Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

c:windows/system32/drivers/ipec.sys trojan horse hider


  • Please log in to reply
29 replies to this topic

#1 jdbangels

jdbangels

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 09:16 PM

MalwareBytes and AVG show that system is clean when scanned. However I get an AVG pop up that states that this file, c:windows/system32/drivers/ipec.sys, has been isolated. I connect to the internet through a wireless connection. Status shows connected but browser unable to connect. System is XP Home. Dell Optiplex DIM3000, Pentium 2.80GHz 2GB RAM.
What should I do??
Thank you

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 09:24 PM

Download

System look

Copy this script
:filefind
ipsec.sys

Paste it in the BOX

Click on Look

Post the log

#3 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 09:40 PM

SystemLook 30.07.11 by jpshortstuff
Log created at 20:35 on 29/12/2011 by
Administrator - Elevation successful

========== filefind ==========

Searching for "ipsec.sys"
C:\I386\IPSEC.SYS --a--c- 74752 bytes [00:33 21/09/2005] [10:00 04/08/2004] 64537AA5C003A6AFEEE1DF819062D0D1
C:\WINDOWS\$NtServicePackUninstall$\ipsec.sys -----c- 74752 bytes [23:39 08/09/2008] [10:00 04/08/2004] 64537AA5C003A6AFEEE1DF819062D0D1
C:\WINDOWS\ServicePackFiles\i386\ipsec.sys ------- 75264 bytes [12:01 05/08/2008] [19:19 13/04/2008] 23C74D75E36E7158768DD63D92789A91
C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys --a---- 75264 bytes [10:00 04/08/2004] [19:19 13/04/2008] 1DA6C0C952319F33A54C16C024FE905A

-= EOF =-

Edited by jdbangels, 29 December 2011 - 09:41 PM.


#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 09:49 PM

Download

http://swandog46.geekstogo.com/avenger2/avenger.zip

Extract and launch it

COpy the script and paste it in the BOX

Begin copying here:
Files to move:
C:\WINDOWS\ServicePackFiles\i386\ipsec.sys | C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys

Click on EXECUTE

Click YES,it will restart your computer.Log file should be generated in C:\avenger.txt.Make sure the script was executed successfully.

See if you can browse now,if you still face issues

Please download Farbar Service Scanner

http://download.bleepingcomputer.com/farbar/FSS.exe

Launch it

* Press "Scan".
* It will create a log (FSS.txt) in the same directory the tool is run.
* Please copy and paste the log to your reply.




Good luck

Edited by narenxp, 29 December 2011 - 09:53 PM.


#5 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 10:25 PM

When computer started up again, got the warning about the infected file being white listed.

Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Thu Dec 29 21:06:08 2011

21:06:03: Error: Invalid syntax in command:
"c:\WINDOWS\ ServicePackFiles\i386\ispec.sys - C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys"
Skipping line. (File move mode)
21:06:08: Error: Execution aborted by user!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Thu Dec 29 21:07:04 2011

21:07:00: Error: Invalid syntax in command:
"c:\WINDOWS\ ServicePackFiles\i386\ispec.sys C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys"
Skipping line. (File move mode)
21:07:04: Error: Execution aborted by user!

also,now seeing spybot window: avenger.exec:\docume 1]jennif 1 locals 1\temp
FraudAV.SJhorwPa

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 10:37 PM

Their seems to be a error in copying script

c:\WINDOWS\ ServicePackFiles\i386\ispec.sys

its ipsec and not ispec.sys

Can you copy the script again and try


Thanks

Edited by narenxp, 29 December 2011 - 10:39 PM.


#7 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 10:39 PM

Sorry, ran it again:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINDOWS\ServicePackFiles\i386\ipsec.sys" not found!
File move operation "C:\WINDOWS\ServicePackFiles\i386\ipsec.sys|C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

Still getting the AVG warning

#8 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 10:43 PM

Can you run the system look again?

Thanks

#9 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 10:45 PM

scan results:

Farbar Service Scanner
Ran by (administrator) on 29-12-2011 at 21:42:22
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============
Dnscache Service is not running. Checking service configuration:
The start type of Dnscache service is OK.
The ImagePath of Dnscache service is OK.
The ServiceDll of Dnscache service is OK.

Dhcp Service is not running. Checking service configuration:
The start type of Dhcp service is OK.
The ImagePath of Dhcp service is OK.
The ServiceDll of Dhcp service is OK.

Tcpip Service is not running. Checking service configuration:
The start type of Tcpip service is OK.
The ImagePath of Tcpip service is OK.

IpSec Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open IpSec registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open IpSec registry key. The service key does not exist.


Connection Status:
==============
Localhost is blocked.
There is no connection to network.
Attempt to access Google IP returned error: Other errors
Attempt to access Yahoo IP returend error: Other errors


Windows Firewall:
=============
sharedaccess Service is not running. Checking service configuration:
The start type of sharedaccess service is OK.
The ImagePath of sharedaccess service is OK.
The ServiceDll of sharedaccess service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking LEGACY_wscsvc: Attention! Unable to open LEGACY_wscsvc\0000 registry key. The key does not exist.


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
Avgtdix(8) Gpc(6) mfetdi2k(9) NetBT(5) PSched(7) Tcpip(3)
0x09000000040000000100000002000000030000000900000008000000050000000600000007000000

**** End of log ****

Edited by jdbangels, 29 December 2011 - 10:46 PM.


#10 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 10:56 PM

Try this script

Begin copying here:
Files to move:
C:\I386\IPSEC.SYS | C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys


#11 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 11:23 PM

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINDOWS\ServicePackFiles\i386\ipsec.sys" not found!
File move operation "C:\WINDOWS\ServicePackFiles\i386\ipsec.sys|C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.






Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File move operation "C:\I386\IPSEC.SYS|C:\WINDOWS\SYSTEM32\DRIVERS\ipsec.sys" completed successfully.

Completed script processing.

*******************

Finished! Terminate.



Still get AVG Resident Shield Alert

c:\Avenger\ipec.sys
Trojan horse Hider.OOW
Detected on open

Process name: c\zip.exe
Process ID: 348

Sucessfully moved to vault

#12 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 11:29 PM

What location does AVG points to?

Also Download

http://support.kaspersky.com/downloads/utils/tdsskiller.exe

Click on SCAN

Do not FIX anything,let me know if it finds infections

Edited by narenxp, 29 December 2011 - 11:30 PM.


#13 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 29 December 2011 - 11:45 PM

I ran it the other day and this is the result:

