08:48:04.0234 2368 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48 08:48:04.0406 2368 ============================================================ 08:48:04.0406 2368 Current date / time: 2012/09/10 08:48:04.0406 08:48:04.0406 2368 SystemInfo: 08:48:04.0406 2368 08:48:04.0406 2368 OS Version: 5.1.2600 ServicePack: 2.0 08:48:04.0406 2368 Product type: Workstation 08:48:04.0406 2368 ComputerName: 1F9467CDC3D54E0 08:48:04.0406 2368 UserName: User 08:48:04.0406 2368 Windows directory: C:\WINDOWS 08:48:04.0406 2368 System windows directory: C:\WINDOWS 08:48:04.0406 2368 Processor architecture: Intel x86 08:48:04.0406 2368 Number of processors: 2 08:48:04.0406 2368 Page size: 0x1000 08:48:04.0406 2368 Boot type: Normal boot 08:48:04.0406 2368 ============================================================ 08:48:06.0953 2368 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0xF245, SectorsPerTrack: 0x3F, TracksPerCylinder: 0x3C, Type 'K0', Flags 0x00000054 08:48:06.0984 2368 ============================================================ 08:48:06.0984 2368 \Device\Harddisk0\DR0: 08:48:07.0000 2368 MBR partitions: 08:48:07.0000 2368 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xFA0800, BlocksNum 0x6FCA000 08:48:07.0015 2368 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x7F6B000, BlocksNum 0x6029800 08:48:07.0015 2368 ============================================================ 08:48:07.0046 2368 C: <-> \Device\Harddisk0\DR0\Partition1 08:48:07.0093 2368 D: <-> \Device\Harddisk0\DR0\Partition2 08:48:07.0093 2368 ============================================================ 08:48:07.0093 2368 Initialize success 08:48:07.0093 2368 ============================================================ 08:49:05.0359 2128 ============================================================ 08:49:05.0359 2128 Scan started 08:49:05.0359 2128 Mode: Manual; 08:49:05.0359 2128 ============================================================ 08:49:06.0437 2128 ================ Scan system memory ======================== 08:49:06.0453 2128 System memory - ok 08:49:06.0453 2128 ================ Scan services ============================= 08:49:06.0750 2128 [ 473F97EDC5A5312F3665AB2921196C0C ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys 08:49:06.0765 2128 Aavmker4 - ok 08:49:06.0765 2128 Abiosdsk - ok 08:49:06.0781 2128 abp480n5 - ok 08:49:06.0890 2128 [ 56922F51DDE99B23A9C61FD5AC25FD7F ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 08:49:06.0953 2128 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ACPI.sys. Real md5: 56922F51DDE99B23A9C61FD5AC25FD7F, Fake md5: A966410ECF83B81F3B0B8E07A71957D4 08:49:06.0953 2128 ACPI ( Virus.Win32.Rloader.a ) - infected 08:49:06.0953 2128 ACPI - detected Virus.Win32.Rloader.a (0) 08:49:07.0000 2128 [ 66A42B7DB194E24B973BBCCE840A0F3F ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 08:49:07.0000 2128 ACPIEC - ok 08:49:07.0140 2128 [ B2B64AF436FACCFA854DD397027C5360 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe 08:49:07.0156 2128 AdobeFlashPlayerUpdateSvc - ok 08:49:07.0156 2128 adpu160m - ok 08:49:07.0250 2128 [ 841F385C6CFAF66B58FBD898722BB4F0 ] aec C:\WINDOWS\system32\drivers\aec.sys 08:49:07.0312 2128 aec - ok 08:49:07.0375 2128 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys 08:49:07.0421 2128 AFD - ok 08:49:07.0421 2128 Aha154x - ok 08:49:07.0437 2128 aic78u2 - ok 08:49:07.0437 2128 aic78xx - ok 08:49:07.0500 2128 [ F79B5C5B0A77A134C5671992335D1409 ] Alerter C:\WINDOWS\system32\alrsvc.dll 08:49:07.0515 2128 Alerter - ok 08:49:07.0546 2128 [ 9D12991BC6B6C5C0FBAB4C06E7073DF1 ] ALG C:\WINDOWS\System32\alg.exe 08:49:07.0578 2128 ALG - ok 08:49:07.0578 2128 AliIde - ok 08:49:07.0593 2128 amsint - ok 08:49:07.0656 2128 [ 8D60B308D061DA209CC271D9B480468C ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 08:49:07.0703 2128 AppMgmt - ok 08:49:07.0937 2128 [ 6D5F95602B8D0D994D31A864872B38EF ] AR5211 C:\WINDOWS\system32\DRIVERS\ar5211.sys 08:49:08.0125 2128 AR5211 - ok 08:49:08.0140 2128 asc - ok 08:49:08.0140 2128 asc3350p - ok 08:49:08.0156 2128 asc3550 - ok 08:49:08.0281 2128 [ D33C507942299753868204CC7642FA27 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 08:49:08.0296 2128 aspnet_state - ok 08:49:08.0343 2128 [ 0AE43C6C411254049279C2EE55630F95 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys 08:49:08.0359 2128 aswFsBlk - ok 08:49:08.0421 2128 [ 8C30B7DDD2F1D8D138EBE40345AF2B11 ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys 08:49:08.0468 2128 aswMon2 - ok 08:49:08.0500 2128 [ DA12626FD9A67F4E917E2F2FBE1E1764 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys 08:49:08.0515 2128 AswRdr - ok 08:49:08.0765 2128 [ DCB199B967375753B5019EC15F008F53 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys 08:49:08.0984 2128 aswSnx - ok 08:49:09.0125 2128 [ B32873E5A1443C0A1E322266E203BF10 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys 08:49:09.0234 2128 aswSP - ok 08:49:09.0265 2128 [ 6FF544175A9180C5D88534D3D9C9A9F7 ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys 08:49:09.0296 2128 aswTdi - ok 08:49:09.0343 2128 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 08:49:09.0343 2128 AsyncMac - ok 08:49:09.0421 2128 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 08:49:09.0421 2128 atapi - ok 08:49:09.0437 2128 Atdisk - ok 08:49:09.0625 2128 [ 982CE0265B922F5F27F36894D51BA990 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe 08:49:09.0781 2128 Ati HotKey Poller - ok 08:49:10.0500 2128 [ EC933673CF0131C4F1422B348D915F48 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 08:49:11.0203 2128 ati2mtag - ok 08:49:11.0265 2128 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 08:49:11.0281 2128 Atmarpc - ok 08:49:11.0343 2128 [ 18BFF5EBA35F2562C5AA03EB9C6BA29E ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 08:49:11.0359 2128 AudioSrv - ok 08:49:11.0421 2128 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 08:49:11.0421 2128 audstub - ok 08:49:11.0578 2128 [ 4041D31508A2A084DFB42C595854090F ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe 08:49:11.0578 2128 avast! Antivirus - ok 08:49:11.0625 2128 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 08:49:11.0625 2128 Beep - ok 08:49:11.0781 2128 [ A6BFD910074B02C8794FC65F39CC6B28 ] BITS C:\WINDOWS\system32\qmgr.dll 08:49:11.0890 2128 BITS - ok 08:49:11.0968 2128 [ 210830D2497FEF78694076179AF8C795 ] Browser C:\WINDOWS\System32\browser.dll 08:49:11.0984 2128 Browser - ok 08:49:12.0046 2128 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 08:49:12.0046 2128 cbidf2k - ok 08:49:12.0093 2128 [ 6163ED60B684BAB19D3352AB22FC48B2 ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 08:49:12.0093 2128 CCDECODE - ok 08:49:12.0109 2128 cd20xrnt - ok 08:49:12.0171 2128 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 08:49:12.0171 2128 Cdaudio - ok 08:49:12.0218 2128 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 08:49:12.0234 2128 Cdfs - ok 08:49:12.0281 2128 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 08:49:12.0296 2128 Cdrom - ok 08:49:12.0296 2128 Changer - ok 08:49:12.0343 2128 [ B4E0A9B9064AA79AE188C0D953543520 ] CiSvc C:\WINDOWS\system32\cisvc.exe 08:49:12.0343 2128 CiSvc - ok 08:49:12.0375 2128 [ 1B11121083C32EA9A55ABE547A23FF71 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 08:49:12.0390 2128 ClipSrv - ok 08:49:12.0421 2128 [ 3C4D595E7F9B747325AEF28B4ADCAAE5 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 08:49:12.0531 2128 clr_optimization_v2.0.50727_32 - ok 08:49:12.0578 2128 [ 4266BE808F85826AEDF3C64C1E240203 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 08:49:12.0593 2128 CmBatt - ok 08:49:12.0593 2128 CmdIde - ok 08:49:12.0625 2128 [ DF1B1A24BF52D0EBC01ED4ECE8979F50 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 08:49:12.0625 2128 Compbatt - ok 08:49:12.0640 2128 COMSysApp - ok 08:49:12.0656 2128 Cpqarray - ok 08:49:12.0718 2128 [ 91723CD7C96C5854149F9CAE820A90DD ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 08:49:12.0734 2128 CryptSvc - ok 08:49:13.0000 2128 [ 982069B9BB37B0323B2022169A32604D ] CXSONORA C:\WINDOWS\system32\drivers\A885VCap.sys 08:49:13.0265 2128 CXSONORA - ok 08:49:13.0265 2128 dac2w2k - ok 08:49:13.0281 2128 dac960nt - ok 08:49:13.0437 2128 [ 346E5B19FC986FE7185A0C2C43593722 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 08:49:13.0578 2128 DcomLaunch - ok 08:49:13.0656 2128 [ 94B49F2D487A7D4A79B3E96B6D5685B0 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 08:49:13.0703 2128 Dhcp - ok 08:49:13.0734 2128 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 08:49:13.0750 2128 Disk - ok 08:49:13.0750 2128 dmadmin - ok 08:49:13.0890 2128 [ 3B809FFAD55DCEBDB156D5CA1BD3DA65 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 08:49:13.0968 2128 dmboot - ok 08:49:14.0015 2128 [ 27725B6501201C3080BA73048BCE389A ] dmio C:\WINDOWS\system32\drivers\dmio.sys 08:49:14.0062 2128 dmio - ok 08:49:14.0078 2128 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 08:49:14.0078 2128 dmload - ok 08:49:14.0109 2128 [ 4ADBB7593EC0115F7622C335B427C3DA ] dmserver C:\WINDOWS\System32\dmserver.dll 08:49:14.0125 2128 dmserver - ok 08:49:14.0187 2128 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 08:49:14.0218 2128 DMusic - ok 08:49:14.0265 2128 [ F61C204EBCAA1D6B5FB5DFE7034741F3 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 08:49:14.0296 2128 Dnscache - ok 08:49:14.0296 2128 dpti2o - ok 08:49:14.0312 2128 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 08:49:14.0312 2128 drmkaud - ok 08:49:14.0375 2128 [ EFD32591F9E29C00A5814DF3F6D46683 ] ERSvc C:\WINDOWS\System32\ersvc.dll 08:49:14.0390 2128 ERSvc - ok 08:49:14.0453 2128 [ 3DA8D964D2CC12EF8E8C342471A37917 ] Eventlog C:\WINDOWS\system32\services.exe 08:49:14.0484 2128 Eventlog - ok 08:49:14.0578 2128 [ DC54CC79E1FAEFA480A8117C9BF105E1 ] EventSystem C:\WINDOWS\system32\es.dll 08:49:14.0671 2128 EventSystem - ok 08:49:14.0750 2128 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 08:49:14.0796 2128 Fastfat - ok 08:49:14.0875 2128 [ 7C8E934687C496EDC69FDBBD2C277E63 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 08:49:14.0921 2128 FastUserSwitchingCompatibility - ok 08:49:14.0984 2128 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 08:49:15.0000 2128 Fdc - ok 08:49:15.0015 2128 [ C5FB298257C0A6514EA17835E774EA0A ] Fips C:\WINDOWS\system32\drivers\Fips.sys 08:49:15.0031 2128 Fips - ok 08:49:15.0062 2128 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 08:49:15.0062 2128 Flpydisk - ok 08:49:15.0156 2128 [ 54FD90F0038F07920CB9FB6591BDE82F ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 08:49:15.0203 2128 FltMgr - ok 08:49:15.0218 2128 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 08:49:15.0218 2128 Fs_Rec - ok 08:49:15.0265 2128 [ ED6D921D8AB423138FB35BEEE6D6A6CB ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 08:49:15.0312 2128 Ftdisk - ok 08:49:15.0343 2128 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 08:49:15.0343 2128 Gpc - ok 08:49:15.0453 2128 [ 3FCC124B6E08EE0E9351F717DD136939 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 08:49:15.0500 2128 HDAudBus - ok 08:49:15.0593 2128 [ E1552A082E8C0FBB70B758F170B3AFF8 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 08:49:15.0625 2128 helpsvc - ok 08:49:15.0625 2128 HidServ - ok 08:49:15.0687 2128 [ 1DE6783B918F540149AA69943BDFEBA8 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 08:49:15.0687 2128 HidUsb - ok 08:49:15.0703 2128 hpn - ok 08:49:15.0828 2128 [ C19B522A9AE0BBC3293397F3055E80A1 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 08:49:15.0921 2128 HTTP - ok 08:49:15.0968 2128 [ 2D303CAF3C6DCFB246E74550DBED5880 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 08:49:15.0984 2128 HTTPFilter - ok 08:49:15.0984 2128 i2omgmt - ok 08:49:16.0000 2128 i2omp - ok 08:49:16.0031 2128 [ 2656FDFE0A7916C3A16F374454C55DD9 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 08:49:16.0046 2128 i8042prt - ok 08:49:16.0156 2128 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe 08:49:16.0187 2128 IDriverT - ok 08:49:16.0250 2128 [ F8AA320C6A0409C0380E5D8A99D76EC6 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 08:49:16.0265 2128 Imapi - ok 08:49:16.0359 2128 [ BC74431E59FB0BADF3E9162BD8D37B00 ] ImapiService C:\WINDOWS\system32\imapi.exe 08:49:16.0421 2128 ImapiService - ok 08:49:16.0421 2128 ini910u - ok 08:49:17.0984 2128 [ 60D7460B07012D364CED11DD9FD83E1F ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 08:49:19.0546 2128 IntcAzAudAddService - ok 08:49:19.0562 2128 IntelIde - ok 08:49:19.0609 2128 [ 78A353438791C6D04C64013A5ABEC6BD ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 08:49:19.0625 2128 intelppm - ok 08:49:19.0671 2128 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 08:49:19.0671 2128 Ip6Fw - ok 08:49:19.0718 2128 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 08:49:19.0734 2128 IpFilterDriver - ok 08:49:19.0765 2128 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 08:49:19.0781 2128 IpInIp - ok 08:49:19.0843 2128 [ B5A8E215AC29D24D60B4D1250EF05ACE ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 08:49:19.0890 2128 IpNat - ok 08:49:19.0968 2128 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 08:49:20.0000 2128 IPSec - ok 08:49:20.0046 2128 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 08:49:20.0046 2128 IRENUM - ok 08:49:20.0078 2128 [ 01A9E68528F4F34E5702123D27C67BD4 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 08:49:20.0093 2128 isapnp - ok 08:49:20.0265 2128 [ A12175F063302CD68F8FC6D572D7E5FD ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 08:49:20.0328 2128 JavaQuickStarterService - ok 08:49:20.0375 2128 [ CC13DB862F929AE33F64C3BEDC01CD31 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 08:49:20.0390 2128 Kbdclass - ok 08:49:20.0484 2128 [ D93CAD07C5683DB066B0B2D2D3790EAD ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 08:49:20.0546 2128 kmixer - ok 08:49:20.0578 2128 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 08:49:20.0609 2128 KSecDD - ok 08:49:20.0687 2128 [ 83EC18EE52DBF7CCE9520F848F4E6584 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll 08:49:20.0734 2128 lanmanserver - ok 08:49:20.0812 2128 [ FF68CD5B967CD210562C292CBD263555 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 08:49:20.0859 2128 lanmanworkstation - ok 08:49:20.0875 2128 lbrtfdc - ok 08:49:20.0906 2128 [ 94136B41F35666254DE29006DCCC30FC ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 08:49:20.0921 2128 LmHosts - ok 08:49:20.0968 2128 [ 6DFE7F2E8E8A337263AA5C92A215F161 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys 08:49:20.0968 2128 MBAMProtector - ok 08:49:21.0265 2128 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 