Format du document : text/plain
Prévisualisation
14:29:24.0700 3132 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
14:29:24.0944 3132 ============================================================
14:29:24.0944 3132 Current date / time: 2013/04/12 14:29:24.0944
14:29:24.0944 3132 SystemInfo:
14:29:24.0944 3132
14:29:24.0944 3132 OS Version: 6.1.7601 ServicePack: 1.0
14:29:24.0944 3132 Product type: Workstation
14:29:24.0945 3132 ComputerName: DANOULH-PC
14:29:24.0945 3132 UserName: Danoulh
14:29:24.0945 3132 Windows directory: C:\Windows
14:29:24.0945 3132 System windows directory: C:\Windows
14:29:24.0945 3132 Processor architecture: Intel x86
14:29:24.0945 3132 Number of processors: 2
14:29:24.0945 3132 Page size: 0x1000
14:29:24.0945 3132 Boot type: Normal boot
14:29:24.0945 3132 ============================================================
14:29:28.0147 3132 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:29:28.0151 3132 ============================================================
14:29:28.0151 3132 \Device\Harddisk0\DR0:
14:29:28.0152 3132 MBR partitions:
14:29:28.0152 3132 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x950C800
14:29:28.0152 3132 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x97FB000, BlocksNum 0x921E800
14:29:28.0152 3132 ============================================================
14:29:28.0205 3132 C: <-> \Device\Harddisk0\DR0\Partition1
14:29:28.0265 3132 D: <-> \Device\Harddisk0\DR0\Partition2
14:29:28.0286 3132 ============================================================
14:29:28.0287 3132 Initialize success
14:29:28.0287 3132 ============================================================
14:30:26.0963 2980 ============================================================
14:30:26.0963 2980 Scan started
14:30:26.0963 2980 Mode: Manual;
14:30:26.0963 2980 ============================================================
14:30:28.0055 2980 ================ Scan system memory ========================
14:30:28.0055 2980 System memory - ok
14:30:28.0055 2980 ================ Scan services =============================
14:30:28.0376 2980 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
14:30:28.0586 2980 1394ohci - ok
14:30:28.0628 2980 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
14:30:28.0861 2980 ACPI - ok
14:30:28.0907 2980 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
14:30:29.0068 2980 AcpiPmi - ok
14:30:29.0181 2980 [ 479901C99FA62D1C3261B7ACB1228DAD ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
14:30:29.0184 2980 AdobeFlashPlayerUpdateSvc - ok
14:30:29.0271 2980 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
14:30:29.0282 2980 adp94xx - ok
14:30:29.0310 2980 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
14:30:29.0324 2980 adpahci - ok
14:30:29.0352 2980 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
14:30:29.0360 2980 adpu320 - ok
14:30:29.0407 2980 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
14:30:29.0408 2980 AeLookupSvc - ok
14:30:29.0476 2980 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
14:30:29.0693 2980 AFD - ok
14:30:29.0805 2980 [ 7E10E3BB9B258AD8A9300F91214D67B9 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
14:30:29.0849 2980 AgereSoftModem - ok
14:30:29.0893 2980 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
14:30:29.0897 2980 agp440 - ok
14:30:29.0969 2980 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
14:30:29.0974 2980 aic78xx - ok
14:30:30.0034 2980 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
14:30:30.0038 2980 ALG - ok
14:30:30.0070 2980 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
14:30:30.0073 2980 aliide - ok
14:30:30.0124 2980 [ B19505648F033393E907E2E419FDE8B3 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
14:30:30.0281 2980 AMD External Events Utility - ok
14:30:30.0350 2980 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
14:30:30.0354 2980 amdagp - ok
14:30:30.0393 2980 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
14:30:30.0396 2980 amdide - ok
14:30:30.0449 2980 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
14:30:30.0452 2980 AmdK8 - ok
14:30:30.0461 2980 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
14:30:30.0465 2980 AmdPPM - ok
14:30:30.0501 2980 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
14:30:30.0671 2980 amdsata - ok
14:30:30.0718 2980 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
14:30:30.0725 2980 amdsbs - ok
14:30:30.0742 2980 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
14:30:30.0931 2980 amdxata - ok
14:30:31.0001 2980 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
14:30:31.0220 2980 AppID - ok
14:30:31.0289 2980 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
14:30:31.0291 2980 AppIDSvc - ok
14:30:31.0327 2980 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
14:30:31.0489 2980 Appinfo - ok
14:30:31.0549 2980 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
14:30:31.0558 2980 AppMgmt - ok
14:30:31.0606 2980 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
14:30:31.0612 2980 arc - ok
14:30:31.0636 2980 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
14:30:31.0641 2980 arcsas - ok
14:30:31.0671 2980 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
14:30:31.0675 2980 AsyncMac - ok
14:30:31.0721 2980 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
14:30:31.0722 2980 atapi - ok
14:30:31.0784 2980 ATE_PROCMON - ok
14:30:32.0010 2980 [ 04F09923A393E4E0E8453A8F78361E73 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
14:30:32.0611 2980 atikmdag - ok
14:30:32.0706 2980 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
14:30:32.0915 2980 AudioEndpointBuilder - ok
14:30:32.0953 2980 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
14:30:32.0958 2980 Audiosrv - ok
14:30:33.0058 2980 AV Engine Scanning Service - ok
14:30:33.0066 2980 AVFSFilter - ok
14:30:33.0116 2980 [ E644F61E46E1353ECB432BD3FA76CB20 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
14:30:33.0302 2980 avgtp - ok
14:30:33.0365 2980 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
14:30:33.0562 2980 AxInstSV - ok
14:30:33.0625 2980 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
14:30:33.0641 2980 b06bdrv - ok
14:30:33.0688 2980 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
14:30:33.0698 2980 b57nd60x - ok