07:52:18.0828 1280 TDSS rootkit removing tool 2.6.22.0 Dec 7 2011 13:21:06
07:52:19.0031 1280 ============================================================
07:52:19.0031 1280 Current date / time: 2011/12/09 07:52:19.0031
07:52:19.0031 1280 SystemInfo:
07:52:19.0031 1280
07:52:19.0031 1280 OS Version: 5.1.2600 ServicePack: 3.0
07:52:19.0031 1280 Product type: Workstation
07:52:19.0031 1280 ComputerName: DGXBMQ71
07:52:19.0031 1280 UserName:
07:52:19.0031 1280 Windows directory: C:\WINDOWS
07:52:19.0031 1280 System windows directory: C:\WINDOWS
07:52:19.0031 1280 Processor architecture: Intel x86
07:52:19.0031 1280 Number of processors: 1
07:52:19.0031 1280 Page size: 0x1000
07:52:19.0031 1280 Boot type: Normal boot
07:52:19.0031 1280 ============================================================
07:52:21.0609 1280 Initialize success
07:52:28.0296 0256 ============================================================
07:52:28.0296 0256 Scan started
07:52:28.0296 0256 Mode: Manual;
07:52:28.0296 0256 ============================================================
07:52:29.0343 0256 Abiosdsk - ok
07:52:29.0421 0256 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
07:52:29.0421 0256 abp480n5 - ok
07:52:29.0562 0256 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
07:52:29.0578 0256 ACPI - ok
07:52:29.0718 0256 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
07:52:29.0718 0256 ACPIEC - ok
07:52:29.0781 0256 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
07:52:29.0796 0256 adpu160m - ok
07:52:29.0937 0256 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
07:52:29.0937 0256 aec - ok
07:52:30.0078 0256 AFD (d4d3cf0f19808decb945ae12bd5431e3) C:\WINDOWS\System32\drivers\afd.sys
07:52:30.0171 0256 AFD ( Rootkit.Win32.ZAccess.k ) - infected
07:52:30.0171 0256 AFD - detected Rootkit.Win32.ZAccess.k (0)
07:52:30.0312 0256 AFS2K (c685cc27a2e637f0dcb5a45e67cc6f74) C:\WINDOWS\system32\drivers\AFS2K.sys
07:52:30.0312 0256 AFS2K - ok
07:52:30.0406 0256 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
07:52:30.0406 0256 agp440 - ok
07:52:30.0500 0256 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
07:52:30.0500 0256 agpCPQ - ok
07:52:30.0625 0256 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
07:52:30.0625 0256 Aha154x - ok
07:52:30.0796 0256 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
07:52:30.0796 0256 aic78u2 - ok
07:52:30.0890 0256 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
07:52:30.0890 0256 aic78xx - ok
07:52:31.0031 0256 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
07:52:31.0031 0256 AliIde - ok
07:52:31.0171 0256 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
07:52:31.0171 0256 alim1541 - ok
07:52:31.0218 0256 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
07:52:31.0218 0256 amdagp - ok
07:52:31.0343 0256 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
07:52:31.0343 0256 amsint - ok
07:52:31.0484 0256 Andbus - ok
07:52:31.0531 0256 AndDiag - ok
07:52:31.0609 0256 AndGps - ok
07:52:31.0796 0256 ANDModem - ok
07:52:31.0906 0256 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
07:52:31.0906 0256 asc - ok
07:52:32.0296 0256 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
07:52:32.0296 0256 asc3350p - ok
07:52:32.0546 0256 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
07:52:32.0546 0256 asc3550 - ok
07:52:32.0625 0256 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
07:52:32.0625 0256 AsyncMac - ok
07:52:32.0750 0256 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
07:52:32.0750 0256 atapi - ok
07:52:32.0828 0256 Atdisk - ok
07:52:32.0953 0256 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
07:52:32.0953 0256 Atmarpc - ok
07:52:33.0062 0256 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
07:52:33.0062 0256 audstub - ok
07:52:33.0156 0256 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
07:52:33.0156 0256 AVGIDSDriver - ok
07:52:33.0296 0256 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
07:52:33.0296 0256 AVGIDSEH - ok
07:52:33.0375 0256 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
07:52:33.0375 0256 AVGIDSFilter - ok
07:52:33.0468 0256 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
07:52:33.0468 0256 AVGIDSShim - ok
07:52:33.0578 0256 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
07:52:33.0578 0256 Avgldx86 - ok
07:52:33.0718 0256 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
07:52:33.0718 0256 Avgmfx86 - ok
07:52:33.0765 0256 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
07:52:33.0765 0256 Avgrkx86 - ok
07:52:33.0890 0256 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
07:52:33.0906 0256 Avgtdix - ok
07:52:34.0031 0256 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
07:52:34.0031 0256 Beep - ok
07:52:34.0078 0256 bvrp_pci - ok
07:52:34.0171 0256 catchme - ok
07:52:34.0265 0256 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
07:52:34.0265 0256 cbidf - ok
07:52:34.0406 0256 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
07:52:34.0406 0256 cbidf2k - ok
07:52:34.0468 0256 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
07:52:34.0468 0256 cd20xrnt - ok
07:52:34.0578 0256 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
07:52:34.0578 0256 Cdaudio - ok
07:52:34.0671 0256 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
07:52:34.0671 0256 Cdfs - ok
07:52:34.0781 0256 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
07:52:34.0781 0256 Cdrom - ok
07:52:34.0921 0256 cfwids (7e6f7da1c4de5680820f964562548949) C:\WINDOWS\system32\drivers\cfwids.sys
07:52:34.0921 0256 cfwids - ok
07:52:34.0953 0256 Changer - ok
07:52:35.0125 0256 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
07:52:35.0125 0256 CmdIde - ok
07:52:35.0250 0256 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
07:52:35.0250 0256 Cpqarray - ok
07:52:35.0328 0256 CrucialSMBusScan - ok
07:52:35.0453 0256 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
07:52:35.0468 0256 dac2w2k - ok
07:52:35.0546 0256 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
07:52:35.0546 0256 dac960nt - ok
07:52:35.0656 0256 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
07:52:35.0656 0256 Disk - ok
07:52:35.0812 0256 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
07:52:35.0843 0256 dmboot - ok
07:52:35.0984 0256 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
07:52:35.0984 0256 dmio - ok
07:52:36.0125 0256 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
07:52:36.0125 0256 dmload - ok
07:52:36.0234 0256 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
07:52:36.0234 0256 DMusic - ok
07:52:36.0359 0256 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
07:52:36.0359 0256 dpti2o - ok
07:52:36.0453 0256 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
07:52:36.0453 0256 drmkaud - ok
07:52:36.0593 0256 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
07:52:36.0593 0256 drvmcdb - ok
07:52:36.0625 0256 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
07:52:36.0625 0256 drvnddm - ok
07:52:36.0796 0256 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
07:52:36.0796 0256 E100B - ok
07:52:36.0906 0256 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
07:52:36.0921 0256 Fastfat - ok
07:52:37.0046 0256 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
07:52:37.0046 0256 Fdc - ok
07:52:37.0125 0256 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
07:52:37.0125 0256 Fips - ok
07:52:37.0234 0256 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
07:52:37.0234 0256 Flpydisk - ok
07:52:37.0375 0256 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
07:52:37.0375 0256 FltMgr - ok
07:52:37.0500 0256 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
07:52:37.0500 0256 Fs_Rec - ok
07:52:37.0593 0256 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
07:52:37.0593 0256 Ftdisk - ok
07:52:37.0687 0256 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
07:52:37.0703 0256 GEARAspiWDM - ok
07:52:37.0828 0256 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
07:52:37.0828 0256 Gpc - ok
07:52:37.0984 0256 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
07:52:37.0984 0256 HidUsb - ok
07:52:38.0109 0256 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
07:52:38.0109 0256 hpn - ok
07:52:38.0203 0256 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
07:52:38.0218 0256 HPZid412 - ok
07:52:38.0343 0256 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
07:52:38.0343 0256 HPZipr12 - ok
07:52:38.0437 0256 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
07:52:38.0437 0256 HPZius12 - ok
07:52:38.0578 0256 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
07:52:38.0593 0256 HTTP - ok
07:52:38.0734 0256 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
07:52:38.0734 0256 i2omgmt - ok
07:52:38.0828 0256 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
07:52:38.0828 0256 i2omp - ok
07:52:38.0906 0256 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
07:52:38.0906 0256 i8042prt - ok
