12:59:58.0093 0x0524 TDSS rootkit removing tool 3.0.0.37 May 30 2014 13:12:03 13:00:17.0218 0x0524 ============================================================ 13:00:17.0218 0x0524 Current date / time: 2014/06/03 13:00:17.0218 13:00:17.0218 0x0524 SystemInfo: 13:00:17.0218 0x0524 13:00:17.0218 0x0524 OS Version: 5.1.2600 ServicePack: 3.0 13:00:17.0218 0x0524 Product type: Workstation 13:00:17.0218 0x0524 ComputerName: A45F7D7627C54C0 13:00:17.0218 0x0524 UserName: Administrator 13:00:17.0218 0x0524 Windows directory: C:\WINDOWS 13:00:17.0218 0x0524 System windows directory: C:\WINDOWS 13:00:17.0218 0x0524 Processor architecture: Intel x86 13:00:17.0218 0x0524 Number of processors: 2 13:00:17.0218 0x0524 Page size: 0x1000 13:00:17.0218 0x0524 Boot type: Safe boot with network 13:00:17.0218 0x0524 ============================================================ 13:00:23.0062 0x0524 KLMD registered as C:\WINDOWS\system32\drivers\59468737.sys 13:00:29.0703 0x0524 System UUID: {6FFE2164-F3FF-CDC7-9505-E17CB2F93CFE} 13:00:30.0343 0x0524 !crdlk 13:00:30.0343 0x0524 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 ( 111.79 Gb ), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'A' 13:00:30.0375 0x0524 ============================================================ 13:00:30.0375 0x0524 \Device\Harddisk0\DR0: 13:00:30.0375 0x0524 MBR partitions: 13:00:30.0375 0x0524 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A962B1 13:00:30.0390 0x0524 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3A9632F, BlocksNum 0xA4F95D1 13:00:30.0390 0x0524 ============================================================ 13:00:30.0437 0x0524 C: <-> \Device\Harddisk0\DR0\Partition1 13:00:30.0500 0x0524 D: <-> \Device\Harddisk0\DR0\Partition2 13:00:30.0671 0x0524 ============================================================ 13:00:30.0671 0x0524 Initialize success 13:00:30.0671 0x0524 ============================================================ 13:00:58.0406 0x0598 ============================================================ 13:00:58.0406 0x0598 Scan started 13:00:58.0406 0x0598 Mode: Manual; 13:00:58.0406 0x0598 ============================================================ 13:00:58.0406 0x0598 KSN ping started 13:01:01.0593 0x0598 KSN ping finished: true 13:01:02.0203 0x0598 ================ Scan system memory ======================== 13:01:02.0203 0x0598 System memory - ok 13:01:02.0203 0x0598 ================ Scan services ============================= 13:01:02.0296 0x0598 Suspicious service (NoAccess): 3fc68e249a2755ff 13:01:02.0437 0x0598 [ F5D871A8D00A0FD9AC920B39483F78C4, 03163AEECE046FC89B098083DED66400D6C67FD7E25C07356377B941EC4EA827 ] 3fc68e249a2755ff C:\WINDOWS\System32\Drivers\3fc68e249a2755ff.sys 13:01:02.0437 0x0598 Suspicious file ( NoAccess ): C:\WINDOWS\System32\Drivers\3fc68e249a2755ff.sys. md5: F5D871A8D00A0FD9AC920B39483F78C4, sha256: 03163AEECE046FC89B098083DED66400D6C67FD7E25C07356377B941EC4EA827 13:01:03.0109 0x0598 3fc68e249a2755ff - detected Rootkit.Win32.Necurs.gen ( 0 ) 13:01:05.0968 0x0598 3fc68e249a2755ff ( Rootkit.Win32.Necurs.gen ) - infected 13:01:05.0968 0x0598 Force sending object to P2P due to detect: C:\WINDOWS\System32\Drivers\3fc68e249a2755ff.sys 13:01:09.0921 0x0598 Object send P2P result: true 13:01:12.0703 0x0598 Abiosdsk - ok 13:01:12.0734 0x0598 abp480n5 - ok 13:01:12.0796 0x0598 [ 05118282F5D039595A2B92B4A4AFE197, 390EBD6088E96571636CE0925E4899D58893D9E5DF2389C09BABBD47A5838B52 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:01:12.0812 0x0598 ACPI - ok 13:01:12.0843 0x0598 [ 66A42B7DB194E24B973BBCCE840A0F3F, 2550F8E5B5ACD88E4191656194E46FB8EC8CCC65AFD4B5E6D5CED9FE297B573F ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 13:01:12.0859 0x0598 ACPIEC - ok 13:01:12.0875 0x0598 adpu160m - ok 13:01:12.0953 0x0598 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys 13:01:12.0968 0x0598 aec - ok 13:01:13.0015 0x0598 [ 7E775010EF291DA96AD17CA4B17137D7, E2B746D5839715432FA073378149545D51C8BEFF8621411E0FF184DE8AA83414 ] AFD C:\WINDOWS\System32\drivers\afd.sys 13:01:13.0015 0x0598 AFD - ok 13:01:13.0031 0x0598 Aha154x - ok 13:01:13.0062 0x0598 aic78u2 - ok 13:01:13.0093 0x0598 aic78xx - ok 13:01:13.0156 0x0598 [ 27AF056D8C42F0AB3CF1DFDCBBEB3243, 9D893C6C0E8619B0B0DA9EAEB5E470A29C9D730F89EC5632134C3F753DE51AC5 ] Alerter C:\WINDOWS\system32\alrsvc.dll 13:01:13.0156 0x0598 Alerter - ok 13:01:13.0187 0x0598 [ D1738DDDFF196C5CEE6D867C136AF745, DD4780276465CB18D14B4DDBB4E70117B374B3A61C618D68B5290714330DB91F ] ALG C:\WINDOWS\System32\alg.exe 13:01:13.0187 0x0598 ALG - ok 13:01:13.0218 0x0598 AliIde - ok 13:01:13.0250 0x0598 amsint - ok 13:01:13.0312 0x0598 [ 940976839B89995FCC30DFB3EE33410B, A9A7D421B666026E4BDA050C9AEBD5813D17FA71997220BD686E10B5F31BE07A ] ApfiltrService C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 13:01:13.0328 0x0598 ApfiltrService - ok 13:01:13.0375 0x0598 [ 1561430DA2F2AB81CC0CE71AF95A778D, 1EFD6F9FCD7A00DA6B4AFEC1E04E3DDF4147B7DF1CF021430B31F821E48395A0 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 13:01:13.0390 0x0598 AppMgmt - ok 13:01:13.0453 0x0598 [ D07CCC37476034EBF5DE4608A8AF4386, 52BFBC8D0F1B5A7DD39B363EB5F0545B5B6B2D4B8EB128A5E4536B27ECA7B4FC ] AR5211 C:\WINDOWS\system32\DRIVERS\ar5211.sys 13:01:13.0468 0x0598 AR5211 - ok 13:01:13.0515 0x0598 asc - ok 13:01:13.0546 0x0598 asc3350p - ok 13:01:13.0578 0x0598 asc3550 - ok 13:01:13.0703 0x0598 [ 0E5E4957549056E2BF2C49F4F6B601AD, F7F19FDC906B719A3516D30A9B4A2262C8CC5B36B94E3D4195C345EC4610FF2B ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 13:01:13.0750 0x0598 aspnet_state - ok 13:01:13.0781 0x0598 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:01:13.0781 0x0598 AsyncMac - ok 13:01:13.0828 0x0598 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 13:01:13.0828 0x0598 atapi - ok 13:01:13.0843 0x0598 Atdisk - ok 13:01:13.0937 0x0598 [ C27A0A876E7277428AB894CD58600686, 4550DF08601E8AA195FF118542036F2FBCC83F5DB435FECA546C3F9946688872 ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe 13:01:13.0984 0x0598 Ati HotKey Poller - ok 13:01:14.0187 0x0598 [ 633D22A45283762DC05989751CC1397C, F7E2E0A4057ACE0ADFA3EC2A823618FF65F63F83355A4C0268D49EE7CE750139 