14:30:33.0755 2980 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
14:30:33.0759 2980 BDESVC - ok
14:30:33.0781 2980 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
14:30:33.0783 2980 Beep - ok
14:30:33.0800 2980 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
14:30:33.0803 2980 blbdrive - ok
14:30:33.0850 2980 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
14:30:34.0107 2980 bowser - ok
14:30:34.0144 2980 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
14:30:34.0147 2980 BrFiltLo - ok
14:30:34.0160 2980 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
14:30:34.0162 2980 BrFiltUp - ok
14:30:34.0208 2980 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
14:30:34.0373 2980 Browser - ok
14:30:34.0411 2980 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
14:30:34.0421 2980 Brserid - ok
14:30:34.0442 2980 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
14:30:34.0446 2980 BrSerWdm - ok
14:30:34.0468 2980 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
14:30:34.0470 2980 BrUsbMdm - ok
14:30:34.0507 2980 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
14:30:34.0509 2980 BrUsbSer - ok
14:30:34.0525 2980 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
14:30:34.0549 2980 BTHMODEM - ok
14:30:34.0610 2980 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
14:30:34.0614 2980 bthserv - ok
14:30:34.0645 2980 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
14:30:34.0647 2980 cdfs - ok
14:30:34.0711 2980 [ 83AA066BBB9310BD654EBF9FDC0DCF4B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
14:30:34.0847 2980 Suspicious file (Forged): C:\Windows\system32\DRIVERS\cdrom.sys. Real md5: 83AA066BBB9310BD654EBF9FDC0DCF4B, Fake md5: BE167ED0FDB9C1FA1133953C18D5A6C9
14:30:34.0848 2980 cdrom ( Virus.Win32.ZAccess.aml ) - infected
14:30:34.0848 2980 cdrom - detected Virus.Win32.ZAccess.aml (0)
14:30:34.0903 2980 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
14:30:35.0044 2980 CertPropSvc - ok
14:30:35.0081 2980 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
14:30:35.0085 2980 circlass - ok
14:30:35.0127 2980 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
14:30:35.0136 2980 CLFS - ok
14:30:35.0229 2980 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:30:35.0235 2980 clr_optimization_v2.0.50727_32 - ok
14:30:35.0345 2980 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
14:30:35.0351 2980 clr_optimization_v4.0.30319_32 - ok
14:30:35.0386 2980 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
14:30:35.0388 2980 CmBatt - ok
14:30:35.0518 2980 [ 2A2D72271844C52F004901A60312B96A ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
14:30:35.0537 2980 cmdAgent - ok
14:30:35.0556 2980 [ A1A240C4BC6ABAAB75E0D25F51B09591 ] cmderd C:\Windows\system32\DRIVERS\cmderd.sys
14:30:35.0558 2980 cmderd - ok
14:30:35.0587 2980 [ A1865742BBCF4C5F38FEE1258F8048FD ] cmdGuard C:\Windows\system32\DRIVERS\cmdguard.sys
14:30:35.0598 2980 cmdGuard - ok
14:30:35.0619 2980 [ 221D000474F01B1606FFC3FF362D9333 ] cmdHlp C:\Windows\system32\DRIVERS\cmdhlp.sys
14:30:35.0621 2980 cmdHlp - ok
14:30:35.0676 2980 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
14:30:35.0678 2980 cmdide - ok
14:30:35.0735 2980 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
14:30:35.0750 2980 CNG - ok
14:30:35.0796 2980 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
14:30:35.0798 2980 Compbatt - ok
14:30:35.0843 2980 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
14:30:36.0035 2980 CompositeBus - ok
14:30:36.0072 2980 COMSysApp - ok
14:30:36.0092 2980 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
14:30:36.0095 2980 crcdisk - ok
14:30:36.0157 2980 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
14:30:36.0373 2980 CryptSvc - ok
14:30:36.0423 2980 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
14:30:36.0649 2980 CSC - ok
14:30:36.0718 2980 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
14:30:36.0920 2980 CscService - ok
14:30:36.0982 2980 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
14:30:36.0988 2980 DcomLaunch - ok
14:30:37.0035 2980 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
14:30:37.0045 2980 defragsvc - ok
14:30:37.0100 2980 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
14:30:37.0293 2980 DfsC - ok
14:30:37.0387 2980 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
14:30:37.0623 2980 Dhcp - ok
14:30:37.0657 2980 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
14:30:37.0660 2980 discache - ok
14:30:37.0720 2980 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
14:30:37.0724 2980 Disk - ok
14:30:37.0770 2980 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
14:30:37.0982 2980 Dnscache - ok
14:30:38.0019 2980 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
14:30:38.0236 2980 dot3svc - ok
14:30:38.0310 2980 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
14:30:38.0512 2980 DPS - ok
14:30:38.0581 2980 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
14:30:38.0583 2980 drmkaud - ok
14:30:38.0677 2980 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
14:30:38.0692 2980 dtsoftbus01 - ok
14:30:38.0765 2980 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
14:30:38.0980 2980 DXGKrnl - ok
14:30:39.0054 2980 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
14:30:39.0060 2980 EapHost - ok
14:30:39.0209 2980 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
14:30:39.0320 2980 ebdrv - ok
14:30:39.0353 2980 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
14:30:39.0356 2980 EFS - ok
14:30:39.0449 2980 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
14:30:39.0681 2980 ehRecvr - ok
14:30:39.0716 2980 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
14:30:39.0721 2980 ehSched - ok
14:30:39.0791 2980 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
14:30:39.0812 2980 elxstor - ok
14:30:39.0826 2980 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
14:30:39.0828 2980 ErrDev - ok
14:30:39.0899 2980 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
14:30:39.0904 2980 EventSystem - ok
14:30:39.0942 2980 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
14:30:39.0947 2980 exfat - ok
14:30:40.0118 2980 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
14:30:40.0123 2980 fastfat - ok
14:30:40.0209 2980 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