07:52:39.0031 0256 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
07:52:39.0078 0256 ialm - ok
07:52:39.0218 0256 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
07:52:39.0218 0256 Imapi - ok
07:52:39.0390 0256 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
07:52:39.0390 0256 ini910u - ok
07:52:39.0500 0256 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
07:52:39.0531 0256 IntelC51 - ok
07:52:39.0703 0256 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
07:52:39.0718 0256 IntelC52 - ok
07:52:39.0890 0256 IntelC53 (cf0b937710cec6ef39416edecd803cbb) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
07:52:39.0890 0256 IntelC53 - ok
07:52:40.0000 0256 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
07:52:40.0000 0256 IntelIde - ok
07:52:40.0093 0256 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
07:52:40.0093 0256 intelppm - ok
07:52:40.0250 0256 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
07:52:40.0250 0256 Ip6Fw - ok
07:52:40.0359 0256 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
07:52:40.0359 0256 IpFilterDriver - ok
07:52:40.0515 0256 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
07:52:40.0515 0256 IpInIp - ok
07:52:40.0593 0256 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
07:52:40.0593 0256 IpNat - ok
07:52:40.0734 0256 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
07:52:40.0734 0256 IPSec - ok
07:52:40.0890 0256 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
07:52:40.0890 0256 IRENUM - ok
07:52:41.0015 0256 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
07:52:41.0015 0256 isapnp - ok
07:52:41.0156 0256 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
07:52:41.0156 0256 Kbdclass - ok
07:52:41.0296 0256 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
07:52:41.0296 0256 kbdhid - ok
07:52:41.0343 0256 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
07:52:41.0343 0256 kmixer - ok
07:52:41.0437 0256 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
07:52:41.0453 0256 KSecDD - ok
07:52:41.0500 0256 Lavasoft Kernexplorer - ok
07:52:41.0625 0256 lbrtfdc - ok
07:52:41.0781 0256 LMIInfo - ok
07:52:41.0968 0256 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
07:52:41.0968 0256 lmimirr - ok
07:52:42.0140 0256 LMIRfsClientNP - ok
07:52:42.0218 0256 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
07:52:42.0218 0256 LMIRfsDriver - ok
07:52:42.0390 0256 mfeapfk (84d59a3eddfb9438fb94f7f80d37859d) C:\WINDOWS\system32\drivers\mfeapfk.sys
07:52:42.0390 0256 mfeapfk - ok
07:52:42.0546 0256 mfefirek (d5f89b4934960c70882924d992c6abfc) C:\WINDOWS\system32\drivers\mfefirek.sys
07:52:42.0562 0256 mfefirek - ok
07:52:42.0687 0256 mfendisk (549dd4966bf0b1d1fc205ca0755a745b) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:52:42.0687 0256 mfendisk - ok
07:52:42.0687 0256 mfendiskmp (549dd4966bf0b1d1fc205ca0755a745b) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
07:52:42.0703 0256 mfendiskmp - ok
07:52:42.0843 0256 mferkdet (c9eda1eada2ab6e34cd1a10c3a24ab25) C:\WINDOWS\system32\drivers\mferkdet.sys
07:52:42.0859 0256 mferkdet - ok
07:52:43.0031 0256 mfetdi2k (e6c5f7aade5a31c057d73201acfe8adf) C:\WINDOWS\system32\drivers\mfetdi2k.sys
07:52:43.0031 0256 mfetdi2k - ok
07:52:43.0250 0256 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
07:52:43.0250 0256 mnmdd - ok
07:52:43.0296 0256 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
07:52:43.0312 0256 Modem - ok
07:52:43.0468 0256 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
07:52:43.0468 0256 MODEMCSA - ok
07:52:43.0578 0256 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
07:52:43.0593 0256 mohfilt - ok
07:52:43.0718 0256 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
07:52:43.0718 0256 Mouclass - ok
07:52:43.0796 0256 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
07:52:43.0796 0256 mouhid - ok
07:52:43.0937 0256 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
07:52:43.0937 0256 MountMgr - ok
07:52:44.0125 0256 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
07:52:44.0125 0256 MpFilter - ok
07:52:44.0281 0256 MpKsl19382b12 - ok
07:52:44.0296 0256 MpKsl1cfe22a1 - ok
07:52:44.0312 0256 MpKsl2ec0dbf1 - ok
07:52:44.0312 0256 MpKsl38e5837b - ok
07:52:44.0328 0256 MpKsl39c73808 - ok
07:52:44.0328 0256 MpKsl3e5a6440 - ok
07:52:44.0343 0256 MpKsl4c7e5043 - ok
07:52:44.0343 0256 MpKsl4d7df669 - ok
07:52:44.0359 0256 MpKsl4de62e75 - ok
07:52:44.0359 0256 MpKsl508730c5 - ok
07:52:44.0375 0256 MpKsl6a8a700c - ok
07:52:44.0390 0256 MpKsl7c287065 - ok
07:52:44.0390 0256 MpKsl80974bb6 - ok
07:52:44.0406 0256 MpKsl9f57362b - ok
07:52:44.0406 0256 MpKsl9fb0c685 - ok
07:52:44.0421 0256 MpKslab944928 - ok
07:52:44.0437 0256 MpKslaba31087 - ok
07:52:44.0437 0256 MpKslaff4a33d - ok
07:52:44.0453 0256 MpKslb73d7df2 - ok
07:52:44.0468 0256 MpKslb8ba437a - ok
07:52:44.0468 0256 MpKsld88e6d05 - ok
07:52:44.0484 0256 MpKslfc29b291 - ok
07:52:44.0562 0256 MpKslfef52473 (5f53edfead46fa7adb78eee9ecce8fdf) c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0B00DB61-51B4-4D30-9260-3B6779E28F6D}\MpKslfef52473.sys
07:52:44.0562 0256 MpKslfef52473 - ok
07:52:44.0734 0256 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
07:52:44.0734 0256 mraid35x - ok
07:52:44.0875 0256 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
07:52:44.0875 0256 MREMP50 - ok
07:52:44.0890 0256 MREMP50a64 - ok
07:52:44.0890 0256 MREMPR5 - ok
07:52:44.0906 0256 MRENDIS5 - ok
07:52:44.0921 0256 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
07:52:44.0921 0256 MRESP50 - ok
07:52:44.0968 0256 MRESP50a64 - ok
07:52:45.0109 0256 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
07:52:45.0109 0256 MRxDAV - ok
07:52:45.0218 0256 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
07:52:45.0250 0256 MRxSmb - ok
07:52:45.0453 0256 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
07:52:45.0453 0256 Msfs - ok
07:52:45.0609 0256 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
07:52:45.0609 0256 MSKSSRV - ok
07:52:45.0703 0256 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
07:52:45.0703 0256 MSPCLOCK - ok
07:52:45.0859 0256 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
07:52:45.0859 0256 MSPQM - ok
07:52:45.0968 0256 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
07:52:45.0968 0256 mssmbios - ok
07:52:46.0062 0256 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
07:52:46.0078 0256 Mup - ok
07:52:46.0218 0256 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
07:52:46.0218 0256 NDIS - ok
07:52:46.0375 0256 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
07:52:46.0390 0256 NdisTapi - ok
07:52:46.0421 0256 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
07:52:46.0421 0256 Ndisuio - ok
07:52:46.0562 0256 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
07:52:46.0562 0256 NdisWan - ok
07:52:46.0687 0256 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
07:52:46.0703 0256 NDProxy - ok
07:52:46.0828 0256 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
07:52:46.0828 0256 NetBIOS - ok
07:52:46.0968 0256 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
07:52:46.0968 0256 NetBT - ok
07:52:47.0156 0256 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
07:52:47.0156 0256 Npfs - ok
07:52:47.0234 0256 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
07:52:47.0250 0256 Ntfs - ok
07:52:47.0390 0256 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
07:52:47.0390 0256 Null - ok
07:52:47.0562 0256 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
07:52:47.0609 0256 nv - ok
07:52:47.0750 0256 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
07:52:47.0750 0256 NwlnkFlt - ok
07:52:47.0812 0256 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
07:52:47.0812 0256 NwlnkFwd - ok
07:52:47.0968 0256 OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
07:52:47.0968 0256 OMCI - ok
07:52:48.0078 0256 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
07:52:48.0078 0256 Parport - ok
07:52:48.0203 0256 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
07:52:48.0203 0256 PartMgr - ok
07:52:48.0312 0256 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
07:52:48.0312 0256 ParVdm - ok
07:52:48.0406 0256 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
07:52:48.0406 0256 PCI - ok
07:52:48.0531 0256 PCIDump - ok
07:52:48.0640 0256 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
07:52:48.0656 0256 PCIIde - ok
07:52:48.0765 0256 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
07:52:48.0765 0256 Pcmcia - ok
07:52:48.0875 0256 PDCOMP - ok
07:52:48.0953 0256 PDFRAME - ok
07:52:49.0031 0256 PDRELI - ok
07:52:49.0125 0256 PDRFRAME - ok
07:52:49.0234 0256 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
07:52:49.0234 0256 perc2 - ok
07:52:49.0328 0256 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
07:52:49.0343 0256 perc2hib - ok
07:52:49.0484 0256 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
07:52:49.0484 0256 PptpMiniport - ok
07:52:49.0640 0256 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
