OK, got the scans etc done, but did encounter a few problems, mainly with TDSSkiller. When it loaded, it asked for a reboot to run in advanced mode, but the reboot hung at the XP splash screen and I was only able to boot into Safe Mode. I was able to run TDSSkiller in Safe Mode, and it found Necurs and produced a log file. When the machine rebooted to complete the removal, it then booted back into normal mode, but TDSSkiller then started again. So I re-ran the scan just to be sure, and it found Necurs again and "removed" it once more. However, at the reboot following that, not only did the firewall not come back, but AVG went down as well, the same as the last infection. Rkill ran OK and produced a log, and MBAM then found and quarantined two items. At that re-boot, both the firewall and AVG refused to start again, and RogueKiller still shows Necurs to be present. So, at the moment, it seems like there's been no progress with elimination. When RogueKiller finished the scan, it came up with a webpage about Necurs elimination, which did mention working in off-line mode, and the machine was online at the time - could that have had an effect on the success of the other programs?
Anyway, here's the log files (including both safe and normal mode TDSSkiller logs, just for completeness):
14:43:59.0950 0x0350 TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34
14:44:04.0937 0x0350 ============================================================
14:44:04.0937 0x0350 Current date / time: 2014/12/08 14:44:04.0937
14:44:04.0937 0x0350 SystemInfo:
14:44:04.0937 0x0350
14:44:04.0937 0x0350 OS Version: 5.1.2600 ServicePack: 3.0
14:44:04.0937 0x0350 Product type: Workstation
14:44:04.0937 0x0350 ComputerName: THINKPAD
14:44:04.0937 0x0350 UserName: IBM
14:44:04.0937 0x0350 Windows directory: C:\WINDOWS
14:44:04.0937 0x0350 System windows directory: C:\WINDOWS
14:44:04.0937 0x0350 Processor architecture: Intel x86
14:44:04.0937 0x0350 Number of processors: 1
14:44:04.0937 0x0350 Page size: 0x1000
14:44:04.0937 0x0350 Boot type: Safe boot
14:44:04.0937 0x0350 ============================================================
14:44:13.0800 0x0350 KLMD registered as C:\WINDOWS\system32\drivers\67146974.sys
14:44:24.0035 0x0350 System UUID: {65C7A9CC-C291-863E-FB8C-E2EA3E48D80E}
14:44:26.0428 0x0350 !crdlk
14:44:26.0428 0x0350 Drive \Device\Harddisk0\DR0 - Size: 0x4A8530000 ( 18.63 Gb ), SectorSize: 0x200, Cylinders: 0xA18, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'A'
14:44:32.0306 0x0350 Drive \Device\Harddisk0\DR0 - Size: 0x4A8530000 ( 18.63 Gb ), SectorSize: 0x200, Cylinders: 0xA18, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'W'
14:44:32.0457 0x0350 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'A'
14:44:38.0285 0x0350 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'W'
14:44:38.0295 0x0350 ============================================================
14:44:38.0295 0x0350 \Device\Harddisk0\DR0:
14:44:38.0295 0x0350 MBR partitions:
14:44:38.0295 0x0350 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2272C11
14:44:38.0295 0x0350 \Device\Harddisk1\DR1:
14:44:38.0295 0x0350 MBR partitions:
14:44:38.0295 0x0350 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
14:44:38.0295 0x0350 ============================================================
14:44:38.0435 0x0350 C: <-> \Device\Harddisk0\DR0\Partition1
14:44:38.0796 0x0350 D: <-> \Device\Harddisk1\DR1\Partition1
14:44:38.0836 0x0350 ============================================================
14:44:38.0836 0x0350 Initialize success
14:44:38.0836 0x0350 ============================================================
14:44:44.0123 0x03b8 ============================================================
14:44:44.0123 0x03b8 Scan started
14:44:44.0123 0x03b8 Mode: Manual;
14:44:44.0123 0x03b8 ============================================================
14:44:44.0123 0x03b8 KSN ping started
14:44:44.0564 0x03b8 KSN ping finished: false
14:44:47.0859 0x03b8 ================ Scan system memory ========================
14:44:47.0859 0x03b8 System memory - ok
14:44:47.0879 0x03b8 ================ Scan services =============================
14:44:48.0810 0x03b8 27784469 - ok
14:44:48.0870 0x03b8 Suspicious service (NoAccess): 2d19a0fd877a76cc
14:44:49.0040 0x03b8 [ 2C41EEBB24C4AA8CA10A1AAD236BA2E1, 073CE628A8CF9BA88BEA4A99AEA35E5DD74E9F3ACE48CF96871E0F44DB6FEE31 ] 2d19a0fd877a76cc C:\WINDOWS\System32\Drivers\2d19a0fd877a76cc.sys
14:44:49.0040 0x03b8 Suspicious file ( NoAccess ): C:\WINDOWS\System32\Drivers\2d19a0fd877a76cc.sys. md5: 2C41EEBB24C4AA8CA10A1AAD236BA2E1, sha256: 073CE628A8CF9BA88BEA4A99AEA35E5DD74E9F3ACE48CF96871E0F44DB6FEE31
14:44:51.0013 0x03b8 2d19a0fd877a76cc - detected Rootkit.Win32.Necurs.gen ( 0 )
14:44:51.0484 0x03b8 2d19a0fd877a76cc ( Rootkit.Win32.Necurs.gen ) - infected
14:44:51.0484 0x03b8 Force sending object to P2P due to detect: 2d19a0fd877a76cc
14:44:51.0524 0x03b8 Object send P2P result: false
14:44:51.0704 0x03b8 Abiosdsk - ok
14:44:51.0835 0x03b8 abp480n5 - ok
14:44:52.0145 0x03b8 [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:44:52.0155 0x03b8 ACPI - ok
14:44:52.0405 0x03b8 [ 9859C0F6936E723E4892D7141B1327D5, 5E8F6A2FC4DF2E5E92A1D66ECC2810E08B42B64E9CD0DF4AD3F78EA8558B90AF ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
14:44:52.0405 0x03b8 ACPIEC - ok
14:44:52.0596 0x03b8 adpu160m - ok
14:44:52.0856 0x03b8 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
14:44:52.0866 0x03b8 aec - ok
14:44:53.0096 0x03b8 [ 58A8273918EEF2BF9204B12ED171513A, 6C79AC93FBBD8B877DD71557A8B2A2B9C20277BBFCEDE6A1ECA7FFC650FC6143 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys
14:44:53.0096 0x03b8 AegisP - ok
14:44:53.0347 0x03b8 [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
14:44:53.0367 0x03b8 AFD - ok
14:44:54.0078 0x03b8 [ AFF071B6290776E1FA162837C35EAC78, 07F3CDB27C767BEDB9E8C82A4FE738AD408225C2A22428669F742EDF30410758 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys
14:44:54.0138 0x03b8 AgereSoftModem - ok
14:44:54.0378 0x03b8 [ 08FD04AA961BDC77FB983F328334E3D7, A784EC8A9EDB579262366B5A9AB177DB7BEC0A421BDE85431D0AD4959D5AF5E7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
14:44:54.0378 0x03b8 agp440 - ok
14:44:54.0528 0x03b8 Aha154x - ok
14:44:54.0689 0x03b8 aic78u2 - ok
14:44:54.0829 0x03b8 aic78xx - ok
14:44:55.0059 0x03b8 [ A9A3DAA780CA6C9671A19D52456705B4, 67C959144B57AE0BBF1D82DBED197F32CDB06FECD883A80C441A0202FE83FAB4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
14:44:55.0059 0x03b8 Alerter - ok
14:44:55.0320 0x03b8 [ 8C515081584A38AA007909CD02020B3D, A5E13CA10F702928E0DE84C74D0EA8ACCB117FD76FBABC55220C75C4FFD596DC ] ALG C:\WINDOWS\System32\alg.exe
14:44:55.0340 0x03b8 ALG - ok
14:44:55.0490 0x03b8 AliIde - ok
14:44:55.0630 0x03b8 amsint - ok
14:44:55.0930 0x03b8 [ D8849F77C0B66226335A59D26CB4EDC6, 4990031453204C57E36E850252A39B05D6ECDAB9E71A8136FB4900F17E59C9CA ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
14:44:56.0021 0x03b8 AppMgmt - ok
14:44:56.0151 0x03b8 asc - ok
14:44:56.0311 0x03b8 asc3350p - ok
14:44:56.0471 0x03b8 asc3550 - ok
14:44:56.0932 0x03b8 [ 0E5E4957549056E2BF2C49F4F6B601AD, F7F19FDC906B719A3516D30A9B4A2262C8CC5B36B94E3D4195C345EC4610FF2B ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
14:44:57.0192 0x03b8 aspnet_state - ok
14:44:57.0493 0x03b8 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:44:57.0493 0x03b8 AsyncMac - ok
14:44:57.0743 0x03b8 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
14:44:57.0743 0x03b8 atapi - ok
14:44:57.0923 0x03b8 Atdisk - ok
14:44:58.0164 0x03b8 [ 418CDC2888D01E1CD5CE297AF00807A3, 1DE3277683E0D3D2B1B83FF9D718C125E3D542477C1505063DDE8145C408391D ] Ati HotKey Poller C:\WINDOWS\System32\Ati2evxx.exe
14:44:58.0234 0x03b8 Ati HotKey Poller - ok
14:44:58.0624 0x03b8 [ D1F804642C627782C6D213BCE0604F09, 43DB2A74835B5E5C796509990E0FCB4A4897A027D0117F5B6C8ECD37E80F7F28 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:44:58.0654 0x03b8 ati2mtag - ok
14:44:58.0825 0x03b8 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:44:58.0835 0x03b8 Atmarpc - ok
14:44:59.0095 0x03b8 [ DEF7A7882BEC100FE0B2CE2549188F9D, 462C95B63D0A1058291A2DC8CBFCB13D7D74CCD1CA43B613A7EB43D49E3276F8 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
14:44:59.0105 0x03b8 AudioSrv - ok
14:44:59.0325 0x03b8 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
14:44:59.0325 0x03b8 audstub - ok
14:45:00.0026 0x03b8 [ AA054CD537357F03D5BA6ABA7562B35F, F331D929920D38B53FEA464AF54DB59224882D386C55689CDDF6C6DC1473284E ] avg9emc C:\Program Files\AVG\AVG9\avgemc.exe
14:45:00.0407 0x03b8 avg9emc - ok
14:45:00.0837 0x03b8 [ C4D15594DB5BE042D3346EA58DF87D89, 8E24868518DE53F28C92C473A415BED613665287F338B815FEDE21D151F01962 ] avg9wd C:\Program Files\AVG\AVG9\avgwdsvc.exe
14:45:00.0948 0x03b8 avg9wd - ok
14:45:01.0258 0x03b8 [ A9F4D19DE72C738759330D10D35C4398, 46D760EBFBABF3FDCD02F4AC38180FBFFEFFA36F68C18602695A9FCB6C4C13DE ] AvgLdx86 C:\WINDOWS\System32\Drivers\avgldx86.sys
14:45:01.0288 0x03b8 AvgLdx86 - ok
14:45:01.0548 0x03b8 [ 80FF2B1B7EEDA966394F0BAA895BBF4B, D8F5C111837707DC37975C1E315FCD33BF96AB21D89874CB0290134A44C46BEF ] AvgMfx86 C:\WINDOWS\System32\Drivers\avgmfx86.sys
14:45:01.0548 0x03b8 AvgMfx86 - ok
14:45:01.0809 0x03b8 [ 9A7A93388F503A34E7339AE7F9997449, 9549146C19EAF65DB98314A7CCB0AB27503DC812B521444CBEA5493998ADAA80 ] AvgTdiX C:\WINDOWS\System32\Drivers\avgtdix.sys
14:45:01.0829 0x03b8 AvgTdiX - ok
14:45:02.0129 0x03b8 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
14:45:02.0129 0x03b8 Beep - ok
14:45:02.0480 0x03b8 [ 574738F61FCA2935F5265DC4E5691314, 3C7CCF064397186C3A3863DD2370AB6414A61B330097DCA4F299CA7BBAA3D1B4 ] BITS C:\WINDOWS\system32\qmgr.dll
14:45:02.0940 0x03b8 BITS - ok
14:45:03.0251 0x03b8 [ CFD4E51402DA9838B5A04AE680AF54A0, 5378F42B195B5832B00A05AD64E00473A45FFB86AC25C57241F26EA82B149FE1 ] Browser C:\WINDOWS\System32\browser.dll
14:45:03.0301 0x03b8 Browser - ok
14:45:03.0521 0x03b8 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
14:45:03.0521 0x03b8 cbidf2k - ok
14:45:03.0682 0x03b8 cd20xrnt - ok
14:45:03.0852 0x03b8 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
14:45:03.0852 0x03b8 Cdaudio - ok
14:45:04.0112 0x03b8 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
14:45:04.0112 0x03b8 Cdfs - ok
14:45:04.0353 0x03b8 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:45:04.0363 0x03b8 Cdrom - ok
14:45:04.0533 0x03b8 Changer - ok
14:45:04.0693 0x03b8 [ 1CFE720EB8D93A7158A4EBC3AB178BDE, 65D2A9D9A88F38D4AF323134C151BA0F4B3CD0F6A134AF86E7AC9D07319F1726 ] cisvc C:\WINDOWS\System32\cisvc.exe
14:45:04.0693 0x03b8 cisvc - ok
14:45:04.0873 0x03b8 [ 34CBE729F38138217F9C80212A2A0C82, A9FD7A758D12E0818A11BEEF1CE772FEFA8373E92EF6C0DA8628CD4572CC9A43 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
14:45:04.0893 0x03b8 ClipSrv - ok
14:45:05.0124 0x03b8 [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:45:05.0484 0x03b8 clr_optimization_v2.0.50727_32 - ok
14:45:05.0694 0x03b8 [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
14:45:05.0694 0x03b8 CmBatt - ok
14:45:05.0855 0x03b8 CmdIde - ok
14:45:06.0005 0x03b8 [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
14:45:06.0005 0x03b8 Compbatt - ok
14:45:06.0175 0x03b8 COMSysApp - ok
14:45:06.0446 0x03b8 Cpqarray - ok
14:45:06.0806 0x03b8 [ 3D4E199942E29207970E04315D02AD3B, 0825960894CF9C86CC8775BDD2A262948A09CA495AA7FE9F210FAF49E7086383 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
14:45:06.0816 0x03b8 CryptSvc - ok
14:45:06.0966 0x03b8 dac2w2k - ok
14:45:07.0126 0x03b8 dac960nt - ok
14:45:07.0557 0x03b8 [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
14:45:07.0687 0x03b8 DcomLaunch - ok
14:45:07.0998 0x03b8 [ 5E38D7684A49CACFB752B046357E0589, F192AD4190BCFB6939A5CBC91648FE63168AF79A5E227A111DEAD6A92E42AB8D ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
14:45:08.0018 0x03b8 Dhcp - ok
14:45:08.0318 0x03b8 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
14:45:08.0318 0x03b8 Disk - ok
14:45:08.0579 0x03b8 dmadmin - ok
14:45:09.0069 0x03b8 [ D992FE1274BDE0F84AD826ACAE022A41, C82BD6561A14F2932A761F5883A787B99031250EE5E9B7B5714AA045545C9B99 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
14:45:09.0129 0x03b8 dmboot - ok
14:45:09.0450 0x03b8 [ 7C824CF7BBDE77D95C08005717A95F6F, A73CB323B7A6410C3D3F258BF204E716ADF8C84C9E4F6562C57AB73DAED8CCDE ] dmio C:\WINDOWS\system32\drivers\dmio.sys
14:45:09.0450 0x03b8 dmio - ok
14:45:09.0690 0x03b8 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
14:45:09.0690 0x03b8 dmload - ok
14:45:09.0931 0x03b8 [ 57EDEC2E5F59F0335E92F35184BC8631, 61F6F0DC2D1A6C61D5EF0D5CC4BE0FFC217F1E61FDA3EA9F704709293656600F ] dmserver C:\WINDOWS\System32\dmserver.dll
14:45:09.0931 0x03b8 dmserver - ok
14:45:10.0131 0x03b8 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
14:45:10.0141 0x03b8 DMusic - ok
14:45:10.0401 0x03b8 [ 5F7E24FA9EAB896051FFB87F840730D2, 356EEFDCD54DECAD0170B34B993E4BF80DD039E2B2922D7A8D09B84031E9FC7A ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
14:45:10.0401 0x03b8 Dnscache - ok
14:45:10.0702 0x03b8 [ 0F0F6E687E5E15579EF4DA8DD6945814, 5C32D88119EB1465B2D719BEE2E05888D1A73454B5E33F2D4928DA710F8BFBA3 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
14:45:10.0752 0x03b8 Dot3svc - ok
14:45:10.0902 0x03b8 dpti2o - ok
14:45:11.0102 0x03b8 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
14:45:11.0102 0x03b8 drmkaud - ok
14:45:11.0353 0x03b8 [ 816AC73D056626333DD1D8F759F0AFAA, E41A12680088D927D011F84F1F173DB9D47444A7C7F701BCC39E7165A313B5A8 ] DSMBATT C:\WINDOWS\system32\drivers\DSMBATT.SYS
14:45:11.0353 0x03b8 DSMBATT - ok
14:45:11.0573 0x03b8 [ 81459BD6D8FEAADF2848AE88B3D02EC3, 240CEBFD1CDF824C43748362B3BDCE1B9D9CA238EDDC1E14051D006C6CCDFCF5 ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
14:45:11.0583 0x03b8 E100B - ok
14:45:11.0853 0x03b8 [ 2187855A7703ADEF0CEF9EE4285182CC, 8233CC11F637866C0074043835A785EA2B616739B6B1181B143A253CF2508CFD ] EapHost C:\WINDOWS\System32\eapsvc.dll
14:45:11.0853 0x03b8 EapHost - ok
14:45:12.0054 0x03b8 [ 938F1EC77BA35858248E584B2D2E9776, E48E7C363F4AAF8601016E3AAAD50C5C99E83747733C6339D9E21D3C8DDDE7B5 ] EGATHDRV C:\WINDOWS\system32\EGATHDRV.SYS
14:45:12.0054 0x03b8 EGATHDRV - ok
