18:40:42.0546 0x08e8 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58 18:40:47.0906 0x08e8 ============================================================ 18:40:47.0906 0x08e8 Current date / time: 2014/08/01 18:40:47.0906 18:40:47.0906 0x08e8 SystemInfo: 18:40:47.0906 0x08e8 18:40:47.0906 0x08e8 OS Version: 5.1.2600 ServicePack: 3.0 18:40:47.0906 0x08e8 Product type: Workstation 18:40:47.0906 0x08e8 ComputerName: KRZYCHO-B625ADA 18:40:47.0906 0x08e8 UserName: Artur 18:40:47.0906 0x08e8 Windows directory: C:\WINDOWS 18:40:47.0906 0x08e8 System windows directory: C:\WINDOWS 18:40:47.0906 0x08e8 Processor architecture: Intel x86 18:40:47.0906 0x08e8 Number of processors: 2 18:40:47.0906 0x08e8 Page size: 0x1000 18:40:47.0906 0x08e8 Boot type: Normal boot 18:40:47.0906 0x08e8 ============================================================ 18:40:50.0218 0x08e8 KLMD registered as C:\WINDOWS\system32\drivers\96346144.sys 18:41:07.0171 0x08e8 System UUID: {5237A3A0-CC34-2F6E-C2A4-E034134A8114} 18:41:08.0078 0x08e8 !crdlk 18:41:08.0078 0x08e8 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 ( 74.53 Gb ), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A' 18:41:08.0109 0x08e8 ============================================================ 18:41:08.0109 0x08e8 \Device\Harddisk0\DR0: 18:41:08.0109 0x08e8 MBR partitions: 18:41:08.0109 0x08e8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x950A5C1 18:41:08.0109 0x08e8 ============================================================ 18:41:08.0171 0x08e8 C: <-> \Device\Harddisk0\DR0\Partition1 18:41:08.0171 0x08e8 ============================================================ 18:41:08.0171 0x08e8 Initialize success 18:41:08.0171 0x08e8 ============================================================ 18:41:10.0625 0x0908 ============================================================ 18:41:10.0625 0x0908 Scan started 18:41:10.0625 0x0908 Mode: Manual; 18:41:10.0625 0x0908 ============================================================ 18:41:10.0625 0x0908 KSN ping started 18:41:10.0859 0x0908 KSN ping finished: true 18:41:11.0406 0x0908 ================ Scan system memory ======================== 18:41:11.0406 0x0908 System memory - ok 18:41:11.0406 0x0908 ================ Scan services ============================= 18:41:11.0453 0x0908 Suspicious service (NoAccess): 631e1f68bd7ed84c 18:41:11.0562 0x0908 [ CEBCEAA33C2A467AC24AA007365A2842, 845B1328243F0D051BFBC39C686BB1212712F71C78374677B63082372D782AC5 ] 631e1f68bd7ed84c C:\WINDOWS\System32\Drivers\631e1f68bd7ed84c.sys 18:41:11.0562 0x0908 Suspicious file ( NoAccess ): C:\WINDOWS\System32\Drivers\631e1f68bd7ed84c.sys. md5: CEBCEAA33C2A467AC24AA007365A2842, sha256: 845B1328243F0D051BFBC39C686BB1212712F71C78374677B63082372D782AC5 18:41:12.0671 0x0908 631e1f68bd7ed84c - detected Rootkit.Win32.Necurs.gen ( 0 ) 18:41:13.0156 0x0908 631e1f68bd7ed84c ( Rootkit.Win32.Necurs.gen ) - infected 18:41:13.0156 0x0908 Force sending object to P2P due to detect: 631e1f68bd7ed84c 18:41:13.0453 0x0908 Object send P2P result: true 18:41:13.0812 0x0908 Abiosdsk - ok 18:41:13.0828 0x0908 abp480n5 - ok 18:41:13.0906 0x0908 [ 05118282F5D039595A2B92B4A4AFE197, 390EBD6088E96571636CE0925E4899D58893D9E5DF2389C09BABBD47A5838B52 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 18:41:13.0921 0x0908 ACPI - ok 18:41:13.0984 0x0908 [ 66A42B7DB194E24B973BBCCE840A0F3F, 2550F8E5B5ACD88E4191656194E46FB8EC8CCC65AFD4B5E6D5CED9FE297B573F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 18:41:13.0984 0x0908 ACPIEC - ok 18:41:14.0062 0x0908 [ 6278AB04AAE16C1438F3C4D34706C3B7, 7067CC28D0EBF90A793F96996AB66C6A22128761820630F70D345DD2715316B7 ] ADILOADER C:\WINDOWS\system32\Drivers\adildr.sys 18:41:14.0062 0x0908 ADILOADER - ok 18:41:14.0140 0x0908 [ CF4304AE140E9574BA91475239ED5E99, 47CE692A889B64950E8ED0FC274F08039150CBA58F7DB4C56B61EC0E15F37CE9 ] adiusbaw C:\WINDOWS\system32\DRIVERS\adiusbaw.sys 18:41:14.0156 0x0908 adiusbaw - ok 18:41:14.0171 0x0908 adpu160m - ok 18:41:14.0234 0x0908 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys 18:41:14.0250 0x0908 aec - ok 18:41:14.0328 0x0908 [ 322D0E36693D6E24A2398BEE62A268CD, FB0BFF5846E50DBCC2826639318A6A1DE79EE7DEA2719ED74A5F6F44454E13D0 ] AFD C:\WINDOWS\System32\drivers\afd.sys 18:41:14.0343 0x0908 AFD - ok 18:41:14.0390 0x0908 [ 08FD04AA961BDC77FB983F328334E3D7, A784EC8A9EDB579262366B5A9AB177DB7BEC0A421BDE85431D0AD4959D5AF5E7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys 18:41:14.0390 0x0908 agp440 - ok 18:41:14.0406 0x0908 Aha154x - ok 18:41:14.0421 0x0908 aic78u2 - ok 18:41:14.0437 0x0908 aic78xx - ok 18:41:14.0468 0x0908 ALCXWDM - ok 18:41:14.0531 0x0908 [ 27AF056D8C42F0AB3CF1DFDCBBEB3243, 9D893C6C0E8619B0B0DA9EAEB5E470A29C9D730F89EC5632134C3F753DE51AC5 ] Alerter C:\WINDOWS\system32\alrsvc.dll 18:41:14.0531 0x0908 Alerter - ok 18:41:14.0578 0x0908 [ D1738DDDFF196C5CEE6D867C136AF745, DD4780276465CB18D14B4DDBB4E70117B374B3A61C618D68B5290714330DB91F ] ALG C:\WINDOWS\System32\alg.exe 18:41:14.0593 0x0908 ALG - ok 18:41:14.0593 0x0908 AliIde - ok 18:41:14.0625 0x0908 amsint - ok 18:41:14.0640 0x0908 AppMgmt - ok 18:41:14.0656 0x0908 asc - ok 18:41:14.0671 0x0908 asc3350p - ok 18:41:14.0687 0x0908 asc3550 - ok 18:41:14.0718 0x0908 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 18:41:14.0718 0x0908 AsyncMac - ok 18:41:14.0750 0x0908 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 18:41:14.0765 0x0908 atapi - ok 18:41:14.0781 0x0908 Atdisk - ok 18:41:14.0812 0x0908 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 18:41:14.0812 0x0908 Atmarpc - ok 18:41:14.0906 0x0908 [ 3A28D3E7BAD0EED3810CD918B2525B54, EFC7CEF39D58E846613E419E78ECBD300DFB18630B70110AB2936737EB2B19C1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 18:41:14.0921 0x0908 AudioSrv - ok 18:41:14.0968 0x0908 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 18:41:14.0968 0x0908 audstub - ok 18:41:15.0031 0x0908 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys 18:41:15.0031 0x0908 Beep - ok 18:41:15.0109 0x0908 [ 78200FAA6FD9C69394134C238C87FB7F, 4E70BD89BB40222CB0647E8F73DBBAB1020594AEC313848C911048D080D0F26A ] BITS C:\WINDOWS\system32\qmgr.dll 18:41:15.0156 0x0908 BITS - ok 18:41:15.0250 0x0908 [ B98ED6D85339A66A73F32FB569EB6C01, 08DF27984060C55F8CDF5F8F9FF73816163B659030B9098F62027FE7303EEDEC ] Browser C:\WINDOWS\System32\browser.dll 18:41:15.0265 0x0908 Browser - ok 18:41:15.0312 0x0908 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 18:41:15.0312 0x0908 cbidf2k - ok 18:41:15.0359 0x0908 cd20xrnt - ok 18:41:15.0375 0x0908 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 18:41:15.0375 0x0908 Cdaudio - ok 18:41:15.0437 0x0908 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 18:41:15.0437 0x0908 Cdfs - ok 18:41:15.0484 0x0908 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 18:41:15.0484 0x0908 Cdrom - ok 18:41:15.0500 0x0908 Changer - ok 18:41:15.0546 0x0908 [ 45B63DF2FB498D219FCBB4425CADE676, D58417D5D0E562E2CCBA04C82CF7E176F6F82026CB4877D45F0DC18944B72960 ] CiSvc C:\WINDOWS\system32\cisvc.exe 18:41:15.0546 0x0908 CiSvc - ok 18:41:15.0593 0x0908 [ C94F1B6F61858D6389C0FA06954FB9C4, 832A8BF5D63FD623632823DE7F36636540DAC9192B40A44C2DE6961D2E086320 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 18:41:15.0609 0x0908 ClipSrv - ok 18:41:15.0718 0x0908 [ 7FA87325900183197BC9710D1CE4C9FA, EFFCB4FDB69A01B019785F203F9779832AF7DE77FCE47B9421BEDC34816C1D82 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 18:41:15.0718 0x0908 clr_optimization_v2.0.50727_32 - ok 18:41:15.0859 0x0908 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 18:41:15.0875 0x0908 clr_optimization_v4.0.30319_32 - ok 18:41:15.0890 0x0908 CmdIde - ok 18:41:16.0031 0x0908 [ C08A31C01041EF684EEA312A47B1F650, E8B6FC82FDC302C7E5D84C1E6F7B60F8D8408A278ED682D60DFCCE98451823EA ] cmuda C:\WINDOWS\system32\drivers\cmuda.sys 18:41:16.0093 0x0908 cmuda - ok 18:41:16.0109 0x0908 COMSysApp - ok 18:41:16.0125 0x0908 Cpqarray - ok 18:41:16.0218 0x0908 [ 6B105FE95F2E9F0B6346044BA59D41C9, DC41FC89E6C4F4219015856AEE9D9CE365094D3C8012AFFC188C129DC3B6A9A8 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 18:41:16.0234 0x0908 CryptSvc - ok 18:41:16.0234 0x0908 dac2w2k - ok 18:41:16.0250 0x0908 dac960nt - ok 18:41:16.0359 0x0908 [ 02396DAB9DD407B06539981F477F3FEC, 02909411C763FE75A66AD31A0C3B4492FBB00F9AF3D2BE8478A444861A086B2A ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 18:41:16.0406 0x0908 DcomLaunch - ok 18:41:16.0484 0x0908 [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7, 9771808A033C781758AC1356F9F51B198A0750081424F4F7A937CE0D7408CEE1 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 18:41:16.0484 0x0908 Dhcp - ok 18:41:16.0562 0x0908 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 18:41:16.0578 0x0908 Disk - ok 18:41:16.0593 0x0908 dmadmin - ok 18:41:16.0734 0x0908 [ BC9219ABC5696942E6F9AC8A9B28670F, DEDD84A5FC12664C7767EC5210E3B4D311664EF8BCE01C9DCF16CC98BE16EDE1 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 18:41:16.0812 0x0908 dmboot - ok 18:41:16.0843 0x0908 [ 5FA232E3BA6E1346F9F5A7E519320CB0, 1C7EEC415C291D3C5FFD479A8454347528AF4FF88F81011EF65EFA8FE8199973 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 18:41:16.0859 0x0908 dmio - ok 18:41:16.0890 0x0908 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys 18:41:16.0890 0x0908 dmload - ok 18:41:16.0937 0x0908 [ D858920A05076914D34B0388E8D96CC0, A8F231BA9022F6AEBB24C9DCC1898923F85B79DE3C8E90B696CA0B295B9C99B7 ] dmserver C:\WINDOWS\System32\dmserver.dll 18:41:16.0937 0x0908 dmserver - ok 18:41:17.0031 0x0908 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 18:41:17.0031 0x0908 DMusic - ok 18:41:17.0109 0x0908 [ 4F7E82841ED3CF026BD8D5CE7C7379DB, EE216CCF13C78ED5BE30F21347A04E8EA3FB6AE016F7C88B67891DF8A49CB031 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 18:41:17.0109 0x0908 Dnscache - ok 18:41:17.0171 0x0908 [ E0B7D66CF29D9ADCCF873C77821CD4CA, 09A3D28585B62FC541EF4F2CB4D749DA119BB5F98739393CFD4D745060217C65 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 18:41:17.0187 0x0908 Dot3svc - ok 18:41:17.0203 0x0908 dpti2o - ok 18:41:17.0250 0x0908 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 18:41:17.0250 0x0908 drmkaud - ok 18:41:17.0296 0x0908 [ 5F256C1AD50FEFDC442CD5AAB58C7DD8, 0FC1F2590195AE4B7CAA802D84CD391B56D73B99CB100BDEBD4D7C002946D06B ] EapHost C:\WINDOWS\System32\eapsvc.dll 18:41:17.0296 0x0908 EapHost - ok 