07:52:49.0640 0256 PSched - ok
07:52:49.0765 0256 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
07:52:49.0765 0256 Ptilink - ok
07:52:49.0812 0256 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
07:52:49.0812 0256 PxHelp20 - ok
07:52:49.0968 0256 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
07:52:49.0968 0256 ql1080 - ok
07:52:50.0015 0256 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
07:52:50.0015 0256 Ql10wnt - ok
07:52:50.0187 0256 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
07:52:50.0187 0256 ql12160 - ok
07:52:50.0312 0256 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
07:52:50.0312 0256 ql1240 - ok
07:52:50.0390 0256 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
07:52:50.0390 0256 ql1280 - ok
07:52:50.0468 0256 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
07:52:50.0468 0256 RasAcd - ok
07:52:50.0625 0256 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
07:52:50.0625 0256 Rasl2tp - ok
07:52:50.0703 0256 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
07:52:50.0718 0256 RasPppoe - ok
07:52:50.0828 0256 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
07:52:50.0843 0256 Raspti - ok
07:52:50.0875 0256 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
07:52:50.0890 0256 Rdbss - ok
07:52:51.0015 0256 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
07:52:51.0015 0256 RDPCDD - ok
07:52:51.0140 0256 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
07:52:51.0140 0256 rdpdr - ok
07:52:51.0265 0256 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
07:52:51.0265 0256 RDPWD - ok
07:52:51.0406 0256 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
07:52:51.0406 0256 redbook - ok
07:52:51.0609 0256 rt2870 (24a0d16d170194b5812ea08542ebdb62) C:\WINDOWS\system32\DRIVERS\rt2870.sys
07:52:51.0640 0256 rt2870 - ok
07:52:51.0828 0256 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS
07:52:51.0828 0256 SASDIFSV - ok
07:52:51.0828 0256 SASENUM - ok
07:52:51.0843 0256 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys
07:52:51.0859 0256 SASKUTIL - ok
07:52:52.0031 0256 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
07:52:52.0062 0256 Secdrv - ok
07:52:52.0218 0256 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
07:52:52.0250 0256 senfilt - ok
07:52:52.0390 0256 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
07:52:52.0390 0256 serenum - ok
07:52:52.0500 0256 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
07:52:52.0500 0256 Serial - ok
07:52:52.0625 0256 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
07:52:52.0625 0256 Sfloppy - ok
07:52:52.0750 0256 Simbad - ok
07:52:52.0796 0256 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
07:52:52.0796 0256 sisagp - ok
07:52:52.0968 0256 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys
07:52:52.0968 0256 smwdm - ok
07:52:53.0140 0256 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
07:52:53.0140 0256 Sparrow - ok
07:52:53.0187 0256 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
07:52:53.0203 0256 splitter - ok
07:52:53.0328 0256 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
07:52:53.0343 0256 sr - ok
07:52:53.0406 0256 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
07:52:53.0421 0256 Srv - ok
07:52:53.0562 0256 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
07:52:53.0562 0256 sscdbhk5 - ok
07:52:53.0656 0256 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
07:52:53.0656 0256 ssrtln - ok
07:52:53.0750 0256 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
07:52:53.0750 0256 StillCam - ok
07:52:53.0843 0256 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
07:52:53.0843 0256 swenum - ok
07:52:53.0953 0256 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
07:52:53.0953 0256 swmidi - ok
07:52:54.0078 0256 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
07:52:54.0078 0256 symc810 - ok
07:52:54.0171 0256 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
07:52:54.0171 0256 symc8xx - ok
07:52:54.0296 0256 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
07:52:54.0296 0256 sym_hi - ok
07:52:54.0375 0256 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
07:52:54.0375 0256 sym_u3 - ok
07:52:54.0515 0256 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
07:52:54.0515 0256 sysaudio - ok
07:52:54.0687 0256 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
07:52:54.0703 0256 Tcpip - ok
07:52:54.0859 0256 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
07:52:54.0859 0256 TDPIPE - ok
07:52:54.0968 0256 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
07:52:54.0984 0256 TDTCP - ok
07:52:55.0078 0256 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
07:52:55.0078 0256 TermDD - ok
07:52:55.0187 0256 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
07:52:55.0187 0256 tfsnboio - ok
07:52:55.0281 0256 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
07:52:55.0281 0256 tfsncofs - ok
07:52:55.0328 0256 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
07:52:55.0328 0256 tfsndrct - ok
07:52:55.0421 0256 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
07:52:55.0421 0256 tfsndres - ok
07:52:55.0484 0256 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
07:52:55.0484 0256 tfsnifs - ok
07:52:55.0593 0256 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
07:52:55.0593 0256 tfsnopio - ok
07:52:55.0671 0256 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
07:52:55.0671 0256 tfsnpool - ok
07:52:55.0734 0256 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
07:52:55.0734 0256 tfsnudf - ok
07:52:55.0843 0256 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
07:52:55.0843 0256 tfsnudfa - ok
07:52:56.0015 0256 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
07:52:56.0015 0256 TosIde - ok
07:52:56.0187 0256 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
07:52:56.0187 0256 Udfs - ok
07:52:56.0359 0256 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
07:52:56.0359 0256 ultra - ok
07:52:56.0468 0256 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
07:52:56.0484 0256 Update - ok
07:52:56.0640 0256 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys
07:52:56.0640 0256 USBAAPL - ok
07:52:56.0703 0256 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
07:52:56.0703 0256 usbccgp - ok
07:52:56.0828 0256 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
07:52:56.0843 0256 usbehci - ok
07:52:56.0968 0256 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
07:52:56.0968 0256 usbhub - ok
07:52:57.0078 0256 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
07:52:57.0078 0256 usbprint - ok
07:52:57.0171 0256 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
07:52:57.0171 0256 usbscan - ok
07:52:57.0296 0256 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
07:52:57.0296 0256 USBSTOR - ok
07:52:57.0390 0256 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
07:52:57.0406 0256 usbuhci - ok
07:52:57.0484 0256 USB_RNDIS_XP (bee793d4a059caea55d6ac20e19b3a8f) C:\WINDOWS\system32\DRIVERS\usb8023.sys
07:52:57.0484 0256 USB_RNDIS_XP - ok
07:52:57.0578 0256 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
07:52:57.0578 0256 VgaSave - ok
07:52:57.0671 0256 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
07:52:57.0671 0256 viaagp - ok
07:52:57.0828 0256 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
07:52:57.0828 0256 ViaIde - ok
07:52:57.0968 0256 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
07:52:57.0968 0256 VolSnap - ok
07:52:58.0046 0256 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
07:52:58.0046 0256 Wanarp - ok
07:52:58.0156 0256 wanatw - ok
07:52:58.0203 0256 WDICA - ok
07:52:58.0328 0256 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
07:52:58.0328 0256 wdmaud - ok
07:52:58.0546 0256 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
07:52:58.0546 0256 WpdUsb - ok
07:52:58.0656 0256 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
07:52:58.0656 0256 WudfPf - ok
07:52:58.0812 0256 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
07:52:58.0812 0256 WudfRd - ok
07:52:58.0890 0256 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0
07:52:58.0906 0256 \Device\Harddisk0\DR0 - ok
07:52:58.0921 0256 Boot (0x1200) (6aca6b1e47d8b770c8048b440d544a87) \Device\Harddisk0\DR0\Partition0
07:52:58.0921 0256 \Device\Harddisk0\DR0\Partition0 - ok
07:52:58.0921 0256 ============================================================
07:52:58.0921 0256 Scan finished
07:52:58.0921 0256 ============================================================
07:52:58.0937 3176 Detected object count: 1
07:52:58.0937 3176 Actual detected object count: 1
07:53:09.0390 3176 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\afd.sys) error 1813
07:53:16.0078 3176 Backup copy found, using it..
07:53:16.0234 3176 C:\WINDOWS\System32\drivers\afd.sys - will be cured on reboot
07:53:24.0453 3176 AFD ( Rootkit.Win32.ZAccess.k ) - User select action: Cure
07:53:37.0937 0176 Deinitialize success