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 13:01:14.0312 0x0598 ati2mtag - ok 13:01:14.0390 0x0598 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 13:01:14.0406 0x0598 Atmarpc - ok 13:01:14.0453 0x0598 [ 3A28D3E7BAD0EED3810CD918B2525B54, EFC7CEF39D58E846613E419E78ECBD300DFB18630B70110AB2936737EB2B19C1 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 13:01:14.0453 0x0598 AudioSrv - ok 13:01:14.0484 0x0598 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 13:01:14.0484 0x0598 audstub - ok 13:01:14.0546 0x0598 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys 13:01:14.0546 0x0598 Beep - ok 13:01:14.0828 0x0598 [ B7150272AADDCC6F0EFDB8BEF1CD7376, 9FA3E9AD868F48917BDDBEA7E57FED7DCA699DDC751936CD03864D6D01FB2F7A ] BHDrvx86 C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\BASHDefs\20140214.001\BHDrvx86.sys 13:01:14.0890 0x0598 BHDrvx86 - ok 13:01:15.0000 0x0598 [ 78200FAA6FD9C69394134C238C87FB7F, 4E70BD89BB40222CB0647E8F73DBBAB1020594AEC313848C911048D080D0F26A ] BITS C:\WINDOWS\system32\qmgr.dll 13:01:15.0031 0x0598 BITS - ok 13:01:15.0078 0x0598 [ B98ED6D85339A66A73F32FB569EB6C01, 08DF27984060C55F8CDF5F8F9FF73816163B659030B9098F62027FE7303EEDEC ] Browser C:\WINDOWS\System32\browser.dll 13:01:15.0078 0x0598 Browser - ok 13:01:15.0125 0x0598 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 13:01:15.0125 0x0598 cbidf2k - ok 13:01:15.0187 0x0598 [ 0BE5AEF125BE881C4F854C554F2B025C, 1770DD70B3F115A0EF460907DEDC1E4B7241C08615A98F194D61A49C3E2BAA54 ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 13:01:15.0187 0x0598 CCDECODE - ok 13:01:15.0281 0x0598 [ 56C2811FD0D7B727808A69407B5BFAE0, 5F84A29A9E6D8F566F95399F3B41A82DD128EA69678BBBCF75AD914DE70D9A74 ] ccSet_NAV C:\WINDOWS\system32\drivers\NAV\1503000.00C\ccSetx86.sys 13:01:15.0296 0x0598 ccSet_NAV - ok 13:01:15.0375 0x0598 [ 56C2811FD0D7B727808A69407B5BFAE0, 5F84A29A9E6D8F566F95399F3B41A82DD128EA69678BBBCF75AD914DE70D9A74 ] ccSet_NST C:\WINDOWS\system32\drivers\NST\7DE07000.02B\ccSetx86.sys 13:01:15.0390 0x0598 ccSet_NST - ok 13:01:15.0437 0x0598 cd20xrnt - ok 13:01:15.0484 0x0598 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 13:01:15.0484 0x0598 Cdaudio - ok 13:01:15.0531 0x0598 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 13:01:15.0531 0x0598 Cdfs - ok 13:01:15.0578 0x0598 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 13:01:15.0578 0x0598 Cdrom - ok 13:01:15.0593 0x0598 Changer - ok 13:01:15.0671 0x0598 [ 45B63DF2FB498D219FCBB4425CADE676, D58417D5D0E562E2CCBA04C82CF7E176F6F82026CB4877D45F0DC18944B72960 ] CiSvc C:\WINDOWS\system32\cisvc.exe 13:01:15.0671 0x0598 CiSvc - ok 13:01:15.0703 0x0598 [ C94F1B6F61858D6389C0FA06954FB9C4, 832A8BF5D63FD623632823DE7F36636540DAC9192B40A44C2DE6961D2E086320 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 13:01:15.0703 0x0598 ClipSrv - ok 13:01:15.0796 0x0598 [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 13:01:15.0843 0x0598 clr_optimization_v2.0.50727_32 - ok 13:01:15.0890 0x0598 [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys 13:01:15.0890 0x0598 CmBatt - ok 13:01:15.0906 0x0598 CmdIde - ok 13:01:15.0937 0x0598 [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys 13:01:15.0937 0x0598 Compbatt - ok 13:01:15.0968 0x0598 COMSysApp - ok 13:01:16.0062 0x0598 Cpqarray - ok 13:01:16.0109 0x0598 [ 6B105FE95F2E9F0B6346044BA59D41C9, DC41FC89E6C4F4219015856AEE9D9CE365094D3C8012AFFC188C129DC3B6A9A8 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 13:01:16.0125 0x0598 CryptSvc - ok 13:01:16.0156 0x0598 dac2w2k - ok 13:01:16.0171 0x0598 dac960nt - ok 13:01:16.0250 0x0598 [ A37311D9D628C1042A2836731787F0F3, 2A4380021407E84FAD47A2D5B02D37F1F17E8E2B1433710208FFCC70D9ECB5AA ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 13:01:16.0296 0x0598 DcomLaunch - ok 13:01:16.0375 0x0598 [ 770471DE2550820FEEB7E5D24BF2E273, 8936056EBDED36F0ABA5889031CBB0F06428CE52A68FF215221819DF85C6D52E ] DgiVecp C:\WINDOWS\system32\Drivers\DgiVecp.sys 13:01:16.0375 0x0598 DgiVecp - ok 13:01:16.0453 0x0598 [ 6B4AFE7C676CFF3EFF2DC06A4EE945F7, 9771808A033C781758AC1356F9F51B198A0750081424F4F7A937CE0D7408CEE1 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 13:01:16.0453 0x0598 Dhcp - ok 13:01:16.0484 0x0598 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 13:01:16.0484 0x0598 Disk - ok 13:01:16.0515 0x0598 dmadmin - ok 13:01:16.0593 0x0598 [ BC9219ABC5696942E6F9AC8A9B28670F, DEDD84A5FC12664C7767EC5210E3B4D311664EF8BCE01C9DCF16CC98BE16EDE1 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 13:01:16.0625 0x0598 dmboot - ok 13:01:16.0703 0x0598 [ 5FA232E3BA6E1346F9F5A7E519320CB0, 1C7EEC415C291D3C5FFD479A8454347528AF4FF88F81011EF65EFA8FE8199973 ] dmio C:\WINDOWS\system32\drivers\dmio.sys 13:01:16.0718 0x0598 dmio - ok 13:01:16.0750 0x0598 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys 13:01:16.0750 0x0598 dmload - ok 13:01:16.0781 0x0598 [ D858920A05076914D34B0388E8D96CC0, A8F231BA9022F6AEBB24C9DCC1898923F85B79DE3C8E90B696CA0B295B9C99B7 ] dmserver C:\WINDOWS\System32\dmserver.dll 13:01:16.0781 0x0598 dmserver - ok 13:01:16.0843 0x0598 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 13:01:16.0843 0x0598 DMusic - ok 13:01:16.0875 0x0598 [ 4F7E82841ED3CF026BD8D5CE7C7379DB, EE216CCF13C78ED5BE30F21347A04E8EA3FB6AE016F7C88B67891DF8A49CB031 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 13:01:16.0875 0x0598 Dnscache - ok 13:01:16.0937 0x0598 [ E0B7D66CF29D9ADCCF873C77821CD4CA, 09A3D28585B62FC541EF4F2CB4D749DA119BB5F98739393CFD4D745060217C65 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 13:01:16.0937 0x0598 Dot3svc - ok 13:01:16.0968 0x0598 dpti2o - ok 13:01:17.0000 0x0598 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 13:01:17.0000 0x0598 drmkaud - ok 13:01:17.0062 0x0598 EagleXNt - ok 13:01:17.0125 0x0598 [ 5F256C1AD50FEFDC442CD5AAB58C7DD8, 0FC1F2590195AE4B7CAA802D84CD391B56D73B99CB100BDEBD4D7C002946D06B ] EapHost C:\WINDOWS\System32\eapsvc.dll 13:01:17.0125 0x0598 EapHost - ok 13:01:17.0187 0x0598 [ ED1B71382C31FD2CF3CDC4672EFAD6EA, AF3CD28B5E6F1ED1D6B7C71C697019B2E2E79AFFE29EB6282253B30BA205F3EA ] ERSvc