14:45:12.0414 0x03b8 [ BC93B4A066477954555966D77FEC9ECB, 27F5B780175EF46DA102EE33F7F33559C8B40C077EEA4405D579D9507F4B1C23 ] ERSvc C:\WINDOWS\System32\ersvc.dll
14:45:12.0424 0x03b8 ERSvc - ok
14:45:12.0725 0x03b8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] Eventlog C:\WINDOWS\system32\services.exe
14:45:12.0745 0x03b8 Eventlog - ok
14:45:13.0065 0x03b8 [ D4991D98F2DB73C60D042F1AEF79EFAE, 58AF949EAEBF4FF3E3314DFB66CE4198BF65F0836B68CD27A6ED319742CCCCD2 ] EventSystem C:\WINDOWS\System32\es.dll
14:45:13.0155 0x03b8 EventSystem - ok
14:45:13.0426 0x03b8 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
14:45:13.0436 0x03b8 Fastfat - ok
14:45:13.0736 0x03b8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
14:45:13.0766 0x03b8 FastUserSwitchingCompatibility - ok
14:45:14.0016 0x03b8 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
14:45:14.0016 0x03b8 Fdc - ok
14:45:14.0197 0x03b8 [ D45926117EB9FA946A6AF572FBE1CAA3, 4C94EF009D778BE0BDF8F812F026B96F91F641BE30AA2531427A5E63DBD280DA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
14:45:14.0207 0x03b8 Fips - ok
14:45:14.0467 0x03b8 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:45:14.0467 0x03b8 Flpydisk - ok
14:45:14.0788 0x03b8 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
14:45:14.0788 0x03b8 FltMgr - ok
14:45:15.0078 0x03b8 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
14:45:15.0148 0x03b8 FontCache3.0.0.0 - ok
14:45:15.0328 0x03b8 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:45:15.0328 0x03b8 Fs_Rec - ok
14:45:15.0559 0x03b8 [ 6AC26732762483366C3969C9E4D2259D, FF2C9A23CC17F380093F0BEA955B1925794271C2FEA16B9B7639668E6999BAE3 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:45:15.0559 0x03b8 Ftdisk - ok
14:45:15.0819 0x03b8 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:45:15.0819 0x03b8 Gpc - ok
14:45:16.0149 0x03b8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:45:16.0200 0x03b8 gupdate - ok
14:45:16.0470 0x03b8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:45:16.0470 0x03b8 gupdatem - ok
14:45:16.0760 0x03b8 [ 4FCCA060DFE0C51A09DD5C3843888BCD, D82417706B517F2610DDF7C86BE03A72EFA9A2A389DF5C8F8ADEAB8144E2C80A ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
14:45:16.0770 0x03b8 helpsvc - ok
14:45:16.0971 0x03b8 HidServ - ok
14:45:17.0171 0x03b8 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
14:45:17.0181 0x03b8 hidusb - ok
14:45:17.0391 0x03b8 [ 8878BD685E490239777BFE51320B88E9, C5C3ECF6B049B6736E35B39518A8F830B45C45A88FFE8E3A6B7922AD946597E2 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
14:45:17.0421 0x03b8 hkmsvc - ok
14:45:17.0582 0x03b8 hpn - ok
14:45:17.0732 0x03b8 hpt3xx - ok
14:45:18.0062 0x03b8 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
14:45:18.0082 0x03b8 HTTP - ok
14:45:18.0323 0x03b8 [ 6100A808600F44D999CEBDEF8841C7A3, 61A75118C327812C60622010985A2E80E79B6FD9030A5732390EE5426E4AF6C9 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
14:45:18.0393 0x03b8 HTTPFilter - ok
14:45:18.0613 0x03b8 i2omgmt - ok
14:45:18.0743 0x03b8 i2omp - ok
14:45:18.0953 0x03b8 [ 4A0B06AA8943C1E332520F7440C0AA30, DB2452390CCFE67E0C5FEB4FD42CA24ABE2DDD40D0B22DD5F5B8F70416863918 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
14:45:18.0953 0x03b8 i8042prt - ok
14:45:19.0174 0x03b8 [ 293131C1DA5F53CB05F75D637739D79C, F5F1A03FB012101FA143A288BCBC048A652A285F7DF533D1D08279E3A4D24326 ] IBMPMDRV C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
14:45:19.0184 0x03b8 IBMPMDRV - ok
14:45:19.0384 0x03b8 [ 91FA023C5203503776BCCC9CF96A0C59, A47C788A26E4D2A282DE2EC8A75E1544CAB17A2C5F4CF867026D3B95B3651D1D ] IBMPMSVC C:\WINDOWS\system32\ibmpmsvc.exe
14:45:19.0404 0x03b8 IBMPMSVC - ok
14:45:19.0624 0x03b8 [ 28DEEBA2E29CB0E91B641CA95F7740FD, 3E4D92E7211AA0CCD38561DB5F7CDC583C141A40D9077AA7D482336D3080369B ] IBMTPCHK C:\WINDOWS\system32\drivers\IBMBLDID.SYS
14:45:19.0624 0x03b8 IBMTPCHK - ok
14:45:19.0995 0x03b8 [ DAF66902F08796F9C694901660E5A64A, F4A4764DED05980426BAB54AAF040BC27A39C80315F5161E8D0B4C7F694BD8E6 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
14:45:20.0035 0x03b8 IDriverT - ok
14:45:20.0736 0x03b8 [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:45:21.0217 0x03b8 idsvc - ok
14:45:21.0537 0x03b8 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
14:45:21.0537 0x03b8 Imapi - ok
14:45:21.0808 0x03b8 [ 30DEAF54A9755BB8546168CFE8A6B5E1, 3936228CD3125C763ABFCB93E86E4B43838202BCC0913A28E84AC0263B43EE0D ] ImapiService C:\WINDOWS\System32\imapi.exe
14:45:21.0858 0x03b8 ImapiService - ok
14:45:22.0088 0x03b8 ini910u - ok
14:45:22.0338 0x03b8 [ B5466A9250342A7AA0CD1FBA13420678, 87E735C4E8924A883AB692D387A83BCBFAE6E165688336AE7AB488F7CA8D339E ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
14:45:22.0338 0x03b8 IntelIde - ok
14:45:22.0539 0x03b8 [ 8C953733D8F36EB2133F5BB58808B66B, 555868F246D73652E998B0B1296476E42FCEDED30D646CC000F31ECE4EBC25E6 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:45:22.0539 0x03b8 intelppm - ok
14:45:22.0719 0x03b8 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
14:45:22.0719 0x03b8 ip6fw - ok
14:45:22.0949 0x03b8 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:45:22.0949 0x03b8 IpFilterDriver - ok
14:45:23.0140 0x03b8 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:45:23.0140 0x03b8 IpInIp - ok
14:45:23.0410 0x03b8 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:45:23.0410 0x03b8 IpNat - ok
14:45:23.0690 0x03b8 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:45:23.0690 0x03b8 IPSec - ok
14:45:23.0901 0x03b8 [ ACA5E7B54409F9CB5EED97ED0C81120E, 1E22F442EA77596F58D133F1A5887CDC4F3325DD0836D24A665E1D31287ABFF7 ] irda C:\WINDOWS\system32\DRIVERS\irda.sys
14:45:23.0911 0x03b8 irda - ok
14:45:24.0111 0x03b8 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
14:45:24.0121 0x03b8 IRENUM - ok
14:45:24.0471 0x03b8 [ 49CC4533CE897CB2E93C1E84A818FDE5, F2AC81CDB971F630699616509748DCE133874EFC79B9D6230517B5A4DFBE193D ] Irmon C:\WINDOWS\System32\irmon.dll
14:45:24.0471 0x03b8 Irmon - ok
14:45:24.0812 0x03b8 [ 05A299EC56E52649B1CF2FC52D20F2D7, 2654619DB3E6D6C385B63AB02F87D4241C4F0250CC31383D1B3586917166C2DC ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:45:24.0822 0x03b8 isapnp - ok
14:45:25.0233 0x03b8 [ DBDB1A25291B2D18C614F5CA963156A8, C8EA730A6A5BCBE7952AAA22F212C244014F206D2F4A274E29384C09F1F10A66 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
14:45:25.0323 0x03b8 JavaQuickStarterService - ok
14:45:25.0553 0x03b8 [ 463C1EC80CD17420A542B7F36A36F128, E3B11BA26AFEAFB50B0FC168EA07F6049DA6B88BCDDEEE20310602D7FC27A3A7 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:45:25.0553 0x03b8 Kbdclass - ok
14:45:25.0803 0x03b8 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
14:45:25.0823 0x03b8 kmixer - ok
14:45:26.0094 0x03b8 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
14:45:26.0094 0x03b8 KSecDD - ok
14:45:26.0364 0x03b8 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527, 0044F03132596A494448CCE5F3D6ECC12617BB4CF6BAE348F79D4DC40ACD6EE0 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
14:45:26.0404 0x03b8 lanmanserver - ok
14:45:26.0715 0x03b8 [ A8888A5327621856C0CEC4E385F69309, B08B63300D824E35E31EEEA2C4C086DFA2C2A964CEDAE512E74D3D88AADAA2C1 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
14:45:26.0745 0x03b8 lanmanworkstation - ok
14:45:26.0875 0x03b8 lbrtfdc - ok
14:45:27.0245 0x03b8 [ 31D8B705DCD5F2366186E731F87C7A71, D73DC732EF74C3C0EADD650B65BC6EEB44EA2C4E86BFD5BE989971A34FBA160A ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
14:45:27.0275 0x03b8 LightScribeService - ok
14:45:27.0576 0x03b8 [ A7DB739AE99A796D91580147E919CC59, EDF4E039BA277B0E6D66FEB0B28096E67D682C09DFC18ECECF062D9DCFB75ACF ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
14:45:27.0586 0x03b8 LmHosts - ok
14:45:27.0836 0x03b8 [ 986B1FF5814366D71E0AC5755C88F2D3, E6AF051174531C24B38E73987755D366ABEC595476C6D17793E8DCCC73F55340 ] Messenger C:\WINDOWS\System32\msgsvc.dll
14:45:27.0836 0x03b8 Messenger - ok
14:45:28.0007 0x03b8 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
14:45:28.0017 0x03b8 mnmdd - ok
14:45:28.0227 0x03b8 [ D18F1F0C101D06A1C1ADF26EED16FCDD, BA0837C7780BD8262E143E2935AFA63BE59C3C39EF56CB8608EED0F50AF070D4 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
14:45:28.0237 0x03b8 mnmsrvc - ok
14:45:28.0457 0x03b8 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1, B342CC9EC3729AB1AB4B5E2E99F890C1E0CA649162DE91F6768AB857B719E97B ] Modem C:\WINDOWS\system32\drivers\Modem.sys
14:45:28.0457 0x03b8 Modem - ok
14:45:28.0718 0x03b8 [ 35C9E97194C8CFB8430125F8DBC34D04, 0C0FCE6B0A23FB0ECB92E1663E1C72D2DD5B177D82E04782957690B69530DB39 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:45:28.0718 0x03b8 Mouclass - ok
14:45:28.0958 0x03b8 [ B1C303E17FB9D46E87A98E4BA6769685, 161A45488522055D0F0474ABEDA04DDD0B5DAC2411AF9154B15190BBD66E7153 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
14:45:28.0958 0x03b8 mouhid - ok
14:45:29.0188 0x03b8 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
14:45:29.0188 0x03b8 MountMgr - ok
14:45:29.0348 0x03b8 mraid35x - ok
14:45:29.0559 0x03b8 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:45:29.0569 0x03b8 MRxDAV - ok
14:45:29.0949 0x03b8 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:45:29.0969 0x03b8 MRxSmb - ok
14:45:30.0160 0x03b8 [ A137F1470499A205ABBB9AAFB3B6F2B1, FB4951727543030D9E6ED74149C3FAACE2CA9DA8C1B5F616301B30B858C724E8 ] MSDTC C:\WINDOWS\System32\msdtc.exe
14:45:30.0160 0x03b8 MSDTC - ok
14:45:30.0460 0x03b8 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
14:45:30.0460 0x03b8 Msfs - ok
14:45:30.0630 0x03b8 MSIServer - ok
14:45:30.0770 0x03b8 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:45:30.0770 0x03b8 MSKSSRV - ok
14:45:30.0981 0x03b8 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:45:30.0981 0x03b8 MSPCLOCK - ok
14:45:31.0141 0x03b8 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
14:45:31.0141 0x03b8 MSPQM - ok
14:45:31.0321 0x03b8 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:45:31.0321 0x03b8 mssmbios - ok
14:45:31.0562 0x03b8 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
14:45:31.0562 0x03b8 Mup - ok
14:45:31.0912 0x03b8 [ 0102140028FAD045756796E1C685D695, 5335B8278418CA200E2772124F0602C3E15A5CAF2D5CC59F6785DFAABF339B09 ] napagent C:\WINDOWS\System32\qagentrt.dll
14:45:32.0032 0x03b8 napagent - ok
14:45:32.0263 0x03b8 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
14:45:32.0273 0x03b8 NDIS - ok
14:45:32.0513 0x03b8 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:45:32.0513 0x03b8 NdisTapi - ok
14:45:32.0703 0x03b8 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:45:32.0703 0x03b8 Ndisuio - ok
14:45:32.0904 0x03b8 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:45:32.0914 0x03b8 NdisWan - ok
14:45:33.0144 0x03b8 [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
14:45:33.0154 0x03b8 NDProxy - ok
14:45:33.0374 0x03b8 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
14:45:33.0384 0x03b8 NetBIOS - ok
14:45:33.0645 0x03b8 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
14:45:33.0655 0x03b8 NetBT - ok
14:45:33.0925 0x03b8 [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDE C:\WINDOWS\system32\netdde.exe
14:45:33.0965 0x03b8 NetDDE - ok
14:45:34.0185 0x03b8 [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
14:45:34.0195 0x03b8 NetDDEdsdm - ok
14:45:34.0386 0x03b8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] Netlogon C:\WINDOWS\System32\lsass.exe
14:45:34.0396 0x03b8 Netlogon - ok
14:45:34.0776 0x03b8 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE, 4E0A67B3CC897E80D4B342FFE8B7B4CC4F6CA2EF2D34C136027A098B2E1C6166 ] Netman C:\WINDOWS\System32\netman.dll
14:45:34.0846 0x03b8 Netman - ok
14:45:35.0177 0x03b8 [ D34612C5D02D026535B3095D620626AE, 1BBCCCBF49EB8807240A77DCB43C25C21682073CC5356594E2C4F53EF36BF657 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:45:35.0217 0x03b8 NetTcpPortSharing - ok
14:45:35.0617 0x03b8 [ 943337D786A56729263071623BBB9DE5, B631B47C869FE4ACF46E4AA272435D9A9CA536E3349E3FFBB8602636FEE7AFD4 ] Nla C:\WINDOWS\System32\mswsock.dll
14:45:35.0708 0x03b8 Nla - ok
14:45:35.0948 0x03b8 NMIndexingService - ok
14:45:36.0178 0x03b8 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
14:45:36.0188 0x03b8 Npfs - ok
14:45:36.0379 0x03b8 [ 2ADC0CA9945C65284B3D19BC18765974, A8E2B848E85A3B38350F4134DE9CA6749854B988F9A0087C60D97E19D474CBF3 ] NSCIRDA C:\WINDOWS\system32\DRIVERS\nscirda.sys
14:45:36.0379 0x03b8 NSCIRDA - ok
14:45:36.0729 0x03b8 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
14:45:36.0759 0x03b8 Ntfs - ok
14:45:36.0909 0x03b8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
14:45:36.0909 0x03b8 NtLmSsp - ok
14:45:37.0330 0x03b8 [ 156F64A3345BD23C600655FB4D10BC08, 9611BE411586E068D9297D77102DB3BE48AA67F1BAD6F61A84F83FC3043FA9CD ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
14:45:37.0490 0x03b8 NtmsSvc - ok
14:45:37.0690 0x03b8 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
14:45:37.0700 0x03b8 Null - ok
14:45:37.0871 0x03b8 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:45:37.0871 0x03b8 NwlnkFlt - ok
14:45:38.0011 0x03b8 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:45:38.0011 0x03b8 NwlnkFwd - ok
14:45:38.0291 0x03b8 [ 5575FAF8F97CE5E713D108C2A58D7C7C, 96D4595D19A78CCBE8B325A08780AC077AE5CC99642ACD72FB47AEAE8D344D3B ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
14:45:38.0301 0x03b8 Parport - ok
14:45:38.0562 0x03b8 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
14:45:38.0562 0x03b8 PartMgr - ok
14:45:38.0802 0x03b8 [ 70E98B3FD8E963A6A46A2E6247E0BEA1, 6771313EC41B3B5BFD398F60706E40BE71617046880CC352DD110B001AFC22A1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
14:45:38.0802 0x03b8 ParVdm - ok
14:45:39.0032 0x03b8 [ A219903CCF74233761D92BEF471A07B1, D4E6C360A1D2FCA4D17C991B834D68BF20F5111DD06B1FAB8B22984804CEC269 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
14:45:39.0032 0x03b8 PCI - ok
14:45:39.0173 0x03b8 PCIDump - ok
14:45:39.0333 0x03b8 PCIIde - ok
14:45:39.0583 0x03b8 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1, 0BA3DB21DC7C641C181E2635B5C9B73965FDCDCD3EBBBE48FCFEC1C8C987F617 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys
