20:51:25.0357 5540 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 20:51:27.0385 5540 ============================================================ 20:51:27.0385 5540 Current date / time: 2013/03/05 20:51:27.0385 20:51:27.0385 5540 SystemInfo: 20:51:27.0385 5540 20:51:27.0385 5540 OS Version: 6.0.6002 ServicePack: 2.0 20:51:27.0385 5540 Product type: Workstation 20:51:27.0385 5540 ComputerName: MOJETO 20:51:27.0385 5540 UserName: Bartek 20:51:27.0385 5540 Windows directory: C:\Windows 20:51:27.0385 5540 System windows directory: C:\Windows 20:51:27.0385 5540 Processor architecture: Intel x86 20:51:27.0385 5540 Number of processors: 2 20:51:27.0385 5540 Page size: 0x1000 20:51:27.0385 5540 Boot type: Normal boot 20:51:27.0385 5540 ============================================================ 20:51:29.0070 5540 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 20:51:29.0070 5540 ============================================================ 20:51:29.0070 5540 \Device\Harddisk0\DR0: 20:51:29.0070 5540 MBR partitions: 20:51:29.0070 5540 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x129C7800 20:51:29.0070 5540 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x12CB6000, BlocksNum 0x127782B0 20:51:29.0070 5540 ============================================================ 20:51:29.0164 5540 C: <-> \Device\Harddisk0\DR0\Partition1 20:51:29.0226 5540 E: <-> \Device\Harddisk0\DR0\Partition2 20:51:29.0242 5540 ============================================================ 20:51:29.0242 5540 Initialize success 20:51:29.0242 5540 ============================================================ 20:51:54.0908 5064 ============================================================ 20:51:54.0908 5064 Scan started 20:51:54.0908 5064 Mode: Manual; 20:51:54.0908 5064 ============================================================ 20:51:55.0751 5064 ================ Scan system memory ======================== 20:51:55.0751 5064 System memory - ok 20:51:55.0766 5064 ================ Scan services ============================= 20:51:55.0985 5064 [ ADC420616C501B45D26C0FD3EF1E54E4 ] ACDaemon C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe 20:51:55.0985 5064 ACDaemon - ok 20:51:56.0250 5064 [ 82B296AE1892FE3DBEE00C9CF92F8AC7 ] ACPI C:\Windows\system32\drivers\acpi.sys 20:51:56.0250 5064 ACPI - ok 20:51:56.0343 5064 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 20:51:56.0359 5064 AdobeARMservice - ok 20:51:56.0453 5064 [ 9942DC4CC265CDA00486504444EF521D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 20:51:56.0453 5064 AdobeFlashPlayerUpdateSvc - ok 20:51:56.0515 5064 [ 04F0FCAC69C7C71A3AC4EB97FAFC8303 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 20:51:56.0546 5064 adp94xx - ok 20:51:56.0593 5064 [ 60505E0041F7751BDBB80F88BF45C2CE ] adpahci C:\Windows\system32\drivers\adpahci.sys 20:51:56.0609 5064 adpahci - ok 20:51:56.0624 5064 [ 8A42779B02AEC986EAB64ECFC98F8BD7 ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 20:51:56.0624 5064 adpu160m - ok 20:51:56.0655 5064 [ 241C9E37F8CE45EF51C3DE27515CA4E5 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 20:51:56.0655 5064 adpu320 - ok 20:51:56.0702 5064 [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 20:51:56.0702 5064 AeLookupSvc - ok 20:51:56.0733 5064 [ FE3EA6E9AFC1A78E6EDCA121E006AFB7 ] Afc C:\Windows\system32\drivers\Afc.sys 20:51:56.0749 5064 Afc - ok 20:51:56.0811 5064 [ 3911B972B55FEA0478476B2E777B29FA ] AFD C:\Windows\system32\drivers\afd.sys 20:51:57.0077 5064 AFD - ok 20:51:57.0139 5064 [ 13F9E33747E6B41A3FF305C37DB0D360 ] agp440 C:\Windows\system32\drivers\agp440.sys 20:51:57.0139 5064 agp440 - ok 20:51:57.0186 5064 [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx C:\Windows\system32\drivers\djsvs.sys 20:51:57.0186 5064 aic78xx - ok 20:51:57.0233 5064 [ 0940030D5A5869067CCC03E3B0B8DEC7 ] alcan5wn C:\Windows\system32\DRIVERS\alcan5wn.sys 20:51:57.0233 5064 alcan5wn - ok 20:51:57.0311 5064 [ 4C9577888C53243E2991456F510488A1 ] alcaudsl C:\Windows\system32\DRIVERS\alcaudsl.sys 20:51:57.0357 5064 alcaudsl - ok 20:51:57.0389 5064 [ A1545B731579895D8CC44FC0481C1192 ] ALG C:\Windows\System32\alg.exe 20:51:57.0389 5064 ALG - ok 20:51:57.0420 5064 [ 9EAEF5FC9B8E351AFA7E78A6FAE91F91 ] aliide C:\Windows\system32\drivers\aliide.sys 20:51:57.0420 5064 aliide - ok 20:51:57.0435 5064 [ C47344BC706E5F0B9DCE369516661578 ] amdagp C:\Windows\system32\drivers\amdagp.sys 20:51:57.0435 5064 amdagp - ok 20:51:57.0467 5064 [ 9B78A39A4C173FDBC1321E0DD659B34C ] amdide C:\Windows\system32\drivers\amdide.sys 20:51:57.0467 5064 amdide - ok 20:51:57.0498 5064 [ 18F29B49AD23ECEE3D2A826C725C8D48 ] AmdK7 C:\Windows\system32\drivers\amdk7.sys 20:51:57.0498 5064 AmdK7 - ok 20:51:57.0513 5064 [ 93AE7F7DD54AB986A6F1A1B37BE7442D ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 20:51:57.0513 5064 AmdK8 - ok 20:51:57.0576 5064 [ C6D704C7F0434DC791AAC37CAC4B6E14 ] Appinfo C:\Windows\System32\appinfo.dll 20:51:57.0607 5064 Appinfo - ok 20:51:57.0638 5064 [ 5D2888182FB46632511ACEE92FDAD522 ] arc C:\Windows\system32\drivers\arc.sys 20:51:57.0654 5064 arc - ok 20:51:57.0669 5064 [ 5E2A321BD7C8B3624E41FDEC3E244945 ] arcsas C:\Windows\system32\drivers\arcsas.sys 20:51:57.0669 5064 arcsas - ok 20:51:57.0716 5064 [ 53B202ABEE6455406254444303E87BE1 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 20:51:57.0716 5064 AsyncMac - ok 20:51:57.0747 5064 [ 1F05B78AB91C9075565A9D8A4B880BC4 ] atapi C:\Windows\system32\drivers\atapi.sys 20:51:57.0763 5064 atapi - ok 20:51:57.0810 5064 [ 8BE56F8300E1C37B578DA23C71816B7A ] athr C:\Windows\system32\DRIVERS\athr.sys 20:51:57.0857 5064 athr - ok 20:51:57.0919 5064 [ ECEA2C66EBA281E9D5A5F8EA54D0630C ] Ati External Event Utility C:\Windows\system32\Ati2evxx.exe 20:51:58.0137 5064 Ati External Event Utility - ok 20:51:58.0278 5064 [ 96F5EEA88F9146F5F803AD20C4264565 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys 20:51:58.0730 5064 atikmdag - ok 20:51:58.0761 5064 [ 5A1465AD2E7C1BC39CDA12A355329096 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys 20:51:58.0777 5064 AtiPcie - ok 20:51:58.0824 5064 [ 3C4B9850A2631C2263507400D029057B ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys 20:51:59.0027 5064 atksgt - ok 20:51:59.0089 5064 [ 68E2A1A0407A66CF50DA0300852424AB ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 20:51:59.0120 5064 AudioEndpointBuilder - ok 20:51:59.0136 5064 [ 68E2A1A0407A66CF50DA0300852424AB ] Audiosrv C:\Windows\System32\Audiosrv.dll 20:51:59.0136 5064 Audiosrv - ok 20:51:59.0198 5064 [ 67E506B75BD5326A3EC7B70BD014DFB6 ] Beep C:\Windows\system32\drivers\Beep.sys 20:51:59.0198 5064 Beep - ok 20:51:59.0214 5064 [ D4DF28447741FD3D953526E33A617397 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 20:51:59.0229 5064 blbdrive - ok 20:51:59.0276 5064 [ 35F376253F687BDE63976CCB3F2108CA ] bowser C:\Windows\system32\DRIVERS\bowser.sys 20:51:59.0448 5064 bowser - ok 20:51:59.0479 5064 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 20:51:59.0479 5064 BrFiltLo - ok 20:51:59.0495 5064 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 20:51:59.0495 5064 BrFiltUp - ok 20:51:59.0541 5064 [ B1564976D98E91FC764D5DC28A0297DA ] Bridge C:\Windows\system32\DRIVERS\bridge.sys 20:51:59.0557 5064 Bridge - ok 20:51:59.0604 5064 [ B1564976D98E91FC764D5DC28A0297DA ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 20:51:59.0604 5064 BridgeMP - ok 20:51:59.0635 5064 [ A3629A0C4226F9E9C72FAAEEBC3AD33C ] Browser C:\Windows\System32\browser.dll 20:51:59.0651 5064 Browser - ok 20:51:59.0682 5064 [ B304E75CFF293029EDDF094246747113 ] Brserid C:\Windows\system32\drivers\brserid.sys 20:51:59.0697 5064 Brserid - ok 20:51:59.0729 