27.0890 0x0b70 ClipSrv - ok 21:17:27.0984 0x0b70 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 21:17:28.0046 0x0b70 clr_optimization_v2.0.50727_32 - ok 21:17:28.0125 0x0b70 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 21:17:28.0250 0x0b70 clr_optimization_v4.0.30319_32 - ok 21:17:28.0250 0x0b70 CmdIde - ok 21:17:28.0250 0x0b70 COMSysApp - ok 21:17:28.0250 0x0b70 Cpqarray - ok 21:17:28.0312 0x0b70 [ 6B105FE95F2E9F0B6346044BA59D41C9 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 21:17:28.0343 0x0b70 CryptSvc - ok 21:17:28.0343 0x0b70 dac2w2k - ok 21:17:28.0343 0x0b70 dac960nt - ok 21:17:28.0609 0x0b70 [ A37311D9D628C1042A2836731787F0F3 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 21:17:29.0125 0x0b70 DcomLaunch - ok 21:17:29.0203 0x0b70 [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 21:17:29.0296 0x0b70 Dhcp - ok 21:17:29.0312 0x0b70 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 21:17:29.0390 0x0b70 Disk - ok 21:17:29.0390 0x0b70 dmadmin - ok 21:17:29.0828 0x0b70 [ BC9219ABC5696942E6F9AC8A9B28670F ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 21:17:30.0187 0x0b70 dmboot - ok 21:17:30.0250 0x0b70 [ 5FA232E3BA6E1346F9F5A7E519320CB0 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 21:17:30.0343 0x0b70 dmio - ok 21:17:30.0390 0x0b70 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 21:17:30.0437 0x0b70 dmload - ok 21:17:30.0468 0x0b70 [ D858920A05076914D34B0388E8D96CC0 ] dmserver C:\WINDOWS\System32\dmserver.dll 21:17:30.0468 0x0b70 dmserver - ok 21:17:30.0500 0x0b70 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 21:17:30.0515 0x0b70 DMusic - ok 21:17:30.0546 0x0b70 [ 082BE13166A3354F25F78E0B2601012B ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 21:17:30.0546 0x0b70 Dnscache - ok 21:17:30.0625 0x0b70 [ E0B7D66CF29D9ADCCF873C77821CD4CA ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 21:17:30.0781 0x0b70 Dot3svc - ok 21:17:30.0796 0x0b70 dpti2o - ok 21:17:30.0812 0x0b70 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 21:17:30.0843 0x0b70 drmkaud - ok 21:17:30.0859 0x0b70 EagleNT - ok 21:17:30.0859 0x0b70 EagleXNt - ok 21:17:30.0890 0x0b70 [ 23A6E5A600D3743BE536161E9C6F2043 ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys 21:17:30.0890 0x0b70 eamon - ok 21:17:30.0921 0x0b70 [ 5F256C1AD50FEFDC442CD5AAB58C7DD8 ] EapHost C:\WINDOWS\System32\eapsvc.dll 21:17:30.0937 0x0b70 EapHost - ok 21:17:30.0968 0x0b70 [ 0ED4FA004A79E44DF4DBDC85F44FC1FD ] easdrv C:\WINDOWS\system32\DRIVERS\easdrv.sys 21:17:30.0968 0x0b70 easdrv - ok 21:17:31.0046 0x0b70 [ 70F11CE0D141C7642F38853C71F68227 ] EhttpSrv C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe 21:17:31.0046 0x0b70 EhttpSrv - ok 21:17:31.0187 0x0b70 [ F5179458B21780A88056C142F395406F ] ekrn C:\Program Files\ESET\ESET Smart Security\ekrn.exe 21:17:31.0203 0x0b70 ekrn - ok 21:17:31.0234 0x0b70 [ 448671F5E60BE264E30CD8499780D7D4 ] epfw C:\WINDOWS\system32\DRIVERS\epfw.sys 21:17:31.0234 0x0b70 epfw - ok 21:17:31.0250 0x0b70 [ 1AAE672D4ABE9460F6C7E18C9B2A660E ] Epfwndis C:\WINDOWS\system32\DRIVERS\Epfwndis.sys 21:17:31.0250 0x0b70 Epfwndis - ok 21:17:31.0281 0x0b70 [ D55A2F580BDF53C1C80CE8771FDF7C40 ] epfwtdi C:\WINDOWS\system32\DRIVERS\epfwtdi.sys 21:17:31.0312 0x0b70 epfwtdi - ok 21:17:31.0343 0x0b70 [ ED1B71382C31FD2CF3CDC4672EFAD6EA ] ERSvc C:\WINDOWS\System32\ersvc.dll 21:17:31.0390 0x0b70 ERSvc - ok 21:17:31.0437 0x0b70 [ 02A467E27AF55F7064C5B251E587315F ] Eventlog C:\WINDOWS\system32\services.exe 21:17:31.0437 0x0b70 Eventlog - ok 21:17:31.0546 0x0b70 [ 6AFF804839C85859E0247164FBE5F5BB ] EventSystem C:\WINDOWS\system32\es.dll 21:17:31.0609 0x0b70 EventSystem - ok 21:17:31.0796 0x0b70 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 21:17:31.0890 0x0b70 Fastfat - ok 21:17:31.0953 0x0b70 [ 55AAE86C7C2CADF6972ACD1D76C24A98 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 21:17:31.0984 0x0b70 FastUserSwitchingCompatibility - ok 21:17:32.0015 0x0b70 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 21:17:32.0078 0x0b70 Fdc - ok 21:17:32.0109 0x0b70 [ 09E2A4D33F81A06A8AAB2BA0A0B5D235 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 21:17:32.0156 0x0b70 Fips - ok 