17:29:42.0578 2596 TDSS rootkit removing tool 2.7.26.0 Apr 4 2012 19:52:02 17:29:42.0581 2596 ============================================================ 17:29:42.0581 2596 Current date / time: 2012/04/05 17:29:42.0581 17:29:42.0581 2596 SystemInfo: 17:29:42.0581 2596 17:29:42.0581 2596 OS Version: 6.1.7600 ServicePack: 0.0 17:29:42.0581 2596 Product type: Workstation 17:29:42.0581 2596 ComputerName: KOXU-KOMPUTER 17:29:42.0583 2596 UserName: koxu 17:29:42.0583 2596 Windows directory: C:\Windows 17:29:42.0583 2596 System windows directory: C:\Windows 17:29:42.0583 2596 Processor architecture: Intel x86 17:29:42.0583 2596 Number of processors: 2 17:29:42.0583 2596 Page size: 0x1000 17:29:42.0583 2596 Boot type: Normal boot 17:29:42.0583 2596 ============================================================ 17:29:43.0522 2596 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 17:29:43.0522 2596 Drive \Device\Harddisk1\DR2 - Size: 0x1DD180000 (7.45 Gb), SectorSize: 0x200, Cylinders: 0x3CD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 17:29:43.0522 2596 \Device\Harddisk0\DR0: 17:29:43.0522 2596 MBR used 17:29:43.0522 2596 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x61A7927 17:29:43.0532 2596 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x61A79A5, BlocksNum 0x61A7927 17:29:43.0552 2596 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC34F30B, BlocksNum 0x61A7927 17:29:43.0562 2596 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x124F6C71, BlocksNum 0x61A7927 17:29:43.0572 2596 \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0x1869E5D7, BlocksNum 0x4B25FAA 17:29:43.0572 2596 \Device\Harddisk1\DR2: 17:29:43.0572 2596 MBR used 17:29:43.0572 2596 \Device\Harddisk1\DR2\Partition0: MBR, Type 0xB, StartLBA 0x20, BlocksNum 0xEE8BE0 17:29:43.0742 2596 Initialize success 17:29:43.0742 2596 ============================================================ 17:29:45.0222 2416 ============================================================ 17:29:45.0222 2416 Scan started 17:29:45.0222 2416 Mode: Manual; 17:29:45.0222 2416 ============================================================ 17:29:46.0024 2416 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 17:29:46.0024 2416 1394ohci - ok 17:29:46.0114 2416 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 17:29:46.0124 2416 ACPI - ok 17:29:46.0234 2416 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 17:29:46.0234 2416 AcpiPmi - ok 17:29:46.0324 2416 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 17:29:46.0324 2416 AdobeARMservice - ok 17:29:46.0464 2416 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 17:29:46.0464 2416 adp94xx - ok 17:29:46.0614 2416 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 17:29:46.0614 2416 adpahci - ok 17:29:46.0704 2416 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 17:29:46.0714 2416 adpu320 - ok 17:29:46.0824 2416 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 17:29:46.0824 2416 AeLookupSvc - ok 17:29:46.0934 2416 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 17:29:46.0934 2416 AFD - ok 17:29:47.0036 2416 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 17:29:47.0036 2416 agp440 - ok 17:29:47.0126 2416 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 17:29:47.0126 2416 aic78xx - ok 17:29:47.0236 2416 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 17:29:47.0246 2416 ALG - ok 17:29:47.0336 2416 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 17:29:47.0336 2416 aliide - ok 17:29:47.0436 2416 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 17:29:47.0436 2416 amdagp - ok 17:29:47.0516 2416 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 17:29:47.0516 2416 amdide - ok 17:29:47.0636 2416 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 17:29:47.0636 2416 AmdK8 - ok 17:29:47.0756 2416 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\Windows\system32\DRIVERS\AmdLLD.sys 17:29:47.0756 2416 AmdLLD - ok 17:29:47.0856 2416 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 17:29:47.0856 2416 AmdPPM - ok 17:29:47.0966 2416 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 17:29:47.0966 2416 amdsata - ok 17:29:48.0086 2416 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 17:29:48.0096 2416 amdsbs - ok 17:29:48.0176 2416 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 17:29:48.0176 2416 amdxata - ok 17:29:48.0288 2416 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 17:29:48.0288 2416 AppID - ok 17:29:48.0368 2416 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 17:29:48.0368 2416 AppIDSvc - ok 17:29:48.0488 2416 Appinfo (7dead9e3f65dcb2794f2711003bbf650) C:\Windows\System32\appinfo.dll 17:29:48.0488 2416 Appinfo - ok 17:29:48.0598 2416 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 17:29:48.0628 2416 Apple Mobile Device - ok 17:29:48.0728 2416 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 17:29:48.0728 2416 AppMgmt - ok 17:29:48.0828 2416 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 17:29:48.0838 2416 arc - ok 17:29:48.0938 2416 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 17:29:48.0948 2416 arcsas - ok 17:29:49.0038 2416 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 17:29:49.0048 2416 AsyncMac - ok 17:29:49.0128 2416 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 17:29:49.0128 2416 atapi - ok 17:29:49.0248 2416 AudioEndpointBuilder (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:29:49.0278 2416 AudioEndpointBuilder - ok 17:29:49.0308 2416 Audiosrv (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:29:49.0308 2416 Audiosrv - ok 17:29:49.0398 2416 AxInstSV (dd6a431b43e34b91a767d1ce33728175) C:\Windows\System32\AxInstSV.dll 17:29:49.0398 2416 AxInstSV - ok 17:29:49.0538 2416 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 17:29:49.0548 2416 b06bdrv - ok 17:29:49.0668 2416 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 17:29:49.0678 2416 b57nd60x - ok 17:29:49.0768 2416 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 17:29:49.0768 2416 BDESVC - ok 17:29:49.0858 2416 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 17:29:49.0868 2416 Beep - ok 17:29:49.0978 2416 BITS (53f476476f55a27f580661bde09c4ec4) C:\Windows\System32\qmgr.dll 17:29:49.0988 2416 BITS - ok 17:29:50.0128 2416 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 17:29:50.0128 2416 blbdrive - ok 17:29:50.0248 2416 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 17:29:50.0258 2416 Bonjour Service - ok 17:29:50.0358 2416 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 17:29:50.0368 2416 bowser - ok 17:29:50.0448 2416 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:29:50.0448 2416 BrFiltLo - ok 17:29:50.0558 2416 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:29:50.0558 2416 BrFiltUp - ok 17:29:50.0648 2416 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys 17:29:50.0648 2416 BridgeMP - ok 17:29:50.0758 2416 Browser (598e1280e7ff3744f4b8329366cc5635) C:\Windows\System32\browser.dll 17:29:50.0758 2416 Browser - ok 17:29:50.0848 2416 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 17:29:50.0848 2416 Brserid - ok 17:29:50.0968 2416 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 17:29:50.0968 2416 BrSerWdm - ok 17:29:51.0058 2416 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:29:51.0058 2416 BrUsbMdm - ok 17:29:51.0158 2416 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 17:29:51.0158 2416 BrUsbSer - ok 17:29:51.0278 2416 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 17:29:51.0288 2416 BTHMODEM - ok 17:29:51.0398 2416 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 17:29:51.0398 2416 bthserv - ok 17:29:51.0488 2416 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 17:29:51.0498 2416 cdfs - ok 17:29:51.0608 2416 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 17:29:51.0608 2416 cdrom - ok 17:29:51.0698 2416 CertPropSvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:29:51.0728 2416 CertPropSvc - ok 17:29:51.0808 2416 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 17:29:51.0808 2416 circlass - ok 17:29:51.0898 2416 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 17:29:51.0898 2416 CLFS - ok 17:29:51.0998 2416 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:29:51.0998 2416 clr_optimization_v2.0.50727_32 - ok 17:29:52.0078 2416 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 17:29:52.0078 2416 CmBatt - ok 17:29:52.0178 2416 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 17:29:52.0178 2416 cmdide - ok 17:29:52.0268 2416 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 17:29:52.0278 2416 CNG - ok 17:29:52.0378 2416 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 17:29:52.0388 2416 Compbatt - ok 17:29:52.0468 2416 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 17:29:52.0468 2416 CompositeBus - ok 17:29:52.0548 2416 COMSysApp - ok 17:29:52.0598 2416 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 17:29:52.0598 2416 crcdisk - ok 17:29:52.0688 2416 CryptSvc (9c231178ce4fb385f4b54b0a9080b8a4) C:\Windows\system32\cryptsvc.dll 17:29:52.0688 2416 CryptSvc - ok 17:29:52.0798 2416 CSC (64450e1fb77c72d12e519a627c521fff) C:\Windows\system32\drivers\csc.sys 17:29:52.0798 2416 Suspicious file (Forged): C:\Windows\system32\drivers\csc.sys. Real md5: 64450e1fb77c72d12e519a627c521fff, Fake md5: 27c9490bdd0ae48911ab8cf1932591ed 17:29:52.0808 2416 CSC ( Virus.Win32.ZAccess.aml ) - infected 17:29:52.0808 2416 CSC - detected Virus.Win32.ZAccess.aml (0) 17:29:52.0898 2416 CscService (56fb5f222ea30d3d3fc459879772cb73) C:\Windows\System32\cscsvc.dll 17:29:52.0918 2416 CscService - ok 17:29:53.0038 2416 DcomLaunch (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 17:29:53.0048 2416 DcomLaunch - ok 17:29:53.0138 2416 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 17:29:53.0148 2416 defragsvc - ok 17:29:53.0228 2416 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 17:29:53.0238 2416 DfsC - ok 17:29:53.0358 2416 Dhcp (c56495fbd770712367cad35e5de72da6) C:\Windows\system32\dhcpcore.dll 17:29:53.0358 2416 Dhcp - ok 17:29:53.0438 2416 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 17:29:53.0438 2416 discache - ok 17:29:53.0518 2416 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 17:29:53.0528 2416 Disk - ok 17:29:53.0618 2416 Dnscache (d0722e963d3c6145446874241401b209) C:\Windows\System32\dnsrslvr.dll 17:29:53.0618 2416 Dnscache - ok 17:29:53.0688 2416 dot3svc (4408c85c21eea48eb0ce486baeef0502) C:\Windows\System32\dot3svc.dll 17:29:53.0688 2416 dot3svc - ok 17:29:53.0788 2416 DPS (7fa81c6e11caa594adb52084da73a1e5) C:\Windows\system32\dps.dll 17:29:53.0798 2416 DPS - ok 17:29:53.0878 2416 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 17:29:53.0878 2416 drmkaud - ok 17:29:53.0978 2416 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys 17:29:53.0978 2416 dtsoftbus01 - ok 17:29:54.0078 2416 DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\Windows\System32\drivers\dxgkrnl.sys 17:29:54.0098 2416 DXGKrnl - ok 17:29:54.0168 2416 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 17:29:54.0188 2416 EapHost - ok 17:29:54.0358 2416 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 17:29:54.0428 2416 ebdrv - ok 17:29:54.0498 2416 EFS (f42309c4191c506b71db5d1126d26318) C:\Windows\System32\lsass.exe 17:29:54.0498 2416 EFS - ok 17:29:54.0578 2416 ehRecvr (3a74a6e33685662b125a3269b1f2114f) C:\Windows\ehome\ehRecvr.exe 17:29:54.0608 2416 ehRecvr - ok 17:29:54.0678 2416 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 17:29:54.0678 2416 ehSched - ok 17:29:54.0798 2416 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 17:29:54.0808 2416 elxstor - ok 17:29:54.0888 2416 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 17:29:54.0888 2416 ErrDev - ok 17:29:54.0998 2416 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 17:29:54.0998 2416 EventSystem - ok 17:29:55.0078 2416 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 17:29:55.0078 2416 exfat - ok 17:29:55.0268 2416 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 17:29:55.0278 2416 fastfat - ok 17:29:55.0488 2416 Fax (f7ea23cc5e6bf2181f3f399d54f6efc1) C:\Windows\system32\fxssvc.exe 17:29:55.0498 2416 Fax - ok 17:29:55.0578 2416 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 17:29:55.0578 2416 fdc - ok 17:29:55.0678 2416 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 17:29:55.0678 2416 fdPHost - ok 17:29:55.0738 2416 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 17:29:55.0738 2416 FDResPub - ok 17:29:55.0848 2416 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 