Results running now;

22:41:01.0281 4092 TDSS rootkit removing tool 2.6.22.0 Dec 7 2011 13:21:06
22:41:01.0296 4092 ============================================================
22:41:01.0296 4092 Current date / time: 2011/12/29 22:41:01.0296
22:41:01.0296 4092 SystemInfo:
22:41:01.0296 4092
22:41:01.0296 4092 OS Version: 5.1.2600 ServicePack: 3.0
22:41:01.0296 4092 Product type: Workstation
22:41:01.0296 4092 ComputerName: DGXBMQ71
22:41:01.0296 4092 UserName:
22:41:01.0296 4092 Windows directory: C:\WINDOWS
22:41:01.0296 4092 System windows directory: C:\WINDOWS
22:41:01.0296 4092 Processor architecture: Intel x86
22:41:01.0296 4092 Number of processors: 1
22:41:01.0296 4092 Page size: 0x1000
22:41:01.0296 4092 Boot type: Normal boot
22:41:01.0296 4092 ============================================================
22:41:02.0593 4092 Initialize success
22:41:04.0031 3468 ============================================================
22:41:04.0031 3468 Scan started
22:41:04.0031 3468 Mode: Manual;
22:41:04.0031 3468 ============================================================
22:41:05.0281 3468 67564505 - ok
22:41:05.0312 3468 Abiosdsk - ok
22:41:05.0390 3468 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
22:41:05.0390 3468 abp480n5 - ok
22:41:05.0578 3468 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:41:05.0578 3468 ACPI - ok
22:41:05.0734 3468 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
22:41:05.0734 3468 ACPIEC - ok
22:41:05.0796 3468 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
22:41:05.0796 3468 adpu160m - ok
22:41:05.0890 3468 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
22:41:05.0890 3468 aec - ok
22:41:06.0046 3468 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
22:41:06.0046 3468 AFD - ok
22:41:06.0187 3468 AFS2K (c685cc27a2e637f0dcb5a45e67cc6f74) C:\WINDOWS\system32\drivers\AFS2K.sys
22:41:06.0187 3468 AFS2K - ok
22:41:06.0265 3468 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
22:41:06.0265 3468 agp440 - ok
22:41:06.0375 3468 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
22:41:06.0375 3468 agpCPQ - ok
22:41:06.0484 3468 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
22:41:06.0484 3468 Aha154x - ok
22:41:06.0578 3468 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
22:41:06.0578 3468 aic78u2 - ok
22:41:06.0687 3468 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
22:41:06.0687 3468 aic78xx - ok
22:41:06.0796 3468 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
22:41:06.0796 3468 AliIde - ok
22:41:06.0875 3468 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
22:41:06.0875 3468 alim1541 - ok
22:41:07.0093 3468 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
22:41:07.0109 3468 amdagp - ok
22:41:07.0171 3468 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
22:41:07.0171 3468 amsint - ok
22:41:07.0296 3468 Andbus - ok
22:41:07.0359 3468 AndDiag - ok
22:41:07.0375 3468 AndGps - ok
22:41:07.0406 3468 ANDModem - ok
22:41:07.0484 3468 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
22:41:07.0484 3468 asc - ok
22:41:07.0953 3468 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
22:41:07.0953 3468 asc3350p - ok
22:41:08.0031 3468 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
22:41:08.0031 3468 asc3550 - ok
22:41:08.0203 3468 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:41:08.0203 3468 AsyncMac - ok
22:41:08.0328 3468 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
22:41:08.0328 3468 atapi - ok
22:41:08.0453 3468 Atdisk - ok
22:41:08.0515 3468 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:41:08.0515 3468 Atmarpc - ok
22:41:08.0671 3468 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
22:41:08.0687 3468 audstub - ok
22:41:08.0781 3468 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
22:41:08.0781 3468 AVGIDSDriver - ok
22:41:08.0875 3468 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
22:41:08.0875 3468 AVGIDSEH - ok
22:41:08.0968 3468 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
22:41:08.0968 3468 AVGIDSFilter - ok
22:41:09.0062 3468 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
22:41:09.0062 3468 AVGIDSShim - ok
22:41:09.0171 3468 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
22:41:09.0171 3468 Avgldx86 - ok
22:41:09.0312 3468 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
22:41:09.0312 3468 Avgmfx86 - ok
22:41:09.0390 3468 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
22:41:09.0406 3468 Avgrkx86 - ok
22:41:09.0500 3468 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
22:41:09.0500 3468 Avgtdix - ok
22:41:09.0625 3468 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
22:41:09.0625 3468 Beep - ok
22:41:09.0671 3468 bvrp_pci - ok
22:41:09.0765 3468 catchme - ok
22:41:09.0921 3468 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
22:41:09.0937 3468 cbidf - ok
22:41:09.0968 3468 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
22:41:09.0968 3468 cbidf2k - ok
22:41:10.0140 3468 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
22:41:10.0140 3468 cd20xrnt - ok
22:41:10.0203 3468 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
22:41:10.0203 3468 Cdaudio - ok
22:41:10.0296 3468 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
22:41:10.0296 3468 Cdfs - ok
22:41:10.0390 3468 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:41:10.0390 3468 Cdrom - ok
22:41:10.0500 3468 cfwids (7e6f7da1c4de5680820f964562548949) C:\WINDOWS\system32\drivers\cfwids.sys
22:41:10.0500 3468 cfwids - ok
22:41:10.0562 3468 Changer - ok
22:41:10.0687 3468 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
22:41:10.0687 3468 CmdIde - ok
22:41:10.0859 3468 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
22:41:10.0859 3468 Cpqarray - ok
22:41:10.0968 3468 CrucialSMBusScan - ok
22:41:11.0140 3468 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
22:41:11.0140 3468 dac2w2k - ok
22:41:11.0218 3468 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
22:41:11.0218 3468 dac960nt - ok
22:41:11.0328 3468 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
22:41:11.0328 3468 Disk - ok
22:41:11.0500 3468 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
22:41:11.0515 3468 dmboot - ok
22:41:11.0656 3468 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
22:41:11.0656 3468 dmio - ok
22:41:11.0781 3468 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
22:41:11.0781 3468 dmload - ok
22:41:11.0859 3468 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
22:41:11.0859 3468 DMusic - ok
22:41:12.0031 3468 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
22:41:12.0031 3468 dpti2o - ok
22:41:12.0109 3468 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
22:41:12.0109 3468 drmkaud - ok
22:41:12.0250 3468 drvmcdb (e814854e6b246ccf498874839ab64d77) C:\WINDOWS\system32\drivers\drvmcdb.sys
22:41:12.0250 3468 drvmcdb - ok
22:41:12.0406 3468 drvnddm (ee83a4ebae70bc93cf14879d062f548b) C:\WINDOWS\system32\drivers\drvnddm.sys
22:41:12.0406 3468 drvnddm - ok