C:\WINDOWS\System32\ersvc.dll 13:01:17.0203 0x0598 ERSvc - ok 13:01:17.0281 0x0598 [ 02A467E27AF55F7064C5B251E587315F, 309D6C6ABC9D7786354758C107B89C50AC722AEA3B10631714F326AB2D3BB3DF ] Eventlog C:\WINDOWS\system32\services.exe 13:01:17.0281 0x0598 Eventlog - ok 13:01:17.0343 0x0598 [ 6AFF804839C85859E0247164FBE5F5BB, 91E1FEC83545BC6489E35CD042BBA756FA31C5BEAD51FC5494DD04F6F8C852AB ] EventSystem C:\WINDOWS\system32\es.dll 13:01:17.0359 0x0598 EventSystem - ok 13:01:17.0406 0x0598 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 13:01:17.0421 0x0598 Fastfat - ok 13:01:17.0500 0x0598 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 13:01:17.0500 0x0598 FastUserSwitchingCompatibility - ok 13:01:17.0546 0x0598 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 13:01:17.0546 0x0598 Fdc - ok 13:01:17.0562 0x0598 [ 09E2A4D33F81A06A8AAB2BA0A0B5D235, D71C2D4212C7ABB1D8EE08B21C59CA25D7195F1A0E92E5BDA1DC5226A0E62CB0 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 13:01:17.0578 0x0598 Fips - ok 13:01:17.0609 0x0598 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 13:01:17.0609 0x0598 Flpydisk - ok 13:01:17.0640 0x0598 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 13:01:17.0656 0x0598 FltMgr - ok 13:01:17.0734 0x0598 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 13:01:17.0734 0x0598 FontCache3.0.0.0 - ok 13:01:17.0796 0x0598 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:01:17.0796 0x0598 Fs_Rec - ok 13:01:17.0828 0x0598 [ ED6D921D8AB423138FB35BEEE6D6A6CB, CF133B76960207595C44181A235E63B84C5A5A4E7BDDDC2E6A01DA837E55832D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 13:01:17.0828 0x0598 Ftdisk - ok 13:01:17.0859 0x0598 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 13:01:17.0859 0x0598 Gpc - ok 13:01:17.0937 0x0598 [ 833051C6C6C42117191935F734CFBD97, 5EB5672ABC7994A4AFF855A572158B8BE4FC6E541CFD4B9BE4FF2739A9A6AFB8 ] hamachi C:\WINDOWS\system32\DRIVERS\hamachi.sys 13:01:17.0937 0x0598 hamachi - ok 13:01:18.0000 0x0598 [ 2A013E7530BEAB6E569FAA83F517E836, 481390EE00AF49BB54B8C885801FCAC0F87F4EF3D935ABBBA42B7C063EFDDB8F ] HdAudAddService C:\WINDOWS\system32\drivers\HdAudio.sys 13:01:18.0000 0x0598 HdAudAddService - ok 13:01:18.0046 0x0598 [ 3FCC124B6E08EE0E9351F717DD136939, EBFE0FB51E14570A1A1D64C8E5383F3FF28509361D13945B79A9C551EB522012 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 13:01:18.0062 0x0598 HDAudBus - ok 13:01:18.0125 0x0598 [ AF752014F7EB61542E3F35B9374D7E76, 8D9F1D1B03D5AF9F592C396C4B6353E17F2E852A2A7F1F468F83763C0731435D ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 13:01:18.0125 0x0598 helpsvc - ok 13:01:18.0156 0x0598 HidServ - ok 13:01:18.0250 0x0598 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys 13:01:18.0250 0x0598 HidUsb - ok 13:01:18.0328 0x0598 [ F0273916DA6FB64CC88E0BD77619554F, C6E3B5C367CE52174251B1CE548F0DF8708AEDD228D5AD74D3F6F31FC3857460 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 13:01:18.0328 0x0598 hkmsvc - ok 13:01:18.0359 0x0598 hpn - ok 13:01:18.0437 0x0598 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 13:01:18.0468 0x0598 HTTP - ok 13:01:18.0515 0x0598 [ AA268079AC119F3A596E5E27AEE4BD17, 2FD9B52A0627B3ECE618BAC855C19002CA6F5339636D11DF9F998E588027292A ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 13:01:18.0531 0x0598 HTTPFilter - ok 13:01:18.0578 0x0598 hwdatacard - ok 13:01:18.0671 0x0598 i2omgmt - ok 13:01:18.0703 0x0598 i2omp - ok 13:01:18.0765 0x0598 [ 177B372AF55C4460D0968B5F1D02AA1C, 39406139B0D42C650F2C1986D85DB2260107D427963BC2C85A11D71561986DEB ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 13:01:18.0765 0x0598 i8042prt - ok 13:01:18.0953 0x0598 [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 13:01:19.0015 0x0598 idsvc - ok 13:01:19.0140 0x0598 [ 96935C6AC3753EBFE4A589D0277A0EA2, 8B1AEC1E0D258B51876E243BA38BEB99BCE5F3E8C837AE6DD7BF2BD864B094DD ] IDSxpx86 C:\Program Files\Norton AntiVirus\NortonData\21.3.0.12\Definitions\IPSDefs\20140224.002\IDSxpx86.sys 13:01:19.0156 0x0598 IDSxpx86 - ok 13:01:19.0218 0x0598 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 13:01:19.0218 0x0598 Imapi - ok 13:01:19.0296 0x0598 [ 9125AF650608A921F98A789E5C5BA864, E530C4FE52EB66549D91490B3039EF8DBC6866E4F9B55213F21E3757892B06CE ] ImapiService C:\WINDOWS\system32\imapi.exe 13:01:19.0312 0x0598 ImapiService - ok 13:01:19.0343 0x0598 ini910u - ok 13:01:19.0703 0x0598 [ 001AACA6ED0E6B00FC5B8FAF74977E81, 1028C75EC3FED34D8FA012E737A7AB9B6B4647F7305A34B0DACA9806C87FB709 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 13:01:19.0968 0x0598 IntcAzAudAddService - ok 13:01:20.0015 0x0598 IntelIde - ok 13:01:20.0093 0x0598 [ DA153EDC09DE8C4F846C085CAA39D1CC, 7669572FDCC2B458A8DCBA910D0260806E6DD7845221B81C509E627AB82ED7B4 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 13:01:20.0093 0x0598 intelppm - ok 13:01:20.0125 0x0598 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 13:01:20.0125 0x0598 Ip6Fw - ok 13:01:20.0187 0x0598 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:01:20.0187 0x0598 IpFilterDriver - ok 13:01:20.0203 0x0598 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 13:01:20.0203 0x0598 IpInIp - ok 13:01:20.0250 0x0598 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 13:01:20.0250 0x0598 IpNat - ok 13:01:20.0281 0x0598 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 13:01:20.0296 0x0598 IPSec - ok 13:01:20.0343 0x0598 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 13:01:20.0343 0x0598 IRENUM - ok 13:01:20.0421 0x0598 [ C8EEF2E93835B81BD335DE2123121283, DF7CCA1141CE15050D5EA516C75BF677B095EABA9E08828880E8917EBDEB2418 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 13:01:20.0421 0x0598 isapnp - ok 13:01:20.0546 0x0598 [ E4B3CCAC6132C784D5BEC93747B284AD, 0C453681A791CC8C83DA6C745A258C5D7516F7FDBE9B3E34BD97A12DA242B1E7 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe 13:01:20.0546 0x0598 JavaQuickStarterService - ok 13:01:20.0593 0x0598 [ 2AECA45D4AEAACBDCB77AD11184E4601, 58724D00A0D6FA17CCAF69DC069EF59E535F08C870C199BF2C9269BC22273A63 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 13:01:20.0593 0x0598 Kbdclass - ok 13:01:20.0656 