18:41:17.0390 0x0908 [ ED1B71382C31FD2CF3CDC4672EFAD6EA, AF3CD28B5E6F1ED1D6B7C71C697019B2E2E79AFFE29EB6282253B30BA205F3EA ] ERSvc C:\WINDOWS\System32\ersvc.dll 18:41:17.0390 0x0908 ERSvc - ok 18:41:17.0468 0x0908 [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] Eventlog C:\WINDOWS\system32\services.exe 18:41:17.0484 0x0908 Eventlog - ok 18:41:17.0562 0x0908 [ BE1B1412A3D488C50B8F67F792196108, 5F7A3CE16D35FAA7D69752320C427DEF907B6B70BAFFF9B64827E5C82D2B008C ] EventSystem C:\WINDOWS\system32\es.dll 18:41:17.0593 0x0908 EventSystem - ok 18:41:17.0640 0x0908 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 18:41:17.0656 0x0908 Fastfat - ok 18:41:17.0718 0x0908 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 18:41:17.0734 0x0908 FastUserSwitchingCompatibility - ok 18:41:17.0781 0x0908 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 18:41:17.0781 0x0908 Fdc - ok 18:41:17.0812 0x0908 [ 09E2A4D33F81A06A8AAB2BA0A0B5D235, D71C2D4212C7ABB1D8EE08B21C59CA25D7195F1A0E92E5BDA1DC5226A0E62CB0 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 18:41:17.0828 0x0908 Fips - ok 18:41:17.0968 0x0908 [ BB0667B0171B632B97EA759515476F07, 07A123B2182D5813D2898928C231638353CF086606E9D5A5AF4A2A73E17CEC27 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe 18:41:18.0062 0x0908 FLEXnet Licensing Service - ok 18:41:18.0140 0x0908 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys 18:41:18.0140 0x0908 Flpydisk - ok 18:41:18.0218 0x0908 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 18:41:18.0234 0x0908 FltMgr - ok 18:41:18.0296 0x0908 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 18:41:18.0296 0x0908 FontCache3.0.0.0 - ok 18:41:18.0328 0x0908 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 18:41:18.0343 0x0908 Fs_Rec - ok 18:41:18.0375 0x0908 [ ED6D921D8AB423138FB35BEEE6D6A6CB, CF133B76960207595C44181A235E63B84C5A5A4E7BDDDC2E6A01DA837E55832D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 18:41:18.0375 0x0908 Ftdisk - ok 18:41:18.0437 0x0908 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 18:41:18.0437 0x0908 Gpc - ok 18:41:18.0546 0x0908 [ AF752014F7EB61542E3F35B9374D7E76, 8D9F1D1B03D5AF9F592C396C4B6353E17F2E852A2A7F1F468F83763C0731435D ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 18:41:18.0546 0x0908 helpsvc - ok 18:41:18.0578 0x0908 HidServ - ok 18:41:18.0625 0x0908 [ F0273916DA6FB64CC88E0BD77619554F, C6E3B5C367CE52174251B1CE548F0DF8708AEDD228D5AD74D3F6F31FC3857460 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 18:41:18.0640 0x0908 hkmsvc - ok 18:41:18.0656 0x0908 hpn - ok 18:41:18.0765 0x0908 [ F6AACF5BCE2893E0C1754AFEB672E5C9, 62A7A70515B5570A649DC30A3A122B1302F6839A63927C8B29EBE04ABA654892 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 18:41:18.0781 0x0908 HTTP - ok 18:41:18.0843 0x0908 [ AA268079AC119F3A596E5E27AEE4BD17, 2FD9B52A0627B3ECE618BAC855C19002CA6F5339636D11DF9F998E588027292A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 18:41:18.0843 0x0908 HTTPFilter - ok 18:41:18.0859 0x0908 i2omgmt - ok 18:41:18.0875 0x0908 i2omp - ok 18:41:18.0921 0x0908 [ 177B372AF55C4460D0968B5F1D02AA1C, 39406139B0D42C650F2C1986D85DB2260107D427963BC2C85A11D71561986DEB ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 18:41:18.0921 0x0908 i8042prt - ok 18:41:18.0953 0x0908 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 18:41:18.0968 0x0908 Imapi - ok 18:41:19.0031 0x0908 [ 9125AF650608A921F98A789E5C5BA864, E530C4FE52EB66549D91490B3039EF8DBC6866E4F9B55213F21E3757892B06CE ] ImapiService C:\WINDOWS\system32\imapi.exe 18:41:19.0046 0x0908 ImapiService - ok 18:41:19.0062 0x0908 ini910u - ok 18:41:19.0093 0x0908 [ 0D3140DB49F05B2B69467BD5DAF1C94B, 891F03610505A5B6CB24B3C1D225166C06590D514B0DBC610A0EBA3AACFE6EBB ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys 18:41:19.0093 0x0908 IntelIde - ok 18:41:19.0125 0x0908 [ DA153EDC09DE8C4F846C085CAA39D1CC, 7669572FDCC2B458A8DCBA910D0260806E6DD7845221B81C509E627AB82ED7B4 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 18:41:19.0140 0x0908 intelppm - ok 18:41:19.0171 0x0908 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys 18:41:19.0171 0x0908 Ip6Fw - ok 18:41:19.0234 0x0908 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 18:41:19.0234 0x0908 IpFilterDriver - ok 18:41:19.0250 0x0908 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 18:41:19.0250 0x0908 IpInIp - ok 18:41:19.0312 0x0908 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 18:41:19.0328 0x0908 IpNat - ok 18:41:19.0359 0x0908 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 18:41:19.0359 0x0908 IPSec - ok 18:41:19.0406 0x0908 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 18:41:19.0406 0x0908 IRENUM - ok 18:41:19.0453 0x0908 [ C8EEF2E93835B81BD335DE2123121283, DF7CCA1141CE15050D5EA516C75BF677B095EABA9E08828880E8917EBDEB2418 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 18:41:19.0468 0x0908 isapnp - ok 18:41:19.0625 0x0908 [ B9436A665A8621073A12338B16D7BFD4, 1F1CB4758768BF7B7DDB27BF9DA944D869B561ABF7EC39CEC059044E10C1EA88 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 18:41:19.0656 0x0908 JavaQuickStarterService - ok 18:41:19.0671 0x0908 [ 2AECA45D4AEAACBDCB77AD11184E4601, 