21:17:32.0171 0x0b70 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 21:17:32.0218 0x0b70 Flpydisk - ok 21:17:32.0281 0x0b70 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 21:17:32.0406 0x0b70 FltMgr - ok 21:17:32.0484 0x0b70 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 21:17:32.0578 0x0b70 FontCache3.0.0.0 - ok 21:17:32.0609 0x0b70 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 21:17:32.0656 0x0b70 Fs_Rec - ok 21:17:32.0812 0x0b70 [ ED6D921D8AB423138FB35BEEE6D6A6CB ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 21:17:32.0953 0x0b70 Ftdisk - ok 21:17:33.0000 0x0b70 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 21:17:33.0062 0x0b70 Gpc - ok 21:17:33.0281 0x0b70 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 21:17:33.0281 0x0b70 gupdate - ok 21:17:33.0328 0x0b70 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 21:17:33.0328 0x0b70 gupdatem - ok 21:17:33.0406 0x0b70 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\WINDOWS\system32\DRIVERS\hamachi.sys 21:17:33.0453 0x0b70 hamachi - ok 21:17:33.0546 0x0b70 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 21:17:33.0546 0x0b70 HDAudBus - ok 21:17:33.0796 0x0b70 [ AF752014F7EB61542E3F35B9374D7E76 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 21:17:33.0828 0x0b70 helpsvc - ok 21:17:33.0875 0x0b70 [ 1776C3B6069EEECC8042535296C1866A ] HidServ C:\WINDOWS\System32\hidserv.dll 21:17:33.0890 0x0b70 HidServ - ok 21:17:33.0906 0x0b70 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 21:17:33.0953 0x0b70 HidUsb - ok 21:17:34.0000 0x0b70 [ F0273916DA6FB64CC88E0BD77619554F ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 21:17:34.0046 0x0b70 hkmsvc - ok 21:17:34.0046 0x0b70 hpn - ok 21:17:34.0265 0x0b70 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 21:17:34.0265 0x0b70 HTTP - ok 21:17:34.0296 0x0b70 [ AA268079AC119F3A596E5E27AEE4BD17 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 21:17:34.0296 0x0b70 HTTPFilter - ok 21:17:34.0312 0x0b70 i2omgmt - ok 21:17:34.0312 0x0b70 i2omp - ok 21:17:34.0359 0x0b70 [ 177B372AF55C4460D0968B5F1D02AA1C ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 21:17:34.0421 0x0b70 i8042prt - ok 21:17:41.0875 0x0b70 [ 3B743262B6456167888D15F1121B3BF7 ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 21:17:45.0062 0x0b70 ialm - ok 21:17:46.0656 0x0b70 [ 02D9E857ABE06213CEC22D7A20783DB7 ] IBUpdaterService C:\Documents and Settings\All Users\Dane aplikacji\IBUpdaterService\ibsvc.exe 21:17:46.0718 0x0b70 IBUpdaterService - ok 21:17:47.0031 0x0b70 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe 21:17:47.0093 0x0b70 IDriverT - ok 21:17:49.0484 0x0b70 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 21:17:50.0453 0x0b70 idsvc - ok 21:17:50.0484 0x0b70 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 21:17:50.0531 0x0b70 Imapi - ok 21:17:50.0828 0x0b70 [ 9125AF650608A921F98A789E5C5BA864 ] ImapiService C:\WINDOWS\system32\imapi.exe 21:17:50.0968 0x0b70 ImapiService - ok 21:17:50.0968 0x0b70 ini910u - ok 21:18:01.0921 0x0b70 [ 5707CEC38DB61B96079E6A14B4702446 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 21:18:02.0125 0x0b70 IntcAzAudAddService - ok 21:18:02.0125 0x0b70 IntelIde - ok 21:18:02.0640 0x0b70 [ DA153EDC09DE8C4F846C085CAA39D1CC ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 21:18:02.0750 0x0b70 intelppm - ok 21:18:02.0953 0x0b70 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 21:18:03.0062 0x0b70 Ip6Fw - ok 21:18:03.0453 0x0b70 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 21:18:03.0562 0x0b70 IpFilterDriver - ok 21:18:05.0046 0x0b70 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 21:18:05.0109 0x0b70 IpInIp - ok 21:18:05.0812 0x0b70 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 21:18:05.0843 0x0b70 IpNat - ok 21:18:05.0921 0x0b70 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 21:18:06.0031 0x0b70 IPSec - ok 21:18:06.0062 0x0b70 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 21:18:06.0109 0x0b70 IRENUM - ok 21:18:06.0156 0x0b70 [ C8EEF2E93835B81BD335DE2123121283 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 21:18:06.0250 0x0b70 isapnp - ok 21:18:07.0109 0x0b70 