5064 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 20:51:59.0729 5064 BrSerWdm - ok 20:51:59.0744 5064 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 20:51:59.0744 5064 BrUsbMdm - ok 20:51:59.0760 5064 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 20:51:59.0760 5064 BrUsbSer - ok 20:51:59.0807 5064 [ DA7B195275BDA7F8FCF79B40E0F45DDE ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys 20:51:59.0807 5064 BthEnum - ok 20:51:59.0853 5064 [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 20:51:59.0853 5064 BTHMODEM - ok 20:51:59.0885 5064 [ 5904EFA25F829BF84EA6FB045134A1D8 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys 20:51:59.0885 5064 BthPan - ok 20:51:59.0931 5064 [ 73D53F8E90550BA81E2CF44A0873B410 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys 20:51:59.0931 5064 BTHPORT - ok 20:51:59.0963 5064 [ A4C8377FA4A994E07075107DBE2E3DCE ] BthServ C:\Windows\System32\bthserv.dll 20:51:59.0963 5064 BthServ - ok 20:51:59.0994 5064 [ 32045A4BB143BBC5BAB1298C4E9E309A ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys 20:51:59.0994 5064 BTHUSB - ok 20:52:00.0025 5064 [ 7ADD03E75BEB9E6DD102C3081D29840A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 20:52:00.0041 5064 cdfs - ok 20:52:00.0072 5064 [ 6B4BFFB9BECD728097024276430DB314 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 20:52:00.0072 5064 cdrom - ok 20:52:00.0119 5064 [ 312EC3E37A0A1F2006534913E37B4423 ] CertPropSvc C:\Windows\System32\certprop.dll 20:52:00.0119 5064 CertPropSvc - ok 20:52:00.0134 5064 [ E5D4133F37219DBCFE102BC61072589D ] circlass C:\Windows\system32\drivers\circlass.sys 20:52:00.0150 5064 circlass - ok 20:52:00.0181 5064 [ D7659D3B5B92C31E84E53C1431F35132 ] CLFS C:\Windows\system32\CLFS.sys 20:52:00.0197 5064 CLFS - ok 20:52:00.0275 5064 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 20:52:00.0290 5064 clr_optimization_v2.0.50727_32 - ok 20:52:00.0399 5064 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 20:52:00.0399 5064 clr_optimization_v4.0.30319_32 - ok 20:52:00.0446 5064 [ 99AFC3795B58CC478FBBBCDC658FCB56 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 20:52:00.0446 5064 CmBatt - ok 20:52:00.0587 5064 [ 2A2D72271844C52F004901A60312B96A ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe 20:52:00.0602 5064 cmdAgent - ok 20:52:00.0633 5064 [ CCF9B580E0A8D4EB9A1378B6728AFD86 ] cmderd C:\Windows\system32\DRIVERS\cmderd.sys 20:52:00.0789 5064 cmderd - ok 20:52:00.0821 5064 [ 623C7421D76860837CE0643950A117E7 ] cmdGuard C:\Windows\system32\DRIVERS\cmdguard.sys 20:52:01.0008 5064 cmdGuard - ok 20:52:01.0023 5064 [ 5A6ED5F670CD80EC338A94A8A08EC7F1 ] cmdHlp C:\Windows\system32\DRIVERS\cmdhlp.sys 20:52:01.0148 5064 cmdHlp - ok 20:52:01.0179 5064 [ 0CA25E686A4928484E9FDABD168AB629 ] cmdide C:\Windows\system32\drivers\cmdide.sys 20:52:01.0179 5064 cmdide - ok 20:52:01.0195 5064 [ 6AFEF0B60FA25DE07C0968983EE4F60A ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 20:52:01.0195 5064 Compbatt - ok 20:52:01.0211 5064 COMSysApp - ok 20:52:01.0257 5064 [ C508B28B9DA7563634A2A2B2EEF4395D ] ConfigFree Service C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe 20:52:01.0398 5064 ConfigFree Service - ok 20:52:01.0413 5064 [ 741E9DFF4F42D2D8477D0FC1DC0DF871 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 20:52:01.0413 5064 crcdisk - ok 20:52:01.0445 5064 [ 1F07BECDCA750766A96CDA811BA86410 ] Crusoe C:\Windows\system32\drivers\crusoe.sys 20:52:01.0445 5064 Crusoe - ok 20:52:01.0507 5064 [ F1E8C34892336D33EDDCDFE44E474F64 ] CryptSvc C:\Windows\system32\cryptsvc.dll 20:52:01.0507 5064 CryptSvc - ok 20:52:01.0554 5064 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] DcomLaunch C:\Windows\system32\rpcss.dll 20:52:01.0569 5064 DcomLaunch - ok 20:52:01.0585 5064 [ 622C41A07CA7E6DD91770F50D532CB6C ] DfsC C:\Windows\system32\Drivers\dfsc.sys 20:52:01.0741 5064 DfsC - ok 20:52:01.0850 5064 [ 2CC3DCFB533A1035B13DCAB6160AB38B ] DFSR C:\Windows\system32\DFSR.exe 20:52:01.0928 5064 DFSR - ok 20:52:01.0991 5064 [ 9028559C132146FB75EB7ACF384B086A ] Dhcp C:\Windows\System32\dhcpcsvc.dll 20:52:01.0991 5064 Dhcp - ok 20:52:02.0022 5064 [ 5D4AEFC3386920236A548271F8F1AF6A ] disk C:\Windows\system32\drivers\disk.sys 20:52:02.0022 5064 disk - ok 20:52:02.0069 5064 [ 57D762F6F5974AF0DA2BE88A3349BAAA ] Dnscache C:\Windows\System32\dnsrslvr.dll 20:52:02.0209 5064 Dnscache - ok 20:52:02.0256 5064 [ 324FD74686B1EF5E7C19A8AF49E748F6 ] dot3svc C:\Windows\System32\dot3svc.dll 20:52:02.0256 5064 dot3svc - ok 20:52:02.0287 5064 [ A622E888F8AA2F6B49E9BC466F0E5DEF ] DPS C:\Windows\system32\dps.dll 20:52:02.0303 5064 DPS - ok 20:52:02.0349 5064 [ 97FEF831AB90BEE128C9AF390E243F80 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 20:52:02.0349 5064 drmkaud - ok 20:52:02.0396 5064 [ C68AC676B0EF30CFBB1080ADCE49EB1F ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 20:52:02.0396 5064 DXGKrnl - ok 20:52:02.0459 5064 [ 5425F74AC0C1DBD96A1E04F17D63F94C ] E1G60 C:\Windows\system32\DRIVERS\E1G60I32.sys 20:52:02.0459 5064 E1G60 - ok 20:52:02.0490 5064 [ C0B95E40D85CD807D614E264248A45B9 ] EapHost C:\Windows\System32\eapsvc.dll 20:52:02.0490 5064 EapHost - ok 20:52:02.0537 5064 [ 7F64EA048DCFAC7ACF8B4D7B4E6FE371 ] Ecache C:\Windows\system32\drivers\ecache.sys 20:52:02.0537 5064 Ecache - ok 20:52:02.0599 5064 [ 9BE3744D295A7701EB425332014F0797 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 20:52:02.0599 5064 ehRecvr - ok 20:52:02.0630 5064 [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched C:\Windows\ehome\ehsched.exe 20:52:02.0630 5064 ehSched - ok 20:52:02.0646 5064 [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart C:\Windows\ehome\ehstart.dll 20:52:02.0646 5064 ehstart - ok 20:52:02.0708 5064 [ 23B62471681A124889978F6295B3F4C6 ] elxstor C:\Windows\system32\drivers\elxstor.sys 20:52:02.0724 5064 elxstor - ok 20:52:02.0786 5064 [ 4E6B23DFC917EA39306B529B773950F4 ] EMDMgmt C:\Windows\system32\emdmgmt.dll 20:52:02.0817 5064 EMDMgmt - ok 20:52:02.0864 5064 [ 3DB974F3935483555D7148663F726C61 ] ErrDev C:\Windows\system32\drivers\errdev.sys 20:52:02.0864 5064 ErrDev - ok 20:52:02.0958 5064 [ 67058C46504BC12D821F38CF99B7B28F ] EventSystem C:\Windows\system32\es.dll 20:52:02.0958 5064 EventSystem - ok 20:52:03.0020 5064 [ 22B408651F9123527BCEE54B4F6C5CAE ] exfat C:\Windows\system32\drivers\exfat.sys 20:52:03.0020 5064 exfat - ok 20:52:03.0067 5064 [ 1E9B9A70D332103C52995E957DC09EF8 ] fastfat C:\Windows\system32\drivers\fastfat.sys 20:52:03.0083 5064 fastfat - ok 20:52:03.0129 5064 [ AFE1E8B9782A0DD7FB46BBD88E43F89A ] fdc C:\Windows\system32\DRIVERS\fdc.sys 20:52:03.0129 5064 fdc - ok 20:52:03.0176 5064 [ 6629B5F0E98151F4AFDD87567EA32BA3 ] fdPHost C:\Windows\system32\fdPHost.dll 20:52:03.0192 5064 fdPHost - ok 20:52:03.0207 5064 [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub C:\Windows\system32\fdrespub.dll 20:52:03.0207 5064 FDResPub - ok 20:52:03.0223 5064 [ A8C0139A884861E3AAE9CFE73B208A9F ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 20:52:03.0223 5064 FileInfo - ok 20:52:03.0254 5064 [ 0AE429A696AECBC5970E3CF2C62635AE ] Filetrace C:\Windows\system32\drivers\filetrace.sys 20:52:03.0254 5064 Filetrace - ok 20:52:03.0270 5064 [ 85B7CF99D532820495D68D747FDA9EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 20:52:03.0270 5064 flpydisk - ok 20:52:03.0317 5064 [ 01334F9EA68E6877C4EF05D3EA8ABB05 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 20:52:03.0317 5064 FltMgr - ok 20:52:03.0426 5064 [ 8CE364388C8ECA59B14B539179276D44 ] FontCache C:\Windows\system32\FntCache.dll 20:52:03.0426 5064 FontCache - ok 20:52:03.0504 5064 [ C7FBDD1ED42F82BFA35167A5C9803EA3 