OK, mi pc de sobre messa lleva desde antes de navidades que tiene el archivo: c:\windows\system32\services.exe infectado, no sabia como solucionarlo ya que es un archivo del sistema, hasta intente reemplazarlo pero no encontré
ningun metodo para hacerlo, si no te importa Anleg_30 realizo tus pasos en los dos ordenadores y te dejo los reportes,
Sobre messa=========>
reporte de TDSSKiller:
.Cita:
13:24:40.0020 4756 TDSS rootkit removing tool 2.8.13.0 Oct 12 2012 17:26:47
13:24:40.0200 4756 ============================================================
13:24:40.0200 4756 Current date / time: 2012/10/31 13:24:40.0200
13:24:40.0200 4756 SystemInfo:
13:24:40.0200 4756
13:24:40.0200 4756 OS Version: 6.0.6002 ServicePack: 2.0
13:24:40.0200 4756 Product type: Workstation
13:24:40.0200 4756 ComputerName: ULTIMATE
13:24:40.0200 4756 UserName: Abelique
13:24:40.0200 4756 Windows directory: C:\Windows
13:24:40.0200 4756 System windows directory: C:\Windows
13:24:40.0200 4756 Running under WOW64
13:24:40.0200 4756 Processor architecture: Intel x64
13:24:40.0200 4756 Number of processors: 2
13:24:40.0201 4756 Page size: 0x1000
13:24:40.0201 4756 Boot type: Normal boot
13:24:40.0201 4756 ============================================================
13:24:42.0434 4756 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:24:42.0439 4756 ============================================================
13:24:42.0439 4756 \Device\Harddisk0\DR0:
13:24:42.0439 4756 MBR partitions:
13:24:42.0439 4756 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC803400
13:24:42.0439 4756 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC80343F, BlocksNum 0x190029BD
13:24:42.0439 4756 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x25805DFC, BlocksNum 0x14B7EE45
13:24:42.0439 4756 ============================================================
13:24:42.0517 4756 C: <-> \Device\Harddisk0\DR0\Partition1
13:24:42.0661 4756 D: <-> \Device\Harddisk0\DR0\Partition2
13:24:42.0715 4756 E: <-> \Device\Harddisk0\DR0\Partition3
13:24:42.0715 4756 ============================================================
13:24:42.0715 4756 Initialize success
13:24:42.0715 4756 ============================================================
13:25:05.0527 4776 ============================================================
13:25:05.0528 4776 Scan started
13:25:05.0528 4776 Mode: Manual; SigCheck; TDLFS;
13:25:05.0528 4776 ============================================================
13:25:06.0601 4776 ================ Scan system memory ========================
13:25:06.0601 4776 System memory - ok
13:25:06.0601 4776 ================ Scan services =============================
13:25:06.0815 4776 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys
13:25:07.0004 4776 ACPI - ok
13:25:07.0103 4776 [ D19C4EE2AC7C47B8F5F84FFF1A789D8A ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:25:07.0121 4776 AdobeARMservice - ok
13:25:07.0263 4776 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:25:07.0285 4776 AdobeFlashPlayerUpdateSvc - ok
13:25:07.0340 4776 [ 9137451D37BA1C325CD6C2DEF3D2D692 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:25:07.0369 4776 adp94xx - ok
13:25:07.0415 4776 [ 01F80898DF5CC7DF19B3B11351846263 ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:25:07.0505 4776 adpahci - ok
13:25:07.0535 4776 [ DA001DB13FFF45DFE9109936E265B7CC ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
13:25:07.0551 4776 adpu160m - ok
13:25:07.0570 4776 [ 2B10C35C5B7C5C0C28F572E035319602 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:25:07.0585 4776 adpu320 - ok
13:25:07.0682 4776 [ 96D6CDD0B32846E8CFBE592F4F32E608 ] AdvancedSystemCareService5 C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
13:25:07.0708 4776 AdvancedSystemCareService5 - ok
13:25:07.0784 4776 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:25:07.0959 4776 AeLookupSvc - ok
13:25:08.0009 4776 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys
13:25:08.0081 4776 AFD - ok
13:25:08.0099 4776 [ 5CCDD13BC602AE33CD8B62D33C29AB72 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:25:08.0115 4776 agp440 - ok
13:25:08.0136 4776 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
13:25:08.0154 4776 aic78xx - ok
13:25:08.0185 4776 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe
13:25:08.0327 4776 ALG - ok
13:25:08.0361 4776 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys
13:25:08.0378 4776 aliide - ok
13:25:08.0392 4776 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys
13:25:08.0410 4776 amdide - ok
13:25:08.0427 4776 [ DE55DC52F7CEB89A967572D6B491ADA2 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
13:25:08.0577 4776 AmdK8 - ok
13:25:08.0604 4776 [ 71336E77F98A65EFAAEB950902611D3F ] AmFSM C:\Windows\system32\DRIVERS\amm6460.sys
13:25:08.0630 4776 AmFSM - ok
13:25:08.0721 4776 [ B11291CBC71231C373743055FB7F5B48 ] AppHostSvc C:\Windows\system32\inetsrv\apphostsvc.dll
13:25:08.0762 4776 AppHostSvc - ok
13:25:08.0813 4776 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll
13:25:08.0862 4776 Appinfo - ok
13:25:08.0921 4776 [ 3DA98C07B18A676180FE7EED924D1673 ] AppMgmt C:\Windows\System32\appmgmts.dll
13:25:08.0970 4776 AppMgmt - ok
13:25:08.0984 4776 [ 2E8623F2FED998A97129A3DB919551C8 ] arc C:\Windows\system32\drivers\arc.sys
13:25:09.0001 4776 arc - ok
13:25:09.0038 4776 [ 741A003C041A3EC480A2E71AF71E9654 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:25:09.0058 4776 arcsas - ok
13:25:09.0099 4776 [ 68726474C69B738EAC3A62E06B33ADDC ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
13:25:09.0114 4776 AsIO - ok
13:25:09.0169 4776 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:25:09.0242 4776 AsyncMac - ok
13:25:09.0269 4776 [ E68D9B3A3905619732F7FE039466A623 ] atapi C:\Windows\system32\drivers\atapi.sys
13:25:09.0291 4776 atapi - ok
13:25:09.0365 4776 [ 788914C42AD8318F1DD7A565EAFFB049 ] athrusb C:\Windows\system32\DRIVERS\athrxusb.sys
13:25:09.0481 4776 athrusb - ok
13:25:09.0525 4776 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:25:09.0599 4776 AudioEndpointBuilder - ok
13:25:09.0609 4776 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll
13:25:09.0654 4776 AudioSrv - ok
13:25:09.0688 4776 Beep - ok
13:25:09.0737 4776 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll
13:25:09.0808 4776 BFE - ok
13:25:09.0893 4776 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\System32\qmgr.dll
13:25:10.0019 4776 BITS - ok
13:25:10.0024 4776 blbdrive - ok
13:25:10.0100 4776 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:25:10.0146 4776 bowser - ok
