22:57:23.0308 3728 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
22:57:23.0542 3728 ============================================================
22:57:23.0542 3728 Current date / time: 2012/10/07 22:57:23.0542
22:57:23.0542 3728 SystemInfo:
22:57:23.0542 3728
22:57:23.0542 3728 OS Version: 5.1.2600 ServicePack: 2.0
22:57:23.0542 3728 Product type: Workstation
22:57:23.0542 3728 ComputerName: ACER-88C919EA93
22:57:23.0542 3728 UserName: Administrator
22:57:23.0542 3728 Windows directory: C:\WINDOWS
22:57:23.0542 3728 System windows directory: C:\WINDOWS
22:57:23.0542 3728 Processor architecture: Intel x86
22:57:23.0542 3728 Number of processors: 2
22:57:23.0542 3728 Page size: 0x1000
22:57:23.0542 3728 Boot type: Normal boot
22:57:23.0542 3728 ============================================================
22:57:24.0699 3728 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
22:57:24.0792 3728 ============================================================
22:57:24.0792 3728 \Device\Harddisk0\DR0:
22:57:24.0808 3728 MBR partitions:
22:57:24.0808 3728 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2711637
22:57:24.0824 3728 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27116B5, BlocksNum 0x1030354B
22:57:24.0824 3728 ============================================================
22:57:24.0886 3728 C: <-> \Device\Harddisk0\DR0\Partition1
22:57:25.0058 3728 D: <-> \Device\Harddisk0\DR0\Partition2
22:57:25.0058 3728 ============================================================
22:57:25.0058 3728 Initialize success
22:57:25.0058 3728 ============================================================
22:58:54.0027 4072 ============================================================
22:58:54.0027 4072 Scan started
22:58:54.0027 4072 Mode: Manual;
22:58:54.0027 4072 ============================================================
22:58:54.0464 4072 ================ Scan system memory ========================
22:58:54.0464 4072 System memory - ok
22:58:54.0464 4072 ================ Scan services =============================
22:58:54.0636 4072 [ 0352A73CD6B1782EA3ED7A03A8268F55 ] Aavmker4 C:\WINDOWS\system32\drivers\Aavmker4.sys
22:58:54.0636 4072 Aavmker4 - ok
22:58:54.0652 4072 Abiosdsk - ok
22:58:54.0652 4072 abp480n5 - ok
22:58:54.0699 4072 [ A10C7534F7223F4A73A948967D00E69B ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:58:54.0714 4072 ACPI - ok
22:58:54.0777 4072 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:58:54.0777 4072 ACPIEC - ok
22:58:54.0824 4072 [ 6D7F09CD92A9FEF3A8EFCE66231FDD79 ] adfs C:\WINDOWS\system32\drivers\adfs.sys
22:58:54.0824 4072 adfs - ok
22:58:54.0839 4072 adpu160m - ok
22:58:54.0886 4072 [ 1EE7B434BA961EF845DE136224C30FEC ] aec C:\WINDOWS\system32\drivers\aec.sys
22:58:54.0902 4072 aec - ok
22:58:54.0949 4072 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys
22:58:54.0964 4072 AFD - ok
22:58:54.0964 4072 Aha154x - ok
22:58:54.0980 4072 aic78u2 - ok
22:58:54.0980 4072 aic78xx - ok
22:58:55.0011 4072 [ C7AE0FD3867DB0D42B03B73C18F3D671 ] Alerter C:\WINDOWS\system32\alrsvc.dll
22:58:55.0027 4072 Alerter - ok
22:58:55.0058 4072 [ F1958FBF86D5C004CF19A5951A9514B7 ] ALG C:\WINDOWS\System32\alg.exe
22:58:55.0074 4072 ALG - ok
22:58:55.0089 4072 AliIde - ok
22:58:55.0089 4072 amsint - ok
22:58:55.0136 4072 [ 9C3C12975C97119412802B181FBEEFFE ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:58:55.0152 4072 AppMgmt - ok
22:58:55.0199 4072 [ F0D692B0BFFB46E30EB3CEA168BBC49F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
22:58:55.0199 4072 Arp1394 - ok
22:58:55.0199 4072 asc - ok
22:58:55.0214 4072 asc3350p - ok
22:58:55.0214 4072 asc3550 - ok
22:58:55.0339 4072 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
22:58:55.0355 4072 aspnet_state - ok
22:58:55.0402 4072 [ F5DC168BF77572D51BE28BA261B30CB4 ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
22:58:55.0402 4072 aswFsBlk - ok
22:58:55.0449 4072 [ 2B9B1DF809E965EF63402CBBA6DB50AE ] aswMon2 C:\WINDOWS\system32\drivers\aswMon2.sys
22:58:55.0449 4072 aswMon2 - ok
22:58:55.0464 4072 [ B7D5E4486BA658ED08624D8084ABB830 ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
22:58:55.0480 4072 AswRdr - ok
22:58:55.0495 4072 [ 30E45AF8B4D83176CA850FC9699E860B ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
22:58:55.0511 4072 aswSnx - ok
22:58:55.0527 4072 [ F04BDBCB965C05C51F4A7DE7B62063D6 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
22:58:55.0527 4072 aswSP - ok
22:58:55.0542 4072 [ DFE9152ABFA89BB8CFDC057409B2D4DA ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
22:58:55.0542 4072 aswTdi - ok
22:58:55.0589 4072 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:58:55.0589 4072 AsyncMac - ok