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 20:52:03.0504 5064 FontCache3.0.0.0 - ok 20:52:03.0535 5064 [ B972A66758577E0BFD1DE0F91AAA27B5 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 20:52:03.0675 5064 Fs_Rec - ok 20:52:03.0738 5064 [ 20DFB4BD5DE8585FDDA02F4C9D00308C ] FTRTSVC C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe 20:52:03.0894 5064 FTRTSVC - ok 20:52:03.0941 5064 [ CBC22823628544735625B280665E434E ] FwLnk C:\Windows\system32\DRIVERS\FwLnk.sys 20:52:04.0097 5064 FwLnk - ok 20:52:04.0128 5064 [ 34582A6E6573D54A07ECE5FE24A126B5 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 20:52:04.0175 5064 gagp30kx - ok 20:52:04.0221 5064 [ 9F5F2F0FB0A7F5AA9F16B9A7B6DAD89F ] GoogleDesktopManager-051210-111108 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe 20:52:04.0221 5064 GoogleDesktopManager-051210-111108 - ok 20:52:04.0268 5064 [ CD5D0AEEE35DFD4E986A5AA1500A6E66 ] gpsvc C:\Windows\System32\gpsvc.dll 20:52:04.0299 5064 gpsvc - ok 20:52:04.0346 5064 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 20:52:04.0362 5064 gupdate - ok 20:52:04.0377 5064 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 20:52:04.0377 5064 gupdatem - ok 20:52:04.0409 5064 [ CC839E8D766CC31A7710C9F38CF3E375 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe 20:52:04.0409 5064 gusvc - ok 20:52:04.0455 5064 [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 20:52:04.0471 5064 HdAudAddService - ok 20:52:04.0533 5064 [ 062452B7FFD68C8C042A6261FE8DFF4A ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 20:52:04.0533 5064 HDAudBus - ok 20:52:04.0549 5064 [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth C:\Windows\system32\drivers\hidbth.sys 20:52:04.0565 5064 HidBth - ok 20:52:04.0580 5064 [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr C:\Windows\system32\drivers\hidir.sys 20:52:04.0580 5064 HidIr - ok 20:52:04.0611 5064 [ 84067081F3318162797385E11A8F0582 ] hidserv C:\Windows\system32\hidserv.dll 20:52:04.0627 5064 hidserv - ok 20:52:04.0674 5064 [ CCA4B519B17E23A00B826C55716809CC ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 20:52:04.0674 5064 HidUsb - ok 20:52:04.0705 5064 [ D8AD255B37DA92434C26E4876DB7D418 ] hkmsvc C:\Windows\system32\kmsvc.dll 20:52:04.0721 5064 hkmsvc - ok 20:52:04.0736 5064 [ 16EE7B23A009E00D835CDB79574A91A6 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 20:52:04.0736 5064 HpCISSs - ok 20:52:04.0767 5064 [ F870AA3E254628EBEAFE754108D664DE ] HTTP C:\Windows\system32\drivers\HTTP.sys 20:52:05.0033 5064 HTTP - ok 20:52:05.0111 5064 [ C6B032D69650985468160FC9937CF5B4 ] i2omp C:\Windows\system32\drivers\i2omp.sys 20:52:05.0111 5064 i2omp - ok 20:52:05.0157 5064 [ 22D56C8184586B7A1F6FA60BE5F5A2BD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 20:52:05.0157 5064 i8042prt - ok 20:52:05.0189 5064 [ 54155EA1B0DF185878E0FC9EC3AC3A14 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 20:52:05.0204 5064 iaStorV - ok 20:52:05.0282 5064 [ DAF66902F08796F9C694901660E5A64A ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe 20:52:05.0485 5064 IDriverT - ok 20:52:05.0563 5064 [ 98477B08E61945F974ED9FDC4CB6BDAB ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 20:52:05.0610 5064 idsvc - ok 20:52:05.0641 5064 [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp C:\Windows\system32\drivers\iirsp.sys 20:52:05.0641 5064 iirsp - ok 20:52:05.0703 5064 [ 9908D8A397B76CD8D31D0D383C5773C9 ] IKEEXT C:\Windows\System32\ikeext.dll 20:52:05.0735 5064 IKEEXT - ok 20:52:05.0766 5064 [ CE3034F551E06F7A290DA4D8DF29246E ] inspect C:\Windows\system32\DRIVERS\inspect.sys 20:52:05.0906 5064 inspect - ok 20:52:05.0984 5064 [ B9CBD3DEA7CA02868621173BF7A2AF9F ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys 20:52:06.0265 5064 IntcAzAudAddService - ok 20:52:06.0281 5064 [ 83AA759F3189E6370C30DE5DC5590718 ] intelide C:\Windows\system32\drivers\intelide.sys 20:52:06.0296 5064 intelide - ok 20:52:06.0327 5064 [ 224191001E78C89DFA78924C3EA595FF ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 20:52:06.0327 5064 intelppm - ok 20:52:06.0359 5064 [ 9AC218C6E6105477484C6FDBE7D409A4 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 20:52:06.0374 5064 IPBusEnum - ok 20:52:06.0390 5064 [ 62C265C38769B864CB25B4BCF62DF6C3 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 20:52:06.0390 5064 IpFilterDriver - ok 20:52:06.0405 5064 IpInIp - ok 20:52:06.0437 5064 [ B25AAF203552B7B3491139D582B39AD1 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 20:52:06.0437 5064 IPMIDRV - ok 20:52:06.0452 5064 [ 8793643A67B42CEC66490B2A0CF92D68 ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 20:52:06.0468 5064 IPNAT - ok 20:52:06.0483 5064 [ 109C0DFB82C3632FBD11949B73AEEAC9 ] IRENUM C:\Windows\system32\drivers\irenum.sys 20:52:06.0483 5064 IRENUM - ok 20:52:06.0499 5064 [ 6C70698A3E5C4376C6AB5C7C17FB0614 ] isapnp C:\Windows\system32\drivers\isapnp.sys 20:52:06.0499 5064 isapnp - ok 20:52:06.0561 5064 [ 232FA340531D940AAC623B121A595034 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 20:52:06.0561 5064 iScsiPrt - ok 20:52:06.0577 5064 [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 20:52:06.0593 5064 iteatapi - ok 20:52:06.0608 5064 [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid C:\Windows\system32\drivers\iteraid.sys 20:52:06.0608 5064 iteraid - ok 20:52:06.0686 5064 [ 723BA0AEC942E91C0A9CE146E73DECEB ] jswpsapi C:\Program Files\Jumpstart\jswpsapi.exe 20:52:06.0951 5064 jswpsapi - ok 20:52:06.0983 5064 [ 7E72514A3A1C5A9F3BFF0660B3866C2B ] jswpslwf C:\Windows\system32\DRIVERS\jswpslwf.sys 20:52:07.0092 5064 jswpslwf - ok 20:52:07.0107 5064 [ 37605E0A8CF00CBBA538E753E4344C6E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 20:52:07.0107 5064 kbdclass - ok 20:52:07.0139 5064 [ 18247836959BA67E3511B62846B9C2E0 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 20:52:07.0139 5064 kbdhid - ok 20:52:07.0154 5064 [ A3E186B4B935905B829219502557314E ] KeyIso C:\Windows\system32\lsass.exe 20:52:07.0154 5064 KeyIso - ok 20:52:07.0185 5064 [ 4A1445EFA932A3BAF5BDB02D7131EE20 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 20:52:07.0217 5064 KSecDD - ok 20:52:07.0263 5064 [ 8078F8F8F7A79E2E6B494523A828C585 ] KtmRm C:\Windows\system32\msdtckrm.dll 20:52:07.0279 5064 KtmRm - ok 20:52:07.0310 5064 [ 1BF5EEBFD518DD7298434D8C862F825D ] LanmanServer C:\Windows\system32\srvsvc.dll 20:52:07.0497 5064 LanmanServer - ok 20:52:07.0529 5064 [ 1DB69705B695B987082C8BAEC0C6B34F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 20:52:07.0544 5064 LanmanWorkstation - ok 20:52:07.0560 5064 Lbd - ok 20:52:07.0591 5064 [ 4127E8B6DDB4090E815C1F8852C277D3 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys 20:52:07.0716 5064 lirsgt - ok 20:52:07.0747 5064 [ D1C5883087A0C3F1344D9D55A44901F6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 20:52:07.0763 5064 lltdio - ok 20:52:07.0794 5064 [ 2D5A428872F1442631D0959A34ABFF63 ] lltdsvc C:\Windows\System32\lltdsvc.dll 20:52:07.0809 5064 lltdsvc - ok 20:52:07.0825 5064 [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts C:\Windows\System32\lmhsvc.dll 20:52:07.0825 5064 lmhosts - ok 20:52:07.0856 5064 [ C7E15E82879BF3235B559563D4185365 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 20:52:07.0856 5064 LSI_FC - ok 20:52:07.0887 5064 [ EE01EBAE8C9BF0FA072E0FF68718920A ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 20:52:07.0887 5064 LSI_SAS - ok 20:52:07.0934 5064 [ 912A04696E9CA30146A62AFA1463DD5C ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 20:52:07.0934 5064 LSI_SCSI - ok 20:52:07.0965 5064 [ 8F5C7426567798E62A3B3614965D62CC ] luafv C:\Windows\system32\drivers\luafv.sys 20:52:07.0965 5064 luafv - ok 20:52:07.0997 