13:25:10.0174 4776 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
13:25:10.0226 4776 BrFiltLo - ok
13:25:10.0254 4776 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
13:25:10.0326 4776 BrFiltUp - ok
13:25:10.0364 4776 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll
13:25:10.0416 4776 Browser - ok
13:25:10.0438 4776 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys
13:25:10.0511 4776 Brserid - ok
13:25:10.0529 4776 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
13:25:10.0606 4776 BrSerWdm - ok
13:25:10.0631 4776 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
13:25:10.0716 4776 BrUsbMdm - ok
13:25:10.0734 4776 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
13:25:10.0808 4776 BrUsbSer - ok
13:25:10.0870 4776 [ 09F926A0D9C0BAFD8417A4307D2ED13C ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys
13:25:10.0916 4776 BthEnum - ok
13:25:10.0940 4776 [ 72F70A38BB15252EB7C4DA7BA3BD4ED1 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
13:25:10.0991 4776 BTHMODEM - ok
13:25:11.0019 4776 [ BEFC5311736B475AC5B60C14FF7C775A ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:25:11.0064 4776 BthPan - ok
13:25:11.0144 4776 [ E1466882252FF51EDDE48C3F7EDA2591 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys
13:25:11.0226 4776 BTHPORT - ok
13:25:11.0264 4776 [ 22E65FFD640F16968F855F5B3528D366 ] BthServ C:\Windows\System32\bthserv.dll
13:25:11.0297 4776 BthServ - ok
13:25:11.0352 4776 [ 970192CDED77A128E7E30722E5EE6B9C ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys
13:25:11.0375 4776 BTHUSB - ok
13:25:11.0391 4776 catchme - ok
13:25:11.0436 4776 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:25:11.0486 4776 cdfs - ok
13:25:11.0540 4776 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
13:25:11.0597 4776 cdrom - ok
13:25:11.0660 4776 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll
13:25:11.0698 4776 CertPropSvc - ok
13:25:11.0754 4776 [ F28F00596824058BC61D5EDF434C9B82 ] circlass C:\Windows\system32\drivers\circlass.sys
13:25:11.0845 4776 circlass - ok
13:25:11.0873 4776 [ 2C0F16506BCBC80097D58099BC6BE4C0 ] CISVC C:\Windows\system32\CISVC.EXE
13:25:11.0900 4776 CISVC - ok
13:25:11.0930 4776 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys
13:25:11.0991 4776 CLFS - ok
13:25:12.0082 4776 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:25:12.0111 4776 clr_optimization_v2.0.50727_32 - ok
13:25:12.0157 4776 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
13:25:12.0177 4776 clr_optimization_v2.0.50727_64 - ok
13:25:12.0260 4776 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:25:12.0280 4776 clr_optimization_v4.0.30319_32 - ok
13:25:12.0335 4776 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
13:25:12.0352 4776 clr_optimization_v4.0.30319_64 - ok
13:25:12.0368 4776 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys
13:25:12.0385 4776 cmdide - ok
13:25:12.0398 4776 [ 0E77A445640BF310817F60941C50560C ] Compbatt C:\Windows\system32\drivers\compbatt.sys
13:25:12.0414 4776 Compbatt - ok
13:25:12.0419 4776 COMSysApp - ok
13:25:12.0453 4776 [ B1192DCD5B9CF46BEED0E2A9E5BCF59A ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
13:25:12.0467 4776 crcdisk - ok
13:25:12.0515 4776 [ CA78B312C44E4D52E842C2C8BD48E452 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:25:12.0555 4776 CryptSvc - ok
13:25:12.0605 4776 [ F60F50C8ED3FCBE358430B95FE27D09C ] CSC C:\Windows\system32\drivers\csc.sys
13:25:12.0673 4776 CSC - ok
13:25:12.0718 4776 [ 1B5F256D31836ED2BA60B3A6C800200C ] CscService C:\Windows\System32\cscsvc.dll
13:25:12.0758 4776 CscService - ok
13:25:12.0807 4776 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll
13:25:12.0853 4776 DcomLaunch - ok
13:25:12.0887 4776 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
13:25:12.0930 4776 DfsC - ok
13:25:13.0042 4776 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe
13:25:13.0281 4776 DFSR - ok
13:25:13.0313 4776 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll
13:25:13.0353 4776 Dhcp - ok
13:25:13.0401 4776 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys
13:25:13.0417 4776 disk - ok
13:25:13.0452 4776 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:25:13.0482 4776 Dnscache - ok
13:25:13.0524 4776 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll
13:25:13.0572 4776 dot3svc - ok
13:25:13.0607 4776 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll
13:25:13.0658 4776 DPS - ok
13:25:13.0696 4776 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:25:13.0742 4776 drmkaud - ok
13:25:13.0811 4776 [ B8E554E502D5123BC111F99D6A2181B4 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:25:13.0856 4776 DXGKrnl - ok
13:25:13.0901 4776 [ D57FE09B575545738A73A0C193D0616A ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys
13:25:13.0967 4776 E1G60 - ok
13:25:14.0025 4776 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll
13:25:14.0078 4776 EapHost - ok
13:25:14.0106 4776 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys
13:25:14.0129 4776 Ecache - ok
13:25:14.0176 4776 [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr C:\Windows\ehome\ehRecvr.exe
13:25:14.0232 4776 ehRecvr - ok
13:25:14.0253 4776 [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched C:\Windows\ehome\ehsched.exe
13:25:14.0271 4776 ehSched - ok
13:25:14.0309 4776 [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart C:\Windows\ehome\ehstart.dll
13:25:14.0355 4776 ehstart - ok
13:25:14.0378 4776 [ 3D6298AFF3FE06C0616CE5D090A3EEAA ] elxstor C:\Windows\system32\drivers\elxstor.sys
13:25:14.0402 4776 elxstor - ok
13:25:14.0456 4776 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll
13:25:14.0520 4776 EMDMgmt - ok
13:25:14.0575 4776 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll
13:25:14.0630 4776 EventSystem - ok
13:25:14.0653 4776 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys
13:25:14.0706 4776 exfat - ok
13:25:14.0731 4776 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:25:14.0783 4776 fastfat - ok
13:25:14.0857 4776 [ 989A776A2FF32A148FCF15C44058B129 ] Fax C:\Windows\system32\fxssvc.exe
13:25:14.0906 4776 Fax - ok
13:25:14.0932 4776 [ 61B6DBD1AD1143F008364D4E9A96B224 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
13:25:14.0996 4776 fdc - ok
13:25:15.0022 4776 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll
13:25:15.0102 4776 fdPHost - ok
13:25:15.0146 4776 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll
13:25:15.0238 4776 FDResPub - ok
13:25:15.0275 4776 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:25:15.0298 4776 FileInfo - ok
