mbar.exe - system-log Code:
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.05.0.1001
(c) Malwarebytes Corporation 2011-2012
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
Account is Administrative
Internet Explorer version: 9.0.8112.16421
Java version: 1.6.0_37
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, E:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 3.292000 GHz
Memory total: 8569864192, free: 3607683072
------------ Kernel report ------------
05/06/2013 19:39:32
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\drivers\hcw88aud.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\drivers\hcw88vid.sys
\SystemRoot\system32\drivers\STREAM.SYS
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\hcw88tse.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\drivers\HCW88BAR.sys
\SystemRoot\system32\drivers\hcw88bda.sys
\SystemRoot\system32\drivers\BdaSup.SYS
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\drivers\usbaudio.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_dumpata.sys
\SystemRoot\System32\Drivers\dump_msahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\SystemRoot\system32\DRIVERS\WSDPrint.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\mbamswissarmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
----------- End -----------
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR3
Upper Device Object: 0xfffffa8007533060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP3T0L0-3\
Lower Device Object: 0xfffffa8007322060
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
Initialization returned 0x0
Port sub-driver loaded: \??\C:\Windows\System32\drivers\ataport.sys (0x0)
Load Function returned 0x0
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR2
Upper Device Object: 0xfffffa8007532060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP4T0L0-4\
Lower Device Object: 0xfffffa800732e4e0
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa8007531060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP5T0L0-5\
Lower Device Object: 0xfffffa800733b680
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa8007530060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-1\
Lower Device Object: 0xfffffa8007308060
Lower Device Driver Name: \Driver\atapi\
Driver name found: atapi
Downloaded database version: v2013.05.06.07
Downloaded database version: v2013.05.01.01
Initializing...
Done!
<<<2>>>
Device number: 0, partition: 2
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa8007530060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007530b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007530060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8007308060, DeviceName: \Device\Ide\IdeDeviceP1T0L0-1\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0xfffff8a008e6ec00, 0xfffffa8007530060, 0xfffffa8007038790
Lower DeviceData: 0xfffff8a009c40d10, 0xfffffa8007308060, 0xfffffa800a22d3d0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning directory: C:\Windows\system32\drivers...
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 659AA457
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 204800
Partition file system is NTFS
Partition is bootable
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 206848 Numsec = 234231808
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 120034123776 bytes
Sector size: 512 bytes
Scanning physical sectors of unpartitioned space on drive 0 (1-2047-234421648-234441648)...
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa8007531060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007531b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007531060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800733b680, DeviceName: \Device\Ide\IdeDeviceP5T0L0-5\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0xfffff8a00c9fb9d0, 0xfffffa8007531060, 0xfffffa800718a790
Lower DeviceData: 0xfffff8a002f8e5b0, 0xfffffa800733b680, 0xfffffa800c1da090
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 1EC31EC2
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 312576000
Partition file system is NTFS
Partition is not bootable
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 160041885696 bytes
Sector size: 512 bytes
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xfffffa8007532060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007532b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007532060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800732e4e0, DeviceName: \Device\Ide\IdeDeviceP4T0L0-4\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
Upper DeviceData: 0xfffff8a009c5eb10, 0xfffffa8007532060, 0xfffffa800720a090
Lower DeviceData: 0xfffff8a009c5e980, 0xfffffa800732e4e0, 0xfffffa8006f0b750
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: C0204B8A
Partition information:
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 3907024896
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 2000398934016 bytes
Sector size: 512 bytes
Physical Sector Size: 512
Drive: 3, DevicePointer: 0xfffffa8007533060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa8007533b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8007533060, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006d27e40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xfffffa8007322060, DeviceName: \Device\Ide\IdeDeviceP3T0L0-3\, DriverName: \Driver\atapi\
------------ End ----------
Alternate DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
Upper DeviceData: 0xfffff8a00a02d8e0, 0xfffffa8007533060, 0xfffffa80086fb290
Lower DeviceData: 0xfffff8a009650200, 0xfffffa8007322060, 0xfffffa800bf7d8c0
Drive 3
Scanning MBR on drive 3...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 4F2AEE19
Partition information:
Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 3907024896
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Disk Size: 2000398934016 bytes
Sector size: 512 bytes
Done!
Performing system, memory and registry scan...
Infected: c:\Users\***\AppData\Local\Temp\winxeyj.exe --> [Trojan.Downloader]
Infected: c:\Users\***\AppData\Local\Temp\winxeyj.exe --> [Trojan.Downloader]
Done!
Scan finished
Creating System Restore point...
Scheduling clean up...
<<<2>>>
Device number: 0, partition: 2
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.05.0.1001
(c) Malwarebytes Corporation 2011-2012
OS version: 6.1.7601 Windows 7 Service Pack 1 x64
Account is Administrative
Internet Explorer version: 9.0.8112.16421
Java version: 1.6.0_37
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, E:\ DRIVE_FIXED, F:\ DRIVE_FIXED
CPU speed: 3.292000 GHz
Memory total: 8569864192, free: 7670947840
Removal queue found; removal started
Removing c:\Users\***\AppData\Local\Temp\winxeyj.exe...
Removal finished
======================================= mbar.exe - mbar-log-2013-05-06 (19-44-47) Code:
Malwarebytes Anti-Rootkit BETA 1.05.0.1001
www.malwarebytes.org
Database version: v2013.05.06.07
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
*** :: ***-PC [administrator]
06.05.2013 19:44:47
mbar-log-2013-05-06 (19-44-47).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 30282
Time elapsed: 3 minute(s), 9 second(s)
Memory Processes Detected: 1
c:\Users\***\AppData\Local\Temp\winxeyj.exe (Trojan.Downloader) -> 2644 -> Delete on reboot.
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
c:\Users\***\AppData\Local\Temp\winxeyj.exe (Trojan.Downloader) -> Delete on reboot.