14:45:39.0593 0x03b8 Pcmcia - ok
14:45:39.0743 0x03b8 PDCOMP - ok
14:45:39.0864 0x03b8 PDFRAME - ok
14:45:40.0014 0x03b8 PDRELI - ok
14:45:40.0154 0x03b8 PDRFRAME - ok
14:45:40.0304 0x03b8 perc2 - ok
14:45:40.0434 0x03b8 perc2hib - ok
14:45:40.0915 0x03b8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] PlugPlay C:\WINDOWS\system32\services.exe
14:45:40.0925 0x03b8 PlugPlay - ok
14:45:41.0095 0x03b8 [ FA292805788528C083F416E151B60AB6, CF47525D15FF3FF98768FF5AE8A8F0C01AE6300C249D24E518D2A02100D5A68A ] PMEM C:\WINDOWS\system32\drivers\PMEMNT.SYS
14:45:41.0095 0x03b8 PMEM - ok
14:45:41.0276 0x03b8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] PolicyAgent C:\WINDOWS\System32\lsass.exe
14:45:41.0286 0x03b8 PolicyAgent - ok
14:45:41.0496 0x03b8 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:45:41.0496 0x03b8 PptpMiniport - ok
14:45:41.0706 0x03b8 [ A32BEBAF723557681BFC6BD93E98BD26, 35039BA72A29F87B2CA37DCDE4EFDAABBDEAD8CE3EB8652ACC665994118145A6 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
14:45:41.0706 0x03b8 Processor - ok
14:45:41.0977 0x03b8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
14:45:41.0977 0x03b8 ProtectedStorage - ok
14:45:42.0157 0x03b8 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
14:45:42.0157 0x03b8 PSched - ok
14:45:42.0407 0x03b8 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:45:42.0407 0x03b8 Ptilink - ok
14:45:42.0648 0x03b8 [ 1BCFED0946F9460D6272F85B70B87A52, 6EDE283D9B5173D9F91C969E5F97A21282395769C989F609B1EFDE7B5E40EA97 ] QCONSVC C:\WINDOWS\system32\QCONSVC.EXE
14:45:42.0668 0x03b8 QCONSVC - ok
14:45:42.0828 0x03b8 ql1080 - ok
14:45:42.0958 0x03b8 Ql10wnt - ok
14:45:43.0118 0x03b8 ql12160 - ok
14:45:43.0258 0x03b8 ql1240 - ok
14:45:43.0419 0x03b8 ql1280 - ok
14:45:43.0599 0x03b8 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:45:43.0599 0x03b8 RasAcd - ok
14:45:43.0859 0x03b8 [ AD188BE7BDF94E8DF4CA0A55C00A5073, C7D76CB579FAEBCCC2873499441BACDD6BD6668ACF5ED7F31862656E96E2B20C ] RasAuto C:\WINDOWS\System32\rasauto.dll
14:45:43.0909 0x03b8 RasAuto - ok
14:45:44.0130 0x03b8 [ 0207D26DDF796A193CCD9F83047BB5FC, 13613036BCB869FBD7229A0FE25D324710308385D8C35E5D990A40E52BE040DF ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys
14:45:44.0130 0x03b8 Rasirda - ok
14:45:44.0320 0x03b8 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:45:44.0320 0x03b8 Rasl2tp - ok
14:45:44.0670 0x03b8 [ 76A9A3CBEADD68CC57CDA5E1D7448235, 4AFD048C5D2306AB8DE46F3AA60AC0213333DDA3B09A9E91F7585DB6EB978EC8 ] RasMan C:\WINDOWS\System32\rasmans.dll
14:45:44.0741 0x03b8 RasMan - ok
14:45:44.0901 0x03b8 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:45:44.0901 0x03b8 RasPppoe - ok
14:45:45.0151 0x03b8 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
14:45:45.0161 0x03b8 Raspti - ok
14:45:45.0432 0x03b8 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:45:45.0442 0x03b8 Rdbss - ok
14:45:45.0662 0x03b8 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:45:45.0662 0x03b8 RDPCDD - ok
14:45:45.0922 0x03b8 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
14:45:45.0932 0x03b8 rdpdr - ok
14:45:46.0253 0x03b8 [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
14:45:46.0263 0x03b8 RDPWD - ok
14:45:46.0583 0x03b8 [ 3C37BF86641BDA977C3BF8A840F3B7FA, AB9A6E54DBA3F4561CD4837372BECCE0D73943D02E3288F944333039375AC08C ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
14:45:46.0633 0x03b8 RDSessMgr - ok
14:45:46.0804 0x03b8 [ F828DD7E1419B6653894A8F97A0094C5, E6150E1F598BA4CFEDB8FF075BC0D576518C331B864388F1CAE8812EFF106ECF ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
14:45:46.0804 0x03b8 redbook - ok
14:45:47.0064 0x03b8 [ 7E699FF5F59B5D9DE5390E3C34C67CF5, 3FCF0442D80AB181FED4303E570378736AA1F8718C0B8B70F689A1E45200FFE4 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
14:45:47.0084 0x03b8 RemoteAccess - ok
14:45:47.0404 0x03b8 [ 5B19B557B0C188210A56A6B699D90B8F, 0FA880B81AE615206FD1738B83428AAA491D54B24168339DE6E87FDE8C6C14B0 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
14:45:47.0414 0x03b8 RemoteRegistry - ok
14:45:47.0675 0x03b8 [ AAED593F84AFA419BBAE8572AF87CF6A, CC0FFC5A69394C8830DC66320DA01A820BBF41AD7E57D0FC343561DC5EF9A360 ] RpcLocator C:\WINDOWS\System32\locator.exe
14:45:47.0705 0x03b8 RpcLocator - ok
14:45:48.0085 0x03b8 [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] RpcSs C:\WINDOWS\system32\rpcss.dll
14:45:48.0105 0x03b8 RpcSs - ok
14:45:48.0416 0x03b8 [ 471B3F9741D762ABE75E9DEEA4787E47, D9ADE42965EC22AEB4B2AD21D429C3C8232A60AA9853DEFDA7AED86A13FE8623 ] RSVP C:\WINDOWS\System32\rsvp.exe
14:45:48.0466 0x03b8 RSVP - ok
14:45:48.0907 0x03b8 [ 88B63F291AE10C1B66D2B9ED6921A7DF, A0174FC75459CE38028B1436BD46234062A3FCBE164E139F53BE49BAB3B8F95F ] rtl8185 C:\WINDOWS\system32\DRIVERS\rtl8185.sys
14:45:48.0917 0x03b8 rtl8185 - ok
14:45:49.0137 0x03b8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] SamSs C:\WINDOWS\system32\lsass.exe
14:45:49.0137 0x03b8 SamSs - ok
14:45:49.0347 0x03b8 [ 86D007E7A654B9A71D1D7D856B104353, 7B1DE53D637A5FC9619D5D07C48927AFEC89D959207F6F2E2F45DD054EEA04C7 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
14:45:49.0377 0x03b8 SCardSvr - ok
14:45:49.0718 0x03b8 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA, 0B582F47BD70732BAC48B8B86E5D06CE7F299A20E8177F3F2E6F28217C3FB605 ] Schedule C:\WINDOWS\system32\schedsvc.dll
14:45:49.0788 0x03b8 Schedule - ok
14:45:50.0058 0x03b8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:45:50.0058 0x03b8 Secdrv - ok
14:45:50.0319 0x03b8 [ CBE612E2BB6A10E3563336191EDA1250, C331797DC3569F0E715766561DE2562F60B924378842246C35D2B1CF867E9D96 ] seclogon C:\WINDOWS\System32\seclogon.dll
14:45:50.0329 0x03b8 seclogon - ok
14:45:50.0609 0x03b8 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0, 7105B026F966A992430F86C3698ABE15EC73E4772F1A3E362E29FD5247A5DCA6 ] SENS C:\WINDOWS\system32\sens.dll
14:45:50.0619 0x03b8 SENS - ok
14:45:50.0799 0x03b8 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
14:45:50.0799 0x03b8 serenum - ok
14:45:51.0010 0x03b8 [ CCA207A8896D4C6A0C9CE29A4AE411A7, 5999B39242283CD803319AADCA171CCCC6E2A40FB2FAFA51B1D29F3FF2DD8D6C ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
14:45:51.0010 0x03b8 Serial - ok
14:45:51.0380 0x03b8 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
14:45:51.0380 0x03b8 Sfloppy - ok
14:45:51.0731 0x03b8 [ 83F41D0D89645D7235C051AB1D9523AC, B681F33EEAA511D6A2DCB9FBAA407B739184C9FF6067C6B7E51F1FC37E9D4DD7 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
14:45:51.0821 0x03b8 SharedAccess - ok
14:45:52.0031 0x03b8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
14:45:52.0041 0x03b8 ShellHWDetection - ok
14:45:52.0211 0x03b8 Simbad - ok
14:45:52.0362 0x03b8 [ E061A9A43C80BE5AA5D94F1EF4A713C1, 334CD9E8C4A57C2BF43A0D3895D18832C7EB0C5A6455CF3361A09F7A28DF4A6F ] Smapint C:\WINDOWS\system32\drivers\Smapint.sys
14:45:52.0372 0x03b8 Smapint - ok
14:45:52.0812 0x03b8 [ 7B06A22F16B64C23C41E0278B8DC90BF, 02867493783DAC96A90B6CD14B358C05C63FE0862A98BD71CD54F34E31632C54 ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
14:45:52.0862 0x03b8 smwdm - ok
14:45:53.0022 0x03b8 Sparrow - ok
14:45:53.0203 0x03b8 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
14:45:53.0203 0x03b8 splitter - ok
14:45:53.0463 0x03b8 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
14:45:53.0493 0x03b8 Spooler - ok
14:45:53.0824 0x03b8 [ 76BB022C2FB6902FD5BDD4F78FC13A5D, 6031CB2344D7277FC703480EB43CF856A0F8F818EA98FF26A2CA532336CD2DFA ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
14:45:53.0824 0x03b8 sr - ok
14:45:54.0094 0x03b8 [ 3805DF0AC4296A34BA4BF93B346CC378, B57A14F1B7B0997E619DDD62B73157AA2399A9852166FB58139CBB358A88F6F3 ] srservice C:\WINDOWS\System32\srsvc.dll
14:45:54.0154 0x03b8 srservice - ok
14:45:54.0505 0x03b8 [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
14:45:54.0525 0x03b8 Srv - ok
14:45:54.0785 0x03b8 [ 0A5679B3714EDAB99E357057EE88FCA6, 01E1A101FFF48402C77E385A78FEF27876E04533B60EB1C18558A737E57E5FA8 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
14:45:54.0795 0x03b8 SSDPSRV - ok
14:45:55.0176 0x03b8 [ 8BAD69CBAC032D4BBACFCE0306174C30, 2AA0DA710FCBFF38FE8DA91EE02E7A4503269347E61F8D3246FCA3384BBA2305 ] stisvc C:\WINDOWS\system32\wiaservc.dll
14:45:55.0276 0x03b8 stisvc - ok
14:45:55.0536 0x03b8 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
14:45:55.0546 0x03b8 swenum - ok
14:45:55.0766 0x03b8 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
14:45:55.0766 0x03b8 swmidi - ok
14:45:55.0897 0x03b8 SwPrv - ok
14:45:56.0107 0x03b8 symc810 - ok
14:45:56.0247 0x03b8 symc8xx - ok
14:45:56.0397 0x03b8 sym_hi - ok
14:45:56.0538 0x03b8 sym_u3 - ok
14:45:56.0728 0x03b8 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
14:45:56.0728 0x03b8 sysaudio - ok
14:45:57.0098 0x03b8 [ E48A91AC570F9A683CBCFE94C59DCB18, 9BDDEAD3900F28BEE90F5DAB2354E8136613E729F3E07193411F00E07A1040CC ] syshost32 C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe
14:45:57.0138 0x03b8 syshost32 - ok
14:45:57.0519 0x03b8 [ C7ABBC59B43274B1109DF6B24D617051, 4384CA0AA6CE9B603CF7DB775A3C721E46715D5B120B94FB57DEADAADE18535B ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
14:45:57.0559 0x03b8 SysmonLog - ok
14:45:57.0889 0x03b8 [ 3CB78C17BB664637787C9A1C98F79C38, F35C31F6B7F366CB949D1044B357C76DEC9170441C5E559802794F62B72FD255 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
14:45:58.0010 0x03b8 TapiSrv - ok
14:45:58.0340 0x03b8 [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:45:58.0360 0x03b8 Tcpip - ok
14:45:58.0530 0x03b8 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
14:45:58.0530 0x03b8 TDPIPE - ok
14:45:58.0781 0x03b8 [ 0353AC9D91E28D936E4227539B1B2393, 8B31C2F496C446DF69B898B9B585A1097DDCA3EE50ACD31B5E09D8B1CD68DF94 ] TDSMAPI C:\WINDOWS\system32\Drivers\TDSMAPI.SYS
14:45:58.0781 0x03b8 TDSMAPI - ok
14:45:58.0991 0x03b8 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
14:45:59.0001 0x03b8 TDTCP - ok
14:45:59.0161 0x03b8 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
14:45:59.0161 0x03b8 TermDD - ok
14:45:59.0562 0x03b8 [ FF3477C03BE7201C294C35F684B3479F, D6246521539BA4ACD022D26983182F5E323D2EF1EA7C54265A248C43A1CE5202 ] TermService C:\WINDOWS\System32\termsrv.dll
14:45:59.0672 0x03b8 TermService - ok
14:45:59.0932 0x03b8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] Themes C:\WINDOWS\System32\shsvcs.dll
14:45:59.0942 0x03b8 Themes - ok
14:46:00.0163 0x03b8 [ DB7205804759FF62C34E3EFD8A4CC76A, 13A4248F528CE98ACA66898E56822E4FC49B11F491FF1F61A687BA601BF0A802 ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
14:46:00.0193 0x03b8 TlntSvr - ok
14:46:00.0383 0x03b8 TosIde - ok
14:46:00.0533 0x03b8 [ 90579B74E1E110C2F379117047BDB356, EDD255C1A104DA6469846A4B4CDBFC5CB40DCD69DDE5207D799FB7DC850A014A ] Tp4Track C:\WINDOWS\system32\DRIVERS\tp4track.sys
14:46:00.0533 0x03b8 Tp4Track - ok
14:46:00.0684 0x03b8 [ 47F23B26F771765FD8CAC0EBAE4545E9, 2AFE4C57FE833F18E65F959DAF8879823CE8BEB13B1BA34A61E6806AF609EDC5 ] TPHKDRV C:\WINDOWS\system32\drivers\TPHKDRV.sys
14:46:00.0684 0x03b8 TPHKDRV - ok
14:46:00.0844 0x03b8 [ C10B74CF569D39594E170734DB590661, 134890D6FAE83FA38F8EEA3B72EC0E12778D6E15C7605758D9933AA4A945E755 ] TPPWR C:\WINDOWS\system32\drivers\Tppwr.sys
14:46:00.0854 0x03b8 TPPWR - ok
14:46:01.0124 0x03b8 [ 55BCA12F7F523D35CA3CB833C725F54E, 849FB1AE31B143B14B298BBC0D91230693D41DEB95F46516878F53A7F4186C38 ] TrkWks C:\WINDOWS\system32\trkwks.dll
14:46:01.0164 0x03b8 TrkWks - ok
14:46:01.0395 0x03b8 [ 76F0A07D83FA24478C07250F4FC8B128, 4894CD9ABDDC9712D3D9938A66B9CD83485AEA7F0D351769D58AC80FA5885412 ] TSMAPIP C:\WINDOWS\system32\drivers\TSMAPIP.SYS
14:46:01.0395 0x03b8 TSMAPIP - ok
14:46:01.0585 0x03b8 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
14:46:01.0585 0x03b8 Udfs - ok
14:46:01.0745 0x03b8 ultra - ok
14:46:02.0065 0x03b8 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
14:46:02.0086 0x03b8 Update - ok
14:46:02.0406 0x03b8 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91, 7746916DB48E3F5B243B63C066596AD9037A494BF1AD935946DD04AC85D983DF ] upnphost C:\WINDOWS\System32\upnphost.dll
14:46:02.0466 0x03b8 upnphost - ok
14:46:02.0696 0x03b8 [ 05365FB38FCA1E98F7A566AAAF5D1815, 16843048CEEC3DAA3B953A12FF1EE339E86783A08F2A56DA7F94AD9F9717D77D ] UPS C:\WINDOWS\System32\ups.exe
14:46:02.0706 0x03b8 UPS - ok
14:46:02.0907 0x03b8 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:46:02.0907 0x03b8 usbehci - ok
14:46:03.0127 0x03b8 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:46:03.0127 0x03b8 usbhub - ok
14:46:03.0327 0x03b8 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
14:46:03.0327 0x03b8 usbscan - ok
14:46:03.0558 0x03b8 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:46:03.0568 0x03b8 USBSTOR - ok
14:46:03.0758 0x03b8 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:46:03.0758 0x03b8 usbuhci - ok
14:46:04.0008 0x03b8 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
14:46:04.0008 0x03b8 VgaSave - ok
14:46:04.0118 0x03b8 ViaIde - ok
14:46:04.0339 0x03b8 [ 4C8FCB5CC53AAB716D810740FE59D025, 010EAC43DBED700B73E4FC908FAAF9F6A0168EBBD5D86751E49BC33AAA18BFA4 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
14:46:04.0339 0x03b8 VolSnap - ok
14:46:04.0689 0x03b8 [ 7A9DB3A67C333BF0BD42E42B8596854B, D31A9A3B1AAAB373EDD73B674102395212FCB616F829E938B7B2B7BE7D4752C5 ] VSS C:\WINDOWS\System32\vssvc.exe
14:46:04.0809 0x03b8 VSS - ok
14:46:05.0200 0x03b8 [ 54AF4B1D5459500EF0937F6D33B1914F, FA1876888BCB9C72A92369DBED4FF1A8666784523FB41E618FA0919490FCDDB9 ] W32Time C:\WINDOWS\System32\w32time.dll
14:46:05.0240 0x03b8 W32Time - ok
14:46:05.0540 0x03b8 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:46:05.0540 0x03b8 Wanarp - ok
14:46:05.0661 0x03b8 WDICA - ok
14:46:05.0861 0x03b8 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
14:46:05.0861 0x03b8 wdmaud - ok
14:46:06.0131 0x03b8 [ 77A354E28153AD2D5E120A5A8687BC06, 8B2D37A4443501C0A8E70BC2079BE27F0A36FD07B561E6F68B40A72EABBC2DFE ] WebClient C:\WINDOWS\System32\webclnt.dll
14:46:06.0141 0x03b8 WebClient - ok
14:46:06.0562 0x03b8 [ 2D0E4ED081963804CCC196A0929275B5, E1D75C7D7233D81DFDE13160B0C80138DF8B35230D04FB79B367A52FACF69BF8 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