13:25:15.0352 4776 [ 7A0E303A18B04771A9DFA64932B5AEE0 ] FileMonitor C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\wlh_amd64\FileMonitor.sys
13:25:15.0385 4776 FileMonitor - ok
13:25:15.0428 4776 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:25:15.0565 4776 Filetrace - ok
13:25:15.0584 4776 [ 12C3D1B4D0CE49E1CE343BA2F22F15E0 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
13:25:15.0708 4776 flpydisk - ok
13:25:15.0750 4776 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:25:15.0778 4776 FltMgr - ok
13:25:15.0869 4776 [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache C:\Windows\system32\FntCache.dll
13:25:16.0003 4776 FontCache - ok
13:25:16.0070 4776 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:25:16.0090 4776 FontCache3.0.0.0 - ok
13:25:16.0141 4776 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:25:16.0191 4776 Fs_Rec - ok
13:25:16.0216 4776 [ 849E38DB7D829962D0233A0A252B60C3 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:25:16.0242 4776 fvevol - ok
13:25:16.0265 4776 [ B54520CC7B4B55134D7527B1CD3FC1F2 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:25:16.0287 4776 gagp30kx - ok
13:25:16.0343 4776 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll
13:25:16.0411 4776 gpsvc - ok
13:25:16.0444 4776 [ BA207B48AA3D9D73FD4856400F852458 ] hcmon C:\Windows\system32\drivers\hcmon.sys
13:25:16.0462 4776 hcmon - ok
13:25:16.0516 4776 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:25:16.0618 4776 HdAudAddService - ok
13:25:16.0653 4776 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
13:25:16.0738 4776 HDAudBus - ok
13:25:16.0773 4776 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys
13:25:16.0847 4776 HidBth - ok
13:25:16.0864 4776 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys
13:25:16.0940 4776 HidIr - ok
13:25:16.0976 4776 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\System32\hidserv.dll
13:25:17.0014 4776 hidserv - ok
13:25:17.0057 4776 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
13:25:17.0133 4776 HidUsb - ok
13:25:17.0175 4776 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll
13:25:17.0250 4776 hkmsvc - ok
13:25:17.0291 4776 [ 8EDC820115DF1E04763B2923676EA5B2 ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
13:25:17.0311 4776 HpCISSs - ok
13:25:17.0361 4776 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:25:17.0411 4776 HTTP - ok
13:25:17.0438 4776 [ F2901763845570ECAC48E6A50EC50812 ] i2omp C:\Windows\system32\drivers\i2omp.sys
13:25:17.0456 4776 i2omp - ok
13:25:17.0514 4776 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
13:25:17.0547 4776 i8042prt - ok
13:25:17.0578 4776 [ 72C3EE7EA3CD75A772E62AE0E5DF8B8C ] iaStorV C:\Windows\system32\drivers\iastorv.sys
13:25:17.0601 4776 iaStorV - ok
13:25:17.0666 4776 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
13:25:17.0720 4776 idsvc - ok
13:25:17.0754 4776 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:25:17.0767 4776 iirsp - ok
13:25:17.0831 4776 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll
13:25:17.0865 4776 IKEEXT - ok
13:25:17.0962 4776 [ 8AE99EBE30E8338907361018D9030835 ] IMFservice C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
13:25:17.0984 4776 IMFservice - ok
13:25:18.0085 4776 [ F04D22D7A49A1B2210DBADF0B803E870 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
13:25:18.0173 4776 IntcAzAudAddService - ok
13:25:18.0237 4776 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys
13:25:18.0252 4776 intelide - ok
13:25:18.0289 4776 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
13:25:18.0341 4776 intelppm - ok
13:25:18.0360 4776 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
13:25:18.0399 4776 IPBusEnum - ok
13:25:18.0436 4776 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:25:18.0484 4776 IpFilterDriver - ok
13:25:18.0517 4776 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:25:18.0551 4776 iphlpsvc - ok
13:25:18.0556 4776 IpInIp - ok
13:25:18.0588 4776 [ EACDBBE429C6D170BDEEE0EFFCBC317B ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
13:25:18.0650 4776 IPMIDRV - ok
13:25:18.0679 4776 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
13:25:18.0727 4776 IPNAT - ok
13:25:18.0765 4776 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:25:18.0803 4776 IRENUM - ok
13:25:18.0838 4776 [ D3BB520B31F28C1A065CD058E762EE73 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:25:18.0854 4776 isapnp - ok
13:25:18.0907 4776 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
13:25:18.0929 4776 iScsiPrt - ok
13:25:18.0951 4776 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
13:25:18.0966 4776 iteatapi - ok
13:25:19.0003 4776 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys
13:25:19.0019 4776 iteraid - ok
13:25:19.0049 4776 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
13:25:19.0068 4776 kbdclass - ok
13:25:19.0080 4776 [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
13:25:19.0113 4776 kbdhid - ok
13:25:19.0134 4776 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe
13:25:19.0191 4776 KeyIso - ok
13:25:19.0265 4776 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:25:19.0310 4776 KSecDD - ok
13:25:19.0349 4776 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:25:19.0403 4776 ksthunk - ok
13:25:19.0455 4776 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll
13:25:19.0557 4776 KtmRm - ok
13:25:19.0616 4776 [ 073508533E422CE8BCEE234EB35CEEBF ] L1E C:\Windows\system32\DRIVERS\L1E60x64.sys
13:25:19.0648 4776 L1E - ok
13:25:19.0688 4776 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\System32\srvsvc.dll
13:25:19.0739 4776 LanmanServer - ok
13:25:19.0764 4776 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:25:19.0826 4776 LanmanWorkstation - ok
13:25:19.0868 4776 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:25:19.0919 4776 lltdio - ok
13:25:19.0963 4776 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:25:20.0023 4776 lltdsvc - ok
13:25:20.0048 4776 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:25:20.0099 4776 lmhosts - ok
13:25:20.0138 4776 [ 1572F8D999C0AB4376AFDCE058A78DF9 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
13:25:20.0162 4776 LSI_FC - ok
13:25:20.0186 4776 [ 64470979C3E3C9FF60EDFB5230C56E0E ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:25:20.0210 4776 LSI_SAS - ok
13:25:20.0240 4776 [ 4CED7D3B54BFC5BBAE75C4A73C7F7428 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:25:20.0262 4776 LSI_SCSI - ok
13:25:20.0307 4776 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys
13:25:20.0372 4776 luafv - ok