(end) TDSKiller log Code:
20:10:54.0225 4792 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
20:10:54.0762 4792 ============================================================
20:10:54.0762 4792 Current date / time: 2013/05/06 20:10:54.0762
20:10:54.0762 4792 SystemInfo:
20:10:54.0762 4792
20:10:54.0762 4792 OS Version: 6.1.7601 ServicePack: 1.0
20:10:54.0762 4792 Product type: Workstation
20:10:54.0762 4792 ComputerName: ***-PC
20:10:54.0763 4792 UserName: ***
20:10:54.0763 4792 Windows directory: C:\Windows
20:10:54.0763 4792 System windows directory: C:\Windows
20:10:54.0763 4792 Running under WOW64
20:10:54.0763 4792 Processor architecture: Intel x64
20:10:54.0763 4792 Number of processors: 4
20:10:54.0763 4792 Page size: 0x1000
20:10:54.0763 4792 Boot type: Normal boot
20:10:54.0763 4792 ============================================================
20:10:54.0910 4792 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:10:54.0926 4792 Drive \Device\Harddisk3\DR3 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:10:54.0935 4792 Drive \Device\Harddisk2\DR2 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:10:54.0967 4792 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
20:10:54.0970 4792 ============================================================
20:10:54.0970 4792 \Device\Harddisk0\DR0:
20:10:54.0971 4792 MBR partitions:
20:10:54.0971 4792 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
20:10:54.0971 4792 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xDF61800
20:10:54.0971 4792 \Device\Harddisk3\DR3:
20:10:54.0971 4792 MBR partitions:
20:10:54.0971 4792 \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
20:10:54.0971 4792 \Device\Harddisk2\DR2:
20:10:54.0971 4792 MBR partitions:
20:10:54.0971 4792 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
20:10:54.0971 4792 \Device\Harddisk1\DR1:
20:10:54.0971 4792 MBR partitions:
20:10:54.0971 4792 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
20:10:54.0971 4792 ============================================================
20:10:54.0972 4792 C: <-> \Device\Harddisk0\DR0\Partition2
20:10:54.0999 4792 D: <-> \Device\Harddisk1\DR1\Partition1
20:10:55.0021 4792 E: <-> \Device\Harddisk3\DR3\Partition1
20:10:55.0038 4792 F: <-> \Device\Harddisk2\DR2\Partition1
20:10:55.0038 4792 ============================================================
20:10:55.0038 4792 Initialize success
20:10:55.0038 4792 ============================================================
20:11:18.0434 4028 ============================================================
20:11:18.0434 4028 Scan started
20:11:18.0434 4028 Mode: Manual; SigCheck; TDLFS;
20:11:18.0434 4028 ============================================================
20:11:18.0649 4028 ================ Scan system memory ========================
20:11:18.0649 4028 System memory - ok
20:11:18.0649 4028 ================ Scan services =============================
20:11:18.0689 4028 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
20:11:18.0728 4028 1394ohci - ok
20:11:18.0733 4028 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
20:11:18.0743 4028 ACPI - ok
20:11:18.0746 4028 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
20:11:18.0760 4028 AcpiPmi - ok
20:11:18.0764 4028 [ B1EA9681502EE57F87DB71D726288A5B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
20:11:18.0770 4028 AdobeARMservice - ok
20:11:18.0795 4028 [ 479901C99FA62D1C3261B7ACB1228DAD ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
20:11:18.0804 4028 AdobeFlashPlayerUpdateSvc - ok
20:11:18.0810 4028 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
20:11:18.0821 4028 adp94xx - ok
20:11:18.0826 4028 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
20:11:18.0836 4028 adpahci - ok
20:11:18.0839 4028 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
20:11:18.0846 4028 adpu320 - ok
20:11:18.0850 4028 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
20:11:18.0893 4028 AeLookupSvc - ok
20:11:18.0899 4028 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
20:11:18.0912 4028 AFD - ok
20:11:18.0921 4028 [ B20C64A91C08A992B1C70B290477A2B0 ] Agile1Password C:\Program Files (x86)\1Password\Agile1pService.exe
20:11:18.0933 4028 Agile1Password - ok
20:11:18.0936 4028 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
20:11:18.0942 4028 agp440 - ok
20:11:18.0945 4028 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
20:11:18.0955 4028 ALG - ok
20:11:18.0957 4028 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
20:11:18.0962 4028 aliide - ok
20:11:18.0965 4028 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
20:11:18.0970 4028 amdide - ok
20:11:18.0972 4028 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
20:11:18.0980 4028 AmdK8 - ok
20:11:18.0982 4028 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
20:11:18.0990 4028 AmdPPM - ok
20:11:18.0993 4028 [ 6EC6D772EAE38DC17C14AED9B178D24B ] amdsata C:\Windows\system32\drivers\amdsata.sys
20:11:18.0999 4028 amdsata - ok
20:11:19.0002 4028 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
20:11:19.0010 4028 amdsbs - ok
20:11:19.0013 4028 [ 1142A21DB581A84EA5597B03A26EBAA0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
20:11:19.0018 4028 amdxata - ok
20:11:19.0020 4028 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
20:11:19.0065 4028 AppID - ok
20:11:19.0068 4028 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
20:11:19.0089 4028 AppIDSvc - ok
20:11:19.0091 4028 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
20:11:19.0112 4028 Appinfo - ok
20:11:19.0116 4028 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
20:11:19.0121 4028 Apple Mobile Device - ok
20:11:19.0124 4028 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
20:11:19.0130 4028 arc - ok
20:11:19.0132 4028 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
20:11:19.0139 4028 arcsas - ok
20:11:19.0150 4028 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
20:11:19.0158 4028 aspnet_state - ok
20:11:19.0160 4028 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
20:11:19.0180 4028 AsyncMac - ok
20:11:19.0183 4028 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
20:11:19.0188 4028 atapi - ok
20:11:19.0196 4028 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
20:11:19.0222 4028 AudioEndpointBuilder - ok
20:11:19.0229 4028 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
20:11:19.0253 4028 AudioSrv - ok
20:11:19.0256 4028 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
20:11:19.0267 4028 AxInstSV - ok
20:11:19.0273 4028 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
20:11:19.0284 4028 b06bdrv - ok
20:11:19.0289 4028 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
20:11:19.0298 4028 b57nd60a - ok
20:11:19.0302 4028 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
20:11:19.0310 4028 BDESVC - ok
20:11:19.0312 4028 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
20:11:19.0333 4028 Beep - ok
20:11:19.0340 4028 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
20:11:19.0367 4028 BFE - ok
20:11:19.0375 4028 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
20:11:19.0405 4028 BITS - ok
20:11:19.0407 4028 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
20:11:19.0414 4028 blbdrive - ok
20:11:19.0420 4028 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
20:11:19.0430 4028 Bonjour Service - ok
20:11:19.0433 4028 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
20:11:19.0440 4028 bowser - ok
20:11:19.0442 4028 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
20:11:19.0451 4028 BrFiltLo - ok
20:11:19.0453 4028 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
20:11:19.0461 4028 BrFiltUp - ok
20:11:19.0464 4028 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
20:11:19.0472 4028 Browser - ok
20:11:19.0476 4028 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
20:11:19.0487 4028 Brserid - ok
20:11:19.0489 4028 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
20:11:19.0498 4028 BrSerWdm - ok
20:11:19.0500 4028 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
20:11:19.0508 4028 BrUsbMdm - ok
20:11:19.0510 4028 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
20:11:19.0517 4028 BrUsbSer - ok
20:11:19.0519 4028 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
20:11:19.0528 4028 BTHMODEM - ok
