13:55:55.0757 7768 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 13:55:57.0767 7768 ============================================================ 13:55:57.0767 7768 Current date / time: 2011/12/03 13:55:57.0767 13:55:57.0767 7768 SystemInfo: 13:55:57.0767 7768 13:55:57.0767 7768 OS Version: 6.1.7601 ServicePack: 1.0 13:55:57.0767 7768 Product type: Workstation 13:55:57.0767 7768 ComputerName: REMIK-KOMPUTER 13:55:57.0767 7768 UserName: remik 13:55:57.0767 7768 Windows directory: C:\Windows 13:55:57.0767 7768 System windows directory: C:\Windows 13:55:57.0767 7768 Processor architecture: Intel x86 13:55:57.0767 7768 Number of processors: 2 13:55:57.0767 7768 Page size: 0x1000 13:55:57.0767 7768 Boot type: Normal boot 13:55:57.0777 7768 ============================================================ 13:56:08.0586 7768 Initialize success 13:56:12.0558 4712 ============================================================ 13:56:12.0558 4712 Scan started 13:56:12.0558 4712 Mode: Manual; 13:56:12.0558 4712 ============================================================ 13:56:19.0044 4712 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys 13:56:19.0067 4712 1394ohci - ok 13:56:19.0537 4712 a2acc (05dac43a484272de87eac038814a7840) C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys 13:56:19.0537 4712 a2acc - ok 13:56:22.0787 4712 A2DDA (f7eabca8375ea2dc6f35c4bca4757515) C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys 13:56:22.0982 4712 A2DDA - ok 13:56:25.0544 4712 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys 13:56:25.0574 4712 ACPI - ok 13:56:26.0491 4712 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys 13:56:26.0902 4712 AcpiPmi - ok 13:56:27.0870 4712 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 13:56:27.0890 4712 adp94xx - ok 13:56:28.0826 4712 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 13:56:28.0836 4712 adpahci - ok 13:56:29.0308 4712 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 13:56:29.0326 4712 adpu320 - ok 13:56:30.0242 4712 AFD (9ebbba55060f786f0fcaa3893bfa2806) C:\Windows\system32\drivers\afd.sys 13:56:30.0282 4712 AFD - ok 13:56:31.0267 4712 AgereSoftModem (7e10e3bb9b258ad8a9300f91214d67b9) C:\Windows\system32\DRIVERS\AGRSM.sys 13:56:31.0295 4712 AgereSoftModem - ok 13:56:31.0586 4712 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys 13:56:31.0589 4712 agp440 - ok 13:56:31.0683 4712 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 13:56:31.0693 4712 aic78xx - ok 13:56:31.0793 4712 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys 13:56:31.0803 4712 aliide - ok 13:56:31.0933 4712 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys 13:56:31.0933 4712 amdagp - ok 13:56:32.0073 4712 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys 13:56:32.0083 4712 amdide - ok 13:56:32.0203 4712 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 13:56:32.0203 4712 AmdK8 - ok 13:56:32.0289 4712 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 13:56:32.0296 4712 AmdPPM - ok 13:56:32.0449 4712 amdsata (e7f4d42d8076ec60e21715cd11743a0d) C:\Windows\system32\drivers\amdsata.sys 13:56:32.0456 4712 amdsata - ok 13:56:32.0608 4712 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 13:56:32.0623 4712 amdsbs - ok 13:56:32.0690 4712 amdxata (146459d2b08bfdcbfa856d9947043c81) C:\Windows\system32\drivers\amdxata.sys 13:56:32.0695 4712 amdxata - ok 13:56:32.0833 4712 AmFSM (36b58a8bafe100de90c87a3c0e56a3f2) C:\Windows\system32\DRIVERS\amm8660.sys 13:56:32.0843 4712 AmFSM - ok 13:56:33.0076 4712 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys 13:56:33.0083 4712 AppID - ok 13:56:33.0244 4712 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 13:56:33.0251 4712 arc - ok 13:56:33.0324 4712 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 13:56:33.0334 4712 arcsas - ok 13:56:33.0484 4712 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 13:56:33.0484 4712 AsyncMac - ok 13:56:33.0604 4712 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys 13:56:33.0604 4712 atapi - ok 13:56:33.0854 4712 athr (ac4adac154563ab41cc79b0257bc685a) C:\Windows\system32\DRIVERS\athr.sys 13:56:33.0938 4712 athr - ok 13:56:34.0270 4712 athrusb6 (373469e83fb000aae521068c84827fa7) C:\Windows\system32\DRIVERS\athru6.sys 13:56:34.0356 4712 athrusb6 - ok 13:56:34.0912 4712 atikmdag (d2e9acb68fa61c911cc21e07f87705bf) C:\Windows\system32\DRIVERS\atikmdag.sys 13:56:35.0076 4712 atikmdag - ok 13:56:35.0236 4712 AvFlt - ok 13:56:35.0356 4712 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 13:56:35.0366 4712 b06bdrv - ok 13:56:35.0503 4712 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 