08:49:21.0500 2128 MBAMService - ok 08:49:21.0531 2128 [ 1D0EBF9EDAE8A61CBF56ED1FF8489FAC ] Messenger C:\WINDOWS\System32\msgsvc.dll 08:49:21.0546 2128 Messenger - ok 08:49:21.0593 2128 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 08:49:21.0593 2128 mnmdd - ok 08:49:21.0640 2128 [ DB082AAFD0859E28744E6629B64E0A91 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 08:49:21.0656 2128 mnmsrvc - ok 08:49:21.0687 2128 [ 15F33D12D604D0198CE5561F102CD9C5 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 08:49:21.0703 2128 Modem - ok 08:49:21.0718 2128 [ 1992E0D143B09653AB0F9C5E04B0FD65 ] MODEMCSA C:\WINDOWS\system32\drivers\MODEMCSA.sys 08:49:21.0734 2128 MODEMCSA - ok 08:49:21.0765 2128 [ 69C12B99AE8B6B99EC314E9B99833728 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 08:49:21.0781 2128 Mouclass - ok 08:49:21.0828 2128 [ ECEC1E6CD558AB80F944F31326E9D3B5 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 08:49:21.0828 2128 mouhid - ok 08:49:21.0859 2128 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 08:49:21.0875 2128 MountMgr - ok 08:49:21.0968 2128 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 08:49:22.0015 2128 MozillaMaintenance - ok 08:49:22.0046 2128 [ 55A9A7E6BB297BF0F5B144029DCB79CC ] MPE C:\WINDOWS\system32\DRIVERS\MPE.sys 08:49:22.0062 2128 MPE - ok 08:49:22.0062 2128 mraid35x - ok 08:49:22.0156 2128 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 08:49:22.0234 2128 MRxDAV - ok 08:49:22.0421 2128 [ 1FD607FC67F7F7C633C3DA65BFC53D18 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 08:49:22.0593 2128 MRxSmb - ok 08:49:22.0625 2128 [ FB68F196B215782333FA1467CBAFC8B0 ] MSDTC C:\WINDOWS\system32\msdtc.exe 08:49:22.0625 2128 MSDTC - ok 08:49:22.0671 2128 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 08:49:22.0687 2128 Msfs - ok 08:49:22.0687 2128 MSIServer - ok 08:49:22.0750 2128 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 08:49:22.0750 2128 MSKSSRV - ok 08:49:22.0750 2128 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 08:49:22.0765 2128 MSPCLOCK - ok 08:49:22.0765 2128 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 08:49:22.0765 2128 MSPQM - ok 08:49:22.0812 2128 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 08:49:22.0828 2128 mssmbios - ok 08:49:22.0843 2128 [ BF13612142995096AB084F2DB7F40F77 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 08:49:22.0859 2128 MSTEE - ok 08:49:22.0875 2128 [ E333010A50BF603ACC350F6019E9CE02 ] MTsensor C:\WINDOWS\system32\DRIVERS\ATKACPI.sys 08:49:22.0875 2128 MTsensor - ok 08:49:22.0937 2128 [ 82035E0F41C2DD05AE41D27FE6CF7DE1 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 08:49:22.0968 2128 Mup - ok 08:49:22.0984 2128 [ 5C8DC6429C43DC6177C1FA5B76290D1A ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 08:49:23.0000 2128 NABTSFEC - ok 08:49:23.0062 2128 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 08:49:23.0125 2128 NDIS - ok 08:49:23.0125 2128 [ 520CE427A8B298F54112857BCF6BDE15 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 08:49:23.0140 2128 NdisIP - ok 08:49:23.0156 2128 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 08:49:23.0171 2128 NdisTapi - ok 08:49:23.0218 2128 [ 34D6CD56409DA9A7ED573E1C90A308BF ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 08:49:23.0218 2128 Ndisuio - ok 08:49:23.0296 2128 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 08:49:23.0328 2128 NdisWan - ok 08:49:23.0359 2128 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 08:49:23.0375 2128 NDProxy - ok 08:49:23.0406 2128 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 08:49:23.0406 2128 NetBIOS - ok 08:49:23.0484 2128 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 08:49:23.0546 2128 NetBT - ok 08:49:23.0609 2128 [ 8DE3841527161ABDFAE5C44AB570F8E1 ] NetDDE C:\WINDOWS\system32\netdde.exe 08:49:23.0640 2128 NetDDE - ok 08:49:23.0671 2128 [ 8DE3841527161ABDFAE5C44AB570F8E1 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 08:49:23.0671 2128 NetDDEdsdm - ok 08:49:23.0703 2128 [ F485FEFC8CC4FD29243D800BE5D275D1 ] Netlogon C:\WINDOWS\system32\lsass.exe 08:49:23.0718 2128 Netlogon - ok 08:49:23.0812 2128 [ 3E7B6583269BC118720D0020B03CC71E ] Netman C:\WINDOWS\System32\netman.dll 08:49:23.0890 2128 Netman - ok 08:49:24.0000 2128 [ 83387067B25E000E64B178A62E5DCD24 ] Nla C:\WINDOWS\System32\mswsock.dll 08:49:24.0078 2128 Nla - ok 08:49:24.0140 2128 [ B9730495E0CF674680121E34BD95A73B ] NPF C:\WINDOWS\system32\drivers\NPF.sys 08:49:24.0171 2128 NPF - ok 08:49:24.0218 2128 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 08:49:24.0234 2128 Npfs - ok 08:49:24.0562 2128 [ B78BE402C3F63DD55521F73876951CDD ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 08:49:24.0765 2128 Ntfs - ok 08:49:24.0796 2128 [ F485FEFC8CC4FD29243D800BE5D275D1 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 08:49:24.0796 2128 NtLmSsp - ok 08:49:24.0937 2128 [ C8CE1566B0537C3F5F7AE1CA458A6697 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 08:49:25.0062 2128 NtmsSvc - ok 08:49:25.0078 2128 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 08:49:25.0078 2128 Null - ok 08:49:25.0109 2128 [ 05C85C8EACFE20AE1F72C25C003405C6 ] NWCWorkstation C:\WINDOWS\System32\nwwks.dll 08:49:25.0140 2128 NWCWorkstation - ok 08:49:25.0171 2128 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 08:49:25.0187 2128 NwlnkFlt - ok 08:49:25.0203 2128 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 08:49:25.0203 2128 NwlnkFwd - ok 08:49:25.0265 2128 [ 79EA3FCDA7067977625B3363A2657C80 ] NwlnkIpx C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys 08:49:25.0281 2128 NwlnkIpx - ok 08:49:25.0328 2128 [ 56D34A67C05E94E16377C60609741FF8 ] NwlnkNb C:\WINDOWS\system32\DRIVERS\nwlnknb.sys 08:49:25.0343 2128 NwlnkNb - ok 08:49:25.0375 2128 [ C0BB7D1615E1ACBDC99757F6CEAF8CF0 ] NwlnkSpx C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys 08:49:25.0390 2128 NwlnkSpx - ok 08:49:25.0453 2128 [ 03373A79440473062C6F3AEDEC6A49C8 ] NWRDR C:\WINDOWS\system32\DRIVERS\nwrdr.sys 08:49:25.0500 2128 NWRDR - ok 08:49:25.0765 2128 [ 84DE1DD996B48B05ACE31AD015FA108A ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 08:49:25.0906 2128 odserv - ok 08:49:25.0984 2128 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 08:49:26.0031 2128 ose - ok 08:49:26.0093 2128 [ 2FF48D8FDC815A8492FB2BD81E6999C2 ] Parport C:\WINDOWS\system32\drivers\Parport.sys 08:49:26.0125 2128 Parport - ok 08:49:26.0140 2128 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 08:49:26.0156 2128 PartMgr - ok 08:49:26.0203 2128 [ 453EC2C2A20A1382F564541918520EEB ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 08:49:26.0203 2128 ParVdm - ok 08:49:26.0250 2128 [ 5FD05C92EC56F696EAA50B68CEF1B84A ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 08:49:26.0265 2128 PCI - ok 08:49:26.0281 2128 PCIDump - ok 08:49:26.0281 2128 [ 548CF2D6369EAE441A4C6BAA75BC4F0A ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 08:49:26.0281 2128 PCIIde - ok 08:49:26.0343 2128 [ 2849812217ECEC059CB45F80EB6E52D4 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 08:49:26.0375 2128 Pcmcia - ok 08:49:26.0375 2128 PDCOMP - ok 08:49:26.0390 2128 PDFRAME - ok 08:49:26.0406 2128 PDRELI - ok 08:49:26.0406 2128 PDRFRAME - ok 08:49:26.0421 2128 perc2 - ok 08:49:26.0421 2128 perc2hib - ok 08:49:26.0500 2128 [ 3DA8D964D2CC12EF8E8C342471A37917 ] PlugPlay C:\WINDOWS\system32\services.exe 08:49:26.0515 2128 PlugPlay - ok 08:49:26.0531 2128 [ F485FEFC8CC4FD29243D800BE5D275D1 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 08:49:26.0531 2128 PolicyAgent - ok 08:49:26.0562 2128 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 08:49:26.0578 2128 PptpMiniport - ok 08:49:26.0593 2128 [ F485FEFC8CC4FD29243D800BE5D275D1 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 08:49:26.0593 2128 ProtectedStorage - ok 08:49:26.0640 2128 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 08:49:26.0671 2128 PSched - ok 08:49:26.0703 2128 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 08:49:26.0703 2128 Ptilink - ok 08:49:26.0703 2128 ql1080 - ok 08:49:26.0718 2128 Ql10wnt - ok 08:49:26.0734 2128 ql12160 - ok 08:49:26.0734 2128 ql1240 - ok 08:49:26.0750 2128 ql1280 - ok 08:49:26.0781 2128 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 08:49:26.0781 2128 RasAcd - ok 08:49:26.0828 2128 [ 5ED5AF86EE8CC13F6392B37A81AF5D5B ] RasAuto C:\WINDOWS\System32\rasauto.dll 08:49:26.0859 2128 RasAuto - ok 08:49:26.0890 2128 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 08:49:26.0906 2128 Rasl2tp - ok 08:49:26.0984 2128 [ FF59EC9427760470DE7FFCA75738ECB8 ] RasMan C:\WINDOWS\System32\rasmans.dll 08:49:27.0046 2128 RasMan - ok 08:49:27.0093 2128 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 08:49:27.0109 2128 RasPppoe - ok 08:49:27.0125 2128 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 08:49:27.0125 2128 Raspti - ok 08:49:27.0203 2128 [ 29D66245ADBA878FFF574CD66ABD2884 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 08:49:27.0265 2128 Rdbss - ok 08:49:27.0281 2128 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 08:49:27.0296 2128 RDPCDD - ok 08:49:27.0406 2128 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 08:49:27.0468 2128 rdpdr - ok 08:49:27.0546 2128 [ D4F5643D7714EF499AE9527FDCD50894 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 08:49:27.0578 2128 RDPWD - ok 08:49:27.0640 2128 [ EE93399BC7CD84624AB7890DD7D8B296 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 08:49:27.0687 2128 RDSessMgr - ok 08:49:27.0718 2128 [ BDDCECE9ACDAD26841C987D10376F6F7 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 08:49:27.0750 2128 redbook - ok 08:49:27.0796 2128 [ 6A9CB0C18B634B187B8B5A32B0FC2773 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 08:49:27.0812 2128 RemoteAccess - ok 08:49:27.0875 2128 [ A19BFED61736127DB5B8B815AFB35190 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 08:49:27.0890 2128 RemoteRegistry - ok 08:49:28.0078 2128 [ 06A49B7BDC36CFBF97DD90804F833369 ] RichVideo C:\Program Files\CyberLink\Shared files\RichVideo.exe 08:49:28.0171 2128 RichVideo - ok 08:49:28.0203 2128 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys 08:49:28.0218 2128 ROOTMODEM - ok 08:49:28.0265 2128 [ 6BE739F700580F23740EFA1D1B57C0A5 ] RpcLocator C:\WINDOWS\system32\locator.exe 08:49:28.0296 2128 RpcLocator - ok 08:49:28.0453 2128 [ 346E5B19FC986FE7185A0C2C43593722 ] RpcSs C:\WINDOWS\system32\rpcss.dll 08:49:28.0468 2128 RpcSs - ok 08:49:28.0531 2128 [ 9ACEE3313020A01235336C2A483AFD1A ] RSVP C:\WINDOWS\system32\rsvp.exe 08:49:28.0578 2128 RSVP - ok 08:49:28.0609 2128 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 08:49:28.0609 2128 rtl8139 - ok 08:49:28.0656 2128 [ 4CDED5D507E0334DFC9FD4D417240FA5 ] RTSTOR C:\WINDOWS\system32\drivers\RTSTOR.SYS 08:49:28.0671 2128 RTSTOR - ok 08:49:28.0687 2128 [ F485FEFC8CC4FD29243D800BE5D275D1 ] SamSs C:\WINDOWS\system32\lsass.exe 08:49:28.0687 2128 SamSs - ok 08:49:28.0734 2128 [ 8DF7262F72C3AB75486D21BA78B9F749 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 08:49:28.0765 2128 SCardSvr - ok 08:49:28.0875 2128 [ E5F1C9EAD4C6617ACD40CA90882CC7D4 ] Schedule C:\WINDOWS\system32\schedsvc.dll 08:49:28.0937 2128 Schedule - ok 08:49:29.0000 2128 [ 531EBC57DB331C8500C042D9F8A6AEF2 ] se45bus C:\WINDOWS\system32\DRIVERS\se45bus.sys 08:49:29.0031 2128 se45bus - ok 08:49:29.0046 2128 [ 148E7E813681D3A0A05F09826080CC2B ] se45mdfl C:\WINDOWS\system32\DRIVERS\se45mdfl.sys 08:49:29.0062 2128 se45mdfl - ok 08:49:29.0093 2128 [ B4CE022564D0D3FD7B0E5459AA12AA72 ] se45mdm C:\WINDOWS\system32\DRIVERS\se45mdm.sys 08:49:29.0140 2128 se45mdm - ok 08:49:29.0187 2128 [ 6D04EA9C049EBD78D64ADE447DE3F7EB ] se45mgmt C:\WINDOWS\system32\DRIVERS\se45mgmt.sys 08:49:29.0234 2128 se45mgmt - ok 08:49:29.0250 2128 [ FDC74BEAA13A801FAC574BC7AF1450C4 ] se45nd5 C:\WINDOWS\system32\DRIVERS\se45nd5.sys 08:49:29.0265 2128 se45nd5 - ok 08:49:29.0296 2128 [ 5E003693822460D37516D9A262DE9E11 ] se45obex C:\WINDOWS\system32\DRIVERS\se45obex.sys 08:49:29.0343 2128 se45obex - ok 08:49:29.0375 2128 [ FC7021ADB632200DA591A55A35A78ACC ] se45unic C:\WINDOWS\system32\DRIVERS\se45unic.sys 08:49:29.0437 2128 se45unic - ok 08:49:29.0578 2128 [ 331E7BDE228914574FC9AE6CD520DAFA ] SeaPort C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 08:49:29.0656 2128 SeaPort - ok 08:49:29.0687 2128 [ D26E26EA516450AF9D072635C60387F4 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 08:49:29.0687 2128 Secdrv - ok 08:49:29.0718 2128 [ 60255AC385A08AAF4897AB4A42483500 ] seclogon C:\WINDOWS\System32\seclogon.dll 08:49:29.0734 2128 seclogon - ok 08:49:29.0765 2128 [ 1398DF553E701C7948188A7D4E347A18 ] SENS C:\WINDOWS\system32\sens.dll 08:49:29.0781 2128 SENS - ok 08:49:29.0828 2128 [ 859BC6F8C3D58CFDA9181E9926C7DDB9 ] Serial C:\WINDOWS\system32\drivers\Serial.sys 08:49:29.0843 2128 Serial - ok 08:49:29.0875 2128 [ 352BE0AA074B0F362966B77B55A88AC9 ] sermouse C:\WINDOWS\system32\DRIVERS\sermouse.sys 08:49:29.0890 2128 sermouse - ok 08:49:29.0906 2128 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 08:49:29.0921 2128 Sfloppy - ok 08:49:30.0046 2128 [ DDC87ADF808D192A5212CC8A1E7F8E87 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 08:49:30.0171 2128 SharedAccess - ok 08:49:30.0234 2128 [ 7C8E934687C496EDC69FDBBD2C277E63 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 08:49:30.0234 2128 ShellHWDetection - ok 08:49:30.0281 2128 [ C16173316918A1360DC22947C4FF6352 ] silabenm C:\WINDOWS\system32\DRIVERS\silabenm.sys 08:49:30.0296 2128 silabenm - ok 08:49:30.0312 2128 [ 20A3CA1DFB7165315753339C204063EA ] silabser C:\WINDOWS\system32\DRIVERS\silabser.sys 08:49:30.0343 2128 silabser - ok 08:49:30.0359 2128 Simbad - ok 08:49:31.0546 2128 [ 0F97E7A47A52F4A36969F0FC319654C2 ] Skype C2C Service C:\Documents and Settings\All Users\Dane aplikacji\Skype\Toolbars\Skype C2C Service\c2c_service.exe 08:49:32.0625 2128 Skype C2C Service - ok 08:49:32.0734 2128 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 08:49:32.0796 2128 SkypeUpdate - ok 08:49:32.0843 2128 [ 5CAEED86821FA2C6139E32E9E05CCDC9 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 08:49:32.0859 2128 SLIP - ok 08:49:32.0859 2128 smserial - ok 08:49:32.0875 2128 Sparrow - ok 08:49:32.0921 2128 [ 8E186B8F23295D1E42C573B82B80D548 ] splitter C:\WINDOWS\system32\drivers\splitter.sys 08:49:32.0921 2128 splitter - ok 08:49:32.0968 2128 [ BEBE8A85954FF460374FD5A0CD21E19B ] Spooler C:\WINDOWS\system32\spoolsv.exe 08:49:32.0984 2128 Spooler - ok 08:49:33.0046 2128 [ 6145CA23BCCDA679A772EC0AF42D6EB5 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 08:49:33.0078 2128 sr - ok 08:49:33.0156 2128 [ F309D9894FCA821E3C2F557A8032D47A ] srservice C:\WINDOWS\system32\srsvc.dll 