20:11:19.0532 4028 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
20:11:19.0553 4028 bthserv - ok
20:11:19.0556 4028 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
20:11:19.0577 4028 cdfs - ok
20:11:19.0580 4028 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
20:11:19.0588 4028 cdrom - ok
20:11:19.0591 4028 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
20:11:19.0612 4028 CertPropSvc - ok
20:11:19.0614 4028 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
20:11:19.0623 4028 circlass - ok
20:11:19.0628 4028 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
20:11:19.0638 4028 CLFS - ok
20:11:19.0642 4028 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
20:11:19.0648 4028 clr_optimization_v2.0.50727_32 - ok
20:11:19.0653 4028 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
20:11:19.0659 4028 clr_optimization_v2.0.50727_64 - ok
20:11:19.0668 4028 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
20:11:19.0678 4028 clr_optimization_v4.0.30319_32 - ok
20:11:19.0681 4028 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
20:11:19.0688 4028 clr_optimization_v4.0.30319_64 - ok
20:11:19.0691 4028 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
20:11:19.0697 4028 CmBatt - ok
20:11:19.0700 4028 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
20:11:19.0705 4028 cmdide - ok
20:11:19.0711 4028 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
20:11:19.0726 4028 CNG - ok
20:11:19.0729 4028 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
20:11:19.0734 4028 Compbatt - ok
20:11:19.0736 4028 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
20:11:19.0745 4028 CompositeBus - ok
20:11:19.0747 4028 COMSysApp - ok
20:11:19.0749 4028 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
20:11:19.0756 4028 crcdisk - ok
20:11:19.0760 4028 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
20:11:19.0768 4028 CryptSvc - ok
20:11:19.0775 4028 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
20:11:19.0800 4028 DcomLaunch - ok
20:11:19.0805 4028 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
20:11:19.0829 4028 defragsvc - ok
20:11:19.0832 4028 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
20:11:19.0853 4028 DfsC - ok
20:11:19.0857 4028 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
20:11:19.0881 4028 Dhcp - ok
20:11:19.0883 4028 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
20:11:19.0904 4028 discache - ok
20:11:19.0907 4028 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
20:11:19.0913 4028 Disk - ok
20:11:19.0916 4028 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
20:11:19.0926 4028 Dnscache - ok
20:11:19.0930 4028 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
20:11:19.0952 4028 dot3svc - ok
20:11:19.0955 4028 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
20:11:19.0977 4028 DPS - ok
20:11:19.0979 4028 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
20:11:19.0987 4028 drmkaud - ok
20:11:19.0997 4028 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
20:11:20.0012 4028 DXGKrnl - ok
20:11:20.0015 4028 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
20:11:20.0037 4028 EapHost - ok
20:11:20.0063 4028 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
20:11:20.0099 4028 ebdrv - ok
20:11:20.0102 4028 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
20:11:20.0110 4028 EFS - ok
20:11:20.0118 4028 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
20:11:20.0133 4028 ehRecvr - ok
20:11:20.0136 4028 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
20:11:20.0145 4028 ehSched - ok
20:11:20.0151 4028 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
20:11:20.0162 4028 elxstor - ok
20:11:20.0164 4028 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
20:11:20.0171 4028 ErrDev - ok
20:11:20.0178 4028 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
20:11:20.0202 4028 EventSystem - ok
20:11:20.0206 4028 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
20:11:20.0228 4028 exfat - ok
20:11:20.0232 4028 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
20:11:20.0255 4028 fastfat - ok
20:11:20.0262 4028 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
20:11:20.0276 4028 Fax - ok
20:11:20.0278 4028 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
20:11:20.0285 4028 fdc - ok
20:11:20.0287 4028 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
20:11:20.0307 4028 fdPHost - ok
20:11:20.0310 4028 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
20:11:20.0331 4028 FDResPub - ok
20:11:20.0333 4028 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
20:11:20.0339 4028 FileInfo - ok
20:11:20.0341 4028 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
20:11:20.0362 4028 Filetrace - ok
20:11:20.0364 4028 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
20:11:20.0371 4028 flpydisk - ok
20:11:20.0375 4028 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
20:11:20.0383 4028 FltMgr - ok
20:11:20.0394 4028 [ B4447F606BB19FD8AD0BAFB59B90F5D9 ] FontCache C:\Windows\system32\FntCache.dll
20:11:20.0426 4028 FontCache - ok
20:11:20.0429 4028 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
20:11:20.0434 4028 FontCache3.0.0.0 - ok
20:11:20.0436 4028 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
20:11:20.0442 4028 FsDepends - ok
20:11:20.0444 4028 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
20:11:20.0449 4028 Fs_Rec - ok
20:11:20.0453 4028 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
20:11:20.0462 4028 fvevol - ok
20:11:20.0465 4028 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
20:11:20.0471 4028 gagp30kx - ok
20:11:20.0473 4028 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
20:11:20.0477 4028 GEARAspiWDM - ok
20:11:20.0485 4028 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
20:11:20.0512 4028 gpsvc - ok
20:11:20.0516 4028 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:11:20.0521 4028 gupdate - ok
20:11:20.0524 4028 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
20:11:20.0528 4028 gupdatem - ok
20:11:20.0530 4028 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
20:11:20.0537 4028 hcw85cir - ok
20:11:20.0540 4028 [ 7760B09A8CD0045B926157C1939DCABD ] HCW88AUD C:\Windows\system32\drivers\hcw88aud.sys
20:11:20.0547 4028 HCW88AUD - ok
20:11:20.0550 4028 [ 179D17EFDBCBCFDE082C8D7ABB120A18 ] hcw88bda C:\Windows\system32\drivers\hcw88bda.sys
20:11:20.0559 4028 hcw88bda - ok
20:11:20.0564 4028 [ 97436988B521CB9CEF87D8F1197AD497 ] HCW88TSE C:\Windows\system32\drivers\hcw88tse.sys
20:11:20.0573 4028 HCW88TSE - ok
20:11:20.0578 4028 [ 3DA6F77699C258A59FC1CE6A288976EA ] hcw88vid C:\Windows\system32\drivers\hcw88vid.sys
20:11:20.0589 4028 hcw88vid - ok
20:11:20.0591 4028 [ AEE8CD58999455A3B8CECFE086FAD8A6 ] HCW88XBAR C:\Windows\system32\drivers\HCW88BAR.sys
20:11:20.0597 4028 HCW88XBAR - ok
20:11:20.0602 4028 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
20:11:20.0613 4028 HdAudAddService - ok
20:11:20.0616 4028 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
20:11:20.0625 4028 HDAudBus - ok
20:11:20.0628 4028 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
20:11:20.0634 4028 HidBatt - ok
20:11:20.0637 4028 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
20:11:20.0646 4028 HidBth - ok
20:11:20.0649 4028 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
20:11:20.0657 4028 HidIr - ok
20:11:20.0660 4028 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
20:11:20.0681 4028 hidserv - ok
20:11:20.0683 4028 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
20:11:20.0690 4028 HidUsb - ok
20:11:20.0692 4028 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
20:11:20.0714 4028 hkmsvc - ok
20:11:20.0718 4028 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
20:11:20.0727 4028 HomeGroupListener - ok
20:11:20.0731 4028 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
20:11:20.0740 4028 HomeGroupProvider - ok
20:11:20.0743 4028 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
20:11:20.0749 4028 HpSAMD - ok
20:11:20.0757 4028 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
20:11:20.0784 4028 HTTP - ok
20:11:20.0786 4028 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
20:11:20.0791 4028 hwpolicy - ok
20:11:20.0794 4028 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
20:11:20.0801 4028 i8042prt - ok