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 21:18:07.0109 0x0b70 JavaQuickStarterService - ok 21:18:07.0359 0x0b70 [ FFDB868A2A069F8D58C0E9A1203378C5 ] jswpsapi C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe 21:18:07.0875 0x0b70 jswpsapi - ok 21:18:07.0953 0x0b70 [ AD67795900AA8C05CC4570F5349E0639 ] JSWSCIMD C:\WINDOWS\system32\DRIVERS\jswscimd.sys 21:18:08.0015 0x0b70 JSWSCIMD - ok 21:18:08.0062 0x0b70 [ 2AECA45D4AEAACBDCB77AD11184E4601 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 21:18:08.0109 0x0b70 Kbdclass - ok 21:18:08.0140 0x0b70 [ F718DCDDAC2544BC693F22977D06F78B ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 21:18:08.0203 0x0b70 kbdhid - ok 21:18:08.0281 0x0b70 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 21:18:08.0281 0x0b70 kmixer - ok 21:18:08.0343 0x0b70 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 21:18:08.0593 0x0b70 KSecDD - ok 21:18:08.0859 0x0b70 [ 061A4BB67C324AC8C176E0D77923B212 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 21:18:08.0921 0x0b70 lanmanserver - ok 21:18:09.0109 0x0b70 [ FA17019DA45C5D6464776A639A5A9ABB ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 21:18:09.0171 0x0b70 lanmanworkstation - ok 21:18:09.0171 0x0b70 lbrtfdc - ok 21:18:09.0234 0x0b70 [ F8A7212D0864EF5E9185FB95E6623F4D ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys 21:18:09.0250 0x0b70 lirsgt - ok 21:18:09.0281 0x0b70 [ 437AA83D68F9FAC234CA68DBD40DB705 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 21:18:09.0296 0x0b70 LmHosts - ok 21:18:09.0328 0x0b70 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 21:18:09.0343 0x0b70 MBAMProtector - ok 21:18:09.0921 0x0b70 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 21:18:10.0093 0x0b70 MBAMScheduler - ok 21:18:10.0718 0x0b70 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 21:18:11.0140 0x0b70 MBAMService - ok 21:18:11.0187 0x0b70 [ 36F3AB18B1BE303DA51DE90A67DE3942 ] Messenger C:\WINDOWS\System32\msgsvc.dll 21:18:11.0234 0x0b70 Messenger - ok 21:18:12.0046 0x0b70 [ 7C4C76B39D5525C4A465E0BE32528E19 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 21:18:12.0093 0x0b70 Microsoft Office Groove Audit Service - ok 21:18:12.0125 0x0b70 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 21:18:12.0156 0x0b70 mnmdd - ok 21:18:12.0203 0x0b70 [ 845814A8CB9D704D030F076E1BCE83F3 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 21:18:12.0218 0x0b70 mnmsrvc - ok 21:18:12.0281 0x0b70 [ 4A068DB7DC37D5AFEDB6512D2931D7B3 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 21:18:12.0328 0x0b70 Modem - ok 21:18:13.0109 0x0b70 [ C7D9F9717916B34C1B00DD4834AF485C ] Monfilt C:\WINDOWS\system32\drivers\Monfilt.sys 21:18:14.0328 0x0b70 Monfilt - ok 21:18:14.0921 0x0b70 [ FBED3DF6B884F8CF00447B73507F2C48 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 21:18:15.0000 0x0b70 Mouclass - ok 21:18:15.0031 0x0b70 [ ECEC1E6CD558AB80F944F31326E9D3B5 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 21:18:15.0062 0x0b70 mouhid - ok 21:18:15.0109 0x0b70 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 21:18:15.0171 0x0b70 MountMgr - ok 21:18:15.0312 0x0b70 [ A35576A433F4AEB0D48976A004657CB6 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 21:18:15.0453 0x0b70 MozillaMaintenance - ok 21:18:15.0453 0x0b70 mraid35x - ok 21:18:15.0625 0x0b70 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 21:18:15.0781 0x0b70 MRxDAV - ok 21:18:15.0953 0x0b70 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 21:18:16.0156 0x0b70 MRxSmb - ok 21:18:16.0171 0x0b70 [ A54C5EECC7D3424824410BAE0AA6C371 ] MSDTC C:\WINDOWS\system32\msdtc.exe 21:18:16.0187 0x0b70 MSDTC - ok 21:18:16.0203 0x0b70 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 21:18:16.0234 0x0b70 Msfs - ok 21:18:16.0250 0x0b70 MSIServer - ok 21:18:16.0265 0x0b70 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 21:18:16.0296 0x0b70 MSKSSRV - ok 21:18:16.0312 0x0b70 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 21:18:16.0343 0x0b70 MSPCLOCK - ok 21:18:16.0671 0x0b70 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 21:18:16.0718 0x0b70 MSPQM - ok 21:18:16.0734 0x0b70 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 21:18:16.0734 