13:25:20.0408 4776 [ A8FE8F2783B2929B56F5370A89356CE9 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:25:20.0429 4776 MBAMProtector - ok
13:25:20.0488 4776 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
13:25:20.0517 4776 MBAMScheduler - ok
13:25:20.0569 4776 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
13:25:20.0604 4776 MBAMService - ok
13:25:20.0640 4776 [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
13:25:20.0754 4776 Mcx2Svc - ok
13:25:20.0785 4776 [ 2F631C2939D5F2E8958935EE701D70D7 ] megasas C:\Windows\system32\drivers\megasas.sys
13:25:20.0845 4776 megasas - ok
13:25:20.0960 4776 Microsoft SharePoint Workspace Audit Service - ok
13:25:20.0992 4776 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll
13:25:21.0057 4776 MMCSS - ok
13:25:21.0082 4776 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys
13:25:21.0132 4776 Modem - ok
13:25:21.0169 4776 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
13:25:21.0238 4776 monitor - ok
13:25:21.0291 4776 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
13:25:21.0313 4776 mouclass - ok
13:25:21.0341 4776 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
13:25:21.0387 4776 mouhid - ok
13:25:21.0408 4776 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
13:25:21.0427 4776 MountMgr - ok
13:25:21.0504 4776 [ 4D7F2682D29B92A6251B17957AA0B985 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:25:21.0523 4776 MozillaMaintenance - ok
13:25:21.0555 4776 [ ED48EAC719EE28DB773359EB1B06E2B5 ] mpio C:\Windows\system32\drivers\mpio.sys
13:25:21.0575 4776 mpio - ok
13:25:21.0611 4776 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:25:21.0671 4776 mpsdrv - ok
13:25:21.0721 4776 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll
13:25:21.0775 4776 MpsSvc - ok
13:25:21.0798 4776 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
13:25:21.0820 4776 Mraid35x - ok
13:25:21.0837 4776 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:25:21.0875 4776 MRxDAV - ok
13:25:21.0923 4776 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:25:21.0967 4776 mrxsmb - ok
13:25:22.0025 4776 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:25:22.0071 4776 mrxsmb10 - ok
13:25:22.0086 4776 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:25:22.0112 4776 mrxsmb20 - ok
13:25:22.0135 4776 [ EEADF970795148BFBB1DB3ABCC89C16B ] msahci C:\Windows\system32\drivers\msahci.sys
13:25:22.0156 4776 msahci - ok
13:25:22.0186 4776 [ 96D7C0A1B98434C6E4FF0C2E26A0E20A ] msdsm C:\Windows\system32\drivers\msdsm.sys
13:25:22.0209 4776 msdsm - ok
13:25:22.0248 4776 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe
13:25:22.0302 4776 MSDTC - ok
13:25:22.0356 4776 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:25:22.0413 4776 Msfs - ok
13:25:22.0461 4776 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:25:22.0477 4776 msisadrv - ok
13:25:22.0517 4776 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:25:22.0569 4776 MSiSCSI - ok
13:25:22.0574 4776 msiserver - ok
13:25:22.0601 4776 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:25:22.0642 4776 MSKSSRV - ok
13:25:22.0660 4776 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:25:22.0705 4776 MSPCLOCK - ok
13:25:22.0738 4776 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:25:22.0776 4776 MSPQM - ok
13:25:22.0825 4776 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:25:22.0842 4776 MsRPC - ok
13:25:22.0854 4776 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
13:25:22.0867 4776 mssmbios - ok
13:25:22.0901 4776 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:25:22.0938 4776 MSTEE - ok
13:25:23.0012 4776 [ 6936198F2CC25B39CF5262436C80DF46 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
13:25:23.0024 4776 MTsensor - ok
13:25:23.0059 4776 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys
13:25:23.0078 4776 Mup - ok
13:25:23.0123 4776 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll
13:25:23.0172 4776 napagent - ok
13:25:23.0228 4776 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:25:23.0267 4776 NativeWifiP - ok
13:25:23.0315 4776 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:25:23.0362 4776 NDIS - ok
13:25:23.0396 4776 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:25:23.0443 4776 NdisTapi - ok
13:25:23.0460 4776 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:25:23.0499 4776 Ndisuio - ok
13:25:23.0520 4776 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:25:23.0567 4776 NdisWan - ok
13:25:23.0584 4776 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:25:23.0625 4776 NDProxy - ok
13:25:23.0784 4776 [ 40D7D0A208EE863BCA8D89E299216F15 ] Nero BackItUp Scheduler 3 C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
13:25:23.0814 4776 Nero BackItUp Scheduler 3 - ok
13:25:23.0870 4776 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:25:23.0926 4776 NetBIOS - ok
13:25:23.0950 4776 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
13:25:23.0986 4776 netbt - ok
13:25:23.0993 4776 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe
13:25:24.0013 4776 Netlogon - ok
13:25:24.0056 4776 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll
13:25:24.0107 4776 Netman - ok
13:25:24.0138 4776 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll
13:25:24.0203 4776 netprofm - ok
13:25:24.0286 4776 [ 61EBE29D1112D368F6E135916897531D ] netr28ux C:\Windows\system32\DRIVERS\netr28ux.sys
13:25:24.0327 4776 netr28ux - ok
13:25:24.0388 4776 [ 4D457321124EF6031875DA01E9C402B3 ] netr7364 C:\Windows\system32\DRIVERS\netr7364.sys
13:25:24.0427 4776 netr7364 - ok
13:25:24.0456 4776 [ 74751DDA198165947FD7454D83F49825 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
13:25:24.0479 4776 NetTcpPortSharing - ok
13:25:24.0521 4776 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:25:24.0542 4776 nfrd960 - ok
13:25:24.0586 4776 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll
13:25:24.0677 4776 NlaSvc - ok
13:25:24.0785 4776 [ EBA1B4BF2E2375ABDADEDB649F283541 ] NMIndexingService C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
13:25:24.0834 4776 NMIndexingService - ok
13:25:24.0908 4776 [ 109338286793775088CB5A3A13C874DB ] NPF C:\Windows\system32\drivers\npf.sys
13:25:24.0925 4776 NPF - ok
13:25:24.0963 4776 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:25:24.0997 4776 Npfs - ok
13:25:25.0065 4776 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll
13:25:25.0109 4776 nsi - ok
13:25:25.0131 4776 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:25:25.0200 4776 nsiproxy - ok
13:25:25.0272 4776 [ BAC869DFB98E499BA4D9BB1FB43270E1 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:25:25.0338 4776 Ntfs - ok