20:11:20.0806 4028 [ 3DF4395A7CF8B7A72A5F4606366B8C2D ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
20:11:20.0816 4028 iaStorV - ok
20:11:20.0825 4028 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
20:11:20.0840 4028 idsvc - ok
20:11:20.0842 4028 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
20:11:20.0848 4028 iirsp - ok
20:11:20.0857 4028 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
20:11:20.0884 4028 IKEEXT - ok
20:11:20.0887 4028 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
20:11:20.0893 4028 intelide - ok
20:11:20.0895 4028 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
20:11:20.0902 4028 intelppm - ok
20:11:20.0905 4028 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
20:11:20.0926 4028 IPBusEnum - ok
20:11:20.0929 4028 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
20:11:20.0950 4028 IpFilterDriver - ok
20:11:20.0956 4028 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
20:11:20.0981 4028 iphlpsvc - ok
20:11:20.0984 4028 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
20:11:20.0991 4028 IPMIDRV - ok
20:11:20.0994 4028 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
20:11:21.0016 4028 IPNAT - ok
20:11:21.0025 4028 [ 6E50CFA46527B39015B750AAD161C5CC ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
20:11:21.0040 4028 iPod Service - ok
20:11:21.0042 4028 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
20:11:21.0052 4028 IRENUM - ok
20:11:21.0054 4028 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
20:11:21.0059 4028 isapnp - ok
20:11:21.0064 4028 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
20:11:21.0072 4028 iScsiPrt - ok
20:11:21.0075 4028 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
20:11:21.0080 4028 kbdclass - ok
20:11:21.0082 4028 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
20:11:21.0089 4028 kbdhid - ok
20:11:21.0091 4028 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
20:11:21.0097 4028 KeyIso - ok
20:11:21.0100 4028 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
20:11:21.0106 4028 KSecDD - ok
20:11:21.0109 4028 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
20:11:21.0116 4028 KSecPkg - ok
20:11:21.0118 4028 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
20:11:21.0139 4028 ksthunk - ok
20:11:21.0144 4028 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
20:11:21.0168 4028 KtmRm - ok
20:11:21.0172 4028 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
20:11:21.0195 4028 LanmanServer - ok
20:11:21.0198 4028 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
20:11:21.0220 4028 LanmanWorkstation - ok
20:11:21.0223 4028 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
20:11:21.0244 4028 lltdio - ok
20:11:21.0249 4028 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
20:11:21.0272 4028 lltdsvc - ok
20:11:21.0275 4028 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
20:11:21.0296 4028 lmhosts - ok
20:11:21.0299 4028 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
20:11:21.0306 4028 LSI_FC - ok
20:11:21.0309 4028 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
20:11:21.0315 4028 LSI_SAS - ok
20:11:21.0317 4028 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
20:11:21.0324 4028 LSI_SAS2 - ok
20:11:21.0326 4028 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
20:11:21.0333 4028 LSI_SCSI - ok
20:11:21.0336 4028 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
20:11:21.0358 4028 luafv - ok
20:11:21.0361 4028 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
20:11:21.0368 4028 Mcx2Svc - ok
20:11:21.0371 4028 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
20:11:21.0376 4028 megasas - ok
20:11:21.0381 4028 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
20:11:21.0390 4028 MegaSR - ok
20:11:21.0392 4028 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
20:11:21.0413 4028 MMCSS - ok
20:11:21.0416 4028 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
20:11:21.0437 4028 Modem - ok
20:11:21.0439 4028 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
20:11:21.0448 4028 monitor - ok
20:11:21.0450 4028 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
20:11:21.0455 4028 mouclass - ok
20:11:21.0457 4028 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
20:11:21.0464 4028 mouhid - ok
20:11:21.0467 4028 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
20:11:21.0473 4028 mountmgr - ok
20:11:21.0476 4028 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
20:11:21.0482 4028 MozillaMaintenance - ok
20:11:21.0486 4028 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
20:11:21.0493 4028 mpio - ok
20:11:21.0496 4028 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
20:11:21.0516 4028 mpsdrv - ok
20:11:21.0525 4028 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
20:11:21.0552 4028 MpsSvc - ok
20:11:21.0556 4028 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
20:11:21.0567 4028 MRxDAV - ok
20:11:21.0571 4028 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
20:11:21.0579 4028 mrxsmb - ok
20:11:21.0583 4028 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
20:11:21.0592 4028 mrxsmb10 - ok
20:11:21.0595 4028 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
20:11:21.0602 4028 mrxsmb20 - ok
20:11:21.0604 4028 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
20:11:21.0610 4028 msahci - ok
20:11:21.0613 4028 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
20:11:21.0619 4028 msdsm - ok
20:11:21.0622 4028 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
20:11:21.0631 4028 MSDTC - ok
20:11:21.0635 4028 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
20:11:21.0655 4028 Msfs - ok
20:11:21.0657 4028 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
20:11:21.0678 4028 mshidkmdf - ok
20:11:21.0680 4028 MSICDSetup - ok
20:11:21.0682 4028 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
20:11:21.0688 4028 msisadrv - ok
20:11:21.0691 4028 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
20:11:21.0713 4028 MSiSCSI - ok
20:11:21.0715 4028 msiserver - ok
20:11:21.0717 4028 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
20:11:21.0738 4028 MSKSSRV - ok
20:11:21.0740 4028 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
20:11:21.0761 4028 MSPCLOCK - ok
20:11:21.0763 4028 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
20:11:21.0783 4028 MSPQM - ok
20:11:21.0788 4028 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
20:11:21.0798 4028 MsRPC - ok
20:11:21.0801 4028 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
20:11:21.0807 4028 mssmbios - ok
20:11:21.0809 4028 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
20:11:21.0831 4028 MSTEE - ok
20:11:21.0833 4028 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
20:11:21.0839 4028 MTConfig - ok
20:11:21.0842 4028 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
20:11:21.0847 4028 Mup - ok
20:11:21.0853 4028 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
20:11:21.0878 4028 napagent - ok
20:11:21.0883 4028 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
20:11:21.0895 4028 NativeWifiP - ok
20:11:21.0905 4028 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
20:11:21.0922 4028 NDIS - ok
20:11:21.0924 4028 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
20:11:21.0945 4028 NdisCap - ok
20:11:21.0947 4028 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
20:11:21.0967 4028 NdisTapi - ok
20:11:21.0970 4028 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
20:11:21.0991 4028 Ndisuio - ok
20:11:21.0994 4028 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
20:11:22.0016 4028 NdisWan - ok
20:11:22.0018 4028 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
20:11:22.0038 4028 NDProxy - ok
20:11:22.0041 4028 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
20:11:22.0062 4028 NetBIOS - ok
20:11:22.0066 4028 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
20:11:22.0088 4028 NetBT - ok
20:11:22.0090 4028 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
20:11:22.0096 4028 Netlogon - ok
20:11:22.0101 4028 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
20:11:22.0126 4028 Netman - ok
20:11:22.0129 4028 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:22.0136 4028 NetMsmqActivator - ok
20:11:22.0138 4028 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:22.0144 4028 NetPipeActivator - ok
20:11:22.0149 4028 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