14:30:40.0444 2980 Fax - ok
14:30:40.0485 2980 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
14:30:40.0489 2980 fdc - ok
14:30:40.0526 2980 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
14:30:40.0529 2980 fdPHost - ok
14:30:40.0543 2980 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
14:30:40.0547 2980 FDResPub - ok
14:30:40.0583 2980 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
14:30:40.0586 2980 FileInfo - ok
14:30:40.0599 2980 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
14:30:40.0602 2980 Filetrace - ok
14:30:40.0615 2980 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
14:30:40.0618 2980 flpydisk - ok
14:30:40.0662 2980 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
14:30:40.0670 2980 FltMgr - ok
14:30:40.0748 2980 [ E12C4928B32ACE04610259647F072635 ] FontCache C:\Windows\system32\FntCache.dll
14:30:40.0976 2980 FontCache - ok
14:30:41.0087 2980 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
14:30:41.0091 2980 FontCache3.0.0.0 - ok
14:30:41.0129 2980 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
14:30:41.0134 2980 FsDepends - ok
14:30:41.0165 2980 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
14:30:41.0329 2980 Fs_Rec - ok
14:30:41.0414 2980 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
14:30:41.0693 2980 fvevol - ok
14:30:41.0746 2980 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
14:30:41.0750 2980 gagp30kx - ok
14:30:41.0796 2980 [ 1BFABBB4C99E1FDBC7B756BE39868D03 ] gfiark C:\Windows\system32\drivers\gfiark.sys
14:30:41.0801 2980 gfiark - ok
14:30:41.0856 2980 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
14:30:41.0867 2980 gpsvc - ok
14:30:41.0920 2980 [ 833051C6C6C42117191935F734CFBD97 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
14:30:41.0924 2980 hamachi - ok
14:30:42.0193 2980 [ 6D12BDA1715C38BE1746B195B1E4337E ] Hamachi2Svc C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
14:30:42.0418 2980 Hamachi2Svc - ok
14:30:42.0463 2980 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
14:30:42.0465 2980 hcw85cir - ok
14:30:42.0537 2980 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
14:30:42.0728 2980 HdAudAddService - ok
14:30:42.0763 2980 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
14:30:42.0958 2980 HDAudBus - ok
14:30:42.0972 2980 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
14:30:42.0975 2980 HidBatt - ok
14:30:43.0006 2980 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
14:30:43.0011 2980 HidBth - ok
14:30:43.0038 2980 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
14:30:43.0042 2980 HidIr - ok
14:30:43.0088 2980 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
14:30:43.0092 2980 hidserv - ok
14:30:43.0160 2980 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
14:30:43.0322 2980 HidUsb - ok
14:30:43.0356 2980 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
14:30:43.0508 2980 hkmsvc - ok
14:30:43.0553 2980 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
14:30:43.0729 2980 HomeGroupListener - ok
14:30:43.0767 2980 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
14:30:43.0975 2980 HomeGroupProvider - ok
14:30:44.0059 2980 HOSTS Anti-PUPs - ok
14:30:44.0115 2980 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
14:30:44.0121 2980 HpSAMD - ok
14:30:44.0196 2980 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
14:30:44.0435 2980 HTTP - ok
14:30:44.0472 2980 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
14:30:44.0633 2980 hwpolicy - ok
14:30:44.0709 2980 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
14:30:44.0711 2980 i8042prt - ok
14:30:44.0767 2980 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
14:30:45.0013 2980 iaStorV - ok
14:30:45.0128 2980 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:30:45.0401 2980 idsvc - ok
14:30:45.0444 2980 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
14:30:45.0447 2980 iirsp - ok
14:30:45.0515 2980 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
14:30:45.0717 2980 IKEEXT - ok
14:30:45.0754 2980 [ 3B6BE2DA5993B1E38613976FAF4AC83E ] inspect C:\Windows\system32\DRIVERS\inspect.sys
14:30:45.0757 2980 inspect - ok
14:30:45.0800 2980 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
14:30:45.0802 2980 intelide - ok
14:30:45.0861 2980 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
14:30:45.0865 2980 intelppm - ok
14:30:45.0899 2980 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
14:30:45.0904 2980 IPBusEnum - ok
14:30:45.0920 2980 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
14:30:45.0924 2980 IpFilterDriver - ok
14:30:46.0087 2980 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
14:30:46.0233 2980 IPMIDRV - ok
14:30:46.0259 2980 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
14:30:46.0262 2980 IPNAT - ok
14:30:46.0290 2980 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
14:30:46.0292 2980 IRENUM - ok
14:30:46.0326 2980 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
14:30:46.0330 2980 isapnp - ok
14:30:46.0352 2980 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
14:30:46.0564 2980 iScsiPrt - ok
14:30:46.0604 2980 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
14:30:46.0607 2980 kbdclass - ok
14:30:46.0660 2980 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
14:30:46.0830 2980 kbdhid - ok
14:30:46.0853 2980 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
14:30:46.0856 2980 KeyIso - ok
14:30:46.0897 2980 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
14:30:46.0900 2980 KSecDD - ok
14:30:46.0917 2980 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
14:30:46.0923 2980 KSecPkg - ok
14:30:46.0980 2980 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
14:30:46.0996 2980 KtmRm - ok
14:30:47.0032 2980 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
14:30:47.0242 2980 LanmanServer - ok
14:30:47.0289 2980 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
14:30:47.0445 2980 LanmanWorkstation - ok
14:30:47.0511 2980 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
14:30:47.0515 2980 lltdio - ok
14:30:47.0561 2980 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
14:30:47.0571 2980 lltdsvc - ok
14:30:47.0594 2980 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
14:30:47.0598 2980 lmhosts - ok
14:30:47.0635 2980 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