14:46:06.0602 0x03b8 winmgmt - ok
14:46:07.0073 0x03b8 [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
14:46:07.0083 0x03b8 WmdmPmSN - ok
14:46:07.0533 0x03b8 [ E76F8807070ED04E7408A86D6D3A6137, BFCF5361B7335760A7AE4B6958DE516A27AC60AA09135A46F0B49F588FAFE3A0 ] Wmi C:\WINDOWS\System32\advapi32.dll
14:46:07.0754 0x03b8 Wmi - ok
14:46:08.0074 0x03b8 [ E0673F1106E62A68D2257E376079F821, 12992F18C9653050B10DC61D12988067933FCFDF02123D3A7EF5DE607A785DDC ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
14:46:08.0124 0x03b8 WmiApSrv - ok
14:46:08.0715 0x03b8 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B, C71FAAC752F6D58BF8556661252DBF8C5DDD090CAE002A2C7E09C9A014526066 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
14:46:09.0046 0x03b8 WMPNetworkSvc - ok
14:46:09.0316 0x03b8 [ CF4DEF1BF66F06964DC0D91844239104, CC1D9CECE2056D29A9651D51BB57C3F4F9BF9E90A4808CF7496C683C874FBD51 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
14:46:09.0316 0x03b8 WpdUsb - ok
14:46:09.0626 0x03b8 [ 7C278E6408D1DCE642230C0585A854D5, DA46079A04F6E8E3441E4AE454AEAC02B3E935DE29CE7F6D4476F57867FCC12A ] wscsvc C:\WINDOWS\system32\wscsvc.dll
14:46:09.0636 0x03b8 wscsvc - ok
14:46:09.0827 0x03b8 [ 35321FB577CDC98CE3EB3A3EB9E4610A, C9A6F5CF282D8FCB3CDFCC4B306013480E78E1B664E1A60A4E27B161F9FFD4CD ] wuauserv C:\WINDOWS\system32\wuauserv.dll
14:46:09.0857 0x03b8 wuauserv - ok
14:46:10.0127 0x03b8 [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
14:46:10.0137 0x03b8 WudfPf - ok
14:46:10.0367 0x03b8 [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
14:46:10.0377 0x03b8 WudfRd - ok
14:46:10.0608 0x03b8 [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
14:46:10.0618 0x03b8 WudfSvc - ok
14:46:10.0988 0x03b8 [ 81DC3F549F44B1C1FFF022DEC9ECF30B, 3D14BFEA539F9CEB16555BD56C5E3C7C8F6692FC62C2789F8AAEA1C042E63940 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
14:46:11.0149 0x03b8 WZCSVC - ok
14:46:11.0469 0x03b8 [ 295D21F14C335B53CB8154E5B1F892B9, 9418477C2E3EA93E93D931A4EDD4500DA568FAD6040204B5201D1080203B0BBC ] xmlprov C:\WINDOWS\System32\xmlprov.dll
14:46:11.0489 0x03b8 xmlprov - ok
14:46:11.0649 0x03b8 ================ Scan global ===============================
14:46:11.0970 0x03b8 [ 42F1F4C0AFB08410E5F02D4B13EBB623, 924C30587C51C0D1E1F47991969AF492A644552E15F2480EA991DCB74A3E68D5 ] C:\WINDOWS\system32\basesrv.dll
14:46:12.0150 0x03b8 [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
14:46:12.0390 0x03b8 [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
14:46:12.0511 0x03b8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] C:\WINDOWS\system32\services.exe
14:46:12.0521 0x03b8 [ Global ] - ok
14:46:12.0541 0x03b8 ================ Scan MBR ==================================
14:46:12.0601 0x03b8 [ AB67D479E4EE1CCAD757294B60DDB98F ] \Device\Harddisk0\DR0
14:46:12.0951 0x03b8 \Device\Harddisk0\DR0 - ok
14:46:13.0001 0x03b8 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
14:46:13.0031 0x03b8 \Device\Harddisk1\DR1 - ok
14:46:13.0051 0x03b8 ================ Scan VBR ==================================
14:46:13.0071 0x03b8 [ 4FDC23B120F0EC5F80AE98557F4D9DCB ] \Device\Harddisk0\DR0\Partition1
14:46:13.0081 0x03b8 \Device\Harddisk0\DR0\Partition1 - ok
14:46:13.0131 0x03b8 [ BDF83EFF05C13F2D4DA35EC086A7BB23 ] \Device\Harddisk1\DR1\Partition1
14:46:13.0842 0x03b8 \Device\Harddisk1\DR1\Partition1 - ok
14:46:13.0862 0x03b8 ================ Scan generic autorun ======================
14:46:14.0013 0x03b8 [ FAE95D6D7651B5629C4E19ADBC9A3863, 8209A13B8C845D8EFB1B1C21135B5119E6E2AC5694B982E2103E53D0CBAA080C ] C:\WINDOWS\system32\Ati2mdxx.exe
14:46:14.0023 0x03b8 ATIModeChange - ok
14:46:14.0153 0x03b8 [ 97826CB927E0E7F4500879D99DE6D3C5, 0FB04C5AA4C1BE2E35BBDE474916DF00E223A41D6E0C590FF0C5132EBBA69051 ] C:\WINDOWS\system32\tp4serv.exe
14:46:14.0223 0x03b8 TrackPointSrv - ok
14:46:14.0313 0x03b8 [ 71E256D5C8FB8FD1933968DCCFD967A0, 92481C790B092CC363BABEA16B0252BEEE1A7CBC1C6FF55F93030DD4AB92FA66 ] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
14:46:14.0333 0x03b8 TPTRAY - ok
14:46:14.0343 0x03b8 BMMGAG - ok
14:46:14.0583 0x03b8 [ 6C2CF216C460BED0D4B83AF07980A761, B8BF59F1F5937558B73F1D6728E92AE8B07CB38AD529357A4E16663A969A81BE ] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
14:46:14.0764 0x03b8 QCTRAY - ok
14:46:14.0844 0x03b8 [ 8633F1E7AA1912AD962E5A656D264045, BB17957ECE5EC9ED25E9B58315AD436C76B2FF1B5A1C5D8397FC7950CC65F126 ] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
14:46:14.0854 0x03b8 QCWLICON - ok
14:46:14.0934 0x03b8 [ AA3B957AF3F3B4AA9047D5531696AB0E, BA826D7A0B56C04528C4A8EDA498173C533BA3CDD75E1C73E224AFD712F06680 ] C:\WINDOWS\system32\tp4ex.exe
14:46:14.0954 0x03b8 TP4EX - ok
14:46:15.0044 0x03b8 [ 6CE63001262FB82D746E1DEEBF00B43B, B660ECA6989ABFC3B97FCEB8D692A11F77B9D4A81D5FC34759462D2EC37A2F63 ] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
14:46:15.0074 0x03b8 TPHOTKEY - ok
14:46:15.0114 0x03b8 Tgcmd - ok
14:46:15.0214 0x03b8 [ C0041BB27E2E5B0550C179ECF53425CD, 82EB1BF88B1D93F4AEC5EB6A1DB790E6EFA0379DD771251707BE9F67266D3547 ] C:\WINDOWS\AGRSMMSG.exe
14:46:20.0522 0x03b8 AGRSMMSG - ok
14:46:20.0662 0x03b8 [ 3E4C03CEFAD8DE135263236B61A49C90, 243201B64F4B60D55CDB1A3BF4B9AA60BC22EB8ACA88E95042EE48AC5DF5F397 ] C:\WINDOWS\system32\\NeroCheck.exe
14:46:20.0742 0x03b8 NeroCheck - ok
14:46:20.0893 0x03b8 [ E284188C5CF416378CC740EB13059A50, 0E0863D84B29662B3EEE0602742CAE8F966CE043E690C62BC3A00244B7D35D04 ] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
14:46:20.0913 0x03b8 Adobe Reader Speed Launcher - ok
14:46:21.0724 0x03b8 [ 29FB6EF1EFB1357E2883FE297F1EBC31, A6F465EA84277D88771BE6438CAC32D8E2C73A6EEC809CB38E1090FFFB27804E ] C:\PROGRA~1\AVG\AVG9\avgtray.exe
14:46:22.0535 0x03b8 AVG9_TRAY - ok
14:46:23.0196 0x03b8 [ 3103FE27C967675B019E880AA6DA3D6D, 515E750ACD28C3CFD8174B7F213E2AA741D8942FB68E57F701EBCBB92EC3F537 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
14:46:23.0747 0x03b8 Adobe ARM - ok
14:46:24.0037 0x03b8 [ 14D6542607ACD4B2D1DDB1A36E0D8813, 3A270600549E8E7988D5AF3486C0F504269B9573393D87BF87BDB2287BF007B2 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
14:46:24.0137 0x03b8 SunJavaUpdateSched - ok
14:46:24.0167 0x03b8 {B2B73189-3468-40D7-B711-0F99FC4A9D69} - ok
14:46:24.0247 0x03b8 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3, 5FB24FC7916A6E6B3BE7D84CB1684215B266CD1495575C2E5672B8447932E5B1 ] C:\WINDOWS\system32\ctfmon.exe
14:46:24.0247 0x03b8 ctfmon.exe - ok
14:46:24.0257 0x03b8 updateMgr - ok
14:46:24.0307 0x03b8 MSMSGS - ok
14:46:24.0328 0x03b8 NeroHomeFirstStart - ok
14:46:24.0568 0x03b8 [ 269AFE2F2E2957DF8F7A5F82B2B092DB, 37B8B913090A01EC5C656214F9081AC93ADE8682582327366A7F76EDBDC98A39 ] C:\Program Files\AVG\AVG9\Notification\SPChecker1.exe
14:46:24.0728 0x03b8 avg_spchecker - ok
14:46:24.0908 0x03b8 AV detected via SS1: AVG Anti-Virus Free, 9.0, enabled, updated
14:46:24.0968 0x03b8 ============================================================
14:46:24.0968 0x03b8 Scan finished
14:46:24.0968 0x03b8 ============================================================
14:46:25.0049 0x037c Detected object count: 1
14:46:25.0049 0x037c Actual detected object count: 1
14:47:42.0380 0x037c C:\WINDOWS\System32\Drivers\2d19a0fd877a76cc.sys - copied to quarantine
14:47:42.0690 0x037c HKLM\SYSTEM\ControlSet002\services\2d19a0fd877a76cc - will be deleted on reboot
14:47:43.0682 0x037c C:\WINDOWS\System32\Drivers\2d19a0fd877a76cc.sys - will be deleted on reboot
14:47:43.0682 0x037c 2d19a0fd877a76cc ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
14:47:45.0524 0x037c KLMD registered as C:\WINDOWS\system32\drivers\57775552.sys
14:48:33.0854 0x0348 Deinitialize success
14:53:53.0360 0x05ec TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34
14:53:56.0235 0x05ec ============================================================
14:53:56.0235 0x05ec Current date / time: 2014/12/08 14:53:56.0235
14:53:56.0235 0x05ec SystemInfo:
14:53:56.0255 0x05ec
14:53:56.0255 0x05ec OS Version: 5.1.2600 ServicePack: 3.0
14:53:56.0255 0x05ec Product type: Workstation
14:53:56.0255 0x05ec ComputerName: THINKPAD
14:53:56.0255 0x05ec UserName: IBM
14:53:56.0255 0x05ec Windows directory: C:\WINDOWS
14:53:56.0255 0x05ec System windows directory: C:\WINDOWS
14:53:56.0255 0x05ec Processor architecture: Intel x86
14:53:56.0255 0x05ec Number of processors: 1
14:53:56.0255 0x05ec Page size: 0x1000
14:53:56.0255 0x05ec Boot type: Normal boot
14:53:56.0285 0x05ec ============================================================
14:53:56.0305 0x05ec BG loaded
14:54:10.0806 0x05ec System UUID: {65C7A9CC-C291-863E-FB8C-E2EA3E48D80E}
14:54:44.0163 0x05ec Drive \Device\Harddisk0\DR0 - Size: 0x4A8530000 ( 18.63 Gb ), SectorSize: 0x200, Cylinders: 0xA18, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000044
14:54:45.0055 0x05ec Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x50C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000044
14:54:45.0145 0x05ec ============================================================
14:54:45.0145 0x05ec \Device\Harddisk0\DR0:
14:54:54.0508 0x05ec MBR partitions:
14:54:54.0508 0x05ec \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2272C11
14:54:54.0508 0x05ec \Device\Harddisk1\DR1:
14:54:54.0518 0x05ec MBR partitions:
14:54:54.0518 0x05ec \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x12A18800
14:54:54.0518 0x05ec ============================================================
14:54:58.0574 0x05ec C: <-> \Device\Harddisk0\DR0\Partition1
14:54:59.0225 0x05ec D: <-> \Device\Harddisk1\DR1\Partition1
14:54:59.0225 0x05ec ============================================================
14:54:59.0225 0x05ec Initialize success
14:54:59.0225 0x05ec ============================================================
14:55:40.0755 0x01f8 ============================================================
14:55:40.0755 0x01f8 Scan started
14:55:40.0755 0x01f8 Mode: Manual;
14:55:40.0755 0x01f8 ============================================================
14:55:40.0755 0x01f8 KSN ping started
14:55:53.0443 0x01f8 KSN ping finished: true
14:55:57.0479 0x01f8 ================ Scan system memory ========================
14:55:57.0489 0x01f8 System memory - ok
14:55:57.0489 0x01f8 ================ Scan services =============================
14:56:05.0881 0x01f8 27784469 - ok
14:56:05.0911 0x01f8 Abiosdsk - ok
14:56:05.0951 0x01f8 abp480n5 - ok
14:56:07.0143 0x01f8 [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:56:07.0623 0x01f8 ACPI - ok
14:56:12.0761 0x01f8 [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:56:12.0771 0x01f8 ACPI - ok
14:56:21.0243 0x01f8 [ 8FD99680A539792A30E97944FDAECF17, 594F8E0C3695400B0C09A797AF6BDFAC6F750ECD67D0EE803914C572B1DCC43C ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
14:56:21.0253 0x01f8 ACPI - ok
14:56:24.0638 0x01f8 [ 9859C0F6936E723E4892D7141B1327D5, 5E8F6A2FC4DF2E5E92A1D66ECC2810E08B42B64E9CD0DF4AD3F78EA8558B90AF ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
14:56:24.0718 0x01f8 ACPIEC - ok
14:56:24.0888 0x01f8 [ 8BED39E3C35D6A489438B8141717A557, 1B5796E56B0927360CE0759641B1151828BC0A9E45620D2B2D880491F5CE33D0 ] aec C:\WINDOWS\system32\drivers\aec.sys
14:56:24.0898 0x01f8 aec - ok
14:56:24.0978 0x01f8 [ 58A8273918EEF2BF9204B12ED171513A, 6C79AC93FBBD8B877DD71557A8B2A2B9C20277BBFCEDE6A1ECA7FFC650FC6143 ] AegisP C:\WINDOWS\system32\DRIVERS\AegisP.sys
14:56:24.0998 0x01f8 AegisP - ok
14:56:28.0914 0x01f8 [ 1E44BC1E83D8FD2305F8D452DB109CF9, CF5EC07E0B589FA2A4701C6CFD69E893FC3ABF274AD57AE3C13FFE49063B02C8 ] AFD C:\WINDOWS\System32\drivers\afd.sys
14:56:29.0014 0x01f8 AFD - ok
14:56:33.0751 0x01f8 [ AFF071B6290776E1FA162837C35EAC78, 07F3CDB27C767BEDB9E8C82A4FE738AD408225C2A22428669F742EDF30410758 ] AgereSoftModem C:\WINDOWS\system32\DRIVERS\AGRSM.sys
14:56:34.0572 0x01f8 AgereSoftModem - ok
14:56:34.0652 0x01f8 [ 08FD04AA961BDC77FB983F328334E3D7, A784EC8A9EDB579262366B5A9AB177DB7BEC0A421BDE85431D0AD4959D5AF5E7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
14:56:34.0873 0x01f8 agp440 - ok
14:56:34.0903 0x01f8 Aha154x - ok
14:56:34.0943 0x01f8 aic78u2 - ok
14:56:34.0973 0x01f8 aic78xx - ok
14:56:35.0223 0x01f8 [ A9A3DAA780CA6C9671A19D52456705B4, 67C959144B57AE0BBF1D82DBED197F32CDB06FECD883A80C441A0202FE83FAB4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
14:56:35.0283 0x01f8 Alerter - ok
14:56:35.0423 0x01f8 [ 8C515081584A38AA007909CD02020B3D, A5E13CA10F702928E0DE84C74D0EA8ACCB117FD76FBABC55220C75C4FFD596DC ] ALG C:\WINDOWS\System32\alg.exe
14:56:35.0423 0x01f8 ALG - ok
14:56:35.0453 0x01f8 AliIde - ok
14:56:35.0484 0x01f8 amsint - ok
14:56:35.0614 0x01f8 [ D8849F77C0B66226335A59D26CB4EDC6, 4990031453204C57E36E850252A39B05D6ECDAB9E71A8136FB4900F17E59C9CA ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
14:56:35.0844 0x01f8 AppMgmt - ok
14:56:35.0874 0x01f8 asc - ok
14:56:35.0894 0x01f8 asc3350p - ok
14:56:35.0934 0x01f8 asc3550 - ok
14:56:36.0655 0x01f8 [ 0E5E4957549056E2BF2C49F4F6B601AD, F7F19FDC906B719A3516D30A9B4A2262C8CC5B36B94E3D4195C345EC4610FF2B ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
14:56:36.0996 0x01f8 aspnet_state - ok
14:56:37.0126 0x01f8 [ B153AFFAC761E7F5FCFA822B9C4E97BC, 7E60F572A6B3C6219E3C86225AA37243AFFD74337DB7F108B04778042E5CC959 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
14:56:37.0156 0x01f8 AsyncMac - ok
14:56:37.0206 0x01f8 [ 9F3A2F5AA6875C72BF062C712CFA2674, B4DF1D2C56A593C6B54DE57395E3B51D288F547842893B32B0F59228A0CF70B9 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
14:56:37.0216 0x01f8 atapi - ok
14:56:37.0246 0x01f8 Atdisk - ok
14:56:37.0336 0x01f8 [ 418CDC2888D01E1CD5CE297AF00807A3, 1DE3277683E0D3D2B1B83FF9D718C125E3D542477C1505063DDE8145C408391D ] Ati HotKey Poller C:\WINDOWS\System32\Ati2evxx.exe
14:56:37.0346 0x01f8 Ati HotKey Poller - ok
14:56:37.0547 0x01f8 [ D1F804642C627782C6D213BCE0604F09, 43DB2A74835B5E5C796509990E0FCB4A4897A027D0117F5B6C8ECD37E80F7F28 ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
14:56:37.0597 0x01f8 ati2mtag - ok
14:56:37.0667 0x01f8 [ 9916C1225104BA14794209CFA8012159, 5D6F05F715C52A16D05CAE15C3DFE77A139A7F27F7AE710EC9A10F9EE05115A1 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
14:56:37.0697 0x01f8 Atmarpc - ok
