09:10:12.0768 1336 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 09:10:13.0689 1336 ============================================================ 09:10:13.0689 1336 Current date / time: 2012/09/01 09:10:13.0689 09:10:13.0689 1336 SystemInfo: 09:10:13.0689 1336 09:10:13.0689 1336 OS Version: 5.1.2600 ServicePack: 3.0 09:10:13.0689 1336 Product type: Workstation 09:10:13.0689 1336 ComputerName: WINDOWZ 09:10:13.0689 1336 UserName: DOM 09:10:13.0689 1336 Windows directory: C:\WINDOWS 09:10:13.0689 1336 System windows directory: C:\WINDOWS 09:10:13.0689 1336 Processor architecture: Intel x86 09:10:13.0689 1336 Number of processors: 1 09:10:13.0689 1336 Page size: 0x1000 09:10:13.0689 1336 Boot type: Normal boot 09:10:13.0689 1336 ============================================================ 09:10:14.0981 1336 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 09:10:14.0981 1336 ============================================================ 09:10:14.0981 1336 \Device\Harddisk0\DR0: 09:10:14.0981 1336 MBR partitions: 09:10:14.0981 1336 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2800A34 09:10:14.0991 1336 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x2800AB2, BlocksNum 0x22C28D4E 09:10:14.0991 1336 ============================================================ 09:10:15.0011 1336 C: <-> \Device\Harddisk0\DR0\Partition1 09:10:15.0051 1336 D: <-> \Device\Harddisk0\DR0\Partition2 09:10:15.0051 1336 ============================================================ 09:10:15.0051 1336 Initialize success 09:10:15.0051 1336 ============================================================ 09:10:27.0088 1796 ============================================================ 09:10:27.0088 1796 Scan started 09:10:27.0088 1796 Mode: Manual; 09:10:27.0088 1796 ============================================================ 09:10:27.0599 1796 ================ Scan system memory ======================== 09:10:27.0619 1796 System memory - ok 09:10:27.0629 1796 ================ Scan services ============================= 09:10:27.0809 1796 Abiosdsk - ok 09:10:27.0839 1796 abp480n5 - ok 09:10:27.0900 1796 [ 05118282F5D039595A2B92B4A4AFE197 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 09:10:27.0900 1796 ACPI - ok 09:10:27.0950 1796 [ 66A42B7DB194E24B973BBCCE840A0F3F ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 09:10:27.0950 1796 ACPIEC - ok 09:10:27.0980 1796 adpu160m - ok 09:10:28.0020 1796 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 09:10:28.0020 1796 aec - ok 09:10:28.0070 1796 [ 91F3DF93F40A74D222CD166FE95DB633 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys 09:10:28.0070 1796 AegisP - ok 09:10:28.0100 1796 [ 4D43E74F2A1239D53929B82600F1971C ] AFD C:\WINDOWS\System32\drivers\afd.sys 09:10:28.0110 1796 AFD - ok 09:10:28.0150 1796 Aha154x - ok 09:10:28.0170 1796 aic78u2 - ok 09:10:28.0190 1796 aic78xx - ok 09:10:28.0260 1796 [ 7BFE59F5EFF8896D043CFDE731B262E9 ] ALCXWDM C:\WINDOWS\system32\drivers\ALCXWDM.SYS 09:10:28.0270 1796 ALCXWDM - ok 09:10:28.0290 1796 [ D1738DDDFF196C5CEE6D867C136AF745 ] ALG C:\WINDOWS\System32\alg.exe 09:10:28.0290 1796 ALG - ok 09:10:28.0310 1796 AliIde - ok 09:10:28.0340 1796 amsint - ok 09:10:28.0380 1796 [ 1561430DA2F2AB81CC0CE71AF95A778D ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 09:10:28.0390 1796 AppMgmt - ok 09:10:28.0440 1796 asc - ok 09:10:28.0460 1796 asc3350p - ok 09:10:28.0480 1796 asc3550 - ok 09:10:28.0581 1796 [ D33C507942299753868204CC7642FA27 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 09:10:28.0591 1796 aspnet_state - ok 09:10:28.0611 1796 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 09:10:28.0611 1796 AsyncMac - ok 09:10:28.0661 1796 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 09:10:28.0671 1796 atapi - ok 09:10:28.0681 1796 Atdisk - ok 09:10:28.0731 1796 [ 471087B5E1E01CC82604E81EA14781D8 