0x0b70 mssmbios - ok 21:18:16.0796 0x0b70 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 21:18:16.0875 0x0b70 Mup - ok 21:18:17.0000 0x0b70 [ 14CB8528E17D1221C50FC8CA88B1795F ] napagent C:\WINDOWS\System32\qagentrt.dll 21:18:17.0093 0x0b70 napagent - ok 21:18:17.0156 0x0b70 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 21:18:17.0218 0x0b70 NDIS - ok 21:18:17.0265 0x0b70 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 21:18:17.0328 0x0b70 NdisTapi - ok 21:18:17.0359 0x0b70 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 21:18:17.0562 0x0b70 Ndisuio - ok 21:18:17.0687 0x0b70 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 21:18:17.0750 0x0b70 NdisWan - ok 21:18:17.0781 0x0b70 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 21:18:17.0937 0x0b70 NDProxy - ok 21:18:18.0343 0x0b70 [ 40D7D0A208EE863BCA8D89E299216F15 ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 21:18:18.0578 0x0b70 Nero BackItUp Scheduler 3 - ok 21:18:18.0609 0x0b70 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 21:18:18.0640 0x0b70 NetBIOS - ok 21:18:18.0703 0x0b70 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 21:18:18.0781 0x0b70 NetBT - ok 21:18:19.0046 0x0b70 [ CBB409B314309FCFFCE5E682E91338C6 ] NetDDE C:\WINDOWS\system32\netdde.exe 21:18:19.0078 0x0b70 NetDDE - ok 21:18:19.0109 0x0b70 [ CBB409B314309FCFFCE5E682E91338C6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 21:18:19.0109 0x0b70 NetDDEdsdm - ok 21:18:19.0140 0x0b70 [ 88296F7943F30A1EE3AF735440B92268 ] Netlogon C:\WINDOWS\system32\lsass.exe 21:18:19.0140 0x0b70 Netlogon - ok 21:18:19.0203 0x0b70 [ 4FE97D0B1B182DF2A9BDD4C02155EF5E ] Netman C:\WINDOWS\System32\netman.dll 21:18:19.0265 0x0b70 Netman - ok 21:18:19.0328 0x0b70 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 21:18:19.0359 0x0b70 NetTcpPortSharing - ok 21:18:19.0453 0x0b70 [ 9D1F13706FB5F02D0E8795FB2D03971D ] Nla C:\WINDOWS\System32\mswsock.dll 21:18:19.0515 0x0b70 Nla - ok 21:18:19.0750 0x0b70 [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 21:18:20.0187 0x0b70 NMIndexingService - ok 21:18:20.0187 0x0b70 NOD32FiXTemDono - ok 21:18:20.0218 0x0b70 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 21:18:20.0265 0x0b70 Npfs - ok 21:18:20.0265 0x0b70 npggsvc - ok 21:18:20.0437 0x0b70 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 21:18:20.0609 0x0b70 Ntfs - ok 21:18:20.0625 0x0b70 [ 88296F7943F30A1EE3AF735440B92268 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 21:18:20.0625 0x0b70 NtLmSsp - ok 21:18:20.0781 0x0b70 [ 3FB5399DBB7001A80D58EDAD64C98225 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 21:18:21.0187 0x0b70 NtmsSvc - ok 21:18:21.0218 0x0b70 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 21:18:21.0234 0x0b70 Null - ok 21:18:24.0796 0x0b70 [ 18C9B152DA7BEA76B2F9E4B6412E0AAF ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 21:18:28.0187 0x0b70 nv - ok 21:18:28.0234 0x0b70 [ 50ACB7253D1104E5917E15A0670D63D5 ] NVHDA C:\WINDOWS\system32\drivers\nvhda32.sys 21:18:28.0265 0x0b70 NVHDA - ok 21:18:29.0421 0x0b70 [ E00696D78AF663C523D3483410C66F21 ] NVIDIA Performance Driver Service C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe 21:18:30.0500 0x0b70 NVIDIA Performance Driver Service - ok 21:18:30.0578 0x0b70 [ A8C1E6FF53FB0628A302843EA5FA5AB6 ] nvsvc C:\WINDOWS\system32\nvsvc32.exe 21:18:30.0609 0x0b70 nvsvc - ok 21:18:30.0640 0x0b70 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 21:18:30.0656 0x0b70 NwlnkFlt - ok 21:18:30.0671 0x0b70 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 21:18:30.0703 0x0b70 NwlnkFwd - ok 21:18:30.0937 0x0b70 [ 1F0E05DFF4F5A833168E49BE1256F002 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 21:18:31.0218 0x0b70 odserv - ok 21:18:31.0281 0x0b70 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 21:18:31.0312 0x0b70 ose - ok 21:18:31.0359 0x0b70 [ 45443C5E549DD0E85A79E188AA319803 ] OverwolfUpdaterService C:\Program Files\Overwolf\OverwolfUpdater.exe 21:18:31.0375 0x0b70 OverwolfUpdaterService - ok 21:18:31.0421 0x0b70 [ 2D4CDAEBCED17743AA9E25D3016DC229 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 21:18:31.0468 0x0b70 Parport - ok 21:18:31.0500 0x0b70 