13:56:35.0509 4712 b57nd60x - ok 13:56:35.0614 4712 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 13:56:35.0617 4712 Beep - ok 13:56:35.0910 4712 BHDrvx86 (9d14d76e4e7b9b2ead17149011db2b11) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20111114.002\BHDrvx86.sys 13:56:35.0933 4712 BHDrvx86 - ok 13:56:36.0126 4712 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 13:56:36.0147 4712 blbdrive - ok 13:56:36.0625 4712 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys 13:56:36.0635 4712 bowser - ok 13:56:36.0745 4712 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 13:56:36.0755 4712 BrFiltLo - ok 13:56:36.0925 4712 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 13:56:36.0935 4712 BrFiltUp - ok 13:56:37.0025 4712 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 13:56:37.0025 4712 Brserid - ok 13:56:37.0129 4712 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 13:56:37.0133 4712 BrSerWdm - ok 13:56:37.0220 4712 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 13:56:37.0223 4712 BrUsbMdm - ok 13:56:37.0324 4712 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 13:56:37.0327 4712 BrUsbSer - ok 13:56:37.0504 4712 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 13:56:37.0508 4712 BTHMODEM - ok 13:56:37.0618 4712 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 13:56:37.0634 4712 cdfs - ok 13:56:38.0067 4712 cdrom (65bb1bb7064c64a0aa3c13f9fa422737) C:\Windows\system32\drivers\cdrom.sys 13:56:38.0077 4712 Suspicious file (Forged): C:\Windows\system32\drivers\cdrom.sys. Real md5: 65bb1bb7064c64a0aa3c13f9fa422737, Fake md5: 393dae054b638eeed3e3d28e09eecdbc 13:56:38.0077 4712 cdrom ( ForgedFile.Multi.Generic ) - warning 13:56:38.0077 4712 cdrom - detected ForgedFile.Multi.Generic (1) 13:56:38.0633 4712 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 13:56:38.0644 4712 circlass - ok 13:56:38.0934 4712 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 13:56:38.0952 4712 CLFS - ok 13:56:39.0341 4712 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 13:56:39.0363 4712 CmBatt - ok 13:56:39.0775 4712 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys 13:56:39.0795 4712 cmdide - ok 13:56:40.0680 4712 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 13:56:40.0711 4712 CNG - ok 13:56:41.0120 4712 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 13:56:41.0131 4712 Compbatt - ok 13:56:41.0206 4712 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys 13:56:41.0216 4712 CompositeBus - ok 13:56:41.0316 4712 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 13:56:41.0316 4712 crcdisk - ok 13:56:41.0496 4712 CSC (3c2177a897b4ca2788c6fb0c3fd81d4b) C:\Windows\system32\drivers\csc.sys 13:56:41.0526 4712 CSC - ok 13:56:41.0793 4712 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys 13:56:41.0803 4712 DfsC - ok 13:56:42.0004 4712 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 13:56:42.0032 4712 discache - ok 13:56:42.0322 4712 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 13:56:42.0332 4712 Disk - ok 13:56:42.0536 4712 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 13:56:42.0543 4712 drmkaud - ok 13:56:42.0724 4712 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys 13:56:42.0767 4712 DXGKrnl - ok 13:56:43.0260 4712 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 13:56:43.0408 4712 ebdrv - ok 13:56:43.0756 4712 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 13:56:43.0806 4712 eeCtrl - ok 13:56:44.0497 4712 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 13:56:44.0527 4712 elxstor - ok 13:56:44.0717 4712 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 13:56:44.0717 4712 EraserUtilRebootDrv - ok 13:56:44.0857 4712 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys 13:56:44.0863 4712 ErrDev - ok 13:56:44.0964 4712 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 13:56:44.0973 4712 exfat - ok 13:56:45.0055 4712 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 13:56:45.0061 4712 fastfat - ok 13:56:45.0130 4712 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 13:56:45.0133 4712 fdc - ok 13:56:45.0268 4712 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 13:56:45.0289 4712 FileInfo - ok 13:56:45.0582 4712 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 13:56:45.0598 4712 Filetrace - ok 13:56:45.0964 4712 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 13:56:45.0984 4712 flpydisk - ok 13:56:46.0590 4712 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 13:56:46.0605 4712 FltMgr - ok 13:56:47.0172 4712 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 13:56:47.0224 4712 FsDepends - ok 