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe 09:10:28.0761 1796 Ati HotKey Poller - ok 09:10:28.0811 1796 [ B979BA0120B6DB757196A8E2E873FE3C ] ATI Smart C:\WINDOWS\system32\ati2sgag.exe 09:10:28.0841 1796 ATI Smart - ok 09:10:29.0001 1796 [ C0B86ECB324E50F6BBD529F9D5C6B24B ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 09:10:29.0051 1796 ati2mtag - ok 09:10:29.0111 1796 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 09:10:29.0121 1796 Atmarpc - ok 09:10:29.0151 1796 [ 3A28D3E7BAD0EED3810CD918B2525B54 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 09:10:29.0151 1796 AudioSrv - ok 09:10:29.0191 1796 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 09:10:29.0191 1796 audstub - ok 09:10:29.0251 1796 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 09:10:29.0251 1796 Beep - ok 09:10:29.0302 1796 [ 78200FAA6FD9C69394134C238C87FB7F ] BITS C:\WINDOWS\system32\qmgr.dll 09:10:29.0312 1796 BITS - ok 09:10:29.0352 1796 [ B98ED6D85339A66A73F32FB569EB6C01 ] Browser C:\WINDOWS\System32\browser.dll 09:10:29.0352 1796 Browser - ok 09:10:29.0402 1796 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 09:10:29.0402 1796 cbidf2k - ok 09:10:29.0432 1796 cd20xrnt - ok 09:10:29.0462 1796 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 09:10:29.0462 1796 Cdaudio - ok 09:10:29.0492 1796 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 09:10:29.0502 1796 Cdfs - ok 09:10:29.0532 1796 [ 4B0A100EAF5C49EF3CCA8C641431EACC ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 09:10:29.0532 1796 Cdrom - ok 09:10:29.0552 1796 Changer - ok 09:10:29.0582 1796 [ C94F1B6F61858D6389C0FA06954FB9C4 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 09:10:29.0582 1796 ClipSrv - ok 09:10:29.0632 1796 [ 3C4D595E7F9B747325AEF28B4ADCAAE5 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 09:10:29.0632 1796 clr_optimization_v2.0.50727_32 - ok 09:10:29.0662 1796 CmdIde - ok 09:10:29.0682 1796 COMSysApp - ok 09:10:29.0712 1796 Cpqarray - ok 09:10:29.0762 1796 [ 6B105FE95F2E9F0B6346044BA59D41C9 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 09:10:29.0772 1796 CryptSvc - ok 09:10:29.0802 1796 dac2w2k - ok 09:10:29.0832 1796 dac960nt - ok 09:10:29.0872 1796 [ C9E5AC78D9A00B1DE8CE2AD1BDDE7E42 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 09:10:29.0892 1796 DcomLaunch - ok 09:10:29.0932 1796 [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 09:10:29.0942 1796 Dhcp - ok 09:10:29.0983 1796 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 09:10:29.0993 1796 Disk - ok 09:10:30.0013 1796 dmadmin - ok 09:10:30.0083 1796 [ BC9219ABC5696942E6F9AC8A9B28670F ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 09:10:30.0103 1796 dmboot - ok 09:10:30.0143 1796 [ 5FA232E3BA6E1346F9F5A7E519320CB0 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 09:10:30.0153 1796 dmio - ok 09:10:30.0203 1796 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 09:10:30.0203 1796 dmload - ok 09:10:30.0243 1796 [ D858920A05076914D34B0388E8D96CC0 ] dmserver C:\WINDOWS\System32\dmserver.dll 09:10:30.0243 1796 dmserver - ok 09:10:30.0293 1796 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 09:10:30.0293 1796 DMusic - ok 09:10:30.0333 1796 [ 4F7E82841ED3CF026BD8D5CE7C7379DB ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 09:10:30.0333 1796 Dnscache - ok 09:10:30.0373 1796 [ E0B7D66CF29D9ADCCF873C77821CD4CA ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 09:10:30.0373 1796 Dot3svc - ok 09:10:30.0403 1796 dpti2o - ok 09:10:30.0433 1796 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 09:10:30.0433 1796 drmkaud - ok 09:10:30.0463 1796 [ 5F256C1AD50FEFDC442CD5AAB58C7DD8 ] EapHost C:\WINDOWS\System32\eapsvc.dll 09:10:30.0463 1796 EapHost - ok 09:10:30.0543 1796 [ 8816E60BF654353E8E0D35ED98875445 ] Eventlog C:\WINDOWS\system32\services.exe 09:10:30.0553 1796 Eventlog - ok 09:10:30.0593 1796 [ 5BB3E442E43C7BB0F38203F23C920D3C ] EventSystem C:\WINDOWS\system32\es.dll 09:10:30.0613 1796 EventSystem - ok 09:10:30.0663 1796 [ 4D893323DAE445E34A4C9038B0551BC9 ] exFat C:\WINDOWS\system32\drivers\exFat.sys 09:10:30.0663 1796 exFat - ok 09:10:30.0704 1796 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 09:10:30.0714 1796 Fastfat - ok 09:10:30.0744 1796 [ 8AD90ED829B8404D962545ED3EFB1129 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 09:10:30.0764 1796 FastUserSwitchingCompatibility - ok 09:10:30.0794 1796 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys 09:10:30.0794 1796 Fdc - ok 09:10:30.0824 1796 [ A1B6365EFD6DB9AC8A735EA0203E02A1 ] FETNDIS C:\WINDOWS\system32\DRIVERS\fetnd5a.sys 09:10:30.0824 1796 FETNDIS - ok 09:10:30.0864 1796 [ 09E2A4D33F81A06A8AAB2BA0A0B5D235 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 09:10:30.0864 1796 Fips - ok 09:10:30.0954 1796 [ 6EA7BC2CD83A6C170422F8F0D67500DA ] FlashFolder C:\Program Files\FlashFolder\FlashFolder.exe 09:10:30.0954 1796 FlashFolder - ok 09:10:30.0984 1796 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 09:10:30.0984 1796 Flpydisk - ok 09:10:31.0034 1796 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 09:10:31.0044 1796 FltMgr - ok 09:10:31.0074 1796 [ 7C2B319EF1F62837AAD0CDD76F0B84C6 ] FolderSize C:\Program Files\FolderSize\FolderSizeSvc.exe 09:10:31.0084 1796 FolderSize - ok 09:10:31.0124 1796 [ 30D42943A54704EF13E2562911DBFCEA ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 09:10:31.0124 1796 Fs_Rec - ok 09:10:31.0154 1796 [ ED6D921D8AB423138FB35BEEE6D6A6CB ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 09:10:31.0164 1796 Ftdisk - ok 09:10:31.0204 1796 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum C:\WINDOWS\system32\DRIVERS\gameenum.sys 09:10:31.0204 1796 gameenum - ok 09:10:31.0224 1796 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 09:10:31.0224 1796 Gpc - ok 09:10:31.0274 1796 [ 40B74831AE2270256168EE282E10310D ] HidServ C:\WINDOWS\System32\hidserv.dll 09:10:31.0274 1796 HidServ - ok 09:10:31.0334 1796 [ F0273916DA6FB64CC88E0BD77619554F ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 09:10:31.0334 1796 hkmsvc - ok 09:10:31.0365 1796 hpn - ok 09:10:31.0415 1796 [ F6AACF5BCE2893E0C1754AFEB672E5C9 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 09:10:31.0415 1796 HTTP - ok 09:10:31.0465 1796 [ AA268079AC119F3A596E5E27AEE4BD17 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 09:10:31.0465 1796 HTTPFilter - ok 09:10:31.0495 1796 i2omgmt - ok 09:10:31.0515 1796 i2omp - ok 09:10:31.0565 1796 [ 177B372AF55C4460D0968B5F1D02AA1C ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 09:10:31.0565 1796 i8042prt - ok 09:10:31.0615 1796 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 09:10:31.0615 1796 Imapi - ok 09:10:31.0645 1796 ini910u - ok 09:10:31.0685 1796 IntelIde - ok 09:10:31.0715 1796 [ DA153EDC09DE8C4F846C085CAA39D1CC ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 09:10:31.0725 1796 intelppm - ok 09:10:31.0755 1796 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 09:10:31.0765 1796 Ip6Fw - ok 09:10:31.0795 1796 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 09:10:31.0815 1796 IpFilterDriver - ok 09:10:31.0835 1796 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 09:10:31.0845 1796 IpInIp - ok 09:10:31.0875 1796 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 09:10:31.0885 1796 IpNat - ok 09:10:31.0925 1796 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 09:10:31.0925 1796 IPSec - ok 09:10:31.0965 1796 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 09:10:31.0965 1796 IRENUM - ok 09:10:32.0015 1796 [ C8EEF2E93835B81BD335DE2123121283 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 09:10:32.0015 1796 isapnp - ok 09:10:32.0096 1796 [ 2AECA45D4AEAACBDCB77AD11184E4601 