13:25:25.0364 4776 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys
13:25:25.0424 4776 Null - ok
13:25:25.0680 4776 [ F12C5F17D48D9F5C70E4408B3CCB5443 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:25:26.0321 4776 nvlddmkm - ok
13:25:26.0346 4776 [ 840EEB44DC49317A6161961F7682CD99 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:25:26.0363 4776 nvraid - ok
13:25:26.0387 4776 [ 94C5334040A5D500897F4C5FD12AEEDE ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:25:26.0403 4776 nvstor - ok
13:25:26.0453 4776 [ 8A55543C379B0582F0C33DB447D1C892 ] NVSvc C:\Windows\system32\nvvsvc.exe
13:25:26.0512 4776 NVSvc - ok
13:25:26.0539 4776 [ AA1B6C86A4763502E20B65C025F39BAD ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:25:26.0558 4776 nv_agp - ok
13:25:26.0564 4776 NwlnkFlt - ok
13:25:26.0570 4776 NwlnkFwd - ok
13:25:26.0604 4776 [ 7B58953E2F263421FDBB09A192712A85 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
13:25:26.0680 4776 ohci1394 - ok
13:25:26.0758 4776 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:25:26.0778 4776 ose - ok
13:25:26.0948 4776 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
13:25:27.0200 4776 osppsvc - ok
13:25:27.0265 4776 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll
13:25:27.0361 4776 p2pimsvc - ok
13:25:27.0396 4776 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll
13:25:27.0420 4776 p2psvc - ok
13:25:27.0543 4776 [ 78B7642B0C51F24F0835C0226540D58B ] Panda Software Controller C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsCtrls.exe
13:25:27.0556 4776 Panda Software Controller - ok
13:25:27.0617 4776 [ 4C6A7FD04DDF4DB88791048382E3EDB1 ] Parport C:\Windows\system32\DRIVERS\parport.sys
13:25:27.0661 4776 Parport - ok
13:25:27.0702 4776 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:25:27.0721 4776 partmgr - ok
13:25:27.0790 4776 [ 337A81B3FF34F9851D245D42A725FC22 ] pavboot C:\Windows\system32\Drivers\pavboot64.sys
13:25:27.0803 4776 pavboot - ok
13:25:27.0914 4776 [ AE848C1613C8738BB83ADAB4F0845E84 ] PAVFNSVR C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PavFnSvr.exe
13:25:27.0993 4776 PAVFNSVR - ok
13:25:28.0048 4776 [ 2AE3F6B23448443BBEF5DE207159213B ] PavPrSrv C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe
13:25:28.0062 4776 PavPrSrv - ok
13:25:28.0078 4776 [ 97005413310966001FB6F4A5C503149C ] PAVSRV C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\pavsrvx86.exe
13:25:28.0096 4776 PAVSRV - ok
13:25:28.0108 4776 PavTPK.sys - ok
13:25:28.0161 4776 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll
13:25:28.0220 4776 PcaSvc - ok
13:25:28.0263 4776 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys
13:25:28.0283 4776 pci - ok
13:25:28.0306 4776 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\drivers\pciide.sys
13:25:28.0321 4776 pciide - ok
13:25:28.0342 4776 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:25:28.0364 4776 pcmcia - ok
13:25:28.0416 4776 [ AF7CE12C4F3DC8CB2B07685C916BBCFE ] pcouffin C:\Windows\system32\Drivers\pcouffin.sys
13:25:28.0457 4776 pcouffin - ok
13:25:28.0485 4776 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:25:28.0583 4776 PEAUTH - ok
13:25:28.0684 4776 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:25:28.0727 4776 PerfHost - ok
13:25:28.0812 4776 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll
13:25:28.0862 4776 pla - ok
13:25:28.0914 4776 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\Windows\SysWOW64\IoctlSvc.exe
13:25:28.0935 4776 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - warning
13:25:28.0935 4776 PLFlash DeviceIoControl Service - detected UnsignedFile.Multi.Generic (1)
13:25:28.0982 4776 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:25:29.0024 4776 PlugPlay - ok
13:25:29.0063 4776 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
13:25:29.0091 4776 PNRPAutoReg - ok
13:25:29.0147 4776 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll
13:25:29.0172 4776 PNRPsvc - ok
13:25:29.0212 4776 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:25:29.0265 4776 PolicyAgent - ok
13:25:29.0316 4776 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:25:29.0355 4776 PptpMiniport - ok
13:25:29.0399 4776 [ 6BC78E5F12CBB74E7930AAAA4A0DB387 ] Processor C:\Windows\system32\drivers\processr.sys
13:25:29.0457 4776 Processor - ok
13:25:29.0497 4776 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll
13:25:29.0537 4776 ProfSvc - ok
13:25:29.0554 4776 Prot6Flt - ok
13:25:29.0579 4776 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
13:25:29.0625 4776 ProtectedStorage - ok
13:25:29.0673 4776 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
13:25:29.0705 4776 PSched - ok
13:25:29.0754 4776 [ 196C450F2779D0B462C444DA4906EA7F ] PSIMSVC C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PsImSvc.exe
13:25:29.0767 4776 PSIMSVC - ok
13:25:29.0787 4776 [ 341457B79B3FC31A80C346C767045879 ] PskSvcRetail C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\PskSvc.exe
13:25:29.0801 4776 PskSvcRetail - ok
13:25:29.0839 4776 [ 4A29D25704917161BAD9B4659A248DFD ] ql2300 C:\Windows\system32\drivers\ql2300.sys
13:25:29.0873 4776 ql2300 - ok
13:25:29.0903 4776 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
13:25:29.0918 4776 ql40xx - ok
13:25:29.0970 4776 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll
13:25:29.0991 4776 QWAVE - ok
13:25:30.0009 4776 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:25:30.0037 4776 QWAVEdrv - ok
13:25:30.0072 4776 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:25:30.0122 4776 RasAcd - ok
13:25:30.0167 4776 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll
13:25:30.0210 4776 RasAuto - ok
13:25:30.0258 4776 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:25:30.0298 4776 Rasl2tp - ok
13:25:30.0321 4776 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll
13:25:30.0367 4776 RasMan - ok
13:25:30.0394 4776 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:25:30.0428 4776 RasPppoe - ok
13:25:30.0476 4776 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:25:30.0492 4776 RasSstp - ok
13:25:30.0513 4776 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:25:30.0556 4776 rdbss - ok
13:25:30.0584 4776 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
13:25:30.0638 4776 RDPCDD - ok
13:25:30.0677 4776 [ AE23E79B13FEB62939E2CA1189E71735 ] rdpdr C:\Windows\system32\DRIVERS\rdpdr.sys
13:25:30.0719 4776 rdpdr - ok
13:25:30.0724 4776 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
13:25:30.0757 4776 RDPENCDD - ok