14:56:37.0767 0x01f8 [ DEF7A7882BEC100FE0B2CE2549188F9D, 462C95B63D0A1058291A2DC8CBFCB13D7D74CCD1CA43B613A7EB43D49E3276F8 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
14:56:37.0777 0x01f8 AudioSrv - ok
14:56:37.0847 0x01f8 [ D9F724AA26C010A217C97606B160ED68, 329B5118F2409731D06FDAE85B6ADD64A048292801BCB3546651CEB303111695 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
14:56:37.0877 0x01f8 audstub - ok
14:56:38.0278 0x01f8 [ AA054CD537357F03D5BA6ABA7562B35F, F331D929920D38B53FEA464AF54DB59224882D386C55689CDDF6C6DC1473284E ] avg9emc C:\Program Files\AVG\AVG9\avgemc.exe
14:56:38.0328 0x01f8 avg9emc - ok
14:56:38.0428 0x01f8 [ C4D15594DB5BE042D3346EA58DF87D89, 8E24868518DE53F28C92C473A415BED613665287F338B815FEDE21D151F01962 ] avg9wd C:\Program Files\AVG\AVG9\avgwdsvc.exe
14:56:38.0448 0x01f8 avg9wd - ok
14:56:38.0568 0x01f8 [ A9F4D19DE72C738759330D10D35C4398, 46D760EBFBABF3FDCD02F4AC38180FBFFEFFA36F68C18602695A9FCB6C4C13DE ] AvgLdx86 C:\WINDOWS\System32\Drivers\avgldx86.sys
14:56:38.0638 0x01f8 AvgLdx86 - ok
14:56:38.0728 0x01f8 [ 80FF2B1B7EEDA966394F0BAA895BBF4B, D8F5C111837707DC37975C1E315FCD33BF96AB21D89874CB0290134A44C46BEF ] AvgMfx86 C:\WINDOWS\System32\Drivers\avgmfx86.sys
14:56:38.0778 0x01f8 AvgMfx86 - ok
14:56:38.0898 0x01f8 [ 9A7A93388F503A34E7339AE7F9997449, 9549146C19EAF65DB98314A7CCB0AB27503DC812B521444CBEA5493998ADAA80 ] AvgTdiX C:\WINDOWS\System32\Drivers\avgtdix.sys
14:56:38.0969 0x01f8 AvgTdiX - ok
14:56:39.0149 0x01f8 [ DA1F27D85E0D1525F6621372E7B685E9, 5A81A46A3BDD19DAFC6C87D277267A5D44F3A1B5302F2CC1111D84B7BAD5610D ] Beep C:\WINDOWS\system32\drivers\Beep.sys
14:56:39.0189 0x01f8 Beep - ok
14:56:39.0319 0x01f8 [ 574738F61FCA2935F5265DC4E5691314, 3C7CCF064397186C3A3863DD2370AB6414A61B330097DCA4F299CA7BBAA3D1B4 ] BITS C:\WINDOWS\system32\qmgr.dll
14:56:40.0230 0x01f8 BITS - ok
14:56:40.0351 0x01f8 [ CFD4E51402DA9838B5A04AE680AF54A0, 5378F42B195B5832B00A05AD64E00473A45FFB86AC25C57241F26EA82B149FE1 ] Browser C:\WINDOWS\System32\browser.dll
14:56:40.0361 0x01f8 Browser - ok
14:56:40.0441 0x01f8 [ 90A673FC8E12A79AFBED2576F6A7AAF9, BDE7858A3457DB979FEDD8577FA6321BF72848E4A7BF9F173C78A6A10CBB3EBE ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
14:56:40.0471 0x01f8 cbidf2k - ok
14:56:40.0511 0x01f8 cd20xrnt - ok
14:56:40.0561 0x01f8 [ C1B486A7658353D33A10CC15211A873B, AA4DD9E7AAE5AAB1146B360B17001F975D2F29A1281CF7B13E7136480410F347 ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
14:56:40.0581 0x01f8 Cdaudio - ok
14:56:40.0691 0x01f8 [ C885B02847F5D2FD45A24E219ED93B32, B26B2F8E3A831E2B65EB0C5195B0645CD50E22615CE79C9B0B391CD563B121DB ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
14:56:40.0731 0x01f8 Cdfs - ok
14:56:40.0811 0x01f8 [ 1F4260CC5B42272D71F79E570A27A4FE, B51C2A3ED3C309953D0EA45869C8E464C10F2533DADE9E0286AF674979098D1D ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
14:56:40.0851 0x01f8 Cdrom - ok
14:56:40.0881 0x01f8 Changer - ok
14:56:40.0951 0x01f8 [ 1CFE720EB8D93A7158A4EBC3AB178BDE, 65D2A9D9A88F38D4AF323134C151BA0F4B3CD0F6A134AF86E7AC9D07319F1726 ] cisvc C:\WINDOWS\System32\cisvc.exe
14:56:40.0971 0x01f8 cisvc - ok
14:56:41.0022 0x01f8 [ 34CBE729F38138217F9C80212A2A0C82, A9FD7A758D12E0818A11BEEF1CE772FEFA8373E92EF6C0DA8628CD4572CC9A43 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
14:56:41.0062 0x01f8 ClipSrv - ok
14:56:41.0242 0x01f8 [ D87ACAED61E417BBA546CED5E7E36D9C, 14AC6034A5BC0FB2A1AFDAD42BEF4DE641556E54AD30D0C46765660A4BE55462 ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
14:56:42.0373 0x01f8 clr_optimization_v2.0.50727_32 - ok
14:56:42.0444 0x01f8 [ 0F6C187D38D98F8DF904589A5F94D411, DB987093446216CEE913AC27503BF7E23E5A62DF169B355730285DAB64F6ED28 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
14:56:42.0474 0x01f8 CmBatt - ok
14:56:42.0504 0x01f8 CmdIde - ok
14:56:42.0554 0x01f8 [ 6E4C9F21F0FAE8940661144F41B13203, 731202A0DD021FCF9287FEA631212603AAAC23F9E7F76B2882F913B18A971F1C ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
14:56:42.0584 0x01f8 Compbatt - ok
14:56:42.0624 0x01f8 COMSysApp - ok
14:56:42.0684 0x01f8 Cpqarray - ok
14:56:42.0764 0x01f8 [ 3D4E199942E29207970E04315D02AD3B, 0825960894CF9C86CC8775BDD2A262948A09CA495AA7FE9F210FAF49E7086383 ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
14:56:42.0764 0x01f8 CryptSvc - ok
14:56:42.0794 0x01f8 dac2w2k - ok
14:56:42.0824 0x01f8 dac960nt - ok
14:56:43.0054 0x01f8 [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
14:56:43.0074 0x01f8 DcomLaunch - ok
14:56:43.0295 0x01f8 [ 5E38D7684A49CACFB752B046357E0589, F192AD4190BCFB6939A5CBC91648FE63168AF79A5E227A111DEAD6A92E42AB8D ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
14:56:43.0305 0x01f8 Dhcp - ok
14:56:43.0385 0x01f8 [ 044452051F3E02E7963599FC8F4F3E25, 584BDDB074618BE76454CF90E74829CFF588B5B5FAEB793E2F7AAD26352DD689 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
14:56:43.0435 0x01f8 Disk - ok
14:56:43.0465 0x01f8 dmadmin - ok
14:56:43.0595 0x01f8 [ D992FE1274BDE0F84AD826ACAE022A41, C82BD6561A14F2932A761F5883A787B99031250EE5E9B7B5714AA045545C9B99 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
14:56:43.0695 0x01f8 dmboot - ok
14:56:43.0775 0x01f8 [ 7C824CF7BBDE77D95C08005717A95F6F, A73CB323B7A6410C3D3F258BF204E716ADF8C84C9E4F6562C57AB73DAED8CCDE ] dmio C:\WINDOWS\system32\drivers\dmio.sys
14:56:43.0846 0x01f8 dmio - ok
14:56:43.0916 0x01f8 [ E9317282A63CA4D188C0DF5E09C6AC5F, D41E002F555FE9015EF620975255F58BB79198CA1FF0E09EC950CB450FF77CF7 ] dmload C:\WINDOWS\system32\drivers\dmload.sys
14:56:43.0946 0x01f8 dmload - ok
14:56:44.0016 0x01f8 [ 57EDEC2E5F59F0335E92F35184BC8631, 61F6F0DC2D1A6C61D5EF0D5CC4BE0FFC217F1E61FDA3EA9F704709293656600F ] dmserver C:\WINDOWS\System32\dmserver.dll
14:56:44.0016 0x01f8 dmserver - ok
14:56:44.0687 0x01f8 [ 8A208DFCF89792A484E76C40E5F50B45, 4E40E2EB38C6254E7CAA488200E89EE7DEBBBA773890BC6A84313CC68178D54F ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
14:56:44.0687 0x01f8 DMusic - ok
14:56:44.0777 0x01f8 [ 5F7E24FA9EAB896051FFB87F840730D2, 356EEFDCD54DECAD0170B34B993E4BF80DD039E2B2922D7A8D09B84031E9FC7A ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
14:56:44.0807 0x01f8 Dnscache - ok
14:56:44.0887 0x01f8 [ 0F0F6E687E5E15579EF4DA8DD6945814, 5C32D88119EB1465B2D719BEE2E05888D1A73454B5E33F2D4928DA710F8BFBA3 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
14:56:44.0927 0x01f8 Dot3svc - ok
14:56:44.0977 0x01f8 dpti2o - ok
14:56:45.0017 0x01f8 [ 8F5FCFF8E8848AFAC920905FBD9D33C8, C8C6FB97AB0871C8C88A2201525A5CF10D5131CB6980D32692ED7A8F58399AD5 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
14:56:45.0017 0x01f8 drmkaud - ok
14:56:45.0298 0x01f8 [ 816AC73D056626333DD1D8F759F0AFAA, E41A12680088D927D011F84F1F173DB9D47444A7C7F701BCC39E7165A313B5A8 ] DSMBATT C:\WINDOWS\system32\drivers\DSMBATT.SYS
14:56:45.0338 0x01f8 DSMBATT - ok
14:56:45.0408 0x01f8 [ 81459BD6D8FEAADF2848AE88B3D02EC3, 240CEBFD1CDF824C43748362B3BDCE1B9D9CA238EDDC1E14051D006C6CCDFCF5 ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
14:56:45.0408 0x01f8 E100B - ok
14:56:45.0488 0x01f8 [ 2187855A7703ADEF0CEF9EE4285182CC, 8233CC11F637866C0074043835A785EA2B616739B6B1181B143A253CF2508CFD ] EapHost C:\WINDOWS\System32\eapsvc.dll
14:56:45.0528 0x01f8 EapHost - ok
14:56:45.0598 0x01f8 [ 938F1EC77BA35858248E584B2D2E9776, E48E7C363F4AAF8601016E3AAAD50C5C99E83747733C6339D9E21D3C8DDDE7B5 ] EGATHDRV C:\WINDOWS\system32\EGATHDRV.SYS
14:56:45.0608 0x01f8 EGATHDRV - ok
14:56:45.0698 0x01f8 [ BC93B4A066477954555966D77FEC9ECB, 27F5B780175EF46DA102EE33F7F33559C8B40C077EEA4405D579D9507F4B1C23 ] ERSvc C:\WINDOWS\System32\ersvc.dll
14:56:45.0708 0x01f8 ERSvc - ok
14:56:45.0808 0x01f8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] Eventlog C:\WINDOWS\system32\services.exe
14:56:45.0848 0x01f8 Eventlog - ok
14:56:45.0949 0x01f8 [ D4991D98F2DB73C60D042F1AEF79EFAE, 58AF949EAEBF4FF3E3314DFB66CE4198BF65F0836B68CD27A6ED319742CCCCD2 ] EventSystem C:\WINDOWS\System32\es.dll
14:56:45.0979 0x01f8 EventSystem - ok
14:56:46.0189 0x01f8 [ 38D332A6D56AF32635675F132548343E, E6909DB836AF679B4F4D62C7396D6C82769CC7ABB8C919C2AABFE934FCE268F6 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
14:56:46.0189 0x01f8 Fastfat - ok
14:56:46.0289 0x01f8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
14:56:46.0329 0x01f8 FastUserSwitchingCompatibility - ok
14:56:46.0379 0x01f8 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81, 8307A532AB4D05CBBCE206DC2759497708BF5AAA880BD00F0E4F281D8578A1F5 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
14:56:46.0399 0x01f8 Fdc - ok
14:56:46.0449 0x01f8 [ D45926117EB9FA946A6AF572FBE1CAA3, 4C94EF009D778BE0BDF8F812F026B96F91F641BE30AA2531427A5E63DBD280DA ] Fips C:\WINDOWS\system32\drivers\Fips.sys
14:56:46.0780 0x01f8 Fips - ok
14:56:46.0890 0x01f8 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0, 69C271AD5BCEBFD8AE5A769BDD7EC51256DA3A8ADAD5D12E5C0D13F4E82D8805 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
14:56:46.0910 0x01f8 Flpydisk - ok
14:56:47.0000 0x01f8 [ B2CF4B0786F8212CB92ED2B50C6DB6B0, 280F5CF8A90F7BEDE73ADD0DD0F8952088133A7CA9A3D3B7041957E33B36845D ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
14:56:47.0771 0x01f8 FltMgr - ok
14:56:48.0032 0x01f8 [ 8BA7C024070F2B7FDD98ED8A4BA41789, 47585006F86B2C6016EC54250A416794792D1E4024FF229C120BC25B684AF66A ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
14:56:48.0342 0x01f8 FontCache3.0.0.0 - ok
14:56:48.0382 0x01f8 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A, EC635E071201A766845D48973772CBE0958942B4162F3F5F70660D114CC877E0 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
14:56:48.0402 0x01f8 Fs_Rec - ok
14:56:48.0462 0x01f8 [ 6AC26732762483366C3969C9E4D2259D, FF2C9A23CC17F380093F0BEA955B1925794271C2FEA16B9B7639668E6999BAE3 ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
14:56:48.0502 0x01f8 Ftdisk - ok
14:56:48.0592 0x01f8 [ 0A02C63C8B144BD8C86B103DEE7C86A2, 7A3235DD3E1995DD72B212FAEB3ECA2A974434DE9BF6D269EA11BA65A80E7E50 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
14:56:48.0622 0x01f8 Gpc - ok
14:56:48.0773 0x01f8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
14:56:48.0793 0x01f8 gupdate - ok
14:56:48.0823 0x01f8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
14:56:48.0833 0x01f8 gupdatem - ok
14:56:48.0963 0x01f8 [ 4FCCA060DFE0C51A09DD5C3843888BCD, D82417706B517F2610DDF7C86BE03A72EFA9A2A389DF5C8F8ADEAB8144E2C80A ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
14:56:48.0973 0x01f8 helpsvc - ok
14:56:49.0003 0x01f8 HidServ - ok
14:56:49.0143 0x01f8 [ CCF82C5EC8A7326C3066DE870C06DAF1, 93395FA4C26B2E82DC8B7025ED3BCF583885E5D8C5F60CD6EEAA6335D6A126EC ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
14:56:49.0173 0x01f8 hidusb - ok
14:56:49.0243 0x01f8 [ 8878BD685E490239777BFE51320B88E9, C5C3ECF6B049B6736E35B39518A8F830B45C45A88FFE8E3A6B7922AD946597E2 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
14:56:49.0273 0x01f8 hkmsvc - ok
14:56:49.0303 0x01f8 hpn - ok
14:56:49.0353 0x01f8 hpt3xx - ok
14:56:49.0454 0x01f8 [ F80A415EF82CD06FFAF0D971528EAD38, 524D9E9201572929522F6805011783711B7C0F76308B924C89CF75F4B7A1FDF3 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
14:56:49.0464 0x01f8 HTTP - ok
14:56:49.0524 0x01f8 [ 6100A808600F44D999CEBDEF8841C7A3, 61A75118C327812C60622010985A2E80E79B6FD9030A5732390EE5426E4AF6C9 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
14:56:49.0624 0x01f8 HTTPFilter - ok
14:56:49.0654 0x01f8 i2omgmt - ok
14:56:49.0674 0x01f8 i2omp - ok
14:56:49.0734 0x01f8 [ 4A0B06AA8943C1E332520F7440C0AA30, DB2452390CCFE67E0C5FEB4FD42CA24ABE2DDD40D0B22DD5F5B8F70416863918 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
14:56:49.0754 0x01f8 i8042prt - ok
14:56:49.0834 0x01f8 [ 293131C1DA5F53CB05F75D637739D79C, F5F1A03FB012101FA143A288BCBC048A652A285F7DF533D1D08279E3A4D24326 ] IBMPMDRV C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
14:56:49.0864 0x01f8 IBMPMDRV - ok
14:56:49.0914 0x01f8 [ 91FA023C5203503776BCCC9CF96A0C59, A47C788A26E4D2A282DE2EC8A75E1544CAB17A2C5F4CF867026D3B95B3651D1D ] IBMPMSVC C:\WINDOWS\system32\ibmpmsvc.exe
14:56:49.0954 0x01f8 IBMPMSVC - ok
14:56:50.0034 0x01f8 [ 28DEEBA2E29CB0E91B641CA95F7740FD, 3E4D92E7211AA0CCD38561DB5F7CDC583C141A40D9077AA7D482336D3080369B ] IBMTPCHK C:\WINDOWS\system32\drivers\IBMBLDID.SYS
14:56:50.0105 0x01f8 IBMTPCHK - ok
14:56:50.0315 0x01f8 [ DAF66902F08796F9C694901660E5A64A, F4A4764DED05980426BAB54AAF040BC27A39C80315F5161E8D0B4C7F694BD8E6 ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
14:56:50.0385 0x01f8 IDriverT - ok
14:56:50.0786 0x01f8 [ C01AC32DC5C03076CFB852CB5DA5229C, A4D7749220B5BC965D96A267F1E02FE8284A230BA249109207BD4B9EA8DFAC96 ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
14:56:51.0947 0x01f8 idsvc - ok
14:56:52.0047 0x01f8 [ 083A052659F5310DD8B6A6CB05EDCF8E, 48D39B03FFB6FAA1529B774443BA12618AE3982D9F65A7B9D18F2269F78B31F4 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
14:56:52.0047 0x01f8 Imapi - ok
14:56:52.0178 0x01f8 [ 30DEAF54A9755BB8546168CFE8A6B5E1, 3936228CD3125C763ABFCB93E86E4B43838202BCC0913A28E84AC0263B43EE0D ] ImapiService C:\WINDOWS\System32\imapi.exe
14:56:52.0188 0x01f8 ImapiService - ok
14:56:52.0248 0x01f8 ini910u - ok
14:56:52.0308 0x01f8 [ B5466A9250342A7AA0CD1FBA13420678, 87E735C4E8924A883AB692D387A83BCBFAE6E165688336AE7AB488F7CA8D339E ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
14:56:52.0358 0x01f8 IntelIde - ok
14:56:52.0428 0x01f8 [ 8C953733D8F36EB2133F5BB58808B66B, 555868F246D73652E998B0B1296476E42FCEDED30D646CC000F31ECE4EBC25E6 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
14:56:52.0428 0x01f8 intelppm - ok
14:56:52.0548 0x01f8 [ 3BB22519A194418D5FEC05D800A19AD0, F6662F440950596DC1382DD1DB5D7891CCEA30A6062BEA942C18445B5F0D8B16 ] ip6fw C:\WINDOWS\system32\drivers\ip6fw.sys
14:56:52.0588 0x01f8 ip6fw - ok
14:56:52.0678 0x01f8 [ 731F22BA402EE4B62748ADAF6363C182, 5C3BEBD008A5BE4DC2F92076FF41A10DDC01E10EC7E6552213CFA11970811848 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
14:56:52.0738 0x01f8 IpFilterDriver - ok
14:56:52.0788 0x01f8 [ B87AB476DCF76E72010632B5550955F5, E6E74D3A86A7917A8BAED44F8E97CCD2EB171E4E4B27E9907F60D1523FAF319A ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
14:56:52.0818 0x01f8 IpInIp - ok