17:29:55.0848 2416 FileInfo - ok 17:29:55.0928 2416 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 17:29:55.0928 2416 Filetrace - ok 17:29:56.0038 2416 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 17:29:56.0038 2416 flpydisk - ok 17:29:56.0128 2416 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 17:29:56.0128 2416 FltMgr - ok 17:29:56.0248 2416 FontCache (b6512a85815fdc3d560c3705f5bdb93d) C:\Windows\system32\FntCache.dll 17:29:56.0268 2416 FontCache - ok 17:29:56.0328 2416 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 17:29:56.0328 2416 FontCache3.0.0.0 - ok 17:29:56.0408 2416 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 17:29:56.0418 2416 FsDepends - ok 17:29:56.0498 2416 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 17:29:56.0498 2416 Fs_Rec - ok 17:29:56.0588 2416 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys 17:29:56.0588 2416 fvevol - ok 17:29:56.0698 2416 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 17:29:56.0698 2416 gagp30kx - ok 17:29:56.0788 2416 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 17:29:56.0788 2416 GEARAspiWDM - ok 17:29:56.0898 2416 gpsvc (8ba3c04702bf8f927ab36ae8313ca4ee) C:\Windows\System32\gpsvc.dll 17:29:56.0938 2416 gpsvc - ok 17:29:57.0048 2416 gupdate (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe 17:29:57.0058 2416 gupdate - ok 17:29:57.0068 2416 gupdatem (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe 17:29:57.0068 2416 gupdatem - ok 17:29:57.0158 2416 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 17:29:57.0158 2416 gusvc - ok 17:29:57.0268 2416 hamachi (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys 17:29:57.0268 2416 hamachi - ok 17:29:57.0358 2416 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 17:29:57.0358 2416 hcw85cir - ok 17:29:57.0478 2416 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 17:29:57.0478 2416 HDAudBus - ok 17:29:57.0548 2416 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 17:29:57.0548 2416 HidBatt - ok 17:29:57.0628 2416 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 17:29:57.0628 2416 HidBth - ok 17:29:57.0728 2416 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 17:29:57.0728 2416 HidIr - ok 17:29:57.0798 2416 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 17:29:57.0808 2416 hidserv - ok 17:29:57.0938 2416 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 17:29:57.0938 2416 HidUsb - ok 17:29:58.0008 2416 hkmsvc (741c2a45ca8407e374aaba3e330b7872) C:\Windows\system32\kmsvc.dll 17:29:58.0008 2416 hkmsvc - ok 17:29:58.0118 2416 HomeGroupListener (a768ca158bb06782a2835b907f4873c3) C:\Windows\system32\ListSvc.dll 17:29:58.0118 2416 HomeGroupListener - ok 17:29:58.0198 2416 HomeGroupProvider (fb08dec5ef43d0c66d83b8e9694e7549) C:\Windows\system32\provsvc.dll 17:29:58.0198 2416 HomeGroupProvider - ok 17:29:58.0318 2416 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 17:29:58.0318 2416 HpSAMD - ok 17:29:58.0418 2416 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 17:29:58.0438 2416 HTTP - ok 17:29:58.0538 2416 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 17:29:58.0538 2416 hwpolicy - ok 17:29:58.0628 2416 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 17:29:58.0628 2416 i8042prt - ok 17:29:58.0748 2416 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 17:29:58.0758 2416 iaStorV - ok 17:29:58.0838 2416 idsvc (5af815eb5bc9802e5a064e2ba62bfc0c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 17:29:58.0868 2416 idsvc - ok 17:29:58.0978 2416 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 17:29:58.0978 2416 iirsp - ok 17:29:59.0098 2416 IKEEXT (fac0ee6562b121b1399d6e855583f7a5) C:\Windows\System32\ikeext.dll 17:29:59.0108 2416 IKEEXT - ok 17:29:59.0188 2416 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 17:29:59.0188 2416 intelide - ok 17:29:59.0298 2416 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 17:29:59.0308 2416 intelppm - ok 17:29:59.0378 2416 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 17:29:59.0378 2416 IPBusEnum - ok 17:29:59.0458 2416 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:29:59.0458 2416 IpFilterDriver - ok 17:29:59.0578 2416 iphlpsvc (477397b432a256a50ee7e4339eb9ea14) C:\Windows\System32\iphlpsvc.dll 17:29:59.0598 2416 iphlpsvc - ok 17:29:59.0678 2416 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 17:29:59.0678 2416 IPMIDRV - ok 17:29:59.0798 2416 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 17:29:59.0798 2416 IPNAT - ok 17:29:59.0868 2416 iPod Service (49918803b661367023bf325cf602afdc) C:\Program Files\iPod\bin\iPodService.exe 17:29:59.0878 2416 iPod Service - ok 17:29:59.0978 2416 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 17:29:59.0978 2416 IRENUM - ok 17:30:00.0058 2416 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 17:30:00.0058 2416 isapnp - ok 17:30:00.0158 2416 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 17:30:00.0168 2416 iScsiPrt - ok 17:30:00.0258 2416 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 17:30:00.0258 2416 kbdclass - ok 17:30:00.0388 2416 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 17:30:00.0388 2416 kbdhid - ok 17:30:00.0488 2416 KeyIso (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:30:00.0488 2416 KeyIso - ok 17:30:00.0578 2416 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 17:30:00.0578 2416 KSecDD - ok 17:30:00.0658 2416 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 17:30:00.0658 2416 KSecPkg - ok 17:30:00.0748 2416 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 17:30:00.0758 2416 KtmRm - ok 17:30:00.0828 2416 LanmanServer (bca92cb047a4326925ecef759dbaa233) C:\Windows\System32\srvsvc.dll 17:30:00.0838 2416 LanmanServer - ok 17:30:00.0908 2416 LanmanWorkstation (b9891f885dcf1f0513a51cb58493cb1f) C:\Windows\System32\wkssvc.dll 17:30:00.0908 2416 LanmanWorkstation - ok 17:30:01.0038 2416 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 17:30:01.0038 2416 lltdio - ok 17:30:01.0128 2416 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 17:30:01.0128 2416 lltdsvc - ok 17:30:01.0198 2416 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 17:30:01.0198 2416 lmhosts - ok 17:30:01.0288 2416 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 17:30:01.0288 2416 LSI_FC - ok 17:30:01.0398 2416 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 17:30:01.0398 2416 LSI_SAS - ok 17:30:01.0488 2416 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:30:01.0488 2416 LSI_SAS2 - ok 17:30:01.0618 2416 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:30:01.0618 2416 LSI_SCSI - ok 17:30:01.0698 2416 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 17:30:01.0698 2416 luafv - ok 17:30:01.0808 2416 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 17:30:01.0808 2416 McComponentHostService - ok 17:30:01.0878 2416 Mcx2Svc (e2b0887816ed336685954e3d8fdaa51d) C:\Windows\system32\Mcx2Svc.dll 17:30:01.0888 2416 Mcx2Svc - ok 17:30:01.0998 2416 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 17:30:01.0998 2416 megasas - ok 17:30:02.0118 2416 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 17:30:02.0118 2416 MegaSR - ok 17:30:02.0218 2416 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:30:02.0218 2416 MMCSS - ok 17:30:02.0298 2416 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 17:30:02.0298 2416 Modem - ok 17:30:02.0408 2416 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 17:30:02.0408 2416 monitor - ok 17:30:02.0498 2416 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 17:30:02.0498 2416 mouclass - ok 17:30:02.0618 2416 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 17:30:02.0618 2416 mouhid - ok 17:30:02.0698 2416 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 17:30:02.0698 2416 mountmgr - ok 17:30:02.0808 2416 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 17:30:02.0808 2416 mpio - ok 17:30:02.0888 2416 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 17:30:02.0888 2416 mpsdrv - ok 17:30:02.0988 2416 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 17:30:02.0988 2416 MRxDAV - ok 17:30:03.0068 2416 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:30:03.0068 2416 mrxsmb - ok 17:30:03.0148 2416 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:30:03.0158 2416 mrxsmb10 - ok 17:30:03.0258 2416 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:30:03.0258 2416 mrxsmb20 - ok 17:30:03.0348 2416 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 17:30:03.0348 2416 msahci - ok 17:30:03.0458 2416 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 17:30:03.0458 2416 msdsm - ok 17:30:03.0528 2416 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 17:30:03.0538 2416 MSDTC - ok 17:30:03.0638 2416 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 17:30:03.0638 2416 Msfs - ok 17:30:03.0708 2416 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 17:30:03.0708 2416 mshidkmdf - ok 17:30:03.0798 2416 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 17:30:03.0798 2416 msisadrv - ok 17:30:03.0888 2416 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 17:30:03.0888 2416 MSiSCSI - ok 17:30:03.0948 2416 msiserver - ok 17:30:04.0028 2416 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 17:30:04.0028 2416 MSKSSRV - ok 17:30:04.0118 2416 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 17:30:04.0118 2416 MSPCLOCK - ok 17:30:04.0218 2416 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 17:30:04.0218 2416 MSPQM - ok 17:30:04.0308 2416 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 17:30:04.0308 2416 MsRPC - ok 17:30:04.0388 2416 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 17:30:04.0388 2416 mssmbios - ok 17:30:04.0498 2416 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 17:30:04.0498 2416 MSTEE - ok 17:30:04.0578 2416 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 17:30:04.0578 2416 MTConfig - ok 17:30:04.0698 2416 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 17:30:04.0698 2416 Mup - ok 17:30:04.0788 2416 napagent (80284f1985c70c86f0b5f86da2dfe1df) C:\Windows\system32\qagentRT.dll 17:30:04.0788 2416 napagent - ok 17:30:04.0898 2416 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 17:30:04.0908 2416 NativeWifiP - ok 17:30:05.0028 2416 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 17:30:05.0048 2416 NDIS - ok 17:30:05.0128 2416 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 17:30:05.0128 2416 NdisCap - ok 17:30:05.0218 2416 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 17:30:05.0258 2416 NdisTapi - ok 17:30:05.0338 2416 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 17:30:05.0338 2416 Ndisuio - ok 17:30:05.0418 2416 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 17:30:05.0418 2416 NdisWan - ok 17:30:05.0508 2416 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 17:30:05.0518 2416 NDProxy - ok 17:30:05.0598 2416 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 17:30:05.0598 2416 NetBIOS - ok 17:30:05.0708 2416 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 17:30:05.0708 2416 NetBT - ok 17:30:05.0778 2416 Netlogon (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:30:05.0778 2416 Netlogon - ok 17:30:05.0918 2416 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 17:30:05.0918 2416 Netman - ok 17:30:06.0008 2416 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 17:30:06.0008 2416 netprofm - ok 17:30:06.0098 2416 NetTcpPortSharing (fe2aa5a684b0dd9b1fae57b7817c198b) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:30:06.0098 2416 NetTcpPortSharing - ok 17:30:06.0188 2416 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 17:30:06.0188 2416 nfrd960 - ok 17:30:06.0298 2416 NlaSvc (2226496e34bd40734946a054b1cd657f) C:\Windows\System32\nlasvc.dll 17:30:06.0308 2416 NlaSvc - ok 17:30:06.0378 2416 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 17:30:06.0388 2416 Npfs - ok 17:30:06.0468 2416 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 17:30:06.0468 2416 nsi - ok 17:30:06.0548 2416 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 17:30:06.0548 2416 nsiproxy - ok 17:30:06.0698 2416 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 17:30:06.0728 2416 Ntfs - ok 17:30:06.0798 2416 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 17:30:06.0798 2416 Null - ok 17:30:06.0928 2416 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys 17:30:06.0928 2416 NVENETFD - ok 17:30:07.0308 2416 nvlddmkm (66b4bf606fcc7f0622d4a21bb1461089) C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:30:07.0358 2416 nvlddmkm - ok 17:30:07.0448 2416 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 17:30:07.0468 2416 nvraid - ok 17:30:07.0548 2416 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 17:30:07.0558 2416 nvstor - ok 17:30:07.0708 2416 nvsvc (d122f7c5f79c68868f5dc28cefeb2ecf) C:\Windows\system32\nvvsvc.exe 17:30:07.0738 2416 nvsvc - ok 17:30:07.0928 2416 nvUpdatusService (003cb0a155568b4a53a301f07c734233) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 17:30:07.0998 2416 nvUpdatusService - ok 17:30:08.0088 2416 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 17:30:08.0108 2416 nv_agp - ok 17:30:08.0178 2416 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 17:30:08.0178 2416 ohci1394 - ok 17:30:08.0258 2416 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:30:08.0268 2416 p2pimsvc - ok 17:30:08.0368 2416 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 17:30:08.0378 2416 p2psvc - ok 17:30:08.0468 2416 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 17:30:08.0468 2416 Parport - ok 17:30:08.0568 2416 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 17:30:08.0568 2416 partmgr - ok 17:30:08.0648 2416 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 17:30:08.0648 2416 Parvdm - ok 17:30:08.0748 2416 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 17:30:08.0748 2416 PcaSvc - ok 17:30:08.0828 2416 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 17:30:08.0838 2416 pci - ok 17:30:08.0938 2416 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 17:30:08.0938 2416 pciide - ok 17:30:09.0008 2416 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 17:30:09.0018 2416 pcmcia - ok 17:30:09.0098 2416 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 17:30:09.0098 2416 pcw - ok 17:30:09.0268 2416 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 17:30:09.0288 2416 PEAUTH - ok 17:30:09.0428 2416 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 17:30:09.0458 2416 PeerDistSvc - ok 17:30:09.0618 2416 pla (9c1bff7910c89a1d12e57343475840cb) C:\Windows\system32\pla.dll 17:30:09.0658 2416 pla - ok 17:30:09.0748 2416 PlugPlay (2cc2008f1296968fba162ed9f9afe328) C:\Windows\system32\umpnpmgr.dll 17:30:09.0758 2416 PlugPlay - ok 17:30:09.0858 2416 PnkBstrA (3a2e85f7d90d15460c337ce80c2e3b29) C:\Windows\system32\PnkBstrA.exe 17:30:09.0858 2416 PnkBstrA - ok 17:30:09.0938 2416 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 17:30:09.0938 2416 PNRPAutoReg - ok 17:30:10.0018 2416 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:30:10.0028 2416 PNRPsvc - ok 17:30:10.0108 2416 PolicyAgent (48e1b75c6dc0232fd92baae4bd344721) C:\Windows\System32\ipsecsvc.dll 17:30:10.0118 2416 PolicyAgent - ok 17:30:10.0208 2416 Power (dbff83f709a91049621c1d35dd45c92c) C:\Windows\system32\umpo.dll 17:30:10.0218 2416 Power - ok 17:30:10.0308 2416 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 17:30:10.0308 2416 PptpMiniport - ok 17:30:10.0408 2416 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 17:30:10.0408 2416 Processor - ok 17:30:10.0488 2416 ProfSvc (630cf26f0227498b7d5a92b12548960f) C:\Windows\system32\profsvc.dll 17:30:10.0488 2416 ProfSvc - ok 17:30:10.0588 2416 ProtectedStorage (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:30:10.0588 2416 ProtectedStorage - ok 17:30:10.0688 2416 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 17:30:10.0688 2416 Psched - ok 17:30:10.0828 2416 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 17:30:10.0868 2416 ql2300 - ok 17:30:10.0948 2416 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 17:30:10.0958 2416 ql40xx - ok 17:30:11.0048 2416 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 17:30:11.0058 2416 QWAVE - ok 17:30:11.0148 2416 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 17:30:11.0148 2416 QWAVEdrv - ok 17:30:11.0238 2416 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 17:30:11.0238 2416 RasAcd - ok 17:30:11.0328 2416 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:30:11.0328 2416 RasAgileVpn - ok 17:30:11.0428 2416 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 17:30:11.0438 2416 RasAuto - ok 17:30:11.0528 2416 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:30:11.0528 2416 Rasl2tp - ok 17:30:11.0638 2416 RasMan (0ce66ec736b7fc526d78f7624c7d2a94) C:\Windows\System32\rasmans.dll 17:30:11.0648 2416 RasMan - ok 17:30:11.0728 2416 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 17:30:11.0728 2416 RasPppoe - ok 17:30:11.0838 2416 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 17:30:11.0838 2416 RasSstp - ok 17:30:11.0928 2416 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 17:30:11.0928 2416 rdbss - ok 17:30:12.0038 2416 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 17:30:12.0038 2416 rdpbus - ok 17:30:12.0118 2416 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:30:12.0118 2416 RDPCDD - ok 17:30:12.0218 2416 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys 17:30:12.0228 2416 RDPDR - ok 17:30:12.0328 2416 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 17:30:12.0328 2416 RDPENCDD - ok 17:30:12.0408 2416 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 17:30:12.0408 2416 RDPREFMP - ok 17:30:12.0488 2416 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 17:30:12.0498 2416 RDPWD - ok 17:30:12.0588 2416 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 17:30:12.0588 2416 rdyboost - ok 17:30:12.0658 2416 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 17:30:12.0658 2416 RemoteAccess - ok 17:30:12.0738 2416 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 17:30:12.0738 2416 RemoteRegistry - ok 17:30:12.0818 2416 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 17:30:12.0818 2416 RpcEptMapper - ok 17:30:12.0858 2416 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 17:30:12.0858 2416 RpcLocator - ok 17:30:12.0948 2416 RpcSs (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 17:30:12.0948 2416 RpcSs - ok 17:30:13.0038 2416 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 17:30:13.0038 2416 rspndr - ok 17:30:13.0158 2416 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys 17:30:13.0158 2416 s3cap - ok 17:30:13.0238 2416 SamSs (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:30:13.0238 2416 SamSs - ok 17:30:13.0368 2416 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 17:30:13.0368 2416 sbp2port - ok 17:30:13.0458 2416 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 17:30:13.0458 2416 SCardSvr - ok 17:30:13.0548 2416 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 17:30:13.0548 2416 scfilter - ok 17:30:13.0658 2416 Schedule (3e8b0c453e25613a1f59762a5c42aa75) C:\Windows\system32\schedsvc.dll 17:30:13.0668 2416 Schedule - ok 17:30:13.0738 2416 SCPolicySvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:30:13.0748 2416 SCPolicySvc - ok 17:30:13.0818 2416 SDRSVC (5fd90abdbfaee85986802622cbb03446) C:\Windows\System32\SDRSVC.dll 17:30:13.0828 2416 SDRSVC - ok 17:30:13.0898 2416 se44mdm (b89cfbe8cb247b57d8c10adaa66b462b) C:\Windows\system32\msgsrvservice.dll 17:30:13.0898 2416 se44mdm ( Backdoor.Multi.ZAccess.gen ) - infected 17:30:13.0898 2416 se44mdm - detected Backdoor.Multi.ZAccess.gen (0) 17:30:13.0998 2416 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 17:30:13.0998 2416 secdrv - ok 17:30:14.0078 2416 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 17:30:14.0078 2416 seclogon - ok 17:30:14.0168 2416 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll 17:30:14.0168 2416 SENS - ok 17:30:14.0250 2416 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 17:30:14.0250 2416 SensrSvc - ok 17:30:14.0340 2416 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 17:30:14.0340 2416 Serenum - ok 17:30:14.0430 2416 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 17:30:14.0430 2416 Serial - ok 17:30:14.0500 2416 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 17:30:14.0500 2416 sermouse - ok 17:30:14.0590 2416 SessionEnv (8f55ce568c543d5adf45c409d16718fc) C:\Windows\system32\sessenv.dll 17:30:14.0590 2416 SessionEnv - ok 17:30:14.0660 2416 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 17:30:14.0660 2416 sffdisk - ok 17:30:14.0740 2416 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 17:30:14.0750 2416 sffp_mmc - ok 17:30:14.0820 2416 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys 17:30:14.0820 2416 sffp_sd - ok 17:30:14.0880 2416 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 17:30:14.0880 2416 sfloppy - ok 17:30:14.0960 2416 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 17:30:14.0960 2416 SharedAccess - ok 17:30:15.0040 2416 ShellHWDetection (cd2e48fa5b29ee2b3b5858056d246ef2) C:\Windows\System32\shsvcs.dll 17:30:15.0050 2416 ShellHWDetection - ok 17:30:15.0130 2416 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 17:30:15.0130 2416 sisagp - ok 17:30:15.0240 2416 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:30:15.0240 2416 SiSRaid2 - ok 17:30:15.0330 2416 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 17:30:15.0330 2416 SiSRaid4 - ok 17:30:15.0420 2416 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 17:30:15.0420 2416 Smb - ok 17:30:15.0500 2416 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 17:30:15.0510 2416 SNMPTRAP - ok 17:30:15.0580 2416 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 17:30:15.0580 2416 spldr - ok 17:30:15.0640 2416 Spooler (49b6dd6ab3715b7a67965f17194e98a9) C:\Windows\System32\spoolsv.exe 17:30:15.0650 2416 Spooler - ok 17:30:15.0790 2416 sppsvc (4c287f9069fedbd791178876ee9de536) C:\Windows\system32\sppsvc.exe 17:30:15.0870 2416 sppsvc - ok 17:30:15.0930 2416 sppuinotify (d8e3e19eebdab49dd4a8d3062ead4ec7) C:\Windows\system32\sppuinotify.dll 17:30:15.0930 2416 sppuinotify - ok 17:30:16.0020 2416 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys 17:30:16.0020 2416 srv - ok 17:30:16.0100 2416 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys 17:30:16.0110 2416 srv2 - ok 17:30:16.0180 2416 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys 17:30:16.0190 2416 srvnet - ok 17:30:16.0260 2416 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 17:30:16.0260 2416 SSDPSRV - ok 17:30:16.0330 2416 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 17:30:16.0330 2416 SstpSvc - ok 17:30:16.0390 2416 Steam Client Service - ok 17:30:16.0490 2416 Stereo Service (9e1222c417291bc836210743624a8e5e) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 17:30:16.0490 2416 Stereo Service - ok 17:30:16.0570 2416 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 17:30:16.0570 2416 stexstor - ok 17:30:16.0660 2416 StiSvc (a22825e7bb7018e8af3e229a5af17221) C:\Windows\System32\wiaservc.dll 17:30:16.0680 2416 StiSvc - ok 17:30:16.0750 2416 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys 17:30:16.0750 2416 storflt - ok 17:30:16.0830 2416 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys 17:30:16.0830 2416 storvsc - ok 17:30:16.0890 2416 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 17:30:16.0890 2416 swenum - ok 17:30:16.0970 2416 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 17:30:16.0980 2416 swprv - ok 17:30:17.0090 2416 SysMain (04105c8da62353589c29bdaeb8d88bd8) C:\Windows\system32\sysmain.dll 17:30:17.0120 2416 SysMain - ok 17:30:17.0190 2416 TabletInputService (fcfb6c552fbc0da299799cbd50ad9fd4) C:\Windows\System32\TabSvc.dll 17:30:17.0190 2416 TabletInputService - ok 17:30:17.0290 2416 TapiSrv (2f46b0c70a4adc8c90cf825da3b4feaf) C:\Windows\System32\tapisrv.dll 17:30:17.0290 2416 TapiSrv - ok 17:30:17.0390 2416 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 17:30:17.0390 2416 TBS - ok 17:30:17.0500 2416 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys 17:30:17.0540 2416 Tcpip - ok 17:30:17.0650 2416 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys 17:30:17.0660 2416 TCPIP6 - ok 17:30:17.0730 2416 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 17:30:17.0730 2416 tcpipreg - ok 17:30:17.0810 2416 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 17:30:17.0810 2416 TDPIPE - ok 17:30:17.0880 2416 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 17:30:17.0880 2416 TDTCP - ok 17:30:17.0960 2416 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 17:30:17.0960 2416 tdx - ok 17:30:18.0030 2416 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 17:30:18.0030 2416 TermDD - ok 17:30:18.0120 2416 TermService (a01e50a04d7b1960b33e92b9080e6a94) C:\Windows\System32\termsrv.dll 17:30:18.0130 2416 TermService - ok 17:30:18.0200 2416 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 17:30:18.0200 2416 Themes - ok 