13:25:30.0806 4776 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:25:30.0834 4776 RDPWD - ok
13:25:30.0912 4776 [ D7AEA5375DB1D6632A4120AD06C52F6B ] RegFilter C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\wlh_amd64\regfilter.sys
13:25:30.0923 4776 RegFilter - ok
13:25:30.0988 4776 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:25:31.0077 4776 RemoteAccess - ok
13:25:31.0120 4776 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:25:31.0186 4776 RemoteRegistry - ok
13:25:31.0228 4776 [ CD71E053D7260E4102D99A28F9196070 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
13:25:31.0253 4776 RFCOMM - ok
13:25:31.0279 4776 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe
13:25:31.0328 4776 RpcLocator - ok
13:25:31.0381 4776 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\system32\rpcss.dll
13:25:31.0423 4776 RpcSs - ok
13:25:31.0468 4776 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:25:31.0510 4776 rspndr - ok
13:25:31.0535 4776 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe
13:25:31.0549 4776 SamSs - ok
13:25:31.0581 4776 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:25:31.0594 4776 sbp2port - ok
13:25:31.0617 4776 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:25:31.0643 4776 SCardSvr - ok
13:25:31.0696 4776 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll
13:25:31.0735 4776 Schedule - ok
13:25:31.0782 4776 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:25:31.0808 4776 SCPolicySvc - ok
13:25:31.0880 4776 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:25:31.0910 4776 SDRSVC - ok
13:25:31.0998 4776 [ D98E936BDD4A6CFE39535F3696D0EC6F ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
13:25:32.0027 4776 SDScannerService - ok
13:25:32.0136 4776 [ 2D5088524613D1ED55D20195AF42DDC7 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
13:25:32.0189 4776 SDUpdateService - ok
13:25:32.0225 4776 [ 59DCE6783F9ED27EB72C81466E363BF8 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
13:25:32.0240 4776 SDWSCService - ok
13:25:32.0266 4776 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:25:32.0336 4776 secdrv - ok
13:25:32.0357 4776 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll
13:25:32.0387 4776 seclogon - ok
13:25:32.0429 4776 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\system32\sens.dll
13:25:32.0461 4776 SENS - ok
13:25:32.0507 4776 [ 2449316316411D65BD2C761A6FFB2CE2 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
13:25:32.0540 4776 Serenum - ok
13:25:32.0582 4776 [ 4B438170BE2FC8E0BD35EE87A960F84F ] Serial C:\Windows\system32\DRIVERS\serial.sys
13:25:32.0615 4776 Serial - ok
13:25:32.0642 4776 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys
13:25:32.0692 4776 sermouse - ok
13:25:32.0746 4776 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll
13:25:32.0798 4776 SessionEnv - ok
13:25:32.0816 4776 [ 541B32F8D6B2DCB92EC43BAB267E79EA ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
13:25:32.0879 4776 sffdisk - ok
13:25:32.0899 4776 [ 446E7CCA3325C7E0AE0FDE7F73CDD9C2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
13:25:32.0948 4776 sffp_mmc - ok
13:25:32.0972 4776 [ 67EDC221348911E895AF51C57D9A3725 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
13:25:33.0013 4776 sffp_sd - ok
13:25:33.0027 4776 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
13:25:33.0083 4776 sfloppy - ok
13:25:33.0127 4776 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:25:33.0165 4776 SharedAccess - ok
13:25:33.0212 4776 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:25:33.0261 4776 ShellHWDetection - ok
13:25:33.0281 4776 [ 03639A3B26AA808BAE79D89FDB4B151C ] ShldFlt C:\Windows\system32\DRIVERS\ShldFlt.sys
13:25:33.0294 4776 ShldFlt - ok
13:25:33.0320 4776 [ 08DDA16573FA44F8B13AFE74597AD2E5 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
13:25:33.0333 4776 SiSRaid2 - ok
13:25:33.0357 4776 [ C52259E9DAAF3890D572D87FFEE0979E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:25:33.0407 4776 SiSRaid4 - ok
13:25:33.0488 4776 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe
13:25:33.0660 4776 slsvc - ok
13:25:33.0682 4776 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll
13:25:33.0723 4776 SLUINotify - ok
13:25:33.0776 4776 [ B68385FD0CB677A1BB3EAB0BEB2999B7 ] SmartDefragDriver C:\Windows\system32\Drivers\SmartDefragDriver.sys
13:25:33.0787 4776 SmartDefragDriver - ok
13:25:33.0816 4776 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys
13:25:33.0841 4776 Smb - ok
13:25:33.0885 4776 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:25:33.0912 4776 SNMPTRAP - ok
13:25:33.0938 4776 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys
13:25:33.0954 4776 spldr - ok
13:25:33.0984 4776 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe
13:25:34.0009 4776 Spooler - ok
13:25:34.0055 4776 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys
13:25:34.0089 4776 srv - ok
13:25:34.0120 4776 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
13:25:34.0176 4776 srv2 - ok
13:25:34.0211 4776 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
13:25:34.0249 4776 srvnet - ok
13:25:34.0321 4776 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
13:25:34.0375 4776 SSDPSRV - ok
13:25:34.0426 4776 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll
13:25:34.0455 4776 SstpSvc - ok
13:25:34.0507 4776 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll
13:25:34.0537 4776 stisvc - ok
13:25:34.0569 4776 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys
13:25:34.0585 4776 swenum - ok
13:25:34.0637 4776 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll
13:25:34.0688 4776 swprv - ok
13:25:34.0703 4776 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
13:25:34.0719 4776 Symc8xx - ok
13:25:34.0733 4776 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
13:25:34.0751 4776 Sym_hi - ok
13:25:34.0765 4776 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
13:25:34.0783 4776 Sym_u3 - ok
13:25:34.0832 4776 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll
13:25:34.0939 4776 SysMain - ok
13:25:34.0971 4776 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
13:25:35.0010 4776 TabletInputService - ok
13:25:35.0060 4776 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll
13:25:35.0114 4776 TapiSrv - ok
13:25:35.0167 4776 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll
13:25:35.0220 4776 TBS - ok
13:25:35.0286 4776 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip C:\Windows\system32\drivers\tcpip.sys
13:25:35.0349 4776 Tcpip - ok
13:25:35.0394 4776 [ 46D448E9117464E4D3BBF36D7E3FA48E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