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 09:10:32.0096 1796 Kbdclass - ok 09:10:32.0136 1796 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 09:10:32.0146 1796 kmixer - ok 09:10:32.0176 1796 [ C6EBF1D6AD71DF30DB49B8D3287E1368 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 09:10:32.0176 1796 KSecDD - ok 09:10:32.0206 1796 [ 427F50A24AA35597A9A5E8FBF029590F ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 09:10:32.0216 1796 LanmanServer - ok 09:10:32.0246 1796 [ 31D2FE1091E94354336B4E85DB818745 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 09:10:32.0276 1796 lanmanworkstation - ok 09:10:32.0296 1796 lbrtfdc - ok 09:10:32.0366 1796 [ 437AA83D68F9FAC234CA68DBD40DB705 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 09:10:32.0366 1796 LmHosts - ok 09:10:32.0436 1796 [ 4A068DB7DC37D5AFEDB6512D2931D7B3 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 09:10:32.0436 1796 Modem - ok 09:10:32.0466 1796 [ FBED3DF6B884F8CF00447B73507F2C48 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 09:10:32.0466 1796 Mouclass - ok 09:10:32.0496 1796 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 09:10:32.0506 1796 MountMgr - ok 09:10:32.0516 1796 mraid35x - ok 09:10:32.0556 1796 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 09:10:32.0566 1796 MRxDAV - ok 09:10:32.0616 1796 [ 7170AB42B51954DEF2781A4D1CCE65F4 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 09:10:32.0626 1796 MRxSmb - ok 09:10:32.0676 1796 [ A54C5EECC7D3424824410BAE0AA6C371 ] MSDTC C:\WINDOWS\system32\msdtc.exe 09:10:32.0676 1796 MSDTC - ok 09:10:32.0716 1796 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 09:10:32.0716 1796 Msfs - ok 09:10:32.0746 1796 MSIServer - ok 09:10:32.0777 1796 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 09:10:32.0777 1796 MSKSSRV - ok 09:10:32.0827 1796 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 09:10:32.0827 1796 MSPCLOCK - ok 09:10:32.0867 1796 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 09:10:32.0877 1796 MSPQM - ok 09:10:32.0907 1796 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 09:10:32.0907 1796 mssmbios - ok 09:10:32.0957 1796 [ CA3E22598F411199ADC2DFEE76CD0AE0 ] ms_mpu401 C:\WINDOWS\system32\drivers\msmpu401.sys 09:10:32.0957 1796 ms_mpu401 - ok 09:10:32.0997 1796 [ 2F625D11385B1A94360BFC70AAEFDEE1 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 09:10:32.0997 1796 Mup - ok 09:10:33.0077 1796 [ 14CB8528E17D1221C50FC8CA88B1795F ] napagent C:\WINDOWS\System32\qagentrt.dll 09:10:33.0087 1796 napagent - ok 09:10:33.0127 1796 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 09:10:33.0137 1796 NDIS - ok 09:10:33.0157 1796 [ 1AB3D00C991AB086E69DB84B6C0ED78F ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 09:10:33.0157 1796 NdisTapi - ok 09:10:33.0187 1796 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 09:10:33.0187 1796 Ndisuio - ok 09:10:33.0217 1796 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 09:10:33.0217 1796 NdisWan - ok 09:10:33.0237 1796 [ 6215023940CFD3702B46ABC304E1D45A ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 09:10:33.0247 1796 NDProxy - ok 09:10:33.0267 1796 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 09:10:33.0267 1796 NetBIOS - ok 09:10:33.0297 1796 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 09:10:33.0297 1796 NetBT - ok 09:10:33.0337 1796 [ CBB409B314309FCFFCE5E682E91338C6 ] NetDDE C:\WINDOWS\system32\netdde.exe 09:10:33.0337 1796 NetDDE - ok 09:10:33.0357 1796 [ CBB409B314309FCFFCE5E682E91338C6 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 09:10:33.0357 1796 NetDDEdsdm - ok 09:10:33.0397 1796 [ 88296F7943F30A1EE3AF735440B92268 ] Netlogon C:\WINDOWS\system32\lsass.exe 09:10:33.0407 1796 Netlogon - ok 09:10:33.0427 1796 [ 4FE97D0B1B182DF2A9BDD4C02155EF5E ] Netman C:\WINDOWS\System32\netman.dll 09:10:33.0437 1796 Netman - ok 