22:41:12.0484 3468 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys
22:41:12.0484 3468 E100B - ok
22:41:12.0609 3468 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
22:41:12.0609 3468 Fastfat - ok
22:41:12.0750 3468 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
22:41:12.0750 3468 Fdc - ok
22:41:12.0843 3468 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
22:41:12.0843 3468 Fips - ok
22:41:12.0953 3468 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
22:41:12.0953 3468 Flpydisk - ok
22:41:13.0093 3468 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
22:41:13.0093 3468 FltMgr - ok
22:41:13.0234 3468 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:41:13.0234 3468 Fs_Rec - ok
22:41:13.0312 3468 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:41:13.0312 3468 Ftdisk - ok
22:41:13.0406 3468 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
22:41:13.0406 3468 GEARAspiWDM - ok
22:41:13.0546 3468 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:41:13.0546 3468 Gpc - ok
22:41:13.0687 3468 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:41:13.0687 3468 HidUsb - ok
22:41:13.0812 3468 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
22:41:13.0812 3468 hpn - ok
22:41:13.0968 3468 HPZid412 (9f1d80908658eb7f1bf70809e0b51470) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
22:41:13.0968 3468 HPZid412 - ok
22:41:14.0062 3468 HPZipr12 (f7e3e9d50f9cd3de28085a8fdaa0a1c3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
22:41:14.0062 3468 HPZipr12 - ok
22:41:14.0234 3468 HPZius12 (cf1b7951b4ec8d13f3c93b74bb2b461b) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
22:41:14.0234 3468 HPZius12 - ok
22:41:14.0406 3468 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
22:41:14.0421 3468 HTTP - ok
22:41:14.0562 3468 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
22:41:14.0562 3468 i2omgmt - ok
22:41:14.0593 3468 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
22:41:14.0609 3468 i2omp - ok
22:41:14.0750 3468 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:41:14.0750 3468 i8042prt - ok
22:41:14.0828 3468 ialm (9a883c3c4d91292c0d09de7c728e781c) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
22:41:14.0828 3468 ialm - ok
22:41:14.0968 3468 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
22:41:14.0968 3468 Imapi - ok
22:41:15.0156 3468 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
22:41:15.0156 3468 ini910u - ok
22:41:15.0359 3468 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
22:41:15.0375 3468 IntelC51 - ok
22:41:15.0546 3468 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
22:41:15.0546 3468 IntelC52 - ok
22:41:15.0718 3468 IntelC53 (cf0b937710cec6ef39416edecd803cbb) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
22:41:15.0718 3468 IntelC53 - ok
22:41:15.0859 3468 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
22:41:15.0859 3468 IntelIde - ok
22:41:16.0000 3468 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:41:16.0000 3468 intelppm - ok
22:41:16.0281 3468 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
22:41:16.0281 3468 Ip6Fw - ok
22:41:16.0375 3468 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:41:16.0375 3468 IpFilterDriver - ok
22:41:16.0515 3468 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:41:16.0515 3468 IpInIp - ok
22:41:16.0625 3468 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:41:16.0625 3468 IpNat - ok
22:41:16.0734 3468 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
22:41:16.0734 3468 IRENUM - ok
22:41:16.0812 3468 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:41:16.0812 3468 isapnp - ok
22:41:16.0906 3468 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:41:16.0906 3468 Kbdclass - ok
22:41:17.0093 3468 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:41:17.0093 3468 kbdhid - ok
22:41:17.0187 3468 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
22:41:17.0187 3468 kmixer - ok
22:41:17.0281 3468 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
22:41:17.0281 3468 KSecDD - ok
22:41:17.0343 3468 Lavasoft Kernexplorer - ok
22:41:17.0468 3468 lbrtfdc - ok
22:41:17.0593 3468 LMIInfo - ok
22:41:17.0765 3468 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
22:41:17.0765 3468 lmimirr - ok
22:41:17.0843 3468 LMIRfsClientNP - ok
22:41:17.0968 3468 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
22:41:17.0968 3468 LMIRfsDriver - ok
22:41:18.0140 3468 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys
22:41:18.0140 3468 MBAMProtector - ok
22:41:18.0281 3468 mfeapfk (84d59a3eddfb9438fb94f7f80d37859d) C:\WINDOWS\system32\drivers\mfeapfk.sys
22:41:18.0281 3468 mfeapfk - ok
22:41:18.0390 3468 mfefirek (d5f89b4934960c70882924d992c6abfc) C:\WINDOWS\system32\drivers\mfefirek.sys
22:41:18.0390 3468 mfefirek - ok
22:41:18.0484 3468 mfendisk (549dd4966bf0b1d1fc205ca0755a745b) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
22:41:18.0484 3468 mfendisk - ok
22:41:18.0500 3468 mfendiskmp (549dd4966bf0b1d1fc205ca0755a745b) C:\WINDOWS\system32\DRIVERS\mfendisk.sys
22:41:18.0500 3468 mfendiskmp - ok
22:41:18.0656 3468 mferkdet (c9eda1eada2ab6e34cd1a10c3a24ab25) C:\WINDOWS\system32\drivers\mferkdet.sys
22:41:18.0656 3468 mferkdet - ok
22:41:18.0718 3468 mfetdi2k (e6c5f7aade5a31c057d73201acfe8adf) C:\WINDOWS\system32\drivers\mfetdi2k.sys
22:41:18.0734 3468 mfetdi2k - ok
22:41:18.0890 3468 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
22:41:18.0890 3468 mnmdd - ok
22:41:18.0984 3468 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
22:41:18.0984 3468 Modem - ok
22:41:19.0140 3468 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
22:41:19.0140 3468 MODEMCSA - ok
22:41:19.0296 3468 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
22:41:19.0296 3468 mohfilt - ok
22:41:19.0343 3468 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:41:19.0343 3468 Mouclass - ok
22:41:19.0468 3468 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:41:19.0468 3468 mouhid - ok
22:41:19.0546 3468 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
22:41:19.0546 3468 MountMgr - ok
22:41:19.0656 3468 MpFilter (fee0baded54222e9f1dae9541212aab1) C:\WINDOWS\system32\DRIVERS\MpFilter.sys
22:41:19.0656 3468 MpFilter - ok
22:41:19.0812 3468 MpKsl19382b12 - ok
22:41:19.0828 3468 MpKsl1cfe22a1 - ok
22:41:19.0843 3468 MpKsl2ec0dbf1 - ok
22:41:19.0843 3468 MpKsl38e5837b - ok
22:41:19.0859 3468 MpKsl39c73808 - ok
22:41:19.0875 3468 MpKsl3e5a6440 - ok
22:41:19.0875 3468 MpKsl4c7e5043 - ok
22:41:19.0890 3468 MpKsl4d7df669 - ok
22:41:19.0906 3468 MpKsl4de62e75 - ok
22:41:19.0906 3468 MpKsl508730c5 - ok
22:41:19.0921 3468 MpKsl6a8a700c - ok
22:41:19.0937 3468 MpKsl7c287065 - ok
22:41:19.0937 3468 MpKsl80974bb6 - ok
22:41:19.0953 3468 MpKsl9f57362b - ok
22:41:19.0968 3468 MpKsl9fb0c685 - ok
22:41:19.0968 3468 MpKslab944928 - ok
22:41:19.0984 3468 MpKslaba31087 - ok
22:41:19.0984 3468 MpKslaff4a33d - ok
22:41:20.0000 3468 MpKslb73d7df2 - ok
22:41:20.0015 3468 MpKslb8ba437a - ok
22:41:20.0015 3468 MpKsld88e6d05 - ok
22:41:20.0031 3468 MpKslfc29b291 - ok