13:56:47.0742 4712 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 13:56:47.0762 4712 Fs_Rec - ok 13:56:48.0314 4712 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys 13:56:48.0347 4712 fvevol - ok 13:56:49.0025 4712 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 13:56:49.0025 4712 gagp30kx - ok 13:56:49.0376 4712 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 13:56:49.0376 4712 GEARAspiWDM - ok 13:56:50.0483 4712 hcmon (fef4c8cb7412c644c36074cd7596df2a) C:\Windows\system32\drivers\hcmon.sys 13:56:56.0717 4712 hcmon - ok 13:56:58.0181 4712 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 13:56:58.0231 4712 hcw85cir - ok 13:56:59.0481 4712 HdAudAddService (a5ef29d5315111c80a5c1abad14c8972) C:\Windows\system32\drivers\HdAudio.sys 13:56:59.0584 4712 HdAudAddService - ok 13:57:00.0500 4712 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys 13:57:00.0521 4712 HDAudBus - ok 13:57:01.0137 4712 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 13:57:01.0161 4712 HidBatt - ok 13:57:01.0528 4712 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 13:57:01.0568 4712 HidBth - ok 13:57:02.0165 4712 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 13:57:02.0182 4712 HidIr - ok 13:57:02.0826 4712 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\drivers\hidusb.sys 13:57:02.0876 4712 HidUsb - ok 13:57:03.0548 4712 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys 13:57:03.0597 4712 HpSAMD - ok 13:57:04.0273 4712 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys 13:57:04.0293 4712 HTTP - ok 13:57:04.0603 4712 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys 13:57:04.0613 4712 hwpolicy - ok 13:57:04.0683 4712 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys 13:57:04.0683 4712 i8042prt - ok 13:57:04.0868 4712 iaStorV (a3cae5d281db4cff7cff8233507ee5ad) C:\Windows\system32\drivers\iaStorV.sys 13:57:04.0917 4712 iaStorV - ok 13:57:06.0358 4712 IDSVix86 (9bc8840de4140e8e2a6fc3192e054a8c) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111122.030\IDSvix86.sys 13:57:06.0369 4712 IDSVix86 - ok 13:57:06.0861 4712 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 13:57:06.0926 4712 iirsp - ok 13:57:07.0296 4712 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys 13:57:07.0307 4712 intelide - ok 13:57:07.0422 4712 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 13:57:07.0432 4712 intelppm - ok 13:57:07.0542 4712 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 13:57:07.0552 4712 IpFilterDriver - ok 13:57:07.0642 4712 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys 13:57:07.0652 4712 IPMIDRV - ok 13:57:07.0772 4712 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 13:57:07.0782 4712 IPNAT - ok 13:57:07.0901 4712 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 13:57:07.0918 4712 IRENUM - ok 13:57:08.0020 4712 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys 13:57:08.0028 4712 isapnp - ok 13:57:08.0144 4712 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys 13:57:08.0173 4712 iScsiPrt - ok 13:57:08.0416 4712 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys 13:57:08.0429 4712 kbdclass - ok 13:57:08.0510 4712 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys 13:57:08.0518 4712 kbdhid - ok 13:57:08.0644 4712 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys 13:57:08.0655 4712 KSecDD - ok 13:57:08.0815 4712 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 13:57:08.0848 4712 KSecPkg - ok 13:57:09.0182 4712 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 13:57:09.0192 4712 lltdio - ok 13:57:09.0372 4712 LPCFilter (31f74d5d47eea83e5e89447586917774) C:\Windows\system32\DRIVERS\LPCFilter.sys 13:57:09.0382 4712 LPCFilter - ok 13:57:09.0582 4712 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 13:57:09.0587 4712 LSI_FC - ok 13:57:09.0659 4712 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 13:57:09.0664 4712 LSI_SAS - ok 13:57:09.0702 4712 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 13:57:09.0708 4712 LSI_SAS2 - ok 13:57:09.0748 4712 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 13:57:09.0753 4712 LSI_SCSI - ok 13:57:09.0815 4712 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 13:57:09.0820 4712 luafv - ok 13:57:10.0158 4712 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\Windows\system32\drivers\mbam.sys 13:57:10.0162 4712 MBAMProtector - ok 13:57:10.0264 4712 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 13:57:10.0268 4712 megasas - ok 13:57:10.0401 4712 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 13:57:10.0410 4712 MegaSR - ok 13:57:10.0540 4712 