5064 [ AEF9BABB8A506BC4CE0451A64AADED46 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 20:52:07.0997 5064 Mcx2Svc - ok 20:52:08.0028 5064 [ 0001CE609D66632FA17B84705F658879 ] megasas C:\Windows\system32\drivers\megasas.sys 20:52:08.0028 5064 megasas - ok 20:52:08.0043 5064 [ C252F32CD9A49DBFC25ECF26EBD51A99 ] MegaSR C:\Windows\system32\drivers\megasr.sys 20:52:08.0075 5064 MegaSR - ok 20:52:08.0106 5064 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] MMCSS C:\Windows\system32\mmcss.dll 20:52:08.0106 5064 MMCSS - ok 20:52:08.0121 5064 [ E13B5EA0F51BA5B1512EC671393D09BA ] Modem C:\Windows\system32\drivers\modem.sys 20:52:08.0121 5064 Modem - ok 20:52:08.0168 5064 [ 0A9BB33B56E294F686ABB7C1E4E2D8A8 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 20:52:08.0168 5064 monitor - ok 20:52:08.0184 5064 [ 5BF6A1326A335C5298477754A506D263 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 20:52:08.0184 5064 mouclass - ok 20:52:08.0199 5064 [ 93B8D4869E12CFBE663915502900876F ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 20:52:08.0199 5064 mouhid - ok 20:52:08.0215 5064 [ BDAFC88AA6B92F7842416EA6A48E1600 ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 20:52:08.0215 5064 MountMgr - ok 20:52:08.0277 5064 [ 5C5E45DDABEFBC9F564F1D5C83258B8F ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 20:52:08.0277 5064 MozillaMaintenance - ok 20:52:08.0306 5064 [ 511D011289755DD9F9A7579FB0B064E6 ] mpio C:\Windows\system32\drivers\mpio.sys 20:52:08.0312 5064 mpio - ok 20:52:08.0344 5064 [ 22241FEBA9B2DEFA669C8CB0A8DD7D2E ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 20:52:08.0348 5064 mpsdrv - ok 20:52:08.0371 5064 [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 20:52:08.0374 5064 Mraid35x - ok 20:52:08.0412 5064 [ 82CEA0395524AACFEB58BA1448E8325C ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 20:52:08.0417 5064 MRxDAV - ok 20:52:08.0457 5064 [ 1E94971C4B446AB2290DEB71D01CF0C2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 20:52:08.0610 5064 mrxsmb - ok 20:52:08.0654 5064 [ 4FCCB34D793B116423209C0F8B7A3B03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 20:52:08.0888 5064 mrxsmb10 - ok 20:52:08.0904 5064 [ C3CB1B40AD4A0124D617A1199B0B9D7C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 20:52:09.0053 5064 mrxsmb20 - ok 20:52:09.0100 5064 [ 5457DCFA7C0DA43522F4D9D4049C1472 ] msahci C:\Windows\system32\drivers\msahci.sys 20:52:09.0102 5064 msahci - ok 20:52:09.0131 5064 [ 4468B0F385A86ECDDAF8D3CA662EC0E7 ] msdsm C:\Windows\system32\drivers\msdsm.sys 20:52:09.0136 5064 msdsm - ok 20:52:09.0162 5064 [ FD7520CC3A80C5FC8C48852BB24C6DED ] MSDTC C:\Windows\System32\msdtc.exe 20:52:09.0170 5064 MSDTC - ok 20:52:09.0199 5064 [ A9927F4A46B816C92F461ACB90CF8515 ] Msfs C:\Windows\system32\drivers\Msfs.sys 20:52:09.0202 5064 Msfs - ok 20:52:09.0253 5064 [ 0F400E306F385C56317357D6DEA56F62 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 20:52:09.0256 5064 msisadrv - ok 20:52:09.0290 5064 [ 85466C0757A23D9A9AECDC0755203CB2 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 20:52:09.0301 5064 MSiSCSI - ok 20:52:09.0312 5064 msiserver - ok 20:52:09.0349 5064 [ D8C63D34D9C9E56C059E24EC7185CC07 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 20:52:09.0352 5064 MSKSSRV - ok 20:52:09.0383 5064 [ 1D373C90D62DDB641D50E55B9E78D65E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 20:52:09.0385 5064 MSPCLOCK - ok 20:52:09.0429 5064 [ B572DA05BF4E098D4BBA3A4734FB505B ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 20:52:09.0431 5064 MSPQM - ok 20:52:09.0473 5064 [ B49456D70555DE905C311BCDA6EC6ADB ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 20:52:09.0484 5064 MsRPC - ok 20:52:09.0507 5064 [ E384487CB84BE41D09711C30CA79646C ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 20:52:09.0508 5064 mssmbios - ok 20:52:09.0542 5064 [ 7199C1EEC1E4993CAF96B8C0A26BD58A ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 20:52:09.0545 5064 MSTEE - ok 20:52:09.0569 5064 [ 6A57B5733D4CB702C8EA4542E836B96C ] Mup C:\Windows\system32\Drivers\mup.sys 20:52:09.0575 5064 Mup - ok 20:52:09.0884 5064 [ E4EAF0C5C1B41B5C83386CF212CA9584 ] napagent C:\Windows\system32\qagentRT.dll 20:52:09.0889 5064 napagent - ok 20:52:10.0059 5064 [ 85C44FDFF9CF7E72A40DCB7EC06A4416 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 20:52:10.0091 5064 NativeWifiP - ok 20:52:10.0151 5064 [ 1357274D1883F68300AEADD15D7BBB42 ] NDIS C:\Windows\system32\drivers\ndis.sys 20:52:10.0156 5064 NDIS - ok 20:52:10.0195 5064 [ 0E186E90404980569FB449BA7519AE61 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 20:52:10.0197 5064 NdisTapi - ok 20:52:10.0208 5064 [ D6973AA34C4D5D76C0430B181C3CD389 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 20:52:10.0212 5064 Ndisuio - ok 20:52:10.0288 5064 [ 818F648618AE34F729FDB47EC68345C3 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 20:52:10.0294 5064 NdisWan - ok 20:52:10.0342 5064 [ 71DAB552B41936358F3B541AE5997FB3 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 20:52:10.0345 5064 NDProxy - ok 20:52:10.0380 5064 [ BCD093A5A6777CF626434568DC7DBA78 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 20:52:10.0383 5064 NetBIOS - ok 20:52:10.0452 5064 [ ECD64230A59CBD93C85F1CD1CAB9F3F6 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 20:52:10.0461 5064 netbt - ok 20:52:10.0507 5064 [ A3E186B4B935905B829219502557314E ] Netlogon C:\Windows\system32\lsass.exe 20:52:10.0509 5064 Netlogon - ok 20:52:10.0657 5064 [ C8052711DAECC48B982434C5116CA401 ] Netman C:\Windows\System32\netman.dll 20:52:10.0681 5064 Netman - ok 20:52:10.0741 5064 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] netprofm C:\Windows\System32\netprofm.dll 20:52:10.0758 5064 netprofm - ok 20:52:10.0817 5064 [ D6C4E4A39A36029AC0813D476FBD0248 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 20:52:10.0824 5064 NetTcpPortSharing - ok 20:52:10.0873 5064 [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 20:52:10.0877 5064 nfrd960 - ok 20:52:10.0906 5064 [ 2997B15415F9BBE05B5A4C1C85E0C6A2 ] NlaSvc C:\Windows\System32\nlasvc.dll 20:52:10.0911 5064 NlaSvc - ok 20:52:10.0964 5064 [ D36F239D7CCE1931598E8FB90A0DBC26 ] Npfs C:\Windows\system32\drivers\Npfs.sys 20:52:10.0967 5064 Npfs - ok 20:52:10.0985 5064 [ 8BB86F0C7EEA2BDED6FE095D0B4CA9BD ] nsi C:\Windows\system32\nsisvc.dll 20:52:10.0989 5064 nsi - ok 20:52:11.0029 5064 [ 609773E344A97410CE4EBF74A8914FCF ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 20:52:11.0031 5064 nsiproxy - ok 20:52:11.0113 5064 [ 6A4A98CEE84CF9E99564510DDA4BAA47 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 20:52:11.0159 5064 Ntfs - ok 20:52:11.0183 5064 [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi C:\Windows\system32\drivers\ntrigdigi.sys 20:52:11.0185 5064 ntrigdigi - ok 20:52:11.0205 5064 [ C5DBBCDA07D780BDA9B685DF333BB41E ] Null C:\Windows\system32\drivers\Null.sys 20:52:11.0208 5064 Null - ok 20:52:11.0238 5064 [ 2EDF9E7751554B42CBB60116DE727101 ] nvraid C:\Windows\system32\drivers\nvraid.sys 20:52:11.0244 5064 nvraid - ok 20:52:11.0268 5064 [ ABED0C09758D1D97DB0042DBB2688177 ] nvstor C:\Windows\system32\drivers\nvstor.sys 20:52:11.0271 5064 nvstor - ok 20:52:11.0297 5064 [ 18BBDF913916B71BD54575BDB6EEAC0B ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 20:52:11.0302 5064 nv_agp - ok 20:52:11.0330 5064 NwlnkFlt - ok 20:52:11.0338 5064 NwlnkFwd - ok 20:52:11.0391 5064 [ 6F310E890D46E246E0E261A63D9B36B4 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 20:52:11.0393 5064 ohci1394 - ok 20:52:11.0517 5064 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 20:52:11.0524 5064 ose - ok 20:52:11.0614 5064 