09:10:33.0488 1796 [ BF80D884E1C60DED1C7CEA3EC6F9DC28 ] Nla C:\WINDOWS\System32\mswsock.dll 09:10:33.0518 1796 Nla - ok 09:10:33.0588 1796 [ FD306FBCCE7ADB1077B709742E7148E9 ] NMSAccessU C:\Program Files\CDBurnerXP\NMSAccessU.exe 09:10:33.0588 1796 NMSAccessU - ok 09:10:33.0638 1796 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 09:10:33.0638 1796 Npfs - ok 09:10:33.0678 1796 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 09:10:33.0688 1796 Ntfs - ok 09:10:33.0718 1796 [ 88296F7943F30A1EE3AF735440B92268 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 09:10:33.0718 1796 NtLmSsp - ok 09:10:33.0758 1796 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 09:10:33.0758 1796 Null - ok 09:10:33.0838 1796 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 09:10:33.0838 1796 NwlnkFlt - ok 09:10:33.0858 1796 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 09:10:33.0858 1796 NwlnkFwd - ok 09:10:33.0958 1796 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 09:10:33.0978 1796 odserv - ok 09:10:34.0008 1796 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 09:10:34.0018 1796 ose - ok 09:10:34.0068 1796 [ 2D4CDAEBCED17743AA9E25D3016DC229 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 09:10:34.0068 1796 Parport - ok 09:10:34.0088 1796 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 09:10:34.0088 1796 PartMgr - ok 09:10:34.0128 1796 [ 453EC2C2A20A1382F564541918520EEB ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 09:10:34.0128 1796 ParVdm - ok 09:10:34.0159 1796 [ 6862C69168D787B85A7D95CCD33C694E ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 09:10:34.0159 1796 PCI - ok 09:10:34.0179 1796 PCIDump - ok 09:10:34.0199 1796 PCIIde - ok 09:10:34.0239 1796 [ 8DB27F1AE9593C94095485305A583862 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 09:10:34.0239 1796 Pcmcia - ok 09:10:34.0259 1796 PDCOMP - ok 09:10:34.0279 1796 PDFRAME - ok 09:10:34.0309 1796 PDRELI - ok 09:10:34.0329 1796 PDRFRAME - ok 09:10:34.0359 1796 perc2 - ok 09:10:34.0379 1796 perc2hib - ok 09:10:34.0449 1796 [ 8816E60BF654353E8E0D35ED98875445 ] PlugPlay C:\WINDOWS\system32\services.exe 09:10:34.0459 1796 PlugPlay - ok 09:10:34.0489 1796 [ 88296F7943F30A1EE3AF735440B92268 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 09:10:34.0489 1796 PolicyAgent - ok 09:10:34.0509 1796 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 09:10:34.0509 1796 PptpMiniport - ok 09:10:34.0549 1796 [ 2E11A09F0F5B3755681A4EF18CD89A3D ] prio_svc C:\Program Files\Prio\prio_svc.exe 09:10:34.0549 1796 prio_svc - ok 09:10:34.0579 1796 [ 88296F7943F30A1EE3AF735440B92268 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 09:10:34.0579 1796 ProtectedStorage - ok 09:10:34.0619 1796 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 09:10:34.0619 1796 PSched - ok 09:10:34.0659 1796 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 09:10:34.0659 1796 Ptilink - ok 09:10:34.0689 1796 ql1080 - ok 09:10:34.0709 1796 Ql10wnt - ok 09:10:34.0739 1796 ql12160 - ok 09:10:34.0769 1796 ql1240 - ok 09:10:34.0789 1796 ql1280 - ok 09:10:34.0819 1796 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 09:10:34.0819 1796 RasAcd - ok 09:10:34.0860 1796 [ BC22C5E1238D4D36D65679E249C483C3 ] RasAuto C:\WINDOWS\System32\rasauto.dll 09:10:34.0870 1796 RasAuto - ok 09:10:34.0900 1796 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 09:10:34.0900 1796 Rasl2tp - ok 09:10:34.0930 1796 [ 0C392E397B8D34AAAF19EC6119CBB788 ] RasMan C:\WINDOWS\System32\rasmans.dll 09:10:34.0940 1796 RasMan - ok 09:10:34.0960 1796 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 09:10:34.0960 1796 RasPppoe - ok 09:10:34.0990 1796 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 09:10:34.0990 1796 Raspti - ok 09:10:35.0020 1796 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 09:10:35.0020 1796 Rdbss - ok 09:10:35.0050 