22:41:20.0250 3468 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
22:41:20.0250 3468 mraid35x - ok
22:41:20.0390 3468 MREMP50 (9bd4dcb5412921864a7aacdedfbd1923) C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS
22:41:20.0390 3468 MREMP50 - ok
22:41:20.0406 3468 MREMP50a64 - ok
22:41:20.0421 3468 MREMPR5 - ok
22:41:20.0421 3468 MRENDIS5 - ok
22:41:20.0453 3468 MRESP50 (07c02c892e8e1a72d6bf35004f0e9c5e) C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS
22:41:20.0453 3468 MRESP50 - ok
22:41:20.0453 3468 MRESP50a64 - ok
22:41:20.0578 3468 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:41:20.0593 3468 MRxDAV - ok
22:41:20.0750 3468 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:41:20.0750 3468 MRxSmb - ok
22:41:20.0796 3468 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
22:41:20.0812 3468 Msfs - ok
22:41:20.0953 3468 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:41:20.0953 3468 MSKSSRV - ok
22:41:21.0046 3468 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:41:21.0046 3468 MSPCLOCK - ok
22:41:21.0234 3468 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
22:41:21.0234 3468 MSPQM - ok
22:41:21.0328 3468 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:41:21.0328 3468 mssmbios - ok
22:41:21.0421 3468 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
22:41:21.0421 3468 Mup - ok
22:41:21.0562 3468 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
22:41:21.0578 3468 NDIS - ok
22:41:21.0734 3468 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:41:21.0734 3468 NdisTapi - ok
22:41:21.0875 3468 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:41:21.0875 3468 Ndisuio - ok
22:41:21.0906 3468 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:41:21.0906 3468 NdisWan - ok
22:41:22.0046 3468 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
22:41:22.0046 3468 NDProxy - ok
22:41:22.0250 3468 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
22:41:22.0250 3468 NetBIOS - ok
22:41:22.0390 3468 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
22:41:22.0390 3468 NetBT - ok
22:41:22.0578 3468 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
22:41:22.0578 3468 Npfs - ok
22:41:22.0734 3468 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
22:41:22.0734 3468 Ntfs - ok
22:41:22.0906 3468 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
22:41:22.0906 3468 Null - ok
22:41:23.0031 3468 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
22:41:23.0046 3468 nv - ok
22:41:23.0234 3468 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:41:23.0250 3468 NwlnkFlt - ok
22:41:23.0312 3468 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:41:23.0312 3468 NwlnkFwd - ok
22:41:23.0468 3468 OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
22:41:23.0468 3468 OMCI - ok
22:41:23.0562 3468 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
22:41:23.0562 3468 Parport - ok
22:41:23.0656 3468 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
22:41:23.0656 3468 PartMgr - ok
22:41:23.0765 3468 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
22:41:23.0765 3468 ParVdm - ok
22:41:23.0906 3468 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
22:41:23.0906 3468 PCI - ok
22:41:23.0937 3468 PCIDump - ok
22:41:24.0109 3468 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
22:41:24.0109 3468 PCIIde - ok
22:41:24.0265 3468 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
22:41:24.0265 3468 Pcmcia - ok
22:41:24.0406 3468 PDCOMP - ok
22:41:24.0484 3468 PDFRAME - ok
22:41:24.0562 3468 PDRELI - ok
22:41:24.0718 3468 PDRFRAME - ok
22:41:24.0828 3468 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
22:41:24.0828 3468 perc2 - ok
22:41:24.0953 3468 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
22:41:24.0953 3468 perc2hib - ok
22:41:25.0171 3468 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:41:25.0171 3468 PptpMiniport - ok
22:41:25.0250 3468 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
22:41:25.0250 3468 PSched - ok
22:41:25.0328 3468 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:41:25.0328 3468 Ptilink - ok
22:41:25.0468 3468 PxHelp20 (1962166e0ceb740704f30fa55ad3d509) C:\WINDOWS\system32\Drivers\PxHelp20.sys
22:41:25.0468 3468 PxHelp20 - ok
22:41:25.0640 3468 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
22:41:25.0640 3468 ql1080 - ok
22:41:25.0812 3468 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
22:41:25.0812 3468 Ql10wnt - ok
22:41:25.0859 3468 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
22:41:25.0859 3468 ql12160 - ok
22:41:26.0015 3468 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
22:41:26.0015 3468 ql1240 - ok
22:41:26.0218 3468 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
22:41:26.0218 3468 ql1280 - ok
22:41:26.0312 3468 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:41:26.0312 3468 RasAcd - ok
22:41:26.0421 3468 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:41:26.0421 3468 Rasl2tp - ok
22:41:26.0500 3468 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:41:26.0500 3468 RasPppoe - ok
22:41:26.0593 3468 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
22:41:26.0593 3468 Raspti - ok
22:41:26.0734 3468 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:41:26.0734 3468 Rdbss - ok
22:41:26.0859 3468 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:41:26.0875 3468 RDPCDD - ok
22:41:26.0937 3468 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:41:26.0953 3468 rdpdr - ok
22:41:27.0140 3468 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
22:41:27.0140 3468 RDPWD - ok
22:41:27.0281 3468 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
22:41:27.0281 3468 redbook - ok
22:41:27.0453 3468 rt2870 (24a0d16d170194b5812ea08542ebdb62) C:\WINDOWS\system32\DRIVERS\rt2870.sys
22:41:27.0468 3468 rt2870 - ok
22:41:27.0656 3468 SASDIFSV (5bf35c4ea3f00fa8d3f1e5bf03d24584) C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS
22:41:27.0656 3468 SASDIFSV - ok
22:41:27.0671 3468 SASENUM - ok
22:41:27.0687 3468 SASKUTIL (c7d81c10d3befeee41f3408714637438) C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys
22:41:27.0687 3468 SASKUTIL - ok
22:41:27.0812 3468 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:41:27.0812 3468 Secdrv - ok
22:41:27.0937 3468 senfilt (b9c7617c1e8ab6fdff75d3c8dafcb4c8) C:\WINDOWS\system32\drivers\senfilt.sys
22:41:27.0937 3468 senfilt - ok
22:41:28.0000 3468 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
22:41:28.0000 3468 serenum - ok
22:41:28.0156 3468 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
22:41:28.0156 3468 Serial - ok
22:41:28.0234 3468 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
22:41:28.0250 3468 Sfloppy - ok
22:41:28.0296 3468 Simbad - ok
22:41:28.0390 3468 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
22:41:28.0390 3468 sisagp - ok
22:41:28.0453 3468 smwdm (c6d9959e493682f872a639b6ec1b4a08) C:\WINDOWS\system32\drivers\smwdm.sys
22:41:28.0453 3468 smwdm - ok
22:41:28.0578 3468 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