20:11:22.0175 4028 netprofm - ok
20:11:22.0178 4028 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:22.0183 4028 NetTcpActivator - ok
20:11:22.0185 4028 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
20:11:22.0191 4028 NetTcpPortSharing - ok
20:11:22.0193 4028 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
20:11:22.0199 4028 nfrd960 - ok
20:11:22.0203 4028 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
20:11:22.0227 4028 NlaSvc - ok
20:11:22.0230 4028 [ 351533ACC2A069B94E80BBFC177E8FDF ] NPF C:\Windows\system32\drivers\npf.sys
20:11:22.0236 4028 NPF - ok
20:11:22.0239 4028 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
20:11:22.0260 4028 Npfs - ok
20:11:22.0262 4028 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
20:11:22.0283 4028 nsi - ok
20:11:22.0285 4028 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
20:11:22.0306 4028 nsiproxy - ok
20:11:22.0322 4028 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
20:11:22.0348 4028 Ntfs - ok
20:11:22.0351 4028 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
20:11:22.0371 4028 Null - ok
20:11:22.0375 4028 [ 1F07B814C0BB5AABA703ABFF1F31F2E8 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
20:11:22.0381 4028 NVHDA - ok
20:11:22.0501 4028 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
20:11:22.0607 4028 nvlddmkm - ok
20:11:22.0613 4028 [ 5D9FD91F3D38DC9DA01E3CB5FA89CD48 ] nvraid C:\Windows\system32\drivers\nvraid.sys
20:11:22.0620 4028 nvraid - ok
20:11:22.0623 4028 [ F7CD50FE7139F07E77DA8AC8033D1832 ] nvstor C:\Windows\system32\drivers\nvstor.sys
20:11:22.0630 4028 nvstor - ok
20:11:22.0639 4028 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe
20:11:22.0654 4028 nvsvc - ok
20:11:22.0666 4028 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
20:11:22.0685 4028 nvUpdatusService - ok
20:11:22.0688 4028 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
20:11:22.0695 4028 nv_agp - ok
20:11:22.0697 4028 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
20:11:22.0705 4028 ohci1394 - ok
20:11:22.0709 4028 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
20:11:22.0720 4028 p2pimsvc - ok
20:11:22.0725 4028 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
20:11:22.0736 4028 p2psvc - ok
20:11:22.0739 4028 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
20:11:22.0747 4028 Parport - ok
20:11:22.0749 4028 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
20:11:22.0755 4028 partmgr - ok
20:11:22.0759 4028 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
20:11:22.0771 4028 PcaSvc - ok
20:11:22.0774 4028 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
20:11:22.0782 4028 pci - ok
20:11:22.0784 4028 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
20:11:22.0789 4028 pciide - ok
20:11:22.0793 4028 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
20:11:22.0801 4028 pcmcia - ok
20:11:22.0803 4028 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
20:11:22.0809 4028 pcw - ok
20:11:22.0815 4028 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
20:11:22.0843 4028 PEAUTH - ok
20:11:22.0866 4028 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
20:11:22.0873 4028 PerfHost - ok
20:11:22.0888 4028 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
20:11:22.0922 4028 pla - ok
20:11:22.0928 4028 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
20:11:22.0940 4028 PlugPlay - ok
20:11:22.0942 4028 PnkBstrA - ok
20:11:22.0945 4028 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
20:11:22.0951 4028 PNRPAutoReg - ok
20:11:22.0955 4028 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
20:11:22.0963 4028 PNRPsvc - ok
20:11:22.0970 4028 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
20:11:22.0994 4028 PolicyAgent - ok
20:11:22.0999 4028 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
20:11:23.0021 4028 Power - ok
20:11:23.0024 4028 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
20:11:23.0045 4028 PptpMiniport - ok
20:11:23.0048 4028 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
20:11:23.0055 4028 Processor - ok
20:11:23.0058 4028 [ 5C78838B4D166D1A27DB3A8A820C799A ] ProfSvc C:\Windows\system32\profsvc.dll
20:11:23.0081 4028 ProfSvc - ok
20:11:23.0083 4028 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
20:11:23.0089 4028 ProtectedStorage - ok
20:11:23.0092 4028 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
20:11:23.0113 4028 Psched - ok
20:11:23.0127 4028 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
20:11:23.0150 4028 ql2300 - ok
20:11:23.0153 4028 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
20:11:23.0161 4028 ql40xx - ok
20:11:23.0165 4028 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
20:11:23.0177 4028 QWAVE - ok
20:11:23.0179 4028 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
20:11:23.0190 4028 QWAVEdrv - ok
20:11:23.0192 4028 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
20:11:23.0213 4028 RasAcd - ok
20:11:23.0216 4028 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
20:11:23.0236 4028 RasAgileVpn - ok
20:11:23.0239 4028 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
20:11:23.0262 4028 RasAuto - ok
20:11:23.0265 4028 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
20:11:23.0285 4028 Rasl2tp - ok
20:11:23.0290 4028 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
20:11:23.0313 4028 RasMan - ok
20:11:23.0316 4028 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
20:11:23.0337 4028 RasPppoe - ok
20:11:23.0340 4028 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
20:11:23.0362 4028 RasSstp - ok
20:11:23.0367 4028 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
20:11:23.0390 4028 rdbss - ok
20:11:23.0392 4028 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
20:11:23.0400 4028 rdpbus - ok
20:11:23.0402 4028 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
20:11:23.0423 4028 RDPCDD - ok
20:11:23.0426 4028 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
20:11:23.0446 4028 RDPENCDD - ok
20:11:23.0449 4028 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
20:11:23.0469 4028 RDPREFMP - ok
20:11:23.0473 4028 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
20:11:23.0481 4028 RDPWD - ok
20:11:23.0485 4028 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
20:11:23.0493 4028 rdyboost - ok
20:11:23.0496 4028 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
20:11:23.0520 4028 RemoteAccess - ok
20:11:23.0523 4028 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
20:11:23.0546 4028 RemoteRegistry - ok
20:11:23.0550 4028 [ B60F58F175DE20A6739194E85B035178 ] rpcapd C:\Program Files (x86)\WinPcap\rpcapd.exe
20:11:23.0556 4028 rpcapd - ok
20:11:23.0558 4028 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
20:11:23.0579 4028 RpcEptMapper - ok
20:11:23.0582 4028 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
20:11:23.0589 4028 RpcLocator - ok
20:11:23.0595 4028 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
20:11:23.0618 4028 RpcSs - ok
20:11:23.0621 4028 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
20:11:23.0642 4028 rspndr - ok
20:11:23.0648 4028 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
20:11:23.0657 4028 RTL8167 - ok
20:11:23.0660 4028 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
20:11:23.0666 4028 SamSs - ok
20:11:23.0669 4028 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
20:11:23.0675 4028 sbp2port - ok
20:11:23.0679 4028 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
20:11:23.0702 4028 SCardSvr - ok
20:11:23.0704 4028 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
20:11:23.0725 4028 scfilter - ok
20:11:23.0735 4028 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
20:11:23.0767 4028 Schedule - ok
20:11:23.0770 4028 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
20:11:23.0790 4028 SCPolicySvc - ok
20:11:23.0794 4028 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
20:11:23.0803 4028 SDRSVC - ok
20:11:23.0805 4028 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
20:11:23.0826 4028 secdrv - ok
20:11:23.0828 4028 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
20:11:23.0849 4028 seclogon - ok
20:11:23.0852 4028 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
20:11:23.0874 4028 SENS - ok
20:11:23.0876 4028 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