14:30:47.0640 2980 LSI_FC - ok
14:30:47.0656 2980 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
14:30:47.0661 2980 LSI_SAS - ok
14:30:47.0680 2980 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
14:30:47.0684 2980 LSI_SAS2 - ok
14:30:47.0707 2980 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
14:30:47.0712 2980 LSI_SCSI - ok
14:30:47.0756 2980 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
14:30:47.0761 2980 luafv - ok
14:30:47.0798 2980 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
14:30:47.0964 2980 Mcx2Svc - ok
14:30:48.0195 2980 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
14:30:48.0212 2980 MDM - ok
14:30:48.0254 2980 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
14:30:48.0258 2980 megasas - ok
14:30:48.0354 2980 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
14:30:48.0364 2980 MegaSR - ok
14:30:48.0403 2980 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
14:30:48.0407 2980 MMCSS - ok
14:30:48.0429 2980 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
14:30:48.0432 2980 Modem - ok
14:30:48.0473 2980 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
14:30:48.0476 2980 monitor - ok
14:30:48.0506 2980 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
14:30:48.0510 2980 mouclass - ok
14:30:48.0558 2980 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
14:30:48.0579 2980 mouhid - ok
14:30:48.0622 2980 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
14:30:48.0820 2980 mountmgr - ok
14:30:48.0895 2980 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
14:30:49.0114 2980 MozillaMaintenance - ok
14:30:49.0151 2980 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
14:30:49.0361 2980 mpio - ok
14:30:49.0395 2980 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
14:30:49.0399 2980 mpsdrv - ok
14:30:49.0443 2980 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
14:30:49.0672 2980 MRxDAV - ok
14:30:49.0747 2980 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
14:30:49.0946 2980 mrxsmb - ok
14:30:49.0967 2980 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
14:30:50.0200 2980 mrxsmb10 - ok
14:30:50.0209 2980 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
14:30:50.0359 2980 mrxsmb20 - ok
14:30:50.0412 2980 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
14:30:50.0589 2980 msahci - ok
14:30:50.0624 2980 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
14:30:50.0821 2980 msdsm - ok
14:30:50.0847 2980 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
14:30:50.0855 2980 MSDTC - ok
14:30:50.0899 2980 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
14:30:50.0901 2980 Msfs - ok
14:30:50.0916 2980 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
14:30:50.0918 2980 mshidkmdf - ok
14:30:50.0958 2980 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
14:30:50.0960 2980 msisadrv - ok
14:30:51.0018 2980 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
14:30:51.0028 2980 MSiSCSI - ok
14:30:51.0037 2980 msiserver - ok
14:30:51.0069 2980 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
14:30:51.0071 2980 MSKSSRV - ok
14:30:51.0086 2980 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
14:30:51.0088 2980 MSPCLOCK - ok
14:30:51.0138 2980 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
14:30:51.0140 2980 MSPQM - ok
14:30:51.0162 2980 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
14:30:51.0170 2980 MsRPC - ok
14:30:51.0214 2980 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
14:30:51.0216 2980 mssmbios - ok
14:30:51.0239 2980 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
14:30:51.0241 2980 MSTEE - ok
14:30:51.0262 2980 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
14:30:51.0264 2980 MTConfig - ok
14:30:51.0281 2980 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
14:30:51.0284 2980 Mup - ok
14:30:51.0345 2980 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
14:30:51.0517 2980 napagent - ok
14:30:51.0601 2980 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
14:30:51.0612 2980 NativeWifiP - ok
14:30:51.0697 2980 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
14:30:51.0729 2980 NDIS - ok
14:30:51.0772 2980 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
14:30:51.0777 2980 NdisCap - ok
14:30:51.0839 2980 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
14:30:51.0843 2980 NdisTapi - ok
14:30:51.0894 2980 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
14:30:52.0063 2980 Ndisuio - ok
14:30:52.0103 2980 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
14:30:52.0331 2980 NdisWan - ok
14:30:52.0384 2980 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
14:30:52.0551 2980 NDProxy - ok
14:30:52.0608 2980 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
14:30:52.0611 2980 NetBIOS - ok
14:30:52.0655 2980 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
14:30:52.0861 2980 NetBT - ok
14:30:52.0908 2980 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
14:30:52.0912 2980 Netlogon - ok
14:30:52.0984 2980 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
14:30:53.0000 2980 Netman - ok
14:30:53.0037 2980 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
14:30:53.0050 2980 netprofm - ok
14:30:53.0088 2980 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:30:53.0299 2980 NetTcpPortSharing - ok
14:30:53.0484 2980 [ 58218EC6B61B1169CF54AAB0D00F5FE2 ] netw5v32 C:\Windows\system32\DRIVERS\netw5v32.sys
14:30:53.0665 2980 netw5v32 - ok
14:30:53.0717 2980 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
14:30:53.0721 2980 nfrd960 - ok
14:30:53.0763 2980 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll
14:30:53.0962 2980 NlaSvc - ok
14:30:54.0000 2980 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
14:30:54.0004 2980 Npfs - ok
14:30:54.0041 2980 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
14:30:54.0045 2980 nsi - ok
14:30:54.0065 2980 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
14:30:54.0068 2980 nsiproxy - ok
14:30:54.0141 2980 [ 0D87503986BB3DFED58E343FE39DDE13 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
14:30:54.0337 2980 Ntfs - ok
14:30:54.0385 2980 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
14:30:54.0387 2980 Null - ok
14:30:54.0428 2980 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
14:30:54.0596 2980 nvraid - ok