14:56:52.0909 0x01f8 [ CC748EA12C6EFFDE940EE98098BF96BB, AF523E21C25D9A1715EFEA573E4F52AF5D4FC9F28A2D613F5DB629C186C439E0 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
14:56:52.0919 0x01f8 IpNat - ok
14:56:52.0969 0x01f8 [ 23C74D75E36E7158768DD63D92789A91, 394D296F38E7D8EFD91A6EEC301D9CE6AF910E35EB9819F1A9E3363863AEDFDC ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
14:56:53.0009 0x01f8 IPSec - ok
14:56:53.0069 0x01f8 [ ACA5E7B54409F9CB5EED97ED0C81120E, 1E22F442EA77596F58D133F1A5887CDC4F3325DD0836D24A665E1D31287ABFF7 ] irda C:\WINDOWS\system32\DRIVERS\irda.sys
14:56:53.0099 0x01f8 irda - ok
14:56:53.0169 0x01f8 [ C93C9FF7B04D772627A3646D89F7BF89, 805FA48E7A46D4F10240BF880A2468F53DEA36E83004399228AB70DB7D20544A ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
14:56:53.0189 0x01f8 IRENUM - ok
14:56:53.0269 0x01f8 [ 49CC4533CE897CB2E93C1E84A818FDE5, F2AC81CDB971F630699616509748DCE133874EFC79B9D6230517B5A4DFBE193D ] Irmon C:\WINDOWS\System32\irmon.dll
14:56:53.0309 0x01f8 Irmon - ok
14:56:53.0389 0x01f8 [ 05A299EC56E52649B1CF2FC52D20F2D7, 2654619DB3E6D6C385B63AB02F87D4241C4F0250CC31383D1B3586917166C2DC ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
14:56:53.0429 0x01f8 isapnp - ok
14:56:53.0660 0x01f8 [ DBDB1A25291B2D18C614F5CA963156A8, C8EA730A6A5BCBE7952AAA22F212C244014F206D2F4A274E29384C09F1F10A66 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
14:56:53.0670 0x01f8 JavaQuickStarterService - ok
14:56:53.0720 0x01f8 [ 463C1EC80CD17420A542B7F36A36F128, E3B11BA26AFEAFB50B0FC168EA07F6049DA6B88BCDDEEE20310602D7FC27A3A7 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
14:56:53.0740 0x01f8 Kbdclass - ok
14:56:53.0810 0x01f8 [ 692BCF44383D056AED41B045A323D378, 1A99DEE83FFAF64E73067FC049C0A4CE07D94E4AE31EFA17B38CEFA9E41D67DC ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
14:56:53.0820 0x01f8 kmixer - ok
14:56:53.0920 0x01f8 [ B467646C54CC746128904E1654C750C1, 3BD71BE3663EA23463D236D8A2A2E42DFA10C502BDB4B6E131FAF0FBA748219E ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
14:56:53.0960 0x01f8 KSecDD - ok
14:56:54.0050 0x01f8 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527, 0044F03132596A494448CCE5F3D6ECC12617BB4CF6BAE348F79D4DC40ACD6EE0 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
14:56:54.0060 0x01f8 lanmanserver - ok
14:56:54.0160 0x01f8 [ A8888A5327621856C0CEC4E385F69309, B08B63300D824E35E31EEEA2C4C086DFA2C2A964CEDAE512E74D3D88AADAA2C1 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
14:56:54.0170 0x01f8 lanmanworkstation - ok
14:56:54.0200 0x01f8 lbrtfdc - ok
14:56:54.0361 0x01f8 [ 31D8B705DCD5F2366186E731F87C7A71, D73DC732EF74C3C0EADD650B65BC6EEB44EA2C4E86BFD5BE989971A34FBA160A ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
14:56:54.0371 0x01f8 LightScribeService - ok
14:56:54.0451 0x01f8 [ A7DB739AE99A796D91580147E919CC59, EDF4E039BA277B0E6D66FEB0B28096E67D682C09DFC18ECECF062D9DCFB75ACF ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
14:56:54.0461 0x01f8 LmHosts - ok
14:56:54.0531 0x01f8 [ 986B1FF5814366D71E0AC5755C88F2D3, E6AF051174531C24B38E73987755D366ABEC595476C6D17793E8DCCC73F55340 ] Messenger C:\WINDOWS\System32\msgsvc.dll
14:56:54.0561 0x01f8 Messenger - ok
14:56:54.0631 0x01f8 [ 4AE068242760A1FB6E1A44BF4E16AFA6, 1FB771162B96AAF787AC24867B818DF8511F0780BB094FA9A38C11D8DBFE68BC ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
14:56:54.0651 0x01f8 mnmdd - ok
14:56:54.0721 0x01f8 [ D18F1F0C101D06A1C1ADF26EED16FCDD, BA0837C7780BD8262E143E2935AFA63BE59C3C39EF56CB8608EED0F50AF070D4 ] mnmsrvc C:\WINDOWS\System32\mnmsrvc.exe
14:56:54.0761 0x01f8 mnmsrvc - ok
14:56:54.0821 0x01f8 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1, B342CC9EC3729AB1AB4B5E2E99F890C1E0CA649162DE91F6768AB857B719E97B ] Modem C:\WINDOWS\system32\drivers\Modem.sys
14:56:54.0831 0x01f8 Modem - ok
14:56:54.0881 0x01f8 [ 35C9E97194C8CFB8430125F8DBC34D04, 0C0FCE6B0A23FB0ECB92E1663E1C72D2DD5B177D82E04782957690B69530DB39 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
14:56:54.0911 0x01f8 Mouclass - ok
14:56:54.0992 0x01f8 [ B1C303E17FB9D46E87A98E4BA6769685, 161A45488522055D0F0474ABEDA04DDD0B5DAC2411AF9154B15190BBD66E7153 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
14:56:55.0042 0x01f8 mouhid - ok
14:56:55.0152 0x01f8 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD, 2A5E15ED2C24C6C65EF2F7E1FD93374774076C9D8D451E4422561F4D269C012F ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
14:56:55.0182 0x01f8 MountMgr - ok
14:56:55.0212 0x01f8 mraid35x - ok
14:56:55.0252 0x01f8 [ 11D42BB6206F33FBB3BA0288D3EF81BD, 76ABCFB62C5AC549F58C231F72A99882CDEB74928104B77FE52554765C2B1A22 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
14:56:55.0262 0x01f8 MRxDAV - ok
14:56:55.0492 0x01f8 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0, DB9B186F7076D7B94F45041AF7B77C1AD2CAB504D683B459C6CB1C22840ED170 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
14:56:55.0562 0x01f8 MRxSmb - ok
14:56:55.0633 0x01f8 [ A137F1470499A205ABBB9AAFB3B6F2B1, FB4951727543030D9E6ED74149C3FAACE2CA9DA8C1B5F616301B30B858C724E8 ] MSDTC C:\WINDOWS\System32\msdtc.exe
14:56:55.0673 0x01f8 MSDTC - ok
14:56:55.0743 0x01f8 [ C941EA2454BA8350021D774DAF0F1027, C940E978C7B66A713A0FDAB54B5F995DF59D089AFCD96221DD3222948CD49BBD ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
14:56:55.0763 0x01f8 Msfs - ok
14:56:55.0793 0x01f8 MSIServer - ok
14:56:55.0853 0x01f8 [ D1575E71568F4D9E14CA56B7B0453BF1, 4ABE0E24786C0D39FA2B885447E56204CA6942FB175E534DCE675D7BCF0B176A ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
14:56:55.0873 0x01f8 MSKSSRV - ok
14:56:55.0943 0x01f8 [ 325BB26842FC7CCC1FCCE2C457317F3E, C07BE560513B1FB91D756494F0BA4AEEB2E1998DE0E1C21EE83DB1183B0CEE91 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
14:56:55.0973 0x01f8 MSPCLOCK - ok
14:56:56.0023 0x01f8 [ BAD59648BA099DA4A17680B39730CB3D, 9AD4C7C94C186C8815D0BC75DCAFB962158DA6935A244BA243EDDDEB33F9816C ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
14:56:56.0073 0x01f8 MSPQM - ok
14:56:56.0243 0x01f8 [ AF5F4F3F14A8EA2C26DE30F7A1E17136, AC93A1E4ABB0D038B772E429015567E44CC2EDB66C54DBE23A5F98176FAC1520 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
14:56:56.0253 0x01f8 mssmbios - ok
14:56:56.0334 0x01f8 [ DE6A75F5C270E756C5508D94B6CF68F5, FCC972DDC36C2C44D836913F10004C2C33B11C54DEFFF0C63E0FDF901D2F9261 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
14:56:56.0364 0x01f8 Mup - ok
14:56:56.0584 0x01f8 [ 0102140028FAD045756796E1C685D695, 5335B8278418CA200E2772124F0602C3E15A5CAF2D5CC59F6785DFAABF339B09 ] napagent C:\WINDOWS\System32\qagentrt.dll
14:56:56.0664 0x01f8 napagent - ok
14:56:56.0744 0x01f8 [ 1DF7F42665C94B825322FAE71721130D, FE0DCB728471465B39A42A7511F4133021FBA5DF88F88BCB5FE2FF34CFD713F9 ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
14:56:56.0794 0x01f8 NDIS - ok
14:56:56.0864 0x01f8 [ 0109C4F3850DFBAB279542515386AE22, 4F6DB1E499AC853FD36FD603FBB6D3AC9BDCEB298C7FE1FB59A9236CB46729B2 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
14:56:56.0894 0x01f8 NdisTapi - ok
14:56:57.0004 0x01f8 [ F927A4434C5028758A842943EF1A3849, B1AA3AF150C05307461774925901789456B0CCCD03A5E71ADA4AB58455962BEE ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
14:56:57.0004 0x01f8 Ndisuio - ok
14:56:57.0075 0x01f8 [ EDC1531A49C80614B2CFDA43CA8659AB, 494042F790F33721328B4451E79842E21919681CC421A4F9633EC4D383E06097 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
14:56:57.0125 0x01f8 NdisWan - ok
14:56:57.0285 0x01f8 [ 9282BD12DFB069D3889EB3FCC1000A9B, 09A46F1712BD9165068D8E153585FE3E6E5CBF4F1DDEC142115555D3A91AEC09 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
14:56:57.0315 0x01f8 NDProxy - ok
14:56:57.0385 0x01f8 [ 5D81CF9A2F1A3A756B66CF684911CDF0, 7989C36607CAEA17AFA2C1C9904145CA0714A54B9F712D9D4C1AB140D0B2CC0C ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
14:56:57.0415 0x01f8 NetBIOS - ok
14:56:57.0565 0x01f8 [ 74B2B2F5BEA5E9A3DC021D685551BD3D, 7932B71F98B4122BE88F576BF6D745A757AE378A48924B7F4358837B75640A82 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
14:56:57.0625 0x01f8 NetBT - ok
14:56:57.0716 0x01f8 [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDE C:\WINDOWS\system32\netdde.exe
14:56:57.0756 0x01f8 NetDDE - ok
14:56:57.0786 0x01f8 [ B857BA82860D7FF85AE29B095645563B, 86FF0E4CDD9C394E8BABD93A4D57E73FF9A779261717DEC6E9CDE99F1C6B0F4C ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
14:56:57.0796 0x01f8 NetDDEdsdm - ok
14:56:57.0866 0x01f8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] Netlogon C:\WINDOWS\System32\lsass.exe
14:56:57.0896 0x01f8 Netlogon - ok
14:56:57.0966 0x01f8 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE, 4E0A67B3CC897E80D4B342FFE8B7B4CC4F6CA2EF2D34C136027A098B2E1C6166 ] Netman C:\WINDOWS\System32\netman.dll
14:56:57.0976 0x01f8 Netman - ok
14:56:58.0306 0x01f8 [ D34612C5D02D026535B3095D620626AE, 1BBCCCBF49EB8807240A77DCB43C25C21682073CC5356594E2C4F53EF36BF657 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
14:56:58.0747 0x01f8 NetTcpPortSharing - ok
14:56:58.0917 0x01f8 [ 943337D786A56729263071623BBB9DE5, B631B47C869FE4ACF46E4AA272435D9A9CA536E3349E3FFBB8602636FEE7AFD4 ] Nla C:\WINDOWS\System32\mswsock.dll
14:56:58.0937 0x01f8 Nla - ok
14:56:59.0017 0x01f8 NMIndexingService - ok
14:56:59.0268 0x01f8 [ 3182D64AE053D6FB034F44B6DEF8034A, 4ADFC76965BA2A5F488E71789A4E4EA702A74AF42725F72130D1CA919406CF19 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
14:56:59.0298 0x01f8 Npfs - ok
14:56:59.0338 0x01f8 [ 2ADC0CA9945C65284B3D19BC18765974, A8E2B848E85A3B38350F4134DE9CA6749854B988F9A0087C60D97E19D474CBF3 ] NSCIRDA C:\WINDOWS\system32\DRIVERS\nscirda.sys
14:56:59.0358 0x01f8 NSCIRDA - ok
14:56:59.0588 0x01f8 [ 78A08DD6A8D65E697C18E1DB01C5CDCA, E0E6F3ED05068E32F1D5C2D2B38CDEF4536B8656DB6756C66CF6B40B60C8F3DA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
14:56:59.0648 0x01f8 Ntfs - ok
14:56:59.0708 0x01f8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] NtLmSsp C:\WINDOWS\System32\lsass.exe
14:56:59.0718 0x01f8 NtLmSsp - ok
14:56:59.0869 0x01f8 [ 156F64A3345BD23C600655FB4D10BC08, 9611BE411586E068D9297D77102DB3BE48AA67F1BAD6F61A84F83FC3043FA9CD ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
14:56:59.0959 0x01f8 NtmsSvc - ok
14:57:00.0019 0x01f8 [ 73C1E1F395918BC2C6DD67AF7591A3AD, B21133A75253EC15E2DFF66D3B480AB1A7E1A2360476C810E7AA55D0F0EB08D4 ] Null C:\WINDOWS\system32\drivers\Null.sys
14:57:00.0049 0x01f8 Null - ok
14:57:00.0159 0x01f8 [ B305F3FAD35083837EF46A0BBCE2FC57, 9D0E0E666D652D0FC9EAB97280A5D67AAF61D6B21929DF7CF8ED72A367720464 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
14:57:00.0189 0x01f8 NwlnkFlt - ok
14:57:00.0219 0x01f8 [ C99B3415198D1AAB7227F2C88FD664B9, DD8DA4B5E804F134AB9233859544C025062902DFC3E8FB8A09A67337A4E73F55 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
14:57:00.0249 0x01f8 NwlnkFwd - ok
14:57:00.0329 0x01f8 [ 5575FAF8F97CE5E713D108C2A58D7C7C, 96D4595D19A78CCBE8B325A08780AC077AE5CC99642ACD72FB47AEAE8D344D3B ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
14:57:00.0359 0x01f8 Parport - ok
14:57:00.0409 0x01f8 [ BEB3BA25197665D82EC7065B724171C6, 7E71C13BA30CD95CEE8A9CC85E6F48A01F30EDEAADEE69D80AE828BF97E5A5CA ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
14:57:00.0429 0x01f8 PartMgr - ok
14:57:00.0469 0x01f8 [ 70E98B3FD8E963A6A46A2E6247E0BEA1, 6771313EC41B3B5BFD398F60706E40BE71617046880CC352DD110B001AFC22A1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
14:57:00.0469 0x01f8 ParVdm - ok
14:57:00.0500 0x01f8 [ A219903CCF74233761D92BEF471A07B1, D4E6C360A1D2FCA4D17C991B834D68BF20F5111DD06B1FAB8B22984804CEC269 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
14:57:00.0570 0x01f8 PCI - ok
14:57:00.0600 0x01f8 PCIDump - ok
14:57:00.0630 0x01f8 PCIIde - ok
14:57:00.0700 0x01f8 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1, 0BA3DB21DC7C641C181E2635B5C9B73965FDCDCD3EBBBE48FCFEC1C8C987F617 ] Pcmcia C:\WINDOWS\system32\DRIVERS\pcmcia.sys
14:57:00.0740 0x01f8 Pcmcia - ok
14:57:00.0760 0x01f8 PDCOMP - ok
14:57:00.0780 0x01f8 PDFRAME - ok
14:57:00.0830 0x01f8 PDRELI - ok
14:57:00.0880 0x01f8 PDRFRAME - ok
14:57:00.0920 0x01f8 perc2 - ok
14:57:00.0980 0x01f8 perc2hib - ok
14:57:01.0090 0x01f8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] PlugPlay C:\WINDOWS\system32\services.exe
14:57:01.0160 0x01f8 PlugPlay - ok
14:57:01.0221 0x01f8 [ FA292805788528C083F416E151B60AB6, CF47525D15FF3FF98768FF5AE8A8F0C01AE6300C249D24E518D2A02100D5A68A ] PMEM C:\WINDOWS\system32\drivers\PMEMNT.SYS
14:57:01.0221 0x01f8 PMEM - ok
14:57:01.0261 0x01f8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] PolicyAgent C:\WINDOWS\System32\lsass.exe
14:57:01.0271 0x01f8 PolicyAgent - ok
14:57:01.0361 0x01f8 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99, C5F0C8C66A3AF7E7BB04CEDE4AC5306F8387AB384A2107DC5BE413AAE968EFF1 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
14:57:01.0401 0x01f8 PptpMiniport - ok
14:57:01.0441 0x01f8 [ A32BEBAF723557681BFC6BD93E98BD26, 35039BA72A29F87B2CA37DCDE4EFDAABBDEAD8CE3EB8652ACC665994118145A6 ] Processor C:\WINDOWS\system32\DRIVERS\processr.sys
14:57:01.0471 0x01f8 Processor - ok
14:57:01.0511 0x01f8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
14:57:01.0511 0x01f8 ProtectedStorage - ok
14:57:01.0571 0x01f8 [ 09298EC810B07E5D582CB3A3F9255424, 35473A1BE25AC289474090EB0806AC6B3035DC33D1F3DF97A14BF1E361AC6AC3 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
14:57:01.0601 0x01f8 PSched - ok
14:57:01.0691 0x01f8 [ 80D317BD1C3DBC5D4FE7B1678C60CADD, DA76804B55D0CAB3DDD01EFC06673764AE4860693375C658B6063FB14AF7F12C ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
14:57:01.0721 0x01f8 Ptilink - ok
14:57:01.0831 0x01f8 [ 1BCFED0946F9460D6272F85B70B87A52, 6EDE283D9B5173D9F91C969E5F97A21282395769C989F609B1EFDE7B5E40EA97 ] QCONSVC C:\WINDOWS\system32\QCONSVC.EXE
14:57:01.0831 0x01f8 QCONSVC - ok
14:57:01.0871 0x01f8 ql1080 - ok
14:57:01.0902 0x01f8 Ql10wnt - ok
14:57:01.0932 0x01f8 ql12160 - ok
14:57:01.0962 0x01f8 ql1240 - ok
14:57:01.0992 0x01f8 ql1280 - ok
14:57:02.0052 0x01f8 [ FE0D99D6F31E4FAD8159F690D68DED9C, 998685622ABE631984B7E4DBF91AB3594B1F574378D75EB9F6265F4650470692 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