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2pimsvc C:\Windows\system32\p2psvc.dll 20:52:11.0646 5064 p2pimsvc - ok 20:52:11.0664 5064 [ 0C8E8E61AD1EB0B250B846712C917506 ] p2psvc C:\Windows\system32\p2psvc.dll 20:52:11.0672 5064 p2psvc - ok 20:52:11.0707 5064 [ 0FA9B5055484649D63C303FE404E5F4D ] Parport C:\Windows\system32\drivers\parport.sys 20:52:11.0712 5064 Parport - ok 20:52:11.0754 5064 [ B9C2B89F08670E159F7181891E449CD9 ] partmgr C:\Windows\system32\drivers\partmgr.sys 20:52:11.0758 5064 partmgr - ok 20:52:11.0782 5064 [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm C:\Windows\system32\drivers\parvdm.sys 20:52:11.0784 5064 Parvdm - ok 20:52:11.0825 5064 [ 1BF91F352D746AD7469FA71783B5FAE8 ] PCAMp50 C:\Windows\system32\Drivers\PCAMp50.sys 20:52:11.0828 5064 PCAMp50 - ok 20:52:11.0846 5064 [ 1961590AA191B6B7DCF18A6A693AF7B8 ] PCASp50 C:\Windows\system32\Drivers\PCASp50.sys 20:52:11.0848 5064 PCASp50 - ok 20:52:11.0885 5064 [ C6276AD11F4BB49B58AA1ED88537F14A ] PcaSvc C:\Windows\System32\pcasvc.dll 20:52:11.0891 5064 PcaSvc - ok 20:52:11.0937 5064 [ 941DC1D19E7E8620F40BBC206981EFDB ] pci C:\Windows\system32\drivers\pci.sys 20:52:11.0944 5064 pci - ok 20:52:11.0966 5064 [ 1636D43F10416AEB483BC6001097B26C ] pciide C:\Windows\system32\drivers\pciide.sys 20:52:11.0969 5064 pciide - ok 20:52:11.0994 5064 [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 20:52:12.0002 5064 pcmcia - ok 20:52:12.0053 5064 [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 20:52:12.0087 5064 PEAUTH - ok 20:52:12.0179 5064 [ B1689DF169143F57053F795390C99DB3 ] pla C:\Windows\system32\pla.dll 20:52:12.0283 5064 pla - ok 20:52:12.0337 5064 [ C5E7F8A996EC0A82D508FD9064A5569E ] PlugPlay C:\Windows\system32\umpnpmgr.dll 20:52:12.0361 5064 PlugPlay - ok 20:52:12.0403 5064 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 20:52:12.0411 5064 PNRPAutoReg - ok 20:52:12.0458 5064 [ 0C8E8E61AD1EB0B250B846712C917506 ] PNRPsvc C:\Windows\system32\p2psvc.dll 20:52:12.0466 5064 PNRPsvc - ok 20:52:12.0565 5064 [ D0494460421A03CD5225CCA0059AA146 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 20:52:12.0598 5064 PolicyAgent - ok 20:52:12.0677 5064 [ ECFFFAEC0C1ECD8DBC77F39070EA1DB1 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 20:52:12.0701 5064 PptpMiniport - ok 20:52:12.0755 5064 [ 2027293619DD0F047C584CF2E7DF4FFD ] Processor C:\Windows\system32\DRIVERS\processr.sys 20:52:12.0756 5064 Processor - ok 20:52:12.0936 5064 [ 0508FAA222D28835310B7BFCA7A77346 ] ProfSvc C:\Windows\system32\profsvc.dll 20:52:12.0976 5064 ProfSvc - ok 20:52:13.0008 5064 [ A3E186B4B935905B829219502557314E ] ProtectedStorage C:\Windows\system32\lsass.exe 20:52:13.0011 5064 ProtectedStorage - ok 20:52:13.0113 5064 [ 99514FAA8DF93D34B5589187DB3AA0BA ] PSched C:\Windows\system32\DRIVERS\pacer.sys 20:52:13.0132 5064 PSched - ok 20:52:13.0161 5064 [ 49452BFCEC22F36A7A9B9C2181BC3042 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys 20:52:13.0165 5064 PxHelp20 - ok 20:52:13.0266 5064 [ 0A6DB55AFB7820C99AA1F3A1D270F4F6 ] ql2300 C:\Windows\system32\drivers\ql2300.sys 20:52:13.0315 5064 ql2300 - ok 20:52:13.0354 5064 [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 20:52:13.0360 5064 ql40xx - ok 20:52:13.0406 5064 [ E9ECAE663F47E6CB43962D18AB18890F ] QWAVE C:\Windows\system32\qwave.dll 20:52:13.0418 5064 QWAVE - ok 20:52:13.0447 5064 [ 9F5E0E1926014D17486901C88ECA2DB7 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 20:52:13.0450 5064 QWAVEdrv - ok 20:52:13.0499 5064 [ 147D7F9C556D259924351FEB0DE606C3 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 20:52:13.0501 5064 RasAcd - ok 20:52:13.0551 5064 [ F6A452EB4CEADBB51C9E0EE6B3ECEF0F ] RasAuto C:\Windows\System32\rasauto.dll 20:52:13.0558 5064 RasAuto - ok 20:52:13.0593 5064 [ A214ADBAF4CB47DD2728859EF31F26B0 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 20:52:13.0598 5064 Rasl2tp - ok 20:52:13.0648 5064 [ 75D47445D70CA6F9F894B032FBC64FCF ] RasMan C:\Windows\System32\rasmans.dll 20:52:13.0672 5064 RasMan - ok 20:52:13.0707 5064 [ 509A98DD18AF4375E1FC40BC175F1DEF ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 20:52:13.0711 5064 RasPppoe - ok 20:52:13.0743 5064 [ 2005F4A1E05FA09389AC85840F0A9E4D ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 20:52:13.0753 5064 RasSstp - ok 20:52:13.0797 5064 [ B14C9D5B9ADD2F84F70570BBBFAA7935 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 20:52:13.0808 5064 rdbss - ok 20:52:13.0863 5064 [ 89E59BE9A564262A3FB6C4F4F1CD9899 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 20:52:13.0866 5064 RDPCDD - ok 20:52:13.0914 5064 [ FBC0BACD9C3D7F6956853F64A66E252D ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 20:52:13.0924 5064 rdpdr - ok 20:52:13.0938 5064 [ 9D91FE5286F748862ECFFA05F8A0710C ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 20:52:13.0940 5064 RDPENCDD - ok 20:52:13.0988 5064 [ C127EBD5AFAB31524662C48DFCEB773A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 20:52:14.0155 5064 RDPWD - ok 20:52:14.0216 5064 [ BCDD6B4804D06B1F7EBF29E53A57ECE9 ] RemoteAccess C:\Windows\System32\mprdim.dll 20:52:14.0223 5064 RemoteAccess - ok 20:52:14.0301 5064 [ 9E6894EA18DAFF37B63E1005F83AE4AB ] RemoteRegistry C:\Windows\system32\regsvc.dll 20:52:14.0308 5064 RemoteRegistry - ok 20:52:14.0365 5064 [ 34CC78C06587718C2AD6D3AA83B1F072 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys 20:52:14.0369 5064 RFCOMM - ok 20:52:14.0432 5064 [ C2EF513BBE069F0D4EE0938A76F975D3 ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys 20:52:14.0436 5064 rimmptsk - ok 20:52:14.0449 5064 [ C398BCA91216755B098679A8DA8A2300 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys 20:52:14.0453 5064 rimsptsk - ok 20:52:14.0530 5064 [ 4F4A4C09CC5BE58A76CAC1C337E004E6 ] RimUsb C:\Windows\system32\Drivers\RimUsb.sys 20:52:14.0769 5064 RimUsb - ok 20:52:14.0830 5064 [ 3A5633AD615E2B15291BD0B1B97CCD8A ] RimVSerPort C:\Windows\system32\DRIVERS\RimSerial.sys 20:52:14.0965 5064 RimVSerPort - ok 20:52:15.0063 5064 [ 2A2554CB24506E0A0508FC395C4A1B42 ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys 20:52:15.0067 5064 rismxdp - ok 20:52:15.0139 5064 [ 75E8A6BFA7374ABA833AE92BF41AE4E6 ] ROOTMODEM C:\Windows\system32\Drivers\RootMdm.sys 20:52:15.0141 5064 ROOTMODEM - ok 20:52:15.0221 5064 [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator C:\Windows\system32\locator.exe 20:52:15.0224 5064 RpcLocator - ok 20:52:15.0274 5064 [ 3B5B4D53FEC14F7476CA29A20CC31AC9 ] RpcSs C:\Windows\system32\rpcss.dll 20:52:15.0282 5064 RpcSs - ok 20:52:15.0316 5064 [ 9C508F4074A39E8B4B31D27198146FAD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 20:52:15.0320 5064 rspndr - ok 20:52:15.0374 5064 [ C853AE16CCF5033C0CBA0855390F5C7F ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIV.sys 20:52:15.0516 5064 RTHDMIAzAudService - ok 20:52:15.0567 5064 [ 7157E70A90CCE49DEB8885D23A073A39 ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh86.sys 20:52:15.0711 5064 RTL8169 - ok 20:52:15.0754 5064 [ A3E186B4B935905B829219502557314E ] SamSs C:\Windows\system32\lsass.exe 20:52:15.0757 5064 SamSs - ok 20:52:17.0323 5064 SASDIFSV - ok 20:52:18.0468 5064 SASKUTIL - ok 20:52:18.0963 5064 [ 3CE8F073A557E172B330109436984E30 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 20:52:18.0968 5064 sbp2port - ok 20:52:19.0182 5064 [ 77B7A11A0C3D78D3386398FBBEA1B632 ] SCardSvr C:\Windows\System32\SCardSvr.dll 20:52:19.0190 5064 SCardSvr - ok 20:52:19.0265 5064 [ 1A58069DB21D05EB2AB58EE5753EBE8D ] Schedule C:\Windows\system32\schedsvc.dll 20:52:19.0464 5064 Schedule - ok 20:52:19.0510 5064 [ 312EC3E37A0A1F2006534913E37B4423 ] SCPolicySvc C:\Windows\System32\certprop.dll 20:52:19.0511 5064 SCPolicySvc - ok 20:52:19.0550 5064 [ 8F36B54688C31EED4580129040C6A3D3 ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys 20:52:19.0555 5064 sdbus - ok 20:52:19.0580 5064 [ 716313D9F6B0529D03F726D5AAF6F191 ] SDRSVC C:\Windows\System32\SDRSVC.dll 20:52:19.0588 5064 SDRSVC - ok 20:52:19.0612 5064 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 20:52:19.0614 5064 secdrv - ok 20:52:19.0626 5064 [ FD5199D4D8A521005E4B5EE7FE00FA9B ] seclogon C:\Windows\system32\seclogon.dll 20:52:19.0631 5064 seclogon - ok 20:52:19.0660 5064 [ A9BBAB5759771E523F55563D6CBE140F ] SENS C:\Windows\System32\sens.dll 20:52:19.0664 5064 SENS - ok 20:52:19.0694 5064 [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum C:\Windows\system32\drivers\serenum.sys 20:52:19.0696 5064 Serenum - ok 20:52:19.0715 5064 [ C70D69A918B178D3C3B06339B40C2E1B ] Serial C:\Windows\system32\drivers\serial.sys 20:52:19.0720 5064 Serial - ok 20:52:19.0759 5064 [ 8AF3D28A879BF75DB53A0EE7A4289624 ] sermouse C:\Windows\system32\drivers\sermouse.sys 20:52:19.0762 5064 sermouse - ok 20:52:19.0913 5064 [ 78546CD2ECA6DD6BDCD4B13048621F88 ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe 20:52:19.0933 5064 ServiceLayer - ok 20:52:19.0999 5064 [ D2193326F729B163125610DBF3E17D57 ] SessionEnv C:\Windows\system32\sessenv.dll 20:52:20.0006 5064 SessionEnv - ok 20:52:20.0035 5064 [ 3EFA810BDCA87F6ECC24F9832243FE86 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys 20:52:20.0038 5064 sffdisk - ok 20:52:20.0069 5064 [ E95D451F7EA3E583AEC75F3B3EE42DC5 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 20:52:20.0071 5064 sffp_mmc - ok 20:52:20.0129 5064 [ 9F66A46C55D6F1CCABC79BB7AFCCC545 ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys 20:52:20.0132 5064 sffp_sd - ok 20:52:20.0148 5064 [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 20:52:20.0151 5064 sfloppy - ok 20:52:20.0239 5064 [ C7230FBEE14437716701C15BE02C27B8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 20:52:20.0402 5064 ShellHWDetection - ok 20:52:20.0450 5064 [ 1D76624A09A054F682D746B924E2DBC3 ] sisagp C:\Windows\system32\drivers\sisagp.sys 20:52:20.0465 5064 sisagp - ok 20:52:20.0572 5064 [ 43CB7AA756C7DB280D01DA9B676CFDE2 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 20:52:20.0578 5064 SiSRaid2 - ok 20:52:20.0622 5064 [ A99C6C8B0BAA970D8AA59DDC50B57F94 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 20:52:20.0630 5064 SiSRaid4 - ok 20:52:20.0718 5064 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe 20:52:20.0726 5064 SkypeUpdate - ok 20:52:21.0345 5064 [ 862BB4CBC05D80C5B45BE430E5EF872F ] slsvc C:\Windows\system32\SLsvc.exe 20:52:21.0436 5064 slsvc - ok 20:52:21.0533 5064 [ 6EDC422215CD78AA8A9CDE6B30ABBD35 ] SLUINotify C:\Windows\system32\SLUINotify.dll 20:52:21.0541 5064 SLUINotify - ok 20:52:21.0605 5064 [ 3566310DF25EA5C3B2E9F50F5B50EAC1 ] SmartFaceVWatchSrv C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe 20:52:21.0802 5064 SmartFaceVWatchSrv - ok 20:52:21.0914 5064 [ 7B75299A4D201D6A6533603D6914AB04 ] Smb C:\Windows\system32\DRIVERS\smb.sys 20:52:21.0919 5064 Smb - ok 20:52:21.0993 5064 [ C8A58FC905C9184FA70E37F71060C64D ] smserial C:\Windows\system32\DRIVERS\smserial.sys 20:52:22.0039 5064 smserial - ok 20:52:22.0081 5064 [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 20:52:22.0086 5064 SNMPTRAP - ok 20:52:22.0122 5064 [ 7AEBDEEF071FE28B0EEF2CDD69102BFF ] spldr C:\Windows\system32\drivers\spldr.sys 20:52:22.0125 5064 spldr - ok 20:52:22.0156 5064 [ 8554097E5136C3BF9F69FE578A1B35F4 ] Spooler C:\Windows\System32\spoolsv.exe 20:52:22.0344 5064 Spooler - ok 20:52:22.0485 5064 [ D15DA1BA189770D93EEA2D7E18F95AF9 ] sptd C:\Windows\system32\Drivers\sptd.sys 20:52:22.0486 5064 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: D15DA1BA189770D93EEA2D7E18F95AF9 20:52:22.0497 5064 sptd ( LockedFile.Multi.Generic ) - warning 20:52:22.0497 5064 sptd - detected LockedFile.Multi.Generic (1) 20:52:22.0547 5064 [ 41987F9FC0E61ADF54F581E15029AD91 ] srv C:\Windows\system32\DRIVERS\srv.sys 20:52:22.0757 5064 srv - ok 20:52:22.0801 5064 [ FF33AFF99564B1AA534F58868CBE41EF ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 20:52:23.0018 5064 srv2 - ok 20:52:23.0183 5064 [ 7605C0E1D01A08F3ECD743F38B834A44 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 20:52:23.0334 5064 srvnet - ok 20:52:23.0568 5064 [ 03D50B37234967433A5EA5BA72BC0B62 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 20:52:23.0582 5064 SSDPSRV - ok 20:52:23.0613 5064 [ 6F1A32E7B7B30F004D9A20AFADB14944 ] SstpSvc C:\Windows\system32\sstpsvc.dll 20:52:23.0622 5064 SstpSvc - ok 20:52:23.0677 5064 [ C9FA6A70C051FC59D22C2E4CD211AD9B ] ST330 C:\Windows\system32\drivers\st330.sys 20:52:23.0812 5064 ST330 - ok 20:52:23.0877 5064 StarOpen - ok 20:52:23.0914 5064 [ 0017202EB0224F82706F04ED35AB23C2 ] STBUS C:\Windows\system32\drivers\stbus.sys 20:52:24.0065 5064 STBUS - ok 20:52:24.0147 5064 [ FC2F19D742F84D2CFF728F20529CBB30 ] STETH C:\Windows\system32\DRIVERS\steth.sys 20:52:24.0295 5064 STETH - ok 20:52:24.0668 5064 [ 5DE7D67E49B88F5F07F3E53C4B92A352 ] stisvc C:\Windows\System32\wiaservc.dll 20:52:24.0749 5064 stisvc - ok 20:52:24.0807 5064 [ 0A9484E3CDAFB529B392B5E9EBBC4AA6 ] stppp C:\Windows\system32\DRIVERS\stppp.sys 20:52:24.0939 5064 stppp - ok 20:52:25.0133 5064 [ 7BA58ECF0C0A9A69D44B3DCA62BECF56 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 20:52:25.0135 5064 swenum - ok 20:52:25.0214 5064 [ F21FD248040681CCA1FB6C9A03AAA93D ] swprv C:\Windows\System32\swprv.dll 20:52:25.0239 5064 swprv - ok 20:52:25.0275 5064 [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 20:52:25.0279 5064 Symc8xx - ok 20:52:25.0314 5064 [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 20:52:25.0317 5064 Sym_hi - ok 20:52:25.0381 5064 [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 20:52:25.0385 5064 Sym_u3 - ok 20:52:25.0440 5064 [ 55F6E55CC2430CA8713387106FA79817 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 20:52:26.0010 5064 SynTP - ok 20:52:26.0640 5064 [ 9A51B04E9886AA4EE90093586B0BA88D ] SysMain C:\Windows\system32\sysmain.dll 20:52:26.0671 5064 SysMain - ok 20:52:26.0719 5064 [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll 20:52:26.0727 5064 TabletInputService - ok 20:52:27.0067 5064 [ D7673E4B38CE21EE54C59EEEB65E2483 ] TapiSrv C:\Windows\System32\tapisrv.dll 20:52:27.0082 5064 TapiSrv - ok 20:52:27.0123 5064 [ CB05822CD9CC6C688168E113C603DBE7 ] TBS C:\Windows\System32\tbssvc.dll 20:52:27.0128 5064 TBS - ok 20:52:27.0228 5064 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 20:52:27.0475 5064 Tcpip - ok 20:52:27.0520 5064 [ 74E2D020C47BB2B2FCCBA29A518A7EB4 ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 20:52:27.0529 5064 Tcpip6 - ok 20:52:27.0605 5064 [ 608C345A255D82A6289C2D468EB41FD7 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 20:52:27.0761 5064 tcpipreg - ok 20:52:27.0802 5064 [ 6FDFBA25002CE4BAC463AC866AE71405 ] tdcmdpst C:\Windows\system32\DRIVERS\tdcmdpst.sys 20:52:27.0947 5064 tdcmdpst - ok 20:52:28.0031 5064 [ 5DCF5E267BE67A1AE926F2DF77FBCC56 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 20:52:28.0033 5064 TDPIPE - ok 20:52:28.0088 5064 [ 389C63E32B3CEFED425B61ED92D3F021 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 20:52:28.0091 5064 TDTCP - ok 20:52:28.0125 5064 [ 76B06EB8A01FC8624D699E7045303E54 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 20:52:28.0131 5064 tdx - ok 20:52:28.0203 5064 [ E538F89E4C64C71F79CB3976DE3C0E8B ] TemproMonitoringService C:\Program Files\Toshiba TEMPRO\TemproSvc.exe 20:52:28.0205 5064 TemproMonitoringService - ok 20:52:28.0255 5064 [ 3CAD38910468EAB9A6479E2F01DB43C7 