17:30:18.0270 2416 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:30:18.0270 2416 THREADORDER - ok 17:30:18.0340 2416 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 17:30:18.0340 2416 TrkWks - ok 17:30:18.0450 2416 TrojanKillerDriver (113384367c3999e084fe156b18c7625e) C:\Windows\system32\DRIVERS\gtkdrv.sys 17:30:18.0450 2416 TrojanKillerDriver - ok 17:30:18.0500 2416 TrustedInstaller (41a4c781d2286208d397d72099304133) C:\Windows\servicing\TrustedInstaller.exe 17:30:18.0510 2416 TrustedInstaller - ok 17:30:18.0560 2416 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:30:18.0560 2416 tssecsrv - ok 17:30:18.0660 2416 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 17:30:18.0660 2416 tunnel - ok 17:30:18.0740 2416 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 17:30:18.0740 2416 uagp35 - ok 17:30:18.0820 2416 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 17:30:18.0830 2416 udfs - ok 17:30:18.0900 2416 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 17:30:18.0900 2416 UI0Detect - ok 17:30:18.0970 2416 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 17:30:18.0970 2416 uliagpkx - ok 17:30:19.0050 2416 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 17:30:19.0050 2416 umbus - ok 17:30:19.0110 2416 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 17:30:19.0120 2416 UmPass - ok 17:30:19.0200 2416 UmRdpService (8ecaca5454844f66386f7be4ae0d7cd1) C:\Windows\System32\umrdp.dll 17:30:19.0200 2416 UmRdpService - ok 17:30:19.0300 2416 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 17:30:19.0310 2416 upnphost - ok 17:30:19.0410 2416 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys 17:30:19.0410 2416 USBAAPL - ok 17:30:19.0480 2416 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 17:30:19.0490 2416 usbaudio - ok 17:30:19.0560 2416 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 17:30:19.0560 2416 usbccgp - ok 17:30:19.0640 2416 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 17:30:19.0640 2416 usbcir - ok 17:30:19.0700 2416 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 17:30:19.0700 2416 usbehci - ok 17:30:19.0790 2416 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 17:30:19.0790 2416 usbhub - ok 17:30:19.0870 2416 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 17:30:19.0870 2416 usbohci - ok 17:30:19.0930 2416 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 17:30:19.0930 2416 usbprint - ok 17:30:19.0990 2416 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:30:19.0990 2416 USBSTOR - ok 17:30:20.0060 2416 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 17:30:20.0060 2416 usbuhci - ok 17:30:20.0120 2416 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 17:30:20.0130 2416 UxSms - ok 17:30:20.0200 2416 VaultSvc (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:30:20.0200 2416 VaultSvc - ok 17:30:20.0280 2416 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 17:30:20.0280 2416 vdrvroot - ok 17:30:20.0370 2416 vds (8c4e7c49d3641bc9e299e466a7f8867d) C:\Windows\System32\vds.exe 17:30:20.0380 2416 vds - ok 17:30:20.0470 2416 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 17:30:20.0470 2416 vga - ok 17:30:20.0550 2416 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 17:30:20.0550 2416 VgaSave - ok 17:30:20.0620 2416 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 17:30:20.0630 2416 vhdmp - ok 17:30:20.0720 2416 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 17:30:20.0720 2416 viaagp - ok 17:30:20.0780 2416 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 17:30:20.0790 2416 ViaC7 - ok 17:30:20.0860 2416 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 17:30:20.0860 2416 viaide - ok 17:30:20.0940 2416 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys 17:30:20.0940 2416 vmbus - ok 17:30:21.0010 2416 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys 17:30:21.0020 2416 VMBusHID - ok 17:30:21.0090 2416 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 17:30:21.0090 2416 volmgr - ok 17:30:21.0160 2416 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 17:30:21.0170 2416 volmgrx - ok 17:30:21.0250 2416 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 17:30:21.0250 2416 volsnap - ok 17:30:21.0350 2416 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 17:30:21.0350 2416 vsmraid - ok 17:30:21.0460 2416 VSS (7ea2bcd94d9cfaf4c556f5cc94532a6c) C:\Windows\system32\vssvc.exe 17:30:21.0490 2416 VSS - ok 17:30:21.0570 2416 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 17:30:21.0570 2416 vwifibus - ok 17:30:21.0650 2416 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 17:30:21.0660 2416 W32Time - ok 17:30:21.0730 2416 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 17:30:21.0740 2416 WacomPen - ok 17:30:21.0820 2416 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:30:21.0820 2416 WANARP - ok 17:30:21.0820 2416 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:30:21.0820 2416 Wanarpv6 - ok 17:30:21.0930 2416 wbengine (7790b77fe1e5ee47dcc66247095bb4c9) C:\Windows\system32\wbengine.exe 17:30:21.0960 2416 wbengine - ok 17:30:22.0030 2416 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 17:30:22.0040 2416 WbioSrvc - ok 17:30:22.0120 2416 wcncsvc (d0f88aa11ee1a62bcc6d6a8a7783ca11) C:\Windows\System32\wcncsvc.dll 17:30:22.0130 2416 wcncsvc - ok 17:30:22.0180 2416 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 17:30:22.0180 2416 WcsPlugInService - ok 17:30:22.0260 2416 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 17:30:22.0260 2416 Wd - ok 17:30:22.0360 2416 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 17:30:22.0360 2416 Wdf01000 - ok 17:30:22.0440 2416 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:30:22.0440 2416 WdiServiceHost - ok 17:30:22.0450 2416 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:30:22.0450 2416 WdiSystemHost - ok 17:30:22.0540 2416 WebClient (d87c7d2c517f82a5ab7a73e203063d9e) C:\Windows\System32\webclnt.dll 17:30:22.0550 2416 WebClient - ok 17:30:22.0620 2416 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 17:30:22.0630 2416 Wecsvc - ok 17:30:22.0700 2416 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 17:30:22.0700 2416 wercplsupport - ok 17:30:22.0800 2416 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 17:30:22.0810 2416 WerSvc - ok 17:30:22.0900 2416 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 17:30:22.0900 2416 WfpLwf - ok 17:30:22.0970 2416 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 17:30:22.0970 2416 WIMMount - ok 17:30:23.0070 2416 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 17:30:23.0090 2416 WinDefend - ok 17:30:23.0110 2416 WinHttpAutoProxySvc - ok 17:30:23.0220 2416 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 17:30:23.0220 2416 Winmgmt - ok 17:30:23.0340 2416 WinRM (c4f5d3901d1b41d602ddc196e0b95b51) C:\Windows\system32\WsmSvc.dll 17:30:23.0370 2416 WinRM - ok 17:30:23.0490 2416 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 17:30:23.0490 2416 WinUsb - ok 17:30:23.0580 2416 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 17:30:23.0610 2416 Wlansvc - ok 17:30:23.0690 2416 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 17:30:23.0690 2416 WmiAcpi - ok 17:30:23.0780 2416 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 17:30:23.0790 2416 wmiApSrv - ok 17:30:23.0890 2416 WMPNetworkSvc (77fbd400984cf72ba0fc4b3489d65f74) C:\Program Files\Windows Media Player\wmpnetwk.exe 17:30:23.0920 2416 WMPNetworkSvc - ok 17:30:23.0990 2416 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 17:30:23.0990 2416 WPCSvc - ok 17:30:24.0090 2416 WPDBusEnum (b7f658a2ebc07129538ad9ab35212637) C:\Windows\system32\wpdbusenum.dll 17:30:24.0090 2416 WPDBusEnum - ok 17:30:24.0170 2416 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 17:30:24.0170 2416 ws2ifsl - ok 17:30:24.0280 2416 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 17:30:24.0280 2416 wscsvc - ok 17:30:24.0340 2416 WSearch - ok 17:30:24.0460 2416 wuauserv (a33408cc036f9c08142b11be5e93f0a1) C:\Windows\system32\wuaueng.dll 17:30:24.0530 2416 wuauserv - ok 17:30:24.0610 2416 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 17:30:24.0610 2416 WudfPf - ok 17:30:24.0720 2416 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:30:24.0720 2416 WUDFRd - ok 17:30:24.0790 2416 wudfsvc (ddee3682fe97037c45f4d7ab467cb8b6) C:\Windows\System32\WUDFSvc.dll 17:30:24.0790 2416 wudfsvc - ok 17:30:24.0890 2416 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 17:30:24.0900 2416 WwanSvc - ok 17:30:25.0000 2416 xusb21 (276842a27953be204a2507096f09b1f3) C:\Windows\system32\DRIVERS\xusb21.sys 17:30:25.0000 2416 xusb21 - ok 17:30:25.0030 2416 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:30:25.0070 2416 \Device\Harddisk0\DR0 - ok 17:30:25.0070 2416 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR2 17:30:25.0080 2416 \Device\Harddisk1\DR2 - ok 17:30:25.0080 2416 Boot (0x1200) (048ccef17a24bc6e1780c46daeaabc5d) \Device\Harddisk0\DR0\Partition0 17:30:25.0080 2416 \Device\Harddisk0\DR0\Partition0 - ok 17:30:25.0100 2416 Boot (0x1200) (32258db9384e7d6cf46b868000cdf49c) \Device\Harddisk0\DR0\Partition1 17:30:25.0100 2416 \Device\Harddisk0\DR0\Partition1 - ok 17:30:25.0110 2416 Boot (0x1200) (3114ea0154e1f216b6ae1285126f4b9c) \Device\Harddisk0\DR0\Partition2 17:30:25.0110 2416 \Device\Harddisk0\DR0\Partition2 - ok 17:30:25.0130 2416 Boot (0x1200) (54a75db28dd230bec091030e7733f328) \Device\Harddisk0\DR0\Partition3 17:30:25.0130 2416 \Device\Harddisk0\DR0\Partition3 - ok 17:30:25.0150 2416 Boot (0x1200) (3be671370f2dd66c14558e1fbec7d814) \Device\Harddisk0\DR0\Partition4 17:30:25.0150 2416 \Device\Harddisk0\DR0\Partition4 - ok 17:30:25.0150 2416 Boot (0x1200) (876a2269e120b88f772795035a5ad836) \Device\Harddisk1\DR2\Partition0 17:30:25.0150 2416 \Device\Harddisk1\DR2\Partition0 - ok 17:30:25.0150 2416 ============================================================ 17:30:25.0150 2416 Scan finished 17:30:25.0150 2416 ============================================================ 17:30:25.0170 3824 Detected object count: 2 17:30:25.0170 3824 Actual detected object count: 2 17:32:01.0800 3824 CSC ( Virus.Win32.ZAccess.aml ) - skipped by user 17:32:01.0800 3824 CSC ( Virus.Win32.ZAccess.aml ) - User select action: Skip 17:32:01.0800 3824 se44mdm ( Backdoor.Multi.ZAccess.gen ) - skipped by user 17:32:01.0800 3824 se44mdm ( Backdoor.Multi.ZAccess.gen ) - User select action: Skip 17:32:21.0720 3508 ============================================================ 17:32:21.0720 3508 Scan started 17:32:21.0720 3508 Mode: Manual; 17:32:21.0720 3508 ============================================================ 17:32:21.0940 3508 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys 17:32:21.0940 3508 1394ohci - ok 17:32:22.0050 3508 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys 17:32:22.0050 3508 ACPI - ok 17:32:22.0130 3508 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys 17:32:22.0130 3508 AcpiPmi - ok 17:32:22.0230 3508 AdobeARMservice (11a52cf7b265631deeb24c6149309eff) C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 17:32:22.0230 3508 AdobeARMservice - ok 17:32:22.0320 3508 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys 17:32:22.0320 3508 adp94xx - ok 17:32:22.0440 3508 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys 17:32:22.0450 3508 adpahci - ok 17:32:22.0530 3508 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys 17:32:22.0540 3508 adpu320 - ok 17:32:22.0600 3508 AeLookupSvc (8b5eefeec1e6d1a72a06c526628ad161) C:\Windows\System32\aelupsvc.dll 17:32:22.0600 3508 AeLookupSvc - ok 17:32:22.0710 3508 AFD (ddc040fdb01ef1712a6b13e52afb104c) C:\Windows\system32\drivers\afd.sys 17:32:22.0720 3508 AFD - ok 17:32:22.0800 3508 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys 17:32:22.0800 3508 agp440 - ok 17:32:22.0900 3508 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys 17:32:22.0900 3508 aic78xx - ok 17:32:22.0960 3508 ALG (18a54e132947cd98fea9accc57f98f13) C:\Windows\System32\alg.exe 17:32:22.0960 3508 ALG - ok 17:32:23.0050 3508 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys 17:32:23.0050 3508 aliide - ok 17:32:23.0130 3508 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys 17:32:23.0130 3508 amdagp - ok 17:32:23.0190 3508 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys 17:32:23.0190 3508 amdide - ok 17:32:23.0290 3508 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys 17:32:23.0290 3508 AmdK8 - ok 17:32:23.0370 3508 AmdLLD (ad8fa28d8ed0d0a689a0559085ce0f18) C:\Windows\system32\DRIVERS\AmdLLD.sys 