20:11:23.0884 4028 SensrSvc - ok
20:11:23.0886 4028 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
20:11:23.0893 4028 Serenum - ok
20:11:23.0896 4028 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
20:11:23.0903 4028 Serial - ok
20:11:23.0906 4028 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
20:11:23.0913 4028 sermouse - ok
20:11:23.0919 4028 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
20:11:23.0941 4028 SessionEnv - ok
20:11:23.0943 4028 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
20:11:23.0952 4028 sffdisk - ok
20:11:23.0954 4028 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
20:11:23.0962 4028 sffp_mmc - ok
20:11:23.0964 4028 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
20:11:23.0972 4028 sffp_sd - ok
20:11:23.0975 4028 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
20:11:23.0982 4028 sfloppy - ok
20:11:23.0987 4028 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
20:11:24.0012 4028 SharedAccess - ok
20:11:24.0017 4028 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
20:11:24.0042 4028 ShellHWDetection - ok
20:11:24.0045 4028 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
20:11:24.0050 4028 SiSRaid2 - ok
20:11:24.0053 4028 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
20:11:24.0059 4028 SiSRaid4 - ok
20:11:24.0063 4028 [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
20:11:24.0069 4028 SkypeUpdate - ok
20:11:24.0072 4028 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
20:11:24.0094 4028 Smb - ok
20:11:24.0099 4028 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
20:11:24.0106 4028 SNMPTRAP - ok
20:11:24.0108 4028 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
20:11:24.0114 4028 spldr - ok
20:11:24.0120 4028 [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler C:\Windows\System32\spoolsv.exe
20:11:24.0146 4028 Spooler - ok
20:11:24.0177 4028 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
20:11:24.0233 4028 sppsvc - ok
20:11:24.0236 4028 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
20:11:24.0258 4028 sppuinotify - ok
20:11:24.0264 4028 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
20:11:24.0275 4028 srv - ok
20:11:24.0281 4028 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
20:11:24.0291 4028 srv2 - ok
20:11:24.0295 4028 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
20:11:24.0303 4028 srvnet - ok
20:11:24.0306 4028 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
20:11:24.0329 4028 SSDPSRV - ok
20:11:24.0332 4028 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
20:11:24.0354 4028 SstpSvc - ok
20:11:24.0357 4028 Steam Client Service - ok
20:11:24.0362 4028 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
20:11:24.0371 4028 Stereo Service - ok
20:11:24.0374 4028 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
20:11:24.0379 4028 stexstor - ok
20:11:24.0386 4028 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
20:11:24.0402 4028 stisvc - ok
20:11:24.0404 4028 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
20:11:24.0410 4028 swenum - ok
20:11:24.0415 4028 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
20:11:24.0442 4028 swprv - ok
20:11:24.0458 4028 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
20:11:24.0484 4028 SysMain - ok
20:11:24.0487 4028 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
20:11:24.0498 4028 TabletInputService - ok
20:11:24.0503 4028 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
20:11:24.0527 4028 TapiSrv - ok
20:11:24.0529 4028 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
20:11:24.0550 4028 TBS - ok
20:11:24.0571 4028 [ B62A953F2BF3922C8764A29C34A22899 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
20:11:24.0600 4028 Tcpip - ok
20:11:24.0619 4028 [ B62A953F2BF3922C8764A29C34A22899 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
20:11:24.0641 4028 TCPIP6 - ok
20:11:24.0645 4028 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
20:11:24.0665 4028 tcpipreg - ok
20:11:24.0668 4028 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
20:11:24.0675 4028 TDPIPE - ok
20:11:24.0677 4028 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
20:11:24.0683 4028 TDTCP - ok
20:11:24.0686 4028 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
20:11:24.0706 4028 tdx - ok
20:11:24.0709 4028 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
20:11:24.0714 4028 TermDD - ok
20:11:24.0722 4028 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
20:11:24.0749 4028 TermService - ok
20:11:24.0753 4028 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
20:11:24.0763 4028 Themes - ok
20:11:24.0766 4028 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
20:11:24.0786 4028 THREADORDER - ok
20:11:24.0789 4028 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
20:11:24.0811 4028 TrkWks - ok
20:11:24.0815 4028 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
20:11:24.0836 4028 TrustedInstaller - ok
20:11:24.0839 4028 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
20:11:24.0859 4028 tssecsrv - ok
20:11:24.0862 4028 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
20:11:24.0869 4028 TsUsbFlt - ok
20:11:24.0871 4028 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
20:11:24.0877 4028 TsUsbGD - ok
20:11:24.0880 4028 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
20:11:24.0901 4028 tunnel - ok
20:11:24.0903 4028 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
20:11:24.0909 4028 uagp35 - ok
20:11:24.0914 4028 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
20:11:24.0937 4028 udfs - ok
20:11:24.0941 4028 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
20:11:24.0949 4028 UI0Detect - ok
20:11:24.0951 4028 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
20:11:24.0957 4028 uliagpkx - ok
20:11:24.0960 4028 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
20:11:24.0967 4028 umbus - ok
20:11:24.0969 4028 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
20:11:24.0976 4028 UmPass - ok
20:11:24.0981 4028 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
20:11:25.0006 4028 upnphost - ok
20:11:25.0009 4028 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
20:11:25.0016 4028 USBAAPL64 - ok
20:11:25.0019 4028 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
20:11:25.0028 4028 usbaudio - ok
20:11:25.0031 4028 [ 481DFF26B4DCA8F4CBAC1F7DCE1D6829 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
20:11:25.0038 4028 usbccgp - ok
20:11:25.0041 4028 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
20:11:25.0050 4028 usbcir - ok
20:11:25.0052 4028 [ 74EE782B1D9C241EFE425565854C661C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
20:11:25.0059 4028 usbehci - ok
20:11:25.0064 4028 [ DC96BD9CCB8403251BCF25047573558E ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
20:11:25.0074 4028 usbhub - ok
20:11:25.0076 4028 [ 58E546BBAF87664FC57E0F6081E4F609 ] usbohci C:\Windows\system32\drivers\usbohci.sys
20:11:25.0083 4028 usbohci - ok
20:11:25.0085 4028 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\drivers\usbprint.sys
20:11:25.0094 4028 usbprint - ok
20:11:25.0096 4028 [ D76510CFA0FC09023077F22C2F979D86 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
20:11:25.0104 4028 USBSTOR - ok
20:11:25.0106 4028 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
20:11:25.0114 4028 usbuhci - ok
20:11:25.0117 4028 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
20:11:25.0127 4028 usbvideo - ok
20:11:25.0130 4028 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
20:11:25.0152 4028 UxSms - ok
20:11:25.0154 4028 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
20:11:25.0161 4028 VaultSvc - ok
20:11:25.0163 4028 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
20:11:25.0168 4028 vdrvroot - ok
20:11:25.0175 4028 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
20:11:25.0201 4028 vds - ok
20:11:25.0203 4028 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
20:11:25.0211 4028 vga - ok
20:11:25.0213 4028 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
20:11:25.0234 4028 VgaSave - ok
20:11:25.0238 4028 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
20:11:25.0246 4028 vhdmp - ok
20:11:25.0248 4028 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
20:11:25.0254 4028 viaide - ok
20:11:25.0256 4028 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