22:58:55.0636 4072 [ CDFE4411A69C224BD1D11B2DA92DAC51 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:58:55.0636 4072 atapi - ok
22:58:55.0652 4072 Atdisk - ok
22:58:55.0699 4072 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:58:55.0699 4072 Atmarpc - ok
22:58:55.0745 4072 [ DB66DB626E4882EBEF55F136F12C1829 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:58:55.0761 4072 AudioSrv - ok
22:58:55.0824 4072 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:58:55.0824 4072 audstub - ok
22:58:55.0980 4072 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
22:58:55.0980 4072 avast! Antivirus - ok
22:58:56.0027 4072 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
22:58:56.0027 4072 Beep - ok
22:58:56.0089 4072 [ 17A0D43C80DB5348759C649835A78CFC ] BITS C:\WINDOWS\system32\qmgr.dll
22:58:56.0120 4072 BITS - ok
22:58:56.0167 4072 [ 39128B5A743545BAEDD3984C210F00A8 ] Browser C:\WINDOWS\System32\browser.dll
22:58:56.0183 4072 Browser - ok
22:58:56.0245 4072 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:58:56.0245 4072 cbidf2k - ok
22:58:56.0245 4072 cd20xrnt - ok
22:58:56.0308 4072 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:58:56.0308 4072 Cdaudio - ok
22:58:56.0355 4072 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:58:56.0355 4072 Cdfs - ok
22:58:56.0402 4072 [ 7B53584D94E9D8716B2DE91D5F1CB42D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:58:56.0417 4072 Cdrom - ok
22:58:56.0417 4072 Changer - ok
22:58:56.0464 4072 [ 3192BD04D032A9C4A85A3278C268A13A ] CiSvc C:\WINDOWS\system32\cisvc.exe
22:58:56.0480 4072 CiSvc - ok
22:58:56.0527 4072 [ C8DEC22C4137D7A90F8BDF41CA4B82AE ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:58:56.0542 4072 ClipSrv - ok
22:58:56.0589 4072 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:58:56.0605 4072 clr_optimization_v2.0.50727_32 - ok
22:58:56.0605 4072 CmdIde - ok
22:58:56.0620 4072 COMSysApp - ok
22:58:56.0620 4072 Cpqarray - ok
22:58:56.0667 4072 [ 87F3E2D2A3231F820F9248DB90090F42 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:58:56.0683 4072 CryptSvc - ok
22:58:56.0683 4072 dac2w2k - ok
22:58:56.0699 4072 dac960nt - ok
22:58:56.0745 4072 [ 348F04E3582EF2467EE5379D67B99FD7 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:58:56.0777 4072 DcomLaunch - ok
22:58:56.0824 4072 [ 3F15A1DBD86F7BDAF404648282D11ECE ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:58:56.0855 4072 Dhcp - ok
22:58:56.0902 4072 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:58:56.0902 4072 Disk - ok
22:58:56.0917 4072 dmadmin - ok
22:58:56.0980 4072 [ C0FBB516E06E243F0CF31F597E7EBF7D ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:58:57.0011 4072 dmboot - ok
22:58:57.0042 4072 [ F5E7B358A732D09F4BCF2824B88B9E28 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
22:58:57.0074 4072 dmio - ok
22:58:57.0120 4072 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
22:58:57.0120 4072 dmload - ok
22:58:57.0167 4072 [ 1639D9964C9E1B2ECCA95C8217D3E70D ] dmserver C:\WINDOWS\System32\dmserver.dll
22:58:57.0183 4072 dmserver - ok
22:58:57.0245 4072 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:58:57.0245 4072 DMusic - ok
22:58:57.0292 4072 [ 7379DE06FD196E396A00AA97B990C00D ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:58:57.0308 4072 Dnscache - ok
22:58:57.0324 4072 dpti2o - ok
22:58:57.0324 4072 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:58:57.0324 4072 drmkaud - ok
22:58:57.0386 4072 [ 67DFF7BBBD0E80AAB7B3CF061448DB8A ] ERSvc C:\WINDOWS\System32\ersvc.dll
22:58:57.0402 4072 ERSvc - ok
22:58:57.0449 4072 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] Eventlog C:\WINDOWS\system32\services.exe
22:58:57.0480 4072 Eventlog - ok
22:58:57.0495 4072 [ 3D9418CF112A11ADC45E2A0C0A44DF47 ] EventSystem C:\WINDOWS\system32\es.dll
22:58:57.0511 4072 EventSystem - ok
22:58:57.0558 4072 [ 3117F595E9615E04F05A54FC15A03B20 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:58:57.0574 4072 Fastfat - ok
22:58:57.0636 4072 [ 53D9184A21C5CBF600D918E51EF3A7E5 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:58:57.0652 4072 FastUserSwitchingCompatibility - ok
22:58:57.0667 4072 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:58:57.0667 4072 Fdc - ok
22:58:57.0714 4072 [ E153AB8A11DE5452BCF5AC7652DBF3ED ] Fips C:\WINDOWS\system32\drivers\Fips.sys
22:58:57.0730 4072 Fips - ok
22:58:57.0839 4072 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:58:57.0855 4072 FLEXnet Licensing Service - ok
22:58:57.0902 4072 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:58:57.0902 4072 Flpydisk - ok