14:57:02.0092 0x01f8 RasAcd - ok
14:57:02.0232 0x01f8 [ AD188BE7BDF94E8DF4CA0A55C00A5073, C7D76CB579FAEBCCC2873499441BACDD6BD6668ACF5ED7F31862656E96E2B20C ] RasAuto C:\WINDOWS\System32\rasauto.dll
14:57:02.0272 0x01f8 RasAuto - ok
14:57:02.0352 0x01f8 [ 0207D26DDF796A193CCD9F83047BB5FC, 13613036BCB869FBD7229A0FE25D324710308385D8C35E5D990A40E52BE040DF ] Rasirda C:\WINDOWS\system32\DRIVERS\rasirda.sys
14:57:02.0392 0x01f8 Rasirda - ok
14:57:02.0442 0x01f8 [ 11B4A627BC9614B885C4969BFA5FF8A6, EAE0A412A2B0F68919C32A96B3A08CC1A06585E4998819F5C9051745F63FF5AD ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
14:57:02.0472 0x01f8 Rasl2tp - ok
14:57:02.0613 0x01f8 [ 76A9A3CBEADD68CC57CDA5E1D7448235, 4AFD048C5D2306AB8DE46F3AA60AC0213333DDA3B09A9E91F7585DB6EB978EC8 ] RasMan C:\WINDOWS\System32\rasmans.dll
14:57:02.0623 0x01f8 RasMan - ok
14:57:02.0673 0x01f8 [ 5BC962F2654137C9909C3D4603587DEE, A5CE5653D0105240F5E86CFAAB89E7917D42D939E2F27A5A7D6979289CA651B8 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
14:57:02.0703 0x01f8 RasPppoe - ok
14:57:02.0803 0x01f8 [ FDBB1D60066FCFBB7452FD8F9829B242, 10A2DACF944BD000032EBA8C095CB3D879CC55B28C377ADF6E52E508E47444DB ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
14:57:02.0843 0x01f8 Raspti - ok
14:57:02.0943 0x01f8 [ 7AD224AD1A1437FE28D89CF22B17780A, 6645235CA27D671954E3557FA37082881C3D7D47492C71264CD8CB8D108EC801 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
14:57:02.0983 0x01f8 Rdbss - ok
14:57:03.0023 0x01f8 [ 4912D5B403614CE99C28420F75353332, 975341ECD660209987B5E5171B8315E032439E408CBE8A5986E67AF767F373BB ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
14:57:03.0053 0x01f8 RDPCDD - ok
14:57:03.0183 0x01f8 [ 15CABD0F7C00C47C70124907916AF3F1, 66B5C978B7FB6359AD8BAC9F568FE9D469E358FEAB07B1F129BA9E85F1DF723E ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
14:57:03.0213 0x01f8 rdpdr - ok
14:57:03.0314 0x01f8 [ 43AF5212BD8FB5BA6EED9754358BD8F7, AF330F61CECA4AFA359CEABC5EB3227E6B56A9A2DCE50701381D665122D7356D ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
14:57:03.0364 0x01f8 RDPWD - ok
14:57:03.0464 0x01f8 [ 3C37BF86641BDA977C3BF8A840F3B7FA, AB9A6E54DBA3F4561CD4837372BECCE0D73943D02E3288F944333039375AC08C ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
14:57:03.0514 0x01f8 RDSessMgr - ok
14:57:03.0564 0x01f8 [ F828DD7E1419B6653894A8F97A0094C5, E6150E1F598BA4CFEDB8FF075BC0D576518C331B864388F1CAE8812EFF106ECF ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
14:57:03.0594 0x01f8 redbook - ok
14:57:03.0654 0x01f8 [ 7E699FF5F59B5D9DE5390E3C34C67CF5, 3FCF0442D80AB181FED4303E570378736AA1F8718C0B8B70F689A1E45200FFE4 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
14:57:03.0714 0x01f8 RemoteAccess - ok
14:57:03.0794 0x01f8 [ 5B19B557B0C188210A56A6B699D90B8F, 0FA880B81AE615206FD1738B83428AAA491D54B24168339DE6E87FDE8C6C14B0 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
14:57:03.0804 0x01f8 RemoteRegistry - ok
14:57:03.0884 0x01f8 [ AAED593F84AFA419BBAE8572AF87CF6A, CC0FFC5A69394C8830DC66320DA01A820BBF41AD7E57D0FC343561DC5EF9A360 ] RpcLocator C:\WINDOWS\System32\locator.exe
14:57:03.0934 0x01f8 RpcLocator - ok
14:57:04.0245 0x01f8 [ 6B27A5C03DFB94B4245739065431322C, 6AEAC16AB4E0DFD25123AAF4D4181FEE1B919B7B2793117006CE8CF30E826CFD ] RpcSs C:\WINDOWS\system32\rpcss.dll
14:57:04.0265 0x01f8 RpcSs - ok
14:57:04.0405 0x01f8 [ 471B3F9741D762ABE75E9DEEA4787E47, D9ADE42965EC22AEB4B2AD21D429C3C8232A60AA9853DEFDA7AED86A13FE8623 ] RSVP C:\WINDOWS\System32\rsvp.exe
14:57:04.0465 0x01f8 RSVP - ok
14:57:04.0575 0x01f8 [ 88B63F291AE10C1B66D2B9ED6921A7DF, A0174FC75459CE38028B1436BD46234062A3FCBE164E139F53BE49BAB3B8F95F ] rtl8185 C:\WINDOWS\system32\DRIVERS\rtl8185.sys
14:57:04.0605 0x01f8 rtl8185 - ok
14:57:04.0645 0x01f8 [ BF2466B3E18E970D8A976FB95FC1CA85, F7794B5D12DC5D820A162850F4388E2AA80426AD07CB221799CF941C682AB501 ] SamSs C:\WINDOWS\system32\lsass.exe
14:57:04.0655 0x01f8 SamSs - ok
14:57:04.0736 0x01f8 [ 86D007E7A654B9A71D1D7D856B104353, 7B1DE53D637A5FC9619D5D07C48927AFEC89D959207F6F2E2F45DD054EEA04C7 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
14:57:04.0786 0x01f8 SCardSvr - ok
14:57:04.0886 0x01f8 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA, 0B582F47BD70732BAC48B8B86E5D06CE7F299A20E8177F3F2E6F28217C3FB605 ] Schedule C:\WINDOWS\system32\schedsvc.dll
14:57:04.0896 0x01f8 Schedule - ok
14:57:04.0976 0x01f8 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
14:57:05.0006 0x01f8 Secdrv - ok
14:57:05.0056 0x01f8 [ CBE612E2BB6A10E3563336191EDA1250, C331797DC3569F0E715766561DE2562F60B924378842246C35D2B1CF867E9D96 ] seclogon C:\WINDOWS\System32\seclogon.dll
14:57:05.0066 0x01f8 seclogon - ok
14:57:05.0186 0x01f8 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0, 7105B026F966A992430F86C3698ABE15EC73E4772F1A3E362E29FD5247A5DCA6 ] SENS C:\WINDOWS\system32\sens.dll
14:57:05.0196 0x01f8 SENS - ok
14:57:05.0266 0x01f8 [ 0F29512CCD6BEAD730039FB4BD2C85CE, 4F98AE390D1B14A755700DD6CEFB9CF921F0404AF2145D2D7E5F52394F87C6A5 ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
14:57:05.0286 0x01f8 serenum - ok
14:57:05.0346 0x01f8 [ CCA207A8896D4C6A0C9CE29A4AE411A7, 5999B39242283CD803319AADCA171CCCC6E2A40FB2FAFA51B1D29F3FF2DD8D6C ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
14:57:05.0397 0x01f8 Serial - ok
14:57:05.0487 0x01f8 [ 8E6B8C671615D126FDC553D1E2DE5562, CEEC0067514555D5CA489F50E3D7562FCA8DB8E952C3C878604C9277FC77959F ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
14:57:05.0517 0x01f8 Sfloppy - ok
14:57:05.0657 0x01f8 [ 83F41D0D89645D7235C051AB1D9523AC, B681F33EEAA511D6A2DCB9FBAA407B739184C9FF6067C6B7E51F1FC37E9D4DD7 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
14:57:05.0677 0x01f8 SharedAccess - ok
14:57:05.0747 0x01f8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
14:57:05.0757 0x01f8 ShellHWDetection - ok
14:57:05.0787 0x01f8 Simbad - ok
14:57:05.0817 0x01f8 SjyPkt - ok
14:57:05.0857 0x01f8 [ E061A9A43C80BE5AA5D94F1EF4A713C1, 334CD9E8C4A57C2BF43A0D3895D18832C7EB0C5A6455CF3361A09F7A28DF4A6F ] Smapint C:\WINDOWS\system32\drivers\Smapint.sys
14:57:05.0887 0x01f8 Smapint - ok
14:57:06.0058 0x01f8 [ 7B06A22F16B64C23C41E0278B8DC90BF, 02867493783DAC96A90B6CD14B358C05C63FE0862A98BD71CD54F34E31632C54 ] smwdm C:\WINDOWS\system32\drivers\smwdm.sys
14:57:06.0128 0x01f8 smwdm - ok
14:57:06.0158 0x01f8 Sparrow - ok
14:57:06.0578 0x01f8 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F, DD17733CBB370FCA08F0296704D7CBEACA3C8F76D0ABE4761C3B1FFDF7481D9E ] splitter C:\WINDOWS\system32\drivers\splitter.sys
14:57:06.0578 0x01f8 splitter - ok
14:57:06.0668 0x01f8 [ 60784F891563FB1B767F70117FC2428F, E0B07F08E60FFBAD36C2E58180F4B2A16DCA47716044CBE0213DF7B74D742F1F ] Spooler C:\WINDOWS\system32\spoolsv.exe
14:57:06.0678 0x01f8 Spooler - ok
14:57:06.0789 0x01f8 [ 76BB022C2FB6902FD5BDD4F78FC13A5D, 6031CB2344D7277FC703480EB43CF856A0F8F818EA98FF26A2CA532336CD2DFA ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
14:57:06.0989 0x01f8 sr - ok
14:57:07.0089 0x01f8 [ 3805DF0AC4296A34BA4BF93B346CC378, B57A14F1B7B0997E619DDD62B73157AA2399A9852166FB58139CBB358A88F6F3 ] srservice C:\WINDOWS\System32\srsvc.dll
14:57:07.0109 0x01f8 srservice - ok
14:57:07.0319 0x01f8 [ 47DDFC2F003F7F9F0592C6874962A2E7, 17C643BD4EB09B5666FE41817DC785BE04A6E491CE79E8E5A702CDBD98E1BDD7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
14:57:07.0339 0x01f8 Srv - ok
14:57:07.0419 0x01f8 [ 0A5679B3714EDAB99E357057EE88FCA6, 01E1A101FFF48402C77E385A78FEF27876E04533B60EB1C18558A737E57E5FA8 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
14:57:07.0429 0x01f8 SSDPSRV - ok
14:57:07.0560 0x01f8 [ 8BAD69CBAC032D4BBACFCE0306174C30, 2AA0DA710FCBFF38FE8DA91EE02E7A4503269347E61F8D3246FCA3384BBA2305 ] stisvc C:\WINDOWS\system32\wiaservc.dll
14:57:07.0590 0x01f8 stisvc - ok
14:57:07.0660 0x01f8 [ 3941D127AEF12E93ADDF6FE6EE027E0F, EA1F0E32E1C5E90FA4AAC421DEBBE086512340758D3217A6334E886BCE638B51 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
14:57:07.0690 0x01f8 swenum - ok
14:57:07.0800 0x01f8 [ 8CE882BCC6CF8A62F2B2323D95CB3D01, B408550A581F3DA222355964AFA4E976AD8471F0AA37573C42C4948AE5A23A3B ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
14:57:07.0800 0x01f8 swmidi - ok
14:57:07.0840 0x01f8 SwPrv - ok
14:57:07.0890 0x01f8 symc810 - ok
14:57:07.0930 0x01f8 symc8xx - ok
14:57:07.0960 0x01f8 sym_hi - ok
14:57:07.0990 0x01f8 sym_u3 - ok
14:57:08.0050 0x01f8 [ 8B83F3ED0F1688B4958F77CD6D2BF290, 546D3602183702B4F53E84413CFA2C933D64C8540378E54A8DCD148F3F36A2DA ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
14:57:08.0050 0x01f8 sysaudio - ok
14:57:08.0070 0x01f8 Suspicious service (NoAccess): syshost32
14:57:08.0271 0x01f8 [ E48A91AC570F9A683CBCFE94C59DCB18, 9BDDEAD3900F28BEE90F5DAB2354E8136613E729F3E07193411F00E07A1040CC ] syshost32 C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe
14:57:08.0281 0x01f8 Suspicious file ( NoAccess ): C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe. md5: E48A91AC570F9A683CBCFE94C59DCB18, sha256: 9BDDEAD3900F28BEE90F5DAB2354E8136613E729F3E07193411F00E07A1040CC
14:57:09.0863 0x01f8 syshost32 - detected Rootkit.Win32.Necurs.gen ( 0 )
14:57:12.0817 0x01f8 syshost32 ( Rootkit.Win32.Necurs.gen ) - infected
14:57:12.0817 0x01f8 Force sending object to P2P due to detect: syshost32
14:57:15.0371 0x01f8 Object send P2P result: true
14:57:17.0874 0x01f8 [ C7ABBC59B43274B1109DF6B24D617051, 4384CA0AA6CE9B603CF7DB775A3C721E46715D5B120B94FB57DEADAADE18535B ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
14:57:17.0925 0x01f8 SysmonLog - ok
14:57:18.0115 0x01f8 [ 3CB78C17BB664637787C9A1C98F79C38, F35C31F6B7F366CB949D1044B357C76DEC9170441C5E559802794F62B72FD255 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
14:57:18.0145 0x01f8 TapiSrv - ok
14:57:18.0345 0x01f8 [ 9AEFA14BD6B182D61E3119FA5F436D3D, EA29E49434585409272E7901AF89771FE9D6E911A7DC44AB3C7020CFF8A44552 ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
14:57:18.0365 0x01f8 Tcpip - ok
14:57:18.0445 0x01f8 [ 6471A66807F5E104E4885F5B67349397, F35CBFFB8BB235CCE30EF94A5273333900DD49FD506BF9D55D99A320B8A53A5A ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
14:57:18.0445 0x01f8 TDPIPE - ok
14:57:18.0505 0x01f8 [ 0353AC9D91E28D936E4227539B1B2393, 8B31C2F496C446DF69B898B9B585A1097DDCA3EE50ACD31B5E09D8B1CD68DF94 ] TDSMAPI C:\WINDOWS\system32\Drivers\TDSMAPI.SYS
14:57:18.0505 0x01f8 TDSMAPI - ok
14:57:18.0565 0x01f8 [ C56B6D0402371CF3700EB322EF3AAF61, 7743FA4C734BCE38EFB1CA69BC17364D8421E2CD172F856F7E38E7AE1EE93F2F ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
14:57:18.0565 0x01f8 TDTCP - ok
14:57:18.0626 0x01f8 [ 88155247177638048422893737429D9E, B6D4E8691917946332C2208D01F8C8281978C1AD1E9951C5D99DF0D49AC34B3B ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
14:57:18.0636 0x01f8 TermDD - ok
14:57:18.0786 0x01f8 [ FF3477C03BE7201C294C35F684B3479F, D6246521539BA4ACD022D26983182F5E323D2EF1EA7C54265A248C43A1CE5202 ] TermService C:\WINDOWS\System32\termsrv.dll
14:57:18.0846 0x01f8 TermService - ok
14:57:18.0986 0x01f8 [ 99BC0B50F511924348BE19C7C7313BBF, A1006C687BD352F700B140DC741515A0CDD9E1352C0FBD1EE410D404E344444B ] Themes C:\WINDOWS\System32\shsvcs.dll
14:57:18.0996 0x01f8 Themes - ok
14:57:19.0086 0x01f8 [ DB7205804759FF62C34E3EFD8A4CC76A, 13A4248F528CE98ACA66898E56822E4FC49B11F491FF1F61A687BA601BF0A802 ] TlntSvr C:\WINDOWS\System32\tlntsvr.exe
14:57:19.0146 0x01f8 TlntSvr - ok
14:57:19.0166 0x01f8 TosIde - ok
14:57:19.0226 0x01f8 [ 90579B74E1E110C2F379117047BDB356, EDD255C1A104DA6469846A4B4CDBFC5CB40DCD69DDE5207D799FB7DC850A014A ] Tp4Track C:\WINDOWS\system32\DRIVERS\tp4track.sys
14:57:19.0226 0x01f8 Tp4Track - ok
14:57:19.0266 0x01f8 [ 47F23B26F771765FD8CAC0EBAE4545E9, 2AFE4C57FE833F18E65F959DAF8879823CE8BEB13B1BA34A61E6806AF609EDC5 ] TPHKDRV C:\WINDOWS\system32\drivers\TPHKDRV.sys
14:57:19.0266 0x01f8 TPHKDRV - ok
14:57:19.0287 0x01f8 [ C10B74CF569D39594E170734DB590661, 134890D6FAE83FA38F8EEA3B72EC0E12778D6E15C7605758D9933AA4A945E755 ] TPPWR C:\WINDOWS\system32\drivers\Tppwr.sys
14:57:19.0287 0x01f8 TPPWR - ok
14:57:19.0417 0x01f8 [ 55BCA12F7F523D35CA3CB833C725F54E, 849FB1AE31B143B14B298BBC0D91230693D41DEB95F46516878F53A7F4186C38 ] TrkWks C:\WINDOWS\system32\trkwks.dll
14:57:19.0427 0x01f8 TrkWks - ok
14:57:19.0487 0x01f8 [ 76F0A07D83FA24478C07250F4FC8B128, 4894CD9ABDDC9712D3D9938A66B9CD83485AEA7F0D351769D58AC80FA5885412 ] TSMAPIP C:\WINDOWS\system32\drivers\TSMAPIP.SYS
14:57:19.0487 0x01f8 TSMAPIP - ok
14:57:19.0537 0x01f8 [ 5787B80C2E3C5E2F56C2A233D91FA2C9, 3774905CF77954DFCECDA5BCC7CDE3D0ED72712BFAAD85ADAE5246306447E46C ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
14:57:19.0537 0x01f8 Udfs - ok
14:57:19.0607 0x01f8 ultra - ok
14:57:19.0737 0x01f8 [ 402DDC88356B1BAC0EE3DD1580C76A31, 32A686595710336A6BFD54C03F552AE39439611662F84EF5D24193AE5665C6F3 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
14:57:19.0767 0x01f8 Update - ok
14:57:19.0867 0x01f8 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91, 7746916DB48E3F5B243B63C066596AD9037A494BF1AD935946DD04AC85D983DF ] upnphost C:\WINDOWS\System32\upnphost.dll
14:57:19.0917 0x01f8 upnphost - ok
14:57:19.0968 0x01f8 [ 05365FB38FCA1E98F7A566AAAF5D1815, 16843048CEEC3DAA3B953A12FF1EE339E86783A08F2A56DA7F94AD9F9717D77D ] UPS C:\WINDOWS\System32\ups.exe
14:57:19.0998 0x01f8 UPS - ok
14:57:20.0068 0x01f8 [ 65DCF09D0E37D4C6B11B5B0B76D470A7, 90EBA8BAF45932B453D905EDF2BDDDF3A432BFD50B9F7DF58CDEAE98D11C2E2F ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
14:57:20.0068 0x01f8 usbehci - ok
14:57:20.0228 0x01f8 [ 1AB3CDDE553B6E064D2E754EFE20285C, A99C4528C4227B1E96847614745AAFACD3C5F1BDFE435214DBF78740FFB300FE ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
14:57:20.0228 0x01f8 usbhub - ok
14:57:20.0338 0x01f8 [ A0B8CF9DEB1184FBDD20784A58FA75D4, D8AFD45BD9CF7B02F2554AA6085194DE82893AF794EDF479BC9B9E9C1758DC75 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
14:57:20.0338 0x01f8 usbscan - ok
14:57:20.0428 0x01f8 [ A32426D9B14A089EAA1D922E0C5801A9, ED1DC52EE45F8EAD3AEC4B1F817BB25634141CF48295494C5947DCE6CF7A9817 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
14:57:20.0428 0x01f8 USBSTOR - ok