14:30:54.0630 2980 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
14:30:54.0808 2980 nvstor - ok
14:30:54.0834 2980 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
14:30:54.0839 2980 nv_agp - ok
14:30:54.0943 2980 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
14:30:54.0960 2980 odserv - ok
14:30:55.0001 2980 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
14:30:55.0006 2980 ohci1394 - ok
14:30:55.0070 2980 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:30:55.0079 2980 ose - ok
14:30:55.0132 2980 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
14:30:55.0144 2980 p2pimsvc - ok
14:30:55.0196 2980 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
14:30:55.0211 2980 p2psvc - ok
14:30:55.0251 2980 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
14:30:55.0254 2980 Parport - ok
14:30:55.0293 2980 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
14:30:55.0297 2980 partmgr - ok
14:30:55.0324 2980 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
14:30:55.0326 2980 Parvdm - ok
14:30:55.0351 2980 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
14:30:55.0360 2980 PcaSvc - ok
14:30:55.0411 2980 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
14:30:55.0413 2980 pci - ok
14:30:55.0428 2980 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
14:30:55.0431 2980 pciide - ok
14:30:55.0460 2980 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
14:30:55.0468 2980 pcmcia - ok
14:30:55.0512 2980 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
14:30:55.0515 2980 pcw - ok
14:30:55.0563 2980 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
14:30:55.0589 2980 PEAUTH - ok
14:30:55.0678 2980 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
14:30:55.0720 2980 PeerDistSvc - ok
14:30:55.0824 2980 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
14:30:56.0068 2980 pla - ok
14:30:56.0155 2980 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
14:30:56.0358 2980 PlugPlay - ok
14:30:56.0410 2980 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
14:30:56.0414 2980 PNRPAutoReg - ok
14:30:56.0443 2980 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
14:30:56.0449 2980 PNRPsvc - ok
14:30:56.0509 2980 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
14:30:56.0710 2980 PolicyAgent - ok
14:30:56.0759 2980 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
14:30:56.0969 2980 Power - ok
14:30:57.0025 2980 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
14:30:57.0030 2980 PptpMiniport - ok
14:30:57.0056 2980 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
14:30:57.0059 2980 Processor - ok
14:30:57.0127 2980 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
14:30:57.0340 2980 ProfSvc - ok
14:30:57.0387 2980 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
14:30:57.0390 2980 ProtectedStorage - ok
14:30:57.0422 2980 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
14:30:57.0430 2980 Psched - ok
14:30:57.0493 2980 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
14:30:57.0543 2980 ql2300 - ok
14:30:57.0578 2980 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
14:30:57.0584 2980 ql40xx - ok
14:30:57.0624 2980 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
14:30:57.0636 2980 QWAVE - ok
14:30:57.0655 2980 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
14:30:57.0658 2980 QWAVEdrv - ok
14:30:57.0675 2980 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
14:30:57.0678 2980 RasAcd - ok
14:30:57.0734 2980 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
14:30:57.0738 2980 RasAgileVpn - ok
14:30:57.0763 2980 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
14:30:57.0770 2980 RasAuto - ok
14:30:57.0797 2980 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
14:30:57.0800 2980 Rasl2tp - ok
14:30:57.0871 2980 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
14:30:58.0174 2980 RasMan - ok
14:30:58.0223 2980 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
14:30:58.0229 2980 RasPppoe - ok
14:30:58.0257 2980 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
14:30:58.0262 2980 RasSstp - ok
14:30:58.0311 2980 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
14:30:58.0554 2980 rdbss - ok
14:30:58.0588 2980 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
14:30:58.0590 2980 rdpbus - ok
14:30:58.0629 2980 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
14:30:58.0764 2980 RDPCDD - ok
14:30:58.0809 2980 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
14:30:59.0012 2980 RDPDR - ok
14:30:59.0074 2980 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
14:30:59.0077 2980 RDPENCDD - ok
14:30:59.0089 2980 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
14:30:59.0092 2980 RDPREFMP - ok
14:30:59.0155 2980 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
14:30:59.0365 2980 RdpVideoMiniport - ok
14:30:59.0427 2980 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
14:30:59.0605 2980 RDPWD - ok
14:30:59.0691 2980 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
14:30:59.0874 2980 rdyboost - ok
14:30:59.0941 2980 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
14:30:59.0949 2980 RemoteAccess - ok
14:31:00.0000 2980 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
14:31:00.0013 2980 RemoteRegistry - ok
14:31:00.0086 2980 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
14:31:00.0093 2980 RpcEptMapper - ok
14:31:00.0136 2980 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
14:31:00.0141 2980 RpcLocator - ok
14:31:00.0184 2980 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
14:31:00.0194 2980 RpcSs - ok
14:31:00.0253 2980 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
14:31:00.0258 2980 rspndr - ok
14:31:00.0311 2980 [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
14:31:00.0318 2980 RTL8167 - ok
14:31:00.0364 2980 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
14:31:00.0532 2980 s3cap - ok
14:31:00.0598 2980 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
14:31:00.0603 2980 SamSs - ok
14:31:00.0659 2980 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
14:31:00.0823 2980 sbp2port - ok
14:31:00.0862 2980 SBRE - ok
14:31:00.0912 2980 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
14:31:00.0921 2980 SCardSvr - ok
14:31:00.0962 2980 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
14:31:01.0122 2980 scfilter - ok