22:58:57.0964 4072 [ 6CC5181F718820861EEADAE38F764B75 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:58:57.0980 4072 FltMgr - ok
22:58:58.0027 4072 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:58:58.0027 4072 Fs_Rec - ok
22:58:58.0089 4072 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:58:58.0105 4072 Ftdisk - ok
22:58:58.0152 4072 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:58:58.0167 4072 Gpc - ok
22:58:58.0230 4072 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
22:58:58.0245 4072 gusvc - ok
22:58:58.0292 4072 [ 3FCC124B6E08EE0E9351F717DD136939 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:58:58.0292 4072 HDAudBus - ok
22:58:58.0402 4072 [ 8827911A8C37E40C027CBFC88E69D967 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:58:58.0417 4072 helpsvc - ok
22:58:58.0480 4072 [ 9376E6893E52B368ABC6255BF54F0B28 ] HidServ C:\WINDOWS\System32\hidserv.dll
22:58:58.0495 4072 HidServ - ok
22:58:58.0511 4072 [ 1DE6783B918F540149AA69943BDFEBA8 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:58:58.0511 4072 hidusb - ok
22:58:58.0511 4072 hpn - ok
22:58:58.0558 4072 [ 30CA91E657CEDE2F95359D6EF186F650 ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
22:58:58.0558 4072 HPZid412 - ok
22:58:58.0605 4072 [ EFD31AFA752AA7C7BBB57BCBE2B01C78 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
22:58:58.0605 4072 HPZipr12 - ok
22:58:58.0652 4072 [ 7AC43C38CA8FD7ED0B0A4466F753E06E ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
22:58:58.0667 4072 HPZius12 - ok
22:58:58.0714 4072 [ CA9A02A72CC7CBDA40AFB457AEA77D2E ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:58:58.0730 4072 HTTP - ok
22:58:58.0777 4072 [ 064D8581ADF77C25133E7D751D917D83 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:58:58.0792 4072 HTTPFilter - ok
22:58:58.0808 4072 i2omgmt - ok
22:58:58.0808 4072 i2omp - ok
22:58:58.0839 4072 [ 5502B58EEF7486EE6F93F3F164DCB808 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:58:58.0839 4072 i8042prt - ok
22:58:58.0902 4072 [ 12C59B8929121ACE2F55ACC86682CF12 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:58:58.0902 4072 Imapi - ok
22:58:58.0917 4072 [ FA788520BCAC0F5D9D5CDE5615C0D931 ] ImapiService C:\WINDOWS\system32\imapi.exe
22:58:58.0933 4072 ImapiService - ok
22:58:58.0933 4072 ini910u - ok
22:58:59.0074 4072 [ 3000E98F519CF6FDA669BAE8E47F7B4F ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:58:59.0105 4072 IntcAzAudAddService - ok
22:58:59.0105 4072 IntelIde - ok
22:58:59.0152 4072 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:58:59.0152 4072 Ip6Fw - ok
22:58:59.0199 4072 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:58:59.0199 4072 IpFilterDriver - ok
22:58:59.0245 4072 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:58:59.0261 4072 IpInIp - ok
22:58:59.0277 4072 [ 472C75F85E631F8AA87D21C9FEE6238D ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:58:59.0292 4072 IpNat - ok
22:58:59.0339 4072 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:58:59.0355 4072 IPSec - ok
22:58:59.0402 4072 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:58:59.0402 4072 IRENUM - ok
22:58:59.0417 4072 [ E504F706CCB699C2596E9A3DA1596E87 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:58:59.0417 4072 isapnp - ok
22:58:59.0574 4072 [ 0A5709543986843D37A92290B7838340 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
22:58:59.0605 4072 JavaQuickStarterService - ok
22:58:59.0652 4072 [ EBDEE8A2EE5393890A1ACEE971C4C246 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:58:59.0652 4072 Kbdclass - ok
22:58:59.0652 4072 [ E182FA8E49E8EE41B4ADC53093F3C7E6 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:58:59.0652 4072 kbdhid - ok
22:58:59.0683 4072 [ 8531438246CE9474E41EE1599904C0C7 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:58:59.0683 4072 kmixer - ok
22:58:59.0730 4072 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:58:59.0745 4072 KSecDD - ok
22:58:59.0792 4072 [ 76B15AC51A74BE936EA86EA6E08817CF ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
22:58:59.0808 4072 lanmanserver - ok
22:58:59.0855 4072 [ 2299B1933CD9207630A00676E390F32F ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:58:59.0886 4072 lanmanworkstation - ok
22:58:59.0886 4072 lbrtfdc - ok
22:58:59.0995 4072 [ 6E5DAC168D1FF9843E84A59D51D31107 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
22:59:00.0011 4072 LightScribeService - ok
22:59:00.0058 4072 [ B3EFF6D938C572E90A07B3D87A3C7657 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:59:00.0074 4072 LmHosts - ok
22:59:00.0089 4072 [ 95FD808E4AC22ABA025A7B3EAC0375D2 ] Messenger C:\WINDOWS\System32\msgsvc.dll
22:59:00.0105 4072 Messenger - ok