14:57:20.0478 0x01f8 [ 26496F9DEE2D787FC3E61AD54821FFE6, 8BE7FF647470B9A951CBB478FAF83D657A15CC78037F42348A6B738F21D523DA ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
14:57:20.0488 0x01f8 usbuhci - ok
14:57:20.0528 0x01f8 [ 0D3A8FAFCEACD8B7625CD549757A7DF1, B9CFDEFCD66AA139F3DC2F967B184669532922563AD5A71769BABDC4370D065E ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
14:57:20.0528 0x01f8 VgaSave - ok
14:57:20.0558 0x01f8 ViaIde - ok
14:57:20.0689 0x01f8 [ 4C8FCB5CC53AAB716D810740FE59D025, 010EAC43DBED700B73E4FC908FAAF9F6A0168EBBD5D86751E49BC33AAA18BFA4 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
14:57:20.0719 0x01f8 VolSnap - ok
14:57:20.0819 0x01f8 [ 7A9DB3A67C333BF0BD42E42B8596854B, D31A9A3B1AAAB373EDD73B674102395212FCB616F829E938B7B2B7BE7D4752C5 ] VSS C:\WINDOWS\System32\vssvc.exe
14:57:20.0899 0x01f8 VSS - ok
14:57:21.0029 0x01f8 [ 54AF4B1D5459500EF0937F6D33B1914F, FA1876888BCB9C72A92369DBED4FF1A8666784523FB41E618FA0919490FCDDB9 ] W32Time C:\WINDOWS\System32\w32time.dll
14:57:21.0049 0x01f8 W32Time - ok
14:57:21.0139 0x01f8 [ E20B95BAEDB550F32DD489265C1DA1F6, 5589B2067E6C9FBA290D8C5EADDC198EBAF39C50C3CD7D2BC5CDA7CBFBC445E5 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
14:57:21.0159 0x01f8 Wanarp - ok
14:57:21.0189 0x01f8 WDICA - ok
14:57:21.0259 0x01f8 [ 6768ACF64B18196494413695F0C3A00F, 3A8F8586F1D997D19A8478345338D2AECD785AEABDB61531DD3F92003D3230A5 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
14:57:21.0259 0x01f8 wdmaud - ok
14:57:21.0319 0x01f8 [ 77A354E28153AD2D5E120A5A8687BC06, 8B2D37A4443501C0A8E70BC2079BE27F0A36FD07B561E6F68B40A72EABBC2DFE ] WebClient C:\WINDOWS\System32\webclnt.dll
14:57:21.0329 0x01f8 WebClient - ok
14:57:21.0830 0x01f8 [ 2D0E4ED081963804CCC196A0929275B5, E1D75C7D7233D81DFDE13160B0C80138DF8B35230D04FB79B367A52FACF69BF8 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
14:57:21.0840 0x01f8 winmgmt - ok
14:57:21.0980 0x01f8 [ C51B4A5C05A5475708E3C81C7765B71D, F776D2680BD3407307B7072626F78460361FC5BC38623C9E16F394D300AB25DE ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
14:57:22.0020 0x01f8 WmdmPmSN - ok
14:57:22.0481 0x01f8 [ E76F8807070ED04E7408A86D6D3A6137, BFCF5361B7335760A7AE4B6958DE516A27AC60AA09135A46F0B49F588FAFE3A0 ] Wmi C:\WINDOWS\System32\advapi32.dll
14:57:22.0521 0x01f8 Wmi - ok
14:57:22.0641 0x01f8 [ E0673F1106E62A68D2257E376079F821, 12992F18C9653050B10DC61D12988067933FCFDF02123D3A7EF5DE607A785DDC ] WmiApSrv C:\WINDOWS\System32\wbem\wmiapsrv.exe
14:57:22.0701 0x01f8 WmiApSrv - ok
14:57:23.0102 0x01f8 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B, C71FAAC752F6D58BF8556661252DBF8C5DDD090CAE002A2C7E09C9A014526066 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
14:57:23.0673 0x01f8 WMPNetworkSvc - ok
14:57:23.0793 0x01f8 [ CF4DEF1BF66F06964DC0D91844239104, CC1D9CECE2056D29A9651D51BB57C3F4F9BF9E90A4808CF7496C683C874FBD51 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
14:57:23.0803 0x01f8 WpdUsb - ok
14:57:23.0883 0x01f8 [ 7C278E6408D1DCE642230C0585A854D5, DA46079A04F6E8E3441E4AE454AEAC02B3E935DE29CE7F6D4476F57867FCC12A ] wscsvc C:\WINDOWS\system32\wscsvc.dll
14:57:23.0883 0x01f8 wscsvc - ok
14:57:23.0993 0x01f8 [ 35321FB577CDC98CE3EB3A3EB9E4610A, C9A6F5CF282D8FCB3CDFCC4B306013480E78E1B664E1A60A4E27B161F9FFD4CD ] wuauserv C:\WINDOWS\system32\wuauserv.dll
14:57:24.0033 0x01f8 wuauserv - ok
14:57:24.0224 0x01f8 [ F15FEAFFFBB3644CCC80C5DA584E6311, 79B3E9AF35976CE49921E9BEA3BA3B4A8AF762FD3F284B62954038B5FFB32471 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
14:57:24.0224 0x01f8 WudfPf - ok
14:57:24.0284 0x01f8 [ 28B524262BCE6DE1F7EF9F510BA3985B, AEFF02B899801A63CBB262757C3D4369E38BFF0690BD085DE60E873DFBE3C3F4 ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
14:57:24.0294 0x01f8 WudfRd - ok
14:57:24.0354 0x01f8 [ 05231C04253C5BC30B26CBAAE680ED89, 5C03C2D7E0B573646D32F4093E2FF2C3BA391C39F5BA37D67F69D38E357FCC3D ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
14:57:24.0384 0x01f8 WudfSvc - ok
14:57:24.0674 0x01f8 [ 81DC3F549F44B1C1FFF022DEC9ECF30B, 3D14BFEA539F9CEB16555BD56C5E3C7C8F6692FC62C2789F8AAEA1C042E63940 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
14:57:24.0714 0x01f8 WZCSVC - ok
14:57:24.0865 0x01f8 [ 295D21F14C335B53CB8154E5B1F892B9, 9418477C2E3EA93E93D931A4EDD4500DA568FAD6040204B5201D1080203B0BBC ] xmlprov C:\WINDOWS\System32\xmlprov.dll
14:57:24.0915 0x01f8 xmlprov - ok
14:57:24.0955 0x01f8 ================ Scan global ===============================
14:57:25.0055 0x01f8 [ 42F1F4C0AFB08410E5F02D4B13EBB623, 924C30587C51C0D1E1F47991969AF492A644552E15F2480EA991DCB74A3E68D5 ] C:\WINDOWS\system32\basesrv.dll
14:57:25.0315 0x01f8 [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
14:57:25.0435 0x01f8 [ 69AE2B2E6968C316536E5B10B9702E63, D9C5DA7A20DDE69D91E72400C3F06F3CB099DEF42EA6C53FCE076258A0C22391 ] C:\WINDOWS\system32\winsrv.dll
14:57:25.0515 0x01f8 [ 65DF52F5B8B6E9BBD183505225C37315, 59C606977DB40A3443DFF0BE2A4C761824881B22C9FDB3D23F6486DB580E92A4 ] C:\WINDOWS\system32\services.exe
14:57:25.0525 0x01f8 [ Global ] - ok
14:57:25.0556 0x01f8 ================ Scan MBR ==================================
14:57:25.0596 0x01f8 [ AB67D479E4EE1CCAD757294B60DDB98F ] \Device\Harddisk0\DR0
14:57:27.0488 0x01f8 \Device\Harddisk0\DR0 - ok
14:57:27.0508 0x01f8 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
14:57:27.0528 0x01f8 \Device\Harddisk1\DR1 - ok
14:57:27.0548 0x01f8 ================ Scan VBR ==================================
14:57:27.0558 0x01f8 [ 4FDC23B120F0EC5F80AE98557F4D9DCB ] \Device\Harddisk0\DR0\Partition1
14:57:27.0558 0x01f8 \Device\Harddisk0\DR0\Partition1 - ok
14:57:27.0588 0x01f8 [ BDF83EFF05C13F2D4DA35EC086A7BB23 ] \Device\Harddisk1\DR1\Partition1
14:57:28.0289 0x01f8 \Device\Harddisk1\DR1\Partition1 - ok
14:57:28.0340 0x01f8 ================ Scan generic autorun ======================
14:57:28.0420 0x01f8 [ FAE95D6D7651B5629C4E19ADBC9A3863, 8209A13B8C845D8EFB1B1C21135B5119E6E2AC5694B982E2103E53D0CBAA080C ] C:\WINDOWS\system32\Ati2mdxx.exe
14:57:28.0420 0x01f8 ATIModeChange - ok
14:57:28.0520 0x01f8 [ 97826CB927E0E7F4500879D99DE6D3C5, 0FB04C5AA4C1BE2E35BBDE474916DF00E223A41D6E0C590FF0C5132EBBA69051 ] C:\WINDOWS\system32\tp4serv.exe
14:57:28.0560 0x01f8 TrackPointSrv - ok
14:57:28.0770 0x01f8 [ 71E256D5C8FB8FD1933968DCCFD967A0, 92481C790B092CC363BABEA16B0252BEEE1A7CBC1C6FF55F93030DD4AB92FA66 ] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
14:57:28.0800 0x01f8 TPTRAY - ok
14:57:28.0830 0x01f8 BMMGAG - ok
14:57:29.0141 0x01f8 [ 6C2CF216C460BED0D4B83AF07980A761, B8BF59F1F5937558B73F1D6728E92AE8B07CB38AD529357A4E16663A969A81BE ] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
14:57:29.0181 0x01f8 QCTRAY - ok
14:57:29.0281 0x01f8 [ 8633F1E7AA1912AD962E5A656D264045, BB17957ECE5EC9ED25E9B58315AD436C76B2FF1B5A1C5D8397FC7950CC65F126 ] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
14:57:29.0281 0x01f8 QCWLICON - ok
14:57:29.0401 0x01f8 [ AA3B957AF3F3B4AA9047D5531696AB0E, BA826D7A0B56C04528C4A8EDA498173C533BA3CDD75E1C73E224AFD712F06680 ] C:\WINDOWS\system32\tp4ex.exe
14:57:29.0411 0x01f8 TP4EX - ok
14:57:29.0581 0x01f8 [ 6CE63001262FB82D746E1DEEBF00B43B, B660ECA6989ABFC3B97FCEB8D692A11F77B9D4A81D5FC34759462D2EC37A2F63 ] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
14:57:29.0581 0x01f8 TPHOTKEY - ok
14:57:29.0651 0x01f8 Tgcmd - ok
14:57:29.0742 0x01f8 [ C0041BB27E2E5B0550C179ECF53425CD, 82EB1BF88B1D93F4AEC5EB6A1DB790E6EFA0379DD771251707BE9F67266D3547 ] C:\WINDOWS\AGRSMMSG.exe
14:57:36.0431 0x01f8 AGRSMMSG - ok
14:57:36.0531 0x01f8 [ 3E4C03CEFAD8DE135263236B61A49C90, 243201B64F4B60D55CDB1A3BF4B9AA60BC22EB8ACA88E95042EE48AC5DF5F397 ] C:\WINDOWS\system32\\NeroCheck.exe
14:57:36.0541 0x01f8 NeroCheck - ok
14:57:36.0692 0x01f8 [ E284188C5CF416378CC740EB13059A50, 0E0863D84B29662B3EEE0602742CAE8F966CE043E690C62BC3A00244B7D35D04 ] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
14:57:36.0692 0x01f8 Adobe Reader Speed Launcher - ok
14:57:37.0092 0x01f8 [ 29FB6EF1EFB1357E2883FE297F1EBC31, A6F465EA84277D88771BE6438CAC32D8E2C73A6EEC809CB38E1090FFFB27804E ] C:\PROGRA~1\AVG\AVG9\avgtray.exe
14:57:37.0222 0x01f8 AVG9_TRAY - ok
14:57:37.0543 0x01f8 [ 3103FE27C967675B019E880AA6DA3D6D, 515E750ACD28C3CFD8174B7F213E2AA741D8942FB68E57F701EBCBB92EC3F537 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
14:57:37.0603 0x01f8 Adobe ARM - ok
14:57:37.0823 0x01f8 [ 14D6542607ACD4B2D1DDB1A36E0D8813, 3A270600549E8E7988D5AF3486C0F504269B9573393D87BF87BDB2287BF007B2 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
14:57:37.0843 0x01f8 SunJavaUpdateSched - ok
14:57:37.0913 0x01f8 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3, 5FB24FC7916A6E6B3BE7D84CB1684215B266CD1495575C2E5672B8447932E5B1 ] C:\WINDOWS\system32\ctfmon.exe
14:57:37.0913 0x01f8 ctfmon.exe - ok
14:57:37.0943 0x01f8 updateMgr - ok
14:57:37.0973 0x01f8 MSMSGS - ok
14:57:37.0983 0x01f8 NeroHomeFirstStart - ok
14:57:38.0104 0x01f8 [ 269AFE2F2E2957DF8F7A5F82B2B092DB, 37B8B913090A01EC5C656214F9081AC93ADE8682582327366A7F76EDBDC98A39 ] C:\Program Files\AVG\AVG9\Notification\SPChecker1.exe
14:57:38.0234 0x01f8 avg_spchecker - ok
14:57:38.0254 0x01f8 Waiting for KSN requests completion. In queue: 8
14:57:39.0255 0x01f8 Waiting for KSN requests completion. In queue: 8
14:57:40.0257 0x01f8 Waiting for KSN requests completion. In queue: 8
14:57:41.0358 0x01f8 AV detected via SS1: AVG Anti-Virus Free, 9.0, enabled, updated
14:57:41.0368 0x01f8 Win FW state via NFM: disabled
14:57:43.0782 0x01f8 ============================================================
14:57:43.0782 0x01f8 Scan finished
14:57:43.0782 0x01f8 ============================================================
14:57:43.0842 0x0a64 Detected object count: 1
14:57:43.0842 0x0a64 Actual detected object count: 1
14:58:56.0596 0x0a64 C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe - copied to quarantine
14:58:56.0596 0x0a64 HKLM\SYSTEM\ControlSet002\services\syshost32 - will be deleted on reboot
14:58:56.0647 0x0a64 C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe - will be deleted on reboot
14:58:56.0647 0x0a64 syshost32 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete
14:59:00.0412 0x0a64 KLMD registered as C:\WINDOWS\system32\drivers\61547588.sys
14:59:58.0315 0x0eb0 Deinitialize success
Rkill 2.6.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 12/08/2014 03:30:52 PM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\WINDOWS\System32\QCONSVC.EXE (PID: 1272) [WD-HEUR]
1 proccess terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* Cannot edit the HOSTS file.
* Permissions Fixed. Administrators can now edit the HOSTS file.
* HOSTS file entries found:
127.0.0.1 localhost
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
127.0.0.1
www.1001-search.info
127.0.0.1 1001-search.info
127.0.0.1
www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1
www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1
www.10sek.com
127.0.0.1 10sek.com
127.0.0.1
www.123topsearch.com
20 out of 15612 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 12/08/2014 03:34:43 PM
Execution time: 0 hours(s), 3 minute(s), and 50 seconds(s)
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 08/12/2014
Scan Time: 15:36:25
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.08.04
Rootkit Database: v2014.12.03.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: IBM
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 356340
Time Elapsed: 1 hr, 5 min, 19 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SYSHOST32, , [20448fd15c208da9e92432441fe5c838],
Registry Values: 1
Trojan.Agent, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SYSHOST32|ImagePath, "C:\WINDOWS\Installer\{F07CB50E-48C0-6B81-B4AF-6E15944F672B}\syshost.exe" /service, , [20448fd15c208da9e92432441fe5c838]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end)
RogueKiller V10.0.9.0 [Dec 8 2014] by Adlice Software
mail :
http://www.adlice.com/contact/
Feedback :
http://forum.adlice.com
Website :
http://www.adlice.com/softwares/roguekiller/
Blog :
http://www.adlice.com
Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : IBM [Administrator]
Mode : Scan -- Date : 12/08/2014 16:57:22
¤¤¤ Processes : 0 ¤¤¤
¤¤¤ Registry : 8 ¤¤¤
[Root.Necurs] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8abc572ce51d2ca0 -> Found
[Root.Necurs] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\8abc572ce51d2ca0 -> Found
[Root.Necurs] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\8abc572ce51d2ca0 -> Found
[Root.Necurs] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\syshost32 -> Found
[PUM.HomePage] HKEY_USERS\S-1-5-21-247674877-3848448594-3852255402-1004\Software\Microsoft\Internet Explorer\Main | Start Page : file:///C:/Documents/Links_07.htm -> Found
[PUM.SearchPage] HKEY_USERS\S-1-5-21-247674877-3848448594-3852255402-1004\Software\Microsoft\Internet Explorer\Main | Search Page :
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> Found
[PUM.StartMenu] HKEY_USERS\S-1-5-21-247674877-3848448594-3852255402-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowRecentDocs : 2 -> Found
[PUM.DesktopIcons] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Found
¤¤¤ Tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ Hosts File : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc0000001]) ¤¤¤
¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] it92t6zv.default : user_pref("browser.startup.homepage", "file:///C:/Documents/Links_07.htm"); -> Found
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: IC25N020ATCS04-0 +++++
--- User ---
[MBR] b6351a83af7db8b2b21a75bce7ef0bde
[BSP] 8ac2aeb576eb43be8ab59644d36fa76e : Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 17637 MB
1 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 36121680 | Size: 1439 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: SAMSUNG HM160HC +++++
--- User ---
[MBR] 0eab729657d325cc560e0cc412daff46
[BSP] b9c8f0477e8a5bf36e966c1e3ec93e3f : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 152625 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_DEL_11162014_152357.log - RKreport_DEL_11182014_013106.log - RKreport_SCN_11162014_003509.log - RKreport_SCN_11162014_152242.log
RKreport_SCN_11172014_140902.log - RKreport_SCN_11172014_192455.log - RKreport_SCN_11182014_012722.log