20:11:25.0263 4028 volmgr - ok
20:11:25.0267 4028 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
20:11:25.0277 4028 volmgrx - ok
20:11:25.0281 4028 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
20:11:25.0290 4028 volsnap - ok
20:11:25.0293 4028 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
20:11:25.0301 4028 vsmraid - ok
20:11:25.0314 4028 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
20:11:25.0350 4028 VSS - ok
20:11:25.0352 4028 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
20:11:25.0361 4028 vwifibus - ok
20:11:25.0366 4028 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
20:11:25.0390 4028 W32Time - ok
20:11:25.0394 4028 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
20:11:25.0401 4028 WacomPen - ok
20:11:25.0403 4028 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
20:11:25.0424 4028 WANARP - ok
20:11:25.0426 4028 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
20:11:25.0446 4028 Wanarpv6 - ok
20:11:25.0460 4028 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
20:11:25.0482 4028 wbengine - ok
20:11:25.0485 4028 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
20:11:25.0497 4028 WbioSrvc - ok
20:11:25.0502 4028 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
20:11:25.0516 4028 wcncsvc - ok
20:11:25.0518 4028 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
20:11:25.0526 4028 WcsPlugInService - ok
20:11:25.0528 4028 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
20:11:25.0533 4028 Wd - ok
20:11:25.0540 4028 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
20:11:25.0553 4028 Wdf01000 - ok
20:11:25.0556 4028 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
20:11:25.0578 4028 WdiServiceHost - ok
20:11:25.0580 4028 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
20:11:25.0590 4028 WdiSystemHost - ok
20:11:25.0594 4028 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
20:11:25.0606 4028 WebClient - ok
20:11:25.0610 4028 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
20:11:25.0634 4028 Wecsvc - ok
20:11:25.0637 4028 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
20:11:25.0659 4028 wercplsupport - ok
20:11:25.0661 4028 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
20:11:25.0683 4028 WerSvc - ok
20:11:25.0685 4028 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
20:11:25.0705 4028 WfpLwf - ok
20:11:25.0708 4028 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
20:11:25.0713 4028 WIMMount - ok
20:11:25.0714 4028 WinDefend - ok
20:11:25.0718 4028 WinHttpAutoProxySvc - ok
20:11:25.0725 4028 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
20:11:25.0747 4028 Winmgmt - ok
20:11:25.0765 4028 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
20:11:25.0803 4028 WinRM - ok
20:11:25.0808 4028 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
20:11:25.0816 4028 WinUsb - ok
20:11:25.0825 4028 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
20:11:25.0844 4028 Wlansvc - ok
20:11:25.0846 4028 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
20:11:25.0852 4028 WmiAcpi - ok
20:11:25.0857 4028 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
20:11:25.0866 4028 wmiApSrv - ok
20:11:25.0867 4028 WMPNetworkSvc - ok
20:11:25.0870 4028 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
20:11:25.0877 4028 WPCSvc - ok
20:11:25.0880 4028 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
20:11:25.0888 4028 WPDBusEnum - ok
20:11:25.0891 4028 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
20:11:25.0911 4028 ws2ifsl - ok
20:11:25.0914 4028 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
20:11:25.0925 4028 wscsvc - ok
20:11:25.0927 4028 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
20:11:25.0935 4028 WSDPrintDevice - ok
20:11:25.0937 4028 WSearch - ok
20:11:25.0960 4028 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
20:11:25.0994 4028 wuauserv - ok
20:11:25.0997 4028 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
20:11:26.0018 4028 WudfPf - ok
20:11:26.0022 4028 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
20:11:26.0043 4028 WUDFRd - ok
20:11:26.0046 4028 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
20:11:26.0067 4028 wudfsvc - ok
20:11:26.0071 4028 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
20:11:26.0083 4028 WwanSvc - ok
20:11:26.0086 4028 ================ Scan global ===============================
20:11:26.0088 4028 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
20:11:26.0092 4028 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:11:26.0097 4028 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
20:11:26.0100 4028 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
20:11:26.0105 4028 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
20:11:26.0108 4028 [Global] - ok
20:11:26.0108 4028 ================ Scan MBR ==================================
20:11:26.0110 4028 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
20:11:26.0216 4028 \Device\Harddisk0\DR0 - ok
20:11:26.0218 4028 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk3\DR3
20:11:26.0264 4028 \Device\Harddisk3\DR3 - ok
20:11:26.0266 4028 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
20:11:26.0314 4028 \Device\Harddisk2\DR2 - ok
20:11:26.0320 4028 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
20:11:26.0448 4028 \Device\Harddisk1\DR1 - ok
20:11:26.0449 4028 ================ Scan VBR ==================================
20:11:26.0452 4028 [ C2B6D49819D82D967F2454EE37621107 ] \Device\Harddisk0\DR0\Partition1
20:11:26.0454 4028 \Device\Harddisk0\DR0\Partition1 - ok
20:11:26.0455 4028 [ 2EAA5D60427984F42D1965CAD5141068 ] \Device\Harddisk0\DR0\Partition2
20:11:26.0457 4028 \Device\Harddisk0\DR0\Partition2 - ok
20:11:26.0458 4028 [ 9513F74D205621C1F412A251DB6683B9 ] \Device\Harddisk3\DR3\Partition1
20:11:26.0460 4028 \Device\Harddisk3\DR3\Partition1 - ok
20:11:26.0462 4028 [ EFFF9AEB5F4F3B66AA62DD21637D7AB5 ] \Device\Harddisk2\DR2\Partition1
20:11:26.0463 4028 \Device\Harddisk2\DR2\Partition1 - ok
20:11:26.0465 4028 [ ED5FBE4FE0488AE80B4F6D932F825702 ] \Device\Harddisk1\DR1\Partition1
20:11:26.0466 4028 \Device\Harddisk1\DR1\Partition1 - ok
20:11:26.0467 4028 ============================================================
20:11:26.0467 4028 Scan finished
20:11:26.0467 4028 ============================================================
20:11:26.0473 4532 Detected object count: 0
20:11:26.0473 4532 Actual detected object count: 0
20:13:04.0846 3444 Deinitialize success aswMBR log Code:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-05-06 19:52:38
-----------------------------
19:52:38.564 OS Version: Windows x64 6.1.7601 Service Pack 1
19:52:38.564 Number of processors: 4 586 0x2A07
19:52:38.564 ComputerName: ***-PC UserName: ***
19:52:38.904 Initialize success
20:04:14.583 AVAST engine defs: 13050501
20:05:56.387 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
20:05:56.390 Disk 0 Vendor: MKNSSDCR120GB 502ABBF0 Size: 114473MB BusType: 11
20:05:56.392 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP5T0L0-5
20:05:56.395 Disk 1 Vendor: ST3160811AS 3.AAE Size: 152627MB BusType: 11
20:05:56.398 Disk 2 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP4T0L0-4
20:05:56.400 Disk 2 Vendor: SAMSUNG_HD204UI 1AQ10001 Size: 1907729MB BusType: 11
20:05:56.404 Disk 3 \Device\Harddisk3\DR3 -> \Device\Ide\IdeDeviceP3T0L0-3
20:05:56.407 Disk 3 Vendor: SAMSUNG_HD204UI 1AQ10001 Size: 1907729MB BusType: 11
20:05:56.415 Disk 0 MBR read successfully
20:05:56.420 Disk 0 MBR scan
20:05:56.423 Disk 0 Windows 7 default MBR code
20:05:56.425 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
20:05:56.428 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 114371 MB offset 206848
20:05:56.436 Disk 0 scanning C:\Windows\system32\drivers
20:05:58.298 Service scanning
20:06:03.434 Modules scanning
20:06:03.441 Disk 0 trace - called modules:
20:06:03.448 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
20:06:03.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007530060]
20:06:03.458 3 CLASSPNP.SYS[fffff880018ca43f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa8007309680]
20:06:03.730 AVAST engine scan C:\Windows
20:06:04.182 AVAST engine scan C:\Windows\system32
20:06:52.434 AVAST engine scan C:\Windows\system32\drivers
20:06:54.730 AVAST engine scan C:\Users\***