14:31:01.0184 2980 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
14:31:01.0396 2980 Schedule - ok
14:31:01.0449 2980 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
14:31:01.0451 2980 SCPolicySvc - ok
14:31:01.0489 2980 [ 0328BE1C7F1CBA23848179F8762E391C ] sdbus C:\Windows\system32\drivers\sdbus.sys
14:31:01.0630 2980 sdbus - ok
14:31:01.0674 2980 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
14:31:01.0854 2980 SDRSVC - ok
14:31:01.0913 2980 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
14:31:01.0916 2980 secdrv - ok
14:31:01.0959 2980 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
14:31:01.0964 2980 seclogon - ok
14:31:02.0008 2980 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
14:31:02.0014 2980 SENS - ok
14:31:02.0052 2980 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
14:31:02.0058 2980 SensrSvc - ok
14:31:02.0078 2980 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
14:31:02.0081 2980 Serenum - ok
14:31:02.0108 2980 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
14:31:02.0113 2980 Serial - ok
14:31:02.0148 2980 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
14:31:02.0150 2980 sermouse - ok
14:31:02.0210 2980 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
14:31:02.0358 2980 SessionEnv - ok
14:31:02.0405 2980 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
14:31:02.0407 2980 sffdisk - ok
14:31:02.0421 2980 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
14:31:02.0426 2980 sffp_mmc - ok
14:31:02.0445 2980 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
14:31:02.0634 2980 sffp_sd - ok
14:31:02.0703 2980 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
14:31:02.0707 2980 sfloppy - ok
14:31:02.0764 2980 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
14:31:02.0953 2980 ShellHWDetection - ok
14:31:03.0000 2980 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
14:31:03.0004 2980 sisagp - ok
14:31:03.0045 2980 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
14:31:03.0048 2980 SiSRaid2 - ok
14:31:03.0071 2980 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
14:31:03.0076 2980 SiSRaid4 - ok
14:31:03.0115 2980 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
14:31:03.0117 2980 Smb - ok
14:31:03.0186 2980 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
14:31:03.0191 2980 SNMPTRAP - ok
14:31:03.0238 2980 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
14:31:03.0242 2980 spldr - ok
14:31:03.0298 2980 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
14:31:03.0311 2980 Spooler - ok
14:31:03.0462 2980 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
14:31:03.0768 2980 sppsvc - ok
14:31:03.0809 2980 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
14:31:03.0967 2980 sppuinotify - ok
14:31:04.0031 2980 [ 68103A2B441BBF3908EBB587F0704D6C ] sptd C:\Windows\System32\Drivers\sptd.sys
14:31:04.0049 2980 sptd - ok
14:31:04.0102 2980 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
14:31:04.0323 2980 srv - ok
14:31:04.0377 2980 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
14:31:04.0622 2980 srv2 - ok
14:31:04.0657 2980 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
14:31:04.0830 2980 srvnet - ok
14:31:04.0911 2980 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
14:31:04.0920 2980 SSDPSRV - ok
14:31:04.0939 2980 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
14:31:04.0947 2980 SstpSvc - ok
14:31:04.0993 2980 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
14:31:04.0997 2980 stexstor - ok
14:31:05.0272 2980 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
14:31:05.0470 2980 StiSvc - ok
14:31:05.0543 2980 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
14:31:05.0688 2980 storflt - ok
14:31:05.0711 2980 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
14:31:05.0868 2980 storvsc - ok
14:31:05.0890 2980 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
14:31:05.0894 2980 swenum - ok
14:31:05.0965 2980 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
14:31:05.0972 2980 swprv - ok
14:31:05.0995 2980 Synth3dVsc - ok
14:31:06.0076 2980 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
14:31:06.0089 2980 SysMain - ok
14:31:06.0136 2980 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
14:31:06.0290 2980 TabletInputService - ok
14:31:06.0335 2980 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
14:31:06.0535 2980 TapiSrv - ok
14:31:06.0600 2980 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
14:31:06.0609 2980 TBS - ok
14:31:06.0698 2980 [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
14:31:06.0937 2980 Tcpip - ok
14:31:06.0996 2980 [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
14:31:07.0007 2980 TCPIP6 - ok
14:31:07.0062 2980 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
14:31:07.0218 2980 tcpipreg - ok
14:31:07.0255 2980 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
14:31:07.0423 2980 TDPIPE - ok
14:31:07.0448 2980 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
14:31:07.0451 2980 TDTCP - ok
14:31:07.0508 2980 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
14:31:07.0692 2980 tdx - ok
14:31:07.0725 2980 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
14:31:07.0861 2980 TermDD - ok
14:31:07.0923 2980 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
14:31:08.0124 2980 TermService - ok
14:31:08.0172 2980 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
14:31:08.0179 2980 Themes - ok
14:31:08.0204 2980 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
14:31:08.0207 2980 THREADORDER - ok
14:31:08.0257 2980 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
14:31:08.0264 2980 TrkWks - ok
14:31:08.0339 2980 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
14:31:08.0499 2980 TrustedInstaller - ok
14:31:08.0584 2980 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
14:31:08.0735 2980 tssecsrv - ok
14:31:08.0821 2980 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
14:31:08.0974 2980 TsUsbFlt - ok
14:31:08.0983 2980 tsusbhub - ok
14:31:09.0055 2980 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
14:31:09.0236 2980 tunnel - ok
14:31:09.0326 2980 [ 792A8B80F8188ABA4B2BE271583F3E46 ] TVALZ C:\Windows\system32\DRIVERS\TVALZ_O.SYS
14:31:09.0330 2980 TVALZ - ok
14:31:09.0391 2980 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
14:31:09.0397 2980 uagp35 - ok