58724D00A0D6FA17CCAF69DC069EF59E535F08C870C199BF2C9269BC22273A63 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 18:41:19.0671 0x0908 Kbdclass - ok 18:41:19.0750 0x0908 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 18:41:19.0765 0x0908 kmixer - ok 18:41:19.0812 0x0908 [ 1705745D900DABF2D89F90EBADDC7517, FE90589415BDB3BA482D3EBE1A87A7BF1429791E8F18BCB66BF8874631CC8B2C ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 18:41:19.0812 0x0908 KSecDD - ok 18:41:19.0875 0x0908 [ 427F50A24AA35597A9A5E8FBF029590F, 561060473E4AB11A1450CCC1C6B7A1D9C8284E4935C165EA2FFD9571D462F70C ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 18:41:19.0890 0x0908 lanmanserver - ok 18:41:19.0937 0x0908 [ 92C7C0C7F4248F1B9F6872BAB9053523, B81EF5B5884818811EACA1469C49483E1670157A26275D431438288490CE5B99 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 18:41:19.0953 0x0908 lanmanworkstation - ok 18:41:19.0968 0x0908 lbrtfdc - ok 18:41:20.0015 0x0908 [ 437AA83D68F9FAC234CA68DBD40DB705, 49B4A9E30778FB6D08AA7F9D66AF173572B86F74863477FFE7A66BBF2E6BCE93 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 18:41:20.0015 0x0908 LmHosts - ok 18:41:20.0046 0x0908 [ 36F3AB18B1BE303DA51DE90A67DE3942, E364FF831EFBDC5FF026CE620EE951C129D4E0C79DD0FED823BC767F36ED0021 ] Messenger C:\WINDOWS\System32\msgsvc.dll 18:41:20.0062 0x0908 Messenger - ok 18:41:20.0171 0x0908 [ FAFE367D032ED82E9332B4C741A20216, 7B123766E360570E0FCB211835B7910D6A1806C25A06BCA9227AB9E993376CA8 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 18:41:20.0171 0x0908 Microsoft Office Groove Audit Service - ok 18:41:20.0203 0x0908 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 18:41:20.0203 0x0908 mnmdd - ok 18:41:20.0234 0x0908 [ 845814A8CB9D704D030F076E1BCE83F3, F35FD4B6CE78A06A6FCF207A75EADF5A8315F2254A3E84ED070928F196D32AF4 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 18:41:20.0234 0x0908 mnmsrvc - ok 18:41:20.0265 0x0908 [ 4A068DB7DC37D5AFEDB6512D2931D7B3, 491F58509188054EE35962B66A13F0029BDF66CC59ED3B5E4058393146CE001C ] Modem C:\WINDOWS\system32\drivers\Modem.sys 18:41:20.0265 0x0908 Modem - ok 18:41:20.0359 0x0908 [ FBED3DF6B884F8CF00447B73507F2C48, 2CAA78DF3DB8BB19C10FD046B6EDC34167D8CA67EF137912703FE751D70803A2 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 18:41:20.0359 0x0908 Mouclass - ok 18:41:20.0390 0x0908 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 18:41:20.0390 0x0908 MountMgr - ok 18:41:20.0468 0x0908 [ 4E9D8041D352A33332FD6F59A3A78B03, D4E6229B07EF9866993EEE4F6223DC7F1FF1108273FE14A3DC74E65C181DE56A ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 18:41:20.0484 0x0908 MozillaMaintenance - ok 18:41:20.0500 0x0908 mraid35x - ok 18:41:20.0546 0x0908 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 18:41:20.0562 0x0908 MRxDAV - ok 18:41:20.0625 0x0908 [ 68755F0FF16070178B54674FE5B847B0, 2FFBCE3A67FA7E30E373624521C602E5510C5565F04381C6C9F961253DA928A6 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 18:41:20.0656 0x0908 MRxSmb - ok 18:41:20.0718 0x0908 [ A54C5EECC7D3424824410BAE0AA6C371, C0C80211DD9A69A529B5277B0751FFABCBB6586292D06A79ED7B842277FBF78A ] MSDTC C:\WINDOWS\system32\msdtc.exe 18:41:20.0718 0x0908 MSDTC - ok 18:41:20.0765 0x0908 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 18:41:20.0765 0x0908 Msfs - ok 18:41:20.0812 0x0908 MSIServer - ok 18:41:20.0875 0x0908 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 18:41:20.0875 0x0908 MSKSSRV - ok 18:41:20.0937 0x0908 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 18:41:20.0937 0x0908 MSPCLOCK - ok 18:41:20.0968 0x0908 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 18:41:20.0968 0x0908 MSPQM - ok 18:41:21.0046 0x0908 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 18:41:21.0046 0x0908 mssmbios - ok 18:41:21.0078 0x0908 [ 2F625D11385B1A94360BFC70AAEFDEE1, 23E4974120233CF1A7BEE48977706A0A55418699379D1450502ABEB24191AC80 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 18:41:21.0078 0x0908 Mup - ok 18:41:21.0156 0x0908 [ 14CB8528E17D1221C50FC8CA88B1795F, E908EAE9A0E606084926941B1802E9F48AE1AC4AE6C6136345DD5699B8B9B526 ] napagent C:\WINDOWS\System32\qagentrt.dll 18:41:21.0187 0x0908 napagent - ok 18:41:21.0218 0x0908 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 18:41:21.0218 0x0908 NDIS - ok 18:41:21.0265 0x0908 [ 1AB3D00C991AB086E69DB84B6C0ED78F, 1F881FCCF5557C44C078D99CA2DD38D635413D6212DBEDC06A428EDAC7F8B04E ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 18:41:21.0265 0x0908 NdisTapi - ok 18:41:21.0296 0x0908 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 18:41:21.0296 0x0908 Ndisuio - ok 18:41:21.0328 0x0908 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 18:41:21.0328 0x0908 NdisWan - ok 18:41:21.0359 0x0908 [ 6215023940CFD3702B46ABC304E1D45A, C767F3A349B365F6E7566C0738E2F62D8FFF8CB4457347E3614BD403BC6CADCB ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 18:41:21.0359 0x0908 NDProxy - ok 18:41:21.0375 0x0908 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 18:41:21.0375 0x0908 NetBIOS - ok 18:41:21.0421 0x0908 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 18:41:21.0437 0x0908 NetBT - ok 18:41:21.0500 0x0908 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDE C:\WINDOWS\system32\netdde.exe 