17:32:23.0370 3508 AmdLLD - ok 17:32:23.0460 3508 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys 17:32:23.0460 3508 AmdPPM - ok 17:32:23.0550 3508 amdsata (2101a86c25c154f8314b24ef49d7fbc2) C:\Windows\system32\DRIVERS\amdsata.sys 17:32:23.0550 3508 amdsata - ok 17:32:23.0650 3508 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys 17:32:23.0650 3508 amdsbs - ok 17:32:23.0720 3508 amdxata (b81c2b5616f6420a9941ea093a92b150) C:\Windows\system32\DRIVERS\amdxata.sys 17:32:23.0720 3508 amdxata - ok 17:32:23.0800 3508 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys 17:32:23.0800 3508 AppID - ok 17:32:23.0890 3508 AppIDSvc (62a9c86cb6085e20db4823e4e97826f5) C:\Windows\System32\appidsvc.dll 17:32:23.0890 3508 AppIDSvc - ok 17:32:23.0950 3508 Appinfo (7dead9e3f65dcb2794f2711003bbf650) C:\Windows\System32\appinfo.dll 17:32:23.0950 3508 Appinfo - ok 17:32:24.0020 3508 Apple Mobile Device (3debbecf665dcdde3a95d9b902010817) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 17:32:24.0020 3508 Apple Mobile Device - ok 17:32:24.0120 3508 AppMgmt (a45d184df6a8803da13a0b329517a64a) C:\Windows\System32\appmgmts.dll 17:32:24.0120 3508 AppMgmt - ok 17:32:24.0210 3508 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys 17:32:24.0210 3508 arc - ok 17:32:24.0330 3508 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys 17:32:24.0330 3508 arcsas - ok 17:32:24.0400 3508 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys 17:32:24.0400 3508 AsyncMac - ok 17:32:24.0500 3508 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys 17:32:24.0500 3508 atapi - ok 17:32:24.0590 3508 AudioEndpointBuilder (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:32:24.0590 3508 AudioEndpointBuilder - ok 17:32:24.0620 3508 Audiosrv (510c873bfa135aa829f4180352772734) C:\Windows\System32\Audiosrv.dll 17:32:24.0620 3508 Audiosrv - ok 17:32:24.0720 3508 AxInstSV (dd6a431b43e34b91a767d1ce33728175) C:\Windows\System32\AxInstSV.dll 17:32:24.0720 3508 AxInstSV - ok 17:32:24.0830 3508 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys 17:32:24.0830 3508 b06bdrv - ok 17:32:24.0930 3508 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys 17:32:24.0930 3508 b57nd60x - ok 17:32:25.0010 3508 BDESVC (ee1e9c3bb8228ae423dd38db69128e71) C:\Windows\System32\bdesvc.dll 17:32:25.0010 3508 BDESVC - ok 17:32:25.0110 3508 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys 17:32:25.0110 3508 Beep - ok 17:32:25.0220 3508 BITS (53f476476f55a27f580661bde09c4ec4) C:\Windows\System32\qmgr.dll 17:32:25.0220 3508 BITS - ok 17:32:25.0330 3508 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys 17:32:25.0330 3508 blbdrive - ok 17:32:25.0410 3508 Bonjour Service (db5bea73edaf19ac68b2c0fad0f92b1a) C:\Program Files\Bonjour\mDNSResponder.exe 17:32:25.0410 3508 Bonjour Service - ok 17:32:25.0520 3508 bowser (fcafaef6798d7b51ff029f99a9898961) C:\Windows\system32\DRIVERS\bowser.sys 17:32:25.0520 3508 bowser - ok 17:32:25.0600 3508 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys 17:32:25.0600 3508 BrFiltLo - ok 17:32:25.0680 3508 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys 17:32:25.0680 3508 BrFiltUp - ok 17:32:25.0770 3508 BridgeMP (77361d72a04f18809d0efb6cceb74d4b) C:\Windows\system32\DRIVERS\bridge.sys 17:32:25.0770 3508 BridgeMP - ok 17:32:25.0840 3508 Browser (598e1280e7ff3744f4b8329366cc5635) C:\Windows\System32\browser.dll 17:32:25.0840 3508 Browser - ok 17:32:25.0960 3508 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys 17:32:25.0960 3508 Brserid - ok 17:32:26.0030 3508 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys 17:32:26.0030 3508 BrSerWdm - ok 17:32:26.0120 3508 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys 17:32:26.0120 3508 BrUsbMdm - ok 17:32:26.0200 3508 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys 17:32:26.0200 3508 BrUsbSer - ok 17:32:26.0340 3508 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys 17:32:26.0340 3508 BTHMODEM - ok 17:32:26.0410 3508 bthserv (1df19c96eef6c29d1c3e1a8678e07190) C:\Windows\system32\bthserv.dll 17:32:26.0410 3508 bthserv - ok 17:32:26.0480 3508 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys 17:32:26.0480 3508 cdfs - ok 17:32:26.0580 3508 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys 17:32:26.0580 3508 cdrom - ok 17:32:26.0650 3508 CertPropSvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:32:26.0650 3508 CertPropSvc - ok 17:32:26.0750 3508 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys 17:32:26.0750 3508 circlass - ok 17:32:26.0830 3508 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys 17:32:26.0830 3508 CLFS - ok 17:32:26.0890 3508 clr_optimization_v2.0.50727_32 (d88040f816fda31c3b466f0fa0918f29) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 17:32:26.0900 3508 clr_optimization_v2.0.50727_32 - ok 17:32:26.0980 3508 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys 17:32:26.0980 3508 CmBatt - ok 17:32:27.0060 3508 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys 17:32:27.0060 3508 cmdide - ok 17:32:27.0180 3508 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys 17:32:27.0180 3508 CNG - ok 17:32:27.0260 3508 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys 17:32:27.0260 3508 Compbatt - ok 17:32:27.0360 3508 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys 17:32:27.0360 3508 CompositeBus - ok 17:32:27.0410 3508 COMSysApp - ok 17:32:27.0450 3508 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys 17:32:27.0450 3508 crcdisk - ok 17:32:27.0540 3508 CryptSvc (9c231178ce4fb385f4b54b0a9080b8a4) C:\Windows\system32\cryptsvc.dll 17:32:27.0540 3508 CryptSvc - ok 17:32:27.0630 3508 CSC (64450e1fb77c72d12e519a627c521fff) C:\Windows\system32\drivers\csc.sys 17:32:27.0640 3508 Suspicious file (Forged): C:\Windows\system32\drivers\csc.sys. Real md5: 64450e1fb77c72d12e519a627c521fff, Fake md5: 27c9490bdd0ae48911ab8cf1932591ed 17:32:27.0640 3508 CSC ( Virus.Win32.ZAccess.aml ) - infected 17:32:27.0640 3508 CSC - detected Virus.Win32.ZAccess.aml (0) 17:32:27.0770 3508 CscService (56fb5f222ea30d3d3fc459879772cb73) C:\Windows\System32\cscsvc.dll 17:32:27.0770 3508 CscService - ok 17:32:27.0870 3508 DcomLaunch (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 17:32:27.0870 3508 DcomLaunch - ok 17:32:27.0960 3508 defragsvc (8d6e10a2d9a5eed59562d9b82cf804e1) C:\Windows\System32\defragsvc.dll 17:32:27.0960 3508 defragsvc - ok 17:32:28.0040 3508 DfsC (8e09e52ee2e3ceb199ef3dd99cf9e3fb) C:\Windows\system32\Drivers\dfsc.sys 17:32:28.0040 3508 DfsC - ok 17:32:28.0130 3508 Dhcp (c56495fbd770712367cad35e5de72da6) C:\Windows\system32\dhcpcore.dll 17:32:28.0130 3508 Dhcp - ok 17:32:28.0220 3508 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys 17:32:28.0230 3508 discache - ok 17:32:28.0330 3508 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys 17:32:28.0330 3508 Disk - ok 17:32:28.0420 3508 Dnscache (d0722e963d3c6145446874241401b209) C:\Windows\System32\dnsrslvr.dll 17:32:28.0420 3508 Dnscache - ok 17:32:28.0490 3508 dot3svc (4408c85c21eea48eb0ce486baeef0502) C:\Windows\System32\dot3svc.dll 17:32:28.0490 3508 dot3svc - ok 17:32:28.0580 3508 DPS (7fa81c6e11caa594adb52084da73a1e5) C:\Windows\system32\dps.dll 17:32:28.0590 3508 DPS - ok 17:32:28.0660 3508 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys 17:32:28.0660 3508 drmkaud - ok 17:32:28.0760 3508 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys 17:32:28.0770 3508 dtsoftbus01 - ok 17:32:28.0870 3508 DXGKrnl (39806cfeddcc55e686a49bccd2972f23) C:\Windows\System32\drivers\dxgkrnl.sys 17:32:28.0870 3508 DXGKrnl - ok 17:32:28.0930 3508 EapHost (8600142fa91c1b96367d3300ad0f3f3a) C:\Windows\System32\eapsvc.dll 17:32:28.0940 3508 EapHost - ok 17:32:29.0120 3508 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys 17:32:29.0130 3508 ebdrv - ok 17:32:29.0240 3508 EFS (f42309c4191c506b71db5d1126d26318) C:\Windows\System32\lsass.exe 17:32:29.0240 3508 EFS - ok 17:32:29.0310 3508 ehRecvr (3a74a6e33685662b125a3269b1f2114f) C:\Windows\ehome\ehRecvr.exe 17:32:29.0310 3508 ehRecvr - ok 17:32:29.0380 3508 ehSched (d389bff34f80caede417bf9d1507996a) C:\Windows\ehome\ehsched.exe 17:32:29.0380 3508 ehSched - ok 17:32:29.0490 3508 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys 17:32:29.0500 3508 elxstor - ok 17:32:29.0580 3508 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys 17:32:29.0580 3508 ErrDev - ok 17:32:29.0650 3508 EventSystem (f6916efc29d9953d5d0df06882ae8e16) C:\Windows\system32\es.dll 17:32:29.0650 3508 EventSystem - ok 17:32:29.0730 3508 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys 17:32:29.0730 3508 exfat - ok 17:32:29.0860 3508 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys 17:32:29.0860 3508 fastfat - ok 17:32:29.0960 3508 Fax (f7ea23cc5e6bf2181f3f399d54f6efc1) C:\Windows\system32\fxssvc.exe 17:32:29.0970 3508 Fax - ok 17:32:30.0050 3508 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys 17:32:30.0050 3508 fdc - ok 17:32:30.0120 3508 fdPHost (f3222c893bd2f5821a0179e5c71e88fb) C:\Windows\system32\fdPHost.dll 17:32:30.0120 3508 fdPHost - ok 17:32:30.0200 3508 FDResPub (7dbe8cbfe79efbdeb98c9fb08d3a9a5b) C:\Windows\system32\fdrespub.dll 17:32:30.0200 3508 FDResPub - ok 17:32:30.0280 3508 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys 17:32:30.0280 3508 FileInfo - ok 17:32:30.0380 3508 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys 17:32:30.0380 3508 Filetrace - ok 17:32:30.0470 3508 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys 17:32:30.0470 3508 flpydisk - ok 17:32:30.0550 3508 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys 17:32:30.0550 3508 FltMgr - ok 17:32:30.0680 3508 FontCache (b6512a85815fdc3d560c3705f5bdb93d) C:\Windows\system32\FntCache.dll 17:32:30.0690 3508 FontCache - ok 17:32:30.0740 3508 FontCache3.0.0.0 (e56f39f6b7fda0ac77a79b0fd3de1a2f) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 17:32:30.0750 3508 FontCache3.0.0.0 - ok 17:32:30.0850 3508 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys 17:32:30.0850 3508 FsDepends - ok 17:32:30.0930 3508 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys 17:32:30.0930 3508 Fs_Rec - ok 17:32:31.0030 3508 fvevol (5592f5dba26282d24d2b080eb438a4d7) C:\Windows\system32\DRIVERS\fvevol.sys 17:32:31.0030 3508 fvevol - ok 17:32:31.0110 3508 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys 17:32:31.0110 3508 gagp30kx - ok 17:32:31.0190 3508 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 17:32:31.0190 3508 GEARAspiWDM - ok 17:32:31.0280 3508 gpsvc (8ba3c04702bf8f927ab36ae8313ca4ee) C:\Windows\System32\gpsvc.dll 17:32:31.0280 3508 gpsvc - ok 17:32:31.0360 3508 gupdate (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe 17:32:31.0370 3508 gupdate - ok 17:32:31.0370 3508 gupdatem (506708142bc63daba64f2d3ad1dcd5bf) C:\Program Files\Google\Update\GoogleUpdate.exe 17:32:31.0370 3508 gupdatem - ok 17:32:31.0420 3508 gusvc (c1b577b2169900f4cf7190c39f085794) C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 17:32:31.0420 3508 gusvc - ok 17:32:31.0510 3508 hamachi (7929a161f9951d173ca9900fe7067391) C:\Windows\system32\DRIVERS\hamachi.sys 17:32:31.0510 3508 hamachi - ok 17:32:31.0580 3508 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys 17:32:31.0580 3508 hcw85cir - ok 17:32:31.0690 3508 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys 17:32:31.0690 3508 HDAudBus - ok 17:32:31.0760 3508 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys 17:32:31.0760 3508 HidBatt - ok 17:32:31.0860 3508 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys 17:32:31.0860 3508 HidBth - ok 17:32:31.0930 3508 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys 17:32:31.0930 3508 HidIr - ok 17:32:32.0010 3508 hidserv (2bc6f6a1992b3a77f5f41432ca6b3b6b) C:\Windows\System32\hidserv.dll 17:32:32.0010 3508 hidserv - ok 17:32:32.0080 3508 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys 17:32:32.0080 3508 HidUsb - ok 17:32:32.0160 3508 hkmsvc (741c2a45ca8407e374aaba3e330b7872) C:\Windows\system32\kmsvc.dll 17:32:32.0160 3508 hkmsvc - ok 17:32:32.0260 3508 HomeGroupListener (a768ca158bb06782a2835b907f4873c3) C:\Windows\system32\ListSvc.dll 17:32:32.0260 3508 HomeGroupListener - ok 17:32:32.0360 3508 HomeGroupProvider (fb08dec5ef43d0c66d83b8e9694e7549) C:\Windows\system32\provsvc.dll 17:32:32.0360 3508 HomeGroupProvider - ok 17:32:32.0460 3508 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys 17:32:32.0460 3508 HpSAMD - ok 17:32:32.0560 3508 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys 17:32:32.0560 3508 HTTP - ok 17:32:32.0660 3508 