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 13:57:10.0540 4712 Modem - ok 13:57:10.0600 4712 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 13:57:10.0600 4712 monitor - ok 13:57:10.0680 4712 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\drivers\mouclass.sys 13:57:10.0680 4712 mouclass - ok 13:57:10.0800 4712 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 13:57:10.0810 4712 mouhid - ok 13:57:10.0860 4712 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys 13:57:10.0870 4712 mountmgr - ok 13:57:10.0940 4712 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys 13:57:10.0950 4712 mpio - ok 13:57:10.0980 4712 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 13:57:10.0980 4712 mpsdrv - ok 13:57:11.0037 4712 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys 13:57:11.0044 4712 MRxDAV - ok 13:57:11.0128 4712 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys 13:57:11.0140 4712 mrxsmb - ok 13:57:11.0303 4712 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys 13:57:11.0311 4712 mrxsmb10 - ok 13:57:11.0372 4712 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys 13:57:11.0377 4712 mrxsmb20 - ok 13:57:11.0452 4712 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys 13:57:11.0456 4712 msahci - ok 13:57:11.0586 4712 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys 13:57:11.0591 4712 msdsm - ok 13:57:11.0954 4712 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 13:57:11.0972 4712 Msfs - ok 13:57:12.0107 4712 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 13:57:12.0147 4712 mshidkmdf - ok 13:57:12.0437 4712 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys 13:57:12.0437 4712 msisadrv - ok 13:57:12.0880 4712 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 13:57:12.0903 4712 MSKSSRV - ok 13:57:13.0504 4712 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 13:57:13.0517 4712 MSPCLOCK - ok 13:57:13.0985 4712 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 13:57:14.0035 4712 MSPQM - ok 13:57:14.0358 4712 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 13:57:14.0377 4712 MsRPC - ok 13:57:14.0519 4712 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys 13:57:14.0523 4712 mssmbios - ok 13:57:14.0705 4712 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 13:57:14.0709 4712 MSTEE - ok 13:57:14.0800 4712 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 13:57:14.0804 4712 MTConfig - ok 13:57:14.0907 4712 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 13:57:14.0912 4712 Mup - ok 13:57:15.0010 4712 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 13:57:15.0028 4712 NativeWifiP - ok 13:57:15.0352 4712 NAVENG (862f55824ac81295837b0ab63f91071f) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111122.018\NAVENG.SYS 13:57:15.0382 4712 NAVENG - ok 13:57:15.0757 4712 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111122.018\NAVEX15.SYS 13:57:15.0864 4712 NAVEX15 - ok 13:57:16.0351 4712 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys 13:57:16.0378 4712 NDIS - ok 13:57:16.0574 4712 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 13:57:16.0583 4712 NdisCap - ok 13:57:16.0729 4712 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 13:57:16.0749 4712 NdisTapi - ok 13:57:16.0799 4712 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys 13:57:16.0809 4712 Ndisuio - ok 13:57:16.0929 4712 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys 13:57:16.0939 4712 NdisWan - ok 13:57:17.0130 4712 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys 13:57:17.0187 4712 NDProxy - ok 13:57:17.0332 4712 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 13:57:17.0343 4712 NetBIOS - ok 13:57:17.0701 4712 NetBT (280122ddcf04b378edd1ad54d71c1e54) C:\Windows\system32\DRIVERS\netbt.sys 13:57:17.0724 4712 NetBT - ok 13:57:17.0898 4712 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 13:57:17.0908 4712 nfrd960 - ok 13:57:18.0616 4712 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 13:57:18.0636 4712 Npfs - ok 13:57:19.0102 4712 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 13:57:19.0120 4712 nsiproxy - ok 13:57:19.0300 4712 Ntfs (33c3093d09017cfe2e219f2472bff6eb) C:\Windows\system32\drivers\Ntfs.sys 13:57:19.0346 4712 Ntfs - ok 13:57:19.0400 4712 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 13:57:19.0404 4712 Null - ok 13:57:19.0566 4712 nvraid (af2eec9580c1d32fb7eaf105d9784061) C:\Windows\system32\drivers\nvraid.sys 13:57:19.0572 4712 nvraid - ok 13:57:19.0697 4712 nvstor (9283c58ebaa2618f93482eb5dabcec82) C:\Windows\system32\drivers\nvstor.sys 13:57:19.0707 4712 nvstor - ok 13:57:19.0797 4712 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys 13:57:19.0797 4712 nv_agp - ok 13:57:19.0867 4712 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys 13:57:19.0867 4712 ohci1394 - ok 13:57:20.0137 4712 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 13:57:20.0137 4712 Parport - ok 13:57:20.0238 4712 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys 13:57:20.0242 4712 partmgr - ok 13:57:20.0370 4712 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 13:57:20.0374 4712 Parvdm - ok 13:57:20.0506 4712 pavboot (55d654258a9c509b671310c314bd30b4) C:\Windows\system32\Drivers\pavboot.sys 13:57:20.0511 4712 pavboot - ok 13:57:20.0724 4712 PavProc (a110035fdc4b8f8f0cd5e71d031274e1) C:\Windows\system32\DRIVERS\PavProc.sys 13:57:20.0731 4712 PavProc - ok 13:57:20.0920 4712 PavSRK.sys - ok 13:57:21.0134 4712 PavTPK.sys - ok 13:57:21.0264 4712 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys 13:57:21.0274 4712 pci - ok 13:57:21.0354 4712 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys 13:57:21.0364 4712 pciide - ok 13:57:21.0464 4712 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 13:57:21.0474 4712 pcmcia - ok 13:57:21.0664 4712 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 13:57:21.0664 4712 pcw - ok 13:57:21.0752 4712 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 13:57:21.0783 4712 PEAUTH - ok 13:57:21.0949 4712 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 13:57:21.0954 4712 PptpMiniport - ok 13:57:22.0095 4712 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 13:57:22.0100 4712 Processor - ok 13:57:22.0237 4712 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 13:57:22.0243 4712 Psched - ok 13:57:22.0429 4712 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys 13:57:22.0452 4712 PxHelp20 - ok 13:57:22.0572 4712 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 13:57:22.0663 4712 ql2300 - ok 13:57:22.0791 4712 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 13:57:22.0791 4712 ql40xx - ok 13:57:23.0091 4712 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 13:57:23.0101 4712 QWAVEdrv - ok 13:57:23.0161 4712 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 13:57:23.0161 4712 RasAcd - ok 13:57:23.0294 4712 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 13:57:23.0298 4712 RasAgileVpn - ok 13:57:23.0386 4712 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 13:57:23.0396 4712 Rasl2tp - ok 13:57:23.0487 4712 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 13:57:23.0493 4712 RasPppoe - ok 13:57:23.0570 4712 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 13:57:23.0575 4712 RasSstp - ok 13:57:23.0706 4712 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys 13:57:23.0716 4712 rdbss - ok 13:57:23.0945 4712 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 13:57:23.0950 4712 rdpbus - ok 13:57:24.0070 4712 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys 13:57:24.0196 4712 RDPCDD - ok 13:57:24.0308 4712 RDPDR (b973fcfc50dc1434e1970a146f7e3885) C:\Windows\system32\drivers\rdpdr.sys 13:57:24.0318 4712 RDPDR - ok 13:57:24.0468 4712 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 13:57:24.0478 4712 RDPENCDD - ok 13:57:24.0548 4712 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 13:57:24.0548 4712 RDPREFMP - ok 13:57:24.0708 4712 RdpVideoMiniport (68a0387f58e226deee23d9715955572a) C:\Windows\system32\drivers\rdpvideominiport.sys 13:57:24.0718 4712 RdpVideoMiniport - ok 13:57:24.0806 4712 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys 13:57:24.0815 4712 RDPWD - ok 13:57:24.0993 4712 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys 13:57:25.0000 4712 rdyboost - ok 13:57:25.0215 4712 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\Windows\system32\Drivers\RimUsb.sys 13:57:25.0220 4712 RimUsb - ok 13:57:25.0322 4712 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\Windows\system32\DRIVERS\RimSerial.sys 13:57:25.0343 4712 RimVSerPort - ok 13:57:25.0432 4712 ROOTMODEM (564297827d213f52c7a3a2ff749568ca) C:\Windows\system32\Drivers\RootMdm.sys 13:57:25.0437 4712 ROOTMODEM - ok 13:57:25.0750 4712 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 13:57:25.0756 4712 rspndr - ok 13:57:25.0856 4712 RTL8167 (3983cea05bb855351d75f5482b6c42ce) C:\Windows\system32\DRIVERS\Rt86win7.sys 13:57:25.0856 4712 RTL8167 - ok 13:57:25.0936 4712 RTL8187 (86d27d129cc701183e22efd001be926f) C:\Windows\system32\DRIVERS\wg111v2.sys 13:57:25.0946 4712 RTL8187 - ok 13:57:26.0086 4712 s3cap (7fa7f2e249a5dcbb7970630e15e1f482) C:\Windows\system32\drivers\vms3cap.sys 13:57:26.0086 4712 s3cap - ok 13:57:26.0186 4712 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys 13:57:26.0196 4712 sbp2port - ok 13:57:26.0322 4712 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys 13:57:26.0327 4712 scfilter - ok 13:57:26.0498 4712 SCMNdisP (3b68015683c27cb00c7a6b60a37cbcfd) C:\Windows\system32\DRIVERS\scmndisp.sys 13:57:26.0503 4712 SCMNdisP - ok 13:57:26.0589 4712 sdbus (0328be1c7f1cba23848179f8762e391c) C:\Windows\system32\drivers\sdbus.sys 13:57:26.0594 4712 sdbus - ok 13:57:26.0705 4712 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 13:57:26.0709 4712 secdrv - ok 13:57:26.0839 4712 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 13:57:26.0843 4712 Serenum - ok 13:57:26.0999 4712 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 13:57:27.0016 4712 Serial - ok 13:57:27.0088 4712 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 13:57:27.0099 4712 sermouse - ok 13:57:27.0313 4712 sfdrv01 (56250672235bbe54ba8a4963b1ac997c) C:\Windows\system32\drivers\sfdrv01.sys 13:57:27.0323 4712 sfdrv01 - ok 13:57:27.0413 4712 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 13:57:27.0433 4712 sffdisk - ok 13:57:27.0553 4712 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys 13:57:27.0563 4712 sffp_mmc - ok 13:57:27.0773 4712 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\DRIVERS\sffp_sd.sys 13:57:27.0783 4712 sffp_sd - ok 13:57:27.0940 4712 sfhlp02 (3ad2b15ccc03febfbaf5ff057822aa75) C:\Windows\system32\drivers\sfhlp02.sys 13:57:27.0971 4712 sfhlp02 - ok 13:57:28.0349 4712 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 13:57:28.0361 4712 sfloppy - ok 13:57:28.0840 4712 sfsync02 (798d918d8f20380008277ce3ce5319d1) C:\Windows\system32\drivers\sfsync02.sys 13:57:28.0850 4712 sfsync02 - ok 13:57:29.0130 4712 ShldDrv (32d6f7632234f0354c79e915ca4613d4) C:\Windows\system32\DRIVERS\ShlDrv51.sys 13:57:29.0160 4712 ShldDrv - ok 13:57:29.0546 4712 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys 13:57:29.0578 4712 sisagp - ok 13:57:29.0854 4712 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 13:57:29.0860 4712 SiSRaid2 - ok 13:57:29.0932 4712 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 13:57:29.0938 4712 SiSRaid4 - ok 13:57:30.0014 4712 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 13:57:30.0020 4712 Smb - ok 13:57:30.0156 4712 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 13:57:30.0164 4712 spldr - ok 13:57:30.0377 4712 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys 13:57:30.0377 4712 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505 13:57:30.0407 4712 sptd ( LockedFile.Multi.Generic ) - warning 13:57:30.0407 4712 sptd - detected LockedFile.Multi.Generic (1) 13:57:30.0647 4712 SRTSP (83726cf02eced69138948083e06b6eac) C:\Windows\System32\Drivers\NIS\1206000.01D\SRTSP.SYS 13:57:30.0677 4712 SRTSP - ok 13:57:30.0777 4712 SRTSPX (4e7eab2e5615d39cf1f1df9c71e5e225) C:\Windows\system32\drivers\NIS\1206000.01D\SRTSPX.SYS 13:57:30.0787 4712 SRTSPX - ok 13:57:30.0936 4712 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys 13:57:30.0946 4712 srv - ok 13:57:31.0047 4712 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys 13:57:31.0056 4712 srv2 - ok 13:57:31.0121 4712 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys 13:57:31.0128 4712 srvnet - ok 13:57:31.0270 4712 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 13:57:31.0275 4712 stexstor - ok 13:57:31.0413 4712 storflt (472af0311073dceceaa8fa18ba2bdf89) C:\Windows\system32\drivers\vmstorfl.sys 13:57:31.0419 4712 storflt - ok 13:57:31.0495 4712 storvsc (dcaffd62259e0bdb433dd67b5bb37619) C:\Windows\system32\drivers\storvsc.sys 13:57:31.0511 4712 storvsc - ok 13:57:31.0584 4712 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys 13:57:31.0589 4712 swenum - ok 13:57:31.0848 4712 SymDS (9bbeb8c6258e72d62e7560e6667aad39) C:\Windows\system32\drivers\NIS\1206000.01D\SYMDS.SYS 13:57:31.0857 4712 SymDS - ok 13:57:32.0054 4712 SymEFA (d5c02629c02a820a7e71bca3d44294a3) C:\Windows\system32\drivers\NIS\1206000.01D\SYMEFA.SYS 13:57:32.0104 4712 SymEFA - ok 13:57:32.0174 4712 SymEvent (ab33c3b196197ca467cbdda717860dba) C:\Windows\system32\Drivers\SYMEVENT.SYS 13:57:32.0184 4712 SymEvent - ok 13:57:32.0324 4712 SymIRON (a73399804d5d4a8b20ba60fcf70c9f1f) C:\Windows\system32\drivers\NIS\1206000.01D\Ironx86.SYS 13:57:32.0324 4712 SymIRON - ok 13:57:32.0459 4712 SymNetS (2c688094650d23b62b0a809decd0b12f) C:\Windows\System32\Drivers\NIS\1206000.01D\SYMNETS.SYS 13:57:32.0468 4712 SymNetS - ok 13:57:32.0627 4712 Synth3dVsc - ok 13:57:32.0865 4712 Tcpip (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\drivers\tcpip.sys 13:57:32.0926 4712 Tcpip - ok 13:57:33.0066 4712 TCPIP6 (65d10b191c59c5501a1263fc33f6894b) C:\Windows\system32\DRIVERS\tcpip.sys 13:57:33.0080 4712 TCPIP6 - ok 13:57:33.0225 4712 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys 13:57:33.0229 4712 tcpipreg - ok 13:57:33.0350 4712 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys 13:57:33.0355 4712 TDPIPE - ok 13:57:33.0451 4712 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys 13:57:33.0451 4712 TDTCP - ok 13:57:33.0571 4712 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys 13:57:33.0581 4712 tdx - ok 13:57:33.0741 4712 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys 13:57:33.0751 4712 TermDD - ok 13:57:33.0871 4712 tifm21 (f779ba4cd37963ab4600c9871b7752a3) C:\Windows\system32\drivers\tifm21.sys 13:57:33.0881 4712 tifm21 - ok 13:57:34.0087 4712 truecrypt (aceb4f4f83b895e15c8c1a2f55009783) C:\Windows\system32\drivers\truecrypt.sys 13:57:34.0100 4712 truecrypt - ok 13:57:34.0299 4712 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys 13:57:34.0304 4712 tssecsrv - ok 13:57:34.0440 4712 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys 13:57:34.0446 4712 TsUsbFlt - ok 13:57:34.0506 4712 tsusbhub - ok 13:57:34.0650 4712 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys 13:57:34.0664 4712 tunnel - ok 13:57:34.0745 4712 TVALZ (fc24015b4052600c324c43e3a79c0664) C:\Windows\system32\DRIVERS\TVALZ_O.SYS 13:57:34.0750 4712 TVALZ - ok 13:57:34.0817 4712 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 13:57:34.0939 4712 uagp35 - ok 13:57:35.0369 4712 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys 13:57:35.0379 4712 udfs - ok 13:57:35.0544 4712 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys 13:57:35.0550 4712 uliagpkx - ok 13:57:35.0662 4712 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys 13:57:35.0667 4712 umbus - ok 13:57:35.0742 4712 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 13:57:35.0749 4712 UmPass - ok 13:57:35.0983 4712 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys 13:57:35.0988 4712 USBAAPL - ok 13:57:36.0202 4712 usbccgp (7e72e7d7e0757d59481d530fd2b0bfae) C:\Windows\system32\drivers\usbccgp.sys 13:57:36.0208 4712 usbccgp - ok 13:57:36.0357 4712 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys 13:57:36.0363 4712 usbcir - ok 13:57:36.0468 4712 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 13:57:36.0478 4712 usbehci - ok 13:57:36.0598 4712 usbhub (9d22aad9ac6a07c691a1113e5f860868) C:\Windows\system32\drivers\usbhub.sys 13:57:36.0608 4712 usbhub - ok 13:57:36.0728 4712 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 13:57:36.0728 4712 usbohci - ok 13:57:36.0818 4712 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 13:57:36.0838 4712 usbprint - ok 13:57:36.0989 4712 USBSTOR (bf63ebfc6979fefb2bc03df7989a0c1a) C:\Windows\system32\DRIVERS\USBSTOR.SYS 13:57:37.0003 4712 USBSTOR - ok 13:57:37.0137 4712 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 13:57:37.0144 4712 usbuhci - ok 13:57:37.0205 4712 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys 13:57:37.0212 4712 usbvideo - ok 13:57:37.0353 4712 VClone (94d73b62e458fb56c9ce60aa96d914f9) C:\Windows\system32\DRIVERS\VClone.sys 13:57:37.0358 4712 VClone - ok 13:57:37.0440 4712 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys 13:57:37.0446 4712 vdrvroot - ok 13:57:37.0583 4712 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 13:57:37.0612 4712 vga - ok 13:57:37.0717 4712 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 13:57:37.0722 4712 VgaSave - ok 13:57:37.0767 4712 VGPU - ok 13:57:37.0834 4712 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys 13:57:37.0841 4712 vhdmp - ok 13:57:37.0905 4712 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys 13:57:37.0914 4712 viaagp - ok 13:57:38.0125 4712 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 13:57:38.0135 4712 ViaC7 - ok 13:57:38.0235 4712 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys 13:57:38.0285 4712 viaide - ok 13:57:38.0495 4712 vmbus (c2f2911156fdc7817c52829c86da494e) C:\Windows\system32\drivers\vmbus.sys 13:57:38.0505 4712 vmbus - ok 13:57:38.0658 4712 VMBusHID (d4d77455211e204f370d08f4963063ce) C:\Windows\system32\drivers\VMBusHID.sys 13:57:38.0670 4712 VMBusHID - ok 13:57:38.0777 4712 vmci (a032c61cf37f5ec1e254348686a1b9f7) C:\Windows\system32\Drivers\vmci.sys 13:57:38.0807 4712 vmci - ok 13:57:39.0032 4712 vmkbd (0ff56144a95abe14c87a20bcc63d6ae1) C:\Windows\system32\drivers\VMkbd.sys 13:57:39.0069 4712 vmkbd - ok 13:57:39.0175 4712 VMnetAdapter (e41704d8149992107b333cc7a52c07cc) C:\Windows\system32\DRIVERS\vmnetadapter.sys 13:57:39.0188 4712 VMnetAdapter - ok 13:57:39.0268 4712 VMnetBridge (462f2a31ea8b87a28962aca998df1869) C:\Windows\system32\DRIVERS\vmnetbridge.sys 13:57:39.0280 4712 VMnetBridge - ok 13:57:39.0392 4712 VMnetuserif (b26da84d8d5c654b107972397a89fb46) C:\Windows\system32\drivers\vmnetuserif.sys 13:57:39.0403 4712 VMnetuserif - ok 13:57:39.0612 4712 vmusb (afb10ad9aa91d2f70c9f0e6bda0d119b) C:\Windows\system32\Drivers\vmusb.sys 13:57:39.0622 4712 vmusb - ok 13:57:39.0882 4712 vmx86 (97c1f1803e208d5e95a60e789a7e070a) C:\Windows\system32\Drivers\vmx86.sys 13:57:39.0992 4712 vmx86 - ok 13:57:40.0237 4712 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys 13:57:40.0249 4712 volmgr - ok 13:57:40.0399 4712 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 13:57:40.0499 4712 volmgrx - ok 13:57:40.0713 4712 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys 13:57:40.0737 4712 volsnap - ok 13:57:40.0889 4712 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 13:57:40.0905 4712 vsmraid - ok 13:57:41.0119 4712 vstor2-ws60 (c40598b7708c6af55a629a4d349e33bb) C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys 13:57:41.0129 4712 vstor2-ws60 - ok 13:57:41.0369 4712 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\system32\DRIVERS\vwifibus.sys 13:57:41.0389 4712 vwifibus - ok 13:57:41.0459 4712 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\Windows\system32\DRIVERS\vwififlt.sys 13:57:41.0469 4712 vwififlt - ok 13:57:41.0529 4712 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 13:57:41.0539 4712 WacomPen - ok 13:57:41.0676 4712 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 13:57:41.0682 4712 WANARP - ok 13:57:41.0701 4712 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys 13:57:41.0706 4712 Wanarpv6 - ok 13:57:41.0856 4712 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 13:57:41.0862 4712 Wd - ok 13:57:41.0933 4712 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 13:57:41.0961 4712 Wdf01000 - ok 13:57:42.0223 4712 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 13:57:42.0229 4712 WfpLwf - ok 13:57:42.0308 4712 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 13:57:42.0313 4712 WIMMount - ok 13:57:42.0430 4712 WinFLdrv (7575ab6902c3f321d62a8e5a7e4f55a9) C:\Windows\system32\WinFLdrv.sys 13:57:42.0452 4712 Suspicious file (Hidden): C:\Windows\system32\WinFLdrv.sys. md5: 7575ab6902c3f321d62a8e5a7e4f55a9 13:57:42.0452 4712 WinFLdrv ( HiddenFile.Multi.Generic ) - warning 13:57:42.0453 4712 WinFLdrv - detected HiddenFile.Multi.Generic (1) 13:57:42.0636 4712 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys 13:57:42.0646 4712 WinUsb - ok 13:57:42.0756 4712 WinVd32 (58997182304759f46902a62128d44d5c) C:\Windows\system32\WinVd32.sys 13:57:42.0786 4712 WinVd32 - ok 13:57:42.0906 4712 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys 13:57:42.0906 4712 WmiAcpi - ok 13:57:43.0076 4712 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 13:57:43.0086 4712 ws2ifsl - ok 13:57:43.0270 4712 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys 13:57:43.0276 4712 WudfPf - ok 13:57:43.0341 4712 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys 13:57:43.0353 4712 WUDFRd - ok 13:57:43.0493 4712 MBR (0x1B8) (32052574bf9f325ae309abc7bfd04460) \Device\Harddisk0\DR0 13:57:43.0632 4712 \Device\Harddisk0\DR0 - ok 13:57:43.0637 4712 Boot (0x1200) (a3fc8c38d160d3a1467655f2c527141f) \Device\Harddisk0\DR0\Partition0 13:57:43.0638 4712 \Device\Harddisk0\DR0\Partition0 - ok 13:57:43.0662 4712 Boot (0x1200) (f86280ea89bb87cd44cbfeddd24a4e53) \Device\Harddisk0\DR0\Partition1 13:57:43.0663 4712 \Device\Harddisk0\DR0\Partition1 - ok 13:57:43.0688 4712 Boot (0x1200) (add044de8849b451e346bde3700a0d61) \Device\Harddisk0\DR0\Partition2 13:57:43.0689 4712 \Device\Harddisk0\DR0\Partition2 - ok 13:57:43.0717 4712 Boot (0x1200) (003327e8d1d2f1b78bf1f5af200683e0) \Device\Harddisk0\DR0\Partition3 13:57:43.0719 4712 \Device\Harddisk0\DR0\Partition3 - ok 13:57:43.0724 4712 ============================================================ 13:57:43.0724 4712 Scan finished 13:57:43.0724 4712 ============================================================ 13:57:43.0743 6500 Detected object count: 3 13:57:43.0743 6500 Actual detected object count: 3 13:59:47.0969 6500 cdrom ( ForgedFile.Multi.Generic ) - skipped by user 13:59:47.0970 6500 cdrom ( ForgedFile.Multi.Generic ) - User select action: Skip 13:59:47.0970 6500 sptd ( LockedFile.Multi.Generic ) - skipped by user 13:59:47.0970 6500 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 13:59:47.0974 6500 WinFLdrv ( HiddenFile.Multi.Generic ) - skipped by user 13:59:47.0974 6500 WinFLdrv ( HiddenFile.Multi.Generic ) - User select action: Skip