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 20:52:28.0259 5064 TermDD - ok 20:52:28.0332 5064 [ BB95DA09BEF6E7A131BFF3BA5032090D ] TermService C:\Windows\System32\termsrv.dll 20:52:28.0362 5064 TermService - ok 20:52:28.0409 5064 [ C7230FBEE14437716701C15BE02C27B8 ] Themes C:\Windows\system32\shsvcs.dll 20:52:28.0418 5064 Themes - ok 20:52:28.0471 5064 [ 1076FFCFFAAE8385FD62DFCB25AC4708 ] THREADORDER C:\Windows\system32\mmcss.dll 20:52:28.0475 5064 THREADORDER - ok 20:52:28.0539 5064 [ 73660755FA75F8144F7E55B168EBD549 ] TNaviSrv C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe 20:52:28.0717 5064 TNaviSrv - ok 20:52:28.0801 5064 [ C5AC715B65B01788ABC22D10749DDDD8 ] TODDSrv C:\Windows\system32\TODDSrv.exe 20:52:28.0960 5064 TODDSrv - ok 20:52:29.0057 5064 [ DA6903958CBDC091FFCBBCA70CCFF34C ] TosCoSrv C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe 20:52:29.0247 5064 TosCoSrv - ok 20:52:29.0311 5064 [ 8E10E654E354CF330ED75882769A0107 ] TOSHIBA Bluetooth Service c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 20:52:29.0480 5064 TOSHIBA Bluetooth Service - ok 20:52:29.0538 5064 [ 22690DFFC7F2A18279A7A0489AA02BAC ] TOSHIBA SMART Log Service C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe 20:52:29.0550 5064 TOSHIBA SMART Log Service - ok 20:52:29.0637 5064 [ 2C15B4856F929AC7DD144044D8334B54 ] tosporte C:\Windows\system32\DRIVERS\tosporte.sys 20:52:29.0640 5064 tosporte - ok 20:52:29.0678 5064 [ CD6E9C27ADC6B37B0B3DF29CC83E15A7 ] tosrfbd C:\Windows\system32\DRIVERS\tosrfbd.sys 20:52:29.0822 5064 tosrfbd - ok 20:52:29.0866 5064 [ 181E217A7A326817D97946D045B3CB46 ] tosrfbnp C:\Windows\system32\Drivers\tosrfbnp.sys 20:52:29.0870 5064 tosrfbnp - ok 20:52:29.0927 5064 [ BC5B7356AB588993D9D94EC4B7DA6A17 ] Tosrfcom C:\Windows\system32\Drivers\tosrfcom.sys 20:52:29.0931 5064 Suspicious file (Forged): C:\Windows\system32\Drivers\tosrfcom.sys. Real md5: BC5B7356AB588993D9D94EC4B7DA6A17, Fake md5: E90ACE3B4FA7A85F992BC21EB779C407 20:52:29.0931 5064 Tosrfcom ( Virus.Win32.ZAccess.aml ) - infected 20:52:29.0931 5064 Tosrfcom - detected Virus.Win32.ZAccess.aml (0) 20:52:29.0972 5064 [ 5C4103544612E5011EF46301B93D1AA6 ] tosrfec C:\Windows\system32\DRIVERS\tosrfec.sys 20:52:29.0975 5064 tosrfec - ok 20:52:30.0001 5064 [ D3F87C46C7C9E5DB99FBD3D17121B891 ] Tosrfhid C:\Windows\system32\DRIVERS\Tosrfhid.sys 20:52:30.0141 5064 Tosrfhid - ok 20:52:30.0204 5064 [ C52FD27B9ADF3A1F22CB90E6BCF9B0CB ] tosrfnds C:\Windows\system32\DRIVERS\tosrfnds.sys 20:52:30.0206 5064 tosrfnds - ok 20:52:30.0254 5064 [ 156D63F6898E4D95F2962F2B72862868 ] TosRfSnd C:\Windows\system32\drivers\tosrfsnd.sys 20:52:30.0257 5064 TosRfSnd - ok 20:52:30.0299 5064 [ 98C04A6432CE9C2AD328F57B9384D348 ] Tosrfusb C:\Windows\system32\DRIVERS\tosrfusb.sys 20:52:30.0302 5064 Tosrfusb - ok 20:52:30.0370 5064 [ 4399A9BF7D8F49991A07FD86590A1619 ] tos_sps32 C:\Windows\system32\DRIVERS\tos_sps32.sys 20:52:30.0551 5064 tos_sps32 - ok 20:52:30.0612 5064 [ EC74E77D0EB004BD3A809B5F8FB8C2CE ] TrkWks C:\Windows\System32\trkwks.dll 20:52:30.0620 5064 TrkWks - ok 20:52:30.0711 5064 [ 97D9D6A04E3AD9B6C626B9931DB78DBA ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 20:52:30.0714 5064 TrustedInstaller - ok 20:52:30.0767 5064 [ DCF0F056A2E4F52287264F5AB29CF206 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 20:52:30.0769 5064 tssecsrv - ok 20:52:30.0810 5064 [ CAECC0120AC49E3D2F758B9169872D38 ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 20:52:30.0813 5064 tunmp - ok 20:52:30.0860 5064 [ 300DB877AC094FEAB0BE7688C3454A9C ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 20:52:31.0017 5064 tunnel - ok 20:52:31.0061 5064 [ 792A8B80F8188ABA4B2BE271583F3E46 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS 20:52:31.0064 5064 TVALZ - ok 20:52:31.0098 5064 [ 7D33C4DB2CE363C8518D2DFCF533941F ] uagp35 C:\Windows\system32\drivers\uagp35.sys 20:52:31.0105 5064 uagp35 - ok 20:52:31.0159 5064 [ D9728AF68C4C7693CB100B8441CBDEC6 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 20:52:31.0184 5064 udfs - ok 20:52:31.0253 5064 [ ECEF404F62863755951E09C802C94AD5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 20:52:31.0259 5064 UI0Detect - ok 20:52:31.0349 5064 [ 332D341D92B933600D41953B08360DFB ] UleadBurningHelper C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe 20:52:31.0359 5064 UleadBurningHelper - ok 20:52:31.0413 5064 [ B0ACFDC9E4AF279E9116C03E014B2B27 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 20:52:31.0417 5064 uliagpkx - ok 20:52:31.0464 5064 [ 9224BB254F591DE4CA8D572A5F0D635C ] uliahci C:\Windows\system32\drivers\uliahci.sys 20:52:31.0474 5064 uliahci - ok 20:52:31.0525 5064 [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata C:\Windows\system32\drivers\ulsata.sys 20:52:31.0531 5064 UlSata - ok 20:52:31.0577 5064 [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 20:52:31.0583 5064 ulsata2 - ok 20:52:31.0619 5064 [ 32CFF9F809AE9AED85464492BF3E32D2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 20:52:31.0624 5064 umbus - ok 20:52:31.0677 5064 [ 68308183F4AE0BE7BF8ECD07CB297999 ] upnphost C:\Windows\System32\upnphost.dll 20:52:31.0690 5064 upnphost - ok 20:52:31.0715 5064 upperdev - ok 20:52:31.0752 5064 [ CAF811AE4C147FFCD5B51750C7F09142 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 20:52:31.0757 5064 usbccgp - ok 20:52:31.0803 5064 [ E9476E6C486E76BC4898074768FB7131 ] usbcir C:\Windows\system32\drivers\usbcir.sys 20:52:31.0807 5064 usbcir - ok 20:52:31.0868 5064 [ 79E96C23A97CE7B8F14D310DA2DB0C9B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 20:52:31.0871 5064 usbehci - ok 20:52:31.0922 5064 [ 4673BBCB006AF60E7ABDDBE7A130BA42 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 20:52:31.0930 5064 usbhub - ok 20:52:32.0004 5064 [ CE697FEE0D479290D89BEC80DFE793B7 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys 20:52:32.0007 5064 usbohci - ok 20:52:32.0041 5064 [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint C:\Windows\system32\drivers\usbprint.sys 20:52:32.0044 5064 usbprint - ok 20:52:32.0108 5064 [ BE3DA31C191BC222D9AD503C5224F2AD ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 20:52:32.0112 5064 USBSTOR - ok 20:52:32.0158 5064 [ 814D653EFC4D48BE3B04A307ECEFF56F ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 20:52:32.0160 5064 usbuhci - ok 20:52:32.0207 5064 [ E67998E8F14CB0627A769F6530BCB352 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 20:52:32.0214 5064 usbvideo - ok 20:52:32.0272 5064 [ 237C444FBD1C697A2E3FA60F02C61F22 ] UVCFTR C:\Windows\system32\Drivers\UVCFTR_S.SYS 20:52:32.0428 5064 UVCFTR - ok 20:52:32.0483 5064 [ 1509E705F3AC1D474C92454A5C2DD81F ] UxSms C:\Windows\System32\uxsms.dll 20:52:32.0490 5064 UxSms - ok 20:52:32.0545 5064 [ CD88D1B7776DC17A119049742EC07EB4 ] vds C:\Windows\System32\vds.exe 20:52:32.0575 5064 vds - ok 20:52:32.0629 5064 [ 87B06E1F30B749A114F74622D013F8D4 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 20:52:32.0632 5064 vga - ok 20:52:32.0668 5064 [ 2E93AC0A1D8C79D019DB6C51F036636C ] VgaSave C:\Windows\System32\drivers\vga.sys 20:52:32.0671 5064 VgaSave - ok 20:52:32.0721 5064 [ 5D7159DEF58A800D5781BA3A879627BC ] viaagp C:\Windows\system32\drivers\viaagp.sys 20:52:32.0725 5064 viaagp - ok 20:52:32.0757 5064 [ C4F3A691B5BAD343E6249BD8C2D45DEE ] ViaC7 C:\Windows\system32\drivers\viac7.sys 20:52:32.0761 5064 ViaC7 - ok 20:52:32.0808 5064 [ AADF5587A4063F52C2C3FED7887426FC ] viaide C:\Windows\system32\drivers\viaide.sys 20:52:32.0811 5064 viaide - ok 20:52:32.0864 5064 [ 69503668AC66C77C6CD7AF86FBDF8C43 ] volmgr C:\Windows\system32\drivers\volmgr.sys 20:52:32.0868 5064 volmgr - ok 20:52:32.0925 5064 [ 23E41B834759917BFD6B9A0D625D0C28 