22:59:00.0152 4072 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:59:00.0152 4072 mnmdd - ok
22:59:00.0199 4072 [ F6415361201915B9FE3896B0E4E724FF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:59:00.0214 4072 mnmsrvc - ok
22:59:00.0261 4072 [ 6FC6F9D7ACC36DCA9B914565A3AEDA05 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
22:59:00.0261 4072 Modem - ok
22:59:00.0277 4072 [ 34E1F0031153E491910E12551400192C ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:59:00.0277 4072 Mouclass - ok
22:59:00.0339 4072 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:59:00.0339 4072 MountMgr - ok
22:59:00.0402 4072 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:59:00.0417 4072 MozillaMaintenance - ok
22:59:00.0417 4072 mraid35x - ok
22:59:00.0464 4072 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:59:00.0480 4072 MRxDAV - ok
22:59:00.0495 4072 [ 321FE492903D8A07F79B7099D71FF578 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:59:00.0527 4072 MRxSmb - ok
22:59:00.0574 4072 [ C7C3D89EB0A6F3DBA622EA737FA335B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
22:59:00.0589 4072 MSDTC - ok
22:59:00.0636 4072 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:59:00.0636 4072 Msfs - ok
22:59:00.0636 4072 MSIServer - ok
22:59:00.0683 4072 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:59:00.0683 4072 MSKSSRV - ok
22:59:00.0699 4072 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:59:00.0714 4072 MSPCLOCK - ok
22:59:00.0714 4072 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:59:00.0714 4072 MSPQM - ok
22:59:00.0761 4072 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:59:00.0761 4072 mssmbios - ok
22:59:00.0824 4072 [ A1DD45CDCD2BF8C57A9A0493C09B00B3 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
22:59:00.0839 4072 Mup - ok
22:59:01.0011 4072 [ 0D01287D85B3715FA8270E8EC919B7F7 ] NBService C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
22:59:01.0042 4072 NBService - ok
22:59:01.0089 4072 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:59:01.0120 4072 NDIS - ok
22:59:01.0261 4072 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:59:01.0261 4072 NdisTapi - ok
22:59:01.0308 4072 [ 77D9BF86B912104C229D4F0D25BE3C12 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:59:01.0308 4072 Ndisuio - ok
22:59:01.0324 4072 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:59:01.0339 4072 NdisWan - ok
22:59:01.0402 4072 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:59:01.0402 4072 NDProxy - ok
22:59:01.0449 4072 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:59:01.0449 4072 NetBIOS - ok
22:59:01.0464 4072 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:59:01.0495 4072 NetBT - ok
22:59:01.0542 4072 [ 05AFB5AD06462257BEA7495283C86D50 ] NetDDE C:\WINDOWS\system32\netdde.exe
22:59:01.0558 4072 NetDDE - ok
22:59:01.0574 4072 [ 05AFB5AD06462257BEA7495283C86D50 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:59:01.0574 4072 NetDDEdsdm - ok
22:59:01.0605 4072 [ 84885F9B82F4D55C6146EBF6065D75D2 ] Netlogon C:\WINDOWS\system32\lsass.exe
22:59:01.0636 4072 Netlogon - ok
22:59:01.0683 4072 [ 3516D8A18B36784B1005B950B84232E1 ] Netman C:\WINDOWS\System32\netman.dll
22:59:01.0699 4072 Netman - ok
22:59:01.0745 4072 [ 5C5C53DB4FEF16CF87B9911C7E8C6FBC ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
22:59:01.0745 4072 NIC1394 - ok
22:59:01.0808 4072 [ 4E74AF063C3271FBEA20DD940CFD1184 ] Nla C:\WINDOWS\System32\mswsock.dll
22:59:01.0824 4072 Nla - ok
22:59:01.0995 4072 [ C4EBBBD7165BE535F0BFD06B80601D91 ] NMIndexingService C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
22:59:02.0011 4072 NMIndexingService - ok
22:59:02.0058 4072 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:59:02.0058 4072 Npfs - ok
22:59:02.0136 4072 [ 52723E766051AC8F0B70491AD91F0079 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:59:02.0152 4072 Ntfs - ok
22:59:02.0167 4072 [ 84885F9B82F4D55C6146EBF6065D75D2 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
22:59:02.0167 4072 NtLmSsp - ok
22:59:02.0230 4072 [ B62F29C00AC55A761B2E45877D85EA0F ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:59:02.0245 4072 NtmsSvc - ok
22:59:02.0292 4072 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
22:59:02.0292 4072 Null - ok
22:59:02.0417 4072 [ B19C2AAE0922072FF4A467F2A37620AD ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:59:02.0511 4072 nv - ok
22:59:02.0558 4072 [ 9ECCD189A9554C30A0D18A429778C7BA ] nvata C:\WINDOWS\system32\DRIVERS\nvata.sys
22:59:02.0574 4072 nvata - ok
22:59:02.0636 4072 [ 9F40402087B6D4A428571DD6CA83AC1E ] NVSvc C:\WINDOWS\system32\nvsvc32.exe
22:59:02.0652 4072 NVSvc - ok