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 21:18:31.0531 0x0b70 PartMgr - ok 21:18:31.0562 0x0b70 [ 453EC2C2A20A1382F564541918520EEB ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 21:18:31.0578 0x0b70 ParVdm - ok 21:18:31.0609 0x0b70 [ 6862C69168D787B85A7D95CCD33C694E ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 21:18:31.0656 0x0b70 PCI - ok 21:18:31.0656 0x0b70 PCIDump - ok 21:18:31.0671 0x0b70 [ 548CF2D6369EAE441A4C6BAA75BC4F0A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 21:18:31.0703 0x0b70 PCIIde - ok 21:18:31.0734 0x0b70 [ 8DB27F1AE9593C94095485305A583862 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 21:18:31.0828 0x0b70 Pcmcia - ok 21:18:31.0828 0x0b70 PDCOMP - ok 21:18:31.0828 0x0b70 PDFRAME - ok 21:18:31.0828 0x0b70 PDRELI - ok 21:18:31.0828 0x0b70 PDRFRAME - ok 21:18:31.0828 0x0b70 perc2 - ok 21:18:31.0843 0x0b70 perc2hib - ok 21:18:31.0890 0x0b70 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\WINDOWS\system32\IoctlSvc.exe 21:18:31.0906 0x0b70 PLFlash DeviceIoControl Service - ok 21:18:31.0953 0x0b70 [ 02A467E27AF55F7064C5B251E587315F ] PlugPlay C:\WINDOWS\system32\services.exe 21:18:31.0968 0x0b70 PlugPlay - ok 21:18:32.0031 0x0b70 [ A1DD33D16F277CE34124EE52AB2C0F14 ] PnkBstrA C:\WINDOWS\system32\PnkBstrA.exe 21:18:32.0031 0x0b70 PnkBstrA - ok 21:18:32.0109 0x0b70 [ 7C01817ADF3207FB65A4B56E6D5AD833 ] PnkBstrB C:\WINDOWS\system32\PnkBstrB.exe 21:18:32.0593 0x0b70 PnkBstrB - ok 21:18:32.0625 0x0b70 [ 88296F7943F30A1EE3AF735440B92268 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 21:18:32.0625 0x0b70 PolicyAgent - ok 21:18:32.0656 0x0b70 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 21:18:32.0703 0x0b70 PptpMiniport - ok 21:18:32.0750 0x0b70 [ 0DFD0DF9AB7A227CEDF97FADEE60F793 ] prodrv06 C:\WINDOWS\System32\drivers\prodrv06.sys 21:18:32.0765 0x0b70 prodrv06 - ok 21:18:32.0812 0x0b70 [ F2E44D17EA6334B39F35CC42251B2ACA ] prohlp02 C:\WINDOWS\system32\drivers\prohlp02.sys 21:18:32.0828 0x0b70 prohlp02 - ok 21:18:32.0843 0x0b70 [ F3471E7971EE62420451D958DA635064 ] prosync1 C:\WINDOWS\system32\drivers\prosync1.sys 21:18:32.0843 0x0b70 prosync1 - ok 21:18:32.0859 0x0b70 [ 88296F7943F30A1EE3AF735440B92268 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 21:18:32.0859 0x0b70 ProtectedStorage - ok 21:18:32.0875 0x0b70 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 21:18:32.0953 0x0b70 PSched - ok 21:18:33.0031 0x0b70 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 21:18:33.0062 0x0b70 Ptilink - ok 21:18:33.0078 0x0b70 ql1080 - ok 21:18:33.0078 0x0b70 Ql10wnt - ok 21:18:33.0078 0x0b70 ql12160 - ok 21:18:33.0078 0x0b70 ql1240 - ok 21:18:33.0078 0x0b70 ql1280 - ok 21:18:33.0109 0x0b70 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 21:18:33.0140 0x0b70 RasAcd - ok 21:18:33.0171 0x0b70 [ BC22C5E1238D4D36D65679E249C483C3 ] RasAuto C:\WINDOWS\System32\rasauto.dll 21:18:33.0187 0x0b70 RasAuto - ok 21:18:33.0218 0x0b70 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 21:18:33.0265 0x0b70 Rasl2tp - ok 21:18:33.0343 0x0b70 [ 0C392E397B8D34AAAF19EC6119CBB788 ] RasMan C:\WINDOWS\System32\rasmans.dll 21:18:33.0390 0x0b70 RasMan - ok 21:18:33.0406 0x0b70 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 21:18:33.0437 0x0b70 RasPppoe - ok 21:18:33.0453 0x0b70 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 21:18:33.0500 0x0b70 Raspti - ok 21:18:33.0562 0x0b70 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 21:18:33.0687 0x0b70 Rdbss - ok 21:18:33.0703 0x0b70 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 21:18:33.0718 0x0b70 RDPCDD - ok 21:18:33.0781 0x0b70 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 21:18:33.0859 0x0b70 rdpdr - ok 21:18:33.0921 0x0b70 [ FC105DD312ED64EB66BFF111E8EC6EAC ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 21:18:34.0031 0x0b70 RDPWD - ok 21:18:34.0109 0x0b70 [ F83907A9A038DB2E35329B039628D293 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 21:18:34.0156 0x0b70 RDSessMgr - ok 21:18:34.0187 0x0b70 [ E0C7BBD18040B58651BAC700C804861D ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 21:18:34.0218 0x0b70 redbook - ok 21:18:34.0250 0x0b70 [ B3F57E6115BCD4DBADE9874F300655E3 