18:41:21.0515 0x0908 NetDDE - ok 18:41:21.0562 0x0908 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 18:41:21.0578 0x0908 NetDDEdsdm - ok 18:41:21.0625 0x0908 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] Netlogon C:\WINDOWS\system32\lsass.exe 18:41:21.0625 0x0908 Netlogon - ok 18:41:21.0703 0x0908 [ 4FE97D0B1B182DF2A9BDD4C02155EF5E, 46F3F4FEB501E1987B49AB1595AADC06432B70E39CA6E9CC67C6410B13DA7B7A ] Netman C:\WINDOWS\System32\netman.dll 18:41:21.0718 0x0908 Netman - ok 18:41:21.0781 0x0908 [ 612E31FCAC1040EDD78ECAC81C9F859F, 87464E4F8CB43466D2859783B87B19C73A8A7D7B5276561D2E8F9ED7CC6DBEA9 ] Nla C:\WINDOWS\System32\mswsock.dll 18:41:21.0812 0x0908 Nla - ok 18:41:21.0859 0x0908 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 18:41:21.0859 0x0908 Npfs - ok 18:41:21.0921 0x0908 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 18:41:21.0968 0x0908 Ntfs - ok 18:41:22.0015 0x0908 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] NtLmSsp C:\WINDOWS\system32\lsass.exe 18:41:22.0015 0x0908 NtLmSsp - ok 18:41:22.0093 0x0908 [ 3FB5399DBB7001A80D58EDAD64C98225, A790DB873DAADB2B241F2C2426B51C0B73D4E13AC4D804B8EBBF5A74B4A41797 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 18:41:22.0125 0x0908 NtmsSvc - ok 18:41:22.0171 0x0908 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys 18:41:22.0171 0x0908 Null - ok 18:41:22.0750 0x0908 [ 8E72E452B9CC1E455D19E3C9FA964D37, 5242982754402BB7F1D05A467EF98CFA62BC14AC901E975477F8332000AD1D57 ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 18:41:23.0281 0x0908 nv - ok 18:41:23.0343 0x0908 [ 934833B3CD462A6F8A96F64D024C8B20, D64DC1BACF732F7EBDB0698C181C492A51C88B932E8E18C7A22814D3155E5D37 ] NVSvc C:\WINDOWS\system32\nvsvc32.exe 18:41:23.0359 0x0908 NVSvc - ok 18:41:23.0421 0x0908 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 18:41:23.0421 0x0908 NwlnkFlt - ok 18:41:23.0468 0x0908 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 18:41:23.0468 0x0908 NwlnkFwd - ok 18:41:23.0609 0x0908 [ 84DE1DD996B48B05ACE31AD015FA108A, 4B9D1E4EF83ECED6C77F23D9879C124534F7053D7423E3A2D0F67A4A720CEA94 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 18:41:23.0640 0x0908 odserv - ok 18:41:23.0687 0x0908 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 18:41:23.0703 0x0908 ose - ok 18:41:23.0781 0x0908 [ 2D4CDAEBCED17743AA9E25D3016DC229, F5D138644F114861DD045975136904325304081221B85FB2C151CD9A411097CE ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 18:41:23.0796 0x0908 Parport - ok 18:41:23.0843 0x0908 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 18:41:23.0843 0x0908 PartMgr - ok 18:41:23.0906 0x0908 [ 453EC2C2A20A1382F564541918520EEB, 797ED3127131BAE255AE793B8327D0E3BB6D054421F8D90511B315937BEBB6B0 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 18:41:23.0906 0x0908 ParVdm - ok 18:41:23.0921 0x0908 [ 6862C69168D787B85A7D95CCD33C694E, 6B7912156A0BAB6AED4F00FE37034488D10646B17435E86DE0D7DBD5951E8FB9 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 18:41:23.0921 0x0908 PCI - ok 18:41:23.0937 0x0908 PCIDump - ok 18:41:23.0968 0x0908 [ 548CF2D6369EAE441A4C6BAA75BC4F0A, C659E9E8A16DD4CBEC97FFB50784D8585E02F20FA360D2280D322D975F00A994 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys 18:41:23.0968 0x0908 PCIIde - ok 18:41:24.0000 0x0908 [ 8DB27F1AE9593C94095485305A583862, 4FDB24BA306944743B50C3B0E39EFC75BD196A4DA1B0A3C859B974E8599B5128 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 18:41:24.0015 0x0908 Pcmcia - ok 18:41:24.0031 0x0908 PDCOMP - ok 18:41:24.0046 0x0908 PDFRAME - ok 18:41:24.0062 0x0908 PDRELI - ok 18:41:24.0078 0x0908 PDRFRAME - ok 18:41:24.0093 0x0908 perc2 - ok 18:41:24.0109 0x0908 perc2hib - ok 18:41:24.0187 0x0908 [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] PlugPlay C:\WINDOWS\system32\services.exe 18:41:24.0203 0x0908 PlugPlay - ok 18:41:24.0234 0x0908 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] PolicyAgent C:\WINDOWS\system32\lsass.exe 18:41:24.0234 0x0908 PolicyAgent - ok 18:41:24.0296 0x0908 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 18:41:24.0296 0x0908 PptpMiniport - ok 18:41:24.0328 0x0908 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 18:41:24.0328 0x0908 ProtectedStorage - ok 18:41:24.0359 0x0908 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 18:41:24.0359 0x0908 PSched - ok 18:41:24.0390 0x0908 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 18:41:24.0390 0x0908 Ptilink - ok 18:41:24.0406 0x0908 ql1080 - ok 18:41:24.0437 0x0908 Ql10wnt - ok 18:41:24.0453 0x0908 ql12160 - ok 18:41:24.0468 0x0908 ql1240 - ok 18:41:24.0484 0x0908 ql1280 - ok 18:41:24.0531 0x0908 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 18:41:24.0531 0x0908 RasAcd - ok 18:41:24.0578 0x0908 [ BC22C5E1238D4D36D65679E249C483C3, 9B01F8D9541F3558F7D6A3E079580EC87DC748EFCA43E10682C83953B8885C3B ] RasAuto C:\WINDOWS\System32\rasauto.dll 18:41:24.0593 0x0908 RasAuto - ok 18:41:24.0640 0x0908 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 18:41:24.0640 0x0908 Rasl2tp - ok 18:41:24.0718 0x0908 [ 0C392E397B8D34AAAF19EC6119CBB788, 843C0B52A92A7F62E0D503A62FE56A020655AD98BC287AE8669ACE93B6A02ECA ] RasMan C:\WINDOWS\System32\rasmans.dll 18:41:24.0750 0x0908 