22:59:02.0699 4072 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:59:02.0699 4072 NwlnkFlt - ok
22:59:02.0714 4072 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:59:02.0714 4072 NwlnkFwd - ok
22:59:02.0777 4072 [ FC128C3D7D5AD30A13742DC3737B9DF7 ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
22:59:02.0777 4072 ohci1394 - ok
22:59:02.0839 4072 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:59:02.0855 4072 ose - ok
22:59:02.0902 4072 [ 29744EB4CE659DFE3B4122DEB45BC478 ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
22:59:02.0917 4072 Parport - ok
22:59:02.0964 4072 [ 1628710C352BD79ABEBA234356E2B586 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:59:02.0964 4072 PartMgr - ok
22:59:02.0980 4072 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:59:02.0980 4072 ParVdm - ok
22:59:03.0042 4072 [ 8086D9979234B603AD5BC2F5D890B234 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:59:03.0042 4072 PCI - ok
22:59:03.0042 4072 PCIDump - ok
22:59:03.0089 4072 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:59:03.0089 4072 PCIIde - ok
22:59:03.0105 4072 [ 82A087207DECEC8456FBE8537947D579 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:59:03.0120 4072 Pcmcia - ok
22:59:03.0136 4072 PDCOMP - ok
22:59:03.0136 4072 PDFRAME - ok
22:59:03.0136 4072 PDRELI - ok
22:59:03.0152 4072 PDRFRAME - ok
22:59:03.0152 4072 perc2 - ok
22:59:03.0167 4072 perc2hib - ok
22:59:03.0199 4072 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] PlugPlay C:\WINDOWS\system32\services.exe
22:59:03.0199 4072 PlugPlay - ok
22:59:03.0245 4072 [ D31F88C5F19EEFA366A415D6BC5F2ABC ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.exe
22:59:03.0245 4072 Pml Driver HPZ12 - ok
22:59:03.0261 4072 [ 84885F9B82F4D55C6146EBF6065D75D2 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
22:59:03.0277 4072 PolicyAgent - ok
22:59:03.0308 4072 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:59:03.0324 4072 PptpMiniport - ok
22:59:03.0370 4072 [ 9E372A156F92425A1904B84589093A37 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
22:59:03.0370 4072 Processor - ok
22:59:03.0386 4072 [ 84885F9B82F4D55C6146EBF6065D75D2 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:59:03.0386 4072 ProtectedStorage - ok
22:59:03.0433 4072 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:59:03.0433 4072 PSched - ok
22:59:03.0480 4072 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:59:03.0480 4072 Ptilink - ok
22:59:03.0527 4072 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
22:59:03.0527 4072 PxHelp20 - ok
22:59:03.0542 4072 ql1080 - ok
22:59:03.0542 4072 Ql10wnt - ok
22:59:03.0542 4072 ql12160 - ok
22:59:03.0558 4072 ql1240 - ok
22:59:03.0558 4072 ql1280 - ok
22:59:03.0589 4072 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:59:03.0589 4072 RasAcd - ok
22:59:03.0652 4072 [ 44DB7A9BDD2FB58747D123FBF1D35ADB ] RasAuto C:\WINDOWS\System32\rasauto.dll
22:59:03.0667 4072 RasAuto - ok
22:59:03.0699 4072 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:59:03.0699 4072 Rasl2tp - ok
22:59:03.0745 4072 [ ED5E89DEDB0111E2869CB37D62B46C7A ] RasMan C:\WINDOWS\System32\rasmans.dll
22:59:03.0761 4072 RasMan - ok
22:59:03.0777 4072 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:59:03.0777 4072 RasPppoe - ok
22:59:03.0824 4072 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:59:03.0824 4072 Raspti - ok
22:59:03.0886 4072 [ B48441A6DC703EE4C36DB14EE51A189C ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:59:03.0886 4072 Rdbss - ok
22:59:03.0949 4072 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:59:03.0949 4072 RDPCDD - ok
22:59:03.0995 4072 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:59:04.0027 4072 rdpdr - ok
22:59:04.0058 4072 [ 047BEA21274C8A4A233674A76C958C2C ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:59:04.0089 4072 RDPWD - ok
22:59:04.0136 4072 [ 729798E0933076B8FCFCD9934698F164 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:59:04.0152 4072 RDSessMgr - ok
22:59:04.0199 4072 [ B31B4588E4086D8D84ADBF9845C2402B ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:59:04.0199 4072 redbook - ok
22:59:04.0245 4072 [ 3046DB917E3CFA040632799DD9B14865 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:59:04.0261 4072 RemoteAccess - ok
22:59:04.0308 4072 [ 3151427DB7D87107D1C5BE58FAC53960 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:59:04.0324 4072 RemoteRegistry - ok
22:59:04.0402 4072 [ 793F04A09B15E7C6C11DBDFFAF06C0AB ] RpcLocator C:\WINDOWS\system32\locator.exe
22:59:04.0417 4072 RpcLocator - ok
22:59:04.0449 4072 [ 348F04E3582EF2467EE5379D67B99FD7 ] RpcSs C:\WINDOWS\system32\rpcss.dll
22:59:04.0449 4072 RpcSs - ok