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 21:18:34.0281 0x0b70 RemoteAccess - ok 21:18:34.0312 0x0b70 [ B472B59EF98469C91651B751D3442CB8 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 21:18:34.0343 0x0b70 RemoteRegistry - ok 21:18:34.0390 0x0b70 [ 6BC4D5A70F46EA27DDC14E5414C862A5 ] RpcLocator C:\WINDOWS\system32\locator.exe 21:18:34.0406 0x0b70 RpcLocator - ok 21:18:34.0531 0x0b70 [ A37311D9D628C1042A2836731787F0F3 ] RpcSs C:\WINDOWS\system32\rpcss.dll 21:18:34.0546 0x0b70 RpcSs - ok 21:18:34.0593 0x0b70 [ 9ACEE3313020A01235336C2A483AFD1A ] RSVP C:\WINDOWS\system32\rsvp.exe 21:18:34.0640 0x0b70 RSVP - ok 21:18:34.0703 0x0b70 [ A74EF45E0DCDB28B9A88A31BC81164CD ] RTL8023xp C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 21:18:34.0718 0x0b70 RTL8023xp - ok 21:18:34.0750 0x0b70 [ 376218D4209B1E749953F9EDEF0CEF2E ] RTLTEAMING C:\WINDOWS\system32\DRIVERS\RTLTEAMING.SYS 21:18:34.0781 0x0b70 RTLTEAMING - ok 21:18:34.0812 0x0b70 [ 6EC43DC18746BB9B6DDEC4C99B15B6FC ] RTLVLAN C:\WINDOWS\system32\DRIVERS\RTLVLAN.SYS 21:18:34.0843 0x0b70 RTLVLAN - ok 21:18:34.0875 0x0b70 [ 5FFD2AAF467B80FAB34929AFB7702060 ] RtNdPt5x C:\WINDOWS\system32\DRIVERS\RtNdPt5x.sys 21:18:34.0875 0x0b70 RtNdPt5x - ok 21:18:34.0906 0x0b70 [ 4294FDF954125CE9E39E68F826415C29 ] s3legacy C:\WINDOWS\system32\DRIVERS\s3legacy.sys 21:18:35.0000 0x0b70 s3legacy - ok 21:18:35.0078 0x0b70 [ 88296F7943F30A1EE3AF735440B92268 ] SamSs C:\WINDOWS\system32\lsass.exe 21:18:35.0078 0x0b70 SamSs - ok 21:18:35.0125 0x0b70 [ C6F479218E94896738C06AF5BA6AB3D3 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 21:18:35.0156 0x0b70 SCardSvr - ok 21:18:35.0234 0x0b70 [ DD73C11A5C4D14945846384B90A61A4B ] Schedule C:\WINDOWS\system32\schedsvc.dll 21:18:35.0281 0x0b70 Schedule - ok 21:18:35.0312 0x0b70 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 21:18:35.0343 0x0b70 Secdrv - ok 21:18:35.0359 0x0b70 [ 2AAD9026648120FFFE2A8D871BB2BBC7 ] seclogon C:\WINDOWS\System32\seclogon.dll 21:18:35.0359 0x0b70 seclogon - ok 21:18:35.0390 0x0b70 [ 9D01E29D59723EB73B72107B208DAFE6 ] SENS C:\WINDOWS\system32\sens.dll 21:18:35.0390 0x0b70 SENS - ok 21:18:35.0421 0x0b70 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 21:18:35.0437 0x0b70 serenum - ok 21:18:35.0468 0x0b70 [ D07B02F88165E69B9F17162CF592C8A6 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 21:18:35.0531 0x0b70 Serial - ok 21:18:35.0578 0x0b70 [ 4354D1EEA9B4B6E29D53151ACDE7980F ] sfdrv01 C:\WINDOWS\system32\drivers\sfdrv01.sys 21:18:35.0609 0x0b70 sfdrv01 - ok 21:18:35.0625 0x0b70 [ 91F99F3E331E24C438819A38A1AD049C ] sfhlp01 C:\WINDOWS\system32\drivers\sfhlp01.sys 21:18:35.0656 0x0b70 sfhlp01 - ok 21:18:35.0671 0x0b70 [ 3AD2B15CCC03FEBFBAF5FF057822AA75 ] sfhlp02 C:\WINDOWS\system32\drivers\sfhlp02.sys 21:18:35.0703 0x0b70 sfhlp02 - ok 21:18:35.0718 0x0b70 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 21:18:35.0734 0x0b70 Sfloppy - ok 21:18:35.0765 0x0b70 [ D14D5C9C11998DA690FA75460F4F1CF3 ] sfsync02 C:\WINDOWS\system32\drivers\sfsync02.sys 21:18:35.0765 0x0b70 sfsync02 - ok 21:18:35.0828 0x0b70 [ 55AAE86C7C2CADF6972ACD1D76C24A98 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 21:18:35.0828 0x0b70 ShellHWDetection - ok 21:18:35.0828 0x0b70 Simbad - ok 21:18:36.0359 0x0b70 sony_ssm.sys - ok 21:18:36.0359 0x0b70 Sparrow - ok 21:18:36.0390 0x0b70 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 21:18:36.0406 0x0b70 splitter - ok 21:18:36.0453 0x0b70 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 21:18:36.0468 0x0b70 Spooler - ok 21:18:36.0703 0x0b70 [ CDDDEC541BC3C96F91ECB48759673505 ] sptd C:\WINDOWS\system32\Drivers\sptd.sys 21:18:36.0703 0x0b70 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: CDDDEC541BC3C96F91ECB48759673505 21:18:36.0703 0x0b70 sptd ( LockedFile.Multi.Generic ) - warning 21:18:36.0703 0x0b70 sptd - detected LockedFile.Multi.Generic (1) 21:18:36.0718 0x0b70 [ EB032822BE406EF220D546DDFFCF0002 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 21:18:36.0765 0x0b70 sr - ok 21:18:36.0843 0x0b70 [ 316D0E66074AE4CDE641C50D3A1C5148 ] srservice C:\WINDOWS\system32\srsvc.dll 21:18:36.0890 0x0b70 srservice - ok 21:18:37.0031 0x0b70 