RasMan - ok 18:41:24.0781 0x0908 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 18:41:24.0796 0x0908 RasPppoe - ok 18:41:24.0812 0x0908 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 18:41:24.0812 0x0908 Raspti - ok 18:41:24.0875 0x0908 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 18:41:24.0890 0x0908 Rdbss - ok 18:41:24.0906 0x0908 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 18:41:24.0906 0x0908 RDPCDD - ok 18:41:24.0984 0x0908 [ 6728E45B66F93C08F11DE2E316FC70DD, EA63ECD4F84CAE08BD2BF843C48AF505B1B9D7B61349A63536C9C6FEBEF23452 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 18:41:25.0000 0x0908 RDPWD - ok 18:41:25.0046 0x0908 [ F83907A9A038DB2E35329B039628D293, 683D478C9EC30102BB5A4CB6D200C4772C8BF5DF7BFC757AFA0B5B44DA1F8961 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 18:41:25.0062 0x0908 RDSessMgr - ok 18:41:25.0093 0x0908 [ E0C7BBD18040B58651BAC700C804861D, 91AE8D3C7D9FB391725664996479DAFDA91CB91C31E446BFE9ECF0C4FC86BE2F ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 18:41:25.0093 0x0908 redbook - ok 18:41:25.0156 0x0908 [ B3F57E6115BCD4DBADE9874F300655E3, DFF4D6AEA1B22C531216ED5A94B01C88D2C61D0EC3BB34744B4572C672EF89E6 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 18:41:25.0156 0x0908 RemoteAccess - ok 18:41:25.0203 0x0908 [ 6BC4D5A70F46EA27DDC14E5414C862A5, D78921FF982CFF26A012A413F19331AACA4F66E53D38C626FE712B4108744E31 ] RpcLocator C:\WINDOWS\system32\locator.exe 18:41:25.0203 0x0908 RpcLocator - ok 18:41:25.0281 0x0908 [ 02396DAB9DD407B06539981F477F3FEC, 02909411C763FE75A66AD31A0C3B4492FBB00F9AF3D2BE8478A444861A086B2A ] RpcSs C:\WINDOWS\system32\rpcss.dll 18:41:25.0312 0x0908 RpcSs - ok 18:41:25.0375 0x0908 [ 9ACEE3313020A01235336C2A483AFD1A, 87DD3B037FB80DC5BB9F3E335C9A0F3926481012EF9A8DE2CEF53C5386F69009 ] RSVP C:\WINDOWS\system32\rsvp.exe 18:41:25.0390 0x0908 RSVP - ok 18:41:25.0468 0x0908 [ D507C1400284176573224903819FFDA3, DD0BDB2AB39A8A0A300B6D60FB6A7F5BA08C4DB8F59E0A784FB763EA8AD72AB2 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 18:41:25.0468 0x0908 rtl8139 - ok 18:41:25.0500 0x0908 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] SamSs C:\WINDOWS\system32\lsass.exe 18:41:25.0500 0x0908 SamSs - ok 18:41:25.0546 0x0908 [ C6F479218E94896738C06AF5BA6AB3D3, 4077BDDE1A44E2A415FF76A8BB3EAD226D7A29696C0218E81381B81E750CD0BA ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 18:41:25.0562 0x0908 SCardSvr - ok 18:41:25.0640 0x0908 [ DD73C11A5C4D14945846384B90A61A4B, C3C6BD62FB976E27C9E2C4C239D01B5458B7D270E9563A90EFBC9801B5DC55EA ] Schedule C:\WINDOWS\system32\schedsvc.dll 18:41:25.0671 0x0908 Schedule - ok 18:41:25.0703 0x0908 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 18:41:25.0718 0x0908 Secdrv - ok 18:41:25.0796 0x0908 [ 2AAD9026648120FFFE2A8D871BB2BBC7, 8F9B35717CBE8B1C30FF15992DA8A857470A96F1A043CDA42CB89E4C6723B4A4 ] seclogon C:\WINDOWS\System32\seclogon.dll 18:41:25.0796 0x0908 seclogon - ok 18:41:25.0875 0x0908 [ 9D01E29D59723EB73B72107B208DAFE6, D334E807C6B41CF08EB64DCF8B2C8F68FA553971130FAB2E14C3EEE4D3B968F7 ] SENS C:\WINDOWS\system32\sens.dll 18:41:25.0875 0x0908 SENS - ok 18:41:25.0906 0x0908 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 18:41:25.0906 0x0908 serenum - ok 18:41:25.0937 0x0908 [ D07B02F88165E69B9F17162CF592C8A6, B494941FC05FC2439F54D4D999B1A65F9709BC296D5AC470C8F73ACFC5DC4729 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 18:41:25.0937 0x0908 Serial - ok 18:41:26.0078 0x0908 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 18:41:26.0078 0x0908 Sfloppy - ok 18:41:26.0171 0x0908 [ DA5C015911F68F22ED821E9EE49AB233, 53694B0E70F77C775CE936F5DB458F724F051314704B6F69E5C2728180F0DC2C ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 18:41:26.0203 0x0908 SharedAccess - ok 18:41:26.0250 0x0908 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 18:41:26.0265 0x0908 ShellHWDetection - ok 18:41:26.0296 0x0908 Simbad - ok 18:41:26.0312 0x0908 Sparrow - ok 18:41:26.0375 0x0908 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys 18:41:26.0375 0x0908 splitter - ok 18:41:26.0437 0x0908 [ DD69EC597AB942C39B950D9C3CE1375D, D09185C8ED73FF04945FDB0B40009E0FCC31A73E80B03D397A1436CC3A373AF5 ] Spooler C:\WINDOWS\system32\spoolsv.exe 18:41:26.0437 0x0908 Spooler - ok 18:41:26.0484 0x0908 [ EB032822BE406EF220D546DDFFCF0002, 916299B409925AB7326CB5F744799B34FD08CA4C4B447215DA5060FF446FEEBE ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 18:41:26.0484 0x0908 sr - ok 18:41:26.0562 0x0908 [ 316D0E66074AE4CDE641C50D3A1C5148, 8429F815AFB4B39F6C1C56FB1CA009E5338C1467A4A02DD8E7E35BADBB8D5221 ] srservice C:\WINDOWS\system32\srsvc.dll 18:41:26.0593 0x0908 srservice - ok 18:41:26.0656 0x0908 [ 5252605079810904E31C332E241CD59B, 039DD965DE2137219168F95CA3BF1CA7353957026BDD0481F7964E2578DF2128 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 18:41:26.0687 0x0908 Srv - ok 18:41:26.0796 0x0908 [ 2C0B1224AA36B4CA1753302BAA855882, F8C90ECBF5BD7C3984E7C82EB00042DFD85A62F263C0205E6790205B6D64E101 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 18:41:26.0796 0x0908 SSDPSRV - ok 18:41:26.0890 0x0908 [ 41508EA375C97DC2B56E5F1AFC067187, 94D8D49AE3634E861DE501E72813C5320F059C49CC61FA01B2867C99E8B36DB4 ] stisvc C:\WINDOWS\system32\wiaservc.dll 18:41:26.0921 0x0908 stisvc - ok 18:41:26.0968 0x0908 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 18:41:26.0968 0x0908 swenum - ok 18:41:27.0031 0x0908 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 18:41:27.0031 0x0908 swmidi - ok 18:41:27.0046 0x0908 SwPrv - ok 18:41:27.0093 0x0908 symc810 - ok 18:41:27.0109 0x0908 symc8xx - ok 18:41:27.0125 0x0908 sym_hi - ok 18:41:27.0140 0x0908 sym_u3 - ok 18:41:27.0187 0x0908 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 18:41:27.0187 0x0908 sysaudio - ok 18:41:27.0296 0x0908 [ A39294798AB118924460E9AC2B20B346, 07D57CE22065EDA23CA52397B42DFC7FE4808A7652D1401967C53B4A99BF6AD6 ] syshost32 C:\WINDOWS\Installer\{BBC198B0-3E79-1E86-92E7-272D711E2AA1}\syshost.exe 18:41:27.0296 0x0908 Suspicious file ( NoAccess ): C:\WINDOWS\Installer\{BBC198B0-3E79-1E86-92E7-272D711E2AA1}\syshost.exe. md5: A39294798AB118924460E9AC2B20B346, sha256: 07D57CE22065EDA23CA52397B42DFC7FE4808A7652D1401967C53B4A99BF6AD6 18:41:27.0328 0x0908 syshost32 - detected LockedFile.Multi.Generic ( 1 ) 18:41:27.0609 0x0908 Detect turned to UDS exact due to KSN untrusted 18:41:27.0609 0x0908 syshost32 ( UDS:DangerousObject.Multi.Generic ) - infected 18:41:27.0609 0x0908 Force sending object to P2P due to detect: syshost32 18:41:28.0437 0x0908 Object send P2P result: true 18:41:28.0718 0x0908 [ E42048198518F9162027A9984CBB7B5C, 2634DE2B1AE9D856966F40BFB41AD951A41E11C557C4B27E61CFF63288B53D52 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 18:41:28.0734 0x0908 SysmonLog - ok 18:41:28.0796 0x0908 [ 2340E6977548038C88E39A9ECBB3FADC, B8992F5E0689B307B8CC162032B398950FB07C4B4EF997431F7B344351406586 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 18:41:28.0812 0x0908 TapiSrv - ok 18:41:28.0875 0x0908 [ 93EA8D04EC73A85DB02EB8805988F733, 013008E23F5F14E0C836C28524D1181759BAF84530C6331163882A772217F398 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 18:41:28.0921 0x0908 Tcpip - ok 18:41:28.0968 0x0908 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 18:41:28.0968 0x0908 TDPIPE - ok 18:41:28.0984 0x0908 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 18:41:29.0000 0x0908 TDTCP - ok 18:41:29.0062 0x0908 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 18:41:29.0062 0x0908 TermDD - ok 18:41:29.0156 0x0908 [ 52E0505408EDD4AB5CCC7F83B67B4299, 93DBA3282025C81DC43D4B43861A6CB30C9557CD0108D4D7E0C3B1269699CF22 ] TermService C:\WINDOWS\System32\termsrv.dll 18:41:29.0187 0x0908 TermService - ok 18:41:29.0218 0x0908 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] Themes C:\WINDOWS\System32\shsvcs.dll 18:41:29.0234 0x0908 Themes - ok 18:41:29.0250 0x0908 TosIde - ok 18:41:29.0328 0x0908 [ 9E70EB419D7785C286DC458A019BAB9B, 3901C6B9C9C197FED9C1039F2EBE0C5ACE240512ABBFECB388CAD201CE032760 ] TrkWks C:\WINDOWS\system32\trkwks.dll 18:41:29.0343 0x0908 TrkWks - ok 18:41:29.0406 0x0908 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 18:41:29.0406 0x0908 Udfs - ok 18:41:29.0421 0x0908 ultra - ok 18:41:29.0500 0x0908 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 18:41:29.0531 0x0908 Update - ok 18:41:29.0593 0x0908 [ E96A6BAEE0B2A14A38B45830D6E30697, 12314B1D96E025718F965C091E3CAD2865EDDAACA2E60A1A0DAF25630AE66B72 ] upnphost C:\WINDOWS\System32\upnphost.dll 18:41:29.0625 0x0908 upnphost - ok 18:41:29.0671 0x0908 [ EB90E28B28541EC845E5345609355CA7, 60C8DF04EB5839AB1B8625C385F4B2089C63FE613463026F779B331D9BC4D4D6 ] UPS C:\WINDOWS\System32\ups.exe 18:41:29.0687 0x0908 UPS - ok 18:41:29.0718 0x0908 [ 173F317CE0DB8E21322E71B7E60A27E8, 7042441BA63AE38AE9D7BE0BC5CA7404FC9EE5BB3F084604A68F01E82769652A ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 18:41:29.0718 0x0908 usbccgp - ok 18:41:29.0765 0x0908 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 18:41:29.0765 0x0908 usbehci - ok 18:41:29.0796 0x0908 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 18:41:29.0796 0x0908 usbhub - ok 18:41:29.0859 0x0908 [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 18:41:29.0859 0x0908 usbprint - ok 18:41:29.0875 0x0908 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 18:41:29.0875 0x0908 usbscan - ok 18:41:29.0937 0x0908 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 18:41:29.0937 0x0908 USBSTOR - ok 18:41:29.0984 0x0908 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 18:41:30.0000 0x0908 usbuhci - ok 18:41:30.0031 0x0908 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 18:41:30.0046 0x0908 VgaSave - ok 18:41:30.0062 0x0908 ViaIde - ok 18:41:30.0093 0x0908 [ 56B191AC5FC0DF219949C95A6C87AFE7, 5DCD42BD686869B394CFB9EFD727DCEEEAE239326DDE3D1655C456FCAE949D9F ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 18:41:30.0109 0x0908 VolSnap - ok 18:41:30.0171 0x0908 [ 7F2D7BFFC4554E1C742DD3629FD1FB1B, 4BFFC8A67F98AF69039DF0AFF1FDA11CFAD6464066E8ED92090D48392C43B6ED ] VSS C:\WINDOWS\System32\vssvc.exe 18:41:30.0203 0x0908 VSS - ok 18:41:30.0312 0x0908 [ A672CA3981352F8E9C30FEA056E80A62, 9AD34EFEB11EFEB234A246639FADF036F49FC67E542C4DE78D7C01E75BC62B59 ] W32Time C:\WINDOWS\system32\w32time.dll 18:41:30.0328 0x0908 W32Time - ok 18:41:30.0375 0x0908 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 