22:59:04.0495 4072 [ 0E11B35E972796042044BC27CE13B065 ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
22:59:04.0495 4072 rspndr - ok
22:59:04.0558 4072 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
22:59:04.0574 4072 RSVP - ok
22:59:04.0589 4072 [ 84885F9B82F4D55C6146EBF6065D75D2 ] SamSs C:\WINDOWS\system32\lsass.exe
22:59:04.0589 4072 SamSs - ok
22:59:04.0636 4072 [ 25D8DE134DF108E3DBC8D7D23B1AA58E ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:59:04.0652 4072 SCardSvr - ok
22:59:04.0699 4072 [ 92360854316611F6CC471612213C3D92 ] Schedule C:\WINDOWS\system32\schedsvc.dll
22:59:04.0714 4072 Schedule - ok
22:59:04.0730 4072 [ 7570380037993520842C2868121A01F9 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:59:04.0745 4072 Secdrv - ok
22:59:04.0792 4072 [ B1E0CE09895376871746F36DC5773B4F ] seclogon C:\WINDOWS\System32\seclogon.dll
22:59:04.0808 4072 seclogon - ok
22:59:04.0870 4072 [ DFD9870CF39C791D86C4C209DA9FA919 ] SENS C:\WINDOWS\system32\sens.dll
22:59:04.0886 4072 SENS - ok
22:59:04.0902 4072 [ A2D868AEEFF612E70E213C451A70CAFB ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
22:59:04.0902 4072 serenum - ok
22:59:04.0917 4072 [ CD9404D115A00D249F70A371B46D5A26 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
22:59:04.0917 4072 Serial - ok
22:59:04.0964 4072 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:59:04.0964 4072 Sfloppy - ok
22:59:05.0027 4072 [ 36CC8C01B5E50163037BEF56CB96DEFF ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:59:05.0042 4072 SharedAccess - ok
22:59:05.0058 4072 [ 53D9184A21C5CBF600D918E51EF3A7E5 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:59:05.0058 4072 ShellHWDetection - ok
22:59:05.0058 4072 Simbad - ok
22:59:05.0292 4072 [ 753D254205E0A62100A050BD8B458D06 ] Skype C2C Service C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
22:59:05.0370 4072 Skype C2C Service - ok
22:59:05.0417 4072 [ EA396139541706B4B433641D62EA53CE ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:59:05.0433 4072 SkypeUpdate - ok
22:59:05.0480 4072 [ 384EED327E9A5BF93C91E8D00D694DF5 ] slnt C:\WINDOWS\system32\DRIVERS\slnt.sys
22:59:05.0480 4072 slnt - ok
22:59:05.0480 4072 Sparrow - ok
22:59:05.0527 4072 [ 9BB1DD670CB7505A90FC4E61D4AA8227 ] splitter C:\WINDOWS\system32\drivers\splitter.sys
22:59:05.0527 4072 splitter - ok
22:59:05.0574 4072 [ AD3D9D191AEA7B5445FE1D82FFBB4788 ] Spooler C:\WINDOWS\system32\spoolsv.exe
22:59:05.0652 4072 Spooler - ok
22:59:05.0761 4072 [ 0022CFFF1A41E5CE3A764050A7DDF22A ] sptd C:\WINDOWS\System32\Drivers\sptd.sys
22:59:05.0792 4072 sptd - ok
22:59:05.0839 4072 [ E41B6D037D6CD08461470AF04500DC24 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:59:05.0855 4072 sr - ok
22:59:05.0886 4072 [ 92BDF74F12D6CBEC43C94D4B7F804838 ] srservice C:\WINDOWS\system32\srsvc.dll
22:59:05.0902 4072 srservice - ok
22:59:05.0949 4072 [ 5230953C21C811B5FC1FF31AE2B48097 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:59:05.0980 4072 Srv - ok
22:59:06.0027 4072 [ 4B8D61792F7175BED48859CC18CE4E38 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:59:06.0042 4072 SSDPSRV - ok
22:59:06.0105 4072 [ D9F097AA3B97034D3358A01B43E635B2 ] stisvc C:\WINDOWS\system32\wiaservc.dll
22:59:06.0120 4072 stisvc - ok
22:59:06.0183 4072 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:59:06.0183 4072 swenum - ok
22:59:06.0183 4072 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:59:06.0199 4072 swmidi - ok
22:59:06.0199 4072 SwPrv - ok
22:59:06.0199 4072 symc810 - ok
22:59:06.0214 4072 symc8xx - ok
22:59:06.0214 4072 sym_hi - ok
22:59:06.0214 4072 sym_u3 - ok
22:59:06.0245 4072 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:59:06.0245 4072 sysaudio - ok
22:59:06.0308 4072 [ 8B54AA346D1B1B113FFAA75501B8B1B2 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:59:06.0324 4072 SysmonLog - ok
22:59:06.0370 4072 [ 1418A3A6E76E5A2E3F5E43866E793A8B ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:59:06.0402 4072 TapiSrv - ok
22:59:06.0449 4072 [ E6B15BCC470953E600EF7ADED3CAB142 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:59:06.0464 4072 Tcpip - ok
22:59:06.0480 4072 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:59:06.0480 4072 TDPIPE - ok
22:59:06.0495 4072 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:59:06.0511 4072 TDTCP - ok
22:59:06.0511 4072 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:59:06.0511 4072 TermDD - ok
22:59:06.0714 4072 [ C33E6F5FD9209F4543B5C0D37CEB742C ] TermService C:\WINDOWS\System32\termsrv.dll
22:59:06.0730 4072 TermService - ok
22:59:06.0745 4072 [ 53D9184A21C5CBF600D918E51EF3A7E5 ] Themes C:\WINDOWS\System32\shsvcs.dll
22:59:06.0761 4072 Themes - ok