1796 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 09:10:35.0050 1796 RDPCDD - ok 09:10:35.0100 1796 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 09:10:35.0110 1796 rdpdr - ok 09:10:35.0160 1796 [ 6728E45B66F93C08F11DE2E316FC70DD ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 09:10:35.0170 1796 RDPWD - ok 09:10:35.0210 1796 [ F83907A9A038DB2E35329B039628D293 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 09:10:35.0210 1796 RDSessMgr - ok 09:10:35.0240 1796 [ E0C7BBD18040B58651BAC700C804861D ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 09:10:35.0240 1796 redbook - ok 09:10:35.0290 1796 [ B3F57E6115BCD4DBADE9874F300655E3 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 09:10:35.0300 1796 RemoteAccess - ok 09:10:35.0330 1796 [ 6BC4D5A70F46EA27DDC14E5414C862A5 ] RpcLocator C:\WINDOWS\system32\locator.exe 09:10:35.0340 1796 RpcLocator - ok 09:10:35.0380 1796 [ C9E5AC78D9A00B1DE8CE2AD1BDDE7E42 ] RpcSs C:\WINDOWS\system32\rpcss.dll 09:10:35.0390 1796 RpcSs - ok 09:10:35.0450 1796 [ 9ACEE3313020A01235336C2A483AFD1A ] RSVP C:\WINDOWS\system32\rsvp.exe 09:10:35.0460 1796 RSVP - ok 09:10:35.0520 1796 [ DA84C3ED2F31B1D5D68F775EBA4ECB59 ] RT61 C:\WINDOWS\system32\DRIVERS\RT61.sys 09:10:35.0520 1796 RT61 - ok 09:10:35.0561 1796 [ 88296F7943F30A1EE3AF735440B92268 ] SamSs C:\WINDOWS\system32\lsass.exe 09:10:35.0561 1796 SamSs - ok 09:10:35.0601 1796 [ C6F479218E94896738C06AF5BA6AB3D3 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 09:10:35.0611 1796 SCardSvr - ok 09:10:35.0651 1796 [ DD73C11A5C4D14945846384B90A61A4B ] Schedule C:\WINDOWS\system32\schedsvc.dll 09:10:35.0661 1796 Schedule - ok 09:10:35.0711 1796 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 09:10:35.0711 1796 Secdrv - ok 09:10:35.0741 1796 [ 2AAD9026648120FFFE2A8D871BB2BBC7 ] seclogon C:\WINDOWS\System32\seclogon.dll 09:10:35.0741 1796 seclogon - ok 09:10:35.0771 1796 [ 9D01E29D59723EB73B72107B208DAFE6 ] SENS C:\WINDOWS\system32\sens.dll 09:10:35.0781 1796 SENS - ok 09:10:35.0801 1796 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 09:10:35.0801 1796 serenum - ok 09:10:35.0811 1796 [ D07B02F88165E69B9F17162CF592C8A6 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 09:10:35.0821 1796 Serial - ok 09:10:35.0861 1796 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 09:10:35.0861 1796 Sfloppy - ok 09:10:35.0891 1796 [ 415E4EBF192A9D68C28DE0541BE48307 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 09:10:35.0901 1796 SharedAccess - ok 09:10:35.0951 1796 [ 8AD90ED829B8404D962545ED3EFB1129 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 09:10:35.0961 1796 ShellHWDetection - ok 09:10:36.0001 1796 [ 2525F35D0A0E94BB0CA7B4B68117B453 ] Si3112 C:\WINDOWS\system32\drivers\Si3112.sys 09:10:36.0001 1796 Si3112 - ok 09:10:36.0061 1796 [ 87D406C592327DED095FF314427A4FA7 ] Si3114r5 C:\WINDOWS\system32\drivers\Si3114r5.sys 09:10:36.0061 1796 Si3114r5 - ok 09:10:36.0091 1796 [ 505C167BE0BC7173C9095CA9B7B346D9 ] Si3124 C:\WINDOWS\system32\drivers\Si3124.sys 09:10:36.0091 1796 Si3124 - ok 09:10:36.0131 1796 [ 0B9B5C6DF6226497EF4819B6E1B2EFD5 ] Si3132 C:\WINDOWS\system32\drivers\Si3132.sys 09:10:36.0131 1796 Si3132 - ok 09:10:36.0171 1796 [ 227E56633D6423E1F7D869618AC8404F ] Si3132r5 C:\WINDOWS\system32\drivers\Si3132r5.sys 09:10:36.0171 1796 Si3132r5 - ok 09:10:36.0191 1796 Simbad - ok 09:10:36.0262 1796 Sparrow - ok 09:10:36.0302 1796 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 09:10:36.0312 1796 splitter - ok 09:10:36.0342 1796 [ DD69EC597AB942C39B950D9C3CE1375D ] Spooler C:\WINDOWS\system32\spoolsv.exe 09:10:36.0342 1796 Spooler - ok 09:10:36.0392 1796 [ EB032822BE406EF220D546DDFFCF0002 ] Sr C:\WINDOWS\system32\DRIVERS\sr.sys 09:10:36.0392 1796 Sr - ok 09:10:36.0422 1796 [ 316D0E66074AE4CDE641C50D3A1C5148 ] srservice C:\WINDOWS\system32\srsvc.dll 09:10:36.0432 