18:41:30.0375 0x0908 Wanarp - ok 18:41:30.0390 0x0908 WDICA - ok 18:41:30.0437 0x0908 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 18:41:30.0437 0x0908 wdmaud - ok 18:41:30.0500 0x0908 [ 81FB88B975E25D76E00B69879D8A434C, 2340CEE200CA3F0A546F88AAD3AFDCFD0805DB027E8480B4280D92E14F6C1F69 ] WebClient C:\WINDOWS\System32\webclnt.dll 18:41:30.0515 0x0908 WebClient - ok 18:41:30.0640 0x0908 [ 70C22297534A88B0AD0568900AB5A6D9, 2457D9B21CD8633D6A59FC053B70B9282A64066789EC020A9F2C937141E95C61 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 18:41:30.0671 0x0908 winmgmt - ok 18:41:30.0750 0x0908 [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 18:41:30.0750 0x0908 WmdmPmSN - ok 18:41:30.0828 0x0908 [ A2B12D80A1670511B047A7D8BB647598, BDE141A77034608D926624583D252650D01B64EC2B3E8156A61D735C79E2A0E6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 18:41:30.0843 0x0908 WmiApSrv - ok 18:41:30.0968 0x0908 [ DCF3E3EDF5109EE8BC02FE6E1F045795, 4B8E14B1CFB095982D34DAEC336114F5039D7793080FB787DC95A63B6B945DD0 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 18:41:31.0015 0x0908 WPFFontCache_v0400 - ok 18:41:31.0125 0x0908 [ B6669F49D42E09BC0F9889FAA0F3336D, B6147A60F763E562E26495A6ACAE759492A52AE3BEFEA4BF40B8874E4CF069F1 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 18:41:31.0140 0x0908 wscsvc - ok 18:41:31.0203 0x0908 [ 04550D5EB7EE82C115DB547C01DF09FD, 6A4D1E5F4E1C641B47BB48489D4205531597E942E02ECD75BCFA856F60A938B0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 18:41:31.0203 0x0908 wuauserv - ok 18:41:31.0281 0x0908 [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 18:41:31.0281 0x0908 WudfPf - ok 18:41:31.0343 0x0908 [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 18:41:31.0343 0x0908 WudfRd - ok 18:41:31.0390 0x0908 [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 18:41:31.0406 0x0908 WudfSvc - ok 18:41:31.0484 0x0908 [ C2842273AAA77AC031EDB87FA19A2147, 8542392E337C543BCD9EDC7A15DC6E8DE8E9B8041CC7A8D707217C9FF0446882 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 18:41:31.0546 0x0908 WZCSVC - ok 18:41:31.0609 0x0908 [ 24ED6935771359A5AEF1FE8BF0C56F39, F0C3B781853714F48DE4F42533A7236CE11076208F190E79500F8A77C9CF9849 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 18:41:31.0625 0x0908 xmlprov - ok 18:41:31.0625 0x0908 ================ Scan global =============================== 18:41:31.0750 0x0908 [ 65C782F8CFC1BEBCC58E1532F44B6408, D5EB7357F37AC9CEF96BC1BCACE765B2897E502D699E64145EFA4DD62BCCE80B ] C:\WINDOWS\system32\basesrv.dll 18:41:31.0781 0x0908 [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 18:41:31.0843 0x0908 [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 18:41:31.0890 0x0908 [ 3E3AE424E27C4CEFE4CAB368C7B570EA, 95A3B2758662D9EB803BA8D0A294881451EEA9F1033978C4C60810317A703C5C ] C:\WINDOWS\system32\services.exe 18:41:31.0906 0x0908 [ Global ] - ok 18:41:31.0906 0x0908 ================ Scan MBR ================================== 18:41:31.0921 0x0908 [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 18:41:32.0109 0x0908 \Device\Harddisk0\DR0 - ok 18:41:32.0109 0x0908 ================ Scan VBR ================================== 18:41:32.0125 0x0908 [ 9FBDD121016E37EC01ADA0AD9626627F ] \Device\Harddisk0\DR0\Partition1 18:41:32.0125 0x0908 \Device\Harddisk0\DR0\Partition1 - ok 18:41:32.0125 0x0908 ================ Scan generic autorun ====================== 18:41:32.0265 0x0908 [ 48BE298F7FD1BEF4D8FBACB04D8D95C4, D375B3F6E850E4B0EC81BAA0E554C356BE2248AA77C6C56F5267CA05460FE4EB ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 18:41:32.0343 0x0908 Adobe ARM - ok 18:41:32.0437 0x0908 [ 4D83DC461F8F4370274CF6E9AC9A34F4, E84F573534C0AC02C9D3329A09F31E594A782FE9BEFB69DFA337D5505135D694 ] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe 18:41:32.0437 0x0908 HP Software Update - ok 18:41:32.0484 0x0908 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\CTFMON.EXE 18:41:32.0484 0x0908 CTFMON.EXE - ok 18:41:32.0500 0x0908 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\CTFMON.EXE 18:41:32.0500 0x0908 CTFMON.EXE - ok 18:41:32.0500 0x0908 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\ctfmon.exe 18:41:32.0515 0x0908 CTFMON.EXE - ok 18:41:32.0515 0x0908 [ 1BD41EDA5B869AFC99895C39A8DE36E1, B532692D7E082A8AE60A199951F82C2E0EE0BAEA3A61F9BAE59E955C914FA3F0 ] C:\WINDOWS\system32\CTFMON.EXE 18:41:32.0515 0x0908 CTFMON.EXE - ok 18:41:32.0515 0x0908 Waiting for KSN requests completion. In queue: 210 18:41:33.0609 0x0908 Win FW state via NFM: disabled 18:41:33.0796 0x0908 ============================================================ 18:41:33.0796 0x0908 Scan finished 18:41:33.0796 0x0908 ============================================================ 18:41:33.0812 0x0900 Detected object count: 2 18:41:33.0812 0x0900 Actual detected object count: 2 18:41:44.0140 0x0900 631e1f68bd7ed84c ( Rootkit.Win32.Necurs.gen ) - skipped by user 18:41:44.0140 0x0900 631e1f68bd7ed84c ( Rootkit.Win32.Necurs.gen ) - User select action: Skip 18:41:44.0140 0x0900 syshost32 ( UDS:DangerousObject.Multi.Generic ) - skipped by user 18:41:44.0140 0x0900 syshost32 ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip 18:42:06.0015 0x08e4 Deinitialize success