0x0598 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 13:01:20.0656 0x0598 kmixer - ok 13:01:20.0750 0x0598 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 13:01:20.0750 0x0598 KSecDD - ok 13:01:20.0812 0x0598 [ 427F50A24AA35597A9A5E8FBF029590F, 561060473E4AB11A1450CCC1C6B7A1D9C8284E4935C165EA2FFD9571D462F70C ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 13:01:20.0812 0x0598 LanmanServer - ok 13:01:20.0875 0x0598 [ FA17019DA45C5D6464776A639A5A9ABB, 5654615E6130D344D2D42B59DF2F5CD02C6D3B1128BBC2A14ED0CB8078180B17 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 13:01:20.0875 0x0598 lanmanworkstation - ok 13:01:20.0906 0x0598 lbrtfdc - ok 13:01:20.0968 0x0598 [ 437AA83D68F9FAC234CA68DBD40DB705, 49B4A9E30778FB6D08AA7F9D66AF173572B86F74863477FFE7A66BBF2E6BCE93 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 13:01:20.0984 0x0598 LmHosts - ok 13:01:21.0015 0x0598 [ 36F3AB18B1BE303DA51DE90A67DE3942, E364FF831EFBDC5FF026CE620EE951C129D4E0C79DD0FED823BC767F36ED0021 ] Messenger C:\WINDOWS\System32\msgsvc.dll 13:01:21.0015 0x0598 Messenger - ok 13:01:21.0046 0x0598 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 13:01:21.0046 0x0598 mnmdd - ok 13:01:21.0109 0x0598 [ 845814A8CB9D704D030F076E1BCE83F3, F35FD4B6CE78A06A6FCF207A75EADF5A8315F2254A3E84ED070928F196D32AF4 ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 13:01:21.0109 0x0598 mnmsrvc - ok 13:01:21.0140 0x0598 [ 4A068DB7DC37D5AFEDB6512D2931D7B3, 491F58509188054EE35962B66A13F0029BDF66CC59ED3B5E4058393146CE001C ] Modem C:\WINDOWS\system32\drivers\Modem.sys 13:01:21.0140 0x0598 Modem - ok 13:01:21.0203 0x0598 [ FBED3DF6B884F8CF00447B73507F2C48, 2CAA78DF3DB8BB19C10FD046B6EDC34167D8CA67EF137912703FE751D70803A2 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 13:01:21.0203 0x0598 Mouclass - ok 13:01:21.0281 0x0598 [ ECEC1E6CD558AB80F944F31326E9D3B5, E61B7124FDFE36D7C9081ABA7745F87F83592CE683AB49F7C31359D393B2E691 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 13:01:21.0281 0x0598 mouhid - ok 13:01:21.0343 0x0598 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 13:01:21.0343 0x0598 MountMgr - ok 13:01:21.0437 0x0598 [ E1B6FCAE82474FC071155263E2841D54, 341E2CEB1A86586730130311C4FAF86851151D5F08EF915A5F89B6C4094AE1F4 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 13:01:21.0453 0x0598 MozillaMaintenance - ok 13:01:21.0468 0x0598 mraid35x - ok 13:01:21.0500 0x0598 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 13:01:21.0515 0x0598 MRxDAV - ok 13:01:21.0593 0x0598 [ 60AE98742484E7AB80C3C1450E708148, EDA62550BFB9EBB0FBE88CB55BB13C8F2636C620E52D691C7BEF13357F68C7DC ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:01:21.0609 0x0598 MRxSmb - ok 13:01:21.0656 0x0598 [ A54C5EECC7D3424824410BAE0AA6C371, C0C80211DD9A69A529B5277B0751FFABCBB6586292D06A79ED7B842277FBF78A ] MSDTC C:\WINDOWS\system32\msdtc.exe 13:01:21.0656 0x0598 MSDTC - ok 13:01:21.0703 0x0598 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 13:01:21.0703 0x0598 Msfs - ok 13:01:21.0718 0x0598 MSIServer - ok 13:01:21.0781 0x0598 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 13:01:21.0781 0x0598 MSKSSRV - ok 13:01:21.0843 0x0598 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 13:01:21.0843 0x0598 MSPCLOCK - ok 13:01:21.0859 0x0598 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 13:01:21.0859 0x0598 MSPQM - ok 13:01:21.0921 0x0598 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 13:01:21.0937 0x0598 mssmbios - ok 13:01:21.0984 0x0598 [ E53736A9E30C45FA9E7B5EAC55056D1D, 38602F280BF69EBA3706AD175AFC1AEB561A8302B4B61E3FECB3C27D7A9BDB41 ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 13:01:21.0984 0x0598 MSTEE - ok 13:01:22.0000 0x0598 [ 2F625D11385B1A94360BFC70AAEFDEE1, 23E4974120233CF1A7BEE48977706A0A55418699379D1450502ABEB24191AC80 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 13:01:22.0015 0x0598 Mup - ok 13:01:22.0078 0x0598 [ 5B50F1B2A2ED47D560577B221DA734DB, C16A554B6E1A7F5F98C94DFA88163E0F7426506BF2F51FD351B1A05FC0DB3BC5 ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 13:01:22.0078 0x0598 NABTSFEC - ok 13:01:22.0140 0x0598 [ 14CB8528E17D1221C50FC8CA88B1795F, E908EAE9A0E606084926941B1802E9F48AE1AC4AE6C6136345DD5699B8B9B526 ] napagent C:\WINDOWS\System32\qagentrt.dll 13:01:22.0156 0x0598 napagent - ok 13:01:22.0406 0x0598 [ A896A6A60BA695CC6082233AFFDBE38F, 907841700F6EFC74A31B7F36A9D074A4043C44A17468CAAF85BBACBA6CC57485 ] NAV C:\Program Files\Norton AntiVirus\Engine\21.3.0.12\NAV.exe 13:01:22.0406 0x0598 NAV - ok 13:01:22.0484 0x0598 NAVENG - ok 13:01:22.0500 0x0598 NAVEX15 - ok 13:01:22.0625 0x0598 [ 97C152DE06F2BEF0BB14FDA3F187EFA9, 34FA61FC9A7225312FBEDE6149D7B9A140AC7C61313A1A4BD2EC0DA89BE497E5 ] NCO C:\Program Files\Norton Identity Safe\Engine\2014.7.0.43\NST.exe 13:01:22.0640 0x0598 NCO - ok 13:01:22.0734 0x0598 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 13:01:22.0750 0x0598 NDIS - ok 13:01:22.0812 0x0598 [ 7FF1F1FD8609C149AA432F95A8163D97, 18CD1FF5AC1EF8A38D1EC53014F2BADD28D9CDF4ECE2EBC2313D08903776F323 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 13:01:22.0812 0x0598 NdisIP - ok 13:01:22.0843 0x0598 [ 1AB3D00C991AB086E69DB84B6C0ED78F, 1F881FCCF5557C44C078D99CA2DD38D635413D6212DBEDC06A428EDAC7F8B04E ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 13:01:22.0843 0x0598 NdisTapi - ok 13:01:22.0875 0x0598 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 13:01:22.0875 0x0598 Ndisuio - ok 13:01:22.0921 0x0598 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:01:22.0921 0x0598 NdisWan - ok 13:01:22.0953 0x0598 [ 6215023940CFD3702B46ABC304E1D45A, C767F3A349B365F6E7566C0738E2F62D8FFF8CB4457347E3614BD403BC6CADCB ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 13:01:22.0968 0x0598 NDProxy - ok 13:01:23.0000 0x0598 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 13:01:23.0000 0x0598 NetBIOS - ok 13:01:23.0031 0x0598 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 13:01:23.0046 0x0598 NetBT - ok 13:01:23.0093 0x0598 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDE C:\WINDOWS\system32\netdde.exe 13:01:23.0109 0x0598 NetDDE - ok 13:01:23.0171 0x0598 [ CBB409B314309FCFFCE5E682E91338C6, 75BB788E9154D0437A8449B6C88432E27F1EACD9B6FDF27A46DE5147EC59CF6D ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 13:01:23.0187 0x0598 NetDDEdsdm - ok 13:01:23.0218 0x0598 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] Netlogon C:\WINDOWS\system32\lsass.exe 13:01:23.0218 0x0598 Netlogon - ok 13:01:23.0265 0x0598 [ 4FE97D0B1B182DF2A9BDD4C02155EF5E, 46F3F4FEB501E1987B49AB1595AADC06432B70E39CA6E9CC67C6410B13DA7B7A ] Netman C:\WINDOWS\System32\netman.dll 13:01:23.0281 0x0598 Netman - ok 13:01:23.0343 0x0598 [ D34612C5D02D026535B3095D620626AE, 1BBCCCBF49EB8807240A77DCB43C25C21682073CC5356594E2C4F53EF36BF657 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe 13:01:23.0343 0x0598 NetTcpPortSharing - ok 13:01:23.0406 0x0598 [ 300BCC512DE4038F1494230941DB2C2A, 7BF1016D72F88AF941AECC8BFA41D5F36D41F4998784D04F0E2343939B18F7A5 ] Nla C:\WINDOWS\System32\mswsock.dll 13:01:23.0421 0x0598 Nla - ok 13:01:23.0453 0x0598 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 13:01:23.0453 0x0598 Npfs - ok 13:01:23.0515 0x0598 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 13:01:23.0562 0x0598 Ntfs - ok 13:01:23.0578 0x0598 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] NtLmSsp C:\WINDOWS\system32\lsass.exe 13:01:23.0578 0x0598 NtLmSsp - ok 13:01:23.0687 0x0598 [ 3FB5399DBB7001A80D58EDAD64C98225, A790DB873DAADB2B241F2C2426B51C0B73D4E13AC4D804B8EBBF5A74B4A41797 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 13:01:23.0718 0x0598 NtmsSvc - ok 13:01:23.0765 0x0598 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys 13:01:23.0765 0x0598 Null - ok 13:01:23.0828 0x0598 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 13:01:23.0828 0x0598 NwlnkFlt - ok 13:01:23.0843 0x0598 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 13:01:23.0843 0x0598 NwlnkFwd - ok 13:01:23.0890 0x0598 [ 2D4CDAEBCED17743AA9E25D3016DC229, F5D138644F114861DD045975136904325304081221B85FB2C151CD9A411097CE ] Parport C:\WINDOWS\system32\drivers\Parport.sys 13:01:23.0890 0x0598 Parport - ok 13:01:23.0953 0x0598 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 13:01:23.0953 0x0598 PartMgr - ok 13:01:23.0984 0x0598 [ 453EC2C2A20A1382F564541918520EEB, 797ED3127131BAE255AE793B8327D0E3BB6D054421F8D90511B315937BEBB6B0 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 13:01:23.0984 0x0598 ParVdm - ok 13:01:24.0046 0x0598 [ 6862C69168D787B85A7D95CCD33C694E, 6B7912156A0BAB6AED4F00FE37034488D10646B17435E86DE0D7DBD5951E8FB9 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 13:01:24.0046 0x0598 PCI - ok 13:01:24.0078 0x0598 PCIDump - ok 13:01:24.0109 0x0598 [ 548CF2D6369EAE441A4C6BAA75BC4F0A, C659E9E8A16DD4CBEC97FFB50784D8585E02F20FA360D2280D322D975F00A994 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 13:01:24.0109 0x0598 PCIIde - ok 13:01:24.0156 0x0598 [ 8DB27F1AE9593C94095485305A583862, 4FDB24BA306944743B50C3B0E39EFC75BD196A4DA1B0A3C859B974E8599B5128 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys 13:01:24.0171 0x0598 Pcmcia - ok 13:01:24.0187 0x0598 PDCOMP - ok 13:01:24.0218 0x0598 PDFRAME - ok 13:01:24.0250 0x0598 PDRELI - ok 13:01:24.0281 0x0598 PDRFRAME - ok 13:01:24.0296 0x0598 perc2 - ok 13:01:24.0328 0x0598 perc2hib - ok 13:01:24.0468 0x0598 [ 02A467E27AF55F7064C5B251E587315F, 309D6C6ABC9D7786354758C107B89C50AC722AEA3B10631714F326AB2D3BB3DF ] PlugPlay C:\WINDOWS\system32\services.exe 13:01:24.0468 0x0598 PlugPlay - ok 13:01:24.0500 0x0598 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] PolicyAgent C:\WINDOWS\system32\lsass.exe 13:01:24.0500 0x0598 PolicyAgent - ok 13:01:24.0562 0x0598 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 13:01:24.0562 0x0598 PptpMiniport - ok 13:01:24.0593 0x0598 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 13:01:24.0593 0x0598 ProtectedStorage - ok 13:01:24.0640 0x0598 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 13:01:24.0640 0x0598 PSched - ok 13:01:24.0671 0x0598 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 13:01:24.0671 0x0598 Ptilink - ok 13:01:24.0703 0x0598 ql1080 - ok 13:01:24.0734 0x0598 Ql10wnt - ok 13:01:24.0765 0x0598 ql12160 - ok 13:01:24.0796 0x0598 ql1240 - ok 13:01:24.0828 0x0598 ql1280 - ok 13:01:24.0843 0x0598 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 13:01:24.0859 0x0598 RasAcd - ok 13:01:24.0953 0x0598 [ BC22C5E1238D4D36D65679E249C483C3, 9B01F8D9541F3558F7D6A3E079580EC87DC748EFCA43E10682C83953B8885C3B ] RasAuto C:\WINDOWS\System32\rasauto.dll 13:01:24.0953 0x0598 RasAuto - ok 13:01:25.0000 0x0598 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 13:01:25.0000 0x0598 Rasl2tp - ok 13:01:25.0062 0x0598 [ 0C392E397B8D34AAAF19EC6119CBB788, 843C0B52A92A7F62E0D503A62FE56A020655AD98BC287AE8669ACE93B6A02ECA ] RasMan C:\WINDOWS\System32\rasmans.dll 13:01:25.0062 0x0598 RasMan - ok 13:01:25.0093 0x0598 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 13:01:25.0093 0x0598 RasPppoe - ok 13:01:25.0140 0x0598 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 13:01:25.0140 0x0598 Raspti - ok 13:01:25.0171 0x0598 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 13:01:25.0187 0x0598 Rdbss - ok 13:01:25.0218 0x0598 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 13:01:25.0218 0x0598 RDPCDD - ok 13:01:25.0296 0x0598 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 13:01:25.0312 0x0598 rdpdr - ok 13:01:25.0390 0x0598 [ 6728E45B66F93C08F11DE2E316FC70DD, EA63ECD4F84CAE08BD2BF843C48AF505B1B9D7B61349A63536C9C6FEBEF23452 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 13:01:25.0390 0x0598 RDPWD - ok 13:01:25.0453 0x0598 [ F83907A9A038DB2E35329B039628D293, 683D478C9EC30102BB5A4CB6D200C4772C8BF5DF7BFC757AFA0B5B44DA1F8961 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 13:01:25.0468 0x0598 RDSessMgr - ok 13:01:25.0500 0x0598 [ E0C7BBD18040B58651BAC700C804861D, 91AE8D3C7D9FB391725664996479DAFDA91CB91C31E446BFE9ECF0C4FC86BE2F ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 13:01:25.0500 0x0598 redbook - ok 13:01:25.0593 0x0598 [ B3F57E6115BCD4DBADE9874F300655E3, DFF4D6AEA1B22C531216ED5A94B01C88D2C61D0EC3BB34744B4572C672EF89E6 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 