22:59:06.0792 4072 [ 37DB0A7D097310E8B4DE803FC3119C78 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:59:06.0808 4072 TlntSvr - ok
22:59:06.0808 4072 TosIde - ok
22:59:06.0870 4072 [ 6D9AC544B30F96C57F8206566C1FB6A1 ] TrkWks C:\WINDOWS\system32\trkwks.dll
22:59:06.0886 4072 TrkWks - ok
22:59:06.0933 4072 [ 12F70256F140CD7D52C58C7048FDE657 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:59:06.0933 4072 Udfs - ok
22:59:06.0949 4072 ultra - ok
22:59:06.0995 4072 [ 1F03139B77B21C6D84C688798808BC28 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
22:59:07.0011 4072 Update - ok
22:59:07.0058 4072 [ 36ACA6CDC19C95FF468A1426EB7F32F0 ] upnphost C:\WINDOWS\System32\upnphost.dll
22:59:07.0074 4072 upnphost - ok
22:59:07.0120 4072 [ 3F5DF65B0758675F95A2D43918A740A3 ] UPS C:\WINDOWS\System32\ups.exe
22:59:07.0136 4072 UPS - ok
22:59:07.0167 4072 [ BFFD9F120CC63BCBAA3D840F3EEF9F79 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:59:07.0167 4072 usbccgp - ok
22:59:07.0183 4072 [ 4A84DD272DF62BE5739394B3F90F8AE2 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:59:07.0183 4072 usbehci - ok
22:59:07.0199 4072 [ DB53E336C44CB0975D7DCB35BAC0ECDA ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:59:07.0199 4072 usbhub - ok
22:59:07.0245 4072 [ 9E36A32190CB43DE871FBBD7B13ACD09 ] usbohci C:\WINDOWS\system32\DRIVERS\usbohci.sys
22:59:07.0245 4072 usbohci - ok
22:59:07.0292 4072 [ A42369B7CD8886CD7C70F33DA6FCBCF5 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:59:07.0292 4072 usbprint - ok
22:59:07.0339 4072 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:59:07.0339 4072 usbscan - ok
22:59:07.0355 4072 [ 6CD7B22193718F1D17A47A1CD6D37E75 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:59:07.0355 4072 usbstor - ok
22:59:07.0433 4072 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:59:07.0433 4072 VgaSave - ok
22:59:07.0449 4072 ViaIde - ok
22:59:07.0480 4072 [ EE4660083DEBA849FF6C485D944B379B ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:59:07.0480 4072 VolSnap - ok
22:59:07.0511 4072 [ 3EE00364AE0FD8D604F46CBAF512838A ] VSS C:\WINDOWS\System32\vssvc.exe
22:59:07.0527 4072 VSS - ok
22:59:07.0542 4072 [ 2B281958F5D0CF99ED626E3EF39D5C8D ] W32Time C:\WINDOWS\system32\w32time.dll
22:59:07.0558 4072 W32Time - ok
22:59:07.0620 4072 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:59:07.0620 4072 Wanarp - ok
22:59:07.0620 4072 WDICA - ok
22:59:07.0652 4072 [ 0BFA8203B8148FB4E54BC212C41CE497 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:59:07.0667 4072 wdmaud - ok
22:59:07.0714 4072 [ 346E7D636ADFE4E3B1B32AF8326220FF ] WebClient C:\WINDOWS\System32\webclnt.dll
22:59:07.0745 4072 WebClient - ok
22:59:07.0839 4072 [ F399242A80C4066FD155EFA4CF96658E ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:59:07.0855 4072 winmgmt - ok
22:59:07.0917 4072 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
22:59:07.0933 4072 WmdmPmSN - ok
22:59:07.0995 4072 [ 1AFF244CA134956C54474F4E2433E4CE ] Wmi C:\WINDOWS\System32\advapi32.dll
22:59:08.0011 4072 Wmi - ok
22:59:08.0058 4072 [ BA8CECC3E813E1F7C441B20393D4F86C ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:59:08.0089 4072 WmiApSrv - ok
22:59:08.0199 4072 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
22:59:08.0230 4072 WMPNetworkSvc - ok
22:59:08.0292 4072 [ 478995B4555958E52388496618D9C678 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
22:59:08.0308 4072 wscsvc - ok
22:59:08.0370 4072 [ D29AD7484B98279ED21877DE051A180F ] wuauserv C:\WINDOWS\system32\wuauserv.dll
22:59:08.0370 4072 wuauserv - ok
22:59:08.0417 4072 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:59:08.0433 4072 WudfPf - ok
22:59:08.0433 4072 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:59:08.0449 4072 WudfRd - ok
22:59:08.0495 4072 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
22:59:08.0511 4072 WudfSvc - ok
22:59:08.0574 4072 [ B1F190A2BF52B8F4601C677F475CE5E5 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:59:08.0589 4072 WZCSVC - ok
22:59:08.0636 4072 [ EEF46DAB68229A14DA3D8E73C99E2959 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
22:59:08.0652 4072 xmlprov - ok
22:59:08.0699 4072 [ 175E7DBC9DB42113DECDEB566CC4C098 ] yukonwxp C:\WINDOWS\system32\DRIVERS\yk51x86.sys
22:59:08.0699 4072 yukonwxp - ok
22:59:08.0714 4072 ================ Scan global ===============================
22:59:08.0761 4072 [ 00EF9C3AF83EDBAF18CA7A2837750117 ] C:\WINDOWS\system32\basesrv.dll
22:59:08.0839 4072 [ 3E958EBBE7DA5691E8B08429A7EDB44B ] C:\WINDOWS\system32\winsrv.dll
22:59:08.0870 4072 [ 3E958EBBE7DA5691E8B08429A7EDB44B ] C:\WINDOWS\system32\winsrv.dll
22:59:08.0886 4072 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] C:\WINDOWS\system32\services.exe