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 21:18:37.0218 0x0b70 Srv - ok 21:18:37.0281 0x0b70 [ 64E44ACD8C238FCBBB78F0BA4BDC4B05 ] ssadbus C:\WINDOWS\system32\DRIVERS\ssadbus.sys 21:18:37.0328 0x0b70 ssadbus - ok 21:18:37.0359 0x0b70 [ BB2C84A15C765DA89FD832B0E73F26CE ] ssadmdfl C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys 21:18:37.0390 0x0b70 ssadmdfl - ok 21:18:37.0453 0x0b70 [ 6D0D132DDC6F43EDA00DCED6D8B1CA31 ] ssadmdm C:\WINDOWS\system32\DRIVERS\ssadmdm.sys 21:18:37.0531 0x0b70 ssadmdm - ok 21:18:37.0578 0x0b70 [ 1A5A397BC459F346AB56492B61EF79F6 ] ssadserd C:\WINDOWS\system32\DRIVERS\ssadserd.sys 21:18:37.0640 0x0b70 ssadserd - ok 21:18:37.0687 0x0b70 [ 2C0B1224AA36B4CA1753302BAA855882 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 21:18:37.0703 0x0b70 SSDPSRV - ok 21:18:37.0718 0x0b70 Steam Client Service - ok 21:18:37.0828 0x0b70 [ 41508EA375C97DC2B56E5F1AFC067187 ] stisvc C:\WINDOWS\system32\wiaservc.dll 21:18:37.0921 0x0b70 stisvc - ok 21:18:37.0937 0x0b70 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 21:18:38.0015 0x0b70 swenum - ok 21:18:38.0140 0x0b70 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 21:18:38.0203 0x0b70 swmidi - ok 21:18:38.0218 0x0b70 SwPrv - ok 21:18:38.0218 0x0b70 symc810 - ok 21:18:38.0234 0x0b70 symc8xx - ok 21:18:38.0234 0x0b70 sym_hi - ok 21:18:38.0234 0x0b70 sym_u3 - ok 21:18:38.0265 0x0b70 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 21:18:38.0281 0x0b70 sysaudio - ok 21:18:38.0328 0x0b70 [ E42048198518F9162027A9984CBB7B5C ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 21:18:38.0359 0x0b70 SysmonLog - ok 21:18:38.0437 0x0b70 [ 2340E6977548038C88E39A9ECBB3FADC ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 21:18:38.0500 0x0b70 TapiSrv - ok 21:18:38.0640 0x0b70 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 21:18:38.0765 0x0b70 Tcpip - ok 21:18:38.0781 0x0b70 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 21:18:38.0812 0x0b70 TDPIPE - ok 21:18:38.0828 0x0b70 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 21:18:38.0859 0x0b70 TDTCP - ok 21:18:38.0875 0x0b70 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 21:18:38.0937 0x0b70 TermDD - ok 21:18:39.0156 0x0b70 [ 52E0505408EDD4AB5CCC7F83B67B4299 ] TermService C:\WINDOWS\System32\termsrv.dll 21:18:39.0250 0x0b70 TermService - ok 21:18:39.0312 0x0b70 [ 55AAE86C7C2CADF6972ACD1D76C24A98 ] Themes C:\WINDOWS\System32\shsvcs.dll 21:18:39.0312 0x0b70 Themes - ok 21:18:39.0359 0x0b70 [ B17551AB6EAA71DCA530632C15FA3D9A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 21:18:39.0390 0x0b70 TlntSvr - ok 21:18:39.0390 0x0b70 TosIde - ok 21:18:39.0421 0x0b70 [ 9E70EB419D7785C286DC458A019BAB9B ] TrkWks C:\WINDOWS\system32\trkwks.dll 21:18:39.0453 0x0b70 TrkWks - ok 21:18:39.0468 0x0b70 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 21:18:39.0515 0x0b70 Udfs - ok 21:18:39.0515 0x0b70 ultra - ok 21:18:39.0640 0x0b70 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 21:18:39.0781 0x0b70 Update - ok 21:18:39.0843 0x0b70 [ E96A6BAEE0B2A14A38B45830D6E30697 ] upnphost C:\WINDOWS\System32\upnphost.dll 21:18:39.0890 0x0b70 upnphost - ok 21:18:39.0906 0x0b70 [ EB90E28B28541EC845E5345609355CA7 ] UPS C:\WINDOWS\System32\ups.exe 21:18:39.0921 0x0b70 UPS - ok 21:18:39.0937 0x0b70 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 21:18:40.0000 0x0b70 usbccgp - ok 21:18:40.0031 0x0b70 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 21:18:40.0062 0x0b70 usbehci - ok 21:18:40.0093 0x0b70 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 21:18:40.0125 0x0b70 usbhub - ok 21:18:40.0171 0x0b70 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 21:18:40.0203 0x0b70 usbprint - ok 21:18:40.0234 0x0b70 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 21:18:40.0265 0x0b70 usbstor - ok 21:18:40.0296 0x0b70 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 21:18:40.0328 0x0b70 usbuhci - ok 21:18:40.0328 0x0b70 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 21:18:40.0359 0x0b70 VgaSave - ok 21:18:40.0359 0x0b70 ViaIde - ok 21:18:40.0390 0x0b70 [ 56B191AC5FC0DF219949C95A6C87AFE7 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 21:18:40.0453 0x0b70 