14:31:09.0454 2980 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
14:31:09.0682 2980 udfs - ok
14:31:09.0762 2980 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
14:31:09.0770 2980 UI0Detect - ok
14:31:09.0809 2980 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
14:31:09.0814 2980 uliagpkx - ok
14:31:09.0856 2980 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
14:31:10.0031 2980 umbus - ok
14:31:10.0101 2980 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
14:31:10.0104 2980 UmPass - ok
14:31:10.0158 2980 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
14:31:10.0378 2980 UmRdpService - ok
14:31:10.0424 2980 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
14:31:10.0437 2980 upnphost - ok
14:31:10.0488 2980 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
14:31:10.0636 2980 usbccgp - ok
14:31:10.0705 2980 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
14:31:10.0710 2980 usbcir - ok
14:31:10.0727 2980 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
14:31:10.0855 2980 usbehci - ok
14:31:10.0897 2980 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
14:31:11.0132 2980 usbhub - ok
14:31:11.0173 2980 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
14:31:11.0350 2980 usbohci - ok
14:31:11.0403 2980 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
14:31:11.0406 2980 usbprint - ok
14:31:11.0468 2980 [ 576096CCBC07E7C4EA4F5E6686D6888F ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
14:31:11.0472 2980 usbscan - ok
14:31:11.0519 2980 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
14:31:11.0690 2980 USBSTOR - ok
14:31:11.0750 2980 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
14:31:11.0865 2980 usbuhci - ok
14:31:11.0927 2980 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
14:31:12.0146 2980 usbvideo - ok
14:31:12.0210 2980 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
14:31:12.0218 2980 UxSms - ok
14:31:12.0244 2980 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
14:31:12.0246 2980 VaultSvc - ok
14:31:12.0287 2980 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
14:31:12.0291 2980 vdrvroot - ok
14:31:12.0336 2980 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
14:31:12.0542 2980 vds - ok
14:31:12.0584 2980 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
14:31:12.0588 2980 vga - ok
14:31:12.0614 2980 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
14:31:12.0617 2980 VgaSave - ok
14:31:12.0627 2980 VGPU - ok
14:31:12.0671 2980 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
14:31:12.0867 2980 vhdmp - ok
14:31:12.0908 2980 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
14:31:12.0912 2980 viaagp - ok
14:31:12.0923 2980 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
14:31:12.0929 2980 ViaC7 - ok
14:31:12.0949 2980 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
14:31:12.0951 2980 viaide - ok
14:31:13.0002 2980 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
14:31:13.0217 2980 vmbus - ok
14:31:13.0229 2980 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
14:31:13.0360 2980 VMBusHID - ok
14:31:13.0422 2980 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
14:31:13.0594 2980 volmgr - ok
14:31:13.0638 2980 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
14:31:13.0653 2980 volmgrx - ok
14:31:13.0676 2980 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
14:31:13.0892 2980 volsnap - ok
14:31:13.0924 2980 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
14:31:13.0936 2980 vsmraid - ok
14:31:14.0442 2980 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
14:31:14.0460 2980 VSS - ok
14:31:14.0512 2980 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
14:31:14.0515 2980 vwifibus - ok
14:31:14.0568 2980 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
14:31:14.0586 2980 W32Time - ok
14:31:14.0622 2980 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
14:31:14.0625 2980 WacomPen - ok
14:31:14.0685 2980 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
14:31:14.0867 2980 WANARP - ok
14:31:14.0904 2980 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
14:31:14.0906 2980 Wanarpv6 - ok
14:31:14.0989 2980 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
14:31:15.0227 2980 WatAdminSvc - ok
14:31:15.0351 2980 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
14:31:15.0714 2980 wbengine - ok
14:31:15.0755 2980 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
14:31:15.0765 2980 WbioSrvc - ok
14:31:15.0818 2980 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
14:31:15.0992 2980 wcncsvc - ok
14:31:16.0019 2980 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
14:31:16.0025 2980 WcsPlugInService - ok
14:31:16.0058 2980 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
14:31:16.0061 2980 Wd - ok
14:31:16.0125 2980 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
14:31:16.0369 2980 Wdf01000 - ok
14:31:16.0411 2980 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
14:31:16.0418 2980 WdiServiceHost - ok
14:31:16.0429 2980 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
14:31:16.0434 2980 WdiSystemHost - ok
14:31:16.0478 2980 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
14:31:16.0671 2980 WebClient - ok
14:31:16.0706 2980 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
14:31:16.0715 2980 Wecsvc - ok
14:31:16.0741 2980 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
14:31:16.0748 2980 wercplsupport - ok
14:31:16.0788 2980 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
14:31:16.0795 2980 WerSvc - ok
14:31:16.0856 2980 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
14:31:16.0858 2980 WfpLwf - ok
14:31:16.0878 2980 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
14:31:16.0880 2980 WIMMount - ok
14:31:16.0896 2980 WinHttpAutoProxySvc - ok
14:31:16.0982 2980 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
14:31:16.0993 2980 Winmgmt - ok
14:31:17.0078 2980 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
14:31:17.0327 2980 WinRM - ok
14:31:17.0436 2980 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
14:31:17.0473 2980 Wlansvc - ok
14:31:17.0517 2980 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
14:31:17.0519 2980 WmiAcpi - ok
14:31:17.0578 2980 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
14:31:17.0601 2980 wmiApSrv - ok