1796 srservice - ok 09:10:36.0492 1796 [ E89B42B216BC86ADA4345908284519CB ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 09:10:36.0512 1796 Srv - ok 09:10:36.0542 1796 [ 2C0B1224AA36B4CA1753302BAA855882 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 09:10:36.0552 1796 SSDPSRV - ok 09:10:36.0592 1796 [ F92254B0BCFCD10CAAC7BCCC7CB7F467 ] StarOpen C:\WINDOWS\system32\drivers\StarOpen.sys 09:10:36.0592 1796 StarOpen - ok 09:10:36.0642 1796 [ 41508EA375C97DC2B56E5F1AFC067187 ] stisvc C:\WINDOWS\system32\wiaservc.dll 09:10:36.0662 1796 stisvc - ok 09:10:36.0692 1796 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 09:10:36.0692 1796 swenum - ok 09:10:36.0712 1796 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 09:10:36.0722 1796 swmidi - ok 09:10:36.0752 1796 SwPrv - ok 09:10:36.0772 1796 symc810 - ok 09:10:36.0802 1796 symc8xx - ok 09:10:36.0832 1796 sym_hi - ok 09:10:36.0852 1796 sym_u3 - ok 09:10:36.0892 1796 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 09:10:36.0892 1796 sysaudio - ok 09:10:36.0922 1796 [ E42048198518F9162027A9984CBB7B5C ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 09:10:36.0933 1796 SysmonLog - ok 09:10:36.0983 1796 [ 2340E6977548038C88E39A9ECBB3FADC ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 09:10:37.0003 1796 TapiSrv - ok 09:10:37.0053 1796 [ 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 09:10:37.0053 1796 Tcpip - ok 09:10:37.0083 1796 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 09:10:37.0093 1796 TDPIPE - ok 09:10:37.0133 1796 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 09:10:37.0133 1796 TDTCP - ok 09:10:37.0173 1796 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 09:10:37.0173 1796 TermDD - ok 09:10:37.0213 1796 [ 52E0505408EDD4AB5CCC7F83B67B4299 ] TermService C:\WINDOWS\System32\termsrv.dll 09:10:37.0233 1796 TermService - ok 09:10:37.0263 1796 [ 8AD90ED829B8404D962545ED3EFB1129 ] Themes C:\WINDOWS\System32\shsvcs.dll 09:10:37.0283 1796 Themes - ok 09:10:37.0303 1796 TosIde - ok 09:10:37.0333 1796 [ 9E70EB419D7785C286DC458A019BAB9B ] TrkWks C:\WINDOWS\system32\trkwks.dll 09:10:37.0343 1796 TrkWks - ok 09:10:37.0383 1796 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 09:10:37.0393 1796 Udfs - ok 09:10:37.0423 1796 ultra - ok 09:10:37.0473 1796 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 09:10:37.0493 1796 Update - ok 09:10:37.0533 1796 [ E96A6BAEE0B2A14A38B45830D6E30697 ] upnphost C:\WINDOWS\System32\upnphost.dll 09:10:37.0543 1796 upnphost - ok 09:10:37.0573 1796 [ EB90E28B28541EC845E5345609355CA7 ] UPS C:\WINDOWS\System32\ups.exe 09:10:37.0583 1796 UPS - ok 09:10:37.0624 1796 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 09:10:37.0624 1796 usbccgp - ok 09:10:37.0674 1796 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 09:10:37.0674 1796 usbehci - ok 09:10:37.0714 1796 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 09:10:37.0714 1796 usbhub - ok 09:10:37.0744 1796 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 09:10:37.0754 1796 usbstor - ok 09:10:37.0784 1796 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 09:10:37.0784 1796 usbuhci - ok 09:10:37.0814 1796 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 09:10:37.0814 1796 VgaSave - ok 09:10:37.0854 1796 [ 004D6EE11E1303D0A4C7502402C9F396 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp1.sys 09:10:37.0854 1796 viaagp - ok 09:10:37.0874 1796 [ 004D6EE11E1303D0A4C7502402C9F396 ] viaagp1 C:\WINDOWS\system32\DRIVERS\viaagp1.sys 09:10:37.0874 1796 viaagp1 - ok 09:10:37.0914 1796 [ A5D8B6C8D43786D4215C1DF6FAB0AAE0 ] ViaIde C:\WINDOWS\system32\DRIVERS\viaidexp.sys 09:10:37.0914 1796 ViaIde - ok 09:10:37.0954 1796 [ 662626BCCF060F2F4B6D5AF7AC121FF5 ] VIAPFD C:\WINDOWS\System32\Drivers\VIAPFD.SYS 09:10:37.0954 1796 VIAPFD - ok 09:10:38.0014 1796 [ 56B191AC5FC0DF219949C95A6C87AFE7 