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 20:52:32.0937 5064 volmgrx - ok 20:52:33.0019 5064 [ 786DB5771F05EF300390399F626BF30A ] volsnap C:\Windows\system32\drivers\volsnap.sys 20:52:33.0235 5064 volsnap - ok 20:52:33.0338 5064 [ 587253E09325E6BF226B299774B728A9 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 20:52:33.0344 5064 vsmraid - ok 20:52:33.0467 5064 [ DB3D19F850C6EB32BDCB9BC0836ACDDB ] VSS C:\Windows\system32\vssvc.exe 20:52:33.0519 5064 VSS - ok 20:52:33.0577 5064 [ 96EA68B9EB310A69C25EBB0282B2B9DE ] W32Time C:\Windows\system32\w32time.dll 20:52:33.0606 5064 W32Time - ok 20:52:33.0642 5064 [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 20:52:33.0650 5064 WacomPen - ok 20:52:33.0912 5064 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 20:52:33.0959 5064 Wanarp - ok 20:52:33.0968 5064 [ 55201897378CCA7AF8B5EFD874374A26 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 20:52:33.0969 5064 Wanarpv6 - ok 20:52:34.0163 5064 [ A3CD60FD826381B49F03832590E069AF ] wcncsvc C:\Windows\System32\wcncsvc.dll 20:52:34.0177 5064 wcncsvc - ok 20:52:34.0295 5064 [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 20:52:34.0322 5064 WcsPlugInService - ok 20:52:34.0378 5064 [ 78FE9542363F297B18C027B2D7E7C07F ] Wd C:\Windows\system32\drivers\wd.sys 20:52:34.0381 5064 Wd - ok 20:52:34.0464 5064 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 20:52:34.0669 5064 Wdf01000 - ok 20:52:34.0684 5064 wdhtgoo - ok 20:52:34.0738 5064 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiServiceHost C:\Windows\system32\wdi.dll 20:52:34.0742 5064 WdiServiceHost - ok 20:52:34.0757 5064 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] WdiSystemHost C:\Windows\system32\wdi.dll 20:52:34.0761 5064 WdiSystemHost - ok 20:52:34.0829 5064 [ 04C37D8107320312FBAE09926103D5E2 ] WebClient C:\Windows\System32\webclnt.dll 20:52:34.0878 5064 WebClient - ok 20:52:34.0948 5064 [ AE3736E7E8892241C23E4EBBB7453B60 ] Wecsvc C:\Windows\system32\wecsvc.dll 20:52:35.0164 5064 Wecsvc - ok 20:52:35.0243 5064 [ 670FF720071ED741206D69BD995EA453 ] wercplsupport C:\Windows\System32\wercplsupport.dll 20:52:35.0253 5064 wercplsupport - ok 20:52:35.0320 5064 [ 32B88481D3B326DA6DEB07B1D03481E7 ] WerSvc C:\Windows\System32\WerSvc.dll 20:52:35.0333 5064 WerSvc - ok 20:52:35.0358 5064 WinHttpAutoProxySvc - ok 20:52:35.0422 5064 [ 6B2A1D0E80110E3D04E6863C6E62FD8A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 20:52:35.0435 5064 Winmgmt - ok 20:52:35.0543 5064 [ 7CFE68BDC065E55AA5E8421607037511 ] WinRM C:\Windows\system32\WsmSvc.dll 20:52:35.0890 5064 WinRM - ok 20:52:36.0013 5064 [ C008405E4FEEB069E30DA1D823910234 ] Wlansvc C:\Windows\System32\wlansvc.dll 20:52:36.0093 5064 Wlansvc - ok 20:52:36.0249 5064 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 20:52:36.0342 5064 wlidsvc - ok 20:52:36.0389 5064 [ 2E7255D172DF0B8283CDFB7B433B864E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 20:52:36.0389 5064 WmiAcpi - ok 20:52:36.0436 5064 [ 43BE3875207DCB62A85C8C49970B66CC ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 20:52:36.0451 5064 wmiApSrv - ok 20:52:36.0561 5064 [ 3978704576A121A9204F8CC49A301A9B ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 20:52:36.0607 5064 WMPNetworkSvc - ok 20:52:36.0639 5064 [ CFC5A04558F5070CEE3E3A7809F3FF52 ] WPCSvc C:\Windows\System32\wpcsvc.dll 20:52:36.0654 5064 WPCSvc - ok 20:52:36.0717 5064 [ 801FBDB89D472B3C467EB112A0FC9246 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 20:52:36.0717 5064 WPDBusEnum - ok 20:52:36.0779 5064 [ DE9D36F91A4DF3D911626643DEBF11EA ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 20:52:36.0779 5064 WpdUsb - ok 20:52:36.0982 5064 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe 20:52:37.0044 5064 WPFFontCache_v0400 - ok 20:52:37.0107 5064 [ E3A3CB253C0EC2494D4A61F5E43A389C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 20:52:37.0107 5064 ws2ifsl - ok 20:52:37.0107 5064 WSearch - ok 20:52:37.0169 5064 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 20:52:37.0325 5064 WudfPf - ok 20:52:37.0387 5064 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 20:52:37.0590 5064 WUDFRd - ok 20:52:37.0653 5064 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 20:52:37.0777 5064 wudfsvc - ok 20:52:37.0871 5064 ================ Scan global =============================== 20:52:37.0918 5064 [ F31EEBC1A1C81FD04005489CC3DCDFE7 ] C:\Windows\system32\basesrv.dll 20:52:37.0965 5064 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 20:52:38.0214 5064 [ D2293B069E4B63DC17B2F08D45E71124 ] C:\Windows\system32\winsrv.dll 20:52:38.0277 5064 [ D4E6D91C1349B7BFB3599A6ADA56851B ] C:\Windows\system32\services.exe 20:52:38.0292 5064 [Global] - ok 20:52:38.0292 5064 ================ Scan MBR ================================== 20:52:38.0339 5064 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 20:52:39.0041 5064 \Device\Harddisk0\DR0 - ok 20:52:39.0041 5064 ================ Scan VBR ================================== 20:52:39.0057 5064 [ 01D1C14F32E20FA7B1336E8FE4A325EA ] \Device\Harddisk0\DR0\Partition1 20:52:39.0057 5064 \Device\Harddisk0\DR0\Partition1 - ok 20:52:39.0072 5064 [ 0637D4D2257459E0E22190971AFE9DD6 ] \Device\Harddisk0\DR0\Partition2 20:52:39.0072 5064 \Device\Harddisk0\DR0\Partition2 - ok 20:52:39.0072 5064 ============================================================ 20:52:39.0072 5064 Scan finished 20:52:39.0072 5064 ============================================================ 20:52:39.0103 5804 Detected object count: 2 20:52:39.0103 5804 Actual detected object count: 2 20:53:23.0080 5804 sptd ( LockedFile.Multi.Generic ) - skipped by user 20:53:23.0080 5804 sptd ( LockedFile.Multi.Generic ) - User select action: Skip 20:53:23.0189 5804 C:\Windows\system32\Drivers\tosrfcom.sys - copied to quarantine 20:53:25.0607 5804 C:\Windows\$NtUninstallKB32880$\2821335130\@ - copied to quarantine 20:53:25.0607 5804 C:\Windows\$NtUninstallKB32880$\2821335130\Desktop.ini - copied to quarantine 20:53:25.0623 5804 C:\Windows\$NtUninstallKB32880$\2821335130\L\00000004.@ - copied to quarantine 20:53:25.0623 5804 C:\Windows\$NtUninstallKB32880$\2821335130\L\201d3dde - copied to quarantine 20:53:25.0669 5804 C:\Windows\$NtUninstallKB32880$\2821335130\L\qnbwvoto - copied to quarantine 20:53:25.0701 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\00000004.@ - copied to quarantine 20:53:25.0716 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\00000008.@ - copied to quarantine 20:53:25.0747 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\000000cb.@ - copied to quarantine 20:53:25.0779 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\80000000.@ - copied to quarantine 20:53:25.0794 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\80000032.@ - copied to quarantine 20:53:26.0325 5804 Backup copy found, using it.. 20:53:26.0527 5804 C:\Windows\system32\Drivers\tosrfcom.sys - will be cured on reboot 20:53:26.0605 5804 C:\Windows\$NtUninstallKB32880$\2821335130\@ - will be deleted on reboot 20:53:26.0605 5804 C:\Windows\$NtUninstallKB32880$\2821335130\Desktop.ini - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\00000004.@ - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\00000008.@ - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\000000cb.@ - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\80000000.@ - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\2821335130\U\80000032.@ - will be deleted on reboot 20:53:26.0621 5804 C:\Windows\$NtUninstallKB32880$\3207693406 - will be deleted on reboot 20:53:26.0652 5804 Tosrfcom ( Virus.Win32.ZAccess.aml ) - User select action: Cure 20:53:34.0561 4092 Deinitialize success