13:25:35.0470 4776 Tcpip6 - ok
13:25:35.0533 4776 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
13:25:35.0589 4776 tcpipreg - ok
13:25:35.0627 4776 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
13:25:35.0682 4776 TDPIPE - ok
13:25:35.0727 4776 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
13:25:35.0770 4776 TDTCP - ok
13:25:35.0795 4776 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
13:25:35.0829 4776 tdx - ok
13:25:35.0949 4776 [ FE559178000347D2CA1B7847F0379749 ] TeamViewer6 C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
13:25:36.0052 4776 TeamViewer6 - ok
13:25:36.0087 4776 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
13:25:36.0110 4776 TermDD - ok
13:25:36.0172 4776 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll
13:25:36.0474 4776 TermService - ok
13:25:36.0500 4776 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll
13:25:36.0527 4776 Themes - ok
13:25:36.0567 4776 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll
13:25:36.0617 4776 THREADORDER - ok
13:25:36.0652 4776 [ B88C4D29CEE2BF7465FA4BF426A24E4E ] TPSrv C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2012\TPSrvWow.exe
13:25:36.0671 4776 TPSrv - ok
13:25:36.0707 4776 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll
13:25:36.0761 4776 TrkWks - ok
13:25:36.0806 4776 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:25:36.0858 4776 TrustedInstaller - ok
13:25:36.0897 4776 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
13:25:36.0962 4776 tssecsrv - ok
13:25:37.0004 4776 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
13:25:37.0032 4776 tunmp - ok
13:25:37.0080 4776 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
13:25:37.0105 4776 tunnel - ok
13:25:37.0153 4776 [ E4722DFBD6232ACF17543EF2C2DCE8D2 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
13:25:37.0176 4776 uagp35 - ok
13:25:37.0232 4776 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
13:25:37.0278 4776 udfs - ok
13:25:37.0337 4776 [ 215462AE7E6A897D675E84DD1E3B3B56 ] ufad-ws60 C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe
13:25:37.0357 4776 ufad-ws60 - ok
13:25:37.0401 4776 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe
13:25:37.0442 4776 UI0Detect - ok
13:25:37.0459 4776 [ 5663D7696ABBE71F8C9D915C5374118A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
13:25:37.0474 4776 uliagpkx - ok
13:25:37.0497 4776 [ 6030B68E86A30D1B315B51C4D7778B16 ] uliahci C:\Windows\system32\drivers\uliahci.sys
13:25:37.0516 4776 uliahci - ok
13:25:37.0538 4776 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys
13:25:37.0554 4776 UlSata - ok
13:25:37.0574 4776 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
13:25:37.0591 4776 ulsata2 - ok
13:25:37.0626 4776 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
13:25:37.0677 4776 umbus - ok
13:25:37.0707 4776 [ DC5E34F189B827199B9CC8481C648269 ] UmRdpService C:\Windows\System32\umrdp.dll
13:25:37.0749 4776 UmRdpService - ok
13:25:37.0791 4776 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll
13:25:37.0856 4776 upnphost - ok
13:25:37.0925 4776 [ 55BA05042FEBB956BE4A54BC5E621593 ] UrlFilter C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\wlh_amd64\UrlFilter.sys
13:25:37.0938 4776 UrlFilter - ok
13:25:37.0976 4776 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
13:25:38.0006 4776 usbccgp - ok
13:25:38.0030 4776 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys
13:25:38.0086 4776 usbcir - ok
13:25:38.0126 4776 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
13:25:38.0155 4776 usbehci - ok
13:25:38.0168 4776 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
13:25:38.0210 4776 usbhub - ok
13:25:38.0233 4776 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys
13:25:38.0283 4776 usbohci - ok
13:25:38.0322 4776 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
13:25:38.0355 4776 usbprint - ok
13:25:38.0397 4776 [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
13:25:38.0424 4776 usbscan - ok
13:25:38.0462 4776 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:25:38.0510 4776 USBSTOR - ok
13:25:38.0550 4776 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
13:25:38.0579 4776 usbuhci - ok
13:25:38.0618 4776 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll
13:25:38.0648 4776 UxSms - ok
13:25:38.0743 4776 [ C83D714B7CA4286515B5954B8F8C3C1F ] VBoxDrv C:\Program Files (x86)\YouWave_Android\vb\VBoxDrv.sys
13:25:38.0764 4776 VBoxDrv - ok
13:25:38.0810 4776 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe
13:25:38.0879 4776 vds - ok
13:25:38.0921 4776 [ 2998DC48905E9B4821AD8FD75B3E070C ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
13:25:38.0983 4776 vga - ok
13:25:39.0004 4776 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys
13:25:39.0045 4776 VgaSave - ok
13:25:39.0072 4776 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys
13:25:39.0088 4776 viaide - ok
13:25:39.0121 4776 [ 6FC9B272B838EE8F5FA0E4A7E971154A ] VMAuthdService C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
13:25:39.0137 4776 VMAuthdService - ok
13:25:39.0168 4776 [ B49CB94DB99519F9DC7F77D2D1F215B5 ] vmci C:\Windows\system32\drivers\vmci.sys
13:25:39.0182 4776 vmci - ok
13:25:39.0210 4776 [ 1AF6462718E5AB0ED55014A6EF3790EF ] vmkbd C:\Windows\system32\drivers\VMkbd.sys
13:25:39.0224 4776 vmkbd - ok
13:25:39.0250 4776 [ 9D54F1339E78C95BF3D9939EBCB66378 ] VMnetAdapter C:\Windows\system32\DRIVERS\vmnetadapter.sys
13:25:39.0264 4776 VMnetAdapter - ok
13:25:39.0311 4776 [ FB54EF3AA613D2832FD3812E7CB2FC75 ] VMnetBridge C:\Windows\system32\DRIVERS\vmnetbridge.sys
13:25:39.0324 4776 VMnetBridge - ok
13:25:39.0331 4776 VMnetDHCP - ok
13:25:39.0382 4776 [ 163B05050FCD9635242EC5206C19A182 ] VMnetuserif C:\Windows\system32\drivers\vmnetuserif.sys
13:25:39.0397 4776 VMnetuserif - ok
13:25:39.0461 4776 [ C8EB96D0C78B1CF67167DAFC617EE960 ] VMparport C:\Windows\system32\drivers\VMparport.sys
13:25:39.0476 4776 VMparport - ok
13:25:39.0512 4776 [ 415B167695C4B5960A13098622EF3D80 ] vmusb C:\Windows\system32\Drivers\vmusb.sys
13:25:39.0527 4776 vmusb - ok
13:25:39.0576 4776 [ F22098DBDD13C1221C274496B3E18DA7 ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
13:25:39.0601 4776 VMUSBArbService - ok
13:25:39.0614 4776 VMware NAT Service - ok
13:25:39.0650 4776 [ F2A8EE62D7161E1598CDD269BF22A03D ] vmx86 C:\Windows\system32\drivers\vmx86.sys
13:25:39.0666 4776 vmx86 - ok
13:25:39.0699 4776 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys
13:25:39.0723 4776 volmgr - ok