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 09:10:38.0014 1796 VolSnap - ok 09:10:38.0054 1796 [ 7F2D7BFFC4554E1C742DD3629FD1FB1B ] VSS C:\WINDOWS\System32\vssvc.exe 09:10:38.0074 1796 VSS - ok 09:10:38.0104 1796 [ A672CA3981352F8E9C30FEA056E80A62 ] W32Time C:\WINDOWS\system32\w32time.dll 09:10:38.0114 1796 W32Time - ok 09:10:38.0154 1796 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 09:10:38.0154 1796 Wanarp - ok 09:10:38.0174 1796 WDICA - ok 09:10:38.0214 1796 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 09:10:38.0214 1796 wdmaud - ok 09:10:38.0244 1796 [ 81FB88B975E25D76E00B69879D8A434C ] WebClient C:\WINDOWS\System32\webclnt.dll 09:10:38.0264 1796 WebClient - ok 09:10:38.0325 1796 [ 70C22297534A88B0AD0568900AB5A6D9 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 09:10:38.0335 1796 winmgmt - ok 09:10:38.0395 1796 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 09:10:38.0395 1796 WmdmPmSN - ok 09:10:38.0455 1796 [ E0DC77033075F52BC9AEE300DFD854F8 ] Wmi C:\WINDOWS\System32\advapi32.dll 09:10:38.0475 1796 Wmi - ok 09:10:38.0525 1796 [ A2B12D80A1670511B047A7D8BB647598 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 09:10:38.0535 1796 WmiApSrv - ok 09:10:38.0605 1796 [ CDFA647AA82FDBA6C9C7A06155AFCB40 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe 09:10:38.0645 1796 WMPNetworkSvc - ok 09:10:38.0695 1796 [ B6669F49D42E09BC0F9889FAA0F3336D ] wscsvc C:\WINDOWS\system32\wscsvc.dll 09:10:38.0705 1796 wscsvc - ok 09:10:38.0745 1796 [ AAE1A6FFBA2B0436E91795120F48C461 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 09:10:38.0755 1796 wuauserv - ok 09:10:38.0785 1796 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys 09:10:38.0785 1796 WudfPf - ok 09:10:38.0825 1796 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys 09:10:38.0825 1796 WudfRd - ok 09:10:38.0855 1796 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll 09:10:38.0865 1796 WudfSvc - ok 09:10:38.0915 1796 [ C2842273AAA77AC031EDB87FA19A2147 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 09:10:38.0945 1796 WZCSVC - ok 09:10:38.0975 1796 [ 24ED6935771359A5AEF1FE8BF0C56F39 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 09:10:38.0985 1796 xmlprov - ok 09:10:39.0005 1796 ================ Scan global =============================== 09:10:39.0036 1796 [ 65C782F8CFC1BEBCC58E1532F44B6408 ] C:\WINDOWS\system32\basesrv.dll 09:10:39.0076 1796 [ 63E4D0B6A52AAC2919CF3BDB8DE254F5 ] C:\WINDOWS\system32\winsrv.dll 09:10:39.0106 1796 [ 63E4D0B6A52AAC2919CF3BDB8DE254F5 ] C:\WINDOWS\system32\winsrv.dll 09:10:39.0136 1796 [ 8816E60BF654353E8E0D35ED98875445 ] C:\WINDOWS\system32\services.exe 09:10:39.0136 1796 [Global] - ok 09:10:39.0146 1796 ================ Scan MBR ================================== 09:10:39.0156 1796 [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 09:10:39.0196 1796 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - infected 09:10:39.0196 1796 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Sinowal.b (0) 09:10:39.0206 1796 ================ Scan VBR ================================== 09:10:39.0216 1796 [ 00D2DB8F87077A0403FE69EB43CCBF5C ] \Device\Harddisk0\DR0\Partition1 09:10:39.0216 1796 \Device\Harddisk0\DR0\Partition1 - ok 09:10:39.0266 1796 [ C0FD0B23EB7166ED236E4534B981C991 ] \Device\Harddisk0\DR0\Partition2 09:10:39.0266 1796 \Device\Harddisk0\DR0\Partition2 - ok 09:10:39.0276 1796 ============================================================ 09:10:39.0276 1796 Scan finished 09:10:39.0276 1796 ============================================================ 09:10:39.0316 1700 Detected object count: 1 09:10:39.0316 1700 Actual detected object count: 1 09:15:45.0486 1700 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - skipped by user 09:15:45.0486 1700 \Device\Harddisk0\DR0 ( Rootkit.Boot.Sinowal.b ) - User select action: Skip