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys 17:32:32.0660 3508 hwpolicy - ok 17:32:32.0740 3508 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys 17:32:32.0740 3508 i8042prt - ok 17:32:32.0840 3508 iaStorV (934af4d7c5f457b9f0743f4299b77b67) C:\Windows\system32\DRIVERS\iaStorV.sys 17:32:32.0840 3508 iaStorV - ok 17:32:32.0930 3508 idsvc (5af815eb5bc9802e5a064e2ba62bfc0c) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 17:32:32.0930 3508 idsvc - ok 17:32:33.0010 3508 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys 17:32:33.0010 3508 iirsp - ok 17:32:33.0110 3508 IKEEXT (fac0ee6562b121b1399d6e855583f7a5) C:\Windows\System32\ikeext.dll 17:32:33.0120 3508 IKEEXT - ok 17:32:33.0200 3508 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys 17:32:33.0200 3508 intelide - ok 17:32:33.0300 3508 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys 17:32:33.0300 3508 intelppm - ok 17:32:33.0370 3508 IPBusEnum (acb364b9075a45c0736e5c47be5cae19) C:\Windows\system32\ipbusenum.dll 17:32:33.0370 3508 IPBusEnum - ok 17:32:33.0460 3508 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys 17:32:33.0460 3508 IpFilterDriver - ok 17:32:33.0550 3508 iphlpsvc (477397b432a256a50ee7e4339eb9ea14) C:\Windows\System32\iphlpsvc.dll 17:32:33.0550 3508 iphlpsvc - ok 17:32:33.0640 3508 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys 17:32:33.0640 3508 IPMIDRV - ok 17:32:33.0740 3508 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys 17:32:33.0740 3508 IPNAT - ok 17:32:33.0810 3508 iPod Service (49918803b661367023bf325cf602afdc) C:\Program Files\iPod\bin\iPodService.exe 17:32:33.0820 3508 iPod Service - ok 17:32:33.0910 3508 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys 17:32:33.0910 3508 IRENUM - ok 17:32:33.0990 3508 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys 17:32:33.0990 3508 isapnp - ok 17:32:34.0100 3508 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys 17:32:34.0100 3508 iScsiPrt - ok 17:32:34.0180 3508 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys 17:32:34.0180 3508 kbdclass - ok 17:32:34.0270 3508 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys 17:32:34.0270 3508 kbdhid - ok 17:32:34.0370 3508 KeyIso (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:32:34.0370 3508 KeyIso - ok 17:32:34.0450 3508 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys 17:32:34.0450 3508 KSecDD - ok 17:32:34.0550 3508 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys 17:32:34.0560 3508 KSecPkg - ok 17:32:34.0640 3508 KtmRm (89a7b9cc98d0d80c6f31b91c0a310fcd) C:\Windows\system32\msdtckrm.dll 17:32:34.0640 3508 KtmRm - ok 17:32:34.0730 3508 LanmanServer (bca92cb047a4326925ecef759dbaa233) C:\Windows\System32\srvsvc.dll 17:32:34.0740 3508 LanmanServer - ok 17:32:34.0810 3508 LanmanWorkstation (b9891f885dcf1f0513a51cb58493cb1f) C:\Windows\System32\wkssvc.dll 17:32:34.0810 3508 LanmanWorkstation - ok 17:32:34.0910 3508 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys 17:32:34.0910 3508 lltdio - ok 17:32:34.0990 3508 lltdsvc (5700673e13a2117fa3b9020c852c01e2) C:\Windows\System32\lltdsvc.dll 17:32:34.0990 3508 lltdsvc - ok 17:32:35.0080 3508 lmhosts (55ca01ba19d0006c8f2639b6c045e08b) C:\Windows\System32\lmhsvc.dll 17:32:35.0080 3508 lmhosts - ok 17:32:35.0180 3508 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys 17:32:35.0190 3508 LSI_FC - ok 17:32:35.0270 3508 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys 17:32:35.0270 3508 LSI_SAS - ok 17:32:35.0360 3508 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys 17:32:35.0360 3508 LSI_SAS2 - ok 17:32:35.0430 3508 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys 17:32:35.0440 3508 LSI_SCSI - ok 17:32:35.0530 3508 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys 17:32:35.0530 3508 luafv - ok 17:32:35.0600 3508 McComponentHostService (f453d1e6d881e8f8717e20ccd4199e85) C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe 17:32:35.0600 3508 McComponentHostService - ok 17:32:35.0680 3508 Mcx2Svc (e2b0887816ed336685954e3d8fdaa51d) C:\Windows\system32\Mcx2Svc.dll 17:32:35.0680 3508 Mcx2Svc - ok 17:32:35.0810 3508 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys 17:32:35.0810 3508 megasas - ok 17:32:35.0900 3508 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys 17:32:35.0900 3508 MegaSR - ok 17:32:35.0980 3508 MMCSS (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:32:35.0990 3508 MMCSS - ok 17:32:36.0070 3508 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys 17:32:36.0070 3508 Modem - ok 17:32:36.0150 3508 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys 17:32:36.0150 3508 monitor - ok 17:32:36.0240 3508 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys 17:32:36.0240 3508 mouclass - ok 17:32:36.0350 3508 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys 17:32:36.0350 3508 mouhid - ok 17:32:36.0440 3508 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys 17:32:36.0440 3508 mountmgr - ok 17:32:36.0520 3508 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys 17:32:36.0520 3508 mpio - ok 17:32:36.0610 3508 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys 17:32:36.0610 3508 mpsdrv - ok 17:32:36.0700 3508 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys 17:32:36.0700 3508 MRxDAV - ok 17:32:36.0800 3508 mrxsmb (f4a054be78af7f410129c4b64b07dc9b) C:\Windows\system32\DRIVERS\mrxsmb.sys 17:32:36.0810 3508 mrxsmb - ok 17:32:36.0890 3508 mrxsmb10 (deffa295bd1895c6ed8e3078412ac60b) C:\Windows\system32\DRIVERS\mrxsmb10.sys 17:32:36.0890 3508 mrxsmb10 - ok 17:32:37.0000 3508 mrxsmb20 (24d76abe5dcad22f19d105f76fdf0ce1) C:\Windows\system32\DRIVERS\mrxsmb20.sys 17:32:37.0000 3508 mrxsmb20 - ok 17:32:37.0070 3508 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys 17:32:37.0070 3508 msahci - ok 17:32:37.0160 3508 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys 17:32:37.0160 3508 msdsm - ok 17:32:37.0240 3508 MSDTC (e1bce74a3bd9902b72599c0192a07e27) C:\Windows\System32\msdtc.exe 17:32:37.0250 3508 MSDTC - ok 17:32:37.0320 3508 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys 17:32:37.0320 3508 Msfs - ok 17:32:37.0420 3508 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys 17:32:37.0420 3508 mshidkmdf - ok 17:32:37.0500 3508 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys 17:32:37.0500 3508 msisadrv - ok 17:32:37.0590 3508 MSiSCSI (90f7d9e6b6f27e1a707d4a297f077828) C:\Windows\system32\iscsiexe.dll 17:32:37.0590 3508 MSiSCSI - ok 17:32:37.0650 3508 msiserver - ok 17:32:37.0690 3508 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys 17:32:37.0690 3508 MSKSSRV - ok 17:32:37.0790 3508 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys 17:32:37.0790 3508 MSPCLOCK - ok 17:32:37.0870 3508 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys 17:32:37.0870 3508 MSPQM - ok 17:32:37.0950 3508 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys 17:32:37.0960 3508 MsRPC - ok 17:32:38.0050 3508 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys 17:32:38.0050 3508 mssmbios - ok 17:32:38.0130 3508 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys 17:32:38.0130 3508 MSTEE - ok 17:32:38.0260 3508 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys 17:32:38.0260 3508 MTConfig - ok 17:32:38.0330 3508 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys 17:32:38.0330 3508 Mup - ok 17:32:38.0450 3508 napagent (80284f1985c70c86f0b5f86da2dfe1df) C:\Windows\system32\qagentRT.dll 17:32:38.0450 3508 napagent - ok 17:32:38.0540 3508 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys 17:32:38.0540 3508 NativeWifiP - ok 17:32:38.0660 3508 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys 17:32:38.0670 3508 NDIS - ok 17:32:38.0750 3508 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys 17:32:38.0750 3508 NdisCap - ok 17:32:38.0870 3508 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys 17:32:38.0870 3508 NdisTapi - ok 17:32:38.0940 3508 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys 17:32:38.0950 3508 Ndisuio - ok 17:32:39.0050 3508 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys 17:32:39.0050 3508 NdisWan - ok 17:32:39.0120 3508 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys 17:32:39.0120 3508 NDProxy - ok 17:32:39.0220 3508 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys 17:32:39.0220 3508 NetBIOS - ok 17:32:39.0300 3508 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys 17:32:39.0300 3508 NetBT - ok 17:32:39.0370 3508 Netlogon (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:32:39.0380 3508 Netlogon - ok 17:32:39.0490 3508 Netman (7cccfca7510684768da22092d1fa4db2) C:\Windows\System32\netman.dll 17:32:39.0490 3508 Netman - ok 17:32:39.0580 3508 netprofm (8c338238c16777a802d6a9211eb2ba50) C:\Windows\System32\netprofm.dll 17:32:39.0580 3508 netprofm - ok 17:32:39.0670 3508 NetTcpPortSharing (fe2aa5a684b0dd9b1fae57b7817c198b) C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 17:32:39.0670 3508 NetTcpPortSharing - ok 17:32:39.0730 3508 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys 17:32:39.0730 3508 nfrd960 - ok 17:32:39.0800 3508 NlaSvc (2226496e34bd40734946a054b1cd657f) C:\Windows\System32\nlasvc.dll 17:32:39.0810 3508 NlaSvc - ok 17:32:39.0910 3508 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys 17:32:39.0910 3508 Npfs - ok 17:32:39.0980 3508 nsi (ba387e955e890c8a88306d9b8d06bf17) C:\Windows\system32\nsisvc.dll 17:32:39.0990 3508 nsi - ok 17:32:40.0080 3508 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys 17:32:40.0080 3508 nsiproxy - ok 17:32:40.0260 3508 Ntfs (3795dcd21f740ee799fb7223234215af) C:\Windows\system32\drivers\Ntfs.sys 17:32:40.0270 3508 Ntfs - ok 17:32:40.0340 3508 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys 17:32:40.0340 3508 Null - ok 17:32:40.0450 3508 NVENETFD (b5e37e31c053bc9950455a257526514b) C:\Windows\system32\DRIVERS\nvm62x32.sys 17:32:40.0460 3508 NVENETFD - ok 17:32:40.0820 3508 nvlddmkm (66b4bf606fcc7f0622d4a21bb1461089) C:\Windows\system32\DRIVERS\nvlddmkm.sys 17:32:40.0870 3508 nvlddmkm - ok 17:32:40.0960 3508 nvraid (3f3d04b1d08d43c16ea7963954ec768d) C:\Windows\system32\DRIVERS\nvraid.sys 17:32:40.0960 3508 nvraid - ok 17:32:41.0050 3508 nvstor (c99f251a5de63c6f129cf71933aced0f) C:\Windows\system32\DRIVERS\nvstor.sys 17:32:41.0060 3508 nvstor - ok 17:32:41.0170 3508 nvsvc (d122f7c5f79c68868f5dc28cefeb2ecf) C:\Windows\system32\nvvsvc.exe 17:32:41.0170 3508 nvsvc - ok 17:32:41.0340 3508 nvUpdatusService (003cb0a155568b4a53a301f07c734233) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe 17:32:41.0350 3508 nvUpdatusService - ok 17:32:41.0440 3508 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys 17:32:41.0440 3508 nv_agp - ok 17:32:41.0510 3508 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys 17:32:41.0510 3508 ohci1394 - ok 17:32:41.0590 3508 p2pimsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:32:41.0590 3508 p2pimsvc - ok 17:32:41.0700 3508 p2psvc (59c3ddd501e39e006dac31bf55150d91) C:\Windows\system32\p2psvc.dll 17:32:41.0700 3508 p2psvc - ok 17:32:41.0790 3508 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys 17:32:41.0790 3508 Parport - ok 17:32:41.0890 3508 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys 17:32:41.0890 3508 partmgr - ok 17:32:41.0970 3508 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys 17:32:41.0970 3508 Parvdm - ok 17:32:42.0050 3508 PcaSvc (358ab7956d3160000726574083dfc8a6) C:\Windows\System32\pcasvc.dll 17:32:42.0050 3508 PcaSvc - ok 17:32:42.0140 3508 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys 17:32:42.0150 3508 pci - ok 17:32:42.0220 3508 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys 17:32:42.0230 3508 pciide - ok 17:32:42.0350 3508 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys 17:32:42.0350 3508 pcmcia - ok 17:32:42.0430 3508 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys 17:32:42.0430 3508 pcw - ok 17:32:42.0560 3508 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys 17:32:42.0560 3508 PEAUTH - ok 17:32:42.0700 3508 PeerDistSvc (af4d64d2a57b9772cf3801950b8058a6) C:\Windows\system32\peerdistsvc.dll 17:32:42.0710 3508 PeerDistSvc - ok 17:32:42.0840 3508 pla (9c1bff7910c89a1d12e57343475840cb) C:\Windows\system32\pla.dll 17:32:42.0850 3508 pla - ok 17:32:42.0940 3508 PlugPlay (2cc2008f1296968fba162ed9f9afe328) C:\Windows\system32\umpnpmgr.dll 17:32:42.0940 3508 PlugPlay - ok 17:32:43.0010 3508 PnkBstrA (3a2e85f7d90d15460c337ce80c2e3b29) C:\Windows\system32\PnkBstrA.exe 17:32:43.0020 3508 PnkBstrA - ok 17:32:43.0100 3508 PNRPAutoReg (63ff8572611249931eb16bb8eed6afc8) C:\Windows\system32\pnrpauto.dll 