14:31:17.0699 2980 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
14:31:17.0928 2980 WMPNetworkSvc - ok
14:31:17.0961 2980 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
14:31:17.0967 2980 WPCSvc - ok
14:31:18.0018 2980 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
14:31:18.0196 2980 WPDBusEnum - ok
14:31:18.0252 2980 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
14:31:18.0255 2980 ws2ifsl - ok
14:31:18.0265 2980 WSearch - ok
14:31:18.0312 2980 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
14:31:18.0451 2980 WudfPf - ok
14:31:18.0501 2980 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
14:31:18.0700 2980 WUDFRd - ok
14:31:18.0751 2980 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
14:31:18.0894 2980 wudfsvc - ok
14:31:18.0937 2980 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
14:31:18.0949 2980 WwanSvc - ok
14:31:18.0994 2980 ================ Scan global ===============================
14:31:19.0027 2980 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
14:31:19.0176 2980 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
14:31:19.0395 2980 [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
14:31:19.0437 2980 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
14:31:19.0489 2980 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
14:31:19.0497 2980 [Global] - ok
14:31:19.0498 2980 ================ Scan MBR ==================================
14:31:19.0520 2980 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
14:31:19.0931 2980 \Device\Harddisk0\DR0 - ok
14:31:19.0932 2980 ================ Scan VBR ==================================
14:31:19.0936 2980 [ 17F670A38DFE190E149BF926C00E415F ] \Device\Harddisk0\DR0\Partition1
14:31:19.0938 2980 \Device\Harddisk0\DR0\Partition1 - ok
14:31:19.0970 2980 [ 70EA22522FF379DFDB314E3C94A11059 ] \Device\Harddisk0\DR0\Partition2
14:31:19.0973 2980 \Device\Harddisk0\DR0\Partition2 - ok
14:31:19.0973 2980 ============================================================
14:31:19.0973 2980 Scan finished
14:31:19.0973 2980 ============================================================
14:31:19.0990 3664 Detected object count: 1
14:31:19.0990 3664 Actual detected object count: 1
14:31:47.0413 3664 C:\Windows\system32\DRIVERS\cdrom.sys - copied to quarantine
14:31:51.0530 3664 C:\Windows\$NtUninstallKB23787$\1932275655\@ - copied to quarantine
14:31:51.0615 3664 C:\Windows\$NtUninstallKB23787$\1932275655\Desktop.ini - copied to quarantine
14:31:51.0636 3664 C:\Windows\$NtUninstallKB23787$\1932275655\L\00000004.@ - copied to quarantine
14:31:51.0640 3664 C:\Windows\$NtUninstallKB23787$\1932275655\L\201d3dde - copied to quarantine
14:31:51.0644 3664 C:\Windows\$NtUninstallKB23787$\1932275655\L\6715e287 - copied to quarantine
14:31:51.0662 3664 C:\Windows\$NtUninstallKB23787$\1932275655\L\76603ac3 - copied to quarantine
14:31:51.0684 3664 C:\Windows\$NtUninstallKB23787$\1932275655\L\xadqgnnk - copied to quarantine
14:31:51.0689 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\00000004.@ - copied to quarantine
14:31:51.0721 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\00000008.@ - copied to quarantine
14:31:51.0726 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\000000cb.@ - copied to quarantine
14:31:51.0750 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\80000000.@ - copied to quarantine
14:31:51.0781 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\80000032.@ - copied to quarantine
14:31:52.0346 3664 Backup copy found, using it..
14:31:52.0622 3664 C:\Windows\system32\DRIVERS\cdrom.sys - will be cured on reboot
14:31:52.0732 3664 C:\Windows\$NtUninstallKB23787$\1185891576 - will be deleted on reboot
14:31:52.0733 3664 C:\Windows\$NtUninstallKB23787$\1932275655\@ - will be deleted on reboot
14:31:52.0733 3664 C:\Windows\$NtUninstallKB23787$\1932275655\Desktop.ini - will be deleted on reboot
14:31:52.0737 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\00000004.@ - will be deleted on reboot
14:31:52.0738 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\00000008.@ - will be deleted on reboot
14:31:52.0739 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\000000cb.@ - will be deleted on reboot
14:31:52.0739 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\80000000.@ - will be deleted on reboot
14:31:52.0740 3664 C:\Windows\$NtUninstallKB23787$\1932275655\U\80000032.@ - will be deleted on reboot
14:31:52.0747 3664 cdrom ( Virus.Win32.ZAccess.aml ) - User select action: Cure
**************************************************************************************************************************************************************************************************
14:50:45.0117 2072 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
14:50:45.0289 2072 ============================================================
14:50:45.0289 2072 Current date / time: 2013/04/12 14:50:45.0289
14:50:45.0289 2072 SystemInfo:
14:50:45.0289 2072
14:50:45.0289 2072 OS Version: 6.1.7601 ServicePack: 1.0
14:50:45.0289 2072 Product type: Workstation
14:50:45.0289 2072 ComputerName: DANOULH-PC
14:50:45.0289 2072 UserName: Danoulh
14:50:45.0289 2072 Windows directory: C:\Windows
14:50:45.0289 2072 System windows directory: C:\Windows
14:50:45.0289 2072 Processor architecture: Intel x86
14:50:45.0289 2072 Number of processors: 2
14:50:45.0289 2072 Page size: 0x1000
14:50:45.0289 2072 Boot type: Normal boot
14:50:45.0289 2072 ============================================================
14:50:50.0361 2072 BG loaded
14:50:51.0453 2072 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
14:50:51.0453 2072 ============================================================
14:50:51.0453 2072 \Device\Harddisk0\DR0:
14:50:51.0453 2072 MBR partitions:
14:50:51.0453 2072 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x950C800
14:50:51.0453 2072 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x97FB000, BlocksNum 0x921E800
14:50:51.0453 2072 ============================================================
14:50:51.0485 2072 C: <-> \Device\Harddisk0\DR0\Partition1
14:50:51.0797 2072 D: <-> \Device\Harddisk0\DR0\Partition2
14:50:51.0797 2072 ============================================================
14:50:51.0797 2072 Initialize success
14:50:51.0797 2072 ============================================================