VolSnap - ok 21:18:40.0562 0x0b70 [ 7F2D7BFFC4554E1C742DD3629FD1FB1B ] VSS C:\WINDOWS\System32\vssvc.exe 21:18:40.0640 0x0b70 VSS - ok 21:18:40.0703 0x0b70 [ A672CA3981352F8E9C30FEA056E80A62 ] W32Time C:\WINDOWS\system32\w32time.dll 21:18:40.0750 0x0b70 W32Time - ok 21:18:40.0765 0x0b70 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 21:18:40.0812 0x0b70 Wanarp - ok 21:18:40.0812 0x0b70 WDICA - ok 21:18:40.0843 0x0b70 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 21:18:40.0890 0x0b70 wdmaud - ok 21:18:40.0921 0x0b70 [ 81FB88B975E25D76E00B69879D8A434C ] WebClient C:\WINDOWS\System32\webclnt.dll 21:18:40.0937 0x0b70 WebClient - ok 21:18:41.0140 0x0b70 [ 70C22297534A88B0AD0568900AB5A6D9 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 21:18:41.0171 0x0b70 winmgmt - ok 21:18:41.0218 0x0b70 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 21:18:41.0250 0x0b70 WmdmPmSN - ok 21:18:41.0453 0x0b70 [ AFCE55C392A9676BD24A287D5ED1C777 ] Wmi C:\WINDOWS\System32\advapi32.dll 21:18:41.0625 0x0b70 Wmi - ok 21:18:41.0671 0x0b70 [ A2B12D80A1670511B047A7D8BB647598 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 21:18:41.0718 0x0b70 WmiApSrv - ok 21:18:42.0109 0x0b70 [ CDFA647AA82FDBA6C9C7A06155AFCB40 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 21:18:42.0359 0x0b70 WMPNetworkSvc - ok 21:18:42.0703 0x0b70 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 21:18:42.0921 0x0b70 WPFFontCache_v0400 - ok 21:18:42.0968 0x0b70 [ 0091D78C5F8FDE0CDF2B214823DE6E48 ] WSIMD C:\WINDOWS\system32\DRIVERS\wsimd.sys 21:18:43.0031 0x0b70 WSIMD - ok 21:18:43.0078 0x0b70 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 21:18:43.0156 0x0b70 WudfPf - ok 21:18:43.0187 0x0b70 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 21:18:43.0234 0x0b70 WudfRd - ok 21:18:43.0265 0x0b70 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 21:18:43.0281 0x0b70 WudfSvc - ok 21:18:43.0453 0x0b70 [ C2842273AAA77AC031EDB87FA19A2147 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 21:18:43.0609 0x0b70 WZCSVC - ok 21:18:43.0656 0x0b70 [ 24ED6935771359A5AEF1FE8BF0C56F39 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 21:18:43.0718 0x0b70 xmlprov - ok 21:18:43.0718 0x0b70 ================ Scan global =============================== 21:18:43.0750 0x0b70 [ 65C782F8CFC1BEBCC58E1532F44B6408 ] C:\WINDOWS\system32\basesrv.dll 21:18:43.0859 0x0b70 [ AC6BEF2C41F0A6BCF1F0483281E24A21 ] C:\WINDOWS\system32\winsrv.dll 21:18:44.0031 0x0b70 [ AC6BEF2C41F0A6BCF1F0483281E24A21 ] C:\WINDOWS\system32\winsrv.dll 21:18:44.0093 0x0b70 [ 02A467E27AF55F7064C5B251E587315F ] C:\WINDOWS\system32\services.exe 21:18:44.0109 0x0b70 [Global] - ok 21:18:44.0109 0x0b70 ================ Scan MBR ================================== 21:18:44.0125 0x0b70 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 21:18:44.0875 0x0b70 \Device\Harddisk0\DR0 - ok 21:18:44.0875 0x0b70 ================ Scan VBR ================================== 21:18:44.0890 0x0b70 [ F6BBE3857DDBC53D1093FC4B6D7DD033 ] \Device\Harddisk0\DR0\Partition1 21:18:44.0890 0x0b70 \Device\Harddisk0\DR0\Partition1 - ok 21:18:44.0890 0x0b70 [ 861DDF795523285B1AD62301B8B40E4C ] \Device\Harddisk0\DR0\Partition2 21:18:44.0906 0x0b70 \Device\Harddisk0\DR0\Partition2 - ok 21:18:44.0921 0x0b70 [ 95C0309EE61F98FFB00B59F233765C6E ] \Device\Harddisk0\DR0\Partition3 21:18:44.0921 0x0b70 \Device\Harddisk0\DR0\Partition3 - ok 21:18:44.0937 0x0b70 [ E7145F13B810B3EF14241C7E1CEA696C ] \Device\Harddisk0\DR0\Partition4 21:18:44.0937 0x0b70 \Device\Harddisk0\DR0\Partition4 - ok 21:18:44.0937 0x0b70 ============================================================ 21:18:44.0937 0x0b70 Scan finished 21:18:44.0937 0x0b70 ============================================================ 21:18:44.0953 0x0eb8 Detected object count: 2 21:18:44.0953 0x0eb8 Actual detected object count: 2 21:18:54.0546 0x0eb8 AFD ( Virus.Win32.ZAccess.k ) - skipped by user 21:18:54.0546 0x0eb8 AFD ( Virus.Win32.ZAccess.k ) - User select action: Skip 21:18:54.0546 0x0eb8 sptd ( LockedFile.Multi.Generic ) - skipped by user 21:18:54.0546 0x0eb8 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 21:18:59.0031 0x0d14 Deinitialize success