13:25:39.0793 4776 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
13:25:39.0826 4776 volmgrx - ok
13:25:39.0866 4776 [ 5280AADA24AB36B01A84A6424C475C8D ] volsnap C:\Windows\system32\drivers\volsnap.sys
13:25:39.0894 4776 volsnap - ok
13:25:39.0925 4776 [ 410AE2C141142C58BC617FC2C677F8B0 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
13:25:39.0948 4776 vsmraid - ok
13:25:39.0990 4776 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe
13:25:40.0132 4776 VSS - ok
13:25:40.0175 4776 [ E61C910E2DDF4797C1B1F9239636E894 ] vstor2-ws60 C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys
13:25:40.0193 4776 vstor2-ws60 - ok
13:25:40.0227 4776 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll
13:25:40.0308 4776 W32Time - ok
13:25:40.0348 4776 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
13:25:40.0439 4776 WacomPen - ok
13:25:40.0474 4776 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
13:25:40.0524 4776 Wanarp - ok
13:25:40.0532 4776 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
13:25:40.0571 4776 Wanarpv6 - ok
13:25:40.0659 4776 [ 33F26FEF446C4AD9FDB0932601FD017B ] WAS C:\Windows\system32\inetsrv\iisw3adm.dll
13:25:40.0738 4776 WAS - ok
13:25:40.0825 4776 [ 48EEE289DF9E4989128B2283F3EEACC6 ] wbengine C:\Windows\system32\wbengine.exe
13:25:40.0927 4776 wbengine - ok
13:25:40.0971 4776 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll
13:25:41.0051 4776 wcncsvc - ok
13:25:41.0119 4776 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:25:41.0162 4776 WcsPlugInService - ok
13:25:41.0197 4776 [ 59B501B0A04C9672142B7FFA2BDBF663 ] Wd C:\Windows\system32\drivers\wd.sys
13:25:41.0217 4776 Wd - ok
13:25:41.0271 4776 [ D02E7E4567DA1E7582FBF6A91144B0DF ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
13:25:41.0317 4776 Wdf01000 - ok
13:25:41.0338 4776 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll
13:25:41.0401 4776 WdiServiceHost - ok
13:25:41.0409 4776 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll
13:25:41.0461 4776 WdiSystemHost - ok
13:25:41.0502 4776 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll
13:25:41.0563 4776 WebClient - ok
13:25:41.0608 4776 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll
13:25:41.0664 4776 Wecsvc - ok
13:25:41.0682 4776 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll
13:25:41.0743 4776 wercplsupport - ok
13:25:41.0764 4776 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll
13:25:41.0819 4776 WerSvc - ok
13:25:41.0858 4776 WinDefend - ok
13:25:41.0873 4776 WinHttpAutoProxySvc - ok
13:25:41.0952 4776 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
13:25:41.0994 4776 Winmgmt - ok
13:25:42.0077 4776 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll
13:25:42.0230 4776 WinRM - ok
13:25:42.0311 4776 Winstep Xtreme Service - ok
13:25:42.0368 4776 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll
13:25:42.0442 4776 Wlansvc - ok
13:25:42.0582 4776 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
13:25:42.0694 4776 wlidsvc - ok
13:25:42.0743 4776 [ AE34218455D5DC12D1E45DE85F160346 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
13:25:42.0823 4776 WmiAcpi - ok
13:25:42.0854 4776 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
13:25:42.0909 4776 wmiApSrv - ok
13:25:42.0940 4776 WMPNetworkSvc - ok
13:25:42.0979 4776 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
13:25:43.0032 4776 WPCSvc - ok
13:25:43.0128 4776 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
13:25:43.0160 4776 WPDBusEnum - ok
13:25:43.0289 4776 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
13:25:43.0331 4776 WPFFontCache_v0400 - ok
13:25:43.0391 4776 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
13:25:43.0440 4776 ws2ifsl - ok
13:25:43.0496 4776 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\system32\wscsvc.dll
13:25:43.0525 4776 wscsvc - ok
13:25:43.0534 4776 WSearch - ok
13:25:43.0624 4776 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
13:25:43.0747 4776 wuauserv - ok
13:25:43.0774 4776 [ 501A65252617B495C0F1832F908D54D8 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
13:25:43.0825 4776 WUDFRd - ok
13:25:43.0848 4776 [ 6CBD51FF913C851D56ED9DC7F2A27DDE ] wudfsvc C:\Windows\System32\WUDFSvc.dll
13:25:43.0911 4776 wudfsvc - ok
13:25:44.0054 4776 ================ Scan global ===============================
13:25:44.0099 4776 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
13:25:44.0141 4776 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
13:25:44.0158 4776 [ AA137104CDFC81818A309CDE32ABB74A ] C:\Windows\system32\winsrv.dll
13:25:44.0180 4776 [ BC81150939BD52DBC7A08C245F1FB229 ] C:\Windows\system32\services.exe
13:25:44.0189 4776 C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.b ) - infected
13:25:44.0189 4776 C:\Windows\system32\services.exe - detected Virus.Win64.ZAccess.b (0)
13:25:44.0189 4776 ================ Scan MBR ==================================
13:25:44.0206 4776 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
13:25:44.0449 4776 \Device\Harddisk0\DR0 - ok
13:25:44.0450 4776 ================ Scan VBR ==================================
13:25:44.0453 4776 [ 23BF0B1E0C996B8CB16E17C42A0947C9 ] \Device\Harddisk0\DR0\Partition1
13:25:44.0455 4776 \Device\Harddisk0\DR0\Partition1 - ok
13:25:44.0483 4776 [ 7923FDD9FA9CECAC8BAA2DE8EBF31280 ] \Device\Harddisk0\DR0\Partition2
13:25:44.0485 4776 \Device\Harddisk0\DR0\Partition2 - ok
13:25:44.0505 4776 [ C8DD793D2A1094D87262A3E84C3AD2CC ] \Device\Harddisk0\DR0\Partition3
13:25:44.0506 4776 \Device\Harddisk0\DR0\Partition3 - ok
13:25:44.0507 4776 ============================================================
13:25:44.0507 4776 Scan finished
13:25:44.0507 4776 ============================================================
13:25:44.0524 4596 Detected object count: 2
13:25:44.0524 4596 Actual detected object count: 2
13:26:03.0810 4596 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - skipped by user
13:26:03.0811 4596 PLFlash DeviceIoControl Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
13:26:03.0851 4596 C:\Windows\system32\services.exe - copied to quarantine
13:26:05.0330 4596 C:\Users\Abelique\AppData\Local\{8ca7d3ce-f44a-a27b-a041-8f83e3901998}\@ - copied to quarantine
13:26:44.0570 4596 Backup copy found, using it..
13:26:44.0669 4596 C:\Users\Abelique\AppData\Local\{8ca7d3ce-f44a-a27b-a041-8f83e3901998}\@ - will be deleted on reboot
13:26:44.0671 4596 C:\Windows\system32\services.exe - will be cured on reboot
13:26:44.0671 4596 C:\Windows\system32\services.exe ( Virus.Win64.ZAccess.b ) - User select action: Cure
13:33:58.0738 3028 Deinitialize success