08:49:33.0218 2128 srservice - ok 08:49:33.0343 2128 [ 20B7E396720353E4117D64D9DCB926CA ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 08:49:33.0468 2128 Srv - ok 08:49:33.0531 2128 [ BB754C4BE0B18F0FAF01A7EBDE7025C4 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 08:49:33.0562 2128 SSDPSRV - ok 08:49:33.0687 2128 [ C6718154A50FE6C55E382CDBDEDCE7A7 ] stisvc C:\WINDOWS\system32\wiaservc.dll 08:49:33.0812 2128 stisvc - ok 08:49:34.0296 2128 [ 8181A2ECC2B5ECCD26B05F6DAD1A8736 ] StkCMini C:\WINDOWS\system32\Drivers\StkCMini.sys 08:49:34.0750 2128 StkCMini - ok 08:49:34.0828 2128 [ 54FB71D9645AE6754BA3390813280DBD ] StkSSrv C:\WINDOWS\System32\StkCSrv.exe 08:49:34.0875 2128 StkSSrv - ok 08:49:34.0906 2128 [ 284C57DF5DC7ABCA656BC2B96A667AFB ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 08:49:34.0906 2128 streamip - ok 08:49:34.0921 2128 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 08:49:34.0937 2128 swenum - ok 08:49:34.0968 2128 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 08:49:34.0984 2128 swmidi - ok 08:49:35.0000 2128 SwPrv - ok 08:49:35.0000 2128 symc810 - ok 08:49:35.0015 2128 symc8xx - ok 08:49:35.0015 2128 sym_hi - ok 08:49:35.0031 2128 sym_u3 - ok 08:49:35.0140 2128 [ 69BF2DD9B1099D1AA3E7CF14B4B842CD ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys 08:49:35.0218 2128 SynTP - ok 08:49:35.0250 2128 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 08:49:35.0265 2128 sysaudio - ok 08:49:35.0328 2128 [ 5893B3B5B966233CAE426B2FEDC34DDF ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 08:49:35.0359 2128 SysmonLog - ok 08:49:35.0468 2128 [ 0A695B77564D8E9333E846B526F95AB2 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 08:49:35.0562 2128 TapiSrv - ok 08:49:35.0734 2128 [ 9F4B36614A0FC234525BA224957DE55C ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 08:49:35.0937 2128 Tcpip - ok 08:49:35.0968 2128 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 08:49:35.0984 2128 TDPIPE - ok 08:49:36.0000 2128 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 08:49:36.0015 2128 TDTCP - ok 08:49:36.0046 2128 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 08:49:36.0062 2128 TermDD - ok 08:49:36.0218 2128 [ 2C28157229925280916B3041CCC5FE4B ] TermService C:\WINDOWS\System32\termsrv.dll 08:49:36.0328 2128 TermService - ok 08:49:36.0390 2128 [ 7C8E934687C496EDC69FDBBD2C277E63 ] Themes C:\WINDOWS\System32\shsvcs.dll 08:49:36.0390 2128 Themes - ok 08:49:36.0437 2128 [ CAC717418CCDF09110F406108017BFA6 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 08:49:36.0468 2128 TlntSvr - ok 08:49:36.0500 2128 [ E362D54FD394999C4178936396664E57 ] toshidpt C:\WINDOWS\system32\drivers\Toshidpt.sys 08:49:36.0500 2128 toshidpt - ok 08:49:36.0515 2128 TosIde - ok 08:49:36.0546 2128 [ 02EBF69066D6F208AF4D07481BBAE0AD ] tosporte C:\WINDOWS\system32\DRIVERS\tosporte.sys 08:49:36.0578 2128 tosporte - ok 08:49:36.0640 2128 [ B52D9CE4A1F2FEB1C77F913B55768530 ] Tosrfbd C:\WINDOWS\system32\Drivers\tosrfbd.sys 08:49:36.0687 2128 Tosrfbd - ok 08:49:36.0703 2128 [ 1AE2BA74B2A4F5A358B13FCD35258C30 ] Tosrfbnp C:\WINDOWS\system32\Drivers\tosrfbnp.sys 08:49:36.0750 2128 Tosrfbnp - ok 08:49:36.0828 2128 [ 5BA1CA3B3CDDB1DDC67DF473F05D1EC2 ] Tosrfcom C:\WINDOWS\system32\Drivers\tosrfcom.sys 08:49:36.0906 2128 Tosrfcom - ok 08:49:36.0937 2128 [ 8310963D2D06860E272EEC87BCA4217A ] Tosrfhid C:\WINDOWS\system32\DRIVERS\Tosrfhid.sys 08:49:36.0953 2128 Tosrfhid - ok 08:49:36.0984 2128 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\WINDOWS\system32\DRIVERS\tosrfnds.sys 08:49:37.0000 2128 tosrfnds - ok 08:49:37.0031 2128 [ AB6FD13D7EFA2634FA6BDF84C7EF0696 ] TosRfSnd C:\WINDOWS\system32\drivers\TosRfSnd.sys 08:49:37.0062 2128 TosRfSnd - ok 08:49:37.0078 2128 [ C639FC314EA7436325ADE8CD514B627C ] Tosrfusb C:\WINDOWS\system32\Drivers\tosrfusb.sys 08:49:37.0093 2128 Tosrfusb - ok 08:49:37.0156 2128 [ FACBC230AA93401D2FE88976E7CB7369 ] TrkWks C:\WINDOWS\system32\trkwks.dll 08:49:37.0187 2128 TrkWks - ok 08:49:37.0265 2128 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 08:49:37.0296 2128 Udfs - ok 08:49:37.0296 2128 ultra - ok 08:49:37.0406 2128 [ AFF2E5045961BBC0A602BB6F95EB1345 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 08:49:37.0484 2128 Update - ok 08:49:37.0562 2128 [ 387D2A06C8E7CCCEA8E9A350C8FE6781 ] upnphost C:\WINDOWS\System32\upnphost.dll 08:49:37.0609 2128 upnphost - ok 08:49:37.0640 2128 [ 576A2C38CF3904F2CA1107F922288435 ] UPS C:\WINDOWS\System32\ups.exe 08:49:37.0656 2128 UPS - ok 08:49:37.0703 2128 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 08:49:37.0718 2128 usbccgp - ok 08:49:37.0843 2128 [ 15E993BA2F6946B2BFBBFCD30398621E ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 08:49:37.0875 2128 usbehci - ok 08:49:37.0906 2128 [ C72F40947F92CEA56A8FB532EDF025F1 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 08:49:37.0937 2128 usbhub - ok 08:49:37.0953 