17:32:43.0100 3508 PNRPAutoReg - ok 17:32:43.0180 3508 PNRPsvc (82a8521ddc60710c3d3d3e7325209bec) C:\Windows\system32\pnrpsvc.dll 17:32:43.0180 3508 PNRPsvc - ok 17:32:43.0270 3508 PolicyAgent (48e1b75c6dc0232fd92baae4bd344721) C:\Windows\System32\ipsecsvc.dll 17:32:43.0270 3508 PolicyAgent - ok 17:32:43.0360 3508 Power (dbff83f709a91049621c1d35dd45c92c) C:\Windows\system32\umpo.dll 17:32:43.0360 3508 Power - ok 17:32:43.0440 3508 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys 17:32:43.0440 3508 PptpMiniport - ok 17:32:43.0530 3508 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys 17:32:43.0530 3508 Processor - ok 17:32:43.0600 3508 ProfSvc (630cf26f0227498b7d5a92b12548960f) C:\Windows\system32\profsvc.dll 17:32:43.0600 3508 ProfSvc - ok 17:32:43.0670 3508 ProtectedStorage (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:32:43.0670 3508 ProtectedStorage - ok 17:32:43.0790 3508 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys 17:32:43.0790 3508 Psched - ok 17:32:43.0960 3508 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys 17:32:43.0970 3508 ql2300 - ok 17:32:44.0050 3508 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys 17:32:44.0050 3508 ql40xx - ok 17:32:44.0150 3508 QWAVE (31ac809e7707eb580b2bdb760390765a) C:\Windows\system32\qwave.dll 17:32:44.0160 3508 QWAVE - ok 17:32:44.0240 3508 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys 17:32:44.0240 3508 QWAVEdrv - ok 17:32:44.0370 3508 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys 17:32:44.0370 3508 RasAcd - ok 17:32:44.0430 3508 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys 17:32:44.0440 3508 RasAgileVpn - ok 17:32:44.0510 3508 RasAuto (a60f1839849c0c00739787fd5ec03f13) C:\Windows\System32\rasauto.dll 17:32:44.0510 3508 RasAuto - ok 17:32:44.0610 3508 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys 17:32:44.0610 3508 Rasl2tp - ok 17:32:44.0690 3508 RasMan (0ce66ec736b7fc526d78f7624c7d2a94) C:\Windows\System32\rasmans.dll 17:32:44.0690 3508 RasMan - ok 17:32:44.0800 3508 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys 17:32:44.0800 3508 RasPppoe - ok 17:32:44.0880 3508 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys 17:32:44.0880 3508 RasSstp - ok 17:32:45.0000 3508 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys 17:32:45.0000 3508 rdbss - ok 17:32:45.0080 3508 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys 17:32:45.0080 3508 rdpbus - ok 17:32:45.0180 3508 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys 17:32:45.0180 3508 RDPCDD - ok 17:32:45.0280 3508 RDPDR (c5ff95883ffef704d50c40d21cfb3ab5) C:\Windows\system32\drivers\rdpdr.sys 17:32:45.0290 3508 RDPDR - ok 17:32:45.0390 3508 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys 17:32:45.0390 3508 RDPENCDD - ok 17:32:45.0470 3508 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys 17:32:45.0470 3508 RDPREFMP - ok 17:32:45.0580 3508 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys 17:32:45.0580 3508 RDPWD - ok 17:32:45.0670 3508 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys 17:32:45.0670 3508 rdyboost - ok 17:32:45.0750 3508 RemoteAccess (7b5e1419717fac363a31cc302895217a) C:\Windows\System32\mprdim.dll 17:32:45.0750 3508 RemoteAccess - ok 17:32:45.0840 3508 RemoteRegistry (cb9a8683f4ef2bf99e123d79950d7935) C:\Windows\system32\regsvc.dll 17:32:45.0840 3508 RemoteRegistry - ok 17:32:45.0900 3508 RpcEptMapper (78d072f35bc45d9e4e1b61895c152234) C:\Windows\System32\RpcEpMap.dll 17:32:45.0900 3508 RpcEptMapper - ok 17:32:45.0940 3508 RpcLocator (94d36c0e44677dd26981d2bfeef2a29d) C:\Windows\system32\locator.exe 17:32:45.0940 3508 RpcLocator - ok 17:32:46.0050 3508 RpcSs (b82cd39e336973359d7c9bf911e8e84f) C:\Windows\system32\rpcss.dll 17:32:46.0050 3508 RpcSs - ok 17:32:46.0140 3508 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys 17:32:46.0140 3508 rspndr - ok 17:32:46.0260 3508 s3cap (5423d8437051e89dd34749f242c98648) C:\Windows\system32\DRIVERS\vms3cap.sys 17:32:46.0260 3508 s3cap - ok 17:32:46.0330 3508 SamSs (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:32:46.0330 3508 SamSs - ok 17:32:46.0440 3508 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys 17:32:46.0450 3508 sbp2port - ok 17:32:46.0540 3508 SCardSvr (8fc518ffe9519c2631d37515a68009c4) C:\Windows\System32\SCardSvr.dll 17:32:46.0550 3508 SCardSvr - ok 17:32:46.0650 3508 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys 17:32:46.0650 3508 scfilter - ok 17:32:46.0740 3508 Schedule (3e8b0c453e25613a1f59762a5c42aa75) C:\Windows\system32\schedsvc.dll 17:32:46.0750 3508 Schedule - ok 17:32:46.0840 3508 SCPolicySvc (628a9e30ec5e18dd5de6be4dbdc12198) C:\Windows\System32\certprop.dll 17:32:46.0840 3508 SCPolicySvc - ok 17:32:46.0910 3508 SDRSVC (5fd90abdbfaee85986802622cbb03446) C:\Windows\System32\SDRSVC.dll 17:32:46.0910 3508 SDRSVC - ok 17:32:46.0990 3508 se44mdm (b89cfbe8cb247b57d8c10adaa66b462b) C:\Windows\system32\msgsrvservice.dll 17:32:46.0990 3508 se44mdm ( Backdoor.Multi.ZAccess.gen ) - infected 17:32:46.0990 3508 se44mdm - detected Backdoor.Multi.ZAccess.gen (0) 17:32:47.0070 3508 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys 17:32:47.0070 3508 secdrv - ok 17:32:47.0150 3508 seclogon (a59b3a4442c52060cc7a85293aa3546f) C:\Windows\system32\seclogon.dll 17:32:47.0150 3508 seclogon - ok 17:32:47.0240 3508 SENS (dcb7fcdcc97f87360f75d77425b81737) C:\Windows\System32\sens.dll 17:32:47.0240 3508 SENS - ok 17:32:47.0310 3508 SensrSvc (50087fe1ee447009c9cc2997b90de53f) C:\Windows\system32\sensrsvc.dll 17:32:47.0310 3508 SensrSvc - ok 17:32:47.0390 3508 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys 17:32:47.0390 3508 Serenum - ok 17:32:47.0480 3508 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys 17:32:47.0480 3508 Serial - ok 17:32:47.0550 3508 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys 17:32:47.0550 3508 sermouse - ok 17:32:47.0630 3508 SessionEnv (8f55ce568c543d5adf45c409d16718fc) C:\Windows\system32\sessenv.dll 17:32:47.0630 3508 SessionEnv - ok 17:32:47.0710 3508 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys 17:32:47.0710 3508 sffdisk - ok 17:32:47.0780 3508 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys 17:32:47.0780 3508 sffp_mmc - ok 17:32:47.0860 3508 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys 17:32:47.0860 3508 sffp_sd - ok 17:32:47.0930 3508 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys 17:32:47.0930 3508 sfloppy - ok 17:32:48.0040 3508 SharedAccess (d1a079a0de2ea524513b6930c24527a2) C:\Windows\System32\ipnathlp.dll 17:32:48.0040 3508 SharedAccess - ok 17:32:48.0120 3508 ShellHWDetection (cd2e48fa5b29ee2b3b5858056d246ef2) C:\Windows\System32\shsvcs.dll 17:32:48.0130 3508 ShellHWDetection - ok 17:32:48.0200 3508 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys 17:32:48.0200 3508 sisagp - ok 17:32:48.0280 3508 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys 17:32:48.0280 3508 SiSRaid2 - ok 17:32:48.0340 3508 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys 17:32:48.0340 3508 SiSRaid4 - ok 17:32:48.0410 3508 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys 17:32:48.0410 3508 Smb - ok 17:32:48.0470 3508 SNMPTRAP (6a984831644eca1a33ffeae4126f4f37) C:\Windows\System32\snmptrap.exe 17:32:48.0480 3508 SNMPTRAP - ok 17:32:48.0570 3508 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys 17:32:48.0570 3508 spldr - ok 17:32:48.0660 3508 Spooler (49b6dd6ab3715b7a67965f17194e98a9) C:\Windows\System32\spoolsv.exe 17:32:48.0660 3508 Spooler - ok 17:32:48.0840 3508 sppsvc (4c287f9069fedbd791178876ee9de536) C:\Windows\system32\sppsvc.exe 17:32:48.0860 3508 sppsvc - ok 17:32:48.0930 3508 sppuinotify (d8e3e19eebdab49dd4a8d3062ead4ec7) C:\Windows\system32\sppuinotify.dll 17:32:48.0930 3508 sppuinotify - ok 17:32:49.0040 3508 srv (2ba4ebc7dfba845a1edbe1f75913be33) C:\Windows\system32\DRIVERS\srv.sys 17:32:49.0040 3508 srv - ok 17:32:49.0120 3508 srv2 (dce7e10feaabd4cae95948b3de5340bb) C:\Windows\system32\DRIVERS\srv2.sys 17:32:49.0120 3508 srv2 - ok 17:32:49.0200 3508 srvnet (b5665baa2120b8a54e22e9cd07c05106) C:\Windows\system32\DRIVERS\srvnet.sys 17:32:49.0210 3508 srvnet - ok 17:32:49.0300 3508 SSDPSRV (d887c9fd02ac9fa880f6e5027a43e118) C:\Windows\System32\ssdpsrv.dll 17:32:49.0310 3508 SSDPSRV - ok 17:32:49.0370 3508 SstpSvc (d318f23be45d5e3a107469eb64815b50) C:\Windows\system32\sstpsvc.dll 17:32:49.0380 3508 SstpSvc - ok 17:32:49.0420 3508 Steam Client Service - ok 17:32:49.0530 3508 Stereo Service (9e1222c417291bc836210743624a8e5e) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 17:32:49.0540 3508 Stereo Service - ok 17:32:49.0610 3508 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys 17:32:49.0610 3508 stexstor - ok 17:32:49.0720 3508 StiSvc (a22825e7bb7018e8af3e229a5af17221) C:\Windows\System32\wiaservc.dll 17:32:49.0730 3508 StiSvc - ok 17:32:49.0800 3508 storflt (957e346ca948668f2496a6ccf6ff82cc) C:\Windows\system32\DRIVERS\vmstorfl.sys 17:32:49.0800 3508 storflt - ok 17:32:49.0900 3508 storvsc (d5751969dc3e4b88bf482ac8ec9fe019) C:\Windows\system32\DRIVERS\storvsc.sys 17:32:49.0900 3508 storvsc - ok 17:32:49.0960 3508 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys 17:32:49.0960 3508 swenum - ok 17:32:50.0040 3508 swprv (a28bd92df340e57b024ba433165d34d7) C:\Windows\System32\swprv.dll 17:32:50.0040 3508 swprv - ok 17:32:50.0160 3508 SysMain (04105c8da62353589c29bdaeb8d88bd8) C:\Windows\system32\sysmain.dll 17:32:50.0170 3508 SysMain - ok 17:32:50.0240 3508 TabletInputService (fcfb6c552fbc0da299799cbd50ad9fd4) C:\Windows\System32\TabSvc.dll 17:32:50.0240 3508 TabletInputService - ok 17:32:50.0360 3508 TapiSrv (2f46b0c70a4adc8c90cf825da3b4feaf) C:\Windows\System32\tapisrv.dll 17:32:50.0360 3508 TapiSrv - ok 17:32:50.0440 3508 TBS (b799d9fdb26111737f58288d8dc172d9) C:\Windows\System32\tbssvc.dll 17:32:50.0440 3508 TBS - ok 17:32:50.0580 3508 Tcpip (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\drivers\tcpip.sys 17:32:50.0590 3508 Tcpip - ok 17:32:50.0720 3508 TCPIP6 (2cc3d75488abd3ec628bbb9a4fc84efc) C:\Windows\system32\DRIVERS\tcpip.sys 17:32:50.0730 3508 TCPIP6 - ok 17:32:50.0810 3508 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys 17:32:50.0810 3508 tcpipreg - ok 17:32:50.0910 3508 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys 17:32:50.0910 3508 TDPIPE - ok 17:32:50.0980 3508 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys 17:32:50.0980 3508 TDTCP - ok 17:32:51.0050 3508 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys 17:32:51.0050 3508 tdx - ok 17:32:51.0150 3508 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys 17:32:51.0150 3508 TermDD - ok 17:32:51.0240 3508 TermService (a01e50a04d7b1960b33e92b9080e6a94) C:\Windows\System32\termsrv.dll 17:32:51.0240 3508 TermService - ok 17:32:51.0340 3508 Themes (42fb6afd6b79d9fe07381609172e7ca4) C:\Windows\system32\themeservice.dll 17:32:51.0340 3508 Themes - ok 17:32:51.0410 3508 THREADORDER (146b6f43a673379a3c670e86d89be5ea) C:\Windows\system32\mmcss.dll 17:32:51.0410 3508 THREADORDER - ok 17:32:51.0500 3508 TrkWks (4792c0378db99a9bc2ae2de6cfff0c3a) C:\Windows\System32\trkwks.dll 17:32:51.0510 3508 TrkWks - ok 17:32:51.0580 3508 TrojanKillerDriver (113384367c3999e084fe156b18c7625e) C:\Windows\system32\DRIVERS\gtkdrv.sys 17:32:51.0580 3508 TrojanKillerDriver - ok 17:32:51.0640 3508 TrustedInstaller (41a4c781d2286208d397d72099304133) C:\Windows\servicing\TrustedInstaller.exe 17:32:51.0640 3508 TrustedInstaller - ok 17:32:51.0730 3508 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys 17:32:51.0730 3508 tssecsrv - ok 17:32:51.0800 3508 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys 17:32:51.0810 3508 tunnel - ok 17:32:51.0900 3508 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys 17:32:51.0900 3508 uagp35 - ok 17:32:51.0980 3508 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys 17:32:51.0980 3508 udfs - ok 17:32:52.0050 3508 UI0Detect (8344fd4fce927880aa1aa7681d4927e5) C:\Windows\system32\UI0Detect.exe 17:32:52.0050 3508 UI0Detect - ok 17:32:52.0140 3508 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys 17:32:52.0140 3508 uliagpkx - ok 17:32:52.0210 3508 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys 17:32:52.0210 3508 umbus - ok 17:32:52.0280 3508 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys 17:32:52.0280 3508 UmPass - ok 17:32:52.0380 3508 UmRdpService (8ecaca5454844f66386f7be4ae0d7cd1) C:\Windows\System32\umrdp.dll 17:32:52.0380 3508 UmRdpService - ok 17:32:52.0480 3508 upnphost (833fbb672460efce8011d262175fad33) C:\Windows\System32\upnphost.dll 