13:01:25.0609 0x0598 RemoteAccess - ok 13:01:25.0656 0x0598 [ B472B59EF98469C91651B751D3442CB8, 544654D84BDA303CBBA9CFDDFE57BDFD3698F5E7E08A2F25C7CF383A856223FA ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 13:01:25.0656 0x0598 RemoteRegistry - ok 13:01:25.0703 0x0598 [ 6BC4D5A70F46EA27DDC14E5414C862A5, D78921FF982CFF26A012A413F19331AACA4F66E53D38C626FE712B4108744E31 ] RpcLocator C:\WINDOWS\system32\locator.exe 13:01:25.0703 0x0598 RpcLocator - ok 13:01:25.0781 0x0598 [ A37311D9D628C1042A2836731787F0F3, 2A4380021407E84FAD47A2D5B02D37F1F17E8E2B1433710208FFCC70D9ECB5AA ] RpcSs C:\WINDOWS\system32\rpcss.dll 13:01:25.0796 0x0598 RpcSs - ok 13:01:25.0843 0x0598 [ 9ACEE3313020A01235336C2A483AFD1A, 87DD3B037FB80DC5BB9F3E335C9A0F3926481012EF9A8DE2CEF53C5386F69009 ] RSVP C:\WINDOWS\system32\rsvp.exe 13:01:25.0859 0x0598 RSVP - ok 13:01:25.0953 0x0598 [ 1E11171C0B9989E1BDAA59E96B2E81C4, C49D3E63DF561800AA498BDE587EFDEDF675BD0A0A7FA35E436365691C539F7E ] RTL8023xp C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 13:01:25.0968 0x0598 RTL8023xp - ok 13:01:26.0000 0x0598 [ D507C1400284176573224903819FFDA3, DD0BDB2AB39A8A0A300B6D60FB6A7F5BA08C4DB8F59E0A784FB763EA8AD72AB2 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 13:01:26.0000 0x0598 rtl8139 - ok 13:01:26.0031 0x0598 [ 88296F7943F30A1EE3AF735440B92268, 8ACCF0331EE351EFB1A0F5EF210B92F822343B387D4B8CC29FE3222FDBFA911B ] SamSs C:\WINDOWS\system32\lsass.exe 13:01:26.0031 0x0598 SamSs - ok 13:01:26.0109 0x0598 [ C6F479218E94896738C06AF5BA6AB3D3, 4077BDDE1A44E2A415FF76A8BB3EAD226D7A29696C0218E81381B81E750CD0BA ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 13:01:26.0109 0x0598 SCardSvr - ok 13:01:26.0187 0x0598 [ DD73C11A5C4D14945846384B90A61A4B, C3C6BD62FB976E27C9E2C4C239D01B5458B7D270E9563A90EFBC9801B5DC55EA ] Schedule C:\WINDOWS\system32\schedsvc.dll 13:01:26.0203 0x0598 Schedule - ok 13:01:26.0250 0x0598 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 13:01:26.0250 0x0598 Secdrv - ok 13:01:26.0281 0x0598 [ 2AAD9026648120FFFE2A8D871BB2BBC7, 8F9B35717CBE8B1C30FF15992DA8A857470A96F1A043CDA42CB89E4C6723B4A4 ] seclogon C:\WINDOWS\System32\seclogon.dll 13:01:26.0281 0x0598 seclogon - ok 13:01:26.0328 0x0598 [ 9D01E29D59723EB73B72107B208DAFE6, D334E807C6B41CF08EB64DCF8B2C8F68FA553971130FAB2E14C3EEE4D3B968F7 ] SENS C:\WINDOWS\system32\sens.dll 13:01:26.0328 0x0598 SENS - ok 13:01:26.0406 0x0598 [ D07B02F88165E69B9F17162CF592C8A6, B494941FC05FC2439F54D4D999B1A65F9709BC296D5AC470C8F73ACFC5DC4729 ] Serial C:\WINDOWS\system32\drivers\Serial.sys 13:01:26.0406 0x0598 Serial - ok 13:01:26.0500 0x0598 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 13:01:26.0500 0x0598 Sfloppy - ok 13:01:26.0562 0x0598 [ DA5C015911F68F22ED821E9EE49AB233, 53694B0E70F77C775CE936F5DB458F724F051314704B6F69E5C2728180F0DC2C ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 13:01:26.0593 0x0598 SharedAccess - ok 13:01:26.0656 0x0598 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 13:01:26.0656 0x0598 ShellHWDetection - ok 13:01:26.0687 0x0598 Simbad - ok 13:01:26.0750 0x0598 SkypeUpdate - ok 13:01:26.0828 0x0598 [ 866D538EBE33709A5C9F5C62B73B7D14, BC94BEB7C17B4FCAC8B5D0D5006A203BC209E0504EECE149651D8691935696CD ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 13:01:26.0828 0x0598 SLIP - ok 13:01:26.0890 0x0598 Sparrow - ok 13:01:26.0937 0x0598 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys 13:01:26.0937 0x0598 splitter - ok 13:01:26.0984 0x0598 [ DD69EC597AB942C39B950D9C3CE1375D, D09185C8ED73FF04945FDB0B40009E0FCC31A73E80B03D397A1436CC3A373AF5 ] Spooler C:\WINDOWS\system32\spoolsv.exe 13:01:26.0984 0x0598 Spooler - ok 13:01:27.0093 0x0598 [ CDDDEC541BC3C96F91ECB48759673505, B030FFA02832317AC5626BF1BF8A4A95A5992C9A6E81BC1C002D5F4D667C27FB ] sptd C:\WINDOWS\system32\Drivers\sptd.sys 13:01:27.0125 0x0598 sptd - ok 13:01:27.0234 0x0598 [ 7584AB48E1A4358D21136B241349934D, 117F6333C08C202A479AF7C3399EBDACF3A0FC3F25ED88BE77FB09E6AC6BD108 ] spupdsvc C:\WINDOWS\system32\spupdsvc.exe 13:01:27.0234 0x0598 spupdsvc - ok 13:01:27.0296 0x0598 SpyEmrg - ok 13:01:27.0359 0x0598 [ EB032822BE406EF220D546DDFFCF0002, 916299B409925AB7326CB5F744799B34FD08CA4C4B447215DA5060FF446FEEBE ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 13:01:27.0375 0x0598 sr - ok 13:01:27.0421 0x0598 [ 316D0E66074AE4CDE641C50D3A1C5148, 8429F815AFB4B39F6C1C56FB1CA009E5338C1467A4A02DD8E7E35BADBB8D5221 ] srservice C:\WINDOWS\system32\srsvc.dll 13:01:27.0421 0x0598 srservice - ok 13:01:27.0578 0x0598 [ 91C966DE2058116525748050A22C8170, EE64D29ED2C5EDE035E6BE56AE28403B42C10815A89AC08A5395DE72375AF550 ] SRTSP C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSP.SYS 13:01:27.0609 0x0598 SRTSP - ok 13:01:27.0687 0x0598 [ 1B6D68043F488F70E889276E1585B7AA, 574925053F0EB2DED6DA03D0720A8E1588590948DFF1E2C6DE84EA5B6856E3DB ] SRTSPX C:\WINDOWS\system32\drivers\NAV\1503000.00C\SRTSPX.SYS 13:01:27.0687 0x0598 SRTSPX - ok 13:01:27.0765 0x0598 [ 3BB03F2BA89D2BE417206C373D2AF17C, 2EFD14332E133E71B09A0E00BF40CD9BC6850E976F05313B94B7E76780CDDF3D ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 13:01:27.0781 0x0598 Srv - ok 13:01:27.0828 0x0598 [ 2C0B1224AA36B4CA1753302BAA855882, F8C90ECBF5BD7C3984E7C82EB00042DFD85A62F263C0205E6790205B6D64E101 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 13:01:27.0843 0x0598 SSDPSRV - ok 13:01:27.0890 0x0598 SSPORT - ok 13:01:27.0953 0x0598 [ 41508EA375C97DC2B56E5F1AFC067187, 94D8D49AE3634E861DE501E72813C5320F059C49CC61FA01B2867C99E8B36DB4 ] stisvc C:\WINDOWS\system32\wiaservc.dll 13:01:28.0000 0x0598 stisvc - ok 13:01:28.0046 0x0598 [ 77813007BA6265C4B6098187E6ED79D2, 93939120E803C46FBFD577C8FC2E6C7E71C0460E01D25CB29579490640AB50C7 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 13:01:28.0046 0x0598 streamip - ok 13:01:28.0078 0x0598 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 13:01:28.0078 0x0598 swenum - ok 13:01:28.0156 0x0598 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 13:01:28.0156 0x0598 swmidi - ok 13:01:28.0187 0x0598 SwPrv - ok 13:01:28.0218 0x0598 symc810 - ok 13:01:28.0250 0x0598 symc8xx - ok 13:01:28.0359 0x0598 [ 