22:41:28.0578 3468 Sparrow - ok
22:41:28.0625 3468 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
22:41:28.0625 3468 splitter - ok
22:41:28.0718 3468 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
22:41:28.0718 3468 sr - ok
22:41:28.0796 3468 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
22:41:28.0796 3468 Srv - ok
22:41:28.0906 3468 sscdbhk5 (d7968049be0adbb6a57cee3960320911) C:\WINDOWS\system32\drivers\sscdbhk5.sys
22:41:28.0906 3468 sscdbhk5 - ok
22:41:29.0015 3468 ssrtln (c3ffd65abfb6441e7606cf74f1155273) C:\WINDOWS\system32\drivers\ssrtln.sys
22:41:29.0015 3468 ssrtln - ok
22:41:29.0156 3468 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys
22:41:29.0156 3468 StillCam - ok
22:41:29.0203 3468 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
22:41:29.0203 3468 swenum - ok
22:41:29.0296 3468 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
22:41:29.0296 3468 swmidi - ok
22:41:29.0437 3468 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
22:41:29.0437 3468 symc810 - ok
22:41:29.0468 3468 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
22:41:29.0468 3468 symc8xx - ok
22:41:29.0609 3468 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
22:41:29.0609 3468 sym_hi - ok
22:41:29.0640 3468 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
22:41:29.0640 3468 sym_u3 - ok
22:41:29.0734 3468 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
22:41:29.0750 3468 sysaudio - ok
22:41:29.0812 3468 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:41:29.0812 3468 Tcpip - ok
22:41:29.0921 3468 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
22:41:29.0921 3468 TDPIPE - ok
22:41:30.0000 3468 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
22:41:30.0000 3468 TDTCP - ok
22:41:30.0125 3468 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
22:41:30.0125 3468 TermDD - ok
22:41:30.0187 3468 tfsnboio (30698355067d07da5f9eb81132c9fdd6) C:\WINDOWS\system32\dla\tfsnboio.sys
22:41:30.0187 3468 tfsnboio - ok
22:41:30.0265 3468 tfsncofs (fb9d825bb4a2abdf24600f7505050e2b) C:\WINDOWS\system32\dla\tfsncofs.sys
22:41:30.0265 3468 tfsncofs - ok
22:41:30.0328 3468 tfsndrct (cafd8cca11aa1e8b6d2ea1ba8f70ec33) C:\WINDOWS\system32\dla\tfsndrct.sys
22:41:30.0328 3468 tfsndrct - ok
22:41:30.0437 3468 tfsndres (8db1e78fbf7c426d8ec3d8f1a33d6485) C:\WINDOWS\system32\dla\tfsndres.sys
22:41:30.0437 3468 tfsndres - ok
22:41:30.0515 3468 tfsnifs (b92f67a71cc8176f331b8aa8d9f555ad) C:\WINDOWS\system32\dla\tfsnifs.sys
22:41:30.0515 3468 tfsnifs - ok
22:41:30.0578 3468 tfsnopio (85985faa9a71e2358fcc2edefc2a3c5c) C:\WINDOWS\system32\dla\tfsnopio.sys
22:41:30.0578 3468 tfsnopio - ok
22:41:30.0671 3468 tfsnpool (bba22094f0f7c210567efdaf11f64495) C:\WINDOWS\system32\dla\tfsnpool.sys
22:41:30.0671 3468 tfsnpool - ok
22:41:30.0734 3468 tfsnudf (81340bef80b9811e98ce64611e67e3ff) C:\WINDOWS\system32\dla\tfsnudf.sys
22:41:30.0734 3468 tfsnudf - ok
22:41:30.0843 3468 tfsnudfa (c035fd116224ccc8325f384776b6a8bb) C:\WINDOWS\system32\dla\tfsnudfa.sys
22:41:30.0843 3468 tfsnudfa - ok
22:41:31.0000 3468 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
22:41:31.0000 3468 TosIde - ok
22:41:31.0125 3468 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
22:41:31.0125 3468 Udfs - ok
22:41:31.0234 3468 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
22:41:31.0234 3468 ultra - ok
22:41:31.0312 3468 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
22:41:31.0312 3468 Update - ok
22:41:31.0421 3468 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys
22:41:31.0421 3468 USBAAPL - ok
22:41:31.0531 3468 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
22:41:31.0531 3468 usbccgp - ok
22:41:31.0593 3468 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:41:31.0609 3468 usbehci - ok
22:41:31.0703 3468 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:41:31.0703 3468 usbhub - ok
22:41:31.0781 3468 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
22:41:31.0781 3468 usbprint - ok
22:41:31.0843 3468 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
22:41:31.0843 3468 usbscan - ok
22:41:31.0953 3468 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:41:31.0953 3468 USBSTOR - ok
22:41:31.0984 3468 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:41:31.0984 3468 usbuhci - ok
22:41:32.0156 3468 USB_RNDIS_XP (bee793d4a059caea55d6ac20e19b3a8f) C:\WINDOWS\system32\DRIVERS\usb8023.sys
22:41:32.0156 3468 USB_RNDIS_XP - ok
22:41:32.0218 3468 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
22:41:32.0218 3468 VgaSave - ok
22:41:32.0312 3468 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
22:41:32.0312 3468 viaagp - ok
22:41:32.0406 3468 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
22:41:32.0406 3468 ViaIde - ok
22:41:32.0468 3468 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
22:41:32.0468 3468 VolSnap - ok
22:41:32.0562 3468 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:41:32.0562 3468 Wanarp - ok
22:41:32.0656 3468 wanatw - ok
22:41:32.0671 3468 WDICA - ok
22:41:32.0718 3468 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
22:41:32.0718 3468 wdmaud - ok
22:41:32.0890 3468 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
22:41:32.0906 3468 WpdUsb - ok
22:41:33.0015 3468 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
22:41:33.0015 3468 WudfPf - ok
22:41:33.0078 3468 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
22:41:33.0078 3468 WudfRd - ok
22:41:33.0140 3468 MBR (0x1B8) (b16a2359f4962b0c622d81a1c1f4b703) \Device\Harddisk0\DR0
22:41:33.0140 3468 \Device\Harddisk0\DR0 - ok
22:41:33.0156 3468 MBR (0x1B8) (ddae9d649db12f6aff24483f2c298989) \Device\Harddisk1\DR8
22:41:33.0156 3468 \Device\Harddisk1\DR8 - ok
22:41:33.0187 3468 Boot (0x1200) (6aca6b1e47d8b770c8048b440d544a87) \Device\Harddisk0\DR0\Partition0
22:41:33.0187 3468 \Device\Harddisk0\DR0\Partition0 - ok
22:41:33.0203 3468 Boot (0x1200) (6edcec8ff37fa3e21dbe2ff888217ebf) \Device\Harddisk1\DR8\Partition0
22:41:33.0203 3468 \Device\Harddisk1\DR8\Partition0 - ok
22:41:33.0203 3468 ============================================================
22:41:33.0203 3468 Scan finished
22:41:33.0203 3468 ============================================================
22:41:33.0218 1912 Detected object count: 0
22:41:33.0218 1912 Actual detected object count: 0
22:42:20.0687 3184 Deinitialize success

Edited by jdbangels, 29 December 2011 - 11:46 PM.


#14 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:14 PM

Posted 29 December 2011 - 11:49 PM

Can you say me the location of ipsec.sys that AVG points as infection?

Also

Download

http://www.mediafire.com/?m1l87047whb0aeu

Launch the reg file,click YES

Restart your PC and see if you can browse now

Edited by narenxp, 29 December 2011 - 11:51 PM.


#15 jdbangels

jdbangels
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:12:14 PM

Posted 30 December 2011 - 12:00 AM

Sorry, don't understand. That downloads as a notepad file.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users