20:06:57.904 File: C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O59L5QVH\InstallMonetizer-PriceGong_v2[1].exe **INFECTED** Win32:SaliCode
20:06:58.084 File: C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YBAYL85N\crush_vsti_5805[1].exe **INFECTED** Win32:SaliCode
20:07:05.325 File: C:\Users\***\AppData\Local\PunkBuster\ACB\pb\PnkBstrA.exe **INFECTED** Win32:SaliCode
20:07:05.349 File: C:\Users\***\AppData\Local\PunkBuster\ACB\pb\PnkBstrB.exe **INFECTED** Win32:SaliCode
20:07:05.439 File: C:\Users\***\AppData\Local\Temp\0038258A_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.491 File: C:\Users\***\AppData\Local\Temp\00385457_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:05.537 File: C:\Users\***\AppData\Local\Temp\0041120A_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:05.582 File: C:\Users\***\AppData\Local\Temp\00414FC5_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.627 File: C:\Users\***\AppData\Local\Temp\0044D02B_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.671 File: C:\Users\***\AppData\Local\Temp\0044FE8A_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.715 File: C:\Users\***\AppData\Local\Temp\00895E19_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.760 File: C:\Users\***\AppData\Local\Temp\00898651_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.830 File: C:\Users\***\AppData\Local\Temp\0109F01D_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.873 File: C:\Users\***\AppData\Local\Temp\010BBC80_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.918 File: C:\Users\***\AppData\Local\Temp\0112E093_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:05.966 File: C:\Users\***\AppData\Local\Temp\0143C660_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.032 File: C:\Users\***\AppData\Local\Temp\01454408_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.099 File: C:\Users\***\AppData\Local\Temp\01455EC8_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:06.162 File: C:\Users\***\AppData\Local\Temp\014797F1_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.226 File: C:\Users\***\AppData\Local\Temp\015136CF_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.293 File: C:\Users\***\AppData\Local\Temp\0156F6E2_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:06.336 File: C:\Users\***\AppData\Local\Temp\01571931_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.381 File: C:\Users\***\AppData\Local\Temp\01655B11_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:06.426 File: C:\Users\***\AppData\Local\Temp\0165A099_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.473 File: C:\Users\***\AppData\Local\Temp\016C017D_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.519 File: C:\Users\***\AppData\Local\Temp\017007F3_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.564 File: C:\Users\***\AppData\Local\Temp\0176265B_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.610 File: C:\Users\***\AppData\Local\Temp\0178DC90_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.656 File: C:\Users\***\AppData\Local\Temp\01B0B717_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:06.707 File: C:\Users\***\AppData\Local\Temp\01B474F9_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.755 File: C:\Users\***\AppData\Local\Temp\01E2F926_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.829 File: C:\Users\***\AppData\Local\Temp\01E318A8_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.879 File: C:\Users\***\AppData\Local\Temp\01E6A202_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.927 File: C:\Users\***\AppData\Local\Temp\020EC980_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:06.975 File: C:\Users\***\AppData\Local\Temp\02105E21_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.022 File: C:\Users\***\AppData\Local\Temp\02113250_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:07.067 File: C:\Users\***\AppData\Local\Temp\0219B841_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:07.122 File: C:\Users\***\AppData\Local\Temp\02B76796_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.174 File: C:\Users\***\AppData\Local\Temp\02B78C07_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.225 File: C:\Users\***\AppData\Local\Temp\0318F823_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.279 File: C:\Users\***\AppData\Local\Temp\03191CC3_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.359 File: C:\Users\***\AppData\Local\Temp\032055AE_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.414 File: C:\Users\***\AppData\Local\Temp\0326D2AA_Rar\legoria3.exe **INFECTED** Win32:SaliCode
20:07:07.478 File: C:\Users\***\AppData\Local\Temp\0332C64B_Rar\legoria3.exe **INFECTED** Win32:Sality
20:07:07.895 File: C:\Users\***\AppData\Local\Temp\oi_5PXETZwuYP\OIAssistWTD.exe **INFECTED** Win32:SaliCode
20:07:08.566 File: C:\Users\***\AppData\Local\Temp\Temp1_depends22_x86.zip\depends.exe **INFECTED** Win32:SaliCode
20:07:08.629 File: C:\Users\***\AppData\Local\Temp\Temp1_nethack-343-win.zip\NetHack.exe **INFECTED** Win32:SaliCode
20:07:08.710 File: C:\Users\***\AppData\Local\Temp\windaodjc.exe **INFECTED** Win32:Sality-GR
20:07:08.727 File: C:\Users\***\AppData\Local\Temp\winrjea.exe **INFECTED** Win32:Sality-GR
20:07:08.746 File: C:\Users\***\AppData\Local\Temp\winvveu.exe **INFECTED** Win32:Sality-GR
20:07:14.076 File: C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxUninstaller.exe **INFECTED** Win32:SaliCode
20:07:14.099 File: C:\Users\***\AppData\Roaming\Dropbox\bin\DropboxUpdateHelper.exe **INFECTED** Win32:SaliCode
20:07:15.820 File: C:\Users\***\AppData\Roaming\PunkBuster\pbsetup\pbsvc.exe **INFECTED** Win32:SaliCode
20:07:17.409 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\gspawn-win32-helper-console.exe **INFECTED** Win32:SaliCode
20:07:17.424 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\gspawn-win32-helper.exe **INFECTED** Win32:Sality
20:07:17.528 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\inkscape.exe **INFECTED** Win32:SaliCode
20:07:17.582 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\inkview.exe **INFECTED** Win32:SaliCode
20:07:20.091 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\Lib\distutils\command\wininst-6.0.exe **INFECTED** Win32:SaliCode
20:07:20.105 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\Lib\distutils\command\wininst-6.exe **INFECTED** Win32:SaliCode
20:07:20.120 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\Lib\distutils\command\wininst-7.1.exe **INFECTED** Win32:SaliCode
20:07:20.136 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\Lib\distutils\command\wininst-8.0.exe **INFECTED** Win32:SaliCode
20:07:20.161 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\Lib\distutils\command\wininst-9.0.exe **INFECTED** Win32:Sality
20:07:21.632 File: C:\Users\***\Desktop\***\JK\InkscapePortable\App\Inkscape\python\pythonw.exe **INFECTED** Win32:Sality
20:07:25.296 File: C:\Users\***\Desktop\Heroes of Might and Magic V - Tribes of the East\registration\RegistrationReminder.exe **INFECTED** Win32:SaliCode
20:07:31.586 File: C:\Users\***\Desktop\Minecraft.exe **INFECTED** Win32:SaliCode
20:07:31.776 File: C:\Users\***\Desktop\Shaiya\Shaiya-DE\CONFIG.exe **INFECTED** Win32:SaliCode
20:07:31.836 File: C:\Users\***\Desktop\Shaiya\Shaiya-DE\game.exe **INFECTED** Win32:Sality
20:07:31.925 File: C:\Users\***\Desktop\Shaiya\Shaiya-DE\Updater.exe **INFECTED** Win32:SaliCode
20:07:36.009 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\32\dlsdump.exe **INFECTED** Win32:SaliCode
20:07:36.027 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\32\gigdump.exe **INFECTED** Win32:SaliCode
20:07:36.060 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\32\gigextract.exe **INFECTED** Win32:Sality
20:07:37.123 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\32\rifftree.exe **INFECTED** Win32:SaliCode
20:07:38.047 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\qsampler.exe **INFECTED** Win32:Sality
20:07:38.142 File: C:\Users\***\Musik\VSTPlugins\LinuxSampler\uninstall.exe **INFECTED** Win32:SaliCode
20:07:38.414 AVAST engine scan C:\ProgramData
20:07:39.766 Scan finished successfully
20:10:10.073 Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\MBR.dat"
20:10:10.077 The log file has been saved successfully to "C:\Users\***\Desktop\aswMBR.txt" |