4C3DEF736D3857570166DE5C858600F5, 45613D3F1935AFDDB1DFE3A427222A0B38430ABF15F9110A35E7C55CDADF1D43 ] SymDS C:\WINDOWS\system32\drivers\NAV\1503000.00C\SYMDS.SYS 13:01:28.0375 0x0598 SymDS - ok 13:01:28.0515 0x0598 [ B70A98F20B4180F2751CFD7656116342, F4BB1904DC4818CE012AA264A7714AA9977F06255CF857FDB3E55B0DBA3D8A9C ] SymEFA C:\WINDOWS\system32\drivers\NAV\1503000.00C\SYMEFA.SYS 13:01:28.0562 0x0598 SymEFA - ok 13:01:28.0609 0x0598 [ E987A9CB539147527F56943BB34B7375, 4627C3E237549587B53CBD0D89AC2CEFF03C04F7624E2868936BCE5D70496AFD ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 13:01:28.0625 0x0598 SymEvent - ok 13:01:28.0734 0x0598 [ E3A3CA230C7547364BB3D9DA0C301A36, 8F173DE08BAF81A7BE7F2D306DC595D60E6537D95AFE32A39E521E43C35AB629 ] SymIRON C:\WINDOWS\system32\drivers\NAV\1503000.00C\Ironx86.SYS 13:01:28.0734 0x0598 SymIRON - ok 13:01:28.0859 0x0598 [ D602FFD15F577256770C82DD2D07214F, 29F1DF9BF1C415B22B8B3E9866E72C74EF0E57B0E7DBE3D42008E9D6647D6120 ] SYMTDI C:\WINDOWS\system32\drivers\NAV\1503000.00C\SYMTDI.SYS 13:01:28.0875 0x0598 SYMTDI - ok 13:01:28.0906 0x0598 sym_hi - ok 13:01:28.0937 0x0598 sym_u3 - ok 13:01:29.0000 0x0598 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 13:01:29.0000 0x0598 sysaudio - ok 13:01:29.0125 0x0598 [ D911A08BE2480E364BDCEFD0ABBD97CC, D4EBF37DB4951E7D4CEA19622906CA6A6D0C6277F108184722DFF82E2C645159 ] syshost32 C:\WINDOWS\Installer\{3469CA44-9B17-89EF-F40D-B9B5D3949C56}\syshost.exe 13:01:29.0125 0x0598 syshost32 - ok 13:01:29.0218 0x0598 [ E42048198518F9162027A9984CBB7B5C, 2634DE2B1AE9D856966F40BFB41AD951A41E11C557C4B27E61CFF63288B53D52 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 13:01:29.0218 0x0598 SysmonLog - ok 13:01:29.0281 0x0598 [ 2340E6977548038C88E39A9ECBB3FADC, B8992F5E0689B307B8CC162032B398950FB07C4B4EF997431F7B344351406586 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 13:01:29.0296 0x0598 TapiSrv - ok 13:01:29.0375 0x0598 [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 13:01:29.0390 0x0598 Tcpip - ok 13:01:29.0437 0x0598 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 13:01:29.0437 0x0598 TDPIPE - ok 13:01:29.0468 0x0598 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 13:01:29.0468 0x0598 TDTCP - ok 13:01:29.0484 0x0598 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 13:01:29.0500 0x0598 TermDD - ok 13:01:29.0578 0x0598 [ 52E0505408EDD4AB5CCC7F83B67B4299, 93DBA3282025C81DC43D4B43861A6CB30C9557CD0108D4D7E0C3B1269699CF22 ] TermService C:\WINDOWS\System32\termsrv.dll 13:01:29.0609 0x0598 TermService - ok 13:01:29.0703 0x0598 [ 8AD90ED829B8404D962545ED3EFB1129, 450027B23223C7BC9C4B344ABF98CF31A173AE3390009E7253CCADF60E6DA8D2 ] Themes C:\WINDOWS\System32\shsvcs.dll 13:01:29.0718 0x0598 Themes - ok 13:01:29.0796 0x0598 [ B17551AB6EAA71DCA530632C15FA3D9A, C80F22CEB4C1DBDE4C00061732A271C2C097BAD72A77E350E4B5E3DBECBA3903 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 13:01:29.0796 0x0598 TlntSvr - ok 13:01:29.0812 0x0598 TosIde - ok 13:01:29.0875 0x0598 [ 9E70EB419D7785C286DC458A019BAB9B, 3901C6B9C9C197FED9C1039F2EBE0C5ACE240512ABBFECB388CAD201CE032760 ] TrkWks C:\WINDOWS\system32\trkwks.dll 13:01:29.0875 0x0598 TrkWks - ok 13:01:29.0937 0x0598 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 13:01:29.0937 0x0598 Udfs - ok 13:01:29.0953 0x0598 ultra - ok 13:01:30.0015 0x0598 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 13:01:30.0031 0x0598 Update - ok 13:01:30.0234 0x0598 [ F648748795C1CAF8B44C28B4F8F3C6A6, 217E498775CFED2DA37391EBCCEDE5494C3DCEE839C1E65B629310E14918DA35 ] Update Rock Turner C:\Program Files\Rock Turner\updateRockTurner.exe 13:01:30.0250 0x0598 Update Rock Turner - ok 13:01:30.0328 0x0598 [ E636773ED8BF116463427C32D75F86A3, 871D1EA2314F893847471CD884D6E33BFF1CCADCA60FB87D31F9F29CB7D7FB41 ] UpdaterSvcRockTurner C:\Program Files\Rock Turner\updater.exe 13:01:30.0328 0x0598 UpdaterSvcRockTurner - ok 13:01:30.0421 0x0598 [ E96A6BAEE0B2A14A38B45830D6E30697, 12314B1D96E025718F965C091E3CAD2865EDDAACA2E60A1A0DAF25630AE66B72 ] upnphost C:\WINDOWS\System32\upnphost.dll 13:01:30.0437 0x0598 upnphost - ok 13:01:30.0468 0x0598 [ EB90E28B28541EC845E5345609355CA7, 60C8DF04EB5839AB1B8625C385F4B2089C63FE613463026F779B331D9BC4D4D6 ] UPS C:\WINDOWS\System32\ups.exe 13:01:30.0484 0x0598 UPS - ok 13:01:30.0546 0x0598 [ 173F317CE0DB8E21322E71B7E60A27E8, 7042441BA63AE38AE9D7BE0BC5CA7404FC9EE5BB3F084604A68F01E82769652A ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys 13:01:30.0546 0x0598 usbccgp - ok 13:01:30.0640 0x0598 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 13:01:30.0640 0x0598 usbehci - ok 13:01:30.0703 0x0598 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 13:01:30.0703 0x0598 usbhub - ok 13:01:30.0734 0x0598 [ 0DAECCE65366EA32B162F85F07C6753B, 3C33AC2FC95E876933F2016CF0CDA2745491679728684DA8DF95A515CE4804BD ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys 13:01:30.0734 0x0598 usbohci - ok 13:01:30.0828 0x0598 [ A717C8721046828520C9EDF31288FC00, 1530BBE832EDBB0974AD89D723A03FF7A0094B368992D73C2C3E62A181DF1E0A ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys 13:01:30.0828 0x0598 usbprint - ok 13:01:30.0875 0x0598 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys 13:01:30.0875 0x0598 usbscan - ok 13:01:31.0000 0x0598 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 13:01:31.0015 0x0598 USBSTOR - ok 13:01:31.0078 0x0598 [ 63BBFCA7F390F4C49ED4B96BFB1633E0, AEB89CF43376709CDD715D844E8CBB8F2BE24D39795F45F7C84F21962F3A52AB ] usbvideo C:\WINDOWS\system32\Drivers\usbvideo.sys 13:01:31.0093 0x0598 usbvideo - ok 13:01:31.0140 0x0598 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 13:01:31.0140 0x0598 VgaSave - ok 13:01:31.0171 0x0598 ViaIde - ok 13:01:31.0203 0x0598 [ 56B191AC5FC0DF219949C95A6C87AFE7, 5DCD42BD686869B394CFB9EFD727DCEEEAE239326DDE3D1655C456FCAE949D9F ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 13:01:31.0203 0x0598 VolSnap - ok 13:01:31.0265 0x0598 [ 7F2D7BFFC4554E1C742DD3629FD1FB1B, 4BFFC8A67F98AF69039DF0AFF1FDA11CFAD6464066E8ED92090D48392C43B6ED ] VSS C:\WINDOWS\System32\vssvc.exe 13:01:31.0296 0x0598 VSS - ok 13:01:31.0390 0x0598 [ A672CA3981352F8E9C30FEA056E80A62, 9AD34EFEB11EFEB234A246639FADF036F49FC67E542C4DE78D7C01E75BC62B59 ] W32Time C:\WINDOWS\system32\w32time.dll 13:01:31.0390 0x0598 W32Time - ok 13:01:31.0453 0x0598 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:01:31.0453 0x0598 Wanarp - ok 13:01:31.0468 0x0598 WDICA - ok 13:01:31.0546 0x0598 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 13:01:31.0546 0x0598 wdmaud - ok 13:01:31.0578 0x0598 [ 81FB88B975E25D76E00B69879D8A434C, 2340CEE200CA3F0A546F88AAD3AFDCFD0805DB027E8480B4280D92E14F6C1F69 ] WebClient C:\WINDOWS\System32\webclnt.dll 13:01:31.0593 0x0598 WebClient - ok 13:01:31.0703 0x0598 [ 70C22297534A88B0AD0568900AB5A6D9, 2457D9B21CD8633D6A59FC053B70B9282A64066789EC020A9F2C937141E95C61 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 13:01:31.0703 0x0598 winmgmt - ok 13:01:31.0812 0x0598 [ 0A824C0FB380CE41D1C5B8E14E006142, 39EF8FAC2926F0B97BC4B94507F2C2F1D22523C361E71BD33DD5622EC3DD6239 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll 13:01:31.0812 0x0598 WmdmPmSN - ok 13:01:31.0937 0x0598 [ AFCE55C392A9676BD24A287D5ED1C777, DFFF02131F25710BDD8F1BD51D3638E70662B67EE9E68153FFF83124E475F762 ] Wmi C:\WINDOWS\System32\advapi32.dll 13:01:32.0000 0x0598 Wmi - ok 13:01:32.0046 0x0598 [ A2B12D80A1670511B047A7D8BB647598, BDE141A77034608D926624583D252650D01B64EC2B3E8156A61D735C79E2A0E6 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 13:01:32.0062 0x0598 WmiApSrv - ok 13:01:32.0171 0x0598 Wpm - ok 13:01:32.0250 0x0598 [ B6669F49D42E09BC0F9889FAA0F3336D, B6147A60F763E562E26495A6ACAE759492A52AE3BEFEA4BF40B8874E4CF069F1 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 13:01:32.0250 0x0598 wscsvc - ok 13:01:32.0312 0x0598 [ C98B39829C2BBD34E454150633C62C78, 71B60EA3AD0E2637917D528C6A9E7ECF2949E3E5E91036AA5BBADA95BD725511 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 13:01:32.0312 0x0598 WSTCODEC - ok 13:01:32.0359 0x0598 [ 04550D5EB7EE82C115DB547C01DF09FD, 6A4D1E5F4E1C641B47BB48489D4205531597E942E02ECD75BCFA856F60A938B0 ] wuauserv C:\WINDOWS\system32\wuauserv.dll 13:01:32.0375 0x0598 wuauserv - ok 13:01:32.0437 0x0598 [ C2842273AAA77AC031EDB87FA19A2147, 8542392E337C543BCD9EDC7A15DC6E8DE8E9B8041CC7A8D707217C9FF0446882 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 13:01:32.0468 0x0598 WZCSVC - ok 13:01:32.0531 0x0598 [ 24ED6935771359A5AEF1FE8BF0C56F39, F0C3B781853714F48DE4F42533A7236CE11076208F190E79500F8A77C9CF9849 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 13:01:32.0531 0x0598 xmlprov - ok 13:01:32.0671 0x0598 [ DF9D7C73508E8D8D853BA24927C05245, BD7D0FA1DC2EFF6DC89FCBA7FC1BF4A50420F9F87CE2F03535C555DA85480BCF ] {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t C:\WINDOWS\system32\drivers\{b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t.sys 13:01:32.0687 0x0598 {b2db3058-74ee-4ace-bcd8-8cd0fbe3a4f6}t - ok 13:01:32.0687 0x0598 ================ Scan global =============================== 13:01:32.0765 0x0598 [ 65C782F8CFC1BEBCC58E1532F44B6408, D5EB7357F37AC9CEF96BC1BCACE765B2897E502D699E64145EFA4DD62BCCE80B ] C:\WINDOWS\system32\basesrv.dll 13:01:32.0796 0x0598 [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 13:01:32.0875 0x0598 [ 3DA6293977416933EC37C5B7D9C77188, 9B7ECC4B3376DDDD8B57F91767482C59A47336DE527FAE85B49AE1F96BC67FC9 ] C:\WINDOWS\system32\winsrv.dll 13:01:32.0906 0x0598 [ 02A467E27AF55F7064C5B251E587315F, 309D6C6ABC9D7786354758C107B89C50AC722AEA3B10631714F326AB2D3BB3DF ] C:\WINDOWS\system32\services.exe 13:01:32.0921 0x0598 [ Global ] - ok 13:01:32.0921 0x0598 ================ Scan MBR ================================== 13:01:32.0937 0x0598 [ 32052574BF9F325AE309ABC7BFD04460 ] \Device\Harddisk0\DR0 13:01:33.0156 0x0598 \Device\Harddisk0\DR0 - ok 13:01:33.0156 0x0598 ================ Scan VBR ================================== 13:01:33.0171 0x0598 [ BC3ADF3801EB69F27330CDF0AB64C9A2 ] \Device\Harddisk0\DR0\Partition1 13:01:33.0171 0x0598 \Device\Harddisk0\DR0\Partition1 - ok 13:01:33.0187 0x0598 [ D95F41E713940FB21BFA4C5FD705F7DE ] \Device\Harddisk0\DR0\Partition2 13:01:33.0203 0x0598 \Device\Harddisk0\DR0\Partition2 - ok 13:01:33.0203 0x0598 Waiting for KSN requests completion. In queue: 236 13:01:34.0203 0x0598 Waiting for KSN requests completion. In queue: 236 13:01:35.0203 0x0598 Waiting for KSN requests completion. In queue: 236 13:01:36.0203 0x0598 Waiting for KSN requests completion. In queue: 236 13:01:37.0203 0x0598 Waiting for KSN requests completion. In queue: 236 13:01:38.0203 0x0598 Have new async UDS detects: 1 13:01:38.0203 0x0598 syshost32 - detected UDS:DangerousObject.Multi.Generic ( 0 ) 13:01:38.0203 0x0598 syshost32 ( UDS:DangerousObject.Multi.Generic ) - infected 13:01:38.0203 0x0598 Force sending object to P2P due to detect: C:\WINDOWS\Installer\{3469CA44-9B17-89EF-F40D-B9B5D3949C56}\syshost.exe 13:01:52.0218 0x0598 Object send P2P result: true 13:01:55.0078 0x0598 Win FW state via NFM: disabled 13:01:57.0812 0x0598 ============================================================ 13:01:57.0812 0x0598 Scan finished 13:01:57.0812 0x0598 ============================================================ 13:01:57.0812 0x05ac Detected object count: 2 13:01:57.0812 0x05ac Actual detected object count: 2 13:02:15.0015 0x05ac C:\WINDOWS\System32\Drivers\3fc68e249a2755ff.sys - copied to quarantine 13:02:15.0093 0x05ac HKLM\SYSTEM\ControlSet001\services\3fc68e249a2755ff - will be deleted on reboot 13:02:15.0343 0x05ac C:\WINDOWS\System32\Drivers\3fc68e249a2755ff.sys - will be deleted on reboot 13:02:15.0343 0x05ac 3fc68e249a2755ff ( Rootkit.Win32.Necurs.gen ) - User select action: Delete 13:02:15.0421 0x05ac C:\WINDOWS\Installer\{3469CA44-9B17-89EF-F40D-B9B5D3949C56}\syshost.exe - copied to quarantine 13:02:15.0421 0x05ac HKLM\SYSTEM\ControlSet001\services\syshost32 - will be deleted on reboot 13:02:15.0531 0x05ac C:\WINDOWS\Installer\{3469CA44-9B17-89EF-F40D-B9B5D3949C56}\syshost.exe - will be deleted on reboot 13:02:15.0531 0x05ac syshost32 ( UDS:DangerousObject.Multi.Generic ) - User select action: Delete 13:02:16.0703 0x05ac KLMD registered as C:\WINDOWS\system32\drivers\62415852.sys 13:02:56.0625 0x0520 Deinitialize success