2128 [ BDFE799A8531BAD8A5A985821FE78760 ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys 08:49:37.0968 2128 usbohci - ok 08:49:38.0031 2128 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 08:49:38.0031 2128 usbprint - ok 08:49:38.0093 2128 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 08:49:38.0109 2128 usbscan - ok 08:49:38.0125 2128 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 08:49:38.0125 2128 usbstor - ok 08:49:38.0156 2128 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 08:49:38.0171 2128 VgaSave - ok 08:49:38.0171 2128 ViaIde - ok 08:49:38.0218 2128 [ ECD173739B8EC10A814CC18653DF5A36 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 08:49:38.0234 2128 VolSnap - ok 08:49:38.0343 2128 [ FEC1E19B91972105044960B23C442949 ] VSS C:\WINDOWS\System32\vssvc.exe 08:49:38.0406 2128 VSS - ok 08:49:38.0515 2128 [ 000A0D516A2E20441E77AEA44E46B19B ] W32Time C:\WINDOWS\system32\w32time.dll 08:49:38.0593 2128 W32Time - ok 08:49:38.0625 2128 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 08:49:38.0640 2128 Wanarp - ok 08:49:38.0921 2128 [ FD47474BD21794508AF449D9D91AF6E6 ] Wdf01000 C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 08:49:39.0046 2128 Wdf01000 - ok 08:49:39.0046 2128 WDICA - ok 08:49:39.0125 2128 [ 2797F33EBF50466020C430EE4F037933 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 08:49:39.0156 2128 wdmaud - ok 08:49:39.0187 2128 [ F796BEFE565C59A30A4C61B640557276 ] WebClient C:\WINDOWS\System32\webclnt.dll 08:49:39.0218 2128 WebClient - ok 08:49:39.0359 2128 [ 482435B2A2DE8E06C83C3B1EB3237C2C ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 08:49:39.0406 2128 winmgmt - ok 08:49:39.0484 2128 [ FA83DF4EE3B86E5CE53A5EA425F3F472 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 08:49:39.0500 2128 WmdmPmSN - ok 08:49:39.0875 2128 [ 5822B8BAF16F7CAE6B56E839D65A8BFB ] Wmi C:\WINDOWS\System32\advapi32.dll 08:49:40.0109 2128 Wmi - ok 08:49:40.0171 2128 [ 45E43704611D7C2202A180FF87E63550 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 08:49:40.0203 2128 WmiApSrv - ok 08:49:40.0281 2128 [ 390D0951271908C46EECF89893876424 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 08:49:40.0312 2128 wscsvc - ok 08:49:40.0375 2128 [ 8FEDE6CF2EB103EF1274CE2C9D8EE0E7 ] WSIMD C:\WINDOWS\system32\DRIVERS\wsimd.sys 08:49:40.0390 2128 WSIMD - ok 08:49:40.0437 2128 [ D5842484F05E12121C511AA93F6439EC ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 08:49:40.0453 2128 WSTCODEC - ok 08:49:40.0484 2128 [ 40C600488FF127953AA2F1835E5FD433 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 08:49:40.0484 2128 wuauserv - ok 08:49:40.0640 2128 [ 98A8014DBE72349F73462262CF493574 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 08:49:40.0796 2128 WZCSVC - ok 08:49:40.0937 2128 [ E3C9EF5BCC9EB171BD81051CD19BDED7 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 08:49:41.0000 2128 xmlprov - ok 08:49:41.0078 2128 [ 72F8C1568A56C7059CB1074A7E529DC6 ] Zwinky_5qService C:\PROGRA~1\ZWINKY~2\bar\1.bin\5qbarsvc.exe 08:49:41.0093 2128 Zwinky_5qService - ok 08:49:41.0187 2128 [ 8098180B3F6C430A4E60333BC036F936 ] {95808DC4-FA4A-4c74-92FE-5B863F82066B} C:\Program Files\CyberLink\PowerDVD\000.fcl 08:49:41.0187 2128 {95808DC4-FA4A-4c74-92FE-5B863F82066B} - ok 08:49:41.0187 2128 ================ Scan global =============================== 08:49:41.0265 2128 [ FF952713E6B51D49B68BBA9233FBAA81 ] C:\WINDOWS\system32\basesrv.dll 08:49:41.0390 2128 [ 143B9018051E3A3CFDE92A861F8080E9 ] C:\WINDOWS\system32\winsrv.dll 08:49:41.0609 2128 [ 143B9018051E3A3CFDE92A861F8080E9 ] C:\WINDOWS\system32\winsrv.dll 08:49:41.0656 2128 [ 3DA8D964D2CC12EF8E8C342471A37917 ] C:\WINDOWS\system32\services.exe 08:49:41.0671 2128 [Global] - ok 08:49:41.0671 2128 ================ Scan MBR ================================== 08:49:41.0703 2128 [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 08:49:42.0031 2128 \Device\Harddisk0\DR0 - ok 08:49:42.0031 2128 ================ Scan VBR ================================== 08:49:42.0046 2128 [ A8398B18F0644B55B29027F29EF258EB ] \Device\Harddisk0\DR0\Partition1 08:49:42.0046 2128 \Device\Harddisk0\DR0\Partition1 - ok 08:49:42.0062 2128 [ 7FF38BC99E8B298D319D155DDAC0A39D ] \Device\Harddisk0\DR0\Partition2 08:49:42.0078 2128 \Device\Harddisk0\DR0\Partition2 - ok 08:49:42.0078 2128 ============================================================ 08:49:42.0078 2128 Scan finished 08:49:42.0078 2128 ============================================================ 08:49:42.0093 2864 Detected object count: 1 08:49:42.0093 2864 Actual detected object count: 1 08:49:58.0843 2864 C:\WINDOWS\system32\DRIVERS\ACPI.sys - copied to quarantine 08:50:09.0218 2864 Backup copy found, using it.. 08:50:09.0343 2864 C:\WINDOWS\system32\DRIVERS\ACPI.sys - will be cured on reboot 08:50:09.0343 2864 ACPI ( Virus.Win32.Rloader.a ) - User select action: Cure 08:52:58.0093 0964 Deinitialize success