22:59:08.0886 4072 [Global] - ok
22:59:08.0886 4072 ================ Scan MBR ==================================
22:59:08.0917 4072 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
22:59:09.0417 4072 \Device\Harddisk0\DR0 - ok
22:59:09.0417 4072 ================ Scan VBR ==================================
22:59:09.0433 4072 [ B13B680B6ABF9E9DC5ECAE743A214828 ] \Device\Harddisk0\DR0\Partition1
22:59:09.0464 4072 \Device\Harddisk0\DR0\Partition1 - ok
22:59:09.0480 4072 [ 2902F46A656EB6254FA8B037D2BB541F ] \Device\Harddisk0\DR0\Partition2
22:59:09.0527 4072 \Device\Harddisk0\DR0\Partition2 - ok
22:59:09.0527 4072 ============================================================
22:59:09.0527 4072 Scan finished
22:59:09.0527 4072 ============================================================
22:59:09.0527 1876 Detected object count: 0
22:59:09.0527 1876 Actual detected object count: 0
RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
https://www.techspot.com/downloads/5562-roguekiller.html
Website:
http://tigzy.geekstogo.com/roguekiller.php
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User : Administrator [Admin rights]
Mode : Scan -- Date : 10/07/2012 23:03:19
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
IRP[DriverStartIo] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xBA5F77C6)
¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST3160215ACE +++++
--- User ---
[MBR] 2fa9c6189ce352f02de3d64a1f8246e8
[BSP] ad1ae0770717efc495dc7f07631897ef : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 20002 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 40965750 | Size: 132614 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[1].txt >>
RKreport[1].txt
RogueKiller V8.1.1 [10/03/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback:
https://www.techspot.com/downloads/5562-roguekiller.html
Website:
http://tigzy.geekstogo.com/roguekiller.php
Blog:
http://tigzyrk.blogspot.com
Operating System: Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User : Administrator [Admin rights]
Mode : Remove -- Date : 10/07/2012 23:03:38
¤¤¤ Bad processes : 0 ¤¤¤
¤¤¤ Registry Entries : 2 ¤¤¤
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
¤¤¤ Particular Files / Folders: ¤¤¤
¤¤¤ Driver : [LOADED] ¤¤¤
IRP[DriverStartIo] : Unknown -> HOOKED ([MAJOR] atapi.sys @ 0xBA5F77C6)
¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost
¤¤¤ MBR Check: ¤¤¤
+++++ PhysicalDrive0: ST3160215ACE +++++
--- User ---
[MBR] 2fa9c6189ce352f02de3d64a1f8246e8
[BSP] ad1ae0770717efc495dc7f07631897ef : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 20002 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 40965750 | Size: 132614 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-10-07 23:11:05
-----------------------------
23:11:05.652 OS Version: Windows 5.1.2600 Service Pack 2
23:11:05.652 Number of processors: 2 586 0x4B02
23:11:05.652 ComputerName: ACER-88C919EA93 UserName: Administrator
23:11:06.308 Initialize success
23:11:06.449 AVAST engine defs: 12100701
23:11:22.761 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c
23:11:22.761 Disk 0 Vendor: ST3160215ACE 3.CKA Size: 152627MB BusType: 3
23:11:22.777 Disk 0 MBR read successfully
23:11:22.777 Disk 0 MBR scan
23:11:22.777 Disk 0 Windows XP default MBR code
23:11:22.777 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 20002 MB offset 63
23:11:22.777 Disk 0 Partition - 00 0F Extended LBA 132614 MB offset 40965750
23:11:22.792 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 132614 MB offset 40965813
23:11:22.824 Disk 0 scanning sectors +312560640
23:11:23.011 Disk 0 scanning C:\WINDOWS\system32\drivers
23:11:36.886 Service scanning
23:12:23.370 Modules scanning
23:12:52.199 Disk 0 trace - called modules:
23:12:52.214 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89bd71e8]<<
23:12:52.214 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89b9cab8]
23:12:52.214 3 CLASSPNP.SYS[ba8e8fcf] -> nt!IofCallDriver -> \Device\0000006a[0x89b4f3b8]
23:12:52.214 5 ACPI.sys[ba664620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-c[0x89b8ed98]
23:12:52.214 \Driver\atapi[0x89b708a8] -> IRP_MJ_CREATE -> 0x89bd71e8
23:12:52.417 AVAST engine scan C:\WINDOWS
23:12:58.324 AVAST engine scan C:\WINDOWS\system32
23:16:18.964 AVAST engine scan C:\WINDOWS\system32\drivers
23:16:38.886 AVAST engine scan C:\Documents and Settings\Administrator
23:35:52.120 AVAST engine scan C:\Documents and Settings\All Users
23:36:29.386 Scan finished successfully
23:36:50.870 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat"
23:36:50.870 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"