17:32:52.0480 3508 upnphost - ok 17:32:52.0590 3508 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\Windows\system32\Drivers\usbaapl.sys 17:32:52.0590 3508 USBAAPL - ok 17:32:52.0660 3508 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys 17:32:52.0660 3508 usbaudio - ok 17:32:52.0750 3508 usbccgp (8455c4ed038efd09e99327f9d2d48ffa) C:\Windows\system32\DRIVERS\usbccgp.sys 17:32:52.0750 3508 usbccgp - ok 17:32:52.0830 3508 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys 17:32:52.0830 3508 usbcir - ok 17:32:52.0890 3508 usbehci (1c333bfd60f2fed2c7ad5daf533cb742) C:\Windows\system32\DRIVERS\usbehci.sys 17:32:52.0890 3508 usbehci - ok 17:32:52.0990 3508 usbhub (ee6ef93ccfa94fae8c6ab298273d8ae2) C:\Windows\system32\DRIVERS\usbhub.sys 17:32:52.0990 3508 usbhub - ok 17:32:53.0050 3508 usbohci (a6fb7957ea7afb1165991e54ce934b74) C:\Windows\system32\DRIVERS\usbohci.sys 17:32:53.0060 3508 usbohci - ok 17:32:53.0110 3508 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys 17:32:53.0120 3508 usbprint - ok 17:32:53.0200 3508 USBSTOR (d8889d56e0d27e57ed4591837fe71d27) C:\Windows\system32\DRIVERS\USBSTOR.SYS 17:32:53.0200 3508 USBSTOR - ok 17:32:53.0270 3508 usbuhci (78780c3ebce17405b1ccd07a3a8a7d72) C:\Windows\system32\DRIVERS\usbuhci.sys 17:32:53.0270 3508 usbuhci - ok 17:32:53.0360 3508 UxSms (081e6e1c91aec36758902a9f727cd23c) C:\Windows\System32\uxsms.dll 17:32:53.0360 3508 UxSms - ok 17:32:53.0430 3508 VaultSvc (f42309c4191c506b71db5d1126d26318) C:\Windows\system32\lsass.exe 17:32:53.0440 3508 VaultSvc - ok 17:32:53.0510 3508 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys 17:32:53.0510 3508 vdrvroot - ok 17:32:53.0630 3508 vds (8c4e7c49d3641bc9e299e466a7f8867d) C:\Windows\System32\vds.exe 17:32:53.0630 3508 vds - ok 17:32:53.0710 3508 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys 17:32:53.0710 3508 vga - ok 17:32:53.0810 3508 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys 17:32:53.0810 3508 VgaSave - ok 17:32:53.0890 3508 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys 17:32:53.0890 3508 vhdmp - ok 17:32:53.0990 3508 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys 17:32:53.0990 3508 viaagp - ok 17:32:54.0050 3508 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys 17:32:54.0060 3508 ViaC7 - ok 17:32:54.0120 3508 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys 17:32:54.0120 3508 viaide - ok 17:32:54.0240 3508 vmbus (379b349f65f453d2a6e75ea6b7448e49) C:\Windows\system32\DRIVERS\vmbus.sys 17:32:54.0240 3508 vmbus - ok 17:32:54.0330 3508 VMBusHID (ec2bbab4b84d0738c6c83d2234dc36fe) C:\Windows\system32\DRIVERS\VMBusHID.sys 17:32:54.0330 3508 VMBusHID - ok 17:32:54.0420 3508 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys 17:32:54.0420 3508 volmgr - ok 17:32:54.0490 3508 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys 17:32:54.0490 3508 volmgrx - ok 17:32:54.0600 3508 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys 17:32:54.0610 3508 volsnap - ok 17:32:54.0690 3508 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys 17:32:54.0690 3508 vsmraid - ok 17:32:54.0820 3508 VSS (7ea2bcd94d9cfaf4c556f5cc94532a6c) C:\Windows\system32\vssvc.exe 17:32:54.0820 3508 VSS - ok 17:32:54.0910 3508 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys 17:32:54.0910 3508 vwifibus - ok 17:32:55.0000 3508 W32Time (55187fd710e27d5095d10a472c8baf1c) C:\Windows\system32\w32time.dll 17:32:55.0010 3508 W32Time - ok 17:32:55.0080 3508 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys 17:32:55.0080 3508 WacomPen - ok 17:32:55.0160 3508 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:32:55.0160 3508 WANARP - ok 17:32:55.0180 3508 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys 17:32:55.0180 3508 Wanarpv6 - ok 17:32:55.0290 3508 wbengine (7790b77fe1e5ee47dcc66247095bb4c9) C:\Windows\system32\wbengine.exe 17:32:55.0300 3508 wbengine - ok 17:32:55.0390 3508 WbioSrvc (9614b5d29dc76ac3c29f6d2d3aa70e67) C:\Windows\System32\wbiosrvc.dll 17:32:55.0400 3508 WbioSrvc - ok 17:32:55.0490 3508 wcncsvc (d0f88aa11ee1a62bcc6d6a8a7783ca11) C:\Windows\System32\wcncsvc.dll 17:32:55.0490 3508 wcncsvc - ok 17:32:55.0570 3508 WcsPlugInService (5d930b6357a6d2af4d7653bdabbf352f) C:\Windows\System32\WcsPlugInService.dll 17:32:55.0570 3508 WcsPlugInService - ok 17:32:55.0670 3508 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys 17:32:55.0670 3508 Wd - ok 17:32:55.0770 3508 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys 17:32:55.0770 3508 Wdf01000 - ok 17:32:55.0860 3508 WdiServiceHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:32:55.0860 3508 WdiServiceHost - ok 17:32:55.0870 3508 WdiSystemHost (46ef9dc96265fd0b423db72e7c38c2a5) C:\Windows\system32\wdi.dll 17:32:55.0870 3508 WdiSystemHost - ok 17:32:55.0960 3508 WebClient (d87c7d2c517f82a5ab7a73e203063d9e) C:\Windows\System32\webclnt.dll 17:32:55.0970 3508 WebClient - ok 17:32:56.0060 3508 Wecsvc (760f0afe937a77cff27153206534f275) C:\Windows\system32\wecsvc.dll 17:32:56.0060 3508 Wecsvc - ok 17:32:56.0140 3508 wercplsupport (ac804569bb2364fb6017370258a4091b) C:\Windows\System32\wercplsupport.dll 17:32:56.0140 3508 wercplsupport - ok 17:32:56.0240 3508 WerSvc (08e420d873e4fd85241ee2421b02c4a4) C:\Windows\System32\WerSvc.dll 17:32:56.0240 3508 WerSvc - ok 17:32:56.0340 3508 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys 17:32:56.0340 3508 WfpLwf - ok 17:32:56.0440 3508 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys 17:32:56.0440 3508 WIMMount - ok 17:32:56.0510 3508 WinDefend (3fae8f94296001c32eab62cd7d82e0fd) C:\Program Files\Windows Defender\mpsvc.dll 17:32:56.0510 3508 WinDefend - ok 17:32:56.0520 3508 WinHttpAutoProxySvc - ok 17:32:56.0640 3508 Winmgmt (f62e510b6ad4c21eb9fe8668ed251826) C:\Windows\system32\wbem\WMIsvc.dll 17:32:56.0640 3508 Winmgmt - ok 17:32:56.0740 3508 WinRM (c4f5d3901d1b41d602ddc196e0b95b51) C:\Windows\system32\WsmSvc.dll 17:32:56.0750 3508 WinRM - ok 17:32:56.0860 3508 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys 17:32:56.0860 3508 WinUsb - ok 17:32:56.0950 3508 Wlansvc (16935c98ff639d185086a3529b1f2067) C:\Windows\System32\wlansvc.dll 17:32:56.0960 3508 Wlansvc - ok 17:32:57.0060 3508 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys 17:32:57.0060 3508 WmiAcpi - ok 17:32:57.0150 3508 wmiApSrv (6eb6b66517b048d87dc1856ddf1f4c3f) C:\Windows\system32\wbem\WmiApSrv.exe 17:32:57.0160 3508 wmiApSrv - ok 17:32:57.0270 3508 WMPNetworkSvc (77fbd400984cf72ba0fc4b3489d65f74) C:\Program Files\Windows Media Player\wmpnetwk.exe 17:32:57.0270 3508 WMPNetworkSvc - ok 17:32:57.0340 3508 WPCSvc (a2f0ec770a92f2b3f9de6d518e11409c) C:\Windows\System32\wpcsvc.dll 17:32:57.0340 3508 WPCSvc - ok 17:32:57.0410 3508 WPDBusEnum (b7f658a2ebc07129538ad9ab35212637) C:\Windows\system32\wpdbusenum.dll 17:32:57.0410 3508 WPDBusEnum - ok 17:32:57.0520 3508 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys 17:32:57.0520 3508 ws2ifsl - ok 17:32:57.0580 3508 wscsvc (6f5d49efe0e7164e03ae773a3fe25340) C:\Windows\system32\wscsvc.dll 17:32:57.0590 3508 wscsvc - ok 17:32:57.0670 3508 WSearch - ok 17:32:57.0760 3508 wuauserv (a33408cc036f9c08142b11be5e93f0a1) C:\Windows\system32\wuaueng.dll 17:32:57.0770 3508 wuauserv - ok 17:32:57.0860 3508 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys 17:32:57.0860 3508 WudfPf - ok 17:32:57.0940 3508 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys 17:32:57.0950 3508 WUDFRd - ok 17:32:58.0020 3508 wudfsvc (ddee3682fe97037c45f4d7ab467cb8b6) C:\Windows\System32\WUDFSvc.dll 17:32:58.0020 3508 wudfsvc - ok 17:32:58.0110 3508 WwanSvc (ff2d745b560f7c71b31f30f4d49f73d2) C:\Windows\System32\wwansvc.dll 17:32:58.0110 3508 WwanSvc - ok 17:32:58.0200 3508 xusb21 (276842a27953be204a2507096f09b1f3) C:\Windows\system32\DRIVERS\xusb21.sys 17:32:58.0200 3508 xusb21 - ok 17:32:58.0230 3508 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0 17:32:58.0300 3508 \Device\Harddisk0\DR0 - ok 17:32:58.0300 3508 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR2 17:32:58.0300 3508 \Device\Harddisk1\DR2 - ok 17:32:58.0310 3508 Boot (0x1200) (048ccef17a24bc6e1780c46daeaabc5d) \Device\Harddisk0\DR0\Partition0 17:32:58.0310 3508 \Device\Harddisk0\DR0\Partition0 - ok 17:32:58.0330 3508 Boot (0x1200) (32258db9384e7d6cf46b868000cdf49c) \Device\Harddisk0\DR0\Partition1 17:32:58.0340 3508 \Device\Harddisk0\DR0\Partition1 - ok 17:32:58.0350 3508 Boot (0x1200) (3114ea0154e1f216b6ae1285126f4b9c) \Device\Harddisk0\DR0\Partition2 17:32:58.0350 3508 \Device\Harddisk0\DR0\Partition2 - ok 17:32:58.0370 3508 Boot (0x1200) (54a75db28dd230bec091030e7733f328) \Device\Harddisk0\DR0\Partition3 17:32:58.0370 3508 \Device\Harddisk0\DR0\Partition3 - ok 17:32:58.0380 3508 Boot (0x1200) (3be671370f2dd66c14558e1fbec7d814) \Device\Harddisk0\DR0\Partition4 17:32:58.0380 3508 \Device\Harddisk0\DR0\Partition4 - ok 17:32:58.0390 3508 Boot (0x1200) (876a2269e120b88f772795035a5ad836) \Device\Harddisk1\DR2\Partition0 17:32:58.0390 3508 \Device\Harddisk1\DR2\Partition0 - ok 17:32:58.0390 3508 ============================================================ 17:32:58.0390 3508 Scan finished 17:32:58.0390 3508 ============================================================ 17:32:58.0400 2968 Detected object count: 2 17:32:58.0400 2968 Actual detected object count: 2 17:33:41.0950 2968 C:\Windows\system32\drivers\csc.sys - copied to quarantine 17:33:41.0960 2968 C:\Windows\$NtUninstallKB57915$\2817374761\@ - copied to quarantine 17:33:41.0980 2968 C:\Windows\$NtUninstallKB57915$\2817374761\L\xadqgnnk - copied to quarantine 17:33:41.0990 2968 C:\Windows\$NtUninstallKB57915$\2817374761\loader.tlb - copied to quarantine 17:33:42.0000 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@00000001 - copied to quarantine 17:33:42.0010 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000c0 - copied to quarantine 17:33:42.0010 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000cb - copied to quarantine 17:33:42.0010 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000cf - copied to quarantine 17:33:42.0030 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@80000000 - copied to quarantine 17:33:42.0040 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000c0 - copied to quarantine 17:33:42.0060 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000cb - copied to quarantine 17:33:42.0080 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000cf - copied to quarantine 17:33:42.0080 2968 C:\Windows\assembly\GAC_MSIL\desktop.ini - copied to quarantine 17:33:42.0090 2968 C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - copied to quarantine 17:33:42.0090 2968 C:\Users\koxu\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - copied to quarantine 17:33:42.0180 2968 Backup copy found, using it.. 17:33:42.0190 2968 C:\Windows\system32\drivers\csc.sys - will be cured on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\1076823715 - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\@ - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\loader.tlb - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@00000001 - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000c0 - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000cb - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@000000cf - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@80000000 - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000c0 - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000cb - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\$NtUninstallKB57915$\2817374761\U\@800000cf - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\assembly\GAC_MSIL\desktop.ini - will be deleted on reboot 17:33:50.0540 2968 C:\Windows\temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - will be deleted on reboot 17:33:50.0540 2968 C:\Users\koxu\AppData\Local\Temp\{E9C1E1AC-C9B2-4c85-94DE-9C1518918D02}.tlb - will be deleted on reboot 17:33:50.0540 2968 CSC ( Virus.Win32.ZAccess.aml ) - User select action: Cure 17:33:50.0610 2968 C:\Windows\system32\msgsrvservice.dll - copied to quarantine 17:33:50.0630 2968 HKLM\SYSTEM\ControlSet001\services\se44mdm - will be deleted on reboot 17:33:50.0690 2968 HKLM\SYSTEM\ControlSet002\services\se44mdm - will be deleted on reboot 17:33:50.0780 2968 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\svchost:netsvcs - cured 17:33:50.0800 2968 C:\Windows\system32\msgsrvservice.dll - will be deleted on reboot 17:33:50.0800 2968 se44mdm ( Backdoor.Multi.ZAccess.gen ) - User select action: Delete 17:33:56.0530 0668 Deinitialize success